Je ne sais comment faire ...

Bonjour,

J'aimerai bien avoir votre aide car je ne sais comment faire.

Quand j'allume mon pc jusque là tous va très bien, Mon internet se connecte et puis tout d'un seul coup il se déconnecte, alors que je n'ai touché a rien et que sur l'autre pc le net marche correctement.

Et aucun antivirus ne trouve rien : avast, norton , a2-squared, antivir.

Alors je ne sais qu faire , d'autant plus que j'ai déjà fais une restauration système et j'en suis au meme stade.

Aidez-moi sil vous plait

Merci d'avance

9 réponses

  1. Voila
    le rapport de l option 1 :

    SmitFraudFix v2.117

    Rapport fait à 21:14:41,53, 01/11/2006
    Executé à partir de C:\Documents and Settings\Propri‚taire\Bureau\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    Fix executé en mode normal

    »»»»»»»»»»»»»»»»»»»»»»»» C:\

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Propri‚taire

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Propri‚taire\Application Data

    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\PROPRI~1\Favoris

    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Ma page d'accueil"

    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""

    »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin

    Le rapport de l option 2 :

    SmitFraudFix v2.117

    Rapport fait à 21:19:06,04, 01/11/2006
    Executé à partir de C:\Documents and Settings\Propri‚taire\Bureau\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    Fix executé en mode sans echec

    »»»»»»»»»»»»»»»»»»»»»»»» Avant SmitFraudFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

    Nettoyage du registre non souhaité.

    »»»»»»»»»»»»»»»»»»»»»»»» Après SmitFraudFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin

    Merci de ton aide
    0
    1. Oups j'ai oublié de te dire que quand j'ouvre le script il me met

      Fichier processus.exe absent
      dézipper la totalité
      0
      1. Je ne dis pas ça mais quand je l'ouvre ça ne me met aucune option alors je ne sais comment faire pourrait tu m'expliquer stp
        0
        1. puis norton me dit que c'est un script malveillant alors comment je fais stp

          Déjà, si tu viens sur le forum, dis toi bien que je ne donnerai pas de lien vérolé.......

          Tu l'as acheté Norton ???
          Parceque comme passoire y'a pas mieux...
          Alors vire-le et mets Avast à la place...

          0
          1. Je ne vois pas ou est l option 1 , car quand je clique sur le truc que tu m as dit le script s ouvre tout de suite et puis norton me dit que c'est un script malveillant alors comment je fais stp ?
            0
            1. Fait ce qui suit
              Télécharge ceci: (merci a S!RI pour ce programme).
              http://siri.urz.free.fr/Fix/SmitfraudFix.zip
              TUTO :: http://siri.urz.free.fr/Fix/SmitfraudFix.php

              Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1, il va générer un rapport
              Copie/colle le sur le poste stp.
              ----------------------------------------------------------------------------
              Démarre en mode sans échec :
              Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
              Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
              Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
              (Si F8 ne marche pas utilise la touche F5).
              ----------------------------------------------------------------------------
              Relance le programme Smitfraud,
              Cette fois choisit l’option 2, répond oui a tous ;
              Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

              ========================================
              Refais un Hitjackthis

              A++

              0
              1. Voila mon rapport :

                Logfile of HijackThis v1.99.1
                Scan saved at 19:48:26, on 01/11/2006
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
                C:\WINDOWS\System32\FTRTSVC.exe
                C:\Program Files\Norton AntiVirus\navapsvc.exe
                C:\WINDOWS\System32\nvsvc32.exe
                C:\WINDOWS\System32\svchost.exe
                C:\windows\system\hpsysdrv.exe
                C:\Program Files\USB Storage RW\shwicon.exe
                C:\HP\KBD\KBD.EXE
                C:\WINDOWS\system32\LVCOMSX.EXE
                C:\Program Files\Logitech\Video\LogiTray.exe
                C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
                C:\WINDOWS\system32\hphmon05.exe
                C:\WINDOWS\system32\rundll32.exe
                C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
                C:\PROGRA~1\TWINTO~1\MouseElf.EXE
                C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                C:\WINDOWS\system32\rundll32.exe
                C:\Program Files\MSN Messenger\MsnMsgr.Exe
                C:\Program Files\TwinTouch LuxeMate\EMouse.exe
                C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
                C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
                C:\PROGRA~1\Wanadoo\ComComp.exe
                C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
                C:\PROGRA~1\Wanadoo\Toaster.exe
                C:\WINDOWS\system32\HPZipm12.exe
                C:\PROGRA~1\Wanadoo\Inactivity.exe
                C:\PROGRA~1\Wanadoo\PollingModule.exe
                C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                C:\Program Files\Logitech\Video\FxSvr2.exe
                C:\PROGRA~1\Wanadoo\Watch.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Windows Media Player\wmplayer.exe
                C:\Program Files\Messenger\msmsgs.exe
                C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\Répertoire temporaire 1 pour Scanner.exe.zip\HijackThis.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr7.hpwis.com/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr7.hpwis.com/
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr7.hpwis.com/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr7.hpwis.com/
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\Program Files\Microsoft Money\System\mnyside.dll
                O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
                O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
                O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
                O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\Coloreal\coloreal.exe"
                O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
                O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
                O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
                O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
                O4 - HKLM\..\Run: [hpppta] C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan\hpppta.exe /ICON
                O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
                O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\TWINTO~1\MouseElf.EXE
                O4 - HKLM\..\Run: [ccApp] C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe
                O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
                O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT

                cnx|PARAM


                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                O4 - Global Startup: BlueSoleil.lnk = ?
                O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe

                Merci d avance et de prendre ton temps pour m'aider.
                0
                1. Tu as quoi comme anti-virus d'installer maintenant
                  ???

                  Fais ce qui suit

                  F - Hijackthis - Outil de diagnostic et réparation
                  lire démo
                  http://pageperso.aol.fr/balltrap34/Hijenr.gif
                  http://pageperso.aol.fr/balltrap34/demohijack.htm
                  Télécharge version française ici
                  http://telechargement.zebulon.fr/160-patch-francais-pour-hijackthis-1991.html
                  Copie/colle le rapport

                  Bon courage

                  A++
                  0
                  1. Slt

                    Et aucun antivirus ne trouve rien : avast, norton , a2-squared, antivir.

                    Tu as combien d'anti-virus ??????

                    Il n'en faut QU'UN SEUL........... sinon ce le conflit assuré....

                    Tu vires tout SAUF AVAST...

                    A++
                    0
                    1. Je supprimais chaque anti-virus a chaque fois que j'en installé un nouveau . Et aucun de ces anti-virus n'a rien trouvé meme avast qui est perfomant.
                      0