Antivirus et Demarrage

Fermé
muriinfo - 4 mai 2009 à 16:35
 muriinfo - 25 mai 2009 à 16:41
Bonjour,
je viens de formater mon disque dur et j'ai un problème avec l'installation de n'importe quel antivirus.en fait les applications qui s'exécutent au démarrage de windows bloque l'antivirus.aidez moi je fais comment?merci d'avance.
A voir également:

7 réponses

geoffrey5 Messages postés 13732 Date d'inscription dimanche 20 mai 2007 Statut Contributeur sécurité Dernière intervention 21 mai 2010 10
4 mai 2009 à 16:43
Bonjour,

pourrais-tu être un peu plus explicite stp ?? De quelles applications parles-tu ??
0
concernant les applications, il s'agit de n'importe quelle application qui s'exécute au démarrage comme super copieur,window messenger etc.Aussi dès que j'exécute msconfig je dois désactiver des éléments de démarrage comme igfxpers, igfxtray et d'autres aussi.aidez moi à résoudre cela s'il vous plait
0
geoffrey5 Messages postés 13732 Date d'inscription dimanche 20 mai 2007 Statut Contributeur sécurité Dernière intervention 21 mai 2010 10
11 mai 2009 à 09:31
Bonjour,

▶ Télécharge Random's System Information Tool (RSIT).

▶ Un tutoriel sera à ta disposition sur mon site web pour l'installer et l'utiliser correctement.

▶ Double clique sur RSIT.exe pour lancer l'outil.

▶ Clique sur 'Continue' à l'écran Disclaimer.

▶ Si l'outil Hijackthis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports.

( C:\RSIT\log.txt et C:\RSIT\info.txt )

CTRL A pour sélectionner tout, CTRL C pour copier et puis CTRL V pour coller
0
info.txt logfile of random's system information tool 1.06 2009-05-11 22:19:10

======Uninstall list======

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
Advanced Mass Sender 4.3-->C:\PROGRA~1\MASSSE~1\UNWISE.EXE C:\PROGRA~1\MASSSE~1\INSTALL.LOG
Assistant Publication de sites Web Microsoft 1.53-->RunDll32 ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\wpie3x86.inf,WebPostUninstall
Correctif pour Windows XP (KB942288-v3)-->"C:\WINDOWS\$NtUninstallKB942288-v3$\spuninst\spuninst.exe"
Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Dev-C++ 5 beta 9 release (4.9.9.2)-->"d:\Dev-Cpp\uninstall.exe"
EVEREST Home Edition v2.20-->"D:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
High Definition Audio - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
iMesh-->C:\Program Files\iMesh Applications\iMesh\UninstallSurvey.exe C:\Program Files\iMesh Applications\iMesh\UnwiseLauncher.exe /A C:\PROGRA~1\IMESHA~1\iMesh\INSTALL.LOG
Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
Intel(R) PRO Network Connections Drivers-->Prounstl.exe
Kaspersky Internet Security 7.0-->MsiExec.exe /I{C774410D-3EF9-4DE7-AC01-332613163ECF}
Kaspersky Internet Security 7.0-->MsiExec.exe /I{C774410D-3EF9-4DE7-AC01-332613163ECF}
K-Lite Codec Pack 3.9.0 Full-->"D:\Program Files\K-Lite Codec Pack\unins000.exe"
LightScribe System Software 1.14.25.1-->MsiExec.exe /X{DA9DAC64-C947-47BA-B411-8A1959B177CF}
MediaBar 2.0-->C:\Program Files\iMesh Applications\iMesh MediaBar\Uninstall.exe
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual Studio 6.0 Édition Professionnelle (Français)-->"D:\Program Files\Microsoft Visual Studio\Common\Setup\1036\Setup.exe"
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB944338-v2)-->"C:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB963027)-->"C:\WINDOWS\$NtUninstallKB963027$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
Rhapsody Player Engine-->MsiExec.exe /I{8A62A068-3FD6-495A-9F66-26FE94F32EC9}
Shareaza MediaBar-->C:\Program Files\Shareaza Applications\Shareaza MediaBar\Uninstall.exe
Shareaza-->D:\Program Files\Shareaza Applications\Shareaza\UninstallSurvey.exe D:\PROGRA~1\SHAREA~1\Shareaza\UNWISE.EXE D:\PROGRA~1\SHAREA~1\Shareaza\INSTALL.LOG
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
SuperCopier2-->"D:\Program Files\SuperCopier2\SC2Uninst.exe"
Total Video Converter 3.10-->"D:\Program Files\Total Video Converter\unins000.exe"
USB PC Camera-168-->C:\Program Files\InstallShield Installation Information\{ECD03DA7-5952-406A-8156-5F0C93618D1F}\setup.exe -runfromtemp -l0x040c -removeonly
VLC media player 0.9.6-->D:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Live Messenger-->MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\unyt.exe

======Security center information======

AV: Kaspersky Internet Security (outdated)
FW: Kaspersky Internet Security

======System event log======

Computer Name: PERSO-336EC5C49
Event Code: 26
Message: Application popup : Windows - Pas de disque : Il n'y a pas de disque dans le lecteur. Insérez un disque dans le lecteur .

Record Number: 2062
Source Name: Application Popup
Time Written: 20090429165052.000000+120
Event Type: Informations
User:

Computer Name: PERSO-336EC5C49
Event Code: 26
Message: Application popup : Windows - Pas de disque : Il n'y a pas de disque dans le lecteur. Insérez un disque dans le lecteur .

Record Number: 2061
Source Name: Application Popup
Time Written: 20090429165051.000000+120
Event Type: Informations
User:

Computer Name: PERSO-336EC5C49
Event Code: 26
Message: Application popup : Windows - Pas de disque : Il n'y a pas de disque dans le lecteur. Insérez un disque dans le lecteur .

Record Number: 2060
Source Name: Application Popup
Time Written: 20090429165051.000000+120
Event Type: Informations
User:

Computer Name: PERSO-336EC5C49
Event Code: 7036
Message: Le service Machine Debug Manager est entré dans l'état : en cours d'exécution.

Record Number: 2059
Source Name: Service Control Manager
Time Written: 20090429165047.000000+120
Event Type: Informations
User:

Computer Name: PERSO-336EC5C49
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Machine Debug Manager.

Record Number: 2058
Source Name: Service Control Manager
Time Written: 20090429165047.000000+120
Event Type: Informations
User: AUTORITE NT\SYSTEM

=====Application event log=====

Computer Name: PERSO-336EC5C49
Event Code: 1800
Message: Le service Centre de sécurité Windows a démarré.

Record Number: 561
Source Name: SecurityCenter
Time Written: 20090503094430.000000+120
Event Type: Informations
User:

Computer Name: PERSO-336EC5C49
Event Code: 4
Message: The LightScribe Service started successfully.

Record Number: 560
Source Name: LightScribeService
Time Written: 20090503094423.000000+120
Event Type: Informations
User:

Computer Name: PERSO-336EC5C49
Event Code: 101
Message: msnmsgr (1276) Le moteur de base de données est arrêté.

Record Number: 559
Source Name: ESENT
Time Written: 20090502180550.000000+120
Event Type: Informations
User:

Computer Name: PERSO-336EC5C49
Event Code: 103
Message: msnmsgr (1276) \\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\zlawrence3@hotmail.com\SharingMetadata\Working\database_10E0_F34D_E0F3_3794\dfsr.db: Le moteur de base de données a arrêté une instance (0).

Record Number: 558
Source Name: ESENT
Time Written: 20090502180550.000000+120
Event Type: Informations
User:

Computer Name: PERSO-336EC5C49
Event Code: 102
Message: msnmsgr (1276) \\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\zlawrence3@hotmail.com\SharingMetadata\Working\database_10E0_F34D_E0F3_3794\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

Record Number: 557
Source Name: ESENT
Time Written: 20090502171558.000000+120
Event Type: Informations
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

-----------------EOF-----------------
voici le second

Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrateur at 2009-05-11 22:20:35
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 1 GB (13%) free of 10 GB
Total RAM: 1014 MB (57% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:20:37, on 11/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
D:\Program Files\SuperCopier2\SuperCopier2.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
C:\Program Files\trend micro\Administrateur.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.imesh.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.com/intl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe, "C:\WINDOWS\system32\M5VBVM60.EXE StartUp"
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: UrlHelper Class - {CFC4F59B-A2DA-4e12-B337-52A4F871E10C} - C:\Program Files\Shareaza Applications\Shareaza MediaBar\ShareazaIEHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Shareaza MediaBar - {196C3A46-4758-433D-A600-802C804AF39C} - C:\Program Files\Shareaza Applications\Shareaza MediaBar\ShareazaMediaBar.dll
O3 - Toolbar: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Dos Optimizer.pif = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{A50C74AE-419E-4EB2-9C3F-E52FFD264C6C}: NameServer = 41.222.192.9,41.222.192.10
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
0
geoffrey5 Messages postés 13732 Date d'inscription dimanche 20 mai 2007 Statut Contributeur sécurité Dernière intervention 21 mai 2010 10
12 mai 2009 à 01:20
Ton PC est très infecté... Commence par faire ceci stp :

▶ Télécharger SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.

