<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" version="2.0">
  <channel>
    <title>Recent Posts in 'Virus sos?' | sgForums.com</title>
    <link>http://sgforums.com/forums/2250/topics/323654</link>
    <language>en-US</language>
    <ttl>60</ttl>
    <atom:link rel="search" type="application/opensearchdescription+xml" href="http://sgforums.com/open_search.xml"/>
    <description></description>
    <item>
      <title>Virus sos? replied by motoway @ Mon, 14 Jul 2008 21:50:43 +0800</title>
      <description>&lt;p&gt;KapserSky log. &lt;img src=
"/images/emoticons/classic/icon_smile.gif" alt=
"icon_smile.gif" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.mediafire.com/?nmezga9byyb" rel=
"nofollow"&gt;http://www.mediafire.com/?nmezga9byyb&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 14 Jul 2008 21:50:43 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8241571</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by ndmmxiaomayi @ Mon, 14 Jul 2008 17:47:46 +0800</title>
      <description>&lt;p&gt;Looks good.&lt;/p&gt;
&lt;ol style=""&gt;
&lt;li&gt;Please go to &lt;a href=
"http://www.kaspersky.nl/scanforvirus-en/kavwebscan.html" rel=
"nofollow"&gt;&lt;strong&gt;&lt;span style="color: blue;"&gt;Kaspersky
website&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt; to perform an online scan.
&lt;strong&gt;&lt;span style="color: red;"&gt;Please use Internet Explorer as
it uses ActiveX.&lt;/span&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Click on &lt;strong&gt;Accept&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;It will prompt you to download an ActiveX. Allow it.&lt;/li&gt;
&lt;li&gt;After that, you will be prompted to install it.&lt;/li&gt;
&lt;li&gt;Once installed, it will start downloading the definitions. This
will take some time. At the same time, you may also receive another
prompt to install another ActiveX. Allow it again and repeat Step
2.&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;When the definitions have finished downloading, click
&lt;strong&gt;Next&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Click on &lt;strong&gt;Scan Settings&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Under &lt;strong&gt;Scan using the following antivirus
database:&lt;/strong&gt;, choose &lt;strong&gt;extended - protect your computer
from Spyware, adware, dialers and potentially dangerous software
such as remote access utilities, prank programs and jokes. We do
not recommend this option to beginners or inexperienced
users.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Under &lt;strong&gt;Scan options:&lt;/strong&gt;, check (tick) both
boxes.&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;Ok&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Under &lt;strong&gt;Please select a target to scan:&lt;/strong&gt;, click
on &lt;strong&gt;My Computer&lt;/strong&gt;. It will start scanning. Please be
patient.&lt;/li&gt;
&lt;li&gt;Click on &lt;strong&gt;Save Report As...&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Give this report a name and change the &lt;strong&gt;Save as
type:&lt;/strong&gt; to &lt;strong&gt;Text file (*.txt)&lt;/strong&gt; before
clicking on &lt;strong&gt;Save&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Please post this log in your next reply.&lt;/li&gt;
&lt;/ol&gt;</description>
      <pubDate>Mon, 14 Jul 2008 17:47:46 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8240744</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by ndmmxiaomayi @ Mon, 14 Jul 2008 17:38:29 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by motoway:&lt;/div&gt;
&lt;div class="quote_body"&gt;
&lt;p&gt;Hey i clicked Send File and the window close. Is that supposed
to happen?&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Yes.&lt;/p&gt;</description>
      <pubDate>Mon, 14 Jul 2008 17:38:29 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8240725</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by motoway @ Mon, 14 Jul 2008 17:23:41 +0800</title>
      <description>&lt;p&gt;Hey i clicked Send File and the window close. Is that supposed
to happen?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This is the combofix log:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.mediafire.com/?sml5t8viogy" rel=
"nofollow"&gt;http://www.mediafire.com/?sml5t8viogy&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;And this is the HijackThis log:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.mediafire.com/?dmdzjycbyk1" rel=
"nofollow"&gt;http://www.mediafire.com/?dmdzjycbyk1&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks Mayi for your detailed instructions thus far. Really
appreciate it! &lt;img src=
"/images/emoticons/classic/icon_mrgreen.gif" alt=
"icon_mrgreen.gif" /&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 14 Jul 2008 17:23:41 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8240714</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by ndmmxiaomayi @ Mon, 14 Jul 2008 15:47:19 +0800</title>
      <description>&lt;p&gt;Yeah...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Disable AntiVir&lt;/strong&gt;
&lt;strong&gt;temporarily&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Right click on the red umbrella and untick &lt;strong&gt;AntiVir Guard
enable&lt;/strong&gt;. &lt;span style="color: #ff0000;"&gt;&lt;strong&gt;Remember to
re-enable it before posting back the logs&lt;/strong&gt;&lt;/span&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Disable Teatimer temporarily&lt;/strong&gt;&lt;/p&gt;
&lt;ol style=""&gt;
&lt;li&gt;Right click the Spybot Icon in the system tray near the clock
(looks like a blue/white calendar with a padlock symbol).&lt;/li&gt;
&lt;li&gt;Click once on &lt;strong&gt;Resident Protection&lt;/strong&gt;, then right
click the Spybot icon again and make sure &lt;strong&gt;Resident
Protection&lt;/strong&gt; is now &lt;strong&gt;Unchecked&lt;/strong&gt;. The Spybot
icon in the System tray should now be now colorless.&lt;/li&gt;
&lt;li&gt;Go to &lt;strong&gt;Start&lt;/strong&gt; &amp;gt; &lt;strong&gt;All Programs&lt;/strong&gt;
&amp;gt; &lt;strong&gt;Spybot - Search &amp;amp; Destroy&lt;/strong&gt; &amp;gt;
&lt;strong&gt;Spybot Search &amp;amp; Destroy&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Click on &lt;strong&gt;Mode&lt;/strong&gt; &amp;gt; &lt;strong&gt;Advanced
Mode&lt;/strong&gt;. When it prompts you, click
&lt;strong&gt;Yes&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;On the left hand side, click on &lt;strong&gt;Tools&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Check (tick) this box if it is not yet ticked:
&lt;strong&gt;Resident&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;You will notice that &lt;strong&gt;Resident&lt;/strong&gt; is now added
under &lt;strong&gt;Tools&lt;/strong&gt;. Click on
&lt;strong&gt;Resident&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Uncheck (untick) this box: &lt;strong&gt;Resident "TeaTimer"
(Protection of over-all system settings) active.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Exit Spybot Search &amp;amp; Destroy.&lt;/li&gt;
&lt;li&gt;Restart your computer for the changes to take effect.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Download this file - &lt;a href=
"http://www.mediafire.com/?mr2rxtcid13" rel=
"nofollow"&gt;http://www.mediafire.com/?mr2rxtcid13&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Save it as &lt;strong&gt;CFScript.txt&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Referring to the picture below, drag CFScript into
Combofix.&lt;br /&gt;
&lt;br /&gt;
&lt;img src=
"http://i266.photobucket.com/albums/ii277/sUBs_/CFScript.gif"
height="65" alt="" width="149" /&gt;&lt;br /&gt;
&lt;br /&gt;
Combofix will start running. When done, a log will be produced.
Please post this log in your next reply.&lt;/p&gt;
&lt;p&gt;In addition, it will prompt you to submit some files for
analyzing.&lt;br /&gt;
&lt;br /&gt;
&lt;img src=
"http://i266.photobucket.com/albums/ii277/sUBs_/CF-Submit_notice.gif"
alt="" /&gt;&lt;br /&gt;
&lt;br /&gt;
Click &lt;strong&gt;OK&lt;/strong&gt;.&lt;br /&gt;
&lt;br /&gt;
Copy and paste the file path into the text box next to the Browse
button (boxed up in red).&lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://xs123.xs.to/xs123/08053/cfsumbit320.png" alt=
"" /&gt;&lt;br /&gt;
&lt;br /&gt;
Click on &lt;strong&gt;Send File&lt;/strong&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;span style="color: #ff0000;"&gt;&lt;strong&gt;Do not mouse click on
Combofix while it is running. That may cause it to
stall.&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Upload both HijackThis and Combofix logs to Mediafire.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description>
      <pubDate>Mon, 14 Jul 2008 15:47:19 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8240488</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by motoway @ Mon, 14 Jul 2008 05:01:36 +0800</title>
      <description>&lt;p&gt;Me thinks virus still around coz my IE keeps hanging. o_0&lt;/p&gt;</description>
      <pubDate>Mon, 14 Jul 2008 05:01:36 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8239453</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by motoway @ Sat, 12 Jul 2008 13:45:28 +0800</title>
      <description>&lt;p&gt;I tink it's dis one ba..&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.mediafire.com/?0ojpxt4z4yg" rel=
"nofollow"&gt;http://www.mediafire.com/?0ojpxt4z4yg&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Too many combo fix file le. I tink the latest one is the one in
C drive rite?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This is the one i found in C drive. Sollie sollie i didn't take
notice of where the latest one is stored. &lt;img src=
"/images/emoticons/classic/icon_mrgreen.gif" alt=
"icon_mrgreen.gif" /&gt;&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jul 2008 13:45:28 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8236178</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by motoway @ Sat, 12 Jul 2008 13:27:08 +0800</title>
      <description>&lt;p&gt;ok i go run combo fix liao hab to off this webbie le.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Later~&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jul 2008 13:27:08 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8236126</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by ndmmxiaomayi @ Sat, 12 Jul 2008 13:20:34 +0800</title>
      <description>&lt;p&gt;Download XP Pro Recovery Console setup file from here - &lt;a href=
"http://www.microsoft.com/downloads/details.aspx?FamilyId=535D248D-5E10-49B5-B80C-0A0205368124&amp;amp;amp;displaylang=en"
rel=
"nofollow"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyId=535D248D-5E10-49B5-B80C-0A0205368124&amp;amp;displaylang=en&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Save it to your desktop and drag it into Combofix.&lt;/p&gt;
&lt;p&gt;Follow the instructions...&lt;/p&gt;
&lt;p&gt;Remember to disable AntiVir (right click on the umbrella and
untick AntiVir Guard enable) before running Combofix.&lt;/p&gt;
&lt;p&gt;Upload the Combofix log to Mediafire.&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jul 2008 13:20:34 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8236097</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by motoway @ Sat, 12 Jul 2008 13:17:13 +0800</title>
      <description>&lt;p&gt;yeps!&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jul 2008 13:17:13 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8236087</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by ndmmxiaomayi @ Sat, 12 Jul 2008 13:16:41 +0800</title>
      <description>&lt;p&gt;Is Boot.bak renamed to boot.ini ?&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jul 2008 13:16:41 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8236086</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by motoway @ Sat, 12 Jul 2008 13:09:45 +0800</title>
      <description>&lt;p&gt;ok sollie missed 1 step.&lt;/p&gt;
&lt;p&gt;Ok already :)&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jul 2008 13:09:45 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8236070</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by ndmmxiaomayi @ Sat, 12 Jul 2008 13:05:26 +0800</title>
      <description>&lt;p&gt;Show hidden files already?&lt;/p&gt;
&lt;p&gt;Boot.ini by default is hidden.&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jul 2008 13:05:26 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8236058</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by motoway @ Sat, 12 Jul 2008 13:04:03 +0800</title>
      <description>&lt;p&gt;I cant find c:\boot.ini in my C drive though when i type
c:\boot.ini i can find it.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As in, i don't see boot.ini file in c:\&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jul 2008 13:04:03 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8236056</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by ndmmxiaomayi @ Sat, 12 Jul 2008 12:38:57 +0800</title>
      <description>&lt;p&gt;The wrong version of Recovery Console has been installed. We
need to get it removed and re-install the correct version.
&lt;strong&gt;Please ensure that you read through all instructions
carefully. If any of the steps are unclear, please let me
know.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Show hidden files and folders&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;ol style=""&gt;
&lt;li&gt;Open My Computer.&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Go to Tools &amp;gt; Folder Options.&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Select the &lt;strong&gt;View&lt;/strong&gt; tab.&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Scroll down to &lt;strong&gt;Hidden files and
folders&lt;/strong&gt;.&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Select &lt;strong&gt;Show hidden files and
folders&lt;/strong&gt;.&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Uncheck (untick) &lt;strong&gt;Hide extensions of known file
types&lt;/strong&gt;.&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Uncheck (untick) &lt;strong&gt;Hide protected operating system files
(Recommended)&lt;/strong&gt;.&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;Yes&lt;/strong&gt; when prompted.&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;OK&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Step 1&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Delete this &lt;strong&gt;file&lt;/strong&gt;, it's on your desktop.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;C:\Documents and
Settings\Administrator\Desktop\WinXP_EN_HOM_BF.EXE&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Step 2&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Delete this &lt;strong&gt;folder&lt;/strong&gt; -
C:\&lt;strong&gt;cmdcons&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Step 3&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Delete this file &lt;strong&gt;file&lt;/strong&gt; -
C:\&lt;strong&gt;Boot.ini&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Step 4&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Right click on this &lt;strong&gt;file&lt;/strong&gt; -
C:\&lt;strong&gt;Boot.bak&lt;/strong&gt; and select
&lt;strong&gt;Rename&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Copy and paste in &lt;strong&gt;Boot.ini&lt;/strong&gt; and press Enter.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Let me know when you have done all 4 steps. Don't
restart your computer yet.&lt;/strong&gt;&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jul 2008 12:38:57 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8236013</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by motoway @ Sat, 12 Jul 2008 11:35:24 +0800</title>
      <description>&lt;p&gt;Here is the combofix file. &lt;img src=
"/images/emoticons/classic/icon_smile.gif" alt=
"icon_smile.gif" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.mediafire.com/?xt9cryy3tqd" rel=
"nofollow"&gt;http://www.mediafire.com/?xt9cryy3tqd&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;My window sometimes has alot of pop up screen. Unstoppable one.
&lt;img src="/images/emoticons/classic/icon_lol.gif" alt=
"icon_lol.gif" /&gt;&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jul 2008 11:35:24 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8235878</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by motoway @ Fri, 11 Jul 2008 15:56:08 +0800</title>
      <description>&lt;p&gt;Ok i upload later k.&lt;/p&gt;
&lt;p&gt;Coz my brother is back from camp and he's hogging the comp.
=_=&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks alot yea!~&lt;/p&gt;</description>
      <pubDate>Fri, 11 Jul 2008 15:56:08 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8234346</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by ndmmxiaomayi @ Fri, 11 Jul 2008 15:35:49 +0800</title>
      <description>&lt;p&gt;&lt;img src="/images/emoticons/kde-3.5.8/redones/biggrin.png" alt=
"biggrin.png" /&gt;&lt;/p&gt;
&lt;p&gt;Please upload the Combofix log to Mediafire. There may be some
leftovers.&lt;/p&gt;
&lt;p&gt;Log can be found at C:\Combofix.txt&lt;/p&gt;</description>
      <pubDate>Fri, 11 Jul 2008 15:35:49 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8234312</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by motoway @ Fri, 11 Jul 2008 01:48:59 +0800</title>
      <description>&lt;p&gt;Fwah i do the Combofix liao. Reali power lehs!&lt;/p&gt;
&lt;p&gt;No more VIRUS ALERT beside my computer clock liao!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;And i can see more items on my desktop now~ I tink the virus
block some programs last time.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.mediafire.com/?f3vbdtmjttz" rel=
"nofollow"&gt;http://www.mediafire.com/?f3vbdtmjttz&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This is the new media log file. Should be ok le rites?? XD&lt;/p&gt;
&lt;p&gt;Sho happi~&lt;/p&gt;</description>
      <pubDate>Fri, 11 Jul 2008 01:48:59 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8233415</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by motoway @ Fri, 11 Jul 2008 01:15:31 +0800</title>
      <description>&lt;p&gt;can can tml den check back ba, i go take my time look around the
web.&lt;/p&gt;
&lt;p&gt;I beri IT idiot one. &lt;img src=
"/images/emoticons/classic/icon_mrgreen.gif" alt=
"icon_mrgreen.gif" /&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 11 Jul 2008 01:15:31 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8233329</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by ndmmxiaomayi @ Fri, 11 Jul 2008 01:12:56 +0800</title>
      <description>&lt;p&gt;Most likely I will check back tomorrow. You can just post if you
want. &lt;img src="/images/emoticons/kde-3.5.8/redones/biggrin.png"
alt="biggrin.png" /&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 11 Jul 2008 01:12:56 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8233323</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by motoway @ Fri, 11 Jul 2008 01:09:22 +0800</title>
      <description>&lt;p&gt;ok me go on desktop now.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;But no rush la, i can settle tml if u need to sleep =D&lt;/p&gt;</description>
      <pubDate>Fri, 11 Jul 2008 01:09:22 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8233311</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by ndmmxiaomayi @ Fri, 11 Jul 2008 01:05:28 +0800</title>
      <description>&lt;p&gt;LOL... you got an assortment of old and new viruses.&lt;/p&gt;
&lt;p&gt;Virus Alert near the clock - New&lt;/p&gt;
&lt;p&gt;That bio hazard background - Old&lt;/p&gt;
&lt;p&gt;In between, add Vundo.&lt;/p&gt;
&lt;p&gt;Disable AntiVir as it will interfere with Combofix.&lt;/p&gt;
&lt;p&gt;This topic contains the instructions for disabling AntiVir
Antivirus (find the one with umbrella icon) - &lt;a href=
"http://www.bleepingcomputer.com/forums/topic114351.html" rel=
"nofollow"&gt;http://www.bleepingcomputer.com/forums/topic114351.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="color: red;"&gt;If you already have Combofix,
please delete this copy and download it again as it's being updated
regularly.&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Please visit this webpage for download links, and instructions
for running the tool:&lt;/p&gt;
&lt;p&gt;&lt;a href=
"http://www.bleepingcomputer.com/combofix/how-to-use-combofix" rel=
"nofollow"&gt;http://www.bleepingcomputer.com/combofix/how-to-use-combofix&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: blue;"&gt;&lt;strong&gt;Please ensure you read this
guide carefully and install the Recovery Console
first.&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;The Windows Recovery Console will allow you to boot up into a
special recovery (repair) mode. This allows us to more easily help
you should your computer have a problem after an attempted removal
of malware. It is a simple procedure that will only take a few
moments of your time.&lt;/p&gt;
&lt;p&gt;Once Recovery Console is installed, you should see a blue screen
prompt like the one below:&lt;/p&gt;
&lt;p&gt;&lt;img src=
"http://img.photobucket.com/albums/v706/ried7/RC_whatnext.gif" alt=
"RC_whatnext.gif" /&gt;&lt;/p&gt;
&lt;p&gt;Click &lt;strong&gt;Yes&lt;/strong&gt; to allow Combofix to continue
scanning for malware.&lt;/p&gt;
&lt;p&gt;When done, a log will be produced. Please post that log and a
new HijackThis log in your next reply.&lt;/p&gt;
&lt;p&gt;&lt;span style="color: red;"&gt;&lt;strong&gt;Do not mouse click on Combofix
while it is running. That may cause it to
stall.&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Upload all the logs to Mediafire as usual so sgF don't eat up
the letters.&lt;/p&gt;</description>
      <pubDate>Fri, 11 Jul 2008 01:05:28 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8233299</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by motoway @ Fri, 11 Jul 2008 01:04:47 +0800</title>
      <description>&lt;p&gt;wah new pattern ar??&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;My windows is working fine, except sumtimes it still prompt me
to dl the file. Other den that it's ok.&lt;/p&gt;</description>
      <pubDate>Fri, 11 Jul 2008 01:04:47 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8233297</guid>
      <author>motoway</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
    <item>
      <title>Virus sos? replied by ndmmxiaomayi @ Fri, 11 Jul 2008 01:02:09 +0800</title>
      <description>&lt;p&gt;Basket. Means it's a new variant.&lt;/p&gt;</description>
      <pubDate>Fri, 11 Jul 2008 01:02:09 +0800</pubDate>
      <guid isPermaLink="false">sgforums.com:2250:323654:8233290</guid>
      <author>ndmmxiaomayi</author>
      <link>http://sgforums.com/forums/2250/topics/323654</link>
    </item>
  </channel>
</rss>
