Email Us | Advertising

Login / Register

User Name
Password

Advertisers


Hong Kong > Forums  > Hong Kong Forums  > Living in Hong Kong  > Technology & Gadgets

Strange Virus / Trojan problem

Reply
 
LinkBack Tools Search Rate Thread
 
Old 02-10-2006, 01:49 AM
Registered User
 
Join Date: Sep 2005
Location: Lantau
Posts: 759
HKNewBi has a little shameless behaviour in the past
Strange Virus / Trojan problem

Guys,

Hope you can help. Got my first virus / trojan on my PC. I have cleared loads of these up from friends / relatives PC's over the years, but first time I get one on my machine, I can't seem to figure out what it is.

My virus checker finds it, doesn't give any info as to the name except Trojan Horse Dropper.Agent.BVY and can't seem to deal with it.

It lives in the c:\documents & settings\username\Local Settings\Temp\RarSFX0 folder and will increment the folder name (ie RarSFX1 onwards)

The virus checker quarantines a file called tshz093.exe and there is another file csrss.exe in that folder. CSRSS.exe is running twice as two separate processes and they can't be stopped.

Booting up to safe mode and removing those folders doesn't seem to do it.

A search of the registry for those files hasn't helped (1 entry found an removed). Nothing in the Run or Runonce keys in the registry.

There is also an odd process running in task manager - 927up.exe

Checked google, symantec etc for a few of these keywords but don't get anything back.

It also pops up some odd winrar box from time to time.

Anyone know what this is and how to get rid?

Thanks
Reply With Quote
 
Old 02-10-2006, 10:23 AM
KnowItAll's Avatar
Resident Peacekeeper
 
Join Date: Apr 2003
Location: Pokfulam
Age: 40
Posts: 10,761
Blog Entries: 11
KnowItAll has a reputation beyond reputeKnowItAll has a reputation beyond reputeKnowItAll has a reputation beyond reputeKnowItAll has a reputation beyond reputeKnowItAll has a reputation beyond reputeKnowItAll has a reputation beyond reputeKnowItAll has a reputation beyond reputeKnowItAll has a reputation beyond reputeKnowItAll has a reputation beyond reputeKnowItAll has a reputation beyond reputeKnowItAll has a reputation beyond repute
HKNewBi : chances are its written over a system file (crss) so you cant delete it . i'd recommend doing a SFC scan ..

sfc /scannow

You will need the windows CD to replace the corrupted / infected file.
Reply With Quote
 
Old 03-10-2006, 04:16 AM
Registered User
 
Join Date: Sep 2005
Location: Lantau
Posts: 759
HKNewBi has a little shameless behaviour in the past
Thanks KIA

The machine became very unstable - it would reboot if putting a new URL into Firefox for example, so I thought I would just format and reinstall.

The installation bluescreened twice!!!

Finally managed to get windows installed but nothing is working properly.

Back to the drawing board
Reply With Quote
 
Old 04-10-2006, 05:20 AM
Registered User
 
Join Date: Oct 2006
Posts: 1
TEST_64 is on a distinguished road
Hi HKNewBi,
I just have the problem then you and found this usefull info:
http://research.sunbelt-software.com...&threatid=3678
Hope that helps.
Reply With Quote
 
Old 04-10-2006, 02:52 PM
Registered User
 
Join Date: Sep 2005
Location: Lantau
Posts: 759
HKNewBi has a little shameless behaviour in the past
Thanks Test but I have since formatted the whole system and reinstalled. Problem gone... for now!
Reply With Quote
 
Old 16-10-2006, 02:21 AM
Registered User
 
Join Date: Oct 2006
Posts: 4
Skindog is on a distinguished road
Quote:
Originally Posted by HKNewBi View Post
Guys,

Hope you can help. Got my first virus / trojan on my PC. I have cleared loads of these up from friends / relatives PC's over the years, but first time I get one on my machine, I can't seem to figure out what it is.

My virus checker finds it, doesn't give any info as to the name except Trojan Horse Dropper.Agent.BVY and can't seem to deal with it.

It lives in the c:\documents & settings\username\Local Settings\Temp\RarSFX0 folder and will increment the folder name (ie RarSFX1 onwards)

The virus checker quarantines a file called tshz093.exe and there is another file csrss.exe in that folder. CSRSS.exe is running twice as two separate processes and they can't be stopped.

Booting up to safe mode and removing those folders doesn't seem to do it.

A search of the registry for those files hasn't helped (1 entry found an removed). Nothing in the Run or Runonce keys in the registry.

There is also an odd process running in task manager - 927up.exe

Checked google, symantec etc for a few of these keywords but don't get anything back.

It also pops up some odd winrar box from time to time.

Anyone know what this is and how to get rid?

Thanks
I have exact same problem and its doing my head in. Run a couple of spyware programs but nothing comes up..

Ran CCleaner and deleted all temp files, as this is where it's hiding. Killed the csrss (under username, not system) with Hijack this. Removed registry entries pointing towards the 927up file. Also kill and delete the file with Killbox.

When restart and browse the internet it keeps popping back.

The 927up.exe installs itself into C:\program files and the the other csrss process comes up in task manager..

Please help get rid of this file..
Reply With Quote
 
Old 16-10-2006, 03:24 PM
Registered User
 
Join Date: Sep 2005
Location: Lantau
Posts: 759
HKNewBi has a little shameless behaviour in the past
Have you tried any of that in safe mode?

I ended up reinstalling windows which solved the problem for me.
Reply With Quote
 
Old 17-10-2006, 12:32 AM
Registered User
 
Join Date: Oct 2006
Posts: 4
Skindog is on a distinguished road
Yes mate, tried pretty much everything. Don't wanna go the format route, too much stuff that I need and don't wanna spend a week reinstalling everything..

Can't believe that there is no information on the net about this..

I use Firefox, but the culprit brings up IE and tries to connect to 123sha.com

Last edited by Skindog : 17-10-2006 at 12:35 AM.
Reply With Quote
 
Old 17-10-2006, 04:50 AM
Registered User
 
Join Date: Oct 2006
Posts: 4
Skindog is on a distinguished road
Just tried deleted everything in Safe Mode again, didn't do the reg entries last time, but did it this time and all seems fine...
Reply With Quote
 
Old 17-10-2006, 01:32 PM
Registered User
 
Join Date: Nov 2005
Posts: 390
Expatriate has pissed of a few people
You got a firewall, anti-virus, spy-remover?
Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan alert from a trading company website rolling smith Technology & Gadgets 2 25-10-2007 07:55 PM
USC Trojan Football Games ipyw Everything Else 0 03-09-2007 08:12 PM
Very strange MSN problem HKNewBi Technology & Gadgets 8 23-11-2006 09:45 PM
Strange windows problem! HKNewBi Technology & Gadgets 20 01-10-2006 05:24 PM
avg scan pick up bittorrent.exe as Trojan Horse seamale Technology & Gadgets 5 16-06-2006 11:21 AM


Tools Search
Search:

Advanced Search
Rate This Thread
Rate This Thread:



All times are GMT +8. The time now is 07:17 PM.


Quick Nav

Partners

Small Business Ads

Advertise Here

Content Relevant URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.