Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Operating Systems > Windows XP

Windows XP Post your Windows XP related questions here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Closed Thread
 
LinkBack Thread Tools
Old 28th February 2005   #1
SuperGeek
 
martinr121's Avatar
 
Profile:
Join Date: Jan 2002
Location: Blue Ridge, Ga.
Posts: 1,197
Computer Experience:
World's record of crashes
martinr121 Reputation Level


Running Services: iass.exe, crss.exe, Constant writes?

Hi All, maybe somebody can enlighten me on this one. I noticed that my hard drive light blinks constantly, about 1 or 1 1/2 times per second forever. As far as I know this is a relatively new behavior.

When I look at running services in task manager, I see constant reads/writes for two services, iass.exe and crss.exe whose tally changes with each HDD blink. I also see svchost.exe, doing reads and writes, but not at the magnitude of the others.

Also, without foreground programs running, performance tab shows the cpu usage constant at 5-7%% and system idle process at 0.

I did a search for those two, including hidden and system fileas, and as far as Windows is concerned, there are no such files on this machine.

Any information would be appreciated.

Take care,

Martin

martinr121 is offline  
Didn't find the information you thought to find?
Check out these Similar Threads
Old 28th February 2005   #2
SuperGeek
 
Profile:
Join Date: Jul 2004
Location: 62864
Posts: 3,720
Computer Experience:
Default
surferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Level


Sounds like malware to me martin. Run AdAware and Spybot to clean it up. Use good ol' HiJackThis also. Delete the files manually if you must. (Safe Mode)
surferdude2 is offline  
Old 28th February 2005   #3
SuperGeek
 
Bmoore1129's Avatar
 
Profile:
Join Date: Jun 2002
Location: Angelina County Texas
Posts: 1,539
Computer Experience:
1995
Bmoore1129 has disabled reputation

My System

I have lsass.exe and csrss.exe running in my processes but they are not causing cpu usage. They are in C:\Windows\system32 and in the DLL cache. Are these the things you see?

Do you have windows indexing turned on? That will cause your HD to hunt and peck incessantly.

Bmoore1129 is offline  
Old 28th February 2005   #4
SuperGeek
 
Profile:
Join Date: Jul 2004
Location: 62864
Posts: 3,720
Computer Experience:
Default
surferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Level


Martin, you need to update your worms. You're running an older version and you may be missing some of the misery.

Agbot Worm

surferdude2 is offline  
Old 28th February 2005   #5
WindowsBBS Team Member
 
TonyT's Avatar
 
Profile:
Join Date: Jan 2002
Location: Fairfax, VA
Posts: 4,798
Computer Experience:
echo $experienced;
TonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation Level


Quote:
Originally Posted by surferdude2
Martin, you need to update your worms. You're running an older version and you may be missing some of the misery.

Agbot Worm

TonyT is offline  
Old 28th February 2005   #6
SuperGeek
 
martinr121's Avatar
 
Profile:
Join Date: Jan 2002
Location: Blue Ridge, Ga.
Posts: 1,197
Computer Experience:
World's record of crashes
martinr121 Reputation Level


Mea Culpa, Mea Culpa:

Correct service names:

csrss.exe
isass.exe

Both are merrily writing and reading, after several hours of uptime. Windows will not allow service shutdown, claiming them to be "Critical Processes"

Ad Aware, Norton AV, SpyBot, PestPatrol, MSFT's anti spyware all come up empty.

Dude, maybe if you send me a link for the Worm update, those programs could find the updated version!

Tale care,

Martin

martinr121 is offline  
Old 28th February 2005   #7
SuperGeek
 
Profile:
Join Date: Jul 2004
Location: 62864
Posts: 3,720
Computer Experience:
Default
surferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Level


isass.exe is still a virus.

http://www.iamnotageek.com/a/isass.exe.php

Sometimes these keyloggers and such escape detection. Do an on-line with HouseCall maybe just for style points.


