<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Misleadapp.downloader in Norton Internet Security / Norton AntiVirus</title>
    <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108051#M56619</link>
    <description>&lt;p&gt;Hi&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;can you please give me the full file details, in the Norton History and the name of the actual file (in details) and where it is saying it is located??&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;</description>
    <pubDate>Tue, 16 Jun 2009 01:10:04 GMT</pubDate>
    <dc:creator>Quads</dc:creator>
    <dc:date>2009-06-16T01:10:04Z</dc:date>
    <item>
      <title>Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/107520#M56366</link>
      <description>&lt;p&gt;I have read some of the previous threads on this particular infection, so i have been able to do some of the initial legwork.&lt;/p&gt;&lt;p&gt;I was able to install hijack this, and run a scan. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;here is the text file:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 9:48:57 AM, on 6/13/2009&lt;br&gt;Platform: Windows Vista SP1 (WinNT 6.00.1905)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6001.18226)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\Windows\system32\Dwm.exe&lt;br&gt;C:\Windows\Explorer.EXE&lt;br&gt;C:\Windows\system32\taskeng.exe&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br&gt;C:\Windows\System32\rundll32.exe&lt;br&gt;C:\Program Files\Synaptics\SynTP\SynTPStart.exe&lt;br&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;br&gt;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&lt;br&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br&gt;C:\Windows\System32\rundll32.exe&lt;br&gt;C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe&lt;br&gt;C:\Program Files\Logitech\QuickCam\Quickcam.exe&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe&lt;br&gt;C:\Windows\ehome\ehtray.exe&lt;br&gt;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&lt;br&gt;C:\Windows\ehome\ehmsas.exe&lt;br&gt;C:\Program Files\Windows Media Player\wmpnscfg.exe&lt;br&gt;C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe&lt;br&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br&gt;C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe&lt;br&gt;C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe&lt;br&gt;C:\Users\Leonel Uribe\Documents\leo.exe&lt;br&gt;&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a target="_blank" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iehome&amp;amp;locale=en_us&amp;amp;c=81&amp;amp;bd=Presario&amp;amp;pf=laptop"&gt;http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iehome&amp;amp;locale=en_us&amp;amp;c=81&amp;amp;bd=Presario&amp;amp;pf=laptop&lt;/a&gt;&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a target="_blank" href="http://www.gmail.com/"&gt;http://www.gmail.com/&lt;/a&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a target="_blank" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iehome&amp;amp;locale=en_us&amp;amp;c=81&amp;amp;bd=Presario&amp;amp;pf=laptop"&gt;http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iehome&amp;amp;locale=en_us&amp;amp;c=81&amp;amp;bd=Presario&amp;amp;pf=laptop&lt;/a&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a target="_blank" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iehome&amp;amp;locale=en_us&amp;amp;c=81&amp;amp;bd=Presario&amp;amp;pf=laptop"&gt;http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iehome&amp;amp;locale=en_us&amp;amp;c=81&amp;amp;bd=Presario&amp;amp;pf=laptop&lt;/a&gt;&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =&lt;br&gt;O1 - Hosts: ::1 localhost&lt;br&gt;O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll&lt;br&gt;O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL&lt;br&gt;O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll&lt;br&gt;O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)&lt;br&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br&gt;O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll&lt;br&gt;O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll&lt;br&gt;O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart&lt;br&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup&lt;br&gt;O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit&lt;br&gt;O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe&lt;br&gt;O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide&lt;br&gt;O4 - HKLM\..\Run: [GrooveMonitor] &amp;quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&amp;quot;&lt;br&gt;O4 - HKLM\..\Run: [NBKeyScan] &amp;quot;C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe&amp;quot;&lt;br&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&amp;quot;&lt;br&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br&gt;O4 - HKLM\..\Run: [LogitechCommunicationsManager] &amp;quot;C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe&amp;quot;&lt;br&gt;O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &amp;quot;C:\Program Files\Logitech\QuickCam\Quickcam.exe&amp;quot; /hide&lt;br&gt;O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe&lt;br&gt;O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe&lt;br&gt;O4 - HKCU\..\Run: [MsnMsgr] &amp;quot;C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe&amp;quot; /background&lt;br&gt;O4 - HKCU\..\Run: [AlcoholAutomount] &amp;quot;C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe&amp;quot; /automount&lt;br&gt;O4 - HKCU\..\Run: [Messenger (Yahoo!)] &amp;quot;C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe&amp;quot; -quiet&lt;br&gt;O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe&lt;br&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')&lt;br&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll&lt;br&gt;O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll&lt;br&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL&lt;br&gt;O13 - Gopher Prefix:&lt;br&gt;O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.111,85.255.112.200&lt;br&gt;O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.112.111,85.255.112.200&lt;br&gt;O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.111,85.255.112.200&lt;br&gt;O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll&lt;br&gt;O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe&lt;br&gt;O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe&lt;br&gt;O23 - Service: Google Update Service (gupdate1c9ea023079f424) (gupdate1c9ea023079f424) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe&lt;br&gt;O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe&lt;br&gt;O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe&lt;br&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;br&gt;O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe&lt;br&gt;O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br&gt;O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br&gt;O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe&lt;br&gt;O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe&lt;br&gt;O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe&lt;br&gt;O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe&lt;br&gt;O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe&lt;br&gt;O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 8620 bytes&lt;br&gt;&lt;br&gt;&lt;br&gt;I believe that part of the problem is the O17 and O18 entries, but i am not sure what other things need to be removed.&lt;/p&gt;&lt;p&gt;Please help!&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Vicodinmonster&lt;/p&gt;</description>
      <pubDate>Sun, 14 Jun 2009 13:12:14 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/107520#M56366</guid>
      <dc:creator>vicodinmonster</dc:creator>
      <dc:date>2009-06-14T13:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/107526#M56370</link>
      <description>&lt;p&gt;I would suggest following the Removal Instructions.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Please make sure you Post the Threat &lt;strong&gt;&lt;em&gt;exactly&lt;/em&gt;&lt;/strong&gt; as it is Detected!&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;font face="arial black,avant garde"&gt;Removal Instructions for Downloader.MisleadApp&lt;/font&gt;&lt;font face="arial,helvetica,sans-serif"&gt;: &lt;a target="_blank" href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-061114-0840-99&amp;amp;tabid=3"&gt;http://www.symantec.com/security_response/writeup.jsp?docid=2007-061114-0840-99&amp;amp;tabid=3&lt;/a&gt;. &lt;/font&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sun, 14 Jun 2009 13:41:12 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/107526#M56370</guid>
      <dc:creator>Floating_Red</dc:creator>
      <dc:date>2009-06-14T13:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/107538#M56376</link>
      <description>&lt;p&gt;tried it already and the av does not pick it up.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;thanks anyway!&lt;/p&gt;</description>
      <pubDate>Sun, 14 Jun 2009 15:24:41 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/107538#M56376</guid>
      <dc:creator>vicodinmonster</dc:creator>
      <dc:date>2009-06-14T15:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/107543#M56381</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;vicodinmonster wrote:&lt;br&gt;&lt;p&gt;tried it already and the av does not pick it up.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;thanks anyway!&lt;/p&gt;&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Have you tired a Full System Scan in Safe Mode, in Your Account and in the Administrator Account? &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;What is your Norton Product and Version, e.g. Norton Internet Security 2009?  I see in your Log that you have 16.0.0.125; you should have either 16.5.0.134/135.  Could you go to: Open your Norton Product &amp;gt; ? Help &amp;amp; Support &amp;gt; About and let us know what the &lt;strong&gt;Version&lt;/strong&gt; is.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Floating_Red on &lt;/span&gt;&lt;span class="local-date"&gt;06-14-2009&lt;/span&gt;&lt;span class="local-time"&gt; 04:53 PM&lt;/span&gt;&lt;/div&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Floating_Red on &lt;/span&gt;&lt;span class="local-date"&gt;06-14-2009&lt;/span&gt;&lt;span class="local-time"&gt; 04:54 PM&lt;/span&gt;&lt;/div&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Floating_Red on &lt;/span&gt;&lt;span class="local-date"&gt;06-14-2009&lt;/span&gt;&lt;span class="local-time"&gt; 04:55 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Sun, 14 Jun 2009 15:55:02 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/107543#M56381</guid>
      <dc:creator>Floating_Red</dc:creator>
      <dc:date>2009-06-14T15:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/107545#M56382</link>
      <description>&lt;p&gt;It looks like something is stopping your Norton from updating properly.  Is the Adaware an older free version or does it also have antivirus scanning capabilities.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;In the other threads you have looked at, you would also have seen a recommendation to download Malwarebytes free version.  See if you are able to download and install it.  if you find that it won't do one or the other come back and let us know.  &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Install it, update it, and run a full scan.  Post the log here.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;a target="_blank" href="http://www.malwarebytes.org"&gt;http://www.malwarebytes.org&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sun, 14 Jun 2009 16:16:55 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/107545#M56382</guid>
      <dc:creator>delphinium</dc:creator>
      <dc:date>2009-06-14T16:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/107989#M56593</link>
      <description>&lt;p&gt;Malwarebytes' Anti-Malware 1.37&lt;br&gt;Database version: 2182&lt;br&gt;Windows 6.0.6001 Service Pack 1&lt;br&gt;&lt;br&gt;6/15/2009 4:25:20 PM&lt;br&gt;mbam-log-2009-06-15 (16-24-59).txt&lt;br&gt;&lt;br&gt;Scan type: Full Scan (C:\|)&lt;br&gt;Objects scanned: 236028&lt;br&gt;Time elapsed: 31 minute(s), 30 second(s)&lt;br&gt;&lt;br&gt;Memory Processes Infected: 0&lt;br&gt;Memory Modules Infected: 0&lt;br&gt;Registry Keys Infected: 3&lt;br&gt;Registry Values Infected: 0&lt;br&gt;Registry Data Items Infected: 2&lt;br&gt;Folders Infected: 2&lt;br&gt;Files Infected: 3&lt;br&gt;&lt;br&gt;Memory Processes Infected:&lt;br&gt;(No malicious items detected)&lt;br&gt;&lt;br&gt;Memory Modules Infected:&lt;br&gt;(No malicious items detected)&lt;br&gt;&lt;br&gt;Registry Keys Infected:&lt;br&gt;HKEY_CURRENT_USER\SOFTWARE\PlayAllDVD (Trojan.DNSChanger) -&amp;gt; No action taken.&lt;br&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PlayAllDVD (Trojan.DNSChanger) -&amp;gt; No action taken.&lt;br&gt;HKEY_CURRENT_USER\SOFTWARE\ColdWare (Malware.Trace) -&amp;gt; No action taken.&lt;br&gt;&lt;br&gt;Registry Values Infected:&lt;br&gt;(No malicious items detected)&lt;br&gt;&lt;br&gt;Registry Data Items Infected:&lt;br&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -&amp;gt; Data: 85.255.112.111,85.255.112.200 -&amp;gt; No action taken.&lt;br&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -&amp;gt; Data: 85.255.112.111,85.255.112.200 -&amp;gt; No action taken.&lt;br&gt;&lt;br&gt;Folders Infected:&lt;br&gt;c:\Users\Leonel Uribe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlayAllDVD (Trojan.DNSChanger) -&amp;gt; No action taken.&lt;br&gt;C:\Program Files\PlayAllDVD (Trojan.DNSChanger) -&amp;gt; No action taken.&lt;br&gt;&lt;br&gt;Files Infected:&lt;br&gt;c:\Users\leonel uribe\AppData\Roaming\microsoft\Windows\start menu\Programs\playalldvd\Uninstall.lnk (Trojan.DNSChanger) -&amp;gt; No action taken.&lt;br&gt;c:\program files\playalldvd\Uninstall.exe (Trojan.DNSChanger) -&amp;gt; No action taken.&lt;br&gt;c:\Windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -&amp;gt; No action taken.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;these are the scan results, i had them removed, but as you have probably guessed, it did not solve the problem. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;so now i am at a loss, i removed what i thought was the problem but nada...&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;any assistance would be greatly appreciated!,&lt;/p&gt;</description>
      <pubDate>Mon, 15 Jun 2009 21:02:52 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/107989#M56593</guid>
      <dc:creator>vicodinmonster</dc:creator>
      <dc:date>2009-06-15T21:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108028#M56606</link>
      <description>&lt;p&gt;In the Malwarebytes' Log, it says No Action Taken, so Malwarebytes' has only Detected it so those Files will still be on your computer.  I would suggest Quaratine them and Remove the Files.  You might even need to do another Full Scan to get these Removed.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;And I also see you only Scanned the C-Drive; please Scan at least C: and D: Drives in the Full Scan.  And I would suggest in Normal and in Safe Mode.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;As always, make sure you Update your Definitions and dis-connect from the Internet before Starting any Anti-Virus Scan.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Floating_Red on &lt;/span&gt;&lt;span class="local-date"&gt;06-16-2009&lt;/span&gt;&lt;span class="local-time"&gt; 12:10 AM&lt;/span&gt;&lt;/div&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Floating_Red on &lt;/span&gt;&lt;span class="local-date"&gt;06-16-2009&lt;/span&gt;&lt;span class="local-time"&gt; 12:13 AM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Mon, 15 Jun 2009 23:13:23 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108028#M56606</guid>
      <dc:creator>Floating_Red</dc:creator>
      <dc:date>2009-06-15T23:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108035#M56609</link>
      <description>Also disable system restore to delete any saved restore points.</description>
      <pubDate>Tue, 16 Jun 2009 00:03:16 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108035#M56609</guid>
      <dc:creator>delphinium</dc:creator>
      <dc:date>2009-06-16T00:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108047#M56615</link>
      <description>&lt;p&gt;Hello all again,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Ran malware, removed the infected entries, in both safe and regular mode, was disconected from the web sys restore was disconected. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;as per the scans my machine is clean. buy the browser keeps getting hijacked. i am on the verge of a reformat....&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;i ran all the scans again and they all come back clean. Rootkit perhaps? i just got another warning from norton 32generic... great...&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;any other ideas anyone? &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;this is really frustrating...&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;thanks again to all&lt;/p&gt;</description>
      <pubDate>Tue, 16 Jun 2009 00:57:40 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108047#M56615</guid>
      <dc:creator>vicodinmonster</dc:creator>
      <dc:date>2009-06-16T00:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108051#M56619</link>
      <description>&lt;p&gt;Hi&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;can you please give me the full file details, in the Norton History and the name of the actual file (in details) and where it is saying it is located??&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;</description>
      <pubDate>Tue, 16 Jun 2009 01:10:04 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108051#M56619</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-16T01:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108057#M56623</link>
      <description>&lt;p&gt;Hi again&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I have a Theory&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;First I need 3 logs&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Please run RootRepeal  as in this post  &lt;a target="_blank" href="http://community.norton.com/norton/board/message?board.id=Norton_360&amp;amp;message.id=13889#M13889"&gt;http://community.norton.com/norton/board/message?board.id=Norton_360&amp;amp;message.id=13889#M13889&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;And GMER, &lt;a target="_blank" href="http://www.gmer.net/"&gt;http://www.gmer.net/&lt;/a&gt;  and &amp;quot;Scan&amp;quot; then &amp;quot;Save&amp;quot;  the log,   then due to the possible side post the log on &lt;a target="_blank" href="http://pastebay.com/"&gt;http://pastebay.com/&lt;/a&gt;   and PM me the link. Use your Norton Name on &lt;strong&gt;Pastebay&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Pastebay does have a Character limit so please make sure that the whole gets posted&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I would also like a DDS log&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Download  &lt;a target="_blank" href="http://homepages.slingshot.co.nz/~crutches/DDS/"&gt;http://homepages.slingshot.co.nz/~crutches/DDS/&lt;/a&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;You will have to go offline and disable auto-protect and the firewall to run it when it is finished it will produce a log. then you can enable everything again and go back online&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;When I have the 3 logs I will cross reference &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;Quads &lt;/span&gt; &lt;/p&gt;</description>
      <pubDate>Tue, 16 Jun 2009 01:40:37 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108057#M56623</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-16T01:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108148#M56683</link>
      <description>&lt;p&gt;Hello Quads,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The name of the security threat is packed.generic233.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Norton does not list it on the history file at least not with that name. which is the same thing it was doing with misleadapp. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;malwarebytes does not pick it up, adaware did not see it... meanwhile all web browsing is hijacked if you use a web link. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;very challenging little bugger this one is...&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;thanks to all for the help.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Tue, 16 Jun 2009 11:40:36 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108148#M56683</guid>
      <dc:creator>vicodinmonster</dc:creator>
      <dc:date>2009-06-16T11:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108312#M56764</link>
      <description>&lt;p&gt;That is the name Norton gives the Treat, not the actual name of the file and it's location, could you please do the 3 logs above&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;</description>
      <pubDate>Tue, 16 Jun 2009 20:45:34 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108312#M56764</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-16T20:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108318#M56769</link>
      <description>&lt;p&gt;As well as doing the Logs for Quads, could you also try the Removal Intructions for Packed.Generic.233.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;font face="arial black,avant garde"&gt;Removal Instructions for Packed.Generic.233&lt;/font&gt;&lt;font face="arial,helvetica,sans-serif"&gt;: &lt;a target="_blank" href="http://www.symantec.com/en/uk/security_response/writeup.jsp?docid=2009-060800-5953-99&amp;amp;tabid=3"&gt;http://www.symantec.com/en/uk/security_response/writeup.jsp?docid=2009-060800-5953-99&amp;amp;tabid=3&lt;/a&gt;. &lt;/font&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Tue, 16 Jun 2009 20:54:34 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108318#M56769</guid>
      <dc:creator>Floating_Red</dc:creator>
      <dc:date>2009-06-16T20:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108322#M56772</link>
      <description>&lt;p&gt;I saw the Symantec writeup, but if Norton does not want to remove it / can't  then it's as useless as an udder on a bull.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;</description>
      <pubDate>Tue, 16 Jun 2009 21:19:52 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108322#M56772</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-16T21:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108628#M56939</link>
      <description>&lt;p&gt;You have the &amp;quot;&lt;span class="Apple-style-span"&gt;MSIVXserv.sys&amp;quot; Rootkit at least. I haven't looked at the DDS log yet I will get there&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;</description>
      <pubDate>Wed, 17 Jun 2009 20:42:01 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108628#M56939</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-17T20:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108747#M57002</link>
      <description>&lt;p&gt;Hi&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;If you have Spybot S&amp;amp;D, please uninstall.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Please go here and Download Avenger to your Desktop, &lt;a target="_blank" href="http://community.norton.com/norton/board/message?board.id=nis_feedback&amp;amp;message.id=53509#M53509"&gt;http://community.norton.com/norton/board/message?board.id=nis_feedback&amp;amp;message.id=53509#M53509&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;With Vista remember to right click, Avenger and select &amp;quot;Run as Administator&amp;quot; from the Menu.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Now  when you get to number 3. use the script below not the one on the other post, SO&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;3. In the &amp;quot;Input script here:&amp;quot; copy and paste the script between the lines&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;&lt;p&gt;Drivers to disable:&lt;/p&gt;&lt;p&gt;MSIVXserv.sys&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Drivers to delete:&lt;/p&gt;&lt;p&gt;MSIVXserv.sys&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Files to delete:&lt;/p&gt;&lt;p&gt;C:\Autorun.inf&lt;/p&gt;&lt;p&gt;D:\Autorun.inf&lt;/p&gt;&lt;p&gt;C:\Windows\System32\drivers\MSIVXcdpppsenlsylcscnqblskitpopcfyxvb.sys&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\drivers\MSIVXfpqebwwxpiswvenobbndeitvrjiwprcc.sys&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\drivers\MSIVXpxettvasrnemkooicrytqcpwbbcsgpsu.sys&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\drivers\MSIVXuytmnaqqiptkkaxqoscjmihrxwtunyfi.sys&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\MSIVXpvymtqimexcpdqpsvymktfnpckdjnchw.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\MSIVXbnixqaxvkdsiborkveqxuehwtveijcqx.dll &lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\MSIVXtcpitqpqhykempvydbqnnhbnpsxftfbb.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\MSIVXgyusdbpapbginsojyucbcvvrtuhvwlnr.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\MSIVXxqfgfomfgbghveijmpekagedsvidtqfm.dll&lt;/p&gt;&lt;p&gt;C:\Windows\System32\MSIVXedopmooyitxvmoohvyxeqwskwwtwajyb.dll&lt;/p&gt;&lt;p&gt;C:\Windows\System32\MSIVXqexdxmxerxnimqrsmftejymvnxurvanw.dll&lt;/p&gt;&lt;p&gt;C:\Windows\System32\MSIVXcount&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Registry keys to delete:&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSIVXserv.sys&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSIVXserv.sys&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\MSIVXserv.sys&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\MSIVXserv.sys&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\MSIVXserv.sys&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\MSIVXserv.sys&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\MSIVXserv.sys&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\MSIVXserv.sys&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\MSIVXserv.sys&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\MSIVXserv.sys&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SOFTWARE\MSIVX&lt;/p&gt;&lt;hr&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Then carry on with the other post from Screenshot and below.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Thu, 18 Jun 2009 04:41:46 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108747#M57002</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-18T04:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108813#M57048</link>
      <description>&lt;p&gt;Hello Quads!&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;It appears as if the problem has been solved I have scanned the system with avenger, gmer and no rootkits found. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Norton is now running again, and the previous threats are now removed.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Web browsing is back to normal, and even performance levels are up.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;My knee jerk reaction was to re install, but the whole experience has been educational! I don't wish this on anyone, but I learned an awful lot!&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thanks Again Quads! &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;and thanks to all the people that contributed on the forum.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Vicodinmonster&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Thu, 18 Jun 2009 11:29:15 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108813#M57048</guid>
      <dc:creator>vicodinmonster</dc:creator>
      <dc:date>2009-06-18T11:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: Misleadapp.downloader</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108843#M57066</link>
      <description>&lt;p&gt;Hi Vicodinmonster:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Glad everything is working well for you.  There should be a .zip file in the Avenger folder.  Please upload it here  &lt;a target="_blank" href="http://rapidshare.com/index.html"&gt;http://rapidshare.com/index.html&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Use your name as you did with the others.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Thu, 18 Jun 2009 15:42:08 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Misleadapp-downloader/m-p/108843#M57066</guid>
      <dc:creator>delphinium</dc:creator>
      <dc:date>2009-06-18T15:42:08Z</dc:date>
    </item>
  </channel>
</rss>

