<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Browser redirect issues - possible Happili infection? (help, Quads...) in Norton 360</title>
    <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717312#M71680</link>
    <description>&lt;p&gt;Download a new  copy of Combofix like the main instructions in the past and so on, on to your desktop but this time run it without any script.&lt;/p&gt;&lt;p&gt;Have to make sure one of the files is gone.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;You Could also have  a permissions problem with files / folders.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Also you do or did have Malwarebytes running with it's realtime protection running (another security product), or it could be that the infection hurt Norton.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
    <pubDate>Mon, 14 May 2012 00:56:31 GMT</pubDate>
    <dc:creator>Quads</dc:creator>
    <dc:date>2012-05-14T00:56:31Z</dc:date>
    <item>
      <title>Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/716916#M71621</link>
      <description>&lt;p&gt;Late this morning, my browser (IE9) began to be redirected to one of several sites whenever I tried to click on a Google search result.  Am running Norton 360, so I tried doing a full system scan first - no threats detected.  Did some quick research, and ended up downloading Malwarebytes' Anti-Malware program while running in safe mode with networking.  Ran that, and it detected Trojan.Happili in a temp directory (don't recall the path.)  The Malwarebytes program said it had resolved the issue, and a subsequent scan was clean.  Ran Ccleaner with secure deletion enabled to clean out temp directories.  Updated Java, and cleared the cache through the Java console.  Tried another Google search - same redirect issue.  Found Quads' suggestions in this forum, and downloaded TDSSKiller and aswMBR while in safe mode with networking.  Stopping there without further guidance, as I don't know how to interpret the results, and it sounds like messing around in ignorance is a recipe for disaster.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Can you help, Quads?  Please let me know if more info is required.&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 01:42:35 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/716916#M71621</guid>
      <dc:creator>armygirl44</dc:creator>
      <dc:date>2012-05-13T01:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/716954#M71634</link>
      <description>&lt;p&gt;Why are you running in Safe Mode with Networking??&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Why are you going about using tools that can cause more damage without any supervision, I have warned about doing so to people??&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Start Malwarebytes and go to the logs tab to see what it detected.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 03:04:09 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/716954#M71634</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-13T03:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/716980#M71636</link>
      <description>&lt;p&gt;Unfortunately, whatever's wrong with my system seems to be preventing me from accessing anti-malware product sites... running in safe mode with networking was the only way I was able to download the Malwarebytes program.  My apologies for jumping the gun with the other two tools - didn't remove anything, just ran them to get the logs to post.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Malwarebytes log is attached as requested.  Thanks for any advice you can offer!&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 04:48:40 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/716980#M71636</guid>
      <dc:creator>armygirl44</dc:creator>
      <dc:date>2012-05-13T04:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/716982#M71637</link>
      <description>&lt;p&gt;Log of subsequent clean mbam scan attached.  Didn't stop the redirect issue though.&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 04:56:30 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/716982#M71637</guid>
      <dc:creator>armygirl44</dc:creator>
      <dc:date>2012-05-13T04:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/716994#M71639</link>
