Fix it now
0x80072746 is Winsock error 10054, WSAECONNRESET: an existing connection was forcibly closed by the remote host. Inside your own network the remote host is rarely the culprit – something on one of the two machines is tearing down a session that was already established. A reset, a refusal and a timeout have three different fixes, so establish which you have before changing any policy.
Test-NetConnection SERVERNAME -Port 445
Get-NetConnectionProfile
netsh advfirewall set allprofiles logging droppedconnections enable
- Note the port that fails. SMB is TCP 445, Remote Desktop is TCP 3389, and print and management traffic use RPC on TCP 135 plus a dynamic high port you can read with
netsh int ipv4 show dynamicport tcp. - If
Test-NetConnectionsucceeds and the application still resets mid-transfer, the path is open and something is closing an established session. That rules out a blocked port and rules in a filter. - Pause the endpoint product’s network or firewall module on the client, retry the operation, then re-enable it immediately. If it works while paused, you have your answer without having changed anything permanently.
- Write the exclusion into the management console – the affected ports and server addresses on the trusted or excluded list – rather than leaving protection off. Push the policy, confirm the client received it, and retest with protection fully enabled.
Read %windir%\system32\logfiles\firewall\pfirewall.log after enabling logging. If Windows Firewall is dropping the traffic, it will be in there, and you can stop investigating the security suite.
If the operation completes with protection fully on, you are done. If pausing protection changed nothing, the next section explains which layer you are actually in.
Why it happens
These five codes mark distinct moments in a TCP conversation, and knowing which one you have removes most of the guesswork. A reset – 0x80072746, WSAECONNRESET – means the connection existed and was torn down. Microsoft’s description is precise: the connection was forcibly closed by the remote host, typically because the peer application stopped, the host was rebooted, the interface was disabled, or the remote end used a hard close. A refusal – 0x8007274D, WSAECONNREFUSED – means nothing was listening when the first packet arrived. A timeout – 0x8007274C, WSAETIMEDOUT – means packets went out and nothing came back, which is the signature of a silent drop rather than an active rejection.
Endpoint protection sits in this path twice. It binds a filter to the adapter, so it sees frames before the TCP stack does, and it registers filters in the Windows Filtering Platform, so it can act on flows that are already established. An inspection module that does not recognise a particular SMB dialect or an RPC callback will often abort the flow rather than pass it, and aborting an established connection is exactly what produces a reset at the application.
That is also why the fault looks intermittent and unfair. Large file copies fail while small ones succeed, because the reset arrives when an inspection buffer fills. Remote Desktop drops after several minutes rather than refusing to connect, because the session is reset rather than blocked. And the fifth code is the one people misread: 0x80072745 is WSAECONNABORTED, which Microsoft describes as an established connection aborted by the software in your host computer. If you are seeing the abort rather than the reset, stop investigating the server – the software doing it is on the machine in front of you.
The endpoint firewall module is dropping internal traffic
You have this one if The failure clears the moment protection is paused, and the agent’s own log records a blocked or reset connection at the same timestamp.
- Open the management console and find the policy applied to the affected machines.
- In the firewall or network protection section, add the internal subnets and the file, print and Remote Desktop servers as trusted addresses.
- Add the specific ports the application uses instead of disabling the module.
- Push the policy, confirm the client has the new version, then retest with protection fully enabled.
Set exclusions in the console, not on the individual machine. A local exception is lost at the next policy sync and you will be back here inside a week.
Protocol inspection is aborting SMB or RPC flows
You have this one if Pausing network protection or protocol filtering fixes it, while pausing file scanning alone does not.
- Exclude the server addresses from protocol and network attack inspection specifically, rather than from on-access scanning.
- Where the product separates scanning from intrusion detection, relax detection for the internal subnet first; it is usually the detection engine that resets sessions.
- Retest with a large file copy rather than a small one, because buffer-driven resets only appear at size.
- If the product offers a compatibility or passive mode for SMB, enable it for the affected group.
Windows Firewall rather than the security suite
You have this one if The traffic fails identically with the third-party product paused, and the firewall log records dropped packets at the same moment.
- Check which profile the adapter is in:
Get-NetConnectionProfile. A domain machine that has landed in the Public profile will block file and print sharing. - Find the rules covering the port:
Get-NetFirewallPortFilter | Where-Object LocalPort -eq 445 | Get-NetFirewallRule. - Enable the built-in File and Printer Sharing and Remote Desktop rule groups for the correct profile.
- Retest with
Test-NetConnection SERVERNAME -Port 445.
A stale network binding from a product that has gone
You have this one if Pausing protection changes nothing, and the machine has previously carried a different security product or VPN client.
- List what is bound to the adapter:
Get-NetAdapterBinding -Name * | Sort-Object Name,DisplayName. - Disable or remove components belonging to software that is no longer installed, using the original vendor’s removal tool where one exists.
- Remove leftover virtual adapters in Device Manager with View, Show hidden devices.
- Reboot and retest.
fltmc filters is often suggested here and answers a different question: it lists file system minifilters, not network bindings. Get-NetAdapterBinding is the one that shows what sits in the network path.
The service really did close the connection
You have this one if The same failure occurs from a machine with no endpoint protection at all, and the server’s own logs record the disconnect.
- On the server, check the System and Application logs at the moment of the reset for service restarts or resource exhaustion.
- For SMB, review
Get-SmbServerConfigurationand the SMB server operational log; for Remote Desktop, check session limits and idle timeout policy. - Rule out a duplicate IP address on the segment, which produces resets that look exactly like filtering.
Full reference
Matching the code to the moment
| Code | Winsock | Constant | What Microsoft says |
|---|---|---|---|
0x80072746 |
10054 | WSAECONNRESET | An existing connection was forcibly closed by the remote host |
0x8007274C |
10060 | WSAETIMEDOUT | The connected party did not properly respond after a period of time, or an established connection failed because the host failed to respond |
0x8007274D |
10061 | WSAECONNREFUSED | No connection could be made because the target computer actively refused it |
0x80072745 |
10053 | WSAECONNABORTED | An established connection was aborted by the software in your host computer |
0x80072751 |
10065 | WSAEHOSTUNREACH | No route to host: a socket operation was attempted to an unreachable host |
Seeing the drop instead of inferring it
Guessing which layer dropped a session wastes more time on this error than anything else, and Windows will tell you if you ask. Two mechanisms are documented and neither needs a third-party tool.
- Turn the firewall’s own log on with
netsh advfirewall set allprofiles logging droppedconnections enableand read%windir%\system32\logfiles\firewall\pfirewall.log. Anything Windows Firewall drops appears there with the source, destination and port. - Enable the Audit Filtering Platform Connection subcategory and read the Security log. Event 5157 is logged when the Windows Filtering Platform has blocked a connection, and it names the process, the addresses and the ports.
- Reproduce the failure while both are on, then compare timestamps against the endpoint agent’s own log. If neither Windows mechanism recorded anything and the agent did, the agent is the one closing the session.
Which ports the affected protocols actually use
| Traffic | Ports |
|---|---|
| SMB file sharing | TCP 445 |
| Remote Desktop | TCP 3389 |
| RPC endpoint mapper | TCP 135 |
| RPC application traffic, including spooler and management | A port from the machine’s dynamic range; read it with netsh int ipv4 show dynamicport tcp rather than assuming |
That last row matters when someone opens 135 and expects printing to work. The endpoint mapper hands the client a second port from the dynamic range, and a firewall that permits 135 while blocking the range produces a connection that establishes and then dies – which is this error exactly. Read the range on the servers involved and allow it between trusted internal subnets, or configure the services concerned to use a fixed port.
When pausing protection changes nothing
- Test from a third machine with no endpoint product installed at all. If it fails there too, the fault is on the server or in the network and no exclusion will help.
- Check for a duplicate IP address on the segment. Two devices answering for one address produce resets that look precisely like inspection.
- Check for an intermediate device doing inspection – a firewall, a proxy, an SD-WAN appliance. Endpoint software is not the only thing that terminates and rebuilds sessions.
- Check MTU and offload settings where the resets cluster around large transfers. A path MTU problem produces size-dependent failures that resemble buffer-driven resets.
- On a virtual machine, check the host’s virtual switch and any security extensions bound to it.
When a licence is the actual fix
Turning protection off is free and takes a second, and it is a diagnostic rather than a fix. The recurring cost here is exclusions that drift because every machine is configured by hand, which is a management problem rather than a security one. ESET Endpoint Security includes both a firewall and Network Attack Protection, which analyses network traffic content and blocks what it considers harmful – and ESET documents the ESET PROTECT Web Console as the place you deploy solutions, manage tasks and enforce security policies across remote computers, so an SMB or Remote Desktop exemption is defined once and applied everywhere. ESET PROTECT Entry is the tier Arco supplies for this; we will confirm which components your estate actually needs and size the seat count with you rather than selling you a tier you will not use.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x80072746 |
Winsock 10054, WSAECONNRESET: an existing connection was forcibly closed by the remote host | Microsoft Learn |
0x8007274C |
Winsock 10060, WSAETIMEDOUT: the other end did not respond in time, either during the attempt or on an established connection | Microsoft Learn |
0x8007274D |
Winsock 10061, WSAECONNREFUSED: the target computer actively refused the connection, which usually means nothing was listening | Microsoft Learn |
0x80072745 |
Winsock 10053, WSAECONNABORTED: an established connection was aborted by software on this machine, not by the far end | Microsoft Learn |
0x80072751 |
Winsock 10065, WSAEHOSTUNREACH: no route to host, so the socket operation was attempted to an unreachable host | Microsoft Learn |
Confirm the fix worked
- Repeat the operation that failed with endpoint protection fully enabled, and confirm it completes.
- Copy a large file rather than a small one, since buffer-driven resets only show up at size.
- Leave a Remote Desktop session open for longer than the interval at which it previously dropped.
- Check the firewall log and the Security log for the same window and confirm no new dropped-connection or 5157 entries were written.
- Confirm the exclusion is in the management policy rather than on the machine, then check a second client has received it.
Questions people ask about this
Should I just uninstall the antivirus?
No. Pausing it proves where the fault is; leaving it off swaps a connectivity problem for a security one. Use the pause as a diagnostic, write the exclusion into the policy, and re-enable protection.
Which ports do file and print sharing need?
TCP 445 for SMB, TCP 3389 for Remote Desktop, and TCP 135 plus a port from the machine’s dynamic RPC range for spooler and management traffic. Read the range with netsh int ipv4 show dynamicport tcp rather than assuming a figure, and allow it between trusted internal subnets only.
Is 0x80072745 different from 0x80072746?
Yes, usefully so. 10054 is a reset from the remote host; 10053 is an abort caused by software on the machine you are sitting at. If you see the abort, the thing to examine is local.
Why does a small file copy work and a large one fail?
Because the two are handled differently by anything inspecting the stream. Small transfers finish before an inspection buffer fills; large ones do not. Always test with a large file, or you will conclude you have fixed something you have not.
Do I have to pay for central management?
Yes, in every major endpoint product – but not for the fix. Setting the exclusion locally on each machine, or using Windows Defender Firewall rules, costs nothing and works. What you buy is not having to do it machine by machine.
