Should I block it?
No, this file is 100% safe to run.
 
 Additional versions
Additional versions
 
Relationships
Parent processes
Child processes
|  PE file structure
 | Show functions | 
Import table
csrsrv.dll
CsrUnhandledExceptionFilter, CsrServerInitialization
ntdll.dll
RtlSetHeapInformation, RtlSetProcessIsCritical, NtTerminateThread, NtSetInformationProcess, RtlSetUnhandledExceptionFilter, NtTerminateProcess, RtlFreeAnsiString, RtlAllocateHeap, isspace, RtlUnicodeStringToAnsiString, RtlNormalizeProcessParams, DbgBreakPoint, RtlUnhandledExceptionFilter, RtlUnwind, _aullshr
 
     
    
        csrss.exe
Client Server Runtime Process by Microsoft
| Version: | 6.1.7600.16385 (win7_rtm.090713-1255) | 
| MD5: | 342271f6142e7c70805b8a81e1ba5f5c | 
| SHA1: | 53bc9b2ae89fcad6197ec519ae588f926c88e460 | 
| SHA256: | f9112b88fec5ef10a7aedf88dcee61956d1fcde7cb42197216e8265578713786 | 
This is a Windows system installed file with Windows File Protection (WFP) enabled.
What is csrss.exe?
Client/Server Runtime Subsystem, or csrss.exe, is a component of the Microsoft Windows NT operating system that provides the user mode side of the Win32 subsystem and is included in Windows 2000, XP, 2003, Vista, Server 2008 and 7. Because most of the Win32 subsystem operations have been moved to kernel mode drivers, in Windows NT 4 and later CSRSS is mainly responsible for Win32 console handling and GUI shutdown.
About csrss.exe (from Microsoft)
“CSRSS runs as a user-mode system service. When a user-mode process calls a function involving console windows, process/thread creation, or Side-by-Side support, instead of issuing a system call, the W”
 Details
Details
| File name: | csrss.exe | 
| Publisher: | Microsoft Corporation | 
| Product name: | Client Server Runtime Process | 
| Description: | Microsoft® Windows® Operating System | 
| Typical file path: | C:\Windows\System32\csrss.exe | 
| Original name: | CSRSS.Exe.MUI | 
| File version: | 6.1.7600.16385 (win7_rtm.090713-1255) | 
| Product version: | 6.1.7600.16385 | 
| Size: | 6 KB (6,144 bytes) | 
| Digital DNA | 
| Entropy: | 4.291245 | 
| File packed: | No | 
| .NET CLR: | No | 
More details
 Behaviors
Behaviors
Scheduled task
- Entry path '\{1B908455-E233-4AF6-9EA8-FB47FE9E21E2}'
 Resource utilization
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
| CPU | 
| Total CPU: | 0.01111741% |  | 
| Kernel CPU: | 0.00751908% |  | 
| User CPU: | 0.00359833% |  | 
| Kernel CPU time: | 65,888,984 ms/min |  | 
| CPU cycles: | 3,033,609/sec |  | 
| Context switches: | 129/sec |  | 
| Memory | 
| Private memory: | 3.74 MB |  | 
| Private (maximum): | 11.16 MB |  | 
| Private (minimum): | 4.24 MB |  | 
| Non-paged memory: | 3.74 MB |  | 
| Virtual memory: | 89.39 MB |  | 
| Virtual memory (peak): | 141.34 MB |  | 
| Working set: | 7.31 MB |  | 
| Working set (peak): | 15.24 MB |  | 
| Page faults: | 95,934/min |  | 
| I/O | 
| I/O read transfer: | 9.83 KB/sec |  | 
| I/O read operations: | 323/sec |  | 
| I/O other transfer: | 361 Bytes/sec |  | 
| I/O other operations: | 21/sec |  | 
| Resource allocations | 
| Threads: | 11 |  | 
| Handles: | 656 |  | 
| GUI GDI count: | 174 |  | 
| GUI GDI peak: | 236 |  | 
| GUI USER count: | 83 |  | 
| GUI USER peak: | 90 |  | 
 