▶ Double cliquer sur SDFix.exe et choisir Install pour l'extraire dans un dossier dédié sur ton disque C:.

/!\ Démarre en mode sans échec : après le bip et avant le logo windows tapoter sur la touche F8 (ou F5): menu M.S.E..

Comment redémarrer en mode sans échec ??

▶ Choisir son compte, pas celui de l'Administrateur ou autre.

Dérouler la liste des instructions ci-dessous :

• Ouvrir le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
• Appuyer sur Y pour commencer le processus de nettoyage.
• Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
• Appuyer sur une touche pour redémarrer le PC.
• Le système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
• Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
• Appuyer sur une touche pour finir l'exécution du script et charger les icônes du Bureau.
• Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
• Enfin, copier/coller le contenu du fichier Report.txt dans la prochaine réponse sur le forum
0
bonsoir,j'ai bien bien reçu votre méssage mais des que je veux démarrer en mode sans échec le pc refuse.je l'ai essayer près de 10 fois mais rien n'a faire.il demarre seulement window normalement.en plus je ne possède qu'un seul compte c'est à dire l'administrateur.dois créer un autre compte?
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
geoffrey5 Messages postés 13732 Date d'inscription dimanche 20 mai 2007 Statut Contributeur sécurité Dernière intervention 21 mai 2010 10
14 mai 2009 à 22:48
Bonsoir,

▶ Telecharge FindyKill sur ton bureau

▶ tutoriel installation

▶ tutoriel recherche

/!\ Ne fait pas le nettoyage tout dessuite /!\

▶ Lance l installation avec les parametres par default

▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

▶ Double clic sur le raccourci FindyKill sur ton bureau

▶ Au menu principal,choisi l option 1 (Recherche)

▶ Post le rapport FindyKill.txt

* Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
0
voici le rapport
############################## [ FindyKill V4.728 ]

# User : Administrateur (Administrateurs) # PERSO-336EC5C49
# Update on 13/05/09 by Chiquitine29
# Start at: 11:18:30 | 17/05/2009
# Website : http://pagesperso-orange.fr/NosTools/findykill.html

# Intel(R) Pentium(R) Dual CPU E2160 @ 1.80GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 6.0.2900.2180
# Windows Firewall Status : Disabled
# AV : Kaspersky Internet Security 7.0.0.125 [ Enabled | (!) Outdated ]
# FW : Kaspersky Internet Security[ (!) Disabled ]7.0.0.125

# C:\ # Disque fixe local # 9,77 Go (1,37 Go free) # NTFS
# D:\ # Disque fixe local # 41,62 Go (40,57 Go free) # NTFS
# E:\ # Disque fixe local # 97,65 Go (96 Go free) # NTFS
# F:\ # Disque amovible
# G:\ # Disque amovible
# H:\ # Disque amovible
# I:\ # Disque amovible
# J:\ # Disque CD-ROM

############################## [ Processus actifs ]

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\Dos Optimizer.pif
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wineunx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

################## [ Fichiers / Dossiers infectieux ]


################## [ Infected Temp Files ]


################## [ Registre / Clés infectieuses ]



################## [ Recherche dans supports amovibles]


################## [ Registre / Mountpoints2 ]

