Jump to content

Unverified files communicating with many IP addresses

Recommended Posts

I have an Android tablet sending certs to other computers on my network (now turned off) and want to check this computer to see if infected with malware.  Many IP addresses are communicating to unknown destinations, and files in sysinternals's procexp64.exe are unverified and Vitus Total check comes back with Unknown.    

Link to post
Share on other sites

Some additional information regarding this issue.  The topic I wrote about "Android tablet sending certs" was an assumption because of other unknown behavior. 

What prompted me to post was McAfee had stopped "C:\windows\System32\AgentActivationRuntimeStarter.exe", but apps associated to it in the WindowsApp folder kept running anyway when viewed in TCPViewer and connecting to all many unknown external IP addresses.  Permissions to that folder are restricted to an unknown user and some entries are not in normal format or were delete.  I have Certs that say "Invalid".  

I searched on "C:\windows\System32\AgentActivationRuntimeStarter.exe" which found this article in Malwarebytes forum

So I'm seeking your help in searching my computer for same malware problem. 

Link to post
Share on other sites

  • 4 weeks later...
  • Root Admin

Due to the lack of feedback, this topic is closed to prevent others from posting here.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this topic. Other members who need assistance please start your own topic in a new thread.

Tips to help protect from infection



Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.