Featured Worklog

Price Search



PC Apex Sponsor


PC Apex Sponsors



PC Apex RSS Feeds

RSS Feed for PC Apex Reviews & ArticlesRSS Feed for PC Apex PC Modding WorklogsRSS Feed for the PC Apex Daily DisturbanceRSS Feed for the latest PC Apex Site NewsRSS Feed for PC Apex Affiliate and Web NewsRSS Feed for PC Apex Deals and Steals
Old 27-May-05, 10:58 PM   #1 (permalink)
Sir Knight of Spamalot
 
Nerdz's Avatar
 
Join Date: Nov 2003
Location: Water-hoe-Bury, CT
Posts: 6,587
Nerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorable
Send a message via AIM to Nerdz Send a message via MSN to Nerdz Send a message via Yahoo to Nerdz
Default Not cool

On The assumption my comp is infected..I curiosly hit CTRL-ALT-DELETE, Ive went though and researched some of the processes that were running..

Everything looked NOrmal..except some process I did reconize..I noticed my comp was using 100% cpu went booting...and i remeber it hasnt used that much...now lets look at what we have...


csrss.exe - Process Information

Process File: csrss or csrss.exe
Process Name: Microsoft Client/Server Runtime Server Subsystem

Description:
csrss.exe is the main executable for the Microsoft Client/Server Runtime Server Subsystem. This process manages most graphical commands in Windows. This program is important for the stable and secure running of your computer and should not be terminated. Note: csrss.exe is also process which is registered as the W32.Netsky.AB@mm worm, the W32.Webus Trojan, Win32.Ladex.a and more. This virus is distributed via the Internet through e-mail and comes in the form of an e-mail message, in the hopes that you open itÂ’s hostile attachment. The worm has itÂ’s own SMTP engine which means it gathers E-mails from your local computer and re-distributes itself. In worst cases this worm can allow attackers to access your computer, stealing passwords and personal data. It is a registered security risk and should be removed immediately. Please see additional details regarding this process




smss.exe - Process Information

Process File: smss or smss.exe
Process Name: Session Manager Subsystem

Description:
smss.exe is a process which is a part of the Microsoft Windows Operating System. It is called the Session Manager SubSystem and is responsible for handling sessions on your system. This program is important for the stable and secure running of your computer and should not be terminated. Note: smss.exe is also a process which is registered as the Win32.Ladex.a Trojan. This Trojan allows attackers to access your computer, stealing passwords and personal data. It is a registered security risk and should be removed immediately.


And there was one more I could remeber because it came up so quickly when I booted.


But Im screwed Arent I? Im using AVG for Free...=/ and oddly hasnt seen these. I cant disable them using task manager...nor using msconfig.


I think it all started when I installed Java..All I wanted to do was do an online scan..but no..I think java did something to my comp also..I deleted it.


I'll try searching for those files, go into safe mode and delete them. If Not, Back up and Format.


I wish I knew what file they came in though...


EDIT: I would also notice my comp would be using 100% CPU when I was just sitting there. Doing Nothing.

One question to, If A port is forwarded on my router is it left open all the time? OR is it only opened when requested? If So, how does the router know if its a trojan and not the program?

btw I am not using a software firewall. I am using the router as a firewall. I was told I did not need one.

__________________
I still fold
"No amount of Experimentation can Prove Me right, It only takes one to prove me Wrong"-Albert Einstein

Last edited by Nerdz; 27-May-05 at 11:46 PM.
Nerdz is offline   Reply With Quote
Sponsored Links
Old 27-May-05, 11:00 PM   #2 (permalink)
Apex Master Tech Apprentice
 
Belgianwaffles's Avatar
 
Join Date: Mar 2005
Location: Salina, Kansas
Posts: 215
Belgianwaffles is gaining favorBelgianwaffles is gaining favor
Default

sounds like it's time to reformat
__________________
Belgianwaffles is offline   Reply With Quote
Old 27-May-05, 11:05 PM   #3 (permalink)
Sir Knight of Spamalot
 
Nerdz's Avatar
 
Join Date: Nov 2003
Location: Water-hoe-Bury, CT
Posts: 6,587
Nerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorable
Send a message via AIM to Nerdz Send a message via MSN to Nerdz Send a message via Yahoo to Nerdz
Default

