Jump to content
MillZee

Numerous outgoing connections blocked due to Malware/Trojan

Recommended Posts

Hi there,
ever since a suspicious inbound connection was blocked yesterday I've been receiving suspicious outgoing connections. I've run a custom scan of my entire PC using malwarebytes premium and it didn't find anything. I've attached 3 examples of the outgoing connections, and the FRST, Addition and exported threat scan .txt files. I'm not sure how to fix this if malwarebytes can't find the problem.

Any help would be appreciated,
Thanks in advance.

FRST.txt Addition.txt Threat Scan.txt Event 1.txt Event 2.txt Event 3.txt

Share this post


Link to post
Share on other sites

Hello, Welcome to Malwarebytes.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

This program will be removed.
S3 cpuz143; C:\Users\Jackm.JACK-PC\AppData\Local\Temp\cpuz143\cpuz143_x64.sys [48952 2019-04-18] (CPUID -> CPUID) <==== ATTENTION

Your copy is not signed and could be compromised.
If you need it please download the latest version from this site.
https://www.cpuid.com/
<<<>>>

Please download the attached Fixlist.txt file to  the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.

fixlist.txt

Share this post


Link to post
Share on other sites

Thank you very much for replying. I ran FRST as you said and have attached the fixlog file. 

I don't think there's a way for me to test if this problem is persisting, but if it happens again I will reply asap.

Thank you again!

Fixlog.txt

Share this post


Link to post
Share on other sites

Glad we could help.

The topic will be kept open for 5 days.

Share this post


Link to post
Share on other sites

Hello, 

I've been receiving the same messages again, all from different IP's. I feel like they may just be ads being blocked but it is a worrying message to receive over and over, especially since it was so sudden. I switched routers in case that was attempting to redirect me but it persisted.
I received multiple inbound threats all on the same IP which I have now blocked in my firewall.
Threat scan returned nothing, would you like me to run FRST again and attach the file?

Thanks again!

Share this post


Link to post
Share on other sites

Hi,

Both logs are clean or malware.

Share this post


Link to post
Share on other sites

Glad we could help.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread.

Thanks

 

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.