Virus help?
27 Apr 2004 01:29 pmWe are stuck here at work with an exe that sucks processing time, shuts down the internet connection and slows down everything.
They identified the culprit as a file called "csrsss.exe" (note three s) that sits in the Winnt/system32 folder and runs a process with the same name.
It's a nasty thing that probably sits somewhere in the network and is resurrected every time it's deleted from the folder and the registry.
Anyone familiar with it and able to suggest a remedy? Sophos doesn't recognize it (yet).
They identified the culprit as a file called "csrsss.exe" (note three s) that sits in the Winnt/system32 folder and runs a process with the same name.
It's a nasty thing that probably sits somewhere in the network and is resurrected every time it's deleted from the folder and the registry.
Anyone familiar with it and able to suggest a remedy? Sophos doesn't recognize it (yet).
no subject
Date: 27/4/04 12:55 pm (UTC)Try running lavasoft's ad-aware first, that deals with some of this stuff but isn't quite so drastic. If that doesn't work try
http://www.spywareinfo.com/~merijn/files/cwshredder.zip
which gets rid of the particular program I had trouble with and some of its variants.
no subject
Date: 27/4/04 07:30 pm (UTC)This thing seems to be very new and no virus checker or adware/spyware checker was able to find it. We searched all over in various forums and websites. A google search came up with three hits, all from people posting about problems with it.
Way OT
Date: 27/4/04 03:43 pm (UTC)Re: Way OT
Date: 27/4/04 04:39 pm (UTC)I was thinking of asking Robin if he wants to come along, otherwise nobody.
It's at the Carling Academy Islington.
http://www.clubharddrive.co.uk for more info.
Re: Way OT
Date: 27/4/04 05:32 pm (UTC)I'll pimp it on my LJ.
Re: Way OT
Date: 27/4/04 06:26 pm (UTC)And if there's four of us, a taxi won't break the bank, either.
I will definitely come to Evil first to drop my bag of night. Work permitting, I'm going to take the 19:45 train, so I should be at Evil around 9?
no subject
Date: 27/4/04 07:11 pm (UTC)Csrss stands for client/server run-time subsystem and is an essential subsystem that must be running at all times.
Csrss is responsible for console windows, creating and/or deleting threads, and some parts of the 16-bit virtual MS-DOS environment.
However it has been targeted for modification by some viruses and spyware as I understand such.
no subject
Date: 27/4/04 07:22 pm (UTC)I finally managed to get of rid after it reappearing time and again but it most likely still lurks on the network somewhere. Let's hope the sysop gets it fixed. I basically lost half a day's work, while being on a tight deadline...
no subject
Date: 28/4/04 12:20 am (UTC)Was hoping it had been a miscommunication of some sort. Cause otherwise boggled.
Good luck with eradicating the bastard from the network. We still have a few things like that on our work network theyhaven't been able to get rid of in 2 years.
no subject
Date: 28/4/04 01:05 pm (UTC)Thanks for trying to help, anyway.