<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: happili.com virus help in Norton Internet Security / Norton AntiVirus</title>
    <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/692899#M200316</link>
    <description>&lt;p&gt;What exactly is a Bootkit by the way?&lt;/p&gt;</description>
    <pubDate>Wed, 04 Apr 2012 22:42:07 GMT</pubDate>
    <dc:creator>Keyboard</dc:creator>
    <dc:date>2012-04-04T22:42:07Z</dc:date>
    <item>
      <title>happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688227#M199595</link>
      <description>&lt;p&gt;I have the happili.com virus on my computer.  I would appreciate any help in getting this removed. I cant Use my Keyboard.    Downloaded TDSSKiller.  did  not detect anything. I downloaded and ran the ComboFix.exe. The script           ComboFix 12-03-29.02 - Dan and Yulichka 03/29/2012  17:18:16.1.2 - x86 .. . .. .Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3316.1777 [GMT -4:00] Running from: c:\users\Dan and Yulichka\Desktop\ComboFix.exe AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((((((   Other Deletions   ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\Downloaded Program Files\IDropPTB.dll . . (((((((((((((((((((((((((   Files Created from 2012-02-28 to 2012-03-29  ))))))))))))))))))))))))))))))) . . 2012-03-29 21:08 . 2012-03-29 21:08 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2C0C1B1F-4B6D-43A5-A913-9AD74EF322E5}\offreg.dll 2012-03-29 20:43 . 2012-03-29 20:43 -------- d-----w- c:\users\Dan and Yulichka\AppData\Roaming\Tific 2012-03-29 05:21 . 2012-03-29 08:12 -------- d-----w- C:\NBRT 2012-03-29 00:45 . 2009-06-12 11:18 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-03-29 00:44 . 2012-03-29 00:44 -------- d-----w- c:\windows\system32\drivers\NBRTWizard 2012-03-29 00:44 . 2012-03-29 00:44 -------- d-----w- c:\program files\Norton Bootable Recovery Tool Wizard 2012-03-28 23:52 . 2012-03-29 00:18 -------- d-----w- c:\users\Dan and Yulichka\AppData\Local\NPE 2012-03-27 22:48 . 2012-03-27 22:48 -------- d-----w- c:\users\Dan and Yulichka\AppData\Roaming\QuickScan 2012-03-27 22:47 . 2012-03-27 22:49 -------- d-----w- c:\programdata\SmartPCScan 2012-03-27 22:41 . 2012-03-27 22:41 -------- d-----w- c:\users\Dan and Yulichka\AppData\Roaming\Malwarebytes 2012-03-27 22:41 . 2012-03-27 22:41 -------- d-----w- c:\programdata\Malwarebytes 2012-03-27 22:41 . 2011-12-10 19:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-03-27 22:41 . 2012-03-27 22:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-03-27 22:29 . 2012-03-14 02:15 6582328 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2C0C1B1F-4B6D-43A5-A913-9AD74EF322E5}\mpengine.dll 2012-03-27 10:23 . 2012-03-27 10:23 -------- d-----w- C:\N360_BACKUP 2012-03-26 20:15 . 2012-03-26 20:15 -------- d-----w- C:\6cd7a14f8dd9e6bd8dba1c00a2 2012-03-26 00:09 . 2012-03-26 00:09 -------- d-----w- c:\users\Dan and Yulichka\AppData\Roaming\Ukpazuy 2012-03-26 00:09 . 2012-03-26 00:09 -------- d-----w- c:\users\Dan and Yulichka\AppData\Roaming\Yfuhhou 2012-03-13 22:18 . 2012-02-02 15:16 2044416 ----a-w- c:\windows\system32\win32k.sys 2012-03-13 22:18 . 2012-02-14 15:45 219648 ----a-w- c:\windows\system32\d3d10_1core.dll 2012-03-13 22:18 . 2012-02-14 15:45 160768 ----a-w- c:\windows\system32\d3d10_1.dll 2012-03-13 22:18 . 2012-02-13 14:12 1172480 ----a-w- c:\windows\system32\d3d10warp.dll 2012-03-13 22:18 . 2012-02-13 13:47 683008 ----a-w- c:\windows\system32\d2d1.dll 2012-03-13 22:18 . 2012-02-13 13:44 1068544 ----a-w- c:\windows\system32\DWrite.dll 2012-03-13 22:18 . 2012-01-31 10:59 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat 2012-03-13 22:17 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll 2012-03-13 22:17 . 2012-01-09 13:58 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-04 08:01 . 2012-03-04 08:01 -------- d-----w- c:\program files\MSXML 4.0 2012-03-03 00:21 . 2012-03-03 00:21 -------- d-----w- c:\users\Dan and Yulichka\AppData\Local\GrantaGateway 2012-03-03 00:20 . 2012-03-03 00:20 -------- d-----w- c:\programdata\FLEXnet 2012-03-02 23:45 . 2012-03-04 17:51 -------- d-----w- c:\users\Dan and Yulichka\AppData\Local\Autodesk 2012-03-02 23:39 . 2012-03-02 23:39 -------- d-----w- c:\program files\Common Files\Macrovision Shared 2012-03-02 23:35 . 2012-03-02 23:35 -------- d-----w- C:\MITSI 2012 Temporary Files 2012-03-02 23:34 . 2012-03-02 23:34 -------- d-----w- c:\program files\Microsoft Chart Controls 2012-03-02 23:33 . 2012-03-02 23:33 -------- d-----w- c:\program files\Microsoft WSE 2012-03-02 23:32 . 2009-09-04 22:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll 2012-03-02 23:32 . 2009-09-04 22:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll 2012-03-02 23:32 . 2009-09-04 22:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll 2012-03-02 23:32 . 2009-09-04 22:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll 2012-03-02 23:32 . 2009-09-04 22:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll 2012-03-02 23:26 . 2012-03-02 23:53 -------- d-----w- c:\program files\Common Files\Autodesk Shared 2012-03-02 23:26 . 2012-03-02 23:52 -------- d-----w- c:\program files\Autodesk 2012-03-02 21:36 . 2012-03-14 23:49 -------- d-----w- c:\users\Dan and Yulichka\AppData\Roaming\Autodesk 2012-03-02 21:36 . 2012-03-14 23:49 -------- d-----w- c:\programdata\Autodesk 2012-03-02 11:46 . 2012-03-02 11:46 -------- d-----w- C:\Autodesk 2012-03-01 21:24 . 2012-03-01 21:25 -------- d-----w- c:\users\Dan and Yulichka\AppData\Local\Akamai . . . ((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-02-23 13:18 . 2010-11-27 01:16 237072 ------w- c:\windows\system32\MpSigStub.exe 2012-01-04 00:59 . 2011-12-30 00:11 163616 ----a-w- c:\windows\system32\drivers\DigiartyVirtualCDBus.sys 2012-01-04 00:03 . 2012-01-02 20:34 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . . (((((((((((((((((((((((((((((((((((((   Reg Loading Points   )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries &amp;amp; legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] &amp;quot;Sidebar&amp;quot;=&amp;quot;c:\program files\Windows Sidebar\sidebar.exe&amp;quot; [2009-04-11 1233920] &amp;quot;ehTray.exe&amp;quot;=&amp;quot;c:\windows\ehome\ehTray.exe&amp;quot; [2008-01-19 125952] &amp;quot;WMPNSCFG&amp;quot;=&amp;quot;c:\program files\Windows Media Player\WMPNSCFG.exe&amp;quot; [2008-01-19 202240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] &amp;quot;QuickTime Task&amp;quot;=&amp;quot;c:\program files\QuickTime\QTTask.exe&amp;quot; [2010-09-08 421888] &amp;quot;IgfxTray&amp;quot;=&amp;quot;c:\windows\system32\igfxtray.exe&amp;quot; [2008-02-12 141848] &amp;quot;HotKeysCmds&amp;quot;=&amp;quot;c:\windows\system32\hkcmd.exe&amp;quot; [2008-02-12 166424] &amp;quot;Persistence&amp;quot;=&amp;quot;c:\windows\system32\igfxpers.exe&amp;quot; [2008-02-12 133656] &amp;quot;CanonMyPrinter&amp;quot;=&amp;quot;c:\program files\Canon\MyPrinter\BJMyPrt.exe&amp;quot; [2007-09-14 1603152] &amp;quot;Adobe ARM&amp;quot;=&amp;quot;c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&amp;quot; [2012-01-03 843712] &amp;quot;Garmin Lifetime Updater&amp;quot;=&amp;quot;c:\program files\Garmin\Lifetime Updater\GarminLifetime.exe&amp;quot; [2011-12-15 1446248] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] &amp;quot;EnableUIADesktopToggle&amp;quot;= 0 (0x0) . S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - 36597832 *Deregistered* - 36597832 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ    FontCache . Contents of the 'Scheduled Tasks' folder . 2012-03-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-01-02 20:34] . 2012-03-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-01-02 20:34] . . ------- Supplementary Scan ------- . uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB . . ------- File Associations ------- . .scr=DWGTrueViewScriptFile . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &lt;a target="_blank" href="http://www.gmer.net"&gt;http://www.gmer.net&lt;/a&gt; Rootkit scan 2012-03-29 17:25 Windows 6.0.6002 Service Pack 2 NTFS . scanning hidden processes ...  . scanning hidden autostart entries ... . scanning hidden files ...  . scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360] &amp;quot;ImagePath&amp;quot;=&amp;quot;\&amp;quot;c:\program files\Norton 360\Engine\4.4.0.12\ccSvcHst.exe\&amp;quot; /s \&amp;quot;N360\&amp;quot; /m \&amp;quot;c:\program files\Norton 360\Engine\4.4.0.12\diMaster.dll\&amp;quot; /prefetch:1&amp;quot; . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) &amp;quot;BlindDial&amp;quot;=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) &amp;quot;BlindDial&amp;quot;=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) &amp;quot;BlindDial&amp;quot;=dword:00000000 . Completion time: 2012-03-29  17:28:54 ComboFix-quarantined-files.txt  2012-03-29 21:28 . Pre-Run: 35,618,500,608 bytes free Post-Run: 35,776,946,176 bytes free . - - End Of File - - 93CCBFAD6D30091661A4D4EEF8372873  &lt;/p&gt;</description>
      <pubDate>Thu, 29 Mar 2012 22:02:24 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688227#M199595</guid>
      <dc:creator>Keyboard</dc:creator>
      <dc:date>2012-03-29T22:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688251#M199601</link>
      <description>&lt;p&gt;You can attach logs to posts instead of the likes of that jumbled mess.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Do not use Advanced programs like combofix without supervision they are dangerous.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I suspect I can see what is wrong, &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Thu, 29 Mar 2012 22:26:59 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688251#M199601</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-03-29T22:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688551#M199643</link>
