PC Review


Reply
Thread Tools Rate Thread

How can I block access to a suspected hack on my local system netw

 
 
=?Utf-8?B?U3RldmUgQy4=?=
Guest
Posts: n/a
 
      26th Jan 2006
I used Zone Alarm security and suspect I inadvertantly allowed a malicious
login into my trust local network. The event log read:
Event Type: Warning
Event Source: WinMgmt
Event Category: None
Event ID: 5603
Date: 1/23/2006
Time: 12:18:12 AM
User: ZZTOP\SEC
Computer: ZZTOP
Description:
A provider, OffProv10, has been registered in the WMI namespace,
Root\MSAPPS10, but did not specify the HostingModel property. This provider
will be run using the LocalSystem account. This account is privileged and
the provider may cause a security violation if it does not correctly
impersonate user requests. Ensure that provider has been reviewed for
security behavior and update the HostingModel property of the provider
registration to an account with the least privileges possible for the
required functionality.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Thank you!

Steve

 
Reply With Quote
 
 
 
 
Wesley Vogel
Guest
Posts: n/a
 
      26th Jan 2006
OffProv10 is for Microsoft Office XP = Microsoft Word 2002 = 10

OFFPRV10.EXE is Office Data Provider for WBEM
C:\Program Files\Common Files\Microsoft Shared\MSInfo\OFFPRV10.EXE

OFFPRV10.DLL is Office Data Provider Proxy/Stub
C:\Program Files\Common Files\Microsoft Shared\MSInfo\OFFPRV10.DLL

Event ID 63 occurs when you run the Microsoft System Information program
from Office 2003
http://support.microsoft.com/default...scid=kb/891642

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In news:54E70A31-8875-43D5-81A4-(E-Mail Removed),
Steve C. <Steve C.@discussions.microsoft.com> hunted and pecked:
> I used Zone Alarm security and suspect I inadvertantly allowed a malicious
> login into my trust local network. The event log read:
> Event Type: Warning
> Event Source: WinMgmt
> Event Category: None
> Event ID: 5603
> Date: 1/23/2006
> Time: 12:18:12 AM
> User: ZZTOP\SEC
> Computer: ZZTOP
> Description:
> A provider, OffProv10, has been registered in the WMI namespace,
> Root\MSAPPS10, but did not specify the HostingModel property. This
> provider will be run using the LocalSystem account. This account is
> privileged and the provider may cause a security violation if it does not
> correctly impersonate user requests. Ensure that provider has been
> reviewed for security behavior and update the HostingModel property of
> the provider registration to an account with the least privileges
> possible for the required functionality.
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
> Thank you!
>
> Steve


 
Reply With Quote
 
=?Utf-8?B?U3RldmUgQy4=?=
Guest
Posts: n/a
 
      27th Jan 2006
Thank you Wesley!

"Wesley Vogel" wrote:

> OffProv10 is for Microsoft Office XP = Microsoft Word 2002 = 10
>
> OFFPRV10.EXE is Office Data Provider for WBEM
> C:\Program Files\Common Files\Microsoft Shared\MSInfo\OFFPRV10.EXE
>
> OFFPRV10.DLL is Office Data Provider Proxy/Stub
> C:\Program Files\Common Files\Microsoft Shared\MSInfo\OFFPRV10.DLL
>
> Event ID 63 occurs when you run the Microsoft System Information program
> from Office 2003
> http://support.microsoft.com/default...scid=kb/891642
>
> --
> Hope this helps. Let us know.
>
> Wes
> MS-MVP Windows Shell/User
>
> In news:54E70A31-8875-43D5-81A4-(E-Mail Removed),
> Steve C. <Steve C.@discussions.microsoft.com> hunted and pecked:
> > I used Zone Alarm security and suspect I inadvertantly allowed a malicious
> > login into my trust local network. The event log read:
> > Event Type: Warning
> > Event Source: WinMgmt
> > Event Category: None
> > Event ID: 5603
> > Date: 1/23/2006
> > Time: 12:18:12 AM
> > User: ZZTOP\SEC
> > Computer: ZZTOP
> > Description:
> > A provider, OffProv10, has been registered in the WMI namespace,
> > Root\MSAPPS10, but did not specify the HostingModel property. This
> > provider will be run using the LocalSystem account. This account is
> > privileged and the provider may cause a security violation if it does not
> > correctly impersonate user requests. Ensure that provider has been
> > reviewed for security behavior and update the HostingModel property of
> > the provider registration to an account with the least privileges
> > possible for the required functionality.
> >
> > For more information, see Help and Support Center at
> > http://go.microsoft.com/fwlink/events.asp.
> >
> > Thank you!
> >
> > Steve

>
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows Server 2000 cant access anything outside of the local netw VOS Microsoft Windows 2000 Networking 1 20th Jan 2009 11:10 PM
map local shared folder as a drive without being connected to netw =?Utf-8?B?Y2hhb3M=?= Windows XP Networking 2 16th Feb 2006 11:14 PM
July 4 Hack suspected =?Utf-8?B?TWlrZQ==?= Microsoft Windows 2000 1 29th Jun 2005 05:36 PM
Can I synchronize my local .pst file with one on my business netw. =?Utf-8?B?YmdyZWVu?= Microsoft Outlook Discussion 1 12th Jan 2005 03:33 PM
suspected attempted hack.. chameleon Windows XP Security 2 23rd Oct 2003 10:35 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 08:02 PM.