Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the Virus/Trojan/Spyware Help forum, or the "First Steps" link at the top right of each page.

Reply
 
LinkBack Thread Tools
Old 05-25-2008, 10:22 AM   #1 (permalink)
Registered User
 
Join Date: May 2008
Posts: 27
OS: xp


cssrss creating HQS Trojan at startup

I have been getting Trojan warning for over a week everytime I run NOD on-demand scan, and I delete the trojan file everytime (they are in the system32 folder), but they keep coming back.

Finally tonight when I turned on the computer NOD pop up saying that an HQS trojan was created by the cssrss process in windows/system32/

I looked through there and saw csrss and cssrss processes, and I believe csrss is a legitimate MS process.

My question is : can I go in and delete cssrss ? Is it a legitimate MS process infected?
calvin333 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 05-25-2008, 10:36 AM   #2 (permalink)
T-Shirt Winner
 
grumpygit's Avatar
 
Join Date: Oct 2006
Location: hertford, england
Posts: 4,746
OS: win xp pro sp3

My System

Blog Entries: 2
Send a message via MSN to grumpygit
Re: cssrss creating HQS Trojan at startup

Hi and welcome to TSF.
cssrss.exe is not a legit process. It is loaded by the W32/FORBOT-CE worm.
http://www.castlecops.com/s6114-cssrss_exe.html

I recommend you follow the instructions in the link below and post your logs in the hijack this section. An analyst will check your logs and advise you on cleaning your machine.

http://www.techsupportforum.com/secu...oval-help.html
__________________
Grumpygit
grumpygit is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-25-2008, 08:32 PM   #3 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,735
OS: 2000 Pro; XP Pro; XP Home


Re: cssrss creating HQS Trojan at startup

csrss.exe in system32 and system32\dllcache is a legit process. It should be 6,144 bytes on most XP machines.

cssrss.exe is not legit, as grumpygit has pointed out.

There's quite possibly something else on the system alongside...but in addition to deleting the file, you need to remove the loading point(s).

If you require assistance, follow the instructs in the link grumpygit has already provided.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 06-11-2008, 03:25 AM   #4 (permalink)
Registered User
 
Join Date: May 2008
Posts: 27
OS: xp


Re: cssrss creating HQS Trojan at startup

First of all thank you for your replies.
I've been trying to do as instructed and scan with Panda ActiveScan but
IE and Firefox keep getting aborted when I'm about 30% complete (going from C to D drive)
and when the browser process was aborted then all data is lost.

So far after C drive scan I get about 7 infected files (mostly from RP3x files) but not getting scan complete is really frustrating. Is it because I don't have enough RAM (I have 512 MB)?

How do I remedy this situation and at least get scan completion?
calvin333 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 06-11-2008, 04:59 AM   #5 (permalink)
Registered User
 
Join Date: May 2008
Posts: 27
OS: xp


Re: cssrss creating HQS Trojan at startup

Finally got Active Scan to run to completion.
I also use the Disinfect function to disinfect several trojan downloader in RP32... etc.
I am doing the DSS scan now and will post all logs in the Hijack this forum.

Thanks again.
calvin333 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 05:42 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85