<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Another Zeroaccess!inf infection in Norton Internet Security / Norton AntiVirus</title>
    <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/715056#M203010</link>
    <description>&lt;p&gt;Yes. ESET is now removed.&lt;/p&gt;</description>
    <pubDate>Thu, 10 May 2012 01:09:29 GMT</pubDate>
    <dc:creator>BudBullets</dc:creator>
    <dc:date>2012-05-10T01:09:29Z</dc:date>
    <item>
      <title>Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/711513#M202606</link>
      <description>&lt;p&gt;I am using Windows XP professional with Service Pack 3 on an Compaq V6000 (x86). Norton picked up the Zeroaccess infection and recommends manual removal.  It looks like I have 2 infected files:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;C:\windows\system32\tshwmdtcp.dll&lt;/p&gt;&lt;p&gt;C:\windows\system32\parport.dll&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Any  help would be appreciated.&lt;/p&gt;</description>
      <pubDate>Sat, 05 May 2012 00:28:52 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/711513#M202606</guid>
      <dc:creator>BudBullets</dc:creator>
      <dc:date>2012-05-05T00:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/711525#M202611</link>
      <description>&lt;p&gt;&lt;font color="#FF0000"&gt;&lt;strong&gt;&lt;span&gt;&lt;span&gt;Please do not run any tools unless instructed to do so&lt;/span&gt;&lt;/span&gt;.&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;font color="#FF0000"&gt;&lt;strong&gt;&lt;span&gt;&lt;span&gt;Please read every post completely before doing anything&lt;/span&gt;&lt;/span&gt;.&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Pay special attention to the &lt;span&gt;&lt;span&gt;&lt;strong&gt;NOTE:&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt; lines, these entries identify an individual issue or important step in the cleanup process.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;u&gt;&lt;font color="#FF0000"&gt;&lt;strong&gt;Please read carefully&lt;/strong&gt;&lt;/font&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span&gt;1. Please download aswMBR h&lt;/span&gt;&lt;strong&gt;&lt;font color="#FF0000"&gt;xx&lt;/font&gt;&lt;/strong&gt;&lt;span&gt;p://public.avast.com/~gmerek/aswMBR.exe to your desktop. (replace the h&lt;/span&gt;&lt;strong&gt;&lt;font color="#FF0000"&gt;xx&lt;/font&gt;&lt;/strong&gt;&lt;span&gt;p with h&lt;/span&gt;&lt;strong&gt;&lt;font color="#FF0000"&gt;tt&lt;/font&gt;&lt;/strong&gt;&lt;span&gt;p)&lt;/span&gt;&lt;br&gt;&lt;span&gt;Double click the aswMBR.exe icon to run it&lt;/span&gt;&lt;br&gt;&lt;span&gt;it will ask to download extra definitions - &lt;/span&gt;&lt;font color="#FF0000"&gt;ALLOW IT / Yes&lt;/font&gt;&lt;br&gt;&lt;span&gt;Click the Scan button to start the scan&lt;/span&gt;&lt;br&gt;&lt;span&gt;On completion of the scan, click the save log button, save it to your desktop and &lt;/span&gt;&lt;strong&gt;Please attach the log in the post back, Don't have the program fix anything.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sat, 05 May 2012 00:47:08 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/711525#M202611</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-05T00:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/711847#M202648</link>
      <description>&lt;p&gt;Attached is the log file.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I did not run any Tools, but Norton AutoProtect was on.  The AutoProtect did pop up a message regarding backdoor.tidserv while scanning.  Do I need to disable or Uninstall Norton and rescan? I also have SpyBot and Malwarebytes (and an outdated ESET package) installed.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thanks for the help.&lt;/p&gt;</description>
      <pubDate>Sat, 05 May 2012 12:46:31 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/711847#M202648</guid>
      <dc:creator>BudBullets</dc:creator>
      <dc:date>2012-05-05T12:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712501#M202699</link>
      <description>&lt;p&gt;Uninstall Spybot S&amp;amp;D&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sun, 06 May 2012 05:27:54 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712501#M202699</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-06T05:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712765#M202712</link>
      <description>&lt;p&gt;I have uninstalled Spybot and rebooted.&lt;/p&gt;</description>
      <pubDate>Sun, 06 May 2012 16:21:47 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712765#M202712</guid>
      <dc:creator>BudBullets</dc:creator>
      <dc:date>2012-05-06T16:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712909#M202731</link>
      <description>&lt;p&gt;Ok, and I know the Windows driver involved, just in case.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span&gt;Please read carefully and follow these steps.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;span&gt;Download TDSSKiller from &lt;a target="_blank" rel="nofollow" href="http://support.kaspersky.com/faq/?qid=208280684"&gt;http://support.kaspersky.com/faq/?qid=208280684&lt;/a&gt;  click on the TDSSkiller.exe green link.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Double click on TDSSKiller.exe to run the application,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Open the Change Parameters option and select the detect TDLsystem&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Then on Start Scan.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;span&gt;If an infected file is detected, the default action will be Cure, click on Continue.&lt;/span&gt;&lt;br&gt;&lt;span&gt;If a suspicious file is detected, the default action will be Skip, click on Continue.&lt;/span&gt;&lt;br&gt;&lt;span&gt;It may ask you to reboot the computer to complete the process. Click on Reboot Now.&lt;/span&gt;&lt;br&gt;&lt;span&gt;If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.&lt;/span&gt;&lt;br&gt;&lt;span&gt;If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of &amp;quot;TDSSKiller.[Version]_[Date]_[Time]_log.txt&amp;quot;. &lt;/span&gt;&lt;strong&gt;Please attach the log in the post back&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Mon, 07 May 2012 00:08:21 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712909#M202731</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-07T00:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712925#M202733</link>
      <description>&lt;p&gt;I did the scan and it found two &amp;quot;threats&amp;quot; . The default action is delete. Should I delete?&lt;/p&gt;</description>
      <pubDate>Mon, 07 May 2012 00:40:19 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712925#M202733</guid>
      <dc:creator>BudBullets</dc:creator>
      <dc:date>2012-05-07T00:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712927#M202734</link>
      <description>&lt;p&gt;What are they as you have not given a log.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Mon, 07 May 2012 00:42:13 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712927#M202734</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-07T00:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712935#M202736</link>
      <description>&lt;p&gt;Sorry, I wasn't sure if &amp;quot;cure&amp;quot; was the same as &amp;quot;delete&amp;quot; as a default option.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Backdoor.Multi.ZAccess.gen&lt;/p&gt;&lt;p&gt;Service:lvsrvlauncher&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Backdoor. Multi.Zaccess.gen&lt;/p&gt;&lt;p&gt;Service: venturi2&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Both with default action set to Delete.&lt;/p&gt;</description>
      <pubDate>Mon, 07 May 2012 00:51:08 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712935#M202736</guid>
      <dc:creator>BudBullets</dc:creator>
      <dc:date>2012-05-07T00:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712937#M202737</link>
      <description>&lt;p&gt;Yes you can have TDSSkiller delete the 2 services, It's similar to the Oak Technology version.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Mon, 07 May 2012 00:56:03 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712937#M202737</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-07T00:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712949#M202741</link>
      <description>&lt;p&gt;Ok. Deleted and rebooted. Log is attached. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Norton Autoprotect came on while it was deleting and gave a message about proteting from 2 threats. Not sure if its relevant.&lt;/p&gt;</description>
      <pubDate>Mon, 07 May 2012 01:12:17 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712949#M202741</guid>
      <dc:creator>BudBullets</dc:creator>
      <dc:date>2012-05-07T01:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712957#M202743</link>
      <description>&lt;p&gt;Norton may have deleted the files after the infection was broken.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;20:37:00.0292 2484 lvsrvlauncher (11028c6a84a967070cb1286550f2058f) C:\WINDOWS\system32\parport.dll&lt;br&gt;20:37:00.0417 2484 Suspicious file (NoAccess): C:\WINDOWS\system32\parport.dll. md5: 11028c6a84a967070cb1286550f2058f&lt;br&gt;20:37:00.0417 2484 lvsrvlauncher ( Backdoor.Multi.ZAccess.gen ) - infected&lt;br&gt;20:37:00.0417 2484 lvsrvlauncher - detected Backdoor.Multi.ZAccess.gen (0)&lt;/p&gt;&lt;p&gt;20:37:12.0527 2484 venturi2 (11028c6a84a967070cb1286550f2058f) C:\WINDOWS\system32\TSHWMDTCP.dll&lt;br&gt;20:37:12.0589 2484 Suspicious file (NoAccess): C:\WINDOWS\system32\TSHWMDTCP.dll. md5: 11028c6a84a967070cb1286550f2058f&lt;br&gt;20:37:12.0589 2484 venturi2 ( Backdoor.Multi.ZAccess.gen ) - infected&lt;br&gt;20:37:12.0589 2484 venturi2 - detected Backdoor.Multi.ZAccess.gen (0)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;u&gt;&lt;strong&gt;&lt;font color="#FF0000"&gt;Read all of this message first&lt;/font&gt;&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span&gt;Download Combofix &lt;a target="_blank" rel="nofollow" href="http://www.bleepingcomputer.com/download/anti-virus/combofix"&gt;http://www.bleepingcomputer.com/download/anti-virus/combofix&lt;/a&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;font color="#0000ff"&gt;&lt;span&gt;&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Ensure that Combofix is saved directly to the Desktop &lt;strong&gt;&lt;font color="red"&gt;&amp;lt;--- Very important&lt;/font&gt;&lt;/strong&gt;&lt;br&gt;&lt;br&gt;&lt;/li&gt;&lt;li&gt;Disable all security programs as they will have a negative effect on Combofix,&lt;/li&gt;&lt;li&gt;Close any open browsers and any other programs you might have running&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Doiwnload the attached CFscript.txt, , For some browsers Right Click the attachment on the forum and select &amp;quot;Save AS&amp;quot; or similar to Download it.&lt;/p&gt;&lt;p&gt;&lt;span&gt;Now &lt;/span&gt;&lt;span&gt; drag the CFScript.txt into the ComboFix.exe  &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;font color="#000000"&gt;&lt;span&gt;&lt;span&gt;&lt;img alt="" border="0" src="http://thespykiller.co.uk/images/CFScriptB.gif" align="center" title=""&gt;&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000"&gt;&lt;span&gt;&lt;span&gt;&lt;br&gt;&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;If you are using windows XP It might display a pop up saying that &amp;quot;Recovery console is not installed, do you want to install?&amp;quot; Please select yes &amp;amp; let it download the files it needs to do this. Once the recovery console is installed Combofix will then offer to scan for malware. Select continue or yes.&lt;/li&gt;&lt;li&gt;When finished, it will produce a report for you. Please post the &amp;quot;C:\ComboFix.txt&amp;quot; for further review&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;strong&gt;&lt;font color="red"&gt;****&lt;/font&gt;&lt;/strong&gt;&lt;strong&gt;&lt;font color="blue"&gt;Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze&lt;/font&gt;&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;&lt;strong&gt;&lt;font color="red"&gt;****&lt;/font&gt;&lt;/strong&gt;&lt;br&gt;&lt;br&gt;&lt;span&gt;Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.&lt;/span&gt;&lt;br&gt;&lt;span&gt;Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal &amp;amp; increase security.&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;span&gt;*EXTRA NOTES*&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.&lt;/li&gt;&lt;li&gt;If Combofix reboot's due to a rootkit, the screen may stay black for several minutes on reboot, this is normal&lt;/li&gt;&lt;li&gt;If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Mon, 07 May 2012 01:21:28 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/712957#M202743</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-07T01:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/713009#M202747</link>
      <description>&lt;p&gt;Ran Combofix.  Attached is the log. Browser seems to working much better (faster).&lt;/p&gt;</description>
      <pubDate>Mon, 07 May 2012 03:04:27 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/713009#M202747</guid>
      <dc:creator>BudBullets</dc:creator>
      <dc:date>2012-05-07T03:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/713013#M202748</link>
      <description>&lt;p&gt;Read the instructions again you did not run the script properly, you had the script as &amp;quot;CFscript.txt 1 KB.URL&amp;quot;     you should have it as &amp;quot;CFscript.txt&amp;quot;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Mon, 07 May 2012 03:12:03 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/713013#M202748</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-07T03:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/713725#M202849</link>
      <description>&lt;p&gt;After the proper script name run, we still need to carry on cleaning the system.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Mon, 07 May 2012 19:46:47 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/713725#M202849</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-07T19:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/713819#M202866</link>
      <description>&lt;p&gt;Re-scanned with the correct file.&lt;/p&gt;</description>
      <pubDate>Mon, 07 May 2012 22:46:49 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/713819#M202866</guid>
      <dc:creator>BudBullets</dc:creator>
      <dc:date>2012-05-07T22:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/713857#M202876</link>
      <description>&lt;p&gt;That has taken care of the main Rootkit&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Now time to scan the hole system to find anything else before using another program to do the final script cleanup&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;u&gt;&lt;font color="#FF0000"&gt;&lt;strong&gt;Please read carefully&lt;/strong&gt;&lt;/font&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; Please scan with ESET next   Using&lt;strong&gt; Internet Explorer&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;strong&gt;I'd like us to scan your machine with ESET OnlineScan&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Hold down Control and click on the following link to open ESET OnlineScan in a new window.&lt;br&gt;&lt;a target="_blank" rel="nofollow external" title="External link" href="http://www.eset.com/us/online-scanner"&gt;ESET OnlineScan&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Click the &lt;img alt="Posted Image" border="0" src="http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetOnline.png"&gt; button.&lt;/li&gt;&lt;li&gt;For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)&lt;ul&gt;&lt;li&gt;Click on &lt;img alt="Posted Image" border="0" src="http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstall.png"&gt; to download the ESET Smart Installer. &lt;strong&gt;Save&lt;/strong&gt; it to your desktop.&lt;/li&gt;&lt;li&gt;Double click on the &lt;img alt="Posted Image" border="0" src="http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstallDesktopIcon.png"&gt; icon on your desktop.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Check &lt;img alt="Posted Image" border="0" src="http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetAcceptTerms.png"&gt;&lt;/li&gt;&lt;li&gt;Click the &lt;img alt="Posted Image" border="0" src="http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetStart.png"&gt; button.&lt;/li&gt;&lt;li&gt;Accept any security warnings from your browser.&lt;/li&gt;&lt;li&gt;Under &lt;em&gt;scan settings&lt;/em&gt;, check &lt;img alt="Posted Image" border="0" src="http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetScanArchives.png"&gt; and&lt;strong&gt;&lt;font color="#FF0000"&gt; DON'T (NO)&lt;/font&gt;&lt;/strong&gt; check &lt;strong&gt;Remove found threats&lt;/strong&gt; &lt;u&gt;&lt;font color="#FF0000"&gt;(reason for this is we don't want something deleted and then Windows won't load).&lt;/font&gt;&lt;/u&gt;&lt;/li&gt;&lt;li&gt;Click &lt;em&gt;Advanced settings&lt;/em&gt; and select the following:&lt;ul&gt;&lt;li&gt;&lt;span&gt;Scan potentially unwanted applications&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Scan for potentially unsafe applications&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Enable Anti-Stealth technology&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.&lt;/li&gt;&lt;li&gt;Attach the resulting log in your next reply&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;span&gt;If you think a log should have been generated then go to C:\Program Files\ESET\ESET Online Scanner\&lt;/span&gt;&lt;strong&gt;log.txt&lt;/strong&gt;&lt;span&gt; to find it. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span&gt;Quads&lt;/span&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 08 May 2012 00:50:07 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/713857#M202876</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-08T00:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/714111#M202905</link>
      <description>&lt;p&gt;Attached is the ESET log.&lt;/p&gt;</description>
      <pubDate>Tue, 08 May 2012 10:23:06 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/714111#M202905</guid>
      <dc:creator>BudBullets</dc:creator>
      <dc:date>2012-05-08T10:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/714353#M202929</link>
      <description>&lt;p&gt;Ok&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;1)  Go into the Add / Remove Programs and select to shows Windows updates, so they are now also listed.&lt;/p&gt;&lt;p&gt;     Find the update &lt;u&gt;&lt;font color="#FF0000"&gt;&lt;strong&gt;KB2536276-v2 &lt;/strong&gt;&lt;/font&gt;&lt;/u&gt;&lt;font color="#FF0000"&gt;&lt;font color="#000000"&gt;and uninstall it,  we will install a fresh copy later.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;font color="#FF0000"&gt;&lt;font color="#000000"&gt;2)  Go here &lt;a target="_blank" href="http://community.norton.com/t5/Norton-Internet-Security-Norton/GOOGLE-REDIRECTS-TO-http-abnow-com/m-p/686159/highlight/true#M199243"&gt;http://community.norton.com/t5/Norton-Internet-Security-Norton/GOOGLE-REDIRECTS-TO-http-abnow-com/m-p/686159/highlight/true#M199243&lt;/a&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#FF0000"&gt;&lt;font color="#000000"&gt;     Download to your desktop the XP_netsvcs.reg.txt   Right click the attachment link &lt;span&gt;nd select &amp;quot;Save Link as&amp;quot; then the dialog          box appears and you can take the .txt part off.  Then run the file and have the data added to the registry. &lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;3)  Download OTL   h&lt;font color="#FF0000"&gt;&lt;strong&gt;xx&lt;/strong&gt;&lt;/font&gt;p://oldtimer.geekstogo.com/OTL.exe   (change the h&lt;font color="#FF0000"&gt;&lt;strong&gt;xx&lt;/strong&gt;&lt;/font&gt;p to h&lt;font color="#FF0000"&gt;&lt;strong&gt;tt&lt;/strong&gt;&lt;/font&gt;p) save it to your Desktop.&lt;/p&gt;&lt;div class="lia-quilt-column lia-quilt-column-20 lia-quilt-column-right lia-quilt-column-main-right"&gt;&lt;div class="lia-quilt-column-alley lia-quilt-column-alley-right"&gt;&lt;div class="lia-message-body lia-component-body"&gt;&lt;div class="lia-message-body-content"&gt;&lt;p&gt;Double click on OTL.exe to run it.  Right click OTL.exe and select run as administator for Vista and Win 7.&lt;br&gt;&lt;br&gt;Click the &lt;strong&gt;Scan All Users&lt;/strong&gt; checkbox.&lt;/p&gt;&lt;p&gt;Change file age to&lt;strong&gt; 60 days&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;under &lt;img alt="" border="0" src="http://www.bleepstatic.com/fhost/uploads/0/customscanfix.png" align="center" title=""&gt; Copy and paste what is below between the lines&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;&lt;p&gt;drivers32&lt;/p&gt;&lt;p&gt;netsvcs&lt;br&gt;&amp;quot;%WinDir%\$NtUninstallKB*$.&amp;quot; /30&lt;br&gt;%SYSTEMDRIVE%\*.exe&lt;br&gt;/md5start&lt;br&gt;volsnap.sys&lt;br&gt;atapi.sys&lt;br&gt;explorer.exe&lt;br&gt;winlogon.exe&lt;br&gt;mrxsmb.sys&lt;/p&gt;&lt;p&gt;/md5stop&lt;/p&gt;&lt;hr&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Press the &lt;img alt="" border="0" src="http://www.bleepstatic.com/fhost/uploads/0/runscan.png" align="center" title=""&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
      <pubDate>Tue, 08 May 2012 20:10:17 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/714353#M202929</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-05-08T20:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: Another Zeroaccess!inf infection</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/714389#M202932</link>
      <description>&lt;p&gt;Completed. It generated two log files.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;First log below:&lt;/p&gt;</description>
      <pubDate>Tue, 08 May 2012 22:25:56 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Another-Zeroaccess-inf-infection/m-p/714389#M202932</guid>
      <dc:creator>BudBullets</dc:creator>
      <dc:date>2012-05-08T22:25:56Z</dc:date>
    </item>
  </channel>
</rss>

