Solved

Virus blocking antivirus websites

Posted on 2006-07-08
7
1,491 Views
Last Modified: 2009-03-28
Hi all

I got a virus from   a sent from while on msn. It disabled my AV (AVG) and closes msconfig, regedit and things like that. It also blocks ALL antivirus websites! It runs as csrss.exe (the illegit one). I managed to disable/delete it, but its damage is done. I cannt get to any AV site yet. I have run avg, trendmicro, ewido and aware... all to no avail. I also ran the winsock fix. Any ideas guys?
0
Comment
Question by:Zorkinhimerlingling
  • 4
  • 3
7 Comments
 
LVL 47

Accepted Solution

by:
rpggamergirl earned 120 total points
ID: 17064817
Please download HijackThis 1.99.1 and let us look at the log.
http://www.cyberanswers.org/forum/uploads/HijackThis1991.exe
Open Hijackthis, click "Do a system scan and save a logfile" don't fix anything yet.

Then go to the below link and login using your Experts-Exchange username and password.
http://www.ee-stuff.com
Click on "Expert Area" tab
type or paste the link to your Question
"Browse" your pc to the location of your Hijackthis log and click "Upload"
Copy the resulting "url" and post it back here.


OR: just paste the log to this site:
http://www.rafb.net/paste/
then at the bottom left corner click "paste"
Copy the address/url and post it here.


The worm has blocked security sites, so check your hosts file.
Windows XP = C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts


Edit your hosts file, delete any entries below this line --> 127.0.0.1 localhost

or at --> http://www.hijackthis.de/ 
and click "Analyse", click "Save".  Then post the link to the saved list here.
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 17064850
Hijackthis log can tell us the exact virus in your pc,
but without looking at your log I'm 90% positive that what you have is the chod.d worm and here is the fix.( I could be wrong of course but it doesn't hurt to run the tool)

Please Download MsnVirRem.exe to your desktop from one of the following mirrors:

http://downloads.malwareremoval.com/MsnVirRem.exe
http://www.thespykiller.co.uk/forum/index.php?action=tpmod;dl=item9
http://www.greyknight17.com/spy/MsnVirRem.exe

* First close any other programs you have running as this will require a reboot
* Double click MsnVirRem.exe to run it
* Once open, click the button labelled "Search and Destroy"
      <<Your computer will now be scanned for Infected Files>>
* When scanning is finished you will be prompted to reboot only if infected, Click OK
* Now click the "REBOOT" Button.
* After the Reboot, you WILL receive file not found errors (usually 4) please acknowledge them and continue.
* A Message should popup from MsnVirRem if not, double click the program again and it will finish

Please Post the contents of C:\msnvirrem.log
0
 
LVL 1

Author Comment

by:Zorkinhimerlingling
ID: 17065157
ah you guys are great, will try that tonight. Yes I heard something about chod in my research of this problem...
0
U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

 
LVL 1

Author Comment

by:Zorkinhimerlingling
ID: 17066586
Fixing the host file fixed my problem, thank you very much.
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 17066622
No problem, thanks!

The virus added those entries in your hosts file but the virus would still be there I guess unless it has been removed.
If problem comes back just run the tool I've mentioned.
Anyhow, we'll be here to help anytime, :)

Good luck!
0
 
LVL 1

Author Comment

by:Zorkinhimerlingling
ID: 17066721
Wish i had more points to give out. Anyway, yes I deleted the virus from my java cache, and had previously ran hijack this. This was just the final damage it had caused. It was interesting to see that exact list of websites it was blockin'. What a bugger!
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 17066741
>>Wish i had more points to give out. <<

Don't worry, we would still help even if you only have 20 pts to give, :)
Glad you got rid of the virus that's the main thing.

One day when you become a premium member you'll have unlimited points to give, :)
0

Featured Post

Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
opensource email gateway 9 66
Win 7 PCs cant connect to RDS server , but Win 10 can 21 91
Penetration Testing home based work 3 75
Admin account lockout 10 40
If you thought ransomware was bad, think again! Doxware has the potential to be even more damaging.
With healthcare moving into the digital age with things like Healthcare.gov, the digitization of patient records and video conferencing with patients, data has a much greater chance of being exposed than ever before.
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question