itman 1,754 Posted July 18, 2020 Share Posted July 18, 2020 In reference to Win Store connections shown below: I have noticed that these same connections on occasion do not appear in either SysInternals TCPView display or via netstat inquiry. Behavior seems to manifest after system logon from prior system logoff activity: Microsoft Windows [Version 10.0.18363.959] (c) 2019 Microsoft Corporation. All rights reserved. C:\Windows\system32>netstat -anob Active Connections Proto Local Address Foreign Address State PID TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 600 RpcSs [svchost.exe] TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4 Can not obtain ownership information TCP 0.0.0.0:5040 0.0.0.0:0 LISTENING 4888 CDPSvc [svchost.exe] TCP 0.0.0.0:49664 0.0.0.0:0 LISTENING 784 [lsass.exe] TCP 0.0.0.0:49665 0.0.0.0:0 LISTENING 704 Can not obtain ownership information TCP 0.0.0.0:49666 0.0.0.0:0 LISTENING 1480 EventLog [svchost.exe] TCP 0.0.0.0:49667 0.0.0.0:0 LISTENING 1272 Schedule [svchost.exe] TCP 0.0.0.0:49668 0.0.0.0:0 LISTENING 2928 [spoolsv.exe] TCP 0.0.0.0:49669 0.0.0.0:0 LISTENING 776 Can not obtain ownership information TCP 192.168.1.xx:139 0.0.0.0:0 LISTENING 4 Can not obtain ownership information TCP 192.168.1.xx:53744 52.230.222.68:443 ESTABLISHED 3248 WpnService [svchost.exe] TCP 192.168.1.xx:53913 52.85.90.122:443 TIME_WAIT 0 TCP 192.168.1.xx:53922 38.90.226.40:80 TIME_WAIT 0 TCP [::]:135 [::]:0 LISTENING 600 RpcSs [svchost.exe] TCP [::]:445 [::]:0 LISTENING 4 Can not obtain ownership information TCP [::]:49664 [::]:0 LISTENING 784 [lsass.exe] TCP [::]:49665 [::]:0 LISTENING 704 Can not obtain ownership information TCP [::]:49666 [::]:0 LISTENING 1480 EventLog [svchost.exe] TCP [::]:49667 [::]:0 LISTENING 1272 Schedule [svchost.exe] TCP [::]:49668 [::]:0 LISTENING 2928 [spoolsv.exe] TCP [::]:49669 [::]:0 LISTENING 776 Can not obtain ownership information UDP 0.0.0.0:500 *:* 3240 IKEEXT [svchost.exe] UDP 0.0.0.0:4500 *:* 3240 IKEEXT [svchost.exe] UDP 0.0.0.0:5050 *:* 4888 CDPSvc [svchost.exe] UDP 0.0.0.0:5353 *:* 1976 Dnscache [svchost.exe] UDP 0.0.0.0:5355 *:* 1976 Dnscache [svchost.exe] UDP 0.0.0.0:62599 *:* 1908 Can not obtain ownership information UDP 127.0.0.1:58061 *:* 3424 iphlpsvc [svchost.exe] UDP 127.0.0.1:60878 *:* 1908 Can not obtain ownership information UDP 192.168.1.xx:137 *:* 4 Can not obtain ownership information UDP 192.168.1.xx:138 *:* 4 Can not obtain ownership information UDP [::]:500 *:* 3240 IKEEXT [svchost.exe] UDP [::]:4500 *:* 3240 IKEEXT [svchost.exe] UDP [::]:5353 *:* 1976 Dnscache [svchost.exe] UDP [::]:5355 *:* 1976 Dnscache [svchost.exe] Link to comment Share on other sites More sharing options...
Recommended Posts