Blocking acces to a potencially malicious site...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Tony41, Sep 7, 2012.

  1. Tony41

    Tony41 Private E-2

    Hi, good day to everybody.
    I'm writing from Italy, but my mother tongue is Spanish, please excuse me for my English :-o

    Before yesterday, I was experiencing for several days the Malwarebytes Anti-Malware message: "Bloqueado con éxito el acceso a un sitio web potencialmente malicioso: 212. 117. 175. 185 (don't remember exactly the number, I could be wrong... is it important?) and apparently nothing happened.
    I know, is Spanish, but I'm sure you will understand the message. ;) -

    But yesterday I got "Bloqueado con éxito el acceso a un sitio web potencialmente malicioso: 48.46.86.74." and my access to Internet was blocked.

    I tried to access with my notebook and it was OK, so I realized that something was wrong. I could unblock it running IE Access Problems Solving procedure (or something like that in English) just to allow me to write this post, but it will come again after rebooting. I use Firefox.

    I have already ran the Windows XP Malware Removal/Cleaning Procedure and got the respective logs waiting for your instructions..

    ONE NOTE: (shame on me...:-o)
    the HitmanPro program detected five issues, and following your instructions of DO NOT delete or quarantine anything, I don't know why, by error clicked the NEXT button BEFORE IGNORE them, moving issues to quarantine... :-o :( Hope not to had worsened the situation. Can I rectify my error ?

    OS: Windows XP 32 bits

    Thanking you in advance for the help I'm sure you will give me.


    Tony
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the requested logs. :)
     
  3. Tony41

    Tony41 Private E-2

    Thanks :)

    Yesterday, after running the IntExp "Diagnostica problemi di connessione" (literally Connectivity Problems Diagnostics), I could start and write the initial post without problems and work fine the rest of the day. Today, after the initial boot, when trying to connect to Internet the problem showed up again: unable to access Internet with the Malwarebytes message blocking the potentially malicious site 48.46.86.74; I had to run the IE Diagnostics routine to be able to connect and answer this message.
    The diagnostic released a log (with some checks results in red, the rest are in green), but the log file extension is .hml rolleyes I'm not sure if this kind of files can be attached :confused

    Just in case could be useful, following are the check that resulted in red:

    Connettività HTTP, HTTPS, FTP

    warn HTTP: errore 12007 durante la connessione a www.microsoft.com: The server name or address could not be resolved
    warn FTP (passiva): errore 12007 durante la connessione a ftp.microsoft.com: The server name or address could not be resolved
    warn HTTPS: errore 12007 durante la connessione a www.microsoft.com: The server name or address could not be resolved
    warn HTTP: errore 12007 durante la connessione a www.hotmail.com: The server name or address could not be resolved
    warn HTTPS: errore 12007 durante la connessione a www.passport.net: The server name or address could not be resolved
    warn FTP (attiva): errore 12007 durante la connessione a ftp.microsoft.com: The server name or address could not be resolved
    error Impossibile eseguire una connessione HTTP.
    error Impossibile eseguire una connessione HTTPS.
    error Impossibile eseguire una connessione FTP.


    Please, let me know if you need help translating ;)


    Thank you.
     

    Attached Files:

  4. Tony41

    Tony41 Private E-2

    CORRECTION:

    The IE diagnostic log file extension is .xml , not .hml as stated before...


    Sorry :-o
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach your latest log from running MBAM.
     
  6. Tony41

    Tony41 Private E-2

    Opsss... Sorry :-o

    I ran it when posted the first time, I just forgot to attach it...
    Ran it again minutes ago for a new log, the problem still alive.
    Again, I had to go trough IE diagnosis routine to unblock and access the forum.

    Thanks, have a good Sunday.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That IP address is coming back as Prudential Insurance. You should just tell MBAM to ignore it.
     
  8. Tony41

    Tony41 Private E-2

    Thank you for your answer and your time Mr. Tim.

    Just one more thing :-o how I tell MBAM to ignore it?
    I opened Malwarebytes and went to the tab 'List of Ignored? (remember that my system is in Spanish) and clicked on Add, but an windows opened asking me to select a folder ???
     
  9. Tony41

    Tony41 Private E-2

    DONE!!


    Thank you again.
    Regards
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  11. Tony41

    Tony41 Private E-2

    Done ;)

    All is running fine, thank you.


    You all are really the best :dood
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds