Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trouble With Darksma Downloader, Virtumonde And Win32:agent-isi


  • Please log in to reply
20 replies to this topic

#1 Francys

Francys

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:09:21 PM

Posted 05 July 2007 - 05:53 AM

Do yo can help get trouble with darksma downloader, Virtumonde and win32:agent-ISI?
last week my computer got infected with these three kinds of virus and untill now i dont managed to kill them out.
Yahoo tool bar detected darksma, Virtumonde was detected by spybot search and destroy, and win32:agent-ISI was detected by avast antivirus:

I have already used ad-aware, windows defender, spy sweeper and others, but the viruses seem to be back as soon as i connect to internet.

last night i unistalled internet explorer 7 and installed firefox 2.0, so yahoo tool was unistalled (it doesnt run with firefox 2.0). what can I to be clean that things out my computer?

here is HijackThis last scan log:

Logfile of HijackThis v1.99.1
Scan saved at 07:34:47, on 5/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\hkcmd.exe
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Arquivos de programas\QuickTime\qttask.exe
C:\Arquivos de programas\iTunes\iTunesHelper.exe
C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe
C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\lib\NMBgMonitor.exe
C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe
C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe
C:\Arquivos de programas\WordWeb\wweb32.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\slserv.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeper.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Arquivos de programas\iPod\bin\iPodService.exe
C:\Arquivos de programas\Alwil Software\Avast4\setup\avast.setup
C:\Arquivos de programas\Arquivos comuns\Ahead\lib\NMIndexStoreSvr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\explorer.exe
D:\Meus documentos\My Completed Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - PC78D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1F6581D5-AA53-4b73-A6F9-41420C6B61F1} - C:\WINDOWS\system32\tmp9E.tmp.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {94ab7fbe-9307-43f6-b1ba-b9b82f723b4f} - C:\WINDOWS\system32\javmrt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll
O2 - BHO: (no name) - C87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: (no name) - C49E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Revealer] "D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe" /b
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [winehq.org] "rundll32.exe" "C:\WINDOWS\geeded.dll",realset
O4 - HKLM\..\Run: [SpySweeper] C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe"
O4 - Startup: WordWeb.lnk = C:\Arquivos de programas\WordWeb\wweb32.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\javmrt.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\javmrt.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: Yahoo! Chess - http://download2.games.yahoo.com/games/clients/y/ct5_x.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE1B9472-92C7-41F5-A3B7-78F0A5902467}: NameServer = 200.250.8.1,200.250.8.3
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\awvttro.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: javmrt - C:\WINDOWS\SYSTEM32\javmrt.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: DomainService - Unknown owner - C:\Documents and Settings\Rogria\Dados de aplicativos\tmp3.tmp.exe
O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Arquivos de programas\Arquivos comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeper.exe

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 05 July 2007 - 06:35 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum Francys :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

First please find and delete:
D:\Meus documentos\My Completed Downloads\HijackThis.exe

Now download and install Hijackthis.
This is a self-extracting version which will automatically install HJT to C:\Program Files\Hijackthis by default.
A desktop shortcut can be created during install under 'Select Additional Tasks'.

=========================

Please download VundoFix.exe to your desktop.
Double-click VundoFix.exe to run it.
When VundoFix re-opens,click the "Scan for Vundo" button.
Once it's done scanning,click the "Remove Vundo" button.
You will receive a prompt asking if you want to remove the files, click "YES".
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed,it will prompt that it will reboot your computer,click "OK".
Post the contents of C:\vundofix.txt into your next reply.

Note:
It is possible that VundoFix encountered a file it could not remove.
In this case,VundoFix will run on reboot,simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

=========================

Please download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.


Also post a new Hijackthis log.
Posted Image
Posted Image

#3 Francys

Francys
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:09:21 PM

Posted 05 July 2007 - 07:33 PM

Hi Richie,

Thanks for your help. Here are the logs you asked to post. I hope you can guide me the rest of the way. (could you please tell me if the problems in executing some functions on my computer (suchs problems in opening windows explorer or my web browser) is due to the damages those bad programs may have cause to my system??


By the way, Here goes the logfiles as you asked.


This is my vundofix.txt:


VundoFix V6.5.4

Checking Java version...

Sun Java not detected
Scan started at 21:08:55 4/7/2007

Listing files found while scanning....

C:\WINDOWS\system32\tmp1.tmp.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\tmp1.tmp.dll
C:\WINDOWS\system32\tmp1.tmp.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.4

Checking Java version...

Sun Java not detected
Scan started at 17:37:43 5/7/2007

Listing files found while scanning....

C:\WINDOWS\system32\tmp9E.tmp.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\tmp9E.tmp.dll
C:\WINDOWS\system32\tmp9E.tmp.dll Has been deleted!

Performing Repairs to the registry.
Done!



My ComboFix last scan logfile


"Rogria" - 2007-07-05 19:48:17 - ComboFix 07-07-06 - Service Pack 2


((((((((((((((((((((((((( Files Created from 2007-06-05 to 2007-07-05 )))))))))))))))))))))))))))))))


2007-07-05 18:41 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-05 17:37 83,024 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-07-05 17:37 57,424 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-07-05 17:37 53,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-07-05 17:37 39,376 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-07-05 17:37 29,264 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-07-05 17:36 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-07-05 17:36 <DIR> d-------- C:\DOCUME~1\ROGRIA~1\DADOSD~1\PC Tools
2007-07-05 17:36 <DIR> d-------- C:\Arquivos de programas\Spyware Doctor
2007-07-05 17:03 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Google Updater
2007-07-05 01:26 1,728 --a------ C:\WINDOWS\mozver.dat
2007-07-05 01:17 <DIR> d-------- C:\DOCUME~1\ROGRIA~1\DADOSD~1\Talkback
2007-07-05 00:20 134,993 --a------ C:\WINDOWS\geeded.dll
2007-07-04 23:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\MailFrontier
2007-07-04 23:04 75,932 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-07-04 23:04 75,248 --a------ C:\WINDOWS\zllsputility.exe
2007-07-04 23:04 74,396 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-07-04 23:04 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-07-04 23:03 520,224 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-07-04 23:03 110,360 --a------ C:\WINDOWS\system32\drivers\kl1.sys
2007-07-04 23:02 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-07-04 23:02 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2007-07-04 22:58 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-07-04 22:09 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Lavasoft
2007-07-04 22:09 <DIR> d-------- C:\Arquivos de programas\Lavasoft
2007-07-04 22:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Wise Installation Wizard
2007-07-04 21:08 <DIR> d-------- C:\VundoFix Backups
2007-07-04 20:56 22,080 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2007-07-04 20:56 21,056 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2007-07-04 20:56 20,544 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
2007-07-04 20:56 144,448 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2007-07-04 20:56 <DIR> d-------- C:\DOCUME~1\LOCALS~1\DADOSD~1\Webroot
2007-07-04 20:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Webroot
2007-07-04 20:56 <DIR> d-------- C:\Arquivos de programas\Webroot
2007-07-04 20:55 164 --a------ C:\install.dat
2007-07-04 20:54 <DIR> d-------- C:\DOCUME~1\ROGRIA~1\DADOSD~1\Webroot
2007-07-04 19:16 <DIR> d-------- C:\DOCUME~1\ROGRIA~1\DADOSD~1\GetRightToGo
2007-07-04 01:39 <DIR> d-------- C:\WINDOWS\CSC
2007-07-04 00:52 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Spybot - Search & Destroy
2007-07-03 23:55 <DIR> d-------- C:\Arquivos de programas\Common Files
2007-07-03 22:53 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Yahoo! Companion
2007-07-03 22:48 <DIR> d-------- C:\DOCUME~1\ROGRIA~1\DADOSD~1\Apple Computer
2007-07-03 22:47 <DIR> d-------- C:\Arquivos de programas\iTunes
2007-07-03 22:47 <DIR> d-------- C:\Arquivos de programas\iPod
2007-07-03 22:46 <DIR> d-------- C:\Arquivos de programas\QuickTime
2007-07-03 22:43 <DIR> d-------- C:\Arquivos de programas\Apple Software Update
2007-07-03 22:42 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Apple
2007-07-03 22:42 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Apple
2007-07-03 22:40 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Apple Computer
2007-07-03 12:24 134,914 --a------ C:\WINDOWS\hgdawt.dll
2007-07-02 01:24 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-07-02 01:24 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Dados de aplicativos
2007-07-02 01:24 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Menu Iniciar
2007-07-02 01:24 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Modelos
2007-07-02 01:24 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Configuraes locais
2007-07-02 01:24 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Ambiente de rede
2007-07-02 01:24 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Ambiente de impresso
2007-07-02 01:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Meus documentos
2007-07-02 01:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritos
2007-07-02 00:40 134,871 --a------ C:\WINDOWS\ljihii.dll
2007-06-30 18:30 <DIR> d-------- C:\!KillBox
2007-06-30 18:07 22 --ah----- C:\qpmd8378.bin
2007-06-30 18:01 <DIR> d-------- C:\Arquivos de programas\Microsoft Windows OneCare Live
2007-06-30 17:59 <DIR> d-------- C:\{00002A3A-0000-0000-F2C2-89695A566C7E}
2007-06-30 15:30 <DIR> d-------- C:\Arquivos de programas\Windows Live Safety Center
2007-06-30 15:22 <DIR> d-------- C:\WINDOWS\pss
2007-06-30 14:01 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-06-30 14:01 208,248 --a------ C:\WINDOWS\system32\muweb.dll
2007-06-30 01:43 95,872 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-06-30 01:43 94,552 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-06-30 01:43 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-06-30 01:43 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-06-30 01:43 26,888 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-06-30 01:43 23,416 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-06-30 01:42 745,600 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-06-29 22:37 <DIR> d-------- C:\Arquivos de programas\Microsoft CAPICOM 2.1.0.2
2007-06-29 21:56 <DIR> d-------- C:\DOCUME~1\ROGRIA~1\SecurityScans
2007-06-29 21:55 <DIR> d-------- C:\Arquivos de programas\Microsoft Baseline Security Analyzer 2
2007-06-29 21:49 8,704 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-06-29 21:48 <DIR> d-------- C:\DOCUME~1\ROGRIA~1\DADOSD~1\Sammsoft
2007-06-29 21:37 89,360 --a------ C:\WINDOWS\system32\VB5DB.DLL
2007-06-29 20:15 134,887 --a------ C:\WINDOWS\mlkhfg.dll
2007-06-29 20:06 92,554 --a------ C:\WINDOWS\system32\javmrt.dll
2007-06-29 20:06 67,796 --a------ C:\WINDOWS\system32\dnfc6d6b8a.dat
2007-06-28 21:36 <DIR> d-------- C:\Arquivos de programas\Shareaza
2007-06-24 07:51 <DIR> d-------- C:\DOCUME~1\ROGRIA~1\DADOSD~1\WordWeb
2007-06-24 07:40 1,042,304 --a------ C:\WINDOWS\wweb32.dll
2007-06-24 07:40 <DIR> d-------- C:\Arquivos de programas\WordWeb
2007-06-23 20:17 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-06-17 12:11 <DIR> d-------- C:\WINDOWS\Performance
2007-06-17 12:11 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Microsoft Corporation
2007-06-17 12:09 <DIR> d-------- C:\Arquivos de programas\Alwil Software
2007-06-17 11:56 56,320 --a------ C:\WINDOWS\gendel32.exe
2007-06-17 11:56 <DIR> d-------- C:\HJDATILO
2007-06-09 00:02 <DIR> d-------- C:\Arquivos de programas\Sonic Foundry Setup
2007-06-06 20:21 <DIR> d-------- C:\DOCUME~1\ROGRIA~1\.lincity


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-05 20:30:22 -------- d-----w C:\Arquivos de programas\Google
2007-07-04 02:55:02 -------- d-----w C:\Arquivos de programas\Yahoo!
2007-07-04 02:14:39 -------- d-----w C:\Arquivos de programas\Arquivos comuns\Ahead
2007-07-01 19:26:11 -------- d--h--w C:\Arquivos de programas\InstallShield Installation Information
2007-07-01 18:41:18 60,400 ----a-w C:\WINDOWS\system32\perfc016.dat
2007-07-01 18:41:18 372,296 ----a-w C:\WINDOWS\system32\perfh016.dat
2007-07-01 14:17:14 -------- d-----w C:\Arquivos de programas\Orbitdownloader
2007-06-30 21:05:15 -------- d-----w C:\DOCUME~1\ROGRIA~1\DADOSD~1\Orbit
2007-06-24 18:16:46 -------- d-----w C:\Arquivos de programas\Microsoft.NET
2007-06-21 02:06:54 -------- d-----w C:\Arquivos de programas\Messenger
2007-06-19 01:00:40 -------- d-----w C:\Arquivos de programas\Microsoft Works
2007-06-04 18:18:48 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 18:17:02 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 18:14:56 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-20 01:34:01 58 ----a-w C:\WINDOWS\popcinfo.dat
2007-05-16 15:13:54 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:22:27 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:13:00 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 01:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 01:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 01:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 01:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 01:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 01:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 01:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 01:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-13 18:19:52 7,680 ----a-w C:\WINDOWS\system32\lsdelete.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-10-22 23:08 62080 --a------ C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 --a------ C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-06-14 18:32 509592 --a------ C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{94ab7fbe-9307-43f6-b1ba-b9b82f723b4f}]
2007-06-29 20:06 92554 --a------ C:\WINDOWS\system32\javmrt.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
2007-07-04 20:28 2193280 -ra------ c:\arquivos de programas\google\googletoolbar1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
2007-07-05 17:03 324536 --a------ C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Revealer"="D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe" [2006-11-28 19:26]
"SoundMAXPnP"="C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-04-01 09:52]
"SoundMAX"="C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" [2004-03-26 13:40]
"Cmaudio"="cmicnfg.cpl" []
"avast!"="C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 12:42]
"Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Arquivos de programas\iTunes\iTunesHelper.exe" [2007-06-28 09:14]
"SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe" [2007-06-14 18:32]
"ZoneAlarm Client"="C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]
"Google Desktop Search"="C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe" [2007-07-05 17:30]
"SDTray"="C:\Arquivos de programas\Spyware Doctor\SDTrayApp.exe" [2007-06-12 13:19]
"SpySweeper"="C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-01-25 22:00]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Arquivos de programas\Arquivos comuns\Ahead\lib\NMBgMonitor.exe" [2005-11-24 15:38]
"SpybotSD TeaTimer"="C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]
"swg"="C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-05 17:03]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"NoResolveSearch"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\javmrt]
javmrt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\awvttro.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc


Contents of the 'Scheduled Tasks' folder
2007-07-04 01:43:43 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-05 20:15:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-05 20:37:44
C:\ComboFix-quarantined-files.txt ... 2007-07-05 20:37

--- E O F ---


and here's my HijackThis last logfile

Logfile of HijackThis v1.99.1
Scan saved at 20:53:53, on 5/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Arquivos de programas\Spyware Doctor\svcntaux.exe
C:\Arquivos de programas\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\slserv.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeper.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\Arquivos de programas\Spyware Doctor\SDTrayApp.exe
D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\Arquivos de programas\QuickTime\qttask.exe
C:\Arquivos de programas\iTunes\iTunesHelper.exe
C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe
C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe
C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\lib\NMBgMonitor.exe
C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe
C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe
C:\Arquivos de programas\WordWeb\wweb32.exe
C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\SSU.EXE
C:\Arquivos de programas\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Arquivos de programas\Alwil Software\Avast4\setup\avast.setup
C:\Arquivos de programas\Arquivos comuns\Ahead\lib\NMIndexStoreSvr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\explorer.exe
C:\Arquivos de programas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - PC78D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {94ab7fbe-9307-43f6-b1ba-b9b82f723b4f} - C:\WINDOWS\system32\javmrt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O2 - BHO: (no name) - C87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: (no name) - C49E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Revealer] "D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe" /b
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SDTray] "C:\Arquivos de programas\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Startup: WordWeb.lnk = C:\Arquivos de programas\WordWeb\wweb32.exe
O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\javmrt.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\javmrt.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: Yahoo! Chess - http://download2.games.yahoo.com/games/clients/y/ct5_x.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE1B9472-92C7-41F5-A3B7-78F0A5902467}: NameServer = 200.250.8.1,200.250.8.3
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\awvttro.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: javmrt - C:\WINDOWS\SYSTEM32\javmrt.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Arquivos de programas\Arquivos comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Arquivos de programas\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Arquivos de programas\Spyware Doctor\swdsvc.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeper.exe

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 06 July 2007 - 03:00 AM

Copy and paste the following bold blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: fix.reg to your desktop.
Then double click on the fix.reg file on your desktopPosted Imageand agree to merge it into the registry,then reboot.

REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=-

================================

*Warning*

C:\WINDOWS\gendel32.exe is currently present on your pc.
Gendel32.exe is a Backdoor Trojan.
A Backdoor is a software program that gives an attacker unauthorized access to a machine and the means for remotely controlling the machine without the user's knowledge. A Backdoor compromises system integrity by making changes to the system that allow it to by used by the attacker for malicious purposes unknown to the user.

They are typically installed without user interaction through security exploits, and may allow an attacker to remotely control the infected machine. Such risks may allow the attacker to install additional malware and use the compromised machine to participate in denial of service attacks, spamming, and bot nets, or to transmit sensitive data to a remote server. The malware may be cloaked and not visible to the user. These risks severely compromise the system by lowering security settings, installing 'backdoors,' infecting system files, or spreading to other networked machines.

If your computer was used for online banking or has credit card information on it, all passwords should be changed immediately to include those used for email, eBay and forums.
You should consider them to be compromised.
They should be changed by using a different computer and not the infected one,if not an attacker may get the new passwords and transaction information.
Banking and credit card institutions should be notified of the possible security breech.

================================

Download Avenger from the link below:
http://swandog46.geekstogo.com/avenger.zip
Unzip/extract it to your desktop.

Start up Avenger.
Check the 'Input script manually' option.
Click the Magnifying Glass icon.
In the box that opens,copy and paste ALL the following bold blue text in the Quote box below:

Files to delete:
C:\WINDOWS\geeded.dll
C:\WINDOWS\hgdawt.dll
C:\WINDOWS\ljihii.dll
C:\WINDOWS\mlkhfg.dll
C:\WINDOWS\gendel32.exe
C:\WINDOWS\popcinfo.dat
C:\WINDOWS\system32\javmrt.dll

Then click on 'Done'.
Click the Traffic Light icon to start the program.
Then press OK at the prompts to reboot your PC.

Post the Avenger output.txt, which you can find at C:\Avenger\.txt into your next reply.
Also post a new Hijackthis log please.
Posted Image
Posted Image

#5 Francys

Francys
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:09:21 PM

Posted 06 July 2007 - 05:33 AM

Done! Here they are:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\byhvunvx

*******************

Script file located at: \??\C:\Documents and Settings\egcvrcsm.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\geeded.dll deleted successfully.
File C:\WINDOWS\hgdawt.dll deleted successfully.
File C:\WINDOWS\ljihii.dll deleted successfully.
File C:\WINDOWS\mlkhfg.dll deleted successfully.
File C:\WINDOWS\gendel32.exe deleted successfully.
File C:\WINDOWS\popcinfo.dat deleted successfully.
File C:\WINDOWS\system32\javmrt.dll deleted successfully.

Completed script processing.

*******************

Finished! Terminate.


Logfile of HijackThis v1.99.1
Scan saved at 07:28:09, on 6/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\slserv.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe
C:\Arquivos de programas\WordWeb\wweb32.exe
C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\notepad.exe
C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Arquivos de programas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - PC78D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {94ab7fbe-9307-43f6-b1ba-b9b82f723b4f} - C:\WINDOWS\system32\javmrt.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O2 - BHO: (no name) - C87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: (no name) - C49E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O4 - HKLM\..\Run: [Revealer] "D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe" /b
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Startup: WordWeb.lnk = C:\Arquivos de programas\WordWeb\wweb32.exe
O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: Yahoo! Chess - http://download2.games.yahoo.com/games/clients/y/ct5_x.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE1B9472-92C7-41F5-A3B7-78F0A5902467}: NameServer = 200.250.8.1,200.250.8.3
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: javmrt - javmrt.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Arquivos de programas\Arquivos comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 06 July 2007 - 07:33 AM

Please disable Spybot S&Ds protection,or it will interfere.
You can enable it after you're clean.
Open Spybot and click on 'Mode' and check 'Advanced Mode'.
Click on 'Tools' in bottom left hand corner.
Click on the 'System Startup' icon.
Uncheck 'Teatimer' box and/or uncheck 'Resident'.
Click the 'Allow Change' box.
Then, check next to the computer clock to see if the icon for Spybot is still there.
If it is, right click it and choose 'exit Spybot-S&D Resident'.
Reboot the computer.

If you find you're experiencing problems disabling Spybot's Tea-Timer,follow the info in the link below:
http://www.russelltexas.com/malware/teatimer.htm

=================================

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: (no name) - PC78D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: (no name) - {94ab7fbe-9307-43f6-b1ba-b9b82f723b4f} - C:\WINDOWS\system32\javmrt.dll (file missing)
O2 - BHO: (no name) - C87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: (no name) - C49E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O20 - Winlogon Notify: javmrt - javmrt.dll (file missing)

Exit Hijackthis.

Start SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.
Also post a new Hijackthis log,let me know how your pc is running now.

Posted Image
Posted Image

#7 Francys

Francys
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:09:21 PM

Posted 06 July 2007 - 06:14 PM

My computer is running better and faster.
Please, let me know what antispies I should let installed permanently on my pc for effective defense. can use more than one? what about firewalls? Is ZoneAlarm firewall a good option?

