Is not a valid Win32 application
Solved
Hello,
I am trying to launch the latest MSN I downloaded from 01net. But when I do, it says "[...] is not a valid win32 application."
I searched through discussions for people who have had this problem, but I couldn't find a solution.
It seems there may be a virus on the computer.
Thank you for guiding me please. Thanks.
I am trying to launch the latest MSN I downloaded from 01net. But when I do, it says "[...] is not a valid win32 application."
I searched through discussions for people who have had this problem, but I couldn't find a solution.
It seems there may be a virus on the computer.
Thank you for guiding me please. Thanks.
164 answers
-
Security ContributorHello,
you downloaded a crack.
Remove it. Otherwise, the infection will restart.
Go to this site:
http://www.zonavirus.com/datos/descargas/95/elibagla.asp
at the bottom of this page, you will find a tool
to download, click on "escargar Elibagla" (the version number changes with updates)
install this file on the Desktop.
then double-click on Elibagla.exe
>leave the "eliminar ficheros automaticamente" box checked
>click on "explorar"
>let it work
>post the final report which will be in c:\infosat.txt
--
@+
Never accept disinfection via PM. -
Hi, I tried ComboFix, it didn't work, and it gave me the following; Please help me.
ComboFix 11-03-19.04 - DELL 2011-03-20 22:40:46.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1036.18.1022.718 [GMT -4:00]
Started from: c:\documents and settings\DELL\Desktop\nonabagle.exe
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
(((((((((((((((((((((((((((((((((((( Other deletions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\config\S-1-5-21-1482476501-1644491937-682003330-1013
c:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
c:\documents and settings\DELL\Application Data\inst.exe
c:\program files\Search Settings
c:\program files\Search Settings\SeARchsettings.dll
c:\program files\Search Settings\SearchSettings.exe
c:\program files\Search Settings\SearchSettingsRes409.dll
.
.
((((((((((((((((((((((((((((( Files created from 2011-02-21 to 2011-03-21 ))))))))))))))))))))))))))))))))))))
.
.
2011-03-19 15:44 . 2011-03-19 15:44 -------- d-----w- c:\program files\CCleaner
2011-03-19 05:55 . 2011-03-19 05:55 -------- d-----w- c:\documents and settings\DELL\Local Settings\Application Data\Identities
2011-03-15 05:25 . 2011-03-15 05:25 137728 ----a-w- c:\windows\Ysuxya.exe
2011-03-14 13:21 . 2011-03-14 13:21 -------- d-----w- c:\documents and settings\DELL\Local Settings\Application Data\PCHealth
2011-02-26 17:44 . 2011-02-26 17:44 -------- d-----w- c:\program files\Common Files\Adobe
.
.
(((((((((((((((((((((((((((((((((( Find3M report ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-26 14:40 . 2010-07-15 20:26 47360 ----a-w- c:\documents and settings\DELL\Application Data\pcouffin.sys
2011-02-09 13:54 . 2004-08-05 12:00 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:54 . 2004-08-05 12:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 07:59 . 2007-12-21 17:00 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2007-12-21 17:00 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2004-08-05 12:00 441344 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-08-05 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2004-08-05 12:00 1855104 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-08-05 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
.
.
((((((((((((((((((((((((((((((((( Registry load points ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty items & legit initial items are not listed
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"KCSCPW1HKH"="c:\windows\Ysuxya.exe" [2011-03-15 137728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-17 8495104]
"nwiz"="nwiz.exe" [2007-11-17 1626112]
"NVHotkey"="nvHotkey.dll" [2007-11-17 86016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-17 81920]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 995328]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 1101824]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-15 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 52256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"<no name="">"= 00 00 00 00
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-08 380928]
R2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [2005-10-18 61440]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 EL3C574;PC Card Network Device Driver FE574B-3Com 10/100;c:\windows\system32\drivers\el574nd4.sys [2007-12-21 24653]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-20 c:\windows\Tasks\User_Feed_Synchronization-{9677DAB8-D601-4C89-A486-87DADEF7B928}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 23:36]
.
2011-03-21 c:\windows\Tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job
- c:\windows\Ysuxya.exe [2011-03-15 05:25]
.
.
------- Additional examination -------
.
uStart Page = hxxp://www.google.ca/
uSearchURL,(Default) = hxxp://ca.search.yahoo.com/search?fr=mcafee&p=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporter to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\DELL\Application Data\Mozilla\Firefox\Profiles\v4cytyzm.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://ca.search.yahoo.com/search?fr=mcafee&p=
FF - prefs.js: network.proxy.type - 4
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-SigmatelSysTrayApp - %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
HKLM-Run-SearchSettings - c:\program files\Search Settings\SearchSettings.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-20 22:44
Windows 5.1.2600 Service Pack 3 NTFS
.
Searching for hidden processes...
.
Searching for hidden auto start items...
.
Searching for hidden files...
.
Scan completed successfully
Hidden files: 0
.
**************************************************************************
.
--------------------- BLOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€-€|ÿÿÿÿÀ*€|ù*9~*]
"C040111900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
End time: 2011-03-20 22:46:44
ComboFix-quarantined-files.txt 2011-03-21 02:46
.
Before-CF: 26 574 393 344 bytes free
After-CF: 42 495 885 312 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - B3492B9C61823DDBE8BC2B9905868BE2</no> -
remove the otmoveit folder and Script.bat too
@+
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki. -
Hi,
I downloaded MSN 8, it installed well. Everything is working fine. I'll update in 2 days. -
no problem, no worries
See you later for confirmation
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
See you later TChiki. -
Okay, thank you very much for everything. Thank you.
-
Logically, it's okay
Yes, download Windows Live Messenger
Use the PC normally and if you notice the message appearing, come back, but I don't believe it too much
If within 2/3 days you don't have the message, you can mark it as resolved
--
Discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Good listening
@ + TChiki. -
OK. So is it settled or what? Can I download the right Windows Live Messenger? Or do I have to wait? And do I check at the top to say that it’s resolved?
-
ok perfect
let's leave it like that, if you notice the message appears come back to us
@++
Good evening
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki. -
Ok it worked
-->- Search:
C:\Qoobox: found!
C:\_OtMoveIt: found!
C:\Documents and Settings\Administrator\Desktop\Dss.exe: found!
C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk: found!
C:\Documents and Settings\Administrator\Desktop\DiagHelp.zip: found!
C:\Documents and Settings\Administrator\Desktop\HJTInstall.exe: found!
C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis: found!
C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis\HijackThis.lnk: found!
C:\Program Files\Trend Micro\HijackThis: found!
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: found!
---------------------------------
-->- Deletion:
C:\Documents and Settings\Administrator\Desktop\Dss.exe: deleted!
C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk: deleted!
C:\Documents and Settings\Administrator\Desktop\DiagHelp.zip: deleted!
C:\Documents and Settings\Administrator\Desktop\HJTInstall.exe: deleted!
C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis\HijackThis.lnk: deleted!
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: deleted!
C:\Qoobox: deleted!
C:\_OtMoveIt: Deletion error!
C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis: deleted!
C:\Program Files\Trend Micro\HijackThis: deleted! -
YES let's see, and keep our fingers crossed
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki. -
It was this program that I couldn't install the other day. It was also giving me the invalid win32 error. Let's see today.
-
Download ToolsCleaner to your desktop.
-->
ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
http://pc-system.fr/
# Click on Search and let the scan run ...
# Click on Delete to finish.
# You can, if you wish, use the Optional Options.
# Click on Exit to get the report.
# Post the report (TCleaner.txt) that is located at the root of your hard drive (C:\).
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki. -
Logfile de Trend Micro HijackThis v2.0.2
Analyse sauvegardée à 11:48:20, le 01/08/2008
Plateforme : Windows XP SP2 (WinNT 5.01.2600)
MSIE : Internet Explorer v7.00 (7.00.6000.16674)
Mode de démarrage : Normal
Processus en cours :
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DkLog.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\System32\dkcktkn.exe
C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
C:\WINDOWS\TEMP\YSEA86.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPSMain.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\OrgangeFrance\Orange Caraibes\Orange Caraibes.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [PadTouch] "C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [DkAutoReg.exe] C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
O4 - HKLM\..\Run: [DkStartup] C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkStartup.exe
O4 - HKLM\..\Run: [Drag'n Drop CD+DVD] C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'SYSTEME')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'Utilisateur par défaut')
O4 - Démarrage global : Orange Caraibes.lnk = C:\Program Files\OrgangeFrance\Orange Caraibes\Orange Caraibes.exe
O9 - Bouton supplémentaire : (pas de nom) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Élément de menu 'Outils' supplémentaire : Désinstaller BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Bouton supplémentaire : Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Bouton supplémentaire : (pas de nom) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Élément de menu 'Outils' supplémentaire : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Bouton supplémentaire : Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Élément de menu 'Outils' supplémentaire : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF : START_PAGE_URL=file:///C:\Program Files\TOSHIBA\Free Update Service\splash.html
O16 - DPF : {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (Objet CKAVWebScan) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF : {1856D980-6604-4504-AE2E-6EEE0235FCF5} - http://www.certeurope.fr/fichiers/activesign/1.2.0.2/ActiveSign.CAB
O16 - DPF : {1DB93715-3B60-43EE-93E6-279BB3E1DF76} - http://213.16.24.101:8080/cab/OCXChecker_6110.cab
O16 - DPF : {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (Contrôle BDSCANONLINE) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF : {DBAFE6AD-DC14-45DF-A3F7-F8832289A1CD} - http://213.16.24.101:8080/cab/DownloadFile_7000.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters : Domaine = vauclin.sud
O17 - HKLM\Software\..\Telephony : DomainName = vauclin.sud
O17 - HKLM\System\CS1\Services\Tcpip\Parameters : Domaine = vauclin.sud
O17 - HKLM\System\CS2\Services\Tcpip\Parameters : Domaine = vauclin.sud
O23 - Service : ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service : Service Log de Datakey (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
O23 - Service : Service de jeton Datakey (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
O23 - Service : Analyse en temps réel OfficeScanNT (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service : Service Agent SoundMAX (Service par défaut SoundMAX) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service : Écouteur OfficeScan NT (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service : Pare-feu OfficeScan NT (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
O23 - Service : Service Proxy OfficeScan NT (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe
--
Fin du fichier - 7400 octets -
you execute it, you click and you click on do a system scan and save a logfile and you post the report
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Happy listening
@ + TChiki. -
Am I the installation tutorial? Or do I install it without making any changes and run it directly?
-
YES
we're going to test hijackthis to start
Download HijackThis here:
-> http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
Installation tutorial:
-> https://forums.cnetfrance.fr
Usage tutorial:
-> https://forums.cnetfrance.fr
Please post the generated report here...
--
Discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki. -
EDIT
--
To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
Enjoy listening
@ + TChiki. -
So far I've been able to do everything you've asked me without seeing it. Otherwise, I wouldn't have been able to execute it.
But so far, it's going well.
Otherwise, do you want me to test a specific program? -
Here
C:\WINDOWS\swsc.exe moved successfully.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08012008_113452
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
Next