Que se passe t il?

bonjour voici mes soucis quand j arrete l ordi il me dit:rundll32.exe ce programme ne repond pas. que dois je faire?
quand j allume spybotsd me dit: a detecte un service systeme qui a ete identifie comme une menace: nom affiche :Command service
cle du registre:cmdService comment l enlever merci d avance pour votre aide

7 réponses

  1. Contributeur
    Bonsoir,

    télécharge HijackThis ici:
    http://www.hijackthis.de/downloads/hijackthis_199.zip

    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre le bien dans c : !
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/Hijenr.gif

    Lance le puis:
    clique sur "do a system scan and save logfile" (cf démo)
    faire un copier coller du log entier sur le forum

    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/demohijack.htm

    Bon courage

    A+
    0
    1. Logfile of HijackThis v1.99.1
      Scan saved at 8:09:23, on 2/03/2006
      Platform: Windows XP (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 (6.00.2600.0000)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\Ontrack\SYSTEM~1\MXTask.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
      C:\Program Files\Logitech\iTouch\iTouch.exe
      C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
      C:\WINDOWS\System32\explorer.exe
      C:\WINDOWS\System32\svxhost.exe
      C:\WINDOWS\System32\rundll32.exe
      C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.1\BHR4.1.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\WINDOWS\System32\mirayyve.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\cllhost.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
      C:\WINDOWS\System32\wuauclt.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\WinZip\WZQKPICK.EXE
      C:\Program Files\DVDAccess\DVDAccess.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\WinRAR\WinRAR.exe
      C:\DOCUME~1\Pat\LOCALS~1\Temp\Rar$EX00.877\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - Default URLSearchHook is missing
      F2 - REG:system.ini: UserInit=userinit.exe
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
      O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-be\msntb.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-be\msntb.dll
      O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
      O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
      O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
      O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\Ontrack\SYSTEM~1\MemCheck.exe
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
      O4 - HKLM\..\Run: [Windows Explorer] C:\WINDOWS\System32\explorer.exe
      O4 - HKLM\..\Run: [AdobeReaderPro] svxhost.exe
      O4 - HKLM\..\Run: [WinDLL (steam.dll)] rundll32.exe C:\WINDOWS\System32\steam.dll,start
      O4 - HKLM\..\Run: [BHR4.1] C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.1\BHR4.1.exe
      O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      O4 - HKLM\..\Run: [mstctd] C:\WINDOWS\System32\mirayyve.exe
      O4 - HKLM\..\Run: [gimmygames] C:\windows\gimmygames11.exe
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [ihost.exe] C:\cllhost.exe
      O4 - HKLM\..\RunServices: [AdobeReaderPro] svxhost.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O4 - Startup: DVDAccess.lnk = C:\Program Files\DVDAccess\DVDAccess.exe
      O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Microsoft Office\Office10\OSA.EXE
      O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
      O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
      O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
      O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
      O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\MICROS~1\Office10\EXCEL.EXE/3000
      O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
      O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
      O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
      O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: SystemSuite Task Manager - Ontrack Data International - C:\PROGRA~1\Ontrack\SYSTEM~1\MXTask.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      0
      1. Contributeur
        Salut

        Télécharge ceci: (merci a S!RI pour ce programme).
        http://siri.urz.free.fr/Fix/SmitfraudFix.zip
        Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1, il va générer un rapport
        Copie/colle le sur le poste stp.

        +

        Ewido:
        http://download.ewido.net/ewido-setup.exe

        Installation puis mises à jour.

        * Lancer et exécuter Ewido pour un scan complet et copier/coller le rapport en forum.

        a+
        0
        1. voila ce que tu m as demande @ECHO OFF

          REM Smitfraud Fix by S!Ri
          REM http://siri.urz.free.fr/Fix/SmitfraudFix.zip

          REM Thanks, Help: balltrap34, moe31, sebdraluorg, Ruby, Vazkor
          REM Miekiemoes Shudder key fix added.
          REM Process.exe by Craig.Peacock added (http://www.beyondlogic.org)
          REM Reboot.exe by Shadowar/Option^Explicit added.
          REM swreg.exe by SteelWerx
          REM swsc.exe by SteelWerx

          set fixname=SmitFraudFix
          set fixvers=v2.21

          VER|find "Windows 95">NUL
          IF NOT ERRORLEVEL 1 GOTO Win
          VER|find "Windows 98">NUL
          IF NOT ERRORLEVEL 1 GOTO Win
          VER|find "Windows Millennium">NUL
          IF NOT ERRORLEVEL 1 GOTO Win
          VER|find "Windows XP">NUL
          IF NOT ERRORLEVEL 1 GOTO NT
          VER|find "Windows 2000">NUL
          IF NOT ERRORLEVEL 1 GOTO NT
          VER|find "Windows 2003">NUL
          IF NOT ERRORLEVEL 1 GOTO NT
          color 47
          echo %fixname% %fixvers%
          echo.
          echo Version non support‚e.
          echo Windows 2000 / XP requis !
          echo.
          pause
          goto end

          :Win
          color 47
          echo %fixname% %fixvers%
          echo.
          echo Version non support‚e.
          echo Windows 2000 / XP requis !
          echo.
          pause
          goto exit

          :NT
          set DoReboot=0
          set syspath=%windir%\system32
          if exist "%userprofile%\Desktop" set desktop=%userprofile%\Desktop
          if exist "%userprofile%\Bureau" set desktop=%userprofile%\Bureau
          if exist "%allusersprofile%\Desktop" set audesktop=%allusersprofile%\Desktop
          if exist "%allusersprofile%\Bureau" set audesktop=%allusersprofile%\Bureau
          if exist "%userprofile%\Favorites" set favorites=%userprofile%\Favorites
          if exist "%userprofile%\Favoris" set favorites=%userprofile%\Favoris
          goto test

          :test
          if not exist Process.exe (
          color 47
          echo %fixname% %fixvers%
          echo.
          echo Fichier Process.exe absent !
          echo Dezippez la totalit‚ de l'archive dans un dossier.
          echo.
          pause
          goto exit
          )

          if not exist swreg.exe (
          color 47
          echo %fixname% %fixvers%
          echo.
          echo Fichier swreg.exe absent !
          echo Dezippez la totalit‚ de l'archive dans un dossier.
          echo.
          pause
          goto exit
          )

          if not exist swsc.exe (
          color 47
          echo %fixname% %fixvers%
          echo.
          echo Fichier swsc.exe absent !
          echo Dezippez la totalit‚ de l'archive dans un dossier.
          echo.
          pause
          goto exit
          )

          if not exist SrchSTS.exe (
          color 47
          echo %fixname% %fixvers%
          echo.
          echo Fichier SrchSTS.exe absent !
          echo Dezippez la totalit‚ de l'archive dans un dossier.
          echo.
          pause
          goto exit
          )

          if not exist %syspath%\Process.exe copy Process.exe %syspath%
          if not exist %syspath%\swreg.exe copy reg.exe %syspath%
          if not exist %syspath%\swsc.exe copy reg.exe %syspath%
          if not exist %syspath%\SrchSTS.exe copy reg.exe %syspath%
          goto menu

          :menu
          color 17
          cls
          echo.
          echo ÉÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ»
          echo º %fixname% %fixvers% º
          echo ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ͹
          echo º 1. Recherche º
          echo º 2. Nettoyage (mode sans echec recommand‚) º
          echo º 3. Effacer les sites de confiance et sensibles º
          echo º Q. Quitter º
          echo ÈÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍͼ
          echo.
          echo Fermez tous les programmes
          echo un red‚marrage peut-ˆtre n‚cessaire
          echo.
          echo.
          set ChoixMenu=''
          set /p ChoixMenu=Entrez votre choix (1,2,3,Q) :
          if '%ChoixMenu%'=='q' GOTO exit
          if '%ChoixMenu%'=='Q' GOTO exit
          if '%ChoixMenu%'=='1' GOTO search
          if '%ChoixMenu%'=='2' GOTO fix
          if '%ChoixMenu%'=='3' GOTO zonefix
          goto menu

          :search
          cls
          echo %fixname% %fixvers%
          echo %fixname% %fixvers%>%systemdrive%\rapport.txt
          echo.
          echo.>>%systemdrive%\rapport.txt
          echo Rapport fait à %time% le %date%>>%systemdrive%\rapport.txt
          for /f "Tokens=*" %%i in ('cd') do set CurDir=%%i
          echo Executé à partir de %CurDir%>>%systemdrive%\rapport.txt
          IF ERRORLEVEL 1 (
          echo Executé à partir de >>%systemdrive%\rapport.txt
          cd >>%systemdrive%\rapport.txt
          )
          for /f "Tokens=*" %%i in ('ver') do set Version=%%i
          echo OS: %Version%>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          echo Recherche %HOMEDRIVE%\...
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %HOMEDRIVE%\>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          pushd %HOMEDRIVE%\

          if exist bsw.exe (echo %HOMEDRIVE%\bsw.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist contextplus.exe (echo %HOMEDRIVE%\contextplus.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist drsmartload1.exe (echo %HOMEDRIVE%\drsmartload1.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist drsmartloadb.exe (echo %HOMEDRIVE%\drsmartloadb.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist ecsiin.stub.exe (echo %HOMEDRIVE%\ecsiin.stub.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist loader.exe (echo %HOMEDRIVE%\loader.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist ntdetecd.exe (echo %HOMEDRIVE%\ntdetecd.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist ntps.exe (echo %HOMEDRIVE%\ntps.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist ntnc.exe (echo %HOMEDRIVE%\ntnc.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist r.exe (echo %HOMEDRIVE%\r.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist secure32.html (echo %HOMEDRIVE%\secure32.html PRESENT !>>%systemdrive%\rapport.txt)
          if exist stub_113_4_0_4_0.exe (echo %HOMEDRIVE%\stub_113_4_0_4_0.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist winstall.exe (echo %HOMEDRIVE%\winstall.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist wp.bmp (echo %HOMEDRIVE%\wp.bmp PRESENT !>>%systemdrive%\rapport.txt)
          if exist wp.exe (echo %HOMEDRIVE%\wp.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist xxx.exe (echo %HOMEDRIVE%\xxx.exe PRESENT !>>%systemdrive%\rapport.txt)

          if exist "%HOMEDRIVE%\spywarevanisher-free" echo %HOMEDRIVE%\spywarevanisher-free\ PRESENT !>>%systemdrive%\rapport.txt

          popd

          echo.>>%systemdrive%\rapport.txt
          echo Recherche %windir%\...
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %windir%>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          pushd %windir%

          if exist adsldpbc.dll (echo %windir%\adsldpbc.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist adsldpbd.dll (echo %windir%\adsldpbd.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist adsldpbe.dll (echo %windir%\adsldpbe.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist adsldpbf.dll (echo %windir%\adsldpbf.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist adtech2005.exe (echo %windir%\adtech2005.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist adtech2006a.exe (echo %windir%\adtech2006a.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist adw.htm (echo %windir%\adw.htm PRESENT !>>%systemdrive%\rapport.txt)
          if exist back.gif (echo %windir%\back.gif PRESENT !>>%systemdrive%\rapport.txt)
          if exist batserv2.exe (echo %windir%\batserv2.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist bg.gif (echo %windir%\bg.gif PRESENT !>>%systemdrive%\rapport.txt)
          if exist blank.mht (echo %windir%\blank.mht PRESENT !>>%systemdrive%\rapport.txt)
          if exist buy.gif (echo %windir%\buy.gif PRESENT !>>%systemdrive%\rapport.txt)
          if exist bxproxy.exe (echo %windir%\bxproxy.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist country.exe (echo %windir%\country.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist d3dn32.exe (echo %windir%\d3dn32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist d3??.dll (echo %windir%\d3??.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist d3pb.exe (echo %windir%\d3pb.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist desktop.html (echo %windir%\desktop.html PRESENT !>>%systemdrive%\rapport.txt)
          if exist download-btn.gif (echo %windir%\download-btn.gif PRESENT !>>%systemdrive%\rapport.txt)
          if exist drsmartload.dat (echo %windir%\drsmartload.dat PRESENT !>>%systemdrive%\rapport.txt)
          if exist drsmartloadb1.dat (echo %windir%\drsmartloadb1.dat PRESENT !>>%systemdrive%\rapport.txt)
          if exist kl.exe (echo %windir%\kl.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist icont.exe (echo %windir%\icont.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist ieyi.dll (echo %windir%\ieyi.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist ieyi.exe (echo %windir%\ieyi.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist ms1.exe (echo %windir%\ms1.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist notepad.com (echo %windir%\notepad.com PRESENT !>>%systemdrive%\rapport.txt)
          if exist popuper.exe (echo %windir%\popuper.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist psg.exe (echo %windir%\psg.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist q*_disk.dll (echo %windir%\q*_disk.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist rzs.exe (echo %windir%\rzs.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist sachostx.exe (echo %windir%\sachostx.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist screen.html (echo %windir%\screen.html PRESENT !>>%systemdrive%\rapport.txt)
          if exist sec.exe (echo %windir%\sec.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist sdkcb.dll (echo %windir%\sdkcb.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist sdkqq.exe (echo %windir%\sdkqq.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist secure32.html (echo %windir%\secure32.html PRESENT !>>%systemdrive%\rapport.txt)
          if exist sites.ini (echo %windir%\sites.ini PRESENT !>>%systemdrive%\rapport.txt)
          if exist slassac.dll (echo %windir%\slassac.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist svchost.exe (echo %windir%\svchost.exe PRESENT!>>%systemdrive%\rapport.txt)
          if exist sysldr32.exe (echo %windir%\sysldr32.exe PRESENT!>>%systemdrive%\rapport.txt)
          if exist sysen.exe (echo %windir%\sysen.exe PRESENT!>>%systemdrive%\rapport.txt)
          if exist temp.000.exe (echo %windir%\temp.000.exe PRESENT!>>%systemdrive%\rapport.txt)
          if exist timessquare.exe (echo %windir%\timessquare.exe PRESENT!>>%systemdrive%\rapport.txt)
          if exist timessquare1.dat (echo %windir%\timessquare1.dat PRESENT!>>%systemdrive%\rapport.txt)
          if exist tool1.exe (echo %windir%\tool1.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist tool2.exe (echo %windir%\tool2.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist tool3.exe (echo %windir%\tool3.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist tool4.exe (echo %windir%\tool4.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist tool5.exe (echo %windir%\tool5.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist toolbar.exe (echo %windir%\toolbar.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist uninstDsk.exe (echo %windir%\uninstDsk.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist uninstIU.exe (echo %windir%\uninstIU.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist update13.js (echo %windir%\update13.js PRESENT !>>%systemdrive%\rapport.txt)
          if exist warnhp.html (echo %windir%\warnhp.html PRESENT !>>%systemdrive%\rapport.txt)
          if exist winsysupd.exe (echo %windir%\winsysupd.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist winsysban.exe (echo %windir%\winsysban.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist windows.html (echo %windir%\windows.html PRESENT !>>%systemdrive%\rapport.txt)
          if exist zloader3.exe (echo %windir%\zloader3.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist __delete_on_reboot__popuper.exe (echo %windir%\__delete_on_reboot__popuper.exe PRESENT !>>%systemdrive%\rapport.txt)

