Bonjour,
Cet été j'avais laissé un message pour signaler que mon ordi se connectait automatiquement sur un site nommé EOREZO. On m'avait conseillé de scanner avec AD-Remover et de poster le rapport. N'ayant pu le faire du fait des vacances je m'en suis occupé ce matin. Le rapport est donc ci-dessous.
Merci d'avance
(je n'ai pas trouvé dans le choix de forum la rubrique "sécurité"
Rapport :
======= RAPPORT D'AD-REMOVER 1.1.4.5_V | UNIQUEMENT XP/VISTA/7 =======
.
Mit à jour par C_XX le 18/09/2009 à 9:00 PM
Contact:
AdRemover.contact@gmail.com
Site web:
http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 9:09:51, 07/10/2009 | Mode Normal | Option: CLEAN
Exécuté de: C:\Program Files\Ad-Remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 2 v5.1.2600
Nom du PC: PRINCIPAL | Utilisateur actuel: Alain
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.
HKCU\Software\EoRezo
HKLM\Software\Classes\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
HKLM\Software\Classes\AppID\EoRezoBHO.DLL
HKLM\Software\Classes\TypeLib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
HKLM\Software\EoRezo
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdate_is1
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\\{08165EA0-E946-11CF-9C87-00AA005127ED}
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\EoEngine
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SoftwareHelper
.
C:\Documents and Settings\Alain\Application Data\EoRezo
C:\Documents and Settings\Alain\Application Data\EoRezo\cache
C:\Documents and Settings\Alain\Application Data\EoRezo\cmhost.cyp
C:\Documents and Settings\Alain\Application Data\EoRezo\ConfMedia.cyp
C:\Documents and Settings\Alain\Application Data\EoRezo\db
C:\Documents and Settings\Alain\Application Data\EoRezo\eoDesktop
C:\Documents and Settings\Alain\Application Data\EoRezo\eoDesktop\config.xml
C:\Documents and Settings\Alain\Application Data\EoRezo\eoDesktop\eoDesktop.html
C:\Documents and Settings\Alain\Application Data\EoRezo\eoDesktop\userConfig.xml
C:\Documents and Settings\Alain\Application Data\EoRezo\host.cyp
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Download
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\help_config.cyp
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.1
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.10
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.10\itstv.exe
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.11
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.11\itstv.exe
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.12
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.12\itstv.exe
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.2
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.2\itstv.exe
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.3
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.3\itstv.exe
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.5
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.5\itstv.exe
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.6
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.6\itstv.exe
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.7
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.7\itstv.exe
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.8
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.8\itstv.exe
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.9
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.9\itstv.exe
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\SoftwareUpdate.exe
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\unins000.dat
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\unins000.exe
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\user_config.cyp
C:\Documents and Settings\Alain\Application Data\EoRezo\SoftwareUpdate\user_profil.cyp
C:\Documents and Settings\Alain\Application Data\EoRezo\user.cyp
C:\Documents and Settings\Alain\Cookies\alain@eorezo[2].txt
C:\WINDOWS\Prefetch\ITSTV.EXE-0626E9E1.pf
C:\WINDOWS\Prefetch\ITSTV.EXE-06BDA51A.pf
C:\WINDOWS\Prefetch\ITSTV.EXE-1F59D867.pf
C:\WINDOWS\Prefetch\ITSTV.EXE-20F13A89.pf
C:\WINDOWS\Prefetch\ITSTV.EXE-278E1E79.pf
C:\WINDOWS\Prefetch\SOFTWAREUPDATEHP.EXE-261A9D3C.pf
(!) -- Fichiers temporaires supprimés.
.
============== Scan additionnel ==============
.
.
* Mozilla FireFox Version 3.0.14 *
.
Nom du profil: j1g9f4qr.default (Alain)
.
(Prefs.js) user_pref("browser.search.defaultenginename", "Google");
(Prefs.js) user_pref("browser.search.selectedEngine", "Ask.com (Virtus Designs)");
(Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.google.fr");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.14");
(Invalidprefs.js) user_pref("browser.search.defaultenginename", "Google");
(Invalidprefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
(Invalidprefs.js) user_pref("browser.startup.homepage", "hxxp://y.lo.st");
(Invalidprefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.11");
.
(Invalidprefs.js) EFFACÉ: user_pref("browser.startup.homepage", "hxxp://y.lo.st");
(prefs.js) EFFACÉ: user_pref("browser.search.selectedEngine", "Ask.com (Virtus Designs)");
(prefs.js) EFFACÉ: user_pref("extensions.enabledItems", "askopensearch-VTS@ask.com:1.0.0.0,FFToolbar@bitdefender.com:2.0,{ba243cb0-b824-4a26-9418-73ee795d9b9d}:0.7.5,fr@dictionaries.addons.mozilla.org:2.1,{3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W,{6e84150a-d526-41f1-a480-a67d3fed910d}:1.4.4,{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02,{B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102,{5c876f30-10ce-11dd-bd0b-0800200c9a66}:3.5,{7694c49c-9fbd-11dc-8314-0800200c9a66}:3.0.2,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14,{ff356687-aa08-463d-a46c-11c451824939}:4.2.4");
.
* Internet Explorer Version 7.0.5730.11 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Start Page:
hxxp://fr.msn.com/
Search Page:
hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Default_search_url:
hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Default_page_url:
hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Search bar:
hxxp://go.microsoft.com/fwlink/?linkid=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL:
hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL:
hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page:
hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page:
hxxp://fr.msn.com/
Search bar:
hxxp://search.msn.com/spbasic.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs:
res://ieframe.dll/tabswelcome.htm
.
===================================
.
8059 Octet(s) - C:\Ad-Report-CLEAN.log
.
58 Fichier(s) - C:\DOCUME~1\Alain\LOCALS~1\Temp
168 Fichier(s) - C:\WINDOWS\Temp
.
19 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
22 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
.
Fin à: 9:22:37 | 07/10/2009
.
============== E.O.F ==============
.