What does IP Protection do?
IP Protection provides an additional layer of security for your computer, by preventing access to known malicious IP addresses and IP ranges, for example, NetDirekt, which is host to the Internet Service Team.
How does it do this?
When you ask your browser to connect to a website, Windows uses DNS or the HOSTS file (depending on configuration), to convert that domain name into it's corresponding IP address (e.g. example.com <> 126.96.36.199). MBAM intercepts the packet communications, to determine whether or not the IP address is known for malicious activity, and if so, blocks the communication.
How does it inform you?
MBAM informs you a malicious IP has been blocked by presenting a bubble notification at the bottom of the screen (next to the system tray).
What does this notification mean?
This notification means quite simply, that an IP address has been blocked. It does NOT necessarily mean you are infected, it simply means a program on your computer (e.g. your browser, IM program, P2P program etc), tried accessing a malicious IP address. If this notice was presented when you were not actually doing anything on the machine, then I suggest having your computer looked at.
I got an alert and I wasn't even surfing, how's that happen?
There are many applications on your system which have access to the Net and any of these can trigger an IP alert with no browser open. Most common offenders are P2P applications and IM clients, usually an ad will trigger an alert. An advanced or premium firewall will be able to give you a list of programs which can access the Net.
I received a notification on a safe site, why?
If a notification is presented on a safe site, and the site loads, it is likely the site was loading content that is hosted on an IP known for malicious activity. In this case, the site itself will be displayed perfectly fine, with the malicious content being blocked.
If however, the site does not load, it is likely the site is also hosted on the same malicious IP address.
It is also entirely possible that the site in question, shares it's IP address with other malicious domains. IP's and IP ranges are blocked if they are either dedicated to malicious content, or have a higher proportion of malicious content, than non-malicious. So for example, if 188.8.131.52 contains 1000 sites and over 50% are malicious, then 184.108.40.206 will be blocked (and even then, if we can get the hosting company to take down the malicious sites, then even better as we do not like blocking shared IP's or IP ranges if we don't have to).
How do I disable this?
I wouldn't recommend disabling it, but if you must, you can do this by right clicking the MBAM tray icon, and unchecking "IP Protection".
I got an alert for an IP or website I think is safe, how can I report it?
If you find a site being blocked, and either don't know why, or are sure it's safe, please report it to us at the False Positive Forum.
IMPORTANT: When posting false postive reports, please ensure you post both the IP address affected, and if applicable, the domain name (e.g. example.com).
Does the IP Protection replace my firewall?
Absolutely NOT! The IP Protection included in Malwarebytes Anti-Malware is NOT a replacement for your firewall.
Where do I find the IP Protection logs?
You can find the logs for the IP Protection facility at;
%AllUsersProfile%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs
Note: %AllUsersProfile% refers to the location of the "All Users" Windows profile, and is usually C:\Documents and Settings\All Users\
How can I add an IP so it won't be detected and can access a site I need to?
This has now been implemented. Visit the blocked site and incur an IP block. Then right-click on the Malwarebytes system-tray icon after the block notification appears, and choose Add to Ignore List and the IP.