<?xml version="1.0" encoding="ISO-8859-1"?>
<!-- generator="FeedCreator 1.7.2" -->
<rss version="2.0">
    <channel>
        <title>Lowyat.NET: Latest topics by NutterButters</title>
        <description></description>
        <link>http://forum.lowyat.net/</link>
        <lastBuildDate>Wed, 25 Nov 2009 01:40:45 +0800</lastBuildDate>
        <generator>FeedCreator 1.7.2</generator>
        <item>
            <title>Plagued by wisdstr.exe virus [CLOSED. THANKS&amp;#33;]</title>
            <link>http://forum.lowyat.net/topic/1131237</link>
            <description>Hi all...I have this problem with a couple of viruses I seem to have gotten while visiting a site? They are:&lt;br /&gt;&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;wisdstr.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;dllcache&amp;#092;figaro.sys&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;braviax.exe&lt;br /&gt;&lt;br /&gt;and in C:&amp;#092;Documents and Settings&amp;#092;LocalService&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5 there&amp;#39;s Install[1].exe; Install[2].exe etc&lt;br /&gt;&lt;br /&gt;The Install[n].exe keeps multiplying itself?? After removal, it keeps coming back after reboot and the problem seems to be detected whenever I connect to the Internet. &lt;br /&gt;&lt;br /&gt;I am using Windows XP. I have used Avira and MBAM to remove them but they keep spawning back...help will be very much appreciated.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here&amp;#39;s the log file I copied:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Avira AntiVir Personal&lt;br /&gt;Report file date: 14 Ogos 2009  12:22&lt;br /&gt;&lt;br /&gt;Scanning for 1637477 virus strains and unwanted programs.&lt;br /&gt;&lt;br /&gt;Licensee        : Avira AntiVir Personal - FREE Antivirus&lt;br /&gt;Serial number   : 0000149996-ADJIE-0000001&lt;br /&gt;Platform        : Windows XP&lt;br /&gt;Windows version : (Service Pack 3)  [5.1.2600]&lt;br /&gt;Boot mode       : Normally booted&lt;br /&gt;Username        : SYSTEM&lt;br /&gt;Computer name   : PERSONAL&lt;br /&gt;&lt;br /&gt;Version information:&lt;br /&gt;BUILD.DAT       : 9.0.0.407     17961 Bytes   7/29/2009 10:34:00&lt;br /&gt;AVSCAN.EXE      : 9.0.3.7      466689 Bytes   7/21/2009 06:36:14&lt;br /&gt;AVSCAN.DLL      : 9.0.3.0       40705 Bytes   2/27/2009 03:58:24&lt;br /&gt;LUKE.DLL        : 9.0.3.2      209665 Bytes   2/20/2009 04:35:49&lt;br /&gt;LUKERES.DLL     : 9.0.2.0       12033 Bytes   2/27/2009 03:58:52&lt;br /&gt;ANTIVIR0.VDF    : 7.1.0.0    15603712 Bytes  10/27/2008 05:30:36&lt;br /&gt;ANTIVIR1.VDF    : 7.1.4.132   5707264 Bytes   6/24/2009 02:21:42&lt;br /&gt;ANTIVIR2.VDF    : 7.1.5.88    2668032 Bytes   8/10/2009 04:20:54&lt;br /&gt;ANTIVIR3.VDF    : 7.1.5.110    263680 Bytes   8/13/2009 04:21:01&lt;br /&gt;Engineversion   : 8.2.1.1  &lt;br /&gt;AEVDF.DLL       : 8.1.1.1      106868 Bytes   7/28/2009 06:31:50&lt;br /&gt;AESCRIPT.DLL    : 8.1.2.25     459130 Bytes   8/14/2009 04:21:29&lt;br /&gt;AESCN.DLL       : 8.1.2.4      127348 Bytes   7/23/2009 02:59:39&lt;br /&gt;AERDL.DLL       : 8.1.2.4      430452 Bytes   7/23/2009 02:59:39&lt;br /&gt;AEPACK.DLL      : 8.1.3.18     401783 Bytes   7/28/2009 06:31:50&lt;br /&gt;AEOFFICE.DLL    : 8.1.0.38     196987 Bytes   7/23/2009 02:59:39&lt;br /&gt;AEHEUR.DLL      : 8.1.0.154   1917302 Bytes   8/14/2009 04:21:26&lt;br /&gt;AEHELP.DLL      : 8.1.5.3      233846 Bytes   7/23/2009 02:59:39&lt;br /&gt;AEGEN.DLL       : 8.1.1.56     356725 Bytes   8/14/2009 04:21:05&lt;br /&gt;AEEMU.DLL       : 8.1.0.9      393588 Bytes   10/9/2008 07:32:40&lt;br /&gt;AECORE.DLL      : 8.1.7.6      184694 Bytes   7/23/2009 02:59:39&lt;br /&gt;AEBB.DLL        : 8.1.0.3       53618 Bytes   10/9/2008 07:32:40&lt;br /&gt;AVWINLL.DLL     : 9.0.0.3       18177 Bytes  12/12/2008 01:47:59&lt;br /&gt;AVPREF.DLL      : 9.0.0.1       43777 Bytes   12/5/2008 03:32:15&lt;br /&gt;AVREP.DLL       : 8.0.0.3      155905 Bytes   1/20/2009 07:34:28&lt;br /&gt;AVREG.DLL       : 9.0.0.0       36609 Bytes   12/5/2008 03:32:09&lt;br /&gt;AVARKT.DLL      : 9.0.0.3      292609 Bytes   3/24/2009 08:05:41&lt;br /&gt;AVEVTLOG.DLL    : 9.0.0.7      167169 Bytes   1/30/2009 03:37:08&lt;br /&gt;SQLITE3.DLL     : 3.6.1.0      326401 Bytes   1/28/2009 08:03:49&lt;br /&gt;SMTPLIB.DLL     : 9.2.0.25      28417 Bytes    2/2/2009 01:21:33&lt;br /&gt;NETNT.DLL       : 9.0.0.0       11521 