Re: Generic Host Process for Win32

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Twayne wrote:
Every so often, out of the blue, Zone Alarm pops up a message saying
"Generic Host Process for Win32 Services is trying to act as a
server", and sometimes it wants to accept connections from the
internet. The application is SVCHOST.EXE.
What is this thing, why does it appear at random times, and should I
allow it or deny it?
Thank you.

Hmm, that's unusual IME. I don't think it should be wanting to act
as a server.
Check your log files for ZA and see if you can tell who's running
it and what it's trying to do? It should be listed with a "blocked"
action since you denied it, or at least I hope you did, for now. It
seems completely wrong for svchost to want to act as a server.

svchost.exe is a service as it sounds, and you may have several of
them running, each one different. e.g. I have 5 running at this
moment, each one servicing something different.
Did you capitalize the name for clarity or was it capitalized in
the message?

What is your OS? Home or Pro?
What are you doing when that message pops up?
What is your level of computer expertise? e.g. novice, exp, very
exp, highly exp, etc.?

Then we could move on to more targeted responses unless someone
recognizes the issue and jumps in here first.

HTH
Twayne


The ZA log shows no source or destination IP. The direction is
incoming (accept) and the action is blocked. No source or destination
DNS. Capitalization was just for clarity.
Using Win XP Pro.
The message wanting to act as a server usually pops up during bootup.
I don't remember, but the other occurred either while browsing or
doing email, not sure.
I am an experienced computer user.

I think I allowed the request the first time it came up, and I denied
it after that. Didn't notice any effect either way. I'll deny from
now on. Thanks.

That could have been just a ping then, looking to find a computer online
and open to access or less likely, completely innocent. If you
highlight the ZA line there should be some info about it in the box at
the bottom of the window; might ID whether it was tcp/ip, icm, etc..
Since it only happens durng the boot process, it sounds like during
boot something is sending out a request and that might be the response
to it. The question is, what's sending out the request and should it be
doing it? I'd have a look at msconfig and System SErvices to start with
and see if there was anything there that shouldn't be.
What happens if you boot with the modem disconnected? Any error
messages on screen or errors in Event Viewer?
Might be time for AV and malware arsenal scans too.

Sorry not more help.

Twayne


.



Relevant Pages

  • Re: Generic Host Processor as server
    ... should be no need for the Generic Host Process to act as a "server." ... > 'Do you want to allow Generic Host Processor for Win32 ... what does it mean to 'act as server'?. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: User-Specific Settings
    ... MCSE, CCEA, Microsoft MVP - Terminal Server ... >> a clear statement from the vendor that running ACT! ... >> changes in settings are not preserved. ... >> Vera Noest ...
    (microsoft.public.win2000.termserv.apps)
  • Re: TalkTalk Broadband Problem
    ... the RiscPC podule slots anyway. ... The modem has five lights, left to right: Power, Link & ACT (these are ... Slot 1 UniPod 100baseT is ticked ... Primary name server: 192.168.1.1 ...
    (comp.sys.acorn.networking)
  • Re: Act 2009 on SBS2003 r2 Premium with Sql
    ... We upgraded from Act 7 to Act 10 this summer. ... We chose to put Act on another server other than our SBS 2003 server because Exchange likes to grab unused RAM and we felt this would impact Act. ... Microsoft Exchange Server 2003 sp2 ...
    (microsoft.public.windows.server.sbs)
  • Re: RDP Sessions not "disconnecting"
    ... and insists remotely loggin on to server verses ... his Desktop to hit these 3rd party apps (ACT, Quickbooks, etc.) when he's on ... RDP connection WITHOUT logging off. ... session there, or at least "disconnected" which i'm thinking uses up one of ...
    (microsoft.public.windows.server.sbs)