Antivirus et Demarrage

Bonjour,
je viens de formater mon disque dur et j'ai un problème avec l'installation de n'importe quel antivirus.en fait les applications qui s'exécutent au démarrage de windows bloque l'antivirus.aidez moi je fais comment?merci d'avance.
Configuration: Windows XP
Firefox 3.0.1

7 réponses

  1. Contributeur sécurité
    Bonjour,

    pourrais-tu être un peu plus explicite stp ?? De quelles applications parles-tu ??
    0
    1. concernant les applications, il s'agit de n'importe quelle application qui s'exécute au démarrage comme super copieur,window messenger etc.Aussi dès que j'exécute msconfig je dois désactiver des éléments de démarrage comme igfxpers, igfxtray et d'autres aussi.aidez moi à résoudre cela s'il vous plait
      0
      1. Contributeur sécurité
        Bonjour,

        ▶ Télécharge Random's System Information Tool (RSIT).

        ▶ Un tutoriel sera à ta disposition sur mon site web pour l'installer et l'utiliser correctement.

        ▶ Double clique sur RSIT.exe pour lancer l'outil.

        ▶ Clique sur 'Continue' à l'écran Disclaimer.

        ▶ Si l'outil Hijackthis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

        ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports.

        ( C:\RSIT\log.txt et C:\RSIT\info.txt )

        CTRL A pour sélectionner tout, CTRL C pour copier et puis CTRL V pour coller
        0
        1. info.txt logfile of random's system information tool 1.06 2009-05-11 22:19:10

          ======Uninstall list======

          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
          Advanced Mass Sender 4.3-->C:\PROGRA~1\MASSSE~1\UNWISE.EXE C:\PROGRA~1\MASSSE~1\INSTALL.LOG
          Assistant Publication de sites Web Microsoft 1.53-->RunDll32 ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\wpie3x86.inf,WebPostUninstall
          Correctif pour Windows XP (KB942288-v3)-->"C:\WINDOWS\$NtUninstallKB942288-v3$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
          Dev-C++ 5 beta 9 release (4.9.9.2)-->"d:\Dev-Cpp\uninstall.exe"
          EVEREST Home Edition v2.20-->"D:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
          High Definition Audio - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
          HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
          iMesh-->C:\Program Files\iMesh Applications\iMesh\UninstallSurvey.exe C:\Program Files\iMesh Applications\iMesh\UnwiseLauncher.exe /A C:\PROGRA~1\IMESHA~1\iMesh\INSTALL.LOG
          Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
          Intel(R) PRO Network Connections Drivers-->Prounstl.exe
          Kaspersky Internet Security 7.0-->MsiExec.exe /I{C774410D-3EF9-4DE7-AC01-332613163ECF}
          Kaspersky Internet Security 7.0-->MsiExec.exe /I{C774410D-3EF9-4DE7-AC01-332613163ECF}
          K-Lite Codec Pack 3.9.0 Full-->"D:\Program Files\K-Lite Codec Pack\unins000.exe"
          LightScribe System Software 1.14.25.1-->MsiExec.exe /X{DA9DAC64-C947-47BA-B411-8A1959B177CF}
          MediaBar 2.0-->C:\Program Files\iMesh Applications\iMesh MediaBar\Uninstall.exe
          Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Microsoft Visual Studio 6.0 Édition Professionnelle (Français)-->"D:\Program Files\Microsoft Visual Studio\Common\Setup\1036\Setup.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
          Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB944338-v2)-->"C:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB963027)-->"C:\WINDOWS\$NtUninstallKB963027$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
          Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
          Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
          Rhapsody Player Engine-->MsiExec.exe /I{8A62A068-3FD6-495A-9F66-26FE94F32EC9}
          Shareaza MediaBar-->C:\Program Files\Shareaza Applications\Shareaza MediaBar\Uninstall.exe
          Shareaza-->D:\Program Files\Shareaza Applications\Shareaza\UninstallSurvey.exe D:\PROGRA~1\SHAREA~1\Shareaza\UNWISE.EXE D:\PROGRA~1\SHAREA~1\Shareaza\INSTALL.LOG
          Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
          SuperCopier2-->"D:\Program Files\SuperCopier2\SC2Uninst.exe"
          Total Video Converter 3.10-->"D:\Program Files\Total Video Converter\unins000.exe"
          USB PC Camera-168-->C:\Program Files\InstallShield Installation Information\{ECD03DA7-5952-406A-8156-5F0C93618D1F}\setup.exe -runfromtemp -l0x040c -removeonly
          VLC media player 0.9.6-->D:\Program Files\VideoLAN\VLC\uninstall.exe
          Windows Live Messenger-->MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
          Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
          WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
          Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
          Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\unyt.exe

          ======Security center information======

          AV: Kaspersky Internet Security (outdated)
          FW: Kaspersky Internet Security

          ======System event log======

          Computer Name: PERSO-336EC5C49
          Event Code: 26
          Message: Application popup : Windows - Pas de disque : Il n'y a pas de disque dans le lecteur. Insérez un disque dans le lecteur .

          Record Number: 2062
          Source Name: Application Popup
          Time Written: 20090429165052.000000+120
          Event Type: Informations
          User:

          Computer Name: PERSO-336EC5C49
          Event Code: 26
          Message: Application popup : Windows - Pas de disque : Il n'y a pas de disque dans le lecteur. Insérez un disque dans le lecteur .

          Record Number: 2061
          Source Name: Application Popup
          Time Written: 20090429165051.000000+120
          Event Type: Informations
          User:

          Computer Name: PERSO-336EC5C49
          Event Code: 26
          Message: Application popup : Windows - Pas de disque : Il n'y a pas de disque dans le lecteur. Insérez un disque dans le lecteur .

          Record Number: 2060
          Source Name: Application Popup
          Time Written: 20090429165051.000000+120
          Event Type: Informations
          User:

          Computer Name: PERSO-336EC5C49
          Event Code: 7036
          Message: Le service Machine Debug Manager est entré dans l'état : en cours d'exécution.

          Record Number: 2059
          Source Name: Service Control Manager
          Time Written: 20090429165047.000000+120
          Event Type: Informations
          User:

          Computer Name: PERSO-336EC5C49
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service Machine Debug Manager.

          Record Number: 2058
          Source Name: Service Control Manager
          Time Written: 20090429165047.000000+120
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          =====Application event log=====

          Computer Name: PERSO-336EC5C49
          Event Code: 1800
          Message: Le service Centre de sécurité Windows a démarré.

          Record Number: 561
          Source Name: SecurityCenter
          Time Written: 20090503094430.000000+120
          Event Type: Informations
          User:

          Computer Name: PERSO-336EC5C49
          Event Code: 4
          Message: The LightScribe Service started successfully.

          Record Number: 560
          Source Name: LightScribeService
          Time Written: 20090503094423.000000+120
          Event Type: Informations
          User:

          Computer Name: PERSO-336EC5C49
          Event Code: 101
          Message: msnmsgr (1276) Le moteur de base de données est arrêté.

          Record Number: 559
          Source Name: ESENT
          Time Written: 20090502180550.000000+120
          Event Type: Informations
          User:

          Computer Name: PERSO-336EC5C49
          Event Code: 103
          Message: msnmsgr (1276) \\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\zlawrence3@hotmail.com\SharingMetadata\Working\database_10E0_F34D_E0F3_3794\dfsr.db: Le moteur de base de données a arrêté une instance (0).

          Record Number: 558
          Source Name: ESENT
          Time Written: 20090502180550.000000+120
          Event Type: Informations
          User:

          Computer Name: PERSO-336EC5C49
          Event Code: 102
          Message: msnmsgr (1276) \\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\zlawrence3@hotmail.com\SharingMetadata\Working\database_10E0_F34D_E0F3_3794\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

          Record Number: 557
          Source Name: ESENT
          Time Written: 20090502171558.000000+120
          Event Type: Informations
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
          "PROCESSOR_REVISION"=0f0d
          "NUMBER_OF_PROCESSORS"=1
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP

          -----------------EOF-----------------
          voici le second

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by Administrateur at 2009-05-11 22:20:35
          Microsoft Windows XP Professionnel Service Pack 2
          System drive C: has 1 GB (13%) free of 10 GB
          Total RAM: 1014 MB (57% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 22:20:37, on 11/05/2009
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\WINDOWS\system32\svchost.exe
          D:\Program Files\SuperCopier2\SuperCopier2.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\WINDOWS\system32\NOTEPAD.EXE
          C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
          C:\Program Files\trend micro\Administrateur.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.imesh.com/sidebar.html?src=ssb
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.com/intl/
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe, "C:\WINDOWS\system32\M5VBVM60.EXE StartUp"
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshIEHelper.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: UrlHelper Class - {CFC4F59B-A2DA-4e12-B337-52A4F871E10C} - C:\Program Files\Shareaza Applications\Shareaza MediaBar\ShareazaIEHelper.dll
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O3 - Toolbar: Shareaza MediaBar - {196C3A46-4758-433D-A600-802C804AF39C} - C:\Program Files\Shareaza Applications\Shareaza MediaBar\ShareazaMediaBar.dll
          O3 - Toolbar: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll
          O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: Dos Optimizer.pif = ?
          O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
          O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O17 - HKLM\System\CCS\Services\Tcpip\..\{A50C74AE-419E-4EB2-9C3F-E52FFD264C6C}: NameServer = 41.222.192.9,41.222.192.10
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          0
      2. Contributeur sécurité
        Ton PC est très infecté... Commence par faire ceci stp :

        ▶ Télécharger SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.

        ▶ Double cliquer sur SDFix.exe et choisir Install pour l'extraire dans un dossier dédié sur ton disque C:.

        /!\ Démarre en mode sans échec : après le bip et avant le logo windows tapoter sur la touche F8 (ou F5): menu M.S.E..

        Comment redémarrer en mode sans échec ??

        ▶ Choisir son compte, pas celui de l'Administrateur ou autre.

        Dérouler la liste des instructions ci-dessous :

        • Ouvrir le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
        • Appuyer sur Y pour commencer le processus de nettoyage.
        • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
        • Appuyer sur une touche pour redémarrer le PC.
        • Le système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
        • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
        • Appuyer sur une touche pour finir l'exécution du script et charger les icônes du Bureau.
        • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
        • Enfin, copier/coller le contenu du fichier Report.txt dans la prochaine réponse sur le forum
        0
        1. bonsoir,j'ai bien bien reçu votre méssage mais des que je veux démarrer en mode sans échec le pc refuse.je l'ai essayer près de 10 fois mais rien n'a faire.il demarre seulement window normalement.en plus je ne possède qu'un seul compte c'est à dire l'administrateur.dois créer un autre compte?
          0
      3. Contributeur sécurité
        Bonsoir,

        ▶ Telecharge FindyKill sur ton bureau

        ▶ tutoriel installation

        ▶ tutoriel recherche

        /!\ Ne fait pas le nettoyage tout dessuite /!\

        ▶ Lance l installation avec les parametres par default

        ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

        ▶ Double clic sur le raccourci FindyKill sur ton bureau

        ▶ Au menu principal,choisi l option 1 (Recherche)

        ▶ Post le rapport FindyKill.txt

        * Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
        0
        1. voici le rapport
          ############################## [ FindyKill V4.728 ]

          # User : Administrateur (Administrateurs) # PERSO-336EC5C49
          # Update on 13/05/09 by Chiquitine29
          # Start at: 11:18:30 | 17/05/2009
          # Website : http://pagesperso-orange.fr/NosTools/findykill.html

