Running netstat -aon
Summary
Active Connections

Proto Local Address Foreign Address State PID
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 696
TCP 0.0.0.0:1025 0.0.0.0:0 LISTENING 476

I have lsass.exe starting at 1025 all the time does that seem normal... I do know what lsass is...
Another thing i look at the task manager i cant see any of the users that started the processes except for the system idle process.

And usually if you look at the users tab in the task manager you should seee the user you are logged in as there. i dont see any entries...

Im not sure if all these are realated since lsass deals with verifying the user logon on the PC

Thanks in advance

By the way "Security task manager" seems like a nice tool