1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Running Services: iass.exe, crss.exe, Constant writes?

Discussion in 'Windows XP' started by martinr121, 2005/02/28.

Thread Status:
Not open for further replies.
  1. 2005/02/28
    martinr121 Lifetime Subscription

    martinr121 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,219
    Likes Received:
    0
    Hi All, maybe somebody can enlighten me on this one. I noticed that my hard drive light blinks constantly, about 1 or 1 1/2 times per second forever. As far as I know this is a relatively new behavior.

    When I look at running services in task manager, I see constant reads/writes for two services, iass.exe and crss.exe whose tally changes with each HDD blink. I also see svchost.exe, doing reads and writes, but not at the magnitude of the others.

    Also, without foreground programs running, performance tab shows the cpu usage constant at 5-7%% and system idle process at 0.

    I did a search for those two, including hidden and system fileas, and as far as Windows is concerned, there are no such files on this machine.

    Any information would be appreciated.

    Take care,

    Martin
     
  2. 2005/02/28
    surferdude2

    surferdude2 Inactive

    Joined:
    2004/07/04
    Messages:
    4,009
    Likes Received:
    23
    Sounds like malware to me martin. Run AdAware and Spybot to clean it up. Use good ol' HiJackThis also. Delete the files manually if you must. (Safe Mode)
     

  3. to hide this advert.

  4. 2005/02/28
    Bmoore1129

    Bmoore1129 Geek Member

    Joined:
    2002/06/11
    Messages:
    1,675
    Likes Received:
    3
    I have lsass.exe and csrss.exe running in my processes but they are not causing cpu usage. They are in C:\Windows\system32 and in the DLL cache. Are these the things you see?

    Do you have windows indexing turned on? That will cause your HD to hunt and peck incessantly.
     
  5. 2005/02/28
    surferdude2

    surferdude2 Inactive

    Joined:
    2004/07/04
    Messages:
    4,009
    Likes Received:
    23
    Martin, you need to update your worms. You're running an older version and you may be missing some of the misery. :eek:

    Agbot Worm
     
  6. 2005/02/28
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    :)
     
  7. 2005/02/28
    martinr121 Lifetime Subscription

    martinr121 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,219
    Likes Received:
    0
    Mea Culpa, Mea Culpa: :eek:

    Correct service names:

    csrss.exe
    isass.exe

    Both are merrily writing and reading, after several hours of uptime. Windows will not allow service shutdown, claiming them to be "Critical Processes "

    Ad Aware, Norton AV, SpyBot, PestPatrol, MSFT's anti spyware all come up empty.

    Dude, maybe if you send me a link for the Worm update, those programs could find the updated version! :D

    Tale care,

    Martin
     
  8. 2005/02/28
    surferdude2

    surferdude2 Inactive

    Joined:
    2004/07/04
    Messages:
    4,009
    Likes Received:
    23
    Last edited: 2005/02/28
  9. 2005/02/28
    Steve R Jones

    Steve R Jones SuperGeek Staff

    Joined:
    2001/12/30
    Messages:
    12,315
    Likes Received:
    252
  10. 2005/02/28
    martinr121 Lifetime Subscription

    martinr121 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,219
    Likes Received:
    0
    Gulp! :eek: :eek:

    From: www.answersthatwork.com
    :confused: Well, it looked like an i to me. :confused:

    I will be in hiding for the next 24 hours.

    Martin
     
  11. 2005/02/28
    surferdude2

    surferdude2 Inactive

    Joined:
    2004/07/04
    Messages:
    4,009
    Likes Received:
    23
    Well, that settles it..You either need to run an on-line scan or run to the optometrist. :) Not to worry martin, I drop my candy in the sand once in a while too. We'll let you slide.
     
  12. 2005/02/28
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi Martin! :)

    Suspicious activity and very odd CPU numbers. Lets have a closer look at your processes. Download Process Explorer, unzip and open, then click file>save as and put on your desktop. Open and copy/paste it here.
     
  13. 2005/02/28
    martinr121 Lifetime Subscription

    martinr121 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,219
    Likes Received:
    0
    Hi Dave, Darn HDD, blink, blink, blink.

    Here's the file:
     
  14. 2005/03/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    This one doesn't look good to me.
    INSTAN~1.EXE 2952

    Please download the List Installed Programs script from here, run it and post it's log.
     
  15. 2005/03/01
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
  16. 2005/03/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    HeHe, you may be right Tony. I figured the cookie.exe is the Cookie Wall program, and I think I've been seeing too much of the Instant Access infection lately. :rolleyes:

    Gonna crawl into the corner and keep Martin company. :D
     
  17. 2005/03/01
    martinr121 Lifetime Subscription

    martinr121 Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,219
    Likes Received:
    0
    I dunno Dave, this corner is kind of crowded!

    Anyhow, both you and Tony are correct, Cookie.exe is the executable for AnalogX's Cookie Wall, and the Instant Access is part of the OCR for ScanSoft scanner software.

    Regardless, I did a search for the infected cookie.exe files, the reg keys associated with it and the DIZ file for the "You've Been Hit" email. All come up negative. (I remember getting that email, but no trace of the virus.)

    I did the online virus scan, comes up empty.

    In the meantime, the HDD led goes blink, blink, blink blink...........

    Task Mgr. Performance now indicates processer use fluctuating between 2 & 4%, I am attaching screen shots, are we done? What else could cause the HDD blinks besides a virus?

    lsass and csrss still doing their reads and writes, I suppose they are supposed to keep going and going and going? :) Along with HDD blink, blink, blink, blink, blink................... :confused:

    Everybody should have a good day today, it is snowing here, BRRRRRRR

    Take care,

    Martin

    Attachments of screenshots of performance graph did not load, 6.9 bytes too big, if of some use, I can resize?
     
    Last edited: 2005/03/01
  18. 2005/03/01
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    could you use FileMon from sysinternals and see whos doing what?
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.