Que se passe t il?

pato Messages postés 5 Statut Membre -  
incognito02 Messages postés 3487 Statut Contributeur -
bonjour voici mes soucis quand j arrete l ordi il me dit:rundll32.exe ce programme ne repond pas. que dois je faire?
quand j allume spybotsd me dit: a detecte un service systeme qui a ete identifie comme une menace: nom affiche :Command service
cle du registre:cmdService comment l enlever merci d avance pour votre aide

7 réponses

  1. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Bonsoir,

    télécharge HijackThis ici:
    http://www.hijackthis.de/downloads/hijackthis_199.zip

    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre le bien dans c : !
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/Hijenr.gif

    Lance le puis:
    clique sur "do a system scan and save logfile" (cf démo)
    faire un copier coller du log entier sur le forum

    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/demohijack.htm

    Bon courage

    A+
    0
  2. pato
     
    Logfile of HijackThis v1.99.1
    Scan saved at 8:09:23, on 2/03/2006
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Ontrack\SYSTEM~1\MXTask.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Logitech\iTouch\iTouch.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\WINDOWS\System32\explorer.exe
    C:\WINDOWS\System32\svxhost.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.1\BHR4.1.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\System32\mirayyve.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\cllhost.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\DVDAccess\DVDAccess.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\WinRAR\WinRAR.exe
    C:\DOCUME~1\Pat\LOCALS~1\Temp\Rar$EX00.877\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: UserInit=userinit.exe
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-be\msntb.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-be\msntb.dll
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\Ontrack\SYSTEM~1\MemCheck.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [Windows Explorer] C:\WINDOWS\System32\explorer.exe
    O4 - HKLM\..\Run: [AdobeReaderPro] svxhost.exe
    O4 - HKLM\..\Run: [WinDLL (steam.dll)] rundll32.exe C:\WINDOWS\System32\steam.dll,start
    O4 - HKLM\..\Run: [BHR4.1] C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.1\BHR4.1.exe
    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [mstctd] C:\WINDOWS\System32\mirayyve.exe
    O4 - HKLM\..\Run: [gimmygames] C:\windows\gimmygames11.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ihost.exe] C:\cllhost.exe
    O4 - HKLM\..\RunServices: [AdobeReaderPro] svxhost.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Startup: DVDAccess.lnk = C:\Program Files\DVDAccess\DVDAccess.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\MICROS~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
    O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: SystemSuite Task Manager - Ontrack Data International - C:\PROGRA~1\Ontrack\SYSTEM~1\MXTask.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    0
  3. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Salut

    Télécharge ceci: (merci a S!RI pour ce programme).
    http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1, il va générer un rapport
    Copie/colle le sur le poste stp.

    +

    Ewido:
    http://download.ewido.net/ewido-setup.exe

    Installation puis mises à jour.

    * Lancer et exécuter Ewido pour un scan complet et copier/coller le rapport en forum.

    a+
    0
    1. pato
       
      voila ce que tu m as demande @ECHO OFF

      REM Smitfraud Fix by S!Ri
      REM http://siri.urz.free.fr/Fix/SmitfraudFix.zip

      REM Thanks, Help: balltrap34, moe31, sebdraluorg, Ruby, Vazkor
      REM Miekiemoes Shudder key fix added.
      REM Process.exe by Craig.Peacock added (http://www.beyondlogic.org)
      REM Reboot.exe by Shadowar/Option^Explicit added.
      REM swreg.exe by SteelWerx
      REM swsc.exe by SteelWerx

      set fixname=SmitFraudFix
      set fixvers=v2.21

      VER|find "Windows 95">NUL
      IF NOT ERRORLEVEL 1 GOTO Win
      VER|find "Windows 98">NUL
      IF NOT ERRORLEVEL 1 GOTO Win
      VER|find "Windows Millennium">NUL
      IF NOT ERRORLEVEL 1 GOTO Win
      VER|find "Windows XP">NUL
      IF NOT ERRORLEVEL 1 GOTO NT
      VER|find "Windows 2000">NUL
      IF NOT ERRORLEVEL 1 GOTO NT
      VER|find "Windows 2003">NUL
      IF NOT ERRORLEVEL 1 GOTO NT
      color 47
      echo %fixname% %fixvers%
      echo.
      echo Version non support‚e.
      echo Windows 2000 / XP requis !
      echo.
      pause
      goto end

      :Win
      color 47
      echo %fixname% %fixvers%
      echo.
      echo Version non support‚e.
      echo Windows 2000 / XP requis !
      echo.
      pause
      goto exit

      :NT
      set DoReboot=0
      set syspath=%windir%\system32
      if exist "%userprofile%\Desktop" set desktop=%userprofile%\Desktop
      if exist "%userprofile%\Bureau" set desktop=%userprofile%\Bureau
      if exist "%allusersprofile%\Desktop" set audesktop=%allusersprofile%\Desktop
      if exist "%allusersprofile%\Bureau" set audesktop=%allusersprofile%\Bureau
      if exist "%userprofile%\Favorites" set favorites=%userprofile%\Favorites
      if exist "%userprofile%\Favoris" set favorites=%userprofile%\Favoris
      goto test

      :test
      if not exist Process.exe (
      color 47
      echo %fixname% %fixvers%
      echo.
      echo Fichier Process.exe absent !
      echo Dezippez la totalit‚ de l'archive dans un dossier.
      echo.
      pause
      goto exit
      )

      if not exist swreg.exe (
      color 47
      echo %fixname% %fixvers%
      echo.
      echo Fichier swreg.exe absent !
      echo Dezippez la totalit‚ de l'archive dans un dossier.
      echo.
      pause
      goto exit
      )

      if not exist swsc.exe (
      color 47
      echo %fixname% %fixvers%
      echo.
      echo Fichier swsc.exe absent !
      echo Dezippez la totalit‚ de l'archive dans un dossier.
      echo.
      pause
      goto exit
      )

      if not exist SrchSTS.exe (
      color 47
      echo %fixname% %fixvers%
      echo.
      echo Fichier SrchSTS.exe absent !
      echo Dezippez la totalit‚ de l'archive dans un dossier.
      echo.
      pause
      goto exit
      )

      if not exist %syspath%\Process.exe copy Process.exe %syspath%
      if not exist %syspath%\swreg.exe copy reg.exe %syspath%
      if not exist %syspath%\swsc.exe copy reg.exe %syspath%
      if not exist %syspath%\SrchSTS.exe copy reg.exe %syspath%
      goto menu

      :menu
      color 17
      cls
      echo.
      echo ÉÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ»
      echo º %fixname% %fixvers% º
      echo ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ͹
      echo º 1. Recherche º
      echo º 2. Nettoyage (mode sans echec recommand‚) º
      echo º 3. Effacer les sites de confiance et sensibles º
      echo º Q. Quitter º
      echo ÈÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍͼ
      echo.
      echo Fermez tous les programmes
      echo un red‚marrage peut-ˆtre n‚cessaire
      echo.
      echo.
      set ChoixMenu=''
      set /p ChoixMenu=Entrez votre choix (1,2,3,Q) :
      if '%ChoixMenu%'=='q' GOTO exit
      if '%ChoixMenu%'=='Q' GOTO exit
      if '%ChoixMenu%'=='1' GOTO search
      if '%ChoixMenu%'=='2' GOTO fix
      if '%ChoixMenu%'=='3' GOTO zonefix
      goto menu



