Malwarebytes Blocking IP address

Page 1 of 3 123 LastLast

  1. Posts : 8
    win 7 32bit Ultimate
       #1

    Malwarebytes Blocking IP address


    Hi,
    Malwarebytes(1.70) is returning "successfully blocked access to a potentially malicious website 91.235.128.161, type outgoing, port 53041, Process: explorer.exe. I've run some p2p software recently, but have uninstalled it, and cannot understand why explorer.exe is the process implicated. I've since run Microsoft Security Essentials and Malwarebytes on my whole system, but they return no errors. Can anyone help?
      My Computer


  2. Posts : 414
    win7 ultimate 32bit
       #2

    mhhack said:
    Hi,
    Malwarebytes(1.70) is returning "successfully blocked access to a potentially malicious website 91.235.128.161, type outgoing, port 53041, Process: explorer.exe. I've run some p2p software recently, but have uninstalled it, and cannot understand why explorer.exe is the process implicated. I've since run Microsoft Security Essentials and Malwarebytes on my whole system, but they return no errors. Can anyone help?
    the message means the MBAM blocked something from accessing Windows Explorer (or kept windows explorer from connecting to that website) in other words...it did what it's supposed to do.

    IF you would like more info see:

    Malwarebytes Forum
      My Computer


  3. Posts : 53,364
    Windows 10 Home x64
       #3

    Welcome to Seven Forums mhhack. IP address in the Ukraine the-pirate-bay.biz

    the-pirate-bay.biz - Ukraine IP. Detailed location, ISP and more info.

    91.235.128.161 IP Address WHOIS | DomainTools.com

    A Guy
      My Computer


  4. Posts : 2,686
    Windows 8.1 Pro w/Media Center 64bit, Windows 7 HP 64bit
       #4

    A lot of times a site you have opened has links to other sites to load advertisments and MB is blocking one of these links.

    Jim
      My Computer


  5. Posts : 8
    win 7 32bit Ultimate
    Thread Starter
       #5

    Thanks for your info, though I still don't see the solution to the fact that even when my computer is doing nothing malwarebytes will popup the blocking message. Remember that the type is outgoing, which I think means that my PC is initiating the request to connect. It's that that I want to stop.
      My Computer


  6. Posts : 431
    Windows 7 Home Premium x64 SP1
       #6

    If I were you, I would at least try a scan with Hitman Pro ( Home - SurfRight ). Also, you made it sound as though you did a full scan with Malwarebytes, but I would do another. Make sure it's up to date first, also make sure that in the settings tab, that you have PUP set to "show in results and check for removal"....... Actually, make sure that all 3 choices are set that way.

    Start with that, and see if they can sniff something out.
      My Computer


  7. Posts : 8
    win 7 32bit Ultimate
    Thread Starter
       #7

    Thanks for your suggestions. I've rerun MB, full scan, and it turns up nothing, with the settings you suggested. I've also run SurfRight with nothing found.
    Somehow or other something is prompting exlorer.exe to try to reach that malicious website, even though at the time nothing is running actively except for background tasks.
    Just noticed looking at the MB logs that this attempt is made every 15 minutes, with the same URL but a different port.
    Last edited by mhhack; 30 Dec 2012 at 14:59.
      My Computer


  8. Posts : 6,330
    Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
       #8

    Someone reported the same type of issue on the Malwarebytes forum.
    If you're interested, MBAM stated they could help determine the cause of the blocks.

    Malwarebytes detects outgoing attempt from explorer.exe - Malwarebytes Forum
      My Computer


  9. Posts : 8
    win 7 32bit Ultimate
    Thread Starter
       #9

    This finally turned out to be a rootkit infection. One or another of those p2p sites downloaded a rootkit that mimicked explorer.exe. Luckily it was blocked by Malwarebytes and finally removed, though it wasn't detected in previous runs. Go know.
      My Computer


  10. Posts : 6,330
    Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
       #10

    Hello mhhack,

    Glad you got this sorted out.
    Can you tell us how you found out you had a rootkit infection?
    It could help others if they run into this.

    Did a Malwarebytes (MBAM) scan find and remove it?

    Malwarebytes does have a new Anti-Rootkit tool (MBAR), but that is still in BETA (as far as I know).
    Malwarebytes : Malwarebytes Anti-Rootkit

    Thanks,
    David
      My Computer


 
Page 1 of 3 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 22:01.
Find Us