Fenetres message publicitaire
Résolu
ROUTIERSYMPA01
Messages postés
87
Statut
Membre
-
ROUTIERSYMPA01 Messages postés 87 Statut Membre -
ROUTIERSYMPA01 Messages postés 87 Statut Membre -
Bonjour, depuis quelques jours je suis importune regulierement par l arrivee de fenetres de messages publicitaires . Je precise bien que cela fait seulement environ 2 a 3 semaines seulement. Pourtant j'ai FIREFOX antispam .................... Que dois je faire ???? J'ai telecharger HIJACK suivant conseil lu sur ce site mais malheureusement ecrit en anglais et je ne comprend pas comment l utiliser . AU SECOUR Besoin d aide MERCI D avance Amities MICHEL le routier sympa du 01
A voir également:
- :Del files tempory echo. echo vous avez choisi la suppression des fichiers temporaires echo. start del /f /s /q %temp% pause goto question
- Recuperer message whatsapp supprimé - Guide
- Message absence thunderbird - Guide
- Sms publicitaire - Guide
- Message supprimé whatsapp - Guide
- Epingler un message whatsapp - Accueil - Messagerie instantanée
41 réponses
Re :-)
Installe hijackthis dans son propre dossier:
-clic droit sur le bureau, choisis "nouveau dossier" puis installe le dedans.
Lance le, clic sur "do a system scan and save logfile"
Puis copie et colle le rapport ici stp
Installe hijackthis dans son propre dossier:
-clic droit sur le bureau, choisis "nouveau dossier" puis installe le dedans.
Lance le, clic sur "do a system scan and save logfile"
Puis copie et colle le rapport ici stp
Logfile of HijackThis v1.99.1
Scan saved at 14:01:32, on 22/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
C:\WINDOWS\system32\ctfmon.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Agendis\Agendis.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
C:\Program Files\Larousse\Encyclopédie Universelle Larousse\bin\hyperappel.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearch.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Boonty\BoontyBox\BoontyBox.exe
C:\Program Files\mp3-explorer\SystrayStarter.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearchIndexer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
C:\Documents and Settings\Utilisateur1\Bureau\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O3 - Toolbar: Barre d'outils MSN Search - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [News Service] "C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [AUDIOSURFFUNKPOLL] C:\Documents and Settings\All Users\Application Data\InterDaleAudioSurf\Eggs stupid.exe
O4 - HKLM\..\Run: [SystemDoctor 2006 Free] C:\Program Files\SystemDoctor 2006 Free\sd2006.exe -scan
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [F-Secure Internet Security] C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\ins3.tmp\is2004.exe -ReportOnly
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Agendis] C:\Program Files\Agendis\Agendis.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_5 -reboot 1
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Phone Option] C:\DOCUME~1\UTILIS~1\APPLIC~1\BROWSE~1\help less meal.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Startup: BoontyBox Alice Jeux.lnk = C:\Program Files\Boonty\BoontyBox\BoontyBox.exe
O4 - Startup: [ mp3 - explorer ].lnk = C:\Program Files\mp3-explorer\SystrayStarter.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
O4 - Global Startup: Hyperappel de l'Encyclopédie Universelle Larousse.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearch.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxmk879YYFR
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?c4e1090286b44fd5ba1c23c49da7420
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?c4e1090286b44fd5ba1c23c49da7420
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Filtre Web - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Filtre Web - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.euro.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - ak.exe.imgfarm.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - update.microsoft.com
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: F-Secure 2006 (BackWeb Client - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Scan saved at 14:01:32, on 22/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
C:\WINDOWS\system32\ctfmon.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Agendis\Agendis.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
C:\Program Files\Larousse\Encyclopédie Universelle Larousse\bin\hyperappel.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearch.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Boonty\BoontyBox\BoontyBox.exe
C:\Program Files\mp3-explorer\SystrayStarter.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearchIndexer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
C:\Documents and Settings\Utilisateur1\Bureau\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O3 - Toolbar: Barre d'outils MSN Search - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [News Service] "C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [AUDIOSURFFUNKPOLL] C:\Documents and Settings\All Users\Application Data\InterDaleAudioSurf\Eggs stupid.exe
O4 - HKLM\..\Run: [SystemDoctor 2006 Free] C:\Program Files\SystemDoctor 2006 Free\sd2006.exe -scan
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [F-Secure Internet Security] C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\ins3.tmp\is2004.exe -ReportOnly
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Agendis] C:\Program Files\Agendis\Agendis.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_5 -reboot 1
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Phone Option] C:\DOCUME~1\UTILIS~1\APPLIC~1\BROWSE~1\help less meal.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Startup: BoontyBox Alice Jeux.lnk = C:\Program Files\Boonty\BoontyBox\BoontyBox.exe
O4 - Startup: [ mp3 - explorer ].lnk = C:\Program Files\mp3-explorer\SystrayStarter.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
O4 - Global Startup: Hyperappel de l'Encyclopédie Universelle Larousse.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearch.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxmk879YYFR
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?c4e1090286b44fd5ba1c23c49da7420
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?c4e1090286b44fd5ba1c23c49da7420
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Filtre Web - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Filtre Web - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.euro.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - ak.exe.imgfarm.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - update.microsoft.com
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: F-Secure 2006 (BackWeb Client - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
slt,
Télécharge Blacklight (de F-Secure) a l’une des 2 adresses :
https://www.f-secure.com/en
et sauvegarde le sur ton Bureau.
Double-clique blbeta.exe et accepte la licence ; laisse [X]scan through Windows Explorer activé ; clique Scan puis Next
Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).
Copie et colle le contenu de ce rapport STP
A+
Télécharge Blacklight (de F-Secure) a l’une des 2 adresses :
https://www.f-secure.com/en
et sauvegarde le sur ton Bureau.
Double-clique blbeta.exe et accepte la licence ; laisse [X]scan through Windows Explorer activé ; clique Scan puis Next
Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).
Copie et colle le contenu de ce rapport STP
A+
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Je vous remercie. BOULEPATE, si je pose trops de question, cest que j 'aurai desire des reponses pour solutionner mon probleme. Amities MICHEL
re routier du calme ! lol
F-secure que tu as est un antivirus ...C
elui que je te demande d'installer n'a rien à voir avec ça...
Donc tu peux le faire.
A+
F-secure que tu as est un antivirus ...C
elui que je te demande d'installer n'a rien à voir avec ça...
Donc tu peux le faire.
A+
09/23/06 21:51:41 [Info]: BlackLight Engine 1.0.46 initialized
09/23/06 21:51:41 [Info]: OS: 5.0 build 2195 ()
09/23/06 21:51:41 [Note]: 7019 4
09/23/06 21:51:41 [Note]: 7005 0
09/23/06 21:51:42 [Note]: 7006 0
09/23/06 21:51:43 [Note]: 7011 3276
09/23/06 21:51:53 [Note]: 7027 5
09/23/06 21:52:03 [Error]: 6030 0
09/23/06 21:52:03 [Note]: 7027 0
09/23/06 21:52:05 [Note]: 7026 0
09/23/06 21:52:05 [Note]: 7026 0
09/23/06 21:53:15 [Note]: FSRAW library version 1.7.1019
09/23/06 21:53:15 [Note]: 7007 0
09/23/06 21:51:41 [Info]: OS: 5.0 build 2195 ()
09/23/06 21:51:41 [Note]: 7019 4
09/23/06 21:51:41 [Note]: 7005 0
09/23/06 21:51:42 [Note]: 7006 0
09/23/06 21:51:43 [Note]: 7011 3276
09/23/06 21:51:53 [Note]: 7027 5
09/23/06 21:52:03 [Error]: 6030 0
09/23/06 21:52:03 [Note]: 7027 0
09/23/06 21:52:05 [Note]: 7026 0
09/23/06 21:52:05 [Note]: 7026 0
09/23/06 21:53:15 [Note]: FSRAW library version 1.7.1019
09/23/06 21:53:15 [Note]: 7007 0
Salut l'amiRoutier
telecharge ça:
http://download.bleepingcomputer.com/sUBs/combofix.exe
appuyes sur "Y" pour continuer
Attends quelques minutes..un rapport va s'ouvrir enregistre son contenu, puis copie et colle le sur ici stp
telecharge ça:
http://download.bleepingcomputer.com/sUBs/combofix.exe
appuyes sur "Y" pour continuer
Attends quelques minutes..un rapport va s'ouvrir enregistre son contenu, puis copie et colle le sur ici stp
Utilisateur1 - 06-09-24 9:39:22.09 Service Pack 2
ComboFix 06.09.23.2 - Running from: "C:\Program Files\Mozilla Firefox"
((((((((((((((((((((((((((((((( Files Created from 2006-08-24 to 2006-09-24 ))))))))))))))))))))))))))))))))))
2006-09-10 17:52 28,672 --a--c--- C:\WINDOWS\system32\f3PSSavr.scr
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-09-24 09:39 -------- d----c--- C:\Program Files\Mozilla Firefox
2006-09-23 12:40 -------- d----c--- C:\Program Files\OpenOffice.org1.1.2
2006-09-22 19:07 -------- d----c--- C:\Program Files\IncrediMail
2006-09-22 17:30 -------- d----c--- C:\Program Files\Softwin
2006-09-22 17:30 -------- d----c--- C:\Program Files\Fichiers communs\Softwin
2006-09-22 13:35 -------- d----c--- C:\Program Files\Winamp
2006-09-14 13:21 -------- d----c--- C:\Program Files\Win G‚n‚alogic
2006-09-11 09:45 -------- d----c--- C:\Program Files\MSN Messenger
2006-09-11 09:45 -------- d----c--- C:\Program Files\FunWebProducts
2006-09-10 17:53 -------- d----c--- C:\Program Files\MyWebSearch
2006-09-02 12:41 -------- d----c--- C:\Program Files\Windows Live Safety Center
2006-08-24 17:02 -------- d----c--- C:\Program Files\WIDCOMM
2006-08-22 12:25 -------- d----c--- C:\Program Files\Yahoo!
2006-08-21 14:26 16896 --a--c--- C:\WINDOWS\system32\fltlib.dll
2006-08-21 11:14 23040 --a--c--- C:\WINDOWS\system32\fltmc.exe
2006-08-21 11:14 128896 --a--c--- C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-21 10:05 -------- d---sc--- C:\Documents and Settings\Utilisateur1\Application Data\Microsoft
2006-08-18 16:43 -------- d----c--- C:\Program Files\Fichiers communs\BOONTY Shared
2006-08-18 16:43 -------- d----c--- C:\Program Files\Fichiers communs
2006-08-18 16:41 12464 --a--c--- C:\WINDOWS\system32\drivers\CdaC15BA.SYS
2006-08-18 16:39 -------- d----c--- C:\Program Files\Mes Jeux T‚l‚charg‚s
2006-08-18 16:39 -------- d----c--- C:\Program Files\BoontyGames
2006-08-18 16:37 711687 --a--c--- C:\WINDOWS\unins000.exe
2006-08-18 16:37 -------- d----c--- C:\Program Files\Boonty
2006-08-15 19:26 -------- d----c--- C:\Documents and Settings\Utilisateur1\Application Data\Identities
2006-08-15 13:08 -------- d----c--- C:\Program Files\Fichiers communs\Adobe
2006-08-15 11:06 -------- d----c--- C:\Documents and Settings\Utilisateur1\Application Data\Browsesignseek
2006-08-15 11:04 -------- d----c--- C:\Documents and Settings\Utilisateur1\Application Data\WMA ITCH
2006-08-15 11:03 -------- d----c--- C:\Program Files\Browsesignseek
2006-08-15 11:02 -------- d----c--- C:\Program Files\Messenger Plus! Live
2006-08-15 11:02 -------- d----c--- C:\Program Files\Adverts
2006-08-15 08:09 -------- d----c--- C:\Program Files\Fichiers communs\Microsoft Shared
2006-08-13 15:46 -------- d----c--- C:\Documents and Settings\Utilisateur1\Application Data\Image Zone Express
2006-08-13 15:07 -------- d----c--- C:\Program Files\HP
2006-08-13 15:07 -------- d----c--- C:\Program Files\Fichiers communs\HP
2006-08-13 14:52 7747 --a--c--- C:\Documents and Settings\Utilisateur1\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
2006-08-09 20:58 -------- d----c--- C:\Program Files\Internet Explorer
2006-08-03 18:14 -------- d----c--- C:\Program Files\WinZip
2006-07-29 19:32 48936 --a--c--- C:\WINDOWS\system32\sirenacm.dll
2006-07-27 15:26 679424 --a--c--- C:\WINDOWS\system32\inetcomm.dll
2006-07-21 10:27 72704 --a--c--- C:\WINDOWS\system32\hlink.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"F-Secure Internet Security"="C:\\DOCUME~1\\UTILIS~1\\LOCALS~1\\Temp\\ins3.tmp\\is2004.exe -ReportOnly"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NVMCTRAY.DLL,NvTaskbarInit"
"NVIEW"="rundll32.exe nview.dll,nViewLoadHook"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Agendis"="C:\\Program Files\\Agendis\\Agendis.exe"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_5 -reboot 1"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"Phone Option"="C:\\DOCUME~1\\UTILIS~1\\APPLIC~1\\BROWSE~1\\help less meal.exe"
"MyWebSearch Email Plugin"="C:\\PROGRA~1\\MYWEBS~1\\bar\\1.bin\\mwsoemon.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"REGSHAVE"="C:\\Program Files\\REGSHAVE\\REGSHAVE.EXE /AUTORUN"
"F-Secure Manager"="\"C:\\Program Files\\F-Secure Internet Security\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program Files\\F-Secure Internet Security\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Edition Découverte\\3.0\\Apps\\apdproxy.exe\""
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"F-Secure Startup Wizard"="\"C:\\Program Files\\F-Secure Internet Security\\FSGUI\\FSSW.EXE\" /reboot"
"News Service"="\"C:\\Program Files\\F-Secure Internet Security\\FSGUI\\ispnews.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"AUDIOSURFFUNKPOLL"="C:\\Documents and Settings\\All Users\\Application Data\\InterDaleAudioSurf\\Eggs stupid.exe"
"SystemDoctor 2006 Free"="C:\\Program Files\\SystemDoctor 2006 Free\\sd2006.exe -scan"
"My Web Search Bar"="rundll32 C:\\PROGRA~1\\MYWEBS~1\\bar\\1.bin\\MWSBAR.DLL,S"
"MyWebSearch Email Plugin"="C:\\PROGRA~1\\MYWEBS~1\\bar\\1.bin\\mwsoemon.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,b0,00,00,00,00,00,00,00,70,02,00,00,3a,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,b0,00,00,00,00,00,00,00,70,02,00,00,3a,02,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NVMCTRAY.DLL,NvTaskbarInit"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NVMCTRAY.DLL,NvTaskbarInit"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Scheduled scanning task.job
Completion time: 06-09-24 9:41:48.81
ComboFix.txt
ComboFix2.txt
ComboFix 06.09.23.2 - Running from: "C:\Program Files\Mozilla Firefox"
((((((((((((((((((((((((((((((( Files Created from 2006-08-24 to 2006-09-24 ))))))))))))))))))))))))))))))))))
2006-09-10 17:52 28,672 --a--c--- C:\WINDOWS\system32\f3PSSavr.scr
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-09-24 09:39 -------- d----c--- C:\Program Files\Mozilla Firefox
2006-09-23 12:40 -------- d----c--- C:\Program Files\OpenOffice.org1.1.2
2006-09-22 19:07 -------- d----c--- C:\Program Files\IncrediMail
2006-09-22 17:30 -------- d----c--- C:\Program Files\Softwin
2006-09-22 17:30 -------- d----c--- C:\Program Files\Fichiers communs\Softwin
2006-09-22 13:35 -------- d----c--- C:\Program Files\Winamp
2006-09-14 13:21 -------- d----c--- C:\Program Files\Win G‚n‚alogic
2006-09-11 09:45 -------- d----c--- C:\Program Files\MSN Messenger
2006-09-11 09:45 -------- d----c--- C:\Program Files\FunWebProducts
2006-09-10 17:53 -------- d----c--- C:\Program Files\MyWebSearch
2006-09-02 12:41 -------- d----c--- C:\Program Files\Windows Live Safety Center
2006-08-24 17:02 -------- d----c--- C:\Program Files\WIDCOMM
2006-08-22 12:25 -------- d----c--- C:\Program Files\Yahoo!
2006-08-21 14:26 16896 --a--c--- C:\WINDOWS\system32\fltlib.dll
2006-08-21 11:14 23040 --a--c--- C:\WINDOWS\system32\fltmc.exe
2006-08-21 11:14 128896 --a--c--- C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-21 10:05 -------- d---sc--- C:\Documents and Settings\Utilisateur1\Application Data\Microsoft
2006-08-18 16:43 -------- d----c--- C:\Program Files\Fichiers communs\BOONTY Shared
2006-08-18 16:43 -------- d----c--- C:\Program Files\Fichiers communs
2006-08-18 16:41 12464 --a--c--- C:\WINDOWS\system32\drivers\CdaC15BA.SYS
2006-08-18 16:39 -------- d----c--- C:\Program Files\Mes Jeux T‚l‚charg‚s
2006-08-18 16:39 -------- d----c--- C:\Program Files\BoontyGames
2006-08-18 16:37 711687 --a--c--- C:\WINDOWS\unins000.exe
2006-08-18 16:37 -------- d----c--- C:\Program Files\Boonty
2006-08-15 19:26 -------- d----c--- C:\Documents and Settings\Utilisateur1\Application Data\Identities
2006-08-15 13:08 -------- d----c--- C:\Program Files\Fichiers communs\Adobe
2006-08-15 11:06 -------- d----c--- C:\Documents and Settings\Utilisateur1\Application Data\Browsesignseek
2006-08-15 11:04 -------- d----c--- C:\Documents and Settings\Utilisateur1\Application Data\WMA ITCH
2006-08-15 11:03 -------- d----c--- C:\Program Files\Browsesignseek
2006-08-15 11:02 -------- d----c--- C:\Program Files\Messenger Plus! Live
2006-08-15 11:02 -------- d----c--- C:\Program Files\Adverts
2006-08-15 08:09 -------- d----c--- C:\Program Files\Fichiers communs\Microsoft Shared
2006-08-13 15:46 -------- d----c--- C:\Documents and Settings\Utilisateur1\Application Data\Image Zone Express
2006-08-13 15:07 -------- d----c--- C:\Program Files\HP
2006-08-13 15:07 -------- d----c--- C:\Program Files\Fichiers communs\HP
2006-08-13 14:52 7747 --a--c--- C:\Documents and Settings\Utilisateur1\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
2006-08-09 20:58 -------- d----c--- C:\Program Files\Internet Explorer
2006-08-03 18:14 -------- d----c--- C:\Program Files\WinZip
2006-07-29 19:32 48936 --a--c--- C:\WINDOWS\system32\sirenacm.dll
2006-07-27 15:26 679424 --a--c--- C:\WINDOWS\system32\inetcomm.dll
2006-07-21 10:27 72704 --a--c--- C:\WINDOWS\system32\hlink.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"F-Secure Internet Security"="C:\\DOCUME~1\\UTILIS~1\\LOCALS~1\\Temp\\ins3.tmp\\is2004.exe -ReportOnly"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NVMCTRAY.DLL,NvTaskbarInit"
"NVIEW"="rundll32.exe nview.dll,nViewLoadHook"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Agendis"="C:\\Program Files\\Agendis\\Agendis.exe"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_5 -reboot 1"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"Phone Option"="C:\\DOCUME~1\\UTILIS~1\\APPLIC~1\\BROWSE~1\\help less meal.exe"
"MyWebSearch Email Plugin"="C:\\PROGRA~1\\MYWEBS~1\\bar\\1.bin\\mwsoemon.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"REGSHAVE"="C:\\Program Files\\REGSHAVE\\REGSHAVE.EXE /AUTORUN"
"F-Secure Manager"="\"C:\\Program Files\\F-Secure Internet Security\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program Files\\F-Secure Internet Security\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Edition Découverte\\3.0\\Apps\\apdproxy.exe\""
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"F-Secure Startup Wizard"="\"C:\\Program Files\\F-Secure Internet Security\\FSGUI\\FSSW.EXE\" /reboot"
"News Service"="\"C:\\Program Files\\F-Secure Internet Security\\FSGUI\\ispnews.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"AUDIOSURFFUNKPOLL"="C:\\Documents and Settings\\All Users\\Application Data\\InterDaleAudioSurf\\Eggs stupid.exe"
"SystemDoctor 2006 Free"="C:\\Program Files\\SystemDoctor 2006 Free\\sd2006.exe -scan"
"My Web Search Bar"="rundll32 C:\\PROGRA~1\\MYWEBS~1\\bar\\1.bin\\MWSBAR.DLL,S"
"MyWebSearch Email Plugin"="C:\\PROGRA~1\\MYWEBS~1\\bar\\1.bin\\mwsoemon.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,b0,00,00,00,00,00,00,00,70,02,00,00,3a,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,b0,00,00,00,00,00,00,00,70,02,00,00,3a,02,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NVMCTRAY.DLL,NvTaskbarInit"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NVMCTRAY.DLL,NvTaskbarInit"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Scheduled scanning task.job
Completion time: 06-09-24 9:41:48.81
ComboFix.txt
ComboFix2.txt
Salut,
Clic sur demarrer ,poste de travail, C:, program files et supprime ces dossiers si présent:
FunWebProducts
MyWebSearch
BoontyGames
Boonty
Browsesignseek
SystemDoctor 2006 Free
Adverts < tu connais, sinon supprime
Clic sur demarrer, poste de travail, C:, Windows et supprime ce fichier:
unins000.exe
___
Pour afficher tous les dossiers et fichiers cachés;
Clic sur "démarrer", "panneau de configuration", "outils" ,"option des dossiers", "affichage"
"
Coche:
¤ afficher les fichiers et dossiers cachés
Clic sur "appliquer" puis "ok"
Clic sur demarrer, poste de travail, C:, documents and settings, all users application data et supprime ce dossier
InterDaleAudioSurf
**Si un fichier persiste lors de la suppression fais ceci:
-Redemarres ton pc, dès l'allumage de celui-ci tapote la touche F8 (ou F5 si F8 ne fonctionne pas), à l'écran qui va apparaitre choisis "mode sans echec" attends un peu.. puis vas supprimer les fichiers/dossiers qui persistaient, vides ta corbeille et redemarres normalement
Puis:
Télécharge lopxp:
http://pageperso.aol.fr/balltrap34/lopxp.zip
dézippe-le sur ton bureau puis double-clic sur le fichier "lopxp.bat"
quand il à terminé, un rapport s'ouvre : fais un copier-coller puis mets le ici
Clic sur demarrer ,poste de travail, C:, program files et supprime ces dossiers si présent:
FunWebProducts
MyWebSearch
BoontyGames
Boonty
Browsesignseek
SystemDoctor 2006 Free
Adverts < tu connais, sinon supprime
Clic sur demarrer, poste de travail, C:, Windows et supprime ce fichier:
unins000.exe
___
Pour afficher tous les dossiers et fichiers cachés;
Clic sur "démarrer", "panneau de configuration", "outils" ,"option des dossiers", "affichage"
"
Coche:
¤ afficher les fichiers et dossiers cachés
Clic sur "appliquer" puis "ok"
Clic sur demarrer, poste de travail, C:, documents and settings, all users application data et supprime ce dossier
InterDaleAudioSurf
**Si un fichier persiste lors de la suppression fais ceci:
-Redemarres ton pc, dès l'allumage de celui-ci tapote la touche F8 (ou F5 si F8 ne fonctionne pas), à l'écran qui va apparaitre choisis "mode sans echec" attends un peu.. puis vas supprimer les fichiers/dossiers qui persistaient, vides ta corbeille et redemarres normalement
Puis:
Télécharge lopxp:
http://pageperso.aol.fr/balltrap34/lopxp.zip
dézippe-le sur ton bureau puis double-clic sur le fichier "lopxp.bat"
quand il à terminé, un rapport s'ouvre : fais un copier-coller puis mets le ici
Rapport fait à 10:14:12.68 le 06-09-25
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\All Users\Application Data
06-08-18 16:43 <REP> BOONTY
06-08-18 16:41 <REP> Macrovision
06-08-15 12:08 <REP> Yahoo!