Also..when I started up..My comp made noises...weird ones like a tone though..a song..
__________________
I still fold
"No amount of Experimentation can Prove Me right, It only takes one to prove me Wrong"-Albert Einstein
Nerdz is offline   Reply With Quote
Old 27-May-05, 11:20 PM   #4 (permalink)
Mystical Schwinn Guru
 
j-dogg's Avatar
 
Join Date: Jul 2003
Location: West Melbourne, Fl-HOE-rida
Posts: 8,870
j-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for all
Send a message via MSN to j-dogg Send a message via Yahoo to j-dogg
Default

Hit it with some HiJack This!, had the EXACT same problem. It's a free download, look in the Essential Freeware Listing! thread.

I think the other one is Lsass.exe.
__________________
j-dogg is offline   Reply With Quote
Old 27-May-05, 11:24 PM   #5 (permalink)
Sir Knight of Spamalot
 
Nerdz's Avatar
 
Join Date: Nov 2003
Location: Water-hoe-Bury, CT
Posts: 6,587
Nerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorable
Send a message via AIM to Nerdz Send a message via MSN to Nerdz Send a message via Yahoo to Nerdz
Default

Opps yea I thought that was an I not an L
__________________
I still fold
"No amount of Experimentation can Prove Me right, It only takes one to prove me Wrong"-Albert Einstein
Nerdz is offline   Reply With Quote
Old 27-May-05, 11:33 PM   #6 (permalink)
Sir Knight of Spamalot
 
Nerdz's Avatar
 
Join Date: Nov 2003
Location: Water-hoe-Bury, CT
Posts: 6,587
Nerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorableNerdz is as respected as he/she is honorable
Send a message via AIM to Nerdz Send a message via MSN to Nerdz Send a message via Yahoo to Nerdz
Default

heres the log file..what am i looking for?
Attached Files
File Type: txt hijackthis.txt (7.0 KB, 20 views)
__________________
I still fold
"No amount of Experimentation can Prove Me right, It only takes one to prove me Wrong"-Albert Einstein
Nerdz is offline   Reply With Quote
Old 28-May-05, 12:00 AM   #7 (permalink)
Apex Tech Maniac Supreme
 
jhoop2002's Avatar
 
Join Date: Nov 2002
Location: duh, pimprig.com
Posts: 988
jhoop2002 is an unknown member
Send a message via AIM to jhoop2002
Default

Well, first off, you can never have too much security, and the fact that you got a virus is proof. I think that when you use port forwarding it is open all the time, not just when requested. I wouldn't use it, but i don't know what you need it for.

also, i don't think any home router can tell what type of activity, actual program or virus is going on, i know some commercial products from hp and cisco can with their virus throttling technology. One of the approaches i like to take towards security, is only enable what you need and leave everything else closed off.
__________________
Abit NF7-S
Athlon XP2400+
Gainward Gefore 4 Ti4600
1 Gig Corsair XMS3200
jhoop2002 is offline   Reply With Quote
Old 28-May-05, 12:05 AM   #8 (permalink)
Mystical Schwinn Guru
 
j-dogg's Avatar
 
Join Date: Jul 2003
Location: West Melbourne, Fl-HOE-rida
Posts: 8,870
j-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for allj-dogg is the ideal member and friend for all
Send a message via MSN to j-dogg Send a message via Yahoo to j-dogg
Default

Quote:
Originally Posted by jhoop2002
I wouldn't use it, but i don't know what you need it for.

Server applications, especially Counterstrike and Halflife. They use Ports 27015 and 27016.
__________________
j-dogg is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
This is so cool. Wafflesomd Anything Goes 6 10-October-06 12:12 AM
Cool or not? unit505 Case Modding 8 16-July-06 11:39 AM
FrozenCPU // Innovatek Pentium 4 Socket 775 Retaining System ( i-Cool Rev 3.0 / i-Cool Rev 4.0 / Plex-O-Matic / V6 Cooler) (501043) Gizmo Vendor News RSS 0 13-April-05 03:05 AM
cool res Rewind Extreme Cooling 9 29-July-03 10:14 AM
wow i did something cool... Fu3lman Case Modding 18 02-April-03 07:00 PM


All times are GMT -5. The time now is 07:05 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
Template-Modifications by TMS
Copyright PCApex.com, GameApex.com, ForumApex.com 2001 - 2008
Advertisements