|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread |
Rating:
|
Display Modes |
|
|
#1 | |||
|
Member (7 bit)
|
csrss.exe, backdoor.bot, conhost.exe
Solved:
Just in case somebody Googles this and needs help: Quote:
Hey PCMech, it's been a while, That is to say, I've managed to not break my computer for quite a long time, but my streak seems to be over. Enter: csrss.exe There are two copies of it running. The first is a system file, the second is in a temp folder, which is coming up red on Malwarebytes, HijackThis, Spybot, AVG, and Security Task Manager. Running Malwarebytes gives me 3 infected issues: Quote:
Here's the HijackThis Log: Quote:
thanks a ton, -Omar Last edited by rabidsheeep; 12-06-2010 at 12:25 PM. |
|||
|
|
|
|
|
#2 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 41,163
|
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:52929
Control panel, Internet options - connections, LAN settings. Uncheck all boxes. F3 - REG:win.ini: load=C:\Users\OMARTH~1\AppData\Local\Temp\csrss.exe O1 - Hosts: ::1 localhost Use HJT to remove these. |
|
|
|
|
|
#3 |
|
Mondsreitersmann
Join Date: Jul 1999
Location: Skingrad
Posts: 8,969
|
And then clean out your Temp folder (C:\Users\OMARTH~1\AppData\Local\Temp\). You may have to enable viewing of hidden files and folders under Folder Options in the Control Panel to be able to do this.
Clean out also the contents of C:\Windows\Temp\.
__________________
Darum still, füg' ich mich, wie Gott es will. Nun, so will ich wacker streiten, und sollt' ich den Tod erleiden, stirbt ein braver Reitersmann. |
|
|
|
|
|
#4 |
|
Member (7 bit)
|
I managed to find a solution, at least I think I did.
For the backdoor.bot, I ran a Trendmicro Housecall scan which removed that pretty easily. Hijack this, as well as manually cleaning the temp folder wasn't removing csrss.exe. Just a reminder, the file was under my C:\USERS\ path, apparently there are other variations that hide in different spots. I backed up my files on a second hard drive and created a new user account with administrative privileges. Control panel > User Accounts > Create New Account I then logged out of my old account, logged into the new one, and deleted the old one. So far Malwarebytes, Housecall, and Hijack this all say that it's gone. Not to be paranoid, but am I at any risk that it's still hiding somewhere? |
|
|
|
|
|
#5 |
|
Mondsreitersmann
Join Date: Jul 1999
Location: Skingrad
Posts: 8,969
|
Malware loves to hide in System Restore so that it can reinstall itself. You can disable system restore, if you don't mind losing all your restore points.
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|