Rootkit dans mon PC

Résolu
Bonjour à tous,
Voilà depuis quelques temps, Avast! me détecte un Rootkit.
J'ai téléchargé Sophos mais il ne le détecte pas.
Quelqu'un peut m'aider, s'il vous plaît?

Merci d'avance
Configuration: Windows XP / Internet Explorer 7.0

55 réponses

Résumé de la discussion

Une détection de rootkit sur Windows XP avec Internet Explorer 7 survient lorsque Avast! avertit, alors que Sophos ne parvient pas à identifier la menace, créant une discordance dans le diagnostic et les démarches. Des conseils recommandent d'exécuter OTL (OLDTimer) et de générer un rapport OTL.txt pour diagnostiquer le rootkit et l'infection, puis de partager le fichier via des liens publics afin d'obtenir une aide rapide. Des mesures ajoutées incluent l'utilisation de ComboFix, l'analyse Find3M et JavaRa pour nettoyer les composants indésirables et afficher les éléments malveillants restants, avec des rapports détaillés fournis. En outre, certains échanges mentionnent la désactivation temporaire du pare-feu et de l'antivirus pour faciliter le nettoyage, suivi d'une réactivation et d'une vérification de l'intégrité du système.

Bobot (l’IA à votre service)
  1. bonjour

    on va analyser ton pc.

    Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

    -> http://images.malwareremoval.com/random/RSIT.exe

    ! Déconnecte toi et ferme toutes tes applications en cours !

    Double-clique sur " RSIT.exe " pour le lancer .

    -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

    * Devant l'option "List files/folders created ..." , tu choisis : 2 months

    * clique ensuite sur " Continue " pour lancer l'analyse ...

    -> laisse faire le scan et ne touche pas au PC ...

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

    Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

    Important : poste un rapport, puis l'autre dans la réponse suivante
    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

    ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
    0
    1. D'abord merci de m'aider.
      Voici le premier rapport log.txt

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by HP_Propriétaire at 2010-03-12 17:57:16
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 113 GB (77%) free of 147 GB
      Total RAM: 511 MB (50% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 17:57:55, on 12/03/2010
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\windows\system\hpsysdrv.exe
      C:\WINDOWS\system32\hphmon06.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
      C:\WINDOWS\system32\keyhook.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\ALCXMNTR.EXE
      C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\QuickTime\QTTask.exe
      C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
      C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\SuperCopier2\SuperCopier2.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Rainlendar2\Rainlendar2.exe
      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
      C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\system32\cisvc.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\alg.exe
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\WINDOWS\system32\cidaemon.exe
      C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
      C:\PROGRA~1\Wanadoo\WOOBRO~1\DownloadManager.exe
      C:\DOCUME~1\HP_PRO~1\Bureau\rsit.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Program Files\trend micro\HP_Propriétaire.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/...
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/...
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/...
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/...
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
      O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe"
      O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
      O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
      O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
      O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\Pavilion\XPHWWBF4\plugin\bin\PCHButton.exe
      O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; Orange 7.4 ; NaviWoo1.1; .NET CLR 1.1.4322; InfoPath.1)" -"http://www8.agame.com/games/shockwave/b/boarder_xl/jeu_fr/boarder_xl_jeu_fr.html"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
      O16 - DPF: {5392B545-31A5-4724-BEF3-4FED1D56FDAC} (CPlayFirstDinerDash2_frControl Object) - file:///C:/Documents%20and%20Settings/HP_Propriétaire/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/DinerDash2_fr.1.0.0.70.cab
      O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.extrafilm.fr/ImageUploader5.cab
      O16 - DPF: {6EBC6744-5383-4213-AD5E-66434ECA1812} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/nordnet/orange/so-4.1/resources/fslauncher.cab
      O16 - DPF: {775879E2-7309-4619-BB02-AADE41F4B690} (CPlayFirstdreamControl Object) - http://jeuxenligne.orange.fr/...
      O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
      O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - file:///C:/Documents%20and%20Settings/HP_Propriétaire/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/ddfotg.1.0.0.37.cab
      O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://www.gamehouse.com/games/zylom/zylomplayer.cab
      O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
      O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - file:///C:/Documents%20and%20Settings/HP_Propriétaire/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/DinerDash.1.0.0.98.cab
      O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - file:///C:/Documents%20and%20Settings/HP_Propriétaire/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/popcaploader_v10.cab
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
      O16 - DPF: {F135A813-7152-4532-AC8D-28AC2136DFC7} (CPlayFirstParkingDasControl Object) - http://jeuxenligne.orange.fr/...
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      0
      1. Et voici le second rapportinfo.txt

