Problème avec zztoolbar

Résolu
Bonjour,
Mon problème c'est que après que j'ai formaté mon PC et pendant que j'ai été entrain de chercher d=sur le net à télécharger un antivirus mon PC était infecté par la barre de zztoolbar ce qu'a causé plusieurs effets sur mon PC :
- A la place de de l'adresse de Google dans la page de démarrage de explorer je trouve une autre adresse d'un site chinois.
- Le pare-feu de Windows XP se désactive tout seul.
- L'horloge de PC indique toujours l'année 2004 ce qu'il empêche les antivirus de s'installer( j'ai essayé avec avast, kaspersky, ...).
- Plusieurs fenêtres de Pub chinois s'ouvrent en même pas deux secondes ce qui bloque mon PC.
Alors j'ai activé une recherche sur le net pour trouver une solution à cette barre zztoolbar que je la trouve à chaque fois (même que je la supprime) dans le lecteur C. Alors j'ai fait des test avec X-cleaner mais à chaque fois qu'il arrive au dossier de zztoolbar il demande de le supprimer et puis redémarrer mais même cela après que je redémarre le problème reste le même. Puis j'ai fait d'autres testes avec ad-award 2008, spybot et Malwarebytes mais même cela ils indiquent des dossiers infectés mais même que je l'ai supprime et je redémarre après le problème reste comme avant des fenêtres de Pub, l'horloge en 2004 et le gros problème c'est que je ne peux pas activer aucun antivirus d'où mon pc risque toujours d'attraper d'autres virus.
A la fin j'ai décidé de formater mon PC mais même cela une fois que j'ai installé le kit de connexion et j'ai ouvert une fenetre d'explorer la barre de zztoolbar s'installe dans mon lecteur C w ce qu'il me parait vrmt bizarre!!!!
Je ne sais pas quoi faire mnt surtout avec cette situation...Je suis prête à toutes les solutions même formater mon PC une autre fois :S.
Je vous donne là le rapport de dernier scanne de Malwarebytes:

Malwarebytes' Anti-Malware 1.31
Version de la base de données: 1500
Windows 5.1.2600 Service Pack 2

15/12/2008 03:55:40
mbam-log-2008-12-15 (03-55-40).txt

Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 76501
Temps écoulé: 17 minute(s), 19 second(s)

Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 30
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 2
Fichier(s) infecté(s): 4

Processus mémoire infecté(s):
C:\WINDOWS\Fonts\svchost.exe (Trojan.Agent) -> Unloaded process successfully.

Module(s) mémoire infecté(s):
C:\Program Files\Fichiers communs\PushWare\cpush.dll (Adware.Sogou) -> Delete on reboot.

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\TypeLib\{de2267bd-b163-407f-9e8d-6adec771e7ab} (Adware.Sogou) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{0ad3ab16-6d0e-4f04-8660-fb1f36bc2dc0} (Adware.Sogou) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2f685b36-c53a-4653-9231-1dae5736de45} (Adware.Sogou) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{50c4cdd9-22d7-49ff-ac6d-7d4d528a3ab2} (Adware.Sogou) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{11f09afd-75ad-4e51-ab43-e09e9351ce16} (Adware.Sogou) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11f09afd-75ad-4e51-ab43-e09e9351ce16} (Adware.Sogou) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11f09afd-75ad-4e51-ab43-e09e9351ce16} (Adware.Sogou) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{34a12a06-48c0-420d-8f11-73552ee9631a} (Adware.Sogou) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{cde9eb54-a08e-4570-b748-13f5ddb5781c} (Adware.Sogou) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\newadpopup.toolbardetector (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\newadpopup.toolbardetector.1 (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\zzToolbar (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\newpush (Adware.CPush) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\cpush (Adware.CPush) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MicroPlugins (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32kui.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP.kxp (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.EXE (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.com (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRegEx.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmsk.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.kxp (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctor.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icesword.exe (Security.Hijack) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.OnlineGames) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.OnlineGames) -> Data: system32\userinit.exe -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
C:\Program Files\Fichiers communs\PushWare (Adware.CPush) -> Quarantined and deleted successfully.
C:\Program Files\zzToolBar (Trojan.BHO) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\Program Files\Fichiers communs\PushWare\cpush.dll (Adware.Sogou) -> Quarantined and deleted successfully.
C:\Program Files\zzToolBar\Toolbar_bho.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\beep.sys (Fake.Beep.Sys) -> Quarantined and deleted successfully.
C:\WINDOWS\Fonts\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.

Rq: Même que le logiciel indique qu'il a supprimé les fichiers avec succès mais une fois je redémarre la situation revient à son état avant le test.
Merci d'avance
Configuration: Windows XP
Firefox 3.0.4

37 réponses

Résumé de la discussion

Après un formatage, l’ordinateur est infecté par zzToolbar, entraînant une page d’accueil modifiée, la désactivation du pare-feu Windows XP, une horloge bloquée en 2004 et des fenêtres publicitaires qui s’ouvrent rapidement, rendant l’installation d’antivirus difficile. Les outils de sécurité (Malwarebytes, Spybot, Ad-Aware, X-Cleaner) détectent des éléments et les placent en quarantaine, mais les symptômes réapparaissent après redémarrage, et le lecteur C conserve l’installation de zzToolbar malgré les suppressions. Des réponses recommandent ToolsCleaner puis des antivirus gratuits (Antivir, AVG8, Avast), des anti-spyware et pare-feux alternatifs (Online Armor, Kerio, ZoneAlarm, Comodo), ainsi que CCleaner et un navigateur plus sûr qu’Internet Explorer, et la suppression des éléments en quarantaine.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    ok c'est bon

    pour virer ce qui a été utilisé:

    Télécharge ToolsCleaner sur ton bureau.
    --> http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
    # Clique sur Recherche et laisse le scan agir ...
    # Clique sur Suppression pour finaliser.
    # Tu peux, si tu le souhaites, te servir des Options facultatives.
    # Clique sur Quitter pour obtenir le rapport.
    # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

    pour protéger gratos ton ordi

    http://www.commentcamarche.net/telecharger/logiciel 4 securite

    mettre un antivirus

    ANTIVIR ou AVG8 ou (AVAST )
    https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
    -------------
    des anti-espions :
    MalwareByte's Anti-Malware + SPYBOT +/- si tea timer non active de spybot:
    WINDOWS DEFENDER ou SPYWARE TERMINATOR

    +
    SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

    Rq : spybot et ad-aware ont sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
    --------
    un pare feu :
    celui de (Windows) ou mieux Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit) ou COMODO

    http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall
    https://www.01net.com/telecharger/windows/Securite/firewall/fiches/39911.html
    https://forum.pcastuces.com/sujet.asp?f=25&s=35606
    https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
    https://manuelsdaide.com/contact/
    http://www.open-files.com/forum/index.php?showtopic=29277
    http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm

    -----------
    CCLEANER pour effacer les traces de surf
    ---------
    naviguer avec firefox ou safari ou opera et non internet explorer plus touché par les virus
    http://www.mozilla-europe.org/fr/products/firefox/
    1
    1. Contributeur sécurité
      slt

      Télécharge ici :

      http://images.malwareremoval.com/random/RSIT.exe

      random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

      Double-clique sur RSIT.exe afin de lancer RSIT.

      Clique Continue à l'écran Disclaimer.

      Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

      Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

      Poste le contenu de log.txt (<<qui sera affiché)
      ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

      NB : Les rapports sont sauvegardés dans le dossier C:\rsit
      0
      1. Ok je dois essayer de faire tout cela vite
        Merci
        0
        1. Désolée pour le retard mais mon PC était bloqué une autre fois avec les fenetres des pubs.
          Bon voilà les deux rapports:

          Log:

          Logfile of random's system information tool 1.04 (written by random/random)
          Run by Administrateur at 2004-12-15 14:43:36
          Microsoft Windows XP Professionnel Service Pack 2
          System drive C: has 26 GB (86%) free of 30 GB
          Total RAM: 191 MB (13% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 14:43:48, on 15/12/2004
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\explorer.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\sytem
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\VTTimer.exe
          C:\WINDOWS\system32\VTtrayp.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Menara\dslmon.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\KLAN01QR\RSIT[1].exe
          C:\Program Files\trend micro\Administrateur.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.co.ma/?gws_rd=ssl
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.menara.ma/
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Menara
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AdPopup - {11F09AFD-75AD-4E51-AB43-E09E9351CE16} - C:\Program Files\Fichiers communs\PushWare\cpush.dll
          O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O2 - BHO: Info cache - {285AB8C6-FB22-4D17-8834-064E2BA0A6F0} - C:\WINDOWS\Rose\pbhealth.dll
          O2 - BHO: ÍøÕ¾ÅÅÃû¹¤¾ßÌõBHO - {489873CE-F3E1-44A3-8E89-04BE26BE4446} - C:\Program Files\zzToolBar\Toolbar_bho.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
          O3 - Toolbar: ÍøÕ¾ÅÅÃû¹¤¾ßÌõ - {0A1230F1-EB52-4CA3-9D34-DE2ABC2EED35} - C:\Program Files\zzToolBar\ToolBand.dll
          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
          O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKLM\..\Policies\Explorer\Run: [internetnet] C:\WINDOWS\system32\spoolsv.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: DSLMON.lnk = C:\Program Files\Menara\dslmon.exe
          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
          O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{FFC76542-8B21-48E9-866C-1540009D0873}: NameServer = 62.251.229.243 212.217.0.3
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
          0
          1. Contributeur sécurité
            telecharge combofix:

            http://download.bleepingcomputer.com/sUBs/ComboFix.exe
            Sauvegarde le sur ton bureau et pas ailleurs !

            Ferme tous tes navigateurs (donc copie ou imprime les instructions avant)

            Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

            File::
            C:\WINDOWS\Rose\pbhealth.dll
            C:\Program Files\zzToolBar\ToolBand.dll
            C:\Program Files\zzToolBar
            C:\Program Files\zzToolBar\Toolbar_bho.dll
            C:\WINDOWS\Rose
            Registry::
            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{285AB8C6-FB22-4D17-8834-064E2BA0A6F0}]
            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{489873CE-F3E1-44A3-8E89-04BE26BE4446}]
            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
            {0A1230F1-EB52-4CA3-9D34-DE2ABC2EED35}-

            Enregistre ce fichier sous le nom CFscript

            Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe

            Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.

            Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

            Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

            Ne touche à rien tant que le scan n'est pas terminé.

