H
H
Hitmanp2015-09-23 03:43:41
Computer networks
Hitmanp, 2015-09-23 03:43:41

The svchost.exe process constantly breaks on the IP address 87.245.202.48. Any thoughts?

The svchost.exe process constantly initializes the connection to the ip address 87.245.202.48. Port 80. Checked, it is claimed that this is the ip of the provider www.ugmk-telecom.ru
Although my provider from Ufa is Bashtel. There are thoughts why this process needs to cling to the web port?
Photo of this process
s49.radikal.ru/i125/1509/f0/6ae78a7fa303.jpg
I read it online. There is an option that Windows Update. Windows is looking for updates on the servers.

Answer the question

In order to leave comments, you need to log in

3 answer(s)
R
Ruslan Fedoseev, 2015-09-23
@Hitmanp

Any softins from the provider are not worth it? Is there a balance check, service management? If not, get treated.

T
TyzhSysAdmin, 2015-09-23
@POS_troi

Do you see the Trojan?
- Not.
- And he is!

V
Valentin, 2015-09-23
@vvpoloskin

Some young (or maybe not) coolhacker has thrown you malware, the server part of which is located on a system connected to the UMMC. Treat with an antivirus, pick the process with your hands, block it with a firewall, reinstall Windows, change your PC - it's up to you.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question