PC Review


Reply
Thread Tools Rate Thread

csrss.exe files

 
 
ron.morse@gmail.com
Guest
Posts: n/a
 
      13th Mar 2007
It seems I have an 'extra' csrss.exe file. Hijack this tells the
following:

"This entry is not running from the System32 folder, so it is
probably nasty.
Possibly nasty! According to our database this process runs normally
in c:\windows\system32\! Check if you know this process and arrange a
viruscheck where required.This process is not running from the
System32 folder as it is supposed to be."
and:
"Must be fixed!Added by the CIADOOR-J TROJAN! Note - this is not the
legitimate csrss.exe process which is always located in the System (9x/
Me) or System32 (NT/2K/XP) folder and should not normally figure in
Msconfig/Startup! This file is located in the Winnt or Windows folder"
I did a search for the file and it's in both WINDOWS and WINDOWS
\system32. the first one is 144kb, version 1.0.0.0 and was added a
couple days ago when I started having problems. The second file is 6kb
version 5.1.2600.2180 (xpsp_sp2) and I'm pretty sure it's the legit
one. At this point, what steps should I take?
I'm also having the same problems with services.exe and syshost.exe.
Services.exe has a copy in both folders, syshost is only in WINDOWS
folder. All three suspect files were created last week.

thanks for the help
(E-Mail Removed)

 
Reply With Quote
 
 
 
 
Lem
Guest
Posts: n/a
 
      13th Mar 2007
(E-Mail Removed) wrote:
> It seems I have an 'extra' csrss.exe file. Hijack this tells the
> following:
>
> "This entry is not running from the System32 folder, so it is
> probably nasty.
> Possibly nasty! According to our database this process runs normally
> in c:\windows\system32\! Check if you know this process and arrange a
> viruscheck where required.This process is not running from the
> System32 folder as it is supposed to be."
> and:
> "Must be fixed!Added by the CIADOOR-J TROJAN! Note - this is not the
> legitimate csrss.exe process which is always located in the System (9x/
> Me) or System32 (NT/2K/XP) folder and should not normally figure in
> Msconfig/Startup! This file is located in the Winnt or Windows folder"
> I did a search for the file and it's in both WINDOWS and WINDOWS
> \system32. the first one is 144kb, version 1.0.0.0 and was added a
> couple days ago when I started having problems. The second file is 6kb
> version 5.1.2600.2180 (xpsp_sp2) and I'm pretty sure it's the legit
> one. At this point, what steps should I take?
> I'm also having the same problems with services.exe and syshost.exe.
> Services.exe has a copy in both folders, syshost is only in WINDOWS
> folder. All three suspect files were created last week.
>
> thanks for the help
> (E-Mail Removed)
>

Not running any anti-virus app?

See advice here, especially Part B:
http://www.elephantboycomputers.com/...moving_Malware

--
Lem MS MVP -- Networking

To the moon and back with 64 Kbits of RAM and 512 Kbits of ROM.
http://en.wikipedia.org/wiki/Apollo_Guidance_Computer
 
Reply With Quote
 
Elmo
Guest
Posts: n/a
 
      13th Mar 2007
(E-Mail Removed) wrote:
> It seems I have an 'extra' csrss.exe file. Hijack this tells the
> following:
>
> "This entry is not running from the System32 folder, so it is
> probably nasty.
> Possibly nasty! According to our database this process runs normally
> in c:\windows\system32\! Check if you know this process and arrange a
> viruscheck where required.This process is not running from the
> System32 folder as it is supposed to be."
> and:
> "Must be fixed!Added by the CIADOOR-J TROJAN! Note - this is not the
> legitimate csrss.exe process which is always located in the System (9x/
> Me) or System32 (NT/2K/XP) folder and should not normally figure in
> Msconfig/Startup! This file is located in the Winnt or Windows folder"
> I did a search for the file and it's in both WINDOWS and WINDOWS
> \system32. the first one is 144kb, version 1.0.0.0 and was added a
> couple days ago when I started having problems. The second file is 6kb
> version 5.1.2600.2180 (xpsp_sp2) and I'm pretty sure it's the legit
> one. At this point, what steps should I take?
> I'm also having the same problems with services.exe and syshost.exe.
> Services.exe has a copy in both folders, syshost is only in WINDOWS
> folder. All three suspect files were created last week.


A few things to try:

1) Restart to a Safe Mode Command Prompt, type

CD C:\Windows

DEL csrss.exe

2) Schedule a boot scan within your a/v software so it can remove the
file before Windows starts.

3. Download software that can handle running malware. Just a couple..
I know that Avast! can be scheduled to do a boot scan:

Avast! - http://www.avast.com/eng/avast_4_home.html
AVG - http://free.grisoft.com/

--
Joe =o)
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
csrss.exe =?Utf-8?B?TGFycnkgRQ==?= Windows Vista General Discussion 2 17th Nov 2007 05:16 PM
2 files called csrss =?Utf-8?B?TmljayBPJyd0ZW5l?= Windows XP Security 2 7th Nov 2007 10:04 PM
How many true csrss.exe files are there in Win xp? =?Utf-8?B?dG9tbWk=?= Windows XP General 6 15th Oct 2005 11:47 PM
csrss.exe =?Utf-8?B?RG9u?= Windows XP General 2 8th Aug 2005 03:51 PM
Task Manager csrss / Csrss Bob Windows XP Help 3 17th Jan 2004 12:33 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 06:02 AM.