<?xml version="1.0" encoding="ISO-8859-1"?>
<!-- generator="FeedCreator 1.7.2" -->
<rss version="2.0">
    <channel>
        <title>Lowyat.NET: Latest topics by eggy</title>
        <description></description>
        <link>http://forum.lowyat.net/</link>
        <lastBuildDate>Wed, 25 Nov 2009 01:52:29 +0800</lastBuildDate>
        <generator>FeedCreator 1.7.2</generator>
        <item>
            <title>Position for Full Time and Part Time Jobs</title>
            <link>http://forum.lowyat.net/topic/927690</link>
            <description>Hello.&lt;br /&gt;&lt;br /&gt;I am helping a friend of mine who is looking for anyone that are currently looking for jobs.&lt;br /&gt;Both full time and part time jobs are available.&lt;br /&gt;Below are the details:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;1. Web Developer / Software Developer / Programmer / Analyst&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Requirements:&lt;/b&gt;&lt;ul&gt;&lt;li&gt;Candidate must possess at least a Diploma, Advanced/Higher/Graduate Diploma, Bachelor&amp;#39;s Degree, Post Graduate Diploma or Professional Degree in Computer Science/Information Technology, Art &amp;amp; Design, Advertising/Media, Architecture/Urban Studies or equivalent.&lt;/li&gt;&lt;li&gt;Required skill(s): HTML, PHP, SQL.&lt;/li&gt;&lt;li&gt;Applicants must be willing to work in Sunway.&lt;/li&gt;&lt;li&gt;Applicants should be Malaysian citizens or hold relevant residence status.&lt;/li&gt;&lt;li&gt;Preferably junior executives specializing in Computer Science, Software Engineering, Multimedia or equivalent.&lt;/li&gt;&lt;li&gt;Full-Time positions available.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;b&gt;2. Part Timer Data Entry&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Requirements:&lt;/b&gt;&lt;ul&gt;&lt;li&gt;Computer&lt;/li&gt;&lt;li&gt;Internet&lt;/li&gt;&lt;li&gt;IT Knowlegde&lt;/li&gt;&lt;li&gt;Computer Skills&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Please visit here for more details: &lt;a href='http://www.komunitikami.com' target='_blank'&gt;www.komunitikami.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Please do not PM me about this job.&lt;/b&gt;&lt;br /&gt;I am &lt;b&gt;NOT&lt;/b&gt; responsible in handling the candidate and stuff &lt;!--emo&amp;:)--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/smile.gif' border='0' style='vertical-align:middle' alt='smile.gif' /&gt;&lt;!--endemo--&gt;</description>
            <author>eggy</author>
            <category>Job Enlistments</category>
            <pubDate>Fri, 06 Feb 2009 18:43:18 +0800</pubDate>
        </item>
        <item>
            <title>Browsing Internet Problem</title>
            <link>http://forum.lowyat.net/topic/719896</link>
            <description>As stated, I am facing some problems when trying to browse the Internet using either Firefox or IE.&lt;br /&gt;BUT I managed to use my MSN and YM&amp;#33; without any problem.&lt;br /&gt;&lt;br /&gt;From the log, I suspected that these entries might be causing the problem:&lt;ul&gt;&lt;li&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [BM6216cd25] Rundll32.exe &amp;quot;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;mffixrdc.dll&amp;quot;,s&lt;/li&gt;&lt;li&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [6125feb9] rundll32.exe &amp;quot;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;evpdvyok.dll&amp;quot;,b&lt;/li&gt;&lt;/ul&gt;I tried to fix those entries BUT it will just come back after a while or when I restart my laptop.&lt;br /&gt;Any help would be much appreciated.&lt;br /&gt;Thank you in advance &lt;!--emo&amp;:respect:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/notworthy.gif' border='0' style='vertical-align:middle' alt='notworthy.gif' /&gt;&lt;!--endemo--&gt; &lt;br /&gt;&lt;br /&gt;&lt;!--QuoteBegin--&gt;&lt;div class='quotetop'&gt;QUOTE&lt;/div&gt;&lt;div class='quotemain'&gt;&lt;!--QuoteEBegin--&gt;Logfile of HijackThis v1.99.1&lt;br /&gt;Scan saved at 7:40:48 PM, on 6/15/2008&lt;br /&gt;Platform: Windows XP SP1 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;smss.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;winlogon.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;services.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;lsass.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;spoolsv.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Symantec Shared&amp;#092;ccEvtMgr.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Explorer.EXE&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;HPConfig.