Trojans Win32.Delf.uv et Win32.Agent.dtt

Bonjour,

Après avoir analyser mon ordinateur avec Spybot, le rapport me dit que je suis infecté par 2 trojans:

. Win32.Delf.uv
. Win32.Agent.dtt

Il m'est impossible de les supprimer...

Quelqu'un peut-il m'indiquer comment faire?

Je vous remercie d'avance!

Cirth
Configuration: Windows 7 Internet Explorer 8.0

12 réponses

  1. Contributeur
    bonjour
    spybot n'est pas un pro contre les trojans, quel antivirus utilise tu?
    0
    1. Bonjour,

      Plus de réponses?.... :(
      0
  2. Bonjour,

    J'utilise Bitdefender Internet Security 2010. Mais uniquement spybot me repère ces trojans.
    0
    1. Contributeur
      Bonjour,

      On va vérifier,

      Télécharge RSIT " Random's System Information Tool " sur ton bureau : http://images.malwareremoval.com/random/RSIT.exe

      - Ferme toutes les applications en cours et double clic sur RSIT.exe
      - Sélectionnes " Continue " à l'ecran >> RSIT va analyser le pc et vérifier si l'outil hijackthis ( version à jour) est présent sur le pc, si ce n'est pas le cas, RSIT le téléchargera >> accepte la license
      - Une fois l'analyse terminée, 2 rapports.txt s'ouvrent,
      --> Log.txt à l'écran
      --> Info.txt réduit dans la barre des tâches
      Poste le contenu des 2 rapports.

      .
      0
      1. Bonjour,

        Merci de ton aide.

        Quand je lance RSIT, au cours de l'analyse ça me marque un message d'erreur :

        AutoIt Error
        Line-1:
        Error : Variable used without being declared

        Je n'ai donc pas les deux rapport .txt...
        0
        1. Contributeur
          AutoIt Error
          Line-1:
          Error : Variable used without being declared


          Il existe une solution : https://www.commentcamarche.net/faq/25150-rsit-autoit-error

          Mais pour le moment, poste le rapport qui a été généré

          ..
          0
          1. J'ai essayé la solution , mais ça me dit "l'installation a échoué"

            Je n'ai donc toujours pas de rapport généré :(
            0
            1. c'est bon, je suis sous windows 7 et j'ai lancé RSIT en mode compatibilité Windows Xp service pack 3. Du coup ça a marché.

              Voici les 2 Rapports :

              Log :

              Logfile of random's system information tool 1.06 (written by random/random)
              Run by Cirth at 2010-02-03 12:39:25
              Microsoft Windows 7 Édition Intégrale Service Pack 3
              System drive C: has 134 GB (22%) free of 610 GB
              Total RAM: 2047 MB (57% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 12:39:26, on 03/02/2010
              Platform: Unknown Windows (WinNT 6.01.3004)
              MSIE: Internet Explorer v8.00 (8.00.7100.0000)
              Boot mode: Normal

              Running processes:
              C:\Windows\system32\taskhost.exe
              C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
              C:\Windows\system32\Dwm.exe
              C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
              C:\Program Files\Razer\Reclusa\razerhid.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Razer\Reclusa\razertra.exe
              C:\Program Files\GameShadow\GameShadow.exe
              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\Glary Utilities\memdefrag.exe
              C:\Program Files\NETGEAR\WPN111\wpn111.exe
              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Users\Cirth\Desktop\RSIT.exe
              C:\Program Files\trend micro\Cirth.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.lemonde.fr/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll
              O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
              O4 - HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
              O4 - HKLM\..\Run: [Reclusa] C:\Program Files\Razer\Reclusa\razerhid.exe
              O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
              O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
              O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
              O4 - HKCU\..\Run: [GameShadow] C:\Program Files\GameShadow\GameShadow.exe /q
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKCU\..\Run: [Glary Memory Optimizer] "C:\Program Files\Glary Utilities\memdefrag.exe" /autostart
              O4 - HKCU\..\Run: [Livestation] C:\Program Files\Livestation\Livestation.exe -startup
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU')
              O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
              O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
              O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
              O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
              O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
              O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O13 - Gopher Prefix:
              O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} (System Requirements Lab Class) - http://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab
              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_1_0.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
              O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
              O23 - Service: BitDefender Serveur Arrakis (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
              O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - https://sourceforge.net/p/libusb-win32/wiki/Home/ - C:\Windows\system32\libusbd-nt.exe
              O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
              O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
              O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
              O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
              0
              1. Contributeur
                Sous 7, il faut désactiver l'UAC (controle descomptes utilisateurs), tu le réactiveras à la fin de la désinfection

                Désactiver l'UAC sous 7

                --------------------

                Il faut avant tout désactiver le tea-timer de Spybot qui risque de génér les différents scan, tu le remettras si tu veux à la fin de la désinfection, mais il faudra alors accépter toutes les modifications de registre qu'il te proposera....

