cssrs.exe - Dangerous
cssrs.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
This is memory-resident worm. It drops and executes a copy of itself as the file CSSRS.EXE.
It takes advantage of the following system vulnerabilities:
DCOM RPC vulnerability using TCP port 135
RPC Locator vulnerability using TCP port 445
WebDav vulnerability using TCP port 80
Attempt to gain access to specific shared folders on the network using a predefined list of user names and passwords.
Connect to an IRC channel and listens for commands from a remote user.
Allow the malicious user to perform several tasks on a damage system.
Terminate antivirus processes, firewall programs, and system tools. It runs on Windows NT, 2000, and XP.
Manual removal:
Delete this keys:
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>CurrentVersion>Run
WinFX = "cssrs.exe"
Display Drivers = "cssrs.exe"
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>CurrentVersion>RunServices
In the right panel, locate and delete the entry:
WinFX = "cssrs.exe"
Display Drivers = "cssrs.exe"
HKEY_LOCAL_MACHINE>System>CurrentControlSet>Services>Driver
Also download and install the critical patches from the Microsoft site:
Microsoft Security Bulletin MS03-026
Microsoft Security Bulletin MS03-001
Microsoft Security Bulletin MS03-007
Automatic removal: Use RegRun Startup Optimizer to remove it from startup.