Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: csrss.exe & smss.exe - Infected Machine?  (Read 3624 times)

0 Members and 1 Guest are viewing this topic.

EchoLynx

    Topic Starter


    Rookie

    Thanked: 1
    csrss.exe & smss.exe - Infected Machine?
    « on: December 23, 2009, 08:48:45 PM »
    I am trying to clean a business machine of a particularly nasty virus. The machine isn't actually mine - I was given it and told the owner had no idea what was wrong with it. Initial diagnosis showed the browser hadn't been hijacked, and no ads presented themselves. There were sporadic slowdowns, which were helped by a RAM upgrade, but a strange screen blanking at boot just prior to the initialisation of the VZAccess Manager (The machine is a laptop and uses 3G broadband as the primary connection. I am continuing to use this as I am not willing to risk my home network by connecting to it.) I updated the Manager, which resolved this problem. However, when I looking at the Task manager I noticed a couple programs I haven't seen before - csrss.exe and smss.exe. Further research proved that they were likely viruses. So I began my time consuming routine of running as many (free) antivirus utilities I could. Below is the list of those I've done already.

    - avast! Antivirus Boot Time Scan x2 (second one was near the end of the cycle and didn't return any hits) - many hits
    - AVG - returned several hits
    - SUPERAntiSpyware - returned some hits
    - Malwarebyte's Anti-Malware - 24 hits!
    - Spybot S&D - returned some hits
    - Windows Defender - returned one hit (First time for everything...)
    - Avira Rescue CD - returned one hit*
    - Ad-Aware - no hits
    - ClamWin - no hits
    - Stinger - no hits

    *Just after I had tried to install COMODO Firewall (with the intent of using it's Defense+ capabilities combined with it's connection notifications in order to detect any "phoning home") my system became unusable. Essentially, explorer.exe would not start. To work around this, I used the Task Manager to run applications and the commandline. It was from the commandline that I was able to Uninstall COMODO. Afterwards, I ran a virus scan with the Avira Rescue CD, which removed the problematic bug and thereafter I was able to install and use COMODO.

    --

    Unfortunately, though I was able to remove over fifty unwanted objects, nothing solved the csrss.exe or the smss.exe issue. Which brings me here. I am suspecting the user had installed LimeWire, as there is remnants of it's presence in the Program Files folder, which is what I suspect caused all this mess. Hopefully, you all can help me out.

    I read the requirements of posting and cleaned up. In the process of doing so, I discovered a folder - C:\Program Files\microsoft frontpage - that is *supposedly* empty (even with view hidden files on) but is still in use and therefore undeletable.

    I also re-ran the virus scans and double checked I had the most up to date JRE, so as to ensure I followed all given directions to the letter.

    Thanks for reading my lengthy post.

    [Saving space, attachment deleted by admin]
    Ian

    unlovedwarrior



      Guru

    • someday this name will be known
    • Thanked: 13
      Re: csrss.exe & smss.exe - Infected Machine?
      « Reply #1 on: December 26, 2009, 12:05:00 AM »
      are u doing these scans in safe mode? and can u give the file path of the two files? also upload them to http://www.virustotal.com/
      for more checking

      ps are u doing full system scans or just quick scans?

      Dr Jay

      • Malware Removal Specialist


      • Specialist
      • Moderator emeritus
      • Thanked: 119
      • Experience: Guru
      • OS: Windows 10
      Re: csrss.exe & smss.exe - Infected Machine?
      « Reply #2 on: September 18, 2010, 08:52:37 PM »
      Does the machine need help or not?
      ~Dr Jay