×
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
m_estock
Contributor
Message 1 of 2

Help with Risky Connection

I moved back to college about a week ago and some strange things have been going on since coming back. I wasn't able to connect to the internet reliably. A lot of the times I would get a message saying my connection had timed out. In addition, McAfee would often pop up with the message saying a risky connection had been blocked. The IP address for the block was 188.229.89.121 and next to Last Attempted By: it says Host Process for Windows Services.

So naturally, I did some research on where this IP address originated from. I found this article about it: http://research.zscaler.com/2011/08/dns-changes-from-w32rorpian.html . If you scroll down to the 'Original Post' section, those symptoms and events described are exactly what happened to me. I then plugged in my girlfriend's MAC notebook into the same ethernet port in my dorm room and the same events happened. The screen telling you to update your browser popped up, etc. This leads me to believe that my computer isn't infected with anything, especially since I have run many full, clean scans with McAfee.

I called my campus's tech department and told them about what was happening. I also told them about the risky connection and gave them the IP address that was blocked. Hopefully they will block this IP from coming through. I'm still paranoid about why this happened to me. Was it something I did or was it the campus network's fault for letting it through? Is there anything I can do to make sure my computer is clean? Thanks

1 Reply
esurname
Former Member
Message 2 of 2

Re: Help with Risky Connection

Hi there I am also getting risky connection blocked messages for last two days, I found a website that tells you where the ip address is registered.

So for the ip address above  188.229.89.121   goto www.ip-adress.com/whois/188.229.89.121 and scroll down the page it shows a map and in  your

case it says Pantelimon in Romania. The service is free.  The last two sites for me were some bloke in the Ukraine and the last one 91.226.78.129 says Russian Federation looks like in the middle of nowhere , scary stuff..Hope the above is of use to anyone reading this..  

Message was edited by: esurname ,site  had 1 d in the website word  'adress'. on 16/02/12 19:56:39 CST
How Many Badges Can You Collect?
Ready for a little competition? Members like you are earning badges and unlocking perks for their helpful answers. Are you? Click here to find out.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community