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;HPQ&amp;#092;Notebook Utilities&amp;#092;HPWirelessMgr.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Microsoft Shared&amp;#092;VS7Debug&amp;#092;mdm.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Norton AntiVirus&amp;#092;navapsvc.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;ntrtscan.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;tmlisten.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;OfcPfwSvc.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;pccntmon.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;ctfmon.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;palmOne&amp;#092;HOTSYNC.EXE&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;TEMP&amp;#092;MJB368.EXE&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;pccntupd.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;firefox.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;rundll32.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;rundll32.exe&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;Yahoo&amp;#33;&amp;#092;MESSEN~1&amp;#092;YAHOOM~1.EXE&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Internet Explorer&amp;#092;IEXPLORE.EXE&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;Windows XP&amp;#092;Desktop&amp;#092;cleaner&amp;#092;Hijack This&amp;#092;HijackThis.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;NOTEPAD.EXE&lt;br /&gt;&lt;br /&gt;R1 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Search Bar = &lt;a href='http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=iesearch&amp;c=3C01&amp;lc=6809' target='_blank'&gt;http://store.presario.net/scripts/redirect...&amp;c=3C01&amp;lc=6809&lt;/a&gt;&lt;br /&gt;R0 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Start Page = &lt;a href='http://www.yahoo.com/' target='_blank'&gt;http://www.yahoo.com/&lt;/a&gt;&lt;br /&gt;R1 - HKLM&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Default_Page_URL = &lt;a href='http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=iehomepage&amp;c=3C01&amp;lc=6809' target='_blank'&gt;http://store.presario.net/scripts/redirect...&amp;c=3C01&amp;lc=6809&lt;/a&gt;&lt;br /&gt;O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:&amp;#092;Program Files&amp;#092;Norton AntiVirus&amp;#092;NavShExt.dll&lt;br /&gt;O3 - Toolbar: (no name) - {8E718888-423F-11D2-876E-00A0C9082467} - (no file)&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [OfficeScanNT Monitor] &amp;quot;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;pccntmon.exe&amp;quot; -HideWindow&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [BM6216cd25] Rundll32.exe &amp;quot;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;mffixrdc.dll&amp;quot;,s&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [6125feb9] rundll32.exe &amp;quot;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;evpdvyok.dll&amp;quot;,b&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [ctfmon.exe] C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;ctfmon.exe&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [Yahoo&amp;#33; Pager] &amp;quot;C:&amp;#092;PROGRA~1&amp;#092;Yahoo&amp;#33;&amp;#092;MESSEN~1&amp;#092;YAHOOM~1.EXE&amp;quot; -quiet&lt;br /&gt;O4 - Startup: HotSync Manager.LNK = C:&amp;#092;Program Files&amp;#092;palmOne&amp;#092;HOTSYNC.EXE&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:&amp;#092;PROGRA~1&amp;#092;MICROS~2&amp;#092;Office10&amp;#092;EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: Yahoo&amp;#33; Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:&amp;#092;Program Files&amp;#092;Yahoo&amp;#33;&amp;#092;Common&amp;#092;yiesrvc.dll&lt;br /&gt;O12 - Plugin for .spop: C:&amp;#092;Program Files&amp;#092;Internet Explorer&amp;#092;Plugins&amp;#092;NPDocBox.dll&lt;br /&gt;O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=iehomepage&amp;amp;c=3C01&amp;amp;lc=5c09&lt;br /&gt;O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) - &lt;a href='https://jupiter.uitm.edu.my/officescan/console/ClientInstall/WinNTChk.cab' target='_blank'&gt;https://jupiter.uitm.edu.my/officescan/cons...ll/WinNTChk.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class) - &lt;a href='https://jupiter.uitm.edu.my/officescan/console/ClientInstall/setupini.cab' target='_blank'&gt;https://jupiter.uitm.edu.my/officescan/cons...ll/setupini.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - &lt;a href='https://jupiter.uitm.edu.my/officescan/console/ClientInstall/setup.cab' target='_blank'&gt;https://jupiter.uitm.edu.my/officescan/cons...stall/setup.