Windows Tips, Help & Tutorials

Current Topic:
Malware Information


Malware Information

Malware Information


» Malware | Malware Videos «


Is or can csrss.exe be malware?

Question: Is or can csrss.exe be malware?

(Posted by: Gregory O on 2010-03-06 11:17:19)

Can a altered form of this be malware?


Answers:

Posted by: R on 2010-03-06, 11:26:13

Yes, for example if it is not located in the usual place (C:\Windows\System32\csrss.exe) then that should raise a red flag. Also, if it is named something slightly different from the original name like Csrss.exe or csrsss.exe that is suspicious as well. There is a CSRSS.EXE that is a worm. I would upload it to VirusTotal to check against multiple engines if I were you.

  

Posted by: zep516 on 2010-03-06, 12:38:06

What is it? csrss.exe - Client/ Server Runtime Server Subsystem What does it do? This is the user-mode portion of the Win32 subsystem (with Win32.sys being the kernel-mode portion). Csrss stands for client/ server run-time subsystem and is an essential subsystem that must be running at all times. Csrss is responsible for console windows, creating and/ or deleting threads, and some parts of the 16-bit virtual MS-DOS environment. It needs to be in the System 32 folder, anywhere else is a worm. As mentioned above...

  

Powered by Yahoo! Answers®


Back to Previous page

» Malware | Malware Videos «

Friends and Other Interesting Sites    
  1. Medical Issues
  2. Soccer Fanatic
  3. Nascar Racing Video
  4. Windows Tips
  5. Wine For Beginners
  6. The Best Of Them
  1. Election Videos
  2. Moto GP Videos
  3. Twitter Videoclips
  4. My Web Hosting Manual
  5. Search All Torrents
  6. Big Lawyer List
  1. The Blog Nut
  2. My Super Heroes
  3. Obesity Mall
  4. Games Town
  5. Plastic Surgeon Locator
  6. Find A Local Golf Course
Sitemap | Contact

© copyright 2008 - 2009 WinTips, All Rights Reserved.

Legal Notice: This website is powered by Amazon®, Adsense™, Yahoo!® Answers and Youtube™.
All trademarks are copyrighted by their respective owners.