Hi Chaps..
There I was, sitting in the toyroom minding my own business when in comes offspring. 'Can you come and look at my pc please daddy'

Why is it such a simple question can make you feel dread to the pit of your stomach?

This time, it was with some justification!
She'd pulled the network cable and pwr lead when things started to look odd so I plugged it back in and turned it on. At the main screen was a nice little window saying 'your system is infected with multiple viruses' with a company logo 'System Tools' on the top line. Where did you get this from.. I didn't! Ah!

After scratching my head and fearing the worst.. I tried various things but the program had cleverly disabled all exe files. It seemed the only way out was to do as it asked and connect to the internet to let the program 'System Tools' remove the viruses. At that point, I'd seen enough. I asked Helen to go to the office pc and google System tools virus and up came a host of info. The virus is of course the program itself. I dread to think what info it would have gathered had we gone online and done as it asked or what damage it would have done. Fear not though.. it is possible to remove it. Going the 'manual' way is almost if not impossible. The automatic way was to download a prog called Malwarebytes Anti-Malware on another pc.. rename it as the virus knows the prog name.. restart the pc in safe mode (with networking) then run the Malware prog. Finally, get a copy of 'host' (a link was provided but I took one from another pc.. they all look the same!).. go to System32/drivers/etc and delete the copy of host there then replace it with the 'good' one. Restart the pc.. hold your breath and the end result is a clean system.
It's a bugger and no mistakin. Had we not had other means of getting online, I'm not sure what we'd have done. It's classified as Dangerous with a 'Medium' damage level so it's a seriously nasty bit of kit.
While looking through her system after the virus had been removed, I found various artifacts and unused Norton progs. Believe it or not, these were more difficult to remove! Uninstall didn't work.. it reported an error so I tried 'repair' hoping that a repaired version would uninstall but no.. another error reported. In the end, I went digging in the registry and binned as many keys as I could THEN noticed she had CCleaner. What a Bobby Dazzler that little program is. I'd not used it before but it is user friendly and you don't end up doing things you have no idea of which the consequences will be

Gone, at last, is Norton
ATB
DaveB