# -> Not found !

################## [ ! Fin du rapport # FindyKill V4.728 ! ]
0
geoffrey5 Messages postés 13732 Date d'inscription dimanche 20 mai 2007 Statut Contributeur sécurité Dernière intervention 21 mai 2010 10
17 mai 2009 à 11:37
Bonjour,

as-tu essayé de redémarrer en mode sans échec avec la touche F5 ??
0
bonsoir,
Oui j'ai essayé de démarrer en mode sans échec mais ça ne prends pas toujours.je ne peux pas faire le nettoyage en mode normal?Aussi dois-je créer un autre compte invité dans le quel je dois faire le nettoyage?
0
muriinfo > muriinfo
24 mai 2009 à 15:53
salut.je n'ai plus eu de vos news.j'espère que vous vous portez bien.bon c'est pour dire que j'ai exécuté findkil et j'ai utiliser l'option 2 puis en ensuite j'ai démarré en mode sans échec et j'ai exécuté SDFIX et voici le rapport.
[b]SDFix: Version 1.240 [/b]
Run by Administrateur on 24/05/2009 at 15:37

Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix

[b]Checking Services [/b]:


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


[b]Checking Files [/b]:

Trojan Files Found:

C:\Documents and Settings\Administrateur\Application Data\smss.exe - Deleted





Removing Temp Files

[b]ADS Check [/b]:



[b]Final Check [/b]:

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-24 15:40:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


[b]Remaining Services [/b]:




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\igfxtray.exe"="C:\\WINDOWS\\system32\\igfxtray.exe:*:Enabled:ipsec"
"C:\\WINDOWS\\system32\\hkcmd.exe"="C:\\WINDOWS\\system32\\hkcmd.exe:*:Enabled:ipsec"
"C:\\WINDOWS\\system32\\igfxpers.exe"="C:\\WINDOWS\\system32\\igfxpers.exe:*:Enabled:ipsec"
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 7.0\\avp.exe"="C:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 7.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"
"K:\\nmao.exe"="K:\\nmao.exe:*:Enabled:ipsec"
"C:\\WINDOWS\\Explorer.EXE"="C:\\WINDOWS\\Explorer.EXE:*:Enabled:ipsec"
"K:\\Visual Basic\\devstudio6cd2\\DISK1\\SETUP.EXE"="K:\\Visual Basic\\devstudio6cd2\\DISK1\\SETUP.EXE:*:Enabled:ipsec"
"C:\\Documents and Settings\\Administrateur\\Bureau\\Visual Basic\\devstudio6cd2\\DISK1\\SETUP.EXE"="C:\\Documents and Settings\\Administrateur\\Bureau\\Visual Basic\\devstudio6cd2\\DISK1\\SETUP.EXE:*:Enabled:ipsec"
"D:\\PROGRA~1\\TOTALV~1\\regsvr32.exe"="D:\\PROGRA~1\\TOTALV~1\\regsvr32.exe:*:Enabled:ipsec"
"C:\\WINDOWS\\system32\\netsh.exe"="C:\\WINDOWS\\system32\\netsh.exe:*:Enabled:ipsec"
"C:\\Program Files\\MSN\\MSNCoreFiles\\Install\\msnsusii.exe"="C:\\Program Files\\MSN\\MSNCoreFiles\\Install\\msnsusii.exe:*:Enabled:ipsec"
"C:\\Program Files\\Fichiers communs\\LightScribe\\LightScribeControlPanel.exe"="C:\\Program Files\\Fichiers communs\\LightScribe\\LightScribeControlPanel.exe:*:Enabled:ipsec"
"K:\\exlsu.pif"="K:\\exlsu.pif:*:Enabled:ipsec"
"C:\\Program Files\\MSN\\MsnInstaller\\msninst.exe"="C:\\Program Files\\MSN\\MsnInstaller\\msninst.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xtqbal.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xtqbal.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpasw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpasw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\amhb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\amhb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tafx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tafx.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\okjjhg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\okjjhg.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lgad.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lgad.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxnnen.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxnnen.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nwtl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nwtl.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fyyyxq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fyyyxq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winahevj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winahevj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winisthax.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winisthax.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpdjl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpdjl.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnnypk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnnypk.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fmim.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fmim.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windstsyp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windstsyp.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fhqw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fhqw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincubajr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincubajr.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmiim.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmiim.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jshtk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jshtk.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bpcphy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bpcphy.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\oolv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\oolv.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mqyq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mqyq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingjvbrf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingjvbrf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmtvpp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmtvpp.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\meinva.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\meinva.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvsvjwf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvsvjwf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingvbogt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingvbogt.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vagw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vagw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkrfow.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkrfow.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nmqi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nmqi.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mfkoq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mfkoq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfrmum.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfrmum.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxecvd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxecvd.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnsvfj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnsvfj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\oybhw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\oybhw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nflw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nflw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwcmy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwcmy.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ywayf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ywayf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjftsyo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjftsyo.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwwrx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwwrx.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ctafqf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ctafqf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxswp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxswp.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkcxe.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkcxe.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dxanm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dxanm.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windubv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windubv.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\msmb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\msmb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gene.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gene.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\rtlcuf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\rtlcuf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincecjo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincecjo.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ntqbs.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ntqbs.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\luemhf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\luemhf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mscw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mscw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jkef.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jkef.exe:*:Enabled:ipsec"
"C:\\WINDOWS\\vsnpstd3.exe"="C:\\WINDOWS\\vsnpstd3.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrglpfr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrglpfr.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winoydbj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winoydbj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winltufu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winltufu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dvejo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dvejo.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsjrvb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsjrvb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuufu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuufu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qste.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qste.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winifldr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winifldr.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpbwe.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpbwe.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ssrl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ssrl.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winongrv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winongrv.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsihewt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsihewt.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwlhh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwlhh.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jskxyd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jskxyd.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingfnu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingfnu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gckyom.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gckyom.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\venh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\venh.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winssxpg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winssxpg.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winomtgaa.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winomtgaa.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windqpkgy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windqpkgy.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingjcil.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingjcil.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\pqdj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\pqdj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winffrmj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winffrmj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmgkg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmgkg.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincfrjq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincfrjq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winaitniy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winaitniy.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winojdl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winojdl.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qumdyu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qumdyu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwuff.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwuff.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrtjo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrtjo.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winscibys.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winscibys.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingbya.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingbya.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gahd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gahd.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vvbqo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vvbqo.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\uoni.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\uoni.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\buqtf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\buqtf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjnsrq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjnsrq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\eujk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\eujk.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpiuf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpiuf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winltnn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winltnn.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winulkbey.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winulkbey.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xdfkei.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xdfkei.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xxxca.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xxxca.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\kuis.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\kuis.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmyonnk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmyonnk.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gayr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gayr.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dbddc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dbddc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlwrlhu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlwrlhu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ucydac.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ucydac.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkuhqxi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkuhqxi.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mxwgfl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mxwgfl.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\memeh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\memeh.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincjrc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincjrc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\solccf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\solccf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winshcgm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winshcgm.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbjyi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbjyi.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\sdbxax.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\sdbxax.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tvyvqu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tvyvqu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\kindx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\kindx.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winirbde.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winirbde.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlqgacn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlqgacn.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrjdxfr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrjdxfr.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winohvssc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winohvssc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxwwc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxwwc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ptbu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ptbu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingfohn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingfohn.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winocym.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winocym.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bdgln.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bdgln.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\srlxf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\srlxf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsxfi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsxfi.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuxde.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuxde.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ccaonp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ccaonp.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vete.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vete.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwnbxka.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwnbxka.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkvlgqr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkvlgqr.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\cwohrm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\cwohrm.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winelsky.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winelsky.