Win32 adware.h

Résolu
ankhaz -  
afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   -
Bonjour à toutes et tous,

Depuis quelques temps, j'avais des trucs bizarres sur mon ordi :
souris qui se déplace toute seule,
quand je voulais fermer un fichier word, j'avais un message comme quoi un autre utlisateur l'utilisait déjà, où alors le programme ne répond plus

Je fais toutes les semaines un scan complet avec avast, il ne trouvait rien,
aujourdh'hui sur les bons conseils de ce forum, j'ai installé zone alarme, et comme on me le proposait après l'installation, j'ai fait un scan pour chercher des logiciels espions.
Et là il m'a trouvé le trojan : "win32 adware.H" Je l'ai mis en quarantaine,

Est-ce-que je le supprime ?

Sinon, quand je fais les scans avast, à la fin, j'ai un message avec une liste de lignes qu'il n'a pas pu scanner, et quand je cllic sur le bouton action, soit je n'ai pas accès aux fonctionnalités de cette option, soit quand je sélectionne une ligne et que j'essaye de la mettre en quarantaine, ça me met qu'une erreure s'est produite.

Dernière précision: j'ai donc avast en antivirus, zone alarme en parefeu, ad adware pour les spywares, et aussi c cleaner pour nettoyer l'ordi.

MERCI d'avance à toutes les bonnes âmes qui me donneront leurs conseils.
Configuration: Windows XP
Firefox 2.0.0.12

39 réponses

  • 1
  • 2
Résumé de la discussion

Des comportements inexpliqués sur un PC Windows sont signalés, avec une souris qui se déplace toute seule, des messages indiquant qu'un autre utilisateur utilise un fichier et des applications qui ne répondent plus. Suite à plusieurs scans avec Avast et ZoneAlarm, détection d'un trojan win32 adware.H conduit à la mise en quarantaine et à la question de sa suppression, ainsi que sur l'incapacité de certains éléments à scanner. Parmi les réponses, un rapport d'AntiVir PersonalEdition Classic détaille les éléments scannés, les modules impliqués et les fichiers non accessibles, ce qui illustre les limites rencontrées lors du scan et du traitement des alertes.

Généré automatiquement par IA
sur la base des meilleures réponses
  1. ankhaz
     
    AntiVir PersonalEdition Classic
    Report file date: dimanche 9 mars 2008 20:24

    Scanning for 1137479 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: marine
    Computer name: M30

    Version information:
    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
    ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 19:12:10
    ANTIVIR2.VDF : 7.0.3.3 2048 Bytes 07/03/2008 19:12:10
    ANTIVIR3.VDF : 7.0.3.5 6144 Bytes 07/03/2008 19:12:10
    AVEWIN32.DLL : 7.6.0.73 3334656 Bytes 09/03/2008 19:12:11
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
    AVPACK32.DLL : 7.6.0.3 360488 Bytes 09/03/2008 19:12:11
    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
    Configuration settings for the scan:
    Jobname..........................: Manual Selection
    Configuration file...............: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\folder.avp
    Logging..........................: high
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: on
    Scan boot sector.................: on
    Boot sectors.....................: D:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: on
    Scan all files...................: All files
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: dimanche 9 mars 2008 20:24

    Starting search for hidden objects.
    The driver could not be initialized.

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Module is OK -> 'c:\program files\avira\antivir personaledition classic\avscan.exe'
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Module is OK -> 'C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe'
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Module is OK -> 'C:\WINDOWS\Explorer.EXE'
    Scan process 'ZCfgSvc.exe' - '1' Module(s) have been scanned
    Module is OK -> 'C:\WINDOWS\system32\ZCfgSvc.exe'
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Module is OK -> 'C:\WINDOWS\system32\svchost.exe'
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Module is OK -> 'C:\WINDOWS\system32\svchost.exe'
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Module is OK -> 'C:\WINDOWS\system32\svchost.exe'
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Module is OK -> 'C:\WINDOWS\system32\lsass.exe'
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Module is OK -> 'C:\WINDOWS\system32\services.exe'
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Module is OK -> 'C:\WINDOWS\system32\winlogon.exe'
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Module is OK -> 'C:\WINDOWS\system32\csrss.exe'
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    Module is OK -> 'C:\WINDOWS\\System32\smss.exe'
    12 processes with 12 modules were scanned

    Starting master boot sector scan:
    Master boot sector HD0
    [NOTE] No virus was found!

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!
    Starting to scan the registry.
    C:\WINDOWS\system32\
    rundll32.exe
    [NOTE] HKEY_LOCAL_MACHINE\RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    C:\WINDOWS\system32\
    nvcpl.dll
    [NOTE] HKEY_LOCAL_MACHINE\RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    C:\WINDOWS\system32\
    nwiz.exe
    [NOTE] HKEY_LOCAL_MACHINE\nwiz.exe /installquiet
    C:\WINDOWS\system32\
    00THotkey.exe
    [NOTE] HKEY_LOCAL_MACHINE\C:\WINDOWS\System32\00THotkey.exe
    C:\WINDOWS\system32\
    000StTHK.exe
    [NOTE] HKEY_LOCAL_MACHINE\000StTHK.exe
    C:\WINDOWS\system32\
    TFNF5.exe
    [NOTE] HKEY_LOCAL_MACHINE\TFNF5.exe
    C:\Program Files\SigmaTel\Pilotes Audio SigmaTel AC97\
    stacmon.exe
    [NOTE] HKEY_LOCAL_MACHINE\C:\Program Files\SigmaTel\Pilotes Audio SigmaTel AC97\stacmon.exe
    C:\Program Files\Synaptics\SynTP\
    SynTPLpr.exe
    [NOTE] HKEY_LOCAL_MACHINE\C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\
    SynTPEnh.exe
    [NOTE] HKEY_LOCAL_MACHINE\C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Toshiba\TouchED\
    TouchED.exe
    [NOTE] HKEY_LOCAL_MACHINE\C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
    C:\WINDOWS\
    ltsmmsg.exe
    [NOTE] HKEY_LOCAL_MACHINE\LTSMMSG.exe
    C:\WINDOWS\system32\
    TPSMain.exe
    [NOTE] HKEY_LOCAL_MACHINE\TPSMain.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\
    jusched.exe
    [NOTE] HKEY_LOCAL_MACHINE\C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    c:\Program Files\Intel\PROSetWireless\NCS\PROSet\
    PRONoMgr.exe
    [NOTE] HKEY_LOCAL_MACHINE\c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\
    WkUFind.exe
    [NOTE] HKEY_LOCAL_MACHINE\C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
    C:\
    qttask.exe
    [NOTE] HKEY_LOCAL_MACHINE\"C:\qttask.exe" -atboottime
    C:\WINDOWS\system32\
    crypt32.dll
    [NOTE] HKEY_LOCAL_MACHINE\crypt32.dll
    C:\WINDOWS\system32\
    cryptnet.dll
    [NOTE] HKEY_LOCAL_MACHINE\cryptnet.dll
    C:\WINDOWS\system32\
    cscdll.dll
    [NOTE] HKEY_LOCAL_MACHINE\cscdll.dll
    C:\WINDOWS\system32\
    wlnotify.dll
    [NOTE] HKEY_LOCAL_MACHINE\wlnotify.dll
    C:\WINDOWS\system32\
    wlnotify.dll
    [NOTE] HKEY_LOCAL_MACHINE\wlnotify.dll
    C:\WINDOWS\system32\
    sclgntfy.dll
    [NOTE] HKEY_LOCAL_MACHINE\sclgntfy.dll
    c:\WINDOWS\system32\
    LgNotify.dll
    [NOTE] HKEY_LOCAL_MACHINE\c:\WINDOWS\System32\LgNotify.dll
    C:\WINDOWS\system32\
    wlnotify.dll
    [NOTE] HKEY_LOCAL_MACHINE\WlNotify.dll
    C:\WINDOWS\system32\
    wlnotify.dll
    [NOTE] HKEY_LOCAL_MACHINE\wlnotify.dll
    C:\WINDOWS\system32\
    WgaLogon.dll
    [NOTE] HKEY_LOCAL_MACHINE\WgaLogon.dll
    C:\WINDOWS\system32\
    wlnotify.dll
    [NOTE] HKEY_LOCAL_MACHINE\wlnotify.dll
    C:\Program Files\Toshiba\TOSCDSPD\
    TOSCDSPD.exe
    [NOTE] HKEY_CURRENT_USER\C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\WINDOWS\system32\
    ctfmon.exe
    [NOTE] HKEY_CURRENT_USER\C:\WINDOWS\system32\ctfmon.exe
    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
    desktop.ini
    [NOTE] HKEY_LOCAL_MACHINE\C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\desktop.ini
    C:\WINDOWS\system32\
    desktop.ini
    [NOTE] HKEY_LOCAL_MACHINE\C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\desktop.ini
    C:\WINDOWS\system32\
    desktop.ini
    [NOTE] HKEY_LOCAL_MACHINE\C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\desktop.ini
    C:\WINDOWS\system32\
    desktop.ini
    [NOTE] HKEY_LOCAL_MACHINE\C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\desktop.ini
    C:\WINDOWS\system32\
    desktop.ini
    [NOTE] HKEY_LOCAL_MACHINE\C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\desktop.ini
    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
    Lancement rapide d'Adobe Reader.lnk
    [NOTE] HKEY_LOCAL_MACHINE\C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
    C:\Program Files\Adobe\Acrobat 7.0\Reader\
    reader_sl.exe
    [NOTE] HKEY_LOCAL_MACHINE\C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
    Lancement rapide de Microsoft Office OneNote 2003.lnk
    [NOTE] HKEY_LOCAL_MACHINE\C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide de Microsoft Office OneNote 2003.lnk
    C:\Program Files\Microsoft Office\OFFICE11\
    ONENOTEM.EXE
    [NOTE] HKEY_LOCAL_MACHINE\C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide de Microsoft Office OneNote 2003.lnk
    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
    Microsoft Office.lnk
    [NOTE] HKEY_LOCAL_MACHINE\C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
    C:\Program Files\Microsoft Office\Office10\
    OSA.EXE
    [NOTE] HKEY_LOCAL_MACHINE\C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
    RAMASST.lnk
    [NOTE] HKEY_LOCAL_MACHINE\C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\RAMASST.lnk
    C:\WINDOWS\system32\
    RAMASST.exe
    [NOTE] HKEY_LOCAL_MACHINE\C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\RAMASST.lnk
    C:\Documents and Settings\marine\Menu Démarrer\Programmes\Démarrage\
    desktop.ini
    [NOTE] HKEY_CURRENT_USER\C:\Documents and Settings\marine\Menu Démarrer\Programmes\Démarrage\desktop.ini
    C:\WINDOWS\system32\
    desktop.ini
    [NOTE] HKEY_CURRENT_USER\C:\Documents and Settings\marine\Menu Démarrer\Programmes\Démarrage\desktop.ini
    C:\WINDOWS\system32\
    desktop.ini
    [NOTE] HKEY_CURRENT_USER\C:\Documents and Settings\marine\Menu Démarrer\Programmes\Démarrage\desktop.ini
    C:\WINDOWS\system32\
    desktop.ini
    [NOTE] HKEY_CURRENT_USER\C:\Documents and Settings\marine\Menu Démarrer\Programmes\Démarrage\desktop.ini
    C:\Documents and Settings\Default User\Menu Démarrer\Programmes\Démarrage\
    desktop.ini
    [NOTE] HKEY_USERS\C:\Documents and Settings\Default User\Menu Démarrer\Programmes\Démarrage\desktop.ini
    C:\WINDOWS\system32\
    desktop.ini
    [NOTE] HKEY_USERS\C:\Documents and Settings\Default User\Menu Démarrer\Programmes\Démarrage\desktop.ini
    C:\WINDOWS\system32\
    desktop.ini
    [NOTE] HKEY_USERS\C:\Documents and Settings\Default User\Menu Démarrer\Programmes\Démarrage\desktop.ini
    C:\WINDOWS\system32\
    desktop.ini
    [NOTE] HKEY_USERS\C:\Documents and Settings\Default User\Menu Démarrer\Programmes\Démarrage\desktop.ini
    C:\WINDOWS\system32\
    desktop.ini
    [NOTE] HKEY_USERS\C:\Documents and Settings\Default User\Menu Démarrer\Programmes\Démarrage\desktop.ini
    The registry was scanned ( '51' files ).

    Starting the file scan:

    Begin scan in 'C:\'
    C:\
    Auth.prof
    AUTOEXEC.BAT
    boot.ini
    Bootfont.bin
    CONFIG.SYS
    DBS.TXT
    debugInstaller.txt
    DownUtubeB3R3.zip
    [0] Archive type: ZIP
    --> dt.exe.config
    --> OpenSmtp.dll
    --> langs/eng.ico
    --> langs/eng.lng
    --> langs/esp.ico
    --> langs/esp.lng
    --> langs/rom.ico
    --> langs/rom.lng
    --> langs/tr.ico
    --> langs/tr.lng
    --> CThumb.dll
    --> dt.exe
    Firefox Setup 2.0.exe
    FirefoxGoogleToolbarSetup.exe
    Grey's Anatomy - 1x09 - Chacun Ses Secrets (Dvd) French.avi
    Grey's Anatomy.S02E26-27.Rester ou fuir - Indécision et cas de conscience.avi
    INSTALL.log
    IO.SYS
    LGSInst.log
    Money2 Sauvegarde.mbf
    [0] Archive type: CAB (Microsoft)
    --> mbf7.tmp
    Money2.mny
    mp10setup.exe
    MSDOS.SYS
    NTDETECT.com
    ntldr
    odebit.exe
    pagefile.sys
    [WARNING] The file could not be opened!
    [WARNING] Error code: 0x000D
    [WARNING] Access error/file locked!
    PictureViewer.exe
    QTInfo.exe
    QTOControl.dll
    QTOLibrary.dll
    QTPlugin.ocx
    qttask.exe
    QTUIPanelControl.dll
    QuickTime Read Me.htm
    QuickTimePlayer.exe
    Sample.mov
    Sample.qtif
    SDFix.exe
    [0] Archive type: RAR SFX (self extracting)
    --> SDFix\apps\leg2.txt
    --> SDFix\apps\legacy.txt
    --> SDFix\apps\Rem.txt
    --> SDFix\apps\Rem2.txt
    --> SDFix\apps\srv2.txt
    --> SDFix\apps\svc.txt
    --> SDFix\RunThis.bat
    --> SDFix\apps\locate.com
    --> SDFix\catchme.exe
    --> SDFix\apps\cliptext.exe
    --> SDFix\apps\download.exe
    --> SDFix\apps\ERUNT.EXE
    --> SDFix\apps\FixPath.exe
    --> SDFix\apps\grep.exe
    --> SDFix\apps\isadmin.exe
    --> SDFix\apps\LS.exe
    --> SDFix\apps\MD5File.exe
    --> SDFix\apps\Process.exe
    --> SDFix\apps\procs.exe
    --> SDFix\apps\psservice.exe
    --> SDFix\apps\Replace\regedit.exe
    --> SDFix\apps\RestartIt!.exe
    --> SDFix\apps\sc.exe
    --> SDFix\apps\sed.exe
    --> SDFix\apps\SF.exe
    --> SDFix\apps\shutdown.exe
    --> SDFix\apps\swreg.exe
    --> SDFix\apps\swsc.exe
    --> SDFix\apps\unzip.exe
    --> SDFix\apps\vfind.exe
    --> SDFix\apps\Replace\W2K.exe
    [1] Archive type: ZIP SFX (self extracting)
    --> autoexec.nt
    --> command.com
    --> config.nt
    --> SDFix\apps\WINMSG.EXE
    --> SDFix\apps\Replace\XP.exe
    [1] Archive type: ZIP SFX (self extracting)
    --> command.com
    --> AUTOEXEC.nt
    --> SDFix\apps\zip.exe
    --> SDFix\apps\Replace\w2k\beep.sys
    --> SDFix\apps\Replace\xp\beep.sys
    --> SDFix\apps\dummy.sys
    --> SDFix\apps\Replace\w2k\null.sys
    --> SDFix\apps\Replace\xp\null.sys
    --> SDFix\apps\ERDNT.E_E
    --> SDFix\apps\ERDNTDOS.loc
    --> SDFix\apps\ERDNTWIN.loc
    --> SDFix\apps\ERUNT.loc
    --> SDFix\apps\assosfix.reg
    --> SDFix\apps\Enable_Command_Prompt.reg
    --> SDFix\apps\fix.reg
    --> SDFix\apps\FixBH.reg
    --> SDFix\apps\FixComponents.reg
    --> SDFix\apps\FIXCU.reg
    --> SDFix\apps\FIXLM.reg
    --> SDFix\apps\FixRedir.reg
    --> SDFix\apps\FixSchedule.reg
    --> SDFix\apps\FixWebCheck.reg
    --> SDFix\apps\fixXP.reg
    --> SDFix\apps\FixXPsp2.reg
    --> SDFix\apps\HPFix.reg
    --> SDFix\apps\HPFix2.reg
    --> SDFix\apps\HPFix3.reg
    --> SDFix\apps\HPFix4.reg
    --> SDFix\apps\HPFix5.reg
    --> SDFix\apps\HPFix6.reg
    --> SDFix\apps\HPFix7.reg
    --> SDFix\apps\MyGcpvFix.reg
    --> SDFix\apps\MyGkFix2.reg
    --> SDFix\apps\Reset_AppInit_DLLs.reg
    --> SDFix\apps\Restore_SecurityCenter.reg
    --> SDFix\apps\Restore_SharedAccess.reg
    --> SDFix\apps\winsec.reg
    --> SDFix\SDFIX_ReadMe_Online.url
    setupfre.exe
    setupfre.exe:Zone.Identifier
    SWSTAMP.txt
    tonightshow112206.zip
    [0] Archive type: ZIP
    --> tonightshow112206.wmv
    TVUPlayer.zip
    [0] Archive type: ZIP
    --> TVUPlayer2.3.0.exe
    UNWISE.EXE

    C:\Documents and Settings\Administrateur\
    NTUSER.dat
    ntuser.dat.log
    ntuser.ini
    C:\Documents and Settings\Administrateur\Application Data\
    desktop.ini
    C:\Documents and Settings\Administrateur\Application Data\Adobe\Acrobat\6.0\
    TMGrpPrm.sav
    C:\Documents and Settings\Administrateur\Application Data\Adobe\Acrobat\6.0\AcroForm\
    MRUFormsList
    C:\Documents and Settings\Administrateur\Application Data\Adobe\Acrobat\6.0\Collab\
    OfflineDocs
    Reviews
    C:\Documents and Settings\Administrateur\Application Data\Adobe\Acrobat\6.0\Updater\
    udstore.js
    C:\Documents and Settings\Administrateur\Application Data\Microsoft\Internet Explorer\
    brndlog.bak
    brndlog.txt
    Desktop.htt
    C:\Documents and Settings\Administrateur\Application Data\Microsoft\Internet Explorer\Quick Launch\
    Bureau.scf
    desktop.ini
    Démarrer Internet Explorer.lnk
    C:\Documents and Settings\Administrateur\Application Data\Microsoft\Protect\
    CREDHIST
    C:\Documents and Settings\Administrateur\Application Data\Microsoft\Protect\S-1-5-21-2034529978-2815154264-1435429344-1003\
    b3db18e6-5352-45a2-854c-00d86647c042
    Preferred
    C:\Documents and Settings\Administrateur\Application Data\Microsoft\Protect\S-1-5-21-527237240-764733703-1957994488-1003\
    be2fff41-f16b-4290-8780-da0e48e3b528
    Preferred
    C:\Documents and Settings\Administrateur\Application Data\Microsoft\Windows\Themes\
    Custom.theme
    C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\
    profiles.ini
    C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\hzsgrats.default\
    bookmarks.bak
    bookmarks.html
    cert8.db
    compatibility.ini
    compreg.dat
    extensions.cache
    extensions.ini
    extensions.rdf
    history.dat
    hostperm.1
    key3.db
    localstore.rdf
    metrics.xml
    mimeTypes.rdf
    prefs.js
    search.rdf
    search.sqlite
    secmod.db
    urlclassifier2.sqlite
    xpti.dat
    C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\hzsgrats.default\bookmarkbackups\
    bookmarks-2008-02-24.html
    C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\hzsgrats.default\chrome\
    userChrome-example.css
    userContent-example.css
    C:\Documents and Settings\Administrateur\Application Data\Sun\Java\Deployment\
    deployment.properties
    C:\Documents and Settings\Administrateur\Application Data\Talkback\MozillaOrg\Firefox2\Win32\2008020121\
    manifest.ini
    permdata.box
    C:\Documents and Settings\Administrateur\Bureau\
    V92 Modem.html
    C:\Documents and Settings\Administrateur\Cookies\
    index.dat
    C:\Documents and Settings\Administrateur\Favoris\
    Desktop.ini
    Guide des stations de radio.url
    MSN.com.url
    C:\Documents and Settings\Administrateur\Favoris\Liens\
    Hotmail.url
    Personnaliser les liens.url
    Windows Media.url
    Windows.url
    C:\Documents and Settings\Administrateur\Favoris\Liens financiers\
    MSN Auto Moto.url
    MSN Communautés.url
    MSN Finances Immobilier.url
    MSN Finances.url
    MSN France.url
    MSN Hotmail.url
    MSN Live.url
    MSN Search.url
    MSN Shopping.url
    C:\Documents and Settings\Administrateur\Local Settings\
    desktop.ini
    C:\Documents and Settings\Administrateur\Local Settings\Application Data\
    IconCache.db
    C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Media Player\
    CurrentDatabase_59R.wmdb
    C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Windows\
    UsrClass.dat
    UsrClass.dat.log
    C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Windows Media\9.0\
    WMSDKNS.dtd
    WMSDKNS.xml
    C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Works\Portfolio\
    Exemple.wsb
    C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\hzsgrats.default\
    XPC.mfl
    XUL.mfl
    C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\hzsgrats.default\Cache\
    _CACHE_001_
    _CACHE_002_
    _CACHE_003_
    _CACHE_MAP_
    C:\Documents and Settings\Administrateur\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}\
    1036.MST
    Java 2 Runtime Environment, SE v1.4.2.msi
    C:\Documents and Settings\Administrateur\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}\
    1036.MST
    Java 2 Runtime Environment, SE v1.4.2_03.msi
    C:\Documents and Settings\Administrateur\Local Settings\Historique\
    desktop.ini
    C:\Documents and Settings\Administrateur\Local Settings\Historique\History.IE5\
    desktop.ini
    index.dat
    C:\Documents and Settings\Administrateur\Local Settings\Historique\History.IE5\MSHist012003101020031011\
    index.dat
    C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\
    desktop.ini
    C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\
    desktop.ini
    index.dat
    C:\Documents and Settings\Administrateur\Menu Démarrer\
    desktop.ini
    C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\
    Assistance à distance.lnk
    desktop.ini
    Internet Explorer.lnk
    Outlook Express.lnk
    C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Accessoires\
    Assistant Compatibilité des programmes.lnk
    Bloc-notes.lnk
    Carnet d'adresses.lnk
    desktop.ini
    Explorateur Windows.lnk
    Invite de commandes.lnk
    Synchroniser.lnk
    Visite guidée de Windows XP.lnk
    C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Accessoires\Accessibilité\
    Clavier visuel.lnk
    desktop.ini
    Gestionnaire d'utilitaires.lnk
    Loupe.lnk
    C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Accessoires\Divertissement\
    desktop.ini
    Lecteur Windows Media.lnk
    C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\
    desktop.ini
    C:\Documents and Settings\Administrateur\Mes documents\
    desktop.ini
    C:\Documents and Settings\Administrateur\Mes documents\Ma musique\
    Desktop.ini
    Échantillons de musique.lnk
    C:\Documents and Settings\Administrateur\Mes documents\Mes images\
    Desktop.ini
    Échantillons d'images.lnk
    C:\Documents and Settings\Administrateur\Modèles\
    amipro.sam
    excel.xls
    excel4.xls
    lotus.wk4
    powerpnt.ppt
    presenta.shw
    quattro.wb2
    sndrec.wav
    winword.doc
    winword2.doc
    wordpfct.wpd
    wordpfct.wpg
    C:\Documents and Settings\Administrateur\Recent\
    Desktop.ini
    C:\Documents and Settings\Administrateur\SendTo\
    Bureau (créer un raccourci).DeskLink
    desktop.ini
    Destinataire.MAPIMail
    Dossier compressé.ZFSendToTarget
    Mes documents.mydocs
    C:\Documents and Settings\All Users\
    NTUSER.dat
    NTUSER.DAT.log
    C:\Documents and Settings\All Users\Application Data\
    addr_file.html
    desktop.ini
    C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\7.0\Replicate\Security\
    directories.acrodata
    C:\Documents and Settings\All Users\Application Data\Apple Computer\QuickTime\
    QuickTime.qtp
    QuickTimeFavorites.qtr
    C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\
    addr_file.html
    AVWIN.ini
    update.conf
    C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\EVENTDB\
    avevtdb.dbe
    C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\IDX\
    classic-nt-en.info
    C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\JOBS\
    scanjob.avj
    startupd.avj
    updjob.avj
    C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\LOGFILES\
    avguard.log
    AVSCAN-20080309-202430-410E74E7.log
    sched.log
    setup.log
    setup00.log
    Upd-2008-03-09-20-02-09.log
    C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\
    folder.avp
    rootkit.avp
    C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\REPORTS\
    53eab569.avl
    C:\Documents and Settings\All Users\Application Data\Azureus\
    azCID.txt
    C:\Documents and Settings\All Users\Application Data\Google\Custom Buttons\
    toolbar.google.com_J66T77NJDBMW4FEUU7FA.xml
    toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.xml
    C:\Documents and Settings\All Users\Application Data\MailFrontier\
    reginfo.xml
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\
    6d14e4b1d8ca773bab785d1be032546e_0745ace1-acbd-4a68-8b06-db81f3d54d15
    d42cc0c3858a58db2db37658219e6400_0745ace1-acbd-4a68-8b06-db81f3d54d15
    C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\
    drwtsn32.log
    user.dmp
    C:\Documents and Settings\All Users\Application Data\Microsoft\Encarta Reference Library\E04FSTRC\Updates\
    UPDATE04.TXT
    C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\
    hhcolreg.dat
    C:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\
    ppcrlconfig.dll
    C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\
    wmplibrary_v_0_12.db
    C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\
    DefaultStore_59R.bin
    UserMigratedStore_59R.bin
    C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\
    1ptrans.gif
    about.dat
    accounts.gif
    actvstmt.gif
    alertdlg.gif
    alerts.gif
    asset.ini
    backuphelp.htm
    banking.gif
    bdgtwlcm.bmp
    bdgtwlcm.htm
    bills.gif
    blmaptop.gif
    bluebot.gif
    bluetop.gif
    book.gif
    bottomleft.gif
    bottomright.gif
    broker.gif
    brwsanim.gif
    brwslogo.gif
    canceled.htm
    champagne.jpg
    clear.gif
    college.dat
    communty.ini
    congrats.gif
    congratstype.gif
    contfbck.htm
    conversion.gif
    conversiontype.gif
    creditqa.ini
    creditReport.xml
    datasrcschema.xml
    debtwlcm.bmp
    debtwlcm.htm
    defenrll.htm
    defserv.htm
    dynaerr.ini
    ebpp.ini
    find_stock.gif
    fipartnr.ini
    fpgoals.fpd
    funds.gif
    fyi_hme.gif
    getting started.htm
    GettingISP.htm
    go.gif
    golf.jpg
    gradation_bar.gif
    grebot.gif
    gretop.gif
    greydot.gif
    grnchk.gif
    header.gif
    headline.ini
    HHsku.xml
    hpthemes.xml
    info.gif
    interest.gif
    invacct.htm
    InvestmentQIFImport.htm
    InvestmentResearch.htm
    invhome.bmp
    invhome.htm
    invhsel.bmp
    invlink.csv
    invport.htm
    InvResearchOnline.htm
    iueaccounts.gif
    iuebills.gif
    iuecongrats.gif
    iuedetails.gif
    iueentry.gif
    iuefavorites.gif
    iuelauchpad.gif
    iuename.gif
    iueonline.gif
    iuepaycheck.gif
    iueplans.gif
    iuepriorities.gif
    iuereview.gif
    iueverify.gif
    iue_priority.gif
    line.gif
    logomsnshopping.gif
    ltwelco2.htm
    ltwelcom.bmp
    ltwelcom.htm
    mc.gif
    mc.htm
    mc.ico
    mcleft.htm
    mcmodule.ini
    mcright.htm
    misurls.xml
    mnycntrl.gif
    mnylogo.gif
    mnypass.ini
    mny_schema.xml
    moreinfo.dat
    msmoney.aw
    msmoney.chm
    [0] Archive type: CHM
    --> /#SYSTEM
    --> /LearnwhattodofirstinMoney.htm
    --> /FindOutWhatsNewInMoney.htm
    --> /Learnaboutmoneyssetupassistant.htm
    --> /Vieworeditinformationinmoneyssetupassistant.htm
    --> /moneytoc.htm
    --> /Learnaboutprioritiesinmoney.htm
    --> /Learnaboutprioritystatus.htm
    --> /LearnaboutmyFinancialHomePageinMoney.htm
    --> /Learnaboutthetaskviewhomepage.htm
    --> /Learnwhatsnewonthemoneyhomepage.htm
    --> /NavigatearoundMoney.htm
    --> /LearnAboutAdvisorFYI.htm
    --> /Learnaboutmoneyandwindowsxp.htm
    --> /LearnaboutgoodMoneyhabits.htm
    --> /FollowAToDoListDaily.htm
    --> /FollowAToDoListWeekly.htm
    --> /FollowAToDoListMonthly.htm
    --> /FollowAToDoListAnnually.htm
    --> /TeachMyChildrenAboutMoney.htm
    --> /LearnAboutWaysToGetHelp.htm
    --> /OpenOrCloseMoneyHelp.htm
    --> /LearnAboutMoneyHelp.htm
    --> /MakeHelpPaneBigger.htm
    --> /SeeListOfAllMoneysHelpTopics.htm
    --> /LearnaboutworkingwithMoneyfiles.htm
    --> /Repaircorruptedfilesfromcommandline.htm
    --> /LearnTheDifferenceBetweenAFileAndAnAccount.htm
    --> /CreateANewFile.htm
    --> /OpenAFile.htm
    --> /OpenAFileFromAPreviousVersionOfMoney.htm
    --> /OpenMoneysSampleFile.htm
    --> /SaveMyWork.htm
    --> /AssignChangeorDeleteAPassword.htm
    --> /SplitAFileIntoTwoFiles.htm
    --> /SwitchBetweenMoneyFiles.htm
    --> /Repaircorruptedfiles2002.htm
    --> /LearnAbouttheMiniDebtReductionPlanner.htm
    --> /MakeSureIAlwaysHaveABackup.htm
    --> /AutomaticallyBackUpMyFileWhenExiting.htm
    --> /BackUpMyFile.htm
    --> /MakeMyBackupFileSmall.htm
    --> /RestoreABackupFile.htm
    --> /ChangeMyBackupOptions.htm
    --> /LearnTheDifferenceBetweenBackingUpAndArchiving.htm
    --> /Learnaboutarchivinginformation.htm
    --> /RetrieveArchivedInformation.htm
    --> /ArchiverYourRecords.htm
    --> /Chooseanarchivedate.htm
    --> /Replaceanarchivedfilewithanewone.htm
    --> /Troubleshootarchiving.htm
    --> /ImportAFileIntoMoney.htm
    --> /ExportAnAccount.htm
    --> /ChangeMoneyOptions.htm
    --> /Customizeyourhomepageview.htm
    --> /defasset.htm
    --> /Learnaboutthemoneytoolbar.htm
    --> /Customizethemoneytoolbar.htm
    --> /Vieworchangefinancialnews.htm
    --> /AddorremoveapriorityfromyourMoneyfile.htm
    --> /Removeadsinmoney.htm
    --> /ChangeMyStartupLocation.htm
    --> /HTMLLinkChecker
    --> /mny02hh.xsl
    --> /defbasis.htm
    --> /InsertDecimalPointsAutomatically.htm
    --> /LearnAboutDates.htm
    --> /CustomizeAdvisorFYI.htm
    --> /TurnMoneyconfirmationmessagesonoroff.htm
    --> /SetColorSchemeForMoney.htm
    --> /ChangeMoneyssounds.htm
    --> /TurnMoneyssoundsonoroff.htm
    --> /defbond.htm
    --> /Troubleshootthemoneytoolbar.htm
    --> /LearnAboutMSNAlertsandMicrosoftPassport.htm
    --> /LearnAboutTheDifferenceBetweenMSNAlertsandAdvisorFYI.htm
    --> /LearnAboutTrackingYourCreditInMoney.htm
    --> /SignUpToTrackYourCreditinMoney.htm
    --> /PrepareAQuickenFileForConversionToMoney.htm
    --> /LearnAboutConvertingAQuickenFile.htm
    --> /ResolveAccountBalancesAfterConversion.htm
    --> /VerifyThatYourDataConvertedSuccessfully.htm
    --> /FindOutTheIssuesRelatedToQIFImportFiles.htm
    --> /ConvertAQuickenFileToMoney.htm
    --> /defcall.htm
    --> /HTML Link Checker HO2.log
    --> /ResolveEndingBalanceDifferencesAfterImportingAQIFFile.htm
    --> /LearnHowQuickenFileElementsConvertInMoney.htm
    --> /FindQuickenCommandsInMoney.htm
    --> /UseQuickenKeyboardShortcuts.htm
    --> /SwitchQuickenOnlineServicesToMoney.htm
    --> /Troubleshootconvertingquickenbudgets.htm
    --> /KeyboardShortcuts.htm
    --> /HowYouCanUseMoneysBillsandDeposits.htm
    --> /Createanaccount.htm
    --> /Decidewhatamounttouseforanopeningbalance.htm
    --> /UseAbbreviationsinTransactions.htm
    --> /ChangeAccountDetails.htm
    --> /Assignabanktoanexistingaccount.htm
    --> /Viewcontactdetailsforabankorbroker.htm
    --> /Viewaccounthistory.htm
    --> /MoveAnAccountToADifferentFile.htm
    --> /Learnthedifferencebetweenclosedanddeletedaccounts.htm
    --> /Closeanaccount.htm
    --> /Deleteanaccount.htm
    --> /TroubleshootAccountSetup.htm
    --> /LearnabouttheAccountOrganizer.htm
    --> /Regroupaccountsandbanksinmylistofaccounts.htm
    --> /Makeanaccountafavoriteaccount.htm
    --> /Viewmyfavoriteaccounts.htm
    --> /Showclosedaccounts.htm
    --> /LearnabouttheAccountRegister.htm
    --> /Changethebalancescreentomatchmystatement.htm
    --> /DisplaytransactionformsintheAccountRegister.htm
    --> /EnterpayeesaddressfromtheAccountRegister.htm
    --> /changedaterangeinaccountregister.htm
    --> /TroubleshootAccountRegister.htm
    --> /Learnaboutcommontransactions.htm
    --> /Enteratransaction.htm
    --> /EnteratransactiondirectlyintotheAccountRegister.htm
    --> /Entertransactionsfromapreviousmonthsstatement.htm
    --> /RecordanAutomaticTellerMachinewithdrawal.htm
    --> /markatransactionforfollowupandcleartheflag.htm
    --> /Clearafollowupflag.htm
    --> /RenewACD.htm
    --> /Restoreadeletedtransaction.htm
    --> /Learnthedifferencebetweengrossandnetpay.htm
    --> /Schedulemypaycheckdeposit.htm
    --> /LearnaboutCategoriesandSubcategories.htm
    --> /Assignacategorytoatransaction.htm
    --> /CreateaNewCategoryorSubcategory.htm
    --> /AboutCategoryGroups.htm
    --> /CreateaClassification.htm
    --> /LearnaboutClassifications.htm
    --> /Editatransaction.htm
    --> /Assignaclassificationtoatransaction.htm
    --> /Learnaboutsplittingatransactionamongmultiplecategories.htm
    --> /Splitatransactionamongmultiplecategories.htm
    --> /UsetheAccountRegisterwhenyoudownloadstatements.htm
    --> /Learnquickwaystoentertransactions.htm
    --> /LearnaboutusingAutoComplete.htm
    --> /TurnAutoCompleteonoroff.htm
    --> /Deleteatransaction.htm
    --> /SwitchbetweenTopLineOnlyandAllTransactionDetailsview.htm
    --> /Displayonlyunreconciledtransactions.htm
    --> /Markatransactionasclearedvoidorreconciled.htm
    --> /Voidatransaction.htm
    --> /Changeinformationinagroupoftransactions.htm
    --> /Sorttransactionsbydatechecknumberamountorentryorder.htm
    --> /Findaspecifictransaction.htm
    --> /HandlerefundsIvereceived.htm
    --> /Moveatransactiontoanotheraccount.htm
    --> /LearnAboutMoneyAgent.htm
    --> /TurnMoneyAgentOnorOff.htm
    --> /Changesettingsformoneyexpress.htm
    --> /learnaboutfeedbackintheaccountregisters.htm
    --> /turnfeedbackonoroff.htm
    --> /Learnaboutspendingthermometers.htm
    --> /Setorchangespendinglimitsonthermometers.htm
    --> /Hidespendingthermometers.htm
    --> /Troubleshootspendingthermometers.htm
    --> /Learnaboutclearedandreconciledtransactions.htm
    --> /Balancereconcileanaccounttopaperstatement.htm
    --> /Changeanaccountsopeningbalance.htm
    --> /Balanceacashaccount.htm
    --> /Troubleshootaccountbalancing.htm
    --> /csLocstart.css
    --> /csOnstart.css
    --> /Troubleshootdifferingbalancesbetweenmoneyandmybank.htm
    --> /LearnaboutforeigncurrenciesandMoney.htm
    --> /Correctanexchangerate.htm
    --> /FRN HO2 HTML Link Checker.log
    --> /ChangethedefaultcurrencyformyMoneyfile.htm
    --> /Changethedefaultcurrencyforanaccount.htm
    --> /DisplayandentertheEurocurrencysymbol.htm
    --> /Convertatransactionfromaforeigncurrency.htm
    --> /Updatecurrencyexchangerates.htm
    --> /LearnabouttypesofaccountsIcancreateinMoney.htm
    --> /Learnaboutbankaccounts.htm
    --> /Createacheckingaccount.htm
    --> /Learnaboutcreditcardaccounts.htm
    --> /Learnwhytotrackacreditcardasanaccountandnotabill.htm
    --> /Learnthedifferencebetweencreditcardsanddebitcards.htm
    --> /Entercreditcardpayments.htm
    --> /Trackacreditcardthroughacheckingaccount.htm
    --> /LearnaboutusingAutoBalanceforcreditcardaccounts.htm
    --> /AutoBalancemycreditcardaccount.htm
    --> /Learnaboutloanaccounts.htm
    --> /Createaloanaccount.htm
    --> /Linkaloanaccounttoitsasset.htm
    --> /EnterLoanpayments.htm
    --> /ItemizeaLoanpayment.htm
    --> /RecordExtraloanpayments.htm
    --> /Balancealoanaccount.htm
    --> /EnterLatefees.htm
    --> /ChangeLoanaccountinformation.htm
    --> /UpdateaninterestrateonanAdjustableRateMortgage.htm
    --> /enterloanrefinanceinformation.htm
    --> /Payoffmyloan.htm
    --> /Understandloanreports.htm
    --> /Figureloanaccountsintomynetworth.htm
    --> /Learnaboutassetaccounts.htm
    --> /Createanassetaccount.htm
    --> /Updateanassetorliabilityaccount.htm
    --> /Balanceanassetaccount.htm
    --> /Learnaboutliabilityaccounts.htm
    --> /Createaliabilityaccount.htm
    --> /Balancealiabilityaccount.htm
    --> /Learnaboutinvestmentaccounts.htm
    --> /Learnaboutcashaccounts.htm
    --> /KeepTrackOfMyReimbursableExpenses.htm
    --> /UseThePayBillsPageForYourBillPayingRoutine.htm
    --> /LearnAboutTrackingBillsandDeposits.htm
    --> /seehowpayingbillsaffectsaccountbalance.htm
    --> /LearnAboutSetupBillsandDeposits.htm
    --> /Customizeviewofbillsanddepositslist.htm
    --> /ScheduleaRecurringBillorDeposit.htm
    --> /CreateTwoRecurringPaymentsforPayrollChecks.htm
    --> /ScheduleOneTimeFuturePayment.htm
    --> /ScheduleRecurringInvestmentPurchase.htm
    --> /AddExistingTransactiontoYourScheduledTransactions.htm
    --> /LearnaboutBillCalendar.htm
    --> /WorkwithTransactionsfromBillCalendar.htm
    --> /Troubleshootsettingupandeditingscheduledtrans.htm
    --> /PrintListofUpcomingBills.htm
    --> /EditDetailsofScheduledTransaction.htm
    --> /RecordScheduledInvestmentPurchase.htm
    --> /SkipanUpcomingBillorDeposit.htm
    --> /PermanentlyDeleteRecurringPayment.htm
    --> /LearnaboutPotentialRecurringTransactions.htm
    --> /Viewscheduledbillsbyproperty.htm
    --> /Automaticallyenterbillsintoyourregisterbeforetheduedate.htm
    --> /Payascheduledbillorrecordascheduleddeposit.htm
    --> /ViewAccountBalancesWhenPayingBills.htm
    --> /MakePaymentstoMultipleAccountsatSameCompany.htm
    --> /LearnaboutoverduebillsanddepositsinMoney.htm
    --> /Estimatebillamountsbasedonpreviouspayments.htm
    --> /Whatispaymentdate.htm
    --> /LearnAboutRecentlyPaidBills.htm
    --> /EditDetailsofRecentlyRecordedScheduledTransactions.htm
    --> /ReviewMyRecentlyPaidBills.htm
    --> /learnaboutcategorydetails.htm
    --> /AutomaticallyDisplayCategoryLists.htm
    --> /UseSingleCategoryLists.htm
    --> /RequireaCategoryforeachTransaction.htm
    --> /AddInformationtoaCategoryorSubcategory.htm
    --> /RenameCategoryorSubcategory.htm
    --> /ChangeaCategoryType.htm
    --> /CombineCategories.htm
    --> /RestoreMoneysStandardCategories.htm
    --> /DeleteUnusedCategories.htm
    --> /DeleteaCategoryorSubcategory.htm
    --> /changethecategorygroupassignedtoacategory.htm
    --> /RenameClassificationorSubClassification.htm
    --> /DeleteaClassificationorSubclassification.htm
    --> /CreateaClassorSubclass.htm
    --> /AddInformationAboutClassesandSubclasses.htm
    --> /EditClassesAndSubClasses.htm
    --> /RenameClassorSubclass.htm
    --> /DeleteClassorSubClass.htm
    --> /CreateaNewPayee.htm
    --> /EditPayeeInformation.htm
    --> /ManagePayeesWithSameNameButDifferentAccountNumbers.htm
    --> /combinepayees.htm
    --> /RenameAPayee.htm
    --> /DeleteaPayee.htm
    --> /sortpayeesbynameordate.htm
    --> /UseMoney'sBillsPlacetoManageCashFlow.htm
    --> /Learnaboutcashflowinmoney.htm
    --> /Learnhowmoneyforecastscashflow.htm
    --> /Learnaboutchanginghowmoneyforecastscashflow.htm
    --> /Learnhowchangingcashflowitemschangesyourmoneyfile.htm
    --> /Selectparticularaccountstoviewincashflow.htm
    --> /Selectparticulardatestoviewincashflow.htm
    --> /ChangeMyBalanceForecast.htm
    --> /Addanitemtoyourcashflowforecast.htm
    --> /Editaniteminyourcashflowforecast.htm
    --> /Changehowmoneyforecastscashflow.htm
    --> /Changehowmoneyforecastsatrendeditem.htm
    --> /Removeanitemfromyourcashflowforecast.htm
    --> /Specifyaninterestrateforanaccount.htm
    --> /Assignbudgetamountstoaccounts.htm
    --> /Learnaboutdifferencebetweennecessaryanddiscretionarycategories.htm
    --> /Markitemsasnecessaryordiscretionary.htm
    --> /Learnaboutplayingwhatifwithcashflow.htm
    --> /Tryawhatifscenarioincashflow.htm
    --> /Learnabouttipstooptimizecashflow.htm
    --> /Viewcashflowoptimizationtips.htm
    --> /LearnaboutBalanceForecast.htm
    --> /PrintBalanceForecast.htm
    --> /Troubleshootcashflow.htm
    --> /LearnAboutTheInvestingCenter.htm
    --> /Researchinvestmentsonline.htm
    --> /Viewinvestmentperformance.htm
    --> /ChooseWhichInvestmentAccountsToSetUp.htm
    --> /Createaninvestmentaccount.htm
    --> /Addsharestoaninvestmentaccount.htm
    --> /changeinvestmentaccountdetails.htm
    --> /Removesharesfromaninvestmentaccount.htm
    --> /learnaboutyourinvestmentaccountsummary.htm
    --> /Fixanegativebalanceinanassociatedcashaccount.htm
    --> /LearnAboutTheCashTransactionsSectionInYourInvestmentAccount.htm
    --> /CreateACashTransactionsSectionInYourInvestmentAccount.htm
    --> /Deleteanassociatedcashaccount.htm
    --> /learnaboutretirementaccounts.htm
    --> /TrackTaxDeferredInvestmentsThatArentTaxDeductible.htm
    --> /CreateARetirementAccount.htm
    --> /convertaninvestmentaccounttoaretirementaccount.htm
    --> /LearnAboutBondReports.htm
    --> /LearnAboutBonds.htm
    --> /EnterABond.htm
    --> /Enterasavingsbond.htm
    --> /TrackThePerformanceOfMyBonds.htm
    --> /UpdateThePriceOfMyBonds.htm
    --> /TroubleshootEnteringBondInformation.htm
    --> /EnterAStockOrMutualFundPurchaseSaleOrOtherActivity.htm
    --> /EnterATransactionInTheCashTransactionsSectionOfAnInvestmentAccount.htm
    --> /LearnAboutPositionTracking.htm
    --> /Modifyaninvestmenttransaction.htm
    --> /ChangeTheCategoryAssignedToAnInvestmentActivity.htm
    --> /HaveMoneyAlertMeWhenTheTransferFieldIsLeftBlank.htm
    --> /TransferAnInvestmentTransactionToADifferentAccount.htm
    --> /Verifyinvestmentpurchaseprice.htm
    --> /LearnAboutOnlineTrading.htm
    --> /Setaremindertobuyorsellaninvestmentonacertaindate.htm
    --> /LearnAboutLots.htm
    --> /Trackputsandcalls.htm
    --> /LearnAboutMarginsAndMarginInterest.htm
    --> /ConvertForeignCurrenciesForInvestments.htm
    --> /LearnAboutThePortfolio.htm
    --> /LearnAboutTheDifferenceBetweenThePortfolioAndTheInvestmentAccountsAreas.htm
    --> /HowToCustomizeWhatYouSeeInYourPortfolio.htm
    --> /learnaboutstocks.htm
    --> /Updateinvestmentholdings.htm
    --> /DownloadMarketPricesUsingOnlineQuotes.htm
    --> /Cleardownloadedquotesforunusedstocks.htm
    --> /Automaticallyclearunuseddownloadeddata.htm
    --> /activateatickersymbolforonlinedownloads.htm
    --> /Deactivateatickersymbolfromonlinedownloads.htm
    --> /LearnHowGainAndPercentageGainAreCalculated.htm
    --> /Vieworeditinvestmenttransactionsintheportfolio.htm
    --> /LearnAboutWatchAccounts.htm
    --> /AddaninvestmentorindextoInvestmentstoWatch.htm
    --> /RemoveaninvestmentorindexfromInvestmentstoWatch.htm
    --> /ViewAnInvestmentAllocationReport.htm
    --> /PrintMyPortfolio.htm
    --> /LearnAboutPortfolioReview.htm
    --> /WhydidntmystocksplitshowupwhenIdownloadedonlinequotes.htm
    --> /Enterastocksplit.htm
    --> /FindOutWhyMyStockSplitHasTheWrongNumberOfShares.htm
    --> /DeleteAStockSplit.htm
    --> /Enterashortsell.htm
    --> /LearnAboutCostBasis.htm
    --> /defclass.htm
    --> /dummy.xml
    --> /LearnHowToRecordASpinoff.htm
    --> /RecordAMerger.htm
    --> /Learnaboutstockoptiongrants.htm
    --> /Enterastockoptiongrant.htm
    --> /ChangeStockOptionDetails.htm
    --> /ConvertstockoptionsfromearlierversionsofMoney.htm
    --> /Exerciseanstockoptiongrant.htm
    --> /Deleteastockoptiongrant.htm
    --> /ViewallstockoptionsharesgrantedintheInvestmentPortfolio.htm
    --> /StockoptionFrequentlyAskedQuestions.htm
    --> /coutglobal.htm
    --> /LearnabouthandlingReturnofCapitaltransactions.htm
    --> /EnterCapitalGainsDistributions.htm
    --> /Enterinterestreceiveddividendsorcapitalgainsdistributions.htm
    --> /Learnaboutthedistributionmethodforshares.htm
    --> /ViewCapitalGainsTaxSummary.htm
    --> /LearnAboutInvestmentReports.htm
    --> /troubleshootinvesting.htm
    --> /LearnthebenefitsofusingOnlineServices.htm
    --> /ChangeDialUpConnectionSettings.htm
    --> /DisableCallWaiting.htm
    --> /UseProxyServer.htm
    --> /GetanInternetServiceProvider.htm
    --> /WhattoaskyourInternetserviceprovidertogetsetup.htm
    --> /SetUpYourComputertoUsetheInternet.htm
    --> /ConfigureMoneyToConnectToTheInternet.htm
    --> /Authorizeonlinepaymentsfrommyaccount.htm
    --> /entermydataontheweb.htm
    --> /UpdateOnlineAccountsWhenYouOpenMoney.htm
    --> /FindoutaboutsecurityinMicrosoftMoney.htm
    --> /Learnaboutonlinepasswords.htm
    --> /SetconnectionoptionsforMoney.htm
    --> /SetupmultipleconnectionmethodsinInternetExplorer5.0.htm
    --> /Troubleshootonlineservicessetup.htm
    --> /Backgroundbankingrequirements.htm
    --> /Setupbackgroundbanking.htm
    --> /Setuponlineservices.htm
    --> /Seewhichaccountsaresetupforonlineservices.htm
    --> /Manageaccountswithdifferentonlinepasswordsatthemsamebank.htm
    --> /CustomizeOnlineServicesInMoney.htm
    --> /ManageAllThePINsIHaveStoredInMoney.htm
    --> /Cancelonlineservicesthroughmybankswebsite.htm
    --> /CancelOnlineServicesformyaccount.htm
    --> /FindoutwhysomeaccountsmaynotbelistedbyOnlineSetup.htm
    --> /Keeptrackofmybankorbrokercontactinformation.htm
    --> /Findoutifmybankorbrokersonlineserviceofferingshavechanged.htm
    --> /Usemybankswebsiteinsteadofmoneysonlineservices.htm
    --> /defARM.htm
    --> /LearnwhotocallforhelpwhenusingWebBanking.htm
    --> /Learnaboutthemoneyshoppingcenter.htm
    --> /Learnaboutonlinestatements.htm
    --> /Learnthebenefitsofdownloadingstatements.htm
    --> /defARRCO.htm
    --> /DownloadastatementviamybankorbrokersWebsite.htm
    --> /Connectanddownloadstatementsforallmyonlineaccounts.htm
    --> /LearnWhatDateRangeToUseWhenDownloadingTransactions.htm
    --> /DisassociateadownloadedstatementwithaMoneyaccount.htm
    --> /FindOutWhatHappensToIntelliChargeAccounts.htm
    --> /Troubleshootonlinestatements.htm
    --> /LearnwhytheAccountRegisteranddownloadedstatementbalancesdiffer.htm
    --> /Matchdownloadedtransactionstothoseinyouraccountregister.htm
    --> /AssociatedownloadedstatementswithaMoneyaccount.htm
    --> /Learnaboutverifyingdownloadedstatements.htm
    --> /TellMeAboutAcceptingDownloadedTransfers.htm
    --> /AcceptDownloadedTransactionsInTheAccountRegister.htm
    --> /Acceptalldownloadeddefinitetransactionmatches.htm
    --> /AcceptAllUnreadTransactionsInTheAccountRegisterAtOnce.htm
    --> /ViewOnlyUnacceptedTransactionsInTheAccountRegister.htm
    --> /AutomaticallymarkacceptedtransactionsasR.htm
    --> /Undoalltransactionmatches.htm
    --> /Changehowmoneynavigatesafteryouacceptatransaction.htm
    --> /LearnAboutMoneyCentral.htm
    --> /LearnWhatBoldTextMeansInTheAccountRegister.htm
    --> /LearnWhatAQuestionMarkMeansInTheAccountRegister.htm
    --> /LearnAboutBrowsers.htm
    --> /Learnaboutunassignedamountsindownloadedtransactions.htm
    --> /NavigateWebinMoney.htm
    --> /hcDropDown.htc
    --> /hcGlossary.htc
    --> /hcToc.htc
    --> /hhGlossary.xsl
    --> /hhLocConvert.xsl
    --> /hhOnstart.xsl
    --> /hhPreprocess.xsl
    --> /Editanentryforanunassignedamountinadownloadedstatement.htm
    --> /Matchadownloadedtransactiontomultipletransactions.htm
    --> /LearnAboutMatchingTransactions.htm
    --> /LearnAboutRenamingPayeesInADownloadedStatement.htm
    --> /Unmatchatransactioninthemanualmatchingdialogbox.htm
    --> /Learnwhythedateschangeafterirecordadownloadedstatement.htm
    --> /MatchTransactionsManuallyWhenReadingDownloadedStatements.htm
    --> /Matchvariationsofpayeenames.htm
    --> /Choosewhichwordstoignoreinpayeenamevariations.htm
    --> /Showstandardizedpayeenames.htm
    --> /Troubleshootpayeenamematching.htm
    --> /Learnaboutwarningsfordownloadedtransactions.htm
    --> /NonReplaceableTransactions.htm
    --> /ViewMyFinancialinstitutionshomepage.htm
    --> /learnaboutfavoritesinmoney.htm
    --> /LearnHowMoneyCanUseTheInternetToKeepYourFinancialDataCurrent.htm
    --> /Sendemailtomyfinancialinstitution.htm
    --> /Learnaboutdirectonlinebanking.htm
    --> /FindoutwhattodowhenIchangebanks.htm
    --> /MergefinancialinstitutionsinMoney.htm
    --> /jsLocstart.js
    --> /Moveanaccountfromonefinancialinstitutiontoanother.htm
    --> /UpdatemybankorbrokersWebaddressforonlineservices.htm
    --> /UpdateInternetInformationinMoney.htm
    --> /SynchronizeWithMoneyCentral.htm
    --> /LearnAboutAddingNewAccountsToMoneyAndMoneyCentral.htm
    --> /LearnAboutSettingUpYourInvestmentPortfolioOnMoneyCentral.htm
    --> /SetUpYourFinancialInformationOnMoneyCentral.htm
    --> /LearnAboutGettingAccountInformationDailyOnMSNMoneyCentral.htm
    --> /DisableMoneyCentralSynchronization.htm
    --> /troubleshootMoneycentralSynchronization.htm
    --> /useonlinemessageboardstohelpwithinvesting.htm
    --> /LearnBenefitsofUsingtheInternet.htm
    --> /FindOutHowToGetOntoTheInternetFromMoney.htm
    --> /FindoutwhathappenswhenIconnecttotheInternetinMoney.htm
    --> /BrowseInternetInsideMoney.htm
    --> /learnaboutusingmoneysinternalbrowser.htm
    --> /LearnAboutInternalWebBrowserControls.htm
    --> /TellMoneyHowILiketoBrowsetheWeb.htm
    --> /PrintWebPageInMoney.htm
    --> /FindOutWhyICantOpenAWebPage.htm
    --> /TroubleshootingIcanconnectbutmypartnercantWhy.htm
    --> /SetYourInternetFavoritesInIEToDisplayInMoney.htm
    --> /ManageMoneysInternetFavorites.htm
    --> /AddaWebPagetoInetFavoritesinMoney.htm
    --> /ViewFavoriteWebPageinMoney.htm
    --> /SetInternetinformationupdateoptions.htm
    --> /Troubleshoototheronlineservicesproblems.htm
    --> /Learnaboutmsnpassport.htm
    --> /Learnthebenefitsofusinganmsnpassportwithmoney.htm
    --> /Learnthedifferencebetweenpassportmoneypasswordsandpins.htm
    --> /Learnaboutmsnemailorhotmailaccountsandpassport.htm
    --> /Createanmsnpassporttousewithmoney.htm
    --> /Changethepassportyouusewithmoney.htm
    --> /Learnhowmsnpassportworkswithmoneysexistingpassword.htm
    --> /Signintomoneyautomaticallywithpassport.htm
    --> /Changeyourpassportpasswordinmoney.htm
    --> /Learnwhatmsnpassporttouseinmoney.htm
    --> /Gethelpwithaforgottenmsnpassportpassword.htm
    --> /Removepassportsigninfrommoney.htm
    --> /Troubleshootmsnpassportsinmoney.htm
    --> /def52WeekHigh.htm
    --> /def52WeekLow.htm
    --> /defAbbreviation.htm
    --> /defAcceleratedDepreciationRate.htm
    --> /defAccount.htm
    --> /defAccountGroup.htm
    --> /defAccountPosition.htm
    --> /defAccountRegister.htm
    --> /defAccountsPayable.htm
    --> /defAccountsReceivable.htm
    --> /defAdditionalWithholding.htm
    --> /defAnnualPercentageRate.htm
    --> /defannualreturn.htm
    --> /defannuity.htm
    --> /defapplication.htm
    --> /defarchive.htm
    --> /defAssetClass.htm
    --> /defAssociatedCashAccount.htm
    --> /defAssociatedContributionsAccount.htm
    --> /DefAssuranceVie.htm
    --> /defATM.htm
    --> /defAutoBalance.htm
    --> /defAutoComplete.htm
    --> /defbalance.htm
    --> /defBaseCurrency.htm
    --> /defbasispoint.htm
    --> /defBearMarket.htm
    --> /defbeneficiary.htm
    --> /DefBIC.htm
    --> /defbroker.htm
    --> /defbrokerageaccount.htm
    --> /defbrowser.htm
    --> /defBulletinBoard.htm
    --> /defBullMarket.htm
    --> /defBusinessBill.htm
    --> /defcalculator.htm
    --> /defCapitalAsset.htm
    --> /defcapitalgain.htm
    --> /defcapitalgainsdistribution.htm
    --> /defcapitalloss.htm
    --> /defCash.htm
    --> /defcasualty.htm
    --> /defcategory.htm
    --> /defCDcertificateofdeposit.htm
    --> /defclassification.htm
    --> /defclearedtransaction.htm
    --> /defClipboard.htm
    --> /defcommission.htm
    --> /DefCompteRetraiteDeLaLoiMadelin.htm
    --> /defconcentrationrisk.htm
    --> /defContact.htm
    --> /defCSV.htm
    --> /LearnWhatsNewInTheBudgetPlanner.htm
    --> /Learnhowmoneyorganizesabudget.htm
    --> /Learnhowthebudgetworkswithyourdebtplan.htm
    --> /Createabudgetinmoney.htm
    --> /Customizemoneysdefaultbudgetvalues.htm
    --> /Saveoropenanarchivedbudget.htm
    --> /Viewactualtransactionswhilecreatingabudget.htm
    --> /Learnaboutmoneysdefaultbudgetvalues.htm
    --> /LearnwhatsnewinAutobudget.htm
    --> /Removeanaccountfrommybudgetcalculations.htm
    --> /Troubleshootabudgetupgrade.htm
    --> /Troubleshootcreatingabudget.htm
    --> /Learnaboutcategoriesandbillsinmoneysbudget.htm
    --> /Addoreditagrouporcategorywhilecreatingabudget.htm
    --> /Moveacategorybetweenbudgetgroupswhilecreatingabudget.htm
    --> /Deleteagrouporcategorywhilecreatingabudget.htm
    --> /Addoreditagrouporcategorywithacompletedbudget.htm
    --> /Moveacategorybetweenbudgetgroupswithacompletedbudget.htm
    --> /Deleteagrouporcategoryfromacompletedbudget.htm
    --> /Learnaboutsavingsgoals.htm
    --> /Addoreditasavingsgoal.htm
    --> /Removeanaccountfromsavingsgoalscalculations.htm
    --> /Removeasavingsgoal.htm
    --> /Troubleshootsavingsgoals.htm
    --> /Learnthedifferencebetweenreallocatingandeditinginabudget.htm
    --> /Learnaboutflexiblebudgetingandreallocation.htm
    --> /Addaonetimeitemtoabudget.htm
    --> /Removeatransactionfromthebudget.htm
    --> /Customizebudgetdetailsview.htm
    --> /Reallocatefundsbetweenbudgetcategories.htm
    --> /Learnwhatspendinglimitstoset.htm
    --> /Adjustbudgetedspendinglimitsfromtheaccountregister.htm
    --> /LearnaboutbudgetreportsinMoney.htm
    --> /Learnwaystoadjustorbalanceyourbudget(BudgetTips).htm
    --> /Troubleshootbudgetmaintenance.htm
    --> /LearnAboutTheDebtReductionPlanner.htm
    --> /LearnhowmyDebtPlanisintegratedwiththerestofmyMoneyfile.htm
    --> /LearnHowMyEstimatedMonthlySpendingIsFactoredIntoMyDebtPlan.htm
    --> /CreateADebtReductionPlan.htm
    --> /EnterADebtWithANointerestNopaymentPeriod.htm
    --> /AddANewDebtAccountToMyDebtPlan.htm
    --> /ChangeTheDetailsOfAnExistingDebtAccount.htm
    --> /RemoveAnAccountFromMyDebtPlan.htm
    --> /ResetmyDebtPlan.htm
    --> /SeeanotherviewofmyDebtPlan.htm
    --> /PrintmyDebtPlan.htm
    --> /UseacreditcardthatsinmyDebtPlan.htm
    --> /PayOffADebtByMakingAOnetimeExtraPayment.htm
    --> /LearnWhatHappensIfIMissAScheduledPaymentTowardsMyDebtPlan.htm
    --> /TroubleshootDebtReductionPlannerproblems.htm
    --> /LearnwhyIshouldbothertoplan.htm
    --> /LearnabouttheLifetimePlanner.htm
    --> /CompareLifetimePlannerplanningpro.htm
    --> /UnderstandhowthePlannerusesinformationfrommyMoneyfile.htm
    --> /GetreadytocreateaLifetimePlan.htm
    --> /Createalifetimeplan.htm
    --> /Changetheownerofanaccount.htm
    --> /LearnhowMoneyusesdates.htm
    --> /LearnthesignificanceofblueandgraytextforitemsinthePlanner.htm
    --> /LearnabouttheAboutYouplace.htm
    --> /EnterOrChangeMyPersonalInformation.htm
    --> /EnterOrChangeInformationAboutMySpouseOrPartner.htm
    --> /EnterInformationAboutMyDependents.htm
    --> /PlanForAFutureSpouseOrPartner.htm
    --> /Correctadependentsnameordateofbirth.htm
    --> /DeleteADependent.htm
    --> /Learnwhatcountsasincome.htm
    --> /LearnabouttheCareerpage.htm
    --> /EnterIncomeInformationForMyselfAndMyPartner.htm
    --> /Enterinformationaboutannualraisesandsalarycap.htm
    --> /Changethestartorenddateofacareer.htm
    --> /Enterselfemploymentincome.htm
    --> /Entercareereventsthataffectsalary.htm
    --> /changethedetailsofacareereventthataffectssalary.htm
    --> /Planforasabb
    1
  2. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Bonjour ankhaz

    A)- Premièrement

    1°- Télécharge SDFix sur ton bureau
    : < http://downloads.andymanchesta.com/RemovalTools/SDFix.exe >
    2°- Installation et Mise à jour de SDFix :
    •- Double clique sur l'icône SDFix.exe > [Exécuter] > Destination folder = C:\ > [Install] > Ouvre le dossier « SDFix », qui vient d'être créé dans le répertoire C:\ > (créer un raccourci sur le bureau) .
    ==> NB: ( Ou bien faire: Clic droit sur l'icône SDFix.exe > "extraire ici" )
    •- > ouvrir le (raccourci) dossier "SDFix" apparu sur le bureau > double-clic sur "RunThis.bat" de SDFix > ensuite tape U = “download latest version of sdfix” > laisser faire > puis Clic sur une touche, et encore « Press any key to close SDFix & Extract latest version » .
    3°- •- Redémarre en mode sans échec.
    Tuto http://www.coupdepoucepc.com/modules/news/article.php?storyid=253 >
    Choisir sa session habituelle, (pas le compte "Administrateur" ou une autre).
    ( note bien ce que tu as à faire, parce que tu n'auras plus accès à IE durant cette procédure ).

    4°- Ouvre le dossier "SDFix" sur le bureau > double-clic sur "RunThis.bat" de SDFix > Tape Y pour lancer le script.
    Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire
    Presse une touche pour redémarrer en mode normal
    Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
    Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
    Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
    Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom « Report.txt ».
    5°- Ouvre le "dossier SDFix" et copie/colle ici le contenu du fichier "Report.txt" ( qui est également sur le bureau )

    Guide d'utilisation de SDFix http://mickael.barroux.free.fr/securite/sdfix.php

    B)- Deuxièmement

    Je constate que Avast ne te sert pas à grand-chose (sinon à t'avertir qu'il a laissé infecter ton PC !!).
    Alors, fais-moi plaisir; applique ceci:

    1)- Télécharger ANTIVIR sur le site de l'éditeur pour avoir la dernière version qui est celle-ci pour xp: < https://www.avira.com/en/free-antivirus-windows >
    et qui prend en compte la case Rootkit.

    TUTORIELS :
    < https://www.astucesinternet.com/modules/news/article.php?storyid=253 > ==> enregistre-le sur ton bureau pour y accéder facilement.
    - ou < http://www.malekal.com/tutorial_antivir.html >
    - ou < http://www.libellules.ch/tuto_antivir.php >

    2)- Désinstaller AVAST: <
    https://www.avast.com/fr-fr/uninstall-utility >

    3)- Attention, après le téléchargement, il faut se déconnecter du Net ( débrancher éventuellement le modem ) avant de lancer l'installation.

    - Attention :
    Sers-toi du tutoriel pour installer ANTIVIR,
    http://www.vista-xp.fr/forum/topic227.html

    4)- Procédure d'utilisation:
    Après l'installation du programme et avant de lancer l'analyse, ...
    ...il faut redémarrer le PC en mode sans échec, comme ceci:
    < http://www.coupdepoucepc.com/modules/news/article.php?storyid=253 >

    Lancer Antivir en Scan complet ( analyse avancée )
    Poster le rapport SVP.
    L'analyse:
    - Lancer Antivir en Scan complet (analyse avancée) en faisant un click-droit sur l’icône d’Antivir dans la « barre des taches » en bas à droite (= Systray, à côté de l’horloge) puis clic sur « start Antivir »
    - Cliquer sur l’onglet « scanner »
    - Vérifier pour « RootKit search » et « Manuelle détection » (en développant avec la petite croix devant chacun d'eux) que tous les disques durs soient bien cochés, puis cliquer sur la loupe (en dessous de statut)
    - Une fenêtre va s’ouvrir « Luke Filewalker »
    - Le scan va démarrer.
    - Mettre tout ce qu il trouve en "quarantine"

    Le rapport:
    Une fois le scan achevé, fermer les deux fenêtres d'Antivir et sauvegarder sur le bureau le rapport qui vient d'apparaître.
    Redémarrer en mode normal puis poster le rapport d'Antivir (qui est sur le bureau).

    Merci
    Bonne chance
    Al
    0
  3. VIRUS_KILLER Messages postés 2075 Statut Contributeur 68
     
    Salut
    Tu dispose de bon logiciel.
    Zone Alarm excelent firewall,AVAST excelent Anti Virus,AdAware excelent netoyeur de spywares et de malwares et enfin c cleaner pour faire le ménage.Tu n'a rien n'a craindre,si tu l'a mis en Quarantaine tu peut le supprimer si tu veut.
    Telecharge HIJACKTHIS et nous un rapport:

    --http://ftpclubic43.clubic.com/...
    VIRUS_KILLER
    a votre SERVICE,le destructeur de virus est la!
    0
  4. ankhaz
     
    ok je t'envoie le rapport dès que c'est prêt
    merci
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Merci ankhaz

    Fais bien les trois applications:
    SDFix et poster le rapport
    Supprimer AVAST !!
    Installer ANTIVIR et poster le rapport

    Ensuite, je t'expliquerai comment bien installer HijackThis.

    Bonne chance
    Al.
    0
  7. ankhaz
     
    voilà le rapport hijackthis, en espérant avoir fait ce qu'il fallait :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:18:04, on 09/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\S24EvMon.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\ZCfgSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\System32\DVDRAMSV.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\RegSrvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\System32\00THotkey.exe
    C:\WINDOWS\system32\TFNF5.exe
    C:\Program Files\SigmaTel\Pilotes Audio SigmaTel AC97\stacmon.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
    C:\WINDOWS\LTSMMSG.exe
    C:\WINDOWS\system32\TPSMain.exe
    C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
    C:\qttask.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\RAMASST.exe
    C:\WINDOWS\System32\1XConfig.exe
    C:\WINDOWS\system32\TPSBattM.exe
    C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
    O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
    O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
    O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
    O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\Pilotes Audio SigmaTel AC97\stacmon.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
    O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
    O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\RunOnce: [srePostpone] rundll32.exe c:\windows\system32\zonelabs\srescan.dll,DoSpecialAction
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C6B18187-CC34-4E01-9F74-C1ACCBA6F971}: NameServer = 213.36.80.1
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    0
  8. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    URGENT ==> ton PC est infecté, comme tu le sais déjà.

    Fais bien les trois applications:
    SDFix et poster le rapport
    Supprimer AVAST !!
    Installer ANTIVIR et poster le rapport

    Merci
    Al
    0
  9. ankhaz
     
    ok je vais suivre tes conseils
    SDFix,
    supprimer avast,
    installer antivir,
    et revenir ici ensuite
    merci
    0
  10. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    ankhaz

    En attendant de tes nouvelles
    Et en espérant que tu n'aies pas de difficultés

    ... voici déjà des aplications qu'il faudra exécuter ensuite (hormis l'aspect infection):

    A)- Java\j2re1.4.2_03 ==> Ta version n’est pas mis à jour. (grosse faille de sécurité!)

    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll

    Rends-toi sur ce lien < https://www.java.com/fr/download/ > afin de télécharger une version à jour.
    Ensuite, vas dans "Panneau de configuration" > "Ajout/suppr.de programmes", et supprime toutes tes anciennes versions
    (Plusieurs nouveaux défauts de sécurité ont été identifiés dans l'environnement Java de Sun.
    L'exploitation d'erreurs dans la machine virtuelle, Java Web Start et d'autres composants peut permettre à un individu malveillant ou à un virus d'effectuer à distance diverses actions malicieuses sur l'ordinateur de sa victime telles que lire, écrire ou exécuter des fichiers.
    )

    B)- Adobe\Reader 7.0 ==> grosse faille de sécurité .

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    Il faut faire la mise à jour version 8.1.2 https://get2.adobe.com/reader/otherversions/
    L'installation d' une nouvelle version désinstallera l' ancienne si besoin est.
    ( http://ardownload.adobe.com/pub/adobe/reader/win/8.x/8.1/fra/AdbeRdr810_fr_FR.exe > lien direct)
    - Décocher "Téléchargez également :Adobe Photoshop® Album Édition"
    - Dans Ajout/Suppression des programmes tu supprimes toutes les autres versions.

    C)- C:\qttask.exe

    This is the QuickTime Tray Icon that is displayed in the System Tray
    Common Path(s): %programfiles%\QuickTime\qttask.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\qttask.exe" -atboottime
    Autrement dit, il n'est pas à sa place !

    Il faudrait faire analyser ce fichier qttask.exe chez VirusTotal
    Tutoriel d'aide ici http://bibou0007.com/tutos-f45/tutorial-sur-virustotal-t190.htm

    Vas là :< https://www.virustotal.com/gui/ >
    •- sur la page qui s'affiche tu cliques sur [Parcourir]
    •- ensuite sur la nouvelle page qui s'affiche, tu suis le chemin du fichier qttask.exe
    c'est-à-dire via "Poste de travail" > C:\
    •- quand tu as trouvé le premier fichier qttask.exe, tu fais "ouvrir" ( sur cette dernière page affichée)
    •- le fichier qttask.exe se retrouve alors ainsi dans la fenêtre de VirusTotal, pour l'analyse
    •- là, tu cliques sur "send file" = « Envoyer » ( de la page de VirusTotal )
    •- et tu attends le résultat (il faut parfois patienter)
    •- Dans l'encadré: "Situation actuelle: terminé" ==> cliquer sur "Formaté"
    •- Une nouvelle fenêtre de votre navigateur apparaîtra...
    •- Dans la nouvelle fenêtre, cliquer sur cette image : < http://img215.imageshack.us/img215/6039/virustotalpourcopierip3.jpg >
    •- Faire un clic-droit sur la page, choisir => "Sélectionner tout" > puis encore clic-droit => Copier...
    Enfin , clic-droit => Coller le(s) résultat(s) dans le WordPad ou Bloc-Notes ==> et le poster sur forum ici.

    D)- Je te conseille de désinstaller Ad-Aware 2007.
    •- La version gratuite n'offre pas de protection en temps réel, ça reste un scanneur donc l'efficacité est plus qu'à douter, voir : https://forum.malekal.com/viewtopic.php?f=45&t=8046
    •- Et pour exclure ce service inutile aawservice, il suffit de faire ainsi:
    Clic sur « Démarrer » > « Exécuter » ; ensuite, dans la lucarne de saisie, coller (recommencer pour chacune des trois commandes suivantes) :
    1°- sc stop aawservice > valider par [OK]
    2°- sc config aawservice start= disabled > valider par [OK]
    3°- sc delete aawservice > valider par [OK]

    Bonne chance
    Dans l'attente des rapports que j'avais demandé post # 1.
    Merci
    Al.
    0
  11. ankhaz
     
    recoucou,
    voilà quelques difficultés pour SDfix mais avec de la persévérance, j'ai réussi,
    je te joins le rapport

    b]SDFix: Version 1.154 [/b]

    Run by marine on 09/03/2008 at 19:26

    Microsoft Windows XP [version 5.1.2600]
    Running From: C:\SDFix

    [b]Checking Services [/b]:

    Restoring Windows Registry Values
    Restoring Windows Default Hosts File

    Rebooting

    [b]Checking Files [/b]:

    No Trojan Files Found

    Removing Temp Files

    [b]ADS Check [/b]:

    [b]Final Check [/b]:

    catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-03-09 19:32:36
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden services & system hive ...

    scanning hidden registry entries ...

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0

    [b]Remaining Services [/b]:

    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

    [b]Remaining Files [/b]:

    File Backups: - C:\SDFix\backups\backups.zip

    [b]Files with Hidden Attributes [/b]:

    Wed 6 Sep 2006 2,716 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti2.tmp"
    Tue 9 Jan 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
    Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d6e228e44f2018dd79eeb427a0b47d06\BIT2.tmp"
    Wed 23 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f7db876e78b88fd8276fd7d29cb7e4eb\BIT2.tmp"

    [b]Finished![/b]

    maintenant je vais poursuivre tes conseils et télécharger antivir, désinstaller avast, et lancer un scan complet avec antivir et te poster le rapport

    toutes mes excuses pour le temps que cela me prends
    0
  12. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Parfait
    La collecte est bonne

    Relance HJT « Do a system Scan only », sur la page/rapport qui s'affiche ( laisse lui le temps de tout scanner ) coche la case devant ces lignes:

    -O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    -O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    -O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    -O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    -O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
    -O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    -O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
    -O4 - HKLM\..\RunOnce: [srePostpone] rundll32.exe c:\windows\system32\zonelabs\srescan.dll,DoSpecialAction
    -O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe


    •-Arrête tous les programmes en cours et ferme toutes les fenêtres.
    ( seul HijackThis doit être ouvert ) ,
    •- et ensuite Clic [Fix checked] ==> (fixer =corriger)

    Aide en images ==> Fixer ligne avec HJT
    http://dcangeldark.blogspot.com/2008/02/hijackthis-202-corriger-des-lignes.html

    Poursuis les autres applications.

    Merci
    Al.
    0
    1. ankhaz
       
      beaucoup de mal à te poster le rapport antivir,
      ça bug à chaque fois
      soit quand je colle le rapport
      soit quand j'envoie le message
      mais à chaque fois, le programme ( firefox ) ne répond plus,
      une solution ?
      0
  13. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Re,

    Donc, tu vois le rapport de Antivir .

    Fais un copier/coller de la partie détection ==> la fin du rapport ;
    .. et collle dans le forum

    Merci
    Al
    0
    1. ankhaz
       
      bon, j'ai réessayer pour le rapport antivir, sans succès, ça commence vraiment à m'énerver, d'autant plus que le copier/coller il a fonctionné avec le rapport hijackthis et virus total.

      Je vais maintenant refaire un scan HJT en fixant les lignes comme tu me l'a expliqué.

      Merci encore pour ton aide précieuse et le temps que tu y consacre.
      0
  14. ankhaz
     
    en attendant de trouver une solution pour te poster le rapport antivir,
    j'ai suivi tes instruction et mis à jour java et adobe et supprimer les versions antérieures.

    J'ai fais analyser attask.exe, voilà le rapport :

    Fichier qttask.exe reçu le 2008.03.09 23:30:11 (CET)
    Antivirus Version Dernière mise à jour Résultat
    AhnLab-V3 2008.3.4.0 2008.03.07 -
    AntiVir 7.6.0.73 2008.03.09 -
    Authentium 4.93.8 2008.03.07 -
    Avast 4.7.1098.0 2008.03.09 -
    AVG 7.5.0.516 2008.03.09 -
    BitDefender 7.2 2008.03.09 -
    CAT-QuickHeal 9.50 2008.03.08 -
    ClamAV 0.92.1 2008.03.09 -
    DrWeb 4.44.0.09170 2008.03.09 -
    eSafe 7.0.15.0 2008.03.09 -
    eTrust-Vet 31.3.5597 2008.03.07 -
    Ewido 4.0 2008.03.09 -
    FileAdvisor 1 2008.03.09 -
    Fortinet 3.14.0.0 2008.03.09 -
    F-Prot 4.4.2.54 2008.03.09 -
    F-Secure 6.70.13260.0 2008.03.09 -
    Ikarus T3.1.1.20 2008.03.09 -
    Kaspersky 7.0.0.125 2008.03.09 -
    McAfee 5247 2008.03.07 -
    Microsoft 1.3301 2008.03.07 -
    NOD32v2 2932 2008.03.09 -
    Norman 5.80.02 2008.03.07 -
    Panda 9.0.0.4 2008.03.09 -
    Prevx1 V2 2008.03.09 -
    Rising 20.34.62.00 2008.03.09 -
    Sophos 4.27.0 2008.03.09 -
    Sunbelt 3.0.930.0 2008.03.05 -
    Symantec 10 2008.03.09 -
    TheHacker 6.2.92.239 2008.03.09 -
    VBA32 3.12.6.2 2008.03.05 -
    VirusBuster 4.3.26:9 2008.03.09 -
    Webwasher-Gateway 6.6.2 2008.03.09 -
    Information additionnelle
    File size: 155648 bytes
    MD5: 3e7d91f24d28c968b92c85c7e2882eed
    SHA1: ed9aaa5cc7600258ad457a8f30cc22906b2c7a0b
    PEiD: -
    0
  15. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Parfait
    Merci
    As-tu essayé l'envoi sous Internet Explorer ? (au lieu de FF)

    A)- Quand tu "fixeras" les lignes avec HijackThis, ajoute celle-ci à la liste:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\qttask.exe" -atboottime

    B)- Après quoi, poste un nouveau rapport HijackThis

    C)- Supprimer ce fichiers en gras:
    C:\Program Files\InterActual\InterActual Player\iti2.tmp
    C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
    C:\WINDOWS\SoftwareDistribution\Download\d6e228e44f2018dd79eeb427a0b47d06\BIT2.tmp&q­uot;
    C:\WINDOWS\SoftwareDistribution\Download\f7db876e78b88fd8276fd7d29cb7e4eb\BIT2.tmp&q­uot;

    D)- Fais un scan en ligne Kaspersky https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr avec Internet Explorer :

    Branche ton Disque Externe (clé USB) éventuellement
    - Clique sur "Démarrer" > "Online-Scanner"( en bas à droite de la page) .
    - Clique maintenant sur J'accepte.
    - Valide l'installation d'un ou de plusieurs ActiveX si c'est nécessaire.

    - Patiente pendant l'installation des Mises à jour.
    Clic sur « Paramètres d'analyse »
    Coche la case « Étendue » >> Ok
    - Choisis par la suite l'analyse du Poste de travail pour faire un « Scan complet ».
    - Sauvegarde puis colle le rapport généré en fin d'analyse.
    http://i204.photobucket.com/albums/bb106/Juliet702/Kas-SaveReport-1.gif
    http://i204.photobucket.com/albums/bb106/Juliet702/Kas-Savetxt.gif

    L'analyse peut durer longtemps ; laisse aller le PC

    NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte toi sur le site de Kaspersky pour retenter le scan en ligne.

    Tuto http://www.infos-du-net.com/forum/267224-11-scan-ligne-kaspersky
    et là https://forum.pcastuces.com/sujet.asp?f=25&s=37641 (par Morgane & nico_dodo)

    Bonne nuit
    Al.
    0
  16. ankhaz
     
    j'ai bien compris que tu allais dormir, néanmoins je te laisse le rapport HJT effectué après avoir coché les lignes, excepté trois d'entre elles que je n'ai pas trouvé :

    04- HKLM \ ..\run : [sunjavasUpdatedSched] C:\Program Files\java\j2re 1.4.2_03\bin\jusched.exe
    04- global startup : lancement rapide Adobe reader.ink =\Program Files`\Adobe\Acrobat 7.0\Reader\Reader_sl.exe
    04-HKLM\..\runonce : [sre Postpone] runddl32.exe & C: \windows`\system 32 \zonelabs\srescan.ddl.DospecialAction


    Donc voilà le rapport HJT :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 01:01:15, on 10/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\S24EvMon.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\system32\ZCfgSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\00THotkey.exe
    C:\WINDOWS\system32\TFNF5.exe
    C:\Program Files\SigmaTel\Pilotes Audio SigmaTel AC97\stacmon.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
    C:\WINDOWS\LTSMMSG.exe
    C:\WINDOWS\system32\TPSMain.exe
    C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\WINDOWS\system32\TPSBattM.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\RAMASST.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\System32\DVDRAMSV.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\RegSrvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\1XConfig.exe
    C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
    O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
    O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
    O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
    O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\Pilotes Audio SigmaTel AC97\stacmon.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
    O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
    O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
    O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C6B18187-CC34-4E01-9F74-C1ACCBA6F971}: NameServer = 213.36.80.1
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    0
  17. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Re,

    Tout ça me paraît bon
    Merci

    Termine les deux derniers points.

    As-tu encore les mêmes soucis avec ton PC ?

    à+..
    Bonne nuit
    Al.
    0
  18. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Bonjour

    Pour la question du curseur de la souris qui se déplace intempestivement, fais des recherches là:

    •- < https://support.microsoft.com/fr-fr/help/895550 >
    •- < https://support.microsoft.com/fr-fr/windows/r%C3%A9soudre-les-probl%C3%A8mes-li%C3%A9s-%C3%A0-votre-souris-ou-clavier-microsoft-5afe478d-6402-d72b-93b9-e4235fd5c4cd >

    •- https://www.google.fr/search?hl=fr&client=pub-9894150458628165&channel=0987409536&cof=FORID%3A1%3BGL%3A1%3BLBGC%3A336699%3BLC%3A%230000ff%3BVLC%3A%23663399%3BGFNT%3A%230000ff%3BGIMP%3A%230000ff%3BDIV%3A%23336699%3B&domains=Hotline-pc.org&ie=ISO-8859-1&oe=ISO-8859-1&q=souris&btnG=Rechercher&sitesearch=Hotline-pc.org&meta=lr%3Dlang_fr
    Je ne sais plus si tu as fais l'essai avec une autre souris.

    •- < http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Peripheriques/probleme-souris-sujet_103519_1.htm >

    Pour cette question: « Quand je voulais fermer un fichier word, j'avais un message comme quoi un autre utlisateur l'utilisait déjà, où alors le programme ne répond plus »
    Cela signifie que tu as encore ce dossier en cours de lecture sur le bureau (par exemple); tu dois le supprimer (après l'avoir éventuellement enregistré).

    Mauvais temps ici, avec coupures de courant électrique.
    Al.

    0
  19. ankhaz
     
    bonjour,

    j'ai supprimé les fichiers WINDOWS que tu m'avais indiqué, ( j'imagine qu'il faut que je vide ma corbeille aussi ?)
    par contre quand je vais dans C :\
    Program files
    interactual - interactualplayer
    je trouve pas le fichier iti2.tmp,( le plus ressemblant c'est itidib2.ddl )
    et dans "documents and settings"
    "all users"
    DRM : pas de dossier DRM
    j'ai cherché dans tous les dossiers "all users" "bureau" "documents partagés"...
    mais pas de fichier Indiv01.tmp

    Là je te poste du travail, dès que je rentre chez moi, je m'occupe de Kaspersky et t'envoie le rapport en fin d'après-midi.

    Petites questions :
    J'avais 5 - 6 trucs dans ma zone de quarantaine d'avast ( trojan...), donc quand j'ai supprimé avast, pas de risques de remettre en route ces bestioles ?

    Sinon tu me conseilles d'enlever ad adware, ok, mais je mets quoi à la place, spybot ?

    merci
    0
  20. afideg Messages postés 10466 Date d'inscription   Statut Contributeur sécurité Dernière intervention   602
     
    Re,

    ATTENTION: En langage informatique, il faut suivre "à la lettre près" les informations reçues.
    Donc, quand je demande de supprimer iti2.tmp, il ne faut toucher à rien d'autre
    ==> et donc ne pas supprimer itidib2.ddl.
    Tu as bien réagi en me questionnant.
    Cela étant dit, que fais-tu avec ce logiciel C:\Program Files\InterActual\ <-- ce dossier ?
    S'il n'est pas vital pour ton entreprise, supprime-le.

    NOTE: Il n'y avait aucune nécessité absolue à supprimer ce fichier avec une extension .temp.
    Ce sont des fichiers temporaires qui se construisent tout au long de ta session en cours.
    Je voulais te donner l'occasion d'une manipulation utile quand on a un PC.

    Lis ceci pour l'avenir :

    1°- Télécharger : ATF-Cleaner < http://www.atribune.org/ccount/click.php?id=1 >
    Tuto < http://mickael.barroux.free.fr/securite/atf_cleaner.php > ,
    et le lancer tous les jours quand tu quittes le PC.

    2°- Aussi (mais incomplet) ==> Sur la "barre de menus" de la page de navigation IE, clic sur "OUTILS", ensuite sur "OPTIONS INTERNET», tu obtiens ceci : < http://img221.imageshack.us/img221/416/screenshot273cl3.gif >.
    Tous les jours, en fin de session, tu cliques sur le bouton radio [supprimer le cookies], ensuite sur [supprimer les fichiers... ]

    3°- Toujours sur la "barre de menus" de la page de navigation IE, clic sur "OUTILS", ensuite sur "OPTIONS INTERNET», choisis l'onglet "Confidentialité" et positionne les réglages "au minimum sur Moyen".
    - Utilise ensuite le bouton "Avancé..." pour activer "Ignorer la gestion automatique des cookies" et "Refuser" les "Cookies tierce partie".

    À ce soir
    Al.
    0
  21. ankhaz
     
    bonjour,

    j'ai pris note pour "lis ceci pour l'avenir", je m'en occupe de suite,

    en attendant voilà le rapport de Kaspersky :

    Monday, March 10, 2008 5:35:38 PM
    Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky On-line Scanner version : 5.0.83.0
    Dernière mise à jour de la base antivirus Kaspersky : 10/03/2008
    Enregistrements dans la base antivirus Kaspersky : 622079
    Paramètres d'analyse
    Analyser avec la base antivirus suivante étendue
    Analyser les archives vrai
    Analyser les bases de messagerie vrai
    Cible de l'analyse Poste de travail
    C:\
    D:\
    Statistiques de l'analyse
    Total d'objets analysés 53737
    Nombre de virus trouvés 0
    Nombre d'objets infectés 0 / 0
    Nombre d'objets suspects 0
    Durée de l'analyse 01:03:36

    Nom de l'objet infecté Nom du virus Dernière action
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\marine\Application Data\MailFrontier\ASD.log L'objet est verrouillé ignoré
    C:\Documents and Settings\marine\Cookies\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\marine\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\marine\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\marine\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\marine\Local Settings\Temp\~DF89F.tmp L'objet est verrouillé ignoré
    C:\Documents and Settings\marine\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\marine\NTUSER.DAT L'objet est verrouillé ignoré
    C:\Documents and Settings\marine\ntuser.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\Cookies\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
    C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
    C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP382\change.log L'objet est verrouillé ignoré
    C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\Internet Logs\fwdbglog.txt L'objet est verrouillé ignoré
    C:\WINDOWS\Internet Logs\fwpktlog.txt L'objet est verrouillé ignoré
    C:\WINDOWS\Internet Logs\IAMDB.RDB L'objet est verrouillé ignoré
    C:\WINDOWS\Internet Logs\M30.ldb L'objet est verrouillé ignoré
    C:\WINDOWS\Internet Logs\tvDebug.log L'objet est verrouillé ignoré
    C:\WINDOWS\ModemLog_TOSHIBA Software Modem AMR.txt L'objet est verrouillé ignoré
    C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
    C:\WINDOWS\SoftwareDistribution\EventCache\{4AF7F8D3-5C02-44BB-B89C-5D6EAFCB987E}.bin L'objet est verrouillé ignoré
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
    C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
    C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
    C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\drivers\fidbox.dat L'objet est verrouillé ignoré
    C:\WINDOWS\system32\drivers\fidbox.idx L'objet est verrouillé ignoré
    C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
    C:\WINDOWS\Temp\ZLT03de2.TMP L'objet est verrouillé ignoré
    C:\WINDOWS\Temp\ZLT06393.TMP L'objet est verrouillé ignoré
    C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
    C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
    C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
    Analyse terminée.

    Comme hier, je n'arrive toujours pas à te mettre le rapport d'antivir,
    j'ai essayé avec internet explorer et pareil le rapport ne se colle pas, l'ordi bug et me met que le programme ne répond pas !!
    en plus aujourd'hui j'ai eu un écran noir au démarrage de l'ordi, en suivant les instructions de windows, j'ai redémarrer avec la dernière configuration ( j'ai bien fait ou alors il fallait que je rédémarre windows normalement ? )
    j'ai essayé aussi de coller le rapport antivir dans un doc word pour ensuite le coller ici ( ça n'a pas marché non plus ), et là encore en voulant fermer le doc word, le programme ne répondait plus, et dans la fenêtre suivante pour envoyer le rapport d'erreur à microsoft, ça me mettait " eve.center.exe" comme nom de fichier, alors que moi je l'ai laissé avec comme nom "doc1" ( j'espère que je suis claire dans les explications ! )

    Sinon, la souris, elle se tient tranquille,
    par contre j'ai toujours par moment le texte qui se brouille ainsi que des points et des traits verticaux, mais là c'est peut-être ma dalle lcd qui me lâche ( l'ordi a 3 ans )

    merci
    0
  • 1
  • 2