<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" version="2.0">
  <channel>
    <title>Recent Posts in 'suspected w3hph.eye malware' | sgForums.com</title>
    <link>http://sgforums.com/forums/2250/topics/321603</link>
    <language>en-US</language>
    <ttl>60</ttl>
    <atom:link rel="search" type="application/opensearchdescription+xml" href="http://sgforums.com/open_search.xml"/>
    <description></description>
    <item>
      <title>suspected w3hph.eye malware replied by Detached @ Mon, 14 Jul 2008 16:39:55 +0800</title>
      <description>&lt;p&gt;Thanks for the reply again, mayi.&lt;/p&gt;
&lt;p&gt;Nvm, I'll just skip... As of now..&amp;nbsp; the lappie's fine... no
problem yet.... You're my lappie's savior :D&lt;/p&gt;</description>
      <pubDate>Mon, 14 Jul 2008 16:39:55 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8240641</guid>
      <author>Detached</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by ndmmxiaomayi @ Mon, 14 Jul 2008 16:36:08 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by Detached:&lt;/div&gt;
&lt;div class="quote_body"&gt;
&lt;p&gt;&lt;br /&gt;
How sia? Don't joke liao leh :(&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Not kidding. Norton is a huge resource eater.&lt;/p&gt;
&lt;p&gt;You can uninstall Norton...&lt;/p&gt;
&lt;p&gt;And use this free antivirus - &lt;a href=
"http://www.antivir-pe.com/freet/index.php?id=25&amp;amp;amp;domain=free-av.com"
rel=
"nofollow"&gt;http://www.antivir-pe.com/freet/index.php?id=25&amp;amp;domain=free-av.com&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 14 Jul 2008 16:36:08 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8240629</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by Detached @ Sat, 12 Jul 2008 15:04:25 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by ndmmxiaomayi:&lt;/div&gt;
&lt;div class="quote_body"&gt;
&lt;p&gt;Ask RP not to use Norton.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;br /&gt;
How sia? Don't joke liao leh :(&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jul 2008 15:04:25 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8236272</guid>
      <author>Detached</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by ndmmxiaomayi @ Sat, 12 Jul 2008 13:08:46 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by Detached:&lt;/div&gt;
&lt;div class="quote_body"&gt;
&lt;p&gt;Update!&lt;/p&gt;
&lt;p&gt;The lappie has been hanging since the last CF, I could be
surfing some sites on IE and the whole screen just freeze up.
Running Taskmanager and ending whatever IE, MSN, Explorer.exe and
re-running Explorer.exe doesn't solve the problem... die die gotta
force shutdown..&lt;/p&gt;
&lt;p&gt;The process charge for 84 running processes shown on taskmanager
gave me a shock.. RTVscan.exe (which I believe it's the antivirus)
is running at 75k and all the usual processes that used to take
like couple of hundred memory.. now takes thousands to run.. Total
commit charge was capped at 60% when it hung..&lt;/p&gt;
&lt;p&gt;Save.Our.Soul!&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Ask RP not to use Norton.&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jul 2008 13:08:46 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8236067</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by ceecookie @ Sat, 12 Jul 2008 00:11:59 +0800</title>
      <description>&lt;p&gt;Lol...no matter how strong a virus is, the uber-reformat will
remove it &lt;img src="/images/emoticons/classic/icon_lol.gif" alt=
"icon_lol.gif" /&gt;&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jul 2008 00:11:59 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8235310</guid>
      <author>ceecookie</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by Detached @ Fri, 11 Jul 2008 23:48:04 +0800</title>
      <description>&lt;p&gt;Update!&lt;/p&gt;
&lt;p&gt;The lappie has been hanging since the last CF, I could be
surfing some sites on IE and the whole screen just freeze up.
Running Taskmanager and ending whatever IE, MSN, Explorer.exe and
re-running Explorer.exe doesn't solve the problem... die die gotta
force shutdown..&lt;/p&gt;
&lt;p&gt;The process charge for 84 running processes shown on taskmanager
gave me a shock.. RTVscan.exe (which I believe it's the antivirus)
is running at 75k and all the usual processes that used to take
like couple of hundred memory.. now takes thousands to run.. Total
commit charge was capped at 60% when it hung..&lt;/p&gt;
&lt;p&gt;Save.Our.Soul!&lt;/p&gt;</description>
      <pubDate>Fri, 11 Jul 2008 23:48:04 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8235268</guid>
      <author>Detached</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by Detached @ Fri, 11 Jul 2008 23:07:09 +0800</title>
      <description>&lt;p&gt;Couldn't upload it to mediafire, after I clicked on upload - it
returned an error page again. What could be the problem? It used to
work for me.&lt;/p&gt;
&lt;p&gt;Anyway, sent the log to your email. Thanks :D&lt;/p&gt;</description>
      <pubDate>Fri, 11 Jul 2008 23:07:09 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8235222</guid>
      <author>Detached</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by Detached @ Fri, 11 Jul 2008 18:35:49 +0800</title>
      <description>&lt;p&gt;Gotcha!&lt;/p&gt;
&lt;p&gt;working on it now, will update as soon as I'm done :P&lt;/p&gt;
&lt;p&gt;Thanks again &lt;img src=
"/images/emoticons/classic/icon_biggrin.gif" alt=
"icon_biggrin.gif" /&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 11 Jul 2008 18:35:49 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8234749</guid>
      <author>Detached</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by ndmmxiaomayi @ Wed, 09 Jul 2008 22:28:32 +0800</title>
      <description>&lt;p&gt;Download &lt;a href="http://www.atribune.org/ccount/click.php?id=1"
rel="nofollow"&gt;&lt;strong&gt;&lt;span style="color: blue;"&gt;ATF
Cleaner&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt; and save it to your desktop.&lt;/p&gt;
&lt;p&gt;Double click on &lt;strong&gt;ATF-Cleaner.exe&lt;/strong&gt; to run it.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Click on &lt;strong&gt;Main&lt;/strong&gt; at the top.&lt;/li&gt;
&lt;li&gt;Tick all the boxes except the &lt;strong&gt;Prefetch&lt;/strong&gt; and
&lt;strong&gt;Cookies&lt;/strong&gt; box.&lt;/li&gt;
&lt;li&gt;Click on &lt;strong&gt;Empty Selected&lt;/strong&gt; button.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="text-decoration: underline;"&gt;If you use
Firefox&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Click on &lt;strong&gt;Firefox&lt;/strong&gt; at the top.&lt;/li&gt;
&lt;li&gt;Tick all the boxes except &lt;strong&gt;Firefox Cookies&lt;/strong&gt; and
&lt;strong&gt;Firefox Saved Passwords&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Click on &lt;strong&gt;Empty Selected&lt;/strong&gt; button.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="text-decoration: underline;"&gt;If you use
Opera&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Click on &lt;strong&gt;Opera&lt;/strong&gt; at the top.&lt;/li&gt;
&lt;li&gt;Tick all the boxes except &lt;strong&gt;Opera Cookies&lt;/strong&gt; and
&lt;strong&gt;Opera Saved Passwords&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Click on &lt;strong&gt;Empty Selected&lt;/strong&gt; button.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Close ATF Cleaner when you are done.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Please download &lt;a href=
"http://www.besttechie.net/tools/mbam-setup.exe" rel=
"nofollow"&gt;&lt;strong&gt;&lt;span style="color: blue;"&gt;Malwarebytes'
Anti-Malware&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt; and save it to a convenient
location.&lt;/li&gt;
&lt;li&gt;Double click on &lt;strong&gt;mbam-setup.exe&lt;/strong&gt; to install
it.&lt;/li&gt;
&lt;li&gt;Before clicking the &lt;strong&gt;Finish&lt;/strong&gt; button, make sure
that these 2 boxes are checked (ticked):
&lt;div style="margin-left: 2em"&gt;&lt;strong&gt;Update Malwarebytes'
Anti-Malware&lt;br /&gt;
Launch Malwarebytes' Anti-Malware&lt;/strong&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;Malwarebytes' Anti-Malware will now check for updates. If your
firewall prompts, please allow it. If you can't update it, select
the &lt;strong&gt;Update&lt;/strong&gt; tab. Under &lt;strong&gt;Update
Mirror&lt;/strong&gt;, select one of the websites and click on
&lt;strong&gt;Check for Updates&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Select the &lt;strong&gt;Scanner&lt;/strong&gt; tab. Click on
&lt;strong&gt;Perform full scan&lt;/strong&gt;, then click on
&lt;strong&gt;Scan&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Leave the default options as it is and click on &lt;strong&gt;Start
Scan&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;When done, you will be prompted. Click &lt;strong&gt;OK&lt;/strong&gt;,
then click on &lt;strong&gt;Show Results&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Checked (ticked) all items and click on &lt;strong&gt;Remove
Selected&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;After it has removed the items, Notepad will open. Please post
this log in your next reply. You can also find the log in the
&lt;strong&gt;Logs&lt;/strong&gt; tab. The bottom most log is the latest.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description>
      <pubDate>Wed, 09 Jul 2008 22:28:32 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8230881</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by Detached @ Wed, 09 Jul 2008 21:39:07 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by ndmmxiaomayi:&lt;/div&gt;
&lt;div class="quote_body"&gt;
&lt;p&gt;Email can work?&lt;/p&gt;
&lt;p&gt;Copy and paste the the whole log.&lt;/p&gt;
&lt;p&gt;Mail is ndmmxiaomayi AT gmail DOT com&lt;/p&gt;
&lt;p&gt;AT = @&lt;/p&gt;
&lt;p&gt;DOT = .&lt;/p&gt;
&lt;p&gt;Remove all the spaces.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;br /&gt;
Sent :D&lt;/p&gt;
&lt;p&gt;Thanks mayi&lt;/p&gt;</description>
      <pubDate>Wed, 09 Jul 2008 21:39:07 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8230750</guid>
      <author>Detached</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by ndmmxiaomayi @ Wed, 09 Jul 2008 21:18:12 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by Detached:&lt;/div&gt;
&lt;div class="quote_body"&gt;
&lt;p&gt;&lt;br /&gt;
The same ol' thing, couldn't disable my antivirus but I still went
ahead with running the CFScript.txt.&lt;/p&gt;
&lt;p&gt;I couldn't upload the log to mediafire, it returned a page
error.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Email can work?&lt;/p&gt;
&lt;p&gt;Copy and paste the the whole log.&lt;/p&gt;
&lt;p&gt;Mail is ndmmxiaomayi AT gmail DOT com&lt;/p&gt;
&lt;p&gt;AT = @&lt;/p&gt;
&lt;p&gt;DOT = .&lt;/p&gt;
&lt;p&gt;Remove all the spaces.&lt;/p&gt;</description>
      <pubDate>Wed, 09 Jul 2008 21:18:12 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8230689</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by Detached @ Wed, 09 Jul 2008 21:15:22 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by ndmmxiaomayi:&lt;/div&gt;
&lt;div class="quote_body"&gt;
&lt;p&gt;Please download this file - &lt;a href=
"http://www.mediafire.com/?13diyhfhenb" rel=
"nofollow"&gt;http://www.mediafire.com/?13diyhfhenb&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;As per previous instructions, save it as
&lt;strong&gt;CFScript.txt&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Drag this file into Combofix.exe. Combofix will start running
and produce a log when done. Please post this log when done.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;br /&gt;
The same ol' thing, couldn't disable my antivirus but I still went
ahead with running the CFScript.txt.&lt;/p&gt;
&lt;p&gt;I couldn't upload the log to mediafire, it returned a page
error.&lt;/p&gt;</description>
      <pubDate>Wed, 09 Jul 2008 21:15:22 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8230677</guid>
      <author>Detached</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by kenn3th @ Mon, 07 Jul 2008 19:00:24 +0800</title>
      <description>&lt;p&gt;off topic abit.&lt;/p&gt;
&lt;p&gt;Mayi, and detached, sorry&amp;nbsp;couldnt help =(&lt;/p&gt;
&lt;p&gt;Will do so after my olevels&lt;/p&gt;</description>
      <pubDate>Mon, 07 Jul 2008 19:00:24 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8224882</guid>
      <author>kenn3th</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by ndmmxiaomayi @ Sun, 06 Jul 2008 20:57:33 +0800</title>
      <description>&lt;p&gt;Please download this file - &lt;a href=
"http://www.mediafire.com/?13diyhfhenb" rel=
"nofollow"&gt;http://www.mediafire.com/?13diyhfhenb&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;As per previous instructions, save it as
&lt;strong&gt;CFScript.txt&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Drag this file into Combofix.exe. Combofix will start running
and produce a log when done. Please post this log when done.&lt;/p&gt;</description>
      <pubDate>Sun, 06 Jul 2008 20:57:33 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8222364</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by Detached @ Sat, 05 Jul 2008 09:30:08 +0800</title>
      <description>&lt;p&gt;Update!&lt;/p&gt;
&lt;p&gt;There's a RUNDLL error when I logged in to windows, it reads
"Error loading C:\Windows\system32\klajxgmf.dll - the specific
module cannot be found"&lt;/p&gt;</description>
      <pubDate>Sat, 05 Jul 2008 09:30:08 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8219186</guid>
      <author>Detached</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by Detached @ Sat, 05 Jul 2008 00:56:18 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by ndmmxiaomayi:&lt;/div&gt;
&lt;div class="quote_body"&gt;
&lt;p&gt;Please post back the Combofix log.&lt;/p&gt;
&lt;p&gt;Log can be found at C:\Combofix.txt&lt;/p&gt;
&lt;p&gt;Hmm... might not be related to any virus issue...&lt;/p&gt;
&lt;p&gt;Sounds like an error or something.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;br /&gt;
One thing to note: The beeping only started right after I
downloaded w3hph.exe, it was fine before - now it takes so long to
start windows :(&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.mediafire.com/?vwtcebny1tm" rel=
"nofollow"&gt;http://www.mediafire.com/?vwtcebny1tm&lt;/a&gt;&amp;nbsp;&amp;lt;---
Combofix log as you requested&lt;/p&gt;</description>
      <pubDate>Sat, 05 Jul 2008 00:56:18 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8218878</guid>
      <author>Detached</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by ndmmxiaomayi @ Sat, 05 Jul 2008 00:53:18 +0800</title>
      <description>&lt;p&gt;Please post back the Combofix log.&lt;/p&gt;
&lt;p&gt;Log can be found at C:\Combofix.txt&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;2) Whenever I log in to windows, there's always a "beep" sound
(I left it out the other time)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Hmm... might not be related to any virus issue...&lt;/p&gt;
&lt;p&gt;Sounds like an error or something.&lt;/p&gt;</description>
      <pubDate>Sat, 05 Jul 2008 00:53:18 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8218871</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by Detached @ Fri, 04 Jul 2008 21:37:06 +0800</title>
      <description>&lt;p&gt;I think my laptop's heavily infected.. Every now and then,
symantec would pop up a "static" window.. or a window to tell me it
had detected a virus..&lt;/p&gt;
&lt;p&gt;The last detection was "Trojan.Vundo"... and it was "cleaned by
deletion"..&lt;/p&gt;
&lt;p&gt;Gosh.. mayi... help &lt;img src=
"/images/emoticons/classic/icon_frown.gif" alt=
"icon_frown.gif" /&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 04 Jul 2008 21:37:06 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8218440</guid>
      <author>Detached</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by Detached @ Fri, 04 Jul 2008 20:44:06 +0800</title>
      <description>&lt;p&gt;Update!&lt;/p&gt;
&lt;p&gt;1) I couldn't disable my antivirus before running combofix with
CFscript but I went ahead anyway&lt;/p&gt;
&lt;p&gt;2) Whenever I log in to windows, there's always a "beep" sound
(I left it out the other time)&lt;/p&gt;
&lt;p&gt;3) I've deleted instafinder via Add/Remove Program&lt;/p&gt;
&lt;p&gt;4) Uploaded samples for analysis&lt;/p&gt;</description>
      <pubDate>Fri, 04 Jul 2008 20:44:06 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8218383</guid>
      <author>Detached</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by Detached @ Fri, 04 Jul 2008 17:52:19 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by ndmmxiaomayi:&lt;/div&gt;
&lt;div class="quote_body"&gt;
&lt;p&gt;Off topic, you haven't grad?&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;br /&gt;
Grad'ed - I'm the 2nd batch &lt;img src=
"/images/emoticons/classic/icon_biggrin.gif" alt=
"icon_biggrin.gif" /&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 04 Jul 2008 17:52:19 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8218096</guid>
      <author>Detached</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by ndmmxiaomayi @ Thu, 03 Jul 2008 00:47:40 +0800</title>
      <description>&lt;p&gt;OK, after uninstalling that, please do the following:&lt;/p&gt;
&lt;p&gt;Download the following file - &lt;a href=
"http://www.mediafire.com/?wlfdycs2cbg" rel=
"nofollow"&gt;http://www.mediafire.com/?wlfdycs2cbg&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Save it as &lt;strong&gt;CFScript.txt&lt;/strong&gt;. Don't change the file
name. Save it in the same place as Combofix.&lt;/p&gt;
&lt;p&gt;Drag this file into Combofix.&lt;/p&gt;
&lt;p&gt;Picture for reference:&lt;/p&gt;
&lt;p&gt;&lt;img src=
"http://i266.photobucket.com/albums/ii277/sUBs_/CFScript.gif"
height="65" alt="" width="149" /&gt;&lt;/p&gt;
&lt;p&gt;Combofix will start running and produce a log. Please upload
that log to Mediafire.&lt;/p&gt;
&lt;p&gt;Also, it will ask you to upload samples for analysis.&lt;/p&gt;
&lt;p&gt;&lt;img src=
"http://i266.photobucket.com/albums/ii277/sUBs_/CF-Submit_notice.gif"
alt="" /&gt;&lt;/p&gt;
&lt;p&gt;Click &lt;strong&gt;OK&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;
Copy and paste the file path into the text box next to the Browse
button (boxed up in red).&lt;/p&gt;
&lt;p&gt;&lt;img src="http://xs123.xs.to/xs123/08053/cfsumbit320.png" alt=
"" /&gt;&lt;/p&gt;
&lt;p&gt;Click on &lt;strong&gt;Send File&lt;/strong&gt; to upload it.&lt;/p&gt;</description>
      <pubDate>Thu, 03 Jul 2008 00:47:40 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8213343</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by ndmmxiaomayi @ Thu, 03 Jul 2008 00:33:04 +0800</title>
      <description>&lt;p&gt;Kazza, I did install in the past and have deleted it since
months ago.&lt;/p&gt;
&lt;p&gt;Oh...&lt;/p&gt;
&lt;p&gt;One of the programs bundled with Kazza will hijack your home
page...&lt;/p&gt;
&lt;p&gt;Uninstall this program if found -
&lt;strong&gt;Instafinder&lt;/strong&gt;&lt;/p&gt;</description>
      <pubDate>Thu, 03 Jul 2008 00:33:04 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8213326</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by ndmmxiaomayi @ Thu, 03 Jul 2008 00:30:29 +0800</title>
      <description>&lt;p&gt;Off topic, you haven't grad?&lt;/p&gt;</description>
      <pubDate>Thu, 03 Jul 2008 00:30:29 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8213324</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by ndmmxiaomayi @ Thu, 03 Jul 2008 00:29:15 +0800</title>
      <description>&lt;p&gt;The Wixawin thingy - this is the 3rd time I've seen it. I can't
put my fingers on anything yet. It seems to come with a lot of
other crap, but no idea what's causing it.&lt;/p&gt;</description>
      <pubDate>Thu, 03 Jul 2008 00:29:15 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8213322</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
    <item>
      <title>suspected w3hph.eye malware replied by Detached @ Wed, 02 Jul 2008 20:35:54 +0800</title>
      <description>&lt;p&gt;Update...&lt;/p&gt;
&lt;p&gt;Just couple mins ago, &lt;a href="http://www.antispywareexpert.com"
rel="nofollow"&gt;www.antispywareexpert.com&lt;/a&gt; pop up again.. This is
one of the website that automatically pop up for no reason :(&lt;/p&gt;
&lt;p&gt;Spy/Malware problem probably not fixed yet...&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href=
"http://www.wixawin.com/sg/ads/iphone.aspx?clickid=000ffC00OoeO31rcdqbk&amp;amp;amp;ce_cid=000ffC00OoeO31rcdq0AtGKL8Bdtvd3f"
rel=
"nofollow"&gt;http://www.wixawin.com/sg/ads/iphone.aspx?clickid=000ffC00OoeO31rcdqbk&amp;amp;ce_cid=000ffC00OoeO31rcdq0AtGKL8Bdtvd3f&lt;/a&gt;&amp;nbsp;&amp;lt;--
another malicious pop up... that tells me "win this iphone"...
argh...&lt;/p&gt;</description>
      <pubDate>Wed, 02 Jul 2008 20:35:54 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:321603:8212787</guid>
      <author>Detached</author>
      <link>http://sgforums.com/forums/2250/topics/321603</link>
    </item>
  </channel>
</rss>
