3 Users Commented In This Post

Subscribe To This Post Comment Rss Or TrackBack URL
mygif
Deyaa Addeen Fahmy Shedeed says, October 15th, 2009   

Welldone, thanks.

mygif
Deyaa Addeen Fahmy Shedeed says, October 15th, 2009   

If a process named csrss.exe is running on your computer, you may have been infected with a strain of the Ahlem.A worm.

csrss.exe is considered to be a security risk, not only because antivirus programs flag Ahlem.A Worm as a virus, but also because a number of users have complained about its performance.

Ahlem.A Worm is likely a virus and as such, presents a serious vulnerability which should be fixed immediately! Delaying the removal of csrss.exe may cause serious harm to your system and will likely cause a number of problems, such as slow performance, loss of data or leaking private information to websites.

From another site.

mygif
Deyaa Addeen Fahmy Shedeed says, October 15th, 2009   

Virus Removal Areses (windows\csrss.exe) Trojan.
Also Areses is known as Win32.HLLM.Perf, W32/Bagle-GT, W32/ARESES.AB@mm – 06-10-04.

Areses is not hard in detection. It uses the same name as the Windows system process “csrss.exe” located in the System32 folder.

But the Areses can make the removal process hard for common user.

If a user simply deletes the file he will see the message that the Windows system file has been deleted and he will be asked for the Windows CD-ROM to restore deleted file.

If a user is smart and he will ignore the Trojan restore process, he will see the blue screen after reboot. Windows explorer could not start.

Why?

Areses uses the following registry key to be started at Windows boot:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\

It creates sub-key explorer.exe and the value under it:

Debugger=c:\windows\csrss.exe

This will allows the Trojan to be started every time when the explorer.exe will be launched.

This possibility is used by debuggers but it’s ideal for viruses too.

The Trojan can use any process name for activation not only explorer.exe. It can add the value notepad.exe and be started with executing Notepad.

The Image File Execution Options must be under control!

If you see the clear screen without explorer, press CTRL+ALT+DEL to start Task Manager, open regedit.exe, delete the registry key. After that open “explorer.exe”.

RegRun with Partizan technology allows you to remove this virus easily with disturbance.

How Partizan works?

Partizan system driver intercepts the registry key open function and it not allows to open Image File Execution Options, Winlogon Notifications keys.

When the “Scan for Viruses” is started it will turn off the protection and Reanimator can delete the registry key without any problems.

ARESES spreads via e-mail with attached crypted “hta” file.

from another site.

Any one pro can axplain.

Leave Your Comments Below
Hello, please leave your thought below

Please Note: Comments may need to approved by admin. so there's no need to resubmit your comments.