Windows 10: Is there a trojan csrss.exe? If so how do I eliminate it.

Discus and support Is there a trojan csrss.exe? If so how do I eliminate it. in AntiVirus, Firewalls and System Security to solve the problem; Belarc listed her Office version as 365 I'm done for in today. Thanks for everything...especially your patience. I'll plug back in tomorrow and... Discussion in 'AntiVirus, Firewalls and System Security' started by Bruce SX, Apr 19, 2017.

  1. Bruce SX Win User

    Is there a trojan csrss.exe? If so how do I eliminate it.


    Belarc listed her Office version as 365

    I'm done for in today. Thanks for everything...especially your patience.

    I'll plug back in tomorrow and see if you are available.

    *Cool
     
    Bruce SX, Apr 21, 2017
    #31
  2. simrick Win User

    Great. Then her subscription will be available in her MS account.

    Ready when you are. *Wink
     
    simrick, Apr 21, 2017
    #32
  3. Bruce SX Win User
    I will be busy this morning until about 1pm your time. I've just finished breakfast, and I am preparing to head out. I'll check back in as soon as I return.

    I took a set of photos, per your excellent suggestion, of the Belarc results.

    If you are available when I return, cool. If not, I have lot's of time today after I return.

    Respectfully,

    *Cool
     
    Bruce SX, Apr 21, 2017
    #33
  4. simrick Win User

    Is there a trojan csrss.exe? If so how do I eliminate it.

    Sounds good. I should be in and out...have some computer work to take care of today.
     
    simrick, Apr 21, 2017
    #34
  5. Bruce SX Win User
    I'm back, but not ready. My roomie is going to be awhile dealing with all her passwords. I'm going to let her use my pc to reset them all. I fear it may take some time. She opted to let her pc remember all her passwords for her but she hadn't bothered to record them.

    I have stressed the fact that she needs to re-evaluate her log-in procedures so that this doesn't happen again in the future. For her protection. She understands.

    It isn't all her fault anyway. Had it not been for my ignorance, in surrendering control of her pc to someone unknown, this situation may not have been necessary.*Redface

    *Cool
     
    Bruce SX, Apr 21, 2017
    #35
  6. simrick Win User
    It really doesn't matter. Allowing your browser to remember your passwords is a very dangerous thing. All you have to do is visit a page with a malicious script that steals them all and you're screwed. A password manager is the only way to go.

    She didn't by any chance use FireFox for her main browser, did she?
     
    simrick, Apr 21, 2017
    #36
  7. Bruce SX Win User
    No. She likes Google Chrome.

    I, however, do use Firefox as my main browser. Should I be concerned? I ask as I was going to try and convince her to do the same.

    *Cool
     
    Bruce SX, Apr 21, 2017
    #37
  8. simrick Win User

    Is there a trojan csrss.exe? If so how do I eliminate it.

    I can get the passwords from Firefox easily, that's why I asked. I prefer Firefox - it's just a safer browser. I try not to use Chrome, so don't know off the top of my head how to get to the passwords in it (have to google that).
     
    simrick, Apr 21, 2017
    #38
  9. simrick Win User
    Or, go to passwords.google.com if they are being synced.
     
    simrick, Apr 23, 2017
    #39
  10. Bruce SX Win User
    Maureen got around to changing most of her passwords this morning on my pc. She has been working all weekend so I didn't press to hard.

    I should be ready to go by around 10am your time tomorrow(Monday) morning.

    Again, I thank you for your patience in helping with this issue. Thanks to you there is light at the end of the tunnel. It will, however, enable me to move forward if it happens again.

    On my pc I use lastpass(the free version). I will set her up with it on her notebook. I am also showing her the benefits of pc security.

    Maureen asked me to relay to you her appreciation, and heartfelt thanks, for the assistance you've provided.

    Best,

    *Cool
     
    Bruce SX, Apr 23, 2017
    #40
  11. simrick Win User
    No problem. That sounds fine. I also use LastPass and am really pleased with it.

    Maureen and you are very welcome. I am sorry this happened, but, in the end, it's a good thing we are able to recover from it, and that there wasn't more severe damage at the onset. I've had scammed computers with the SysKey set by the perpetrators, so that rebooting locked the owner out completely. (and, yes, there is a way out of that as well, but it's a bit involved.)

    Just a few things for Maureen to think about:
    It's good to change important passwords every so often (like email, banking, online retailers). The situation of Yahoo being breached, several times, without people finding out until months later, is one example where regular password changes help mitigate those problems, at least to some degree. Once a scammer has your email password, he'll start doing password resets on all your other accounts, and virtually begin to take over your online identity. Two-factor authentication is also recommended wherever it is offered.

    Never "re-use" passwords. Each account should have a unique password, so that if one is breached, it doesn't give hackers access to other accounts as well. LastPass will auto-generate secure passwords for her in the future.

    LastPass should only be logged in when you need to use it; otherwise it should be set to auto-log-off after a very short amount of time, and also upon browser close. The master password should be complex, (upper+lower case letters+numbers+special characters), but in a way that is easy to remember, and never written down. It also will sync to her smartphone, and should be used there as well. It is also possible to have it generate a one-time password, in case she gets locked out. Remember, LP information is encrypted, salted and hashed using very strong algorithms before it leaves your computer to go to their online servers, so even the employees never have access to your info. Previous hacks of LP servers have resulted in useless databases of gibberish.

    -------------------------------
    Post 6 has the prep info for the clean install. Once you've got the downloads finished, we'll walk through it.
    Please be sure to have a list of her currently installed programs, so we can get her back up and running, verify W10 Home or Pro, (you indicated it was Home), grab the W10 key from ShowKeyPlus, and all data is backed up. Important: You will *NOT* be entering a key during the install.

    Question: Does she log into her computer using her MS account, or a non-MS account? If she uses her MS account to login to the computer, this computer will show up on her device list in her MS account. Once the clean install is complete, there will likely be 2 systems in her device list. The old one can then be deleted. This is relevant because MS allow a maximum of 10 devices.
     
    simrick, Apr 23, 2017
    #41
  12. Bruce SX Win User
    I have got to brew a pot of coffee.

    Just got in from taking my pal out for his morning necessities. I'll start on post 6 when the fog clears. When I've completed the process I'll check back in.

    *Cool
     
    Bruce SX, Apr 23, 2017
    #42
  13. simrick Win User

    Is there a trojan csrss.exe? If so how do I eliminate it.

    Coffee is good. I've got a fresh cup. *Smile

    Don't start the process yet, just have everything downloaded and ready to go.
     
    simrick, Apr 23, 2017
    #43
  14. Bruce SX Win User
    I have the ISO download to a flash drive. I had done the download from Maureen's notebook.

    Should I redo the download from my pc?

    *Cool
     
    Bruce SX, Apr 23, 2017
    #44
  15. simrick Win User
    I think we'll be okay, as MS check all hashes to make sure the ISO is intact before allowing you to close the media tool.

    To recap:
    W10 ISO is downloaded
    W10 keycode is written down - does it end in H8Q99? That is the generic one for W10Home.
    Edition is W10 Home (previous was W8.x)
    Belarc has been photographed for any other keys needed to install other programs.
    Installed programs list from Ccleaner is available (and won't be lost when reinstalling the OS?)
    Office has been confirmed on her MS account as O365
    Passwords have been changed on a known clean computer
    All data has been backed up
     
    simrick, Apr 23, 2017
    #45
Thema:

Is there a trojan csrss.exe? If so how do I eliminate it.

Loading...
  1. Is there a trojan csrss.exe? If so how do I eliminate it. - Similar Threads - trojan csrss exe

  2. How do I remove this Trojan

    in Windows 10 Gaming
    How do I remove this Trojan: I have noticed that my chrome is keep on ending itself seconds after I open it. It then opens it up again with the old tab i was suspicious that I got a virus then when i was just on my device all of the sudden things like a command bar opens up then quickly leaves. Now I...
  3. How do I remove this Trojan

    in Windows 10 Software and Apps
    How do I remove this Trojan: I have noticed that my chrome is keep on ending itself seconds after I open it. It then opens it up again with the old tab i was suspicious that I got a virus then when i was just on my device all of the sudden things like a command bar opens up then quickly leaves. Now I...
  4. How do I remove this Trojan

    in AntiVirus, Firewalls and System Security
    How do I remove this Trojan: I have noticed that my chrome is keep on ending itself seconds after I open it. It then opens it up again with the old tab i was suspicious that I got a virus then when i was just on my device all of the sudden things like a command bar opens up then quickly leaves. Now I...
  5. SIHOST64.exe Mining Trojan

    in AntiVirus, Firewalls and System Security
    SIHOST64.exe Mining Trojan: Hi. I recently found a virus in my computer, sihost64 and sihost32 running on the background. I dont know how to remove it. Please help me, especially @_AW_ who was helped people with the same problem.Here i attached my...
  6. How do eliminate the password in logon

    in Windows 10 Software and Apps
    How do eliminate the password in logon: How can I eliminate the password during logon? https://answers.microsoft.com/en-us/windows/forum/all/how-do-eliminate-the-password-in-logon/b2132cf7-a9bc-432c-9ebd-5a6881bcc273
  7. How do eliminate the password in logon

    in Windows 10 Gaming
    How do eliminate the password in logon: How can I eliminate the password during logon? https://answers.microsoft.com/en-us/windows/forum/all/how-do-eliminate-the-password-in-logon/b2132cf7-a9bc-432c-9ebd-5a6881bcc273
  8. How do I remove a Trojan

    in AntiVirus, Firewalls and System Security
    How do I remove a Trojan: Hello, I downloaded a file some days ago. After that I got warning from Windows security, "That comes with windows, not the scam" It said trojan detected. It was set to quarantine. After weeks later my computer act different. My files was looking weird. It does not say any...
  9. how do I eliminate a long running script

    in Windows 10 BSOD Crashes and Debugging
    how do I eliminate a long running script: how do I eliminate a long running script https://answers.microsoft.com/en-us/windows/forum/all/how-do-i-eliminate-a-long-running-script/45acadbf-e478-464f-b1dc-2d93c8178c3e
  10. Reoccuring pcds32.exe trojan

    in AntiVirus, Firewalls and System Security
    Reoccuring pcds32.exe trojan: Hello, I've been getting a lot of notifications from bitdefender that i have viruses named: pcds32.exe, pcds64.exe, and rv32.exe. Bitdefender usually finds it in my temp folder and it'll keep disinfecting it and blocking it and I've manually deleted it as well but it keeps...