06-05-13 15:31 <REP> Messenger Plus!
06-04-10 21:14 <REP> F-Secure
06-01-17 16:42 <REP> PlayFirst
06-01-17 16:42 <REP> Zylom
05-12-15 22:52 <REP> Adobe
05-11-08 10:02 <REP> MSN Search Toolbar
05-10-15 16:15 <REP> QuickTime
05-10-14 18:36 <REP> Hewlett-Packard
05-10-14 18:21 3061 hpzinstall.log
05-10-13 14:44 <REP> Windows Genuine Advantage
05-10-13 14:27 62 desktop.ini
05-10-13 14:26 <REP> Microsoft
05-10-13 14:26 <REP> .
05-10-13 14:26 <REP> ..
2 fichier(s) 3123 octets
15 R‚p(s) 7892619264 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Default User\Application Data
05-10-13 14:27 62 desktop.ini
05-10-13 14:26 <REP> ..
05-10-13 14:26 <REP> Microsoft
05-10-13 14:26 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Invit‚\Application Data
06-08-13 12:13 <REP> ispnews
06-08-13 12:11 <REP> Identities
06-08-13 12:11 62 desktop.ini
06-08-13 12:11 <REP> ..
06-08-13 12:11 <REP> Microsoft
06-08-13 12:11 <REP> .
1 fichier(s) 62 octets
5 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Jeremy\Application Data
06-07-16 20:31 <REP> Media Player Classic
06-07-15 13:03 <REP> Winamp
06-04-10 23:33 <REP> F-Secure
06-04-10 23:29 <REP> ispnews
06-03-28 23:35 <REP> AdobeUM
06-03-28 23:34 <REP> Leadertech
06-03-21 01:20 <REP> Help
06-02-19 17:10 <REP> Adobe
06-02-13 20:29 <REP> Sun
06-02-13 19:59 <REP> Macromedia
06-02-13 19:56 <REP> MSN Search Toolbar
06-02-13 19:54 <REP> Mozilla
06-02-13 19:53 <REP> Identities
06-02-13 19:52 62 desktop.ini
06-02-13 19:52 <REP> ..
06-02-13 19:52 <REP> .
06-02-13 19:52 <REP> Microsoft
1 fichier(s) 62 octets
16 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\TOTOF\Application Data
06-08-04 13:53 92368 errorsafescannerinstall_fr[1].exe
06-05-22 13:30 <REP> Real
06-05-04 12:39 <REP> F-Secure
06-04-15 13:04 <REP> ispnews
06-04-01 14:47 <REP> Help
06-01-25 22:35 <REP> AdobeUM
06-01-17 16:42 <REP> PlayFirst
06-01-17 16:42 <REP> Zylom
06-01-17 16:41 <REP> Zylom Games
05-12-18 18:42 <REP> FUJIFILM
05-12-18 18:38 <REP> Leadertech
05-12-05 23:57 <REP> Adobe
05-11-11 19:26 <REP> Media Player Classic
05-11-08 12:21 <REP> MSN Search Toolbar
05-10-26 11:42 <REP> Mozilla
05-10-21 21:34 <REP> Sun
05-10-21 21:28 <REP> Macromedia
05-10-21 21:15 <REP> Identities
05-10-21 21:15 62 desktop.ini
05-10-21 21:15 <REP> ..
05-10-21 21:15 <REP> .
05-10-21 21:15 <REP> Microsoft
2 fichier(s) 92430 octets
20 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Utilisateur1\Application Data
06-08-15 11:03 <REP> WMA ITCH
06-08-15 11:03 <REP> Browsesignseek
06-08-13 14:51 7747 GdiplusUpgrade_MSIApproach_Wrapper.log
06-04-10 22:11 <REP> PEX
06-04-10 21:34 <REP> F-Secure
06-04-10 21:22 <REP> ispnews
06-01-08 13:53 <REP> Image Zone Express
06-01-05 21:37 <REP> Media Player Classic
06-01-04 19:45 <REP> Leadertech
05-11-15 21:10 <REP> InterTrust
05-11-03 20:02 <REP> AdobeUM
05-10-29 23:39 <REP> Real
05-10-25 11:03 <REP> Ahead
05-10-24 19:18 <REP> Mozilla
05-10-24 14:41 <REP> Google
05-10-17 20:09 <REP> FUJIFILM
05-10-15 13:15 <REP> Help
05-10-14 22:05 <REP> Sun
05-10-14 19:57 <REP> MSNInstaller
05-10-14 18:07 <REP> FotoWire
05-10-14 15:28 <REP> Macromedia
05-10-14 13:35 <REP> Adobe
05-10-14 12:06 83 sversion.ini
05-10-14 12:01 <REP> vlc
05-10-13 14:25 <REP> Identities
05-10-13 14:25 62 desktop.ini
05-10-13 14:25 <REP> Microsoft
05-10-13 14:25 <REP> .
05-10-13 14:25 <REP> ..
3 fichier(s) 7892 octets
26 R‚p(s) 7892541440 octets libres
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\WINDOWS\Tasks
06-04-10 22:12 552 Scheduled scanning task.job
05-10-13 14:14 6 SA.DAT
05-10-13 14:01 65 desktop.ini
05-10-13 14:01 <REP> ..
05-10-13 14:01 <REP> .
3 fichier(s) 623 octets
2 R‚p(s) 7,892,541,440 octets libres
******************************************
Recherche dans Program files
Le dossier C:\Program Files\C2Media n'existe pas
*************** Fin du rapport ****************
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\All Users\Application Data
06-08-18 16:43 <REP> BOONTY
06-08-18 16:41 <REP> Macrovision
06-08-15 12:08 <REP> Yahoo!
06-05-13 15:31 <REP> Messenger Plus!
06-04-10 21:14 <REP> F-Secure
06-01-17 16:42 <REP> PlayFirst
06-01-17 16:42 <REP> Zylom
05-12-15 22:52 <REP> Adobe
05-11-08 10:02 <REP> MSN Search Toolbar
05-10-15 16:15 <REP> QuickTime
05-10-14 18:36 <REP> Hewlett-Packard
05-10-14 18:21 3061 hpzinstall.log
05-10-13 14:44 <REP> Windows Genuine Advantage
05-10-13 14:27 62 desktop.ini
05-10-13 14:26 <REP> Microsoft
05-10-13 14:26 <REP> .
05-10-13 14:26 <REP> ..
2 fichier(s) 3123 octets
15 R‚p(s) 7892619264 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Default User\Application Data
05-10-13 14:27 62 desktop.ini
05-10-13 14:26 <REP> ..
05-10-13 14:26 <REP> Microsoft
05-10-13 14:26 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Invit‚\Application Data
06-08-13 12:13 <REP> ispnews
06-08-13 12:11 <REP> Identities
06-08-13 12:11 62 desktop.ini
06-08-13 12:11 <REP> ..
06-08-13 12:11 <REP> Microsoft
06-08-13 12:11 <REP> .
1 fichier(s) 62 octets
5 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Jeremy\Application Data
06-07-16 20:31 <REP> Media Player Classic
06-07-15 13:03 <REP> Winamp
06-04-10 23:33 <REP> F-Secure
06-04-10 23:29 <REP> ispnews
06-03-28 23:35 <REP> AdobeUM
06-03-28 23:34 <REP> Leadertech
06-03-21 01:20 <REP> Help
06-02-19 17:10 <REP> Adobe
06-02-13 20:29 <REP> Sun
06-02-13 19:59 <REP> Macromedia
06-02-13 19:56 <REP> MSN Search Toolbar
06-02-13 19:54 <REP> Mozilla
06-02-13 19:53 <REP> Identities
06-02-13 19:52 62 desktop.ini
06-02-13 19:52 <REP> ..
06-02-13 19:52 <REP> .
06-02-13 19:52 <REP> Microsoft
1 fichier(s) 62 octets
16 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\TOTOF\Application Data
06-08-04 13:53 92368 errorsafescannerinstall_fr[1].exe
06-05-22 13:30 <REP> Real
06-05-04 12:39 <REP> F-Secure
06-04-15 13:04 <REP> ispnews
06-04-01 14:47 <REP> Help
06-01-25 22:35 <REP> AdobeUM
06-01-17 16:42 <REP> PlayFirst
06-01-17 16:42 <REP> Zylom
06-01-17 16:41 <REP> Zylom Games
05-12-18 18:42 <REP> FUJIFILM
05-12-18 18:38 <REP> Leadertech
05-12-05 23:57 <REP> Adobe
05-11-11 19:26 <REP> Media Player Classic
05-11-08 12:21 <REP> MSN Search Toolbar
05-10-26 11:42 <REP> Mozilla
05-10-21 21:34 <REP> Sun
05-10-21 21:28 <REP> Macromedia
05-10-21 21:15 <REP> Identities
05-10-21 21:15 62 desktop.ini
05-10-21 21:15 <REP> ..
05-10-21 21:15 <REP> .
05-10-21 21:15 <REP> Microsoft
2 fichier(s) 92430 octets
20 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Utilisateur1\Application Data
06-08-15 11:03 <REP> WMA ITCH
06-08-15 11:03 <REP> Browsesignseek
06-08-13 14:51 7747 GdiplusUpgrade_MSIApproach_Wrapper.log
06-04-10 22:11 <REP> PEX
06-04-10 21:34 <REP> F-Secure
06-04-10 21:22 <REP> ispnews
06-01-08 13:53 <REP> Image Zone Express
06-01-05 21:37 <REP> Media Player Classic
06-01-04 19:45 <REP> Leadertech
05-11-15 21:10 <REP> InterTrust
05-11-03 20:02 <REP> AdobeUM
05-10-29 23:39 <REP> Real
05-10-25 11:03 <REP> Ahead
05-10-24 19:18 <REP> Mozilla
05-10-24 14:41 <REP> Google
05-10-17 20:09 <REP> FUJIFILM
05-10-15 13:15 <REP> Help
05-10-14 22:05 <REP> Sun
05-10-14 19:57 <REP> MSNInstaller
05-10-14 18:07 <REP> FotoWire
05-10-14 15:28 <REP> Macromedia
05-10-14 13:35 <REP> Adobe
05-10-14 12:06 83 sversion.ini
05-10-14 12:01 <REP> vlc
05-10-13 14:25 <REP> Identities
05-10-13 14:25 62 desktop.ini
05-10-13 14:25 <REP> Microsoft
05-10-13 14:25 <REP> .
05-10-13 14:25 <REP> ..
3 fichier(s) 7892 octets
26 R‚p(s) 7892541440 octets libres
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\WINDOWS\Tasks
06-04-10 22:12 552 Scheduled scanning task.job
05-10-13 14:14 6 SA.DAT
05-10-13 14:01 65 desktop.ini
05-10-13 14:01 <REP> ..
05-10-13 14:01 <REP> .
3 fichier(s) 623 octets
2 R‚p(s) 7,892,541,440 octets libres
******************************************
Recherche dans Program files
Le dossier C:\Program Files\C2Media n'existe pas
*************** Fin du rapport ****************
Rapport fait à 10:14:12.68 le 06-09-25
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\All Users\Application Data
06-08-18 16:43 <REP> BOONTY
06-08-18 16:41 <REP> Macrovision
06-08-15 12:08 <REP> Yahoo!
06-05-13 15:31 <REP> Messenger Plus!
06-04-10 21:14 <REP> F-Secure
06-01-17 16:42 <REP> PlayFirst
06-01-17 16:42 <REP> Zylom
05-12-15 22:52 <REP> Adobe
05-11-08 10:02 <REP> MSN Search Toolbar
05-10-15 16:15 <REP> QuickTime
05-10-14 18:36 <REP> Hewlett-Packard
05-10-14 18:21 3061 hpzinstall.log
05-10-13 14:44 <REP> Windows Genuine Advantage
05-10-13 14:27 62 desktop.ini
05-10-13 14:26 <REP> Microsoft
05-10-13 14:26 <REP> .
05-10-13 14:26 <REP> ..
2 fichier(s) 3123 octets
15 R‚p(s) 7892619264 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Default User\Application Data
05-10-13 14:27 62 desktop.ini
05-10-13 14:26 <REP> ..
05-10-13 14:26 <REP> Microsoft
05-10-13 14:26 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Invit‚\Application Data
06-08-13 12:13 <REP> ispnews
06-08-13 12:11 <REP> Identities
06-08-13 12:11 62 desktop.ini
06-08-13 12:11 <REP> ..
06-08-13 12:11 <REP> Microsoft
06-08-13 12:11 <REP> .
1 fichier(s) 62 octets
5 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Jeremy\Application Data
06-07-16 20:31 <REP> Media Player Classic
06-07-15 13:03 <REP> Winamp
06-04-10 23:33 <REP> F-Secure
06-04-10 23:29 <REP> ispnews
06-03-28 23:35 <REP> AdobeUM
06-03-28 23:34 <REP> Leadertech
06-03-21 01:20 <REP> Help
06-02-19 17:10 <REP> Adobe
06-02-13 20:29 <REP> Sun
06-02-13 19:59 <REP> Macromedia
06-02-13 19:56 <REP> MSN Search Toolbar
06-02-13 19:54 <REP> Mozilla
06-02-13 19:53 <REP> Identities
06-02-13 19:52 62 desktop.ini
06-02-13 19:52 <REP> ..
06-02-13 19:52 <REP> .
06-02-13 19:52 <REP> Microsoft
1 fichier(s) 62 octets
16 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\TOTOF\Application Data
06-08-04 13:53 92368 errorsafescannerinstall_fr[1].exe
06-05-22 13:30 <REP> Real
06-05-04 12:39 <REP> F-Secure
06-04-15 13:04 <REP> ispnews
06-04-01 14:47 <REP> Help
06-01-25 22:35 <REP> AdobeUM
06-01-17 16:42 <REP> PlayFirst
06-01-17 16:42 <REP> Zylom
06-01-17 16:41 <REP> Zylom Games
05-12-18 18:42 <REP> FUJIFILM
05-12-18 18:38 <REP> Leadertech
05-12-05 23:57 <REP> Adobe
05-11-11 19:26 <REP> Media Player Classic
05-11-08 12:21 <REP> MSN Search Toolbar
05-10-26 11:42 <REP> Mozilla
05-10-21 21:34 <REP> Sun
05-10-21 21:28 <REP> Macromedia
05-10-21 21:15 <REP> Identities
05-10-21 21:15 62 desktop.ini
05-10-21 21:15 <REP> ..
05-10-21 21:15 <REP> .
05-10-21 21:15 <REP> Microsoft
2 fichier(s) 92430 octets
20 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Utilisateur1\Application Data
06-08-15 11:03 <REP> WMA ITCH
06-08-15 11:03 <REP> Browsesignseek
06-08-13 14:51 7747 GdiplusUpgrade_MSIApproach_Wrapper.log
06-04-10 22:11 <REP> PEX
06-04-10 21:34 <REP> F-Secure
06-04-10 21:22 <REP> ispnews
06-01-08 13:53 <REP> Image Zone Express
06-01-05 21:37 <REP> Media Player Classic
06-01-04 19:45 <REP> Leadertech
05-11-15 21:10 <REP> InterTrust
05-11-03 20:02 <REP> AdobeUM
05-10-29 23:39 <REP> Real
05-10-25 11:03 <REP> Ahead
05-10-24 19:18 <REP> Mozilla
05-10-24 14:41 <REP> Google
05-10-17 20:09 <REP> FUJIFILM
05-10-15 13:15 <REP> Help
05-10-14 22:05 <REP> Sun
05-10-14 19:57 <REP> MSNInstaller
05-10-14 18:07 <REP> FotoWire
05-10-14 15:28 <REP> Macromedia
05-10-14 13:35 <REP> Adobe
05-10-14 12:06 83 sversion.ini
05-10-14 12:01 <REP> vlc
05-10-13 14:25 <REP> Identities
05-10-13 14:25 62 desktop.ini
05-10-13 14:25 <REP> Microsoft
05-10-13 14:25 <REP> .
05-10-13 14:25 <REP> ..
3 fichier(s) 7892 octets
26 R‚p(s) 7892541440 octets libres
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\WINDOWS\Tasks
06-04-10 22:12 552 Scheduled scanning task.job
05-10-13 14:14 6 SA.DAT
05-10-13 14:01 65 desktop.ini
05-10-13 14:01 <REP> ..
05-10-13 14:01 <REP> .
3 fichier(s) 623 octets
2 R‚p(s) 7,892,541,440 octets libres
******************************************
Recherche dans Program files
Le dossier C:\Program Files\C2Media n'existe pas
*************** Fin du rapport ****************
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\All Users\Application Data
06-08-18 16:43 <REP> BOONTY
06-08-18 16:41 <REP> Macrovision
06-08-15 12:08 <REP> Yahoo!
06-05-13 15:31 <REP> Messenger Plus!
06-04-10 21:14 <REP> F-Secure
06-01-17 16:42 <REP> PlayFirst
06-01-17 16:42 <REP> Zylom
05-12-15 22:52 <REP> Adobe
05-11-08 10:02 <REP> MSN Search Toolbar
05-10-15 16:15 <REP> QuickTime
05-10-14 18:36 <REP> Hewlett-Packard
05-10-14 18:21 3061 hpzinstall.log
05-10-13 14:44 <REP> Windows Genuine Advantage
05-10-13 14:27 62 desktop.ini
05-10-13 14:26 <REP> Microsoft
05-10-13 14:26 <REP> .
05-10-13 14:26 <REP> ..
2 fichier(s) 3123 octets
15 R‚p(s) 7892619264 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Default User\Application Data
05-10-13 14:27 62 desktop.ini
05-10-13 14:26 <REP> ..
05-10-13 14:26 <REP> Microsoft
05-10-13 14:26 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Invit‚\Application Data
06-08-13 12:13 <REP> ispnews
06-08-13 12:11 <REP> Identities
06-08-13 12:11 62 desktop.ini
06-08-13 12:11 <REP> ..
06-08-13 12:11 <REP> Microsoft
06-08-13 12:11 <REP> .
1 fichier(s) 62 octets
5 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Jeremy\Application Data
06-07-16 20:31 <REP> Media Player Classic
06-07-15 13:03 <REP> Winamp
06-04-10 23:33 <REP> F-Secure
06-04-10 23:29 <REP> ispnews
06-03-28 23:35 <REP> AdobeUM
06-03-28 23:34 <REP> Leadertech
06-03-21 01:20 <REP> Help
06-02-19 17:10 <REP> Adobe
06-02-13 20:29 <REP> Sun
06-02-13 19:59 <REP> Macromedia
06-02-13 19:56 <REP> MSN Search Toolbar
06-02-13 19:54 <REP> Mozilla
06-02-13 19:53 <REP> Identities
06-02-13 19:52 62 desktop.ini
06-02-13 19:52 <REP> ..
