Scan hijackthis, s'il vous plait aidez moi

Bonjours a tous, voila quelque tems que j'ai une multide de problemes sur mon ordinateur (redemarrage intempestif, déconection, ralentissement, messages d'erreur, trojan,ect...ect..) Bref un fonctionnement difficile de l'ordinateur. j'ai deja connu ce genre de problemes et c'est justement sur ce forum que j'avais exposé mon problemes et a l'aide s'un scan de hijackthis une personne m'avais généreusement aidé a resoudre ce probleme, j'espere que toujours a l'aide de ce scan qui pour moi est incomprehensible quelqu'un pourra m'aidé, je vous remercie d'avance, n'hesitez pas a me posé des questions.

Logfile of HijackThis v1.99.1
Scan saved at 21:09:43, on 24/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\syscntrl.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UAService7.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\apps\ABoard\ABoard.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\splsijn32.exe
C:\WINDOWS\System32\scchost.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\JVTorrent\btdownloadgui.exe
C:\Program Files\L'Entraîneur 5\CM5.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\System32\vturo.dll
O2 - BHO: ATLDistrib Object - {659E147E-BD03-4605-988C-AA6D7EA497CA} - C:\WINDOWS\System32\geeda.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Network Host Service] splsijn32.exe
O4 - HKLM\..\Run: [Alive SYstem] C:\WINDOWS\System32\scchost.exe
O4 - HKLM\..\RunServices: [Network Host Service] splsijn32.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128881205359
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c11.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\System32\btxppanel.dll
O20 - Winlogon Notify: geeda - C:\WINDOWS\System32\geeda.dll
O20 - Winlogon Notify: vturo - C:\WINDOWS\SYSTEM32\vturo.dll
O23 - Service: AOL Instant Messanger (AIM) - Unknown owner - C:\WINDOWS\aim.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Network Harware Detection (NetDDTC) (NetDDTC) - Unknown owner - C:\WINDOWS\system32\syscntrl.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Configuration: PC p4 2.4 ghz
256 mo ram 
Windows xp

33 réponses

Résumé de la discussion

Plusieurs dysfonctionnements informatiques, tels que redémarrages intempestifs, déconnexions et ralentissements, accompagnent un log HijackThis et des alertes antivirus signalant des éléments potentiellement malveillants et nécessitant une évaluation approfondie. La meilleure réponse identifie des éléments de démarrage et des extensions de registre potentiellement malveillants, notamment des composants Avast, Zone Alarm et diverses entrées Run, Active Desktop et shells contextuels. D'autres contributeurs évoquent des détections de trojans et la nécessité d'un scan croisé avec plusieurs antivirus, précisant que les résultats varient et que les restaurations système peuvent contenir des éléments suspects. En cas de doute, il est conseillé de nettoyer les éléments de démarrage, supprimer les extensions non fiables et vérifier les rapports antivirus pour confirmer les menaces.

Bobot (l’IA à votre service)
  1. Contributeur
    Bonsoir Cedric,

    tu peux commencer par ça :

    ¤Télécharge ces logiciels:

    1/Spybot S&D 1.4 <<nouvelle version
    http://www.safer-networking.org/fr/index.html

    Démo d utilisation (merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

    Le mettre à jour.

    2/Ad-Aware SE 1.06 <<nouvelle version
    http://www.lavasoftusa.com/software/adaware/
    -Une aide:
    http://www.tutopat.com/viewtopic.php?t=1191
    - installe le patch français, tu pourra le trouver ici:
    http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
    et une petite vidéo ici d'utilisation:(merci a Moe31 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/adawrevid.asf

    Le mettre à jour.

    3/Clean Up 40:
    http://pageperso.aol.fr/balltrap34/CleanUp40.exe
    -aide en image:(merci a Balltrap34)
    http://pageperso.aol.fr/balltrap34/democleanup.htm

    passes un coup de chaque et dis nous où en sont tes soucis.