      :search
      cls
      echo %fixname% %fixvers%
      echo %fixname% %fixvers%>%systemdrive%\rapport.txt
      echo.
      echo.>>%systemdrive%\rapport.txt
      echo Rapport fait à %time% le %date%>>%systemdrive%\rapport.txt
      for /f "Tokens=*" %%i in ('cd') do set CurDir=%%i
      echo Executé à partir de %CurDir%>>%systemdrive%\rapport.txt
      IF ERRORLEVEL 1 (
      echo Executé à partir de >>%systemdrive%\rapport.txt
      cd >>%systemdrive%\rapport.txt
      )
      for /f "Tokens=*" %%i in ('ver') do set Version=%%i
      echo OS: %Version%>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt




      echo Recherche %HOMEDRIVE%\...
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %HOMEDRIVE%\>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt



      pushd %HOMEDRIVE%\

      if exist bsw.exe (echo %HOMEDRIVE%\bsw.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist contextplus.exe (echo %HOMEDRIVE%\contextplus.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist drsmartload1.exe (echo %HOMEDRIVE%\drsmartload1.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist drsmartloadb.exe (echo %HOMEDRIVE%\drsmartloadb.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist ecsiin.stub.exe (echo %HOMEDRIVE%\ecsiin.stub.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist loader.exe (echo %HOMEDRIVE%\loader.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist ntdetecd.exe (echo %HOMEDRIVE%\ntdetecd.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist ntps.exe (echo %HOMEDRIVE%\ntps.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist ntnc.exe (echo %HOMEDRIVE%\ntnc.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist r.exe (echo %HOMEDRIVE%\r.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist secure32.html (echo %HOMEDRIVE%\secure32.html PRESENT !>>%systemdrive%\rapport.txt)
      if exist stub_113_4_0_4_0.exe (echo %HOMEDRIVE%\stub_113_4_0_4_0.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist winstall.exe (echo %HOMEDRIVE%\winstall.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist wp.bmp (echo %HOMEDRIVE%\wp.bmp PRESENT !>>%systemdrive%\rapport.txt)
      if exist wp.exe (echo %HOMEDRIVE%\wp.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist xxx.exe (echo %HOMEDRIVE%\xxx.exe PRESENT !>>%systemdrive%\rapport.txt)

      if exist "%HOMEDRIVE%\spywarevanisher-free" echo %HOMEDRIVE%\spywarevanisher-free\ PRESENT !>>%systemdrive%\rapport.txt

      popd



      echo.>>%systemdrive%\rapport.txt
      echo Recherche %windir%\...
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %windir%>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt



      pushd %windir%

      if exist adsldpbc.dll (echo %windir%\adsldpbc.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist adsldpbd.dll (echo %windir%\adsldpbd.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist adsldpbe.dll (echo %windir%\adsldpbe.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist adsldpbf.dll (echo %windir%\adsldpbf.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist adtech2005.exe (echo %windir%\adtech2005.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist adtech2006a.exe (echo %windir%\adtech2006a.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist adw.htm (echo %windir%\adw.htm PRESENT !>>%systemdrive%\rapport.txt)
      if exist back.gif (echo %windir%\back.gif PRESENT !>>%systemdrive%\rapport.txt)
      if exist batserv2.exe (echo %windir%\batserv2.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist bg.gif (echo %windir%\bg.gif PRESENT !>>%systemdrive%\rapport.txt)
      if exist blank.mht (echo %windir%\blank.mht PRESENT !>>%systemdrive%\rapport.txt)
      if exist buy.gif (echo %windir%\buy.gif PRESENT !>>%systemdrive%\rapport.txt)
      if exist bxproxy.exe (echo %windir%\bxproxy.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist country.exe (echo %windir%\country.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist d3dn32.exe (echo %windir%\d3dn32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist d3??.dll (echo %windir%\d3??.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist d3pb.exe (echo %windir%\d3pb.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist desktop.html (echo %windir%\desktop.html PRESENT !>>%systemdrive%\rapport.txt)
      if exist download-btn.gif (echo %windir%\download-btn.gif PRESENT !>>%systemdrive%\rapport.txt)
      if exist drsmartload.dat (echo %windir%\drsmartload.dat PRESENT !>>%systemdrive%\rapport.txt)
      if exist drsmartloadb1.dat (echo %windir%\drsmartloadb1.dat PRESENT !>>%systemdrive%\rapport.txt)
      if exist kl.exe (echo %windir%\kl.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist icont.exe (echo %windir%\icont.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist ieyi.dll (echo %windir%\ieyi.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist ieyi.exe (echo %windir%\ieyi.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist ms1.exe (echo %windir%\ms1.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist notepad.com (echo %windir%\notepad.com PRESENT !>>%systemdrive%\rapport.txt)
      if exist popuper.exe (echo %windir%\popuper.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist psg.exe (echo %windir%\psg.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist q*_disk.dll (echo %windir%\q*_disk.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist rzs.exe (echo %windir%\rzs.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist sachostx.exe (echo %windir%\sachostx.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist screen.html (echo %windir%\screen.html PRESENT !>>%systemdrive%\rapport.txt)
      if exist sec.exe (echo %windir%\sec.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist sdkcb.dll (echo %windir%\sdkcb.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist sdkqq.exe (echo %windir%\sdkqq.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist secure32.html (echo %windir%\secure32.html PRESENT !>>%systemdrive%\rapport.txt)
      if exist sites.ini (echo %windir%\sites.ini PRESENT !>>%systemdrive%\rapport.txt)
      if exist slassac.dll (echo %windir%\slassac.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist svchost.exe (echo %windir%\svchost.exe PRESENT!>>%systemdrive%\rapport.txt)
      if exist sysldr32.exe (echo %windir%\sysldr32.exe PRESENT!>>%systemdrive%\rapport.txt)
      if exist sysen.exe (echo %windir%\sysen.exe PRESENT!>>%systemdrive%\rapport.txt)
      if exist temp.000.exe (echo %windir%\temp.000.exe PRESENT!>>%systemdrive%\rapport.txt)
      if exist timessquare.exe (echo %windir%\timessquare.exe PRESENT!>>%systemdrive%\rapport.txt)
      if exist timessquare1.dat (echo %windir%\timessquare1.dat PRESENT!>>%systemdrive%\rapport.txt)
      if exist tool1.exe (echo %windir%\tool1.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist tool2.exe (echo %windir%\tool2.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist tool3.exe (echo %windir%\tool3.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist tool4.exe (echo %windir%\tool4.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist tool5.exe (echo %windir%\tool5.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist toolbar.exe (echo %windir%\toolbar.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist uninstDsk.exe (echo %windir%\uninstDsk.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist uninstIU.exe (echo %windir%\uninstIU.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist update13.js (echo %windir%\update13.js PRESENT !>>%systemdrive%\rapport.txt)
      if exist warnhp.html (echo %windir%\warnhp.html PRESENT !>>%systemdrive%\rapport.txt)
      if exist winsysupd.exe (echo %windir%\winsysupd.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist winsysban.exe (echo %windir%\winsysban.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist windows.html (echo %windir%\windows.html PRESENT !>>%systemdrive%\rapport.txt)
      if exist zloader3.exe (echo %windir%\zloader3.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist __delete_on_reboot__popuper.exe (echo %windir%\__delete_on_reboot__popuper.exe PRESENT !>>%systemdrive%\rapport.txt)

      if exist "%windir%\inet20001" echo %windir%\inet20001\ PRESENT!>>%systemdrive%\rapport.txt
      if exist "%windir%\inet20010" echo %windir%\inet20010\ PRESENT!>>%systemdrive%\rapport.txt
      if exist "%windir%\inet20066" echo %windir%\inet20066\ PRESENT!>>%systemdrive%\rapport.txt
      if exist "%windir%\inet20099" echo %windir%\inet20099\ PRESENT!>>%systemdrive%\rapport.txt

      popd






      echo.>>%systemdrive%\rapport.txt
      echo Recherche %windir%\system...
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %windir%\system>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt



      pushd %windir%\system

      if exist csrss.exe (echo %windir%\system\csrss.exe PRESENT!>>%systemdrive%\rapport.txt)
      if exist svchost.exe (echo %windir%\system\svchost.exe PRESENT!>>%systemdrive%\rapport.txt)
      if exist svchost.dll (echo %windir%\system\svchost.dll PRESENT!>>%systemdrive%\rapport.txt)
      if exist svwhost.exe (echo %windir%\system\svwhost.exe PRESENT!>>%systemdrive%\rapport.txt)
      if exist svwhost.dll (echo %windir%\system\svwhost.dll PRESENT!>>%systemdrive%\rapport.txt)

      popd




      echo.>>%systemdrive%\rapport.txt
      echo Recherche %windir%\Web...
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %windir%\Web>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt



      pushd %windir%\Web

      if exist desktop.html (echo %windir%\Web\desktop.html PRESENT!>>%systemdrive%\rapport.txt)
      if exist wallpaper.html (echo %windir%\Web\wallpaper.html PRESENT!>>%systemdrive%\rapport.txt)

      popd



      echo.>>%systemdrive%\rapport.txt
      echo Recherche %syspath%...
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %syspath%>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt



      pushd %syspath%

      if exist ~update.exe (echo %syspath%\~update.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Air Tickets.ico" (echo %syspath%\Air Tickets.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist AdService.dll (echo %syspath%\AdService.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist adsmart.exe (echo %syspath%\adsmart.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist bhoimpl.dll (echo %syspath%\bhoimpl.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Big Tits.ico" (echo %syspath%\Big Tits.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist birdihuy.dll (echo %syspath%\birdihuy.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist birdihuy32.dll (echo %syspath%\birdihuy32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist Blackjack.ico (echo %syspath%\Blackjack.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist bnmsrv.exe (echo %syspath%\bnmsrv.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist bre.dll (echo %syspath%\bre.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist bre32.dll (echo %syspath%\bre32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist browsela.dll (echo %syspath%\browsela.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Britney Spears.ico" (echo %syspath%\Britney Spears.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist bu.exe (echo %syspath%\bu.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Car Insurance.ico" (echo %syspath%\Car Insurance.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist casino.ico (echo %syspath%\casino.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Cheap Cigarettes.ico" (echo %syspath%\Cheap Cigarettes.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist child.dll (echo %syspath%\child.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist chp.dll (echo %syspath%\chp.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist cmd32.exe (echo %syspath%\cmd32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist cmdtel.exe (echo %syspath%\cmdtel.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist cnymxw32.dll (echo %syspath%\cnymxw32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist combo.exe (echo %syspath%\combo.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Credit Card.ico" (echo %syspath%\Credit Card.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist Cruises.ico (echo %syspath%\Cruises.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Currency Trading.ico" (echo %syspath%\Currency Trading.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist cvxh8jkdq?.exe (echo %syspath%\cvxh8jkdq?.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist date.ico (echo %syspath%\date.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist dial23.exe (echo %syspath%\dial23.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist doser.exe (echo %syspath%\doser.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist dxmpp.dll (echo %syspath%\dxmpp.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist efsdfgxg.exe (echo %syspath%\efsdfgxg.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist exa32.exe (echo %syspath%\exa32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist exeha2.exe (echo %syspath%\exeha2.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist exeha3.exe (echo %syspath%\exeha3.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist games.ico (echo %syspath%\games.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist gunist.exe (echo %syspath%\gunist.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist helper.exe (echo %syspath%\helper.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist hhk.dll (echo %syspath%\hhk.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist hookdump.exe (echo %syspath%\hookdump.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist hp????.tmp (echo %syspath%\hp????.tmp PRESENT !>>%systemdrive%\rapport.txt)
      if exist IeHelperEx.dll (echo %syspath%\IeHelperEx.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist intel32.exe (echo %syspath%\intel32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist intell321.exe (echo %syspath%\intell321.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist intell32.exe (echo %syspath%\intell32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist intmon.exe (echo %syspath%\intmon.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist intmonp.exe (echo %syspath%\intmonp.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist intxt.exe (echo %syspath%\intxt.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist ioctrl.dll (echo %syspath%\ioctrl.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist kernels32.exe (echo %syspath%\kernels32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist kernels64.exe (echo %syspath%\kernels64.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist latest.exe (echo %syspath%\latest.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Lesbian Sex.ico" (echo %syspath%\Lesbian Sex.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist ld????.tmp (echo %syspath%\ld????.tmp PRESENT !>>%systemdrive%\rapport.txt)
      if exist links.exe (echo %syspath%\links.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist ll.exe (echo %syspath%\ll.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist maxd1.exe (echo %syspath%\maxd1.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist maxd64.exe (echo %syspath%\maxd64.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist migicons.exe (echo %syspath%\migicons.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist mobile.ico (echo %syspath%\mobile.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist MP3.ico (echo %syspath%\MP3.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist msbe.dll (echo %syspath%\msbe.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist mscornet.exe (echo %syspath%\mscornet.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist mssearchnet.exe (echo %syspath%\mssearchnet.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist msmsgs.exe (echo %syspath%\msmsgs.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist msnscps.dll (echo %syspath%\msnscps.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist msole32.exe (echo %syspath%\msole32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist mspostsp.exe.exe (echo %syspath%\mspostsp.exe.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist msupdate32.dll (echo %syspath%\msupdate32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist msvcp.exe.exe (echo %syspath%\msvcp.exe.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist msvol.tlb (echo %syspath%\msvol.tlb PRESENT !>>%systemdrive%\rapport.txt)
      if exist mswinb32.dll (echo %syspath%\mswinb32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist mswinb32.exe (echo %syspath%\mswinb32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist mswinf32.dll (echo %syspath%\mswinf32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist mswinf32.exe (echo %syspath%\mswinf32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist mswinup32.dll (echo %syspath%\mswinup32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist mswinxml.dll (echo %syspath%\mswinxml.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist MTC.dll (echo %syspath%\MTC.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist MTC.ini (echo %syspath%\MTC.ini PRESENT !>>%systemdrive%\rapport.txt)
      if exist multitran.exe (echo %syspath%\multitran.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist ncompat.tlb (echo %syspath%\ncompat.tlb PRESENT !>>%systemdrive%\rapport.txt)
      if exist network.ico (echo %syspath%\network.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist netwrap.dll (echo %syspath%\netwrap.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist notepad.com (echo %syspath%\notepad.com PRESENT !>>%systemdrive%\rapport.txt)
      if exist NTCommLib3.exe (echo %syspath%\NTCommLib3.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist nuclabdll.dll (echo %syspath%\nuclabdll.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist nvctrl.exe (echo %syspath%\nvctrl.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist nvms.dll (echo %syspath%\nvms.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist ole32vbs.exe (echo %syspath%\ole32vbs.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist oleadm.dll (echo %syspath%\oleadm.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist oleadm32.dll (echo %syspath%\oleadm32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist oleext.dll (echo %syspath%\oleext.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist oleext32.dll (echo %syspath%\oleext32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Online Betting.ico" (echo %syspath%\Online Betting.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Online Gambling.ico" (echo %syspath%\Online Gambling.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Oral Sex.ico" (echo %syspath%\Oral Sex.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist ot.ico (echo %syspath%\ot.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist param32.dll (echo %syspath%\param32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist paradise.raw.exe (echo %syspath%\paradise.raw.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Party Poker.ico" (echo %syspath%\Party Poker.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist paytime.exe (echo %syspath%\paytime.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist perfcii.ini (echo %syspath%\perfcii.ini PRESENT !>>%systemdrive%\rapport.txt)
      if exist performent217.dll (echo %syspath%\performent217.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist pharm.ico (echo %syspath%\pharm.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist pharm2.ico (echo %syspath%\pharm2.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist Pharmacy.ico (echo %syspath%\Pharmacy.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist Phentermine.ico (echo %syspath%\Phentermine.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist pop_up.dll (echo %syspath%\pop_up.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist Pornstars.ico (echo %syspath%\Pornstars.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist priva.exe (echo %syspath%\priva.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist prflbmsgp32.dll (echo %syspath%\prflbmsgp32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist qvxgamet?.exe (echo %syspath%\qvxgamet?.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Remove Spyware.ico" (echo %syspath%\Remove Spyware.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist replmap.dll (echo %syspath%\replmap.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist RpcxSs.dll (echo %syspath%\RpcxSs.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist runsrv32.dll (echo %syspath%\runsrv32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist runsrv32.exe (echo %syspath%\runsrv32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist sachostc.exe (echo %syspath%\sachostc.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist sachostp.exe (echo %syspath%\sachostp.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist sachosts.exe (echo %syspath%\sachosts.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist scanner.ico (echo %syspath%\scanner.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist sdfdil.exe (echo %syspath%\sdfdil.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist searchdll.dll (echo %syspath%\searchdll.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist sender.exe (echo %syspath%\sender.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist shdochp.dll (echo %syspath%\shdochp.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist shdochp.exe (echo %syspath%\shdochp.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist shdochop.dll (echo %syspath%\shdochop.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist shdocnva.dll (echo %syspath%\shdocnva.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist shdocsvc.dll (echo %syspath%\shdocsvc.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist shdocsvc.exe (echo %syspath%\shdocsvc.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist shell386.exe (echo %syspath%\shell386.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist shnlog.exe (echo %syspath%\shnlog.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist shsexl32.dll (echo %syspath%\shsexl32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist socks.exe (echo %syspath%\socks.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist spam.ico (echo %syspath%\spam.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist split.exe (echo %syspath%\split.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist split1.exe (echo %syspath%\split1.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist split2.exe (echo %syspath%\split2.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist spyware.ico (echo %syspath%\spyware.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist srpcsrv32.dll (echo %syspath%\srpcsrv32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist srpcsrv32.exe (echo %syspath%\srpcsrv32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist st3.dll (echo %syspath%\st3.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist svchop.exe (echo %syspath%\svchop.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist svchosts.dll (echo %syspath%\svchosts.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist svchosts.exe (echo %syspath%\svchosts.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist svcnt.exe (echo %syspath%\svcnt.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist svcnt32.exe (echo %syspath%\svcnt32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist svcnva.exe (echo %syspath%\svcnva.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist svwhost.exe (echo %syspath%\svwhost.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist symsvcsa.exe (echo %syspath%\symsvcsa.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist sysbho.exe (echo %syspath%\sysbho.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist sysinit32z.exe (echo %syspath%\sysinit32z.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist sysjv32.exe (echo %syspath%\sysjv32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist sysmain.dll (echo %syspath%\sysmain.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist sysvcs.exe (echo %syspath%\sysvcs.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist sywsvcs.exe (echo %syspath%\sywsvcs.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist taras.exe (echo %syspath%\taras.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist tcpservice2.exe (echo %syspath%\tcpservice2.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist trf32.dll (echo %syspath%\trf32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist ts.ico (echo %syspath%\ts.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist txfdb32.dll (echo %syspath%\txfdb32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist viagra.ico (echo %syspath%\viagra.ico PRESENT !>>%systemdrive%\rapport.txt)
      if exist vxgame?.exe (echo %syspath%\vxgame?.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist vxgame?.exe????.exe (echo %syspath%\vxgame?.exe????.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist vxgame?.exe????.exe.bak (echo %syspath%\vxgame?.exe????.exe.bak PRESENT !>>%systemdrive%\rapport.txt)
      if exist vxgamet?.exe (echo %syspath%\vxgamet?.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist vxgamet?.exe????.exe (echo %syspath%\vxgamet?.exe????.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist vxh8jkdq?.exe (echo %syspath%\vxh8jkdq?.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist w8673492.exe (echo %syspath%\w8673492.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist wbeconm.dll (echo %syspath%\wbeconm.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist web.exe (echo %syspath%\web.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist wiatwain.dll (echo %syspath%\wiatwain.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist winapi32.dll (echo %syspath%\winapi32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist windesktop.dll (echo %syspath%\windesktop.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist windesktop.exe (echo %syspath%\windesktop.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist winldra.exe (echo %syspath%\winldra.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist winlfl32.dll (echo %syspath%\winlfl32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist winnook.exe (echo %syspath%\winnook.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist winstyle2.dll (echo %syspath%\winstyle2.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist winstyle3.dll (echo %syspath%\winstyle3.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist winstyle32.dll (echo %syspath%\winstyle32.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist wldr.dll (echo %syspath%\wldr.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist wp.bmp (echo %syspath%\wp.bmp PRESENT !>>%systemdrive%\rapport.txt)
      if exist wppp.html (echo %syspath%\wppp.html PRESENT !>>%systemdrive%\rapport.txt)
      if exist wstart.dll (echo %syspath%\wstart.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist x.exe (echo %syspath%\x.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist yaemu.exe (echo %syspath%\yaemu.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist z11.exe (echo %syspath%\z11.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist z12.exe (echo %syspath%\z12.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist z13.exe (echo %syspath%\z13.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist z14.exe (echo %syspath%\z14.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist z15.exe (echo %syspath%\z15.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist z16.exe (echo %syspath%\z16.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist zlbw.dll (echo %syspath%\zlbw.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist zolker011.dll (echo %syspath%\zolker011.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist ztoolb011.dll (echo %syspath%\ztoolb011.dll PRESENT !>>%systemdrive%\rapport.txt)
      if exist ztoolbar.bmp (echo %syspath%\ztoolbar.bmp PRESENT !>>%systemdrive%\rapport.txt)
      if exist ztoolbar.xml (echo %syspath%\ztoolbar.xml PRESENT !>>%systemdrive%\rapport.txt)
      if exist __delete_on_reboot__intmon.exe (echo %syspath%\__delete_on_reboot__intmon.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist __delete_on_reboot__intel32.exe (echo %syspath%\__delete_on_reboot__intel32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist __delete_on_reboot__intell32.exe (echo %syspath%\__delete_on_reboot__intell32.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist __delete_on_reboot__OLEADM.dll (echo %syspath%\__delete_on_reboot__OLEADM.dll PRESENT !>>%systemdrive%\rapport.txt)

