Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Tag Cloud
access acer asus bios bsod computer crash desktop dns driver drivers error ethernet excel freeze gaming graphics hard drive hardware hdmi internet laptop malware memory monitor motherboard network printer problem ram registry repair router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Earthlink Firewall Alert "A Process"

Reply  
Thread Tools
GenXnyc's Avatar
Computer Specs
Junior Member with 1 posts.
 
Join Date: Aug 2007
Experience: Intermediate
25-Aug-2007, 06:18 PM #1
Earthlink Firewall Alert "A Process"
I keep getting Firewall alerts from Earthlink's Firewall about something that seems suspicious. It always says "A Process" is attempting communication. It is from different IP Addresses, but almost always says on port "0". In many cases, it seems there is a set of IP addresses it is coming from that are repeated regularly. I can't find any information on what "A Process" is. Because "A" is in CAPS I assume it is on a generic "A" as in "a process is attempting", but rather a phony name of a process.

I never had this happen using windows firewall and am not sure it is a problem because blocking it seems to have no effect and it appears even after running anti virus and anti spyware programs. I'm posting some of the Firewall log below and have removed my IP address from it. In particular the last IP address in the list shows up more than most, however no information comes up when searching it. Any info would be appreciated.

When I do a WHOIS search for the originating IP addresses they all come from Shaw Cable in Canada.

=========================================================
Time: 8/25/2007 4:44:17 PM
Event ID: 397223 User Response Deny

=========================================================
Time: 8/25/2007 4:46:40 PM
Default Action: Deny
Event ID: 400090
Application: N/A
Protocol: 1
Remote: 64.130.162.202:0
Local:
Traffic: Outbound
PID: 0

=========================================================
Time: 8/25/2007 4:47:40 PM
Event ID: 400090 User Response Deny

=========================================================
Time: 8/25/2007 4:50:31 PM
Default Action: Deny
Event ID: 403971
Application: N/A
Protocol: 1
Remote: 24.64.115.254:0
Local:
Traffic: Outbound
PID: 0

=========================================================
Time: 8/25/2007 4:51:31 PM
Event ID: 403971 User Response Deny

=========================================================
Time: 8/25/2007 4:57:51 PM
Default Action: Deny
Event ID: 410725
Application: N/A
Protocol: 1
Remote: 81.41.144.5:0
Local:
Traffic: Outbound
PID: 0

=========================================================
Time: 8/25/2007 4:58:51 PM
Event ID: 410725 User Response Deny

=========================================================
Time: 8/25/2007 4:59:12 PM
Default Action: Deny
Event ID: 412085
Application: N/A
Protocol: 1
Remote: 24.64.223.60:0
Local:
Traffic: Outbound
PID: 0

=========================================================
Time: 8/25/2007 5:00:12 PM
Event ID: 412085 User Response Deny

=========================================================
Time: 8/25/2007 5:02:03 PM
Default Action: Deny
Event ID: 415274
Application: N/A
Protocol: 1
Remote: 72.28.230.72:0
Local:
Traffic: Outbound
PID: 0

=========================================================
Time: 8/25/2007 5:03:03 PM
Event ID: 415274 User Response Deny

=========================================================
Time: 8/25/2007 5:03:17 PM
Default Action: Deny
Event ID: 416943
Application: N/A
Protocol: 1
Remote: 24.64.183.156:0
Local:
Traffic: Outbound
PID: 0

=========================================================
Time: 8/25/2007 5:04:18 PM
Event ID: 416943 User Response Deny

=========================================================
Time: 8/25/2007 5:04:49 PM
Default Action: Deny
Event ID: 418538
Application: N/A
Protocol: 0
Remote: 239.255.255.250:0
Local:
Traffic: Outbound
PID: 0
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 09:45 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.