Re: AV showing unauthorized access attempts after installing IE8

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance




"azdesert" <azdesert@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C7120E66-93B3-4C8B-A409-6CF492598EF4@xxxxxxxxxxxxx
I am on Windows XP Sp3 and using Nortion Antivirus 2009. All
antivirus and windows updates are current. NAV is showing in its
history "unauthorized access blocked" (medium threat level) all day
long, sometimes with attempts at access every few minutes. NAV
doesn't otherwise show any problem and a complete system scan found
nothing wrong. I only discovered this when checking the history for
something else.

I did install IE8 a few days ago. My question is:

Has anyone else seen this and is it some sort of conflict with IE8?
Or is it possible that there are continual attempts from the outside
to take control of the computer or to install malware on my computer?

You are most likely seeing "normal" WAN side noise or traffic and have
one or more ports open that is reacing to queies; usually echo requests.
On the internet side of your modem are many, many people trolling for
open ports and machines they can get into. When they find an open port,
they query it to see if it responds. If it does, the port is open and
they try to use it to get into your computer system. You NAV is seeing
that, blocking it, and reporting to you what it did about it.
They just grab an IP address and go through it number by number,
looking for places that will let them in. It's the "normal" , "wrong
side of the tracks" idiots looking for ANY machine they can find, pretty
much at random, that will give them access.

There isn't a whole lot you can do about it other than be sure to keep
your security program in place and updated.
If you're into learning more about the subject, you can go to
www.grc.com (Gibson Research) and they can run various tests on your
system from there. One of the tests is for open ports. The results are
Open, Closed, or Stealthed. Stealth is best, Closed next. If anything
should be done about the test results, it'll offer suggestions on what
can be done. I take a silly pride in seeing that my machine is
Stealthed on all ports - noone outside can tell they're there<g>.

In case I'm sending you to a site you never heard of before, feel free
to Google it etc. first to see what if any "bad" things you can find.
You won't find much bad. No spam, no cookies they don't tell you about,
no forcing of anything onto your machine; perfectly safe web site. But
I know taking someone else's word for something like that can be folly
which is why I suggest checking it out yourself if you're not already
familiar with it. It's great for learning things about port usage.

HTH,

Twayne`



.



Relevant Pages

  • Re: Plausible reasons for http access?
    ... snip some important but volumous and onorous content...to free up your time while helping me.. ... provides transportation service - in this case, transporting packets. ... Many instances have different open 'ports' numbered anything but 80,110,25. ... I wonder though if Spybots utility has failed to differentiate a proxy port and an actual open ethernet-internet port and is telling me I have "open ports" but no tcp/ip packets are acknowledged unless specificaly allowed? ...
    (comp.security.misc)
  • Re: SMB File Sharing XP SP2
    ... i went straight to manually configuring my ports to allow file sharing ... > to manually configure the open ports. ... it's trying to automate ...
    (microsoft.public.windowsxp.general)
  • Re: Pentest - ISA server
    ... of them have over 50000 open ports. ... Tried to run fast-track using reverse connections but no luck. ... with that many ports open. ... ISA Server is a proxy firewall, so TCP port scanning ...
    (Pen-Test)
  • Re: Concerns about wording of man blackhole
    ... As open ports still show up as open I don't see the protection. ... What does this have to do with "blackhole". ... skillful intruders leapfrog around the firewall by abusing the HTTP CONNECT ...
    (freebsd-questions)
  • RE: ghostly mail ports
    ... In order to filter your incoming e-mail, NAV places itself between your ... Now normally the e-mail client connects ... to port 110 on the POP server. ... Subject: ghostly mail ports ...
    (Security-Basics)