csrsc.exe is a W32.Spybot.CF Virus. The process is not visible and loads during the Windows boot process. When started, it connects to a remote IRC server waiting for instructions to be executed. Csrcs.exe is known to be associated with a number of other threats. People often mistake it for csrss.exe. csrss.exe refers to Client/Server Run-Time Subsystem, and is an essential subsystem that must be running at all times. So, make sure that you don’t get confused and try to get rid of the wrong file.
Scan with a good antivirus program and get rid of the virus. Once done, you need to make sure that there are no entries left in the registry. To do so, follow the below steps:
Go to Start> Run> type regedit and hit enter.
Now, navigate to the following paths, check for the entries relating to csrcs.exe and delete them.
Once done, navigate to the following path:
There is a key with the name “Shell”. Click on it and check the value of the key. If it contains the words “csrcs.exe” then change the value to “explorer.exe”.
Once you’re done with the above steps, close the registry editor and restart your computer for changes to take effect.