      <description>&lt;p&gt;&lt;font color="#FF0000"&gt;&lt;strong&gt;Please do not run any tools unless instructed to do so.&lt;/strong&gt; &lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;font color="#FF0000"&gt;&lt;strong&gt;Please read every post completely before doing anything.&lt;/strong&gt; &lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Pay special attention to the &lt;strong&gt;NOTE:&lt;/strong&gt; lines, these entries identify an individual issue or important step in the cleanup process.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be &lt;strong&gt;patient&lt;/strong&gt; while I analyze any logs you post. &lt;strong&gt;Please remember&lt;/strong&gt;, I am a &lt;font color="#FF0000"&gt;&lt;strong&gt;volunteer&lt;/strong&gt;&lt;/font&gt;, and I do have a life outside of these forum, (sometimes &lt;img border="0" alt=":smileylol:" src="http://norton.i.lithium.com/i/smilies/16x16_smiley-lol.gif" title="Smiley LOL"&gt;)&lt;br&gt;&lt;br&gt;&lt;/li&gt;&lt;li&gt; &lt;strong&gt;Attention to detail is&lt;font color="#FF0000"&gt; important&lt;/font&gt;&lt;/strong&gt;&lt;font color="#FF0000"&gt;!&lt;/font&gt; Since I cannot see or directly interact with your computer &lt;strong&gt;I am dependent on you to &amp;quot;be my eyes&amp;quot; and provide as much information as you can regarding the current state of your computer.&lt;/strong&gt;&lt;br&gt;&lt;br&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;If you're not sure, or if something unexpected happens, do &lt;font color="#FF0000"&gt;NOT&lt;/font&gt; continue!&lt;/strong&gt; &lt;font color="#FF0000"&gt;&lt;strong&gt;Stop and ask!&lt;/strong&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;u&gt;&lt;font color="#FF0000"&gt;&lt;strong&gt;Please read carefully&lt;/strong&gt;&lt;/font&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;font color="#000000"&gt;&lt;span&gt;We may yet have to do this with a program without Windows loading as something is Blocking Programs from running etc. But we will try and log with this,&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;font color="#000000"&gt;&lt;span&gt;a)  &lt;/span&gt;&lt;/font&gt;Download OTL   h&lt;font color="#FF0000"&gt;&lt;strong&gt;xx&lt;/strong&gt;&lt;/font&gt;p://oldtimer.geekstogo.com/OTL.exe   (change the h&lt;font color="#FF0000"&gt;&lt;strong&gt;xx&lt;/strong&gt;&lt;/font&gt;p to h&lt;font color="#FF0000"&gt;&lt;strong&gt;tt&lt;/strong&gt;&lt;/font&gt;p) save it to your Desktop.  In Safe Mode if Need be.&lt;/p&gt;&lt;p&gt;Restart the Computer into &lt;strong&gt;Normal Mode &lt;/strong&gt;&lt;/p&gt;&lt;div class="lia-quilt-column lia-quilt-column-20 lia-quilt-column-right lia-quilt-column-main-right"&gt;&lt;div class="lia-quilt-column-alley lia-quilt-column-alley-right"&gt;&lt;div class="lia-message-body lia-component-body"&gt;&lt;div class="lia-message-body-content"&gt;&lt;p&gt;Double click on OTL.exe to run it.  Right click OTL.exe and select run as administator for Vista and Win 7.&lt;br&gt;&lt;br&gt;Click the &lt;strong&gt;Scan All Users&lt;/strong&gt; checkbox.&lt;/p&gt;&lt;p&gt;Change file age to&lt;strong&gt; 60 days&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;under &lt;img border="0" alt="" src="http://www.bleepstatic.com/fhost/uploads/0/customscanfix.png" title="" align="center"&gt; Copy and paste what is below between the lines&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;&lt;p&gt;drivers32&lt;br&gt;netsvcs&lt;br&gt;&amp;quot;%WinDir%\$NtUninstallKB*$.&amp;quot; /30&lt;br&gt;C:\Program Files\Common Files\ComObjects\*.* /s&lt;br&gt;%systemroot%\*. /mp /s&lt;br&gt;%systemroot%\*. /rp /s&lt;br&gt;%systemroot%\system32\*.dll /lockedfiles&lt;br&gt;%systemroot%\Tasks\*.job /lockedfiles&lt;br&gt;%systemroot%\system32\drivers\*.sys /lockedfiles&lt;br&gt;%systemroot%\System32\config\*.sav&lt;br&gt;%systemroot%\system32\drivers\*.sys /90&lt;br&gt;%SYSTEMDRIVE%\*.exe&lt;br&gt;/md5start&lt;br&gt;volsnap.sys&lt;br&gt;atapi.sys&lt;br&gt;explorer.exe&lt;br&gt;winlogon.exe&lt;br&gt;wininit.exe&lt;br&gt;/md5stop&lt;br&gt;hklm\software\clients\startmenuinternet|command /rs&lt;br&gt;hklm\software\clients\startmenuinternet|command /64 /rs&lt;/p&gt;&lt;hr&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Press the &lt;img border="0" alt="" src="http://www.bleepstatic.com/fhost/uploads/0/runscan.png" title="" align="center"&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;An OTL.txt will be created.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
      <pubDate>Sun, 13 May 2012 05:20:25 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/716994#M71639</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-13T05:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/716998#M71640</link>
      <description>&lt;p&gt;Thanks for helping me!  OTL.txt is attached as requested.&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 06:02:27 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/716998#M71640</guid>
      <dc:creator>armygirl44</dc:creator>
      <dc:date>2012-05-13T06:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717002#M71641</link>
      <description>&lt;p&gt;A 64 bit System, hmmmmm&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Do you have a Flash Drive??&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 06:14:14 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717002#M71641</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-13T06:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717004#M71642</link>
      <description>&lt;p&gt;Sure do! :)  It's got some stuff on it, but nothing that can't be replaced. What do you need me to do with it?&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 06:24:38 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717004#M71642</guid>
      <dc:creator>armygirl44</dc:creator>
      <dc:date>2012-05-13T06:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717010#M71643</link>
      <description>&lt;p&gt;Got to make sure the subsystems is untouched with anything linked to that.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Please download h&lt;strong&gt;&lt;font color="#FF0000"&gt;xx&lt;/font&gt;&lt;/strong&gt;p://download.bleepingcomputer.com/farbar/FRST64.exe  (change the h&lt;strong&gt;&lt;font color="#FF0000"&gt;xx&lt;/font&gt;&lt;/strong&gt;p to h&lt;strong&gt;&lt;font color="#FF0000"&gt;tt&lt;/font&gt;&lt;/strong&gt;p) and save it to a flash drive.&lt;br&gt;&lt;br&gt;Plug the flashdrive into the infected PC.&lt;br&gt;&lt;br&gt;Enter &lt;strong&gt;System Recovery Options&lt;/strong&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;To enter System Recovery Options from the Advanced Boot Options:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Restart the computer.&lt;/li&gt;&lt;li&gt;As soon as the BIOS is loaded begin tapping the&lt;strong&gt; F8&lt;/strong&gt; key until Advanced Boot Options appears.&lt;/li&gt;&lt;li&gt;Use the arrow keys to select the &lt;strong&gt;Repair your computer&lt;/strong&gt; menu item.&lt;/li&gt;&lt;li&gt;Choose your language settings, and then click &lt;strong&gt;Next&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;Select the operating system you want to repair, and then click &lt;strong&gt;Next&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;Select your user account and click &lt;strong&gt;Next&lt;/strong&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;strong&gt;On the System Recovery Options menu you will get the following options:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Startup Repair&lt;br&gt;System Restore&lt;br&gt;Windows Complete PC Restore&lt;br&gt;Windows Memory Diagnostic Tool&lt;br&gt;&lt;font color="#FF0000"&gt;Command Prompt&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Select &lt;font color="#FF0000"&gt;&lt;strong&gt;Command Prompt&lt;/strong&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;In the command window type in &lt;strong&gt;notepad&lt;/strong&gt; and press &lt;strong&gt;Enter&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;The notepad opens. Under File menu select &lt;strong&gt;Open&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;Select &amp;quot;Computer&amp;quot; and find your flash drive letter and close the notepad.&lt;/li&gt;&lt;li&gt;In the command window type &lt;strong&gt;&lt;font color="#FF0000"&gt;e&lt;/font&gt;:\frst.exe&lt;/strong&gt; (for x64 bit version type &lt;strong&gt;&lt;font color="#FF0000"&gt;e&lt;/font&gt;:\frst64&lt;/strong&gt;) and press &lt;strong&gt;Enter&lt;/strong&gt;&lt;br&gt;&lt;strong&gt;Note:&lt;/strong&gt; Replace letter &lt;font color="#FF0000"&gt;e&lt;/font&gt; with the drive letter of your flash drive.&lt;/li&gt;&lt;li&gt;The tool will start to run.&lt;/li&gt;&lt;li&gt;When the tool opens click Yes to disclaimer.&lt;/li&gt;&lt;li&gt;Press &lt;strong&gt;Scan&lt;/strong&gt; button.&lt;/li&gt;&lt;li&gt;It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 06:32:43 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717010#M71643</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-13T06:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717012#M71644</link>
      <description>&lt;p&gt;Next step in process.  OTL created another txt file called extras.txt that I just noticed.  It is attached, in case it is useful.&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 06:39:38 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717012#M71644</guid>
      <dc:creator>armygirl44</dc:creator>
      <dc:date>2012-05-13T06:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717014#M71645</link>
      <description>&lt;p&gt;The URL h&lt;strong&gt;&lt;font color="#ff0000"&gt;xx&lt;/font&gt;&lt;/strong&gt;p://download.bleepingcomputer.com/farbar/FRST64.ex​e leads to a 404 not found page.  Is there an alternative site for this download?&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 06:42:38 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717014#M71645</guid>
      <dc:creator>armygirl44</dc:creator>
      <dc:date>2012-05-13T06:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717016#M71646</link>
      <description>&lt;p&gt;hxxp://download.bleepingcomputer.com/farbar/FRST64.exe    (change the xx   to tt) did work for me&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;There is also a link on the first post here &lt;a href="http://www.bleepingcomputer.com/forums/topic452205.html/page__st__15" target="_blank"&gt;http://www.bleepingcomputer.com/forums/topic452205.html/page__st__15&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 07:00:22 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717016#M71646</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-13T07:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717018#M71647</link>
      <description>&lt;p&gt;Got it.  Log to follow.&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 07:00:33 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717018#M71647</guid>
      <dc:creator>armygirl44</dc:creator>
      <dc:date>2012-05-13T07:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717022#M71649</link>
      <description>&lt;p&gt;FRST.txt attached as requested.  Also - following the restart required after running FRST64.exe, and without any action on my part, Norton 360 reported that Trojan.tracur!gen2 had been detected and removed.  Am attaching the export of the security history from Norton 360, in case it is useful.&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 07:31:57 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717022#M71649</guid>
      <dc:creator>armygirl44</dc:creator>
      <dc:date>2012-05-13T07:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717024#M71650</link>
      <description>&lt;p&gt;Can you get the full details of this entry in the history  &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;5/13/2012 12:22 AM,High,wtzvdsv.dll (Trojan.Tracur!gen2) detected by Auto-Protect,Quarantined,Resolved - No Action&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Like location it was taken from.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 07:36:41 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717024#M71650</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-13T07:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717026#M71651</link>
      <description>&lt;p&gt;File insight says that the infected file was wtzvdsv.dll and that the file performed two actions.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;File actions dropbox says:&lt;/p&gt;&lt;p&gt;File:  c:\users\lauren\appdata\local\apple\adobe\wtzvdsv.dll&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Registry actions dropbox says:&lt;/p&gt;&lt;p&gt;Registry Run entry:  HKEY_USERS\S-1-5-21-4253071426-4000798264-1434264933-1006\Software\Microsoft\Windows\CurrentVersion\Run-&amp;gt;Adobe&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;File insight also says it was removed,no further action needed.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Am guessing there are other steps required to ensure this issue is really resolved?&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 07:54:43 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717026#M71651</guid>
      <dc:creator>armygirl44</dc:creator>
      <dc:date>2012-05-13T07:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717034#M71653</link>
      <description>&lt;p&gt;It could be the parts leftover in the OTL log as locked and not found&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Now&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;1)  Uninstall Malwarebytes&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Then&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;2)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;u&gt;&lt;strong&gt;&lt;font color="#FF0000"&gt;Read all of this message first&lt;/font&gt;&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span&gt;Download Combofix &lt;a target="_blank" rel="nofollow" href="http://www.bleepingcomputer.com/download/anti-virus/combofix"&gt;http://www.bleepingcomputer.com/download/anti-virus/combofix&lt;/a&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;font color="#0000ff"&gt;&lt;span&gt;&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Ensure that Combofix is saved directly to the Desktop &lt;strong&gt;&lt;font color="red"&gt;&amp;lt;--- Very important&lt;/font&gt;&lt;/strong&gt;&lt;br&gt;&lt;br&gt;&lt;/li&gt;&lt;li&gt;Disable all security programs as they will have a negative effect on Combofix,&lt;/li&gt;&lt;li&gt;Close any open browsers and any other programs you might have running&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Doiwnload the attached CFscript.txt, , For some browsers Right Click the attachment on the forum and select &amp;quot;Save AS&amp;quot; or similar to Download it. See screenshot below.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;img alt="Right Click download.jpg" border="0" title="Right Click download.jpg" src="http://community.norton.com/t5/image/serverpage/image-id/27895i84874E73F6694185/image-size/original?v=mpbl-1&amp;amp;px=-1" align="center"&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;font color="#FF0000"&gt;Now  drag the CFScript.txt into the ComboFix.exe  &lt;/font&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;font color="#000000"&gt;&lt;span&gt;&lt;span&gt;&lt;img alt="" border="0" title="" src="http://thespykiller.co.uk/images/CFScriptB.gif" align="center"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000"&gt;&lt;span&gt;&lt;span&gt;&lt;br&gt;&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;If you are using windows XP It might display a pop up saying that &amp;quot;Recovery console is not installed, do you want to install?&amp;quot; Please select yes &amp;amp; let it download the files it needs to do this. Once the recovery console is installed Combofix will then offer to scan for malware. Select continue or yes.&lt;/li&gt;&lt;li&gt;When finished, it will produce a report for you. Please post the &amp;quot;C:\ComboFix.txt&amp;quot; for further review&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;strong&gt;&lt;font color="red"&gt;****&lt;/font&gt;&lt;/strong&gt;&lt;strong&gt;&lt;font color="blue"&gt;Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze&lt;/font&gt;&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;&lt;strong&gt;&lt;font color="red"&gt;****&lt;/font&gt;&lt;/strong&gt;&lt;br&gt;&lt;br&gt;&lt;span&gt;Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.&lt;/span&gt;&lt;br&gt;&lt;span&gt;Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal &amp;amp; increase security.&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;span&gt;*EXTRA NOTES*&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.&lt;/li&gt;&lt;li&gt;If Combofix reboot's due to a rootkit, the screen may stay black for several minutes on reboot, this is normal&lt;/li&gt;&lt;li&gt;If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 08:07:37 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717034#M71653</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-13T08:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717044#M71654</link>
      <description>&lt;p&gt;Disabled security programs and closed open programs, then downloaded ComboFix and the CFScript.txt file to the desktop as directed.  When I drag the script onto the ComboFix icon, a small window appears, numerous lines scroll past, and then that window closes.  A few seconds later, another slightly bigger blue window opens (header says &amp;quot;Administrator&amp;quot;) and then a dialog box appears with the following message:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;CFScript Name Error&lt;/p&gt;&lt;p&gt;Were you trying to run CFScript?&lt;/p&gt;&lt;p&gt;The name, CFScript appears to be incorrectly spelt&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The program did not ask about a recovery console or a malware scan, and no combofix.txt file was generated after the error message was closed.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Did I miss a step?&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 08:48:50 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717044#M71654</guid>
      <dc:creator>armygirl44</dc:creator>
      <dc:date>2012-05-13T08:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717224#M71665</link>
      <description>&lt;p&gt;Also, Norton 360 is now giving me an error message (code 3040, 40018 - conflict with another security program) when I try to access the security history, and recommends installing v6 as the fix.  Not sure what the conflict is - removed mbam as previously directed.  Have not been able to find any other way to access the security history, and did not yet install the new version of 360 pending your further instruction.&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 19:55:24 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717224#M71665</guid>
      <dc:creator>armygirl44</dc:creator>
      <dc:date>2012-05-13T19:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Browser redirect issues - possible Happili infection? (help, Quads...)</title>
      <link>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717230#M71667</link>
      <description>&lt;p&gt;Take Combofix.exe  and rename it to something like  Badfile.exe and see if that works.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sun, 13 May 2012 20:07:23 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Browser-redirect-issues-possible-Happili-infection-help-Quads/m-p/717230#M71667</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-13T20:07:23Z</dc:date>
    </item>
  </channel>
</rss>

