Avatar billede hans01 Nybegynder
11. december 2007 - 14:20 Der er 23 kommentarer og
1 løsning

Min browser sær

Jeg skriver fordi min browser IE6 opfører sig mærkeligt, igår måtte jeg installere panda antivirus program da der var trojanske heste og virus på min pc (Win2K) jeg fik samtidigt installeret zonealarm jeg fik alt fjernet, men min browser IE6 bliver ved med at åbne nye sider med mærkelige indhold. Kan min browser være hacket? eller hvad er galt, PS jeg har kørt alle windows opdateringer(tror jeg)
Avatar billede hans01 Nybegynder
11. december 2007 - 17:01 #1
er der virkeligt ingen der kan hjælpe jeg kan slet ikke åbne IE 6 så vælter det ind med ting jeg skal down loade hurtigere ind jeg kan lukke vinduerne.. hjæææælp
Avatar billede hans01 Nybegynder
11. december 2007 - 18:28 #2
Nåmen jeg har nu ændret lidt på active x instillingerne og kørt en spybot. fik ram på en lang række skidt.. men alligevel så åbner der stadigt en ny side med "stop Impaired driving" jeg tror ikke den skal reklamer ligger på ekspertens side.. eller hva?
11. december 2007 - 22:11 #3
... for en go' ordens skyld; stik os/mig en HiJackThis ->
http://www.spywareinfo.dk/index.htm#/manualer/hijackthis.htm

Bemærk at HiJackThis.exe programmet skal gemmes i en dertil oprettet mappe og IKKE køres direkte fra nettet...

PS: Brug denne version af HJT -> http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis.exe

(Jooo - jeg har 'virus' på hjernen...)
Avatar billede hans01 Nybegynder
12. december 2007 - 07:57 #4
Hej Karise Larry

Jeg har været igennem sådan noget tidligere, så jeg kører lige en hiJack this rap.
Avatar billede hans01 Nybegynder
12. december 2007 - 08:01 #5
Her er den så:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:15:41, on 12-12-2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv50.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\cisvc.exe
C:\WINNT\system32\CTSvcCDA.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\system32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\inKline Global\PC Booster\pcbooster.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
c:\program files\panda software\panda antivirus 2007\WebProxy.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINNT\System32\cidaemon.exe
C:\WINNT\g12071093.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\VoipBusterMate\VoipBusterMate.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINNT\system32\HPZipm12.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\WINNT\msagent\AgentSvr.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Panda Software\Panda Antivirus 2007\psimreal.exe
C:\Documents and Settings\HANS\Desktop\HiJackThis(2).exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2AE4005E-689F-4FB9-8C3D-D2B8B58AC072} - C:\WINNT\system32\hgghfcb.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {54195AF2-A99D-43AE-AEAB-DCE5EE69D58D} - C:\WINNT\system32\vtsqp.dll (file missing)
O2 - BHO: (no name) - {9CAA1535-79C0-466D-BBA6-D64E06C6AB10} - C:\WINNT\system32\pmnlm.dll
O2 - BHO: {7a5e9150-d120-a7d8-41e4-9da45aa32fdd} - {ddf23aa5-4ad9-4e14-8d7a-021d0519e5a7} - C:\WINNT\system32\knbqrkrx.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [PC Booster] C:\Program Files\inKline Global\PC Booster\pcbooster.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [a003fbcc] rundll32.exe "C:\WINNT\system32\veayqhpj.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [VoipStunt] "C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe" -nosplash -minimized
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSNAgent] C:\WINNT\g12071093.exe
O4 - HKUS\.DEFAULT\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: []  (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: VoipBusterMate.lnk = VoipBusterMate\VoipBusterMate.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1192814038750
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O20 - Winlogon Notify: hgghfcb - C:\WINNT\SYSTEM32\hgghfcb.dll
O20 - Winlogon Notify: tatpzqce - tatpzqce.dll (file missing)
O20 - Winlogon Notify: winzzc32 - winzzc32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTSvcCDA.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv50.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

--
End of file - 8973 bytes
Avatar billede hans01 Nybegynder
12. december 2007 - 17:20 #6
Er der ingen andre der umiddelbart kan gennemskue det, jeg har nu kørt spybot, adaware panda bare for at nævne nogen hele dagen jeg har tillige modtaget en IE opdate fra Microsoft men lige meget hjælper det...
12. december 2007 - 17:44 #7
Jeg ser på den - lige et øjeblik...
Avatar billede hans01 Nybegynder
12. december 2007 - 17:51 #8
Tusind tak, det er lidt af et gedemarked her, jeg kan slet ikke anvender IE6, så jeg ville være meget glad hvis du finder noget snavs
12. december 2007 - 17:57 #9
Der er ret så mange (>10) 'sjove' (u)ønskede elementer ifølge din log - og det er bare dem man kan se der!
Så jeg vil foreslå at lade http://www.eksperten.dk/artikler/1123 proceduren fixe dem - og sansynlig meget mere...

Jeg kan se at du - måske mere eller mindre mod din vilje - har installeret [Yahoo Toolbar] ?
Den er dog ikke 'farlig', men bare et irriterende program/toolbar som bare fylder op .
Hvis du vil slippe af med den kan du følge guiden herfra ->
http://support.microsoft.com/kb/303047
Avatar billede hans01 Nybegynder
12. december 2007 - 18:14 #10
Jamen det går jeg så igang med, jeg har installeret CCleaner, men cleaner ikke reg basen men det gør jeg så, har tillige superantispyware installeret, rootchk og combofix kører jeg lige, jeg vender lige tilbage med en frisk hijack når alt er lavet...
Avatar billede supersquirrel Nybegynder
12. december 2007 - 18:20 #11
Nu hvor du er igang, så prøv prevx.com :))
Avatar billede hans01 Nybegynder
12. december 2007 - 19:41 #12
Så er jeg klar med de 4 første log files:

1. rootlog.********************************* ROOTCHK-(5-12-07)-LOG, by ejvindh
on 12-12-2007 18:33:21,39

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-12 18:33:22
Windows 5.0.2195 Service Pack 4
scanning hidden processes ...

scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USB\Vid_6993&Pid_b001&Mi_00\6&1c525841&0&0\Device Parameters]
"HWRevision?U\x2039\xec\x81\xec\xcc?"="1"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\USB\Vid_6993&Pid_b001&Mi_00\6&1c525841&0&0\Device Parameters]
"HWRevision?U\x2039\xec\x81\xec\xcc?"="1"

scanning hidden registry entries ...

scanning hidden files ...

hidden processes: 0
hidden services: 0
hidden files: 0

2. super spyware:

SUPERAntiSpyware Scan Log
Generated 12/12/2007 at 07:42 PM

Application Version : 3.6.1000

Core Rules Database Version : 3359
Trace Rules Database Version: 1358

Scan type      : Complete Scan
Total Scan Time : 00:52:10

Memory items scanned      : 160
Memory threats detected  : 0
Registry items scanned    : 6336
Registry threats detected : 5
File items scanned        : 36964
File threats detected    : 1

