This keeps showing up in my online armor firewall logs

Discussion in 'other firewalls' started by Anth-Unit, Feb 12, 2012.

Thread Status:
Not open for further replies.
  1. Anth-Unit

    Anth-Unit Registered Member

    Joined:
    Oct 13, 2006
    Posts:
    108
    I came back to my computer after leaving it idle from some time and had an online armor notification that it had allowed outgoing icmp access to ping.exe. I had the firewall logs set to report block only so I don't know what it connected to, but I keep getting this notification pop up every couple of seconds. The color in the log file is green, which I assume means the connection was allowed, because blocked events typically show up as red. Any idea what it means? Here it is:


    [12/02/12 02:32:17] 3056/BF0 ICMP <- Destination unreachable(Network unreachable error) 192.168.1.114 60.53.203.50
    [12/02/12 02:32:17] 3056/BF0 Passed by ICMP rule
    [12/02/12 02:32:25] 3056/BF0 ICMP <- Destination unreachable(Network unreachable error) 192.168.1.114 60.53.203.50
    [12/02/12 02:32:25] 3056/BF0 Passed by ICMP rule
    [12/02/12 02:32:27] 3056/BF0 ICMP <- Destination unreachable(Network unreachable error) 192.168.1.114 60.53.203.50
    [12/02/12 02:32:27] 3056/BF0 Passed by ICMP rule
    [12/02/12 02:32:29] 3056/BF0 ICMP <- Destination unreachable(Network unreachable error) 192.168.1.114 60.53.203.50
    [12/02/12 02:32:29] 3056/BF0 Passed by ICMP rule
    [12/02/12 02:32:37] 3056/BF0 ICMP <- Destination unreachable(Network unreachable error) 192.168.1.114 60.53.203.50
    [12/02/12 02:32:37] 3056/BF0 Passed by ICMP rule
     
  2. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    1,734
  3. Anth-Unit

    Anth-Unit Registered Member

    Joined:
    Oct 13, 2006
    Posts:
    108
    So what would you do with this? I'm not sure how I would be infected with anything, or where it could've come from, because I'm pretty careful. I'm behind my router as well as online armor. Should I get a better firewall? Not really sure what I can do to stop someone like this, as a average user, beyond what I've already done.
     
  4. andrewf

    andrewf Registered Member

    Joined:
    Aug 26, 2010
    Posts:
    25
    Open Online Armor Configuration, go to "Firewall->ICMP" and untick "allowed" for appropriate ICMP rule ;)
     
  5. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    1,734
    that does not solve the problem - whois showed up the target network.
    i dont know if user operates in malysia - so its on his decision if he dont sit there.

    OA has some features for its usablity but i dont think that there is a server in malysia for that feature.

    so OA is formerly a firewall - OA Plus has additional antivirus.

    feel free to use avira rescue disk - or kaspersky - or...
    http://www.avira.com/en/support-download-avira-antivir-rescue-system
    http://support.kaspersky.com/viruses/rescuedisk

    burn ISO and boot from it.
     
  6. Anth-Unit

    Anth-Unit Registered Member

    Joined:
    Oct 13, 2006
    Posts:
    108

    I'll boot up the rescue disc when I get home. I'm not from malaysia, so this is very strange. I've already scanned my computer with Prevx, MSE, Kaspersky, MBAM. I don't see anything strange running either.

    -edit-

    I don't think the rescue discs would work. I'm using truecrypt full disc encryption.
     
Loading...
Thread Status:
Not open for further replies.