Que se passe t il?

pato Messages postés 5 Statut Membre -  
incognito02 Messages postés 3487 Statut Contributeur -
bonjour voici mes soucis quand j arrete l ordi il me dit:rundll32.exe ce programme ne repond pas. que dois je faire?
quand j allume spybotsd me dit: a detecte un service systeme qui a ete identifie comme une menace: nom affiche :Command service
cle du registre:cmdService comment l enlever merci d avance pour votre aide

7 réponses

incognito02 Messages postés 3487 Statut Contributeur 138
 
Bonsoir,

télécharge HijackThis ici:
http://www.hijackthis.de/downloads/hijackthis_199.zip

Dézippe le dans un dossier prévu à cet effet.
Par exemple C:\hijackthis < Enregistre le bien dans c : !
Démo : (Merci a Balltrap34 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/Hijenr.gif

Lance le puis:
clique sur "do a system scan and save logfile" (cf démo)
faire un copier coller du log entier sur le forum

Démo : (Merci a Balltrap34 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/demohijack.htm

Bon courage

A+
0
pato
 
Logfile of HijackThis v1.99.1
Scan saved at 8:09:23, on 2/03/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Ontrack\SYSTEM~1\MXTask.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\explorer.exe
C:\WINDOWS\System32\svxhost.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.1\BHR4.1.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\mirayyve.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\cllhost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\DVDAccess\DVDAccess.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Pat\LOCALS~1\Temp\Rar$EX00.877\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-be\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-be\msntb.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\Ontrack\SYSTEM~1\MemCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Windows Explorer] C:\WINDOWS\System32\explorer.exe
O4 - HKLM\..\Run: [AdobeReaderPro] svxhost.exe
O4 - HKLM\..\Run: [WinDLL (steam.dll)] rundll32.exe C:\WINDOWS\System32\steam.dll,start
O4 - HKLM\..\Run: [BHR4.1] C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.1\BHR4.1.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [mstctd] C:\WINDOWS\System32\mirayyve.exe
O4 - HKLM\..\Run: [gimmygames] C:\windows\gimmygames11.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ihost.exe] C:\cllhost.exe
O4 - HKLM\..\RunServices: [AdobeReaderPro] svxhost.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: DVDAccess.lnk = C:\Program Files\DVDAccess\DVDAccess.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SystemSuite Task Manager - Ontrack Data International - C:\PROGRA~1\Ontrack\SYSTEM~1\MXTask.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
0
incognito02 Messages postés 3487 Statut Contributeur 138
 
Salut

Télécharge ceci: (merci a S!RI pour ce programme).
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1, il va générer un rapport
Copie/colle le sur le poste stp.

+

Ewido:
http://download.ewido.net/ewido-setup.exe

Installation puis mises à jour.

* Lancer et exécuter Ewido pour un scan complet et copier/coller le rapport en forum.

a+
0
pato
 
voila ce que tu m as demande @ECHO OFF

REM Smitfraud Fix by S!Ri
REM http://siri.urz.free.fr/Fix/SmitfraudFix.zip

REM Thanks, Help: balltrap34, moe31, sebdraluorg, Ruby, Vazkor
REM Miekiemoes Shudder key fix added.
REM Process.exe by Craig.Peacock added (http://www.beyondlogic.org)
REM Reboot.exe by Shadowar/Option^Explicit added.
REM swreg.exe by SteelWerx
REM swsc.exe by SteelWerx

set fixname=SmitFraudFix
set fixvers=v2.21

VER|find "Windows 95">NUL
IF NOT ERRORLEVEL 1 GOTO Win
VER|find "Windows 98">NUL
IF NOT ERRORLEVEL 1 GOTO Win
VER|find "Windows Millennium">NUL
IF NOT ERRORLEVEL 1 GOTO Win
VER|find "Windows XP">NUL
IF NOT ERRORLEVEL 1 GOTO NT
VER|find "Windows 2000">NUL
IF NOT ERRORLEVEL 1 GOTO NT
VER|find "Windows 2003">NUL
IF NOT ERRORLEVEL 1 GOTO NT
color 47
echo %fixname% %fixvers%
echo.
echo Version non support‚e.
echo Windows 2000 / XP requis !
echo.
pause
goto end

:Win
color 47
echo %fixname% %fixvers%
echo.
echo Version non support‚e.
echo Windows 2000 / XP requis !
echo.
pause
goto exit

:NT
set DoReboot=0
set syspath=%windir%\system32
if exist "%userprofile%\Desktop" set desktop=%userprofile%\Desktop
if exist "%userprofile%\Bureau" set desktop=%userprofile%\Bureau
if exist "%allusersprofile%\Desktop" set audesktop=%allusersprofile%\Desktop
if exist "%allusersprofile%\Bureau" set audesktop=%allusersprofile%\Bureau
if exist "%userprofile%\Favorites" set favorites=%userprofile%\Favorites
if exist "%userprofile%\Favoris" set favorites=%userprofile%\Favoris
goto test

:test
if not exist Process.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier Process.exe absent !
echo Dezippez la totalit‚ de l'archive dans un dossier.
echo.
pause
goto exit
)

if not exist swreg.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier swreg.exe absent !
echo Dezippez la totalit‚ de l'archive dans un dossier.
echo.
pause
goto exit
)

if not exist swsc.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier swsc.exe absent !
echo Dezippez la totalit‚ de l'archive dans un dossier.
echo.
pause
goto exit
)

if not exist SrchSTS.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier SrchSTS.exe absent !
echo Dezippez la totalit‚ de l'archive dans un dossier.
echo.
pause
goto exit
)

if not exist %syspath%\Process.exe copy Process.exe %syspath%
if not exist %syspath%\swreg.exe copy reg.exe %syspath%
if not exist %syspath%\swsc.exe copy reg.exe %syspath%
if not exist %syspath%\SrchSTS.exe copy reg.exe %syspath%
goto menu

:menu
color 17
cls
echo.
echo ÉÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ»
echo º %fixname% %fixvers% º
echo ÌÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ͹
echo º 1. Recherche º
echo º 2. Nettoyage (mode sans echec recommand‚) º
echo º 3. Effacer les sites de confiance et sensibles º
echo º Q. Quitter º
echo ÈÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍͼ
echo.
echo Fermez tous les programmes
echo un red‚marrage peut-ˆtre n‚cessaire
echo.
echo.
set ChoixMenu=''
set /p ChoixMenu=Entrez votre choix (1,2,3,Q) :
if '%ChoixMenu%'=='q' GOTO exit
if '%ChoixMenu%'=='Q' GOTO exit
if '%ChoixMenu%'=='1' GOTO search
if '%ChoixMenu%'=='2' GOTO fix
if '%ChoixMenu%'=='3' GOTO zonefix
goto menu



:search
cls
echo %fixname% %fixvers%
echo %fixname% %fixvers%>%systemdrive%\rapport.txt
echo.
echo.>>%systemdrive%\rapport.txt
echo Rapport fait à %time% le %date%>>%systemdrive%\rapport.txt
for /f "Tokens=*" %%i in ('cd') do set CurDir=%%i
echo Executé à partir de %CurDir%>>%systemdrive%\rapport.txt
IF ERRORLEVEL 1 (
echo Executé à partir de >>%systemdrive%\rapport.txt
cd >>%systemdrive%\rapport.txt
)
for /f "Tokens=*" %%i in ('ver') do set Version=%%i
echo OS: %Version%>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt




echo Recherche %HOMEDRIVE%\...
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %HOMEDRIVE%\>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt



pushd %HOMEDRIVE%\

if exist bsw.exe (echo %HOMEDRIVE%\bsw.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist contextplus.exe (echo %HOMEDRIVE%\contextplus.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist drsmartload1.exe (echo %HOMEDRIVE%\drsmartload1.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist drsmartloadb.exe (echo %HOMEDRIVE%\drsmartloadb.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist ecsiin.stub.exe (echo %HOMEDRIVE%\ecsiin.stub.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist loader.exe (echo %HOMEDRIVE%\loader.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist ntdetecd.exe (echo %HOMEDRIVE%\ntdetecd.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist ntps.exe (echo %HOMEDRIVE%\ntps.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist ntnc.exe (echo %HOMEDRIVE%\ntnc.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist r.exe (echo %HOMEDRIVE%\r.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist secure32.html (echo %HOMEDRIVE%\secure32.html PRESENT !>>%systemdrive%\rapport.txt)
if exist stub_113_4_0_4_0.exe (echo %HOMEDRIVE%\stub_113_4_0_4_0.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist winstall.exe (echo %HOMEDRIVE%\winstall.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist wp.bmp (echo %HOMEDRIVE%\wp.bmp PRESENT !>>%systemdrive%\rapport.txt)
if exist wp.exe (echo %HOMEDRIVE%\wp.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist xxx.exe (echo %HOMEDRIVE%\xxx.exe PRESENT !>>%systemdrive%\rapport.txt)

if exist "%HOMEDRIVE%\spywarevanisher-free" echo %HOMEDRIVE%\spywarevanisher-free\ PRESENT !>>%systemdrive%\rapport.txt

popd



echo.>>%systemdrive%\rapport.txt
echo Recherche %windir%\...
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %windir%>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt



pushd %windir%

if exist adsldpbc.dll (echo %windir%\adsldpbc.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist adsldpbd.dll (echo %windir%\adsldpbd.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist adsldpbe.dll (echo %windir%\adsldpbe.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist adsldpbf.dll (echo %windir%\adsldpbf.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist adtech2005.exe (echo %windir%\adtech2005.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist adtech2006a.exe (echo %windir%\adtech2006a.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist adw.htm (echo %windir%\adw.htm PRESENT !>>%systemdrive%\rapport.txt)
if exist back.gif (echo %windir%\back.gif PRESENT !>>%systemdrive%\rapport.txt)
if exist batserv2.exe (echo %windir%\batserv2.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist bg.gif (echo %windir%\bg.gif PRESENT !>>%systemdrive%\rapport.txt)
if exist blank.mht (echo %windir%\blank.mht PRESENT !>>%systemdrive%\rapport.txt)
if exist buy.gif (echo %windir%\buy.gif PRESENT !>>%systemdrive%\rapport.txt)
if exist bxproxy.exe (echo %windir%\bxproxy.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist country.exe (echo %windir%\country.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist d3dn32.exe (echo %windir%\d3dn32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist d3??.dll (echo %windir%\d3??.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist d3pb.exe (echo %windir%\d3pb.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist desktop.html (echo %windir%\desktop.html PRESENT !>>%systemdrive%\rapport.txt)
if exist download-btn.gif (echo %windir%\download-btn.gif PRESENT !>>%systemdrive%\rapport.txt)
if exist drsmartload.dat (echo %windir%\drsmartload.dat PRESENT !>>%systemdrive%\rapport.txt)
if exist drsmartloadb1.dat (echo %windir%\drsmartloadb1.dat PRESENT !>>%systemdrive%\rapport.txt)
if exist kl.exe (echo %windir%\kl.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist icont.exe (echo %windir%\icont.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist ieyi.dll (echo %windir%\ieyi.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist ieyi.exe (echo %windir%\ieyi.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist ms1.exe (echo %windir%\ms1.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist notepad.com (echo %windir%\notepad.com PRESENT !>>%systemdrive%\rapport.txt)
if exist popuper.exe (echo %windir%\popuper.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist psg.exe (echo %windir%\psg.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist q*_disk.dll (echo %windir%\q*_disk.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist rzs.exe (echo %windir%\rzs.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist sachostx.exe (echo %windir%\sachostx.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist screen.html (echo %windir%\screen.html PRESENT !>>%systemdrive%\rapport.txt)
if exist sec.exe (echo %windir%\sec.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist sdkcb.dll (echo %windir%\sdkcb.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist sdkqq.exe (echo %windir%\sdkqq.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist secure32.html (echo %windir%\secure32.html PRESENT !>>%systemdrive%\rapport.txt)
if exist sites.ini (echo %windir%\sites.ini PRESENT !>>%systemdrive%\rapport.txt)
if exist slassac.dll (echo %windir%\slassac.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist svchost.exe (echo %windir%\svchost.exe PRESENT!>>%systemdrive%\rapport.txt)
if exist sysldr32.exe (echo %windir%\sysldr32.exe PRESENT!>>%systemdrive%\rapport.txt)
if exist sysen.exe (echo %windir%\sysen.exe PRESENT!>>%systemdrive%\rapport.txt)
if exist temp.000.exe (echo %windir%\temp.000.exe PRESENT!>>%systemdrive%\rapport.txt)
if exist timessquare.exe (echo %windir%\timessquare.exe PRESENT!>>%systemdrive%\rapport.txt)
if exist timessquare1.dat (echo %windir%\timessquare1.dat PRESENT!>>%systemdrive%\rapport.txt)
if exist tool1.exe (echo %windir%\tool1.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist tool2.exe (echo %windir%\tool2.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist tool3.exe (echo %windir%\tool3.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist tool4.exe (echo %windir%\tool4.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist tool5.exe (echo %windir%\tool5.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist toolbar.exe (echo %windir%\toolbar.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist uninstDsk.exe (echo %windir%\uninstDsk.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist uninstIU.exe (echo %windir%\uninstIU.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist update13.js (echo %windir%\update13.js PRESENT !>>%systemdrive%\rapport.txt)
if exist warnhp.html (echo %windir%\warnhp.html PRESENT !>>%systemdrive%\rapport.txt)
if exist winsysupd.exe (echo %windir%\winsysupd.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist winsysban.exe (echo %windir%\winsysban.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist windows.html (echo %windir%\windows.html PRESENT !>>%systemdrive%\rapport.txt)
if exist zloader3.exe (echo %windir%\zloader3.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist __delete_on_reboot__popuper.exe (echo %windir%\__delete_on_reboot__popuper.exe PRESENT !>>%systemdrive%\rapport.txt)

if exist "%windir%\inet20001" echo %windir%\inet20001\ PRESENT!>>%systemdrive%\rapport.txt
if exist "%windir%\inet20010" echo %windir%\inet20010\ PRESENT!>>%systemdrive%\rapport.txt
if exist "%windir%\inet20066" echo %windir%\inet20066\ PRESENT!>>%systemdrive%\rapport.txt
if exist "%windir%\inet20099" echo %windir%\inet20099\ PRESENT!>>%systemdrive%\rapport.txt

popd






echo.>>%systemdrive%\rapport.txt
echo Recherche %windir%\system...
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %windir%\system>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt



pushd %windir%\system

if exist csrss.exe (echo %windir%\system\csrss.exe PRESENT!>>%systemdrive%\rapport.txt)
if exist svchost.exe (echo %windir%\system\svchost.exe PRESENT!>>%systemdrive%\rapport.txt)
if exist svchost.dll (echo %windir%\system\svchost.dll PRESENT!>>%systemdrive%\rapport.txt)
if exist svwhost.exe (echo %windir%\system\svwhost.exe PRESENT!>>%systemdrive%\rapport.txt)
if exist svwhost.dll (echo %windir%\system\svwhost.dll PRESENT!>>%systemdrive%\rapport.txt)