 Process properties
Process properties
| Integrety level: | System | 
| Platform: | 32-bit | 
| Command lines: | 
%systemroot%\system32\csrss.exe objectdirectory=\windows sharedsection=1024,12288,512 windows=on subsystemtype=windows serverdll=basesrv,1 serverdll=winsrC:userserverdllinitialization,3 serverdll=winsrC:conserverdllinitialization,2 serverdll=sxssrv,4 profilecontrol=off maxrequestthreads=16 | 
| Owner: | SYSTEM | 
| Parent processes: |  | 
 Threads
Threads
Averages
 
| ntdll.dll | 
| Total CPU: | 6.88113089% |  | 
| Kernel CPU: | 6.88113089% |  | 
| User CPU: | 0.00000000% |  | 
| CPU cycles: | 210,149,830/sec |  | 
| Memory: | 1.24 MB |  | 
| kernel32.dll | 
| Total CPU: | 0.73957067% |  | 
| Kernel CPU: | 0.73957067% |  | 
| User CPU: | 0.00000000% |  | 
| CPU cycles: | 17,647,376/sec |  | 
| Context switches: | 23/sec |  | 
| Memory: | 848 KB |  | 
| ADVAPI32.dll | 
| Total CPU: | 0.46094808% |  | 
| Kernel CPU: | 0.46094808% |  | 
| User CPU: | 0.00000000% |  | 
| CPU cycles: | 11,472,831/sec |  | 
| Context switches: | 24/sec |  | 
| Memory: | 640 KB |  | 
| LPK.dll | 
| Total CPU: | 0.13591083% |  | 
| Kernel CPU: | 0.13591083% |  | 
| User CPU: | 0.00000000% |  | 
| CPU cycles: | 4,996,505/sec |  | 
| Context switches: | 12/sec |  | 
| Memory: | 40 KB |  | 
| USP10.dll | 
| Total CPU: | 0.09552189% |  | 
| Kernel CPU: | 0.09552189% |  | 
| User CPU: | 0.00000000% |  | 
| CPU cycles: | 3,765,734/sec |  | 
| Context switches: | 14/sec |  | 
| Memory: | 628 KB |  | 
| sechost.dll | 
| Total CPU: | 0.08451359% |  | 
| Kernel CPU: | 0.08451359% |  | 
| User CPU: | 0.00000000% |  | 
| CPU cycles: | 3,945,815/sec |  | 
| Context switches: | 8/sec |  | 
| Memory: | 100 KB |  | 
| USER32.dll | 
| Total CPU: | 0.08087163% |  | 
| Kernel CPU: | 0.08087163% |  | 
| User CPU: | 0.00000000% |  | 
| CPU cycles: | 3,800,549/sec |  | 
| Context switches: | 6/sec |  | 
| Memory: | 804 KB |  | 
| winsrv.DLL | 
| Total CPU: | 0.07102479% |  | 
| Kernel CPU: | 0.07102479% |  | 
| User CPU: | 0.00000000% |  | 
| CPU cycles: | 3,936,202/sec |  | 
| Context switches: | 82/sec |  | 
| Memory: | 176 KB |  | 
| msvcrt.dll | 
| Total CPU: | 0.05970307% |  | 
| Kernel CPU: | 0.05970307% |  | 
| User CPU: | 0.00000000% |  | 
| CPU cycles: | 2,785,801/sec |  | 
| Context switches: | 7/sec |  | 
| Memory: | 688 KB |  | 
| GDI32.dll | 
| Total CPU: | 0.05059654% |  | 
| Kernel CPU: | 0.05059654% |  | 
| User CPU: | 0.00000000% |  | 
| CPU cycles: | 2,293,666/sec |  | 
| Context switches: | 11/sec |  | 
| Memory: | 312 KB |  | 
| RPCRT4.dll | 
| Total CPU: | 0.04732139% |  | 
| Kernel CPU: | 0.04732139% |  | 
| User CPU: | 0.00000000% |  | 
| CPU cycles: | 2,398,939/sec |  | 
| Context switches: | 8/sec |  | 
| Memory: | 644 KB |  | 
| CSRSRV.dll | 
| Total CPU: | 0.01593108% |  | 
| Kernel CPU: | 0.01189701% |  | 
| User CPU: | 0.00403407% |  | 
| CPU cycles: | 326,184/sec |  | 
| Context switches: | 2/sec |  | 
| Memory: | 52 KB |  | 
 
 Distribution by Windows OS
Distribution by Windows OS
| OS version | distribution | 
| Windows 7 Home Premium | 58.00% |  | 
| Windows 7 Ultimate | 23.00% |  | 
| Windows 7 Professional | 12.00% |  | 
| Windows 7 Home Basic | 5.00% |  | 
| Windows Seven Black Edition | 1.00% |  | 
| Windows Vista Home Premium | 1.00% |  | 
 Distribution by country
Distribution by country
United States installs about 49.49% of Client Server Runtime Process.
 Distribution by PC manufacturer
Distribution by PC manufacturer
| PC Manufacturer | distribution | 
| Dell | 26.56% |  | 
| Hewlett-Packard | 19.14% |  | 
| Acer | 15.23% |  | 
| ASUS | 14.06% |  | 
| Toshiba | 12.50% |  | 
| Sony | 6.25% |  | 
| Alienware | 1.56% |  | 
| Samsung | 1.56% |  | 
| GIGABYTE | 1.56% |  | 
| Lenovo | 1.56% |  |