Virus trouble (VERY weird stalker virus)

Status
Not open for further replies.

mightyboosh

Broken In
Hello,

i'm just writing this quick thread to see if anyone here knows about this problem and if they can suggest ways to cure my computer. My computer was very badly screwed for long because of some unrecognisable reason; i did scan it with AVG free but it didn't detect anything and i was convinced that my computer doesnot have a virus and it's just some hardware trouble that's causing the problem.

However, i was just double checking using pcpitstop.com to see if it could detect any more problems and i discovered that my computer had a virus (called csrss.exe) and i think there's a system file named that. i knew the location of the file (it was in a hidden 'application data' folder) but i couldn't open folder options for some reason. Then i searched for the folder and tried deleting the file but it just reappeared when i clicked on 'refresh' and when i checked in the tasks (ctrl + alt + delete) i couldn't end process (it sais it was an important system process and cannot be ended)

This is the weirdest part, whenever i google search the virus name, no matter what browser it is, it shuts down and shortly after that my system reboots. I haven't a clue what to do to get rid of it now. Please help!
Should i just reformat my drive because i kept updating my AVG and this thing was right under it's nose..

If possible could you google search the name and forward me the links or the applications which i can use to get rid of this.

Thanks for reading,
- MCW
 

Kiran.dks

Technomancer
Your system is infected with W32/Brontok worm. It spreads through mails. When infected it copies itself to <User>\Local Settings\Application Data\csrss.exe

There exists csrss.exe, which is a critical Windows process. It runs in C:\Windows\System32 and not Application Data.

:arrow: Download:BitDefender Removal tool

Start windows in safe mode and scan entire system.
 
Last edited:

anandk

Distinguished Member
Sample infectors that use the name CSRSS.EXE are...

C:\CSRSS.EXE
W32/Buchon.c@MM -- *vil.nai.com/vil/content/v_130857.htm

%WinDir%\MSAGENT\WIN32\CSRSS.EXE
W32/Sober.l@MM -- *vil.nai.com/vil/content/v_131869.htm

%WinDir%\CSRSS.EXE
W32/Melare@MM -- *vil.nai.com/vil/content/v_100306.htm

%WinDir%\CSRSS.EXE
W32/Netsky.ab@MM -- *vil.nai.com/vil/content/v_124873.htm

%WinDir%\CSRSS.EXE
MultiDropper-JW -- *vil.nai.com/vil/content/v_101115.htm

%WinDir%\CSRSS.EXE
Downloader-MC -- *vil.nai.com/vil/content/v_126644.htm

fruitful discussion here at CSRSS.EXE Virus That Won't Go Away
 
Status
Not open for further replies.
Top Bottom