I was just browsing Youtube and got a "Malwarebytes' Anti-Malware IP Protection: Infection detected: 209.44.99.178" notice.
I'm not sure if Youtube has anything to do with it since I googled the IP and found out it belongs to Evilrtcw2.com and also evilterritory.com and warcraft-source.com.
Is this a threat or just a common false positive?
Thanks for your support.
IP protection detecting infection from evilterritory.com/Evilrtcw2.com
Started by derrick90, Sep 04 2009 11:19 PM
#1
Posted 04 September 2009 - 11:19 PM
#2
Posted 04 September 2009 - 11:32 PM
It looks like a legit IP, but I'm not an expert. See here
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#3
Posted 04 September 2009 - 11:43 PM
swagger, on Sep 4 2009, 11:32 PM, said:
It looks like a legit IP, but I'm not an expert. See here
Well, it's not listed on hosts-file.net's database.
Do you (or anyone else viewing this thread) get the same message when you visit evilterritory.com or any of the other sites that I mentioned?
Also, how reliable is hosts-file.net as a threat identifier?
#4
Posted 04 September 2009 - 11:47 PM
It isn't blocked on 1.41 beta which may further back the evidence for a false positive as there is a bug in 1.40 that blocks legitimate IPs.
I've seen most of the experts refer to http://hosts-file.net when dealing with IPs since this new feature has been introduced. I think with that being said, it's pretty reliable
I've seen most of the experts refer to http://hosts-file.net when dealing with IPs since this new feature has been introduced. I think with that being said, it's pretty reliable
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#5
Posted 04 September 2009 - 11:52 PM
swagger, on Sep 4 2009, 11:47 PM, said:
It isn't blocked on 1.41 beta which may further back the evidence for a false positive as there is a bug in 1.40 that blocks legitimate IPs.
I've seen most of the experts refer to <a href="http://hosts-file.net" target="_blank">http://hosts-file.net</a> when dealing with IPs since this new feature has been introduced. I think with that being said, it's pretty reliable
I've seen most of the experts refer to <a href="http://hosts-file.net" target="_blank">http://hosts-file.net</a> when dealing with IPs since this new feature has been introduced. I think with that being said, it's pretty reliable
Thanks for your insight but I'd like an expert (you said you are not one) to answer my question, no offense intended.
And thanks for the info about hosts-file.net
#6
Posted 04 September 2009 - 11:57 PM
No offense taken at all. You have your rights
I hope one helps you soon
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#7
Posted 05 September 2009 - 01:00 AM
A little update: IP Protection just detected 200.98.197.7. This site is listed on hosts-file.net and is considered to be threatening.
The only reason that I found it necessary to make this thread is because I don't usually get warnings like this regularly from MBAM. I am getting these warnings while browsing sites that I commonly visit. It's just at this moment that I am getting an unreasonable amount of warnings which makes me suspect something harmful. I don't have a p2p program open so I know it's not a false positive from some random person.
Any ideas as to what might be going on?
The only reason that I found it necessary to make this thread is because I don't usually get warnings like this regularly from MBAM. I am getting these warnings while browsing sites that I commonly visit. It's just at this moment that I am getting an unreasonable amount of warnings which makes me suspect something harmful. I don't have a p2p program open so I know it's not a false positive from some random person.
Any ideas as to what might be going on?
#8
Posted 05 September 2009 - 01:23 AM
You're right, according to hosts-file.net it does seem to be malicious. I tried pinging the IP from my desktop running version 1.41 beta and I was able to reach the IP. This could be due to the fact that the definitions for the beta don't include this IP... We aren't allowed to update from the beta because it's still being tested.
Do you have any IM software? What are the sites that you browse if you don't mind me asking? Maybe there's an ad on the page that is trying to load from that IP.
Do you have any IM software? What are the sites that you browse if you don't mind me asking? Maybe there's an ad on the page that is trying to load from that IP.
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#9
Posted 05 September 2009 - 01:28 AM
Quote
@ Derrick90
I might be mistaken, but, I think that P2P's could potentially cause this to happen even if they aren't actually open. Do you have any P2P programs?
I might be mistaken, but, I think that P2P's could potentially cause this to happen even if they aren't actually open. Do you have any P2P programs?
#10
Posted 05 September 2009 - 01:36 AM
swagger, on Sep 5 2009, 02:23 AM, said:
You're right, according to hosts-file.net it does seem to be malicious. I tried pinging the IP from my desktop running version 1.41 beta and I was able to reach the IP. This could be due to the fact that the definitions for the beta don't include this IP... We aren't allowed to update from the beta because it's still being tested.
Do you have any IM software? What are the sites that you browse if you don't mind me asking? Maybe there's an ad on the page that is trying to load from that IP.
Do you have any IM software? What are the sites that you browse if you don't mind me asking? Maybe there's an ad on the page that is trying to load from that IP.
When you say "IM software" you mean instant messaging right? If so, then no, although I have previously installed a few of them, which are now uninstalled (properly I hope).
The sites that I have been browsing include youtube, google, yahoo and other similar sites. Just general popular sites like this. I actually got the 200.98.197.7 warning while I was using the google search engine... These warnings may have had nothing to do with the sites that I was browsing, I just listed some of them as I thought it might be relevant.
#11
Posted 05 September 2009 - 01:40 AM
Yes, I use uTorrent and I have never had any problems using utorrent and MBAM in sync. I usually turn off IP protection while using utorrent to avoid the constant false positives.
I have never encountered this problem while utorrent was inactive.
I have never encountered this problem while utorrent was inactive.
#12
Posted 05 September 2009 - 01:55 AM
Quote
@ Derrick90
Hmm I'm out of ideas then. Hopefully an expert on this can jump in here and hopefully will be able to tell you whats going on or what might be going on.
Hmm I'm out of ideas then. Hopefully an expert on this can jump in here and hopefully will be able to tell you whats going on or what might be going on.
#13
Posted 05 September 2009 - 02:12 AM
Apologies for taking so long to notice this thread. To answer your questions;
209.44.99.178
This IP is on a Netelligent IP range, who are known for housing criminals, which is why it is blocked.
200.98.197.7
The IP itself seems fine, I can't identify any malicious activity thus far, however, the rest of the range does presently house malicious activity, because of this, the range itself was blocked, rather than just the IP's.
/edit
For clarity by the way, hpHosts is actually run by me.
209.44.99.178
This IP is on a Netelligent IP range, who are known for housing criminals, which is why it is blocked.
200.98.197.7
The IP itself seems fine, I can't identify any malicious activity thus far, however, the rest of the range does presently house malicious activity, because of this, the range itself was blocked, rather than just the IP's.
/edit
For clarity by the way, hpHosts is actually run by me.
#14
Posted 05 September 2009 - 02:33 AM
MysteryFCM, on Sep 5 2009, 03:12 AM, said:
Apologies for taking so long to notice this thread. To answer your questions;
209.44.99.178
This IP is on a Netelligent IP range, who are known for housing criminals, which is why it is blocked.
200.98.197.7
The IP itself seems fine, I can't identify any malicious activity thus far, however, the rest of the range does presently house malicious activity, because of this, the range itself was blocked, rather than just the IP's.
/edit
For clarity by the way, hpHosts is actually run by me.
209.44.99.178
This IP is on a Netelligent IP range, who are known for housing criminals, which is why it is blocked.
200.98.197.7
The IP itself seems fine, I can't identify any malicious activity thus far, however, the rest of the range does presently house malicious activity, because of this, the range itself was blocked, rather than just the IP's.
/edit
For clarity by the way, hpHosts is actually run by me.
Thanks for the info.
The "attacks" seem to have subsided for now. I will update this thread if I encounter any more threats.
Thanks again.
#15
Posted 05 September 2009 - 02:39 AM
#16
Posted 05 September 2009 - 01:21 PM
MysteryFCM, on Sep 4 2009, 10:12 PM, said:
For clarity by the way, hpHosts is actually run by me.
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#17
Posted 06 September 2009 - 10:51 AM
#18
Posted 07 September 2009 - 01:16 AM
I have a question and I'm not sure this is the place to post it -- but when I am browsing and I get a warning that Malwarebytes has identified an infection - do they quarantine or disinfect automatically? Each time I get this warning I immediately do a full scan and no malicious objects are detected?
#19
Posted 07 September 2009 - 01:18 AM
It's not actually an infection per-se, it's a known malicious IP, so it will actually prevent the site from infecting you to begin with.
For details, please see;
http://www.malwareby...showtopic=21076
For details, please see;
http://www.malwareby...showtopic=21076
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
Sign In
Create Account
Back to top










