Author Topic: repeated strange connection request to 198.105.244.228  (Read 2065 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
repeated strange connection request to 198.105.244.228
« on: September 25, 2016, 08:13:56 AM »
Every time I launch Google Chrome (latest version) on my Mac OS 10.11.6, com.avast.proxy requests the following connection: 

com.avast.proxy tried to establish a connection to avefeoamzfs on TCP port 80 (http).

The "avefeoamzfs" part is always different.  The IP Addresses are always: 198.105.244.228, 198.105.254.228 and that is is requested by process owner: system.

I always deny it, but it seems strange that it happens every time I launch Chrome. And that the name is different gibberish letters every time. Is there something on my computer or in Chrome that is causing this to happen?  Some internet searches have revealed confusing and conflicting answers.  One said that the IP is a known malware dns redirecting site and another said it was a third party company working for time warner cable.  If it is legit, why the phony name every time???  I am just leery of approving it, but would like to know what it is and why the name changes every time.  They have to know that makes it seem suspicious. 

http://www.dslreports.com/forum/r29736397-answers

the link suggests :( it is time warner related.

Any help would be appreciated. 

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: repeated strange connection request to 198.105.244.228
« Reply #1 on: September 25, 2016, 08:55:23 AM »
https://whois.arin.net/rest/nets;q=198.105.244.228?showDetails=true&showARIN=false&showNonArinTopLevelNet=false&ext=netref2

Seems to be a browser hijacker.
As I don't know about MAC's I can't help you, but a good start could be to remove Chrome and install it fresh again.