          # Intel(R) Pentium(R) Dual CPU E2160 @ 1.80GHz
          # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
          # Internet Explorer 6.0.2900.2180
          # Windows Firewall Status : Disabled
          # AV : Kaspersky Internet Security 7.0.0.125 [ Enabled | (!) Outdated ]
          # FW : Kaspersky Internet Security[ (!) Disabled ]7.0.0.125

          # C:\ # Disque fixe local # 9,77 Go (1,37 Go free) # NTFS
          # D:\ # Disque fixe local # 41,62 Go (40,57 Go free) # NTFS
          # E:\ # Disque fixe local # 97,65 Go (96 Go free) # NTFS
          # F:\ # Disque amovible
          # G:\ # Disque amovible
          # H:\ # Disque amovible
          # I:\ # Disque amovible
          # J:\ # Disque CD-ROM

          ############################## [ Processus actifs ]

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\WgaTray.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\vsnpstd3.exe
          C:\Program Files\MSN Messenger\msnmsgr.exe
          C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\Dos Optimizer.pif
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wineunx.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          ################## [ Fichiers / Dossiers infectieux ]

          ################## [ Infected Temp Files ]

          ################## [ Registre / Clés infectieuses ]

          ################## [ Recherche dans supports amovibles]

          ################## [ Registre / Mountpoints2 ]

          # -> Not found !

          ################## [ ! Fin du rapport # FindyKill V4.728 ! ]
          0
      4. Contributeur sécurité
        Bonjour,

        as-tu essayé de redémarrer en mode sans échec avec la touche F5 ??
        0
        1. bonsoir,
          Oui j'ai essayé de démarrer en mode sans échec mais ça ne prends pas toujours.je ne peux pas faire le nettoyage en mode normal?Aussi dois-je créer un autre compte invité dans le quel je dois faire le nettoyage?
          0
        2. @muriinfosalut.je n'ai plus eu de vos news.j'espère que vous vous portez bien.bon c'est pour dire que j'ai exécuté findkil et j'ai utiliser l'option 2 puis en ensuite j'ai démarré en mode sans échec et j'ai exécuté SDFIX et voici le rapport.
          [b]SDFix: Version 1.240 [/b]
          Run by Administrateur on 24/05/2009 at 15:37

          Microsoft Windows XP [version 5.1.2600]
          Running From: C:\SDFix

          [b]Checking Services [/b]:

          Restoring Default Security Values
          Restoring Default Hosts File

          Rebooting

          [b]Checking Files [/b]:

          Trojan Files Found:

          C:\Documents and Settings\Administrateur\Application Data\smss.exe - Deleted

          Removing Temp Files

          [b]ADS Check [/b]:

          [b]Final Check [/b]:

          catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2009-05-24 15:40:39
          Windows 5.1.2600 Service Pack 3 NTFS

          scanning hidden processes ...

          scanning hidden services & system hive ...

          scanning hidden registry entries ...

          scanning hidden files ...

          scan completed successfully
          hidden processes: 0
          hidden services: 0
          hidden files: 0

          [b]Remaining Services [/b]:

          Authorized Application Key Export:

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
          "C:\\WINDOWS\\system32\\igfxtray.exe"="C:\\WINDOWS\\system32\\igfxtray.exe:*:Enabled:ipsec"
          "C:\\WINDOWS\\system32\\hkcmd.exe"="C:\\WINDOWS\\system32\\hkcmd.exe:*:Enabled:ipsec"
          "C:\\WINDOWS\\system32\\igfxpers.exe"="C:\\WINDOWS\\system32\\igfxpers.exe:*:Enabled:ipsec"
          "C:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 7.0\\avp.exe"="C:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 7.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"
          "K:\\nmao.exe"="K:\\nmao.exe:*:Enabled:ipsec"
          "C:\\WINDOWS\\Explorer.EXE"="C:\\WINDOWS\\Explorer.EXE:*:Enabled:ipsec"
          "K:\\Visual Basic\\devstudio6cd2\\DISK1\\SETUP.EXE"="K:\\Visual Basic\\devstudio6cd2\\DISK1\\SETUP.EXE:*:Enabled:ipsec"
          "C:\\Documents and Settings\\Administrateur\\Bureau\\Visual Basic\\devstudio6cd2\\DISK1\\SETUP.EXE"="C:\\Documents and Settings\\Administrateur\\Bureau\\Visual Basic\\devstudio6cd2\\DISK1\\SETUP.EXE:*:Enabled:ipsec"
          "D:\\PROGRA~1\\TOTALV~1\\regsvr32.exe"="D:\\PROGRA~1\\TOTALV~1\\regsvr32.exe:*:Enabled:ipsec"
          "C:\\WINDOWS\\system32\\netsh.exe"="C:\\WINDOWS\\system32\\netsh.exe:*:Enabled:ipsec"
          "C:\\Program Files\\MSN\\MSNCoreFiles\\Install\\msnsusii.exe"="C:\\Program Files\\MSN\\MSNCoreFiles\\Install\\msnsusii.exe:*:Enabled:ipsec"
          "C:\\Program Files\\Fichiers communs\\LightScribe\\LightScribeControlPanel.exe"="C:\\Program Files\\Fichiers communs\\LightScribe\\LightScribeControlPanel.exe:*:Enabled:ipsec"
          "K:\\exlsu.pif"="K:\\exlsu.pif:*:Enabled:ipsec"
          "C:\\Program Files\\MSN\\MsnInstaller\\msninst.exe"="C:\\Program Files\\MSN\\MsnInstaller\\msninst.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xtqbal.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xtqbal.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpasw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpasw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\amhb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\amhb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tafx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tafx.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\okjjhg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\okjjhg.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lgad.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lgad.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxnnen.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxnnen.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nwtl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nwtl.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fyyyxq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fyyyxq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winahevj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winahevj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winisthax.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winisthax.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpdjl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpdjl.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnnypk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnnypk.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fmim.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fmim.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windstsyp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windstsyp.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fhqw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fhqw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincubajr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincubajr.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmiim.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmiim.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jshtk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jshtk.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bpcphy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bpcphy.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\oolv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\oolv.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mqyq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mqyq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingjvbrf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingjvbrf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmtvpp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmtvpp.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\meinva.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\meinva.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvsvjwf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvsvjwf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingvbogt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingvbogt.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vagw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vagw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkrfow.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkrfow.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nmqi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nmqi.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mfkoq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mfkoq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfrmum.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfrmum.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxecvd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxecvd.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnsvfj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnsvfj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\oybhw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\oybhw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nflw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nflw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwcmy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwcmy.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ywayf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ywayf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjftsyo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjftsyo.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwwrx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwwrx.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ctafqf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ctafqf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxswp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxswp.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkcxe.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkcxe.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dxanm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dxanm.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windubv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windubv.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\msmb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\msmb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gene.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gene.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\rtlcuf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\rtlcuf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincecjo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincecjo.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ntqbs.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ntqbs.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\luemhf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\luemhf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mscw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mscw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jkef.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jkef.exe:*:Enabled:ipsec"
          "C:\\WINDOWS\\vsnpstd3.exe"="C:\\WINDOWS\\vsnpstd3.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrglpfr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrglpfr.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winoydbj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winoydbj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winltufu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winltufu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dvejo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dvejo.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsjrvb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsjrvb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuufu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuufu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qste.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qste.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winifldr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winifldr.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpbwe.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpbwe.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ssrl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ssrl.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winongrv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winongrv.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsihewt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsihewt.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwlhh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwlhh.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jskxyd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jskxyd.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingfnu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingfnu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gckyom.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gckyom.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\venh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\venh.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winssxpg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winssxpg.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winomtgaa.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winomtgaa.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windqpkgy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windqpkgy.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingjcil.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingjcil.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\pqdj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\pqdj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winffrmj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winffrmj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmgkg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmgkg.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincfrjq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincfrjq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winaitniy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winaitniy.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winojdl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winojdl.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qumdyu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qumdyu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwuff.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwuff.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrtjo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrtjo.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winscibys.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winscibys.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingbya.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingbya.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gahd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gahd.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vvbqo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vvbqo.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\uoni.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\uoni.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\buqtf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\buqtf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjnsrq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjnsrq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\eujk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\eujk.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpiuf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpiuf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winltnn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winltnn.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winulkbey.