Windows XP PRO Newbee Please help

G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

Everytime I restart my PC running Windows XP PRO SP2 I get a lot of these
event messages

Event Type: Failure Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 861
Date: 5/13/2005
Time: 8:40:07 PM
User: NT AUTHORITY\NETWORK SERVICE
Computer: TGKW001
Description:
The Windows Firewall has detected an application listening for incoming
traffic.

Name: -
Path: C:\WINDOWS\system32\svchost.exe
Process identifier: 908
User account: NETWORK SERVICE
User domain: NT AUTHORITY
Service: Yes
RPC server: No
IP version: IPv4
IP protocol: UDP
Port number: 1077
Allowed: No
User notified: No

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

It happens on several services at startup

First of all the Windows Firewall is not enabled I use McAfee's Firewall
program.

Any ideas

Thanks

Tom
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

> Description:
> The Windows Firewall has detected an application listening for incoming
> traffic.

>> First of all the Windows Firewall is not enabled I use McAfee's Firewall
>> program.
>>

Obviously, one of these statements is not correct. The SE log shows that
the Windows Firewall *is* on. Did you have the McAfee firewall running
when SP2 was installed or was it installed afterwards ?
You can ascertain whether the Windows Firewall is being loaded on
startup by opening the Services console and checking that the Startup
type has been set to Disabled.

MowGreen [MVP 2004-2005]
===============
*-343-* FDNY
Never Forgotten
===============

Thomas Grassi wrote:

> Everytime I restart my PC running Windows XP PRO SP2 I get a lot of these
> event messages
>
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Detailed Tracking
> Event ID: 861
> Date: 5/13/2005
> Time: 8:40:07 PM
> User: NT AUTHORITY\NETWORK SERVICE
> Computer: TGKW001
> Description:
> The Windows Firewall has detected an application listening for incoming
> traffic.
>
> Name: -
> Path: C:\WINDOWS\system32\svchost.exe
> Process identifier: 908
> User account: NETWORK SERVICE
> User domain: NT AUTHORITY
> Service: Yes
> RPC server: No
> IP version: IPv4
> IP protocol: UDP
> Port number: 1077
> Allowed: No
> User notified: No
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
> It happens on several services at startup
>
> First of all the Windows Firewall is not enabled I use McAfee's Firewall
> program.
>
> Any ideas
>
> Thanks
>
> Tom
>
>
 

drew

Distinguished
Apr 2, 2004
125
0
18,680
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

I have experienced the same thing. I have the Firewall disabled through GPO
by enabling the following setting
Computer Configuration / admin templates / network / network connections /
Prohibit use of Internet Connection Firewall on your DNS domain network

after the GPO is applied, all the firewall settings in the Security Center
are grayed out, and the current setting is set to "Off".

However, the Windows Firewall service is still started and running, and the
security logs still fill up with Event 861, like the earlier post mentioned.

Now what...

Thanks

"MowGreen [MVP]" wrote:

> > Description:
> > The Windows Firewall has detected an application listening for incoming
> > traffic.
>
> >> First of all the Windows Firewall is not enabled I use McAfee's Firewall
> >> program.
> >>
>
> Obviously, one of these statements is not correct. The SE log shows that
> the Windows Firewall *is* on. Did you have the McAfee firewall running
> when SP2 was installed or was it installed afterwards ?
> You can ascertain whether the Windows Firewall is being loaded on
> startup by opening the Services console and checking that the Startup
> type has been set to Disabled.
>
> MowGreen [MVP 2004-2005]
> ===============
> *-343-* FDNY
> Never Forgotten
> ===============
>
> Thomas Grassi wrote:
>
> > Everytime I restart my PC running Windows XP PRO SP2 I get a lot of these
> > event messages
> >
> > Event Type: Failure Audit
> > Event Source: Security
> > Event Category: Detailed Tracking
> > Event ID: 861
> > Date: 5/13/2005
> > Time: 8:40:07 PM
> > User: NT AUTHORITY\NETWORK SERVICE
> > Computer: TGKW001
> > Description:
> > The Windows Firewall has detected an application listening for incoming
> > traffic.
> >
> > Name: -
> > Path: C:\WINDOWS\system32\svchost.exe
> > Process identifier: 908
> > User account: NETWORK SERVICE
> > User domain: NT AUTHORITY
> > Service: Yes
> > RPC server: No
> > IP version: IPv4
> > IP protocol: UDP
> > Port number: 1077
> > Allowed: No
> > User notified: No
> >
> > For more information, see Help and Support Center at
> > http://go.microsoft.com/fwlink/events.asp.
> >
> > It happens on several services at startup
> >
> > First of all the Windows Firewall is not enabled I use McAfee's Firewall
> > program.
> >
> > Any ideas
> >
> > Thanks
> >
> > Tom
> >
> >
>