06-02-13 19:52 <REP> .
06-02-13 19:52 <REP> Microsoft
1 fichier(s) 62 octets
16 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\TOTOF\Application Data
06-08-04 13:53 92368 errorsafescannerinstall_fr[1].exe
06-05-22 13:30 <REP> Real
06-05-04 12:39 <REP> F-Secure
06-04-15 13:04 <REP> ispnews
06-04-01 14:47 <REP> Help
06-01-25 22:35 <REP> AdobeUM
06-01-17 16:42 <REP> PlayFirst
06-01-17 16:42 <REP> Zylom
06-01-17 16:41 <REP> Zylom Games
05-12-18 18:42 <REP> FUJIFILM
05-12-18 18:38 <REP> Leadertech
05-12-05 23:57 <REP> Adobe
05-11-11 19:26 <REP> Media Player Classic
05-11-08 12:21 <REP> MSN Search Toolbar
05-10-26 11:42 <REP> Mozilla
05-10-21 21:34 <REP> Sun
05-10-21 21:28 <REP> Macromedia
05-10-21 21:15 <REP> Identities
05-10-21 21:15 62 desktop.ini
05-10-21 21:15 <REP> ..
05-10-21 21:15 <REP> .
05-10-21 21:15 <REP> Microsoft
2 fichier(s) 92430 octets
20 R‚p(s) 7892541440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\Documents and Settings\Utilisateur1\Application Data
06-08-15 11:03 <REP> WMA ITCH
06-08-15 11:03 <REP> Browsesignseek
06-08-13 14:51 7747 GdiplusUpgrade_MSIApproach_Wrapper.log
06-04-10 22:11 <REP> PEX
06-04-10 21:34 <REP> F-Secure
06-04-10 21:22 <REP> ispnews
06-01-08 13:53 <REP> Image Zone Express
06-01-05 21:37 <REP> Media Player Classic
06-01-04 19:45 <REP> Leadertech
05-11-15 21:10 <REP> InterTrust
05-11-03 20:02 <REP> AdobeUM
05-10-29 23:39 <REP> Real
05-10-25 11:03 <REP> Ahead
05-10-24 19:18 <REP> Mozilla
05-10-24 14:41 <REP> Google
05-10-17 20:09 <REP> FUJIFILM
05-10-15 13:15 <REP> Help
05-10-14 22:05 <REP> Sun
05-10-14 19:57 <REP> MSNInstaller
05-10-14 18:07 <REP> FotoWire
05-10-14 15:28 <REP> Macromedia
05-10-14 13:35 <REP> Adobe
05-10-14 12:06 83 sversion.ini
05-10-14 12:01 <REP> vlc
05-10-13 14:25 <REP> Identities
05-10-13 14:25 62 desktop.ini
05-10-13 14:25 <REP> Microsoft
05-10-13 14:25 <REP> .
05-10-13 14:25 <REP> ..
3 fichier(s) 7892 octets
26 R‚p(s) 7892541440 octets libres
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D412-F18F
R‚pertoire de C:\WINDOWS\Tasks
06-04-10 22:12 552 Scheduled scanning task.job
05-10-13 14:14 6 SA.DAT
05-10-13 14:01 65 desktop.ini
05-10-13 14:01 <REP> ..
05-10-13 14:01 <REP> .
3 fichier(s) 623 octets
2 R‚p(s) 7,892,541,440 octets libres
******************************************
Recherche dans Program files
Le dossier C:\Program Files\C2Media n'existe pas
*************** Fin du rapport ****************
J'ai bien efface tous fichiers que tu m as dit mais maintenant les jeux que j'avais: dossier boonty sont effaces......
Salut,
clic sur demarrer, tous les programmes, accessoires, outils système, restauration du système et choisis un point pas trop loin dans le temps.
Si tes dossiers sont dans la corbeille restaure les(boonty)
clic sur demarrer, tous les programmes, accessoires, outils système, restauration du système et choisis un point pas trop loin dans le temps.
Si tes dossiers sont dans la corbeille restaure les(boonty)
Tant pis c est bien fait pour moi. J'aurai du faire une disquette de sauvegarde. Tous mon dossier jeux BOONTY est supprime. Jespere que cela a servi a quelque chose.
Oui mais impossible de reprendre ces fichiers. Ce n'est pas trops grave. J'espere que je pourrais toujours les telecharger ulterieurement. As tu trouve solution a mon probleme ?? Amities MICHEL
Salut,
ok, donc essaye ça
Télécharge SmitfraudFix (enregistre le sur le "bureau")
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
décompresse SmitfraudFix
Lance le fichier SmitfraudFix ou SmitfraudFix.cmd et choisis l option 1 copie le rapport ici stp
Puis
Telecharge, installe puis mets à jour ce logiciel(Ewido), une fois que c'est fait, fais un scan complet de ton système, supprime (delete) tout ce qu'il te trouve puis colle le rapport ici avec un nouveau rapport hijackthis
Ewido: (reste gratuit après la période d'essai)
Télécharger Ewido Security Suite
A+++
ok, donc essaye ça
Télécharge SmitfraudFix (enregistre le sur le "bureau")
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
décompresse SmitfraudFix
Lance le fichier SmitfraudFix ou SmitfraudFix.cmd et choisis l option 1 copie le rapport ici stp
Puis
Telecharge, installe puis mets à jour ce logiciel(Ewido), une fois que c'est fait, fais un scan complet de ton système, supprime (delete) tout ce qu'il te trouve puis colle le rapport ici avec un nouveau rapport hijackthis
Ewido: (reste gratuit après la période d'essai)
Télécharger Ewido Security Suite
A+++
@ECHO OFF
REM Smitfraud Fix by S!Ri
REM http://siri.urz.free.fr/Fix/SmitfraudFix.zip
REM Thanks, Help: atribune, balltrap34, Beamerke, derek, Grinler, ipl_001, LonnyRJones, MAD,
REM Malekal_morte, Marckie, moe31, ~Mark, Ruby, Roel, Sebdraluorg,
REM tirol, TonyKlein, Vazkor,
REM and all the ones I forgot who submit files, analyses, help users...
REM Miekiemoes' Shudder key fix added.
REM Process.exe by Craig.Peacock added (https://www.beyondlogic.org/)
REM Reboot.exe by Shadowar/Option^Explicit added.
REM swreg.exe by SteelWerx (https://fstaal01.home.xs4all.nl/commandline-us.html)
REM swsc.exe by SteelWerx (https://fstaal01.home.xs4all.nl/commandline-us.html)
REM restart.exe - SuperFast Shutdown (http://www.xp-smoker.com/freeware.html)
REM dumphive.exe - Markus Stephany (http://www.mirkes.de)
REM unzip.exe - info-zip (http://infozip.sourceforge.net/)
REM SmiUpdate.exe - Sebdraluorg
set fixname=SmitFraudFix
set fixvers=v2.100
VER|find "Windows 95">NUL
IF NOT ERRORLEVEL 1 GOTO Win
VER|find "Windows 98">NUL
IF NOT ERRORLEVEL 1 GOTO Win
VER|find "Windows Millennium">NUL
IF NOT ERRORLEVEL 1 GOTO Win
VER|find "Windows XP">NUL
IF NOT ERRORLEVEL 1 GOTO NT
VER|find "Windows 2000">NUL
IF NOT ERRORLEVEL 1 GOTO NT
VER|find "Version 5.2.3790">NUL
IF NOT ERRORLEVEL 1 GOTO NT
if %OS%==Windows_NT goto NT
color 47
echo %fixname% %fixvers%
echo.
echo Version non support^‚e.
echo Windows 2000 / XP requis !
echo.
echo Unsupported Version.
echo Windows 2000 / XP required !
echo.
pause
goto exit
:Win
color 47
echo %fixname% %fixvers%
echo.
echo Version non support^‚e.
echo Windows 2000 / XP requis !
echo.
echo Unsupported Version.
echo Windows 2000 / XP required !
echo.
pause
goto exit
:NT
set DoReboot=0
set DoRestart=0
set syspath=%windir%\system32
echo Option Explicit>GetPaths.vbs
echo.>>GetPaths.vbs
echo Dim Shell>>GetPaths.vbs
echo Dim KeyPath>>GetPaths.vbs
echo Dim ObjFileSystem>>GetPaths.vbs
echo Dim ObjOutputFile>>GetPaths.vbs
echo Dim ObjRegExp>>GetPaths.vbs
echo Dim File>>GetPaths.vbs
echo Dim TmpVar>>GetPaths.vbs
echo Dim Var>>GetPaths.vbs
echo Dim Accent>>GetPaths.vbs
echo.>>GetPaths.vbs
echo KeyPath = "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\">>GetPaths.vbs
echo File = "SetPaths.bat">>GetPaths.vbs
echo.>>GetPaths.vbs
echo Set Shell = WScript.CreateObject("WScript.Shell")>>GetPaths.vbs
echo Set ObjFileSystem = CreateObject("Scripting.fileSystemObject")>>GetPaths.vbs
echo Set ObjOutputFile = ObjFileSystem.CreateTextFile(File, TRUE)>>GetPaths.vbs
echo Set ObjRegExp = New RegExp>>GetPaths.vbs
echo.>>GetPaths.vbs
echo Function ShortFileName(Path)>>GetPaths.vbs
echo Dim f>>GetPaths.vbs
echo Set f = ObjFileSystem.GetFolder(Path)>>GetPaths.vbs
echo ShortFileName = f.ShortPath>>GetPaths.vbs
echo End Function>>GetPaths.vbs
echo Function Accents(Str)>>GetPaths.vbs
echo ObjRegExp.Pattern = "[^a-zA-Z_0-9\\: ]">>GetPaths.vbs
echo ObjRegExp.IgnoreCase = True>>GetPaths.vbs
echo ObjRegExp.Global = True>>GetPaths.vbs
echo Accents = ObjRegExp.Replace(Str, "?")>>GetPaths.vbs
echo End Function>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Desktop")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set desktop=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Favorites")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set favorites=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Programs")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set startprg=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Start Menu")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set startm=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Startup")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set startup=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo KeyPath = "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\">>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Common Desktop")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set audesktop=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Common Favorites")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set aufavorites=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Common Programs")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set austartprg=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Common Start Menu")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set austartm=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Common Startup")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set austartup=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo ObjOutputFile.Close>>GetPaths.vbs
echo Set objFileSystem = Nothing>>GetPaths.vbs
echo Set Shell = Nothing>>GetPaths.vbs
echo Set ObjRegExp = nothing>>GetPaths.vbs
echo.>>GetPaths.vbs
cscript //I //nologo GetPaths.vbs
del GetPaths.vbs
Call SetPaths.bat
del SetPaths.bat
if exist "%userprofile%\Bureau" (
set lang=fra
) else (
set lang=int
)
goto test
:test
if not exist Process.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier Process.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo Process.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist swreg.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier swreg.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo swreg.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist swsc.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier swsc.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo swsc.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist SrchSTS.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier SrchSTS.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo SrchSTS.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist Reboot.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier Reboot.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo Reboot.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist restart.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier restart.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo restart.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist GenericRenosFix.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier GenericRenosFix.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo GenericRenosFix.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist dumphive.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier dumphive.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo dumphive.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist unzip.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier unzip.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo unzip.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist SmiUpdate.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier SmiUpdate.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo SmiUpdate.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if exist Update.cmd del Update.cmd
if not exist %syspath%\Process.exe copy Process.exe %syspath% >NUL
if not exist %syspath%\swreg.exe copy swreg.exe %syspath% >NUL
if not exist %syspath%\swsc.exe copy swsc.exe %syspath% >NUL
if not exist %syspath%\SrchSTS.exe copy SrchSTS.exe %syspath% >NUL
goto notice
:notice
color 17
cls
if %lang%==fra (
echo.
echo.
echo.
echo.
echo.
echo.
echo.
echo.
echo joedanger n'est pas affili^‚ avec SmitfraudFix!
echo.
echo Cet outil a ^‚t^‚ cr^‚^‚ par S!Ri pour une utilisation GRATUITE.
echo Des dons seront accept^‚es par S!Ri, uniquement sur son site Web principal
echo N'importe qui d'autre qui essaie d'en tirer profit
echo ou qui solicite de l'argent est impliqu^‚ dans une fraude.
echo.
echo.
echo Appuyez sur une touche pour continuer...
echo.
) else (
echo.
echo.
echo.
echo.
echo.
echo.
echo.
echo.
echo joedanger is NOT involved with Smitfraudfix in any way!
echo.
echo This tool was created by S!Ri, and is available for FREE.
echo Voluntary donations will be accepted by S!Ri, at his main website only.
echo Anyone, other than the creator, trying to make a profit
echo or solicit money from its use would be involved in fraudulent activity.
echo.
echo.
echo Press a key to continue...
echo.
)
pause>NUL
goto menu
:menu
color 17
cls
if %lang%==fra (
set sChoice=Entrez votre choix
set sScanDate=Rapport fait à
set sRunFrom=Executé à partir de
set SafeMWarn=Fix executé en mode normal
set SafeMDisp=Fix executé en mode sans echec
set sSearch=Recherche
set sFound=PRESENT !
set sDel=supprimé
set sInfect=infecté !
set sInfect2=infect^‚ !
set pe386Mess=pe386 détecté, utilisez un scanner de Rootkit
set lzx32Mess=lzx32 détecté, utilisez un scanner de Rootkit
set msguardMess=msguard détecté, utilisez un scanner de Rootkit
set sWiniSearch=Recherche wininet.dll de remplacement
set sEnd=Fin
set sProcess=Arret des processus
set sError=Problème suppression
set sTempFolder=Suppression Fichiers Temporaires
set sRegCleanQ=Voulez-vous nettoyer le registre ? ^(o/n^)
set sRegClean=Nettoyage du registre
set sWininetQ=Corriger le fichier infect^‚ ? ^(o/n^)
set sTrustQ=R^‚initialiser la liste des sites de confiance et sensibles ? ^(o/n^)
set sTrustBackUp=Copie de sauvegarde
set sTrustDone=Sites de confiance et sensibles effac^‚s.
set sTrustError=*** Erreur : zone.reg non trouv^‚ ***
echo.
echo.
echo %fixname% %fixvers%
echo.
echo.
echo.
echo 1. Recherche
echo 2. Nettoyage ^( mode sans echec recommand^‚ ^)
echo 3. Effacer les sites de confiance et sensibles
echo 4. V^‚rifier les Mises ^… jour
echo L. Langue Anglaise
echo Q. Quitter
echo.
echo.
echo Fermez tous les programmes
echo un red^‚marrage peut-^ˆtre n^‚cessaire
echo.
echo.
echo.
) else (
set sChoice=Enter your choice
set sScanDate=Scan done at
set sRunFrom=Run from
set SafeMWarn=Fix ran in normal mode
set SafeMDisp=Fix ran in safe mode
set sSearch=Scanning
set sFound=FOUND !
set sDel=Deleted
set sInfect=infected !
set sInfect2=infected !
set pe386Mess=pe386 detected, use a Rootkit scanner
set lzx32Mess=lzx32 detected, use a Rootkit scanner
set msguardMess=msguard detected, use a Rootkit scanner
set sWiniSearch=Scanning wininet.dll backup
set sEnd=End
set sProcess=Killing process
set sError=Problem while deleting
set sTempFolder=Deleting Temp Files
set sRegCleanQ=Do you want to clean the registry ? ^(y/n^)
set sRegClean=Registry Cleaning
set sWininetQ=Replace infected file ? ^(y/n^)
set sTrustQ=Restore Trusted Zone ? ^(y/n^)
set sTrustBackUp=Saving BackUp
set sTrustDone=Trusted Zone deleted.
set sTrustError=*** Error : zone.reg not found ***
echo.
echo.
echo %fixname% %fixvers%
echo.
echo.
echo.
echo 1. Search
echo 2. Clean ^(safe mode recommended^)
echo 3. Delete Trusted zone
echo 4. Check for updates
echo L. French Language
echo Q. Quit
echo.
echo.
echo Close all applications
echo Computer may reboot
echo.
echo.
echo.
)
set ChoixMenu=''
set /p ChoixMenu=%sChoice% (1,2,3,4,L,Q) :
if '%ChoixMenu%'=='l' GOTO SwappL
if '%ChoixMenu%'=='L' GOTO SwappL
if '%ChoixMenu%'=='q' GOTO exit
if '%ChoixMenu%'=='Q' GOTO exit
if '%ChoixMenu%'=='1' GOTO search
if '%ChoixMenu%'=='2' GOTO fix
if '%ChoixMenu%'=='3' GOTO zonefix
if '%ChoixMenu%'=='4' GOTO update
goto menu
:SwappL
if '%lang%'=='fra' (
set lang=int
) else (
set lang=fra
)
goto notice
:search
cls
echo %fixname% %fixvers%
echo %fixname% %fixvers%>%systemdrive%\rapport.txt
echo.
echo.>>%systemdrive%\rapport.txt
echo %sScanDate% %time%, %date%>>%systemdrive%\rapport.txt
for /f "Tokens=*" %%i in ('cd') do set CurDir=%%i
echo %sRunFrom% %CurDir%>>%systemdrive%\rapport.txt
IF ERRORLEVEL 1 (
echo %sRunFrom% >>%systemdrive%\rapport.txt
cd >>%systemdrive%\rapport.txt
)
for /f "Tokens=*" %%i in ('ver') do set Version=%%i
echo OS: %Version% - %OS%>>%systemdrive%\rapport.txt
if not defined safeboot_option echo %SafeMWarn%>>%systemdrive%\rapport.txt
if defined safeboot_option echo %SafeMDisp%>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
echo %sSearch% %HOMEDRIVE%\...
echo »»»»»»»»»»»»»»»»»»»»»»»» %HOMEDRIVE%\>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
pushd %HOMEDRIVE%\
if exist bsw.exe (echo %HOMEDRIVE%\bsw.exe %sFound%>>%systemdrive%\rapport.txt)
if exist contextplus.exe (echo %HOMEDRIVE%\contextplus.exe %sFound%>>%systemdrive%\rapport.txt)
if exist country.exe (echo %HOMEDRIVE%\country.exe %sFound%>>%systemdrive%\rapport.txt)
if exist defender??.exe (echo %HOMEDRIVE%\defender??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dfndr.exe (echo %HOMEDRIVE%\dfndr.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dfndra.exe (echo %HOMEDRIVE%\dfndra.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dfndr?_?.exe (echo %HOMEDRIVE%\dfndr?_?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload?.exe (echo %HOMEDRIVE%\drsmartload?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload??.exe (echo %HOMEDRIVE%\drsmartload??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload???.exe (echo %HOMEDRIVE%\drsmartload???.exe %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload????.exe (echo %HOMEDRIVE%\drsmartload????.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ecsiin.stub.exe (echo %HOMEDRIVE%\ecsiin.stub.exe %sFound%>>%systemdrive%\rapport.txt)
if exist exit (echo %HOMEDRIVE%\exit %sFound%>>%systemdrive%\rapport.txt)
if exist gimmysmileys.exe (echo %HOMEDRIVE%\gimmysmileys.exe %sFound%>>%systemdrive%\rapport.txt)
if exist gimmysmileys?.exe (echo %HOMEDRIVE%\gimmysmileys?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard.exe (echo %HOMEDRIVE%\keyboard.exe %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard?.exe (echo %HOMEDRIVE%\keyboard?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard??.exe (echo %HOMEDRIVE%\keyboard??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kl1.exe (echo %HOMEDRIVE%\kl1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kybrd.exe (echo %HOMEDRIVE%\kybrd.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kybrd_?.exe (echo %HOMEDRIVE%\kybrd_?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kybrd?_?.exe (echo %HOMEDRIVE%\kybrd?_?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist loader.exe (echo %HOMEDRIVE%\loader.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mousepad.exe (echo %HOMEDRIVE%\mousepad.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mousepad?.exe (echo %HOMEDRIVE%\mousepad?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mousepad??.exe (echo %HOMEDRIVE%\mousepad??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist MTE3NDI6ODoxNg.exe (echo %HOMEDRIVE%\MTE3NDI6ODoxNg.exe %sFound%>>%systemdrive%\rapport.txt)
if exist nwnm.exe (echo %HOMEDRIVE%\nwnm.exe %sFound%>>%systemdrive%\rapport.txt)
if exist nwnm_?.exe (echo %HOMEDRIVE%\nwnm_?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist nwnm?_?.exe (echo %HOMEDRIVE%\nwnm?_?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist newname?.exe (echo %HOMEDRIVE%\newname?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist newname??.exe (echo %HOMEDRIVE%\newname??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ntdetecd.exe (echo %HOMEDRIVE%\ntdetecd.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ntps.exe (echo %HOMEDRIVE%\ntps.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ntnc.exe (echo %HOMEDRIVE%\ntnc.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ms1.exe (echo %HOMEDRIVE%\ms1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist r.exe (echo %HOMEDRIVE%\r.exe %sFound%>>%systemdrive%\rapport.txt)
if exist secure32.html (echo %HOMEDRIVE%\secure32.html %sFound%>>%systemdrive%\rapport.txt)
if exist stub_113_4_0_4_0.exe (echo %HOMEDRIVE%\stub_113_4_0_4_0.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool1.exe (echo %HOMEDRIVE%\tool1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool2.exe (echo %HOMEDRIVE%\tool2.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool3.exe (echo %HOMEDRIVE%\tool3.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool4.exe (echo %HOMEDRIVE%\tool4.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool5.exe (echo %HOMEDRIVE%\tool5.exe %sFound%>>%systemdrive%\rapport.txt)
if exist toolbar.exe (echo %HOMEDRIVE%\toolbar.exe %sFound%>>%systemdrive%\rapport.txt)
if exist uniq (echo %HOMEDRIVE%\uniq %sFound%>>%systemdrive%\rapport.txt)
if exist winstall.exe (echo %HOMEDRIVE%\winstall.exe %sFound%>>%systemdrive%\rapport.txt)
if exist wp.bmp (echo %HOMEDRIVE%\wp.bmp %sFound%>>%systemdrive%\rapport.txt)
if exist wp.exe (echo %HOMEDRIVE%\wp.exe %sFound%>>%systemdrive%\rapport.txt)
if exist xxx.exe (echo %HOMEDRIVE%\xxx.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "%HOMEDRIVE%\spywarevanisher-free" echo %HOMEDRIVE%\spywarevanisher-free\ %sFound%>>%systemdrive%\rapport.txt
popd
echo.>>%systemdrive%\rapport.txt
echo %sSearch% %windir%\...
echo »»»»»»»»»»»»»»»»»»»»»»»» %windir%>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
pushd %windir%
if exist ".protected" (echo %windir%\.protected %sFound%>>%systemdrive%\rapport.txt)
if exist aapfr.exe (echo %windir%\aapfr.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ads.js (echo %windir%\ads.js %sFound%>>%systemdrive%\rapport.txt)
if exist adsldpbc.dll (echo %windir%\adsldpbc.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adsldpbd.dll (echo %windir%\adsldpbd.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adsldpbe.dll (echo %windir%\adsldpbe.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adsldpbf.dll (echo %windir%\adsldpbf.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adsldpbj.dll (echo %windir%\adsldpbj.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adtech2005.exe (echo %windir%\adtech2005.exe %sFound%>>%systemdrive%\rapport.txt)
if exist adtech2006a.exe (echo %windir%\adtech2006a.exe %sFound%>>%systemdrive%\rapport.txt)
if exist adw.htm (echo %windir%\adw.htm %sFound%>>%systemdrive%\rapport.txt)
if exist "adware-sheriff-box.gif" (echo %windir%\adware-sheriff-box.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "adware-sheriff-header.gif" (echo %windir%\adware-sheriff-header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist alexaie.dll (echo %windir%\alexaie.dll %sFound%>>%systemdrive%\rapport.txt)
if exist alxie328.dll (echo %windir%\alxie328.dll %sFound%>>%systemdrive%\rapport.txt)
if exist alxtb1.dll (echo %windir%\alxtb1.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "antispylab-logo.gif" (echo %windir%\antispylab-logo.gif %sFound%>>%systemdrive%\rapport.txt)
if exist about_spyware_bg.gif (echo %windir%\about_spyware_bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist about_spyware_bottom.gif (echo %windir%\about_spyware_bottom.gif %sFound%>>%systemdrive%\rapport.txt)
if exist as.gif (echo %windir%\as.gif %sFound%>>%systemdrive%\rapport.txt)
if exist as_header.gif (echo %windir%\as_header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist azesearch.bmp (echo %windir%\azesearch.bmp %sFound%>>%systemdrive%\rapport.txt)
if exist back.gif (echo %windir%\back.gif %sFound%>>%systemdrive%\rapport.txt)
if exist batserv2.exe (echo %windir%\batserv2.exe %sFound%>>%systemdrive%\rapport.txt)
if exist bg.gif (echo %windir%\bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist bg_bg.gif (echo %windir%\bg_bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist big_red_x.gif (echo %windir%\big_red_x.gif %sFound%>>%systemdrive%\rapport.txt)
if exist blank.mht (echo %windir%\blank.mht %sFound%>>%systemdrive%\rapport.txt)
if exist "blue-bg.gif" (echo %windir%\blue-bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist box_1.gif (echo %windir%\box_1.gif %sFound%>>%systemdrive%\rapport.txt)
if exist box_2.gif (echo %windir%\box_2.gif %sFound%>>%systemdrive%\rapport.txt)
if exist box_3.gif (echo %windir%\box_3.gif %sFound%>>%systemdrive%\rapport.txt)
if exist BTGrab.dll (echo %windir%\BTGrab.dll %sFound%>>%systemdrive%\rapport.txt)
if exist button_buynow.gif (echo %windir%\button_buynow.gif %sFound%>>%systemdrive%\rapport.txt)
if exist button_freescan.gif (echo %windir%\button_freescan.gif %sFound%>>%systemdrive%\rapport.txt)
if exist buy.gif (echo %windir%\buy.gif %sFound%>>%systemdrive%\rapport.txt)
if exist buy_now.gif (echo %windir%\buy_now.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "buy-now-btn.gif" (echo %windir%\buy-now-btn.gif %sFound%>>%systemdrive%\rapport.txt)
if exist bxproxy.exe (echo %windir%\bxproxy.exe %sFound%>>%systemdrive%\rapport.txt)
if exist click_for_free_scan.gif (echo %windir%\click_for_free_scan.gif %sFound%>>%systemdrive%\rapport.txt)
if exist close_ico.gif (echo %windir%\close_ico.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "close-bar.gif" (echo %windir%\close-bar.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "corner-left.gif" (echo %windir%\corner-left.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "corner-right.gif" (echo %windir%\corner-right.gif %sFound%>>%systemdrive%\rapport.txt)
if exist country.exe (echo %windir%\country.exe %sFound%>>%systemdrive%\rapport.txt)
if exist d3dn32.exe (echo %windir%\d3dn32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist d3??.dll (echo %windir%\d3??.dll %sFound%>>%systemdrive%\rapport.txt)
if exist d3pb.exe (echo %windir%\d3pb.exe %sFound%>>%systemdrive%\rapport.txt)
if exist defender??.exe (echo %windir%\defender??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist desktop.html (echo %windir%\desktop.html %sFound%>>%systemdrive%\rapport.txt)
if exist dlmax.dll (echo %windir%\dlmax.dll %sFound%>>%systemdrive%\rapport.txt)
if exist download.gif (echo %windir%\download.gif %sFound%>>%systemdrive%\rapport.txt)
if exist download_box.gif (echo %windir%\download_box.gif %sFound%>>%systemdrive%\rapport.txt)
if exist download_product.gif (echo %windir%\download_product.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "download-btn.gif" (echo %windir%\download-btn.gif %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload.dat (echo %windir%\drsmartload.dat %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload2.dat (echo %windir%\drsmartload2.dat %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload95a.exe (echo %windir%\drsmartload95a.exe %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartloadb1.dat (echo %windir%\drsmartloadb1.dat %sFound%>>%systemdrive%\rapport.txt)
if exist "facts.gif" (echo %windir%\facts.gif %sFound%>>%systemdrive%\rapport.txt)
if exist features.gif (echo %windir%\features.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "footer.gif" (echo %windir%\footer.giff %sFound%>>%systemdrive%\rapport.txt)
if exist footer_back.gif (echo %windir%\footer_back.gif %sFound%>>%systemdrive%\rapport.txt)
if exist footer_back.jpg (echo %windir%\footer_back.jpg %sFound%>>%systemdrive%\rapport.txt)
if exist free_scan_red_btn.gif (echo %windir%\free_scan_red_btn.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "free-scan-btn.gif" (echo %windir%\free-scan-btn.gif %sFound%>>%systemdrive%\rapport.txt)
if exist gimmygames.dat (echo %windir%\gimmygames.dat %sFound%>>%systemdrive%\rapport.txt)
if exist "h-line-gradient.gif" (echo %windir%\h-line-gradient.gif %sFound%>>%systemdrive%\rapport.txt)
if exist header_1.gif (echo %windir%\header_1.gif %sFound%>>%systemdrive%\rapport.txt)
if exist header_2.gif (echo %windir%\header_2.gif %sFound%>>%systemdrive%\rapport.txt)
if exist header_3.gif (echo %windir%\header_3.gif %sFound%>>%systemdrive%\rapport.txt)
if exist header_4.gif (echo %windir%\header_4.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "header-bg.gif" (echo %windir%\header-bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist icon_warning_big.gif (echo %windir%\icon_warning_big.gif %sFound%>>%systemdrive%\rapport.txt)
if exist icont.exe (echo %windir%\icont.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ieyi.dll (echo %windir%\ieyi.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ieyi.exe (echo %windir%\ieyi.exe %sFound%>>%systemdrive%\rapport.txt)
if exist inetloader.dll (echo %windir%\inetloader.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "infected.gif" (echo %windir%\infected.gif %sFound%>>%systemdrive%\rapport.txt)
if exist infected_top_bg.gif (echo %windir%\infected_top_bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "info.gif" (echo %windir%\info.gif %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard.exe (echo %windir%\keyboard.exe %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard?.exe (echo %windir%\keyboard?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard1.dat (echo %windir%\keyboard1.dat %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard??.exe (echo %windir%\keyboard??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kl.exe (echo %windir%\kl.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kl1.exe (echo %windir%\kl1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist loadadv728.exe (echo %windir%\loadadv728.exe %sFound%>>%systemdrive%\rapport.txt)
if exist local.html (echo %windir%\local.html %sFound%>>%systemdrive%\rapport.txt)
if exist logo.gif (echo %windir%\logo.gif %sFound%>>%systemdrive%\rapport.txt)
if exist main_back.gif (echo %windir%\main_back.gif %sFound%>>%systemdrive%\rapport.txt)
if exist mxd.exe (echo %windir%\mxd.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mousepad.exe (echo %windir%\mousepad.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mousepad?.exe (echo %windir%\mousepad?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mousepad??.exe (echo %windir%\mousepad??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist navibar_bg.gif (echo %windir%\navibar_bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist navibar_corner_left.gif (echo %windir%\navibar_corner_left.gif %sFound%>>%systemdrive%\rapport.txt)
if exist navibar_corner_right.gif (echo %windir%\navibar_corner_right.gif %sFound%>>%systemdrive%\rapport.txt)
if exist newname.dat (echo %windir%\newname.dat %sFound%>>%systemdrive%\rapport.txt)
if exist newname?.exe (echo %windir%\newname?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist newname??.exe (echo %windir%\newname??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ms1.exe (echo %windir%\ms1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "no-icon.gif" (echo %windir%\no-icon.gif %sFound%>>%systemdrive%\rapport.txt)
if exist notepad.com (echo %windir%\notepad.com %sFound%>>%systemdrive%\rapport.txt)
if exist onlineshopping.ico (echo %windir%\onlineshopping.ico %sFound%>>%systemdrive%\rapport.txt)
if exist osaupd.exe (echo %windir%\osaupd.exe %sFound%>>%systemdrive%\rapport.txt)
if exist pop06ap2.exe (echo %windir%\pop06ap2.exe %sFound%>>%systemdrive%\rapport.txt)
if exist popuper.exe (echo %windir%\popuper.exe %sFound%>>%systemdrive%\rapport.txt)
if exist processes.txt (echo %windir%\processes.txt %sFound%>>%systemdrive%\rapport.txt)
if exist product_box.gif (echo %windir%\product_box.gif %sFound%>>%systemdrive%\rapport.txt)
if exist psg.exe (echo %windir%\psg.exe %sFound%>>%systemdrive%\rapport.txt)
if exist Pynix.dll (echo %windir%\Pynix.dll %sFound%>>%systemdrive%\rapport.txt)
if exist q*_disk.dll (echo %windir%\q*_disk.dll %sFound%>>%systemdrive%\rapport.txt)
if exist red_warning_ico.gif (echo %windir%\red_warning_ico.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "reg-freeze-box.gif" (echo %windir%\reg-freeze-box.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "reg-freeze-header.gif" (echo %windir%\reg-freeze-header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist remove_spyware_header.gif (echo %windir%\remove_spyware_header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "remove-spyware-btn.gif" (echo %windir%\remove-spyware-btn.gif %sFound%>>%systemdrive%\rapport.txt)
if exist removeadware.ico (echo %windir%\removeadware.ico %sFound%>>%systemdrive%\rapport.txt)
if exist rf.gif (echo %windir%\rf.gif %sFound%>>%systemdrive%\rapport.txt)
if exist rf_header.gif (echo %windir%\rf_header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist rzs.exe (echo %windir%\rzs.exe %sFound%>>%systemdrive%\rapport.txt)
if exist sachostx.exe (echo %windir%\sachostx.exe %sFound%>>%systemdrive%\rapport.txt)
if exist safe_and_trusted.gif (echo %windir%\safe_and_trusted.gif %sFound%>>%systemdrive%\rapport.txt)
if exist scan_btn.gif (echo %windir%\scan_btn.gif %sFound%>>%systemdrive%\rapport.txt)
if exist screen.html (echo %windir%\screen.html %sFound%>>%systemdrive%\rapport.txt)
if exist se_spoof.dll (echo %windir%\se_spoof.dll %sFound%>>%systemdrive%\rapport.txt)
if exist sec.exe (echo %windir%\sec.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "security-center-bg.gif" (echo %windir%\security-center-bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "security-center-logo.gif" (echo %windir%\security-center-logo.gif %sFound%>>%systemdrive%\rapport.txt)
if exist security_center_caption.gif (echo %windir%\security_center_caption.gif %sFound%>>%systemdrive%\rapport.txt)
if exist sep_hor.gif (echo %windir%\sep_hor.gif %sFound%>>%systemdrive%\rapport.txt)
if exist sep_vert.gif (echo %windir%\sep_vert.gif %sFound%>>%systemdrive%\rapport.txt)
if exist sexpersonals.ico (echo %windir%\sexpersonals.ico %sFound%>>%systemdrive%\rapport.txt)
if exist sdkcb.dll (echo %windir%\sdkcb.dll %sFound%>>%systemdrive%\rapport.txt)
if exist sdkqq.exe (echo %windir%\sdkqq.exe %sFound%>>%systemdrive%\rapport.txt)
if exist secure32.html (echo %windir%\secure32.html %sFound%>>%systemdrive%\rapport.txt)
if exist sites.ini (echo %windir%\sites.ini %sFound%>>%systemdrive%\rapport.txt)
if exist slassac.dll (echo %windir%\slassac.dll %sFound%>>%systemdrive%\rapport.txt)
if exist spacer.gif (echo %windir%\spacer.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "spacer.gif'" (echo %windir%\spacer.gif' %sFound%>>%systemdrive%\rapport.txt)
if exist spyware_detected.gif (echo %windir%\spyware_detected.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "spyware-detected.gif" (echo %windir%\spyware-detected.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "spyware-sheriff-header.gif" (echo %windir%\spyware-sheriff-header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "spyware-sheriff-box.gif" (echo %windir%\spyware-sheriff-box.gif %sFound%>>%systemdrive%\rapport.txt)
if exist sss_main.ini (echo %windir%\sss_main.ini %sFound%>>%systemdrive%\rapport.txt)
if exist "star.gif" (echo %windir%\star.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "star-grey.gif" (echo %windir%\star-grey.gif %sFound%>>%systemdrive%\rapport.txt)
if exist star_gray.gif (echo %windir%\star_gray.gif %sFound%>>%systemdrive%\rapport.txt)
if exist star_gray_small.gif (echo %windir%\star_gray_small.gif %sFound%>>%systemdrive%\rapport.txt)
if exist star_small.gif (echo %windir%\star_small.gif %sFound%>>%systemdrive%\rapport.txt)
if exist susp.exe (echo %windir%\susp.exe %sFound%>>%systemdrive%\rapport.txt)
if exist svchost.exe (echo %windir%\svchost.exe %sFound%>>%systemdrive%\rapport.txt)
if exist sysen.exe (echo %windir%\sysen.exe %sFound%>>%systemdrive%\rapport.txt)
if exist sysvx_.exe (echo %windir%\sysvx_.exe %sFound%>>%systemdrive%\rapport.txt)
if exist sysldr32.exe (echo %windir%\sysldr32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist System32fab.exe (echo %windir%\System32fab.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tctool.exe (echo %windir%\tctool.exe %sFound%>>%systemdrive%\rapport.txt)
if exist teller2.chk (echo %windir%\teller2.chk %sFound%>>%systemdrive%\rapport.txt)
if exist temp.000.exe (echo %windir%\temp.000.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ticads.exe (echo %windir%\ticads.exe %sFound%>>%systemdrive%\rapport.txt)
if exist timessquare.exe (echo %windir%\timessquare.exe %sFound%>>%systemdrive%\rapport.txt)
if exist timessquare1.dat (echo %windir%\timessquare1.dat %sFound%>>%systemdrive%\rapport.txt)
if exist tool1.exe (echo %windir%\tool1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool2.exe (echo %windir%\tool2.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool3.exe (echo %windir%\tool3.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool4.exe (echo %windir%\tool4.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool5.exe (echo %windir%\tool5.exe %sFound%>>%systemdrive%\rapport.txt)
if exist toolbar.exe (echo %windir%\toolbar.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tpopup.exe (echo %windir%\tpopup.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "true-stories.gif" (echo %windir%\true-stories.gif %sFound%>>%systemdrive%\rapport.txt)
if exist trustinbar.exe (echo %windir%\trustinbar.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ts.gif (echo %windir%\ts.gif %sFound%>>%systemdrive%\rapport.txt)
if exist ts_header.gif (echo %windir%\ts_header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist tse.exe (echo %windir%\tse.exe %sFound%>>%systemdrive%\rapport.txt)
if exist uninstDsk.exe (echo %windir%\uninstDsk.exe %sFound%>>%systemdrive%\rapport.txt)
if exist uninstIU.exe (echo %windir%\uninstIU.exe %sFound%>>%systemdrive%\rapport.txt)
if exist update13.js (echo %windir%\update13.js %sFound%>>%systemdrive%\rapport.txt)
if exist url.exe (echo %windir%\url.exe %sFound%>>%systemdrive%\rapport.txt)
if exist v.gif (echo %windir%\v.gif %sFound%>>%systemdrive%\rapport.txt)
if exist videoslots.ico (echo %windir%\videoslots.ico %sFound%>>%systemdrive%\rapport.txt)
if exist warnhp.html (echo %windir%\warnhp.html %sFound%>>%systemdrive%\rapport.txt)
if exist warning_icon.gif (echo %windir%\warning_icon.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "warning-bar-ico.gif" (echo %windir%\warning-bar-ico.gif %sFound%>>%systemdrive%\rapport.txt)
if exist win_logo.gif (echo %windir%\win_logo.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "win-sec-center-logo.gif" (echo %windir%\win-sec-center-logo.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "windows-compatible.gif" (echo %windir%\windows-compatible.gif %sFound%>>%systemdrive%\rapport.txt)
if exist winsysupd.exe (echo %windir%\winsysupd.exe %sFound%>>%systemdrive%\rapport.txt)
if exist winsysban.exe (echo %windir%\winsysban.exe %sFound%>>%systemdrive%\rapport.txt)
if exist winsysban8.exe (echo %windir%\winsysban8.exe %sFound%>>%systemdrive%\rapport.txt)
if exist windows.html (echo %windir%\windows.html %sFound%>>%systemdrive%\rapport.txt)
if exist wupdmgr.exe (echo %windir%\wupdmgr.exe %sFound%>>%systemdrive%\rapport.txt)
if exist x.gif (echo %windir%\x.gif %sFound%>>%systemdrive%\rapport.txt)
if exist xpupdate.exe (echo %windir%\xpupdate.exe %sFound%>>%systemdrive%\rapport.txt)
if exist yellow_warning_ico.gif (echo %windir%\yellow_warning_ico.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "yes-icon.gif" (echo %windir%\yes-icon.gif %sFound%>>%systemdrive%\rapport.txt)
if exist zloader3.exe (echo %windir%\zloader3.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ZServ.dll (echo %windir%\ZServ.dll %sFound%>>%systemdrive%\rapport.txt)
if exist __delete_on_reboot__popuper.exe (echo %windir%\__delete_on_reboot__popuper.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "%windir%\muwq" echo %windir%\muwq\ %sFound%>>%systemdrive%\rapport.txt
if exist "%windir%\inet20001" echo %windir%\inet20001\ %sFound%>>%systemdrive%\rapport.txt
if exist "%windir%\inet20010" echo %windir%\inet20010\ %sFound%>>%systemdrive%\rapport.txt
if exist "%windir%\inet20066" echo %windir%\inet20066\ %sFound%>>%systemdrive%\rapport.txt
if exist "%windir%\inet20099" echo %windir%\inet20099\ %sFound%>>%systemdrive%\rapport.txt
popd
echo.>>%systemdrive%\rapport.txt
echo %sSearch% %windir%\system...
echo »»»»»»»»»»»»»»»»»»»»»»»» %windir%\system>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
pushd %windir%\system
if exist csrss.exe (echo %windir%\system\csrss.exe %sFound%>>%systemdrive%\rapport.txt)
if exist eooyt.exe (echo %windir%\system\eooyt.exe %sFound%>>%systemdrive%\rapport.txt)
if exist processes.txt (echo %windir%\system\processes.txt %sFound%>>%systemdrive%\rapport.txt)
if exist svchost.exe (echo %windir%\system\svchost.exe %sFound%>>%systemdrive%\rapport.txt)
if exist svchost.dll (echo %windir%\system\svchost.dll %sFound%>>%systemdrive%\rapport.txt)
if exist svwhost.exe (echo %windir%\system\svwhost.exe %sFound%>>%systemdrive%\rapport.txt)
if exist svwhost.dll (echo %windir%\system\svwhost.dll %sFound%>>%systemdrive%\rapport.txt)
popd
echo.>>%systemdrive%\rapport.txt
echo %sSearch% %windir%\Web...
echo »»»»»»»»»»»»»»»»»»»»»»»» %windir%\Web>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
pushd %windir%\Web
if exist desktop.html (echo %windir%\Web\desktop.html %sFound%>>%systemdrive%\rapport.txt)
if exist wallpaper.html (echo %windir%\Web\wallpaper.html %sFound%>>%systemdrive%\rapport.txt)
popd
echo.>>%systemdrive%\rapport.txt
echo %sSearch% %syspath%...
echo »»»»»»»»»»»»»»»»»»»»»»»» %syspath%>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
pushd %syspath%
if exist ~update.exe (echo %syspath%\~update.exe %sFound%>>%systemdrive%\rapport.txt)
if exist 0mcamcap.exe (echo %syspath%\0mcamcap.exe %sFound%>>%systemdrive%\rapport.txt)
if exist 977efcdb.exe (echo %syspath%\977efcdb.exe %sFound%>>%systemdrive%\rapport.txt)
if exist a.exe (echo %syspath%\a.exe %sFound%>>%systemdrive%\rapport.txt)
if exist acvgxw.dll (echo %syspath%\acvgxw.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adobepnl.dll (echo %syspath%\adobepnl.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "Air Tickets.ico" (echo %syspath%\Air Tickets.ico %sFound%>>%systemdrive%\rapport.txt)
if exist AdService.dll (echo %syspath%\AdService.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adsmart.exe (echo %syspath%\adsmart.exe %sFound%>>%systemdrive%\rapport.txt)
if exist alxres.dll (echo %syspath%\alxres.dll %sFound%>>%systemdrive%\rapport.txt)
if exist appmagr.dll (echo %syspath%\appmagr.dll %sFound%>>%systemdrive%\rapport.txt)
if exist asxbbx.dll (echo %syspath%\asxbbx.dll %sFound%>>%systemdrive%\rapport.txt)
if exist atmclk.exe (echo %syspath%\atmclk.exe %sFound%>>%systemdrive%\rapport.txt)
if exist autodisc32.dll (echo %syspath%\autodisc32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist bhoimpl.dll (echo %syspath%\bhoimpl.dll %sFound%>>%systemdrive%\rapport.txt)
if exist bikini.exe (echo %syspath%\bikini.exe %sFound%>>%systemdrive%\rapport.txt)
if exist bin29a.log (echo %syspath%\bin29a.log %sFound%>>%systemdrive%\rapport.txt)
if exist "Big Tits.ico" (echo %syspath%\Big Tits.ico %sFound%>>%systemdrive%\rapport.txt)
if exist birdihuy.dll (echo %syspath%\birdihuy.dll %sFound%>>%systemdrive%\rapport.txt)
if exist birdihuy32.dll (echo %syspath%\birdihuy32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist Blackjack.ico (echo %syspath%\Blackjack.ico %sFound%>>%systemdrive%\rapport.txt)
if exist bnmsrv.exe (echo %syspath%\bnmsrv.exe %sFound%>>%systemdrive%\rapport.txt)
if exist bolnyz.dll (echo %syspath%\bolnyz.dll %sFound%>>%systemdrive%\rapport.txt)
if exist bre.dll (echo %syspath%\bre.dll %sFound%>>%systemdrive%\rapport.txt)
if exist bre32.dll (echo %syspath%\bre32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist bridge.dll (echo %syspath%\bridge.dll %sFound%>>%systemdrive%\rapport.txt)
if exist bpvcou.dll (echo %syspath%\bpvcou.dll %sFound%>>%systemdrive%\rapport.txt)
if exist browsela.dll (echo %syspath%\browsela.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "Britney Spears.ico" (echo %syspath%\Britney Spears.ico %sFound%>>%systemdrive%\rapport.txt)
if exist bu.exe (echo %syspath%\bu.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "Car Insurance.ico" (echo %syspath%\Car Insurance.ico %sFound%>>%systemdrive%\rapport.txt)
if exist casino.ico (echo %syspath%\casino.ico %sFound%>>%systemdrive%\rapport.txt)
if exist "Cheap Cigarettes.ico" (echo %syspath%\Cheap Cigarettes.ico %sFound%>>%systemdrive%\rapport.txt)
if exist child.dll (echo %syspath%\child.dll %sFound%>>%systemdrive%\rapport.txt)
if exist chp.dll (echo %syspath%\chp.dll %sFound%>>%systemdrive%\rapport.txt)
if exist cmd32.exe (echo %syspath%\cmd32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist cmdtel.exe (echo %syspath%\cmdtel.exe %sFound%>>%systemdrive%\rapport.txt)
if exist cnymxw32.dll (echo %syspath%\cnymxw32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist combo.exe (echo %syspath%\combo.exe %sFound%>>%systemdrive%\rapport.txt)
if exist comdlg64.dll (echo %syspath%\comdlg64.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "Credit Card.ico" (echo %syspath%\Credit Card.ico %sFound%>>%systemdrive%\rapport.txt)
if exist Cruises.ico (echo %syspath%\Cruises.ico %sFound%>>%systemdrive%\rapport.txt)
if exist "Currency Trading.ico" (echo %syspath%\Currency Trading.ico %sFound%>>%systemdrive%\rapport.txt)
if exist cvxh8jkdq?.exe (echo %syspath%\cvxh8jkdq?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist CWS_iestart.exe (echo %syspath%\CWS_iestart.exe %sFound%>>%systemdrive%\rapport.txt)
if exist date.ico (echo %syspath%\date.ico %sFound%>>%systemdrive%\rapport.txt)
if exist dailytoolbar.dll (echo %syspath%\dailytoolbar.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_14.dll (echo %syspath%\dcom_14.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_15.dll (echo %syspath%\dcom_15.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_16.dll (echo %syspath%\dcom_16.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_18.dll (echo %syspath%\dcom_18.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_19.dll (echo %syspath%\dcom_19.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_20.dll (echo %syspath%\dcom_20.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_21.dll (echo %syspath%\dcom_21.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcomcfg.exe (echo %syspath%\dcomcfg.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dial23.exe (echo %syspath%\dial23.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dlh9jkdq?.exe (echo %syspath%\dlh9jkdq?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist doser.exe (echo %syspath%\doser.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dfrgsrv.exe (echo %syspath%\dfrgsrv.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dnefhw.dll (echo %syspath%\dnefhw.dll %sFound%>>%systemdrive%\rapport.txt)
if exist duxzj.dll (echo %syspath%\duxzj.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dvdcap.dll (echo %syspath%\dvdcap.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dxole32.exe (echo %syspath%\dxole32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dxmpp.dll (echo %syspath%\dxmpp.dll %sFound%>>%systemdrive%\rapport.txt)
if exist efsdfgxg.exe (echo %syspath%\efsdfgxg.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ekvrlfzz.exe (echo %syspath%\ekvrlfzz.exe %sFound%>>%systemdrive%\rapport.txt)
if exist eowygj.dll (echo %syspath%\eowygj.dll %sFound%>>%systemdrive%\rapport.txt)
if exist erxbx.dll (echo %syspath%\erxbx.dll %sFound%>>%systemdrive%\rapport.txt)
if exist exa32.exe (echo %syspath%\exa32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist exeha2.exe (echo %syspath%\exeha2.exe %sFound%>>%systemdrive%\rapport.txt)
if exist exeha3.exe (echo %syspath%\exeha3.exe %sFound%>>%systemdrive%\rapport.txt)
if exist exuc32.tmp (echo %syspath%\exuc32.tmp %sFound%>>%systemdrive%\rapport.txt)
if exist fhmfes.dll (echo %syspath%\fhmfes.dll %sFound%>>%systemdrive%\rapport.txt)
if exist fjdcy.dll (echo %syspath%\fjdcy.dll %sFound%>>%systemdrive%\rapport.txt)
if exist fyhhxw.dll (echo %syspath%\fyhhxw.dll %sFound%>>%systemdrive%\rapport.txt)
if exist games.ico (echo %syspath%\games.ico %sFound%>>%systemdrive%\rapport.txt)
if exist ginuerep.dll (echo %syspath%\ginuerep.dll %sFound%>>%systemdrive%\rapport.txt)
if exist gtpbx.dll (echo %syspath%\gtpbx.dll %sFound%>>%systemdrive%\rapport.txt)
if exist gunist.exe (echo %syspath%\gunist.exe %sFound%>>%systemdrive%\rapport.txt)
if exist guxxa.dll (echo %syspath%\guxxa.dll %sFound%>>%systemdrive%\rapport.txt)
if exist helper.exe (echo %syspath%\helper.exe %sFound%>>%systemdrive%\rapport.txt)
if exist higjxe.dll (echo %syspath%\higjxe.dll %sFound%>>%systemdrive%\rapport.txt)
if exist hhk.dll (echo %syspath%\hhk.dll %sFound%>>%systemdrive%\rapport.txt)
if exist hookdump.exe (echo %syspath%\hookdump.exe %sFound%>>%systemdrive%\rapport.txt)
if exist hp???.tmp (echo %syspath%\hp???.tmp %sFound%>>%systemdrive%\rapport.txt)
if exist hp????.tmp (echo %syspath%\hp????.tmp %sFound%>>%systemdrive%\rapport.txt)
if exist htey.dll (echo %syspath%\htey.dll %sFound%>>%systemdrive%\rapport.txt)
if exist hvcycg.dll (echo %syspath%\hvcycg.dll %sFound%>>%systemdrive%\rapport.txt)
if exist hvnwm.dll (echo %syspath%\hvnwm.dll %sFound%>>%systemdrive%\rapport.txt)
if exist hzclqhc.dll (echo %syspath%\hzclqhc.dll %sFound%>>%systemdrive%\rapport.txt)
if exist icima.dll (echo %syspath%\icima.dll %sFound%>>%systemdrive%\rapport.txt)
if exist IeHelperEx.dll (echo %syspath%\IeHelperEx.dll %sFound%>>%systemdrive%\rapport.txt)
if exist imfdfcj.dll (echo %syspath%\imfdfcj.dll %sFound%>>%systemdrive%\rapport.txt)
if exist intel32.exe (echo %syspath%\intel32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist intell321.exe (echo %syspath%\intell321.exe %sFound%>>%systemdrive%\rapport.txt)
if exist intell32.exe (echo %syspath%\intell32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist interf.tlb (echo %syspath%\interf.tlb %sFound%>>%systemdrive%\rapport.txt)
if exist intmon.exe (echo %syspath%\intmon.exe %sFound%>>%systemdrive%\rapport.txt)
if exist intmonp.exe (echo %syspath%\intmonp.exe %sFound%>>%systemdrive%\rapport.txt)
if exist intxt.exe (echo %syspath%\intxt.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ioctrl.dll (echo %syspath%\ioctrl.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ipztub.dll (echo %syspath%\ipztub.dll %sFound%>>%systemdrive%\rapport.txt)
if exist iqzv.dll (echo %syspath%\iqzv.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ishost.exe (echo %syspath%\ishost.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ismini.exe (echo %syspath%\ismini.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ismon.exe (echo %syspath%\ismon.exe %sFound%>>%systemdrive%\rapport.txt)
if exist isnotify.exe (echo %syspath%\isnotify.exe %sFound%>>%systemdrive%\rapport.txt)
if exist issearch.exe (echo %syspath%\issearch.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ixt?.dll (echo %syspath%\ixt?.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ixt??.dll (echo %syspath%\ixt??.dll %sFound%>>%systemdrive%\rapport.txt)
if exist jao.dll (echo %syspath%\jao.dll %sFound%>>%systemdrive%\rapport.txt)
if exist jevtxpg.dll (echo %syspath%\jevtxpg.dll %sFound%>>%systemdrive%\rapport.txt)
if exist jpqet.dll (echo %syspath%\jpqet.dll %sFound%>>%systemdrive%\rapport.txt)
if exist kernels8.exe (echo %syspath%\kernels8.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kernels32.exe (echo %syspath%\kernels32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kernels64.exe (echo %syspath%\kernels64.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kfhrvq.dll (echo %syspath%\kfhrvq.dll %sFound%>>%systemdrive%\rapport.txt)
if exist kkqfb.dll (echo %syspath%\kkqfb.dll %sFound%>>%systemdrive%\rapport.txt)
if exist latest.exe (echo %syspath%\latest.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "Lesbian Sex.ico" (echo %syspath%\Lesbian Sex.ico %sFound%>>%systemdrive%\rapport.txt)
if exist ld???.tmp (echo %syspath%\ld???.tmp %sFound%>>%systemdrive%\rapport.txt)
if exist ld????.tmp (echo %syspath%\ld????.tmp %sFound%>>%systemdrive%\rapport.txt)
if exist lich.exe (echo %syspath%\lich.exe %sFound%>>%systemdrive%\rapport.txt)
if exist links.exe (echo %syspath%\links.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ll.exe (echo %syspath%\ll.exe %sFound%>>%systemdrive%\rapport.txt)
if exist lwpfwjb.dll (echo %syspath%\lwpfwjb.dll %sFound%>>%systemdrive%\rapport.txt)
if exist main.exe (echo %syspath%\main.exe %sFound%>>%systemdrive%\rapport.txt)
if exist maxd1.exe (echo %syspath%\maxd1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist maxd64.exe (echo %syspath%\maxd64.exe %sFound%>>%systemdrive%\rapport.txt)
if exist migicons.exe (echo %syspath%\migicons.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mirarsearch_toolbar.exe (echo %syspath%\mirarsearch_toolbar.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mobile.ico (echo %syspath%\mobile.ico %sFound%>>%systemdrive%\rapport.txt)
if exist MP3.ico (echo %syspath%\MP3.ico %sFound%>>%systemdrive%\rapport.txt)
if exist msbe.dll (echo %syspath%\msbe.dll %sFound%>>%systemdrive%\rapport.txt)
if exist mscornet.exe (echo %syspath%\mscornet.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mshtml32.tdb (echo %syspath%\mshtml32.tdb %sFound%>>%systemdrive%\rapport.txt)
if exist mssearchnet.exe (echo %syspath%\mssearchnet.exe %sFound%>>%systemdrive%\rapport.txt)
if exist msmsgs.exe (echo %syspath%\msmsgs.exe %sFound%>>%systemdrive%\rapport.txt)
if exist msnscps.dll (echo %syspath%\msnscps.dll %sFound%>>%systemdrive%\rapport.txt)
if exist msole32.exe (echo %syspath%\msole32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mspostsp.exe.exe (echo %syspath%\mspostsp.exe.exe %sFound%>>%systemdrive%\rapport.txt)
if exist msupdate32.dll (echo %syspath%\msupdate32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist msvcp.exe.exe (echo %syspath%\msvcp.exe.exe %sFound%>>%systemdrive%\rapport.txt)
if exist msvol.tlb (echo %syspath%\msvol.tlb %sFound%>>%systemdrive%\rapport.txt)
if exist mswinb32.dll (echo %syspath%\mswinb32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist mswinb32.exe (echo %syspath%\mswinb32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mswinf32.dll (echo %syspath%\mswinf32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist mswinf32.exe (echo %syspath%\mswinf32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mswinup32.dll (echo %syspath%\mswinup32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist mswinxml.dll (echo %syspath%\mswinxml.dll %sFound%>>%systemdrive%\rapport.txt)
if exist MTC.dll (echo %syspath%\MTC.dll %sFound%>>%systemdrive%\rapport.txt)
if exist MTC.ini (echo %syspath%\MTC.ini %sFound%>>%systemdrive%\rapport.txt)
if exist multitran.exe (echo %syspath%\multitran.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mzoeut.dll (echo %syspath%\mzoeut.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ncompat.tlb (echo %syspath%\ncompat.tlb %sFound%>>%systemdrive%\rapport.txt)
if exist netfilt4.exe (echo %syspath%\netfilt4.exe %sFound%>>%systemdrive%\rapport.txt)
if exist network.ico (echo %syspath%\network.ico %sFound%>>%systemdrive%\rapport.txt)
if exist netwrap.dll (echo %syspath%\netwrap.dll %sFound%>>%systemdrive%\rapport.txt)
if exist notepad.com (echo %syspath%\notepad.com %sFound%>>%systemdrive%\rapport.txt)
if exist notifysb.dll (echo %syspath%\notifysb.dll %sFound%>>%systemdrive%\rapport.txt)
if exist NTCommLib3.exe (echo %syspath%\NTCommLib3.exe %sFound%>>%systemdrive%\rapport.txt)
if exist nuclabdll.dll (echo %syspath%\nuclabdll.dll %sFound%>>%systemdrive%\rapport.txt)
if exist nvctrl.exe (echo %syspath%\nvctrl.exe %sFound%>>%systemdrive%\rapport.txt)
if exist nvms.dll (echo %syspath%\nvms.dll %sFound%>>%systemdrive%\rapport.txt)
if exist oerucu.dll (echo %syspath%\oerucu.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ofcukiz.dll (echo %syspath%\ofcukiz.dll %sFound%>>%systemdrive%\rapport.txt)
if exist office_pnl.dll (echo %syspath%\office_pnl.dll %sFound%>>%systemdrive%\rapport.txt)
if exist officescan.exe (echo %syspath%\officescan.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ole32vbs.exe (echo %syspath%\ole32vbs.exe %sFound%>>%systemdrive%\rapport.txt)
if exist oleadm.dll (echo %syspath%\oleadm.dll %sFound%>>%systemdrive%\rapport.txt)
if exist oleadm32.dll (echo %syspath%\oleadm32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist oleext.dll (echo %syspath%\oleext.dll %sFound%>>%systemdrive%\rapport.txt)
if exist oleext32.dll (echo %syspath%\oleext32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "Online Betting.ico" (echo %syspath%\Online Betting.ico %sFound%>>%systemdrive%\rapport.txt)
if exist "Online Gambling.ico" (echo %syspath%\Online Gambling.ico %sFound%>>%systemdrive%\rapport.txt)
if exist onofub.dll (echo %syspath%\onofub.dll %sFound%>>%systemdrive%\rapport.txt)
if exist oqabf.dll (echo %syspath%\oqabf.dll %sFound%>>%systemdrive%\rapport.txt)
if exist oqipt.dll (echo %syspath%\oqipt.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "Oral Sex.ico" (echo %syspath%\Oral Sex.ico %sFound%>>%systemdrive%\rapport.txt)
if exist ornzq.dll (echo %syspath%\ornzq.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ot.ico (echo %syspath%\ot.ico %sFound%>>%systemdrive%\rapport.txt)
if exist oybgrql.dll (echo %syspath%\oybgrql.dll %sFound%>>%systemdrive%\rapport.txt)
if exist param32.dll (echo %syspath%\param32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist parad.raw.exe (echo %syspath%\parad.raw.exe %sFound%>>%systemdrive%\rapport.txt)
if exist paradise.raw.exe (echo %syspath%\paradise.raw.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "Party Poker.ico" (echo %syspath%\Party Poker.ico %sFound%>>%systemdrive%\rapport.txt)
if exist paytime.exe (echo %syspath%\paytime.exe %sFound%>>%systemdrive%\rapport.txt)
if exist perfcii.ini (echo %syspath%\perfcii.ini %sFound%>>%systemdrive%\rapport.txt)
if exist performent217.dll (echo %syspath%\performent217.dll %sFound%>>%systemdrive%\rapport.txt)
if exist pharm.ico (echo %syspath%\pharm.ico %sFound%>>%systemdrive%\rapport.txt)
if exist pharm2.ico (echo %syspath%\pharm2.ico %sFound%>>%systemdrive%\rapport.txt)
if exist Pharmacy.ico (echo %syspath%\Pharmacy.ico %sFound%>>%systemdrive%\rapport.txt)
if exist Phentermine.ico (echo %syspath%\Phentermine.ico %sFound%>>%systemdrive%\rapport.txt)
if exist piggl
REM Smitfraud Fix by S!Ri
REM http://siri.urz.free.fr/Fix/SmitfraudFix.zip
REM Thanks, Help: atribune, balltrap34, Beamerke, derek, Grinler, ipl_001, LonnyRJones, MAD,
REM Malekal_morte, Marckie, moe31, ~Mark, Ruby, Roel, Sebdraluorg,
REM tirol, TonyKlein, Vazkor,
REM and all the ones I forgot who submit files, analyses, help users...
REM Miekiemoes' Shudder key fix added.
REM Process.exe by Craig.Peacock added (https://www.beyondlogic.org/)
REM Reboot.exe by Shadowar/Option^Explicit added.
