Virus SEARCH DAILY

Résolu
Bonjour,
Ma barre de recherche internet via google est infectée par un virus search daily qui me redirige systémaiquement vers les sites qu'il veut et pas ce que je veux. Il me laisse des cookies de type porno adulte. c'est très fatiguant à supporter , il faut taper 5 ou 6 six sur un lien avant d acceder à un site voulu!
Merci par avance.
Configuration: Windows XP service pack 2
Internet Explorer 6.0

14 réponses

  1. Contributeur sécurité
    slt,

    Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

    O2 - BHO: ads_optimizer - {9C8A568E-4201-478a-8536-526CF371D2E2} - C:\WINDOWS\system32\nsdA6.dll
    O2 - BHO: (no name) - {BF85CC8A-0025-4E80-B7F6-4D04C5C6C118} - C:\WINDOWS\system32\dpwsoc.dll (file missing)
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    _________________

    Télécharge BTFix de Bibi26
    http://cluster1.easy-hebergement.net/
    Dézippe l'archive sur ton Bureau.
    Ouvre le dossier BTFix.
    Double clique sur BTFix.exe.
    Clique sur Rechercher.
    Un rapport va apparaître, copie/colle-le dans ta prochaine réponse.

    ___________________

    télécharge OTMoveIt
    http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
    double-clique sur OTMoveIt.exe pour le lancer.
    copie la liste qui se trouve en citation ci-dessous,
    et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

    Citation :

    C:\WINDOWS\system32\dpwsoc.dll
    C:\WINDOWS\system32\nsdA6.dll

    clique sur MoveIt! pour lancer la suppression.
    le résultat apparaitra dans le cadre "Results".
    clique sur Exit pour fermer.
    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
    ___________________

    vire ce qui est dans moved files en allant dans poste de travail ppuis c puis otmovit

    ___________________

    mets a jour internet explorer ici:
    https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/33081.html
    __________________
    recolle hijakhcits et dis tes soucis
    1. Voila j'ai un gros prob avec ce virus TR/BHO.abo.9 qui apparemment attaque le fichier dpwsoc.dll.
      Les consequence son que ma machine plainte et redemarre réguliérement.
      Si vous pourriez m'aider comme les autres, je vous serais extremement reconnaissant.

      Voici mon rapport antivir:

      IIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII

      AntiVir PersonalEdition Classic
      Report file date: jeudi 20 mars 2008 17:38

      Scanning for 1160082 virus strains and unwanted programs.

      Licensed to: Avira AntiVir PersonalEdition Classic
      Serial number: 0000149996-ADJIE-0001
      Platform: Windows XP
      Windows version: (Service Pack 2) [5.1.2600]
      Username: Virg
      Computer name: VIRGINIE

      Version information:
      BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
      AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:30
      AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:52
      LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:48
      LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:22
      ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:16
      ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 16:35:26
      ANTIVIR2.VDF : 7.0.3.3 2048 Bytes 07/03/2008 16:35:26
      ANTIVIR3.VDF : 7.0.3.61 328192 Bytes 20/03/2008 16:35:26
      AVEWIN32.DLL : 7.6.0.75 3334656 Bytes 20/03/2008 16:35:26
      AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:28
      AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:18
      AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
      AVPACK32.DLL : 7.6.0.3 360488 Bytes 20/03/2008 16:35:26
      AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:08
      AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:34
      AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:20
      NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:44
      RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:14
      RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:38
      SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:22

      Configuration settings for the scan:
      Jobname..........................: Windows System Directory
      Configuration file...............: c:\program files\avira\antivir personaledition classic\sysdir.avp
      Logging..........................: low
      Primary action...................: interactive
      Secondary action.................: ignore
      Scan master boot sector..........: off
      Scan boot sector.................: on
      Boot sectors.....................: C:,
      Scan memory......................: on
      Process scan.....................: on
      Scan registry....................: on
      Search for rootkits..............: off
      Scan all files...................: Intelligent file selection
      Scan archives....................: on
      Recursion depth..................: 20
      Smart extensions.................: on
      Macro heuristic..................: on
      File heuristic...................: medium

      Start of the scan: jeudi 20 mars 2008 17:38

      The scan of running processes will be started
      Scan process 'avscan.exe' - '1' Module(s) have been scanned
      Scan process 'WMIPRVSE.EXE' - '1' Module(s) have been scanned
      Scan process 'firefox.exe' - '1' Module(s) have been scanned
      Scan process 'WMIPRVSE.EXE' - '1' Module(s) have been scanned
      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
      Scan process 'sched.exe' - '1' Module(s) have been scanned
      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
      Scan process 'avguard.exe' - '1' Module(s) have been scanned
      Scan process 'TosBtProc.exe' - '1' Module(s) have been scanned
      Scan process 'iPodService.exe' - '1' Module(s) have been scanned
      Scan process 'TosOBEX.exe' - '1' Module(s) have been scanned
      Scan process 'TosBtPSS.exe' - '1' Module(s) have been scanned
      Scan process 'TosBtHSP.exe' - '1' Module(s) have been scanned
      Scan process 'TosBtHid.exe' - '1' Module(s) have been scanned
      Scan process 'TosA2dp.exe' - '1' Module(s) have been scanned
      Scan process 'Dot1XCfg.exe' - '1' Module(s) have been scanned
      Scan process 'ATKOSD.exe' - '1' Module(s) have been scanned
      Scan process 'TosBtMng.exe' - '1' Module(s) have been scanned
      Scan process 'SuperCopier2.exe' - '1' Module(s) have been scanned
      Scan process 'CTFMON.EXE' - '1' Module(s) have been scanned
      Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
      Scan process 'JUSCHED.EXE' - '1' Module(s) have been scanned
      Scan process 'realsched.exe' - '1' Module(s) have been scanned
      Scan process 'DAEMON.EXE' - '1' Module(s) have been scanned
      Scan process 'iFrmewrk.exe' - '1' Module(s) have been scanned
      Scan process 'ZCfgSvc.exe' - '1' Module(s) have been scanned
      Scan process 'RTHDCPL.EXE' - '1' Module(s) have been scanned
      Scan process 'HControl.exe' - '1' Module(s) have been scanned
      Scan process 'ALG.EXE' - '1' Module(s) have been scanned
      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
      Scan process 'RegSrvc.exe' - '1' Module(s) have been scanned
      Scan process 'NVSVC32.EXE' - '1' Module(s) have been scanned
      Scan process 'EXPLORER.EXE' - '1' Module(s) have been scanned
      Scan process 'SQLSERVR.EXE' - '1' Module(s) have been scanned
      Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
      Scan process 'SPOOLSV.EXE' - '1' Module(s) have been scanned
      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
      Scan process 'S24EvMon.exe' - '1' Module(s) have been scanned
      Scan process 'EvtEng.exe' - '1' Module(s) have been scanned
      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
      Scan process 'LSASS.EXE' - '1' Module(s) have been scanned
      Scan process 'SERVICES.EXE' - '1' Module(s) have been scanned
      Scan process 'WINLOGON.EXE' - '1' Module(s) have been scanned
      Scan process 'CSRSS.EXE' - '1' Module(s) have been scanned
      Scan process 'SMSS.EXE' - '1' Module(s) have been scanned
      49 processes with 49 modules were scanned

      Start scanning boot sectors:
      Boot sector 'C:\'
      [NOTE] No virus was found!

      Starting to scan the registry.
      The registry was scanned ( '34' files ).

      Starting the file scan:

      Begin scan in 'C:\WINDOWS\system32'
      C:\WINDOWS\system32\dpwsoc.dll
      [DETECTION] Is the Trojan horse TR/BHO.abo.9
      [WARNING] The file could not be deleted!
      C:\WINDOWS\system32\drivers\sptd.sys
      [WARNING] The file could not be opened!

      End of the scan: jeudi 20 mars 2008 17:39
      Used time: 01:11 min

      The scan has been done completely.

