Windows 10: Lots Of Connections on netstat / Wireshark

Discus and support Lots Of Connections on netstat / Wireshark in AntiVirus, Firewalls and System Security to solve the problem; So I haven't needed to netstat anything in a while and certainly never did on Win 10 but I don't remember so many active, established connections... Discussion in 'AntiVirus, Firewalls and System Security' started by gator, Sep 8, 2015.

  1. gator Win User

    Lots Of Connections on netstat / Wireshark


    So I haven't needed to netstat anything in a while and certainly never did on Win 10 but I don't remember so many active, established connections before.

    I have established connections with Twitter, Pandora, Google, Microsoft, Linode Networks, Akamai, CloudFlare and probably a few others I haven't looked up just yet. Now I don't necessarily think most of these are a problem. Linode, Akamia and CloudFlare are the most questionable but they could easily be backbone type stuff Comcast uses, I don't know.

    However, what makes me wonder is that the PID associated with these connections are connected to WebProxy.exe

    Furthermore, Wireshark is actively communicating with most of the names I mentioned above that showed up in Netstat, even when no browser is open. I previously disabled Microsofts supposed settings that allow them to track your online usage but could this be part of something I missed? Do I just not recall correctly that all of my traffic should be going through a WebProxy? Should I still be talking to Twitter even though I am not on that website nor do I have a browser open?

    I've noticed weird things and redirects every once in a while and I do a thorough cleanup which never produces much of anything (I am a tech who has cleaned up 100's of PC's, so it wasn't half azz).

    Any thoughts would be appreciated.

    :)
     
    gator, Sep 8, 2015
    #1

  2. Windows 10 - Delivery Optimization hogging bandwidth

    I just had the worst quality Skype call with my son in Australia I have ever had, and this was on a wired connection. Once we ended the call I noticed that the activity light on my Ethernet connection was still flickering like crazy. I fired up Wireshark
    and was quite disturbed to find my PC with several open connections to a server in Korea. C2 server I thought, and so checked the executable with netstat -aob - it was DoSvc. I used Process Explorer to find the svchost running it and killed the process.
    The flickering light stopped dead.

    Not your finest hour Microsoft. IMHO, you need to rethink the update strategy.
     
    Paul Offord, Sep 8, 2015
    #2
  3. Windows 10 home Remote Assistance Ports

    If you have all ports open and have successfully established a connection, try running netstat -na from the Command Line. You will need to know the IP addresses of the local and remote computer which then netstat shows the port connectivity source to
    destination.
     
    BobMullineaux, Sep 8, 2015
    #3
  4. Mystere Win User

    Lots Of Connections on netstat / Wireshark

    According to several sources, WebProxy.exe is part of the Panda Internet Security Suite... if you have this installed, then it redirects traffic through itself so it can watch for malicious activities. If you don't have this installed, it may be that you have a virus or malware.
     
    Mystere, Sep 8, 2015
    #4
  5. gator Win User
    I've put it on client PCs but have since went to a different anti-virus. Im not 100% sure if I put it on my personal PC but I'm leaning towards... probably.

    Should I have active communication with Twitter and other websites when my browser is closed?
     
    gator, Sep 8, 2015
    #5
  6. Mystere Win User
    Well, you will have to identify where those connections are coming from. You might want to disable the webproxy and check their source process id's. They might be "live tile" updates, or they might be other background services that you might have installed but forgotten about.
     
    Mystere, Apr 5, 2018
    #6
Thema:

Lots Of Connections on netstat / Wireshark

Loading...
  1. Lots Of Connections on netstat / Wireshark - Similar Threads - Lots Connections netstat

  2. Netstat scan

    in Windows 10 Gaming
    Netstat scan: Can someone please explain to me what a typical netstat scan should look like? Im worried someone is monitoring my network and my netstat scan seems to be extremely long and is always changingI would upload the netstat results but im not sure if that would compromise my...
  3. Netstat scan

    in Windows 10 Software and Apps
    Netstat scan: Can someone please explain to me what a typical netstat scan should look like? Im worried someone is monitoring my network and my netstat scan seems to be extremely long and is always changingI would upload the netstat results but im not sure if that would compromise my...
  4. Netstat

    in Windows 10 Gaming
    Netstat: Netstat is extremely confusing, it starts with the average small length of connection lines and then it expands into almost two sentences! It even has weird names for domains. It's extremely odd and all the "see if your computer is hack" barely explains how they find the...
  5. Netstat

    in Windows 10 Software and Apps
    Netstat: Netstat is extremely confusing, it starts with the average small length of connection lines and then it expands into almost two sentences! It even has weird names for domains. It's extremely odd and all the "see if your computer is hack" barely explains how they find the...
  6. Netstat connections

    in AntiVirus, Firewalls and System Security
    Netstat connections: Hello I was playing with my cmd and I noticed several netstat connections labelled as "Bad6" does anyone know what this may be? Also if this is malicious could someone please tell me how to terminate the connection. Thank you for any and all answers!...
  7. netstat is this normal?

    in Windows 10 Network and Sharing
    netstat is this normal?: Proto Local Address Foreign Address State TCP 127.0.0.1:51339 MSI:61870 ESTABLISHED TCP 127.0.0.1:54161 MSI:54162 ESTABLISHED TCP 127.0.0.1:54162 MSI:54161 ESTABLISHED TCP 127.0.0.1:54166 MSI:54167 ESTABLISHED TCP 127.0.0.1:54167 MSI:54166 ESTABLISHED TCP 127.0.0.1:54200...
  8. Netstat connections, is this normal?

    in Windows 10 Network and Sharing
    Netstat connections, is this normal?: Just wondering if this is normal when I type netstat in cmd.... Proto Local Address Foreign Address State TCP 127.0.0.1:49790 DESKTOP-GOVM7NU:wsd TIME_WAIT TCP 192.168.1.151:49787 a-0001:https ESTABLISHED TCP...
  9. netstat -a reports many Established connections; is that bad?

    in AntiVirus, Firewalls and System Security
    netstat -a reports many Established connections; is that bad?: When running netstat -a, I see many "established" connections to high address ports on my computer for example 49924. Should I be concerned? If so, what action should I take? I have McAfee on my computer and use a Netgear R7000 router. Thanks....
  10. Netstat -an showing lots of listening + established, why?

    in Windows 10 Network and Sharing
    Netstat -an showing lots of listening + established, why?: my friend was showing me how to do something on my computer and went on CMD, netstat -an .. it showed a lot of conections some where at TIME WAIT, most split between LISTENING and ESTABLISHED there are 74 i counted, is this something or nothing, tried to look it up online but...