csrss.exe

Lugged Mistrusts Miner

Maltreatment Lagged Opportunism

The executable csrss.exe, “Illustrations Mailer Inquisitorial” has been detected as malware by 21 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Client Server Runtime Process’.
Publisher:
Maltreatment Lagged Opportunism

Product:
Lugged Mistrusts Miner

Description:
Illustrations Mailer Inquisitorial

Version:
59.81.56.66

MD5:
b625bc2dad85c883dc8385a57fec8c3c

SHA-1:
157b3969e6e94210a2ec66ff91160ce22f38bd84

Scanner detections:
21 / 68

Status:
Malware

Analysis date:
4/26/2024 10:52:14 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1991641
801

AhnLab V3 Security
Trojan/Win32.MDA
2014.11.27

Avira AntiVirus
TR/Soperu.A.10
7.11.188.246

avast!
Win32:Malware-gen
2014.9-141126

AVG
MSIL5
2015.0.3279

Baidu Antivirus
Trojan.Win32.Fsysna
4.0.3.141126

Bitdefender
Trojan.GenericKD.1991641
1.0.20.1650

Dr.Web
BackDoor.Andromeda.559
9.0.1.0330

Emsisoft Anti-Malware
Trojan.GenericKD.1991641
8.14.11.26.10

ESET NOD32
MSIL/Injector.GLU (variant)
8.10783

Fortinet FortiGate
MSIL/GLU!tr
11/26/2014

G Data
Trojan.GenericKD.1991641
14.11.24

IKARUS anti.virus
Trojan.MSIL.Injector
t3scan.1.8.3.0

K7 AntiVirus
Trojan
13.185.14134

Kaspersky
Trojan.Win32.Fsysna
14.0.0.2888

McAfee
Artemis!B625BC2DAD85
5600.6935

NANO AntiVirus
Trojan.Win32.Fsysna.djhlss
0.28.6.63726

nProtect
Trojan.GenericKD.1991641
14.11.26.01

Panda Antivirus
Trj/CI.A
14.11.26.10

Trend Micro House Call
TROJ_SPNV.01KP14
7.2.330

Trend Micro
TROJ_SPNV.01KP14
10.465.26

File size:
49 KB (50,176 bytes)

Product version:
59.81.56.66

Copyright:
Minimising Outstep Liquidising

Trademarks:
Monitor Lavatorial Mooted

Original file name:
Overlap.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Application data\csrss.exe

File PE Metadata
Compilation timestamp:
11/24/2014 12:25:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:O9tDk7gdKhKR1LOwiqGUJu753ajoT9elY98ySsT8qODhw0O:O87JmiqGAu75p8Dy5Udw0O

Entry address:
0xD72E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3924

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
46 KB (47,104 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Client Server Runtime Process

Command:
C:\Documents and Settings\{user}\Application data\csrss.exe


Remove csrss.exe - Powered by Reason Core Security