      231 Scanning directories
      4059 Files were scanned
      1 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      1 Files cannot be scanned
      4058 Files not concerned
      3 Archives were scanned
      2 Warnings
      0 Notes

      IIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII

      Et voici mon rapport hijack

      IIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 18:11:03, on 20/03/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\ATK0100\HControl.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
      C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
      C:\Program Files\DAEMON Tools\daemon.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\SuperCopier2\SuperCopier2.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
      C:\WINDOWS\ATK0100\ATKOSD.exe
      C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPSS.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.asus.com/fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: ads_optimizer - {9C8A568E-4201-478a-8536-526CF371D2E2} - C:\WINDOWS\system32\nsdA6.dll
      O2 - BHO: (no name) - {BF85CC8A-0025-4E80-B7F6-4D04C5C6C118} - C:\WINDOWS\system32\dpwsoc.dll (file missing)
      O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
      O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
      O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
      O4 - HKLM\..\Run: [Pinnacle WebUpdater] "C:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" -s -f=UpdateVersion.xml -url=http://cdn.pinnaclesys.com/SupportFiles
      O4 - HKLM\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [PCLEUSBTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
      O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [PMCS] "C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Bluetooth Manager.lnk = ?
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      1. Merci beaucoup je n'ai plus de redirection intempestives!
        1. Contributeur sécurité
          Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

          O2 - BHO: (no name) - {01F24B21-2B40-46DA-AA04-E89CDF74AEE8} - C:\WINDOWS\System32\cewmd.dll (file missing)

          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

          ___________________

          tu n'as pas d'anti espion alors installe spybot et scan avec (tu le gardera par la suite pour te proteger)

          spybot : (si vous avez une version instalée avant sept 2007 changer là par la version 1.5)

          https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/26157.html

          voir demo d utilisation (merci Balltrap)
          http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

          ___________________

          utilise pour supprimer tes traces (a garder par la suite et utiliser toutes les semaines)

          CCLEANER: (lance un nettoyage et répare 3 fois les erreurs) sans installer la barre yahoo

          https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

          _____________________

          mets a jour interenet explorer:
          https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/33081.html
          ___________________
          supprime ce qui est en quarantaine dans antivir et colle un rapport

          ___________________

          recolle un rapport hijackthis et surtoiut dis tes problemes actuels
          1. Voici le rapport hijackthis:
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 20:00:10, on 26/12/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
            C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
            C:\Program Files\neuf telecom\neuf Box\Wizard\QuickAccess.exe
            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
            C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
            C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\HPZipm12.exe
            C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.neuf.fr
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: (no name) - {01F24B21-2B40-46DA-AA04-E89CDF74AEE8} - C:\WINDOWS\System32\cewmd.dll (file missing)
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKCU\..\Run: [Configuration de la neuf Box] C:\Program Files\neuf telecom\neuf Box\Wizard\QuickAccess.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
            O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
            O4 - Global Startup: hp psc 1000 series.lnk = ?
            O4 - Global Startup: hpoddt01.exe.lnk = ?
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
            1. Contributeur sécurité
              recolle un nouveau hijackthis et dis tes soucis
              1. Voici le rapport antivir

                AntiVir PersonalEdition Classic
                Report file date: mercredi 26 décembre 2007 18:18

                Scanning for 835736 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 2) [5.1.2600]
                Username: Le Corse
                Computer name: PAUL

                Version information:
                BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 14:26:55
                ANTIVIR2.VDF : 7.0.0.1 2048 Bytes 13/09/2007 14:27:04
                ANTIVIR3.VDF : 7.0.0.2 2048 Bytes 13/09/2007 14:27:13
                AVEWIN32.DLL : 7.6.0.15 2806272 Bytes 17/09/2007 17:43:56
                AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:00
                AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                Configuration settings for the scan:
                Jobname..........................: Windows System Directory
                Configuration file...............: C:\Program Files\Avira\AntiVir PersonalEdition Classic\setupprf.dat
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: off
                Scan boot sector.................: on
                Boot sectors.....................: C:,
                Scan memory......................: on
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: Intelligent file selection
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: medium

                Start of the scan: mercredi 26 décembre 2007 18:18

                The scan of running processes will be started
                Scan process 'rundll32.exe' - '0' Module(s) have been scanned
                Scan process 'control.exe' - '1' Module(s) have been scanned
                Scan process 'rundll32.exe' - '1' Module(s) have been scanned
                Scan process 'control.exe' - '1' Module(s) have been scanned
                Scan process 'control.exe' - '1' Module(s) have been scanned
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                Scan process 'sched.exe' - '1' Module(s) have been scanned
                Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
                Scan process 'hposts08.exe' - '1' Module(s) have been scanned
                Scan process 'alg.exe' - '1' Module(s) have been scanned
                Scan process 'HPZipm12.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'hpoevm08.exe' - '1' Module(s) have been scanned
                Scan process 'soffice.bin' - '1' Module(s) have been scanned
                Scan process 'soffice.exe' - '1' Module(s) have been scanned
                Scan process 'hpotdd01.exe' - '1' Module(s) have been scanned
                Scan process 'hpohmr08.exe' - '1' Module(s) have been scanned
                Scan process 'QuickAccess.exe' - '1' Module(s) have been scanned
                Scan process 'jusched.exe' - '1' Module(s) have been scanned
                Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
                Scan process 'apdproxy.exe' - '1' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                35 processes with 35 modules were scanned

                Start scanning boot sectors:
                Boot sector 'C:\'
                [NOTE] No virus was found!

                Starting to scan the registry.
                The registry was scanned ( '29' files ).

                Starting the file scan:

                Begin scan in 'C:\WINDOWS\system32'

                End of the scan: mercredi 26 décembre 2007 18:20
                Used time: 01:21 min

                The scan has been done completely.

                153 Scanning directories
                4380 Files were scanned
                0 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                0 files were deleted
                0 files were repaired
                0 files were moved to quarantine
                0 files were renamed
                0 Files cannot be scanned
                4380 Files not concerned
                10 Archives were scanned
                0 Warnings
                0 Notes

                puis après

                AntiVir PersonalEdition Classic
                Report file date: mercredi 26 décembre 2007 19:31

                Scanning for 992748 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 2) [5.1.2600]
                Username: Le Corse
                Computer name: PAUL

                Version information:
                BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 18:22:30
                ANTIVIR2.VDF : 7.0.1.157 286720 Bytes 26/12/2007 18:22:30
                ANTIVIR3.VDF : 7.0.1.158 2048 Bytes 26/12/2007 18:22:30
                AVEWIN32.DLL : 7.6.0.46 3084800 Bytes 26/12/2007 18:22:30
                AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                AVPACK32.DLL : 7.6.0.2 360488 Bytes 26/12/2007 18:22:30
                AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                Configuration settings for the scan:
                Jobname..........................: Local Hard Disks
                Configuration file...............: c:\program files\avira\antivir personaledition classic\alldiscs.avp
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: off
                Scan boot sector.................: on
                Boot sectors.....................: C:,
                Scan memory......................: on
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: Intelligent file selection
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: medium

                Start of the scan: mercredi 26 décembre 2007 19:31

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                Scan process 'sched.exe' - '1' Module(s) have been scanned
                Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                Scan process 'hposts08.exe' - '1' Module(s) have been scanned
                Scan process 'alg.exe' - '1' Module(s) have been scanned
                Scan process 'HPZipm12.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'hpoevm08.exe' - '1' Module(s) have been scanned
                Scan process 'soffice.bin' - '1' Module(s) have been scanned
                Scan process 'soffice.exe' - '1' Module(s) have been scanned
                Scan process 'hpotdd01.exe' - '1' Module(s) have been scanned
                Scan process 'hpohmr08.exe' - '1' Module(s) have been scanned
                Scan process 'QuickAccess.exe' - '1' Module(s) have been scanned
                Scan process 'jusched.exe' - '1' Module(s) have been scanned
                Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
                Scan process 'apdproxy.exe' - '1' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                32 processes with 32 modules were scanned

                Start scanning boot sectors:
                Boot sector 'C:\'
                [NOTE] No virus was found!

                Starting to scan the registry.
                The registry was scanned ( '29' files ).

                Starting the file scan:

                Begin scan in 'C:\'
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                C:\Documents and Settings\Le Corse\Local Settings\Temp\nst32.tmp\bann.exe
                [DETECTION] Is the Trojan horse TR/Dldr.Agent.9876
                [INFO] The file was moved to '47e09ead.qua'!
                C:\Documents and Settings\Le Corse\Local Settings\Temp\Rar$EX00.688\setup.exe
                [DETECTION] Is the Trojan horse TR/Dldr.Faux
                [INFO] The file was moved to '47e69eb7.qua'!
                C:\Program Files\Trend Micro\HijackThis\backups\backup-20071226-140728-846.dll
                [DETECTION] Is the Trojan horse TR/BHO.abo.9
                [INFO] The file was moved to '47d5a1cb.qua'!
                C:\Program Files\Trend Micro\HijackThis\backups\backup-20071226-140823-540.dll
                [DETECTION] Is the Trojan horse TR/BHO.abo.9
                [INFO] The file was moved to '47d5a1ce.qua'!
                C:\Program Files\Trend Micro\HijackThis\backups\backup-20071226-140853-334.dll
                [DETECTION] Is the Trojan horse TR/BHO.abo.9
                [INFO] The file was moved to '47d5a1d0.qua'!
                C:\Program Files\Trend Micro\HijackThis\backups\backup-20071226-140955-887.dll
                [DETECTION] Is the Trojan horse TR/BHO.abo.9
                [INFO] The file was moved to '47d5a1d1.qua'!
                C:\Program Files\Trend Micro\HijackThis\backups\backup-20071226-141048-936.dll
                [DETECTION] Is the Trojan horse TR/BHO.abo.9
                [INFO] The file was moved to '47d5a1d3.qua'!
                C:\Program Files\Trend Micro\HijackThis\backups\backup-20071226-141614-710.dll
                [DETECTION] Is the Trojan horse TR/BHO.abo.9
                [INFO] The file was moved to '47d5a1d5.qua'!
                C:\Program Files\Trend Micro\HijackThis\backups\backup-20071226-142349-870.dll
                [DETECTION] Is the Trojan horse TR/BHO.abo.9
                [INFO] The file was moved to '47d5a1d7.qua'!

                End of the scan: mercredi 26 décembre 2007 19:54
                Used time: 23:42 min

                The scan has been done completely.

                2583 Scanning directories
                190553 Files were scanned
                9 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                0 files were deleted
                0 files were repaired
                9 files were moved to quarantine
                0 files were renamed
                1 Files cannot be scanned
                190544 Files not concerned
                1912 Archives were scanned
                1 Warnings
                0 Notes
                1. il m'est impossible de faire "fix checked" pour la ligne

                  O2 - BHO: (no name) - {01F24B21-2B40-46DA-AA04-E89CDF74AEE8} - C:\WINDOWS\System32\cewmd.dll

                  hijackthis me demande de fermer toutes les fenetres internets et les fenetres windows
                  c'est ce que je fait mais pas moyen de fixé la ligne O2
                  1. Contributeur sécurité
                    Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://accountservices.passport.net/reg.srf?xpwiz=true&lc=1036&id=2
                    O2 - BHO: (no name) - {01F24B21-2B40-46DA-AA04-E89CDF74AEE8} - C:\WINDOWS\System32\cewmd.dll

                    ____________________

                    télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe (de Old_Timer) sur ton Bureau.
                    double-clique sur OTMoveIt.exe pour le lancer.
                    copie la liste qui se trouve en citation ci-dessous,
                    et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                    Citation :

                    C:\WINDOWS\System32\cewmd.dll

                    clique sur MoveIt! pour lancer la suppression.
                    le résultat apparaitra dans le cadre "Results".
                    clique sur Exit pour fermer.
                    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes. COLLE MOI LE RAPPORT

                    _______________________

                    remplace avast par antivir et colle un rapoprt

                    https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)

                    _________________________

                    recolle un nouveau hijackthis et dis tes soucis

                    a plus
                    1. Excusez moi mais entre temps mon ordi à bugger et maintenant j'ai un autre rapport qui m apparait !après une restauration système !

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 13:52:01, on 26/12/2007
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
                      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                      C:\Program Files\neuf telecom\neuf Box\Wizard\QuickAccess.exe
                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
                      C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
                      C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                      C:\WINDOWS\System32\HPZipm12.exe
                      C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.neuf.fr
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://accountservices.passport.net/reg.srf?xpwiz=true&lc=1036&id=2
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: (no name) - {01F24B21-2B40-46DA-AA04-E89CDF74AEE8} - C:\WINDOWS\System32\cewmd.dll
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                      O4 - HKCU\..\Run: [Configuration de la neuf Box] C:\Program Files\neuf telecom\neuf Box\Wizard\QuickAccess.exe
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                      O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
                      O4 - Global Startup: hp psc 1000 series.lnk = ?
                      O4 - Global Startup: hpoddt01.exe.lnk = ?
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                      1. Contributeur sécurité
                        Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://accountservices.passport.net/reg.srf?xpwiz=true&lc=1036&id=2

                        O2 - BHO: (no name) - {01F24B21-2B40-46DA-AA04-E89CDF74AEE8} - C:\WINDOWS\System32\cewmd.dll

                        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                        O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Fichiers communs\ReparateurDeSysteme\strpmon.exe" dm=http://reparateurdesysteme.com ad=http://reparateurdesysteme.com sd=http://repay.reparateurdesysteme.com

                        __________________

                        télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe (de Old_Timer) sur ton Bureau.
                        double-clique sur OTMoveIt.exe pour le lancer.
                        copie la liste qui se trouve en citation ci-dessous,
                        et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                        Citation :

                        C:\WINDOWS\System32\cewmd.dll
                        C:\Program Files\Fichiers communs\ReparateurDeSysteme\strpmon.exe

                        clique sur MoveIt! pour lancer la suppression.
                        le résultat apparaitra dans le cadre "Results".
                        clique sur Exit pour fermer.
                        poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                        il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                        _______________________

                        remplace avast par antivir et colle un rapoprt

                        https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)

                        _________________________

                        recolle un nouveau hijackthis et dis tes soucis

                        a plus
                        1. Comme convenu voici mon rapport si ce n est pas trop tard et merci encore !

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 10:27:02, on 26/12/2007
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
                          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                          C:\Program Files\Fichiers communs\ReparateurDeSysteme\strpmon.exe
                          C:\Program Files\neuf telecom\neuf Box\Wizard\QuickAccess.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
                          C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
                          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                          C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
                          C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\WINDOWS\System32\HPZipm12.exe
                          C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.neuf.fr
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
                          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://accountservices.passport.net/reg.srf?xpwiz=true&lc=1036&id=2
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: (no name) - {01F24B21-2B40-46DA-AA04-E89CDF74AEE8} - C:\WINDOWS\System32\cewmd.dll
                          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                          O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Fichiers communs\ReparateurDeSysteme\strpmon.exe" dm=http://reparateurdesysteme.com ad=http://reparateurdesysteme.com sd=http://repay.reparateurdesysteme.com
                          O4 - HKCU\..\Run: [Configuration de la neuf Box] C:\Program Files\neuf telecom\neuf Box\Wizard\QuickAccess.exe
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                          O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
                          O4 - Global Startup: hp psc 1000 series.lnk = ?
                          O4 - Global Startup: hpoddt01.exe.lnk = ?
                          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                          1. Contributeur sécurité
                            bonjour,

                            colle un rapport hijackthis

                            http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

                            manuel :

                            https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

                            Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

                            ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

                            Ensuite avec Explorer créer un dossier c:\hijackthis
                            Décompresser Hijackthis dans ce dossier.
                            C'est important pour les sauvegardes."