    Bon courage.

    a+
    0
    1. Merci beaucoup ! j'ai tout passé mais j'ai toujours des gros problèmes comme le remarrage, les blockages, les messages de trojan pour j'ai en firewall zone alarm et en anti-virus avast mais est-ce le scan est positif ?
      0
      1. salut,
        normal
        remet un hijack this

        a+
        0
        1. Apparement ca a l'air de se calmer lol mais pour etre sur je t'envoie comme tu me l'avais demandé ce scan on ne sais jamais :
          0
          1. oups j'ai oublié ca lol :

            Logfile of HijackThis v1.99.1
            Scan saved at 23:53:11, on 24/11/2005
            Platform: Windows XP SP1 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
            C:\WINDOWS\system32\syscntrl.exe
            C:\WINDOWS\system32\slserv.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\UAService7.exe
            C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\WINDOWS\Explorer.EXE
            C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\apps\ABoard\ABoard.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
            C:\apps\ABoard\AOSD.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\WINDOWS\System32\splsijn32.exe
            C:\WINDOWS\System32\scchost.exe
            C:\Program Files\MSN Messenger\MsnMsgr.Exe
            C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
            C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
            C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\hijackthis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.fr/
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\System32\vturo.dll (file missing)
            O2 - BHO: ATLDistrib Object - {659E147E-BD03-4605-988C-AA6D7EA497CA} - C:\WINDOWS\System32\geeda.dll
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
            O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
            O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
            O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [Network Host Service] splsijn32.exe
            O4 - HKLM\..\Run: [Alive SYstem] C:\WINDOWS\System32\scchost.exe
            O4 - HKLM\..\RunServices: [Network Host Service] splsijn32.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - Global Startup: BTTray.lnk = ?
            O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
            O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
            O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128881205359
            O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
            O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c11.cab
            O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
            O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
            O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
            O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
            O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\System32\btxppanel.dll
            O20 - Winlogon Notify: geeda - C:\WINDOWS\System32\geeda.dll
            O20 - Winlogon Notify: vturo - vturo.dll (file missing)
            O23 - Service: AOL Instant Messanger (AIM) - Unknown owner - C:\WINDOWS\aim.exe (file missing)
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
            O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
            O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
            O23 - Service: Network Harware Detection (NetDDTC) (NetDDTC) - Unknown owner - C:\WINDOWS\system32\syscntrl.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
            O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
            O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe
            O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            0
            1. Salut,

              Imprime, ou enregistre ceci dans le bloc note pour ne rien oublier.

              1/

              télécharge : process xp ici:
              http://www.sysinternals.com/files/procexpnt.zip

              Télécharge: Pocket Killbox ici
              http://www.downloads.subratam.org/KillBox.exe

              :: Démo d utilisation (merci a Balltrap34 pour cette réalisation) ::
              http://pageperso.aol.fr/balltrap34/killbox.htm

              2/

              Déconnecte toi du net.
              Ferme tous les programmes en cours (média player, internet explorer, ...etc)

              Dézippe (clic droit > extraire) process xp et double clic sur processxp.exe

              * Dans la fenêtre principale de processxp double clic sur winlogon.exe
              Dans la nouvelle fenêtre qui s'ouvre clique sur threads
              sélectionne seulement les lignes qui contiennent vturo.dll puis clique sur kill pour chacune des lignes trouvées.
              une fois fait, valide avec ok

              * Dans la fenêtre principale de processxp double clic sur explorer.exe
              Dans la nouvelle fenêtre qui s'ouvre clique sur threads
              sélectionner seulement les lignes qui contiennent vturo.dll puis clique sur kill pour chacune des lignes trouvées.
              une fois fait, valide avec ok
              ----------------------------------------------------------------------------
              * Dans la fenêtre principale de processxp double clic sur winlogon.exe
              Dans la nouvelle fenêtre qui s'ouvre clique sur threads
              sélectionne seulement les lignes qui contiennent geeda.dll puis clique sur kill pour chacune des lignes trouvées.
              une fois fait, valide avec ok

