Q&A Malwarebytes not blocking IP address

Discussion in 'Malwarebytes' started by boredog, Nov 17, 2017.

  1. boredog

    boredog Level 8

    Jul 5, 2016
    392
    819
    Retired
    usa
    Windows 10
    Malwarebytes
    This mourning I got 6 blocks from Malwarebytes for the same IP.
    I then looked at my firewall and it showed an established connection outgoing. Unfortunately I didn't take a screen shot of the firewall connection but killed the connection.
    What I am wondering is if Malwarebytes logged the connection as being blocked, why did my firewall show it established. I am including a screen shot and the MB log file info.

    Malwarebytes
    www.malwarebytes.com
    -Log Details-
    Protection Event Date: 11/17/17
    Protection Event Time: 10:11 AM
    Log File: 07c33340-cbb2-11e7-a19e-00ffd3199732.json
    Administrator: Yes
    -Software Information-
    Version: 3.3.1.2183
    Components Version: 1.0.236
    Update Package Version: 1.0.3282
    License: Premium
    -System Information-
    OS: Windows 10 (Build 17035.1000)
    CPU: x64
    File System: NTFS
    User: System
    -Blocked Website Details-
    Malicious Website: 1
    , , Blocked, [-1], [-1],0.0.0
    -Website Data-
    Domain: tn.symcd.com
    IP Address: 23.60.139.27
    Port: [51701]
    Type: Outbound
    File: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe

    (end)
    ScreenHunter_82 Nov. 17 10.31.jpg
     
  2. Emanuel Tomasin

    Emanuel Tomasin Level 3

    Nov 15, 2017
    111
    236
    Argentina
    Windows 10
    Emsisoft
  3. Opcode

    Opcode Level 18
    Content Creator

    Aug 17, 2017
    890
    6,303
    Caille
    Windows 10
    Since Microsoft Edge was the cause according to the logs, were you browsing at the time of the block alerts?
     
  4. boredog

    boredog Level 8

    Jul 5, 2016
    392
    819
    Retired
    usa
    Windows 10
    Malwarebytes
    Not sure what you mean.

    Malwarebytes said it blocked the connection but Tinywall said I was connected. Not sure what Edge has to do with that. I use CCleaner to clear all that.
     
    harlan4096 likes this.
  5. boredog

    boredog Level 8

    Jul 5, 2016
    392
    819
    Retired
    usa
    Windows 10
    Malwarebytes
    When I check tn.symcd.com on VT Malwarebytes URL checker gives an all clean and so that still doesn't explain why the installed Malwarebytes said it blocked that URL.
     
  6. Opcode

    Opcode Level 18
    Content Creator

    Aug 17, 2017
    890
    6,303
    Caille
    Windows 10
    Microsoft Edge was making an outbound connection to the IP address being flagged by Malwarebytes.

    Code:
    File: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
    
    Presumably you were browsing at the time of the alert notifications, otherwise another program was making the outbound connection whilst using Microsoft Edge to do it. Regarding VirusTotal, the engines on the service are not identical to those in the actual end-user products.

    There could be many explanations, it is hard to point the finger at any without more details.
     
    venustus and harlan4096 like this.
  7. boredog

    boredog Level 8

    Jul 5, 2016
    392
    819
    Retired
    usa
    Windows 10
    Malwarebytes
    I think was accessing the that site from e-mail for some reason.
     
  8. Emanuel Tomasin

    Emanuel Tomasin Level 3

    Nov 15, 2017
    111
    236
    Argentina
    Windows 10
    Emsisoft
    Reset Edge.Greetings friend.
     
  9. Emanuel Tomasin

    Emanuel Tomasin Level 3

    Nov 15, 2017
    111
    236
    Argentina
    Windows 10
    Emsisoft
    And how does that problem continue? Greetings friend.
     
  10. boredog

    boredog Level 8

    Jul 5, 2016
    392
    819
    Retired
    usa
    Windows 10
    Malwarebytes
    Well, last night my computer updated to the newest insider build 17040 and now Edge does not work at all. Won't open any pages and the update cleared all my favorites and killed Ublock. grrrrrr .Edge has never always opened pages in the past builds and have reported it but now they really did a number on Edge.
     
  11. Emanuel Tomasin

    Emanuel Tomasin Level 3

    Nov 15, 2017
    111
    236
    Argentina
    Windows 10
    Emsisoft
    You tried uninstalling Edge? Greetings, friend.
     
  12. boredog

    boredog Level 8

    Jul 5, 2016
    392
    819
    Retired
    usa
    Windows 10
    Malwarebytes
    I did the reset you posted and rebooted and all is well again.

    Thanks
     
  13. Emanuel Tomasin

    Emanuel Tomasin Level 3

    Nov 15, 2017
    111
    236
    Argentina
    Windows 10
    Emsisoft
    I'm glad friend. Best regards.
     
Loading...
Similar Threads Forum Date
SOLVED Malwarebytes blocking outgoing file(s) Malware Removal Assistance For Windows Oct 15, 2017
Malwarebytes blocking c:\windows\syswow64\dllhost.exe Malware Removal Assistance For Windows Jun 24, 2015
Malwarebytes Blocking C:\Windows\SysWOW64\dllhost.exe NONSTOP Malware Removal Assistance For Windows Feb 16, 2015