REM swreg.exe by SteelWerx (https://fstaal01.home.xs4all.nl/commandline-us.html)
REM swsc.exe by SteelWerx (https://fstaal01.home.xs4all.nl/commandline-us.html)
REM restart.exe - SuperFast Shutdown (http://www.xp-smoker.com/freeware.html)
REM dumphive.exe - Markus Stephany (http://www.mirkes.de)
REM unzip.exe - info-zip (http://infozip.sourceforge.net/)
REM SmiUpdate.exe - Sebdraluorg
set fixname=SmitFraudFix
set fixvers=v2.100
VER|find "Windows 95">NUL
IF NOT ERRORLEVEL 1 GOTO Win
VER|find "Windows 98">NUL
IF NOT ERRORLEVEL 1 GOTO Win
VER|find "Windows Millennium">NUL
IF NOT ERRORLEVEL 1 GOTO Win
VER|find "Windows XP">NUL
IF NOT ERRORLEVEL 1 GOTO NT
VER|find "Windows 2000">NUL
IF NOT ERRORLEVEL 1 GOTO NT
VER|find "Version 5.2.3790">NUL
IF NOT ERRORLEVEL 1 GOTO NT
if %OS%==Windows_NT goto NT
color 47
echo %fixname% %fixvers%
echo.
echo Version non support^‚e.
echo Windows 2000 / XP requis !
echo.
echo Unsupported Version.
echo Windows 2000 / XP required !
echo.
pause
goto exit
:Win
color 47
echo %fixname% %fixvers%
echo.
echo Version non support^‚e.
echo Windows 2000 / XP requis !
echo.
echo Unsupported Version.
echo Windows 2000 / XP required !
echo.
pause
goto exit
:NT
set DoReboot=0
set DoRestart=0
set syspath=%windir%\system32
echo Option Explicit>GetPaths.vbs
echo.>>GetPaths.vbs
echo Dim Shell>>GetPaths.vbs
echo Dim KeyPath>>GetPaths.vbs
echo Dim ObjFileSystem>>GetPaths.vbs
echo Dim ObjOutputFile>>GetPaths.vbs
echo Dim ObjRegExp>>GetPaths.vbs
echo Dim File>>GetPaths.vbs
echo Dim TmpVar>>GetPaths.vbs
echo Dim Var>>GetPaths.vbs
echo Dim Accent>>GetPaths.vbs
echo.>>GetPaths.vbs
echo KeyPath = "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\">>GetPaths.vbs
echo File = "SetPaths.bat">>GetPaths.vbs
echo.>>GetPaths.vbs
echo Set Shell = WScript.CreateObject("WScript.Shell")>>GetPaths.vbs
echo Set ObjFileSystem = CreateObject("Scripting.fileSystemObject")>>GetPaths.vbs
echo Set ObjOutputFile = ObjFileSystem.CreateTextFile(File, TRUE)>>GetPaths.vbs
echo Set ObjRegExp = New RegExp>>GetPaths.vbs
echo.>>GetPaths.vbs
echo Function ShortFileName(Path)>>GetPaths.vbs
echo Dim f>>GetPaths.vbs
echo Set f = ObjFileSystem.GetFolder(Path)>>GetPaths.vbs
echo ShortFileName = f.ShortPath>>GetPaths.vbs
echo End Function>>GetPaths.vbs
echo Function Accents(Str)>>GetPaths.vbs
echo ObjRegExp.Pattern = "[^a-zA-Z_0-9\\: ]">>GetPaths.vbs
echo ObjRegExp.IgnoreCase = True>>GetPaths.vbs
echo ObjRegExp.Global = True>>GetPaths.vbs
echo Accents = ObjRegExp.Replace(Str, "?")>>GetPaths.vbs
echo End Function>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Desktop")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set desktop=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Favorites")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set favorites=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Programs")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set startprg=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Start Menu")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set startm=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Startup")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set startup=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo KeyPath = "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\">>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Common Desktop")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set audesktop=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Common Favorites")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set aufavorites=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Common Programs")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set austartprg=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Common Start Menu")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set austartm=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Common Startup")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set austartup=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo.>>GetPaths.vbs
echo ObjOutputFile.Close>>GetPaths.vbs
echo Set objFileSystem = Nothing>>GetPaths.vbs
echo Set Shell = Nothing>>GetPaths.vbs
echo Set ObjRegExp = nothing>>GetPaths.vbs
echo.>>GetPaths.vbs
cscript //I //nologo GetPaths.vbs
del GetPaths.vbs
Call SetPaths.bat
del SetPaths.bat
if exist "%userprofile%\Bureau" (
set lang=fra
) else (
set lang=int
)
goto test
:test
if not exist Process.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier Process.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo Process.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist swreg.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier swreg.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo swreg.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist swsc.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier swsc.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo swsc.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist SrchSTS.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier SrchSTS.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo SrchSTS.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist Reboot.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier Reboot.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo Reboot.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist restart.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier restart.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo restart.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist GenericRenosFix.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier GenericRenosFix.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo GenericRenosFix.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist dumphive.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier dumphive.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo dumphive.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist unzip.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier unzip.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo unzip.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if not exist SmiUpdate.exe (
color 47
echo %fixname% %fixvers%
echo.
echo Fichier SmiUpdate.exe absent !
echo Dezippez la totalit^‚ de l'archive dans un dossier.
echo.
echo SmiUpdate.exe file missing !
echo Unzip all the archive in a folder.
echo.
pause
goto exit
)
if exist Update.cmd del Update.cmd
if not exist %syspath%\Process.exe copy Process.exe %syspath% >NUL
if not exist %syspath%\swreg.exe copy swreg.exe %syspath% >NUL
if not exist %syspath%\swsc.exe copy swsc.exe %syspath% >NUL
if not exist %syspath%\SrchSTS.exe copy SrchSTS.exe %syspath% >NUL
goto notice
:notice
color 17
cls
if %lang%==fra (
echo.
echo.
echo.
echo.
echo.
echo.
echo.
echo.
echo joedanger n'est pas affili^‚ avec SmitfraudFix!
echo.
echo Cet outil a ^‚t^‚ cr^‚^‚ par S!Ri pour une utilisation GRATUITE.
echo Des dons seront accept^‚es par S!Ri, uniquement sur son site Web principal
echo N'importe qui d'autre qui essaie d'en tirer profit
echo ou qui solicite de l'argent est impliqu^‚ dans une fraude.
echo.
echo.
echo Appuyez sur une touche pour continuer...
echo.
) else (
echo.
echo.
echo.
echo.
echo.
echo.
echo.
echo.
echo joedanger is NOT involved with Smitfraudfix in any way!
echo.
echo This tool was created by S!Ri, and is available for FREE.
echo Voluntary donations will be accepted by S!Ri, at his main website only.
echo Anyone, other than the creator, trying to make a profit
echo or solicit money from its use would be involved in fraudulent activity.
echo.
echo.
echo Press a key to continue...
echo.
)
pause>NUL
goto menu
:menu
color 17
cls
if %lang%==fra (
set sChoice=Entrez votre choix
set sScanDate=Rapport fait à
set sRunFrom=Executé à partir de
set SafeMWarn=Fix executé en mode normal
set SafeMDisp=Fix executé en mode sans echec
set sSearch=Recherche
set sFound=PRESENT !
set sDel=supprimé
set sInfect=infecté !
set sInfect2=infect^‚ !
set pe386Mess=pe386 détecté, utilisez un scanner de Rootkit
set lzx32Mess=lzx32 détecté, utilisez un scanner de Rootkit
set msguardMess=msguard détecté, utilisez un scanner de Rootkit
set sWiniSearch=Recherche wininet.dll de remplacement
set sEnd=Fin
set sProcess=Arret des processus
set sError=Problème suppression
set sTempFolder=Suppression Fichiers Temporaires
set sRegCleanQ=Voulez-vous nettoyer le registre ? ^(o/n^)
set sRegClean=Nettoyage du registre
set sWininetQ=Corriger le fichier infect^‚ ? ^(o/n^)
set sTrustQ=R^‚initialiser la liste des sites de confiance et sensibles ? ^(o/n^)
set sTrustBackUp=Copie de sauvegarde
set sTrustDone=Sites de confiance et sensibles effac^‚s.
set sTrustError=*** Erreur : zone.reg non trouv^‚ ***
echo.
echo.
echo %fixname% %fixvers%
echo.
echo.
echo.
echo 1. Recherche
echo 2. Nettoyage ^( mode sans echec recommand^‚ ^)
echo 3. Effacer les sites de confiance et sensibles
echo 4. V^‚rifier les Mises ^… jour
echo L. Langue Anglaise
echo Q. Quitter
echo.
echo.
echo Fermez tous les programmes
echo un red^‚marrage peut-^ˆtre n^‚cessaire
echo.
echo.
echo.
) else (
set sChoice=Enter your choice
set sScanDate=Scan done at
set sRunFrom=Run from
set SafeMWarn=Fix ran in normal mode
set SafeMDisp=Fix ran in safe mode
set sSearch=Scanning
set sFound=FOUND !
set sDel=Deleted
set sInfect=infected !
set sInfect2=infected !
set pe386Mess=pe386 detected, use a Rootkit scanner
set lzx32Mess=lzx32 detected, use a Rootkit scanner
set msguardMess=msguard detected, use a Rootkit scanner
set sWiniSearch=Scanning wininet.dll backup
set sEnd=End
set sProcess=Killing process
set sError=Problem while deleting
set sTempFolder=Deleting Temp Files
set sRegCleanQ=Do you want to clean the registry ? ^(y/n^)
set sRegClean=Registry Cleaning
set sWininetQ=Replace infected file ? ^(y/n^)
set sTrustQ=Restore Trusted Zone ? ^(y/n^)
set sTrustBackUp=Saving BackUp
set sTrustDone=Trusted Zone deleted.
set sTrustError=*** Error : zone.reg not found ***
echo.
echo.
echo %fixname% %fixvers%
echo.
echo.
echo.
echo 1. Search
echo 2. Clean ^(safe mode recommended^)
echo 3. Delete Trusted zone
echo 4. Check for updates
echo L. French Language
echo Q. Quit
echo.
echo.
echo Close all applications
echo Computer may reboot
echo.
echo.
echo.
)
set ChoixMenu=''
set /p ChoixMenu=%sChoice% (1,2,3,4,L,Q) :
if '%ChoixMenu%'=='l' GOTO SwappL
if '%ChoixMenu%'=='L' GOTO SwappL
if '%ChoixMenu%'=='q' GOTO exit
if '%ChoixMenu%'=='Q' GOTO exit
if '%ChoixMenu%'=='1' GOTO search
if '%ChoixMenu%'=='2' GOTO fix
if '%ChoixMenu%'=='3' GOTO zonefix
if '%ChoixMenu%'=='4' GOTO update
goto menu
:SwappL
if '%lang%'=='fra' (
set lang=int
) else (
set lang=fra
)
goto notice
:search
cls
echo %fixname% %fixvers%
echo %fixname% %fixvers%>%systemdrive%\rapport.txt
echo.
echo.>>%systemdrive%\rapport.txt
echo %sScanDate% %time%, %date%>>%systemdrive%\rapport.txt
for /f "Tokens=*" %%i in ('cd') do set CurDir=%%i
echo %sRunFrom% %CurDir%>>%systemdrive%\rapport.txt
IF ERRORLEVEL 1 (
echo %sRunFrom% >>%systemdrive%\rapport.txt
cd >>%systemdrive%\rapport.txt
)
for /f "Tokens=*" %%i in ('ver') do set Version=%%i
echo OS: %Version% - %OS%>>%systemdrive%\rapport.txt
if not defined safeboot_option echo %SafeMWarn%>>%systemdrive%\rapport.txt
if defined safeboot_option echo %SafeMDisp%>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
echo %sSearch% %HOMEDRIVE%\...
echo »»»»»»»»»»»»»»»»»»»»»»»» %HOMEDRIVE%\>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
pushd %HOMEDRIVE%\
if exist bsw.exe (echo %HOMEDRIVE%\bsw.exe %sFound%>>%systemdrive%\rapport.txt)
if exist contextplus.exe (echo %HOMEDRIVE%\contextplus.exe %sFound%>>%systemdrive%\rapport.txt)
if exist country.exe (echo %HOMEDRIVE%\country.exe %sFound%>>%systemdrive%\rapport.txt)
if exist defender??.exe (echo %HOMEDRIVE%\defender??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dfndr.exe (echo %HOMEDRIVE%\dfndr.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dfndra.exe (echo %HOMEDRIVE%\dfndra.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dfndr?_?.exe (echo %HOMEDRIVE%\dfndr?_?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload?.exe (echo %HOMEDRIVE%\drsmartload?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload??.exe (echo %HOMEDRIVE%\drsmartload??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload???.exe (echo %HOMEDRIVE%\drsmartload???.exe %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload????.exe (echo %HOMEDRIVE%\drsmartload????.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ecsiin.stub.exe (echo %HOMEDRIVE%\ecsiin.stub.exe %sFound%>>%systemdrive%\rapport.txt)
if exist exit (echo %HOMEDRIVE%\exit %sFound%>>%systemdrive%\rapport.txt)
if exist gimmysmileys.exe (echo %HOMEDRIVE%\gimmysmileys.exe %sFound%>>%systemdrive%\rapport.txt)
if exist gimmysmileys?.exe (echo %HOMEDRIVE%\gimmysmileys?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard.exe (echo %HOMEDRIVE%\keyboard.exe %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard?.exe (echo %HOMEDRIVE%\keyboard?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard??.exe (echo %HOMEDRIVE%\keyboard??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kl1.exe (echo %HOMEDRIVE%\kl1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kybrd.exe (echo %HOMEDRIVE%\kybrd.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kybrd_?.exe (echo %HOMEDRIVE%\kybrd_?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kybrd?_?.exe (echo %HOMEDRIVE%\kybrd?_?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist loader.exe (echo %HOMEDRIVE%\loader.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mousepad.exe (echo %HOMEDRIVE%\mousepad.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mousepad?.exe (echo %HOMEDRIVE%\mousepad?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mousepad??.exe (echo %HOMEDRIVE%\mousepad??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist MTE3NDI6ODoxNg.exe (echo %HOMEDRIVE%\MTE3NDI6ODoxNg.exe %sFound%>>%systemdrive%\rapport.txt)
if exist nwnm.exe (echo %HOMEDRIVE%\nwnm.exe %sFound%>>%systemdrive%\rapport.txt)
if exist nwnm_?.exe (echo %HOMEDRIVE%\nwnm_?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist nwnm?_?.exe (echo %HOMEDRIVE%\nwnm?_?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist newname?.exe (echo %HOMEDRIVE%\newname?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist newname??.exe (echo %HOMEDRIVE%\newname??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ntdetecd.exe (echo %HOMEDRIVE%\ntdetecd.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ntps.exe (echo %HOMEDRIVE%\ntps.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ntnc.exe (echo %HOMEDRIVE%\ntnc.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ms1.exe (echo %HOMEDRIVE%\ms1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist r.exe (echo %HOMEDRIVE%\r.exe %sFound%>>%systemdrive%\rapport.txt)
if exist secure32.html (echo %HOMEDRIVE%\secure32.html %sFound%>>%systemdrive%\rapport.txt)
if exist stub_113_4_0_4_0.exe (echo %HOMEDRIVE%\stub_113_4_0_4_0.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool1.exe (echo %HOMEDRIVE%\tool1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool2.exe (echo %HOMEDRIVE%\tool2.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool3.exe (echo %HOMEDRIVE%\tool3.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool4.exe (echo %HOMEDRIVE%\tool4.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool5.exe (echo %HOMEDRIVE%\tool5.exe %sFound%>>%systemdrive%\rapport.txt)
if exist toolbar.exe (echo %HOMEDRIVE%\toolbar.exe %sFound%>>%systemdrive%\rapport.txt)
if exist uniq (echo %HOMEDRIVE%\uniq %sFound%>>%systemdrive%\rapport.txt)
if exist winstall.exe (echo %HOMEDRIVE%\winstall.exe %sFound%>>%systemdrive%\rapport.txt)
if exist wp.bmp (echo %HOMEDRIVE%\wp.bmp %sFound%>>%systemdrive%\rapport.txt)
if exist wp.exe (echo %HOMEDRIVE%\wp.exe %sFound%>>%systemdrive%\rapport.txt)
if exist xxx.exe (echo %HOMEDRIVE%\xxx.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "%HOMEDRIVE%\spywarevanisher-free" echo %HOMEDRIVE%\spywarevanisher-free\ %sFound%>>%systemdrive%\rapport.txt
popd
echo.>>%systemdrive%\rapport.txt
echo %sSearch% %windir%\...
echo »»»»»»»»»»»»»»»»»»»»»»»» %windir%>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
pushd %windir%
if exist ".protected" (echo %windir%\.protected %sFound%>>%systemdrive%\rapport.txt)
if exist aapfr.exe (echo %windir%\aapfr.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ads.js (echo %windir%\ads.js %sFound%>>%systemdrive%\rapport.txt)
if exist adsldpbc.dll (echo %windir%\adsldpbc.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adsldpbd.dll (echo %windir%\adsldpbd.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adsldpbe.dll (echo %windir%\adsldpbe.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adsldpbf.dll (echo %windir%\adsldpbf.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adsldpbj.dll (echo %windir%\adsldpbj.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adtech2005.exe (echo %windir%\adtech2005.exe %sFound%>>%systemdrive%\rapport.txt)
if exist adtech2006a.exe (echo %windir%\adtech2006a.exe %sFound%>>%systemdrive%\rapport.txt)
if exist adw.htm (echo %windir%\adw.htm %sFound%>>%systemdrive%\rapport.txt)
if exist "adware-sheriff-box.gif" (echo %windir%\adware-sheriff-box.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "adware-sheriff-header.gif" (echo %windir%\adware-sheriff-header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist alexaie.dll (echo %windir%\alexaie.dll %sFound%>>%systemdrive%\rapport.txt)
if exist alxie328.dll (echo %windir%\alxie328.dll %sFound%>>%systemdrive%\rapport.txt)
if exist alxtb1.dll (echo %windir%\alxtb1.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "antispylab-logo.gif" (echo %windir%\antispylab-logo.gif %sFound%>>%systemdrive%\rapport.txt)
if exist about_spyware_bg.gif (echo %windir%\about_spyware_bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist about_spyware_bottom.gif (echo %windir%\about_spyware_bottom.gif %sFound%>>%systemdrive%\rapport.txt)
if exist as.gif (echo %windir%\as.gif %sFound%>>%systemdrive%\rapport.txt)
if exist as_header.gif (echo %windir%\as_header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist azesearch.bmp (echo %windir%\azesearch.bmp %sFound%>>%systemdrive%\rapport.txt)
if exist back.gif (echo %windir%\back.gif %sFound%>>%systemdrive%\rapport.txt)
if exist batserv2.exe (echo %windir%\batserv2.exe %sFound%>>%systemdrive%\rapport.txt)
if exist bg.gif (echo %windir%\bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist bg_bg.gif (echo %windir%\bg_bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist big_red_x.gif (echo %windir%\big_red_x.gif %sFound%>>%systemdrive%\rapport.txt)
if exist blank.mht (echo %windir%\blank.mht %sFound%>>%systemdrive%\rapport.txt)
if exist "blue-bg.gif" (echo %windir%\blue-bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist box_1.gif (echo %windir%\box_1.gif %sFound%>>%systemdrive%\rapport.txt)
if exist box_2.gif (echo %windir%\box_2.gif %sFound%>>%systemdrive%\rapport.txt)
if exist box_3.gif (echo %windir%\box_3.gif %sFound%>>%systemdrive%\rapport.txt)
if exist BTGrab.dll (echo %windir%\BTGrab.dll %sFound%>>%systemdrive%\rapport.txt)
if exist button_buynow.gif (echo %windir%\button_buynow.gif %sFound%>>%systemdrive%\rapport.txt)
if exist button_freescan.gif (echo %windir%\button_freescan.gif %sFound%>>%systemdrive%\rapport.txt)
if exist buy.gif (echo %windir%\buy.gif %sFound%>>%systemdrive%\rapport.txt)
if exist buy_now.gif (echo %windir%\buy_now.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "buy-now-btn.gif" (echo %windir%\buy-now-btn.gif %sFound%>>%systemdrive%\rapport.txt)
if exist bxproxy.exe (echo %windir%\bxproxy.exe %sFound%>>%systemdrive%\rapport.txt)
if exist click_for_free_scan.gif (echo %windir%\click_for_free_scan.gif %sFound%>>%systemdrive%\rapport.txt)
if exist close_ico.gif (echo %windir%\close_ico.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "close-bar.gif" (echo %windir%\close-bar.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "corner-left.gif" (echo %windir%\corner-left.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "corner-right.gif" (echo %windir%\corner-right.gif %sFound%>>%systemdrive%\rapport.txt)
if exist country.exe (echo %windir%\country.exe %sFound%>>%systemdrive%\rapport.txt)
if exist d3dn32.exe (echo %windir%\d3dn32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist d3??.dll (echo %windir%\d3??.dll %sFound%>>%systemdrive%\rapport.txt)
if exist d3pb.exe (echo %windir%\d3pb.exe %sFound%>>%systemdrive%\rapport.txt)
if exist defender??.exe (echo %windir%\defender??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist desktop.html (echo %windir%\desktop.html %sFound%>>%systemdrive%\rapport.txt)
if exist dlmax.dll (echo %windir%\dlmax.dll %sFound%>>%systemdrive%\rapport.txt)
if exist download.gif (echo %windir%\download.gif %sFound%>>%systemdrive%\rapport.txt)
if exist download_box.gif (echo %windir%\download_box.gif %sFound%>>%systemdrive%\rapport.txt)
if exist download_product.gif (echo %windir%\download_product.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "download-btn.gif" (echo %windir%\download-btn.gif %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload.dat (echo %windir%\drsmartload.dat %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload2.dat (echo %windir%\drsmartload2.dat %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartload95a.exe (echo %windir%\drsmartload95a.exe %sFound%>>%systemdrive%\rapport.txt)
if exist drsmartloadb1.dat (echo %windir%\drsmartloadb1.dat %sFound%>>%systemdrive%\rapport.txt)
if exist "facts.gif" (echo %windir%\facts.gif %sFound%>>%systemdrive%\rapport.txt)
if exist features.gif (echo %windir%\features.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "footer.gif" (echo %windir%\footer.giff %sFound%>>%systemdrive%\rapport.txt)
if exist footer_back.gif (echo %windir%\footer_back.gif %sFound%>>%systemdrive%\rapport.txt)
if exist footer_back.jpg (echo %windir%\footer_back.jpg %sFound%>>%systemdrive%\rapport.txt)
if exist free_scan_red_btn.gif (echo %windir%\free_scan_red_btn.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "free-scan-btn.gif" (echo %windir%\free-scan-btn.gif %sFound%>>%systemdrive%\rapport.txt)
if exist gimmygames.dat (echo %windir%\gimmygames.dat %sFound%>>%systemdrive%\rapport.txt)
if exist "h-line-gradient.gif" (echo %windir%\h-line-gradient.gif %sFound%>>%systemdrive%\rapport.txt)
if exist header_1.gif (echo %windir%\header_1.gif %sFound%>>%systemdrive%\rapport.txt)
if exist header_2.gif (echo %windir%\header_2.gif %sFound%>>%systemdrive%\rapport.txt)
if exist header_3.gif (echo %windir%\header_3.gif %sFound%>>%systemdrive%\rapport.txt)
if exist header_4.gif (echo %windir%\header_4.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "header-bg.gif" (echo %windir%\header-bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist icon_warning_big.gif (echo %windir%\icon_warning_big.gif %sFound%>>%systemdrive%\rapport.txt)
if exist icont.exe (echo %windir%\icont.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ieyi.dll (echo %windir%\ieyi.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ieyi.exe (echo %windir%\ieyi.exe %sFound%>>%systemdrive%\rapport.txt)
if exist inetloader.dll (echo %windir%\inetloader.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "infected.gif" (echo %windir%\infected.gif %sFound%>>%systemdrive%\rapport.txt)
if exist infected_top_bg.gif (echo %windir%\infected_top_bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "info.gif" (echo %windir%\info.gif %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard.exe (echo %windir%\keyboard.exe %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard?.exe (echo %windir%\keyboard?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard1.dat (echo %windir%\keyboard1.dat %sFound%>>%systemdrive%\rapport.txt)
if exist keyboard??.exe (echo %windir%\keyboard??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kl.exe (echo %windir%\kl.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kl1.exe (echo %windir%\kl1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist loadadv728.exe (echo %windir%\loadadv728.exe %sFound%>>%systemdrive%\rapport.txt)
if exist local.html (echo %windir%\local.html %sFound%>>%systemdrive%\rapport.txt)
if exist logo.gif (echo %windir%\logo.gif %sFound%>>%systemdrive%\rapport.txt)
if exist main_back.gif (echo %windir%\main_back.gif %sFound%>>%systemdrive%\rapport.txt)
if exist mxd.exe (echo %windir%\mxd.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mousepad.exe (echo %windir%\mousepad.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mousepad?.exe (echo %windir%\mousepad?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mousepad??.exe (echo %windir%\mousepad??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist navibar_bg.gif (echo %windir%\navibar_bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist navibar_corner_left.gif (echo %windir%\navibar_corner_left.gif %sFound%>>%systemdrive%\rapport.txt)
if exist navibar_corner_right.gif (echo %windir%\navibar_corner_right.gif %sFound%>>%systemdrive%\rapport.txt)
if exist newname.dat (echo %windir%\newname.dat %sFound%>>%systemdrive%\rapport.txt)
if exist newname?.exe (echo %windir%\newname?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist newname??.exe (echo %windir%\newname??.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ms1.exe (echo %windir%\ms1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "no-icon.gif" (echo %windir%\no-icon.gif %sFound%>>%systemdrive%\rapport.txt)
if exist notepad.com (echo %windir%\notepad.com %sFound%>>%systemdrive%\rapport.txt)
if exist onlineshopping.ico (echo %windir%\onlineshopping.ico %sFound%>>%systemdrive%\rapport.txt)
if exist osaupd.exe (echo %windir%\osaupd.exe %sFound%>>%systemdrive%\rapport.txt)
if exist pop06ap2.exe (echo %windir%\pop06ap2.exe %sFound%>>%systemdrive%\rapport.txt)
if exist popuper.exe (echo %windir%\popuper.exe %sFound%>>%systemdrive%\rapport.txt)
if exist processes.txt (echo %windir%\processes.txt %sFound%>>%systemdrive%\rapport.txt)
if exist product_box.gif (echo %windir%\product_box.gif %sFound%>>%systemdrive%\rapport.txt)
if exist psg.exe (echo %windir%\psg.exe %sFound%>>%systemdrive%\rapport.txt)
if exist Pynix.dll (echo %windir%\Pynix.dll %sFound%>>%systemdrive%\rapport.txt)
if exist q*_disk.dll (echo %windir%\q*_disk.dll %sFound%>>%systemdrive%\rapport.txt)
if exist red_warning_ico.gif (echo %windir%\red_warning_ico.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "reg-freeze-box.gif" (echo %windir%\reg-freeze-box.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "reg-freeze-header.gif" (echo %windir%\reg-freeze-header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist remove_spyware_header.gif (echo %windir%\remove_spyware_header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "remove-spyware-btn.gif" (echo %windir%\remove-spyware-btn.gif %sFound%>>%systemdrive%\rapport.txt)
if exist removeadware.ico (echo %windir%\removeadware.ico %sFound%>>%systemdrive%\rapport.txt)
if exist rf.gif (echo %windir%\rf.gif %sFound%>>%systemdrive%\rapport.txt)
if exist rf_header.gif (echo %windir%\rf_header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist rzs.exe (echo %windir%\rzs.exe %sFound%>>%systemdrive%\rapport.txt)
if exist sachostx.exe (echo %windir%\sachostx.exe %sFound%>>%systemdrive%\rapport.txt)
if exist safe_and_trusted.gif (echo %windir%\safe_and_trusted.gif %sFound%>>%systemdrive%\rapport.txt)
if exist scan_btn.gif (echo %windir%\scan_btn.gif %sFound%>>%systemdrive%\rapport.txt)
if exist screen.html (echo %windir%\screen.html %sFound%>>%systemdrive%\rapport.txt)
if exist se_spoof.dll (echo %windir%\se_spoof.dll %sFound%>>%systemdrive%\rapport.txt)
if exist sec.exe (echo %windir%\sec.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "security-center-bg.gif" (echo %windir%\security-center-bg.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "security-center-logo.gif" (echo %windir%\security-center-logo.gif %sFound%>>%systemdrive%\rapport.txt)
if exist security_center_caption.gif (echo %windir%\security_center_caption.gif %sFound%>>%systemdrive%\rapport.txt)
if exist sep_hor.gif (echo %windir%\sep_hor.gif %sFound%>>%systemdrive%\rapport.txt)
if exist sep_vert.gif (echo %windir%\sep_vert.gif %sFound%>>%systemdrive%\rapport.txt)
if exist sexpersonals.ico (echo %windir%\sexpersonals.ico %sFound%>>%systemdrive%\rapport.txt)
if exist sdkcb.dll (echo %windir%\sdkcb.dll %sFound%>>%systemdrive%\rapport.txt)
if exist sdkqq.exe (echo %windir%\sdkqq.exe %sFound%>>%systemdrive%\rapport.txt)
if exist secure32.html (echo %windir%\secure32.html %sFound%>>%systemdrive%\rapport.txt)
if exist sites.ini (echo %windir%\sites.ini %sFound%>>%systemdrive%\rapport.txt)
if exist slassac.dll (echo %windir%\slassac.dll %sFound%>>%systemdrive%\rapport.txt)
if exist spacer.gif (echo %windir%\spacer.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "spacer.gif'" (echo %windir%\spacer.gif' %sFound%>>%systemdrive%\rapport.txt)
if exist spyware_detected.gif (echo %windir%\spyware_detected.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "spyware-detected.gif" (echo %windir%\spyware-detected.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "spyware-sheriff-header.gif" (echo %windir%\spyware-sheriff-header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "spyware-sheriff-box.gif" (echo %windir%\spyware-sheriff-box.gif %sFound%>>%systemdrive%\rapport.txt)
if exist sss_main.ini (echo %windir%\sss_main.ini %sFound%>>%systemdrive%\rapport.txt)
if exist "star.gif" (echo %windir%\star.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "star-grey.gif" (echo %windir%\star-grey.gif %sFound%>>%systemdrive%\rapport.txt)
if exist star_gray.gif (echo %windir%\star_gray.gif %sFound%>>%systemdrive%\rapport.txt)
if exist star_gray_small.gif (echo %windir%\star_gray_small.gif %sFound%>>%systemdrive%\rapport.txt)
if exist star_small.gif (echo %windir%\star_small.gif %sFound%>>%systemdrive%\rapport.txt)
if exist susp.exe (echo %windir%\susp.exe %sFound%>>%systemdrive%\rapport.txt)
if exist svchost.exe (echo %windir%\svchost.exe %sFound%>>%systemdrive%\rapport.txt)
if exist sysen.exe (echo %windir%\sysen.exe %sFound%>>%systemdrive%\rapport.txt)
if exist sysvx_.exe (echo %windir%\sysvx_.exe %sFound%>>%systemdrive%\rapport.txt)
if exist sysldr32.exe (echo %windir%\sysldr32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist System32fab.exe (echo %windir%\System32fab.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tctool.exe (echo %windir%\tctool.exe %sFound%>>%systemdrive%\rapport.txt)
if exist teller2.chk (echo %windir%\teller2.chk %sFound%>>%systemdrive%\rapport.txt)
if exist temp.000.exe (echo %windir%\temp.000.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ticads.exe (echo %windir%\ticads.exe %sFound%>>%systemdrive%\rapport.txt)
if exist timessquare.exe (echo %windir%\timessquare.exe %sFound%>>%systemdrive%\rapport.txt)
if exist timessquare1.dat (echo %windir%\timessquare1.dat %sFound%>>%systemdrive%\rapport.txt)
if exist tool1.exe (echo %windir%\tool1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool2.exe (echo %windir%\tool2.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool3.exe (echo %windir%\tool3.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool4.exe (echo %windir%\tool4.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tool5.exe (echo %windir%\tool5.exe %sFound%>>%systemdrive%\rapport.txt)
if exist toolbar.exe (echo %windir%\toolbar.exe %sFound%>>%systemdrive%\rapport.txt)
if exist tpopup.exe (echo %windir%\tpopup.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "true-stories.gif" (echo %windir%\true-stories.gif %sFound%>>%systemdrive%\rapport.txt)
if exist trustinbar.exe (echo %windir%\trustinbar.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ts.gif (echo %windir%\ts.gif %sFound%>>%systemdrive%\rapport.txt)
if exist ts_header.gif (echo %windir%\ts_header.gif %sFound%>>%systemdrive%\rapport.txt)
if exist tse.exe (echo %windir%\tse.exe %sFound%>>%systemdrive%\rapport.txt)
if exist uninstDsk.exe (echo %windir%\uninstDsk.exe %sFound%>>%systemdrive%\rapport.txt)
if exist uninstIU.exe (echo %windir%\uninstIU.exe %sFound%>>%systemdrive%\rapport.txt)
if exist update13.js (echo %windir%\update13.js %sFound%>>%systemdrive%\rapport.txt)
if exist url.exe (echo %windir%\url.exe %sFound%>>%systemdrive%\rapport.txt)
if exist v.gif (echo %windir%\v.gif %sFound%>>%systemdrive%\rapport.txt)
if exist videoslots.ico (echo %windir%\videoslots.ico %sFound%>>%systemdrive%\rapport.txt)
if exist warnhp.html (echo %windir%\warnhp.html %sFound%>>%systemdrive%\rapport.txt)
if exist warning_icon.gif (echo %windir%\warning_icon.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "warning-bar-ico.gif" (echo %windir%\warning-bar-ico.gif %sFound%>>%systemdrive%\rapport.txt)
if exist win_logo.gif (echo %windir%\win_logo.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "win-sec-center-logo.gif" (echo %windir%\win-sec-center-logo.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "windows-compatible.gif" (echo %windir%\windows-compatible.gif %sFound%>>%systemdrive%\rapport.txt)
if exist winsysupd.exe (echo %windir%\winsysupd.exe %sFound%>>%systemdrive%\rapport.txt)
if exist winsysban.exe (echo %windir%\winsysban.exe %sFound%>>%systemdrive%\rapport.txt)
if exist winsysban8.exe (echo %windir%\winsysban8.exe %sFound%>>%systemdrive%\rapport.txt)
if exist windows.html (echo %windir%\windows.html %sFound%>>%systemdrive%\rapport.txt)
if exist wupdmgr.exe (echo %windir%\wupdmgr.exe %sFound%>>%systemdrive%\rapport.txt)
if exist x.gif (echo %windir%\x.gif %sFound%>>%systemdrive%\rapport.txt)
if exist xpupdate.exe (echo %windir%\xpupdate.exe %sFound%>>%systemdrive%\rapport.txt)
if exist yellow_warning_ico.gif (echo %windir%\yellow_warning_ico.gif %sFound%>>%systemdrive%\rapport.txt)
if exist "yes-icon.gif" (echo %windir%\yes-icon.gif %sFound%>>%systemdrive%\rapport.txt)
if exist zloader3.exe (echo %windir%\zloader3.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ZServ.dll (echo %windir%\ZServ.dll %sFound%>>%systemdrive%\rapport.txt)
if exist __delete_on_reboot__popuper.exe (echo %windir%\__delete_on_reboot__popuper.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "%windir%\muwq" echo %windir%\muwq\ %sFound%>>%systemdrive%\rapport.txt
if exist "%windir%\inet20001" echo %windir%\inet20001\ %sFound%>>%systemdrive%\rapport.txt
if exist "%windir%\inet20010" echo %windir%\inet20010\ %sFound%>>%systemdrive%\rapport.txt
if exist "%windir%\inet20066" echo %windir%\inet20066\ %sFound%>>%systemdrive%\rapport.txt
if exist "%windir%\inet20099" echo %windir%\inet20099\ %sFound%>>%systemdrive%\rapport.txt
popd
echo.>>%systemdrive%\rapport.txt
echo %sSearch% %windir%\system...
echo »»»»»»»»»»»»»»»»»»»»»»»» %windir%\system>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
pushd %windir%\system
if exist csrss.exe (echo %windir%\system\csrss.exe %sFound%>>%systemdrive%\rapport.txt)
if exist eooyt.exe (echo %windir%\system\eooyt.exe %sFound%>>%systemdrive%\rapport.txt)
if exist processes.txt (echo %windir%\system\processes.txt %sFound%>>%systemdrive%\rapport.txt)
if exist svchost.exe (echo %windir%\system\svchost.exe %sFound%>>%systemdrive%\rapport.txt)
if exist svchost.dll (echo %windir%\system\svchost.dll %sFound%>>%systemdrive%\rapport.txt)
if exist svwhost.exe (echo %windir%\system\svwhost.exe %sFound%>>%systemdrive%\rapport.txt)
if exist svwhost.dll (echo %windir%\system\svwhost.dll %sFound%>>%systemdrive%\rapport.txt)
popd
echo.>>%systemdrive%\rapport.txt
echo %sSearch% %windir%\Web...
echo »»»»»»»»»»»»»»»»»»»»»»»» %windir%\Web>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
pushd %windir%\Web
if exist desktop.html (echo %windir%\Web\desktop.html %sFound%>>%systemdrive%\rapport.txt)
if exist wallpaper.html (echo %windir%\Web\wallpaper.html %sFound%>>%systemdrive%\rapport.txt)
popd
echo.>>%systemdrive%\rapport.txt
echo %sSearch% %syspath%...
echo »»»»»»»»»»»»»»»»»»»»»»»» %syspath%>>%systemdrive%\rapport.txt
echo.>>%systemdrive%\rapport.txt
pushd %syspath%
if exist ~update.exe (echo %syspath%\~update.exe %sFound%>>%systemdrive%\rapport.txt)
if exist 0mcamcap.exe (echo %syspath%\0mcamcap.exe %sFound%>>%systemdrive%\rapport.txt)
if exist 977efcdb.exe (echo %syspath%\977efcdb.exe %sFound%>>%systemdrive%\rapport.txt)
if exist a.exe (echo %syspath%\a.exe %sFound%>>%systemdrive%\rapport.txt)
if exist acvgxw.dll (echo %syspath%\acvgxw.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adobepnl.dll (echo %syspath%\adobepnl.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "Air Tickets.ico" (echo %syspath%\Air Tickets.ico %sFound%>>%systemdrive%\rapport.txt)
if exist AdService.dll (echo %syspath%\AdService.dll %sFound%>>%systemdrive%\rapport.txt)
if exist adsmart.exe (echo %syspath%\adsmart.exe %sFound%>>%systemdrive%\rapport.txt)
if exist alxres.dll (echo %syspath%\alxres.dll %sFound%>>%systemdrive%\rapport.txt)
if exist appmagr.dll (echo %syspath%\appmagr.dll %sFound%>>%systemdrive%\rapport.txt)
if exist asxbbx.dll (echo %syspath%\asxbbx.dll %sFound%>>%systemdrive%\rapport.txt)
if exist atmclk.exe (echo %syspath%\atmclk.exe %sFound%>>%systemdrive%\rapport.txt)
if exist autodisc32.dll (echo %syspath%\autodisc32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist bhoimpl.dll (echo %syspath%\bhoimpl.dll %sFound%>>%systemdrive%\rapport.txt)
if exist bikini.exe (echo %syspath%\bikini.exe %sFound%>>%systemdrive%\rapport.txt)
if exist bin29a.log (echo %syspath%\bin29a.log %sFound%>>%systemdrive%\rapport.txt)
if exist "Big Tits.ico" (echo %syspath%\Big Tits.ico %sFound%>>%systemdrive%\rapport.txt)
if exist birdihuy.dll (echo %syspath%\birdihuy.dll %sFound%>>%systemdrive%\rapport.txt)
if exist birdihuy32.dll (echo %syspath%\birdihuy32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist Blackjack.ico (echo %syspath%\Blackjack.ico %sFound%>>%systemdrive%\rapport.txt)
if exist bnmsrv.exe (echo %syspath%\bnmsrv.exe %sFound%>>%systemdrive%\rapport.txt)
if exist bolnyz.dll (echo %syspath%\bolnyz.dll %sFound%>>%systemdrive%\rapport.txt)
if exist bre.dll (echo %syspath%\bre.dll %sFound%>>%systemdrive%\rapport.txt)
if exist bre32.dll (echo %syspath%\bre32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist bridge.dll (echo %syspath%\bridge.dll %sFound%>>%systemdrive%\rapport.txt)
if exist bpvcou.dll (echo %syspath%\bpvcou.dll %sFound%>>%systemdrive%\rapport.txt)
if exist browsela.dll (echo %syspath%\browsela.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "Britney Spears.ico" (echo %syspath%\Britney Spears.ico %sFound%>>%systemdrive%\rapport.txt)
if exist bu.exe (echo %syspath%\bu.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "Car Insurance.ico" (echo %syspath%\Car Insurance.ico %sFound%>>%systemdrive%\rapport.txt)
if exist casino.ico (echo %syspath%\casino.ico %sFound%>>%systemdrive%\rapport.txt)
if exist "Cheap Cigarettes.ico" (echo %syspath%\Cheap Cigarettes.ico %sFound%>>%systemdrive%\rapport.txt)
if exist child.dll (echo %syspath%\child.dll %sFound%>>%systemdrive%\rapport.txt)
if exist chp.dll (echo %syspath%\chp.dll %sFound%>>%systemdrive%\rapport.txt)
if exist cmd32.exe (echo %syspath%\cmd32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist cmdtel.exe (echo %syspath%\cmdtel.exe %sFound%>>%systemdrive%\rapport.txt)
if exist cnymxw32.dll (echo %syspath%\cnymxw32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist combo.exe (echo %syspath%\combo.exe %sFound%>>%systemdrive%\rapport.txt)
if exist comdlg64.dll (echo %syspath%\comdlg64.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "Credit Card.ico" (echo %syspath%\Credit Card.ico %sFound%>>%systemdrive%\rapport.txt)
if exist Cruises.ico (echo %syspath%\Cruises.ico %sFound%>>%systemdrive%\rapport.txt)
if exist "Currency Trading.ico" (echo %syspath%\Currency Trading.ico %sFound%>>%systemdrive%\rapport.txt)
if exist cvxh8jkdq?.exe (echo %syspath%\cvxh8jkdq?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist CWS_iestart.exe (echo %syspath%\CWS_iestart.exe %sFound%>>%systemdrive%\rapport.txt)
if exist date.ico (echo %syspath%\date.ico %sFound%>>%systemdrive%\rapport.txt)
if exist dailytoolbar.dll (echo %syspath%\dailytoolbar.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_14.dll (echo %syspath%\dcom_14.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_15.dll (echo %syspath%\dcom_15.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_16.dll (echo %syspath%\dcom_16.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_18.dll (echo %syspath%\dcom_18.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_19.dll (echo %syspath%\dcom_19.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_20.dll (echo %syspath%\dcom_20.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcom_21.dll (echo %syspath%\dcom_21.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dcomcfg.exe (echo %syspath%\dcomcfg.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dial23.exe (echo %syspath%\dial23.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dlh9jkdq?.exe (echo %syspath%\dlh9jkdq?.exe %sFound%>>%systemdrive%\rapport.txt)
if exist doser.exe (echo %syspath%\doser.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dfrgsrv.exe (echo %syspath%\dfrgsrv.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dnefhw.dll (echo %syspath%\dnefhw.dll %sFound%>>%systemdrive%\rapport.txt)
if exist duxzj.dll (echo %syspath%\duxzj.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dvdcap.dll (echo %syspath%\dvdcap.dll %sFound%>>%systemdrive%\rapport.txt)
if exist dxole32.exe (echo %syspath%\dxole32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist dxmpp.dll (echo %syspath%\dxmpp.dll %sFound%>>%systemdrive%\rapport.txt)
if exist efsdfgxg.exe (echo %syspath%\efsdfgxg.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ekvrlfzz.exe (echo %syspath%\ekvrlfzz.exe %sFound%>>%systemdrive%\rapport.txt)
if exist eowygj.dll (echo %syspath%\eowygj.dll %sFound%>>%systemdrive%\rapport.txt)
if exist erxbx.dll (echo %syspath%\erxbx.dll %sFound%>>%systemdrive%\rapport.txt)
if exist exa32.exe (echo %syspath%\exa32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist exeha2.exe (echo %syspath%\exeha2.exe %sFound%>>%systemdrive%\rapport.txt)
if exist exeha3.exe (echo %syspath%\exeha3.exe %sFound%>>%systemdrive%\rapport.txt)
if exist exuc32.tmp (echo %syspath%\exuc32.tmp %sFound%>>%systemdrive%\rapport.txt)
if exist fhmfes.dll (echo %syspath%\fhmfes.dll %sFound%>>%systemdrive%\rapport.txt)
if exist fjdcy.dll (echo %syspath%\fjdcy.dll %sFound%>>%systemdrive%\rapport.txt)
if exist fyhhxw.dll (echo %syspath%\fyhhxw.dll %sFound%>>%systemdrive%\rapport.txt)
if exist games.ico (echo %syspath%\games.ico %sFound%>>%systemdrive%\rapport.txt)
if exist ginuerep.dll (echo %syspath%\ginuerep.dll %sFound%>>%systemdrive%\rapport.txt)
if exist gtpbx.dll (echo %syspath%\gtpbx.dll %sFound%>>%systemdrive%\rapport.txt)
if exist gunist.exe (echo %syspath%\gunist.exe %sFound%>>%systemdrive%\rapport.txt)
if exist guxxa.dll (echo %syspath%\guxxa.dll %sFound%>>%systemdrive%\rapport.txt)
if exist helper.exe (echo %syspath%\helper.exe %sFound%>>%systemdrive%\rapport.txt)
if exist higjxe.dll (echo %syspath%\higjxe.dll %sFound%>>%systemdrive%\rapport.txt)
if exist hhk.dll (echo %syspath%\hhk.dll %sFound%>>%systemdrive%\rapport.txt)
if exist hookdump.exe (echo %syspath%\hookdump.exe %sFound%>>%systemdrive%\rapport.txt)
if exist hp???.tmp (echo %syspath%\hp???.tmp %sFound%>>%systemdrive%\rapport.txt)
if exist hp????.tmp (echo %syspath%\hp????.tmp %sFound%>>%systemdrive%\rapport.txt)
if exist htey.dll (echo %syspath%\htey.dll %sFound%>>%systemdrive%\rapport.txt)
if exist hvcycg.dll (echo %syspath%\hvcycg.dll %sFound%>>%systemdrive%\rapport.txt)
if exist hvnwm.dll (echo %syspath%\hvnwm.dll %sFound%>>%systemdrive%\rapport.txt)
if exist hzclqhc.dll (echo %syspath%\hzclqhc.dll %sFound%>>%systemdrive%\rapport.txt)
if exist icima.dll (echo %syspath%\icima.dll %sFound%>>%systemdrive%\rapport.txt)
if exist IeHelperEx.dll (echo %syspath%\IeHelperEx.dll %sFound%>>%systemdrive%\rapport.txt)
if exist imfdfcj.dll (echo %syspath%\imfdfcj.dll %sFound%>>%systemdrive%\rapport.txt)
if exist intel32.exe (echo %syspath%\intel32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist intell321.exe (echo %syspath%\intell321.exe %sFound%>>%systemdrive%\rapport.txt)
if exist intell32.exe (echo %syspath%\intell32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist interf.tlb (echo %syspath%\interf.tlb %sFound%>>%systemdrive%\rapport.txt)
if exist intmon.exe (echo %syspath%\intmon.exe %sFound%>>%systemdrive%\rapport.txt)
if exist intmonp.exe (echo %syspath%\intmonp.exe %sFound%>>%systemdrive%\rapport.txt)
if exist intxt.exe (echo %syspath%\intxt.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ioctrl.dll (echo %syspath%\ioctrl.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ipztub.dll (echo %syspath%\ipztub.dll %sFound%>>%systemdrive%\rapport.txt)
if exist iqzv.dll (echo %syspath%\iqzv.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ishost.exe (echo %syspath%\ishost.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ismini.exe (echo %syspath%\ismini.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ismon.exe (echo %syspath%\ismon.exe %sFound%>>%systemdrive%\rapport.txt)
if exist isnotify.exe (echo %syspath%\isnotify.exe %sFound%>>%systemdrive%\rapport.txt)
if exist issearch.exe (echo %syspath%\issearch.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ixt?.dll (echo %syspath%\ixt?.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ixt??.dll (echo %syspath%\ixt??.dll %sFound%>>%systemdrive%\rapport.txt)
if exist jao.dll (echo %syspath%\jao.dll %sFound%>>%systemdrive%\rapport.txt)
if exist jevtxpg.dll (echo %syspath%\jevtxpg.dll %sFound%>>%systemdrive%\rapport.txt)
if exist jpqet.dll (echo %syspath%\jpqet.dll %sFound%>>%systemdrive%\rapport.txt)
if exist kernels8.exe (echo %syspath%\kernels8.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kernels32.exe (echo %syspath%\kernels32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kernels64.exe (echo %syspath%\kernels64.exe %sFound%>>%systemdrive%\rapport.txt)
if exist kfhrvq.dll (echo %syspath%\kfhrvq.dll %sFound%>>%systemdrive%\rapport.txt)
if exist kkqfb.dll (echo %syspath%\kkqfb.dll %sFound%>>%systemdrive%\rapport.txt)
if exist latest.exe (echo %syspath%\latest.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "Lesbian Sex.ico" (echo %syspath%\Lesbian Sex.ico %sFound%>>%systemdrive%\rapport.txt)
if exist ld???.tmp (echo %syspath%\ld???.tmp %sFound%>>%systemdrive%\rapport.txt)
if exist ld????.tmp (echo %syspath%\ld????.tmp %sFound%>>%systemdrive%\rapport.txt)
if exist lich.exe (echo %syspath%\lich.exe %sFound%>>%systemdrive%\rapport.txt)
if exist links.exe (echo %syspath%\links.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ll.exe (echo %syspath%\ll.exe %sFound%>>%systemdrive%\rapport.txt)
if exist lwpfwjb.dll (echo %syspath%\lwpfwjb.dll %sFound%>>%systemdrive%\rapport.txt)
if exist main.exe (echo %syspath%\main.exe %sFound%>>%systemdrive%\rapport.txt)
if exist maxd1.exe (echo %syspath%\maxd1.exe %sFound%>>%systemdrive%\rapport.txt)
if exist maxd64.exe (echo %syspath%\maxd64.exe %sFound%>>%systemdrive%\rapport.txt)
if exist migicons.exe (echo %syspath%\migicons.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mirarsearch_toolbar.exe (echo %syspath%\mirarsearch_toolbar.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mobile.ico (echo %syspath%\mobile.ico %sFound%>>%systemdrive%\rapport.txt)
if exist MP3.ico (echo %syspath%\MP3.ico %sFound%>>%systemdrive%\rapport.txt)
if exist msbe.dll (echo %syspath%\msbe.dll %sFound%>>%systemdrive%\rapport.txt)
if exist mscornet.exe (echo %syspath%\mscornet.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mshtml32.tdb (echo %syspath%\mshtml32.tdb %sFound%>>%systemdrive%\rapport.txt)
if exist mssearchnet.exe (echo %syspath%\mssearchnet.exe %sFound%>>%systemdrive%\rapport.txt)
if exist msmsgs.exe (echo %syspath%\msmsgs.exe %sFound%>>%systemdrive%\rapport.txt)
if exist msnscps.dll (echo %syspath%\msnscps.dll %sFound%>>%systemdrive%\rapport.txt)
if exist msole32.exe (echo %syspath%\msole32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mspostsp.exe.exe (echo %syspath%\mspostsp.exe.exe %sFound%>>%systemdrive%\rapport.txt)
if exist msupdate32.dll (echo %syspath%\msupdate32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist msvcp.exe.exe (echo %syspath%\msvcp.exe.exe %sFound%>>%systemdrive%\rapport.txt)
if exist msvol.tlb (echo %syspath%\msvol.tlb %sFound%>>%systemdrive%\rapport.txt)
if exist mswinb32.dll (echo %syspath%\mswinb32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist mswinb32.exe (echo %syspath%\mswinb32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mswinf32.dll (echo %syspath%\mswinf32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist mswinf32.exe (echo %syspath%\mswinf32.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mswinup32.dll (echo %syspath%\mswinup32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist mswinxml.dll (echo %syspath%\mswinxml.dll %sFound%>>%systemdrive%\rapport.txt)
if exist MTC.dll (echo %syspath%\MTC.dll %sFound%>>%systemdrive%\rapport.txt)
if exist MTC.ini (echo %syspath%\MTC.ini %sFound%>>%systemdrive%\rapport.txt)
if exist multitran.exe (echo %syspath%\multitran.exe %sFound%>>%systemdrive%\rapport.txt)
if exist mzoeut.dll (echo %syspath%\mzoeut.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ncompat.tlb (echo %syspath%\ncompat.tlb %sFound%>>%systemdrive%\rapport.txt)
if exist netfilt4.exe (echo %syspath%\netfilt4.exe %sFound%>>%systemdrive%\rapport.txt)
if exist network.ico (echo %syspath%\network.ico %sFound%>>%systemdrive%\rapport.txt)
if exist netwrap.dll (echo %syspath%\netwrap.dll %sFound%>>%systemdrive%\rapport.txt)
if exist notepad.com (echo %syspath%\notepad.com %sFound%>>%systemdrive%\rapport.txt)
if exist notifysb.dll (echo %syspath%\notifysb.dll %sFound%>>%systemdrive%\rapport.txt)
if exist NTCommLib3.exe (echo %syspath%\NTCommLib3.exe %sFound%>>%systemdrive%\rapport.txt)
if exist nuclabdll.dll (echo %syspath%\nuclabdll.dll %sFound%>>%systemdrive%\rapport.txt)
if exist nvctrl.exe (echo %syspath%\nvctrl.exe %sFound%>>%systemdrive%\rapport.txt)
if exist nvms.dll (echo %syspath%\nvms.dll %sFound%>>%systemdrive%\rapport.txt)
if exist oerucu.dll (echo %syspath%\oerucu.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ofcukiz.dll (echo %syspath%\ofcukiz.dll %sFound%>>%systemdrive%\rapport.txt)
if exist office_pnl.dll (echo %syspath%\office_pnl.dll %sFound%>>%systemdrive%\rapport.txt)
if exist officescan.exe (echo %syspath%\officescan.exe %sFound%>>%systemdrive%\rapport.txt)
if exist ole32vbs.exe (echo %syspath%\ole32vbs.exe %sFound%>>%systemdrive%\rapport.txt)
if exist oleadm.dll (echo %syspath%\oleadm.dll %sFound%>>%systemdrive%\rapport.txt)
if exist oleadm32.dll (echo %syspath%\oleadm32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist oleext.dll (echo %syspath%\oleext.dll %sFound%>>%systemdrive%\rapport.txt)
if exist oleext32.dll (echo %syspath%\oleext32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "Online Betting.ico" (echo %syspath%\Online Betting.ico %sFound%>>%systemdrive%\rapport.txt)
if exist "Online Gambling.ico" (echo %syspath%\Online Gambling.ico %sFound%>>%systemdrive%\rapport.txt)
if exist onofub.dll (echo %syspath%\onofub.dll %sFound%>>%systemdrive%\rapport.txt)
if exist oqabf.dll (echo %syspath%\oqabf.dll %sFound%>>%systemdrive%\rapport.txt)
if exist oqipt.dll (echo %syspath%\oqipt.dll %sFound%>>%systemdrive%\rapport.txt)
if exist "Oral Sex.ico" (echo %syspath%\Oral Sex.ico %sFound%>>%systemdrive%\rapport.txt)
if exist ornzq.dll (echo %syspath%\ornzq.dll %sFound%>>%systemdrive%\rapport.txt)
if exist ot.ico (echo %syspath%\ot.ico %sFound%>>%systemdrive%\rapport.txt)
if exist oybgrql.dll (echo %syspath%\oybgrql.dll %sFound%>>%systemdrive%\rapport.txt)
if exist param32.dll (echo %syspath%\param32.dll %sFound%>>%systemdrive%\rapport.txt)
if exist parad.raw.exe (echo %syspath%\parad.raw.exe %sFound%>>%systemdrive%\rapport.txt)
if exist paradise.raw.exe (echo %syspath%\paradise.raw.exe %sFound%>>%systemdrive%\rapport.txt)
if exist "Party Poker.ico" (echo %syspath%\Party Poker.ico %sFound%>>%systemdrive%\rapport.txt)
if exist paytime.exe (echo %syspath%\paytime.exe %sFound%>>%systemdrive%\rapport.txt)
if exist perfcii.ini (echo %syspath%\perfcii.ini %sFound%>>%systemdrive%\rapport.txt)
if exist performent217.dll (echo %syspath%\performent217.dll %sFound%>>%systemdrive%\rapport.txt)
if exist pharm.ico (echo %syspath%\pharm.ico %sFound%>>%systemdrive%\rapport.txt)
if exist pharm2.ico (echo %syspath%\pharm2.ico %sFound%>>%systemdrive%\rapport.txt)
if exist Pharmacy.ico (echo %syspath%\Pharmacy.ico %sFound%>>%systemdrive%\rapport.txt)
if exist Phentermine.ico (echo %syspath%\Phentermine.ico %sFound%>>%systemdrive%\rapport.txt)
if exist piggl
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 21:13 06-09-26
+ Scan result:
C:\Documents and Settings\Jeremy\Local Settings\Temp\18069.tmp -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Documents and Settings\TOTOF\Local Settings\Temporary Internet Files\Content.IE5\QX6T0HGV\Setup[1].exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Documents and Settings\TOTOF\Mes documents\Mes vidéos\Setup.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-776561741-117609710-1177238915-1007\Dc13.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SystemDoctor 2006 Free -> Adware.SystemDoctor2006 : Cleaned with backup (quarantined).
C:\Program Files\Fichiers communs\WinFixer 2005\FCrXML.dll -> Adware.Winfixer : Cleaned with backup (quarantined).
C:\Documents and Settings\TOTOF\Application Data\errorsafescannerinstall_fr[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored.
:mozilla.151:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.152:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.46:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.51:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.55:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.56:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.62:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@aolfr.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@metacafe.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@aolfr.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@boonty.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.382:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.383:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.384:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.568:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.593:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.626:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.632:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\TOTOF\Local Settings\Temp\Cookies\totof@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.565:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.566:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.567:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
:mozilla.124:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.125:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.351:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.352:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.353:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.50:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.51:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.30:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.25:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.52:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.692:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.693:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.388:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.389:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.390:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.231:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.645:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@com[2].txt -> TrackingCookie.Com : Cleaned.
:mozilla.95:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.386:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@c.enhance[1].txt -> TrackingCookie.Enhance : Cleaned.
:mozilla.166:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
:mozilla.49:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.35:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.36:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.37:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.38:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.39:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.40:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.41:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.42:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.43:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.44:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@cityclub.gamingpromo[2].txt -> TrackingCookie.Gamingpromo : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@gamingpromo[2].txt -> TrackingCookie.Gamingpromo : Cleaned.
:mozilla.232:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.366:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.369:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.401:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.417:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\Copie (3) de utilisateur1@ivwbox[1].txt -> TrackingCookie.Ivwbox : Cleaned.
:mozilla.359:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.360:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.22:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@banner.newyorkcasino[1].txt -> TrackingCookie.Newyorkcasino : Cleaned.
:mozilla.167:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.168:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.385:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@data4.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@ads.planetactive[1].txt -> TrackingCookie.Planetactive : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@ads.realcastmedia[1].txt -> TrackingCookie.Realcastmedia : Cleaned.
:mozilla.19:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.20:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.21:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.22:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.23:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.24:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.25:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.26:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.27:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.28:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.29:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.37:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.38:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.39:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.45:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.46:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.391:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.392:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@ads1.revenue[1].txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.145:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.146:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.147:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.148:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.149:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.150:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.32:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.33:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.34:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.47:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.48:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.49:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.625:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.80:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.81:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.82:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.83:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.326:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.710:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.711:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.45:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.46:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.47:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.37:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@ad.yieldmanager[3].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.381:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
::Report end
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 21:13 06-09-26
+ Scan result:
C:\Documents and Settings\Jeremy\Local Settings\Temp\18069.tmp -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Documents and Settings\TOTOF\Local Settings\Temporary Internet Files\Content.IE5\QX6T0HGV\Setup[1].exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Documents and Settings\TOTOF\Mes documents\Mes vidéos\Setup.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-776561741-117609710-1177238915-1007\Dc13.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SystemDoctor 2006 Free -> Adware.SystemDoctor2006 : Cleaned with backup (quarantined).
C:\Program Files\Fichiers communs\WinFixer 2005\FCrXML.dll -> Adware.Winfixer : Cleaned with backup (quarantined).
C:\Documents and Settings\TOTOF\Application Data\errorsafescannerinstall_fr[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored.
:mozilla.151:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.152:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.46:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.51:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.55:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.56:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.62:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@aolfr.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@metacafe.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@aolfr.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@boonty.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.382:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.383:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.384:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.568:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.593:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.626:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.632:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\TOTOF\Local Settings\Temp\Cookies\totof@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.565:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.566:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.567:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
:mozilla.124:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.125:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.351:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.352:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.353:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.50:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.51:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.30:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.25:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.52:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.692:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.693:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.388:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.389:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.390:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.231:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.645:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@com[2].txt -> TrackingCookie.Com : Cleaned.
:mozilla.95:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.386:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@c.enhance[1].txt -> TrackingCookie.Enhance : Cleaned.
:mozilla.166:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
:mozilla.49:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.35:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.36:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.37:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.38:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.39:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.40:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.41:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.42:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.43:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.44:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@cityclub.gamingpromo[2].txt -> TrackingCookie.Gamingpromo : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@gamingpromo[2].txt -> TrackingCookie.Gamingpromo : Cleaned.
:mozilla.232:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.366:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.369:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.401:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.417:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\Copie (3) de utilisateur1@ivwbox[1].txt -> TrackingCookie.Ivwbox : Cleaned.
:mozilla.359:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.360:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.22:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@banner.newyorkcasino[1].txt -> TrackingCookie.Newyorkcasino : Cleaned.
:mozilla.167:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.168:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.385:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@data4.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@ads.planetactive[1].txt -> TrackingCookie.Planetactive : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@ads.realcastmedia[1].txt -> TrackingCookie.Realcastmedia : Cleaned.
:mozilla.19:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.20:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.21:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.22:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.23:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.24:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.25:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.26:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.27:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.28:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.29:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.37:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.38:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.39:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.45:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.46:C:\Documents and Settings\TOTOF\Application Data\Mozilla\Firefox\Profiles\zpynid9w.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.391:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.392:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@ads1.revenue[1].txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.145:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.146:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.147:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.148:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.149:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.150:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.32:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.33:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.34:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.47:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.48:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.49:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.625:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.80:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.81:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.82:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.83:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.326:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.710:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.711:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.45:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.46:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.47:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.37:C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\cxbeiohz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Jeremy\Cookies\jeremy@ad.yieldmanager[3].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\TOTOF\Cookies\totof@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Utilisateur1\Cookies\utilisateur1@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.381:C:\Documents and Settings\Utilisateur1\Application Data\Mozilla\Firefox\Profiles\pkjkonq5.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
::Report end
c'est sale la dedans !
Fait ce nettoyage: (à faire réguliérement)
¤Telecharges et installes ceci:
CCleaner:
Télécharger Ccleaner
dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis cliques en bas sur "chercher des erreurs" une fois finit, cliques sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
Les sauvegardes que tu aura faites tu pourra les supprimer si ton ordinateur n'a plus de problémes
¤Relance Ccleaner, vas dans l'onglet "nettoyeur" present sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"
Redémarres le PC en mode sans échec : tu tapotes sur la touche F8 de ton clavier (ou F5 ) et tu choisis le mode sans échec)
- Ouvre le dossier "SmitfraudFix" et double clic sur "Smitfraudfix.cmd", choisit l 'option 2 et tu réponds oui à tout.
Copie/colle le rapport sur le forum stp.
Fait ce nettoyage: (à faire réguliérement)
¤Telecharges et installes ceci:
CCleaner:
Télécharger Ccleaner
dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis cliques en bas sur "chercher des erreurs" une fois finit, cliques sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
Les sauvegardes que tu aura faites tu pourra les supprimer si ton ordinateur n'a plus de problémes
¤Relance Ccleaner, vas dans l'onglet "nettoyeur" present sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"
Redémarres le PC en mode sans échec : tu tapotes sur la touche F8 de ton clavier (ou F5 ) et tu choisis le mode sans échec)
- Ouvre le dossier "SmitfraudFix" et double clic sur "Smitfraudfix.cmd", choisit l 'option 2 et tu réponds oui à tout.
Copie/colle le rapport sur le forum stp.