The Web Design Group

... Making the Web accessible to all.

Welcome Guest ( Log In | Register )

> Task manager tries to connect to the internet
pandy
post Dec 24 2023, 07:40 PM
Post #61


🌟Computer says no🌟
********

Group: WDG Moderators
Posts: 20,734
Joined: 9-August 06
Member No.: 6



Why?

I've used TinyWall for several years, but haven't really looked at all the features. I found it can show all connections it has blocked the last 5 minutes. Taskmgr.exe has been blocked more than a hundred times - in 5 minutes. Why does it try to get out at all? Obviously it doesn't hurt anything that it's blocked, not that I've noticed anyway.

Note, TinyWall isn't a firewall in the usual sense. It sits on top Windows firewall and works by simply blocking all connections except those you OK. So when you first install it there's some fiddling. I think it's great, even if you have to remember to OK all new programs, but that's quickly done. I suppose it can be used as the only FW, but I keep the Windows one running. If anyone wants to try it, please note it doesn't work together with other firewall software, just the Windows one.

This is only the top of the list. You can see it's just 2 or 3 seconds between tries.

Attached Image

I don't know what the System process is about either. I didn't have to OK any system processes when I installed TinyWall, so it must have a built in whitelist.
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
 
Reply to this topicStart new topic
Replies
Christian J
post Jan 17 2024, 01:50 PM
Post #62


.
********

Group: WDG Moderators
Posts: 9,665
Joined: 10-August 06
Member No.: 7



Glasswire keeps longer logs.
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
pandy
post Jan 17 2024, 05:29 PM
Post #63


🌟Computer says no🌟
********

Group: WDG Moderators
Posts: 20,734
Joined: 9-August 06
Member No.: 6



OK. Can several firewalls run at the same time or do they fight?

Today a nasty app called bigo live opened on my phone. It's on Google Play, so assumedly a legit live streaming app. But all I saw on the splash screen were big boobs and tushies. That's the first time I have had an app install on my phone without my consent. How does that happen? I hardly ever use my phone for the web. I don't even read email on it. I use it for SMS and a hand-full of apps that I've used for ages.

WTF is going on? I'm beginning to feel stalked here. ninja.gif
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
Christian J
post Jan 17 2024, 06:44 PM
Post #64


.
********

Group: WDG Moderators
Posts: 9,665
Joined: 10-August 06
Member No.: 7



QUOTE(pandy @ Jan 17 2024, 11:29 PM) *

OK. Can several firewalls run at the same time or do they fight?

No idea, FWIW I've only used it to monitor traffic, not block.

Maybe Pi-hole could be used as well for monitoring? Since it runs on its own hardware it won't fight anything.

QUOTE
That's the first time I have had an app install on my phone without my consent. How does that happen? I hardly ever use my phone for the web. I don't even read email on it. I use it for SMS and a hand-full of apps that I've used for ages.

Could it be that one of your old apps has changed owner, and a recent update by the new owner has changed its functionality?

Nowadays I'm feeling very reluctant to update apps for this reason, and because even legit developers may suddenly start displaying ads, change functionality etc.


User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
pandy
post Jan 17 2024, 10:14 PM
Post #65


🌟Computer says no🌟
********

Group: WDG Moderators
Posts: 20,734
Joined: 9-August 06
Member No.: 6



QUOTE
No idea, FWIW I've only used it to monitor traffic, not block.


So I can tun off some features? I'll try it tomorrow.

I had a connection monitoring program at some point. In those days I wouldn't even have ran Windows firewall or AV. Today I'm so tired of everything and just make do with what's there.


QUOTE
Could it be that one of your old apps has changed owner, and a recent update by the new owner has changed its functionality?


I don't think so. It was among "recently installed" or what it's called. But I found that later. It just splat open from nowhere. I thought it was FF with a porn site loaded and wondered how that happened. And I don't have any apps that are even remotely similar. I just have boring things like map apps, photography related apps, bird and flower recognition apps, apps that list historical places... Things like that. Please don't tell anyone. blush.gif

This is crazy. I think it's 10 or 15 years ago I had a virus that actually did something (I don't count the odd attachment that can't do anything if you don't click it) and I've never had anything on my phone. Now it's something new each day.

BTW I got nothing in the systemprofile folder today. There is no system to this.
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
Christian J
post Jan 18 2024, 07:29 AM
Post #66


.
********

Group: WDG Moderators
Posts: 9,665
Joined: 10-August 06
Member No.: 7



QUOTE(pandy @ Jan 18 2024, 04:14 AM) *

QUOTE
No idea, FWIW I've only used it to monitor traffic, not block.


So I can tun off some features? I'll try it tomorrow.

Maybe blocking requires the paid version, can't remember.


QUOTE
QUOTE
Could it be that one of your old apps has changed owner, and a recent update by the new owner has changed its functionality?


I don't think so. It was among "recently installed" or what it's called.

No I meant that one of the old trusted apps may have changed owner, and the new owner sends an update that makes it install more apps. I recall some apps may have permission for that (outrageous as it sounds), not sure.

QUOTE
It just splat open from nowhere.

It wasn't some kind of overlay screen from another app?
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
pandy
post Jan 18 2024, 05:58 PM
Post #67


🌟Computer says no🌟
********

Group: WDG Moderators
Posts: 20,734
Joined: 9-August 06
Member No.: 6



QUOTE
No I meant that one of the old trusted apps may have changed owner, and the new owner sends an update that makes it install more apps. I recall some apps may have permission for that (outrageous as it sounds), not sure.


Didn't know that.

QUOTE

It wasn't some kind of overlay screen from another app?


No. It was among recently installed apps.

I haven't got a single file in systemprofile today either. I haven't done anything that can have put an end to it.

User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
Christian J
post Jan 18 2024, 07:33 PM
Post #68


.
********

Group: WDG Moderators
Posts: 9,665
Joined: 10-August 06
Member No.: 7



QUOTE(pandy @ Jan 18 2024, 11:58 PM) *

QUOTE
No I meant that one of the old trusted apps may have changed owner, and the new owner sends an update that makes it install more apps. I recall some apps may have permission for that (outrageous as it sounds), not sure.


Didn't know that.

It's likely not permitted by Google Play generally, but maybe Google's control is inefficient (especially for updates).

Not sure if this is tells everything, but if you go to:

CODE
Settings > Apps & Notifications > Advanced > Special App Access > Install unknown apps

the listed apps should have their permissions shown (none allowed in my case).

unsure.gif



User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
pandy
post Jan 19 2024, 01:44 AM
Post #69


🌟Computer says no🌟
********

Group: WDG Moderators
Posts: 20,734
Joined: 9-August 06
Member No.: 6



None? Don't you use your phone for anything?

I never checked. Just uninstalled it. The permission choices are so limited they feel like bogus anyway.
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
Christian J
post Jan 19 2024, 08:13 AM
Post #70


.
********

Group: WDG Moderators
Posts: 9,665
Joined: 10-August 06
Member No.: 7



QUOTE(pandy @ Jan 19 2024, 07:44 AM) *

None? Don't you use your phone for anything?

It's (allegedly) a list of apps that are allowed to install other apps, of course I don't allow that. cool.gif Or maybe "unknown" means apps outside the Play store?

QUOTE
I never checked. Just uninstalled it.

I meant maybe you can see which of your old apps that had permission to install Bigo Live. That old app should still be in the list.

QUOTE
The permission choices are so limited they feel like bogus anyway.

Yeah, under "Special app access" the summary on my phone says "1 app can use unrestricted data", but in the actual list no app like that is shown, not even when I enable "Show system". Seems reassuring. wacko.gif
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
pandy
post Jan 19 2024, 09:53 PM
Post #71


🌟Computer says no🌟
********

Group: WDG Moderators
Posts: 20,734
Joined: 9-August 06
Member No.: 6



Where do you find that list? I'm only aware of the ridiculously few and unspecific permissions for individual apps.
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
pandy
post Jan 20 2024, 05:52 AM
Post #72


🌟Computer says no🌟
********

Group: WDG Moderators
Posts: 20,734
Joined: 9-August 06
Member No.: 6



Today systemprofile filled up again.

I made a mistake about the time stamps. I orignally hade files from early 2023 until now. So I thought that was the dates the files were copied to that folder and showed how long this has been going on. Most of today's files have a time stamp from this morning, but a bunch of them are much older, the oldest from 2012! So in reality I have no idea when it started.

I have 8 copies of the one from 2012, all of them have the same time stamp, to the second. The file doesn't exist elsewhere on the computer. It's a freaking DHL logo.

Gaaah! IPB Image
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
Christian J
post Jan 20 2024, 08:20 AM
Post #73


.
********

Group: WDG Moderators
Posts: 9,665
Joined: 10-August 06
Member No.: 7



QUOTE(pandy @ Jan 20 2024, 11:52 AM) *

It's a freaking DHL logo.

Maybe it comes from an email? Either an email that has later been deleted, or maybe the image was hosted remotely before being copied to Windows.

The attachment didn't work. mellow.gif
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
pandy
post Jan 21 2024, 01:02 AM
Post #74


🌟Computer says no🌟
********

Group: WDG Moderators
Posts: 20,734
Joined: 9-August 06
Member No.: 6



QUOTE(Christian J @ Jan 20 2024, 02:20 PM) *

Maybe it comes from an email? Either an email that has later been deleted, or maybe the image was hosted remotely before being copied to Windows.

Yes, everything does. Attachments, embedded pictures, eml files...

QUOTE

The attachment didn't work. mellow.gif


I know. It was just the GIF. I uploaded it elsewhere but forgot to remove the attachment here. blush.gif
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post

Posts in this topic
pandy   Task manager tries to connect to the internet   Dec 24 2023, 07:40 PM
Christian J   Maybe its telemetry, but the IP 91.92.240.95 (91.9...   Dec 25 2023, 06:15 AM
pandy   I don't know. But it's the same now and I ...   Dec 25 2023, 08:20 AM
pandy   I have 16 copies of taskmgr.exe. One of them is in...   Dec 25 2023, 08:33 AM
pandy   OK. The one in the program directory is different ...   Dec 25 2023, 08:59 AM
pandy   Fynny thing. When I googled LkIropI.exe there was ...   Dec 25 2023, 09:04 AM
Christian J   I have 16 copies of taskmgr.exe. One of them is i...   Dec 27 2023, 09:28 AM
pandy   Which program's directory? Is that program tr...   Dec 27 2023, 10:45 AM
pandy   That went well. :wacko:   Dec 27 2023, 10:50 AM
pandy   On the Details tab in Task Manger I see 6 Taskmgr....   Dec 27 2023, 11:04 AM
pandy   Gaah! Now it couldn't be deleted because i...   Dec 27 2023, 11:13 AM
pandy   Nope. Didn't come back. But the mystery contin...   Dec 27 2023, 11:40 AM
Christian J   That went well. :wacko: You can't see wh...   Dec 27 2023, 12:18 PM
pandy   Nope. I don't know how to do that. I know ther...   Dec 27 2023, 01:53 PM
pandy   I saved a zipped up copy of the one in Roaming, bu...   Dec 27 2023, 07:11 PM
pandy   Tried ClamWin that didn't find anything. Then...   Dec 27 2023, 10:21 PM
pandy   I downloadef a free version of one of the software...   Dec 27 2023, 11:06 PM
pandy   It was pretty fast. I set it to scan everything - ...   Dec 28 2023, 10:38 AM
pandy   That was quickly done. The only possible one is al...   Dec 28 2023, 11:25 AM
Christian J   https://www.f-secure.com/v-descs/trojan-js-cryxos...   Dec 28 2023, 01:03 PM
pandy   [quote name='pandy' post='146867' date='Dec 28 20...   Dec 28 2023, 10:35 PM
pandy   Here we go again. Is this really a legit warning f...   Jan 10 2024, 08:08 AM
pandy   Gaah! Now image uploads don't work again...   Jan 10 2024, 08:11 AM
Christian J   [quote name='Christian J' post='146853' date='Dec...   Dec 27 2023, 12:17 PM
Christian J   Yeah, Limenet is odd. I don't know exactly wh...   Dec 27 2023, 09:27 AM
Christian J   Never heard that Firefox displays virus warnings (...   Jan 10 2024, 08:25 AM
pandy   Never heard that Firefox displays virus warnings ...   Jan 10 2024, 09:01 AM
pandy   Got the menu!   Jan 10 2024, 09:07 AM
Christian J   Never heard that Firefox displays virus warnings...   Jan 10 2024, 09:14 AM
pandy   But how does it work? If it's just a URL the b...   Jan 10 2024, 11:05 AM
Christian J   But how does it work? If it's just a URL the ...   Jan 10 2024, 01:09 PM
pandy   But I did, just before this started. I googled som...   Jan 10 2024, 07:39 PM
pandy   My computer oddities continues. I'm short of s...   Jan 12 2024, 05:57 PM
pandy   OK. I discovered that if I move the files out of t...   Jan 12 2024, 06:16 PM
pandy   This is nuts. I've been deleting like crazy. I...   Jan 12 2024, 08:49 PM
Christian J   So I searched C for .pdf. And found a shitload in...   Jan 13 2024, 07:39 AM
Christian J   BTW, have you checked if Disk Cleanup or similar r...   Jan 13 2024, 10:08 AM
pandy   I'm scared of automatic cleanup. I deleted the...   Jan 13 2024, 11:51 AM
pandy   Oh yes. I had 5 files. Fetched mail and now I have...   Jan 13 2024, 12:16 PM
Christian J   I'm scared of automatic cleanup. Why? I coul...   Jan 13 2024, 01:22 PM
pandy   [quote name='pandy' post='146910' date='Jan 13 20...   Jan 13 2024, 02:16 PM
pandy   The plot thickens. I didn't get many more file...   Jan 14 2024, 07:50 AM
Christian J   When I started email today I once again got a lot...   Jan 14 2024, 07:56 AM
pandy   But it hasn't done that in a long time. It di...   Jan 14 2024, 08:51 AM
pandy   Forgot to say. I had hopes at first after installi...   Jan 14 2024, 08:57 AM
pandy   Found a tip about ProcessExplorer in a thread abou...   Jan 14 2024, 09:11 AM
pandy   Nah. It just lists active processes and tells you ...   Jan 14 2024, 09:20 AM
pandy   I caught it. :shades: I used another Sysinternal...   Jan 14 2024, 10:39 AM
pandy   I emptied the folder and now 4 new files are creat...   Jan 14 2024, 10:47 AM
Christian J   The right field that's partly hidden in the f...   Jan 14 2024, 12:35 PM
pandy   The sync part seems related to the problem anyway.   Jan 14 2024, 01:22 PM
Christian J   Maybe some process is gathering suitable files for...   Jan 14 2024, 03:00 PM
pandy   Yes, that's what I was touching on before. A t...   Jan 14 2024, 03:59 PM
pandy   My conclusion was wrong. Yesterday it didn't h...   Jan 16 2024, 10:30 AM
Christian J   Same time of day? Perhaps it tries to do it a cert...   Jan 16 2024, 05:28 PM
pandy   No, I don't think it was the same time. When s...   Jan 16 2024, 07:56 PM
Christian J   Glasswire keeps longer logs.   Jan 17 2024, 01:50 PM
pandy   OK. Can several firewalls run at the same time or ...   Jan 17 2024, 05:29 PM
Christian J   OK. Can several firewalls run at the same time or...   Jan 17 2024, 06:44 PM
pandy   So I can tun off some features? I'll try it ...   Jan 17 2024, 10:14 PM
Christian J   So I can tun off some features? I'll try it...   Jan 18 2024, 07:29 AM
pandy   Didn't know that. No. It was among recent...   Jan 18 2024, 05:58 PM
Christian J   Didn't know that. It's likely not perm...   Jan 18 2024, 07:33 PM
pandy   None? Don't you use your phone for anything? ...   Jan 19 2024, 01:44 AM
Christian J   None? Don't you use your phone for anything? ...   Jan 19 2024, 08:13 AM
pandy   Where do you find that list? I'm only aware of...   Jan 19 2024, 09:53 PM
pandy   Today systemprofile filled up again. I made a mis...   Jan 20 2024, 05:52 AM
Christian J   It's a freaking DHL logo. Maybe it comes fr...   Jan 20 2024, 08:20 AM
pandy   Maybe it comes from an email? Either an email tha...   Jan 21 2024, 01:02 AM
Christian J   Where do you find that list? I'm only aware o...   Jan 20 2024, 08:18 AM
pandy   Where do you find that list? I'm only aware ...   Jan 21 2024, 12:59 AM


Reply to this topicStart new topic
7 User(s) are reading this topic (7 Guests and 0 Anonymous Users)
0 Members:

 



- Lo-Fi Version Time is now: 16th May 2024 - 10:14 PM