Is not a valid Win32 application

Solved
Hello,

I am trying to launch the latest MSN I downloaded from 01net. But when I do, it says "[...] is not a valid win32 application."
I searched through discussions for people who have had this problem, but I couldn't find a solution.
It seems there may be a virus on the computer.

Thank you for guiding me please. Thanks.

164 answers

  1. Security Contributor
    Hello,

    you downloaded a crack.

    Remove it. Otherwise, the infection will restart.

    Go to this site:
    http://www.zonavirus.com/datos/descargas/95/elibagla.asp
    at the bottom of this page, you will find a tool
    to download, click on "escargar Elibagla" (the version number changes with updates)
    install this file on the Desktop.
    then double-click on Elibagla.exe
    >leave the "eliminar ficheros automaticamente" box checked
    >click on "explorar"
    >let it work
    >post the final report which will be in c:\infosat.txt
    --

    @+
    Never accept disinfection via PM.
    3
    1. Hi, I tried ComboFix, it didn't work, and it gave me the following; Please help me.

      ComboFix 11-03-19.04 - DELL 2011-03-20 22:40:46.1.2 - x86
      Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1036.18.1022.718 [GMT -4:00]
      Started from: c:\documents and settings\DELL\Desktop\nonabagle.exe
      AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
      FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
      .
      .
      (((((((((((((((((((((((((((((((((((( Other deletions ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      c:\config\S-1-5-21-1482476501-1644491937-682003330-1013
      c:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
      c:\documents and settings\DELL\Application Data\inst.exe
      c:\program files\Search Settings
      c:\program files\Search Settings\SeARchsettings.dll
      c:\program files\Search Settings\SearchSettings.exe
      c:\program files\Search Settings\SearchSettingsRes409.dll
      .
      .
      ((((((((((((((((((((((((((((( Files created from 2011-02-21 to 2011-03-21 ))))))))))))))))))))))))))))))))))))
      .
      .
      2011-03-19 15:44 . 2011-03-19 15:44 -------- d-----w- c:\program files\CCleaner
      2011-03-19 05:55 . 2011-03-19 05:55 -------- d-----w- c:\documents and settings\DELL\Local Settings\Application Data\Identities
      2011-03-15 05:25 . 2011-03-15 05:25 137728 ----a-w- c:\windows\Ysuxya.exe
      2011-03-14 13:21 . 2011-03-14 13:21 -------- d-----w- c:\documents and settings\DELL\Local Settings\Application Data\PCHealth
      2011-02-26 17:44 . 2011-02-26 17:44 -------- d-----w- c:\program files\Common Files\Adobe
      .
      .
      (((((((((((((((((((((((((((((((((( Find3M report ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2011-02-26 14:40 . 2010-07-15 20:26 47360 ----a-w- c:\documents and settings\DELL\Application Data\pcouffin.sys
      2011-02-09 13:54 . 2004-08-05 12:00 270848 ----a-w- c:\windows\system32\sbe.dll
      2011-02-09 13:54 . 2004-08-05 12:00 186880 ----a-w- c:\windows\system32\encdec.dll
      2011-02-02 07:59 . 2007-12-21 17:00 2067456 ----a-w- c:\windows\system32\mstscax.dll
      2011-01-27 11:57 . 2007-12-21 17:00 677888 ----a-w- c:\windows\system32\mstsc.exe
      2011-01-21 14:44 . 2004-08-05 12:00 441344 ----a-w- c:\windows\system32\shimgvw.dll
      2011-01-07 14:09 . 2004-08-05 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
      2010-12-31 14:04 . 2004-08-05 12:00 1855104 ----a-w- c:\windows\system32\win32k.sys
      2010-12-22 12:34 . 2004-08-05 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
      .
      .
      ((((((((((((((((((((((((((((((((( Registry load points ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty items & legit initial items are not listed
      REGEDIT4
      .
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
      "KCSCPW1HKH"="c:\windows\Ysuxya.exe" [2011-03-15 137728]
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-17 8495104]
      "nwiz"="nwiz.exe" [2007-11-17 1626112]
      "NVHotkey"="nvHotkey.dll" [2007-11-17 86016]
      "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-17 81920]
      "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
      "Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
      "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 995328]
      "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 1101824]
      "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-15 71216]
      "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 52256]
      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
      "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
      .
      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
      .
      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
      "<no name="">"= 00 00 00 00
      .
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
      @=""
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
      "AntiVirusOverride"=dword:00000001
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
      "DisableMonitoring"=dword:00000001
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
