Jump to content

Malicious Website Protection possible issue?


Recommended Posts

Hello. I've been getting quite a few blocks (4-8 daily) from this feature, blocking inbound IPs, the latest log looks like this:
 

Detection, 2015.08.10 01:51, SYSTEM, --, Protection, Malicious Website Protection, IP, 50.118.172.239, 443, Inbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 2015.08.10 01:51, SYSTEM, --, Protection, Malicious Website Protection, IP, 50.118.172.239, 443, Inbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 2015.08.10 01:51, SYSTEM, --, Protection, Malicious Website Protection, IP, 50.118.172.239, 443, Inbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 2015.08.10 01:51, SYSTEM, --, Protection, Malicious Website Protection, IP, 50.118.172.239, 443, Inbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 2015.08.10 02:02, SYSTEM, --, Protection, Malicious Website Protection, IP, 89.248.174.100, 138, Inbound,
Detection, 2015.08.10 02:02, SYSTEM, --, Protection, Malicious Website Protection, IP, 89.248.174.100, 138, Inbound,
Detection, 2015.08.10 02:26, SYSTEM, --, Protection, Malicious Website Protection, IP, 89.248.172.35, 19, Inbound, C:\Windows\System32\svchost.exe,
Detection, 2015.08.10 02:26, SYSTEM, --, Protection, Malicious Website Protection, IP, 89.248.172.35, 19, Inbound, C:\Windows\System32\svchost.exe,
 

So far I've seen it come from skype, svchost and wininit.

I was wondering if I should be concerned or is this a typical behaviour that everyone experiences?

 

Another issue I've noticed while going through the logs is that the malicious website protection service keeps stopping/starting at random times. One of the logs:

 

Protection, 2015.08.09 10:34, SYSTEM, --, Protection, Malicious Website Protection, Stopping,
Protection, 2015.08.09 10:34, SYSTEM, --, Protection, Malicious Website Protection, Stopped,
Protection, 2015.08.09 10:35, SYSTEM, --, Protection, Refresh, Success,
Protection, 2015.08.09 10:35, SYSTEM, --, Protection, Malicious Website Protection, Starting,
Protection, 2015.08.09 10:35, SYSTEM, --, Protection, Malicious Website Protection, Started,
Update, 2015.08.09 12:35, SYSTEM, --, Scheduler, Malware Database, 2015.8.9.1, 2015.8.9.2,
Protection, 2015.08.09 12:35, SYSTEM, --, Protection, Refresh, Starting,
Protection, 2015.08.09 12:35, SYSTEM, --, Protection, Malicious Website Protection, Stopping,
Protection, 2015.08.09 12:35, SYSTEM, --, Protection, Malicious Website Protection, Stopped,

 

I am very new to malwarebytes and I'm sorry if I'm asking about obvious things, it just seemed a little bit strange, therefore I want to be sure that everything's alright. Thank you in advance!

Link to post
Share on other sites

Hello and :welcome: :
 
Last question first -- the intermittent stopping/starting of web protection is for update checks.  The protection must pause -- for a second or two -- in order to refresh the files that are in use.  IOW this is normal.
 
Next, the Skype IP blocks -- those are explained here: Why does Malwarebytes Anti-Malware block Skype? and here What does it mean when I get an alert that Malwarebytes Anti-Malware has blocked a malicious site?
IOW they are to be expected when using Skype or P2P software
 
Finally, the other blocks you show are all inbound.  Generally, those, too, are to be expected and are less suspicious than outbound blocks; your firewall and/or router would block those.  However, it's impossible to say from the snippet of log provided whether or not you might be infected.

So, for expert assistance, I suggest that you might want to please follow the advice in this pinned topic: Available Assistance For Possibly Infected Computers.
It explains the options for free, expert help >>AND<< the suggested, preliminary steps to expedite the process.
A malware analyst will assist you with looking into your issue - the helper will guide you through scanning and any needed cleanup.

Thanks,

Link to post
Share on other sites

Hi:

 

Yes, it would be a good idea to please follow the advice in this pinned topic: Available Assistance For Possibly Infected Computers.
It explains the options for free, expert help >>AND<< the suggested, preliminary steps to expedite the process.
A malware analyst will assist you with looking into your issue - the helper will guide you through scanning and any needed cleanup.

The help is free and will only cost you a bit of your time.

 

Thanks again,

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.