Trojans Win32.Delf.uv et Win32.Agent.dtt

Cirth -  
 Cirth -
Bonjour,

Après avoir analyser mon ordinateur avec Spybot, le rapport me dit que je suis infecté par 2 trojans:

. Win32.Delf.uv
. Win32.Agent.dtt

Il m'est impossible de les supprimer...

Quelqu'un peut-il m'indiquer comment faire?

Je vous remercie d'avance!

Cirth
Configuration: Windows 7 Internet Explorer 8.0

12 réponses

  1. Xavstarblues Messages postés 10585 Date d'inscription   Statut Contributeur Dernière intervention   1 858
     
    bonjour
    spybot n'est pas un pro contre les trojans, quel antivirus utilise tu?
    0
    1. Cirth
       
      Bonjour,

      Plus de réponses?.... :(
      0
  2. Cirth
     
    Bonjour,

    J'utilise Bitdefender Internet Security 2010. Mais uniquement spybot me repère ces trojans.
    0
  3. Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   667
     
    Bonjour,

    On va vérifier,

    Télécharge RSIT " Random's System Information Tool " sur ton bureau : http://images.malwareremoval.com/random/RSIT.exe

    - Ferme toutes les applications en cours et double clic sur RSIT.exe
    - Sélectionnes " Continue " à l'ecran >> RSIT va analyser le pc et vérifier si l'outil hijackthis ( version à jour) est présent sur le pc, si ce n'est pas le cas, RSIT le téléchargera >> accepte la license
    - Une fois l'analyse terminée, 2 rapports.txt s'ouvrent,
    --> Log.txt à l'écran
    --> Info.txt réduit dans la barre des tâches
    Poste le contenu des 2 rapports.

    .
    0
  4. Cirth
     
    Bonjour,

    Merci de ton aide.

    Quand je lance RSIT, au cours de l'analyse ça me marque un message d'erreur :

    AutoIt Error
    Line-1:
    Error : Variable used without being declared

    Je n'ai donc pas les deux rapport .txt...
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   667
     
    AutoIt Error
    Line-1:
    Error : Variable used without being declared


    Il existe une solution : https://www.commentcamarche.net/faq/25150-rsit-autoit-error

    Mais pour le moment, poste le rapport qui a été généré

    ..
    0
  7. Cirth
     
    J'ai essayé la solution , mais ça me dit "l'installation a échoué"

    Je n'ai donc toujours pas de rapport généré :(
    0
  8. Cirth
     
    c'est bon, je suis sous windows 7 et j'ai lancé RSIT en mode compatibilité Windows Xp service pack 3. Du coup ça a marché.

    Voici les 2 Rapports :

    Log :

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by Cirth at 2010-02-03 12:39:25
    Microsoft Windows 7 Édition Intégrale Service Pack 3
    System drive C: has 134 GB (22%) free of 610 GB
    Total RAM: 2047 MB (57% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:39:26, on 03/02/2010
    Platform: Unknown Windows (WinNT 6.01.3004)
    MSIE: Internet Explorer v8.00 (8.00.7100.0000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskhost.exe
    C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
    C:\Windows\system32\Dwm.exe
    C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\Razer\Reclusa\razerhid.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Razer\Reclusa\razertra.exe
    C:\Program Files\GameShadow\GameShadow.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Glary Utilities\memdefrag.exe
    C:\Program Files\NETGEAR\WPN111\wpn111.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Users\Cirth\Desktop\RSIT.exe
    C:\Program Files\trend micro\Cirth.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.lemonde.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll
    O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    O4 - HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
    O4 - HKLM\..\Run: [Reclusa] C:\Program Files\Razer\Reclusa\razerhid.exe
    O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
    O4 - HKCU\..\Run: [GameShadow] C:\Program Files\GameShadow\GameShadow.exe /q
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [Glary Memory Optimizer] "C:\Program Files\Glary Utilities\memdefrag.exe" /autostart
    O4 - HKCU\..\Run: [Livestation] C:\Program Files\Livestation\Livestation.exe -startup
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
    O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
    O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O13 - Gopher Prefix:
    O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} (System Requirements Lab Class) - http://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab
    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_1_0.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
    O23 - Service: BitDefender Serveur Arrakis (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
    O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - https://sourceforge.net/p/libusb-win32/wiki/Home/ - C:\Windows\system32\libusbd-nt.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
    0
  9. Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   667
     
    Sous 7, il faut désactiver l'UAC (controle descomptes utilisateurs), tu le réactiveras à la fin de la désinfection

