<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>MajorGeeks Support Forums - Malware Removal</title>
		<link>http://forums.majorgeeks.com/</link>
		<description>Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.</description>
		<language>en</language>
		<lastBuildDate>Wed, 16 May 2012 19:49:36 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://forums.majorgeeks.com/images/misc/rss.jpg</url>
			<title>MajorGeeks Support Forums - Malware Removal</title>
			<link>http://forums.majorgeeks.com/</link>
		</image>
		<item>
			<title>please wait while the connection is being established</title>
			<link>http://forums.majorgeeks.com/showthread.php?t=258947&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 19:21:39 GMT</pubDate>
			<description>I see that this problem is keep growing. I pick up the same malware with other people too.  
 
I prepare my fixlist.txt ;) 
 
I really thank you in advance for any help you will provide me.  
 
Thomas</description>
			<content:encoded><![CDATA[<div>I see that this problem is keep growing. I pick up the same malware with other people too. <br />
<br />
I prepare my fixlist.txt ;)<br />
<br />
I really thank you in advance for any help you will provide me. <br />
<br />
Thomas</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://forums.majorgeeks.com/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.majorgeeks.com/attachment.php?attachmentid=178805&amp;d=1337196036">FRST.txt</a> (26.4 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.majorgeeks.com/forumdisplay.php?f=35">Malware Removal</category>
			<dc:creator>Artikia</dc:creator>
			<guid isPermaLink="true">http://forums.majorgeeks.com/showthread.php?t=258947</guid>
		</item>
		<item>
			<title>Lost Yahoo Account</title>
			<link>http://forums.majorgeeks.com/showthread.php?t=258941&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 18:20:52 GMT</pubDate>
			<description><![CDATA[I'm working with a client who's Yahoo mail account was Hacked and now she cannot retreive her mail. We have tried all kinds of fixes but the account is empty. We try to find help but there seems to be none. Does anyone have any input maybe a help line that is not publiched?]]></description>
			<content:encoded><![CDATA[<div>I'm working with a client who's Yahoo mail account was Hacked and now she cannot retreive her mail. We have tried all kinds of fixes but the account is empty. We try to find help but there seems to be none. Does anyone have any input maybe a help line that is not publiched?</div>

]]></content:encoded>
			<category domain="http://forums.majorgeeks.com/forumdisplay.php?f=35">Malware Removal</category>
			<dc:creator>flyinhgh</dc:creator>
			<guid isPermaLink="true">http://forums.majorgeeks.com/showthread.php?t=258941</guid>
		</item>
		<item>
			<title>Locked Files after Malware removal</title>
			<link>http://forums.majorgeeks.com/showthread.php?t=258932&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 16:34:46 GMT</pubDate>
			<description>Hi, 
 
I wonder if someone can help. I have locked files after a malware removal. I was reading a post on here that lead me to a program called Rannoh Decryptor but I am having problems getting it to work and cannot post to old thread hence starting a new one. 
 
I have the original file in the...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I wonder if someone can help. I have locked files after a malware removal. I was reading a post on here that lead me to a program called Rannoh Decryptor but I am having problems getting it to work and cannot post to old thread hence starting a new one.<br />
<br />
I have the original file in the original folder with the same name but I am getting the error that the file size is not equal to the original. When looking at the file size of both they are the same. <br />
<br />
Any help would be appreciated.<br />
<br />
Thanks<br />
Diamond Support</div>

]]></content:encoded>
			<category domain="http://forums.majorgeeks.com/forumdisplay.php?f=35">Malware Removal</category>
			<dc:creator>Diamond Support</dc:creator>
			<guid isPermaLink="true">http://forums.majorgeeks.com/showthread.php?t=258932</guid>
		</item>
		<item>
			<title>Blocked by CBL Lookup Utility - Torpig infection</title>
			<link>http://forums.majorgeeks.com/showthread.php?t=258928&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 15:39:26 GMT</pubDate>
			<description>Hi, 
 
I am getting the following message relating to email rejections: 
This IP is infected with, or is NATting for a machine infected with Torpig, also known by Symantec as Anserin. 
 
This was detected by observing this IP attempting to make contact to a Torpig Command and Control server at...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I am getting the following message relating to email rejections:<br />
<blockquote><i>This IP is infected with, or is NATting for a machine infected with Torpig, also known by Symantec as Anserin.<br />
<br />
This was detected by observing this IP attempting to make contact to a Torpig Command and Control server at xxx.yyy.zzz.ttt, with contents unique to Torpig C&amp;C command protocols.</i></blockquote>Which needless to say makes me believe I have a torpig infection on my Vista SP1 64 bit desktop. I can confirm that from time to time (every few hours) I see my computer connect to one of the torpig addresses the email lists (via monitoring on my gateway).<br />
<br />
I have tried using standalone boot CDs from Kapersky, Hirens Boot CD and Bit Defender, as well as scans in safe mode using tdskiller and Malwarebytes AntiMalware.<br />
<br />
The only problems reported were from tdskiller that listed 11 unsigned files that looked kosher to me, yet my desktop continues to try to connect to these sites.<br />
<br />
Any help would be greatly appreciated!<br />
<br />
P.S. If there is any tool that would allw me to detect the EXE that is making the connection, that might also be a great help!</div>

]]></content:encoded>
			<category domain="http://forums.majorgeeks.com/forumdisplay.php?f=35">Malware Removal</category>
			<dc:creator>grunthos</dc:creator>
			<guid isPermaLink="true">http://forums.majorgeeks.com/showthread.php?t=258928</guid>
		</item>
		<item>
			<title><![CDATA[frst.txt included - 'please wait while the connection is being established']]></title>
			<link>http://forums.majorgeeks.com/showthread.php?t=258911&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 04:33:53 GMT</pubDate>
			<description><![CDATA[Hello Generous People who Volunteer Here, 
 
I am the family computer administrator by default, and find myself out of my depth with this conundrum.  The computer is an HP Pavilion s5000 series running Windows 7 Home 64bit. The dreaded 'please wait while the connection is being established' with...]]></description>
			<content:encoded><![CDATA[<div>Hello Generous People who Volunteer Here,<br />
<br />
I am the family computer administrator by default, and find myself out of my depth with this conundrum.  The computer is an HP Pavilion s5000 series running Windows 7 Home 64bit. The dreaded 'please wait while the connection is being established' with German text below has replaced the desktop and the task manager is disabled. I ran the FRST tool but unfortunately can't figure out how to write a fix to feed to it. I really appreciate your time and kindness.</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://forums.majorgeeks.com/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.majorgeeks.com/attachment.php?attachmentid=178784&amp;d=1337142203">FRST.txt</a> (21.9 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.majorgeeks.com/forumdisplay.php?f=35">Malware Removal</category>
			<dc:creator>headaches</dc:creator>
			<guid isPermaLink="true">http://forums.majorgeeks.com/showthread.php?t=258911</guid>
		</item>
		<item>
			<title>VIRUS?  Windows Loads - No Icons - HELP</title>
			<link>http://forums.majorgeeks.com/showthread.php?t=258904&amp;goto=newpost</link>
			<pubDate>Tue, 15 May 2012 23:32:03 GMT</pubDate>
			<description>Hi, 
I have a Dell 4400 desktop running XP.. I go to work the other day and I notice before I left the PC was doing a windows update.. It must of refreshed itself,  
 
1. I come home its a black screen so I refresh and it took forever to load, when it did load there is no icons on the desktop and ...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
I have a Dell 4400 desktop running XP.. I go to work the other day and I notice before I left the PC was doing a windows update.. It must of refreshed itself, <br />
<br />
1. I come home its a black screen so I refresh and it took forever to load, when it did load there is no icons on the desktop and  button would nor click. So I refresh again.. Same thing. At this point I knew something was not right. I refreshed 5 more times before simply going to &quot;Safemode&quot;...<br />
<br />
2.) Once in &quot;Safemode&quot; the PC ran GREAT &amp; fast. I did a virus scann, and all the other scans to remove virus and Malware.. (SEE LOGS)..<br />
<br />
3.) Root repll does not work in Safe mode, it simply freezes up.. Also Combo fix would run yet when it got down to &quot;Scan for virus&quot; it never started the scann. So I assume Combo fix does not work in Safemode..<br />
<br />
4.) Once I ran everything the I restarted XP, it loaded slow yet icons came back on desktop. Bad thing is you click on them and none open, I click on Start button and the PC is FROZE.. Rebooted tried once more and same thing..<br />
<br />
Please see my logs.. Thank you for any assistance<br />
Regards<br />
Superlost6</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://forums.majorgeeks.com/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.majorgeeks.com/attachment.php?attachmentid=178777&amp;d=1337124705">SUPERAntiSpyware Scan Log - 05-15-2012 - 10-57-34.log</a> (1.7 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://forums.majorgeeks.com/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.majorgeeks.com/attachment.php?attachmentid=178778&amp;d=1337124705">msrvlog.txt</a> (19.6 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://forums.majorgeeks.com/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.majorgeeks.com/attachment.php?attachmentid=178779&amp;d=1337124705">mbam-log-2012-05-13 (23-05-30).txt</a> (2.1 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://forums.majorgeeks.com/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.majorgeeks.com/attachment.php?attachmentid=178780&amp;d=1337124705">hijackthis.log</a> (6.0 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.majorgeeks.com/forumdisplay.php?f=35">Malware Removal</category>
			<dc:creator>Superlost6</dc:creator>
			<guid isPermaLink="true">http://forums.majorgeeks.com/showthread.php?t=258904</guid>
		</item>
		<item>
			<title>ZeroAccess Rootkit (From Troj_ZAccess.CQJ)</title>
			<link>http://forums.majorgeeks.com/showthread.php?t=258902&amp;goto=newpost</link>
			<pubDate>Tue, 15 May 2012 22:06:03 GMT</pubDate>
			<description><![CDATA[Hi Guys 
 
I got a Trojan infection yesterday. First I saw of it was when TrendMicro OfficeScan came up saying I had "Troj_ZAccess.CQJ 
 
Tried a few things to get rid of it first, OfficeScan itself, SpyBot etc. Then started a thread in another forum who advised to run ComboFix. However, help has...]]></description>
			<content:encoded><![CDATA[<div>Hi Guys<br />
<br />
I got a Trojan infection yesterday. First I saw of it was when TrendMicro OfficeScan came up saying I had &quot;Troj_ZAccess.CQJ<br />
<br />
Tried a few things to get rid of it first, OfficeScan itself, SpyBot etc. Then started a thread in another forum who advised to run ComboFix. However, help has dried up in other frorum and I need the computer for work tomorrow. So I went through your instructions and here are my logs. I accidently ran ComboFix again after completing all steps you described (so 3rd time in total) and its still saying that I have ZeroAccess rootkit that is in the TCP/IP stack or some such line as that so guessing still not gone. <br />
<br />
Any help greatly appreciated. <br />
<br />
I'll attach the second ComboFix and the final one. They are named 1 &amp; 2<br />
<br />
Thanks in advance<br />
Terry</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://forums.majorgeeks.com/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.majorgeeks.com/attachment.php?attachmentid=178772&amp;d=1337119544">SUPERAntiSpyware Scan Log - 05-15-2012 - 20-03-50.log</a> (2.0 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://forums.majorgeeks.com/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.majorgeeks.com/attachment.php?attachmentid=178773&amp;d=1337119544">mbam-log-2012-05-15 (19-52-10).txt</a> (1.9 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://forums.majorgeeks.com/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.majorgeeks.com/attachment.php?attachmentid=178774&amp;d=1337119544">RootRepealLog.txt</a> (1.2 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.majorgeeks.com/forumdisplay.php?f=35">Malware Removal</category>
			<dc:creator>Terry1908</dc:creator>
			<guid isPermaLink="true">http://forums.majorgeeks.com/showthread.php?t=258902</guid>
		</item>
		<item>
			<title>Virus has disabled most things on computer</title>
			<link>http://forums.majorgeeks.com/showthread.php?t=258900&amp;goto=newpost</link>
			<pubDate>Tue, 15 May 2012 19:50:18 GMT</pubDate>
			<description>Hey there guys.  
I was looking for free online movies (seriously!). i watched a few FG episodes when I noticed ie was moving slow. Checked task manager and there was three or four ie explorer processes running. Closed them all, and immediatly came to this site and downloaded new combofix new...</description>
			<content:encoded><![CDATA[<div>Hey there guys. <br />
I was looking for free online movies (seriously!). i watched a few FG episodes when I noticed ie was moving slow. Checked task manager and there was three or four ie explorer processes running. Closed them all, and immediatly came to this site and downloaded new combofix new mgtools etc. Ran CC Cleaner, malware anti, Ran combofix, but it still said it needed to update, so I ran it again and again. Each time it was acting weird, like it would autoclose without even getting to the 'Stages' section. Finally it ran fully, but after this, my desktop disappeared! It also came up with an error saying 'explorer.exe not found&quot; or something. it displayed the same message after running both it and smitfraudfix in 'safe' mode as well.<br />
<br />
So I thought, ok no problem I'll use Task manager to open programs and run MG tools etc. However, something repreatedly kept disabling my PC's new usb wireless network adapter. effectively stoping me from acessing the internet. I kept trying different usb slots until they eventually all stoped working for my wireless adaptor. Mouse still works though.<br />
<br />
So, ok I though, no problem. I'll just use task manager to save files to a memory stick to transfer txt files onto a different computer. However the Pc is not recognising any memory stick no matter which slot I place them into!<br />
<br />
I was starting to get worried. No real biggie though, I'd just use a CD and save files onto that to transfer them to a diff computer to upload them to you guys. It's probably safer that way anyway.<br />
BUT NO DICE! Whenever I try to copy things to a blank CD (I know they're blank because I check em out in a diff computer first, and it let me format them and save MGtools files on them), the Copying box comes up, and stays there FOREVER. Even after an hour, it was still copying one small Combofix txt file. This happens if I try to 'send' them to the disk drive as well.<br />
<br />
So I'm honestly all out of ideas. I recognise I may have t just wipe the drive, but I really don't want to lose certain files on there, as I've been mapmaking for Zero Hour, and nearly finished, and don't want to have to spend another two weeks all over again!<br />
<br />
<br />
Can you guys help at all? :cry</div>

]]></content:encoded>
			<category domain="http://forums.majorgeeks.com/forumdisplay.php?f=35">Malware Removal</category>
			<dc:creator>SEGA</dc:creator>
			<guid isPermaLink="true">http://forums.majorgeeks.com/showthread.php?t=258900</guid>
		</item>
	</channel>
</rss>

