csrss.exe

Daniel Monteiro

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘KernelSys32M’.
Publisher:
Daniel Monteiro  (signed and verified)

MD5:
8f9c92a4cd5cc16af9a6e286d7c3560e

SHA-1:
d0b4d319a4686eb9781ddff106140368c3497d39

SHA-256:
8d4201267f8cd2bd53c368ff8f2a5badcd2d32649e22b9b358bce5395f1b7d61

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/15/2024 1:26:41 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/LogicielsEspions.C potentially unsafe application
8.0.319.0

Sophos
Virus 'Mal/Behav-053'
5.23

File size:
1.6 MB (1,700,608 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/25/2013 12:00:00 AM

Valid to:
2/25/2014 11:59:59 PM

Subject:
CN=Daniel Monteiro, O=Daniel Monteiro, STREET="Condominio Costa Nova. Rua Dois, 601", L=Caraguatatuba, S=SP, PostalCode=11677-000, C=BR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00899BB4D3DAE16CC66EF4EB9C6BBF803E

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:JiWuImTZW5AIJDGUVyWo7sv1IMCrVCAfT2MQrgKNs7kc6GtiN5qq:JEWkrWo7mCcITXAgK6dvtiN5qq

Entry address:
0xDD3A8

Entry point:
55, 8B, EC, 83, C4, F0, B8, 90, CF, 4D, 00, E8, 5C, 9C, F2, FF, A1, 3C, 6D, 4E, 00, 8B, 00, E8, 6C, 34, F8, FF, 8B, 0D, 78, 6E, 4E, 00, A1, 3C, 6D, 4E, 00, 8B, 00, 8B, 15, 0C, 54, 4D, 00, E8, 6C, 34, F8, FF, 8B, 0D, B8, 6E, 4E, 00, A1, 3C, 6D, 4E, 00, 8B, 00, 8B, 15, 9C, F2, 4C, 00, E8, 54, 34, F8, FF, A1, 3C, 6D, 4E, 00, 8B, 00, E8, C8, 34, F8, FF, E8, 2F, 73, F2, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
881.5 KB (902,656 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KernelSys32M

Command:
C:\msc\sp\csrss.exe rke


Scan csrss.exe - Powered by Reason Core Security