do these result look suspicious?
comodo was showing some high upload and download speeds, and even though my cousin laptop usies wifi i saw no program that could trigger that
windows wasnt being updated etc
Follow this thread and attach the logs (Adwcleaner, OTL and Aswmbr)
Just use process explorer to examine what services are making those connections.
There is also this program.
http://svchostviewer.codeplex.com/
Also check out this site to see if you can cut down some of your services.
http://www.blackviper.com/
Thanks.
@TwinHeadedEagle thanks i always run adwcleaner first and its clean, i didnt run avastantirootkit as thats a bit tricky (don’t wanna delete something good) but kaspersky full scanner, eset, hitman pro, and tddsskiller came back clean
@Arnold72 thx, i use blackviper all the time and thanks for the svchostviewer (i saw a similar post on bleepingcomputer in 2010 but the link was outdated)
right now i’m using killswitch (since i use comodo) and one of the ips was traced to comcast and another was private (as looking at registered port to see if the ones seen are known for malicious activity)
so far blocked them, and no windows service was affected