popd




echo.>>%systemdrive%\rapport.txt
echo Recherche %windir%\Web...
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %windir%\Web>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt



pushd %windir%\Web

if exist desktop.html (echo %windir%\Web\desktop.html PRESENT!>>%systemdrive%\rapport.txt)
if exist wallpaper.html (echo %windir%\Web\wallpaper.html PRESENT!>>%systemdrive%\rapport.txt)

popd



echo.>>%systemdrive%\rapport.txt
echo Recherche %syspath%...
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %syspath%>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt



pushd %syspath%

if exist ~update.exe (echo %syspath%\~update.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist "Air Tickets.ico" (echo %syspath%\Air Tickets.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist AdService.dll (echo %syspath%\AdService.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist adsmart.exe (echo %syspath%\adsmart.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist bhoimpl.dll (echo %syspath%\bhoimpl.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist "Big Tits.ico" (echo %syspath%\Big Tits.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist birdihuy.dll (echo %syspath%\birdihuy.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist birdihuy32.dll (echo %syspath%\birdihuy32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist Blackjack.ico (echo %syspath%\Blackjack.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist bnmsrv.exe (echo %syspath%\bnmsrv.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist bre.dll (echo %syspath%\bre.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist bre32.dll (echo %syspath%\bre32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist browsela.dll (echo %syspath%\browsela.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist "Britney Spears.ico" (echo %syspath%\Britney Spears.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist bu.exe (echo %syspath%\bu.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist "Car Insurance.ico" (echo %syspath%\Car Insurance.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist casino.ico (echo %syspath%\casino.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist "Cheap Cigarettes.ico" (echo %syspath%\Cheap Cigarettes.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist child.dll (echo %syspath%\child.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist chp.dll (echo %syspath%\chp.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist cmd32.exe (echo %syspath%\cmd32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist cmdtel.exe (echo %syspath%\cmdtel.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist cnymxw32.dll (echo %syspath%\cnymxw32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist combo.exe (echo %syspath%\combo.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist "Credit Card.ico" (echo %syspath%\Credit Card.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist Cruises.ico (echo %syspath%\Cruises.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist "Currency Trading.ico" (echo %syspath%\Currency Trading.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist cvxh8jkdq?.exe (echo %syspath%\cvxh8jkdq?.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist date.ico (echo %syspath%\date.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist dial23.exe (echo %syspath%\dial23.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist doser.exe (echo %syspath%\doser.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist dxmpp.dll (echo %syspath%\dxmpp.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist efsdfgxg.exe (echo %syspath%\efsdfgxg.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist exa32.exe (echo %syspath%\exa32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist exeha2.exe (echo %syspath%\exeha2.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist exeha3.exe (echo %syspath%\exeha3.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist games.ico (echo %syspath%\games.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist gunist.exe (echo %syspath%\gunist.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist helper.exe (echo %syspath%\helper.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist hhk.dll (echo %syspath%\hhk.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist hookdump.exe (echo %syspath%\hookdump.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist hp????.tmp (echo %syspath%\hp????.tmp PRESENT !>>%systemdrive%\rapport.txt)
if exist IeHelperEx.dll (echo %syspath%\IeHelperEx.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist intel32.exe (echo %syspath%\intel32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist intell321.exe (echo %syspath%\intell321.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist intell32.exe (echo %syspath%\intell32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist intmon.exe (echo %syspath%\intmon.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist intmonp.exe (echo %syspath%\intmonp.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist intxt.exe (echo %syspath%\intxt.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist ioctrl.dll (echo %syspath%\ioctrl.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist kernels32.exe (echo %syspath%\kernels32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist kernels64.exe (echo %syspath%\kernels64.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist latest.exe (echo %syspath%\latest.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist "Lesbian Sex.ico" (echo %syspath%\Lesbian Sex.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist ld????.tmp (echo %syspath%\ld????.tmp PRESENT !>>%systemdrive%\rapport.txt)
if exist links.exe (echo %syspath%\links.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist ll.exe (echo %syspath%\ll.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist maxd1.exe (echo %syspath%\maxd1.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist maxd64.exe (echo %syspath%\maxd64.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist migicons.exe (echo %syspath%\migicons.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist mobile.ico (echo %syspath%\mobile.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist MP3.ico (echo %syspath%\MP3.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist msbe.dll (echo %syspath%\msbe.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist mscornet.exe (echo %syspath%\mscornet.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist mssearchnet.exe (echo %syspath%\mssearchnet.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist msmsgs.exe (echo %syspath%\msmsgs.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist msnscps.dll (echo %syspath%\msnscps.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist msole32.exe (echo %syspath%\msole32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist mspostsp.exe.exe (echo %syspath%\mspostsp.exe.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist msupdate32.dll (echo %syspath%\msupdate32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist msvcp.exe.exe (echo %syspath%\msvcp.exe.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist msvol.tlb (echo %syspath%\msvol.tlb PRESENT !>>%systemdrive%\rapport.txt)
if exist mswinb32.dll (echo %syspath%\mswinb32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist mswinb32.exe (echo %syspath%\mswinb32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist mswinf32.dll (echo %syspath%\mswinf32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist mswinf32.exe (echo %syspath%\mswinf32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist mswinup32.dll (echo %syspath%\mswinup32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist mswinxml.dll (echo %syspath%\mswinxml.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist MTC.dll (echo %syspath%\MTC.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist MTC.ini (echo %syspath%\MTC.ini PRESENT !>>%systemdrive%\rapport.txt)
if exist multitran.exe (echo %syspath%\multitran.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist ncompat.tlb (echo %syspath%\ncompat.tlb PRESENT !>>%systemdrive%\rapport.txt)
if exist network.ico (echo %syspath%\network.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist netwrap.dll (echo %syspath%\netwrap.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist notepad.com (echo %syspath%\notepad.com PRESENT !>>%systemdrive%\rapport.txt)
if exist NTCommLib3.exe (echo %syspath%\NTCommLib3.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist nuclabdll.dll (echo %syspath%\nuclabdll.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist nvctrl.exe (echo %syspath%\nvctrl.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist nvms.dll (echo %syspath%\nvms.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist ole32vbs.exe (echo %syspath%\ole32vbs.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist oleadm.dll (echo %syspath%\oleadm.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist oleadm32.dll (echo %syspath%\oleadm32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist oleext.dll (echo %syspath%\oleext.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist oleext32.dll (echo %syspath%\oleext32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist "Online Betting.ico" (echo %syspath%\Online Betting.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist "Online Gambling.ico" (echo %syspath%\Online Gambling.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist "Oral Sex.ico" (echo %syspath%\Oral Sex.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist ot.ico (echo %syspath%\ot.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist param32.dll (echo %syspath%\param32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist paradise.raw.exe (echo %syspath%\paradise.raw.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist "Party Poker.ico" (echo %syspath%\Party Poker.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist paytime.exe (echo %syspath%\paytime.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist perfcii.ini (echo %syspath%\perfcii.ini PRESENT !>>%systemdrive%\rapport.txt)
if exist performent217.dll (echo %syspath%\performent217.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist pharm.ico (echo %syspath%\pharm.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist pharm2.ico (echo %syspath%\pharm2.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist Pharmacy.ico (echo %syspath%\Pharmacy.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist Phentermine.ico (echo %syspath%\Phentermine.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist pop_up.dll (echo %syspath%\pop_up.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist Pornstars.ico (echo %syspath%\Pornstars.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist priva.exe (echo %syspath%\priva.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist prflbmsgp32.dll (echo %syspath%\prflbmsgp32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist qvxgamet?.exe (echo %syspath%\qvxgamet?.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist "Remove Spyware.ico" (echo %syspath%\Remove Spyware.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist replmap.dll (echo %syspath%\replmap.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist RpcxSs.dll (echo %syspath%\RpcxSs.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist runsrv32.dll (echo %syspath%\runsrv32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist runsrv32.exe (echo %syspath%\runsrv32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist sachostc.exe (echo %syspath%\sachostc.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist sachostp.exe (echo %syspath%\sachostp.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist sachosts.exe (echo %syspath%\sachosts.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist scanner.ico (echo %syspath%\scanner.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist sdfdil.exe (echo %syspath%\sdfdil.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist searchdll.dll (echo %syspath%\searchdll.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist sender.exe (echo %syspath%\sender.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist shdochp.dll (echo %syspath%\shdochp.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist shdochp.exe (echo %syspath%\shdochp.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist shdochop.dll (echo %syspath%\shdochop.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist shdocnva.dll (echo %syspath%\shdocnva.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist shdocsvc.dll (echo %syspath%\shdocsvc.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist shdocsvc.exe (echo %syspath%\shdocsvc.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist shell386.exe (echo %syspath%\shell386.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist shnlog.exe (echo %syspath%\shnlog.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist shsexl32.dll (echo %syspath%\shsexl32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist socks.exe (echo %syspath%\socks.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist spam.ico (echo %syspath%\spam.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist split.exe (echo %syspath%\split.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist split1.exe (echo %syspath%\split1.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist split2.exe (echo %syspath%\split2.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist spyware.ico (echo %syspath%\spyware.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist srpcsrv32.dll (echo %syspath%\srpcsrv32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist srpcsrv32.exe (echo %syspath%\srpcsrv32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist st3.dll (echo %syspath%\st3.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist svchop.exe (echo %syspath%\svchop.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist svchosts.dll (echo %syspath%\svchosts.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist svchosts.exe (echo %syspath%\svchosts.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist svcnt.exe (echo %syspath%\svcnt.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist svcnt32.exe (echo %syspath%\svcnt32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist svcnva.exe (echo %syspath%\svcnva.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist svwhost.exe (echo %syspath%\svwhost.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist symsvcsa.exe (echo %syspath%\symsvcsa.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist sysbho.exe (echo %syspath%\sysbho.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist sysinit32z.exe (echo %syspath%\sysinit32z.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist sysjv32.exe (echo %syspath%\sysjv32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist sysmain.dll (echo %syspath%\sysmain.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist sysvcs.exe (echo %syspath%\sysvcs.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist sywsvcs.exe (echo %syspath%\sywsvcs.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist taras.exe (echo %syspath%\taras.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist tcpservice2.exe (echo %syspath%\tcpservice2.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist trf32.dll (echo %syspath%\trf32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist ts.ico (echo %syspath%\ts.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist txfdb32.dll (echo %syspath%\txfdb32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist viagra.ico (echo %syspath%\viagra.ico PRESENT !>>%systemdrive%\rapport.txt)
if exist vxgame?.exe (echo %syspath%\vxgame?.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist vxgame?.exe????.exe (echo %syspath%\vxgame?.exe????.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist vxgame?.exe????.exe.bak (echo %syspath%\vxgame?.exe????.exe.bak PRESENT !>>%systemdrive%\rapport.txt)
if exist vxgamet?.exe (echo %syspath%\vxgamet?.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist vxgamet?.exe????.exe (echo %syspath%\vxgamet?.exe????.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist vxh8jkdq?.exe (echo %syspath%\vxh8jkdq?.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist w8673492.exe (echo %syspath%\w8673492.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist wbeconm.dll (echo %syspath%\wbeconm.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist web.exe (echo %syspath%\web.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist wiatwain.dll (echo %syspath%\wiatwain.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist winapi32.dll (echo %syspath%\winapi32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist windesktop.dll (echo %syspath%\windesktop.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist windesktop.exe (echo %syspath%\windesktop.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist winldra.exe (echo %syspath%\winldra.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist winlfl32.dll (echo %syspath%\winlfl32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist winnook.exe (echo %syspath%\winnook.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist winstyle2.dll (echo %syspath%\winstyle2.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist winstyle3.dll (echo %syspath%\winstyle3.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist winstyle32.dll (echo %syspath%\winstyle32.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist wldr.dll (echo %syspath%\wldr.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist wp.bmp (echo %syspath%\wp.bmp PRESENT !>>%systemdrive%\rapport.txt)
if exist wppp.html (echo %syspath%\wppp.html PRESENT !>>%systemdrive%\rapport.txt)
if exist wstart.dll (echo %syspath%\wstart.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist x.exe (echo %syspath%\x.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist yaemu.exe (echo %syspath%\yaemu.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist z11.exe (echo %syspath%\z11.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist z12.exe (echo %syspath%\z12.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist z13.exe (echo %syspath%\z13.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist z14.exe (echo %syspath%\z14.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist z15.exe (echo %syspath%\z15.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist z16.exe (echo %syspath%\z16.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist zlbw.dll (echo %syspath%\zlbw.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist zolker011.dll (echo %syspath%\zolker011.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist ztoolb011.dll (echo %syspath%\ztoolb011.dll PRESENT !>>%systemdrive%\rapport.txt)
if exist ztoolbar.bmp (echo %syspath%\ztoolbar.bmp PRESENT !>>%systemdrive%\rapport.txt)
if exist ztoolbar.xml (echo %syspath%\ztoolbar.xml PRESENT !>>%systemdrive%\rapport.txt)
if exist __delete_on_reboot__intmon.exe (echo %syspath%\__delete_on_reboot__intmon.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist __delete_on_reboot__intel32.exe (echo %syspath%\__delete_on_reboot__intel32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist __delete_on_reboot__intell32.exe (echo %syspath%\__delete_on_reboot__intell32.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist __delete_on_reboot__OLEADM.dll (echo %syspath%\__delete_on_reboot__OLEADM.dll PRESENT !>>%systemdrive%\rapport.txt)

