Jump to content

Malicious IPs being blocked nonstop


Recommended Posts

As soon as I upgraded and enabled IP protection for the past 20 minutes I've gotten the

Malwarebytes Anti-Malware has succesfully blocked access to malicious IP: *

After performing a quick scan MWB's found no infections

Is there a way to find out what program is attemping access to these IPs?

I'm not on any malicious web-pages at this moment in time either.

Link to post
Share on other sites

@ RandomTaskMan

Welcome to the forums!

Are the pop ups happening constantly, or only at certain webpages?

Do you have any P2P programs, such as BitTorrent or LimeWire?

Also, just as a side note, when replying, please erase what the person said and just address them @username or username:, as this makes the forum easier to read :)

Link to post
Share on other sites

@mountaintree16

I didn't think about that

I am using the program utorrent

could this be the reason?

and how would I prevent this from happening

as well as I want to attempt the silentipmode

described in this thread

but the steps are a little unclear for someone who doesn't know much about the registries

http://www.malwarebytes.org/forums/index.p...st&p=124874

any help would be appreciated

Link to post
Share on other sites

@RandomTaskMan

Yes, utorrent could definitely be the or at least part of the cause of the constant pop ups. I would STRONGLY recommend uninstalling it. If you choose to do this, restart your computer afterwards

Facebook has never thrown an IP block at me, at least not yet.

I'm glad that you found the IP registry tweak page, I was just going to direct you to it, actually.

Hmm I am actually not too good with registry editing either, I've only looked at it before (once or twice) and have never edited... I'll send along a message to someone who knows better and see if they can jump in here and help you :)

Link to post
Share on other sites

I think I may have found the issue but don't know how to solve it.

I opened up my task manager and found iexplore.exe running and as I don't use I.E. I terminated the program.

I've also found several programs that don't look like they should running at all

lsass.exe under SYSTEM

csrss.exe under SYSTEM

smss.exe under SYSTEM

spoolsv.exe under SYSTEM

cih.exe under OWNER

m9m8tgpttdfr .exe under OWNER

Link to post
Share on other sites

RandomTaskMan,

lsass is normal as far as I know, I have it too.

I have spoolssv, csrss, smss also. I believe these are also normal.

I have no idea what cih or m9m8tgpttdfr are, though.

I PMed a Moderator about your Registry question :)

Link to post
Share on other sites

I've also found several programs that don't look like they should running at all

lsass.exe under SYSTEM

csrss.exe under SYSTEM

smss.exe under SYSTEM

spoolsv.exe under SYSTEM

cih.exe under OWNER

m9m8tgpttdfr .exe under OWNER

m9m8tgpttdfr .exe is unknown and is probably malicious.

cih.exe is a worm according to Sophos.

Please follow these instructions (skipping any steps you are unable to complete) for posting in our Malware Removal - HijackThis Logs forum. If you cannot follow any of those steps, then please create a new topic in that forum explaining what happened when you tried to run each of the tools in the instructions, and the expert who helps you will be able to suggest steps to take to get the tools working.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.