Aboutbank ysb toolbar

Résolu
baba100966 Messages postés 107 Statut Membre -  
 Utilisateur anonyme -
bonjout a tous et toutes j ai aboutbank qui squatte ma page d accueil et avast qui s enerve ysb toolbar sur mon pc et chaque fois le met en quarantaine et cela fait quatre heures que cela dure
scannne spybot donne rien ad adware non plus merci d avance
A voir également:

10 réponses

aranjuez31 Messages postés 8069 Statut Contributeur 354
 
hello
~~~~~~~~~
cOLLE le rapport de ce progr
ewido (dowload)
http://www.ewido.net/fr/download/

on verra sans doute plus clair aprés
1
baba100966 Messages postés 107 Statut Membre 2
 
merci de ton aide il 1800 objets infecte?
0
aranjuez31 Messages postés 8069 Statut Contributeur 354
 
ouarf !
tous ont-ils été bloqués ?
si non il faut aller plus loin
0
baba100966 Messages postés 107 Statut Membre 2
 
excuse il a trouver3333 fichier et me demande sije veux les suprimer et cela un pat un cela prend du temp
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
baba100966 Messages postés 107 Statut Membre 2
 
ouilouil c est un worm vbdw dis moi que le pc n est pas foutu avst n arret pas de hurler
0
aranjuez31 Messages postés 8069 Statut Contributeur 354
 
re
3333 fichier s !!!!
tu bats des records là
tu vides bien sur
peut-être que certains seront rétifs
~~~~~~~~~~~
nettoie encore avec ceci
scan online avec (sous IE)
http://www.bitdefender.fr/bd/site/search.php#
COLLE moi le rapport
~~~~~~~~~~
ensuite télécharge ceci
http://telechargement.zebulon.fr/160-patch-francais-pour-hijackthis-1991.html
suis mode d emploi
http://pageperso.aol.fr/balltrap34/Hijenr.gif
http://pageperso.aol.fr/balltrap34/demohijack.htm

0
baba100966 Messages postés 107 Statut Membre 2
 
merci de ton aide voici un rapport comment ce ver a pu penetrer le pc alorss qu il y a avast spytbot et pare feu ? et faire autant de degats
je continues tes instructions desolee je suis un peu lente etencore merci a tous

Report file date: samedi 18 février 2006 12:15

Jobname: 'Local Drives'

Scanning for 316424 virus strains and unwanted programs.

Licensed to: AntiVir PersonalEdition Classic
Serialnumber: 0000149996-WURGE-0001
Platform: Windows XP
Windowsversion: (Service Pack 2) [5.1.2600]
Username: vaneeckhout ladanyi
Computername: VAN-MFE3QVDEIPG

Versioninformations:
AVSCAN.EXE : 7.0.0.21 528424 31/01/2006 10:54:48
AVSCAN.DLL : 7.0.0.21 42536 31/01/2006 10:54:48
LUKE.DLL : 7.0.0.21 114728 31/01/2006 10:54:48
LUKERES.DLL : 7.0.0.21 27688 31/01/2006 10:54:48
ANTIVIR0.VDF : 6.32.0.60 4323840 06/12/2005 10:47:34
ANTIVIR1.VDF : 6.33.0.207 1160192 08/02/2006 08:09:40
ANTIVIR2.VDF : 6.33.0.234 97280 18/02/2006 11:12:32
ANTIVIR3.VDF : 6.33.1.4 52224 18/02/2006 11:12:32
AVEWIN32.DLL : 6.33.0.36 1163776 18/02/2006 11:12:32
AVPREF.DLL : 6.34.0.0 38440 18/01/2006 12:06:02
AVREP.DLL : 6.33.1.0 2392104 18/02/2006 11:12:32
AVPACK32.DLL : 6.33.0.6 331816 09/01/2006 09:03:38
AVREG.DLL : 6.31.0.90 27688 28/07/2005 10:06:36
NETNT.DLL : 6.32.0.0 6696 27/09/2005 07:56:50
NETNW.DLL : 6.32.0.0 9768 27/09/2005 07:56:50

Start of the scan: samedi 18 février 2006 12:15

Start scanning boot sectors:

Boot sector 'C:'
[NOTE] No virus was found!
Boot sector 'D:'
[NOTE] No virus was found!

Starting to scan the registry.

The registry was scanned ( 37 files ).

Starting the file scan:

C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\LocalService\NTUSER.DAT
[WARNING] The file could not be opened!
C:\Documents and Settings\LocalService\ntuser.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\NTUSER.DAT
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\ntuser.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\ntuser.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\ntuser.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Shareaza\Data\TigerTree.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Skype\barbaralaszloo100966\call256.dbb
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Skype\barbaralaszloo100966\chat512.dbb
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Skype\barbaralaszloo100966\chatmsg256.dbb
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Skype\barbaralaszloo100966\chatmsg512.dbb
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Skype\barbaralaszloo100966\contactgroup256.dbb
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Skype\barbaralaszloo100966\index2.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Skype\barbaralaszloo100966\profile16384.dbb
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Skype\barbaralaszloo100966\transfer256.dbb
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Skype\barbaralaszloo100966\transfer512.dbb
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Skype\barbaralaszloo100966\user1024.dbb
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Skype\barbaralaszloo100966\user16384.dbb
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Skype\barbaralaszloo100966\user4096.dbb
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Application Data\Skype\barbaralaszloo100966\voicemail256.dbb
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\02 10 06 A Chinese Tall Story 2005 情癲大聖-VCD.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44170238.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\24 - 24 season 1 complete.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4417023d.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\24 24 Season 1 Complete Divx Rkl.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4417023f.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Age Of Empires Gold Edition rar.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445c0274.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ahead Of The Competition 4.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445c0276.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ahead Of The Competition 3 7.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445c027c.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\airmapsv5 zip.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4469027e.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Alien Arena 2006 Gold Edition.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44600281.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\All Software.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44630281.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Alpeak Audimovie, CDAnyware Run Your CDs Anywhere.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44670282.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\AmericanGothicDVDRipDisc1of6ISO937672 Demonoid com.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445c0283.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\AmericanGothicDVDRipDisc2of6ISO937672 Demonoid com.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445c0284.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\AmericanGothicDVDRipDisc3of6ISO937672 Demonoid com.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459678b1.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ana Gabriel - Dos Amores Un Amante MP3 Bitrate 256 Covers.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44580285.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ana Gabriel - Joyas de Dos Siglos MP3 Bitrate 256 Covers.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44580286.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ana Gabriel - Mi Mexico MP3 Bitrate 256 Covers.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459278b3.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Andersen, Laine, Readman - III 2006 224k (Melodic Hard Rock).zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445b0287.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Andromeda - Season 5.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459178bc.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Andrzej Mleczko - Najlepsze Rysunki [PL] [PDF].zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445b0288.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\animation and 3D text AIO.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44600288.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Anton Szandor LaVey - The Satanic Bible pdf.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446b0288.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\AnyDVD 5 9 1 1 rar [www.PBNova.us].zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44700289.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\ARABIC Nancy Agram - Ya Atabtab - 2006 - 192KBS [WWW TORRENTAT UNI CC].zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4438026d.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Arctic Monkeys-Whatever People Say I Am Thats What Im Not-CD-2006-LOSSLESS-QiE.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a028e.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Armand Van Helden - Sugar (Incl Cagedbaby Mix) Promo CDM [House][2006][www pctrecords com].zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4464028e.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Armin Van Buuren-Live At Trance Energy 2006-LINE-2006-CiN[unrealtorrents.com].zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4464028f.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Arthur 2 On The Rocks DVDrip [Spanish] [emulebit com & elitetorrent net] avi.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446b028f.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\ASHAMPOO BURNING STUDIO.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '443f0270.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ashanti - Cant Stop - CDM.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445f0291.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Audio & Video.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445b0293.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Aura - Indywidualnie (2005) (mp3@160-256kbps).zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44690294.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Australia's Biggest Loser - S01E05 (2006.02.17) - XviD.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446a0294.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Autopsy life & Death.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446b0294.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Avid-Xpress-Pro-HD-v5 0 [www.PBNova.us].zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44600296.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Béla Fleck and The Flecktones.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445c0246.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\B&W Pro 2 2.12.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '444e0247.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\B-Coder Pro 4.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '443a024e.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\B-Free Small Business 4.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '443d024f.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\B-Jigsaw 7.7.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4441024f.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\B-Randomizer 0.2.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44490250.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\B-Tree 1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '444b0250.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\B.I.R.D. 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44400252.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\B12 Anti Spyware 1.2.6.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44290255.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\B2 CDLGen 3.1.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44170256.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\B2 Spice AD Lite 4.2.14.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44170257.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\B2 Spice A_D 5.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45dd786c.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\b2evolution 0.9.0.11.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445c0258.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\B3 HTML Studio 4.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44170259.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\B4 1.1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4417025b.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BAARK 3.01.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44380268.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babala 0.3.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44590288.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babarosa Gif Animator 3.6.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44590289.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babble MP3 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378be.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babble Rock 10.1.0.11.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4459028a.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babbling Brook 1.5.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378bf.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BabeFest 2002 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445902f4.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BabelBloX 1.9.3.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4459028b.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babelizer 1.5.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378b8.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BabeSave Screensaver Bikini Edition 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4459028c.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babesavers Screensaver - Mariah Carey 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378b9.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BabeSavers Screensaver - Sexy Cindy Crawford 1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4459028d.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BabeX 1.12.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378ba.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babies of the Wilderness 1.3.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4459028e.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babimals 2.03.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378bb.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babu Converter Plus 1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4459028f.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babushka 2.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378a4.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baby Album - Basic Edition 2.14 build 6.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44590291.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baby Article Collections 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44590290.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baby ASP Web Server 2.6.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378a5.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baby Boom 1.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378a6.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baby Boom II 1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44590293.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baby Boomer Bible Browser 1.5.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44590292.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baby Days and Toddler Tales 1.2.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378a7.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baby Diary 1.9.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378a0.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baby In A Box Screen Saver 2.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44590295.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baby Its Me - Desktop Share 1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378a2.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baby Names 1.1.0.4.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44590294.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baby Names Dictionary 1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378a1.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baby Safe 1.05.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44590297.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babya Logic 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378ac.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babyblues Wonderful Waterfalls 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44590296.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BabyDays 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378a3.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BabyKeys for Windows 1.5.2.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4459029c.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Babylon-Pro 5.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44590299.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BabyMelodyPilot (Macintosh) 1.1.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378ae.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BabyMelodyPilot 1.3.2.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44590298.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BabyName 1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378ad.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BabyPlan 2.1 eng..zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4459029b.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BabyShield 2.4.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459378a8.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BabyWatch 211.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4459029d.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baccarat Basic Strategy Analysis 2.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a029a.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baccarat Tool 1.3.5.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459078af.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bach Flower Emotional Wellness Quiz 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a029b.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Back Alley Brawl 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459078a8.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Back Online 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a029c.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Back to Baghdad demo .zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459078a9.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Back-IT-Up 5.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a029e.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Back2Life 2.32.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a029d.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Back2Life for TC 2.3.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459078aa.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Back4Win 5.0.0.2.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459078ab.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Back4WinXP 5.0.4.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a0298.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backbase Community Edition 3.1.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a029f.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backdrop GC 2.05.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907894.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backer 6.5.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02a0.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backgammon 1.51.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907895.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backgammon Blitz 1.9.5.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02a2.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backgammon Classic 3.2.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02a1.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backgammon Deluxe 1.5.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907896.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backgammon, by George 1.91.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907897.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Background Buddy 1.06.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02ac.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackLinks Master 1.0.2.3.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02a3.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackPack 2006 LE 2.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907890.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackPack Professional 3.6.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02a5.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backspin Billiards 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02a4.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backstage 1.0 (b1).zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907891.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackStreet Browser 2.8.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907892.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackTracker 2.1.0.72.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02a7.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup 2.4.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02a6.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup dD 2.1 build 181.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907893.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Deluxe 2005 1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4590789c.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup E-mail 1.7 revision 0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02a9.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Exec Panther beta.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4590789e.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup for One 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02a8.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup for Workgroups 2.5.2.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4590789d.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Genie 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02ab.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Machine XP 1.1.27.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907898.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Made Easy 3.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02aa.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Made Simple 5.1.187.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4590789f.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Magic 1.6.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02ad.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackUp Maker Standard Edition 4.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4590789a.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Manager 1.0.7.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02af.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Manager 2.5.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907899.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup MyPC (Europe) 5.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02ae.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Platinum 2.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4590789b.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Plus 7.7.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907884.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Plus DVD Edition 1.1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02b1.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Premium 2.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a0294.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Scheduler 1.0.0.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459078a1.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackUp Solutions Online Backup 7.5.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907886.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup to DVDCD Made Simple 5.1.187.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02b3.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup To Neighbor 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02b0.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Utility System 1.0.7.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907885.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Watcher for MySQL 1.9.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02b2.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Wolf 3.13.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907880.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup Xpresso 2.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02b5.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup-Burner CD-Recording Component 5.6.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907887.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup2000 1.3.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02bc.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup2005 Pro 4.4.9.160.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907882.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup2005 Synchronizer 3.2.4.30.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02b7.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup2Net 1.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4590788c.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Backup4all 3.0 build 184.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02b4.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackupAssist 2.3.2.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907881.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackupBuddy Personal 2.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02b9.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackupBuddy Professional 2.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4590788e.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackupBuddyVFS Personal 3.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02bb.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackupBuddyVFS Professional 3.2.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02b6.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackupIQ 7.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907883.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackupMe 1.28.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45907888.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackupOnDemand 2.7.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02bd.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackupSW 3.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4590788a.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackupXfer for Palm 1.2d1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445a02b8.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BackupXpress Pro 2.74.41 build 191.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4590788d.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bad Apples 1.3.11.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445b02b9.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bad Breath, Morning Breath 12 - Step Plan 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4591788e.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bad Check Tracker 2.0.03.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445b02bb.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bad Cookie (OS X) 1.6.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445b02ba.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bad Cookie 1.6.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4591788f.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bad Games Autorun 0.52.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45917888.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bad Intentionz 1.5.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445b02bd.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bad Mojo demo .zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4591788a.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bad News Bears Trailer .zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445b02bc.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bad Toys 3D 1.95.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45917889.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BadBlue Personal Edition 2.5.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445b02be.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BadCopy Pro 3.8 build 1108.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445b02bf.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BadgeBuilder Express 4.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459178f4.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baggle 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445e02be.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bagle Toolbar 3.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '4594788b.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bagle Toolbar 4.5.8.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '445e02bf.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Bagle X 4.5.83.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '459478f4.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BakBot 3.00.24.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446202bf.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BaKoMa TeX 7.3.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '444202c0.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baladana 4.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302c0.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Balder Multiboot 2.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302c1.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baldies demo .zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45a978f6.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Baldur's Gate II Throne of Bhaal v26498 Patch .zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302c3.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Balistick 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302c2.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ball Attack 1.12.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45a978f7.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ball Bounce Deluxe 1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302cc.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ball Deluxe 7.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45a978f0.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ball-Bar 1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302c5.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BallClicks 1.0.4.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45a978f2.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ballet .zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302c4.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ballistics 1.0.1 patch .zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45a978f1.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ballistics 1.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302c7.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ballistics demo .zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45a978fc.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\ballistics test bb wmv.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302c9.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ballistik 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302c6.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ballmaster 2 1.5.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45a978f3.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Balloon Blast .zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45a978fe.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Balloon Dart 1.2.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302cb.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Balloon OCX 2.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45a978f8.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Balloon Tooltips .NET 2.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302c8.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Ballooneys Lite Screensaver 2.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45a978fd.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BalloonRain 1.0d.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302cd.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Balloons Animated Jigsaw Puzzle 1.0.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45a978fa.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Balls 1.1.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302ca.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Balls Millennium 1.2.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '45a978ff.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Balls of Steel Patch 1.3.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '44630334.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\Balls Up Episode 1 1.11a.zip
[0] Archivetype: ZIP
--> Setup.exe
[DETECTION] Contains signature of the worm WORM/VB.DW
[INFO] The file was moved to '446302cf.qua'!
C:\Documents and Settings\vaneeckhout ladanyi\Mes documents\Downloads\Shared\BallSwapper 1.05.1.zip
[0] Archivetyp
0
Utilisateur anonyme
 
Salut,

télécharge hijackthis:
http://www.hijackthis.de/downloads/hijackthis_199.zip

Installe le dans son propre dossier:
Par exemple C:\hijackthis
Lance le, clique sur "do a system scan and save logfile"
Puis copie et colle le rapport ici.

A++
0
baba100966 Messages postés 107 Statut Membre 2
 
voici le rapporLogfile of HijackThis v1.99.1
Scan saved at 14:50:28, on 18/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Documents and Settings\vaneeckhout ladanyi\Bureau\630_209_winxp\CD\Utility\sistray.EXE
C:\windows\winsysban9.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\DOCUME~1\VANEEC~1\LOCALS~1\Temp\Répertoire temporaire 1 pour hijackthis_199[1].zip\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SiS Tray] C:\Documents and Settings\vaneeckhout ladanyi\Bureau\630_209_winxp\CD\Utility\sistray.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [winsysupd] C:\windows\winsysupd9.exe
O4 - HKLM\..\Run: [winsysban] C:\windows\winsysban9.exe
O4 - HKLM\..\Run: [gimmygames] C:\\gimmygames9.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/download/SISTransfer.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138082780232
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://metaboli.clubic.com/components/Metaboli.ocx
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{500DBD8B-5098-4A51-BA62-5A339E0BE76C}: NameServer = 195.238.2.22 195.238.2.21
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

t
0
Utilisateur anonyme > baba100966 Messages postés 107 Statut Membre
 
Relance HijackThis, choisis " do a scan only" coche la case devant les lignes ci-dessous et clique en bas sur "fix checked"

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.htm
O4 - HKLM\..\Run: [winsysupd] C:\windows\winsysupd9.exe
O4 - HKLM\..\Run: [winsysban] C:\windows\winsysban9.exe
O4 - HKLM\..\Run: [gimmygames] C:\\gimmygames9.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN
O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/download/SISTransfer.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://metaboli.clubic.com/components/Metaboli.ocx
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

clique sur demarrer, rechercher, cherches et supprime ces fichiers:

winsysupd9.exe
gimmygames9.exe
winsysban9.exe

Installe un pare-feu pour te proteger des attaques du net! en voici un gratuit

ZoneAlarm:
http://www.01net.com/telecharger/windows/Internet/internet_utlitaire/fiches/18128.html

Puis fais ceci:

Telecharge, installe puis mets à jour ce logiciel, une fois que c'est fait, fais un scan complet de ton systeme et colle le rapport ici avec un nouveau rapport hijackthis
Ewido:
http://www.01net.com/telecharger/windows/Utilitaire/antivirus/fiches/31851.html

A++

0
baba100966 Messages postés 107 Statut Membre 2 > Utilisateur anonyme
 
---------------------------------------------------------
ewido anti-malware - Rapport de scan
---------------------------------------------------------

+ Créé le: 17:40:45, 18/02/2006
+ Somme de contrôle: C53C227E

+ Résultats du scan:

C:\Documents and Settings\vaneeckhout ladanyi\Cookies\vaneeckhout ladanyi@247realmedia[1].txt -> TrackingCookie.247realmedia : Nettoyer et sauvegarder
C:\Documents and Settings\vaneeckhout ladanyi\Cookies\vaneeckhout ladanyi@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Nettoyer et sauvegarder
C:\Documents and Settings\vaneeckhout ladanyi\Cookies\vaneeckhout ladanyi@as-eu.falkag[2].txt -> TrackingCookie.Falkag : Nettoyer et sauvegarder
C:\Documents and Settings\vaneeckhout ladanyi\Cookies\vaneeckhout ladanyi@bluestreak[2].txt -> TrackingCookie.Bluestreak : Nettoyer et sauvegarder
C:\Documents and Settings\vaneeckhout ladanyi\Cookies\vaneeckhout ladanyi@casinotropez[1].txt -> TrackingCookie.Casinotropez : Nettoyer et sauvegarder
C:\Documents and Settings\vaneeckhout ladanyi\Cookies\vaneeckhout ladanyi@estat[1].txt -> TrackingCookie.Estat : Nettoyer et sauvegarder
C:\Documents and Settings\vaneeckhout ladanyi\Cookies\vaneeckhout ladanyi@sel.as-eu.falkag[2].txt -> TrackingCookie.Falkag : Nettoyer et sauvegarder
C:\Documents and Settings\vaneeckhout ladanyi\Cookies\vaneeckhout ladanyi@weborama[1].txt -> TrackingCookie.Weborama : Nettoyer et sauvegarder
C:\Documents and Settings\vaneeckhout ladanyi\Cookies\vaneeckhout ladanyi@wreport.weborama[1].txt -> TrackingCookie.Weborama : Nettoyer et sauvegarder
C:\Documents and Settings\vaneeckhout ladanyi\Cookies\vaneeckhout ladanyi@www.casinotropez[2].txt -> TrackingCookie.Casinotropez : Nettoyer et sauvegarder
C:\Documents and Settings\vaneeckhout ladanyi\Cookies\vaneeckhout ladanyi@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
C:\Program Files\Messenger Plus! 3\Setup.dat/Sponsor.exe -> Downloader.Swizzor.bt : Nettoyer et sauvegarder
C:\Program Files\Save -> Adware.SaveNow : Nettoyer et sauvegarder
C:\Program Files\Save\save.cch -> Adware.SaveNow : Nettoyer et sauvegarder
C:\RECYCLER\S-1-5-21-1214440339-113007714-1060284298-1003\Dc7.exe -> Downloader.VB.ww : Nettoyer et sauvegarder
C:\RECYCLER\S-1-5-21-1214440339-113007714-1060284298-1003\Dc8.exe -> Downloader.VB.ww : Nettoyer et sauvegarder
C:\WINDOWS\Downloaded Program Files\UERSV_0001_LPNetInstaller.exe -> Not-A-Virus.Downloader.Win32.Agent.d : Nettoyer et sauvegarder


::Fin du rapport
0
baba100966 Messages postés 107 Statut Membre 2 > Utilisateur anonyme
 
Logfile of HijackThis v1.99.1
Scan saved at 17:41:47, on 18/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Documents and Settings\vaneeckhout ladanyi\Bureau\630_209_winxp\CD\Utility\sistray.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SiS Tray] C:\Documents and Settings\vaneeckhout ladanyi\Bureau\630_209_winxp\CD\Utility\sistray.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138082780232
O17 - HKLM\System\CCS\Services\Tcpip\..\{500DBD8B-5098-4A51-BA62-5A339E0BE76C}: NameServer = 195.238.2.22 195.238.2.21
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
0
baba100966 Messages postés 107 Statut Membre 2
 
merci a toi a ton avis c est grave?
0
Utilisateur anonyme
 
Grave ..eyh .. . tu vas pas en mourrir mais c'est pas bon, tu es infecté donc avec hijackthis on verra ça d'un peu plus près ;-)
0
baba100966 Messages postés 107 Statut Membre 2
 
autre question je travaille avec mon pc et envoie des dossiers es ce que je n ai infecte d autre pc ne faut il pas que je les avertissent?
0
baba100966 Messages postés 107 Statut Membre 2
 
Logfile of HijackThis v1.99.1
Scan saved at 18:32:57, on 18/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Documents and Settings\vaneeckhout ladanyi\Bureau\630_209_winxp\CD\Utility\sistray.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SiS Tray] C:\Documents and Settings\vaneeckhout ladanyi\Bureau\630_209_winxp\CD\Utility\sistray.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunOnce: [srePostpone] rundll32.exe c:\windows\system32\zonelabs\srescan.dll,DoSpecialAction
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138082780232
O17 - HKLM\System\CCS\Services\Tcpip\..\{500DBD8B-5098-4A51-BA62-5A339E0BE76C}: NameServer = 195.238.2.22 195.238.2.21
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
0
Utilisateur anonyme
 
Pour te repondre ça se pourrait car tu es infecté par un vers de là à aller prevenir les autres personnes euh ..non

fais ceci et colle le rapport ici une fois qu'il à fini

http://www.bitdefender.fr/scan/license.php
0
baba100966 Messages postés 107 Statut Membre 2 > Utilisateur anonyme
 
mon cher boulepate (mignon) je te remercie pour le temps passer a dépanner mon pc ,il ne suffit pas d être un fana d informatique pour aider des personnes que tu ne connais ni d adam ni d eve et il faut avoir un coeur gros comme cela ,je pense que mon pc est sorti d affaire grâce a vous et la rapidité de vos interventions alors de pc a pc je vous envoie un gros bisou plein de reconnaissance donc avant le resultat scan je voulais vous dire merci baba
0
Utilisateur anonyme > baba100966 Messages postés 107 Statut Membre
 
Merci ça me fait plaisir, mais je suis aussi content de "travailler" avec des personnes comme toi qui écoute ce qu'on leurs dit de faire :-)

Hésites pas si t as des questions ou des doutes le forum est là ;-)

0
baba100966 Messages postés 107 Statut Membre 2 > Utilisateur anonyme
 
ronron, dernier scan antivirus est negatiif as tu vraiment besoin de le voir? mille et un merci baba
0
Utilisateur anonyme > baba100966 Messages postés 107 Statut Membre
 
S'il est négatif, non ce n'est pas la peine c'est que ton pc est propre..ton rapport hijackthis je ne vois rien de bizarre donc pour moi c'est ok :-)
0