    Désactiver l'UAC sous 7

    --------------------

    Il faut avant tout désactiver le tea-timer de Spybot qui risque de génér les différents scan, tu le remettras si tu veux à la fin de la désinfection, mais il faudra alors accépter toutes les modifications de registre qu'il te proposera....

    désactive le tea-timer de spybot, suis ce lien et cliques sur - " desactiver le the-timer "

    http://perso.orange.fr/rginformatique/section%20virus/demo%20spybot.htm

    ---------------------

    Télécharge UsbFix sur ton bureau

    branche tes supports amovibles (clé usb, disque dur externe, etc) sans les ouvrir

    # Double-clique sur le raccourci UsbFix présent sur ton bureau.

    -Tape F pour français , et presse enter pour valider

    # Le menu apparait, choisi l'option 1 ( recherche )

    # Laisse l'outil travailler

    # Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

    Note : le rapport est également à C:\USBFix.txt

    Un tutoriel : http://pagesperso-orange.fr/nostools/usbfix.html
    0
  10. Cirth
     
    ############################## | UsbFix V6.086 |

    User : Cirth (Administrateurs) # CIRTH-PC
    Update on 03/02/2010 by El Desaparecido , C_XX & Chimay8
    Start at: 17:41:10 | 03/02/2010
    Website : http://pagesperso-orange.fr/NosTools/index.html
    Contact : FindyKill.Contact@gmail.com

    Pentium(R) Dual-Core CPU E6300 @ 2.80GHz
    Microsoft Windows 7 Édition Intégrale (6.1.7100 32-bit) #
    Internet Explorer 8.0.7100.0
    Windows Firewall Status : Disabled
    AV : Antivirus BitDefender 12.0 [ Enabled | Updated ]
    FW : Pare-feu BitDefender [ Enabled ]12.0

    C:\ -> Disque fixe local # 596,07 Go (130,05 Go free) # NTFS
    D:\ -> Disque CD-ROM
    E:\ -> Disque fixe local
    H:\ -> Disque fixe local # 298,02 Go (143,58 Go free) [My Passport] # FAT32
    I:\ -> Disque fixe local # 181,8 Go (145,56 Go free) [Volume] # NTFS
    Z:\ -> Disque CD-ROM

    ############################## | Processus actifs |

    C:\Windows\System32\smss.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\winlogon.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\libusbd-nt.exe
    C:\Windows\system32\PnkBstrA.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\Razer\Reclusa\razerhid.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\GameShadow\GameShadow.exe
    C:\Program Files\Glary Utilities\memdefrag.exe
    C:\Program Files\Razer\Reclusa\razertra.exe
    C:\Program Files\NETGEAR\WPN111\wpn111.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Program Files\Secunia\PSI\psi.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
    C:\Windows\servicing\TrustedInstaller.exe
    C:\Windows\system32\conhost.exe
    \\?\C:\Windows\system32\wbem\WMIADAP.EXE
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    ################## | Elements infectieux |

    ################## | Registre |

    ################## | Mountpoints2 |

    HKCU\..\..\Explorer\MountPoints2\E
    shell\AutoRun\command =E:\BSAutoRun.exe

    ################## | ! Fin du rapport # UsbFix V6.086 ! |
    0
  11. Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   667
     
    Bonjour,

    branche tes supports amovibles (clé Usb, DD externe, etc.) et clique sur OK .

    -Tape F pour français , et presse enter pour valider

    # Le menu apparait, choisi l'option 2 ( Suppression )

    # Ton bureau disparaitra et le pc redémarrera .

    # Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

    # Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

    Note : le rapport est également à C:\USBFix.txt

    ....

    Télécharge Malwarebytes' Anti-Malware :
    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

    - Installe le > double-clic sur Mbam-setup.exe, à la fin de l'installation, il se mettra automatiquement à jour
    - Une fois installé, fermes toutes les applications en cours et lances Malwarebytes
    - Exécutes un examen rapide du pc ( tu n'auras pas accés à internet pendant l'analyse)
    - A la fin du scan clic sur " Afficher les résultats ", si Malwarebytes a trouvé des infections >> clic sur " Supprimer la sélection "
    - Si il a besoin de redémarrer le pc pour finir la désinfection, acceptes
    - Un rapport s'établira, postes son contenu.
    .
    0
  12. Cirth
     
    Bonjour,

    Voici les 2 rapports :

    Usb fix :

    ############################## | UsbFix V6.086 |

    User : Cirth (Administrateurs) # CIRTH-PC
    Update on 03/02/2010 by El Desaparecido , C_XX & Chimay8
    Start at: 11:27:33 | 05/02/2010
    Website : http://pagesperso-orange.fr/NosTools/index.html
    Contact : FindyKill.Contact@gmail.com

    Pentium(R) Dual-Core CPU E6300 @ 2.80GHz
    Microsoft Windows 7 Édition Intégrale (6.1.7100 32-bit) #
    Internet Explorer 8.0.7100.0
    Windows Firewall Status : Disabled
    AV : Antivirus BitDefender 12.0 [ Enabled | Updated ]
    FW : Pare-feu BitDefender [ Enabled ]12.0

    C:\ -> Disque fixe local # 596,07 Go (123,4 Go free) # NTFS
    D:\ -> Disque CD-ROM
    E:\ -> Disque fixe local
    H:\ -> Disque fixe local # 298,02 Go (143,58 Go free) [My Passport] # FAT32
    I:\ -> Disque fixe local # 181,8 Go (145,56 Go free) [Volume] # NTFS
    Z:\ -> Disque CD-ROM

    ############################## | Processus actifs |

    C:\Windows\System32\smss.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\winlogon.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    C:\Windows\system32\LogonUI.exe
    C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\libusbd-nt.exe
    C:\Windows\system32\PnkBstrA.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\servicing\TrustedInstaller.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\userinit.exe
    C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\runonce.exe
    C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
    C:\Windows\system32\conhost.exe

    ################## | Elements infectieux |

    Supprimé ! C:\$Recycle.Bin\S-1-5-20
    Supprimé ! C:\$Recycle.Bin\S-1-5-21-2531296791-2081128194-250223863-1000
    Supprimé ! I:\$Recycle.Bin\S-1-5-21-2531296791-2081128194-250223863-1000

    ################## | Registre |

    ################## | Mountpoints2 |

    Supprimé ! HKCU\...\Explorer\MountPoints2\E\Shell\AutoRun\Command

    ################## | Listing des fichiers présent |

    [20/03/2009 16:42|--a------|24] C:\autoexec.bat
    [29/01/2010 00:39|--a------|45788] C:\bdlog.txt
    [20/03/2009 16:42|--a------|10] C:\config.sys
    [31/12/2009 18:38|--a------|227] C:\CtDrvIns.log
    [31/12/2009 18:59|--a------|202] C:\CtDrvStp.log
    [?|?|?] C:\hiberfil.sys
    [31/01/2010 10:01|-rahs----|0] C:\IO.SYS
    [31/01/2010 10:01|-rahs----|0] C:\MSDOS.SYS
    [?|?|?] C:\pagefile.sys
    [05/02/2010 11:32|--a------|3132] C:\UsbFix.txt
    [24/04/2004 12:38|--a------|37888] H:\JSTART.exe
    [18/07/2008 11:23|--a------|319488] H:\Setup.exe
    [16/07/2008 09:14|--a------|42760] H:\WDInstaller.xml
    [08/07/2008 11:53|--a------|1760039] H:\WDSetup.exe
    [13/11/2008 11:56|--a------|46] H:\wdEULA.log
    [13/11/2008 11:56|--a------|14] H:\wdstatus.log
    [13/11/2008 11:58|--a------|89] H:\wdinstaller.log
    [30/05/2008 09:31|--ah-----|54] H:\autorun.in_2.org
    [13/11/2008 16:13|--a------|3827785] H:\WDSync.zip
    [13/02/2008 11:46|--a------|4523520] H:\WDSync_v7_1_020.exe

    ################## | Vaccination |

    # C:\autorun.inf -> Dossier créé par UsbFix.
    # H:\autorun.inf -> Dossier créé par UsbFix.
    # I:\autorun.inf -> Dossier créé par UsbFix.

    ################## | Upload |

    Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_Cirth-PC.zip : https://www.ionos.fr/?affiliate_id=77097
    Merci pour votre contribution .

    ################## | ! Fin du rapport # UsbFix V6.086 ! |

    Maleware Bytes :

    Malwarebytes' Anti-Malware 1.43
    Version de la base de données: 3497
    Windows 6.1.7100
    Internet Explorer 8.0.7100.0

    05/02/2010 11:48:03
    mbam-log-2010-02-05 (11-48-03).txt

    Type de recherche: Examen rapide
    Eléments examinés: 94781
    Temps écoulé: 4 minute(s), 34 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0