cynofiy Posted February 11, 2021 ID:1437991 Share Posted February 11, 2021 Hello I have been seeing suspicious connections when I open netstat I don't know if they are safe connections or not and I have been worried. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 12, 2021 Root Admin ID:1438222 Share Posted February 12, 2021 Hello @cynofiy Please download Farbar Recovery Scan Tool and save it to your desktop. Note: You need to run the version compatible with your system. You can check here if you're not sure if your computer is 32-bit or 64-bit Double-click to run it. When the tool opens click Yes to disclaimer. Press the Scan button. It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply. The first time the tool is run, it also makes another log (Addition.txt). Please attach it to your reply as well. Thank you Link to post Share on other sites More sharing options...
cynofiy Posted February 12, 2021 Author ID:1438228 Share Posted February 12, 2021 Addition.txtFRST.txt Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 12, 2021 Root Admin ID:1438232 Share Posted February 12, 2021 The logs show no signs of an infection. You are using Controlled Folder Access which is blocking some files Date: 2021-02-07 01:12:53.2450000Z Description: C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe has been blocked from modifying %userprofile%\Videos by Controlled Folder Access. Detection time: 2021-02-07T09:12:53.245Z Path: %userprofile%\Videos Process Name: C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe Security intelligence Version: 1.331.309.0 Engine Version: 1.1.17800.5 Product Version: 4.18.2011.6 You have a lot of errors from your Volume Shadow Copy service. Please run the tool below to check on it further. Please download and run the following Volume Shadow Copy Service (VSS), Diagnostic Tool, from Acronis Acronis VSS Doctor Free tool for diagnosing and repairing Volume Shadow Copy Service issues. Download link on the bottom of the page.Download - Acronis VSS Doctor In many cases, it can correct the issues on its own. If not, then it will give details on what may be causing the issues. Please save the report in text format and post back that log on your next reply. You can also try the tool from Macrium Reflect if the Acronis tool did not work. Macrium Reflect Volume Shadow Copy Service (VSS) Repair Tool VSSfix 32bit - download VSSfix 64bit - download Once you've run the repair tool you need to restart your computer. Then check your Event Logs to see if the error was corrected. You can post new logs from FRST which will also show the Event Log entries If you don't have System Restore enabled then please take this time to enable it. If possible choose 10% of your C drive to store Restore Points. System Restore disabled or greyed out? Turn On System Restore in Windows 10 Please run the following as well Please download MiniToolBox save it to your desktop and run it. Checkmark the following check-boxes: Flush DNS Report IE Proxy Settings Reset IE Proxy Settings Report FF Proxy Settings Reset FF Proxy Settings List content of Hosts List IP configuration List Winsock Entries List last 10 Event Viewer log List Installed Programs List Devices List Users, Partitions and Memory size. List Minidump Files Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run. Note: When using Reset FF Proxy Settings option Firefox should be closed. Link to post Share on other sites More sharing options...
cynofiy Posted February 12, 2021 Author ID:1438234 Share Posted February 12, 2021 MTB.txt Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 12, 2021 Root Admin ID:1438243 Share Posted February 12, 2021 Did you run the VSS tool? Was it able to correct the issue? The MTB log shows no issues with your network route. You don't have any assigned routes that don't belong. Let me have you run a different scanner to double-check. I don't expect it to find anything, but no harm in checking. I would suggest a free scan with the ESET Online Scanner Go to https://download.eset.com/com/eset/tools/online_scanner/latest/esetonlinescanner.exe It will start a download of "esetonlinescanner.exe" Save the file to your system, such as the Downloads folder, or else to the Desktop. Go to the saved file, and double click it to get it started. When presented with the initial ESET options, click on "Computer Scan". Next, when prompted by Windows, allow it to start by clicking Yes When prompted for scan type, Click on Full scan Look at & tick ( select ) the radio selection "Enable ESET to detect and quarantine potentially unwanted applications" and click on Start scan button. Have patience. The entire process may take an hour or more. There is an initial update download. There is a progress window display. You should ignore all prompts to get the ESET antivirus software program. ( e.g. their standard program). You do not need to buy or get or install anything else. When the scan is completed, if something was found, it will show a screen with the number of detected items. If so, click the button marked “View detected results”. Click The blue “Save scan log” to save the log. If something was removed and you know it is a false finding, you may click on the blue ”Restore cleaned files” ( in blue, at bottom). Press Continue when all done. You should click to off the offer for “periodic scanning”. Link to post Share on other sites More sharing options...
cynofiy Posted February 12, 2021 Author ID:1438247 Share Posted February 12, 2021 i ran the test and it found no viruses and i also ran the vss scan and it found a problem but it fixed it and i also found a problem with event log. Link to post Share on other sites More sharing options...
cynofiy Posted February 12, 2021 Author ID:1438248 Share Posted February 12, 2021 Acronic VSS Doctor event log errors.txt This was the event log errors. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 12, 2021 Root Admin ID:1438250 Share Posted February 12, 2021 Great, thanks. Is there anything else I can assist you with then at this time? Link to post Share on other sites More sharing options...
Solution cynofiy Posted February 12, 2021 Author Solution ID:1438251 Share Posted February 12, 2021 im curious about the event log errors i got on the vss scan. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 12, 2021 Root Admin ID:1438253 Share Posted February 12, 2021 That is showing the Events from the Windows Event Logs and what prompted me to have you run the tool. I thought you said it fixed the issue though. If you reboot the computer a few times you should not see any new errors for the VSS come up anymore. Link to post Share on other sites More sharing options...
cynofiy Posted February 12, 2021 Author ID:1438255 Share Posted February 12, 2021 It fixed the errors for control configuration but it dosnt have a choice to fix the event log errors can i post the errors it shows for event log. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 12, 2021 Root Admin ID:1438257 Share Posted February 12, 2021 No, the errors remain there for a long time. No need to remove them. They are just history. As you restart the computer daily they should not be showing any new ones. Link to post Share on other sites More sharing options...
cynofiy Posted February 12, 2021 Author ID:1438258 Share Posted February 12, 2021 oh ok thanks for the help have a nice day. Link to post Share on other sites More sharing options...
cynofiy Posted February 12, 2021 Author ID:1438260 Share Posted February 12, 2021 oh one last question i aslo had a connection to an ip from level 3 communications and microsoft azure is that normal? Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 12, 2021 Root Admin ID:1438288 Share Posted February 12, 2021 Yes, it's quite normal to have dozens of connections all over the Internet. There are multiple hops to get to sites and many underlying programs that run on Windows that are always reaching out and talking on the network. It would drive a normal person crazy trying to keep track of all of them. We try to block and prevent connections to known bad sites. I'll go ahead and close your topic and it will give you a link to information to help better protect your computer and privacy. Bookmark it and read as you get time, no rush. Take care and have a great upcoming weekend. Cheers Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 12, 2021 Root Admin ID:1438289 Share Posted February 12, 2021 Glad we could help. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Please review the following for Tips to help protect from infection Thank you Link to post Share on other sites More sharing options...
Recommended Posts