Running Processes

Status
Not open for further replies.

Mr. tech

In Runtime
Messages
384
I've been entering my processes found in Task manager into http://www.pcpitstop.com/spycheck/known.asp

Below are the ones they said to remove... is this correct?

csrss.exe (Ascentive BeAware)
smss.exe (Dalbug/Ladex worm)

These oens they found no record of. Sould I remove them?:

dcfssvc.exe
PTS.exe

What is the best way to remove them?
 
Hi Mr. tech

this is what i found

CSRSS.EXE is a system file, but there's also a virus which uses the same name. depending on where it's located but usually no donot delete it


csrss - csrss.exe - Process Information

Process File: csrss or csrss.exe
Process Name: Microsoft Client/Server Runtime Server Subsystem

Description:
csrss.exe is the main executable for the Microsoft Client/Server Runtime Server Subsystem. This process manages most graphical commands in Windows. This program is important for the stable and secure running of your computer and should not be terminated. Note: csrss.exe is also process which is registered as the W32.Netsky.AB@mm worm, the W32.Webus Trojan, Win32.Ladex.a and more. This virus is distributed via the Internet through e-mail and comes in the form of an e-mail message, in the hopes that you open itÂ’s hostile attachment. The worm has itÂ’s own SMTP engine which means it gathers E-mails from your local computer and re-distributes itself. In worst cases this worm can allow attackers to access your computer, stealing passwords and personal data. It is a registered security risk and should be removed immediately. Please see additional details regarding this process


smss.exe

Process File: smss or smss.exe
Process Name: Session Manager Subsystem

Description:
smss.exe is a process which is a part of the Microsoft Windows Operating System. It is called the Session Manager SubSystem and is responsible for handling sessions on your system. This program is important for the stable and secure running of your computer and should not be terminated. Note: smss.exe is also a process which is registered as the Win32.Ladex.a Trojan. This Trojan allows attackers to access your computer, stealing passwords and personal data. It is a registered security risk and should be removed immediately. Please see additional details regarding this process

Are you having trouble with your computer or you were just curious

Lobos
 
Justt curious... Better safe then sorry :)

Where did you find that detailed information BTW?
 
Status
Not open for further replies.
Back
Top Bottom