Re: How to tell the running process--csrss.exe is malicious or not?

From: Galen (galennews_at_gmail.com)
Date: 04/25/05


Date: Mon, 25 Apr 2005 10:19:28 -0400

In news:OaPy$3XSFHA.508@TK2MSFTNGP12.phx.gbl,
john <anonymous@discussion.microsoft.com> had this to say:

 My reply is at the bottom of your sent message:

> From the information about csrss.exe on the internet, it could be
> normal process or virus.
>
> But how can I find out its true attributes? By some specific
> software, or not?
>
> Thank you.

It's actually potentially a legitimate file but, as you've been told, it's
also potentially a virus. It's normally the main exe file for the Microsoft
Client/Server Runtime Server Subsystem but it's also capable of being a
number of viruses and trojans. Here's some varied links if they are what
you're really interested in.

Virus:
www.grisoft.com - AVG
www.antivir.com - AntiVir
http://www.my-etrust.com/microsoft/index.cfm - CA eTrust

Spyware:
www.lavasoft.de - AdAware
http://security.kolla.de/ - Spybot
http://www.microsoft.com/athome/security/spyware/software/default.mspx -
Microsoft Anti-Spyware Beta

Trojan:
www.emsisoft.com/en/software/free/ - a Squared
http://swatit.org/ Swat It

Before cleaning download this:

LSP-Fix - a free program to repair damaged Winsock 2 stacks:
http://www.cexx.org/lspfix.htm

Use that should cleaning out your PC remove or damage your in-place winsock
and you can't connect to the internet.

>From the virus and trojan category pick one application, they're all free,
download it and install it. Make sure that you update it. From the spyware
category pick all three, download them and update them to the latest
definitions. Reboot, press the F8 key over and over again, from the menu
select Safe mode without networking. Do your cleaning in there. Reboot to
regular mode and run the scans again. This isn't going to be quick or easy
but it might just solve your problems and it should prevent you from further
problems so long as you keep them updated and scan often. Most of them can
be enabled to update and scan automatically.

Galen

-- 
Signature changed for a moment of silence.
Rest well Alex and we'll see you on the other side. 


Relevant Pages

  • Re: desktop,themes tabs Missing
    ... It also might not be virus, ... for spyware too. ... Before cleaning download this: ... Use that should cleaning out your PC remove or damage your in-place winsock ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: xp shuts down
    ... Spyware? ... Virus? ... Before cleaning download this: ... Use that should cleaning out your PC remove or damage your in-place winsock ...
    (microsoft.public.windowsxp.general)
  • Re: How Do I Remove Hotfix KB828741?
    ... > jim evans wrote: ... >> I have to have virus protection. ... Before cleaning download this: ... Use that should cleaning out your PC remove or damage your in-place winsock ...
    (microsoft.public.windowsxp.general)
  • Re: Virus (Trojan?)
    ... >> I think I've picked up a virus. ... Before cleaning download this: ... Use that should cleaning out your PC remove or damage your in-place winsock ... select Safe mode without networking. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Internet Explorer 6.0
    ... > I tried to run sfc /scannow and on prompting, inserted my XP disc. ... > have reinstalled it ayear ago after a virus attack, ... Before cleaning download this: ...
    (microsoft.public.windowsxp.help_and_support)