Jump to content

TCP suspicious connections


Recommended Posts

I got an alert from glass wire informing me that there was a suspicious host connection(it happened when I opened my browser). So I opened malwarebytes and performed a scan because it didn't find something I tried with adwcleaner. AdwCleaner found a pup folder and two registries that had been affected(I think it all started from a program named popcorn time which caught my attention because a friend said that it would give me access to movies for free legally but the program seemed sketchy so I uninstalled it). After I quarantined and restarted my computer the problem was still there. I used the command netstat in cmd and I found out that I had a lot of tcp connections that matched the names of hosts that my browser was connecting on. I checked for updated in malwarebytes and performed again a scan but it didn't find something. What can I do to remove those tcp connections?

image.png.f7a030e1948a2d8e9f44a7a24d96a7a6.png

image.thumb.png.b5b29b2f3683f124a887ada421e53a8e.png

FRST.txt Addition.txt

Link to post
Share on other sites

Hello, Welcome to Malwarebytes.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

This extension is problematic.
OPR Extension: (No Name) - C:\Users\George\AppData\Roaming\Opera Software\Opera Stable\Extensions\bdbghbgbindbkaainmmmekddaokgbffn [2018-11-13]
The name is normally  "Honey". I would for now disable it. Your call if you wish to use it.

If Opera is synchronized between your devices, I suggest you Sign out.
Refer to this topic
http://help.opera.com/opera/Windows/2393/en/sync.html

Follow the instructions under the Sync Section.

When done restart Opera.

You can Sign in after the test.
====

Is the problem persisting?

Link to post
Share on other sites

Hi,

Please download the attached Fixlist.txt file to  the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.

fixlist.txt

Link to post
Share on other sites

I also have this issue which first appeared December 23rd without any new downloaded activity. Glasswire warns me of "suspicious host connection" when I attempt to connect to my back using either the Chrome browser or Edge. In each case Glasswire shows the connection alert to "nexus.ensighten.com" initially. However this morning it is also shows chrome connecting to "bam.nr-data.net" and "idsync.rlcdn.com". No time to worry about this today.

Merry Christmas everyone. Cheers

Link to post
Share on other sites

Hi,

@ giorgos_spinkl

"nexus.ensighten.com"  looks good. Tested at VirusTotal.

https://www.virustotal.com/gui/url/f56a200495cffd7bac79fe193aedc75c6cfabde6b6bfa9b0ce5edbd256ff9e7e/detection

Did you get an answer from the Glasswire Forums?

===

Note to @ Dewbear

You are not allowed to post in this topic.
If you need help please start your own topic.

Link to post
Share on other sites

  • 2 weeks later...

Glad we could help.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread.

Thanks

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.