Smidfaufix infection!
Solved
magicien10024
Posted messages
3317
Status
Membre
-
magicien10024 Posted messages 3317 Status Membre -
magicien10024 Posted messages 3317 Status Membre -
Hello,
I got infected by smidfraufix! It seems very strange since this software is designed by definition to eradicate infections
after performing an online scan with Norton I found them but impossible to get rid of them
1 explicit image
http://img185.imageshack.us/img185/9936/scannortonko3.png
thank you for suggesting the appropriate procedures
I got infected by smidfraufix! It seems very strange since this software is designed by definition to eradicate infections
after performing an online scan with Norton I found them but impossible to get rid of them
1 explicit image
http://img185.imageshack.us/img185/9936/scannortonko3.png
thank you for suggesting the appropriate procedures
Configuration: Windows XP Firefox 3.0.1
11 réponses
Hello everyone, if you take the time to read the tutorial http://siri.urz.free.fr/Fix/SmitfraudFix.php all the way through before using it, you will find the following
False positive:
process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool. It is not a virus, but a utility designed to terminate processes. In the wrong hands, this utility could stop security software (Antivirus, Firewall...) which is why these antivirus programs issue alerts.
http://www.beyondlogic.org/consulting/processutil/processutil.htm
--
Warning !! the multiplication of security software does not
protect better; in fact, it can cause conflicts and
crashes. " but everyone remains the master of their PC "
False positive:
process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool. It is not a virus, but a utility designed to terminate processes. In the wrong hands, this utility could stop security software (Antivirus, Firewall...) which is why these antivirus programs issue alerts.
http://www.beyondlogic.org/consulting/processutil/processutil.htm
--
Warning !! the multiplication of security software does not
protect better; in fact, it can cause conflicts and
crashes. " but everyone remains the master of their PC "
magicien10024
Posted messages
3317
Status
Membre
283
Ok, thanks for the info, Jacques.
Hello,
Download ToolsCleaner to your desktop.
-->
ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
http://pc-system.fr/
# Click on Search and let the scan run ...
# Click on Delete to finalize.
# You can, if you wish, use the Optional Settings.
# Click on Exit to obtain the report.
# Post the report (TCleaner.txt) found at the root of your hard drive (C:\).
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki.
Download ToolsCleaner to your desktop.
-->
ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
http://pc-system.fr/
# Click on Search and let the scan run ...
# Click on Delete to finalize.
# You can, if you wish, use the Optional Settings.
# Click on Exit to obtain the report.
# Post the report (TCleaner.txt) found at the root of your hard drive (C:\).
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki.
Thank you for your quick response
So that you can accurately target this problem, I'm sending you a link
http://www.commentcamarche.net/forum/affich 7765802 pub intempestive?page=3#68
I have followed all these procedures and the one you just suggested
I was hoping that this infection had been eradicated, but this rather tough virus has reactivated
Warning, post 46 contains a virus (I reported it to the moderator)
So that you can accurately target this problem, I'm sending you a link
http://www.commentcamarche.net/forum/affich 7765802 pub intempestive?page=3#68
I have followed all these procedures and the one you just suggested
I was hoping that this infection had been eradicated, but this rather tough virus has reactivated
Warning, post 46 contains a virus (I reported it to the moderator)
smithfraud is not a virus, but some AV detects it that way
we're going to remove it, but first do this:
uninstall: Desktop Messenger
then do this:
Download this file to the desktop:
http://downloads.malwareremoval.com/Nel/FixP.zip
Extract and double-click on Fix_Protocol_zones_ranges.reg.
Accept when it asks you to merge with the registry.
then:
Download DSS (formerly Comboscan) from Deckard to your desktop:
http://deckard.geekstogo.com/dss.exe
(choose save, then Desktop as the location)
Close all running applications.
Double-click on DSS.exe to launch the tool.
A window opens, prompting you to close all applications, click OK.
At the end of the scan, a window opens, click OK.
The main.txt report will display, copy it into your next response.
If a supplementary report was created (extra.txt), post that as well in your reply.
The reports are here:
(!) C:\Deckard\System Scanner\main.txt
(!) C:\Deckard\System Scanner\extra.txt
(CTRL+A to select all, CTRL+C to copy and CTRL+V to paste)
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Good listening
@ + TChiki.
we're going to remove it, but first do this:
uninstall: Desktop Messenger
then do this:
Download this file to the desktop:
http://downloads.malwareremoval.com/Nel/FixP.zip
Extract and double-click on Fix_Protocol_zones_ranges.reg.
Accept when it asks you to merge with the registry.
then:
Download DSS (formerly Comboscan) from Deckard to your desktop:
http://deckard.geekstogo.com/dss.exe
(choose save, then Desktop as the location)
Close all running applications.
Double-click on DSS.exe to launch the tool.
A window opens, prompting you to close all applications, click OK.
At the end of the scan, a window opens, click OK.
The main.txt report will display, copy it into your next response.
If a supplementary report was created (extra.txt), post that as well in your reply.
The reports are here:
(!) C:\Deckard\System Scanner\main.txt
(!) C:\Deckard\System Scanner\extra.txt
(CTRL+A to select all, CTRL+C to copy and CTRL+V to paste)
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Good listening
@ + TChiki.
Here are the 2 reports detected Windows Info:
PlatformId = 2
MajorVersion = 5
MinorVersion = 1
- - - - - - - - - - - - - - - - - - - - - - -
Launch Setup
09/08/2008 16:32:43
Setup path: E:\CD1\Setup.exe
Trying to get version of
E:\CD1\Setup.exe
...succeeded.
E:\CD1\Setup.exe is version 11.0.5510.0
Current version of Setup.exe: 11.0.5510.0
Searching for .INI file: Setup.INI
E:\CD1\FILES\SETUP\Setup.INI
Settings file located: E:\CD1\FILES\SETUP\Setup.INI
GetTempPath returned: C:\DOCUME~1\magicien\LOCALS~1\Temp\
Reading settings file
E:\CD1\FILES\SETUP\Setup.INI
Located: E:\CD1\PRO11.MSI
Package to install: E:\CD1\PRO11.MSI
Add Property:
PIDKEY=GWH28DGCMPP6RC46J4MT3HFDY
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Product\SkipLangCheck" (Default: 0)
Value: 0
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Product\CheckUpdates" (Default: 0)
Value: 0
Product {9011040C-6000-11D3-8CFE-0150048383C9} is installed for the user.
Read Package Version: 11.0.5614.0
Read Product Version: 11.0.5614.0
Media Package Code: {75419C14-0873-424E-AC03-3945F63E2823}
Installed Package Code: {75419C14-0873-424E-AC03-3945F63E2823}
Checking for Windows Installer....
C:\WINDOWS\System32\MSI.DLL
.. succeeded.
Checking for any beta version of the product.
dwNoLtCoExist = 0
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\CDCache" (Default: 0)
Value: auto
Office-specific properties added: PIDKEY="GWH28DGCMPP6RC46J4MT3HFDY"
General properties added: LAUNCHEDFROMSETUP="1" SETUPEXEPATH="E:\CD1\" SETUPEXENAME="Setup.exe"
Writing Task: Main - Microsoft Office 2003
Path: C:\WINDOWS\System32\msiexec.exe
CmdLine: /I E:\CD1\PRO11.MSI PIDKEY="GWH28DGCMPP6RC46J4MT3HFDY" LAUNCHEDFROMSETUP="1" SETUPEXEPATH="E:\CD1\" SETUPEXENAME="Setup.exe"
Looking for setup tasks to process.
09/08/2008 16:32:44 WaitForMsiExecDone...
WaitForSingleObject...
09/08/2008 16:33:46 WaitForMsiExecDone exits
Verifying install package is available
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\CDCache" (Default: 0)
Value: auto
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\Purge" (Default: 0)
Value: 0
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\DeletableCache" (Default: 0)
Value: 1
SetupXml is at: E:\CD1\Files\Setup\PRO11.xml
Parsing Download Info
Starting to load install configuration
Download Info:
Download Code : 9000040c-6000-11D3-8CFE-0150048383C9
Source Path : E:\CD1\
Product Code : {9011040C-6000-11D3-8CFE-0150048383C9}
Prod Src Path : PRO11.MSI
Use Windows Installer : false
Files to Download:
File: FILES\WINDOWS\INF\AER_1036.ADM (DW20.ADM_1036)
File: FILES\PFILES\COMMON\MSSHARED\DW\DW20.EXE (DW20.EXE_0001)
File: FILES\PFILES\COMMON\MSSHARED\DW\DWDCW20.DLL (DWDCW20.DLL)
File: FILES\PFILES\COMMON\MSSHARED\DW\1036\DWINTL20.DLL (DWINTL20.DLL_0001_1036)
File: FILES\PFILES\COMMON\MSSHARED\DW\DWTRIG20.EXE (DWTRIG20.EXE)
File: FILES\PFILES\MSOFFICE\OFFICE11\OCLEAN.DLL (OCLEAN.DLL_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\OCLNCORE.OPC (OCLNCORE.OPC_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\OCLNCUST.OPC (OCLNCUST.OPC_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\OCLNINTL.OPC (OCLNINTL.OPC_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\OFFCLN.EXE (OFFCLN.EXE_1036)
File: FILES\SETUP\OSE.EXE (OSE.EXE)
File: PRO11.MSI (PRO11.MSI)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\PSS10O.CHM (PSS10O.CHM_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\PSS10R.CHM (PSS10R.CHM_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\SETUP.CHM (SETUP.CHM_1036)
File: SKU011.XML (SKU011.XML_0002_1036)
File: A2561404.CAB (A2561404.CAB)
File: A3561404.CAB (A3561404.CAB)
File: A4561404.CAB (A4561404.CAB)
File: AV561404.CAB (AV561404.CAB)
File: CC561401.CAB (CC561401.CAB)
File: CD561401.CAB (CD561401.CAB)
File: CF561401.CAB (CF561401.CAB)
File: CL561401.CAB (CL561401.CAB)
File: CM561401.CAB (CM561401.CAB)
File: CP561401.CAB (CP561401.CAB)
File: CR561401.CAB (CR561401.CAB)
File: CS561401.CAB (CS561401.CAB)
File: E2561404.CAB (E2561404.CAB)
File: E3561404.CAB (E3561404.CAB)
File: E4561404.CAB (E4561404.CAB)
File: EV561404.CAB (EV561404.CAB)
File: G3561404.CAB (G3561404.CAB)
