Bo Berglund wrote:
> My Event log continuously fills up with failure audit events of this
> type:
>
> The Windows Firewall has detected an application listening for
> incoming traffic.
>
> Name: -
> Path: C:\WINDOWS\system32\lsass.exe
> Process identifier: 1312
> User account: SYSTEM
> User domain: NT AUTHORITY
> Service: Yes
> RPC server: No
> IP version: IPv4
> IP protocol: UDP
> Port number: 3562
> Allowed: No
> User notified: No
>
> The strange thing is that I am behind a firewall so Windows Firewall
> is set to OFF....
> How can Windows Firewall log events if it is OFF?????
>
> And how can I get rid of this nuisance?
> I am running a fully up to date Symantec Corporate antivirus on this
> PC.
http://www.eventid.net/display.asp?eventid=861&eventno=4615&source=Security&phase=1
--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html