Comment supprimé les trojans aaa,bbb,ccc ...

Bonjour et merci d'avance a tous ceux qui répondrons a cette question.
Depuis quelques temps des fichiers telle que aaa.exe bbb.exe ccc.exe ect.. apparècent régulièrement dans le répertoire WINNT/system32 (j'ai win2000 pro), j'ai essayer pratiquement tous les antivirus (AVG,Avast,Kaspersky ....) et ils me disent tous la méme chose,se sont des trojans puis je les suppriment et petit a petit ils reviennent 1 par 1 ,aaa,bbb,ccc,ddd,eee,fff,ggg,hhh,iii,jjj,kkk,lll,mmm,nnn,ooo,ppp,qqq,rrr,sss,ttt,uuu,vvv,
www,xxx,yyy,zzz.
J'aimerais savoir comment les supprimé définitivement de mon pc.

19 réponses

Résumé de la discussion

Le fil décrit l’apparition récurrente de fichiers exe nommés aaa.exe, bbb.exe,ccc.exe, etc., dans le répertoire WINNT/System32 sous Windows 2000, identifiés comme des trojans par plusieurs antivirus et bloqués à répétition. Plusieurs réponses suggèrent des manipulations via HijackThis, suppression de services comme Network DDE Client (NetDDEclnt), désactivation et suppression de netddeclnt.exe, nettoyage des fichiers temporaires et passage en mode sans échec. D'autres privilégient des outils externes (HouseCall, BitDefender Online, Panda ActiveScan, RaVa) et des utilitaires comme KillBox ou pfind/rkfiles pour supprimer les fichiers tenaces en mode sans échec. Si malgré ces mesures les trojans persistent, des entrées de registre peuvent être impliquées et des scans répétés avec des rapports détaillés aident à cibler le problème.

Bobot (l’IA à votre service)
  1. Alors F@b ? As tu réussi à t'en débarasser ?
    0
    1. Salut

      Désolé pour le retard dans la réponse. Bon alors, j'ai fait la manip indiquée mais impossible de virer mon uuu.exe.
      Apres plusieurs essais, un eee.exe est apparu.
      J'ai donc appliqué ta méthode au dessus en passant par la commande services.msc pour désactivé le eee.exe.
      J'ai pu donc le supprimer
      Néanmoins, la commande ou l'executable doit toujours être en activité car mon antivirus me previent de l'apparition de nouveaux fichiers dès que je me connecte au net.

      Question le ATI2EVX.exe ne serait il pas à l'origine de ces pbs ?

      Bref voici le hijack

      ----------------------------------------------------------------------
      Logfile of HijackThis v1.99.1
      Scan saved at 13:01:43, on 26/06/2005
      Platform: Windows 2000 SP2 (WinNT 5.00.2195)
      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

      Running processes:
      C:\WINNT\System32\smss.exe
      C:\WINNT\system32\csrss.exe
      C:\WINNT\system32\winlogon.exe
      C:\WINNT\system32\services.exe
      C:\WINNT\system32\lsass.exe
      C:\WINNT\system32\svchost.exe
      C:\WINNT\system32\spoolsv.exe
      C:\Program Files\AVPersonal\AVGUARD.EXE
      C:\Program Files\AVPersonal\AVWUPSRV.EXE
      C:\WINNT\System32\CTsvcCDA.EXE
      C:\WINNT\System32\svchost.exe
      C:\WINNT\system32\regsvc.exe
      C:\WINNT\system32\MSTask.exe
      E:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
      C:\WINNT\system32\stisvc.exe
      C:\WINNT\system32\ZONELABS\vsmon.exe
      C:\WINNT\Explorer.EXE
      C:\WINNT\System32\WBEM\WinMgmt.exe
      C:\WINNT\SOUNDMAN.EXE
      C:\Program Files\D-Tools\daemon.exe
      C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
      C:\PROGRA~1\mcafee.com\agent\McAgent.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
      C:\Program Files\SEC\MagicTune 2.5\GammaTray.exe
      C:\Program Files\Antipub\antipub.exe
      c:\progra~1\mcafee.com\vso\mcvsescn.exe
      C:\Documents and Settings\Malphas\Bureau\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - Default URLSearchHook is missing
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
      O2 - BHO: Internet Explorer Hot Fix - {F7C3EF6C-4C53-439C-8509-170FC9F716DD} - C:\WINNT\System32\gvgev.dll (file missing)
      O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
      O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
      O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 -lock
      O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
      O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
      O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
      O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
      O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
      O4 - Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe
      O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Color Calibration.lnk = C:\Program Files\SEC\MagicTune 2.5\GammaTray.exe
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O8 - Extra context menu item: Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
      O8 - Extra context menu item: Télécharger tout avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
      O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
      O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O16 - DPF: {297F2B65-017C-11D5-A128-00D0B7869AD6} (SpectorPhotoUploader Control) - http://www.extrafilm.fr/import/spu.cab
      O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/fr/4,0,0,90/mcinsctl.cab
      O16 - DPF: {92E7E45A-D8C8-480E-AF99-176E43997CAA} (Aurigma Image Uploader 3.0 Combo Control) - http://www.photoenligne.com/Components/Upload/ImageUploader3.cab
      O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
      O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.girafoto.fr/XUpload.ocx
      O16 - DPF: {FD18DD5E-B398-452A-B22A-B54636BA9F0D} (Aurigma Image Uploader 2.5) - http://www.easyfoto.fr/fonctions/ImageUploader2.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{92F96D8D-CE84-4673-9776-EE23487DD3DF}: NameServer = 69.50.184.84,195.225.176.37
      O17 - HKLM\System\CCS\Services\Tcpip\..\{D27F9CF5-3C38-4D26-84F7-9297607277B6}: NameServer = 69.50.184.84,195.225.176.37
      O17 - HKLM\System\CCS\Services\Tcpip\..\{F58CA0C4-26E2-4495-AAD0-CA459B26E6C8}: NameServer = 69.50.184.84,195.225.176.37
      O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 69.50.184.84,195.225.176.37
      O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 69.50.184.84,195.225.176.37
      O17 - HKLM\System\CS3\Services\VxD\MSTCP: NameServer = 69.50.184.84,195.225.176.37
      O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.50.184.84,195.225.176.37
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evx (file missing)
      O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.EXE
      O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
      O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
      O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
      O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
      O23 - Service: ScsiAccess - Unknown owner - E:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZONELABS\vsmon.exe

      Merci de ton aide
      0
      1. Contributeur
        Tout d'abord, imprime ce message pour ne rien oublier

        *** Déconnecte toi d'Internet

        *** Vide ton cache Internet :

        Panneau de configuration - Options Internet :
        - Clique sur "Supprimer les cookies"
        - Clique sur "Supprimer les fichiers" en cochant la case
        Puis valide ...

        *** Désactive la restauration système
        Clic droit sur poste de travail - propriétés - onglet Restauration système
        Coche "désactiver la restauration système" (accepte le redémarrage).

        *** Redémarre en mode sans échec
        Laisse passer l'écran du bios, puis tapote sur la touche F8.
        Choisis le mode sans échec dans les options et valide avec entrée.

        *** Rend visible les fichiers cachés et système :
        Panneau de configuration - Options des dossiers - onglet Affichage
        Coche " Afficher les fichiers et dossiers cachés "
        Décoche " Masquer les extensions des fichiers dont le type est connu"
        Décoche " Masquer les fichiers protégés du système" puis valide

        *** Toujours en mode sans échec, lance hijackthis et fixe :
        (Coche les cases au début des lignes suivantes)

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Malphas\LOCALS~1\Temp\se.dll/sp.html
        O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINNT\System32\orjrx.dll (file missing)
        O2 - BHO: (no name) - {4CEB256D-33FB-410A-8A5C-12F593967D0D} - (no file)
        O23 - Service: Managing FAT and NTFS partitions (Defragmentation Manager) - Unknown owner - C:\WINNT\system32\uuu.exe

        Puis valide avec Fix Checked

        *** Recherche et supprime si présent :

        [Dans le cas ou tu utiliserais la fonction Rechercher :
        Tous les fichiers et tous les dossiers - Options avancées
        • Rechercher dans les dossiers systèmes } DOIT ÊTRE COCHÉ
        • Rechercher dans les fichiers et les dossiers cachés } DOIT ÊTRE COCHÉ
        • Rechercher dans les sous-dossiers } DOIT ÊTRE COCHÉ

        *** Supprime :

        C:\Windows\System32\uuu.exe

        *** Supprime les fichiers temporaires avec ce petit programme :
        http://pageperso.aol.fr/Balltrap34/CleanUp312.exe

