PRocesses: A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 0 1 2 3 4 5 6 7 8 9
Dlls: A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 0 1 2 3 4 5 6 7 8 9
Popular: svchost.exe | csrss.exe | rthdcpl.exe | spoolsv.exe | mrt.exe | lsass.exe | Home | Manufacturers | Top 1000

csrss.exe

What does the csrss.exe process do?

What is the purpose of the csrss.exe (Client/Server Runtime Server Subsystem) on Windows?

Maybe someone could give a good explanation or pointers to documentation? Unfortunately Google results are pretty noisy when searching a core process of Windows.

The reason I'm asking is that I got a BSOD from my service application which seems to be related to the csrss.exe process, at least this is what the analysis of the memory dump shows:

PROCESS_OBJECT: 85eeeb70

IMAGE_NAME: csrss.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: csrss
FAULTING_MODULE: 00000000
PROCESS_NAME: PreviewService.
BUGCHECK_STR: 0xF4_PreviewService.
DEFAULT_BUCKET_ID: DRIVER_FAULT
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 80998221 to 80876b40

STACK_TEXT:
f5175d00 80998221 000000f4 00000003 85eeeb70 nt!KeBugCheckEx+0x1b
f5175d24 8095b1be 8095b1fa 85eeeb70 85eeecd4 nt!PspCatchCriticalBreak+0x75
f5175d54 8082350b 00000494 ffffffff 051bf114 nt!NtTerminateProcess+0x7a
f5175d54 7c8285ec 00000494 ffffffff 051bf114 nt!KiFastCallEntry+0xf8
051bf114 00000000 00000000 00000000 00000000 ntdll!KiFastSystemCallRet

STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
FAILURE_BUCKET_ID: 0xF4_PreviewService._IMAGE_csrss.exe
BUCKET_ID: 0xF4_PreviewService._IMAGE_csrss.exe

Followup: MachineOwner


EDIT: Thanks already for the good answers, but I actually don't need help concerning my service, I just would like to get some basic understanding of what the purpose of this service is.

View Complete Forum Thread with Replies

Related posts for csrss.exe

See Related Forum Messages: Follow the Links Below to View Complete Thread

Is it possible to get the “Image Path Name” of csrss.exe which is a SYSTEM process?
Hunting down application errors coming from csrss.exe
batch or vbs forced BSOD
Is there a way to inject behavior to csrss.exe and modify/enhance windows console?
make a windows 7 machine crash on BSOD
What does the csrss.exe process do?
is ??c:windows path legitimate

csrss.exe: Is it possible to get the “Image Path Name” of csrss.exe which is a SYSTEM process?

The windows system process (in Windows 7 for this example) 'csrss.exe' runs as a SYSTEM process and when I go to get (programmatically, of course) the process list with pid, command line, and image path name I get no values for command line or image path name because Windows won't let you grab that information for a SYSTEM process (I believe).

Is there a way I can grab image path name from a SYSTEM process? Does Windows actually prevent you from doing this? Is there a workaround?

U

csrss.exe: Hunting down application errors coming from csrss.exe

I'm the maintainer of a legacy Delphi application. On machines running this program an Application Error appears sometimes with the caption referring to this Delphi app and a message like the following:


The instruction at '...' referenced memory at '...'. The memory could not be 'read'.

Click on OK to terminate the program.


Task Manager says the process belonging to this message box is csrss.exe. What would be a systematic way to find the root cause of this e

csrss.exe: batch or vbs forced BSOD

Is there a way is batch or vbs to force the blue screen of death to appear, or a forced crash. This can happen from stopping the process 'csrss.exe' but it wont close via simple batch or vbs script. How can this be done?

csrss.exe: Is there a way to inject behavior to csrss.exe and modify/enhance windows console?

I'm aware of Console2 and similar solutions, but I would really like to enhance every console window in my system. Any ideas?

csrss.exe: make a windows 7 machine crash on BSOD

I'm trying to write a windows debug utility and I would need to automatically crash a Windows machine and make a Blue Screen Of Death appear.

I can obviously kill the csrss.exe process from the task manager, but the command TASKKILL /F /IM csrss.exe in a .bat file doesn't work.

Is there another way to make a Windows machine crash on bsod? Maybe some external library able to kill any process.

I would prefer to use a command line approach since I'm more familiar with it.

csrss.exe: What does the csrss.exe process do?

What is the purpose of the csrss.exe (Client/Server Runtime Server Subsystem) on Windows?

Maybe someone could give a good explanation or pointers to documentation? Unfortunately Google results are pretty noisy when searching a core process of Windows.

The reason I'm asking is that I got a BSOD from my service application which seems to be related to the csrss.exe process, at least this is what the analysis of the memory dump shows:

PROCESS_OBJECT: 85eeeb70

IMAGE_NAME

csrss.exe: is ??c:windows path legitimate

I am going to check loading and memory path of process to find malicious processes. for example if csrss.exe is executaed from other path than windows/system32 would be considered malicious. But the result of volatility for common process such as csrss.exe is as follow:

loading path : ??C:WINDOWSsystem32csrss.exe

mapped path : WINDOWSsystem32csrss.exe

or for sms.exe I have

loading path : SystemRootSystem32smss.exe

mapped path : WINDOWSsystem32smss.

regedit.exe: How to detect Java is installed via REGEDIT.exe from a batch file?

I am looking for a batch file snippet that somehow reads the Windows registry and detects which Java JDK is on a Windows system and then asks the user which one they want to use and remembers the choice.

Here is what I have so far... needs some modifications. This script only finds the first JDK... it doesn't handle multiples.

@echo off
SETLOCAL EnableDelayedExpansion
:: findJDK.bat
start /w regedit /e reg1.txt 'HKEY_LOCAL_MACHINESOFTWAREJavaSoftJava Development Kit'

sqlservr.exe: Detecting SqlServr.exe WriteFile Operation Within C#

There's a requirement that we will need to support querying a local SQL Server database for new data when the database is updated. Since these are external SQL Server databases, we may not be able to use SQL Server Notification Services nor can we make any changes to the database.

My basic idea is to watch for data being written to the database to trigger a query (instead of polling at set intervals). However, I'm having a tough time trying to figure out how I could get the WriteFile

googleearth.exe: How to get the path of an unrelated file with java?

I'm running a program that needs to open Google Earth at some point, and I need it's path to open it. Is there any way to get googleearth.exe absolute path from my code (if it's installed in the computer) without having to reach it using a jfilechooser or some sort of file chooser?

Thanks!

totalcmd.exe: c# open folder in C:Windowssystem32 via total-commander

I have a little problem with opening windows system folder using total-commander
When i run command manually in cmd itīs ok, but when it runs as ProcessStartInfo not.
This problem happens on Windows XP, Windows 7 argument (path) is a little bit different but working.

ProcessStartInfo startInfo = new ProcessStartInfo(); //New Proccess
startInfo.Arguments = '/L=' + GetArgument(); //Return C:WINDOWSsystem32configsystemprofileLocal SettingsApplication ataMyApp

wmiprvse.exe: WMIPRVSE needs to be run under network services by default

I have 2 separate servers (windows server 2008 r2) from where I am running vbs scripts through a microsoft scheduler ( my-computer>manager>Schedule). when I run vbs scripts locally they are working fine, but when it is being run through scheduler one of servers is getting stacked. while the other is working fine. And also I have noticed from task manager that the working server runs the WMIPRVSE.exe though Network Service user and the other one shows SERVICES as user.

How to make sure t

notepad.exe: Launch notepad.exe from a PHP file

In an attempt to simplify a problem I am having running a batch file from within PHP on a WAMP windows XP system I am trying to launch notepad.exe from a PHP file. I have a PHP file containing....

<?php
exec('c:windows otepad.exe');
?>


When I run the PHP file I can see the notepad.exe process start in the task manager but notepad itself does not open. What am I doing wrong?

igfxtray.exe: how to get specific column from REG QUERY?

c:>REG QUERY HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun
XSENZ REG_SZ C:Windowssyswow64XSENZ.EXE
Persistence REG_SZ C:windowssystem32igfxpers.exe
IntelliPoint REG_SZ 'c:Program FilesMicrosoft IntelliPointipoint.exe'
IgfxTray REG_SZ C:windowssystem32igfxtray.exe
HotKeysCmds REG_SZ C:windowssystem32hkcmd.exe


I want to get only first column. Can anyone suggest an answer?

consent.exe: “Send to” a folder over to a batch script not behaving as expected

I have a simple batch script take.cmd

echo %1


I've then created a shortcut to it in the C:UsersabcAppDataRoamingMicrosoftWindowsSendTo folder. Specifically the shortcut and not the batch script itself so that I can run it as admin (right click > properties > advanced > Run as administrator).

Now when I right click a folder and Send To it to the shortcut I've created it prompts the consent.exe asking for permission as expected but then instead of running the batch script

msdtc.exe: How should MSDTC be configured to use SSL with Websphere MQ when coordinating a distributed …

We have a process that uses a number of resources to perform a complete operation.

When the process is not configured to use a distributed transaction using MSDTC the operation completes.

When the process is configured to use a distributed transaction using MSDTC the operation does not complete. MSDTC throws the following exception that indicates that MSDTC cannot connect via SSL.

Log Name: Application
Source: WebSphere MQ (Installation1)
Date: 1

werfault.exe: Getting crash information from event log, without need to press “close program” when program…

I have a very weird problem, when my application e.g. internet explorer crashes. WerFault.exe pops up to inform about the crash at the same point of time a 'crash' log is recorded in Event Viewer > Application in windows. However unless i press 'close program' more information about the particular crash is not generated in the application event log. How do i automatically make WerFault create the necessary crash dump information without needing to physically click 'Close Program'. I am doing pyt

Disclaimer
This web site and all information written here is for information purposes only, WITHOUT ANY VARANTY. YOU ARE USING THIS PAGES ON YOU OWN RISK. You should always verify the accuracy of information provided on this page. We pay a big attention to provide you with the correct information. However, many spyware and malware programs use filenames of usual, non-malware processes and DLLs. If we have included information about csrss.exe that is inaccurate, we would appreciate your help by getting us know about your user review. Also, web links to software and DLL vendors are provided just for your conform, and we cannot guarantee its accuracy nor relevance with DLL or process listed on this page. We are not affiliated with this pages. We are not responsible for misprints on this site or changes occured since this page was published. The product, software and operating system names mentioned on this web site, can be copyrighted and registered trademarks of their owners.

csrss.exe