Hi, I am using process explorer.
There is a particular program named winnit.exe, which has a local and remote address listed for TCP/TCPV6. They are both assigned to a desktop which I cannot recognize.
Is this the result of a remote access?
I understand that winnit.exe is a Windows program, but unlike virtually every single other Windows process, it doesn't have its company name (Microsoft Corporation) listed, and instead has no company name listed.
Almost no process has a TCP/IP listed; and the few i've found lurking that do have it; also don't have their Company Name listed. Trying to end the tree processes for winnit.exe resulted in a flurry of access denies, i'm also denied access from seeing the user in winnit.exe.