csrss.exe

Client Server Runtime Process

ABDULKADIR SAHIN

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application csrss.exe, “Client Server Runtime Process” by ABDULKADIR SAHIN has been detected as adware by 14 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘csrss’.
Publisher:
Microsoft Corporation  (signed by ABDULKADIR SAHIN)

Product:
Microsoft® Windows® Operating System

Description:
Client Server Runtime Process

Version:
6.1.7600.16385

MD5:
7aeb1ca702da0300ef7754527295903a

SHA-1:
1108268fdbfe4dda7da06d59f8d33e0e6de81090

SHA-256:
bc6b4b7c588c06e5a3202e363f2619f02969e76275152652d06b04f19b53f8fd

Scanner detections:
14 / 68

Status:
Adware

Analysis date:
4/26/2024 6:04:44 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1487407
1118

AhnLab V3 Security
Trojan/Win32.Agent
2014.01.07

Bitdefender
Trojan.GenericKD.1487407
1.0.20.60

Emsisoft Anti-Malware
Trojan.GenericKD.1487407
8.14.01.12.06

G Data
Trojan.GenericKD.1487407
14.1.22

IKARUS anti.virus
Trojan.Msil
t3scan.2.2.29

K7 AntiVirus
Trojan
13.175.10750

Kaspersky
Trojan.MSIL.StartPage
14.0.0.4476

Malwarebytes
Trojan.FakeMS
v2014.01.12.06

McAfee
Artemis!7AEB1CA702DA
5600.7252

MicroWorld eScan
Trojan.GenericKD.1487407
15.0.0.36

Reason Heuristics
PUP.Startup.ABDULKADIRSAHIN.F
14.7.3.9

Sophos
Mal/Generic-S
4.96

XVirus List
Win32.Detected
2.7.3

File size:
106.3 KB (108,880 bytes)

Product version:
6.1.7600.16385

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
csrss.exe

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

Common path:
C:\ProgramData\csrss.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/18/2013 2:00:00 AM

Valid to:
3/20/2014 1:59:59 AM

Subject:
CN=ABDULKADIR SAHIN, OU=Individual Developer, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=No Organization Affiliation, L=ANKARA, S=KECIOREN, C=TR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
516CAE126302D8B129C8550A077CDF6F

File PE Metadata
Compilation timestamp:
12/20/2013 3:23:40 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:BnMndTMJdG2aJZRCwaqIu57D+u1fxIM/vbh9MJ+GEMj+3fF6mSNssU9jm8kdBH3K:BMdQdQrZJ3d6C9jQBUlzL

Entry address:
0x1A11E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
96.5 KB (98,816 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
csrss

Command:
C:\ProgramData\csrss.exe


Remove csrss.exe - Powered by Reason Core Security