Faded123 0 Posted May 16, 2024 Posted May 16, 2024 I have a issue so ESET has blocked 140 network things from a iPhone and ever since downloading eset and it’s blocking SSDP Discovery ever since it’s doing that Windows explorer and Command host has not been using upwards of 350Mb of ram daily on boot this block happened as soon as I connected to the WiFi would like to mention that it was one of command hosts processes not just all of it and these SSDP discovery is happening from a IPhone another time it said it was a Samsung we don’t own a Samsung or use one but one is connected to the WiFi I’m afraid we are a bot net but I don’t know what to do next and if it ran commands using svchost.exe in the background. The WiFi company said we are safe however my mom uses a poor password that makes us vulnerable to this despite persuading and trying to persuade her it’s not been changed. also Windows explore used to take up 350-400mb of ram ever since downloading eset which has blocked it it has used less ram and overall power on my entire pc. What should I do I’m lost. Should I factory reset the router will that fix the issues?
Faded123 0 Posted May 16, 2024 Author Posted May 16, 2024 Although I have been told not to worry about the usage of RAM the overall power used on my pc and the same processes have been less which makes me think that they could have used svchost.exe maliciously as I only just downloaded ESET to use it to scan after seeing the network block and knowing that my router hub was accessed recently I’m worried that instead of a malware infection it’s something for in-depth
Faded123 0 Posted May 16, 2024 Author Posted May 16, 2024 One final thing before waiting for reply , I’ve ran many AV scanners as said before and has been sure that there’s no files that are malware but am afraid there’s a possibility of evading detection as there’s a lot of them things in my system 32 config I don’t recognise and it seems like it’s hiding since if I go to the Directory I can’t find the files that are names SECURITY.LOG 1 and 2 and software log 1 and 2 and SAM.log 1 and 2 and some other and a lot of things are password protected and this never happened before
Faded123 0 Posted May 16, 2024 Author Posted May 16, 2024 SysInspector-FZ-240516-174553.zip heres a log
itman 1,924 Posted May 16, 2024 Posted May 16, 2024 Try disabling SSDP service. First, stop the service prior to disabling it. Then determine if all your Eset firewall blocking issues in regards to SSDP been resolved.
Faded123 0 Posted May 16, 2024 Author Posted May 16, 2024 How do I block SSDP service and if I haven’t done anything to try and resolve it how can it get resolved? Also what could it signify? Should I even bother also I think it could signify something if on boot my ram / process list is using less power then before I installed eset which started blocking the things
Faded123 0 Posted May 16, 2024 Author Posted May 16, 2024 How do I disable* Just now, Faded123 said: How do I block SSDP service and if I haven’t done anything to try and resolve it how can it get resolved? Also what could it signify? Should I even bother also I think it could signify something if on boot my ram / process list is using less power then before I installed eset which started blocking the things
Faded123 0 Posted May 16, 2024 Author Posted May 16, 2024 Final update : when trying to connect to the internet I don’t get any internet but this could be anything the main thing is the facts that it says there’s a network with the same name as ours and it’s different but that network has the Router my pc and a phone connected to it but the other network has all the iPhones connected to it they are completely different since the one I marked as MY network is showing no internet at all but the one that has WiFi which isn’t my network to it being on default settings has the router connected to it but when I look in my network there’s only 1 network to connect to and our network isn’t showing up they have the same name though I’m gonna do a restart on the WiFi and see what happens
itman 1,924 Posted May 16, 2024 Posted May 16, 2024 16 minutes ago, Faded123 said: How do I disable* https://learn.microsoft.com/en-us/answers/questions/1531024/how-to-permanently-disable-windows-update-service
Faded123 0 Posted May 16, 2024 Author Posted May 16, 2024 Okay but is this how to trouble shoot it ? What would disabling the service do and it’s not resolved bc this has happened last time where it blocked 10 IPS all private and blocked 3 remote devices
Faded123 0 Posted May 16, 2024 Author Posted May 16, 2024 8 minutes ago, Faded123 said: Final update : when trying to connect to the internet I don’t get any internet but this could be anything the main thing is the facts that it says there’s a network with the same name as ours and it’s different but that network has the Router my pc and a phone connected to it but the other network has all the iPhones connected to it they are completely different since the one I marked as MY network is showing no internet at all but the one that has WiFi which isn’t my network to it being on default settings has the router connected to it but when I look in my network there’s only 1 network to connect to and our network isn’t showing up they have the same name though I’m gonna do a restart on the WiFi and see what happens This is further confirmed by Avast saying that there’s 2 networks in network inspector
Faded123 0 Posted May 16, 2024 Author Posted May 16, 2024 5 minutes ago, Faded123 said: This is further confirmed by Avast saying that there’s 2 networks in network inspector One more thing this isn’t just SSDP discovery this is also a IP that gets blocked in other local applications and on the remote device it said in details Application: svchost.exe 2 blocks had no rule 20 blocks had SSDP requests for svchost.exe
Faded123 0 Posted May 16, 2024 Author Posted May 16, 2024 5 minutes ago, Faded123 said: One more thing this isn’t just SSDP discovery this is also a IP that gets blocked in other local applications and on the remote device it said in details Application: svchost.exe 2 blocks had no rule 20 blocks had SSDP requests for svchost.exe Update : When restarting the internet on connect a new unknown device popped up and was blocked with a new IP
Recommended Posts