<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help to remove Packed.Generic.200, please in Norton 360</title>
    <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109840#M14870</link>
    <description>&lt;p&gt;Browser cache cleared.   Results from gmer scan below, from Devices only:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;---- Devices - GMER 1.0.15 ----&lt;/p&gt;&lt;p&gt;AttachedDevice  \Driver\Tcpip \Device\Ip          SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)&lt;br&gt;AttachedDevice  \Driver\Tcpip \Device\Tcp      SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)&lt;br&gt;AttachedDevice  \Driver\Tcpip \Device\Udp      SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)&lt;br&gt;AttachedDevice  \Driver\Tcpip \Device\RawIp  SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)&lt;br&gt;AttachedDevice  \FileSystem\Fastfat \Fat         fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;---- EOF - GMER 1.0.15 ----&lt;/p&gt;&lt;p&gt;kw&lt;/p&gt;</description>
    <pubDate>Sun, 21 Jun 2009 21:12:33 GMT</pubDate>
    <dc:creator>kwalker</dc:creator>
    <dc:date>2009-06-21T21:12:33Z</dc:date>
    <item>
      <title>Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109760#M14860</link>
      <description>&lt;p class="MsoNormal"&gt;&lt;font face="Calibri"&gt;&lt;span&gt;I have been working for the past 2 weeks to remove the Packed.Generic.200 virus from my computer, originally detected on 4 June 2009.  &lt;/span&gt;&lt;/font&gt;&lt;span&gt;&lt;font face="Calibri"&gt;Every time I start up my desktop I get a virus alert indicating the Packed.Generic.200 virus that is high risk and requires immediate attention, yet my Norton icon in the system tray shows the green circle with check mark.  &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span&gt;&lt;font face="Calibri"&gt; &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;&lt;font face="Calibri"&gt;Details:&lt;span&gt;  &lt;/span&gt;globalroot\systemroot\system32\uacjjcfucovholpyxm.dll&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;&lt;font face="Calibri"&gt;Affected Area:&lt;span&gt;   &lt;/span&gt;1 file;&lt;span&gt;  &lt;/span&gt;1 Browser cache&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span&gt;&lt;font face="Calibri"&gt; &lt;/font&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;&lt;span&gt;Initially, I contacted and paid for support from Norton’s Virus and Spyware Removal team.  The technician told me at the end of a 2 hour session that my computer was cleaned and I was safe to go back on to the Internet.  Next day start up and the virus alert window shows up with the virus still showing in the “Unresolved Security Risks” history.   Next, I follow the specific instructions posted by Norton at this link &lt;em&gt;&lt;a target="_blank" href="http://www.symantec.com/security_response/writeup.jsp?docid=2009-040809-3630-99&amp;amp;tabid=3"&gt;http://www.symantec.com/security_response/writeup.jsp?docid=2009-040809-3630-99&amp;amp;tabid=3&lt;/a&gt;&lt;/em&gt;;  these instructions were unsuccessful; disabling System Restore and running full scan in Safe Mode also did not work.&lt;span&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;font face="Calibri"&gt;&lt;span&gt;I have additionally tried the following free downloads/online scans:  Malwarebytes,  ESET, Kasperkey, TrendMicro HouseCalls, and  Super Antivirus, all with no success; only objects found have been cookies.&lt;/span&gt;&lt;/font&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;&lt;font face="Calibri"&gt;I have been researching the Norton discussion boards, the Yahoo Tech boards, Tech Forums, and the GeeksToGo boards and have yet to find a solution that appears to work.   Can anyone help?   &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;</description>
      <pubDate>Sun, 21 Jun 2009 17:32:53 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109760#M14860</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-21T17:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109783#M14861</link>
      <description>&lt;p&gt;Hi Kwalker:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;You have joined the elite group of people with a UAC rootkit.  Please remove all of the extra antimalware except Malwarebytes and Superantispyware as they do not conflict with Norton.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;You will then need to download Rootrepeal from here &lt;a target="_blank" href="http://homepages.slingshot.co.nz/~crutches/RootRepel/"&gt;http://homepages.slingshot.co.nz/~crutches/RootRepel/&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Tick the boxes for drivers, stealth objects and hidden services and click okay.  Post the log here in two or three posts.  Quads, who has become very good at removing these things is in a different time zone and will be available later in the day.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Also run this program  &lt;a target="_blank" href="http://www.gmer.net/"&gt;http://www.gmer.net/&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;We ask that you post this log in two or three parts if necessary from &amp;quot;Devices&amp;quot; down to the end of the log. Do NOT do anything else with GMER or you may crash&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by delphinium on &lt;/span&gt;&lt;span class="local-date"&gt;06-22-2009&lt;/span&gt;&lt;span class="local-time"&gt; 06:54 AM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Sun, 21 Jun 2009 18:54:58 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109783#M14861</guid>
      <dc:creator>delphinium</dc:creator>
      <dc:date>2009-06-21T18:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109800#M14864</link>
      <description>&lt;p&gt;Hi Delphinium,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I've tried to access the link for Root Repel and I get the message: IE cannot display webpage. &lt;/p&gt;&lt;p&gt;My Internet connectivity is working fine, do you know if there is a problem with the link website?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Many thanks for the help,&lt;/p&gt;&lt;p&gt;kwalker&lt;/p&gt;</description>
      <pubDate>Sun, 21 Jun 2009 19:44:09 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109800#M14864</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-21T19:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109808#M14865</link>
      <description>&lt;p&gt;Possibly, let me see if I can get you another link.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Try here.  The download is down at the bottom.  Do not do anything else with Rootrepeal other than provide a scan.  Some forums let it take out the files that it thinks should be removed but it might miss some, which will defeat the purpose, or it might take something that you would rather not lose.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;a target="_blank" href="http://rootrepeal.googlepages.com/"&gt;http://rootrepeal.googlepages.com/&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Sun, 21 Jun 2009 19:58:51 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109808#M14865</guid>
      <dc:creator>delphinium</dc:creator>
      <dc:date>2009-06-21T19:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109814#M14867</link>
      <description>&lt;p&gt;Googlepages was successful, thanks!  Below is the RootRepeal log:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;ROOTREPEAL (c) AD, 2007-2009&lt;br&gt;==================================================&lt;br&gt;Scan Time:   2009/06/21 13:16&lt;br&gt;Program Version:  Version 1.3.0.0&lt;br&gt;Windows Version:  Windows XP SP3&lt;br&gt;==================================================&lt;/p&gt;&lt;p&gt;Drivers&lt;br&gt;-------------------&lt;br&gt;Name: dump_atapi.sys&lt;br&gt;Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys&lt;br&gt;Address: 0xF24FE000 Size: 98304 File Visible: No Signed: -&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: dump_WMILIB.SYS&lt;br&gt;Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS&lt;br&gt;Address: 0xF7BB2000 Size: 8192 File Visible: No Signed: -&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: rootrepeal.sys&lt;br&gt;Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys&lt;br&gt;Address: 0xEEF43000 Size: 49152 File Visible: No Signed: -&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: SYMEFA.SYS&lt;br&gt;Image Path: SYMEFA.SYS&lt;br&gt;Address: 0xF7375000 Size: 323584 File Visible: No Signed: -&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Stealth Objects&lt;br&gt;-------------------&lt;br&gt;Object: Hidden Module [Name: System.EnterpriseServices.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x04510000 Size: 266240&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Transactions.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x04260000 Size: 270336&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.Client.BusinessLogic.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03e10000 Size: 143360&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Application.UpdateService.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00a00000 Size: 36864&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00c40000 Size: 28672&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00e00000 Size: 61440&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.Client.Common.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00e40000 Size: 86016&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.Core.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00ea0000 Size: 258048&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00ef0000 Size: 36864&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Foundations.Primary.Logging.