help me please URGENT!!! BIG PROBLEM NEED HELP A.S.A.P.

  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Joined: May 29, 2007
  • Posts: 481
  • Status: Offline

Post May 21st, 2008, 2:35 am

You already posted this output. Could you try the other command that I had given above?

You do seem to have a lot of processes running. Whenever you're dealing with a problem, it's best to close all other programs, for example, in your case, Yahoo Messenger and Winamp Agent.

Also, you seem to have a lot of svchost processes running - that may be a bad sign, since many viruses use that name.
No Strings Attached: A JavaScript graphics demo.
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post May 21st, 2008, 2:35 am

  • franciskenz
  • Beginner
  • Beginner
  • No Avatar
  • Joined: May 21, 2008
  • Posts: 40
  • Status: Offline

Post May 21st, 2008, 2:45 am

so far there are still no threast but somthing was changed
file======Result/Infection====Path
shell32======change===========C:/Windows/system32/shell32.dll
ntoskrnl=====change===========C:/Windows/system32/ntoskrnl.exe
is that godd???

righteous_trespasser wrote:
you won't know until you've scanned it ... so? ... what are you waiting for? press that "scan now" button ...
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Joined: May 29, 2007
  • Posts: 481
  • Status: Offline

Post May 21st, 2008, 2:48 am

A change to those two files doesn't sound good - one is the OS kernel and the other deals with most of the stuff on your desktop - I think you should post a HJT log - see this post
No Strings Attached: A JavaScript graphics demo.
  • franciskenz
  • Beginner
  • Beginner
  • No Avatar
  • Joined: May 21, 2008
  • Posts: 40
  • Status: Offline

Post May 21st, 2008, 2:48 am

this is the second command and i already closed yahoo and winamp

C:\Windows\system32>reg query "hklm\software\microsoft\windows nt\currentversion
\winlogon"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe C:\WINDOWS\Config\csrss.exe
Userinit REG_SZ C:\Windows\system32\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
AutoRestartShell REG_DWORD 0x1
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ShutdownWithoutLogon REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0x0
passwordexpirywarning REG_DWORD 0xe
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
WinStationsDisabled REG_SZ 0
DisableCAD REG_DWORD 0x1
scremoveoption REG_SZ 0
ShutdownFlags REG_DWORD 0x80000027
AutoLogonCount REG_DWORD 0x1

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\GPExten
sions
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Notify
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\AutoLog
onChecked

C:\Windows\system32>
  • franciskenz
  • Beginner
  • Beginner
  • No Avatar
  • Joined: May 21, 2008
  • Posts: 40
  • Status: Offline

Post May 21st, 2008, 2:50 am

so what must I do to it??

casablanca wrote:
A change to those two files doesn't sound good - one is the OS kernel and the other deals with most of the stuff on your desktop - I think you should post a HJT log - see this post
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Joined: May 29, 2007
  • Posts: 481
  • Status: Offline

Post May 21st, 2008, 2:51 am

That explains it - you do have a virus. The "Shell" value is supposed to be Explorer.exe but it's Config\csrss.exe. Download this utility and run it. Then, open task manager and kill csrss.exe - there might be two of them, one belongs to Windows and the other is the virus.
No Strings Attached: A JavaScript graphics demo.
  • franciskenz
  • Beginner
  • Beginner
  • No Avatar
  • Joined: May 21, 2008
  • Posts: 40
  • Status: Offline

Post May 21st, 2008, 2:54 am

how to kill them??

casablanca wrote:
That explains it - you do have a virus. The "Shell" value is supposed to be Explorer.exe but it's Config\csrss.exe. Download this utility and run it. Then, open task manager and kill csrss.exe - there might be two of them, one belongs to Windows and the other is the virus.
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Joined: May 29, 2007
  • Posts: 481
  • Status: Offline

Post May 21st, 2008, 2:55 am

Go to the Processes tab in Task Manager, find csrss.exe and click End Process.
No Strings Attached: A JavaScript graphics demo.
  • franciskenz
  • Beginner
  • Beginner
  • No Avatar
  • Joined: May 21, 2008
  • Posts: 40
  • Status: Offline

Post May 21st, 2008, 2:57 am

its says access denied
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Joined: May 29, 2007
  • Posts: 481
  • Status: Offline

Post May 21st, 2008, 2:58 am

That one belongs to Windows. Is there only one csrss.exe? Try killing all of them.
No Strings Attached: A JavaScript graphics demo.
  • franciskenz
  • Beginner
  • Beginner
  • No Avatar
  • Joined: May 21, 2008
  • Posts: 40
  • Status: Offline

Post May 21st, 2008, 2:58 am

you said theres two i think its winlogon.exe i think its the 2nd virus
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Joined: May 29, 2007
  • Posts: 481
  • Status: Offline

Post May 21st, 2008, 3:00 am

That's also part of Windows, unless there's more than one winlogon too.
Many viruses use the names of existing Windows programs such as csrss, lsass, userinit, winlogon, svchost.
No Strings Attached: A JavaScript graphics demo.
  • franciskenz
  • Beginner
  • Beginner
  • No Avatar
  • Joined: May 21, 2008
  • Posts: 40
  • Status: Offline

Post May 21st, 2008, 3:11 am

i tried to click "Show proccesses from all user then there are two of or crss.exe,one winlogon,one lsass and almost 15 svchost i tried to end one of th crss then the pc shut down and restrat
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Joined: May 29, 2007
  • Posts: 481
  • Status: Offline

Post May 21st, 2008, 3:13 am

Well, did you run the utility I posted? Since you mentioned your computer restarted anyway, did the desktop come back?
No Strings Attached: A JavaScript graphics demo.
  • franciskenz
  • Beginner
  • Beginner
  • No Avatar
  • Joined: May 21, 2008
  • Posts: 40
  • Status: Offline

Post May 21st, 2008, 3:14 am

no the deskytop did not appear
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post May 21st, 2008, 3:14 am

Post Information

  • Total Posts in this topic: 62 posts
  • Users browsing this forum: No registered users and 130 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
cron
 

© 2011 Unmelted, LLC. Ozzu® is a registered trademark of Unmelted, LLC.