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\siqobb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\siqobb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlqbb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlqbb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\exrg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\exrg.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jrwj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jrwj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnvnybn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnvnybn.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqmxth.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqmxth.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\afgli.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\afgli.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpysda.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpysda.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jilsk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jilsk.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winahjho.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winahjho.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbpyr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbpyr.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxwfho.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxwfho.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbiuce.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbiuce.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\axgdm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\axgdm.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxglqky.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxglqky.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windhov.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windhov.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dotc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dotc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxppoh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxppoh.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xsvigy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xsvigy.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsyvncw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsyvncw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\iaklmx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\iaklmx.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\afqbdy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\afqbdy.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bipog.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bipog.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\kiyaax.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\kiyaax.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsfwrai.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsfwrai.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvwusua.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvwusua.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintcmb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintcmb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ueuxio.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ueuxio.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmane.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmane.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\pnmbkg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\pnmbkg.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhnfoo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhnfoo.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxmqyqt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxmqyqt.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winccjev.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winccjev.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xeyp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xeyp.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhdrid.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhdrid.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winruotuv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winruotuv.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\rdpqca.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\rdpqca.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintvgf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintvgf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxivj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxivj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wkma.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wkma.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xjyaeb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xjyaeb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fmis.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fmis.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winukupw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winukupw.exe:*:Enabled:ipsec"
"C:\\Documents and Settings\\Administrateur\\Bureau\\sp32395.exe"="C:\\Documents and Settings\\Administrateur\\Bureau\\sp32395.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\scgb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\scgb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\snpk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\snpk.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xqxkm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xqxkm.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\esqg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\esqg.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nqkffw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nqkffw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\cfxnil.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\cfxnil.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwnevf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwnevf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winilap.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winilap.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xsknia.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xsknia.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ndlb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ndlb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\whkeke.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\whkeke.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lagki.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lagki.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbxaiaa.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbxaiaa.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqdrlb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqdrlb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\rqqqr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\rqqqr.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lvlqq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lvlqq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmgqjg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmgqjg.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincooxu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincooxu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windgxqd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windgxqd.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wcbjhu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wcbjhu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuursaj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuursaj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windswgg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windswgg.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\stmnof.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\stmnof.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xvii.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xvii.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlctph.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlctph.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingxyyl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingxyyl.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwjjvdd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwjjvdd.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkautyy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkautyy.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuauok.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuauok.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\npuj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\npuj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjxhh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjxhh.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\uifm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\uifm.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ikms.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ikms.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windhbmol.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windhbmol.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincpaip.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincpaip.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyfgoga.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyfgoga.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bvaaqt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bvaaqt.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\owssq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\owssq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winspdqt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winspdqt.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lxka.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lxka.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpbpvj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpbpvj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvmsn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvmsn.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmjnkxu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmjnkxu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lurqn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lurqn.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvprpxw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvprpxw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dpuq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dpuq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winoviebu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winoviebu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmqdi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmqdi.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\omlu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\omlu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ckyrm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ckyrm.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windqtjy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windqtjy.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ncrd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ncrd.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingdoi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingdoi.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyssxa.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyssxa.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winocrx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winocrx.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ckbma.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ckbma.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winiinvjx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winiinvjx.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpkvd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpkvd.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjdowq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjdowq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jlyir.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\jlyir.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\uenq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\uenq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqfyved.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqfyved.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfcnrdy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfcnrdy.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gksrbq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gksrbq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbjiom.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbjiom.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xfygbm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xfygbm.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkocdl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkocdl.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhqqb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhqqb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuubtxu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuubtxu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbudkee.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbudkee.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lgor.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lgor.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fyweq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fyweq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vlqj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vlqj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mnekd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mnekd.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winiaxnoc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winiaxnoc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winiebua.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winiebua.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhpll.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhpll.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xunq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\xunq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\cpxwd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\cpxwd.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpbon.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpbon.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwqydft.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwqydft.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winycpbhe.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winycpbhe.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmsvs.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmsvs.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ogehy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ogehy.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winghlfrb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winghlfrb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwlsb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwlsb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winglbg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winglbg.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxsxkgg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxsxkgg.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuygbwo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuygbwo.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tfne.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tfne.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bhxyir.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bhxyir.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\twsb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\twsb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wineakupe.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wineakupe.exe:*:Enabled:ipsec"
