Windows 7 x64 CryptSvc under Svchost uploading data

Page 3 of 4 FirstFirst 1234 LastLast

  1. Posts : 129
    Windows 7 Ultimate 64Bit (SP1)
    Thread Starter
       #21

    OK so it has been a while now on this and since setting it to Not allow remote connection I have been unable to see any more erratic activity as before. So what now? Re-enable it and if it has erratic activity like that again does that mean someone is trying to access my machine? Someone trying to access my my machine would be an INCOMING connection and show as yellow on the network meter would it not?
      My Computer


  2. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #22

    If it was my computer I would not activate it. You found the problem and then fixed the problem. I would leave it fixed. I would NOT allow AVG to have remote access to my computers.
    Last edited by Layback Bear; 29 Apr 2015 at 13:01. Reason: spelling
      My Computer


  3. Posts : 4,776
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
       #23

    Disable RDP?


    Layback Bear said:
    If it was my computer I would not activate it. You found the problem and then fixed the problem. I would leave it fixed. I would NOT allow AVG to have remove access to my computers.

    Agreed. Leave it disabled and only enable it on a when needed basis.
      My Computer


  4. Posts : 129
    Windows 7 Ultimate 64Bit (SP1)
    Thread Starter
       #24

    So its AVG that does all that weird uploading?
      My Computer


  5. Posts : 4,776
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
       #25

    Don't know that it's AVG. Looking at your AVG settings you've got them set correctly. That IP Address resolves to somewhere in Vietnam.

    Windows 7 x64 CryptSvc under Svchost uploading data-ipnetinfo.jpg

    Also read the article here: Remote Desktop (RDP) Hacking 101: I can see your desktop from here!

    What firewall do you use?
      My Computer


  6. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #26

    Good find Chris. Hanoi is scary.
    It's hard for me to believe that AVG is using Hanoi.
    Their must be some other bad thing in this system.
    The thing I would do if found something in my computer from Hanoi.

    I would suggest with a clean computer changing ALL passwords for everything. I would also suggest to notify all banks and credit card companies that your computer has been compromised.

    At that point I wouldn't take any chances. I would do a Clean Install.
      My Computer


  7. Posts : 129
    Windows 7 Ultimate 64Bit (SP1)
    Thread Starter
       #27

    Edit: Deleted/canceled post
      My Computer


  8. Posts : 4,776
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
       #28

    Okay so I know you deleted your post but what would be really interesting is to get the process name from the process PID you gave. The ip address from your deleted post resolves to an OVH server and OVH have faced criticism for allowing malware and hackers to use their servers. Personally I run Peerblock and all OVH server ip address ranges are blocked. There's no good reason for your machine to be connecting to any OVH server.
      My Computer


  9. Posts : 129
    Windows 7 Ultimate 64Bit (SP1)
    Thread Starter
       #29

    Did you get my entire post in a reply email? It had the netstat -ano results in it. I thought I had RDP disabled but I must have renabled it to see if it would happen again after a long time of no activity. I guess I forgot to disable it again. Once I had RDP disabled again I deleted that post.

    If you got my full reply in an email is the IP you are talking about now the one I said was in Quebec Canada? If so The process associated with 4488 PID was svchost and the crptsvc process was under that host.

    Definitely RDP related.
      My Computer


  10. Posts : 4,776
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
       #30

    Seems like you've nailed it. If disabling RDP does the trick then I wouldn't worry about it. As far as disabling cryptsvc sevice is concerned - it's not a good idea if you need to keep windows updates working.

    Also I got the email notification and details you posted were contained in the email.
      My Computer


 
Page 3 of 4 FirstFirst 1234 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 15:06.
Find Us