<?xml version="1.0" encoding="ISO-8859-1"?>
<!-- generator="FeedCreator 1.7.2" -->
<rss version="2.0">
    <channel>
        <title>Lowyat.NET: Latest topics by mryellow19</title>
        <description></description>
        <link>http://forum.lowyat.net/</link>
        <lastBuildDate>Wed, 25 Nov 2009 03:00:26 +0800</lastBuildDate>
        <generator>FeedCreator 1.7.2</generator>
        <item>
            <title>need help here to clean the log....</title>
            <link>http://forum.lowyat.net/topic/467134</link>
            <description>yesterday as i transfer the log from my frens brontok infected com to my desktop to post here...the thumb drive tat got infected actually infected my com too...then i ran system restore to the day b4...so it was fine..but then my com is acting very weird...when i start my com and when it reaches the loading screen..the BSOD will appear and it will restart all over again...i cant see BSOD coz it dissapear too fast..wat i did was start in safe mode but it will hang..then press the restart button then run windows normally..then only can log in to window...after logging in...a few minutes after tat my audio driver will be missing and my desktop theme will change to windows classic theme...when i wan to change back to xp theme it is missing..&lt;br /&gt;&lt;br /&gt;below is the logs...&lt;br /&gt;&lt;br /&gt;HJT log&lt;br /&gt;&lt;!--SPOILER BEGIN--&gt;&lt;div class=&quot;spoilertop&quot; onClick=&quot;openClose('58b802a51c35324028e154e3839d69c6')&quot; style=&quot;font-weight: bold&quot;&gt;&lt;u&gt;&amp;raquo; Click to show Spoiler - click again to hide... &amp;laquo;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;spoilermain&quot; id=&quot;58b802a51c35324028e154e3839d69c6&quot; style=&quot;display:none&quot;&gt;&lt;!--SPOILER END--&gt;Logfile of HijackThis v1.99.1&lt;br /&gt;Scan saved at 9:40:54 PM, on 6/3/2007&lt;br /&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;System32&amp;#092;smss.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;winlogon.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;services.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;lsass.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;spoolsv.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;Explorer.EXE&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;SOUNDMAN.EXE&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;TEXTBR~1.0&amp;#092;Bin&amp;#092;INSTAN~1.EXE&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Winamp&amp;#092;winampa.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Real&amp;#092;Update_OB&amp;#092;realsched.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;AOL&amp;#092;Active Virus Shield&amp;#092;avp.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;ctfmon.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Ahead&amp;#092;lib&amp;#092;NMBgMonitor.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;AOL&amp;#092;Active Virus Shield&amp;#092;avp.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;TextBridge Pro 8.0&amp;#092;Ereg&amp;#092;REMIND32.EXE&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;wscntfy.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;MSN Messenger&amp;#092;usnsvc.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Hijackthis&amp;#092;HijackThis.exe&lt;br /&gt;&lt;br /&gt;R0 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Start Page = &lt;a href='http://www.yahoo.com/' target='_blank'&gt;http://www.yahoo.com/&lt;/a&gt;&lt;br /&gt;O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Acrobat 7.0&amp;#092;ActiveX&amp;#092;AcroIEHelper.dll&lt;br /&gt;O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:&amp;#092;Program Files&amp;#092;BitComet&amp;#092;tools&amp;#092;BitCometBHO_1.1.3.28.dll&lt;br /&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Microsoft Shared&amp;#092;Windows Live&amp;#092;WindowsLiveLogin.dll&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [IMJPMIG8.1] &amp;quot;C:&amp;#092;WINDOWS1&amp;#092;IME&amp;#092;imjp8_1&amp;#092;IMJPMIG.EXE&amp;quot; /Spoil /RemAdvDef /Migration32&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [PHIME2002ASync] C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;IME&amp;#092;TINTLGNT&amp;#092;TINTSETP.EXE /SYNC&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [PHIME2002A] C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;IME&amp;#092;TINTLGNT&amp;#092;TINTSETP.EXE /IMEName&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [SoundMan] SOUNDMAN.EXE&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [InstantAccess] C:&amp;#092;PROGRA~1&amp;#092;TEXTBR~1.0&amp;#092;Bin&amp;#092;INSTAN~1.EXE /h&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [RegisterDropHandler] C:&amp;#092;PROGRA~1&amp;#092;TEXTBR~1.0&amp;#092;Bin&amp;#092;REGIST~1.EXE&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [NeroFilterCheck] C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;NeroCheck.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [WinampAgent] C:&amp;#092;Program Files&amp;#092;Winamp&amp;#092;winampa.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [TkBellExe] &amp;quot;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Real&amp;#092;Update_OB&amp;#092;realsched.exe&amp;quot;  -osboot&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [aol] &amp;quot;C:&amp;#092;Program Files&amp;#092;AOL&amp;#092;Active Virus Shield&amp;#092;avp.exe&amp;quot;&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;RunServices: [RegisterDropHandler] C:&amp;#092;PROGRA~1&amp;#092;TEXTBR~1.0&amp;#092;Bin&amp;#092;REGIST~1.EXE&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [CTFMON.EXE] C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;ctfmon.exe&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &amp;quot;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Ahead&amp;#092;lib&amp;#092;NMBgMonitor.exe&amp;quot;&lt;br /&gt;O4 - Startup: reminder-ScanSoft Product Registration.lnk = C:&amp;#092;Program Files&amp;#092;TextBridge Pro 8.0&amp;#092;Ereg&amp;#092;REMIND32.EXE&lt;br /&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Acrobat 7.0&amp;#092;Reader&amp;#092;reader_sl.exe&lt;br /&gt;O8 - Extra context menu item: &amp;amp;D&amp;amp;ownload &amp;amp;with BitComet - res://C:&amp;#092;Program Files&amp;#092;BitComet&amp;#092;BitComet.exe/AddLink.htm&lt;br /&gt;O8 - Extra context menu item: &amp;amp;D&amp;amp;ownload all video with BitComet - res://C:&amp;#092;Program Files&amp;#092;BitComet&amp;#092;BitComet.exe/AddVideo.htm&lt;br /&gt;O8 - Extra context menu item: &amp;amp;D&amp;amp;ownload all with BitComet - res://C:&amp;#092;Program Files&amp;#092;BitComet&amp;#092;BitComet.exe/AddAllLink.htm&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&amp;#092;PROGRA~1&amp;#092;MICROS~2&amp;#092;OFFICE11&amp;#092;REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:&amp;#092;Documents and Settings&amp;#092;Calvin.CALVIN-F5560AEC&amp;#092;Start Menu&amp;#092;Programs&amp;#092;IMVU&amp;#092;Run IMVU.lnk&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%&amp;#092;Network Diagnostic&amp;#092;xpnetdiag.exe (file missing)&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%&amp;#092;Network Diagnostic&amp;#092;xpnetdiag.exe (file missing)&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&amp;#092;Program Files&amp;#092;Messenger&amp;#092;msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&amp;#092;Program Files&amp;#092;Messenger&amp;#092;msmsgs.exe&lt;br /&gt;O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - &lt;a href='http://www.e-games.com.my/com/EGamesPlugin.cab' target='_blank'&gt;http://www.e-games.com.my/com/EGamesPlugin.cab&lt;/a&gt;&lt;br /&gt;O17 - HKLM&amp;#092;System&amp;#092;CCS&amp;#092;Services&amp;#092;Tcpip&amp;#092;..&amp;#092;{E2551C3D-960A-4364-BFD0-7B813A026A61}: NameServer = 202.188.0.133 202.188.1.5&lt;br /&gt;O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:&amp;#092;PROGRA~1&amp;#092;MSNMES~1&amp;#092;MSGRAP~1.DLL&lt;br /&gt;O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:&amp;#092;PROGRA~1&amp;#092;MSNMES~1&amp;#092;MSGRAP~1.DLL&lt;br /&gt;O20 - Winlogon Notify: klogon - C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;klogon.dll&lt;br /&gt;O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:&amp;#092;Program Files&amp;#092;Ares&amp;#092;chatServer.exe&lt;br /&gt;O23 - Service: Active Virus Shield (AVP) - Unknown owner - C:&amp;#092;Program Files&amp;#092;AOL&amp;#092;Active Virus Shield&amp;#092;avp.exe&amp;quot; -r (file missing)&lt;br /&gt;&lt;br /&gt;&lt;!--SPOILER DIV--&gt;&lt;/div&gt;&lt;!--SPOILER DIV--&gt;&lt;br /&gt;&lt;br /&gt;and the combo fix log&lt;br /&gt;&lt;!--SPOILER BEGIN--&gt;&lt;div class=&quot;spoilertop&quot; onClick=&quot;openClose('de8dbd0dc3dacd65b15466b2157f20d3')&quot; style=&quot;font-weight: bold&quot;&gt;&lt;u&gt;&amp;raquo; Click to show Spoiler - click again to hide... &amp;laquo;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;spoilermain&quot; id=&quot;de8dbd0dc3dacd65b15466b2157f20d3&quot; style=&quot;display:none&quot;&gt;&lt;!