

InterviewSolution
1. |
Solve : csrssc.exe and csrcs.exe [NOT csrss.exe]? |
Answer» Well, today I was trying to play RTC Wolfenstein ONLINE when every time I pressed any key on the keyboard the game would crash and exit me out. Anyway I tried restarting my PC but till the same thing happened so I ran Kaspersky Full Scan and Kaspersky found a bunch of Trojans (my license EXPIRED like a week ago and I was too lazy to get another one so my my computer was unprotected for like a week.) Anyway I deleted the Trojans and restarted my PC and tried to Wolfenstein again and it still does the same thing, so I was about to scan again when Kaspersky gave me alert about csrcs.exe and csrssc.exe(not csrss.exe, which is the system file so no onegets confused!) I know that those two files shouldn't be there and Kaspersky doesn't delete them but instead only restricts their operation. I need help on removing those files please.
Here is log.txt: http://www.megaupload.com/?d=CTMKZ1EY Here is info.txt: http://www.megaupload.com/?d=276JJEV2 Sorry for the download links, the files were too long to post.If you have to upload any more then please use MediaFire.com. That site has too many pop-ups and junk. Could be where you got the virus. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet EXPLORER, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log and a new HijackThis log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.Ok did what you said and ran ComboFix, performed its scan, and rebooted my PC. After that I tried play Wolfenstein and the old problem seems to be resolved. Here is the ComboFix log: log.txt Here is RSIT log: log.txt Everything seems to be good, is there anything else I should do? And thanks for the help! Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: File:: c:\windows\ekikiqaqoju.dll c:\windows\Okimuqoboxe.dll c:\windows\ST4UNST.EXE c:\windows\Setup1.exe c:\windows\ST6UNST.EXE c:\windows\ST6UNST.000 c:\windows\msdownld.tmp C:\WINDOWS\zip.exe C:\WINDOWS\VFIND.exe C:\WINDOWS\SWXCACLS.exe C:\WINDOWS\SWSC.exe C:\WINDOWS\SWREG.exe C:\WINDOWS\sed.exe C:\WINDOWS\NIRCMD.exe C:\WINDOWS\grep.exe C:\WINDOWS\fdsv.exe Folder:: C:\khq Registry:: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Nxirodowurafox"=- "Ebubitigokid"=- 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeOk did what you said here is the second log file: log.txt
Download Alternate download link Note: Vista users must use Run As Administrator
---------- Download OTCleanIt.exe and save it to your Desktop.
Important: Restart the computer before continuing. ---------- Scan with Panda ActiveScan This scanner requires Internet Explorer
I ran into this ARTICLE, hope it will help: <Removed> |
|