Aidez moi eorezo

Fermé
oumcarla - 12 mai 2010 à 15:30
 Utilisateur anonyme - 12 mai 2010 à 15:38
bonjour, j'essaie de supprimer eorezo, j'ai téléchargé ad remover dont voici le rapport, d'avance, merci pour votre aide



.
======= RAPPORT D'AD-REMOVER 2.0.0.0,D | UNIQUEMENT XP/VISTA/7 =======
.
Mis à jour par C_XX le 07/05/10 à 16:50
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 15:09:58 le 12/05/2010 | Mode normal | Option: SCAN
Exécuté de: C:\Ad-Remover\ADR.exe
SE: Microsoft® Windows XP(TM) Service Pack 3 - X86
Nom du PC: RR-F468132F5A3F
Utilisateur actuel: test
.
============== ÉLÉMENT(S) TROUVÉ(S) ==============
.
.
C:\Documents and Settings\All Users.WINDOWS\Application Data\{DF750BED-BBA7-4829-9F3C-94C56FA58223}\offline\C_\Build.Desktop\Installer\bin\win32\IMBooster
C:\Documents and Settings\All Users.WINDOWS\Application Data\AGI
C:\Documents and Settings\All Users.WINDOWS\Application Data\agi\UnifiedToolbar
C:\Documents and Settings\All Users.WINDOWS\Application Data\Iminent
C:\Documents and Settings\All Users.WINDOWS\Application Data\Iminent\IMBooster
C:\Documents and Settings\All Users.WINDOWS\Application Data\Kiwee Toolbar
C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\IMBooster
C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Kiwee Toolbar
C:\Documents and Settings\LocalService.AUTORITE NT\Application Data\agi
C:\Documents and Settings\Propriétaire\Application Data\SpamBlocker
C:\Documents and Settings\Propriétaire\Application Data\SpamBlockerUtility
C:\Documents and Settings\Propriétaire\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility
C:\Documents and Settings\rr\Application Data\Agence Exclusive
C:\Documents and Settings\rr\Local Settings\Application Data\Agence Exclusive
C:\Documents and Settings\rr\Local Settings\Application Data\Kiwee Toolbar
C:\Documents and Settings\test\Application Data\AGI
C:\Documents and Settings\test\Application Data\Macromedia\Flash Player\#Security\FlashPlayerTrust\UnifiedToolbar.cfg
C:\Documents and Settings\test\Application Data\Mozilla\FireFox\Profiles\3pnx0o7j.default\searchplugins\kiwee-toolbar.xml
C:\Documents and Settings\test\Local Settings\Application Data\EoRezo
C:\Documents and Settings\test\Local Settings\Application Data\IMBooster4web-en
C:\Documents and Settings\test\Local Settings\Application Data\Kiwee Toolbar
C:\Program Files\Agence Exclusive
C:\Program Files\AGI
C:\Program Files\EoRezo
C:\Program Files\IMBooster4web-en
C:\Program Files\Iminent
C:\Program Files\Kiwee Toolbar
C:\Program Files\Mozilla FireFox\searchplugins\SearchTheWeb.xml
C:\Program Files\UnifiedToolbar
C:\WINDOWS\Installer\{E1B94435-241E-4519-B1C3-C4DD9EB352A2}
C:\WINDOWS\system32\Macromed\Flash\FlashPlayerTrust\UnifiedToolbar.cfg
.
HKCU\Software\AGI
HKCU\Software\EoRezo
HKCU\Software\IMBooster4web-en
HKCU\Software\Iminent
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0495F4D7-9FE3-4456-AA9D-1D57E78DF5F0}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1C99B848-84CB-4CE4-8CD8-ED5719484D9F}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{346DE098-61F9-4B42-89DA-6DFBA7091BB6}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4260e0cc-0f75-462e-88a3-1e05c248bf4c}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0495F4D7-9FE3-4456-AA9D-1D57E78DF5F0}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1C99B848-84CB-4CE4-8CD8-ED5719484D9F}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{346DE098-61F9-4B42-89DA-6DFBA7091BB6}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4260e0cc-0f75-462e-88a3-1e05c248bf4c}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6E9BAAF-53CD-4575-967B-2AF710A7D21F}