--SPOILER END--&gt;&amp;quot;Calvin&amp;quot; - 2007-06-03 21:41:38    Service Pack 2  &lt;br /&gt;ComboFix 07-05.21.6.V - Running from: &amp;quot;C:&amp;#092;Documents and Settings&amp;#092;Calvin.CALVIN-F5560AEC&amp;#092;Desktop&amp;#092;&amp;quot;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;(((((((((((((((((((((((((((((((   Files Created from 2007-05-03 to 2007-06-03  ))))))))))))))))))))))))))))))))))&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2007-06-02 21:36	6,688	--ahs----	C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;drivers&amp;#092;fidbox2.dat&lt;br /&gt;2007-06-02 21:36	2,354,720	--ahs----	C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;drivers&amp;#092;fidbox.dat&lt;br /&gt;2007-06-02 21:36	&amp;lt;DIR&amp;gt;	d--------	C:&amp;#092;DOCUME~1&amp;#092;ALLUSE~1.WIN&amp;#092;APPLIC~1&amp;#092;AOL&lt;br /&gt;2007-06-01 21:21	3,031,040	--a------	C:&amp;#092;DOCUME~1&amp;#092;CALVIN~1.CAL&amp;#092;ntuser.dat&lt;br /&gt;2007-05-22 00:02	49,152	--a------	C:&amp;#092;WINDOWS1&amp;#092;nircmd.exe&lt;br /&gt;2007-05-12 21:48	&amp;lt;DIR&amp;gt;	d--------	C:&amp;#092;WINDOWS1&amp;#092;pss&lt;br /&gt;2007-05-10 00:19	&amp;lt;DIR&amp;gt;	d--------	C:&amp;#092;DOCUME~1&amp;#092;CALVIN~1.CAL&amp;#092;APPLIC~1&amp;#092;AdobeUM&lt;br /&gt;2007-05-08 18:37	&amp;lt;DIR&amp;gt;	d--------	C:&amp;#092;Program Files&amp;#092;Xinox Software&lt;br /&gt;2007-05-08 18:37	&amp;lt;DIR&amp;gt;	d--------	C:&amp;#092;DOCUME~1&amp;#092;CALVIN~1.CAL&amp;#092;APPLIC~1&amp;#092;Help&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;((((((((((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br /&gt;&lt;br /&gt;2007-05-16 09:56:16	--------	d-----w	C:&amp;#092;DOCUME~1&amp;#092;CALVIN~1.CAL&amp;#092;APPLIC~1&amp;#092;Real&lt;br /&gt;2007-05-15 13:25:13	--------	d-----w	C:&amp;#092;DOCUME~1&amp;#092;CALVIN~1.CAL&amp;#092;APPLIC~1&amp;#092;Ahead&lt;br /&gt;2007-05-05 15:41:02	--------	d-----w	C:&amp;#092;DOCUME~1&amp;#092;CALVIN~1.CAL&amp;#092;APPLIC~1&amp;#092;IMVU&lt;br /&gt;2007-05-01 10:38:01	--------	d-----w	C:&amp;#092;Program Files&amp;#092;MSECache&lt;br /&gt;2007-04-27 11:55:41	--------	d-----w	C:&amp;#092;Program Files&amp;#092;e-Games&lt;br /&gt;2007-04-27 11:55:40	--------	d--h--w	C:&amp;#092;Program Files&amp;#092;InstallShield Installation Information&lt;br /&gt;2007-04-27 10:25:25	--------	d-----w	C:&amp;#092;DOCUME~1&amp;#092;CALVIN~1.CAL&amp;#092;APPLIC~1&amp;#092;Media Player Classic&lt;br /&gt;2007-04-26 16:22:09	--------	d-----w	C:&amp;#092;Program Files&amp;#092;IMVU&lt;br /&gt;2007-04-25 14:51:37	--------	d-----w	C:&amp;#092;Program Files&amp;#092;9you&lt;br /&gt;2007-04-25 14:36:44	--------	d-----w	C:&amp;#092;Program Files&amp;#092;BitComet&lt;br /&gt;2007-04-25 14:34:15	2,560	----a-w	C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;BitCometRes.dll&lt;br /&gt;2007-04-25 14:20:40	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;xing shared&lt;br /&gt;2007-04-25 14:20:37	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Real&lt;br /&gt;2007-04-25 14:20:15	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Real&lt;br /&gt;2007-04-25 14:18:50	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Ares&lt;br /&gt;2007-04-25 14:16:59	499,712	----a-w	C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;msvcp71.dll&lt;br /&gt;2007-04-25 14:14:21	--------	d-----w	C:&amp;#092;Program Files&amp;#092;MSN Messenger&lt;br /&gt;2007-04-25 14:13:18	--------	d-----w	C:&amp;#092;Program Files&amp;#092;K-Lite Codec Pack&lt;br /&gt;2007-04-25 14:11:23	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Winamp&lt;br /&gt;2007-04-25 14:02:02	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Ahead&lt;br /&gt;2007-04-25 14:02:01	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Nero&lt;br /&gt;2007-04-25 13:33:02	--------	d-----w	C:&amp;#092;Program Files&amp;#092;MGI&lt;br /&gt;2007-04-25 13:31:31	--------	d-----w	C:&amp;#092;Program Files&amp;#092;TextBridge Pro 8.0&lt;br /&gt;2007-04-25 13:15:54	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Realtek Sound Manager&lt;br /&gt;2007-04-25 13:15:54	--------	d-----w	C:&amp;#092;Program Files&amp;#092;AvRack&lt;br /&gt;2007-04-25 13:15:44	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Realtek AC97&lt;br /&gt;2007-04-25 03:29:17	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Windows Media Connect 2&lt;br /&gt;2007-04-25 03:09:11	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Movie Maker&lt;br /&gt;2007-04-25 03:08:09	21,640	----a-w	C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;emptyregdb.dat&lt;br /&gt;2007-04-25 03:07:35	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Online Services&lt;br /&gt;2007-04-25 03:06:52	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Messenger&lt;br /&gt;2007-04-25 03:06:38	--------	d-----w	C:&amp;#092;Program Files&amp;#092;Windows NT&lt;br /&gt;2007-04-24 04:27:35	--------	d-----w	C:&amp;#092;Program Files&amp;#092;VIA&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;((((((((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))&lt;br /&gt; &lt;br /&gt; &lt;br /&gt;*Note* empty entries &amp;amp; legit default entries are not shown &lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Explorer&amp;#092;Browser Helper Objects]&lt;br /&gt;{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Acrobat 7.0&amp;#092;ActiveX&amp;#092;AcroIEHelper.dll [2004-12-14 01:56]&lt;br /&gt;{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}=C:&amp;#092;Program Files&amp;#092;BitComet&amp;#092;tools&amp;#092;BitCometBHO_1.1.3.28.dll [2007-03-29 22:31]&lt;br /&gt;{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Microsoft Shared&amp;#092;Windows Live&amp;#092;WindowsLiveLogin.dll [2006-08-31 20:33]&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Run]&lt;br /&gt;&amp;quot;IMJPMIG8.1&amp;quot;=&amp;quot;C:&amp;#092;WINDOWS1&amp;#092;IME&amp;#092;imjp8_1&amp;#092;IMJPMIG.exe&amp;quot; [2006-10-15 23:40]&lt;br /&gt;&amp;quot;PHIME2002ASync&amp;quot;=&amp;quot;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;IME&amp;#092;TINTLGNT&amp;#092;TINTSETP.exe&amp;quot; [2004-08-04 04:32]&lt;br /&gt;&amp;quot;PHIME2002A&amp;quot;=&amp;quot;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;IME&amp;#092;TINTLGNT&amp;#092;TINTSETP.exe&amp;quot; [2004-08-04 04:32]&lt;br /&gt;&amp;quot;SoundMan&amp;quot;=&amp;quot;SOUNDMAN.EXE&amp;quot; []&lt;br /&gt;&amp;quot;InstantAccess&amp;quot;=&amp;quot;C:&amp;#092;PROGRA~1&amp;#092;TEXTBR~1.0&amp;#092;Bin&amp;#092;INSTAN~1.exe&amp;quot; [1998-12-10 13:57]&lt;br /&gt;&amp;quot;RegisterDropHandler&amp;quot;=&amp;quot;C:&amp;#092;PROGRA~1&amp;#092;TEXTBR~1.0&amp;#092;Bin&amp;#092;REGIST~1.EXE&amp;quot; [1998-12-10 12:33]&lt;br /&gt;&amp;quot;NWEReboot&amp;quot;=&amp;quot;&amp;quot; []&lt;br /&gt;&amp;quot;NeroFilterCheck&amp;quot;=&amp;quot;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;NeroCheck.exe&amp;quot; [2001-07-09 11:50]&lt;br /&gt;&amp;quot;WinampAgent&amp;quot;=&amp;quot;C:&amp;#092;Program Files&amp;#092;Winamp&amp;#092;winampa.exe&amp;quot; [2007-02-14 02:29]&lt;br /&gt;&amp;quot;TkBellExe&amp;quot;=&amp;quot;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Real&amp;#092;Update_OB&amp;#092;realsched.exe&amp;quot; [2007-04-25 22:20]&lt;br /&gt;&amp;quot;aol&amp;quot;=&amp;quot;C:&amp;#092;Program Files&amp;#092;AOL&amp;#092;Active Virus Shield&amp;#092;avp.exe&amp;quot; [2006-05-30 11:13]&lt;br /&gt;&amp;quot;@&amp;quot;=&amp;quot;&amp;quot; []&lt;br /&gt;&lt;br /&gt;[HKEY_CURRENT_USER&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Run]&lt;br /&gt;&amp;quot;CTFMON.EXE&amp;quot;=&amp;quot;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;ctfmon.exe&amp;quot; [2004-08-04 06:56]&lt;br /&gt;&amp;quot;BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}&amp;quot;=&amp;quot;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Ahead&amp;#092;lib&amp;#092;NMBgMonitor.exe&amp;quot; [2005-09-03 15:18]&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;software&amp;#092;microsoft&amp;#092;windows&amp;#092;currentversion&amp;#092;runservices]&lt;br /&gt;&amp;quot;RegisterDropHandler&amp;quot;=C:&amp;#092;PROGRA~1&amp;#092;TEXTBR~1.0&amp;#092;Bin&amp;#092;REGIST~1.EXE&lt;br /&gt;&lt;br /&gt;[HKEY_CURRENT_USER&amp;#092;software&amp;#092;microsoft&amp;#092;windows&amp;#092;currentversion&amp;#092;policies&amp;#092;explorer]&lt;br /&gt;&amp;quot;RestrictRun&amp;quot;=0 (0x0)&lt;br /&gt;	&lt;br /&gt;&lt;br /&gt;Contents of the &amp;#39;Scheduled Tasks&amp;#39; folder&lt;br /&gt;2007-06-02 11:41:05  C:&amp;#092;WINDOWS1&amp;#092;tasks&amp;#092;At1.job&lt;br /&gt;&lt;br /&gt;********************************************************************&lt;br /&gt;&lt;br /&gt;catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, &lt;a href='http://www.gmer.net' target='_blank'&gt;http://www.gmer.net&lt;/a&gt;&lt;br /&gt;Rootkit scan 2007-06-03 21:43:27&lt;br /&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;br /&gt;&lt;br /&gt;scanning hidden processes ...&lt;br /&gt;&lt;br /&gt;  ? [348]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;scanning hidden autostart entries ...&lt;br /&gt;&lt;br /&gt;scanning hidden files ...&lt;br /&gt;&lt;br /&gt;scan completed successfully&lt;br /&gt;hidden files: 0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;********************************************************************&lt;br /&gt;&lt;br /&gt;Completion time: 2007-06-03 21:44:04&lt;br /&gt;&lt;br /&gt;	--- E O F ---&lt;br /&gt;(((((((((((((((((((((((((((((((   Files Created from 06/0-01-07 to 06/03/2007  ))))))))))))))))))))))))))))))))))&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!--SPOILER DIV--&gt;&lt;/div&gt;&lt;!--SPOILER DIV--&gt;&lt;br /&gt;&lt;br /&gt;sempurna i already pm u....so hope u can help me again...hehe... &lt;!--emo&amp;:D--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/biggrin.gif' border='0' style='vertical-align:middle' alt='biggrin.gif' /&gt;&lt;!--endemo--&gt;</description>
