cancel
Showing results for 
Search instead for 
Did you mean: 

"Risky Connection Blocked" message

    I've got the messages about risky connection blocked. IP Address blocked connection is 188.254.235.254 What should I do to solve this problem ? This message appeared few times and continue do this further.

6 Replies

Re: "Risky Connection Blocked" message

Both Trusted Source-McAfee, And Securi has this Ip Address "Blacklisted" and rated as "High Risk". It originates from Bulgaria. Meaning that Your protection is doing it,s job. Their are a few other Domains associated with it as well.

Hayton, and the other Moderators are more informed than I am. Just be self assured that you are being protected. Hope this helps somewhat.....

Have a Merry Christmas.....

Regards,

CatDaddy

Message was edited by: catdaddy on 12/23/13 5:00:23 PM CST
Cliff
McAfee Volunteer
Hayton
Level 18
Report Inappropriate Content
Message 3 of 7

Re: "Risky Connection Blocked" message

The IP address is reported to be a Zeus Command and Control server (Group 7). If your PC is trying to connect to it that's not good news; your PC is possibly infected with malware and may be part of one of the Zeus botnets. Depending on which botnet is involved your financial transactions may be at risk, or your login and password credentials may have been stolen.

http://urlquery.net/report.php?id=8522767

https://zeustracker.abuse.ch/monitor.php?search=188.254.235.254

Download the latest McAfee updates and run a full scan. If nothing is detected don't assume you're in the clear; run at least one other scan as a check - Malwarebytes or Microsoft's Safety Scanner, or one of your own choice.

If anything is detected and quarantined you must assume the worst, especially if you use the PC for financial transactions.

In any case you should change all your passwords as a precaution, since those are invariably targeted.

http://en.wikipedia.org/wiki/Zeus_(Trojan_horse)

http://malwaretips.com/blogs/zeus-trojan-virus/

Re: "Risky Connection Blocked" message

Thanks Hayton, I seen that the particular Host was sf.ddns.bulsat.com -with that Ip Address. I was wondering myself why the above mentioned PC was attempting to connect ? Therefore is when your vast knowledge of such came in.

Better get off here, Inundated with Family and such.

Merry Christmas....

Regards,

CatDaddy

Cliff
McAfee Volunteer

Re: "Risky Connection Blocked" message

McAfee Communities: Anti-Spyware/Malware & Hijacker Tools

use a couple of these free scanners or Microsoft saftey scanner as Hayton suggested above. Just adding this to assist you finding them.

Re: "Risky Connection Blocked" message

I got the same message for the IP address

IP 91.222.6.85 (attacker from Belgrad, Serbia)

Moderator
Moderator
Report Inappropriate Content
Message 7 of 7

Re: "Risky Connection Blocked" message

Hi

Were you on any specific website when you got this alert? McAfee blocks any risky or untrusted connection which is when you should have received this alert.

Security Report has the history of the number of connections that were blocked for the week, month and year. You can go to Security Report from the UI itself but the way to get to Security Report will vary according to the UI version you have.

Regards

Farhan