Close all browsers. Wait 5 minutes for all connections to time out.
Search for
cmd
Run As Administrator
Type:
netstat -bn
hit Enter
Should look something like:
Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!
Close all browsers. Wait 5 minutes for all connections to time out.
Search for
cmd
Run As Administrator
Type:
netstat -bn
hit Enter
Should look something like:
So I started to do what you said and immediately ran into some problems. (Also Google said It logged me out of my email cause it says it still thinks I have malware on my pc).
I ran the cmd prompt and got a BILLION lines that said:
TCP 127.0.0.1:60967 127.0.0.1:49350 TIME_WAIT
before I finally got one that said:
TCP 127.0.0.1:64182 127.0.0.1:27060 ESTABLISHED
When I ran it through whois it said:
NetRange: 127.0.0.0 - 127.255.255.255
CIDR: 127.0.0.0/8
NetName: SPECIAL-IPV4-LOOPBACK-IANA-RESERVED
NetHandle: NET-127-0-0-0-1
Parent: ()
NetType: IANA Special Use
OriginAS:
Organization: Internet Assigned Numbers Authority (IANA)
RegDate:
Updated: 2013-08-30
Comment: Addresses starting with "127." are used when one program needs to talk to
another program running on the same machine using the Internet
Comment: Protocol. 127.0.0.1 is the most commonly used address and is called the
"loopback" address.
Comment:
Comment: These addresses were assigned by the IETF, the organization that develops
Internet protocols, in the Standard document, RFC 1122, which can
Comment: be found here:
Comment: http://datatracker.i...org/doc/rfc1122
Ref: https://rdap.arin.ne...ry/ip/127.0.0.0
OrgName: Internet Assigned Numbers Authority
OrgId: IANA
Address: 12025 Waterfront Drive
Address: Suite 300
City: Los Angeles
StateProv: CA
PostalCode: 90292
Country: US
RegDate:
Updated: 2012-08-31
Ref: https://rdap.arin.ne...try/entity/IANA
OrgAbuseHandle: IANA-IP-ARIN
OrgAbuseName: ICANN
OrgAbusePhone: +1-310-301-5820
OrgAbuseEmail:
OrgAbuseRef: https://rdap.arin.ne...ty/IANA-IP-ARIN
OrgTechHandle: IANA-IP-ARIN
OrgTechName: ICANN
OrgTechPhone: +1-310-301-5820
OrgTechEmail:
I then started to go down the list and got about 4-5 more IPs in before whois said I cannot check any more without buying a subscription to the service. Should I copypaste the before and after netstat logs?
So I got this guy who I couldn't trace back (i switched to nordvpns ip lookup tool)
Can not obtain ownership information
34.117.122.6:443 ESTABLISHED
These also came up with nothing:
52.33.84.190
104.17.49.74
204.79.197.222
Edited by isolationary, 29 June 2022 - 03:33 PM.
Once a connection drops it sits in Time_Wait for a minute or so and then should be removed automatically. That's why I said to wait 5 minutes after you close your browser before doing this.
127.0.0.1 is a loopback port. Some process is using TCP/IP to connect to another local process. Did it say on the next line which process that was?
Sorry for the bad Whois link. Didn't realize it had a limit. As an alternative you can just put the IP address in a Google Search box and read a few of the hits.
34.117.122.6 Google Cloud
52.33.84.190 Amazon
104.17.49.74 Nord VPN or Cloudflare supposedly safe per VirusTotal but what process does it say on the next line?
204.79.197.222 Microsoft
Yeah I set a timer for five minutes and it still gave me those time_wait things so I ran it again today. I didn't see anything suspicious really. A lot of stuff when my browser opened but it was mostly google or amazon. I also got this:
151.101.193.21
This is from Fastly? I'm not sure what that is but a quick google search shows its some company I assume is associated with networking and not malicious But otherwise everything looks legit. I also uninstalled my firefox browser and then installed a new version and signed in and I don't seem to be getting Gmail malicious software warnings anymore when I try to sign in so I'm wondering if It didn't highjack the browser I was using. All of my firefox IP addresses seem to be legit now? I'm still a bit anxious about it but nobody's seemed to log into any of my stuff the last day or so and I've regained control of my duolingo account.
You are running netstat -BN (caps don't matter but it's easier to read). Right?
I seldom get very many time_waits so I wonder why. If you click on the Start button to get the menu of programs do you see a lot of Microsoft's little windows like News, Sports, Weather, Office. various games?
I've gone in and removed all of the little windows since I have no use for them and they just waste bandwidth and CPU cycles. (Just right click on them and there should be an option to remove them) Also if you see little pictures down in the Search Box these can be removed by right clicking then Search and uncheck Show Search Highlights. Also some of Microsoft's spyware may be active:
I did as you suggested and I'm still getting a ton of TIME_WAITs it says its from the esrv_svc.exe, svchost.exe and SearchApp.exe mostly.
When I run a netsat -bn after I open firefox it also (firefox.exe) has a large number of TIME_WAITs.
When I run the established IPs through NordVPN ip lookup they seem to be reputable.
esrv_svc.exe is part of
Intel® Driver & Support Assistant
which never worked well. I would uninstall it and see if that cuts down the number of time_waits.
Yeah that cleared up the TIME_WAITs significantly. (by pages worth). Now its a lot more manageable to navigate. Triple checked the IP addresses and everything looks legit. I also haven't had any of my passwords cracked or accounts logged into in the last couple days so I'm hoping we finally got it. Thanks so much for all your help and being thorough.
0 members, 1 guests, 0 anonymous users
Community Forum Software by IP.Board
Licensed to: Geeks to Go, Inc.