            <author>mryellow19</author>
            <category>Technical Support</category>
            <pubDate>Sun, 03 Jun 2007 21:50:22 +0800</pubDate>
        </item>
        <item>
            <title>need help...folder option missing..</title>
            <link>http://forum.lowyat.net/topic/466611</link>
            <description>my frens com got brontok coz he told me missing folder option and regedit has been disabled....so i used dr web cureit to clean the thing...but it seems tat after the scan and i restart the com...when the com start in the window...there is nothing on the desktop...not even the start toolbar...it oni pop out the my documents folder...since i cant navigate the desktop i navigated it through the folder to run hijakthis...coz as long as i close the my document folder nth can be done aleidi to restart the com..even ctrl+alt+delete function disabled...so i hope someone can help me here to solve the problem...below is the hijackthis log for my frens computer... &lt;!--emo&amp;:help:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/icon_question.gif' border='0' style='vertical-align:middle' alt='icon_question.gif' /&gt;&lt;!--endemo--&gt; &lt;br /&gt;&lt;br /&gt;Logfile of Trend Micro HijackThis v2.0.0 (BETA)&lt;br /&gt;Scan saved at 05:21:57 PM, on 02/06/2007&lt;br /&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;smss.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;winlogon.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;services.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;lsass.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Ahead&amp;#092;InCD&amp;#092;InCDsrv.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;spoolsv.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Explorer.EXE&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;wscntfy.exe&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;Gary&amp;#092;Desktop&amp;#092;HiJackThis_v2.exe&lt;br /&gt;&lt;br /&gt;R0 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Start Page = &lt;a href='http://runonce.msn.com/?v=msgrv75' target='_blank'&gt;http://runonce.msn.com/?v=msgrv75&lt;/a&gt;&lt;br /&gt;F2 - REG:system.ini: Shell=&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Acrobat 7.0&amp;#092;ActiveX&amp;#092;AcroIEHelper.dll&lt;br /&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Microsoft Shared&amp;#092;Windows Live&amp;#092;WindowsLiveLogin.dll&lt;br /&gt;O2 - BHO: DownloadBHO T2BHO - {B1D147E7-873E-4909-8127-695D9BB78728} - C:&amp;#092;WINDOWS&amp;#092;Downloaded Program Files&amp;#092;barhelp24.0.dll&lt;br /&gt;O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:&amp;#092;Program Files&amp;#092;Windows Live Toolbar&amp;#092;msntb.dll&lt;br /&gt;O3 - Toolbar: ÌìÏÂËÑË÷ - {56A7DC70-E102-4408-A34A-AE06FEF01586} - C:&amp;#092;WINDOWS&amp;#092;DOWNLO~1&amp;#092;IEBAR2~1.DLL&lt;br /&gt;O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:&amp;#092;Program Files&amp;#092;Windows Live Toolbar&amp;#092;msntb.dll&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [IMJPMIG8.1] &amp;quot;C:&amp;#092;WINDOWS&amp;#092;IME&amp;#092;imjp8_1&amp;#092;IMJPMIG.EXE&amp;quot; /Spoil /RemAdvDef /Migration32&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [PHIME2002ASync] C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;IME&amp;#092;TINTLGNT&amp;#092;TINTSETP.EXE /SYNC&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [PHIME2002A] C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;IME&amp;#092;TINTLGNT&amp;#092;TINTSETP.EXE /IMEName&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [IgfxTray] C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;igfxtray.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [HotKeysCmds] C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;hkcmd.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [SoundMan] SOUNDMAN.EXE&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [AlcWzrd] ALCWZRD.EXE&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [Alcmtr] ALCMTR.EXE&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [NeroFilterCheck] C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;NeroCheck.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [InCD] C:&amp;#092;Program Files&amp;#092;Ahead&amp;#092;InCD&amp;#092;InCD.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [PCTVOICE] pctspk.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [Sony Ericsson PC Suite] &amp;quot;C:&amp;#092;Program Files&amp;#092;Sony Ericsson&amp;#092;Mobile2&amp;#092;Application Launcher&amp;#092;Application Launcher.exe&amp;quot; /startoptions&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [Adobe Photo Downloader] &amp;quot;C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Photoshop Album Starter Edition&amp;#092;3.0&amp;#092;Apps&amp;#092;apdproxy.exe&amp;quot;&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [Messaging] C:&amp;#092;Program Files&amp;#092;Instant Messenger Names&amp;#092;IM-svr.EXE&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [AutomatedSurfer] C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;SurferClient.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [StormCodec_Helper] &amp;quot;C:&amp;#092;Program Files&amp;#092;Ringz Studio&amp;#092;Storm Codec&amp;#092;StormSet.exe&amp;quot; /S /opti&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [MsnMsgr] &amp;quot;C:&amp;#092;Program Files&amp;#092;MSN Messenger&amp;#092;MsnMsgr.Exe&amp;quot; /background&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [ctfmon.exe] C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;ctfmon.exe&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [updateMgr] &amp;quot;C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Acrobat 7.0&amp;#092;Reader&amp;#092;AdobeUpdateManager.exe&amp;quot; AcRdB7_0_9 -reboot 1&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [AutomatedSurfer] C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;SurferClient.exe&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [KKBOX Tray Icon] C:&amp;#092;Program Files&amp;#092;KKBOX&amp;#092;KKBOX_Tray.exe&lt;br /&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Acrobat 7.0&amp;#092;Reader&amp;#092;reader_sl.exe&lt;br /&gt;O7 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Policies&amp;#092;System, DisableRegedit=1&lt;br /&gt;O8 - Extra context menu item: &amp;amp;Windows Live Search - res://C:&amp;#092;Program Files&amp;#092;Windows Live Toolbar&amp;#092;msntb.dll/search.htm&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:&amp;#092;PROGRA~1&amp;#092;MICROS~2&amp;#092;OFFICE11&amp;#092;EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&amp;#092;PROGRA~1&amp;#092;MICROS~2&amp;#092;OFFICE11&amp;#092;REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%&amp;#092;Network Diagnostic&amp;#092;xpnetdiag.exe (file missing)&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%&amp;#092;Network Diagnostic&amp;#092;xpnetdiag.exe (file missing)&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&amp;#092;Program Files&amp;#092;Messenger&amp;#092;msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&amp;#092;Program Files&amp;#092;Messenger&amp;#092;msmsgs.exe&lt;br /&gt;O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &lt;a href='http://garycshmil.spaces.live.com//PhotoUpload/MsnPUpld.cab' target='_blank'&gt;http://garycshmil.spaces.live.com//PhotoUpload/MsnPUpld.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} (ÌìÏÂËÑË÷) - &lt;a href='http://iebar.t2t2.com/iebar.cab' target='_blank'&gt;http://iebar.t2t2.com/iebar.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - &lt;a href='http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab' target='_blank'&gt;http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab&lt;/a&gt;&lt;br /&gt;O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;browseui.dll&lt;br /&gt;O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;browseui.dll&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;InstallShield&amp;#092;Driver&amp;#092;11&amp;#092;Intel 32&amp;#092;IDriverT.exe&lt;br /&gt;O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:&amp;#092;Program Files&amp;#092;Ahead&amp;#092;InCD&amp;#092;InCDsrv.exe&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 5206 bytes&lt;br /&gt;&lt;br /&gt;tq in advance for ur help...hope u can und the situation i posted.... &lt;!--emo&amp;:help:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/icon_question.gif' border='0' style='vertical-align:middle' alt='icon_question.gif' /&gt;&lt;!--endemo--&gt;</description>
            <author>mryellow19</author>
            <category>Technical Support</category>
            <pubDate>Sat, 02 Jun 2007 19:03:03 +0800</pubDate>
        </item>
        <item>
            <title>Need help checking tis HJT log...</title>
            <link>http://forum.lowyat.net/topic/460488</link>
            <description>My com got infected wif trojan.download...avg detected it and i clicked heal..not sure whether its still in my com coz sometimes my IE will suddenly close...can someone pls help me to check it... &lt;!--emo&amp;:help:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/icon_question.gif' border='0' style='vertical-align:middle' alt='icon_question.gif' /&gt;&lt;!--endemo--&gt; ...thanks a lot...here is the HJT log...&lt;br /&gt;&lt;br /&gt;Logfile of HijackThis v1.99.1&lt;br /&gt;Scan saved at 9:16:01 PM, on 5/21/2007&lt;br /&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;System32&amp;#092;smss.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;winlogon.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;services.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;lsass.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;winsersec.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;spoolsv.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;Explorer.EXE&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;SOUNDMAN.EXE&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;TEXTBR~1.0&amp;#092;Bin&amp;#092;INSTAN~1.EXE&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;sdaemon.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;winwd.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Winamp&amp;#092;winampa.exe&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVG7&amp;#092;avgcc.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Real&amp;#092;Update_OB&amp;#092;realsched.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;ctfmon.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Ahead&amp;#092;lib&amp;#092;NMBgMonitor.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;TextBridge Pro 8.0&amp;#092;Ereg&amp;#092;REMIND32.EXE&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVG7&amp;#092;avgamsvr.exe&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVG7&amp;#092;avgupsvc.exe&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVG7&amp;#092;avgemc.exe&lt;br /&gt;C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;wscntfy.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;MSN Messenger&amp;#092;msnmsgr.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;MSN Messenger&amp;#092;usnsvc.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Internet Explorer&amp;#092;iexplore.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Microsoft Shared&amp;#092;Windows Live&amp;#092;WLLoginProxy.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Hijackthis&amp;#092;HijackThis.exe&lt;br /&gt;&lt;br /&gt;R0 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Start Page = &lt;a href='http://www.yahoo.com/' target='_blank'&gt;http://www.yahoo.com/&lt;/a&gt;&lt;br /&gt;O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Acrobat 7.0&amp;#092;ActiveX&amp;#092;AcroIEHelper.dll&lt;br /&gt;O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:&amp;#092;Program Files&amp;#092;BitComet&amp;#092;tools&amp;#092;BitCometBHO_1.1.3.28.dll&lt;br /&gt;O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)&lt;br /&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Microsoft Shared&amp;#092;Windows Live&amp;#092;WindowsLiveLogin.dll&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [IMJPMIG8.1] &amp;quot;C:&amp;#092;WINDOWS1&amp;#092;IME&amp;#092;imjp8_1&amp;#092;IMJPMIG.EXE&amp;quot; /Spoil /RemAdvDef /Migration32&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [PHIME2002ASync] C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;IME&amp;#092;TINTLGNT&amp;#092;TINTSETP.EXE /SYNC&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [PHIME2002A] C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;IME&amp;#092;TINTLGNT&amp;#092;TINTSETP.EXE /IMEName&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [SoundMan] SOUNDMAN.EXE&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [InstantAccess] C:&amp;#092;PROGRA~1&amp;#092;TEXTBR~1.0&amp;#092;Bin&amp;#092;INSTAN~1.EXE /h&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [RegisterDropHandler] C:&amp;#092;PROGRA~1&amp;#092;TEXTBR~1.0&amp;#092;Bin&amp;#092;REGIST~1.EXE&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [NeroFilterCheck] C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;NeroCheck.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [SDaemon] C:&amp;#092;WINDOWS1&amp;#092;sdaemon.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [SWd] C:&amp;#092;WINDOWS1&amp;#092;winwd.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [WinampAgent] C:&amp;#092;Program Files&amp;#092;Winamp&amp;#092;winampa.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [AVG7_CC] C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVG7&amp;#092;avgcc.exe /STARTUP&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [TkBellExe] &amp;quot;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Real&amp;#092;Update_OB&amp;#092;realsched.exe&amp;quot;  -osboot&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;RunServices: [RegisterDropHandler] C:&amp;#092;PROGRA~1&amp;#092;TEXTBR~1.0&amp;#092;Bin&amp;#092;REGIST~1.EXE&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [CTFMON.EXE] C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;ctfmon.exe&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &amp;quot;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Ahead&amp;#092;lib&amp;#092;NMBgMonitor.exe&amp;quot;&lt;br /&gt;O4 - Startup: reminder-ScanSoft Product Registration.lnk = C:&amp;#092;Program Files&amp;#092;TextBridge Pro 8.0&amp;#092;Ereg&amp;#092;REMIND32.EXE&lt;br /&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Acrobat 7.0&amp;#092;Reader&amp;#092;reader_sl.exe&lt;br /&gt;O8 - Extra context menu item: &amp;amp;D&amp;amp;ownload &amp;amp;with BitComet - res://C:&amp;#092;Program Files&amp;#092;BitComet&amp;#092;BitComet.exe/AddLink.htm&lt;br /&gt;O8 - Extra context menu item: &amp;amp;D&amp;amp;ownload all video with BitComet - res://C:&amp;#092;Program Files&amp;#092;BitComet&amp;#092;BitComet.exe/AddVideo.htm&lt;br /&gt;O8 - Extra context menu item: &amp;amp;D&amp;amp;ownload all with BitComet - res://C:&amp;#092;Program Files&amp;#092;BitComet&amp;#092;BitComet.exe/AddAllLink.htm&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&amp;#092;PROGRA~1&amp;#092;MICROS~2&amp;#092;OFFICE11&amp;#092;REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:&amp;#092;Documents and Settings&amp;#092;Calvin.CALVIN-F5560AEC&amp;#092;Start Menu&amp;#092;Programs&amp;#092;IMVU&amp;#092;Run IMVU.lnk&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%&amp;#092;Network Diagnostic&amp;#092;xpnetdiag.exe (file missing)&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%&amp;#092;Network Diagnostic&amp;#092;xpnetdiag.exe (file missing)&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&amp;#092;Program Files&amp;#092;Messenger&amp;#092;msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&amp;#092;Program Files&amp;#092;Messenger&amp;#092;msmsgs.exe&lt;br /&gt;O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - &lt;a href='http://www.e-games.com.my/com/EGamesPlugin.cab' target='_blank'&gt;http://www.e-games.com.my/com/EGamesPlugin.cab&lt;/a&gt;&lt;br /&gt;O17 - HKLM&amp;#092;System&amp;#092;CCS&amp;#092;Services&amp;#092;Tcpip&amp;#092;..&amp;#092;{E2551C3D-960A-4364-BFD0-7B813A026A61}: NameServer = 202.188.0.133 202.188.1.5&lt;br /&gt;O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:&amp;#092;PROGRA~1&amp;#092;MSNMES~1&amp;#092;MSGRAP~1.DLL&lt;br /&gt;O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:&amp;#092;PROGRA~1&amp;#092;MSNMES~1&amp;#092;MSGRAP~1.DLL&lt;br /&gt;O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:&amp;#092;Program Files&amp;#092;Ares&amp;#092;chatServer.exe&lt;br /&gt;O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVG7&amp;#092;avgamsvr.exe&lt;br /&gt;O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVG7&amp;#092;avgupsvc.exe&lt;br /&gt;O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:&amp;#092;PROGRA~1&amp;#092;Grisoft&amp;#092;AVG7&amp;#092;avgemc.exe&lt;br /&gt;O23 - Service: winser - Unknown owner - C:&amp;#092;WINDOWS1&amp;#092;system32&amp;#092;winsersec.exe</description>
            <author>mryellow19</author>
            <category>Technical Support</category>
            <pubDate>Mon, 21 May 2007 21:21:05 +0800</pubDate>
        </item>
        <item>
            <title>Need help&amp;#33;Acer lappy problem&amp;#33;</title>
            <link>http://forum.lowyat.net/topic/457932</link>
            <description>i juz bought a acer aspire series lappy in pc fair...then these few days gila aleidi...not sure wats happening...when i start computer there is the windows log in sound...but after a few minutes when i on windows media player an error came out stating tat no mixer is found and cant play the song...when i click on volume control it states that no mixer is found and ask me to go control panel to add hardware...but i cant seem to add any hardware...even uninstall and installing back the sound driver does not work...dunno wats happening..&lt;br /&gt;&lt;br /&gt;secondly after i log in...after 5 minutes my desktop appereance will change automatically to windows classic theme..when i wan to change back to windows xp theme in properties the windows xp theme does not exist...i try going to appearance and change the windows xp style but it also not exist...after a while it will suddenly change back to the xp theme....dunno wats happening oso...&lt;br /&gt;&lt;br /&gt;pls help me here...i dunno wat to do and sorry for my bad english..hope u guys out there can und and help me....</description>
            <author>mryellow19</author>
            <category>Technical Support</category>
            <pubDate>Wed, 16 May 2007 18:16:55 +0800</pubDate>
        </item>
    </channel>
</rss>