      <description>&lt;p&gt;I have to try and figure out which driver has gone missing or is corrupt / infected&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;1.  Download OTL   h&lt;strong&gt;&lt;font color="#FF0000"&gt;xx&lt;/font&gt;&lt;/strong&gt;p://oldtimer.geekstogo.com/OTL.exe   (change the h&lt;font color="#FF0000"&gt;&lt;strong&gt;xx&lt;/strong&gt;&lt;/font&gt;p to h&lt;font color="#FF0000"&gt;&lt;strong&gt;tt&lt;/strong&gt;&lt;/font&gt;p) save it to your Desktop.&lt;/p&gt;&lt;p&gt;Double click on OTL.exe to run it.  Right click OTL.exe and select run as administator for Vista and Win 7.&lt;br&gt;&lt;br&gt;Click the &lt;strong&gt;Scan All Users&lt;/strong&gt; checkbox.&lt;/p&gt;&lt;p&gt;Change file age to&lt;strong&gt; 60 days&lt;/strong&gt;&lt;br&gt;Click on Run Scan at the top left hand corner.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Post back the  log &lt;strong&gt;OTL.txt &lt;/strong&gt;(attach)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Download h&lt;font color="#FF0000"&gt;&lt;strong&gt;xx&lt;/strong&gt;&lt;/font&gt;p://download.bleepingcomputer.com/farbar/FSS.exe  (change the h&lt;strong&gt;&lt;font color="#FF0000"&gt;xx&lt;/font&gt;&lt;/strong&gt;p to h&lt;font color="#FF0000"&gt;&lt;strong&gt;tt&lt;/strong&gt;&lt;/font&gt;p) and run it on the computer with the issue. On the desktop.&lt;/p&gt;&lt;p&gt;&lt;span&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Make sure the following options are checked:&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;strong&gt;Internet Services&lt;/strong&gt;&lt;br&gt;&lt;strong&gt;Windows Firewall&lt;/strong&gt;&lt;br&gt;&lt;strong&gt;System Restore&lt;/strong&gt;&lt;br&gt;&lt;strong&gt;Security Center/Action Center&lt;/strong&gt;&lt;br&gt;&lt;strong&gt;Windows Update&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Press &amp;quot;&lt;strong&gt;Scan&lt;/strong&gt;&amp;quot;.&lt;br&gt;It will create a log (FSS.txt) in the same directory the tool is run.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 12:09:18 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688551#M199643</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-03-30T12:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688561#M199644</link>
      <description>&lt;p&gt;Quads,&lt;/p&gt;&lt;p&gt;Thanks for jumping onto this thread. I am on my work computer now (with a keyboard that works) but even this one is giving me a hard time because my work's computer security loads the Norton webpages painfully slow. I had to copy and paste individual letters to make the first few sentences of my last post.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;A better summary of what happened:&lt;/p&gt;&lt;p&gt;I think I got the virus from watching a TV show online, started getting redirects to &amp;quot;Happili.com&amp;quot; and my computer was running very slow.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I did a Norton Scan (Norton 360), which detected nothing.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I did the Windows Malware Scan, which detected and removed 3 different malwares (Harnig.B and two others, can't remember but I have it written down at home)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I then did malwarebytes, which detected some more malware which I think it removed. I don't know if I still have that log.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I then used Norton Power Eraser, that detected some trojans.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;At this point, the computer was working faster but google wouldn't search at all.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I then used the Norton Reboot program (for the infections that are so bad your computer wont start). It found 1 trojan.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;That is when my keyboard stopped working.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I then ran TDSSKiller, which found nothing and then ComboFix. Combofix found 1 malware as shown in my post.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I checked my keyboard hardware in the Windows Control Panel, it looks like the driver has been erased because windows doesn't detect any plugged in keyboard. Not sure how to fix that one.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads, Again thanks for jumping onto the thread. I see you are very thorough in solving all the problems, and I will attach logs from now on. If you can provide some help it would be greatly appreciated.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;On a side note, is it safe to back up files from my computer (pictures and music) onto my removable hard disk? Or will it just infect the hard disk? I figure as a worst case scenario I could just wipe my hard drive but I don't think that is necessary.&lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 12:27:09 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688561#M199644</guid>
      <dc:creator>Keyboard</dc:creator>
      <dc:date>2012-03-30T12:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688565#M199646</link>
      <description>&lt;p&gt;Why are people determined to do this when they don't know what they are doing, Geez&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;&lt;p&gt;I did the Windows Malware Scan, which detected and removed 3 different malwares (Harnig.B and two others, can't remember but I have it written down at home)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I then did malwarebytes, which detected some more malware which I think it removed. I don't know if I still have that log.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I then used Norton Power Eraser, that detected some trojans.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;At this point, the computer was working faster but google wouldn't search at all.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I then used the Norton Reboot program (for the infections that are so bad your computer wont start). It found 1 trojan.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;That is when my keyboard stopped working.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I then ran TDSSKiller, which found nothing and then ComboFix. Combofix found 1 malware  &lt;font color="#FF0000"&gt;Combofix does not detect Malware as such&lt;/font&gt;&lt;/p&gt;&lt;hr&gt;&lt;p&gt;&lt;font color="#FF0000"&gt;&lt;br&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 12:37:37 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688565#M199646</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-03-30T12:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688575#M199650</link>
      <description>&lt;p&gt;&amp;quot;Why are people determined to do this when they don't know what they are doing, Geez&amp;quot;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads,&lt;/p&gt;&lt;p&gt;I admit stupidity on my part with the shoot-from-the-hips action of installing some of the tools developed by masters of the computer engineering and programming world. In my frustration, I did something stupid that could have caused a lot of damage and I admit fault. I also admit I don't understand the full use of combofix. I will follow only your instruction and those instructions to a tee.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Anything on how I can at least use my keyboard? The copy and paste of individual letters is quite frustrating.&lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 13:15:33 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688575#M199650</guid>
      <dc:creator>Keyboard</dc:creator>
      <dc:date>2012-03-30T13:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688843#M199672</link>
      <description>&lt;p&gt;Are you using a USB or PS/2 keyboard??&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 21:12:12 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688843#M199672</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-03-30T21:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688887#M199684</link>
      <description>&lt;p&gt;ps2&lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 22:01:40 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688887#M199684</guid>
      <dc:creator>Keyboard</dc:creator>
      <dc:date>2012-03-30T22:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688893#M199685</link>
      <description>&lt;p&gt;Try a USB keyboard, or  turn on the Vista on screen keyboard for now.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I will need the Malware bytes log to.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;It may be easier to have NBRT and Malwarebytes restore / undo the objects, including the driver back even though it's infected, and then have the infection removed correctly.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 22:08:11 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688893#M199685</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-03-30T22:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688909#M199687</link>
      <description>&lt;p&gt;OTL logfile  &lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 22:13:42 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688909#M199687</guid>
      <dc:creator>Keyboard</dc:creator>
      <dc:date>2012-03-30T22:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688915#M199688</link>
      <description>&lt;p&gt;Farbar Service Scanner&lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 22:21:04 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688915#M199688</guid>
      <dc:creator>Keyboard</dc:creator>
      <dc:date>2012-03-30T22:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688919#M199689</link>
      <description>&lt;p&gt;Bugger, doesn't show which file has gone missing,  Do you remember which one was removed??&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Like say &amp;quot;i8042prt.sys&amp;quot;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 22:24:33 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688919#M199689</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-03-30T22:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688927#M199692</link>
      <description>&lt;p&gt;Don't remember which one was removed&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 22:39:07 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688927#M199692</guid>
      <dc:creator>Keyboard</dc:creator>
      <dc:date>2012-03-30T22:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688931#M199693</link>
      <description>&lt;p&gt;&amp;quot;I then used the Norton Reboot program (for the infections that are so bad your computer wont start). It found 1 trojan.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;That is when my keyboard stopped working.&amp;quot;&lt;/p&gt;&lt;hr&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Start the program and have it restore the driver it took.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 22:43:59 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688931#M199693</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-03-30T22:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688939#M199695</link>
      <description>&lt;p&gt;I wrote some Down. .&lt;/p&gt;&lt;p align="justify"&gt;&lt;font size="2"&gt;PUp.bundle.offers.llq&lt;/font&gt;&lt;/p&gt;&lt;p align="justify"&gt;&lt;font size="2"&gt;sDBot&lt;/font&gt;&lt;/p&gt;&lt;p align="justify"&gt;&lt;font size="2"&gt;zonebac.b&lt;/font&gt;&lt;/p&gt;&lt;p align="justify"&gt;&lt;font size="2"&gt;Harnig.bt&lt;/font&gt;&lt;/p&gt;&lt;p align="justify"&gt; &lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 22:55:43 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688939#M199695</guid>
      <dc:creator>Keyboard</dc:creator>
      <dc:date>2012-03-30T22:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688943#M199696</link>
      <description>&lt;p&gt;That is not the file name, you have to get the program to in the history Undo what it did, thus putting the file back in the folder.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Fri, 30 Mar 2012 22:58:54 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/688943#M199696</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-03-30T22:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/689239#M199742</link>
      <description>&lt;p&gt;reran Norton  Bootable Recovery Tool Wizard. did  not detect anything. no Keyboard. redirects to happili.com seem to have stopped.&lt;/p&gt;</description>
      <pubDate>Sat, 31 Mar 2012 13:27:26 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/689239#M199742</guid>
      <dc:creator>Keyboard</dc:creator>
      <dc:date>2012-03-31T13:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/689315#M199759</link>
      <description>&lt;p&gt;I get an error  on  start Up. [RunDll......error  loading......c:\windows\system32\Config\systemprofile\Appdata\roaming\Microsoft\Microsoft\xqsnxwgl.Dll......Access is Denied.&lt;/p&gt;</description>
      <pubDate>Sat, 31 Mar 2012 15:52:50 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/689315#M199759</guid>
      <dc:creator>Keyboard</dc:creator>
      <dc:date>2012-03-31T15:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/689549#M199802</link>
      <description>&lt;p&gt;I told you to have the program UNDO (put back) what it removed the last time.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sun, 01 Apr 2012 00:54:33 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/689549#M199802</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-04-01T00:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: happili.com virus help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/689589#M199816</link>
      <description>&lt;p&gt;how do i make the program undo it? it runs as a boot disk. hould i just download a driver for the eyboard?&lt;/p&gt;</description>
      <pubDate>Sun, 01 Apr 2012 02:51:29 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/happili-com-virus-help/m-p/689589#M199816</guid>
      <dc:creator>Keyboard</dc:creator>
      <dc:date>2012-04-01T02:51:29Z</dc:date>
    </item>
  </channel>
</rss>

