CSRSS.EXE – Worm Brontok

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CSRSS.EXE – Worm Brontok removal

FileMD5Virus Alias
CSRSS.EXE 391d82aa0fa1c9638a917c19194aa58a Worm Brontok
CSRSS.EXE 391d82aa0fa1c9638a917c19194aa58a Trojan Agent

CSRSS.EXE size: 45523 bytes
CSRSS.EXE hash: 391D82AA0FA1C9638A917C19194AA58A

Created files:

%WinDir%\KesenjanganSosial.exe
%WinDir%\ShellNew\RakyatKelaparan.exe
%SysDir%\cmd-brontok.exe
%UserProfile%\Local Settings\Application Data\br5205on.exe
%UserProfile%\Local Settings\Application Data\csrss.exe
%UserProfile%\Local Settings\Application Data\inetinfo.exe
%UserProfile%\Local Settings\Application Data\lsass.exe
%UserProfile%\Local Settings\Application Data\services.exe
%UserProfile%\Local Settings\Application Data\smss.exe
%UserProfile%\Local Settings\Application Data\svchost.exe
%SysDir%\msvbvm60.dll

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\run\Bron-Spizaetus: “%WinDir%\ShellNew\RakyatKelaparan.exe”
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe “%WinDir%\KesenjanganSosial.exe”
HKCU\Software\Microsoft\Windows\CurrentVersion\run\Tok-Cirrhatus-2091: “%Local AppData%\br5205on.exe”

Detected by UnHackMe:

CSRSS.EXE
Default location: %LOCAL APPDATA%\CSRSS.EXE

Dropper information:
MD5: 391d82aa0fa1c9638a917c19194aa58a
File size: 45523 bytes

Leave a Reply