Troubleshoot What's the program trying to connect to Taiwanese & other foreign computers on my system?

conceptualclarity

Level 21
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 23, 2013
1,072
CurrPort and TCPView were interesting but did not resolve my issue. CurrPort created an HTML file I would like to be able to post here, but it's a long horizontal file that I don't believe I can properly convert.

Here is the weirdest and by far the most specifically identified site that something on my computer has tried to contact lately:
xw7LAv.png


This is comical! @:p

Free Product Demo | IP2Location
IP Address 50.198.35.237
Location
us.png
United States, Illinois, Yorkville
Latitude & Longitude 41.620980, -88.431720 (41°37'16"N 88°25'54"W)
ISP Rosati's Pizza
Local Time
06 Jan, 2017 09:43 PM (UTC -06:00)
Domain comcastbusiness.net
Net Speed (COMP) Company/T1
IDD & Area Code (1) 630/815
ZIP Code 60560
Weather Station Yorkville (USIL1300)
Mobile Country Code (MCC) -
Mobile Network Code (MNC) -
Carrier Name -
Elevation 183m
Usage Type (COM) Commercial
Anonymous Proxy No
Shortcut http://www.ip2location.com/50.198.35.237
Twitterbot @ip2location 50.198.35.237
Slackbot /ip2location 50.198.35.237

http://whois.domaintools.com/50.198.35.237
IP Location
us.gif
United States Yorkville Rosati's Pizza
ASN
us.gif
AS7922 COMCAST-7922 - Comcast Cable Communications, LLC, US (registered Feb 14, 1997)
Resolve Host 50-198-35-237-static.hfc.comcastbusiness.net
Whois Server whois.arin.net
IP Address 50.198.35.237
NetRange: 50.198.0.0 - 50.198.63.255
CIDR: 50.198.0.0/18
NetName: CBC-ILLINOIS-14
NetHandle: NET-50-198-0-0-1
Parent: CCCH3-4 (NET-50-128-0-0-1)
NetType: Reallocated
OriginAS:
Organization: Comcast Cable Communications Holdings, Inc (CCCH-3)
RegDate: 2013-01-04
Updated: 2013-01-04
Ref: Whois-RWS

OrgName: Comcast Cable Communications Holdings, Inc
OrgId: CCCH-3
Address: 1800 Bishops Gate Blvd
City: Mt Laurel
StateProv: NJ
PostalCode: 08054
Country: US
RegDate: 2003-07-28
Updated: 2016-09-06
Ref: Whois-RWS

OrgTechHandle: IC161-ARIN
OrgTechName: Comcast Cable Communications Inc
OrgTechPhone: +1-856-317-7200
OrgTechEmail:
OrgTechRef: Whois-RWS

OrgAbuseHandle: NAPO-ARIN
OrgAbuseName: Network Abuse and Policy Observance
OrgAbusePhone: +1-888-565-4329
OrgAbuseEmail:
OrgAbuseRef: Whois-RWS

NetRange: 50.198.35.232 - 50.198.35.239
CIDR: 50.198.35.232/29
NetName: ROSATISPIZZA
NetHandle: NET-50-198-35-232-1
Parent: CBC-ILLINOIS-14 (NET-50-198-0-0-1)
NetType: Reassigned
OriginAS:
Customer: ROSATI'S PIZZA (C03301715)
RegDate: 2013-02-03
Updated: 2013-12-07
Ref: Whois-RWS

CustName: ROSATI'S PIZZA
Address: 1 Unavailable Street
City: YORKVILLE
StateProv: IL
PostalCode: 60560
Country: US
RegDate: 2013-02-03
Updated: 2013-02-03
Ref: Whois-RWS

OrgTechHandle: IC161-ARIN
OrgTechName: Comcast Cable Communications Inc
OrgTechPhone: +1-856-317-7200
OrgTechEmail:
OrgTechRef: Whois-RWS

OrgAbuseHandle: NAPO-ARIN
OrgAbuseName: Network Abuse and Policy Observance
OrgAbusePhone: +1-888-565-4329
OrgAbuseEmail:
OrgAbuseRef: Whois-RWS

NetRange: 50.128.0.0 - 50.255.255.255
CIDR: 50.128.0.0/9
NetName: CCCH3-4
NetHandle: NET-50-128-0-0-1
Parent: NET50 (NET-50-0-0-0-0)
NetType: Direct Allocation
OriginAS: AS7922
Organization: Comcast Cable Communications, LLC (CCCS)
RegDate: 2010-10-21
Updated: 2016-08-31
Ref: Whois-RWS

OrgName: Comcast Cable Communications, LLC
OrgId: CCCS
Address: 1800 Bishops Gate Blvd
City: Mt Laurel
StateProv: NJ
PostalCode: 08054
Country: US
RegDate: 2001-09-18
Updated: 2008-10-04
Ref: Whois-RWS

Here are a couple of screenshots of TCPView on my system scrubbed for privacy.

TCPView1a.PNG


_TCPView 2.png



Can someone direct me to a better ports program than these two? And more specifically can someone help me figure out how I can find out which program is making all these connection attempts? It seems like surely there ought to be a way for me to pin that down.
 
  • Like
Reactions: AtlBo
5

509322

Thank you for bringing that to my attention. I subscribed to that thread, and I'll be interested to see if anything develops.

I am wanting to scan my system myself before getting involved with a malware assistance forum, but an ESET scan failed prior to finishing. Maybe I'll try Zemana AntiMalware next.

The notifications are not as intense now, but they're still coming on about an hourly basis, and now it's almost always hinet.net from Taiwan.

I suggest Emsisoft Emergency Kit and\or Hitman Pro.

EEK will remove any detected malware whereas HMP will not unless you activate the trial.

If those scanners don't detect anything, then it is unlikely you will find anything even if you scan your system with every single available scanner.
 
  • Like
Reactions: conceptualclarity
Upvote 0
5

509322

The longer you delay in getting a malware removal expert to inspect your system, the much greater the probability that whatever damage is possible is already done - if the cause of the suspicious system behavior is malware on your physical system.

Suspicious behavior began on your system almost a month ago.
 
Last edited by a moderator:
Upvote 0

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top