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winulkbey.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xdfkei.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xdfkei.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xxxca.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xxxca.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\kuis.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\kuis.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmyonnk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmyonnk.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gayr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gayr.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dbddc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dbddc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlwrlhu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlwrlhu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ucydac.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ucydac.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkuhqxi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkuhqxi.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mxwgfl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mxwgfl.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\memeh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\memeh.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincjrc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincjrc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\solccf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\solccf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winshcgm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winshcgm.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbjyi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbjyi.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\sdbxax.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\sdbxax.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tvyvqu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tvyvqu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\kindx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\kindx.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winirbde.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winirbde.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlqgacn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlqgacn.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrjdxfr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrjdxfr.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winohvssc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winohvssc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxwwc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxwwc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ptbu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ptbu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingfohn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingfohn.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winocym.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winocym.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bdgln.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bdgln.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\srlxf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\srlxf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsxfi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsxfi.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuxde.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuxde.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ccaonp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ccaonp.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vete.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vete.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwnbxka.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwnbxka.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkvlgqr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkvlgqr.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\cwohrm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\cwohrm.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winelsky.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winelsky.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\siqobb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\siqobb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlqbb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlqbb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\exrg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\exrg.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jrwj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jrwj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnvnybn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnvnybn.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqmxth.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqmxth.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\afgli.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\afgli.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpysda.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpysda.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jilsk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jilsk.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winahjho.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winahjho.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbpyr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbpyr.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxwfho.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxwfho.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbiuce.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbiuce.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\axgdm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\axgdm.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxglqky.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxglqky.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windhov.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windhov.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dotc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dotc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxppoh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxppoh.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xsvigy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xsvigy.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsyvncw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsyvncw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\iaklmx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\iaklmx.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\afqbdy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\afqbdy.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bipog.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bipog.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\kiyaax.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\kiyaax.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsfwrai.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsfwrai.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvwusua.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvwusua.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintcmb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintcmb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ueuxio.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ueuxio.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmane.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmane.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\pnmbkg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\pnmbkg.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhnfoo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhnfoo.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxmqyqt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxmqyqt.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winccjev.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winccjev.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xeyp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xeyp.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhdrid.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhdrid.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winruotuv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winruotuv.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\rdpqca.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\rdpqca.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintvgf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintvgf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxivj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxivj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wkma.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wkma.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xjyaeb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xjyaeb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fmis.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fmis.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winukupw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winukupw.exe:*:Enabled:ipsec"
          "C:\\Documents and Settings\\Administrateur\\Bureau\\sp32395.exe"="C:\\Documents and Settings\\Administrateur\\Bureau\\sp32395.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\scgb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\scgb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\snpk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\snpk.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xqxkm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xqxkm.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\esqg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\esqg.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nqkffw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nqkffw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\cfxnil.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\cfxnil.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwnevf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwnevf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winilap.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winilap.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xsknia.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xsknia.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ndlb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ndlb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\whkeke.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\whkeke.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lagki.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lagki.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbxaiaa.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbxaiaa.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqdrlb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqdrlb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\rqqqr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\rqqqr.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lvlqq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lvlqq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmgqjg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmgqjg.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincooxu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincooxu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windgxqd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windgxqd.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wcbjhu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wcbjhu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuursaj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuursaj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windswgg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windswgg.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\stmnof.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\stmnof.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xvii.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xvii.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlctph.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlctph.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingxyyl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingxyyl.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwjjvdd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwjjvdd.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkautyy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkautyy.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuauok.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuauok.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\npuj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\npuj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjxhh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjxhh.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\uifm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\uifm.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ikms.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ikms.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windhbmol.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windhbmol.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincpaip.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincpaip.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyfgoga.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyfgoga.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bvaaqt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bvaaqt.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\owssq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\owssq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winspdqt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winspdqt.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lxka.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lxka.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpbpvj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpbpvj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvmsn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvmsn.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmjnkxu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmjnkxu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lurqn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lurqn.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvprpxw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvprpxw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dpuq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dpuq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winoviebu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winoviebu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmqdi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmqdi.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\omlu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\omlu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ckyrm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ckyrm.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windqtjy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windqtjy.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ncrd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ncrd.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingdoi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingdoi.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyssxa.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyssxa.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winocrx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winocrx.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ckbma.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ckbma.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winiinvjx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winiinvjx.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpkvd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpkvd.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjdowq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjdowq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jlyir.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jlyir.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\uenq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\uenq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqfyved.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqfyved.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfcnrdy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfcnrdy.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gksrbq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gksrbq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbjiom.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbjiom.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xfygbm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xfygbm.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkocdl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkocdl.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhqqb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhqqb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuubtxu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuubtxu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbudkee.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbudkee.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lgor.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lgor.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fyweq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fyweq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vlqj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vlqj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mnekd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mnekd.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winiaxnoc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winiaxnoc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winiebua.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winiebua.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhpll.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhpll.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xunq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xunq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\cpxwd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\cpxwd.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpbon.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpbon.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwqydft.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwqydft.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winycpbhe.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winycpbhe.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmsvs.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmsvs.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ogehy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ogehy.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winghlfrb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winghlfrb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwlsb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwlsb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winglbg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winglbg.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxsxkgg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxsxkgg.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuygbwo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuygbwo.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tfne.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tfne.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bhxyir.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bhxyir.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\twsb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\twsb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wineakupe.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wineakupe.exe:*:Enabled:ipsec"
          "C:\\Documents and Settings\\Administrateur\\Bureau\\msgr9fr.exe"="C:\\Documents and Settings\\Administrateur\\Bureau\\msgr9fr.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fbnj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fbnj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkgdtb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkgdtb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuxnb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuxnb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhhrdr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhhrdr.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winddwv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winddwv.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winedqpp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winedqpp.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\frjoc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\frjoc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkwxfpg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkwxfpg.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winowwy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winowwy.exe:*:Enabled:ipsec"
          "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwftyjt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwftyjt.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\irjqn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\irjqn.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhcva.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhcva.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhxik.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhxik.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winaltyew.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winaltyew.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nwuoc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nwuoc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmfqi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmfqi.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkujk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkujk.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ajpn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ajpn.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winekncjc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winekncjc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winybgrck.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winybgrck.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnhfyn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnhfyn.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfukhdj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfukhdj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnsrh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnsrh.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsmdf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsmdf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\hipvfo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\hipvfo.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mvxf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mvxf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winstbp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winstbp.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincbtv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincbtv.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ffse.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ffse.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjadp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjadp.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmadii.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmadii.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\apgqbd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\apgqbd.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\knqc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\knqc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsgiep.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsgiep.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winffhjxn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winffhjxn.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqgioxb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqgioxb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windkbk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windkbk.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\frtslq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\frtslq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwacpi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwacpi.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincpqoc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincpqoc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windgvd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windgvd.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ebwji.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ebwji.