Sorry, but I couldn't copy the log of SUPERAntivirus: It opens in Notepad but doesn't allows me to edit by simply stopping working.

Logfile of HijackThis v1.99.1
Scan saved at 18:58:59, on 6/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\slserv.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe
C:\Arquivos de programas\WordWeb\wweb32.exe
C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\notepad.exe
C:\Arquivos de programas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O4 - HKLM\..\Run: [Revealer] "D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe" /b
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: WordWeb.lnk = C:\Arquivos de programas\WordWeb\wweb32.exe
O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: Yahoo! Chess - http://download2.games.yahoo.com/games/clients/y/ct5_x.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE1B9472-92C7-41F5-A3B7-78F0A5902467}: NameServer = 200.250.8.1,200.250.8.3
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Arquivos de programas\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Arquivos de programas\Arquivos comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 07 July 2007 - 06:08 AM

Please, let me know what antispies I should let installed permanently on my pc for effective defense.


Well you've already got SuperAntispyware installed,its freeware,you should keep that.

You might want to download/install SpywareBlaster[freeware]:
http://www.javacoolsoftware.com/spywareblaster.html

can use more than one?

You can indeed.

what about firewalls? Is ZoneAlarm firewall a good option?

Below you'll find free third party firewalls,they're all very good:

Outpost Firewall Free:
http://www.agnitum.com/products/outpostfree/index.php

Sygate Personal Firewall Free Edition:
http://www.filehippo.com/download_sygate_personal_firewall/

Zone Alarm Free:
http://download.zonelabs.com/bin/free/1001..._737_000_en.exe

Comodo Personal Firewall:
http://www.personalfirewall.comodo.com/

================================

Your log is clean :thumbsup:
If all's ok,please do the following:

Find and delete:
VundoFix.exe
Combofix.exe
fix.reg
Avenger


C:\VundoFix Backups
C:\Avenger
C:\QOOBOX
================================

Enable Spybot S&Ds protection.

================================

Download ATF Cleaner by Atribune:
http://www.atribune.org/ccount/click.php?id=1

Double-click ATF-Cleaner.exe to run the program.
Click 'Select All' found at the bottom of the list.
Click the 'Empty Selected' button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

If you use Opera browser,do this also:
Click Opera at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

Click 'Exit' on the Main menu to close the program.

================================

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
'How to prevent Malware' by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html
Posted Image
Posted Image

#9 Francys

Francys
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:09:21 PM

Posted 07 July 2007 - 12:57 PM

Thank you very much for helping me, Richie. Everything is really doing fine.

But I still have two question:

1) I have in my d: driver two folders i don't know how they came out.when i try to access them appears the message "access denied".
Are that folders related to those malwares?


D:\95b0099c86758821f8c578e23f19

D:\8cd121c50b129be0a08aae07a4

2) When I run HijackThis I notice that there still are some (no file) or (missing file).

O2 - BHO: (no name) - PC78D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {94ab7fbe-9307-43f6-b1ba-b9b82f723b4f} - (no file)
O2 - BHO: (no name) - C87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: (no name) - C49E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

Does that mean any kind of trouble?

This the entire HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 14:46:39, on 7/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\slserv.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe
C:\Arquivos de programas\WordWeb\wweb32.exe
C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\ARQUIV~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Arquivos de programas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - PC78D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {94ab7fbe-9307-43f6-b1ba-b9b82f723b4f} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O2 - BHO: (no name) - C87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: (no name) - C49E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O4 - HKLM\..\Run: [Revealer] "D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe" /b
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: WordWeb.lnk = C:\Arquivos de programas\WordWeb\wweb32.exe
O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\javmrt.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\javmrt.dll (file missing)
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: Yahoo! Chess - http://download2.games.yahoo.com/games/clients/y/ct5_x.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE1B9472-92C7-41F5-A3B7-78F0A5902467}: NameServer = 200.250.8.1,200.250.8.3
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Arquivos de programas\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: javmrt - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Arquivos de programas\Arquivos comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I will grateful if you could once more make things clear to me

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 07 July 2007 - 01:49 PM

Please download DrWeb-CureIt & save it to your desktop. DO NOT perform a scan yet.

You should copy/print the following because you need to be in Safe Mode from here on.

Reboot your computer into SAFE MODE" using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: (no name) - PC78D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: (no name) - {94ab7fbe-9307-43f6-b1ba-b9b82f723b4f} - (no file)
O2 - BHO: (no name) - C87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: (no name) - C49E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\javmrt.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\javmrt.dll (file missing)
O20 - Winlogon Notify: javmrt - C:\WINDOWS\

Exit Hijackthis.

Find and delete:
D:\95b0099c86758821f8c578e23f19
D:\8cd121c50b129be0a08aae07a4

Still in Safe Mode scan with DrWeb-CureIt as follows:
* Double-click on drweb-cureit.exe to start the program. An "Express Scan of your PC" notice will appear.
* Under "Start the Express Scan Now", Click "OK" to start. This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.
* Once the short scan has finished, Click Options > Change settings
* Choose the "Scan tab" and UNcheck "Heuristic analysis"
* Back at the main window, click "Select drives" (a red dot will show which drives have been chosen)
* Then click the "Start/Stop Scanning" button (green arrow on the right) and the scan will start.
* When done, a message will be displayed at the bottom advising if any viruses were found.
* Click "Yes to all" if it asks if you want to cure/move the file.
* When the scan has finished, look if you can see the icon next to the files found. If so, click it, then click the next icon right below and select "Move incurable".
(This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
* Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
* Save the DrWeb.csv report to your desktop.
* Exit Dr.Web Cureit when done.
* Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
* After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

Also post a new Hijackthis log.
Posted Image
Posted Image

#11 Francys

Francys
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:09:21 PM

Posted 08 July 2007 - 12:38 PM

I did as you told me to do but

couldn't delete
D:\95b0099c86758821f8c578e23f19
D:\8cd121c50b129be0a08aae07a4

this the Dr.Web log
VBAOL11.CHM\html/olobjAddressEntries.htm;C:\Arquivos de programas\Microsoft Office\OFFICE11\1046\VBAOL11.CHM;Modificao de VBS.Petik;;
VBAOL11.CHM;C:\Arquivos de programas\Microsoft Office\OFFICE11\1046;O arquivo contm objectos infectados;Movido.;
RegUBP2b-Rogria.reg;C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Snapshots;Trojan.StartPage.1505;Deleted.;
A0008048.reg;C:\System Volume Information\_restore{F08E7FBE-9859-43FB-B56C-960EC46CF3C9}\RP17;Trojan.StartPage.1505;Deleted.;

and here 's the HijackThis new log
Logfile of HijackThis v1.99.1
Scan saved at 14:30:24, on 8/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\slserv.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe
C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe
C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe
C:\Arquivos de programas\WordWeb\wweb32.exe
C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Arquivos de programas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - PC78D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {94ab7fbe-9307-43f6-b1ba-b9b82f723b4f} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O2 - BHO: MU Online Toolbar Helper - {D3138B39-C8A6-440B-9D42-50F766AEA8C7} - C:\Arquivos de programas\MU Online Toolbar\v3.2.0.0\MU_Online_Toolbar.dll
O2 - BHO: (no name) - C87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: (no name) - C49E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O3 - Toolbar: MU Online Toolbar - {B9D1647F-A66A-4695-B249-07901A45FF59} - C:\Arquivos de programas\MU Online Toolbar\v3.2.0.0\MU_Online_Toolbar.dll
O4 - HKLM\..\Run: [Revealer] "D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe" /b
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: WordWeb.lnk = C:\Arquivos de programas\WordWeb\wweb32.exe
O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: Yahoo! Chess - http://download2.games.yahoo.com/games/clients/y/ct5_x.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE1B9472-92C7-41F5-A3B7-78F0A5902467}: NameServer = 200.250.8.1,200.250.8.3
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Arquivos de programas\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: javmrt - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Arquivos de programas\Arquivos comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 08 July 2007 - 12:54 PM

Please disable Spybot S&Ds protection,as its interfering.
You can enable it after you're clean.
Open Spybot and click on 'Mode' and check 'Advanced Mode'.
Click on 'Tools' in bottom left hand corner.
Click on the 'System Startup' icon.
Uncheck 'Teatimer' box and/or uncheck 'Resident'.
Click the 'Allow Change' box.
Then, check next to the computer clock to see if the icon for Spybot is still there.
If it is, right click it and choose 'exit Spybot-S&D Resident'.
Reboot the computer.

*Note*
If you find you're experiencing problems disabling Spybot's Tea-Timer,follow the info in the link below:
http://www.russelltexas.com/malware/teatimer.htm

==============================

Please download the OTMoveIt by OldTimer:
http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

D:\95b0099c86758821f8c578e23f19
D:\8cd121c50b129be0a08aae07a4


Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
Click the red Moveit! button.
Close OTMoveIt

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.
If you are asked to reboot the machine choose Yes.

===============================

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: (no name) - PC78D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: (no name) - {94ab7fbe-9307-43f6-b1ba-b9b82f723b4f} - (no file)
O2 - BHO: (no name) - C87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: (no name) - C49E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O20 - Winlogon Notify: javmrt - C:\WINDOWS\

Exit Hijackthis.

Restart your pc.
Post a new Hijackthis log please.
Posted Image
Posted Image

#13 Francys

Francys
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:09:21 PM

Posted 08 July 2007 - 05:15 PM

I disabled Spybot Search and destroys protection, downloaded and ran OTMoveIt but not even in safe mode I could get off D:\95b0099c86758821f8c578e23f19
D:\8cd121c50b129be0a08aae07a4

After done what you told me to do I verified they were still there ate the same place, so tried to open these folders but the same message came out "Access denied. Verify if the disc is full or protect from recording and if the file is not in use"

But the disc is not full nor protected from recording
I also notice their size points to 0 but once I dragged a folder containing about 100 image files into one of them.

Logfile of HijackThis v1.99.1
Scan saved at 18:56:50, on 8/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\slserv.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe
C:\Arquivos de programas\WordWeb\wweb32.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Arquivos de programas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O3 - Toolbar: MU Online Toolbar - {B9D1647F-A66A-4695-B249-07901A45FF59} - C:\Arquivos de programas\MU Online Toolbar\v3.2.0.0\MU_Online_Toolbar.dll
O4 - HKLM\..\Run: [Revealer] "D:\Meus documentos\Francisnei\Programas\Revealer Free Edition\revealer.exe" /b
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: WordWeb.lnk = C:\Arquivos de programas\WordWeb\wweb32.exe
O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: Yahoo! Chess - http://download2.games.yahoo.com/games/clients/y/ct5_x.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE1B9472-92C7-41F5-A3B7-78F0A5902467}: NameServer = 200.250.8.1,200.250.8.3
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Arquivos de programas\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Arquivos de programas\Arquivos comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

#14 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 08 July 2007 - 05:54 PM

I have in my d: driver two folders i don't know how they came out.when i try to access them appears the message "access denied".
Are that folders related to those malwares?

D:\95b0099c86758821f8c578e23f19
D:\8cd121c50b129be0a08aae07a4

I don't think those folders are malware related,try the following,see if you can gain access to them.

How to take ownership of a file or folder in Windows XP:
http://support.microsoft.com/kb/308421

Scroll down to and follow the instructions at:
How to take ownership of a folder.

Let me know how you get on please.
Posted Image
Posted Image

#15 Francys

Francys
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:09:21 PM

Posted 08 July 2007 - 10:01 PM

The first folder had my image file folder in; I deleted it: Did I do right?

The second has a logfile in, I don't know what it means. Could you please help with this?

This is thee name of the file: msxml4-KB927978-enu


and this the first part of file (I divide into parts because the post was too long to be applied)
Please tell me what to do. :thumbsup:

=== Verbose logging started: 12/2/2007 22:57:54 Build type: SHIP UNICODE 3.00.3790.2180 Calling process: C:\WINDOWS\system32\msiexec.exe ===
MSI © (E8:94) [22:57:54:593]: Resetting cached policy values
MSI © (E8:94) [22:57:54:593]: Machine policy value 'Debug' is 0
MSI © (E8:94) [22:57:54:593]: ******* RunEngine:
******* Product: d:\64e9d6f09c56f8c573aedda6df\msxml.msi
******* Action:
******* CommandLine: **********
MSI © (E8:94) [22:57:54:609]: Client-side and UI is none or basic: Running entire install on the server.
MSI © (E8:94) [22:57:54:609]: Grabbed execution mutex.
MSI © (E8:94) [22:57:54:734]: Cloaking enabled.
MSI © (E8:94) [22:57:54:734]: Attempting to enable all disabled priveleges before calling Install on Server
MSI © (E8:94) [22:57:54:734]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (88:80) [22:57:54:781]: Grabbed execution mutex.
MSI (s) (88:58) [22:57:54:781]: Resetting cached policy values
MSI (s) (88:58) [22:57:54:781]: Machine policy value 'Debug' is 0
MSI (s) (88:58) [22:57:54:781]: ******* RunEngine:
******* Product: d:\64e9d6f09c56f8c573aedda6df\msxml.msi
******* Action:
******* CommandLine: **********
MSI (s) (88:58) [22:57:54:812]: Machine policy value 'DisableUserInstalls' is 0
MSI (s) (88:58) [22:57:54:859]: End dialog not enabled
MSI (s) (88:58) [22:57:54:859]: Original package ==> d:\64e9d6f09c56f8c573aedda6df\msxml.msi
MSI (s) (88:58) [22:57:54:859]: Package we're running from ==> C:\WINDOWS\Installer\e4bf99.msi
MSI (s) (88:58) [22:57:54:875]: APPCOMPAT: looking for appcompat database entry with ProductCode '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (88:58) [22:57:54:875]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (88:58) [22:57:54:906]: MSCOREE not loaded loading copy from system32
MSI (s) (88:58) [22:57:55:359]: Machine policy value 'DisablePatch' is 0
MSI (s) (88:58) [22:57:55:359]: Machine policy value 'AllowLockdownPatch' is 0
MSI (s) (88:58) [22:57:55:359]: Machine policy value 'DisableLUAPatching' is 0
MSI (s) (88:58) [22:57:55:359]: Machine policy value 'DisableFlyWeightPatching' is 0
MSI (s) (88:58) [22:57:55:359]: APPCOMPAT: looking for appcompat database entry with ProductCode '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (88:58) [22:57:55:359]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (88:58) [22:57:55:359]: Transforms are not secure.
MSI (s) (88:58) [22:57:55:359]: Command Line: REBOOT=ReallySuppress CURRENTDIRECTORY=d:\64e9d6f09c56f8c573aedda6df CLIENTUILEVEL=3 CLIENTPROCESSID=3816
MSI (s) (88:58) [22:57:55:359]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{2B27DCD9-53FA-4885-B6CD-698623819F4C}'.
MSI (s) (88:58) [22:57:55:359]: Product Code passed to Engine.Initialize: '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'
MSI (s) (88:58) [22:57:55:359]: Product Code from property table before transforms: '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'
MSI (s) (88:58) [22:57:55:359]: Product Code from property table after transforms: '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'
MSI (s) (88:58) [22:57:55:359]: Product registered: entering maintenance mode
MSI (s) (88:58) [22:57:55:359]: PROPERTY CHANGE: Adding ProductState property. Its value is '5'.
MSI (s) (88:58) [22:57:55:359]: PROPERTY CHANGE: Adding ProductToBeRegistered property. Its value is '1'.
MSI (s) (88:58) [22:57:55:359]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (88:58) [22:57:55:359]: Specifed source is not already in a list.
MSI (s) (88:58) [22:57:55:359]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (88:58) [22:57:55:359]: Machine policy value 'DisableBrowse' is 0
MSI (s) (88:58) [22:57:55:359]: Machine policy value 'AllowLockdownBrowse' is 0
MSI (s) (88:58) [22:57:55:359]: Adding new sources is allowed.
MSI (s) (88:58) [22:57:55:359]: Package name retrieved from configuration data: 'msxml.msi'
MSI (s) (88:58) [22:57:55:359]: Determined that existing product (either this product or the product being upgraded with a patch) is installed per-machine.
MSI (s) (88:58) [22:57:55:359]: Note: 1: 2729
MSI (s) (88:58) [22:57:55:468]: Note: 1: 2729
MSI (s) (88:58) [22:57:55:468]: Note: 1: 2262 2: AdminProperties 3: -2147287038
MSI (s) (88:58) [22:57:55:468]: Machine policy value 'DisableMsi' is 0
MSI (s) (88:58) [22:57:55:468]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (88:58) [22:57:55:468]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (88:58) [22:57:55:484]: Product {37477865-A3F1-4772-AD43-AAFC6BCFF99F} is admin assigned: LocalSystem owns the publish key.
MSI (s) (88:58) [22:57:55:484]: Product {37477865-A3F1-4772-AD43-AAFC6BCFF99F} is managed.
MSI (s) (88:58) [22:57:55:484]: Running product '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}' with elevated privileges: Product is assigned.
MSI (s) (88:58) [22:57:55:484]: PROPERTY CHANGE: Adding REBOOT property. Its value is 'ReallySuppress'.
MSI (s) (88:58) [22:57:55:484]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'd:\64e9d6f09c56f8c573aedda6df'.
MSI (s) (88:58) [22:57:55:484]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.
MSI (s) (88:58) [22:57:55:484]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '3816'.
MSI (s) (88:58) [22:57:55:484]: TRANSFORMS property is now:
MSI (s) (88:58) [22:57:55:484]: PROPERTY CHANGE: Adding PRODUCTLANGUAGE property. Its value is '1033'.
MSI (s) (88:58) [22:57:55:484]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '200'.
MSI (s) (88:58) [22:57:55:500]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Dados de aplicativos
MSI (s) (88:58) [22:57:55:500]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Favoritos
MSI (s) (88:58) [22:57:55:515]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Ambiente de rede
MSI (s) (88:58) [22:57:55:515]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Meus documentos
MSI (s) (88:58) [22:57:55:515]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Ambiente de impresso
MSI (s) (88:58) [22:57:55:515]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Recent
MSI (s) (88:58) [22:57:55:515]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\SendTo
MSI (s) (88:58) [22:57:55:515]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Modelos
MSI (s) (88:58) [22:57:55:515]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Dados de aplicativos
MSI (s) (88:58) [22:57:55:515]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Configuraes locais\Dados de aplicativos
MSI (s) (88:58) [22:57:55:515]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Meus documentos\Minhas imagens
MSI (s) (88:58) [22:57:55:515]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Menu iniciar\Programas\Ferramentas administrativas
MSI (s) (88:58) [22:57:55:515]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar
MSI (s) (88:58) [22:57:55:515]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Menu Iniciar\Programas
MSI (s) (88:58) [22:57:55:531]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Menu Iniciar
MSI (s) (88:58) [22:57:55:531]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Desktop
MSI (s) (88:58) [22:57:55:531]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Menu iniciar\Programas\Ferramentas administrativas
MSI (s) (88:58) [22:57:55:546]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Menu Iniciar\Programas\Inicializar
MSI (s) (88:58) [22:57:55:546]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Menu Iniciar\Programas
MSI (s) (88:58) [22:57:55:562]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Menu Iniciar
MSI (s) (88:58) [22:57:55:562]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Desktop
MSI (s) (88:58) [22:57:55:562]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Modelos
MSI (s) (88:58) [22:57:55:562]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\Fonts
MSI (s) (88:58) [22:57:55:562]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16
MSI (s) (88:58) [22:57:55:562]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.
MSI (s) (88:58) [22:57:55:562]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'Ingacvom'.
MSI (s) (88:58) [22:57:55:562]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (88:58) [22:57:55:562]: PROPERTY CHANGE: Adding Installed property. Its value is '00:00:00'.
MSI (s) (88:58) [22:57:55:562]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'C:\WINDOWS\Installer\e4bf99.msi'.
MSI (s) (88:58) [22:57:55:562]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'd:\64e9d6f09c56f8c573aedda6df\msxml.msi'.
MSI (s) (88:58) [22:57:55:562]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (88:58) [22:57:55:562]: Machine policy value 'DisableRollback' is 0
MSI (s) (88:58) [22:57:55:562]: User policy value 'DisableRollback' is 0
MSI (s) (88:58) [22:57:55:562]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.
=== Logging started: 12/2/2007 22:57:55 ===
MSI (s) (88:58) [22:57:55:562]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.
MSI (s) (88:58) [22:57:55:562]: Doing action: INSTALL
MSI (s) (88:58) [22:57:55:578]: Running ExecuteSequence
MSI (s) (88:58) [22:57:55:593]: Doing action: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901
Action start 22:57:55: INSTALL.
MSI (s) (88:58) [22:57:55:593]: PROPERTY CHANGE: Adding DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Documents and Settings\All Users\Desktop\'.
Action start 22:57:55: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901.
MSI (s) (88:58) [22:57:55:593]: Doing action: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901
Action ended 22:57:55: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901. Return value 1.
MSI (s) (88:58) [22:57:55:593]: PROPERTY CHANGE: Adding ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Documents and Settings\All Users\Menu Iniciar\Programas\'.
Action start 22:57:55: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901.
MSI (s) (88:58) [22:57:55:609]: Doing action: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
Action ended 22:57:55: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901. Return value 1.
MSI (s) (88:58) [22:57:55:609]: PROPERTY CHANGE: Adding WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 22:57:55: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537.
MSI (s) (88:58) [22:57:55:609]: Doing action: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
