<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2" -->
<rss version="2.0">
    <channel>
        <title>Lowyat.NET: Latest topics by Ray78</title>
        <description></description>
        <link>http://forum.lowyat.net/</link>
        <lastBuildDate>Fri, 05 Jun 2026 10:01:34 +0800</lastBuildDate>
        <generator>FeedCreator 1.7.2</generator>
        <item>
            <title>[WTB] Finding Nemo 3D</title>
            <link>http://forum.lowyat.net/topic/3088384</link>
            <description>As per title.New or used.Kindly PM me.Thanks.</description>
            <author>Ray78</author>
            <category>Garage Sales Archive</category>
            <pubDate>Sat, 04 Jan 2014 12:22:29 +0800</pubDate>
        </item>
        <item>
            <title>[HELP] PC infected with virus</title>
            <link>http://forum.lowyat.net/topic/1472969</link>
            <description>Hi.&lt;br /&gt;&lt;br /&gt;Before I post HJT and SRE log files here is what happens:&lt;br /&gt;&lt;br /&gt;&amp;quot;RECYCLER&amp;quot; , &amp;quot;SYSTEM VOLUME INFORMATION&amp;quot; folders created on both my C: and D: drives.I cannot delete these folders as they keep regenerating.I believe my PC got infected through USB flashdrive which I used.I am unable to delete autorun.inf files even using cmd.And there is Isass window on my C: drive.I tried deleting it but access is denied.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here is my HJT log:&lt;br /&gt;&lt;br /&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 20:02:03, on 6/28/2010&lt;br /&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;smss.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;winlogon.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;services.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;lsass.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;spoolsv.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;IObit&amp;#092;IObit Security 360&amp;#092;IS360srv.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;nvsvc32.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Explorer.EXE&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Analog Devices&amp;#092;SoundMAX&amp;#092;SMAgent.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;TEMP&amp;#092;ggktpfg.exe&lt;br /&gt;C:&amp;#092;DOCUMENTS AND SETTINGS&amp;#092;WINDOWS XP&amp;#092;START MENU&amp;#092;PROGRAMS&amp;#092;STARTUP&amp;#092;Adobe update.com&lt;br /&gt;C:&amp;#092;DOCUMENTS AND SETTINGS&amp;#092;WINDOWS XP&amp;#092;START MENU&amp;#092;PROGRAMS&amp;#092;STARTUP&amp;#092;Adobe Online.com&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;HijackThis&amp;#092;HijackThis.exe&lt;br /&gt;c:&amp;#092;lsass.exe&lt;br /&gt;&lt;br /&gt;O3 - Toolbar: &amp;amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;msdxm.ocx&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [32740] C:&amp;#092;WINDOWS&amp;#092;TEMP&amp;#092;ggktpfg.exe&lt;br /&gt;O4 - Startup: Adobe Online.com&lt;br /&gt;O4 - Startup: Adobe update.com&lt;br /&gt;O4 - Global Startup: Tenda W541U.lnk = ?&lt;br /&gt;O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:&amp;#092;WINDOWS&amp;#092;web&amp;#092;related.htm&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Show &amp;amp;Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:&amp;#092;WINDOWS&amp;#092;web&amp;#092;related.htm&lt;br /&gt;O23 - Service: IS360service - IObit - C:&amp;#092;Program Files&amp;#092;IObit&amp;#092;IObit Security 360&amp;#092;IS360srv.exe&lt;br /&gt;O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;nvsvc32.exe&lt;br /&gt;O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:&amp;#092;Program Files&amp;#092;Analog Devices&amp;#092;SoundMAX&amp;#092;SMAgent.exe&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 1871 bytes&lt;br /&gt;________________________________________________________________________________________________&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here is another log from SREng:&lt;br /&gt;&lt;br /&gt;007-06-28,11:27:18&lt;br /&gt;&lt;br /&gt;System Repair Engineer 2.5.16.900&lt;br /&gt;Smallfrogs (http://www.KZTechs.com)&lt;br /&gt;&lt;br /&gt;Windows XP Professional Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed&lt;br /&gt;&lt;br /&gt;Follow item(s) have been choosed:&lt;br /&gt;    All Boot Items (Including Registry, Startup Folders, Services and so on)&lt;br /&gt;    Browser Add-ons&lt;br /&gt;    Runing Processes (Including process model information)&lt;br /&gt;    File Associations&lt;br /&gt;    Winsock Provider&lt;br /&gt;    Autorun.Inf&lt;br /&gt;    HOSTS File&lt;br /&gt;    Process Privileges Scan&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Boot Items&lt;br /&gt;Registry&lt;br /&gt;[HKEY_CURRENT_USER&amp;#092;Software&amp;#092;Microsoft&amp;#092;Windows NT&amp;#092;CurrentVersion&amp;#092;Windows]&lt;br /&gt;    &amp;lt;load&amp;gt;&amp;lt;&amp;gt;  [N/A]&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;Software&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Run]&lt;br /&gt;    &amp;lt;27378&amp;gt;&amp;lt;C:&amp;#092;WINDOWS&amp;#092;TEMP&amp;#092;ggktpfg.exe&amp;gt;  []&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;Software&amp;#092;Microsoft&amp;#092;Windows NT&amp;#092;CurrentVersion&amp;#092;Winlogon]&lt;br /&gt;    &amp;lt;shell&amp;gt;&amp;lt;Explorer.exe&amp;gt;  [(Verified)]&lt;br /&gt;    &amp;lt;Userinit&amp;gt;&amp;lt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;userinit.exe,&amp;gt;  [(Verified)]&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;Software&amp;#092;Microsoft&amp;#092;Windows NT&amp;#092;CurrentVersion&amp;#092;Windows]&lt;br /&gt;    &amp;lt;AppInit_DLLs&amp;gt;&amp;lt;&amp;gt;  [N/A]&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;Software&amp;#092;Microsoft&amp;#092;Windows NT&amp;#092;CurrentVersion&amp;#092;Winlogon]&lt;br /&gt;    &amp;lt;UIHost&amp;gt;&amp;lt;logonui.exe&amp;gt;  [(Verified)]&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Active Setup&amp;#092;Installed Components&amp;#092;&amp;gt;{26923b43-4d38-484f-9b9e-de460746276c}]&lt;br /&gt;    &amp;lt;Internet Explorer&amp;gt;&amp;lt;%systemroot%&amp;#092;system32&amp;#092;shmgrate.exe OCInstallUserConfigIE&amp;gt;  [N/A]&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Active Setup&amp;#092;Installed Components&amp;#092;&amp;gt;{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]&lt;br /&gt;    &amp;lt;Outlook Express&amp;gt;&amp;lt;%systemroot%&amp;#092;system32&amp;#092;shmgrate.exe OCInstallUserConfigOE&amp;gt;  [N/A]&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Active Setup&amp;#092;Installed Components&amp;#092;{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]&lt;br /&gt;    &amp;lt;Microsoft Windows Media Player 6.4&amp;gt;&amp;lt;rundll32.exe advpack.dll,LaunchINFSection C:&amp;#092;WINDOWS&amp;#092;INF&amp;#092;mplayer2.inf,PerUserStub.NT&amp;gt;  [(Verified)Microsoft Windows XP Publisher]&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Active Setup&amp;#092;Installed Components&amp;#092;{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]&lt;br /&gt;    &amp;lt;Themes Setup&amp;gt;&amp;lt;%SystemRoot%&amp;#092;system32&amp;#092;regsvr32.exe /s /n /i:/UserInstall %SystemRoot%&amp;#092;system32&amp;#092;themeui.dll&amp;gt;  [N/A]&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Active Setup&amp;#092;Installed Components&amp;#092;{306D6C21-C1B6-4629-986C-E59E1875B8AF}]&lt;br /&gt;    &amp;lt;N/A&amp;gt;&amp;lt;&amp;quot;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;rundll32.exe&amp;quot; &amp;quot;C:&amp;#092;Program Files&amp;#092;Messenger&amp;#092;msgsc.dll&amp;quot;,ShowIconsUser&amp;gt;  [(Verified)Microsoft Windows XP Publisher]&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Active Setup&amp;#092;Installed Components&amp;#092;{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]&lt;br /&gt;    &amp;lt;Microsoft Outlook Express 6&amp;gt;&amp;lt;&amp;quot;%ProgramFiles%&amp;#092;Outlook Express&amp;#092;setup50.exe&amp;quot; /APP:OE /CALLER:WINNT /user /install&amp;gt;  [N/A]&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Active Setup&amp;#092;Installed Components&amp;#092;{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]&lt;br /&gt;    &amp;lt;NetMeeting 3.01&amp;gt;&amp;lt;rundll32.exe advpack.dll,LaunchINFSection C:&amp;#092;WINDOWS&amp;#092;INF&amp;#092;msnetmtg.inf,NetMtg.Install.PerUser.NT&amp;gt;  [(Verified)Microsoft Windows XP Publisher]&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Active Setup&amp;#092;Installed Components&amp;#092;{5945c046-1e7d-11d1-bc44-00c04fd912be}]&lt;br /&gt;    &amp;lt;Windows Messenger&amp;gt;&amp;lt;rundll32.exe advpack.dll,LaunchINFSection C:&amp;#092;WINDOWS&amp;#092;INF&amp;#092;msmsgs.inf,BLC.Install.PerUser&amp;gt;  [(Verified)Microsoft Windows XP Publisher]&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Active Setup&amp;#092;Installed Components&amp;#092;{6BF52A52-394A-11d3-B153-00C04F79FAA6}]&lt;br /&gt;    &amp;lt;Microsoft Windows Media Player 8&amp;gt;&amp;lt;rundll32.exe advpack.dll,LaunchINFSection C:&amp;#092;WINDOWS&amp;#092;INF&amp;#092;wmp.inf,PerUserStub&amp;gt;  [(Verified)Microsoft Windows XP Publisher]&lt;br /&gt;[HKEY_LOCAL_MACHINE&amp;#092;SOFTWARE&amp;#092;Microsoft&amp;#092;Active Setup&amp;#092;Installed Components&amp;#092;{7790769C-0471-11d2-AF11-00C04FA35D02}]&lt;br /&gt;    &amp;lt;Address Book 6&amp;gt;&amp;lt;&amp;quot;%ProgramFiles%&amp;#092;Outlook Express&amp;#092;setup50.exe&amp;quot; /APP:WAB /CALLER:WINNT /user /install&amp;gt;  [N/A]&lt;br /&gt;&lt;br /&gt;==================================&lt;br /&gt;Startup Folders&lt;br /&gt;[Tenda W541U]&lt;br /&gt;  &amp;lt;C:&amp;#092;Documents and Settings&amp;#092;All Users&amp;#092;Start Menu&amp;#092;Programs&amp;#092;Startup&amp;#092;Tenda W541U.lnk --&amp;#62; C:&amp;#092;PROGRA~1&amp;#092;Tenda&amp;#092;W541U&amp;#092;UI.exe []&amp;gt;&amp;lt;N&amp;gt;&lt;br /&gt;[Adobe Online]&lt;br /&gt;  &amp;lt;C:&amp;#092;Documents and Settings&amp;#092;Windows XP&amp;#092;Start Menu&amp;#092;Programs&amp;#092;Startup&amp;#092;Adobe Online.com --&amp;#62;  [N/A]&amp;gt;&amp;lt;N&amp;gt;&lt;br /&gt;[Adobe update]&lt;br /&gt;  &amp;lt;C:&amp;#092;Documents and Settings&amp;#092;Windows XP&amp;#092;Start Menu&amp;#092;Programs&amp;#092;Startup&amp;#092;Adobe update.com --&amp;#62;  [N/A]&amp;gt;&amp;lt;N&amp;gt;&lt;br /&gt;&lt;br /&gt;==================================&lt;br /&gt;Services&lt;br /&gt;[Human Interface Device Access / HidServ][Stopped/Disabled]&lt;br /&gt;  &amp;lt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe -k netsvcs--&amp;#62;%SystemRoot%&amp;#092;System32&amp;#092;hidserv.dll&amp;gt;&amp;lt;N/A&amp;gt;&lt;br /&gt;[NVIDIA Driver Helper Service / NVSvc][Running/Auto Start]&lt;br /&gt;  &amp;lt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;nvsvc32.exe&amp;gt;&amp;lt;NVIDIA Corporation&amp;gt;&lt;br /&gt;[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]&lt;br /&gt;  &amp;lt;C:&amp;#092;Program Files&amp;#092;Analog Devices&amp;#092;SoundMAX&amp;#092;SMAgent.exe&amp;gt;&amp;lt;Analog Devices, Inc.&amp;gt;&lt;br /&gt;&lt;br /&gt;==================================&lt;br /&gt;Drivers&lt;br /&gt;[aeaudio / aeaudio][Running/Manual Start]&lt;br /&gt;  &amp;lt;system32&amp;#092;drivers&amp;#092;aeaudio.sys&amp;gt;&amp;lt;Andrea Electronics Corporation&amp;gt;&lt;br /&gt;[AEGIS Protocol (IEEE 802.1x) v3.5.3.0 / AegisP][Running/Auto Start]&lt;br /&gt;  &amp;lt;System32&amp;#092;DRIVERS&amp;#092;AegisP.sys&amp;gt;&amp;lt;Meetinghouse Data Communications&amp;gt;&lt;br /&gt;[nv / nv][Running/Manual Start]&lt;br /&gt;  &amp;lt;System32&amp;#092;DRIVERS&amp;#092;nv4_mini.sys&amp;gt;&amp;lt;NVIDIA Corporation&amp;gt;&lt;br /&gt;[Direct Parallel Link Driver / Ptilink][Running/Manual Start]&lt;br /&gt;  &amp;lt;System32&amp;#092;DRIVERS&amp;#092;ptilink.sys&amp;gt;&amp;lt;Parallel Technologies, Inc.&amp;gt;&lt;br /&gt;[RT73 USB Wireless LAN Card Driver / RT73][Running/Manual Start]&lt;br /&gt;  &amp;lt;System32&amp;#092;DRIVERS&amp;#092;rt73.sys&amp;gt;&amp;lt;Ralink Technology, Corp.&amp;gt;&lt;br /&gt;[Secdrv / Secdrv][Stopped/Manual Start]&lt;br /&gt;  &amp;lt;System32&amp;#092;DRIVERS&amp;#092;secdrv.sys&amp;gt;&amp;lt;N/A&amp;gt;&lt;br /&gt;[smwdm / smwdm][Running/Manual Start]&lt;br /&gt;  &amp;lt;system32&amp;#092;drivers&amp;#092;smwdm.sys&amp;gt;&amp;lt;Analog Devices, Inc.&amp;gt;&lt;br /&gt;&lt;br /&gt;==================================&lt;br /&gt;Browser Add-ons&lt;br /&gt;[@shdoclc.dll,-866]&lt;br /&gt;  {c95fe080-8f5d-11d2-a20b-00aa003c157a} &amp;lt;, N/A&amp;gt;&lt;br /&gt;[&amp;amp;Radio]&lt;br /&gt;  {8E718888-423F-11D2-876E-00A0C9082467} &amp;lt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;msdxm.ocx, &amp;gt;&lt;br /&gt;[Shockwave Flash Object]&lt;br /&gt;  {D27CDB6E-AE6D-11CF-96B8-444553540000} &amp;lt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;Macromed&amp;#092;Flash&amp;#092;Flash10h.ocx, Adobe Systems, Inc.&amp;gt;&lt;br /&gt;&lt;br /&gt;==================================&lt;br /&gt;Running Processes&lt;br /&gt;[PID: 404 / SYSTEM][&amp;#092;SystemRoot&amp;#092;System32&amp;#092;smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]&lt;br /&gt;[PID: 628 / SYSTEM][&amp;#092;??&amp;#092;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;[PID: 652 / SYSTEM][&amp;#092;??&amp;#092;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;SYNCOR11.DLL]  [SoundMAX, 1.2.2]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;[PID: 696 / SYSTEM][C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;SYNCOR11.DLL]  [SoundMAX, 1.2.2]&lt;br /&gt;[PID: 712 / SYSTEM][C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]&lt;br /&gt;[PID: 896 / SYSTEM][C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;[PID: 920 / SYSTEM][C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;SYNCOR11.DLL]  [SoundMAX, 1.2.2]&lt;br /&gt;[PID: 992 / NETWORK SERVICE][C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;[PID: 1016 / LOCAL SERVICE][C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;[PID: 1064 / SYSTEM][C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]&lt;br /&gt;[PID: 1364 / SYSTEM][C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.4403]&lt;br /&gt;[PID: 1396 / SYSTEM][C:&amp;#092;Program Files&amp;#092;Analog Devices&amp;#092;SoundMAX&amp;#092;SMAgent.exe]  [Analog Devices, Inc., 3, 2, 5, 0]&lt;br /&gt;[PID: 360 / Windows XP][C:&amp;#092;Program Files&amp;#092;Tenda&amp;#092;W541U&amp;#092;UI.exe]  [, 1.0.0.1]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Tenda&amp;#092;W541U&amp;#092;acAuth.dll]  [, 4.1.0.65 2006-07-12 18:36:34]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Tenda&amp;#092;W541U&amp;#092;dllPublicFunc.dll]  [, 1.0.0]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Tenda&amp;#092;W541U&amp;#092;dllCommonCtrl.dll]  [, 1.0.0]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Tenda&amp;#092;W541U&amp;#092;dllMultiLanguage.dll]  [, 1.0.0.1]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;SYNCOR11.DLL]  [SoundMAX, 1.2.2]&lt;br /&gt;[PID: 444 / Windows XP][C:&amp;#092;Documents and Settings&amp;#092;Windows XP&amp;#092;Start Menu&amp;#092;Programs&amp;#092;Startup&amp;#092;Adobe Online.com]  [N/A, ]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;thumbs   .db]  [N/A, ]&lt;br /&gt;[PID: 496 / SYSTEM][C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;wbem&amp;#092;wmiprvse.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]&lt;br /&gt;[PID: 1840 / Windows XP][C:&amp;#092;WINDOWS&amp;#092;TEMP&amp;#092;ggktpfg.exe]  [N/A, ]&lt;br /&gt;[PID: 140 / SYSTEM][C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;[PID: 612 / SYSTEM][C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;[PID: 1640 / SYSTEM][C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;[PID: 5356 / SYSTEM][C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;SYNCOR11.DLL]  [SoundMAX, 1.2.2]&lt;br /&gt;[PID: 5124 / Windows XP][C:&amp;#092;DOCUMENTS AND SETTINGS&amp;#092;WINDOWS XP&amp;#092;START MENU&amp;#092;PROGRAMS&amp;#092;STARTUP&amp;#092;Adobe update.com]  [N/A, ]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;thumbs   .db]  [N/A, ]&lt;br /&gt;[PID: 4792 / Windows XP][C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;firefox.exe]  [Mozilla Corporation, 1.9.2.6]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;xul.dll]  [Mozilla Foundation, 1.9.2.6]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;sqlite3.dll]  [sqlite.org, 3.6.22]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;MOZCRT19.dll]  [Mozilla Foundation, 8.00.0000]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;js3250.dll]  [N/A, ]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;nspr4.dll]  [Mozilla Foundation, 4.8.3]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;smime3.dll]  [Mozilla Foundation, 3.12.6.2 Basic ECC]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;nss3.dll]  [Mozilla Foundation, 3.12.6.2 Basic ECC]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;nssutil3.dll]  [Mozilla Foundation, 3.12.6.2]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;plc4.dll]  [Mozilla Foundation, 4.8.3]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;plds4.dll]  [Mozilla Foundation, 4.8.3]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;ssl3.dll]  [Mozilla Foundation, 3.12.6.2 Basic ECC]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;MOZCPP19.dll]  [Mozilla Foundation, 8.00.0000]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;xpcom.dll]  [Mozilla Foundation, 1.9.2.6]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;SYNCOR11.DLL]  [SoundMAX, 1.2.2]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;components&amp;#092;browserdirprovider.dll]  [Mozilla Foundation, 1.9.2.6]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;components&amp;#092;brwsrcmp.dll]  [Mozilla Foundation, 1.9.2.6]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;softokn3.dll]  [Mozilla Foundation, 3.12.4.6 Basic ECC]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;nssdbm3.dll]  [Mozilla Foundation, 3.12.4.6 Basic ECC]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;freebl3.dll]  [Mozilla Foundation, 3.12.4.6 Basic ECC]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;nssckbi.dll]  [Mozilla Foundation, 1.78]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;[PID: 5172 / Windows XP][C:&amp;#092;WINDOWS&amp;#092;explorer.