Hey guys, rela busy with Fam this weekend. I am posting this from a virt vista machine (:CLP)
here is the initial netstat w/o any addons/updates:
C:\Users\Usem>netstat -an
Active Connections
Proto Local Address Foreign Address State
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49152 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49153 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49154 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49155 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49156 0.0.0.0:0 LISTENING
TCP 172.16.30.60:139 0.0.0.0:0 LISTENING
TCP 172.16.30.60:49160 63.88.212.184:80 TIME_WAIT
TCP [::]:135 [::]:0 LISTENING
TCP [::]:445 [::]:0 LISTENING
TCP [::]:49152 [::]:0 LISTENING
TCP [::]:49153 [::]:0 LISTENING
TCP [::]:49154 [::]:0 LISTENING
TCP [::]:49155 [::]:0 LISTENING
TCP [::]:49156 [::]:0 LISTENING
UDP 0.0.0.0:123 :
UDP 0.0.0.0:500 :
UDP 0.0.0.0:4500 :
UDP 0.0.0.0:5355 :
UDP 127.0.0.1:1900 :
UDP 127.0.0.1:65499 :
UDP 172.16.30.60:137 :
UDP 172.16.30.60:138 :
UDP 172.16.30.60:1900 :
UDP [::]:123 :
UDP [::]:500 :
UDP [::]:5355 :
UDP [::1]:1900 :
UDP [::1]:65498 :
UDP [fe80::20ef:bca:53ef:e1c3%15]:1900 :
NETSTAT -ANOB:
C:\Users\Usem>netstat -anob
Active Connections
Proto Local Address Foreign Address State PID
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 836
RpcSs
[svchost.exe]
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
Can not obtain ownership information
x: Windows Sockets initialization failed: 5
TCP 0.0.0.0:49152 0.0.0.0:0 LISTENING 516
[wininit.exe]
TCP 0.0.0.0:49153 0.0.0.0:0 LISTENING 944
Eventlog
[svchost.exe]
TCP 0.0.0.0:49154 0.0.0.0:0 LISTENING 1000
Schedule
[svchost.exe]
TCP 0.0.0.0:49155 0.0.0.0:0 LISTENING 604
[lsass.exe]
TCP 0.0.0.0:49156 0.0.0.0:0 LISTENING 560
[services.exe]
TCP 172.16.30.60:139 0.0.0.0:0 LISTENING 4
Can not obtain ownership information
x: Windows Sockets initialization failed: 5
TCP [::]:135 [::]:0 LISTENING 836
RpcSs
[svchost.exe]
TCP [::]:445 [::]:0 LISTENING 4
Can not obtain ownership information
x: Windows Sockets initialization failed: 5
TCP [::]:49152 [::]:0 LISTENING 516
[wininit.exe]
TCP [::]:49153 [::]:0 LISTENING 944
Eventlog
[svchost.exe]
TCP [::]:49154 [::]:0 LISTENING 1000
Schedule
[svchost.exe]
TCP [::]:49155 [::]:0 LISTENING 604
[lsass.exe]
TCP [::]:49156 [::]:0 LISTENING 560
[services.exe]
UDP 0.0.0.0:123 : 1148
W32Time
[svchost.exe]
UDP 0.0.0.0:500 : 1000
IKEEXT
[svchost.exe]
UDP 0.0.0.0:4500 : 1000
IKEEXT
[svchost.exe]
UDP 0.0.0.0:5355 : 1320
Dnscache
[svchost.exe]
UDP 127.0.0.1:1900 : 1148
SSDPSRV
[svchost.exe]
UDP 127.0.0.1:64324 : 2784
[iexplore.exe]
UDP 127.0.0.1:65499 : 1148
SSDPSRV
[svchost.exe]
UDP 172.16.30.60:137 : 4
Can not obtain ownership information
x: Windows Sockets initialization failed: 5
UDP 172.16.30.60:138 : 4
Can not obtain ownership information
x: Windows Sockets initialization failed: 5
UDP 172.16.30.60:1900 : 1148
SSDPSRV
[svchost.exe]
UDP [::]:123 : 1148
W32Time
[svchost.exe]
UDP [::]:500 : 1000
IKEEXT
[svchost.exe]
UDP [::]:5355 : 1320
Dnscache
[svchost.exe]
UDP [::1]:1900 : 1148
SSDPSRV
[svchost.exe]
UDP [::1]:65498 : 1148
SSDPSRV
[svchost.exe]
UDP [fe80::20ef:bca:53ef:e1c3%15]:1900 :
1148
SSDPSRV
[svchost.exe]
Havent had time to go through this yet myself. Let me know what you think.