      "DisableMonitoring"=dword:00000001
      .
      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\system32\sessmgr.exe"=
      "c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
      "%windir%\Network Diagnostic\xpnetdiag.exe"=
      "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
      "c:\\Program Files\\Messenger\\msmsgs.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      .
      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
      "AllowInboundEchoRequest"= 1 (0x1)
      .
      R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-08 380928]
      R2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [2005-10-18 61440]
      S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
      S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
      S3 EL3C574;PC Card Network Device Driver FE574B-3Com 10/100;c:\windows\system32\drivers\el574nd4.sys [2007-12-21 24653]
      S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
      .
      Contents of the 'Scheduled Tasks' folder
      .
      2011-03-20 c:\windows\Tasks\User_Feed_Synchronization-{9677DAB8-D601-4C89-A486-87DADEF7B928}.job
      - c:\windows\system32\msfeedssync.exe [2007-08-13 23:36]
      .
      2011-03-21 c:\windows\Tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job
      - c:\windows\Ysuxya.exe [2011-03-15 05:25]
      .
      .
      ------- Additional examination -------
      .
      uStart Page = hxxp://www.google.ca/
      uSearchURL,(Default) = hxxp://ca.search.yahoo.com/search?fr=mcafee&p=%s
      IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
      IE: E&xporter to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
      FF - ProfilePath - c:\documents and settings\DELL\Application Data\Mozilla\Firefox\Profiles\v4cytyzm.default\
      FF - prefs.js: browser.search.selectedEngine - Google
      FF - prefs.js: keyword.URL - hxxp://ca.search.yahoo.com/search?fr=mcafee&p=
      FF - prefs.js: network.proxy.type - 4
      FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
      FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
      FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
      FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
      .
      - - - - ORPHANS REMOVED - - - -
      .
      Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
      WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
      WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
      HKLM-Run-SigmatelSysTrayApp - %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
      HKLM-Run-SearchSettings - c:\program files\Search Settings\SearchSettings.exe
      .
      .
      .
      **************************************************************************
      .
      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2011-03-20 22:44
      Windows 5.1.2600 Service Pack 3 NTFS
      .
      Searching for hidden processes...
      .
      Searching for hidden auto start items...
      .
      Searching for hidden files...
      .
      Scan completed successfully
      Hidden files: 0
      .
      **************************************************************************
      .
      --------------------- BLOCKED REGISTRY KEYS ---------------------
      .
      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
      @Denied: (A 2) (Everyone)
      @="FlashBroker"
      "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
      "Enabled"=dword:00000001
      .
      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
      @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
      @Denied: (A 2) (Everyone)
      @="IFlashBroker4"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
      @="{00020424-0000-0000-C000-000000000046}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      "Version"="1.0"
      .
      [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€-€|ÿÿÿÿÀ*€|ù*9~*]
      "C040111900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
      .
      End time: 2011-03-20 22:46:44
      ComboFix-quarantined-files.txt 2011-03-21 02:46
      .
      Before-CF: 26 574 393 344 bytes free
      After-CF: 42 495 885 312 bytes free
      .
      WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
      [boot loader]
      timeout=2
      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
      [operating systems]
      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
      UnsupportedDebug="do not select this" /debug
      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
      .
      - - End Of File - - B3492B9C61823DDBE8BC2B9905868BE2</no>
      0
      1. remove the otmoveit folder and Script.bat too

        @+
        --
        To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
        Enjoy listening
        @ + TChiki.
        0
        1. Hi Chiquitine29. In the end, everything is going well, nothing to say. Thank you very much for everything. I will mark it as "resolved."
          Thank you for your time.
          0
      2. Hi,

        I downloaded MSN 8, it installed well. Everything is working fine. I'll update in 2 days.
        0
        1. no problem, no worries

