PDA

View Full Version : Please Help again, same type different PC



Vince Vespertino
2007-10-02, 18:11
Hello,

I hope that someone can help me with my daughters PC this time. It looks like the virtumomde virus again. Your help, as before, is greatly appreciated.

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2007-10-02 07:13
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 2/10/2007
Kaspersky Anti-Virus database records: 426153
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\

Scan Statistics:
Total number of scanned objects: 728480
Number of viruses found: 34
Number of infected objects: 99
Number of suspicious objects: 3
Duration of the scan process: 08:24:38

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant.zip/v1.8.1/wbuninst.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS00B223D2-4095-486F-BADD-6D7B4E28F1FC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS03D2429B-B100-4FE6-8B21-B2A412CD0BC6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS04D404CA-C17C-46DF-8452-0534B5DB204E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0AFF89CA-73D7-4CBB-81BE-B3BE4B1725EA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0B140BAA-C6DC-4190-BC5E-4E397083AB83.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0E3B34DF-0738-438F-8C21-235EBB5D690E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS10738459-899F-4523-85E5-8377788C0CA7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS136C43C2-5631-40F6-B002-DA102A1AA102.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS174363C3-D3F9-4CC4-B23B-B0AE89C59BC9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS180F0F2D-500B-4086-8EF3-ECC375D81C2D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1A6DFB01-8F64-403C-88BC-505900DF6E75.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1B412D42-4863-4FDD-AE97-182FDB297779.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1BFF01DB-45A6-4561-8CD3-86ACC9E14691.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2425892C-E820-4656-83B2-4B95F60C0F22.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2A4B4E54-3A9B-49DD-8FF8-A846AAA0FC40.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2B53195E-8B79-4FFA-94DC-57A9858867B4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3052F9FC-D0BF-4634-ABEE-AF6084B70326.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS36806A33-39A2-4F5B-9D93-9B158005464F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS37F025D1-6158-4CDD-84A8-E1EA938EC40A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3A935E52-2598-42BA-86E0-C96942037D8D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3B2702A9-BBF8-4176-B2EA-A56904037782.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3C9CEEC2-A766-4233-9A12-DC84014B2EF3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4585E727-8E46-42BE-B65C-99E0393F4D77.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4796822D-60B1-41E0-9467-3DC81CE7283C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4A3D7884-B9F8-439C-970C-AF5BC03A2A82.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4EE972E3-9F58-46F7-995A-6C5D9AE909AC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS50E366CD-04F3-4C87-889B-C56276DD5A62.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS53414FBA-B97D-42EB-BFE6-D0C0115C52FD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS548DDB14-F0D9-429D-8DA1-D23A983F8A53.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5A8B826F-0A03-4A08-8333-2E7BDFCF60AF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6072C0ED-1400-4FA7-8D89-0DA1E298BC63.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6115C9A0-F6DA-40CD-838F-F6C880FD4E13.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS627DCB8F-C279-49A2-8B04-DDCC0DE6E980.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS63B3020D-D5B0-479E-BE8C-3F4E2E75DF11.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS649B69A8-1FAE-4E1B-A07A-97CEB3F197C6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS64B4B302-359E-42F4-93E0-EBA4EB7588BD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS685FAC71-DE14-4B82-99C8-9F3E85F4AD33.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6A5259EA-A9C1-4778-BCE7-BC117CE90B0E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6D902DC2-2E0E-40B5-866E-4FB106D21DB5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6FF734DE-633C-4CBA-B148-9ECCB4D1CD27.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS717726A3-5B6D-45BC-A848-A2629358BC8B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS743D7EFC-8E3F-4676-A089-4F9839B1D9C7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS74D6E3A0-8211-4224-897A-0C8F1F75477C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS774D4F20-DB37-4896-B2C0-B981F55ED665.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS793303DA-9545-4B8F-88A8-28A2AB1096DE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS812C2D0B-2276-4E7D-83FB-EAE0CD850B71.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8265FD0B-3205-4BDD-96AE-0C12F41B82A4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS83F2B33C-E413-44DD-89B2-025CA73FCFAF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8436651F-113B-4755-9C1C-95697A8DCD25.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS859EA34C-6CDB-4C1C-8D1F-384FB8311B80.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8A786068-0A7E-4003-9616-A2C7D6E9F3AF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS932A4313-05A7-4142-B3FA-A69267F16AEB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9536CDB3-6773-4E1C-B13D-1F0E7E38E647.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS95C64514-7994-4D3D-8195-D4D86B7604C1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS986F65B7-D85A-4FED-A412-15F7B9F7260C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9944D404-2F68-4866-AAD9-E7EB90F79969.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9A93AF1C-B047-4079-A46A-93239D7B6A0C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9D279552-CC36-4835-88FD-7FF80D0B0C84.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9D719C10-99A7-4D52-ABE4-A7CEB6A979C3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA20CE82E-C4EE-43E3-9D0F-BF436D416672.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA47B5206-FDC8-4BA8-9914-50F82AC69DB7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA62079AE-3238-4672-9668-8BC39C5A8555.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSABE24B83-C28A-49C5-BB37-3BFEC6EB34EB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB1F99EDC-FA84-4458-A904-9F8143BB42E5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB9029618-6514-4D9B-9AE0-7407FD1294B9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBDDBE6EC-5B1F-4E28-AE06-65DEE63A465F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBECEA029-5EB6-4740-A010-5DEEB9515931.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC686BB65-5F74-4B78-9F23-AAD9B00F4974.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCA6F455C-F7F7-4319-A3A6-F2E3BA147928.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCDE90F6A-C375-4DAF-A884-E1424D181E10.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCDF7B6AB-0F2C-4C9D-869C-BD6FD03065D4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD7469061-E217-4C8E-8772-D9CD785328B7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD913579A-A0CA-4A4D-9BC6-E9D0E270A192.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDFE7209A-73EB-4294-A8D1-45C610D673ED.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE0784DFF-A7D8-4E66-8412-42D6E09381C6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE1292A38-8A8A-4228-9055-FFD3635137B3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE26880EC-C757-425C-B9BF-70F370940400.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE3AF0F7D-F13C-49CD-BAD9-00F67D570189.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE590EC45-D43F-4EB7-B0D0-A235F11693EA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE6165664-9950-4C51-B29F-61DA3A175448.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE628F79B-1BD2-4262-99C1-0794B33F162A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE8726E5E-F44A-41E8-A479-9DB24398933D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE99FAC85-B5CB-41C8-9537-4F7DAC165307.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSED4787CD-55F4-40A8-8E62-A5F44931DE15.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEDD0609E-2A90-4840-9D34-930291BDFC04.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF3A6888C-4E1F-4407-BF32-1C3B31136490.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF6B0FEC7-7255-426E-9DCA-4E0470069A1C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFC6DF8D1-8779-4266-86FD-7F2C41DC91DA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFFB85D2C-BB89-45E9-B7FB-7FF74A55D20E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\skinnybone\Application Data\Webroot\Spy Sweeper\Logs\071001170531.ses Object is locked skipped
C:\Documents and Settings\skinnybone\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\skinnybone\Desktop\catchme.zip/pmnno.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.af skipped
C:\Documents and Settings\skinnybone\Desktop\catchme.zip/wvuusrr.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\Documents and Settings\skinnybone\Desktop\catchme.zip ZIP: infected - 2 skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\dbc2e.ht1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\dbdam Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\dbdao Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\dbeam Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\dbeao Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\dbm Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\dbu2d.ht1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\dbvm.cf1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\dbvmh.ht1 Object is locked skipped

Vince Vespertino
2007-10-02, 18:12
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\fii.cf1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\fiih.ht1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\hp Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\hpt2i.ht1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\rpm.cf1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\rpm1m.cf1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\rpm1mh.ht1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\rpmh.ht1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\safeweb\goog-black-enchashm.cf1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\safeweb\goog-black-enchashmh.ht1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\safeweb\goog-black-urlm.cf1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\safeweb\goog-black-urlmh.ht1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\safeweb\goog-malware-domainm.cf1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\safeweb\goog-malware-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\safeweb\goog-white-domainm.cf1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Google\Google Desktop\f0897d9dc68e\safeweb\goog-white-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Temp\pvrejkhu.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\skinnybone\Local Settings\Temp\~DF293D.tmp Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\4N7FU4DL\image[1].htm Infected: Trojan-Downloader.VBS.Agent.p skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\62UDX1SM\WinAntiVirusPro2007FreeInstall[1].cab/UWA7P_0001_N91M0809NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\62UDX1SM\WinAntiVirusPro2007FreeInstall[1].cab CAB: infected - 1 skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\AB8F9EFQ\iesecuritytool[2] Infected: not-virus:Hoax.JS.Agent.a skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\AB8F9EFQ\image[1].htm Infected: Trojan-Downloader.VBS.Agent.p skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\AB8F9EFQ\mw_setup[1].exe/data0007 Infected: not-a-virus:FraudTool.Win32.MalwareWipe.d skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\AB8F9EFQ\mw_setup[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\FFDVFTCO\ErrorSafeFreeInstallW[1].cab/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\FFDVFTCO\ErrorSafeFreeInstallW[1].cab CAB: infected - 1 skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\GHIJKHIN\adfcook[1] Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\KPMNOTQV\idien[1] Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\KZ2R89EZ\stats[1].htm Infected: Trojan-Downloader.VBS.Agent.n skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\KZ2R89EZ\valera[1] Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\KZ2R89EZ\_affvm[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.op skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\M98TQLW5\_affvm[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.op skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\MPGDIXGN\kcehc_eicooc20070702[1] Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\MPGDIXGN\kcehc_eicooc[1] Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\NQFXTLNB\19f06c7b227aa4a7cb7eef3d59a4dbc3[1] Infected: Trojan.Win32.Agent.avi skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\NQFXTLNB\is68089[1].exe Infected: Trojan.Win32.Pakes skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\NQFXTLNB\snapsnet[1].exe/data0005 Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\NQFXTLNB\snapsnet[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\NQFXTLNB\thinksnet[1].exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\NQFXTLNB\yazzlesnet[1].exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\NQFXTLNB\yazzlesnet[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\QH2XUHOR\deliver46860[1].htm Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\W1YZ4523\WinAntiVirusPro2007FreeInstall[1].cab/UWA7P_0001_N91M0809NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\W1YZ4523\WinAntiVirusPro2007FreeInstall[1].cab CAB: infected - 1 skipped
C:\Documents and Settings\skinnybone\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\skinnybone\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped
C:\qoobox\Quarantine\C\DOCUME~1\Guest\APPLIC~1\winantispyware2007freeinstall[1].exe.vir Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\qoobox\Quarantine\C\Program Files\TTX.exe.vir Infected: not-a-virus:AdWare.Win32.TTC.c skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\asjgyqxb.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\B1\chkq22011.exe.vir/data0004 Infected: not-a-virus:AdWare.Win32.TTC.c skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\B1\chkq22011.exe.vir NSIS: infected - 1 skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bshvuawh.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\dxsdypmr.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\f02WtR\f02WtR1065.exe.vir Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\gdjuvgir.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\gwvhvled.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ikssqkmn.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ldblvrgf.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\pktboxeq.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\plrbnxto.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\qhnacdob.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\srouahmd.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\sysqfogy.exe.vir Infected: Trojan.Win32.Agent.bck skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\vpndhtwv.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\wbagnfcn.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\win\w71.exe.vir Infected: Trojan-Downloader.Win32.Small.eqn skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\wlyjtseq.exe.vir Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP477\A0034258.exe Infected: not-a-virus:AdWare.Win32.Agent.co skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP477\A0034325.exe Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP477\A0034335.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP477\A0034336.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP483\A0046355.exe Infected: Trojan-Dropper.Win32.VB.nn skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP483\A0046357.exe Infected: not-a-virus:FraudTool.Win32.AntivirusGolden.3460 skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP483\A0046359.exe Infected: not-a-virus:FraudTool.Win32.MalwareWipe.d skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP483\A0046363.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP483\A0046367.dll Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP483\A0046369.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP483\A0046370.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP483\A0046395.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.r skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0047942.exe Infected: Trojan-Downloader.Win32.Zlob.ayz skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0047943.EXE Infected: Trojan-Dropper.Win32.Agent.mu skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0047944.dll Infected: not-a-virus:FraudTool.Win32.WorldSecurityOnline.a skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0047945.exe Infected: Trojan-Clicker.Win32.Agent.jh skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0047946.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0047947.exe Infected: Trojan-Clicker.Win32.Agent.jh skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0047948.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0047949.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0047950.exe Infected: Trojan-Downloader.Win32.Zlob.ayz skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0047951.exe Infected: Trojan-Downloader.Win32.Zlob.ayz skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0047952.exe Infected: Trojan-Clicker.Win32.Agent.jh skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0047953.exe Infected: Trojan-Clicker.Win32.Agent.jh skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0047954.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP520\A0048203.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048818.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048825.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048826.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048827.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048828.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048829.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048830.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048831.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048832.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048833.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048834.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048835.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048836.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048837.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048838.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\A0048839.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{D4570988-6ED1-4CC3-80FF-4ADC37F89602}\RP559\change.log Object is locked skipped
C:\VundoFix Backups\acfbmqxa.exe.bad Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\VundoFix Backups\pmnno.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.af skipped
C:\VundoFix Backups\wvuusrr.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{06B8CF0B-92EC-4330-9DB1-037F0DACD76C}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\druidy_redux.exe Infected: Trojan.Win32.Kolweb.j skipped
C:\WINDOWS\system32\durvily.dll Infected: Trojan.Win32.Kolweb.b skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\kXWERs4Y.exe Infected: Trojan.Win32.Agent.avi skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

Vince Vespertino
2007-10-02, 18:13
I've renamed the HJT.EXE to Something.exe

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:04, on 2007-10-02
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Trend Micro\HijackThis\something.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R3 - URLSearchHook: (no name) - {5909C662-0B85-2425-A19C-73D58A22BA99} - (no file)
O2 - BHO: (no name) - {016CB750-FE76-4BE9-88EB-2824DBDC3E90} - C:\WINDOWS\System32\pmnno.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: PeoplePC ScamGuard - {7E3659A6-4BC5-4d93-B3FD-8B5ACC2FEDED} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll
O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
O4 - HKLM\..\Run: [WorkFlow] D:\Install\WorkFlow.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [{5B-B0-07-7F-ZN}] "c:\windows\system32\dwdsrngt.exe" CHD003
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Cqvk] "C:\Documents and Settings\skinnybone\Application Data\s?curity\?vchost.exe"
O4 - HKCU\..\Policies\Explorer\Run: [{6435B07F-09E5-1033-0603-041025200001}] "C:\Program Files\Common Files\{6435B07F-09E5-1033-0603-041025200001}\Update.exe" te-110-12-0000213
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1190868535640
O20 - AppInit_DLLs: ?#A C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: pmnno - C:\WINDOWS\System32\pmnno.dll
O20 - Winlogon Notify: wvuusrr - C:\WINDOWS\SYSTEM32\wvuusrr.dll
O22 - SharedTaskScheduler: (no name) - {951a98d0-dad6-4a77-8280-a494279a884b} - (no file)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 5135 bytes

Mr_JAk3
2007-10-05, 20:57
Hello Vince Vespertino and welcome to the Forums :)

You're infected..

At first you need to disable a few realtime protections. These may interfere with our cleaning process.
We'll enable these when you're clean...

Disable SpySweeper's realtime protection.
Open Spysweeper and click on Options
Choose Program Options and uncheck "load at windows startup".
On the left click "shields" and then uncheck everything.
Uncheck "home page shield".
Uncheck "automatically restore default without notification".
Exit the program.

1. Download this file - combofix.exe (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Vince Vespertino
2007-10-08, 04:23
Hello Mr_Jak3 and thank you for your reply.

ComboFix 07-10-07.2 - skinnybone 2007-10-07 18:08:42.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.106 [GMT -7:00]
Running from: C:\Documents and Settings\skinnybone\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\pmnno.dll
C:\WINDOWS\system32\wvuusrr.dll

.
((((((((((((((((((((((((( Files Created from 2007-09-08 to 2007-10-08 )))))))))))))))))))))))))))))))
.

2007-10-02 07:59 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-02 07:16 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-10-02 07:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-10-02 07:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\CyberLink
2007-10-02 03:01 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-10-01 17:13 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-10-01 17:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-01 16:57 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-09-26 21:55 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-26 20:54 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-09-26 20:25 260,096 --a------ C:\WINDOWS\system32\mstask.dll
2007-09-26 20:25 172,544 --a------ C:\WINDOWS\system32\schedsvc.dll
2007-09-26 20:25 10,752 --a------ C:\WINDOWS\system32\mstinit.exe
2007-09-26 20:18 <DIR> d-------- C:\VundoFix Backups
2007-09-26 17:08 92,224 --a------ C:\WINDOWS\system32\krnl386.exe
2007-09-26 17:08 35,648 --a------ C:\WINDOWS\system32\ntio411.sys
2007-09-26 17:08 35,424 --a------ C:\WINDOWS\system32\ntio412.sys
2007-09-26 17:08 34,560 --a------ C:\WINDOWS\system32\ntio804.sys
2007-09-26 17:08 34,560 --a------ C:\WINDOWS\system32\ntio404.sys
2007-09-26 17:08 33,840 --a------ C:\WINDOWS\system32\ntio.sys
2007-09-26 17:08 245,760 --a------ C:\WINDOWS\system32\wow32.dll
2007-09-26 17:08 23,040 --a------ C:\WINDOWS\system32\vdmdbg.dll
2007-09-26 17:08 13,312 --a------ C:\WINDOWS\system32\ntvdmd.dll
2007-09-26 16:44 593,408 -----c--- C:\WINDOWS\system32\dllcache\xpsp2res.dll
2007-09-26 16:38 <DIR> d-------- C:\WINDOWS\system32\bits
2007-09-26 16:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-09-26 16:12 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-09-26 16:05 285,184 --a------ C:\WINDOWS\system32\kerberos.dll
2007-09-26 16:02 64,512 -----c--- C:\WINDOWS\system32\dllcache\ciodm.dll
2007-09-26 16:02 1,350,144 --a------ C:\WINDOWS\system32\query.dll
2007-09-26 16:02 1,350,144 -----c--- C:\WINDOWS\system32\dllcache\query.dll
2007-09-26 16:00 238,592 --a------ C:\WINDOWS\system32\tapisrv.dll
2007-09-26 15:59 493,056 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-09-26 15:55 991,232 --a------ C:\WINDOWS\system32\esent.dll
2007-09-26 15:55 316,928 --a------ C:\WINDOWS\system32\zipfldr.dll
2007-09-26 15:55 140,288 -----c--- C:\WINDOWS\system32\dllcache\dnsapi.dll
2007-09-26 15:55 128,000 --a------ C:\WINDOWS\system32\itss.dll
2007-09-26 15:55 103,936 -----c--- C:\WINDOWS\system32\dllcache\dhcpcsvc.dll
2007-09-26 15:52 92,160 --a------ C:\WINDOWS\system32\cscdll.dll
2007-09-26 15:52 92,160 -----c--- C:\WINDOWS\system32\dllcache\cscdll.dll
2007-09-26 15:52 433,152 -----c--- C:\WINDOWS\system32\dllcache\mrxsmb.sys
2007-09-26 15:52 166,656 -----c--- C:\WINDOWS\system32\dllcache\rdbss.sys
2007-09-26 15:50 53,760 --a------ C:\WINDOWS\system32\authz.dll
2007-09-14 11:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-09-14 10:48 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2007-09-14 10:48 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2007-09-14 10:48 20,480 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2007-09-14 10:48 20,480 --a------ C:\WINDOWS\system32\hidserv.dll
2007-09-14 10:48 13,952 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2007-09-14 10:48 13,952 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2007-09-14 10:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2007-09-14 10:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-26 21:38 --------- d-------- C:\Program Files\BigFix
2007-09-26 21:05 --------- d-------- C:\Program Files\ICQ
2007-09-26 20:06 --------- d-------- C:\Program Files\Norton AntiVirus
2007-09-26 20:06 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-09-26 19:58 --------- d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-09-26 19:50 --------- d-------- C:\Program Files\LimeWire
2007-09-26 19:50 --------- d-------- C:\Program Files\FilmLoop Player
2007-09-26 19:49 --------- d-------- C:\Program Files\Lavasoft
2007-09-14 11:46 --------- d-------- C:\Program Files\PestCapture
2007-08-15 11:00 --------- d-------- C:\Documents and Settings\Guest\Application Data\Webroot
2007-08-15 11:00 --------- d-------- C:\Documents and Settings\Guest\Application Data\FilmLoop
2007-08-08 09:43 25664 --a------ C:\WINDOWS\system32\kXWERs4Y.exe
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 207736 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-19 22:54 1521464 --a------ C:\WINDOWS\WRSetup.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
2006-01-24 16:07 220672 --a------ C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A8FB8EB3-183B-4598-924D-86F0E5E37085}"= C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll [2006-01-24 16:07 220672]

[HKEY_CLASSES_ROOT\CLSID\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
[HKEY_CLASSES_ROOT\PeoplePal Toolbar]
[HKEY_CLASSES_ROOT\TypeLib\{994D628D-4D22-4DB9-B6DB-F7D9F1635817}]
[HKEY_CLASSES_ROOT\PeoplePal Toolbar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"@"="" []
"WorkFlow"="D:\Install\WorkFlow.exe" []
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-03 08:19]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 04:03]
"{5B-B0-07-7F-ZN}"="c:\windows\system32\dwdsrngt.exe" []
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"@"="" []
"AIM"="C:\Program Files\aim\aim.exe" []
"Cqvk"="C:\Documents and Settings\skinnybone\Application Data\s?curity\?vchost.exe" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=?
R0 SSFS0BB8;Spy Sweeper File System Filer Driver: 0BB8;C:\WINDOWS\System32\Drivers\SSFS0BB8.SYS
S3 PRISM_USB;Linksys Wireless-B USB Network Adapter Driver;C:\WINDOWS\System32\DRIVERS\LSPMUSB.sys
S3 XIRLINK;Veo Mobile/Advanced Web Camera;C:\WINDOWS\System32\DRIVERS\ucdnt.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-08-06 19:46:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-10-02 07:01:06 C:\WINDOWS\Tasks\At1.job"
"2007-10-02 16:01:00 C:\WINDOWS\Tasks\At10.job"
"2007-10-02 17:01:00 C:\WINDOWS\Tasks\At11.job"
"2007-10-02 18:01:00 C:\WINDOWS\Tasks\At12.job"
"2007-10-02 19:01:00 C:\WINDOWS\Tasks\At13.job"
"2007-10-02 20:01:00 C:\WINDOWS\Tasks\At14.job"
"2007-10-02 21:01:00 C:\WINDOWS\Tasks\At15.job"
"2007-10-02 22:01:00 C:\WINDOWS\Tasks\At16.job"
"2007-10-02 23:01:00 C:\WINDOWS\Tasks\At17.job"
"2007-10-02 00:05:13 C:\WINDOWS\Tasks\At18.job"
"2007-10-08 01:01:28 C:\WINDOWS\Tasks\At19.job"
"2007-10-02 08:01:05 C:\WINDOWS\Tasks\At2.job"
"2007-10-02 02:01:05 C:\WINDOWS\Tasks\At20.job"
"2007-10-02 03:01:04 C:\WINDOWS\Tasks\At21.job"
"2007-10-02 04:01:07 C:\WINDOWS\Tasks\At22.job"
"2007-10-02 05:01:07 C:\WINDOWS\Tasks\At23.job"
"2007-10-02 06:01:06 C:\WINDOWS\Tasks\At24.job"
"2007-10-02 09:01:03 C:\WINDOWS\Tasks\At3.job"
"2007-10-02 10:01:00 C:\WINDOWS\Tasks\At4.job"
"2007-10-02 11:01:02 C:\WINDOWS\Tasks\At5.job"
"2007-10-02 12:01:00 C:\WINDOWS\Tasks\At6.job"
"2007-10-02 13:01:00 C:\WINDOWS\Tasks\At7.job"
"2007-10-02 14:01:00 C:\WINDOWS\Tasks\At8.job"
"2007-10-02 15:01:45 C:\WINDOWS\Tasks\At9.job"
"2007-07-16 07:00:12 C:\WINDOWS\Tasks\wrSpySweeper_4A7E725A6C3A4851B713C6DEBA80057F.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-07 18:15:03
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-07 18:16:23 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-10-07 18:16
.
--- E O F ---

Vince Vespertino
2007-10-08, 04:24
I am also including a fresh HJT log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:19:28 PM, on 10/7/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\something.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R3 - URLSearchHook: (no name) - {5909C662-0B85-2425-A19C-73D58A22BA99} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: PeoplePC ScamGuard - {7E3659A6-4BC5-4d93-B3FD-8B5ACC2FEDED} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll
O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
O4 - HKLM\..\Run: [WorkFlow] D:\Install\WorkFlow.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [{5B-B0-07-7F-ZN}] "c:\windows\system32\dwdsrngt.exe" CHD003
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Cqvk] "C:\Documents and Settings\skinnybone\Application Data\s?curity\?vchost.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1190868535640
O20 - AppInit_DLLs: ?#A C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O22 - SharedTaskScheduler: (no name) - {951a98d0-dad6-4a77-8280-a494279a884b} - (no file)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 4738 bytes

Mr_JAk3
2007-10-09, 22:08
Hi again and sorry for the delay.

Open Control Panel -> Add/Remove programs -> Remove all the of the following or similar entries if found:

PeoplePal
PeoplePC

and any other programs you didn't install or don't recognize - if your not sure please ask first

Open notepad and copy/paste the text in the quotebox below into it:


File::
C:\WINDOWS\system32\kXWERs4Y.exe
c:\windows\system32\dwdsrngt.exe
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job

Folder::
C:\Program Files\PeoplePC

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

[-HKEY_CLASSES_ROOT\CLSID\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
[-HKEY_CLASSES_ROOT\PeoplePal Toolbar]
[-HKEY_CLASSES_ROOT\TypeLib\{994D628D-4D22-4DB9-B6DB-F7D9F1635817}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{5B-B0-07-7F-ZN}"=-

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cqvk"=-

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"="C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL"




Save this as "CFScript"

http://img.photobucket.com/albums/v666/sUBs/CFScript.gif

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Vince Vespertino
2007-10-10, 01:46
Hello Mr_Jak3 and thank you again for getting back to me.

I could not find entries in "add/remove programs" in control panel for PeoplePC or PeoplePal. I ran the CFScript as you instructed. The first time the CF screen just sat there after a reboot. I terminated the program after about an hour and ran it again. It worked the second time a spat out the log. However, after I ran ComboFix the second time, the program did not require a system reboot. I do not know if this is important or not, just thought I would mention.

Additionally, after running the ComboFix, the PeoplePC toolbar in IE program is not longer present. I take this as a good thing?

The logs you requested:

ComboFix 07-10-07.2 - skinnybone 2007-10-09 15:30:57.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.99 [GMT -7:00]
Running from: C:\Documents and Settings\skinnybone\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\skinnybone\Desktop\CFScript.txt
* Created a new restore point

FILE::
c:\windows\system32\dwdsrngt.exe
C:\WINDOWS\system32\kXWERs4Y.exe
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job
.

((((((((((((((((((((((((( Files Created from 2007-09-09 to 2007-10-09 )))))))))))))))))))))))))))))))
.

2007-10-02 07:59 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-02 07:16 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-10-02 07:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-10-02 07:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\CyberLink
2007-10-02 03:01 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-10-01 17:13 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-10-01 17:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-01 16:57 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-09-26 21:55 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-26 20:54 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-09-26 20:25 260,096 --a------ C:\WINDOWS\system32\mstask.dll
2007-09-26 20:25 172,544 --a------ C:\WINDOWS\system32\schedsvc.dll
2007-09-26 20:25 10,752 --a------ C:\WINDOWS\system32\mstinit.exe
2007-09-26 20:18 <DIR> d-------- C:\VundoFix Backups
2007-09-26 17:08 92,224 --a------ C:\WINDOWS\system32\krnl386.exe
2007-09-26 17:08 35,648 --a------ C:\WINDOWS\system32\ntio411.sys
2007-09-26 17:08 35,424 --a------ C:\WINDOWS\system32\ntio412.sys
2007-09-26 17:08 34,560 --a------ C:\WINDOWS\system32\ntio804.sys
2007-09-26 17:08 34,560 --a------ C:\WINDOWS\system32\ntio404.sys
2007-09-26 17:08 33,840 --a------ C:\WINDOWS\system32\ntio.sys
2007-09-26 17:08 245,760 --a------ C:\WINDOWS\system32\wow32.dll
2007-09-26 17:08 23,040 --a------ C:\WINDOWS\system32\vdmdbg.dll
2007-09-26 17:08 13,312 --a------ C:\WINDOWS\system32\ntvdmd.dll
2007-09-26 16:44 593,408 -----c--- C:\WINDOWS\system32\dllcache\xpsp2res.dll
2007-09-26 16:38 <DIR> d-------- C:\WINDOWS\system32\bits
2007-09-26 16:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-09-26 16:12 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-09-26 16:05 285,184 --a------ C:\WINDOWS\system32\kerberos.dll
2007-09-26 16:02 64,512 -----c--- C:\WINDOWS\system32\dllcache\ciodm.dll
2007-09-26 16:02 1,350,144 --a------ C:\WINDOWS\system32\query.dll
2007-09-26 16:02 1,350,144 -----c--- C:\WINDOWS\system32\dllcache\query.dll
2007-09-26 16:00 238,592 --a------ C:\WINDOWS\system32\tapisrv.dll
2007-09-26 15:59 493,056 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-09-26 15:55 991,232 --a------ C:\WINDOWS\system32\esent.dll
2007-09-26 15:55 316,928 --a------ C:\WINDOWS\system32\zipfldr.dll
2007-09-26 15:55 140,288 -----c--- C:\WINDOWS\system32\dllcache\dnsapi.dll
2007-09-26 15:55 128,000 --a------ C:\WINDOWS\system32\itss.dll
2007-09-26 15:55 103,936 -----c--- C:\WINDOWS\system32\dllcache\dhcpcsvc.dll
2007-09-26 15:52 92,160 --a------ C:\WINDOWS\system32\cscdll.dll
2007-09-26 15:52 92,160 -----c--- C:\WINDOWS\system32\dllcache\cscdll.dll
2007-09-26 15:52 433,152 -----c--- C:\WINDOWS\system32\dllcache\mrxsmb.sys
2007-09-26 15:52 166,656 -----c--- C:\WINDOWS\system32\dllcache\rdbss.sys
2007-09-26 15:50 53,760 --a------ C:\WINDOWS\system32\authz.dll
2007-09-14 11:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-09-14 10:48 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2007-09-14 10:48 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2007-09-14 10:48 20,480 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2007-09-14 10:48 20,480 --a------ C:\WINDOWS\system32\hidserv.dll
2007-09-14 10:48 13,952 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2007-09-14 10:48 13,952 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2007-09-14 10:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2007-09-14 10:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-09 14:41 --------- d-------- C:\Program Files\Google
2007-09-26 21:38 --------- d-------- C:\Program Files\BigFix
2007-09-26 21:05 --------- d-------- C:\Program Files\ICQ
2007-09-26 20:06 --------- d-------- C:\Program Files\Norton AntiVirus
2007-09-26 20:06 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-09-26 19:58 --------- d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-09-26 19:50 --------- d-------- C:\Program Files\LimeWire
2007-09-26 19:50 --------- d-------- C:\Program Files\FilmLoop Player
2007-09-26 19:49 --------- d-------- C:\Program Files\Lavasoft
2007-09-14 11:46 --------- d-------- C:\Program Files\PestCapture
2007-08-15 11:00 --------- d-------- C:\Documents and Settings\Guest\Application Data\Webroot
2007-08-15 11:00 --------- d-------- C:\Documents and Settings\Guest\Application Data\FilmLoop
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 207736 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-19 22:54 1521464 --a------ C:\WINDOWS\WRSetup.dll
.

((((((((((((((((((((((((((((( snapshot@2007-10-07_18.15.36.53 )))))))))))))))))))))))))))))))))))))))))
.
----a-w 16,384 2007-10-09 21:54:05 C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
----a-w 32,768 2007-10-09 21:54:05 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
----a-w 49,152 2007-10-09 21:54:05 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
----a-w 16,384 2007-10-08 01:14:40 C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
----a-w 32,768 2007-10-08 01:14:40 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
----a-w 49,152 2007-10-08 01:14:40 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WorkFlow"="D:\Install\WorkFlow.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 04:03]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\Program Files\aim\aim.exe" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=?
R0 SSFS0BB8;Spy Sweeper File System Filer Driver: 0BB8;C:\WINDOWS\System32\Drivers\SSFS0BB8.SYS
S3 PRISM_USB;Linksys Wireless-B USB Network Adapter Driver;C:\WINDOWS\System32\DRIVERS\LSPMUSB.sys
S3 XIRLINK;Veo Mobile/Advanced Web Camera;C:\WINDOWS\System32\DRIVERS\ucdnt.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-08-06 19:46:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-07-16 07:00:12 C:\WINDOWS\Tasks\wrSpySweeper_4A7E725A6C3A4851B713C6DEBA80057F.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-09 15:32:34
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

**************************************************************************
.
Completion time: 2007-10-09 15:33:53
C:\ComboFix-quarantined-files.txt ... 2007-10-09 15:33
C:\ComboFix2.txt ... 2007-10-07 18:16
.
--- E O F ---

Vince Vespertino
2007-10-10, 01:47
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:36:06 PM, on 10/9/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\something.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R3 - URLSearchHook: (no name) - {5909C662-0B85-2425-A19C-73D58A22BA99} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - (no file)
O4 - HKLM\..\Run: [WorkFlow] D:\Install\WorkFlow.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1190868535640
O20 - AppInit_DLLs: ?#A
O22 - SharedTaskScheduler: (no name) - {951a98d0-dad6-4a77-8280-a494279a884b} - (no file)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 3761 bytes

Mr_JAk3
2007-10-10, 20:56
Hi again :)

We'll continue...

Run HijackThis, click Do a system scan only, and check the box next to each of these entries if still present. Close all other windows and press Fix checked. If something isn't there, please continue with the next entry in the list.
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - (no file)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O20 - AppInit_DLLs: ?#AO22 - SharedTaskScheduler: (no name) - {951a98d0-dad6-4a77-8280-a494279a884b} - (no file)

You should print these instructions or save these to a text file. Follow these instructions carefully.

Download Dr.Web CureIt to the desktop -> ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

Restart your computer to the safe mode:
Restart your computer
Start tapping the F8 key when the computer restarts.
When the start menu opens, choose Safe mode
Press Enter. The computer then begins to start in Safe mode.
Run a scan with Dr.Web CureIt Doubleclick the drweb-cureit.exe file and Allow to run the express scan
This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
Once the short scan has finished, you should now mark the drives that you want to scan.
Select all drives. A red dot shows which drives have been chosen.
Click the green arrow at the right, and the scan will start.
Click 'Yes to all' if it asks if you want to cure/move the file.

When the scan has finished, look if you can click next icon next to the files found http://users.telenet.be/bluepatchy/miekiemoes/images/check.gif
If so, click it and then click the next icon right below and select Move incurable
After the scan, in the menu, click file and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
Close Dr.Web Cureit.
Reboot the computer in Normal Mode,
Post the Cure-it report and a fresh HijackThis log

Vince Vespertino
2007-10-11, 04:09
Hello Mr_Jak3,

This first log is what Dr Web produced, HJT log follows:

image[1].htm;C:\Documents and Settings\skinnybone\Local Settings\Temporary Internet Files\Content.IE5\AB8F9EFQ;Trojan.DownLoader.30252;Deleted.;

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:04:05 PM, on 10/10/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\something.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R3 - URLSearchHook: (no name) - {5909C662-0B85-2425-A19C-73D58A22BA99} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [WorkFlow] D:\Install\WorkFlow.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1190868535640
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 3241 bytes

Mr_JAk3
2007-10-11, 21:39
Ok looks very good now :)

Run HijackThis, click Do a system scan only, and check the box next to each of these entries if still present. Close all other windows and press Fix checked. If something isn't there, please continue with the next entry in the list.
R3 - URLSearchHook: (no name) - {5909C662-0B85-2425-A19C-73D58A22BA99} - (no file)


You don't seem to have a third-party firewall (http://forum.malwareremoval.com/viewtopic.php?p=56#56) installed. You must install one firewall.
It is possible that you're using the Windows XP firewall. That is of course better than nothing but I recommend that you install a more advanced firewall that gives more protection. Windows firewall doesn't eg protect your computer from inbound threats. This means that any malware on your computer is free to "phone home" for more instructions. Remember to use only one firewall at the same time. I'll give you a few alternatives if you want to install a third-party firewall:

These are good (free) firewalls: Sunbelt-Kerio (http://www.sunbelt-software.com/Kerio.cfm)
ZoneAlarm (http://www.zonelabs.com/)
Sygate (http://http://www.majorgeeks.com/download.php?det=3356)
Outpost (http://www.majorgeeks.com/download.php?det=1056)
Comodo (http://www.personalfirewall.comodo.com)

You don't have an antivirus (http://forum.malwareremoval.com/viewtopic.php?p=53#53) on your computer, you must install one antivirus. Otherwise you'll get infected again.

These are good (free) antiviruses: AVG (http://free.grisoft.com)
Antivir (http://www.free-av.com)
Avast (http://www.avast.com)

Restart the computer and post a one more HijackThis log.

Vince Vespertino
2007-10-11, 21:55
Hello MR_Jak3,

This PC does have a purchased copy of SpySweeper. Does SpySweeper not have a firewall?

As a reminder, when we started this process, you had me disable SpySweeper so as to not interfere with removal.

Here is the latest HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:50:39 AM, on 10/11/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Trend Micro\HijackThis\something.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [WorkFlow] D:\Install\WorkFlow.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1190868535640
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 3092 bytes

Mr_JAk3
2007-10-12, 21:11
Hello :)

You can enable SpySweeper now.

SpySweeper isn't an antivirus program and it doesn't include a firewall. You'll need to install on firewall and one antivirus immediately :bigthumb:

Vince Vespertino
2007-10-13, 19:25
Hello Mr_Jak3,

Thank you so much for your help. The PC is running well except for one problem that may or not be related to the infection you assisted me with.

While trying to install XP SP2, I recieve an "Access is Denied" error and the upgrade process reverses.

I've researched the issue and found that there seems to be a problem with an entry in the registry: "HKey_Local_Machine\SYSTEM\CurrentControlSet\Services\ssdpsrv\\DependOnService".

First of all, there is no DependOnService entry in the "ssdpsrv" folder in the registry.

Second, there are many subfolders to the "ssdpsrv" folder which look very suspicious to me. These subfolders have names that consist a running sequence of symbols and numbers.

For instance, the first subfolder is called, \$%&'()*+,-.

the next is called, \$%&'()*+,-./

the last one is called, \$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'(

Can you help or least point me in the proper direction?

Vince Vespertino
2007-10-13, 19:27
Hello Mr_Jak3,

Thank you so much for your help. The PC is running well except for one problem that may or not be related to the infection you assisted me with.

While trying to install XP SP2, I recieve an "Access is Denied" error and the installation process reverses.

I've researched the issue and found that there seems to be a problem with an entry in the registry: "HKey_Local_Machine\SYSTEM\CurrentControlSet\Services\ssdpsrv\\DependOnService".

First of all, there is no DependOnService entry in the "ssdpsrv" folder in the registry.

Second, there are many subfolders to the "ssdpsrv" folder which look very suspicious to me. These subfolders have names that consist a running sequence of symbols and numbers.

For instance, the first subfolder is called, \$%&'()*+,-.

the next is called, \$%&'()*+,-./

the last one is called, \$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'()*+,-./0123$%&'(

Can you help or least point me in the proper direction?

Mr_JAk3
2007-10-14, 12:44
Ok I made some research and this might have to do with registry permissions.

Backup Your Registry with ERUNT:
Download erunt.zip to your Desktop from here:
http://aumha.org/downloads/erunt.zip
Right-click erunt.zip, select Extract All... and follow the prompts to extract ERUNT to a new folder on your Desktop
Inside the new folder, double-click ERUNT.exe to start the program
OK all the prompts to back up your registry to the default location.Note: to restore your registry, go to the backup folder and start ERDNT.exe

Click Start then Run
Type in regedit
Click Ok.

In left pane of registry editor, Navigate to:

Hkey_Local_Machine\SYSTEM\CurrentControlSet\Services\ssdpsrv

click once on the key name to highlight it and click on the Permission menu option under Edit. Uncheck Allow inheritible permissions and press copy. Click on everyone and put a checkmark in full control, press apply and ok.

Restart the computer and try installing SP2 again :)

Vince Vespertino
2007-10-15, 01:55
Hi Mr_Jak3,

I have followed your instruction and have encountered the same result.

In the permissions menu are listed 4 users, Administrators, Creator Owner, System and Users.

When the Creator Owner user is selected, I select Full Control. When I hit apply, the check marks go away from the Full Control and Read selections.

Any ideas on what I can do next?

Mr_JAk3
2007-10-15, 21:29
Hmm ok we'll do some research :)

Please post the contents of this text file to here:

C:\WINDOWS\setupapi.log

Vince Vespertino
2007-10-15, 21:34
Hi Mr_Jak3,

I had already enabled verbose logging so the registry info you may be looking for should be here:

[SetupAPI Log]
OS Version = 5.1.2600 Service Pack 1
Platform ID = 2 (NT)
Service Pack = 1.0
Suite = 0x0300
Product Type = 1
Architecture = x86
[2007/10/15 09:15:15 1492.476 Driver Install]
#-019 Searching for hardware ID(s): display\in-kch-8xx-chipsets
#-018 Searching for compatible ID(s): display\in-kch-8xx-chipsets
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [KCH.Device] in "c:\windows\inf\oem3.inf".
#I320 Class GUID of device remains: {D07AF4AC-3BED-458D-9A68-380F23572661}.
#I060 Set selected driver.
[2007/10/15 09:15:16 1492.480 Driver Install]
#-019 Searching for hardware ID(s): display\in-sb-8xx-platforms
#-018 Searching for compatible ID(s): display\in-sb-8xx-platforms
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [SoftBIOS.Device] in "c:\windows\inf\oem2.inf".
#I320 Class GUID of device remains: {D07AF4AC-3BED-458D-9A68-380F23572661}.
#I060 Set selected driver.
[2007/10/15 09:15:18 1492.514 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_14f1&dev_2f20&subsys_200014f1&rev_00,pci\ven_14f1&dev_2f20&subsys_200014f1,pci\ven_14f1&dev_2f20&cc_078000,pci\ven_14f1&dev_2f20&cc_0780
#-018 Searching for compatible ID(s): pci\ven_14f1&dev_2f20&rev_00,pci\ven_14f1&dev_2f20,pci\ven_14f1&cc_078000,pci\ven_14f1&cc_0780,pci\ven_14f1,pci\cc_078000,pci\cc_0780
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [ModemX] in "c:\windows\inf\oem0.inf".
#I320 Class GUID of device remains: {4D36E96D-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 09:15:19 1492.518 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_1039&subsys_30488086&rev_81,pci\ven_8086&dev_1039&subsys_30488086,pci\ven_8086&dev_1039&cc_020000,pci\ven_8086&dev_1039&cc_0200
#-018 Searching for compatible ID(s): pci\ven_8086&dev_1039&rev_81,pci\ven_8086&dev_1039,pci\ven_8086&cc_020000,pci\ven_8086&cc_0200,pci\ven_8086,pci\cc_020000,pci\cc_0200
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [XP_D110K.ndi] in "c:\windows\inf\oem19.inf".
#I320 Class GUID of device remains: {4D36E972-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 09:15:20 1492.522 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_244e&subsys_00000000&rev_81,pci\ven_8086&dev_244e&subsys_00000000,pci\ven_8086&dev_244e&rev_81,pci\ven_8086&dev_244e,pci\ven_8086&dev_244e&cc_060400,pci\ven_8086&dev_244e&cc_0604
#-018 Searching for compatible ID(s): pci\ven_8086&cc_060400,pci\ven_8086&cc_0604,pci\ven_8086,pci\cc_060400,pci\cc_0604
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [INTEL_PCI] in "c:\windows\inf\ich4core.inf".
#I320 Class GUID of device remains: {4D36E97D-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 09:15:22 1492.528 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24c0&subsys_00000000&rev_01,pci\ven_8086&dev_24c0&subsys_00000000,pci\ven_8086&dev_24c0&rev_01,pci\ven_8086&dev_24c0,pci\ven_8086&dev_24c0&cc_060100,pci\ven_8086&dev_24c0&cc_0601
#-018 Searching for compatible ID(s): pci\ven_8086&cc_060100,pci\ven_8086&cc_0601,pci\ven_8086,pci\cc_060100,pci\cc_0601
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [INTEL_ISAPNP] in "c:\windows\inf\ich4core.inf".
#I320 Class GUID of device remains: {4D36E97D-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 09:15:22 1492.534 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24c2&subsys_53528086&rev_01,pci\ven_8086&dev_24c2&subsys_53528086,pci\ven_8086&dev_24c2&cc_0c0300,pci\ven_8086&dev_24c2&cc_0c03
#-018 Searching for compatible ID(s): pci\ven_8086&dev_24c2&rev_01,pci\ven_8086&dev_24c2,pci\ven_8086&cc_0c0300,pci\ven_8086&cc_0c03,pci\ven_8086,pci\cc_0c0300,pci\cc_0c03
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [INTEL_USB] in "c:\windows\inf\ich4usb.inf".
#I320 Class GUID of device remains: {36FC9E60-C465-11CF-8056-444553540000}.
#I060 Set selected driver.
[2007/10/15 09:15:23 1492.540 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24c3&subsys_53528086&rev_01,pci\ven_8086&dev_24c3&subsys_53528086,pci\ven_8086&dev_24c3&cc_0c0500,pci\ven_8086&dev_24c3&cc_0c05
#-018 Searching for compatible ID(s): pci\ven_8086&dev_24c3&rev_01,pci\ven_8086&dev_24c3,pci\ven_8086&cc_0c0500,pci\ven_8086&cc_0c05,pci\ven_8086,pci\cc_0c0500,pci\cc_0c05
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [NO_DRV] in "c:\windows\inf\ich4core.inf".
#I320 Class GUID of device remains: {4D36E97D-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 09:15:23 1492.546 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24c4&subsys_53528086&rev_01,pci\ven_8086&dev_24c4&subsys_53528086,pci\ven_8086&dev_24c4&cc_0c0300,pci\ven_8086&dev_24c4&cc_0c03
#-018 Searching for compatible ID(s): pci\ven_8086&dev_24c4&rev_01,pci\ven_8086&dev_24c4,pci\ven_8086&cc_0c0300,pci\ven_8086&cc_0c03,pci\ven_8086,pci\cc_0c0300,pci\cc_0c03
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [INTEL_USB] in "c:\windows\inf\ich4usb.inf".
#I320 Class GUID of device remains: {36FC9E60-C465-11CF-8056-444553540000}.
#I060 Set selected driver.
[2007/10/15 09:15:24 1492.552 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24c5&subsys_02088086&rev_01,pci\ven_8086&dev_24c5&subsys_02088086,pci\ven_8086&dev_24c5&cc_040100,pci\ven_8086&dev_24c5&cc_0401
#-018 Searching for compatible ID(s): pci\ven_8086&dev_24c5&rev_01,pci\ven_8086&dev_24c5,pci\ven_8086&cc_040100,pci\ven_8086&cc_0401,pci\ven_8086,pci\cc_040100,pci\cc_0401
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [AC97AUD] in "c:\windows\inf\oem23.inf".
#I320 Class GUID of device remains: {4D36E96C-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
#-124 Doing copy-only install of "PCI\VEN_8086&DEV_24C5&SUBSYS_02088086&REV_01\3&267A616A&0&FD".
#W313 Copy target "C:\WINDOWS\System32\a3d.dll" is also a Delete target, forcing COPYFLG_NODECOMP.
#W313 Copy target "C:\WINDOWS\System32\Audio3D.dll" is also a Delete target, forcing COPYFLG_NODECOMP.
[2007/10/15 09:15:26 1492.556 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24c7&subsys_53528086&rev_01,pci\ven_8086&dev_24c7&subsys_53528086,pci\ven_8086&dev_24c7&cc_0c0300,pci\ven_8086&dev_24c7&cc_0c03
#-018 Searching for compatible ID(s): pci\ven_8086&dev_24c7&rev_01,pci\ven_8086&dev_24c7,pci\ven_8086&cc_0c0300,pci\ven_8086&cc_0c03,pci\ven_8086,pci\cc_0c0300,pci\cc_0c03
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [INTEL_USB] in "c:\windows\inf\ich4usb.inf".
#I320 Class GUID of device remains: {36FC9E60-C465-11CF-8056-444553540000}.
#I060 Set selected driver.
[2007/10/15 09:15:26 1492.562 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24cb&subsys_53528086&rev_01,pci\ven_8086&dev_24cb&subsys_53528086,pci\ven_8086&dev_24cb&cc_01018a,pci\ven_8086&dev_24cb&cc_0101
#-018 Searching for compatible ID(s): pci\ven_8086&dev_24cb&rev_01,pci\ven_8086&dev_24cb,pci\ven_8086&cc_01018a,pci\ven_8086&cc_0101,pci\ven_8086,pci\cc_01018a,pci\cc_0101
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [intelide] in "c:\windows\inf\ich4ide.inf".
#I320 Class GUID of device remains: {4D36E96A-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 09:15:27 1492.570 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_2560&subsys_00000000&rev_01,pci\ven_8086&dev_2560&subsys_00000000,pci\ven_8086&dev_2560&rev_01,pci\ven_8086&dev_2560,pci\ven_8086&dev_2560&cc_060000,pci\ven_8086&dev_2560&cc_0600
#-018 Searching for compatible ID(s): pci\ven_8086&cc_060000,pci\ven_8086&cc_0600,pci\ven_8086,pci\cc_060000,pci\cc_0600
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [NO_DRV] in "c:\windows\inf\845g.inf".
#I320 Class GUID of device remains: {4D36E97D-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 09:15:28 1492.576 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_2562&subsys_53528086&rev_01,pci\ven_8086&dev_2562&subsys_53528086,pci\ven_8086&dev_2562&cc_030000,pci\ven_8086&dev_2562&cc_0300
#-018 Searching for compatible ID(s): pci\ven_8086&dev_2562&rev_01,pci\ven_8086&dev_2562,pci\ven_8086&cc_030000,pci\ven_8086&cc_0300,pci\ven_8086,pci\cc_030000,pci\cc_0300
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [i845G] in "c:\windows\inf\oem1.inf".
#I320 Class GUID of device remains: {4D36E968-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 09:15:41 1492.708 Driver Install]
#-019 Searching for hardware ID(s): usb\vid_0545&pid_810a&rev_0500,usb\vid_0545&pid_810a
#-018 Searching for compatible ID(s): usb\class_ff&subclass_ff&prot_ff,usb\class_ff&subclass_ff,usb\class_ff
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [Xirlink.Device.Composite] in "c:\windows\inf\oem31.inf".
#I320 Class GUID of device remains: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F}.
#I060 Set selected driver.
[2007/10/15 09:15:42 1492.714 Driver Install]
#-019 Searching for hardware ID(s): usb\vid_0545&pid_810a&rev_0500,usb\vid_0545&pid_810a
#-018 Searching for compatible ID(s): usb\class_ff&subclass_ff&prot_ff,usb\class_ff&subclass_ff,usb\class_ff
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [Xirlink.Device.Composite] in "c:\windows\inf\oem31.inf".
#I320 Class GUID of device remains: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F}.
#I060 Set selected driver.
[2007/10/15 09:15:42 1492.720 Driver Install]
#-019 Searching for hardware ID(s): usb\vid_0545&pid_810a&rev_0500&mi_00,usb\vid_0545&pid_810a&mi_00
#-018 Searching for compatible ID(s): usb\class_ff&subclass_ff&prot_ff,usb\class_ff&subclass_ff,usb\class_ff
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [Xirlink.Device] in "c:\windows\inf\oem31.inf".
#I320 Class GUID of device remains: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F}.
#I060 Set selected driver.
[2007/10/15 09:15:44 1492.724 Driver Install]
#-019 Searching for hardware ID(s): usb\vid_0545&pid_810a&rev_0500&mi_00,usb\vid_0545&pid_810a&mi_00
#-018 Searching for compatible ID(s): usb\class_ff&subclass_ff&prot_ff,usb\class_ff&subclass_ff,usb\class_ff
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [Xirlink.Device] in "c:\windows\inf\oem31.inf".
#I320 Class GUID of device remains: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F}.
#I060 Set selected driver.
[2007/10/15 09:15:46 1492.746 Driver Install]
#-019 Searching for hardware ID(s): usb\vid_0d64&pid_3108&rev_0100,usb\vid_0d64&pid_3108
#-018 Searching for compatible ID(s): usb\class_08&subclass_05&prot_00,usb\class_08&subclass_05,usb\class_08
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [USBSTOR_CBI] in "c:\windows\inf\oem32.inf".
#I320 Class GUID of device remains: {36FC9E60-C465-11CF-8056-444553540000}.
#I060 Set selected driver.
[2007/10/15 09:15:46 1492.754 Driver Install]
#-019 Searching for hardware ID(s): usb\vid_1915&pid_2236&rev_0132,usb\vid_1915&pid_2236
#-018 Searching for compatible ID(s): usb\class_ff&subclass_ff&prot_ff,usb\class_ff&subclass_ff,usb\class_ff
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [PRISM_USB] in "c:\windows\inf\oem26.inf".
#I320 Class GUID of device remains: {4D36E972-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 09:15:47 1492.758 Driver Install]
#-019 Searching for hardware ID(s): usbprint\canonip150039e6,canonip150039e6
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [CNM_0214XP] in "c:\windows\inf\oem29.inf".
#I320 Class GUID of device remains: {4D36E979-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 09:15:48 1492.762 Driver Install]
#-019 Searching for hardware ID(s): usbprint\hewlett-packarddeskje09c,hewlett-packarddeskje09c
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\fec3752563e444ecc6182e8b7e8bd110\update\update.exe" with command line: update\update.exe /si /ParentInfo:a31a4355718bc740bcc13e3d52cf5e6f
#I063 Selected driver installs from section [HPVDJ89E.GPD.ICM] in "c:\windows\inf\ntprint.inf".
#I320 Class GUID of device remains: {4D36E979-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.

Vince Vespertino
2007-10-15, 21:54
Don't know what happened. I've been using the setupapi log to troubleshoot for the past 3 days after enabling verbose logging but it seems as if the enable was not working during the last attempt this morning.:sad:

I am now sending the previous log (edited with just information from today) from earlier this morning that I believe may better help.

[2007/10/15 08:08:25 2292.475 Driver Install]
#-019 Searching for hardware ID(s): display\in-kch-8xx-chipsets
#-018 Searching for compatible ID(s): display\in-kch-8xx-chipsets
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [KCH.Device] in "c:\windows\inf\oem3.inf".
#I320 Class GUID of device remains: {D07AF4AC-3BED-458D-9A68-380F23572661}.
#I060 Set selected driver.
[2007/10/15 08:08:26 2292.479 Driver Install]
#-019 Searching for hardware ID(s): display\in-sb-8xx-platforms
#-018 Searching for compatible ID(s): display\in-sb-8xx-platforms
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [SoftBIOS.Device] in "c:\windows\inf\oem2.inf".
#I320 Class GUID of device remains: {D07AF4AC-3BED-458D-9A68-380F23572661}.
#I060 Set selected driver.
[2007/10/15 08:08:29 2292.513 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_14f1&dev_2f20&subsys_200014f1&rev_00,pci\ven_14f1&dev_2f20&subsys_200014f1,pci\ven_14f1&dev_2f20&cc_078000,pci\ven_14f1&dev_2f20&cc_0780
#-018 Searching for compatible ID(s): pci\ven_14f1&dev_2f20&rev_00,pci\ven_14f1&dev_2f20,pci\ven_14f1&cc_078000,pci\ven_14f1&cc_0780,pci\ven_14f1,pci\cc_078000,pci\cc_0780
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [ModemX] in "c:\windows\inf\oem0.inf".
#I320 Class GUID of device remains: {4D36E96D-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 08:08:31 2292.517 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_1039&subsys_30488086&rev_81,pci\ven_8086&dev_1039&subsys_30488086,pci\ven_8086&dev_1039&cc_020000,pci\ven_8086&dev_1039&cc_0200
#-018 Searching for compatible ID(s): pci\ven_8086&dev_1039&rev_81,pci\ven_8086&dev_1039,pci\ven_8086&cc_020000,pci\ven_8086&cc_0200,pci\ven_8086,pci\cc_020000,pci\cc_0200
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [XP_D110K.ndi] in "c:\windows\inf\oem19.inf".
#I320 Class GUID of device remains: {4D36E972-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 08:08:31 2292.521 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_244e&subsys_00000000&rev_81,pci\ven_8086&dev_244e&subsys_00000000,pci\ven_8086&dev_244e&rev_81,pci\ven_8086&dev_244e,pci\ven_8086&dev_244e&cc_060400,pci\ven_8086&dev_244e&cc_0604
#-018 Searching for compatible ID(s): pci\ven_8086&cc_060400,pci\ven_8086&cc_0604,pci\ven_8086,pci\cc_060400,pci\cc_0604
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [INTEL_PCI] in "c:\windows\inf\ich4core.inf".
#I320 Class GUID of device remains: {4D36E97D-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 08:08:33 2292.527 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24c0&subsys_00000000&rev_01,pci\ven_8086&dev_24c0&subsys_00000000,pci\ven_8086&dev_24c0&rev_01,pci\ven_8086&dev_24c0,pci\ven_8086&dev_24c0&cc_060100,pci\ven_8086&dev_24c0&cc_0601
#-018 Searching for compatible ID(s): pci\ven_8086&cc_060100,pci\ven_8086&cc_0601,pci\ven_8086,pci\cc_060100,pci\cc_0601
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [INTEL_ISAPNP] in "c:\windows\inf\ich4core.inf".
#I320 Class GUID of device remains: {4D36E97D-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 08:08:33 2292.533 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24c2&subsys_53528086&rev_01,pci\ven_8086&dev_24c2&subsys_53528086,pci\ven_8086&dev_24c2&cc_0c0300,pci\ven_8086&dev_24c2&cc_0c03
#-018 Searching for compatible ID(s): pci\ven_8086&dev_24c2&rev_01,pci\ven_8086&dev_24c2,pci\ven_8086&cc_0c0300,pci\ven_8086&cc_0c03,pci\ven_8086,pci\cc_0c0300,pci\cc_0c03
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [INTEL_USB] in "c:\windows\inf\ich4usb.inf".
#I320 Class GUID of device remains: {36FC9E60-C465-11CF-8056-444553540000}.
#I060 Set selected driver.
[2007/10/15 08:08:34 2292.539 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24c3&subsys_53528086&rev_01,pci\ven_8086&dev_24c3&subsys_53528086,pci\ven_8086&dev_24c3&cc_0c0500,pci\ven_8086&dev_24c3&cc_0c05
#-018 Searching for compatible ID(s): pci\ven_8086&dev_24c3&rev_01,pci\ven_8086&dev_24c3,pci\ven_8086&cc_0c0500,pci\ven_8086&cc_0c05,pci\ven_8086,pci\cc_0c0500,pci\cc_0c05
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [NO_DRV] in "c:\windows\inf\ich4core.inf".
#I320 Class GUID of device remains: {4D36E97D-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 08:08:34 2292.545 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24c4&subsys_53528086&rev_01,pci\ven_8086&dev_24c4&subsys_53528086,pci\ven_8086&dev_24c4&cc_0c0300,pci\ven_8086&dev_24c4&cc_0c03
#-018 Searching for compatible ID(s): pci\ven_8086&dev_24c4&rev_01,pci\ven_8086&dev_24c4,pci\ven_8086&cc_0c0300,pci\ven_8086&cc_0c03,pci\ven_8086,pci\cc_0c0300,pci\cc_0c03
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [INTEL_USB] in "c:\windows\inf\ich4usb.inf".
#I320 Class GUID of device remains: {36FC9E60-C465-11CF-8056-444553540000}.
#I060 Set selected driver.
[2007/10/15 08:08:35 2292.551 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24c5&subsys_02088086&rev_01,pci\ven_8086&dev_24c5&subsys_02088086,pci\ven_8086&dev_24c5&cc_040100,pci\ven_8086&dev_24c5&cc_0401
#-018 Searching for compatible ID(s): pci\ven_8086&dev_24c5&rev_01,pci\ven_8086&dev_24c5,pci\ven_8086&cc_040100,pci\ven_8086&cc_0401,pci\ven_8086,pci\cc_040100,pci\cc_0401
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [AC97AUD] in "c:\windows\inf\oem23.inf".
#I320 Class GUID of device remains: {4D36E96C-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
#-124 Doing copy-only install of "PCI\VEN_8086&DEV_24C5&SUBSYS_02088086&REV_01\3&267A616A&0&FD".
#W313 Copy target "C:\WINDOWS\System32\a3d.dll" is also a Delete target, forcing COPYFLG_NODECOMP.
#W313 Copy target "C:\WINDOWS\System32\Audio3D.dll" is also a Delete target, forcing COPYFLG_NODECOMP.
[2007/10/15 08:08:37 2292.555 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24c7&subsys_53528086&rev_01,pci\ven_8086&dev_24c7&subsys_53528086,pci\ven_8086&dev_24c7&cc_0c0300,pci\ven_8086&dev_24c7&cc_0c03
#-018 Searching for compatible ID(s): pci\ven_8086&dev_24c7&rev_01,pci\ven_8086&dev_24c7,pci\ven_8086&cc_0c0300,pci\ven_8086&cc_0c03,pci\ven_8086,pci\cc_0c0300,pci\cc_0c03
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [INTEL_USB] in "c:\windows\inf\ich4usb.inf".
#I320 Class GUID of device remains: {36FC9E60-C465-11CF-8056-444553540000}.
#I060 Set selected driver.
[2007/10/15 08:08:38 2292.561 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_24cb&subsys_53528086&rev_01,pci\ven_8086&dev_24cb&subsys_53528086,pci\ven_8086&dev_24cb&cc_01018a,pci\ven_8086&dev_24cb&cc_0101
#-018 Searching for compatible ID(s): pci\ven_8086&dev_24cb&rev_01,pci\ven_8086&dev_24cb,pci\ven_8086&cc_01018a,pci\ven_8086&cc_0101,pci\ven_8086,pci\cc_01018a,pci\cc_0101
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [intelide] in "c:\windows\inf\ich4ide.inf".
#I320 Class GUID of device remains: {4D36E96A-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 08:08:39 2292.569 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_2560&subsys_00000000&rev_01,pci\ven_8086&dev_2560&subsys_00000000,pci\ven_8086&dev_2560&rev_01,pci\ven_8086&dev_2560,pci\ven_8086&dev_2560&cc_060000,pci\ven_8086&dev_2560&cc_0600
#-018 Searching for compatible ID(s): pci\ven_8086&cc_060000,pci\ven_8086&cc_0600,pci\ven_8086,pci\cc_060000,pci\cc_0600
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [NO_DRV] in "c:\windows\inf\845g.inf".
#I320 Class GUID of device remains: {4D36E97D-E325-11CE-BFC1-08002BE10318}.

