|
-
January 4th, 2004, 08:09 PM
#21
seems to me that you probably have a few different ones.. there are processes there that I've never heard of.. just googling each one could tell you more. For example, I picked "SMSS.exe" , googled it and found this link.. http://www.viruslist.com/eng/viruslist.html?id=51071.. which shows that you have Worm.Win32.Ladex.. as you'll see by that link, the CRSS.exe is also part of that worm. read that link please because there's good info in there.. I'll just quote the last part..
Invisibility
Using the additional components SMSS.EXE and CSRSS.EXE the worm tries to mask (hide)itself in the system. Both files ensure the functioning of the main module LMHSVC.EXE if for any reason it appears unloaded from memory. Besides these components it looks for REGEDIT - if REGEDIT is open it temporarily removes the keys in the system registry and restores them upon the closure of the REGEDIT application. Thus the worm achieves invisibility in the system registry.
Payload
The worm starts the joke program LADY.EXE which displays a set of creeping flies which can be "killed" with the mouse cursor.
as for hijacking, since no one has mentioned it yet.. try hijackthis, but be careful of what you delete. posting a log of it either at tomcoyote's forum or here would be advisable.
hijackthis : http://www.tomcoyote.org/hjt/
log tutorial : http://www.spywareinfo.com/~merijn/htlogtutorial.html
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|