Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 23, 2013, 07:29:10 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663726
Posts
70577
Topics
145219
Members
Latest Member:
bonky00
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
Help - CIS
Firewall Help - CIS
Need someone to analyze logs for me
« previous
next »
Pages:
[
1
]
Author
Topic: Need someone to analyze logs for me (Read 2581 times)
Cvette
Comodo Family Member
Offline
Posts: 62
Need someone to analyze logs for me
«
on:
April 23, 2010, 08:08:15 PM »
Hi there, lately I've been having a TON of alerts in my log, major network slowdowns, slow browsing...etc. If someone is willing, could you please analyze the log for me and let me know if there is anything I should do? Thanks!
Logged
COMODO Firewall 5 w/D+ and TM - Sandboxie - Norton DNS
futuretech
Comodo Family Member
Offline
Posts: 95
Re: Need someone to analyze logs for me
«
Reply #1 on:
April 25, 2010, 07:26:36 AM »
Sure, just post a screenshot of the firewall logs or export them and attache it to your post.
Logged
Cvette
Comodo Family Member
Offline
Posts: 62
Re: Need someone to analyze logs for me
«
Reply #2 on:
April 25, 2010, 06:37:57 PM »
Thanks a bunch!
ss1.gif
(42.98 KB, 788x544 - viewed 26 times.)
Logged
COMODO Firewall 5 w/D+ and TM - Sandboxie - Norton DNS
LordRayden
Newbie
Offline
Posts: 21
mess with the best, die like the rest
Re: Need someone to analyze logs for me
«
Reply #3 on:
April 26, 2010, 12:09:09 PM »
As far as I see, you are blocking your Windows Messenger from Broadcasting (port 1900), you are blocking the svchost.exe from getting to the Internet (port 80) which could be responsible for your Internet slowdown, and you are blocking ports 137 and 138 which are basically broadcasting, but could be a slowdown.
You can't generally block the system from getting to the Internet, especially not the svchost.exe cause you get major problems, which you have, you can switch to "Custom policy mode" so you can decide when the systems gets out and when not, for example no browser, Mail, P2P open, and the svchost want to go to the Internet, then you can block it (but don't hit the "remember" switch")...
Could be you blocked it by accident, happened to me. Let svchost.exe out, and if you are using the Messenger, let him out also. Important, the file Name is svchost.exe, this files is Ok, if the filename is svchosts.exe then it's a virus and shouldn't get out.
LordRayden
«
Last Edit: April 26, 2010, 12:12:49 PM by LordRayden
»
Logged
Cvette
Comodo Family Member
Offline
Posts: 62
Re: Need someone to analyze logs for me
«
Reply #4 on:
April 26, 2010, 01:27:37 PM »
Thank you!
Yes I did indeed block svchost a few weeks ago, I randomly received a pop-up from COMODO asking about it, a pop I have never received before so I blocked it to be safe. I'll check into the messenger too and make sure alls good.
Thanks again! You guys are great!
Logged
COMODO Firewall 5 w/D+ and TM - Sandboxie - Norton DNS
Cvette
Comodo Family Member
Offline
Posts: 62
Re: Need someone to analyze logs for me
«
Reply #5 on:
April 26, 2010, 09:59:15 PM »
Here's all that is left, I completely renewed my Firewall rules and made sure to allow Messenger and svchost.
ss3.gif
(37.12 KB, 834x435 - viewed 11 times.)
Logged
COMODO Firewall 5 w/D+ and TM - Sandboxie - Norton DNS
clockwork
Comodo's Hero
Offline
Posts: 1919
Oxygen requires Chuck Norris to live
Re: Need someone to analyze logs for me
«
Reply #6 on:
April 27, 2010, 02:14:41 AM »
i dont know, which operating system you are using.
but if you look for port 137 and 138 you will understand, why to block them is a really good idea. i just say netbios (what should be disabled itself!).
for the future: if you block something, make it "block and log". and when something slows down or doesnt work, just look in the log, which rule was fired.
i dont see a hint in your log about "svchost.exe".
choose firefox as "treat as a webbrowser" in comodo. IF svchost is necessary to connect (somehow), that you can use the internet, just allow the FEW adresses where it would want to connect to (i guess only local ones to the router, for example). make a windows update, and after that you know all the adresses. apart from them, svchost has NO need to connect to the INTERNET.
for example, i have blocked everything system related.... guess what, all is working fine. only windows updates wouldnt work while that.
you said yourself: "internet explorer is working". firefox isnt a system program. so, when firefox doesnt work, but IE does, then you shouldnt allow UN-needed system connections.
i guess, you just messed up the firefox rule. just mark "treat as a web browser".
MOST IMPORTANT: dont get used to allow "svchost" connections temporary on the fly. because one day there could be a "svchosts.exe tries to connect", and you will allow it by routine. fail.
make the least amount of necessary rules, and save them for the future. when one day a question comes, but all is working, you know that you dont need to allow that.
«
Last Edit: April 27, 2010, 02:19:28 AM by clockwork
»
Logged
"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.043 seconds with 22 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com