Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection » Malwarebytes blocking malicious IP address
Reply
Old 11-07-2009, 02:15 PM   #1 (permalink)
Hampton's Avatar
 
Yee Ol' Salt

Join Date: Dec 2008

Location: USA

Posts: 626

Hampton is on a distinguished road

Default Malwarebytes blocking malicious IP address

"Malwarebytes blocking malicious IP address"

This is the notification bubble every 30 seconds from my current install of MB, it says that, plus the IP address it is blocking.. what does this mean?

I still have a trojan?

It finished cleaning up the trojan I caught yesterday.. but still gives these notifications.
__________________

Find my post helpful? IF so please rate me by clicking the green check mark under my avatar.





Antec 300|M3N72-D|AMD PHM II X3 BE 720 3.0ghz (CodeName "Heka")|OCZ Stealth Xtreme 600w|2 two gig OCZ DDR2 1066 gold 4 GB of Ram|BFG-GTX 260 512||Samsung 42" Plasma| XP x86 sp3 /Vista x386 and x64|
The face I make everytime I'm on my machine :eek:
Hampton is offline   Reply With Quote
Old 11-07-2009, 02:30 PM   #2 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,058

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: Malwarebytes blocking malicious IP address

Let me see the hijackthis log, there may be an IP address to remove in there
__________________
Osiris is offline   Reply With Quote
Old 11-07-2009, 04:13 PM   #3 (permalink)
Hampton's Avatar
 
Yee Ol' Salt

Join Date: Dec 2008

Location: USA

Posts: 626

Hampton is on a distinguished road

Default Re: Malwarebytes blocking malicious IP address

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:11:53 PM, on 11/7/2009
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7201.0000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Windows7FirewallControl\Windows7FirewallCont rol.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe
C:\Program Files\ATI\Catalyst Media Center\CMCService.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
D:\xp slip stream stuff\WPI\Install\security\Peer Block\PeerBlock_r181__Win32_Release_(Vista)\peerbl ock.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Lavalys\EVEREST Ultimate Edition\everest.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKLM\..\Run: [Windows7FirewallControl] C:\Program Files\Windows7FirewallControl\Windows7FirewallCont rol.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [PSUNMain] "C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar
O4 - HKLM\..\Run: [CMCService] "C:\Program Files\ATI\Catalyst Media Center\CMCService.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [PeerBlock] D:\xp slip stream stuff\WPI\Install\security\Peer Block\PeerBlock_r181__Win32_Release_(Vista)\peerbl ock.exe
O4 - HKCU\..\Run: [EVEREST AutoStart] C:\Program Files\Lavalys\EVEREST Ultimate Edition\everest_start.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O13 - Gopher Prefix:
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\ATI\Catalyst Media Center\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\ATI\Catalyst Media Center\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\ATI\Catalyst Media Center\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt. exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NanoServiceMain - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: Windows7FirewallService - Sphinx Software - C:\Program Files\Windows7FirewallControl\Windows7FirewallServ ice.exe

--
End of file - 8134 bytes
__________________

Find my post helpful? IF so please rate me by clicking the green check mark under my avatar.





Antec 300|M3N72-D|AMD PHM II X3 BE 720 3.0ghz (CodeName "Heka")|OCZ Stealth Xtreme 600w|2 two gig OCZ DDR2 1066 gold 4 GB of Ram|BFG-GTX 260 512||Samsung 42" Plasma| XP x86 sp3 /Vista x386 and x64|
The face I make everytime I'm on my machine :eek:
Hampton is offline   Reply With Quote
Old 11-07-2009, 05:02 PM   #4 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,058

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: Malwarebytes blocking malicious IP address

That didnt show anythinhg. What is the IP address in question?
__________________
Osiris is offline   Reply With Quote
Old 11-09-2009, 05:25 AM   #5 (permalink)
Hampton's Avatar
 
Yee Ol' Salt

Join Date: Dec 2008

Location: USA

Posts: 626

Hampton is on a distinguished road

Default Re: Malwarebytes blocking malicious IP address

I woke up and had no net so with out even thinking i just formatted to get rid of any problems..

Gonna give avg free 9 a try on this fresh install... if that fails me.. then all i have to say is all the free stuff is that.. free.. you get what you pay for.. I always have had faith in AVG and Panda.. but now i don't know who to trust..
__________________

Find my post helpful? IF so please rate me by clicking the green check mark under my avatar.





