Mauvais: keyloggers et screenshooters

Bonjour,

Quelques problemes de tailles que je n'ai découvert que récemment. Je suis infecté par plusieurs keyloggers et screenshooters, il semblerait. Ma défense:
-panda antivirus firewall 2008
-spyware terminator
-spybot search and destroy
-avg anti spyware

Le probleme majeur est que ces derniers n'ont jamais détecté ce qu'un prog récemment installé vient de faire:
-anti keylogger elite

Ce qu'il m'indique comme fichiers étant infecté par un keylogger: msctf.dll, A2contmenu.dll, shell32.dll, ltforms.dll et surement d'autres par la suite. De plus, il bloque continuellement des fichiers tentant de faire je ne sais quoi, le message est en anglais (par exemple: msctf.dll which have hooked ****.dll+nombre have been blocked, etc).

Donc que dois-je faire? Comment se fait-il que ça n'ait jamais été détecté avant? Est-ce dangereux? Quelle est la meilleure protection contre les keyloggers qui semblent être capable d'infecter n'importe quel dll sans se faire prendre? Et comment désinfecter tous ces dll sans rien delete?

Merci d'avance pour votre aide!

Kaizerchar, qui commence à s'inquiéter pour ses email et mdp...
Configuration: Windows XP
Firefox 2.0.0.14

5 réponses

  1. Maj de dernière minute, le log de l'anti keylogger

    06/17,2008 19:14:45 Allowed Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:14:45 Blocked Keylogger C:\PROGRA~1\A-SQUA~1\A2CONT~1.DLL
    06/17,2008 19:18:38 Allowed Keylogger C:\WINDOWS\system32\SHELL32.dll
    06/17,2008 19:18:42 Allowed Screen Shooter C:\WINDOWS\system32\SHELL32.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:38 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:48 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:48 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:48 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:48 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:48 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:48 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:48 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:48 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:23:48 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:24:00 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:24:10 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:32:43 Blocked Screen Shooter C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\LTForms.dll
    06/17,2008 19:43:51 Allowed Keylogger C:\WINDOWS\system32\ieframe.dll
    06/17,2008 19:43:51 Block Keylogger C:\WINDOWS\system32\MSCTF.dll
    06/17,2008 19:44:11 Block Keylogger C:\WINDOWS\system32\ieframe.dll
    0
    1. Up

      Personne pour m'aider?
      0
      1. Salut,

        Clique sur ce lien
        http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
        pour télécharger le fichier d'installation d'HijackThis.

        Enregistre HJTInstall.exe sur ton bureau.

        Double-clique sur HJTInstall.exe pour lancer le programme

        Par défaut, il s'installera là :
        C:\Program Files\Trend Micro\HijackThis

        Accepte la license en cliquant sur le bouton "I Accept"

        Ensuite, renommes le dede.exe.

        Puis clique sur "do a system scan and save a logfile" et postes le rapport
        0
        1. Merci pour votre réponse. Je vais le faire immédiatement mais est-ce que cela va résoudre tous les problemes? Et pour l'utilité de renommer, ce serait du au fait que certains malwares réagissent au nom original de l'anti malwares?
          0
      2. le rapport:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 5:56:08 AM, on 6/20/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16608)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
        C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AVENGINE.EXE
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
        C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
        C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
        C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
        C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
        C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\HP\QuickPlay\QPService.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
        C:\WINDOWS\system32\GSICON.EXE
        C:\WINDOWS\system32\dslagent.exe
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\DAEMON Tools\daemon.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
        C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
        C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
        C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
        C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE
        C:\Program Files\Anti Keylogger Elite\AKE.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
        C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
        C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\WebProxy.exe
        C:\WINDOWS\system32\drwtsn32.exe
        C:\WINDOWS\system32\drwtsn32.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\DAP\DAP.EXE
        C:\Program Files\Trend\HijaTis\tete.exe
        C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\avciman.exe
        C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\psimreal.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
        O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
        O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
        O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
        O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
        O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
        O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
        O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
        O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
        O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
        O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
        O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
        O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
        O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE" /s
        O4 - HKLM\..\Run: [ISS_SIP] C:\Program Files\Anti Keylogger Elite\AKE.exe
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Startup: Registration .LNK = C:\Program Files\Ubisoft\Dark Messiah of Might and Magic\RegistrationReminder.exe
        O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
        O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
        O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
        O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
        O8 - Extra context menu item: Crawler Search - tbr:iemenu
        O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
        O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - https://www.fileplanet.com/
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
        O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
        O20 - Winlogon Notify: winemx32 - winemx32.dll (file missing)
        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
        O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
        O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
        O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
        O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
        O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
        O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe
        O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
        O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
        0
        1. Re,

          Fais un scan avec Spybot et dis moi s'il trouve quelque chose.
          0