I have a base new install of windows 7, and when I went to look for something else I saw the attached netstat output.
What concerns me is that this is Windows + Truecrypt + drivers, nothing else installed.
The sequential high ranged ports belonging to several different seemingly not out of place services seemed odd.
So I torched the install, used Active@ to scrub the disk, re-downloaded the ISO from MSDN, and did a fresh reinstall, viola, they are there again.
It just seems out of place, I have seen a many netstats over the years, this one just strikes me as odd, so I started thinking rootkit? (JUst FYI, when I reloaded I named the machine "Error" so that is why the task manager reads the computer name as such.)
So I would like to know if anyone else could explain it, and therefore is may be normal, or would they be worried as well, and should I start considering I have some very strange thing occuring on my network?
In the end this ended up being the fact that I did not know (too many years buried in code, less in the guts of my OS) that the ephemeral port range had been changed from > 1024 to start at 49152 as confirmed by...
I confirmed all executables listening were correct versions, and the alarm was false, just a misunderstanding and not anticipating them being so high.