Problème mot de passe

Résolu
Bonjour,
mon mot de passe est devenue inconnu, ainsi que la réponse à ma question secrète, je n'arrive plus à me connecter sur facebook, ni sur msn, ni sur ma messagerie hotmail barbarou13@hotmail.fr. Aucun moyen de secours que je connais marche. Lors de ma connection sur msn un message m'indique l'erreur 80048821
merci pour votre aide.
Configuration: Windows XP Internet Explorer 7.0

30 réponses

Résumé de la discussion

Le fil décrit une perte d'accès à plusieurs services en ligne (Facebook, MSN et Hotmail) suite à l'erreur 80048821, avec l'oubli du mot de passe et de la réponse à la question secrète. Plusieurs éléments préconisent d'afficher les fichiers cachés, lancer des outils de nettoyage et repérer une menace spécifique comme cacgaym.exe afin de la supprimer définitivement rapidement. En cas d'infection avérée, l'emploi de Malwarebytes, le mode sans échec et des outils dédiés comme MSNFix ou HijackThis peut être utile pour analyser les rapports et expliquer les mesures à suivre. Des éléments d'analyse complémentaires évoquent l'examen des rapports et des résultats antivirus pour évaluer l'infection et guider les prochaines étapes dans les cas similaires rencontrés.

Bobot (l’IA à votre service)
  1. Non ben je pense que c'est bon.
    Ton pc est débarrasser de ce keylogger.
    Si on te vole encore ton compte msn, le poste reste ouvert et n'hésite pas a me poster un rapport .

    Bonne continuation !
    0
    1. merci beaucoup pour ton aide et ta rapidité à me repondre
      0
  2. Suis mes indications pour supprimer ce Trojan

    ~~~~~~~~~~~~~~~~> Virustotal <~~~~~~~~~~~~~~~~~~~

    Tu vas scanner le fichier cmdow.exe ce situant : c:/WINDOWS/system32/cmdow.exe

    - Va sur Virustotal
    >https://www.virustotal.com/gui/

    - Fait parcourir et cherche le fichier cmdow.exe ce situant dans c:/WINDOWS/system32/cmdow.exe
    >***
    - Virustotal va scanner ton fichier
    /!\ Laisse l'analyse ce terminer correctement /!\

    - Une fois le fichier scanner poste moi le rapport du fichier cmdow.exe , je veut le rapport entier
    0
    1. Antivirus Version Dernière mise à jour Résultat
      a-squared 4.5.0.18 2009.07.09 Riskware.RiskTool.Win32.HideWindows!IK
      AhnLab-V3 5.0.0.2 2009.07.09 -
      AntiVir 7.9.0.204 2009.07.09 APPL/HideWindows.31232.1
      Antiy-AVL 2.0.3.1 2009.07.09 -
      Authentium 5.1.2.4 2009.07.09 -
      Avast 4.8.1335.0 2009.07.09 -
      AVG 8.5.0.386 2009.07.09 -
      BitDefender 7.2 2009.07.09 -
      CAT-QuickHeal 10.00 2009.07.09 (Suspicious) - DNAScan
      ClamAV 0.94.1 2009.07.09 -
      Comodo 1595 2009.07.09 ApplicUnsaf.Win32.CMDOW.143
      DrWeb 5.0.0.12182 2009.07.09 Tool.HideWindows
      eSafe 7.0.17.0 2009.07.09 -
      eTrust-Vet 31.6.6606 2009.07.09 -
      F-Prot 4.4.4.56 2009.07.09 -
      F-Secure 8.0.14470.0 2009.07.09 RiskTool.Win32.HideWindows
      Fortinet 3.117.0.0 2009.07.03 HackerTool/HideWindow
      GData 19 2009.07.09 -
      Ikarus T3.1.1.64.0 2009.07.09 not-a-virus:RiskTool.Win32.HideWindows
      Jiangmin 11.0.706 2009.07.09 -
      K7AntiVirus 7.10.788 2009.07.09 Non-Virus:RiskTool.Win32.HideWindows
      Kaspersky 7.0.0.125 2009.07.09 not-a-virus:RiskTool.Win32.HideWindows
      McAfee 5671 2009.07.09 potentially unwanted program Tool-HideWindow
      McAfee+Artemis 5671 2009.07.09 potentially unwanted program Tool-HideWindow
      McAfee-GW-Edition 6.8.5 2009.07.09 Heuristic.LooksLike.Win32.HideWindows.L
      Microsoft 1.4803 2009.07.09 Tool:Win32/Cmdow
      NOD32 4229 2009.07.09 Win32/CMDOW.143
      Norman 6.01.09 2009.07.09 -
      nProtect 2009.1.8.0 2009.07.09 -
      Panda 10.0.0.14 2009.07.09 -
      PCTools 4.4.2.0 2009.07.09 RiskTool.HideWindows.K
      Prevx 3.0 2009.07.09 -
      Rising 21.37.34.00 2009.07.09 -
      Sophos 4.43.0 2009.07.09 HideWindow
      Sunbelt 3.2.1858.2 2009.07.09 -
      Symantec 1.4.4.12 2009.07.09 SecurityRisk.Cmdow
      TheHacker 6.3.4.3.363 2009.07.08 Aplicacion/HideWindows
      TrendMicro 8.950.0.1094 2009.07.09 PAK_Generic.001
      VBA32 3.12.10.7 2009.07.09 -
      ViRobot 2009.7.9.1827 2009.07.09 Not_a_virus:RiskTools.HideWindows.31232
      VirusBuster 4.6.5.0 2009.07.09 RiskTool.HideWindows.K
      Information additionnelle
      File size: 31232 bytes
      MD5...: 48a78bf8ef453d9ca4d6c0587ae2de94
      SHA1..: fdcc71edb09d13165abb106dec95b5376cc05527
      SHA256: 319390597ae00859d5862aec261584cdb8e6c863c06ac69fecbe374165491756
      ssdeep: 384:nuqo9Bl0uuBLutbA4rjsWVjbeGDdamJClleaGylF6wB0RwGWm6CimkZR55yy
      n0:uqo9bnlfJzQ3eapNtmNwL55ys0

      PEiD..: -
      TrID..: File type identification
      Windows Screen Saver (39.4%)
      Win32 Executable Generic (25.6%)
      Win32 Dynamic Link Library (generic) (22.8%)
      Generic Win/DOS Executable (6.0%)
      DOS Executable Generic (6.0%)
      PEInfo: PE Structure information

      ( base data )
      entrypointaddress.: 0x7748
      timedatestamp.....: 0x41c566e5 (Sun Dec 19 11:32:53 2004)
      machinetype.......: 0x14c (I386)

      ( 3 sections )
      name viradd virsiz rawdsiz ntrpy md5
      .rdata 0x1000 0x6a4 0x800 4.53 117c0711fefe4b7aa08b03bfb8c7853a
      .data 0x2000 0x6938 0x6600 6.11 ec36eef2210936e7ebbbca9c69971f0e
      .rsrc 0x9000 0x7d0 0x800 3.29 eec57ea28d67832abe028cf50c0a6d63

      ( 4 imports )
      > KERNEL32.dll: GetProcessHeap, lstrlenA, ExitProcess, WriteFile, GetStdHandle, lstrcatA, GetCommandLineA, SetConsoleDisplayMode, GetVersionExA, WideCharToMultiByte, Sleep, SetConsoleTitleA, GetCurrentProcessId, GetTickCount, HeapAlloc, CloseHandle, TerminateProcess, OpenProcess, CreateProcessA, HeapReAlloc, HeapFree, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, MultiByteToWideChar, RtlUnwind, lstrcpyA, lstrcmpiA, GetConsoleTitleA, lstrcmpA
      > USER32.dll: GetParent, GetWindow, GetWindowLongA, IsWindow, GetForegroundWindow, SetForegroundWindow, SystemParametersInfoA, ShowWindowAsync, GetWindowRect, SetWindowTextA, MoveWindow, SetWindowPos, GetWindowThreadProcessId, GetWindowTextLengthA, GetWindowTextA, GetClassNameA, EnableWindow, ScreenToClient, GetDesktopWindow, EnumWindows, wsprintfA, wvsprintfA, FindWindowA, PostMessageA, EnumChildWindows
      > ADVAPI32.dll: RegCloseKey, RegOpenKeyExA, RegQueryValueExA
      > SHELL32.dll: ShellExecuteA

      ( 0 exports )

      PDFiD.: -
      RDS...: NSRL Reference Data Set
      -
      ThreatExpert info: <a href='http://www.threatexpert.com/report.aspx?md5=48a78bf8ef453d9ca4d6c0587ae2de94' target='_blank'>https://www.symantec.com?md5=48a78bf8ef453d9ca4d6c0587ae2de94</a>
      0
  3. voila ce qu'ils disent sur ce virus

    Aliases
    not-a-virus:RiskTool.Win32.HideWindows (Kaspersky Lab) is also known as: IRC/Flood.cl.hidewin (McAfee), Trojan.Flood.22016 (Doctor Web), Tool:Win32/HideWindows (RAV), TROJ_FLOOD.A (Trend Micro), TR/Drop.Small.WH (H+BEDV), HideWindow (Grisoft), Virtool.Hidewindows.C (SOFTWIN), Trojan.IRC.Flood.AQ (ClamAV), Application/HideWin (Panda) Detection added Jul 30 2005
    Behavior not-a-virus:RiskTool

    Currently there is no description available for this program.

    As many viruses and worms are modifications of earlier versions, it may help you to check the descriptions of similar programs. If such descriptions are available, they will be listed at the top of the page.

    Our virus analysts work hard to ensure that descriptions of the commonest and most potentially dangerous software are available to users. The Virus Encyclopedia is updated on a regular basis.

    If you cannot find the description you need, please check back later, or contact us on webmaster@viruslist.com.
    0
    1. j'ai trouvé comment contacter msn
      0
      1. Il faut que tu contact Msn comme quoi tu t'est fait hacker ton compte msn.

        As tu fait Kaspersky et Ccleaner ?
        0
        1. kaspersky est toujours en analyse et ccleaner ne trouve plus rien à supprimer.
          comment puis-je contacter msn?
          0
      2. un bloc note s'est ouvert avec hijackthis, dois-je le poster?
        0
        1. que veut dire "contacter le support" pour reccupérer mes mots de passe?
          la question secrète ne marche pas non plus
          j'ai coché toutes les lignes et les ai effacées enfin en tout cas j'ai suivi toutes les étapes pour "HijackThis"
          0
          1. ~~~~~~~~~~~~~~~~> Hijack This <~~~~~~~~~~~~~~~~~~~

            - Telecharger Hijack
            >http://ftpclubic22.clubic.com/...

            Une fois Hijack installer, exécuter le :
            - Cliquer sur "Do a system scan and save a logfile"

            Coche les ligne suivante :

            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
            O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
            O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
            O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.1.cab
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)


            Apres avoir coché ces lignes, cliquer sur Fix checked
            0
            1. ccleaner ne trouve plus rien à supprimer avec le nettoyeur ni avec le registre.
              0
          2. Donc je t'explique ce que j'ai fait, j'ai tout désinfecter ton pc parce que perde tout ces mots de passe est vraiment très louche donc j'ai supposer un Keylogger, enfin bref ...
            Pour récupérer tes mots de passes contact le support ou regarde si il y a moyen de répondre a une question secrète, ect ...
            On va continuer comme ca tu auras un Pc Clean .
            Pour cela

            ~~~~~~> Scan du Pc avec l'antivirus en ligne Kaspersky <~~~~~~

            Se rendre sur ce lien : https://www.kaspersky.fr/downloads

            /!\ Utiliser Internet Explorer ou Firefox /!\</gras>

            - En bas, à droite de la fenêtre, cliquez sur Kaspersky Online Scanner

            - Dans la nouvelle fenêtre qui s'ouvre, cliquez sur: J'accepte

            * Si ce bandeau jaune apparaît en haut de la fenêtre, clic gauche sur le bandeau et ==> Acceptez d'installer le contrôle ActiveX

            * Le téléchargement est alors proposé.

            * Le scan va à présent s'initialiser et mettre à jour sa base de données

            * A présent, vous choisir la cible. C'est à dire indiquer quel emplacement va être analysé. Choisir My computer.

            * Le scan est à présent lancé, il ne reste plus qu'à attendre qu'il se termine.
            * Une fois le scan achevé, vous obtenez une fenêtre (en fonction de ce qui est trouvé sur votre PC) :

            * Il ne reste plus qu'à enregistrer le rapport afin de pouvoir le poster sur le forum

            __________________________________________________________________________________

            ~~~~~~~~~~~~~~~~~~~~> Ccleaner <~~~~~~~~~~~~~~~~~~~~~~~~~

            * Télécharger et installer CCleaner .
            > http://www.commentcamarche.net/telecharger/telecharger 168 ccleaner
            /!\ Ne pas installer la Yahoo! Toolbar /!\

            * Dans l'onglet "Nettoyeur", cliquer sur "Analyser".
            * Une fois l'analyse terminée, cliquer sur "Nettoyer".
            * Recommencer jusqu’à ce qu’il ne trouve plus rien (cela varie en général entre 1 et 4 fois).

            * Dans l'onglet " Registre ", cliquer sur " Chercher les erreurs "
            * Une fois l'analyse terminée, cliquer sur " Corriger les erreurs sélectionnées "
            * Recommencer jusqu’à ce qu’il ne trouve plus rien.

            ______________________________________________________________________________________

            N'oublie pas de mettre a jour tout tes logiciel de sécurités et j'attends le rapport de Kaspersky.

            0
            1. Le scan Malwarebytes et supprimer le fichier cacgaym.exe qui était infecté.
              Je vais analyser le rapport que tu ma donner et regarder si je trouve encore quelque chose et je te redis tout cela cette après midi .
              0
              1. je ne trouve pas le fichier info dans la barre des tâches
                MSNFix : lorsque j'appuie sur A la fenêtre bleue se ferme sans laisser de rapport. le dernier message est
                *********infection absente**********
                l'infection n'a pas était trouvée
                voila il y a t'il autre chose que je doives faire ?
                bonne chance pour l'analyse
                0
                1. log bloc note le fichier info ne s'est pas ouvert

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by Propriétaire at 2009-07-09 09:21:26
                  Microsoft Windows XP Édition familiale Service Pack 3
                  System drive C: has 4 GB (8%) free of 57 GB
                  Total RAM: 1023 MB (47% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 09:21:35, on 09/07/2009
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  C:\Program Files\Windows Live\Family Safety\fsui.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                  C:\Program Files\Electronic Arts\EADM\Core.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
                  C:\Program Files\DNA\btdna.exe
                  C:\WINDOWS\system32\RUNDLL32.EXE
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\Panasonic\MotionSD STUDIO\SD_Browser\AutoLauncher.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\WINDOWS\system32\bgsvcgen.exe
                  C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\CNAC3RPK.EXE
                  C:\Program Files\CDBurnerXP\NMSAccessU.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Windows Live\Toolbar\wltuser.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
                  C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\SJJQCUUQ\RSIT[1].exe
                  C:\Program Files\trend micro\Propriétaire.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
                  O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                  O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                  O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
                  O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                  O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
                  O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
                  O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: MotionSD STUDIO - Auto-activation Navigateur SD -.lnk = C:\Program Files\Panasonic\MotionSD STUDIO\SD_Browser\AutoLauncher.exe
                  O8 - Extra context menu item: Download Video on This Page - C:\Program Files\Tomato\YouTube Video Downloader\IEPage.html
                  O8 - Extra context menu item: Download Video This Links To - C:\Program Files\Tomato\YouTube Video Downloader\IELink.html
                  O9 - Extra button: Download Video - {11F19C45-9675-488A-A8E0-8E8234DC245D} - C:\Program Files\Tomato\YouTube Video Downloader\IEPage.html
                  O9 - Extra 'Tools' menuitem: Download Video on This Page - {11F19C45-9675-488A-A8E0-8E8234DC245D} - C:\Program Files\Tomato\YouTube Video Downloader\IEPage.html
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O14 - IERESET.INF: START_PAGE_URL=https://www.google.fr/?gws_rd=ssl
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                  O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                  O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                  O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.1.cab
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
                  O23 - Service: Service Google Update (gupdate1c9b44d52559d16) (gupdate1c9b44d52559d16) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
                  O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
                  O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe
                  0
                  1. rapport du scann

                    Malwarebytes' Anti-Malware 1.38
                    Version de la base de données: 2394
                    Windows 5.1.2600 Service Pack 3

                    08/07/2009 20:31:39
                    mbam-log-2009-07-08 (20-31-39).txt

                    Type de recherche: Examen complet (C:\|)
                    Eléments examinés: 194651
                    Temps écoulé: 1 hour(s), 10 minute(s), 41 second(s)

                    Processus mémoire infecté(s): 1
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 5
                    Valeur(s) du Registre infectée(s): 1
                    Elément(s) de données du Registre infecté(s): 1
                    Dossier(s) infecté(s): 0
                    Fichier(s) infecté(s): 3

                    Processus mémoire infecté(s):
                    C:\documents and settings\propriétaire\local settings\application data\cacgaym.exe (Adware.Navipromo.H) -> Unloaded process successfully.

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                    HKEY_LOCAL_MACHINE\SOFTWARE\OOO (Rogue.LivePlayer) -> Quarantined and deleted successfully.
                    HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.
                    HKEY_CURRENT_USER\SOFTWARE\OOO (Malware.Trace) -> Quarantined and deleted successfully.
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Live-Player (Malware.Trace) -> Quarantined and deleted successfully.

                    Valeur(s) du Registre infectée(s):
                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cacgaym (Adware.Navipromo.H) -> Quarantined and deleted successfully.

                    Elément(s) de données du Registre infecté(s):
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                    Dossier(s) infecté(s):
                    (Aucun élément nuisible détecté)

                    Fichier(s) infecté(s):
                    c:\documents and settings\propriétaire\local settings\application data\cacgaym_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                    c:\documents and settings\propriétaire\local settings\application data\cacgaym.dat (Adware.Navipromo.H) -> Delete on reboot.
                    c:\documents and settings\propriétaire\local settings\application data\cacgaym.exe (Adware.Navipromo.H) -> Delete on reboot.
                    0
                    1. Télécharger sur le bureau MSNFix.zip
                      >http://sosvirus.changelog.fr/MSNFix.zip

                      - Clic-Droit sur MSNFix.zip
                      - Extraire ici ( ou extraire sans confirmation ou tout ou unzip)
                      - Double-Clic sur le dossier MSNfix qui vient de se créer
                      - Double-Clic MSNfix ( Symbole roue dentée )

                      - Choisir F pour français
                      - Choisir R ( pour rechercher les infections )
                      - Choisir ensuite A quand le choix se présent
                      - Choisir ensuite N ( si infection)
                      - Enregistrer le rapport sur le bureau de préférence

                      0
                      1. Pour le supprimer tu va démarrer en mode sans echec, pour cela :

                        - Redémarre ton PC, et dès qu'il se relance tape la touche F8 ou F5 toutes les secondes. Tu verras alors une fenêtre

                        - A l'aide des touches directionnelles, sélectionne Mode sans échec, qui sera ainsi mis en surbrillance. Appui ensuite sur la touche Enter ou Entrée.
                        Un nouvel écran apparaît :

                        - Choisi le système d'exploitation qui démarreras en Mode sans échec avec les touches directionnelles et validez en appuyant sur la touche Enter ou Entrée.

                        /!\ Le Mode sans échec peut mettre un certain temps à démarrer, soit patient !
                        0
                        1. Bien ,

                          Surprime ce fichier

                          ~~~~~~>Télécharge Malwarebytes <~~~~~~

                          - Sur la page clique sur Télécharger Malwarebyte’s Anti-Malware
                          - Enregistre le sur le bureau
                          - Double clique sur le fichier téléchargé pour lancer le processus d’installation
                          - Lorsqu’il te le sera demandé, mets à jour Malwarebytes anti malware
                          - Si le pare-feu demande l’autorisation de se connecter pour malwarebytes, acceptes
                          - Une fois la mise à jour terminée, ferme Malwarebytes

                          - Double-clique sur l’icône de malwarebytes pour le relancer
                          - Dans l’onglet, Recherche, probablement ouvert par défaut,
                          - Sélectionne Exécuter un examen complet
                          - Clique sur Rechercher
                          - Le scan démarre

                          - A la fin de l’analyse, un message s’affiche : L’examen s’est terminé normalement. Cliquez sur ‘Afficher les résultats’ pour afficher tous les objets trouvés.
                          - Clique sur Ok pour poursuivre.
                          - Si des malwares ont été détectés, cliques sur Afficher les résultats
                          - Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                          - Malwarebytes va ouvrir le bloc-notes et y copier le rapport d’analyse.
                          - Rends toi dans l’onglet rapport/log
                          - Tu clique dessus pour l’afficher.
                          - Une fois affiché, cliques sur édition en haut du bloc notes, et puis sur sélectionner tout
                          - Tu recliques sur édition et puis sur copier et tu reviens sur le forum et dans ta réponse
                          - Tu clique droit dans le cadre de la réponse et coller

                          *****

                          * Télécharger Random's System Information Tool (RSIT) sur le Bureau.
                          > http://images.malwareremoval.com/random/RSIT.exe

                          * Double-cliquer sur RSIT.exe afin de lancer le programme (Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur).

                          * Cliquer sur Continue à l'écran Disclaimer.

                          * Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autoriser l'accès dans le pare-feu, si demandé) et vous devrez accepter la licence.

                          * Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poster le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que vous verrez dans la barre des tâches)
                          0
                          1. bonne chance !

                            Fichier cacgaym.exe reçu le 2009.07.08 15:12:33 (UTC)
                            Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE

                            Résultat: 1/41 (2.44%)
                            en train de charger les informations du serveur...
                            Votre fichier est dans la file d'attente, en position: 1.
                            L'heure estimée de démarrage est entre 43 et 62 secondes.
                            Ne fermez pas la fenêtre avant la fin de l'analyse.
                            L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
                            Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
                            Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
                            les résultats seront affichés au fur et à mesure de leur génération.
                            Formaté Impression des résultats Votre fichier a expiré ou n'existe pas.
                            Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.
                            Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée. Email:

                            Antivirus Version Dernière mise à jour Résultat
                            a-squared 4.5.0.18 2009.07.08 -
                            AhnLab-V3 5.0.0.2 2009.07.08 -
                            AntiVir 7.9.0.204 2009.07.08 -
                            Antiy-AVL 2.0.3.1 2009.07.08 -
                            Authentium 5.1.2.4 2009.07.08 -
                            Avast 4.8.1335.0 2009.07.07 -
                            AVG 8.5.0.386 2009.07.08 -
                            BitDefender 7.2 2009.07.08 -
                            CAT-QuickHeal 10.00 2009.07.08 -
                            ClamAV 0.94.1 2009.07.08 -
                            Comodo 1578 2009.07.08 -
                            DrWeb 5.0.0.12182 2009.07.08 -
                            eSafe 7.0.17.0 2009.07.08 -
                            eTrust-Vet 31.6.6602 2009.07.08 -
                            F-Prot 4.4.4.56 2009.07.07 -
                            F-Secure 8.0.14470.0 2009.07.08 -
                            Fortinet 3.117.0.0 2009.07.03 -
                            GData 19 2009.07.08 -
                            Ikarus T3.1.1.64.0 2009.07.08 -
                            Jiangmin 11.0.706 2009.07.08 -
                            K7AntiVirus 7.10.787 2009.07.08 -
                            Kaspersky 7.0.0.125 2009.07.08 -
                            McAfee 5669 2009.07.07 -
                            McAfee+Artemis 5669 2009.07.07 -
                            McAfee-GW-Edition 6.8.5 2009.07.08 -
                            Microsoft 1.4803 2009.07.08 -
                            NOD32 4224 2009.07.08 -
                            Norman 6.01.09 2009.07.07 -
                            nProtect 2009.1.8.0 2009.07.08 -
                            Panda 10.0.0.14 2009.07.08 -
                            PCTools 4.4.2.0 2009.07.08 -
                            Prevx 3.0 2009.07.08 Low Risk Adware
                            Rising 21.37.24.00 2009.07.08 -
                            Sophos 4.43.0 2009.07.08 -
                            Sunbelt 3.2.1858.2 2009.07.08 -
                            Symantec 1.4.4.12 2009.07.08 -
                            TheHacker 6.3.4.3.363 2009.07.08 -
                            TrendMicro 8.950.0.1094 2009.07.08 -
                            VBA32 3.12.10.7 2009.07.08 -
                            ViRobot 2009.7.8.1824 2009.07.08 -
                            VirusBuster 4.6.5.0 2009.07.08 -
                            Information additionnelle
                            File size: 270336 bytes
                            MD5...: 106934870e6b779a25c0e10e908530ee
                            SHA1..: 4909818f1089599d3c30e8d73b143f849732ff99
                            SHA256: 7559faacfdc815e86255b686e4cd1530307baa6b850238b24eca95fe1ef86470
                            ssdeep: 6144:b5mJvlUIa/UWWKLbxFNEaWOk32O/sTu5R:14UDlWKLbxFNEa/IsTQ

                            PEiD..: Armadillo v1.71
                            TrID..: File type identification
                            Win32 Executable MS Visual C++ (generic) (65.2%)
                            Win32 Executable Generic (14.7%)
                            Win32 Dynamic Link Library (generic) (13.1%)
                            Generic Win/DOS Executable (3.4%)
                            DOS Executable Generic (3.4%)
                            PEInfo: PE Structure information

                            ( base data )
                            entrypointaddress.: 0x216a
                            timedatestamp.....: 0x4455c8ec (Mon May 01 08:38:04 2006)
                            machinetype.......: 0x14c (I386)

                            ( 3 sections )
                            name viradd virsiz rawdsiz ntrpy md5
                            .text 0x1000 0x33e9a 0x34000 7.45 d9c8250a440c015ba984a1f83355a0ff
                            .data 0x35000 0xa486 0xb000 4.45 d3a53518288266db5eafa480f23285f9
                            .rsrc 0x40000 0x1300 0x2000 2.24 3eb5a6b885100dc094e775ae66244f25

                            ( 11 imports )
                            > COMCTL32.dll: ImageList_GetBkColor, ImageList_GetImageInfo, ImageList_Replace, ImageList_DragEnter, ImageList_SetDragCursorImage
                            > OLEAUT32.dll: -
                            > KERNEL32.dll: GetThreadLocale, OpenFile, WaitForSingleObject, FlushFileBuffers, GetModuleHandleA, LocalLock, GetPrivateProfileStringA, GetCurrentThreadId, GetTimeFormatA, CopyFileA, ExitProcess, GlobalFindAtomA, FindResourceExW, GetPrivateProfileSectionA, FindResourceW, GetEnvironmentStrings, WriteConsoleA, QueryDosDeviceA, CreateThread, GlobalGetAtomNameW, TlsAlloc, lstrcmpA, GetTempPathA, GetTempFileNameW, OpenMutexW, GetProcessAffinityMask, HeapCreate, GetModuleFileNameA, UnhandledExceptionFilter, GetStartupInfoA, GetVersion, TerminateProcess, GetCurrentProcess, HeapAlloc, GetCPInfo, GetACP, GetOEMCP, TlsSetValue, TlsGetValue, GetLastError, FreeEnvironmentStringsA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, GlobalUnlock, GetStdHandle, GetFileType, GetEnvironmentVariableA, GetVersionExA, HeapDestroy, VirtualFree, HeapFree, RtlUnwind, WriteFile, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, HeapReAlloc, MultiByteToWideChar, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, GetProcAddress, LoadLibraryA, InterlockedDecrement, InterlockedIncrement, CompareStringW, GetSystemDirectoryW, GetProfileStringA, CreateFileMappingA, SearchPathA, WritePrivateProfileStringW, RemoveDirectoryA, _lread, FindNextChangeNotification, CreateTimerQueue, SetLastError, SetHandleCount, TlsFree, GetSystemWindowsDirectoryW, VirtualAlloc, GetCommandLineA, CreateTimerQueueTimer, CreateFileA, GetSystemInfo
                            > ole32.dll: CoCreateFreeThreadedMarshaler, OleIsRunning, StgCreateDocfile, CreateFileMoniker, CoInitialize, WriteClassStg, CoTaskMemAlloc, OleSetContainedObject
                            > SHELL32.dll: ExtractIconExW, SHFileOperationA, SHGetPathFromIDListA
                            > USER32.dll: SetWindowPlacement, GetCursor, DialogBoxIndirectParamW, ValidateRgn, RegisterClassExW, AllowSetForegroundWindow, GetClientRect, LoadBitmapA, DrawTextA, InsertMenuItemA, ReuseDDElParam, ClientToScreen, InSendMessage, GetIconInfo, IsClipboardFormatAvailable, EnableScrollBar, DrawStateW, CharNextA, LoadStringW, CharUpperW, SendMessageW, FrameRect, TrackPopupMenu, GetActiveWindow, RegisterClipboardFormatW, DestroyMenu, EnumThreadWindows, CreateDialogIndirectParamW, DrawFocusRect, GetMenuCheckMarkDimensions, DefMDIChildProcA, InsertMenuA, DdeCreateDataHandle, MonitorFromPoint, GetDialogBaseUnits, GetWindowLongA, GetUserObjectInformationW, UnregisterClassW, GetQueueStatus, GetPropA, CreateDialogParamW, SendMessageTimeoutA, InvertRect, GetCapture, FillRect, SetWindowLongW, SetScrollPos, GetPropW, BeginPaint, LoadAcceleratorsA, ActivateKeyboardLayout, CharLowerBuffA, EnumChildWindows, ReplyMessage, UnregisterClassA, SetForegroundWindow, TrackPopupMenuEx, GetClassInfoW, UpdateLayeredWindow, DeferWindowPos, OffsetRect, SetMenuItemInfoW, MsgWaitForMultipleObjects, CreateAcceleratorTableW, ChildWindowFromPoint, DdeUninitialize, IsRectEmpty, GetScrollRange, CharLowerW, IsCharAlphaW, CopyAcceleratorTableA, ShowCursor, CharUpperA, SetWindowsHookExA, CharToOemBuffA, SetDlgItemInt, MessageBoxA, GrayStringW, GetDCEx
                            > GDI32.dll: DeleteEnhMetaFile, SetDIBits, CreateFontIndirectW, GetTextFaceW
                            > comdlg32.dll: ChooseColorA, GetOpenFileNameW, GetOpenFileNameA
                            > SHLWAPI.dll: StrStrIW, StrCmpIW, PathRenameExtensionW
                            > ADVAPI32.dll: CryptGenRandom, GetSecurityDescriptorSacl, CreateServiceW, RegQueryValueA, MakeAbsoluteSD, RegQueryInfoKeyW, RegQueryValueW, RegDeleteKeyA, SetEntriesInAclW, CryptDestroyKey, GetSecurityDescriptorOwner, ControlService, GetSecurityDescriptorLength, RegCloseKey, RegFlushKey
                            > VERSION.dll: GetFileVersionInfoSizeW

                            ( 0 exports )

                            PDFiD.: -
                            RDS...: NSRL Reference Data Set
                            -
                            Prevx info: <a href='http://info.prevx.com/aboutprogramtext.asp?PX5=F23C92E20019AF8120410435D9F57000881AC8A0' target='_blank'>http://info.prevx.com/aboutprogramtext.asp?PX5=F23C92E20019AF8120410435D9F57000881AC8A0</a>
                            0
                            1. Il faut démasquer tes fichier masquer pour cela :

                              Poste de travaille >
                              > Outils
                              > Option des dossiers
                              > Onglet Affichage
                              > Coche " Afficher les fichiers et les dossiers cachés "
                              0
                              • 1
                              • 2