Professional Documents
Culture Documents
reg
Access Denied. Administrator permissions are needed to use the selected options.
Use an administrator command prompt to complete these tasks.
32788R22FWJFW\PEV.exe UZIP 32788R22FWJFW\License\pv_5_2_2.zip 32788R22FWJFW\
MOVE /Y 32788R22FWJFW\PV.exe 32788R22FWJFW\PV.cfxxe
Le texte du message associ au num ro 0x236e est introuvable dans le fichier de mess
ages pour Application.
32788R22FWJFW\PV.cfxxe -kf *.pif nircmd.* ANDRE.EXE TOLO.exe Merlin.scr jalang.e
xe jalangkung.exe jantungan.exe DOSEN.exe C3W3K4MPUS.exe cmd.exe
Killing '*.pif'
Killing 'nircmd.*'
"C:\32788R22FWJFW\nircmd.cfxxe" cmdwait 1700 exec hide "C:\Windows\system32\cmd.
execf" /c 32788R22FWJFW\prep.cmd (892)
Killing 'ANDRE.EXE'
Killing 'TOLO.exe'
Killing 'Merlin.scr'
Killing 'jalang.exe'
Killing 'jalangkung.exe'
Killing 'jantungan.exe'
Killing 'DOSEN.exe'
Killing 'C3W3K4MPUS.exe'
Killing 'cmd.exe'
PUSHD "C:\32788R22FWJFW"
IF NOT EXIST pev.cfxxe COPY /Y pev.exe pev.cfxxe
Le texte du message associ au num ro 0x2336 est introuvable dans le fichier de mess
ages pour Application.
IF NOT EXIST NircmdB.exe COPY /Y Nircmd.cfxxe NircmdB.exe
Le texte du message associ au num ro 0x2336 est introuvable dans le fichier de mess
ages pour Application.
SET "Comspec=C:\Windows\system32\cmd.execf"
IF NOT EXIST C:\Windows\system32\cmd.exe GOTO Not_NT
IF EXIST OsVer EXIT
VER 1>OsVer
GREP.cfxxe -F "5.2." OsVer
IF 1 == 0 GOTO Not_NT
GREP.cfxxe -F "5.1.2" OsVer 1>XP.mac
IF 1 == 0 GOTO NT
DEL XP.mac
GREP.cfxxe -F "6.0.6" OsVer 1>Vista.mac
IF 1 == 0 GOTO NT
DEL Vista.mac
GREP.cfxxe -F "5.00.2" OsVer 1>W2K.mac
IF 1 == 0 GOTO NT
DEL W2K.mac
GREP.cfxxe -sq "currentversion.* 6.0" OsVer00 && GOTO NT
GREP.cfxxe -isq "ProductType.*WinNT" WinNT00 || GOTO Not_NT
Le texte du message associ au num ro 0x236e est introuvable dans le fichier de mess
ages pour Application.
SED.cfxxe "/^PATH=/I!d; s///; s/\x22//g" Oripath 1>OriPath00
PEV.EXE -rtf -s+901 .\OriPath00 && (
SED.cfxxe -r "s/\x22//g; s/(.{900}).*/\1/; s/;[^;]*$//" OriPath00 1>OriPath01
FOR /F "TOKENS=*" %G IN (OriPath01) DO @SET "PATH=C:\32788R22FWJFW;C:\Windows\s
ystem32;C:\Windows;C:\Windows\system32\wbem;%G"
)
IF NOT EXIST OriPath01 FOR /F "TOKENS=*" %G IN (OriPath00) DO SET "PATH=C:\32788
R22FWJFW;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;%G"
SET "PATH=C:\32788R22FWJFW;C:\Windows\system32;C:\Windows;C:\Windows\system32\wb
em;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\hp\bin\Python;C:\P
rogram Files (x86)\Pinnacle\Shared Files\;C:\Program Files (x86)\QuickTime\QTSys
tem\"
Access Denied. Administrator permissions are needed to use the selected options.
Use an administrator command prompt to complete these tasks.
Killing 'runonce.exe'
Killing 'grpconv.exe'
Killing 'procmon.exe'
Killing 'ANDRE.EXE'
Killing 'TOLO.exe'
Killing 'Merlin.scr'
Killing 'jalang.exe'
Killing 'jalangkung.exe'
Killing 'jantungan.exe'
Killing 'DOSEN.exe'
Killing 'C3W3K4MPUS.exe'
pv: No matching processes found
PEV -rtf --c:##5# .\* and { License.exe or 32788R22FWJFW.exe or OsVer.exe or Win
NT.exe or N_.exe } 1>temp00 && (
PV -o%f * 1>temp01
PEV -tf -t!o --files:temp01 --c:##5#b#f# 1>temp02
GREP -Fif temp00 temp02 1>temp03
SED "/.* /!d; s///" temp03 1>temp04
SED ":a; $!N; s/\n/\x22 \x22/; ta; s/.*/\x22&\x22/" temp04 1>temp05
FOR /F "TOKENS=*" %G IN (temp05) DO @NIRCMD KILLPROCESS %G
)
CALL :MDCheck
Le texte du message associ au num ro 0x40002712 est introuvable dans le fichier de
messages pour Application.
PEV -rtf -md5EBD121FE8B159AF39744B86ECED1E24F .\md5sum.pif || CALL :MDFaiL Chk
Sum_Fail
.\md5sum.pif
PEV -tf --files:files.pif --c:##5#b#f# 1>mdCheck00.dat
GREP -vs "^!MD5:" mdCheck00.dat 1>mdCheck0a.dat
GREP -Fvf md5sum.pif mdCheck0a.dat 1>mdCheck01.dat && CALL :MDFaiL
GOTO :EOF
=============================================
ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\Jean-Michel\AppData\Roaming
cfExt=cfxxe
CFLDR=32788R22FWJFW
Chksum=EBD121FE8B159AF39744B86ECED1E24F
CLASSPATH=.;C:\Program Files (x86)\Java\jre6\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files (x86)\Common Files
CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files
CommonProgramW6432=C:\Program Files\Common Files
COMPUTERNAME=PC-DE-JEAN-MICH
ComSpec=C:\Windows\system32\cmd.execf
DFSTRACINGON=FALSE
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\Jean-Michel
KMD=CF27145.exe
LOCALAPPDATA=C:\Users\Jean-Michel\AppData\Local
LOGONSERVER=\\PC-DE-JEAN-MICH
MSWorksProductCode={3B160861-7250-451E-B5EE-8B92BF30A710}
NUMBER_OF_PROCESSORS=4
OnlineServices=Online Services
OS=Windows_NT
Path=C:\32788R22FWJFW;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:
\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\hp\bin\Python;C:\Progra
m Files (x86)\Pinnacle\Shared Files\;C:\Program Files (x86)\QuickTime\QTSystem\
PATHEXT=.cfxxe;.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PCBRAND=Pavilion
Platform=HPD
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_ARCHITEW6432=AMD64
PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=170a
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files (x86)
ProgramFiles(x86)=C:\Program Files (x86)
ProgramW6432=C:\Program Files
PROMPT=$
PUBLIC=C:\Users\Public
Qrntn=C:\Qoobox\Quarantine
QTJAVA=C:\Program Files (x86)\Java\jre6\lib\ext\QTJava.zip
RKEY_=hklm\software\microsoft\windows nt\currentversion\windows
SAFEBOOT_OPTION=NETWORK
SESSIONNAME=Console
sfxcmd="C:\ComboFix.exe"
sfxname=C:\ComboFix.exe
SYSTEM=C:\Windows\system32
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\JEAN-M~1\AppData\Local\Temp
TMP=C:\Users\JEAN-M~1\AppData\Local\Temp
TRACE_FORMAT_SEARCH_PATH=\\NTREL202.ntdev.corp.microsoft.com\34FB5F65-FFEB-4B61-
BF0E-A6A76C450FAA\TraceFormat
USERDOMAIN=PC-de-Jean-Mich
USERNAME=Jean-Michel
USERPROFILE=C:\Users\Jean-Michel
windir=C:\Windows
=============================================