Page 1 of 2 1 2 LastLast
Results 1 to 15 of 16

Thread: Strange log files

  1. #1
    Member
    Join Date
    Nov 2002
    Posts
    235

    Strange log files

    I am getting strange log files in my C:\ directory. Below are the first few lines from one of the recent files, which are generated, it seems, each time I reboot my XP pro (SP 2) 43p Thinkpad. They seem to have something to do with the MS Installer. Can anyone tell me why I am getting these, and how to stop it? I have been deleting them, with no apparent harm.
    --------------------------------------

    === Verbose logging started: 2/4/2007 3:00:47 Build type: SHIP UNICODE 3.01.4000.2435 Calling process: C:\WINDOWS\system32\msiexec.exe ===
    MSI (c) (18:F8) [03:00:47:812]: Resetting cached policy values
    MSI (c) (18:F8) [03:00:47:812]: Machine policy value 'Debug' is 0
    MSI (c) (18:F8) [03:00:47:812]: ******* RunEngine:
    ******* Product: c:\ecfc7a747f660c631cf660f8f3\msxml.msi
    ******* Action:
    ******* CommandLine: **********
    MSI (c) (18:F8) [03:00:47:812]: Client-side and UI is none or basic: Running entire install on the server.
    MSI (c) (18:F8) [03:00:47:812]: Grabbed execution mutex.
    MSI (c) (18:F8) [03:00:47:828]: Cloaking enabled.
    MSI (c) (18:F8) [03:00:47:828]: Attempting to enable all disabled priveleges before calling Install on Server
    MSI (c) (18:F8) [03:00:47:828]: Incrementing counter to disable shutdown. Counter after increment: 0
    MSI (s) (50:40) [03:00:47:828]: Grabbed execution mutex.
    MSI (s) (50:2C) [03:00:47:828]: Resetting cached policy values
    MSI (s) (50:2C) [03:00:47:828]: Machine policy value 'Debug' is 0
    MSI (s) (50:2C) [03:00:47:828]: ******* RunEngine:
    ******* Product: c:\ecfc7a747f660c631cf660f8f3\msxml.msi

  2. #2
    Administrator Steve R Jones's Avatar
    Join Date
    May 1999
    Location
    Largo, FL.
    Posts
    5,275
    What are the names of the files?
    "Vegetarians live up to nine years longer than the rest of us...Nine horrible, worthless, baconless years."

  3. #3
    Mod w/ an attitude Sterling_Aug's Avatar
    Join Date
    Jun 1999
    Location
    Schuylkill Haven, PA 1797
    Posts
    12,786
    Quote Originally Posted by venik
    MSI (c) (18:F8) [03:00:47:828]: Cloaking enabled.

    MSI (c) (18:F8) [03:00:47:828]: Attempting to enable all disabled priveleges before calling Install on Server

    MSI (c) (18:F8) [03:00:47:828]: Incrementing counter to disable shutdown. Counter after increment: 0

    These few lines have me very worried. I would bet a weeks paycheck that you are infected with a trojan horse virus or some very nasty spyware that is attampting to steal personal data and connect to a remote server in "who knows where, probably Russia".

    I would run a full scan using Adware Away.

    http://www.adwareaway.com/

  4. #4
    Senior Member rockinup1231's Avatar
    Join Date
    May 2006
    Location
    Northern Michigan
    Posts
    942
    Yeah, that is definately it Sterling. It is resetting everything, and normal downloads should never do that, especially by themselves.

    I think I am going to use adware away too. I have three worms (not harmful, not performance killers, just sitting there) that AVG won't kill.
    MSI 870S-G46 | AMD Phenom II X4 965 @ 3.8ghz | Gigabyte Radeon 7870 Ghz Edition | 1 x 128GB Kingston HyperX SSD | 2 x WD 500GB Blue HDD | Arch Linux x64 | BFG Tech LS SERIES LS-550 550W | 2 x 4GB DDR3 1600 RAM, 2 x 2GB DDR3 1600 RAM (12 GB)

  5. #5
    Senior Member rockinup1231's Avatar
    Join Date
    May 2006
    Location
    Northern Michigan
    Posts
    942
    Thought I should mention that the trial version is only good for a scan.
    MSI 870S-G46 | AMD Phenom II X4 965 @ 3.8ghz | Gigabyte Radeon 7870 Ghz Edition | 1 x 128GB Kingston HyperX SSD | 2 x WD 500GB Blue HDD | Arch Linux x64 | BFG Tech LS SERIES LS-550 550W | 2 x 4GB DDR3 1600 RAM, 2 x 2GB DDR3 1600 RAM (12 GB)

  6. #6
    Ultimate Member Strawbs's Avatar
    Join Date
    Sep 2001
    Posts
    4,706
    yep! it's an odds on bet.

    a-squared is a free trojan scanner! it might help if adaware away doesn't do the job.

  7. #7
    Mod w/ an attitude Sterling_Aug's Avatar
    Join Date
    Jun 1999
    Location
    Schuylkill Haven, PA 1797
    Posts
    12,786
    You can try searching for the older version of Adware Away (version 2.2.8.9) which had a 15 day free trial period.

    If you can't find it, then I can email it to you.

    Let me know.

    You may also want to try Counterspy.

  8. #8
    Senior Member rockinup1231's Avatar
    Join Date
    May 2006
    Location
    Northern Michigan
    Posts
    942
    I installed a-squared full (30 day trial), got to the updater, then becuase of my FREAKING faulty psu the whole system locked up and I had to reboot. Then when I tried to use the program again it said the 30 day trial was over.

    I know it is my psu 'cause the cd I tried to get the cd rom drive to read resulted in the blinking light to dim out while blinking til it completely died out. But that is a different problem...

    Just my luck...
    MSI 870S-G46 | AMD Phenom II X4 965 @ 3.8ghz | Gigabyte Radeon 7870 Ghz Edition | 1 x 128GB Kingston HyperX SSD | 2 x WD 500GB Blue HDD | Arch Linux x64 | BFG Tech LS SERIES LS-550 550W | 2 x 4GB DDR3 1600 RAM, 2 x 2GB DDR3 1600 RAM (12 GB)

  9. #9
    Senior Member rockinup1231's Avatar
    Join Date
    May 2006
    Location
    Northern Michigan
    Posts
    942
    I was looking for that old version of Adware Away and couldn't find it since so far all the links to the download were to the new version.

    I did however find a list of related programs, I really don'r know how good they are.

    http://www.softwarelist.us/76.html
    MSI 870S-G46 | AMD Phenom II X4 965 @ 3.8ghz | Gigabyte Radeon 7870 Ghz Edition | 1 x 128GB Kingston HyperX SSD | 2 x WD 500GB Blue HDD | Arch Linux x64 | BFG Tech LS SERIES LS-550 550W | 2 x 4GB DDR3 1600 RAM, 2 x 2GB DDR3 1600 RAM (12 GB)

  10. #10
    Member
    Join Date
    Nov 2002
    Posts
    235
    Thanks-- I'll try these when I get home. However, I routinely run Spybot Search and Destroy and Adaware. I also have Norton AV running every night.
    The name of one of the files is: ecfc7a747f660c631cf660f8f3.log, but the names vary.
    I did search the MS KB-- the results were laughable, and really irrelevant, at least as far as I could see.
    Last edited by venik; 02-05-2007 at 06:51 PM.

  11. #11
    Member
    Join Date
    Nov 2002
    Posts
    235
    I have tried A squared-- it was useless, and found nothing.

  12. #12
    Member
    Join Date
    Nov 2002
    Posts
    235
    "If you can't find it, then I can email it to you."

    Thanks, Sterling-- I think it is no longer available, so if you could email it to **Email Removed so you don't get smapped to Death.** that would be great. Much appreciated.

  13. #13
    Senior Member rockinup1231's Avatar
    Join Date
    May 2006
    Location
    Northern Michigan
    Posts
    942
    Venik, you should pm (private message) him that info, this is the internet, and open to the public, ya know.
    MSI 870S-G46 | AMD Phenom II X4 965 @ 3.8ghz | Gigabyte Radeon 7870 Ghz Edition | 1 x 128GB Kingston HyperX SSD | 2 x WD 500GB Blue HDD | Arch Linux x64 | BFG Tech LS SERIES LS-550 550W | 2 x 4GB DDR3 1600 RAM, 2 x 2GB DDR3 1600 RAM (12 GB)

  14. #14
    Senior Member rockinup1231's Avatar
    Join Date
    May 2006
    Location
    Northern Michigan
    Posts
    942
    Hotmail will block the file venik, he sent it to me, I guess Hotmail does that to all apps.
    MSI 870S-G46 | AMD Phenom II X4 965 @ 3.8ghz | Gigabyte Radeon 7870 Ghz Edition | 1 x 128GB Kingston HyperX SSD | 2 x WD 500GB Blue HDD | Arch Linux x64 | BFG Tech LS SERIES LS-550 550W | 2 x 4GB DDR3 1600 RAM, 2 x 2GB DDR3 1600 RAM (12 GB)

  15. #15
    Mod w/ an attitude Sterling_Aug's Avatar
    Join Date
    Jun 1999
    Location
    Schuylkill Haven, PA 1797
    Posts
    12,786

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •