• MalwareBytes false positive?

    Author
    Topic
    #483020

    My paid Pro version of MalwareBytes keep notifying me it is blocking access to a certain IP address –
    here’s the log entry:
    IP-BLOCK 204.51.78.248 (Type: outgoing, Port: 49569, Process: firefox.exe)

    I ran the IP on VirusTotal and it’s apparently a clean site, so I’m not sure what’s going on here.
    I’d be a bit hesitant to disable MBAM and see what’s at that address. A full scan earlier today removed
    “Trojan.Tracur,’ will rerun the scan. I’m also using MS Security Essentials, along with OpenDNS on my
    router. I don’t usually get this kind of hassle, so I’m wondering if contacting that IP is something Firefox does
    during regular use.

    geobytes.com says it’s in Miami, FL but I’m fishing for more information.
    http://www.geobytes.com/IpLocator.htm?GetLocation&IpAddress=204.51.78.248

    A reverse IP lookup at domaintz.com has this:
    [TABLE=”class: list-view”]
    [TR]
    [TD]Resolve Host:[/TD]
    [TD]n/a (204.51.78.248)
    [/TD]
    [/TR]
    [TR]
    [TD]IP Location:[/TD]
    [TD] United States, Wilmington, MPC Systems LLC (204.51.78.248)
    [/TD]
    [/TR]
    [TR]
    [TD]Reverse IP:[/TD]
    [TD]none
    [/TD]
    [/TR]
    [/TABLE]

    Any clues? Thanks for the help!

    Jim

    Viewing 1 reply thread
    Author
    Replies
    • #1330997

      Have you checked with the Malwarebytes Forums?

      Joe

      --Joe

    • #1330999

      Allow MBAM to permanently block the IP and rerun the scan from safemode too, if you havn’t already.
      I don’t think anyone could say it’s a fales posative, especially since you reportedly removed a known redirect trojan.

    Viewing 1 reply thread
    Reply To: MalwareBytes false positive?

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: