Every time I open Skype a I get a pop-up warning saying Malwarebyte's Anti-malware has successfully blocked access to malicious IP: 89.28.118.132
What is that?
Thanks
#1
Posted 25 October 2009 - 01:38 AM
#2
Posted 25 October 2009 - 02:01 AM
I've asked one of the support guys to stop by and take a look at your post. He'll be able to give you further advice.
#3
Posted 25 October 2009 - 02:08 AM
The IP belongs to Starnet, and has no relation to Skype that I can find.
http://hosts-file.net/?s=89.28.118.132
If possible, could you try and identify the source and target please? (either your firewall logs, or Wireshark (http://www.wireshark.org), will be able to provide the necessary details).
http://hosts-file.net/?s=89.28.118.132
If possible, could you try and identify the source and target please? (either your firewall logs, or Wireshark (http://www.wireshark.org), will be able to provide the necessary details).
#4
Posted 25 October 2009 - 02:46 AM
My router does not show that is getting an attack from that IP. If I type on the browser the IP 89-28-118-132 Malearebyte's Anti-malware popups with the warning.
But every time I sign in on Skype pops up and every minute as well
But every time I sign in on Skype pops up and every minute as well
#5
Posted 25 October 2009 - 03:02 AM
The IP is on a known malicious network, so I'd strongly advise against trying to load it.
There's two possibilities for this issue, either there's adverts in the program causing a connection, or the program itself is doing such. We need to track this down, and the best way of doing this, is using a firewall (NOT your router).
Either download Wireshark from the following;
http://www.wireshark.org
Or download a firewall such as Online Armor if you've not already got one;
http://www.tallemu.com
Both of these will provide logs that will allow us to see the destination and source details (Wireshark will also additionally give us the packet information, so we can see why it is trying to contact the IP).
There's two possibilities for this issue, either there's adverts in the program causing a connection, or the program itself is doing such. We need to track this down, and the best way of doing this, is using a firewall (NOT your router).
Either download Wireshark from the following;
http://www.wireshark.org
Or download a firewall such as Online Armor if you've not already got one;
http://www.tallemu.com
Both of these will provide logs that will allow us to see the destination and source details (Wireshark will also additionally give us the packet information, so we can see why it is trying to contact the IP).
#6
Posted 25 October 2009 - 03:09 AM
You could also try running these commands from a DOS console.
ipconfig /displaydns
netstat -a
netstat -b -v
ipconfig /displaydns
netstat -a
netstat -b -v
#7
Posted 25 October 2009 - 03:44 AM
Can you tell from this report? www.slaudio.com.ar/report.pcap
#8
Posted 25 October 2009 - 04:26 AM
I'm not seeing anything referencing that IP in the pcap file, no.
#9
Posted 25 October 2009 - 04:37 AM
It is weird do. I have run several times and cannot fond that IP, but while I am running it I open Skype, and MBAM shows the warning: Malwarebyte's Anti-malware has successfully blocked access to malicious IP: 89.28.118.132
I have deleted all my contacts and still the same. It happens when I sign in only.
Anything else that I can try?
Thanks
I have deleted all my contacts and still the same. It happens when I sign in only.
Anything else that I can try?
Thanks
#10
Posted 25 October 2009 - 07:47 AM
Can you do the following please?
1. Install WireShark
2. Load WireShark and open Skype
If the IP doesn't show up, close Skype and disable MBAM's IP Protection, then re-load Skype
Then post the log here.
1. Install WireShark
2. Load WireShark and open Skype
If the IP doesn't show up, close Skype and disable MBAM's IP Protection, then re-load Skype
Then post the log here.
#11
Posted 19 December 2009 - 02:27 AM
Hi everyone. I have a similar problem. Slightly different IP, but on the same network id. I also had Skype turned on.
I will send some of the Oupost Firewalls log that correlates with the timeframe of the MBAMs log to Malwarebyte support by email. I'll keep you informed
I will send some of the Oupost Firewalls log that correlates with the timeframe of the MBAMs log to Malwarebyte support by email. I'll keep you informed
Computer: Hp 4710s, Intel Core2Duo 2,53 ghz, 4gb Ram, 500 gb hdd, Ati Mobility Radeon 4330 512mb, Windows 7 x64
Security: G Data, Immunet, Malwarebytes' Anti-Malware Pro, SuperAntiSpyware Pro, Outpost Firewall Pro, Threatfire, PeerBlock, HostMan
Other: Acronis True Image 2010, O&O Defrag 12, Revo Uninstaller Pro, Macro Express Pro, Process Lasso, PrimoPDF, Winamp, CDBurnerXP, Alcohol 52%, Flash Renamer, Registry Workshop, jv16 PowerTools 2009, Search Everything, TeraCopy, Mozilla Firefox, Skype
Security: G Data, Immunet, Malwarebytes' Anti-Malware Pro, SuperAntiSpyware Pro, Outpost Firewall Pro, Threatfire, PeerBlock, HostMan
Other: Acronis True Image 2010, O&O Defrag 12, Revo Uninstaller Pro, Macro Express Pro, Process Lasso, PrimoPDF, Winamp, CDBurnerXP, Alcohol 52%, Flash Renamer, Registry Workshop, jv16 PowerTools 2009, Search Everything, TeraCopy, Mozilla Firefox, Skype
#12
Posted 19 December 2009 - 01:21 PM
Alright, I got the following response:
Hope this helps :-)
Quote
That IP address resolves to Moldova:
http://hosts-file.ne...p?s=89.28.11.13
It's possible that the server at that address is sending out spam messages via Skype, and our software is blocking them.
http://hosts-file.ne...p?s=89.28.11.13
It's possible that the server at that address is sending out spam messages via Skype, and our software is blocking them.
Hope this helps :-)
Computer: Hp 4710s, Intel Core2Duo 2,53 ghz, 4gb Ram, 500 gb hdd, Ati Mobility Radeon 4330 512mb, Windows 7 x64
Security: G Data, Immunet, Malwarebytes' Anti-Malware Pro, SuperAntiSpyware Pro, Outpost Firewall Pro, Threatfire, PeerBlock, HostMan
Other: Acronis True Image 2010, O&O Defrag 12, Revo Uninstaller Pro, Macro Express Pro, Process Lasso, PrimoPDF, Winamp, CDBurnerXP, Alcohol 52%, Flash Renamer, Registry Workshop, jv16 PowerTools 2009, Search Everything, TeraCopy, Mozilla Firefox, Skype
Security: G Data, Immunet, Malwarebytes' Anti-Malware Pro, SuperAntiSpyware Pro, Outpost Firewall Pro, Threatfire, PeerBlock, HostMan
Other: Acronis True Image 2010, O&O Defrag 12, Revo Uninstaller Pro, Macro Express Pro, Process Lasso, PrimoPDF, Winamp, CDBurnerXP, Alcohol 52%, Flash Renamer, Registry Workshop, jv16 PowerTools 2009, Search Everything, TeraCopy, Mozilla Firefox, Skype
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
Sign In
Create Account

Back to top









