Weird processes, is it malware?

Status
Not open for further replies.

damnitq

New Member
Thread author
Jun 23, 2020
3
Good morning.

For around 2 months I'm having problems with my connection - router is randomly loosing signal, there are problems logging into banks because of some IP problems, also I can't log into my paypal anymore because of some fraud protection, etc. That's why I decided to share my problem with You since I'm getting really worried about this situation.
I have called my ISP about the situation but all they have done was changing the phone number which im actually using on simcard from them.

Router I'm using is 4G EE Router HH70VB. After some time of reading and trying to fix my problem, I found that this router has some backdoor SSH credentials. That made me even more worried.

Backdoor in EE 4GEE HH70

I'm really thankful for any further help and advices.

Wish You guys great morning.
 

Attachments

  • Addition.txt
    30.3 KB · Views: 10
  • FRST.txt
    226.1 KB · Views: 8

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

No malware was found in your logs.

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.

If you know the process name that is causing issues please post the name of the process.
 

Attachments

  • fixlist.txt
    141 bytes · Views: 9

damnitq

New Member
Thread author
Jun 23, 2020
3
Hello there. So in my opinion, someone is tracking and stealing my informations through ssh credentials backdoor of my router. Through local laptop which I can't really get onto.

Before format there was a lot of weird "root" registry keys, also my firewall settings are constantly changning.

There are many svchost.exe processes working and weird "DisturbedCOM" LRPC warning events in event viewer

Greetings.
 

Attachments

  • Fixlog.txt
    2.3 KB · Views: 8
  • Fixlog.txt
    2.3 KB · Views: 8
Last edited:

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

There are many svchost.exe processes working and weird "DisturbedCOM" LRPC warning events in event viewer

This as far as I know is not caused by malware.

You may have seen this topic.


What I suggest is that you start a new topic in the Windows 10 Forum at BleepingComputer.
You may have to register.


An expert with this issue will be able to help you as this is not my forte.

This topic will be closed in 6 days.
If you need to return please do.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top