mystery 1

18
1.265: ====================================================================== ========== 1.265: 2012/08/01 11:02:41.640 (local) 1.265: C:\WINDOWS\SoftwareDistribution\Download\ 51401b498f4675531d9efb941ee01ef3\update\update.exe (version 6.3.13.0) 1.265: Failed To Enable SE_SHUTDOWN_PRIVILEGE 1.265: Hotfix started with following command line: -q -z -er /ParentInfo:674ccb3bfd17ea40b8d772594402a918 1.281: In Function GetReleaseSet, line 1240, RegQueryValueEx failed with error 0x2 1.703: ---- Old Information In The Registry ------ 1.703: Source:C:\Documents and Settings\CAPLIBUSER\Local Settings\ Application Data\Google\Chrome 1.703: Destination: 1.703: Source:C:\Documents and Settings\CAPLIBUSER\Local Settings\ Application Data\Google\Update\1.3.21.111 1.703: Destination: 1.703: Source:C:\DOCUME~1\CAPLIB~1\LOCALS~1\Temp\ GoogleUpdateSetup.exe235d77 (1.3.21.115) 1.703: Destination: 1.703: Source:C:\WINDOWS\system32\SET1F5.tmp (5.7.0.18066) 1.703: Destination:C:\WINDOWS\system32\jscript.dll (5.7.0.16599) 1.703: Source:C:\WINDOWS\system32\SET20F.tmp (2001.12.4414.706) 1.703: Destination:C:\WINDOWS\system32\es.dll (2001.12.4414.701) 1.703: Source:C:\WINDOWS\system32\SET217.tmp (5.1.2600.5694) 1.703: Destination:C:\WINDOWS\system32\netapi32.dll (5.1.2600.5512)

Upload: rwewgmailcom

Post on 30-Oct-2014

108 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Mystery 1

1.265: ================================================================================

1.265: 2012/08/01 11:02:41.640 (local)

1.265: C:\WINDOWS\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\update\update.exe (version 6.3.13.0)

1.265: Failed To Enable SE_SHUTDOWN_PRIVILEGE

1.265: Hotfix started with following command line: -q -z -er /ParentInfo:674ccb3bfd17ea40b8d772594402a918

1.281: In Function GetReleaseSet, line 1240, RegQueryValueEx failed with error 0x2

1.703: ---- Old Information In The Registry ------

1.703: Source:C:\Documents and Settings\CAPLIBUSER\Local Settings\Application Data\Google\Chrome

1.703: Destination:

1.703: Source:C:\Documents and Settings\CAPLIBUSER\Local Settings\Application Data\Google\Update\1.3.21.111

1.703: Destination:

1.703: Source:C:\DOCUME~1\CAPLIB~1\LOCALS~1\Temp\GoogleUpdateSetup.exe235d77 (1.3.21.115)

1.703: Destination:

1.703: Source:C:\WINDOWS\system32\SET1F5.tmp (5.7.0.18066)

1.703: Destination:C:\WINDOWS\system32\jscript.dll (5.7.0.16599)

1.703: Source:C:\WINDOWS\system32\SET20F.tmp (2001.12.4414.706)

1.703: Destination:C:\WINDOWS\system32\es.dll (2001.12.4414.701)

1.703: Source:C:\WINDOWS\system32\SET217.tmp (5.1.2600.5694)

1.703: Destination:C:\WINDOWS\system32\netapi32.dll (5.1.2600.5512)

1.703: Source:C:\WINDOWS\system32\SET21B.tmp (5.1.2600.5698)

1.703: Destination:C:\WINDOWS\system32\gdi32.dll (5.1.2600.5512)

1.703: Source:C:\WINDOWS\AppPatch\SET21F.tmp

1.703: Destination:C:\WINDOWS\AppPatch\sysmain.sdb (0.2.1.14878)

Page 2: Mystery 1

1.703: Source:C:\Program Files\windows nt\accessories\SET220.tmp (5.1.2600.5584)

1.703: Destination:C:\Program Files\windows nt\accessories\wordpad.exe (5.1.2600.5512)

1.703: ---- New Information In The Registry ------

1.703: Source:C:\Documents and Settings\CAPLIBUSER\Local Settings\Application Data\Google\Chrome

