Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1511
  • Last Modified:

Virus blocking antivirus websites

Hi all

I got a virus from   a sent from while on msn. It disabled my AV (AVG) and closes msconfig, regedit and things like that. It also blocks ALL antivirus websites! It runs as csrss.exe (the illegit one). I managed to disable/delete it, but its damage is done. I cannt get to any AV site yet. I have run avg, trendmicro, ewido and aware... all to no avail. I also ran the winsock fix. Any ideas guys?
0
Zorkinhimerlingling
Asked:
Zorkinhimerlingling
  • 4
  • 3
1 Solution
 
rpggamergirlCommented:
Please download HijackThis 1.99.1 and let us look at the log.
http://www.cyberanswers.org/forum/uploads/HijackThis1991.exe
Open Hijackthis, click "Do a system scan and save a logfile" don't fix anything yet.

Then go to the below link and login using your Experts-Exchange username and password.
http://www.ee-stuff.com
Click on "Expert Area" tab
type or paste the link to your Question
"Browse" your pc to the location of your Hijackthis log and click "Upload"
Copy the resulting "url" and post it back here.


OR: just paste the log to this site:
http://www.rafb.net/paste/
then at the bottom left corner click "paste"
Copy the address/url and post it here.


The worm has blocked security sites, so check your hosts file.
Windows XP = C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts


Edit your hosts file, delete any entries below this line --> 127.0.0.1 localhost

or at --> http://www.hijackthis.de/ 
and click "Analyse", click "Save".  Then post the link to the saved list here.
0
 
rpggamergirlCommented:
Hijackthis log can tell us the exact virus in your pc,
but without looking at your log I'm 90% positive that what you have is the chod.d worm and here is the fix.( I could be wrong of course but it doesn't hurt to run the tool)

Please Download MsnVirRem.exe to your desktop from one of the following mirrors:

http://downloads.malwareremoval.com/MsnVirRem.exe
http://www.thespykiller.co.uk/forum/index.php?action=tpmod;dl=item9
http://www.greyknight17.com/spy/MsnVirRem.exe

* First close any other programs you have running as this will require a reboot
* Double click MsnVirRem.exe to run it
* Once open, click the button labelled "Search and Destroy"
      <<Your computer will now be scanned for Infected Files>>
* When scanning is finished you will be prompted to reboot only if infected, Click OK
* Now click the "REBOOT" Button.
* After the Reboot, you WILL receive file not found errors (usually 4) please acknowledge them and continue.
* A Message should popup from MsnVirRem if not, double click the program again and it will finish

Please Post the contents of C:\msnvirrem.log
0
 
ZorkinhimerlinglingAuthor Commented:
ah you guys are great, will try that tonight. Yes I heard something about chod in my research of this problem...
0
Managing Security Policy in a Changing Environment

The enterprise network environment is evolving rapidly as companies extend their physical data centers to embrace cloud computing and software-defined networking. This new reality means that the challenge of managing the security policy is much more dynamic and complex.

 
ZorkinhimerlinglingAuthor Commented:
Fixing the host file fixed my problem, thank you very much.
0
 
rpggamergirlCommented:
No problem, thanks!

The virus added those entries in your hosts file but the virus would still be there I guess unless it has been removed.
If problem comes back just run the tool I've mentioned.
Anyhow, we'll be here to help anytime, :)

Good luck!
0
 
ZorkinhimerlinglingAuthor Commented:
Wish i had more points to give out. Anyway, yes I deleted the virus from my java cache, and had previously ran hijack this. This was just the final damage it had caused. It was interesting to see that exact list of websites it was blockin'. What a bugger!
0
 
rpggamergirlCommented:
>>Wish i had more points to give out. <<

Don't worry, we would still help even if you only have 20 pts to give, :)
Glad you got rid of the virus that's the main thing.

One day when you become a premium member you'll have unlimited points to give, :)
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now