Vince Vespertino
2007-10-15, 21:55
#I060 Set selected driver.
[2007/10/15 08:08:40 2292.575 Driver Install]
#-019 Searching for hardware ID(s): pci\ven_8086&dev_2562&subsys_53528086&rev_01,pci\ven_8086&dev_2562&subsys_53528086,pci\ven_8086&dev_2562&cc_030000,pci\ven_8086&dev_2562&cc_0300
#-018 Searching for compatible ID(s): pci\ven_8086&dev_2562&rev_01,pci\ven_8086&dev_2562,pci\ven_8086&cc_030000,pci\ven_8086&cc_0300,pci\ven_8086,pci\cc_030000,pci\cc_0300
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [i845G] in "c:\windows\inf\oem1.inf".
#I320 Class GUID of device remains: {4D36E968-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 08:08:52 2292.707 Driver Install]
#-019 Searching for hardware ID(s): usb\vid_0545&pid_810a&rev_0500,usb\vid_0545&pid_810a
#-018 Searching for compatible ID(s): usb\class_ff&subclass_ff&prot_ff,usb\class_ff&subclass_ff,usb\class_ff
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [Xirlink.Device.Composite] in "c:\windows\inf\oem31.inf".
#I320 Class GUID of device remains: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F}.
#I060 Set selected driver.
[2007/10/15 08:08:53 2292.713 Driver Install]
#-019 Searching for hardware ID(s): usb\vid_0545&pid_810a&rev_0500,usb\vid_0545&pid_810a
#-018 Searching for compatible ID(s): usb\class_ff&subclass_ff&prot_ff,usb\class_ff&subclass_ff,usb\class_ff
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [Xirlink.Device.Composite] in "c:\windows\inf\oem31.inf".
#I320 Class GUID of device remains: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F}.
#I060 Set selected driver.
[2007/10/15 08:08:54 2292.719 Driver Install]
#-019 Searching for hardware ID(s): usb\vid_0545&pid_810a&rev_0500&mi_00,usb\vid_0545&pid_810a&mi_00
#-018 Searching for compatible ID(s): usb\class_ff&subclass_ff&prot_ff,usb\class_ff&subclass_ff,usb\class_ff
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [Xirlink.Device] in "c:\windows\inf\oem31.inf".
#I320 Class GUID of device remains: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F}.
#I060 Set selected driver.
[2007/10/15 08:08:55 2292.723 Driver Install]
#-019 Searching for hardware ID(s): usb\vid_0545&pid_810a&rev_0500&mi_00,usb\vid_0545&pid_810a&mi_00
#-018 Searching for compatible ID(s): usb\class_ff&subclass_ff&prot_ff,usb\class_ff&subclass_ff,usb\class_ff
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [Xirlink.Device] in "c:\windows\inf\oem31.inf".
#I320 Class GUID of device remains: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F}.
#I060 Set selected driver.
[2007/10/15 08:08:57 2292.745 Driver Install]
#-019 Searching for hardware ID(s): usb\vid_0d64&pid_3108&rev_0100,usb\vid_0d64&pid_3108
#-018 Searching for compatible ID(s): usb\class_08&subclass_05&prot_00,usb\class_08&subclass_05,usb\class_08
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [USBSTOR_CBI] in "c:\windows\inf\oem32.inf".
#I320 Class GUID of device remains: {36FC9E60-C465-11CF-8056-444553540000}.
#I060 Set selected driver.
[2007/10/15 08:08:58 2292.753 Driver Install]
#-019 Searching for hardware ID(s): usb\vid_1915&pid_2236&rev_0132,usb\vid_1915&pid_2236
#-018 Searching for compatible ID(s): usb\class_ff&subclass_ff&prot_ff,usb\class_ff&subclass_ff,usb\class_ff
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [PRISM_USB] in "c:\windows\inf\oem26.inf".
#I320 Class GUID of device remains: {4D36E972-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 08:08:58 2292.757 Driver Install]
#-019 Searching for hardware ID(s): usbprint\canonip150039e6,canonip150039e6
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [CNM_0214XP] in "c:\windows\inf\oem29.inf".
#I320 Class GUID of device remains: {4D36E979-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 08:09:05 2292.761 Driver Install]
#-019 Searching for hardware ID(s): usbprint\hewlett-packarddeskje09c,hewlett-packarddeskje09c
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [HPVDJ89E.GPD.ICM] in "c:\windows\inf\ntprint.inf".

Vince Vespertino
2007-10-15, 21:56
#I320 Class GUID of device remains: {4D36E979-E325-11CE-BFC1-08002BE10318}.
#I060 Set selected driver.
[2007/10/15 08:17:28 2292.1260 Driver Install]
#-019 Searching for hardware ID(s): acpi\genuineintel_-_x86_family_15_model_2,*genuineintel_-_x86_family_15_model_2,acpi\genuineintel_-_x86_family_15,*genuineintel_-_x86_family_15,acpi\genuineintel_-_x86,*genuineintel_-_x86
#-018 Searching for compatible ID(s): acpi\processor
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I022 Found "ACPI\Processor" in C:\WINDOWS\INF\cpu.inf; Device: "Processor"; Driver: "Processor"; Provider: "Microsoft"; Mfg: "(Standard processor types)"; Section name: "Processor_Inst".
#I023 Actual install section: [Processor_Inst.NT]. Rank: 0x00002000. Effective driver date: 07/01/2002.
#-166 Device install function: DIF_SELECTBESTCOMPATDRV.
#I063 Selected driver installs from section [Processor_Inst] in "c:\windows\inf\cpu.inf".
#I320 Class GUID of device remains: {50127DC3-0F36-415E-A6CC-4CB3BE910B65}.
#I060 Set selected driver.
#I058 Selected best compatible driver.
[2007/10/15 08:17:28 2292.1265 Driver Install]
#-406 Obtaining rollback information for device "ACPI\GENUINEINTEL_-_X86_FAMILY_15_MODEL_2\_0":
#-019 Searching for hardware ID(s): acpi\genuineintel_-_x86_family_15_model_2,*genuineintel_-_x86_family_15_model_2,acpi\genuineintel_-_x86_family_15,*genuineintel_-_x86_family_15,acpi\genuineintel_-_x86,*genuineintel_-_x86
#-018 Searching for compatible ID(s): acpi\processor
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [Processor_Inst] in "c:\windows\inf\cpu.inf".
#I320 Class GUID of device remains: {50127DC3-0F36-415E-A6CC-4CB3BE910B65}.
#I060 Set selected driver.
[2007/10/15 08:17:31 2292.1266 Driver Install]
#-019 Searching for hardware ID(s): acpi\genuineintel_-_x86_family_15_model_3,*genuineintel_-_x86_family_15_model_3,acpi\genuineintel_-_x86_family_15,*genuineintel_-_x86_family_15,acpi\genuineintel_-_x86,*genuineintel_-_x86
#-018 Searching for compatible ID(s): acpi\processor
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I022 Found "ACPI\Processor" in C:\WINDOWS\INF\cpu.inf; Device: "Processor"; Driver: "Processor"; Provider: "Microsoft"; Mfg: "(Standard processor types)"; Section name: "Processor_Inst".
#I023 Actual install section: [Processor_Inst.NT]. Rank: 0x00002000. Effective driver date: 07/01/2002.
#-166 Device install function: DIF_SELECTBESTCOMPATDRV.
#I063 Selected driver installs from section [Processor_Inst] in "c:\windows\inf\cpu.inf".
#I320 Class GUID of device remains: {50127DC3-0F36-415E-A6CC-4CB3BE910B65}.
#I060 Set selected driver.
#I058 Selected best compatible driver.
[2007/10/15 08:17:31 2292.1271 Driver Install]
#-406 Obtaining rollback information for device "ACPI\GENUINEINTEL_-_X86_FAMILY_15_MODEL_3\_0":
#-019 Searching for hardware ID(s): acpi\genuineintel_-_x86_family_15_model_3,*genuineintel_-_x86_family_15_model_3,acpi\genuineintel_-_x86_family_15,*genuineintel_-_x86_family_15,acpi\genuineintel_-_x86,*genuineintel_-_x86
#-018 Searching for compatible ID(s): acpi\processor
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#I063 Selected driver installs from section [Processor_Inst] in "c:\windows\inf\cpu.inf".
#I320 Class GUID of device remains: {50127DC3-0F36-415E-A6CC-4CB3BE910B65}.
#I060 Set selected driver.
[2007/10/15 08:07:37 2292.7]
#-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.exe" with command line: update\update.exe -z /DefaultUninstallNoPrompt /AcceptEulaNoPrompt /DefaultFinishNoPrompt /ParentInfo:07f706a39d8a164aba11caa3ff2bca4b
#E197 Writing "C:\WINDOWS\INF\wmp.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wdma_via.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wdma_int.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wdma_ali.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E099 Writing of "C:\WINDOWS\INF\unregmp2.exe" to "C:\WINDOWS\INF" can cause problems.
#E197 Writing "C:\WINDOWS\INF\skins.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\setupqry.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\qmgr.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netwv48.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netwlan2.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netwlan.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netrtsnt.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netnm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netklsi.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mymusic.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\msnetmtg.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mplayer2.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\moviemk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmvv.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmusrk1.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmsuprv.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmrpci.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmlt3.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmirmdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmgen.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmetech.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\i81xnt5.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\g400.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\fxsocm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\fp40ext.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wstcodec.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wordpad.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\usbport.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\tsoc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\tape.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\syssetup.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\sysoc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\swflash.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\streamip.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.

Vince Vespertino
2007-10-15, 21:57
#E197 Writing "C:\WINDOWS\INF\smartcrd.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\slip.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\shl_img.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\shell.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\secrecs.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\scsi.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\sceregvl.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\pnpscsi.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\pchealth.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\oobe.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ntprint.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netwzc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netupnph.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nettcpip.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netrass.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netoc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netmscli.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netip6.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ndisip.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nabtsfec.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\multimed.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mstape.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\msoe50.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mshdc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mpe.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdac.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mchgr.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\machine.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\layout.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ksfilter.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\kscaptur.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ks.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\keyboard.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\intl.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\input.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ims.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\iis.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ieaccess.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ie.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\hidserv.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\drvindex.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\dwup.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\disk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\devxprop.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\defltwk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\cpu.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\cdrom.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ccdecode.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\biosinfo.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\bda.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\battery.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\au.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\acpi.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\accessor.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E099 Writing of "C:\WINDOWS\INF\wuau.adm" to "C:\WINDOWS\INF" can cause problems.
#E197 Writing "C:\WINDOWS\INF\wtv5.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wtv4.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wtv3.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wtv2.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wtv1.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wtv0.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wmpocm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wmfsdk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wmdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wmaccess.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp8.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp7.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp6.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp5.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp4.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp3.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp2.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp1.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp0.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\tdibth.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ramdisk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ps5333.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\parhmse.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\oeaccess.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nvts.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nvdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nvct.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nv4_disp.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nettun.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netrndis.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netbeac.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmntstm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmhamrw.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmcxsf2.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmbtmdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\hidbth.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\drm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\bthspp.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\bthprint.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\bthpan.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\bth.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\atixpwdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\atiixpag.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\atiixpaa.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ati1xwdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\usbvideo.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\startoc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\sffdisk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\sdbus.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\p2p.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netfw.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\hiddigi.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\fltmgr.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.

Vince Vespertino
2007-10-15, 21:58
#E197 Writing "C:\WINDOWS\INF\agp.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\msmsgs.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wzcsvc.dll" to "C:\WINDOWS\System32\wzcsvc.dll" via temporary file "C:\WINDOWS\System32\SET4D8.tmp".
#W190 File "C:\WINDOWS\System32\SET4D8.tmp" marked to be moved to "C:\WINDOWS\System32\wzcsvc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wtsapi32.dll" to "C:\WINDOWS\System32\wtsapi32.dll" via temporary file "C:\WINDOWS\System32\SET547.tmp".
#W190 File "C:\WINDOWS\System32\SET547.tmp" marked to be moved to "C:\WINDOWS\System32\wtsapi32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wsock32.dll" to "C:\WINDOWS\System32\wsock32.dll" via temporary file "C:\WINDOWS\System32\SET57D.tmp".
#W190 File "C:\WINDOWS\System32\SET57D.tmp" marked to be moved to "C:\WINDOWS\System32\wsock32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wshtcpip.dll" to "C:\WINDOWS\System32\wshtcpip.dll" via temporary file "C:\WINDOWS\System32\SET592.tmp".
#W190 File "C:\WINDOWS\System32\SET592.tmp" marked to be moved to "C:\WINDOWS\System32\wshtcpip.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ws2help.dll" to "C:\WINDOWS\System32\ws2help.dll" via temporary file "C:\WINDOWS\System32\SET5E3.tmp".
#W190 File "C:\WINDOWS\System32\SET5E3.tmp" marked to be moved to "C:\WINDOWS\System32\ws2help.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ws2_32.dll" to "C:\WINDOWS\System32\ws2_32.dll" via temporary file "C:\WINDOWS\System32\SET5E4.tmp".
#W190 File "C:\WINDOWS\System32\SET5E4.tmp" marked to be moved to "C:\WINDOWS\System32\ws2_32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wow32.dll" to "C:\WINDOWS\System32\wow32.dll" via temporary file "C:\WINDOWS\System32\SET678.tmp".
#W190 File "C:\WINDOWS\System32\SET678.tmp" marked to be moved to "C:\WINDOWS\System32\wow32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wmi.dll" to "C:\WINDOWS\System32\wmi.dll" via temporary file "C:\WINDOWS\System32\SET71B.tmp".
#W190 File "C:\WINDOWS\System32\SET71B.tmp" marked to be moved to "C:\WINDOWS\System32\wmi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wlnotify.dll" to "C:\WINDOWS\System32\wlnotify.dll" via temporary file "C:\WINDOWS\System32\SET742.tmp".
#W190 File "C:\WINDOWS\System32\SET742.tmp" marked to be moved to "C:\WINDOWS\System32\wlnotify.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wldap32.dll" to "C:\WINDOWS\System32\wldap32.dll" via temporary file "C:\WINDOWS\System32\SET74C.tmp".
#W190 File "C:\WINDOWS\System32\SET74C.tmp" marked to be moved to "C:\WINDOWS\System32\wldap32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wintrust.dll" to "C:\WINDOWS\System32\wintrust.dll" via temporary file "C:\WINDOWS\System32\SET755.tmp".
#W190 File "C:\WINDOWS\System32\SET755.tmp" marked to be moved to "C:\WINDOWS\System32\wintrust.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\winsta.dll" to "C:\WINDOWS\System32\winsta.dll" via temporary file "C:\WINDOWS\System32\SET791.tmp".
#W190 File "C:\WINDOWS\System32\SET791.tmp" marked to be moved to "C:\WINDOWS\System32\winsta.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\winsrv.dll" to "C:\WINDOWS\System32\winsrv.dll" via temporary file "C:\WINDOWS\System32\SET79C.tmp".
#W190 File "C:\WINDOWS\System32\SET79C.tmp" marked to be moved to "C:\WINDOWS\System32\winsrv.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\winscard.dll" to "C:\WINDOWS\System32\winscard.dll" via temporary file "C:\WINDOWS\System32\SET7AD.tmp".
#W190 File "C:\WINDOWS\System32\SET7AD.tmp" marked to be moved to "C:\WINDOWS\System32\winscard.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\winrnr.dll" to "C:\WINDOWS\System32\winrnr.dll" via temporary file "C:\WINDOWS\System32\SET7AF.tmp".
#W190 File "C:\WINDOWS\System32\SET7AF.tmp" marked to be moved to "C:\WINDOWS\System32\winrnr.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\winmm.dll" to "C:\WINDOWS\System32\winmm.dll" via temporary file "C:\WINDOWS\System32\SET7B4.tmp".
#W190 File "C:\WINDOWS\System32\SET7B4.tmp" marked to be moved to "C:\WINDOWS\System32\winmm.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\winlogon.exe" to "C:\WINDOWS\System32\winlogon.exe" via temporary file "C:\WINDOWS\System32\SET7B8.tmp".
#W190 File "C:\WINDOWS\System32\SET7B8.tmp" marked to be moved to "C:\WINDOWS\System32\winlogon.exe" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\winipsec.dll" to "C:\WINDOWS\System32\winipsec.dll" via temporary file "C:\WINDOWS\System32\SET7B9.tmp".
#W190 File "C:\WINDOWS\System32\SET7B9.tmp" marked to be moved to "C:\WINDOWS\System32\winipsec.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wininet.dll" to "C:\WINDOWS\System32\wininet.dll" via temporary file "C:\WINDOWS\System32\SET7C1.tmp".
#W190 File "C:\WINDOWS\System32\SET7C1.tmp" marked to be moved to "C:\WINDOWS\System32\wininet.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wiaservc.dll" to "C:\WINDOWS\System32\wiaservc.dll" via temporary file "C:\WINDOWS\System32\SET7E5.tmp".
#W190 File "C:\WINDOWS\System32\SET7E5.tmp" marked to be moved to "C:\WINDOWS\System32\wiaservc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\webclnt.dll" to "C:\WINDOWS\System32\webclnt.dll" via temporary file "C:\WINDOWS\System32\SET814.tmp".
#W190 File "C:\WINDOWS\System32\SET814.tmp" marked to be moved to "C:\WINDOWS\System32\webclnt.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\webcheck.dll" to "C:\WINDOWS\System32\webcheck.dll" via temporary file "C:\WINDOWS\System32\SET818.tmp".
#W190 File "C:\WINDOWS\System32\SET818.tmp" marked to be moved to "C:\WINDOWS\System32\webcheck.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wdmaud.drv" to "C:\WINDOWS\System32\wdmaud.drv" via temporary file "C:\WINDOWS\System32\SET81E.tmp".
#W190 File "C:\WINDOWS\System32\SET81E.tmp" marked to be moved to "C:\WINDOWS\System32\wdmaud.drv" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wdigest.dll" to "C:\WINDOWS\System32\wdigest.dll" via temporary file "C:\WINDOWS\System32\SET823.tmp".
#W190 File "C:\WINDOWS\System32\SET823.tmp" marked to be moved to "C:\WINDOWS\System32\wdigest.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\w32time.dll" to "C:\WINDOWS\System32\w32time.dll" via temporary file "C:\WINDOWS\System32\SET842.tmp".
#W190 File "C:\WINDOWS\System32\SET842.tmp" marked to be moved to "C:\WINDOWS\System32\w32time.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\vssapi.dll" to "C:\WINDOWS\System32\vssapi.dll" via temporary file "C:\WINDOWS\System32\SET848.tmp".
#W190 File "C:\WINDOWS\System32\SET848.tmp" marked to be moved to "C:\WINDOWS\System32\vssapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\version.dll" to "C:\WINDOWS\System32\version.dll" via temporary file "C:\WINDOWS\System32\SET84C.tmp".
#W190 File "C:\WINDOWS\System32\SET84C.tmp" marked to be moved to "C:\WINDOWS\System32\version.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\vdmdbg.dll" to "C:\WINDOWS\System32\vdmdbg.dll" via temporary file "C:\WINDOWS\System32\SET84E.tmp".
#W190 File "C:\WINDOWS\System32\SET84E.tmp" marked to be moved to "C:\WINDOWS\System32\vdmdbg.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\vbscript.dll" to "C:\WINDOWS\System32\vbscript.dll" via temporary file "C:\WINDOWS\System32\SET84F.tmp".
#W190 File "C:\WINDOWS\System32\SET84F.tmp" marked to be moved to "C:\WINDOWS\System32\vbscript.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\uxtheme.dll" to "C:\WINDOWS\System32\uxtheme.dll" via temporary file "C:\WINDOWS\System32\SET866.tmp".
#W190 File "C:\WINDOWS\System32\SET866.tmp" marked to be moved to "C:\WINDOWS\System32\uxtheme.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\userenv.dll" to "C:\WINDOWS\System32\userenv.dll" via temporary file "C:\WINDOWS\System32\SET879.tmp".
#W190 File "C:\WINDOWS\System32\SET879.tmp" marked to be moved to "C:\WINDOWS\System32\userenv.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\user32.dll" to "C:\WINDOWS\System32\user32.dll" via temporary file "C:\WINDOWS\System32\SET87A.tmp".
#W190 File "C:\WINDOWS\System32\SET87A.tmp" marked to be moved to "C:\WINDOWS\System32\user32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\usbmon.dll" to "C:\WINDOWS\System32\usbmon.dll" via temporary file "C:\WINDOWS\System32\SET87C.tmp".
#W190 File "C:\WINDOWS\System32\SET87C.tmp" marked to be moved to "C:\WINDOWS\System32\usbmon.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\urlmon.dll" to "C:\WINDOWS\System32\urlmon.dll" via temporary file "C:\WINDOWS\System32\SET87D.tmp".
#W190 File "C:\WINDOWS\System32\SET87D.tmp" marked to be moved to "C:\WINDOWS\System32\urlmon.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\url.dll" to "C:\WINDOWS\System32\url.dll" via temporary file "C:\WINDOWS\System32\SET87E.tmp".
#W190 File "C:\WINDOWS\System32\SET87E.tmp" marked to be moved to "C:\WINDOWS\System32\url.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\upnp.dll" to "C:\WINDOWS\System32\upnp.dll" via temporary file "C:\WINDOWS\System32\SET887.tmp".
#W190 File "C:\WINDOWS\System32\SET887.tmp" marked to be moved to "C:\WINDOWS\System32\upnp.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\uniplat.dll" to "C:\WINDOWS\System32\uniplat.dll" via temporary file "C:\WINDOWS\System32\SET889.tmp".
#W190 File "C:\WINDOWS\System32\SET889.tmp" marked to be moved to "C:\WINDOWS\System32\uniplat.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\unimdmat.dll" to "C:\WINDOWS\System32\unimdmat.dll" via temporary file "C:\WINDOWS\System32\SET88E.tmp".
#W190 File "C:\WINDOWS\System32\SET88E.tmp" marked to be moved to "C:\WINDOWS\System32\unimdmat.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\unimdm.tsp" to "C:\WINDOWS\System32\unimdm.tsp" via temporary file "C:\WINDOWS\System32\SET893.tmp".
#W190 File "C:\WINDOWS\System32\SET893.tmp" marked to be moved to "C:\WINDOWS\System32\unimdm.tsp" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\umpnpmgr.dll" to "C:\WINDOWS\System32\umpnpmgr.dll" via temporary file "C:\WINDOWS\System32\SET899.tmp".
#W190 File "C:\WINDOWS\System32\SET899.tmp" marked to be moved to "C:\WINDOWS\System32\umpnpmgr.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\trkwks.dll" to "C:\WINDOWS\System32\trkwks.dll" via temporary file "C:\WINDOWS\System32\SET8E2.tmp".
#W190 File "C:\WINDOWS\System32\SET8E2.tmp" marked to be moved to "C:\WINDOWS\System32\trkwks.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\themeui.dll" to "C:\WINDOWS\System32\themeui.dll" via temporary file "C:\WINDOWS\System32\SET8F3.tmp".
#W190 File "C:\WINDOWS\System32\SET8F3.tmp" marked to be moved to "C:\WINDOWS\System32\themeui.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\termsrv.dll" to "C:\WINDOWS\System32\termsrv.dll" via temporary file "C:\WINDOWS\System32\SET8F7.tmp".
#W190 File "C:\WINDOWS\System32\SET8F7.tmp" marked to be moved to "C:\WINDOWS\System32\termsrv.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\tcpmon.dll" to "C:\WINDOWS\System32\tcpmon.dll" via temporary file "C:\WINDOWS\System32\SET903.tmp".
#W190 File "C:\WINDOWS\System32\SET903.tmp" marked to be moved to "C:\WINDOWS\System32\tcpmon.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\tapisrv.dll" to "C:\WINDOWS\System32\tapisrv.dll" via temporary file "C:\WINDOWS\System32\SET907.tmp".
#W190 File "C:\WINDOWS\System32\SET907.tmp" marked to be moved to "C:\WINDOWS\System32\tapisrv.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\tapi32.dll" to "C:\WINDOWS\System32\tapi32.dll" via temporary file "C:\WINDOWS\System32\SET908.tmp".
#W190 File "C:\WINDOWS\System32\SET908.tmp" marked to be moved to "C:\WINDOWS\System32\tapi32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sxs.dll" to "C:\WINDOWS\System32\sxs.dll" via temporary file "C:\WINDOWS\System32\SET91E.tmp".
#W190 File "C:\WINDOWS\System32\SET91E.tmp" marked to be moved to "C:\WINDOWS\System32\sxs.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\svchost.exe" to "C:\WINDOWS\System32\svchost.exe" via temporary file "C:\WINDOWS\System32\SET91F.tmp".
#W190 File "C:\WINDOWS\System32\SET91F.tmp" marked to be moved to "C:\WINDOWS\System32\svchost.exe" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\stobject.dll" to "C:\WINDOWS\System32\stobject.dll" via temporary file "C:\WINDOWS\System32\SET924.tmp".
#W190 File "C:\WINDOWS\System32\SET924.tmp" marked to be moved to "C:\WINDOWS\System32\stobject.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ssdpsrv.dll" to "C:\WINDOWS\System32\ssdpsrv.dll" via temporary file "C:\WINDOWS\System32\SET944.tmp".
#W190 File "C:\WINDOWS\System32\SET944.tmp" marked to be moved to "C:\WINDOWS\System32\ssdpsrv.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ssdpapi.dll" to "C:\WINDOWS\System32\ssdpapi.dll" via temporary file "C:\WINDOWS\System32\SET949.tmp".
#W190 File "C:\WINDOWS\System32\SET949.tmp" marked to be moved to "C:\WINDOWS\System32\ssdpapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\srsvc.dll" to "C:\WINDOWS\System32\srsvc.dll" via temporary file "C:\WINDOWS\System32\SET95E.tmp".

Vince Vespertino
2007-10-15, 22:01
#W190 File "C:\WINDOWS\System32\SET95E.tmp" marked to be moved to "C:\WINDOWS\System32\srsvc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\srclient.dll" to "C:\WINDOWS\System32\srclient.dll" via temporary file "C:\WINDOWS\System32\SET962.tmp".
#W190 File "C:\WINDOWS\System32\SET962.tmp" marked to be moved to "C:\WINDOWS\System32\srclient.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sqlunirl.dll" to "C:\WINDOWS\System32\sqlunirl.dll" via temporary file "C:\WINDOWS\System32\SET966.tmp".
#W190 File "C:\WINDOWS\System32\SET966.tmp" marked to be moved to "C:\WINDOWS\System32\sqlunirl.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sqlsrv32.rll" to "C:\WINDOWS\System32\sqlsrv32.rll" via temporary file "C:\WINDOWS\System32\SET968.tmp".
#W190 File "C:\WINDOWS\System32\SET968.tmp" marked to be moved to "C:\WINDOWS\System32\sqlsrv32.rll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sqlsrv32.dll" to "C:\WINDOWS\System32\sqlsrv32.dll" via temporary file "C:\WINDOWS\System32\SET96A.tmp".
#W190 File "C:\WINDOWS\System32\SET96A.tmp" marked to be moved to "C:\WINDOWS\System32\sqlsrv32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\spoolsv.exe" to "C:\WINDOWS\System32\spoolsv.exe" via temporary file "C:\WINDOWS\System32\SET96B.tmp".
#W190 File "C:\WINDOWS\System32\SET96B.tmp" marked to be moved to "C:\WINDOWS\System32\spoolsv.exe" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\spoolss.dll" to "C:\WINDOWS\System32\spoolss.dll" via temporary file "C:\WINDOWS\System32\SET96D.tmp".
#W190 File "C:\WINDOWS\System32\SET96D.tmp" marked to be moved to "C:\WINDOWS\System32\spoolss.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\shsvcs.dll" to "C:\WINDOWS\System32\shsvcs.dll" via temporary file "C:\WINDOWS\System32\SET9A4.tmp".
#W190 File "C:\WINDOWS\System32\SET9A4.tmp" marked to be moved to "C:\WINDOWS\System32\shsvcs.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\shlwapi.dll" to "C:\WINDOWS\System32\shlwapi.dll" via temporary file "C:\WINDOWS\System32\SET9A9.tmp".
#W190 File "C:\WINDOWS\System32\SET9A9.tmp" marked to be moved to "C:\WINDOWS\System32\shlwapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\shimeng.dll" to "C:\WINDOWS\System32\shimeng.dll" via temporary file "C:\WINDOWS\System32\SET9AB.tmp".
#W190 File "C:\WINDOWS\System32\SET9AB.tmp" marked to be moved to "C:\WINDOWS\System32\shimeng.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\shfolder.dll" to "C:\WINDOWS\System32\shfolder.dll" via temporary file "C:\WINDOWS\System32\SET9AD.tmp".
#W190 File "C:\WINDOWS\System32\SET9AD.tmp" marked to be moved to "C:\WINDOWS\System32\shfolder.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\shell32.dll" to "C:\WINDOWS\System32\shell32.dll" via temporary file "C:\WINDOWS\System32\SET9AE.tmp".
#W190 File "C:\WINDOWS\System32\SET9AE.tmp" marked to be moved to "C:\WINDOWS\System32\shell32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\shdocvw.dll" to "C:\WINDOWS\System32\shdocvw.dll" via temporary file "C:\WINDOWS\System32\SET9AF.tmp".
#W190 File "C:\WINDOWS\System32\SET9AF.tmp" marked to be moved to "C:\WINDOWS\System32\shdocvw.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\shdoclc.dll" to "C:\WINDOWS\System32\shdoclc.dll" via temporary file "C:\WINDOWS\System32\SET9B5.tmp".
#W190 File "C:\WINDOWS\System32\SET9B5.tmp" marked to be moved to "C:\WINDOWS\System32\shdoclc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sfc_os.dll" to "C:\WINDOWS\System32\sfc_os.dll" via temporary file "C:\WINDOWS\System32\SET9B9.tmp".
#W190 File "C:\WINDOWS\System32\SET9B9.tmp" marked to be moved to "C:\WINDOWS\System32\sfc_os.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sfc.dll" to "C:\WINDOWS\System32\sfc.dll" via temporary file "C:\WINDOWS\System32\SET9BA.tmp".
#W190 File "C:\WINDOWS\System32\SET9BA.tmp" marked to be moved to "C:\WINDOWS\System32\sfc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sensapi.dll" to "C:\WINDOWS\System32\sensapi.dll" via temporary file "C:\WINDOWS\System32\SET9C1.tmp".
#W190 File "C:\WINDOWS\System32\SET9C1.tmp" marked to be moved to "C:\WINDOWS\System32\sensapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sens.dll" to "C:\WINDOWS\System32\sens.dll" via temporary file "C:\WINDOWS\System32\SET9C2.tmp".
#W190 File "C:\WINDOWS\System32\SET9C2.tmp" marked to be moved to "C:\WINDOWS\System32\sens.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\secur32.dll" to "C:\WINDOWS\System32\secur32.dll" via temporary file "C:\WINDOWS\System32\SET9D6.tmp".
#W190 File "C:\WINDOWS\System32\SET9D6.tmp" marked to be moved to "C:\WINDOWS\System32\secur32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\seclogon.dll" to "C:\WINDOWS\System32\seclogon.dll" via temporary file "C:\WINDOWS\System32\SET9D8.tmp".
#W190 File "C:\WINDOWS\System32\SET9D8.tmp" marked to be moved to "C:\WINDOWS\System32\seclogon.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\scrrun.dll" to "C:\WINDOWS\System32\scrrun.dll" via temporary file "C:\WINDOWS\System32\SET9DE.tmp".
#W190 File "C:\WINDOWS\System32\SET9DE.tmp" marked to be moved to "C:\WINDOWS\System32\scrrun.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\schedsvc.dll" to "C:\WINDOWS\System32\schedsvc.dll" via temporary file "C:\WINDOWS\System32\SET9EE.tmp".
#W190 File "C:\WINDOWS\System32\SET9EE.tmp" marked to be moved to "C:\WINDOWS\System32\schedsvc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\scesrv.dll" to "C:\WINDOWS\System32\scesrv.dll" via temporary file "C:\WINDOWS\System32\SET9F0.tmp".
#W190 File "C:\WINDOWS\System32\SET9F0.tmp" marked to be moved to "C:\WINDOWS\System32\scesrv.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\scecli.dll" to "C:\WINDOWS\System32\scecli.dll" via temporary file "C:\WINDOWS\System32\SET9F8.tmp".
#W190 File "C:\WINDOWS\System32\SET9F8.tmp" marked to be moved to "C:\WINDOWS\System32\scecli.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\rtutils.dll" to "C:\WINDOWS\System32\rtutils.dll" via temporary file "C:\WINDOWS\System32\SETA10.tmp".
#W190 File "C:\WINDOWS\System32\SETA10.tmp" marked to be moved to "C:\WINDOWS\System32\rtutils.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\rsaenh.dll" to "C:\WINDOWS\System32\rsaenh.dll" via temporary file "C:\WINDOWS\System32\SETA21.tmp".
#W190 File "C:\WINDOWS\System32\SETA21.tmp" marked to be moved to "C:\WINDOWS\System32\rsaenh.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\rpcss.dll" to "C:\WINDOWS\System32\rpcss.dll" via temporary file "C:\WINDOWS\System32\SETA22.tmp".
#W190 File "C:\WINDOWS\System32\SETA22.tmp" marked to be moved to "C:\WINDOWS\System32\rpcss.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\rpcrt4.dll" to "C:\WINDOWS\System32\rpcrt4.dll" via temporary file "C:\WINDOWS\System32\SETA23.tmp".
#W190 File "C:\WINDOWS\System32\SETA23.tmp" marked to be moved to "C:\WINDOWS\System32\rpcrt4.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\riched20.dll" to "C:\WINDOWS\System32\riched20.dll" via temporary file "C:\WINDOWS\System32\SETA27.tmp".
#W190 File "C:\WINDOWS\System32\SETA27.tmp" marked to be moved to "C:\WINDOWS\System32\riched20.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\resutils.dll" to "C:\WINDOWS\System32\resutils.dll" via temporary file "C:\WINDOWS\System32\SETA2C.tmp".
#W190 File "C:\WINDOWS\System32\SETA2C.tmp" marked to be moved to "C:\WINDOWS\System32\resutils.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\regapi.dll" to "C:\WINDOWS\System32\regapi.dll" via temporary file "C:\WINDOWS\System32\SETA3B.tmp".
#W190 File "C:\WINDOWS\System32\SETA3B.tmp" marked to be moved to "C:\WINDOWS\System32\regapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\rastls.dll" to "C:\WINDOWS\System32\rastls.dll" via temporary file "C:\WINDOWS\System32\SETA53.tmp".
#W190 File "C:\WINDOWS\System32\SETA53.tmp" marked to be moved to "C:\WINDOWS\System32\rastls.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\rasppp.dll" to "C:\WINDOWS\System32\rasppp.dll" via temporary file "C:\WINDOWS\System32\SETA56.tmp".
#W190 File "C:\WINDOWS\System32\SETA56.tmp" marked to be moved to "C:\WINDOWS\System32\rasppp.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\rasmans.dll" to "C:\WINDOWS\System32\rasmans.dll" via temporary file "C:\WINDOWS\System32\SETA5D.tmp".
#W190 File "C:\WINDOWS\System32\SETA5D.tmp" marked to be moved to "C:\WINDOWS\System32\rasmans.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\raschap.dll" to "C:\WINDOWS\System32\raschap.dll" via temporary file "C:\WINDOWS\System32\SETA60.tmp".
#W190 File "C:\WINDOWS\System32\SETA60.tmp" marked to be moved to "C:\WINDOWS\System32\raschap.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\rasadhlp.dll" to "C:\WINDOWS\System32\rasadhlp.dll" via temporary file "C:\WINDOWS\System32\SETA61.tmp".
#W190 File "C:\WINDOWS\System32\SETA61.tmp" marked to be moved to "C:\WINDOWS\System32\rasadhlp.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\pstorsvc.dll" to "C:\WINDOWS\System32\pstorsvc.dll" via temporary file "C:\WINDOWS\System32\SETA71.tmp".
#W190 File "C:\WINDOWS\System32\SETA71.tmp" marked to be moved to "C:\WINDOWS\System32\pstorsvc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\psbase.dll" to "C:\WINDOWS\System32\psbase.dll" via temporary file "C:\WINDOWS\System32\SETA77.tmp".
#W190 File "C:\WINDOWS\System32\SETA77.tmp" marked to be moved to "C:\WINDOWS\System32\psbase.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\psapi.dll" to "C:\WINDOWS\System32\psapi.dll" via temporary file "C:\WINDOWS\System32\SETA79.tmp".
#W190 File "C:\WINDOWS\System32\SETA79.tmp" marked to be moved to "C:\WINDOWS\System32\psapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\profmap.dll" to "C:\WINDOWS\System32\profmap.dll" via temporary file "C:\WINDOWS\System32\SETA7C.tmp".
#W190 File "C:\WINDOWS\System32\SETA7C.tmp" marked to be moved to "C:\WINDOWS\System32\profmap.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\powrprof.dll" to "C:\WINDOWS\System32\powrprof.dll" via temporary file "C:\WINDOWS\System32\SETA7E.tmp".
#W190 File "C:\WINDOWS\System32\SETA7E.tmp" marked to be moved to "C:\WINDOWS\System32\powrprof.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\pngfilt.dll" to "C:\WINDOWS\System32\pngfilt.dll" via temporary file "C:\WINDOWS\System32\SETA81.tmp".
#W190 File "C:\WINDOWS\System32\SETA81.tmp" marked to be moved to "C:\WINDOWS\System32\pngfilt.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\pjlmon.dll" to "C:\WINDOWS\System32\pjlmon.dll" via temporary file "C:\WINDOWS\System32\SETA82.tmp".
#W190 File "C:\WINDOWS\System32\SETA82.tmp" marked to be moved to "C:\WINDOWS\System32\pjlmon.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\olepro32.dll" to "C:\WINDOWS\System32\olepro32.dll" via temporary file "C:\WINDOWS\System32\SETA9D.tmp".
#W190 File "C:\WINDOWS\System32\SETA9D.tmp" marked to be moved to "C:\WINDOWS\System32\olepro32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ole32.dll" to "C:\WINDOWS\System32\ole32.dll" via temporary file "C:\WINDOWS\System32\SETA9F.tmp".
#W190 File "C:\WINDOWS\System32\SETA9F.tmp" marked to be moved to "C:\WINDOWS\System32\ole32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\odbctrac.dll" to "C:\WINDOWS\System32\odbctrac.dll" via temporary file "C:\WINDOWS\System32\SETAA6.tmp".
#W190 File "C:\WINDOWS\System32\SETAA6.tmp" marked to be moved to "C:\WINDOWS\System32\odbctrac.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\odbcp32r.dll" to "C:\WINDOWS\System32\odbcp32r.dll" via temporary file "C:\WINDOWS\System32\SETAA7.tmp".
#W190 File "C:\WINDOWS\System32\SETAA7.tmp" marked to be moved to "C:\WINDOWS\System32\odbcp32r.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\odbcint.dll" to "C:\WINDOWS\System32\odbcint.dll" via temporary file "C:\WINDOWS\System32\SETAAA.tmp".
#W190 File "C:\WINDOWS\System32\SETAAA.tmp" marked to be moved to "C:\WINDOWS\System32\odbcint.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\odbccu32.dll" to "C:\WINDOWS\System32\odbccu32.dll" via temporary file "C:\WINDOWS\System32\SETAAD.tmp".
#W190 File "C:\WINDOWS\System32\SETAAD.tmp" marked to be moved to "C:\WINDOWS\System32\odbccu32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\odbccr32.dll" to "C:\WINDOWS\System32\odbccr32.dll" via temporary file "C:\WINDOWS\System32\SETAAF.tmp".
#W190 File "C:\WINDOWS\System32\SETAAF.tmp" marked to be moved to "C:\WINDOWS\System32\odbccr32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\odbccp32.dll" to "C:\WINDOWS\System32\odbccp32.dll" via temporary file "C:\WINDOWS\System32\SETAB0.tmp".
#W190 File "C:\WINDOWS\System32\SETAB0.tmp" marked to be moved to "C:\WINDOWS\System32\odbccp32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\odbccp32.cpl" to "C:\WINDOWS\System32\odbccp32.cpl" via temporary file "C:\WINDOWS\System32\SETAB3.tmp".
#W190 File "C:\WINDOWS\System32\SETAB3.tmp" marked to be moved to "C:\WINDOWS\System32\odbccp32.cpl" on next reboot.

Vince Vespertino
2007-10-15, 22:02
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\odbcconf.exe" to "C:\WINDOWS\System32\odbcconf.exe" via temporary file "C:\WINDOWS\System32\SETAB5.tmp".
#W190 File "C:\WINDOWS\System32\SETAB5.tmp" marked to be moved to "C:\WINDOWS\System32\odbcconf.exe" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\odbcconf.dll" to "C:\WINDOWS\System32\odbcconf.dll" via temporary file "C:\WINDOWS\System32\SETAB6.tmp".
#W190 File "C:\WINDOWS\System32\SETAB6.tmp" marked to be moved to "C:\WINDOWS\System32\odbcconf.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\odbcbcp.dll" to "C:\WINDOWS\System32\odbcbcp.dll" via temporary file "C:\WINDOWS\System32\SETAB9.tmp".
#W190 File "C:\WINDOWS\System32\SETAB9.tmp" marked to be moved to "C:\WINDOWS\System32\odbcbcp.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\odbcad32.exe" to "C:\WINDOWS\System32\odbcad32.exe" via temporary file "C:\WINDOWS\System32\SETABE.tmp".
#W190 File "C:\WINDOWS\System32\SETABE.tmp" marked to be moved to "C:\WINDOWS\System32\odbcad32.exe" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\odbc32gt.dll" to "C:\WINDOWS\System32\odbc32gt.dll" via temporary file "C:\WINDOWS\System32\SETAC0.tmp".
#W190 File "C:\WINDOWS\System32\SETAC0.tmp" marked to be moved to "C:\WINDOWS\System32\odbc32gt.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\odbc32.dll" to "C:\WINDOWS\System32\odbc32.dll" via temporary file "C:\WINDOWS\System32\SETAC5.tmp".
#W190 File "C:\WINDOWS\System32\SETAC5.tmp" marked to be moved to "C:\WINDOWS\System32\odbc32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\oakley.dll" to "C:\WINDOWS\System32\oakley.dll" via temporary file "C:\WINDOWS\System32\SETACC.tmp".
#W190 File "C:\WINDOWS\System32\SETACC.tmp" marked to be moved to "C:\WINDOWS\System32\oakley.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ntshrui.dll" to "C:\WINDOWS\System32\ntshrui.dll" via temporary file "C:\WINDOWS\System32\SETACE.tmp".
#W190 File "C:\WINDOWS\System32\SETACE.tmp" marked to be moved to "C:\WINDOWS\System32\ntshrui.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ntmarta.dll" to "C:\WINDOWS\System32\ntmarta.dll" via temporary file "C:\WINDOWS\System32\SETAD5.tmp".
#W190 File "C:\WINDOWS\System32\SETAD5.tmp" marked to be moved to "C:\WINDOWS\System32\ntmarta.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ntlanman.dll" to "C:\WINDOWS\System32\ntlanman.dll" via temporary file "C:\WINDOWS\System32\SETAD6.tmp".
#W190 File "C:\WINDOWS\System32\SETAD6.tmp" marked to be moved to "C:\WINDOWS\System32\ntlanman.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ntdsapi.dll" to "C:\WINDOWS\System32\ntdsapi.dll" via temporary file "C:\WINDOWS\System32\SETAD7.tmp".
#W190 File "C:\WINDOWS\System32\SETAD7.tmp" marked to be moved to "C:\WINDOWS\System32\ntdsapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\newdev.dll" to "C:\WINDOWS\System32\newdev.dll" via temporary file "C:\WINDOWS\System32\SETADD.tmp".
#W190 File "C:\WINDOWS\System32\SETADD.tmp" marked to be moved to "C:\WINDOWS\System32\newdev.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\netui1.dll" to "C:\WINDOWS\System32\netui1.dll" via temporary file "C:\WINDOWS\System32\SETADE.tmp".
#W190 File "C:\WINDOWS\System32\SETADE.tmp" marked to be moved to "C:\WINDOWS\System32\netui1.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\netui0.dll" to "C:\WINDOWS\System32\netui0.dll" via temporary file "C:\WINDOWS\System32\SETAE0.tmp".
#W190 File "C:\WINDOWS\System32\SETAE0.tmp" marked to be moved to "C:\WINDOWS\System32\netui0.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\netshell.dll" to "C:\WINDOWS\System32\netshell.dll" via temporary file "C:\WINDOWS\System32\SETAE5.tmp".
#W190 File "C:\WINDOWS\System32\SETAE5.tmp" marked to be moved to "C:\WINDOWS\System32\netshell.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\netrap.dll" to "C:\WINDOWS\System32\netrap.dll" via temporary file "C:\WINDOWS\System32\SETAEA.tmp".
#W190 File "C:\WINDOWS\System32\SETAEA.tmp" marked to be moved to "C:\WINDOWS\System32\netrap.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\netman.dll" to "C:\WINDOWS\System32\netman.dll" via temporary file "C:\WINDOWS\System32\SETAEF.tmp".
#W190 File "C:\WINDOWS\System32\SETAEF.tmp" marked to be moved to "C:\WINDOWS\System32\netman.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\netlogon.dll" to "C:\WINDOWS\System32\netlogon.dll" via temporary file "C:\WINDOWS\System32\SETAF0.tmp".
#W190 File "C:\WINDOWS\System32\SETAF0.tmp" marked to be moved to "C:\WINDOWS\System32\netlogon.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\netcfgx.dll" to "C:\WINDOWS\System32\netcfgx.dll" via temporary file "C:\WINDOWS\System32\SETAF3.tmp".
#W190 File "C:\WINDOWS\System32\SETAF3.tmp" marked to be moved to "C:\WINDOWS\System32\netcfgx.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\netapi32.dll" to "C:\WINDOWS\System32\netapi32.dll" via temporary file "C:\WINDOWS\System32\SETAF6.tmp".
#W190 File "C:\WINDOWS\System32\SETAF6.tmp" marked to be moved to "C:\WINDOWS\System32\netapi32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ndptsp.tsp" to "C:\WINDOWS\System32\ndptsp.tsp" via temporary file "C:\WINDOWS\System32\SETAFB.tmp".
#W190 File "C:\WINDOWS\System32\SETAFB.tmp" marked to be moved to "C:\WINDOWS\System32\ndptsp.tsp" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\nddeapi.dll" to "C:\WINDOWS\System32\nddeapi.dll" via temporary file "C:\WINDOWS\System32\SETB03.tmp".
#W190 File "C:\WINDOWS\System32\SETB03.tmp" marked to be moved to "C:\WINDOWS\System32\nddeapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ncobjapi.dll" to "C:\WINDOWS\System32\ncobjapi.dll" via temporary file "C:\WINDOWS\System32\SETB06.tmp".
#W190 File "C:\WINDOWS\System32\SETB06.tmp" marked to be moved to "C:\WINDOWS\System32\ncobjapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mtxclu.dll" to "C:\WINDOWS\System32\mtxclu.dll" via temporary file "C:\WINDOWS\System32\SETB0D.tmp".
#W190 File "C:\WINDOWS\System32\SETB0D.tmp" marked to be moved to "C:\WINDOWS\System32\mtxclu.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mswsock.dll" to "C:\WINDOWS\System32\mswsock.dll" via temporary file "C:\WINDOWS\System32\SETB16.tmp".
#W190 File "C:\WINDOWS\System32\SETB16.tmp" marked to be moved to "C:\WINDOWS\System32\mswsock.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msvcrt.dll" to "C:\WINDOWS\System32\msvcrt.dll" via temporary file "C:\WINDOWS\System32\SETB1F.tmp".
#W190 File "C:\WINDOWS\System32\SETB1F.tmp" marked to be moved to "C:\WINDOWS\System32\msvcrt.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msvcp60.dll" to "C:\WINDOWS\System32\msvcp60.dll" via temporary file "C:\WINDOWS\System32\SETB20.tmp".
#W190 File "C:\WINDOWS\System32\SETB20.tmp" marked to be moved to "C:\WINDOWS\System32\msvcp60.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msvbvm60.dll" to "C:\WINDOWS\System32\msvbvm60.dll" via temporary file "C:\WINDOWS\System32\SETB22.tmp".
#W190 File "C:\WINDOWS\System32\SETB22.tmp" marked to be moved to "C:\WINDOWS\System32\msvbvm60.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mstlsapi.dll" to "C:\WINDOWS\System32\mstlsapi.dll" via temporary file "C:\WINDOWS\System32\SETB26.tmp".
#W190 File "C:\WINDOWS\System32\SETB26.tmp" marked to be moved to "C:\WINDOWS\System32\mstlsapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mstask.dll" to "C:\WINDOWS\System32\mstask.dll" via temporary file "C:\WINDOWS\System32\SETB2A.tmp".
#W190 File "C:\WINDOWS\System32\SETB2A.tmp" marked to be moved to "C:\WINDOWS\System32\mstask.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msprivs.dll" to "C:\WINDOWS\System32\msprivs.dll" via temporary file "C:\WINDOWS\System32\SETB3A.tmp".
#W190 File "C:\WINDOWS\System32\SETB3A.tmp" marked to be moved to "C:\WINDOWS\System32\msprivs.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mspatcha.dll" to "C:\WINDOWS\System32\mspatcha.dll" via temporary file "C:\WINDOWS\System32\SETB3E.tmp".
#W190 File "C:\WINDOWS\System32\SETB3E.tmp" marked to be moved to "C:\WINDOWS\System32\mspatcha.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msorcl32.dll" to "C:\WINDOWS\System32\msorcl32.dll" via temporary file "C:\WINDOWS\System32\SETB41.tmp".
#W190 File "C:\WINDOWS\System32\SETB41.tmp" marked to be moved to "C:\WINDOWS\System32\msorcl32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msorc32r.dll" to "C:\WINDOWS\System32\msorc32r.dll" via temporary file "C:\WINDOWS\System32\SETB42.tmp".
#W190 File "C:\WINDOWS\System32\SETB42.tmp" marked to be moved to "C:\WINDOWS\System32\msorc32r.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msimtf.dll" to "C:\WINDOWS\System32\msimtf.dll" via temporary file "C:\WINDOWS\System32\SETB52.tmp".
#W190 File "C:\WINDOWS\System32\SETB52.tmp" marked to be moved to "C:\WINDOWS\System32\msimtf.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msimg32.dll" to "C:\WINDOWS\System32\msimg32.dll" via temporary file "C:\WINDOWS\System32\SETB53.tmp".
#W190 File "C:\WINDOWS\System32\SETB53.tmp" marked to be moved to "C:\WINDOWS\System32\msimg32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msidle.dll" to "C:\WINDOWS\System32\msidle.dll" via temporary file "C:\WINDOWS\System32\SETB55.tmp".
[2007/10/15 08:07:37 2292.7]
#W190 File "C:\WINDOWS\System32\SETB55.tmp" marked to be moved to "C:\WINDOWS\System32\msidle.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mshtmled.dll" to "C:\WINDOWS\System32\mshtmled.dll" via temporary file "C:\WINDOWS\System32\SETB58.tmp".
#W190 File "C:\WINDOWS\System32\SETB58.tmp" marked to be moved to "C:\WINDOWS\System32\mshtmled.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mshtml.tlb" to "C:\WINDOWS\System32\mshtml.tlb" via temporary file "C:\WINDOWS\System32\SETB5A.tmp".
#W190 File "C:\WINDOWS\System32\SETB5A.tmp" marked to be moved to "C:\WINDOWS\System32\mshtml.tlb" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mshtml.dll" to "C:\WINDOWS\System32\mshtml.dll" via temporary file "C:\WINDOWS\System32\SETB5B.tmp".
#W190 File "C:\WINDOWS\System32\SETB5B.tmp" marked to be moved to "C:\WINDOWS\System32\mshtml.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msgina.dll" to "C:\WINDOWS\System32\msgina.dll" via temporary file "C:\WINDOWS\System32\SETB60.tmp".
#W190 File "C:\WINDOWS\System32\SETB60.tmp" marked to be moved to "C:\WINDOWS\System32\msgina.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdart.dll" to "C:\WINDOWS\System32\msdart.dll" via temporary file "C:\WINDOWS\System32\SETB6E.tmp".
#W190 File "C:\WINDOWS\System32\SETB6E.tmp" marked to be moved to "C:\WINDOWS\System32\msdart.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msctf.dll" to "C:\WINDOWS\System32\msctf.dll" via temporary file "C:\WINDOWS\System32\SETB70.tmp".
#W190 File "C:\WINDOWS\System32\SETB70.tmp" marked to be moved to "C:\WINDOWS\System32\msctf.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mscpxl32.dll" to "C:\WINDOWS\System32\mscpxl32.dll" via temporary file "C:\WINDOWS\System32\SETB71.tmp".
#W190 File "C:\WINDOWS\System32\SETB71.tmp" marked to be moved to "C:\WINDOWS\System32\mscpxl32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mscpx32r.dll" to "C:\WINDOWS\System32\mscpx32r.dll" via temporary file "C:\WINDOWS\System32\SETB72.tmp".
#W190 File "C:\WINDOWS\System32\SETB72.tmp" marked to be moved to "C:\WINDOWS\System32\mscpx32r.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mscms.dll" to "C:\WINDOWS\System32\mscms.dll" via temporary file "C:\WINDOWS\System32\SETB74.tmp".
#W190 File "C:\WINDOWS\System32\SETB74.tmp" marked to be moved to "C:\WINDOWS\System32\mscms.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msasn1.dll" to "C:\WINDOWS\System32\msasn1.dll" via temporary file "C:\WINDOWS\System32\SETB76.tmp".
#W190 File "C:\WINDOWS\System32\SETB76.tmp" marked to be moved to "C:\WINDOWS\System32\msasn1.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msacm32.dll" to "C:\WINDOWS\System32\msacm32.dll" via temporary file "C:\WINDOWS\System32\SETB7B.tmp".
#W190 File "C:\WINDOWS\System32\SETB7B.tmp" marked to be moved to "C:\WINDOWS\System32\msacm32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mprapi.dll" to "C:\WINDOWS\System32\mprapi.dll" via temporary file "C:\WINDOWS\System32\SETB7E.tmp".
#W190 File "C:\WINDOWS\System32\SETB7E.tmp" marked to be moved to "C:\WINDOWS\System32\mprapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mpr.dll" to "C:\WINDOWS\System32\mpr.dll" via temporary file "C:\WINDOWS\System32\SETB7F.tmp".
#W190 File "C:\WINDOWS\System32\SETB7F.tmp" marked to be moved to "C:\WINDOWS\System32\mpr.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\modemui.dll" to "C:\WINDOWS\System32\modemui.dll" via temporary file "C:\WINDOWS\System32\SETB85.tmp".
#W190 File "C:\WINDOWS\System32\SETB85.tmp" marked to be moved to "C:\WINDOWS\System32\modemui.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mlang.dll" to "C:\WINDOWS\System32\mlang.dll" via temporary file "C:\WINDOWS\System32\SETB91.tmp".
#W190 File "C:\WINDOWS\System32\SETB91.tmp" marked to be moved to "C:\WINDOWS\System32\mlang.dll" on next reboot.

