Suspicious autoruns

Status
Not open for further replies.

poisonedSYS

Active member
Joined
Sep 13, 2023
Posts
31
Are these normal processes?

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
+ "Delete Cached Standalone Update Binary" "Windows Command Processor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cmd.exe" "Wed Oct 11 13:03:36 2023" "
+ "Delete Cached Update Binary" "Windows Command Processor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cmd.exe" "Wed Oct 11 13:03:36 2023" "
+ "Uninstall 23.209.1008.0002" "Windows Command Processor" "(Verified) Microsoft Windows" "C:\WINDOWS\system32\cmd.exe" "Wed Oct 11 13:03:36 2023" "
+ "\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler" "Performs periodic Windows Update maintenance tasks." "(Verified) Microsoft Windows" "C:\Program Files\RUXIM\PLUGscheduler.exe" "Fri Sep 15 20:37:12 2023" "
 
These are marked as positive 1/76 on VirusTotal
 

Attachments

  • Untitleddddddddd.png
    Untitleddddddddd.png
    321.4 KB · Views: 1
  • Untitledddddddd.png
    Untitledddddddd.png
    319.4 KB · Views: 1
  • DESKTOP-DL2BG03today.txt
    DESKTOP-DL2BG03today.txt
    598.7 KB · Views: 1
  • Untitleddddddd.png
    Untitleddddddd.png
    336.4 KB · Views: 1
  • Untitledddddd.png
    Untitledddddd.png
    321.4 KB · Views: 1
You mean the VirusTotal detection? This will definitely be a false positive of one of the engines. Can you please share the VT links to see which engine it is?
 
IIS (Internet Information Services) is also a part of Windows and used by different services e.g.
 
The results of the engines SecureAge and Skyhigh (SWG) are definitely false positives and can be ignored.
 
I don't know what you want to tell us with the above screenshots? Can you please describe the issue if you are experiencing problems with the internal (WiFi) network?
 
Multiple tcp port scan attacks, icmp redirect attacks, udp and tcp flooding, syn flooding and everytime it is from a different IP, surely masked by proxy.
 
Status
Not open for further replies.
Back
Top