Weird connection showing up in TCPView

Page 1 of 2 12 LastLast

  1. Posts : 5
    Win 10 Pro, v21H1 (OS Build 19043.1021)
       #1

    Weird connection showing up in TCPView


    Hello,

    Lately I've been seeing some weird remote address -1-1ads.com - show up whenever I check connections in TCPView.

    Here's a pic
    Weird connection showing up in TCPView-tcpview.png

    I've tried the following - uninstalling and reinstalling the affected software, starting Firefox in safe mode, refreshing it, manually disabling extensions and re-enabling them, followed this guide, scanned with Malwarebytes, ADWCleaner, Hitman Pro... nothing came up.

    I also have the - 1-1ads.com - blocked in windows's hosts file but it still seems to show up.

    As a note - whenever firefox/apple services are closed/not running, the address doesn't show up in TCPView.

    Win 10, v21H1 (OS Build 19043.1021)

    I'm out of ideas here and seek your wisdom.
      My Computer


  2. Posts : 8,103
    windows 10
       #2
      My Computer


  3. Posts : 5
    Win 10 Pro, v21H1 (OS Build 19043.1021)
    Thread Starter
       #3


    This seems to have solved part of it.
    The address doesn't show up for the rest of Apple services anymore, but it's still there for Firefox (cleared cache and cookies one more time after removing Bonjour)

    Any ideas on that? Thanks for the help so far <3
    Weird connection showing up in TCPView-tcpview64_pjljf1z4j5.png
      My Computer


  4. Posts : 8,103
    windows 10
       #4

    Look for any extension in ff you can run ff in its own safe mode(not windows safe mode) try running like that see if it stops
      My Computer


  5. Posts : 5
    Win 10 Pro, v21H1 (OS Build 19043.1021)
    Thread Starter
       #5

    Unfortunately the issue persists.

    I've tried even with another browser and the connection seems to persist.
    I'm really curious if this address is something legit that may be tied to Apple when installing iTunes/iCloud and hooks unto everything else it can and phones home (for user experience improvement of course ) or if there's something malicious somewhere in the middle.

    Thanks again for all the help so far, if there's any other ideas that I can try (besides a clean Windows reinstall) I'm open to suggestions.
      My Computer


  6. Posts : 8,103
    windows 10
       #6

    Contact is made via malware the actual web domain is a place were you can rent a server https://otx.alienvault.com/indicator...4c94c98f499500.

    Try adaware and malwarebytes again but have the webrowser running when you scan if its only active with a browser it may not have picked it up if the browsers isnt running before running check its connecting
      My Computer


  7. Posts : 5
    Win 10 Pro, v21H1 (OS Build 19043.1021)
    Thread Starter
       #7

    Still no luck

    Neither Malwarebytes, ADWCleaner nor Hitman Pro have detected anything.
    At this point I think I'll just have to ignore it :/
    As much as I dislike this issue and it's an itch on the back of the head, I'm out of ideas.
      My Computer


  8. Posts : 8,103
    windows 10
       #8

    Make sure its connecting then open taskmanager click detals at the top now look for the PID numbers the tcip is using and it will tell you what apps using it
      My Computer


  9. Posts : 2,800
    Windows 7 Pro
       #9

    If your Firefox is not using the hosts file, it may be because it is configured to use DNS over HTTPS

    I just did the test and was unable to block the site via Hosts file while Firefox is using DNS over HTTPS.

    As soon as I disabled it, the site became unreachable.
      My Computers


  10. Posts : 5
    Win 10 Pro, v21H1 (OS Build 19043.1021)
    Thread Starter
       #10

    Sorry for the lack of updates everyone, it's been a long night struggling with this.
    In the end I bit the bullet and reinstalled Windows and everything is fine now.

    @MaloK - I didn't have FF set up to use DNS over HTTPS so I guess it was something else. @Samuria - thanks once again for all the help offered.

    Dunno what it was but I'll keep an eye on things in case it returns (hope it doesn't tho D:)

    Thanks everyone!
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 16:33.
Find Us




Windows 10 Forums