Vince Vespertino
2007-10-15, 22:03
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\midimap.dll" to "C:\WINDOWS\System32\midimap.dll" via temporary file "C:\WINDOWS\System32\SETB94.tmp".
#W190 File "C:\WINDOWS\System32\SETB94.tmp" marked to be moved to "C:\WINDOWS\System32\midimap.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mfcsubs.dll" to "C:\WINDOWS\System32\mfcsubs.dll" via temporary file "C:\WINDOWS\System32\SETB95.tmp".
#W190 File "C:\WINDOWS\System32\SETB95.tmp" marked to be moved to "C:\WINDOWS\System32\mfcsubs.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mdminst.dll" to "C:\WINDOWS\System32\mdminst.dll" via temporary file "C:\WINDOWS\System32\SETB99.tmp".
#W190 File "C:\WINDOWS\System32\SETB99.tmp" marked to be moved to "C:\WINDOWS\System32\mdminst.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\lsass.exe" to "C:\WINDOWS\System32\lsass.exe" via temporary file "C:\WINDOWS\System32\SETBA1.tmp".
#W190 File "C:\WINDOWS\System32\SETBA1.tmp" marked to be moved to "C:\WINDOWS\System32\lsass.exe" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\linkinfo.dll" to "C:\WINDOWS\System32\linkinfo.dll" via temporary file "C:\WINDOWS\System32\SETBB4.tmp".
#W190 File "C:\WINDOWS\System32\SETBB4.tmp" marked to be moved to "C:\WINDOWS\System32\linkinfo.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\kmddsp.tsp" to "C:\WINDOWS\System32\kmddsp.tsp" via temporary file "C:\WINDOWS\System32\SETBC8.tmp".
#W190 File "C:\WINDOWS\System32\SETBC8.tmp" marked to be moved to "C:\WINDOWS\System32\kmddsp.tsp" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\kerberos.dll" to "C:\WINDOWS\System32\kerberos.dll" via temporary file "C:\WINDOWS\System32\SETBCA.tmp".
#W190 File "C:\WINDOWS\System32\SETBCA.tmp" marked to be moved to "C:\WINDOWS\System32\kerberos.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ipsecsvc.dll" to "C:\WINDOWS\System32\ipsecsvc.dll" via temporary file "C:\WINDOWS\System32\SETBDE.tmp".
#W190 File "C:\WINDOWS\System32\SETBDE.tmp" marked to be moved to "C:\WINDOWS\System32\ipsecsvc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ipnathlp.dll" to "C:\WINDOWS\System32\ipnathlp.dll" via temporary file "C:\WINDOWS\System32\SETBE5.tmp".
#W190 File "C:\WINDOWS\System32\SETBE5.tmp" marked to be moved to "C:\WINDOWS\System32\ipnathlp.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\iphlpapi.dll" to "C:\WINDOWS\System32\iphlpapi.dll" via temporary file "C:\WINDOWS\System32\SETBE6.tmp".
#W190 File "C:\WINDOWS\System32\SETBE6.tmp" marked to be moved to "C:\WINDOWS\System32\iphlpapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ipconf.tsp" to "C:\WINDOWS\System32\ipconf.tsp" via temporary file "C:\WINDOWS\System32\SETBEA.tmp".
#W190 File "C:\WINDOWS\System32\SETBEA.tmp" marked to be moved to "C:\WINDOWS\System32\ipconf.tsp" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\inetpp.dll" to "C:\WINDOWS\System32\inetpp.dll" via temporary file "C:\WINDOWS\System32\SETBF6.tmp".
#W190 File "C:\WINDOWS\System32\SETBF6.tmp" marked to be moved to "C:\WINDOWS\System32\inetpp.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\imm32.dll" to "C:\WINDOWS\System32\imm32.dll" via temporary file "C:\WINDOWS\System32\SETBFE.tmp".
#W190 File "C:\WINDOWS\System32\SETBFE.tmp" marked to be moved to "C:\WINDOWS\System32\imm32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\imgutil.dll" to "C:\WINDOWS\System32\imgutil.dll" via temporary file "C:\WINDOWS\System32\SETC02.tmp".
#W190 File "C:\WINDOWS\System32\SETC02.tmp" marked to be moved to "C:\WINDOWS\System32\imgutil.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\iepeers.dll" to "C:\WINDOWS\System32\iepeers.dll" via temporary file "C:\WINDOWS\System32\SETC0E.tmp".
#W190 File "C:\WINDOWS\System32\SETC0E.tmp" marked to be moved to "C:\WINDOWS\System32\iepeers.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\icmp.dll" to "C:\WINDOWS\System32\icmp.dll" via temporary file "C:\WINDOWS\System32\SETC16.tmp".
#W190 File "C:\WINDOWS\System32\SETC16.tmp" marked to be moved to "C:\WINDOWS\System32\icmp.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\icaapi.dll" to "C:\WINDOWS\System32\icaapi.dll" via temporary file "C:\WINDOWS\System32\SETC19.tmp".
#W190 File "C:\WINDOWS\System32\SETC19.tmp" marked to be moved to "C:\WINDOWS\System32\icaapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\hnetcfg.dll" to "C:\WINDOWS\System32\hnetcfg.dll" via temporary file "C:\WINDOWS\System32\SETC1E.tmp".
#W190 File "C:\WINDOWS\System32\SETC1E.tmp" marked to be moved to "C:\WINDOWS\System32\hnetcfg.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\hidserv.dll" to "C:\WINDOWS\System32\hidserv.dll" via temporary file "C:\WINDOWS\System32\SETC1F.tmp".
#W190 File "C:\WINDOWS\System32\SETC1F.tmp" marked to be moved to "C:\WINDOWS\System32\hidserv.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\hidphone.tsp" to "C:\WINDOWS\System32\hidphone.tsp" via temporary file "C:\WINDOWS\System32\SETC20.tmp".
#W190 File "C:\WINDOWS\System32\SETC20.tmp" marked to be moved to "C:\WINDOWS\System32\hidphone.tsp" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\hid.dll" to "C:\WINDOWS\System32\hid.dll" via temporary file "C:\WINDOWS\System32\SETC21.tmp".
#W190 File "C:\WINDOWS\System32\SETC21.tmp" marked to be moved to "C:\WINDOWS\System32\hid.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\hhctrl.ocx" to "C:\WINDOWS\System32\hhctrl.ocx" via temporary file "C:\WINDOWS\System32\SETC23.tmp".
#W190 File "C:\WINDOWS\System32\SETC23.tmp" marked to be moved to "C:\WINDOWS\System32\hhctrl.ocx" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\h323.tsp" to "C:\WINDOWS\System32\h323.tsp" via temporary file "C:\WINDOWS\System32\SETC26.tmp".
#W190 File "C:\WINDOWS\System32\SETC26.tmp" marked to be moved to "C:\WINDOWS\System32\h323.tsp" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\gdi32.dll" to "C:\WINDOWS\System32\gdi32.dll" via temporary file "C:\WINDOWS\System32\SETC2A.tmp".
#W190 File "C:\WINDOWS\System32\SETC2A.tmp" marked to be moved to "C:\WINDOWS\System32\gdi32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\faultrep.dll" to "C:\WINDOWS\System32\faultrep.dll" via temporary file "C:\WINDOWS\System32\SETC32.tmp".
#W190 File "C:\WINDOWS\System32\SETC32.tmp" marked to be moved to "C:\WINDOWS\System32\faultrep.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\eventlog.dll" to "C:\WINDOWS\System32\eventlog.dll" via temporary file "C:\WINDOWS\System32\SETC35.tmp".
#W190 File "C:\WINDOWS\System32\SETC35.tmp" marked to be moved to "C:\WINDOWS\System32\eventlog.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\esent.dll" to "C:\WINDOWS\System32\esent.dll" via temporary file "C:\WINDOWS\System32\SETC37.tmp".
#W190 File "C:\WINDOWS\System32\SETC37.tmp" marked to be moved to "C:\WINDOWS\System32\esent.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\es.dll" to "C:\WINDOWS\System32\es.dll" via temporary file "C:\WINDOWS\System32\SETC38.tmp".
#W190 File "C:\WINDOWS\System32\SETC38.tmp" marked to be moved to "C:\WINDOWS\System32\es.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ersvc.dll" to "C:\WINDOWS\System32\ersvc.dll" via temporary file "C:\WINDOWS\System32\SETC39.tmp".
#W190 File "C:\WINDOWS\System32\SETC39.tmp" marked to be moved to "C:\WINDOWS\System32\ersvc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\dxtrans.dll" to "C:\WINDOWS\System32\dxtrans.dll" via temporary file "C:\WINDOWS\System32\SETC3B.tmp".
#W190 File "C:\WINDOWS\System32\SETC3B.tmp" marked to be moved to "C:\WINDOWS\System32\dxtrans.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\dxtmsft.dll" to "C:\WINDOWS\System32\dxtmsft.dll" via temporary file "C:\WINDOWS\System32\SETC3C.tmp".
#W190 File "C:\WINDOWS\System32\SETC3C.tmp" marked to be moved to "C:\WINDOWS\System32\dxtmsft.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\dssenh.dll" to "C:\WINDOWS\System32\dssenh.dll" via temporary file "C:\WINDOWS\System32\SETC47.tmp".
#W190 File "C:\WINDOWS\System32\SETC47.tmp" marked to be moved to "C:\WINDOWS\System32\dssenh.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\drprov.dll" to "C:\WINDOWS\System32\drprov.dll" via temporary file "C:\WINDOWS\System32\SETC52.tmp".
#W190 File "C:\WINDOWS\System32\SETC52.tmp" marked to be moved to "C:\WINDOWS\System32\drprov.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\dnsrslvr.dll" to "C:\WINDOWS\System32\dnsrslvr.dll" via temporary file "C:\WINDOWS\System32\SETC66.tmp".
#W190 File "C:\WINDOWS\System32\SETC66.tmp" marked to be moved to "C:\WINDOWS\System32\dnsrslvr.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\dnsapi.dll" to "C:\WINDOWS\System32\dnsapi.dll" via temporary file "C:\WINDOWS\System32\SETC67.tmp".
#W190 File "C:\WINDOWS\System32\SETC67.tmp" marked to be moved to "C:\WINDOWS\System32\dnsapi.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ddrawex.dll" to "C:\WINDOWS\System32\ddrawex.dll" via temporary file "C:\WINDOWS\System32\SETC84.tmp".
#W190 File "C:\WINDOWS\System32\SETC84.tmp" marked to be moved to "C:\WINDOWS\System32\ddrawex.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ddraw.dll" to "C:\WINDOWS\System32\ddraw.dll" via temporary file "C:\WINDOWS\System32\SETC85.tmp".
#W190 File "C:\WINDOWS\System32\SETC85.tmp" marked to be moved to "C:\WINDOWS\System32\ddraw.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\dciman32.dll" to "C:\WINDOWS\System32\dciman32.dll" via temporary file "C:\WINDOWS\System32\SETC87.tmp".
#W190 File "C:\WINDOWS\System32\SETC87.tmp" marked to be moved to "C:\WINDOWS\System32\dciman32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\dbghelp.dll" to "C:\WINDOWS\System32\dbghelp.dll" via temporary file "C:\WINDOWS\System32\SETC8C.tmp".
#W190 File "C:\WINDOWS\System32\SETC8C.tmp" marked to be moved to "C:\WINDOWS\System32\dbghelp.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\davclnt.dll" to "C:\WINDOWS\System32\davclnt.dll" via temporary file "C:\WINDOWS\System32\SETC8F.tmp".
#W190 File "C:\WINDOWS\System32\SETC8F.tmp" marked to be moved to "C:\WINDOWS\System32\davclnt.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\csrss.exe" to "C:\WINDOWS\System32\csrss.exe" via temporary file "C:\WINDOWS\System32\SETC95.tmp".
#W190 File "C:\WINDOWS\System32\SETC95.tmp" marked to be moved to "C:\WINDOWS\System32\csrss.exe" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\cscui.dll" to "C:\WINDOWS\System32\cscui.dll" via temporary file "C:\WINDOWS\System32\SETC96.tmp".
#W190 File "C:\WINDOWS\System32\SETC96.tmp" marked to be moved to "C:\WINDOWS\System32\cscui.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\cscdll.dll" to "C:\WINDOWS\System32\cscdll.dll" via temporary file "C:\WINDOWS\System32\SETC98.tmp".
#W190 File "C:\WINDOWS\System32\SETC98.tmp" marked to be moved to "C:\WINDOWS\System32\cscdll.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\cryptui.dll" to "C:\WINDOWS\System32\cryptui.dll" via temporary file "C:\WINDOWS\System32\SETC99.tmp".
#W190 File "C:\WINDOWS\System32\SETC99.tmp" marked to be moved to "C:\WINDOWS\System32\cryptui.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\cryptsvc.dll" to "C:\WINDOWS\System32\cryptsvc.dll" via temporary file "C:\WINDOWS\System32\SETC9A.tmp".
#W190 File "C:\WINDOWS\System32\SETC9A.tmp" marked to be moved to "C:\WINDOWS\System32\cryptsvc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\cryptnet.dll" to "C:\WINDOWS\System32\cryptnet.dll" via temporary file "C:\WINDOWS\System32\SETC9B.tmp".
#W190 File "C:\WINDOWS\System32\SETC9B.tmp" marked to be moved to "C:\WINDOWS\System32\cryptnet.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\cryptdll.dll" to "C:\WINDOWS\System32\cryptdll.dll" via temporary file "C:\WINDOWS\System32\SETC9D.tmp".
#W190 File "C:\WINDOWS\System32\SETC9D.tmp" marked to be moved to "C:\WINDOWS\System32\cryptdll.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\crypt32.dll" to "C:\WINDOWS\System32\crypt32.dll" via temporary file "C:\WINDOWS\System32\SETC9F.tmp".
#W190 File "C:\WINDOWS\System32\SETC9F.tmp" marked to be moved to "C:\WINDOWS\System32\crypt32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\credui.dll" to "C:\WINDOWS\System32\credui.dll" via temporary file "C:\WINDOWS\System32\SETCA0.tmp".
#W190 File "C:\WINDOWS\System32\SETCA0.tmp" marked to be moved to "C:\WINDOWS\System32\credui.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\conime.exe" to "C:\WINDOWS\System32\conime.exe" via temporary file "C:\WINDOWS\System32\SETCA2.tmp".
#W190 File "C:\WINDOWS\System32\SETCA2.tmp" marked to be moved to "C:\WINDOWS\System32\conime.exe" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\comsvcs.dll" to "C:\WINDOWS\System32\comsvcs.dll" via temporary file "C:\WINDOWS\System32\SETCA4.tmp".
#W190 File "C:\WINDOWS\System32\SETCA4.tmp" marked to be moved to "C:\WINDOWS\System32\comsvcs.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\comres.dll" to "C:\WINDOWS\System32\comres.dll" via temporary file "C:\WINDOWS\System32\SETCA5.tmp".
#W190 File "C:\WINDOWS\System32\SETCA5.tmp" marked to be moved to "C:\WINDOWS\System32\comres.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\colbact.dll" to "C:\WINDOWS\System32\colbact.dll" via temporary file "C:\WINDOWS\System32\SETCA8.tmp".
#W190 File "C:\WINDOWS\System32\SETCA8.tmp" marked to be moved to "C:\WINDOWS\System32\colbact.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\cnbjmon.dll" to "C:\WINDOWS\System32\cnbjmon.dll" via temporary file "C:\WINDOWS\System32\SETCA9.tmp".
#W190 File "C:\WINDOWS\System32\SETCA9.tmp" marked to be moved to "C:\WINDOWS\System32\cnbjmon.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\clusapi.dll" to "C:\WINDOWS\System32\clusapi.dll" via temporary file "C:\WINDOWS\System32\SETCB1.tmp".
#W190 File "C:\WINDOWS\System32\SETCB1.tmp" marked to be moved to "C:\WINDOWS\System32\clusapi.dll" on next reboot.

Vince Vespertino
2007-10-15, 22:05
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\clbcatq.dll" to "C:\WINDOWS\System32\clbcatq.dll" via temporary file "C:\WINDOWS\System32\SETCB8.tmp".
#W190 File "C:\WINDOWS\System32\SETCB8.tmp" marked to be moved to "C:\WINDOWS\System32\clbcatq.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\cfgmgr32.dll" to "C:\WINDOWS\System32\cfgmgr32.dll" via temporary file "C:\WINDOWS\System32\SETCBD.tmp".
#W190 File "C:\WINDOWS\System32\SETCBD.tmp" marked to be moved to "C:\WINDOWS\System32\cfgmgr32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\certcli.dll" to "C:\WINDOWS\System32\certcli.dll" via temporary file "C:\WINDOWS\System32\SETCC1.tmp".
#W190 File "C:\WINDOWS\System32\SETCC1.tmp" marked to be moved to "C:\WINDOWS\System32\certcli.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\catsrvut.dll" to "C:\WINDOWS\System32\catsrvut.dll" via temporary file "C:\WINDOWS\System32\SETCC4.tmp".
#W190 File "C:\WINDOWS\System32\SETCC4.tmp" marked to be moved to "C:\WINDOWS\System32\catsrvut.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\catsrv.dll" to "C:\WINDOWS\System32\catsrv.dll" via temporary file "C:\WINDOWS\System32\SETCC6.tmp".
#W190 File "C:\WINDOWS\System32\SETCC6.tmp" marked to be moved to "C:\WINDOWS\System32\catsrv.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\cabinet.dll" to "C:\WINDOWS\System32\cabinet.dll" via temporary file "C:\WINDOWS\System32\SETCC9.tmp".
#W190 File "C:\WINDOWS\System32\SETCC9.tmp" marked to be moved to "C:\WINDOWS\System32\cabinet.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\browseui.dll" to "C:\WINDOWS\System32\browseui.dll" via temporary file "C:\WINDOWS\System32\SETCCB.tmp".
#W190 File "C:\WINDOWS\System32\SETCCB.tmp" marked to be moved to "C:\WINDOWS\System32\browseui.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\browser.dll" to "C:\WINDOWS\System32\browser.dll" via temporary file "C:\WINDOWS\System32\SETCCC.tmp".
#W190 File "C:\WINDOWS\System32\SETCCC.tmp" marked to be moved to "C:\WINDOWS\System32\browser.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\browselc.dll" to "C:\WINDOWS\System32\browselc.dll" via temporary file "C:\WINDOWS\System32\SETCCD.tmp".
#W190 File "C:\WINDOWS\System32\SETCCD.tmp" marked to be moved to "C:\WINDOWS\System32\browselc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\batmeter.dll" to "C:\WINDOWS\System32\batmeter.dll" via temporary file "C:\WINDOWS\System32\SETCD2.tmp".
#W190 File "C:\WINDOWS\System32\SETCD2.tmp" marked to be moved to "C:\WINDOWS\System32\batmeter.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\basesrv.dll" to "C:\WINDOWS\System32\basesrv.dll" via temporary file "C:\WINDOWS\System32\SETCD3.tmp".
#W190 File "C:\WINDOWS\System32\SETCD3.tmp" marked to be moved to "C:\WINDOWS\System32\basesrv.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\authz.dll" to "C:\WINDOWS\System32\authz.dll" via temporary file "C:\WINDOWS\System32\SETCD7.tmp".
#W190 File "C:\WINDOWS\System32\SETCD7.tmp" marked to be moved to "C:\WINDOWS\System32\authz.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\audiosrv.dll" to "C:\WINDOWS\System32\audiosrv.dll" via temporary file "C:\WINDOWS\System32\SETCD8.tmp".
#W190 File "C:\WINDOWS\System32\SETCD8.tmp" marked to be moved to "C:\WINDOWS\System32\audiosrv.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\atl.dll" to "C:\WINDOWS\System32\atl.dll" via temporary file "C:\WINDOWS\System32\SETCDC.tmp".
#W190 File "C:\WINDOWS\System32\SETCDC.tmp" marked to be moved to "C:\WINDOWS\System32\atl.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\asycfilt.dll" to "C:\WINDOWS\System32\asycfilt.dll" via temporary file "C:\WINDOWS\System32\SETCDE.tmp".
#W190 File "C:\WINDOWS\System32\SETCDE.tmp" marked to be moved to "C:\WINDOWS\System32\asycfilt.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\apphelp.dll" to "C:\WINDOWS\System32\apphelp.dll" via temporary file "C:\WINDOWS\System32\SETCE2.tmp".
#W190 File "C:\WINDOWS\System32\SETCE2.tmp" marked to be moved to "C:\WINDOWS\System32\apphelp.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\alg.exe" to "C:\WINDOWS\System32\alg.exe" via temporary file "C:\WINDOWS\System32\SETCE5.tmp".
#W190 File "C:\WINDOWS\System32\SETCE5.tmp" marked to be moved to "C:\WINDOWS\System32\alg.exe" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\advpack.dll" to "C:\WINDOWS\System32\advpack.dll" via temporary file "C:\WINDOWS\System32\SETCE7.tmp".
#W190 File "C:\WINDOWS\System32\SETCE7.tmp" marked to be moved to "C:\WINDOWS\System32\advpack.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\adsldpc.dll" to "C:\WINDOWS\System32\adsldpc.dll" via temporary file "C:\WINDOWS\System32\SETCEA.tmp".
#W190 File "C:\WINDOWS\System32\SETCEA.tmp" marked to be moved to "C:\WINDOWS\System32\adsldpc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\actxprxy.dll" to "C:\WINDOWS\System32\actxprxy.dll" via temporary file "C:\WINDOWS\System32\SETCED.tmp".
#W190 File "C:\WINDOWS\System32\SETCED.tmp" marked to be moved to "C:\WINDOWS\System32\actxprxy.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\activeds.dll" to "C:\WINDOWS\System32\activeds.dll" via temporary file "C:\WINDOWS\System32\SETCEF.tmp".
#W190 File "C:\WINDOWS\System32\SETCEF.tmp" marked to be moved to "C:\WINDOWS\System32\activeds.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\explorer.exe" to "C:\WINDOWS\explorer.exe" via temporary file "C:\WINDOWS\SETD22.tmp".
#W190 File "C:\WINDOWS\SETD22.tmp" marked to be moved to "C:\WINDOWS\explorer.exe" on next reboot.
#E197 Writing "C:\WINDOWS\INF\wmp.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wdma_via.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wdma_int.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wdma_ali.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E099 Writing of "C:\WINDOWS\INF\unregmp2.exe" to "C:\WINDOWS\INF" can cause problems.
#E197 Writing "C:\WINDOWS\INF\skins.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\setupqry.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\qmgr.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netwv48.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netwlan2.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netwlan.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netrtsnt.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netnm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netklsi.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mymusic.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\msnetmtg.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mplayer2.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\moviemk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmvv.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmusrk1.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmsuprv.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmrpci.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmlt3.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmirmdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmgen.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmetech.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\i81xnt5.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\g400.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\fxsocm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\fp40ext.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\timesbd.ttf" to "C:\WINDOWS\fonts\timesbd.ttf" via temporary file "C:\WINDOWS\fonts\SETD41.tmp".

Vince Vespertino
2007-10-15, 22:07
#W190 File "C:\WINDOWS\fonts\SETD41.tmp" marked to be moved to "C:\WINDOWS\fonts\timesbd.ttf" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\times.ttf" to "C:\WINDOWS\fonts\times.ttf" via temporary file "C:\WINDOWS\fonts\SETD42.tmp".
#W190 File "C:\WINDOWS\fonts\SETD42.tmp" marked to be moved to "C:\WINDOWS\fonts\times.ttf" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\tahomabd.ttf" to "C:\WINDOWS\fonts\tahomabd.ttf" via temporary file "C:\WINDOWS\fonts\SETD43.tmp".
#W190 File "C:\WINDOWS\fonts\SETD43.tmp" marked to be moved to "C:\WINDOWS\fonts\tahomabd.ttf" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\tahoma.ttf" to "C:\WINDOWS\fonts\tahoma.ttf" via temporary file "C:\WINDOWS\fonts\SETD44.tmp".
#W190 File "C:\WINDOWS\fonts\SETD44.tmp" marked to be moved to "C:\WINDOWS\fonts\tahoma.ttf" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\micross.ttf" to "C:\WINDOWS\fonts\micross.ttf" via temporary file "C:\WINDOWS\fonts\SETD45.tmp".
#W190 File "C:\WINDOWS\fonts\SETD45.tmp" marked to be moved to "C:\WINDOWS\fonts\micross.ttf" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\comic.ttf" to "C:\WINDOWS\fonts\comic.ttf" via temporary file "C:\WINDOWS\fonts\SETD46.tmp".
#W190 File "C:\WINDOWS\fonts\SETD46.tmp" marked to be moved to "C:\WINDOWS\fonts\comic.ttf" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\arialbd.ttf" to "C:\WINDOWS\fonts\arialbd.ttf" via temporary file "C:\WINDOWS\fonts\SETD47.tmp".
#W190 File "C:\WINDOWS\fonts\SETD47.tmp" marked to be moved to "C:\WINDOWS\fonts\arialbd.ttf" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\arial.ttf" to "C:\WINDOWS\fonts\arial.ttf" via temporary file "C:\WINDOWS\fonts\SETD48.tmp".
#W190 File "C:\WINDOWS\fonts\SETD48.tmp" marked to be moved to "C:\WINDOWS\fonts\arial.ttf" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sqlxmlx.rll" to "C:\Program Files\Common Files\SYSTEM\ole db\sqlxmlx.rll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD49.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD49.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\sqlxmlx.rll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sqlxmlx.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\sqlxmlx.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD4A.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD4A.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\sqlxmlx.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sqloledb.rll" to "C:\Program Files\Common Files\SYSTEM\ole db\sqloledb.rll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD4B.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD4B.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\sqloledb.rll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sqloledb.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\sqloledb.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD4C.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD4C.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\sqloledb.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\oledb32r.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\oledb32r.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD4D.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD4D.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\oledb32r.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\oledb32.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\oledb32.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD4E.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD4E.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\oledb32.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msxactps.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msxactps.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD4F.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD4F.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msxactps.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdaurl.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdaurl.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD50.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD50.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdaurl.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdatt.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdatt.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD51.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD51.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdatt.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdatl3.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdatl3.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD52.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD52.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdatl3.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdasqlr.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdasqlr.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD53.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD53.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdasqlr.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdasql.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdasql.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD54.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD54.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdasql.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdasc.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdasc.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD55.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD55.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdasc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdaps.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdaps.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD56.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD56.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdaps.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdaosp.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdaosp.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD57.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD57.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdaosp.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdaorar.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdaorar.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD58.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD58.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdaorar.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdaora.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdaora.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD59.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD59.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdaora.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdaipp.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdaipp.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD5A.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD5A.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdaipp.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdaer.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdaer.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD5B.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD5B.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdaer.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdaenum.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdaenum.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD5C.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD5C.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdaenum.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdadc.dll" to "C:\Program Files\Common Files\SYSTEM\ole db\msdadc.dll" via temporary file "C:\Program Files\Common Files\SYSTEM\ole db\SETD5D.tmp".
#W190 File "C:\Program Files\Common Files\SYSTEM\ole db\SETD5D.tmp" marked to be moved to "C:\Program Files\Common Files\SYSTEM\ole db\msdadc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wmiutils.dll" to "C:\WINDOWS\System32\WBEM\wmiutils.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD68.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD68.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\wmiutils.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wmisvc.dll" to "C:\WINDOWS\System32\WBEM\wmisvc.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD69.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD69.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\wmisvc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wmiprvse.exe" to "C:\WINDOWS\System32\WBEM\wmiprvse.exe" via temporary file "C:\WINDOWS\System32\WBEM\SETD6B.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD6B.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\wmiprvse.exe" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wmiprvsd.dll" to "C:\WINDOWS\System32\WBEM\wmiprvsd.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD6C.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD6C.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\wmiprvsd.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wmiprov.dll" to "C:\WINDOWS\System32\WBEM\wmiprov.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD6D.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD6D.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\wmiprov.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wbemsvc.dll" to "C:\WINDOWS\System32\WBEM\wbemsvc.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD7A.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD7A.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\wbemsvc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wbemprox.dll" to "C:\WINDOWS\System32\WBEM\wbemprox.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD7B.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD7B.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\wbemprox.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wbemess.dll" to "C:\WINDOWS\System32\WBEM\wbemess.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD7D.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD7D.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\wbemess.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wbemcore.dll" to "C:\WINDOWS\System32\WBEM\wbemcore.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD7F.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD7F.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\wbemcore.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wbemcomn.dll" to "C:\WINDOWS\System32\WBEM\wbemcomn.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD81.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD81.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\wbemcomn.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\repdrvfs.dll" to "C:\WINDOWS\System32\WBEM\repdrvfs.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD88.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD88.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\repdrvfs.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\ncprov.dll" to "C:\WINDOWS\System32\WBEM\ncprov.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD8B.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD8B.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\ncprov.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mofd.dll" to "C:\WINDOWS\System32\WBEM\mofd.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD8C.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD8C.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\mofd.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\mofcomp.exe" to "C:\WINDOWS\System32\WBEM\mofcomp.exe" via temporary file "C:\WINDOWS\System32\WBEM\SETD8D.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD8D.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\mofcomp.exe" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\framedyn.dll" to "C:\WINDOWS\System32\WBEM\framedyn.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD8F.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD8F.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\framedyn.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\fastprox.dll" to "C:\WINDOWS\System32\WBEM\fastprox.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD90.tmp".
#W190 File "C:\WINDOWS\System32\WBEM\SETD90.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\fastprox.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\esscli.dll" to "C:\WINDOWS\System32\WBEM\esscli.dll" via temporary file "C:\WINDOWS\System32\WBEM\SETD92.tmp".

Vince Vespertino
2007-10-15, 22:08
#W190 File "C:\WINDOWS\System32\WBEM\SETD92.tmp" marked to be moved to "C:\WINDOWS\System32\WBEM\esscli.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdfmap.dll" to "C:\Program Files\Common Files\System\MSADC\msdfmap.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDD5.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDD5.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msdfmap.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdaremr.dll" to "C:\Program Files\Common Files\System\MSADC\msdaremr.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDD6.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDD6.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msdaremr.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdarem.dll" to "C:\Program Files\Common Files\System\MSADC\msdarem.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDD7.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDD7.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msdarem.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdaprst.dll" to "C:\Program Files\Common Files\System\MSADC\msdaprst.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDD8.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDD8.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msdaprst.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msdaprsr.dll" to "C:\Program Files\Common Files\System\MSADC\msdaprsr.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDD9.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDD9.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msdaprsr.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msaddsr.dll" to "C:\Program Files\Common Files\System\MSADC\msaddsr.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDDA.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDDA.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msaddsr.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msadds.dll" to "C:\Program Files\Common Files\System\MSADC\msadds.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDDB.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDDB.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msadds.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msadcs.dll" to "C:\Program Files\Common Files\System\MSADC\msadcs.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDDC.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDDC.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msadcs.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msadcor.dll" to "C:\Program Files\Common Files\System\MSADC\msadcor.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDDD.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDDD.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msadcor.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msadco.dll" to "C:\Program Files\Common Files\System\MSADC\msadco.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDDE.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDDE.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msadco.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msadcfr.dll" to "C:\Program Files\Common Files\System\MSADC\msadcfr.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDDF.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDDF.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msadcfr.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msadcf.dll" to "C:\Program Files\Common Files\System\MSADC\msadcf.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDE0.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDE0.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msadcf.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msadcer.dll" to "C:\Program Files\Common Files\System\MSADC\msadcer.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDE1.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDE1.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msadcer.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msadce.dll" to "C:\Program Files\Common Files\System\MSADC\msadce.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDE2.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDE2.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msadce.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\adcvbs.inc" to "C:\Program Files\Common Files\System\MSADC\adcvbs.inc" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDE3.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDE3.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\adcvbs.inc" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\adcjavas.inc" to "C:\Program Files\Common Files\System\MSADC\adcjavas.inc" via temporary file "C:\Program Files\Common Files\System\MSADC\SETDE4.tmp".
#W190 File "C:\Program Files\Common Files\System\MSADC\SETDE4.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\adcjavas.inc" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msjro.dll" to "C:\Program Files\Common Files\System\ADO\msjro.dll" via temporary file "C:\Program Files\Common Files\System\ADO\SETDE5.tmp".
#W190 File "C:\Program Files\Common Files\System\ADO\SETDE5.tmp" marked to be moved to "C:\Program Files\Common Files\System\ADO\msjro.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msadrh15.dll" to "C:\Program Files\Common Files\System\ADO\msadrh15.dll" via temporary file "C:\Program Files\Common Files\System\ADO\SETDE6.tmp".
#W190 File "C:\Program Files\Common Files\System\ADO\SETDE6.tmp" marked to be moved to "C:\Program Files\Common Files\System\ADO\msadrh15.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msadox.dll" to "C:\Program Files\Common Files\System\ADO\msadox.dll" via temporary file "C:\Program Files\Common Files\System\ADO\SETDE7.tmp".
#W190 File "C:\Program Files\Common Files\System\ADO\SETDE7.tmp" marked to be moved to "C:\Program Files\Common Files\System\ADO\msadox.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msador15.dll" to "C:\Program Files\Common Files\System\ADO\msador15.dll" via temporary file "C:\Program Files\Common Files\System\ADO\SETDE8.tmp".
#W190 File "C:\Program Files\Common Files\System\ADO\SETDE8.tmp" marked to be moved to "C:\Program Files\Common Files\System\ADO\msador15.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msadomd.dll" to "C:\Program Files\Common Files\System\ADO\msadomd.dll" via temporary file "C:\Program Files\Common Files\System\ADO\SETDE9.tmp".
#W190 File "C:\Program Files\Common Files\System\ADO\SETDE9.tmp" marked to be moved to "C:\Program Files\Common Files\System\ADO\msadomd.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msado26.tlb" to "C:\Program Files\Common Files\System\ADO\msado26.tlb" via temporary file "C:\Program Files\Common Files\System\ADO\SETDEA.tmp".
#W190 File "C:\Program Files\Common Files\System\ADO\SETDEA.tmp" marked to be moved to "C:\Program Files\Common Files\System\ADO\msado26.tlb" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msado25.tlb" to "C:\Program Files\Common Files\System\ADO\msado25.tlb" via temporary file "C:\Program Files\Common Files\System\ADO\SETDEB.tmp".
#W190 File "C:\Program Files\Common Files\System\ADO\SETDEB.tmp" marked to be moved to "C:\Program Files\Common Files\System\ADO\msado25.tlb" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msado21.tlb" to "C:\Program Files\Common Files\System\ADO\msado21.tlb" via temporary file "C:\Program Files\Common Files\System\ADO\SETDEC.tmp".
#W190 File "C:\Program Files\Common Files\System\ADO\SETDEC.tmp" marked to be moved to "C:\Program Files\Common Files\System\ADO\msado21.tlb" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msado20.tlb" to "C:\Program Files\Common Files\System\ADO\msado20.tlb" via temporary file "C:\Program Files\Common Files\System\ADO\SETDED.tmp".
#W190 File "C:\Program Files\Common Files\System\ADO\SETDED.tmp" marked to be moved to "C:\Program Files\Common Files\System\ADO\msado20.tlb" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msado15.dll" to "C:\Program Files\Common Files\System\ADO\msado15.dll" via temporary file "C:\Program Files\Common Files\System\ADO\SETDEE.tmp".
#W190 File "C:\Program Files\Common Files\System\ADO\SETDEE.tmp" marked to be moved to "C:\Program Files\Common Files\System\ADO\msado15.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msader15.dll" to "C:\Program Files\Common Files\System\ADO\msader15.dll" via temporary file "C:\Program Files\Common Files\System\ADO\SETDEF.tmp".
#W190 File "C:\Program Files\Common Files\System\ADO\SETDEF.tmp" marked to be moved to "C:\Program Files\Common Files\System\ADO\msader15.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\adovbs.inc" to "C:\Program Files\Common Files\System\ADO\adovbs.inc" via temporary file "C:\Program Files\Common Files\System\ADO\SETDF0.tmp".
#W190 File "C:\Program Files\Common Files\System\ADO\SETDF0.tmp" marked to be moved to "C:\Program Files\Common Files\System\ADO\adovbs.inc" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\adojavas.inc" to "C:\Program Files\Common Files\System\ADO\adojavas.inc" via temporary file "C:\Program Files\Common Files\System\ADO\SETDF1.tmp".
#W190 File "C:\Program Files\Common Files\System\ADO\SETDF1.tmp" marked to be moved to "C:\Program Files\Common Files\System\ADO\adojavas.inc" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sysmain.sdb" to "C:\WINDOWS\AppPatch\sysmain.sdb" via temporary file "C:\WINDOWS\AppPatch\SETE0E.tmp".
#W190 File "C:\WINDOWS\AppPatch\SETE0E.tmp" marked to be moved to "C:\WINDOWS\AppPatch\sysmain.sdb" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\msimain.sdb" to "C:\WINDOWS\AppPatch\msimain.sdb" via temporary file "C:\WINDOWS\AppPatch\SETE0F.tmp".
#W190 File "C:\WINDOWS\AppPatch\SETE0F.tmp" marked to be moved to "C:\WINDOWS\AppPatch\msimain.sdb" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\apphelp.sdb" to "C:\WINDOWS\AppPatch\apphelp.sdb" via temporary file "C:\WINDOWS\AppPatch\SETE10.tmp".
#W190 File "C:\WINDOWS\AppPatch\SETE10.tmp" marked to be moved to "C:\WINDOWS\AppPatch\apphelp.sdb" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\acxtrnal.dll" to "C:\WINDOWS\AppPatch\acxtrnal.dll" via temporary file "C:\WINDOWS\AppPatch\SETE11.tmp".
#W190 File "C:\WINDOWS\AppPatch\SETE11.tmp" marked to be moved to "C:\WINDOWS\AppPatch\acxtrnal.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\acspecfc.dll" to "C:\WINDOWS\AppPatch\acspecfc.dll" via temporary file "C:\WINDOWS\AppPatch\SETE12.tmp".
#W190 File "C:\WINDOWS\AppPatch\SETE12.tmp" marked to be moved to "C:\WINDOWS\AppPatch\acspecfc.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\aclua.dll" to "C:\WINDOWS\AppPatch\aclua.dll" via temporary file "C:\WINDOWS\AppPatch\SETE13.tmp".
#W190 File "C:\WINDOWS\AppPatch\SETE13.tmp" marked to be moved to "C:\WINDOWS\AppPatch\aclua.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\aclayers.dll" to "C:\WINDOWS\AppPatch\aclayers.dll" via temporary file "C:\WINDOWS\AppPatch\SETE14.tmp".
#W190 File "C:\WINDOWS\AppPatch\SETE14.tmp" marked to be moved to "C:\WINDOWS\AppPatch\aclayers.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\acgenral.dll" to "C:\WINDOWS\AppPatch\acgenral.dll" via temporary file "C:\WINDOWS\AppPatch\SETE15.tmp".
#W190 File "C:\WINDOWS\AppPatch\SETE15.tmp" marked to be moved to "C:\WINDOWS\AppPatch\acgenral.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\iexplore.exe" to "C:\Program Files\internet explorer\iexplore.exe" via temporary file "C:\Program Files\internet explorer\SETE61.tmp".
#W190 File "C:\Program Files\internet explorer\SETE61.tmp" marked to be moved to "C:\Program Files\internet explorer\iexplore.exe" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\pchsvc.dll" to "C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll" via temporary file "C:\WINDOWS\pchealth\helpctr\binaries\SETE64.tmp".
#W190 File "C:\WINDOWS\pchealth\helpctr\binaries\SETE64.tmp" marked to be moved to "C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll" on next reboot.
#E197 Writing "C:\WINDOWS\INF\wstcodec.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wordpad.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\usbport.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\tsoc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
[2007/10/15 08:07:37 2292.7]
#E197 Writing "C:\WINDOWS\INF\tape.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\syssetup.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\sysoc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\swflash.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\streamip.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\smartcrd.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\slip.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\shl_img.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\shell.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\secrecs.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\scsi.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\sceregvl.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\pnpscsi.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\pchealth.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.

Vince Vespertino
2007-10-15, 22:08
#E197 Writing "C:\WINDOWS\INF\oobe.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ntprint.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netwzc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netupnph.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nettcpip.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netrass.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netoc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netmscli.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netip6.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ndisip.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nabtsfec.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\multimed.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mstape.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\msoe50.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mshdc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mpe.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdac.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mchgr.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\machine.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\layout.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ksfilter.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\kscaptur.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ks.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\keyboard.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\intl.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\input.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ims.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\iis.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ieaccess.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ie.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\hidserv.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\drvindex.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\dwup.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\disk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\devxprop.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\defltwk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\cpu.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\cdrom.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ccdecode.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\biosinfo.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\bda.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\battery.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\au.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\acpi.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\accessor.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sp2.cab" to "c:\windows\ServicePackFiles\i386\sp2.cab" via temporary file "c:\windows\ServicePackFiles\i386\SET135D.tmp".
#E361 An unsigned or incorrectly signed file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sp2.cab" will be installed (Policy=Ignore). Error 0x800b0100: No signature was present in the subject.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\wuauserv.dll" to "C:\WINDOWS\System32\wuauserv.dll" via temporary file "C:\WINDOWS\System32\SET16CA.tmp".
#W190 File "C:\WINDOWS\System32\SET16CA.tmp" marked to be moved to "C:\WINDOWS\System32\wuauserv.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\winhttp.dll" to "C:\WINDOWS\System32\winhttp.dll" via temporary file "C:\WINDOWS\System32\SET16D8.tmp".
#W190 File "C:\WINDOWS\System32\SET16D8.tmp" marked to be moved to "C:\WINDOWS\System32\winhttp.dll" on next reboot.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\qmgr.dll" to "C:\WINDOWS\System32\qmgr.dll" via temporary file "C:\WINDOWS\System32\SET16EA.tmp".
#W190 File "C:\WINDOWS\System32\SET16EA.tmp" marked to be moved to "C:\WINDOWS\System32\qmgr.dll" on next reboot.
#E099 Writing of "C:\WINDOWS\INF\wuau.adm" to "C:\WINDOWS\INF" can cause problems.
#E197 Writing "C:\WINDOWS\INF\wtv5.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wtv4.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wtv3.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wtv2.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wtv1.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wtv0.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wmpocm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wmfsdk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wmdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wmaccess.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp8.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp7.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp6.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp5.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp4.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp3.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp2.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp1.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\wfp0.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\tdibth.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ramdisk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ps5333.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\parhmse.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\oeaccess.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nvts.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nvdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nvct.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nv4_disp.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\nettun.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netrndis.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netbeac.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmntstm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmhamrw.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmcxsf2.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\mdmbtmdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\hidbth.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\drm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\bthspp.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\bthprint.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\bthpan.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\bth.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\atixpwdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\atiixpag.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\atiixpaa.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\ati1xwdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#-336 Copying file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sp2.cab" to "C:\WINDOWS\Driver Cache\i386\sp2.cab" via temporary file "C:\WINDOWS\Driver Cache\i386\SET17C1.tmp".
#E361 An unsigned or incorrectly signed file "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\sp2.cab" will be installed (Policy=Ignore). Error 0x800b0100: No signature was present in the subject.
#E197 Writing "C:\WINDOWS\INF\usbvideo.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\startoc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\sffdisk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\sdbus.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\p2p.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\netfw.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\hiddigi.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\fltmgr.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\agp.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\INF\msmsgs.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.

Vince Vespertino
2007-10-15, 22:09
#E008 Setting registry value HKLM\SYSTEM\CurrentControlSet\Services\ssdpsrv\\DependOnService
#E033 Error 5: Access is denied.
#E065 Parsing AddReg section [Product.Add.Reg] in "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.inf" failed. Error 5: Access is denied.
#E064 Parsing install section [ProductInstall.GlobalRegistryChanges.Install] in "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.inf" failed. Error 5: Access is denied.
#E008 Setting registry value HKLM\SYSTEM\CurrentControlSet\Services\ssdpsrv\\DependOnService
#E033 Error 5: Access is denied.
#E065 Parsing AddReg section [Product.Add.Reg] in "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.inf" failed. Error 5: Access is denied.
#E064 Parsing install section [ProductInstall.GlobalRegistryChanges.Install] in "c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\update\update.inf" failed. Error 5: Access is denied.
[2007/10/15 08:33:41 3980.1]
#-198 Command line processed: C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe /~ -u -z
#E361 An unsigned or incorrectly signed file "c:\windows\$ntservicepackuninstall$\spuninst\spuninst.inf" will be installed (Policy=Ignore). Error 1168: Element not found.
#E197 Writing "C:\WINDOWS\inf\accessor.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\atiixpaa.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\atiixpag.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\atiradn1.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\atixpwdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\au.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\bda.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\biosinfo.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\cpu.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\defltwk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\devxprop.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\drm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\drvindex.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\dwup.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\fxsocm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\hiddigi.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\hidserv.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\i81xnt5.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\i81xwfp0.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\i81xwfp1.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\i81xwfp2.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\i81xwfp3.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\i81xwfp4.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\i81xwtv0.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\i81xwtv1.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\i81xwtv2.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\i81xwtv3.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\i81xwtv4.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\ie.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\ieaccess.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\ims.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\input.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\intl.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\keyboard.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\ks.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\kscaptur.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\ksfilter.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\layout.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\machine.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\mchgr.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\mdac.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\mdmirmdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\moviemk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\mpe.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\mplayer2.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\mshdc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\msmsgs.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\msnetmtg.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\msoe50.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\mstape.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\multimed.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\mymusic.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\nabtsfec.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\ndisip.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\netac300.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\netbeac.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\netip6.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\netmscli.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\netoc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\netrass.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\netrtsnt.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\nettcpip.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\nettun.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\netupnph.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\netwzc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\ntprint.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\nv4_disp.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\nvct.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\nvdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\nvts.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\oeaccess.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\oobe.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\pchealth.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\pnpscsi.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\qmgr.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\ramdisk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\s3nb.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\sceregvl.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\scsi.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\secrecs.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\shell.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\shl_img.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\skins.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\slip.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\smartcrd.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\streamip.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\swflash.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\sysoc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\syssetup.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\tape.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\tsoc.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E099 Writing of "C:\WINDOWS\inf\unregmp2.exe" to "C:\WINDOWS\INF" can cause problems.
#E197 Writing "C:\WINDOWS\inf\usbport.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\wmaccess.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\wmdm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\wmfsdk.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\wmp.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\wmpocm.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\wordpad.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E197 Writing "C:\WINDOWS\inf\wstcodec.inf" to "C:\WINDOWS\INF" is not an approved method of installing INF files. Use a 'CopyINF' entry instead.
#E099 Writing of "C:\WINDOWS\inf\wuau.adm" to "C:\WINDOWS\INF" can cause problems.

Mr_JAk3
2007-10-16, 21:15
Hi :)

Are you logged in with an account that has administrative rigths?

Vince Vespertino
2007-10-16, 21:51
Yes, I am logged on as administrator.

Mr_JAk3
2007-10-17, 22:09
Hi :)

Ok I think that I'll need to guide you to CastleCops. There is this Windows NT/2000/2003/XP (http://www.castlecops.com/f134-Windows_NT_2000_2003_XP.html ) section for instance.

This doesn't seem to be a malware issues as you're looking clean.

These kind of issues aren't really my cup of tea so I think that you get better help at CastleCops.

Good luck :bigthumb: