|
csrss.exe (5.1.2600.0)
Bevat in software |
Naam: | Windows XP Home Edition, Deutsch |
Vergunning: | commercieel |
De verbinding van de informatie: | http://www.microsoft.com/windowsxp/ |
De details van het dossier |
De weg van het dossier: | C:\WINDOWS\system32\dllcache \ csrss.exe |
De datum van het dossier: | 2002-08-29 14:00:00 |
Versie: | 5.1.2600.0 |
De grootte van het dossier: | 4.096 bytes |
De knoeiboel van de controlesom en van het dossier |
CRC32: | 7567F540 |
MD5: | C113 8540 3DCE 2C9F C292 54DC A980 5ECD |
SHA1: | 0B1B 4B29 8153 60C9 E280 AC1C E03F 9E07 C290 892C |
Het middelinformatie van de versie |
Firmanaam: | Microsoft Corporation |
De beschrijving van het dossier: | Client Server Runtime Process |
Het werkende systeem van het dossier: | Windows NT, Windows 2000, Windows XP, Windows 2003 |
Het type van dossier: | Application |
De versie van het dossier: | 5.1.2600.0 |
Interne naam: | CSRSS.Exe |
Wettelijk auteursrecht: | © Microsoft Corporation. All rights reserved. |
Originele filename: | CSRSS.Exe |
De naam van het product: | Microsoft® Windows® Operating System |
De versie van het product: | 5.1.2600.0 |
csrss.exe werd gevonden in de volgende rapporten:
|
W32.Dalbug.Worm |
Technische details ...%windir%Smss.exe %windir%Csrss.exe NOTE: %windir% is a variable.... ...This is a non-malicious joke program that is executed by Smss.exe and Csrss.exe once they are running.... ...NOTE: The files Smss.exe and Csrss.exe have the same file names as two system files that reside in the %windir%System32... ...During execution, the Smss.exe and Csrss.exe files keep the service running, and checking every three seconds to make sure... ... %windir%smss.exe Csrss.exe %windir%csrss.exe... ...process if it is activated. Smss.exe and Csrss.exe also try to create the these registry values, however if they detect that Regedit.exe... ...(instead of creating them). Finally, Smss.exe and Csrss.exe will also copy the worm to the following files:... Bron: http://securityresponse.symantec.com/avcenter/venc/data/w32.dalbug.worm.html |
Trojan.Webus |
Technische details ...Copies itself as %System%csrss.exe. Note: %System% is a variable... ..."ccpApps" = "%System%csrss.exe" ".WMAudio" = "%System%csrss.exe"... ..."Prog" = "%System%csrss.exe" "FiendlyType" =... ...".TEXTCONV" = "%System%csrss.exe" "Microsoft SourceSafe"... ..."RegDone Ex" = "%System%csrss.exe" "BuildLabs" = "%System%csrss.exe"... De instructies van de verwijdering ..."ccpApps" = "%System%csrss.exe" ".WMAudio" = "%System%csrss.exe"... ..."Prog" = "%System%csrss.exe" "FiendlyType" =... ...".TEXTCONV" = "%System%csrss.exe" "Microsoft SourceSafe"... ..."RegDone Ex" = "%System%csrss.exe" "BuildLabs" = "%System%csrss.exe"... Bron: http://securityresponse.symantec.com/avcenter/venc/data/trojan.webus.html |
Backdoor.Hale |
Technische details ...A harmless text file. Csrss.exe: a Backdoor Trojan Horse detected... ..."NTDLM" = "c:winntsystem32qossrvcsrss.exe" to the registry key:... ...NTS (Secure.exe) NTP (Csrss.exe) NOTE:... ...C:WinntSystem32dhcp: Csrsslsrms.dll: A text file, not a dll.... ...C:WinntSystem32
estore: Csrss.exe: Detected as Backdoor.Padmin.... De instructies van de verwijdering ..."NTDLM"="c:winntsystem32qossrvcsrss.exe" Navigate to the key:... Bron: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.hale.html |
Spyware.LoverSpy |
Technische details ...%Windir%Rec_pwd.html %System%ShellExtCsrss.exe Notes:... De instructies van de verwijdering ...%Windir%Rec_pwd.html %System%ShellExtCsrss.exe Write-up by:... Bron: http://securityresponse.symantec.com/avcenter/venc/data/spyware.loverspy.html |
W32.Ahlem.A@mm |
Technische details ...Create a copy of the worm as %Windir%Csrss.exe. NOTE: %Windir% is a variable.... ..."SYSTEMSars32"="%Windir%csrss.exe" to the registry key:... De instructies van de verwijdering ..."SYSTEMSars32"="%windir%csrss.exe" Exit the Registry Editor.... Bron: http://securityresponse.symantec.com/avcenter/venc/data/w32.ahlem.a@mm.html |
Backdoor.Stanex |
Technische details ...%Windir%systemSysTray.exe. %Windir%TEMPCSRSS.exe %Windir%systemCSRSS.exe... ...Windows 95/98/Me: %Windir%system32CSRSS.exe. On Windows 95/98/Me, the Trojan... Bron: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.stanex.html |
Trojan.Gutta |
Technische details ...Copies itself as C:WindowsCSRSS.exe. This path is hard-coded and... ..."rundll32" = "windowscsrss.exe" in the registry key:... De instructies van de verwijdering ..."rundll32"="C:WindowsCSRSS.exe" Exit the Registry Editor.... Bron: http://securityresponse.symantec.com/avcenter/venc/data/trojan.gutta.html |
W32.Sndog@mm |
Technische details ...Copies itself to %windir%csrss.exe as a hidden file. Note: %Windir% is a variable... ..."Shockwave" = "%windir%csrss.exe" to the registry key:... De instructies van de verwijdering ..."Shockwave" = "%windir%csrss.exe" Exit the Registry Editor.... Bron: http://securityresponse.symantec.com/avcenter/venc/data/w32.sndog@mm.html |
W32.Nimda.E@mm |
Technische details ...The worm now copies itself to the \%Windows% folder as Csrss.exe instead of Mmc.exe NOTE: %Windows% is a variable.... Bron: http://securityresponse.symantec.com/avcenter/venc/data/w32.nimda.e@mm.html |
Backdoor.Sokacaps |
Technische details ...Creates the files: C:windowsmediacsrss.exe C:windowsmediacsrss.uzy... ..."RegWrite"="c:windowsmediacsrss.exe" to the registry key:... De instructies van de verwijdering ...Scroll through the list and look for Csrss.uzy. If you find the file, click... ..."RegWrite"="c:windowsmediacsrss.exe" Exit the Registry Editor.... ...... Bron: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sokacaps.html |
|
|