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00f10000 Size: 53248&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Foundations.Primary.ExceptionHandling.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00fd0000 Size: 77824&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Foundations.Portability.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03020000 Size: 471040&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.configuration.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03240000 Size: 438272&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Foundations.Primary.Config.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x031a0000 Size: 86016&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x034e0000 Size: 3158016&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.XML.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x032b0000 Size: 2060288&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Api.Net.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03c10000 Size: 421888&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.Client.DataAccess.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03db0000 Size: 135168&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Data.SQLite.DLL]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03e70000 Size: 778240&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Data.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03f30000 Size: 2961408&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Map.Reporter.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x04350000 Size: 479232&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Runtime.Remoting.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x04b60000 Size: 307200&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Windows.Forms.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x04dc0000 Size: 5033984&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Drawing.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x05390000 Size: 634880&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Map.WindowsFirewallUtilities.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x05540000 Size: 1077248&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.ServiceProcess.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x056b0000 Size: 126976&lt;/p&gt;&lt;p&gt;==EOF==&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;gmer scan coming next. . .&lt;/p&gt;</description>
      <pubDate>Sun, 21 Jun 2009 20:20:53 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109814#M14867</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-21T20:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109817#M14868</link>
      <description>Kwalker, clear your browser cache as well.  Tools, internet options, browsing history, delete.  In Firefox go to tools, clear private data, uncheck all but cache.</description>
      <pubDate>Sun, 21 Jun 2009 20:32:52 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109817#M14868</guid>
      <dc:creator>delphinium</dc:creator>
      <dc:date>2009-06-21T20:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109840#M14870</link>
      <description>&lt;p&gt;Browser cache cleared.   Results from gmer scan below, from Devices only:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;---- Devices - GMER 1.0.15 ----&lt;/p&gt;&lt;p&gt;AttachedDevice  \Driver\Tcpip \Device\Ip          SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)&lt;br&gt;AttachedDevice  \Driver\Tcpip \Device\Tcp      SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)&lt;br&gt;AttachedDevice  \Driver\Tcpip \Device\Udp      SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)&lt;br&gt;AttachedDevice  \Driver\Tcpip \Device\RawIp  SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)&lt;br&gt;AttachedDevice  \FileSystem\Fastfat \Fat         fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;---- EOF - GMER 1.0.15 ----&lt;/p&gt;&lt;p&gt;kw&lt;/p&gt;</description>
      <pubDate>Sun, 21 Jun 2009 21:12:33 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109840#M14870</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-21T21:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109843#M14871</link>
      <description>&lt;p&gt;What??   when doing the Malware/rootkit scan the output has no service, reg entries or files.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;</description>
      <pubDate>Sun, 21 Jun 2009 21:16:29 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109843#M14871</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-21T21:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109847#M14872</link>
      <description>&lt;p&gt;My apology Quads,  I am very &amp;quot;low tech&amp;quot;  you'll have to help me understand your post in basic terms.  Is there a step in the process that I might be missing? I only checked the following boxes on the &amp;quot;Reports&amp;quot; tab:  Driver, Stealth Objects, Hidden Services&amp;quot;.  &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I just reloaded Rootrepeal and am rescanning with all boxes checked on the Report tab.&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by kwalker on &lt;/span&gt;&lt;span class="local-date"&gt;06-21-2009&lt;/span&gt;&lt;span class="local-time"&gt; 02:28 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Sun, 21 Jun 2009 21:28:39 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109847#M14872</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-21T21:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109851#M14873</link>
      <description>&lt;p&gt;New scan results from Rootrepeal:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;ROOTREPEAL (c) AD, 2007-2009&lt;br&gt;==================================================&lt;br&gt;Scan Time:   2009/06/21 14:26&lt;br&gt;Program Version:  Version 1.3.0.0&lt;br&gt;Windows Version:  Windows XP SP3&lt;br&gt;==================================================&lt;/p&gt;&lt;p&gt;Drivers&lt;br&gt;-------------------&lt;br&gt;Name: dump_atapi.sys&lt;br&gt;Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys&lt;br&gt;Address: 0xF24FE000 Size: 98304 File Visible: No Signed: -&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: dump_WMILIB.SYS&lt;br&gt;Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS&lt;br&gt;Address: 0xF7BB2000 Size: 8192 File Visible: No Signed: -&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: qblauikj.sys&lt;br&gt;Image Path: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\qblauikj.sys&lt;br&gt;Address: 0xEEB3D000 Size: 81664 File Visible: No Signed: -&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: rootrepeal.sys&lt;br&gt;Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys&lt;br&gt;Address: 0xEF1C8000 Size: 49152 File Visible: No Signed: -&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: SYMEFA.SYS&lt;br&gt;Image Path: SYMEFA.SYS&lt;br&gt;Address: 0xF7375000 Size: 323584 File Visible: No Signed: -&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Hidden/Locked Files&lt;br&gt;-------------------&lt;br&gt;Path: C:\hiberfil.sys&lt;br&gt;Status: Locked to the Windows API!&lt;/p&gt;&lt;p&gt;Path: c:\documents and settings\compaq_owner\local settings\temp\~df90ed.tmp&lt;br&gt;Status: Allocation size mismatch (API: 16384, Raw: 0)&lt;/p&gt;&lt;p&gt;Path: c:\documents and settings\compaq_owner\local settings\temp\~dfd832.tmp&lt;br&gt;Status: Allocation size mismatch (API: 16384, Raw: 0)&lt;/p&gt;&lt;p&gt;SSDT&lt;br&gt;-------------------&lt;br&gt;#: 012 Function Name: NtAlertResumeThread&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x8605bef8&lt;/p&gt;&lt;p&gt;#: 013 Function Name: NtAlertThread&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x861f1bd8&lt;/p&gt;&lt;p&gt;#: 017 Function Name: NtAllocateVirtualMemory&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860cd690&lt;/p&gt;&lt;p&gt;#: 019 Function Name: NtAssignProcessToJobObject&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860aade0&lt;/p&gt;&lt;p&gt;#: 031 Function Name: NtConnectPort&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x861f3188&lt;/p&gt;&lt;p&gt;#: 041 Function Name: NtCreateKey&lt;br&gt;Status: Hooked by &amp;quot;C:\WINDOWS\system32\Drivers\SYMEVENT.SYS&amp;quot; at address 0xf28b7040&lt;/p&gt;&lt;p&gt;#: 043 Function Name: NtCreateMutant&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x86115118&lt;/p&gt;&lt;p&gt;#: 052 Function Name: NtCreateSymbolicLinkObject&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x86232de0&lt;/p&gt;&lt;p&gt;#: 053 Function Name: NtCreateThread&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860f7d38&lt;/p&gt;&lt;p&gt;#: 057 Function Name: NtDebugActiveProcess&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860e08b0&lt;/p&gt;&lt;p&gt;#: 063 Function Name: NtDeleteKey&lt;br&gt;Status: Hooked by &amp;quot;C:\WINDOWS\system32\Drivers\SYMEVENT.SYS&amp;quot; at address 0xf28b72c0&lt;/p&gt;&lt;p&gt;#: 065 Function Name: NtDeleteValueKey&lt;br&gt;Status: Hooked by &amp;quot;C:\WINDOWS\system32\Drivers\SYMEVENT.SYS&amp;quot; at address 0xf28b7820&lt;/p&gt;&lt;p&gt;#: 068 Function Name: NtDuplicateObject&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860bdae8&lt;/p&gt;&lt;p&gt;#: 083 Function Name: NtFreeVirtualMemory&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860a8008&lt;/p&gt;&lt;p&gt;#: 089 Function Name: NtImpersonateAnonymousToken&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x8622ede0&lt;/p&gt;&lt;p&gt;#: 091 Function Name: NtImpersonateThread&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x86069658&lt;/p&gt;&lt;p&gt;#: 097 Function Name: NtLoadDriver&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x86254928&lt;/p&gt;&lt;p&gt;#: 108 Function Name: NtMapViewOfSection&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860a8120&lt;/p&gt;&lt;p&gt;#: 114 Function Name: NtOpenEvent&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x861bb658&lt;/p&gt;&lt;p&gt;#: 122 Function Name: NtOpenProcess&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860cdf38&lt;/p&gt;&lt;p&gt;#: 123 Function Name: NtOpenProcessToken&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860c5de0&lt;/p&gt;&lt;p&gt;#: 125 Function Name: NtOpenSection&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860b62b8&lt;/p&gt;&lt;p&gt;#: 128 Function Name: NtOpenThread&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860cde68&lt;/p&gt;&lt;p&gt;#: 137 Function Name: NtProtectVirtualMemory&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x86232eb0&lt;/p&gt;&lt;p&gt;#: 206 Function Name: NtResumeThread&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x8624f128&lt;/p&gt;&lt;p&gt;#: 213 Function Name: NtSetContextThread&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860dfd30&lt;/p&gt;&lt;p&gt;#: 228 Function Name: NtSetInformationProcess&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x8604c440&lt;/p&gt;&lt;p&gt;#: 240 Function Name: NtSetSystemInformation&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860ffde0&lt;/p&gt;&lt;p&gt;#: 247 Function Name: NtSetValueKey&lt;br&gt;Status: Hooked by &amp;quot;C:\WINDOWS\system32\Drivers\SYMEVENT.SYS&amp;quot; at address 0xf28b7a70&lt;/p&gt;&lt;p&gt;#: 253 Function Name: NtSuspendProcess&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860b6870&lt;/p&gt;&lt;p&gt;#: 254 Function Name: NtSuspendThread&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860b32b8&lt;/p&gt;&lt;p&gt;#: 257 Function Name: NtTerminateProcess&lt;br&gt;Status: Hooked by &amp;quot;C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys&amp;quot; at address 0xf27dddf0&lt;/p&gt;&lt;p&gt;#: 258 Function Name: NtTerminateThread&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860927d0&lt;/p&gt;&lt;p&gt;#: 267 Function Name: NtUnmapViewOfSection&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x86129228&lt;/p&gt;&lt;p&gt;#: 277 Function Name: NtWriteVirtualMemory&lt;br&gt;Status: Hooked by &amp;quot;&amp;lt;unknown&amp;gt;&amp;quot; at address 0x860cd5c0&lt;/p&gt;&lt;p&gt;Stealth Objects&lt;br&gt;-------------------&lt;br&gt;Object: Hidden Module [Name: System.EnterpriseServices.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x04510000 Size: 266240&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Transactions.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x04260000 Size: 270336&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.Client.BusinessLogic.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03e10000 Size: 143360&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Application.UpdateService.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00a00000 Size: 36864&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00c40000 Size: 28672&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00e00000 Size: 61440&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.Client.Common.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00e40000 Size: 86016&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.Core.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00ea0000 Size: 258048&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00ef0000 Size: 36864&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Foundations.Primary.Logging.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00f10000 Size: 53248&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Foundations.Primary.ExceptionHandling.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x00fd0000 Size: 77824&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Foundations.Portability.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03020000 Size: 471040&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.configuration.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03240000 Size: 438272&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Foundations.Primary.Config.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x031a0000 Size: 86016&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x034e0000 Size: 3158016&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.XML.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x032b0000 Size: 2060288&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Api.Net.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03c10000 Size: 421888&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.Client.DataAccess.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03db0000 Size: 135168&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Data.SQLite.DLL]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03e70000 Size: 778240&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Data.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x03f30000 Size: 2961408&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Map.Reporter.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x04350000 Size: 479232&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Runtime.Remoting.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x04b60000 Size: 307200&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Windows.Forms.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x04dc0000 Size: 5033984&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Drawing.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x05390000 Size: 634880&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Map.WindowsFirewallUtilities.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x05540000 Size: 1077248&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.ServiceProcess.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1784) Address: 0x056b0000 Size: 126976&lt;/p&gt;&lt;p&gt;==EOF==&lt;/p&gt;</description>
      <pubDate>Sun, 21 Jun 2009 21:32:15 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109851#M14873</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-21T21:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109858#M14874</link>
      <description>&lt;p&gt;I meant with GMER&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Like with this persons GMER log from devices to the end, see the services registry entries etc&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;a target="_blank" href="http://community.norton.com/norton/board/message?board.id=nis_feedback&amp;amp;message.id=57269#M57269"&gt;http://community.norton.com/norton/board/message?board.id=nis_feedback&amp;amp;message.id=57269#M57269&lt;/a&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;</description>
      <pubDate>Sun, 21 Jun 2009 21:51:52 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109858#M14874</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-21T21:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109932#M14894</link>
      <description>&lt;p&gt;Hi Quads,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I had a look at the log example you posted, I understand what you are looking for.  Here is what I have done since I last posted:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;1.  Loaded GMER again and am on the Rootkit/Malware Tab;  All areas checked for scan:  Systems,  Sections,  IAT/EAT,  Devices,&lt;/p&gt;Modules,  Processes,  Threads,  Libraries,  Services,  Registry,  Files,   C:\ and D:\,  and ADS.  &lt;span&gt; &lt;/span&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I reran the scan and got the same results that I posted in the earlier post that you questioned.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;2.  I closed GMER and reopend and reran the scan and I unchecked the D:\ drive.   Part way through the scan I got an error message window entitled  &amp;quot;Device Write Failure&amp;quot;, several of them to be specific all with file extensions that I was not able to capture.  I exited the program and the computer seemed unstable, so I shut down and restarted.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;3.  I loaded GMER and rescanned and below is the log,  nothing different from the original log.   What am I doing wrong?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;---- Kernel code sections - GMER 1.0.15 ----&lt;/p&gt;&lt;p&gt;.text           ntkrnlpa.exe!ZwCallbackReturn + 2D28                                    805045C4 4 Bytes  CALL DED64EAD&lt;br&gt;.text           ntkrnlpa.exe!ZwCallbackReturn + 2DC4                                   80504660 4 Bytes  JMP D74C8614&lt;br&gt;?               SYMEFA.SYS                                                                The system cannot find the file specified. !&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;---- Devices - GMER 1.0.15 ----&lt;/p&gt;&lt;p&gt;AttachedDevice  \Driver\Tcpip \Device\Ip                               SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)&lt;br&gt;AttachedDevice  \Driver\Tcpip \Device\Tcp                           SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)&lt;br&gt;AttachedDevice  \Driver\Tcpip \Device\Udp                           SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)&lt;br&gt;AttachedDevice  \Driver\Tcpip \Device\RawIp                       SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)&lt;br&gt;AttachedDevice  \FileSystem\Fastfat \Fat                             fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)&lt;/p&gt;&lt;p&gt;---- EOF - GMER 1.0.15 ----&lt;br&gt; &lt;/p&gt;</description>
      <pubDate>Mon, 22 Jun 2009 01:48:31 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109932#M14894</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-22T01:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109934#M14896</link>
      <description>&lt;p&gt;The rootkit is no longer there,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;So, I would say it has to do with this, the fact another program has removed it and Norton  has it stuck in the unresolved list.&lt;/p&gt;&lt;hr&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Now if Norton still notifies you of this on startup, it could be because of this:-&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; That as you have had other programs remove the infection(s) Norton has the threat in the &amp;quot;unresolved&amp;quot; list (security History) So when you restart the PC Norton notifes you that you have a threat, even though you have used another program to remove it.  The entry has to be removed from the Unresoved list, in the Security History. Norton still can think the threat is still there as you have not had Norton remove it, (empting the the unresoved list).&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I found that out buy testing with a &lt;strong&gt;CD&lt;/strong&gt;/&lt;strong&gt;DVD&lt;/strong&gt; that had Malware on it, Norton detected it, I asked it to do nothing, so was placed in the unresolved list.  After a restart Norton notified me that I had a threat on the F:\ drive (&lt;strong&gt;DVD&lt;/strong&gt;) even though the &lt;strong&gt;CD&lt;/strong&gt; / &lt;strong&gt;DVD&lt;/strong&gt; is no longer in the drive so nothing to detect. Empty drive,  had to remove from the Norton history for it to no longer Notify me.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Workaround&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;&lt;blockquote&gt;THE FIX:&lt;br&gt;It is not necesary to erase the complete Qbackup folder, neither you need to&lt;font size="2" face="trebuchet ms,geneva"&gt; boot in safe mode also. QBackup folder (Quarantine Backup) is used by Norton AntiVirus component to store backup recoveries of repaired and removed threats when you fix/remove threats during the scan. It may also contain information about threats detected and retains the remediated data in your computer itself. It will be automatically recreated by Norton program when you run scan next time.&lt;br&gt;So to FIX this problem&lt;/font&gt;. Just open NIS2009 history,  GO to &amp;quot;unresolved security risk&amp;quot; Press &amp;quot;Remove*&amp;quot; the item failed to remove, wait for the &amp;quot;failed to remove&amp;quot; status, this will update the &amp;quot;*.qbi&amp;quot; file which have the history of the unresolved items. Then go to NIS2009 settings, go to &amp;quot;miscellaneous setting&amp;quot; and disable&lt;font size="2" face="trebuchet ms,geneva"&gt; the Norton Product Tamper Protection under Miscellanious Settings. Then open your windows explorer and go to&lt;br&gt;&lt;/font&gt;  &amp;quot;C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\QBackup&amp;quot;&lt;br&gt;and erase your most recently (updated, newly)  &amp;quot;*.QBI&amp;quot; file. The asteric it a long number as &amp;quot;{DDAB4332-ED04-4898-9C20-D231FDC4B0C5}.qbi&amp;quot; it will be a small file 1-10 KB. Only deleted this file. Close Windows explorer, go to NIS2009 reactived the  &lt;font size="2" face="trebuchet ms,geneva"&gt;Norton Product Tamper Protection under Miscellanious Settings and you can enter to the HISTORY and you will find it is empty (clear).&lt;/font&gt;&lt;/blockquote&gt;&lt;blockquote&gt;Hope this will help to not erase the hole (complete) &amp;quot;Qbackup folder&amp;quot;.&lt;/blockquote&gt;&lt;blockquote&gt;BEST REGARDS (SALU2 PARA LA RAZA)&lt;br&gt;TUFE (aka JC.WILCOX or SABROSO)&lt;/blockquote&gt;&lt;hr&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;Quads &lt;/span&gt; &lt;/p&gt;</description>
      <pubDate>Mon, 22 Jun 2009 01:58:26 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/109934#M14896</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-22T01:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Help to remove Packed.Generic.200, please</title>
      <link>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/110172#M14923</link>
      <description>&lt;p&gt;Thank you Quads, followed your instruction above and the Norton history has been cleared; no Alert message today on start up; Unresolved Security Risk is empty.  I have another issue that has presented itself, I'll start a new thread.&lt;/p&gt;&lt;p&gt;kw&lt;/p&gt;</description>
      <pubDate>Mon, 22 Jun 2009 17:30:45 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Help-to-remove-Packed-Generic-200-please/m-p/110172#M14923</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-22T17:30:45Z</dc:date>
    </item>
  </channel>
</rss>

