csrss.exe

The executable csrss.exe has been detected as malware by 25 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘acmon’.
MD5:
8313f8d8240e673d20ed4a35e38cd6ed

SHA-1:
0668bc4ca2f64ee5d95045393f6d8af9118f899a

SHA-256:
45a67cd64bb79651cdcc78316e0bf8c223050fcee53d51a8317f77e06cdd7f1d

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
4/27/2024 1:00:04 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.504589
795

Agnitum Outpost
Trojan.FKM
7.1.1

Avira AntiVirus
TR/Crypt.FKM.Gen
7.11.189.196

avast!
Win32:Malware-gen
2014.9-141201

AVG
Generic11_c
2015.0.3256

Bitdefender
Gen:Variant.Kazy.504589
1.0.20.1675

Emsisoft Anti-Malware
Gen:Variant.Kazy.504589
9.0.0.4668

ESET NOD32
Win32/TrojanClicker.VB.OGE trojan
7.0.302.0

Fortinet FortiGate
W32/Swisyn.FKRJ!tr
12/19/2014

F-Prot
W32/Trojan2.OGIZ (exact, not disinfectable)
4.6.5.141

F-Secure
Gen:Variant.Kazy.504589
11.2014-01-12_2

G Data
Gen:Variant.Kazy.504589
14.12.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.3.0

K7 AntiVirus
Trojan
13.186.14198

Kaspersky
Trojan.Win32.Swisyn
14.0.0.2775

McAfee
Artemis!DA3F764CB8B2
5600.6929

MicroWorld eScan
Gen:Variant.Kazy.504589
15.0.0.1005

NANO AntiVirus
Trojan.Win32.Swisyn.djezes
0.28.6.64267

nProtect
Trojan.Generic.12284109
14.12.15.01

Qihoo 360 Security
HEUR/QVM11.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.19.0

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
Suspici.A51421B4
7.2.335

VIPRE Antivirus
Trojan.Win32.Generic
35766

Zillya! Antivirus
Trojan.Agent.Win32.457387
2.0.0.1997

File size:
1.1 MB (1,103,426 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\csrss.exe

File PE Metadata
Compilation timestamp:
11/24/2014 1:06:46 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:oUWCMbry/nCqtwdApC8nyi26bw5yL7qBhGOKxt3tN0ctE42rV7qC/:x5tKApC8lnw5GiZQ3tNnG42rsC/

Entry address:
0x1101C

Entry point:
E8, 0F, 65, 00, 00, E9, 78, FE, FF, FF, 55, 8B, EC, 83, EC, 04, 89, 7D, FC, 8B, 7D, 08, 8B, 4D, 0C, C1, E9, 07, 66, 0F, EF, C0, EB, 08, 8D, A4, 24, 00, 00, 00, 00, 90, 66, 0F, 7F, 07, 66, 0F, 7F, 47, 10, 66, 0F, 7F, 47, 20, 66, 0F, 7F, 47, 30, 66, 0F, 7F, 47, 40, 66, 0F, 7F, 47, 50, 66, 0F, 7F, 47, 60, 66, 0F, 7F, 47, 70, 8D, BF, 80, 00, 00, 00, 49, 75, D0, 8B, 7D, FC, 8B, E5, 5D, C3, 55, 8B, EC, 83, EC, 10, 89, 7D, FC, 8B, 45, 08, 99, 8B, F8, 33, FA, 2B, FA, 83, E7, 0F, 33, FA, 2B, FA, 85, FF, 75, 3C, 8B...
 
[+]

Entropy:
7.8971  (probably packed)

Code size:
112 KB (114,688 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
acmon

Command:
C:\users\{user}\appdata\local\temp\{random}.tmp\csrss.exe


Remove csrss.exe - Powered by Reason Core Security