[filename.info logo]
[cn csrss.exe][de csrss.exe][es csrss.exe][fr csrss.exe][gb csrss.exe][it csrss.exe][jp csrss.exe][kr csrss.exe][nl csrss.exe][pt csrss.exe][ru csrss.exe][us csrss.exe]
 

csrss.exe (5.1.2600.0)

Содержали в средстве программирования

Имя:Windows XP Home Edition, Deutsch
Лицензия:коммерчески
Соединение информации:http://www.microsoft.com/windowsxp/

Детали архива

Курс архива:C:\WINDOWS\system32\dllcache \ csrss.exe
Дата архива:2002-08-29 14:00:00
Вариант:5.1.2600.0
Размер архива:4.096 байты

Hashes checksum и архива

CRC32:7567F540
MD5:C113 8540 3DCE 2C9F C292 54DC A980 5ECD
SHA1:0B1B 4B29 8153 60C9 E280 AC1C E03F 9E07 C290 892C

Данные по ресурса варианта

Имя компании:Microsoft Corporation
Описание архива:Client Server Runtime Process
Оперативная система архива:Windows NT, Windows 2000, Windows XP, Windows 2003
Тип архива:Application
Вариант архива:5.1.2600.0
Внутренне имя:CSRSS.Exe
Законное авторское право:© Microsoft Corporation. All rights reserved.
Первоначально filename:CSRSS.Exe
Имя продукта:Microsoft® Windows® Operating System
Вариант продукта:5.1.2600.0

csrss.exe было найдено в following рапортах:

W32.Dalbug.Worm

Технически детали
...%windir%Smss.exe %windir%Csrss.exe NOTE: %windir% is a variable....
...This is a non-malicious joke program that is executed by Smss.exe and Csrss.exe once they are running....
...NOTE: The files Smss.exe and Csrss.exe have the same file names as two system files that reside in the %windir%System32...
...During execution, the Smss.exe and Csrss.exe files keep the service running, and checking every three seconds to make sure...
...    %windir%smss.exe Csrss.exe      %windir%csrss.exe...
...process if it is activated. Smss.exe and Csrss.exe also try to create the these registry values, however if they detect that Regedit.exe...
...(instead of creating them). Finally, Smss.exe and Csrss.exe will also copy the worm to the following files:...
Источник: http://securityresponse.symantec.com/avcenter/venc/data/w32.dalbug.worm.html

Trojan.Webus

Технически детали
...Copies itself as %System%csrss.exe. Note: %System% is a variable...
..."ccpApps" = "%System%csrss.exe" ".WMAudio" = "%System%csrss.exe"...
..."Prog" = "%System%csrss.exe" "FiendlyType" =...
...".TEXTCONV" = "%System%csrss.exe" "Microsoft SourceSafe"...
..."RegDone Ex" = "%System%csrss.exe" "BuildLabs" = "%System%csrss.exe"...
Инструкции удаления
..."ccpApps" = "%System%csrss.exe" ".WMAudio" = "%System%csrss.exe"...
..."Prog" = "%System%csrss.exe" "FiendlyType" =...
...".TEXTCONV" = "%System%csrss.exe" "Microsoft SourceSafe"...
..."RegDone Ex" = "%System%csrss.exe" "BuildLabs" = "%System%csrss.exe"...
Источник: http://securityresponse.symantec.com/avcenter/venc/data/trojan.webus.html

Backdoor.Hale

Технически детали
...A harmless text file. Csrss.exe: a Backdoor Trojan Horse detected...
..."NTDLM" = "c:winntsystem32qossrvcsrss.exe" to the registry key:...
...NTS (Secure.exe) NTP (Csrss.exe) NOTE:...
...C:WinntSystem32dhcp: Csrsslsrms.dll: A text file, not a dll....
...C:WinntSystem32 estore: Csrss.exe: Detected as Backdoor.Padmin....
Инструкции удаления
..."NTDLM"="c:winntsystem32qossrvcsrss.exe" Navigate to the key:...
Источник: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.hale.html

Spyware.LoverSpy

Технически детали
...%Windir%Rec_pwd.html %System%ShellExtCsrss.exe Notes:...
Инструкции удаления
...%Windir%Rec_pwd.html %System%ShellExtCsrss.exe Write-up by:...
Источник: http://securityresponse.symantec.com/avcenter/venc/data/spyware.loverspy.html

W32.Ahlem.A@mm

Технически детали
...Create a copy of the worm as %Windir%Csrss.exe. NOTE: %Windir% is a variable....
..."SYSTEMSars32"="%Windir%csrss.exe" to the registry key:...
Инструкции удаления
..."SYSTEMSars32"="%windir%csrss.exe" Exit the Registry Editor....
Источник: http://securityresponse.symantec.com/avcenter/venc/data/w32.ahlem.a@mm.html

Backdoor.Stanex

Технически детали
...%Windir%systemSysTray.exe. %Windir%TEMPCSRSS.exe %Windir%systemCSRSS.exe...
...Windows 95/98/Me: %Windir%system32CSRSS.exe. On Windows 95/98/Me, the Trojan...
Источник: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.stanex.html

Trojan.Gutta

Технически детали
...Copies itself as C:WindowsCSRSS.exe. This path is hard-coded and...
..."rundll32" = "windowscsrss.exe" in the registry key:...
Инструкции удаления
..."rundll32"="C:WindowsCSRSS.exe" Exit the Registry Editor....
Источник: http://securityresponse.symantec.com/avcenter/venc/data/trojan.gutta.html

W32.Sndog@mm

Технически детали
...Copies itself to %windir%csrss.exe as a hidden file. Note: %Windir% is a variable...
..."Shockwave" = "%windir%csrss.exe" to the registry key:...
Инструкции удаления
..."Shockwave" = "%windir%csrss.exe" Exit the Registry Editor....
Источник: http://securityresponse.symantec.com/avcenter/venc/data/w32.sndog@mm.html

W32.Nimda.E@mm

Технически детали
...The worm now copies itself to the \%Windows% folder as Csrss.exe instead of Mmc.exe NOTE: %Windows% is a variable....
Источник: http://securityresponse.symantec.com/avcenter/venc/data/w32.nimda.e@mm.html

Backdoor.Sokacaps

Технически детали
...Creates the files: C:windowsmediacsrss.exe C:windowsmediacsrss.uzy...
..."RegWrite"="c:windowsmediacsrss.exe" to the registry key:...
Инструкции удаления
...Scroll through the list and look for Csrss.uzy. If you find the file, click...
..."RegWrite"="c:windowsmediacsrss.exe" Exit the Registry Editor....
......
Источник: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sokacaps.html



Valid HTML 4.01!