Jump to content

Olav

Members
  • Posts

    4
  • Joined

  • Last visited

Posts posted by Olav

  1. Hello!

    At irregular intervals, Malwarebytes blocks outbound powershell connections in category 'Riskware' going to 'imonews.net', with the IP-address: 172.67.190.202 on port: 443.
    It also blocks outbound powershell connections in category 'Riskware' going to the IP-address: 135.181.231.130 on port: 80.

    This has been going on for a few months now, but neither Malwarebytes nor Symantec Endpoint Protection (14.3 RU9) find anything when doing a full scan of the computer. Both apps are updated to the latest version.

    At one time, Symantec Endpoint Protection also terminated a powershell process with the risk name: 'CL.Downloader!gen96'.

    I'm on a Windows 11 23H2 PC, and I've tried to disable powershell as outlined here: https://www.thewindowsclub.com/how-to-disable-powershell-windows-10, but it did not fix the problem. FYI, I've enabled powershell in the OS again.

    Can someone please help me look into and hopefully solve this?

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.