ISP question

Posted on 2006-07-05
Last Modified: 2010-03-17

We recently have been alerted by our isp that we have a port scanning worm in our system and so they set up a filter to shut off our internet access until we remove it from our network so it won't affect their network.  Problem is we have sophos enterprise for our antivirus and we are clean so far and yet they still insist we have a virus of some type.  Problem is that by shutting off internet access, we can't ge email and our vpn is down.  It seems harsh to turn off internet access for this since one of the first steps in fixing virus outbreak is to go out to internet and get latest ides or check website of existing antivirus vendor so disinfection instructions can be obtained but without internet this is not possible.  If everyone who got a virus all over the world got their internet access shut off, nobody would be able to recover unless they could use sytem restore in xp but even this is hit or miss.  My question is does anyone know if this is getter more common these days to filter a company's internet access when a possible infection is detected or is the isp we have using too stringent a system?  Spoke to their tech support and they agreed it is difficult to fix a virus infection when internet access is shut down yet nobody wants to take responsibility there and they all said they do it to protect their network not ours.  At least a virus is free while we are paying them to give us downtime.  Thinking of getting another isp but for time being we need internet to be turned on so getting new isp will still take time so currently we are at their mercy.  Any ideas?  How do we check for port scanning activity on our netscreen firewalls?  Thanks.
Question by:eservando
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Accepted Solution

imacgouf earned 100 total points
ID: 17048138

Did the ISP show you any report or log to show you that such activity is happening.

Here is one article
Port scans may not always signal attacks, research indicates
A study found little correlation between port scanning and network attacks,10801,106849,00.html

Here  in the link below shows the type of ports and tools which may help you in your quest
Network Security Auditing / Monitoring Tools

LVL 14

Assisted Solution

ECNSSMT earned 100 total points
ID: 17055979
well weekend is fast approaching; it may give you some time to do some investigating.  Haven't used netscreen; but if you've used either etherpeek or ethereal you can attempt to see which devices are sending out consistant traffic to various ports; the ones I've seen queries successive ports so you may see something like destination;; etc.  Once you locate those boxes; either try to clean them with an anti-virus product; or if your site uses images for your desktop and laptops; just reimage them.  Or if you can do that; just mark them and turn them off or remove them from the network so that they may be isolated away from the network.  Once you think you have that; contact the ISP and negotiate the reconnection of your internet.

I'm kinda wondering if they are bots or zombies....


Assisted Solution

Booda2us earned 100 total points
ID: 17056001
Hello eservando, Your ISP should provide you with information and support to solve this, since it was them that delivered the worm to you after all,(unless its proven to be internally activated). Like Imacgouf  mentioned, they should have some documentation, to assist you in hunting it down and ultimately killing it, or proving it's harmless..Like you said they've cut off access to updating your A-V, or diagnostic abilities, leaving you out in the cold. My ISP shut down some ports a few years ago during an attack  to stop proliferation of a worm or virus,(I don't remember which one), but it was only for a week or so until the fix could be distributed. We still had Internet acess though, I have never heard of a complete shutdown of service before. Make loud complaints....

Assisted Solution

contrlkaos earned 100 total points
ID: 17143893
I would just be rational with them.  Tell them you need to have them turn enable the connection while you're on the phone.  In that short period, go download AVG's Free AV, and update it.  Shouldn't take more than 2-3 minutes.  

Just be rational and be calm.  It goes along way trust me.

Assisted Solution

mbavisi earned 100 total points
ID: 17164614
Sounds to me like this ISP dont have a clue about what they are talking about. Ive never seen an ISP shut down a DSL connection just because they had a virus, if that was the case, half the internet would be shut down by now.


1)you were 'spamming' them with mail, or

2)someone on the internet must of complained they were getting problems from you IP

Tell your ISP you have fixed the problem and have bought a new PC.

Run windows in safe mode with networking, download ethereal.

Disconnect physically from the internet, restart your PC in normal mode, launch ethereal, look out for dodgy packets going to internet, kill processes in your task manager till this stops, or use 'msconfig' to restrict the programs that start up on launch.

Dont worry about your ISP, bypass them with that excuse earlier, most ISP tech support are dumb anyway.

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Home Network Bandidth 3 158
Google Fiber Upload Speeds? 3 60
Brush face plates or proper sockets for cabling a house 4 73
RV325 Dual Wan Router with SBS2011 6 118
    Over the past few years, small business and home owners have become so dependent on internet that a need for redundancy has arisen.    What happens when your small business or home / home office loses its internet connection?  The results c…
Cable Modem Provisioning from DPoE compliant server  This Article is to support CMTS administrators to provide an overview of DOCSIS compliance configuration file, and to provision a cable modem located at customer place from a Back office serve…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question