Can anyone please advise if this could be above board ? I have used SA for a while because I thought theirs was a good idea. McAfee took over and each day SA would show on Curr Ports for a few minutes - presumably updating. Yesterday and today that changed on Curr Ports, it showed up as 216.143.70.73 and something called Pla-sadownload.mca bombarding my machine for a couple of hours on both days. I typed the IP addy. into Google and it took me to McAfee's web site. Are any other SA users experiencing this ? Kind Regards.