      if exist "%syspath%\1024" echo %syspath%\1024\ PRESENT!>>%systemdrive%\rapport.txt

      if exist "%syspath%\drivers\hesvc.sys" echo %syspath%\drivers\hesvc.sys PRESENT!>>%systemdrive%\rapport.txt


      popd





      if NOT exist %syspath%\LogFiles goto suiteScanAppData

      echo.>>%systemdrive%\rapport.txt
      echo Recherche %syspath%\LogFiles...
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %syspath%\LogFiles>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt

      pushd %syspath%\LogFiles

      if exist A5281300.so (echo %syspath%\A5281300.so PRESENT !>>%systemdrive%\rapport.txt)
      if exist T54111925.so (echo %syspath%\T54111925.so PRESENT !>>%systemdrive%\rapport.txt)
      if exist H53131712.so (echo %syspath%\H53131712.so PRESENT !>>%systemdrive%\rapport.txt)
      if exist A54102200.so (echo %syspath%\A54102200.so PRESENT !>>%systemdrive%\rapport.txt)
      if exist S53252000.so (echo %syspath%\S53252000.so PRESENT !>>%systemdrive%\rapport.txt)
      if exist A04111925.so (echo %syspath%\A04111925.so PRESENT !>>%systemdrive%\rapport.txt)
      if exist M54111925.so (echo %syspath%\M54111925.so PRESENT !>>%systemdrive%\rapport.txt)
      if exist P54111925.so (echo %syspath%\P54111925.so PRESENT !>>%systemdrive%\rapport.txt)

      popd



      :suiteScanAppData
      echo.>>%systemdrive%\rapport.txt
      echo Recherche %userprofile%\Application Data...
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche ...\Application Data>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt

      if exist "%HOMEDRIVE%\Documents and Settings\LocalService\Application Data\AlfaCleaner" echo %HOMEDRIVE%\Documents and Settings\LocalService\Application Data\AlfaCleaner PRESENT !>>%systemdrive%\rapport.txt

      pushd %userprofile%\Application Data

      if exist "%userprofile%\Application Data\Install.dat" echo %userprofile%\Application Data\Install.dat PRESENT !>>%systemdrive%\rapport.txt
      if exist "%userprofile%\Application Data\AlfaCleaner" echo %userprofile%\Application Data\AlfaCleaner PRESENT !>>%systemdrive%\rapport.txt
      if exist "%userprofile%\Application Data\PSGuard.com" echo %userprofile%\Application Data\PSGuard.com PRESENT !>>%systemdrive%\rapport.txt
      if exist "%userprofile%\Application Data\Shudder Global Limited" echo %userprofile%\Application Data\Shudder Global Limited PRESENT !>>%systemdrive%\rapport.txt
      if exist "%userprofile%\Application Data\Skinux" echo %userprofile%\Application Data\Skinux PRESENT !>>%systemdrive%\rapport.txt

      if exist "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\AlfaCleaner.lnk" echo %userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\AlfaCleaner.lnk PRESENT !>>%systemdrive%\rapport.txt
      if exist "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\SpywareStrike 2.5.lnk" echo %userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\SpywareStrike 2.5.lnk PRESENT !>>%systemdrive%\rapport.txt
      if exist "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyFalcon 2.0.lnk" echo %userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyFalcon 2.0.lnk PRESENT !>>%systemdrive%\rapport.txt

      popd



      echo.>>%systemdrive%\rapport.txt
      echo Recherche Menu D‚marrer...
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt

      if exist "%userprofile%\Menu D‚marrer\SpyAxe 3.0.lnk" (echo %userprofile%\Menu Démarrer\SpyAxe 3.0.lnk PRESENT !>>%systemdrive%\rapport.txt)
      if exist "%userprofile%\Menu D‚marrer\SpyFalcon 2.0.lnk" (echo %userprofile%\Menu Démarrer\SpyFalcon 2.0.lnk PRESENT !>>%systemdrive%\rapport.txt)
      if exist "%userprofile%\Menu D‚marrer\SpywareStrike 2.5.lnk" (echo %userprofile%\Menu Démarrer\SpywareStrike 2.5.lnk PRESENT !>>%systemdrive%\rapport.txt)
      if exist "%userprofile%\Menu D‚marrer\Programmes\SpyAxe" (echo %userprofile%\Menu Démarrer\Programmes\SpyAxe PRESENT !>>%systemdrive%\rapport.txt)
      if exist "%userprofile%\Menu D‚marrer\Programmes\SpyFalcon" (echo %userprofile%\Menu Démarrer\Programmes\SpyFalcon PRESENT !>>%systemdrive%\rapport.txt)
      if exist "%userprofile%\Menu D‚marrer\Programmes\SpySheriff" (echo %userprofile%\Menu Démarrer\Programmes\SpySheriff PRESENT !>>%systemdrive%\rapport.txt)
      if exist "%userprofile%\Menu D‚marrer\Programmes\SpywareStrike" (echo %userprofile%\Menu Démarrer\Programmes\SpywareStrike PRESENT !>>%systemdrive%\rapport.txt)
      if exist "%allusersprofile%\Menu D‚marrer\PopUp Blocker.url" (echo %allusersprofile%\Menu Démarrer\PopUp Blocker.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "%allusersprofile%\Menu D‚marrer\Spyware Remover.url" (echo %allusersprofile%\Menu Démarrer\Spyware Remover.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "%allusersprofile%\Menu D‚marrer\Programmes\AlfaCleaner" (echo %allusersprofile%\Menu Démarrer\Programmes\AlfaCleaner PRESENT !>>%systemdrive%\rapport.txt)
      if exist "%allusersprofile%\Menu D‚marrer\Programmes\P.S.Guard spyware remover" (echo %allusersprofile%\Menu Démarrer\Programmes\P.S.Guard spyware remover PRESENT !>>%systemdrive%\rapport.txt)
      if exist "%allusersprofile%\Menu D‚marrer\Programmes\WinHound spyware remover" (echo %allusersprofile%\Menu Démarrer\Programmes\WinHound spyware remover PRESENT !>>%systemdrive%\rapport.txt)



      echo.>>%systemdrive%\rapport.txt
      echo Recherche %desktop%...
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt

      pushd %desktop%

      if exist "access" (echo %desktop%\access PRESENT !>>%systemdrive%\rapport.txt)
      if exist asfds (echo %desktop%\asfds PRESENT !>>%systemdrive%\rapport.txt)
      if exist "domains" (echo %desktop%\domains PRESENT !>>%systemdrive%\rapport.txt)
      if exist "map.txt" (echo %desktop%\map.txt PRESENT !>>%systemdrive%\rapport.txt)
      if exist m00.exe (echo %desktop%\m00.exe PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Air Tickets.url" (echo %desktop%\Air Tickets.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist AlfaCleaner.lnk (echo %desktop%\AlfaCleaner.lnk PRESENT !>>%systemdrive%\rapport.txt)
      if exist AntivirusGold.lnk (echo %desktop%\AntivirusGold.lnk PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Big Tits.url" (echo %desktop%\Big Tits.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist Blackjack.url (echo %desktop%\Blackjack.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist Blowjob.url (echo %desktop%\Blowjob.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Britney Spears.url" (echo %desktop%\Britney Spears.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Car Insurance.url" (echo %desktop%\Car Insurance.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist cdegfr (echo %desktop%\cdegfr PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Cheap Cigarettes.url" (echo %desktop%\Cheap Cigarettes.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Cigarettes Discount.url" (echo %desktop%\Cigarettes Discount.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Credit Card.url" (echo %desktop%\Credit Card.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist Cruises.url (echo %desktop%\Cruises.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Currency Trading.url" (echo %desktop%\Currency Trading.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist fdsf (echo %desktop%\fdsf PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Forex Trading.url" (echo %desktop%\Forex Trading.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Free Ringtones.url" (echo %desktop%\Free Ringtones.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Gift Ideas.url" (echo %desktop%\Gift Ideas.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Group Sex.url" (echo %desktop%\Group Sex.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Home Loan.url" (echo %desktop%\Home Loan.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Lesbian Sex.url" (echo %desktop%\Lesbian Sex.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist MP3.url (echo %desktop%\MP3.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Mp3 Download.url" (echo %desktop%\Mp3 Download.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Online Betting.url" (echo %desktop%\Online Betting.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Online Casino.url" (echo %desktop%\Online Casino.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Online Dating.url" (echo %desktop%\Online Dating.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Online Gambling.url" (echo %desktop%\Online Gambling.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Oral Sex.url" (echo %desktop%\Oral Sex.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Party Poker.url" (echo %desktop%\Party Poker.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist Pharmacy.url (echo %desktop%\Pharmacy.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist Phentermine.url (echo %desktop%\Phentermine.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Play Poker.url" (echo %desktop%\Play Poker.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "PopUp Blocker.url" (echo %desktop%\PopUp Blocker.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Porn Dvd.url" (echo %desktop%\Porn Dvd.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist Pornstars.url (echo %desktop%\Pornstars.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "P.S.Guard spyware remover.lnk" (echo %desktop%\P.S.Guard spyware remover.lnk PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Real Estate.url" (echo %desktop%\Real Estate.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Remove Spyware.url" (echo %desktop%\Remove Spyware.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist sdfdsf (echo %desktop%\sdfdsf PRESENT !>>%systemdrive%\rapport.txt)
      if exist sdfff (echo %desktop%\sdfff PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Sport Betting.url" (echo %desktop%\Sport Betting.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist SpyFalcon.lnk (echo %desktop%\SpyFalcon.lnk PRESENT !>>%systemdrive%\rapport.txt)
      if exist SpySheriff.lnk (echo %desktop%\SpySheriff.lnk PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Spyware Remover.url" (echo %desktop%\Spyware Remover.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist SpywareStrike.lnk (echo %desktop%\SpywareStrike.lnk PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Texas Holdem.url" (echo %desktop%\Texas Holdem.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist viagra.url (echo %desktop%\viagra.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist wdcevf (echo %desktop%\wdcevf PRESENT !>>%systemdrive%\rapport.txt)
      if exist wdcevf (echo %desktop%\wdcevf PRESENT !>>%systemdrive%\rapport.txt)
      if exist zxczxc (echo %desktop%\zxczxc PRESENT !>>%systemdrive%\rapport.txt)


      popd



      pushd %audesktop%


      if exist "Air Tickets.url" (echo %audesktop%\Air Tickets.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist AntivirusGold.lnk (echo %audesktop%\AntivirusGold.lnk PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Big Tits.url" (echo %audesktop%\Big Tits.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist Blackjack.url (echo %audesktop%\Blackjack.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist Blowjob.url (echo %audesktop%\Blowjob.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Britney Spears.url" (echo %audesktop%\Britney Spears.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Car Insurance.url" (echo %audesktop%\Car Insurance.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Cheap Cigarettes.url" (echo %audesktop%\Cheap Cigarettes.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Cigarettes Discount.url" (echo %audesktop%\Cigarettes Discount.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Credit Card.url" (echo %audesktop%\Credit Card.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist Cruises.url (echo %audesktop%\Cruises.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Currency Trading.url" (echo %audesktop%\Currency Trading.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Forex Trading.url" (echo %audesktop%\Forex Trading.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Free Ringtones.url" (echo %audesktop%\Free Ringtones.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Gift Ideas.url" (echo %audesktop%\Gift Ideas.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Group Sex.url" (echo %audesktop%\Group Sex.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Home Loan.url" (echo %audesktop%\Home Loan.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Lesbian Sex.url" (echo %audesktop%\Lesbian Sex.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Mp3 Download.url" (echo %audesktop%\Mp3 Download.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist MP3.url (echo %audesktop%\MP3.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Online Betting.url" (echo %audesktop%\Online Betting.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Online Casino.url" (echo %audesktop%\Online Casino.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Online Dating.url" (echo %audesktop%\Online Dating.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Online Gambling.url" (echo %audesktop%\Online Gambling.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Oral Sex.url" (echo %audesktop%\Oral Sex.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Party Poker.url" (echo %audesktop%\Party Poker.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist Pharmacy.url (echo %audesktop%\Pharmacy.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist Phentermine.url (echo %audesktop%\Phentermine.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Play Poker.url" (echo %audesktop%\Play Poker.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "PopUp Blocker.url" (echo %audesktop%\PopUp Blocker.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Porn Dvd.url" (echo %audesktop%\Porn Dvd.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist Pornstars.url (echo %audesktop%\Pornstars.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "P.S.Guard spyware remover.lnk" (echo %audesktop%\P.S.Guard spyware remover.lnk PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Real Estate.url" (echo %audesktop%\Real Estate.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Remove Spyware.url" (echo %audesktop%\Remove Spyware.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Sport Betting.url" (echo %audesktop%\Sport Betting.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist SpySheriff.lnk (echo %audesktop%\SpySheriff.lnk PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Spyware Remover.url" (echo %audesktop%\Spyware Remover.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist viagra.url (echo %audesktop%\viagra.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "Texas Holdem.url" (echo %audesktop%\Texas Holdem.url PRESENT !>>%systemdrive%\rapport.txt)
      if exist "WinHound spyware remover.lnk" (echo %audesktop%\WinHound spyware remover.lnk PRESENT !>>%systemdrive%\rapport.txt)

      popd



      echo.>>%systemdrive%\rapport.txt
      echo Recherche %ProgramFiles%...
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %ProgramFiles% >>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt


      if exist "%ProgramFiles%\AdwareDelete" echo %ProgramFiles%\AdwareDelete\ PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\AlfaCleaner" echo %ProgramFiles%\AlfaCleaner\ PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\AntivirusGold" echo %ProgramFiles%\AntivirusGold\ PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Daily Weather Forecast" echo %ProgramFiles%\Daily Weather Forecast\ PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\PSGuard" echo %ProgramFiles%\PSGuard\ PRESENT!>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\P.S.Guard" echo %ProgramFiles%\P.S.Guard\ PRESENT!>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Search Maid" echo %ProgramFiles%\Search Maid\ PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Security IGuard" echo %ProgramFiles%\Security IGuard\ PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\SpyAxe" echo %ProgramFiles%\SpyAxe\ PRESENT!>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\SpyFalcon" echo %ProgramFiles%\SpyFalcon\ PRESENT!>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\SpySheriff" echo %ProgramFiles%\SpySheriff\ PRESENT!>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\SpyKiller" echo %ProgramFiles%\SpyKiller\ PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\SpywareStrike" echo %ProgramFiles%\SpywareStrike\ PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Virtual Maid" echo %ProgramFiles%\Virtual Maid\ PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\WinHound" echo %ProgramFiles%\WinHound\ PRESENT !>>%systemdrive%\rapport.txt

