Author Topic: I was told to scan my system because of MBAM notification spam  (Read 1158 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
I was told to scan my system because of MBAM notification spam
« on: September 19, 2017, 12:26:59 AM »
Sorry about long description, but I want to give all the info I can for someone who coud help me with this.

Yesterday evening I noticed MBAM premium trial version (installed automatically with newest version update) giving few similar notifications of "Malicious website blocked", but all the report showed was an IP address being blocked instead of a webpage (and all I had open when these notifications first began to spam was Youtube. The IP address was similar to the IP of my PC and our Samsung television that has an internet connection, minus the last number, which Avast showed me when I did WLAN scan. So the blocked IP apparently belonged to my local area network. My father had a theory that my PC was somehow picking up one of our home media devices trying to connect to our router's signal, since in the past (before having MBAM premium trial) there was at some point a new device in my "This computer" folder with my main disk drives that had device info in it matching with our set-up box, and this device has later remoed itself from the folder it seems. I did MBAM and Avast scans on the same evening these notifications started to appear and scans came out clean. However, today soon after turned on my PC, the same notifications began to spam even more continuing on to do so for every few hours, and by the evening my MBAM premium has came up with 190 alert reports for the IP address. Also, unlike yesterday evening, some reports showed the file trying to apparently connect to the IP MBAM blocked being System32\scvhost.exe file, and it had different number in "Port" portion. I imported one sample of both reports as textfiles (attaching them to the post).

After I mentioned the incident to people on MBAM subreddit, one folk told me the issue could be adware/browser exploit trying to reroute my browser and encouraged me to do scan with Adwcleaner. I went and downloaded the software from toolslib.net (where I got directed from offical malwarebytes.com) and ran a scan, and it didn't find anything form my machine. I also checked browser exctentions for both Firefox and Chrome (though I barely use the latter, but just to be sure) without noticing anything abnormal. However, what the person on reddit told me made me rather worried, so I decided to see if someone here could help me out, and I ran Farbar scan (though when I started it I went and clicked "Scan" while the software was checking for updates. It seemingly completed the scan normally, but I wonder if it messed anything up :-\), I've inserted the logs below.

I haven't recieved MBAM notifications in few hours now. However, my MBAM Premium trial is about to expire (the software says it ends "today" but I'm not sure about the exact time) so obviously I'll stop getting these notifications after that. But nonetheless I want to see if there is indeed something nasty in my system like the person on reddit said or if it's some sort of false positive launched by some WLAN device in our household like my dad theorized.
« Last Edit: September 19, 2017, 01:23:31 AM by Pernaman »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: I was told to scan my system because of MBAM notification spam
« Reply #1 on: September 19, 2017, 12:51:03 AM »
Since this is a malwarebytes detection problem, why don't you check / ask in malwarebytes forum?


REDACTED

  • Guest
Re: I was told to scan my system because of MBAM notification spam
« Reply #2 on: September 19, 2017, 01:13:20 AM »
Since this is a malwarebytes detection problem, why don't you check / ask in malwarebytes forum?

Ah yes, that's true. :-[ I'll repost this here and come back if needed.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: I was told to scan my system because of MBAM notification spam
« Reply #3 on: September 19, 2017, 01:28:17 AM »
It may be a Mbam bug? And those who know Mbam best are in that forum