"Larry" <(E-Mail Removed)> wrote in message
news:93D64866-F3C5-4C4E-A159-(E-Mail Removed)...
> 0.0.0.0: followed by a port number was blocked by Zone Alarm. The full
> message:
> WINDOWS\system32\mmc.exe
> What is this?
The IP 0.0.0.0 is not very informative, so knowing the port number and
protocol from the message would be useful. DHCP is a possibility. 0.0.0.0
could perhaps be a spoofed source address, or it might be an attempt at a
network broadcast from certain devices. Some solutions use this IP to
represent an aggregation of multiple IP addresses causing a similar event,
but this doesn't sound like the case here.
--
kind regards,
Karl Levinson, CISSP, CCSA, MCSE [MS MVP]
--------------------------------
Microsoft Security FAQ:
http://securityadmin.info