Computing.Net > Forums > Windows XP > csrss.exe Trojan csrss386.exe

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Click here to start participating now! Also, check out the New User Guide.

csrss.exe Trojan csrss386.exe

Reply to Message Icon

Name: muarrij
Date: November 26, 2004 at 03:38:08 Pacific
OS: Windows
CPU/Ram: 1
Comment:

CSRSS.exe is indeed an MS process. However it is also a trojan. One form of this trojan installs a client that looks up its server and advertises an "Anti Spyware" message through Messenger. (Not to be confused with MSN Messenger or Windows Messenger).
CSRSS386.exe is definitely a spyware executable as far as I can tell.

The best way to determine whether you have spyware is to stick on a firewall like Zonealarm which should tell you what programs are trying to reach the internet.

In order to eliminate the threat of spyware, either use an anti spyware program like Ad-Aware or filter through your drives and registry searching for keywords like csrss.exe etc.

Be careful not to delete valid keys from your registry otherwise you will courrupt your OS and your pc will probably end up doing all sorts of weird things like autoshutdowns and BSD.



Sponsored Link
Ads by Google

Response Number 1
Name: gadfly
Date: November 30, 2004 at 21:41:04 Pacific
Reply:

csrss386.exe is similar to W32.IRCBot.D (http://securityresponse.symantec.com/avcenter/venc/data/w32.ircbot.d.html). We saw this on 2 of our machines last week (11/23/2004) and was unable to find any info on it (absolutely 0 Google hits, nothing at Symantec). It does the following:

1) adds itself to various Run keys in the registry (search the registry for csrss386.exe) (see link above)
2) scans the network for servers on port 445 (microsoft-ds), I assume so it can spread itself via Windows sharing
3) deletes the admin shares (see link above)

To fix: find the exe and rename it to *.old, and remove the Run keys from the registry. At least this fixed it for us.


0

Response Number 2
Name: gadfly
Date: November 30, 2004 at 21:42:51 Pacific
Reply:

... and to restore the admin shares, either restart, or run the following:

net share c$
net share ipc$
net share admin$


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


Incoming tcp connections internet explorer exits t...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Sponsored links

Ads by Google


Results for: csrss.exe Trojan csrss386.exe

belt.exe trojan virus www.computing.net/answers/windows-xp/beltexe-trojan-virus/89459.html

Trojan netdc.exe st.exe www.computing.net/answers/windows-xp/trojan-netdcexe-stexe/112969.html

Trojan - Belt.exe. www.computing.net/answers/windows-xp/trojan-beltexe/84669.html