Wikiposts
Search
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Ports being probed ?

Thread Tools
 
Search this Thread
 
Old 18th Mar 2011, 05:59
  #1 (permalink)  
TWT
Thread Starter
 
Join Date: Apr 2008
Location: troposphere
Posts: 831
Received 34 Likes on 19 Posts
Ports being probed ?

I run Malwarebytes with full time protection (paid version).Whenever I use my laptop with my 3G data USB stick,I see that Malwarebytes is quite active in blocking attempts to probe various ports.Svchost.exe always involved.

I looked at the logs and did a 'whois' on the blocked IP addresses and...every one of them originates in China.

The USB data stick is made in China by Huawei.Only occurs when the USB data stick is in use,never with my home ADSL or Wifi.

Just a co-incidence or maybe something more nefarious ?

Last edited by TWT; 18th Mar 2011 at 06:28.
TWT is offline  
Old 18th Mar 2011, 07:04
  #2 (permalink)  
 
Join Date: Jan 2008
Location: Bracknell, Berks, UK
Age: 52
Posts: 1,133
Likes: 0
Received 0 Likes on 0 Posts
It's nothing to do with the Huawei nature of your 3G dongle.

It's to do with you needing a firewall when you use it, as there's no NAT between you and the internet when you do. Ensure your PC uses a firewall at all times.
Mike-Bracknell is offline  
Old 18th Mar 2011, 08:08
  #3 (permalink)  
 
Join Date: Dec 2005
Location: Wellington,NZ
Age: 66
Posts: 1,678
Received 10 Likes on 4 Posts
Agree with MB.
You almost certainly do not have a firewall turned on. Have a look at this site.
Hit "proceed" at the bottom to test the effectiveness of the firewall. All ports, ideally, will appear as stealthed.
The Windows firewall is effective at this, provided there is no actual malware on the computer. It is not so good at controlling outbound applications.

Last edited by Tarq57; 18th Mar 2011 at 08:10. Reason: submitted before post finished.
Tarq57 is offline  
Old 18th Mar 2011, 08:55
  #4 (permalink)  
TWT
Thread Starter
 
Join Date: Apr 2008
Location: troposphere
Posts: 831
Received 34 Likes on 19 Posts
Thanks for your replies.I have a work issued laptop with W7.I have limited admin status,unit setup by IT at HQ.I checked and Windows firewall is enabled.I ran the GRC test,all ports tested and got a perfect 'Trustealth' rating for 1st 1056 ports.I used the USB data stick in question for this test (and am using it now).

Don't know if it's relevant,but MS Forefront Client Security is running on the machine.I have no priveleges to see what it's doing.All I can do is see a list of applied updates which are pushed out over VPN from HQ.

Interesting.
TWT is offline  
Old 18th Mar 2011, 09:15
  #5 (permalink)  
 
Join Date: Sep 2007
Location: Paris, France
Posts: 350
Likes: 0
Received 0 Likes on 0 Posts
Just a co-incidence or maybe something more nefarious?
Coincidence. There are mysterious sites in China that constantly probe every machine they can reach. I sometimes get hundreds or thousands of hits in an hour, and sometimes many attempts per day.

As long as you have a firewall, you're fine. If you don't have a firewall, you have a potential problem. If you're running just an ordinary desktop machine (not a server), you should have just about all incoming unsolicited traffic blocked.

The svchost.exe program is used to run all sorts of utility functions, including a number of essential network services, so it's not surprising or abnormal to see its name pop up in association with network activity.
AnthonyGA is offline  
Old 18th Mar 2011, 09:49
  #6 (permalink)  
 
Join Date: Jan 2008
Location: Bracknell, Berks, UK
Age: 52
Posts: 1,133
Likes: 0
Received 0 Likes on 0 Posts
Originally Posted by TWT
Thanks for your replies.I have a work issued laptop with W7.I have limited admin status,unit setup by IT at HQ.I checked and Windows firewall is enabled.I ran the GRC test,all ports tested and got a perfect 'Trustealth' rating for 1st 1056 ports.I used the USB data stick in question for this test (and am using it now).

Don't know if it's relevant,but MS Forefront Client Security is running on the machine.I have no priveleges to see what it's doing.All I can do is see a list of applied updates which are pushed out over VPN from HQ.

Interesting.
At which point i'd theorise that the Malwarebytes runtime is interacting with the firewall correctly and keeping these ports blocked whilst also monitoring them. The only thing it's doing wrong is giving you a small sense of worry.

You wouldn't get these same messages when connected to your broadband at home, as your home router does the firewalling function for you, hence none of those port scans ever reach your laptop for Malwarebytes to complain about them.

A pretty secure system there sir
Mike-Bracknell is offline  
Old 18th Mar 2011, 09:54
  #7 (permalink)  
TWT
Thread Starter
 
Join Date: Apr 2008
Location: troposphere
Posts: 831
Received 34 Likes on 19 Posts
Thanks everyone for giving me the benefit of your knowledge.Much appreciated.
TWT is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.