Topic: e6 is triggering Malwarebytes as Compromised

Posted under Site Bug Reports & Feature Requests

Today malwarebytes detects e6 as compromised. Been using Malwarebytes for years and this is first time im seeing this.

Malwarebytes
www.malwarebytes.com

-Log Details-
Protection Event Date: 8/28/22
Protection Event Time: 10:13 PM
Log File: df6fecfa-270d-11ed-9940-2cfda1bf247a.json

-Software Information-
Version: 4.4.11.149
Components Version: 1.0.1513
Update Package Version: 1.0.59329
License: Premium

-System Information-
OS: Windows 10 (Build 19043.1889)
CPU: x64
File System: NTFS
User: System

-Blocked Website Details-
Malicious Website: 1
, C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, Blocked, -1, -1, 0.0.0, ,

-Website Data-
Category: Compromised
Domain: static1.e621.net
IP Address: 148.163.96.42
Port: 443
Type: Outbound
File: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe

We're aware of this problem and are working with the relevant parties to get it resolved. This is a false positive.

lonelylupine said:
It appears that your problem is that you're using Edge as your browser.

its triggering on all the browsers i have. Chrome, Firefox and also Edge.

kiranoot said:
We're aware of this problem and are working with the relevant parties to get it resolved. This is a false positive.

Thank you for the update!

redishdragie said:
Today malwarebytes detects e6 as compromised. Been using Malwarebytes for years and this is first time im seeing this.

<snip>

I'll second this, Malwarebytes is giving me the same error and preventing most functionality of the website (E.G. not showing images.)

Edit: that's what I get for typing slow lol, glad it's already being worked on.

Would it be safe to white list for the time being? Not a permanent thing, of course. Just until the all OK signal is given...

Updated

foxczer said:
Would it be safe to white list for the time being? Not a permanent thing, of course. Just until the all OK signal is given...

Kira said it's a false positive, so it would be safe to whitelist, since nothing has actually been compromised.

lonelylupine said:
It appears that your problem is that you're using Edge as your browser.

Good to see the 1st reply to the issue topic is unhelpful shitposting, especially considering it's not a browser issue in the first place.

kiranoot said:
We're aware of this problem and are working with the relevant parties to get it resolved. This is a false positive.

Can anybody estimate when this will be fixed? e261 is still compromised and even though I've listed the site as 'safe' on MalwareBytes, it's still not showing any new images.

Same here. Yesterday I was on the site in the morning, when I came back in the afternoon MWB was blocking the site. I have it whitelisted and the site is functioning normally. I'm assuming things are okay as i'm sure we would have heard something serious going on by now.

kallinx said:
Same here. Yesterday I was on the site in the morning, when I came back in the afternoon MWB was blocking the site. I have it whitelisted and the site is functioning normally. I'm assuming things are okay as i'm sure we would have heard something serious going on by now.

How do you completely whitelist a site? It doesn't seem to be working when I put this on the acceptable sites section in my Malwarebytes. Do I need to shut down my computer after that before it functions?

Can also confirm the MalwareBytes issue. I'll try to whitelist the site for the time being.

predaking2000 said:
How do you completely whitelist a site? It doesn't seem to be working when I put this on the acceptable sites section in my Malwarebytes. Do I need to shut down my computer after that before it functions?

You may have to restart the browser to get it to update, you don't have to restart the entire PC.

dripen_arn said:
false positives notwithstanding: should i get malwarebytes?

The free version of malwarebytes is a great tool to have installed and run occasionally to catch a few things that Window's Defender may have missed, but the premium version is not needed if you don't know you need what it offers. Window's Defender is currently one of the best solutions on the market for all your firewall, anti-virus, and malware protection, and thus upgrading to MalwareBytes Premium doesn't give you too much of a benefit for the price they ask of you.

notmenotyou said:
You may have to restart the browser to get it to update, you don't have to restart the entire PC.

The free version of malwarebytes is a great tool to have installed and run occasionally to catch a few things that Window's Defender may have missed, but the premium version is not needed if you don't know you need what it offers. Window's Defender is currently one of the best solutions on the market for all your firewall, anti-virus, and malware protection, and thus upgrading to MalwareBytes Premium doesn't give you too much of a benefit for the price they ask of you.

"We make a great bargain! Price for a month that you used to pay for a full license." Wasn't it something like that? :P

notmenotyou said:
You may have to restart the browser to get it to update, you don't have to restart the entire PC.

The free version of malwarebytes is a great tool to have installed and run occasionally to catch a few things that Window's Defender may have missed, but the premium version is not needed if you don't know you need what it offers. Window's Defender is currently one of the best solutions on the market for all your firewall, anti-virus, and malware protection, and thus upgrading to MalwareBytes Premium doesn't give you too much of a benefit for the price they ask of you.

I deactivated my account and everything is back to normal. But I'm worried. Doesn't this leave me at greater risk of viruses? Or does the free version of Malwarebytes work just as good?

predaking2000 said:
I deactivated my account and everything is back to normal. But I'm worried. Doesn't this leave me at greater risk of viruses? Or does the free version of Malwarebytes work just as good?

The best virus protection you can have is to simply don't click on sus links, websites or programs.

That said, prevention is better than the cure. Try running an adblocker, and if you feel a site is worth using, you can whitelist its ads.
Librewolf, Brave, and the uBlock Origin extension are very good. Using uBlock you can even disable javascript and whitelist it on sites you trust.

predaking2000 said:
How do you completely whitelist a site? It doesn't seem to be working when I put this on the acceptable sites section in my Malwarebytes. Do I need to shut down my computer after that before it functions?

For e621, the URL you want to whitelist is "static1.e621.net". That's what worked for me.

If that still doesn't work, bring up the browser's developer tools for the page. In firefox, it's as easy as Right Click > Inspect.
Then, in the developer tools, switch to the "Network" tab.
Then refresh the original page with the dev tools still open.
After refreshing the page, the network tab, it should show you exactly which requests failed, which are likely the ones you need to whitelist.

  • 1