Please can anyone offer any tech advice? Event 11005 MsmSecurity

Dinky

New member
Local time
9:18 AM
Messages
6
Hi there

Apologies im new but desperately need some clarification.

Towards the end of last year I had some security issues with my asus laptop, windows 7 premium 64, it began with my bank cards being cloned and credit card details being used (5 separate incidents). The laptop kept crashing, unknown log on events and unknown IP log on to Facebook. I eventually had computer wiped cleaned and started again. That was at the end of Nov 2012.

It appears similar things are beginning to occurr again. For the last few days its been continuously crashing, programs failing to load, printer will not connect and nothing as far as I know has been changed.

During the last crash at 0217 hrs I found the event id 11005 WLAN auto config, wirless security suceeded showing details of a foreign MAC address

Please can anyone confirm that this is indeed strange, I was unable to convince friends and family last time and they thought I was being paranoid?

Any advice would be much appreciated
Many thanks
 

My Computer My Computer

At a glance

Windows 7 Premium 64
OS
Windows 7 Premium 64
Welcome to Seven forums dinky.
Just a guess but since the issue resurfaced you are getting crap from a like or friend of a friend of a friend of a friend of a friend from Facebook. Is your WLAN WPA2 and have a good password?
 

My Computer My Computer

At a glance

Windows 7 Ultimate X64 SP1Intel i5-2550K, Differing ~4.4-4.8GHz No buil...16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GBASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
Hi

Thanks so much for getting back to me. Really appreciate it.

Honestly I have no enemies, friends, family or otherwise that would be interferring. I dont actually use facebook that much. It was only becuase I was checking all my security that I happened to notice the unusual IP.

It is WPA2 and the password is a good one and only known by myself and my husband (believe me I have thought and accused him)
 

My Computer My Computer

At a glance

Windows 7 Premium 64
OS
Windows 7 Premium 64
I agree totally with Britton30 here. What kind of security do you use on your machine?
 

My Computer My Computer

At a glance

Windows 10x64 Build 1709Intel i7 7700HQ Kaby Lake16 GB DDR4 @2400Nvidia Geforce GTX 1060
Computer type
Laptop
Computer Manufacturer/Model Number
MSI GE72VR Apache Pro-416
OS
Windows 10x64 Build 1709
CPU
Intel i7 7700HQ Kaby Lake
Motherboard
Micro-Star Intl. MS-179B (U3C1)
Memory
16 GB DDR4 @2400
Graphics Card(s)
Nvidia Geforce GTX 1060
Screen Resolution
1920x1080 120Hz
Hard Drives
256 GB Nvme M.2 SSD

1TB HDD@7200
Cooling
Cooler Blast 4
Keyboard
Steel Series
Antivirus
Bit Defender Free
Browser
Edge
I use Microsoft security essentials. Scans have never picked up on anything
 

My Computer My Computer

At a glance

Windows 7 Premium 64
OS
Windows 7 Premium 64

My Computer My Computer

At a glance

Windows 7 Ultimate X64 SP1Intel i5-2550K, Differing ~4.4-4.8GHz No buil...16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GBASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
Thanks. Ill give that a try and get back to you. I have not had any further issues with facebook just problems with laptop crashing, mouse jumping about, very long start up, error messages when nothing different has been changed on computer. Just to give you an idea. Im starting a log of the ocurrences before I forget and will try the link. Thanks
 

My Computer My Computer

At a glance

Windows 7 Premium 64
OS
Windows 7 Premium 64
You're welcome. What you're describing are symptoms of an infection of some sort, Virus, Trojan, keylogger, etc.
 

My Computer My Computer

At a glance

Windows 7 Ultimate X64 SP1Intel i5-2550K, Differing ~4.4-4.8GHz No buil...16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GBASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.

My Computer My Computer

At a glance

Microsoft Windows 8.1 Enterprise 64-bitIntel(R) Core(TM) i7-3770K CPU @ 4.7GHz (Over...32 GB 12800 DDR3 Crucial Ballistix SportNVIDIA GeForce GTX 660 SC x 2 (SLI) by EVGA
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Intel DZ77GA-70K
OS
Microsoft Windows 8.1 Enterprise 64-bit
CPU
Intel(R) Core(TM) i7-3770K CPU @ 4.7GHz (Overclocked)
Motherboard
Intel Corporation DZ77GA-70K, 0066 BIOS version
Memory
32 GB 12800 DDR3 Crucial Ballistix Sport
Graphics Card(s)
NVIDIA GeForce GTX 660 SC x 2 (SLI) by EVGA
Sound Card
(1) Bluetooth Hands-free Audio (2) NVIDIA High Definition
Monitor(s) Displays
LG 27" HDMI
Screen Resolution
12920 x 1080 x 32 bits (4294967296 colors) @ 60Hz
Hard Drives
Intel 120GB SSD (ATA INTEL SSDSC2CT12 SCSI Disk Device)
Western Digital Caviar Black 64M cache 2TB 7200rpm (ATA WDC WD2002FAEX-0 SCSI Disk Device), 3 x WD 150Gb 10k Velociraptor hard drives in RAID 0 (testing)
PSU
Corsair 750w fully modular
Case
Corsair 650D with perforated side panel
Cooling
3 200mm case fans, Intel liquid cooling for CPU w 120mm fans
Keyboard
Logitech backlit
Mouse
Dell
Internet Speed
11Mbps DSL
Antivirus
Windows Defender, MalWareBytes Pro and CCleaner Pro
Browser
Chrome, IE and FireFox (latest versions)
Other Info
Windows Home Server 2011 with 10 clients at home
Thanks. Any advice is welcome and appreciated. I'm yet to get chance to try suggestions but will get on it. Further look on event viewer showed that at same time as crash last night there was a special logon event from an IP address showing registered to 'hon hai precision ltd' in Taiwan

Surely this can't be authentic? Any ideas?
 

My Computer My Computer

At a glance

Windows 7 Premium 64
OS
Windows 7 Premium 64
Give the scans a try to see how it turns out. Seems like you have a hole in your network. Change the network password and don't go near FB and see if you have any foreign log ins.
 

My Computer My Computer

At a glance

Windows 7 Ultimate X64 SP1Intel i5-2550K, Differing ~4.4-4.8GHz No buil...16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GBASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
I've not been on Facebook for while. Last time was about week ago just to check all in order. Nothing suspicious since I wiped laptop in nov. trying scans and will let you know?

Just out of interest, if someone with legitimate access was monitoring my use could this cause these issues and how would I identify it?
 

My Computer My Computer

At a glance

Windows 7 Premium 64
OS
Windows 7 Premium 64
I've not been on Facebook for while. Last time was about week ago just to check all in order. Nothing suspicious since I wiped laptop in nov. trying scans and will let you know?

Just out of interest, if someone with legitimate access was monitoring my use could this cause these issues and how would I identify it?
Hard to tell but I don't think someone with legitimate access would need a malware to monitor your activity.
BTW, just logging on FB could expose you to infections if all the right permissions, like, friends, etc. are already in place. The people who do that are quite smart, and ratbags.
 

My Computer My Computer

At a glance

Windows 7 Ultimate X64 SP1Intel i5-2550K, Differing ~4.4-4.8GHz No buil...16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GBASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
If you haven't enabled MAC filtering on your router, do so. This will only allow authorised devices to connect and not others, even if they have the correct SSID and password. Incidentally, for your password go to https://www.grc.com/passwords.htm
 

My Computer My Computer

At a glance

Windows 8.1 Pro RTM x64Intel Core-i5-3570K 4-core @ 3.4GHz (Ivy Brid...4 x 4GB DDR3-1600 Corsair Vengeance CMZ8GX3M2...MSI GeForce GTX770 Gaming OC 2GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dwarf Dwf/11/2012 r09/2013
OS
Windows 8.1 Pro RTM x64
CPU
Intel Core-i5-3570K 4-core @ 3.4GHz (Ivy Bridge) (OC 4.4GHz)
Motherboard
ASRock Z77 Extreme4-M
Memory
4 x 4GB DDR3-1600 Corsair Vengeance CMZ8GX3M2A1600C9B (16GB)
Graphics Card(s)
MSI GeForce GTX770 Gaming OC 2GB
Sound Card
Realtek High Definition on board solution (ALC 898)
Monitor(s) Displays
ViewSonic VA1912w Widescreen (VGA)
Screen Resolution
1440x900
Hard Drives
OCZ Agility 3 SSD 120GB SATA III x2 (RAID 0)
Samsung HD501LJ 500GB SATA II x2
Hitachi HDS721010CLA332 1TB SATA II
Iomega 1.5TB Ext USB 2.0
WD 2.0TB Ext USB 3.0
PSU
XFX Pro Series 850W Semi-Modular
Case
Gigabyte IF233
Cooling
1 x 120mm Front Inlet 1 x 120mm Rear Exhaust
Keyboard
Microsoft Comfort Curve Keyboard 3000 (USB)
Mouse
Microsoft Comfort Mouse 3000 for Business (USB)
Internet Speed
NetGear DG834Gv3 ADSL Modem/Router (Ethernet) ~4.0 Mb/s (O2)
Antivirus
Avast! 8.0.1497
Browser
IE 11
Other Info
Optical Drive: HL-DT-ST BD-RE BH10LS30 SATA Bluray
Lexmark S305 Printer/Scanner/Copier (USB)
WEI Score: 8.1/8.1/8.5/8.5/8.25
Asus Eee PC 1011PX Netbook (Windows 7 x86 Starter)
Hi,

You've already received some good advice regarding malware scans and the MAC filtering on your router. I'd like to make a few more suggestions:

1. Perform a scan for rootkits using this tool:

https://support.kaspersky.com/viruses/solutions?qid=208280684

2. Also ensure that no one can access your computer remotely, by following these steps:

Click :orb:
Right-click My Computer
Click Properties
Click Remote Settings

Ensure your panel looks like this:
capture.PNG
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Back
Top