1.703: Destination:

1.703: Source:C:\Documents and Settings\CAPLIBUSER\Local Settings\Application Data\Google\Update\1.3.21.111

1.703: Destination:

1.703: Source:C:\DOCUME~1\CAPLIB~1\LOCALS~1\Temp\GoogleUpdateSetup.exe235d77 (1.3.21.115)

1.703: Destination:

1.703: Source:C:\WINDOWS\system32\SET1F5.tmp (5.7.0.18066)

1.703: Destination:C:\WINDOWS\system32\jscript.dll (5.7.0.16599)

1.703: Source:C:\WINDOWS\system32\SET20F.tmp (2001.12.4414.706)

1.703: Destination:C:\WINDOWS\system32\es.dll (2001.12.4414.701)

1.703: Source:C:\WINDOWS\system32\SET217.tmp (5.1.2600.5694)

1.703: Destination:C:\WINDOWS\system32\netapi32.dll (5.1.2600.5512)

1.718: Source:C:\WINDOWS\system32\SET21B.tmp (5.1.2600.5698)

1.718: Destination:C:\WINDOWS\system32\gdi32.dll (5.1.2600.5512)

1.718: Source:C:\WINDOWS\AppPatch\SET21F.tmp

1.718: Destination:C:\WINDOWS\AppPatch\sysmain.sdb (0.2.1.14878)

1.718: Source:C:\Program Files\windows nt\accessories\SET220.tmp (5.1.2600.5584)

1.718: Destination:C:\Program Files\windows nt\accessories\wordpad.exe (5.1.2600.5512)

1.718: In Function GetReleaseSet, line 1240, RegQueryValueEx failed with error 0x2

1.718: SetProductTypes: InfProductBuildType=BuildType.IP

1.718: SetAltOsLoaderPath: No section uses DirId 65701; done.

Page 3: Mystery 1

1.734: DoInstallation: FetchSourceURL for c:\windows\softwaredistribution\download\51401b498f4675531d9efb941ee01ef3\update\update_SP3GDR.inf failed

1.734: CreateUninstall = 1,Directory = C:\WINDOWS\$NtUninstallKB956572$

1.765: LoadFileQueues: UpdSpGetSourceFileLocation for halaacpi.dll failed: 0xe0000102

1.812: BuildCabinetManifest: update.url absent

1.843: Starting AnalyzeComponents

1.843: AnalyzePhaseZero used 0 ticks

1.843: No c:\windows\INF\updtblk.inf file.

1.843: SetupFindFirstLine in LoadExclusionList Failed with error: 0xe0000102

1.843: SetupFindFirstLine in LoadExclusionList Failed with error: 0xe0000102

1.843: Enumerating Devices of computer, GUID {4d36e966-e325-11ce-bfc1-08002be10318}

2.015: OEM file scan used 172 ticks

2.437: AnalyzePhaseOne: used 594 ticks

2.437: AnalyzeComponents: Hotpatch analysis disabled; skipping.

2.437: AnalyzeComponents: Hotpatching is disabled.

2.437: FindFirstFile c:\windows\$hf_mig$\*.*

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

Page 4: Mystery 1

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.437: KB956572 Setup encountered an error: The update.ver file is not correct.

2.453: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

Page 5: Mystery 1

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

Page 6: Mystery 1

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

2.468: KB956572 Setup encountered an error: The update.ver file is not correct.

3.078: AnalyzeForBranching used 610 ticks.

6.515: AnalyzePhaseTwo used 3422 ticks

6.515: AnalyzePhaseThree used 0 ticks

6.515: AnalyzePhaseFive used 0 ticks

6.515: AnalyzePhaseSix used 0 ticks

6.515: AnalyzeComponents used 4672 ticks

6.515: Downloading 0 files

6.515: bPatchMode = FALSE

6.515: Inventory complete: ReturnStatus=0, 4781 ticks

6.515: Num Ticks for invent : 4781

6.515: VerifyTargetFileSize: Unable to verify size as Source = NULL for file c:\windows\inf\HFX229.tmp

6.531: Copied file: c:\windows\inf\branches.inf

6.562: Allocation size of drive C: is 4096 bytes, free space = 33393782784 bytes

6.734: AnalyzeDiskUsage: Skipping EstimateDiskUsageForUninstall.

6.734: Drive C: free 31846MB req: 57MB w/uninstall: NOT CALCULATED.

6.734: CabinetBuild complete

6.734: Num Ticks for Cabinet build : 219

6.734: DynamicStrings section not defined or empty.

6.750: FileInUse:: Detection disabled.

7.750: LoadFileQueues: UpdSpGetSourceFileLocation for halaacpi.dll failed: 0xe0000102

8.593: Num Ticks for Backup : 1859

9.031: Num Ticks for creating uninst inf : 438

Page 7: Mystery 1

9.031: Registering Uninstall Program for -> KB956572, KB956572 , 0x0

9.203: LoadFileQueues: UpdSpGetSourceFileLocation for halaacpi.dll failed: 0xe0000102

9.250: System Restore Point set.

9.359: Copied file: C:\WINDOWS\system32\spmsg.dll

9.375: PFE2: Not avoiding Per File Exceptions.

9.422: GetCatVersion: Failed to retrieve version information from C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB956572.cat with error 0x57

9.500: ProcessSetupContentSection: PROCESS_SETUP_CONTENT_OP_INSTALL: Copied c:\windows\softwaredistribution\download\51401b498f4675531d9efb941ee01ef3\update\update_SP3QFE.inf -> c:\windows\$hf_mig$\KB956572\update\update_SP3QFE.inf.

9.500: ProcessSetupContentSection: PROCESS_SETUP_CONTENT_OP_INSTALL: Copied c:\windows\softwaredistribution\download\51401b498f4675531d9efb941ee01ef3\spuninst.exe -> c:\windows\$hf_mig$\KB956572\spuninst.exe.

9.500: ProcessSetupContentSection: PROCESS_SETUP_CONTENT_OP_INSTALL: Copied c:\windows\softwaredistribution\download\51401b498f4675531d9efb941ee01ef3\spmsg.dll -> c:\windows\$hf_mig$\KB956572\spmsg.dll.

9.500: ProcessSetupContentSection: PROCESS_SETUP_CONTENT_OP_INSTALL: Copied c:\windows\softwaredistribution\download\51401b498f4675531d9efb941ee01ef3\update\spcustom.dll -> c:\windows\$hf_mig$\KB956572\update\spcustom.dll.

9.515: ProcessSetupContentSection: PROCESS_SETUP_CONTENT_OP_INSTALL: Copied c:\windows\softwaredistribution\download\51401b498f4675531d9efb941ee01ef3\update\KB956572.CAT -> c:\windows\$hf_mig$\KB956572\update\KB956572.CAT.

9.531: ProcessSetupContentSection: PROCESS_SETUP_CONTENT_OP_INSTALL: Copied c:\windows\softwaredistribution\download\51401b498f4675531d9efb941ee01ef3\update\update.exe -> c:\windows\$hf_mig$\KB956572\update\update.exe.

9.578: ProcessSetupContentSection: PROCESS_SETUP_CONTENT_OP_INSTALL: Copied c:\windows\softwaredistribution\download\51401b498f4675531d9efb941ee01ef3\update\updspapi.dll -> c:\windows\$hf_mig$\KB956572\update\updspapi.dll.

9.578: ProcessSetupContentSection: PROCESS_SETUP_CONTENT_OP_INSTALL: Copied c:\windows\softwaredistribution\download\51401b498f4675531d9efb941ee01ef3\update\update.ver -> c:\windows\$hf_mig$\KB956572\update\update.ver.

Page 8: Mystery 1

9.593: ProcessSetupContentSection: PROCESS_SETUP_CONTENT_OP_INSTALL: Copied c:\windows\softwaredistribution\download\51401b498f4675531d9efb941ee01ef3\update\updatebr.inf -> c:\windows\$hf_mig$\KB956572\update\updatebr.inf.

9.593: ProcessSetupContentSection: PROCESS_SETUP_CONTENT_OP_INSTALL: Copied c:\windows\softwaredistribution\download\51401b498f4675531d9efb941ee01ef3\update\eula.txt -> c:\windows\$hf_mig$\KB956572\update\eula.txt.

