• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

I'm from Microsoft, there's something wrong with your computer

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    #31
    PC may be hijacked, in the near future when she will start it up a ransom screen will appear with an amount in bitcoins to pay on a Nigerian or Russian account to release the PC

    Comment


      #32
      I've disconnected her from the internet, and having a poke around.

      So it looks like he was connected via logmein for 40 minutes. He also installed teamviewer.

      Looks like he's downloaded a csrss.exe - running a scan now...

      Comment


        #33
        Originally posted by mudskipper View Post
        I've disconnected her from the internet, and having a poke around.

        So it looks like he was connected via logmein for 40 minutes. He also installed teamviewer.

        Looks like he's downloaded a csrss.exe - running a scan now...
        csrss.exe is part of windows update. It can become compromised and usually a sign of that is this file running as a process hogging the CPU. That said it could just be windows updates trying to come down.

        Switch off windows updates and turn off the service. If the file continues to hog CPU then be suspicious.

        Truly HTH

        Edit : I'm having a petit mal it seems. It is a valid windows process but is the usermode sub system and nothing to do with windows update, sorry. https://en.wikipedia.org/wiki/Client...time_Subsystem
        Last edited by suityou01; 18 August 2015, 20:06.
        Knock first as I might be balancing my chakras.

        Comment


          #34
          Scan clear - going to reconnect to interwebs and download malware finder stuff.

          Comment


            #35
            Originally posted by mudskipper View Post
            Scan clear - going to reconnect to interwebs and download malware finder stuff.
            The very best of luck.
            Knock first as I might be balancing my chakras.

            Comment


              #36
              Originally posted by suityou01 View Post
              The very best of luck.
              You still doing fifteen dorra PC fix?

              Comment


                #37
                Originally posted by mudskipper View Post
                You still doing fifteen dorra PC fix?


                Knock first as I might be balancing my chakras.

                Comment


                  #38
                  Originally posted by mudskipper View Post
                  You still doing fifteen dorra PC fix?
                  Hold tight. I'm going in
                  (\__/)
                  (>'.'<)
                  ("")("") Born to Drink. Forced to Work

                  Comment


                    #39
                    Just buy her a Chromebook. Further assistance not required. Game over for Bobbits.
                    I was an IPSE Consultative Council Member, until the BoD abolished it. I am not an IPSE Member, since they have no longer have any relevance to me, as an IT Contractor. Read my lips...I recommend QDOS for ALL your Insurance requirements (Contact me for a referral code).

                    Comment


                      #40
                      Originally posted by mudskipper View Post
                      I've disconnected her from the internet, and having a poke around.

                      So it looks like he was connected via logmein for 40 minutes. He also installed teamviewer.

                      Looks like he's downloaded a csrss.exe - running a scan now...
                      don't want to teach anyone to suck eggs, but with my old girl's pc a very simple search on files that had been modified that day was very revealing

                      Comment

                      Working...
                      X