Jump to content

Malwarebytes

Skype


11 replies to this topic

#1
ehambra

    New Member

  • Members
  • Pip
  • 4 posts
Every time I open Skype a I get a pop-up warning saying Malwarebyte's Anti-malware has successfully blocked access to malicious IP: 89.28.118.132

What is that?

Thanks

#2
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
I've asked one of the support guys to stop by and take a look at your post. He'll be able to give you further advice.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#3
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
The IP belongs to Starnet, and has no relation to Skype that I can find.

http://hosts-file.net/?s=89.28.118.132

If possible, could you try and identify the source and target please? (either your firewall logs, or Wireshark (http://www.wireshark.org), will be able to provide the necessary details).
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#4
ehambra

    New Member

  • Members
  • Pip
  • 4 posts
My router does not show that is getting an attack from that IP. If I type on the browser the IP 89-28-118-132 Malearebyte's Anti-malware popups with the warning.

But every time I sign in on Skype pops up and every minute as well

#5
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
The IP is on a known malicious network, so I'd strongly advise against trying to load it.

There's two possibilities for this issue, either there's adverts in the program causing a connection, or the program itself is doing such. We need to track this down, and the best way of doing this, is using a firewall (NOT your router).

Either download Wireshark from the following;

http://www.wireshark.org

Or download a firewall such as Online Armor if you've not already got one;

http://www.tallemu.com

Both of these will provide logs that will allow us to see the destination and source details (Wireshark will also additionally give us the packet information, so we can see why it is trying to contact the IP).
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#6
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
You could also try running these commands from a DOS console.


ipconfig /displaydns
netstat -a
netstat -b -v
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#7
ehambra

    New Member

  • Members
  • Pip
  • 4 posts
Can you tell from this report? www.slaudio.com.ar/report.pcap

#8
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
I'm not seeing anything referencing that IP in the pcap file, no.
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9
ehambra

    New Member

  • Members
  • Pip
  • 4 posts
It is weird do. I have run several times and cannot fond that IP, but while I am running it I open Skype, and MBAM shows the warning: Malwarebyte's Anti-malware has successfully blocked access to malicious IP: 89.28.118.132

I have deleted all my contacts and still the same. It happens when I sign in only.

Anything else that I can try?

Thanks

#10
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
Can you do the following please?

1. Install WireShark
2. Load WireShark and open Skype

If the IP doesn't show up, close Skype and disable MBAM's IP Protection, then re-load Skype

Then post the log here.
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#11
dv986

    New Member

  • Members
  • Pip
  • 21 posts
  • Gender:Male
  • Location:Croatia
Hi everyone. I have a similar problem. Slightly different IP, but on the same network id. I also had Skype turned on.

I will send some of the Oupost Firewalls log that correlates with the timeframe of the MBAMs log to Malwarebyte support by email. I'll keep you informed :)
Computer: Hp 4710s, Intel Core2Duo 2,53 ghz, 4gb Ram, 500 gb hdd, Ati Mobility Radeon 4330 512mb, Windows 7 x64
Security: G Data, Immunet, Malwarebytes' Anti-Malware Pro, SuperAntiSpyware Pro, Outpost Firewall Pro, Threatfire, PeerBlock, HostMan
Other: Acronis True Image 2010, O&O Defrag 12, Revo Uninstaller Pro, Macro Express Pro, Process Lasso, PrimoPDF, Winamp, CDBurnerXP, Alcohol 52%, Flash Renamer, Registry Workshop, jv16 PowerTools 2009, Search Everything, TeraCopy, Mozilla Firefox, Skype

#12
dv986

    New Member

  • Members
  • Pip
  • 21 posts
  • Gender:Male
  • Location:Croatia
Alright, I got the following response:

Quote

That IP address resolves to Moldova:
http://hosts-file.ne...p?s=89.28.11.13


It's possible that the server at that address is sending out spam messages via Skype, and our software is blocking them.

Hope this helps :-)
Computer: Hp 4710s, Intel Core2Duo 2,53 ghz, 4gb Ram, 500 gb hdd, Ati Mobility Radeon 4330 512mb, Windows 7 x64
Security: G Data, Immunet, Malwarebytes' Anti-Malware Pro, SuperAntiSpyware Pro, Outpost Firewall Pro, Threatfire, PeerBlock, HostMan
Other: Acronis True Image 2010, O&O Defrag 12, Revo Uninstaller Pro, Macro Express Pro, Process Lasso, PrimoPDF, Winamp, CDBurnerXP, Alcohol 52%, Flash Renamer, Registry Workshop, jv16 PowerTools 2009, Search Everything, TeraCopy, Mozilla Firefox, Skype





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us