            Une fois le scan achevé, un rapport va s'afficher: poste son contenu.

            Remets aussi un rapport RSIT

            Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
            0
            1. OK je dois le faire mais si je tard aussi c'est à cause de ce pc :S
              0
              1. désolée mais il ne veut pas enregistrer le ComboFix sur son nom ou je sais pas et il me donne un message d'erreur:
                vous nous pouvez pas renommer ComboFix en ComboFix [1]
                Veuillez choisir un autre nom de préference composé de caractères alphanumériques.
                et quans j'essaie de clické ok il ne me donne rien .. rien di tout
                0
                1. Contributeur sécurité
                  nomme le killfix
                  0
                  1. Contributeur sécurité
                    et pas ComboFix [1]
                    0
                    1. je clik pour le nommer un autre nom mais la fenetre d'erreur se ferme et j'attends kélk aparait mais rien di tout koi faire alors ??
                      est ce que spybot ou je sais pas bloque quelque chose dans ce programme ou même cette barre zztoolbar le bloque ??
                      0
                      1. Contributeur sécurité
                        télécharge OTMoveIt
                        http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.

                        double-clique sur OTMoveIt.exe pour le lancer.
                        copie la liste qui se trouve en citation ci-dessous,
                        et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
                        (attention bien mettre :files)

                        :files
                        C:\WINDOWS\Rose\pbhealth.dll
                        C:\Program Files\zzToolBar\ToolBand.dll
                        C:\Program Files\zzToolBar
                        C:\Program Files\zzToolBar\Toolbar_bho.dll
                        C:\WINDOWS\Rose
                        :reg
                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{285AB8C6-FB22-4D17-8834-064E2BA0A6F0}]
                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{489873CE-F3E1-44A3-8E89-04BE26BE4446}]
                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                        {0A1230F1-EB52-4CA3-9D34-DE2ABC2EED35}-
                        :commands
                        [purity]
                        [emptytemp]
                        [start explorer]

                        clique sur MoveIt! pour lancer la suppression.
                        le résultat apparaitra dans le cadre "Results".
                        clique sur Exit pour fermer.
                        poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                        il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                        puis remets un rapport RSIT
                        0
                        1. Bon voilà mnt ça marche désolée pour le derangement je dois essayer de faire ce vous m'avez indiqué avant .
                          Merciiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
                          0
                          1. Contributeur sécurité
                            non alors fais pas otmovit et colle le rapport combofix
                            0
                            1. Bon bon bon je sais que j'ai tardé mais vrmt je doute que ce programme à fait un scanne correcte !!! je sais pas moi car à la fin il a débuté le scanne une fois j'ai glisser le fichier de CFscript en tout cas voilà le rapport qu'il m'a donné à la fin (aussi je note qu'il a redemarré deux fois mais comme vous m'avez dit j'ai rien touché jusqu'à qu'il a affiché le rapport aussi une question est ce que vous voulez que je fasse un autre test sur http://images.malwareremoval.com/random/RSIT.exe pour avoir un nouveau rapport RSIT ??)
                              Bon voilà le rapport donner par ComboFix:

                              ComboFix 08-12-14.04 - Administrateur 2008-12-15 15:46:22.3 - NTFSx86
                              Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.191.59 [GMT 0:00]
                              Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
                              Commutateurs utilisés :: c:\documents and settings\Administrateur\Bureau\CFscript.txt
                              * Un nouveau point de restauration a été créé

                              FILE ::
                              c:\program files\zzToolBar
                              c:\program files\zzToolBar\ToolBand.dll
                              c:\program files\zzToolBar\Toolbar_bho.dll
                              c:\windows\Rose
                              c:\windows\Rose\pbhealth.dll
                              .

                              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              C:\AUTORUN.INF
                              c:\program files\zzToolBar
                              c:\program files\zzToolBar\IP.dat
                              c:\program files\zzToolBar\SearchEngineConfig
                              c:\program files\zzToolBar\ToolBand.dll
                              c:\program files\zzToolBar\Toolbar_bho.dll
                              c:\program files\zzToolBar\uISGRLFile.dat
                              c:\program files\zzToolBar\Uninstall.exe
                              C:\ZGZU.PIF
                              D:\Autorun.inf
                              D:\ZGZU.PIF
                              .
                              ---- Previous Run -------
                              .
                              C:\Autorun.inf
                              c:\documents and settings\2s.pif
                              c:\documents and settings\6s.pif
                              c:\documents and settings\9s.pif
                              c:\program files\ccdd.pif
                              c:\program files\Fichiers communs\PushWare
                              c:\program files\Fichiers communs\PushWare\cpush.dll
                              c:\program files\Internet Explorer\VitnNt64.987
                              c:\program files\Internet Explorer\VneNt64.Jmp
                              c:\program files\zzToolBar
                              c:\program files\zzToolBar\IP.dat
                              c:\program files\zzToolBar\SearchEngineConfig
                              c:\program files\zzToolBar\ToolBand.dll
                              c:\program files\zzToolBar\Toolbar_bho.dll
                              c:\program files\zzToolBar\uISGRLFile.dat
                              c:\program files\zzToolBar\Uninstall.exe
                              C:\ttmm.tep
                              c:\windows\Fonts\svchost.exe
                              c:\windows\KB611311.log
                              c:\windows\Rose
                              c:\windows\Rose\pbhealth.dll
                              c:\windows\system32\d3d1caps.srg
                              c:\windows\system32\drivers\acpidisk.sys
                              c:\windows\system32\drivers\Atieccx.sys
                              c:\windows\system32\drivers\npf.sys
                              c:\windows\system32\gprmsgse.axz
                              c:\windows\system32\gscpx32r.det
                              c:\windows\system32\mprmsgse.axz
                              c:\windows\system32\Packet.dll
                              c:\windows\system32\WanPacket.dll
                              c:\windows\system32\winlib .dll
                              c:\windows\system32\wpcap.dll
                              C:\ZGZU.PIF
                              D:\Autorun.inf
                              D:\ZGZU.PIF

                              .
                              ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              -------\Legacy_ACPIDISK
                              -------\Legacy_MYDOG
                              -------\Legacy_NPF
                              -------\Service_acpidisk
                              -------\Service_npf
                              -------\Legacy_ACPIDISK
                              -------\Legacy_MYDOG
                              -------\Legacy_NPF

                              ((((((((((((((((((((((((((((( Fichiers créés du 2004-11-15 au 2004-12-15 ))))))))))))))))))))))))))))))))))))
                              .

                              2008-12-15 05:04 . 2008-12-15 15:06 <REP> d-------- c:\documents and settings\All Users\Application Data\NOS
                              2008-12-14 23:51 . 2008-12-14 23:51 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
                              2008-12-14 23:51 . 2008-12-14 23:51 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
                              2008-12-14 23:32 . 2008-12-15 15:01 <REP> d-------- c:\documents and settings\Administrateur\Application Data\skypePM
                              2008-12-14 23:32 . 2008-12-15 15:01 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Skype
                              2008-12-14 23:32 . 2008-12-14 23:32 32 --a--c--- c:\documents and settings\All Users\Application Data\ezsid.dat
                              2008-12-14 23:30 . 2008-12-14 23:31 <REP> d-------- c:\documents and settings\All Users\Application Data\Skype
                              2004-12-15 02:09 . 2004-12-15 02:09 <REP> d-------- c:\documents and settings\Administrateur\Application Data\MxBoost
                              2004-12-15 01:26 . 2004-12-15 03:57 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