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:&amp;#092;Program Files&amp;#092;Yahoo&amp;#33;&amp;#092;Common&amp;#092;Yinsthelper.dll&lt;br /&gt;O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} (Encrypt Class) - &lt;a href='https://jupiter.uitm.edu.my/officescan/console/html/AtxEnc.cab' target='_blank'&gt;https://jupiter.uitm.edu.my/officescan/cons...html/AtxEnc.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) - &lt;a href='https://jupiter.uitm.edu.my/officescan/console/ClientInstall/RemoveCtrl.cab' target='_blank'&gt;https://jupiter.uitm.edu.my/officescan/cons.../RemoveCtrl.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - &lt;a href='http://nyatoh.uitm.edu.my/dwa7W.cab' target='_blank'&gt;http://nyatoh.uitm.edu.my/dwa7W.cab&lt;/a&gt;&lt;br /&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Symantec Shared&amp;#092;ccEvtMgr.exe&lt;br /&gt;O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Unknown owner - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Symantec Shared&amp;#092;ccPwdSvc.exe&lt;br /&gt;O23 - Service: Command Service (cmdService) - Unknown owner - C:&amp;#092;WINDOWS&amp;#092;V2luZG93cyBYUA&amp;#092;command.exe (file missing)&lt;br /&gt;O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;HPConfig.exe&lt;br /&gt;O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:&amp;#092;Program Files&amp;#092;HPQ&amp;#092;Notebook Utilities&amp;#092;HPWirelessMgr.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;InstallShield&amp;#092;Driver&amp;#092;11&amp;#092;Intel 32&amp;#092;IDriverT.exe&lt;br /&gt;O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:&amp;#092;Program Files&amp;#092;Norton AntiVirus&amp;#092;navapsvc.exe&lt;br /&gt;O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;ntrtscan.exe&lt;br /&gt;O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;OfcPfwSvc.exe&lt;br /&gt;O23 - Service: Pml Driver HPZ12 - HP - C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;HPZipm12.exe&lt;br /&gt;O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:&amp;#092;PROGRA~1&amp;#092;COMMON~1&amp;#092;SYMANT~1&amp;#092;SCRIPT~1&amp;#092;SBServ.exe&lt;br /&gt;O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;tmlisten.exe&lt;!--QuoteEnd--&gt;&lt;/div&gt;&lt;!--QuoteEEnd--&gt;</description>
            <author>eggy</author>
            <category>Technical Support</category>
            <pubDate>Sun, 15 Jun 2008 20:00:35 +0800</pubDate>
        </item>
        <item>
            <title>PC Infected with Worm/Generic.FX</title>
            <link>http://forum.lowyat.net/topic/351316</link>
            <description>My friend PC has been infected with this Generic worm.&lt;br /&gt;AVG keeps on pop-ing up the warning message and he keeps on pressing the Heal button.&lt;br /&gt;BUT after few minutes AVG will warn again about the same virus which is very annoying&amp;#33;  &lt;!--emo&amp;:angry:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/mad.gif' border='0' style='vertical-align:middle' alt='mad.gif' /&gt;&lt;!--endemo--&gt; &lt;br /&gt;Here i attached some screen shots of the popup message.&lt;br /&gt;&lt;br /&gt;&lt;!--SPOILER BEGIN--&gt;&lt;div class=&quot;spoilertop&quot; onClick=&quot;openClose('bc7064166927bf0c5ef6986d63cfea9e')&quot; style=&quot;font-weight: bold&quot;&gt;&lt;u&gt;&amp;raquo; Click to show Spoiler - click again to hide... &amp;laquo;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;spoilermain&quot; id=&quot;bc7064166927bf0c5ef6986d63cfea9e&quot; style=&quot;display:none&quot;&gt;&lt;!--SPOILER END--&gt;[center]&lt;img src='http://img245.imageshack.us/img245/7852/winziptmpcz2.jpg' border='0' alt='user posted image' /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src='http://img378.imageshack.us/img378/3126/winzipquickih0.jpg' border='0' alt='user posted image' /&gt;[/center]&lt;br /&gt;&lt;!--SPOILER DIV--&gt;&lt;/div&gt;&lt;!--SPOILER DIV--&gt;&lt;br /&gt;&lt;br /&gt;This is my HijackThis log.&lt;br /&gt;&lt;!--SPOILER BEGIN--&gt;&lt;div class=&quot;spoilertop&quot; onClick=&quot;openClose('ec187aca58b920ec264e94703ae0fa7a')&quot; style=&quot;font-weight: bold&quot;&gt;&lt;u&gt;&amp;raquo; Click to show Spoiler - click again to hide... &amp;laquo;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;spoilermain&quot; id=&quot;ec187aca58b920ec264e94703ae0fa7a&quot; style=&quot;display:none&quot;&gt;&lt;!--SPOILER END--&gt;&lt;br /&gt;Logfile of HijackThis v1.99.1&lt;br /&gt;Scan saved at 11:19:17 AM, on 10/9/2006&lt;br /&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;smss.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;winlogon.