Welcome, Guest. Please login or register.
Did you miss your activation email?
May 22, 2013, 08:00:43 AM

Login with username, password and session length

663552 Posts
70553 Topics
153542 Members

Latest Member: grourcino

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Firewall Help - CIS
| | | | |-+  Disabling svchost sending to Akamai Technologies each logon
« previous next »
Pages: [1] Go Down Print
Author Topic: Disabling svchost sending to Akamai Technologies each logon  (Read 5104 times)
SilentMusic7
Comodo's Hero
*****
Offline Offline

Posts: 310


« on: April 09, 2012, 03:19:26 PM »

I need help in finding how to prevent svchost.exe from sending TCP to deploy.akamaitechnologies.com several times after each logon to my Win7 Professional PC.  Doing so will allow the Comodo firewall to block unauthorized Internet access by malware hiding behind svchost.exe.

I used the free app at systemexplorer.net to find lookup the URL given the IP address and to trace that the process ID for the sending instance of svchost.exe is the one hosting the Cryptographic service.  This instance of svchost.exe hosts no other services because I disabled the Workstation service.  I don't understand why the Cryptographic service is accessing the internet since I used gpedit.msc to enable "Restrict Internet communication" under \Computer Configuration\Administrative Templates\System\Internet Communication Management\.

I have the latest version of Comodo's Firewall installed (CIS 5.10).  I tried to block svchost.exe from outputting TCP to host name=deploy.akamaitechnologies.com and host name=akamaitechnologies.com, but Comodo's Firewall didn't block this.  The IP address varies with each logon, so I cannot block it based on the IP address.

I tried disabling the Cryptographic service, but Win7 forces its startup type to manual and starts it automatically at the next reboot.  I am hoping someone knows a Group Policy to turn off this internet access by svchost.exe.

More info about my configuration and experience:
https://forums.comodo.com/general-security-questions-and-comments/disabling-windows-internet-access-via-svchostexe-t70441.0.html;msg501001#msg501001
Logged
SilentMusic7
Comodo's Hero
*****
Offline Offline

Posts: 310


« Reply #1 on: April 09, 2012, 03:42:06 PM »

I forgot to mention that in \Control Panel\Programs and Features\Turn Windows features on or off\, I have disabled everything except Microsoft .NET Framework 3.5.1 (subfeatures are disabled) and Windows Fax and Scan.
Logged
Radaghast
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 4034



« Reply #2 on: April 09, 2012, 09:50:12 PM »

Akamai along with other content delivery networks, such as Level 3 are used by Microsoft and many others to facilitate various updates, including Windows and root certificate store updates. Whet you're seeing with the Cryptographic service is related to the latter. You can read more about the mechanics of certificate checks/updates here
Logged

“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 13180


Volunteer Moderator


« Reply #3 on: April 10, 2012, 09:56:42 AM »

It's probably using cryptic names, you can try to run this in a command-box and see if the IP shows up with a name:

ipconfig /displaydns
Logged

Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!
SilentMusic7
Comodo's Hero
*****
Offline Offline

Posts: 310


« Reply #4 on: April 10, 2012, 10:30:18 AM »

Akamai along with other content delivery networks, such as Level 3 are used by Microsoft and many others to facilitate various updates, including Windows and root certificate store updates. Whet you're seeing with the Cryptographic service is related to the latter. You can read more about the mechanics of certificate checks/updates here
I am familiar with the web page you mentioned.  It references this page, which has the instructions I followed for the "Restrict Internet communication" policy.  As seen on that page, the individual policies affected by this meta policy include "Turn off Automatic Root Certificates Update".  Therefore, there is some other feature of the Cryptographic service that is accessing the internet.  What could it be?
Logged
SilentMusic7
Comodo's Hero
*****
Offline Offline

Posts: 310


« Reply #5 on: April 10, 2012, 05:45:00 PM »

It's probably using cryptic names, you can try to run this in a command-box and see if the IP shows up with a name:

ipconfig /displaydns
Thanks so much Ronny.  I had to use a Cmd box with admin privileges and temporarily enable the DNS Client service for it to work, but your suggestion revealed that the host names that Win7 queries are crl.microsoft.com and crl.globalsign.net.  Using these host names, the Comodo firewall successfully blocked these internet accesses.

Searching the internet for crl.microsoft.com, I learned that these queries are updates to the certificate revocation list:
http://social.technet.microsoft.com/wiki/contents/articles/964.aspx
I found this page showing how to prevent Win7 from making these queries:
http://social.msdn.microsoft.com/forums/en-US/vsto/thread/a8bdbafb-383b-4896-966b-cce5ffd88993/
This eliminates the need for the firewall to block them.

Mystery solved.  Thanks to the Comodo forum members!
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 13180


Volunteer Moderator


« Reply #6 on: April 11, 2012, 09:06:25 AM »

Your welcome.
Logged

Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!
pazsion
Comodo Loves me
****
Offline Offline

Posts: 131


« Reply #7 on: April 23, 2012, 04:53:36 AM »

unless your paranoid like me and only want to update these kinds of things when i choose to. Not at windows start or end. Previous expereinces tells me to watch such things closely.
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.045 seconds with 23 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com