<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Digital Immunodeficiency Disorder?</title>
	<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder/</link>
	<description>Comments on Ask MetaFilter post Digital Immunodeficiency Disorder?</description>
	<pubDate>Sun, 25 Jan 2009 17:59:07 -0800</pubDate>
	<lastBuildDate>Sun, 25 Jan 2009 17:59:07 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: Digital Immunodeficiency Disorder?</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder</link>	
		<description>My laptop&apos;s been infected by something that is interfering with all the usual solutions. Please help! &lt;br /&gt;&lt;br /&gt; After the recent hacking attempt that brought down Mefi, I scanned my laptop for any problems it may have picked up from it. AVG detected one threat, a trojan, which it promptly deleted. But that wasn&apos;t quick enough, apparently.&lt;br&gt;
&lt;br&gt;
Now, my Windows XP setup is exhibiting weird behavior all around, and everything I&apos;ve tried to do to fix it has been blocked. Here are all the symptoms:&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Firewall&lt;/b&gt; - was originally turned off; I&apos;m not sure for how long. I&apos;ve since turned it back on.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Security software&lt;/b&gt; - AVG isn&apos;t detecting anything, but there&apos;s obviously something still wrong. Attempting to update the virus database throws an error. Most troubling, I cannot install the newest version of AVG as its website is blocked. Ditto for all the other major antivirus vendors -- trying to access their websites results in a page error.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Tech support sites&lt;/b&gt; - Same as above. Something is blocking all attempts to connect to the major tech help sites. I knew enough to check my hosts file, but can see no problems there. At least AskMe still works...&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Google search&lt;/b&gt; - Searching Google for solutions leads to a standard results page. But when I click on a result, instead of going to the relevant page, it opens up a new tab and goes to a random spam site. This happens on Yahoo and other search sites as well. I can still get to the page I want by copying the URL and pasting, but it&apos;s slowing me down. And of course any link that points to a support site won&apos;t work.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Other browsers&lt;/b&gt; - I&apos;d been using Firefox 3 up to this point, so I tried the other browsers on my system on the off chance they&apos;d work better. No luck -- Google Chrome refuses to connect to *any* website, and Internet Explorer crashes immediately after launching.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;System Restore&lt;/b&gt; - fed up with all the problems, I tried to roll back my system to a point before the infection. But to my great surprise, all the old system restore points have been deleted.&lt;br&gt;
&lt;br&gt;
So to sum up: AV software is borked, security and support sites are blocked, searching is hampered, and I can&apos;t go back to an older system configuration. Any ideas?&lt;br&gt;
&lt;br&gt;
&lt;small&gt;PS: I know you are not my tech support, but like I said, all the more dedicated help sites I&apos;d normally consult have been disappeared. Thanks for your time and patience!&lt;/small&gt;</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2009:site.112548</guid>
		<pubDate>Sun, 25 Jan 2009 17:44:21 -0800</pubDate>
		<dc:creator>Rhaomi</dc:creator>
		
			<category>trojan</category>
		
			<category>virus</category>
		
			<category>antivirus</category>
		
			<category>google</category>
		
			<category>systemrestore</category>
		
			<category>techsupport</category>
		
			<category>windowsxp</category>
		
			<category>redirect</category>
		
			<category>spyware</category>
		
			<category>spam</category>
		
			<category>resolved</category>
		
	</item> <item>
		<title>By: Justinian</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617729</link>	
		<description>For an infestation this serious I would suggest nuking the site from orbit.  It&apos;s the only way to be sure.&lt;br&gt;
&lt;br&gt;
(format and reinstall the operating system).</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617729</guid>
		<pubDate>Sun, 25 Jan 2009 17:59:07 -0800</pubDate>
		<dc:creator>Justinian</dc:creator>
	</item><item>
		<title>By: gemmy</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617730</link>	
		<description>Might be the &lt;a href=&quot;http://www.networkworld.com/news/2009/012309-downadup-conflicker-worm.html?hpg1=bn&quot;&gt;Downadup/Conflicker&lt;/a&gt; worm that&apos;s spreading like wildfire.&lt;br&gt;
&lt;br&gt;
&lt;a href=&quot;http://www.secureworks.com/research/threats/downadup-removal/?ap1=rcb&quot;&gt;Removal instructions&lt;/a&gt;.&lt;br&gt;
&lt;br&gt;
Use a proxy server to get around the &quot;can&apos;t get there to download stuff&quot; issue. I like Proxify.com, but there are tons of them out there.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617730</guid>
		<pubDate>Sun, 25 Jan 2009 18:00:17 -0800</pubDate>
		<dc:creator>gemmy</dc:creator>
	</item><item>
		<title>By: Susurration</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617737</link>	
		<description>You will probably need to boot Windows from a CD to remove this infestation. There is an excellent generic Windows boot CD, with anti-malware apps included, at &lt;a href=&quot;http://www.ubcd4win.com&quot;&gt;http://www.ubcd4win.com&lt;/a&gt;/ &lt;br&gt;
The software is free to download and has copies of all the drivers and disk utilities that you are likely to need (you can download the latest updates for your favorite anti-malware utilities before you burn the project -- see the CD creation instructions). Its originator can be trusted (i.e. it is free from malware) -- he has been running this project for about 5 years (he has the cease-and-desist letters from Microsoft to prove it!). You will need to burn the recovery/AV boot CD on a different PC, obviously! The CD takes about 20 minutes to make up and you&apos;ll need a Windows XP install CD to compile it. This has saved my bacon a few times - I highly recommend it.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617737</guid>
		<pubDate>Sun, 25 Jan 2009 18:05:41 -0800</pubDate>
		<dc:creator>Susurration</dc:creator>
	</item><item>
		<title>By: DarkForest</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617740</link>	
		<description>&lt;a href=&quot;http://trinityhome.org/Home/index.php?wpid=1&amp;front_id=12&quot;&gt;Trinity Rescue Kit&lt;/a&gt; is a bootable linux cd that will allow you to virus scan a windows machine.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617740</guid>
		<pubDate>Sun, 25 Jan 2009 18:06:56 -0800</pubDate>
		<dc:creator>DarkForest</dc:creator>
	</item><item>
		<title>By: imjosh</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617741</link>	
		<description>Check to see if the virus changed your Hosts files to block the sites you can&apos;t get to.&lt;br&gt;
&lt;br&gt;
Location and default info.&lt;br&gt;
&lt;a href=&quot;http://en.wikipedia.org/wiki/Hosts_file#Location_and_default_content&quot;&gt;&lt;br&gt;
http://en.wikipedia.org/wiki/Hosts_file#Location_and_default_content&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Alternately you can download the new AVG or the newest AVG definitions on another computer and install them.&lt;br&gt;
&lt;br&gt;
You&apos;ll also do well to run either CCleaner or Lavasoft&apos;s Adaware and see what they turn up.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617741</guid>
		<pubDate>Sun, 25 Jan 2009 18:08:36 -0800</pubDate>
		<dc:creator>imjosh</dc:creator>
	</item><item>
		<title>By: Rhaomi</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617772</link>	
		<description>Hey, everybody, thanks for the feedback.&lt;br&gt;
&lt;br&gt;
First off, after 80,000 items AVG turned up one more threat, which I&apos;ve nuked. I&apos;ll let it finish it&apos;s deep scan before trying anything else, which could take awhile.&lt;br&gt;
&lt;br&gt;
Even better, I&apos;ve discovered that I can bypass the website blocks using Google&apos;s cache -- this is letting me access the tech help sites and is giving me a few more options to try. In particular, &lt;a href=&quot;http://74.125.47.132/search?q=cache:help.lockergnome.com/security/access-anti-virus-websites--ftopict11459.html&quot;&gt;this site&lt;/a&gt; is describing the same symptoms I&apos;m getting, and linked to &lt;a href=&quot;http://74.125.47.132/search?q=cache:www.techtalkz.com/computer-security/515329-cannot-access-antivirus-sites-google-avast-etc.html&quot;&gt;this site&lt;/a&gt; with a potential fix which they said worked. I&apos;ll try that when the scan is done. (Currently at just over 200,000 items scanned...)&lt;br&gt;
&lt;br&gt;
I&apos;ll follow up if and when I get this thing fixed.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617772</guid>
		<pubDate>Sun, 25 Jan 2009 18:45:06 -0800</pubDate>
		<dc:creator>Rhaomi</dc:creator>
	</item><item>
		<title>By: tdismukes</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617776</link>	
		<description>I&apos;ll second Susurration&apos;s recommendation of ubcd4win.  I had to rescue my mom&apos;s pc from a serious infestation a few weeks ago, and the bootable disc was what saved the day.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617776</guid>
		<pubDate>Sun, 25 Jan 2009 18:52:59 -0800</pubDate>
		<dc:creator>tdismukes</dc:creator>
	</item><item>
		<title>By: patnok</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617791</link>	
		<description>sounds like what we had a couple weeks ago. malwarebytes fixed it. had to install it from a disk.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617791</guid>
		<pubDate>Sun, 25 Jan 2009 19:06:40 -0800</pubDate>
		<dc:creator>patnok</dc:creator>
	</item><item>
		<title>By: patnok</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617794</link>	
		<description>win32/vundo</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617794</guid>
		<pubDate>Sun, 25 Jan 2009 19:09:35 -0800</pubDate>
		<dc:creator>patnok</dc:creator>
	</item><item>
		<title>By: cosmonaught</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617798</link>	
		<description>I&apos;ve had nothing but luck running &lt;a href=&quot;http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html&quot;&gt;HijackThis&lt;/a&gt; (freeware) from Trend Micro, and then either &lt;a href=&quot;http://www.bleepingcomputer.com/tutorials/tutorial42.html&quot;&gt;analyzing the logs&lt;/a&gt;, or posting them on a message board and having someone help (a few forums: &lt;a href=&quot;http://www.lavasoftsupport.com/index.php?showforum=36&quot;&gt;1&lt;/a&gt; &lt;a href=&quot;http://www.geekstogo.com/forum/Malware-Removal-HijackThis-Logs-Go-Here-f37.html&quot;&gt;2&lt;/a&gt; &lt;a href=&quot;http://www.security-forums.com/viewforum.php?f=48&quot;&gt;3&lt;/a&gt;).</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617798</guid>
		<pubDate>Sun, 25 Jan 2009 19:10:50 -0800</pubDate>
		<dc:creator>cosmonaught</dc:creator>
	</item><item>
		<title>By: Rhaomi</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617889</link>	
		<description>Persistent little bastard. I let AVG do its full run and deleted everything it found, then rebooted. Nothing has changed -- Google still redirects, sites still blocked, etc. I did a bit more research and learned that sometimes these &lt;s&gt;viruses&lt;/s&gt; virii can rewrite the location of your HOSTS file, creating a clone of it squirreled away somewhere with a list of blocked sites and telling your browser to use that one. That way if you check the normal location it looks fine, even though it isn&apos;t.&lt;br&gt;
&lt;br&gt;
Anyway, the folks in &lt;a href=&quot;http://74.125.47.132/search?q=cache:KFCLePHJkTkJ:forums.whirlpool.net.au/forum-replies-archive.cfm/1072137.html+%22go.google.com%22+%22hosts+file+is+clean%22&amp;hl=en&amp;ct=clnk&amp;cd=2&amp;gl=us&quot;&gt;the thread&lt;/a&gt; I was reading used an app called Malwarebytes (which &lt;b&gt;patnok&lt;/b&gt; had also recommended). I couldn&apos;t get to the main site for it, naturally, so I went to one of the standard download sites and got it there. Problem is, I can&apos;t install it. This nefarious little bugger is interfering with the setup process.&lt;br&gt;
&lt;br&gt;
I&apos;ll have to check the registry for the cloned file they mentioned -- that should help fix it.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617889</guid>
		<pubDate>Sun, 25 Jan 2009 21:02:21 -0800</pubDate>
		<dc:creator>Rhaomi</dc:creator>
	</item><item>
		<title>By: Rhaomi</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617891</link>	
		<description>FUCK. This &lt;i&gt;jackass&lt;/i&gt;-of-all-trades has also disabled regedit. Now I&apos;m going to have to figure out how to get *that* up and running before I can do anything else.&lt;br&gt;
&lt;br&gt;
What next, a routine that automatically translates all onscreen text into Sanskrit?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617891</guid>
		<pubDate>Sun, 25 Jan 2009 21:05:36 -0800</pubDate>
		<dc:creator>Rhaomi</dc:creator>
	</item><item>
		<title>By: HopperFan</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617892</link>	
		<description>We&apos;ve had problems with Antivirus 2009 (and the behavior your PC is exhibiting sounds like its doings) -  Malwarebytes &lt;strong&gt;used&lt;/strong&gt; to be the answer, but further nasty variants in the past week or so have quashed that notion. As much as I detest the tired old &quot;nuke it from orbit!&quot; cliche, it&apos;s probably the right thing to do.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617892</guid>
		<pubDate>Sun, 25 Jan 2009 21:06:40 -0800</pubDate>
		<dc:creator>HopperFan</dc:creator>
	</item><item>
		<title>By: HopperFan</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617896</link>	
		<description>If you continue to work on it, though, one question (and I may have missed this info): You&apos;re trying to install/run Malwarebytes in safe mode/no networking, correct?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617896</guid>
		<pubDate>Sun, 25 Jan 2009 21:12:00 -0800</pubDate>
		<dc:creator>HopperFan</dc:creator>
	</item><item>
		<title>By: HopperFan</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617902</link>	
		<description>Antivirus 2009 info &lt;a href=&quot;http://www.2-spyware.com/remove-antivirus-2009.html&quot;&gt;here&lt;/a&gt;. (don&apos;t know if you&apos;ll be able to access it)</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617902</guid>
		<pubDate>Sun, 25 Jan 2009 21:16:21 -0800</pubDate>
		<dc:creator>HopperFan</dc:creator>
	</item><item>
		<title>By: Xuff</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617904</link>	
		<description>You might have some luck booting into Safe Mode and installing/repairing things from there if you don&apos;t want to go the boot-from-CD route.  However, I&apos;ve seen some malware that disables Safe Mode as well (or makes it bluescreen on startup), so that may not work.&lt;br&gt;
&lt;br&gt;
If you&apos;d like to try it restart the computer and repeatedly hit the F8 key until you&apos;re presented with a menu of options including Safe Mode.&lt;br&gt;
&lt;br&gt;
Having said that, however, the others who recommend a format and reinstall are probably right.  An infection this bad is usually a lot more trouble than it&apos;s worth; it&apos;ll likely require much more effort and time than starting from scratch and restoring from backups.&lt;br&gt;
&lt;br&gt;
Good luck!</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617904</guid>
		<pubDate>Sun, 25 Jan 2009 21:18:04 -0800</pubDate>
		<dc:creator>Xuff</dc:creator>
	</item><item>
		<title>By: Rhaomi</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617915</link>	
		<description>&lt;b&gt;HopperFan:&lt;/b&gt; I am now (currently writing this from my iPod) -- but it *still* won&apos;t install, even in Safe Mode. So, WTF, basically.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Xuff:&lt;/b&gt; I may have to do that. If I don&apos;t get it done by tomorrow I&apos;ll see about starting from scratch.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617915</guid>
		<pubDate>Sun, 25 Jan 2009 21:27:51 -0800</pubDate>
		<dc:creator>Rhaomi</dc:creator>
	</item><item>
		<title>By: defcom1</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617950</link>	
		<description>if you need to get to regedit, find the regedit.exe in system32 and rename to regedit.com  It will run, usually it&apos;s not blocked.&lt;br&gt;
&lt;br&gt;
(c:\windows\system32\regedt32.exe) to regedt32.com under win xp.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617950</guid>
		<pubDate>Sun, 25 Jan 2009 22:41:19 -0800</pubDate>
		<dc:creator>defcom1</dc:creator>
	</item><item>
		<title>By: defcom1</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617951</link>	
		<description>oh, and rebooting while you suspect you&apos;re infected - usually not a good idea.  If you don&apos;t get all the little bits out, on reboot it usually digs itself in again deeper.  (for future reference).</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617951</guid>
		<pubDate>Sun, 25 Jan 2009 22:43:07 -0800</pubDate>
		<dc:creator>defcom1</dc:creator>
	</item><item>
		<title>By: Rhaomi</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617977</link>	
		<description>Well, I&apos;ve made some progress. While in safe mode, I noticed some items in the Startup area that I had not created. On investigating, I found all of them were created right around when I started experiencing problems. These items were:&lt;br&gt;
&lt;br&gt;
C:\WINDOWS\ihufogutudi.dll&lt;br&gt;
C:\WINDOWS\TEMP\winlognn.exe&lt;br&gt;
C:\Docume~1\[username]\LOCALS~1\Temp\csrssc.exe&lt;br&gt;
C:\WINDOWS\Ivazonafazeqeq.dll&lt;br&gt;
&lt;br&gt;
I managed to find and delete these files in safe mode -- well, all of them except for csrssc.exe. This was in my user folder, and I couldn&apos;t access it as the administrator (?). So I switched to my profile (still in safe mode). But! All of the hidden files were, well, hidden, and the option to show hidden files was missing. In fact, the &quot;Tools &amp;gt; Folder Options&quot; menu was missing.&lt;br&gt;
&lt;br&gt;
So I rebooted into normal mode. Still missing. Did some tinkering, recovered the option, deleted that sucker once and for all. Or not.&lt;br&gt;
&lt;br&gt;
While checking up to see if I missed anything, the csrssc.exe file recreated itself (!) and disabled regedit once again.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617977</guid>
		<pubDate>Mon, 26 Jan 2009 00:01:16 -0800</pubDate>
		<dc:creator>Rhaomi</dc:creator>
	</item><item>
		<title>By: Rhaomi</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617978</link>	
		<description>(It also re-hid all the folders, btw.)</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617978</guid>
		<pubDate>Mon, 26 Jan 2009 00:06:46 -0800</pubDate>
		<dc:creator>Rhaomi</dc:creator>
	</item><item>
		<title>By: taz</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617989</link>	
		<description>eek! Do you know what this is called yet, Rhaomi?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617989</guid>
		<pubDate>Mon, 26 Jan 2009 01:26:53 -0800</pubDate>
		<dc:creator>taz</dc:creator>
	</item><item>
		<title>By: Xuff</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1617996</link>	
		<description>Removal instructions for what you&apos;ve got can be found here:&lt;br&gt;
&lt;br&gt;
&lt;a href=&quot;http://forums.whatthetech.com/csrssc_exe_other_problems_t91807.html&quot;&gt;http://forums.whatthetech.com/csrssc_exe_other_problems_t91807.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
If that site won&apos;t load because of the infection let me know and I&apos;ll throw up a temporary mirror of the content for you.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1617996</guid>
		<pubDate>Mon, 26 Jan 2009 01:56:41 -0800</pubDate>
		<dc:creator>Xuff</dc:creator>
	</item><item>
		<title>By: Rhaomi</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1618001</link>	
		<description>&lt;i&gt;&quot;Victory at all costs, victory in spite of all terror, victory however long and hard the road may be; for without victory there is no survival.&quot;&lt;/i&gt;&lt;br&gt;
&lt;br&gt;
Like the quote? It&apos;s from Winston Churchill. I found it by searching GOOGLE. Without being SPAMMED. &lt;small&gt;WOOOOOOHOO.&lt;/small&gt;&lt;br&gt;
&lt;br&gt;
As is the case for most of these issues, the solution was pretty simple, if difficult to track down. I wasted a lot of time trying to isolate and kill that csrssc.exe file, which kept getting recreated randomly. I ended up deleting it in safe mode as the administrator -- I had to change the ownership and permissions of the container folder to get at it, though.&lt;br&gt;
&lt;br&gt;
Anyway, I did more searching using the base URL of the spam site redirect: &quot;go.google.com&quot;. That led me to &lt;a href=&quot;http://www.computing.net/answers/security/yet-another-google-redirect-virus/24030.html&quot;&gt;this site&lt;/a&gt;, which suggested the site block/redirect/antiviral interference problem stemmed from a certain service.&lt;br&gt;
&lt;br&gt;
Here are their instructions:&lt;br&gt;
&lt;blockquote&gt;Thank you for your help. I&apos;m not finished yet, but I did discover something important for those of us who are so completely hijacked that we can&apos;t download or run the anti-malware programs. My sister (aka &quot;the LAN Goddess&quot;) found this on www.Troublefixers.com and I am copying it verbatim. It fixed my problems with loading and running the software, at least. Maybe now we can get to the bottom of this.&lt;br&gt;
&lt;blockquote&gt;We have received a comment on this post which will again help you remove go.google.com redirect virus given below&lt;br&gt;
&lt;br&gt;
Last Method to Remove Go.google.com virus&lt;br&gt;
&lt;br&gt;
Go to Start &amp;gt; Control Panel &amp;gt; System &amp;gt; Hardware &amp;gt; Device Manager &amp;gt; View &amp;gt; Show Hidden Devices.&lt;br&gt;
&lt;br&gt;
Scroll down to &quot;Non-plug and Play Drivers&quot; and click the plus icon to open those drivers.&lt;br&gt;
&lt;br&gt;
Then search for &quot;TDSSserv.sys&quot;&lt;br&gt;
&lt;br&gt;
Right click on it, and select &quot;Disable&quot;&lt;br&gt;
&lt;br&gt;
Note: If you select Uninstall, it will install itself again when you reboot the system, so DON&apos;T select Uninstall.&lt;br&gt;
&lt;br&gt;
Restart your pc.&lt;/blockquote&gt;You can now update your Antirus/Malware/Rootkit softwares and the go.google rubbish will stop.&lt;br&gt;
&lt;br&gt;
Its now up to the Anti-Virus/Malware/Spyware companies to make an effort to stop this, and not rely on simple basic home PC user&apos;s like myself to save the world&lt;br&gt;
&lt;br&gt;
In simple terms, TDSSserv.sys is a service/server redirecting all software updates to 127.0.0.1 (your own computer) so they won&apos;t update.&lt;br&gt;
&lt;br&gt;
Ron&lt;/blockquote&gt;It worked like a charm, at first. Google worked, antivirus sites worked, the Malwarebytes installer worked. I then ran the AVG updater to get the latest virus definitions. The updated info allowed what I assume to be the original infection to be detected. I tried to delete it but it threw up a blue screen of death. A final, useless gambit! After restarting I immediately ran AVG and knocked the infection out. I&apos;m now running one last scan to clear out any lingering problems, and will check tomorrow for residual stuff like keyloggers and adware.&lt;br&gt;
&lt;br&gt;
Thanks so much you guys for your patience and help! I hope my slog helps out a few fellow victims out there, too.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1618001</guid>
		<pubDate>Mon, 26 Jan 2009 02:36:24 -0800</pubDate>
		<dc:creator>Rhaomi</dc:creator>
	</item><item>
		<title>By: Rhaomi</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1618002</link>	
		<description>Oh, and patnok gets brownie points for identifying the trojan -- one of them was indeed of the vundo &quot;strain&quot;.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1618002</guid>
		<pubDate>Mon, 26 Jan 2009 02:37:30 -0800</pubDate>
		<dc:creator>Rhaomi</dc:creator>
	</item><item>
		<title>By: Rhaomi</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1618007</link>	
		<description>Lastly, for posterity, here are the instructions I used to access the registry and show hidden folders after initially being denied:&lt;br&gt;
&lt;br&gt;
&lt;b&gt;ENABLE REGEDIT&lt;/b&gt; - This will allow access to the registry editor if a virus has blocked it.&lt;br&gt;
&lt;br&gt;
Start -&amp;gt; Run -&amp;gt; type in gpedit.msc&lt;br&gt;
&lt;br&gt;
In the window&apos;s left-hand pane, expand User configuration, then Administrative Templates, then select System&lt;br&gt;
&lt;br&gt;
Double-click &quot;Prevent access to registry editing tools&quot; on the right and change it to Disabled&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;b&gt;SHOW HIDDEN FOLDERS&lt;/b&gt; - This will allow you to reveal all hidden folders if there is no &quot;Folder Options&quot; in your folders&apos; Tools menu.&lt;br&gt;
&lt;br&gt;
Start -&amp;gt; Run -&amp;gt; type in regedit&lt;br&gt;
&lt;br&gt;
Using the folder tree on the left, navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced&lt;br&gt;
&lt;br&gt;
Double-click the item &quot;Hidden&quot; on the right and change the value to &quot;1&quot;.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1618007</guid>
		<pubDate>Mon, 26 Jan 2009 02:51:02 -0800</pubDate>
		<dc:creator>Rhaomi</dc:creator>
	</item><item>
		<title>By: HopperFan</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1618077</link>	
		<description>Trojans are only part of the issue : &quot;Like any other of its predecessors, Antivirus2009 uses trojans, such as Zlob or Vundo, to spread.&quot;&lt;br&gt;
&lt;br&gt;
Glad you got it worked out!</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1618077</guid>
		<pubDate>Mon, 26 Jan 2009 06:27:39 -0800</pubDate>
		<dc:creator>HopperFan</dc:creator>
	</item><item>
		<title>By: SuperSquirrel</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1618112</link>	
		<description>A huge thank you for all this info! Halfway to FINALLY cleaning out the crap out of my daughter&apos;s pc, which has been a long-standing ulcer-inducing THANG.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1618112</guid>
		<pubDate>Mon, 26 Jan 2009 07:03:42 -0800</pubDate>
		<dc:creator>SuperSquirrel</dc:creator>
	</item><item>
		<title>By: Rhaomi</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1618139</link>	
		<description>Final (?) update: First thing this morning, installed Malwarebytes and let it scan. It turned up &lt;b&gt;twice&lt;/b&gt; as much stuff as AVG did, including the registry change that had hidden the &quot;folder options&quot; menu. Everything seems to be free and clear now!</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1618139</guid>
		<pubDate>Mon, 26 Jan 2009 07:45:11 -0800</pubDate>
		<dc:creator>Rhaomi</dc:creator>
	</item><item>
		<title>By: PeterParker</title>
		<link>http://ask.metafilter.com/112548/Digital-Immunodeficiency-Disorder#1646186</link>	
		<description>Make sure you reboot your computer immediately after removing the viruses.  Often times they can simply regenerate themselves if you don&apos;t.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.112548-1646186</guid>
		<pubDate>Thu, 19 Feb 2009 12:51:27 -0800</pubDate>
		<dc:creator>PeterParker</dc:creator>
	</item>
	</channel>
</rss>
