General discussion

Good or Bad news?

A few days ago I received the message "Norton has detected a remote system that is attempting to access your computer"
It says - Path C:\Windows\System32\svchost.exe
File Name- Microsoft Generic Host Process for Win32
Direction - Inbound
Local address - All Local Network adaptors
Remote address -
Remote Port - 12442 Protocol - UDP
Do you want to BLOCK this or Allow this?

Today I received a similar message from
Remote address -
Remote Port - 3678

I've blocked both of these since I don't know who they are from.
Are these Good news or Bad news messages? Should I receive these messages or keep blocking them? Thanks!

Discussion is locked

Reply to: Good or Bad news?
PLEASE NOTE: Do not post advertisements, offensive materials, profanity, or personal attacks. Please remember to be considerate of other members. If you are new to the CNET Forums, please read our CNET Forums FAQ. All submitted content is subject to our Terms of Use.
Reporting: Good or Bad news?
This post has been flagged and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.
Sorry, there was a problem flagging this post. Please try again now or at a later time.
If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.
- Collapse -
You are safe

Firstly, your Norton firewall is doing it's job and protecting you from unauthorised access attempts into your computer, and you are safe.

You will get many such communications attempts, and this is what firewalls are meant to do. They block such attempts where they do not recognise why the attempt has been made. But such attempts are not necessarily nasty.

Your ISP will often ask for information from your computer to update it's records and these can be blocked safely without your connection suffering.

But there will be other sources seeking unprotected computers to hack and spy on the users, and so if your firewall asks you again, and you do not know why such an attempt has been made, you are right to be cautious and deny access.

If by blocking these two you have not seen any degradation in your internet performance then you did the right thing to say No and blocking them.

If you examine your Norton's firewall program, you may see options to limit alerts so that they don't show up all the time. The blocking of unauthorised access will still continue in the background, but you will not be pestered with alerts.

Then you can always check Norton's log every so often to see how many access attempts it has blocked.

I hope this helps.


- Collapse -
Automated port scans

Generally nothing to be worried about if you have all the latest Windows/IE patches installed. Of course don't go getting too cocky, because if an actual person starts knocking on your door, as opposed to an automated probe, there's not a single thing you're going to be able to do to keep them out.

Remember that security is an ongoing process, not just something you do once and never have to think about again.

- Collapse -

Sounds pretty bad to me

it could be many things...

A) runing P2P software?? dont, its suicide

B) look at every program in your processes list, if its unknown kill it, if nothing happen ( when you just receive a message) go to command prompt
then type: ping (ip adress) no brackets

C) Norton really sucks

Norton is gay

just keep blocking them

- Collapse -
Good News I think....

I got here and found your post due to the same situation. This link will tell you a bit more but not necessarily if it is something you should enable. Some posts I read in other areas associated negative things with this file in the same discussion, i.e. browser hijackers, spyware, etc.

Norton reccommends enabling and after the above link I am going to enable permanently, since it keeps coming up.

DO NOT FOLLOW BASED ON WHAT I AM DOING!!!! YOur guess might be as good (or bad) as mine... Just my decision.

Good luck and let me know if you find out anything further.


CNET Forums

Forum Info