ok - I'd like to clarify my interest in this thread - does KNOPPIX secure all its ports out of the box?

I would like to introduce KNOPPIX as a secure alternative to WinXP out of the box.

I booted KNOPPIX 5.0.1 and ran a Trojan scan at http://scan.sygate.com. It reports the following vulnerabilities:

Trojan 21 OPEN Back Construction, Blade Runner, Doly Trojan, Fore, FTP trojan, Invisible FTP, Larva, WebEx, WinCrash
Trojan 23 OPEN Tiny Telnet Server (= TTS)
Trojan 80 OPEN Executor, RingZero

I was a bit surprised to see this. Are there additional steps I need to take to secure my PC?

Is there a reason these ports are open by default?