954,136 Members — Technology Publication meets Social Media
Username:
Password:
Lost login information?
Have something to say? Contribute New Article Reply to this Article

blank pop-ups

The past couple of days I've been having problems with blank pop-ups on my computer. When I try to use task manager to close them (since right clicking on them won't let me), they keep popping right back up again. Also have had my windows, if I have two or three minimized, wanting to close on their own. I have ran Adaware and Spybot and let them fix what they found, and my AVG hasn't picked anything up at all. Any ideas or suggestions? Thanks! ~DeOnna

deonnanicole
Posting Whiz in Training
253 posts since Jun 2004
Reputation Points: 18
Solved Threads: 13
 

I also wanted to add that this has been coming up too:

Debug Assertion Failed
Program: C:\Program Files\Internet Explorer\iexplore.exe
File: dbgheap.C
Expression: _CrtIsValidHeapPointer(pUser Data)

Then it gives me the choices of abort, retry, or ignore.

deonnanicole
Posting Whiz in Training
253 posts since Jun 2004
Reputation Points: 18
Solved Threads: 13
 

Blank popups combined with that error? Obviously the host malware is scripted poorly.
==Get CCleaner from http://www.ccleaner.com/ - and put it in a new folder. You should keep this one for general use. I set the installation checkboxes only to open from the recycle bin. It's neater that way.
Now run CCleaner from the recycle bin rclick menu using its default settings [if you set up CCleaner as i suggested, rclicking the bin icon should give you the Open CCleaner option...]. Select the Cleaner icon, press Run Cleaner.
[For future quick temp file cleaning select the options you wish to use via the Windows and Applications tabs ..]
==GET AVG antispyware 7.5 here.. http://free.grisoft.com/doc/5390/lng/us/tpl/v5
or here.. http://free.grisoft.com/freeweb.php/doc/5390/lng/us/tpl/v5#avg-anti-spyware-free
-Install it and UPDATE it.
Start AVG a-s 7.5;
-under Scanner/ Settings please change the default action from Recommended Actions to QUARANTINE, and run the complete system scan.
-press Apply all Actions and Save the log file. Post the log file.
==download hijackthis: http://www.majorgeeks.com/download5554.html
-install it to a new folder alongside your program files and then... rename hijackthis .exe to imabunny.exe
-in that folder start HijackThis by dclicking the .exe; now close ALL other applications and any open windows including the explorer window containing HijackThis.
-click the Scan and Save a Logfile button. Post the log here.

gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
 

Ok hopefully I will get done typing this before the window closes again. I thought everything was fine until I came here and the window keeps closing on its own. I will follow the instructions you gave me first thing in the morning and post again. Thanks so much! And sorry for the delay in responding. :)

deonnanicole
Posting Whiz in Training
253 posts since Jun 2004
Reputation Points: 18
Solved Threads: 13
 

Ok here are the logfiles.....CCleaner first:

=== Verbose logging started: 11/15/2006 22:08:21 Build type: SHIP UNICODE 3.01.4000.2435 Calling process: C:\WINDOWS\system32\msiexec.exe ===
MSI (c) (FC:88) [22:08:21:046]: Resetting cached policy values
MSI (c) (FC:88) [22:08:21:046]: Machine policy value 'Debug' is 0
MSI (c) (FC:88) [22:08:21:046]: ******* RunEngine:
******* Product: c:\59eb719a0cb67cf60067\msxml.msi
******* Action:
******* CommandLine: **********
MSI (c) (FC:88) [22:08:21:046]: Client-side and UI is none or basic: Running entire install on the server.
MSI (c) (FC:88) [22:08:21:046]: Grabbed execution mutex.
MSI (c) (FC:88) [22:08:21:203]: Cloaking enabled.
MSI (c) (FC:88) [22:08:21:203]: Attempting to enable all disabled priveleges before calling Install on Server
MSI (c) (FC:88) [22:08:21:218]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (F0:C0) [22:08:21:234]: Grabbed execution mutex.
MSI (s) (F0:2C) [22:08:21:234]: Resetting cached policy values
MSI (s) (F0:2C) [22:08:21:234]: Machine policy value 'Debug' is 0
MSI (s) (F0:2C) [22:08:21:234]: ******* RunEngine:
******* Product: c:\59eb719a0cb67cf60067\msxml.msi
******* Action:
******* CommandLine: **********
MSI (s) (F0:2C) [22:08:21:250]: Machine policy value 'DisableUserInstalls' is 0
MSI (s) (F0:2C) [22:08:21:281]: File will have security applied from OpCode.
MSI (s) (F0:2C) [22:08:21:359]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'c:\59eb719a0cb67cf60067\msxml.msi' against software restriction policy
MSI (s) (F0:2C) [22:08:21:359]: SOFTWARE RESTRICTION POLICY: c:\59eb719a0cb67cf60067\msxml.msi has a digital signature
MSI (s) (F0:2C) [22:08:22:046]: SOFTWARE RESTRICTION POLICY: c:\59eb719a0cb67cf60067\msxml.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (F0:2C) [22:08:22:046]: End dialog not enabled
MSI (s) (F0:2C) [22:08:22:046]: Original package ==> c:\59eb719a0cb67cf60067\msxml.msi
MSI (s) (F0:2C) [22:08:22:046]: Package we're running from ==> c:\WINDOWS\Installer\1459a2f.msi
MSI (s) (F0:2C) [22:08:22:078]: APPCOMPAT: looking for appcompat database entry with ProductCode '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (F0:2C) [22:08:22:078]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (F0:2C) [22:08:22:093]: MSCOREE not loaded loading copy from system32
MSI (s) (F0:2C) [22:08:22:109]: Machine policy value 'TransformsSecure' is 0
MSI (s) (F0:2C) [22:08:22:109]: User policy value 'TransformsAtSource' is 0
MSI (s) (F0:2C) [22:08:22:109]: Machine policy value 'DisablePatch' is 0
MSI (s) (F0:2C) [22:08:22:109]: Machine policy value 'AllowLockdownPatch' is 0
MSI (s) (F0:2C) [22:08:22:109]: Machine policy value 'DisableLUAPatching' is 0
MSI (s) (F0:2C) [22:08:22:109]: Machine policy value 'DisableFlyWeightPatching' is 0
MSI (s) (F0:2C) [22:08:22:109]: APPCOMPAT: looking for appcompat database entry with ProductCode '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (F0:2C) [22:08:22:109]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (F0:2C) [22:08:22:109]: Transforms are not secure.
MSI (s) (F0:2C) [22:08:22:109]: Command Line: REBOOT=ReallySuppress CURRENTDIRECTORY=c:\59eb719a0cb67cf60067 CLIENTUILEVEL=3 CLIENTPROCESSID=3324
MSI (s) (F0:2C) [22:08:22:109]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{2B27DCD9-53FA-4885-B6CD-698623819F4C}'.
MSI (s) (F0:2C) [22:08:22:109]: Product Code passed to Engine.Initialize: ''
MSI (s) (F0:2C) [22:08:22:109]: Product Code from property table before transforms: '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'
MSI (s) (F0:2C) [22:08:22:109]: Product Code from property table after transforms: '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'
MSI (s) (F0:2C) [22:08:22:109]: Product not registered: beginning first-time install
MSI (s) (F0:2C) [22:08:22:109]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.
MSI (s) (F0:2C) [22:08:22:109]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (F0:2C) [22:08:22:109]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (F0:2C) [22:08:22:109]: Adding new sources is allowed.
MSI (s) (F0:2C) [22:08:22:109]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.
MSI (s) (F0:2C) [22:08:22:109]: Package name extracted from package path: 'msxml.msi'
MSI (s) (F0:2C) [22:08:22:109]: Package to be registered: 'msxml.msi'
MSI (s) (F0:2C) [22:08:22:109]: Note: 1: 2729
MSI (s) (F0:2C) [22:08:22:125]: Note: 1: 2729
MSI (s) (F0:2C) [22:08:22:125]: Note: 1: 2262 2: AdminProperties 3: -2147287038
MSI (s) (F0:2C) [22:08:22:125]: Machine policy value 'DisableMsi' is 0
MSI (s) (F0:2C) [22:08:22:125]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (F0:2C) [22:08:22:125]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (F0:2C) [22:08:22:125]: Product installation will be elevated because user is admin and product is being installed per-machine.
MSI (s) (F0:2C) [22:08:22:125]: Running product '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}' with elevated privileges: Product is assigned.
MSI (s) (F0:2C) [22:08:22:125]: PROPERTY CHANGE: Adding REBOOT property. Its value is 'ReallySuppress'.
MSI (s) (F0:2C) [22:08:22:125]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'c:\59eb719a0cb67cf60067'.
MSI (s) (F0:2C) [22:08:22:125]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.
MSI (s) (F0:2C) [22:08:22:125]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '3324'.
MSI (s) (F0:2C) [22:08:22:125]: TRANSFORMS property is now:
MSI (s) (F0:2C) [22:08:22:125]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '200'.
MSI (s) (F0:2C) [22:08:22:125]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Application Data
MSI (s) (F0:2C) [22:08:22:140]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Favorites
MSI (s) (F0:2C) [22:08:22:140]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\NetHood
MSI (s) (F0:2C) [22:08:22:140]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\My Documents
MSI (s) (F0:2C) [22:08:22:140]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\PrintHood
MSI (s) (F0:2C) [22:08:22:140]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Recent
MSI (s) (F0:2C) [22:08:22:140]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\SendTo
MSI (s) (F0:2C) [22:08:22:140]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Templates
MSI (s) (F0:2C) [22:08:22:140]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Application Data
MSI (s) (F0:2C) [22:08:22:140]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data
MSI (s) (F0:2C) [22:08:22:140]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\My Documents\My Pictures
MSI (s) (F0:2C) [22:08:22:171]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
MSI (s) (F0:2C) [22:08:22:171]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs\Startup
MSI (s) (F0:2C) [22:08:22:171]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs
MSI (s) (F0:2C) [22:08:22:171]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu
MSI (s) (F0:2C) [22:08:22:171]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Desktop
MSI (s) (F0:2C) [22:08:22:171]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Administrative Tools
MSI (s) (F0:2C) [22:08:22:203]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup
MSI (s) (F0:2C) [22:08:22:203]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs
MSI (s) (F0:2C) [22:08:22:203]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu
MSI (s) (F0:2C) [22:08:22:203]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Desktop
MSI (s) (F0:2C) [22:08:22:203]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Templates
MSI (s) (F0:2C) [22:08:22:203]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\Fonts
MSI (s) (F0:2C) [22:08:22:218]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16
MSI (s) (F0:2C) [22:08:22:218]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.
MSI (s) (F0:2C) [22:08:22:218]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (F0:2C) [22:08:22:218]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'DEONNA WALKER'.
MSI (s) (F0:2C) [22:08:22:218]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (F0:2C) [22:08:22:218]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'c:\WINDOWS\Installer\1459a2f.msi'.
MSI (s) (F0:2C) [22:08:22:218]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'c:\59eb719a0cb67cf60067\msxml.msi'.
MSI (s) (F0:2C) [22:08:22:218]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (F0:2C) [22:08:22:218]: Machine policy value 'DisableRollback' is 0
MSI (s) (F0:2C) [22:08:22:218]: User policy value 'DisableRollback' is 0
MSI (s) (F0:2C) [22:08:22:218]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.
=== Logging started: 11/15/2006 22:08:22 ===
MSI (s) (F0:2C) [22:08:22:218]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.
MSI (s) (F0:2C) [22:08:22:218]: Doing action: INSTALL
MSI (s) (F0:2C) [22:08:22:218]: Running ExecuteSequence
MSI (s) (F0:2C) [22:08:22:218]: Doing action: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901
Action start 22:08:22: INSTALL.
MSI (s) (F0:2C) [22:08:22:234]: PROPERTY CHANGE: Adding DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Documents and Settings\All Users\Desktop\'.
Action start 22:08:22: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901.
MSI (s) (F0:2C) [22:08:22:234]: Doing action: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901
Action ended 22:08:22: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901. Return value 1.
MSI (s) (F0:2C) [22:08:22:234]: PROPERTY CHANGE: Adding ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Documents and Settings\All Users\Start Menu\Programs\'.
Action start 22:08:22: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901.
MSI (s) (F0:2C) [22:08:22:234]: Doing action: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
Action ended 22:08:22: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901. Return value 1.
MSI (s) (F0:2C) [22:08:22:234]: PROPERTY CHANGE: Adding WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 22:08:22: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537.
MSI (s) (F0:2C) [22:08:22:234]: Doing action: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
Action ended 22:08:22: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (F0:2C) [22:08:22:234]: PROPERTY CHANGE: Adding SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:08:22: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537.
MSI (s) (F0:2C) [22:08:22:234]: Doing action: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537
Action ended 22:08:22: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (F0:2C) [22:08:22:234]: PROPERTY CHANGE: Adding WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 22:08:22: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537.
MSI (s) (F0:2C) [22:08:22:250]: Doing action: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537
Action ended 22:08:22: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (F0:2C) [22:08:22:250]: PROPERTY CHANGE: Adding SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:08:22: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537.
MSI (s) (F0:2C) [22:08:22:250]: Doing action: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
Action ended 22:08:22: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (F0:2C) [22:08:22:250]: PROPERTY CHANGE: Adding WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 22:08:22: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537.
MSI (s) (F0:2C) [22:08:22:250]: Doing action: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
Action ended 22:08:22: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (F0:2C) [22:08:22:250]: PROPERTY CHANGE: Adding SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:08:22: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537.
MSI (s) (F0:2C) [22:08:22:250]: Doing action: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB
Action ended 22:08:22: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (F0:2C) [22:08:22:250]: PROPERTY CHANGE: Adding SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:08:22: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB.
MSI (s) (F0:2C) [22:08:22:250]: Doing action: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1
Action ended 22:08:22: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB. Return value 1.
MSI (s) (F0:2C) [22:08:22:265]: PROPERTY CHANGE: Adding SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:08:22: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1.
MSI (s) (F0:2C) [22:08:22:265]: Doing action: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7
Action ended 22:08:22: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1. Return value 1.
MSI (s) (F0:2C) [22:08:22:265]: PROPERTY CHANGE: Adding SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:08:22: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7.
MSI (s) (F0:2C) [22:08:22:265]: Doing action: LaunchConditions
Action ended 22:08:22: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7. Return value 1.
Action start 22:08:22: LaunchConditions.
MSI (s) (F0:2C) [22:08:22:265]: Doing action: FindRelatedProducts
Action ended 22:08:22: LaunchConditions. Return value 1.
Action start 22:08:22: FindRelatedProducts.
MSI (s) (F0:2C) [22:08:22:265]: Doing action: AppSearch
Action ended 22:08:22: FindRelatedProducts. Return value 1.
Action start 22:08:22: AppSearch.
MSI (s) (F0:2C) [22:08:22:265]: Note: 1: 2262 2: Signature 3: -2147287038
MSI (s) (F0:2C) [22:08:22:265]: PROPERTY CHANGE: Adding WINHTTP_51 property. Its value is 'WinHttpRequest Component version 5.1'.
MSI (s) (F0:2C) [22:08:22:265]: Skipping action: CCPSearch (condition is false)
MSI (s) (F0:2C) [22:08:22:265]: Skipping action: RMCCPSearch (condition is false)
MSI (s) (F0:2C) [22:08:22:265]: Doing action: ValidateProductID
Action ended 22:08:22: AppSearch. Return value 1.
Action start 22:08:22: ValidateProductID.
MSI (s) (F0:2C) [22:08:22:281]: Doing action: CostInitialize
Action ended 22:08:22: ValidateProductID. Return value 1.
MSI (s) (F0:2C) [22:08:22:281]: Machine policy value 'MaxPatchCacheSize' is 10
Action start 22:08:22: CostInitialize.
MSI (s) (F0:2C) [22:08:22:296]: PROPERTY CHANGE: Adding ROOTDRIVE property. Its value is 'c:\'.
MSI (s) (F0:2C) [22:08:22:296]: PROPERTY CHANGE: Adding CostingComplete property. Its value is '0'.
MSI (s) (F0:2C) [22:08:22:296]: Note: 1: 2205 2: 3: Patch
MSI (s) (F0:2C) [22:08:22:296]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (F0:2C) [22:08:22:296]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (F0:2C) [22:08:22:296]: Note: 1: 2205 2: 3: __MsiPatchFileList
MSI (s) (F0:2C) [22:08:22:296]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (F0:2C) [22:08:22:296]: Note: 1: 2228 2: 3: PatchPackage 4: SELECT `DiskId`, `PatchId`, `LastSequence` FROM `Media`, `PatchPackage` WHERE `Media`.`DiskId`=`PatchPackage`.`Media_` ORDER BY `DiskId`
MSI (s) (F0:2C) [22:08:22:296]: Doing action: FileCost
Action ended 22:08:22: CostInitialize. Return value 1.
MSI (s) (F0:2C) [22:08:22:296]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:08:22: FileCost.
MSI (s) (F0:2C) [22:08:22:296]: Doing action: CostFinalize
Action ended 22:08:22: FileCost. Return value 1.
MSI (s) (F0:2C) [22:08:22:296]: PROPERTY CHANGE: Adding OutOfDiskSpace property. Its value is '0'.
MSI (s) (F0:2C) [22:08:22:296]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Its value is '0'.
MSI (s) (F0:2C) [22:08:22:296]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceAvailable property. Its value is '0'.
MSI (s) (F0:2C) [22:08:22:296]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRequired property. Its value is '0'.
MSI (s) (F0:2C) [22:08:22:296]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRemaining property. Its value is '0'.
MSI (s) (F0:2C) [22:08:22:296]: Note: 1: 2205 2: 3: Patch
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding TARGETDIR property. Its value is 'c:\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying WindowsFolder property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying CommonFilesFolder property. Its current value is 'C:\Program Files\Common Files\'. Its new value: 'c:\Program Files\Common Files\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 property. Its value is 'c:\Program Files\Common Files\Microsoft Shared\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 property. Its value is 'c:\Program Files\Common Files\Microsoft Shared\MSDN\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa6920e9f98fc\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying DesktopFolder property. Its current value is 'C:\Documents and Settings\All Users\Desktop\'. Its new value: 'c:\Documents and Settings\All Users\Desktop\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying ProgramFilesFolder property. Its current value is 'C:\Program Files\'. Its new value: 'c:\Program Files\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding MSXML property. Its value is 'c:\Program Files\MSXML 4.0\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding INC.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\inc\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding LIB.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\lib\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding DOC.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\doc\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its current value is 'C:\Documents and Settings\All Users\Start Menu\Programs\'. Its new value: 'c:\Documents and Settings\All Users\Start Menu\Programs\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Adding MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Documents and Settings\All Users\Start Menu\Programs\MSXML 4.0\'.
MSI (s) (F0:2C) [22:08:22:312]: PROPERTY CHANGE: Modifying DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its current value is 'C:\Documents and Settings\All Users\Desktop\'. Its new value: 'c:\Documents and Settings\All Users\Desktop\'.
MSI (s) (F0:2C) [22:08:22:312]: Target path resolution complete. Dumping Directory table...
MSI (s) (F0:2C) [22:08:22:312]: Note: target paths subject to change (via custom actions or browsing)
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: TARGETDIR , Object: c:\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: WindowsFolder , Object: c:\WINDOWS\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: CommonFilesFolder , Object: c:\Program Files\Common Files\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\Program Files\Common Files\Microsoft Shared\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\Program Files\Common Files\Microsoft Shared\MSDN\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa6920e9f98fc\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB , Object: c:\WINDOWS\system32\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 , Object: c:\WINDOWS\system32\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 , Object: c:\WINDOWS\system32\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: DesktopFolder , Object: c:\Documents and Settings\All Users\Desktop\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: ProgramFilesFolder , Object: c:\Program Files\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: MSXML , Object: c:\Program Files\MSXML 4.0\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: INC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\inc\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: LIB.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\lib\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: DOC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\doc\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Start Menu\Programs\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Start Menu\Programs\MSXML 4.0\
MSI (s) (F0:2C) [22:08:22:312]: Dir (target): Key: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Desktop\
Action start 22:08:22: CostFinalize.
MSI (s) (F0:2C) [22:08:22:328]: Doing action: SetODBCFolders
Action ended 22:08:22: CostFinalize. Return value 1.
MSI (s) (F0:2C) [22:08:22:328]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (F0:2C) [22:08:22:328]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `ComponentId`,`Description`,`Directory_`, `ActionRequest`, `Installed`, `Attributes` FROM `ODBCDriver`, `Component` WHERE `ODBCDriver`.`Component_` = `Component` AND (`ActionRequest` = 1 OR `ActionRequest` = 2)
MSI (s) (F0:2C) [22:08:22:328]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (F0:2C) [22:08:22:328]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `ComponentId`,`Description`,`Directory_`, `ActionRequest`, `Installed`, `Attributes` FROM `ODBCTranslator`, `Component` WHERE `ODBCTranslator`.`Component_` = `Component` AND (`ActionRequest` = 1 OR `ActionRequest` = 2)
Action start 22:08:22: SetODBCFolders.
MSI (s) (F0:2C) [22:08:22:328]: Doing action: MigrateFeatureStates
Action ended 22:08:22: SetODBCFolders. Return value 0.
Action start 22:08:22: MigrateFeatureStates.
MSI (s) (F0:2C) [22:08:22:328]: Doing action: InstallValidate
Action ended 22:08:22: MigrateFeatureStates. Return value 0.
MSI (s) (F0:2C) [22:08:22:328]: Feature: MSXML; Installed: Absent; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Feature: MSXMLSYS; Installed: Absent; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Feature: MSXMLSUPP; Installed: Absent; Request: Null; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Feature: MSXMLSUPP2; Installed: Absent; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Feature: MSXMLSXS; Installed: Absent; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Feature: XMLSDK; Installed: Absent; Request: Null; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: RememberInstallFolder; Installed: Absent; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: QKBKEY; Installed: Absent; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: MSXML4_System.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: MSXML4_SystemRes.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: MSXML4_ANSI.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: WINHTTP50_COMPONENT.781A0624_31FF_4712_BFFD_31C829FFDBF1; Installed: Absent; Request: Null; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: PROXYCFG_COMPONENT.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB; Installed: Absent; Request: Local; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: uplevel.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: downlevel_manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: downlevel_payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: uplevel.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: downlevel_manifest.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: downlevel_payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: uplevel.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: downlevel_manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: XMLSDK_Docs.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: XMLSDK_LIB.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: XMLSDK_INC.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: CookDoc_dll.3FB7DAB3_19E7_40A0_8730_4482CE77AC59; Installed: Absent; Request: Null; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: __uplevel.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: __uplevel.DA6654F6_456F_3658_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: __uplevel.0E9F98FC_A692_A6DF_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: __QKBKEY65; Installed: Null; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: __MSXML4_System.246EB7AD_459A_4FA8_83D1_4165; Installed: Null; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: __downlevel_payload.7B2FCEFF_0F22_B7E1_FF665; Installed: Null; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: __downlevel_manifest.7B2FCEFF_0F22_B7E1_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: __downlevel_payload.DA6654F6_456F_3658_FF665; Installed: Null; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: __downlevel_manifest.DA6654F6_456F_3658_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: __downlevel_manifest.0E9F98FC_A692_A6DF_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (F0:2C) [22:08:22:328]: Component: __CookDoc_dll.3FB7DAB3_19E7_40A0_8730_448265; Installed: Null; Request: Null; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Component: __XMLSDK_Docs.4576A2F1_959E_4BCA_94A9_596565; Installed: Null; Request: Null; Action: Null
MSI (s) (F0:2C) [22:08:22:328]: Note: 1: 2205 2: 3: BindImage
MSI (s) (F0:2C) [22:08:22:328]: Note: 1: 2262 2: PublishComponent 3: -2147287038
MSI (s) (F0:2C) [22:08:22:328]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F0:2C) [22:08:22:328]: Note: 1: 2205 2: 3: Font
Action start 22:08:22: InstallValidate.
MSI (s) (F0:2C) [22:08:22:328]: Note: 1: 2205 2: 3: _RemoveFilePath
MSI (s) (F0:2C) [22:08:22:453]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F0:2C) [22:08:22:453]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F0:2C) [22:08:22:453]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F0:2C) [22:08:22:453]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F0:2C) [22:08:22:453]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F0:2C) [22:08:22:453]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F0:2C) [22:08:22:453]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F0:2C) [22:08:22:453]: PROPERTY CHANGE: Modifying CostingComplete property. Its current value is '0'. Its new value: '1'.
MSI (s) (F0:2C) [22:08:22:453]: Note: 1: 2205 2: 3: BindImage
MSI (s) (F0:2C) [22:08:22:453]: Note: 1: 2262 2: PublishComponent 3: -2147287038
MSI (s) (F0:2C) [22:08:22:453]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F0:2C) [22:08:22:453]: Note: 1: 2205 2: 3: Font
MSI (s) (F0:2C) [22:08:22:453]: Note: 1: 2727 2:
MSI (s) (F0:2C) [22:08:22:468]: Note: 1: 2727 2:
MSI (s) (F0:2C) [22:08:22:468]: Doing action: InstallInitialize
Action ended 22:08:22: InstallValidate. Return value 1.
MSI (s) (F0:2C) [22:08:22:468]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (F0:2C) [22:08:22:468]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (F0:2C) [22:08:22:468]: BeginTransaction: Locking Server
MSI (s) (F0:2C) [22:08:22:468]: SRSetRestorePoint skipped for this transaction.
MSI (s) (F0:2C) [22:08:22:468]: Server not locked: locking for product {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
Action start 22:08:22: InstallInitialize.
MSI (s) (F0:2C) [22:08:23:062]: Doing action: SxsInstallCA
Action ended 22:08:23: InstallInitialize. Return value 1.
MSI (s) (F0:54) [22:08:23:078]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI1B2.tmp, Entrypoint: CustomAction_SxsMsmInstall
MSI (s) (F0:60) [22:08:23:078]: Generating random cookie.
MSI (s) (F0:60) [22:08:23:093]: Created Custom Action Server with PID 1244 (0x4DC).
MSI (s) (F0:94) [22:08:23:218]: Running as a service.
MSI (s) (F0:74) [22:08:23:218]: Hello, I'm your 32bit Elevated custom action server.
Action start 22:08:23: SxsInstallCA.
1: sxsdelca 2: traceop 3: 1256 4: 0
1: sxsdelca 2: traceop 3: 1257 4: 0
1: sxsdelca 2: traceop 3: 1258 4: 0
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 1306 4: 0
1: sxsdelca 2: traceop 3: 1307 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_manifest.DA6654F6_456F_3658_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 259
1: sxsdelca 2: SxsMsmInstall completed 3: 0 4: 0
MSI (s) (F0:2C) [22:08:23:671]: Doing action: AllocateRegistrySpace
Action ended 22:08:23: SxsInstallCA. Return value 1.
Action start 22:08:23: AllocateRegistrySpace.
MSI (s) (F0:2C) [22:08:23:671]: Doing action: ProcessComponents
Action ended 22:08:23: AllocateRegistrySpace. Return value 1.
MSI (s) (F0:2C) [22:08:23:687]: Note: 1: 2205 2: 3: MsiPatchCertificate
MSI (s) (F0:2C) [22:08:23:687]: LUA patching is disabled: missing MsiPatchCertificate table
MSI (s) (F0:2C) [22:08:23:687]: Resolving source.
MSI (s) (F0:2C) [22:08:23:687]: Resolving source to launched-from source.
MSI (s) (F0:2C) [22:08:23:687]: Setting launched-from source as last-used.
MSI (s) (F0:2C) [22:08:23:687]: PROPERTY CHANGE: Adding SourceDir property. Its value is 'c:\59eb719a0cb67cf60067\'.
MSI (s) (F0:2C) [22:08:23:687]: PROPERTY CHANGE: Adding SOURCEDIR property. Its value is 'c:\59eb719a0cb67cf60067\'.
MSI (s) (F0:2C) [22:08:23:687]: PROPERTY CHANGE: Adding SourcedirProduct property. Its value is '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (F0:2C) [22:08:23:687]: SOURCEDIR ==> c:\59eb719a0cb67cf60067\
MSI (s) (F0:2C) [22:08:23:687]: SOURCEDIR product ==> {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSI (s) (F0:2C) [22:08:23:687]: Determining source type
MSI (s) (F0:2C) [22:08:23:687]: Source type from package 'msxml.msi': 2
Action start 22:08:23: ProcessComponents.
MSI (s) (F0:2C) [22:08:23:687]: Source path resolution complete. Dumping Directory table...
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: TARGETDIR , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: WindowsFolder , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: CommonFilesFolder , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Microsoft Shared\ , ShortSubPath: MICROS~1\
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Microsoft Shared\MSDN\ , ShortSubPath: MICROS~1\MSDN\
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\system32\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\k0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\h0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\Manifests\ , ShortSubPath: Windows\winsxs\manifest\
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\Policies\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\Policies\i0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\j0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\system32\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\8n0mtfut.k85\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\Policies\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\Policies\6n0mtfut.k85\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\Manifests\ , ShortSubPath: Windows\winsxs\manifest\
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\5n0mtfut.k85\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\7n0mtfut.k85\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\system32\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\wl34x2va.rt8\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\Policies\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\Policies\ul34x2va.rt8\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\Manifests\ , ShortSubPath: Windows\winsxs\manifest\
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\tl34x2va.rt8\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: Windows\winsxs\vl34x2va.rt8\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: System\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: DesktopFolder , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: ProgramFilesFolder , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: MSXML , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: redist\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: INC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: redist\inc\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: LIB.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: redist\lib\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: DOC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: redist\doc\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: redist\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: redist\MSXML 4.0\ , ShortSubPath: redist\MSXML4\
MSI (s) (F0:2C) [22:08:23:687]: Dir (source): Key: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\59eb719a0cb67cf60067\ , LongSubPath: redist\ , ShortSubPath:
MSI (s) (F0:2C) [22:08:23:703]: Doing action: UnpublishComponents
Action ended 22:08:23: ProcessComponents. Return value 1.
MSI (s) (F0:2C) [22:08:23:703]: Note: 1: 2262 2: PublishComponent 3: -2147287038
Action start 22:08:23: UnpublishComponents.
MSI (s) (F0:2C) [22:08:23:703]: Doing action: MsiUnpublishAssemblies
Action ended 22:08:23: UnpublishComponents. Return value 1.
Action start 22:08:23: MsiUnpublishAssemblies.
MSI (s) (F0:2C) [22:08:23:703]: Doing action: UnpublishFeatures
Action ended 22:08:23: MsiUnpublishAssemblies. Return value 1.
Action start 22:08:23: UnpublishFeatures.
MSI (s) (F0:2C) [22:08:23:703]: Doing action: StopServices
Action ended 22:08:23: UnpublishFeatures. Return value 1.
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2205 2: 3: ServiceControl
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2228 2: 3: ServiceControl 4: SELECT `Name`,`Wait`,`Arguments`,`Event`, `Action` FROM `ServiceControl`, `Component` WHERE `Component_` = `Component` AND (`Action` = 0 OR `Action` = 1 OR `Action` = 2)
Action start 22:08:23: StopServices.
MSI (s) (F0:2C) [22:08:23:718]: Doing action: DeleteServices
Action ended 22:08:23: StopServices. Return value 1.
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2205 2: 3: ServiceControl
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2228 2: 3: ServiceControl 4: SELECT `Name`,`Wait`,`Arguments`,`Event`, `Action` FROM `ServiceControl`, `Component` WHERE `Component_` = `Component` AND (`Action` = 0 OR `Action` = 1 OR `Action` = 2)
Action start 22:08:23: DeleteServices.
MSI (s) (F0:2C) [22:08:23:718]: Doing action: UnregisterComPlus
Action ended 22:08:23: DeleteServices. Return value 1.
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2205 2: 3: Complus
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2228 2: 3: Complus 4: SELECT `ComponentId`, `FileName`, `Component`.`Directory_`, `ExpType`, `Component`.`Action`, `Component`.`Installed` FROM `Complus`, `Component`, `File` WHERE `Complus`.`Component_` = `Component` AND `Component`.`KeyPath` = `File`.`File` AND `Action` = 0
Action start 22:08:23: UnregisterComPlus.
MSI (s) (F0:2C) [22:08:23:718]: Doing action: SelfUnregModules
Action ended 22:08:23: UnregisterComPlus. Return value 0.
Action start 22:08:23: SelfUnregModules.
MSI (s) (F0:2C) [22:08:23:718]: Doing action: UnregisterTypeLibraries
Action ended 22:08:23: SelfUnregModules. Return value 1.
Action start 22:08:23: UnregisterTypeLibraries.
MSI (s) (F0:2C) [22:08:23:718]: Doing action: RemoveODBC
Action ended 22:08:23: UnregisterTypeLibraries. Return value 1.
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND `Component`.`Action` = 0 AND `BinaryType` = ?
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND `Component`.`Action` = 0 AND `BinaryType` = ?
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCTranslator`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCTranslator`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCDriver`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCDriver`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2711 2: ODBCDriverManager
Action start 22:08:23: RemoveODBC.
MSI (s) (F0:2C) [22:08:23:718]: Note: 1: 2711 2: ODBCDriverManager64
MSI (s) (F0:2C) [22:08:23:718]: Doing action: UnregisterFonts
Action ended 22:08:23: RemoveODBC. Return value 1.
MSI (s) (F0:2C) [22:08:23:734]: Note: 1: 2205 2: 3: Font
MSI (s) (F0:2C) [22:08:23:734]: Note: 1: 2228 2: 3: Font 4: SELECT `FontTitle`, `FileName`, `Directory_`, `Installed`From `Font`, `FileAction` Where `Font`.`File_` = `FileAction`.`File` And `FileAction`.`Action` = 0 ORDER BY `FileAction`.`Directory_`
Action start 22:08:23: UnregisterFonts.
MSI (s) (F0:2C) [22:08:23:734]: Doing action: RemoveRegistryValues
Action ended 22:08:23: UnregisterFonts. Return value 1.
Action start 22:08:23: RemoveRegistryValues.
MSI (s) (F0:2C) [22:08:23:734]: Doing action: UnregisterClassInfo
Action ended 22:08:23: RemoveRegistryValues. Return value 1.
Action start 22:08:23: UnregisterClassInfo.
MSI (s) (F0:2C) [22:08:23:734]: Doing action: UnregisterExtensionInfo
Action ended 22:08:23: UnregisterClassInfo. Return value 1.
MSI (s) (F0:2C) [22:08:23:734]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:08:23: UnregisterExtensionInfo.
MSI (s) (F0:2C) [22:08:23:734]: Doing action: UnregisterProgIdInfo
Action ended 22:08:23: UnregisterExtensionInfo. Return value 1.
MSI (s) (F0:2C) [22:08:23:734]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:08:23: UnregisterProgIdInfo.
MSI (s) (F0:2C) [22:08:23:734]: Doing action: UnregisterMIMEInfo
Action ended 22:08:23: UnregisterProgIdInfo. Return value 1.
MSI (s) (F0:2C) [22:08:23:734]: Note: 1: 2262 2: MIME 3: -2147287038
MSI (s) (F0:2C) [22:08:23:734]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:08:23: UnregisterMIMEInfo.
MSI (s) (F0:2C) [22:08:23:734]: Doing action: RemoveIniValues
Action ended 22:08:23: UnregisterMIMEInfo. Return value 1.
MSI (s) (F0:2C) [22:08:23:750]: Note: 1: 2205 2: 3: IniFile
MSI (s) (F0:2C) [22:08:23:750]: Note: 1: 2228 2: 3: IniFile 4: SELECT `FileName`,`IniFile`.`DirProperty`,`Section`,`IniFile`.`Key`,`IniFile`.`Value`,`IniFile`.`Action` FROM `IniFile`, `Component` WHERE `Component`=`Component_` AND `Component`.`Action`=0 ORDER BY `FileName`,`Section`
Action start 22:08:23: RemoveIniValues.
MSI (s) (F0:2C) [22:08:23:750]: Doing action: RemoveShortcuts
Action ended 22:08:23: RemoveIniValues. Return value 1.
Action start 22:08:23: RemoveShortcuts.
MSI (s) (F0:2C) [22:08:23:750]: Doing action: RemoveEnvironmentStrings
Action ended 22:08:23: RemoveShortcuts. Return value 1.
MSI (s) (F0:2C) [22:08:23:750]: Note: 1: 2205 2: 3: Environment
MSI (s) (F0:2C) [22:08:23:750]: Note: 1: 2228 2: 3: Environment 4: SELECT `Name`,`Value` FROM `Environment`,`Component` WHERE `Component_`=`Component` AND (`Component`.`Action` = 0)
Action start 22:08:23: RemoveEnvironmentStrings.
MSI (s) (F0:2C) [22:08:23:750]: Doing action: RemoveDuplicateFiles
Action ended 22:08:23: RemoveEnvironmentStrings. Return value 1.
Action start 22:08:23: RemoveDuplicateFiles.
MSI (s) (F0:2C) [22:08:23:750]: Doing action: RemoveFiles
Action ended 22:08:23: RemoveDuplicateFiles. Return value 1.
MSI (s) (F0:2C) [22:08:23:750]: Note: 1: 2205 2: 3: RemoveFile
MSI (s) (F0:2C) [22:08:23:750]: Note: 1: 2205 2: 3: RemoveFile
Action start 22:08:23: RemoveFiles.
MSI (s) (F0:2C) [22:08:23:750]: Doing action: RemoveFolders
Action ended 22:08:23: RemoveFiles. Return value 0.
Action start 22:08:23: RemoveFolders.
MSI (s) (F0:2C) [22:08:23:750]: Doing action: CreateFolders
Action ended 22:08:23: RemoveFolders. Return value 1.
Action start 22:08:23: CreateFolders.
MSI (s) (F0:2C) [22:08:23:750]: Doing action: MoveFiles
Action ended 22:08:23: CreateFolders. Return value 1.
Action start 22:08:23: MoveFiles.
MSI (s) (F0:2C) [22:08:23:765]: Doing action: InstallFiles
Action ended 22:08:23: MoveFiles. Return value 1.
Action start 22:08:23: InstallFiles.
MSI (s) (F0:2C) [22:08:23:765]: Note: 1: 2205 2: 3: Patch
MSI (s) (F0:2C) [22:08:23:765]: Note: 1: 2228 2: 3: Patch 4: SELECT `Patch`.`File_`, `Patch`.`Header`, `Patch`.`Attributes`, `Patch`.`Sequence`, `Patch`.`StreamRef_` FROM `Patch` WHERE `Patch`.`File_` = ? AND `Patch`.`#_MsiActive`=? ORDER BY `Patch`.`Sequence`
MSI (s) (F0:2C) [22:08:23:765]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (F0:2C) [22:08:23:765]: Note: 1: 2228 2: 3: MsiPatchHeaders 4: SELECT `Header` FROM `MsiPatchHeaders` WHERE `StreamRef` = ?
MSI (s) (F0:2C) [22:08:23:765]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (F0:2C) [22:08:23:765]: Doing action: PatchFiles
Action ended 22:08:23: InstallFiles. Return value 1.
MSI (s) (F0:2C) [22:08:23:765]: Note: 1: 2205 2: 3: Patch
MSI (s) (F0:2C) [22:08:23:765]: Note: 1: 2228 2: 3: Patch 4: SELECT `File`,`FileName`,`FileSize`,`Directory_`,`PatchSize`,`File`.`Attributes`,`Patch`.`Attributes`,`Patch`.`Sequence`,`Component`.`Component`,`Component`.`ComponentId` FROM `File`,`Component`,`Patch` WHERE `Patch`.`#_MsiActive`=? AND `File`=`File_` AND `Component`=`Component_` ORDER BY `Patch`.`Sequence`
Action start 22:08:23: PatchFiles.
MSI (s) (F0:2C) [22:08:23:781]: Doing action: DuplicateFiles
Action ended 22:08:23: PatchFiles. Return value 0.
Action start 22:08:23: DuplicateFiles.
MSI (s) (F0:2C) [22:08:23:781]: Doing action: BindImage
Action ended 22:08:23: DuplicateFiles. Return value 1.
Action start 22:08:23: BindImage.
MSI (s) (F0:2C) [22:08:23:781]: Doing action: CreateShortcuts
Action ended 22:08:23: BindImage. Return value 1.
Action start 22:08:23: CreateShortcuts.
MSI (s) (F0:2C) [22:08:23:781]: Doing action: RegisterClassInfo
Action ended 22:08:23: CreateShortcuts. Return value 1.
Action start 22:08:23: RegisterClassInfo.
MSI (s) (F0:2C) [22:08:23:781]: Doing action: RegisterExtensionInfo
Action ended 22:08:23: RegisterClassInfo. Return value 1.
MSI (s) (F0:2C) [22:08:23:781]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:08:23: RegisterExtensionInfo.
MSI (s) (F0:2C) [22:08:23:781]: Doing action: RegisterProgIdInfo
Action ended 22:08:23: RegisterExtensionInfo. Return value 1.
MSI (s) (F0:2C) [22:08:23:781]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:08:23: RegisterProgIdInfo.
MSI (s) (F0:2C) [22:08:23:796]: Doing action: RegisterMIMEInfo
Action ended 22:08:23: RegisterProgIdInfo. Return value 1.
MSI (s) (F0:2C) [22:08:23:796]: Note: 1: 2262 2: MIME 3: -2147287038
MSI (s) (F0:2C) [22:08:23:796]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:08:23: RegisterMIMEInfo.
MSI (s) (F0:2C) [22:08:23:796]: Doing action: WriteRegistryValues
Action ended 22:08:23: RegisterMIMEInfo. Return value 1.
Action start 22:08:23: WriteRegistryValues.
MSI (s) (F0:2C) [22:08:23:843]: Doing action: WriteIniValues
Action ended 22:08:23: WriteRegistryValues. Return value 1.
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2205 2: 3: IniFile
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2228 2: 3: IniFile 4: SELECT `FileName`,`IniFile`.`DirProperty`,`Section`,`IniFile`.`Key`,`IniFile`.`Value`,`IniFile`.`Action` FROM `IniFile`, `Component` WHERE `Component`=`Component_` AND (`Component`.`Action`=1 OR `Component`.`Action`=2) ORDER BY `FileName`,`Section`
Action start 22:08:23: WriteIniValues.
MSI (s) (F0:2C) [22:08:23:859]: Doing action: WriteEnvironmentStrings
Action ended 22:08:23: WriteIniValues. Return value 1.
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2205 2: 3: Environment
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2228 2: 3: Environment 4: SELECT `Name`,`Value` FROM `Environment`,`Component` WHERE `Component_`=`Component` AND (`Component`.`Action` = 1 OR `Component`.`Action` = 2)
Action start 22:08:23: WriteEnvironmentStrings.
MSI (s) (F0:2C) [22:08:23:859]: Doing action: RegisterFonts
Action ended 22:08:23: WriteEnvironmentStrings. Return value 1.
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2205 2: 3: Font
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2228 2: 3: Font 4: SELECT `FontTitle`, `FileName`, `Directory_`, `Action` From `Font`, `FileAction` Where `Font`.`File_` = `FileAction`.`File` And (`FileAction`.`Action` = 1 Or `FileAction`.`Action` = 2) ORDER BY `FileAction`.`Directory_`
Action start 22:08:23: RegisterFonts.
MSI (s) (F0:2C) [22:08:23:859]: Doing action: InstallODBC
Action ended 22:08:23: RegisterFonts. Return value 1.
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2711 2: ODBCDriverManager
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2711 2: ODBCDriverManager64
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCDriver`, `File`, `Component` WHERE `File_` = `File` AND `ODBCDriver`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCDriver`, `File`, `Component` WHERE `File_` = `File` AND `ODBCDriver`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCTranslator`, `File`, `Component` WHERE `File_` = `File` AND `ODBCTranslator`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCTranslator`, `File`, `Component` WHERE `File_` = `File` AND `ODBCTranslator`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND (`Component`.`Action` = 1 OR `Component`.`Action` = 2) AND `BinaryType` = ?
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND (`Component`.`Action` = 1 OR `Component`.`Action` = 2) AND `BinaryType` = ?
Action start 22:08:23: InstallODBC.
MSI (s) (F0:2C) [22:08:23:859]: Doing action: RegisterTypeLibraries
Action ended 22:08:23: InstallODBC. Return value 0.
Action start 22:08:23: RegisterTypeLibraries.
MSI (s) (F0:2C) [22:08:23:859]: Doing action: SelfRegModules
Action ended 22:08:23: RegisterTypeLibraries. Return value 1.
Action start 22:08:23: SelfRegModules.
MSI (s) (F0:2C) [22:08:23:859]: Doing action: RegisterComPlus
Action ended 22:08:23: SelfRegModules. Return value 1.
MSI (s) (F0:2C) [22:08:23:859]: Note: 1: 2205 2: 3: Complus
MSI (s) (F0:2C) [22:08:23:875]: Note: 1: 2228 2: 3: Complus 4: SELECT `ComponentId`, `FileName`, `Component`.`Directory_`, `ExpType`, `Component`.`Action`, `Component`.`Installed` FROM `Complus`, `Component`, `File` WHERE `Complus`.`Component_` = `Component` AND `Component`.`KeyPath` = `File`.`File` AND (`Action` = 1 OR `Action` = 2)
Action start 22:08:23: RegisterComPlus.
MSI (s) (F0:2C) [22:08:23:875]: Doing action: InstallServices
Action ended 22:08:23: RegisterComPlus. Return value 0.
MSI (s) (F0:2C) [22:08:23:875]: Detected older ServiceInstall table schema
MSI (s) (F0:2C) [22:08:23:875]: Note: 1: 2205 2: 3: ServiceInstall
MSI (s) (F0:2C) [22:08:23:875]: Note: 1: 2228 2: 3: ServiceInstall 4: SELECT `Name`,`DisplayName`,`ServiceType`,`StartType`,`ErrorControl`,`LoadOrderGroup`,`Dependencies`,`StartName`,`Password`,`ComponentId`,`Directory_`,`FileName`,`Arguments` FROM `ServiceInstall`, `Component`, `File` WHERE `ServiceInstall`.`Component_` = `Component`.`Component` AND (`Component`.`KeyPath` = `File`.`File`) AND (`Action` = 1 OR `Action` = 2)
Action start 22:08:23: InstallServices.
MSI (s) (F0:2C) [22:08:23:875]: Doing action: StartServices
Action ended 22:08:23: InstallServices. Return value 1.
MSI (s) (F0:2C) [22:08:23:875]: Note: 1: 2205 2: 3: ServiceControl
MSI (s) (F0:2C) [22:08:23:875]: Note: 1: 2228 2: 3: ServiceControl 4: SELECT `Name`,`Wait`,`Arguments`,`Event`, `Action` FROM `ServiceControl`, `Component` WHERE `Component_` = `Component` AND (`Action` = 0 OR `Action` = 1 OR `Action` = 2)
Action start 22:08:23: StartServices.
MSI (s) (F0:2C) [22:08:23:875]: Doing action: RegisterUser
Action ended 22:08:23: StartServices. Return value 1.
Action start 22:08:23: RegisterUser.
MSI (s) (F0:2C) [22:08:23:875]: Doing action: RegisterProduct
Action ended 22:08:23: RegisterUser. Return value 1.
Action start 22:08:23: RegisterProduct.
MSI (s) (F0:2C) [22:08:23:875]: PROPERTY CHANGE: Adding ProductToBeRegistered property. Its value is '1'.
MSI (s) (F0:2C) [22:08:23:875]: Doing action: PublishComponents
Action ended 22:08:23: RegisterProduct. Return value 1.
MSI (s) (F0:2C) [22:08:23:890]: Note: 1: 2262 2: PublishComponent 3: -2147287038
Action start 22:08:23: PublishComponents.
MSI (s) (F0:2C) [22:08:23:890]: Doing action: MsiPublishAssemblies
Action ended 22:08:23: PublishComponents. Return value 1.
Action start 22:08:23: MsiPublishAssemblies.
MSI (s) (F0:2C) [22:08:23:890]: Doing action: PublishFeatures
Action ended 22:08:23: MsiPublishAssemblies. Return value 1.
Action start 22:08:23: PublishFeatures.
MSI (s) (F0:2C) [22:08:23:890]: Doing action: PublishProduct
Action ended 22:08:23: PublishFeatures. Return value 1.
Action start 22:08:23: PublishProduct.
MSI (s) (F0:2C) [22:08:23:890]: Doing action: InstallFinalize
Action ended 22:08:23: PublishProduct. Return value 1.
MSI (s) (F0:2C) [22:08:23:906]: Running Script: C:\WINDOWS\Installer\MSI1B3.tmp
MSI (s) (F0:2C) [22:08:23:906]: PROPERTY CHANGE: Adding UpdateStarted property. Its value is '1'.
MSI (s) (F0:2C) [22:08:23:906]: Machine policy value 'DisableRollback' is 0
MSI (s) (F0:2C) [22:08:23:906]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (F0:2C) [22:08:23:921]: Executing op: Header(Signature=1397708873,Version=301,Timestamp=896512268,LangId=1033,Platform=0,ScriptType=1,ScriptMajorVersion=21,ScriptMinorVersion=4,ScriptAttributes=1)
Action start 22:08:23: InstallFinalize.
MSI (s) (F0:2C) [22:08:23:921]: Executing op: ProductInfo(ProductKey={37477865-A3F1-4772-AD43-AAFC6BCFF99F},ProductName=MSXML 4.0 SP2 (KB927978),PackageName=msxml.msi,Language=1033,Version=68429425,Assignment=1,ObsoleteArg=0,,,PackageCode={2B27DCD9-53FA-4885-B6CD-698623819F4C},,,InstanceType=0,LUASetting=0,RemoteURTInstalls=0)
MSI (s) (F0:2C) [22:08:23:921]: Executing op: DialogInfo(Type=0,Argument=1033)
MSI (s) (F0:2C) [22:08:23:937]: Executing op: DialogInfo(Type=1,Argument=MSXML 4.0 SP2 (KB927978))
MSI (s) (F0:2C) [22:08:23:937]: Executing op: RollbackInfo(,RollbackAction=Rollback,RollbackDescription=Rolling back action:,RollbackTemplate=[1],CleanupAction=RollbackCleanup,CleanupDescription=Removing backup files,CleanupTemplate=File: [1])
MSI (s) (F0:2C) [22:08:23:937]: Executing op: SetBaseline(Baseline=0,)
MSI (s) (F0:2C) [22:08:23:937]: Executing op: SetBaseline(Baseline=1,)
MSI (s) (F0:2C) [22:08:23:937]: Executing op: ActionStart(Name=ProcessComponents,Description=Updating component registration,)
MSI (s) (F0:2C) [22:08:23:937]: Executing op: ProgressTotal(Total=5,Type=1,ByteEquivalent=24000)
MSI (s) (F0:2C) [22:08:23:937]: Executing op: ComponentUnregister(ComponentId={E9BC82F6-AC0E-407C-8666-619D6D60DF2B},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (F0:2C) [22:08:23:937]: Note: 1: 1402 2: UNKNOWN\Components\6F28CB9EE0CAC704686616D9D606FDB2 3: 2
MSI (s) (F0:2C) [22:08:23:937]: Note: 1: 1402 2: UNKNOWN\Components\6F28CB9EE0CAC704686616D9D606FDB2 3: 2
MSI (s) (F0:2C) [22:08:23:937]: Executing op: ComponentUnregister(ComponentId={81754FFD-DA2B-49C6-9447-E1C1E1733BB6},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (F0:2C) [22:08:23:937]: Note: 1: 1402 2: UNKNOWN\Components\DFF45718B2AD6C9449741E1C1E37B36B 3: 2
MSI (s) (F0:2C) [22:08:23:937]: Note: 1: 1402 2: UNKNOWN\Components\DFF45718B2AD6C9449741E1C1E37B36B 3: 2
MSI (s) (F0:2C) [22:08:23:937]: Executing op: ComponentUnregister(ComponentId={5E6714E1-EA46-4B0F-B479-06D87058DC74},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (F0:2C) [22:08:23:937]: Note: 1: 1402 2: UNKNOWN\Components\1E4176E564AEF0B44B97608D0785CD47 3: 2
MSI (s) (F0:2C) [22:08:23:937]: Note: 1: 1402 2: UNKNOWN\Components\1E4176E564AEF0B44B97608D0785CD47 3: 2
MSI (s) (F0:2C) [22:08:23:937]: Executing op: ComponentUnregister(ComponentId={57E0F99D-E884-4BD0-B8CB-803CF9EA2066},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (F0:2C) [22:08:23:937]: Note: 1: 1402 2: UNKNOWN\Components\D99F0E75488E0DB48BBC08C39FAE0266 3: 2
MSI (s) (F0:2C) [22:08:23:937]: Note: 1: 1402 2: UNKNOWN\Components\D99F0E75488E0DB48BBC08C39FAE0266 3: 2
MSI (s) (F0:2C) [22:08:23:937]: Executing op: ComponentUnregister(ComponentId={C763CD13-6E1E-4166-8C78-D274B266E9B6},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (F0:2C) [22:08:23:937]: Note: 1: 1402 2: UNKNOWN\Components\31DC367CE1E66614C8872D472B669E6B 3: 2
MSI (s) (F0:2C) [22:08:23:937]: Note: 1: 1402 2: UNKNOWN\Components\31DC367CE1E66614C8872D472B669E6B 3: 2
MSI (s) (F0:2C) [22:08:23:937]: Executing op: ProgressTotal(Total=14,Type=1,ByteEquivalent=24000)
MSI (s) (F0:2C) [22:08:23:937]: Executing op: ComponentRegister(ComponentId={4075CDF6-D88F-4F57-AF1A-29A124755695},KeyPath=c:\Program Files\MSXML 4.0\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:937]: Executing op: ComponentRegister(ComponentId={D21D9CCD-C3FA-4D72-982F-C29A2DE361EC},KeyPath=02:\Software\Microsoft\Updates\MSXML4SP2\Q927978\Description,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:937]: Executing op: ComponentRegister(ComponentId={4B1F71A7-50C6-44B7-A3AD-B6C3574BB896},KeyPath=c:\WINDOWS\system32\msxml4.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:953]: Executing op: ComponentRegister(ComponentId={62846705-2671-4547-AB45-854DCC93B3C7},KeyPath=c:\WINDOWS\system32\msxml4r.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:953]: Executing op: ComponentRegister(ComponentId={3AAE95CD-F592-46E7-89A1-9B56717C4413},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:953]: Executing op: ComponentRegister(ComponentId={CCF8B6EF-5FB9-4DE1-A276-683008BA3485},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:953]: Executing op: ComponentRegister(ComponentId={7B2FCEFF-0F22-B7E1-A06B-D6B9ABF34537},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:953]: Executing op: ComponentRegister(ComponentId={7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\downlevel_manifest\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:953]: Executing op: ComponentRegister(ComponentId={7B2FCEFF-0F22-B7E1-B06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\downlevel_payload\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:968]: Executing op: ComponentRegister(ComponentId={DA6654F6-456F-3658-A06B-D6B9ABF34537},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:968]: Executing op: ComponentRegister(ComponentId={DA6654F6-456F-3658-C06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\downlevel_manifest\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:968]: Executing op: ComponentRegister(ComponentId={DA6654F6-456F-3658-B06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\downlevel_payload\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:968]: Executing op: ComponentRegister(ComponentId={0E9F98FC-A692-A6DF-A06B-D6B9ABF34537},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:968]: Executing op: ComponentRegister(ComponentId={0E9F98FC-A692-A6DF-C06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\downlevel_manifest\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:968]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (F0:2C) [22:08:23:968]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:968]: Executing op: ProgressTick()
MSI (s) (F0:2C) [22:08:23:968]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (F0:2C) [22:08:23:968]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:968]: Executing op: ProgressTick()
MSI (s) (F0:2C) [22:08:23:968]: Executing op: ActionStart(Name=RemoveODBC,Description=Removing ODBC components,)
MSI (s) (F0:2C) [22:08:23:968]: Executing op: ODBCDriverManager(,BinaryType=0)
MSI (s) (F0:2C) [22:08:23:968]: Executing op: ODBCDriverManager(,BinaryType=1)
MSI (s) (F0:2C) [22:08:23:968]: Executing op: ActionStart(Name=CreateFolders,Description=Creating folders,Template=Folder: [1])
MSI (s) (F0:2C) [22:08:23:968]: Executing op: FolderCreate(Folder=c:\Program Files\MSXML 4.0\,Foreign=0,)
MSI (s) (F0:2C) [22:08:23:984]: Executing op: ActionStart(Name=InstallFiles,Description=Copying new files,Template=File: [1], Directory: [9], Size: [6])
MSI (s) (F0:2C) [22:08:24:000]: Executing op: ProgressTotal(Total=2521072,Type=0,ByteEquivalent=1)
MSI (s) (F0:2C) [22:08:24:000]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\system32\)
MSI (s) (F0:2C) [22:08:24:000]: Executing op: SetSourceFolder(Folder=1\System\)
MSI (s) (F0:2C) [22:08:24:000]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,MediaCabinet=XML_Core.cab,BytesPerTick=32768,CopierType=2,ModuleFileName=c:\WINDOWS\Installer\1459a2f.msi,,,,,IsFirstPhysicalMedia=1)
MSI (s) (F0:2C) [22:08:24:000]: Executing op: FileCopy(SourceName=msxml4.dll,SourceCabKey=msxml4.dll.246EB7AD_459A_4FA8_83D1_41A46D7634B7,DestName=msxml4.dll,Attributes=512,FileSize=1245696,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,Version=4.20.9841.0,Language=0,InstallMode=58982400,,,,,,,)
MSI (s) (F0:2C) [22:08:24:000]: File: c:\WINDOWS\system32\msxml4.dll; Overwrite; Won't patch; Existing file is a lower version
MSI (s) (F0:2C) [22:08:24:000]: Source for file 'msxml4.dll.246EB7AD_459A_4FA8_83D1_41A46D7634B7' is compressed
MSI (s) (F0:2C) [22:08:24:000]: Re-applying security from existing file.
MSI (s) (F0:2C) [22:08:24:015]: Verifying accessibility of file: msxml4.dll
MSI (s) (F0:2C) [22:08:24:031]: SOFTWARE RESTRICTION POLICY: Verifying object --> 'c:\WINDOWS\Installer\1459a2f.msi' against software restriction policy
MSI (s) (F0:2C) [22:08:24:031]: SOFTWARE RESTRICTION POLICY: c:\WINDOWS\Installer\1459a2f.msi has a digital signature
MSI (s) (F0:2C) [22:08:24:171]: SOFTWARE RESTRICTION POLICY: c:\WINDOWS\Installer\1459a2f.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (F0:2C) [22:08:24:171]: Note: 1: 2318 2: c:\WINDOWS\system32\msxml4.dll
MSI (s) (F0:2C) [22:08:24:171]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:171]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:171]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:171]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:171]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:171]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:171]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:171]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:171]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:187]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:203]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:218]: Executing op: FileCopy(SourceName=msxml4r.dll,SourceCabKey=msxml4r.dll.246EB7AD_459A_4FA8_83D1_41A46D7634B7,DestName=msxml4r.dll,Attributes=512,FileSize=82432,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,Version=4.10.9404.0,Language=1033,InstallMode=58982400,,,,,,,)
MSI (s) (F0:2C) [22:08:24:218]: File: c:\WINDOWS\system32\msxml4r.dll; Won't Overwrite; Won't patch; Existing file is of an equal version
MSI (s) (F0:2C) [22:08:24:218]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\Manifests\)
MSI (s) (F0:2C) [22:08:24:218]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\manifest\|Windows\winsxs\Manifests\)
MSI (s) (F0:2C) [22:08:24:218]: Executing op: FileCopy(SourceName=xl34x2va.rt8|x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest,SourceCabKey=manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537,DestName=x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest,,FileSize=3973,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-85909274,HashPart2=-393638470,HashPart3=495071453,HashPart4=945762879,,)
MSI (s) (F0:2C) [22:08:24:218]: File: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest; To be installed; Won't patch; No existing file
MSI (s) (F0:2C) [22:08:24:218]: Source for file 'manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537' is compressed
MSI (s) (F0:2C) [22:08:24:218]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest
MSI (s) (F0:2C) [22:08:24:234]: Executing op: FileCopy(SourceName=yl34x2va.rt8|x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat,SourceCabKey=catalog.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537,DestName=x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat,,FileSize=8347,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1679697816,HashPart2=1808584787,HashPart3=1425912084,HashPart4=629236904,,)
MSI (s) (F0:2C) [22:08:24:234]: File: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat; To be installed; Won't patch; No existing file
MSI (s) (F0:2C) [22:08:24:234]: Source for file 'catalog.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537' is compressed
MSI (s) (F0:2C) [22:08:24:234]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat
MSI (s) (F0:2C) [22:08:24:234]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\)
MSI (s) (F0:2C) [22:08:24:234]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\tl34x2va.rt8\)
MSI (s) (F0:2C) [22:08:24:234]: Executing op: FileCopy(SourceName=1m34x2va.rt8|msxml4.dll,SourceCabKey=msxml4.dll.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537,DestName=msxml4.dll,,FileSize=1245696,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,Version=4.20.9841.0,Language=0,InstallMode=58982400,,,,,,,)
MSI (s) (F0:2C) [22:08:24:234]: File: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\msxml4.dll; To be installed; Won't patch; No existing file
MSI (s) (F0:2C) [22:08:24:234]: Source for file 'msxml4.dll.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537' is compressed
MSI (s) (F0:2C) [22:08:24:250]: Note: 1: 2318 2: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\msxml4.dll
MSI (s) (F0:2C) [22:08:24:250]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:250]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:250]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:250]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:250]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:250]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:250]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:250]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:250]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:250]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:250]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:265]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:281]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:281]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:281]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:281]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:281]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:281]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:281]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:281]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:281]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:281]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:281]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:281]: Note: 1: 2360
MSI (s) (F0:2C) [22:08:24:296]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\Manifests\)
MSI (s) (F0:2C) [22:08:24:296]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\manifest\|Windows\winsxs\Manifests\)
MSI (s) (F0:2C) [22:08:24:296]: Executing op: FileCopy(SourceName=9n0mtfut.k85|x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.manifest,SourceCabKey=manifest.DA6654F6_456F_3658_FF6B_D6B9ABF34537,DestName=x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.manifest,,FileSize=500,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-707213148,HashPart2=1938794768,HashPart3=-933075776,HashPart4=-843550219,,)
MSI (s) (F0:2C) [22:08:24:296]: File: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.manifest; Won't Overwrite; Won't patch; Existing file is unversioned and unmodified - hash matches source file
MSI (s) (F0:2C) [22:08:24:296]: Executing op: FileCopy(SourceName=an0mtfut.k85|x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat,SourceCabKey=catalog.DA6654F6_456F_3658_FF6B_D6B9ABF34537,DestName=x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat,,FileSize=8349,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1336197992,HashPart2=-627824155,HashPart3=82633343,HashPart4=1105156543,,)
MSI (s) (F0:2C) [22:08:24:296]: File: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat; Overwrite; Won't patch; Existing file is unversioned and unmodified - hash doesn't match source file
MSI (s) (F0:2C) [22:08:24:296]: Source for file 'catalog.DA6654F6_456F_3658_FF6B_D6B9ABF34537' is compressed
MSI (s) (F0:2C) [22:08:24:296]: Re-applying security from existing file.
MSI (s) (F0:2C) [22:08:24:359]: Verifying accessibility of file: x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat
MSI (s) (F0:2C) [22:08:24:375]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat
MSI (s) (F0:2C) [22:08:24:390]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\)
MSI (s) (F0:2C) [22:08:24:390]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\5n0mtfut.k85\)
MSI (s) (F0:2C) [22:08:24:390]: Executing op: FileCopy(SourceName=dn0mtfut.k85|msxml4r.dll,SourceCabKey=msxml4r.dll.DA6654F6_456F_3658_FF6B_D6B9ABF34537,DestName=msxml4r.dll,,FileSize=82432,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,Version=4.10.9404.0,Language=1033,InstallMode=58982400,,,,,,,)
MSI (s) (F0:2C) [22:08:24:406]: File: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\msxml4r.dll; Won't Overwrite; Won't patch; Existing file is of an equal version
MSI (s) (F0:2C) [22:08:24:406]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\)
MSI (s) (F0:2C) [22:08:24:406]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\Policies\i0r1wg7y.dqe\)
MSI (s) (F0:2C) [22:08:24:406]: Executing op: FileCopy(SourceName=l0r1wg7y.dqe|4.20.9841.0.policy,SourceCabKey=manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537,DestName=4.20.9841.0.policy,,FileSize=652,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=49613189,HashPart2=1139053242,HashPart3=-1699064514,HashPart4=-854272932,,)
MSI (s) (F0:2C) [22:08:24:406]: File: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.policy; To be installed; Won't patch; No existing file
MSI (s) (F0:2C) [22:08:24:406]: Source for file 'manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537' is compressed
MSI (s) (F0:2C) [22:08:24:406]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.policy
MSI (s) (F0:2C) [22:08:24:406]: Executing op: FileCopy(SourceName=m0r1wg7y.dqe|4.20.9841.0.cat,SourceCabKey=catalog.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537,DestName=4.20.9841.0.cat,,FileSize=8359,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-861819424,HashPart2=1423527147,HashPart3=-1146259424,HashPart4=2040409349,,)
MSI (s) (F0:2C) [22:08:24:406]: File: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.cat; To be installed; Won't patch; No existing file
MSI (s) (F0:2C) [22:08:24:406]: Source for file 'catalog.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537' is compressed
MSI (s) (F0:2C) [22:08:24:406]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.cat
MSI (s) (F0:2C) [22:08:24:406]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,MediaCabinet=XML_SDK.cab,BytesPerTick=32768,CopierType=2,ModuleFileName=c:\WINDOWS\Installer\1459a2f.msi,,,,,IsFirstPhysicalMedia=1)
MSI (s) (F0:2C) [22:08:24:406]: Executing op: CacheSizeFlush(,)
MSI (s) (F0:2C) [22:08:24:406]: Executing op: InstallProtectedFiles(AllowUI=0)
MSI (s) (F0:2C) [22:08:24:406]: Executing op: ActionStart(Name=WriteRegistryValues,Description=Writing system registry values,Template=Key: [1], Name: [2], Value: [3])
MSI (s) (F0:2C) [22:08:24:406]: Executing op: ProgressTotal(Total=112,Type=1,ByteEquivalent=13200)
MSI (s) (F0:2C) [22:08:24:406]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:406]: Executing op: RegAddValue(,Value=XML DOM Document 4.0,)
MSI (s) (F0:2C) [22:08:24:406]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:406]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:406]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=Msxml2.DOMDocument.4.0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value=XML DOM Document 4.0,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value=Msxml2.DOMDocument.4.0,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=Msxml2.DOMDocument.4.0\CLSID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value={88D969C0-F192-11D4-A65F-0040963251E5},)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value=Free Threaded XML DOM Document 4.0,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=Msxml2.FreeThreadedDOMDocument.4.0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value=Free Threaded XML DOM Document 4.0,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value=Msxml2.FreeThreadedDOMDocument.4.0,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=Msxml2.FreeThreadedDOMDocument.4.0\CLSID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value={88D969C1-F192-11D4-A65F-0040963251E5},)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value=XML Data Source Object 4.0,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(Name=ThreadingModel,Value=Apartment,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=Msxml2.DSOControl.4.0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value=XML Data Source Object 4.0,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value=Msxml2.DSOControl.4.0,)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:421]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=Msxml2.DSOControl.4.0\CLSID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value={88D969C4-F192-11D4-A65F-0040963251E5},)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value=XML HTTP 4.0,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(Name=ThreadingModel,Value=Apartment,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=Msxml2.XMLHTTP.4.0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value=XML HTTP 4.0,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value=Msxml2.XMLHTTP.4.0,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=Msxml2.XMLHTTP.4.0\CLSID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value={88D969C5-F192-11D4-A65F-0040963251E5},)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value=Server XML HTTP 4.0,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(Name=ThreadingModel,Value=Apartment,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=Msxml2.ServerXMLHTTP.4.0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value=Server XML HTTP 4.0,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value=Msxml2.ServerXMLHTTP.4.0,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=Msxml2.ServerXMLHTTP.4.0\CLSID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value={88D969C6-F192-11D4-A65F-0040963251E5},)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=CLSID\{88D969C2-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value=XML Schema Cache 4.0,)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegOpenKey(,Key=CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:437]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=Msxml2.XMLSchemaCache.4.0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value=XML Schema Cache 4.0,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value=Msxml2.XMLSchemaCache.4.0,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=Msxml2.XMLSchemaCache.4.0\CLSID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value={88D969C2-F192-11D4-A65F-0040963251E5},)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=CLSID\{88D969C3-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value=XSL Template 4.0,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=Msxml2.XSLTemplate.4.0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value=XSL Template 4.0,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value=Msxml2.XSLTemplate.4.0,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=Msxml2.XSLTemplate.4.0\CLSID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value={88D969C3-F192-11D4-A65F-0040963251E5},)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F},,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value=SAX XML Reader 4.0,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\InProcServer32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=Msxml2.SAXXMLReader.4.0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value=SAX XML Reader 4.0,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\ProgID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value=Msxml2.SAXXMLReader.4.0,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\Version,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=Msxml2.SAXXMLReader.4.0\CLSID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegAddValue(,Value={7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F},)
MSI (s) (F0:2C) [22:08:24:453]: Executing op: RegOpenKey(,Key=CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136},,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=MX XML Reader 4.0,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136}\InProcServer32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=CLSID\{88D969C8-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=MXXMLWriter 4.0,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=Msxml2.MXXMLWriter.4.0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=MXXMLWriter 4.0,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=Msxml2.MXXMLWriter.4.0,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=Msxml2.MXXMLWriter.4.0\CLSID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value={88D969C8-F192-11D4-A65F-0040963251E5},)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=CLSID\{88D969C9-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=MXHTMLWriter 4.0,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=Msxml2.MXHTMLWriter.4.0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=MXHTMLWriter 4.0,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=Msxml2.MXHTMLWriter.4.0,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=Msxml2.MXHTMLWriter.4.0\CLSID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value={88D969C9-F192-11D4-A65F-0040963251E5},)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=CLSID\{88D969CA-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=SAXAttributes 4.0,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegOpenKey(,Key=CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:468]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegOpenKey(,Key=Msxml2.SAXAttributes.4.0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(,Value=SAXAttributes 4.0,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegOpenKey(,Key=CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(,Value=Msxml2.SAXAttributes.4.0,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegOpenKey(,Key=CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegOpenKey(,Key=Msxml2.SAXAttributes.4.0\CLSID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(,Value={88D969CA-F192-11D4-A65F-0040963251E5},)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegOpenKey(,Key=CLSID\{88D969D6-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(,Value=MXNamespaceManager 4.0,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegOpenKey(,Key=CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegOpenKey(,Key=Msxml2.MXNamespaceManager.4.0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(,Value=MXNamespaceManager 4.0,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegOpenKey(,Key=CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(,Value=Msxml2.MXNamespaceManager.4.0,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegOpenKey(,Key=CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegOpenKey(,Key=Msxml2.MXNamespaceManager.4.0\CLSID,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(,Value={88D969D6-F192-11D4-A65F-0040963251E5},)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Updates\MSXML4SP2\Q927978,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(Name=Description,Value=FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(Name=InstalledDate,Value=11/15/2006,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(Name=InstalledBy,Value=DEONNA WALKER,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(Name=IsInstalled,Value=#1,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(Name=ServicePack,Value=#1,)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:484]: Executing op: RegAddValue(,Value=Microsoft XML, v4.0,)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0\0,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegAddValue(,,)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0\0\win32,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0\FLAGS,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegAddValue(,Value=0,)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0\HELPDIR,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegAddValue(,,)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\downlevel_payload,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegAddValue(,,)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\downlevel_manifest,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegAddValue(,,)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\downlevel_payload,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegAddValue(,,)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\downlevel_manifest,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegAddValue(,,)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\downlevel_manifest,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegAddValue(,,)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\SideBySide\PatchedComponents,,BinaryType=0)
MSI (s) (F0:2C) [22:08:24:500]: Executing op: RegAddValue(Name={7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\Manifests\\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest[~]{7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Manifests\\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat[~]{7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Manifests\[~]{7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537},)
MSI (s) (F0:2C) [22:08:24:515]: Executing op: RegAddValue(Name={7B2FCEFF-0F22-B7E1-B06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\\msxml4.dll[~]{7B2FCEFF-0F22-B7E1-B06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\[~]{7B2FCEFF-0F22-B7E1-B06B-D6B9ABF34537},)
MSI (s) (F0:2C) [22:08:24:515]: Executing op: RegAddValue(Name={DA6654F6-456F-3658-C06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\Manifests\\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.manifest[~]{DA6654F6-456F-3658-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Manifests\\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat[~]{DA6654F6-456F-3658-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Manifests\[~]{DA6654F6-456F-3658-C06B-D6B9ABF34537},)
MSI (s) (F0:2C) [22:08:24:515]: Executing op: RegAddValue(Name={DA6654F6-456F-3658-B06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\\msxml4r.dll[~]{DA6654F6-456F-3658-B06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\[~]{DA6654F6-456F-3658-B06B-D6B9ABF34537},)
MSI (s) (F0:2C) [22:08:24:515]: Executing op: RegAddValue(Name={0E9F98FC-A692-A6DF-C06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\\4.20.9841.0.policy[~]{0E9F98FC-A692-A6DF-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\\4.20.9841.0.cat[~]{0E9F98FC-A692-A6DF-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\[~]{0E9F98FC-A692-A6DF-C06B-D6B9ABF34537},)
MSI (s) (F0:2C) [22:08:24:515]: Executing op: ActionStart(Name=RegisterTypeLibraries,Description=Registering type libraries,Template=LibID: [1])
MSI (s) (F0:2C) [22:08:24:515]: Executing op: TypeLibraryRegister(,,FilePath=c:\WINDOWS\system32\msxml4.dll,LibID={F5078F18-C551-11D3-89B9-0000F81FE221},Version=1024,,Language=0,,BinaryType=0,IgnoreRegistrationFailure=0)
MSI (s) (F0:2C) [22:08:24:515]: QueryPathOfRegTypeLib returned 0 in local context. Path is 'c:\WINDOWS\system32\msxml4.dll'
MSI (s) (F0:2C) [22:08:24:515]: Note: 1: 1402 2: UNKNOWN\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\400.0\0\win32 3: 2
MSI (s) (F0:2C) [22:08:24:515]: CMsiServices::ProcessTypeLibrary runs in local context, not impersonated.
MSI (s) (F0:2C) [22:08:24:578]: ProcessTypeLibraryCore returns: 0. (0 means OK)
MSI (s) (F0:2C) [22:08:24:578]: CMsiServices::ProcessTypeLibrary runs in local context, not impersonated.
MSI (s) (F0:2C) [22:08:24:578]: ProcessTypeLibraryCore returns: 0. (0 means OK)
MSI (s) (F0:2C) [22:08:24:578]: Executing op: ActionStart(Name=RegisterUser,Description=Registering user,Template=[1])
MSI (s) (F0:2C) [22:08:24:578]: Executing op: UserRegister(Owner=DEONNA WALKER,,ProductId=none)
MSI (s) (F0:2C) [22:08:24:593]: Executing op: ActionStart(Name=RegisterProduct,Description=Registering product,Template=[1])
MSI (s) (F0:2C) [22:08:24:593]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,MediaCabinet=XML_Core.cab,BytesPerTick=0,CopierType=2,ModuleFileName=c:\WINDOWS\Installer\1459a2f.msi,,,,,IsFirstPhysicalMedia=1)
MSI (s) (F0:2C) [22:08:24:593]: Executing op: DatabaseCopy(DatabasePath=c:\WINDOWS\Installer\1459a2f.msi,ProductCode={37477865-A3F1-4772-AD43-AAFC6BCFF99F},CabinetStreams=XML_Core.cab;XML_SDK.cab,,)
MSI (s) (F0:2C) [22:08:24:750]: Executing op: ProductRegister(UpgradeCode={7CE723E3-E56B-432C-9F24-78C0606045A5},VersionString=4.20.9841.0,HelpLink=http://support.microsoft.com/kb/927978,,,InstallSource=c:\59eb719a0cb67cf60067\,Publisher=Microsoft Corporation,,,,,,,,,,,,EstimatedSize=2625)
MSI (s) (F0:2C) [22:08:24:781]: Executing op: ProductCPDisplayInfoRegister()
MSI (s) (F0:2C) [22:08:24:781]: Executing op: ActionStart(Name=PublishFeatures,Description=Publishing Product Features,Template=Feature: [1])
MSI (s) (F0:2C) [22:08:24:781]: Executing op: FeaturePublish(Feature=MSXML,,Absent=2,Component=MF}e835XRAhvfl[X%h~W(s-UlQ2mt@MgogY-xd{t)
MSI (s) (F0:2C) [22:08:24:796]: Executing op: FeaturePublish(Feature=MSXMLSYS,Parent=MSXML,Absent=2,Component=V2?0@7$9*=IdbugpYRMX}GHaGLdZ==A&kv@Y~]3iui-r60O)l=Em%pCn7G4))
MSI (s) (F0:2C) [22:08:24:796]: Executing op: FeaturePublish(Feature=MSXMLSUPP2,Parent=MSXML,Absent=2,Component=?`ZsjqO[%A*`NW3OG&nR)
MSI (s) (F0:2C) [22:08:24:796]: Executing op: FeaturePublish(Feature=MSXMLSXS,Parent=MSXML,Absent=2,Component=LdCZOHqG+dpWsfdDE!j5LdCZOHqG+d6XsfdDE!j5LdCZOHqG+d%XsfdDE!j5`DM4olJ_O5pWsfdDE!j5`DM4olJ_O56XsfdDE!j5`DM4olJ_O5%XsfdDE!j5l0Rd'9?m^^pWsfdDE!j5l0Rd'9?m^^6XsfdDE!j5)
MSI (s) (F0:2C) [22:08:24:812]: Executing op: FeaturePublish(Feature=XMLSDK,,Absent=3,Component=mk`[Q=PRe?RvYBgpXHXc5~{DF_B]-@1_XLnB~RWMMvh8D]u5G@j^sM7=J&oH0G,*i]!a$9uKNVM3Kykc)
MSI (s) (F0:2C) [22:08:24:812]: Executing op: ActionStart(Name=PublishProduct,Description=Publishing product information,)
MSI (s) (F0:2C) [22:08:24:812]: Executing op: IconCreate(Icon=icon.exe,Data=BinaryData)
MSI (s) (F0:2C) [22:08:24:828]: Executing op: CleanupConfigData()
MSI (s) (F0:2C) [22:08:24:828]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\568774731F3A2774DA34AACFB6FC9FF9\Patches 3: 2
MSI (s) (F0:2C) [22:08:24:828]: Executing op: RegisterPatchOrder(Continue=0,SequenceType=1,Remove=0)
MSI (s) (F0:2C) [22:08:24:828]: Note: 1: 1402 2: UNKNOWN\Products\568774731F3A2774DA34AACFB6FC9FF9\Patches 3: 2
MSI (s) (F0:2C) [22:08:24:843]: Executing op: ProductPublish(PackageKey={2B27DCD9-53FA-4885-B6CD-698623819F4C})
MSI (s) (F0:2C) [22:08:24:843]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F0:2C) [22:08:24:843]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F0:2C) [22:08:24:843]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F0:2C) [22:08:24:843]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F0:2C) [22:08:24:843]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F0:2C) [22:08:24:843]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F0:2C) [22:08:24:843]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F0:2C) [22:08:24:843]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F0:2C) [22:08:24:843]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F0:2C) [22:08:24:843]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F0:2C) [22:08:24:843]: Executing op: UpgradeCodePublish(UpgradeCode={7CE723E3-E56B-432C-9F24-78C0606045A5})
MSI (s) (F0:2C) [22:08:24:843]: Executing op: SourceListPublish(,,,,NumberOfDisks=2)
MSI (s) (F0:2C) [22:08:24:843]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9\SourceList 3: 2
MSI (s) (F0:2C) [22:08:24:859]: Executing op: ProductPublishClient(,,)
MSI (s) (F0:2C) [22:08:24:859]: Executing op: SourceListRegisterLastUsed(SourceProduct={37477865-A3F1-4772-AD43-AAFC6BCFF99F},LastUsedSource=c:\59eb719a0cb67cf60067\)
MSI (s) (F0:2C) [22:08:24:859]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (F0:2C) [22:08:24:859]: Specifed source is already in a list.
MSI (s) (F0:2C) [22:08:24:859]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (F0:2C) [22:08:24:859]: Machine policy value 'DisableBrowse' is 0
MSI (s) (F0:2C) [22:08:24:859]: Machine policy value 'AllowLockdownBrowse' is 0
MSI (s) (F0:2C) [22:08:24:859]: Adding new sources is allowed.
MSI (s) (F0:2C) [22:08:24:859]: Set LastUsedSource to: c:\59eb719a0cb67cf60067\.
MSI (s) (F0:2C) [22:08:24:859]: Set LastUsedType to: n.
MSI (s) (F0:2C) [22:08:24:859]: Set LastUsedIndex to: 1.
MSI (s) (F0:2C) [22:08:24:859]: Executing op: End(Checksum=0,ProgressTotalHDWord=0,ProgressTotalLDWord=4481872)
MSI (s) (F0:2C) [22:08:24:859]: User policy value 'DisableRollback' is 0
MSI (s) (F0:2C) [22:08:24:859]: Machine policy value 'DisableRollback' is 0
MSI (s) (F0:2C) [22:08:24:921]: No System Restore sequence number for this installation.
MSI (s) (F0:2C) [22:08:24:921]: Unlocking Server
MSI (s) (F0:2C) [22:08:24:921]: PROPERTY CHANGE: Deleting UpdateStarted property. Its current value is '1'.
MSI (s) (F0:2C) [22:08:24:921]: Skipping action: SxsUninstallCA (condition is false)
MSI (s) (F0:2C) [22:08:24:921]: Doing action: RemoveExistingProducts
Action ended 22:08:24: InstallFinalize. Return value 1.
Action start 22:08:24: RemoveExistingProducts.
Action ended 22:08:24: RemoveExistingProducts. Return value 1.
Action ended 22:08:24: INSTALL. Return value 1.
Property(S): ProductName = MSXML 4.0 SP2 (KB927978)
Property(S): ProductCode = {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
Property(S): Manufacturer = Microsoft Corporation
Property(S): ProductVersion = 4.20.9841.0
Property(S): ProductLanguage = 1033
Property(S): BannerBitmap = bannrbmp
Property(S): IAgree = No
Property(S): ProductID = none
Property(S): ARPHELPLINK = http://support.microsoft.com/kb/927978
Property(S): ButtonText_Back = < &Back
Property(S): ButtonText_Browse = Br&owse
Property(S): ButtonText_Cancel = Cancel
Property(S): ButtonText_Exit = &Exit
Property(S): ButtonText_Finish = &Finish
Property(S): ButtonText_Ignore = &Ignore
Property(S): ButtonText_Install = &Install
Property(S): ButtonText_InstallNow = &Install Now
Property(S): ButtonText_Next = &Next >
Property(S): ButtonText_No = &No
Property(S): ButtonText_OK = OK
Property(S): ButtonText_Remove = &Remove
Property(S): ButtonText_Reset = &Reset
Property(S): ButtonText_Resume = &Resume
Property(S): ButtonText_Retry = &Retry
Property(S): ButtonText_Return = &Return
Property(S): ButtonText_Yes = &Yes
Property(S): CompleteSetupIcon = completi
Property(S): CustomSetupIcon = custicon
Property(S): DialogBitmap = dlgbmp
Property(S): DlgTitleFont = {&DlgFontBold8}
Property(S): ExclamationIcon = exclamic
Property(S): InfoIcon = info
Property(S): InstallerIcon = insticon
Property(S): INSTALLLEVEL = 3
Property(S): InstallModeTxt_1 = Custom
Property(S): InstallModeVal = InstallModeTxt_1
Property(S): InstallModeTxt_2 = Complete
Property(S): InstallModeTxt_3 = Server Image
Property(S): InstallModeTxt_4 = Change
Property(S): InstallModeTxt_5 = Repair
Property(S): InstallModeTxt_6 = Remove
Property(S): PIDTemplate = 12345<###-%%%%%%%>@@@@@
Property(S): Progress1Txt_1 = Installing
Property(S): Progress1 = Progress1Txt_1
Property(S): Progress2Txt_1 = installs
Property(S): Progress2 = Progress2Txt_1
Property(S): Progress1Txt_2 = Changing
Property(S): Progress2Txt_2 = changes
Property(S): Progress1Txt_3 = Repairing
Property(S): Progress2Txt_3 = repairs
Property(S): Progress1Txt_4 = Removing
Property(S): Progress2Txt_4 = removes
Property(S): PROMPTROLLBACKCOST = P
Property(S): RemoveIcon = removico
Property(S): RepairIcon = repairic
Property(S): Setup = Setup
Property(S): Wizard = Setup Wizard
Property(S): DefaultUIFont = DlgFont8
Property(S): ErrorDialog = ErrorDlg
Property(S): TARGETDIR = c:\
Property(S): USERNAME = DEONNA WALKER
Property(S): APPS_TEST = 1
Property(S): VersionNT = 501
Property(S): SecureCustomProperties = MSXML4SP2
Property(S): UpgradeCode = {7CE723E3-E56B-432C-9F24-78C0606045A5}
Property(S): ALLUSERS = 1
Property(S): WINHTTP_51 = WinHttpRequest Component version 5.1
Property(S): MSXML = c:\Program Files\MSXML 4.0\
Property(S): SourceDir = c:\59eb719a0cb67cf60067\
Property(S): DesktopFolder = c:\Documents and Settings\All Users\Desktop\
Property(S): ProgramFilesFolder = c:\Program Files\
Property(S): ProductState = -1
Property(S): PackageCode = {2B27DCD9-53FA-4885-B6CD-698623819F4C}
Property(S): SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 = c:\WINDOWS\system32\
Property(S): SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 = c:\WINDOWS\system32\
Property(S): SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB = c:\WINDOWS\system32\
Property(S): WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\
Property(S): payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\
Property(S): payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
Property(S): WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Manifests\
Property(S): WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\
Property(S): SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\system32\
Property(S): WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\
Property(S): policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\
Property(S): policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
Property(S): WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\
Property(S): payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\
Property(S): payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
Property(S): WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Manifests\
Property(S): WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\
Property(S): SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\system32\
Property(S): WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\
Property(S): policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\
Property(S): policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
Property(S): WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\
Property(S): payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa6920e9f98fc\
Property(S): WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\
Property(S): policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\
Property(S): WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\
Property(S): SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\system32\
Property(S): WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Manifests\
Property(S): payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
Property(S): policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
Property(S): DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Documents and Settings\All Users\Desktop\
Property(S): ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Documents and Settings\All Users\Start Menu\Programs\
Property(S): MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Documents and Settings\All Users\Start Menu\Programs\MSXML 4.0\
Property(S): DOC.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Program Files\MSXML 4.0\doc\
Property(S): LIB.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Program Files\MSXML 4.0\lib\
Property(S): INC.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Program Files\MSXML 4.0\inc\
Property(S): CommonFilesFolder = c:\Program Files\Common Files\
Property(S): MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 = c:\Program Files\Common Files\Microsoft Shared\
Property(S): MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 = c:\Program Files\Common Files\Microsoft Shared\MSDN\
Property(S): Date = 11/15/2006
Property(S): PackagecodeChanging = 1
Property(S): REBOOT = ReallySuppress
Property(S): CURRENTDIRECTORY = c:\59eb719a0cb67cf60067
Property(S): CLIENTUILEVEL = 3
Property(S): CLIENTPROCESSID = 3324
Property(S): VersionDatabase = 200
Property(S): VersionMsi = 3.01
Property(S): WindowsBuild = 2600
Property(S): ServicePackLevel = 2
Property(S): ServicePackLevelMinor = 0
Property(S): MsiNTProductType = 1
Property(S): WindowsFolder = c:\WINDOWS\
Property(S): WindowsVolume = c:\
Property(S): SystemFolder = C:\WINDOWS\system32\
Property(S): System16Folder = C:\WINDOWS\system\
Property(S): RemoteAdminTS = 1
Property(S): TempFolder = C:\WINDOWS\TEMP\
Property(S): AppDataFolder = C:\WINDOWS\system32\config\systemprofile\Application Data\
Property(S): FavoritesFolder = C:\WINDOWS\system32\config\systemprofile\Favorites\
Property(S): NetHoodFolder = C:\WINDOWS\system32\config\systemprofile\NetHood\
Property(S): PersonalFolder = C:\WINDOWS\system32\config\systemprofile\My Documents\
Property(S): PrintHoodFolder = C:\WINDOWS\system32\config\systemprofile\PrintHood\
Property(S): RecentFolder = C:\WINDOWS\system32\config\systemprofile\Recent\
Property(S): SendToFolder = C:\WINDOWS\system32\config\systemprofile\SendTo\
Property(S): TemplateFolder = C:\Documents and Settings\All Users\Templates\
Property(S): CommonAppDataFolder = C:\Documents and Settings\All Users\Application Data\
Property(S): LocalAppDataFolder = C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\
Property(S): MyPicturesFolder = C:\WINDOWS\system32\config\systemprofile\My Documents\My Pictures\
Property(S): AdminToolsFolder = C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\
Property(S): StartupFolder = C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Property(S): ProgramMenuFolder = C:\Documents and Settings\All Users\Start Menu\Programs\
Property(S): StartMenuFolder = C:\Documents and Settings\All Users\Start Menu\
Property(S): FontsFolder = C:\WINDOWS\Fonts\
Property(S): GPTSupport = 1
Property(S): OLEAdvtSupport = 1
Property(S): ShellAdvtSupport = 1
Property(S): Intel = 15
Property(S): PhysicalMemory = 959
Property(S): VirtualMemory = 2027
Property(S): AdminUser = 1
Property(S): LogonUser = SYSTEM
Property(S): UserSID = S-1-5-18
Property(S): UserLanguageID = 1033
Property(S): ComputerName = LIVINGROOM
Property(S): SystemLanguageID = 1033
Property(S): ScreenX = 1024
Property(S): ScreenY = 768
Property(S): CaptionHeight = 26
Property(S): BorderTop = 1
Property(S): BorderSide = 1
Property(S): TextHeight = 16
Property(S): ColorBits = 32
Property(S): TTCSupport = 1
Property(S): Time = 22:08:25
Property(S): MsiNetAssemblySupport = 1.1.4322.2032
Property(S): MsiWin32AssemblySupport = 5.1.2600.2180
Property(S): RedirectedDllSupport = 2
Property(S): Privileged = 1
Property(S): DATABASE = c:\WINDOWS\Installer\1459a2f.msi
Property(S): OriginalDatabase = c:\59eb719a0cb67cf60067\msxml.msi
Property(S): UILevel = 2
Property(S): ACTION = INSTALL
Property(S): ROOTDRIVE = c:\
Property(S): CostingComplete = 1
Property(S): OutOfDiskSpace = 0
Property(S): OutOfNoRbDiskSpace = 0
Property(S): PrimaryVolumeSpaceAvailable = 0
Property(S): PrimaryVolumeSpaceRequired = 0
Property(S): PrimaryVolumeSpaceRemaining = 0
Property(S): SOURCEDIR = c:\59eb719a0cb67cf60067\
Property(S): SourcedirProduct = {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
Property(S): ProductToBeRegistered = 1
MSI (s) (F0:2C) [22:08:25:046]: Note: 1: 1707
MSI (s) (F0:2C) [22:08:25:046]: Product: MSXML 4.0 SP2 (KB927978) -- Installation completed successfully.

MSI (s) (F0:2C) [22:08:25:062]: Cleaning up uninstalled install packages, if any exist
MSI (s) (F0:2C) [22:08:25:062]: MainEngineThread is returning 0
MSI (s) (F0:C0) [22:08:25:171]: Destroying RemoteAPI object.
MSI (s) (F0:60) [22:08:25:187]: Custom Action Manager thread ending.
=== Logging stopped: 11/15/2006 22:08:25 ===
MSI (c) (FC:88) [22:08:25:187]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1
MSI (c) (FC:88) [22:08:25:187]: MainEngineThread is returning 0
=== Verbose logging stopped: 11/15/2006 22:08:25 ===

And hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:00:44 AM, on 10/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\HP\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\arservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP DigitalMedia Archive\bak\DMAScheduler.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Documents and Settings\HP_Administrator\My Documents\My Pictures\avgantispy\hijackthis\imabunny.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PAVILION&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PAVILION&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Snapfish\SNAPFI~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Exif Launcher 2.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.whataboutadog.com
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1176386419203
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://ak.imgag.com/imgag/cp/install/Crusher.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.29.11/ttinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 12597 bytes

I went several days and didn't get that debug error until I came to Daniweb....so I don't know what's up with that. And the window wants to keep closing when I come to Daniweb too. Not sure if that has anything to do with what's going on or not. Thanks again for your help with this.

