« Recovered Photos from Hawaii - Day 10 (April 3rd) | Main | The Pride of Madeira »

April 11, 2011

Trojan Horse BackDoor.Generic 13

Wow. I think I finally turned the corner on a nasty computer virus. I hard a hard time getting on top of this one. Don't know where it came from. AVG saw it, but couldn't get rid of it. Malwarebytes Anti-Malware could always see it, but couldn't get rid of it.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Data: c:\docume~1\rob\locals~1\temp\csrss.exe -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\Rob\Local Settings\Temp\csrss.exe (Trojan.Agent) -> Delete on reboot.

The trick was that there was a file named "C:\Documents and Settings\Rob\Local Settings\Temp\csrss.exe" that I couldn't delete. This was the Trojan Horse, and he was getting loaded into memory at startup by the Registry Key "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Data: c:\docume~1\rob\locals~1\temp\csrss.exe".

Finally, I had to reboot in Safe Mode. Once I was in Safe Mode, I could unload the process csrss.exe using Task Killer. Once the process was unloaded, I deleted the file and rebooted. It came up saying it couldn't find the file csrss.exe, so I scanned the registry and deleted the references to this file "c:\docume~1\rob\locals~1\temp\csrss.exe". This one is kinda tricky though, because there is a valid csrss.exe in the registry, but it's located in the system32 folder. So, don't delete that one, of course. Hahaha. Wow. That was a close one.

Update: I never could get on top of this one. I ended up having to reinstall the O/S.

Technorati tags:
Delicious tags:

Folksonomy:These icons link to social bookmarking sites where readers can share web pages.
 
digg  Furl  Spurl  Reddit  blinkbits  BlinkList  blogmarks  connotea  De.lirio.us  Fark  feedmelinks  LinkaGoGo  Ma.gnolia  NewsVine  Netvouz  RawSugar  scuttle  Shadows  Simpy  Smarking  TailRank  Wists  YahooMyWeb

Posted by Rob Kiser on April 11, 2011 at 5:09 AM

Trackback Pings

TrackBack URL for this entry:>
http://www.peeniewallie.com/mt/mt-tb.cgi/3699

Comments

Post a comment




Remember Me?

(you may use HTML tags for style)


NOTICE: IT WILL TAKE APPROX 1-2 MINS FOR YOUR COMMENT TO POST SUCCESSFULLY. YOU WILL HAVE TO REFRESH YOUR BROWSER. PLEASE DO NOT DOUBLE POST COMMENTS OR I WILL KILL YOU.
-->