if exist "%syspath%\1024" echo %syspath%\1024\ PRESENT!>>%systemdrive%\rapport.txt

if exist "%syspath%\drivers\hesvc.sys" echo %syspath%\drivers\hesvc.sys PRESENT!>>%systemdrive%\rapport.txt


popd





if NOT exist %syspath%\LogFiles goto suiteScanAppData

echo.>>%systemdrive%\rapport.txt
echo Recherche %syspath%\LogFiles...
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %syspath%\LogFiles>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt

pushd %syspath%\LogFiles

if exist A5281300.so (echo %syspath%\A5281300.so PRESENT !>>%systemdrive%\rapport.txt)
if exist T54111925.so (echo %syspath%\T54111925.so PRESENT !>>%systemdrive%\rapport.txt)
if exist H53131712.so (echo %syspath%\H53131712.so PRESENT !>>%systemdrive%\rapport.txt)
if exist A54102200.so (echo %syspath%\A54102200.so PRESENT !>>%systemdrive%\rapport.txt)
if exist S53252000.so (echo %syspath%\S53252000.so PRESENT !>>%systemdrive%\rapport.txt)
if exist A04111925.so (echo %syspath%\A04111925.so PRESENT !>>%systemdrive%\rapport.txt)
if exist M54111925.so (echo %syspath%\M54111925.so PRESENT !>>%systemdrive%\rapport.txt)
if exist P54111925.so (echo %syspath%\P54111925.so PRESENT !>>%systemdrive%\rapport.txt)

