Shoutbox

msconfig - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Tech Talk (/forumdisplay.php?fid=17)
+----- Thread: msconfig (/showthread.php?tid=53387)

msconfig by TylerG on 11-27-2005 at 06:27 PM

Ok so here's the deal.  Whenever I try to run msconfig it opens for like 2 seconds and then closes itself.  I can't get anything done.  I have tried restarting, and it has been a problem for like a month now.  Has anyone had this problem and/or knows how to fix it?  Any help will be much appreciated.


RE: msconfig by Stigmata on 11-27-2005 at 06:29 PM

youve got a virus running..

use task manager to close any programs you dont reconise, then try

my theory is that it checks for the window to be shown, then closes it. this is because as a measure to prevent it from being stopped, its not allowing you to remove it from startup.


RE: msconfig by TylerG on 11-27-2005 at 06:34 PM

I have tried, all the ones that I ended that look suspicious didn't help.  Any idea what it might be called?  Plus I have tried scanning with symantic, xoftspy, and ad-aware, and symantic is the only one that detects it, but it can't delete it:(


RE: msconfig by lizard.boy on 11-27-2005 at 06:42 PM

try running the program "autoruns" from sysinternals, disable the startup item for the process you think it is, and then reboot. then run your antivirus or boot into safemode and delete the file manually.


RE: msconfig by TylerG on 11-27-2005 at 06:48 PM

I think I found it, but when I try to end it, it says "This is a critical system process.  Task Manager cannot end this process.":S  But it might just be a regular process, but I don't think I have seen it before.


RE: msconfig by Snake on 11-27-2005 at 06:53 PM

I have had this problem before, can you open control panel?  If you can't then the computer does have a virus on and you have to reformat and start over again.

I have never figured away how to get rid of this virus.


RE: msconfig by Stigmata on 11-27-2005 at 06:57 PM

there is always turn on in safemode then disable it from startup


RE: msconfig by TylerG on 11-27-2005 at 07:24 PM

Ok, so I booted in safemode right, took it off startup, rebooted and it lets me open msconfig now, but the virus is still running in taskmanager:S Scanning with Symantec as we speak.


RE: msconfig by ShawnZ on 11-27-2005 at 07:42 PM

What do you think it is...?


RE: msconfig by TylerG on 11-27-2005 at 07:43 PM

csrss.exe


RE: msconfig by Menthix on 11-27-2005 at 07:51 PM

csrss.exe is a normal process too. See csrss.exe process information. Don't try to delete it before you are sure it really is a virus, you may damage Windows otherwise :).


RE: msconfig by MeEtc on 11-28-2005 at 12:55 PM

quote:
Originally posted by TylerG
I think I found it, but when I try to end it, it says "This is a critical system process.  Task Manager cannot end this process.":S  But it might just be a regular process, but I don't think I have seen it before.
use services.msc to end it :)

Start > Run > services.msc
RE: RE: msconfig by CookieRevised on 11-28-2005 at 02:51 PM

quote:
Originally posted by MeEtc
quote:
Originally posted by TylerG
I think I found it, but when I try to end it, it says "This is a critical system process.  Task Manager cannot end this process.":S  But it might just be a regular process, but I don't think I have seen it before.
use services.msc to end it :)

Start > Run > services.msc

csrss.exe is not a service, therefore starting up services.msc woudn't do anything good.

-----------

TylerG,

If csrss.exe is the virus, then there should be two csrss.exe processes running. One for the virus and one for the legit windows process.

To determine which is which, you need to:
  • either look at who has started the process. If it is "SYSTEM" or "NT AUTHORITY" or the likes then it means it is the legit windows process. If it is your username/computername then it means csrss.exe has started up as a normal program and thus the process is not legit and a fake.
  • either look at the startup directory of csrss.exe. If it is C:\Windows\System32 Then that it is the legit windows program. If it is another directory, you have your virus (but seeing the directory is not possible in Windows' TaskManager).


Killing the process in Windows' TaskManager will indeed popup the "this is a system process yadda yadda"-warning as Windows only checks for filename (which is of course the same as the real legit one) and thus it gives that warning.



[Image: attachment.php?pid=570865]
To remove it properly:
  1. Run "Process Explorer" from SysInternal. Find the not-legit csrss.exe file by right clicking on its name and checking its properties for the startup directroy and/or check who owns the process "NT AUTHORITY/SYSTEM" or you.
  2. If found, and still in Process Explorer, kill it using right click, "Kill Process Tree".
  3. Now run "AutoRuns" from SysInternal. And find the startup entry (or entries) of the not-legit csrss.exe and remove it.
  4. Reboot

Also see CookieRevised's reply to Block-Checker