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;SYNCOR11.DLL]  [SoundMAX, 1.2.2]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;[PID: 4760 / Windows XP][C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;trillian.exe]  [Cerulean Studios, 4, 1, 0, 24]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;SSLEAY32.dll]  [The OpenSSL Project, &lt;a href='http://www.openssl.org/' target='_blank'&gt;http://www.openssl.org/&lt;/a&gt;, 0.9.8j]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;LIBEAY32.dll]  [The OpenSSL Project, &lt;a href='http://www.openssl.org/' target='_blank'&gt;http://www.openssl.org/&lt;/a&gt;, 0.9.8j]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;MSVCR90.dll]  [Microsoft Corporation, 9.00.21022.8]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;zlib1.dll]  [, 1.2.3]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;MSVCP90.dll]  [Microsoft Corporation, 9.00.21022.8]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;images.dll]  [Cerulean Studios, 4, 1, 0, 24]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;core.dll]  [Cerulean Studios, LLC, 4, 1, 0, 21]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;jpeg62.dll]  [Independent JPEG Group &amp;lt;www.ijg.org&amp;gt;, 6b.1961.25445]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;libpng12.dll]  [GnuWin32 &amp;lt;http://gnuwin32.sourceforge.net&amp;gt;, 1.2.34.3276]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;libungif.dll]  [, 4, 1, 4, 0]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;expatxml.dll]  [Cerulean Studios, 4, 1, 0, 24]&lt;br /&gt;    [c:&amp;#092;program files&amp;#092;trillian&amp;#092;languages&amp;#092;en&amp;#092;trillian.dll]  [N/A, ]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;toolkit.dll]  [Cerulean Studios, 4, 1, 0, 24]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;kdu_v43R.dll]  [The University of New South Wales, 4, 3, 1, 1]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;SYNCOR11.DLL]  [SoundMAX, 1.2.2]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;events.dll]  [Cerulean Studios, 4, 1, 0, 24]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;crypto.dll]  [Cerulean Studios, LLC, 4, 1, 0, 21]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;list.dll]  [Cerulean Studios, 4, 1, 0, 24]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;buddy.dll]  [Cerulean Studios, 4, 1, 0, 24]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;talk.dll]  [Cerulean Studios, 4, 1, 0, 24]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;plugins&amp;#092;astra.dll]  [Cerulean Studios, LLC, 4, 1, 0, 21]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;libspeex.dll]  [N/A, ]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;plugins&amp;#092;MSVCP90.dll]  [Microsoft Corporation, 9.00.21022.8]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;plugins&amp;#092;MSVCR90.dll]  [Microsoft Corporation, 9.00.21022.8]&lt;br /&gt;    [c:&amp;#092;program files&amp;#092;trillian&amp;#092;languages&amp;#092;en&amp;#092;toolkit.dll]  [N/A, ]&lt;br /&gt;    [c:&amp;#092;program files&amp;#092;trillian&amp;#092;languages&amp;#092;en&amp;#092;events.dll]  [N/A, ]&lt;br /&gt;    [c:&amp;#092;program files&amp;#092;trillian&amp;#092;languages&amp;#092;en&amp;#092;buddy.dll]  [N/A, ]&lt;br /&gt;    [c:&amp;#092;program files&amp;#092;trillian&amp;#092;languages&amp;#092;en&amp;#092;talk.dll]  [N/A, ]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;plugins&amp;#092;mail.dll]  [Cerulean Studios, 4, 1, 0, 24]&lt;br /&gt;    [C:&amp;#092;Program Files&amp;#092;Trillian&amp;#092;plugins&amp;#092;msn.dll]  [Cerulean Studios, LLC, 4, 1, 0, 21]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]&lt;br /&gt;[PID: 5052 / Windows XP][C:&amp;#092;Documents and Settings&amp;#092;Windows XP&amp;#092;My Documents&amp;#092;sreng2&amp;#092;SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]&lt;br /&gt;    [C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;SYNCOR11.DLL]  [SoundMAX, 1.2.2]&lt;br /&gt;    [C:&amp;#092;Documents and Settings&amp;#092;Windows XP&amp;#092;My Documents&amp;#092;sreng2&amp;#092;Upload&amp;#092;3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]&lt;br /&gt;&lt;br /&gt;==================================&lt;br /&gt;File Associations&lt;br /&gt;.TXT  OK. [%SystemRoot%&amp;#092;system32&amp;#092;NOTEPAD.EXE %1]&lt;br /&gt;.EXE  OK. [&amp;quot;%1&amp;quot; %*]&lt;br /&gt;.COM  OK. [&amp;quot;%1&amp;quot; %*]&lt;br /&gt;.PIF  OK. [&amp;quot;%1&amp;quot; %*]&lt;br /&gt;.REG  OK. [regedit.exe &amp;quot;%1&amp;quot;]&lt;br /&gt;.BAT  OK. [&amp;quot;%1&amp;quot; %*]&lt;br /&gt;.SCR  Error. [%1]&lt;br /&gt;.CHM  OK. [&amp;quot;C:&amp;#092;WINDOWS&amp;#092;hh.exe&amp;quot; %1]&lt;br /&gt;.HLP  OK. [%SystemRoot%&amp;#092;System32&amp;#092;winhlp32.exe %1]&lt;br /&gt;.INI  OK. [%SystemRoot%&amp;#092;System32&amp;#092;NOTEPAD.EXE %1]&lt;br /&gt;.INF  OK. [%SystemRoot%&amp;#092;System32&amp;#092;NOTEPAD.EXE %1]&lt;br /&gt;.VBS  OK. [%SystemRoot%&amp;#092;System32&amp;#092;WScript.exe &amp;quot;%1&amp;quot; %*]&lt;br /&gt;.JS   OK. [%SystemRoot%&amp;#092;System32&amp;#092;WScript.exe &amp;quot;%1&amp;quot; %*]&lt;br /&gt;.LNK  OK. [{00021401-0000-0000-C000-000000000046}]&lt;br /&gt;&lt;br /&gt;==================================&lt;br /&gt;Winsock Provider&lt;br /&gt;N/A&lt;br /&gt;&lt;br /&gt;==================================&lt;br /&gt;Autorun.Inf&lt;br /&gt;[C:&amp;#092;]&lt;br /&gt;[Autorun]&lt;br /&gt;Open=Thumbs.com -a&lt;br /&gt;ShellExecute=Thumbs.com&lt;br /&gt;Shell&amp;#092;Auto&amp;#092;Command=Thumbs.com&lt;br /&gt;Shell=Auto&lt;br /&gt;[Definitions]&lt;br /&gt;Launchpad=Thumbs.com&lt;br /&gt;Vtype=1&lt;br /&gt;[D:&amp;#092;]&lt;br /&gt;[Autorun]&lt;br /&gt;Open=Thumbs.com -a&lt;br /&gt;ShellExecute=Thumbs.com&lt;br /&gt;Shell&amp;#092;Auto&amp;#092;Command=Thumbs.com&lt;br /&gt;Shell=Auto&lt;br /&gt;[Definitions]&lt;br /&gt;Launchpad=Thumbs.com&lt;br /&gt;Vtype=1&lt;br /&gt;&lt;br /&gt;==================================&lt;br /&gt;HOSTS File&lt;br /&gt;127.0.0.1 www.Brenz.pl&lt;br /&gt;127.0.0.1       localhost&lt;br /&gt;&lt;br /&gt;==================================&lt;br /&gt;Process Privileges Scan&lt;br /&gt;Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1064, C:&amp;#092;WINDOWS&amp;#092;SYSTEM32&amp;#092;SPOOLSV.EXE]&lt;br /&gt;Special Privilege Enabled: SeLoadDriverPrivilege [PID = 360, C:&amp;#092;PROGRAM FILES&amp;#092;TENDA&amp;#092;W541U&amp;#092;UI.EXE]&lt;br /&gt;Special Privilege Enabled: SeLoadDriverPrivilege [PID = 444, C:&amp;#092;DOCUMENTS AND SETTINGS&amp;#092;WINDOWS XP&amp;#092;START MENU&amp;#092;PROGRAMS&amp;#092;STARTUP&amp;#092;ADOBE ONLINE.COM]&lt;br /&gt;Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1840, C:&amp;#092;WINDOWS&amp;#092;TEMP&amp;#092;GGKTPFG.EXE]&lt;br /&gt;Special Privilege Enabled: SeLoadDriverPrivilege [PID = 5124, C:&amp;#092;DOCUMENTS AND SETTINGS&amp;#092;WINDOWS XP&amp;#092;START MENU&amp;#092;PROGRAMS&amp;#092;STARTUP&amp;#092;ADOBE UPDATE.COM]&lt;br /&gt;Special Privilege Enabled: SeLoadDriverPrivilege [PID = 5172, C:&amp;#092;WINDOWS&amp;#092;EXPLORER.EXE]&lt;br /&gt;&lt;br /&gt;==================================&lt;br /&gt;API HOOK&lt;br /&gt;Entrypoint Error: NtCreateFile (Dangerous Level: High,  Hooked by Module: 0x7FFA64D2)&lt;br /&gt;Entrypoint Error: NtCreateProcess (Dangerous Level: High,  Hooked by Module: 0x7FFA6561)&lt;br /&gt;Entrypoint Error: NtCreateProcessEx (Dangerous Level: High,  Hooked by Module: 0x7FFA656E)&lt;br /&gt;Entrypoint Error: NtQueryInformationProcess (Dangerous Level: High,  Hooked by Module: 0x7FFA65AF)&lt;br /&gt;Entrypoint Error: ZwCreateFile (Dangerous Level: High,  Hooked by Module: 0x7FFA64D2)&lt;br /&gt;Entrypoint Error: ZwCreateProcess (Dangerous Level: High,  Hooked by Module: 0x7FFA6561)&lt;br /&gt;Entrypoint Error: ZwCreateProcessEx (Dangerous Level: High,  Hooked by Module: 0x7FFA656E)&lt;br /&gt;Entrypoint Error: ZwOpenFile (Dangerous Level: High,  Hooked by Module: 0x7FFA6557)&lt;br /&gt;Entrypoint Error: ZwQueryInformationProcess (Dangerous Level: High,  Hooked by Module: 0x7FFA65AF)&lt;br /&gt;&lt;br /&gt;==================================&lt;br /&gt;Hidden Process&lt;br /&gt;    [1932] c:&amp;#092;lsass.exe&lt;br /&gt;&lt;br /&gt;==================================&lt;br /&gt;&lt;br /&gt;________________________________________________________________________________________________&lt;br /&gt;&lt;br /&gt;BTW,I have also tried Combofix removal tool from bleepingcomputer.com but unfortunately it could not start and says there could be file-patching virus in my PC.&lt;br /&gt;&lt;br /&gt;Tried DR.Web CureIt too(in safe mode) but it just halts saying &amp;quot;Invalid path to virus database&amp;quot;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Please help.Thanks&amp;#33;</description>
            <author>Ray78</author>
            <category>Technical Support</category>
            <pubDate>Mon, 28 Jun 2010 20:13:02 +0800</pubDate>
        </item>
        <item>
            <title>CHROMEHOUNDS : FINAL FAREWELL</title>
            <link>http://forum.lowyat.net/topic/1264131</link>
            <description>&lt;i&gt;&lt;b&gt;Ask your Questions - Chromehounds Japanese Producer&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;So, I&amp;#39;ve brokered what I hope to be a Q&amp;amp;A with the Japanese producer, Nabeshima-san, on Chromehounds as a final send off for you, the fans, to interact with the development side of things. I&amp;#39;m honestly not sure what the extent of the Q&amp;amp;A portion of the message will be, but I do know that there is an opportunity, and I have a quick turnaround to get some questions . Let&amp;#39;s roll the dice and see what we can get.&lt;br /&gt;&lt;br /&gt;Ok, so, if you have questions (and I expect you do), please write them below and I will compile and send along. No guarauntee that they will be answered, please remember to be respectful (hate posts will be ignored), and try to be clear in your question (so I don&amp;#39;t have to guess as to the point). Cut off for the questions is Monday, December 21.&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;LINK:&lt;br /&gt;&lt;a href='http://forums.sega.com/showthread.php?t=306988' target='_blank'&gt;http://forums.sega.com/showthread.php?t=306988&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;</description>
            <author>Ray78</author>
            <category>Xbox</category>
            <pubDate>Fri, 18 Dec 2009 11:31:13 +0800</pubDate>
        </item>
    </channel>
</rss>
