ISP question

Posted on 2006-07-05
Medium Priority
Last Modified: 2010-03-17

We recently have been alerted by our isp that we have a port scanning worm in our system and so they set up a filter to shut off our internet access until we remove it from our network so it won't affect their network.  Problem is we have sophos enterprise for our antivirus and we are clean so far and yet they still insist we have a virus of some type.  Problem is that by shutting off internet access, we can't ge email and our vpn is down.  It seems harsh to turn off internet access for this since one of the first steps in fixing virus outbreak is to go out to internet and get latest ides or check website of existing antivirus vendor so disinfection instructions can be obtained but without internet this is not possible.  If everyone who got a virus all over the world got their internet access shut off, nobody would be able to recover unless they could use sytem restore in xp but even this is hit or miss.  My question is does anyone know if this is getter more common these days to filter a company's internet access when a possible infection is detected or is the isp we have using too stringent a system?  Spoke to their tech support and they agreed it is difficult to fix a virus infection when internet access is shut down yet nobody wants to take responsibility there and they all said they do it to protect their network not ours.  At least a virus is free while we are paying them to give us downtime.  Thinking of getting another isp but for time being we need internet to be turned on so getting new isp will still take time so currently we are at their mercy.  Any ideas?  How do we check for port scanning activity on our netscreen firewalls?  Thanks.
Question by:eservando

Accepted Solution

imacgouf earned 400 total points
ID: 17048138

Did the ISP show you any report or log to show you that such activity is happening.

Here is one article
Port scans may not always signal attacks, research indicates
A study found little correlation between port scanning and network attacks

Here  in the link below shows the type of ports and tools which may help you in your quest
Network Security Auditing / Monitoring Tools

LVL 14

Assisted Solution

ECNSSMT earned 400 total points
ID: 17055979
well weekend is fast approaching; it may give you some time to do some investigating.  Haven't used netscreen; but if you've used either etherpeek or ethereal you can attempt to see which devices are sending out consistant traffic to various ports; the ones I've seen queries successive ports so you may see something like destination;; etc.  Once you locate those boxes; either try to clean them with an anti-virus product; or if your site uses images for your desktop and laptops; just reimage them.  Or if you can do that; just mark them and turn them off or remove them from the network so that they may be isolated away from the network.  Once you think you have that; contact the ISP and negotiate the reconnection of your internet.

I'm kinda wondering if they are bots or zombies....


Assisted Solution

Booda2us earned 400 total points
ID: 17056001
Hello eservando, Your ISP should provide you with information and support to solve this, since it was them that delivered the worm to you after all,(unless its proven to be internally activated). Like Imacgouf  mentioned, they should have some documentation, to assist you in hunting it down and ultimately killing it, or proving it's harmless..Like you said they've cut off access to updating your A-V, or diagnostic abilities, leaving you out in the cold. My ISP shut down some ports a few years ago during an attack  to stop proliferation of a worm or virus,(I don't remember which one), but it was only for a week or so until the fix could be distributed. We still had Internet acess though, I have never heard of a complete shutdown of service before. Make loud complaints....

Assisted Solution

contrlkaos earned 400 total points
ID: 17143893
I would just be rational with them.  Tell them you need to have them turn enable the connection while you're on the phone.  In that short period, go download AVG's Free AV, and update it.  Shouldn't take more than 2-3 minutes.  

Just be rational and be calm.  It goes along way trust me.

Assisted Solution

mbavisi earned 400 total points
ID: 17164614
Sounds to me like this ISP dont have a clue about what they are talking about. Ive never seen an ISP shut down a DSL connection just because they had a virus, if that was the case, half the internet would be shut down by now.


1)you were 'spamming' them with mail, or

2)someone on the internet must of complained they were getting problems from you IP

Tell your ISP you have fixed the problem and have bought a new PC.

Run windows in safe mode with networking, download ethereal.

Disconnect physically from the internet, restart your PC in normal mode, launch ethereal, look out for dodgy packets going to internet, kill processes in your task manager till this stops, or use 'msconfig' to restrict the programs that start up on launch.

Dont worry about your ISP, bypass them with that excuse earlier, most ISP tech support are dumb anyway.

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

    Over the past few years, small business and home owners have become so dependent on internet that a need for redundancy has arisen.    What happens when your small business or home / home office loses its internet connection?  The results c…
Sometimes you have to pull out old tricks to get a new firewall to work… While we were installing a new Sonicwall at a customers site we found that sites they were able to visit before were not working.  It seemed random and we could not understa…
Look below the covers at a subform control , and the form that is inside it. Explore properties and see how easy it is to aggregate, get statistics, and synchronize results for your data. A Microsoft Access subform is used to show relevant calcul…
Enter Foreign and Special Characters Enter characters you can't find on a keyboard using its ASCII code ... and learn how to make a handy reference for yourself using Excel ~ Use these codes in any Windows application! ... whether it is a Micr…
Suggested Courses

621 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question