Post by Dheeraj ChawlaDear Andy,
I would like to inform you that it could be possible that
your dns server could be contacting other dns servers or the name servers on
internet. When you stop the dns service, the ports do disappear from the port
scan. try to type netstat|more on the command prompt and post the results
here while the service is on and off. This command will give you the number
of connections going in and out from your server. Also go to the task
manager. This can be done by right clicking on the Taskbar and click on task
Manager. Click on Processes and take a look on all the processes make sure
that you don't find any funny names that are started either by the System or
the user.
Do let me know if my answer could be helpful
When I run the command before and after I stop the DNS server this is the
output I get:
Active Connections
Proto Local Address Foreign Address State
TCP technics:ldap technics.multizite.local:1034 ESTABLISHED
TCP technics:ldap technics.multizite.local:1035 ESTABLISHED
TCP technics:ldap technics.multizite.local:1038 ESTABLISHED
TCP technics:ldap technics.multizite.local:1151 ESTABLISHED
TCP technics:ldap technics.multizite.local:1177 ESTABLISHED
TCP technics:1034 technics.multizite.local:ldap ESTABLISHED
TCP technics:1035 technics.multizite.local:ldap ESTABLISHED
TCP technics:1038 technics.multizite.local:ldap ESTABLISHED
TCP technics:1151 technics.multizite.local:ldap ESTABLISHED
TCP technics:1177 technics.multizite.local:ldap ESTABLISHED
TCP technics:ldap technics.multizite.local:1047 ESTABLISHED
TCP technics:ldap technics.multizite.local:1143 ESTABLISHED
TCP technics:ldap technics.multizite.local:1268 TIME_WAIT
TCP technics:ldap technics.multizite.local:1269 TIME_WAIT
TCP technics:microsoft-ds technics.multizite.local:1270 ESTABLISHED
TCP technics:1025 technics.multizite.local:1049 ESTABLISHED
TCP technics:1025 technics.multizite.local:1179 ESTABLISHED
TCP technics:1047 technics.multizite.local:ldap ESTABLISHED
TCP technics:1049 technics.multizite.local:1025 ESTABLISHED
TCP technics:1143 technics.multizite.local:ldap ESTABLISHED
TCP technics:1169 technics.multizite.local:1025 TIME_WAIT
TCP technics:1178 technics.multizite.local:epmap TIME_WAIT
TCP technics:1179 technics.multizite.local:1025 ESTABLISHED
TCP technics:1270 technics.multizite.local:microsoft-ds
ESTABLISHED
TCP technics:3389 172.16.0.16:3265 ESTABLISHED
DNS stopped:
Active Connections
Proto Local Address Foreign Address State
TCP technics:ldap technics.multizite.local:1034 ESTABLISHED
TCP technics:ldap technics.multizite.local:1035 ESTABLISHED
TCP technics:ldap technics.multizite.local:1038 ESTABLISHED
TCP technics:ldap technics.multizite.local:1151 ESTABLISHED
TCP technics:1034 technics.multizite.local:ldap ESTABLISHED
TCP technics:1035 technics.multizite.local:ldap ESTABLISHED
TCP technics:1038 technics.multizite.local:ldap ESTABLISHED
TCP technics:1151 technics.multizite.local:ldap ESTABLISHED
TCP technics:ldap technics.multizite.local:1047 ESTABLISHED
TCP technics:ldap technics.multizite.local:1143 ESTABLISHED
TCP technics:ldap technics.multizite.local:1268 TIME_WAIT
TCP technics:ldap technics.multizite.local:1269 TIME_WAIT
TCP technics:1025 technics.multizite.local:1049 ESTABLISHED
TCP technics:1025 technics.multizite.local:1179 ESTABLISHED
TCP technics:1047 technics.multizite.local:ldap ESTABLISHED
TCP technics:1049 technics.multizite.local:1025 ESTABLISHED
TCP technics:1143 technics.multizite.local:ldap ESTABLISHED
TCP technics:1169 technics.multizite.local:1025 TIME_WAIT
TCP technics:1178 technics.multizite.local:epmap TIME_WAIT
TCP technics:1179 technics.multizite.local:1025 ESTABLISHED
TCP technics:1270 technics.multizite.local:microsoft-ds
TIME_WAIT
TCP technics:3389 172.16.0.16:3265 ESTABLISHED
As you can se I do not have any pport 1050 open. I've also installed NOD32
virus scanner from Esat now, and it didn't detect any viruses on the
machine.
Any idea?
/A.