Last night Malwarebytes started blocking IPs in Firefox when the browser opens - and whenever I use the browser to surf. The browser is working slowly and these same IPs are not being blocked in IE:
216.240.187.103
216.240.187.102
The browser fights to connect with these IPs. I believe after a bit of troubleshooting it is related to the updater. When I disable the IP protection, the updater for the browser and the updater for my addons works. They do not connect when malwarebytes is on. I don't know if this is a false positive or if somehow my browser is infected or corrupted.
I have tried to contact firefox to find out if these ips are related to their service. I did not get very much information. They did say that .103 is a firefox 403 forbidden error. They did not address the .102 ip at all during the chat session. I did follow their instructions to re-add their program in McAfee. [I had been getting a message that update XML file malformed (200)] After re-adding the program to my firewall, I no longer got that error notice but it still would not update unless I disabled the Malwarebytes IP protection. They gave no other info. I have been through their troubleshooting process. I have started it in safe mode - same alerts. I have disabled all addons and I have no themes - same problem on startup of firefox - getting alerts to the IPs. I redownloaded the program - same problems. The only thing I have not done yet is a wipeout and a complete reinstall from scratch - which I am trying to avoid in order not to lose my bookmarks and have to reload all the features.
I have run my full-scan malwarebytes and get no issues. I have run a full scan in McAfee and get no issues - I also ran their scan from their website to make sure that their program's antivirus is not being blocked somehow.
The mbam log which was run in the developer's mode was:
Malwarebytes' Anti-Malware 1.41
Database version: 3081
Windows 5.1.2600 Service Pack 3
11/2/2009 12:43:19 PM
mbam-log-2009-11-02 (12-43-19).txt
Scan type: Full Scan (C:\|)
Objects scanned: 190664
Time elapsed: 1 hour(s), 25 minute(s), 42 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
My discussion with Firefox was:
Thank you for using Firefox Support's Live Chat. If you still need help, you can visit http://support.mozilla.com to find an answer or ask another question.
[12:25 PM] wandergirl has joined the room
[12:25 PM] zzxc has joined the room
[12:25 PM] zzxc: Hello
[12:25 PM] wandergirl: HI did you get my message? I need help.
[12:27 PM] wandergirl: I am getting alerts that malicious IPs are being blocked in my browser: 216.240.187.103 & .102
[1 2:27 PM] zzxc: yes
[12:27 PM] zzxc: '
[12:27 PM] zzxc: Are they blocked in other browsers as well?
[12:27 PM] wandergirl: no
[12:27 PM] wandergirl: Do you work with these IPs?
[12:28 PM] wandergirl: I have tried all of you're troubleshooting directions and nothing helps. I have even disabled Malwarebytes to see if it is a false positive blocking the updater and it is not.
[12:29 PM] wandergirl: I still get the error for malformed file (200) when Malwarebytes is disabled.
[12:31 PM] wandergirl: I do not get the messages when I use IE.
[12:33 PM] zzxc: I get a 403 forbidden error at 216.240.187.103
[12:33 PM] wandergirl: The only troubleshooting step I have not yet taken is the complete wipeout of firefox for a fresh reload. I have already done a reinstall without wipeout.
[12:33 PM] wandergirl: what is that?
[12:33 PM] wandergirl: what do think is going on?
[12:34 PM] zzxc: Does this work when malwarebytes is disabled?
[12:36 PM] wandergirl: no the updater still will not update - I get the xml file malformed 200 error even when malwarebytes disabled.
[12:37 PM] wandergirl: nothing will update - not even addons.
[12:39 PM] zzxc: ok
[12:39 PM] zzxc: try running enumprocess to see all othe r security programs
[12:39 PM] zzxc: http://www.trolly.homepage.t-online.de/EnumProcess.exe
[12:40 PM] wandergirl: It says windows firewall is off 9 processes from McAfee detected - I use their firewall.
[12:43 PM] wandergirl: I use malwarebytes and mcafee total protection. Only malwarebytes is blocking what it deems to be malicious ips from loading into the firefox browser. this does not happen on IE
[12:44 PM] wandergirl: has my browser been corrupted?
[12:44 PM] wandergirl:</ td> I am trying to figure that out if it is corrupted or this is a false positive.
[12:44 PM] zzxc: What did enumprocess say?
[12:45 PM] zzxc: This problem is usually caused by a misbehaving firewall.
[12:45 PM] wandergirl: it said that windows firewall is off and 9 processes from mcafee detected.
[12:46 PM] wandergirl: I have already tired disabling the ip addresses in my firewall - then the updater just reads no updates available. when i took the addresses out of the blocked list, the programs tries to update but cannot - again the prol
[12:47 PM] wandergirl: the problem is that malwarebytes is blocking it - not the firewall and says that the ips are malicious and I was assuming that they were associated with the updater
[12:48 PM] wandergirl: when i looked up the ips online one said that the .103 was associated with firefox
[12:48 PM] wandergirl: but you have said that .103 is a forbidden error
[12:50 PM] zzxc: Which firewall do you have?
[12:50 PM] wandergirl: McAfee - it is part of the total protection security suite
[12:54 PM] zzxc: try the steps at ((configuring mcafee internet security))
[12:56 PM] wandergirl: ok hold on
[12:56 PM] wandergirl: do I have to close our chat to perform this?
[12:59 PM] wandergirl has left the room
Like I said these instructions did nothing. The browser had been set to full access in my firewall. When I re-installed firefox.exe, I gave it only outgoing permissions. The same alerts happened nothing changed.
Please please help me figure this out.
