[filename.info logo]
[cn csrss.exe][de csrss.exe][es csrss.exe][fr csrss.exe][gb csrss.exe][it csrss.exe][jp csrss.exe][kr csrss.exe][nl csrss.exe][pt csrss.exe][ru csrss.exe][us csrss.exe]
 

csrss.exe (5.1.2600.0)

Contenuto nel software

Nome:Windows XP Home Edition, Deutsch
Autorizzazione:commerciale
Collegamento delle informazioni:http://www.microsoft.com/windowsxp/

Particolari della lima

Percorso della lima:C:\WINDOWS\system32\dllcache \ csrss.exe
Data della lima:2002-08-29 14:00:00
Versione:5.1.2600.0
Formato di lima:4.096 byte

Il totale di controllo e la lima hashes

CRC32:7567F540
MD5:C113 8540 3DCE 2C9F C292 54DC A980 5ECD
SHA1:0B1B 4B29 8153 60C9 E280 AC1C E03F 9E07 C290 892C

Le informazioni delle risorse di versione

Nome di azienda:Microsoft Corporation
Descrizione della lima:Client Server Runtime Process
Sistema operativo della lima:Windows NT, Windows 2000, Windows XP, Windows 2003
Tipo della lima:Application
Versione della lima:5.1.2600.0
Nome interno:CSRSS.Exe
Copyright legale:© Microsoft Corporation. All rights reserved.
Nome di schedario originale:CSRSS.Exe
Nome del prodotto:Microsoft® Windows® Operating System
Versione del prodotto:5.1.2600.0

csrss.exe è stato trovato nei seguenti rapporti:

W32.Dalbug.Worm

Particolari tecnici
...%windir%Smss.exe %windir%Csrss.exe NOTE: %windir% is a variable....
...This is a non-malicious joke program that is executed by Smss.exe and Csrss.exe once they are running....
...NOTE: The files Smss.exe and Csrss.exe have the same file names as two system files that reside in the %windir%System32...
...During execution, the Smss.exe and Csrss.exe files keep the service running, and checking every three seconds to make sure...
...    %windir%smss.exe Csrss.exe      %windir%csrss.exe...
...process if it is activated. Smss.exe and Csrss.exe also try to create the these registry values, however if they detect that Regedit.exe...
...(instead of creating them). Finally, Smss.exe and Csrss.exe will also copy the worm to the following files:...
Fonte: http://securityresponse.symantec.com/avcenter/venc/data/w32.dalbug.worm.html

Trojan.Webus

Particolari tecnici
...Copies itself as %System%csrss.exe. Note: %System% is a variable...
..."ccpApps" = "%System%csrss.exe" ".WMAudio" = "%System%csrss.exe"...
..."Prog" = "%System%csrss.exe" "FiendlyType" =...
...".TEXTCONV" = "%System%csrss.exe" "Microsoft SourceSafe"...
..."RegDone Ex" = "%System%csrss.exe" "BuildLabs" = "%System%csrss.exe"...
Istruzioni di rimozione
..."ccpApps" = "%System%csrss.exe" ".WMAudio" = "%System%csrss.exe"...
..."Prog" = "%System%csrss.exe" "FiendlyType" =...
...".TEXTCONV" = "%System%csrss.exe" "Microsoft SourceSafe"...
..."RegDone Ex" = "%System%csrss.exe" "BuildLabs" = "%System%csrss.exe"...
Fonte: http://securityresponse.symantec.com/avcenter/venc/data/trojan.webus.html

Backdoor.Hale

Particolari tecnici
...A harmless text file. Csrss.exe: a Backdoor Trojan Horse detected...
..."NTDLM" = "c:winntsystem32qossrvcsrss.exe" to the registry key:...
...NTS (Secure.exe) NTP (Csrss.exe) NOTE:...
...C:WinntSystem32dhcp: Csrsslsrms.dll: A text file, not a dll....
...C:WinntSystem32 estore: Csrss.exe: Detected as Backdoor.Padmin....
Istruzioni di rimozione
..."NTDLM"="c:winntsystem32qossrvcsrss.exe" Navigate to the key:...
Fonte: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.hale.html

Spyware.LoverSpy

Particolari tecnici
...%Windir%Rec_pwd.html %System%ShellExtCsrss.exe Notes:...
Istruzioni di rimozione
...%Windir%Rec_pwd.html %System%ShellExtCsrss.exe Write-up by:...
Fonte: http://securityresponse.symantec.com/avcenter/venc/data/spyware.loverspy.html

W32.Ahlem.A@mm

Particolari tecnici
...Create a copy of the worm as %Windir%Csrss.exe. NOTE: %Windir% is a variable....
..."SYSTEMSars32"="%Windir%csrss.exe" to the registry key:...
Istruzioni di rimozione
..."SYSTEMSars32"="%windir%csrss.exe" Exit the Registry Editor....
Fonte: http://securityresponse.symantec.com/avcenter/venc/data/w32.ahlem.a@mm.html

Backdoor.Stanex

Particolari tecnici
...%Windir%systemSysTray.exe. %Windir%TEMPCSRSS.exe %Windir%systemCSRSS.exe...
...Windows 95/98/Me: %Windir%system32CSRSS.exe. On Windows 95/98/Me, the Trojan...
Fonte: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.stanex.html

Trojan.Gutta

Particolari tecnici
...Copies itself as C:WindowsCSRSS.exe. This path is hard-coded and...
..."rundll32" = "windowscsrss.exe" in the registry key:...
Istruzioni di rimozione
..."rundll32"="C:WindowsCSRSS.exe" Exit the Registry Editor....
Fonte: http://securityresponse.symantec.com/avcenter/venc/data/trojan.gutta.html

W32.Sndog@mm

Particolari tecnici
...Copies itself to %windir%csrss.exe as a hidden file. Note: %Windir% is a variable...
..."Shockwave" = "%windir%csrss.exe" to the registry key:...
Istruzioni di rimozione
..."Shockwave" = "%windir%csrss.exe" Exit the Registry Editor....
Fonte: http://securityresponse.symantec.com/avcenter/venc/data/w32.sndog@mm.html

W32.Nimda.E@mm

Particolari tecnici
...The worm now copies itself to the \%Windows% folder as Csrss.exe instead of Mmc.exe NOTE: %Windows% is a variable....
Fonte: http://securityresponse.symantec.com/avcenter/venc/data/w32.nimda.e@mm.html

Backdoor.Sokacaps

Particolari tecnici
...Creates the files: C:windowsmediacsrss.exe C:windowsmediacsrss.uzy...
..."RegWrite"="c:windowsmediacsrss.exe" to the registry key:...
Istruzioni di rimozione
...Scroll through the list and look for Csrss.uzy. If you find the file, click...
..."RegWrite"="c:windowsmediacsrss.exe" Exit the Registry Editor....
......
Fonte: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sokacaps.html



Valid HTML 4.01!