Antec 300|M3N72-D|AMD PHM II X3 BE 720 3.0ghz (CodeName "Heka")|OCZ Stealth Xtreme 600w|2 two gig OCZ DDR2 1066 gold 4 GB of Ram|BFG-GTX 260 512||Samsung 42" Plasma| XP x86 sp3 /Vista x386 and x64|
The face I make everytime I'm on my machine :eek:
Hampton is offline   Reply With Quote
Old 11-09-2009, 05:41 AM   #6 (permalink)
Hefemeister's Avatar
 

Join Date: Feb 2004

Location: Sweden

Posts: 6,673

Hefemeister is just really niceHefemeister is just really niceHefemeister is just really niceHefemeister is just really nice

Default Re: Malwarebytes blocking malicious IP address

Have you tried MSE yet? The best free AV I have ever used.
__________________
ASUS P6T Deluxe V2 :: INTEL i7 920 @3.4 :: XFX GTX260 :: 6gb Corsair 1600 :: Corsair 750TX :: TRUE 120 :: Samsung T240 24" :: Windows 7 X64

I do not accept support questions via PM

"The man in black fled across the desert, and the gunslinger followed."
Hefemeister is offline   Reply With Quote
Old 11-10-2009, 07:14 PM   #7 (permalink)
Hampton's Avatar
 
Yee Ol' Salt

Join Date: Dec 2008

Location: USA

Posts: 626

Hampton is on a distinguished road

Default Re: Malwarebytes blocking malicious IP address

No sir, havn't tried MSE.

Ok I thought the IP thing was panda's IP.. but this is a fresh install and Malware bytes is still having that pop up.. I have no AV installed atm.. havn't decided who to go with..

could it just be my network IP?
__________________

Find my post helpful? IF so please rate me by clicking the green check mark under my avatar.





Antec 300|M3N72-D|AMD PHM II X3 BE 720 3.0ghz (CodeName "Heka")|OCZ Stealth Xtreme 600w|2 two gig OCZ DDR2 1066 gold 4 GB of Ram|BFG-GTX 260 512||Samsung 42" Plasma| XP x86 sp3 /Vista x386 and x64|
The face I make everytime I'm on my machine :eek:
Hampton is offline   Reply With Quote
Old 11-10-2009, 07:19 PM   #8 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,058

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: Malwarebytes blocking malicious IP address

What is the IP on your system?

ipconfig /all

does it match the IP malwarebytes is complaining about?
__________________
Osiris is offline   Reply With Quote
Old 11-10-2009, 08:28 PM   #9 (permalink)
Hampton's Avatar
 
Yee Ol' Salt

Join Date: Dec 2008

Location: USA

Posts: 626

Hampton is on a distinguished road

Default Re: Malwarebytes blocking malicious IP address

actually there are multipul IP's, at least 6.. I only have 3 on the network and those would be in simuliar address as the main IP.. kind of strange tho that if it were a hacker trying to bust in.. how did he get past the D-link.. aren't routers supposed to block un requested requests?
__________________

Find my post helpful? IF so please rate me by clicking the green check mark under my avatar.





Antec 300|M3N72-D|AMD PHM II X3 BE 720 3.0ghz (CodeName "Heka")|OCZ Stealth Xtreme 600w|2 two gig OCZ DDR2 1066 gold 4 GB of Ram|BFG-GTX 260 512||Samsung 42" Plasma| XP x86 sp3 /Vista x386 and x64|
The face I make everytime I'm on my machine :eek:
Hampton is offline   Reply With Quote
Old 11-10-2009, 08:39 PM   #10 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,058

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: Malwarebytes blocking malicious IP address

they can get around whatever they want if they have a way but I doubt this is the case. Check around on MBAM to see if you can ignore them, etc.
__________________
Osiris is offline   Reply With Quote
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
All VOIP programs (skype, yahoo, msn) cause PC crash (only voice calls, chat ok)??? disksko Hardware Troubleshooting 10 03-17-2009 09:17 AM
what is arp? wildsniper Articles 1 01-10-2009 01:26 PM
DVD Data Burning enigm@tic Hardware Troubleshooting 4 08-25-2008 08:30 PM
New log shades9323 HijackThis Logs (finished) 20 06-02-2008 03:03 PM
Blocking a certain IP address from accessing my PC CalcProgrammer1 Computer Networking & Internet Access 3 02-15-2008 10:04 PM