Csrss.exe virus problem

Miguel - Jun 23, 2011 at 11:26 AM
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 - Nov 9, 2012 at 03:41 PM

I got a serious problem with a virus I got, seems that it is infecting the csrss.exe file of my OS (windows 7 64bit). My antivirus MSE (Microsoft security essentials) gets to block the program and also the Malwarebytes does blocks it, but the thing is that they never get to find the infected file and delete it 'cause the treat disappears. I got only 3 csrss.exe files on my pc, on system32, system64 and a folder named AMD which I checked and is legitimate. I have run the scaner on safe mode, without being connected to the internet, I tried the Regedit thing and the values are ok, I tried the CCleaner, I have tried everything and I still have the virus on my pc, and I have had to restore the pc to a previous date 3 times already cause although the virus is being blocked it is damaging my system somehow. BTW the task manager only have 1 csrss.exe running. I'll appreciate a LOT any response, thanks ahead.

8 responses

Has this been resolved I have the same exact problem to the "T".
Anonymous User
Oct 16, 2011 at 09:31 PM
Need more details,possibly you can create a new thread so that we could help you
Its the same exact problem. The only slight difference is that I get BSOD on boot of regular win 7 boot and safe mode. The exception is 0x0000135 mossing %hs file.
juju666 Posts 35446 Registration date Wednesday December 17, 2008 Status Security contributor Last seen April 21, 2024
Oct 17, 2011 at 03:48 AM

Please open your topik for more help ;)

a registry change will allow you to boot. boot from a pe disc (I used Hiren's as it has a good pe registry editor), run a reg editor that can load the offline hives from your windows directory, navigate to HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\SubSystems and change the value of the "Windows" entry. You will see a reference to consrv.dll, change that to winsrv. It will look like this after the fix: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

ServerDLL=winsrv is more than likeley says ServerDLL=consrv at the moment...some references say that the same thing may need to be done in ControlSet002 also.
Bowzer, you are the man!

been searching for that key for over a day now

thanks a million