hello me revoila bien dormi ???
moi vi. tt ses kaka dans cette machine ne m'on pas emmpecher de dormir ...
bon voila le rapport de antivir et derriere il y a le hijackthis
tt a etais fait comme l'indique la procedure de ô gd Mr tesgaz....
okk voili voila .......
Creation date of the report file: samedi 9 juillet 2005 01:55
AntiVir®/XP (2000 + NT) PersonalEdition Classic
Build 1047 vom 07.06.2005
Mainprogram 6.31.00.03 of 10.05.2005
VDF file 6.31.0.177 (0) of 08.07.2005
This program is for PERSONAL USE only.
Any other use is PROHIBITED.
Informations regarding commercial versions of AntiVir may be obtained from:
www.hbedv.com.
Scanning for 191598 virus strains and unwanted programs.
Licensed for: AntiVir Personal Edition
Serial number: 0000149996-WURGE-0001
Please enter the workstation and
contact name with phone number in this form:
Name ___________________________________________
Street ___________________________________________
Town ___________________________________________
Phone/Fax ___________________________________________
Email ___________________________________________
Platform: Windows NT Workstation
Windows version: 5.1 Build 2600 ()
Username: Jacques
Processor: Pentium
Working memory: 196080 KB free
Version information:
AVWIN.DLL : 6.31.00.03 561192 10.05.2005 16:50:16
AVEWIN32.DLL : 6.31.0.9 823808 09.07.2005 01:43:36
AVGNT.EXE : 6.31.00.01 168039 10.05.2005 16:50:16
AVGUARD.EXE : 6.31.00.01 238120 29.04.2005 08:07:12
GUARDMSG.DLL : 6.30.00.02 94248 01.02.2005 11:24:10
AVGCMSG.DLL : 6.31.00.00 295029 29.04.2005 08:07:16
AVGNTDW.SYS : 6.31.00.01 32896 29.04.2005 08:07:16
AVPACK32.DLL : 6.31.00.03 323664 25.05.2005 10:43:02
AVGETVER.DLL : 6.30.00.00 24576 28.01.2005 18:10:20
AVWIN.DLL : 6.31.00.03 561192 10.05.2005 16:50:16
AVSHLEXT.DLL : 6.30.00.01 40960 28.01.2005 18:10:22
AVSched32.EXE : 6.30.00.00 110632 01.02.2005 11:24:10
AVSched32.DLL : 6.30.00.00 122880 01.02.2005 11:24:10
AVREG.DLL : 6.30.00.03 41000 10.02.2005 18:47:48
AVRep.DLL : 6.31.00.172 1212456 09.07.2005 01:44:06
INETUPD.EXE : 6.31.00.02 249915 29.04.2005 08:07:14
INETUPD.DLL : 6.31.00.02 143360 29.04.2005 08:07:14
CTL3D32.DLL : 2.31.000 27136 28.08.2001 14:00:00
MFC42.DLL : 6.00.8665.0 995383 28.08.2001 14:00:00
MSVCRT.DLL : 7.0.2600.0 (xpclient.010817-1148
MSVCRT.DLL : 7.0.2600.0 (xp 322560 28.08.2001 14:00:00
CTL3DV2.DLL : No information
Configuration file:
Name of configuration file: C:\Program Files\AVPersonal\AVWIN.INI
Name of report file: C:\Program Files\AVPersonal\LOGFILES\AVWIN.LOG
Start path: C:\Program Files\AVPersonal
Command line:
Start mode: unknown
Mode of report file:
[ ] Do not create report
[X] Overwrite report
[ ] Append new report
Data in report file:
[X] Infected files
[ ] Infected files with paths
[ ] All scanned files
[ ] Full information
Abridge report file:
[ ] Abridge report file
Warnings in report:
[X] Access denied/file locked
[X] Wrong file size in directory
[X] Wrong creation time in directory
[ ] COM file is too large
[X] Invalid start address
[X] Invalid EXE header
[X] Possibly damaged
Summary report:
[X] Create summary report
Output file: AVWIN.ACT
Maximum number of entries: 100
Where to search:
[X] Memory
[X] Boot record of selected drives
[ ] Report unknown boot sectors
[X] All files
[ ] Program files
Response in case of a detection:
[X] Repair with prompt
[ ] Repair without prompt
[ ] Delete with prompt
[ ] Delete without prompt
[ ] Write in report file only
[X] Acoustic alarm
Response in case of destroyed files:
[X] Delete with prompt
[ ] Delete without prompt
[ ] Ignore
Response in case of destroyed files:
[X] No change
[ ] Current system time
[ ] Correct date
Drag&drop settings:
[X] Scan subdirectories
Profile settings:
[X] Scan subdirectories
Archive options
[X] Search archive
[X] Archive types to leave out
1002 1001 1000
Miscellaneous options:
Temporary path: %TEMP% -> C:\Program Files\AVPersonal\BUILD.DAT
[X] Overwrite infected files
[ ] Detect idle time
[X] Allow interruptions of scan
[ ] Load AVWin®/NT Guard on System start
General settings:
[X] Save options on exiting AntiVir
Priority: medium
Drives:
A: Floppy drive
C: Hard disk
D: CD-ROM
Start of scan: samedi 9 juillet 2005 01:55
Memory test OK
Master boot record of hard disk HD0 OK
Boot record of drive A:
The record could not be read!
Error code: 0x0015
Boot record of drive C: OK
C:\
pagefile.sys
Access denied! Error during file opening!
This is a Windows swap file. This file is locked by Windows.
Error code: 0x000D
WARNING! Access error/file locked!
C:\Documents and Settings\Jacques
NTUSER.DAT
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
ntuser.dat.LOG
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
C:\Documents and Settings\Jacques\Local Settings\Application Data\Microsoft\Windows
UsrClass.dat
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
UsrClass.dat.LOG
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
C:\Documents and Settings\Jacques\Local Settings\Temp
se.dll
[DETECTION] Is the Trojan horse TR/StartPage.qr.DLL
WAS DELETED!
C:\Documents and Settings\Jacques\Local Settings\Temporary Internet Files\Content.IE5\Y74R38XW
netia32_EN_XP[1].cab
ArchiveType: CAB (Microsoft)
--> netia32.dll
[DETECTION] Is the Trojan horse TR/Trilon.A.2
--> netia32.inf
[DETECTION] Is the Trojan horse TR/Trilon.B.2
C:\Program Files\AVPersonal\INFECTED
ewmdmc.VIR
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
C:\Program Files\Fichiers communs\InstallShield\engine\6\Intel 32
ILog.dll
Access denied! Error during file opening!
Error code: 0x0002
WARNING! Access error/file locked!
C:\Program Files\WinRAR
rarnew.dat
ArchiveType: RAR
NOTE! The archive is created by multiple volumes
C:\RECYCLER\NPROTECT
00008212.exe
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
00008217.DLL
[DETECTION] Is the Trojan horse TR/StartPage.qr.DLL
WAS DELETED!
C:\SOFTZONE
SBDIALOG.DLL
Access denied! Error during file opening!
Error code: 0x0002
WARNING! Access error/file locked!
Error! Could not change directory: System Volume Information
C:\WINDOWS
actulice.exe
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
C:\WINDOWS\system32
asphoner.exe
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
dpclipr.exe
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
e4uiniti.exe
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
EGDHTML_1026.dll
[DETECTION] Contains signature of the dial-up program DIAL/302132
WAS DELETED!
esetupi.exe
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
eventlog.dll
Access denied! Error during file opening!
Error code: 0x0002
WARNING! Access error/file locked!
fc_oss.exe
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
frgresd.exe
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
msdtclog.dll
Access denied! Error during file opening!
Error code: 0x0002
WARNING! Access error/file locked!
nscardwi.exe
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
pxwani.exe
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
ratelcms.exe
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
seru.exe
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
svidc32m.exe
[DETECTION] Is the Trojan horse TR/Revop.B.1
WAS DELETED!
txflog.dll
Access denied! Error during file opening!
Error code: 0x0002
WARNING! Access error/file locked!
wmdmlog.dll
Access denied! Error during file opening!
Error code: 0x0002
WARNING! Access error/file locked!
C:\WINDOWS\system32\config
default
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
default.LOG
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
SAM
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
SAM.LOG
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
SECURITY
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
SECURITY.LOG
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
software
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
software.LOG
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
system
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
system.LOG
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
C:\WINDOWS\system32\dllcache
eventlog.dll
Access denied! Error during file opening!
Error code: 0x0002
WARNING! Access error/file locked!
msdtclog.dll
Access denied! Error during file opening!
Error code: 0x0002
WARNING! Access error/file locked!
txflog.dll
Access denied! Error during file opening!
Error code: 0x0002
WARNING! Access error/file locked!
wmdmlog.dll
Access denied! Error during file opening!
Error code: 0x0002
WARNING! Access error/file locked!
End of scan: samedi 9 juillet 2005 08:41
Time taken: 405:21 min
1397 directories were scanned
37508 files were scanned
25 warning messages were issued
17 files were deleted
0 files were repaired
19 detections
Logfile of HijackThis v1.99.1
Scan saved at 09:55:15, on 09/07/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\hijackthis\hijackthis + patch fr + inst zeb\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://1-se.com/srchasst.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Jacques\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Jacques\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {00110011-4B0B-44D5-9718-90C88817369B} - C:\WINDOWS\sys_ext.dll (file missing)
O2 - BHO: (no name) - {021BB032-80A8-4FB6-B3D5-CF27B1553B95} - C:\WINDOWS\mslagent\4b_1,0,1,0_mslagent.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {95B311DD-5759-42C1-A69C-F3E1814AAD7E} - C:\WINDOWS\System32\eoaj.dll (file missing)
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [siS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [siSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [Windows Shell Library Loader] load shell.dll /c /set
O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [urlLSTCK.exe] C:\Program Files\Norton Internet Security Professional\UrlLstCk.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\Olitec\USB ADSL\CnxDslTb.exe
O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [sSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\se.dll,DllInstall
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [WrCtrl] "C:\Program Files\WinRoute Pro\wrctrl.exe"
O4 - HKCU\..\Run: [instant Access] rundll32.exe EGDHTML_1026.dll,InstantAccess
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{80C42E2D-74E4-4E42-901C-E2DFA860C93A}: NameServer = 80.118.196.36 80.118.192.100
O18 - Filter: text/html - {B0B657CB-F273-4AB6-80AE-A255EAF3521B} - C:\WINDOWS\System32\eoaj.dll
O18 - Filter: text/plain - {B0B657CB-F273-4AB6-80AE-A255EAF3521B} - C:\WINDOWS\System32\eoaj.dll
O19 - User stylesheet: C:\WINDOWS\sample.txt
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe
donc voila .......
qui , qui me dit quoi je doit faire ?
merci merci