|
csrss.exe (5.1.2600.0)
Contenu dans le logiciel |
Nom: | Windows XP Home Edition, Deutsch |
Permis: | commercial |
Lien de l'information: | http://www.microsoft.com/windowsxp/ |
Détails de dossier |
Chemin de dossier: | C:\WINDOWS\system32\dllcache \ csrss.exe |
Date de dossier: | 2002-08-29 14:00:00 |
Version: | 5.1.2600.0 |
Volume de fichier: | 4.096 bytes |
La somme et le dossier hache |
CRC32: | 7567F540 |
MD5: | C113 8540 3DCE 2C9F C292 54DC A980 5ECD |
SHA1: | 0B1B 4B29 8153 60C9 E280 AC1C E03F 9E07 C290 892C |
L'information de ressource de version |
Nom de compagnie: | Microsoft Corporation |
Description de dossier: | Client Server Runtime Process |
Logiciel d'exploitation de dossier: | Windows NT, Windows 2000, Windows XP, Windows 2003 |
Type de dossier: | Application |
Version de dossier: | 5.1.2600.0 |
Nom interne: | CSRSS.Exe |
Copyright légal: | © Microsoft Corporation. All rights reserved. |
Nom de fichier original: | CSRSS.Exe |
Nom de produit: | Microsoft® Windows® Operating System |
Version de produit: | 5.1.2600.0 |
csrss.exe a été trouvé dans les rapports suivants:
|
W32.Dalbug.Worm |
Détails techniques ...%windir%Smss.exe %windir%Csrss.exe NOTE: %windir% is a variable.... ...This is a non-malicious joke program that is executed by Smss.exe and Csrss.exe once they are running.... ...NOTE: The files Smss.exe and Csrss.exe have the same file names as two system files that reside in the %windir%System32... ...During execution, the Smss.exe and Csrss.exe files keep the service running, and checking every three seconds to make sure... ... %windir%smss.exe Csrss.exe %windir%csrss.exe... ...process if it is activated. Smss.exe and Csrss.exe also try to create the these registry values, however if they detect that Regedit.exe... ...(instead of creating them). Finally, Smss.exe and Csrss.exe will also copy the worm to the following files:... Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.dalbug.worm.html |
Trojan.Webus |
Détails techniques ...Copies itself as %System%csrss.exe. Note: %System% is a variable... ..."ccpApps" = "%System%csrss.exe" ".WMAudio" = "%System%csrss.exe"... ..."Prog" = "%System%csrss.exe" "FiendlyType" =... ...".TEXTCONV" = "%System%csrss.exe" "Microsoft SourceSafe"... ..."RegDone Ex" = "%System%csrss.exe" "BuildLabs" = "%System%csrss.exe"... Instructions de déplacement ..."ccpApps" = "%System%csrss.exe" ".WMAudio" = "%System%csrss.exe"... ..."Prog" = "%System%csrss.exe" "FiendlyType" =... ...".TEXTCONV" = "%System%csrss.exe" "Microsoft SourceSafe"... ..."RegDone Ex" = "%System%csrss.exe" "BuildLabs" = "%System%csrss.exe"... Source: http://securityresponse.symantec.com/avcenter/venc/data/trojan.webus.html |
Backdoor.Hale |
Détails techniques ...A harmless text file. Csrss.exe: a Backdoor Trojan Horse detected... ..."NTDLM" = "c:winntsystem32qossrvcsrss.exe" to the registry key:... ...NTS (Secure.exe) NTP (Csrss.exe) NOTE:... ...C:WinntSystem32dhcp: Csrsslsrms.dll: A text file, not a dll.... ...C:WinntSystem32
estore: Csrss.exe: Detected as Backdoor.Padmin.... Instructions de déplacement ..."NTDLM"="c:winntsystem32qossrvcsrss.exe" Navigate to the key:... Source: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.hale.html |
Spyware.LoverSpy |
Détails techniques ...%Windir%Rec_pwd.html %System%ShellExtCsrss.exe Notes:... Instructions de déplacement ...%Windir%Rec_pwd.html %System%ShellExtCsrss.exe Write-up by:... Source: http://securityresponse.symantec.com/avcenter/venc/data/spyware.loverspy.html |
W32.Ahlem.A@mm |
Détails techniques ...Create a copy of the worm as %Windir%Csrss.exe. NOTE: %Windir% is a variable.... ..."SYSTEMSars32"="%Windir%csrss.exe" to the registry key:... Instructions de déplacement ..."SYSTEMSars32"="%windir%csrss.exe" Exit the Registry Editor.... Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.ahlem.a@mm.html |
Backdoor.Stanex |
Détails techniques ...%Windir%systemSysTray.exe. %Windir%TEMPCSRSS.exe %Windir%systemCSRSS.exe... ...Windows 95/98/Me: %Windir%system32CSRSS.exe. On Windows 95/98/Me, the Trojan... Source: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.stanex.html |
Trojan.Gutta |
Détails techniques ...Copies itself as C:WindowsCSRSS.exe. This path is hard-coded and... ..."rundll32" = "windowscsrss.exe" in the registry key:... Instructions de déplacement ..."rundll32"="C:WindowsCSRSS.exe" Exit the Registry Editor.... Source: http://securityresponse.symantec.com/avcenter/venc/data/trojan.gutta.html |
W32.Sndog@mm |
Détails techniques ...Copies itself to %windir%csrss.exe as a hidden file. Note: %Windir% is a variable... ..."Shockwave" = "%windir%csrss.exe" to the registry key:... Instructions de déplacement ..."Shockwave" = "%windir%csrss.exe" Exit the Registry Editor.... Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.sndog@mm.html |
W32.Nimda.E@mm |
Détails techniques ...The worm now copies itself to the \%Windows% folder as Csrss.exe instead of Mmc.exe NOTE: %Windows% is a variable.... Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.nimda.e@mm.html |
Backdoor.Sokacaps |
Détails techniques ...Creates the files: C:windowsmediacsrss.exe C:windowsmediacsrss.uzy... ..."RegWrite"="c:windowsmediacsrss.exe" to the registry key:... Instructions de déplacement ...Scroll through the list and look for Csrss.uzy. If you find the file, click... ..."RegWrite"="c:windowsmediacsrss.exe" Exit the Registry Editor.... ...... Source: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sokacaps.html |
|
|