99% certain comp is fine just keep getting MBAM blocking malicious site so someone on here suggested I submit logs


Hello gettheman,

Keep in mind what my colleagues mentioned on IP blocks on the general mbam sub-forum.

Also, if all your browsers are closed, & with no instant messenger app running, & your system being clean, normally one would not expect an "outbound ip block".

With that all said, did you just recently switch from Avast to BitDefender? what was the sequence you used to switch? and did you do a restart just before installing the new security app?

It is quite possible you have adwares or unwanted add-ons on your system that would be the source for the "issue at hand".

As I help you and we go along, please do not run other tools on your own.

I need for you to follow my guidance.

If my instructions are not clear, please stop and ask. Read all instructions before diving in.

Also, as you report back, let me know in each reply whether the ip blocks happen again, with detail on the ip number & whether Outbound.

Step 1

1. Go >> Here << and download ERUNT

(ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)

2. Install ERUNT by following the prompts

(use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)

3. Start ERUNT by doing a Right-Click on it & select Run As Admisnistrator

4. Choose a location for the backup

(the default location is C:\WINDOWS\ERDNT which is acceptable).

5. Make sure that at least the first two check boxes are ticked

6. Press OK

7. Press YES to create the folder.

Step 2

Show all files:

  • Click the Start button, and then click Computer.
  • On the Organize menu, click Folder and Search Options.
  • Click the View tab.
  • Locate and uncheck Hide file extensions for known file types.
  • Locate and uncheck Hide protected operating system files (Recommended).
  • Locate and click Show hidden files and folders.
  • Click Apply > OK.

Step 3

Close any open work documents, if any, saving your work.

Make sure to close any other programs that you started before.

Please download Junkware Removal Tool by Thisisu to your Desktop.

  • Please close your security software to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or 7 or 8, right-mouse click JRT.exe and select Run as administrator.
  • The tool will open and display information and disclaimer in a Command prompt window.
  • I'd suggest you close all internet browsers at this point.
  • Press a key on keyboard to start scanning your system.
  • Please be very patient as this will take several minutes to complete, depending on your system's specifications.
  • There are approximatly 12 phases or so in this tool. You will see each phase listed in the Command prompt window.
  • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open. And the command prompt will have been closed.
  • Please post the contents of JRT.txt into a new reply.
  • Re-enable your security software.

Step 4

  • Download & SAVE to your Desktop Tigzy's RogueKiller >> from here << or
    >> from here <<
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7 / 8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.
    For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on Scan button at upper right of screen.
  • Wait until the Status box shows "Scan Finished"
  • Click on Report and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Do NOT press any Fix button.
  • Exit/Close RogueKiller

Step 5

Please download AdwCleaner © Xplode from >>here<< and save it on your Desktop.

If your are running Windows XP, double click adwcleaner.exe to start it.

Otherwise, Right-click on adwcleaner.exe and select Run As Administrator to launch the application.

Now click on the Search tab.

Please post the contents of the log-file created in your next post.

Note: The log can also be located at C:\AdwCleaner[XX].txt where XX Denotes the number of times the application has been ran, so in this should be something like R1.

yes I swictehd but got rid of one before using the other. just tried to load erunt and got the error Server not found

Firefox can't find the server at dundats.mvps.org. then I click again and it works but getting the problem loading page alot no matter what firewall

I keep getting errors about malicious outbound. next time will try and screensave it--logs to follow

Link to post
Share on other sites

junkware removal tool was running for 1 hour but still deep scanning registry?

managed to get it done eventually

after 5 hours


Curious as to why Adwcleaner was run so many times ?

btw, if an outbound IP block shows up, just write down (document) the IP address & report that in a reply.

We'll continue with running other tools.

Task 1

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

For directions on how, see How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Do NOT turn off the firewall

Please download Rkill by Grinler and save it to your desktop.

Task 2

1. Download Malwarebytes Anti-Rootkit from http://www.malwarebytes.org/products/mbar/

2. Unzip the contents to a folder in a convenient location.

3. Open the folder where the contents were unzipped and run mbar.exe

4. Follow the instructions in the wizard to update and allow the program to scan your computer for threats.

5. Click on the Cleanup button to remove any threats and reboot if prompted to do so.

6. Wait while the system shuts down and the cleanup process is performed.

7. Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.

yes I keep getting outbound blocks on MBAM but not been quick enough to capture it, it is always to do with firefox though I noticed

Make a note that Firefox browser is something that needs looking at, later. For now, Close it and keep it closed.

Use Internet Explorer instead, as much as possible.

The TDSSKiller result is good. No detections. We will be doing more checks.

Save and close any work documents, close any apps that you started.

Temporarily turn off (disable) your antivirus program

How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Start your MBAM MalwareBytes' Anti-Malware.

Click the Settings Tab and then the General Settings sub-tab. Make sure all option lines have a checkmark.

Then click the Scanner settings sub-tab in second row of tabs. Make sure all option lines have a checkmark.

If you have the PRO license, then do this too: Click the Protection tab. Make sure all option lines have a checkmark.

Next, Click the Update tab. Press the "Check for Updates" button.

If prompted for a Restart, do that.

When done, click the Scanner tab.

Do a Full Scan. i_arrow-l.gif

When the scan is complete, click OK, then Show Results to view the results.

Make sure that everything is checked, and click Remove Selected.

When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

When all done, Copy & paste the MBAM scan log into a new reply.

Tell me, How is the system ?

Re-enable your antivirus program.

Then do a Quick scan of your system with your BitDefender antivirus.

Please let me know that result.

To Reset Firefox to its default state:

Start Firefox

in the address bar, type in


Click on the Reset Firefox button at top right of screen.

While in Firefox, press Shift+CTRL+Delete keys and delete temporary internet cache files.

Close Firefox.

Firefox keeps hanging. Not responding for about 30 secs then its okay for some unknown reason

Bit defender scan was fine although it has 227 password protected files which it wont let me scan without password

Malwarebytes Anti-Malware (PRO)


Database version: v2013.04.11.09

Windows Vista Service Pack 2 x86 NTFS

Internet Explorer 9.0.8112.16421

Chris :: DELL-530 [administrator]

Protection: Enabled

11/04/2013 23:30:12

mbam-log-2013-04-11 (23-30-12).txt

Scan type: Full scan (C:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 293071

Time elapsed: 53 minute(s), 4 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)


Your BitDefender run found nothing apparently.

The MBAM full scan detected nothing; which is excellent.

I would suggest you uninstall firefox, restart the system.

Then if you must have Firefox, get the latest release version and install that.

I'd be very careful as to what browser add-ons you put on.

Also, as much as possible, use a blank start-page in your browser setting.

btw, keep Internet Explorer set as the system default browser. If offered by FF to have it as the default, decline the option.

Link to post
What exactly gives you a "server not found" ???

I need the verbatim {exact & complete) text of any such message .....with detail on "how" /when / where it shows up.

IF need be, take a snapshot (if possible) with your camera or do a screen-capture, and then attach as a GIF file.

Link to post
