sorry
nope this is not an M$ question, but it sure may be M$ fault, as always.
this is a sample from my ulog(viewed thru fwfilter)
Sep 13 13:52:25 ALL - DROP IN=eth1 SRC=64.124.113.204 DST=xxxx.xxxx.xxxx.xxxx PROTO=TCP DPT=65535 SPT=52248 TTL=51 CE SEQ=3032250045 ACK=0 SYN
Sep 13 13:52:35 ALL - DROP IN=eth1 SRC=209.203.99.232 DST=xxxx.xxxx.xxxx.xxxx PROTO=TCP DPT=65535 SPT=41141 TTL=49 SEQ=3216952148 ACK=0 SYN
Sep 13 13:52:37 ALL - DROP IN=eth1 SRC=64.124.113.204 DST=xxxx.xxxx.xxxx.xxxx PROTO=TCP DPT=65535 SPT=52248 TTL=51 CE SEQ=3032250045 ACK=0 SYN
Sep 13 13:52:38 ALL - DROP IN=eth1 SRC=209.203.99.232 DST=xxxx.xxxx.xxxx.xxxx PROTO=TCP DPT=65535 SPT=41141 TTL=49 SEQ=3216952148 ACK=0 SYN
Sep 13 13:52:44 ALL - DROP IN=eth1 SRC=209.203.99.232 DST=xxxx.xxxx.xxxx.xxxx PROTO=TCP DPT=65535 SPT=41141 TTL=49 SEQ=3216952148 ACK=0 SYN
as you see there's alot of connection to port 65535 and these keeps going on, i get about 40-60 of these a minute
PS. and not just from these IP addresses either, its from all over
