07-23-2012 12:29 PM
07-23-2012 12:39 PM
peterweb wrote:
There seems to be a lot of posts lately asking for help to remove infections. Maybe there should be a separate board for these posts, so the boards for individual products can be devoted to the questions about the products.
Hi,
That might be a permanent fix for a temporary problem.
07-23-2012 05:29 PM
Hi Peter,
You might like to see the reply by elsewhere to the suggestion of DavidThomas88.
Dave.
Windows 7 x64 SP1 N360v20.3.1.22 NU16 SSR 2013 Secunia PSI SpywareBlaster NoScript MBAM free SAS free
07-25-2012 02:18 PM
am with you peter there sould be a forum board and they can all ways close it when this out break ends
07-26-2012 06:27 AM
IMHO - It is getting to the point where something needs to be done in regards to "cleaning up the boards".
It is taking those of us who assist with other than "trojan/malware" to find a posts that still need us to address them. I think I went thru close to three pages on the NAV/NIS board before I found a post that was not trojan related early this AM.
I know part of that is because Quads has been working his tail off and burning a lot of midnight oil - thus moving those posts to the top of the product boards.
07-26-2012 12:37 PM
A new forum board for infected systems should be created asap !
One reason for this escalation is imho, that Symantec ( except Tony's comment ) gives zero information to the users, who have the zero.access malware.
The support from Symantec to their customers is a shame.
Symantec should not ignore, that we pay for their jobs !
--- Bring back the offline vault // N360 v6.4 on german 64 bit win7, IE9 ---
07-26-2012 09:00 PM
While I agree with the idea on principle, Symantec have a payed malware removal service, so may not agree.
Also, If I may quote Delphinium : -
"No, actually, we did have that. Quads removed approximately 315 rootkits from user's machines in 2009 and it kept four of us busy sorting out who had what, requesting scans and scheduling who was next to be helped. It was great. Quads, however was about worn out and he really is the only specialist on the forum. There were times when he went 36 hours straight.He stopped doing complex removals using advanced tools because there was no protection for the users. Now he offers suggestions for readily available, relatively safe tools, or we send them to the forums.
The malware removal forums have enough members that they have their own training schools. The helpers are taught what to do and what not to do. The new helpers have overseers to prevent damage to user's machines. There is a long supervised practice period before they are allowed to try removals on their own.
We have no one here to do that training.
This is an open forum, which means that everyone is allowed to post on any thread whether they have any idea of what is going on or not. The four of us assisting Quads had to chase around on threads trying to prevent damage to peoples' machine by obeying instructions that ranged from useless to dangerous.
We asked several times for a separate forum, but were denied, partly due to liability questions, partly to do with the fact that Symantec charges for malware removal, and partly because an entire forum should not rely on one individual.
The Norton products have improved to such a degree that what we are seeing for infections now is hardly noticeable. There were times that every thread on the forum page was a rootkit complaint. Now it would not provide enough threads for a separate forum, even if it could be protected."
Thanks,
Dave.
Windows 7 x64 SP1 N360v20.3.1.22 NU16 SSR 2013 Secunia PSI SpywareBlaster NoScript MBAM free SAS free
07-27-2012 03:41 PM
Now we got details from Symantec about Trojan.Zeroaccess.
Please read this:
http://community.norton.com/t5/Norton-Internet-Sec
Trojan.Zeroaccess Removal Tool
http://www.symantec.com/security_response/writeup.
Trojan.Zeroaccess - Removal
http://www.symantec.com/security_response/writeup.
--- Bring back the offline vault // N360 v6.4 on german 64 bit win7, IE9 ---
08-18-2012 12:05 AM
Hello
Yes, I have looked at the posted links. Unfortunately, the removal of malware isn't such an easy thing to do. Even malware with the same name will be different on each computer. The malware also is changed by the malware writers all the time. The use of NPE is still a powerful tool that shouldn't be used by the average user. If it was so easy to remove, you wouldn't see threads that Quads is working on that take pages and pages to clean up the malware safely from each individual person's computer. Unfortunately, there is not a single procedure that will work on all computers to clean this malware or any other piece of malware. It's also difficult to clean a computer thru a forum when you can not actually see the computer in front of you.
Yes, we did request a separate section of the Forum for malware cleaning even as a temporary board during a massive outbreak time as this, but as pointed out, there are legal issues that would prevent such a type of board in an open forum as this is.Malware cleaning is something that takes quite a bit of training and schooling and that is for the normal malware cleaning that is done by a person sitting in front of the person's infected machine. To be able to clean a person's computer safely in a forum requires even more knowledge and getting the cleaning customized to that particular machine.
I know I wouldn't feel safe using such powerful tools without a malware removal expert supervising the procedures and making sure the right files are cleaned and also having a way to replace the system files which are cleaned with other ones that will allow the computer to boot up. Advanced tools may be ok in the hands of expert users under the supervision of expert malware removers.
Success always occurs in private and failure in full view.
