also @ TechSpot: Intel says Haswell will improve battery life by 50 percent

Malware problem maybe more?

Discussion in 'Virus and Malware Removal' started by billyd, May 13, 2012.

Post New Reply
  1. billyd Newcomer, in training Posts: 60

    will do
    thanks for your help its been a fun learning process :)
  2. Broni Malware Annihilator Posts: 39,412   +177

    You're very welcome [IMG]
  3. billyd Newcomer, in training Posts: 60

    ok may havee been a fluke because laptops been running great but had a crash today ?

    ==================================================
    Dump File : Mini060812-01.dmp
    Crash Time : 6/8/2012 5:18:37 PM
    Bug Check String : MEMORY_MANAGEMENT
    Bug Check Code : 0x0000001a
    Parameter 1 : 0x00004000
    Parameter 2 : 0x86c212c0
    Parameter 3 : 0x80000000
    Parameter 4 : 0x0023dfed
    Caused By Driver : win32k.sys
    Caused By Address : win32k.sys+be38a
    File Description : Multi-User Win32 Driver
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+cdabf
    Stack Address 1 : ntkrnlpa.exe+b674e
    Stack Address 2 : ntkrnlpa.exe+85573
    Stack Address 3 : ntkrnlpa.exe+4ac3a
    Computer Name :
    Full Path : C:\Windows\Minidump\Mini060812-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 6002
    Dump File Size : 139,176
    ==================================================
  4. Broni Malware Annihilator Posts: 39,412   +177

    One BSOD is usually meaningless. It happens.
  5. billyd Newcomer, in training Posts: 60

    Ok having a new problem should I start a new thread or continue here?

    getting this pop up over and over again when starting IE9 internet explorer "

    "Microsoft Windows Search Protocol Host has stopped working" popping up every 10 seconds
  6. billyd Newcomer, in training Posts: 60

     
  7. Broni Malware Annihilator Posts: 39,412   +177

  8. billyd Newcomer, in training Posts: 60

    Ok I should also say the "search protocol host stopped working" pop up happens right after boot up ! IE9 starts up but when I go to a sight it acts like its there but the screen is blank !

    now by ALL the steps you mean run the fix it and reset internet explorer and also click the delete personal settings? if so I did this but no luck still have the problem !

    thanks bill
  9. billyd Newcomer, in training Posts: 60

    I just noticed the windows spider sol and windows freecell sol are coming up blank screen also :S
  10. Broni Malware Annihilator Posts: 39,412   +177

    In this forum, we make sure, your computer is free of malware and your computer is clean :)
    Because the access to malware forum is very limited, your best option is to create new topic about your current issue, at Windows section.
    You'll get more attention.

    Good luck :)
    billyd likes this.
  11. billyd Newcomer, in training Posts: 60

    Ok thanks !
  12. Broni Malware Annihilator Posts: 39,412   +177

  13. billyd Newcomer, in training Posts: 60

    Hi just wanted to let you know because no one was replying in the other thread!

    I ran sfc scannow followed by combofix ! seems to have fixed the problem still haven't tried everything though !

    I can post the logs if you want interpret them ? if so word wrap or not ? I've forgotten which way you like them!

    Merry Christmas to you also!:D
  14. Broni Malware Annihilator Posts: 39,412   +177

    Sure....
  15. billyd Newcomer, in training Posts: 60

    ComboFix 12-12-20.02 - William 12/20/2012 18:21:41.5.2 - x86
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3061.1929 [GMT -5:00]
    Running from: c:\users\William\Desktop\ComboFix.exe
    AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
    FW: ESET Personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
    SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\program files\iWin Games\iWinGamesHookIE.dll
    c:\users\William\AppData\Roaming\vso_ts_preview.xml
    c:\users\William\GoToAssistDownloadHelper.exe
    c:\windows\desktop
    c:\windows\system32\drivers\etc\hosts.ics
    c:\windows\system32\mscsptisrv.dll
    .
    Infected copy of c:\windows\system32\userinit.exe was found and disinfected
    Restored copy from - c:\windows\ERDNT\cache\userinit.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Service_server
    -------\Service_timounter
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-11-20 to 2012-12-20 )))))))))))))))))))))))))))))))
    .
    .
    2012-12-20 23:34 . 2012-12-20 23:37 -------- d-----w- c:\users\William\AppData\Local\temp
    2012-12-20 23:34 . 2012-12-20 23:34 -------- d-----w- c:\users\Public\AppData\Local\temp
    2012-12-20 23:34 . 2012-12-20 23:34 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-12-20 22:15 . 2012-12-16 13:12 34304 ----a-w- c:\windows\system32\atmlib.dll
    2012-12-20 22:15 . 2012-12-16 10:50 293376 ----a-w- c:\windows\system32\atmfd.dll
    2012-12-18 19:16 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{98BCAFC5-E53A-40A4-9E63-3C4228B96AFF}\mpengine.dll
    2012-12-12 08:03 . 2012-07-26 02:46 9728 ----a-w- c:\windows\system32\Wdfres.dll
    2012-12-12 08:03 . 2012-07-26 02:32 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
    2012-12-12 08:03 . 2012-07-26 02:33 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
    2012-12-12 08:03 . 2009-07-14 12:12 16896 ----a-w- c:\windows\system32\winusb.dll
    2012-12-12 08:03 . 2012-07-26 03:20 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
    2012-12-12 08:03 . 2012-07-26 03:20 172032 ------w- c:\windows\system32\WUDFPlatform.dll
    2012-12-12 08:03 . 2012-07-26 03:39 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
    2012-12-12 08:03 . 2012-07-26 03:39 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
    2012-12-12 08:03 . 2012-07-26 03:20 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
    2012-12-12 08:03 . 2012-07-26 03:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe
    2012-12-12 08:03 . 2012-07-26 03:20 613888 ----a-w- c:\windows\system32\WUDFx.dll
    2012-12-12 06:57 . 2012-11-13 01:36 2048000 ----a-w- c:\windows\system32\win32k.sys
    2012-12-12 06:57 . 2012-11-02 10:18 376320 ----a-w- c:\windows\system32\dpnet.dll
    2012-12-12 06:57 . 2012-11-02 08:26 23040 ----a-w- c:\windows\system32\dpnsvr.exe
    2012-12-12 06:57 . 2012-11-13 01:29 2048 ----a-w- c:\windows\system32\tzres.dll
    2012-12-01 08:53 . 2012-12-01 08:53 -------- d-----w- c:\users\William\AppData\Roaming\Big Fish Games
    2012-12-01 08:51 . 2010-06-02 09:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
    2012-12-01 08:51 . 2010-06-02 09:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
    2012-12-01 08:51 . 2010-06-02 09:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
    2012-12-01 08:51 . 2010-05-26 16:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
    2012-12-01 08:51 . 2010-05-26 16:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
    2012-12-01 08:51 . 2010-05-26 16:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
    2012-12-01 08:51 . 2010-05-26 16:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
    2012-12-01 08:51 . 2010-05-26 16:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-12-12 11:58 . 2012-04-04 17:05 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2012-12-12 11:58 . 2011-12-23 00:38 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-11-07 01:19 . 2012-11-07 01:19 499712 ----a-w- c:\windows\system32\msvcp71.dll
    2012-11-07 01:19 . 2012-11-07 01:19 348160 ----a-w- c:\windows\system32\msvcr71.dll
    2012-09-29 23:54 . 2012-05-13 23:46 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-09-25 16:19 . 2012-11-14 02:32 75776 ----a-w- c:\windows\system32\synceng.dll
    2012-09-24 19:32 . 2012-06-23 20:03 477168 ----a-w- c:\windows\system32\npdeployJava1.dll
    2012-09-24 19:32 . 2012-03-20 23:22 473072 ----a-w- c:\windows\system32\deployJava1.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
    "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-12-08 3444736]
    "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2219184]
    "Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
    "dlbamon.exe"="c:\program files\Dell AIO Printer A940\dlbamon.exe" [2007-03-05 435696]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]
    "TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2012-11-07 296096]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-10-14 291896]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
    @="Service"
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Turbo Tourney 2012 Scheduler.lnk]
    backup=c:\windows\pss\Turbo Tourney 2012 Scheduler.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
    2011-07-28 23:08 1259376 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
    2008-02-12 01:13 141848 ----a-w- c:\windows\System32\igfxtray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
    2008-02-12 01:13 133656 ----a-w- c:\windows\System32\igfxpers.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    .
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    se2Bunic
    ofcpfwsvc
    upsmonservice
    nmservice
    atkkeyboardservice
    SE2Bmdfl
    SE2Dbus
    omsad
    tmtdi
    wscsvc
    wm
    UNDPX2A
    sdcoreservice
    EIO_XP
    ErrDev
    qfcoresvc
    mcdetect.exe
    pelusblf
    DS1410D
    CTMFLT
    EMATCORE
    CVirtA
    mssqlserverolapservice
    pgpsdkservice
    PTDCVsp
    dsNcAdpt
    sisnic
    btnetfilter
    nimcdfxk
    MTC0001_ESB
    SprintRcAppSvc
    pcx1unic
    RDID1027
    pwkntmon
    axsaki
    mwagent
    oracle_load_balancer_60_server-forms6ip9
    rslinxng
    mysql
    teefer
    atixsaudio
    adminserver
    mvserver
    spmd
    bc_filter
    atiavaiw
    UimBus
    sisperf
    imapiservice
    s716mdm
    rt2500usb
    ppped
    tfsnboio
    dlartl_n
    vstor2-ws60
    iPassPeriodicUpdateService
    speakerphone
    ZDPNDIS5
    ISAMSvc
    plsremotesvc
    smartwiservice
    mcdbus
    se45mgmt
    ccflic0
    webdriveservice
    wlluc48b
    webrootenterpriseclientservice
    imagesrv
    flashcom
    ssm_bus
    olapserver
    wintab32
    a016mgmt
    MRV6X32P
    EACSvrMngr
    sglogplayer
    AcronisOSSReinstallSvc
    atdisk
    bantext
    nwlnkspx
    PBADRV
    oraclewebassistant
    sonytvc
    intelroam
    papyjoy
    tfsnudf
    U3sHlpDr
    npapimon
    comhost
    SetupSys
    pdlnatcm
    iPassP
    perc2
    statusagent
    ATWPKT2
    AdobeActiveFileMonitor6.0
    WD_FireWire_HID
    {a7447300-8075-4b0d-83f1-3d75c8ebc623}
    hclinetd
    i81x
    SWUMX51
    MQAC
    UsbserFilt
    dlbu_device
    szkg
    incdsrv
    acrotray
    rootmodem
    nwlnknb
    avgems
    datasvr
    NETw4v32
    cfgwzsvc
    tvtfilter
    USB_NDIS_51
    s125mdfl
    tng-dtmg
    vproeventmonitor
    wmconnectcds
    redbook
    DivisCTS
    NWSAP
    macformatservice
    sit_flt
    EL2000
    ssfs0509
    procexp90
    iksyssec
    starwindservice
    mnsframework
    bwcsrv
    aolservice
    crauto
    nvax
    mctskshd.exe
    ICAM5USB
    LC7981
    razerusb
    EagleNT
    elockservice
    xfilt
    ageremodemaudio
    MA8032U
    fshttps
    slabbus
    useraccess7
    ctljystk
    acermemusagecheckservice
    NVR0Dev
    rnadirectory
    netmdsb
    nm
    bc_pat_f
    MREMP50
    W700mdm
    oraclemtsrecoveryservice
    pduip6000dmemcrdmgr
    roxwatch
    svv
    SMCB000
    vncdrv
    tapeware
    Angel2
    qkbfiltr
    persfw
    cpucoolserver
    elnkservice
    btwusb
    STV680m
    msftpsvc
    mxnic
    ikhfile
    opcenum
    trioservice
    cebdaldr
    winpppoverethernet
    lpx
    TOSHIBASoftModem
    mssql$sqlexpress
    Hotkey
    NITaggerService
    dlcj_device
    slabser
    openldap-slapd
    diskeeper
    WinVd32
    rchost
    w800mdm
    NTIDrvr
    dlcc_device
    SE26mgmt
    z800mgmt
    emitray
    aspi32
    S3GIGP
    tgsrvc_smartagent
    beatjamupnpmusicserver
    iaimfp1
    Slntamr
    defwatch
    sis315
    queuemgr
    penrendezvous
    lktimesync
    bthpan
    ATMsg
    ino_flpy
    cvslock
    dtsrvc
    noipducservice
    WaveFDE
    ntcharge
    se45nd5
    rfcomm
    tavsvc
    SABSVC
    screadspool
    GTSCSER
    mysqlinventime
    modemcsa
    NETw3v32
    ma_cmidi_installerservice
    getPlusHelper
    nimxdfk
    tdimsys
    bdselfpr
    PD0620VID
    PGPdisk
    SimpTcp
    mfeavfk
    AVerTV
    SPFDRV
    btwhid
    pcradminserver
    audstub
    mlkkbdntdriver
    WBHWDOCT
    lvprcsrv
    uleadburninghelper
    mwstick
    vsdatant
    hibernation
    lmab_device
    rppkt
    mcsysmon
    UWProSys
    s217nd5
    CX88AUD
    pdlnshay
    monfilt
    lxcj_device
    ntpr_nic_service2
    a016mdm
    iAimTV5
    zpsc
    haspnt
    Jukebox
    VAIOMediaPlatform-MusicServer-HTTP
    FETNDIS
    scsk4
    outpostfirewall
    backupexecalertserver
    nmwcdc
    pavdrv
    slee_503_service
    HIDSwvd
    ssm_mdm
    LVRS
    sifilter
    viaagp1
    ood2000
    STV680
    CnxTrLan
    win32sl
    s116mdm
    cwcwdm
    Pctspk
    jaguar
    ROB_A
    Appn
    hwpsgt
    AVCSTRM
    spcsutilityservice
    nvstor32
    mfesmfk
    roxupnpserver
    avg7rsw
    SWNC5E00
    DNE
    ovsecurityserver
    p2k
    ADIDTSFiltService
    wuolservice
    ggsemc
    winpowerrmi
    GoToAssist
    DgiVecp
    cccredmgr
    srvdpi
    db2das00
    spbbcsvc
    vcommmgr
    SNP2STD
    NIPALK
    hpqddsvc
    harmony
    sshrmd
    GT890x
    winpower
    Slpsvdr
    oracle_load_balancer_60_client-forms6ip9
    APLMp50
    TMKEmu
    HPFECP20
    pcidump
    ftsata2
    UVCFTR
    nbservice
    license
    oracleorahomehttpserver
    DirectUpdate
    PGPsdkDriver
    retroexplauncher
    nfmservice
    tng-dts
    SE2Eobex
    wampmysqld
    s217mdm
    dlcf_device
    rimvserport
    TNaviSrv
    el90xbc
    RESMGR
    SDdriver
    pdlnsx25
    gameenum
    wdica
    AR5523
    picturetaker
    Evian
    btwavdt
    rnadiagnosticsservice
    cusrvc
    Via4in1
    freepops
    nimcrpcsu
    dmio
    TuneUp.Defrag
    iPassPeriodicUpdateApp
    prism_a02
    IFPUSB
    bt3cser
    transarcafsdaemon
    k750mdfl
    USB_RNDIS
    SRTSP
    ifxtcs
    VICESYS
    PTDCBus
    tcsd_win32.exe
    pml
    ScFBPNT3
    UxTuneUp
    vc5secs
    tbhsd
    stacsv
    licensemanagersocket
    avgarcln
    tosrfnds
    ql1280
    s3ssavage
    hmonitor
    wlluc48
    tmmbd
    cbidf
    zebrbus
    dvd_2K
    vsapint
    w200bus
    awhost32
    filechecker
    NsTrcNT
    hsf_dp
    trackcam4
    arcltsrv
    dladresm
    WUSB54GPV4SRV
    us30service
    vvoice
    inotask
    inorpc
    VNUSB
    lxrjd31d
    Ncrc710
    rca
    s125obex
    NxSysMon
    VX3000
    srescan
    {95808DC4-FA4A-4c74-92FE-5B863F82066B}
    isapisearch
    lockmgr
    nvcap
    ss_mdfl
    SRS_SSCFilter
    klif
    DCamUSBSQTECH
    se26unic
    mks_scan
    s7otranx
    SED133x
    ibmcicstransactiongateway
    s7oppitx
    LKbdFlt2
    3comtftp
    UMPass
    U81xobex
    U2SP
    co_mon
    atierecord
    qbfcservice
    tosrfsnd
    openvpnservice
    AmdLLD
    freebsd
    atkdisplf
    se58unic
    RMCAST
    mcnasvc
    cdr4_2k
    avg7updsvc
    cvsnt
    k750mdm
    s616unic
    artourservice
    symmpi
    iastor
    aclient
    BTSLBCSP
    askernel
    acprfmgrsvc
    https-admserv61
    splitter
    SaiU040B
    proxyhostservice
    USB_RNDIS_XP
    nmsaccess
    mfehidk
    snmptrapdservice
    digictrl
    emupia
    rimusb
    array_utility_service4,0,1,3
    gearaspiwdm
    eskerlicensecontrol
    lxbs_device
    nimdbgk
    CTMSHD
    ihcservice
    pavreport
    ATKFUSService
    iomdisk
    se59mdfl
    pnkbstrb
    lp6nds35
    syntp
    SWMX00
    se2Bnd5
    e1express
    w800mdfl
    entech
    T6963C
    hnmsvc
    VCAM
    purgeieservice
    XFX_program
    smcservice
    ldlcserv
    PQNTDrv
    iviaspi
    enxpsvc
    DniVad
    acedrv07
    Subsonic
    iwebmsg
    qmofiltr
    agrsrvce
    SunkFilt39
    TcUsb
    MA_CMIDI
    trcboot
    smsmdd
    iam
    a016mdfl
    db2ntsecserver
    ec2007service
    sqlagent$sony_mediamgr
    soma
    tvs
    ipsraidn
    kservice
    Bcim
    amon
    axinstsv
    btwrchid
    bdfsdrv
    SE2Dmdfl
    MTsensor
    maya70docserver
    ctdvda2k
    wg111nd5
    nchssvad
    SaiNtSub
    cpqarray
    gv3
    UpdateCenterService
    MobilePreInstallerService
    SQLWriter
    iap
    usb20l
    s716nd5
    FireTDI
    pdframe
    HSFHWICH
    yukonwxp
    lvpopflt
    vzcdbsvc
    NVTCP
    SE27mdm
    atalk
    SunkFilt
    NVENET
    ctmmfilt
    cicssfs.scmmc223
    ifxspmgtsrv
    se44nd5
    agentsrv
    ATMsrvc
    nsengine
    s117obex
    aswrdr
    z800obex
    mwspollserver
    lxbu_device
    rtl8139
    se44bus
    USB11LDR
    ramaint
    pfc
    athr
    se59nd5
    sentinel
    ser2pl
    websenselogserver
    ltck000c
    ZuneWlanCfgSvc
    k750mgmt
    Nsynas32
    uclauncherservice
    ossrv
    sprtsvc_smartagent
    autocomplete
    sbhooksvc
    USBCamera
    TestHandler
    adiloader
    elotouchscreen
    cwafrmiregistry
    W55U01
    tvicport
    aec
    ino_fltr
    CTEDSPFX.DLL
    U81xmdm
    HFACSVC
    imaservice
    tmactmon
    MpFilter
    bthusb
    symids
    ASMMAP
    atchksrv
    AKSIFDH
    GV600_4
    nvmpu401
    ASNDIS5
    omniusbl
    papycpu2
    cpuz132
    HECI
    tsdhd
    protexislicensing
    slapd-data52
    tandpl
    dxdebug
    scanwscs
    ntrtscan
    mod7700
    TVALG
    oracle_load_balancer_60_client-forms6ip14
    telnet
    mapserver6.3
    incdfs
    eamon
    GTPTSER
    atmeltpm
    vetmsgnt
    nvsmu
    RSAFAL
    alertmanager
    sysmonlog
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-12-20 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 11:58]
    .
    2012-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2012-01-20 21:41]
    .
    2012-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2012-01-20 21:41]
    .
    2012-12-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1815498000-2833343681-1250068786-1000Core.job
    - c:\users\William\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-23 04:45]
    .
    2012-12-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1815498000-2833343681-1250068786-1000UA.job
    - c:\users\William\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-23 04:45]
    .
    2012-12-18 c:\windows\Tasks\ReclaimerUpdateFiles_William.job
    - c:\users\William\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.30\agent\rnupgagent.exe [2012-12-16 01:26]
    .
    2012-12-19 c:\windows\Tasks\ReclaimerUpdateXML_William.job
    - c:\users\William\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.30\agent\rnupgagent.exe [2012-12-16 01:26]
    .
    2012-12-20 c:\windows\Tasks\RNUpgradeHelperLogonPrompt_William.job
    - c:\users\William\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.30\agent\rnupgagent.exe [2012-12-16 01:26]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    Trusted Zone: intuit.com\ttlc
    TCP: DhcpNameServer = 192.168.1.1
    .
    - - - - ORPHANS REMOVED - - - -
    .
    HKLM-Run-NortonSupport - c:\program files\Norton Internet Security\Engine\19.1.0.28\symerr.exe
    SafeBoot-WudfPf
    SafeBoot-WudfRd
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-12-20 18:37
    Windows 6.0.6002 Service Pack 2 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
    @Denied: (2) (LocalSystem)
    "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
    27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
    "{326E768D-4182-46FD-9C16-1449A49795F4}"=hex:51,66,7a,6c,4c,1d,38,12,e3,75,7d,
    36,b0,0f,93,03,e3,00,57,09,a1,c9,d1,e0
    "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
    94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
    "{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
    ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
    .
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
    @Denied: (2) (LocalSystem)
    "Timestamp"=hex:81,97,c7,74,c6,e0,cc,01
    .
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
    @Denied: (2) (LocalSystem)
    "6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
    d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,44,3b,da,52,c0,a4,82,4f,a1,90,3e,\
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\System32\WLTRYSVC.EXE
    c:\windows\System32\bcmwltry.exe
    c:\windows\system32\WLANExt.exe
    c:\windows\system32\dlbacoms.exe
    c:\program files\ESET\ESET Smart Security\ekrn.exe
    c:\program files\iWin Games\iWinTrusted.exe
    c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
    c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
    c:\windows\system32\msiexec.exe
    c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
    c:\program files\Secunia\PSI\PSIA.exe
    c:\program files\TeamViewer\Version7\TeamViewer_Service.exe
    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    c:\program files\TeamViewer\Version7\TeamViewer.exe
    c:\program files\Secunia\PSI\sua.exe
    c:\program files\TeamViewer\Version7\tv_w32.exe
    c:\windows\system32\igfxsrvc.exe
    c:\program files\DellTPad\ApMsgFwd.exe
    c:\windows\ehome\ehmsas.exe
    c:\program files\DellTPad\HidFind.exe
    c:\program files\DellTPad\Apntex.exe
    c:\program files\Windows Media Player\wmpnscfg.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\program files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
    c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
    .
    **************************************************************************
    .
    Completion time: 2012-12-20 18:43:25 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-12-20 23:43
    ComboFix2.txt 2012-05-25 19:23
    ComboFix3.txt 2012-05-25 11:25
    .
    Pre-Run: 85,502,816,256 bytes free
    Post-Run: 85,457,219,584 bytes free
    .
    - - End Of File - - 5E48F7E7CD0F8286D9073F866A742DA1
  16. Broni Malware Annihilator Posts: 39,412   +177

    Well, it looks like you got reinfected at some point.

    Let's run couple more scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

    2. Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.

    3. Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.

    4. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
  17. billyd Newcomer, in training Posts: 60

    This is the sfc scannow log called cbs.persist.log its pretty long also have a cbs.log if needed?

    2012-12-20 17:47:58, Info CBS Archived log file: C:\Windows\Logs\CBS\CBS.log to: C:\Windows\Logs\CBS\CBS.persist.log
    2012-12-20 17:47:58, Info CBS Loaded Servicing Stack v6.0.6002.18005 with Core: C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\cbscore.dll
    2012-12-20 17:47:58, Info CSI 00000001@2012/12/20:22:47:58.279 WcpInitialize (wcp.dll version 0.0.0.5) called (stack @0x63a88a50 @0x6fd9854e @0x6fd763a1 @0x171392 @0x171ed4 @0x1717cb)
    2012-12-20 17:47:58, Info CSI 00000002@2012/12/20:22:47:58.301 WcpInitialize (wcp.dll version 0.0.0.5) called (stack @0x63a88a50 @0x6fdce7b6 @0x6fdb0f93 @0x171392 @0x171ed4 @0x1717cb)
    2012-12-20 17:47:58, Info CSI 00000003@2012/12/20:22:47:58.304 WcpInitialize (wcp.dll version 0.0.0.5) called (stack @0x63a88a50 @0x74781a0d @0x74781794 @0x17360b @0x172be3 @0x1717cb)
    2012-12-20 17:47:58, Info CBS NonStart: Checking to ensure startup processing was not required.
    2012-12-20 17:47:58, Info CSI 00000004 IAdvancedInstallerAwareStore_ResolvePendingTransactions (call 1) (flags = 00000004, progress = NULL, phase = 0, pdwDisposition = @0xf7f89c
    2012-12-20 17:47:58, Info CBS NonStart: Success, startup processing not required as expected.
    2012-12-20 17:47:58, Info CSI 00000005 CSI Store 3533832 (0x0035ec08) initialized
    2012-12-20 17:47:58, Info CBS Session: 30269188:246816404 initialized.
    2012-12-20 17:47:58, Info CBS Session: 30269188:246816404 finalized. Reboot required: no
    2012-12-20 17:47:58, Info CBS Session: 30269188:246846404 initialized.
    2012-12-20 17:47:58, Info CBS Session: 30269188:246846404 finalized. Reboot required: no
    2012-12-20 17:47:58, Info CBS Session: 30269188:250736404 initialized.
    2012-12-20 17:47:58, Info CBS Session: 30269188:250736404 finalized. Reboot required: no
    2012-12-20 17:47:58, Info CBS Session: 30269188:250756404 initialized.
    2012-12-20 17:47:58, Info CBS Session: 30269188:250756404 finalized. Reboot required: no
    2012-12-20 17:47:58, Info CBS Session: 30269188:250766404 initialized.
    2012-12-20 17:47:58, Info CBS Session: 30269188:250766404 finalized. Reboot required: no
    2012-12-20 17:47:58, Info CBS Session: 30269188:250786404 initialized.
    2012-12-20 17:47:58, Info CBS Session: 30269188:250786404 finalized. Reboot required: no
    2012-12-20 17:47:59, Info CBS Session: 30269188:261986404 initialized.
    2012-12-20 17:47:59, Info CBS Session: 30269188:261986404 finalized. Reboot required: no
    2012-12-20 17:47:59, Info CBS Session: 30269188:262006404 initialized.
    2012-12-20 17:48:00, Info CBS Session: 30269188:262006404 finalized. Reboot required: no
    2012-12-20 17:48:01, Info CBS Session: 30269188:276794404 initialized.
    2012-12-20 17:48:01, Info CBS Session: 30269188:276794404 finalized. Reboot required: no
    2012-12-20 17:48:01, Info CBS Session: 30269188:276814404 initialized.
    2012-12-20 17:48:01, Info CBS Session: 30269188:276814404 finalized. Reboot required: no
    2012-12-20 17:48:01, Info CBS Session: 30269188:276834404 initialized.
    2012-12-20 17:48:01, Info CBS Session: 30269188:276834404 finalized. Reboot required: no
    2012-12-20 17:48:01, Info CBS Session: 30269188:276844404 initialized.
    2012-12-20 17:48:01, Info CBS Session: 30269188:276844404 finalized. Reboot required: no
    2012-12-20 17:48:04, Info CBS Session: 30269188:311942404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB2378111~31bf3856ad364e35~x86~~6.0.1.3, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:311942404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:313822404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Microsoft-Windows-AutomationAPI-Package-TopLevel~31bf3856ad364e35~x86~~6.0.6002.18156, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:313822404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:313912404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Microsoft-Windows-WPD7IP-Package-TopLevel~31bf3856ad364e35~x86~~7.0.6002.18112, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:313912404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:314072404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Microsoft-Windows-DGT-Package-TopLevel~31bf3856ad364e35~x86~~7.0.6002.18107, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:314072404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:314202404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Microsoft-Windows-UIRibbon-Package-TopLevel~31bf3856ad364e35~x86~~7.0.6002.18108, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:314202404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:314302404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: KB937286~31bf3856ad364e35~x86~lt-LT~6.0.1.18000, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:05, Info CBS Session: 30269188:314302404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:314472404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB2345886~31bf3856ad364e35~x86~~6.0.1.1, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:314472404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:315982404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB981322~31bf3856ad364e35~x86~~6.0.1.1, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:315982404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:316062404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB2423089~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:316062404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:316112404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB977864~31bf3856ad364e35~x86~~6.1.1.0, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:05, Info CBS Session: 30269188:316112404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:316182404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB974307~31bf3856ad364e35~x86~~6.1.1.2,
  18. billyd Newcomer, in training Posts: 60

    ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:05, Info CBS Session: 30269188:316182404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:316232404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB966315~31bf3856ad364e35~x86~~6.1.1.2, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:05, Info CBS Session: 30269188:316232404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:316262404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB972270~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 0, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:316262404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:316442404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB2661254~31bf3856ad364e35~x86~~6.0.1.5, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:316442404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:317958404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB979910~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:317958404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:318270404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB971961~31bf3856ad364e35~x86~~8.0.1.1, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:05, Info CBS Session: 30269188:318270404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:318426404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB2779562~31bf3856ad364e35~x86~~6.0.1.2, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:318426404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:319986404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB2585542~31bf3856ad364e35~x86~~6.0.1.2, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:319986404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:320142404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB2761465~31bf3856ad364e35~x86~~9.1.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:320142404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:320298404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: KB937286~31bf3856ad364e35~x86~hr-HR~6.0.1.18000, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:05, Info CBS Session: 30269188:320298404 finalized. Reboot required: no
    2012-12-20 17:48:05, Info CBS Session: 30269188:320628404 initialized.
    2012-12-20 17:48:05, Info CBS Read out cached package applicability for package: Package_for_KB2718704~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:05, Info CBS Session: 30269188:320628404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:323688404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2753842~31bf3856ad364e35~x86~~6.0.2.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:323688404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:323758404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2508429~31bf3856ad364e35~x86~~6.0.1.1, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:323758404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:323838404 initialized.
    2012-12-20 17:48:06, Info CBS Session: 30269188:323838404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:324298404 initialized.
    2012-12-20 17:48:06, Info CBS Session: 30269188:324298404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:324578404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2621146~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:06, Info CBS Session: 30269188:324578404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:324638404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2601626~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:06, Info CBS Session: 30269188:324638404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:324688404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2579686~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:324688404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:324728404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB946253~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:0
    2012-12-20 17:48:06, Info CBS Session: 30269188:324728404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:324758404 initialized.
    2012-12-20 17:48:06, Info CBS Session: 30269188:324758404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:324778404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2419640~31bf3856ad364e35~x86~~6.0.1.2, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:324778404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:324958404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2628642~31bf3856ad364e35~x86~~6.1.1.0, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:06, Info CBS Session: 30269188:324958404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:324988404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB982480~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:324988404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:325098404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2646524~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:325098404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:325328404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB967723~31bf3856ad364e35~x86~~6.0.1.7, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:325328404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:329048404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2511455~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:329048404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:329208404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB970710~31bf3856ad364e35~x86~~6.0.1.1, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:329208404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:329288404 initialized.
    2012-12-20 17:48:06, Info CBS Session: 30269188:329288404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:329518404 initialized.
    2012-12-20 17:48:06, Info CBS Session: 30269188:329518404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:329758404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2535512~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:329758404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:329838404 initialized.
    2012-12-20 17:48:06, Info CBS Session: 30269188:329838404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:330068404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2393802~31bf3856ad364e35~x86~~6.0.1.3, ApplicableState: 0, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:330068404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:330188404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2779030~31bf3856ad364e35~x86~~6.0.1.2, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:330188404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:330500404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2712808~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:330500404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:332060404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2604094~31bf3856ad364e35~x86~~6.0.1.1, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:332060404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:332684404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2532531~31bf3856ad364e35~x86~~6.0.1.2, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:332684404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:332840404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2506212~31bf3856ad364e35~x86~~6.0.1.1, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:332840404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:332840405 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB2644615~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:332840405 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:332996404 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB978542~31bf3856ad364e35~x86~~6.0.1.3, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:332996404 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:332996405 initialized.
    2012-12-20 17:48:06, Info CBS Read out cached package applicability for package: Package_for_KB982665~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:06, Info CBS Session: 30269188:332996405 finalized. Reboot required: no
    2012-12-20 17:48:06, Info CBS Session: 30269188:333152404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB2117917~31bf3856ad364e35~x86~~6.0.1.5, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:07, Info CBS Session: 30269188:333152404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:333776404 initialized.
    2012-12-20 17:48:07, Info CBS Session: 30269188:333776404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:333776405 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB2727528~31bf3856ad364e35~x86~~6.0.1.3, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:07, Info CBS Session: 30269188:333776405 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:333776406 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB947821~31bf3856ad364e35~x86~~6.0.25.0, ApplicableState: 7, CurrentState:0
    2012-12-20 17:48:07, Info CBS Session: 30269188:333776406 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:333776407 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB947821~31bf3856ad364e35~x86~~6.0.24.0, ApplicableState: 7, CurrentState:0
    2012-12-20 17:48:07, Info CBS Session: 30269188:333776407 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:333932404
  19. billyd Newcomer, in training Posts: 60

    Initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: KB937286~31bf3856ad364e35~x86~nb-NO~6.0.1.18000, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:07, Info CBS Session: 30269188:333932404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:333932405 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB968816~31bf3856ad364e35~x86~~6.0.1.1, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:07, Info CBS Session: 30269188:333932405 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:334088404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB981332~31bf3856ad364e35~x86~~8.0.1.0, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:07, Info CBS Session: 30269188:334088404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:334088405 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_1_for_KB925028~31bf3856ad364e35~x86~~6.0.0.1, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:07, Info CBS Session: 30269188:334088405 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:334400404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB2536276~31bf3856ad364e35~x86~~6.0.2.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:07, Info CBS Session: 30269188:334400404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:334410404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB2691442~31bf3856ad364e35~x86~~6.0.1.2, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:07, Info CBS Session: 30269188:334410404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:334410405 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: KB937286~31bf3856ad364e35~x86~zh-TW~6.0.1.18000, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:07, Info CBS Session: 30269188:334410405 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:334490404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB2509553~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:07, Info CBS Session: 30269188:334490404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:334600404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB2686833~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:07, Info CBS Session: 30269188:334600404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:335140404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: KB937286~31bf3856ad364e35~x86~hu-HU~6.0.1.18000, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:07, Info CBS Session: 30269188:335140404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:335230404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB981550~31bf3856ad364e35~x86~~6.0.1.2, ApplicableState: 0, CurrentState:0
    2012-12-20 17:48:07, Info CBS Session: 30269188:335230404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:335290404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB979482~31bf3856ad364e35~x86~~6.0.1.1, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:07, Info CBS Session: 30269188:335290404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:335350404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB2510581~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 0, CurrentState:7
    2012-12-20 17:48:07, Info CBS Session: 30269188:335350404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:335440404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Package_for_KB981349~31bf3856ad364e35~x86~~6.0.1.0, ApplicableState: 0, CurrentState:7
    2012-12-20 17:48:07, Info CBS Session: 30269188:335440404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:335550404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Microsoft-Windows-AutomationAPI-Package-TopLevel~31bf3856ad364e35~x86~~6.0.6002.18156, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:07, Info CBS Session: 30269188:335550404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:335630404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package applicability for package: Microsoft-Windows-WPD7IP-Package-TopLevel~31bf3856ad364e35~x86~~7.0.6002.18112, ApplicableState: 7, CurrentState:7
    2012-12-20 17:48:07, Info CBS Session: 30269188:335630404 finalized. Reboot required: no
    2012-12-20 17:48:07, Info CBS Session: 30269188:335730404 initialized.
    2012-12-20 17:48:07, Info CBS Read out cached package
  20. billyd Newcomer, in training Posts: 60

    This is too long I'll start doing your other instructions now