          See you later for confirmation
          --
          To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
          Enjoy listening
          See you later TChiki.
          0
          1. Okay, thank you very much for everything. Thank you.
            0
            1. Logically, it's okay

              Yes, download Windows Live Messenger

              Use the PC normally and if you notice the message appearing, come back, but I don't believe it too much

              If within 2/3 days you don't have the message, you can mark it as resolved
              --
              Discover: Estopa, Rosario Flores, La Oreja De Van Gogh
              Good listening
              @ + TChiki.
              0
              1. OK. So is it settled or what? Can I download the right Windows Live Messenger? Or do I have to wait? And do I check at the top to say that it’s resolved?
                0
                1. ok perfect

                  let's leave it like that, if you notice the message appears come back to us

                  @++

                  Good evening
                  --
                  To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
                                     Enjoy listening
                                     @ + TChiki.
                  0
                  1. Ok it worked

                    -->- Search:

                    C:\Qoobox: found!
                    C:\_OtMoveIt: found!
                    C:\Documents and Settings\Administrator\Desktop\Dss.exe: found!
                    C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk: found!
                    C:\Documents and Settings\Administrator\Desktop\DiagHelp.zip: found!
                    C:\Documents and Settings\Administrator\Desktop\HJTInstall.exe: found!
                    C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis: found!
                    C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis\HijackThis.lnk: found!
                    C:\Program Files\Trend Micro\HijackThis: found!
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: found!

                    ---------------------------------
                    -->- Deletion:

                    C:\Documents and Settings\Administrator\Desktop\Dss.exe: deleted!
                    C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk: deleted!
                    C:\Documents and Settings\Administrator\Desktop\DiagHelp.zip: deleted!
                    C:\Documents and Settings\Administrator\Desktop\HJTInstall.exe: deleted!
                    C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis\HijackThis.lnk: deleted!
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: deleted!
                    C:\Qoobox: deleted!
                    C:\_OtMoveIt: Deletion error!
                    C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis: deleted!
                    C:\Program Files\Trend Micro\HijackThis: deleted!
                    0
                    1. YES let's see, and keep our fingers crossed
                      --
                      To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
                      Enjoy listening
                      @ + TChiki.
                      0
                      1. It was this program that I couldn't install the other day. It was also giving me the invalid win32 error. Let's see today.
                        0
                        1. Download ToolsCleaner to your desktop.
                          -->
                          ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
                          http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
                          http://pc-system.fr/

                          # Click on Search and let the scan run ...
                          # Click on Delete to finish.
                          # You can, if you wish, use the Optional Options.
                          # Click on Exit to get the report.
                          # Post the report (TCleaner.txt) that is located at the root of your hard drive (C:\).

                          --
                          To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
                                             Enjoy listening
                                             @ + TChiki.
                          0
                          1. Logfile de Trend Micro HijackThis v2.0.2
                            Analyse sauvegardée à 11:48:20, le 01/08/2008
                            Plateforme : Windows XP SP2 (WinNT 5.01.2600)
                            MSIE : Internet Explorer v7.00 (7.00.6000.16674)
                            Mode de démarrage : Normal

                            Processus en cours :
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                            C:\WINDOWS\System32\DkLog.exe
                            C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                            C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
                            C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
                            C:\WINDOWS\System32\dkcktkn.exe
                            C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
                            C:\WINDOWS\TEMP\YSEA86.EXE
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
                            C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
                            C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
                            C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
                            C:\WINDOWS\System32\00THotkey.exe
                            C:\Program Files\Apoint2K\Apoint.exe
                            C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
                            C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe
                            C:\WINDOWS\System32\ezSP_Px.exe
                            C:\WINDOWS\System32\hkcmd.exe
                            C:\WINDOWS\System32\igfxtray.exe
                            C:\WINDOWS\LTSMMSG.exe
                            C:\WINDOWS\system32\TFNF5.exe
                            C:\WINDOWS\system32\TPSMain.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                            C:\Program Files\Apoint2K\Apntex.exe
                            C:\WINDOWS\system32\TPSBattM.exe
                            C:\Program Files\OrgangeFrance\Orange Caraibes\Orange Caraibes.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
                            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
                            O4 - HKLM\..\Run: [PadTouch] "C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
                            O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
                            O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
                            O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
                            O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                            O4 - HKLM\..\Run: [DkAutoReg.exe] C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
                            O4 - HKLM\..\Run: [DkStartup] C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkStartup.exe
                            O4 - HKLM\..\Run: [Drag'n Drop CD+DVD] C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe /StartUp
                            O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
                            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
                            O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
                            O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
                            O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'SYSTEME')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'Utilisateur par défaut')
                            O4 - Démarrage global : Orange Caraibes.lnk = C:\Program Files\OrgangeFrance\Orange Caraibes\Orange Caraibes.exe
                            O9 - Bouton supplémentaire : (pas de nom) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                            O9 - Élément de menu 'Outils' supplémentaire : Désinstaller BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                            O9 - Bouton supplémentaire : Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                            O9 - Bouton supplémentaire : (pas de nom) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Élément de menu 'Outils' supplémentaire : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Bouton supplémentaire : Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Élément de menu 'Outils' supplémentaire : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O14 - IERESET.INF : START_PAGE_URL=file:///C:\Program Files\TOSHIBA\Free Update Service\splash.html
                            O16 - DPF : {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (Objet CKAVWebScan) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                            O16 - DPF : {1856D980-6604-4504-AE2E-6EEE0235FCF5} - http://www.certeurope.fr/fichiers/activesign/1.2.0.2/ActiveSign.CAB
                            O16 - DPF : {1DB93715-3B60-43EE-93E6-279BB3E1DF76} - http://213.16.24.101:8080/cab/OCXChecker_6110.cab
                            O16 - DPF : {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (Contrôle BDSCANONLINE) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                            O16 - DPF : {DBAFE6AD-DC14-45DF-A3F7-F8832289A1CD} - http://213.16.24.101:8080/cab/DownloadFile_7000.cab
                            O17 - HKLM\System\CCS\Services\Tcpip\Parameters : Domaine = vauclin.sud
                            O17 - HKLM\Software\..\Telephony : DomainName = vauclin.sud
                            O17 - HKLM\System\CS1\Services\Tcpip\Parameters : Domaine = vauclin.sud
                            O17 - HKLM\System\CS2\Services\Tcpip\Parameters : Domaine = vauclin.sud
                            O23 - Service : ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                            O23 - Service : Service Log de Datakey (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
                            O23 - Service : Service de jeton Datakey (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
                            O23 - Service : Analyse en temps réel OfficeScanNT (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
                            O23 - Service : Service Agent SoundMAX (Service par défaut SoundMAX) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                            O23 - Service : Écouteur OfficeScan NT (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
                            O23 - Service : Pare-feu OfficeScan NT (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
                            O23 - Service : Service Proxy OfficeScan NT (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe

                            --
                            Fin du fichier - 7400 octets
                            0
                            1. you execute it, you click and you click on do a system scan and save a logfile and you post the report

                              --
                              To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
                              Happy listening
                              @ + TChiki.
                              0
                              1. Am I the installation tutorial? Or do I install it without making any changes and run it directly?
                                0
                                1. YES

                                  we're going to test hijackthis to start

                                  Download HijackThis here:

                                  -> http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

                                  Installation tutorial:

                                  -> https://forums.cnetfrance.fr

                                  Usage tutorial:

                                  -> https://forums.cnetfrance.fr

                                  Please post the generated report here...

                                  --
                                  Discover: Estopa, Rosario Flores, La Oreja De Van Gogh
                                                     Enjoy listening
                                                     @ + TChiki.
                                  0
                                  1. EDIT
                                    --
                                    To discover: Estopa, Rosario Flores, La Oreja De Van Gogh
                                                       Enjoy listening
                                                       @ + TChiki.
                                    0
                                    1. So far I've been able to do everything you've asked me without seeing it. Otherwise, I wouldn't have been able to execute it.
                                      But so far, it's going well.
                                      Otherwise, do you want me to test a specific program?
                                      0
                                      1. Here

                                        C:\WINDOWS\swsc.exe moved successfully.

                                        OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08012008_113452
                                        0
                                        • 1
                                        • 2
                                        • 3
                                        • 4
                                        • 5
                                        • 6
                                        • 7
                                        • 8
                                        • 9