Action ended 22:57:55: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (88:58) [22:57:55:609]: PROPERTY CHANGE: Adding SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:57:55: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537.
MSI (s) (88:58) [22:57:55:609]: Doing action: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537
Action ended 22:57:55: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (88:58) [22:57:55:609]: PROPERTY CHANGE: Adding WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 22:57:55: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537.
MSI (s) (88:58) [22:57:55:609]: Doing action: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537
Action ended 22:57:55: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (88:58) [22:57:55:609]: PROPERTY CHANGE: Adding SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:57:55: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537.
MSI (s) (88:58) [22:57:55:609]: Doing action: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
Action ended 22:57:55: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (88:58) [22:57:55:609]: PROPERTY CHANGE: Adding WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 22:57:55: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537.
MSI (s) (88:58) [22:57:55:609]: Doing action: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
Action ended 22:57:55: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (88:58) [22:57:55:609]: PROPERTY CHANGE: Adding SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:57:55: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537.
MSI (s) (88:58) [22:57:55:609]: Doing action: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB
Action ended 22:57:55: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (88:58) [22:57:55:609]: PROPERTY CHANGE: Adding SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:57:55: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB.
MSI (s) (88:58) [22:57:55:609]: Doing action: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1
Action ended 22:57:55: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB. Return value 1.
MSI (s) (88:58) [22:57:55:625]: PROPERTY CHANGE: Adding SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:57:55: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1.
MSI (s) (88:58) [22:57:55:625]: Doing action: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7
Action ended 22:57:55: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1. Return value 1.
MSI (s) (88:58) [22:57:55:625]: PROPERTY CHANGE: Adding SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:57:55: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7.
MSI (s) (88:58) [22:57:55:625]: Doing action: LaunchConditions
Action ended 22:57:55: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7. Return value 1.
Action start 22:57:55: LaunchConditions.
MSI (s) (88:58) [22:57:55:625]: Doing action: FindRelatedProducts
Action ended 22:57:55: LaunchConditions. Return value 1.
MSI (s) (88:58) [22:57:55:625]: Skipping FindRelatedProducts action: not run in maintenance mode
Action start 22:57:55: FindRelatedProducts.
MSI (s) (88:58) [22:57:55:625]: Doing action: AppSearch
Action ended 22:57:55: FindRelatedProducts. Return value 0.
Action start 22:57:55: AppSearch.
MSI (s) (88:58) [22:57:55:625]: Note: 1: 2262 2: Signature 3: -2147287038
MSI (s) (88:58) [22:57:55:625]: PROPERTY CHANGE: Adding WINHTTP_51 property. Its value is 'WinHttpRequest Component version 5.1'.
MSI (s) (88:58) [22:57:55:625]: Skipping action: CCPSearch (condition is false)
MSI (s) (88:58) [22:57:55:625]: Skipping action: RMCCPSearch (condition is false)
MSI (s) (88:58) [22:57:55:625]: Doing action: ValidateProductID
Action ended 22:57:55: AppSearch. Return value 1.
Action start 22:57:55: ValidateProductID.
MSI (s) (88:58) [22:57:55:625]: Doing action: CostInitialize
Action ended 22:57:55: ValidateProductID. Return value 1.
MSI (s) (88:58) [22:57:55:625]: Machine policy value 'MaxPatchCacheSize' is 10
Action start 22:57:55: CostInitialize.
MSI (s) (88:58) [22:57:55:640]: PROPERTY CHANGE: Adding ROOTDRIVE property. Its value is 'd:\'.
MSI (s) (88:58) [22:57:55:640]: PROPERTY CHANGE: Adding CostingComplete property. Its value is '0'.
MSI (s) (88:58) [22:57:55:640]: Note: 1: 2205 2: 3: Patch
MSI (s) (88:58) [22:57:55:640]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (88:58) [22:57:55:640]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (88:58) [22:57:55:640]: Note: 1: 2205 2: 3: __MsiPatchFileList
MSI (s) (88:58) [22:57:55:640]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (88:58) [22:57:55:640]: Note: 1: 2228 2: 3: PatchPackage 4: SELECT `DiskId`, `PatchId`, `LastSequence` FROM `Media`, `PatchPackage` WHERE `Media`.`DiskId`=`PatchPackage`.`Media_` ORDER BY `DiskId`
MSI (s) (88:58) [22:57:55:640]: Doing action: FileCost
Action ended 22:57:55: CostInitialize. Return value 1.
MSI (s) (88:58) [22:57:55:656]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:57:55: FileCost.
MSI (s) (88:58) [22:57:55:656]: Doing action: CostFinalize
Action ended 22:57:55: FileCost. Return value 1.
MSI (s) (88:58) [22:57:55:656]: PROPERTY CHANGE: Adding OutOfDiskSpace property. Its value is '0'.
MSI (s) (88:58) [22:57:55:656]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Its value is '0'.
MSI (s) (88:58) [22:57:55:656]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceAvailable property. Its value is '0'.
MSI (s) (88:58) [22:57:55:656]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRequired property. Its value is '0'.
MSI (s) (88:58) [22:57:55:656]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRemaining property. Its value is '0'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding MSXML property. Its value is 'C:\Arquivos de programas\MSXML 4.0'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Modifying SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'C:\WINDOWS\system32'.
MSI (s) (88:58) [22:57:55:671]: Note: 1: 2205 2: 3: Patch
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding TARGETDIR property. Its value is 'd:\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 property. Its value is 'C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 property. Its value is 'C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\MSDN\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\Manifests\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\Policies\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa6920e9f98fc\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\Policies\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\Manifests\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\Policies\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\Manifests\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Modifying SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 property. Its current value is 'C:\WINDOWS\system32'. Its new value: 'C:\WINDOWS\system32\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Modifying MSXML property. Its current value is 'C:\Arquivos de programas\MSXML 4.0'. Its new value: 'C:\Arquivos de programas\MSXML 4.0\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding INC.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Arquivos de programas\MSXML 4.0\inc\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding LIB.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Arquivos de programas\MSXML 4.0\lib\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding DOC.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Arquivos de programas\MSXML 4.0\doc\'.
MSI (s) (88:58) [22:57:55:671]: PROPERTY CHANGE: Adding MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Documents and Settings\All Users\Menu Iniciar\Programas\MSXML 4.0\'.
MSI (s) (88:58) [22:57:55:671]: Target path resolution complete. Dumping Directory table...
MSI (s) (88:58) [22:57:55:671]: Note: target paths subject to change (via custom actions or browsing)
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: TARGETDIR , Object: d:\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: WindowsFolder , Object: C:\WINDOWS\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: CommonFilesFolder , Object: C:\Arquivos de programas\Arquivos comuns\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\MSDN\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\system32\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\Manifests\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\Policies\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa6920e9f98fc\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\system32\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\Policies\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\Manifests\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\system32\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\Policies\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\Manifests\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: C:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB , Object: C:\WINDOWS\system32\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 , Object: C:\WINDOWS\system32\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 , Object: C:\WINDOWS\system32\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: DesktopFolder , Object: C:\Documents and Settings\All Users\Desktop\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: ProgramFilesFolder , Object: C:\Arquivos de programas\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: MSXML , Object: C:\Arquivos de programas\MSXML 4.0\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: INC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: C:\Arquivos de programas\MSXML 4.0\inc\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: LIB.4576A2F1_959E_4BCA_94A9_596523761901 , Object: C:\Arquivos de programas\MSXML 4.0\lib\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: DOC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: C:\Arquivos de programas\MSXML 4.0\doc\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: C:\Documents and Settings\All Users\Menu Iniciar\Programas\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 , Object: C:\Documents and Settings\All Users\Menu Iniciar\Programas\MSXML 4.0\
MSI (s) (88:58) [22:57:55:671]: Dir (target): Key: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: C:\Documents and Settings\All Users\Desktop\
Action start 22:57:55: CostFinalize.
MSI (s) (88:58) [22:57:55:671]: Doing action: SetODBCFolders
Action ended 22:57:55: CostFinalize. Return value 1.
MSI (s) (88:58) [22:57:55:671]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (88:58) [22:57:55:671]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `ComponentId`,`Description`,`Directory_`, `ActionRequest`, `Installed`, `Attributes` FROM `ODBCDriver`, `Component` WHERE `ODBCDriver`.`Component_` = `Component` AND (`ActionRequest` = 1 OR `ActionRequest` = 2)
MSI (s) (88:58) [22:57:55:671]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (88:58) [22:57:55:671]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `ComponentId`,`Description`,`Directory_`, `ActionRequest`, `Installed`, `Attributes` FROM `ODBCTranslator`, `Component` WHERE `ODBCTranslator`.`Component_` = `Component` AND (`ActionRequest` = 1 OR `ActionRequest` = 2)
Action start 22:57:55: SetODBCFolders.
MSI (s) (88:58) [22:57:55:671]: Doing action: MigrateFeatureStates
Action ended 22:57:55: SetODBCFolders. Return value 0.
MSI (s) (88:58) [22:57:55:671]: Skipping MigrateFeatureStates action: not run in maintenance mode
Action start 22:57:55: MigrateFeatureStates.
MSI (s) (88:58) [22:57:55:687]: Doing action: InstallValidate
Action ended 22:57:55: MigrateFeatureStates. Return value 0.
MSI (s) (88:58) [22:57:55:687]: Feature: MSXML; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Feature: MSXMLSYS; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Feature: MSXMLSUPP; Installed: Absent; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Feature: MSXMLSUPP2; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Feature: MSXMLSXS; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Feature: XMLSDK; Installed: Absent; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: RememberInstallFolder; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: QKBKEY; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: MSXML4_System.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: MSXML4_SystemRes.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: MSXML4_ANSI.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: WINHTTP50_COMPONENT.781A0624_31FF_4712_BFFD_31C829FFDBF1; Installed: Absent; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: PROXYCFG_COMPONENT.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: uplevel.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: downlevel_manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: downlevel_payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: uplevel.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: downlevel_manifest.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: downlevel_payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: uplevel.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: downlevel_manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537; Installed: Local; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: XMLSDK_Docs.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: XMLSDK_LIB.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: XMLSDK_INC.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: CookDoc_dll.3FB7DAB3_19E7_40A0_8730_4482CE77AC59; Installed: Absent; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: __uplevel.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF365; Installed: Null; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: __uplevel.DA6654F6_456F_3658_FF6B_D6B9ABF365; Installed: Null; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: __uplevel.0E9F98FC_A692_A6DF_FF6B_D6B9ABF365; Installed: Null; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: __QKBKEY65; Installed: Null; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: __MSXML4_System.246EB7AD_459A_4FA8_83D1_4165; Installed: Null; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: __downlevel_payload.7B2FCEFF_0F22_B7E1_FF665; Installed: Null; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: __downlevel_manifest.7B2FCEFF_0F22_B7E1_FF65; Installed: Null; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: __downlevel_payload.DA6654F6_456F_3658_FF665; Installed: Null; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: __downlevel_manifest.DA6654F6_456F_3658_FF65; Installed: Null; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: __downlevel_manifest.0E9F98FC_A692_A6DF_FF65; Installed: Null; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: __CookDoc_dll.3FB7DAB3_19E7_40A0_8730_448265; Installed: Null; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Component: __XMLSDK_Docs.4576A2F1_959E_4BCA_94A9_596565; Installed: Null; Request: Null; Action: Null
MSI (s) (88:58) [22:57:55:687]: Note: 1: 2205 2: 3: BindImage
MSI (s) (88:58) [22:57:55:687]: Note: 1: 2262 2: PublishComponent 3: -2147287038
MSI (s) (88:58) [22:57:55:687]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (88:58) [22:57:55:687]: Note: 1: 2205 2: 3: Font
Action start 22:57:55: InstallValidate.
MSI (s) (88:58) [22:57:55:687]: PROPERTY CHANGE: Modifying CostingComplete property. Its current value is '0'. Its new value: '1'.
MSI (s) (88:58) [22:57:55:687]: Note: 1: 2205 2: 3: BindImage
MSI (s) (88:58) [22:57:55:687]: Note: 1: 2262 2: PublishComponent 3: -2147287038
MSI (s) (88:58) [22:57:55:687]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (88:58) [22:57:55:687]: Note: 1: 2205 2: 3: Font
MSI (s) (88:58) [22:57:55:687]: Note: 1: 2727 2:
MSI (s) (88:58) [22:57:55:687]: Note: 1: 2727 2:
MSI (s) (88:58) [22:57:55:687]: Doing action: InstallInitialize
Action ended 22:57:55: InstallValidate. Return value 1.
MSI (s) (88:58) [22:57:55:687]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (88:58) [22:57:55:687]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (88:58) [22:57:55:687]: BeginTransaction: Locking Server
MSI (s) (88:58) [22:57:55:687]: SRSetRestorePoint skipped for this transaction.
MSI (s) (88:58) [22:57:55:687]: Server not locked: locking for product {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
Action start 22:57:55: InstallInitialize.
MSI (s) (88:58) [22:57:55:765]: Doing action: SxsInstallCA
Action ended 22:57:55: InstallInitialize. Return value 1.
MSI (s) (88:48) [22:57:55:765]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI95.tmp, Entrypoint: CustomAction_SxsMsmInstall
MSI (s) (88:98) [22:57:55:765]: Generating random cookie.
MSI (s) (88:98) [22:57:55:781]: Created Custom Action Server with PID 3076 (0xC04).
MSI (s) (88:C8) [22:57:55:828]: Running as a service.
MSI (s) (88:3C) [22:57:55:843]: Hello, I'm your 32bit Elevated custom action server.
Action start 22:57:55: SxsInstallCA.
1: sxsdelca 2: traceop 3: 1256 4: 0
1: sxsdelca 2: traceop 3: 1257 4: 0
1: sxsdelca 2: traceop 3: 1258 4: 0
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 1318 4: 0
1: sxsdelca: Skipping component 2: downlevel_manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 1318 4: 0
1: sxsdelca: Skipping component 2: downlevel_payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 1318 4: 0
1: sxsdelca: Skipping component 2: downlevel_manifest.DA6654F6_456F_3658_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 1318 4: 0
1: sxsdelca: Skipping component 2: downlevel_payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 1318 4: 0
1: sxsdelca: Skipping component 2: downlevel_manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 259
1: sxsdelca 2: SxsMsmInstall completed 3: 0 4: 0
MSI (s) (88:58) [22:57:56:140]: Skipping action: AllocateRegistrySpace (condition is false)
MSI (s) (88:58) [22:57:56:140]: Doing action: ProcessComponents
Action ended 22:57:56: SxsInstallCA. Return value 1.
Action start 22:57:56: ProcessComponents.
MSI (s) (88:58) [22:57:56:140]: Doing action: UnpublishComponents
Action ended 22:57:56: ProcessComponents. Return value 1.
MSI (s) (88:58) [22:57:56:156]: Note: 1: 2262 2: PublishComponent 3: -2147287038
Action start 22:57:56: UnpublishComponents.
MSI (s) (88:58) [22:57:56:156]: Doing action: MsiUnpublishAssemblies
Action ended 22:57:56: UnpublishComponents. Return value 1.
Action start 22:57:56: MsiUnpublishAssemblies.
MSI (s) (88:58) [22:57:56:156]: Doing action: UnpublishFeatures
Action ended 22:57:56: MsiUnpublishAssemblies. Return value 1.
Action start 22:57:56: UnpublishFeatures.
MSI (s) (88:58) [22:57:56:171]: Doing action: StopServices
Action ended 22:57:56: UnpublishFeatures. Return value 1.
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2205 2: 3: ServiceControl
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2228 2: 3: ServiceControl 4: SELECT `Name`,`Wait`,`Arguments`,`Event`, `Action` FROM `ServiceControl`, `Component` WHERE `Component_` = `Component` AND (`Action` = 0 OR `Action` = 1 OR `Action` = 2)
Action start 22:57:56: StopServices.
MSI (s) (88:58) [22:57:56:171]: Doing action: DeleteServices
Action ended 22:57:56: StopServices. Return value 1.
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2205 2: 3: ServiceControl
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2228 2: 3: ServiceControl 4: SELECT `Name`,`Wait`,`Arguments`,`Event`, `Action` FROM `ServiceControl`, `Component` WHERE `Component_` = `Component` AND (`Action` = 0 OR `Action` = 1 OR `Action` = 2)
Action start 22:57:56: DeleteServices.
MSI (s) (88:58) [22:57:56:171]: Doing action: UnregisterComPlus
Action ended 22:57:56: DeleteServices. Return value 1.
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2205 2: 3: Complus
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2228 2: 3: Complus 4: SELECT `ComponentId`, `FileName`, `Component`.`Directory_`, `ExpType`, `Component`.`Action`, `Component`.`Installed` FROM `Complus`, `Component`, `File` WHERE `Complus`.`Component_` = `Component` AND `Component`.`KeyPath` = `File`.`File` AND `Action` = 0
Action start 22:57:56: UnregisterComPlus.
MSI (s) (88:58) [22:57:56:171]: Doing action: SelfUnregModules
Action ended 22:57:56: UnregisterComPlus. Return value 0.
Action start 22:57:56: SelfUnregModules.
MSI (s) (88:58) [22:57:56:171]: Doing action: UnregisterTypeLibraries
Action ended 22:57:56: SelfUnregModules. Return value 1.
Action start 22:57:56: UnregisterTypeLibraries.
MSI (s) (88:58) [22:57:56:171]: Doing action: RemoveODBC
Action ended 22:57:56: UnregisterTypeLibraries. Return value 1.
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND `Component`.`Action` = 0 AND `BinaryType` = ?
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND `Component`.`Action` = 0 AND `BinaryType` = ?
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCTranslator`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCTranslator`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCDriver`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCDriver`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2711 2: ODBCDriverManager
Action start 22:57:56: RemoveODBC.
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2711 2: ODBCDriverManager64
MSI (s) (88:58) [22:57:56:171]: Doing action: UnregisterFonts
Action ended 22:57:56: RemoveODBC. Return value 1.
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2205 2: 3: Font
MSI (s) (88:58) [22:57:56:171]: Note: 1: 2228 2: 3: Font 4: SELECT `FontTitle`, `FileName`, `Directory_`, `Installed`From `Font`, `FileAction` Where `Font`.`File_` = `FileAction`.`File` And `FileAction`.`Action` = 0 ORDER BY `FileAction`.`Directory_`
Action start 22:57:56: UnregisterFonts.
MSI (s) (88:58) [22:57:56:187]: Doing action: RemoveRegistryValues
Action ended 22:57:56: UnregisterFonts. Return value 1.
Action start 22:57:56: RemoveRegistryValues.
MSI (s) (88:58) [22:57:56:187]: Doing action: UnregisterClassInfo
Action ended 22:57:56: RemoveRegistryValues. Return value 1.
Action start 22:57:56: UnregisterClassInfo.
MSI (s) (88:58) [22:57:56:187]: Doing action: UnregisterExtensionInfo
Action ended 22:57:56: UnregisterClassInfo. Return value 1.
MSI (s) (88:58) [22:57:56:187]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:57:56: UnregisterExtensionInfo.
MSI (s) (88:58) [22:57:56:187]: Doing action: UnregisterProgIdInfo
Action ended 22:57:56: UnregisterExtensionInfo. Return value 1.
