SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Pastimes : Computer Learning -- Ignore unavailable to you. Want to Upgrade?


To: thecow who wrote (66220)10/27/2009 6:05:04 PM
From: Raptech  Read Replies (4) | Respond to of 110581
 
Thanks, I have been fighting with a "redirect infection" for months. After my computer is idle for a few hours and I try to open IE to my home page it takes me to a Bell South / Yahoo page and will not allow me to go to any other link. I have to reboot the computer to then be able to go online normally. I run all of the Malwarebytes, Spybot, AVG, and Super AV and detect nothing.

I think it may be something related to a recent Java upgrade so may just uninstall Java and see if that fixes it.

If I do a Norton online scan will they load a lot of junk that may be hard to get rid of. That's been my past experience with Norton which I no longer wish to use permanently. Thanks.



To: thecow who wrote (66220)10/28/2009 2:33:28 AM
From: maceng2  Read Replies (2) | Respond to of 110581
 
Hi Cow.
Thanks for the reply, I have a subscription copy of AVG and currently upgrading from 8.5 to 9.0 and there is a few problems on that one, but AVG are actively working on that one. I sill have not had an email reply whether JS/Redir is a virus or not. My system was detecting it as a virus though and had removed three copies in as many days.

So, being concerned, I took the matter into my own hands. I have XP service pack 3.

The offending file was found here. (I have X'd out actual names and addresses)

C:\Documents and Settings\MYNAME\Local Settings\Application Data\{XXXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}\chrome\content\overlay.xul 25/10/2009, 17:50:30

and there were 3 versions of this along with a bunch of other files in the application data folder.

I noticed every time I logged into Goggle (my home page) a advert would come up to download the Chrome version of IE. I don't use Chrome. Anyway, inspired, I deleted all the folders and files marked with as above "chrome" as a subdirectory. I opened up IE and this time I pressed the little "x" in the TRH corner of the Chrome advert which promptly disappeared and has not come back. I now have one new version of the chrome application data as described above but no virus is coming up on the scan and the folders are not replicating like they were before.

[Note to newbies, don't attempt anything like this unless you have your system completely imaged as a back up is case you screw up your PC. Backing up potential viruses brings it's own concerns too. I had an image of my system before this problem ocurred, so restoring that image was the action of last resort and losing a few weeks of data and updates]

So I think that is it. I am waiting for confirmation here from the internet experts that this fix is good, before sending in my solution to AVG along with my internet safety consultants fee.

Just joking, I will check over the next few days that the fix is permanent of course.-g-