      if exist "%ProgramFiles%\internet explorer\ieengine.exe" echo %ProgramFiles%\internet explorer\ieengine.exe PRESENT !>>%systemdrive%\rapport.txt

      if exist "%ProgramFiles%\Fichiers communs\Download\mc-58-12-0000113.exe" echo %ProgramFiles%\Fichiers communs\Download\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Common Files\Download\mc-58-12-0000113.exe" echo %ProgramFiles%\Common Files\Download\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Fichiers communs\InetGet\mc-58-12-0000113.exe" echo %ProgramFiles%\Fichiers communs\InetGet\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Common Files\InetGet\mc-58-12-0000113.exe" echo %ProgramFiles%\Common Files\InetGet\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Fichiers communs\muwq\ echo %ProgramFiles%\Fichiers communs\muwq\" PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Common Files\muwq\ echo %ProgramFiles%\Common Files\muwq\" PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Fichiers communs\Windows\mc-58-12-0000113.exe" echo %ProgramFiles%\Fichiers communs\Windows\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Common Files\Windows\mc-58-12-0000113.exe" echo %ProgramFiles%\Common Files\Windows\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Fichiers communs\Windows\services32.exe" echo %ProgramFiles%\Fichiers communs\Windows\services32.exe PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Common Files\Windows\services32.exe" echo %ProgramFiles%\Common Files\Windows\services32.exe PRESENT !>>%systemdrive%\rapport.txt

      if exist "%ProgramFiles%\Common Files\VCClient\VCMain.exe" echo %ProgramFiles%\Common Files\VCClient\VCMain.exe PRESENT !>>%systemdrive%\rapport.txt
      if exist "%ProgramFiles%\Common Files\VCClient\VCClient.exe" echo %ProgramFiles%\Common Files\VCClient\VCClient.exe PRESENT !>>%systemdrive%\rapport.txt

      if exist %syspath%\intell32.exe goto DateFile
      goto sudderltd

      :DateFile
      dir %syspath%\intell32.exe /4 /A /N /-C>result.txt
      type result.txt | find /i "intell32.exe">result2.txt
      for /f "tokens=1" %%a in (result2.txt) do set filedate=%%a

      echo Recherche des fichiers cr‚‚s le %filedate%...
      echo.>>%systemdrive%\rapport.txt
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche fichiers créés le %filedate%>>%systemdrive%\rapport.txt
      echo !!! Attention, les fichiers qui suivent ne sont pas forcément infectés !!!>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt

      dir %HOMEDRIVE%\*.* /4 /A /N /-C | find /i "%filedate%">result.txt
      for /f "tokens=4" %%a in (result.txt) do echo %HOMEDRIVE%\%%a>>%systemdrive%\rapport.txt
      dir %windir%\*.* /4 /A /N /-C | find /i "%filedate%">result.txt
      for /f "tokens=4" %%a in (result.txt) do echo %windir%\%%a>>%systemdrive%\rapport.txt
      dir %syspath%\*.* /4 /A /N /-C | find /i "%filedate%">result.txt
      for /f "tokens=4" %%a in (result.txt) do echo %syspath%\%%a>>%systemdrive%\rapport.txt

      if exist result.txt del result.txt
      if exist result2.txt del result2.txt
      goto sudderltd


      :sudderltd
      echo Recherche pr‚sence de cl‚s corrompues
      echo.>>%systemdrive%\rapport.txt
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt

      regedit.exe /e %systemdrive%\SHUDDERLTD.txt "HKEY_LOCAL_MACHINE\SOFTWARE\SHUDDERLTD"
      IF EXIST %systemdrive%\SHUDDERLTD.txt (
      echo HKLM\SOFTWARE\SHUDDERLTD Présent !>>%systemdrive%\rapport.txt
      del %systemdrive%\SHUDDERLTD.txt
      )

      regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com"
      IF EXIST %systemdrive%\PSGuard.txt (
      echo HKLM\SOFTWARE\PSGuard.com Présent !>>%systemdrive%\rapport.txt
      del %systemdrive%\PSGuard.txt
      )

      regedit.exe /e %systemdrive%\WinHound.txt "HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com"
      IF EXIST %systemdrive%\WinHound.txt (
      echo HKLM\SOFTWARE\WinHound.com Présent !>>%systemdrive%\rapport.txt
      del %systemdrive%\WinHound.txt
      )



      echo Recherche ‚l‚ments du bureau
      echo.>>%systemdrive%\rapport.txt
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt
      IF EXIST desktop.txt del desktop.txt
      regedit.exe /e desktop.txt "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0"
      IF EXIST desktop.txt (
      echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]>>%systemdrive%\rapport.txt
      type desktop.txt | find /i "Source">>%systemdrive%\rapport.txt
      type desktop.txt | find /i "SubscribedURL">>%systemdrive%\rapport.txt
      type desktop.txt | find /i "FriendlyName">>%systemdrive%\rapport.txt
      )
      IF EXIST desktop.txt del desktop.txt

      echo.>>%systemdrive%\rapport.txt

      IF EXIST desktop.txt del desktop.txt
      regedit.exe /e desktop.txt "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1"
      IF EXIST desktop.txt (
      echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]>>%systemdrive%\rapport.txt
      type desktop.txt | find /i "Source">>%systemdrive%\rapport.txt
      type desktop.txt | find /i "SubscribedURL">>%systemdrive%\rapport.txt
      type desktop.txt | find /i "FriendlyName">>%systemdrive%\rapport.txt
      )
      IF EXIST desktop.txt del desktop.txt

      IF EXIST desktop.txt del desktop.txt
      regedit.exe /e desktop.txt "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\2"
      IF EXIST desktop.txt (
      echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\2]>>%systemdrive%\rapport.txt
      type desktop.txt | find /i "Source">>%systemdrive%\rapport.txt
      type desktop.txt | find /i "SubscribedURL">>%systemdrive%\rapport.txt
      type desktop.txt | find /i "FriendlyName">>%systemdrive%\rapport.txt
      )
      IF EXIST desktop.txt del desktop.txt




      echo Recherche Sharedtaskscheduler
      echo.>>%systemdrive%\rapport.txt
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt
      SrchSTS>>%systemdrive%\rapport.txt



      goto wininetscan



      :wininetscan
      echo Recherche infection wininet.dll
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt

      findstr /m /I "OLEADM" %syspath%\wininet.dll>result.txt
      for /F "TOKENS=* DELIMS=" %%A IN (result.txt) do echo wininet.dll infecté !>infected.txt
      findstr /m /I "OLEEXT" %syspath%\wininet.dll>result.txt
      for /F "TOKENS=* DELIMS=" %%A IN (result.txt) do echo wininet.dll infecté !>infected.txt
      del result.txt
      if exist infected.txt (
      del infected.txt
      echo.
      echo %syspath%\wininet.dll infect‚ !
      echo %syspath%\wininet.dll infecté !>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt
      echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche wininet.dll de remplacement>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt
      dir %systemroot%\wininet.dll /a h /s>>%systemdrive%\rapport.txt
      )


      echo.
      echo fin
      echo.>>%systemdrive%\rapport.txt
      echo »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt
      if exist CheckVersion.vbs del CheckVersion.vbs
      if exist result2.txt del result2.txt
      start %windir%\notepad.exe %systemdrive%\rapport.txt
      goto menu











      :fix

      cls
      echo %fixname% %fixvers%
      echo %fixname% %fixvers%>%systemdrive%\rapport.txt
      echo.
      echo.>>%systemdrive%\rapport.txt
      echo Rapport fait à %time% le %date%>>%systemdrive%\rapport.txt
      for /f "Tokens=*" %%i in ('cd') do set CurDir=%%i
      echo Executé à partir de %CurDir%>>%systemdrive%\rapport.txt
      IF ERRORLEVEL 1 (
      echo Executé à partir de >>%systemdrive%\rapport.txt
      cd >>%systemdrive%\rapport.txt
      )
      for /f "Tokens=*" %%i in ('ver') do set Version=%%i
      echo OS: %Version%>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt



      echo Arret des processus...
      echo »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus>>%systemdrive%\rapport.txt
      echo.>>%systemdrive%\rapport.txt

      process -k explorer.exe >NUL

      swsc stop AlfaCleanerService >NUL
      swsc delete AlfaCleanerService >NUL

      Process -k 1.tmp >NUL
      Process -k 3.tmp >NUL
      Process -k 4.tmp >NUL
      Process -k adsmart.exe >NUL
      Process -k adtech2005.exe >NUL
      Process -k adtech2006a.exe >NUL
      Process -k AlfaCleaner.exe >NUL
      Process -k AntivirusGold.exe >NUL
      Process -k batserv2.exe >NUL
      Process -k bsw.exe >NUL
      Process -k bu.exe >NUL
      Process -k bxproxy.exe >NUL
      Process -k cmd32.exe >NUL
      Process -k cmdtel.exe >NUL
      Process -k combo.exe >NUL
      Process -k contextplus.exe >NUL
      Process -k d3dn32.exe >NUL
      Process -k d3pb.exe >NUL
      Process -k doser.exe >NUL
      Process -k ecsiin.stub.exe >NUL
      Process -k efsdfgxg.exe >NUL
      Process -k exa32.exe >NUL
      Process -k exeha2.exe >NUL
      Process -k exeha3.exe >NUL
      Process -k gunist.exe >NUL
      Process -k helper.exe >NUL
      Process -k hookdump.exe >NUL
      Process -k ieengine.exe >NUL
      Process -k ieyi.exe >NUL
      Process -k intel32.exe >NUL
      Process -k intell321.exe >NUL
      Process -k intell32.exe >NUL
      Process -k intmon.exe >NUL
      Process -k intmonp.exe >NUL
      Process -k intxt.exe >NUL
      Process -k kernels32.exe >NUL
      Process -k kernels64.exe >NUL
      Process -k kl.exe >NUL
      Process -k latest.exe >NUL
      Process -k links.exe >NUL
      Process -k ll.exe >NUL
      Process -k
      0
    2. pato Messages postés 5 Statut Membre
       
      merci pour l aide voila le rapport de scan ewido---------------------------------------------------------
      ewido anti-malware - Rapport de scan
      ---------------------------------------------------------

      + Créé le: 10:14:44, 3/03/2006
      + Somme de contrôle: 1EA98FC

      + Résultats du scan:

      C:\Documents and Settings\LocalService\Cookies\system@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Nettoyer et sauvegarder
      C:\Documents and Settings\LocalService\Cookies\system@banners.searchingbooth[1].txt -> TrackingCookie.Searchingbooth : Nettoyer et sauvegarder
      C:\Documents and Settings\LocalService\Cookies\system@media.top-banners[1].txt -> TrackingCookie.Top-banners : Nettoyer et sauvegarder
      C:\Documents and Settings\LocalService\Cookies\system@paypopup[2].txt -> TrackingCookie.Paypopup : Nettoyer et sauvegarder
      C:\Documents and Settings\LocalService\Cookies\system@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Nettoyer et sauvegarder
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\AN01KFGB\wallpap[1].exe -> Hijacker.Agent.gp : Nettoyer et sauvegarder
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WXMZ45M3\ErrorSafeFreeInstall[1].cab/UERS_0001_N68M1801NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
      C:\Documents and Settings\Pat\Cookies\pat@wreport.weborama[1].txt -> TrackingCookie.Weborama : Nettoyer et sauvegarder
      C:\Documents and Settings\Pat\Cookies\pat@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
      C:\Documents and Settings\Pat\Internet Optimizer\optimize.exe -> Downloader.Dyfuca.ei : Nettoyer et sauvegarder
      C:\Documents and Settings\Steph\bleh.exe -> Dropper.Agent.ye : Nettoyer et sauvegarder
      C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UERSV_0001_N68M0602NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
      C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UERSV_0001_N68M0602NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
      C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UERSV_0001_N68M0602NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
      C:\WINDOWS\Downloaded Program Files\UERSV_0001_N68M0602NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
      C:\WINDOWS\Downloaded Program Files\UERS_0001_N68M1801NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
      C:\WINDOWS\eee2.exe -> Adware.MediaMotor : Nettoyer et sauvegarder
      C:\WINDOWS\eeedo.exe/eee2.exe -> Adware.MediaMotor : Nettoyer et sauvegarder
      C:\WINDOWS\sns\index1.exe -> Trojan.LowZones.cf : Nettoyer et sauvegarder
      C:\WINDOWS\sns.exe/sns\index1.exe -> Trojan.LowZones.cf : Nettoyer et sauvegarder
      C:\WINDOWS\surv3.exe -> Downloader.VB.vv : Nettoyer et sauvegarder
      C:\WINDOWS\system32\birdasfihuy32.dll -> Proxy.Small.ct : Nettoyer et sauvegarder
      C:\WINDOWS\system32\bleh.exe -> Dropper.Agent.ye : Nettoyer et sauvegarder
      C:\WINDOWS\system32\bum392.exe -> Downloader.Small.cjd : Nettoyer et sauvegarder
      C:\WINDOWS\system32\csrs.exe -> Backdoor.PoeBot.b : Nettoyer et sauvegarder
      C:\WINDOWS\system32\nzndkece.exe -> Backdoor.Rbot.apd : Nettoyer et sauvegarder
      C:\WINDOWS\system32\svxhost.exe -> Backdoor.Rbot : Nettoyer et sauvegarder
      C:\WINDOWS\system32\voi376.exe -> Downloader.CWS.r : Nettoyer et sauvegarder
      C:\WINDOWS\system32\winldra.exe -> Backdoor.Dumador.fr : Nettoyer et sauvegarder
      C:\WINDOWS\system32\__delete_on_reboot__steam.dll -> Backdoor.Akbot.a : Nettoyer et sauvegarder
      C:\WINDOWS\uninstDsk.exe -> Trojan.Small.ev : Nettoyer et sauvegarder
      C:\WINDOWS\wallpap.exe -> Hijacker.Agent.gp : Nettoyer et sauvegarder


      ::Fin du rapport
      0
  4. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Salut

    tu as double cliker sur le mauvais.Choisis ou c est ecrit smitfraudfix.

    a+
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Salut

    tu as double cliker sur le mauvais.Choisis ou c est ecrit smitfraudfix.

    a+
    0
  7. pato Messages postés 5 Statut Membre
     
    quand je clique la dessus il me dit fichier process.exe absent
    dezippez la totalite de l archive dans un dossier
    0
  8. incognito02 Messages postés 3487 Statut Contributeur 138
     
    salut

    Lorsque tu l as telechargé.Clik droit sur le fichier et choisis extraire tout.Un fichier est extrait a coté de l autre, ouvre le et ouvre smitfraudfix

    a+
    0