New
#1
TCPView shows multiple [System Process] network connections...
Hi all,
TCPView is showing multiple network connections listed as [System Process].
These are usually connected to unrecognized IPs and certainly not IPs I would want the system to automatically connect to without request or authorization on the part of the user.
Does this indicate malware? This isn't the usual block of Akamai servers that Windows Update uses to download updates.
I've tried an AV scan but it shows no results.
I've tried blocking these IPs with a firewall but plenty more IPs from entirely different domains keep appearing under [System Process].
How are they establishing connections, how can I identify these unknown processes and how can I completely prevent this activity without using a firewall that requires manual authorization for EVERY connection (this computer's user couldn't handle that level of complexity).
The OS is Windows 10.
Much appreciated.