              * Dans la fenêtre principale de processxp double clic sur explorer.exe
              Dans la nouvelle fenêtre qui s'ouvre clique sur threads
              sélectionner seulement les lignes qui contiennent geeda.dll puis clique sur kill pour chacune des lignes trouvées.
              une fois fait, valide avec ok

              3/

              puis lancer HijackThis:

              clique sur "do a system scan only"

              * Cocher la case au début de ces lignes:

              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm

              O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\System32\vturo.dll (file missing)

              O2 - BHO: ATLDistrib Object - {659E147E-BD03-4605-988C-AA6D7EA497CA} - C:\WINDOWS\System32\geeda.dll

              O4 - HKLM\..\Run: [Network Host Service] splsijn32.exe

              O4 - HKLM\..\Run: [Alive SYstem] C:\WINDOWS\System32\scchost.exe

              O4 - HKLM\..\RunServices: [Network Host Service] splsijn32.exe

              O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm

              O20 - Winlogon Notify: geeda - C:\WINDOWS\System32\geeda.dll

              O20 - Winlogon Notify: geeda - C:\WINDOWS\System32\geeda.dll

              O20 - Winlogon Notify: vturo - vturo.dll (file missing)

              * Valider avec fix checked

              5/

              Double clic sur killbox.exe (Pocket Killbox)

              Avec la methode du bloc note (cf video)

              Liste:

              C:\WINDOWS\System32\vturo.dll
              C:\WINDOWS\System32\splsijn32.exe
              C:\WINDOWS\System32\scchost.exe
              C:\WINDOWS\System32\geeda.dll

              Laisse le pc redémarrer.
              Et après reposte un log HijackThis.

              A+
              0
              1. Merci beaucoup pour ton aide j'ai fais tout ce que tu m'as dit mais il y a un fichier que j'arrive pas a detruire avec la kill box c'est celui la : C:\WINDOWS\System32\scchost.exe ca fait que j'ai encore plein de message d'erreur, je te montre quand meme le log :

                Logfile of HijackThis v1.99.1
                Scan saved at 14:09:30, on 25/11/2005
                Platform: Windows XP SP1 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                C:\WINDOWS\system32\syscntrl.exe
                C:\WINDOWS\system32\slserv.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\UAService7.exe
                C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\WINDOWS\Explorer.EXE
                C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                C:\apps\ABoard\ABoard.exe
                C:\apps\ABoard\AOSD.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                C:\Program Files\QuickTime\qttask.exe
                C:\WINDOWS\System32\scchost.exe
                C:\Program Files\MSN Messenger\MsnMsgr.Exe
                C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
                C:\WINDOWS\System32\wuauclt.exe
                C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
                C:\hijackthis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.fr/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
                O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [Alive SYstem] C:\WINDOWS\System32\scchost.exe
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                O4 - Global Startup: BTTray.lnk = ?
                O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
                O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128881205359
                O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c11.cab
                O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
                O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
                O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\System32\btxppanel.dll
                O23 - Service: AOL Instant Messanger (AIM) - Unknown owner - C:\WINDOWS\aim.exe (file missing)
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                O23 - Service: Network Harware Detection (NetDDTC) (NetDDTC) - Unknown owner - C:\WINDOWS\system32\syscntrl.exe
                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe
                O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                0
                1. salut

                  fixe ceci
                  O4 - HKLM\..\Run: [Alive SYstem] C:\WINDOWS\System32\scchost.exe

                  ¤Démarre en mode sans échec :
                  Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                  Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                  Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                  (Si F8 ne marche pas utilise la touche F5).

                  supprime
                  C:\WINDOWS\System32\scchost.exe

                  vide ta poubelle

                  redemarre et remet un log

                  a+
                  0
                  1. Merci apparement ca a l'air d'aller enfin j'espere lol merci pour ces réponses si rapides ! je te remet le dernier log j'espere ! :

                    Logfile of HijackThis v1.99.1
                    Scan saved at 14:48:36, on 25/11/2005
                    Platform: Windows XP SP1 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                    C:\WINDOWS\system32\syscntrl.exe
                    C:\WINDOWS\system32\slserv.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\System32\UAService7.exe
                    C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\System32\wuauclt.exe
                    C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    C:\apps\ABoard\ABoard.exe
                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    C:\apps\ABoard\AOSD.exe
                    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\Program Files\MSN Messenger\MsnMsgr.Exe
                    C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
                    C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
                    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\hijackthis\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.fr/
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                    O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                    O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
                    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                    O4 - Global Startup: BTTray.lnk = ?
                    O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
                    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128881205359
                    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                    O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c11.cab
                    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                    O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
                    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
                    O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                    O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\System32\btxppanel.dll
                    O23 - Service: AOL Instant Messanger (AIM) - Unknown owner - C:\WINDOWS\aim.exe (file missing)
                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                    O23 - Service: Network Harware Detection (NetDDTC) (NetDDTC) - Unknown owner - C:\WINDOWS\system32\syscntrl.exe
                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                    O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe
                    O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                    0
                    1. Désolé mais ton liens ne marche pas et ce fichier C:\WINDOWS\System32\scchost.exe ne veut pas se supprimer mon ant-virus ne peut pas le supprimer c'est un trojan je sais pas trop quoi...
                      0
                      1. salut
                        redemarre ton pc et remet un hijack this

                        a+
                        0
                        1. Rien a Faire j'ai beau suprimer ce fichier il reviens toujours...

                          Logfile of HijackThis v1.99.1
                          Scan saved at 18:27:33, on 25/11/2005
                          Platform: Windows XP SP1 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                          C:\apps\ABoard\ABoard.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\apps\ABoard\AOSD.exe
                          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                          C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                          C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          C:\WINDOWS\system32\syscntrl.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\Program Files\QuickTime\qttask.exe
                          C:\WINDOWS\System32\scchost.exe
                          C:\Program Files\MSN Messenger\MsnMsgr.Exe
                          C:\WINDOWS\system32\slserv.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\UAService7.exe
                          C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                          C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
                          C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
                          C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\WINDOWS\System32\wuauclt.exe
                          C:\hijackthis\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.fr/
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                          O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                          O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                          O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                          O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
                          O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [Alive SYstem] C:\WINDOWS\System32\scchost.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                          O4 - Global Startup: BTTray.lnk = ?
                          O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
                          O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                          O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                          O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128881205359
                          O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                          O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c11.cab
                          O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                          O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
                          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
                          O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
                          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                          O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\System32\btxppanel.dll
                          O23 - Service: AOL Instant Messanger (AIM) - Unknown owner - C:\WINDOWS\aim.exe (file missing)
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                          O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                          O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                          O23 - Service: Network Harware Detection (NetDDTC) (NetDDTC) - Unknown owner - C:\WINDOWS\system32\syscntrl.exe
                          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                          O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                          O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe
                          O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          0
                          1. "Silent Runners.vbs", revision 41, http://www.silentrunners.org/
                            Operating System: Windows XP
                            Output limited to non-default values, except where indicated by "{++}"

                            Startup items buried in registry:
                            ---------------------------------

                            HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                            "MsnMsgr" = ""C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background" [MS]

                            HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                            "ATIModeChange" = "Ati2mdxx.exe" ["ATI Technologies, Inc."]
                            "ATIPTA" = "C:\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]
                            "ACTIVBOARD" = "c:\apps\ABoard\ABoard.exe" ["NEC Computers International"]
                            "avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data]
                            "Zone Labs Client" = "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" ["Zone Labs, LLC"]
                            "HP Component Manager" = ""C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"" ["Hewlett-Packard Company"]
                            "HP Software Update" = "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Co."]
                            "CTRegRun" = "C:\WINDOWS\CTRegRun.EXE" ["Creative Technology Ltd "]
                            "NeroCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
                            "TkBellExe" = ""C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
                            "QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
                            "Alive SYstem" = "C:\WINDOWS\System32\scchost.exe" [null data]

                            HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
                            "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
                            -> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
                            "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
                            -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
                            "{D3581EB7-5E16-4182-9F58-86FA713B42F9}" = "AOL Partenaire de Packard Bell"
                            -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Fichiers communs\aolshare\shell\fr\shellext.dll" ["America Online, Inc."]
                            "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
                            -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshellext.dll" ["RealNetworks"]
                            "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
                            -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
                            "{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
                            -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
                            "{AB77609F-2178-4E6F-9C4B-44AC179D937A}" = "a² Context Menu Shell Extension"
                            -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\A2FREE~1\A2CONT~1.DLL" [null data]
                            "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
                            -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
                            "{6af09ec9-b429-11d4-a1fb-0090960218cb}" = "My Bluetooth Places"
                            -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\btneighborhood.dll" ["Broadcom Corporation"]
                            "{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
                            -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
                            "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
                            -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]

                            HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
                            avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
                            -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
                            WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                            -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

                            HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
                            WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                            -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

                            HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
                            a2ContMenu\(Default) = "{AB77609F-2178-4E6F-9C4B-44AC179D937A}"
                            -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\A2FREE~1\A2CONT~1.DLL" [null data]
                            avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
                            -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
                            WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                            -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

                            Active Desktop and Wallpaper:
                            -----------------------------

                            Active Desktop is disabled at this entry:
                            HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
                            0
                            1. salut
                              atends qq minutes avant de recuperer le rapport, il est pas en entier sinon

                              bon appetit
                              0
                              1. Oups désolé lol

                                "Silent Runners.vbs", revision 41, http://www.silentrunners.org/
                                Operating System: Windows XP
                                Output limited to non-default values, except where indicated by "{++}"

                                Startup items buried in registry:
                                ---------------------------------

                                HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                                "MsnMsgr" = ""C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background" [MS]

                                HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                                "ATIModeChange" = "Ati2mdxx.exe" ["ATI Technologies, Inc."]
                                "ATIPTA" = "C:\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]
                                "ACTIVBOARD" = "c:\apps\ABoard\ABoard.exe" ["NEC Computers International"]
                                "avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data]
                                "Zone Labs Client" = "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" ["Zone Labs, LLC"]
                                "HP Component Manager" = ""C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"" ["Hewlett-Packard Company"]
                                "HP Software Update" = "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Co."]
                                "CTRegRun" = "C:\WINDOWS\CTRegRun.EXE" ["Creative Technology Ltd "]
                                "NeroCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
                                "TkBellExe" = ""C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
                                "QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
                                "Alive SYstem" = "C:\WINDOWS\System32\scchost.exe" [null data]

                                HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
                                "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
                                -> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
                                "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
                                -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
                                "{D3581EB7-5E16-4182-9F58-86FA713B42F9}" = "AOL Partenaire de Packard Bell"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Fichiers communs\aolshare\shell\fr\shellext.dll" ["America Online, Inc."]
                                "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshellext.dll" ["RealNetworks"]
                                "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
                                "{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
                                "{AB77609F-2178-4E6F-9C4B-44AC179D937A}" = "a² Context Menu Shell Extension"
                                -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\A2FREE~1\A2CONT~1.DLL" [null data]
                                "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
                                "{6af09ec9-b429-11d4-a1fb-0090960218cb}" = "My Bluetooth Places"
                                -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\btneighborhood.dll" ["Broadcom Corporation"]
                                "{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
                                -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
                                "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
                                -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]

                                HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
                                avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
                                WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

                                HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
                                WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

                                HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
                                a2ContMenu\(Default) = "{AB77609F-2178-4E6F-9C4B-44AC179D937A}"
                                -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\A2FREE~1\A2CONT~1.DLL" [null data]
                                avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
                                WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

                                Active Desktop and Wallpaper:
                                -----------------------------

                                Active Desktop is disabled at this entry:
                                HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

                                HKCU\Control Panel\Desktop\
                                "Wallpaper" = "C:\WINDOWS\DESK.BMP"

                                Startup items in "Cédric" & "All Users" startup folders:
                                --------------------------------------------------------

                                C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
                                "BTTray" -> shortcut to: "C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe" ["Broadcom Corporation"]
                                "Démarrage rapide du logiciel HP Image Zone" -> shortcut to: "C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe -s" [null data]
                                "HP Digital Imaging Monitor" -> shortcut to: "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" ["Hewlett-Packard Co."]

                                Winsock2 Service Provider DLLs:
                                -------------------------------

                                Namespace Service Providers

                                HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
                                000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
                                000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
                                000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

                                Transport Service Providers

                                HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
                                0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
                                %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17
                                %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

                                Toolbars, Explorer Bars, Extensions:
                                ------------------------------------

                                Toolbars

                                HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
                                "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "Yahoo! Toolbar" [from CLSID]
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]

                                HKLM\Software\Microsoft\Internet Explorer\Toolbar\
                                "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "Yahoo! Toolbar" [from CLSID]
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]

                                Explorer Bars

                                HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
                                {FE54FA40-D68C-11D2-98FA-00C0F0318AFE}\ = "Real.com" [from CLSID]
                                -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Shdocvw.dll" [MS]

                                Extensions (Tools menu items, main toolbar menu buttons)

                                HKLM\Software\Microsoft\Internet Explorer\Extensions\
                                {CCA281CA-C863-46EF-9331-5C8D4460577F}\
                                "ButtonText" = "@btrez.dll,-4015"
                                "MenuText" = "@btrez.dll,-4017"
                                "Script" = "C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm" [null data]

                                {CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\
                                "ButtonText" = "Real.com"

                                Miscellaneous IE Hijack Points
                                ------------------------------

                                C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

                                Added lines (compared with English-language version):
                                (unwritable string)

                                Missing lines (compared with English-language version):
                                [Version]: 2 lines
                                [RestoreHomePage]: 1 line
                                [RestoreHomePage.reg]: 1 line
                                [RestoreBrowserSettings.reg]: 12 lines
                                [DeleteTemplates.reg]: 5 lines
                                [DeleteAutosearch.reg]: 1 line
                                [Strings]: 1 line
                                [RestoreBrowserSettings]: 2 lines
                                [Strings]: 3 lines

                                HOSTS file
                                ----------

                                HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\
                                HIJACK WARNING! "DataBasePath" = "%SystemRoot%\System32\drivers\etc"

                                Running Services (Display Name, Service Name, Path {Service DLL}):
                                ------------------------------------------------------------------

                                avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" [null data]
                                avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" [null data]
                                avast! Mail Scanner, avast! Mail Scanner, ""C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"]
                                avast! Web Scanner, avast! Web Scanner, ""C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]
                                Bluetooth Service, btwdins, "C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe" ["Broadcom Corporation"]
                                Machine Debug Manager, MDM, ""C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe"" [MS]
                                Network Harware Detection (NetDDTC), NetDDTC, ""C:\WINDOWS\system32\syscntrl.exe"" [null data]
                                SecuROM User Access Service (V7), UserAccess7, "C:\WINDOWS\System32\UAService7.exe" [null data]
                                SmartLinkService, SLService, "slserv.exe" [" "]
                                TrueVector Internet Monitor, vsmon, "C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service" ["Zone Labs, LLC"]
                                Virtual CD v4 Security service (SDK - Version), VCSSecS, "C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe" ["H+H Software GmbH"]
                                Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\System32\wdfmgr.exe" [MS]

                                Print Monitors:
                                ---------------

                                HKLM\System\CurrentControlSet\Control\Print\Monitors\
                                hpzsnt10\Driver = "hpzsnt10.dll" ["HP"]
                                Port imprimante Bluetooth\Driver = "bthcrp.dll" ["Broadcom Corporation"]

                                ----------
                                + This report excludes default entries except where indicated.
                                + To see *everywhere* the script checks and *everything* it finds,
                                launch it from a command prompt or a shortcut with the -all parameter.
                                + To search all directories of local fixed drives for DESKTOP.INI
                                DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
                                use the -supp parameter or answer "No" at the first message box.
                                ---------- (total run time: 75 seconds, including 20 seconds for message boxes)
                                0
                                1. re,
                                  cette infection c est du serieux....et grave...

                                  1/¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

                                  O4 - HKLM\..\Run: [Alive SYstem] C:\WINDOWS\System32\scchost.exe

                                  2/Ouvre le bloc note et copie colle ceci entre les étoiles

                                  **********
                                  REGEDIT4

                                  [-HKLM\SOFTWARE\Microsoft\Mrdo\winid]

                                  ************
                                  enregistre le sur ton bureau et nomme le www.reg
                                  et dans la case en dessous type met sur tous fichiers

                                  la vas sur ton bureau et double click sur se fichier que tu vient de faire et accepte la fusion avec le registre.

                                  3/Double clic sur killbox.exe (Pocket Killbox)

                                  - coche: delete on reboot
                                  - Dans "Full Path of File to Delete"
                                  copie et colle:

                                  C:\WINDOWS\System32\scchost.exe

                                  - clique sur la croix rouge
                                  - une fenêtre va apparaître pour confirmation clique sur YES
                                  - une seconde fenêtre te demande si tu veux redémarrer clique sur YES

                                  Laisse le pc redémarrer.
                                  Et après reposte un log HijackThis.

                                  A+
                                  0
                                  1. Oulala je sais pas du tout ce que tu m'as fait faire la, lol mais ca a l'air de marcher je crois que le fichier est partit si c'est le cas je te remercie enormément et je sais que ici je peut comter sur forum et le meilleur de tout ca c'est qu'aux meme moment ou j'ecrit ce message ben le fichier revenu... comme par miracle.... je l'avais pourtant suprimer... je comprend pas j'ai fais exactement comme tu me l'avais dit

                                    Logfile of HijackThis v1.99.1
                                    Scan saved at 21:08:51, on 25/11/2005
                                    Platform: Windows XP SP1 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                                    C:\WINDOWS\system32\syscntrl.exe
                                    C:\WINDOWS\system32\slserv.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\System32\UAService7.exe
                                    C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                    C:\apps\ABoard\ABoard.exe
                                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                    C:\apps\ABoard\AOSD.exe
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                    C:\Program Files\QuickTime\qttask.exe
                                    C:\Program Files\MSN Messenger\MsnMsgr.Exe
                                    C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    C:\WINDOWS\System32\wuauclt.exe
                                    C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
                                    C:\WINDOWS\System32\scchost.exe
                                    C:\hijackthis\HijackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.fr/
                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                                    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                                    O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                    O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
                                    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O4 - HKLM\..\Run: [Alive SYstem] C:\WINDOWS\System32\scchost.exe
                                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                                    O4 - Global Startup: BTTray.lnk = ?
                                    O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
                                    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                                    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                                    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                                    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                                    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128881205359
                                    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                                    O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c11.cab
                                    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                                    O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
                                    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
                                    O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
                                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                                    O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\System32\btxppanel.dll
                                    O23 - Service: AOL Instant Messanger (AIM) - Unknown owner - C:\WINDOWS\aim.exe (file missing)
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                                    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                                    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                                    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                                    O23 - Service: Network Harware Detection (NetDDTC) (NetDDTC) - Unknown owner - C:\WINDOWS\system32\syscntrl.exe
                                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                                    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                                    O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe
                                    O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                    0
                                    1. Contributeur sécurité
                                      salut
                                      fait analyser se fichier ici
                                      23 editeur d anti virus
                                      http://www.virustotal.com/xhtml/virustotal_en.html
                                      clik sur parcourir localise le fichier et clik sur send attend le rapport
                                      et donne nous le
                                      -----------------------
                                      telecharge ceci decompresse le et clik sur remove.bat
                                      a la fin clik sur exit
                                      http://cjoint.com/?lzvUmTFa03

                                      relance hijack coche et fix si existe toujours
                                      O4 - HKLM\..\Run: [Alive SYstem] C:\WINDOWS\System32\scchost.exe

                                      redemarre et refait un nouvel hijack
                                      0
                                      • 1
                                      • 2