hello me revoila   bien dormi ??? 
moi vi. tt ses kaka dans cette machine ne m'on pas emmpecher de dormir ... 
bon voila le rapport de antivir et derriere il y a le hijackthis 
tt a etais fait comme l'indique la procedure de ô gd Mr tesgaz.... 
  
okk voili voila ....... 
  
  
Creation date of the report file:  samedi 9 juillet 2005  01:55 
  
AntiVir®/XP (2000 + NT) PersonalEdition Classic 
Build 1047 vom 07.06.2005 
Mainprogram 6.31.00.03 of 10.05.2005 
VDF file 6.31.0.177 (0) of 08.07.2005 
  
  
This program is for PERSONAL USE only. 
Any other use is PROHIBITED. 
Informations regarding commercial versions of AntiVir may be obtained from: 
www.hbedv.com. 
  
  
Scanning for 191598 virus strains and unwanted programs. 
  
Licensed for:  AntiVir Personal Edition 
Serial number: 0000149996-WURGE-0001 
  
Please enter the workstation and 
contact name with phone number in this form: 
  
Name        ___________________________________________ 
  
Street      ___________________________________________ 
  
Town        ___________________________________________ 
  
Phone/Fax   ___________________________________________ 
  
Email       ___________________________________________ 
  
Platform:        Windows NT Workstation 
Windows version: 5.1 Build 2600 () 
Username:        Jacques 
Processor:       Pentium 
Working memory:  196080 KB free 
  
Version information: 
 AVWIN.DLL      : 6.31.00.03     561192  10.05.2005  16:50:16 
 AVEWIN32.DLL   : 6.31.0.9       823808  09.07.2005  01:43:36 
 AVGNT.EXE      : 6.31.00.01     168039  10.05.2005  16:50:16 
 AVGUARD.EXE    : 6.31.00.01     238120  29.04.2005  08:07:12 
 GUARDMSG.DLL   : 6.30.00.02      94248  01.02.2005  11:24:10 
 AVGCMSG.DLL    : 6.31.00.00     295029  29.04.2005  08:07:16 
 AVGNTDW.SYS    : 6.31.00.01      32896  29.04.2005  08:07:16 
 AVPACK32.DLL   : 6.31.00.03     323664  25.05.2005  10:43:02 
 AVGETVER.DLL   : 6.30.00.00      24576  28.01.2005  18:10:20 
 AVWIN.DLL      : 6.31.00.03     561192  10.05.2005  16:50:16 
 AVSHLEXT.DLL   : 6.30.00.01      40960  28.01.2005  18:10:22 
 AVSched32.EXE  : 6.30.00.00     110632  01.02.2005  11:24:10 
 AVSched32.DLL  : 6.30.00.00     122880  01.02.2005  11:24:10 
 AVREG.DLL      : 6.30.00.03      41000  10.02.2005  18:47:48 
 AVRep.DLL      : 6.31.00.172    1212456  09.07.2005  01:44:06 
 INETUPD.EXE    : 6.31.00.02     249915  29.04.2005  08:07:14 
 INETUPD.DLL    : 6.31.00.02     143360  29.04.2005  08:07:14 
 CTL3D32.DLL    : 2.31.000        27136  28.08.2001  14:00:00 
 MFC42.DLL      : 6.00.8665.0     995383  28.08.2001  14:00:00 
 MSVCRT.DLL     : 7.0.2600.0 (xpclient.010817-1148 
 MSVCRT.DLL     : 7.0.2600.0 (xp     322560  28.08.2001  14:00:00 
 CTL3DV2.DLL    : No information 
  
Configuration file: 
  
 Name of configuration file: C:\Program Files\AVPersonal\AVWIN.INI 
 Name of report file:        C:\Program Files\AVPersonal\LOGFILES\AVWIN.LOG 
 Start path:                 C:\Program Files\AVPersonal 
 Command line:                
 Start mode:                  unknown 
  
 Mode of report file: 
 [ ] Do not create report 
 [X] Overwrite report 
 [ ] Append new report 
  
 Data in report file: 
 [X] Infected files 
 [ ] Infected files with paths 
 [ ] All scanned files 
 [ ] Full information 
  
 Abridge report file: 
 [ ] Abridge report file 
  
 Warnings in report: 
 [X] Access denied/file locked 
 [X] Wrong file size in directory 
 [X] Wrong creation time in directory 
 [ ] COM file is too large 
 [X] Invalid start address 
 [X] Invalid EXE header 
 [X] Possibly damaged 
  
 Summary report: 
 [X] Create summary report 
     Output file: AVWIN.ACT 
     Maximum number of entries: 100 
  
 Where to search: 
 [X] Memory 
 [X] Boot record of selected drives 
 [ ] Report unknown boot sectors 
 [X] All files 
 [ ] Program files 
  
 Response in case of a detection: 
 [X] Repair with prompt 
 [ ] Repair without prompt 
 [ ] Delete with prompt 
 [ ] Delete without prompt 
 [ ] Write in report file only 
 [X] Acoustic alarm 
  
 Response in case of destroyed files: 
 [X] Delete with prompt 
 [ ] Delete without prompt 
 [ ] Ignore 
  
 Response in case of destroyed files: 
 [X] No change 
 [ ] Current system time 
 [ ] Correct date 
  
 Drag&drop settings: 
 [X] Scan subdirectories 
  
 Profile settings: 
 [X] Scan subdirectories 
  
 Archive options 
 [X] Search archive 
 [X] Archive types to leave out 
     1002 1001 1000  
  
 Miscellaneous options: 
 Temporary path: %TEMP% -> C:\Program Files\AVPersonal\BUILD.DAT 
 [X] Overwrite infected files 
 [ ] Detect idle time 
 [X] Allow interruptions of scan 
 [ ] Load AVWin®/NT Guard on System start 
  
 General settings: 
 [X] Save options on exiting AntiVir 
 Priority: medium 
  
 Drives: 
 A: Floppy drive 
 C: Hard disk 
 D: CD-ROM 
  
Start of scan:  samedi 9 juillet 2005  01:55 
  
Memory test                          OK 
Master boot record of hard disk HD0   OK 
Boot record of drive A:             
      The record could not be read! 
      Error code: 0x0015 
Boot record of drive C:            OK 
  
  
C:\ 
  pagefile.sys 
      Access denied! Error during file opening! 
      This is a Windows swap file. This file is locked by Windows. 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
C:\Documents and Settings\Jacques 
  NTUSER.DAT 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
  ntuser.dat.LOG 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
C:\Documents and Settings\Jacques\Local Settings\Application Data\Microsoft\Windows 
  UsrClass.dat 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
  UsrClass.dat.LOG 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
C:\Documents and Settings\Jacques\Local Settings\Temp 
  se.dll 
      [DETECTION] Is the Trojan horse TR/StartPage.qr.DLL 
      WAS DELETED! 
C:\Documents and Settings\Jacques\Local Settings\Temporary Internet Files\Content.IE5\Y74R38XW 
  netia32_EN_XP[1].cab 
  ArchiveType: CAB (Microsoft) 
    --> netia32.dll 
        [DETECTION] Is the Trojan horse TR/Trilon.A.2 
    --> netia32.inf 
        [DETECTION] Is the Trojan horse TR/Trilon.B.2 
C:\Program Files\AVPersonal\INFECTED 
  ewmdmc.VIR 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
C:\Program Files\Fichiers communs\InstallShield\engine\6\Intel 32 
  ILog.dll 
      Access denied! Error during file opening! 
      Error code: 0x0002 
      WARNING! Access error/file locked! 
C:\Program Files\WinRAR 
  rarnew.dat 
  ArchiveType: RAR 
      NOTE! The archive is created by multiple volumes 
C:\RECYCLER\NPROTECT 
  00008212.exe 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
  00008217.DLL 
      [DETECTION] Is the Trojan horse TR/StartPage.qr.DLL 
      WAS DELETED! 
C:\SOFTZONE 
  SBDIALOG.DLL 
      Access denied! Error during file opening! 
      Error code: 0x0002 
      WARNING! Access error/file locked! 
Error! Could not change directory: System Volume Information 
C:\WINDOWS 
  actulice.exe 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
C:\WINDOWS\system32 
  asphoner.exe 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
  dpclipr.exe 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
  e4uiniti.exe 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
  EGDHTML_1026.dll 
      [DETECTION] Contains signature of the dial-up program DIAL/302132 
      WAS DELETED! 
  esetupi.exe 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
  eventlog.dll 
      Access denied! Error during file opening! 
      Error code: 0x0002 
      WARNING! Access error/file locked! 
  fc_oss.exe 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
  frgresd.exe 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
  msdtclog.dll 
      Access denied! Error during file opening! 
      Error code: 0x0002 
      WARNING! Access error/file locked! 
  nscardwi.exe 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
  pxwani.exe 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
  ratelcms.exe 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
  seru.exe 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
  svidc32m.exe 
      [DETECTION] Is the Trojan horse TR/Revop.B.1 
      WAS DELETED! 
  txflog.dll 
      Access denied! Error during file opening! 
      Error code: 0x0002 
      WARNING! Access error/file locked! 
  wmdmlog.dll 
      Access denied! Error during file opening! 
      Error code: 0x0002 
      WARNING! Access error/file locked! 
C:\WINDOWS\system32\config 
  default 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
  default.LOG 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
  SAM 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
  SAM.LOG 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
  SECURITY 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
  SECURITY.LOG 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
  software 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
  software.LOG 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
  system 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
  system.LOG 
      Access denied! Error during file opening! 
      Error code: 0x000D 
      WARNING! Access error/file locked! 
C:\WINDOWS\system32\dllcache 
  eventlog.dll 
      Access denied! Error during file opening! 
      Error code: 0x0002 
      WARNING! Access error/file locked! 
  msdtclog.dll 
      Access denied! Error during file opening! 
      Error code: 0x0002 
      WARNING! Access error/file locked! 
  txflog.dll 
      Access denied! Error during file opening! 
      Error code: 0x0002 
      WARNING! Access error/file locked! 
  wmdmlog.dll 
      Access denied! Error during file opening! 
      Error code: 0x0002 
      WARNING! Access error/file locked! 
  
