Rapport Ad-Remover

Fermé
Tom - 24 déc. 2009 à 13:02
 Tom - 24 déc. 2009 à 23:35
Bonjour,

Mon ordinateur est infecté par Eorezo. J'ai donc suivi la préocédure pour le supprimer avec Ad-remover et voici comme demandé le rapport :

.
======= RAPPORT D'AD-REMOVER 1.1.4.6_F | UNIQUEMENT XP/VISTA/7 =======
.
Mit à jour par C_XX le 23.12.2009 à 20:36
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 1:45:21, 24/12/2009 | Mode Normal | Option: SCAN
Exécuté de: C:\Program Files\Ad-Remover\
Système d'exploitation: Microsoft® Windows Vista™ Home Premium Service Pack 2 v6.0.6002
Nom du PC: PC-DE-TOM | Utilisateur actuel: Tom

Bonnes fêtes de fin d'année à vous tous :)
.
============== ÉLÉMENT(S) TROUVÉ(S) ==============
.

C:\Users\TOM~1.PC-\AppData\Roaming\Mozilla\FireFox\Profiles\jurx2arm.default\searchplugins\ask.xml
C:\Program Files\Mozilla FireFox\Components\AskSearch.js
C:\log_lobby.txt
C:\log_lobby_dumper.txt
C:\Users\TOM~1.PC-\AppData\Roaming\EoRezo
C:\Program Files\Windows Live\Messenger\Riched20.dll
C:\Program Files\Windows Live\Messenger\Msimg32.dll
.
HKCU\software\EoRezo
HKCU\software\Grand Virtual
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKLM\Software\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
HKLM\Software\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
HKLM\Software\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}
HKLM\Software\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
HKLM\software\Dealio
HKLM\software\EoRezo
HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
HKLM\Software\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\EoEngine
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SoftwareHelper
HKLM\software\microsoft\windows\currentversion\uninstall\SoftwareUpdate_is1
HKU\s-1-5-21-3915819837-3197513282-749317194-1000\software\EoRezo
HKU\s-1-5-21-3915819837-3197513282-749317194-1000\software\Grand Virtual
.
============== Scan additionnel ==============
.
.
* Mozilla FireFox Version 3.0.13 [fr] *
.
Nom du profil: jurx2arm.default (Tom)
.
(TOM~1.PC-, prefs.js) Browser.download.dir, C:\Users\Tom.PC-de-Tom\Downloads
(TOM~1.PC-, prefs.js) Browser.download.lastDir, C:\Users\Tom.PC-de-Tom\Desktop
(TOM~1.PC-, prefs.js) Browser.search.defaultenginename, Ask
(TOM~1.PC-, prefs.js) Browser.search.defaulturl, hxxp://slirsredirect.search.aol.com/slirs_hxxp/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
(TOM~1.PC-, prefs.js) Browser.search.selectedEngine, Google
(TOM~1.PC-, prefs.js) Browser.startup.homepage, hxxp://y.lo.st
(TOM~1.PC-, prefs.js) Extensions.enabledItems, dvscontextmenuy@dvdvideosoft.com:1.0,{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05,{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,jiwack@akryus.net:2.3.3.9,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13
(TOM~1.PC-, prefs.js) Keyword.URL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101761&gct=&gc=1&q=
.
(TOM~1.PC-, prefs.js) TROUVE - Browser.startup.homepage, hxxp://y.lo.st
(TOM~1.PC-, prefs.js) TROUVE - Extensions.snipit.chromeURL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101761&gct=&gc=1&q={searchTerms}&crm=1
(TOM~1.PC-, prefs.js) TROUVE - Extensions.snipit.history_query, youtube=ASKURL=hxxp://www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=hxxp://www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=hxxp://www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=hxxp://www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=/\÷/www.ask.com/web?q=ogre%20pØúæØúØúæØúæØú§ØúØúòØú
(TOM~1.PC-, prefs.js) TROUVE - ØúúØú«Øúaname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=AØúæSKURØúL=//Øúæwww.Øúæask.Øú§c\÷Øúom/wØúòeb?qØú
(TOM~1.PC-, prefs.js) TROUVE - tubeØúú&qsrØú«c=28Øú71&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis
(TOM~1.PC-, prefs.js) TROUVE - Keyword.URL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101761&gct=&gc=1&q=
(TOM~1.PC-, prefs.js) TROUVE - /web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogre%2520paname&qsrc=2871&o=101761&l=dis||youtube=ASKURL=//www.ask.com/web?q=youtube&qsrc=2871&o=101761&l=dis||deezer=ASKURL=//www.ask.com/web?q=deezer&qsrc=2871&o=101761&l=dis||ogre%20paname=ASKURL=//www.ask.com/web?q=ogre%20paname&qsrc=2871&o=101761&l=dis||ogre%2520paname=ASKURL=//www.ask.com/web?q=ogreØúæ%2520panØúame&qsrcØúæ=2871&o=Øúæ101761&lØú§=dis||yoØúutube=ASØúòKURL=//wØú
.
(TOM~1.PC-, user.js) Keyword.URL, hxxp://redirecterror.sfr.fr/?q=
.
.
* Internet Explorer Version 8.0.6001.18865 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Do404Search: 01000000
Local Page: C:\Windows\system32\blank.htm
Show_ToolBar: yes
Search Page: hxxp://www.google.com
Enable Browser Extensions: yes
Use Search Asst: no
Start Page Redirect Cache: hxxp://fr.msn.com/?ocid=iehp
Start Page Redirect Cache AcceptLangs: fr
Start Page: hxxp://www.google.fr/
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Delete_Temp_Files_On_Exit: yes
Local Page: C:\Windows\system32\blank.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
===================================
.
12832 Octet(s) - C:\Ad-Report-SCAN[1].log
.
97 Fichier(s) - C:\Users\TOM~1.PC-\AppData\Local\Temp
8 Fichier(s) - C:\Windows\Temp
120 Fichier(s) - C:\Windows\Prefetch
.
2 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
0 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
.
Fin à: 1:55:13 | 24/12/2009 - SCAN[1]
.
============== E.O.F ==============
.

Que dois-je faire par la suite ?

Merci d'avance pour votre précieuse aide.

Tom
A voir également:

1 réponse

jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 1 616
24 déc. 2009 à 13:13
bonjour, postes un RSIT pour voir si plus rien sur le pc , Merci

• Télécharge Random's System Information Tool (RSIT) de Random/Random, et enregistre le sur ton Bureau.
• Double clique sur RSIT.exe pour lancer l'outil.
* laisses le chois 1 month
• Clique sur "Continue" à l'écran Disclaimer.
• Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande) et tu devras accepter la licence.
• Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

ps:Les rapports se trouvent à cet endroit:

C:\rsit\info.txt

C:\rsit\log.txt


Tutoriel pour t'aider

0
Merci Jacques, je fais la manip' de suite ;-)
0