Today I manually turned on the Protection Module (another thread details my problems in getting it working automatically). I was looking for more information about the Outpost Agnitum Free Firewall that I've installed on my WinXP Pro computer, and after doing a Google search I went to a web site entitled The Web Hikers Guide to Outpost Firewall at www.outpostfirewall.com/guide/ . To my surprise, MBAM's IP Protection popped up, saying "Infection detected" and providing the IP number 208.73.210.27. As far as I could tell, this site (the Web Hikers Guide) wasn't blocked, but when I went to different pages on the site, MBAM repeated its warning. I think 8 instances are recorded in the MBAM log, all for the same IP address.
I'm not sure what "Infection detected" refers to. Infection where? On multiple pages of this seemingly innocent website? In the browser that accessed the site? I ran a Quick Scan with MBAM using database 2675, and no malware was found on my computer. How am I supposed to know whether there's really a problem with this site, and if there IS a problem, why am I able to access it and roam about on it? I should add that I did a WhoIs search for the IP address and found it's registered to a company in California that probably just distributes such addresses:
OrgName: Oversee.net
OrgID: OVERS-1
Address: 515 S. Flower St
Address: Suite 4400
City: Los Angeles
StateProv: CA
PostalCode: 90071
Country: US
NetRange: 208.73.208.0 - 208.73.215.255
CIDR: 208.73.208.0/21
NetName: OVERSEE-NET-2
NetHandle: NET-208-73-208-0-1
Parent: NET-208-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.OVERSEE.NET
NameServer: NS2.OVERSEE.NET
Comment:
RegDate: 2006-12-28
Updated: 2006-12-28
I'd really like to understand these "infection detected" alerts better. In particular, I'd like to know what specifically they refer to, when to take them seriously and when to ignore them, and what I should do when they appear. Thanks in advance for your help.
#1
Posted 22 August 2009 - 01:37 PM
Dell XPS 8300 Win7 Prof. 64-bit desktop (Intel Core i5-2400 processor, 8 GB RAM): MS Security Essentials AV, Windows Firewall, MBAM Pro, WinPatrol PLUS
Toshiba NB305-N410BL netbook: Win7 Starter (2 GB RAM), MS Security Essentials AV, Windows Firewall, MBAM Pro, WinPatrol PLUS
Toshiba NB305-N410BL netbook: Win7 Starter (2 GB RAM), MS Security Essentials AV, Windows Firewall, MBAM Pro, WinPatrol PLUS
#2
Posted 22 August 2009 - 02:05 PM
Have a look at this FAQ
It does not mean that you are infected. I believe I read that the MBAM team is working on changing the notification.
It does not mean that you are infected. I believe I read that the MBAM team is working on changing the notification.
Avira Antivir Personal and MBAM Pro
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
#3
Posted 22 August 2009 - 02:35 PM
prairie dog, on Aug 22 2009, 10:05 AM, said:
Have a look at this FAQ
It does not mean that you are infected. I believe I read that the MBAM team is working on changing the notification.
It does not mean that you are infected. I believe I read that the MBAM team is working on changing the notification.
I hope MBAM refines its IP Protection feature to provide a lot more specific information. Right now it seems to raise a number of unanswered questions. I have no idea, for example, where if at all on this site the threat lies or even if the threat is real.
Dell XPS 8300 Win7 Prof. 64-bit desktop (Intel Core i5-2400 processor, 8 GB RAM): MS Security Essentials AV, Windows Firewall, MBAM Pro, WinPatrol PLUS
Toshiba NB305-N410BL netbook: Win7 Starter (2 GB RAM), MS Security Essentials AV, Windows Firewall, MBAM Pro, WinPatrol PLUS
Toshiba NB305-N410BL netbook: Win7 Starter (2 GB RAM), MS Security Essentials AV, Windows Firewall, MBAM Pro, WinPatrol PLUS
#4
Posted 22 August 2009 - 02:41 PM
you're welcome
This being the first release of this new feature, I'm sure some tweaks will be coming in future updates
This being the first release of this new feature, I'm sure some tweaks will be coming in future updates
Avira Antivir Personal and MBAM Pro
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
#5
Posted 22 August 2009 - 03:19 PM
I believe that installing hpHOST file will block those sites and if you install HostsMan with its browser speed up proxy HostsServer that has logging capability you will be able to see what sites are referred that load malicious content:
http://www.softpedia.com/get/Network-Tools.../HostsMan.shtml
MysteryFCM is the maintainer of hpHosts file.
http://www.softpedia.com/get/Network-Tools.../HostsMan.shtml
MysteryFCM is the maintainer of hpHosts file.
E5200 2.5GHZ, 4GB RAM, 320GB HD, Win7 Home Premium 64-bit, avast! V6.0 Free, IE9
P4 2.8GHZ, 1.5GB RAM, 40GB HD, XP Pro SP3, 32-bit, avast! V6.0 Pro, Macrium Reflect
with IE8 and Chrome, hpHosts, MVPS HOSTS files, MBAM Full, OpenDNS, SpeedFan, WinPatrol PLUS
P4 2.8GHZ, 1.5GB RAM, 40GB HD, XP Pro SP3, 32-bit, avast! V6.0 Pro, Macrium Reflect
with IE8 and Chrome, hpHosts, MVPS HOSTS files, MBAM Full, OpenDNS, SpeedFan, WinPatrol PLUS
#6
Posted 22 August 2009 - 05:58 PM
YoKenny1, on Aug 22 2009, 11:19 AM, said:
I believe that installing hpHOST file will block those sites and if you install HostsMan with its browser speed up proxy HostsServer that has logging capability you will be able to see what sites are referred that load malicious content:
http://www.softpedia.com/get/Network-Tools.../HostsMan.shtml
http://www.softpedia.com/get/Network-Tools.../HostsMan.shtml
Again, thanks very much.
Dell XPS 8300 Win7 Prof. 64-bit desktop (Intel Core i5-2400 processor, 8 GB RAM): MS Security Essentials AV, Windows Firewall, MBAM Pro, WinPatrol PLUS
Toshiba NB305-N410BL netbook: Win7 Starter (2 GB RAM), MS Security Essentials AV, Windows Firewall, MBAM Pro, WinPatrol PLUS
Toshiba NB305-N410BL netbook: Win7 Starter (2 GB RAM), MS Security Essentials AV, Windows Firewall, MBAM Pro, WinPatrol PLUS
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
Sign In
Create Account


Back to top








