Startup List Results
Startup Entry
Startup Entry
Name | Filename | Description | Status |
boby | csrs.scr | Troj/Bancban-PC Note: Located in \%WINDIR%\%System%\ Note: Read the link, steals information | X |
Client Server Runtime | csrs.exe | W32/Poebot-KR Note: Read the link, allows remote access | X |
Client Server Runtime Process | csrs.exe | Added by the W32.LINKBOT.M WORM! | X |
Com+ Sys | csrs.exe | Added by the W32/FORBOT-BT WORM! | X |
dark | csrs.scr | Added by TROJ/BANCBAN-GT or TROJ/BANCBAN-GU TROJAN! | X |
O23 List Results
Windows Services
Windows Services
Name | Filename | Description | Status |
Windows Time Sync (wservtime) | csrs.exe | Added by the W32/Tilebot-N WORM! Note: This is not the legitimate Windows Process csrss.exe. (Which is found in the System32 folder.) This worm/trojan file (csrs.exe) is found in the Windows or Winnt folder. Note: Read the link, rootkit type stealth involved. | X |
Active Setup List Results
Active Setup - Installed Component
Active Setup - Installed Component
CLSID | Name | Filename | Description | Status |
{W2L14436-0G2T-JM1T-SO0K-12M4AP2574W4} | (no name) | csrs.exe | Infostealer trojan, detected by Microsoft as Worm:Win32/Rebhip.A - also see here | X |