Question Possible hacker download attempt ?

Page 2 - Seeking answers? Join the Tom's Hardware community: where nearly two million members share solutions and discuss the latest tech.

Cpt Snake

Reputable
Jan 20, 2022
133
6
4,585
OS: Windows 10

About every seven to ten days, I get a message that states:

"Sorry need to update your computer", and starts to download from [to?] my computer. The message is on a light blue background, with a tilted sad face in a block. I immediately shut down my computer and restart.
Is this a hacker attempting to gather information? It does not appear to be a MS update. It's only when I am on the internet. Any advise is appreciated. Thanks
 
I will make the suggestion to look in Reliability History/Monitor and Event Viewer.

Either one or both tools may be capturing some error code, warning, or even an informational event just before or at the time those messages appear.

Start with Reliability History/Monitor. It has a time line format that you can use to identify any 7 -10 day patterns.

Also look in Task Scheduler: There may be some task pre-scheduled or triggered that originates the messages.

Especially since "things/download" just happened.
 
OK, the Download hacker is back. Installed Bitdefender yesterday and I keep getting this alert message below multiple times an hour.

Suspicious connection blocked
34 minutes ago
Feature:Online Threat Prevention
msedge.exe attempted to establish a connection relying on an untrusted certificate to wpad. We blocked the connection to keep your data safe since untrusted certificates are issued by unrecognized Certificate Authorities.

What I don't understand is my Win 10 allows this download. Nothing is allow to be downloaded without my permission.
 
OK, the Download hacker is back. Installed Bitdefender yesterday and I keep getting this alert message below multiple times an hour.

Suspicious connection blocked
34 minutes ago
Feature:Online Threat Prevention
msedge.exe attempted to establish a connection relying on an untrusted certificate to wpad. We blocked the connection to keep your data safe since untrusted certificates are issued by unrecognized Certificate Authorities.

What I don't understand is my Win 10 allows this download. Nothing is allow to be downloaded without my permission.
Edge can be a problem. What I would recommend is that you look at the sites that have requested permissions. The URL is edge://settings/content/all
If there is anything that looks odd, I would wipe out the cached data. You can get to that by clicking on the three dots on the top right. Click on History, then click on the trash can at the top. That will bring up the delete browsing data. SCROLL DOWN and make sure that "Site permissions" is checked. Make sure the time is set to "All Time". delete the data. See if that clears up your warning.
 
OK, Thanks to all first. I know it's a pain. Update, the download hack attacks my computer on or off the internet. I does it's download then restarts my computer without a prompt. I've got the internet quick disconnect set up. I can save to the clipboard. I can access the clip board, but having problems saving the "PINNED" image.
 
Yes scanned with Glary Malware, Bitdefender Plus, Windows anti virus. Nothing showed. Windows defender states, no action required. Ran Command, sfc/scannow today showed nothing.
 
OK, Thanks, You guys on Tom's Hardware are great...Really! Thanks for helping an old guy that was born before TV was invented. I do my best, but thanks to you guy, it makes it easier. I really appreciate the help. :jakebarnssmiley:
 
  • Like
Reactions: COLGeek
Well, I thought I was done with the Hack Thing, but not so. I just cleaned my computer today and before I could connect the Internet quick disconnect, it got me in the middle of a game on Steam. I am convinced it's coming from Microsoft. The little time I had I read the message, "microsoft/windows/stop code". This started with my last windows update on 5/16/25. After the interruption, I installed the New Provisional Windows Update. Maybe that will fix the problem. It took over 40 min to install. Anyway, I'll be back.
 
Well, I thought I was done with the Hack Thing, but not so. I just cleaned my computer today and before I could connect the Internet quick disconnect, it got me in the middle of a game on Steam. I am convinced it's coming from Microsoft. The little time I had I read the message, "microsoft/windows/stop code". This started with my last windows update on 5/16/25. After the interruption, I installed the New Provisional Windows Update. Maybe that will fix the problem. It took over 40 min to install. Anyway, I'll be back.
Are you using your Microsoft account when you sign into Windows? Or are you using a local account?

What you have been describing is not a Windows Update sort of thing. It could be (as previously asked) a backup, if you are indeed using Onedrive, for example.
 
OK,finally got to read the hack thing. Something about a problem with my windows and it had to repair it. I gave up and restored an image with Macrium from 3/1/25. Lets see what happens
 
Thanks, I am using the Window 10 Microsoft account with local drive, not one drive. We need more info, I'll try to get it. I am using Malwarebytes, which did not stop it.
Local drive does not equal local account.

MS account refers to one you signed up for with Microsoft, to access their stuff, like Windows registration and the Microsoft Store, for example. Heck, to play Flight Simulator 2020 you have to be signed into your MS account.

A local account does not reach out to the network when you sign in. It is only on your system. Many users use a local account for day to day use. Only signing into MS accounts when absolutely needed. That is what I do and have both types on my PCs.

Your Macrium comment suggests you do perform backups locally and that you aren't using MS for their backup service. Correct?

By the way, aside from the 3/1/2025 image restore, is Windows fully updated? Do you have Windows Update running in its default mode? Are you using any applications to update drivers or other applications?
 
Yes, It takes an image of the date, saves it to a local hard drive, then one can re-image from the local hard drive to that date. Pretty easy, I keep my C drive almost bare, My games are on the D drive, E drive is a junk drawer.