avast Port Scanning

My firewall is reporting continuous (every day) attacks from avast website. Any information about this?

10:51:57
Attack Detection Report
Port Scanning has been detected from download3.avast.com (scanned ports:TCP (3558, 3557))

Hmm does this by change happens 6 times a day? I am thinking of the Avast update that takes place every 4 hours, well at least the checking for updates.

Well, what’s the reason for the attack?
My system control the updates, the time for it, checks if the server is on… Why the Incoming attack? ::slight_smile:

Do you use Pro version? And are you sure its inbound? I think this was explaind dew months ago. It was the common problem for Sygate firewall.

Technical, download3.avast.com is not, by any way, connecting to your machine. You can be confident about that…

I use Outpost Firewall.
That was a copy & paste information from it. I’m not trying to panic nobody :cry:

IMO it’s just a misinformation. If you get the very same message again, try running ‘netstat’ from commandline.

I think you’ll see something like
TCP yourip:3558 download03:80 somestatus
TCP yourip:3557 download03:80 somestatus

Let me know.

It’s not the first time when somebody reported such behaviour. I have to track if such users only use Outpost.

And let me state it again:
There is NO scanning software installed on ANY of our servers.

Port Scanning has been detected.....
If it really was port scanning, the one (whoever it is/was) wouldn't just scan 2 ports if you ask me. Strong indication of a false report by the firewall.

Kubecj, I’ll try to do what you asked me. Right now, the log was automatically empty and I can’t see it again. Sorry.

netstat -a -n might give a little more info

Well, it happens again :cry:

technical,
Have you had any luck determining what is happening with that “port scanning” poblem?

No, I haven’t.
I used the command: netstat -a -n
but I get nothing, no ports opened at that time, but, of course, the firewall have blocked them before.
Am I making something wrong? ::slight_smile:

Technical, if netstat doesn’t show any established connections (other than the expected ones for your browser etc) you are at least safe.

It could be ip spoofing, have you cleared out your temp internet files/cookies?

Also try from cmd ipconfig /flushdns

I recently switched to Outpost and don’t have any problems with Avast’s servers at all.
Edit

I noticed in an earlier post your screen shot. I use the free Outpost firewall and can’t find anything like that in my version, the blue shield might be the clue.

Technical, are you using the paid for version of Outpost firewall? It might be just that version that is causing you to see this information. I believe the free version of Outpost does not cause this problem as mentioned in the post above mine.

Yeah, I was geeting same reports before while I was using Pro version. Now, I’m on Freeware 1.0 version and all those reports are gone…

See one of my old threads in here:

http://forum.avast.com/index.php?board=1;action=display;threadid=5513;start=msg40611#msg40611

Also, there is screenshot…

Cheers !

Thought the blue shield was Kerio? It certainly isn’t here in Outpost ver 1 free version.

What blue shield ? I used to use Outpost Pro and back then I’ve got all those reports… Now I switched back to v1.0 (Freeware) and all those reports are nothing but history…

Cheers !

Sasha, many thanks… I’m not alone :cry:

Well, you are now… hehe… I’m not using Pro version any more… Freeware v 1.0 is as good as Pro, especailly combined with my hardware router/firewall - perfect combination.

Cheers !