[filename.info logo]
[cn csrss.exe][de csrss.exe][es csrss.exe][fr csrss.exe][gb csrss.exe][it csrss.exe][jp csrss.exe][kr csrss.exe][nl csrss.exe][pt csrss.exe][ru csrss.exe][us csrss.exe]
 

csrss.exe (5.1.2600.0)

包含在软件

名字:Windows XP Home Edition, Deutsch
执照:商业
信息链接:http://www.microsoft.com/windowsxp/

文件细节

文件道路:C:\WINDOWS\system32\dllcache \ csrss.exe
文件日期:2002-08-29 14:00:00
版本:5.1.2600.0
文件大小:4.096 字节

检查和和文件hashes

CRC32:7567F540
MD5:C113 8540 3DCE 2C9F C292 54DC A980 5ECD
SHA1:0B1B 4B29 8153 60C9 E280 AC1C E03F 9E07 C290 892C

版本资源信息

公司名称:Microsoft Corporation
文件描述:Client Server Runtime Process
文件操作系统:Windows NT, Windows 2000, Windows XP, Windows 2003
文件类型:Application
文件版本:5.1.2600.0
内部名:CSRSS.Exe
法律版权:© Microsoft Corporation. All rights reserved.
原始的文件名:CSRSS.Exe
产品名称:Microsoft® Windows® Operating System
产品版本:5.1.2600.0

csrss.exe 被发现了在以下报告:

W32.Dalbug.Worm

技术细节
...%windir%Smss.exe %windir%Csrss.exe NOTE: %windir% is a variable....
...This is a non-malicious joke program that is executed by Smss.exe and Csrss.exe once they are running....
...NOTE: The files Smss.exe and Csrss.exe have the same file names as two system files that reside in the %windir%System32...
...During execution, the Smss.exe and Csrss.exe files keep the service running, and checking every three seconds to make sure...
...    %windir%smss.exe Csrss.exe      %windir%csrss.exe...
...process if it is activated. Smss.exe and Csrss.exe also try to create the these registry values, however if they detect that Regedit.exe...
...(instead of creating them). Finally, Smss.exe and Csrss.exe will also copy the worm to the following files:...
来源: http://securityresponse.symantec.com/avcenter/venc/data/w32.dalbug.worm.html

Trojan.Webus

技术细节
...Copies itself as %System%csrss.exe. Note: %System% is a variable...
..."ccpApps" = "%System%csrss.exe" ".WMAudio" = "%System%csrss.exe"...
..."Prog" = "%System%csrss.exe" "FiendlyType" =...
...".TEXTCONV" = "%System%csrss.exe" "Microsoft SourceSafe"...
..."RegDone Ex" = "%System%csrss.exe" "BuildLabs" = "%System%csrss.exe"...
撤除指示
..."ccpApps" = "%System%csrss.exe" ".WMAudio" = "%System%csrss.exe"...
..."Prog" = "%System%csrss.exe" "FiendlyType" =...
...".TEXTCONV" = "%System%csrss.exe" "Microsoft SourceSafe"...
..."RegDone Ex" = "%System%csrss.exe" "BuildLabs" = "%System%csrss.exe"...
来源: http://securityresponse.symantec.com/avcenter/venc/data/trojan.webus.html

Backdoor.Hale

技术细节
...A harmless text file. Csrss.exe: a Backdoor Trojan Horse detected...
..."NTDLM" = "c:winntsystem32qossrvcsrss.exe" to the registry key:...
...NTS (Secure.exe) NTP (Csrss.exe) NOTE:...
...C:WinntSystem32dhcp: Csrsslsrms.dll: A text file, not a dll....
...C:WinntSystem32 estore: Csrss.exe: Detected as Backdoor.Padmin....
撤除指示
..."NTDLM"="c:winntsystem32qossrvcsrss.exe" Navigate to the key:...
来源: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.hale.html

Spyware.LoverSpy

技术细节
...%Windir%Rec_pwd.html %System%ShellExtCsrss.exe Notes:...
撤除指示
...%Windir%Rec_pwd.html %System%ShellExtCsrss.exe Write-up by:...
来源: http://securityresponse.symantec.com/avcenter/venc/data/spyware.loverspy.html

W32.Ahlem.A@mm

技术细节
...Create a copy of the worm as %Windir%Csrss.exe. NOTE: %Windir% is a variable....
..."SYSTEMSars32"="%Windir%csrss.exe" to the registry key:...
撤除指示
..."SYSTEMSars32"="%windir%csrss.exe" Exit the Registry Editor....
来源: http://securityresponse.symantec.com/avcenter/venc/data/w32.ahlem.a@mm.html

Backdoor.Stanex

技术细节
...%Windir%systemSysTray.exe. %Windir%TEMPCSRSS.exe %Windir%systemCSRSS.exe...
...Windows 95/98/Me: %Windir%system32CSRSS.exe. On Windows 95/98/Me, the Trojan...
来源: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.stanex.html

Trojan.Gutta

技术细节
...Copies itself as C:WindowsCSRSS.exe. This path is hard-coded and...
..."rundll32" = "windowscsrss.exe" in the registry key:...
撤除指示
..."rundll32"="C:WindowsCSRSS.exe" Exit the Registry Editor....
来源: http://securityresponse.symantec.com/avcenter/venc/data/trojan.gutta.html

W32.Sndog@mm

技术细节
...Copies itself to %windir%csrss.exe as a hidden file. Note: %Windir% is a variable...
..."Shockwave" = "%windir%csrss.exe" to the registry key:...
撤除指示
..."Shockwave" = "%windir%csrss.exe" Exit the Registry Editor....
来源: http://securityresponse.symantec.com/avcenter/venc/data/w32.sndog@mm.html

W32.Nimda.E@mm

技术细节
...The worm now copies itself to the \%Windows% folder as Csrss.exe instead of Mmc.exe NOTE: %Windows% is a variable....
来源: http://securityresponse.symantec.com/avcenter/venc/data/w32.nimda.e@mm.html

Backdoor.Sokacaps

技术细节
...Creates the files: C:windowsmediacsrss.exe C:windowsmediacsrss.uzy...
..."RegWrite"="c:windowsmediacsrss.exe" to the registry key:...
撤除指示
...Scroll through the list and look for Csrss.uzy. If you find the file, click...
..."RegWrite"="c:windowsmediacsrss.exe" Exit the Registry Editor....
......
来源: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sokacaps.html



Valid HTML 4.01!