• 0

Heeeelp! I got a trojan:Win32/Conhook.i


Question

Hello,

Well, I don't really know its source, but I know that a conhook.i hit my computer, I did a scan with kaspersky but no result, I did another scan with malwarebytes' anti malware, but the same thing, it detected nothing, the only thing that detected it is windows defender but when I try to neutralize it, it shows an error: 0x80501001!! I think that there is a process running so it cannot be deleted, I tried different methods for removal but none of them worked!! As side effects of this damned trojan, my pc is sooooo slow and I get "not responding" messages all the time from any program, thus the pc is unusable!!! Please help because I have a job to do for monday

Here is a highjackthis report:

Logfile of HijackThis v1.99.1
Scan saved at 14:33:59, on 26/07/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter3.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91AgentS1.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Windows\AStiDog1210.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search.orbitdownloader.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O1 - Hosts: ::1 localhost
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [Waiting1210] C:\Windows\AStiDog1210.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ScanSoft OmniPage 16-reminder] "C:\Program Files\ScanSoft\OmniPage16\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\OmniPage 16\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\opnlMDWQ.dll,#1
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [OpAgent] "OpAgent.exe" /agent
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la s?lection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la s?lection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens s?lectionn?s en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens s?lectionn?s en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - (no file)
O9 - Extra button: (no name) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: (no name) - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (no file)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix: 
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll,
O23 - Service: Adobe Version Cue CS3 {fr_FR}  (Adobe Version Cue CS3) - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing)
O23 - Service: Kaspersky Internet Security (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

Thanks in advance!!

Link to comment
Share on other sites

Recommended Posts

  • 0

Did you try scanning in safe mode? That way the process may not be initialized at startup, making it easier to delete.

Link to comment
Share on other sites

  • 0

Yep I tried scanning in safe mode!! But it didn't work

Link to comment
Share on other sites

  • 0

O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\opnlMDWQ.dll,#1

O4 - HKLM\..\Run: [Waiting1210] C:\Windows\AStiDog1210.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search.orbitdownloader.com

These look dodgy.

Link to comment
Share on other sites

  • 0

It looks like you have tons and tons of crap starting up automatically with your computer. Please go through msconfig and wipe out everything that you don't absolutely need to autolaunch. Then scan and post another log for us to look through, it will be neater and easier to go through.

Also, do you download torrents and pirate software? If so, that is a likely route of infection. That said, you'll probably have to use something like an Ubuntu Live CD to mount the NTFS volume and nuke the spyware files. Otherwise, get avenger (http://swandog46.geekstogo.com/avenger.exe) and tell it to remove the file on boot.

Link to comment
Share on other sites

  • 0
Hello,

Well, I don't really know its source, but I know that a conhook.i hit my computer, I did a scan with kaspersky but no result, I did another scan with malwarebytes' anti malware, but the same thing, it detected nothing, the only thing that detected it is windows defender but when I try to neutralize it, it shows an error: 0x80501001!!

..............................................

So many processes and services , Pls post a SREng log , maybe I can help you.

run SREngLdr.EXE file , select 'Smart Scan' and then scan ur PC.

Could u tell me which file KIS alarm as 'Win32/Conhook.i' ?

Link to comment
Share on other sites

  • 0
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\opnlMDWQ.dll,#1

O4 - HKLM\..\Run: [Waiting1210] C:\Windows\AStiDog1210.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search.orbitdownloader.com

These look dodgy.

Yes indeed they look suspicious except for the last one, it is a download manager!! I don't know but I think it can't harm the pc!!

Well I went into C:\Windows\system32\, but did not find opnlMDWQ.dll !!

for the other one I found it but I cannot delete it!! It says I need an authorization in order to delete it!!

@Relativity_17: it is a new pc, and I didn't install much things on it, could specify what is crap to you??

@thealexweb: I don't think that this will solve my problem, besides I have newly installed games and I don't want to install them again because installing them was really painful and long ( Devil May Cry 4 and Assasin's Creed)

Any ideas? Isn't there a specific remval tool, like vundo remover and Combofix??

Link to comment
Share on other sites

  • 0
So many processes and services , Pls post a SREng log , maybe I can help you.

run SREngLdr.EXE file , select 'Smart Scan' and then scan ur PC.

Could u tell me which file KIS alarm as 'Win32/Conhook.i' ?

KIS doesn't alarm anything, it's windows defender that detected it and it doesn't show which file is it!!

And here is the report done with the program you provided!! it's quite long!! (i'll have to double post)

2008-07-26,16:00:02

System Repair Engineer 2.6.12.1018
Smallfrogs (http://www.KZTechs.com)

Windows Vista Ultimate Edition Service Pack 1 (Build 6001) - Administrative User - Completed Functions Allowed

Follow item(s) have been selected:
    All Boot Items (Including Registry, Startup Folders, Services and so on)
    Browser Add-ons
    Running Processes (Including process model information)
    File Associations
    Winsock Provider
    Autorun.Inf
    HOSTS File
    Process Privileges Scan


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <Sidebar><C:\Program Files\Windows Sidebar\sidebar.exe /autoRun>  [(Verified)Microsoft Windows]
    <MsnMsgr><"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background>  [(Verified)Microsoft Corporation]
    <DAEMON Tools Lite><"C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun>  [(Verified)DAEMON Tools Code Signing Services]
    <ehTray.exe><C:\Windows\ehome\ehTray.exe>  [(Verified)Microsoft Windows]
    <AdobeUpdater><C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe>  [(Verified)Adobe Systems Incorporated]
    <Skype><"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized>  [(Verified)Skype Technologies SA]
    <OpAgent><"OpAgent.exe" /agent>  [N/A]
    <ISUSPM Startup><C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup>  [InstallShield Software Corporation]
    <WMPNSCFG><C:\Program Files\Windows Media Player\WMPNSCFG.exe>  [(Verified)Microsoft Windows]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Windows Defender><%ProgramFiles%\Windows Defender\MSASCui.exe -hide>  [(Verified)Microsoft Windows]
    <RtHDVCpl><RtHDVCpl.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <SunJavaUpdateSched><"C:\Program Files\Java\jre6\bin\jusched.exe">  [(Verified)"Sun Microsystems, Inc."]
    <QuickTime Task><"C:\Program Files\QuickTime\QTTask.exe" -atboottime>  [Apple Inc.]
    <AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe">  [(Verified)Kaspersky Lab]
    <Waiting1210><C:\Windows\AStiDog1210.exe>  []
    <GrooveMonitor><"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe">  [(Verified)Microsoft Corporation]
    <Acrobat Assistant 8.0><"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe">  [(Verified)"Adobe Systems, Incorporated"]
    <Adobe_ID0EYTHM><C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE>  [Adobe Systems Incorporated]
    <CanonSolutionMenu><C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon>  [(Verified)Canon Inc.]
    <CanonMyPrinter><C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon>  [(Verified)Canon Inc.]
    <NvCplDaemon><RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <NvMediaCenter><RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <Adobe Reader Speed Launcher><"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe">  [(Verified)"Adobe Systems, Incorporated"]
    <ISUSScheduler><"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start>  [InstallShield Software Corporation]
    <ScanSoft OmniPage 16-reminder><"C:\Program Files\ScanSoft\OmniPage16\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\OmniPage 16\Ereg\Ereg.ini">  [File is missing]
    <SSBkgdUpdate><"C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot>  [(Verified)"Nuance Communications, Inc."]
    <ISTray><"C:\Program Files\Spyware Doctor\pctsTray.exe">  [(Verified)PC Tools]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><explorer.exe>  [(Verified)Microsoft Windows]
    <Userinit><C:\Windows\system32\userinit.exe,>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll,>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{F6725EDC-93FF-479B-A98B-C5B9E3C44864}><C:\Windows\system32\rqRHaYop.dll>  [File is missing]
    <{B5A7F190-DDA6-4420-B3BA-52453494E6CD}><C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll>  [(Verified)Microsoft Corporation]
    <{E5646F36-145E-4F1D-B6D1-87C5EFC5BA1C}><C:\Windows\system32\opnlMDWQ.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    <WinlogonNotify: klogon><C:\Windows\system32\klogon.dll>  [(Verified)Kaspersky Lab]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Windows Mail 7><"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
    <Windows Ultimate Extras><%SystemRoot%\system32\soundschemes.exe /AddRegistration>  [Microsoft Corporation]

==================================
Startup Folders
[Adobe Reader Synchronizer]
  <C:\ProgramData\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk --> C:\PROGRA~1\Adobe\ACROBA~1.0\Acrobat\ADOBEC~1.EXE []><N>
[Lancement rapide d'Adobe Acrobat]
  <C:\ProgramData\Start Menu\Programs\Startup\Lancement rapide d'Adobe Acrobat.lnk --> C:\Windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [N/A]><N>
[Orbit]
  <C:\ProgramData\Start Menu\Programs\Startup\Orbit.lnk --> C:\PROGRA~1\ORBITD~1\orbitdm.exe [Orbitdownloader.com]><N>
[Adobe Reader Synchronizer]
  <C:\ProgramData\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk --> C:\PROGRA~1\Adobe\ACROBA~1.0\Acrobat\ADOBEC~1.EXE []><N>
[Lancement rapide d'Adobe Acrobat]
  <C:\ProgramData\Start Menu\Programs\Startup\Lancement rapide d'Adobe Acrobat.lnk --> C:\Windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [N/A]><N>
[Orbit]
  <C:\ProgramData\Start Menu\Programs\Startup\Orbit.lnk --> C:\PROGRA~1\ORBITD~1\orbitdm.exe [Orbitdownloader.com]><N>

==================================
Services
[Adobe Version Cue CS3 {fr_FR}  / Adobe Version Cue CS3][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service><Adobe Systems Incorporated>
[Kaspersky Internet Security / AVP][Running/Auto Start]
  <"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" -r><Kaspersky Lab>
[##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## / Bonjour Service][Running/Auto Start]
  <"C:\Program Files\Bonjour\mDNSResponder.exe"><Apple Computer, Inc.>
[FLEXnet Licensing Service / FLEXnet Licensing Service][Running/Manual Start]
  <"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"><Macrovision Europe Ltd.>
[PIXMA Extended Survey Program / IJPLMSVC][Running/Auto Start]
  <C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE><>
[Java Quick Starter / JavaQuickStarterService][Running/Auto Start]
  <"C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"><Sun Microsystems, Inc.>
[NVIDIA Display Driver Service / nvsvc][Running/Auto Start]
  <C:\Windows\system32\nvvsvc.exe><NVIDIA Corporation>
[PD91Agent / PD91Agent][Running/Auto Start]
  <"C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe"><Raxco Software, Inc.>
[PD91Engine / PD91Engine][Stopped/Manual Start]
  <"C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe"><Raxco Software, Inc.>
[PC Tools Auxiliary Service / sdAuxService][Running/Auto Start]
  <C:\Program Files\Spyware Doctor\pctsAuxs.exe><PC Tools>
[PC Tools Security Service / sdCoreService][Running/Auto Start]
  <C:\Program Files\Spyware Doctor\pctsSvc.exe><PC Tools>
[Windows Live Setup Service / WLSetupSvc][Stopped/Manual Start]
  <"C:\Program Files\Windows Live\installer\WLSetupSvc.exe"><Microsoft Corporation>

==================================
Drivers
[adp94xx / adp94xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adp94xx.sys><Adaptec, Inc.>
[adpahci / adpahci][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adpahci.sys><Adaptec, Inc.>
[adpu160m / adpu160m][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adpu160m.sys><Adaptec, Inc.>
[adpu320 / adpu320][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adpu320.sys><Adaptec, Inc.>
[aic78xx / aic78xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\djsvs.sys><Adaptec, Inc.>
[aliide / aliide][Stopped/Disabled]
  <\SystemRoot\system32\drivers\aliide.sys><Acer Laboratories Inc.>
[arc / arc][Stopped/Disabled]
  <\SystemRoot\system32\drivers\arc.sys><Adaptec, Inc.>
[arcsas / arcsas][Stopped/Disabled]
  <\SystemRoot\system32\drivers\arcsas.sys><Adaptec, Inc.>
[atksgt / atksgt][Running/Auto Start]
  <system32\DRIVERS\atksgt.sys><N/A>
[blbdrive / blbdrive][Stopped/Disabled]
  <\SystemRoot\system32\drivers\blbdrive.sys><N/A>
[Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\brfiltlo.sys><Brother Industries, Ltd.>
[Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\brfiltup.sys><Brother Industries, Ltd.>
[Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\brserid.sys><Brother Industries Ltd.>
[Brother WDM Serial driver / BrSerWdm][Stopped/Disabled]
  <\SystemRoot\system32\drivers\brserwdm.sys><Brother Industries Ltd.>
[Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Disabled]
  <\SystemRoot\system32\drivers\brusbmdm.sys><Brother Industries Ltd.>
[Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\brusbser.sys><Brother Industries Ltd.>
[USB video camera / CAM1210][Running/Manual Start]
  <System32\Drivers\cam1210.sys><USB video camera>
[cmdide / cmdide][Stopped/Disabled]
  <\SystemRoot\system32\drivers\cmdide.sys><CMD Technology, Inc.>
[Intel(R) PRO/1000 NDIS 6 Adapter Driver / E1G60][Stopped/Manual Start]
  <system32\DRIVERS\E1G60I32.sys><Intel Corporation>
[elxstor / elxstor][Stopped/Disabled]
  <\SystemRoot\system32\drivers\elxstor.sys><Emulex>
[GMSIPCI / GMSIPCI][Stopped/Manual Start]
  <\??\E:\INSTALL\GMSIPCI.SYS><N/A>
[HpCISSs / HpCISSs][Stopped/Disabled]
  <\SystemRoot\system32\drivers\hpcisss.sys><Hewlett-Packard Company>
[Intel RAID Controller Vista / iaStorV][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iastorv.sys><Intel Corporation>
[iirsp / iirsp][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iirsp.sys><Intel Corp./ICP vortex GmbH>
[File Security Driver / IKFileSec][Running/Boot Start]
  <\SystemRoot\system32\drivers\ikfilesec.sys><PCTools Research Pty Ltd.>
[System Filter Driver / IKSysFlt][Running/System Start]
  <system32\drivers\iksysflt.sys><PCTools Research Pty Ltd.>
[System Security Driver / IKSysSec][Running/System Start]
  <system32\drivers\iksyssec.sys><PCTools Research Pty Ltd.>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
  <system32\drivers\RTKVHDA.sys><Realtek Semiconductor Corp.>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
  <system32\DRIVERS\ipinip.sys><N/A>
[ITEATAPI_Service_Install / iteatapi][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iteatapi.sys><Integrated Technology Express, Inc.>
[ITERAID_Service_Install / iteraid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iteraid.sys><Integrated Technology Express, Inc.>
[kl1 / kl1][Running/System Start]
  <system32\DRIVERS\kl1.sys><Kaspersky Lab>
[Kaspersky Lab Boot Guard Driver / klbg][Running/Boot Start]
  <\SystemRoot\system32\drivers\klbg.sys><Kaspersky Lab>
[Kaspersky Lab KLFltDev / KLFLTDEV][Running/Manual Start]
  <system32\DRIVERS\klfltdev.sys><Kaspersky Lab>
[Kaspersky Lab Driver / KLIF][Running/System Start]
  <system32\DRIVERS\klif.sys><Kaspersky Lab>
[Kaspersky Anti-Virus NDIS 6 Filter / KLIM6][Running/System Start]
  <system32\DRIVERS\klim6.sys><Kaspersky Lab>
[lirsgt / lirsgt][Running/Auto Start]
  <system32\DRIVERS\lirsgt.sys><N/A>
[LSI_FC / LSI_FC][Stopped/Disabled]
  <\SystemRoot\system32\drivers\lsi_fc.sys><LSI Logic>
[LSI_SAS / LSI_SAS][Stopped/Disabled]
  <\SystemRoot\system32\drivers\lsi_sas.sys><LSI Logic>
[LSI_SCSI / LSI_SCSI][Stopped/Disabled]
  <\SystemRoot\system32\drivers\lsi_scsi.sys><LSI Logic>
[megasas / megasas][Stopped/Disabled]
  <\SystemRoot\system32\drivers\megasas.sys><LSI Logic Corporation>
[Mraid35x / Mraid35x][Stopped/Disabled]
  <\SystemRoot\system32\drivers\mraid35x.sys><LSI Logic Corporation>
[nfrd960 / nfrd960][Stopped/Disabled]
  <\SystemRoot\system32\drivers\nfrd960.sys><IBM Corporation>
[NTACCESS / NTACCESS][Stopped/Manual Start]
  <\??\E:\NTACCESS.sys><N/A>
[N-trig HID Tablet Driver / ntrigdigi][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ntrigdigi.sys><N-trig Innovative Technologies>
[nvlddmkm / nvlddmkm][Running/Manual Start]
  <system32\DRIVERS\nvlddmkm.sys><NVIDIA Corporation>
[nvraid / nvraid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\nvraid.sys><NVIDIA Corporation>
[nvstor / nvstor][Stopped/Disabled]
  <\SystemRoot\system32\drivers\nvstor.sys><NVIDIA Corporation>
[IPX Traffic Filter Driver / NwlnkFlt][Stopped/Manual Start]
  <system32\DRIVERS\nwlnkflt.sys><N/A>
[IPX Traffic Forwarder Driver / NwlnkFwd][Stopped/Manual Start]
  <system32\DRIVERS\nwlnkfwd.sys><N/A>
[Royalty OEM Bios Extension / OemBiosDevice][Stopped/Boot Start]
  <\SystemRoot\System32\drivers\royal.sys><PARADOX>
[QLogic Fibre Channel Miniport Driver / ql2300][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ql2300.sys><QLogic Corporation>
[QLogic iSCSI Miniport Driver / ql40xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ql40xx.sys><QLogic Corporation>
[Pilote Realtek 8169 NT / RTL8169][Running/Manual Start]
  <system32\DRIVERS\Rtlh86.sys><Realtek Corporation>
[Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter / RTL8187][Stopped/Manual Start]
  <system32\DRIVERS\RTL8187.sys><Realtek Semiconductor Corporation>
[SetupNTGLM7X / SetupNTGLM7X][Stopped/Manual Start]
  <\??\E:\NTGLM7X.sys><N/A>
[SiSRaid2 / SiSRaid2][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sisraid2.sys><Silicon Integrated Systems Corp.>
[SiSRaid4 / SiSRaid4][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sisraid4.sys><Silicon Integrated Systems>
[sptd / sptd][Running/Boot Start]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[Symc8xx / Symc8xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\symc8xx.sys><LSI Logic>
[Sym_hi / Sym_hi][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sym_hi.sys><LSI Logic>
[Sym_u3 / Sym_u3][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sym_u3.sys><LSI Logic>
[uliahci / uliahci][Stopped/Disabled]
  <\SystemRoot\system32\drivers\uliahci.sys><ULi Electronics Inc.>
[UlSata / UlSata][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ulsata.sys><Promise Technology, Inc.>
[ulsata2 / ulsata2][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ulsata2.sys><Promise Technology, Inc.>
[viaide / viaide][Stopped/Disabled]
  <\SystemRoot\system32\drivers\viaide.sys><VIA Technologies, Inc.>
[vsmraid / vsmraid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\vsmraid.sys><VIA Technologies Inc.,Ltd>

==================================
Browser Add-ons
[Octh Class]
  {000123B4-9B42-4900-B3F7-F4B073EFC214} <C:\Program Files\Orbitdownloader\orbitcth.dll, Orbitdownloader.com>
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, (Signed) Adobe Systems Incorporated>
[ContributeBHO Class]
  {074C1DC5-9320-4A9A-947D-C042949C6216} <C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll, Adobe Systems Incorporated.>
[BitComet Helper]
  {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll, (Signed) BitComet>
[IEVkbdBHO Class]
  {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} <C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll, (Signed) Kaspersky Lab>
[Groove GFS Browser Helper]
  {72853161-30C5-4D22-B7F9-0BBC1D38A37E} <C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll, (Signed) Microsoft Corporation>
[Java(tm) Plug-In SSV Helper]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre6\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[]
  {7E853D72-626A-48EC-A868-BA8D5E23E045} <, >
[Windows Live Sign-in Helper]
  {9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, (Signed) Microsoft Corporation>
[]
  {9658B22E-6095-443E-8F51-D4BC266DA23C} <C:\Windows\system32\ddCSLDuV.dll, N/A>
[Adobe PDF Conversion Toolbar Helper]
  {AE7CD045-E861-484f-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll, (Signed) Adobe Systems Incorporated>
[Java(tm) Plug-In 2 SSV Helper]
  {DBC80044-A445-435b-BC74-9C25C1C588A9} <C:\Program Files\Java\jre6\bin\jp2ssv.dll, Sun Microsystems, Inc.>
[JQSIEStartDetectorImpl Class]
  {E7E6F031-17CE-4C07-BC86-EABFE594F69C} <C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll, Sun Microsystems, Inc.>
[BitComet]
  {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} <, >
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll, (Signed) Adobe Systems Incorporated>
[Contribute Toolbar]
  {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} <C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll, Adobe Systems Incorporated.>
[Grab Pro]
  {C55BBCD6-41AD-48AD-9953-3609C48EACC7} <C:\Program Files\Orbitdownloader\GrabPro.dll, >
[Office Genuine Advantage Validation Tool]
  {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} <C:\Windows\system32\OGACheckControl.dll, >
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700} <C:\Windows\system32\LegitCheckControl.DLL, (Signed) Microsoft Corporation>
[Java Plug-in 1.6.0_10]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre6\bin\jp2iexp.dll, >
[Java Plug-in 1.6.0_10]
  {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} <C:\Program Files\Java\jre6\bin\jp2iexp.dll, >
[Java Plug-in 1.6.0_10]
  {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre6\bin\npjpi160_10.dll, (Signed) Sun Microsystems, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash9f.ocx, (Signed) Adobe Systems, Inc.>
[Octh Class]
  {000123B4-9B42-4900-B3F7-F4B073EFC214} <C:\Program Files\Orbitdownloader\orbitcth.dll, Orbitdownloader.com>
[Office Genuine Advantage Validation Tool]
  {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} <C:\Windows\system32\OGACheckControl.dll, >
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, (Signed) Adobe Systems Incorporated>
[ContributeBHO Class]
  {074C1DC5-9320-4A9A-947D-C042949C6216} <C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll, Adobe Systems Incorporated.>
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700} <C:\Windows\system32\LegitCheckControl.DLL, (Signed) Microsoft Corporation>
[XML DOM Document]
  {2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[BitComet Helper]
  {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll, (Signed) BitComet>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll, (Signed) Adobe Systems Incorporated>
[Contribute Toolbar]
  {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} <C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll, Adobe Systems Incorporated.>
[IEVkbdBHO Class]
  {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} <C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll, (Signed) Kaspersky Lab>
[InstallShield Update Service Agent]
  {5B7524C8-2446-40E9-9474-94A779DBA224} <C:\Windows\Downloaded Program Files\isusweb.dll, InstallShield Software Corporation>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[Groove GFS Browser Helper]
  {72853161-30C5-4D22-B7F9-0BBC1D38A37E} <C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll, (Signed) Microsoft Corporation>
[Java(tm) Plug-In SSV Helper]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre6\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[]
  {7E853D72-626A-48EC-A868-BA8D5E23E045} <, >
[Windows Live Sign-in Helper]
  {9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, (Signed) Microsoft Corporation>
[]
  {9658B22E-6095-443E-8F51-D4BC266DA23C} <C:\Windows\system32\ddCSLDuV.dll, N/A>
[Adobe PDF Conversion Toolbar Helper]
  {AE7CD045-E861-484F-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll, (Signed) Adobe Systems Incorporated>
[Grab Pro]
  {C55BBCD6-41AD-48AD-9953-3609C48EACC7} <C:\Program Files\Orbitdownloader\GrabPro.dll, >
[]
  {D18A0B52-D63C-4ED0-AFC6-C1E3DC1AF43A} <, >
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash9f.ocx, (Signed) Adobe Systems, Inc.>
[Java(tm) Plug-In 2 SSV Helper]
  {DBC80044-A445-435B-BC74-9C25C1C588A9} <C:\Program Files\Java\jre6\bin\jp2ssv.dll, Sun Microsystems, Inc.>
[AgControl Class]
  {DFEAF541-F3E1-4C24-ACAC-99C30715084A} <c:\Program Files\Microsoft Silverlight\npctrl.1.0.30401.0.dll, (Signed)  Microsoft Corporation>
[JQSIEStartDetectorImpl Class]
  {E7E6F031-17CE-4C07-BC86-EABFE594F69C} <C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll, Sun Microsystems, Inc.>
[XML HTTP Request]
  {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[]
  {EEA05BDF-8A83-4B30-866D-D0BE8FBBEBB5} <, >
[XML HTTP]
  {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[&D&ownload &with BitComet]
  <res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm, N/A>
[&D&ownload all video with BitComet]
  <res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm, N/A>
[&D&ownload all with BitComet]
  <res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm, N/A>
[&Download by Orbit]
  <res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201, N/A>
[&Grab video by Orbit]
  <res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204, N/A>
[Add to Banner Ad Blocker]
  <C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm, N/A>
[Ajouter au fichier PDF existant]
  <res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[Convertir en Adobe PDF]
  <res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[Convertir la cible du lien en Adobe PDF]
  <res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[Convertir la cible du lien en un fichier PDF existant]
  <res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[Convertir la s?lection en Adobe PDF]
  <res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[Convertir la s?lection en un fichier PDF existant]
  <res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[Convertir les liens s?lectionn?s en fichier Adobe PDF]
  <res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html, N/A>
[Convertir les liens s?lectionn?s en un fichier PDF existant]
  <res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html, N/A>
[Do&wnload selected by Orbit]
  <res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203, N/A>
[Down&load all by Orbit]
  <res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202, N/A>
[E&xport to Microsoft Excel]
  <res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000, N/A>

==================================
Running Processes
[PID: 516 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 600 / SYSTEM][C:\Windows\system32\csrss.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 644 / SYSTEM][C:\Windows\system32\wininit.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 652 / SYSTEM][C:\Windows\system32\csrss.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 688 / SYSTEM][C:\Windows\system32\services.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 700 / SYSTEM][C:\Windows\system32\lsass.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 712 / SYSTEM][C:\Windows\system32\lsm.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 864 / SYSTEM][C:\Windows\system32\winlogon.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 888 / SYSTEM][C:\Windows\system32\svchost.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 936 / SYSTEM][C:\Windows\system32\nvvsvc.exe]  [NVIDIA Corporation, 7.15.11.7519]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 964 / SERVICE R?SEAU][C:\Windows\system32\svchost.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 1032 / SYSTEM][C:\Windows\System32\svchost.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1239B21A-F2E4-4676-8C27-B67778BACAAD}\mpengine.dll]  [Microsoft Corporation, 1.1.3704.0]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 1096 / SERVICE LOCAL][C:\Windows\System32\svchost.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Windows\system32\RtkAPO.dll]  [Realtek Semiconductor Corp., 11.0.6000.38 built by: WinDDK]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 1128 / SYSTEM][C:\Windows\System32\svchost.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll]  [Microsoft Corporation, 5.2.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 1152 / SYSTEM][C:\Windows\system32\svchost.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 1280 / SYSTEM][C:\Windows\system32\svchost.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 1328 / SERVICE R?SEAU][C:\Windows\system32\SLsvc.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 1416 / SERVICE LOCAL][C:\Windows\system32\svchost.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
[PID: 1520 / SYSTEM][C:\Windows\system32\rundll32.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Windows\system32\NVSVC.DLL]  [NVIDIA Corporation, 7.15.11.7519]
    [C:\Windows\system32\nvapi.dll]  [NVIDIA Corporation, 7.15.11.7519]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 1816 / SYSTEM][C:\Windows\System32\spoolsv.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\System32\AdobePDF.dll]  [Adobe Systems Incorporated., 8.0.0.00]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdistRes.FRA]  [, ]
    [C:\Windows\System32\CNMLM93.DLL]  [CANON INC., 2.10.2.40]
    [C:\Windows\System32\msonpmon.dll]  [Microsoft Corporation, 12.3.4518.1014]
    [C:\Windows\system32\spool\PRTPROCS\W32X86\CNMPD93.DLL]  [CANON INC., 2.10.2.40]
    [C:\Windows\system32\spool\PRTPROCS\W32X86\msonpppr.dll]  [Microsoft Corporation, 12.3.4518.1014]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 1848 / SERVICE LOCAL][C:\Windows\system32\svchost.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 336 / SYSTEM][C:\Program Files\Bonjour\mDNSResponder.exe]  [Apple Computer, Inc., 1,0,3,1]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 528 / SERVICE R?SEAU][C:\Windows\system32\svchost.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
[PID: 544 / SYSTEM][C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE]  [, 1.2.0.101]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 568 / SYSTEM][C:\Program Files\Java\jre6\bin\jqs.exe]  [Sun Microsystems, Inc., 6.0.100.23]
    [C:\Program Files\Java\jre6\bin\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 1568 / SYSTEM][C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe]  [Raxco Software, Inc., 9, 0, 0, 52]
    [C:\Program Files\Raxco\PerfectDisk2008\PDDb.dll]  [Raxco Software, Inc., 9, 0, 0, 52]
    [C:\Program Files\Raxco\PerfectDisk2008\sqlite3.dll]  [Raxco Software, Inc., 9, 0, 0, 52]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Raxco\PerfectDisk2008\PD91EnginePS.dll]  [Raxco Software, Inc., 9, 0, 0, 52]
[PID: 836 / SERVICE R?SEAU][C:\Windows\system32\svchost.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 2108 / SYSTEM][C:\Program Files\Spyware Doctor\pctsAuxs.exe]  [PC Tools, 6, 0, 0, 2]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\PCTWSC.dll]  [PC Tools, 2, 0, 1, 2]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 2148 / SYSTEM][C:\Program Files\Spyware Doctor\pctsSvc.exe]  [PC Tools, 6.0.0.10]
    [C:\Program Files\Spyware Doctor\rtl100.bpl]  [CodeGear, 11.0.2902.10471]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\vcl100.bpl]  [CodeGear, 11.0.2902.10471]
    [C:\Program Files\Spyware Doctor\SysAccess.dll]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\ikdll.dll]  [PCTools Research Pty Ltd., 5.0.2.1040 built by: WinDDK]
    [C:\Program Files\Spyware Doctor\CommOM.dll]  [PC Tools, 6.0.0.3]
    [C:\Program Files\Spyware Doctor\CommLib.dll]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\commhlpr.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\RegHelper.dll]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\inethlpr.dll]  [PC Tools, 6.0.0.2]
    [C:\Program Files\Spyware Doctor\filehlpr.dll]  [PC Tools, 6.0.0.2]
    [C:\Program Files\Spyware Doctor\sdcore.dll]  [PC Tools, 6.0.0.2]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]

[C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\FileStorage.sdp]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\Settings.sdp]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\IDBLib.sdp]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\SDInfo.sdp]  [PC Tools, 6.0.0.3]
    [C:\Program Files\Spyware Doctor\SDExtra.sdp]  [PC Tools, 6.0.0.5]
    [C:\Program Files\Spyware Doctor\Immunizer.sdp]  [PC Tools, 6.0.0.2]
    [C:\Program Files\Spyware Doctor\Localizer.sdp]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\NfyMan.sdp]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\quarantine.sdp]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\BH.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\RebootManager.sdp]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\scaneng.sdp]  [PC Tools, 6.0.0.2]
    [C:\Program Files\Spyware Doctor\stasks.sdp]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\SystemMonitor.sdp]  [PC Tools, 6.0.0.5]
    [C:\Program Files\Spyware Doctor\whitelist.sdp]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\sdwvhlp.dll]  [PC Tools, 1, 0, 0, 2]
    [C:\Program Files\Spyware Doctor\plugins\Browsers.SDP]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\plugins\cookie.sdp]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\plugins\grAV.sdp]  [PC Tools, 6.0.0.4]
    [C:\Program Files\Spyware Doctor\plugins\grfiles.SDP]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\plugins\grImmunizer.SDP]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\plugins\grregistry.SDP]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\PCToolsComponents.bpl]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\SH.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\plugins\KLGuard.SDP]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\plugins\Network.SDP]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\plugins\Process.SDP]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\plugins\ScriptEngine.SDP]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\plugins\SDNET.SDP]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\plugins\StartUp.SDP]  [PC Tools, 6.0.0.2]
    [C:\Program Files\Spyware Doctor\avengine\SDAVgate.dll]  [PC Tools Research, 1, 0, 11, 0]
    [C:\Program Files\Spyware Doctor\avengine\PCTAVEng.dll]  [PC Tools Research Pty Ltd, 4.4.5]
    [C:\Program Files\Spyware Doctor\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 2384 / Mohamed][C:\Windows\system32\Dwm.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 7.15.11.7519]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 2420 / Mohamed][C:\Windows\system32\taskeng.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 2444 / Mohamed][C:\Windows\Explorer.EXE]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll]  [Microsoft Corporation, 5.2.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\PROGRA~1\WI4EB4~1\wmpband.dll]  [Microsoft Corporation, 11.0.6000.6324 (vista_rtm.061101-2205)]
    [C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Microsoft Office\Office12\GrooveMisc.dll]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\FileZilla FTP Client\fzshellext.dll]  [, 3, 0, 11, 1]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 8.0.0.2006102200]
    [C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlResource.dll]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll]  [Malwarebytes, 1, 0, 0, 0]
    [C:\Program Files\ScanSoft\PDF Create 4\bin\DirectShellExt.dll]  [Zeon International Investment Corp. , 8, 0, 0, 1]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ShellEx.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll]  [Adobe Systems Inc., 8.0.5.2006102200\0]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80FRA.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.fra]  [Adobe Systems Inc., 8.0.5.2006102200\0]
    [C:\Program Files\Microsoft Office\Office12\msohevi.dll]  [Microsoft Corporation, 12.0.4518.1014]
[PID: 2684 / SYSTEM][C:\Windows\system32\taskeng.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 3192 / Mohamed][C:\Program Files\Windows Defender\MSASCui.exe]  [Microsoft Corporation, 1.1.1600.0]
    [C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll]  [Microsoft Corporation, 5.2.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
[PID: 3216 / Mohamed][C:\Windows\RtHDVCpl.exe]  [Realtek Semiconductor, 1, 0, 0, 69]
    [C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll]  [Microsoft Corporation, 5.2.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 3336 / SERVICE LOCAL][C:\Windows\system32\svchost.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 3364 / SYSTEM][C:\Windows\System32\svchost.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 3388 / Mohamed][C:\Program Files\Spyware Doctor\pctsTray.exe]  [PC Tools, 6.0.0.6]
    [C:\Program Files\Spyware Doctor\rtl100.bpl]  [CodeGear, 11.0.2902.10471]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\vcl100.bpl]  [CodeGear, 11.0.2902.10471]
    [C:\Program Files\Spyware Doctor\SysAccess.dll]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\ikdll.dll]  [PCTools Research Pty Ltd., 5.0.2.1040 built by: WinDDK]
    [C:\Program Files\Spyware Doctor\CommOM.dll]  [PC Tools, 6.0.0.3]
    [C:\Program Files\Spyware Doctor\CommLib.dll]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\PCToolsComponents.bpl]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Spyware Doctor\sdinfo.sdp]  [PC Tools, 6.0.0.3]
    [C:\Program Files\Spyware Doctor\cdialogs.dll]  [PC Tools, 6.0.0.4]
    [C:\Program Files\Spyware Doctor\pwindow.dll]  [PC Tools, 6.0.0.1]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 3432 / SYSTEM][C:\Windows\system32\SearchIndexer.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 3836 / Mohamed][C:\Program Files\Java\jre6\bin\jusched.exe]  [Sun Microsystems, Inc., 6.0.100.23]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
[PID: 2408 / Mohamed][C:\Windows\AStiDog1210.exe]  [, 0, 9, 1, 0]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 2340 / Mohamed][C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll]  [Microsoft Corporation, 12.0.6211.1000]
[PID: 2884 / Mohamed][C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe]  [Adobe Systems Inc., 8.0.0.2006102200]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.fra]  [Adobe Systems Inc., 8.0.0.0]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Adobe\Acrobat 8.0\Acrobat\FNP_Act_Installer.dll]  [Macrovision Europe Ltd., 11.03.005]
    [C:\Program Files\Adobe\Acrobat 8.0\Acrobat\asneu.dll]  [Adobe Systems Inc., 1, 6, 0, 8]
    [C:\Program Files\Adobe\Acrobat 8.0\Acrobat\adobe_personalization.dll]  [Adobe Systems Incorporated, 2,0,0,37]
    [C:\Program Files\Adobe\Acrobat 8.0\Acrobat\adobe_epic.dll]  [Adobe Systems Incorporated, 2,0,0,37]
    [C:\Program Files\Adobe\Acrobat 8.0\Acrobat\adobe_pcd.dll]  [Adobe Systems Incorporated, 1,0,0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
    [C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroTray.DEU]  [Adobe Systems Inc., 8.0.0.0]
[PID: 3352 / Mohamed][C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE]  [CANON INC., 1, 5, 0, 0]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Canon\MyPrinter\BJMyRes.dll]  [CANON INC., 1, 5, 0, 0]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 1972 / Mohamed][C:\Windows\System32\rundll32.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Windows\system32\NvMcTray.dll]  [NVIDIA Corporation, 7.15.11.7519]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Windows\System32\nvapi.dll]  [NVIDIA Corporation, 7.15.11.7519]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 3424 / Mohamed][C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe]  [InstallShield Software Corporation, 4, 10, 100, 25539]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 3780 / Mohamed][C:\Program Files\Windows Sidebar\sidebar.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll]  [Microsoft Corporation, 5.2.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\scrchpg.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\klscav.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\prremote.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\prloader.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\prkernel.ppl]  [Kaspersky Lab, 8.0.0.357]
    [c:\program files\kaspersky lab\kaspersky internet security 2009\params.ppl]  [Kaspersky Lab, 8.0.0.357]
    [c:\program files\kaspersky lab\kaspersky internet security 2009\pxstub.ppl]  [Kaspersky Lab, 8.0.0.357]
    [c:\program files\kaspersky lab\kaspersky internet security 2009\tempfile.ppl]  [Kaspersky Lab, 8.0.0.369]
    [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 7.15.11.7519]
    [C:\Windows\system32\icm32.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
[PID: 2184 / Mohamed][C:\Program Files\DAEMON Tools Lite\daemon.exe]  [DT Soft Ltd, 4.12.3.0]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\DAEMON Tools Lite\DaemonPlugin.dll]  [DT Soft Ltd, 4.12.0.0]
    [C:\Program Files\DAEMON Tools Lite\daemon.dll]  [DT Soft Ltd., 4.12.0.0]
    [C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL]  [Microsoft Corporation, 12.0.6211.1000]

[C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\DAEMON Tools Lite\Lang\ENU.dll]  [N/A, ]
    [C:\Program Files\DAEMON Tools Lite\Plugins\Images\bw5mount.dll]  [, 1.1.3.0]
    [C:\Program Files\DAEMON Tools Lite\Plugins\Images\bwtmount.dll]  [DT Soft Ltd., 1.01.0.0]
    [C:\Program Files\DAEMON Tools Lite\Plugins\Images\ccdmount.dll]  [DT Soft Ltd., 1.10.0.0]
    [C:\Program Files\DAEMON Tools Lite\Plugins\Images\cuemount.dll]  [DT Soft Ltd., 1.02.0.0]
    [C:\Program Files\DAEMON Tools Lite\Plugins\Images\iszmount.dll]  [DT Soft Ltd., 1.03.0.0]
    [C:\Program Files\DAEMON Tools Lite\Plugins\Images\nrgmount.dll]  [DT Soft Ltd., 1.12.0.0]
    [C:\Program Files\DAEMON Tools Lite\Plugins\Images\pdimount.dll]  [DT Soft Ltd., 1.01.0.0]
    [C:\Program Files\DAEMON Tools Lite\Plugins\Images\pfcmount.dll]  [DT Soft Ltd., 1.00.0.0]
    [C:\Program Files\DAEMON Tools Lite\pfctoc.dll]  [Padus(R), Inc., 1, 0, 0, 12]
[PID: 1352 / Mohamed][C:\Windows\ehome\ehtray.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 1868 / Mohamed][C:\Program Files\Skype\Phone\Skype.exe]  [Skype Technologies S.A., 3.8.0.139]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
[PID: 1680 / Mohamed][C:\Windows\ehome\ehmsas.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 2724 / Mohamed][C:\Program Files\Windows Media Player\wmpnscfg.exe]  [Microsoft Corporation, 11.0.6000.6324 (vista_rtm.061101-2205)]
    [C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll]  [Microsoft Corporation, 5.2.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 3404 / Mohamed][C:\Program Files\Orbitdownloader\orbitdm.exe]  [Orbitdownloader.com, 2, 7, 0, 1]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Orbitdownloader\download.dll]  [Orbitdownloader.com, 2, 6, 0, 4]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
[PID: 2656 / Mohamed][C:\Program Files\Raxco\PerfectDisk2008\PD91AgentS1.exe]  [Raxco Software, Inc., 9, 0, 0, 52]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 4068 / Mohamed][C:\Program Files\Windows Live\Messenger\msnmsgr.exe]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll]  [Microsoft Corporation, 5.2.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Program Files\Windows Live\Messenger\MSNCore.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Windows Live\Messenger\msidcrl40.dll]  [Microsoft Corporation, 4.100.313.1]
    [C:\Program Files\Windows Live\Messenger\ContactsUX.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Windows Live\Messenger\msgrvsta.thm]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Program Files\Windows Live\Messenger\msgslang.8.5.1302.1018.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Program Files\Windows Live\Messenger\msgsres.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Program Files\Windows Live\Messenger\lcapi.dll]  [Microsoft Corporation, 1.7.256.0 (RTC Version 4.3.5371.0) built by: msn8.0(rtbldlab)]
    [C:\Program Files\Windows Live\Messenger\lcres.dll]  [Microsoft Corporation, 1.7.180.0 (RTC Version 4.3.5371.0) built by: msn8.0(rtbldlab)]
    [C:\Program Files\Windows Live\Messenger\RTMPLTFM.dll]  [Microsoft Corporation, 3.0.5774.0 built by: media_msn80]
    [C:\Program Files\Windows Live\Messenger\MSGSWCAM.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Windows\system32\sirenacm.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Windows\system32\cam1210.ax]  [USBC, 1, 1, 0, 0]
    [C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGSC8~1.DLL]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Program Files\Windows Live\Messenger\lmcdata.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
    [C:\Program Files\Windows Live\Messenger\contact.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Program Files\Windows Live\Messenger\dfsr.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Windows Live\Messenger\abssm.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\scrchpg.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\klscav.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\prremote.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\prloader.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\prkernel.ppl]  [Kaspersky Lab, 8.0.0.357]
    [c:\program files\kaspersky lab\kaspersky internet security 2009\params.ppl]  [Kaspersky Lab, 8.0.0.357]
    [c:\program files\kaspersky lab\kaspersky internet security 2009\pxstub.ppl]  [Kaspersky Lab, 8.0.0.357]
    [c:\program files\kaspersky lab\kaspersky internet security 2009\tempfile.ppl]  [Kaspersky Lab, 8.0.0.369]
    [C:\Program Files\Windows Live\Messenger\custsat.dll]  [Microsoft Corporation, 9.0.3790.2428 (srv03_sp1_qfe.050422-1043)]
    [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 7.15.11.7519]
    [C:\Program Files\Windows Live\Messenger\usnsvcps.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
[PID: 2872 / SERVICE R?SEAU][C:\Program Files\Windows Media Player\wmpnetwk.exe]  [Microsoft Corporation, 11.0.6000.6324 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll]  [Microsoft Corporation, 5.2.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 2844 / Mohamed][C:\Program Files\Windows Sidebar\sidebar.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll]  [Microsoft Corporation, 5.2.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\scrchpg.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\klscav.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\prremote.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\prloader.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\prkernel.ppl]  [Kaspersky Lab, 8.0.0.357]
    [c:\program files\kaspersky lab\kaspersky internet security 2009\params.ppl]  [Kaspersky Lab, 8.0.0.357]
    [c:\program files\kaspersky lab\kaspersky internet security 2009\pxstub.ppl]  [Kaspersky Lab, 8.0.0.357]
    [c:\program files\kaspersky lab\kaspersky internet security 2009\tempfile.ppl]  [Kaspersky Lab, 8.0.0.369]
    [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 7.15.11.7519]
[PID: 4388 / Mohamed][C:\Program Files\Orbitdownloader\orbitnet.exe]  [Orbitdownloader.com, 2, 6, 0, 4]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
    [C:\Program Files\Orbitdownloader\idht.dll]  [Orbitdownloader.com, 1.3.0.1]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
[PID: 4708 / SYSTEM][C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe]  [Macrovision Europe Ltd., 11.03.005]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 4964 / Mohamed][C:\Program Files\Skype\Plugin Manager\skypePM.exe]  [Skype Technologies, 2.0.0.58]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll]  [EasyBits Media AS, 2.0.0.136]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
[PID: 5792 / SYSTEM][C:\Program Files\Windows Live\Messenger\usnsvc.exe]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Windows Live\Messenger\usnsvcps.dll]  [Microsoft Corporation, 8.5.1302.1018]
[PID: 6052 / Mohamed][C:\Program Files\Mozilla Firefox\firefox.exe]  [Mozilla Corporation, 1.9.0.1]
    [C:\Program Files\Mozilla Firefox\xul.dll]  [Mozilla Foundation, 1.9.0.1]
    [C:\Program Files\Mozilla Firefox\sqlite3.dll]  [sqlite.org, 3.5.9]
    [C:\Program Files\Mozilla Firefox\MOZCRT19.dll]  [Mozilla Foundation, 8.00.0000]
    [C:\Program Files\Mozilla Firefox\js3250.dll]  [Netscape Communications Corporation, 4.0]
    [C:\Program Files\Mozilla Firefox\nspr4.dll]  [Mozilla Foundation, 4.7.1]
    [C:\Program Files\Mozilla Firefox\smime3.dll]  [Mozilla Foundation, 3.12.0.3 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nss3.dll]  [Mozilla Foundation, 3.12.0.3 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nssutil3.dll]  [Mozilla Foundation, 3.12.0.3 Basic ECC]
    [C:\Program Files\Mozilla Firefox\plc4.dll]  [Mozilla Foundation, 4.7.1]
    [C:\Program Files\Mozilla Firefox\plds4.dll]  [Mozilla Foundation, 4.7.1]
    [C:\Program Files\Mozilla Firefox\ssl3.dll]  [Mozilla Foundation, 3.12.0.3 Basic ECC]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Mozilla Firefox\xpcom.dll]  [Mozilla Foundation, 1.9.0.1]
    [C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll]  [Kaspersky Lab, 8.0.0.370]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll]  [Mozilla Foundation, 1.9.0.1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
    [C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Mozilla Firefox\softokn3.dll]  [Mozilla Foundation, 3.12.0.3 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nssdbm3.dll]  [Mozilla Foundation, 3.12.0.3 Basic ECC]
    [C:\Program Files\Mozilla Firefox\freebl3.dll]  [Mozilla Foundation, 3.12.0.3 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nssckbi.dll]  [Mozilla Foundation, 1.70]
    [C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll]  [Mozilla Foundation, 1.9.0.1]
    [C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll]  [Microsoft Corporation, 5.2.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\PNRComponent.dll]  [Softomate, 1, 0, 0, 9]
    [C:\Program Files\Skype\Toolbars\Shared\SPhoneParser.dll]  [Skype Technologies, 1, 0, 1, 179]
    [C:\Program Files\Microsoft Office\Office12\msohevi.dll]  [Microsoft Corporation, 12.0.4518.1014]
[PID: 5896 / Mohamed][D:\Program Files\Counter-Strike 1.6\hlds.exe]  [Valve, 4, 1, 1, 1]
    [D:\Program Files\Counter-Strike 1.6\dbg.dll]  [N/A, ]
    [D:\Program Files\Counter-Strike 1.6\Steam.dll]  [Valve Corporation, 2.0.0.0]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [D:\Program Files\Counter-Strike 1.6\swds.dll]  [N/A, ]
    [D:\Program Files\Counter-Strike 1.6\vgui.dll]  [N/A, ]
    [D:\Program Files\Counter-Strike 1.6\mss32.dll]  [N/A, ]
    [D:\Program Files\Counter-Strike 1.6\filesystem_stdio.dll]  [N/A, ]
    [D:\Program Files\Counter-Strike 1.6\vgui2.dll]  [N/A, ]
    [D:\Program Files\Counter-Strike 1.6\Platform\Admin\AdminServer.dll]  [N/A, ]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
    [D:\Program Files\Counter-Strike 1.6\cstrike\dlls\mpbots.dll]  [N/A, ]
    [D:\Program Files\Counter-Strike 1.6\steamclient.dll]  [N/A, ]
    [D:\Program Files\Counter-Strike 1.6\vstdlib_s.dll]  [N/A, ]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [D:\Program Files\Counter-Strike 1.6\tier0_s.dll]  [N/A, ]
[PID: 4452 / SYSTEM][C:\Windows\system32\SearchProtocolHost.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
[PID: 1344 / Mohamed][C:\Program Files\BitComet\BitComet.exe]  [www.BitComet.com, 1.01]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\scrchpg.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\klscav.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\prremote.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\prloader.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\prkernel.ppl]  [Kaspersky Lab, 8.0.0.357]
    [c:\program files\kaspersky lab\kaspersky internet security 2009\params.ppl]  [Kaspersky Lab, 8.0.0.357]
    [c:\program files\kaspersky lab\kaspersky internet security 2009\pxstub.ppl]  [Kaspersky Lab, 8.0.0.357]
    [c:\program files\kaspersky lab\kaspersky internet security 2009\tempfile.ppl]  [Kaspersky Lab, 8.0.0.369]
[PID: 2708 / SYSTEM][C:\Windows\system32\SearchFilterHost.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 5280 / Mohamed][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.DLL]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1434_none_d08b6002442c891f\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.1434]
    [C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL]  [Microsoft Corporation, 12.0.6211.1000]
    [C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3\gdiplus.dll]  [Microsoft Corporation, 5.2.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Program Files\FileZilla FTP Client\fzshellext.dll]  [, 3, 0, 11, 1]
[PID: 6108 / Mohamed][C:\Users\Mohamed\AppData\Local\Temp\Rar$EX00.680\SREngLdr.EXE]  [Smallfrogs Studio, 2.6.12.1018]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll]  [Kaspersky Lab, 8.0.0.357]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
[PID: 5748 / Mohamed][C:\Users\Mohamed\AppData\Local\Temp\Rar$EX00.680\SRE5f41b4b.EXE]  [Smallfrogs Studio, 2.6.12.1018]
    [C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.dll]  [Microsoft Corporation, 6.10 (vista_rtm.061101-2205)]
    [C:\Program Files\Spyware Doctor\smumhook.dll]  [PC Tools, 6.0.0.1]
    [C:\Program Files\Spyware Doctor\klg.dat]  [PC Tools, 6.0.0.0]
    [C:\Users\Mohamed\AppData\Local\Temp\Rar$EX00.680\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]

==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  Error. [regedit.exe "%1" %*]
.BAT  OK. ["%1" %*]
.SCR  Error. ["%1" %*]
.CHM  OK. ["%SystemRoot%\hh.exe" %1]
.HLP  OK. [%SystemRoot%\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
.JS   Error. ["C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe","%1"]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1       localhost
::1             localhost

==================================
Process Privileges Scan
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 336, C:\PROGRAM FILES\BONJOUR\MDNSRESPONDER.EXE]
Special Privileges Enabled: SeSystemtimePrivilege [PID = 336, C:\PROGRAM FILES\BONJOUR\MDNSRESPONDER.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 544, C:\PROGRAM FILES\CANON\IJPLM\IJPLMSVC.EXE]
Special Privileges Enabled: SeSystemtimePrivilege [PID = 544, C:\PROGRAM FILES\CANON\IJPLM\IJPLMSVC.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 568, C:\PROGRAM FILES\JAVA\JRE6\BIN\JQS.EXE]
Special Privileges Enabled: SeSystemtimePrivilege [PID = 568, C:\PROGRAM FILES\JAVA\JRE6\BIN\JQS.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2408, C:\WINDOWS\ASTIDOG1210.EXE]
Special Privileges Enabled: SeSystemtimePrivilege [PID = 2408, C:\WINDOWS\ASTIDOG1210.EXE]
Special Privileges Enabled: SeDebugPrivilege [PID = 2408, C:\WINDOWS\ASTIDOG1210.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 3424, C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE]
Special Privileges Enabled: SeSystemtimePrivilege [PID = 3424, C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE]
Special Privileges Enabled: SeDebugPrivilege [PID = 3424, C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 3404, C:\PROGRAM FILES\ORBITDOWNLOADER\ORBITDM.EXE]
Special Privileges Enabled: SeSystemtimePrivilege [PID = 3404, C:\PROGRAM FILES\ORBITDOWNLOADER\ORBITDM.EXE]
Special Privileges Enabled: SeDebugPrivilege [PID = 3404, C:\PROGRAM FILES\ORBITDOWNLOADER\ORBITDM.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 4388, C:\PROGRAM FILES\ORBITDOWNLOADER\ORBITNET.EXE]
Special Privileges Enabled: SeSystemtimePrivilege [PID = 4388, C:\PROGRAM FILES\ORBITDOWNLOADER\ORBITNET.EXE]
Special Privileges Enabled: SeDebugPrivilege [PID = 4388, C:\PROGRAM FILES\ORBITDOWNLOADER\ORBITNET.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 4708, C:\PROGRAM FILES\COMMON FILES\MACROVISION SHARED\FLEXNET PUBLISHER\FNPLICENSINGSERVICE.EXE]
Special Privileges Enabled: SeSystemtimePrivilege [PID = 4708, C:\PROGRAM FILES\COMMON FILES\MACROVISION SHARED\FLEXNET PUBLISHER\FNPLICENSINGSERVICE.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 5896, D:\PROGRAM FILES\COUNTER-STRIKE 1.6\HLDS.EXE]
Special Privileges Enabled: SeSystemtimePrivilege [PID = 5896, D:\PROGRAM FILES\COUNTER-STRIKE 1.6\HLDS.EXE]
Special Privileges Enabled: SeDebugPrivilege [PID = 5896, D:\PROGRAM FILES\COUNTER-STRIKE 1.6\HLDS.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 5280, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
Special Privileges Enabled: SeSystemtimePrivilege [PID = 5280, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
Special Privileges Enabled: SeDebugPrivilege [PID = 5280, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 6108, C:\USERS\MOHAMED\APPDATA\LOCAL\TEMP\RAR$EX00.680\SRENGLDR.EXE]
Special Privileges Enabled: SeSystemtimePrivilege [PID = 6108, C:\USERS\MOHAMED\APPDATA\LOCAL\TEMP\RAR$EX00.680\SRENGLDR.EXE]
Special Privileges Enabled: SeDebugPrivilege [PID = 6108, C:\USERS\MOHAMED\APPDATA\LOCAL\TEMP\RAR$EX00.680\SRENGLDR.EXE]

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================

Link to comment
Share on other sites

  • 0
KIS doesn't alarm anything, it's windows defender that detected it and it doesn't show which file is it!!

And here is the report done with the program you provided!! it's quite long!! (i'll have to double post)

yes, too long , unexpected... :o

C:\Windows\AStiDog1210.exe

C:\Windows\system32\ddCSLDuV.dll

what are those 2 files used for ? Do you have shown all files ? Including system documents ?

Link to comment
Share on other sites

  • 0

First off.. the best solution especially in a multitude of your case would be to format and reinstall. Virus's can greatly affect your system files and your installation will never be the same unless you completely start over. Most virus's are hard to get rid of becaue of a rootkit.

How I rid viruses:

Turn off System Restore (this is your decision. I do not run any of my systems with system restore because virus's are known to hide in the restore files).

Go to start/run and type in msconfig: go to the startup tab and uncheck anything that looks fishy to you. Click OK and reboot as requested.

Run safe mode with networking. Go to housecall.trendmicro.com. Run a scan and let it remove or rid all that it can. Keep note and aware of items that Trend was NOT able to remove. Write these items down.

Restart the system and continue to safe mode with networking. Locate and download any standalone removal tools usually provided through Symantec for the virus's that you located. Be sure that these tools are run in safe mode and a reboot after each tool may be required. (best way to get these?? Google: *virus name* removal tool*

Run utilities like Spybot and Adaware to get additional malware.

This isn't something you will be able to fix in 10 minutes.. it will take alot of time and patience. A reinstall will probably take less time.

Link to comment
Share on other sites

  • 0

@missing: I don't know either of the files!! And I see all system docs

@Killa Aaron: it's a last resort, it's too complicated and the result isn't guaranteed, a friend of mine tried it on the conhook.b but didn't work!! Conhook.i is more powerful than the Conhook.b!

@Rob2687: ok I'm gonna try this and inform you with the result

@+Volatile: I say no to a format!! Because I had painful hours in filling the pc with media and so on!! Besides, I formatted the PC 3 times (because of motheboard changes) in 2 months which is very often!! For your solution to get rid of viruses, I will do that Rob2687's method fails!

Thanks a lot everyone for your contribution!!

Link to comment
Share on other sites

  • 0

@Rob2687, Your method didn't work! :( after hours of scanning!!

Now I noticed also that IE is running in without addons mode (I didn't notice that b4 because I use FF)

I'll be trying every way possible to delete this crap :'(

@Joel, I tried to scan with spyware doctor, which is, i think, is better than Superantispyware, is it?

@corona2k: thanks for the link, I'll try that too!!

Hopefully that this misery ends asap!!! I really need my pc back.

Thanks everyone for your help and your effort!

Link to comment
Share on other sites

  • 0

Hey everyone, you know what I think it's gone, I don't know what's the thing that made it disappear, but it's all gone!! lol I tried everything posted on this thread one of them worked and I didn't realize that till I made scan with spyhunter3 and showed that the pc is all clean, I also noticed that the lags are gone and all the problems related to the trojan are gone!! And also I think that the crappy processes, here is a newly made hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 14:08:29, on 27/07/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Windows\AStiDog1210.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91AgentS1.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Windows\system32\conime.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fen?tres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Octh Class - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9658B22E-6095-443E-8F51-D4BC266DA23C} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fen?tres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la s?lection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la s?lection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens s?lectionn?s en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens s?lectionn?s en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - (no file)
O9 - Extra button: (no name) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: (no name) - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (no file)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix: 
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll,
O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll
O23 - Service: Adobe Version Cue CS3 {fr_FR}  (Adobe Version Cue CS3) - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing)
O23 - Service: Kaspersky Internet Security (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

Thanks everyone for your help!! It's very appreciated, viva the neowin community!!

Link to comment
Share on other sites

  • 0

Could you please navigate to C:\Windows\AStiDog1210.exe , rt click on it and check up its Properties... or maybe also get it checked at C:\Windows\AStiDog1210.exe Just to be on the safe side.

Link to comment
Share on other sites

  • 0

What am I supposed to look for in the properties? The file C:\Windows\AStiDog1210.exe is there, and I don't know where it came from!

Link to comment
Share on other sites

  • 0

The only true way to know the virus is gone is to format the machine, the virus could have duplicated itself anywhere on your machine and be waiting to hit you again.

Link to comment
Share on other sites

  • 0

i got avast.. and first scan (it scanned just before the boot of windows) and i found a couple of trojans.. was kinda funny too since I was so sure there was nothing on it.. that I gave my mate a lot of that stuff.. (and he doesnt have a virus scanner) and now he has a problem, and i just got rid of it XD

Link to comment
Share on other sites

  • 0

The best and safest thing to do is reformat. I did a quick google search for AStiDog1210.exe and nothing comes up. This suggests that it is probably a virus.

Reformat the computer and be done with it!

Link to comment
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.