9.593: ProcessSetupContentSection: PROCESS_SETUP_CONTENT_OP_INSTALL: Copied c:\windows\softwaredistribution\download\51401b498f4675531d9efb941ee01ef3\update\branches.inf -> c:\windows\$hf_mig$\KB956572\update\branches.inf.

9.890: Copied file: C:\WINDOWS\system32\ntoskrnl.exe

10.297: Copied file: C:\WINDOWS\system32\ntkrnlpa.exe

10.390: Copied file: C:\WINDOWS\system32\services.exe

10.562: Copied file: C:\WINDOWS\system32\ntdll.dll

10.734: Copied file: C:\WINDOWS\system32\lsasrv.dll

11.156: Copied file: C:\WINDOWS\system32\advapi32.dll

11.172: Copied file: C:\WINDOWS\system32\sc.exe

11.343: Copied file: C:\WINDOWS\system32\rpcss.dll

11.625: Copied file (delayed): C:\WINDOWS\system32\SET232.tmp

11.625: Copied file: C:\WINDOWS\system32\pdh.dll

11.750: Copied file: C:\WINDOWS\system32\WBEM\wmiprvse.exe

11.937: Copied file (delayed): C:\WINDOWS\system32\WBEM\SET234.tmp

11.953: Copied file: C:\WINDOWS\system32\WBEM\wmiprvsd.dll

12.156: Copied file (delayed): C:\WINDOWS\system32\WBEM\SET235.tmp

12.172: Copied file: C:\WINDOWS\system32\WBEM\fastprox.dll

12.328: Copied file (delayed): C:\WINDOWS\system32\WBEM\SET236.tmp

12.328: Copied file: C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe

12.562: Copied file: C:\WINDOWS\Driver Cache\i386\ntkrpamp.exe

12.875: Copied file: C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe

Page 9: Mystery 1

13.078: Copied file: C:\WINDOWS\Driver Cache\i386\ntkrnlmp.exe

13.390: Copied file: C:\WINDOWS\system32\DllCache\wmiprvse.exe

13.468: Copied file: C:\WINDOWS\system32\DllCache\wmiprvsd.dll

13.531: Copied file: C:\WINDOWS\system32\DllCache\services.exe

13.625: Copied file: C:\WINDOWS\system32\DllCache\sc.exe

13.703: Copied file: C:\WINDOWS\system32\DllCache\rpcss.dll

13.781: Copied file: C:\WINDOWS\system32\DllCache\pdh.dll

13.843: Copied file: C:\WINDOWS\system32\DllCache\ntoskrnl.exe

13.953: Copied file: C:\WINDOWS\system32\DllCache\ntkrpamp.exe

14.031: Copied file: C:\WINDOWS\system32\DllCache\ntkrnlpa.exe

14.156: Copied file: C:\WINDOWS\system32\DllCache\ntkrnlmp.exe

14.297: Copied file: C:\WINDOWS\system32\DllCache\ntdll.dll

14.343: Copied file: C:\WINDOWS\system32\DllCache\lsasrv.dll

14.422: Copied file: C:\WINDOWS\system32\DllCache\fastprox.dll

14.468: Copied file: C:\WINDOWS\system32\DllCache\advapi32.dll

14.812: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\fastprox.dll

14.984: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe

15.203: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\advapi32.dll

15.578: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll

15.687: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\lsasrv.dll

15.890: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\wmiprvsd.dll

16.031: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\sc.exe

16.156: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\pdh.dll

16.312: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlmp.exe

16.578: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\ntdll.dll

Page 10: Mystery 1

16.672: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe

16.953: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe

17.297: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\wmiprvse.exe

17.422: Copied file: c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrpamp.exe

17.672: DoInstallation: Installing assemblies with source root path: c:\windows\softwaredistribution\download\51401b498f4675531d9efb941ee01ef3\

17.672: Num Ticks for Copying files : 8641

17.797: Num Ticks for Reg update and deleting 0 size files : 125

17.797: Starting process: C:\WINDOWS\system32\spupdsvc.exe /install "Enables Windows XP Service Pack Installer to complete its scheduled post-reboot tasks"

18.734: Return Code = 0

18.734: ---- Old Information In The Registry ------

18.734: Source:C:\Documents and Settings\CAPLIBUSER\Local Settings\Application Data\Google\Chrome

18.734: Destination:

18.734: Source:C:\Documents and Settings\CAPLIBUSER\Local Settings\Application Data\Google\Update\1.3.21.111

18.734: Destination:

18.734: Source:C:\DOCUME~1\CAPLIB~1\LOCALS~1\Temp\GoogleUpdateSetup.exe235d77 (1.3.21.115)

18.734: Destination:

18.734: Source:C:\WINDOWS\system32\SET1F5.tmp (5.7.0.18066)

18.734: Destination:C:\WINDOWS\system32\jscript.dll (5.7.0.16599)

18.734: Source:C:\WINDOWS\system32\SET20F.tmp (2001.12.4414.706)

18.734: Destination:C:\WINDOWS\system32\es.dll (2001.12.4414.701)

18.734: Source:C:\WINDOWS\system32\SET217.tmp (5.1.2600.5694)

18.734: Destination:C:\WINDOWS\system32\netapi32.dll (5.1.2600.5512)

18.734: Source:C:\WINDOWS\system32\SET21B.tmp (5.1.2600.5698)

Page 11: Mystery 1

18.734: Destination:C:\WINDOWS\system32\gdi32.dll (5.1.2600.5512)

18.734: Source:C:\WINDOWS\AppPatch\SET21F.tmp

18.734: Destination:C:\WINDOWS\AppPatch\sysmain.sdb (0.2.1.14878)

18.734: Source:C:\Program Files\windows nt\accessories\SET220.tmp (5.1.2600.5584)

18.734: Destination:C:\Program Files\windows nt\accessories\wordpad.exe (5.1.2600.5512)

18.750: Source:C:\WINDOWS\system32\_000019_.tmp.dll (5.1.2600.5512)

18.750: Destination:

18.750: Source:C:\WINDOWS\system32\_000020_.tmp.dll (5.1.2600.5512)

18.750: Destination:

18.750: Source:C:\WINDOWS\system32\_000021_.tmp.dll (5.1.2600.5512)

18.750: Destination:

18.750: Source:C:\WINDOWS\system32\_000022_.tmp.dll (5.1.2600.5512)

18.750: Destination:

18.765: Source:C:\WINDOWS\system32\SET232.tmp (5.1.2600.5755)

18.765: Destination:C:\WINDOWS\system32\rpcss.dll (5.1.2600.5512)

18.765: Source:C:\WINDOWS\system32\WBEM\SET234.tmp (5.1.2600.5755)

18.765: Destination:C:\WINDOWS\system32\WBEM\wmiprvse.exe (5.1.2600.5512)

18.781: Source:C:\WINDOWS\system32\WBEM\SET235.tmp (5.1.2600.5755)

18.781: Destination:C:\WINDOWS\system32\WBEM\wmiprvsd.dll (5.1.2600.5512)

18.797: Source:C:\WINDOWS\system32\WBEM\SET236.tmp (5.1.2600.5755)

18.797: Destination:C:\WINDOWS\system32\WBEM\fastprox.dll (5.1.2600.5512)

18.797: ---- New Information In The Registry ------

18.797: Source:C:\Documents and Settings\CAPLIBUSER\Local Settings\Application Data\Google\Chrome

18.797: Destination:

Page 12: Mystery 1

18.797: Source:C:\Documents and Settings\CAPLIBUSER\Local Settings\Application Data\Google\Update\1.3.21.111

18.797: Destination:

18.797: Source:C:\DOCUME~1\CAPLIB~1\LOCALS~1\Temp\GoogleUpdateSetup.exe235d77 (1.3.21.115)

18.797: Destination:

18.797: Source:C:\WINDOWS\system32\SET1F5.tmp (5.7.0.18066)

18.797: Destination:C:\WINDOWS\system32\jscript.dll (5.7.0.16599)

18.797: Source:C:\WINDOWS\system32\SET20F.tmp (2001.12.4414.706)

18.797: Destination:C:\WINDOWS\system32\es.dll (2001.12.4414.701)

18.797: Source:C:\WINDOWS\system32\SET217.tmp (5.1.2600.5694)

18.797: Destination:C:\WINDOWS\system32\netapi32.dll (5.1.2600.5512)

18.797: Source:C:\WINDOWS\system32\SET21B.tmp (5.1.2600.5698)

18.797: Destination:C:\WINDOWS\system32\gdi32.dll (5.1.2600.5512)

18.797: Source:C:\WINDOWS\AppPatch\SET21F.tmp

18.797: Destination:C:\WINDOWS\AppPatch\sysmain.sdb (0.2.1.14878)

18.797: Source:C:\Program Files\windows nt\accessories\SET220.tmp (5.1.2600.5584)

18.797: Destination:C:\Program Files\windows nt\accessories\wordpad.exe (5.1.2600.5512)

18.797: Source:C:\WINDOWS\system32\_000019_.tmp.dll (5.1.2600.5512)

18.797: Destination:

18.797: Source:C:\WINDOWS\system32\_000020_.tmp.dll (5.1.2600.5512)

18.797: Destination:

18.797: Source:C:\WINDOWS\system32\_000021_.tmp.dll (5.1.2600.5512)

18.797: Destination:

18.797: Source:C:\WINDOWS\system32\_000022_.tmp.dll (5.1.2600.5512)

18.797: Destination:

18.797: Source:C:\WINDOWS\system32\SET232.tmp (5.1.2600.5755)

Page 13: Mystery 1

18.797: Destination:C:\WINDOWS\system32\rpcss.dll (5.1.2600.5512)

18.797: Source:C:\WINDOWS\system32\WBEM\SET234.tmp (5.1.2600.5755)

18.797: Destination:C:\WINDOWS\system32\WBEM\wmiprvse.exe (5.1.2600.5512)

18.797: Source:C:\WINDOWS\system32\WBEM\SET235.tmp (5.1.2600.5755)

18.797: Destination:C:\WINDOWS\system32\WBEM\wmiprvsd.dll (5.1.2600.5512)

18.797: Source:C:\WINDOWS\system32\WBEM\SET236.tmp (5.1.2600.5755)

18.797: Destination:C:\WINDOWS\system32\WBEM\fastprox.dll (5.1.2600.5512)

21.078: UpdateSpUpdSvcInf: Source [ProcessesToRunAfterReboot] section is empty; nothing to do.

21.078: IsRebootRequiredForFileQueue: At least one file operation was delayed; reboot is required.

If none are listed below, check above for delayed deletes.

21.078: IsRebootRequiredForFileQueue: c:\windows\system32\wbem\wmiprvse.exe was delayed; reboot is required.

21.078: IsRebootRequiredForFileQueue: c:\windows\system32\wbem\wmiprvsd.dll was delayed; reboot is required.

21.078: IsRebootRequiredForFileQueue: c:\windows\system32\services.exe was no-delay replaced; reboot is required.

21.078: IsRebootRequiredForFileQueue: c:\windows\system32\rpcss.dll was delayed; reboot is required.

21.078: IsRebootRequiredForFileQueue: c:\windows\system32\ntoskrnl.exe was no-delay replaced; reboot is required.

21.078: IsRebootRequiredForFileQueue: c:\windows\system32\ntkrnlpa.exe was no-delay replaced; reboot is required.

21.078: IsRebootRequiredForFileQueue: c:\windows\system32\ntdll.dll was no-delay replaced; reboot is required.

21.078: IsRebootRequiredForFileQueue: c:\windows\system32\lsasrv.dll was no-delay replaced; reboot is required.

21.078: IsRebootRequiredForFileQueue: c:\windows\system32\wbem\fastprox.dll was delayed; reboot is required.

21.078: IsRebootRequiredForFileQueue: c:\windows\system32\advapi32.dll was no-delay replaced; reboot is required.

Page 14: Mystery 1

21.078: DoInstallation: A reboot is required to complete the installation of one or more files.

21.093: DoInstallation: A reboot is required because the ProcessesToRunAfterReboot inf section was non-empty.

21.140: RebootNecessary = 1,WizardInput = 1 , DontReboot = 1, ForceRestart = 0