Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hello gents,
I had viruses and other windows exploits in the past which has prompted me to take action such as blocking open ports and closing known ports used by trojans etc.
I use Norton Personal Firewall have recently configured BOTH system wide-settings and trojan horse settings to block ports 135, 139, 445, 1025, 1028 & 5000.
For a while the system looked secure backed-up with a good virus Scanner and the additional extras like Spyware Blaster, ad-aware etc. Despite this, I couldn't help but notice that surfing the web has become slower to retrive and view webpages. If I unblock the ports web pages load at the normal high speed.
How do I go about this one? Is it worth blocking these ports because legitimate programs also use them and it slows them down, or should I be safe rather than sorry?
Your views please.
Thank-You all.(Solarian you're welcome to answer this one too if you want, since you possess knowledge of such things :D)

Legitimate programs don't use those ports for web browsing. Keep them blocked or you will have worse problems especially with the symptoms you describe.
try CWShredder & see if it finds anything. Then try HiJackThis.

Sarge:
Long time, no post. 8-)
Seriously, the ports you listed are the most dangerous ones when left unprotected. Not having used Norton Personal Firewall, I can't explain why your web surfing has suffered a speed problem.
I keep all of my PC's ports stealthed (invisible), not just closed. I've never had a speed problem while surfing, and I've used all four of the most popular firewalls: Sygate, Agnitum, Zone Alarm, and Kerio. At the moment, I'm using Sygate.
Have you tested your firewall? If not, there are a couple of good online tests at:
www.grc.com
Look for ShieldsUp.
Another online test can be found at:
www.pcflank.com
Look for Advanced Port Scanner.
The tests won't help you with your speed issue, but they will determine your firewall's effectiveness.
I'm sure someone using Norton Personal Firewall will post and have a solution, or at least a suggestion, for you.
Best of luck, Solarian

Sarge:
Just read Response Number 1. If you do decide to post a HijackThis log, make sure to mention at the beginning that you've scanned your PC with both Spybot and Ad-Aware (it's a forum rule).
Your problem could very well be related to spyware--one of the first symptoms is browser performance.
Solarian

If your firewall is completely blocking port 113, instead of showing it closed, then that can cause some web sites to respond slowly. ZoneAlarm has special code to "handle" this ID port, and I would expect your firewall would too. Make sure you have not altered any default settings of your firewall for port 113. It is OK for it to show up as "Closed" on port tests.

Afternoon LADIES & Gents
Nice to hear from you again Solarian =D
I did as you said and went to grc.com and went to shields up, to do the online test, only to get the "This page cannot be displayed: cannot find server" error.
Also ran some tests at pcflank.com, the advanced port scanner tells me that ports 23, 135, 137, 138, 139, 1080, 1243, 3128, 12345, 12348, 27374 and 31337 are "closed", except for ports 21 & 80.
I've scanned my PC with Ad-aware and Spybot S&D and here's my Hijack-this log: -
Logfile of HijackThis v1.97.7
Scan saved at 13:52:05, on 20/11/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\spoolsv.exe
G:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
G:\Program Files\Norton Personal Firewall\NISUM.exe
G:\WINDOWS\System32\nvsvc32.exe
G:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
G:\Program Files\Norton Personal Firewall\NISSERV.exe
G:\Program Files\Norton Personal Firewall\SymProxySvc.exe
G:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
G:\WINDOWS\Explorer.exe
G:\PROGRA~1\POP-UP~1\dpps2.exe
G:\Program Files\Norton Personal Firewall\IAMAPP.exe
G:\Program Files\Winamp\Winampa.exe
G:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
G:\WINDOWS\System32\ctfmon.exe
G:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
G:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
G:\Program Files\Internet Explorer\IEXPLORE.exe
G:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Documents and Settings\ManUTD\Desktop\HijackThis.exeR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=:0
F2 - REG:system.ini: UserInit=G:\WINDOWS\System32\Userinit.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - G:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - G:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O4 - HKLM\..\Run: [Pop-Up Stopper] "G:\PROGRA~1\POP-UP~1\dpps2.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe G:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iamapp] G:\Program Files\Norton Personal Firewall\IAMAPP.exe
O4 - HKLM\..\Run: [WinampAgent] "G:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [WebScan] G:\PROGRA~1\ACCELE~1\ANTI-V~1\DEFSCA~1.exe -k
O4 - HKCU\..\Run: [siabcs] G:\Program Files\Steganos Internet Anonym 2\siabcs.exe
O4 - HKCU\..\Run: [Steam] G:\Program Files\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "G:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [CTFMON.EXE] G:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item:
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37944.7933449074
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabAs for port 113 it doesn't stae if it's closed or open Jack.
Thank-you ALL for your advice and assistance.
Hope to hear from you soon (yes you too Solarian). :D

Hi Guys,
I do not see anything suspicious in the log (though someone else might).
I have complained about NPF before. You seem to be having some of the problems I did. Norton also tended to "forget" some of my rules which had worked previously (and there was no virus).
I would disable norton and try the free version of Zone Alarm. If your problems dissappear, you know to get rid of Norton.

hello
the only thing i can see with why your d/ls are slower with is that your cpu is working a bit harder runing your fire wall with the ports blocked.not knowing what your cpu ram situation is.

My CPU speed is 1.2 Ghz, I have 256 MB Ram and I am currently using Norton Personal Firewall, (Considering the use of Zone Alarm Pro in the meantime).

Sarge:
Just an opinion from personal experience. There's no need to shell out $ for the Pro version of Zone Alarm--unless you want the extra bells and whistles.
The free version will completely stealth your computer.
Solarian

My intention was to use the free version, but upon testing it at pcflank.com, the results show exactly the same ports closed & open as with Norton Personal Firewall. I was hoping to stealth my computer like you mentioned. Maybe I haven't figured how exactly to stealth it. Thanx for your thoughts on that, will re-consider now :D

Are the sites loading faster without Norton?
I have zone alarm on my lesser-used pc. It is set to medium security in the internet zone and shows up as full stealth at grc (though I also have port 113 forwarded on my router).
I do not remember what other settings I changed and will not have access to it right now.

![]() |
trojanhorse downloader.wi...
|
need help with trojan.dow...
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |