What is this?


HowDidGetThis wrote:

Nerimash, I have downloaded TDSSKiller and ran it, but it does not work.

 

Quads, you say there are ways around and that is?

 

Appreciate your help.


I have a good handful of zeroaccess droppers / installers I test by infecting my PC like the everyday user, from the older (1 year + old) versions to the latest zeroaccess I can find. the family does change including which programs do or do not hit the tripwire, folder locations etc.

 

I have some of the new versions TDSSkiller does not detect or closes due to the tripwire, or like I tried Norton Power Eraser and on the NPE restart I had a endless bootloop. Another person on this forum who went to one of the specialist forums, which is for the users protection. got asked to use TDSSkiller and that also did not detect anything.

 

I did find other ways to remove zeroaccess including the latest I have, but I no longer do the more dangerous or for that matter any Malware removal on this forum and this thread shows why, and other threads at the moment.

Please go to join one of the Malware removal forums to get help from a Malware removalist and they are the only guys allowed to post on users threads.

 

To the other user here, I am not doing any testing of zeroaccess for you as you asked, my theories, tests etc. are for me and the likes of Symantec, like in the past.

Here is an idea,  you could infect your own PC with all the Malware and find out for yourself.

 

Quads

System Infected: ZeroAccess Rootkit Activity 2

 

I got a message saying it was a high risk and blocked. Did a search and it was a very high risk rootkit?

 

Also, everytime I click on a link, I am re-directed to something random. E.g I search Symantec and click on first link, I get some random page giving me antivirus offers.

 

I believe that is an effect of it, I am doing a full system scan as I am typing.

 

Please tell me how to get rid of it and if you can thanks.

Thank you for the confirmation, @chargil1

Thank you very much!

Turning off the Nvidia 'In-Game Overlay' worked.

I appreciate all the help I have received here.

Thank you to everyone for your input.

Hello

Welcome to the Norton Community Forum

Please see this link that shows how to hide the NVidia Overlays.

https://www.howtogeek.com/271199/how-to-hide-the-nvidia-geforce-experiences-in-game-overlay-icons/

Have a Good Night and

Thanks.

 

I will try that in the morning. Thank you.

Hi @chargil1 -  We believe this is related to the Nvidia display driver.

If you remove the ‘Game overlay’ option from Nvidia GeForce they should go away.

Let us know if that works for you.
 

There was nothing there before. New icons simply appeared.

Downloaded Norton product directly from Norton.
Argos package contained only the product key and instructions.

Was there any other icon or branding image there before these new icons appeared?

Where did you download your product when you first installed? Was it directly from Norton, or did Argos have a separate link?

 

 

They suddenly appeared 3 days ago.

Have those icons always been there, or did they suddenly appear?

 

I bought it at Argos.

Where did you purchase your Norton? The location of those icons is where some branded versions (such as Staples) have the brand logo.

 

1682.png

I bought my Norton Security Premium (10 Devices) 1 year subscription in July this year. Also includes cloud storage.

The icons only appeared about 2 days ago, and are only present on my main pc.

I have updated and restarted several times, but nothing seems to work.

The icon seems to flicker between the 'refresh' looking icon and the 'pause' one.

I do not see that on my Norton Security with Backup product. What version of Norton Internet Security do you have? Click on Help - About.

Have you restarted your computer?