Solved

Zone Alarm blocking access to svchost.exe

Posted on 2004-08-13
7
516 Views
Last Modified: 2006-11-17
Hello,

I get my internet from my university's network and I have just noticed that Zone Alarm keeps blocking continuous attempts to access svchost.exe from other users within my part of the network, and occasionally from network admin ips.

I'm thinking it's probably some normal function of the network, but I'm not sure. Does anyone know what it is?

Thank you :)
0
Comment
Question by:NorVegan
7 Comments
 
LVL 1

Expert Comment

by:mkgmkg
Comment Utility
Hi,

The Svchost.exe file is located in the %SystemRoot%\System32 folder. At startup, Svchost.exe checks the services part of the registry to construct a list of services that it must load. Multiple instances of Svchost.exe can run at the same time. Each Svchost.exe session can contain a grouping of services. Therefore, separate services can run, depending on how and where Svchost.exe is started. This grouping of services permits better control and easier debugging.

You should not allow svchost to listen for incoming connection requests. You really don't know who or what is trying to connect.  unless you know what is coming in, I'd block it.
All the programs that need internet access to function properly can initiate the contact from your computer so there is really no need to allow incoming connections to be accepted.
0
 
LVL 8

Expert Comment

by:cooljai1
Comment Utility
Mkgmkg is right, check the name properly. Is it svchost or SCVHOST?
If its scvhost, then thats a worm
http://www.kephyr.com/spywarescanner/library/scvhost.worm/index.phtml
Svchost could cause this issue if your system has been affected with the blaster worm.
So update your virus definitions and run a thorough virus scan on the system.
this link gives you some information about the worm
http://securityresponse.symantec.com/avcenter/venc/data/w32.welchia.worm.html
0
 

Author Comment

by:NorVegan
Comment Utility
I tried blocking it, but that blocked all traffic, so I opened it again. It still blocks those attempts, though. The two central servers are probably the ones I go through to get online, but I still don't see why it get so many hits from the other students' computers. Could it be poor network design, or is it normal that firwalls pick up traffic from other users on the same subnet?

Here's an example: "Medium rating, 2004/08/13 14:14:32+2:00 GMT, Program Access, svchost.exe, 129.240.***.***:3005 , Incoming (accept), Blocked, 1 count, bjs2-dhcp***.studby.***.no

It's not scvhost.exe. I doubt it is a virus.
0
How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

 
LVL 1

Expert Comment

by:mkgmkg
Comment Utility
I am using zonealarm and have confirmed from the programs list that
only three programs are configured to listen on Internet side ie MSn , Yahoo and generic host process.exe. Rest all programs including Svchost.exe are blocked from listening to Internet side and this configuration is working finr for me.

Hence , i will suggest you that you can try re-installing the zonealarm once again and not allow svchost.exe to laccept conccetion from internet.

This should solve the problem.


0
 

Author Comment

by:NorVegan
Comment Utility
But svchost.exe IS the generic host process executable.. I contacted the network admins, and although I couldn't get any clear and consise answers, one of them was thinking it might be machines infected with the DCOM/RPC exploit probing other machines on the network, and I think he might be right. One of them even stated he didn't have much knowledge of windows systems. I think this must be a podunk university when it comes to computer science. =D

Thanks for the reply, though.
0
 

Accepted Solution

by:
modulo earned 0 total points
Comment Utility
PAQed with points refunded (50)

modulo
Community Support Moderator
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Join & Write a Comment

Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now