Re: XP Home connectivity lost after SP2: NETBT??

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Martin Kochanski (nothing_at_nobody.net)
Date: 09/30/04


Date: Thu, 30 Sep 2004 10:03:26 +0100

Thank you for your quick response. There were no other relevant messages
in Event Viewer.

It turns out that someone was concerned about Windows Firewall leaving
port 445 open to the Internet (even though, in "Exceptions", it's set up
to be "subnet only") and altered
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters to
rename the TransportBindName string. This did indeed prevent my computer
from listening on port 445, but it also (as we have seen) stopped NetBT
working completely. Once I undid that alteration everything was OK.

This does, however, raise the question of the unsecured port 445. Now,
when I am connected to the Internet, netstat quite often reports
ESTABLISHED connections to 'microsoft-ds' on my computer, from remote
dialup computers somewhere else on the Internet. These connections are
of course unwanted and presumably malicious in intent.

1. Is there any way of blocking these connections, since Windows
Firewall won't do it?
2. Are these connections a security risk?

"Steve Winograd [MVP]" wrote:
>
> In article <415B212E.24E9C9DE@nobody.net>, Martin Kochanski
> <nothing@nobody.net> wrote:
> >A pair of computers linked via Ethernet: one 98, one XP Home. Each
> >belongs to the workgroup WORKGROUP and has shares that the other
> >connects to. After SP2,
> >
> >- TCP/IP works. I can ping from one computer to the other and I can also
> >make TCP connections from one computer to the other.
> >- the 98 computer browsing the network sees WORKGROUP and sees itself
> >but does not see the XP Home computer.
> >- the XP Home computer browsing the network through My Network Places
> >sees WORKGROUP, but WORKGROUP appears blank: it doesn't even see itself
> >there.
> >- Event Viewer reports "4311" error messages for NetBT.
> >- Although TCP/IP > Properties > Advanced > WINS says "Enable NETBIOS",
> >ipconfig/all reports "NetBIOS over Tcpip Disabled".
> >- net view \\xpmachine lists all the XP machine's shares.
> >- net view \\98machine reports "System error 1231 has occurred".
> >- I have checked that the workgroup name is still WORKGROUP.
> >- uninstalling the network card and allowing XP to find it again makes
> >no difference to the problem.
> >- Disabling Windows Firewall makes no difference to the problem.
> >- Disabling and re-enabling the LAN connection makes no difference to
> >the problem.
> >- Repairing the LAN connection fails. The message is "Windows could not
> >finish repairing the problem because the following action cannot be
> >completed: Clearing NetBT".
> >
> >I'm sort of running out of things to try. Does anyone have any
> >suggestions?
>
> Event ID 4311 means that "Initialization failed because the driver
> device could not be created." Are there any other relevant messages
> in Event Viewer? Anything about TCP/IP Protocol Driver or IPSEC
> Driver?
>
> Make sure that the TCP/IP NetBIOS Helper service is running and is
> configured to start automatically.
>
> This web page has more information:
>
> http://www.eventid.net/display.asp?eventid=4311&eventno=910&source=NetBT&phase=1
> --
> Best Wishes,
> Steve Winograd, MS-MVP (Windows Networking)
>
> Please post any reply as a follow-up message in the news group
> for everyone to see. I'm sorry, but I don't answer questions
> addressed directly to me in E-mail or news groups.
>
> Microsoft Most Valuable Professional Program
> http://mvp.support.microsoft.com



Relevant Pages

  • RE: http-NO (mail,news,messenging..)-yes
    ... The Unknown P wrote: ... Fast connections do not equal fast throughput. ... I have the pc in my workshop, and No http port 80, but I ... I tried IE, Firefox, as well as the windows help system, no luck. ...
    (microsoft.public.windowsxp.general)
  • Re: Change COM port
    ... software and physically remove your modem so that you can reboot the system ... with DOS and DOS based Windows.. ... I remember the days going> back to DOS 6.22, when in connecting up a modem, it had to> be set, and sometimes jumpered, for appropriate COM port. ... >> connections), ...
    (microsoft.public.windowsxp.basics)
  • Windows 2003 RDP will not work with WAN but port 3389 is listening
    ... Windows 2003 Server with SP 2 and port 339879 running and will allow ... RD connections from LAN only. ... There is no evidence on the server ... Windows Firewall ...
    (microsoft.public.windows.terminal_services)
  • Re: VNC server on windows, linux client cannot connect
    ... Did that for all the ports in the range 5900-9 with my own firewall down. ... Accept Socket Connections is checked. ... Display or port numbers to display 0 (choosing main port as 5900 and http as ... How do I find out whether this windows machine is running a firewall? ...
    (comp.os.linux.x)
  • Re: Need help with bandwidth management . . .
    ... also be a good time to separate the wired from the wireless parts of ... wired connections. ... QoS lan port settings, and I cannot get anything consistent. ... switch ports and limit the bandwidth per port (the settings are ...
    (alt.internet.wireless)