<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2" -->
<rss version="2.0">
    <channel>
        <title>Lowyat.NET: Latest topics by boon77</title>
        <description></description>
        <link>http://forum.lowyat.net/</link>
        <lastBuildDate>Mon, 22 Jun 2026 15:04:06 +0800</lastBuildDate>
        <generator>FeedCreator 1.7.2</generator>
        <item>
            <title>all MS Doc file hidden and generate exe</title>
            <link>http://forum.lowyat.net/topic/864971</link>
            <description>Hi, &lt;br /&gt;&lt;br /&gt;I face a problem which is similar to below threat: &lt;br /&gt;&lt;br /&gt;Word files change into application, Suspected virus attacked &lt;br /&gt;&lt;a href='http://forum.lowyat.net/topic/836822' target='_blank'&gt;http://forum.lowyat.net/topic/836822&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;i&amp;#39;ve follow the way Hattori suggeted to run the command (Post#9)  and all my MS doc files is able to see now, &lt;br /&gt;So, i deleted the exe files, but after a while the malware/virus generate another set of exe files again. &lt;br /&gt;I run the HijackThis and seems like do not have any suspicious service or process is running.&lt;br /&gt;Below is my HijackThis logfile.&lt;br /&gt;&lt;br /&gt;Appreciate if any can help me on this issue. &lt;br /&gt;Thanks in advance. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 10:00:54 AM, on 12/4/2008&lt;br /&gt;Platform: Windows 2003 SP2 (WinNT 5.02.3790)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16735)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;smss.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;winlogon.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;services.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;lsass.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;spoolsv.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;Dfssvc.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;dns.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;SYSTEM32&amp;#092;DWRCS.EXE&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Trend&amp;#092;SProtect&amp;#092;EarthAgent.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;inetsrv&amp;#092;inetinfo.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;ismserv.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;ntfrs.exe&lt;br /&gt;C:&amp;#092;PCCSRV&amp;#092;web&amp;#092;service&amp;#092;ofcservice.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;wins.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;tcpsvcs.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Microsoft ISA Server&amp;#092;mspadmin.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Microsoft ISA Server&amp;#092;wspsrv.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Microsoft ISA Server&amp;#092;w3proxy.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Microsoft ISA Server&amp;#092;W3Prefch.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;winlogon.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;rdpclip.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Explorer.EXE&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;ctfmon.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Trend Micro&amp;#092;HijackThis&amp;#092;HijackThis.exe&lt;br /&gt;&lt;br /&gt;R1 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm&lt;br /&gt;R1 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Search Page = &lt;a href='http://go.microsoft.com/fwlink/?LinkId=54896' target='_blank'&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Start Page = res://shdoclc.dll/softAdmin.htm&lt;br /&gt;R1 - HKLM&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Default_Page_URL = &lt;a href='http://go.microsoft.com/fwlink/?LinkId=69157' target='_blank'&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R1 - HKLM&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Default_Search_URL = &lt;a href='http://go.microsoft.com/fwlink/?LinkId=54896' target='_blank'&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Search Page = &lt;a href='http://go.microsoft.com/fwlink/?LinkId=54896' target='_blank'&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Start Page = &lt;a href='http://go.microsoft.com/fwlink/?LinkId=69157' target='_blank'&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br /&gt;R0 - HKLM&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Search,SearchAssistant = &lt;br /&gt;R0 - HKLM&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Search,CustomizeSearch = &lt;br /&gt;R1 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,First Home Page = res://shdoclc.dll/softAdmin.htm&lt;br /&gt;R1 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Internet Settings,ProxyServer = 192.168.8.1:8080&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [AuCaption] DSA OMSA Reminder&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [AuFlag] &lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [AuRemind] %SystemRoot%&amp;#092;..&amp;#092;dell&amp;#092;openmanage&amp;#092;remind.exe&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [ctfmon.exe] C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;ctfmon.exe&lt;br /&gt;O4 - HKUS&amp;#092;S-1-5-19&amp;#092;..&amp;#092;RunOnce: [tscuninstall] %systemroot%&amp;#092;system32&amp;#092;tscupgrd.exe (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS&amp;#092;S-1-5-19&amp;#092;..&amp;#092;RunOnce: [&amp;#33;teamcfg] %SystemRoot%&amp;#092;..&amp;#092;dell&amp;#092;nicteaming&amp;#092;intel&amp;#092;nicteamconfig.bat (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS&amp;#092;S-1-5-20&amp;#092;..&amp;#092;RunOnce: [tscuninstall] %systemroot%&amp;#092;system32&amp;#092;tscupgrd.exe (User &amp;#39;NETWORK SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS&amp;#092;S-1-5-18&amp;#092;..&amp;#092;RunOnce: [tscuninstall] %systemroot%&amp;#092;system32&amp;#092;tscupgrd.exe (User &amp;#39;SYSTEM&amp;#39;)&lt;br /&gt;O4 - HKUS&amp;#092;.DEFAULT&amp;#092;..&amp;#092;RunOnce: [tscuninstall] %systemroot%&amp;#092;system32&amp;#092;tscupgrd.exe (User &amp;#39;Default user&amp;#39;)&lt;br /&gt;O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:&amp;#092;Program Files&amp;#092;Microsoft Office&amp;#092;Office&amp;#092;1033&amp;#092;OLFSNT40.EXE&lt;br /&gt;O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &lt;a href='http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab' target='_blank'&gt;http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - &lt;a href='http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab' target='_blank'&gt;http://cdn.scan.onecare.live.com/resource/...lscbase6662.cab&lt;/a&gt;&lt;br /&gt;O17 - HKLM&amp;#092;System&amp;#092;CCS&amp;#092;Services&amp;#092;Tcpip&amp;#092;Parameters: Domain = sb.my.kellyasia.com&lt;br /&gt;O17 - HKLM&amp;#092;Software&amp;#092;..&amp;#092;Telephony: DomainName = sb.my.kellyasia.com&lt;br /&gt;O17 - HKLM&amp;#092;System&amp;#092;CCS&amp;#092;Services&amp;#092;Tcpip&amp;#092;..&amp;#092;{071C78BF-FD35-49C0-96BF-CC54FAD4C215}: NameServer = 192.168.8.1&lt;br /&gt;O17 - HKLM&amp;#092;System&amp;#092;CCS&amp;#092;Services&amp;#092;Tcpip&amp;#092;..&amp;#092;{3FA18F2E-37EC-485A-A640-5A1C6A562914}: NameServer = 192.168.8.1&lt;br /&gt;O17 - HKLM&amp;#092;System&amp;#092;CS1&amp;#092;Services&amp;#092;Tcpip&amp;#092;Parameters: Domain = sb.my.kellyasia.com&lt;br /&gt;O17 - HKLM&amp;#092;System&amp;#092;CS1&amp;#092;Services&amp;#092;Tcpip&amp;#092;..&amp;#092;{071C78BF-FD35-49C0-96BF-CC54FAD4C215}: NameServer = 192.168.8.1&lt;br /&gt;O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:&amp;#092;WINDOWS&amp;#092;SYSTEM32&amp;#092;DWRCS.EXE&lt;br /&gt;O23 - Service: Trend ServerProtect Agent (EarthAgent) - Trend Micro Inc. - C:&amp;#092;Program Files&amp;#092;Trend&amp;#092;SProtect&amp;#092;EarthAgent.exe&lt;br /&gt;O23 - Service: Microsoft H.323 Gatekeeper (GKSVC) - Unknown owner - svchost.exe (file missing)&lt;br /&gt;O23 - Service: OfficeScan Master Service (ofcservice) - Trend Micro Inc. - C:&amp;#092;PCCSRV&amp;#092;web&amp;#092;service&amp;#092;ofcservice.exe&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 4716 bytes&lt;br /&gt;&lt;br /&gt;[addedon]December 9, 2008, 9:20 am[/addedon]anyone can help me??? &lt;br /&gt;:&amp;#39;(</description>
            <author>boon77</author>
            <category>Technical Support</category>
            <pubDate>Thu, 04 Dec 2008 10:29:26 +0800</pubDate>
        </item>
        <item>
            <title>Aztech Dsl600EW or Dlink DSl G604T</title>
            <link>http://forum.lowyat.net/topic/394127</link>
            <description>Hi there.. &lt;br /&gt;&lt;br /&gt;may i know which product is better? i&amp;#39;ve try to google it the review... for Dlink review mostly is negative  &lt;!--emo&amp;:sweat:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/sweat.gif' border='0' style='vertical-align:middle' alt='sweat.gif' /&gt;&lt;!--endemo--&gt; ... for aztech review is not many... &lt;!--emo&amp;:stars:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/rclxub.gif' border='0' style='vertical-align:middle' alt='rclxub.gif' /&gt;&lt;!--endemo--&gt; &lt;br /&gt;&lt;br /&gt;can help me to deicde which to take???&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;thx in advanced..  &lt;!--emo&amp;:respect:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/notworthy.gif' border='0' style='vertical-align:middle' alt='notworthy.gif' /&gt;&lt;!--endemo--&gt;</description>
            <author>boon77</author>
            <category>Networks and Broadband</category>
            <pubDate>Mon, 08 Jan 2007 12:45:54 +0800</pubDate>
        </item>
        <item>
            <title>Video Converter</title>
            <link>http://forum.lowyat.net/topic/346036</link>
            <description>Hi there... may i know which video converter is the best? I need to convert RM or RMVB file to Mpeg4... any recommend?  &lt;!--emo&amp;:P--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/tongue.gif' border='0' style='vertical-align:middle' alt='tongue.gif' /&gt;&lt;!--endemo--&gt; &lt;br /&gt;&lt;br /&gt;Thx&amp;#33;&amp;#33;</description>
            <author>boon77</author>
            <category>Multimedia</category>
            <pubDate>Wed, 27 Sep 2006 11:16:46 +0800</pubDate>
        </item>
        <item>
            <title>MS EXCEL</title>
            <link>http://forum.lowyat.net/topic/313333</link>
            <description>Dear experts, &lt;br /&gt;&lt;br /&gt;I&amp;#39;m not very familiar wif excel macro. I face a problem, and i dunno whether excel macro can solve my problem or not, if can kindly advise me... thanks in advances.  &lt;br /&gt;I need to move a set of data from one column to another column base on the row 1 description. &lt;br /&gt;&lt;br /&gt;e.g: For column A data is PO number and have to move to column B, and column B is Date and have to move to column A. &lt;br /&gt;&lt;br /&gt;Is there any marco function can do this for me??? &lt;br /&gt; &lt;br /&gt;pls advise... TQTQTQ &lt;!--emo&amp;:respect:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/notworthy.gif' border='0' style='vertical-align:middle' alt='notworthy.gif' /&gt;&lt;!--endemo--&gt;</description>
            <author>boon77</author>
            <category>Software</category>
            <pubDate>Thu, 13 Jul 2006 16:40:47 +0800</pubDate>
        </item>
        <item>
            <title>Installe Windows server 2003 in Linux box?</title>
            <link>http://forum.lowyat.net/topic/181042</link>
            <description>Dear all expert, &lt;br /&gt;&lt;br /&gt;is tat possible to W2K3 server OS in a HDD which had already installed Suse Linux and make it dual-boot?&lt;br /&gt;i try to google to find the solution, but seems most of the scenarion is installed Windows OS first then only installe linux OS. &lt;br /&gt;&lt;br /&gt;can anyone help me and gimme some comments on this issues..???? &lt;br /&gt;&lt;br /&gt; &lt;!--emo&amp;:respect:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/notworthy.gif' border='0' style='vertical-align:middle' alt='notworthy.gif' /&gt;&lt;!--endemo--&gt; thx in advanced &lt;!--emo&amp;:respect:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/notworthy.gif' border='0' style='vertical-align:middle' alt='notworthy.gif' /&gt;&lt;!--endemo--&gt;</description>
            <author>boon77</author>
            <category>Linux &amp;amp; Open Source Software</category>
            <pubDate>Wed, 27 Jul 2005 13:45:13 +0800</pubDate>
        </item>
    </channel>
</rss>
