Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 29, 2009, 02:00:25 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
345900
Posts
38197
Topics
86769
Members
Latest Member:
GezusK
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archive Boards
Comodo Firewall
Help for v3
Windows Operating System / System Idle Process in Logs [Merged Threads]
« previous
next »
Pages:
[
1
]
2
3
...
19
Author
Topic: Windows Operating System / System Idle Process in Logs [Merged Threads] (Read 32006 times)
Bros
Comodo Member
Offline
Posts: 27
Windows Operating System / System Idle Process in Logs [Merged Threads]
«
on:
November 20, 2007, 04:13:05 PM »
I recently installed comodo firewall 3 and while looking through the new gui i suddenly notice a lot of connection blocked i check the log and its all a bunch of incoming tcp from seemingly random ip's for system idle proccess
what can this be?
Additional Information:
comodo firewall version:3.0.1
os: windows xp sp2
internet: adsl shared through home lan
other secuirty program: avast antivirus 4.7.1074
permissions level: admin
«
Last Edit: November 23, 2007, 10:18:23 PM by Soyabeaner
»
Logged
Goose19
Comodo's Hero
Offline
Posts: 1218
Re: HELP: Loads of strange connection blocks
«
Reply #1 on:
November 20, 2007, 04:53:49 PM »
I also am getting around 100 of these alerts too.. wonder if anyone knows why?
Logged
System Specs: Pentium 4 with HT 3.06 Ghz, 1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB DDR3
New Build: AMD Athlon 64 x2 6000 3.1 Ghz 4 Gb RAM 320GB WDC Hard Drive 650 watt quad rail Power supply(overkill
) 9500GT Hybrid SLi with 8200 (onboard video) Decent Gaming rig
Soyabeaner
Legendary
Global Moderator
Comodo's Hero
Offline
Posts: 7655
Re: HELP: Loads of strange connection blocks
«
Reply #2 on:
November 20, 2007, 04:57:14 PM »
I got them as well, but I disabled the logging on it
. Depending on how you set your rules (I shouldn't have picked expert on everything
), the application rules now have the ability to log blocked connection attempts.
Logged
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2731
Follow the White Rabbit...
Windows Operating System / System Idle Process in Logs [Merged Threads]
«
Reply #3 on:
November 21, 2007, 01:40:46 AM »
Don't remember seeing this in Beta, but I'm getting a lot of blocked inbound connection from various IP's to SIP. Any thoughts?
«
Last Edit: December 20, 2007, 10:46:53 AM by Japo
»
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 5325
I'm not a complete idiot, some bits are missing.
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #4 on:
November 21, 2007, 02:38:16 AM »
Really? I've always had blocks against System Idle in probably every release. Although Egemen might have said.. I'm vague on this. I've asked previously what it was, but I can't remember if I got an answer. It's not reference in the Help. I've assumed, up to now, that System Idle means "no associated process".. and/or maybe a Global Block.
Logged
Vista Business x32+SP2 with CIS 3.12 & Firefox 3.5 & Becky! 2.52
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2731
Follow the White Rabbit...
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #5 on:
November 21, 2007, 02:43:56 AM »
Hi Kail, I guess the block does come under the Global Rule, but I'm curious as to what, exactly, it's doing. I've never seen this in any firewall I've used. Almost as soon as I logged on to the Net, I got inundated with these block events.
I've put Wireshark on the case, maybe it'll reveal something.
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
ocky
Guest
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #6 on:
November 21, 2007, 06:20:35 AM »
Have just installed and am also seeing plenty System Idle Process blocks. Even testing at
Shields Up (via dial-up to bypass router), shows all the Shields Up source ports as SIP blocks.
Logged
shinobiteno
Comodo Family Member
Offline
Posts: 54
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #7 on:
November 21, 2007, 07:16:48 AM »
AFAIK SIP is only required to be configured for tunneling and can be safely blocked for other things.
Always blocked it, since it always tried to make outbound DHCP calls to some unknown(for me) locations.
Logged
Marvin Heemeyer - True Hero!
ahuramazda
Newbie
Offline
Posts: 4
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #8 on:
November 21, 2007, 04:42:01 PM »
I'm also getting this "system Idle process" blocked in my log for version 3. I've never seen it in any firewalls I've used either. What does it do and what is it blocking?
Logged
AuraWolf
Newbie
Offline
Posts: 6
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #9 on:
November 21, 2007, 05:04:43 PM »
I've noticed this as well. The SIP from what I understand has to do with process' in your own computer, nothing with the internet. Under Firewall-Advanced-Network Security Policy the system is outgoing only and blocks unmatching requests. I don't know what it means but I, personally, don't think it's going to hurt the system.
Logged
AnotherOne
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 712
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #10 on:
November 21, 2007, 05:43:56 PM »
If you look at the TaskManager processes window, SIP is the process that nominally uses all the system resources that are not being used by other processes. I think it is a RAM scavenger, picking up RAM from other processes as a housekeeping action. I don't get the blocks on my system, but I have configured it for local and multicasting privileges. The multicasting IP range is from 224.0.0.0 to 224.0.0.255 and 239.0.0.0 to 239.255.255.255 for local multicasting and 224.0.1.0 to 238.255.255.255 for Internet multicasting. If you are seeing remote IP's not in the multicasting range, you should try stealthing your ports. There is also the possibility of torrent servers polling your computer to see if it is available and probably others that I know nothing about.
Logged
What do you mean, my shoes are on the wrong feet??? These are the only feet I've got!
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2731
Follow the White Rabbit...
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #11 on:
November 21, 2007, 06:07:40 PM »
'System Idle Processes' reflects the percentage of time your Processor has nothing to do, that's all. Generally this value has a high value 90 plus.
I can see no reason why this process should be trying to connect to the Internet, as it's a local system process.
As I said the IPs and ports it's attempting to connect to are totally random. I don't use P2P or IM...
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #12 on:
November 21, 2007, 07:32:48 PM »
What those entries look like?
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2731
Follow the White Rabbit...
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #13 on:
November 21, 2007, 08:13:11 PM »
Hi gibran, here's a couple.
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
ice
Newbie
Offline
Posts: 4
Re: System Idle Process in Firewall Event Logs [Merged Threads]
«
Reply #14 on:
November 21, 2007, 08:15:49 PM »
I have the same problem like Toggie.
Logged
Tags:
strange connection
blocks
lots of block
system idle proccess
strange block
Pages:
[
1
]
2
3
...
19
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.04 seconds with 17 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com