Windows 10: TCPView shows multiple [System Process] network connections...

Discus and support TCPView shows multiple [System Process] network connections... in AntiVirus, Firewalls and System Security to solve the problem; Hi all, TCPView is showing multiple network connections listed as [System Process]. These are usually connected to unrecognized IPs and certainly... Discussion in 'AntiVirus, Firewalls and System Security' started by Thelps, Jul 11, 2017.

  1. Thelps Win User

    TCPView shows multiple [System Process] network connections...


    Hi all,

    TCPView is showing multiple network connections listed as [System Process].

    These are usually connected to unrecognized IPs and certainly not IPs I would want the system to automatically connect to without request or authorization on the part of the user.

    Does this indicate malware? This isn't the usual block of Akamai servers that Windows Update uses to download updates.

    I've tried an AV scan but it shows no results.

    I've tried blocking these IPs with a firewall but plenty more IPs from entirely different domains keep appearing under [System Process]​.

    How are they establishing connections, how can I identify these unknown processes and how can I completely prevent this activity without using a firewall that requires manual authorization for EVERY connection (this computer's user couldn't handle that level of complexity).

    The OS is Windows 10.

    Much appreciated.

    :)
     
    Thelps, Jul 11, 2017
    #1
  2. Ralf_G Win User

    Windows 10 excessive system downloads

    That does seem rather a lot of data usage for System. By way of comparison mine shows only 68.3MB of data usage over the last month. My first suspect would be the Updates setting that allows
    uploading and downloads of Windows Update data to/from PCs on the internet.

    You can try monitoring which processes are actively transferring data over the network and/or to hard disk without you having invoked those data transfers by using Resource Monitor and/or TaskManager. Resource Monitor will show the network addresses being
    connected to by the various processes. There are also 3rd party programs which can give more details about the remote sites being connected to by individual apps or processes (eg. CPorts & IPNetInfo from NirSoft - freeware utilities: password recovery, system utilities, desktop utilities
    ). TCPView from
    www.sysinternals.com
    is a similar utility which can display the quantity of bytes being sent/received by each process.
     
    Ralf_G, Jul 11, 2017
    #2
  3. JTIMAN Win User
    Many Connections in TIME_WAIT Status Lingering In Windows 10

    I recently installed Windows 10 Pro x64, for normal, personal desktop usage (i.e. not to serve as a web or database server) and was using SysInternals TCPView to monitor connections, and am noticing at least a hundred connections with status of TIME_WAIT
    lingering. The process information for these all is [System Process], PID 0, using TCP, and in almost all cases the remote address is my router at remote port 2555 (only a handful are not). I've seen this go as high as 200-300, but no lower than 115-130.

    I have also used TCPView in Windows 7 Pro x64, and did not see anywhere near as many of these connections.

    Has anyone else noticed this in Windows 10? Any ideas why this would be happening? And is this anything to worry about?

    Any thoughts are appreciated.
     
    JTIMAN, Jul 11, 2017
    #3
  4. Samuria Win User

    TCPView shows multiple [System Process] network connections...

    If you can give us a list that will give us a better idea of what's going on. It worth checking schedule task to see if any of them are doing it
     
    Samuria, Jul 11, 2017
    #4
  5. Thelps Win User
    The list has a huge variation of IPs. I haven't noted any pattern in what IPs appear.

    Could you suggest how I could identify this process or set of processes referred to as [System Process]?
     
    Thelps, Jul 11, 2017
    #5
  6. TairikuOkami, Jul 12, 2017
    #6
  7. Thelps Win User
    So the System Idle Process represents connections that are in the process of being dropped.

    However, what ARE these connections? I don't recognize their IPs at all.

    Also, why is Explorer making network connections to unknown IPs and how can I stop that? I have the explorer.exe firewalled and denied access to the internet but it is continuing to connect. I understand this is probably just Windows Update but would like to control all network traffic and only allow wuausrv and other explorer-based programs network access when I'm aware of what they're doing.

    Further advice much appreciated.
     
    Thelps, Jul 15, 2017
    #7
  8. Thelps Win User

    TCPView shows multiple [System Process] network connections...

    I'd really appreciate it if someone could shed further assistance on the topic.
     
    Thelps, Apr 5, 2018
    #8
Thema:

TCPView shows multiple [System Process] network connections...

Loading...
  1. TCPView shows multiple [System Process] network connections... - Similar Threads - TCPView shows multiple

  2. BSoD, Critical Process Died, Multiple Systems

    in Windows 10 Gaming
    BSoD, Critical Process Died, Multiple Systems: I'm at a bit of a loss folks!In the last week and change, 5 systems have started blue screening roughly every hour, give or take. They all get the Critical Process Died stop code. When using Bluescreenview on their dump files, it's pointing to the ntoskrnl.All Dell systems,...
  3. BSoD, Critical Process Died, Multiple Systems

    in Windows 10 Software and Apps
    BSoD, Critical Process Died, Multiple Systems: I'm at a bit of a loss folks!In the last week and change, 5 systems have started blue screening roughly every hour, give or take. They all get the Critical Process Died stop code. When using Bluescreenview on their dump files, it's pointing to the ntoskrnl.All Dell systems,...
  4. Multiple versions of home network appear in network connections

    in Windows 10 Gaming
    Multiple versions of home network appear in network connections: In network connections my computer consistently shows multiple versions of my home network; I have a Fios router and the name of the network is MOTOR18, however, there are always at least 4 'MOTOR 18' networks shown, and also always 'MOTOR18 2, MOTOR18 3,' and so on. They all...
  5. Multiple versions of home network appear in network connections

    in Windows 10 Software and Apps
    Multiple versions of home network appear in network connections: In network connections my computer consistently shows multiple versions of my home network; I have a Fios router and the name of the network is MOTOR18, however, there are always at least 4 'MOTOR 18' networks shown, and also always 'MOTOR18 2, MOTOR18 3,' and so on. They all...
  6. Multiple versions of home network appear in network connections

    in Windows 10 Network and Sharing
    Multiple versions of home network appear in network connections: In network connections my computer consistently shows multiple versions of my home network; I have a Fios router and the name of the network is MOTOR18, however, there are always at least 4 'MOTOR 18' networks shown, and also always 'MOTOR18 2, MOTOR18 3,' and so on. They all...
  7. Multiple ethernet network connections

    in Windows 10 Network and Sharing
    Multiple ethernet network connections: I carry my laptop between work and home frequently. At work, I have an assigned IP address. And at home, I am using DHCP. Right now, if I switch to DHCP, then I have to reenter my assigned IP address when I take the laptop to work. Is there someway to set up two "identities"...
  8. Network shows not connected although connected

    in Windows 10 Drivers and Hardware
    Network shows not connected although connected: Hello - I have a Yoga Lenovo 930C and I am able to surf the internet via Edge Google etc but it says that "I am not connected to the Internet" and the only suggestion it gives me is to "reset my network" which I have done and it still doesn't show as connected although I...
  9. How to remove Multiple Network Connections?

    in Windows 10 Network and Sharing
    How to remove Multiple Network Connections?: I have a pocket Wifi Device, however, it is NOT using Wifi connection, as I have it connected to my PC using an USB Cable. Every morning I turn on my PC, it creates a new network connection, for example "Network 7" How do I remove Network 1 to 6, and where are they...
  10. Multiple Network connections

    in Windows 10 Network and Sharing
    Multiple Network connections: Can someone please tell me how to get rid of these connections. [img] I have tried disabling them. Is it safe to delete them..? and is it safe to do so. Thanks. 65209