This keeps showing up in my online armor firewall logs

Discussion in 'other firewalls' started by Anth-Unit, Feb 12, 2012.

Thread Status:
Not open for further replies.
  1. Anth-Unit

    Anth-Unit Registered Member

    Joined:
    Oct 13, 2006
    Posts:
    108
    I came back to my computer after leaving it idle from some time and had an online armor notification that it had allowed outgoing icmp access to ping.exe. I had the firewall logs set to report block only so I don't know what it connected to, but I keep getting this notification pop up every couple of seconds. The color in the log file is green, which I assume means the connection was allowed, because blocked events typically show up as red. Any idea what it means? Here it is:


    [12/02/12 02:32:17] 3056/BF0 ICMP <- Destination unreachable(Network unreachable error) 192.168.1.114 60.53.203.50
    [12/02/12 02:32:17] 3056/BF0 Passed by ICMP rule
    [12/02/12 02:32:25] 3056/BF0 ICMP <- Destination unreachable(Network unreachable error) 192.168.1.114 60.53.203.50
    [12/02/12 02:32:25] 3056/BF0 Passed by ICMP rule
    [12/02/12 02:32:27] 3056/BF0 ICMP <- Destination unreachable(Network unreachable error) 192.168.1.114 60.53.203.50
    [12/02/12 02:32:27] 3056/BF0 Passed by ICMP rule
    [12/02/12 02:32:29] 3056/BF0 ICMP <- Destination unreachable(Network unreachable error) 192.168.1.114 60.53.203.50
    [12/02/12 02:32:29] 3056/BF0 Passed by ICMP rule
    [12/02/12 02:32:37] 3056/BF0 ICMP <- Destination unreachable(Network unreachable error) 192.168.1.114 60.53.203.50
    [12/02/12 02:32:37] 3056/BF0 Passed by ICMP rule
     
  2. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    2,735
  3. Anth-Unit

    Anth-Unit Registered Member

    Joined:
    Oct 13, 2006
    Posts:
    108
    So what would you do with this? I'm not sure how I would be infected with anything, or where it could've come from, because I'm pretty careful. I'm behind my router as well as online armor. Should I get a better firewall? Not really sure what I can do to stop someone like this, as a average user, beyond what I've already done.
     
  4. andrewf

    andrewf Registered Member

    Joined:
    Aug 26, 2010
    Posts:
    25
    Open Online Armor Configuration, go to "Firewall->ICMP" and untick "allowed" for appropriate ICMP rule ;)
     
  5. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    2,735
    that does not solve the problem - whois showed up the target network.
    i dont know if user operates in malysia - so its on his decision if he dont sit there.

    OA has some features for its usablity but i dont think that there is a server in malysia for that feature.

    so OA is formerly a firewall - OA Plus has additional antivirus.

    feel free to use avira rescue disk - or kaspersky - or...
    http://www.avira.com/en/support-download-avira-antivir-rescue-system
    http://support.kaspersky.com/viruses/rescuedisk

    burn ISO and boot from it.
     
  6. Anth-Unit

    Anth-Unit Registered Member

    Joined:
    Oct 13, 2006
    Posts:
    108

    I'll boot up the rescue disc when I get home. I'm not from malaysia, so this is very strange. I've already scanned my computer with Prevx, MSE, Kaspersky, MBAM. I don't see anything strange running either.

    -edit-

    I don't think the rescue discs would work. I'm using truecrypt full disc encryption.
     
Loading...
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.