Archon Prime
Well-Known Member
- Reaction score
- 1,232
- Location
- Canada
I've been seeing this on MY computer believe it or not since I've had Malwarebytes Premium installed on the system. I've noticed bouts of inbound/outbound blocking from svchost.exe. (glad I installed this software if this has been happening in the background)
I've run every scan you could possibly think of with everything on my usb stick for malware/viruses/rootkits/trojans, etc.
I've not found anything suspicious on the system at all, yet the svchost keeps getting blocked for communicating with overseas IP's, China, India, Netherlands, etc. It's random but I keep seeing this occur periodically. I don't have anything running besides Emsisoft, Plex (local only), Malwarebytes, and Kabuto. I went to the point to check each svchost process and they all pop up in the correct forlder for System32.
I think I need some extra set of eyes/brains on this one. It could be nothing, it could be something.
I've exported 4 of the blocked website log that occurred this afternoon:
I've run every scan you could possibly think of with everything on my usb stick for malware/viruses/rootkits/trojans, etc.
I've not found anything suspicious on the system at all, yet the svchost keeps getting blocked for communicating with overseas IP's, China, India, Netherlands, etc. It's random but I keep seeing this occur periodically. I don't have anything running besides Emsisoft, Plex (local only), Malwarebytes, and Kabuto. I went to the point to check each svchost process and they all pop up in the correct forlder for System32.
I think I need some extra set of eyes/brains on this one. It could be nothing, it could be something.
I've exported 4 of the blocked website log that occurred this afternoon:
Malwarebytes
www.malwarebytes.com
-Log Details-
Protection Event Date: 4/19/17
Protection Event Time: 1:27 PM
Logfile:
Administrator: Yes
-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.103
Update Package Version: 1.0.1762
License: Premium
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, , Blocked, [-1], [-1],0.0.0
-Website Data-
Domain:
IP Address: 94.102.52.6
Port: [3389]
Type: Outbound
File:
(end)
--------------------------------------
Malwarebytes
www.malwarebytes.com
-Log Details-
Protection Event Date: 4/19/17
Protection Event Time: 1:27 PM
Logfile: dfdf.txt
Administrator: Yes
-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.103
Update Package Version: 1.0.1762
License: Premium
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, , Blocked, [-1], [-1],0.0.0
-Website Data-
Domain:
IP Address: 94.102.52.6
Port: [3389]
Type: Outbound
File:
(end)
----------------------------------
Malwarebytes
www.malwarebytes.com
-Log Details-
Protection Event Date: 4/19/17
Protection Event Time: 1:27 PM
Logfile:
Administrator: Yes
-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.103
Update Package Version: 1.0.1762
License: Premium
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, , Blocked, [-1], [-1],0.0.0
-Website Data-
Domain:
IP Address: 94.102.52.6
Port: [3389]
Type: Outbound
File:
(end)
---------------------------------
Malwarebytes
www.malwarebytes.com
-Log Details-
Protection Event Date: 4/19/17
Protection Event Time: 1:27 PM
Logfile:
Administrator: Yes
-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.103
Update Package Version: 1.0.1762
License: Premium
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, , Blocked, [-1], [-1],0.0.0
-Website Data-
Domain:
IP Address: 94.102.52.6
Port: [3389]
Type: Outbound
File:
(end)
www.malwarebytes.com
-Log Details-
Protection Event Date: 4/19/17
Protection Event Time: 1:27 PM
Logfile:
Administrator: Yes
-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.103
Update Package Version: 1.0.1762
License: Premium
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, , Blocked, [-1], [-1],0.0.0
-Website Data-
Domain:
IP Address: 94.102.52.6
Port: [3389]
Type: Outbound
File:
(end)
--------------------------------------
Malwarebytes
www.malwarebytes.com
-Log Details-
Protection Event Date: 4/19/17
Protection Event Time: 1:27 PM
Logfile: dfdf.txt
Administrator: Yes
-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.103
Update Package Version: 1.0.1762
License: Premium
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, , Blocked, [-1], [-1],0.0.0
-Website Data-
Domain:
IP Address: 94.102.52.6
Port: [3389]
Type: Outbound
File:
(end)
----------------------------------
Malwarebytes
www.malwarebytes.com
-Log Details-
Protection Event Date: 4/19/17
Protection Event Time: 1:27 PM
Logfile:
Administrator: Yes
-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.103
Update Package Version: 1.0.1762
License: Premium
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, , Blocked, [-1], [-1],0.0.0
-Website Data-
Domain:
IP Address: 94.102.52.6
Port: [3389]
Type: Outbound
File:
(end)
---------------------------------
Malwarebytes
www.malwarebytes.com
-Log Details-
Protection Event Date: 4/19/17
Protection Event Time: 1:27 PM
Logfile:
Administrator: Yes
-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.103
Update Package Version: 1.0.1762
License: Premium
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, , Blocked, [-1], [-1],0.0.0
-Website Data-
Domain:
IP Address: 94.102.52.6
Port: [3389]
Type: Outbound
File:
(end)