| Windows 7: Malwarebytes Blocking IP address |
29 Dec 2012
|
#1 | | |
Malwarebytes Blocking IP address Hi,
Malwarebytes(1.70) is returning "successfully blocked access to a potentially malicious website 91.235.128.161, type outgoing, port 53041, Process: explorer.exe. I've run some p2p software recently, but have uninstalled it, and cannot understand why explorer.exe is the process implicated. I've since run Microsoft Security Essentials and Malwarebytes on my whole system, but they return no errors. Can anyone help? | My System Specs |
| |
30 Dec 2012
|
#2 | | |

Quote: Originally Posted by mhhack Hi,
Malwarebytes(1.70) is returning "successfully blocked access to a potentially malicious website 91.235.128.161, type outgoing, port 53041, Process: explorer.exe. I've run some p2p software recently, but have uninstalled it, and cannot understand why explorer.exe is the process implicated. I've since run Microsoft Security Essentials and Malwarebytes on my whole system, but they return no errors. Can anyone help? the message means the MBAM blocked something from accessing Windows Explorer (or kept windows explorer from connecting to that website) in other words...it did what it's supposed to do.
IF you would like more info see: Malwarebytes Forum | My System Specs | | System Manufacturer/Model Number SALEON model 2.2b OS win7 ultimate 32bit CPU core2 Extreme QX6850-OCd to 3.15 GHz Motherboard ASUS P5G41-M LE Memory 4 GB Graphics Card NVidia 8600 GT Monitor(s) Displays 23" acer PSU 500W Thermaltake Case mini tower Hard Drives one SATA 250GB partitioned equally in half
one SATA 160GB-internal storage |
30 Dec 2012
|
#3 | | Windows 7 Home Premium x64 SP1 Bay Area Peninsula |
| My System Specs | | OS Windows 7 Home Premium x64 SP1 CPU INTEL Core i5-750 Quad-Core 3.37GHz Motherboard ASUS P7P55D Memory KINGSTON 4GB (2 x 2GB) HyperX PC3-12800 DDR3 1600MHz CL8 Graphics Card MSI N240GT-MD1G/D5 GeForce GT 240 1GB 128-bit GDDR5 Monitor(s) Displays Samsung SyncMaster B2430H 24" Screen Resolution 1920 x 1080 PSU ANTEC TruePower New TP-550, 80 PLUS, 550W Case ANTEC Three Hundred Illusion Cooling COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's Hard Drives Intel X25M Gen2 80GB, SEAGATE 500GB Barracudaź 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache Internet Speed 20 + Mbps Antivirus Avast Browser Opera |
30 Dec 2012
|
#4 | | Windows 7 HP 64bit, Windows 8 Pro w/Media Center 64bit Covington, La |
A lot of times a site you have opened has links to other sites to load advertisments and MB is blocking one of these links.
Jim | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Home Built OS Windows 7 HP 64bit, Windows 8 Pro w/Media Center 64bit CPU Phenom II X6 1100T Motherboard ASUS M5A99X EVO Memory Crucial Balistic 8gb DDR3-1866 CL9 Graphics Card MSI R6850 Cyclone IGD5 PE Sound Card On Board Monitor(s) Displays ASUS VE258Q 25" LED with DVI-HDMI-DisplayPort Screen Resolution 1920 x 1080 Keyboard Logitech K120 Mouse Logitech Marble Mouse USB, Logitech Precision Game Pad PSU Seasonic X650 80 Plus GOLD Modular Case Corsair 400R Cooling Antec Kuhler H2O 620, Two 120mm and four 140mm Hard Drives Two WD Cavier Black 2TB Sata III, WD My Book Essential 2TB USB 3.0 Internet Speed 15MB Antivirus Norton IS 2012, Malwarebytes Pro Browser IE-10, FF-19 Other Info APC UPS ES 750, Netgear WNR3500L Gigabit & Wireless N Router with SamKnows Test Program, Motorola SB6120 Gigabit Cable Modem. Brother HL-2170W Laser Printer, Epson V300 Scanner |
30 Dec 2012
|
#5 | | |
Thanks for your info, though I still don't see the solution to the fact that even when my computer is doing nothing malwarebytes will popup the blocking message. Remember that the type is outgoing, which I think means that my PC is initiating the request to connect. It's that that I want to stop. | My System Specs | | |
30 Dec 2012
|
#6 | | Windows 7 Home Premium x64 SP1 SoCal USA |
If I were you, I would at least try a scan with Hitman Pro ( Home - SurfRight ). Also, you made it sound as though you did a full scan with Malwarebytes, but I would do another. Make sure it's up to date first, also make sure that in the settings tab, that you have PUP set to "show in results and check for removal"....... Actually, make sure that all 3 choices are set that way.
Start with that, and see if they can sniff something out. | My System Specs | | OS Windows 7 Home Premium x64 SP1 |
30 Dec 2012
|
#7 | | |
Thanks for your suggestions. I've rerun MB, full scan, and it turns up nothing, with the settings you suggested. I've also run SurfRight with nothing found.
Somehow or other something is prompting exlorer.exe to try to reach that malicious website, even though at the time nothing is running actively except for background tasks.
Just noticed looking at the MB logs that this attempt is made every 15 minutes, with the same URL but a different port.
Last edited by mhhack; 30 Dec 2012 at 02:59 PM..
| My System Specs | | |
30 Dec 2012
|
#8 | | Win 7 Pro x64 SP1, Win 7 Ult x86 SP1 NC, USA |
Someone reported the same type of issue on the Malwarebytes forum.
If you're interested, MBAM stated they could help determine the cause of the blocks. Malwarebytes detects outgoing attempt from explorer.exe - Malwarebytes Forum | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number home built OS Win 7 Pro x64 SP1, Win 7 Ult x86 SP1 CPU AMD Athlon II x4 620 Motherboard Gigabyte GA-MA785G-UD3H Memory 6GB GSkill DDR2 800 Graphics Card AMD 4670 GPU + AMD 4200 IGP Sound Card on board Realtek ALC889A Monitor(s) Displays RCA 40" LCD TV, Insignia 32" LCD TV, HP 15" LCD monitor Screen Resolution 1680 x 1050... Keyboard Gyration wireless, Logitech wireless, Dell USB wired Mouse Gyration wireless, Logitech wireless, V7 USB wired PSU Corsair 500 W Case Rosewill mid tower Cooling CM 90mm Tower Hard Drives OCZ Vertex 3 120GB,
Samsung F3 1TB (3),
Several others - WD, Seagate, Hitachi, ... Internet Speed Uverse - 12Mbps D / 1.5Mbps U Antivirus Avast free OR MSE. (+ MBAM Pro). Browser 1-Firefox, 2-IE. (Chrome and Opera for testing) Other Info 2 PCs: Primary: dual-boot, Test: triple-boot.
Mainly HTPC/Gen purpose (no gaming).
Trendnet USB KVM.
LG DVD burner/Blue Ray Player.
Tray system for removable SATA backup drives.
Not currently OCd, under-volted.
I use Hybrid sleep, rarely re-boot or shutdown.
Hauppauge HD-PVR, Avermedia PCIe TV Tuner, Hauppauge PCI TV Tuner. |
02 Jan 2013
|
#9 | | |
This finally turned out to be a rootkit infection. One or another of those p2p sites downloaded a rootkit that mimicked explorer.exe. Luckily it was blocked by Malwarebytes and finally removed, though it wasn't detected in previous runs. Go know. | My System Specs | | |
02 Jan 2013
|
#10 | | Win 7 Pro x64 SP1, Win 7 Ult x86 SP1 NC, USA |
Hello mhhack,
Glad you got this sorted out.
Can you tell us how you found out you had a rootkit infection?
It could help others if they run into this.
Did a Malwarebytes (MBAM) scan find and remove it?
Malwarebytes does have a new Anti-Rootkit tool (MBAR), but that is still in BETA (as far as I know). Malwarebytes : Malwarebytes Anti-Rootkit
Thanks,
David | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number home built OS Win 7 Pro x64 SP1, Win 7 Ult x86 SP1 CPU AMD Athlon II x4 620 Motherboard Gigabyte GA-MA785G-UD3H Memory 6GB GSkill DDR2 800 Graphics Card AMD 4670 GPU + AMD 4200 IGP Sound Card on board Realtek ALC889A Monitor(s) Displays RCA 40" LCD TV, Insignia 32" LCD TV, HP 15" LCD monitor Screen Resolution 1680 x 1050... Keyboard Gyration wireless, Logitech wireless, Dell USB wired Mouse Gyration wireless, Logitech wireless, V7 USB wired PSU Corsair 500 W Case Rosewill mid tower Cooling CM 90mm Tower Hard Drives OCZ Vertex 3 120GB,
Samsung F3 1TB (3),
Several others - WD, Seagate, Hitachi, ... Internet Speed Uverse - 12Mbps D / 1.5Mbps U Antivirus Avast free OR MSE. (+ MBAM Pro). Browser 1-Firefox, 2-IE. (Chrome and Opera for testing) Other Info 2 PCs: Primary: dual-boot, Test: triple-boot.
Mainly HTPC/Gen purpose (no gaming).
Trendnet USB KVM.
LG DVD burner/Blue Ray Player.
Tray system for removable SATA backup drives.
Not currently OCd, under-volted.
I use Hybrid sleep, rarely re-boot or shutdown.
Hauppauge HD-PVR, Avermedia PCIe TV Tuner, Hauppauge PCI TV Tuner. Malwarebytes Blocking IP address problems? All times are GMT -5. The time now is 11:55 AM. | |