Netstat -b

Phrosen

New member
Member
Local time
3:01 PM
Messages
92
Location
Sweden
Hi.

I used the command netstat -b in the command prompt and I got a bunch of text that I don't know what it is. (I closed down all internet connections first, such as steam, web browser, etc.)
Could you guys help me find out what these things are?

Here's what it looks like:



Prot. Lokal adress Extern adress Status
[System]
TCP 192.168.***** 213-155-158-73:http TIME_WAIT
TCP 192.168.***** 213-155-158-73:http FIN_WAIT_2
[System]
TCP 192.168.***** 213-155-158-73:http TIME_WAIT
TCP 192.168.***** www-12-02-ash3:http TIME_WAIT
TCP 192.168.***** channel-150-155:http TIME_WAIT
TCP 192.168.***** 195-12-231-50:http FIN_WAIT_2
[System]
TCP 192.168.***** 195-12-231-50:http FIN_WAIT_2
[System]
TCP 192.168.1.***** 195-12-231-50:http FIN_WAIT_2
[System]
TCP 192.168.1.***** 195-12-231-50:http FIN_WAIT_2
[System]
TCP 192.168.1.***** 195-12-231-50:http FIN_WAIT_2
[System]
TCP 192.168.1.***** 195-12-231-50:http FIN_WAIT_2
[System]
TCP 192.168.1.***** 199.7.79.171:http FIN_WAIT_2
[System]
TCP 192.168.1.***** 213-155-158-73:http TIME_WAIT
TCP 192.168.1.***** www-12-02-ash3:http TIME_WAIT
TCP 192.168.1.***** www-12-02-ash3:http TIME_WAIT
TCP 192.168.1.***** 199.7.79.171:http FIN_WAIT_2
[System]
TCP 192.168.1.***** ip-69:http TIME_WAIT
TCP 192.168.1.***** 193-45-3-138:http TIME_WAIT


(I blanked out the local ip, just in case.)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Myself
OS
Windows 7 Professional x64
CPU
AMD FX 8320
Motherboard
ASUS M5A97
Memory
8GB
Graphics Card(s)
Nvidia Geforce GTX 770
Monitor(s) Displays
Acer P223w
Screen Resolution
1680x1050
Hard Drives
Samsung SpinPoint 1TB @ 7200rpm
PSU
Corsair 620HX - 620W
Case
Lian-Li Scandinavian Edition
Keyboard
Razer Lycosa
Mouse
Razer DeathAdder
Those are a bunch of sockets that were going to web sites that are now cut off (probably ungracefully) and waiting to close after the sockets time out.

If you do a netstat after a few minutes they should all be gone.

Can't tell what program was originally opening them though... legitimate programs and nefarious programs alike can leave hung sockets quite often. When they are all gone, open your programs one at a time andyou can see what matches up if you want.

The TIME_WAITs and FIN_WAITS are nothing to be worried about in themselves unless you had like thousands of them.

[Edit] Or did you want to know specifically if anyone know what "System" process was opening them?[/edit]
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Scratch built
OS
Windows 7 x64 Ultimate
CPU
i7 960
Motherboard
Asus P6X58D
Memory
12 Gig Corsair Dominator
Graphics Card(s)
Nvidia 480
Sound Card
Maudio Delta 44 + breakout box
Monitor(s) Displays
Dell UltraSharp U2410 24in and Samsung 21 dual monitors
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
Primary: Intel X-25M G2 160G SSD
Secondary: Segate baracuda 1.0 TB
HDs in AHCI mode.
PSU
Corasair TX850
Case
Cooler Master HAF
Cooling
Corsair H50
Keyboard
Logitech G15 + N52 game pad
Mouse
Logitech MX518
Internet Speed
15kbs down 4.5kbps up
Other Info
WEI 7.6
CPU & RAM 7.6
Graphics 7.9
Hard disk 7.7
Thanks.

I shut everything down, waited for about 20 mins and tried again.
Now I got a few stuff (for example one saying steampowered - even though steam was offline.) They all said ESTABLISHED in the "status".
One said: cdce:http as "external ip" -What's this?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Myself
OS
Windows 7 Professional x64
CPU
AMD FX 8320
Motherboard
ASUS M5A97
Memory
8GB
Graphics Card(s)
Nvidia Geforce GTX 770
Monitor(s) Displays
Acer P223w
Screen Resolution
1680x1050
Hard Drives
Samsung SpinPoint 1TB @ 7200rpm
PSU
Corsair 620HX - 620W
Case
Lian-Li Scandinavian Edition
Keyboard
Razer Lycosa
Mouse
Razer DeathAdder
netstat abbreviates names when it can to maintain formatting. For example is you were connected to www.sevenforums.com it would just say "sevenforums:http". The name can also be a local MS network name as well. I.e. the name of another computer on your local network.

If you want to know what the IP address is, do a netstat -bn. Then you'll get the IP addresses instead and you can do a reverse lookup on the IP address and get the full name using:
nslookup <ipaddress>

Though sometimes your default DNS server wont do reverse lookups, if it can't find the name and the address you got is not on your local network do a:
nslookup <ipaddress> 8.8.8.8

That will use Google's DNS to do the name lookup for you.
 

My Computer

Computer Manufacturer/Model Number
Scratch built
OS
Windows 7 x64 Ultimate
CPU
i7 960
Motherboard
Asus P6X58D
Memory
12 Gig Corsair Dominator
Graphics Card(s)
Nvidia 480
Sound Card
Maudio Delta 44 + breakout box
Monitor(s) Displays
Dell UltraSharp U2410 24in and Samsung 21 dual monitors
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
Primary: Intel X-25M G2 160G SSD
Secondary: Segate baracuda 1.0 TB
HDs in AHCI mode.
PSU
Corasair TX850
Case
Cooler Master HAF
Cooling
Corsair H50
Keyboard
Logitech G15 + N52 game pad
Mouse
Logitech MX518
Internet Speed
15kbs down 4.5kbps up
Other Info
WEI 7.6
CPU & RAM 7.6
Graphics 7.9
Hard disk 7.7
Back
Top