Solved! Use CSRSS.EXE (Trojan Downloader) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CSRSS.EXE – Trojan Downloader removal

FileMD5Virus Alias
CSRSS.EXE 3170de7c9e95b178a0d6ccafbe72f236 Trojan Downloader
CSRSS.EXE 3170de7c9e95b178a0d6ccafbe72f236 Trojan Xema
CSRSS.EXE 3170de7c9e95b178a0d6ccafbe72f236 Trojan Eldorado
CSRSS.EXE 3170de7c9e95b178a0d6ccafbe72f236 Trojan Agent

CSRSS.EXE size: 69632 bytes
CSRSS.EXE hash: 3170DE7C9E95B178A0D6CCAFBE72F236

Created files:

C:\windows\1YCERLBZA9.dll
C:\windows\2.3.exe
C:\windows\Config\csrss.exe
C:\windows\system32\MSWINSCK.OCX
%Temp%\NZ3 No-ip.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe %WinDir%\Config\csrss.exe

Detected by UnHackMe:

CSRSS.EXE
Default location: %WinDir%\CONFIG\CSRSS.EXE

Dropper information:
MD5: 2d9cbfeaa7a51c040ab34327dd442ba1
File size: 453082 bytes

Leave a Reply