Greetings Doctor
Those were actual intrusion alerts from NIS. I hace received these types of intrusion alerts before. As with your configuration setting ports to monitor. This normally happens when LW has not been started yet. My best guess is they are hosts who have direct connected to you. And as soon as you connect to the internet they try and reconnect before you have started LW. Therefore NIS catches and blocks them until you select block or permit. I block all of them until I start LW. Then they can connect once LW is started.
If you have any questions whether your NIS firewall is configured properly to allow LW full access see the images below. If you have doubts you can click on limewire then click remove. This should be done while LimeWire is closed/not running. You can then restart LW and a window from NIS will popup and ask what you want to do. Select Permit. This imagine is of NIS 2004.
Thank you for the help with the images LOTR