bloc note hijackthis
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.neuf.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [KAVPersonal50] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
bloc notes avscan
Report file date: mardi 21 février 2006 07:54
Jobname: 'Manual Selection'
Scanning for 309167 virus strains and unwanted programs.
Licensed to: AntiVir PersonalEdition Classic
Serialnumber: 0000149996-WURGE-0001
Platform: Windows XP
Windowsversion: (Service Pack 2) [5.1.2600]
Username: F.R.E.D
Computername: MAFIA
Versioninformations:
AVSCAN.EXE : 7.0.0.21 389160 31/01/2006 10:54:36
AVSCAN.DLL : 7.0.0.21 42536 31/01/2006 10:54:36
LUKE.DLL : 7.0.0.21 110632 31/01/2006 10:54:36
LUKERES.DLL : 7.0.0.21 27688 31/01/2006 10:54:36
ANTIVIR0.VDF : 6.32.0.60 4323840 06/12/2005 10:47:34
ANTIVIR1.VDF : 6.33.0.207 1160192 08/02/2006 08:09:40
ANTIVIR2.VDF : 6.33.0.208 1536 08/02/2006 08:09:40
ANTIVIR3.VDF : 6.33.0.216 35328 08/02/2006 08:09:40
AVEWIN32.DLL : 6.33.0.34 1044992 02/02/2006 10:21:04
AVPREF.DLL : 6.34.0.0 33320 18/01/2006 12:05:46
AVREP.DLL : 6.33.0.201 1663016 08/02/2006 09:19:48
AVPACK32.DLL : 6.33.0.6 331816 09/01/2006 09:03:38
AVREG.DLL : 6.31.0.90 25128 28/07/2005 10:06:12
NETNT.DLL : 6.32.0.0 6696 27/09/2005 07:56:46
NETNW.DLL : 6.32.0.0 9768 27/09/2005 07:56:46
Start of the scan: mardi 21 février 2006 07:54
Start scanning boot sectors:
Boot sector 'C:'
[NOTE] No virus was found!
Boot sector 'D:'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( 16 files ).
Starting the file scan:
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\F.R.E.D.MAFIA\NTUSER.DAT
[WARNING] The file could not be opened!
C:\Documents and Settings\F.R.E.D.MAFIA\ntuser.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\F.R.E.D.MAFIA\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\F.R.E.D.MAFIA\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService.AUTORITE NT\NTUSER.DAT
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService.AUTORITE NT\ntuser.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService.AUTORITE NT\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService.AUTORITE NT\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\default
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\default.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\software
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\software.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\system
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\system.LOG
[WARNING] The file could not be opened!
D:\incoming\Cracks,Serialnumbers,Keygenerators,Nero,Corel Draw,Antivirus,Adobe,Macromedia, Norton,Paint Shop Pro,Winrar,Winzip,X Win,A.rar
[0] Archivetype: RAR
--> Cracks,Serialnumbers,Keygenerators,Nero,Corel Draw,Antivirus,Adobe,Macromedia, Norton,Paint Shop Pro,Winrar,Winzip,X Win,A.txt
[DETECTION] Contains signature of the VBS script virus VBS/Redlof.a.3
[iNFO] The file was moved to 'af5e352d.qua'!
End of the scan: mardi 21 février 2006 09:48
Used time: 1:54:14 min
The scan has been done completely.
3459 Scanning directories
121373 Files were scanned
1 viruses and/or unwanted programs was found
0 files were deleted
0 files were repaired
1 files were moved to quarantine
0 files were renamed
748 Archives were scanned
38 Warnings
1 Notes
j'ai fait delete sur le dossier mis en quarantaine.
en esperant que j'ai tout bien fait.
Merci d'avance et bonne journée