Malwarebytes has block access to IP

Discussion in 'Software' started by garyjwilson, Mar 30, 2010.

  1. garyjwilson

    garyjwilson Private E-2

    Hi,

    I have just installed a new version of malwarebytes (1.44) with IP protection.
    I keep getting a notification stating that it has blocked access to rogue I.P's and can not fathom out what is causing it.

    07:30:49 Gary IP-BLOCK 69.31.87.197
    07:58:08 Gary IP-BLOCK 121.8.214.143
    07:58:42 Gary IP-BLOCK 94.96.210.93
    07:59:07 Gary IP-BLOCK 58.241.135.165
    08:13:36 Gary IP-BLOCK 222.186.70.193
    08:13:48 Gary IP-BLOCK 62.45.126.183
    08:29:06 Gary IP-BLOCK 121.8.169.101
    08:29:18 Gary IP-BLOCK 58.240.193.69
    08:45:32 Gary IP-BLOCK 89.28.48.252

    Above is a section of the malwarebytes log.
    as you can see the times vary and it does not matter if i am using the p.c or not.
    I have checked the IP's and they are from China, USA, Saudia Arabia etc.
    I have done a full scan with AVG malwarebytes and A squared and they have not found the issue.
    Also went through system processes and could not find an obvious rogue one.
    The p.c. is running fine and my internet connection has not slowed or anything but the notifications and the cause are driving me mad.
    I am using windows XP.

    Does anyone have any ideas. ?

    thanks

    Gary
     
  2. Mada_Milty

    Mada_Milty MajorGeek

    This is a reality of the internet. There are bots and worms and spiders, etc constantly scanning IP addresses, looking for vulnerabilities to exploit, and data to scrape. (Hence the necessity of a firewall) I wouldn't worry about it, it sounds like your application is doing its job, but perhaps there is a way to configure the notification to be less of a nuisance?
     
  3. garyjwilson

    garyjwilson Private E-2

    Thanks

    but are you sure these are inbound attacks.
    I am worried that it is my p.c trying to send something out !!!
    If these are standard inbound attacks then everyone with malwarebytes would surely be getting the same problem as me flagged up.....
    If not why am I getting them.
     
    Last edited: Mar 30, 2010
  4. Mada_Milty

    Mada_Milty MajorGeek

    With the volume of them, yes, I would expect that they are inbound. (Does malwarebytes not give any indication of the direction?)

    However, if you are really concerned, there is always the READ & RUN ME FIRST. Malware Removal Guide available for your peace of mind.
     
  5. garyjwilson

    garyjwilson Private E-2

    no indication of the direction is given
     
  6. garyjwilson

    garyjwilson Private E-2

    do you think it would be advisable to install zone alarm or similar to see if this gives me more information about the problem i.e. inbound or outbound ?
     
  7. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    1. belongs to Pilosoft dsl company
    http://www.dslreports.com/reviews/2158
    2. Chinatelecom (bet it is some sort of bot)
    3. Sauditelecom
    4. Jiangsu Province network

    That gives you an idea that lots of foreigners want in. Do you run any P2P programs or torrents? That might be the result of some of those.

    You can grab a program to find out who these IPs belong to.
    Go here and grab Whois
    http://www.karenware.com/powertools/ptwhois.asp
     
  8. dj munchbunch

    dj munchbunch Private E-2

    I have had similar experiences with MalwareBytes and continue to do so. At the notification area of the taskbar i keep getting bubbles that say its blocked a potential malicious website, but when I try to run the intruding IP's through whois, and DNS IP trackers it comes back saying user doesnt not exist.

    I am including an attached txt file which is just 1 of todays logs, you will be quite suprised how big it is
     

    Attached Files:

  9. Oldphil

    Oldphil Sergeant


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds