• All Community
    • All Community
    • Forums
    • Ideas
    • Blogs
Advanced

Not what you are looking for? Ask the experts!

This forum thread needs a solution.
Kudos0

?about contents of history and what it means

I can not supply more info than what I am about to give you as I reinstalled last night and wiped out history.

Unauthorized access logged (open process)

DETAILED as

ACTOR- c:\windows\system\drwtsn32.exe

ACTOR- PID

TARGET- C:\Programfiles\CommonFiles.............. (also the lower case f is accurate)

Unauthorized access blocked (Send Terminate message to window)

Detailed

ACTOR- c:\windows\system32\ctfmon.exe

TARGET- C:\ProgramFiles\NortonInternetSecurity\Engine\16.0.0.125\ccSudtst.eue      .......(I wrote .eue. Googled it and nothing, it asked exe so googled that still nothing)

REACTION- Unauthorized access blocked

There are 3 more Unauthorized access   1:logged open thread

                                                                   2:Blocked only suspend thread

                                                                   3:Blocked  Send Terminate message to window

What do these mean?

The same day had 4 attacking computers.............I found that they are from China. Does not bother me as they are being blocked but the above I truly do not understand. Any info would be appreciated.

Windows7 64 bitIE 8; Firefox v. 3.6.8NIS 2010; MBAM v.1.46; SAS v.4.34.1; SpywareBlaster

Replies

Kudos0

Re: ?about contents of history and what it means

I can not supply more info than what I am about to give you as I reinstalled last night and wiped out history.

Unauthorized access logged (open process)

DETAILED as

ACTOR- c:\windows\system\drwtsn32.exe

ACTOR- PID

TARGET- C:\Programfiles\CommonFiles.............. (also the lower case f is accurate)

Unauthorized access blocked (Send Terminate message to window)

Detailed

ACTOR- c:\windows\system32\ctfmon.exe

TARGET- C:\ProgramFiles\NortonInternetSecurity\Engine\16.0.0.125\ccSudtst.eue      .......(I wrote .eue. Googled it and nothing, it asked exe so googled that still nothing)

REACTION- Unauthorized access blocked

There are 3 more Unauthorized access   1:logged open thread

                                                                   2:Blocked only suspend thread

                                                                   3:Blocked  Send Terminate message to window

What do these mean?

The same day had 4 attacking computers.............I found that they are from China. Does not bother me as they are being blocked but the above I truly do not understand. Any info would be appreciated.

Windows7 64 bitIE 8; Firefox v. 3.6.8NIS 2010; MBAM v.1.46; SAS v.4.34.1; SpywareBlaster
Kudos0

Re: ?about contents of history and what it means

I have googled  drwtsn32.exe and it is DrWatson for Windows error debugger. I also know that ctfmon is part of Windows OS. But the rest I do not understand. I may be making this harder for myself than what it actually is.
Windows7 64 bitIE 8; Firefox v. 3.6.8NIS 2010; MBAM v.1.46; SAS v.4.34.1; SpywareBlaster
Kudos0

Re: ?about contents of history and what it means

Notice my annotations =) 

Gypsygrace wrote:

I can not supply more info than what I am about to give you as I reinstalled last night and wiped out history.

Unauthorized access logged (open process)

DETAILED as

ACTOR- c:\windows\system\drwtsn32.exe

ACTOR- PID

TARGET- C:\Programfiles\CommonFiles.............. (also the lower case f is accurate)

Unauthorized access blocked (Send Terminate message to window)

Detailed

ACTOR- c:\windows\system32\ctfmon.exe -- Advanced Text Services; reconigzed as a Keylogger by N360 b/c it is transalates keystrokes so you can type in East Asian lang. 

TARGET- C:\ProgramFiles\NortonInternetSecurity\Engine\16.0.0.125\ccSudtst.eue      .......(I wrote .eue. Googled it and nothing, it asked exe so googled that still nothing)---trying to access a Symantec related file

REACTION- Unauthorized access blocked -- Detected and blocked by Norton Product Tamper protection

There are 3 more Unauthorized access   1:logged open thread - ?

                                                                   2:Blocked only suspend thread - some1 tried to suspend Norton

                                                                   3:Blocked  Send Terminate message to window - some1 tried to terminate Norton

What do these mean?

The same day had 4 attacking computers.............I found that they are from China. Does not bother me as they are being blocked but the above I truly do not understand. Any info would be appreciated.


  1. Run a HiJackThis Scan and post the log file here. 
  2. Upload c:\windows\system\drwtsn32.exe to Virustotal.com for instant malware anylysis
  3. Same for c:\windows\system32\ctfmon.exe
Message Edited by Tech0utsider on 10-24-2008 10:02 PM
=\
Kudos0

Re: ?about contents of history and what it means

something is preventing me to send. going to send this to see if works.
Windows7 64 bitIE 8; Firefox v. 3.6.8NIS 2010; MBAM v.1.46; SAS v.4.34.1; SpywareBlaster
Kudos0

Re: ?about contents of history and what it means

Try again:Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:28:02 PM, on 10/24/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\SBC Yahoo!\Connection Manager\ConnectionManager.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Norton SystemWorks Basic Edition\CKA\CKA.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\WINDOWS\webshots.scr
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\imapi.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/norton/index.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks Basic Edition\osCheck.exe"
O4 - HKLM\..\Run: [AT&T Dial Connection Manager] C:\Program Files\SBC Yahoo!\Connection Manager\ConnectionManager.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ANONYMIZER_SPYWAREKILLER] C:\Program Files\Anonymizer\sk\SpyWareKiller.exe /BOOT /TRAY
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [SymKeepAlive] C:\Program Files\Norton SystemWorks Basic Edition\CKA\CKA.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Norton Internet Security.LNK = C:\Program Files\Norton Internet Security\Engine\16.0.0.125\uiStub.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks Basic Edition\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks Basic Edition\Norton Cleanup\WCQuick.lnk
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.symantec.com
O15 - Trusted Zone: http://www.symentec.com
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://surechat.com:9000/Java/cfs31229.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {1A781DED-C22D-4153-3213-A3211E29DF13} (GameDesire Card Games) - http://67.15.48.49/g_bin/eng/cards_2_0_0_44.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
O16 - DPF: {4B4513E2-4E57-43DF-9496-FCD37E9DFA64} (GameDesire Sea Battle) - http://67.15.101.2/g_bin/eng/navy_2_0_0_14.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/136a11582a15b97f5221/netzip/RdxIE601.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - https://mysupport.nai.com/amiuptodate/bin/1,0,0,7/McUpdatePortal.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1200266471187
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.48.49/g_bin/eng/poker_2_0_0_29.cab
O16 - DPF: {A1FE3DEF-CF77-11D4-8340-0080C8D7ED4A} (GameDesire Pinball Pirate) - http://67.15.101.2/g_bin/eng/pirate_2_0_0_14.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 - DPF: {BDD2F926-8158-4F62-9E0D-B3B75FD1F07F} (McObjectFactory Class) - http://download.mcafee.com/molbin/shared/McMySec/en-us/1,0,0,2/mcmysec.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - http://67.15.101.2/g_bin/eng/billard8_2_0_0_20.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1DFBB8D6-F2FA-410E-8A30-B8C5EB30E90C}: NameServer = 151.164.1.8 206.13.28.12
O17 - HKLM\System\CS1\Services\Tcpip\..\{1DFBB8D6-F2FA-410E-8A30-B8C5EB30E90C}: NameServer = 151.164.1.8 206.13.28.12
O22 - SharedTaskScheduler: (no name) - {F0C8173F-BC0E-4a06-ABA9-DB5A3E1FDA89} - (no file)
O23 - Service: AffinegyService - Affinegy LLC - C:\Program Files\COX\InstaLAN\AffinegyService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 11472 bytes

I do not know how to upload. How do I find the files to upload?? Thanks TechO

Windows7 64 bitIE 8; Firefox v. 3.6.8NIS 2010; MBAM v.1.46; SAS v.4.34.1; SpywareBlaster
Kudos0

Re: ?about contents of history and what it means

You can get rid of 

O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

I have also notice you have more than one Norton product installed, You have NIS 2009, plus something else, or part of a previously installed version. AS Well as something belonging to McAfee, hope is is only the spamkiller you have and nothing related to Anti virus or Antispyware as you already have Norton

You also have ANONYMIZER_SPYWAREKILLER installed and set to boot on start-up, which means you have 2 or more realtime products running, this could cause problems (a conflict).

Also remove

O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} -http://mediaplayer.walmart.com/installer/install.cab

Download Malwarebytes Antimalware http://www.malwarebytes.org/  

update the defs and do a full scan in safe mode.

Never seen "\ccSudtst.eue" before 

Quads 

Kudos0

Re: ?about contents of history and what it means

Hi

I have done a search for  "ccSudtst" on my hard drive as I have NIS 2009,   I have also manually searched for "ccSudtst" in the folder you stated in your first message, I have no such file of that name on my PC. Either ccSudtst.eue, ccSudtst.exe, ccSudtst.dll. or any other extentsion.

If you can find the file manually, so you know where it is. Please submit it to   https://submit.symantec.com/websubmit/retail.cgi

I am sure the Symantec guys would be interested if a file is pretending to be part of NIS 2009 when it may in fact not be.

Also you can upload to http://www.virustotal.com/

and wait for the results.

