title
Products            Buy            Support Forum            Professional            About            Codec Central
 

Malwarebytes blocking cd ripper?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • WillT
    • Nov 2016
    • 5

    Malwarebytes blocking cd ripper?

    The ripper is working fine but today for the first time I got the following warning from Malwarebytes:

    Malicious Website Protection, Domain, 207.241.227.173, ia601303.us.archive.org, 49293, Outbound, C:\Program Files\dBpoweramp\CDGrab.exe

    I did a search and did not find anyone else with this issue but I am thinking it is a false positive? And that it would be OK to add that ip to Malwarebyte's exclusion list?
  • Spoon
    Administrator
    • Apr 2002
    • 43919

    #2
    Re: Malwarebytes blocking cd ripper?

    >ia601303.us.archive.org

    This is album art from Musicbrainz, not sure how a jpg image can be classed as malicious, it sounds like they are blocking all of archive.org, considering it is one of the largest, oldest websites on the internet, I not think it is wise of them.
    Spoon
    www.dbpoweramp.com

    Comment

    • WillT
      • Nov 2016
      • 5

      #3
      Re: Malwarebytes blocking cd ripper?

      OK Thanks. I can actually go to archive.org just fine without Malwarebytes blocking. But if I try to go to that particular link it blocks it. So I excluded it and went there anyway to see what is at that address. It is kind of odd and it is not album art. I don't really know what it is. It is just a list of numbers 1 to 35, each of which is a link to an index page which looks meaningless to me?

      Comment

      • Spoon
        Administrator
        • Apr 2002
        • 43919

        #4
        Re: Malwarebytes blocking cd ripper?

        You would need the full url, not just the domain name, but you cannot easily get this.
        Spoon
        www.dbpoweramp.com

        Comment

        • GeorgeButel
          • Aug 2005
          • 42

          #5
          Re: Malwarebytes blocking cd ripper?

          The same thing just happened to me. Click image for larger version

Name:	dB Meta blocked by MBAM CDGrab.exe.png
Views:	1
Size:	53.3 KB
ID:	293245 It's no big loss; if it was due to an image, I got by without it anyway by manually searching the internet for the album cover. There are regular scares about poisoned image files, the most recent one being "Locky Ransomware," malware that's spread via Facebook. I seem to recall such scares every couple of years. I remember a 2004 article in Wired about poisoned jpegs: https://www.wired.com/2004/09/malici...ides-in-jpegs/.

          Analyzing the IP, 207.241.227.173, at VirusTotal, gave an archived analysis record of 0/67. Reanalyzing added one more "no hit" but "suspicious." https://quttera.com/website-malware-scanner considers something suspicious, a file. However, looking at "more details," it gives--
          "Severity: Suspicious
          Reason: Detected suspicious redirection to external web resources at HTTP level. [What's this?]
          Details: Detected HTTP redirection to https://archive.org."
          I wouldn't worry about a redirection to the wayback machine.

          I found another site to check IPs, http://www.threatstop.com/checkip. It's actively trying to sell some kind of security product, since it won't give you a result without an email address, but I did it anyway. It also finds something "suspicious," something it calls "PhishTank"--which it assigns a "Danger Level" of 3 on a 0 to 5 scale. See Click image for larger version

Name:	dB Meta analysis threatstop.PNG
Views:	1
Size:	77.9 KB
ID:	293246.

          I don't think there's anything to worry about.

          Comment

          • GeorgeButel
            • Aug 2005
            • 42

            #6
            Re: Malwarebytes blocking cd ripper?

            Norton is getting frisky these days. Today, I decided to update the aac encoder, and Norton ate it. I submitted the file to Symantec as a false positive.Click image for larger version

Name:	Norton eats  aac encoder 2.PNG
Views:	1
Size:	42.6 KB
ID:	293247

            Comment

            Working...

            ]]>