Hidden process since last Windows update

Read Only

New member
Local time
1:21 PM
Messages
49
This is a thread addressed to security experts willing to help.

Ever since I installed the latest windows security updates, my firewall is detecting a hidden process acting as a medium when I try to go online with some applications. I call it hidden process because my firewall is unable to tell the app name and its location, which is quite unusual.

If I refuse internet access to that hidden process, then certain applications fail to go online.

This is quite worrying because it happens with an encrypted sandbox and encrypted openoffice documents. So since the latest windows update, both virtualbox and openoffice can no longer go online without that hidden process acting as a medium.

Could somebody give me indications about how I could identify that process? My system is Win 7 x64 SP1 up to date and nothing was detected by a full scan from a leading antivirus software.
 

My Computer

OS
Windows 7 Professional x64

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HomieJunker
OS
W7 Prof 64 bit
CPU
i7-3770k
Motherboard
Sabertooth Z77
Memory
G.Skill Sniper 1866 16 GB
Graphics Card(s)
Evga GTX 770
Sound Card
Sound Blaster Z
Monitor(s) Displays
Asus VG278HE
Screen Resolution
1920 x 1080
Hard Drives
4 Seagate Barracudas 250 GB
2 Intel® X25-M 160GB
PSU
Corsair H1000X
Case
Lian-Li A77B
Cooling
Phantek 120 dual fans
Keyboard
Corsair K70 RGB
Mouse
Logitech G502
Internet Speed
FiOS Quantum
Antivirus
Avira
Browser
Chrome
I wish it was that easy, but I wouldn't need to post about it then.

The process is completely hidden to regular tools, it is probably located in the RAM and encrypted. I will need something a lot more advanced to identify it.
 

My Computer

OS
Windows 7 Professional x64
Does the firewall log not even show a Process ID?
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
Log of the process

U/D#
U-44941

Date
25/11/14,19:13:07

Rule
APP: Blocked

Type
EXE

Address/Application
?

Compliment
UNKNOWN
 

My Computer

OS
Windows 7 Professional x64
And if you compare that to a log entry for another not "hidden" file, can you see the PID?

Don't know what firewall you have but Windows Firewall that I use shows a blocked connection like this:
FWblock.png
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
I have a very basic firewall, no it does not show process id unfortunately, but it does its firewall job with high reliability, and unlike other "advanced" firewalls such as comodo, it has never failed preventing an app going online.
 

My Computer

OS
Windows 7 Professional x64

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
I doubt anything an antivir is going to help, I have already tried that, first I'm going to uninstall the windows security updates one by one to identify the one that is inserting the hidden process, then I'll look for a security expert site.

Thank guys see you.
 

My Computer

OS
Windows 7 Professional x64
Hello Read Only:

I would be appropriately surprised if any of your computer's hidden Internet activities could elude monitoring by https://www.wireshark.org.

Good hunting.
 

My Computer

Computer type
PC/Desktop
OS
W7
Back
Top