Solved csrss and javaw.exe

DavisRaymondArt

New member
Local time
7:13 AM
Messages
10
I have recently seen 2 weird processes "javaw.exe" and "csrss.exe" both are running from hidden folders and are hidden themselves . When any of the two "Even javaw" process is killed my pc immediatly has a memory dump . Can someone tell me how to fix or remove this problem please
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
MSI
OS
Windows 7 Home Premium 64bit
Welcome to the forum.

What is the exact and full path to these processes. This is critical.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Pro 64 bit
CPU
Xeon W3520
Memory
8 GB
Graphics Card(s)
Nvidia Geforce 210
javaw : C:\Users\msi\AppData\Local\Sun

csrss : C:\Users\msi\AppData\Local\Temp
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
MSI
OS
Windows 7 Home Premium 64bit
Welcome to the forum.

What is the exact and full path to these processes. This is critical.
javaw : C:\Users\msi\AppData\Local\Sun

csrss : C:\Users\msi\AppData\Lo
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
MSI
OS
Windows 7 Home Premium 64bit
javaw is the Java process.

csrss is a critical system file but that one you listed there is a fake csrss, caused by an infection. From my experience with those fake cssrs:es is that they are very hard to remove. If you do remove the fake cssrs BSODs will occur at shutdown(0xF4's to be exact), that's why i find them very hard to remove. I haven't tried deleting it from safe mode but someone here at the forums probably knows how to delete this virus.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
me!
OS
Windows 10 Pro x64
CPU
AMD Ryzen 5 1600 @ [email protected]
Motherboard
ASUS B350 PRIME-PLUS
Memory
G.Skill Flare X 16GB (2x8GB) DDR4-2400 @ 2666MHz
Graphics Card(s)
Sapphire Radeon Vega 56 NITRO+
Sound Card
None
Monitor(s) Displays
ASUS VG248QZ
Screen Resolution
1920x1080
Hard Drives
Samsung 850 EVO 250GB*, 1TB Seagate Constellation ES, 2x Samsung 840 250GB in RAID0*

*Thanks ICIT2LOL for supplying me with all of these drives!
PSU
Corsair VS550
Case
Corsair Crystal 460X
Cooling
AMD Wraith Spire
Keyboard
Ducky Shine 6 w/ MX Browns and PBT keycaps
Mouse
Xtrfy M1-Ice
Internet Speed
100MBit/s down, 20MBit/s up
Antivirus
Bitdefender
Browser
Google Chrome
javaw is the Java process.

csrss is a critical system file but that one you listed there is a fake csrss, caused by an infection. From my experience with those fake cssrs:es is that they are very hard to remove. If you do remove the fake cssrs BSODs will occur at shutdown(0xF4's to be exact), that's why i find them very hard to remove. I haven't tried deleting it from safe mode but someone here at the forums probably knows how to delete this virus.

Javaw itself when closed causes 0xF4 BSOD so i think it has a connection in a way
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
MSI
OS
Windows 7 Home Premium 64bit
Oh, that means both are fakes.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
me!
OS
Windows 10 Pro x64
CPU
AMD Ryzen 5 1600 @ [email protected]
Motherboard
ASUS B350 PRIME-PLUS
Memory
G.Skill Flare X 16GB (2x8GB) DDR4-2400 @ 2666MHz
Graphics Card(s)
Sapphire Radeon Vega 56 NITRO+
Sound Card
None
Monitor(s) Displays
ASUS VG248QZ
Screen Resolution
1920x1080
Hard Drives
Samsung 850 EVO 250GB*, 1TB Seagate Constellation ES, 2x Samsung 840 250GB in RAID0*

*Thanks ICIT2LOL for supplying me with all of these drives!
PSU
Corsair VS550
Case
Corsair Crystal 460X
Cooling
AMD Wraith Spire
Keyboard
Ducky Shine 6 w/ MX Browns and PBT keycaps
Mouse
Xtrfy M1-Ice
Internet Speed
100MBit/s down, 20MBit/s up
Antivirus
Bitdefender
Browser
Google Chrome
Oh, that means both are fakes.

Yes it seems though and its gotten so far to the point switching off my pc causes this error
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
MSI
OS
Windows 7 Home Premium 64bit
Exactly, they are very hard to remove.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
me!
OS
Windows 10 Pro x64
CPU
AMD Ryzen 5 1600 @ [email protected]
Motherboard
ASUS B350 PRIME-PLUS
Memory
G.Skill Flare X 16GB (2x8GB) DDR4-2400 @ 2666MHz
Graphics Card(s)
Sapphire Radeon Vega 56 NITRO+
Sound Card
None
Monitor(s) Displays
ASUS VG248QZ
Screen Resolution
1920x1080
Hard Drives
Samsung 850 EVO 250GB*, 1TB Seagate Constellation ES, 2x Samsung 840 250GB in RAID0*

*Thanks ICIT2LOL for supplying me with all of these drives!
PSU
Corsair VS550
Case
Corsair Crystal 460X
Cooling
AMD Wraith Spire
Keyboard
Ducky Shine 6 w/ MX Browns and PBT keycaps
Mouse
Xtrfy M1-Ice
Internet Speed
100MBit/s down, 20MBit/s up
Antivirus
Bitdefender
Browser
Google Chrome
Yea still hoping someone has a solution
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
MSI
OS
Windows 7 Home Premium 64bit

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
me!
OS
Windows 10 Pro x64
CPU
AMD Ryzen 5 1600 @ [email protected]
Motherboard
ASUS B350 PRIME-PLUS
Memory
G.Skill Flare X 16GB (2x8GB) DDR4-2400 @ 2666MHz
Graphics Card(s)
Sapphire Radeon Vega 56 NITRO+
Sound Card
None
Monitor(s) Displays
ASUS VG248QZ
Screen Resolution
1920x1080
Hard Drives
Samsung 850 EVO 250GB*, 1TB Seagate Constellation ES, 2x Samsung 840 250GB in RAID0*

*Thanks ICIT2LOL for supplying me with all of these drives!
PSU
Corsair VS550
Case
Corsair Crystal 460X
Cooling
AMD Wraith Spire
Keyboard
Ducky Shine 6 w/ MX Browns and PBT keycaps
Mouse
Xtrfy M1-Ice
Internet Speed
100MBit/s down, 20MBit/s up
Antivirus
Bitdefender
Browser
Google Chrome

In addition to @Laith's expert advice....

For the record, in order to work properly & completely, MBAM ought to be run in normal Windows mode.
Running it in Safe Mode is not recommended and is really a last resort, especially since there are other means (such as Chameleon) to get it to run on badly infected systems.

Having said that, as @Laith also mentioned, some types of malware can be very difficult to fully remove & repair, as explained here.

If you still need help with this after running the aforementioned scan, then you might want to head over to one of several computer disinfection fora for a bit of expert, free help (unless @Laith, @Jacee,@cottonball, or someone else here can walk you through it:)).

Cheers,

MM
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Studio XPS 8500
OS
OEM Windows 7 Ult (x64) SP1
CPU
Intel Core-i7 3770 @ 3.4 GHz
Motherboard
"Dell" branded
Memory
16 GB DDR3 SDRAM @ 1333 MHz
Graphics Card(s)
NVidia GeForce GT620 1 GB
Sound Card
THX TruStudio PC
Monitor(s) Displays
Dell U2410 Full HD
Hard Drives
2.0 TB SATA2 @ 7200 RPM
PSU
350W
Keyboard
MS 4000 Ergon - Wired
Mouse
Logitech Anywhere MX
Internet Speed
Cable HSI w/Turbo (router)
Antivirus
KIS-MBAM Premium-MBAE Premium
Browser
Fx (current version); IE
Other Info
And a Win7/64 Pro laptop; And a Win10/64 Pro desktop.
I would suggest a re-install to completely get rid of this problem as it's very hard virus to properly fix. If you do have a system restore please restore from that.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
me!
OS
Windows 10 Pro x64
CPU
AMD Ryzen 5 1600 @ [email protected]
Motherboard
ASUS B350 PRIME-PLUS
Memory
G.Skill Flare X 16GB (2x8GB) DDR4-2400 @ 2666MHz
Graphics Card(s)
Sapphire Radeon Vega 56 NITRO+
Sound Card
None
Monitor(s) Displays
ASUS VG248QZ
Screen Resolution
1920x1080
Hard Drives
Samsung 850 EVO 250GB*, 1TB Seagate Constellation ES, 2x Samsung 840 250GB in RAID0*

*Thanks ICIT2LOL for supplying me with all of these drives!
PSU
Corsair VS550
Case
Corsair Crystal 460X
Cooling
AMD Wraith Spire
Keyboard
Ducky Shine 6 w/ MX Browns and PBT keycaps
Mouse
Xtrfy M1-Ice
Internet Speed
100MBit/s down, 20MBit/s up
Antivirus
Bitdefender
Browser
Google Chrome
Is there a way to boot up to system restore and choose a restore ? Since the control panel method has failed and asks for a disk check which fails due to some software guessing the malware
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
MSI
OS
Windows 7 Home Premium 64bit
Safe mode.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
me!
OS
Windows 10 Pro x64
CPU
AMD Ryzen 5 1600 @ [email protected]
Motherboard
ASUS B350 PRIME-PLUS
Memory
G.Skill Flare X 16GB (2x8GB) DDR4-2400 @ 2666MHz
Graphics Card(s)
Sapphire Radeon Vega 56 NITRO+
Sound Card
None
Monitor(s) Displays
ASUS VG248QZ
Screen Resolution
1920x1080
Hard Drives
Samsung 850 EVO 250GB*, 1TB Seagate Constellation ES, 2x Samsung 840 250GB in RAID0*

*Thanks ICIT2LOL for supplying me with all of these drives!
PSU
Corsair VS550
Case
Corsair Crystal 460X
Cooling
AMD Wraith Spire
Keyboard
Ducky Shine 6 w/ MX Browns and PBT keycaps
Mouse
Xtrfy M1-Ice
Internet Speed
100MBit/s down, 20MBit/s up
Antivirus
Bitdefender
Browser
Google Chrome
Before i start the process let me confirm . 1. I have to run malwarebytes in safe mode 2. Run a system restore in safe mode . Then all done ?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
MSI
OS
Windows 7 Home Premium 64bit
No, run Malwarebytes Charmeleon, if it fixes it, it fixes it. System restore is if Charmeleon didn't fix it.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
me!
OS
Windows 10 Pro x64
CPU
AMD Ryzen 5 1600 @ [email protected]
Motherboard
ASUS B350 PRIME-PLUS
Memory
G.Skill Flare X 16GB (2x8GB) DDR4-2400 @ 2666MHz
Graphics Card(s)
Sapphire Radeon Vega 56 NITRO+
Sound Card
None
Monitor(s) Displays
ASUS VG248QZ
Screen Resolution
1920x1080
Hard Drives
Samsung 850 EVO 250GB*, 1TB Seagate Constellation ES, 2x Samsung 840 250GB in RAID0*

*Thanks ICIT2LOL for supplying me with all of these drives!
PSU
Corsair VS550
Case
Corsair Crystal 460X
Cooling
AMD Wraith Spire
Keyboard
Ducky Shine 6 w/ MX Browns and PBT keycaps
Mouse
Xtrfy M1-Ice
Internet Speed
100MBit/s down, 20MBit/s up
Antivirus
Bitdefender
Browser
Google Chrome
No, run Malwarebytes Charmeleon, if it fixes it, it fixes it. System restore is if Charmeleon didn't fix it.

Okay starting the process i will post results soon
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
MSI
OS
Windows 7 Home Premium 64bit
Sounds good to me.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
me!
OS
Windows 10 Pro x64
CPU
AMD Ryzen 5 1600 @ [email protected]
Motherboard
ASUS B350 PRIME-PLUS
Memory
G.Skill Flare X 16GB (2x8GB) DDR4-2400 @ 2666MHz
Graphics Card(s)
Sapphire Radeon Vega 56 NITRO+
Sound Card
None
Monitor(s) Displays
ASUS VG248QZ
Screen Resolution
1920x1080
Hard Drives
Samsung 850 EVO 250GB*, 1TB Seagate Constellation ES, 2x Samsung 840 250GB in RAID0*

*Thanks ICIT2LOL for supplying me with all of these drives!
PSU
Corsair VS550
Case
Corsair Crystal 460X
Cooling
AMD Wraith Spire
Keyboard
Ducky Shine 6 w/ MX Browns and PBT keycaps
Mouse
Xtrfy M1-Ice
Internet Speed
100MBit/s down, 20MBit/s up
Antivirus
Bitdefender
Browser
Google Chrome
It worked guys. Thank you all so much ^^ still doing extra scans just incase malware bytes left some over
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
MSI
OS
Windows 7 Home Premium 64bit
Back
Top