Generic Host Process for Win32 Services alert in Zone Alarm

Jul 27, 2004 8 Replies

In Message-ID: posted on Mon, 26 Jul 2004 21:00:42 GMT, Stu Wilson wrote: Begin

If you simply don't want to see the alerts, turn them off: [Alerts And Logs] - [Main] check the bottom (off) radio button. If you want to see where the application causing them is: [Program Control] look for the name the alerts are reporting, highlight it, and read the details in the pane below.

Sounds ok. You probably don't need Server trusted checked... Most important thing is to not give it internet server access..

Generic Host Process for Win32 Services alert in Zone Alarm open original image

I keep getting an alert that my ZA firewall has blocked Generic Host Process for Win32 Services from outgoing use of my computer. Can anyone tell me why this is happening and how I can safely stop this message from reoccurring?



Thanks



Stu


In Message-ID: posted on Mon,

26 Jul 2004 22:57:46 GMT, Stu Wilson wrote: Begin

Might be best to leave it alone in that case, providing that it's not some RAT using that name, but the fact that it wants to connect outbound raises suspicion. What's svchost is supposed to be, From the Microsoft knowledge base:

formatting link
it shouldn't, but might be, see the second paragraph here:
formatting link

Believe it could be one of several OS programs doing what the User has set ... i.e. time check, automatic update, etc.

reoccurring?

Under Zone Alarm program control for Generic Host Process in "access" trusted and internet are checked. Under "server" trusted is checked and internet is blocked. Is that proper?

reoccurring?

The file named is svchost.exe, part of the XP operating system.

As a follow up to my question above, The IP address listed on the Zone Alarm pop alert as being blocked going out from my computer is the same IP as one of three DNS servers listed for my computer when I ran ipconfig /all. Can anyone help explain what all this indicates?

Thanks

"Stu Wilson" wrote in news:X5zNc.98156$ snipped-for-privacy@twister.nyroc.rr.com:

It indicates nothing. It would be one thing if the contact was being made to a remote IP that was unknown to you. The contact is being made with an IP that belongs to your ISP's DNS server. Therefore, you know who it is and you should determine that it's not dubious in nature. -- let it go. All it is indicating is that App Control in PFW solutions is worthless with too many questions.

Duane :)

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required