~DeOnna

deonnanicole
Posting Whiz in Training
253 posts since Jun 2004
Reputation Points: 18
Solved Threads: 13
 

Aw, heck.. :o
Crunchie, give deonnanicole an elephant stamp for posting the first installer log... and then delete it, maybe?
Deonna, there is no CCleaner log that I am interested in, you just run it to clean [if you use FF be sure to visit Applications tab and ensure Mozilla cookies box is checked]..... but I would have liked to see the AVG AS log.....
If you have not already run it, please run it now.
You have a trojan downloader that has replaced many of your system files with infected copies, so next...
==Please dl this file from http://noahdfear.geekstogo.com/FindAWF.exe -to your desktop, perhaps.
-option 1: dclick the .exe to start the program, select option 1 to start the process. Please post the contents of the notepad that opens.

gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
 

So sorry...lol. For some reason I thought it was the AVG anti-spyware that I had posted. Oops. :S Off to follow the last of your instructions and I will post that log here when done. Thanks again.

DeOnna

deonnanicole
Posting Whiz in Training
253 posts since Jun 2004
Reputation Points: 18
Solved Threads: 13
 

Here you go...


Find AWF report by noahdfear ©2006
Version 1.40

The current date is: Thu 10/25/2007
The current time is: 8:31:59.84


bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\HPDIGI~1\BAK

04/13/2006 12:05 PM 90,112 DMAScheduler.exe
1 File(s) 90,112 bytes

Directory of C:\PROGRA~1\MSNMES~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\PICASA2\BAK

06/15/2007 07:15 PM 366,400 PicasaMediaDetector.exe
1 File(s) 366,400 bytes

Directory of C:\PROGRA~1\REGSHAVE\BAK

02/04/2002 10:32 PM 53,248 REGSHAVE.EXE
1 File(s) 53,248 bytes

Directory of C:\PROGRA~1\WIFD1F~1\BAK

11/03/2006 07:20 PM 866,584 MSASCui.exe
1 File(s) 866,584 bytes

Directory of C:\WINDOWS\CREATOR\BAK

12/14/2004 05:23 AM 663,552 Remind_XP.exe
1 File(s) 663,552 bytes

Directory of C:\WINDOWS\EHOME\BAK

09/30/2005 12:01 AM 67,584 ehtray.exe
1 File(s) 67,584 bytes

Directory of C:\WINDOWS\SMINST\BAK

07/23/2005 01:14 AM 237,568 RECGUARD.EXE
1 File(s) 237,568 bytes

Directory of C:\PROGRA~1\GRISOFT\AVGFRE~1\BAK

09/14/2007 09:38 AM 421,888 avgcc.exe
1 File(s) 421,888 bytes

Directory of C:\PROGRA~1\HEWLET~1\HPBOOT~1\BAK

02/16/2006 01:34 AM 249,856 HPBootOp.exe
1 File(s) 249,856 bytes

Directory of C:\PROGRA~1\HP\HPSOFT~1\BAK

02/16/2005 11:11 PM 49,152 HPWuSchd2.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\YAHOO!\MESSEN~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\YAHOO!\SEARCH~1\BAK

06/08/2007 10:59 AM 224,248 SearchProtection.exe
1 File(s) 224,248 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

07/31/2006 07:16 PM 180,269 realsched.exe
1 File(s) 180,269 bytes

Directory of C:\PROGRA~1\JAVA\JRE16~2.0_0\BIN\BAK

07/12/2007 04:00 AM 132,496 jusched.exe
1 File(s) 132,496 bytes

Directory of C:\PROGRA~1\SNAPFISH\SNAPFI~1\DATA\XTRAS\BAK

01/31/2005 03:06 PM 208,896 mssysmgr.exe
1 File(s) 208,896 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

27660 Oct 3 2007 "C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
90112 Apr 13 2006 "C:\Program Files\HP DigitalMedia Archive\bak\DMAScheduler.exe"
591416 Sep 27 2007 "C:\Program Files\Picasa2\PicasaUpdate.exe"
5388088 Jun 29 2007 "C:\Documents and Settings\HP_Administrator\My Documents\picasaweb-current-setup.exe"
366400 Jun 15 2007 "C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe"
665160 Sep 27 2007 "C:\Program Files\Picasa2\cdautorun\PicasaRestore.exe"
27660 Oct 3 2007 "C:\Program Files\REGSHAVE\REGSHAVE.EXE"
53248 Feb 4 2002 "C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE"
27660 Oct 3 2007 "C:\Program Files\Windows Defender\MSASCui.exe"
866584 Nov 3 2006 "C:\Program Files\Windows Defender\bak\MSASCui.exe"
27660 Oct 3 2007 "C:\WINDOWS\CREATOR\Remind_XP.exe"
663552 Dec 14 2004 "C:\WINDOWS\CREATOR\bak\Remind_XP.exe"
64512 Aug 5 2005 "C:\WINDOWS\$NtUninstallKB908246$\ehtray.exe"
64512 Aug 5 2005 "C:\WINDOWS\ehome\ehtray.exe"
67584 Sep 30 2005 "C:\WINDOWS\ehome\bak\ehtray.exe"
27660 Oct 3 2007 "C:\WINDOWS\SMINST\RECGUARD.EXE"
237568 Jul 23 2005 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
27660 Oct 3 2007 "C:\Program Files\Grisoft\AVG Free\avgcc.exe"
421888 Sep 14 2007 "C:\Program Files\Grisoft\AVG Free\bak\avgcc.exe"
27660 Oct 3 2007 "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe"
249856 Feb 16 2006 "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe"
27660 Oct 3 2007 "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
49152 Feb 16 2005 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
27660 Oct 3 2007 "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
224248 Jun 8 2007 "C:\Program Files\Yahoo!\Search Protection\bak\SearchProtection.exe"
27660 Oct 3 2007 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"
180269 Jul 31 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
36975 Nov 10 2005 "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
49263 Nov 9 2006 "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
49263 Oct 12 2006 "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
75520 Dec 15 2006 "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
83608 Mar 14 2007 "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
27660 Oct 3 2007 "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"
27660 Oct 3 2007 "C:\Program Files\Snapfish\Snapfish PhotoShow\data\Xtras\mssysmgr.exe"
208896 Jan 31 2005 "C:\Program Files\Snapfish\Snapfish PhotoShow\data\Xtras\bak\mssysmgr.exe"


end of report

deonnanicole
Posting Whiz in Training
253 posts since Jun 2004
Reputation Points: 18
Solved Threads: 13
 

Okay, deonna... you have no AVG AS log for me?
Firstly I want you to go to CP, add/remove pgms and uninstall all old versions of java [keep only 1.6.0.2], then go to C:\Program Files and delete all these folders and their contents if they exist:

C:\Program Files\Java\jre1.5.0_06
C:\Program Files\Java\jre1.5.0_10
C:\Program Files\Java\jre1.5.0_09
C:\Program Files\Java\jre1.5.0_11
C:\Program Files\Java\jre1.6.0_01

Okay, next:
-option 2, FindAWF: dclick the .exe to start the program, select to restore files, into the text file that opens paste all the text between the lines:
_____________________________________________________________
"C:\Program Files\HP DigitalMedia Archive\bak\DMAScheduler.exe"
"C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe"
"C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE"
"C:\Program Files\Windows Defender\bak\MSASCui.exe"
"C:\WINDOWS\CREATOR\bak\Remind_XP.exe"
"C:\WINDOWS\ehome\bak\ehtray.exe"
"C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
"C:\Program Files\Grisoft\AVG Free\bak\avgcc.exe"
"C:\Program Files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe"
"C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
"C:\Program Files\Yahoo!\Search Protection\bak\SearchProtection.exe"
"C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
"C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"
"C:\Program Files\Snapfish\Snapfish PhotoShow\data\Xtras\bak\mssysmgr.exe"
_____________________________________________________________

-close the text file and click Yes. Please post the contents of the notepad that opens.

gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
 

First, the AVG log:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 11:51:06 AM 10/25/2007

+ Scan result:

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP408\A0042404.exe -> Hijacker.Small : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@rotator.adjuggler[2].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@revsci[1].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@anad.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.


::Report end

Here is the other logfile you wanted:

Find AWF report by noahdfear ©2006
Version 1.40
Option 2 run successfully

The current date is: Thu 10/25/2007
The current time is: 11:00:17.53


bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\HPDIGI~1\BAK

04/13/2006 12:05 PM 90,112 DMAScheduler.exe
1 File(s) 90,112 bytes

Directory of C:\PROGRA~1\MSNMES~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\PICASA2\BAK

06/15/2007 07:15 PM 366,400 PicasaMediaDetector.exe
1 File(s) 366,400 bytes

Directory of C:\PROGRA~1\REGSHAVE\BAK

02/04/2002 10:32 PM 53,248 REGSHAVE.EXE
1 File(s) 53,248 bytes

Directory of C:\PROGRA~1\WIFD1F~1\BAK

11/03/2006 07:20 PM 866,584 MSASCui.exe
1 File(s) 866,584 bytes

Directory of C:\WINDOWS\CREATOR\BAK

12/14/2004 05:23 AM 663,552 Remind_XP.exe
1 File(s) 663,552 bytes

Directory of C:\WINDOWS\EHOME\BAK

09/30/2005 12:01 AM 67,584 ehtray.exe
1 File(s) 67,584 bytes

Directory of C:\WINDOWS\SMINST\BAK

07/23/2005 01:14 AM 237,568 RECGUARD.EXE
1 File(s) 237,568 bytes

Directory of C:\PROGRA~1\GRISOFT\AVGFRE~1\BAK

09/14/2007 09:38 AM 421,888 avgcc.exe
1 File(s) 421,888 bytes

Directory of C:\PROGRA~1\HEWLET~1\HPBOOT~1\BAK

02/16/2006 01:34 AM 249,856 HPBootOp.exe
1 File(s) 249,856 bytes

Directory of C:\PROGRA~1\HP\HPSOFT~1\BAK

02/16/2005 11:11 PM 49,152 HPWuSchd2.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\YAHOO!\MESSEN~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\YAHOO!\SEARCH~1\BAK

06/08/2007 10:59 AM 224,248 SearchProtection.exe
1 File(s) 224,248 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

07/31/2006 07:16 PM 180,269 realsched.exe
1 File(s) 180,269 bytes

Directory of C:\PROGRA~1\JAVA\JRE16~2.0_0\BIN\BAK

07/12/2007 04:00 AM 132,496 jusched.exe
1 File(s) 132,496 bytes

Directory of C:\PROGRA~1\SNAPFISH\SNAPFI~1\DATA\XTRAS\BAK

01/31/2005 03:06 PM 208,896 mssysmgr.exe
1 File(s) 208,896 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

90112 Apr 13 2006 "C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
90112 Apr 13 2006 "C:\Program Files\HP DigitalMedia Archive\bak\DMAScheduler.exe"
591416 Sep 27 2007 "C:\Program Files\Picasa2\PicasaUpdate.exe"
5388088 Jun 29 2007 "C:\Documents and Settings\HP_Administrator\My Documents\picasaweb-current-setup.exe"
366400 Jun 15 2007 "C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe"
665160 Sep 27 2007 "C:\Program Files\Picasa2\cdautorun\PicasaRestore.exe"
53248 Feb 4 2002 "C:\Program Files\REGSHAVE\REGSHAVE.EXE"
53248 Feb 4 2002 "C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE"
866584 Nov 3 2006 "C:\Program Files\Windows Defender\MSASCui.exe"
866584 Nov 3 2006 "C:\Program Files\Windows Defender\bak\MSASCui.exe"
663552 Dec 14 2004 "C:\WINDOWS\CREATOR\Remind_XP.exe"
663552 Dec 14 2004 "C:\WINDOWS\CREATOR\bak\Remind_XP.exe"
64512 Aug 5 2005 "C:\WINDOWS\$NtUninstallKB908246$\ehtray.exe"
64512 Aug 5 2005 "C:\WINDOWS\ehome\ehtray.exe"
67584 Sep 30 2005 "C:\WINDOWS\ehome\bak\ehtray.exe"
237568 Jul 23 2005 "C:\WINDOWS\SMINST\RECGUARD.EXE"
237568 Jul 23 2005 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
421888 Sep 14 2007 "C:\Program Files\Grisoft\AVG Free\avgcc.exe"
421888 Sep 14 2007 "C:\Program Files\Grisoft\AVG Free\bak\avgcc.exe"
249856 Feb 16 2006 "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe"
249856 Feb 16 2006 "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe"
49152 Feb 16 2005 "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
49152 Feb 16 2005 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
224248 Jun 8 2007 "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
224248 Jun 8 2007 "C:\Program Files\Yahoo!\Search Protection\bak\SearchProtection.exe"
180269 Jul 31 2006 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"
180269 Jul 31 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
36975 Nov 10 2005 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc1.0_06\bin\jusched.exe"
49263 Nov 9 2006 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc2.0_10\bin\jusched.exe"
49263 Oct 12 2006 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc3.0_09\bin\jusched.exe"
75520 Dec 15 2006 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc4.0_11\bin\jusched.exe"
132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"
208896 Jan 31 2005 "C:\Program Files\Snapfish\Snapfish PhotoShow\data\Xtras\mssysmgr.exe"
208896 Jan 31 2005 "C:\Program Files\Snapfish\Snapfish PhotoShow\data\Xtras\bak\mssysmgr.exe"


end of report

I followed your other instructions also about deleting the folders and programs.

~DeOnna

deonnanicole
Posting Whiz in Training
253 posts since Jun 2004
Reputation Points: 18
Solved Threads: 13
 

DeOnna, for some reason [not your fault, it's the trojan...] that operation did not fully work, so please repeat option2 with the same block of entries [repeated below]
[We are trying to copy the original files back into their proper locations, overwriting the affected files.]
So:
-option 2, FindAWF: dclick the .exe to start the program, select to restore files, into the text file that opens paste all the text between the lines:
_____________________________________________________________
"C:\Program Files\HP DigitalMedia Archive\bak\DMAScheduler.exe"
"C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe"
"C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE"
"C:\Program Files\Windows Defender\bak\MSASCui.exe"
"C:\WINDOWS\CREATOR\bak\Remind_XP.exe"
"C:\WINDOWS\ehome\bak\ehtray.exe"
"C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
"C:\Program Files\Grisoft\AVG Free\bak\avgcc.exe"
"C:\Program Files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe"
"C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
"C:\Program Files\Yahoo!\Search Protection\bak\SearchProtection.exe"
"C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
"C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"
"C:\Program Files\Snapfish\Snapfish PhotoShow\data\Xtras\bak\mssysmgr.exe"
_____________________________________________________________

-close the text file and click Yes. Please post the contents of the notepad that opens.

gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
 

Here you go.....


Find AWF report by noahdfear ©2006
Version 1.40
Option 2 run successfully

The current date is: Fri 10/26/2007
The current time is: 8:43:31.29


bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\HPDIGI~1\BAK

04/13/2006 12:05 PM 90,112 DMAScheduler.exe
1 File(s) 90,112 bytes

Directory of C:\PROGRA~1\MSNMES~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\PICASA2\BAK

06/15/2007 07:15 PM 366,400 PicasaMediaDetector.exe
1 File(s) 366,400 bytes

Directory of C:\PROGRA~1\REGSHAVE\BAK

02/04/2002 10:32 PM 53,248 REGSHAVE.EXE
1 File(s) 53,248 bytes

Directory of C:\PROGRA~1\WIFD1F~1\BAK

11/03/2006 07:20 PM 866,584 MSASCui.exe
1 File(s) 866,584 bytes

Directory of C:\WINDOWS\CREATOR\BAK

12/14/2004 05:23 AM 663,552 Remind_XP.exe
1 File(s) 663,552 bytes

Directory of C:\WINDOWS\EHOME\BAK

09/30/2005 12:01 AM 67,584 ehtray.exe
1 File(s) 67,584 bytes

Directory of C:\WINDOWS\SMINST\BAK

07/23/2005 01:14 AM 237,568 RECGUARD.EXE
1 File(s) 237,568 bytes

Directory of C:\PROGRA~1\GRISOFT\AVGFRE~1\BAK

09/14/2007 09:38 AM 421,888 avgcc.exe
1 File(s) 421,888 bytes

Directory of C:\PROGRA~1\HEWLET~1\HPBOOT~1\BAK

02/16/2006 01:34 AM 249,856 HPBootOp.exe
1 File(s) 249,856 bytes

Directory of C:\PROGRA~1\HP\HPSOFT~1\BAK

02/16/2005 11:11 PM 49,152 HPWuSchd2.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\YAHOO!\MESSEN~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\YAHOO!\SEARCH~1\BAK

06/08/2007 10:59 AM 224,248 SearchProtection.exe
1 File(s) 224,248 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

07/31/2006 07:16 PM 180,269 realsched.exe
1 File(s) 180,269 bytes

Directory of C:\PROGRA~1\JAVA\JRE16~2.0_0\BIN\BAK

07/12/2007 04:00 AM 132,496 jusched.exe
1 File(s) 132,496 bytes

Directory of C:\PROGRA~1\SNAPFISH\SNAPFI~1\DATA\XTRAS\BAK

01/31/2005 03:06 PM 208,896 mssysmgr.exe
1 File(s) 208,896 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

