Share via

PC is being remotely accessed, Event Viewer logs

Anonymous
2022-04-03T04:30:05+00:00

My PC is being remotely accessed/hacked, Im pretty sure these Events in Event Veiwer are from them, but I dont know what they mean, or how they're getting access to my PC, can you guys see how theyre doing it from these logs? ill copy/paste them

Device ROOT\NET\0000 was started.

Driver Name: oem6.inf

Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}

Service: aswTap

Lower Filters: 

Upper Filters: 

Log Name: Microsoft-Windows-Kernel-PnP/Device Configuration

Kernel-PnP 2/24/2022 12:39:37 AM

Event ID: 410

User: System Computer: Desktop-censord letter/numbers

Device ROOT\NET\0000 was configured.

Driver Name: oem6.inf

Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}

Driver Date: 07/02/2012

Driver Version: 9.0.0.10

Driver Provider: TAP-Windows Provider V9

Driver Section: aswTap.ndi

Driver Rank: 0xFF0000

Matching Device Id: aswTap

Outranked Drivers: 

Device Updated: true

Parent Device: HTREE\ROOT\0

Event ID: 400

Device ROOT\NET\0000 was deleted.

Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}

Event ID: 420

Windows PowerShell

Details: 

ProviderName=Certificate

NewProviderState=Started

SequenceNumber=15

HostName=ConsoleHost

HostVersion=5.1.19041.1320

HostId=61bf9dba-7118-4245-8076-e6399876c9b7

HostApplication=C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoExit -Command Help Set-ExecutionPolicy

EngineVersion=5.1.19041.1320

RunspaceId=cb614ae6-07e9-425f-a0c8-140a374f9fbf

PipelineId=13

CommandName=

CommandType=

ScriptName=

CommandPath=

CommandLine=

Event ID:600

Engine state is changed from None to Available. 

Details: 

NewEngineState=Available

PreviousEngineState=None

SequenceNumber=13

HostName=ConsoleHost

HostVersion=5.1.19041.1320

HostId=61bf9dba-7118-4245-8076-e6399876c9b7

HostApplication=C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoExit -Command Help Set-ExecutionPolicy

EngineVersion=5.1.19041.1320

RunspaceId=cb614ae6-07e9-425f-a0c8-140a374f9fbf

PipelineId=

CommandName=

CommandType=

ScriptName=

CommandPath=

CommandLine=

Event ID:400

Provider "Variable" is Started. 

Details: 

ProviderName=Variable

NewProviderState=Started

SequenceNumber=11

HostName=ConsoleHost

HostVersion=5.1.19041.1320

HostId=61bf9dba-7118-4245-8076-e6399876c9b7

HostApplication=C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoExit -Command Help Set-ExecutionPolicy

EngineVersion=

RunspaceId=

PipelineId=

CommandName=

CommandType=

ScriptName=

CommandPath=

CommandLine=

Event ID:600

ProviderName=Function

NewProviderState=Started

SequenceNumber=9

HostName=ConsoleHost

HostVersion=5.1.19041.1320

HostId=61bf9dba-7118-4245-8076-e6399876c9b7

HostApplication=C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoExit -Command Help Set-ExecutionPolicy

EngineVersion=

RunspaceId=

PipelineId=

CommandName=

CommandType=

ScriptName=

CommandPath=

CommandLine=

Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0x00FFB4CAB5AD.  The following error occurred: 0x79. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Dhcp-Client

Event ID:1001

User: Local Service

OP Code: IpAddressNotAssigned

Microsoft-Windows-RemoteAssistance/Operational

Remote Assistance started with:        as the command line parameters.

Diagnosis Repro Attempt resulted in a failure.

Remote Desktop Services: Shell start notification received:

User: DESKTOP-xxxxxx\TorreyDesktop

Session ID: 2

Source Network Address: LOCAL

Microsoft-Windows-TerminalServices-LocalSessionManager/Operational

Event ID:22

Remote Desktop Services: Session logon succeeded:

User: DESKTOP-3H16OGA\TorreyDesktop

Session ID: 2

Source Network Address: LOCAL

Event ID:21

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

5 answers

Sort by: Most helpful
  1. Anonymous
    2022-04-05T17:58:52+00:00

    Torrey -

    While you have me here to help why don't you back up your files to quarantine and wipe the drive to do a gold standard Clean Install which compiles the best possible Install of Windows which will stay that way as long as you stick with the tools and methods given, has zero reported problems, and is better than any amount of money could buy: http://answers.microsoft.com/en-us/windows/wiki.... Read over it first, take notes, ask back any questions so you're prepared.

    To create bootable Windows 10 Installation Media (on another PC if necessary) install Media Creation tool and follow the steps toward the bottom of the download page here in the section "Using the tool to create installation media:"

    https://www.microsoft.com/en-US/software-downlo...

    Insert media, boot it by powering up PC while pressing the BIOS Boot Menu Key for your PC maker given in this chart: https://www.sysnative.com/forums/hardware-tutor...

    If the media won't boot you may need to enter BIOS/UEFI Setup (pressing key given in chart in link above) to turn off Fast Boot or Fast Startup first.

    Choose the boot device as a UEFI device if offered, then on second screen choose Install Now, then Custom Install, then at the drive selection screen delete all partitions down to Unallocated Space to get it cleanest, select the Unallocated Space, click Next to let it create and format the needed partitions and start install - this makes it foolproof.

    During the account setup phase you can disconnect from the internet to force it to let you create a Local Account to leave your MS account off for now. If you need OneDrive or another feature you can sign into it individually so that Windows is not as easily hacked.

    I would use two factor authentication to sign into Windows and your financial accounts: https://www.windowscentral.com/how-set-two-step.... Follow all of the other steps in the guides I gave you in my first post.

    You will get and keep the best possible install to the exact extent you stick with the steps, tools and methods in the linked tutorial. It's a great learning experience that will make you the master of your PC because you will learn everything that works best and how to apply it with your own hands.

    Feel free to ask back any questions. Report back results for more steps if necessary.

    ______________________________________________

    Standard Disclaimer: There are links to non-Microsoft websites. The pages appear to be providing accurate, safe information. Watch out for ads on the sites that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the sites before you decide to download and install it.

    5 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-04-03T05:16:21+00:00

    Hi Torrey. I'm Greg, 10 years awarded Windows MVP, specializing in Installation, Performance, Troubleshooting and Activation, here to help you.

    No need to worry about the Events shown, they are routine attempt to connect to internet, which sometimes fails and has to try again and is logged. If you didn't notice an interruption in your internet service, it's a negligible error, like 90% of the errors in Event Viewer - which are really only useful if you have actual performance problems and need to use it to troubleshoot them.

    What makes you think you're being hacked? Here are the best guides to read up on how to know if you're being hacked, prevent it or react:

    https://preyproject.com/blog/en/have-i-been-hac...

    https://www.windowscentral.com/signs-pc-hacked

    https://www.csoonline.com/article/2457873/signs...

    Let's go over the PC to make sure it's not infected with malware or spyware, has unwanted remote connection apps or browser extensions:

    To check most thoroughly for infection and any resulting System damage, Download, install and run a full scan with the most powerful on-demand free scanner Malwarebytes:

    https://www.malwarebytes.com/mwb-download/ Make sure to only choose the Free version.

    In the Malwarebytes Settings (gear icon) > Security tab set it to include scanning for Rootkits.

    If necessary run it in Safe Mode with Networking (to have internet), or Safe Mode accessed by one of these methods: https://www.digitalcitizen.life/4-ways-boot-saf.... These require a password and not PIN to access.

    Clean up anything found, restart PC and then run again until it comes up clean.

    Then download, install and run a full scan with AdwCleaner:

    http://www.bleepingcomputer.com/download/adwcle...

    Remove whatever it finds.

    Check for anything found but is still left over in Settings > Apps > Apps & Features, and C:\Program Files and C:\Program Files(86) to uninstall or delete them. I can guide you how to do this if there are problems.

    Also in each of your browser's Extensions, Home Page settings, Search service or Add-On's as shown here: https://www.computerhope.com/issues/ch001411.htm

    to disable anything you didn't add yourself and are sure you need. Ask back if in doubt.

    Then check for damaged System files by running System File Checker and DISM from Step 10 in this checklist:

    https://answers.microsoft.com/en-us/windows/for...

    If completing all of Step 10 in above Checklist doesn't fix it then run a Repair Install which reinstalls WIndows while keeping your files, programs and most settings in place, by installing the Media Creation Tool from this link: https://www.microsoft.com/en-US/software-downlo..., open the tool and choose Upgrade This PC Now. This will solve most problems and also bring it up to the latest version which you need anyway and by the most stable method.

    If you want to keep Malwarebytes as an on-demand scanner then you can turn off its Real Time trial version using the slider buttons on it's front panel. I recommend it as the #1 tool for your toolbox. For best WIndows performance, use built-in Defender which gives adequate real-time protection.

    Feel free to ask back any questions. Report back results for more steps if necessary.

    ______________________________________________

    Standard Disclaimer: There are links to non-Microsoft websites. The pages appear to be providing accurate, safe information. Watch out for ads on the sites that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the sites before you decide to download and install it.

    5 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2022-04-03T14:03:27+00:00

    Remote Desktop Services: Session logon succeeded:

    User: DESKTOP-3H16OGA\TorreyDesktop

    Session ID: 2

    Source Network Address: LOCAL

    Event ID:21

    Remote Assistance started with:        as the command line parameters.

    Microsoft-Windows-RemoteAssistance/Operationa

    logged: 4/2/2022 1:20:30 PM

    source: RemoteAssistance

    EventID: 13

    Level: Verbose

    User: DESKTOP-3H16OGA\TorreyDesktop Computer:DESKTOP-3H16OGA

    This I'm sure is proof as I don't have any remote access that I allowed, but the User: DESKTOP-3H16OGA\TorreyDesktop is my pc.

    Ill start with malwarebytes scan then AdwCleaner

    4 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2022-04-05T16:31:08+00:00

    Ok I ran malwarebytes and it detected 1rootkit and deleted it.

    I cant access my task manager or event veiwer anymore, I cant even save a screenshot to my picture folder, Im sure they saw me doing this and messed a bunch of stuff up, and yea I also had my net connection turned off and on numerous times recently. The AdWCleaner wont run either.

    Network Error

    Winindows cannot access

    C:/Windows/System32/eventvwr.msc

    and when I click on diagnose I get

    An error occurred while troubleshooting

    A Problem is preventing the troubleshooter from starting

    Under Settings there were a few Xbox apps that i didnt install

    Xbox Game Bar

    Xbox Networking

    Connection status

    Internet connection: Connected

    Xbox live services Up and Running

    I also ran netstat -a

    theres like 50 TCP addresses LISTENING and about 25 ESTABLISHED, I didnt wanna post here cuz the addresses.

    I dont know what to to now, I really wanted to backup event veiwer logs atleast then prolly a fresh install of windows. I really wana find a way to getto and backup those event viewer logs.

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2022-04-03T19:54:15+00:00

    You can disable Windows 10 remote assistance here:

    https://www.windowscentral.com/how-disable-remo...

    Keep me posted on your progress as I will be here to help until the case is resolved.

    1 person found this answer helpful.
    0 comments No comments