Hi,

Spybot found on my computer following entries:

Win32.Agent.pz: Program directory
C:\WINDOWS\System32\wsnpoem\

Win32.Agent.pz: Library
C:\WINDOWS\System32\wsnpoem\audio.dll

Win32.Agent.pz: Library
C:\WINDOWS\System32\wsnpoem\video.dll

Win32.Agent.pz: Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit=...C:\WINDOWS\System32\ntos.exe

And was not able to remove them. Norton antivirus found nothing.

Wondering what was going on I started to search for similar cases on your forum, and found this:

http://forums.spybot.info/showthread.php?t=12758

In panic because of the comments of "Angelfire777 - Warrior", I kept on searching and found also this:

http://forums.spybot.info/showthread...light=ntos.exe

Were "bitman - Spybot Advisor Team' advices "Gabe2k2" to take a look at this:

http://ip.securescience.net/advisori...eCaseStudy.pdf

I also took a look at this document and followed the advice given to clean up the trojan:

"There is an easier way to clean the system that does not share the same stability concerns, but is very effective. One can use a tool such as Process Explorer, [11] to close winlogon.exe’s handle to ntos.exe. This can be done by using the “Find Handle” function and searching for “ntos.exe.”
From here, ntos.exe can be deleted; and once the system is rebooted, it will no longer be infected. This is because after removing ntos.exe from disk, the trojan is only memory resident. The remaining files and registry values identified in the detection program can be removed, however they will not cause harm to the system once the main trojan code is deactivated."
([Prg] Malware Case Study, By Secure Science Corporation and Michael Ligh
13-November 2006, v1.0)

After having done this, and rebooting the system, Spybot found the same entries like given before, but was now able to remove the entries.

So, according to Spybot my system is clean now. But beeing an absolut dummy on this matters, and after reading so many comments and things that I don't understand at all, i have serious doubts if indeed the problem is completely solved> Therefore these questions:
1. Are the hackers indeed not receiving information from my pc anymore?
2. Am I more vurnible now for other attacks?
3. Can i (still) spread or affect other computers with this trojan?
And 4. If this trojan is already know that well since november 2006, how come that Norton, wich costs me +/- €100 a year for two computers, don't report anything? - How come that Spybot still can not repair the entry?

I thank U already in advance to help this dummy to become a little less dumb.