90112 Apr 13 2006 "C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
90112 Apr 13 2006 "C:\Program Files\HP DigitalMedia Archive\bak\DMAScheduler.exe"
591416 Sep 27 2007 "C:\Program Files\Picasa2\PicasaUpdate.exe"
5388088 Jun 29 2007 "C:\Documents and Settings\HP_Administrator\My Documents\picasaweb-current-setup.exe"
366400 Jun 15 2007 "C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe"
665160 Sep 27 2007 "C:\Program Files\Picasa2\cdautorun\PicasaRestore.exe"
53248 Feb 4 2002 "C:\Program Files\REGSHAVE\REGSHAVE.EXE"
53248 Feb 4 2002 "C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE"
866584 Nov 3 2006 "C:\Program Files\Windows Defender\MSASCui.exe"
866584 Nov 3 2006 "C:\Program Files\Windows Defender\bak\MSASCui.exe"
663552 Dec 14 2004 "C:\WINDOWS\CREATOR\Remind_XP.exe"
663552 Dec 14 2004 "C:\WINDOWS\CREATOR\bak\Remind_XP.exe"
64512 Aug 5 2005 "C:\WINDOWS\$NtUninstallKB908246$\ehtray.exe"
64512 Aug 5 2005 "C:\WINDOWS\ehome\ehtray.exe"
67584 Sep 30 2005 "C:\WINDOWS\ehome\bak\ehtray.exe"
237568 Jul 23 2005 "C:\WINDOWS\SMINST\RECGUARD.EXE"
237568 Jul 23 2005 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
421888 Sep 14 2007 "C:\Program Files\Grisoft\AVG Free\avgcc.exe"
421888 Sep 14 2007 "C:\Program Files\Grisoft\AVG Free\bak\avgcc.exe"
421888 Sep 14 2007 "C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7upd\backup\avgcc.exe"
249856 Feb 16 2006 "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe"
249856 Feb 16 2006 "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe"
49152 Feb 16 2005 "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
49152 Feb 16 2005 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
224248 Jun 8 2007 "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
224248 Jun 8 2007 "C:\Program Files\Yahoo!\Search Protection\bak\SearchProtection.exe"
180269 Jul 31 2006 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"
180269 Jul 31 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
132496 Sep 25 2007 "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
36975 Nov 10 2005 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc1.0_06\bin\jusched.exe"
49263 Nov 9 2006 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc2.0_10\bin\jusched.exe"
49263 Oct 12 2006 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc3.0_09\bin\jusched.exe"
75520 Dec 15 2006 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc4.0_11\bin\jusched.exe"
132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"
208896 Jan 31 2005 "C:\Program Files\Snapfish\Snapfish PhotoShow\data\Xtras\mssysmgr.exe"
208896 Jan 31 2005 "C:\Program Files\Snapfish\Snapfish PhotoShow\data\Xtras\bak\mssysmgr.exe"


end of report

deonnanicole
Posting Whiz in Training
253 posts since Jun 2004
Reputation Points: 18
Solved Threads: 13
 

DeOnna, try option 2 again with just these two:

"C:\WINDOWS\ehome\bak\ehtray.exe"
"C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe"

gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
 

Find AWF report by noahdfear ©2006
Version 1.40
Option 2 run successfully

The current date is: Fri 10/26/2007
The current time is: 9:37:44.73


bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\HPDIGI~1\BAK

04/13/2006 12:05 PM 90,112 DMAScheduler.exe
1 File(s) 90,112 bytes

Directory of C:\PROGRA~1\MSNMES~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\PICASA2\BAK

06/15/2007 07:15 PM 366,400 PicasaMediaDetector.exe
1 File(s) 366,400 bytes

Directory of C:\PROGRA~1\REGSHAVE\BAK

02/04/2002 10:32 PM 53,248 REGSHAVE.EXE
1 File(s) 53,248 bytes

Directory of C:\PROGRA~1\WIFD1F~1\BAK

11/03/2006 07:20 PM 866,584 MSASCui.exe
1 File(s) 866,584 bytes

Directory of C:\WINDOWS\CREATOR\BAK

12/14/2004 05:23 AM 663,552 Remind_XP.exe
1 File(s) 663,552 bytes

Directory of C:\WINDOWS\EHOME\BAK

09/30/2005 12:01 AM 67,584 ehtray.exe
1 File(s) 67,584 bytes

Directory of C:\WINDOWS\SMINST\BAK

07/23/2005 01:14 AM 237,568 RECGUARD.EXE
1 File(s) 237,568 bytes

Directory of C:\PROGRA~1\GRISOFT\AVGFRE~1\BAK

09/14/2007 09:38 AM 421,888 avgcc.exe
1 File(s) 421,888 bytes

Directory of C:\PROGRA~1\HEWLET~1\HPBOOT~1\BAK

02/16/2006 01:34 AM 249,856 HPBootOp.exe
1 File(s) 249,856 bytes

Directory of C:\PROGRA~1\HP\HPSOFT~1\BAK

02/16/2005 11:11 PM 49,152 HPWuSchd2.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\YAHOO!\MESSEN~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\YAHOO!\SEARCH~1\BAK

06/08/2007 10:59 AM 224,248 SearchProtection.exe
1 File(s) 224,248 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

07/31/2006 07:16 PM 180,269 realsched.exe
1 File(s) 180,269 bytes

Directory of C:\PROGRA~1\JAVA\JRE16~2.0_0\BIN\BAK

07/12/2007 04:00 AM 132,496 jusched.exe
1 File(s) 132,496 bytes

Directory of C:\PROGRA~1\SNAPFISH\SNAPFI~1\DATA\XTRAS\BAK

01/31/2005 03:06 PM 208,896 mssysmgr.exe
1 File(s) 208,896 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

90112 Apr 13 2006 "C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
90112 Apr 13 2006 "C:\Program Files\HP DigitalMedia Archive\bak\DMAScheduler.exe"
591416 Sep 27 2007 "C:\Program Files\Picasa2\PicasaUpdate.exe"
5388088 Jun 29 2007 "C:\Documents and Settings\HP_Administrator\My Documents\picasaweb-current-setup.exe"
366400 Jun 15 2007 "C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe"
665160 Sep 27 2007 "C:\Program Files\Picasa2\cdautorun\PicasaRestore.exe"
53248 Feb 4 2002 "C:\Program Files\REGSHAVE\REGSHAVE.EXE"
53248 Feb 4 2002 "C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE"
866584 Nov 3 2006 "C:\Program Files\Windows Defender\MSASCui.exe"
866584 Nov 3 2006 "C:\Program Files\Windows Defender\bak\MSASCui.exe"
663552 Dec 14 2004 "C:\WINDOWS\CREATOR\Remind_XP.exe"
663552 Dec 14 2004 "C:\WINDOWS\CREATOR\bak\Remind_XP.exe"
64512 Aug 5 2005 "C:\WINDOWS\$NtUninstallKB908246$\ehtray.exe"
64512 Aug 5 2005 "C:\WINDOWS\ehome\ehtray.exe"
67584 Sep 30 2005 "C:\WINDOWS\ehome\bak\ehtray.exe"
237568 Jul 23 2005 "C:\WINDOWS\SMINST\RECGUARD.EXE"
237568 Jul 23 2005 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
421888 Sep 14 2007 "C:\Program Files\Grisoft\AVG Free\avgcc.exe"
421888 Sep 14 2007 "C:\Program Files\Grisoft\AVG Free\bak\avgcc.exe"
421888 Sep 14 2007 "C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7upd\backup\avgcc.exe"
249856 Feb 16 2006 "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe"
249856 Feb 16 2006 "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe"
49152 Feb 16 2005 "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
49152 Feb 16 2005 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
224248 Jun 8 2007 "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
224248 Jun 8 2007 "C:\Program Files\Yahoo!\Search Protection\bak\SearchProtection.exe"
180269 Jul 31 2006 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"
180269 Jul 31 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
132496 Sep 25 2007 "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
36975 Nov 10 2005 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc1.0_06\bin\jusched.exe"
49263 Nov 9 2006 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc2.0_10\bin\jusched.exe"
49263 Oct 12 2006 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc3.0_09\bin\jusched.exe"
75520 Dec 15 2006 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc4.0_11\bin\jusched.exe"
132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"
208896 Jan 31 2005 "C:\Program Files\Snapfish\Snapfish PhotoShow\data\Xtras\mssysmgr.exe"
208896 Jan 31 2005 "C:\Program Files\Snapfish\Snapfish PhotoShow\data\Xtras\bak\mssysmgr.exe"


end of report

deonnanicole
Posting Whiz in Training
253 posts since Jun 2004
Reputation Points: 18
Solved Threads: 13
 

Nope, it is failing on those two again. So we'll try it the brute force way.
==Please copy the text between the lines to a notepad [format/wordwrap unchecked] and save as fixawf.bat, as type "all files", to your desktop; dclick it to run.
__________________________________________________________
if exist "C:\WINDOWS\ehome\ehtray.exe" del /q "C:\WINDOWS\ehome\ehtray.exe"
copy "C:\WINDOWS\ehome\bak\ehtray.exe" "C:\WINDOWS\ehome"
if exist "C:\WINDOWS\$NtUninstallKB908246$\ehtray.exe" del /q "C:\WINDOWS\$NtUninstallKB908246$\ehtray.exe"
copy "C:\WINDOWS\ehome\bak\ehtray.exe" "C:\WINDOWS\$NtUninstallKB908246$"
del /q "C:\WINDOWS\ehome\bak\ehtray.exe"

if exist "C:\Program Files\Picasa2\PicasaMediaDetector.exe" del /q "C:\Program Files\Picasa2\PicasaMediaDetector.exe"
copy "C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe" "C:\Program Files\Picasa2"
del /q "C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe"
__________________________________________________________

Finally run option 1 again so that I may check the replacements.

gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
 

Grinning here... that't the final edit. Run it.
And it's bedtime for me now.

gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
 

Ok, when I do that and double click on it, it opens for just a second and then closes again.....am I doing something wrong? Thanks again!

DeOnna

deonnanicole
Posting Whiz in Training
253 posts since Jun 2004
Reputation Points: 18
Solved Threads: 13
 

Here is what I got after doing that, and running option one again.


Find AWF report by noahdfear ©2006
Version 1.40

The current date is: Fri 10/26/2007
The current time is: 10:40:34.32


bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\HPDIGI~1\BAK

04/13/2006 12:05 PM 90,112 DMAScheduler.exe
1 File(s) 90,112 bytes

Directory of C:\PROGRA~1\MSNMES~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\PICASA2\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\REGSHAVE\BAK

02/04/2002 10:32 PM 53,248 REGSHAVE.EXE
1 File(s) 53,248 bytes

Directory of C:\PROGRA~1\WIFD1F~1\BAK

11/03/2006 07:20 PM 866,584 MSASCui.exe
1 File(s) 866,584 bytes

Directory of C:\WINDOWS\CREATOR\BAK

12/14/2004 05:23 AM 663,552 Remind_XP.exe
1 File(s) 663,552 bytes

Directory of C:\WINDOWS\EHOME\BAK

0 File(s) 0 bytes

Directory of C:\WINDOWS\SMINST\BAK

07/23/2005 01:14 AM 237,568 RECGUARD.EXE
1 File(s) 237,568 bytes

Directory of C:\PROGRA~1\GRISOFT\AVGFRE~1\BAK

09/14/2007 09:38 AM 421,888 avgcc.exe
1 File(s) 421,888 bytes

Directory of C:\PROGRA~1\HEWLET~1\HPBOOT~1\BAK

02/16/2006 01:34 AM 249,856 HPBootOp.exe
1 File(s) 249,856 bytes

Directory of C:\PROGRA~1\HP\HPSOFT~1\BAK

02/16/2005 11:11 PM 49,152 HPWuSchd2.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\YAHOO!\MESSEN~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\YAHOO!\SEARCH~1\BAK

06/08/2007 10:59 AM 224,248 SearchProtection.exe
1 File(s) 224,248 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

07/31/2006 07:16 PM 180,269 realsched.exe
1 File(s) 180,269 bytes

Directory of C:\PROGRA~1\JAVA\JRE16~2.0_0\BIN\BAK

07/12/2007 04:00 AM 132,496 jusched.exe
1 File(s) 132,496 bytes

Directory of C:\PROGRA~1\SNAPFISH\SNAPFI~1\DATA\XTRAS\BAK

01/31/2005 03:06 PM 208,896 mssysmgr.exe
1 File(s) 208,896 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

90112 Apr 13 2006 "C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
90112 Apr 13 2006 "C:\Program Files\HP DigitalMedia Archive\bak\DMAScheduler.exe"
53248 Feb 4 2002 "C:\Program Files\REGSHAVE\REGSHAVE.EXE"
53248 Feb 4 2002 "C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE"
866584 Nov 3 2006 "C:\Program Files\Windows Defender\MSASCui.exe"
866584 Nov 3 2006 "C:\Program Files\Windows Defender\bak\MSASCui.exe"
663552 Dec 14 2004 "C:\WINDOWS\CREATOR\Remind_XP.exe"
663552 Dec 14 2004 "C:\WINDOWS\CREATOR\bak\Remind_XP.exe"
237568 Jul 23 2005 "C:\WINDOWS\SMINST\RECGUARD.EXE"
237568 Jul 23 2005 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
421888 Sep 14 2007 "C:\Program Files\Grisoft\AVG Free\avgcc.exe"
421888 Sep 14 2007 "C:\Program Files\Grisoft\AVG Free\bak\avgcc.exe"
421888 Sep 14 2007 "C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7upd\backup\avgcc.exe"
249856 Feb 16 2006 "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe"
249856 Feb 16 2006 "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe"
49152 Feb 16 2005 "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
49152 Feb 16 2005 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
224248 Jun 8 2007 "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
224248 Jun 8 2007 "C:\Program Files\Yahoo!\Search Protection\bak\SearchProtection.exe"
180269 Jul 31 2006 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"
180269 Jul 31 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
132496 Sep 25 2007 "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
36975 Nov 10 2005 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc1.0_06\bin\jusched.exe"
49263 Nov 9 2006 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc2.0_10\bin\jusched.exe"
49263 Oct 12 2006 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc3.0_09\bin\jusched.exe"
75520 Dec 15 2006 "C:\RECYCLER\S-1-5-21-3809739533-768046810-4258763112-1007\Dc4.0_11\bin\jusched.exe"
132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"
208896 Jan 31 2005 "C:\Program Files\Snapfish\Snapfish PhotoShow\data\Xtras\mssysmgr.exe"
208896 Jan 31 2005 "C:\Program Files\Snapfish\Snapfish PhotoShow\data\Xtras\bak\mssysmgr.exe"


end of report

deonnanicole
Posting Whiz in Training
253 posts since Jun 2004
Reputation Points: 18
Solved Threads: 13
 

Sorry, DeOnna, I should have mentioned that, yes, all you would see is a brief flick of a black window. It did its job [if you did, trying it more than once would not have hurt].
So now all the good files are copied back into their original directories, replacing the infected copies. This next step deletes the copy folders:
-option 3, FindAWF: start the program again, select to remove bak folders, into the text file that opens paste all the text between the lines:
_____________________________________________________________
C:\Program Files\HP DigitalMedia Archive\bak
C:\Program Files\REGSHAVE\bak
C:\Program Files\Windows Defender\bak
C:\WINDOWS\CREATOR\bak
C:\WINDOWS\SMINST\bak
C:\Program Files\Grisoft\AVG Free\bak
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\bak
C:\Program Files\HP\HP Software Update\bak
C:\Program Files\Yahoo!\Search Protection\bak
C:\Program Files\Common Files\Real\Update_OB\bak
C:\Program Files\Java\jre1.6.0_02\bin\bak
C:\Program Files\Snapfish\Snapfish PhotoShow\data\Xtras\bak
_____________________________________________________________

-close the text file and click Yes. Please post the contents of the notepad that opens.
Then, if and only if these two sections of the report are empty...:

bak folders found
~~~~~~~~~~~
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

...go ahead and run option 4 next -this will reset your restricted and trusted sites in IE, tools, internet options, security. If you have added trusted sites you will have to re-enter them afterward [for an extra level of security I keep the https box checked here]. That is up to your judgement.
If you use SpywareBlaster, IE-SpyAd, Spybot etc you will need to re-enable their restrictions afterwards.
Say how things are and post a fresh hijackthis log.
Cheers.

gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
 

Find AWF report by noahdfear ©2006
Version 1.40
Option 3 run successfully

The current date is: Fri 10/26/2007
The current time is: 21:48:04.53


bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\MSNMES~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\PICASA2\BAK

0 File(s) 0 bytes

Directory of C:\WINDOWS\EHOME\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\YAHOO!\MESSEN~1\BAK

0 File(s) 0 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

end of report

As you can see, no files found. I am going to run the last option now, and post a hijackthis log either tonight or tomorrow morning if I have time before family from out of town gets here. If not, I will post it tomorrow night. Thanks!

deonnanicole
Posting Whiz in Training
253 posts since Jun 2004
Reputation Points: 18
Solved Threads: 13
 

This article has been dead for over three months

Post: Markdown Syntax: Formatting Help
You