popd



:suiteScanAppData
echo.>>%systemdrive%\rapport.txt
echo Recherche %userprofile%\Application Data...
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche ...\Application Data>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt

if exist "%HOMEDRIVE%\Documents and Settings\LocalService\Application Data\AlfaCleaner" echo %HOMEDRIVE%\Documents and Settings\LocalService\Application Data\AlfaCleaner PRESENT !>>%systemdrive%\rapport.txt

pushd %userprofile%\Application Data

if exist "%userprofile%\Application Data\Install.dat" echo %userprofile%\Application Data\Install.dat PRESENT !>>%systemdrive%\rapport.txt
if exist "%userprofile%\Application Data\AlfaCleaner" echo %userprofile%\Application Data\AlfaCleaner PRESENT !>>%systemdrive%\rapport.txt
if exist "%userprofile%\Application Data\PSGuard.com" echo %userprofile%\Application Data\PSGuard.com PRESENT !>>%systemdrive%\rapport.txt
if exist "%userprofile%\Application Data\Shudder Global Limited" echo %userprofile%\Application Data\Shudder Global Limited PRESENT !>>%systemdrive%\rapport.txt
if exist "%userprofile%\Application Data\Skinux" echo %userprofile%\Application Data\Skinux PRESENT !>>%systemdrive%\rapport.txt

if exist "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\AlfaCleaner.lnk" echo %userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\AlfaCleaner.lnk PRESENT !>>%systemdrive%\rapport.txt
if exist "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\SpywareStrike 2.5.lnk" echo %userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\SpywareStrike 2.5.lnk PRESENT !>>%systemdrive%\rapport.txt
if exist "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyFalcon 2.0.lnk" echo %userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyFalcon 2.0.lnk PRESENT !>>%systemdrive%\rapport.txt

popd



echo.>>%systemdrive%\rapport.txt
echo Recherche Menu D‚marrer...
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt

if exist "%userprofile%\Menu D‚marrer\SpyAxe 3.0.lnk" (echo %userprofile%\Menu Démarrer\SpyAxe 3.0.lnk PRESENT !>>%systemdrive%\rapport.txt)
if exist "%userprofile%\Menu D‚marrer\SpyFalcon 2.0.lnk" (echo %userprofile%\Menu Démarrer\SpyFalcon 2.0.lnk PRESENT !>>%systemdrive%\rapport.txt)
if exist "%userprofile%\Menu D‚marrer\SpywareStrike 2.5.lnk" (echo %userprofile%\Menu Démarrer\SpywareStrike 2.5.lnk PRESENT !>>%systemdrive%\rapport.txt)
if exist "%userprofile%\Menu D‚marrer\Programmes\SpyAxe" (echo %userprofile%\Menu Démarrer\Programmes\SpyAxe PRESENT !>>%systemdrive%\rapport.txt)
if exist "%userprofile%\Menu D‚marrer\Programmes\SpyFalcon" (echo %userprofile%\Menu Démarrer\Programmes\SpyFalcon PRESENT !>>%systemdrive%\rapport.txt)
if exist "%userprofile%\Menu D‚marrer\Programmes\SpySheriff" (echo %userprofile%\Menu Démarrer\Programmes\SpySheriff PRESENT !>>%systemdrive%\rapport.txt)
if exist "%userprofile%\Menu D‚marrer\Programmes\SpywareStrike" (echo %userprofile%\Menu Démarrer\Programmes\SpywareStrike PRESENT !>>%systemdrive%\rapport.txt)
if exist "%allusersprofile%\Menu D‚marrer\PopUp Blocker.url" (echo %allusersprofile%\Menu Démarrer\PopUp Blocker.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "%allusersprofile%\Menu D‚marrer\Spyware Remover.url" (echo %allusersprofile%\Menu Démarrer\Spyware Remover.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "%allusersprofile%\Menu D‚marrer\Programmes\AlfaCleaner" (echo %allusersprofile%\Menu Démarrer\Programmes\AlfaCleaner PRESENT !>>%systemdrive%\rapport.txt)
if exist "%allusersprofile%\Menu D‚marrer\Programmes\P.S.Guard spyware remover" (echo %allusersprofile%\Menu Démarrer\Programmes\P.S.Guard spyware remover PRESENT !>>%systemdrive%\rapport.txt)
if exist "%allusersprofile%\Menu D‚marrer\Programmes\WinHound spyware remover" (echo %allusersprofile%\Menu Démarrer\Programmes\WinHound spyware remover PRESENT !>>%systemdrive%\rapport.txt)



echo.>>%systemdrive%\rapport.txt
echo Recherche %desktop%...
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt

pushd %desktop%

if exist "access" (echo %desktop%\access PRESENT !>>%systemdrive%\rapport.txt)
if exist asfds (echo %desktop%\asfds PRESENT !>>%systemdrive%\rapport.txt)
if exist "domains" (echo %desktop%\domains PRESENT !>>%systemdrive%\rapport.txt)
if exist "map.txt" (echo %desktop%\map.txt PRESENT !>>%systemdrive%\rapport.txt)
if exist m00.exe (echo %desktop%\m00.exe PRESENT !>>%systemdrive%\rapport.txt)
if exist "Air Tickets.url" (echo %desktop%\Air Tickets.url PRESENT !>>%systemdrive%\rapport.txt)
if exist AlfaCleaner.lnk (echo %desktop%\AlfaCleaner.lnk PRESENT !>>%systemdrive%\rapport.txt)
if exist AntivirusGold.lnk (echo %desktop%\AntivirusGold.lnk PRESENT !>>%systemdrive%\rapport.txt)
if exist "Big Tits.url" (echo %desktop%\Big Tits.url PRESENT !>>%systemdrive%\rapport.txt)
if exist Blackjack.url (echo %desktop%\Blackjack.url PRESENT !>>%systemdrive%\rapport.txt)
if exist Blowjob.url (echo %desktop%\Blowjob.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Britney Spears.url" (echo %desktop%\Britney Spears.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Car Insurance.url" (echo %desktop%\Car Insurance.url PRESENT !>>%systemdrive%\rapport.txt)
if exist cdegfr (echo %desktop%\cdegfr PRESENT !>>%systemdrive%\rapport.txt)
if exist "Cheap Cigarettes.url" (echo %desktop%\Cheap Cigarettes.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Cigarettes Discount.url" (echo %desktop%\Cigarettes Discount.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Credit Card.url" (echo %desktop%\Credit Card.url PRESENT !>>%systemdrive%\rapport.txt)
if exist Cruises.url (echo %desktop%\Cruises.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Currency Trading.url" (echo %desktop%\Currency Trading.url PRESENT !>>%systemdrive%\rapport.txt)
if exist fdsf (echo %desktop%\fdsf PRESENT !>>%systemdrive%\rapport.txt)
if exist "Forex Trading.url" (echo %desktop%\Forex Trading.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Free Ringtones.url" (echo %desktop%\Free Ringtones.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Gift Ideas.url" (echo %desktop%\Gift Ideas.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Group Sex.url" (echo %desktop%\Group Sex.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Home Loan.url" (echo %desktop%\Home Loan.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Lesbian Sex.url" (echo %desktop%\Lesbian Sex.url PRESENT !>>%systemdrive%\rapport.txt)
if exist MP3.url (echo %desktop%\MP3.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Mp3 Download.url" (echo %desktop%\Mp3 Download.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Online Betting.url" (echo %desktop%\Online Betting.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Online Casino.url" (echo %desktop%\Online Casino.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Online Dating.url" (echo %desktop%\Online Dating.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Online Gambling.url" (echo %desktop%\Online Gambling.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Oral Sex.url" (echo %desktop%\Oral Sex.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Party Poker.url" (echo %desktop%\Party Poker.url PRESENT !>>%systemdrive%\rapport.txt)
if exist Pharmacy.url (echo %desktop%\Pharmacy.url PRESENT !>>%systemdrive%\rapport.txt)
if exist Phentermine.url (echo %desktop%\Phentermine.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Play Poker.url" (echo %desktop%\Play Poker.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "PopUp Blocker.url" (echo %desktop%\PopUp Blocker.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Porn Dvd.url" (echo %desktop%\Porn Dvd.url PRESENT !>>%systemdrive%\rapport.txt)
if exist Pornstars.url (echo %desktop%\Pornstars.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "P.S.Guard spyware remover.lnk" (echo %desktop%\P.S.Guard spyware remover.lnk PRESENT !>>%systemdrive%\rapport.txt)
if exist "Real Estate.url" (echo %desktop%\Real Estate.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Remove Spyware.url" (echo %desktop%\Remove Spyware.url PRESENT !>>%systemdrive%\rapport.txt)
if exist sdfdsf (echo %desktop%\sdfdsf PRESENT !>>%systemdrive%\rapport.txt)
if exist sdfff (echo %desktop%\sdfff PRESENT !>>%systemdrive%\rapport.txt)
if exist "Sport Betting.url" (echo %desktop%\Sport Betting.url PRESENT !>>%systemdrive%\rapport.txt)
if exist SpyFalcon.lnk (echo %desktop%\SpyFalcon.lnk PRESENT !>>%systemdrive%\rapport.txt)
if exist SpySheriff.lnk (echo %desktop%\SpySheriff.lnk PRESENT !>>%systemdrive%\rapport.txt)
if exist "Spyware Remover.url" (echo %desktop%\Spyware Remover.url PRESENT !>>%systemdrive%\rapport.txt)
if exist SpywareStrike.lnk (echo %desktop%\SpywareStrike.lnk PRESENT !>>%systemdrive%\rapport.txt)
if exist "Texas Holdem.url" (echo %desktop%\Texas Holdem.url PRESENT !>>%systemdrive%\rapport.txt)
if exist viagra.url (echo %desktop%\viagra.url PRESENT !>>%systemdrive%\rapport.txt)
if exist wdcevf (echo %desktop%\wdcevf PRESENT !>>%systemdrive%\rapport.txt)
if exist wdcevf (echo %desktop%\wdcevf PRESENT !>>%systemdrive%\rapport.txt)
if exist zxczxc (echo %desktop%\zxczxc PRESENT !>>%systemdrive%\rapport.txt)


popd



pushd %audesktop%


if exist "Air Tickets.url" (echo %audesktop%\Air Tickets.url PRESENT !>>%systemdrive%\rapport.txt)
if exist AntivirusGold.lnk (echo %audesktop%\AntivirusGold.lnk PRESENT !>>%systemdrive%\rapport.txt)
if exist "Big Tits.url" (echo %audesktop%\Big Tits.url PRESENT !>>%systemdrive%\rapport.txt)
if exist Blackjack.url (echo %audesktop%\Blackjack.url PRESENT !>>%systemdrive%\rapport.txt)
if exist Blowjob.url (echo %audesktop%\Blowjob.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Britney Spears.url" (echo %audesktop%\Britney Spears.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Car Insurance.url" (echo %audesktop%\Car Insurance.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Cheap Cigarettes.url" (echo %audesktop%\Cheap Cigarettes.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Cigarettes Discount.url" (echo %audesktop%\Cigarettes Discount.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Credit Card.url" (echo %audesktop%\Credit Card.url PRESENT !>>%systemdrive%\rapport.txt)
if exist Cruises.url (echo %audesktop%\Cruises.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Currency Trading.url" (echo %audesktop%\Currency Trading.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Forex Trading.url" (echo %audesktop%\Forex Trading.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Free Ringtones.url" (echo %audesktop%\Free Ringtones.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Gift Ideas.url" (echo %audesktop%\Gift Ideas.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Group Sex.url" (echo %audesktop%\Group Sex.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Home Loan.url" (echo %audesktop%\Home Loan.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Lesbian Sex.url" (echo %audesktop%\Lesbian Sex.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Mp3 Download.url" (echo %audesktop%\Mp3 Download.url PRESENT !>>%systemdrive%\rapport.txt)
if exist MP3.url (echo %audesktop%\MP3.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Online Betting.url" (echo %audesktop%\Online Betting.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Online Casino.url" (echo %audesktop%\Online Casino.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Online Dating.url" (echo %audesktop%\Online Dating.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Online Gambling.url" (echo %audesktop%\Online Gambling.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Oral Sex.url" (echo %audesktop%\Oral Sex.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Party Poker.url" (echo %audesktop%\Party Poker.url PRESENT !>>%systemdrive%\rapport.txt)
if exist Pharmacy.url (echo %audesktop%\Pharmacy.url PRESENT !>>%systemdrive%\rapport.txt)
if exist Phentermine.url (echo %audesktop%\Phentermine.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Play Poker.url" (echo %audesktop%\Play Poker.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "PopUp Blocker.url" (echo %audesktop%\PopUp Blocker.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Porn Dvd.url" (echo %audesktop%\Porn Dvd.url PRESENT !>>%systemdrive%\rapport.txt)
if exist Pornstars.url (echo %audesktop%\Pornstars.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "P.S.Guard spyware remover.lnk" (echo %audesktop%\P.S.Guard spyware remover.lnk PRESENT !>>%systemdrive%\rapport.txt)
if exist "Real Estate.url" (echo %audesktop%\Real Estate.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Remove Spyware.url" (echo %audesktop%\Remove Spyware.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Sport Betting.url" (echo %audesktop%\Sport Betting.url PRESENT !>>%systemdrive%\rapport.txt)
if exist SpySheriff.lnk (echo %audesktop%\SpySheriff.lnk PRESENT !>>%systemdrive%\rapport.txt)
if exist "Spyware Remover.url" (echo %audesktop%\Spyware Remover.url PRESENT !>>%systemdrive%\rapport.txt)
if exist viagra.url (echo %audesktop%\viagra.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "Texas Holdem.url" (echo %audesktop%\Texas Holdem.url PRESENT !>>%systemdrive%\rapport.txt)
if exist "WinHound spyware remover.lnk" (echo %audesktop%\WinHound spyware remover.lnk PRESENT !>>%systemdrive%\rapport.txt)

popd



echo.>>%systemdrive%\rapport.txt
echo Recherche %ProgramFiles%...
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche %ProgramFiles% >>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt


if exist "%ProgramFiles%\AdwareDelete" echo %ProgramFiles%\AdwareDelete\ PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\AlfaCleaner" echo %ProgramFiles%\AlfaCleaner\ PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\AntivirusGold" echo %ProgramFiles%\AntivirusGold\ PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Daily Weather Forecast" echo %ProgramFiles%\Daily Weather Forecast\ PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\PSGuard" echo %ProgramFiles%\PSGuard\ PRESENT!>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\P.S.Guard" echo %ProgramFiles%\P.S.Guard\ PRESENT!>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Search Maid" echo %ProgramFiles%\Search Maid\ PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Security IGuard" echo %ProgramFiles%\Security IGuard\ PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\SpyAxe" echo %ProgramFiles%\SpyAxe\ PRESENT!>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\SpyFalcon" echo %ProgramFiles%\SpyFalcon\ PRESENT!>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\SpySheriff" echo %ProgramFiles%\SpySheriff\ PRESENT!>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\SpyKiller" echo %ProgramFiles%\SpyKiller\ PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\SpywareStrike" echo %ProgramFiles%\SpywareStrike\ PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Virtual Maid" echo %ProgramFiles%\Virtual Maid\ PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\WinHound" echo %ProgramFiles%\WinHound\ PRESENT !>>%systemdrive%\rapport.txt

if exist "%ProgramFiles%\internet explorer\ieengine.exe" echo %ProgramFiles%\internet explorer\ieengine.exe PRESENT !>>%systemdrive%\rapport.txt

if exist "%ProgramFiles%\Fichiers communs\Download\mc-58-12-0000113.exe" echo %ProgramFiles%\Fichiers communs\Download\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Common Files\Download\mc-58-12-0000113.exe" echo %ProgramFiles%\Common Files\Download\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Fichiers communs\InetGet\mc-58-12-0000113.exe" echo %ProgramFiles%\Fichiers communs\InetGet\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Common Files\InetGet\mc-58-12-0000113.exe" echo %ProgramFiles%\Common Files\InetGet\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Fichiers communs\muwq\ echo %ProgramFiles%\Fichiers communs\muwq\" PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Common Files\muwq\ echo %ProgramFiles%\Common Files\muwq\" PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Fichiers communs\Windows\mc-58-12-0000113.exe" echo %ProgramFiles%\Fichiers communs\Windows\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Common Files\Windows\mc-58-12-0000113.exe" echo %ProgramFiles%\Common Files\Windows\mc-58-12-0000113.exe PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Fichiers communs\Windows\services32.exe" echo %ProgramFiles%\Fichiers communs\Windows\services32.exe PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Common Files\Windows\services32.exe" echo %ProgramFiles%\Common Files\Windows\services32.exe PRESENT !>>%systemdrive%\rapport.txt

if exist "%ProgramFiles%\Common Files\VCClient\VCMain.exe" echo %ProgramFiles%\Common Files\VCClient\VCMain.exe PRESENT !>>%systemdrive%\rapport.txt
if exist "%ProgramFiles%\Common Files\VCClient\VCClient.exe" echo %ProgramFiles%\Common Files\VCClient\VCClient.exe PRESENT !>>%systemdrive%\rapport.txt

if exist %syspath%\intell32.exe goto DateFile
goto sudderltd

:DateFile
dir %syspath%\intell32.exe /4 /A /N /-C>result.txt
type result.txt | find /i "intell32.exe">result2.txt
for /f "tokens=1" %%a in (result2.txt) do set filedate=%%a

echo Recherche des fichiers cr‚‚s le %filedate%...
echo.>>%systemdrive%\rapport.txt
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche fichiers créés le %filedate%>>%systemdrive%\rapport.txt
echo !!! Attention, les fichiers qui suivent ne sont pas forcément infectés !!!>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt

dir %HOMEDRIVE%\*.* /4 /A /N /-C | find /i "%filedate%">result.txt
for /f "tokens=4" %%a in (result.txt) do echo %HOMEDRIVE%\%%a>>%systemdrive%\rapport.txt
dir %windir%\*.* /4 /A /N /-C | find /i "%filedate%">result.txt
for /f "tokens=4" %%a in (result.txt) do echo %windir%\%%a>>%systemdrive%\rapport.txt
dir %syspath%\*.* /4 /A /N /-C | find /i "%filedate%">result.txt
for /f "tokens=4" %%a in (result.txt) do echo %syspath%\%%a>>%systemdrive%\rapport.txt

if exist result.txt del result.txt
if exist result2.txt del result2.txt
goto sudderltd


:sudderltd
echo Recherche pr‚sence de cl‚s corrompues
echo.>>%systemdrive%\rapport.txt
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt

regedit.exe /e %systemdrive%\SHUDDERLTD.txt "HKEY_LOCAL_MACHINE\SOFTWARE\SHUDDERLTD"
IF EXIST %systemdrive%\SHUDDERLTD.txt (
echo HKLM\SOFTWARE\SHUDDERLTD Présent !>>%systemdrive%\rapport.txt
del %systemdrive%\SHUDDERLTD.txt
)

regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com"
IF EXIST %systemdrive%\PSGuard.txt (
echo HKLM\SOFTWARE\PSGuard.com Présent !>>%systemdrive%\rapport.txt
del %systemdrive%\PSGuard.txt
)

regedit.exe /e %systemdrive%\WinHound.txt "HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com"
IF EXIST %systemdrive%\WinHound.txt (
echo HKLM\SOFTWARE\WinHound.com Présent !>>%systemdrive%\rapport.txt
del %systemdrive%\WinHound.txt
)



echo Recherche ‚l‚ments du bureau
echo.>>%systemdrive%\rapport.txt
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
IF EXIST desktop.txt del desktop.txt
regedit.exe /e desktop.txt "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0"
IF EXIST desktop.txt (
echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]>>%systemdrive%\rapport.txt
type desktop.txt | find /i "Source">>%systemdrive%\rapport.txt
type desktop.txt | find /i "SubscribedURL">>%systemdrive%\rapport.txt
type desktop.txt | find /i "FriendlyName">>%systemdrive%\rapport.txt
)
IF EXIST desktop.txt del desktop.txt

echo.>>%systemdrive%\rapport.txt

IF EXIST desktop.txt del desktop.txt
regedit.exe /e desktop.txt "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1"
IF EXIST desktop.txt (
echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]>>%systemdrive%\rapport.txt
type desktop.txt | find /i "Source">>%systemdrive%\rapport.txt
type desktop.txt | find /i "SubscribedURL">>%systemdrive%\rapport.txt
type desktop.txt | find /i "FriendlyName">>%systemdrive%\rapport.txt
)
IF EXIST desktop.txt del desktop.txt

IF EXIST desktop.txt del desktop.txt
regedit.exe /e desktop.txt "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\2"
IF EXIST desktop.txt (
echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\2]>>%systemdrive%\rapport.txt
type desktop.txt | find /i "Source">>%systemdrive%\rapport.txt
type desktop.txt | find /i "SubscribedURL">>%systemdrive%\rapport.txt
type desktop.txt | find /i "FriendlyName">>%systemdrive%\rapport.txt
)
IF EXIST desktop.txt del desktop.txt




echo Recherche Sharedtaskscheduler
echo.>>%systemdrive%\rapport.txt
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
SrchSTS>>%systemdrive%\rapport.txt



goto wininetscan



:wininetscan
echo Recherche infection wininet.dll
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt

findstr /m /I "OLEADM" %syspath%\wininet.dll>result.txt
for /F "TOKENS=* DELIMS=" %%A IN (result.txt) do echo wininet.dll infecté !>infected.txt
findstr /m /I "OLEEXT" %syspath%\wininet.dll>result.txt
for /F "TOKENS=* DELIMS=" %%A IN (result.txt) do echo wininet.dll infecté !>infected.txt
del result.txt
if exist infected.txt (
del infected.txt
echo.
echo %syspath%\wininet.dll infect‚ !
echo %syspath%\wininet.dll infecté !>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
echo »»»»»»»»»»»»»»»»»»»»»»»» Recherche wininet.dll de remplacement>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
dir %systemroot%\wininet.dll /a h /s>>%systemdrive%\rapport.txt
)


echo.
echo fin
echo.>>%systemdrive%\rapport.txt
echo »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
if exist CheckVersion.vbs del CheckVersion.vbs
if exist result2.txt del result2.txt
start %windir%\notepad.exe %systemdrive%\rapport.txt
goto menu











:fix

cls
echo %fixname% %fixvers%
echo %fixname% %fixvers%>%systemdrive%\rapport.txt
echo.
echo.>>%systemdrive%\rapport.txt
echo Rapport fait à %time% le %date%>>%systemdrive%\rapport.txt
for /f "Tokens=*" %%i in ('cd') do set CurDir=%%i
echo Executé à partir de %CurDir%>>%systemdrive%\rapport.txt
IF ERRORLEVEL 1 (
echo Executé à partir de >>%systemdrive%\rapport.txt
cd >>%systemdrive%\rapport.txt
)
for /f "Tokens=*" %%i in ('ver') do set Version=%%i
echo OS: %Version%>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt



echo Arret des processus...
echo »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt

process -k explorer.exe >NUL

swsc stop AlfaCleanerService >NUL
swsc delete AlfaCleanerService >NUL

Process -k 1.tmp >NUL
Process -k 3.tmp >NUL
Process -k 4.tmp >NUL
Process -k adsmart.exe >NUL
Process -k adtech2005.exe >NUL
Process -k adtech2006a.exe >NUL
Process -k AlfaCleaner.exe >NUL
Process -k AntivirusGold.exe >NUL
Process -k batserv2.exe >NUL
Process -k bsw.exe >NUL
Process -k bu.exe >NUL
Process -k bxproxy.exe >NUL
Process -k cmd32.exe >NUL
Process -k cmdtel.exe >NUL
Process -k combo.exe >NUL
Process -k contextplus.exe >NUL
Process -k d3dn32.exe >NUL
Process -k d3pb.exe >NUL
Process -k doser.exe >NUL
Process -k ecsiin.stub.exe >NUL
Process -k efsdfgxg.exe >NUL
Process -k exa32.exe >NUL
Process -k exeha2.exe >NUL
Process -k exeha3.exe >NUL
Process -k gunist.exe >NUL
Process -k helper.exe >NUL
Process -k hookdump.exe >NUL
Process -k ieengine.exe >NUL
Process -k ieyi.exe >NUL
Process -k intel32.exe >NUL
Process -k intell321.exe >NUL
Process -k intell32.exe >NUL
Process -k intmon.exe >NUL
Process -k intmonp.exe >NUL
Process -k intxt.exe >NUL
Process -k kernels32.exe >NUL
Process -k kernels64.exe >NUL
Process -k kl.exe >NUL
Process -k latest.exe >NUL
Process -k links.exe >NUL
Process -k ll.exe >NUL
Process -k
0
pato Messages postés 5 Statut Membre
 
merci pour l aide voila le rapport de scan ewido---------------------------------------------------------
ewido anti-malware - Rapport de scan
---------------------------------------------------------

+ Créé le: 10:14:44, 3/03/2006
+ Somme de contrôle: 1EA98FC

+ Résultats du scan:

C:\Documents and Settings\LocalService\Cookies\system@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Nettoyer et sauvegarder
C:\Documents and Settings\LocalService\Cookies\system@banners.searchingbooth[1].txt -> TrackingCookie.Searchingbooth : Nettoyer et sauvegarder
C:\Documents and Settings\LocalService\Cookies\system@media.top-banners[1].txt -> TrackingCookie.Top-banners : Nettoyer et sauvegarder
C:\Documents and Settings\LocalService\Cookies\system@paypopup[2].txt -> TrackingCookie.Paypopup : Nettoyer et sauvegarder
C:\Documents and Settings\LocalService\Cookies\system@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Nettoyer et sauvegarder
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\AN01KFGB\wallpap[1].exe -> Hijacker.Agent.gp : Nettoyer et sauvegarder
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WXMZ45M3\ErrorSafeFreeInstall[1].cab/UERS_0001_N68M1801NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
C:\Documents and Settings\Pat\Cookies\pat@wreport.weborama[1].txt -> TrackingCookie.Weborama : Nettoyer et sauvegarder
C:\Documents and Settings\Pat\Cookies\pat@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
C:\Documents and Settings\Pat\Internet Optimizer\optimize.exe -> Downloader.Dyfuca.ei : Nettoyer et sauvegarder
C:\Documents and Settings\Steph\bleh.exe -> Dropper.Agent.ye : Nettoyer et sauvegarder
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UERSV_0001_N68M0602NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UERSV_0001_N68M0602NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UERSV_0001_N68M0602NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
C:\WINDOWS\Downloaded Program Files\UERSV_0001_N68M0602NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
C:\WINDOWS\Downloaded Program Files\UERS_0001_N68M1801NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Nettoyer et sauvegarder
C:\WINDOWS\eee2.exe -> Adware.MediaMotor : Nettoyer et sauvegarder
C:\WINDOWS\eeedo.exe/eee2.exe -> Adware.MediaMotor : Nettoyer et sauvegarder
C:\WINDOWS\sns\index1.exe -> Trojan.LowZones.cf : Nettoyer et sauvegarder
C:\WINDOWS\sns.exe/sns\index1.exe -> Trojan.LowZones.cf : Nettoyer et sauvegarder
C:\WINDOWS\surv3.exe -> Downloader.VB.vv : Nettoyer et sauvegarder
C:\WINDOWS\system32\birdasfihuy32.dll -> Proxy.Small.ct : Nettoyer et sauvegarder
C:\WINDOWS\system32\bleh.exe -> Dropper.Agent.ye : Nettoyer et sauvegarder
C:\WINDOWS\system32\bum392.exe -> Downloader.Small.cjd : Nettoyer et sauvegarder
C:\WINDOWS\system32\csrs.exe -> Backdoor.PoeBot.b : Nettoyer et sauvegarder
C:\WINDOWS\system32\nzndkece.exe -> Backdoor.Rbot.apd : Nettoyer et sauvegarder
C:\WINDOWS\system32\svxhost.exe -> Backdoor.Rbot : Nettoyer et sauvegarder
C:\WINDOWS\system32\voi376.exe -> Downloader.CWS.r : Nettoyer et sauvegarder
C:\WINDOWS\system32\winldra.exe -> Backdoor.Dumador.fr : Nettoyer et sauvegarder
C:\WINDOWS\system32\__delete_on_reboot__steam.dll -> Backdoor.Akbot.a : Nettoyer et sauvegarder
C:\WINDOWS\uninstDsk.exe -> Trojan.Small.ev : Nettoyer et sauvegarder
C:\WINDOWS\wallpap.exe -> Hijacker.Agent.gp : Nettoyer et sauvegarder


::Fin du rapport
0
incognito02 Messages postés 3487 Statut Contributeur 138
 
Salut

tu as double cliker sur le mauvais.Choisis ou c est ecrit smitfraudfix.

a+
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
incognito02 Messages postés 3487 Statut Contributeur 138
 
Salut

tu as double cliker sur le mauvais.Choisis ou c est ecrit smitfraudfix.

a+
0
pato Messages postés 5 Statut Membre
 
quand je clique la dessus il me dit fichier process.exe absent
dezippez la totalite de l archive dans un dossier
0
incognito02 Messages postés 3487 Statut Contributeur 138
 
salut

Lorsque tu l as telechargé.Clik droit sur le fichier et choisis extraire tout.Un fichier est extrait a coté de l autre, ouvre le et ouvre smitfraudfix

a+
0