What's new

Device Infected message in AI Protection means device protected rather than infected?

Marcus Yansen

Regular Contributor
Hi, I saw this on my asus router AI protection, and I also have skynet firewall running, does it mean my device is infected? I get the sense it means that my device was prevented from acting as part of a botnet instead? I can't find that local IP anymore, the one ending with with ".34". Are there any ways to make sure?



".34" ...
infectedd.png
 
Whatever it was (real of false positive) it's not there anymore and no AI was involved. It's AiProtection.
 
Are there any ways to make sure?
What device is using the 192.168.50.34 address? If a computer, do you have anti virus/anti malware program(s) installed on that computer? If so, run a update the software and scan the computer to see if it's been infected with anything. There are various programs that can be installed to a boot device (USB flash drive, CD disk, etc.) to boot the computer and scan for malware and viruses. But as others have indicated, what ever it was appears to have either disappeared, been resolved, or gone quite since Oct 2025.
 
Both external destination IP addresses are classified as “Suspicious IP” by CrowdSec’s Threat Intelligence because those addresses are known for SSH/HTTP brute force attacks.

One might wonder why a local device in your network is contacting those addresses (unless it was under attack by them?).
 
Of course the logs don't go far bag for me to tell - but i believe now that this was perhaps my less up to date laptop in power while away, as i mainly keep my main laptop up to date which i take with me. since that laptop isn't plugged in anymore, i will run a full scan on it next time - i believe the .34 address was for that device, but since the syslogs don't go far back enough i can't be 100% sure. Certainly no device right now or in my asus router syslog matches that ip. i appreciate everyone's help here - now i realize it may have been my less up to date laptop which somehow got infected when i was away, although i was running a firewall and an antivirus so hopefully those did something as well in terms of protection; but then it seems AI protection sees the device infection but i assume it blocked that outbound connection anyway; or maybe Skynet firewall in my router helped as well, who knows.

Yes it may have also been a false positive, who knows.

I did run a full AV scan and rootkins by several scanners on my current setup, nothing was found (but then again this computer was not even plugged in then).
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top