        Ou manuellement : vide tout le contenu des dossiers en gras :
        -- C:\Documents and Settings\ton compte\Local Settings\Temp
        -- C:\Documents and Settings\tous les autres comptes\Local Settings\Temp
        -- C:\Temp
        -- C:\Windows\Temp
        -- C:\WINDOWS\Prefetch : Sauf le fichier layout.ini

        *** Vide ta corbeille !

        Redémarre normalement ton PC. Ensuite, fais un scan AV ici :
        http://www.ravantivirus.com/scan/
        Clique sur "To continue without subscribing click here" et attends
        Lorsque "Ready" est affiché dans "status", coche la case Autoclean et clique sur "Scan my PC"
        A la fin de l'analyse, copie/colle le rapport ici + un nouveau rapport Hijackthis

        @+++
        0
        1. Et c'est parti pour le Log d'Hijack...
          Pour complément, j'avais installé bitdefender (oui une version cracké j'ai honte) et sa saleté de fichier vsserv.exe me ralentissait mon PC.
          Je l'ai donc désinstallé tant bien que mal mais il reste qq traces dont je n'arrive pas à me défaire (cf 2 dernieres lignes du log)

          De plus, pour les symptomes voilà ce que me detecte AVR de temps en temps...
          "C:\WINNT\SYSTEM32\POOJHGSF.EXE
          Contains a signature of the (dangerous) backdoor program BDS/PoeBot.B Backdoor server programs"

          mais place au log et encore merci pour vos aides éclairées !!

          ----------------------------------------
          Logfile of HijackThis v1.99.1
          Scan saved at 20:50:05, on 24/06/2005
          Platform: Windows 2000 SP2 (WinNT 5.00.2195)
          MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

          Running processes:
          C:\WINNT\System32\smss.exe
          C:\WINNT\system32\csrss.exe
          C:\WINNT\system32\winlogon.exe
          C:\WINNT\system32\services.exe
          C:\WINNT\system32\lsass.exe
          C:\WINNT\system32\svchost.exe
          C:\WINNT\system32\spoolsv.exe
          C:\Program Files\AVPersonal\AVGUARD.EXE
          C:\Program Files\AVPersonal\AVWUPSRV.EXE
          C:\WINNT\System32\CTsvcCDA.EXE
          C:\WINNT\system32\uuu.exe
          C:\WINNT\System32\svchost.exe
          C:\WINNT\system32\regsvc.exe
          C:\WINNT\system32\MSTask.exe
          E:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
          C:\WINNT\system32\stisvc.exe
          C:\WINNT\system32\ZONELABS\vsmon.exe
          C:\WINNT\Explorer.EXE
          C:\WINNT\System32\WBEM\WinMgmt.exe
          C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
          C:\WINNT\SOUNDMAN.EXE
          C:\Program Files\D-Tools\daemon.exe
          C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
          C:\PROGRA~1\mcafee.com\agent\McAgent.exe
          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
          C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
          c:\progra~1\mcafee.com\vso\mcvsescn.exe
          C:\Program Files\SEC\MagicTune 2.5\GammaTray.exe
          C:\Program Files\Antipub\antipub.exe
          C:\Documents and Settings\Malphas\Bureau\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Malphas\LOCALS~1\Temp\se.dll/sp.html
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - Default URLSearchHook is missing
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
          O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINNT\System32\orjrx.dll (file missing)
          O2 - BHO: (no name) - {4CEB256D-33FB-410A-8A5C-12F593967D0D} - (no file)
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
          O2 - BHO: Internet Explorer Hot Fix - {F7C3EF6C-4C53-439C-8509-170FC9F716DD} - C:\WINNT\System32\gvgev.dll (file missing)
          O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
          O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
          O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 -lock
          O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
          O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
          O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
          O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
          O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
          O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
          O4 - Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe
          O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: Color Calibration.lnk = C:\Program Files\SEC\MagicTune 2.5\GammaTray.exe
          O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
          O8 - Extra context menu item: Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
          O8 - Extra context menu item: Télécharger tout avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
          O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
          O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
          O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
          O16 - DPF: {297F2B65-017C-11D5-A128-00D0B7869AD6} (SpectorPhotoUploader Control) - http://www.extrafilm.fr/import/spu.cab
          O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
          O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/fr/4,0,0,90/mcinsctl.cab
          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
          O16 - DPF: {92E7E45A-D8C8-480E-AF99-176E43997CAA} (Aurigma Image Uploader 3.0 Combo Control) - http://www.photoenligne.com/Components/Upload/ImageUploader3.cab
          O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.girafoto.fr/XUpload.ocx
          O16 - DPF: {FD18DD5E-B398-452A-B22A-B54636BA9F0D} (Aurigma Image Uploader 2.5) - http://www.easyfoto.fr/fonctions/ImageUploader2.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{92F96D8D-CE84-4673-9776-EE23487DD3DF}: NameServer = 69.50.184.84,195.225.176.37
          O17 - HKLM\System\CCS\Services\Tcpip\..\{D27F9CF5-3C38-4D26-84F7-9297607277B6}: NameServer = 69.50.184.84,195.225.176.37
          O17 - HKLM\System\CCS\Services\Tcpip\..\{F58CA0C4-26E2-4495-AAD0-CA459B26E6C8}: NameServer = 69.50.184.84,195.225.176.37
          O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 69.50.184.84,195.225.176.37
          O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 69.50.184.84,195.225.176.37
          O17 - HKLM\System\CS3\Services\VxD\MSTCP: NameServer = 69.50.184.84,195.225.176.37
          O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.50.184.84,195.225.176.37
          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
          O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evx (file missing)
          O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
          O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
          O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.EXE
          O23 - Service: Managing FAT and NTFS partitions (Defragmentation Manager) - Unknown owner - C:\WINNT\system32\uuu.exe
          O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
          O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
          O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
          O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
          O23 - Service: ScsiAccess - Unknown owner - E:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZONELABS\vsmon.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender8\vsserv.exe" /service (file missing)
          O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
          0
          1. Mes symptomes sont similaires à ceux de F@b à savoir :
            (je suis sous W2000)
            - apparition d'un uuu.exe dans les processus en cours (impossible à enlever en direct meme en mode sans echec)
            - blocage du driver de ma carte son (winamp et windows media player ne se lancent pas du coup)
            - apparition de fichiers dll sous system32, contenant divers trojans détectés par antivir, effacés par ce dernier et... ils reviennent
            - il y également un repertoire Adcache que j'efface qui revient
            heu... je crois que c'est tout !
            0
            1. Contributeur
              Peux-tu poster un log HijackThis ici, STP ???
              0
          2. Merci Neo-Nil@u

            Je fais cela ce soir ou demain, une fois rentré à la casa !
            0
            1. Contributeur
              No problem ... Par contre, pourras-tu décrire tes problèmes dans un nouveau message ?? Merci !! @+++
              0
          3. Moi qui croyait que j'étais le seul !!!
            Quelle galère ! Cela fait 3 jours que je me bats également contre cette merde !
            Ah les nuits blanches devant le PC...
            Magré mes efforts, il est toujours là et Mcfee et Antivir et Zonealarm ne voient rien
            Je venais chercher un peu d'aide car je ne m'en sors plus.
            Je vais tester tes manips Moe31 et à ce titre je te remercie déjà de ton aide !
            Je repars à l'attaque de mon uuu.exe
            et je vous tiens au courant !
            0
            1. salut fab

              je peux pas trop rester ce midi, je repasse ce soir.

              poste les log des 2 progs + un hijack

              a+
              0
              1. salut fab

                pas facile, car il n'y a pas grand chose dans ton hijack.
                a part ceci XoftSpy.job.
                xoftspy est un faux utilitaire de securité, désinstalle le.
                va dans C:\WINDOWS\Task et supprime XoftSpy.job.

                ensuite telecharge:

                PFIND-New
                http://www.bleepingcomputer.com/files/grinler/pfind-new.zip
                et
                rkfiles
                http://skads.org/special/rkfiles.zip

                redemarre en mode sans echecs et double clic sur pfind.bat et sauvegarde le rapport.
                ensuite double clic sur rkfiles.bat et sauvegarde le rapport.

                redemarre normalement et poste ici les 2 rapports.

                en esperant que ca nous en apprendra un peu plus...

                a+
                0
                1. Ok je vais faire ca tout de suite a+.
                  0
              2. dur dur :-(

                lance hijackthis, clic sur "open the misc tools section"
                là tu va voir un bouton "generate startuplist log" et juste à coté 2 cases.
                coche les et ensuite appuie sur "generate startuplist log"
                ca va generer un log plus long et plus detaillé.
                poste le resultat

                a+
                0
                1. RE.Voici ce que tu ma demander c'est trés long ^^.En tout cas les aaa.exe bbb,ccc ect... il ne reviennent plus,je n'est plus d'alerte de sygate qui me dit u'un de ces trucs veut se lancer et j'ai regarder entiérement system32 il n'y a plus tous ces trojans.a+