Bytes   12/5/2008 03:32:10&lt;br /&gt;RCIMAGE.DLL     : 9.0.0.25    2438913 Bytes   5/15/2009 08:39:58&lt;br /&gt;RCTEXT.DLL      : 9.0.37.0      86785 Bytes   4/17/2009 03:19:48&lt;br /&gt;&lt;br /&gt;Configuration settings for the scan:&lt;br /&gt;Jobname.............................: Complete system scan&lt;br /&gt;Configuration file..................: c:&amp;#092;program files&amp;#092;avira&amp;#092;antivir desktop&amp;#092;sysscan.avp&lt;br /&gt;Logging.............................: low&lt;br /&gt;Primary action......................: interactive&lt;br /&gt;Secondary action....................: ignore&lt;br /&gt;Scan master boot sector.............: on&lt;br /&gt;Scan boot sector....................: on&lt;br /&gt;Boot sectors........................: C:, E:, &lt;br /&gt;Process scan........................: on&lt;br /&gt;Scan registry.......................: on&lt;br /&gt;Search for rootkits.................: on&lt;br /&gt;Integrity checking of system files..: off&lt;br /&gt;Scan all files......................: All files&lt;br /&gt;Scan archives.......................: on&lt;br /&gt;Recursion depth.....................: 20&lt;br /&gt;Smart extensions....................: on&lt;br /&gt;Macro heuristic.....................: on&lt;br /&gt;File heuristic......................: medium&lt;br /&gt;&lt;br /&gt;Start of the scan: 14 Ogos 2009  12:22&lt;br /&gt;&lt;br /&gt;Starting search for hidden objects.&lt;br /&gt;&amp;#39;33998&amp;#39; objects were checked, &amp;#39;0&amp;#39; hidden objects were found.&lt;br /&gt;&lt;br /&gt;The scan of running processes will be started&lt;br /&gt;Scan process &amp;#39;avscan.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;avcenter.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;avcenter.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;rundll32.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;avgnt.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;sched.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;avguard.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;msiexec.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;chrome.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;chrome.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;chrome.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;chrome.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;chrome.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;chrome.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;chrome.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;skypePM.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;chrome.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;uTorrent.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;svchost.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;rundll32.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;braviax.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;svchost.exe&amp;#39; - &amp;#39;0&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;svchost.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;svchost.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;msword98.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;wlcomm.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;iPodService.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;YahooWidgets.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;YahooWidgets.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;YahooWidgets.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;RKLauncher.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;DSLMON.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;msmsgs.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;wmiprvse.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;msnmsgr.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;Skype.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;hpqwmiex.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;GoogleCrashHandler.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;iTunesHelper.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;realsched.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;jusched.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;ashDisp.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;QLBCTRL.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;igfxsrvc.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;AzMixerSel.