File: GV561402.CAB (GV561402.CAB)
File: IJ561401.CAB (IJ561401.CAB)
File: IS561401.CAB (IS561401.CAB)
File: IU561401.CAB (IU561401.CAB)
File: L2561404.CAB (L2561404.CAB)
File: L3561405.CAB (L3561405.CAB)
File: L4561405.CAB (L4561405.CAB)
File: L9561402.CAB (L9561402.CAB)
File: LV561405.CAB (LV561405.CAB)
File: M2561403.CAB (M2561403.CAB)
File: M3561403.CAB (M3561403.CAB)
File: M4561403.CAB (M4561403.CAB)
File: M9561401.CAB (M9561401.CAB)
File: MA561405.CAB (MA561405.CAB)
File: MC561403.CAB (MC561403.CAB)
File: MG561403.CAB (MG561403.CAB)
File: MH561401.CAB (MH561401.CAB)
File: MO561404.CAB (MO561404.CAB)
File: MT561403.CAB (MT561403.CAB)
File: O0561401.CAB (O0561401.CAB)
File: O1561407.CAB (O1561407.CAB)
File: O9561402.CAB (O9561402.CAB)
File: P2561404.CAB (P2561404.CAB)
File: P3561405.CAB (P3561405.CAB)
File: P4561405.CAB (P4561405.CAB)
File: PA561401.CAB (PA561401.CAB)
File: PR102593.CAB (PR102593.CAB)
File: PR103196.CAB (PR103196.CAB)
File: PR103369.CAB (PR103369.CAB)
File: PR103601.CAB (PR103601.CAB)
File: PR104301.CAB (PR104301.CAB)
File: PR308246.CAB (PR308246.CAB)
File: PV561405.CAB (PV561405.CAB)
File: PW561405.CAB (PW561405.CAB)
File: Q2561405.CAB (Q2561405.CAB)
File: Q3561405.CAB (Q3561405.CAB)
File: Q4561405.CAB (Q4561405.CAB)
File: QV561405.CAB (QV561405.CAB)
File: SKU011.CAB (SKU011.CAB)
File: TA561401.CAB (TA561401.CAB)
File: TR102537.CAB (TR102537.CAB)
File: TR103113.CAB (TR103113.CAB)
File: TR308222.CAB (TR308222.CAB)
File: V3561402.CAB (V3561402.CAB)
File: W2561405.CAB (W2561405.CAB)
File: W3561405.CAB (W3561405.CAB)
File: W4561405.CAB (W4561405.CAB)
File: WV561405.CAB (WV561405.CAB)
File: X2561405.CAB (X2561405.CAB)
File: X3561405.CAB (X3561405.CAB)
File: YA561403.CAB (YA561403.CAB)
File: YB561403.CAB (YB561403.CAB)
File: YC561403.CAB (YC561403.CAB)
File: YH561402.CAB (YH561402.CAB)
File: YI561401.CAB (YI561401.CAB)
File: YL561403.CAB (YL561403.CAB)
File: YM561403.CAB (YM561403.CAB)
File: YO561402.CAB (YO561402.CAB)
File: YT561401.CAB (YT561401.CAB)
File: ZA561401.CAB (ZA561401.CAB)
File: ZC561402.CAB (ZC561402.CAB)
File: ZD561403.CAB (ZD561403.CAB)
File: ZE561402.CAB (ZE561402.CAB)
File: ZF561402.CAB (ZF561402.CAB)
File: ZG561401.CAB (ZG561401.CAB)
File: ZH561403.CAB (ZH561403.CAB)
File: ZI561402.CAB (ZI561402.CAB)
File: ZJ561401.CAB (ZJ561401.CAB)
File: ZK561401.CAB (ZK561401.CAB)
File: ZM561401.CAB (ZM561401.CAB)
File: ZN561401.CAB (ZN561401.CAB)
File: ZO561403.CAB (ZO561403.CAB)
File: ZQ561401.CAB (ZQ561401.CAB)
File: ZR561402.CAB (ZR561402.CAB)
File: ZS561401.CAB (ZS561401.CAB)
File: ZT561401.CAB (ZT561401.CAB)
File: ZU561405.CAB (ZU561405.CAB)
File: ZV561401.CAB (ZV561401.CAB)
File: ZY561403.CAB (ZY561403.CAB)
File: ZZ561401.CAB (ZZ561401.CAB)
File: FILES\SETUP\SETUP.INI (PRO11.INI)
File: SETUP.EXE (SETUP.EXE_1036)
Using Office Source Engine at path: E:\CD1\FILES\SETUP\OSE.EXE
Successfully started Office Source Engine in stand-alone mode.
Using Local Cache Drive of already installed product: C:\.
Found pre-existing download, will use this as default drive for local cache.
Found enough space on drive "C:\" to cache all feature cabinets.
(CDCACHE=AUTO) - There is enough space to cache some or all of the image. Drive for this download is C:\
Completed download for file: DW20.ADM_1036.
Completed download for file: DW20.EXE_0001.
Completed download for file: DWDCW20.DLL.
Completed download for file: DWINTL20.DLL_0001_1036.
Completed download for file: DWTRIG20.EXE.
Completed download for file: OCLEAN.DLL_1036.
Completed download for file: OCLNCORE.OPC_1036.
Completed download for file: OCLNCUST.OPC_1036.
Completed download for file: OCLNINTL.OPC_1036.
Completed download for file: OFFCLN.EXE_1036.
Completed download for file: OSE.EXE.
Completed download for file: PRO11.MSI.
Completed download for file: PSS10O.CHM_1036.
Completed download for file: PSS10R.CHM_1036.
Completed download for file: SETUP.CHM_1036.
Completed download for file: SKU011.XML_0002_1036.
Finished CDCache Download, retrieving msi download info
09/08/2008 16:33:53
Package was: E:\CD1\PRO11.MSI.
Setting Package to: C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\PRO11.MSI.
Done with CD Caching, cached MSI to: C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\PRO11.MSI
09/08/2008 16:33:53
Parsed arg: /I
Parsed arg: E:\CD1\PRO11.MSI
Parsed arg: PIDKEY=GWH28DGCMPP6RC46J4MT3HFDY
Parsed arg: LAUNCHEDFROMSETUP=1
Parsed arg: SETUPEXEPATH=E:\CD1\
Parsed arg: SETUPEXENAME=Setup.exe
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\Purge" (Default: 0)
Value: 0
Finished local caching successfully.
DWSETUPLOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001).txt"
DWMSILOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt"
Command Line Logging Parameters: /lpiwaeo "C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt"
09/08/2008 16:33:53
Executing Task:
Microsoft Office 2003
"C:\WINDOWS\System32\msiexec.exe" /I "C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\PRO11.MSI" PIDKEY=GWH28DGCMPP6RC46J4MT3HFDY LAUNCHEDFROMSETUP=1 SETUPEXEPATH=E:\CD1\ SETUPEXENAME=Setup.exe /lpiwaeo "C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt" STANDALONEOSE="C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\SETUP\OSE.EXE" CDCACHE="2" DELETABLECACHE="1" LOCALCACHEDRIVE="C" DWSETUPLOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001).txt" DWMSILOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt"
Type: msi
Ignore Return Values: False
Reboot: False
Successfully launched MsiExec....
09/08/2008 16:34:44 Chained install return code: 1602
Shutting down chained setup processing.
***** Setup exits
09/08/2008 16:34:44
(return = 1602)
report 2
=== Start writing to log: 09/08/2008 16:33:54 ===
Start of action 16:33:54: INSTALL.
Start of action 16:33:54: SetOfficeProps.
End of action 16:33:56: SetOfficeProps. Return value: 1.
Start of action 16:33:56: LaunchConditions.
End of action 16:33:56: LaunchConditions. Return value: 1.
Start of action 16:33:56: PreActionDialog.
Information 2898. An internal error occurred. (Tahoma8 Tahoma 0 13 )
Information 2898. An internal error occurred. (TahomaContrastBlackBold8 Tahoma 0 13 )
Information 2898. An internal error occurred. (TahomaContrastBlack8 Tahoma 0 13 )
Information 2836. An internal error occurred. (PreActionDialog ActionTextInstall )
Action 16:33:56: PreActionDialog. Dialog created
End of action 16:33:56: PreActionDialog. Return value: 1.
Start of action 16:33:56: FindRelatedProducts.
End of action 16:33:56: FindRelatedProducts. Return value: 0.
Start of action 16:33:56: AppSearch.
Action 16:33:56: AppSearch. Preparing for the installation of Microsoft Office Professional Edition 2003
End of action 16:33:56: AppSearch. Return value: 1.
Start of action 16:33:56: SkuRedReinstall.
End of action 16:33:56: SkuRedReinstall. Return value: 1.
Start of action 16:33:56: CallRegLookup.
End of action 16:33:57: CallRegLookup. Return value: 1.
Start of action 16:33:57: SetSystemMdw.
End of action 16:33:57: SetSystemMdw. Return value: 1.
Start of action 16:33:57: SetSystemNTDir.
End of action 16:33:57: SetSystemNTDir. Return value: 1.
Start of action 16:33:57: ReserveCacheCost.
End of action 16:33:58: ReserveCacheCost. Return value: 1.
Start of action 16:33:58: DIRCA_TARGETDIR.40D5CE2532074296B6DD2138D9286013.
End of action 16:33:58: DIRCA_TARGETDIR.40D5CE2532074296B6DD2138D9286013. Return value: 1.
Start of action 16:33:58: CostInitialize.
End of action 16:33:58: CostInitialize. Return value: 1.
Start of action 16:33:58: OPCMigrateStartFolders.
End of action 16:33:59: OPCMigrateStartFolders. Return value: 1.
Start of action 16:33:59: OPCCleanUpShortcuts.
Action 16:33:59: Cancel. Dialog created
OPCCleanUpShortcuts: install type is per machine
OPCCleanUpShortcuts: searching the profiles of all users
FInsertDarShortcutTable: opcd16524143434f557e322e4c4e4b opcd16 RACCOU~2|Shortcut to EXCEL Global_Excel_Core #EXCEL.EXE -2147483648 -2147483648 1 opcd18
FInsertDarShortcutTable: opcd16524143434f557e332e4c4e4b opcd16 RACCOU~3|Shortcut to MSPUB Global_Publisher_Core #MSPUB.EXE -2147483648 -2147483648 1 opcd18
FInsertDarShortcutTable: opcd16524143434f557e312e4c4e4b opcd16 RACCOU~1|Shortcut to WINWORD Global_Word_Core #WINWORD.EXE -2147483648 -2147483648 1 opcd18
End of action 16:34:03: OPCCleanUpShortcuts. Return value: 1.
Start of action 16:34:03: FileCost.
End of action 16:34:03: FileCost. Return value: 1.
Start of action 16:34:03: CMWMain.
CMWMain FOpenConditionTables: End - succeed
CMWMain User possesses Admin privileges.
CMWMain No CMW File
CMWMain FCloseConditionTables: End - succeed
End of action 16:34:04: CMWMain. Return value: 1.
Start of action 16:34:04: CostFinalize.
End of action 16:34:04: CostFinalize. Return value: 1.
Start of action 16:34:04: SetLocalCacheFolder.
End of action 16:34:04: SetLocalCacheFolder. Return value: 1.
Start of action 16:34:04: SetSMARTSOURCEDIR_SEP.
End of action 16:34:04: SetSMARTSOURCEDIR_SEP. Return value: 1.
Start of action 16:34:04: FeatureDependency.
End of action 16:34:05: FeatureDependency. Return value: 1.
Start of action 16:34:05: SetSetupHelpFileDir_Installed.
End of action 16:34:05: SetSetupHelpFileDir_Installed. Return value: 1.
Start of action 16:34:05: SetSetupPSSHelpFileDir_Installed.
End of action 16:34:05: SetSetupPSSHelpFileDir_Installed. Return value: 1.
Start of action 16:34:05: SetDefaultInstallLocation.
End of action 16:34:05: SetDefaultInstallLocation. Return value: 1.
Start of action 16:34:05: DoDialogSequence.
DoDialogSequence: FindNextDialogtoShow: IN: next (null)
DoDialogSequence: FindNextDialogtoShow: got condition ACTION="ADMIN" AND NOT PATCH evaluated to 0
DoDialogSequence: FindNextDialogtoShow: got condition (NOT RESUME AND ACTION="INSTALL") AND Installed AND NOT Preselected AND NOT CONVERTTRIAL evaluated to 1
DoDialogSequence: FindNextDialogtoShow: Set property CurrentDialog to MMode
DoDialogSequence: FindNextDialogtoShow: Set property NextDialog to MMode
DoDialogSequence: FindNextDialogtoShow: OUT: next MMode
DoDialogSequence: DoDialogSequence: Calling DoAction MMode
Start of action 16:34:06: MMode.
Action 16:34:06: MMode. Dialog created
Start of action 16:34:14: CalcNextDialog.
End of action 16:34:15: CalcNextDialog. Return value: 1.
Information 2898. An internal error occurred. (TahomaBold8 Tahoma 0 13 )
Information 2836. An internal error occurred. (
PlatformId = 2
MajorVersion = 5
MinorVersion = 1
- - - - - - - - - - - - - - - - - - - - - - -
Launch Setup
09/08/2008 16:32:43
Setup path: E:\CD1\Setup.exe
Trying to get version of
E:\CD1\Setup.exe
...succeeded.
E:\CD1\Setup.exe is version 11.0.5510.0
Current version of Setup.exe: 11.0.5510.0
Searching for .INI file: Setup.INI
E:\CD1\FILES\SETUP\Setup.INI
Settings file located: E:\CD1\FILES\SETUP\Setup.INI
GetTempPath returned: C:\DOCUME~1\magicien\LOCALS~1\Temp\
Reading settings file
E:\CD1\FILES\SETUP\Setup.INI
Located: E:\CD1\PRO11.MSI
Package to install: E:\CD1\PRO11.MSI
Add Property:
PIDKEY=GWH28DGCMPP6RC46J4MT3HFDY
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Product\SkipLangCheck" (Default: 0)
Value: 0
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Product\CheckUpdates" (Default: 0)
Value: 0
Product {9011040C-6000-11D3-8CFE-0150048383C9} is installed for the user.
Read Package Version: 11.0.5614.0
Read Product Version: 11.0.5614.0
Media Package Code: {75419C14-0873-424E-AC03-3945F63E2823}
Installed Package Code: {75419C14-0873-424E-AC03-3945F63E2823}
Checking for Windows Installer....
C:\WINDOWS\System32\MSI.DLL
.. succeeded.
Checking for any beta version of the product.
dwNoLtCoExist = 0
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\CDCache" (Default: 0)
Value: auto
Office-specific properties added: PIDKEY="GWH28DGCMPP6RC46J4MT3HFDY"
General properties added: LAUNCHEDFROMSETUP="1" SETUPEXEPATH="E:\CD1\" SETUPEXENAME="Setup.exe"
Writing Task: Main - Microsoft Office 2003
Path: C:\WINDOWS\System32\msiexec.exe
CmdLine: /I E:\CD1\PRO11.MSI PIDKEY="GWH28DGCMPP6RC46J4MT3HFDY" LAUNCHEDFROMSETUP="1" SETUPEXEPATH="E:\CD1\" SETUPEXENAME="Setup.exe"
Looking for setup tasks to process.
09/08/2008 16:32:44 WaitForMsiExecDone...
WaitForSingleObject...
09/08/2008 16:33:46 WaitForMsiExecDone exits
Verifying install package is available
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\CDCache" (Default: 0)
Value: auto
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\Purge" (Default: 0)
Value: 0
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\DeletableCache" (Default: 0)
Value: 1
SetupXml is at: E:\CD1\Files\Setup\PRO11.xml
Parsing Download Info
Starting to load install configuration
Download Info:
Download Code : 9000040c-6000-11D3-8CFE-0150048383C9
Source Path : E:\CD1\
Product Code : {9011040C-6000-11D3-8CFE-0150048383C9}
Prod Src Path : PRO11.MSI
Use Windows Installer : false
Files to Download:
File: FILES\WINDOWS\INF\AER_1036.ADM (DW20.ADM_1036)
File: FILES\PFILES\COMMON\MSSHARED\DW\DW20.EXE (DW20.EXE_0001)
File: FILES\PFILES\COMMON\MSSHARED\DW\DWDCW20.DLL (DWDCW20.DLL)
File: FILES\PFILES\COMMON\MSSHARED\DW\1036\DWINTL20.DLL (DWINTL20.DLL_0001_1036)
File: FILES\PFILES\COMMON\MSSHARED\DW\DWTRIG20.EXE (DWTRIG20.EXE)
File: FILES\PFILES\MSOFFICE\OFFICE11\OCLEAN.DLL (OCLEAN.DLL_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\OCLNCORE.OPC (OCLNCORE.OPC_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\OCLNCUST.OPC (OCLNCUST.OPC_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\OCLNINTL.OPC (OCLNINTL.OPC_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\OFFCLN.EXE (OFFCLN.EXE_1036)
File: FILES\SETUP\OSE.EXE (OSE.EXE)
File: PRO11.MSI (PRO11.MSI)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\PSS10O.CHM (PSS10O.CHM_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\PSS10R.CHM (PSS10R.CHM_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\SETUP.CHM (SETUP.CHM_1036)
File: SKU011.XML (SKU011.XML_0002_1036)
File: A2561404.CAB (A2561404.CAB)
File: A3561404.CAB (A3561404.CAB)
File: A4561404.CAB (A4561404.CAB)
File: AV561404.CAB (AV561404.CAB)
File: CC561401.CAB (CC561401.CAB)
File: CD561401.CAB (CD561401.CAB)
File: CF561401.CAB (CF561401.CAB)
File: CL561401.CAB (CL561401.CAB)
File: CM561401.CAB (CM561401.CAB)
File: CP561401.CAB (CP561401.CAB)
File: CR561401.CAB (CR561401.CAB)
File: CS561401.CAB (CS561401.CAB)
File: E2561404.CAB (E2561404.CAB)
File: E3561404.CAB (E3561404.CAB)
File: E4561404.CAB (E4561404.CAB)
File: EV561404.CAB (EV561404.CAB)
File: G3561404.CAB (G3561404.CAB)
File: GV561402.CAB (GV561402.CAB)
File: IJ561401.CAB (IJ561401.CAB)
File: IS561401.CAB (IS561401.CAB)
File: IU561401.CAB (IU561401.CAB)
File: L2561404.CAB (L2561404.CAB)
File: L3561405.CAB (L3561405.CAB)
File: L4561405.CAB (L4561405.CAB)
File: L9561402.CAB (L9561402.CAB)
File: LV561405.CAB (LV561405.CAB)
File: M2561403.CAB (M2561403.CAB)
File: M3561403.CAB (M3561403.CAB)
File: M4561403.CAB (M4561403.CAB)
File: M9561401.CAB (M9561401.CAB)
File: MA561405.CAB (MA561405.CAB)
File: MC561403.CAB (MC561403.CAB)
File: MG561403.CAB (MG561403.CAB)
File: MH561401.CAB (MH561401.CAB)
File: MO561404.CAB (MO561404.CAB)
File: MT561403.CAB (MT561403.CAB)
File: O0561401.CAB (O0561401.CAB)
File: O1561407.CAB (O1561407.CAB)
File: O9561402.CAB (O9561402.CAB)
File: P2561404.CAB (P2561404.CAB)
File: P3561405.CAB (P3561405.CAB)
File: P4561405.CAB (P4561405.CAB)
File: PA561401.CAB (PA561401.CAB)
File: PR102593.CAB (PR102593.CAB)
File: PR103196.CAB (PR103196.CAB)
File: PR103369.CAB (PR103369.CAB)
File: PR103601.CAB (PR103601.CAB)
File: PR104301.CAB (PR104301.CAB)
File: PR308246.CAB (PR308246.CAB)
File: PV561405.CAB (PV561405.CAB)
File: PW561405.CAB (PW561405.CAB)
File: Q2561405.CAB (Q2561405.CAB)
File: Q3561405.CAB (Q3561405.CAB)
File: Q4561405.CAB (Q4561405.CAB)
File: QV561405.CAB (QV561405.CAB)
File: SKU011.CAB (SKU011.CAB)
File: TA561401.CAB (TA561401.CAB)
File: TR102537.CAB (TR102537.CAB)
File: TR103113.CAB (TR103113.CAB)
File: TR308222.CAB (TR308222.CAB)
File: V3561402.CAB (V3561402.CAB)
File: W2561405.CAB (W2561405.CAB)
File: W3561405.CAB (W3561405.CAB)
File: W4561405.CAB (W4561405.CAB)
File: WV561405.CAB (WV561405.CAB)
File: X2561405.CAB (X2561405.CAB)
File: X3561405.CAB (X3561405.CAB)
File: YA561403.CAB (YA561403.CAB)
File: YB561403.CAB (YB561403.CAB)
File: YC561403.CAB (YC561403.CAB)
File: YH561402.CAB (YH561402.CAB)
File: YI561401.CAB (YI561401.CAB)
File: YL561403.CAB (YL561403.CAB)
File: YM561403.CAB (YM561403.CAB)
File: YO561402.CAB (YO561402.CAB)
File: YT561401.CAB (YT561401.CAB)
File: ZA561401.CAB (ZA561401.CAB)
File: ZC561402.CAB (ZC561402.CAB)
File: ZD561403.CAB (ZD561403.CAB)
File: ZE561402.CAB (ZE561402.CAB)
File: ZF561402.CAB (ZF561402.CAB)
File: ZG561401.CAB (ZG561401.CAB)
File: ZH561403.CAB (ZH561403.CAB)
File: ZI561402.CAB (ZI561402.CAB)
File: ZJ561401.CAB (ZJ561401.CAB)
File: ZK561401.CAB (ZK561401.CAB)
File: ZM561401.CAB (ZM561401.CAB)
File: ZN561401.CAB (ZN561401.CAB)
File: ZO561403.CAB (ZO561403.CAB)
File: ZQ561401.CAB (ZQ561401.CAB)
File: ZR561402.CAB (ZR561402.CAB)
File: ZS561401.CAB (ZS561401.CAB)
File: ZT561401.CAB (ZT561401.CAB)
File: ZU561405.CAB (ZU561405.CAB)
File: ZV561401.CAB (ZV561401.CAB)
File: ZY561403.CAB (ZY561403.CAB)
File: ZZ561401.CAB (ZZ561401.CAB)
File: FILES\SETUP\SETUP.INI (PRO11.INI)
File: SETUP.EXE (SETUP.EXE_1036)
Using Office Source Engine at path: E:\CD1\FILES\SETUP\OSE.EXE
Successfully started Office Source Engine in stand-alone mode.
Using Local Cache Drive of already installed product: C:\.
Found pre-existing download, will use this as default drive for local cache.
Found enough space on drive "C:\" to cache all feature cabinets.
(CDCACHE=AUTO) - There is enough space to cache some or all of the image. Drive for this download is C:\
Completed download for file: DW20.ADM_1036.
Completed download for file: DW20.EXE_0001.
Completed download for file: DWDCW20.DLL.
Completed download for file: DWINTL20.DLL_0001_1036.
Completed download for file: DWTRIG20.EXE.
Completed download for file: OCLEAN.DLL_1036.
Completed download for file: OCLNCORE.OPC_1036.
Completed download for file: OCLNCUST.OPC_1036.
Completed download for file: OCLNINTL.OPC_1036.
Completed download for file: OFFCLN.EXE_1036.
Completed download for file: OSE.EXE.
Completed download for file: PRO11.MSI.
Completed download for file: PSS10O.CHM_1036.
Completed download for file: PSS10R.CHM_1036.
Completed download for file: SETUP.CHM_1036.
Completed download for file: SKU011.XML_0002_1036.
Finished CDCache Download, retrieving msi download info
09/08/2008 16:33:53
Package was: E:\CD1\PRO11.MSI.
Setting Package to: C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\PRO11.MSI.
Done with CD Caching, cached MSI to: C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\PRO11.MSI
09/08/2008 16:33:53
Parsed arg: /I
Parsed arg: E:\CD1\PRO11.MSI
Parsed arg: PIDKEY=GWH28DGCMPP6RC46J4MT3HFDY
Parsed arg: LAUNCHEDFROMSETUP=1
Parsed arg: SETUPEXEPATH=E:\CD1\
Parsed arg: SETUPEXENAME=Setup.exe
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\Purge" (Default: 0)
Value: 0
Finished local caching successfully.
DWSETUPLOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001).txt"
DWMSILOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt"
Command Line Logging Parameters: /lpiwaeo "C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt"
09/08/2008 16:33:53
Executing Task:
Microsoft Office 2003
"C:\WINDOWS\System32\msiexec.exe" /I "C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\PRO11.MSI" PIDKEY=GWH28DGCMPP6RC46J4MT3HFDY LAUNCHEDFROMSETUP=1 SETUPEXEPATH=E:\CD1\ SETUPEXENAME=Setup.exe /lpiwaeo "C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt" STANDALONEOSE="C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\SETUP\OSE.EXE" CDCACHE="2" DELETABLECACHE="1" LOCALCACHEDRIVE="C" DWSETUPLOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001).txt" DWMSILOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt"
Type: msi
Ignore Return Values: False
Reboot: False
Successfully launched MsiExec....
09/08/2008 16:34:44 Chained install return code: 1602
Shutting down chained setup processing.
***** Setup exits
09/08/2008 16:34:44
(return = 1602)
report 2
=== Start writing to log: 09/08/2008 16:33:54 ===
Start of action 16:33:54: INSTALL.
Start of action 16:33:54: SetOfficeProps.
End of action 16:33:56: SetOfficeProps. Return value: 1.
Start of action 16:33:56: LaunchConditions.
End of action 16:33:56: LaunchConditions. Return value: 1.
Start of action 16:33:56: PreActionDialog.
Information 2898. An internal error occurred. (Tahoma8 Tahoma 0 13 )
Information 2898. An internal error occurred. (TahomaContrastBlackBold8 Tahoma 0 13 )
Information 2898. An internal error occurred. (TahomaContrastBlack8 Tahoma 0 13 )
Information 2836. An internal error occurred. (PreActionDialog ActionTextInstall )
Action 16:33:56: PreActionDialog. Dialog created
End of action 16:33:56: PreActionDialog. Return value: 1.
Start of action 16:33:56: FindRelatedProducts.
End of action 16:33:56: FindRelatedProducts. Return value: 0.
Start of action 16:33:56: AppSearch.
Action 16:33:56: AppSearch. Preparing for the installation of Microsoft Office Professional Edition 2003
End of action 16:33:56: AppSearch. Return value: 1.
Start of action 16:33:56: SkuRedReinstall.
End of action 16:33:56: SkuRedReinstall. Return value: 1.
Start of action 16:33:56: CallRegLookup.
End of action 16:33:57: CallRegLookup. Return value: 1.
Start of action 16:33:57: SetSystemMdw.
End of action 16:33:57: SetSystemMdw. Return value: 1.
Start of action 16:33:57: SetSystemNTDir.
End of action 16:33:57: SetSystemNTDir. Return value: 1.
Start of action 16:33:57: ReserveCacheCost.
End of action 16:33:58: ReserveCacheCost. Return value: 1.
Start of action 16:33:58: DIRCA_TARGETDIR.40D5CE2532074296B6DD2138D9286013.
End of action 16:33:58: DIRCA_TARGETDIR.40D5CE2532074296B6DD2138D9286013. Return value: 1.
Start of action 16:33:58: CostInitialize.
End of action 16:33:58: CostInitialize. Return value: 1.
Start of action 16:33:58: OPCMigrateStartFolders.
End of action 16:33:59: OPCMigrateStartFolders. Return value: 1.
Start of action 16:33:59: OPCCleanUpShortcuts.
Action 16:33:59: Cancel. Dialog created
OPCCleanUpShortcuts: install type is per machine
OPCCleanUpShortcuts: searching the profiles of all users
FInsertDarShortcutTable: opcd16524143434f557e322e4c4e4b opcd16 RACCOU~2|Shortcut to EXCEL Global_Excel_Core #EXCEL.EXE -2147483648 -2147483648 1 opcd18
FInsertDarShortcutTable: opcd16524143434f557e332e4c4e4b opcd16 RACCOU~3|Shortcut to MSPUB Global_Publisher_Core #MSPUB.EXE -2147483648 -2147483648 1 opcd18
FInsertDarShortcutTable: opcd16524143434f557e312e4c4e4b opcd16 RACCOU~1|Shortcut to WINWORD Global_Word_Core #WINWORD.EXE -2147483648 -2147483648 1 opcd18
End of action 16:34:03: OPCCleanUpShortcuts. Return value: 1.
Start of action 16:34:03: FileCost.
End of action 16:34:03: FileCost. Return value: 1.
Start of action 16:34:03: CMWMain.
CMWMain FOpenConditionTables: End - succeed
CMWMain User possesses Admin privileges.
CMWMain No CMW File
CMWMain FCloseConditionTables: End - succeed
End of action 16:34:04: CMWMain. Return value: 1.
Start of action 16:34:04: CostFinalize.
End of action 16:34:04: CostFinalize. Return value: 1.
Start of action 16:34:04: SetLocalCacheFolder.
End of action 16:34:04: SetLocalCacheFolder. Return value: 1.
Start of action 16:34:04: SetSMARTSOURCEDIR_SEP.
End of action 16:34:04: SetSMARTSOURCEDIR_SEP. Return value: 1.
Start of action 16:34:04: FeatureDependency.
End of action 16:34:05: FeatureDependency. Return value: 1.
Start of action 16:34:05: SetSetupHelpFileDir_Installed.
End of action 16:34:05: SetSetupHelpFileDir_Installed. Return value: 1.
Start of action 16:34:05: SetSetupPSSHelpFileDir_Installed.
End of action 16:34:05: SetSetupPSSHelpFileDir_Installed. Return value: 1.
Start of action 16:34:05: SetDefaultInstallLocation.
End of action 16:34:05: SetDefaultInstallLocation. Return value: 1.
Start of action 16:34:05: DoDialogSequence.
DoDialogSequence: FindNextDialogtoShow: IN: next (null)
DoDialogSequence: FindNextDialogtoShow: got condition ACTION="ADMIN" AND NOT PATCH evaluated to 0
DoDialogSequence: FindNextDialogtoShow: got condition (NOT RESUME AND ACTION="INSTALL") AND Installed AND NOT Preselected AND NOT CONVERTTRIAL evaluated to 1
DoDialogSequence: FindNextDialogtoShow: Set property CurrentDialog to MMode
DoDialogSequence: FindNextDialogtoShow: Set property NextDialog to MMode
DoDialogSequence: FindNextDialogtoShow: OUT: next MMode
DoDialogSequence: DoDialogSequence: Calling DoAction MMode
Start of action 16:34:06: MMode.
Action 16:34:06: MMode. Dialog created
Start of action 16:34:14: CalcNextDialog.
End of action 16:34:15: CalcNextDialog. Return value: 1.
Information 2898. An internal error occurred. (TahomaBold8 Tahoma 0 13 )
Information 2836. An internal error occurred. (
here are the 2 reports
Detected Windows Info:
PlatformId = 2
MajorVersion = 5
MinorVersion = 1
- - - - - - - - - - - - - - - - - - - - - - -
Launch Setup
09/08/2008 16:32:43
Setup path: E:\CD1\Setup.exe
Trying to get version of
E:\CD1\Setup.exe
...succeeded.
E:\CD1\Setup.exe is version 11.0.5510.0
Current version of Setup.exe: 11.0.5510.0
Searching for .INI file: Setup.INI
E:\CD1\FILES\SETUP\Setup.INI
Settings file located: E:\CD1\FILES\SETUP\Setup.INI
GetTempPath returned: C:\DOCUME~1\magicien\LOCALS~1\Temp\
Reading settings file
E:\CD1\FILES\SETUP\Setup.INI
Located: E:\CD1\PRO11.MSI
Package to install: E:\CD1\PRO11.MSI
Add Property:
PIDKEY=GWH28DGCMPP6RC46J4MT3HFDY
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Product\SkipLangCheck" (Default: 0)
Value: 0
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Product\CheckUpdates" (Default: 0)
Value: 0
Product {9011040C-6000-11D3-8CFE-0150048383C9} is installed for the user.
Read Package Version: 11.0.5614.0
Read Product Version: 11.0.5614.0
Media Package Code: {75419C14-0873-424E-AC03-3945F63E2823}
Installed Package Code: {75419C14-0873-424E-AC03-3945F63E2823}
Checking for Windows Installer....
C:\WINDOWS\System32\MSI.DLL
.. succeeded.
Checking for any beta version of the product.
dwNoLtCoExist = 0
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\CDCache" (Default: 0)
Value: auto
Office-specific properties added: PIDKEY="GWH28DGCMPP6RC46J4MT3HFDY"
General properties added: LAUNCHEDFROMSETUP="1" SETUPEXEPATH="E:\CD1\" SETUPEXENAME="Setup.exe"
Writing Task: Main - Microsoft Office 2003
Path: C:\WINDOWS\System32\msiexec.exe
CmdLine: /I E:\CD1\PRO11.MSI PIDKEY="GWH28DGCMPP6RC46J4MT3HFDY" LAUNCHEDFROMSETUP="1" SETUPEXEPATH="E:\CD1\" SETUPEXENAME="Setup.exe"
Looking for setup tasks to process.
09/08/2008 16:32:44 WaitForMsiExecDone...
WaitForSingleObject...
