| Answer» Computer : ZOOMSTORMPRO Intel (R) Celeron (R) CPU 430 1.80 GHZ
 1.00 GB
 System Type : 32 BIT operating system
 WINDOWS VISTA
 
 HI i have had this computer now for about 2 months i have AVG and Avira Anitvir personal. I have just downloaded spyware doctor but for same reason none of the anti virus sofeware find this VIRUS. The way i found out was looking at my task manager and saw cssrss.exe so looked this up on Google and it SAID it was very harmful to the computer and it has winlogon.exe normally with which i have found.
 
 I have try scanning the computer with everything but no joy. You have helped me out before with my sister computer had spme bad virus on it SO ONLY ONE PLACE I TRUST IN THIS MATTER IS HERE. Cos everything you have told me has worked
 
 SO PLEASE CAN YPU HELP ME OUT AGAIN BEFORE THIS VIRUS TAKES OVER MY COMPUTER
 
 THANK YOU SO MUCH
 
 JENZO
 
 Malwarebytes' Anti-Malware 1.19
 Database VERSION: 899
 Windows 6.0.6001 Service Pack 1
 
 22:21:15 28/06/2008
 mbam-log-6-28-2008 (22-21-15).txt
 
 Scan type: Quick Scan
 Objects scanned: 34526
 Time elapsed: 7 minute(s), 51 second(s)
 
 Memory Processes Infected: 0
 Memory Modules Infected: 0
 Registry Keys Infected: 0
 Registry Values Infected: 0
 Registry Data Items Infected: 0
 Folders Infected: 0
 Files Infected: 0
 
 Memory Processes Infected:
 (No malicious items detected)
 
 Memory Modules Infected:
 (No malicious items detected)
 
 Registry Keys Infected:
 (No malicious items detected)
 
 Registry Values Infected:
 (No malicious items detected)
 
 Registry Data Items Infected:
 (No malicious items detected)
 
 Folders Infected:
 (No malicious items detected)
 
 Files Infected:
 (No malicious items detected)
 HERE IS A SYSTEM LOG
 
 Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 11:20:53, on 28/06/2008
 Platform: Windows Vista SP1 (WinNT 6.00.1905)
 MSIE: Internet Explorer v7.00 (7.00.6001.18000)
 Boot mode: Normal
 
 Running processes:
 C:\Windows\System32\smss.exe
 C:\Windows\system32\csrss.exe
 C:\Windows\system32\wininit.exe
 C:\Windows\system32\csrss.exe
 C:\Windows\system32\winlogon.exe
 C:\Windows\system32\services.exe
 C:\Windows\system32\lsass.exe
 C:\Windows\system32\lsm.exe
 C:\Windows\system32\svchost.exe
 C:\Windows\system32\svchost.exe
 C:\Windows\System32\svchost.exe
 C:\Windows\System32\svchost.exe
 C:\Windows\System32\svchost.exe
 C:\Windows\system32\svchost.exe
 C:\Windows\system32\SLsvc.exe
 C:\Windows\system32\svchost.exe
 C:\Windows\system32\svchost.exe
 C:\Windows\System32\spoolsv.exe
 C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
 C:\Windows\system32\svchost.exe
 C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
 C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
 C:\Program Files\MICROSOFT Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 C:\Windows\system32\IoctlSvc.exe
 C:\Windows\system32\svchost.exe
 c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
 C:\Windows\system32\taskeng.exe
 c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
 C:\Windows\system32\svchost.exe
 C:\Windows\System32\svchost.exe
 C:\Windows\system32\SearchIndexer.exe
 C:\Windows\system32\Dwm.exe
 C:\Windows\Explorer.EXE
 C:\Windows\system32\taskeng.exe
 C:\PROGRA~1\AVG\AVG8\avgrsx.exe
 C:\Program Files\Windows Defender\MSASCui.exe
 C:\Windows\RtHDVCpl.exe
 C:\Windows\System32\hkcmd.exe
 C:\Windows\System32\igfxpers.exe
 C:\Program Files\AVG\AVG8\avgtray.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
 C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
 C:\Program Files\Windows Sidebar\sidebar.exe
 C:\Users\JENZO\Program Files\DNA\btdna.exe
 C:\Program Files\Windows Media Player\wmpnscfg.exe
 C:\Program Files\Windows Media Player\wmpnetwk.exe
 C:\Program Files\BBC Alerts\BBC_Alerts.exe
 C:\Windows\system32\igfxsrvc.exe
 C:\Program Files\Spyware Doctor\pctsAuxs.exe
 C:\Program Files\Spyware Doctor\pctsSvc.exe
 C:\Program Files\Spyware Doctor\pctsTray.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 C:\Windows\system32\wbem\wmiprvse.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
 O1 - Hosts: ::1 localhost
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
 O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
 O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
 O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
 O4 - HKLM\..\Run: [Skytel] Skytel.exe
 O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
 O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
 O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
 O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
 O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
 O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\JENZO\Program Files\DNA\btdna.exe"
 O4 - HKCU\..\Run: [BBC Alerts] "C:\Program Files\BBC Alerts\BBC_Alerts.exe"
 O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
 O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
 O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
 O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
 O13 - Gopher Prefix:
 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
 O20 - AppInit_DLLs: avgrsstx.dll
 O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
 O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
 O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
 O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
 O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
 O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
 
 --
 End of file - 7661 bytes
 The log is clean.
 I can see csrss.exe running, not cssrss.exe
 csrss.exe is legit Windows file.but when i run my task mananger is has cssrss.exs & winlogon.exe running.When i try 2 stop then i just doubles up so two are running then
 
 BUT i take your word for it everything is ok this site as alway sorted out my other viruses
 
 THANK YOU SO MUCH
 
 JENZO
 winlogon.exe is also legit Windows file, unless it's not located in C:\Windows\System32.
 Search your computer for it, and see where it's located.
 Can you post a screenshot, showing Task Manager with cssrss.exe running? There is only one "s" DIFFERENCE between legit, and bad file.
 |