        info.txt logfile of random's system information tool 1.06 2010-03-12 17:58:00

        ======Uninstall list======

        -->"C:\Program Files\InstallShield Installation Information\{1A91D1FA-B9B3-4556-9878-5C61059A19B2}\setup.exe" REMOVEALL
        -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
        -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\Setup.exe"
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{89AD2814-AFA2-46AF-AE53-C27196D9FBE6}\setup.exe" REMOVEALL
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\Setup.exe"
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AAA4CCCE-78DB-47B0-A651-68270D838BD4}\setup.exe" REMOVEALL
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\Setup.exe"
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E06E4F4E-72D6-4497-BFFD-BCB43077C2F4}\setup.exe" -l0x40c -uninst
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
        Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
        Adobe SVG Viewer 3.0-->C:\Program Files\Fichiers communs\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Fichiers communs\Adobe\SVG Viewer 3.0\Uninstall\Install.log
        Adobe® Photoshop® Album Edition Découverte 3.0-->MsiExec.exe /I{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}
        Agere Systems PCI Soft Modem-->agrsmdel
        Apple Mobile Device Support-->MsiExec.exe /I{AFA20D47-69C3-4030-8DF8-D37466E70F13}
        Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
        ArcSoft PhotoImpression 6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8DE40268-220A-4AF6-90EC-09966CBE8772}\Setup.exe" -l0x40c
        ArcSoft PhotoStudio 5.5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{230CCBE9-14B0-4008-97AF-30C10F99E42C}\setup.exe" -l0x40c
        Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
        avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
        Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
        CanoScan Toolbox 4.5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{143FB15C-0C48-41E3-9C30-F56FB69BF3D7}\setup.exe" -l0x40c anything
        Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
        Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB979306)-->"C:\WINDOWS\$NtUninstallKB979306$\spuninst\spuninst.exe"
        Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
        Gestionnaire Internet-->C:\PROGRA~1\Wanadoo\uninstall.exe
        Help and Support Additions-->C:\PROGRA~1\HELPAN~1\UNWISE.EXE C:\PROGRA~1\HELPAN~1\INSTALL.LOG
        High Definition Audio Driver Package - KB835221-->C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
        HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
        Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
        HP Deskjet Preloaded Printer Drivers-->MsiExec.exe /X{F419D20A-7719-4639-8E30-C073A040D878}
        HP Image Zone 4.2-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
        HP Image Zone Plus 4.2-->C:\Program Files\HP\Digital Imaging\{5E1494D4-3562-4FFB-B35C-600F80F6934C}\setup\hpzscr01.exe -datfile hpdscr01.dat
        HP PSC & OfficeJet 4.0-->"C:\Program Files\HP\Digital Imaging\{A1062847-0846-427A-92A1-BB8251A91E91}\setup\hpzscr01.exe" -datfile hposcr04.dat
        HP Software Update-->MsiExec.exe /X{457791C5-D702-4143-A7B2-2744BE9573F2}
        HPIZ402-->MsiExec.exe /X{8D9768AE-DE42-4A04-A461-2361A58C384D}
        Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
        Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
        InterVideo Home Theater-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F7514465-E5F3-48E9-A952-327DAEF33DE6}\setup.exe" REMOVEALL
        InterVideo WinDVD Creator 2-->"C:\Program Files\InstallShield Installation Information\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}\setup.exe" REMOVEALL
        InterVideo WinDVD Player-->"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
        iTunes-->MsiExec.exe /I{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}
        IZArc 3.81-->"C:\Program Files\IZArc\unins000.exe"
        Java 2 Runtime Environment, SE v1.4.2_03-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
        Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
        Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
        Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
        KBD-->C:\HP\KBD\KBD.EXE uninstalled
        Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
        livebox-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe" -l0x40c
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
        Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
        Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
        Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
        Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
        Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
        Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
        Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB974455)-->"C:\WINDOWS\ie7updates\KB974455-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB976325)-->"C:\WINDOWS\ie7updates\KB976325-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB978207)-->"C:\WINDOWS\ie7updates\KB978207-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB978207)-->"C:\WINDOWS\ie8updates\KB978207-IE8\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB975561)-->"C:\WINDOWS\$NtUninstallKB975561$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB977165)-->"C:\WINDOWS\$NtUninstallKB977165$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB978251)-->"C:\WINDOWS\$NtUninstallKB978251$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB978262)-->"C:\WINDOWS\$NtUninstallKB978262$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB978706)-->"C:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe"
        Mise à jour pour Windows Internet Explorer 7 (KB976749)-->"C:\WINDOWS\ie7updates\KB976749-IE7\spuninst\spuninst.exe"
        Mise à jour pour Windows Internet Explorer 8 (KB976662)-->"C:\WINDOWS\ie8updates\KB976662-IE8\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
        Monopoly-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Hasbro Interactive\Monopoly\Uninst.isu"
        Mozilla Firefox (2.0)-->C:\Program Files\Mozilla Firefox\uninstall\uninst.exe
        MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
        Navigateur Orange-->C:\PROGRA~1\Wanadoo\Shell.exe inst\uninst_FTBrowser.shl
        Navman F20 Service Pack-->C:\Program Files\InstallShield Installation Information\{D972C4DC-0E76-4698-A2B4-ABEFA25FFB9E}\setup.exe -runfromtemp -l0x040c -removeonly
        Norton Internet Security-->MsiExec.exe /I{F396D99B-1FA8-4ED1-A006-B7A5972E06E2}
        NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
        OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
        PC-Doctor pour Windows-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\Setup.exe"
        Photo et imagerie HP 3.5 - HP Devices-->C:\Program Files\HP\Digital Imaging\{15B9DC72-73F9-4d99-9E28-848D66DA8D99}\setup\hpzscr01.exe -datfile hpiscr01.dat
        Photosmart 320,370,7400,8100,8400 Series (fra)-->C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\setup\hpzscr01.exe -datfile hphscr01.dat
        Print Artist 2004-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Sierra\Print Artist 2004\HiUninst.isu" -c"C:\Program Files\Sierra\Print Artist 2004\Uninstpa.DLL"
        PS2-->C:\WINDOWS\system32\ps2.exe uninstall
        Python 2.2 combined Win32 extensions-->C:\Python22\Lib\SITE-P~1\UNWISE~1.EXE C:\Python22\Lib\SITE-P~1\w32inst.log
        Python 2.2.1-->C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG
        QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
        Rainlendar2 (remove only)-->"C:\Program Files\Rainlendar2\uninst.exe"
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
        SierraAddressBook 3.0-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7CE979C6-E5FF-41C5-B6CC-4EE18071563B}\Setup.exe" -l0x40c
        SiS VGA Utilities-->Rundll32 SiSInst.dll,Uninstall VGA,R
        Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
        Sony Ericsson PC Suite 1.20.224-->MsiExec.exe /I{7689CA7A-1270-425A-9959-EB4CB25EA29A}
        Sophos Anti-Rootkit 1.5.0-->C:\Program Files\Sophos\Sophos Anti-Rootkit\helper.exe remove
        SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
        Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
        Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
        Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
        Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
        Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
        Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
        Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
        Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

        ======Security center information======

        AV: avast! antivirus 4.8.1296 [VPS 100311-1]

        ======System event log======

        Computer Name: NOM-641695C7437
        Event Code: 7023
        Message: Le service Gestion d'applications s'est arrêté avec l'erreur :
        Le module spécifié est introuvable.

        Record Number: 24008
        Source Name: Service Control Manager
        Time Written: 20100116082313.000000+060
        Event Type: erreur
        User:

        Computer Name: NOM-641695C7437
        Event Code: 7036
        Message: Le service Gestion d'applications est entré dans l'état : arrêté.

        Record Number: 24007
        Source Name: Service Control Manager
        Time Written: 20100116082313.000000+060
        Event Type: Informations
        User:

        Computer Name: NOM-641695C7437
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Gestion d'applications.

        Record Number: 24006
        Source Name: Service Control Manager
        Time Written: 20100116082313.000000+060
        Event Type: Informations
        User: NOM-641695C7437\HP_Propriétaire

        Computer Name: NOM-641695C7437
        Event Code: 7023
        Message: Le service Gestion d'applications s'est arrêté avec l'erreur :
        Le module spécifié est introuvable.

        Record Number: 24005
        Source Name: Service Control Manager
        Time Written: 20100116082313.000000+060
        Event Type: erreur
        User:

        Computer Name: NOM-641695C7437
        Event Code: 7036
        Message: Le service Gestion d'applications est entré dans l'état : arrêté.

        Record Number: 24004
        Source Name: Service Control Manager
        Time Written: 20100116082313.000000+060
        Event Type: Informations
        User:

        =====Application event log=====

        Computer Name: NOM-641695C7437
        Event Code: 1800
        Message: Le service Centre de sécurité Windows a démarré.

