New rules in firewall =2 new exe's in task manager?

Duis mollis, est non commodo luctus, nisi erat porttitor ligula, eget lacinia odio sem nec elit. Sed posuere consectetur est at lobortis. Vestibulum id ligula porta felis euismod semper. Donec ullamcorper nulla non metus auctor fringilla. Aenean lacinia bibendum nulla sed consectetur. Cras justo odio, dapibus ac facilisis in, egestas eget quam. Cras mattis consectetur purus sit amet fermentum. Morbi leo risus, porta ac consectetur ac, vestibulum at eros. Sed posuere consectetur est at lobortis. Etiam porta sem malesuada magna mollis euismod. Cum sociis natoque penatibus et magnis dis parturient montes, nascetur ridiculus mus. Duis mollis, est non commodo luctus, nisi erat porttitor ligula, eget lacinia odio sem nec elit. Cras justo odio, dapibus ac facilisis in, egestas eget quam. Aenean eu leo quam. Pellentesque ornare sem lacinia quam venenatis vestibulum. Curabitur blandit tempus porttitor. Sed posuere consectetur est at lobortis.

Hi All

In recent history and firewall activities these 2 new rules showed up

com surrogate outbound UDP port 53(dllhost.exe appeared with this in task manager)

mmc.exe 2 inbound connections on ports 1254 and 1255

also in the application logs(event viewer)you have com + system sent start control 9.26.25 pm

the distributed transaction coordinator service was sent a start control 9.26.28pm

And in the task manager msdtc.exe turned up and in the application log it reads

msdtc started with the following settings:security config(xxxxxxxx)

                                                                  network admin of transactions=

                                                                  network clients=

                                                                  inbound distributed transactions using native MSDTC protocol=

                                                                  outbound distributed transactions using native MSDTC protocol=

                                                                   transaction internet protocol(tip)=

and before this entry there was one by crypt32 which said it was by download.microsoft

can anyone explain what this means and how some thing other than me can send these services a start control?????Is there something going on that I should be worried about.Any insight would be greatly appreciated on this one.

Cheers Mo

 Do you think this might be linked to my other post about the flickering harddrive???sorry if its a bit confusing as I did not know how to write the info down.

 

Well if there are error messages, and it seems like it has to run as a Network Service, it is probably a process that requires access to the internet.

 

Yes it is normal. You terminated a Network Service process and now it is not running as a Network Service. 

 

 

Hi Tech0utsider

where did I terminate a network service process?All I know is I saw mmc.exe receiving 2 inbound connections to ports 1254/1255 as well as an outbound UDP by com surrogate.(I don't know why this would happen lack of knowledge on my part,I have looked up what they are but it does not make it any clearer to what has happened)Then In my event viewer the other things showed up and I suppose I would like to know what they are' did I instigate it somehow?or again its just the mystery of computers.And I suppose I'm still learning to trust NIS 2009 firewall knows what its doing.Thanks again for your input.Any other insights.

Cheers Mo

Hi Guys No thoughts on this?when I shut down last night after the msdtc entry there was this entry Userenv event ID 1517

windows saved user xxxxxxx registry while an application or service was still using the registry during log off....it then said something about a service running in the wrong account(user account) not as a network/local service??is this normal to occur especially when in the above post all that happened, as I'm assuming thru the firewall.

Ahhhh computers you gotta love em!!They keep me guessing.

Cheers Mo