Bug
Bug
reg
32788R22FWJFW\PEV.exe UZIP 32788R22FWJFW\License\pv_5_2_2.zip 32788R22FWJFW\
32788R22FWJFW\PV.exe -kf *.pif nircmd.* ANDRE.EXE TOLO.exe Merlin.scr jalang.exe
jalangkung.exe jantungan.exe DOSEN.exe C3W3K4MPUS.exe
Killing '*.pif'
Killing 'nircmd.*'
"C:\32788R22FWJFW\nircmd.cfexe" cmdwait 1700 exec hide "~$folder.system$\cmd.exe
cf" /c 32788R22FWJFW\prep.cmd (680)
Killing 'ANDRE.EXE'
Killing 'TOLO.exe'
Killing 'Merlin.scr'
Killing 'jalang.exe'
Killing 'jalangkung.exe'
Killing 'jantungan.exe'
Killing 'DOSEN.exe'
Killing 'C3W3K4MPUS.exe'
MOVE /Y 32788R22FWJFW\PV.exe 32788R22FWJFW\PV.cfexe
The system cannot find message text for message number 0x236e in the message fil
e for Application.
32788R22FWJFW\PV.cfexe -kf *.pif nircmd.* ANDRE.EXE TOLO.exe Merlin.scr jalang.e
xe jalangkung.exe jantungan.exe DOSEN.exe C3W3K4MPUS.exe
Killing '*.pif'
Killing 'nircmd.*'
Killing 'ANDRE.EXE'
Killing 'TOLO.exe'
Killing 'Merlin.scr'
Killing 'jalang.exe'
Killing 'jalangkung.exe'
Killing 'jantungan.exe'
Killing 'DOSEN.exe'
Killing 'C3W3K4MPUS.exe'
pv: No matching processes found
PUSHD "C:\32788R22FWJFW"
IF NOT EXIST pev.cfexe COPY /Y pev.exe pev.cfexe
The system cannot find message text for message number 0x2336 in the message fil
e for Application.
IF NOT EXIST NircmdB.exe COPY /Y Nircmd.cfexe NircmdB.exe
The system cannot find message text for message number 0x2336 in the message fil
e for Application.
SET "Comspec=C:\Windows\system32\cmd.execf"
IF NOT EXIST C:\Windows\system32\cmd.exe GOTO Not_NT
IF EXIST OsVer EXIT
VER 1>OsVer
GREP.cfexe -F "5.2." OsVer
IF 1 == 0 GOTO Not_NT
GREP.cfexe -F "5.1.2" OsVer 1>XP.mac
IF 1 == 0 GOTO NT
DEL XP.mac
GREP.cfexe -F "6.0.6" OsVer 1>Vista.mac
IF 1 == 0 GOTO NT
DEL Vista.mac
GREP.cfexe -F "5.00.2" OsVer 1>W2K.mac
IF 1 == 0 GOTO NT
DEL W2K.mac
GREP.cfexe -sq "currentversion.* 6.0" OsVer00 && GOTO NT
GREP.cfexe -isq "ProductType.*WinNT" WinNT00 || GOTO Not_NT
The system cannot find message text for message number 0x236e in the message fil
e for Application.
SED.CFEXE "/^PATH=/I!d; s///; s/\x22//g" Oripath 1>OriPath00
PEV.EXE -rtf -s+901 .\OriPath00 && (
SED.CFEXE -r "s/\x22//g; s/(.{900}).*/\1/; s/;[^;]*$//" OriPath00 1>OriPath01
FOR /F "TOKENS=*" %G IN (OriPath01) DO @SET "PATH=C:\32788R22FWJFW;C:\Windows\s
ystem32;C:\Windows;C:\Windows\system32\wbem;%G"
)
IF NOT EXIST OriPath01 FOR /F "TOKENS=*" %G IN (OriPath00) DO SET "PATH=C:\32788
R22FWJFW;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;%G"
SET "PATH=C:\32788R22FWJFW;C:\Windows\system32;C:\Windows;C:\Windows\system32\wb
em;C:\Windows\system32;C:\Windows;C:\Windows\system32\Wbem;c:\Program Files (x86
)\NVIDIA Corporation\PhysX\Common;C:\Program Files (x86)\QuickTime\QTSystem\;C:\
Program Files (x86)\Common Files\DivX Shared\;C:\Windows\System32\WindowsPowerSh
ell\v1.0\"
Killing 'runonce.exe'
Killing 'grpconv.exe'
Killing 'procmon.exe'
Killing 'ANDRE.EXE'
Killing 'TOLO.exe'
Killing 'Merlin.scr'
Killing 'jalang.exe'
Killing 'jalangkung.exe'
Killing 'jantungan.exe'
Killing 'DOSEN.exe'
Killing 'C3W3K4MPUS.exe'
pv: No matching processes found
PEV -rtf --c:##5# .\* and { License.exe or 32788R22FWJFW.exe or OsVer.exe or Win
NT.exe or N_.exe } 1>temp00 && (
PV -o%f * 1>temp01
PEV -tf -t!o --files:temp01 --c:##5#b#f# 1>temp02
GREP -Fif temp00 temp02 1>temp03
SED "/.* /!d; s///" temp03 1>temp04
SED ":a; $!N; s/\n/\x22 \x22/; ta; s/.*/\x22&\x22/" temp04 1>temp05
FOR /F "TOKENS=*" %G IN (temp05) DO @NIRCMD KILLPROCESS %G
)
CALL :MDCheck
The system cannot find message text for message number 0x40002712 in the message
file for Application.
PEV -rtf -md55B01B2EF0CAB2B124AB1B19AA62FCC6B .\md5sum.pif || CALL :MDFaiL Chk
Sum_Fail
.\md5sum.pif
PEV -tf --files:files.pif --c:##5#b#f# 1>mdCheck00.dat
GREP -vs "^!MD5:" mdCheck00.dat 1>mdCheck0a.dat
GREP -Fvf md5sum.pif mdCheck0a.dat 1>mdCheck01.dat && CALL :MDFaiL
GOTO :EOF
=============================================
ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\FBI-SCANBOT\AppData\Roaming
CFLDR=32788R22FWJFW
Chksum=5B01B2EF0CAB2B124AB1B19AA62FCC6B
CLASSPATH=.;C:\Program Files (x86)\QuickTime\QTSystem\QTJava.zip
CommonProgramFiles=C:\Program Files (x86)\Common Files
CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files
CommonProgramW6432=C:\Program Files\Common Files
COMPUTERNAME=FBI-SCANBOT-H4X
ComSpec=C:\Windows\system32\cmd.execf
configsetroot=C:\Windows\ConfigSetRoot
DFSTRACINGON=FALSE
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\FBI-SCANBOT
KMD=CF23159.exe
LOCALAPPDATA=C:\Users\FBI-SCANBOT\AppData\Local
LOGONSERVER=\\FBI-SCANBOT-H4X
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\32788R22FWJFW;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:
\Windows\system32;C:\Windows;C:\Windows\system32\Wbem;c:\Program Files (x86)\NVI
DIA Corporation\PhysX\Common;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Progr
am Files (x86)\Common Files\DivX Shared\;C:\Windows\System32\WindowsPowerShell\v
1.0\
PATHEXT=.CFEXE;.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_ARCHITEW6432=AMD64
PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 23 Stepping 6, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=1706
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files (x86)
ProgramFiles(x86)=C:\Program Files (x86)
ProgramW6432=C:\Program Files
PROMPT=$
PSModulePath=C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
PUBLIC=C:\Users\Public
Qrntn=C:\Qoobox\Quarantine
QTJAVA=C:\Program Files (x86)\QuickTime\QTSystem\QTJava.zip
RKEY_=hklm\software\microsoft\windows nt\currentversion\windows
SAFEBOOT_OPTION=MINIMAL
SESSIONNAME=Console
sfxcmd="D:\FalconFour's Ultimate Boot CD v2.0\f4ubcd2\HBCD\WinTools\ComboFix.exe
"
sfxname=D:\FalconFour's Ultimate Boot CD v2.0\f4ubcd2\HBCD\WinTools\ComboFix.exe
SYSTEM=C:\Windows\system32
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\FBI-SC~1\AppData\Local\Temp
TMP=C:\Users\FBI-SC~1\AppData\Local\Temp
TRACE_FORMAT_SEARCH_PATH=\\NTREL202.ntdev.corp.microsoft.com\34FB5F65-FFEB-4B61-
BF0E-A6A76C450FAA\TraceFormat
USERDOMAIN=FBI-SCANBOT-H4X
USERNAME=FBI-SCANBOT
USERPROFILE=C:\Users\FBI-SCANBOT
windir=C:\Windows
=============================================