My Auto update is set at 3:00am. it is now 1:30pm and I've been on my computer for hours. Up pops WXP update using port 1269. Is it normal for known trojan ports to be used for normal applications? I'm a newbe….please forgive. I have two or three known trojan ports popping up when I use netstat -a. Both UDP and TCP. Some are 1024, 1026, 1045, 1050, 1054, 1269, 1492. Am I just paranoid? :blink: <_<