                désactive le tea-timer de spybot, suis ce lien et cliques sur - " desactiver le the-timer "

                http://perso.orange.fr/rginformatique/section%20virus/demo%20spybot.htm

                ---------------------

                Télécharge UsbFix sur ton bureau

                branche tes supports amovibles (clé usb, disque dur externe, etc) sans les ouvrir

                # Double-clique sur le raccourci UsbFix présent sur ton bureau.

                -Tape F pour français , et presse enter pour valider

                # Le menu apparait, choisi l'option 1 ( recherche )

                # Laisse l'outil travailler

                # Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

                Note : le rapport est également à C:\USBFix.txt

                Un tutoriel : http://pagesperso-orange.fr/nostools/usbfix.html
                0
                1. ############################## | UsbFix V6.086 |

                  User : Cirth (Administrateurs) # CIRTH-PC
                  Update on 03/02/2010 by El Desaparecido , C_XX & Chimay8
                  Start at: 17:41:10 | 03/02/2010
                  Website : http://pagesperso-orange.fr/NosTools/index.html
                  Contact : FindyKill.Contact@gmail.com

                  Pentium(R) Dual-Core CPU E6300 @ 2.80GHz
                  Microsoft Windows 7 Édition Intégrale (6.1.7100 32-bit) #
                  Internet Explorer 8.0.7100.0
                  Windows Firewall Status : Disabled
                  AV : Antivirus BitDefender 12.0 [ Enabled | Updated ]
                  FW : Pare-feu BitDefender [ Enabled ]12.0

                  C:\ -> Disque fixe local # 596,07 Go (130,05 Go free) # NTFS
                  D:\ -> Disque CD-ROM
                  E:\ -> Disque fixe local
                  H:\ -> Disque fixe local # 298,02 Go (143,58 Go free) [My Passport] # FAT32
                  I:\ -> Disque fixe local # 181,8 Go (145,56 Go free) [Volume] # NTFS
                  Z:\ -> Disque CD-ROM

                  ############################## | Processus actifs |

                  C:\Windows\System32\smss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                  C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
                  C:\Windows\system32\atiesrxx.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\atieclxx.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\spoolsv.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\libusbd-nt.exe
                  C:\Windows\system32\PnkBstrA.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
                  C:\Windows\system32\taskhost.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
                  C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
                  C:\Program Files\Razer\Reclusa\razerhid.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\GameShadow\GameShadow.exe
                  C:\Program Files\Glary Utilities\memdefrag.exe
                  C:\Program Files\Razer\Reclusa\razertra.exe
                  C:\Program Files\NETGEAR\WPN111\wpn111.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Program Files\Windows Media Player\wmpnetwk.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Program Files\Secunia\PSI\psi.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
                  C:\Windows\servicing\TrustedInstaller.exe
                  C:\Windows\system32\conhost.exe
                  \\?\C:\Windows\system32\wbem\WMIADAP.EXE
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Windows\system32\wbem\wmiprvse.exe

                  ################## | Elements infectieux |

                  ################## | Registre |

                  ################## | Mountpoints2 |

                  HKCU\..\..\Explorer\MountPoints2\E
                  shell\AutoRun\command =E:\BSAutoRun.exe

                  ################## | ! Fin du rapport # UsbFix V6.086 ! |
                  0
                  1. Contributeur
                    Bonjour,

                    branche tes supports amovibles (clé Usb, DD externe, etc.) et clique sur OK .

                    -Tape F pour français , et presse enter pour valider

                    # Le menu apparait, choisi l'option 2 ( Suppression )

                    # Ton bureau disparaitra et le pc redémarrera .

                    # Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

                    # Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

                    Note : le rapport est également à C:\USBFix.txt

                    ....

                    Télécharge Malwarebytes' Anti-Malware :
                    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                    - Installe le > double-clic sur Mbam-setup.exe, à la fin de l'installation, il se mettra automatiquement à jour
                    - Une fois installé, fermes toutes les applications en cours et lances Malwarebytes
                    - Exécutes un examen rapide du pc ( tu n'auras pas accés à internet pendant l'analyse)
                    - A la fin du scan clic sur " Afficher les résultats ", si Malwarebytes a trouvé des infections >> clic sur " Supprimer la sélection "
                    - Si il a besoin de redémarrer le pc pour finir la désinfection, acceptes
                    - Un rapport s'établira, postes son contenu.
                    .
                    0
                    1. Bonjour,

                      Voici les 2 rapports :

                      Usb fix :

                      ############################## | UsbFix V6.086 |

                      User : Cirth (Administrateurs) # CIRTH-PC
                      Update on 03/02/2010 by El Desaparecido , C_XX & Chimay8
                      Start at: 11:27:33 | 05/02/2010
                      Website : http://pagesperso-orange.fr/NosTools/index.html
                      Contact : FindyKill.Contact@gmail.com

                      Pentium(R) Dual-Core CPU E6300 @ 2.80GHz
                      Microsoft Windows 7 Édition Intégrale (6.1.7100 32-bit) #
                      Internet Explorer 8.0.7100.0
                      Windows Firewall Status : Disabled
                      AV : Antivirus BitDefender 12.0 [ Enabled | Updated ]
                      FW : Pare-feu BitDefender [ Enabled ]12.0

                      C:\ -> Disque fixe local # 596,07 Go (123,4 Go free) # NTFS
                      D:\ -> Disque CD-ROM
                      E:\ -> Disque fixe local
                      H:\ -> Disque fixe local # 298,02 Go (143,58 Go free) [My Passport] # FAT32
                      I:\ -> Disque fixe local # 181,8 Go (145,56 Go free) [Volume] # NTFS
                      Z:\ -> Disque CD-ROM

                      ############################## | Processus actifs |

                      C:\Windows\System32\smss.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\wininit.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\services.exe
                      C:\Windows\system32\lsass.exe
                      C:\Windows\system32\lsm.exe
                      C:\Windows\system32\winlogon.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                      C:\Windows\system32\LogonUI.exe
                      C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
                      C:\Windows\system32\atiesrxx.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\atieclxx.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\spoolsv.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\libusbd-nt.exe
                      C:\Windows\system32\PnkBstrA.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\wbem\wmiprvse.exe
                      C:\Windows\servicing\TrustedInstaller.exe
                      C:\Windows\system32\taskhost.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\userinit.exe
                      C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Windows\system32\runonce.exe
                      C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
                      C:\Windows\system32\conhost.exe

                      ################## | Elements infectieux |

                      Supprimé ! C:\$Recycle.Bin\S-1-5-20
                      Supprimé ! C:\$Recycle.Bin\S-1-5-21-2531296791-2081128194-250223863-1000
                      Supprimé ! I:\$Recycle.Bin\S-1-5-21-2531296791-2081128194-250223863-1000

                      ################## | Registre |

                      ################## | Mountpoints2 |

                      Supprimé ! HKCU\...\Explorer\MountPoints2\E\Shell\AutoRun\Command

                      ################## | Listing des fichiers présent |

                      [20/03/2009 16:42|--a------|24] C:\autoexec.bat
                      [29/01/2010 00:39|--a------|45788] C:\bdlog.txt
                      [20/03/2009 16:42|--a------|10] C:\config.sys
                      [31/12/2009 18:38|--a------|227] C:\CtDrvIns.log
                      [31/12/2009 18:59|--a------|202] C:\CtDrvStp.log
                      [?|?|?] C:\hiberfil.sys
                      [31/01/2010 10:01|-rahs----|0] C:\IO.SYS
                      [31/01/2010 10:01|-rahs----|0] C:\MSDOS.SYS
                      [?|?|?] C:\pagefile.sys
                      [05/02/2010 11:32|--a------|3132] C:\UsbFix.txt
                      [24/04/2004 12:38|--a------|37888] H:\JSTART.exe
                      [18/07/2008 11:23|--a------|319488] H:\Setup.exe
                      [16/07/2008 09:14|--a------|42760] H:\WDInstaller.xml
                      [08/07/2008 11:53|--a------|1760039] H:\WDSetup.exe
                      [13/11/2008 11:56|--a------|46] H:\wdEULA.log
                      [13/11/2008 11:56|--a------|14] H:\wdstatus.log
                      [13/11/2008 11:58|--a------|89] H:\wdinstaller.log
                      [30/05/2008 09:31|--ah-----|54] H:\autorun.in_2.org
                      [13/11/2008 16:13|--a------|3827785] H:\WDSync.zip
                      [13/02/2008 11:46|--a------|4523520] H:\WDSync_v7_1_020.exe

                      ################## | Vaccination |

                      # C:\autorun.inf -> Dossier créé par UsbFix.
                      # H:\autorun.inf -> Dossier créé par UsbFix.
                      # I:\autorun.inf -> Dossier créé par UsbFix.

                      ################## | Upload |

                      Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_Cirth-PC.zip : https://www.ionos.fr/?affiliate_id=77097
                      Merci pour votre contribution .

                      ################## | ! Fin du rapport # UsbFix V6.086 ! |

                      Maleware Bytes :

                      Malwarebytes' Anti-Malware 1.43
                      Version de la base de données: 3497
                      Windows 6.1.7100
                      Internet Explorer 8.0.7100.0

                      05/02/2010 11:48:03
                      mbam-log-2010-02-05 (11-48-03).txt

                      Type de recherche: Examen rapide
                      Eléments examinés: 94781
                      Temps écoulé: 4 minute(s), 34 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 0
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 0

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      (Aucun élément nuisible détecté)
                      0