Ok. I have Windows XP machine that I am using as a quasi-server temporarily. It was setup with Multiple users and multiple shared folders for each user. These users connect via the network, so it’s supposed to resemble an active directory setup without the active directory, get it? I am not the one who set it up but this is what we have to do for now because there is no server on site yet. Anyway, I was running a security tool that I use sometimes (GFI LanGuard) and noticed a whole bunch of UDP ports wide open. I did a netstat -an and confirmed these open ports.
here are a few;
UDP 50304
UDP 50314
UDP 50324
UDP 50324
UDP 50334
UDP 50344
GFI defaults and says that this is due to trojans (because of the fact that trojans commonly open up those dynamic range ports). The problem is I have run my AV, Anti-spyware, and anti-rootkit software and all is telling me that I am clean. System performance and experience tell me that I am clean also (no strange entries in the startup group, no strange services running, etc.)
My question is; Would all of those open shares be causing these ports to be open? The sequential way they are numbered led me to suspect that but I am not sure. So that’s it. Would allot of open shares cause Windows XP to leave a bunch of UDP ports open like that for the clients to connect? Thanks in advance for any help.