We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Help with Google Re-Direct Virus...

13

Comments

  • MrsChips
    MrsChips Posts: 407 Forumite
    Anyways ~ THIS is dodgy
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe

    I've just spoken to my B/F he says that this file has been removed by an AVG Scan - we cant locate this file on the Computer and when we start up the PC a Windows message pops up to tell us that it cant find the file?

    I'll do the other Scan now and report back as soon as I have results.

    I will also re-check the TeaTimer Setting in SpyBot - I did un-tick the box but couldnt see an option to apply new setting or save changes. would it do it automatically is I un-ticked the box?
    2009 Savings & Winnings so far....
    Pigsback £15.06 +[strike]£40[/strike] M&S Vouchers + £20 New Look + TNS £15 Capital Bonds + Qype Ninja Goodies + £50 Virgin Voucher
    Sealed Pot Challenge #589 - Target £150
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    tea timer ~ no settings to save. Its either ticked, or it isnt ~ theres 2 on the same page though, top one SHOULD be ticked, bottom one (tea timer) should be UNTICKED :)
    :idea:
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    If the scan doesnt sort the problem, try GLARY UTILITIES
    http://www.download.com/Glary-Utilities/3000-2094_4-10508531.html
    Run the ONE CLICK scan
    :idea:
  • MrsChips
    MrsChips Posts: 407 Forumite
    Well you did right with what you said about switching tea timer off. Are you SURE you unticked it? (Should have gone from the control panel bottom right)

    Just checked TeaTimer and it was still Ticked - Did it again and it seems to have saved the change now...... Just going to start the Scan now.
    2009 Savings & Winnings so far....
    Pigsback £15.06 +[strike]£40[/strike] M&S Vouchers + £20 New Look + TNS £15 Capital Bonds + Qype Ninja Goodies + £50 Virgin Voucher
    Sealed Pot Challenge #589 - Target £150
  • MrsChips
    MrsChips Posts: 407 Forumite
    Hi all - I'm still Scanning with Kaspersky - its taking a while so I may have to post results tommorrow.
    2009 Savings & Winnings so far....
    Pigsback £15.06 +[strike]£40[/strike] M&S Vouchers + £20 New Look + TNS £15 Capital Bonds + Qype Ninja Goodies + £50 Virgin Voucher
    Sealed Pot Challenge #589 - Target £150
  • GunJack
    GunJack Posts: 11,897 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    good luck chips...it'll get there eventually :) sounds like it could be one of the current new breed of browser hijackers..they are proving to be persistent little burgers :(


    p.s. not too sure about this in HJT log....maybe R-S or RIK could provide more detail as to whether legit or not....

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1


    ...and this still looks a bit norton-ish.....
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Hi Jack
    Yeah, that proxy is very dodgy. Ill get the OP to kill it if Kaspersky fails

    As for norton. I dont want to touch it in case it effects something else (And ive no clue how to fully remove it safely as theres nothing else by them running)
    :idea:
  • MrsChips
    MrsChips Posts: 407 Forumite
    I'm still here....

    IE has just crashed after 4 hours of Scanning so i've lost all the current scan on Kaspersky !!! It hadnt picked up anything in those 4 hours so I've begun the GLARY UTILITIES scan instead. I can always go back to Kaspersky tommorrow if this doesnt work (I Hope!)

    Gunjack - I'll wait to see what the others say about the Suspect files before I remove them. It's odd that Norton is still showing because we've had a brand new Hard Drive since we last had Norton Installed ??

    I'll be back tomorrow.
    2009 Savings & Winnings so far....
    Pigsback £15.06 +[strike]£40[/strike] M&S Vouchers + £20 New Look + TNS £15 Capital Bonds + Qype Ninja Goodies + £50 Virgin Voucher
    Sealed Pot Challenge #589 - Target £150
  • GunJack
    GunJack Posts: 11,897 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    aliEnRIK wrote: »
    As for norton. I dont want to touch it in case it effects something else (And ive no clue how to fully remove it safely as theres nothing else by them running)

    I was thinking their own removal tool.....but might be worth checking the filepath and see what else is in that symantec shared folder...might give a clue as towhat it is...
    edit: a quick google has shown up this info on that norton file...looks big and a resource hog...might be best to get shut !!

    http://www.file.net/process/symlcsvc.exe.html
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.3K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.3K Work, Benefits & Business
  • 601.1K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.