I have a domain lockout issue and in troubleshooting, I found through netstat that my machine is pummeling the domain controllers on ports 445 and 139. It is creating thousands of user ports to do this: today it started at port 54000ish and within a couple of hours was up to 60000.
netstat -ob identifies the process as PID 4.
In my research so far, I keep hearing that a virus is the likely cause. I have trend micro and windows defender running--A full scan by windows defender identified nothing amiss.
Are there any other causes besides a virus that I could look into?
I was able to stop it by blocking the outbound ports in windows firewall, but obviously this is not ideal.
Anything I can do short of reinstalling the OS?