                  StartupList report, 22/06/2005, 08:54:19
                  StartupList version: 1.52.2
                  Started from : C:\Documents and Settings\XXXXXX\Bureau\HijackThis.EXE
                  Detected: Windows 2000 (WinNT 5.00.2195)
                  Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
                  * Using default options
                  * Including empty and uninteresting sections
                  * Showing rarely important sections
                  ==================================================

                  Running processes:

                  C:\WINNT\System32\smss.exe
                  C:\WINNT\system32\winlogon.exe
                  C:\WINNT\system32\services.exe
                  C:\WINNT\system32\lsass.exe
                  C:\WINNT\System32\Ati2evxx.exe
                  C:\Program Files\Sygate\SPF\smc.exe
                  C:\WINNT\system32\svchost.exe
                  C:\WINNT\system32\spoolsv.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINNT\System32\svchost.exe
                  C:\WINNT\system32\hidserv.exe
                  C:\WINNT\System32\netddeclnt.exe
                  C:\WINNT\system32\regsvc.exe
                  C:\WINNT\system32\MSTask.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  C:\WINNT\System32\WBEM\WinMgmt.exe
                  C:\WINNT\system32\Ati2evxx.exe
                  C:\WINNT\Explorer.exe
                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  C:\Program Files\Logitech\iTouch\iTouch.exe
                  C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINNT\loadqm.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Documents and Settings\XXXXXX\Bureau\HijackThis.exe

                  --------------------------------------------------

                  Listing of startup folders:

                  Shell folders Startup:
                  [C:\Documents and Settings\XXXXXX\Menu Démarrer\Programmes\Démarrage]
                  *No files*

                  Shell folders AltStartup:
                  *Folder not found*

                  User shell folders Startup:
                  *Folder not found*

                  User shell folders AltStartup:
                  *Folder not found*

                  Shell folders Common Startup:
                  [C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage]
                  Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

                  Shell folders Common AltStartup:
                  *Folder not found*

                  User shell folders Common Startup:
                  *Folder not found*

                  User shell folders Alternate Common Startup:
                  *Folder not found*

                  --------------------------------------------------

                  Checking Windows NT UserInit:

                  [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  UserInit = C:\WINNT\system32\userinit.exe,

                  [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
                  *Registry key not found*

                  [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  *Registry value not found*

                  [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries from Registry:
                  HKLM\Software\Microsoft\Windows\CurrentVersion\Run

                  Synchronization Manager = mobsync.exe /logon
                  ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  zBrowser Launcher = C:\Program Files\Logitech\iTouch\iTouch.exe
                  EM_EXEC = C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  %FP%Friendly fts.exe = "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
                  avast! = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  LoadQM = loadqm.exe
                  SmcService = C:\PROGRA~1\Sygate\SPF\smc.exe -startgui

                  --------------------------------------------------

                  Autorun entries from Registry:
                  HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

                  *No values found*

                  --------------------------------------------------

                  Autorun entries from Registry:
                  HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

                  *No values found*

                  --------------------------------------------------

                  Autorun entries from Registry:
                  HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries from Registry:
                  HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries from Registry:
                  HKCU\Software\Microsoft\Windows\CurrentVersion\Run

                  Steam =

                  --------------------------------------------------

                  Autorun entries from Registry:
                  HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

                  *No values found*

                  --------------------------------------------------

                  Autorun entries from Registry:
                  HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries from Registry:
                  HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries from Registry:
                  HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries from Registry:
                  HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries from Registry:
                  HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries in Registry subkeys of:
                  HKLM\Software\Microsoft\Windows\CurrentVersion\Run
                  *No subkeys found*

                  --------------------------------------------------

                  Autorun entries in Registry subkeys of:
                  HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
                  *No subkeys found*

                  --------------------------------------------------

                  Autorun entries in Registry subkeys of:
                  HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
                  *No subkeys found*

                  --------------------------------------------------

                  Autorun entries in Registry subkeys of:
                  HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries in Registry subkeys of:
                  HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries in Registry subkeys of:
                  HKCU\Software\Microsoft\Windows\CurrentVersion\Run
                  *No subkeys found*

                  --------------------------------------------------

                  Autorun entries in Registry subkeys of:
                  HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
                  *No subkeys found*

                  --------------------------------------------------

                  Autorun entries in Registry subkeys of:
                  HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries in Registry subkeys of:
                  HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries in Registry subkeys of:
                  HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries in Registry subkeys of:
                  HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries in Registry subkeys of:
                  HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
                  *Registry key not found*

                  --------------------------------------------------

                  File association entry for .EXE:
                  HKEY_CLASSES_ROOT\exefile\shell\open\command

                  (Default) = "%1" %*

                  --------------------------------------------------

                  File association entry for .COM:
                  HKEY_CLASSES_ROOT\comfile\shell\open\command

                  (Default) = "%1" %*

                  --------------------------------------------------

                  File association entry for .BAT:
                  HKEY_CLASSES_ROOT\batfile\shell\open\command

                  (Default) = "%1" %*

                  --------------------------------------------------

                  File association entry for .PIF:
                  HKEY_CLASSES_ROOT\piffile\shell\open\command

                  (Default) = "%1" %*

                  --------------------------------------------------

                  File association entry for .SCR:
                  HKEY_CLASSES_ROOT\scrfile\shell\open\command

                  (Default) = "%1" /S

                  --------------------------------------------------

                  File association entry for .HTA:
                  HKEY_CLASSES_ROOT\htafile\shell\open\command

                  (Default) = C:\WINNT\System32\mshta.exe "%1" %*

                  --------------------------------------------------

                  File association entry for .TXT:
                  HKEY_CLASSES_ROOT\txtfile\shell\open\command

                  (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

                  --------------------------------------------------

                  Enumerating Active Setup stub paths:
                  HKLM\Software\Microsoft\Active Setup\Installed Components
                  (* = disabled by HKCU twin)

                  [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                  StubPath = C:\WINNT\inf\unregmp2.exe /ShowWMP

                  [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
                  StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

                  [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
                  StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

                  [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
                  StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

                  [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
                  StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\wmp.inf,PerUserStub

                  [{7790769C-0471-11d2-AF11-00C04FA35D02}] *
                  StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

                  [{89820200-ECBD-11cf-8B85-00AA005B4340}] *
                  StubPath = regsvr32.exe /s /n /i:U shell32.dll

                  [{89820200-ECBD-11cf-8B85-00AA005B4383}] *
                  StubPath = %SystemRoot%\System32\ie4uinit.exe

                  [{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
                  StubPath = %SystemRoot%\System32\updcrl.exe -e -u %SystemRoot%\System32\verisignpub1.crl

                  --------------------------------------------------

                  Enumerating ICQ Agent Autostart apps:
                  HKCU\Software\Mirabilis\ICQ\Agent\Apps

                  *Registry key not found*

                  --------------------------------------------------

                  Load/Run keys from C:\WINNT\WIN.INI:

                  load=*INI section not found*
                  run=*INI section not found*

                  Load/Run keys from Registry:

                  HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
                  HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
                  HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
                  HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
                  HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
                  HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
                  HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
                  HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
                  HKCU\..\Windows NT\CurrentVersion\Windows: load=
                  HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
                  HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
                  HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
                  HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

                  --------------------------------------------------

                  Shell & screensaver key from C:\WINNT\SYSTEM.INI:

                  Shell=*INI section not found*
                  SCRNSAVE.EXE=*INI section not found*
                  drivers=*INI section not found*

                  Shell & screensaver key from Registry:

                  Shell=Explorer.exe
                  SCRNSAVE.EXE=*Registry value not found*
                  drivers=*Registry value not found*

                  Policies Shell key:

                  HKCU\..\Policies: Shell=*Registry value not found*
                  HKLM\..\Policies: Shell=*Registry value not found*

                  --------------------------------------------------

                  Checking for EXPLORER.EXE instances:

                  C:\WINNT\Explorer.exe: PRESENT!

                  C:\Explorer.exe: not present
                  C:\WINNT\Explorer\Explorer.exe: not present
                  C:\WINNT\System\Explorer.exe: not present
                  C:\WINNT\System32\Explorer.exe: not present
                  C:\WINNT\Command\Explorer.exe: not present
                  C:\WINNT\Fonts\Explorer.exe: not present

                  --------------------------------------------------

                  Checking for superhidden extensions:

                  .lnk: HIDDEN! (arrow overlay: yes)
                  .pif: HIDDEN! (arrow overlay: yes)
                  .exe: not hidden
                  .com: not hidden
                  .bat: not hidden
                  .hta: not hidden
                  .scr: not hidden
                  .shs: HIDDEN!
                  .shb: HIDDEN!
                  .vbs: not hidden
                  .vbe: not hidden
                  .wsh: not hidden
                  .scf: HIDDEN! (arrow overlay: NO!)
                  .url: HIDDEN! (arrow overlay: yes)
                  .js: not hidden
                  .jse: not hidden

                  --------------------------------------------------

                  Verifying REGEDIT.EXE integrity:

                  - Regedit.exe found in C:\WINNT
                  - .reg open command is normal (regedit.exe %1)
                  - Regedit.exe has no CompanyName property! It is either missing or named something else.
                  - Regedit.exe has no OriginalFilename property! It is either missing or named something else.
                  - Regedit.exe has no FileDescription property! It is either missing or named something else.

                  Registry check failed!

                  --------------------------------------------------

                  Enumerating Browser Helper Objects:

                  *No BHO's found*

                  --------------------------------------------------

                  Enumerating Task Scheduler jobs:

                  XoftSpy.job

                  --------------------------------------------------

                  Enumerating Download Program Files:

                  [DirectAnimation Java Classes]
                  CODEBASE = file://C:\WINNT\Java\classes\dajava.cab
                  OSD = C:\WINNT\Downloaded Program Files\DirectAnimation Java Classes.osd

                  [Microsoft XML Parser for Java]
                  CODEBASE = file://C:\WINNT\Java\classes\xmldso.cab
                  OSD = C:\WINNT\Downloaded Program Files\Microsoft XML Parser for Java.osd

                  --------------------------------------------------

                  Enumerating Winsock LSP files:

                  NameSpace #1: C:\WINNT\System32\rnr20.dll
                  NameSpace #2: C:\WINNT\System32\winrnr.dll
                  Protocol #1: C:\WINNT\system32\msafd.dll
                  Protocol #2: C:\WINNT\system32\msafd.dll
                  Protocol #3: C:\WINNT\system32\msafd.dll
                  Protocol #4: C:\WINNT\system32\rsvpsp.dll
                  Protocol #5: C:\WINNT\system32\rsvpsp.dll
                  Protocol #6: C:\WINNT\system32\msafd.dll
                  Protocol #7: C:\WINNT\system32\msafd.dll
                  Protocol #8: C:\WINNT\system32\msafd.dll
                  Protocol #9: C:\WINNT\system32\msafd.dll
                  Protocol #10: C:\WINNT\system32\msafd.dll
                  Protocol #11: C:\WINNT\system32\msafd.dll
                  Protocol #12: C:\WINNT\system32\msafd.dll
                  Protocol #13: C:\WINNT\system32\msafd.dll
                  Protocol #14: C:\WINNT\system32\msafd.dll
                  Protocol #15: C:\WINNT\system32\msafd.dll
                  Protocol #16: C:\WINNT\system32\msafd.dll
                  Protocol #17: C:\WINNT\system32\msafd.dll

                  --------------------------------------------------

                  Enumerating Windows NT/2000/XP services

                  Pilote ACPI Microsoft: System32\DRIVERS\ACPI.sys (system)
                  aeaudio: system32\drivers\aeaudio.sys (manual start)
                  Environnement de prise en charge de réseau AFD: \SystemRoot\System32\drivers\afd.sys (autostart)
                  Avertissement: %SystemRoot%\System32\services.exe (manual start)
                  Gestion d'applications: %SystemRoot%\system32\services.exe (manual start)
                  ASUSHWIO: \??\C:\WINNT\System32\drivers\ASUSHWIO.sys (manual start)
                  aswRdr: \??\C:\WINNT\System32\drivers\aswRdr.sys (manual start)
                  avast! iAVS4 Control Service: "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe" (autostart)
                  Pilote de média asynchrone RAS: System32\DRIVERS\asyncmac.sys (manual start)
                  Contrôleur de disque dur IDE/ESDI standard: System32\DRIVERS\atapi.sys (system)
                  Ati HotKey Poller: %SystemRoot%\System32\Ati2evxx.exe (autostart)
                  ATI Smart: C:\WINNT\system32\ati2sgag.exe (autostart)
                  ati2mtag: System32\DRIVERS\ati2mtag.sys (manual start)
                  Protocole client ATM ARP: System32\DRIVERS\atmarpc.sys (manual start)
                  Pilote audio Stub: System32\DRIVERS\audstub.sys (manual start)
                  avast! Antivirus: "C:\Program Files\Alwil Software\Avast4\ashServ.exe" (autostart)
                  avast! Mail Scanner: "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (manual start)
                  avast! Web Scanner: "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (manual start)
                  Explorateur d'ordinateur: %SystemRoot%\System32\services.exe (autostart)
                  Closed Caption Decoder: System32\DRIVERS\CCDECODE.sys (manual start)
                  Pilote de CD-ROM: System32\DRIVERS\cdrom.sys (system)
                  Service d'indexation: C:\WINNT\System32\cisvc.exe (manual start)
                  Gestionnaire de l'Album: %SystemRoot%\system32\clipsrv.exe (manual start)
                  Client DHCP: %SystemRoot%\System32\services.exe (autostart)
                  Pilote de disque: System32\DRIVERS\disk.sys (system)
                  Service d'administration du Gestionnaire de disque logique: %SystemRoot%\System32\dmadmin.exe /com (manual start)
                  dmboot: System32\drivers\dmboot.sys (disabled)
                  Pilote de Gestionnaire de disque logique: System32\drivers\dmio.sys (system)
                  dmload: System32\drivers\dmload.sys (system)
                  Gestionnaire de disque logique: %SystemRoot%\System32\services.exe (autostart)
                  Synthé logiciel Microsoft DirectMusic (WDM): system32\drivers\DMusic.sys (manual start)
                  Client DNS: %SystemRoot%\System32\services.exe (autostart)
                  Journal des événements: %SystemRoot%\system32\services.exe (autostart)
                  Système d'événements de COM+: C:\WINNT\System32\svchost.exe -k netsvcs (manual start)
                  NETGEAR FA311/FA312 NDIS 5.0 Miniport Driver: System32\DRIVERS\FA31XND5.SYS (manual start)
                  Service de télécopie: %systemroot%\system32\faxsvc.exe (manual start)
                  Pilote de contrôleur de lecteur de disquettes: System32\DRIVERS\fdc.sys (manual start)
                  Pilote de lecteur de disquettes: System32\DRIVERS\flpydisk.sys (manual start)
                  Pilote du Gestionnaire de volume: System32\DRIVERS\ftdisk.sys (system)
                  Game Port Enumerator: System32\DRIVERS\gameenum.sys (manual start)
                  Classificateur de paquets générique: System32\DRIVERS\msgpc.sys (manual start)
                  HID Input Service: %SystemRoot%\system32\hidserv.exe (autostart)
                  Pilote de classe HID Microsoft: System32\DRIVERS\hidusb.sys (autostart)
                  Pilote de filtre de trafic IP: System32\DRIVERS\ipfltdrv.sys (manual start)
                  Pilote de tunnelage IP dans IP: System32\DRIVERS\ipinip.sys (manual start)
                  Traducteur d'adresses réseau IP: System32\DRIVERS\ipnat.sys (manual start)
                  Pilote IPSEC: System32\DRIVERS\ipsec.sys (manual start)
                  Pilote de bus Plug-and-Play ISA/EISA: System32\DRIVERS\isapnp.sys (system)
                  iTouch Keyboard Filter: System32\Drivers\itchfltr.sys (manual start)
                  Pilote de la classe Clavier: System32\DRIVERS\kbdclass.sys (system)
                  Pilote HID de clavier: System32\DRIVERS\kbdhid.sys (system)
                  Mélangeur audio Wave de noyau Microsoft: system32\drivers\kmixer.sys (manual start)
                  Serveur: %SystemRoot%\System32\services.exe (autostart)
                  Station de travail: %SystemRoot%\System32\services.exe (autostart)
                  Logitech USB Filter Driver: system32\drivers\lccfltr.sys (manual start)
                  Logitech HID/USB Mouse Filter Driver: System32\DRIVERS\lhidflt2.sys (manual start)
                  Logitech USB Receiver device driver: system32\drivers\lhidusb.sys (manual start)
                  Logitech Keyboard Class Filter Driver: System32\DRIVERS\lkbdflt2.sys (manual start)
                  Service d'application d'assistance TCP/IP NetBIOS: %SystemRoot%\System32\services.exe (autostart)
                  Logitech Mouse Class Filter Driver: System32\DRIVERS\lmouflt2.sys (manual start)
                  Affichage des messages: %SystemRoot%\System32\services.exe (disabled)
                  Partage de Bureau à distance NetMeeting: C:\WINNT\System32\mnmsrvc.exe (manual start)
                  Pilote de la classe Souris: System32\DRIVERS\mouclass.sys (system)
                  Pilote HID de souris: System32\DRIVERS\mouhid.sys (manual start)
                  BDA MPE Filter: System32\DRIVERS\MPE.sys (manual start)
                  MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
                  Distributed Transaction Coordinator: C:\WINNT\System32\msdtc.exe (manual start)
                  Windows Installer: C:\WINNT\System32\MsiExec.exe /V (manual start)
                  Proxy de service de répartition Microsoft: system32\drivers\MSKSSRV.sys (manual start)
                  Proxy d'horloge de répartition Microsoft: system32\drivers\MSPCLOCK.sys (manual start)
                  Proxy de gestion de qualité de répartition Microsoft: system32\drivers\MSPQM.sys (manual start)
                  Microsoft Streaming Tee/Sink-to-Sink Converter: system32\drivers\MSTEE.sys (manual start)
                  NABTS/FEC VBI Codec: System32\DRIVERS\NABTSFEC.sys (manual start)
                  Pilote TAPI NDIS d'accès à distance: System32\DRIVERS\ndistapi.sys (manual start)
                  Pilote réseau étendu NDIS d'accès à distance: System32\DRIVERS\ndiswan.sys (manual start)
                  Interface NetBIOS: System32\DRIVERS\netbios.sys (system)
                  NetBIOS sur TCP/IP: System32\DRIVERS\netbt.sys (system)
                  DDE réseau: %SystemRoot%\system32\netdde.exe (manual start)
                  Network DDE Client: C:\WINNT\System32\netddeclnt.exe (autostart)
                  DSDM DDE réseau: %SystemRoot%\system32\netdde.exe (manual start)
                  NetDetect: \SystemRoot\system32\drivers\netdtect.sys (manual start)
                  Ouverture de session réseau: %SystemRoot%\System32\lsass.exe (manual start)
                  Connexions réseau: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                  Fournisseur de la prise en charge de sécurité LM NT: %SystemRoot%\System32\lsass.exe (manual start)
                  Médias amovibles: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                  Pilote de filtre de trafic IPX: System32\DRIVERS\nwlnkflt.sys (manual start)
                  Pilote de transfert de trafic IPX: System32\DRIVERS\nwlnkfwd.sys (manual start)
                  Palladia 300/400 Usb Adsl Modem: System32\DRIVERS\usbiad.sys (manual start)
                  Pilote de classe parallèle: System32\DRIVERS\parallel.sys (manual start)
                  Pilote de port parallèle: System32\DRIVERS\parport.sys (system)
                  PCI Bus Driver: System32\DRIVERS\pci.sys (system)
                  PCIIde: System32\DRIVERS\pciide.sys (system)
                  Plug-and-Play: %SystemRoot%\system32\services.exe (autostart)
                  Agent de stratégie IPSEC: %SystemRoot%\System32\lsass.exe (autostart)
                  PPPoEWin Miniport: System32\DRIVERS\PPPoEWin.SYS (manual start)
                  Miniport réseau étendu (PPTP): System32\DRIVERS\raspptp.sys (manual start)
                  Emplacement protégé: %SystemRoot%\system32\services.exe (autostart)
                  Pilote de liaison parallèle directe: System32\DRIVERS\ptilink.sys (manual start)
                  Pilote de connexion automatique d'accès distant: System32\DRIVERS\rasacd.sys (system)
                  Gestionnaire de connexion automatique d'accès distant: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                  Miniport réseau étendu (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
                  Gestionnaire de connexions d'accès distant: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                  Parallèle direct: System32\DRIVERS\raspti.sys (manual start)
                  Microsoft Streaming Network Raw Channel Access: system32\drivers\RCA.sys (manual start)
                  Rdbss: System32\DRIVERS\rdbss.sys (system)
                  Pilote de filtre de lecture digitale de CD audio: System32\DRIVERS\redbook.sys (system)
                  Routage et accès distant: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
                  Service d'accès à distance au Registre: %SystemRoot%\system32\regsvc.exe (autostart)
                  Localisateur d'appels de procédure distante (RPC): %SystemRoot%\System32\locator.exe (manual start)
                  Appel de procédure distante (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
                  QoS RSVP: %SystemRoot%\System32\rsvp.exe -s (manual start)
                  Gestionnaire de comptes de sécurité: %SystemRoot%\system32\lsass.exe (autostart)
                  Prise en charge des cartes à puces: %SystemRoot%\System32\SCardSvr.exe (manual start)
                  Carte à puce: %SystemRoot%\System32\SCardSvr.exe (manual start)
                  Planificateur de tâches: %SystemRoot%\system32\MSTask.exe (autostart)
                  SecDrv: \??\C:\WINNT\System32\drivers\SECDRV.SYS (autostart)
                  Service d'exécution par délégation: %SystemRoot%\system32\services.exe (autostart)
                  Notification d'événement système: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
                  Pilote de filtre Serenum: System32\DRIVERS\serenum.sys (manual start)
                  Pilote de port série: System32\DRIVERS\serial.sys (system)
                  Partage de connexion Internet: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                  BDA Slip De-Framer: System32\DRIVERS\SLIP.sys (manual start)
                  Sygate Personal Firewall: C:\Program Files\Sygate\SPF\smc.exe (autostart)
                  smwdm: system32\drivers\smwdm.sys (manual start)
                  SoundMAX Agent Service: C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (autostart)
                  Spouleur d'impression: %SystemRoot%\system32\spoolsv.exe (autostart)
                  Srv: System32\DRIVERS\srv.sys (manual start)
                  BDA IPSink: System32\DRIVERS\StreamIP.sys (manual start)
                  Pilote de bus logiciel: System32\DRIVERS\swenum.sys (manual start)
                  Synthétiseur de table de sons GC noyau Microsoft: system32\drivers\swmidi.sys (manual start)
                  Périphérique audio système Microsoft: system32\drivers\sysaudio.sys (manual start)
                  Journaux et alertes de performance: %SystemRoot%\system32\smlogsvc.exe (manual start)
                  Téléphonie: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                  Pilote du protocole TCP/IP: System32\DRIVERS\tcpip.sys (system)
                  Teefer for NT: SYSTEM32\Drivers\Teefer.sys (system)
                  Telnet: %SystemRoot%\system32\tlntsvr.exe (manual start)
                  Client de suivi de lien distribué: %SystemRoot%\system32\services.exe (autostart)
                  Pilote de contrôleur hôte universel USB Microsoft: System32\DRIVERS\uhcd.sys (manual start)
                  Pilote de mise à jour microcode: System32\DRIVERS\update.sys (manual start)
                  Onduleur: %SystemRoot%\System32\ups.exe (manual start)
                  Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: System32\DRIVERS\usbehci.sys (manual start)
                  Pilote de concentrateur standard USB Microsoft: System32\DRIVERS\usbhub.sys (manual start)
                  USB 2.0 Root Hub Support: System32\DRIVERS\usbhub20.sys (manual start)
                  Gestionnaire d'utilitaires: %SystemRoot%\System32\UtilMan.exe (manual start)
                  VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
                  VIA AGP Filter: System32\DRIVERS\viaagp1.sys (system)
                  VIA USB Filter: \SystemRoot\System32\Drivers\viausb.sys (manual start)
                  viaide: System32\DRIVERS\viaide.sys (system)
                  VIA USB Host Controller Lower Filter: \SystemRoot\System32\Drivers\vulfnth.sys (manual start)
                  VIA USB Roothub Lower Filter: \SystemRoot\System32\Drivers\vulfntr.sys (manual start)
                  Horloge Windows: %SystemRoot%\System32\services.exe (manual start)
                  Pilote ARP IP d'accès à distance: System32\DRIVERS\wanarp.sys (manual start)
                  Pilote WINMM de compatibilité audio WDM Microsoft: system32\drivers\wdmaud.sys (manual start)
                  SyGate for NT, wg3n: \SystemRoot\SYSTEM32\Drivers\wg3n.sys (autostart)
                  SyGate for NT, wg4n: \SystemRoot\SYSTEM32\Drivers\wg4n.sys (autostart)
                  SyGate for NT, wg5n: \SystemRoot\SYSTEM32\Drivers\wg5n.sys (autostart)
                  SyGate for NT, wg6n: \SystemRoot\SYSTEM32\Drivers\wg6n.sys (autostart)
                  Infrastructure de gestion Windows: %SystemRoot%\System32\WBEM\WinMgmt.exe (autostart)
                  Service de numéro de série du lecteur multimédia portable: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                  Extensions du pilote WMI: %SystemRoot%\system32\Services.exe (manual start)
                  wpsdrvnt: \??\C:\WINNT\System32\drivers\wpsdrvnt.sys (system)
                  World Standard Teletext Codec: System32\DRIVERS\WSTCODEC.SYS (manual start)