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;services.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;lsass.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;spoolsv.exe&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVGFRE~1&amp;#092;avgamsvr.exe&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVGFRE~1&amp;#092;avgupsvc.exe&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVGFRE~1&amp;#092;avgemc.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;IVT Corporation&amp;#092;BlueSoleil&amp;#092;BTNtService.exe&lt;br /&gt;C:&amp;#092;iFtpSvc&amp;#092;iFtpSvc.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;inetsrv&amp;#092;inetinfo.exe&lt;br /&gt;C:&amp;#092;mySQL&amp;#092;bin&amp;#092;mysqld-nt.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;ntrtscan.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;tmlisten.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;OfcPfwSvc.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;TEMP&amp;#092;IC446C.EXE&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Explorer.EXE&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;pccntmon.exe&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVGFRE~1&amp;#092;avgcc.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;ctfmon.exe&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;MOZILL~1&amp;#092;FIREFOX.EXE&lt;br /&gt;C:&amp;#092;pwrs&amp;#092;PB6&amp;#092;pb60.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;ntvdm.exe&lt;br /&gt;D:&amp;#092;My Download&amp;#092;HijackThis.exe&lt;br /&gt;&lt;br /&gt;R0 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Start Page = &lt;a href='http://delima/' target='_blank'&gt;http://delima/&lt;/a&gt;&lt;br /&gt;R1 - HKLM&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Default_Page_URL = &lt;a href='http://delima' target='_blank'&gt;http://delima&lt;/a&gt;&lt;br /&gt;R1 - HKLM&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Search Bar = &lt;a href='http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html' target='_blank'&gt;http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html&lt;/a&gt;&lt;br /&gt;R0 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Local Page = &lt;br /&gt;R1 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Window Title = Microsoft Internet Explorer provided by Seksyen Teknologi Maklumat UHB&lt;br /&gt;R1 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Internet Settings,ProxyServer = yakut.udanet.com:8080&lt;br /&gt;R1 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Internet Settings,ProxyOverride = *.udanet.com;http://delima;&amp;lt;local&amp;gt;&lt;br /&gt;O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Acrobat 7.0&amp;#092;ActiveX&amp;#092;AcroIEHelper.dll&lt;br /&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:&amp;#092;Program Files&amp;#092;Java&amp;#092;jre1.5.0_06&amp;#092;bin&amp;#092;ssv.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:&amp;#092;program files&amp;#092;google&amp;#092;googletoolbar2.dll&lt;br /&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:&amp;#092;program files&amp;#092;google&amp;#092;googletoolbar2.dll&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [OfficeScanNT Monitor] &amp;quot;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;pccntmon.exe&amp;quot; -HideWindow&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [AVG7_CC] C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVGFRE~1&amp;#092;avgcc.exe /STARTUP&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [QuickTime Task] &amp;quot;C:&amp;#092;Program Files&amp;#092;QuickTime&amp;#092;qttask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [MSMSGS] &amp;quot;C:&amp;#092;Program Files&amp;#092;Messenger&amp;#092;msmsgs.exe&amp;quot; /background&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [ctfmon.exe] C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;ctfmon.exe&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:&amp;#092;PROGRA~1&amp;#092;MICROS~2&amp;#092;OFFICE11&amp;#092;EXCEL.EXE/3000&lt;br /&gt;O8 - Extra context menu item: Sothink SWF Catcher - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;SourceTec&amp;#092;SWF Catcher&amp;#092;InternetExplorer.htm&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&amp;#092;Program Files&amp;#092;Java&amp;#092;jre1.5.0_06&amp;#092;bin&amp;#092;ssv.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&amp;#092;Program Files&amp;#092;Java&amp;#092;jre1.5.0_06&amp;#092;bin&amp;#092;ssv.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&amp;#092;PROGRA~1&amp;#092;MICROS~2&amp;#092;OFFICE11&amp;#092;REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;SourceTec&amp;#092;SWF Catcher&amp;#092;InternetExplorer.htm&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;SourceTec&amp;#092;SWF Catcher&amp;#092;InternetExplorer.htm&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&amp;#092;Program Files&amp;#092;Messenger&amp;#092;msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&amp;#092;Program Files&amp;#092;Messenger&amp;#092;msmsgs.exe&lt;br /&gt;O14 - IERESET.INF: START_PAGE_URL=http://delima&lt;br /&gt;O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - &lt;a href='http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab' target='_blank'&gt;http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab&lt;/a&gt;&lt;br /&gt;O17 - HKLM&amp;#092;System&amp;#092;CCS&amp;#092;Services&amp;#092;Tcpip&amp;#092;Parameters: Domain = udanet.com&lt;br /&gt;O17 - HKLM&amp;#092;Software&amp;#092;..&amp;#092;Telephony: DomainName = udanet.com&lt;br /&gt;O17 - HKLM&amp;#092;System&amp;#092;CCS&amp;#092;Services&amp;#092;Tcpip&amp;#092;..&amp;#092;{52389EDB-59BE-41F6-A7D1-0DEE0AC31876}: NameServer = 172.16.1.15,172.16.1.20&lt;br /&gt;O17 - HKLM&amp;#092;System&amp;#092;CS1&amp;#092;Services&amp;#092;Tcpip&amp;#092;Parameters: Domain = udanet.com&lt;br /&gt;O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;WPDShServiceObj.dll&lt;br /&gt;O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVGFRE~1&amp;#092;avgamsvr.exe&lt;br /&gt;O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVGFRE~1&amp;#092;avgupsvc.exe&lt;br /&gt;O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVGFRE~1&amp;#092;avgemc.exe&lt;br /&gt;O23 - Service: BlueSoleil Hid Service - Unknown owner - C:&amp;#092;Program Files&amp;#092;IVT Corporation&amp;#092;BlueSoleil&amp;#092;BTNtService.exe&lt;br /&gt;O23 - Service: Ipswitch WS_FTP Server (iFtpSvc) - Ipswitch, Inc.  10 Maguire Road - Suite 220 Lexington MA. - C:&amp;#092;iFtpSvc&amp;#092;iFtpSvc.exe&lt;br /&gt;O23 - Service: MySQL - Unknown owner - C:&amp;#092;mySQL&amp;#092;bin&amp;#092;mysqld-nt.exe&lt;br /&gt;O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;ntrtscan.exe&lt;br /&gt;O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;OfcPfwSvc.exe&lt;br /&gt;O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;OfficeScan Client&amp;#092;tmlisten.exe&lt;br /&gt;&lt;!--SPOILER DIV--&gt;&lt;/div&gt;&lt;!--SPOILER DIV--&gt;&lt;br /&gt;</description>
            <author>eggy</author>
            <category>Technical Support</category>
            <pubDate>Mon, 09 Oct 2006 11:20:38 +0800</pubDate>
        </item>
        <item>
            <title>Problem Starting Windows 2000</title>
            <link>http://forum.lowyat.net/topic/325173</link>
            <description>My friends already format the PC few times and the PC just wont start.&lt;br /&gt;It keeps restarting when loading the Windows during the &lt;b&gt;Starting Windows... &lt;/b&gt;message.&lt;br /&gt;Already tried in Safe Mode, Last Good Configuration but the problem still the same.&lt;br /&gt;Already changed the RAMs, GC and Sound Card.</description>
            <author>eggy</author>
            <category>Technical Support</category>
            <pubDate>Thu, 10 Aug 2006 14:53:33 +0800</pubDate>
        </item>
        <item>
            <title>W32.Rontokbro Worm</title>
            <link>http://forum.lowyat.net/topic/265366</link>
            <description>Here are two tools that might help you in cleanning and removing the worm.&lt;br /&gt;All credit goes to sUBs. &lt;!--emo&amp;:)--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/smile.gif' border='0' style='vertical-align:middle' alt='smile.gif' /&gt;&lt;!--endemo--&gt; &lt;br /&gt;&lt;br /&gt;Newer and updated version of &lt;a href='http://download.bleepingcomputer.com/sUBs/CleanX-II.exe' target='_blank'&gt;CleanX-II&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!--QuoteBegin-sUBs+Apr 2 2006, 07:31 AM--&gt;&lt;div class='quotetop'&gt;QUOTE(sUBs &amp;#064; Apr 2 2006, 07:31 AM)&lt;/div&gt;&lt;div class='quotemain'&gt;&lt;!--QuoteEBegin--&gt;&lt;span style='color:quot'&gt;As promised earlier, here&amp;#39;s the removal tool for Brontok. It&amp;#39;s usage is pretty straightforward. Please take note of the following points. &lt;ul&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt; Download the attachment I placed with this post - &lt;a href='http://forum.lowyat.net/index.php?act=Attach&amp;type=post&amp;id=102842' target='_blank'&gt;CleanX&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt; Save it on Desktop.&lt;br /&gt;&lt;/li&gt;&lt;li&gt; Disconnect/unplug the computer from the internet.