Forum Moderators: phranque

Message Too Old, No Replies

Attempt to access Generic Host Process

by someone in China

         

carfac

12:41 am on May 9, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Hi:

Not so much a webmaster question- this happened on my home computer. Figured this was about the best place for it..... sorry if I was wrong.

Anyway, I have Norton Internet Security on this machine as it is on DSL. I occasionally see the firewall tell me about "A remote system Attempt to access Generic Host Process for Win32 Services on my computer."

I never really thought too much about it- Norton claims there is no problem... but I always deny anyway.

Well, today, I checked into it. The"probe" (and that is what I think it is!) was from 218.91.243.198 which resolves to CHINANET jiangsu province network at APNIC.... now this does NOT seem like something I want on here.

And yet Norton recommends I allow this!

Any ideas what this might be?

Dave

grahamstewart

1:50 am on May 9, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Its difficult because Microsoft have bundled a bunch of different system services so that they all run as 'Generic Host Process'.

I use ZoneAlarm and it shows two 'Generic Host Process for Win32 Services' connected to the net all the time on my machine (WinXP Prof).

I think at least one of these is for DNS.

I allow them to act as server (i.e. accept incoming requests) but like you I am a little uneasy about it.

carfac

2:07 am on May 9, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Well, I cannot see ANY legitimate reason why someone would want to connect to my machine at all. So I will not allow it.

I used to think it was just my system checking in with the mothership at MS... I was VERY surprised to see the IP go back to Chiner.

I could maybe... MAYBE see allowing MS in, if it were worthwhile, but certianly not anyone else!

g1smd

10:48 am on May 9, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



While running a webcam website on May 7th, we had nearly 4000 connects from China. Quite a few of those were reqesting various .dll files, various parts of Microsoft Office and other such stuff. Quite a lot of hacking attempts, though none were successful as far as we can tell.