Adware.Vundo Variant
    HKLM\Software\Classes\CLSID\{54195AF2-A99D-43AE-AEAB-DCE5EE69D58D}
    HKCR\CLSID\{54195AF2-A99D-43AE-AEAB-DCE5EE69D58D}
    HKCR\CLSID\{54195AF2-A99D-43AE-AEAB-DCE5EE69D58D}\InprocServer32
    HKCR\CLSID\{54195AF2-A99D-43AE-AEAB-DCE5EE69D58D}\InprocServer32#ThreadingModel
    C:\WINNT\SYSTEM32\VTSQP.DLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{54195AF2-A99D-43AE-AEAB-DCE5EE69D58D}

3. combofix:

ComboFix 07-12-12.3 - HANS 12-12-2007 18:36:31.1 - NTFSx86
Microsoft Windows 2000 Professional  5.0.2195.4.1252.1.1033.18.425 [GMT 1:00]
Running from: C:\Documents and Settings\HANS\Desktop\ComboFix.exe
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Hans Lundqvist\Application Data\unins000.exe
C:\WINNT\cookies.ini
C:\WINNT\system32\byxwxyy.dll
C:\WINNT\system32\fccywxv.dll
C:\WINNT\system32\hgghfcb.dll
C:\WINNT\system32\mlnmp.ini
C:\WINNT\system32\mlnmp.ini2
C:\WINNT\system32\pmnlm.dll
C:\WINNT\system32\pqstv.ini
C:\WINNT\system32\pqstv.ini2
C:\WINNT\system32\tatpzqce.dllbox

.
(((((((((((((((((((((((((  Files Created from 2007-11-12 to 2007-12-12  )))))))))))))))))))))))))))))))
.

2007-12-12 16:02 . 07-12-12 16:04     1,429    --a------    C:\WINNT\imsins.BAK
2007-12-12 10:59 . 07-12-12 10:59     85,568    --a------    C:\WINNT\system32\4575.tmp
2007-12-12 10:30 . 07-12-12 18:46     37    d-a------    C:\WINNT\.
2007-12-12 10:17 . 07-12-12 18:46     37    d-a------    C:\WINNT\.
2007-12-12 10:04 . 07-12-12 18:46     37    d-a------    C:\WINNT\.
2007-12-12 09:51 . 07-12-12 18:46     37    d-a------    C:\WINNT\.
2007-12-12 09:38 . 07-12-12 18:46     37    d-a------    C:\WINNT\.
2007-12-12 09:25 . 07-12-12 18:46     37    d-a------    C:\WINNT\.
2007-12-12 09:17 . 07-12-12 09:17     885,340    --ahs----    C:\WINNT\system32\vssvkssc.ini
2007-12-12 08:59 . 07-12-12 18:46     37    d-a------    C:\WINNT\.
2007-12-12 08:34 . 07-12-12 18:46     37    d-a------    C:\WINNT\.
2007-12-12 08:25 . 07-12-12 08:25     <DIR>    d--------    C:\Program Files\Lavasoft
2007-12-12 08:25 . 07-12-12 08:25     <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-12 08:23 . 07-12-12 08:23     <DIR>    d--------    C:\Program Files\Common Files\Wise Installation Wizard
2007-12-12 08:21 . 07-12-12 18:46     37    d-a------    C:\WINNT\.
2007-12-11 17:12 . 07-12-12 18:46     37    d-a------    C:\WINNT\.
2007-12-11 15:56 . 07-12-11 15:56     <DIR>    d--h-----    C:\Documents and Settings\HANS\InstallAnywhere
2007-12-11 14:36 . 07-12-12 18:46     37    d-a------    C:\WINNT\.
2007-12-11 14:23 . 07-12-12 18:46     37    d-a------    C:\WINNT\.
2007-12-11 14:10 . 07-12-12 18:46     37    d-a------    C:\WINNT\.
2007-12-11 13:21 . 07-12-12 08:54     884,726    --ahs----    C:\WINNT\system32\jphqyaev.ini
2007-12-11 10:09 . 07-12-12 17:59     37    --a------    C:\WINNT\E
2007-12-11 09:16 . 07-12-11 09:16     37    --a------    C:\WINNT\Q
2007-12-10 20:12 . 07-12-11 19:32     744,338    ---h-----    C:\WINNT\ShellIconCache
2007-12-10 20:09 . 07-12-12 12:32     <DIR>    d--------    C:\Program Files\MSN Messenger
2007-12-10 18:00 . 07-12-12 15:59     37    --a------    C:\WINNT\u
2007-12-10 17:41 . 07-12-10 17:41     <DIR>    d--------    C:\Documents and Settings\HANS\Application Data\Kerio
2007-12-10 17:29 . 07-12-10 17:29     37    --a------    C:\WINNT\r007
2007-12-10 17:28 . 07-12-10 17:28     37    --a------    C:\WINNT\p
2007-12-10 17:27 . 07-12-10 17:45     <DIR>    d-a------    C:\WINNT\system32\PAV
2007-12-10 17:27 . 06-02-22 10:50     70,656    --a------    C:\WINNT\system32\drivers\PAVDRV50.SYS
2007-12-10 17:27 . 05-09-27 12:13     45,056    --a------    C:\WINNT\system32\avldr.dll
2007-12-10 17:26 . 07-12-10 17:26     <DIR>    d-a------    C:\Program Files\Panda Software
2007-12-10 15:53 . 05-07-26 12:39     66,048    --a------    C:\WINNT\system32\drivers\kvpndrv.sys
2007-12-10 14:04 . 07-12-10 14:04     28,672    --a------    C:\WINNT\system32\drivers\CO_Mon.sys
2007-12-10 13:28 . 07-12-12 12:44     <DIR>    d-a------    C:\WINNT\system32\ZoneLabs
2007-12-10 13:28 . 07-12-10 13:28     <DIR>    d-a------    C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-10 13:28 . 04-04-27 04:40     11,264    --a------    C:\WINNT\system32\SpOrder.dll
2007-12-10 13:28 . 07-12-11 08:09     4,212    --ah-----    C:\WINNT\system32\zllictbl.dat
2007-12-10 13:27 . 07-12-12 18:42     <DIR>    d-a------    C:\WINNT\Internet Logs
2007-12-10 12:18 . 07-12-11 12:19     896,342    --ahs----    C:\WINNT\system32\ivxktpks.ini
2007-12-09 12:08 . 07-12-10 12:48     <DIR>    d--------    C:\Program Files\Helper
2007-12-09 12:08 . 07-12-09 12:17     57,856    --a------    C:\pgdxf.exe
2007-12-09 12:08 . 07-12-09 12:08     37,043    --a------    C:\WINNT\g12071093.exe
2007-12-09 12:08 . 07-12-09 12:17     2    --a------    C:\-1610351773
2007-12-09 10:45 . 07-12-09 10:45     <DIR>    d--------    C:\Program Files\Common Files\Scanner
2007-12-09 10:43 . 07-12-09 10:43     <DIR>    d--------    C:\Documents and Settings\HANS\Application Data\Yahoo!
2007-12-09 10:41 . 07-12-11 08:34     54,156    --ah-----    C:\WINNT\QTFont.qfn
2007-12-09 10:41 . 07-12-09 10:41     1,409    --a------    C:\WINNT\QTFont.for
2007-12-09 10:35 . 07-12-09 10:45     <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-09 09:37 . 07-12-09 09:37     <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\e-Safekey
2007-12-08 15:29 . 07-12-08 15:30     <DIR>    d--------    C:\Program Files\SmartFTP Client 2.5 Setup Files
2007-12-07 19:40 . 07-12-07 19:40     <DIR>    d--------    C:\WINNT\winsxs
2007-12-07 18:51 . 07-12-07 18:57     <DIR>    d--------    C:\CrashLogs
2007-12-07 18:36 . 07-12-07 18:49     <DIR>    d--------    C:\Documents and Settings\HANS\Application Data\OfficeUpdate12
2007-12-07 18:35 . 07-12-07 18:35     <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2007-12-07 18:08 . 07-12-07 18:26     <DIR>    d--------    C:\Documents and Settings\HANS\Application Data\VoipBuster
2007-12-07 18:08 . 99-10-12 15:57     68,912    --a------    C:\WINNT\system32\drivers\USBAUDIO.sys
2007-12-07 18:08 . 99-10-12 15:57     68,912    --a--c---    C:\WINNT\system32\dllcache\usbaudio.sys
2007-12-07 18:07 . 07-12-12 10:45     <DIR>    d--------    C:\Program Files\VoipBusterMate
2007-12-07 18:07 . 07-12-07 18:07     <DIR>    d--------    C:\Program Files\VoipBuster.com
2007-12-07 16:20 . 07-12-07 16:56     1,279    --a------    C:\WINNT\mozver.dat
2007-12-07 14:10 . 07-12-07 14:10     <DIR>    d-a------    C:\WINNT\system32\html
2007-12-07 14:10 . 07-12-07 14:10     <DIR>    d-a------    C:\WINNT\system32\0
2007-12-07 14:10 . 07-12-07 14:10     <DIR>    d-a------    C:\WINNT\system32\-1
2007-12-07 13:46 . 07-12-07 13:46     <DIR>    d--------    C:\Program Files\Common Files\Adaptec Shared
2007-12-07 13:40 . 03-01-10 16:21     2,953,216    --a------    C:\WINNT\system32\wmploc.dll
2007-12-07 13:39 . 07-12-07 13:39     <DIR>    d--h-c---    C:\WINNT\$SQLUninstallMDAC28-KB927779-x86-ENU$
2007-12-07 13:36 . 07-10-31 02:17     2,109,440    -----c---    C:\WINNT\system32\dllcache\wmvcore.dll
2007-12-07 12:46 . 07-12-07 12:46     <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SlySoft
2007-12-07 12:43 . 07-12-07 12:43     24    ---hs----    C:\WINNT\S2AF2A0A5.tmp
2007-12-07 12:42 . 07-12-07 12:42     <DIR>    d--------    C:\Program Files\SlySoft
2007-12-03 15:09 . 07-12-03 15:09     <DIR>    d--------    C:\Documents and Settings\HANS\Application Data\Alien Skin
2007-11-30 16:23 . 07-11-30 16:23     97,216    --a------    C:\WINNT\system32\drivers\AnyDVD.sys
2007-11-26 10:58 . 07-12-10 15:22     <DIR>    d--------    C:\Program Files\Google
2007-11-22 18:24 . 07-11-22 18:24     <DIR>    d--------    C:\Documents and Settings\HANS\Application Data\Apple Computer
2007-11-22 18:17 . 07-12-12 12:33     <DIR>    d--------    C:\Program Files\QuickTime
2007-11-22 18:17 . 07-11-22 18:17     <DIR>    d-a------    C:\Documents and Settings\All Users\Application Data\Apple Computer

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-12 17:31    ---------    d-----w    C:\Program Files\SUPERAntiSpyware
2007-12-12 15:57    ---------    d-----w    C:\Documents and Settings\HANS\Application Data\IBP
2007-12-12 11:34    ---------    d-----w    C:\Program Files\SmartFTP Client 2.0
2007-12-12 07:17    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-12 07:13    7,524    ----a-w    C:\Program Files\hijackthis.log
2007-12-11 14:27    ---------    d-----w    C:\Program Files\Opera
2007-12-11 08:07    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-10 16:55    ---------    d--h--w    C:\Program Files\InstallShield Installation Information
2007-12-09 09:45    ---------    d-----w    C:\Program Files\Yahoo!
2007-12-07 13:32    ---------    d-----w    C:\Program Files\SummaSummarum
2007-12-07 12:46    58,000    ----a-w    C:\WINNT\system32\drivers\cdr4_2K.sys
2007-12-07 12:46    57,344    ----a-w    C:\WINNT\uneng.exe
2007-12-07 12:46    23,420    ----a-w    C:\WINNT\system32\drivers\cdralw2k.sys
2007-11-10 07:15    ---------    d-----w    C:\Documents and Settings\HANS\Application Data\Ahead
2007-11-10 07:15    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Ahead
2007-10-31 09:46    ---------    d---a-w    C:\Documents and Settings\All Users\Application Data\Adobe Systems
2007-10-31 09:45    ---------    d-----w    C:\Program Files\Common Files\Adobe
2007-10-31 09:43    ---------    d-----w    C:\Program Files\Common Files\Adobe Systems Shared
2007-10-24 08:25    ---------    d-----w    C:\Program Files\EasyPHP1-8
2007-10-23 12:54    ---------    d-----w    C:\Documents and Settings\HANS\Application Data\Creative
2007-10-23 07:08    ---------    d-----w    C:\Program Files\microsoft frontpage
2007-10-22 15:46    ---------    d-----w    C:\Program Files\ATI Technologies
2007-10-22 09:57    524,288    ----a-w    C:\WINNT\opuc.dll
2007-10-22 05:54    ---------    d-----w    C:\Program Files\Common Files\Vbox
2007-10-21 08:40    ---------    d-----w    C:\Documents and Settings\HANS\Application Data\SUPERAntiSpyware.com
2007-10-21 08:36    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Webroot
2007-10-21 08:36    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-21 08:36    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-21 08:36    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\SBT
2007-10-21 08:35    ---------    d-----w    C:\Documents and Settings\Default User\Application Data\Talkback
2007-10-21 08:35    ---------    d-----w    C:\Documents and Settings\Default User\Application Data\AVG7
2007-10-21 08:35    ---------    d-----w    C:\Documents and Settings\Default User\Application Data\AdobeUM
2007-10-21 08:23    ---------    d---a-w    C:\Documents and Settings\Hans Lundqvist\Application Data\Leadertech
2007-10-21 08:23    ---------    d---a-w    C:\Documents and Settings\Hans Lundqvist\Application Data\Creative
2007-10-21 08:23    ---------    d---a-w    C:\Documents and Settings\Hans Lundqvist\Application Data\AdobeUM
2007-10-21 08:23    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\Lavasoft
2007-10-21 08:23    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\Jasc
2007-10-21 08:23    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\Image Zone Express
2007-10-21 08:23    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\IBP
2007-10-21 08:23    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\CoffeeCup Software
2007-10-21 08:23    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\AVG7
2007-10-21 08:23    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\Apple Computer
2007-10-21 08:23    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\AI Internet Solutions
2007-10-21 08:22    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\Microsoft Web Folders
2007-10-21 08:21    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\Talkback
2007-10-21 08:21    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\SUPERAntiSpyware.com
2007-10-21 08:21    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\SpamPal
2007-10-21 08:21    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\SPAMfighter
2007-10-21 08:21    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\SmartFTP
2007-10-21 08:21    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\Sereniti
2007-10-21 08:21    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\Printer Info Cache
2007-10-21 08:21    ---------    d-----w    C:\Documents and Settings\Hans Lundqvist\Application Data\OfficeUpdate12
2007-10-21 08:03    ---------    d---a-w    C:\Documents and Settings\sara\Application Data\Symantec
2007-10-21 08:03    ---------    d---a-w    C:\Documents and Settings\sara\Application Data\Creative
2007-10-21 08:03    ---------    d-----w    C:\Documents and Settings\sara\Application Data\Talkback
2007-10-21 08:03    ---------    d-----w    C:\Documents and Settings\sara\Application Data\Sereniti
2007-10-21 08:03    ---------    d-----w    C:\Documents and Settings\sara\Application Data\Lavasoft
2007-10-21 08:02    ---------    d-----w    C:\Documents and Settings\SYSTEM\Application Data\Talkback
2007-10-21 08:02    ---------    d-----w    C:\Documents and Settings\SYSTEM\Application Data\AdobeUM
2007-10-21 07:58    ---------    d-----w    C:\Program Files\X-Cleaner
2007-10-21 07:58    ---------    d-----w    C:\Program Files\Windows Journal Viewer
2007-10-21 07:58    ---------    d-----w    C:\Program Files\WebWriter4
2007-10-21 07:58    ---------    d-----w    C:\Program Files\Viewpoint
2007-10-21 07:58    ---------    d-----w    C:\Program Files\USBToolbox
2007-10-21 07:57    ---------    d-----w    C:\Program Files\Tablet
2007-10-21 07:57    ---------    d-----w    C:\Program Files\SourceTec
2007-10-21 07:57    ---------    d-----w    C:\Program Files\Snapshot Viewer
2007-10-21 07:57    ---------    d-----w    C:\Program Files\SmartFTP Client 2.0 Setup Files
2007-10-21 07:57    ---------    d-----w    C:\Program Files\Return to Castle Wolfenstein
2007-10-21 07:45    ---------    d-----w    C:\Program Files\PCB
2007-10-21 07:45    ---------    d-----w    C:\Program Files\Overland
2007-10-21 07:45    ---------    d-----w    C:\Program Files\MSXML 4.0
2007-10-21 07:45    ---------    d-----w    C:\Program Files\Microsoft Script Debugger
2007-10-21 07:44    ---------    d-----w    C:\Program Files\Microsoft Data Analyzer
2007-10-21 07:44    ---------    d-----w    C:\Program Files\Microsoft AntiSpyware
2007-10-21 07:44    ---------    d-----w    C:\Program Files\Maguma
2007-10-21 07:44    ---------    d-----w    C:\Program Files\Logitech
2007-10-21 07:43    ---------    d-----w    C:\Program Files\Java
2007-10-21 07:41    ---------    d-----w    C:\Program Files\ITEKSOFT
2007-10-21 07:41    ---------    d-----w    C:\Program Files\inKline Global
2007-10-21 07:41    ---------    d-----w    C:\Program Files\IFBIN
2007-10-21 07:41    ---------    d-----w    C:\Program Files\IBP 8
2007-10-21 07:41    ---------    d-----w    C:\Program Files\hp deskjet 930c series
2007-10-21 07:39    ---------    d-----w    C:\Program Files\GroupMail 5
2007-10-21 07:39    ---------    d-----w    C:\Program Files\Galax_Sync
2007-10-21 07:39    ---------    d-----w    C:\Program Files\FireTune
2007-10-21 07:32    ---------    d-----w    C:\Program Files\Eidos Interactive
2007-10-21 07:31    ---------    d-----w    C:\Program Files\directx
2007-10-21 07:31    ---------    d-----w    C:\Program Files\DeKnop
2007-10-21 07:30    ---------    d-----w    C:\Program Files\Creative
2007-10-21 07:30    ---------    d-----w    C:\Program Files\backups
2007-10-21 07:30    ---------    d-----w    C:\Program Files\Audacity
2007-10-21 07:30    ---------    d-----w    C:\Program Files\Apple Software Update
2007-10-21 07:30    ---------    d-----w    C:\Program Files\Apperson
2007-10-21 07:30    ---------    d-----w    C:\Program Files\Apache Software Foundation
2007-10-21 07:30    ---------    d-----w    C:\Program Files\AOL Security Toolbar
2007-10-21 07:30    ---------    d-----w    C:\Program Files\Ahead
2007-10-21 07:29    ---------    d-----w    C:\Program Files\E-Color
2007-10-21 07:29    ---------    d-----w    C:\Program Files\Actinic v8
2007-10-21 07:18    ---------    d-----w    C:\Documents and Settings\HANS\Application Data\ATI
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54195AF2-A99D-43AE-AEAB-DCE5EE69D58D}]
            C:\WINNT\system32\vtsqp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7ab8a650-77f5-4956-82c7-3ee7c4aeaa5a}]
            C:\WINNT\system32\hwerbdoa.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SmartFTP Drop]
@={EA5A76F7-8138-4B53-B0F5-ADCC730CAFBD}

[HKEY_CLASSES_ROOT\CLSID\{EA5A76F7-8138-4B53-B0F5-ADCC730CAFBD}]
07-12-05 00:41     472376    --a------    C:\Program Files\SmartFTP Client 2.0\sfShellTools.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [05-03-21 15:13  C:\WINNT\system32\CTFMON.EXE]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [07-03-12 12:49 ]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [07-03-08 09:17 ]
"VoipStunt"="C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe" []
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [07-11-30 16:28 ]
"VoipBuster"="C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" [07-06-21 12:26 ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [07-09-04 16:40 ]
"MSNAgent"="C:\WINNT\g12071093.exe" [07-12-09 12:08 ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 11:05  C:\WINNT\system32\mobsync.exe]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [05-01-12 14:54 ]
"PC Booster"="C:\Program Files\inKline Global\PC Booster\pcbooster.exe" [05-12-28 11:39 ]
"NvCplDaemon"="RUNDLL32.exe" [99-12-07 13:00  C:\WINNT\system32\rundll32.exe]
"nwiz"="nwiz.exe" [06-08-11 14:43  C:\WINNT\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [99-12-07 13:00  C:\WINNT\system32\rundll32.exe]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [05-02-22 21:21 ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [07-02-16 10:54 ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [07-10-10 19:51 ]
"APVXDWIN"="C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.exe" [06-09-13 07:59 ]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [07-09-06 16:14 ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [05-02-22 21:21 ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 11:05 ]

C:\Documents and Settings\HANS\Start Menu\Programs\Startup\
VoipBusterMate.lnk - C:\Program Files\VoipBusterMate\VoipBusterMate.exe [2006-07-24 10:36:40]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ATI CATALYST System Tray.lnk - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe [2005-02-22 21:21:26]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 21:31:38]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 22:06:36]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 05:05:56]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 05-09-27 12:13  45056 C:\WINNT\system32\avldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tatpzqce]
tatpzqce.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winzzc32]
winzzc32.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages    REG_MULTI_SZ      msv1_0 C:\WINNT\system32\pmnlm.dll

