Supprimer wuauclt.exe sur XP

Bonjour,

Après avoir cherché, je pense que ce .exe est un trojan, comment le retirer efficacement ?

Merci,

10 réponses

  1. Salut ,

    ~~~~~~~~~~~~~~~~> RSIT <~~~~~~~~~~~~~~~~~~~

    • Télécharger Random's System Information Tool (RSIT) sur le Bureau.

    › http://images.malwareremoval.com/random/RSIT.exe

    • Double-cliquer sur RSIT.exe afin de lancer le programme (Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur).

    • Cliquer sur Continue à l'écran Disclaimer.

    • Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autoriser l'accès dans le pare-feu, si demandé) et vous devrez accepter la licence.

    • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poster le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que vous verrez dans la barre des tâches)
    3
    1. c'est un updater pour windows ME mais j'ai XP ... étrange ou normal ?
      2
      1. NORMAL windows update est installé sur Xp
        2
        1. Bonsoir,

          faites-le avec un antivirus et uniquement en mode sans échec sans prise en charge réseau
          1
          1. wuauclt.exe n'est pas un TROJAN ... c'est Windows Update wuauclt signifiant Windows Update client for WindowsME (les mises a jour quoi)

            donc pas d'inquiétude

            Maintenant si tu est SUR que c'est un trojan (il ne se trouve pas dans un bon endroit pas exemple) tu peut le supprimer DEFINITIVEMENT avec Eraser (https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/6615.html) ce logiciel gratuit Efface COMPLETEMENT le fichier (il repase 35x sur le fichier grace a un systeme d'équation tres compliqué ... bref apres tu fait clic droit sur ton fichier et ERASE

            voila
            0
            1. info.txt logfile of random's system information tool 1.06 2009-10-11 19:39:20

              ======Uninstall list======

              -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
              Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
              Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
              Adobe Reader 9.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
              AMD Processor Driver-->C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe -runfromtemp -l0x0009 -removeonly
              AutoHotkey 1.0.48.05-->C:\Program Files\AutoHotkey\uninst.exe
              avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
              BetClic Poker-->C:\PROGRA~1\BETCLI~1\UNWISE.EXE C:\PROGRA~1\BETCLI~1\INSTALL.LOG
              CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
              COMODO Internet Security-->C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe -u
              EVEREST Ultimate Edition v5.02-->"C:\Program Files\Lavalys\EVEREST Ultimate Edition\unins000.exe"
              Geonaute KeyMaze 300-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{35DFE767-D0DB-4228-A64E-7E6D50B6FEA4}\Setup.exe"
              Google Chrome-->"C:\Program Files\Google\Chrome\Application\3.0.195.25\Installer\setup.exe" --uninstall --system-level
              Google Earth-->MsiExec.exe /X{3A05B900-A3E7-11DE-A9B7-005056806466}
              Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
              HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
              Holdem Manager-->MsiExec.exe /I{42DE940E-8037-4266-9FBF-5A3AEDA39E96}
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
              Java(TM) 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
              Logitech SetPoint 5.20-->MsiExec.exe /I{D3120436-1358-4253-9EB2-257FFE8CE1D9}
              Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
              Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
              Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
              Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
              Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
              Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
              Microsoft Money 2007 Home & Business-->"C:\Program Files\Microsoft Money 2007\MNYCoreFiles\Setup\uninst.exe" /s:120
              Microsoft Money Shared Libraries-->MsiExec.exe /X{5F00DF7E-418B-4CD9-8EC5-781156BCC49E}
              Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
              Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
              Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
              Mozilla Firefox (3.0.14)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
              Mozilla Thunderbird (2.0.0.23)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
              NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
              NVIDIA ForceWare Network Access Manager-->"C:\Program Files\InstallShield Installation Information\{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}\setup.exe" -runfromtemp -l0x0409 -removeonly
              NVIDIA ForceWare Network Access Manager-->MsiExec.exe /I{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}
              NVIDIA nView Desktop Manager-->C:\Program Files\NVIDIA Corporation\nView\nViewSetup.exe -uninstall
              OGA Notifier 2.0.0048.0-->MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
              OpenOffice.org 3.1-->MsiExec.exe /I{0FA44E79-CD7D-4E8D-A2EE-26FE05F509B6}
              Pacific Poker-->C:\PROGRA~1\PACIFI~1\UNWISE.EXE C:\PROGRA~1\PACIFI~1\INSTALL.LOG
              PartyPoker-->"C:\Program Files\PartyGaming\PartyPoker\Uninstall.exe" "C:\Program Files\PartyGaming\PartyPoker\install.log"
              PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
              pdfsam 0.7b1-->C:\Program Files\pdfsam\uninst.exe
              PL-2303 USB-to-Serial-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\Setup.exe" -l0x9 Installed
              PokerStove version 1.23-->"C:\Program Files\PokerStove\unins000.exe"
              PostgreSQL 8.4-->C:\Program Files\PostgreSQL\8.4\uninstall-postgresql.exe
              Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
              RedKings Poker-->"C:\RedKings\unins000.exe"
              Security Update for Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
              Security Update for Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
              Security Update for Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
              Security Update for Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
              Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
              System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
              Ubuntu-->C:\ubuntu\Uninstall-Ubuntu.exe
              Unibet-->C:\MicroGaming\Poker\unibetpokerMPP\install.exe -uninstall
              Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
              Update for Windows Internet Explorer 8 (KB973874)-->"C:\WINDOWS\ie8updates\KB973874-IE8\spuninst\spuninst.exe"
              Vuze-->C:\Program Files\Vuze\uninstall.exe
              WiFi Station-->C:\Program Files\InstallShield Installation Information\{DECE22F4-EEDD-4615-BC56-2F4827FAD64B}\setup.exe -runfromtemp -l0x0009 -removeonly
              Winamax-->"C:\Winamax\unins000.exe"
              Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
              Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"

              ======Hosts File======

              127.0.0.1 www.007guard.com
              127.0.0.1 007guard.com
              127.0.0.1 008i.com
              127.0.0.1 www.008k.com
              127.0.0.1 008k.com
              127.0.0.1 www.00hq.com
              127.0.0.1 00hq.com
              127.0.0.1 010402.com
              127.0.0.1 www.032439.com
              127.0.0.1 032439.com

              ======Security center information======

              AV: avast! antivirus 4.8.1356 [VPS 091010-0]
              FW: COMODO Firewall

              ======System event log======

              Computer Name: ----------
              Event Code: 1000
              Message: Your computer has lost the lease to its IP address 192.168.0.13 on the
              Network Card with network address 001966D81F65.

              Record Number: 306
              Source Name: Dhcp
              Time Written: 20090911043307.000000+120
              Event Type: error
              User:

              Computer Name: ----------
              Event Code: 1003
              Message: Your computer was not able to renew its address from the network (from the
              DHCP Server) for the Network Card with network address 001966D81F65. The following
              error occurred:
              The semaphore timeout period has expired.
              .
              Your computer will continue to try and obtain an address on its own from
              the network address (DHCP) server.

              Record Number: 305
              Source Name: Dhcp
              Time Written: 20090911043307.000000+120
              Event Type: warning
              User:

              Computer Name: ----------
              Event Code: 10016
              Message: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
              {BC866CF2-5486-41F7-B46B-9AA49CF3EBB1}
              to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19). This security permission can be modified using the Component Services administrative tool.

              Record Number: 303
              Source Name: DCOM
              Time Written: 20090910192808.000000+120
              Event Type: error
              User: NT AUTHORITY\LOCAL SERVICE

              Computer Name: ----------
              Event Code: 10016
              Message: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
              {BC866CF2-5486-41F7-B46B-9AA49CF3EBB1}
              to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19). This security permission can be modified using the Component Services administrative tool.

              Record Number: 286
              Source Name: DCOM
              Time Written: 20090910190247.000000+120
              Event Type: error
              User: NT AUTHORITY\LOCAL SERVICE

              Computer Name: ----------
              Event Code: 10016
              Message: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
              {BC866CF2-5486-41F7-B46B-9AA49CF3EBB1}
              to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19). This security permission can be modified using the Component Services administrative tool.

              Record Number: 285
              Source Name: DCOM
              Time Written: 20090910190247.000000+120
              Event Type: error
              User: NT AUTHORITY\LOCAL SERVICE

              =====Application event log=====

              Computer Name: ----------
              Event Code: 63
              Message: A provider, NPU Management Provider, has been registered in the WMI namespace, root\nVIDIA\NS_Eth\NS_EthStat, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

              Record Number: 154
              Source Name: WinMgmt
              Time Written: 20090911044955.000000+120
              Event Type: warning
              User: ----------\Pierre

              Computer Name: ----------
              Event Code: 63
              Message: A provider, NPU Management Provider, has been registered in the WMI namespace, root\nVIDIA\NS_Eth\NS_EthStat, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

              Record Number: 153
              Source Name: WinMgmt
              Time Written: 20090911044955.000000+120
              Event Type: warning
              User: ----------\Pierre

              Computer Name: ----------
              Event Code: 63
              Message: A provider, NPU Management Provider, has been registered in the WMI namespace, root\nVIDIA\NS_Eth\NS_EthConfig, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

              Record Number: 152
              Source Name: WinMgmt
              Time Written: 20090911044955.000000+120
              Event Type: warning
              User: ----------\Pierre

              Computer Name: ----------
              Event Code: 63
              Message: A provider, NPU Management Provider, has been registered in the WMI namespace, root\nVIDIA\NS_Eth\NS_EthConfig, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

              Record Number: 151
              Source Name: WinMgmt
              Time Written: 20090911044955.000000+120
              Event Type: warning
              User: ----------\Pierre

              Computer Name: ----------
              Event Code: 63
              Message: A provider, NPU Management Provider, has been registered in the WMI namespace, root\nVIDIA\NS_Eth\NS_EthConfig, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

              Record Number: 150
              Source Name: WinMgmt
              Time Written: 20090911044955.000000+120
              Event Type: warning
              User: ----------\Pierre

              ======Environment variables======

              "ComSpec"=%SystemRoot%\system32\cmd.exe
              "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
              "windir"=%SystemRoot%
              "FP_NO_HOST_CHECK"=NO
              "OS"=Windows_NT
              "PROCESSOR_ARCHITECTURE"=x86
              "PROCESSOR_LEVEL"=16
              "PROCESSOR_IDENTIFIER"=x86 Family 16 Model 6 Stepping 2, AuthenticAMD
              "PROCESSOR_REVISION"=0602
              "NUMBER_OF_PROCESSORS"=2
              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
              "TEMP"=%SystemRoot%\TEMP
              "TMP"=%SystemRoot%\TEMP

              -----------------EOF-----------------

              Logfile of random's system information tool 1.06 (written by random/random)
              Run by Pierre at 2009-10-11 19:38:55
              Microsoft Windows XP Professional Service Pack 3
              System drive C: has 187 GB (78%) free of 238 GB
              Total RAM: 1535 MB (62% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 19:39:12, on 11/10/2009
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
              C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\RTHDCPL.EXE
              C:\WINDOWS\system32\RUNDLL32.EXE
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Hercules\WiFi Station\WifiStation.exe
              C:\WINDOWS\system32\msiexec.exe
              C:\Program Files\Mozilla Thunderbird\thunderbird.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Documents and Settings\Pierre\My Documents\Téléchargements\RSIT.exe
              C:\Program Files\trend micro\Pierre.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
              O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
              O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
              O4 - HKUS\S-1-5-21-1390067357-1450960922-1801674531-1005\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'postgres')
              O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
              O4 - Global Startup: WiFi Station.lnk = ?
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
              O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra button: Unibet - {00000000-0000-0000-0000-000000000000} - C:\MicroGaming\Poker\unibetpokerMPP\MPPoker.exe (HKCU)
              O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
              O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
              O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
              O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
              O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - https://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
              O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
              O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
              O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
              O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
              O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: PostgreSQL Server 8.4 (postgresql-8.4) - PostgreSQL Global Development Group - C:/Program Files/PostgreSQL/8.4/bin/pg_ctl.exe
              0
              1. Wuauclt.exe n'est pas un TROJAN ... c'est Windows Update wuauclt signifiant Windows Update client for WindowsME (les mises a jour quoi)

                donc pas d'inquiétude

                Maintenant si tu est SUR que c'est un trojan (il ne se trouve pas dans un bon endroit pas exemple) tu peut le supprimer DEFINITIVEMENT avec Eraser (https://www.01net.com/404/­urs_et_installeurs/fiches/6615.html) ce logiciel gratuit Efface COMPLETEMENT le fichier (il repase 35x sur le fichier grace a un systeme d'équation tres compliqué ... bref apres tu fait clic droit sur ton fichier et ERASE

                voila
                0
                1. j'ai résolu le problème ! je suis pas une pro de l'informatique, je précise!!! mais ça a fonctionné! mais j'ai lu que c'est un "processus" et j'ai fait une relation avec les processus que l'on voit quand on fait une "ctrl" "alt" et delete consécutivement! on a "le gestionnaire des taches" qui s'affiche, il suffit de cliquer sur l'onglet "PROCESSUS " et de rechercher ce fameux "wuauclt.exe" dans la liste! de le supprimer et le sélectionnant et en cliquant sur terminer le processus ! donc je récapitule! parce que je sais que c'est peut être pas trop clair quand on s'y connais pas comme moi , et qu'on cherche dans la panique un moyen de résoudre le soucis!
                  1) appuyé sur "ctrl" "alt" "delete"
                  2) choisissez l'onglet "processus"
                  3) sélectionner ce fichu "wuauclt.exe"
                  4)appuyez sur "terminer le processus"
                  5) soufflez c'est fini..
                  0
                  1. c'est faux. cette manip' arrête le processus et ne le supprime pas.
                    0
                  2. super nan..., et tu recommences comme ca tous les jours à chaque fois que tu redémarres ton pc ? A mon avis, ce n'est pas la bonne méthode !
                    0