 For Future reference in XP if the "Ctfmon.exe" needs to be replaced due to corruption or being altered, there is a back-up copy in the "dllcache" folder     (is a hidden folder).

Quads 

Kudos0

Re: ?about contents of history and what it means

Any luck??  I have another idea, (it's hard not being personally at a PC screen) it could be a rootkit embedded within "ctfmon.exe"  then executing  "ccSudtst.eue", I still have no idea what that belongs to malware or not.

Quads 

Kudos0

Re: ?about contents of history and what it means

Hello Gypsygrace,

Can you verify to see if the file ccSudtst.eue exists on the computer in that path on your history  (C:\ProgramFiles\NortonInternetSecurity\Engine\16.0.0.125\ccSudtst.eue).

Did you manually type these history events? Were they written down? We have a component called ccSvcHst.exe which might be what the "target" really was.

In any case, it seems as through since the Unauthorized access blocked was shown, that we're working fine. The Actor was simply the program that was trying to access the Target (in this case, Symantec components). We block this, so that malware can not disable our software and infect your computer. This is our Norton Product Tamper Protection working as it should. Don't worry. It's not going to cause any problems for your other software.

I would still verify that the file above doesn't exist, just to be on the safe side. 

Kudos0

Re: ?about contents of history and what it means

I want to thank you guys for your input. I lost my internet connection that same night and it was no where to be found.

I just wrote a post  but timed out and I'm to tired to do it again. Briefly, I lost a componet or componets and was unable to even set up a dial up connection. I t kept saying I had no modem or drivers. This was the same night I posted the orignal post and the others. connection timed out and then I had nothing. I couldn't even do a system restore. I did that twice. I had 3-5 people Dell techs and my ISP having  me go through the same processes. I had  checked Device manager, I think that was the name, right now I can barely think, to check if there were any conflicts or modem unabled but they were ok.

I went to Control Panel>  phone and modem icon and they were ok

I went to Internet Properties> connection> Grayed out nothing there, should have been but wasn't.

I went to system restore and gues what I tried two dates in Oct and it could not restore. There were very few days to restore in Oct. and I was unable to go backwards to previous months. I do know that windows wipes it clean I think it is every 90 days.

Spent time on phone with 3-5 people having me go through the exact same processes and one that had tried once was to set dial up again but couldn't as it was also grayed out the only thing you could set up was DSL. Can't get here.

I ended up reformatting my C drive. Please don't ask how I did it. Okay. . Please. I'ts clean and I have spent days trying to download what I need on here and I am unable to get SP3.

I had to download SP1, SP2. I tried to get SP3 no go then SP2 was offered, no go. then only SP1 and I got it. Then SP2 and someother hotfixes and whatever but the the majority I can't seem to get to download and /or install. It's driving me crazy.

Hope everyone had a great weekend.

Windows7 64 bitIE 8; Firefox v. 3.6.8NIS 2010; MBAM v.1.46; SAS v.4.34.1; SpywareBlaster
Kudos0

Re: ?about contents of history and what it means

Hi

Try  

http://www.microsoft.com/downloads/details.aspx?FamilyID=5B33B5A8-5E76-401F-BE08-1E1555D4F3D4&displaylang=en

Although, it's the full package, I downloaded it and actually have it on a bootable CD-ROM for any future use, on my PC or others.  

Includes SP1 and 2 as well.

Quads 

Kudos0

Re: ?about contents of history and what it means

Thanks for answering my post, so fast too!!:)

I'll give it a shot. Have a nice night.

Windows7 64 bitIE 8; Firefox v. 3.6.8NIS 2010; MBAM v.1.46; SAS v.4.34.1; SpywareBlaster
Kudos0

Re: ?about contents of history and what it means

Hello Gypsygrace,

Please let me know if my post above helped with this issue. 

Kudos0

Re: ?about contents of history and what it means

Tim, is this why when you run task manager  and check the processes and services, it logs down in the alerts as an attempt to access these services?
Kudos0

Re: ?about contents of history and what it means

Hello Notechguy,

Sorry - I don't understand your question. Was this message intended for a different thread?

Kudos0

Re: ?about contents of history and what it means


Quads wrote:

Hi

Try  

http://www.microsoft.com/downloads/details.aspx?FamilyID=5B33B5A8-5E76-401F-BE08-1E1555D4F3D4&displaylang=en

Although, it's the full package, I downloaded it and actually have it on a bootable CD-ROM for any future use, on my PC or others.  

Includes SP1 and 2 as well.

Quads 


Quids,

Have had issues besides computer, so its taking me this long to get back. I checked the link and since it was for servers, and I'm one pc then I chose not to.

I get to looking around that same day and found that I had to "update" my MSI. I had no clue. But I dug around and found my WUD logs and found what I had and what it said I needed. so downloaded that and no problem. Installed SP3.

Now I have checked every so often, Add/Remove programs and SP3 is there. Has been there. since the 2nd of Nov.or the 3rd can't remember.

Today is only day I've had time to really get on pc and check things out and mail etc. I go to check my update history on windows update page and  didn't have it there. So check my WUD log and I really can't tell from that. I check Add/Remove programs and it is there. I checked the update history several times. The last time was previous to coming to this page. Anyway, it had SP3 being installed and downloaded 11/7, not the 2nd or 3rd.  I on't unstand how it could be in added programs but not in the updates per that date. As I also remember checking that also after it was downloaded and installed the 2nd or 3rd and it was listed on one of those dates.

Beats me what was going on. I found MSI was updated again, today.

I probably sound paranoid, just that I had such a hard time trying to get SP3 downloaded and installed. Got it now, I happy camper!!

Thank you for your help.

Windows7 64 bitIE 8; Firefox v. 3.6.8NIS 2010; MBAM v.1.46; SAS v.4.34.1; SpywareBlaster
Kudos2 Stats

Re: ?about contents of history and what it means

Hi There 

The link below is actually can be used for XP Home and pro, on Home Computers, I have for repairing PC's I also have XP with SP3 built in.

It's just that Microsoft would prefer Home users to use the Automatic Update instead of Millions around the world downloading the full package.

So they write  "Windows XP Service Pack 3 Network Installation Package for IT Professionals and Developers"

Brief Description

This installation package is intended for IT professionals and developers downloading and installing on multiple computers on a network. If you're updating just one computer, please visit Windows Update. "

As a deterant 


Quads wrote:

Hi

Try  

http://www.microsoft.com/downloads/details.aspx?FamilyID=5B33B5A8-5E76-401F-BE08-1E1555D4F3D4&displaylang=en

Although, it's the full package, I downloaded it and actually have it on a bootable CD-ROM for any future use, on my PC or others.  

Includes SP1 and 2 as well.

Quads 


Quads

Kudos0

Re: ?about contents of history and what it means

Hi,

Thanks for the info. You're right, they deliberately sent me away! Like I mentioned above, I had to install a current MSInstaller, first. After that I didn't think to go back to your link. Sorry

I really appreicate your time and advice, though. Thanks, Quiads

Windows7 64 bitIE 8; Firefox v. 3.6.8NIS 2010; MBAM v.1.46; SAS v.4.34.1; SpywareBlaster
Kudos0

Re: ?about contents of history and what it means

Hi Quads

just have to say great information,A while ago I did the exact same thing as Gypsygrace at first but then went back and did the download!And thanks to mijcar for putting me on to this download.

Go the AllBlacks!(rugby team)

Cheers Mo Windows 7 64 bit, NIS2013
Kudos0

Re: ?about contents of history and what it means


Quads wrote:

Hi There 

The link below is actually can be used for XP Home and pro, on Home Computers, I have for repairing PC's I also have XP with SP3 built in.

It's just that Microsoft would prefer Home users to use the Automatic Update instead of Millions around the world downloading the full package.

So they write  "Windows XP Service Pack 3 Network Installation Package for IT Professionals and Developers"

Brief Description

This installation package is intended for IT professionals and developers downloading and installing on multiple computers on a network. If you're updating just one computer, please visit Windows Update. "

As a deterant 


Quads wrote:

Hi

Try  

http://www.microsoft.com/downloads/details.aspx?FamilyID=5B33B5A8-5E76-401F-BE08-1E1555D4F3D4&displaylang=en

Although, it's the full package, I downloaded it and actually have it on a bootable CD-ROM for any future use, on my PC or others.  

Includes SP1 and 2 as well.

Quads 


Quads


I've been trying to Kudo this post and it won't stick. What could be the cause?

Windows7 64 bitIE 8; Firefox v. 3.6.8NIS 2010; MBAM v.1.46; SAS v.4.34.1; SpywareBlaster
Kudos0

Re: ?about contents of history and what it means

Hi Gypsygrace

Are you hitting the star,if you hit above the star you see who has kudo'ed before.

Cheers Mo Windows 7 64 bit, NIS2013
Kudos0

Re: ?about contents of history and what it means

Thanks mo. Did the trick!

Have a great day!

Windows7 64 bitIE 8; Firefox v. 3.6.8NIS 2010; MBAM v.1.46; SAS v.4.34.1; SpywareBlaster
Kudos0

Re: ?about contents of history and what it means

Hi Mo

The All Blacks, yeah, only just bet Munster, phew   Even the Americans will have heard of Our national team, We may be playing in Denver at the Mile High stadium, The All blacks will be paid BIG money.

Quads 

Message Edited by Quads on 11-20-2008 10:18 AM

This thread is closed from further comment. Please visit the forum to start a new thread.