R0 viamraid;viamraid;C:\WINNT\system32\DRIVERS\viamraid.sys
R0 viaagp1;VIA AGP Filter;C:\WINNT\system32\DRIVERS\viaagp1.sys
R3 usbhub20;USB 2.0 Root Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys
S3 agony;agony;\??\C:\Documents and Settings\HANS\Desktop\wininit.sys
S3 kvpndev;Kerio VPN adapter;C:\WINNT\system32\DRIVERS\kvpndrv.sys
S3 viafilter;VIA USB Filter;C:\WINNT\system32\Drivers\viausb.sys

*Newly Created Service* - SHAREDACCESS
.
Contents of the 'Scheduled Tasks' folder
"2007-12-12 08:00:01 C:\WINNT\Tasks\backup.job"
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-12 18:46:14
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINNT\system32\winlogon.exe
-> C:\WINNT\system32\NavLogon.dll
.
Completion time: 2007-12-12 18:47:23 - machine was rebooted
.
2007-12-12 15:04:42    --- E O F --- 


4. hijack
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:50:46, on 12-12-2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv50.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINNT\System32\cisvc.exe
C:\WINNT\system32\CTSvcCDA.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\system32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\inKline Global\PC Booster\pcbooster.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
c:\program files\panda software\panda antivirus 2007\WebProxy.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINNT\g12071093.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\VoipBusterMate\VoipBusterMate.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINNT\system32\HPZipm12.exe
C:\Documents and Settings\HANS\Desktop\HiJackThis(2).exe
C:\Program Files\HP\hpcoretech\comp\hpdarc.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: {a5aaea4c-7ee3-7c28-6594-5f77056a8ba7} - {7ab8a650-77f5-4956-82c7-3ee7c4aeaa5a} - C:\WINNT\system32\hwerbdoa.dll (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [PC Booster] C:\Program Files\inKline Global\PC Booster\pcbooster.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [VoipStunt] "C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe" -nosplash -minimized
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSNAgent] C:\WINNT\g12071093.exe
O4 - HKUS\.DEFAULT\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: VoipBusterMate.lnk = VoipBusterMate\VoipBusterMate.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1192814038750
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O20 - Winlogon Notify: tatpzqce - tatpzqce.dll (file missing)
O20 - Winlogon Notify: winzzc32 - winzzc32.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTSvcCDA.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv50.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

--
End of file - 8483 bytes

vender lige tilbage med prevx.com
Avatar billede hans01 Nybegynder
12. december 2007 - 19:51 #13
så er prevx loggen her:

Prevx CSI Build:  (v1.2.101.109)
Prevx Computer Security Investigator Output Log
System analyzed at: 12/12/07 at 20:03:47

C:\WINNT\system32\ntdll.dll
    Loaded into: C:\WINNT\System32\smss.exe
    Loaded into: C:\WINNT\system32\csrss.exe
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv50.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\system32\CTSvcCDA.EXE
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\regsvc.exe
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\stisvc.exe
    Loaded into: C:\WINNT\System32\WBEM\WinMgmt.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    Loaded into: C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    Loaded into: C:\WINNT\system32\RUNDLL32.EXE
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\QuickTime\qttask.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\WINNT\system32\ctfmon.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: c:\program files\panda software\panda antivirus 2007\WebProxy.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\psimreal.exe
    Loaded into: C:\Documents and Settings\HANS\Desktop\PREVXCSIFREE.EXE
PX5: 5ADDFB4F10980C22611207E53C01FB0086A6B4B1
MD5: 4c0f0b57de8c1669aa6f49d285b3865a
Determination: GOOD

C:\WINNT\System32\sfcfiles.dll
    Loaded into: C:\WINNT\System32\smss.exe
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
PX5: B2D3A702102A6529D9870EE8BCAC9A00E52AF584
MD5: 7645645bb506c26b96b8f31893378c4b
Determination: GOOD

C:\WINNT\system32\CSRSS.EXE
    Loaded into: C:\WINNT\system32\CSRSS.EXE
    Loaded into: C:\WINNT\system32\csrss.exe
PX5: A2D490031055CF0015CE001FC3A854004FEE9BAE
MD5: 6533392c5af4bf5c7ff12e453dd59ae5
Determination: GOOD

C:\WINNT\system32\CSRSRV.dll
    Loaded into: C:\WINNT\system32\csrss.exe
PX5: 9C56579A104D4D2D89D8002D0119FD008FCCF2BD
MD5: a863252332fffe4c530b5f1aa2cbb292
Determination: GOOD

C:\WINNT\system32\basesrv.dll
    Loaded into: C:\WINNT\system32\csrss.exe
PX5: DF503C1810563E9BB56F002E9E85D8008C9EA4F9
MD5: 4daebd9f0f5b16fbdae8f26cd4ab7b74
Determination: GOOD

C:\WINNT\system32\winsrv.dll
    Loaded into: C:\WINNT\system32\csrss.exe
PX5: 1C9DBCB810462CE7BF78036BA6BFD9009BD00A60
MD5: e3211e4884a21375f4d64a4b3986bca3
Determination: GOOD

C:\WINNT\system32\USER32.dll
    Loaded into: C:\WINNT\system32\csrss.exe
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv50.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\system32\CTSvcCDA.EXE
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\stisvc.exe
    Loaded into: C:\WINNT\System32\WBEM\WinMgmt.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    Loaded into: C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    Loaded into: C:\WINNT\system32\RUNDLL32.EXE
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\QuickTime\qttask.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\WINNT\system32\ctfmon.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: c:\program files\panda software\panda antivirus 2007\WebProxy.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\psimreal.exe
    Loaded into: C:\Documents and Settings\HANS\Desktop\PREVXCSIFREE.EXE
PX5: 46EB9B0510B30AE7D10905A866B71100685F0A34
MD5: 40023a7103796b1af6ca41a6dbc54775
Determination: GOOD

C:\WINNT\system32\KERNEL32.dll
    Loaded into: C:\WINNT\system32\csrss.exe
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv50.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\system32\CTSvcCDA.EXE
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\regsvc.exe
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\stisvc.exe
    Loaded into: C:\WINNT\System32\WBEM\WinMgmt.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    Loaded into: C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    Loaded into: C:\WINNT\system32\RUNDLL32.EXE
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\QuickTime\qttask.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\WINNT\system32\ctfmon.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: c:\program files\panda software\panda antivirus 2007\WebProxy.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\psimreal.exe
    Loaded into: C:\Documents and Settings\HANS\Desktop\PREVXCSIFREE.EXE
PX5: 7F40BB7C10A54681E1C70A422BD7080003DBAD1D
MD5: 0ab23b46ccaeba64d748a5cf79cb4bb6
Determination: GOOD

C:\WINNT\system32\GDI32.dll
    Loaded into: C:\WINNT\system32\csrss.exe
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv50.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\system32\CTSvcCDA.EXE
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\stisvc.exe
    Loaded into: C:\WINNT\System32\WBEM\WinMgmt.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    Loaded into: C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    Loaded into: C:\WINNT\system32\RUNDLL32.EXE
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\QuickTime\qttask.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\WINNT\system32\ctfmon.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: c:\program files\panda software\panda antivirus 2007\WebProxy.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\psimreal.exe
    Loaded into: C:\Documents and Settings\HANS\Desktop\PREVXCSIFREE.EXE
PX5: 528AA68110C0E0A39739038D1FE21200C3EE0DE2
MD5: d395c9eeac3b9a6c5b90ce00e50fff78
Determination: GOOD

C:\WINNT\system32\MSVCRT.dll
    Loaded into: C:\WINNT\system32\csrss.exe
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\stisvc.exe
    Loaded into: C:\WINNT\System32\WBEM\WinMgmt.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    Loaded into: C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    Loaded into: C:\WINNT\system32\RUNDLL32.EXE
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\QuickTime\qttask.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\WINNT\system32\ctfmon.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: c:\program files\panda software\panda antivirus 2007\WebProxy.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\Documents and Settings\HANS\Desktop\PREVXCSIFREE.EXE
PX5: C5139EBD35560958602F04816A7BD0006832D602
MD5: ba7be6f92680b28b9031170659fd222d
Determination: GOOD

C:\WINNT\system32\WINLOGON.EXE
    Loaded into: C:\WINNT\system32\WINLOGON.EXE
    Loaded into: C:\WINNT\system32\winlogon.exe
PX5: 77DCA6EE1095F66BD93D02C03593BB002490A791
MD5: bb1daf6a5737652646d52665251a0265
Determination: GOOD

C:\WINNT\system32\ADVAPI32.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv50.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\system32\CTSvcCDA.EXE
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\regsvc.exe
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\stisvc.exe
    Loaded into: C:\WINNT\System32\WBEM\WinMgmt.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    Loaded into: C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    Loaded into: C:\WINNT\system32\RUNDLL32.EXE
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\QuickTime\qttask.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\WINNT\system32\ctfmon.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: c:\program files\panda software\panda antivirus 2007\WebProxy.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\psimreal.exe
    Loaded into: C:\Documents and Settings\HANS\Desktop\PREVXCSIFREE.EXE
PX5: 78F9CF1A10A3631A1FCB06F759DE310003AE40D9
MD5: 67d5fc28cab4066922da01eb9c28167a
Determination: GOOD

C:\WINNT\system32\RPCRT4.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv50.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\system32\CTSvcCDA.EXE
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\regsvc.exe
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\stisvc.exe
    Loaded into: C:\WINNT\System32\WBEM\WinMgmt.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    Loaded into: C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    Loaded into: C:\WINNT\system32\RUNDLL32.EXE
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\QuickTime\qttask.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\WINNT\system32\ctfmon.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: c:\program files\panda software\panda antivirus 2007\WebProxy.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\psimreal.exe
    Loaded into: C:\Documents and Settings\HANS\Desktop\PREVXCSIFREE.EXE
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Rpc\ClientProtocols\ncacn_np    rpcrt4.dll
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Rpc\ClientProtocols\ncacn_ip_tcp    rpcrt4.dll
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Rpc\ClientProtocols\ncadg_ip_udp    rpcrt4.dll
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Rpc\ClientProtocols\ncacn_nb_tcp    rpcrt4.dll
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Rpc\ClientProtocols\ncacn_http    rpcrt4.dll
PX5: 18D1A0DF10E60431B3570659BBEA49003B970026
MD5: e11ad7a9e8320ad76954eab83356efbe
Determination: GOOD

C:\WINNT\system32\Secur32.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv50.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\system32\CTSvcCDA.EXE
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\regsvc.exe
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\stisvc.exe
    Loaded into: C:\WINNT\System32\WBEM\WinMgmt.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    Loaded into: C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    Loaded into: C:\WINNT\system32\RUNDLL32.EXE
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\QuickTime\qttask.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\WINNT\system32\ctfmon.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: c:\program files\panda software\panda antivirus 2007\WebProxy.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\psimreal.exe
    Loaded into: C:\Documents and Settings\HANS\Desktop\PREVXCSIFREE.EXE
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Rpc\SecurityService    secur32.dll
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Rpc\SecurityService    secur32.dll
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Rpc\SecurityService\10    secur32.dll
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Rpc\SecurityService\16    secur32.dll
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Rpc\SecurityService\18    secur32.dll
PX5: 962274C310C43BCFBFFC002373B32B001F6D4350
MD5: 0d6b5a519879138244ef3f8549c02432
Determination: GOOD

C:\WINNT\system32\NDdeApi.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
PX5: F244B53110EB073A3F52001FFF856100E40DC341
MD5: 3327e705cb22ef064ee3fe08beb7851d
Determination: GOOD

C:\WINNT\system32\PROFMAP.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
PX5: E05862481054498B75EB003E5EFCDA0061AC15C2
MD5: 6d252e14e13830706c8f1ad6d7ebc412
Determination: GOOD

C:\WINNT\system32\NETAPI32.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
PX5: EE4F56871057A0D3B9DF0464A1FCF500EB0CFA32
MD5: 38d8ed5a74a4d09cd440b651245edd6f
Determination: GOOD

C:\WINNT\system32\NTDSAPI.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
PX5: 9BDAE4CD10AD09A6E18D008B5D98BD00B32BEC21
MD5: 1a9f0053b554fd71730b21e23458bc53
Determination: GOOD

C:\WINNT\system32\DNSAPI.DLL
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
PX5: CC74657510A91ADC19A302331BB99600119F3B72
MD5: df8993aad9ef38d5e248d214fae321fc
Determination: GOOD

C:\WINNT\system32\WSOCK32.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: c:\program files\panda software\panda antivirus 2007\WebProxy.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
PX5: 46A68F0110C4FF335509000CF2395B00E7DD1160
MD5: 183d2d8e28a0393b4798addd46ad27b0
Determination: GOOD

C:\WINNT\system32\WS2_32.DLL
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\System32\WBEM\WinMgmt.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: c:\program files\panda software\panda antivirus 2007\WebProxy.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
PX5: A6241AF410373C05119A01F4E2940100E0A7B79B
MD5: 0190c62de42396d78db9be771cf2403e
Determination: GOOD

C:\WINNT\system32\WS2HELP.DLL
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\System32\WBEM\WinMgmt.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: c:\program files\panda software\panda antivirus 2007\WebProxy.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
PX5: C0FDB0D4104FA04547D800E35DDD6200F5B02BBF
MD5: 28336b1300ec048124197091354251b6
Determination: GOOD

C:\WINNT\system32\WLDAP32.DLL
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
PX5: 165DED76100F72103B2F025EE7E09B0030397DDB
MD5: 0da1335235dc386dab3c2329bcf2d4ee
Determination: GOOD

C:\WINNT\system32\NETRAP.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
PX5: 94EA276E107A2AE22D1000B960563D00A4D12764
MD5: 3de628eb3d632875b8a24bdc53e67277
Determination: GOOD

C:\WINNT\system32\SAMLIB.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
PX5: 40E7EAA710C39CA9CB8B00153C8E9E000820F134
MD5: abda35a92538d23407d3f394f5179002
Determination: GOOD

C:\WINNT\system32\sfc.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
PX5: EB9B6B243020774E7335017F3A441200A8E82B3C
MD5: 0e1f5e9b2d00611dc9fe59eef9487c76
Determination: GOOD

C:\WINNT\system32\USERENV.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\stisvc.exe
    Loaded into: C:\WINNT\System32\WBEM\WinMgmt.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
PX5: DFA1DCD4105FECE7175F06DE85D72D001CAD575D
MD5: 099cd26e9c34225002e4477c8ac8dcb0
Determination: GOOD