          if exist "%windir%\inet20001" echo %windir%\inet20001\ PRESENT!>>%systemdrive%\rapport.txt
          if exist "%windir%\inet20010" echo %windir%\inet20010\ PRESENT!>>%systemdrive%\rapport.txt
          if exist "%windir%\inet20066" echo %windir%\inet20066\ PRESENT!>>%systemdrive%\rapport.txt
          if exist "%windir%\inet20099" echo %windir%\inet20099\ PRESENT!>>%systemdrive%\rapport.txt

          popd

          echo.>>%systemdrive%\rapport.txt
          echo Recherche %windir%\system...
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %windir%\system>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          pushd %windir%\system

          if exist csrss.exe (echo %windir%\system\csrss.exe PRESENT!>>%systemdrive%\rapport.txt)
          if exist svchost.exe (echo %windir%\system\svchost.exe PRESENT!>>%systemdrive%\rapport.txt)
          if exist svchost.dll (echo %windir%\system\svchost.dll PRESENT!>>%systemdrive%\rapport.txt)
          if exist svwhost.exe (echo %windir%\system\svwhost.exe PRESENT!>>%systemdrive%\rapport.txt)
          if exist svwhost.dll (echo %windir%\system\svwhost.dll PRESENT!>>%systemdrive%\rapport.txt)

          popd

          echo.>>%systemdrive%\rapport.txt
          echo Recherche %windir%\Web...
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %windir%\Web>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          pushd %windir%\Web

          if exist desktop.html (echo %windir%\Web\desktop.html PRESENT!>>%systemdrive%\rapport.txt)
          if exist wallpaper.html (echo %windir%\Web\wallpaper.html PRESENT!>>%systemdrive%\rapport.txt)

          popd

          echo.>>%systemdrive%\rapport.txt
          echo Recherche %syspath%...
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %syspath%>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          pushd %syspath%

          if exist ~update.exe (echo %syspath%\~update.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Air Tickets.ico" (echo %syspath%\Air Tickets.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist AdService.dll (echo %syspath%\AdService.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist adsmart.exe (echo %syspath%\adsmart.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist bhoimpl.dll (echo %syspath%\bhoimpl.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Big Tits.ico" (echo %syspath%\Big Tits.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist birdihuy.dll (echo %syspath%\birdihuy.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist birdihuy32.dll (echo %syspath%\birdihuy32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist Blackjack.ico (echo %syspath%\Blackjack.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist bnmsrv.exe (echo %syspath%\bnmsrv.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist bre.dll (echo %syspath%\bre.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist bre32.dll (echo %syspath%\bre32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist browsela.dll (echo %syspath%\browsela.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Britney Spears.ico" (echo %syspath%\Britney Spears.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist bu.exe (echo %syspath%\bu.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Car Insurance.ico" (echo %syspath%\Car Insurance.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist casino.ico (echo %syspath%\casino.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Cheap Cigarettes.ico" (echo %syspath%\Cheap Cigarettes.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist child.dll (echo %syspath%\child.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist chp.dll (echo %syspath%\chp.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist cmd32.exe (echo %syspath%\cmd32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist cmdtel.exe (echo %syspath%\cmdtel.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist cnymxw32.dll (echo %syspath%\cnymxw32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist combo.exe (echo %syspath%\combo.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Credit Card.ico" (echo %syspath%\Credit Card.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist Cruises.ico (echo %syspath%\Cruises.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Currency Trading.ico" (echo %syspath%\Currency Trading.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist cvxh8jkdq?.exe (echo %syspath%\cvxh8jkdq?.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist date.ico (echo %syspath%\date.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist dial23.exe (echo %syspath%\dial23.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist doser.exe (echo %syspath%\doser.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist dxmpp.dll (echo %syspath%\dxmpp.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist efsdfgxg.exe (echo %syspath%\efsdfgxg.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist exa32.exe (echo %syspath%\exa32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist exeha2.exe (echo %syspath%\exeha2.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist exeha3.exe (echo %syspath%\exeha3.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist games.ico (echo %syspath%\games.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist gunist.exe (echo %syspath%\gunist.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist helper.exe (echo %syspath%\helper.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist hhk.dll (echo %syspath%\hhk.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist hookdump.exe (echo %syspath%\hookdump.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist hp????.tmp (echo %syspath%\hp????.tmp PRESENT !>>%systemdrive%\rapport.txt)
          if exist IeHelperEx.dll (echo %syspath%\IeHelperEx.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist intel32.exe (echo %syspath%\intel32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist intell321.exe (echo %syspath%\intell321.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist intell32.exe (echo %syspath%\intell32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist intmon.exe (echo %syspath%\intmon.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist intmonp.exe (echo %syspath%\intmonp.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist intxt.exe (echo %syspath%\intxt.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist ioctrl.dll (echo %syspath%\ioctrl.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist kernels32.exe (echo %syspath%\kernels32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist kernels64.exe (echo %syspath%\kernels64.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist latest.exe (echo %syspath%\latest.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Lesbian Sex.ico" (echo %syspath%\Lesbian Sex.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist ld????.tmp (echo %syspath%\ld????.tmp PRESENT !>>%systemdrive%\rapport.txt)
          if exist links.exe (echo %syspath%\links.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist ll.exe (echo %syspath%\ll.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist maxd1.exe (echo %syspath%\maxd1.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist maxd64.exe (echo %syspath%\maxd64.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist migicons.exe (echo %syspath%\migicons.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist mobile.ico (echo %syspath%\mobile.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist MP3.ico (echo %syspath%\MP3.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist msbe.dll (echo %syspath%\msbe.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist mscornet.exe (echo %syspath%\mscornet.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist mssearchnet.exe (echo %syspath%\mssearchnet.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist msmsgs.exe (echo %syspath%\msmsgs.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist msnscps.dll (echo %syspath%\msnscps.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist msole32.exe (echo %syspath%\msole32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist mspostsp.exe.exe (echo %syspath%\mspostsp.exe.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist msupdate32.dll (echo %syspath%\msupdate32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist msvcp.exe.exe (echo %syspath%\msvcp.exe.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist msvol.tlb (echo %syspath%\msvol.tlb PRESENT !>>%systemdrive%\rapport.txt)
          if exist mswinb32.dll (echo %syspath%\mswinb32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist mswinb32.exe (echo %syspath%\mswinb32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist mswinf32.dll (echo %syspath%\mswinf32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist mswinf32.exe (echo %syspath%\mswinf32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist mswinup32.dll (echo %syspath%\mswinup32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist mswinxml.dll (echo %syspath%\mswinxml.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist MTC.dll (echo %syspath%\MTC.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist MTC.ini (echo %syspath%\MTC.ini PRESENT !>>%systemdrive%\rapport.txt)
          if exist multitran.exe (echo %syspath%\multitran.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist ncompat.tlb (echo %syspath%\ncompat.tlb PRESENT !>>%systemdrive%\rapport.txt)
          if exist network.ico (echo %syspath%\network.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist netwrap.dll (echo %syspath%\netwrap.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist notepad.com (echo %syspath%\notepad.com PRESENT !>>%systemdrive%\rapport.txt)
          if exist NTCommLib3.exe (echo %syspath%\NTCommLib3.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist nuclabdll.dll (echo %syspath%\nuclabdll.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist nvctrl.exe (echo %syspath%\nvctrl.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist nvms.dll (echo %syspath%\nvms.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist ole32vbs.exe (echo %syspath%\ole32vbs.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist oleadm.dll (echo %syspath%\oleadm.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist oleadm32.dll (echo %syspath%\oleadm32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist oleext.dll (echo %syspath%\oleext.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist oleext32.dll (echo %syspath%\oleext32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Online Betting.ico" (echo %syspath%\Online Betting.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Online Gambling.ico" (echo %syspath%\Online Gambling.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Oral Sex.ico" (echo %syspath%\Oral Sex.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist ot.ico (echo %syspath%\ot.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist param32.dll (echo %syspath%\param32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist paradise.raw.exe (echo %syspath%\paradise.raw.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Party Poker.ico" (echo %syspath%\Party Poker.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist paytime.exe (echo %syspath%\paytime.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist perfcii.ini (echo %syspath%\perfcii.ini PRESENT !>>%systemdrive%\rapport.txt)
          if exist performent217.dll (echo %syspath%\performent217.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist pharm.ico (echo %syspath%\pharm.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist pharm2.ico (echo %syspath%\pharm2.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist Pharmacy.ico (echo %syspath%\Pharmacy.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist Phentermine.ico (echo %syspath%\Phentermine.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist pop_up.dll (echo %syspath%\pop_up.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist Pornstars.ico (echo %syspath%\Pornstars.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist priva.exe (echo %syspath%\priva.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist prflbmsgp32.dll (echo %syspath%\prflbmsgp32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist qvxgamet?.exe (echo %syspath%\qvxgamet?.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Remove Spyware.ico" (echo %syspath%\Remove Spyware.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist replmap.dll (echo %syspath%\replmap.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist RpcxSs.dll (echo %syspath%\RpcxSs.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist runsrv32.dll (echo %syspath%\runsrv32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist runsrv32.exe (echo %syspath%\runsrv32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist sachostc.exe (echo %syspath%\sachostc.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist sachostp.exe (echo %syspath%\sachostp.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist sachosts.exe (echo %syspath%\sachosts.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist scanner.ico (echo %syspath%\scanner.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist sdfdil.exe (echo %syspath%\sdfdil.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist searchdll.dll (echo %syspath%\searchdll.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist sender.exe (echo %syspath%\sender.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist shdochp.dll (echo %syspath%\shdochp.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist shdochp.exe (echo %syspath%\shdochp.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist shdochop.dll (echo %syspath%\shdochop.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist shdocnva.dll (echo %syspath%\shdocnva.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist shdocsvc.dll (echo %syspath%\shdocsvc.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist shdocsvc.exe (echo %syspath%\shdocsvc.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist shell386.exe (echo %syspath%\shell386.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist shnlog.exe (echo %syspath%\shnlog.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist shsexl32.dll (echo %syspath%\shsexl32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist socks.exe (echo %syspath%\socks.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist spam.ico (echo %syspath%\spam.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist split.exe (echo %syspath%\split.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist split1.exe (echo %syspath%\split1.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist split2.exe (echo %syspath%\split2.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist spyware.ico (echo %syspath%\spyware.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist srpcsrv32.dll (echo %syspath%\srpcsrv32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist srpcsrv32.exe (echo %syspath%\srpcsrv32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist st3.dll (echo %syspath%\st3.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist svchop.exe (echo %syspath%\svchop.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist svchosts.dll (echo %syspath%\svchosts.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist svchosts.exe (echo %syspath%\svchosts.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist svcnt.exe (echo %syspath%\svcnt.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist svcnt32.exe (echo %syspath%\svcnt32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist svcnva.exe (echo %syspath%\svcnva.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist svwhost.exe (echo %syspath%\svwhost.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist symsvcsa.exe (echo %syspath%\symsvcsa.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist sysbho.exe (echo %syspath%\sysbho.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist sysinit32z.exe (echo %syspath%\sysinit32z.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist sysjv32.exe (echo %syspath%\sysjv32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist sysmain.dll (echo %syspath%\sysmain.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist sysvcs.exe (echo %syspath%\sysvcs.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist sywsvcs.exe (echo %syspath%\sywsvcs.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist taras.exe (echo %syspath%\taras.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist tcpservice2.exe (echo %syspath%\tcpservice2.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist trf32.dll (echo %syspath%\trf32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist ts.ico (echo %syspath%\ts.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist txfdb32.dll (echo %syspath%\txfdb32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist viagra.ico (echo %syspath%\viagra.ico PRESENT !>>%systemdrive%\rapport.txt)
          if exist vxgame?.exe (echo %syspath%\vxgame?.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist vxgame?.exe????.exe (echo %syspath%\vxgame?.exe????.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist vxgame?.exe????.exe.bak (echo %syspath%\vxgame?.exe????.exe.bak PRESENT !>>%systemdrive%\rapport.txt)
          if exist vxgamet?.exe (echo %syspath%\vxgamet?.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist vxgamet?.exe????.exe (echo %syspath%\vxgamet?.exe????.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist vxh8jkdq?.exe (echo %syspath%\vxh8jkdq?.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist w8673492.exe (echo %syspath%\w8673492.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist wbeconm.dll (echo %syspath%\wbeconm.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist web.exe (echo %syspath%\web.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist wiatwain.dll (echo %syspath%\wiatwain.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist winapi32.dll (echo %syspath%\winapi32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist windesktop.dll (echo %syspath%\windesktop.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist windesktop.exe (echo %syspath%\windesktop.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist winldra.exe (echo %syspath%\winldra.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist winlfl32.dll (echo %syspath%\winlfl32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist winnook.exe (echo %syspath%\winnook.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist winstyle2.dll (echo %syspath%\winstyle2.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist winstyle3.dll (echo %syspath%\winstyle3.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist winstyle32.dll (echo %syspath%\winstyle32.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist wldr.dll (echo %syspath%\wldr.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist wp.bmp (echo %syspath%\wp.bmp PRESENT !>>%systemdrive%\rapport.txt)
          if exist wppp.html (echo %syspath%\wppp.html PRESENT !>>%systemdrive%\rapport.txt)
          if exist wstart.dll (echo %syspath%\wstart.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist x.exe (echo %syspath%\x.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist yaemu.exe (echo %syspath%\yaemu.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist z11.exe (echo %syspath%\z11.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist z12.exe (echo %syspath%\z12.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist z13.exe (echo %syspath%\z13.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist z14.exe (echo %syspath%\z14.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist z15.exe (echo %syspath%\z15.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist z16.exe (echo %syspath%\z16.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist zlbw.dll (echo %syspath%\zlbw.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist zolker011.dll (echo %syspath%\zolker011.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist ztoolb011.dll (echo %syspath%\ztoolb011.dll PRESENT !>>%systemdrive%\rapport.txt)
          if exist ztoolbar.bmp (echo %syspath%\ztoolbar.bmp PRESENT !>>%systemdrive%\rapport.txt)
          if exist ztoolbar.xml (echo %syspath%\ztoolbar.xml PRESENT !>>%systemdrive%\rapport.txt)
          if exist __delete_on_reboot__intmon.exe (echo %syspath%\__delete_on_reboot__intmon.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist __delete_on_reboot__intel32.exe (echo %syspath%\__delete_on_reboot__intel32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist __delete_on_reboot__intell32.exe (echo %syspath%\__delete_on_reboot__intell32.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist __delete_on_reboot__OLEADM.dll (echo %syspath%\__delete_on_reboot__OLEADM.dll PRESENT !>>%systemdrive%\rapport.txt)

          if exist "%syspath%\1024" echo %syspath%\1024\ PRESENT!>>%systemdrive%\rapport.txt

          if exist "%syspath%\drivers\hesvc.sys" echo %syspath%\drivers\hesvc.sys PRESENT!>>%systemdrive%\rapport.txt

          popd

          if NOT exist %syspath%\LogFiles goto suiteScanAppData

          echo.>>%systemdrive%\rapport.txt
          echo Recherche %syspath%\LogFiles...
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %syspath%\LogFiles>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          pushd %syspath%\LogFiles

          if exist A5281300.so (echo %syspath%\A5281300.so PRESENT !>>%systemdrive%\rapport.txt)
          if exist T54111925.so (echo %syspath%\T54111925.so PRESENT !>>%systemdrive%\rapport.txt)
          if exist H53131712.so (echo %syspath%\H53131712.so PRESENT !>>%systemdrive%\rapport.txt)
          if exist A54102200.so (echo %syspath%\A54102200.so PRESENT !>>%systemdrive%\rapport.txt)
          if exist S53252000.so (echo %syspath%\S53252000.so PRESENT !>>%systemdrive%\rapport.txt)
          if exist A04111925.so (echo %syspath%\A04111925.so PRESENT !>>%systemdrive%\rapport.txt)
          if exist M54111925.so (echo %syspath%\M54111925.so PRESENT !>>%systemdrive%\rapport.txt)
          if exist P54111925.so (echo %syspath%\P54111925.so PRESENT !>>%systemdrive%\rapport.txt)

          popd

          :suiteScanAppData
          echo.>>%systemdrive%\rapport.txt
          echo Recherche %userprofile%\Application Data...
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche ...\Application Data>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          if exist "%HOMEDRIVE%\Documents and Settings\LocalService\Application Data\AlfaCleaner" echo %HOMEDRIVE%\Documents and Settings\LocalService\Application Data\AlfaCleaner PRESENT !>>%systemdrive%\rapport.txt

          pushd %userprofile%\Application Data

          if exist "%userprofile%\Application Data\Install.dat" echo %userprofile%\Application Data\Install.dat PRESENT !>>%systemdrive%\rapport.txt
          if exist "%userprofile%\Application Data\AlfaCleaner" echo %userprofile%\Application Data\AlfaCleaner PRESENT !>>%systemdrive%\rapport.txt
          if exist "%userprofile%\Application Data\PSGuard.com" echo %userprofile%\Application Data\PSGuard.com PRESENT !>>%systemdrive%\rapport.txt
          if exist "%userprofile%\Application Data\Shudder Global Limited" echo %userprofile%\Application Data\Shudder Global Limited PRESENT !>>%systemdrive%\rapport.txt
          if exist "%userprofile%\Application Data\Skinux" echo %userprofile%\Application Data\Skinux PRESENT !>>%systemdrive%\rapport.txt

          if exist "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\AlfaCleaner.lnk" echo %userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\AlfaCleaner.lnk PRESENT !>>%systemdrive%\rapport.txt
          if exist "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\SpywareStrike 2.5.lnk" echo %userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\SpywareStrike 2.5.lnk PRESENT !>>%systemdrive%\rapport.txt
          if exist "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyFalcon 2.0.lnk" echo %userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyFalcon 2.0.lnk PRESENT !>>%systemdrive%\rapport.txt

          popd

          echo.>>%systemdrive%\rapport.txt
          echo Recherche Menu D‚marrer...
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          if exist "%userprofile%\Menu D‚marrer\SpyAxe 3.0.lnk" (echo %userprofile%\Menu Démarrer\SpyAxe 3.0.lnk PRESENT !>>%systemdrive%\rapport.txt)
          if exist "%userprofile%\Menu D‚marrer\SpyFalcon 2.0.lnk" (echo %userprofile%\Menu Démarrer\SpyFalcon 2.0.lnk PRESENT !>>%systemdrive%\rapport.txt)
          if exist "%userprofile%\Menu D‚marrer\SpywareStrike 2.5.lnk" (echo %userprofile%\Menu Démarrer\SpywareStrike 2.5.lnk PRESENT !>>%systemdrive%\rapport.txt)
          if exist "%userprofile%\Menu D‚marrer\Programmes\SpyAxe" (echo %userprofile%\Menu Démarrer\Programmes\SpyAxe PRESENT !>>%systemdrive%\rapport.txt)
          if exist "%userprofile%\Menu D‚marrer\Programmes\SpyFalcon" (echo %userprofile%\Menu Démarrer\Programmes\SpyFalcon PRESENT !>>%systemdrive%\rapport.txt)
          if exist "%userprofile%\Menu D‚marrer\Programmes\SpySheriff" (echo %userprofile%\Menu Démarrer\Programmes\SpySheriff PRESENT !>>%systemdrive%\rapport.txt)
          if exist "%userprofile%\Menu D‚marrer\Programmes\SpywareStrike" (echo %userprofile%\Menu Démarrer\Programmes\SpywareStrike PRESENT !>>%systemdrive%\rapport.txt)
          if exist "%allusersprofile%\Menu D‚marrer\PopUp Blocker.url" (echo %allusersprofile%\Menu Démarrer\PopUp Blocker.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "%allusersprofile%\Menu D‚marrer\Spyware Remover.url" (echo %allusersprofile%\Menu Démarrer\Spyware Remover.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "%allusersprofile%\Menu D‚marrer\Programmes\AlfaCleaner" (echo %allusersprofile%\Menu Démarrer\Programmes\AlfaCleaner PRESENT !>>%systemdrive%\rapport.txt)
          if exist "%allusersprofile%\Menu D‚marrer\Programmes\P.S.Guard spyware remover" (echo %allusersprofile%\Menu Démarrer\Programmes\P.S.Guard spyware remover PRESENT !>>%systemdrive%\rapport.txt)
          if exist "%allusersprofile%\Menu D‚marrer\Programmes\WinHound spyware remover" (echo %allusersprofile%\Menu Démarrer\Programmes\WinHound spyware remover PRESENT !>>%systemdrive%\rapport.txt)

          echo.>>%systemdrive%\rapport.txt
          echo Recherche %desktop%...
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          pushd %desktop%

          if exist "access" (echo %desktop%\access PRESENT !>>%systemdrive%\rapport.txt)
          if exist asfds (echo %desktop%\asfds PRESENT !>>%systemdrive%\rapport.txt)
          if exist "domains" (echo %desktop%\domains PRESENT !>>%systemdrive%\rapport.txt)
          if exist "map.txt" (echo %desktop%\map.txt PRESENT !>>%systemdrive%\rapport.txt)
          if exist m00.exe (echo %desktop%\m00.exe PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Air Tickets.url" (echo %desktop%\Air Tickets.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist AlfaCleaner.lnk (echo %desktop%\AlfaCleaner.lnk PRESENT !>>%systemdrive%\rapport.txt)
          if exist AntivirusGold.lnk (echo %desktop%\AntivirusGold.lnk PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Big Tits.url" (echo %desktop%\Big Tits.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist Blackjack.url (echo %desktop%\Blackjack.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist Blowjob.url (echo %desktop%\Blowjob.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Britney Spears.url" (echo %desktop%\Britney Spears.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Car Insurance.url" (echo %desktop%\Car Insurance.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist cdegfr (echo %desktop%\cdegfr PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Cheap Cigarettes.url" (echo %desktop%\Cheap Cigarettes.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Cigarettes Discount.url" (echo %desktop%\Cigarettes Discount.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Credit Card.url" (echo %desktop%\Credit Card.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist Cruises.url (echo %desktop%\Cruises.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Currency Trading.url" (echo %desktop%\Currency Trading.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist fdsf (echo %desktop%\fdsf PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Forex Trading.url" (echo %desktop%\Forex Trading.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Free Ringtones.url" (echo %desktop%\Free Ringtones.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Gift Ideas.url" (echo %desktop%\Gift Ideas.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Group Sex.url" (echo %desktop%\Group Sex.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Home Loan.url" (echo %desktop%\Home Loan.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Lesbian Sex.url" (echo %desktop%\Lesbian Sex.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist MP3.url (echo %desktop%\MP3.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Mp3 Download.url" (echo %desktop%\Mp3 Download.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Online Betting.url" (echo %desktop%\Online Betting.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Online Casino.url" (echo %desktop%\Online Casino.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Online Dating.url" (echo %desktop%\Online Dating.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Online Gambling.url" (echo %desktop%\Online Gambling.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Oral Sex.url" (echo %desktop%\Oral Sex.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Party Poker.url" (echo %desktop%\Party Poker.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist Pharmacy.url (echo %desktop%\Pharmacy.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist Phentermine.url (echo %desktop%\Phentermine.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Play Poker.url" (echo %desktop%\Play Poker.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "PopUp Blocker.url" (echo %desktop%\PopUp Blocker.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Porn Dvd.url" (echo %desktop%\Porn Dvd.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist Pornstars.url (echo %desktop%\Pornstars.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "P.S.Guard spyware remover.lnk" (echo %desktop%\P.S.Guard spyware remover.lnk PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Real Estate.url" (echo %desktop%\Real Estate.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Remove Spyware.url" (echo %desktop%\Remove Spyware.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist sdfdsf (echo %desktop%\sdfdsf PRESENT !>>%systemdrive%\rapport.txt)
          if exist sdfff (echo %desktop%\sdfff PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Sport Betting.url" (echo %desktop%\Sport Betting.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist SpyFalcon.lnk (echo %desktop%\SpyFalcon.lnk PRESENT !>>%systemdrive%\rapport.txt)
          if exist SpySheriff.lnk (echo %desktop%\SpySheriff.lnk PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Spyware Remover.url" (echo %desktop%\Spyware Remover.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist SpywareStrike.lnk (echo %desktop%\SpywareStrike.lnk PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Texas Holdem.url" (echo %desktop%\Texas Holdem.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist viagra.url (echo %desktop%\viagra.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist wdcevf (echo %desktop%\wdcevf PRESENT !>>%systemdrive%\rapport.txt)
          if exist wdcevf (echo %desktop%\wdcevf PRESENT !>>%systemdrive%\rapport.txt)
          if exist zxczxc (echo %desktop%\zxczxc PRESENT !>>%systemdrive%\rapport.txt)

          popd

          pushd %audesktop%

          if exist "Air Tickets.url" (echo %audesktop%\Air Tickets.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist AntivirusGold.lnk (echo %audesktop%\AntivirusGold.lnk PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Big Tits.url" (echo %audesktop%\Big Tits.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist Blackjack.url (echo %audesktop%\Blackjack.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist Blowjob.url (echo %audesktop%\Blowjob.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Britney Spears.url" (echo %audesktop%\Britney Spears.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Car Insurance.url" (echo %audesktop%\Car Insurance.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Cheap Cigarettes.url" (echo %audesktop%\Cheap Cigarettes.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Cigarettes Discount.url" (echo %audesktop%\Cigarettes Discount.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Credit Card.url" (echo %audesktop%\Credit Card.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist Cruises.url (echo %audesktop%\Cruises.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Currency Trading.url" (echo %audesktop%\Currency Trading.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Forex Trading.url" (echo %audesktop%\Forex Trading.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Free Ringtones.url" (echo %audesktop%\Free Ringtones.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Gift Ideas.url" (echo %audesktop%\Gift Ideas.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Group Sex.url" (echo %audesktop%\Group Sex.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Home Loan.url" (echo %audesktop%\Home Loan.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Lesbian Sex.url" (echo %audesktop%\Lesbian Sex.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Mp3 Download.url" (echo %audesktop%\Mp3 Download.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist MP3.url (echo %audesktop%\MP3.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Online Betting.url" (echo %audesktop%\Online Betting.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Online Casino.url" (echo %audesktop%\Online Casino.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Online Dating.url" (echo %audesktop%\Online Dating.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Online Gambling.url" (echo %audesktop%\Online Gambling.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Oral Sex.url" (echo %audesktop%\Oral Sex.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Party Poker.url" (echo %audesktop%\Party Poker.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist Pharmacy.url (echo %audesktop%\Pharmacy.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist Phentermine.url (echo %audesktop%\Phentermine.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Play Poker.url" (echo %audesktop%\Play Poker.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "PopUp Blocker.url" (echo %audesktop%\PopUp Blocker.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Porn Dvd.url" (echo %audesktop%\Porn Dvd.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist Pornstars.url (echo %audesktop%\Pornstars.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "P.S.Guard spyware remover.lnk" (echo %audesktop%\P.S.Guard spyware remover.lnk PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Real Estate.url" (echo %audesktop%\Real Estate.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Remove Spyware.url" (echo %audesktop%\Remove Spyware.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Sport Betting.url" (echo %audesktop%\Sport Betting.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist SpySheriff.lnk (echo %audesktop%\SpySheriff.lnk PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Spyware Remover.url" (echo %audesktop%\Spyware Remover.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist viagra.url (echo %audesktop%\viagra.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "Texas Holdem.url" (echo %audesktop%\Texas Holdem.url PRESENT !>>%systemdrive%\rapport.txt)
          if exist "WinHound spyware remover.lnk" (echo %audesktop%\WinHound spyware remover.lnk PRESENT !>>%systemdrive%\rapport.txt)

          popd

          echo.>>%systemdrive%\rapport.txt
          echo Recherche %ProgramFiles%...
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %ProgramFiles% >>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          if exist "%ProgramFiles%\AdwareDelete" echo %ProgramFiles%\AdwareDelete\ PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\AlfaCleaner" echo %ProgramFiles%\AlfaCleaner\ PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\AntivirusGold" echo %ProgramFiles%\AntivirusGold\ PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Daily Weather Forecast" echo %ProgramFiles%\Daily Weather Forecast\ PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\PSGuard" echo %ProgramFiles%\PSGuard\ PRESENT!>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\P.S.Guard" echo %ProgramFiles%\P.S.Guard\ PRESENT!>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Search Maid" echo %ProgramFiles%\Search Maid\ PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Security IGuard" echo %ProgramFiles%\Security IGuard\ PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\SpyAxe" echo %ProgramFiles%\SpyAxe\ PRESENT!>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\SpyFalcon" echo %ProgramFiles%\SpyFalcon\ PRESENT!>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\SpySheriff" echo %ProgramFiles%\SpySheriff\ PRESENT!>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\SpyKiller" echo %ProgramFiles%\SpyKiller\ PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\SpywareStrike" echo %ProgramFiles%\SpywareStrike\ PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Virtual Maid" echo %ProgramFiles%\Virtual Maid\ PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\WinHound" echo %ProgramFiles%\WinHound\ PRESENT !>>%systemdrive%\rapport.txt

          if exist "%ProgramFiles%\internet explorer\ieengine.exe" echo %ProgramFiles%\internet explorer\ieengine.exe PRESENT !>>%systemdrive%\rapport.txt

          if exist "%ProgramFiles%\Fichiers communs\Download\mc-58-12-0000113.exe" echo %ProgramFiles%\Fichiers communs\Download\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Common Files\Download\mc-58-12-0000113.exe" echo %ProgramFiles%\Common Files\Download\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Fichiers communs\InetGet\mc-58-12-0000113.exe" echo %ProgramFiles%\Fichiers communs\InetGet\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Common Files\InetGet\mc-58-12-0000113.exe" echo %ProgramFiles%\Common Files\InetGet\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Fichiers communs\muwq\ echo %ProgramFiles%\Fichiers communs\muwq\" PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Common Files\muwq\ echo %ProgramFiles%\Common Files\muwq\" PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Fichiers communs\Windows\mc-58-12-0000113.exe" echo %ProgramFiles%\Fichiers communs\Windows\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Common Files\Windows\mc-58-12-0000113.exe" echo %ProgramFiles%\Common Files\Windows\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Fichiers communs\Windows\services32.exe" echo %ProgramFiles%\Fichiers communs\Windows\services32.exe PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Common Files\Windows\services32.exe" echo %ProgramFiles%\Common Files\Windows\services32.exe PRESENT !>>%systemdrive%\rapport.txt

          if exist "%ProgramFiles%\Common Files\VCClient\VCMain.exe" echo %ProgramFiles%\Common Files\VCClient\VCMain.exe PRESENT !>>%systemdrive%\rapport.txt
          if exist "%ProgramFiles%\Common Files\VCClient\VCClient.exe" echo %ProgramFiles%\Common Files\VCClient\VCClient.exe PRESENT !>>%systemdrive%\rapport.txt

          if exist %syspath%\intell32.exe goto DateFile
          goto sudderltd

          :DateFile
          dir %syspath%\intell32.exe /4 /A /N /-C>result.txt
          type result.txt | find /i "intell32.exe">result2.txt
          for /f "tokens=1" %%a in (result2.txt) do set filedate=%%a

          echo Recherche des fichiers cr‚‚s le %filedate%...
          echo.>>%systemdrive%\rapport.txt
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche fichiers créés le %filedate%>>%systemdrive%\rapport.txt
          echo !!! Attention, les fichiers qui suivent ne sont pas forcément infectés !!!>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          dir %HOMEDRIVE%\*.* /4 /A /N /-C | find /i "%filedate%">result.txt
          for /f "tokens=4" %%a in (result.txt) do echo %HOMEDRIVE%\%%a>>%systemdrive%\rapport.txt
          dir %windir%\*.* /4 /A /N /-C | find /i "%filedate%">result.txt
          for /f "tokens=4" %%a in (result.txt) do echo %windir%\%%a>>%systemdrive%\rapport.txt
          dir %syspath%\*.* /4 /A /N /-C | find /i "%filedate%">result.txt
          for /f "tokens=4" %%a in (result.txt) do echo %syspath%\%%a>>%systemdrive%\rapport.txt

          if exist result.txt del result.txt
          if exist result2.txt del result2.txt
          goto sudderltd

          :sudderltd
          echo Recherche pr‚sence de cl‚s corrompues
          echo.>>%systemdrive%\rapport.txt
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          regedit.exe /e %systemdrive%\SHUDDERLTD.txt "HKEY_LOCAL_MACHINE\SOFTWARE\SHUDDERLTD"
          IF EXIST %systemdrive%\SHUDDERLTD.txt (
          echo HKLM\SOFTWARE\SHUDDERLTD Présent !>>%systemdrive%\rapport.txt
          del %systemdrive%\SHUDDERLTD.txt
          )

          regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com"
          IF EXIST %systemdrive%\PSGuard.txt (
          echo HKLM\SOFTWARE\PSGuard.com Présent !>>%systemdrive%\rapport.txt
          del %systemdrive%\PSGuard.txt
          )

          regedit.exe /e %systemdrive%\WinHound.txt "HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com"
          IF EXIST %systemdrive%\WinHound.txt (
          echo HKLM\SOFTWARE\WinHound.com Présent !>>%systemdrive%\rapport.txt
          del %systemdrive%\WinHound.txt
          )

          echo Recherche ‚l‚ments du bureau
          echo.>>%systemdrive%\rapport.txt
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt
          IF EXIST desktop.txt del desktop.txt
          regedit.exe /e desktop.txt "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0"
          IF EXIST desktop.txt (
          echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]>>%systemdrive%\rapport.txt
          type desktop.txt | find /i "Source">>%systemdrive%\rapport.txt
          type desktop.txt | find /i "SubscribedURL">>%systemdrive%\rapport.txt
          type desktop.txt | find /i "FriendlyName">>%systemdrive%\rapport.txt
          )
          IF EXIST desktop.txt del desktop.txt

          echo.>>%systemdrive%\rapport.txt

          IF EXIST desktop.txt del desktop.txt
          regedit.exe /e desktop.txt "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1"
          IF EXIST desktop.txt (
          echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]>>%systemdrive%\rapport.txt
          type desktop.txt | find /i "Source">>%systemdrive%\rapport.txt
          type desktop.txt | find /i "SubscribedURL">>%systemdrive%\rapport.txt
          type desktop.txt | find /i "FriendlyName">>%systemdrive%\rapport.txt
          )
          IF EXIST desktop.txt del desktop.txt

          IF EXIST desktop.txt del desktop.txt
          regedit.exe /e desktop.txt "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\2"
          IF EXIST desktop.txt (
          echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\2]>>%systemdrive%\rapport.txt
          type desktop.txt | find /i "Source">>%systemdrive%\rapport.txt
          type desktop.txt | find /i "SubscribedURL">>%systemdrive%\rapport.txt
          type desktop.txt | find /i "FriendlyName">>%systemdrive%\rapport.txt
          )
          IF EXIST desktop.txt del desktop.txt

          echo Recherche Sharedtaskscheduler
          echo.>>%systemdrive%\rapport.txt
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt
          SrchSTS>>%systemdrive%\rapport.txt

          goto wininetscan

          :wininetscan
          echo Recherche infection wininet.dll
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          findstr /m /I "OLEADM" %syspath%\wininet.dll>result.txt
          for /F "TOKENS=* DELIMS=" %%A IN (result.txt) do echo wininet.dll infecté !>infected.txt
          findstr /m /I "OLEEXT" %syspath%\wininet.dll>result.txt
          for /F "TOKENS=* DELIMS=" %%A IN (result.txt) do echo wininet.dll infecté !>infected.txt
          del result.txt
          if exist infected.txt (
          del infected.txt
          echo.
          echo %syspath%\wininet.dll infect‚ !
          echo %syspath%\wininet.dll infecté !>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt
          echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche wininet.dll de remplacement>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt
          dir %systemroot%\wininet.dll /a h /s>>%systemdrive%\rapport.txt
          )

          echo.
          echo fin
          echo.>>%systemdrive%\rapport.txt
          echo »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt
          if exist CheckVersion.vbs del CheckVersion.vbs
          if exist result2.txt del result2.txt
          start %windir%\notepad.exe %systemdrive%\rapport.txt
          goto menu

          :fix

          cls
          echo %fixname% %fixvers%
          echo %fixname% %fixvers%>%systemdrive%\rapport.txt
          echo.
          echo.>>%systemdrive%\rapport.txt
          echo Rapport fait à %time% le %date%>>%systemdrive%\rapport.txt
          for /f "Tokens=*" %%i in ('cd') do set CurDir=%%i
          echo Executé à partir de %CurDir%>>%systemdrive%\rapport.txt
          IF ERRORLEVEL 1 (
          echo Executé à partir de >>%systemdrive%\rapport.txt
          cd >>%systemdrive%\rapport.txt
          )
          for /f "Tokens=*" %%i in ('ver') do set Version=%%i
          echo OS: %Version%>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          echo Arret des processus...
          echo »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus>>%systemdrive%\rapport.txt
          echo.>>%systemdrive%\rapport.txt

          process -k explorer.exe >NUL

          swsc stop AlfaCleanerService >NUL
          swsc delete AlfaCleanerService >NUL

          Process -k 1.tmp >NUL
          Process -k 3.tmp >NUL
          Process -k 4.tmp >NUL
          Process -k adsmart.exe >NUL
          Process -k adtech2005.exe >NUL
          Process -k adtech2006a.exe >NUL
          Process -k AlfaCleaner.exe >NUL
          Process -k AntivirusGold.exe >NUL
          Process -k batserv2.exe >NUL
          Process -k bsw.exe >NUL
          Process -k bu.exe >NUL
          Process -k bxproxy.exe >NUL
          Process -k cmd32.exe >NUL
          Process -k cmdtel.exe >NUL
          Process -k combo.exe >NUL
          Process -k contextplus.exe >NUL
          Process -k d3dn32.exe >NUL
          Process -k d3pb.exe >NUL
          Process -k doser.exe >NUL
          Process -k ecsiin.stub.exe >NUL
          Process -k efsdfgxg.exe >NUL
          Process -k exa32.exe >NUL
          Process -k exeha2.exe >NUL
          Process -k exeha3.exe >NUL
          Process -k gunist.exe >NUL
          Process -k helper.exe >NUL
          Process -k hookdump.exe >NUL
          Process -k ieengine.exe >NUL
          Process -k ieyi.exe >NUL
          Process -k intel32.exe >NUL
          Process -k intell321.exe >NUL
          Process -k intell32.exe >NUL
          Process -k intmon.exe >NUL
          Process -k intmonp.exe >NUL
          Process -k intxt.exe >NUL
          Process -k kernels32.exe >NUL
          Process -k kernels64.exe >NUL
          Process -k kl.exe >NUL
          Process -k latest.exe >NUL
          Process -k links.exe >NUL
          Process -k ll.exe >NUL
          Process -k
          0
        2. merci pour l aide voila le rapport de scan ewido---------------------------------------------------------
          ewido anti-malware - Rapport de scan
          ---------------------------------------------------------

          + Créé le: 10:14:44, 3/03/2006
          + Somme de contrôle: 1EA98FC

          + Résultats du scan:

          C:\Documents and Settings\LocalService\Cookies\system@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Nettoyer et sauvegarder
          C:\Documents and Settings\LocalService\Cookies\system@banners.searchingbooth[1].txt -> TrackingCookie.Searchingbooth : Nettoyer et sauvegarder
          C:\Documents and Settings\LocalService\Cookies\system@media.top-banners[1].txt -> TrackingCookie.Top-banners : Nettoyer et sauvegarder
          C:\Documents and Settings\LocalService\Cookies\system@paypopup[2].txt -> TrackingCookie.Paypopup : Nettoyer et sauvegarder
          C:\Documents and Settings\LocalService\Cookies\system@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Nettoyer et sauvegarder
          C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\AN01KFGB\wallpap[1].exe -> Hijacker.Agent.gp : Nettoyer et sauvegarder
          C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WXMZ45M3\ErrorSafeFreeInstall[1].cab/UERS_0001_N68M1801NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
          C:\Documents and Settings\Pat\Cookies\pat@wreport.weborama[1].txt -> TrackingCookie.Weborama : Nettoyer et sauvegarder
          C:\Documents and Settings\Pat\Cookies\pat@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
          C:\Documents and Settings\Pat\Internet Optimizer\optimize.exe -> Downloader.Dyfuca.ei : Nettoyer et sauvegarder
          C:\Documents and Settings\Steph\bleh.exe -> Dropper.Agent.ye : Nettoyer et sauvegarder
          C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UERSV_0001_N68M0602NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
          C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UERSV_0001_N68M0602NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
          C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UERSV_0001_N68M0602NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
          C:\WINDOWS\Downloaded Program Files\UERSV_0001_N68M0602NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
          C:\WINDOWS\Downloaded Program Files\UERS_0001_N68M1801NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
          C:\WINDOWS\eee2.exe -> Adware.MediaMotor : Nettoyer et sauvegarder
          C:\WINDOWS\eeedo.exe/eee2.exe -> Adware.MediaMotor : Nettoyer et sauvegarder
          C:\WINDOWS\sns\index1.exe -> Trojan.LowZones.cf : Nettoyer et sauvegarder
          C:\WINDOWS\sns.exe/sns\index1.exe -> Trojan.LowZones.cf : Nettoyer et sauvegarder
          C:\WINDOWS\surv3.exe -> Downloader.VB.vv : Nettoyer et sauvegarder
          C:\WINDOWS\system32\birdasfihuy32.dll -> Proxy.Small.ct : Nettoyer et sauvegarder
          C:\WINDOWS\system32\bleh.exe -> Dropper.Agent.ye : Nettoyer et sauvegarder
          C:\WINDOWS\system32\bum392.exe -> Downloader.Small.cjd : Nettoyer et sauvegarder
          C:\WINDOWS\system32\csrs.exe -> Backdoor.PoeBot.b : Nettoyer et sauvegarder
          C:\WINDOWS\system32\nzndkece.exe -> Backdoor.Rbot.apd : Nettoyer et sauvegarder
          C:\WINDOWS\system32\svxhost.exe -> Backdoor.Rbot : Nettoyer et sauvegarder
          C:\WINDOWS\system32\voi376.exe -> Downloader.CWS.r : Nettoyer et sauvegarder
          C:\WINDOWS\system32\winldra.exe -> Backdoor.Dumador.fr : Nettoyer et sauvegarder
          C:\WINDOWS\system32\__delete_on_reboot__steam.dll -> Backdoor.Akbot.a : Nettoyer et sauvegarder
          C:\WINDOWS\uninstDsk.exe -> Trojan.Small.ev : Nettoyer et sauvegarder
          C:\WINDOWS\wallpap.exe -> Hijacker.Agent.gp : Nettoyer et sauvegarder

          ::Fin du rapport
          0
      2. Contributeur
        Salut

        tu as double cliker sur le mauvais.Choisis ou c est ecrit smitfraudfix.

        a+
        0
        1. Contributeur
          Salut

          tu as double cliker sur le mauvais.Choisis ou c est ecrit smitfraudfix.

          a+
          0
          1. quand je clique la dessus il me dit fichier process.exe absent
            dezippez la totalite de l archive dans un dossier
            0
            1. Contributeur
              salut

              Lorsque tu l as telechargé.Clik droit sur le fichier et choisis extraire tout.Un fichier est extrait a coté de l autre, ouvre le et ouvre smitfraudfix

              a+
              0