Last edited by surferdude2; 28th February 2005 at 22:07.
surferdude2 is offline  
Old 28th February 2005   #8
Staff
 
Steve R Jones's Avatar
 
Profile:
Join Date: Dec 2001
Location: Dallas, TX
Posts: 8,151
Computer Experience:
Experienced
Steve R Jones Reputation LevelSteve R Jones Reputation LevelSteve R Jones Reputation LevelSteve R Jones Reputation LevelSteve R Jones Reputation LevelSteve R Jones Reputation LevelSteve R Jones Reputation LevelSteve R Jones Reputation LevelSteve R Jones Reputation LevelSteve R Jones Reputation LevelSteve R Jones Reputation Level


"The pages below are from our in-house database and provide guidance on the usefulness or not of these programs, and removal procedures when recommended."


http://www.answersthatwork.com/Taskl...s/tasklist.htm

Steve R Jones is offline  
Old 1st March 2005   #9
SuperGeek
 
martinr121's Avatar
 
Profile:
Join Date: Jan 2002
Location: Blue Ridge, Ga.
Posts: 1,197
Computer Experience:
World's record of crashes
martinr121 Reputation Level


Gulp!

From: www.answersthatwork.com
Quote:
Isass
isass.exe

(???)
You have the Backdoor.Futro virus.

Note – do not confuse this with LSASS which will most times show as “lsass” in your Task List where the first letter is in fact a lowercase “L” rather than an “i”.
Well, it looked like an i to me.

I will be in hiding for the next 24 hours.

Martin

martinr121 is offline  
Old 1st March 2005   #10
SuperGeek
 
Profile:
Join Date: Jul 2004
Location: 62864
Posts: 3,720
Computer Experience:
Default
surferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Levelsurferdude2 Reputation Level


Well, that settles it..You either need to run an on-line scan or run to the optometrist. Not to worry martin, I drop my candy in the sand once in a while too. We'll let you slide.
surferdude2 is offline  
Old 1st March 2005   #11
Staff
 
noahdfear's Avatar
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,524
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

Hi Martin!

Suspicious activity and very odd CPU numbers. Lets have a closer look at your processes. Download Process Explorer, unzip and open, then click file>save as and put on your desktop. Open and copy/paste it here.

noahdfear is offline  
Old 1st March 2005   #12
SuperGeek
 
martinr121's Avatar
 
Profile:
Join Date: Jan 2002
Location: Blue Ridge, Ga.
Posts: 1,197
Computer Experience:
World's record of crashes
martinr121 Reputation Level


Hi Dave, Darn HDD, blink, blink, blink.

Here's the file:

martinr121 is offline  
Old 1st March 2005   #13
Staff
 
noahdfear's Avatar
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,524
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

This one doesn't look good to me.
INSTAN~1.EXE 2952

Please download the List Installed Programs script from here, run it and post it's log.

noahdfear is offline  
Old 1st March 2005   #14
WindowsBBS Team Member
 
TonyT's Avatar
 
Profile:
Join Date: Jan 2002
Location: Fairfax, VA
Posts: 4,798
Computer Experience:
echo $experienced;
TonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation Level


INSTAN~1.EXE = scanner software.

possible baddies:
cookie.exe:
http://vil.nai.com/vil/content/v_99083.htm

TonyT is offline  
Old 1st March 2005   #15
Staff
 
noahdfear's Avatar
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,524
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

HeHe, you may be right Tony. I figured the cookie.exe is the Cookie Wall program, and I think I've been seeing too much of the Instant Access infection lately.

Gonna crawl into the corner and keep Martin company.

noahdfear is offline  
Closed Thread

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
About:blank strikes again... JHD536 Malware and Virus Removal 17 29th September 2004 23:46
Start Dreck Log need help! HJT log posted Proudmoms Malware and Virus Removal 14 23rd September 2004 18:55
More of the same... Regenerating Spyware MikeXsells General Security 22 19th August 2004 00:36
Running Services FireDancer Windows XP 1 11th July 2004 20:59
Sever 2000 many services running..help nice22 Windows 2000 2 8th December 2003 22:54


All times are GMT +1. The time now is 09:34.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]