Hoping some one can help me here.
I keep my system pretty secure - XP Home fully updated, Zone Alarm Plus, Trend Micro's PC Cillin 2003 under corporate license, fully updated, regular sccans with Pest Patrol, Adaware and Spybot S&D.
Paranoid, you might say, but so far I have not been infected with any virus and MSBlaster didn't get me
Also, as part of my routine I regularly go to
www.grc.com and use his Shields Up port scan facility to make sure all is in order re the firewall. On my last visit but one all my service ports were stealthed and I was smugly satisfied that evildoers would have some difficulty getting into my system.
However in the last couple of days a Shields Up check reveals that Port 1024 is open. I don't know enough about this to be able to talk in depth, but as far as I can figure out from the info on the GRC pages, 1024 being open while I'm on broadband is a security risk. Port 135, which I believe controls access to port 1024, remains stealthed.
MSBlaster uses port 135 and I am concerned that an unsuccessful attempt by MSBlaster may have done this and I want to correct it.
I have searched for components of MSBlaster on my PC and I don't have them. My ISP told me that the trojans/adware progs Netspy, Latinus and Jade all use port 1024, but as far as I can tell I don't have those (Spybot and Pest Patrol scans come up clean.)
Questions:
Given that port 135 remains stealthed, should I be concerned?
Is there a prog or utility that I can run that will tell me which running program or process opens port 1024 on my PC?
How can I close the port? I followed the instructions for doing that in Zonealarm, but it made no difference. (Ie, Firewall | Main | Internet Zone Security | Custom then scroll down to the list of ports to block where there is a facility to add your own, which I did.)
Smugness gone, now a little uneasy
AA