Windows 11 Events - could it be a virus?


spluff

New member
Local time
1:51 PM
Posts
3
OS
Windows 11
Hi all,

I noticed in EventViewer / System I was getting around 15 of events like these with different http://

EVENT ID 112 Attempted to reserve URL https://+:5986/wsman/. Status 0x0. Process Id 0x4 Executable path , User SYSTEM
EVENT ID 112 Attempted to reserve URL http://+:47001/wsman/. Status 0x0. Process Id 0x4 Executable path , User SYSTEM
EVENT ID 112 Attempted to reserve URL https://*:5358/. Status 0x0. Process Id 0x4 Executable path , User SYSTEM

They appear straight away after startup on a PC restart (not shutdown).

They look kinda dodgy to me as if its trying to connect to something? I needed to do a reinstall of Windows so I did it. This is also happening on a clean install of Windows 11.

Can you please have a look in Event Viewer - System section and see if you can see these kind of events?

Anyone have any idea what they are and if they are a virus or something i should be concerned about?

Kind regards
SpLuFF
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
This appears to be a command attempting to create a remote management link to a server.
Open a PowerShell console as admin and enter 'dir WSMan:\localhost\Service' without the quote marks, this will tell you the WSMAN settings and point to the folder in use on the local computer (your machine).
There may well be a valid reason for this setting to be active so don't just disable it or attempt to delete the folder without checking first.
 

My Computer My Computer

At a glance

Windows 11 Pro 22H2, build: 22621.521Intel i7-12700K 3.6GHz Base (5.0GHz Turbo)64GB DDR 3600MhzAsus Tuff RTX 3080 10GB OC
OS
Windows 11 Pro 22H2, build: 22621.521
Computer type
PC/Desktop
Manufacturer/Model
Scan 3XS Custom 1700
CPU
Intel i7-12700K 3.6GHz Base (5.0GHz Turbo)
Motherboard
Asus ProArt Creator B660 D4
Memory
64GB DDR 3600Mhz
Graphics Card(s)
Asus Tuff RTX 3080 10GB OC
Sound Card
Onboard Realtek
Monitor(s) Displays
Gigabyte G32QC 32inch 16:9 curved @2560 x 1440p 165Hz Freesync Premium Pro/ Dell SE2422H 24inch 16:9 1920 x 1080p 75Hz Freesync
Screen Resolution
2560 x 1440p & 1920 x 1080p
Hard Drives
WD SN570 1TB NVME (Boot), Samsung 870QVO 1TB (SSD), SanDisk 3D Ultra 500Gb (SSD) x2, Seagate 3Tb Expansion Desk (Ext HDD), 2x Toshiba 1Tb P300 (Ext HDD)
PSU
Corsair RM1000X Modular
Case
Corsair 4000D Airflow Desktop
Cooling
Corsair Hydro H150i RGB Pro XT 360mm Liquid Cooler, 3 x 120mm fans, 1x Exhaust
Keyboard
Microsoft Ergonomic
Mouse
Logitech G402
Internet Speed
800Mbs
Browser
Edge Chromium
Antivirus
Defender, Malwarebytes
I have the WsMan service(Windows Remote Management) but it is set to manual and the service is stopped. I see nothing in event viewer regarding it.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8655i9-10900 10 core 20 threads32 gbnone-Intel UHD Graphics 630
    OS
    Windows 11 Pro 25H2 26200.8655
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    2x1tb Solidigm m.2 nvme /External drives 512gb Samsung m.2 sata+2tb Kingston m2.nvme
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    #1 Edge #2 Firefox
    Antivirus
    Defender+MWB Premium
  • At a glance

    Windows 11 Pro 24H2 26200.8457AMD Ryzen 7 6800U32 gbintegrated
    Operating System
    Windows 11 Pro 24H2 26200.8457
    Computer type
    PC/Desktop
    Manufacturer/Model
    Beelink Mini PC SER5
    CPU
    AMD Ryzen 7 6800U
    Memory
    32 gb
    Graphics card(s)
    integrated
    Sound Card
    integrated
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Crucial nvme
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    still too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender
    Other Info
    System 3 is non compliant Dell 9020 i7-4770/24gb ram Win11 PRO 26200.8457
When i run that command it says WinRM service is not started currently. Running this command will start the WinRM service....

I clicked NO
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Ok, so the service is not running and you don't need to worry about the connection being made. If you want to dig further you can try to find out what is trying to reserve that URL, it could be an app or srvice that is perfectly valid, like Corsair iCue or a printer driver, looking to connect to the upgrade center or similar.
A combination of Autoruns, Process Explorer and Process Monitor (parts of the Sysinternals suite, available for free through the MS Store) with appropiate filters set should pinpoint the culprit, then you can either keep things as they are or remove it if not needed.
If it just generates an entry in the event log and is non malicious I would just leave it as is.
 

My Computer My Computer

At a glance

Windows 11 Pro 22H2, build: 22621.521Intel i7-12700K 3.6GHz Base (5.0GHz Turbo)64GB DDR 3600MhzAsus Tuff RTX 3080 10GB OC
OS
Windows 11 Pro 22H2, build: 22621.521
Computer type
PC/Desktop
Manufacturer/Model
Scan 3XS Custom 1700
CPU
Intel i7-12700K 3.6GHz Base (5.0GHz Turbo)
Motherboard
Asus ProArt Creator B660 D4
Memory
64GB DDR 3600Mhz
Graphics Card(s)
Asus Tuff RTX 3080 10GB OC
Sound Card
Onboard Realtek
Monitor(s) Displays
Gigabyte G32QC 32inch 16:9 curved @2560 x 1440p 165Hz Freesync Premium Pro/ Dell SE2422H 24inch 16:9 1920 x 1080p 75Hz Freesync
Screen Resolution
2560 x 1440p & 1920 x 1080p
Hard Drives
WD SN570 1TB NVME (Boot), Samsung 870QVO 1TB (SSD), SanDisk 3D Ultra 500Gb (SSD) x2, Seagate 3Tb Expansion Desk (Ext HDD), 2x Toshiba 1Tb P300 (Ext HDD)
PSU
Corsair RM1000X Modular
Case
Corsair 4000D Airflow Desktop
Cooling
Corsair Hydro H150i RGB Pro XT 360mm Liquid Cooler, 3 x 120mm fans, 1x Exhaust
Keyboard
Microsoft Ergonomic
Mouse
Logitech G402
Internet Speed
800Mbs
Browser
Edge Chromium
Antivirus
Defender, Malwarebytes
it was on my old computer which was updated from windows 10

and then i formatted and it was happening on brand new clean install from Microsoft usb install
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11

My Computers My Computers

  • At a glance

    Win 11 ProAMD Ryzen™ 7 7730U24GB Dual-Channel DDR4 @ 1596MHz (22-22-22-52)512MB ATI AMD Radeon Graphics (ASUStek Comput...
    OS
    Win 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    ASUS Vivobook
    CPU
    AMD Ryzen™ 7 7730U
    Motherboard
    M1605YA
    Memory
    24GB Dual-Channel DDR4 @ 1596MHz (22-22-22-52)
    Graphics Card(s)
    512MB ATI AMD Radeon Graphics (ASUStek Computer Inc)
    Monitor(s) Displays
    Generic PnP Monitor (1920x1200@60Hz) - P1 PLUS (1920x1080@59Hz)
    Screen Resolution
    1920 X 1200
    Hard Drives
    953GB Western Digital WD
    PSU
    45 Watts
    Mouse
    Lenovo Bluetooth.
    Internet Speed
    500 Mbps
    Browser
    Edge
    Antivirus
    Defender
  • At a glance

    Windows 11AMD Ryzen 7 5800H / 3.2 GHz32 GB DDR4 SDRAM 3200 MHzNVIDIA GeForce RTX 3060 6 GB GDDR6 SDRAM
    Operating System
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    ACER NITRO
    CPU
    AMD Ryzen 7 5800H / 3.2 GHz
    Motherboard
    CZ Scala_CAS (FP6)
    Memory
    32 GB DDR4 SDRAM 3200 MHz
    Graphics card(s)
    NVIDIA GeForce RTX 3060 6 GB GDDR6 SDRAM
    Sound Card
    Realtek Audio. NVIDIA High Definition Audio
    Monitor(s) Displays
    15.6" LED backlight 1920 x 1080 (Full HD) 144 Hz
    Screen Resolution
    1920 x 1080 (Full HD)
    Hard Drives
    Samsung 970 Evo Plus 2TB NVMe M.2
    PSU
    180 Watt, 19.5 V
    Mouse
    Lenovo Bluetooth
    Internet Speed
    500 Mbps
    Browser
    Edge
    Antivirus
    Defender
Back
Top Bottom