Zone alarm pro is going nuts! What now?

ImTyping

Banned
Aug 6, 2001
777
0
0
WI
Whois Lookup of 24.156.142.211
Rogers@Home (NETBLK-ROGERS-6-BLOCK) ROGERS-6-BLOCK 24.156.0.0 - 24.157.255.255
Rogers@Home Hnsn (NETBLK-ON-ROG-3-2HNSN-9) ON-ROG-3-2HNSN-9
24.156.142.0 - 24.156.143.255

To single out one record, look it up with "!xxx", where xxx is the
handle, shown in parenthesis following the name, which comes first.

The ARIN Registration Services Host contains ONLY Internet
Network Information: Networks, ASN's, and related POC's.
Please use the whois server at rs.internic.net for DOMAIN related
Information and whois.nic.mil for NIPRNET Information.



The above information was obtained from the whois database of one of the Regional Internet Registries (ARIN, RIPE, or APNIC). This information contains administrative and contact information for a network provider that administers a large block of IP addresses, including 24.156.142.211. (Note: This information is probably not about the administrator of the specific computer at 24.156.142.211).

Please do not assume the people named in this report are the ones who are responsible for the alert you saw. If you are getting repeated alerts from IP addresses in the same IP block, however, this is a good place to find out who administers the network. If you have identified malicious or highly suspicious activity and have ruled out configuration errors, bugs, and other benign causes, you may wish to contact the network administrator to politely notify him or her of possible abuse of the network.

This IP addy is causing Zone Alarm to go off every 30 seconds or so...wtf are you supposed to do about that?
 

LoneWolf1

Golden Member
Jun 16, 2001
1,159
0
0
It could be that (s)he has a virus that is trying to replicate itself or possibly just a port scanner. As long as ZA is catching it and not letting it thru, I wouldn't worry too much about it. Just set your security settings to high and you should be all set.

BTW, what port(s) is it trying to get thru??
 

jacklutz

Senior member
Aug 13, 2001
605
0
0


<< So this is normal? >>



Yes. Your ISP will probably be sending some stuff at you, and there's always people scanning.