Windows 10: I ran netstat -ano and have an established connection to pid 4 ntos kernel... is this normal?

Discus and support I ran netstat -ano and have an established connection to pid 4 ntos kernel... is this normal? in AntiVirus, Firewalls and System Security to solve the problem; Hello, To reiterate, I run windows ten, lately I have been noticing my email and other apps getting hacked, so i decided to run some diagnostics on my... Discussion in 'AntiVirus, Firewalls and System Security' started by uziXwraith, Oct 12, 2020.

  1. I ran netstat -ano and have an established connection to pid 4 ntos kernel... is this normal?


    Hello, To reiterate, I run windows ten, lately I have been noticing my email and other apps getting hacked, so i decided to run some diagnostics on my PC. I ran the antivirus, downloaded AVG ran that too, was all good. I then went advanced, and opened an admin CMD, and checked sfc /scannow, was fine, then i ran netstat.ano, and found that PID 4 was ESTABLISHED at some point and had a very strange IP address, TCP LOCAL [ : : 1] :10801 FOREIGN [ : : 1] :4976 Searched online and it says those are TCP UDP ports that are unassigned??? I looked up task manager details, pid 4 was labeled system, I searched online from the right click option, and NTOSKRNL came up... & thats when i panic'd... is this maybe someone remote viewing my system? Searching online gave no results, so here i am asking you! If there is a problem how do i block them reestablishing on pid 4? should i run DISM and reinstall everything? Am doing regardless, but insight is helpful.

    thanks

    :)
     
    uziXwraith, Oct 12, 2020
    #1

  2. unwanted open, established connections.

    Why does windows 10 have over ten established connects and how do I stop them. Blocking the IP's in the firewall is not effective, why is that. From a command line enter 'netstat -ano'. Or should I get an external firewall nd block them there?

    Looking at the IP's, they all go to various Microsoft servers. Why and what are they collecting?
     
    DonTaylorOceanCity, Oct 12, 2020
    #2
  3. bbgodfrey Win User
    netstat -a reports many Established connections; is that bad?

    When running netstat -a, I see many "established" connections to high address ports on my computer (for example 49924). Should I be concerned? If so, what action should I take? I have McAfee on my computer and use a Netgear R7000 router. Thanks.
     
    bbgodfrey, Oct 12, 2020
    #3
  4. Ugo Lopez Win User

    I ran netstat -ano and have an established connection to pid 4 ntos kernel... is this normal?

    netstat results

    Ciao, Can you please run the following and share the outcome? netstat -ano Ciao and thanks Ugo
     
    Ugo Lopez, Oct 12, 2020
    #4
Thema:

I ran netstat -ano and have an established connection to pid 4 ntos kernel... is this normal?

Loading...
  1. I ran netstat -ano and have an established connection to pid 4 ntos kernel... is this normal? - Similar Threads - ran netstat ano

  2. Is this normal in Netstat -b?

    in Windows 10 Gaming
    Is this normal in Netstat -b?: Active Connections Proto Local Address Foreign Address State TCP 127.0.0.1:49678 Doghousecomp:49679 ESTABLISHED [WUDFHost.exe] TCP 127.0.0.1:49679 Doghousecomp:49678 ESTABLISHED [WUDFHost...
  3. Is this normal in Netstat -b?

    in Windows 10 Software and Apps
    Is this normal in Netstat -b?: Active Connections Proto Local Address Foreign Address State TCP 127.0.0.1:49678 Doghousecomp:49679 ESTABLISHED [WUDFHost.exe] TCP 127.0.0.1:49679 Doghousecomp:49678 ESTABLISHED [WUDFHost...
  4. Netstat connections

    in AntiVirus, Firewalls and System Security
    Netstat connections: Hello I was playing with my cmd and I noticed several netstat connections labelled as "Bad6" does anyone know what this may be? Also if this is malicious could someone please tell me how to terminate the connection. Thank you for any and all answers!...
  5. netstat is this normal?

    in Windows 10 Network and Sharing
    netstat is this normal?: Proto Local Address Foreign Address State TCP 127.0.0.1:51339 MSI:61870 ESTABLISHED TCP 127.0.0.1:54161 MSI:54162 ESTABLISHED TCP 127.0.0.1:54162 MSI:54161 ESTABLISHED TCP 127.0.0.1:54166 MSI:54167 ESTABLISHED TCP 127.0.0.1:54167 MSI:54166 ESTABLISHED TCP 127.0.0.1:54200...
  6. Established PID in CMD but not found in Task Manager

    in Windows 10 BSOD Crashes and Debugging
    Established PID in CMD but not found in Task Manager: Skimming through Established connections trying to eliminate unnecessary processes and I came across 2 Established PID's 8754 &3600 that are not found in the Task Manager or in the Process Explorer. I'm not sure what this would mean and I'm unsure what the connection even is...
  7. Netstat not showing pids

    in Windows 10 Network and Sharing
    Netstat not showing pids: When using 'netstat -b' command; pids are not shown. How do I fix this? The only things that are listed are; protocol, local address, foreign address and state, but again no pid. Example: [ATTACH]...
  8. Netstat connections, is this normal?

    in Windows 10 Network and Sharing
    Netstat connections, is this normal?: Just wondering if this is normal when I type netstat in cmd.... Proto Local Address Foreign Address State TCP 127.0.0.1:49790 DESKTOP-GOVM7NU:wsd TIME_WAIT TCP 192.168.1.151:49787 a-0001:https ESTABLISHED TCP...
  9. netstat -a reports many Established connections; is that bad?

    in AntiVirus, Firewalls and System Security
    netstat -a reports many Established connections; is that bad?: When running netstat -a, I see many "established" connections to high address ports on my computer for example 49924. Should I be concerned? If so, what action should I take? I have McAfee on my computer and use a Netgear R7000 router. Thanks....
  10. Netstat -an showing lots of listening + established, why?

    in Windows 10 Network and Sharing
    Netstat -an showing lots of listening + established, why?: my friend was showing me how to do something on my computer and went on CMD, netstat -an .. it showed a lot of conections some where at TIME WAIT, most split between LISTENING and ESTABLISHED there are 74 i counted, is this something or nothing, tried to look it up online but...