Jump to content

Malwarebytes

IP Block message help

- - - - -

58 replies to this topic

#41
Maniac

    Forum Deity

  • Experts
  • PipPipPipPipPipPip
  • 16,999 posts
  • Gender:Male
  • Location:Bulgaria, EU
I suggest you to do not use CCleaner for registry cleaner. It is not recommended that you use the Registry feature unless you are very familiar with the registry as it has been known to find legitimate items for removal, which can cause issues with other programs.

Any progress now?
My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#42
rsglick

    New Member

  • Members
  • Pip
  • 31 posts
I haven't got the IP block message as of yet. It was sporadic at best. I will watch it closely and if I get more I will post back. Either way I will wait a week or so, if I don't get anymore IP blocks from that same IP I will have to consider it fixed.

#43
Maniac

    Forum Deity

  • Experts
  • PipPipPipPipPipPip
  • 16,999 posts
  • Gender:Male
  • Location:Bulgaria, EU
Good! :)

Keep me informed.

Thanks!
My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#44
rsglick

    New Member

  • Members
  • Pip
  • 31 posts
I'm still getting the IP block message from the same IP.


2012/06/25 11:41:42 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 50805, Process: chrome.exe)
2012/06/25 11:41:42 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 50817, Process: chrome.exe)
2012/06/25 13:28:58 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 51419, Process: chrome.exe)
2012/06/25 13:29:38 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 51424, Process: chrome.exe)

#45
rsglick

    New Member

  • Members
  • Pip
  • 31 posts
On a side note, I had the freemake video converter plugin for chrome installled. I just uninstalled it so I can see if that was what was doing it. I have no other extensions installed on chrome. I will keep you advised.

#46
Maniac

    Forum Deity

  • Experts
  • PipPipPipPipPipPip
  • 16,999 posts
  • Gender:Male
  • Location:Bulgaria, EU
Good idea! :)

Let me know.
My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#47
rsglick

    New Member

  • Members
  • Pip
  • 31 posts
nope it didn't work.


2012/06/25 16:03:30 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53610, Process: chrome.exe)
2012/06/25 16:04:11 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53651, Process: chrome.exe)
2012/06/25 16:04:11 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53652, Process: chrome.exe)
2012/06/25 16:04:11 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53653, Process: chrome.exe)
2012/06/25 16:08:12 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53694, Process: chrome.exe)
2012/06/25 16:08:12 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53695, Process: chrome.exe)
2012/06/25 16:35:27 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 54127, Process: chrome.exe)

#48
Maniac

    Forum Deity

  • Experts
  • PipPipPipPipPipPip
  • 16,999 posts
  • Gender:Male
  • Location:Bulgaria, EU
Please download Fiddler and save it on your desktop. With its help we can determine which site is blocked. Will show in red in the left panel. Let me know.
My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#49
rsglick

    New Member

  • Members
  • Pip
  • 31 posts
Ok I've installed it. What do I do now?

#50
rsglick

    New Member

  • Members
  • Pip
  • 31 posts
[Fiddler] The socket connection to www.crazycampground.com failed. A Firewall may be blocking Fiddler's traffic.
ErrorCode: 10013.
An attempt was made to access a socket in a way forbidden by its access permissions 74.208.30.205:80

#51
Maniac

    Forum Deity

  • Experts
  • PipPipPipPipPipPip
  • 16,999 posts
  • Gender:Male
  • Location:Bulgaria, EU
Is this the full address to a Web site that showed you? Have you tried to load the site when this occurs?
My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#52
rsglick

    New Member

  • Members
  • Pip
  • 31 posts
I'm not really sure what I'm supposed to do or copy when I run that program. Do I just run it all the time and look for all the red ones and post them here? Is there a log for it? I'm not really sure what you want me to show you.

#53
Maniac

    Forum Deity

  • Experts
  • PipPipPipPipPipPip
  • 16,999 posts
  • Gender:Male
  • Location:Bulgaria, EU
I mean when you copy this one:

View Postrsglick, on 25 June 2012 - 08:28 PM, said:

[Fiddler] The socket connection to www.crazycampground.com failed. A Firewall may be blocking Fiddler's traffic.
ErrorCode: 10013.
An attempt was made to access a socket in a way forbidden by its access permissions 74.208.30.205:80

Is that the entire URL?

Try to load this website and let me know how are things.
My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#54
rsglick

    New Member

  • Members
  • Pip
  • 31 posts
That website was in red. I did try going to it and it worked fine. I know the people who are also associated with the site. It also is showing legit websites like microsoft as red.

#55
Maniac

    Forum Deity

  • Experts
  • PipPipPipPipPipPip
  • 16,999 posts
  • Gender:Male
  • Location:Bulgaria, EU
My question is: Is that the entire URL you post here? I mean this: www.crazycampground.com
My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#56
rsglick

    New Member

  • Members
  • Pip
  • 31 posts
yes that was the entire message, nothing omitted, that I got inside fiddler

#57
Maniac

    Forum Deity

  • Experts
  • PipPipPipPipPipPip
  • 16,999 posts
  • Gender:Male
  • Location:Bulgaria, EU
Please download WireShark and save it on your Desktop. Install it and run it. Then click on Start button. When you see the blocked IP on your screen, click on Stop the capture. Next, open File => Save As and save it on your Desktop. Finally, attach the file in your next reply.
My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#58
screen317

    MBAM Sentinel

  • Moderators
  • PipPipPipPipPipPip
  • 19,464 posts
  • Gender:Male
  • Location:New Haven, CT
Are you still with us? This topic will be closed in a few days if we do not hear back from you.
Chris Fistonich
Research Team

Posted Image

Follow us: Twitter, Become a fan: Facebook

#59
screen317

    MBAM Sentinel

  • Moderators
  • PipPipPipPipPipPip
  • 19,464 posts
  • Gender:Male
  • Location:New Haven, CT
Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!
Chris Fistonich
Research Team

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us