February 14th, 2009, 01:39 PM
#1
Windows installer, preparing to install. What is this?
Hello folk's...
Windows installer window saying "preparing to install"
When I turn on my PC, I get this message from windows installer, again and again but it doesn't seem to be actually installing anything!
If someone could talk me through a cure for this problem, I would be very grateful as it is starting to sap my patience.
regards
BobUK
On the keyboard of life, always keep one finger on the escape key.
MS Windows 8.1 (64 bit) - Intel Core i5-440S - CPU @ 2.80 Ghz - 8.0GB RAM - AMD Radeon R7 240 - CCleaner, BullGuard, Easy Cleaner, SpyBot.
February 14th, 2009, 05:14 PM
#2
February 14th, 2009, 06:03 PM
#3
Hi SuperSparks. Many thanks for your input.
I ran, at your suggestion, MSICUU2.exe, with the following result.
Windows Script Host
C:\Users\AppData\Local\Temp\1xp000.temp Start Msi.vbs
Line 17
Char 1
Error Permission Denied
Source Microsoft VB Script runtime error
regards
BobUK
On the keyboard of life, always keep one finger on the escape key.
MS Windows 8.1 (64 bit) - Intel Core i5-440S - CPU @ 2.80 Ghz - 8.0GB RAM - AMD Radeon R7 240 - CCleaner, BullGuard, Easy Cleaner, SpyBot.
February 14th, 2009, 06:08 PM
#4
Hmmm. Try right-clicking and choose "Run as Administrator".
Nick.
February 14th, 2009, 06:39 PM
#5
Hi SuperSparks Thanks for your input
Your suggestion worked and the programme ran ok. I have just 'rebooted' and we are back to square one.
ps Does the programme run itself just from the 'run' command ?
regards
BobUK
On the keyboard of life, always keep one finger on the escape key.
MS Windows 8.1 (64 bit) - Intel Core i5-440S - CPU @ 2.80 Ghz - 8.0GB RAM - AMD Radeon R7 240 - CCleaner, BullGuard, Easy Cleaner, SpyBot.
February 14th, 2009, 07:16 PM
#6
Let's see what's running there....
Download HijackThis :
http://www.trendsecure.com/portal/en...kthis/download
by clicking on Download HijackThis Installer
Install, and run it.
Post HijackTHis log.
February 15th, 2009, 03:22 AM
#7
Hi Broni Many thanks for your input.
Here are the results from Hijack This.
regards
BobUK
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:19:50, on 15/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\Program Files\Safari\Safari.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [BullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe" -boot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\Windows\TEMP\E_S92AD.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [BullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Search - ?p=ZUxdm486YYGB
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/reso...PUplden-gb.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BullGuard LiveUpdate (BgLiveSvc) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
--
End of file - 8183 bytes
Last edited by BobUK; February 15th, 2009 at 03:37 AM .
On the keyboard of life, always keep one finger on the escape key.
MS Windows 8.1 (64 bit) - Intel Core i5-440S - CPU @ 2.80 Ghz - 8.0GB RAM - AMD Radeon R7 240 - CCleaner, BullGuard, Easy Cleaner, SpyBot.
February 15th, 2009, 01:37 PM
#8
Open HJT, and checkmark:
- O8 - Extra context menu item: &Search - ?p=ZUxdm486YYGB
Click "Fix checked" button.
Go Start, in "Start search" type:
services.msc
Hit Enter.
Services window will open.
Find:
InstallDriver Table Manager (IDriverT)
in the list.
Stop the service.
Then, right click on the service, click Properties , and under Startup type , select Disable from the drop-down menu.
Restart computer.
February 15th, 2009, 04:57 PM
#9
Broni Many thanks for your input.
I thought this would finally kill the 'beast' but to no avail.
But I do thank you for your time.
regards
BobUK
On the keyboard of life, always keep one finger on the escape key.
MS Windows 8.1 (64 bit) - Intel Core i5-440S - CPU @ 2.80 Ghz - 8.0GB RAM - AMD Radeon R7 240 - CCleaner, BullGuard, Easy Cleaner, SpyBot.
February 15th, 2009, 06:46 PM
#10
Open HJT, and see, if both of those entries are gone.
If so...
Download Autoruns for Windows : http://technet.microsoft.com/en-us/s.../bb963902.aspx
No installation required.
Simply unzip Autoruns.zip file, and double click on autoruns.exe file to run the program.
Go File>Save As, and save AutoRuns.txt file to know location.
Attach AutoRuns.txt file to your next reply.
February 16th, 2009, 11:19 AM
#11
Hi Broni Thanks for your input.
Confirming that both entries were removed/disabled.
I ran, at your suggestion, AutoRun and the result was far too long to submit.
95817 characters long which is far too big for this programme.
Have I messed up somewhere ?
regards
BobUK
On the keyboard of life, always keep one finger on the escape key.
MS Windows 8.1 (64 bit) - Intel Core i5-440S - CPU @ 2.80 Ghz - 8.0GB RAM - AMD Radeon R7 240 - CCleaner, BullGuard, Easy Cleaner, SpyBot.
February 16th, 2009, 01:45 PM
#12
February 16th, 2009, 02:49 PM
#13
Broni Many thanks for your reply/patience.
You always get at least one 'dumb-wit' sorry.
Here goes;;;
Attached Files
On the keyboard of life, always keep one finger on the escape key.
MS Windows 8.1 (64 bit) - Intel Core i5-440S - CPU @ 2.80 Ghz - 8.0GB RAM - AMD Radeon R7 240 - CCleaner, BullGuard, Easy Cleaner, SpyBot.
February 16th, 2009, 03:06 PM
#14
Let's start with disabling some unnecessary startups.
Open Autoruns, and UN-check:
EPSON Stylus DX4000 Series EPSON Status Monitor 3 SEIKO EPSON CORPORATION c:\windows\system32\spool\drivers\w32x86\3\e_fatibee.exe iTunesHelper iTunesHelper Module Apple Inc. c:\program files\itunes\ituneshelper.exe NvCplDaemon NVIDIA Display Properties Extension NVIDIA Corporation c:\windows\system32\nvcpl.dll QuickTime Task QuickTime Task Apple Inc. c:\program files\quicktime\qttask.exe SunJavaUpdateSched Java(TM) Platform SE binary Sun Microsystems, Inc. c:\program files\java\jre6\bin\jusched.exe TkBellExe RealNetworks Scheduler RealNetworks, Inc. c:\program files\common files\real\update_ob\realsched.exe WMPNSCFG Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation c:\program files\windows media player\wmpnscfg.exe
Restart computer.
Same thing?
February 16th, 2009, 06:20 PM
#15
Broni Many thanks for your input.
I unchecked the items suggested in your last efforts to correct this problem, but I have to say that the problem still exists.
Grateful thanks for your efforts.
kind regards
BobUK
On the keyboard of life, always keep one finger on the escape key.
MS Windows 8.1 (64 bit) - Intel Core i5-440S - CPU @ 2.80 Ghz - 8.0GB RAM - AMD Radeon R7 240 - CCleaner, BullGuard, Easy Cleaner, SpyBot.
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
Forum Rules