                              .
                              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              2008-12-15 15:06 --------- d-----w c:\program files\NOS
                              2008-12-15 13:33 --------- d-----w c:\program files\S3
                              2008-12-15 13:32 --------- d--h--w c:\program files\InstallShield Installation Information
                              2008-12-15 13:32 --------- d-----w c:\program files\Fichiers communs\InstallShield
                              2008-12-15 03:57 --------- d-----w c:\program files\Spybot - Search & Destroy
                              2008-12-15 03:06 --------- d-----w c:\program files\X-Cleaner
                              2008-12-14 23:51 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
                              2008-12-14 23:31 --------- d-----w c:\program files\Skype
                              2008-12-14 23:31 --------- d-----w c:\program files\Fichiers communs\Skype
                              2008-12-14 22:13 --------- d-----w c:\program files\Menara
                              2008-12-11 19:25 --------- d-----w c:\program files\Services en ligne
                              2008-12-03 19:52 38,496 -c--a-w c:\windows\system32\drivers\mbamswissarmy.sys
                              2008-12-03 19:52 15,504 -c--a-w c:\windows\system32\drivers\mbam.sys
                              2008-10-16 14:13 202,776 -c--a-w c:\windows\system32\wuweb.dll
                              2008-10-16 14:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
                              2008-10-16 14:12 561,688 -c--a-w c:\windows\system32\wuapi.dll
                              2008-10-16 14:12 323,608 -c--a-w c:\windows\system32\wucltui.dll
                              2008-10-16 14:09 92,696 -c--a-w c:\windows\system32\cdm.dll
                              2008-10-16 14:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
                              2008-10-16 14:09 43,544 ----a-w c:\windows\system32\wups2.dll
                              2008-10-16 14:08 34,328 -c--a-w c:\windows\system32\wups.dll
                              2008-08-28 22:40 --------- d-----w c:\documents and settings\LocalService.AUTORITE NT.001\Application Data\HP
                              2008-08-14 09:51 138,368 ----a-w c:\windows\system32\drivers\afd.sys
                              2008-07-25 11:52 --------- dcsh--w c:\program files\Fichiers communs\WindowsLiveInstaller
                              2008-07-10 00:57 --------- d-----w c:\program files\microsoft frontpage
                              2008-07-07 20:31 253,952 ----a-w c:\windows\system32\es.dll
                              2006-07-21 14:37 31 -c--a-w c:\windows\system32\drivers\adidsl.cfg
                              2006-05-17 12:31 217 -c--a-w c:\windows\system32\drivers\cmv4i.txt
                              2006-05-17 09:42 318 -c--a-w c:\windows\system32\drivers\cmv4p.txt
                              2006-05-11 22:51 152,308 -c--a-w c:\windows\system32\drivers\L1E4I2.BIN
                              2006-05-11 22:51 152,306 -c--a-w c:\windows\system32\drivers\L1E4I1.BIN
                              2006-05-11 22:51 152,306 -c--a-w c:\windows\system32\drivers\L1E4I0.BIN
                              2006-05-11 09:44 152,146 -c--a-w c:\windows\system32\drivers\L1E4P2.BIN
                              2006-05-11 09:44 152,145 -c--a-w c:\windows\system32\drivers\L1E4P1.BIN
                              2006-05-11 09:44 152,145 -c--a-w c:\windows\system32\drivers\L1E4P0.BIN
                              2006-05-04 17:20 114,616 -c--a-r c:\windows\system32\drivers\e4usbaw.sys
                              2006-05-04 17:20 114,616 ----a-w c:\windows\system32\e4usbaw.sys
                              2006-04-10 12:13 152,126 -c--a-w c:\windows\system32\drivers\L1E9I2.BIN
                              2006-04-10 12:13 152,126 -c--a-w c:\windows\system32\drivers\L1E9I1.BIN
                              2006-04-10 12:13 152,126 -c--a-w c:\windows\system32\drivers\L1E9I0.BIN
                              2006-04-10 12:10 152,126 -c--a-w c:\windows\system32\drivers\L1E9P2.BIN
                              2006-04-10 12:10 152,126 -c--a-w c:\windows\system32\drivers\L1E9P1.BIN
                              2006-04-10 12:10 152,126 -c--a-w c:\windows\system32\drivers\L1E9P0.BIN
                              2006-04-03 14:27 509 -c--a-w c:\windows\system32\drivers\CMV3p.txt
                              2006-04-03 14:27 486 -c--a-w c:\windows\system32\drivers\cmvep.txt
                              2006-03-02 17:55 63,555 -c--a-r c:\windows\system32\drivers\e4ldr.sys
                              2006-03-02 13:13 152,036 -c--a-w c:\windows\system32\drivers\L1E4D2.BIN
                              2006-03-02 13:13 152,034 -c--a-w c:\windows\system32\drivers\L1E4D1.BIN
                              2006-03-02 13:13 152,034 -c--a-w c:\windows\system32\drivers\L1E4D0.BIN
                              2006-02-16 06:14 143,360 ----a-w c:\windows\adiras.exe
                              2006-02-15 13:21 126,976 ----a-w c:\windows\system32\coclassfast.dll
                              2006-01-23 14:10 135,168 -c--a-w c:\windows\system32\unaddrv.exe
                              2005-12-27 03:08 1,875,968 ----a-r c:\windows\system32\vticd.dll
                              2005-12-27 03:06 3,490,432 ----a-r c:\windows\system32\vtdisp.dll
                              2005-12-27 03:06 247,040 -c--a-r c:\windows\system32\drivers\vtmini.sys
                              2005-12-01 16:27 128 -c--a-w c:\windows\system32\drivers\cmv4.txt
                              2005-11-28 20:05 446,464 ----a-r c:\windows\system32\VTGamma2.dll
                              2005-11-17 10:06 540,672 ----a-r c:\windows\system32\VTovrlay.dll
                              2005-11-01 02:35 28,672 ----a-r c:\windows\system32\VModes.exe
                              2005-10-31 21:58 319,488 ----a-r c:\windows\system32\VTInfo2.dll
                              2005-10-31 20:15 163,840 ----a-r c:\windows\system32\VTTrayp.exe
                              2005-10-17 14:48 42,496 -c--a-w c:\windows\system32\drivers\fetnd5bv.sys
                              2005-09-22 18:28 10,459,136 ------r c:\windows\system32\RTLCPL.exe
                              2005-09-22 16:42 90,112 ------r c:\windows\soundman.exe
                              2005-09-22 16:34 3,727,680 ------r c:\windows\system32\drivers\alcxwdm.sys
                              2005-09-19 11:58 126,489 ----a-w c:\windows\system32\adiusbaw.sys
                              2005-09-16 14:14 157,184 ------r c:\windows\system32\RtlCPAPI.dll
                              2005-09-09 16:39 212,992 ------r c:\windows\alcrmv.exe
                              2005-08-12 18:40 307,200 ------r c:\windows\alcupd.exe
                              2005-07-15 16:48 40,960 ------r c:\windows\system32\ChCfg.exe
                              2005-06-17 11:41 61,440 ----a-w c:\windows\system32\vuins32.dll
                              2005-05-23 18:36 581,632 ----a-r c:\windows\system32\VTDisply.dll
                              2005-04-26 20:30 5,824 -c--a-w c:\windows\system32\drivers\ASUSHWIO.SYS
                              2005-03-07 19:33 53,248 ----a-r c:\windows\system32\VTTimer.exe
                              2005-02-25 03:35 22,752 ----a-w c:\windows\system32\spupdsvc.exe
                              2004-12-15 14:43 --------- d-----w c:\program files\trend micro
                              2004-12-15 14:40 13,824 ----a-w c:\windows\system32\dbuzdtt.dll
                              2004-12-15 14:40 13,531 -c--a-w c:\windows\system32\wacudlt.exe
                              2004-12-15 14:38 126,976 -c--a-w c:\windows\system32\winlib1.dll
                              2004-12-15 13:43 126,976 ----a-w c:\windows\system32\winlib0.dll
                              2004-12-15 13:36 --------- d-----w c:\program files\Realtek Sound Manager
                              2004-12-15 13:36 --------- d-----w c:\program files\AvRack
                              2004-12-15 13:35 --------- d-----w c:\program files\Realtek AC97
                              2004-12-15 03:59 13,824 -c--a-w c:\windows\system32\dhnjanut.dll
                              2004-12-11 00:38 13,312 -csh--w c:\windows\system32\spoolsv.exe
                              .

                              ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              .
                              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                              REGEDIT4

                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
                              "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "VTTimer"="VTTimer.exe" [2005-03-07 c:\windows\system32\VTTimer.exe]
                              "VTTrayp"="VTtrayp.exe" [2005-10-31 c:\windows\system32\VTTrayp.exe]
                              "SoundMan"="SOUNDMAN.EXE" [2005-09-22 c:\windows\soundman.exe]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                              "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

                              c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                              DSLMON.lnk - c:\program files\Menara\dslmon.exe [2004-12-11 839680]

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                              "%windir%\\system32\\sessmgr.exe"=
                              "c:\\Program Files\\Skype\\Phone\\Skype.exe"=

                              R3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\DRIVERS\e4usbaw.sys [2008-12-14 114616]
                              S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\Drivers\e4ldr.sys [2008-12-14 63555]
                              .
                              - - - - ORPHELINS SUPPRIMES - - - -

                              BHO-{285AB8C6-FB22-4D17-8834-064E2BA0A6F0} - (no file)
                              BHO-{489873CE-F3E1-44A3-8E89-04BE26BE4446} - (no file)

                              .
                              ------- Examen supplémentaire -------
                              .
                              uStart Page = hxxp://www.google.co.ma/
                              uInternet Connection Wizard,ShellNext = hxxp://www.menara.ma/
                              uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
                              .

                              **************************************************************************

                              catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2004-12-15 15:48:46
                              Windows 5.1.2600 Service Pack 2 NTFS

                              Recherche de processus cachés ...

                              Recherche d'éléments en démarrage automatique cachés ...

                              Recherche de fichiers cachés ...

                              Scan terminé avec succès
                              Fichiers cachés: 0

                              **************************************************************************
                              .
                              ------------------------ Autres processus actifs ------------------------
                              .
                              c:\windows\system32\wscntfy.exe
                              .
                              **************************************************************************
                              .
                              Heure de fin: 2004-12-15 15:52:03 - La machine a redémarré [Administrateur]
                              ComboFix-quarantined-files.txt 2004-12-15 15:52:00

                              Avant-CF: 27,066,146,816 octets libres
                              Après-CF: 27,040,899,072 octets libres

                              227 --- E O F --- 2008-12-15 15:23:13
                              0
                              1. Contributeur sécurité
                                c'est quoi ton antivirus???

                                remets un rapport RSIT
                                0
                                1. Bon comme j'ai dit dans mon premier message j'ai pas mnt un antivirus !!! car tt simplement avec cette horloge de 2004 aucun antivirus ne veut s'installer w j'ai essayé de regler l'horloge et instalé mais une fois je redemarre il se bloque !!!
                                  Alors voilà le rapport Log :
                                  Logfile of random's system information tool 1.04 (written by random/random)
                                  Run by Administrateur at 2004-12-15 16:06:13
                                  Microsoft Windows XP Professionnel Service Pack 2
                                  System drive C: has 26 GB (86%) free of 30 GB
                                  Total RAM: 191 MB (29% free)

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 16:06:23, on 15/12/2004
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\VTTimer.exe
                                  C:\WINDOWS\system32\VTtrayp.exe
                                  C:\WINDOWS\SOUNDMAN.EXE
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  C:\Program Files\Menara\dslmon.exe
                                  C:\WINDOWS\system32\wscntfy.exe
                                  C:\WINDOWS\explorer.exe
                                  C:\WINDOWS\system32\NOTEPAD.EXE
                                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                  C:\WINDOWS\system32\NOTEPAD.EXE
                                  C:\Program Files\Skype\Phone\Skype.exe
                                  C:\Program Files\Skype\Plugin Manager\skypePM.exe
                                  C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\2HKHCP4B\RSIT[1].exe
                                  C:\Program Files\trend micro\Administrateur.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.co.ma/?gws_rd=ssl
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.menara.ma/
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                                  O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
                                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                  O4 - Global Startup: DSLMON.lnk = C:\Program Files\Menara\dslmon.exe
                                  O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                                  O17 - HKLM\System\CCS\Services\Tcpip\..\{FFC76542-8B21-48E9-866C-1540009D0873}: NameServer = 62.251.229.243 212.217.0.3
                                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                                  0
                                  1. Après une heure de téléchargement des mise à jours de kaspersky en ligne il m'as dit à la fin k j'ai peut etre un antivirus activé !!!!!!!!!!!!!!!!mais moi j'ai pas ditout alors koi faire ??
                                    0
                                    1. Désolée pour le retard :( bon Voilà j'ai fait un scan avec http://pandasoftware.fr et voilà son rapport

                                      ;***********************************************************************************************************************************************************************************
                                      ANALYSIS: 2008-12-15 18:12:33
                                      PROTECTIONS: 0
                                      MALWARE: 13
                                      SUSPECTS: 3
                                      ;***********************************************************************************************************************************************************************************
                                      PROTECTIONS
                                      Description Version Active Updated
                                      ;===================================================================================================================================================================================
                                      ;===================================================================================================================================================================================
                                      MALWARE
                                      Id Description Type Active Severity Disinfectable Disinfected Location
                                      ;===================================================================================================================================================================================
                                      00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\Administrateur\Cookies\administrateur@xiti[1].txt
                                      00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\Administrateur\Cookies\administrateur@smartadserver[1].txt
                                      00474628 Trj/Lineage.KGX Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP10\A0001734.exe
                                      00474628 Trj/Lineage.KGX Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP3\A0000958.exe
                                      00474655 Adware/ZzToolbar Adware No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP11\A0001789.pif
                                      00474655 Adware/ZzToolbar Adware No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP8\A0001630.pif
                                      00474655 Adware/ZzToolbar Adware No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP10\A0001744.pif
                                      00474655 Adware/ZzToolbar Adware No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP12\A0003301.pif
                                      00474655 Adware/ZzToolbar Adware No 0 Yes No C:\Documents and Settings\10s.pif
                                      00474655 Adware/ZzToolbar Adware No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP2\A0000153.pif
                                      00474655 Adware/ZzToolbar Adware No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001340.pif
                                      00474655 Adware/ZzToolbar Adware No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001278.pif
                                      00474655 Adware/ZzToolbar Adware No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP4\A0001074.pif
                                      00520762 Trj/Downloader.NTB Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP15\A0003782.exe
                                      00520762 Trj/Downloader.NTB Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\C\WINDOWS\Fonts\svchost.exe.vir
                                      00520762 Trj/Downloader.NTB Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP12\A0003224.exe
                                      01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP17\A0005361.EXE
                                      01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP17\A0005322.EXE
                                      02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP17\A0005330.sys
                                      02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP16\A0005304.sys
                                      03625274 Adware/Cinmus Adware No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP7\A0001442.exe
                                      03625274 Adware/Cinmus Adware No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP4\A0000975.exe
                                      03625274 Adware/Cinmus Adware No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP8\A0001643.exe
                                      03625274 Adware/Cinmus Adware No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP11\A0001802.exe
                                      03625274 Adware/Cinmus Adware No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP2\A0000773.exe
                                      03636351 Bck/NetSniff.L Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP8\A0001637.exe
                                      03636351 Bck/NetSniff.L Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP11\A0001795.exe
                                      03636351 Bck/NetSniff.L Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP10\A0001749.exe
                                      03636351 Bck/NetSniff.L Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP12\A0003304.exe
                                      03636351 Bck/NetSniff.L Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001346.exe
                                      03636351 Bck/NetSniff.L Virus/Trojan No 1 Yes No C:\WINDOWS\system32\wacudlt.exe
                                      03636351 Bck/NetSniff.L Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP3\A0000966.exe
                                      03636351 Bck/NetSniff.L Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001163.exe
                                      04084349 Rootikit/Lineage.KGY HackTools No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP3\A0000960.sys
                                      04084349 Rootikit/Lineage.KGY HackTools No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001165.sys
                                      04084349 Rootikit/Lineage.KGY HackTools No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP15\A0003786.sys
                                      04084349 Rootikit/Lineage.KGY HackTools No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP8\A0001633.sys
                                      04084349 Rootikit/Lineage.KGY HackTools No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP11\A0001797.sys
                                      04084349 Rootikit/Lineage.KGY HackTools No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP10\A0001742.sys
                                      04084349 Rootikit/Lineage.KGY HackTools No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP12\A0003297.sys
                                      04084349 Rootikit/Lineage.KGY HackTools No 1 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001348.sys
                                      04084349 Rootikit/Lineage.KGY HackTools No 1 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\Atieccx.sys.vir
                                      04315544 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP11\A0001801.dll
                                      04315544 Generic Malware Virus/Trojan No 0 No No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001338.pif[cpush.tmp]
                                      04315544 Generic Malware Virus/Trojan No 0 No No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP12\A0003295.pif[cpush.tmp]
                                      04315544 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP15\A0003778.dll
                                      04315544 Generic Malware Virus/Trojan No 0 No No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP8\A0001627.pif[cpush.tmp]
                                      04315544 Generic Malware Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\C\Program Files\Fichiers communs\PushWare\cpush.dll.vir
                                      04315544 Generic Malware Virus/Trojan No 0 No No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP15\A0003790.pif[cpush.tmp]
                                      04315544 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP8\A0001642.dll
                                      04315544 Generic Malware Virus/Trojan No 0 No No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP4\A0001072.pif[cpush.tmp]
                                      04315544 Generic Malware Virus/Trojan No 0 No No C:\Qoobox\Quarantine\C\Documents and Settings\6s.pif.vir[cpush.tmp]
                                      04315544 Generic Malware Virus/Trojan No 0 No No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP11\A0001786.pif[cpush.tmp]
                                      04315544 Generic Malware Virus/Trojan No 0 No No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP2\A0000152.pif[cpush.tmp]
                                      04315544 Generic Malware Virus/Trojan No 0 No No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP10\A0001737.pif[cpush.tmp]
                                      04315544 Generic Malware Virus/Trojan No 0 No No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001276.pif[cpush.tmp]
                                      04330459 Trj/QQPass.QV Virus/Trojan No 1 Yes No C:\Qoobox\Quarantine\C\Program Files\Internet Explorer\VitnNt64.987.vir
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP11\A0001756.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP17\A0005310.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP11\A0001760.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\WINDOWS\system32\spoolsv.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP10\A0001730.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP3\A0000948.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP3\A0000950.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP3\A0000954.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\D\_ZGZU_.PIF.zip[ZGZU.PIF.1]
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP16\A0004279.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\D\_ZGZU_.PIF.zip[ZGZU.PIF]
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP4\A0000969.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\D\av2.zip[Qoobox/Quarantine/D/ZGZU.PIF.vir]
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP15\A0004238.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\D\av2.zip[Qoobox/ZGZU.PIF]
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001112.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001150.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001155.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\C\_ZGZU_.PIF.zip[ZGZU.PIF.1]
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP15\A0004233.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001272.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP15\A0003772.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\C\_ZGZU_.PIF.zip[ZGZU.PIF]
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001329.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001330.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001335.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP14\A0003667.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\C\ZGZU.PIF.vir
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP13\A0003605.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP11\A0002820.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP6\A0001351.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP7\A0001357.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\C\ttmm.tep.vir
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP8\A0001460.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP8\A0001610.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP8\A0001618.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP8\A0001624.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP12\A0003290.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP17\A0005329.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP12\A0003284.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP12\A0003283.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP11\A0002825.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP12\A0002834.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP9\A0001726.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\sytem
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\WINDOWS\system32\dllcache\spoolsv.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP16\A0005233.exe
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP10\A0001732.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP11\A0001759.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP12\A0002837.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP12\A0003292.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP13\A0003607.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP14\A0003669.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP15\A0003774.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP15\A0004240.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP16\A0004281.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP17\A0005312.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP17\A0005336.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP5\A0001337.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP6\A0001353.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP7\A0001359.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP8\A0001462.PIF
                                      04333699 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{82F8F095-6B9C-49E6-BEFD-65472BB1E223}\RP8\A0001626.PIF
                                      ;===================================================================================================================================================================================
                                      SUSPECTS
                                      Sent Location
                                      ;===================================================================================================================================================================================
                                      No C:\Qoobox\Quarantine\C\Documents and Settings\2s.pif.vir[²ÖÇ\168.exe][²èÇ]
                                      No C:\Qoobox\Quarantine\C\Documents and Settings\9s.pif.vir
                                      No C:\Qoobox\Quarantine\C\WINDOWS\Rose\pbhealth.dll.vir
                                      ;===================================================================================================================================================================================
                                      VULNERABILITIES
                                      Id Severity Description
                                      ;===================================================================================================================================================================================
                                      184380 MEDIUM MS08-002
                                      184379 MEDIUM MS08-001
                                      182048 HIGH MS07-069
                                      182046 HIGH MS07-067
                                      182043 HIGH MS07-064
                                      179553 HIGH MS07-061
                                      176382 HIGH MS07-057
                                      176383 HIGH MS07-058
                                      170911 HIGH MS07-050
                                      170907 HIGH MS07-046
                                      170906 HIGH MS07-045
                                      170904 HIGH MS07-043
                                      164915 HIGH MS07-035
                                      164913 HIGH MS07-033
                                      164911 HIGH MS07-031
                                      160623 HIGH MS07-027
                                      157262 HIGH MS07-022
                                      157261 HIGH MS07-021
                                      157260 HIGH MS07-020
                                      157259 HIGH MS07-019
                                      156477 HIGH MS07-017
                                      150253 HIGH MS07-016
                                      150249 HIGH MS07-013
                                      150248 HIGH MS07-012
                                      150247 HIGH MS07-011
                                      150243 HIGH MS07-008
                                      150242 HIGH MS07-007
                                      150241 MEDIUM MS07-006
                                      141034 HIGH MS06-076
                                      141033 MEDIUM MS06-075
                                      141030 HIGH MS06-072
                                      137571 HIGH MS06-070
                                      137568 HIGH MS06-067
                                      133387 MEDIUM MS06-065
                                      133386 MEDIUM MS06-064
                                      133385 MEDIUM MS06-063
                                      133379 HIGH MS06-057
                                      131654 HIGH MS06-055
                                      129977 MEDIUM MS06-053
                                      129976 MEDIUM MS06-052
                                      126093 HIGH MS06-051
                                      126092 MEDIUM MS06-050
                                      126087 HIGH MS06-046
                                      126086 MEDIUM MS06-045
                                      126083 HIGH MS06-042
                                      126082 HIGH MS06-041
                                      126081 HIGH MS06-040
                                      123421 HIGH MS06-036
                                      123420 HIGH MS06-035
                                      120825 MEDIUM MS06-032
                                      120823 MEDIUM MS06-030
                                      120818 HIGH MS06-025
                                      120815 HIGH MS06-022
                                      120814 HIGH MS06-021
                                      117384 MEDIUM MS06-018
                                      114666 HIGH MS06-015
                                      114664 HIGH MS06-013
                                      108744 MEDIUM MS06-008
                                      108743 MEDIUM MS06-007
                                      108742 MEDIUM MS06-006
                                      104567 HIGH MS06-002
                                      104237 HIGH MS06-001
                                      96574 HIGH MS05-053
                                      93395 HIGH MS05-051
                                      93394 HIGH MS05-050
                                      93454 MEDIUM MS05-049
                                      Bon je dois essayer de télécharger antivir une autre fis même que j'ai essayé avec lui aussi hier mais il ne marche pas mais bon j'essai une autre fois.
                                      Merci
                                      0
                                      • 1
                                      • 2