  
  
End of scan:  samedi 9 juillet 2005  08:41 
Time taken:         405:21 min 
  
  
1397 directories were scanned 
37508 files were scanned 
  25 warning messages were issued 
  17 files were deleted 
   0 files were repaired 
  19 detections 
  
                                    
  
  
Logfile of HijackThis v1.99.1 
Scan saved at 09:55:15, on 09/07/2005 
Platform: Windows XP  (WinNT 5.01.2600) 
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000) 
  
Running processes: 
C:\WINDOWS\System32\smss.exe 
C:\WINDOWS\system32\winlogon.exe 
C:\WINDOWS\system32\services.exe 
C:\WINDOWS\system32\lsass.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\Explorer.EXE 
C:\Program Files\hijackthis\hijackthis + patch fr + inst zeb\HijackThis.exe 
  
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://1-se.com/srchasst.html (obfuscated) 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Jacques\LOCALS~1\Temp\se.dll/sp.html 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Jacques\LOCALS~1\Temp\se.dll/sp.html 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank 
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens 
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) 
O2 - BHO: (no name) - {00110011-4B0B-44D5-9718-90C88817369B} - C:\WINDOWS\sys_ext.dll (file missing) 
O2 - BHO: (no name) - {021BB032-80A8-4FB6-B3D5-CF27B1553B95} - C:\WINDOWS\mslagent\4b_1,0,1,0_mslagent.dll (file missing) 
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll 
O2 - BHO: (no name) - {95B311DD-5759-42C1-A69C-F3E1814AAD7E} - C:\WINDOWS\System32\eoaj.dll (file missing) 
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll 
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\NavShExt.dll 
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll 
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\NavShExt.dll 
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx 
O4 - HKLM\..\Run: [siS Tray] C:\WINDOWS\System32\sistray.EXE 
O4 - HKLM\..\Run: [siSUSBRG] C:\WINDOWS\sisUSBrg.exe 
O4 - HKLM\..\Run: [Windows Shell Library Loader] load shell.dll /c /set 
O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe 
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB 
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" 
O4 - HKLM\..\Run: [urlLSTCK.exe] C:\Program Files\Norton Internet Security Professional\UrlLstCk.exe 
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\Olitec\USB ADSL\CnxDslTb.exe 
O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer 
O4 - HKLM\..\Run: [sSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe 
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\se.dll,DllInstall 
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" 
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto 
O4 - HKCU\..\Run: [WrCtrl] "C:\Program Files\WinRoute Pro\wrctrl.exe" 
O4 - HKCU\..\Run: [instant Access] rundll32.exe EGDHTML_1026.dll,InstantAccess 
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background 
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm 
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm 
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -  
O17 - HKLM\System\CCS\Services\Tcpip\..\{80C42E2D-74E4-4E42-901C-E2DFA860C93A}: NameServer = 80.118.196.36 80.118.192.100 
O18 - Filter: text/html - {B0B657CB-F273-4AB6-80AE-A255EAF3521B} - C:\WINDOWS\System32\eoaj.dll 
O18 - Filter: text/plain - {B0B657CB-F273-4AB6-80AE-A255EAF3521B} - C:\WINDOWS\System32\eoaj.dll 
O19 - User stylesheet: C:\WINDOWS\sample.txt 
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE 
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE 
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe 
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe 
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe 
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe 
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\navapsvc.exe 
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\AdvTools\NPROTECT.EXE 
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\SAVScan.exe 
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe 
O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe 
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe 
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe 
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe 
  
   donc voila ....... 
  
qui , qui me dit quoi je doit faire ? 
merci merci