csjesse
-
Posts
1 -
Joined
-
Last visited
This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.
Outbound TCP port 80 to Botnet IP
in Malwarebytes for Windows Support Forum
Posted
Hi.. haven't had any trace of malware in a long time, I keep stuff pretty tight.
I run Windows Firewall + MSE, the firewall is set to block outbound and inbound unless there's an allow rule.
I also run Windows Firewall Notifier, which detects new connections and asks me if I'd like to allow/block (thus creating a rule).
Today I saw an alarming outbound connection asking for permission.
Path: \windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe
Target: 63.148.207.142 & 63.148.207.127 ,both TCP port 80
Googled the ips and found them to be botnet associated. I've run a malwarebytes scan and MSE scan, nothing showing as infected. The mscorsvw.exe process is running (although it's a normal system process).
Any ideas?