                  --------------------------------------------------

                  Enumerating Windows NT logon/logoff scripts:
                  *No scripts set to run*

                  Windows NT checkdisk command:
                  BootExecute = autocheck autochk *

                  Windows NT 'Wininit.ini':
                  PendingFileRenameOperations: *Registry value not found*

                  --------------------------------------------------

                  Enumerating ShellServiceObjectDelayLoad items:

                  Network.ConnectionTray: C:\WINNT\system32\NETSHELL.dll
                  WebCheck: C:\WINNT\System32\webcheck.dll
                  SysTray: stobject.dll

                  --------------------------------------------------
                  Autorun entries from Registry:
                  HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

                  *Registry key not found*

                  --------------------------------------------------

                  Autorun entries from Registry:
                  HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

                  *No values found*

                  --------------------------------------------------

                  End of report, 28 827 bytes
                  Report generated in 0,109 seconds

                  Command line options:
                  /verbose - to add additional info on each section
                  /complete - to include empty sections and unsuspicious data
                  /full - to include several rarely-important sections
                  /force9x - to include Win9x-only startups even if running on WinNT
                  /forcent - to include WinNT-only startups even if running on Win9x
                  /forceall - to include all Win9x and WinNT startups, regardless of platform
                  /history - to list version history only
                  0
                2. @F[@]BRE moe31 j'ai u une mauvaise suprprise iii.exe a fait son aparition alors qu'il ni avait plus rien je l'est bloquer avec sygate.
                  a+
                  0

              3. ok, on va essayer autre chose.

                Telecharge: Pocket Killbox ici
                http://www.downloads.subratam.org/KillBox.exe
                un petite aide en image pour l'utiliser ici:
                http://get.yourfile.net/ix48472.jpg

                Imprime, ou fais un copier coller et enregistre dans le bloc note pour ne rien oublier.

                Déconnecte toi d'internet:

                Vide le cache d'Internet Explorer et supprime les cookies:

                * Panneau de configuration >> Options internet >> Onglet "Général"
                - Clic sur [supprimer les cookies]
                - Clic sur [Supprimer les fichiers] et coche la case "Supprimer tout le contenu hors connexion"
                Valide avec ok

                Redémarre en mode sans échec
                Laisse passer l'écran du bios, puis tapote sur la touche F8 avant qu'apparaisse l'écran de chargement de windows.
                Choisis le mode sans échec dans les options et valide avec entrée.

                Rend visible les fichiers cachés et systeme
                panneau de configuration > options des dossiers > onglet affichage
                Cocher " afficher les fichiers et dossiers cachés "
                Décocher " masquer les extentions des fichiers dont le type est connu
                Décocher " masquer les fichiers protégés du système"
                clic sur ok pour valider

                -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

                Dans le menu Demarrer>Executer >tape: Services.msc
                recherche les services avec cette orthographe exacte: (peut etre que certains ni seront pas, mais vaut mieux vérifier).

                Network DDE Client
                Remote Procedure Call (RPC) Client
                Smart Card Client
                Sound Sservice Driver


                Double clic dessus et clic sur [arreter] puis dans :
                type de demarrage --> sélectionne désactivé.

                Lance hijackthis et clic sur "do a system scan only"
                cocher la case au début des lignes suivantes:

                O4 - HKLM\..\Run: [Windows Network Firewall] C:\WINNT\System32\firewall.exe
                O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                O23 - Service: Network DDE Client (NetDDEclnt) - Unknown owner - C:\WINNT\system32\ppp.exe

                valider avec [fix checked]

                -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

                Ensuite, tres important:

                :: Supprimer les fichiers temporaires ::

                demarrer > executer et tape %temp% (ca va ouvrir directement le dossier qui contient les fichiers temporaires)
                supprime tout. (pas le dossier, mais ce qu'il contient)

                * C:\Windows\Temp
                vider tout le contenu du dossier en gras.

                * Ne pas oublier de vider la corbeille !

                -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

                1- Double-clic sur KillBox.exe
                2- ouvre le bloc note et copie la liste des fichiers à supprimer, en gras ci-dessous
                3- Selectionne "Delete on Reboot"
                4- Copie le chemin du 1er fichier de la liste en gras et colle dans "Full Path of File to Delete"
                5- clic sur la croix rouge
                6- une fenetre va apparaitre pour confirmation clic sur YES
                7- une seconde fenetre te demande si tu veux redemarrer clic sur NO

                Recommence à l'étape 3 pour chaques fichiers de la liste en gras.
                Une fois le dernier fichier selectionnées, a l'étape 7 clic sur YES

                Liste:

                C:\WINNT\System32\netddeclnt.exe
                C:\WINNT\System32\rpcclient.exe
                C:\WINNT\System32\SCardClnt.exe
                C:\WINNT\System32\cfmon.exe
                C:\WINNT\System32\firewall.exe
                C:\WINNT\System32\aaa.exe
                C:\WINNT\System32\bbb.exe
                C:\WINNT\System32\ccc.exe
                etc... jusqu'a
                C:\WINNT\System32\zzz.exe


                tous les fichier ne seront peut etre pas présent, si tu recois un message de killbox du style:
                PendingFileRenameOperations Registry... etc
                dans ce cas, passe au fichier suivant dans la liste

                le pc devrait redemarrer tout seul.
                une fois revenu en mode normal, reposte un hijack.

                a+
                0
                1. RE.J'ai fait tous ce que tu ma dit de faire et le seul probléme c'est que méme en supprimé netddeclnt.exe et en désactivant le service il revient, je le voit car mon parefeu Sygate me demande si je doit le bloquer ou pas et biensur je le bloque.Voila pour le reste ca a lair d'avoir marché, je te fait un autre hijack a la suite de celui ci-dessous.

                  Logfile of HijackThis v1.99.1
                  Scan saved at 21:10:33, on 21/06/2005
                  Platform: Windows 2000 (WinNT 5.00.2195)
                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                  Running processes:
                  C:\WINNT\System32\smss.exe
                  C:\WINNT\system32\winlogon.exe
                  C:\WINNT\system32\services.exe
                  C:\WINNT\system32\lsass.exe
                  C:\WINNT\System32\Ati2evxx.exe
                  C:\Program Files\Sygate\SPF\smc.exe
                  C:\WINNT\system32\svchost.exe
                  C:\WINNT\system32\spoolsv.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINNT\System32\svchost.exe
                  C:\WINNT\system32\hidserv.exe
                  C:\WINNT\system32\regsvc.exe
                  C:\WINNT\system32\MSTask.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  C:\WINNT\System32\WBEM\WinMgmt.exe
                  C:\WINNT\system32\Ati2evxx.exe
                  C:\WINNT\Explorer.exe
                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  C:\Program Files\Logitech\iTouch\iTouch.exe
                  C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINNT\loadqm.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\Documents and Settings\XXXXXX\Bureau\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O3 - Toolbar: @msdxmLC.dll,-1@1036,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
                  O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
                  O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
                  O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [LoadQM] loadqm.exe
                  O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
                  O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                  O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                  O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
                  O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
                  O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  0
                2. @F[@]BRegarde tous ce que je t'est écrit au dessus et voila un autre hijack.a+

                  Logfile of HijackThis v1.99.1
                  Scan saved at 21:20:39, on 21/06/2005
                  Platform: Windows 2000 (WinNT 5.00.2195)
                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                  Running processes:
                  C:\WINNT\System32\smss.exe
                  C:\WINNT\system32\winlogon.exe
                  C:\WINNT\system32\services.exe
                  C:\WINNT\system32\lsass.exe
                  C:\WINNT\System32\Ati2evxx.exe
                  C:\Program Files\Sygate\SPF\smc.exe
                  C:\WINNT\system32\spoolsv.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINNT\System32\svchost.exe
                  C:\WINNT\system32\hidserv.exe
                  C:\WINNT\system32\regsvc.exe
                  C:\WINNT\system32\MSTask.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  C:\WINNT\System32\WBEM\WinMgmt.exe
                  C:\WINNT\system32\Ati2evxx.exe
                  C:\WINNT\Explorer.exe
                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  C:\Program Files\Logitech\iTouch\iTouch.exe
                  C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINNT\loadqm.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\WINNT\System32\netddeclnt.exe
                  C:\Documents and Settings\XXXXXX\Bureau\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O3 - Toolbar: @msdxmLC.dll,-1@1036,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
                  O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
                  O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
                  O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [LoadQM] loadqm.exe
                  O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{D7FCDE8B-01F5-4007-8463-5D7FA7AA3EFD}: NameServer = 80.118.192.111 80.118.196.41
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
                  O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                  O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                  O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
                  O23 - Service: Network DDE Client (NetDDEclnt) - Unknown owner - C:\WINNT\System32\netddeclnt.exe
                  O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
                  O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  0
              4. salut

                reposte un hijack pour voir.

                apparement codbot ae est lié au fichier rpcclient.exe.

                a+
                0
                1. Voici mon hijack.Merci de m'aider moe31.

                  Logfile of HijackThis v1.99.1
                  Scan saved at 18:28:58, on 21/06/2005
                  Platform: Windows 2000 (WinNT 5.00.2195)
                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                  Running processes:
                  C:\WINNT\System32\smss.exe
                  C:\WINNT\system32\winlogon.exe
                  C:\WINNT\system32\services.exe
                  C:\WINNT\system32\lsass.exe
                  C:\WINNT\System32\Ati2evxx.exe
                  C:\Program Files\Sygate\SPF\smc.exe
                  C:\WINNT\system32\spoolsv.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINNT\System32\svchost.exe
                  C:\WINNT\system32\hidserv.exe
                  C:\WINNT\system32\jjj.exe
                  C:\WINNT\system32\regsvc.exe
                  C:\WINNT\system32\MSTask.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  C:\WINNT\System32\WBEM\WinMgmt.exe
                  C:\WINNT\system32\Ati2evxx.exe
                  C:\WINNT\Explorer.exe
                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  C:\Program Files\Logitech\iTouch\iTouch.exe
                  C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINNT\loadqm.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Documents and Settings\XXXXXX\Bureau\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O3 - Toolbar: @msdxmLC.dll,-1@1036,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
                  O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
                  O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
                  O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [LoadQM] loadqm.exe
                  O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
                  O4 - HKLM\..\Run: [Windows Network Firewall] C:\WINNT\System32\firewall.exe
                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                  O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                  O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{D7FCDE8B-01F5-4007-8463-5D7FA7AA3EFD}: NameServer = 80.118.192.112 80.118.196.42
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
                  O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                  O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                  O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
                  O23 - Service: Network DDE Client (NetDDEclnt) - Unknown owner - C:\WINNT\system32\ppp.exe
                  O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
                  O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  0
              5. salut

                fais analyser un de ces fichiers ici:
                http://virusscan.jotti.org/
                et poste le rapport

                a+
                0
                1. Salut moe31, j'ai fait scanner le fichier sss.exe sur le site que tu ma donner et voila ce que ca donne:

                  File: sss.exe
                  Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
                  MD5 3fb46c9a10aa4d7ca7f32cb06b16bd35
                  Packers detected:
                  PE-CRYPT.ANTIDEB

                  Scanner results
                  -AntiVir
                  Found Worm/Codbot.AE
                  -ArcaVir
                  Found Trojan.Codbot.Ae
                  -Avast
                  Found nothing
                  -AVG Antivirus
                  Found BackDoor.Generic.EEV
                  -BitDefender
                  Found nothing
                  -ClamAV
                  Found nothing
                  -Dr.Web
                  Found BackDoor.CodBot
                  -F-Prot Antivirus
                  Found nothing
                  -Fortinet
                  Found W32/Codbot.AE-bdr
                  -Kaspersky Anti-Virus
                  Found Backdoor.Win32.Codbot.ae
                  -NOD32
                  Found Win32/Codbot
                  -Norman Virus Control
                  Found nothing
                  -VBA32
                  Found Backdoor.Win32.Codbot.ae

                  Ce n'est pas la peine que j'essay de le supprimé avec un de ces antivirus je les est deja tous essayer et a chaque fois ca me le supprime mais il revient de toute facon.
                  0
              6. il est toujours là (netddeclnt.exe )

                il faut, en mode sans echecs

                arreter le service qu'il à crée:
                Dans le menu Demarrer>Executer >tape: Services.msc
                recherche le service avec cette orthographe exacte:
                Network DDE Client
                Double clic dessus et clic sur [arreter] puis dans :
                type de demarrage --> sélectionne désactivé

                puis supprimer le fichier C:\WINNT\System32\netddeclnt.exe

                et supprimer le service:
                lance hijackthis
                clic sur "open the misc tool section"
                clic sur "delete an NT service"

                tape: NetDDEclnt et valide

                nettoyage des fichiers temporaires avec cleanup
                ou alors tu vide le contenu de:
                c:\winnt\temp
                et dans demarrer > executer tape %temp%
                et tu supprime tout ce qui apparait.

                redemarre le pc et va faire plusieurs scans av en ligne (je sais, c'est long mais bon...).

                http://housecall.trendmicro.com
                http://www.bitdefender.com/scan/licence.php
                http://www.pandasoftware.com/activescan/fr/activescan_principal.htm
                http://www.ravantivirus.com

                si tu peux, fais les tous et n'oublie pas de noter le nom et le chemin des fichiers qui seront trouvés.

                a+
                0
                1. Ca y est j'ai fait tous ce que tu ma dit de faire.J'ai scanner le pc en ligne avec tes liens et je n'avais rien d'autres comme virus.J'ai installer un parefeu (Sygate) et de temps en temps il y a toujours les trojans qu'il veulent se lancer alors que j'ai tous supprimé,je les bloques avec le parefeu (eee.exe ,mmm.exe ,rrr.exe ....) et en plus il ne sont pas considéré comme des trojans par plusieurs antivirus comme trojanshunter,AVG (ca dépend des fois),Avast (ca dépend des fois aussi) donc je ne c'est toujours pas comment supprimé définitivement ces trojans trés envahissent.
                  A mon avis c'est quelque chose qui a étais rajouté dans la base de registre mais je ne sais pas quoi.
                  0
              7. salut fab

                Déconnecte toi d'internet:

                Vide le cache d'Internet Explorer et supprime les cookies:

                * Panneau de configuration >> Options internet >> Onglet "Général"
                - Clic sur [supprimer les cookies]
                - Clic sur [Supprimer les fichiers] et coche la case "Supprimer tout le contenu hors connexion"
                Valide avec ok

                Redémarre en mode sans échec
                Laisse passer l'écran du bios, puis tapote sur la touche F8 avant qu'apparaisse l'écran de chargement de windows.
                Choisis le mode sans échec dans les options et valide avec entrée.

                Rend visible les fichiers cachés et systeme
                panneau de configuration > options des dossiers > onglet affichage
                Cocher " afficher les fichiers et dossiers cachés "
                Décocher " masquer les extentions des fichiers dont le type est connu
                Décocher " masquer les fichiers protégés du système"
                clic sur ok pour valider

                -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

                Dans le menu Demarrer>Executer >tape: Services.msc
                recherche le service avec cette orthographe exacte:
                Network DDE Client
                Remote Procedure Call (RPC) Client
                Smart Card Client
                Sound Sservice Driver
                Double clic dessus et clic sur [arreter] puis dans :
                type de demarrage --> sélectionne désactivé.

                -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

                recherche et supprime si présent:

                C:\WINNT\System32\netddeclnt.exe
                C:\WINNT\System32\rpcclient.exe
                C:\WINNT\System32\SCardClnt.exe
                C:\WINNT\System32\cfmon.exe
                + tous les fichiers aaa.exe, bbb.exe etc...
                Supprime tous les fichiers temporaires avec ce prog:
                http://pageperso.aol.fr/Balltrap34/CleanUp312.exe
                la demo ici:
                http://pageperso.aol.fr/balltrap34/democleanup.htm

                Ensuite lance hijackthis
                clic sur "open the misc tool section"
                clic sur "delete an NT service"

                tape: RpcClient ou si tu as un message d'erreur Remote Procedure Call (RPC) Client et valide
                fais pareil avec:

                SCardClnt ou Smart Card Client

                Sound Service ou Sound Sservice Driver

                redemarre le pc, reposte un hijack et dis nous ou en sont tes soucis.

                a+
                0
                1. RE moe31, j'ai suivi a la lettre tous ce que tu ma dit de faire et il me reste un fichier kkk.exe qui se trouve sur mon bureau et que je n'arrive pas a supprimé méme en mode sans échec il me dit qu'il est en cours d'ulilisation et quand je fait ctrl+alt+suppr il n'est pas dans les processus en cour.Je ne c'est pas comment le supprimé.

                  Logfile of HijackThis v1.99.1
                  Scan saved at 20:42:09, on 20/06/2005
                  Platform: Windows 2000 (WinNT 5.00.2195)
                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                  Running processes:
                  C:\WINNT\System32\smss.exe
                  C:\WINNT\system32\csrss.exe
                  C:\WINNT\system32\winlogon.exe
                  C:\WINNT\system32\services.exe
                  C:\WINNT\system32\lsass.exe
                  C:\WINNT\System32\Ati2evxx.exe
                  C:\WINNT\system32\svchost.exe
                  C:\WINNT\system32\spoolsv.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINNT\System32\svchost.exe
                  C:\WINNT\system32\hidserv.exe
                  C:\WINNT\system32\regsvc.exe
                  C:\WINNT\system32\MSTask.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  C:\WINNT\System32\WBEM\WinMgmt.exe
                  C:\WINNT\system32\Ati2evxx.exe
                  C:\WINNT\Explorer.exe
                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  C:\Program Files\Logitech\iTouch\iTouch.exe
                  C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINNT\loadqm.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Documents and Settings\XXXXXX\Bureau\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neuf.fr
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O3 - Toolbar: @msdxmLC.dll,-1@1036,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
                  O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
                  O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
                  O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [LoadQM] loadqm.exe
                  O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                  O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                  O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{D7FCDE8B-01F5-4007-8463-5D7FA7AA3EFD}: NameServer = 80.118.196.40 80.118.192.110
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
                  O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                  O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                  O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
                  O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

                  Merci beaucoup pour ton aide moe31.
                  0
                2. @F[@]BCa y est je viens de réussir a supprimé kkk.exe ne me demande pas comment c'est un miracle ^^.
                  J'aimerais savoir si je n'est pas d'autres virus ou trojans aparent dans mon hijack merci de me répondre.

                  Logfile of HijackThis v1.99.1
                  Scan saved at 20:56:41, on 20/06/2005
                  Platform: Windows 2000 (WinNT 5.00.2195)
                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                  Running processes:
                  C:\WINNT\System32\smss.exe
                  C:\WINNT\system32\csrss.exe
                  C:\WINNT\system32\winlogon.exe
                  C:\WINNT\system32\services.exe
                  C:\WINNT\system32\lsass.exe
                  C:\WINNT\System32\Ati2evxx.exe
                  C:\WINNT\system32\spoolsv.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINNT\System32\svchost.exe
                  C:\WINNT\system32\hidserv.exe
                  C:\WINNT\system32\regsvc.exe
                  C:\WINNT\system32\MSTask.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  C:\WINNT\System32\WBEM\WinMgmt.exe
                  C:\WINNT\system32\Ati2evxx.exe
                  C:\WINNT\Explorer.exe
                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  C:\Program Files\Logitech\iTouch\iTouch.exe
                  C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINNT\loadqm.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINNT\System32\netddeclnt.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Documents and Settings\XXXXXX\Bureau\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neuf.fr
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O3 - Toolbar: @msdxmLC.dll,-1@1036,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
                  O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
                  O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
                  O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [LoadQM] loadqm.exe
                  O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                  O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                  O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{D7FCDE8B-01F5-4007-8463-5D7FA7AA3EFD}: NameServer = 80.118.196.40 80.118.192.110
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
                  O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                  O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                  O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
                  O23 - Service: Network DDE Client (NetDDEclnt) - Unknown owner - C:\WINNT\System32\netddeclnt.exe
                  O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  0
              8. salut

                reposte un hijack pour voir

                a+
                0
                1. Logfile of HijackThis v1.99.1
                  Scan saved at 09:41:04, on 20/06/2005
                  Platform: Windows 2000 (WinNT 5.00.2195)
                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                  Running processes:
                  C:\WINNT\System32\smss.exe
                  C:\WINNT\system32\csrss.exe
                  C:\WINNT\system32\winlogon.exe
                  C:\WINNT\system32\services.exe
                  C:\WINNT\system32\lsass.exe
                  C:\WINNT\System32\Ati2evxx.exe
                  C:\WINNT\system32\svchost.exe
                  C:\WINNT\system32\spoolsv.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINNT\System32\svchost.exe
                  C:\WINNT\system32\hidserv.exe
                  C:\WINNT\System32\netddeclnt.exe
                  C:\WINNT\system32\regsvc.exe
                  C:\WINNT\system32\MSTask.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  C:\WINNT\System32\WBEM\WinMgmt.exe
                  C:\WINNT\system32\Ati2evxx.exe
                  C:\WINNT\Explorer.exe
                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  C:\Program Files\Logitech\iTouch\iTouch.exe
                  C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINNT\loadqm.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINNT\System32\MsiExec.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Documents and Settings\XXXXXX\Bureau\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neuf.fr
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O3 - Toolbar: @msdxmLC.dll,-1@1036,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
                  O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
                  O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
                  O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                  O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [LoadQM] loadqm.exe
                  O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                  O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                  O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{D7FCDE8B-01F5-4007-8463-5D7FA7AA3EFD}: NameServer = 80.118.192.110 80.118.196.40
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
                  O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                  O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                  O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
                  O23 - Service: Network DDE Client (NetDDEclnt) - Unknown owner - C:\WINNT\System32\netddeclnt.exe
                  O23 - Service: Remote Procedure Call (RPC) Client (RpcClient) - Unknown owner - C:\WINNT\System32\rpcclient.exe (file missing)
                  O23 - Service: Smart Card Client (SCardClnt) - Unknown owner - C:\WINNT\System32\SCardClnt.exe (file missing)
                  O23 - Service: Sound Sservice Driver (Sound Service) - Unknown owner - C:\WINNT\System32\cfmon.exe (file missing)
                  O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  0
              9. salut
                installes un antitrojan
                a2free là
                http://www.emsisoft.com/en/
                ou celui-là
                http://www.ewido.net/en/?section=features (payant après 30j)
                ou scanTrojan en ligne : http://www.windowsecurity.com/trojanscan/
                ou TDS-3 là http://tds.diamondcs.com.au/ (payant )
                ou TrojanHunter 4.1
                http://www.misec.net/trojanhunter/ (payant après 30j)
                ou The Cleaner (payant après 30j)
                http://www.moosoft.com/products/cleaner/download/
                a+
                0
                1. J'ai essayer tous les site que tu m'a donner et aucun ne ma enlever les trojans dont je parle.J'ai juste apris que c'étaient des backdoor Codbot.ae mais je ne sais toujours pas comment les enlever définitivement.
                  (aaa,bbb,ccc,ddd,eee,fff,ggg,hhh,iii,jjj,kkk,lll,mmm,nnn,ooo,ppp,qqq,rrr,sss,
                  ttt,uuu,vvv,www,xxx,yyy,zzz.exe)
                  0
              10. Logfile of HijackThis v1.99.1
                Scan saved at 17:49:42, on 19/06/2005
                Platform: Windows 2000 (WinNT 5.00.2195)
                MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                Running processes:
                C:\WINNT\System32\smss.exe
                C:\WINNT\system32\winlogon.exe
                C:\WINNT\system32\services.exe
                C:\WINNT\system32\lsass.exe
                C:\WINNT\System32\Ati2evxx.exe
                C:\WINNT\system32\spoolsv.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
                C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
                C:\WINNT\System32\svchost.exe
                C:\WINNT\system32\hidserv.exe
                C:\WINNT\system32\nnn.exe
                C:\WINNT\system32\regsvc.exe
                C:\WINNT\system32\MSTask.exe
                C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                C:\WINNT\System32\WBEM\WinMgmt.exe
                C:\WINNT\system32\Ati2evxx.exe
                C:\WINNT\Explorer.exe
                C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                C:\Program Files\Logitech\iTouch\iTouch.exe
                C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
                C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\WINNT\loadqm.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\WINNT\system32\drwtsn32.exe
                C:\Documents and Settings\XXXXXX\Bureau\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neuf.fr
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O3 - Toolbar: @msdxmLC.dll,-1@1036,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
                O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
                O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
                O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
                O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
                O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [LoadQM] loadqm.exe
                O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                O17 - HKLM\System\CCS\Services\Tcpip\..\{D7FCDE8B-01F5-4007-8463-5D7FA7AA3EFD}: NameServer = 80.118.196.36 80.118.192.100
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
                O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
                O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
                O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
                O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
                O23 - Service: Network DDE Client (NetDDEclnt) - Unknown owner - C:\WINNT\system32\nnn.exe
                O23 - Service: Remote Procedure Call (RPC) Client (RpcClient) - Unknown owner - C:\WINNT\System32\rpcclient.exe (file missing)
                O23 - Service: Smart Card Client (SCardClnt) - Unknown owner - C:\WINNT\System32\SCardClnt.exe (file missing)
                O23 - Service: Sound Sservice Driver (Sound Service) - Unknown owner - C:\WINNT\System32\cfmon.exe (file missing)
                O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                0