Solved

Virus blocking antivirus websites

Posted on 2006-07-08
7
1,503 Views
Last Modified: 2009-03-28
Hi all

I got a virus from   a sent from while on msn. It disabled my AV (AVG) and closes msconfig, regedit and things like that. It also blocks ALL antivirus websites! It runs as csrss.exe (the illegit one). I managed to disable/delete it, but its damage is done. I cannt get to any AV site yet. I have run avg, trendmicro, ewido and aware... all to no avail. I also ran the winsock fix. Any ideas guys?
0
Comment
Question by:Zorkinhimerlingling
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 47

Accepted Solution

by:
rpggamergirl earned 120 total points
ID: 17064817
Please download HijackThis 1.99.1 and let us look at the log.
http://www.cyberanswers.org/forum/uploads/HijackThis1991.exe
Open Hijackthis, click "Do a system scan and save a logfile" don't fix anything yet.

Then go to the below link and login using your Experts-Exchange username and password.
http://www.ee-stuff.com
Click on "Expert Area" tab
type or paste the link to your Question
"Browse" your pc to the location of your Hijackthis log and click "Upload"
Copy the resulting "url" and post it back here.


OR: just paste the log to this site:
http://www.rafb.net/paste/
then at the bottom left corner click "paste"
Copy the address/url and post it here.


The worm has blocked security sites, so check your hosts file.
Windows XP = C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts


Edit your hosts file, delete any entries below this line --> 127.0.0.1 localhost

or at --> http://www.hijackthis.de/ 
and click "Analyse", click "Save".  Then post the link to the saved list here.
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 17064850
Hijackthis log can tell us the exact virus in your pc,
but without looking at your log I'm 90% positive that what you have is the chod.d worm and here is the fix.( I could be wrong of course but it doesn't hurt to run the tool)

Please Download MsnVirRem.exe to your desktop from one of the following mirrors:

http://downloads.malwareremoval.com/MsnVirRem.exe
http://www.thespykiller.co.uk/forum/index.php?action=tpmod;dl=item9
http://www.greyknight17.com/spy/MsnVirRem.exe

* First close any other programs you have running as this will require a reboot
* Double click MsnVirRem.exe to run it
* Once open, click the button labelled "Search and Destroy"
      <<Your computer will now be scanned for Infected Files>>
* When scanning is finished you will be prompted to reboot only if infected, Click OK
* Now click the "REBOOT" Button.
* After the Reboot, you WILL receive file not found errors (usually 4) please acknowledge them and continue.
* A Message should popup from MsnVirRem if not, double click the program again and it will finish

Please Post the contents of C:\msnvirrem.log
0
 
LVL 1

Author Comment

by:Zorkinhimerlingling
ID: 17065157
ah you guys are great, will try that tonight. Yes I heard something about chod in my research of this problem...
0
[Live Webinar] The Cloud Skills Gap

As Cloud technologies come of age, business leaders grapple with the impact it has on their team's skills and the gap associated with the use of a cloud platform.

Join experts from 451 Research and Concerto Cloud Services on July 27th where we will examine fact and fiction.

 
LVL 1

Author Comment

by:Zorkinhimerlingling
ID: 17066586
Fixing the host file fixed my problem, thank you very much.
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 17066622
No problem, thanks!

The virus added those entries in your hosts file but the virus would still be there I guess unless it has been removed.
If problem comes back just run the tool I've mentioned.
Anyhow, we'll be here to help anytime, :)

Good luck!
0
 
LVL 1

Author Comment

by:Zorkinhimerlingling
ID: 17066721
Wish i had more points to give out. Anyway, yes I deleted the virus from my java cache, and had previously ran hijack this. This was just the final damage it had caused. It was interesting to see that exact list of websites it was blockin'. What a bugger!
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 17066741
>>Wish i had more points to give out. <<

Don't worry, we would still help even if you only have 20 pts to give, :)
Glad you got rid of the virus that's the main thing.

One day when you become a premium member you'll have unlimited points to give, :)
0

Featured Post

What, When and Where - Security Threats from Q1

Join Corey Nachreiner, CTO, and Marc Laliberte, Information Security Threat Analyst, on July 26th as they explore their key findings from the first quarter of 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here's a look at newsworthy articles and community happenings during the last month.
Article by: Justin
In light of the WannaCry ransomware attack that affected millions of Windows machines, you might wonder if your Mac needs protecting. Yes, it does and here is how to do it.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
Suggested Courses
Course of the Month7 days, 15 hours left to enroll

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question