Solved! Use CSRSS.EXE (Virus Sality) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

CSRSS.EXE – Virus Sality removal

File MD5 Virus Alias
CSRSS.EXE c8981df5459ea8c86e39b9b4b5c0fc24 Virus Sality
CSRSS.EXE c8981df5459ea8c86e39b9b4b5c0fc24 Trojan Agent

CSRSS.EXE size: 225280 bytes
CSRSS.EXE hash: C8981DF5459EA8C86E39B9B4B5C0FC24

Created files:

%WinDir%\csrss.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Kbltlm samuya\ConnectGroup: ??????
HKLM\System\CurrentControlSet\Services\Kbltlm samuya\MarkTime: 2016-02-09 08:00
HKLM\System\CurrentControlSet\Services\Kbltlm samuya\Type: 10010000
HKLM\System\CurrentControlSet\Services\Kbltlm samuya\Start: 02000000
HKLM\System\CurrentControlSet\Services\Kbltlm samuya\DisplayName: Ekmycs wmikamyk
HKLM\System\CurrentControlSet\Services\Kbltlm samuya\ImagePath: %WinDir%\csrss.exe
HKLM\System\CurrentControlSet\Services\wudfsvc\ReleiceName: Kbltlm samuya

Detected by UnHackMe:

CSRSS.EXE
Default location: %WinDir%\CSRSS.EXE

Dropper information:
MD5: c8981df5459ea8c86e39b9b4b5c0fc24
File size: 225280 bytes

Leave a Reply