&lt;br /&gt;&lt;/li&gt;&lt;li&gt; Save any work which you&amp;#39;re doing &amp;amp; &lt;b&gt;close all other programs&lt;/b&gt;. &lt;br /&gt;&lt;/li&gt;&lt;li&gt; &lt;b&gt;If Brontok hasn&amp;#39;t totally disabled your security programs yet, kindly disable them now&lt;/b&gt;. They might intefere with the tool&amp;#39;s working. &lt;br /&gt;&lt;/li&gt;&lt;li&gt; For Window&amp;#39;s XP, please create a new system restore point. &lt;ul&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt; Go to Start &amp;gt;&amp;gt; Run - type &lt;b&gt;control sysdm.cpl,,4&lt;/b&gt; &amp;amp; press Enter &lt;ul&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt; Tick on the checkbox - &lt;b&gt;Turn off System Restore on all drives&lt;/b&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt; Click Apply&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&amp;nbsp; &lt;br /&gt;&lt;/li&gt;&lt;li&gt; Turn it back &amp;#39;On&amp;#39; by unticking the same checkbox &amp;amp; click OK&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt; Once you have done that, double-click on the file you downloaded &amp;amp; double click the executable within - &lt;b&gt;CleanX.exe&lt;/b&gt; (It doesn&amp;#39;t require to be run in Safe Mode)&lt;br /&gt;&lt;/li&gt;&lt;li&gt; You should be greeted by the following message (refer to pic below)&lt;br /&gt;&lt;img src='http://img.photobucket.com/albums/v666/sUBs/c1fd31cb.gif' border='0' alt='user posted image' /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt; Read the message carefully before clicking OK&lt;br /&gt;&lt;/li&gt;&lt;li&gt; The tool will begin scanning your machine. Because this worm names it&amp;#39;s files randomly, I have to place a series of cross-checks/verification processes to ensure that the tool does not remove legitimate files. Depending on the size of your drives, this scan may take several minutes. Please be patient during this period &amp;amp; allow it to complete it&amp;#39;s task.&amp;nbsp;  &lt;br /&gt;&lt;/li&gt;&lt;li&gt; Once it has finished scanning, it will provide a post mortem of it&amp;#39;s actions. This is in the form of a log file&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt; &lt;br /&gt;&lt;!--SPOILER BEGIN--&gt;&lt;div class=&quot;spoilertop&quot; onClick=&quot;openClose('94b304d1e3cc6f4755ba47aee0970b06')&quot; style=&quot;font-weight: bold&quot;&gt;&lt;u&gt;&amp;raquo; Click to show Spoiler - click again to hide... &amp;laquo;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;spoilermain&quot; id=&quot;94b304d1e3cc6f4755ba47aee0970b06&quot; style=&quot;display:none&quot;&gt;&lt;!--SPOILER END--&gt;&lt;span style='color:quot'&gt;&amp;nbsp; ::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;  &lt;span style='color:BLUE'&gt;&lt;b&gt; Brontok Worm Removal Tool - (Version - 6.03.29) &lt;/b&gt;&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style='color:quot'&gt;::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;/span&gt;&lt;br /&gt;=== &lt;b&gt;PRE RUN ANALYSIS&lt;/b&gt; ==================================&lt;br /&gt;&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;j6235022.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;o4235027.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;_default23502.pif&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Ad22098&amp;#092;qm10563.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;c_23502k.com&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;csrss.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;lsass.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;m10563.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;services.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;smss.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;winlogon.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;zh592115084y.exe&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;Administrator&amp;#092;Local Settings&amp;#092;Application Data&amp;#092;jalak-932115015-bali.com&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;Administrator&amp;#092;Local Settings&amp;#092;Application Data&amp;#092;dv6211500x&amp;#092;yesbron.com&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;c.bron.tok.txt&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;domlist.txt&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Sent.Bro&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;svt22sj.tok&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;zh592115084y.exeupi22xbm.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;#092;ajohnson@rpi.net.au.ini.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;#092;aka@mvps.org.ini.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;#092;a.kadrichu@intelsat.int.ini.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;#092;arrow.comp@xtzyra.co.nz.ini.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;#092;arrow.comp@xtzyra.co.nz.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;#092;artech@qaos.com.ini.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;#092;baldji@mail.bg.ini.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;#092;calypso@fly.srk.fer.hr.ini.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;#092;choung@a.websponsors.ini.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;#092;fatmir.raka@coatings.basf.org.ini.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;#092;frank.de.kort@home.nl.ini.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;#092;gazumba@ig.com.br.ini.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;Spread.Mail.Bro&amp;#092;gglbp@21cn.com.ini.ini&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;Tasks&amp;#092;At1.job&amp;quot;&lt;br /&gt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;Tasks&amp;#092;At2.job&amp;quot;&lt;br /&gt;=== &lt;b&gt;POST RUN ANALYSIS&lt;/b&gt; ================================== &lt;br /&gt;&amp;nbsp;  &lt;br /&gt;&amp;nbsp;  &lt;span style='color:blue'&gt;NOTE&amp;nbsp; &lt;br /&gt;&amp;nbsp;  This portion should be empty. If it&amp;#39;s not, try running the tool a second time. &lt;br /&gt;&lt;br /&gt;&amp;nbsp;  this report is located at C:&amp;#092;REPORT.TXT&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;===================================================&lt;!--SPOILER DIV--&gt;&lt;/div&gt;&lt;!--SPOILER DIV--&gt;&lt;br /&gt;&lt;span style='color:quot'&gt;This is a sample of what the logfile would look like. It&amp;#39;s made up of 2 parts - &lt;b&gt;BEFORE / AFTER.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;In the lower portion,&amp;nbsp; POST RUN ANALYSIS, make sure that no files appear there. &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;If it looks something like below you will need to run the tool a 2nd time. &lt;/span&gt;&lt;br /&gt;&lt;!--SPOILER BEGIN--&gt;&lt;div class=&quot;spoilertop&quot; onClick=&quot;openClose('f546715840d117cfb65bce627f4071aa')&quot; style=&quot;font-weight: bold&quot;&gt;&lt;u&gt;&amp;raquo; Click to show Spoiler - click again to hide... &amp;laquo;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;spoilermain&quot; id=&quot;f546715840d117cfb65bce627f4071aa&quot; style=&quot;display:none&quot;&gt;&lt;!--SPOILER END--&gt;&lt;br /&gt;=== &lt;b&gt;POST RUN ANALYSIS&lt;/b&gt; ==================================&lt;br /&gt;&lt;br /&gt;&lt;span style='color:purple'&gt;C:&amp;#092;WINDOWS&amp;#092;j6235022.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;o4235027.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;csrss.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;lsass.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;s8787&amp;#092;m10563.exe&lt;/span&gt;&lt;!--SPOILER DIV--&gt;&lt;/div&gt;&lt;!--SPOILER DIV--&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style='color:quot'&gt;If the files remain after a 2nd run, there&amp;#39;s no need to run it a 3rd time. We&amp;#39;re probably dealing with a variant of Brontok that I didn&amp;#39;t have a sample of. In such circumstances, I will require a sample file from the afflicted machine for reseach.&lt;/span&gt;&lt;br /&gt;&lt;u&gt;Note: &lt;/u&gt;&lt;br /&gt;It has been brought to my attention that some people may experience an error message like the one below. If that happens to you, you shall need to visit this website to download additional files &amp;gt; &lt;a href='http://www.tech-forums.net/computer/topic/29806.html' target='_blank'&gt;http://www.tech-forums.net/computer/topic/29806.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src='http://img.photobucket.com/albums/v666/sUBs/autoexec.gif' border='0' alt='user posted image' /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style='color:RED'&gt;Edit: Updated to ver 6.04.02&lt;br /&gt;Edit: Ver 6.04.03 - discovered a scripting error which caused the removal engine to fail. &lt;br /&gt;Edit: Ver 6.04.04. - This version scans faster &amp;amp; does a better job removing all the files in one go. Does away with the need to reboot. &lt;br /&gt;Edit: Ver 6.04.09 - Updated with more viral signatures &amp;amp; added heuristic scanning to the tool. This ensures that it detects a wider range of Brontok variants. Unless it&amp;#39;s creator decides to do a major overhaul of the worm, this tool should disinfect almost all Brontok cases. &lt;br /&gt;Edit: Ver 6.04.11 - Improved heuristics. Less leftover files. Also fixed some bugs&lt;/span&gt;&lt;br /&gt;[right][snapback]6577860[/snapback][/right]&lt;br /&gt;&lt;!--QuoteEnd--&gt;&lt;/div&gt;&lt;!--QuoteEEnd--&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!--QuoteBegin-sUBs+Jun 8 2006, 01:22 AM--&gt;&lt;div class='quotetop'&gt;QUOTE(sUBs &amp;#064; Jun 8 2006, 01:22 AM)&lt;/div&gt;&lt;div class='quotemain'&gt;&lt;!--QuoteEBegin--&gt;Download this... It works &amp;#33;&amp;#33;&lt;br /&gt;&lt;br /&gt;* Download &lt;b&gt;Dr.Web CureIt&lt;/b&gt; to the desktop:&lt;br /&gt;&lt;a href='ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe' target='_blank'&gt;ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe&lt;/a&gt;&lt;ul&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Doubleclick the &lt;b&gt;drweb-cureit.exe&lt;/b&gt; file and Allow to run the express scan&lt;br /&gt;&lt;/li&gt;&lt;li&gt;This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Once the short scan has finished, mark the drives that you want to scan.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Select all drives. A red dot shows which drives have been chosen.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Click the &lt;b&gt;green arrow&lt;/b&gt; at the right, and the scan will start.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Click &amp;#39;Yes to all&amp;#39; if it asks if you want to cure/move the file.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;When the scan has finished, look if you can click next icon next to the files found: &lt;img src='http://users.telenet.be/bluepatchy/miekiemoes/images/check.gif' border='0' alt='user posted image' /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;If so, click it and then click the next icon right below and select &lt;b&gt;Move incurable&lt;/b&gt; as you&amp;#39;ll see in next image:&lt;br /&gt;&lt;img src='http://users.telenet.be/bluepatchy/miekiemoes/images/move.gif' border='0' alt='user posted image' /&gt;&lt;br /&gt;This will move it to the %userprofile%&amp;#092;DoctorWeb&amp;#092;quarantaine-folder if it can&amp;#39;t be cured. &lt;br /&gt;&lt;/li&gt;&lt;li&gt;After selecting, in the Dr.Web CureIt menu on top, click &lt;b&gt;file&lt;/b&gt; and choose &lt;b&gt;save report list&lt;/b&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Save the report to your desktop. The report will be called &lt;b&gt;DrWeb.csv&lt;/b&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Close Dr.Web Cureit.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Reboot&lt;/b&gt; your computer&amp;#33;&amp;#33; Because it could be possible that files in use will be moved/deleted during reboot.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;[right][snapback]7376888[/snapback][/right]&lt;br /&gt;&lt;!--QuoteEnd--&gt;&lt;/div&gt;&lt;!--QuoteEEnd--&gt;</description>
            <author>eggy</author>
            <category>Technical Support</category>
            <pubDate>Sun, 19 Mar 2006 10:07:20 +0800</pubDate>
        </item>
        <item>
            <title>VB 6</title>
            <link>http://forum.lowyat.net/topic/259683</link>
            <description>err..&lt;br /&gt;how to show my answer on 2 decimal points?  &lt;!--emo&amp;:unsure:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/unsure.gif' border='0' style='vertical-align:middle' alt='unsure.gif' /&gt;&lt;!--endemo--&gt; &lt;br /&gt;&lt;br /&gt;eg. &lt;br /&gt;if the answer is 2.31213445 i want it to print out 2.31 only..&lt;br /&gt;&lt;br /&gt;thnx in advance  &lt;!--emo&amp;:thumbs:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/thumbup.gif' border='0' style='vertical-align:middle' alt='thumbup.gif' /&gt;&lt;!--endemo--&gt;</description>
            <author>eggy</author>
            <category>Codemasters</category>
            <pubDate>Mon, 06 Mar 2006 10:37:11 +0800</pubDate>
        </item>
        <item>
            <title>VB6 Chat Program</title>
            <link>http://forum.lowyat.net/topic/252242</link>
            <description>im doin a vb6 program and need some example with it..&lt;br /&gt;anyone know which site i should go?&lt;br /&gt;thanx  &lt;!--emo&amp;:)--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/smile.gif' border='0' style='vertical-align:middle' alt='smile.gif' /&gt;&lt;!--endemo--&gt;</description>
            <author>eggy</author>
            <category>Codemasters</category>
            <pubDate>Thu, 16 Feb 2006 15:12:39 +0800</pubDate>
        </item>
    </channel>
</rss>