MSI (s) (88:58) [22:57:56:187]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:57:56: UnregisterProgIdInfo.
MSI (s) (88:58) [22:57:56:187]: Doing action: UnregisterMIMEInfo
Action ended 22:57:56: UnregisterProgIdInfo. Return value 1.
MSI (s) (88:58) [22:57:56:187]: Note: 1: 2262 2: MIME 3: -2147287038
MSI (s) (88:58) [22:57:56:187]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:57:56: UnregisterMIMEInfo.
MSI (s) (88:58) [22:57:56:187]: Doing action: RemoveIniValues
Action ended 22:57:56: UnregisterMIMEInfo. Return value 1.
MSI (s) (88:58) [22:57:56:187]: Note: 1: 2205 2: 3: IniFile
MSI (s) (88:58) [22:57:56:187]: Note: 1: 2228 2: 3: IniFile 4: SELECT `FileName`,`IniFile`.`DirProperty`,`Section`,`IniFile`.`Key`,`IniFile`.`Value`,`IniFile`.`Action` FROM `IniFile`, `Component` WHERE `Component`=`Component_` AND `Component`.`Action`=0 ORDER BY `FileName`,`Section`
Action start 22:57:56: RemoveIniValues.
MSI (s) (88:58) [22:57:56:187]: Doing action: RemoveShortcuts
Action ended 22:57:56: RemoveIniValues. Return value 1.
Action start 22:57:56: RemoveShortcuts.
MSI (s) (88:58) [22:57:56:187]: Doing action: RemoveEnvironmentStrings
Action ended 22:57:56: RemoveShortcuts. Return value 1.
MSI (s) (88:58) [22:57:56:187]: Note: 1: 2205 2: 3: Environment
MSI (s) (88:58) [22:57:56:187]: Note: 1: 2228 2: 3: Environment 4: SELECT `Name`,`Value` FROM `Environment`,`Component` WHERE `Component_`=`Component` AND (`Component`.`Action` = 0)
Action start 22:57:56: RemoveEnvironmentStrings.
MSI (s) (88:58) [22:57:56:187]: Doing action: RemoveDuplicateFiles
Action ended 22:57:56: RemoveEnvironmentStrings. Return value 1.
Action start 22:57:56: RemoveDuplicateFiles.
MSI (s) (88:58) [22:57:56:203]: Doing action: RemoveFiles
Action ended 22:57:56: RemoveDuplicateFiles. Return value 1.
MSI (s) (88:58) [22:57:56:203]: Note: 1: 2205 2: 3: RemoveFile
MSI (s) (88:58) [22:57:56:203]: Note: 1: 2205 2: 3: RemoveFile
Action start 22:57:56: RemoveFiles.
MSI (s) (88:58) [22:57:56:203]: Doing action: RemoveFolders
Action ended 22:57:56: RemoveFiles. Return value 0.
Action start 22:57:56: RemoveFolders.
MSI (s) (88:58) [22:57:56:203]: Doing action: CreateFolders
Action ended 22:57:56: RemoveFolders. Return value 1.
Action start 22:57:56: CreateFolders.
MSI (s) (88:58) [22:57:56:203]: Doing action: MoveFiles
Action ended 22:57:56: CreateFolders. Return value 1.
Action start 22:57:56: MoveFiles.
MSI (s) (88:58) [22:57:56:203]: Doing action: InstallFiles
Action ended 22:57:56: MoveFiles. Return value 1.
MSI (s) (88:58) [22:57:56:203]: Note: 1: 2205 2: 3: Patch
MSI (s) (88:58) [22:57:56:203]: Note: 1: 2228 2: 3: Patch 4: SELECT `Patch`.`File_`, `Patch`.`Header`, `Patch`.`Attributes`, `Patch`.`Sequence`, `Patch`.`StreamRef_` FROM `Patch` WHERE `Patch`.`File_` = ? AND `Patch`.`#_MsiActive`=? ORDER BY `Patch`.`Sequence`
MSI (s) (88:58) [22:57:56:203]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (88:58) [22:57:56:203]: Note: 1: 2228 2: 3: MsiPatchHeaders 4: SELECT `Header` FROM `MsiPatchHeaders` WHERE `StreamRef` = ?
Action start 22:57:56: InstallFiles.
MSI (s) (88:58) [22:57:56:203]: Doing action: PatchFiles
Action ended 22:57:56: InstallFiles. Return value 1.
MSI (s) (88:58) [22:57:56:203]: Note: 1: 2205 2: 3: Patch
MSI (s) (88:58) [22:57:56:203]: Note: 1: 2228 2: 3: Patch 4: SELECT `File`,`FileName`,`FileSize`,`Directory_`,`PatchSize`,`File`.`Attributes`,`Patch`.`Attributes`,`Patch`.`Sequence`,`Component`.`Component`,`Component`.`ComponentId` FROM `File`,`Component`,`Patch` WHERE `Patch`.`#_MsiActive`=? AND `File`=`File_` AND `Component`=`Component_` ORDER BY `Patch`.`Sequence`
Action start 22:57:56: PatchFiles.
MSI (s) (88:58) [22:57:56:203]: Doing action: DuplicateFiles
Action ended 22:57:56: PatchFiles. Return value 0.
Action start 22:57:56: DuplicateFiles.
MSI (s) (88:58) [22:57:56:203]: Doing action: BindImage
Action ended 22:57:56: DuplicateFiles. Return value 1.
Action start 22:57:56: BindImage.
MSI (s) (88:58) [22:57:56:203]: Doing action: CreateShortcuts
Action ended 22:57:56: BindImage. Return value 1.
Action start 22:57:56: CreateShortcuts.
MSI (s) (88:58) [22:57:56:218]: Doing action: RegisterClassInfo
Action ended 22:57:56: CreateShortcuts. Return value 1.
Action start 22:57:56: RegisterClassInfo.
MSI (s) (88:58) [22:57:56:218]: Doing action: RegisterExtensionInfo
Action ended 22:57:56: RegisterClassInfo. Return value 1.
MSI (s) (88:58) [22:57:56:218]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:57:56: RegisterExtensionInfo.
MSI (s) (88:58) [22:57:56:218]: Doing action: RegisterProgIdInfo
Action ended 22:57:56: RegisterExtensionInfo. Return value 1.
MSI (s) (88:58) [22:57:56:218]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:57:56: RegisterProgIdInfo.
MSI (s) (88:58) [22:57:56:218]: Doing action: RegisterMIMEInfo
Action ended 22:57:56: RegisterProgIdInfo. Return value 1.
MSI (s) (88:58) [22:57:56:218]: Note: 1: 2262 2: MIME 3: -2147287038
MSI (s) (88:58) [22:57:56:218]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:57:56: RegisterMIMEInfo.
MSI (s) (88:58) [22:57:56:218]: Doing action: WriteRegistryValues
Action ended 22:57:56: RegisterMIMEInfo. Return value 1.
Action start 22:57:56: WriteRegistryValues.
MSI (s) (88:58) [22:57:56:218]: Doing action: WriteIniValues
Action ended 22:57:56: WriteRegistryValues. Return value 1.
MSI (s) (88:58) [22:57:56:218]: Note: 1: 2205 2: 3: IniFile
MSI (s) (88:58) [22:57:56:218]: Note: 1: 2228 2: 3: IniFile 4: SELECT `FileName`,`IniFile`.`DirProperty`,`Section`,`IniFile`.`Key`,`IniFile`.`Value`,`IniFile`.`Action` FROM `IniFile`, `Component` WHERE `Component`=`Component_` AND (`Component`.`Action`=1 OR `Component`.`Action`=2) ORDER BY `FileName`,`Section`
Action start 22:57:56: WriteIniValues.
MSI (s) (88:58) [22:57:56:218]: Doing action: WriteEnvironmentStrings
Action ended 22:57:56: WriteIniValues. Return value 1.
MSI (s) (88:58) [22:57:56:218]: Note: 1: 2205 2: 3: Environment
MSI (s) (88:58) [22:57:56:218]: Note: 1: 2228 2: 3: Environment 4: SELECT `Name`,`Value` FROM `Environment`,`Component` WHERE `Component_`=`Component` AND (`Component`.`Action` = 1 OR `Component`.`Action` = 2)
Action start 22:57:56: WriteEnvironmentStrings.
MSI (s) (88:58) [22:57:56:218]: Doing action: RegisterFonts
Action ended 22:57:56: WriteEnvironmentStrings. Return value 1.
MSI (s) (88:58) [22:57:56:218]: Note: 1: 2205 2: 3: Font
MSI (s) (88:58) [22:57:56:218]: Note: 1: 2228 2: 3: Font 4: SELECT `FontTitle`, `FileName`, `Directory_`, `Action` From `Font`, `FileAction` Where `Font`.`File_` = `FileAction`.`File` And (`FileAction`.`Action` = 1 Or `FileAction`.`Action` = 2) ORDER BY `FileAction`.`Directory_`
Action start 22:57:56: RegisterFonts.
MSI (s) (88:58) [22:57:56:234]: Doing action: InstallODBC
Action ended 22:57:56: RegisterFonts. Return value 1.
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2711 2: ODBCDriverManager
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2711 2: ODBCDriverManager64
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCDriver`, `File`, `Component` WHERE `File_` = `File` AND `ODBCDriver`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCDriver`, `File`, `Component` WHERE `File_` = `File` AND `ODBCDriver`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCTranslator`, `File`, `Component` WHERE `File_` = `File` AND `ODBCTranslator`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCTranslator`, `File`, `Component` WHERE `File_` = `File` AND `ODBCTranslator`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND (`Component`.`Action` = 1 OR `Component`.`Action` = 2) AND `BinaryType` = ?
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND (`Component`.`Action` = 1 OR `Component`.`Action` = 2) AND `BinaryType` = ?
Action start 22:57:56: InstallODBC.
MSI (s) (88:58) [22:57:56:234]: Doing action: RegisterTypeLibraries
Action ended 22:57:56: InstallODBC. Return value 0.
Action start 22:57:56: RegisterTypeLibraries.
MSI (s) (88:58) [22:57:56:234]: Doing action: SelfRegModules
Action ended 22:57:56: RegisterTypeLibraries. Return value 1.
Action start 22:57:56: SelfRegModules.
MSI (s) (88:58) [22:57:56:234]: Doing action: RegisterComPlus
Action ended 22:57:56: SelfRegModules. Return value 1.
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2205 2: 3: Complus
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2228 2: 3: Complus 4: SELECT `ComponentId`, `FileName`, `Component`.`Directory_`, `ExpType`, `Component`.`Action`, `Component`.`Installed` FROM `Complus`, `Component`, `File` WHERE `Complus`.`Component_` = `Component` AND `Component`.`KeyPath` = `File`.`File` AND (`Action` = 1 OR `Action` = 2)
Action start 22:57:56: RegisterComPlus.
MSI (s) (88:58) [22:57:56:234]: Doing action: InstallServices
Action ended 22:57:56: RegisterComPlus. Return value 0.
MSI (s) (88:58) [22:57:56:234]: Detected older ServiceInstall table schema
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2205 2: 3: ServiceInstall
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2228 2: 3: ServiceInstall 4: SELECT `Name`,`DisplayName`,`ServiceType`,`StartType`,`ErrorControl`,`LoadOrderGroup`,`Dependencies`,`StartName`,`Password`,`ComponentId`,`Directory_`,`FileName`,`Arguments` FROM `ServiceInstall`, `Component`, `File` WHERE `ServiceInstall`.`Component_` = `Component`.`Component` AND (`Component`.`KeyPath` = `File`.`File`) AND (`Action` = 1 OR `Action` = 2)
Action start 22:57:56: InstallServices.
MSI (s) (88:58) [22:57:56:234]: Doing action: StartServices
Action ended 22:57:56: InstallServices. Return value 1.
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2205 2: 3: ServiceControl
MSI (s) (88:58) [22:57:56:234]: Note: 1: 2228 2: 3: ServiceControl 4: SELECT `Name`,`Wait`,`Arguments`,`Event`, `Action` FROM `ServiceControl`, `Component` WHERE `Component_` = `Component` AND (`Action` = 0 OR `Action` = 1 OR `Action` = 2)
Action start 22:57:56: StartServices.
MSI (s) (88:58) [22:57:56:234]: Doing action: RegisterUser
Action ended 22:57:56: StartServices. Return value 1.
Action start 22:57:56: RegisterUser.
MSI (s) (88:58) [22:57:56:234]: Doing action: RegisterProduct
Action ended 22:57:56: RegisterUser. Return value 0.
Action start 22:57:56: RegisterProduct.
MSI (s) (88:58) [22:57:56:234]: Doing action: PublishComponents
Action ended 22:57:56: RegisterProduct. Return value 1.
MSI (s) (88:58) [22:57:56:250]: Note: 1: 2262 2: PublishComponent 3: -2147287038
Action start 22:57:56: PublishComponents.
MSI (s) (88:58) [22:57:56:250]: Doing action: MsiPublishAssemblies
Action ended 22:57:56: PublishComponents. Return value 1.
Action start 22:57:56: MsiPublishAssemblies.
MSI (s) (88:58) [22:57:56:250]: Doing action: PublishFeatures
Action ended 22:57:56: MsiPublishAssemblies. Return value 1.
Action start 22:57:56: PublishFeatures.
MSI (s) (88:58) [22:57:56:250]: Doing action: PublishProduct
Action ended 22:57:56: PublishFeatures. Return value 1.
Action start 22:57:56: PublishProduct.
MSI (s) (88:58) [22:57:56:250]: Resolving source.
MSI (s) (88:58) [22:57:56:250]: Resolving source to launched-from source.
MSI (s) (88:58) [22:57:56:250]: Setting launched-from source as last-used.
MSI (s) (88:58) [22:57:56:250]: PROPERTY CHANGE: Adding SourceDir property. Its value is 'd:\64e9d6f09c56f8c573aedda6df\'.
MSI (s) (88:58) [22:57:56:250]: PROPERTY CHANGE: Adding SOURCEDIR property. Its value is 'd:\64e9d6f09c56f8c573aedda6df\'.
MSI (s) (88:58) [22:57:56:250]: PROPERTY CHANGE: Adding SourcedirProduct property. Its value is '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (88:58) [22:57:56:250]: SOURCEDIR ==> d:\64e9d6f09c56f8c573aedda6df\
MSI (s) (88:58) [22:57:56:250]: SOURCEDIR product ==> {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSI (s) (88:58) [22:57:56:250]: Determining source type
MSI (s) (88:58) [22:57:56:250]: Source type from package 'msxml.msi': 2
MSI (s) (88:58) [22:57:56:250]: Source path resolution complete. Dumping Directory table...
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: TARGETDIR , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: WindowsFolder , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: CommonFilesFolder , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Microsoft Shared\ , ShortSubPath: MICROS~1\
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Microsoft Shared\MSDN\ , ShortSubPath: MICROS~1\MSDN\
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\system32\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\k0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\h0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\Manifests\ , ShortSubPath: Windows\winsxs\manifest\
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\Policies\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\Policies\i0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\j0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\system32\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\8n0mtfut.k85\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\Policies\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\Policies\6n0mtfut.k85\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\Manifests\ , ShortSubPath: Windows\winsxs\manifest\
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\5n0mtfut.k85\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\7n0mtfut.k85\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\system32\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\wl34x2va.rt8\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\Policies\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\Policies\ul34x2va.rt8\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\Manifests\ , ShortSubPath: Windows\winsxs\manifest\
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\tl34x2va.rt8\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: Windows\winsxs\vl34x2va.rt8\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: System\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: DesktopFolder , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: ProgramFilesFolder , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: MSXML , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: redist\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: INC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: redist\inc\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: LIB.4576A2F1_959E_4BCA_94A9_596523761901 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: redist\lib\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: DOC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: redist\doc\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: redist\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: redist\MSXML 4.0\ , ShortSubPath: redist\MSXML4\
MSI (s) (88:58) [22:57:56:250]: Dir (source): Key: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: d:\64e9d6f09c56f8c573aedda6df\ , LongSubPath: redist\ , ShortSubPath:
MSI (s) (88:58) [22:57:56:250]: Doing action: InstallFinalize
Action ended 22:57:56: PublishProduct. Return value 1.
MSI (s) (88:58) [22:57:56:250]: Running Script: C:\WINDOWS\Installer\MSI96.tmp
MSI (s) (88:58) [22:57:56:250]: PROPERTY CHANGE: Adding UpdateStarted property. Its value is '1'.
MSI (s) (88:58) [22:57:56:250]: Machine policy value 'DisableRollback' is 0
MSI (s) (88:58) [22:57:56:281]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (88:58) [22:57:56:281]: Executing op: Header(Signature=1397708873,Version=300,Timestamp=910997309,LangId=1033,Platform=0,ScriptType=1,ScriptMajorVersion=21,ScriptMinorVersion=4,ScriptAttributes=1)
Action start 22:57:56: InstallFinalize.
MSI (s) (88:58) [22:57:56:281]: Executing op: ProductInfo(ProductKey={37477865-A3F1-4772-AD43-AAFC6BCFF99F},ProductName=MSXML 4.0 SP2 (KB927978),PackageName=msxml.msi,Language=1033,Version=68429425,Assignment=1,ObsoleteArg=0,,,PackageCode={2B27DCD9-53FA-4885-B6CD-698623819F4C},,,InstanceType=0,LUASetting=0)
MSI (s) (88:58) [22:57:56:296]: Executing op: DialogInfo(Type=0,Argument=1033)
MSI (s) (88:58) [22:57:56:296]: Executing op: DialogInfo(Type=1,Argument=MSXML 4.0 SP2 (KB927978))
MSI (s) (88:58) [22:57:56:296]: Executing op: RollbackInfo(,RollbackAction=Rollback,RollbackDescription=Rolling back action:,RollbackTemplate=[1],CleanupAction=RollbackCleanup,CleanupDescription=Removing backup files,CleanupTemplate=File: [1])
MSI (s) (88:58) [22:57:56:296]: Executing op: SetBaseline(Baseline=0,)
MSI (s) (88:58) [22:57:56:296]: Executing op: SetBaseline(Baseline=1,)
MSI (s) (88:58) [22:57:56:296]: Executing op: ActionStart(Name=RemoveODBC,Description=Removing ODBC components,)
MSI (s) (88:58) [22:57:56:296]: Executing op: ODBCDriverManager(,BinaryType=0)
MSI (s) (88:58) [22:57:56:296]: Executing op: ODBCDriverManager(,BinaryType=1)
MSI (s) (88:58) [22:57:56:296]: Executing op: ActionStart(Name=InstallFiles,Description=Copying new files,Template=File: [1], Directory: [9], Size: [6])
MSI (s) (88:58) [22:57:56:296]: Executing op: InstallProtectedFiles(AllowUI=0)
MSI (s) (88:58) [22:57:56:296]: Executing op: ActionStart(Name=RegisterProduct,Description=Registering product,Template=[1])
MSI (s) (88:58) [22:57:56:296]: Executing op: UpdateEstimatedSize(EstimatedSize=-20)
MSI (s) (88:58) [22:57:56:296]: Executing op: ProductCPDisplayInfoRegister()
MSI (s) (88:58) [22:57:56:296]: Executing op: ActionStart(Name=PublishProduct,Description=Publishing product information,)
MSI (s) (88:58) [22:57:56:296]: Executing op: CleanupConfigData()
MSI (s) (88:58) [22:57:56:296]: Executing op: RegisterPatchOrder(Continue=0,SequenceType=1,Remove=0)
MSI (s) (88:58) [22:57:56:296]: Executing op: SourceListRegisterLastUsed(SourceProduct={37477865-A3F1-4772-AD43-AAFC6BCFF99F},LastUsedSource=d:\64e9d6f09c56f8c573aedda6df\)
MSI (s) (88:58) [22:57:56:296]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (88:58) [22:57:56:296]: Specifed source is not already in a list.
MSI (s) (88:58) [22:57:56:296]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (88:58) [22:57:56:296]: Adding new sources is allowed.
MSI (s) (88:58) [22:57:56:296]: Added new source 'd:\64e9d6f09c56f8c573aedda6df\' with index '17'
MSI (s) (88:58) [22:57:56:296]: Set LastUsedSource to: d:\64e9d6f09c56f8c573aedda6df\.
MSI (s) (88:58) [22:57:56:296]: Set LastUsedType to: n.
MSI (s) (88:58) [22:57:56:296]: Set LastUsedIndex to: 17.
MSI (s) (88:58) [22:57:56:296]: Executing op: End(Checksum=0,ProgressTotal=0)
MSI (s) (88:58) [22:57:56:296]: User policy value 'DisableRollback' is 0
MSI (s) (88:58) [22:57:56:296]: Machine policy value 'DisableRollback' is 0
MSI (s) (88:58) [22:57:56:328]: No System Restore sequence number for this installation.
MSI (s) (88:58) [22:57:56:328]: Unlocking Server
MSI (s) (88:58) [22:57:56:328]: PROPERTY CHANGE: Deleting UpdateStarted property. Its current value is '1'.
MSI (s) (88:58) [22:57:56:328]: Doing action: SxsUninstallCA
Action ended 22:57:56: InstallFinalize. Return value 1.
MSI (s) (88:B8) [22:57:56:328]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI99.tmp, Entrypoint: CustomAction_SxsMsmCleanup
Action start 22:57:56: SxsUninstallCA.
1: sxsdelca tried opening key w/o wow64key 2: Software\Microsoft\Windows\CurrentVersion\SideBySide\PatchedComponents 3: 368 4: 0
1: sxsdelca tried opening wow64key 2: Software\Microsoft\Windows\CurrentVersion\SideBySide\PatchedComponents 3: 388 4: 0
1: sxsdelca 2: traceop 3: 1158 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {9BFEE365-EA45-10B3-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {9BFEE365-EA45-10B3-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {98CB24AD-52FB-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {98CB24AD-52FB-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {98CB1B80-5997-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {98CB1B80-5997-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {98CB1712-5C31-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {98CB16C1-5C55-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {98CB1763-5C0D-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {98CB16C1-5C55-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {98CB1712-5C31-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {98CB17B4-5BE9-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {98CB1763-5C0D-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {98CB1805-5BC5-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {5546CDB5-2CE2-498B-B059-5B3BF81FC41F} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {F4C2E5F5-2970-45f4-ABD3-C180C4D961C4} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {00000416-78E1-11D2-B60F-006097C998E7} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {350C9416-3D7C-4EE8-BAA9-00BCB3D54227} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {B996AE66-10DB-4ac5-B151-E8B4BFBC42FC} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {AC76BA86-7AD7-1046-7B44-A80000000000} 3: {98CB1856-5BA1-DB5F-C01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: 3
1: sxsdelca 2: traceop 3: 1193 4: 0
1: sxsdelca 2: traceop 3: 1186 4: 0
1: sxsdelca 2: traceop 3: 732 4: 0
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {505AFDC0-5E72-4928-8368-5DEA385E3647} 3: {98CB17B4-5BE9-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {6882DD11-33B8-4DEA-8305-7E765BF74BD3} 3: {98CB17B4-5BE9-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {0837A661-FEC3-48B3-876C-91E7D32048A9} 3: {98CB17B4-5BE9-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {4C24A8C1-7CFA-4650-AF15-732F5BD7B46D} 3: {98CB17B4-5BE9-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {1F33AB52-B196-1BFC-6790-70C08A731046} 3: {98CB17B4-5BE9-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {30C19FF2-7FBA-4d09-B9DE-1659977F64F6} 3: {98CB17B4-5BE9-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {E3F90083-80D4-4b5a-87C7-E97E12F5516D} 3: {98CB17B4-5BE9-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {56F8AFC3-FA98-4ff1-9673-8A026CBF85BE} 3: {98CB17B4-5BE9-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {EA103B64-C0E4-4C0E-A506-751590E1653D} 3: {98CB17B4-5BE9-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {15EE79F4-4ED1-4267-9B0F-351009325D7D} 3: {98CB17B4-5BE9-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 3: {98CB17B4-5BE9-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0
1: scavenge 2: {531317A5-586A-4E36-87C1-CA823447B375} 3: {98CB17B4-5BE9-DB5F-B01F-C8B3B9A1E18E} 4: {37477865-A3F1-4772-AD43-AAFC6BCFF99F} 5: -1
1: sxsdelca 2: traceop 3: 748 4: 0




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users