| | #1 (permalink) | |
| On The assumption my comp is infected..I curiosly hit CTRL-ALT-DELETE, Ive went though and researched some of the processes that were running.. Everything looked NOrmal..except some process I did reconize..I noticed my comp was using 100% cpu went booting...and i remeber it hasnt used that much...now lets look at what we have... csrss.exe - Process Information Process File: csrss or csrss.exe Process Name: Microsoft Client/Server Runtime Server Subsystem Description: csrss.exe is the main executable for the Microsoft Client/Server Runtime Server Subsystem. This process manages most graphical commands in Windows. This program is important for the stable and secure running of your computer and should not be terminated. Note: csrss.exe is also process which is registered as the W32.Netsky.AB@mm worm, the W32.Webus Trojan, Win32.Ladex.a and more. This virus is distributed via the Internet through e-mail and comes in the form of an e-mail message, in the hopes that you open itÂ’s hostile attachment. The worm has itÂ’s own SMTP engine which means it gathers E-mails from your local computer and re-distributes itself. In worst cases this worm can allow attackers to access your computer, stealing passwords and personal data. It is a registered security risk and should be removed immediately. Please see additional details regarding this process smss.exe - Process Information Process File: smss or smss.exe Process Name: Session Manager Subsystem Description: smss.exe is a process which is a part of the Microsoft Windows Operating System. It is called the Session Manager SubSystem and is responsible for handling sessions on your system. This program is important for the stable and secure running of your computer and should not be terminated. Note: smss.exe is also a process which is registered as the Win32.Ladex.a Trojan. This Trojan allows attackers to access your computer, stealing passwords and personal data. It is a registered security risk and should be removed immediately. And there was one more I could remeber because it came up so quickly when I booted. But Im screwed Arent I? Im using AVG for Free...=/ and oddly hasnt seen these. I cant disable them using task manager...nor using msconfig. I think it all started when I installed Java..All I wanted to do was do an online scan..but no..I think java did something to my comp also..I deleted it. I'll try searching for those files, go into safe mode and delete them. If Not, Back up and Format. I wish I knew what file they came in though... EDIT: I would also notice my comp would be using 100% CPU when I was just sitting there. Doing Nothing. One question to, If A port is forwarded on my router is it left open all the time? OR is it only opened when requested? If So, how does the router know if its a trojan and not the program? btw I am not using a software firewall. I am using the router as a firewall. I was told I did not need one. Last edited by Nerdz; 27-May-05 at 11:46 PM.. | ||
| | | |
| | #7 (permalink) | |
| Well, first off, you can never have too much security, and the fact that you got a virus is proof. I think that when you use port forwarding it is open all the time, not just when requested. I wouldn't use it, but i don't know what you need it for. also, i don't think any home router can tell what type of activity, actual program or virus is going on, i know some commercial products from hp and cisco can with their virus throttling technology. One of the approaches i like to take towards security, is only enable what you need and leave everything else closed off. | ||
| | | |
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| This is so cool. | Wafflesomd | Anything Goes | 6 | 10-October-06 12:12 AM |
| Cool or not? | unit505 | Case Modding | 8 | 16-July-06 11:39 AM |
| FrozenCPU // Innovatek Pentium 4 Socket 775 Retaining System ( i-Cool Rev 3.0 / i-Cool Rev 4.0 / Plex-O-Matic / V6 Cooler) (501043) | Gizmo | Vendor News RSS | 0 | 13-April-05 03:05 AM |
| cool res | Rewind | Extreme Cooling | 9 | 29-July-03 10:14 AM |
| wow i did something cool... | Fu3lman | Case Modding | 18 | 02-April-03 07:00 PM |