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvxir.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvxir.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winojtb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winojtb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tousq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tousq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vwxgyn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vwxgyn.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winycitac.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winycitac.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvroy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvroy.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\faswjr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\faswjr.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfhlk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfhlk.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dilxml.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dilxml.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincxqtnx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincxqtnx.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjuccd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjuccd.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjxqewr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjxqewr.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjdyxxr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjdyxxr.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvrfq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvrfq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winokbl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winokbl.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winywmw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winywmw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qppgm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qppgm.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlthjt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlthjt.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\taclk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\taclk.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vyjof.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vyjof.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winikybob.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winikybob.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjhywp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjhywp.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingjlcrq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingjlcrq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winolhq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winolhq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyyiu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyyiu.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvbqyj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvbqyj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\hjxry.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\hjxry.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ckdx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ckdx.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ktwp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ktwp.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wqwh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wqwh.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnvmh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnvmh.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintuil.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintuil.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwpkfmb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwpkfmb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrkil.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrkil.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winophl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winophl.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winosdbcx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winosdbcx.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windsdsdg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windsdsdg.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbdoihp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbdoihp.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpesjo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpesjo.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\txcrys.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\txcrys.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ktsx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ktsx.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmhosqa.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmhosqa.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsplwhw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsplwhw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tahqt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tahqt.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wsxvno.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wsxvno.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingsimf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingsimf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winryersl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winryersl.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\koidqh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\koidqh.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qyht.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qyht.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mxly.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mxly.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\iegjlf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\iegjlf.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxkgjb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxkgjb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bfowpa.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bfowpa.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuetjj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuetjj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winafmfxe.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winafmfxe.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\heig.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\heig.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnlvtc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnlvtc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvwogjs.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvwogjs.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrdat.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrdat.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintemsc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintemsc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkncpo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkncpo.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhpaby.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhpaby.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyaiwv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyaiwv.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gbjtwo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gbjtwo.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qcoyje.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qcoyje.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qawi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qawi.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winajvmqt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winajvmqt.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingdro.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingdro.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjyjw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjyjw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsdtnt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsdtnt.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wjpl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wjpl.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\owkpap.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\owkpap.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwwnso.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwwnso.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\hcbe.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\hcbe.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingudq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingudq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\yudpgo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\yudpgo.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winaxnujb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winaxnujb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ivnaoi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ivnaoi.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlsevhx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlsevhx.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincgiw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincgiw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqlqc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqlqc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrick.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrick.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmusj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmusj.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmbkybm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmbkybm.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winghpwhb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winghpwhb.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbfll.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbfll.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winodprxw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winodprxw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvelbal.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvelbal.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnwxuxp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnwxuxp.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\knsuw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\knsuw.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\reff.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\reff.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnnblxq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnnblxq.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\pbivdm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\pbivdm.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winliykml.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winliykml.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winobbjc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winobbjc.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\thqi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\thqi.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lcvja.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lcvja.exe:*:Enabled:ipsec"
          "C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\win
          0
      5. Contributeur sécurité
        Bonjour,

        je te conseille de faire des sauvegardes de tes documents et photos importantes sur disques amovibles (clés usb, disque dur externe ou CD/DVD) car ton PC est très infecté et la désinfection ne pourrait peut-être pas arranger les choses...

        ensuite :

        ▶ Telecharge UsbFix de C_XX & Chiquitine29

        ▶ tutoriel d'installation

        ▶ tutoriel recherche

        ▶ Lance l installation avec les parametres par default

        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

        ▶ Double clic sur le raccourci UsbFix sur ton bureau

        ▶ Choisi l'option 1 (recherche)

        ▶ Laisse travailler l'outil

        ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra

        * Note : le rapport UsbFix.txt est sauvegardé a la racine du disque

        * Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

        * Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
        0
        1. salut! avant de lancer le programme je voudrais que tu saches que mon gestionnaire de tâches n'apparaît pas car dés que je le lance j'obtient le message d'erreur suivant : le gestionnaire des tâches a été désactivé par l'administrateur.comment je fais alors.
          0