09/08/2008 16:33:46 WaitForMsiExecDone exits
Verifying install package is available
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\CDCache" (Default: 0)
Value: auto
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\Purge" (Default: 0)
Value: 0
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\DeletableCache" (Default: 0)
Value: 1
SetupXml is at: E:\CD1\Files\Setup\PRO11.xml
Parsing Download Info
Starting to load install configuration
Download Info:
Download Code : 9000040c-6000-11D3-8CFE-0150048383C9
Source Path : E:\CD1\
Product Code : {9011040C-6000-11D3-8CFE-0150048383C9}
Prod Src Path : PRO11.MSI
Use Windows Installer : false
Files to Download:
File: FILES\WINDOWS\INF\AER_1036.ADM (DW20.ADM_1036)
File: FILES\PFILES\COMMON\MSSHARED\DW\DW20.EXE (DW20.EXE_0001)
File: FILES\PFILES\COMMON\MSSHARED\DW\DWDCW20.DLL (DWDCW20.DLL)
File: FILES\PFILES\COMMON\MSSHARED\DW\1036\DWINTL20.DLL (DWINTL20.DLL_0001_1036)
File: FILES\PFILES\COMMON\MSSHARED\DW\DWTRIG20.EXE (DWTRIG20.EXE)
File: FILES\PFILES\MSOFFICE\OFFICE11\OCLEAN.DLL (OCLEAN.DLL_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\OCLNCORE.OPC (OCLNCORE.OPC_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\OCLNCUST.OPC (OCLNCUST.OPC_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\OCLNINTL.OPC (OCLNINTL.OPC_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\OFFCLN.EXE (OFFCLN.EXE_1036)
File: FILES\SETUP\OSE.EXE (OSE.EXE)
File: PRO11.MSI (PRO11.MSI)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\PSS10O.CHM (PSS10O.CHM_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\PSS10R.CHM (PSS10R.CHM_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\SETUP.CHM (SETUP.CHM_1036)
File: SKU011.XML (SKU011.XML_0002_1036)
File: A2561404.CAB (A2561404.CAB)
File: A3561404.CAB (A3561404.CAB)
File: A4561404.CAB (A4561404.CAB)
File: AV561404.CAB (AV561404.CAB)
File: CC561401.CAB (CC561401.CAB)
File: CD561401.CAB (CD561401.CAB)
File: CF561401.CAB (CF561401.CAB)
File: CL561401.CAB (CL561401.CAB)
File: CM561401.CAB (CM561401.CAB)
File: CP561401.CAB (CP561401.CAB)
File: CR561401.CAB (CR561401.CAB)
File: CS561401.CAB (CS561401.CAB)
File: E2561404.CAB (E2561404.CAB)
File: E3561404.CAB (E3561404.CAB)
File: E4561404.CAB (E4561404.CAB)
File: EV561404.CAB (EV561404.CAB)
File: G3561404.CAB (G3561404.CAB)
File: GV561402.CAB (GV561402.CAB)
File: IJ561401.CAB (IJ561401.CAB)
File: IS561401.CAB (IS561401.CAB)
File: IU561401.CAB (IU561401.CAB)
File: L2561404.CAB (L2561404.CAB)
File: L3561405.CAB (L3561405.CAB)
File: L4561405.CAB (L4561405.CAB)
File: L9561402.CAB (L9561402.CAB)
File: LV561405.CAB (LV561405.CAB)
File: M2561403.CAB (M2561403.CAB)
File: M3561403.CAB (M3561403.CAB)
File: M4561403.CAB (M4561403.CAB)
File: M9561401.CAB (M9561401.CAB)
File: MA561405.CAB (MA561405.CAB)
File: MC561403.CAB (MC561403.CAB)
File: MG561403.CAB (MG561403.CAB)
File: MH561401.CAB (MH561401.CAB)
File: MO561404.CAB (MO561404.CAB)
File: MT561403.CAB (MT561403.CAB)
File: O0561401.CAB (O0561401.CAB)
File: O1561407.CAB (O1561407.CAB)
File: O9561402.CAB (O9561402.CAB)
File: P2561404.CAB (P2561404.CAB)
File: P3561405.CAB (P3561405.CAB)
File: P4561405.CAB (P4561405.CAB)
File: PA561401.CAB (PA561401.CAB)
File: PR102593.CAB (PR102593.CAB)
File: PR103196.CAB (PR103196.CAB)
File: PR103369.CAB (PR103369.CAB)
File: PR103601.CAB (PR103601.CAB)
File: PR104301.CAB (PR104301.CAB)
File: PR308246.CAB (PR308246.CAB)
File: PV561405.CAB (PV561405.CAB)
File: PW561405.CAB (PW561405.CAB)
File: Q2561405.CAB (Q2561405.CAB)
File: Q3561405.CAB (Q3561405.CAB)
File: Q4561405.CAB (Q4561405.CAB)
File: QV561405.CAB (QV561405.CAB)
File: SKU011.CAB (SKU011.CAB)
File: TA561401.CAB (TA561401.CAB)
File: TR102537.CAB (TR102537.CAB)
File: TR103113.CAB (TR103113.CAB)
File: TR308222.CAB (TR308222.CAB)
File: V3561402.CAB (V3561402.CAB)
File: W2561405.CAB (W2561405.CAB)
File: W3561405.CAB (W3561405.CAB)
File: W4561405.CAB (W4561405.CAB)
File: WV561405.CAB (WV561405.CAB)
File: X2561405.CAB (X2561405.CAB)
File: X3561405.CAB (X3561405.CAB)
File: YA561403.CAB (YA561403.CAB)
File: YB561403.CAB (YB561403.CAB)
File: YC561403.CAB (YC561403.CAB)
File: YH561402.CAB (YH561402.CAB)
File: YI561401.CAB (YI561401.CAB)
File: YL561403.CAB (YL561403.CAB)
File: YM561403.CAB (YM561403.CAB)
File: YO561402.CAB (YO561402.CAB)
File: YT561401.CAB (YT561401.CAB)
File: ZA561401.CAB (ZA561401.CAB)
File: ZC561402.CAB (ZC561402.CAB)
File: ZD561403.CAB (ZD561403.CAB)
File: ZE561402.CAB (ZE561402.CAB)
File: ZF561402.CAB (ZF561402.CAB)
File: ZG561401.CAB (ZG561401.CAB)
File: ZH561403.CAB (ZH561403.CAB)
File: ZI561402.CAB (ZI561402.CAB)
File: ZJ561401.CAB (ZJ561401.CAB)
File: ZK561401.CAB (ZK561401.CAB)
File: ZM561401.CAB (ZM561401.CAB)
File: ZN561401.CAB (ZN561401.CAB)
File: ZO561403.CAB (ZO561403.CAB)
File: ZQ561401.CAB (ZQ561401.CAB)
File: ZR561402.CAB (ZR561402.CAB)
File: ZS561401.CAB (ZS561401.CAB)
File: ZT561401.CAB (ZT561401.CAB)
File: ZU561405.CAB (ZU561405.CAB)
File: ZV561401.CAB (ZV561401.CAB)
File: ZY561403.CAB (ZY561403.CAB)
File: ZZ561401.CAB (ZZ561401.CAB)
File: FILES\SETUP\SETUP.INI (PRO11.INI)
File: SETUP.EXE (SETUP.EXE_1036)
Using Office Source Engine at path: E:\CD1\FILES\SETUP\OSE.EXE
Successfully started Office Source Engine in stand-alone mode.
Using Local Cache Drive of already installed product: C:\.
Found pre-existing download, will use this as default drive for local cache.
Found enough space on drive "C:\" to cache all feature cabinets.
(CDCACHE=AUTO) - There is enough space to cache some or all of the image. Drive for this download is C:\
Completed download for file: DW20.ADM_1036.
Completed download for file: DW20.EXE_0001.
Completed download for file: DWDCW20.DLL.
Completed download for file: DWINTL20.DLL_0001_1036.
Completed download for file: DWTRIG20.EXE.
Completed download for file: OCLEAN.DLL_1036.
Completed download for file: OCLNCORE.OPC_1036.
Completed download for file: OCLNCUST.OPC_1036.
Completed download for file: OCLNINTL.OPC_1036.
Completed download for file: OFFCLN.EXE_1036.
Completed download for file: OSE.EXE.
Completed download for file: PRO11.MSI.
Completed download for file: PSS10O.CHM_1036.
Completed download for file: PSS10R.CHM_1036.
Completed download for file: SETUP.CHM_1036.
Completed download for file: SKU011.XML_0002_1036.
Finished CDCache Download, retrieving msi download info
09/08/2008 16:33:53
Package was: E:\CD1\PRO11.MSI.
Setting Package to: C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\PRO11.MSI.
Done with CD Caching, cached MSI to: C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\PRO11.MSI
09/08/2008 16:33:53
Parsed arg: /I
Parsed arg: E:\CD1\PRO11.MSI
Parsed arg: PIDKEY=GWH28DGCMPP6RC46J4MT3HFDY
Parsed arg: LAUNCHEDFROMSETUP=1
Parsed arg: SETUPEXEPATH=E:\CD1\
Parsed arg: SETUPEXENAME=Setup.exe
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\Purge" (Default: 0)
Value: 0
Finished local caching successfully.
DWSETUPLOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001).txt"
DWMSILOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt"
Command Line Logging Parameters: /lpiwaeo "C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt"
09/08/2008 16:33:53
Executing Task:
Microsoft Office 2003
"C:\WINDOWS\System32\msiexec.exe" /I "C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\PRO11.MSI" PIDKEY=GWH28DGCMPP6RC46J4MT3HFDY LAUNCHEDFROMSETUP=1 SETUPEXEPATH=E:\CD1\ SETUPEXENAME=Setup.exe /lpiwaeo "C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt" STANDALONEOSE="C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\SETUP\OSE.EXE" CDCACHE="2" DELETABLECACHE="1" LOCALCACHEDRIVE="C" DWSETUPLOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001).txt" DWMSILOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt"
Type: msi
Ignore Return Values: False
Reboot: False
Successfully launched MsiExec....
09/08/2008 16:34:44 Chained install return code: 1602
Shutting down chained setup processing.
***** Setup exits
09/08/2008 16:34:44
(return = 1602)
report 2
=== Start writing to the log: 09/08/2008 16:33:54 ===
Start of action 16:33:54: INSTALL.
Start of action 16:33:54: SetOfficeProps.
End of action 16:33:56: SetOfficeProps. Return value: 1.
Start of action 16:33:56: LaunchConditions.
End of action 16:33:56: LaunchConditions. Return value: 1.
Start of action 16:33:56: PreActionDialog.
Information 2898. An internal error occurred. (Tahoma8 Tahoma 0 13 )
Information 2898. An internal error occurred. (TahomaContrastBlackBold8 Tahoma 0 13 )
Information 2898. An internal error occurred. (TahomaContrastBlack8 Tahoma 0 13 )
Information 2836. An internal error occurred. (PreActionDialog ActionTextInstall )
Action 16:33:56: PreActionDialog. Dialog created
End of action 16:33:56: PreActionDialog. Return value: 1.
Start of action 16:33:56: FindRelatedProducts.
End of action 16:33:56: FindRelatedProducts. Return value: 0.
Start of action 16:33:56: AppSearch.
Action 16:33:56: AppSearch. Preparing installation of Microsoft Office Professional Edition 2003
End of action 16:33:56: AppSearch. Return value: 1.
Start of action 16:33:56: SkuRedReinstall.
End of action 16:33:56: SkuRedReinstall. Return value: 1.
Start of action 16:33:56: CallRegLookup.
End of action 16:33:57: CallRegLookup. Return value: 1.
Start of action 16:33:57: SetSystemMdw.
End of action 16:33:57: SetSystemMdw. Return value: 1.
Start of action 16:33:57: SetSystemNTDir.
End of action 16:33:57: SetSystemNTDir. Return value: 1.
Start of action 16:33:57: ReserveCacheCost.
End of action 16:33:58: ReserveCacheCost. Return value: 1.
Start of action 16:33:58: DIRCA_TARGETDIR.40D5CE2532074296B6DD2138D9286013.
End of action 16:33:58: DIRCA_TARGETDIR.40D5CE2532074296B6DD2138D9286013. Return value: 1.
Start of action 16:33:58: CostInitialize.
End of action 16:33:58: CostInitialize. Return value: 1.
Start of action 16:33:58: OPCMigrateStartFolders.
End of action 16:33:59: OPCMigrateStartFolders. Return value: 1.
Start of action 16:33:59: OPCCleanUpShortcuts.
Action 16:33:59: Cancel. Dialog created
OPCCleanUpShortcuts: install type is per machine
OPCCleanUpShortcuts: searching the profiles of all users
FInsertDarShortcutTable: opcd16524143434f557e322e4c4e4b opcd16 RACCOU~2|Shortcut to EXCEL Global_Excel_Core #EXCEL.EXE -2147483648 -2147483648 1 opcd18
FInsertDarShortcutTable: opcd16524143434f557e332e4c4e4b opcd16 RACCOU~3|Shortcut to MSPUB Global_Publisher_Core #MSPUB.EXE -2147483648 -2147483648 1 opcd18
FInsertDarShortcutTable: opcd16524143434f557e312e4c4e4b opcd16 RACCOU~1|Shortcut to WINWORD Global_Word_Core #WINWORD.EXE -2147483648 -2147483648 1 opcd18
End of action 16:34:03: OPCCleanUpShortcuts. Return value: 1.
Start of action 16:34:03: FileCost.
End of action 16:34:03: FileCost. Return value: 1.
Start of action 16:34:03: CMWMain.
CMWMain FOpenConditionTables: End - succeed
CMWMain User possesses Admin privileges.
CMWMain No CMW File
CMWMain FCloseConditionTables: End - succeed
End of action 16:34:04: CMWMain. Return value: 1.
Start of action 16:34:04: CostFinalize.
End of action 16:34:04: CostFinalize. Return value: 1.
Start of action 16:34:04: SetLocalCacheFolder.
End of action 16:34:04: SetLocalCacheFolder. Return value: 1.
Start of action 16:34:04: SetSMARTSOURCEDIR_SEP.
End of action 16:34:04: SetSMARTSOURCEDIR_SEP. Return value: 1.
Start of action 16:34:04: FeatureDependency.
End of action 16:34:05: FeatureDependency. Return value: 1.
Start of action 16:34:05: SetSetupHelpFileDir_Installed.
End of action 16:34:05: SetSetupHelpFileDir_Installed. Return value: 1.
Start of action 16:34:05: SetSetupPSSHelpFileDir_Installed.
End of action 16:34:05: SetSetupPSSHelpFileDir_Installed. Return value: 1.
Start of action 16:34:05: SetDefaultInstallLocation.
End of action 16:34:05: SetDefaultInstallLocation. Return value: 1.
Start of action 16:34:05: DoDialogSequence.
DoDialogSequence: FindNextDialogtoShow: IN: next (null)
DoDialogSequence: FindNextDialogtoShow: got condition ACTION="ADMIN" AND NOT PATCH evaluated to 0
DoDialogSequence: FindNextDialogtoShow: got condition (NOT RESUME AND ACTION="INSTALL") AND Installed AND NOT Preselected AND NOT CONVERTTRIAL evaluated to 1
DoDialogSequence: FindNextDialogtoShow: Set property CurrentDialog to MMode
DoDialogSequence: FindNextDialogtoShow: Set property NextDialog to MMode
DoDialogSequence: FindNextDialogtoShow: OUT: next MMode
DoDialogSequence: DoDialogSequence: Calling DoAction MMode
Start of action 16:34:06: MMode.
Action 16:34:06: MMode. Dialog created
Start of action 16:34:14: CalcNextDialog.
End of action 16:34:15: CalcNextDialog. Return value: 1.
Information 2898. An internal error occurred. (TahomaBold8 Tahoma 0 13 )
Information 2836. An internal error occurred. (PreActionDialog ActionTextInstall )
Detected Windows Info:
PlatformId = 2
MajorVersion = 5
MinorVersion = 1
- - - - - - - - - - - - - - - - - - - - - - -
Launch Setup
09/08/2008 16:32:43
Setup path: E:\CD1\Setup.exe
Trying to get version of
E:\CD1\Setup.exe
...succeeded.
E:\CD1\Setup.exe is version 11.0.5510.0
Current version of Setup.exe: 11.0.5510.0
Searching for .INI file: Setup.INI
E:\CD1\FILES\SETUP\Setup.INI
Settings file located: E:\CD1\FILES\SETUP\Setup.INI
GetTempPath returned: C:\DOCUME~1\magicien\LOCALS~1\Temp\
Reading settings file
E:\CD1\FILES\SETUP\Setup.INI
Located: E:\CD1\PRO11.MSI
Package to install: E:\CD1\PRO11.MSI
Add Property:
PIDKEY=GWH28DGCMPP6RC46J4MT3HFDY
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Product\SkipLangCheck" (Default: 0)
Value: 0
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Product\CheckUpdates" (Default: 0)
Value: 0
Product {9011040C-6000-11D3-8CFE-0150048383C9} is installed for the user.
Read Package Version: 11.0.5614.0
Read Product Version: 11.0.5614.0
Media Package Code: {75419C14-0873-424E-AC03-3945F63E2823}
Installed Package Code: {75419C14-0873-424E-AC03-3945F63E2823}
Checking for Windows Installer....
C:\WINDOWS\System32\MSI.DLL
.. succeeded.
Checking for any beta version of the product.
dwNoLtCoExist = 0
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\CDCache" (Default: 0)
Value: auto
Office-specific properties added: PIDKEY="GWH28DGCMPP6RC46J4MT3HFDY"
General properties added: LAUNCHEDFROMSETUP="1" SETUPEXEPATH="E:\CD1\" SETUPEXENAME="Setup.exe"
Writing Task: Main - Microsoft Office 2003
Path: C:\WINDOWS\System32\msiexec.exe
CmdLine: /I E:\CD1\PRO11.MSI PIDKEY="GWH28DGCMPP6RC46J4MT3HFDY" LAUNCHEDFROMSETUP="1" SETUPEXEPATH="E:\CD1\" SETUPEXENAME="Setup.exe"
Looking for setup tasks to process.
09/08/2008 16:32:44 WaitForMsiExecDone...
WaitForSingleObject...
09/08/2008 16:33:46 WaitForMsiExecDone exits
Verifying install package is available
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\CDCache" (Default: 0)
Value: auto
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\Purge" (Default: 0)
Value: 0
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\DeletableCache" (Default: 0)
Value: 1
SetupXml is at: E:\CD1\Files\Setup\PRO11.xml
Parsing Download Info
Starting to load install configuration
Download Info:
Download Code : 9000040c-6000-11D3-8CFE-0150048383C9
Source Path : E:\CD1\
Product Code : {9011040C-6000-11D3-8CFE-0150048383C9}
Prod Src Path : PRO11.MSI
Use Windows Installer : false
Files to Download:
File: FILES\WINDOWS\INF\AER_1036.ADM (DW20.ADM_1036)
File: FILES\PFILES\COMMON\MSSHARED\DW\DW20.EXE (DW20.EXE_0001)
File: FILES\PFILES\COMMON\MSSHARED\DW\DWDCW20.DLL (DWDCW20.DLL)
File: FILES\PFILES\COMMON\MSSHARED\DW\1036\DWINTL20.DLL (DWINTL20.DLL_0001_1036)
File: FILES\PFILES\COMMON\MSSHARED\DW\DWTRIG20.EXE (DWTRIG20.EXE)
File: FILES\PFILES\MSOFFICE\OFFICE11\OCLEAN.DLL (OCLEAN.DLL_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\OCLNCORE.OPC (OCLNCORE.OPC_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\OCLNCUST.OPC (OCLNCUST.OPC_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\OCLNINTL.OPC (OCLNINTL.OPC_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\OFFCLN.EXE (OFFCLN.EXE_1036)
File: FILES\SETUP\OSE.EXE (OSE.EXE)
File: PRO11.MSI (PRO11.MSI)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\PSS10O.CHM (PSS10O.CHM_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\PSS10R.CHM (PSS10R.CHM_1036)
File: FILES\PFILES\MSOFFICE\OFFICE11\1036\SETUP.CHM (SETUP.CHM_1036)
File: SKU011.XML (SKU011.XML_0002_1036)
File: A2561404.CAB (A2561404.CAB)
File: A3561404.CAB (A3561404.CAB)
File: A4561404.CAB (A4561404.CAB)
File: AV561404.CAB (AV561404.CAB)
File: CC561401.CAB (CC561401.CAB)
File: CD561401.CAB (CD561401.CAB)
File: CF561401.CAB (CF561401.CAB)
File: CL561401.CAB (CL561401.CAB)
File: CM561401.CAB (CM561401.CAB)
File: CP561401.CAB (CP561401.CAB)
File: CR561401.CAB (CR561401.CAB)
File: CS561401.CAB (CS561401.CAB)
File: E2561404.CAB (E2561404.CAB)
File: E3561404.CAB (E3561404.CAB)
File: E4561404.CAB (E4561404.CAB)
File: EV561404.CAB (EV561404.CAB)
File: G3561404.CAB (G3561404.CAB)
File: GV561402.CAB (GV561402.CAB)
File: IJ561401.CAB (IJ561401.CAB)
File: IS561401.CAB (IS561401.CAB)
File: IU561401.CAB (IU561401.CAB)
File: L2561404.CAB (L2561404.CAB)
File: L3561405.CAB (L3561405.CAB)
File: L4561405.CAB (L4561405.CAB)
File: L9561402.CAB (L9561402.CAB)
File: LV561405.CAB (LV561405.CAB)
File: M2561403.CAB (M2561403.CAB)
File: M3561403.CAB (M3561403.CAB)
File: M4561403.CAB (M4561403.CAB)
File: M9561401.CAB (M9561401.CAB)
File: MA561405.CAB (MA561405.CAB)
File: MC561403.CAB (MC561403.CAB)
File: MG561403.CAB (MG561403.CAB)
File: MH561401.CAB (MH561401.CAB)
File: MO561404.CAB (MO561404.CAB)
File: MT561403.CAB (MT561403.CAB)
File: O0561401.CAB (O0561401.CAB)
File: O1561407.CAB (O1561407.CAB)
File: O9561402.CAB (O9561402.CAB)
File: P2561404.CAB (P2561404.CAB)
File: P3561405.CAB (P3561405.CAB)
File: P4561405.CAB (P4561405.CAB)
File: PA561401.CAB (PA561401.CAB)
File: PR102593.CAB (PR102593.CAB)
File: PR103196.CAB (PR103196.CAB)
File: PR103369.CAB (PR103369.CAB)
File: PR103601.CAB (PR103601.CAB)
File: PR104301.CAB (PR104301.CAB)
File: PR308246.CAB (PR308246.CAB)
File: PV561405.CAB (PV561405.CAB)
File: PW561405.CAB (PW561405.CAB)
File: Q2561405.CAB (Q2561405.CAB)
File: Q3561405.CAB (Q3561405.CAB)
File: Q4561405.CAB (Q4561405.CAB)
File: QV561405.CAB (QV561405.CAB)
File: SKU011.CAB (SKU011.CAB)
File: TA561401.CAB (TA561401.CAB)
File: TR102537.CAB (TR102537.CAB)
File: TR103113.CAB (TR103113.CAB)
File: TR308222.CAB (TR308222.CAB)
File: V3561402.CAB (V3561402.CAB)
File: W2561405.CAB (W2561405.CAB)
File: W3561405.CAB (W3561405.CAB)
File: W4561405.CAB (W4561405.CAB)
File: WV561405.CAB (WV561405.CAB)
File: X2561405.CAB (X2561405.CAB)
File: X3561405.CAB (X3561405.CAB)
File: YA561403.CAB (YA561403.CAB)
File: YB561403.CAB (YB561403.CAB)
File: YC561403.CAB (YC561403.CAB)
File: YH561402.CAB (YH561402.CAB)
File: YI561401.CAB (YI561401.CAB)
File: YL561403.CAB (YL561403.CAB)
File: YM561403.CAB (YM561403.CAB)
File: YO561402.CAB (YO561402.CAB)
File: YT561401.CAB (YT561401.CAB)
File: ZA561401.CAB (ZA561401.CAB)
File: ZC561402.CAB (ZC561402.CAB)
File: ZD561403.CAB (ZD561403.CAB)
File: ZE561402.CAB (ZE561402.CAB)
File: ZF561402.CAB (ZF561402.CAB)
File: ZG561401.CAB (ZG561401.CAB)
File: ZH561403.CAB (ZH561403.CAB)
File: ZI561402.CAB (ZI561402.CAB)
File: ZJ561401.CAB (ZJ561401.CAB)
File: ZK561401.CAB (ZK561401.CAB)
File: ZM561401.CAB (ZM561401.CAB)
File: ZN561401.CAB (ZN561401.CAB)
File: ZO561403.CAB (ZO561403.CAB)
File: ZQ561401.CAB (ZQ561401.CAB)
File: ZR561402.CAB (ZR561402.CAB)
File: ZS561401.CAB (ZS561401.CAB)
File: ZT561401.CAB (ZT561401.CAB)
File: ZU561405.CAB (ZU561405.CAB)
File: ZV561401.CAB (ZV561401.CAB)
File: ZY561403.CAB (ZY561403.CAB)
File: ZZ561401.CAB (ZZ561401.CAB)
File: FILES\SETUP\SETUP.INI (PRO11.INI)
File: SETUP.EXE (SETUP.EXE_1036)
Using Office Source Engine at path: E:\CD1\FILES\SETUP\OSE.EXE
Successfully started Office Source Engine in stand-alone mode.
Using Local Cache Drive of already installed product: C:\.
Found pre-existing download, will use this as default drive for local cache.
Found enough space on drive "C:\" to cache all feature cabinets.
(CDCACHE=AUTO) - There is enough space to cache some or all of the image. Drive for this download is C:\
Completed download for file: DW20.ADM_1036.
Completed download for file: DW20.EXE_0001.
Completed download for file: DWDCW20.DLL.
Completed download for file: DWINTL20.DLL_0001_1036.
Completed download for file: DWTRIG20.EXE.
Completed download for file: OCLEAN.DLL_1036.
Completed download for file: OCLNCORE.OPC_1036.
Completed download for file: OCLNCUST.OPC_1036.
Completed download for file: OCLNINTL.OPC_1036.
Completed download for file: OFFCLN.EXE_1036.
Completed download for file: OSE.EXE.
Completed download for file: PRO11.MSI.
Completed download for file: PSS10O.CHM_1036.
Completed download for file: PSS10R.CHM_1036.
Completed download for file: SETUP.CHM_1036.
Completed download for file: SKU011.XML_0002_1036.
Finished CDCache Download, retrieving msi download info
09/08/2008 16:33:53
Package was: E:\CD1\PRO11.MSI.
Setting Package to: C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\PRO11.MSI.
Done with CD Caching, cached MSI to: C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\PRO11.MSI
09/08/2008 16:33:53
Parsed arg: /I
Parsed arg: E:\CD1\PRO11.MSI
Parsed arg: PIDKEY=GWH28DGCMPP6RC46J4MT3HFDY
Parsed arg: LAUNCHEDFROMSETUP=1
Parsed arg: SETUPEXEPATH=E:\CD1\
Parsed arg: SETUPEXENAME=Setup.exe
Reading from "E:\CD1\FILES\SETUP\Setup.INI": "Cache\Purge" (Default: 0)
Value: 0
Finished local caching successfully.
DWSETUPLOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001).txt"
DWMSILOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt"
Command Line Logging Parameters: /lpiwaeo "C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt"
09/08/2008 16:33:53
Executing Task:
Microsoft Office 2003
"C:\WINDOWS\System32\msiexec.exe" /I "C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\PRO11.MSI" PIDKEY=GWH28DGCMPP6RC46J4MT3HFDY LAUNCHEDFROMSETUP=1 SETUPEXEPATH=E:\CD1\ SETUPEXENAME=Setup.exe /lpiwaeo "C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt" STANDALONEOSE="C:\MSOCache\All Users\9000040c-6000-11D3-8CFE-0150048383C9\FILES\SETUP\OSE.EXE" CDCACHE="2" DELETABLECACHE="1" LOCALCACHEDRIVE="C" DWSETUPLOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001).txt" DWMSILOGFILE="C:\DOCUME~1\magicien\LOCALS~1\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt"
Type: msi
Ignore Return Values: False
Reboot: False
Successfully launched MsiExec....
09/08/2008 16:34:44 Chained install return code: 1602
Shutting down chained setup processing.
***** Setup exits
09/08/2008 16:34:44
(return = 1602)
report 2
=== Start writing to the log: 09/08/2008 16:33:54 ===
Start of action 16:33:54: INSTALL.
Start of action 16:33:54: SetOfficeProps.
End of action 16:33:56: SetOfficeProps. Return value: 1.
Start of action 16:33:56: LaunchConditions.
End of action 16:33:56: LaunchConditions. Return value: 1.
Start of action 16:33:56: PreActionDialog.
Information 2898. An internal error occurred. (Tahoma8 Tahoma 0 13 )
Information 2898. An internal error occurred. (TahomaContrastBlackBold8 Tahoma 0 13 )
Information 2898. An internal error occurred. (TahomaContrastBlack8 Tahoma 0 13 )
Information 2836. An internal error occurred. (PreActionDialog ActionTextInstall )
Action 16:33:56: PreActionDialog. Dialog created
End of action 16:33:56: PreActionDialog. Return value: 1.
Start of action 16:33:56: FindRelatedProducts.
End of action 16:33:56: FindRelatedProducts. Return value: 0.
Start of action 16:33:56: AppSearch.
Action 16:33:56: AppSearch. Preparing installation of Microsoft Office Professional Edition 2003
End of action 16:33:56: AppSearch. Return value: 1.
Start of action 16:33:56: SkuRedReinstall.
End of action 16:33:56: SkuRedReinstall. Return value: 1.
Start of action 16:33:56: CallRegLookup.
End of action 16:33:57: CallRegLookup. Return value: 1.
Start of action 16:33:57: SetSystemMdw.
End of action 16:33:57: SetSystemMdw. Return value: 1.
Start of action 16:33:57: SetSystemNTDir.
End of action 16:33:57: SetSystemNTDir. Return value: 1.
Start of action 16:33:57: ReserveCacheCost.
End of action 16:33:58: ReserveCacheCost. Return value: 1.
Start of action 16:33:58: DIRCA_TARGETDIR.40D5CE2532074296B6DD2138D9286013.
End of action 16:33:58: DIRCA_TARGETDIR.40D5CE2532074296B6DD2138D9286013. Return value: 1.
Start of action 16:33:58: CostInitialize.
End of action 16:33:58: CostInitialize. Return value: 1.
Start of action 16:33:58: OPCMigrateStartFolders.
End of action 16:33:59: OPCMigrateStartFolders. Return value: 1.
Start of action 16:33:59: OPCCleanUpShortcuts.
Action 16:33:59: Cancel. Dialog created
OPCCleanUpShortcuts: install type is per machine
OPCCleanUpShortcuts: searching the profiles of all users
FInsertDarShortcutTable: opcd16524143434f557e322e4c4e4b opcd16 RACCOU~2|Shortcut to EXCEL Global_Excel_Core #EXCEL.EXE -2147483648 -2147483648 1 opcd18
FInsertDarShortcutTable: opcd16524143434f557e332e4c4e4b opcd16 RACCOU~3|Shortcut to MSPUB Global_Publisher_Core #MSPUB.EXE -2147483648 -2147483648 1 opcd18
FInsertDarShortcutTable: opcd16524143434f557e312e4c4e4b opcd16 RACCOU~1|Shortcut to WINWORD Global_Word_Core #WINWORD.EXE -2147483648 -2147483648 1 opcd18
End of action 16:34:03: OPCCleanUpShortcuts. Return value: 1.
Start of action 16:34:03: FileCost.
End of action 16:34:03: FileCost. Return value: 1.
Start of action 16:34:03: CMWMain.
CMWMain FOpenConditionTables: End - succeed
CMWMain User possesses Admin privileges.
CMWMain No CMW File
CMWMain FCloseConditionTables: End - succeed
End of action 16:34:04: CMWMain. Return value: 1.
Start of action 16:34:04: CostFinalize.
End of action 16:34:04: CostFinalize. Return value: 1.
Start of action 16:34:04: SetLocalCacheFolder.
End of action 16:34:04: SetLocalCacheFolder. Return value: 1.
Start of action 16:34:04: SetSMARTSOURCEDIR_SEP.
End of action 16:34:04: SetSMARTSOURCEDIR_SEP. Return value: 1.
Start of action 16:34:04: FeatureDependency.
End of action 16:34:05: FeatureDependency. Return value: 1.
Start of action 16:34:05: SetSetupHelpFileDir_Installed.
End of action 16:34:05: SetSetupHelpFileDir_Installed. Return value: 1.
Start of action 16:34:05: SetSetupPSSHelpFileDir_Installed.
End of action 16:34:05: SetSetupPSSHelpFileDir_Installed. Return value: 1.
Start of action 16:34:05: SetDefaultInstallLocation.
End of action 16:34:05: SetDefaultInstallLocation. Return value: 1.
Start of action 16:34:05: DoDialogSequence.
DoDialogSequence: FindNextDialogtoShow: IN: next (null)
DoDialogSequence: FindNextDialogtoShow: got condition ACTION="ADMIN" AND NOT PATCH evaluated to 0
DoDialogSequence: FindNextDialogtoShow: got condition (NOT RESUME AND ACTION="INSTALL") AND Installed AND NOT Preselected AND NOT CONVERTTRIAL evaluated to 1
DoDialogSequence: FindNextDialogtoShow: Set property CurrentDialog to MMode
DoDialogSequence: FindNextDialogtoShow: Set property NextDialog to MMode
DoDialogSequence: FindNextDialogtoShow: OUT: next MMode
DoDialogSequence: DoDialogSequence: Calling DoAction MMode
Start of action 16:34:06: MMode.
Action 16:34:06: MMode. Dialog created
Start of action 16:34:14: CalcNextDialog.
End of action 16:34:15: CalcNextDialog. Return value: 1.
Information 2898. An internal error occurred. (TahomaBold8 Tahoma 0 13 )
Information 2836. An internal error occurred. (PreActionDialog ActionTextInstall )
It's the report main.txt that has to be
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki.
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki.
I'm sorry for this duplicate
here is the report
Deckard's System Scanner v20071014.68
Run by magician on 2008-08-10 00:12:45
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-08-09 22:12:47 UTC - RP1 - System checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as magician.exe) --------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:14:23, on 10/08/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Softwin\BitDefender10\bdmcon.exe
C:\Program Files\Glary Utilities\Integrator.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\magician\My Documents\wink\dss.exe
F:\UTILIT~1\LOGICI~1\magician.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.minet.net:81
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: Helper for Adobe PDF Reader Link - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Burn4Free Toolbar Helper - {D187A56B-A33F-4CBE-9D77-459FC0BAE012} - C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: Burn4Free Toolbar - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: E&xporter to Microsoft Excel - res://D:\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_activex/fr/TSEasyInstallX.CAB
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
O18 - Protocol: bw+0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
--
End of file - 18064 bytes
-- File Associations -----------------------------------------------------------
[COLOR=red].cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*/COLOR
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 prohlp02 (StarForce Protection Helper Driver v2) - c:\windows\system32\drivers\prohlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp01 (StarForce Protection Helper Driver) - c:\windows\system32\drivers\sfhlp01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfvfs02 (StarForce Protection VFS Driver (version 2.x)) - c:\windows\system32\drivers\sfvfs02.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 bdpredir - c:\program files\softwin\bitdefender10\bdpredir.sys <Not Verified; Softwin SRL; BitDefender 10>
R1 papycpu2 - c:\windows\system32\drivers\papycpu2.sys
R1 papyjoy - c:\windows\system32\drivers\papyjoy.sys
R1 prodrv06 (StarForce Protection Environment Driver v6) - c:\windows\system32\drivers\prodrv06.sys <Not Verified; Protection Technology; StarForce Protection System>
R2 athsgt - c:\windows\system32\drivers\athsgt.sys
R2 limsgt - c:\windows\system32\drivers\limsgt.sys
R3 fcdabus - c:\windows\system32\drivers\fcdabus.sys <Not Verified; FarStone Inc.; >
R3 FVDSCSI - c:\windows\system32\drivers\fvdscsi.sys <Not Verified; FarStone Inc.; FarStone VirtualDrive>
R3 LVPrcMon (Logitech LVPrcMon Driver) - c:\windows\system32\drivers\lvprcmon.sys
S0 FVXSCSI - c:\windows\system32\drivers\fvxscsi.sys (file missing)
S0 viaagp1 (VIA AGP Filter) - c:\windows\system32\drivers\viaagp1.sys (file missing)
S3 Amps2prt (Trust Ami PS/2 Port Mouse Driver (6)) - c:\windows\system32\drivers\amps2prt.sys <Not Verified; (Standard Mouse Types); iWheelWorks Mouse Driver>
S3 catchme - c:\docume~1\magician\locals~1\temp\catchme.sys (file missing)
S3 ezplay (VSO Software ezplay) - c:\windows\system32\drivers\ezplay.sys <Not Verified; VSO Software; autoplay Application>
S3 FETNDIS (VIA PCI Fast Ethernet NT Driver 10/100Mo) - c:\windows\system32\drivers\fetnd5.sys (file missing)
S3 fsRamDsk (RamDisk Drive Service) - c:\windows\system32\drivers\fsramdsk.sys <Not Verified; FarStone; FarStone RamDisk>
S3 GVCplDrv - c:\windows\system32\drivers\gvcpldrv.sys
S3 PCAMPR5 (PCAMPR5 NDIS Protocol Driver) - c:\windows\system32\pcampr5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
S3 PCANDIS5 (PCANDIS5 NDIS Protocol Driver) - c:\windows\system32\pcandis5.sys
here is the report
Deckard's System Scanner v20071014.68
Run by magician on 2008-08-10 00:12:45
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-08-09 22:12:47 UTC - RP1 - System checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as magician.exe) --------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:14:23, on 10/08/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Softwin\BitDefender10\bdmcon.exe
C:\Program Files\Glary Utilities\Integrator.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\magician\My Documents\wink\dss.exe
F:\UTILIT~1\LOGICI~1\magician.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.minet.net:81
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: Helper for Adobe PDF Reader Link - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Burn4Free Toolbar Helper - {D187A56B-A33F-4CBE-9D77-459FC0BAE012} - C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: Burn4Free Toolbar - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: E&xporter to Microsoft Excel - res://D:\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_activex/fr/TSEasyInstallX.CAB
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
O18 - Protocol: bw+0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {89238DCB-13FA-49D9-8F87-DD099B15C9C8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
--
End of file - 18064 bytes
-- File Associations -----------------------------------------------------------
[COLOR=red].cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*/COLOR
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 prohlp02 (StarForce Protection Helper Driver v2) - c:\windows\system32\drivers\prohlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp01 (StarForce Protection Helper Driver) - c:\windows\system32\drivers\sfhlp01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfvfs02 (StarForce Protection VFS Driver (version 2.x)) - c:\windows\system32\drivers\sfvfs02.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 bdpredir - c:\program files\softwin\bitdefender10\bdpredir.sys <Not Verified; Softwin SRL; BitDefender 10>
R1 papycpu2 - c:\windows\system32\drivers\papycpu2.sys
R1 papyjoy - c:\windows\system32\drivers\papyjoy.sys
R1 prodrv06 (StarForce Protection Environment Driver v6) - c:\windows\system32\drivers\prodrv06.sys <Not Verified; Protection Technology; StarForce Protection System>
R2 athsgt - c:\windows\system32\drivers\athsgt.sys
R2 limsgt - c:\windows\system32\drivers\limsgt.sys
R3 fcdabus - c:\windows\system32\drivers\fcdabus.sys <Not Verified; FarStone Inc.; >
R3 FVDSCSI - c:\windows\system32\drivers\fvdscsi.sys <Not Verified; FarStone Inc.; FarStone VirtualDrive>
R3 LVPrcMon (Logitech LVPrcMon Driver) - c:\windows\system32\drivers\lvprcmon.sys
S0 FVXSCSI - c:\windows\system32\drivers\fvxscsi.sys (file missing)
S0 viaagp1 (VIA AGP Filter) - c:\windows\system32\drivers\viaagp1.sys (file missing)
S3 Amps2prt (Trust Ami PS/2 Port Mouse Driver (6)) - c:\windows\system32\drivers\amps2prt.sys <Not Verified; (Standard Mouse Types); iWheelWorks Mouse Driver>
S3 catchme - c:\docume~1\magician\locals~1\temp\catchme.sys (file missing)
S3 ezplay (VSO Software ezplay) - c:\windows\system32\drivers\ezplay.sys <Not Verified; VSO Software; autoplay Application>
S3 FETNDIS (VIA PCI Fast Ethernet NT Driver 10/100Mo) - c:\windows\system32\drivers\fetnd5.sys (file missing)
S3 fsRamDsk (RamDisk Drive Service) - c:\windows\system32\drivers\fsramdsk.sys <Not Verified; FarStone; FarStone RamDisk>
S3 GVCplDrv - c:\windows\system32\drivers\gvcpldrv.sys
S3 PCAMPR5 (PCAMPR5 NDIS Protocol Driver) - c:\windows\system32\pcampr5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
S3 PCANDIS5 (PCANDIS5 NDIS Protocol Driver) - c:\windows\system32\pcandis5.sys
+1 for Jacques
--
Must listen: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki.
--
Must listen: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki.
Download OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (by Old_Timer) to your Desktop.
Double-click on OTMoveIt.exe to launch it.
Make sure the Unregister Dll's and Ocx's checkbox is checked
Copy the list below in bold,
and paste it into the left box of OTMoveIt: Paste List of Files/Folders to be moved.
C:\WINDOWS\System32\WS2Fix.exe
C:\WINDOWS\System32\VCCLSID.exe
C:\WINDOWS\System32\VACFix.exe
C:\WINDOWS\System32\SrchSTS.exe
C:\WINDOWS\System32\IEDFix.exe
C:\WINDOWS\System32\dumphive.exe
C:\WINDOWS\System32\404Fix.exe
C:\Program Files\Navilog1
Click on MoveIt! to start the deletion.
The result will appear in the "Results" box.
Click on Exit to close.
Post the report located in C:\_OTMoveIt\MovedFiles.
Then:
* To remove the tools/fixes used:
Download ToolsCleaner to your desktop.
-->
ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
http://pc-system.fr/
# Click on Search and let the scan run...
# Click on Delete to finish.
# You can, if you wish, use the Optional Options.
# Click on Exit to obtain the report.
# Post the report (TCleaner.txt) located at the root of your hard drive (C:\).
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki.
Double-click on OTMoveIt.exe to launch it.
Make sure the Unregister Dll's and Ocx's checkbox is checked
Copy the list below in bold,
and paste it into the left box of OTMoveIt: Paste List of Files/Folders to be moved.
C:\WINDOWS\System32\WS2Fix.exe
C:\WINDOWS\System32\VCCLSID.exe
C:\WINDOWS\System32\VACFix.exe
C:\WINDOWS\System32\SrchSTS.exe
C:\WINDOWS\System32\IEDFix.exe
C:\WINDOWS\System32\dumphive.exe
C:\WINDOWS\System32\404Fix.exe
C:\Program Files\Navilog1
Click on MoveIt! to start the deletion.
The result will appear in the "Results" box.
Click on Exit to close.
Post the report located in C:\_OTMoveIt\MovedFiles.
Then:
* To remove the tools/fixes used:
Download ToolsCleaner to your desktop.
-->
ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
http://pc-system.fr/
# Click on Search and let the scan run...
# Click on Delete to finish.
# You can, if you wish, use the Optional Options.
# Click on Exit to obtain the report.
# Post the report (TCleaner.txt) located at the root of your hard drive (C:\).
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki.
OTMoveIt report
C:\WINDOWS\System32\WS2Fix.exe moved successfully.
C:\WINDOWS\System32\VCCLSID.exe moved successfully.
C:\WINDOWS\System32\VACFix.exe moved successfully.
C:\WINDOWS\System32\SrchSTS.exe moved successfully.
C:\WINDOWS\System32\IEDFix.exe moved successfully.
C:\WINDOWS\System32\dumphive.exe moved successfully.
C:\WINDOWS\System32\404Fix.exe moved successfully.
C:\Program Files\Navilog1\Safebackup moved successfully.
C:\Program Files\Navilog1\Report moved successfully.
C:\Program Files\Navilog1\Contents moved successfully.
C:\Program Files\Navilog1\Backupnavi moved successfully.
C:\Program Files\Navilog1 moved successfully.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08102008_004411
tools report
I didn't find the report but I made a copy-paste of the summary
-->- Search:
C:\!Killbox: found!
C:\_OtMoveIt: found!
C:\!KillBox\SmitFraudfix: found!
C:\Documents and Settings\All Users\Start Menu\Programs\Navilog1: found!
C:\Documents and Settings\All Users\Start Menu\Programs\Navilog1\Navilog1.lnk: found!
C:\Documents and Settings\magicien\My Documents\wink\Dss.exe: found!
C:\_OTMoveIt\MovedFiles\08102008_004411\Program Files\Navilog1: found!
C:\_OTMoveIt\MovedFiles\08102008_004411\Program Files\Navilog1\Navilog1.bat: found!
I performed the deletion
C:\WINDOWS\System32\WS2Fix.exe moved successfully.
C:\WINDOWS\System32\VCCLSID.exe moved successfully.
C:\WINDOWS\System32\VACFix.exe moved successfully.
C:\WINDOWS\System32\SrchSTS.exe moved successfully.
C:\WINDOWS\System32\IEDFix.exe moved successfully.
C:\WINDOWS\System32\dumphive.exe moved successfully.
C:\WINDOWS\System32\404Fix.exe moved successfully.
C:\Program Files\Navilog1\Safebackup moved successfully.
C:\Program Files\Navilog1\Report moved successfully.
C:\Program Files\Navilog1\Contents moved successfully.
C:\Program Files\Navilog1\Backupnavi moved successfully.
C:\Program Files\Navilog1 moved successfully.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08102008_004411
tools report
I didn't find the report but I made a copy-paste of the summary
-->- Search:
C:\!Killbox: found!
C:\_OtMoveIt: found!
C:\!KillBox\SmitFraudfix: found!
C:\Documents and Settings\All Users\Start Menu\Programs\Navilog1: found!
C:\Documents and Settings\All Users\Start Menu\Programs\Navilog1\Navilog1.lnk: found!
C:\Documents and Settings\magicien\My Documents\wink\Dss.exe: found!
C:\_OTMoveIt\MovedFiles\08102008_004411\Program Files\Navilog1: found!
C:\_OTMoveIt\MovedFiles\08102008_004411\Program Files\Navilog1\Navilog1.bat: found!
I performed the deletion