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;igfxpers.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;hkcmd.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;igfxtray.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;PDVDServ.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;alg.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;GrooveMonitor.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;ashWebSv.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;ashMaiSv.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;svchost.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;jqs.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;mDNSResponder.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;AppleMobileDeviceService.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;spoolsv.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;ctfmon.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;explorer.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;ashServ.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;aswUpdSv.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;svchost.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;svchost.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;svchost.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;svchost.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;svchost.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;lsass.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;services.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;winlogon.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;csrss.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;Scan process &amp;#39;smss.exe&amp;#39; - &amp;#39;1&amp;#39; Module(s) have been scanned&lt;br /&gt;71 processes with 71 modules were scanned&lt;br /&gt;&lt;br /&gt;Starting master boot sector scan:&lt;br /&gt;Master boot sector HD0&lt;br /&gt;    [INFO]      No virus was found&amp;#33;&lt;br /&gt;Master boot sector HD1&lt;br /&gt;    [INFO]      No virus was found&amp;#33;&lt;br /&gt;Master boot sector HD2&lt;br /&gt;    [INFO]      No virus was found&amp;#33;&lt;br /&gt;&lt;br /&gt;Start scanning boot sectors:&lt;br /&gt;Boot sector &amp;#39;C:&amp;#092;&amp;#39;&lt;br /&gt;    [INFO]      No virus was found&amp;#33;&lt;br /&gt;Boot sector &amp;#39;E:&amp;#092;&amp;#39;&lt;br /&gt;    [INFO]      No virus was found&amp;#33;&lt;br /&gt;&lt;br /&gt;Starting to scan executable files (registry).&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;2kadiras.exe&lt;br /&gt;    [DETECTION] Contains recognition pattern of the DIAL/32768.A.29 dialer&lt;br /&gt;&lt;br /&gt;The registry was scanned ( &amp;#39;67&amp;#39; files ).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Starting the file scan:&lt;br /&gt;&lt;br /&gt;Begin scan in &amp;#39;C:&amp;#092;&amp;#39;&lt;br /&gt;C:&amp;#092;pagefile.sys&lt;br /&gt;    [WARNING]   The file could not be opened&amp;#33;&lt;br /&gt;    [NOTE]      This file is a Windows system file.&lt;br /&gt;    [NOTE]      This file cannot be opened for scanning.&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temp&amp;#092;2E.tmp&lt;br /&gt;    [DETECTION] Is the TR/Dropper.Gen Trojan&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;4PIJ856Z&amp;#092;Install[1].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;4PIJ856Z&amp;#092;Install[3].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;4PIJ856Z&amp;#092;Install[4].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;OXYFOXE7&amp;#092;Install[1].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;OXYFOXE7&amp;#092;Install[2].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;OXYFOXE7&amp;#092;Install[3].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;S12JCT2R&amp;#092;Install[2].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;S12JCT2R&amp;#092;Install[3].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;WH2RC5ER&amp;#092;Install[1].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;eRightSoft&amp;#092;SUPER&amp;#092;SUPER1.dlm&lt;br /&gt;    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan&lt;br /&gt;C:&amp;#092;System Volume Information&amp;#092;_restore{8E354EBD-E0CB-454D-A49F-EA46C28E8068}&amp;#092;RP17&amp;#092;A0005246.exe&lt;br /&gt;    [DETECTION] Is the TR/Keygen.GM Trojan&lt;br /&gt;C:&amp;#092;System Volume Information&amp;#092;_restore{8E354EBD-E0CB-454D-A49F-EA46C28E8068}&amp;#092;RP18&amp;#092;A0005412.exe&lt;br /&gt;  [0] Archive type: CAB SFX (self extracting)&lt;br /&gt;    --&amp;#62; &amp;#092;data1.cab&lt;br /&gt;      [WARNING]   No further files can be extracted from this archive. The archive will be closed&lt;br /&gt;    [WARNING]   No further files can be extracted from this archive. The archive will be closed&lt;br /&gt;C:&amp;#092;System Volume Information&amp;#092;_restore{8E354EBD-E0CB-454D-A49F-EA46C28E8068}&amp;#092;RP28&amp;#092;A0007049.exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;C:&amp;#092;System Volume Information&amp;#092;_restore{8E354EBD-E0CB-454D-A49F-EA46C28E8068}&amp;#092;RP30&amp;#092;A0007245.exe&lt;br /&gt;    [DETECTION] Contains recognition pattern of the DIAL/32768.A.29 dialer&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Temp&amp;#092;wpv381250008288.exe&lt;br /&gt;  [0] Archive type: RAR SFX (self extracting)&lt;br /&gt;    [DETECTION] Contains recognition pattern of the DR/Dldr.Boltolog.hkm dropper&lt;br /&gt;    --&amp;#62; install.exe&lt;br /&gt;      [DETECTION] Is the TR/Dropper.Gen Trojan&lt;br /&gt;Begin scan in &amp;#39;E:&amp;#092;&amp;#39; &amp;lt;DATA&amp;gt;&lt;br /&gt;&lt;br /&gt;Beginning disinfection:&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;2kadiras.exe&lt;br /&gt;    [DETECTION] Contains recognition pattern of the DIAL/32768.A.29 dialer&lt;br /&gt;    [WARNING]   An error has occurred and the file was not deleted. ErrorID: 26004&lt;br /&gt;    [WARNING]   The source file could not be found.&lt;br /&gt;    [NOTE]      Attempting to perform action using the ARK library.&lt;br /&gt;    [WARNING]   Error in ARK library&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temp&amp;#092;2E.tmp&lt;br /&gt;    [DETECTION] Is the TR/Dropper.Gen Trojan&lt;br /&gt;    [NOTE]      The file was moved to &amp;#39;4ab2f6c9.qua&amp;#39;&amp;#33;&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;4PIJ856Z&amp;#092;Install[1].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;    [NOTE]      The file was moved to &amp;#39;4af7f6f2.qua&amp;#39;&amp;#33;&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;4PIJ856Z&amp;#092;Install[3].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;    [NOTE]      The file was moved to &amp;#39;4e4b6a43.qua&amp;#39;&amp;#33;&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;4PIJ856Z&amp;#092;Install[4].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;    [NOTE]      The file was moved to &amp;#39;4e4842fb.qua&amp;#39;&amp;#33;&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;OXYFOXE7&amp;#092;Install[1].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;    [NOTE]      The file was moved to &amp;#39;4c83e463.qua&amp;#39;&amp;#33;&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;OXYFOXE7&amp;#092;Install[2].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;    [NOTE]      The file was moved to &amp;#39;4c82ecab.qua&amp;#39;&amp;#33;&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;OXYFOXE7&amp;#092;Install[3].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;    [NOTE]      The file was moved to &amp;#39;4c81d4d3.qua&amp;#39;&amp;#33;&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;S12JCT2R&amp;#092;Install[2].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;    [WARNING]   An error has occurred and the file was not deleted. ErrorID: 26004&lt;br /&gt;    [WARNING]   The source file could not be found.&lt;br /&gt;    [NOTE]      Attempting to perform action using the ARK library.&lt;br /&gt;    [WARNING]   Error in ARK library&lt;br /&gt;    [NOTE]      The file is scheduled for deleting after reboot.&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;S12JCT2R&amp;#092;Install[3].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;    [WARNING]   An error has occurred and the file was not deleted. ErrorID: 26004&lt;br /&gt;    [WARNING]   The source file could not be found.&lt;br /&gt;    [NOTE]      Attempting to perform action using the ARK library.&lt;br /&gt;    [WARNING]   Error in ARK library&lt;br /&gt;    [NOTE]      The file is scheduled for deleting after reboot.&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temporary Internet Files&amp;#092;Content.IE5&amp;#092;WH2RC5ER&amp;#092;Install[1].exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;    [NOTE]      The file was moved to &amp;#39;4af7f827.qua&amp;#39;&amp;#33;&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;eRightSoft&amp;#092;SUPER&amp;#092;SUPER1.dlm&lt;br /&gt;    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan&lt;br /&gt;    [NOTE]      The file was moved to &amp;#39;4ad4f80e.qua&amp;#39;&amp;#33;&lt;br /&gt;C:&amp;#092;System Volume Information&amp;#092;_restore{8E354EBD-E0CB-454D-A49F-EA46C28E8068}&amp;#092;RP17&amp;#092;A0005246.exe&lt;br /&gt;    [DETECTION] Is the TR/Keygen.GM Trojan&lt;br /&gt;    [NOTE]      The file was moved to &amp;#39;4ab4f7ea.qua&amp;#39;&amp;#33;&lt;br /&gt;C:&amp;#092;System Volume Information&amp;#092;_restore{8E354EBD-E0CB-454D-A49F-EA46C28E8068}&amp;#092;RP28&amp;#092;A0007049.exe&lt;br /&gt;    [DETECTION] Is the TR/Dldr.FraudLo.sxm Trojan&lt;br /&gt;    [NOTE]      The file was moved to &amp;#39;4e19dcc3.qua&amp;#39;&amp;#33;&lt;br /&gt;C:&amp;#092;System Volume Information&amp;#092;_restore{8E354EBD-E0CB-454D-A49F-EA46C28E8068}&amp;#092;RP30&amp;#092;A0007245.exe&lt;br /&gt;    [DETECTION] Contains recognition pattern of the DIAL/32768.A.29 dialer&lt;br /&gt;    [NOTE]      The file was moved to &amp;#39;4ccb867b.qua&amp;#39;&amp;#33;&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Temp&amp;#092;wpv381250008288.exe&lt;br /&gt;    [DETECTION] Contains recognition pattern of the DR/Dldr.Boltolog.hkm dropper&lt;br /&gt;    [NOTE]      The file was moved to &amp;#39;4afaf82a.qua&amp;#39;&amp;#33;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;End of the scan: 14 Ogos 2009  13:35&lt;br /&gt;Used time:  1:05:47 Hour(s)&lt;br /&gt;&lt;br /&gt;The scan has been done completely.&lt;br /&gt;&lt;br /&gt;   5044 Scanned directories&lt;br /&gt; 172336 Files were scanned&lt;br /&gt;     17 Viruses and/or unwanted programs were found&lt;br /&gt;      0 Files were classified as suspicious&lt;br /&gt;      0 files were deleted&lt;br /&gt;      0 Viruses and unwanted programs were repaired&lt;br /&gt;     13 Files were moved to quarantine&lt;br /&gt;      0 Files were renamed&lt;br /&gt;      1 Files cannot be scanned&lt;br /&gt; 172318 Files not concerned&lt;br /&gt;   2364 Archives were scanned&lt;br /&gt;      6 Warnings&lt;br /&gt;     17 Notes&lt;br /&gt;  33998 Objects were scanned with rootkit scan&lt;br /&gt;      0 Hidden objects were found&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;And from MBAM:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Malwarebytes&amp;#39; Anti-Malware 1.40&lt;br /&gt;Database version: 2551&lt;br /&gt;Windows 5.1.2600 Service Pack 3&lt;br /&gt;&lt;br /&gt;8/15/2009 2:03:55 PM&lt;br /&gt;mbam-log-2009-08-15 (14-03-55).txt&lt;br /&gt;&lt;br /&gt;Scan type: Quick Scan&lt;br /&gt;Objects scanned: 89722&lt;br /&gt;Time elapsed: 8 minute(s), 10 second(s)&lt;br /&gt;&lt;br /&gt;Memory Processes Infected: 1&lt;br /&gt;Memory Modules Infected: 0&lt;br /&gt;Registry Keys Infected: 0&lt;br /&gt;Registry Values Infected: 4&lt;br /&gt;Registry Data Items Infected: 6&lt;br /&gt;Folders Infected: 0&lt;br /&gt;Files Infected: 20&lt;br /&gt;&lt;br /&gt;Memory Processes Infected:&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;braviax.exe (Trojan.FakeAlert) -&amp;gt; Unloaded process successfully.&lt;br /&gt;&lt;br /&gt;Memory Modules Infected:&lt;br /&gt;(No malicious items detected)&lt;br /&gt;&lt;br /&gt;Registry Keys Infected:&lt;br /&gt;(No malicious items detected)&lt;br /&gt;&lt;br /&gt;Registry Values Infected:&lt;br /&gt;HKEY_CURRENT_USER&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Run&amp;#092;msword98 (Trojan.FakeAlert.H) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Run&amp;#092;msword98 (Trojan.FakeAlert.H) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Run&amp;#092;braviax (Trojan.Downloader) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_CURRENT_USER&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Run&amp;#092;braviax (Trojan.Downloader) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;&lt;br /&gt;Registry Data Items Infected:&lt;br /&gt;HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Security Center&amp;#092;AntiVirusDisableNotify (Disabled.SecurityCenter) -&amp;gt; Bad: (1) Good: (0) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Security Center&amp;#092;FirewallDisableNotify (Disabled.SecurityCenter) -&amp;gt; Bad: (1) Good: (0) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Security Center&amp;#092;UpdatesDisableNotify (Disabled.SecurityCenter) -&amp;gt; Bad: (1) Good: (0) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_CURRENT_USER&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Security Center&amp;#092;AntiVirusDisableNotify (Disabled.SecurityCenter) -&amp;gt; Bad: (1) Good: (0) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_CURRENT_USER&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Security Center&amp;#092;FirewallDisableNotify (Disabled.SecurityCenter) -&amp;gt; Bad: (1) Good: (0) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_CURRENT_USER&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Security Center&amp;#092;UpdatesDisableNotify (Disabled.SecurityCenter) -&amp;gt; Bad: (1) Good: (0) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;&lt;br /&gt;Folders Infected:&lt;br /&gt;(No malicious items detected)&lt;br /&gt;&lt;br /&gt;Files Infected:&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;msword98.exe (Trojan.FakeAlert.H) -&amp;gt; Delete on reboot.&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;msword98.exe (Trojan.FakeAlert.H) -&amp;gt; Delete on reboot.&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Temp&amp;#092;wpv111250109698.exe (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Temp&amp;#092;BN10.tmp (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Temp&amp;#092;BN12.tmp (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Temp&amp;#092;BN13.tmp (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Temp&amp;#092;BN18.tmp (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Temp&amp;#092;BN19.tmp (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Temp&amp;#092;BN1A.tmp (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Temp&amp;#092;BN94.tmp (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Temp&amp;#092;BN95.tmp (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temp&amp;#092;BN1B.tmp (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temp&amp;#092;BN1F.tmp (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temp&amp;#092;BN20.tmp (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temp&amp;#092;BN21.tmp (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Local Settings&amp;#092;Temp&amp;#092;BN27.tmp (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;braviax.exe (Trojan.FakeAlert) -&amp;gt; Delete on reboot.&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;Application Data&amp;#092;wiaserva.log (Malware.Trace) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;LocalService&amp;#092;oashdihasidhasuidhiasdhiashdiuasdhasd (Trace.Pandex) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;PYKONG&amp;#092;oashdihasidhasuidhiasdhiashdiuasdhasd (Trace.Pandex) -&amp;gt; Quarantined and deleted successfully.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks for reading and I hope someone might be able to help...</description>
            <author>NutterButters</author>
            <category>Technical Support</category>
            <pubDate>Sat, 15 Aug 2009 16:05:48 +0800</pubDate>
        </item>
        <item>
            <title>Celcom Broadband Question</title>
            <link>http://forum.lowyat.net/topic/928974</link>
            <description>Hi everyone...I just got Celcom Broadband, the D98 package...and I have some questions:&lt;br /&gt;&lt;br /&gt;1) Is there anyway to bypass the shared IP thing? (I&amp;#39;m a pretty heavy downloader, mostly from Rapidshare) Do programs like Hide My IP, etc etc... work? &lt;br /&gt;&lt;br /&gt;2) What happens if I go over the 5GB limit? Does Celcom charge me extra for it? &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks in advance&amp;#33;</description>
            <author>NutterButters</author>
            <category>Networks and Broadband</category>
            <pubDate>Sun, 08 Feb 2009 00:30:20 +0800</pubDate>
        </item>
        <item>
            <title>Question about Laptops...</title>
            <link>http://forum.lowyat.net/topic/711787</link>
            <description>Hi everyone...I was wondering if you can buy laptops at a cheaper price when you enter local uni? Is there a special student price or anything? &lt;br /&gt;&lt;br /&gt;Thanks for reading...any help is appreciated..</description>
            <author>NutterButters</author>
            <category>Education Essentials</category>
            <pubDate>Wed, 04 Jun 2008 16:23:45 +0800</pubDate>
        </item>
    </channel>
</rss>
