I'm not sure if this happens all the time, but I was going through my Mcafee settings and found the option to see all outbound, inbound, IDEs, etc. Being curious, I clicked on Inbound events only to see that I'm getting about 20 Inbound events every minute. Here's what the event detail says of one of them: A computer at xxx.xxx.xxx.xxx has attempted an unsolicited connection to TCP port 22349 on your computer. Now, about 99% of all the events show the same port - 22349. Very few of them show 1026, 1027, or 1028. I've done research on the latter three and it turns out that those ports are in fact very common among hack attempts. There has also been a few IPs constantly attempting to ICMP Ping me. Every now and then I see an event called Microsoft-SQL Server (or Monitor). Oh, and there are an extremely wide varieties of IPs that are logged in the events. Some are repeated multiple times. Like this one IP that keeps pinging me from the Middle Eastern/China area. I run virus scans twice a week using both Ad-aware and Mcafee, never picked anything up. However, I just ran a Malwarebyte scan and detected 2 files - but they were both registry changes from HJT (kind of weird). This post is getting a bit long, so I'll sum it up by asking: Do Inbound attempts happen all the time even if your system is clean?