csrss.exe - Dangerous

%windir%\system\csrss.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

%windir%\system\csrss.exe
I-Worm.Netsky.ac
This worm spreads via the Internet as an attachment to infected messages, and via shared network resources.

Characteristics of infected messages:
Message header, body and attachment name (with .pif extension) are chosen at random from predefined list.
The worm uses a direct connection to the SMTP-server to send messages.

The wom copies itself to the Windows directory under the name csrss.exe
and registers this file in the system registry auto-run key:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\BagleAV
thus attempting to disguise itself as an antivirus working against Bagle.

Also, the worm attempts to delete registry keys created by I-Worm.Bagle.y

Automatic removal:
Use RegRun Startup Optimizer to delete this worm from your machine.

Remove csrss.exe now!