HKLM\Software\AgenceExclusive
HKLM\Software\AGI
HKLM\Software\Classes\AG.MediaPlayerCOM
HKLM\Software\Classes\agcore.Config.AGConfig
HKLM\Software\Classes\agcore.Search.Search
HKLM\Software\Classes\AgenceBHO.AEBHO
HKLM\Software\Classes\AgenceBHO.AEBHO.1
HKLM\Software\Classes\agihelper.AGUtils
HKLM\Software\Classes\AppID\{9B70CBA7-E01C-4e1f-B046-D13CD051A84B}
HKLM\Software\Classes\AppID\{AFBB7970-789A-4264-BA70-E8127DECE400}
HKLM\Software\Classes\AppID\AgenceBHO.DLL
HKLM\Software\Classes\AppID\EoEngineBHO.DLL
HKLM\Software\Classes\CLSID\{0495F4D7-9FE3-4456-AA9D-1D57E78DF5F0}
HKLM\Software\Classes\CLSID\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
HKLM\Software\Classes\CLSID\{1C99B848-84CB-4CE4-8CD8-ED5719484D9F}
HKLM\Software\Classes\CLSID\{26C9BBE4-6D45-4AB6-A5B4-E068C9F5EF6D}
HKLM\Software\Classes\CLSID\{346DE098-61F9-4B42-89DA-6DFBA7091BB6}
HKLM\Software\Classes\CLSID\{4260e0cc-0f75-462e-88a3-1e05c248bf4c}
HKLM\Software\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
HKLM\Software\Classes\CLSID\{696E3174-4F6C-4777-7834-654C4A705677}
HKLM\Software\Classes\CLSID\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}
HKLM\Software\Classes\CLSID\{96D282A7-6478-4E9D-9744-2841733448BC}
HKLM\Software\Classes\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
HKLM\Software\Classes\CLSID\{A6E9BAAF-53CD-4575-967B-2AF710A7D21F}
HKLM\Software\Classes\CLSID\{A93B530D-2B18-48C7-9F3C-281679403372}
HKLM\Software\Classes\CLSID\{E03BAFDC-EB9D-4C35-A7A2-AB6C62FF0A68}
HKLM\Software\Classes\CLSID\{E6375F37-E4D1-4F51-B651-4658C27AC5BF}
HKLM\Software\Classes\ComObject.DeskbarEnabler
HKLM\Software\Classes\ComObject.DeskbarEnabler.1
HKLM\Software\Classes\EoEngineBHO.EOBHO
HKLM\Software\Classes\EoEngineBHO.EOBHO.1
HKLM\Software\Classes\IminentBHONavigationError.CHelperBHO
HKLM\Software\Classes\IminentBHONavigationError.CHelperBHO.1
HKLM\Software\Classes\IminentLinkToContent.LinkToContent
HKLM\Software\Classes\IminentLinkToContent.LinkToContent.1
HKLM\Software\Classes\Installer\Products\53449B1EE14291541B3C4CDDE93B252A
HKLM\Software\Classes\Installer\Products\C73660D04266C3348A703CD454AD1B48
HKLM\Software\Classes\Interface\{0CA97EEE-C8C4-4B10-A332-10AF1FBEB534}
HKLM\Software\Classes\Interface\{12FB9C3D-0875-4CAA-B3B1-9DCCCE749DE5}
HKLM\Software\Classes\Interface\{3E16A203-C0AA-4D44-ACC5-38A70A8C76DA}
HKLM\Software\Classes\Interface\{492D9495-CC24-4460-8856-CF52179A3C3D}
HKLM\Software\Classes\Interface\{819DB72D-1C28-4387-9778-E2FF3DC86F74}
HKLM\Software\Classes\Interface\{DF76E9B7-35EC-46FC-AF56-5B79DED9D64F}
HKLM\Software\Classes\TypeLib\{18AF7201-4F14-4BCF-93FE-45617CF259FF}
HKLM\Software\Classes\TypeLib\{2C6674DB-EFB5-464A-A715-3E770B9C8A94}
HKLM\Software\Classes\TypeLib\{587D1093-12E0-4B0E-9426-AF9DC5ABB77D}
HKLM\Software\Classes\TypeLib\{77860007-19AE-4C29-B26D-AEA48F3A05C5}
HKLM\Software\Classes\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}
HKLM\Software\Classes\TypeLib\{C7403C30-3644-43D8-A82F-4BD84B9682D9}
HKLM\Software\Classes\TypeLib\{D105A2C4-36DA-49AD-BDB1-34215B3A9ED9}
HKLM\Software\Classes\UnifiedToolbar.UnifiedToolbar
HKLM\Software\Classes\urlsearchhook.toolbarurlsearchhook
HKLM\Software\Classes\urlsearchhook.toolbarurlsearchhook.1
HKLM\Software\EoRezo
HKLM\Software\iAvatars.com
HKLM\Software\IMBooster4web-en
HKLM\Software\Iminent
HKLM\Software\Loader
HKLM\Software\Microsoft\Code Store Database\Distribution Units\CabBuilder
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\13ab0a5e-e0aa-4c62-b498-e887995abd07
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\b498002a-aac3-42e3-89f9-3f8df7069fd4
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\fb7f86bc-f7e7-4758-b362-788fd33a2995
HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}
HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\Agence
HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\funkyemoticons
HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\helper
HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchTheWeb
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0495F4D7-9FE3-4456-AA9D-1D57E78DF5F0}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{346DE098-61F9-4B42-89DA-6DFBA7091BB6}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6E9BAAF-53CD-4575-967B-2AF710A7D21F}
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{96D282A7-6478-4E9D-9744-2841733448BC}
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\53449B1EE14291541B3C4CDDE93B252A
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\C73660D04266C3348A703CD454AD1B48
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0D06637C-6624-433C-A807-C34D45DAB184}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8AADE841-03C5-486A-B048-BB112CC0CAC5}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E1B94435-241E-4519-B1C3-C4DD9EB352A2}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Agence_is1
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\EoRezo_is1
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBooster
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBooster4web-en Toolbar
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWeb
HKU\.DEFAULT\Software\AGI
HKU\S-1-5-18\Software\AGI
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{346DE098-61F9-4B42-89DA-6DFBA7091BB6}
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{346de098-61f9-4b42-89da-6dfba7091bb6}
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{84FF7BD6-B47F-46F8-9130-01B2696B36CB}
HKLM\Software\Microsoft\Internet Explorer\Toolbar|{1C99B848-84CB-4CE4-8CD8-ED5719484D9F}
HKLM\Software\Microsoft\Internet Explorer\Toolbar|{346DE098-61F9-4B42-89DA-6DFBA7091BB6}
HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Eorezo
HKLM\Software\Microsoft\Windows\CurrentVersion\Run|IMBooster
HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Iminent.Notifier
HKLM\Software\Microsoft\Windows\CurrentVersion\Run|KiweeHook
HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Iminent\MMServer\Iminent.MMPlayer.swf
HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Iminent\MMServer\Iminent.MMServer.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Iminent\MMServer\Iminent.MMServer.WinTracker.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Iminent\MMServer\Iminent.MMServerPS.dll
HKLM\Software\Mozilla\Firefox\Extensions|unifiedtoolbar@aginteractive.com
.
.
============== SCAN ADDITIONNEL ==============
.
* Mozilla FireFox Version 3.5.1 (fr) *
.
C:\Documents and Settings\test\..\3pnx0o7j.default\prefs.js - browser.search.defaultenginename: Kiwee Toolbar
C:\Documents and Settings\test\..\3pnx0o7j.default\prefs.js - browser.search.selectedEngine: Google
C:\Documents and Settings\test\..\3pnx0o7j.default\prefs.js - browser.startup.homepage: hxxp://msn.fr
C:\Documents and Settings\test\..\3pnx0o7j.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.1.1
C:\Documents and Settings\test\..\3pnx0o7j.default\prefs.js - keyword.URL: hxxp://search.imgag.com/?appid=kwtb&component=UnifiedToolbarFF&c=EMKWO50024&sbs=1&sc=&f=web&vernum=3.2&uid=&did={e9dc98a6-8fdd-4f96-a2b7-b537dfa0c0b9}&q=
C:\Documents and Settings\rr\..\hminx9l0.default\prefs.js - browser.search.defaultenginename: MyStart Search
C:\Documents and Settings\rr\..\hminx9l0.default\prefs.js - browser.search.selectedEngine: MyStart Search
C:\Documents and Settings\rr\..\hminx9l0.default\prefs.js - browser.startup.homepage: hxxp://mystart.incredimail.com/
C:\Documents and Settings\rr\..\hminx9l0.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.1.1
C:\Documents and Settings\rr\..\hminx9l0.default\prefs.js - keyword.URL: hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&vernum=1.0&uid=&did=f8d4a70c-98e2-4081-901d-01bf93043ede&q=
.
TROUVÉ: C:\Documents and Settings\test\..\3pnx0o7j.default\prefs.js - user_pref("agcore.default.extid", "unifiedtoolbar@aginteractive.com");
TROUVÉ: C:\Documents and Settings\test\..\3pnx0o7j.default\prefs.js - user_pref("browser.search.defaultenginename", "Kiwee Toolbar");
TROUVÉ: C:\Documents and Settings\test\..\3pnx0o7j.default\prefs.js - user_pref("extensions.enabledItems", "webbooster@iminent.com:1.0.1007.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,unifiedtoolbar@aginteractive.com:3.0,SpiderMessengerHelper@spidermessenger.com:1.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.1");
TROUVÉ: C:\Documents and Settings\test\..\3pnx0o7j.default\prefs.js - user_pref("keyword.URL", "hxxp://search.imgag.com/?appid=kwtb&component=UnifiedToolbarFF&c=EMKWO50024&sbs=1&sc=&f=web&vernum=3.2&uid=&did={e9dc98a6-8fdd-4f96-a2b7-b537dfa0c0b9}&q=");
.
* Internet Explorer Version 8.0.6001.18702 *
.
[HKCU\Software\Microsoft\Internet Explorer\Main]
.
Do404Search: 0x01000000
Enable Browser Extensions: yes
First Home Page: hxxp://y.lo.st
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Show_ToolBar: yes
Start Page: hxxp://search.iminent.com/?appId=05b5994c-9b2a-40d0-9846-42be7b767c1a
Use Search Asst: no
.
[HKLM\Software\Microsoft\Internet Explorer\Main]
.
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
.
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
.
Tabs: hxxp://www.kiwee.com/websearch/index.pd?appid=kwtb&c=EMKWO50024&sbs=7&sc=2&f=web&vernum=3.2&uid=&did={e9dc98a6-8fdd-4f96-a2b7-b537dfa0c0b9}
Blank: res://mshtml.dll/blank.htm
.
========================================
.
C:\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Ad-Remover\Backup: 0 Fichier(s)
.
C:\Ad-Report-SCAN[1].txt - 486 Octet(s)
C:\Ad-Report-SCAN[2].txt - 486 Octet(s)
C:\Ad-Report-SCAN[3].txt - 15356 Octet(s)
.
Fin à: 15:18:35, 12/05/2010
.
============== E.O.F - SCAN[3] ==============

2 réponses

fred08700 Messages postés 3389 Date d'inscription lundi 19 janvier 2009 Statut Contributeur sécurité Dernière intervention 9 février 2014 550
12 mai 2010 à 15:37
salut

relances ad-remover ==> nettoyage et poste le rapport

ensuite , fais ceci

● Télécharges Random's System Information Tool (RSIT) de Random/Random, et enregistres le sur ton Bureau.

● Double clique sur RSIT.exe pour lancer l'outil.

● Cliques sur "Continue" à l'écran Disclaimer.

● Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande) et tu devras accepter la licence.

● Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

* Tutoriel illustré pour t'aider

* pour héberger les rapports trop longs de RSIT


0
Utilisateur anonyme
12 mai 2010 à 15:38
bonjour
relance AD Remover, et clique sur nettoyer
poste le rapport
Il est sauvegardé dans C:\Ad-Remover-CLEAN[1].txt
0