So I have been reading on the internet that it is possible that you can check if a hacker logged onto your computer by using netstat. So with this said and done, I found 3 establishments under 127.0.0.1:x, the x obviously standing for the port numbers. After looking at the PID in the taskmgr, I do recognize one of them being legit. However, the other 2 are the same PID and are under the image name "System". There is no CPU usage running and the memory usage is quite low, but is this legit for your local host to have established a connection? I ask this because I do recall back in sometime in 2005 or so, when I was infected the COOL WEB infection on my older system, the tech who was helping me at the time said that my local host file was hijacked, not saying that is what is happening here. I just want to knowe if this is legit?
BnTheMan
Topic Starter