How to remove csrss.exe
csrss.exe
The module csrss.exe has been detected as Ransom.Wacatac
File Details
| Product Name: | GoldenEgg |
| MD5: | 95e0b6919792bd01cee49650814215b8 |
| Size: | 4 MB |
| First Published: | 2023-07-07 23:20:50 (2 years ago) |
| Latest Published: | 2023-07-11 23:12:07 (2 years ago) |
| Status: | Ransom.Wacatac (on last analysis) | |
| Analysis Date: | 2023-07-11 23:12:07 (2 years ago) |
Overview
| Signed By: | 522a1720000d011b430433013e102d3427142b4024102b2a13264116170e10372429 |
| Status: | Valid |
Common Places:
| %windir% |
| %windir% |
| %localappdata%\microsoft\windows\inetcache\ie |
Geography:
| 100.0% |
OS Version:
| Windows 10 | 100.0% |
Analysis
| Subsystem: | Windows GUI |
| PE Type: | pe |
| OS Bitness: | 32 |
| Image Base: | 0x00400000 |
| Entry Address: | 0x00004437 |
PE Sections:
| Name | Size of data | MD5 |
| .text | 4229632 | f7d3de522727c53e4f89bb9c8ad96876 |
| .data | 7168 | a4afdbaaed6b79eb55b5ddaeab29f3d1 |
| .rsrc | 71680 | 43d81ec31fa380db4ae6cf828f187378 |
| .reloc | 17408 | b1de55b9e8a1c26c16b08d6536f099ad |
More information:
Download GridinSoft
Anti-Malware - Removal tool for csrss.exe