Proto Local Address Foreign Address State
TCP bt-7hdhj4a5rp8l:1027 localhost:4196 TIME_WAIT
TCP bt-7hdhj4a5rp8l:1027 localhost:4198 TIME_WAIT
TCP bt-7hdhj4a5rp8l:1027 localhost:4200 TIME_WAIT
TCP bt-7hdhj4a5rp8l:1027 localhost:4202 TIME_WAIT
TCP bt-7hdhj4a5rp8l:1027 localhost:4204 TIME_WAIT
TCP bt-7hdhj4a5rp8l:1248 64.12.25.67:5190 ESTABLISHED
TCP bt-7hdhj4a5rp8l:1874 198.74.33.66:6667 ESTABLISHED
This is typical of an instant messenger program similar to Trillian
TCP bt-7hdhj4a5rp8l:4197 63.99.109.171: pop3 TIME_WAIT
TCP bt-7hdhj4a5rp8l:4199 208.50.7.212: pop3 TIME_WAIT
TCP bt-7hdhj4a5rp8l:4201 imv15.mail.bellsouth.net: pop3 TIME_WAIT
TCP bt-7hdhj4a5rp8l:4203 66-162-74-6.gen.twtelecom.net: pop3 TIME_WAIT
TCP bt-7hdhj4a5rp8l:4205 208.50.7.212: pop3 TIME_WAIT
These are closed sessions to your mail servers, it looks like you have 5 accounts set up
TCP bt-7hdhj4a5rp8l:4207 ads.web.aol.com:http TIME_WAIT
TCP bt-7hdhj4a5rp8l:4208 ads.web.aol.com:http TIME_WAIT
TCP bt-7hdhj4a5rp8l:4210 ads.web.aol.com:http TIME_WAIT
TCP bt-7hdhj4a5rp8l:4211 ads.web.aol.com:http TIME_WAIT
TCP bt-7hdhj4a5rp8l:4213 65.221.101.43:http CLOSE_WAIT
TCP bt-7hdhj4a5rp8l:4214 65.221.101.43:http CLOSE_WAIT
TCP bt-7hdhj4a5rp8l:4215 216.120.226.229:http CLOSE_WAIT
TCP bt-7hdhj4a5rp8l:4216 fdcservers.net:http CLOSE_WAIT
This is your websurfing. Notice that most ad links don't actually close the session...
this is generally for cookie tracking allowing them to trace your progress across the net.
To be sure, grab
TCPView (it's free) and check what actual applications have the ports mapped. It will verify if you have trojans or spyware listening.