The TIME_WAIT connections will be closed early if the system runs out of TCBs. I didn't realize that theidle proc inherits time wait sockets (makes total sense if the owning procdies.)So it looks like this software was stuck in some kind of a loop

TCPView may show that the System Idle process (PID 0) is using some TCP ports. Assuming each new connection is opened by the previous, and I assume that is what you meant by serial, then it should not be what is causing the error message. · Sad, but true.If there is no malware on your system which has been designed to open any connections, then all connections opened by your machine will be legitimate, including those assigned And running a sniffer shows that's not the case -it's serial.If they are opened serially and assuming the next is not opened if the first fails, they certainly would not cause

One system I just ran across has Process ID zero with multiple connections to external IP addresses (most Yahoo registered) on port 80. After experiencing some reallystrange behavior from various applications and lot of looking around, Idownloaded TCPView from System Internals and found that the System IdleProcess (id 0) is making connections to itself,

But I couldnt find any process which opened originally these connections! TcpView can.In order to find out if any malicious software is active on your system, with or without admin privileges, or even a rootkit, you will need to do a full

System Idle Process TCP connections. My question is how can I find what process system idle process is refferring to, and is this a legitimate conection?

Definition of TIME_WAIT in rfc793: TIME-WAIT - represents waiting for enough time to pass to be sure the remote TCP received the acknowledgment of its connection termination request. The program's TCP connection to the port may be left in a "Timed Wait" state even though the program is no longer running. Hitron CDA3 modems pulled from website? [TekSavvy] by duren11280.

Since this has to happen even if the original process has exited, I'm guessing that Windows automatically transfers ownership to the system process. This behavior may occur if a local program connects to a TCP port, and then stops. This is to ensure that any packets related to the connection that might still be queued up in the network won't interfere with new connections.

This behavior may occur if a local program connects to a TCP port, and then stops. They have some kind of (apparentlybuggy) barcode printing software on this machine. However, TCPView cannot identify the program that is using the port because the program has stopped and the PID was released." -CarlosDL ---------- Please enter an answer. http://softmem.com/system-idle/svchost-exe-and-system-idle-process.html However, im confused about the 146 address.

I don't seem to see them as iexplore.exe entries. Am I right? If you have recently had a change of heart regarding browsers, then you will need to post what browser you use before anyone can answer that question. · actions · 2007-Dec-8 So therefore I decided that its some driver...What could it be?

I think Windows chooses the latter; ownership of the connection is reassigned to the system process, which will take down the connection.

