Computer Forums

Go Back   Computer Forums > Software > Security Software

Security Software Protect your computer from internet nasties... firewalls, antivirus, and everything computer security related belongs here.

Register Now for FREE!
Computer Forums

Username: Password: Confirm Password: E-Mail: Confirm E-Mail:
Agree to forum rules 


Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-10-2007, 11:32 AM
New Member
 
Join Date: 18 Jan 2007
Location: Darwin Australia
Posts: 16
Nimshie29 is on a distinguished road
Default Firewall repeating block svchost.exe

Hi Guys just worked out how to post a new thread again - sorry for posting to old thread.
While Windows was updating my Zone Alarm blocked 14 of the following:
Description Generic Host Process for Win32 Services was blocked from accepting a connection from the Internet (10.0.0.138ort 1388).
Rating Medium
Date / Time 2007/10/10 19:51:00+9:00 GMT
Type Program Access
Program svchost.exe
Source IP 10.0.0.138:1388
Destination IP
Direction Incoming (accept)
Action Taken Blocked
Count 1
Source DNS SpeedTouch.lan
Destination DNS

About every 10 minutes it does the same thing. I have read info on web - some articles refer to a virus and others to a memory leak during downloading of updates. The above information mentions my Modem (Speedtouch). I use Anti Vir free anti-virus which works in conjunction with Zone alarm. Can anyone tell me what the significance of this block is please? Should I just click 'do not display again' I cannot understand why it keeps repeating the same attempt to access my program as there are not updates every 10 minutes. Should I check out the port adress? Any advice greatly appreciated. Regards, Nimshie29
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 10-10-2007, 06:49 PM
Thaylok's Avatar
Life is Weird, Embrace IT
 
Join Date: 06 Jun 2007
Location: Dallas Texas, USA
Posts: 548
Thaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond repute
Default

I've noted in the past that some Generic Host Processes (GHP) will need to get to the internet. I'm purely guessing but maybe the WGA uses GHP as it's route to phone home. I admit I'd have to research that avenue some more. In the past, I noticed that when I blocked GHP completely, very little of my OS worked at all, a lot of lock-ups would occur. Allowing it helped.

Being paranoid (err, I mean concerned), I like to see those messages, but depending on the frequency, you may very well want to "not show" that action. You may want to allow GHP for that good, but again, i don't like doing that.

Again, the Virus mentioned may very well be the WGA (Windows Genuine Advantage) software. I know that is how I see it. Don't know why Speedtouch will be trying to access the 'net, unless it has an updater for software you have installed there.

Not much help, but maybe anything is better than nothing. Some things are always easier seen/diagnosed hands-on, this is true with cars and computers.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 10-11-2007, 01:30 AM
New Member
 
Join Date: 18 Jan 2007
Location: Darwin Australia
Posts: 16
Nimshie29 is on a distinguished road
Default

Quote:
Originally Posted by Thaylok View Post
I've noted in the past that some Generic Host Processes (GHP) will need to get to the internet. I'm purely guessing but maybe the WGA uses GHP as it's route to phone home. I admit I'd have to research that avenue some more. In the past, I noticed that when I blocked GHP completely, very little of my OS worked at all, a lot of lock-ups would occur. Allowing it helped.

Being paranoid (err, I mean concerned), I like to see those messages, but depending on the frequency, you may very well want to "not show" that action. You may want to allow GHP for that good, but again, i don't like doing that.

Again, the Virus mentioned may very well be the WGA (Windows Genuine Advantage) software. I know that is how I see it. Don't know why Speedtouch will be trying to access the 'net, unless it has an updater for software you have installed there.

Not much help, but maybe anything is better than nothing. Some things are always easier seen/diagnosed hands-on, this is true with cars and computers.
Thanks very much for that Thaylok. I will keep looking bearing in mind what you have said.
Peace,
John Smith
________________________
This user added the following:
________________________
Quote:
Originally Posted by Nimshie29 View Post
Thanks very much for that Thaylok. I will keep looking bearing in mind what you have said.
Peace,
John Smith
Hi Thaylok, I had a look under the Zone Alarm forum and came up with this but I am not able to do what it suggests?

"svchost.exe

The prooper setting for Generic Host Process For Win32 Services in Zone alarm access in both zones and 'server' rights only the Trusted Zone. In case you don't
know svchost.exe is Generic Host Process For Win32 Searvices in your Zone Programs list. If after you set those pernissions you still see svchost.exe getting in you logs that is OK . You have granted the permissions needed"
I have included this under the Firewall heading but itwill not add to Programs in Zone Alarm ?
Will this post be visible to users generally as it may be of use to some?
Enjoy,
Nim

Last edited by Nimshie29; 10-11-2007 at 10:46 AM. Reason: Double Post
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 10-12-2007, 10:06 AM
New Member
 
Join Date: 18 Jan 2007
Location: Darwin Australia
Posts: 16
Nimshie29 is on a distinguished road
Default

Hi Guys, I entered MS Generic Host details in the Firewall Trusted Zone only and I have had no more block svchost.exe block pop ups. Looks like its fixed. hope someone else can use this and thanks for your interest Thaylok.
Enjoy,
Nim
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 10-12-2007, 01:47 PM
Thaylok's Avatar
Life is Weird, Embrace IT
 
Join Date: 06 Jun 2007
Location: Dallas Texas, USA
Posts: 548
Thaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond repute
Default

Great, glad you got it worked out. SVChost.exe is a very broad process. It usually encompases 16-20 sub processes, including *drum roll* Automatic Updates.
Again, glad you were able to get the proper settings.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 10-12-2007, 11:06 PM
Ultra_Man's Avatar
CompuForums Moderator
 
Join Date: 29 Aug 2006
Location: Missouri
Posts: 578
Ultra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud of
Default

The Svchost.exe file is located in the %SystemRoot%\System32 folder. At startup, Svchost.exe checks the services part of the registry to construct a list of services that it must load. Multiple instances of Svchost.exe can run at the same time. Each Svchost.exe session can contain a grouping of services. Therefore, separate services can run, depending on how and where Svchost.exe is started. This grouping of services permits better control and easier debugging.
__________________
Welcome to CompuForums

Please Read The Rules Before Posting

http://www.compuforums.org/announcem...post_message_1


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 10-13-2007, 11:45 AM
New Member
 
Join Date: 18 Jan 2007
Location: Darwin Australia
Posts: 16
Nimshie29 is on a distinguished road
Default

Thanks for your input and help Guys. Its easier doing it with support than on your own.
Thanks,
Nim
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 04:38 PM.



Powered by: vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Limited.
Content © Copyright 2005-2008 CompuForums. All Rights Reserved. Some content © Copyright of the respective owners.
Loan - Cheap Gas - Mortgage - Loans

Content Relevant URLs by vBSEO 3.2.0 RC5