"C:\\Documents and Settings\\Administrateur\\Bureau\\msgr9fr.exe"="C:\\Documents and Settings\\Administrateur\\Bureau\\msgr9fr.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fbnj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\fbnj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkgdtb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkgdtb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuxnb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuxnb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhhrdr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhhrdr.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winddwv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winddwv.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winedqpp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winedqpp.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\frjoc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\frjoc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkwxfpg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkwxfpg.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winowwy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winowwy.exe:*:Enabled:ipsec"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwftyjt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwftyjt.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\irjqn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\irjqn.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhcva.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhcva.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhxik.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhxik.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winaltyew.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winaltyew.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nwuoc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\nwuoc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmfqi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmfqi.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkujk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkujk.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ajpn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ajpn.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winekncjc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winekncjc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winybgrck.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winybgrck.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnhfyn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnhfyn.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfukhdj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfukhdj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnsrh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnsrh.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsmdf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsmdf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\hipvfo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\hipvfo.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mvxf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mvxf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winstbp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winstbp.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincbtv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincbtv.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ffse.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ffse.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjadp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjadp.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmadii.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmadii.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\apgqbd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\apgqbd.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\knqc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\knqc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsgiep.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsgiep.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winffhjxn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winffhjxn.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqgioxb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqgioxb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windkbk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windkbk.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\frtslq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\frtslq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwacpi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwacpi.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincpqoc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincpqoc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windgvd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windgvd.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ebwji.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ebwji.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvxir.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvxir.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winojtb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winojtb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tousq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tousq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vwxgyn.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vwxgyn.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winycitac.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winycitac.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvroy.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvroy.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\faswjr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\faswjr.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfhlk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winfhlk.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dilxml.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\dilxml.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincxqtnx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincxqtnx.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjuccd.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjuccd.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjxqewr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjxqewr.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjdyxxr.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjdyxxr.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvrfq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvrfq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winokbl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winokbl.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winywmw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winywmw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qppgm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qppgm.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlthjt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlthjt.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\taclk.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\taclk.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vyjof.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\vyjof.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winikybob.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winikybob.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjhywp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjhywp.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingjlcrq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingjlcrq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winolhq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winolhq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyyiu.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyyiu.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvbqyj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvbqyj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\hjxry.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\hjxry.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ckdx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ckdx.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ktwp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ktwp.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wqwh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wqwh.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnvmh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnvmh.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintuil.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintuil.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwpkfmb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwpkfmb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrkil.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrkil.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winophl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winophl.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winosdbcx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winosdbcx.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windsdsdg.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windsdsdg.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbdoihp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbdoihp.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpesjo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winpesjo.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\txcrys.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\txcrys.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ktsx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ktsx.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmhosqa.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmhosqa.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsplwhw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsplwhw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tahqt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\tahqt.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wsxvno.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wsxvno.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingsimf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingsimf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winryersl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winryersl.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\koidqh.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\koidqh.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qyht.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qyht.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mxly.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\mxly.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\iegjlf.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\iegjlf.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxkgjb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winxkgjb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bfowpa.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\bfowpa.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuetjj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winuetjj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winafmfxe.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winafmfxe.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\heig.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\heig.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnlvtc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnlvtc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvwogjs.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvwogjs.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrdat.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrdat.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintemsc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wintemsc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkncpo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winkncpo.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhpaby.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winhpaby.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyaiwv.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winyaiwv.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gbjtwo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\gbjtwo.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qcoyje.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qcoyje.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qawi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\qawi.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winajvmqt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winajvmqt.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingdro.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingdro.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjyjw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winjyjw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsdtnt.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winsdtnt.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wjpl.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wjpl.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\owkpap.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\owkpap.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwwnso.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winwwnso.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\hcbe.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\hcbe.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingudq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wingudq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\yudpgo.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\yudpgo.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winaxnujb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winaxnujb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ivnaoi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\ivnaoi.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlsevhx.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winlsevhx.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincgiw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\wincgiw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqlqc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqlqc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrick.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winrick.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmusj.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmusj.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmbkybm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winmbkybm.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winghpwhb.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winghpwhb.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbfll.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winbfll.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winodprxw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winodprxw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvelbal.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winvelbal.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnwxuxp.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnwxuxp.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\knsuw.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\knsuw.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\reff.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\reff.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnnblxq.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winnnblxq.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\pbivdm.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\pbivdm.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winliykml.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winliykml.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winobbjc.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winobbjc.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\thqi.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\thqi.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lcvja.exe"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\lcvja.exe:*:Enabled:ipsec"
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\win
0
geoffrey5 Messages postés 13732 Date d'inscription dimanche 20 mai 2007 Statut Contributeur sécurité Dernière intervention 21 mai 2010 10
24 mai 2009 à 16:20
Bonjour,

je te conseille de faire des sauvegardes de tes documents et photos importantes sur disques amovibles (clés usb, disque dur externe ou CD/DVD) car ton PC est très infecté et la désinfection ne pourrait peut-être pas arranger les choses...

ensuite :

▶ Telecharge UsbFix de C_XX & Chiquitine29

▶ tutoriel d'installation

▶ tutoriel recherche

▶ Lance l installation avec les parametres par default

Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

▶ Double clic sur le raccourci UsbFix sur ton bureau

▶ Choisi l'option 1 (recherche)

▶ Laisse travailler l'outil

▶ Ensuite post le rapport UsbFix.txt qui apparaîtra

* Note : le rapport UsbFix.txt est sauvegardé a la racine du disque

* Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

* Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
0
salut! avant de lancer le programme je voudrais que tu saches que mon gestionnaire de tâches n'apparaît pas car dés que je le lance j'obtient le message d'erreur suivant : le gestionnaire des tâches a été désactivé par l'administrateur.comment je fais alors.
0