Author Topic: Can I Ask for Help?  (Read 6877 times)

0 Members and 1 Guest are viewing this topic.

Probzzie

  • Guest
Can I Ask for Help?
« on: June 03, 2011, 04:49:57 AM »
Okay I Just recently activated a Malware bytes trial to the full version and its continuously blocking a website, should I ask there for help? I ran scans with both Avast and MBAM
I have managed to type down the website can anyone confirm whats happening?

89.28.31. 1 95 is what pops up as the address, came up as soon as I opened internet explorer, start page google

Probzzie

  • Guest
Re: Can I Ask for Help?
« Reply #1 on: June 03, 2011, 08:35:59 AM »
Forget it, Malware Bytes is popping up false possitives like ninety on both my systems... I find it hard to believe they're both blocking malicious sites as when I went to one site I know is not infected it blocked it and said it stop potentially harmful site

Probzzie

  • Guest
Re: Can I Ask for Help?
« Reply #2 on: June 03, 2011, 01:57:54 PM »
Can anyone just help confirm this for me, because on my secondary, when it was turned on even before internet explorer or any browser was open it was saying its blocking websites, and my avast and mbam are both running clean, Is this a bug? Because it sure is starting to spook me..
It's stating that there is both incoming and out going attempts that are being blocked.
popping up frequently at least once every ten minutes.
89.2 8.31. 1 95 ran clean on virus total so i'm at a loss to why its being blocked, further more why its blocking sites when inactive..
« Last Edit: June 03, 2011, 02:19:23 PM by -BigBear- »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89055
  • No support PMs thanks
Re: Can I Ask for Help?
« Reply #3 on: June 03, 2011, 02:48:22 PM »
The IP address you gave is incorrect as there should be no spaces in it, but if it is 89.2 8.31.195 then there is a possibility that MBAM considers it malicious, unless you are connecting to a site in Moldova.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Probzzie

  • Guest
Re: Can I Ask for Help?
« Reply #4 on: June 03, 2011, 03:12:00 PM »
Yes, there is no spaces, I wasn't sure whether it was infected so I broke it up for protection.
I received and am still receiving blocks even with an idle connection.. No browser or any internet resource was openned or IS open when these come in.
« Last Edit: June 03, 2011, 03:15:00 PM by -BigBear- »

msgreyberry

  • Guest
Re: Can I Ask for Help?
« Reply #5 on: June 03, 2011, 04:33:31 PM »
I have the same problem :P Even when I don't have my browser open... So chances are that it's a false positive :P

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89055
  • No support PMs thanks
Re: Can I Ask for Help?
« Reply #6 on: June 03, 2011, 05:18:13 PM »
Yes, there is no spaces, I wasn't sure whether it was infected so I broke it up for protection.
I received and am still receiving blocks even with an idle connection.. No browser or any internet resource was openned or IS open when these come in.

Well I would certainly be concerned if for no other reason than you aren't connected. well browsing and since it is a moldova IP.

You mention "No browser or any internet resource was openned or IS open when these come in." That puts an entirely different spin on things if this is only inbound and not outbound.

So please post some examples from the MBAM Protection log.

What is your firewall on this system ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89055
  • No support PMs thanks
Re: Can I Ask for Help?
« Reply #7 on: June 03, 2011, 05:22:26 PM »
I have the same problem :P Even when I don't have my browser open... So chances are that it's a false positive :P

A dangerous assumption to make, given the location of the IP, which you should always check out.

There are lots of port scanning attempts out there trying to find IP addresses that have computers attached and more so that answer any ping or port scan attempts (not stealthed).

Once they find an IP with a computer, then you are likely to get more detailed/directed attention as they try to run any exploit, etc. in the hope of getting into the computer.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

msgreyberry

  • Guest
Re: Can I Ask for Help?
« Reply #8 on: June 03, 2011, 09:10:14 PM »
I have the same problem :P Even when I don't have my browser open... So chances are that it's a false positive :P

A dangerous assumption to make, given the location of the IP, which you should always check out.

There are lots of port scanning attempts out there trying to find IP addresses that have computers attached and more so that answer any ping or port scan attempts (not stealthed).

Once they find an IP with a computer, then you are likely to get more detailed/directed attention as they try to run any exploit, etc. in the hope of getting into the computer.

Now that I read this, I think you're right and I was really wrong to say what I said~  :-[
After all, an antivirus is just an antivirus and interprets things in how it was constructed to interpret stuffy~
I just checked my Malwarebytes log and found a massive log of blocked IPs. Maybe I was really at risk? But it stopped so I guess it's done and over with now.... ;D

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89055
  • No support PMs thanks
Re: Can I Ask for Help?
« Reply #9 on: June 03, 2011, 09:30:37 PM »
Well I would also say that if you have a half decent firewall these port scans should go unanswered, effectively keeping the system stealthed. If it is then I don't see how MBAM is able to record any inbound connection attempt from external IPs.

On my win7 netbook with mbam pro, my daily protection logs basically consisted of it being updated and zero IP protection entries. Mind you a) it isn't used as much and b) it is obviously behind the wifi router and modem, so I don't know if that has an effect.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Probzzie

  • Guest
Re: Can I Ask for Help?
« Reply #10 on: June 03, 2011, 10:32:27 PM »
Okay, I have Avast Free on my secondary fully updated which I just remembered does not offer a firewall. So just the default windows firewall is in place on the XP Professional based machine.
The connections are not just outbound, they are inbound also and its frequent, well it was a lot more frequent last night. I am definentely suspicious because MBAM is such a great scanner I trust it knows what its talking about.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Can I Ask for Help?
« Reply #11 on: June 03, 2011, 10:35:29 PM »
you could always post an OTS log and let Essexboy have a look inside....

Probzzie

  • Guest
Re: Can I Ask for Help?
« Reply #12 on: June 03, 2011, 10:53:57 PM »
Reg - Disabled MS Config Items
Reg - Drivers32
Reg - NetSvcs
Reg - SafeBoot Minimal
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check

Run OTS with these items ticked off?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Can I Ask for Help?
« Reply #13 on: June 04, 2011, 12:40:32 AM »
Just like this  ;D

Download OTS to your Desktop and double-click on it to run it
  • Make sure you close all other programs and don't use the PC while the scan runs.
  • Select All Users
  • Under additional scans select the following
Reg - Disabled MS Config Items
Reg - Drivers32
Reg - NetSvcs
Reg - SafeBoot Minimal
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check

  • Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%\*. /mp /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
CREATERESTOREPOINT

  • Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Please attach the log in your next post.

Probzzie

  • Guest
Re: Can I Ask for Help?
« Reply #14 on: June 04, 2011, 01:12:13 AM »
Ok scan is running and in the mean time here is a picture of the blocked site just as my computer was turned on. No browser open.