        Record Number: 3132
        Source Name: SecurityCenter
        Time Written: 20090512112503.000000+120
        Event Type: Informations
        User:

        Computer Name: NOM-641695C7437
        Event Code: 1
        Message:
        Record Number: 3131
        Source Name: Bonjour Service
        Time Written: 20090512112502.000000+120
        Event Type: Informations
        User:

        Computer Name: NOM-641695C7437
        Event Code: 2002
        Message:
        Record Number: 3130
        Source Name: EAPOL
        Time Written: 20090511095027.000000+120
        Event Type: Informations
        User:

        Computer Name: NOM-641695C7437
        Event Code: 2003
        Message:
        Record Number: 3129
        Source Name: EAPOL
        Time Written: 20090511095027.000000+120
        Event Type: Informations
        User:

        Computer Name: NOM-641695C7437
        Event Code: 0
        Message:
        Record Number: 3128
        Source Name: iPod Service
        Time Written: 20090511095020.000000+120
        Event Type: Informations
        User:

        =====Security event log=====

        Computer Name: NOM-641695C7437
        Event Code: 576
        Message: Privilèges spéciaux assignés à la nouvelle session :

        Utilisateur :

        Domaine :

        Id. de la session : (0x0,0x3E5)

        Privilèges : SeAuditPrivilege
        SeAssignPrimaryTokenPrivilege
        SeChangeNotifyPrivilege

        Record Number: 45707
        Source Name: Security
        Time Written: 20100216080723.000000+060
        Event Type: Succès de l'audit
        User: AUTORITE NT\SERVICE LOCAL

        Computer Name: NOM-641695C7437
        Event Code: 528
        Message: Ouverture de session réseau réussie :

        Utilisateur : SERVICE LOCAL

        Domaine : AUTORITE NT

        Id. de la session : (0x0,0x3E5)

        Type de session : 5

        Processus de session : Advapi

        Package d'authentification : Negotiate

        Station de travail :

        GUID d'ouv. de session : -

        Record Number: 45706
        Source Name: Security
        Time Written: 20100216080723.000000+060
        Event Type: Succès de l'audit
        User: AUTORITE NT\SERVICE LOCAL

        Computer Name: NOM-641695C7437
        Event Code: 576
        Message: Privilèges spéciaux assignés à la nouvelle session :

        Utilisateur : SERVICE RÉSEAU

        Domaine : AUTORITE NT

        Id. de la session : (0x0,0x3E4)

        Privilèges : SeAuditPrivilege
        SeAssignPrimaryTokenPrivilege
        SeChangeNotifyPrivilege

        Record Number: 45705
        Source Name: Security
        Time Written: 20100216080723.000000+060
        Event Type: Succès de l'audit
        User: AUTORITE NT\SERVICE RÉSEAU

        Computer Name: NOM-641695C7437
        Event Code: 528
        Message: Ouverture de session réseau réussie :

        Utilisateur : SERVICE RÉSEAU

        Domaine : AUTORITE NT

        Id. de la session : (0x0,0x3E4)

        Type de session : 5

        Processus de session : Advapi

        Package d'authentification : Negotiate

        Station de travail :

        GUID d'ouv. de session : -

        Record Number: 45704
        Source Name: Security
        Time Written: 20100216080723.000000+060
        Event Type: Succès de l'audit
        User: AUTORITE NT\SERVICE RÉSEAU

        Computer Name: NOM-641695C7437
        Event Code: 576
        Message: Privilèges spéciaux assignés à la nouvelle session :

        Utilisateur :

        Domaine :

        Id. de la session : (0x0,0x3E4)

        Privilèges : SeAuditPrivilege
        SeAssignPrimaryTokenPrivilege
        SeChangeNotifyPrivilege

        Record Number: 45703
        Source Name: Security
        Time Written: 20100216080723.000000+060
        Event Type: Succès de l'audit
        User: AUTORITE NT\SERVICE RÉSEAU

        ======Environment variables======

        "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "FP_NO_HOST_CHECK"=NO
        "NUMBER_OF_PROCESSORS"=1
        "OS"=Windows_NT
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;c:\Python22;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\Fichiers communs\Teleca Shared;C:\Program Files\QuickTime\QTSystem\;C:\Windows\Twain_32\CNQL20
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 12 Stepping 0, AuthenticAMD
        "PROCESSOR_LEVEL"=15
        "PROCESSOR_REVISION"=0c00
        "QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "windir"=%SystemRoot%

        -----------------EOF-----------------
        0
        1. 1)quel est le fichier qu il te dit d infecter?

          2)passe cet antimalware, fait comme indique
          Telecharges malwaresbytes antimalwares(MBAM) : egalement tres util sur pb de pub mais pas tous malheureusement

          Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe

          Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
          fais comme indique,mise a jour , scan complet et le rapport.
          COLLE LE RAPPORT APRES SUPPRESSION MERCI.

          garde le et lance un scan tout les mois comme indique.

          si tu as ad aware tu peux desinstalle car il ne reconnait plus grand chose.

          0
          1. 1) system32 est son nom commence par "gbtx" ou quelque chose comme ça
            0
            1. voici le rapport de malware:

              Malwarebytes' Anti-Malware 1.44
              Version de la base de données: 3860
              Windows 5.1.2600 Service Pack 3
              Internet Explorer 8.0.6001.18702

              12/03/2010 19:29:05
              mbam-log-2010-03-12 (19-28-53).txt

              Type de recherche: Examen complet (C:\|D:\|)
              Eléments examinés: 243239
              Temps écoulé: 1 hour(s), 4 minute(s), 53 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 2
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 1
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 2

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> No action taken.
              HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> No action taken.

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              C:\WINDOWS\system32\drivers\gbtxamc.sys (Rootkit.Agent) -> No action taken.
              C:\Documents and Settings\HP_Propriétaire\Application Data\avdrn.dat (Malware.Trace) -> No action taken.
              0
              1. Après un redémarrage pour suppression du malware, Avast! me dit que le rootkit est tjrs là.

                Détails:

                Nom du fichier:
                C:\Windows\system32\drivers\gbtxamc.sys
                Type:
                services cachés
                Nom du Malware:
                WI\Program Files

                Que pensez-vous de ça? Que dois-je faire?
                0
                1. 1)pour malwarebyte as tu bien tout supprimer? tu me colles le rapport avant suppression.

                  2)si oui passe cela.
                  pour voir télécharge combofix (par sUBs) ici :

                  http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                  et enregistre le sur le bureau.

                  déconnecte toi d'internet et ferme toutes tes applications.

                  désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

                  double-clique sur combofix.exe et suis les instructions

                  à la fin, il va produire un rapport C:\ComboFix.txt

                  réactive ton parefeu, ton antivirus, la garde de ton antispyware

                  copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

                  Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

                  Tu as un tutoriel complet ici :

                  https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
                  0
                  1. J'ai fait ce que tu m'as demandé et je t'envois le rapport de ComboFix:

                    ComboFix 10-03-13.03 - HP_Propriétaire 14/03/2010 14:00:57.1.1 - x86
                    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.511.280 [GMT 1:00]
                    Lancé depuis: c:\documents and settings\HP_Propriétaire\Bureau\combofix.exe
                    AV: avast! antivirus 4.8.1296 [VPS 100313-2] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
                    .

                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    c:\windows\Downloaded Program Files\popcaploader.dll
                    c:\windows\Downloaded Program Files\popcaploader.inf
                    c:\windows\system32\ps2.bat
                    D:\Autorun.inf

                    .
                    ((((((((((((((((((((((((((((( Fichiers créés du 2010-02-14 au 2010-03-14 ))))))))))))))))))))))))))))))))))))
                    .

                    2010-03-12 17:16 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                    2010-03-12 17:16 . 2010-03-12 17:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                    2010-03-12 17:16 . 2010-03-12 17:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                    2010-03-12 17:16 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
                    2010-03-12 16:57 . 2010-03-12 16:57 -------- d-----w- c:\program files\trend micro
                    2010-03-12 16:57 . 2010-03-12 16:58 -------- d-----w- C:\rsit

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2010-03-14 13:15 . 2009-12-12 15:36 802304 ----a-w- c:\windows\system32\drivers\gbtxamc.sys
                    2010-03-14 13:13 . 2008-05-24 08:53 -------- d-----w- c:\program files\Wanadoo
                    2010-02-07 09:15 . 2010-02-07 09:15 -------- d-----w- c:\program files\Sophos
                    2010-01-21 07:33 . 2009-06-06 18:01 -------- d-----w- c:\program files\Microsoft Silverlight
                    2010-01-16 07:22 . 2009-11-26 13:12 -------- d-----w- c:\program files\SimTractor 4.0
                    2010-01-16 07:10 . 2009-03-28 18:26 -------- d-----w- c:\program files\Aqua3D
                    2009-12-31 16:50 . 2008-10-08 19:59 353792 ----a-w- c:\windows\system32\drivers\srv.sys
                    2009-12-21 19:07 . 2004-01-01 20:53 916480 ----a-w- c:\windows\system32\wininet.dll
                    2009-12-17 07:41 . 2008-10-08 20:00 347648 ----a-w- c:\windows\system32\mspaint.exe
                    2009-12-16 10:16 . 2009-12-16 10:16 49152 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\zylom\chocolatier2\fr-FR\ZylomAdapter.dll
                    2009-12-16 10:16 . 2009-12-16 10:16 1757184 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\zylom\chocolatier2\fr-FR\chocolatier2.exe
                    2009-12-15 07:06 . 2004-01-01 20:53 450536 ----a-w- c:\windows\system32\perfh00C.dat
                    2009-12-15 07:06 . 2004-01-01 20:53 65990 ----a-w- c:\windows\system32\perfc00C.dat
                    2006-10-11 08:04 . 2009-05-28 20:37 61036 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
                    2006-10-11 08:04 . 2009-05-28 20:37 48742 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
                    2006-10-11 08:05 . 2009-05-28 20:37 29313 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
                    2006-10-11 08:05 . 2009-05-28 20:37 41082 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
                    2006-10-11 08:04 . 2009-05-28 20:37 166510 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
                    2005-01-30 16:04 . 2008-05-23 00:02 0 -csha-w- c:\windows\SMINST\HPCD.SYS
                    .

                    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                    REGEDIT4

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
                    "WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [2004-08-23 122880]
                    "Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2008-08-24 4067328]
                    "Acme.PCHButton"="c:\progra~1\HELPAN~1\Pavilion\XPHWWBF4\plugin\bin\PCHButton.exe" [2004-01-01 159744]

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
                    "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
                    "HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
                    "HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]
                    "KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 61440]
                    "Home Theater SchSvr"="c:\program files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe" [2004-08-20 155648]
                    "WINREMOTE"="c:\program files\InterVideo\Common\Bin\WinRemote.exe" [2004-06-25 192512]
                    "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
                    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-07-01 4112384]
                    "nwiz"="nwiz.exe" [2004-07-01 843776]
                    "SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2004-05-20 249856]
                    "AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
                    "PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
                    "AlcxMonitor"="ALCXMNTR.EXE" [2003-04-04 50176]
                    "WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-08-23 20480]
                    "WOOTASKBARICON"="c:\progra~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
                    "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
                    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
                    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
                    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
                    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
                    "ArcSoft Connection Service"="c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-07-17 64000]
                    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]

                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                    "DisableMonitoring"=dword:00000001

                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                    "DisableMonitoring"=dword:00000001

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                    "c:\\WINDOWS\\system32\\sessmgr.exe"=
                    "c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
                    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                    "%windir%\\system32\\sessmgr.exe"=
                    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                    "c:\\Documents and Settings\\HP_Propriétaire\\Mes documents\\freezer v1.4 fr\\freezer v1.4 fr\\freezer.exe"=
                    "c:\\Program Files\\iTunes\\iTunes.exe"=
                    "c:\\WINDOWS\\system32\\AlertModule\\AlertModule.exe"=
                    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

                    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [20/11/2008 20:50 111184]
                    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20/11/2008 20:50 20560]
                    R3 PhTVTune;ASUS WDM TV Tuner;c:\windows\system32\drivers\PhTVTune.sys [01/01/2004 15:30 24608]
                    S3 Navcar;Navman In-car Navigator USB Driver Service;c:\windows\system32\drivers\Navcar.sys [12/02/2009 13:25 30329]
                    S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [20/09/2008 13:39 87824]
                    S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [20/09/2008 13:25 85696]

                    --- Autres Services/Pilotes en mémoire ---

                    *Deregistered* - gbtxamc
                    *Deregistered* - mchInjDrv
                    .
                    Contenu du dossier 'Tâches planifiées'

                    2010-03-11 c:\windows\Tasks\AppleSoftwareUpdate.job
                    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
                    .
                    .
                    ------- Examen supplémentaire -------
                    .
                    uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                    uStart Page = hxxp://www.google.fr/
                    mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                    uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                    IE: { - c:\program files\Messenger\msmsgs.exe
                    DPF: {5392B545-31A5-4724-BEF3-4FED1D56FDAC} - file:///C:/Documents%20and%20Settings/HP_Propriétaire/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/DinerDash2_fr.1.0.0.70.cab
                    DPF: {775879E2-7309-4619-BB02-AADE41F4B690} - hxxp://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--9b4e31a2-26b0-4209-92b6-ee687a2aabd4/online/dream_chronicles/fr/dreamweb.1.0.0.9.cab
                    DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://www.gamehouse.com/games/zylom/zylomplayer.cab
                    DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} - file:///C:/Documents%20and%20Settings/HP_Propriétaire/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/DinerDash.1.0.0.98.cab
                    DPF: {F135A813-7152-4532-AC8D-28AC2136DFC7} - hxxp://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--abba468b-bf3e-4f00-9cd9-aaaeccbde8aa/online/parking_dash/fr/parkingdash.1.0.0.15.cab
                    FF - ProfilePath - c:\documents and settings\HP_Propriétaire\Application Data\Mozilla\Firefox\Profiles\bbeqt1m3.default\
                    FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
                    FF - prefs.js: browser.search.selectedEngine - Google
                    FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
                    FF - component: c:\program files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll
                    FF - component: c:\program files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll
                    FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
                    .
                    - - - - ORPHELINS SUPPRIMES - - - -

                    HKLM-Run-VTTimer - VTTimer.exe
                    AddRemove-FranceTelecomUninstall_FTBrowser - c:\progra~1\Wanadoo\Shell.exe inst\uninst_FTBrowser.shl

                    **************************************************************************

                    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2010-03-14 14:12
                    Windows 5.1.2600 Service Pack 3 NTFS

                    Recherche de processus cachés ...

                    Recherche d'éléments en démarrage automatique cachés ...

                    Recherche de fichiers cachés ...

                    Scan terminé avec succès
                    Fichiers cachés: 0

                    **************************************************************************

                    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
                    "ImagePath"="\??\c:\docume~1\HP_PRO~1\LOCALS~1\Temp\mc22.tmp"

                    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gbtxamc]

                    .
                    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
                    "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
                    .
                    --------------------- DLLs chargées dans les processus actifs ---------------------

                    - - - - - - - > 'explorer.exe'(632)
                    c:\program files\SuperCopier2\SC2Hook.dll
                    c:\windows\system32\nview.dll
                    c:\windows\system32\NVWRSFR.DLL
                    c:\progra~1\Wanadoo\Inactivity.dll
                    c:\windows\system32\eappprxy.dll
                    c:\windows\system32\nvwddi.dll
                    c:\windows\system32\webcheck.dll
                    c:\windows\system32\WPDShServiceObj.dll
                    c:\windows\system32\PortableDeviceTypes.dll
                    c:\windows\system32\PortableDeviceApi.dll
                    .
                    ------------------------ Autres processus actifs ------------------------
                    .
                    c:\program files\Alwil Software\Avast4\aswUpdSv.exe
                    c:\program files\Alwil Software\Avast4\ashServ.exe
                    c:\windows\AGRSMMSG.exe
                    c:\windows\system32\rundll32.exe
                    c:\windows\ALCXMNTR.EXE
                    c:\progra~1\Wanadoo\TaskBarIcon.exe
                    c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    c:\program files\Bonjour\mDNSResponder.exe
                    c:\program files\Fichiers communs\Teleca Shared\CapabilityManager.exe
                    c:\windows\System32\FTRTSVC.exe
                    c:\windows\system32\nvsvc32.exe
                    c:\progra~1\Wanadoo\GestionnaireInternet.exe
                    c:\progra~1\Wanadoo\ComComp.exe
                    c:\progra~1\Wanadoo\Toaster.exe
                    c:\progra~1\Wanadoo\Inactivity.exe
                    c:\progra~1\Wanadoo\PollingModule.exe
                    c:\windows\System32\ALERTM~1\ALERTM~1.EXE
                    c:\program files\Alwil Software\Avast4\ashMaiSv.exe
                    c:\program files\Fichiers communs\Teleca Shared\Generic.exe
                    c:\program files\Alwil Software\Avast4\ashWebSv.exe
                    c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                    c:\program files\iPod\bin\iPodService.exe
                    .
                    **************************************************************************
                    .
                    Heure de fin: 2010-03-14 14:18:21 - La machine a redémarré
                    ComboFix-quarantined-files.txt 2010-03-14 13:18

                    Avant-CF: 118 877 884 416 octets libres
                    Après-CF: 119 282 188 288 octets libres

                    - - End Of File - - DC80192C8ED304896898293D7C291AD6
                    0
                    1. 1)Télécharge OTMoveIt3 de OldTimer sur ton Bureau en cliquant sur ce lien :
                      https://www.zebulon.fr/telechargements/divers/outils/otmoveit.html

                      2)Une fois téléchargé double-clique sur OTMoveIt3.exe pour le lancer.

                      Assure toi que la case Unregister Dll's and Ocx's soit bien cochée

                      3)puis copie les lignes en gras qui se trouvent en dessous :

                      :processes
                      explorer.exe

                      :reg
                      [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gbtxamc]

                      :files
                      c:\windows\system32\drivers\gbtxamc.sy­s

                      :commands
                      [purity]
                      [emptytemp]
                      [start explorer]
                      [reboot]

                      et colle-les dans le cadre de gauche de OTMoveIt : "Paste List Of Files/Folders to Move."
                      clique sur move it pour lancer la suppression.
                      le résultat apparaitra dans le cadre Results.
                      clique sur Exit pour fermer.
                      4) Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                      (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                      5) Il te sera peut-être demander de redémarrer le pc pour achever la suppression -> Accepte ( si il ne fait pas automatiquement , fait-le toi même )

                      /!\ Note : Au démarrage ton bureau RISQUE de ne plus apparaître , dans ce cas fait --> CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
                      Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

                      Tape explorer.exe et valide. Cela fera re-apparaître le Bureau.

                      0
                      1. Je n'ai pas la case Unregister Dll's and Ocx's
                        0
                        1. est-ce que je peux faire la manip même si je n'ai pas les cases qui apparaissent?
                          0
                          1. Je ferais le nettoyage demain.
                            Merci pour tout.

                            De quelle clé parles-tu?
                            0
                            1. fait plutot ce script a la place de celui que je t ai indique dans le precedent message.

                              :processes
                              explorer.exe

                              :reg
                              [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gbtxamc]
                              "gbtxamc"=-

                              :files
                              c:\windows\system32\drivers\gbtxamc.sy­s

                              :commands
                              [purity]
                              [emptytemp]
                              [start explorer]
                              [reboot]
                              0
                              1. voici le rapport de OTM:
                                All processes killed
                                ========== PROCESSES ==========
                                No active process named explorer.exe was found!
                                ========== REGISTRY ==========
                                Registry key HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gbtxamc not found.
                                ========== FILES ==========
                                File/Folder c:\windows\system32\drivers\gbtxamc.sy­s not found.
                                ========== COMMANDS ==========

                                [EMPTYTEMP]

                                User: All Users

                                User: Default User
                                ->Temp folder emptied: 70231 bytes
                                ->Temporary Internet Files folder emptied: 32902 bytes

                                User: HP_Propriétaire
                                ->Temp folder emptied: 26402 bytes
                                ->Temporary Internet Files folder emptied: 80564449 bytes
                                ->Java cache emptied: 20266283 bytes
                                ->FireFox cache emptied: 3363568 bytes
                                ->Flash cache emptied: 300368 bytes

                                User: HP_PropriÚtaire
                                ->Temp folder emptied: 18256 bytes

                                User: LocalService
                                ->Temp folder emptied: 65748 bytes
                                ->Temporary Internet Files folder emptied: 33170 bytes

                                User: NetworkService
                                ->Temp folder emptied: 0 bytes
                                ->Temporary Internet Files folder emptied: 33170 bytes

                                %systemdrive% .tmp files removed: 0 bytes
                                %systemroot% .tmp files removed: 1076450 bytes
                                %systemroot%\System32 .tmp files removed: 8008704 bytes
                                %systemroot%\System32\dllcache .tmp files removed: 0 bytes
                                %systemroot%\System32\drivers .tmp files removed: 0 bytes
                                Windows Temp folder emptied: 32768 bytes
                                %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
                                %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
                                RecycleBin emptied: 0 bytes

                                Total Files Cleaned = 109,00 mb

                                OTM by OldTimer - Version 3.1.10.0 log created on 03152010_082204

                                Files moved on Reboot...
                                File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
                                C:\WINDOWS\temp\Perflib_Perfdata_584.dat moved successfully.

                                Registry entries deleted on Reboot...
                                0
                                1. Après redémarrage, Avast me signale toujours ce rootkit.
                                  ça m'énerve!!!!!!!!!
                                  0
                                  1. salut : pour avancer :


                                    __________________________________________________________
                                    =>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
                                    =>il est fort déconseillé de le transposer sur un autre ordinateur !<=====|
                                    ---------------------------------------------------------------


                                    Toujours avec toutes les protections désactivées, fais ceci :

                                    ▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
                                    ▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

                                    ----------------------------------------------------------
                                    KillAll::

                                    Collect::[4]
                                    c:\windows\system32\drivers\gbtxamc.sys

                                    File::
                                    c:\windows\System32\gbtxamc.*

                                    Driver::
                                    gbtxamc

                                    Registry::
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "Adobe Reader Speed Launcher"=-
                                    "HPHUPD06"=-
                                    "nwiz"=-
                                    "Home Theater SchSvr"=-
                                    "AlcxMonitor"=-
                                    "QuickTime Task"=-
                                    "iTunesHelper"=-

                                    ------------------------------------------------------------------

                                    ▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
                                    ▶ Quitte le Bloc Notes

                                    ▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix

                                    ▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
                                    ▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
                                    ▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt

                                    0
                                    1. fait ce que t a ecrit gen ackman cela devrait fonctionner pas comme ce que je t ai ecrit.
                                      0
                                      • 1
                                      • 2
                                      • 3