Jump to content

Malwarebytes

V1.40 Reports Valid IP Address As Infected


4 replies to this topic

#1
Hytec

    New Member

  • Members
  • Pip
  • 2 posts
Version 1.40 added IP address blocking. My copy now is reporting that a valid IP address is infected. Also it appears that Malwarebytes is scanning the data being downloaded from that site before allowing it to be displayed, which takes 15-20 seconds. However, there does not appear to be any way that I can determine what conditions cause Malwarebytes to report this site, or to tell it that this site is OK.

The IP address is 206.44.108.236 which belongs to Netelligent Hosting Services, Inc. of Laval, QC. I am assuming that one of the 657 companies that Netelligent hosts is an advertiser or link on the primary website site that I'm downloading, which I do many times every day. Also, this is the only site where this condition occurs. BTW, Malwarebytes does not report or log this site after running a Full Scan which is surprising since it has been detected and reported as infected.

Does anyone have a suggestion as to how to correct this condition?

Thanks

#2
GT500

    Mostly Cantankerous

  • Trusted Advisors
  • PipPipPipPipPipPip
  • 5,532 posts
  • Gender:Male
  • Location:Fortville, IN
Well, I'm not seeing anything bad about that IP, but Steven will have to be the one to take a look at it.

What website are you browsing while this comes up, and what are you trying to download?

You can always right-click on the Malwarebytes' Anti-Mawlare icon down in the lower-right corner of your screen, and select to turn off IP Protection. This is, of course, just a temporary fix.

Quote

For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...

#3
Hytec

    New Member

  • Members
  • Pip
  • 2 posts
The threat report only occurs when I download from Trainboard.com. Unfortunately it occurs with every page associated with that site. Trainboard.com is powered by vBulletin, if that helps.

#4
Raid

    Malware Researcher

  • Experts
  • PipPipPipPipPipPip
  • 1,549 posts
  • Gender:Male
  • Location:United States
I have informed Steven of this issue, as soon as is possible we'll see what we can do about this. Sorry for any inconvenience caused.

#5
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,233 posts
  • Gender:Male
  • Location:Tyneside, UK
Netelligent are sadly, known as a crimeware friendly ISP, which is why their IP ranges are blackholed.

This particular IP however, is on a range owned by American Standard, Inc., and is not actually in the IPBL.

http://hosts-file.ne...=206.44.108.236
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us