Solved! Use CSSRSS.EXE (Trojan Agent) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

CSSRSS.EXE – Trojan Agent removal

File MD5 Virus Alias
CSSRSS.EXE 0276a878a5ef7a60ad4d8e7e3604eddc Trojan Agent
CSSRSS.EXE 0276a878a5ef7a60ad4d8e7e3604eddc Trojan Artemis
CSSRSS.EXE 0276a878a5ef7a60ad4d8e7e3604eddc Trojan XPACK
CSSRSS.EXE 0276a878a5ef7a60ad4d8e7e3604eddc Trojan Generic
CSSRSS.EXE 0276a878a5ef7a60ad4d8e7e3604eddc Trojan Downloader
CSSRSS.EXE 0276a878a5ef7a60ad4d8e7e3604eddc Trojan Crypt

CSSRSS.EXE size: 37376 bytes
CSSRSS.EXE hash: 0276A878A5EF7A60AD4D8E7E3604EDDC

Created files:

%SysDir%\cssrss.exe
%SysDir%\drivers\ac97intc.sys
%SysDir%\drivers\ACPI.sys
%SysDir%\drivers\aec.sys
%SysDir%\drivers\asyncmac.sys
%SysDir%\drivers\atapi.sys
%SysDir%\drivers\atmarpc.sys
%SysDir%\drivers\audstub.sys
%SysDir%\drivers\cdrom.sys
%SysDir%\drivers\CmBatt.sys
%SysDir%\drivers\compbatt.sys
%SysDir%\drivers\disk.sys
%SysDir%\drivers\dmboot.sys
%SysDir%\drivers\dmio.sys
%SysDir%\drivers\dmload.sys
%SysDir%\drivers\DMusic.sys
%SysDir%\drivers\drmkaud.sys
%SysDir%\drivers\fltMgr.sys
%SysDir%\drivers\ftdisk.sys
%SysDir%\drivers\hidusb.sys
%SysDir%\drivers\HTTP.sys
%SysDir%\drivers\i8042prt.sys
%SysDir%\drivers\imapi.sys
%SysDir%\drivers\intelide.sys
%SysDir%\drivers\Ip6Fw.sys
%SysDir%\drivers\ipfltdrv.sys
%SysDir%\drivers\ipinip.sys
%SysDir%\drivers\ipnat.sys
%SysDir%\drivers\ipsec.sys
%SysDir%\drivers\irenum.sys
%SysDir%\drivers\isapnp.sys
%SysDir%\drivers\kbdclass.sys
%SysDir%\drivers\kmixer.sys
%SysDir%\drivers\mouclass.sys
%SysDir%\drivers\mouhid.sys
%SysDir%\drivers\mrxdav.sys
%SysDir%\drivers\mrxsmb.sys
%SysDir%\drivers\msgpc.sys
%SysDir%\drivers\MSKSSRV.sys
%SysDir%\drivers\MSPCLOCK.sys
%SysDir%\drivers\MSPQM.sys
%SysDir%\drivers\mssmbios.sys
%SysDir%\drivers\ndistapi.sys
%SysDir%\drivers\ndisuio.sys
%SysDir%\drivers\ndiswan.sys
%SysDir%\drivers\netbios.sys
%SysDir%\drivers\netbt.sys
%SysDir%\drivers\nwlnkflt.sys
%SysDir%\drivers\nwlnkfwd.sys
%SysDir%\drivers\parport.sys
%SysDir%\drivers\pci.sys
%SysDir%\drivers\pcntpci5.sys
%SysDir%\drivers\psched.sys
%SysDir%\drivers\ptilink.sys
%SysDir%\drivers\rasacd.sys
%SysDir%\drivers\rasl2tp.sys
%SysDir%\drivers\raspppoe.sys
%SysDir%\drivers\raspptp.sys
%SysDir%\drivers\raspti.sys
%SysDir%\drivers\rdbss.sys
%SysDir%\drivers\rdpdr.sys
%SysDir%\drivers\redbook.sys
%SysDir%\drivers\secdrv.sys
%SysDir%\drivers\splitter.sys
%SysDir%\drivers\srv.sys
%SysDir%\drivers\swenum.sys
%SysDir%\drivers\swmidi.sys
%SysDir%\drivers\sysaudio.sys
%SysDir%\drivers\tcpip.sys
%SysDir%\drivers\termdd.sys
%SysDir%\drivers\update.sys
%SysDir%\drivers\usbhub.sys
%SysDir%\drivers\usbohci.sys
%SysDir%\drivers\VBoxGuest.sys
%SysDir%\drivers\VBoxMouse.sys
%SysDir%\drivers\VBoxSF.sys
%SysDir%\drivers\VBoxVideo.sys
%SysDir%\drivers\wanarp.sys
%SysDir%\drivers\wdmaud.sys
%SysDir%\mnmsrvc.exe
%SysDir%\msdtc.exe
%SysDir%\sessmgr.exe
%SysDir%\tlntsvr.exe
%SysDir%\VBoxService.exe
%SysDir%\Vw393S.syz
%SysDir%\wbem\wmiapsrv.exe

Detected by UnHackMe:

CSSRSS.EXE
Default location: %SYSDIR%\CSSRSS.EXE

Dropper information:
MD5: 0276a878a5ef7a60ad4d8e7e3604eddc
File size: 37376 bytes

Leave a Reply