Seems like I caught something

Discussion in 'Malware Help (A Specialist Will Reply)' started by whatthewhatthe, Nov 26, 2008.

  1. whatthewhatthe

    whatthewhatthe Private E-2

    Righto.
    So, the other night I got a warning from norton about some file accessing something or other... csrssc.exe
    I had a look and a heap of applications were now present in my c:\ directory.
    I've deleted them and ran a scan on Malwarebytes and 'repaired' a bunch of things it found.
    After restarting my computer, I've found that norton is completely disabled (application files deleted), and I can't connect to the internet (though I can connect to my modem and router).
    Whatever this thing is, it's edited my internet settings and 'unchecked' the "show pictures" option in the advanced settings.
    Can anyone help? I can post logs from whatever application if that'd help
    cheers.
     
  2. whatthewhatthe

    whatthewhatthe Private E-2

    OK, I've attached my most recent HJT, ComboFix and MBAM logs.

    Just checked something out, and my norton files hadn't been deleted (I was looking in the wrong folder :-o), though NIS no longer loads on startup. Don't know if that helps, just thought I'd mention it.

    Thanks guys
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We need you to run the MGTools program and attach the C:\MGLogs.zip.
     
  4. whatthewhatthe

    whatthewhatthe Private E-2

    Cool. Thanks.
    Latest logs are attached.
    Search and Destroy didn't find anything.
    Internet connection is still down so there's something interfering there...
    All help appreciated.
    Ta.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, your logs are clean. I would suggest that, if running a router, you reset it to factory settings, check your network properties and be sure that dns and ip are set to auto detect.
    Also go to your IE settings and reset security to default.

    If this does not work, please post in the software or networking section.

     
  6. whatthewhatthe

    whatthewhatthe Private E-2

    Thanks TimW,

    Turns out this thing edited my network settings and deleted my DNS specifics, disabling my internet access. It also locked my task-bar, cleared out my start-up folder, disabled viewing images in internet explorer, plus probably a whole heap of other things which I haven't worked out yet.

    My Norton internet security monitored some of the activity that was attempted and/or performed:
    "payload was blocked from accessing your network resources"
    "firewall rules were automatically created for naoe"
    "firewall rules were automatically created for ocvugtko"
    "firewall rules were automatically created for services"
    "cohdejrg.exe modified your program startup settings"
    "2684403242.exe modified your windows atartup settings"
    "csrssc was blocked from accessing your network resources"
    "winlogin was blocked from accessing your network resources"
    "winlogin detected by norton internet security"
    .... then it gets a bit confusing as I began to install some anti-spyware applications at that stage.

    Anyway, all seems well here for now.

    I guess it serves me right for attempting to download an application via a torrent, rather than the author's website.

    Thanks for your help, and the verification that the logs are clean (otherwise I'd likely be fretting).

    Cheers.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....it is a nasty that resets your router setting and then causes havoc within your system.

    Good to know you are back running. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds