Results 1 to 5 of 5

Thread: Getting multiple suspicious files: Csrss, Dwm and Conhost.exe files

  1. #1
    Join Date
    Jun 2011
    Posts
    16

    Getting multiple suspicious files: Csrss, Dwm and Conhost.exe files

    I am using Windows XP in my installed in my computer along with the Bit defender total security running. Last night Active Virus control prompted me to either block or allow the csrss.exe file when I was browsing on MySpace page of someone. Immediately I was prompted to allow/block the dwm.exe file. By unaware of it I just clicked on allow. The problem is whenever I am browsing on the google search, it displays the advertising pages instead of the search page. After sometime I was prompted to block or allow conhost.exe file. I found that task manager lists these files (csrss.exe, dwm.exe and conhost.exe) as running in my back ground. With other csrss.exe task. I scanned the system and found that the Csrss.exe file is found on the user/Local Settings/Temp/ map. I also tried to map the dwm.exe and conhost.exe, I got the notification that the, dwm.exe virus name Gen:Variant.Kazy.22500 "BD can't disinfect, delete or quarantine this file. Access to this file has been denied." Ans conhost.exe virus name Gen:Variant.Kazy.22500 "BD can't disinfect, delete or quarantine this file. Access to this file has been denied." Today I found that both the browsers I am using Opera 11.10 and Firefox 4.0.1 not allowing me to browse for anything saying that “can’t connect to proxy server” how can I get rid of these files for sure?

  2. #2
    Join Date
    Jul 2009
    Posts
    1,179

    Re: Getting multiple suspicious files: Csrss, Dwm and Conhost.exe files

    I think there might be a Trojan that is interfering in between and making you to redirect through the proxy server, this is not the way we use it. Before making a system scan, first try to turn off all your firewalls and then unplug your internet connection to avoid it sending any information through the net. I went through a deep scan last night and I was able to solve the redirecting issue. If you want I can send you a log file of the deep system scan.

  3. #3
    Join Date
    Jul 2009
    Posts
    1,118

    Re: Getting multiple suspicious files: Csrss, Dwm and Conhost.exe files

    I was able to delete all the files that you have mentioned. But I did this by manually removing it, I removed it by removing the registry values using HijackThis or some other registry tool. After I reboot my system every time when I started using these tools I get this file occurring again, it pop ups with error message pointing out that file cannot be found. It was referring to the entry HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load. I am sure that on every reboot I find F3 - REG:win.ini: load=c:/documents and settings/user/ on using the HijackThis is not a major issue.

  4. #4
    Join Date
    May 2009
    Posts
    1,084

    Re: Getting multiple suspicious files: Csrss, Dwm and Conhost.exe files

    Always keep note that Microsoft has created a windows files named Csrss.exe, the graphical instructions of the Operating System of Microsoft Is managed using this. And if you find any of these files other than %system%\csrss.exe file folder then it could be a virus. Make sure that you make our system scan with an updated Anti-virus. See to it that you have only one antivirus installed in your system. If you have any other Anti-virus installed make them disable, and then scan it.

  5. #5
    Join Date
    Nov 2009
    Posts
    955

    Re: Getting multiple suspicious files: Csrss, Dwm and Conhost.exe files

    The file names that you have mentioned conhost.exe and dwm.exe are identified as a Trojan backdoor cycbot in the virus analysis programs report. On a host machine it opens a backdoor which is done by a cycbot which is a Trojan horse. Try removing the file from the registry and also from start up of windows. Some of the programs running on your system may have the same name as the virus name, so first differentiate it using Windows Defender and then delete those files, as some files may be important for your system.

Similar Threads

  1. PUP.FunWebProducts: myfuncards has number of suspicious files
    By Kabilan in forum Networking & Security
    Replies: 3
    Last Post: 29-08-2011, 12:51 AM
  2. cmd.exe, conhost.exe & csrss.exe using 20% of CPU after boot
    By L 4 Life in forum Operating Systems
    Replies: 4
    Last Post: 25-01-2011, 08:09 AM
  3. Replies: 3
    Last Post: 14-05-2009, 10:25 AM
  4. Are these files suspicious? Needs to be removed?
    By wimmer in forum MediaCenter
    Replies: 2
    Last Post: 16-03-2007, 08:19 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,716,294,372.99894 seconds with 17 queries