logo elektroda
logo elektroda
X
logo elektroda

[Solved] What is Allow 9009 on Firewall? Virus or Port Issue? Win10 Pro, TCP Port 9009, Pichat Service

moher40 25359 5
ADVERTISEMENT
Treść została przetłumaczona polish » english Zobacz oryginalną wersję tematu
  • #1 17005187
    moher40
    Level 3  
    I have exactly the same problem:
    https://www.bleepingcomputer.com/forums/t/642063/keep-seeing-something-hosted-on-port-9009/

    and followed the instructions therein. It didn't do anything.

    Commonly in the firewall I have an attempt to output something called ALLOW and it connects only to TCP port 9009. I have no clue what it is. Win10 Pro (ori) system and zero installed goodies.

    What is Allow 9009 on Firewall? Virus or Port Issue? Win10 Pro, TCP Port 9009, Pichat Service

    I got in here:
    http://www.ipfingerprints.com/portscan.php
    and I have this result:

    Note: Host seems down. If it is really up, but blocking our ping probes, try "Don't Ping" in advance mode.
    Host is up!
    PORT STATE SERVICE
    9009/tcp filtered pichat
    9009/udp open|filtered pichat

    TCPview only shows this:
    What is Allow 9009 on Firewall? Virus or Port Issue? Win10 Pro, TCP Port 9009, Pichat Service
  • ADVERTISEMENT
  • #2 17005235
    dt1
    Admin of Computers group
    Hello. Run the command line as administrator and enter the command:
    netstat -n -a -b

    It should display all listening processes and connections established at the moment. See if you can identify a process that is listening on port 9009.

    Do a FRST scan: https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/ - don't change any parameters. Upload both generated logs (FRST and Addition text files) as attachments.
  • ADVERTISEMENT
  • ADVERTISEMENT
  • #4 17006440
    dt1
    Admin of Computers group
    I guess a bunch of (from my perspective) redundant LED control software might be using port 9009 for communication. RGB Fusion has a smartphone app that communicates over this port, so I wouldn't be surprised if the software took care to keep it open.
  • ADVERTISEMENT
  • #5 17006976
    moher40
    Level 3  
    I put a clean system straight from M$. Te Allow is from Microsoft. I put a clean W10, depriving it only of telemetry, defender, antimalware and a few other reptiles. I put in a firewall and it still pops up connecting to port 9009.
    So I blocked this port in the firewall in UDP and TCP and we'll see what it does.

    What is Allow 9009 on Firewall? Virus or Port Issue? Win10 Pro, TCP Port 9009, Pichat Service
  • #6 17012699
    moher40
    Level 3  
    It turned out to be a service related to the so-called. GCloud is some garbage from Gigabyte packed in APP-Center. I got rid of it and nothing similar to Allow 9009 speaks anymore. It's ok.
ADVERTISEMENT