IT bods - quick que...
 

  You don't need to be an 'investor' to invest in Singletrack: 6 days left: 95% of target - Find out more

[Closed] IT bods - quick question on malware....

10 Posts
5 Users
0 Reactions
64 Views
 DT78
Posts: 10064
Free Member
Topic starter
 

my virus protection (malwarebytes) keeps flashing up a warning when I'm on a website.

Pops up -

successfully blocked access to a potential malicious website 91.214.44.120

type outgoing
port 49329
process chrome.exe

Any ideas what this is, and what I should do about it? The site itself seems genuine (though it could be shady)


 
Posted : 16/02/2012 12:05 am
Posts: 0
Free Member
 

Malware alerts are over vealous at times.

Google says that ip is to do with us military stuff. Is that related to your search?

http://revip.info/ipinfo/91.214.44.120


 
Posted : 16/02/2012 12:07 am
 DT78
Posts: 10064
Free Member
Topic starter
 

No.... it's a replica watch site (a colleague has used them in the past, but hence the could be shady comment)

Military? Hmmmmmm


 
Posted : 16/02/2012 12:11 am
Posts: 2
Free Member
 

Has it been set as your home page?


 
Posted : 16/02/2012 12:16 am
Posts: 0
Free Member
 

Just google the ip. Ignore the top 5 of all listings (if its proper dodgy then that would be fixed / scammed). Eyeball the rest.

If in doubt - use google chrome - and cntl - shift - N = private mode -nothing is allowed install / download on your machine ("is" should really be "shouldnt").


 
Posted : 16/02/2012 12:17 am
 DT78
Posts: 10064
Free Member
Topic starter
 

Not set as homepage, just cleared all the cookies, clicked on url and same message, different port this time 50643.

Maybe I'll leave it alone, seems dodgy

Link I'm clicking on below, but at your own risk!
http://www.watchs-shops.co.uk/breitling-watches/breitling-chronomat-b01-chronograph-watches-br1685.html


 
Posted : 16/02/2012 12:20 am
Posts: 0
Free Member
 

Nope, nothing for me?


 
Posted : 16/02/2012 12:21 am
Posts: 0
Free Member
 

In a cosseted sub-session that doesnt ring any alarms at all. But the price of that is well dodgy. To me that's an obvious fake. Sorry.

#Edit. A £5000 watch for £80 and you have to ask. I've just wasted my time!


 
Posted : 16/02/2012 12:24 am
Posts: 2
Free Member
 

Well. Something on your computer is trying to get there.

Checked the installed software? Run a malware scan?


 
Posted : 16/02/2012 12:27 am
 DT78
Posts: 10064
Free Member
Topic starter
 

off to google 'cosseted sub-session'

watches themselves are most definitely fake, however unless you hold next to the real thing it is very difficult to know. Reason I was looking is a chap I met today had a rolex sub, which turned out to be a fake from this site. Looked the part to me.

(and yes, yes I would love the real thing, just not likely in this life time - most likely I will get a homage like Steinharts Ocean1, just googling options at the moment and got worried I'd picked up a virus)

EDIT - great, googling cosseted sub-session comes up with this thread....


 
Posted : 16/02/2012 12:29 am
Posts: 77347
Free Member
 

Could be an embedded advert or something. Maybe something to do with the 'live chat' widget that's floating around on the site?

"Potentially malicious" does not directly equate to "actually malicious," could just be MBAM being overcautious as couldahadashortername says.

cosseted sub-session

I think that's about 80 quid an hour in Soho.


 
Posted : 16/02/2012 10:52 am

6 DAYS LEFT
We are currently at 95% of our target!