<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2" -->
<rss version="2.0">
    <channel>
        <title>Lowyat.NET: Latest topics by keptz</title>
        <description></description>
        <link>http://forum.lowyat.net/</link>
        <lastBuildDate>Wed, 03 Jun 2026 20:42:01 +0800</lastBuildDate>
        <generator>FeedCreator 1.7.2</generator>
        <item>
            <title>TrojanZlob.G attack</title>
            <link>http://forum.lowyat.net/topic/869014</link>
            <description>The windows firewall has detected and blocked the suspicious software. My comp suddenly become very laggy. The AVG8 has been disable by itself. help me out with this. &lt;br /&gt;&lt;br /&gt;Here my logfile..&lt;br /&gt;&lt;br /&gt;&lt;!--SPOILER BEGIN--&gt;&lt;div class=&quot;spoilertop&quot; onClick=&quot;openClose('32eb3e07c6a56e3445aa7b3543eafcce')&quot; style=&quot;font-weight: bold&quot;&gt;&lt;u&gt;&amp;raquo; Click to show Spoiler - click again to hide... &amp;laquo;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;spoilermain&quot; id=&quot;32eb3e07c6a56e3445aa7b3543eafcce&quot; style=&quot;display:none&quot;&gt;&lt;!--SPOILER END--&gt;&lt;br /&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 4:50:17 PM, on 12/8/2008&lt;br /&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;smss.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;winlogon.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;AVG&amp;#092;AVG8&amp;#092;avgrsx.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;services.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;lsass.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;spoolsv.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Explorer.EXE&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Bonjour&amp;#092;mDNSResponder.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;InterVideo&amp;#092;DeviceService&amp;#092;DevSvc.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;PnkBstrA.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;NVIDIA Corporation&amp;#092;NvMixer&amp;#092;NVMixerTray.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Alcohol Soft&amp;#092;Alcohol 120&amp;#092;StarWind&amp;#092;StarWindService.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;AVG&amp;#092;AVG8&amp;#092;avgtray.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Windows Live&amp;#092;Messenger&amp;#092;MsnMsgr.Exe&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;Yahoo&amp;#33;&amp;#092;MESSEN~1&amp;#092;YAHOOM~1.EXE&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Microsoft ActiveSync&amp;#092;wcescomm.exe&lt;br /&gt;C:&amp;#092;PROGRA~1&amp;#092;MICROS~3&amp;#092;rapimgr.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Windows Live&amp;#092;Messenger&amp;#092;usnsvc.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;firefox.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;HijackThis&amp;#092;HijackThis.exe&lt;br /&gt;&lt;br /&gt;R1 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Connection Wizard,ShellNext = &lt;a href='http://go.microsoft.com/fwlink/?LinkId=488' target='_blank'&gt;http://go.microsoft.com/fwlink/?LinkId=488&lt;/a&gt;&lt;br /&gt;R1 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Internet Settings,ProxyOverride = *.local&lt;br /&gt;R3 - URLSearchHook: Yahoo&amp;#33; Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:&amp;#092;PROGRA~1&amp;#092;Yahoo&amp;#33;&amp;#092;Companion&amp;#092;Installs&amp;#092;cpn&amp;#092;yt.dll&lt;br /&gt;O2 - BHO: &amp;amp;Yahoo&amp;#33; Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:&amp;#092;PROGRA~1&amp;#092;Yahoo&amp;#33;&amp;#092;Companion&amp;#092;Installs&amp;#092;cpn&amp;#092;yt.dll&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Adobe&amp;#092;Acrobat&amp;#092;ActiveX&amp;#092;AcroIEHelper.dll&lt;br /&gt;O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:&amp;#092;Program Files&amp;#092;AVG&amp;#092;AVG8&amp;#092;avgssie.dll&lt;br /&gt;O2 - BHO: Yahoo&amp;#33; IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:&amp;#092;Program Files&amp;#092;Yahoo&amp;#33;&amp;#092;Common&amp;#092;yiesrvc.dll&lt;br /&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:&amp;#092;Program Files&amp;#092;Java&amp;#092;jre1.6.0_05&amp;#092;bin&amp;#092;ssv.dll&lt;br /&gt;O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)&lt;br /&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Microsoft Shared&amp;#092;Windows Live&amp;#092;WindowsLiveLogin.dll&lt;br /&gt;O3 - Toolbar: Yahoo&amp;#33; Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:&amp;#092;PROGRA~1&amp;#092;Yahoo&amp;#33;&amp;#092;Companion&amp;#092;Installs&amp;#092;cpn&amp;#092;yt.dll&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [NVMixerTray] &amp;quot;C:&amp;#092;Program Files&amp;#092;NVIDIA Corporation&amp;#092;NvMixer&amp;#092;NVMixerTray.exe&amp;quot;&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [Adobe Reader Speed Launcher] &amp;quot;C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Reader 8.0&amp;#092;Reader&amp;#092;Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [AVG8_TRAY] C:&amp;#092;PROGRA~1&amp;#092;AVG&amp;#092;AVG8&amp;#092;avgtray.exe&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [MsnMsgr] &amp;quot;C:&amp;#092;Program Files&amp;#092;Windows Live&amp;#092;Messenger&amp;#092;MsnMsgr.Exe&amp;quot; /background&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [Yahoo&amp;#33; Pager] &amp;quot;C:&amp;#092;PROGRA~1&amp;#092;Yahoo&amp;#33;&amp;#092;MESSEN~1&amp;#092;YAHOOM~1.EXE&amp;quot; -quiet&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [H/PC Connection Agent] &amp;quot;C:&amp;#092;Program Files&amp;#092;Microsoft ActiveSync&amp;#092;wcescomm.exe&amp;quot;&lt;br /&gt;O4 - Global Startup: Adobe Gamma Loader.lnk = C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Adobe&amp;#092;Calibration&amp;#092;Adobe Gamma Loader.exe&lt;br /&gt;O4 - Global Startup: Microsoft Office.lnk = C:&amp;#092;Program Files&amp;#092;Microsoft Office&amp;#092;Office10&amp;#092;OSA.EXE&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:&amp;#092;PROGRA~1&amp;#092;MICROS~2&amp;#092;Office10&amp;#092;EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&amp;#092;Program Files&amp;#092;Java&amp;#092;jre1.6.0_05&amp;#092;bin&amp;#092;ssv.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&amp;#092;Program Files&amp;#092;Java&amp;#092;jre1.6.0_05&amp;#092;bin&amp;#092;ssv.dll&lt;br /&gt;O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:&amp;#092;PROGRA~1&amp;#092;MICROS~3&amp;#092;INetRepl.dll&lt;br /&gt;O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:&amp;#092;PROGRA~1&amp;#092;MICROS~3&amp;#092;INetRepl.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:&amp;#092;PROGRA~1&amp;#092;MICROS~3&amp;#092;INetRepl.dll&lt;br /&gt;O9 - Extra button: Yahoo&amp;#33; Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:&amp;#092;Program Files&amp;#092;Yahoo&amp;#33;&amp;#092;Common&amp;#092;yiesrvc.dll&lt;br /&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:&amp;#092;Program Files&amp;#092;Yahoo&amp;#33;&amp;#092;Common&amp;#092;Yinsthelper.dll&lt;br /&gt;O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:&amp;#092;Program Files&amp;#092;AVG&amp;#092;AVG8&amp;#092;avgpp.dll&lt;br /&gt;O20 - AppInit_DLLs: avgrsstx.dll&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:&amp;#092;Program Files&amp;#092;Bonjour&amp;#092;mDNSResponder.exe&lt;br /&gt;O23 - Service: Capture Device Service - InterVideo Inc. - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;InterVideo&amp;#092;DeviceService&amp;#092;DevSvc.exe&lt;br /&gt;O23 - Service: PnkBstrA - Unknown owner - C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;PnkBstrA.exe&lt;br /&gt;O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:&amp;#092;Program Files&amp;#092;Alcohol Soft&amp;#092;Alcohol 120&amp;#092;StarWind&amp;#092;StarWindService.exe&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 4879 bytes&lt;br /&gt;&lt;!--SPOILER DIV--&gt;&lt;/div&gt;&lt;!--SPOILER DIV--&gt;</description>
            <author>keptz</author>
            <category>Technical Support</category>
            <pubDate>Mon, 08 Dec 2008 17:03:26 +0800</pubDate>
        </item>
    </channel>
</rss>