C:\WINNT\system32\msgina.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
PX5: 19D4EE7C10F19AEA2BD505B71C09BA003EF66A34
MD5: 1c142b2ebd4aacc7eca0c28f06843655
Determination: GOOD

C:\WINNT\system32\COMCTL32.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\stisvc.exe
    Loaded into: C:\WINNT\System32\WBEM\WinMgmt.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    Loaded into: C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    Loaded into: C:\WINNT\system32\RUNDLL32.EXE
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\QuickTime\qttask.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\WINNT\system32\ctfmon.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\Documents and Settings\HANS\Desktop\PREVXCSIFREE.EXE
PX5: E26E3B1010501EA717D308F0BBFAAA00992B9744
MD5: f4230caa2b9166e5114441f6b7b2dc3f
Determination: GOOD

C:\WINNT\system32\SHELL32.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    Loaded into: C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    Loaded into: C:\WINNT\system32\RUNDLL32.EXE
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\QuickTime\qttask.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\WINNT\system32\ctfmon.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\Documents and Settings\HANS\Desktop\PREVXCSIFREE.EXE
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\VmApplet    rundll32 shell32,Control_RunDLL "sysdm.cpl"
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{AEB6717E-7E19-11d0-97EE-00C04FD91972}
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}\StubPath    regsvr32.exe /s /n /i:U shell32.dll
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1A9BA3A0-143A-11CF-8350-444553540000}    Shell Favorite Folder
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{20D04FE0-3AEA-1069-A2D8-08002B30309D}    My Computer
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{86747AC0-42A0-1069-A2E6-08002B30309D}    Briefcase Folder
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0AFACED1-E828-11D1-9187-B532F1E9575D}    Folder Shortcut
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{12518493-00B2-11d2-9FA5-9E3420524153}    Mounted Volume
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{21B22460-3AEA-1069-A2DC-08002B30309D}    File Property Page Extension
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B091E540-83E3-11CF-A713-0020AFD79762}    File Types Page
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FBF23B41-E3F0-101B-8488-00AA003E56F8}    MIME File Types Hook
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C2FBB630-2971-11d1-A18C-00C04FD75D13}    Microsoft CopyTo Service
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C2FBB631-2971-11d1-A18C-00C04FD75D13}    Microsoft MoveTo Service
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{13709620-C279-11CE-A49E-444553540000}    Shell Automation Service
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{62112AA1-EBE4-11cf-A5FB-0020AFE7292D}    Shell Automation Folder View
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4622AD11-FF23-11d0-8D34-00A0C90F2719}    Start Menu
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7BA4C740-9E81-11CF-99D3-00AA004AE837}    Microsoft SendTo Service
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D969A300-E7FF-11d0-A93B-00A0C90F2719}    Microsoft New Object Service
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{09799AFB-AD67-11d1-ABCD-00C04FC30936}    Open With Context Menu Handler
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3FC0B520-68A9-11D0-8D77-00C04FD70822}    Display Control Panel HTML Extensions
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{75048700-EF1F-11D0-9888-006097DEACF9}    ActiveDesktop
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6D5313C0-8C62-11D1-B2CD-006097DF8C11}    Folder Options Property Page Extension
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{57651662-CE3E-11D0-8D77-00C04FC99D61}    CmdFileIcon
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4657278A-411B-11d2-839A-00C04FD918D0}    Shell Drag and Drop helper
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A470F8CF-A1E8-4f65-8335-227475AA5C46}    Add encryption item to context menus in explorer
    Loaded from: \REGISTRY\Machine\Software\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}\(default)
    Loaded from: \REGISTRY\Machine\Software\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}\(default)
    Loaded from: \REGISTRY\Machine\Software\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}\(default)
    Loaded from: \REGISTRY\Machine\Software\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}\(default)
    Loaded from: \REGISTRY\Machine\Software\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}\(default)
    Loaded from: \REGISTRY\Machine\Software\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}\(default)
    Loaded from: \REGISTRY\Machine\Software\Classes\*\shellex\ContextMenuHandlers\Open With\(default)    {09799AFB-AD67-11d1-ABCD-00C04FC30936}
    Loaded from: \REGISTRY\Machine\Software\Classes\*\shellex\ContextMenuHandlers\Open With\(default)    {09799AFB-AD67-11d1-ABCD-00C04FC30936}
    Loaded from: \REGISTRY\Machine\Software\Classes\*\shellex\ContextMenuHandlers\Open With EncryptionMenu\(default)    {A470F8CF-A1E8-4f65-8335-227475AA5C46}
    Loaded from: \REGISTRY\Machine\Software\Classes\*\shellex\ContextMenuHandlers\Open With EncryptionMenu\(default)    {A470F8CF-A1E8-4f65-8335-227475AA5C46}
    Loaded from: \REGISTRY\Machine\Software\Classes\Directory\shellex\ContextMenuHandlers\Open With EncryptionMenu\(default)    {A470F8CF-A1E8-4f65-8335-227475AA5C46}
    Loaded from: \REGISTRY\Machine\Software\Classes\Directory\shellex\ContextMenuHandlers\Open With EncryptionMenu\(default)    {A470F8CF-A1E8-4f65-8335-227475AA5C46}
    Loaded from: \REGISTRY\Machine\Software\Classes\Directory\shellex\CopyHookHandlers\FileSystem\(default)    {217FC9C0-3AEA-1069-A2DB-08002B30309D}
    Loaded from: \REGISTRY\Machine\Software\Classes\Directory\shellex\CopyHookHandlers\FileSystem\(default)    {217FC9C0-3AEA-1069-A2DB-08002B30309D}
    Loaded from: \REGISTRY\User\S-1-5-21-1606980848-73586283-725345543-1000\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU\000
    Loaded from: \REGISTRY\User\S-1-5-21-1606980848-73586283-725345543-1000\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\UseSearchOptions
PX5: 90C695CF1091C44B0DE9246012021A0008740F35
MD5: 961cfc812107bcbd77488224c48e1a58
Determination: GOOD

C:\WINNT\system32\SHLWAPI.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\cisvc.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    Loaded into: C:\WINNT\system32\nvsvc32.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\MsPMSPSv.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    Loaded into: C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    Loaded into: C:\WINNT\system32\RUNDLL32.EXE
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\QuickTime\qttask.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\WINNT\system32\ctfmon.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    Loaded into: C:\WINNT\system32\HPZipm12.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\System32\cidaemon.exe
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\Documents and Settings\HANS\Desktop\PREVXCSIFREE.EXE
PX5: 59DDD7D900FEE8B5263106145560BC0038AAA072
MD5: 6d5d14164cef511a056d3401aa36517e
Determination: GOOD

C:\WINNT\system32\WINSTA.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
PX5: C6902A491060888699F00033EE35E900D96EB134
MD5: 04ca4218d9d4a08e5159d4f7f49a1ddf
Determination: GOOD

C:\WINNT\system32\WINMM.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
PX5: B56CB76610E5BB38E39F02D22DF3AF0068855257
MD5: 89ae2927b977604d720b1680e208af47
Determination: GOOD

C:\WINNT\system32\setupapi.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\WINNT\system32\spoolsv.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\MSTask.exe
    Loaded into: C:\WINNT\system32\stisvc.exe
    Loaded into: C:\WINNT\System32\WBEM\WinMgmt.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Loaded into: C:\Program Files\VoipBusterMate\VoipBusterMate.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
PX5: A48B00FC102869BEB328084C4887A9004DAE6399
MD5: 9726125daa47dcbf34f53cef8c677b9c
Determination: GOOD

C:\WINNT\system32\avldr.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avldr\DllName    avldr.dll
    Loaded from: FILE
PX5: D18D9B49005EF726B05000BF81FD3F0060DEB1A3
MD5: 0635428dbe74ce5669371e0351727c97
Determination: GOOD

C:\WINNT\system32\cscdll.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded into: C:\WINNT\system32\NOTEPAD.EXE
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll\DLLName    cscdll.dll
PX5: 6CD61851103AF48D8B80019B4F30E0002137B779
MD5: 99b3f8bc2e6dd1eece66eb6ca5007729
Determination: GOOD

C:\WINNT\system32\WlNotify.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn\DLLName    WlNotify.dll
PX5: 2BA12D9A10AEBB2CDF4B003D1BF92400868260E6
MD5: 0ac7c01fae29d99696147295cbd0a0be
Determination: GOOD

C:\WINNT\system32\certcli.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
PX5: D6635D0C10A613AE11B9025C7C459600274521C2
MD5: 5505dc90fbac613be8a15dfdc3bde112
Determination: GOOD

C:\WINNT\system32\ATL.DLL
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
PX5: 841B948D3A9551FF241A01A583C9E30086A6CD77
MD5: 613baa8eff406d543746584f32ca0efe
Determination: GOOD

C:\WINNT\system32\CRYPT32.DLL
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    Loaded into: C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    Loaded into: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Loaded into: C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
    Loaded into: C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
    Loaded into: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    Loaded into: C:\Program Files\MSN Messenger\MsnMsgr.Exe
    Loaded into: C:\WINNT\g12071093.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    Loaded into: C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    Loaded into: C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    Loaded into: C:\Program Files\Mozilla Firefox\firefox.exe
    Loaded from: \REGISTRY\Machine\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain\DllName    crypt32.dll
PX5: DC2E0DD110A5AE809B5F08702DB3A20097AC93C4
MD5: 9726a08c3e529c5e6a48fff274a32932
Determination: GOOD

C:\WINNT\system32\MSASN1.dll
    Loaded into: C:\WINNT\system32\winlogon.exe
    Loaded into: C:\WINNT\system32\services.exe
    Loaded into: C:\WINNT\system32\lsass.exe
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    Loaded into: C:\WINNT\System32\svchost.exe
    Loaded into: C:\WINNT\Explorer.EXE
    Loaded into: C:\WINNT\system32\svchost.exe
    Loaded into: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    Loaded into: C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    Loaded into: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    Loaded into: C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
    Loaded into: C:\Program Files\Common Files\
13. december 2007 - 09:07 #14
... efterfølgende oprydning:

Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er disse, som skal fixes:

O2 - BHO: {a5aaea4c-7ee3-7c28-6594-5f77056a8ba7} - {7ab8a650-77f5-4956-82c7-3ee7c4aeaa5a} - C:\WINNT\system32\hwerbdoa.dll (file missing)

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [MSNAgent] C:\WINNT\g12071093.exe

O20 - Winlogon Notify: tatpzqce - tatpzqce.dll (file missing)
O20 - Winlogon Notify: winzzc32 - winzzc32.dll (file missing)

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

Genstart, kør en ny scanning med hijackthis, og kopier en frisk log herind til tjek.

------------------------------------------------------------------------

Jeg kan se at du - måske mere eller mindre mod din vilje - har installeret [Yahoo Toolbar] ?
Den er dog ikke 'farlig', men bare et irriterende program/toolbar som bare fylder op .
Hvis du vil slippe af med den kan du følge guiden herfra ->
http://support.microsoft.com/kb/303047
Avatar billede hans01 Nybegynder
13. december 2007 - 09:39 #15
Hej Larry

Jeg går straks igang med at rydde ud. mht yahoo så skal jeg åbne IE browseren og den vil jeg ikke aktivere før alt smuds er ude, det er den der har givet mig problemer ikke de andre browsere. Jeg sletter lige så snart jeg er klar..
Avatar billede hans01 Nybegynder
13. december 2007 - 09:53 #16
Så er der en frisk hjt:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:07:24, on 13-12-2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv50.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINNT\System32\cisvc.exe
C:\WINNT\system32\CTSvcCDA.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\system32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\inKline Global\PC Booster\pcbooster.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\panda software\panda antivirus 2007\WebProxy.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\VoipBusterMate\VoipBusterMate.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINNT\system32\HPZipm12.exe
C:\Documents and Settings\HANS\Desktop\HiJackThis(2).exe
C:\Program Files\Panda Software\Panda Antivirus 2007\avtask.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [PC Booster] C:\Program Files\inKline Global\PC Booster\pcbooster.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [VoipStunt] "C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe" -nosplash -minimized
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\.DEFAULT\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: VoipBusterMate.lnk = VoipBusterMate\VoipBusterMate.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1192814038750
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTSvcCDA.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv50.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

--
End of file - 7655 bytes
13. december 2007 - 18:05 #17
Giver denne  [PC Booster]  noget som helst af betydning ?
13. december 2007 - 18:06 #18
... eller ser det pænt ud nu ...

Hvordan kører putteren så nu ?
Avatar billede hans01 Nybegynder
13. december 2007 - 18:15 #19
Hej larry

PC booster giver meget begrænset udbytte, iøvrigt spiller alt som det skal, et stk glad mand i min ende. smid lige et velfortjent svar.
13. december 2007 - 22:45 #20
Du er velkommen en anden gang...

Du bør rense temp med denne fil, det tager kun få sek.
http://www.spywareinfo.dk/download/cleantempxp2k.bat

Et par artikler om sikker surfing finder du her:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414

Safe Surfing...
Avatar billede hans01 Nybegynder
14. december 2007 - 07:55 #21
Tusind tak for hjælpen, jeg ønsker dig også en god ju, vi nærmer os jo.

Og tak for links, cleantemp, kunnne jeg nu ikke få til at køre, ellers så kørte den automatisk.

Filen/side ser sådan ud.
RD /s /q "%temp%"
MD "%temp%"
RD /s /q "%tmp%"
MD "%tmp%"
RD /s /q "%windir%\Temp"
MD "%windir%\Temp"
RD /s /q "%userprofile%\Local Settings\Temp"
MD "%userprofile%\Local Settings\Temp"
RD /s /q "%userprofile%\Lokale indstillinger\Temp"
MD "%userprofile%\Lokale indstillinger\Temp"
del %windir%\prefetch\*.* /f /q
del c:\*.tmp /f /q
14. december 2007 - 11:10 #22
Hmmm...
Ved kørsel er det 'overstået' på få sekunder!
Avatar billede hans01 Nybegynder
14. december 2007 - 11:17 #23
jamen så er det vel iorden, har samtidigt loaded fasterfox. Lige et tillægs sp. jeg har jo installeret PCbooster og efter alt det her viser den avail mem på kun 19 mb HVAD ER NU DET FOR NOGET?

jeg har totalt 1023 mb
Avatar billede hans01 Nybegynder
14. december 2007 - 11:28 #24
Jeg var lidt hurtig, rebootede så fnadt den de manglende ram
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester