Using Sysinternals TCPview program, I've recently been noticing over a dozen unconnected endpoints that utilize the System 8 process, and the TCP protocol.
They're using local ports in the 1300-1400 range.

In addition, I'll see several instances of the Vsmon process running.

Both of these events occur even when no browser or e-mail program is open.
I'll just have my firewall, AV program, and MS Windows Defender running (with Spybot operating somewhere in the background).

I can't recall ever seeing so many System 8 processes (though unconnected).
Using a netstat -an command, all the addresses are 0.0.0.0 and the state is "listening".
Any and all comments would be appreciated.



Message Edited by clayachin on 05-09-200605:27 AM

Operating System:Windows 2000 Pro
Product Name:ZoneAlarm Pro
Software Version:5.x