Maybe this topic interests more people as this is the reason i place it.
I also is immediately an complain directed to autosurf sites and search portal sites.
I first tested this to be 100% sure that what i am about to say is true.
When i first looked to my logs from firewall i thought it was random "garbage" scans that where just an result of one of the many targetted ip adresses.
But then i discovered they are connected to visits to certain websites.
After i visit some sites (like search portals) i immediately get an scan and when testing the ip it comes from the same location.
Also the same happens when doing autosurfs but that is connected to the sites that are promoted there mostly not because of the autosurfs themselves.
I am very sure this will disturb many people but unfortunately it seems to be true and i first could not believe it myself.
Now i know the facts im continuing to see which sites this happens on and if this behaviour will keep going on the same way.
If you want to add something you seem to have experienced PM me your site and i will check and keep an eye on it.
Also you all might want to download or enable your firewall and block at least the next ports: 137 (known netbeui vulnerablity), 23 (telnet most likely will not be used so best to close), 79 finger (also best to completely shut this one down), best is to block anything between 135 to 139 (most secure anyway to not have things use that ports anymore)
As some more experienced people will see very fast these ports are the most common ones where an hack attempt could succeed so it really could jeperdise an person his or her's computer.
If you need more information you can search for it on google (just type port number and type port after that and you would most likely get an accurate document)