Re Bonjour,
Merci de m'aider...
Voila le rapport HIJACK this :
Logfile of HijackThis v1.99.1
Scan saved at 17:16:04, on 11/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00
(7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT
Corporation\BlueSoleil\BTNtService.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared
Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared
Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\drivers\STDSB.exe
C:\WINDOWS\system32\drivers\Icon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Fichiers
communs\Real\Update_OB\realsched.exe
C:\WINDOWS\VM305_STI.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet
Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft
Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\mohamed\Mes
documents\logiciels\problem
pubs\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet
Connection Wizard,ShellNext =
http://www.hotmail.com
R0 - HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-
C3F9-4EFB-9B51-7695ECA05670} - C:\Program
Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-
C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 5.0
\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: PBFRV2 - {4E7BD74F-2B8D-469E-A0E8-
ED6AB685FA7D} - C:\WINDOWS\system32
\pbfrv2.dll
O2 - BHO: EoBho Class - {64F56FC1-1272-44CD-
BA6E-39723696E350} - C:\PROGRA~1
\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-
462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-
A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de
connexion Windows Live - {9030D464-4C02-4ABF
-8ECC-5164760863C6} - C:\Program
Files\Fichiers communs\Microsoft
Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-
01DD-4d91-8333-CF10577473F7} - c:\program
files\google\googletoolbar2.dll
O2 - BHO: System Process - {C2EEB4FA-B6D6-
41b9-9CFA-ABA87F862BCB} -
C:\WINDOWS\system32\navshext1.dll (file
missing)
O3 - Toolbar: PBFRV2 - {4E7BD74F-2B8D-469E-
A0E8-ED6AB685FA7D} - C:\WINDOWS\system32
\pbfrv2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-
C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-
9B18-009027A5CD4F} - c:\program
files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil
/RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
/SYNC
O4 - HKLM\..\Run: [PHIME2002A]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
/IMEName
O4 - HKLM\..\Run: [SynTPLpr] C:\Program
Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program
Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [STDSB]
C:\WINDOWS\system32\drivers\STDSB.exe
O4 - HKLM\..\Run: [Icon] C:\WINDOWS\system32
\drivers\Icon.exe
O4 - HKLM\..\Run: [igfxtray]
C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd]
C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers]
C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program
Files\Fichiers
communs\Real\Update_OB\realsched.exe" -
osboot
O4 - HKLM\..\Run: [opqjzssubf]
c:\windows\system32\opqjzssubf.exe opqjzssubf
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program
Files\Kaspersky Lab\Kaspersky Anti-Virus
Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [BigDog305]
C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC
Camera (ZC0305)
O4 - HKLM\..\Run: [Realtime Audio Engine]
mmrtkrnl.exe
O4 - HKLM\..\Run: [NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -
atboottime
O4 - HKCU\..\Run: [ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xporter vers
Microsoft Excel - res://C:\PROGRA~1\MICROS~3
\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-
18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1
\MICROS~3\OFFICE11\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL]
International*
O14 - IERESET.INF:
START_PAGE_URL=file://C:\APPS\IE\offline\fr.h
tm
O16 - DPF: {00B71CFB-6864-4346-A978-
C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr
.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-
97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Messenge
rStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-
C7C580BBF700} (Windows Genuine Advantage
Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-
83BD84642501} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr
.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-
494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSwee
per.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-
FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/
yinst/yinst_current.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-
2D05CB959537} (MSN Photo Upload Tool) -
http://by119fd.bay119.hotmail.msn.com/resourc
es/MsnPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-
00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2005111401
/housecall.trendmicro.com/housecall/xscan53.c
ab
O16 - DPF: {8E0D4DE5-3180-4024-A327-
4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Messenge
rStatsClient.cab31267.cab
O16 - DPF: {92E7E45A-D8C8-480E-AF99-
176E43997CAA} (Aurigma Image Uploader 3.5
Combo Control) -
http://www.pixdiscount.fr/clients/ImageUpload
er3.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-
220313175592} (ZoneIntro Class) -
http://messenger.zone.msn.com/binary/ZIntro.c
ab47946.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-
B2CCF06D9A1B} (Zylom Games Player) -
http://game05.zylom.com/activex/zylomgamespla
yer.cab
O16 - DPF: {C36112BF-2FA3-4694-8603-
3B510EA3B465} (Lycos File Upload Component) -
http://f012.mail.caramail.lycos.fr/app/upload
er/FileUploader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-
3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Messenge
rStatsPAClient.cab56907.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-
0E40F83B1ADF} (Live365Player Class) -
http://www.live365.com/players/play365.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-
444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwa
ve/cabs/flash/swflash.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-
00C04F8EF29D} (Hotmail Attachments Control) -
http://by104fd.bay104.hotmail.msn.com/activex
/HMAtchmt.ocx
O16 - DPF: {F5A7706B-B9C0-4C89-A715-
7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSwee
per.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-
F385591623AF} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary/Solitair
eShowdown.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-
4009-854F-8E305202313F} - C:\PROGRA~1
\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-
854F-8E305202313F} - C:\PROGRA~1\WINDOW~4
\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui -
C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon -
C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: BlueSoleil Hid Service -
Unknown owner - C:\Program Files\IVT
Corporation\BlueSoleil\BTNtService.exe
O23 - Service: CyberLink Background Capture
Service (CBCS) (CLCapSvc) - Unknown owner -
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS)
(CLSched) - Unknown owner -
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library
Service - Cyberlink - C:\Program
Files\CyberLink\Shared
Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID
Keyboard Input Collections
(GenericHidService) - Unknown owner -
c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: InstallDriver Table Manager
(IDriverT) - Macrovision Corporation -
C:\Program Files\Fichiers
communs\InstallShield\Driver\11\Intel 32
\IDriverT.exe
O23 - Service: iPod Service - Apple Computer,
Inc. - C:\Program
Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Lab -
C:\Program Files\Kaspersky Lab\Kaspersky
Anti-Virus Personal\kavsvc.exe
O23 - Service: LexBce Server (LexBceS) -
Lexmark International, Inc. -
C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MySqlInventime - Unknown owner
- c:\mysql\bin\mysqld-max-nt.exe
O23 - Service: SmartLinkService (SLService) -
- C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SolidWorks Licensing Service -
SolidWorks - C:\Program Files\Fichiers
communs\SolidWorks
Shared\Service\SolidWorksLicensing.exe
O23 - Service: Windows Live Setup Service
(WLSetupSvc) - Unknown owner - C:\Program
Files\Windows Live\installer\WLSetupSvc.exe
//FIN DU RAPPORT
je continue les etapes ..... A+