Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 22, 2010, 10:25:00 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373681
Posts
41474
Topics
94225
Members
Latest Member:
gmusgrave
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products & Services
Comodo Internet Security - CIS
Help - CIS
Firewall Help - CIS
Constant attempts to connect to svchost.exe
« previous
next »
Pages:
[
1
]
Author
Topic: Constant attempts to connect to svchost.exe (Read 896 times)
cheber
Newbie
Offline
Posts: 22
Constant attempts to connect to svchost.exe
«
on:
December 23, 2009, 08:40:30 PM »
Application: svchost.exe
Protocol: UDP
Destination Port: 56453 (always this port)
Over 170 000 connection attempts and counting, it's practically one attempt per second. I guess it's a botnet as the IPs are spread all over the world. What are they trying to achieve with this? Bruteforce? But what? I don't see much in the FTP log except maybe a couple times a day and they get blocked after 5 attempts anyway. Real VNC blocks after 3 attempts.
I got utorrent (port 54000), FTP server (port 21) and Real VNC server (port 5900) running 24/7.
«
Last Edit: December 23, 2009, 09:24:07 PM by cheber
»
Logged
rolo007
Newbie
Offline
Posts: 1
Re: Constant attempts to connect to svchost.exe
«
Reply #1 on:
December 26, 2009, 07:47:45 AM »
wish i could help.. however im getting an attempt per second..and i cant figure it out..and from the look of all the replies here it doesnt look like im going to find any direction any time soon. I think im going to go into the task manager and close processes 1 at a time to see if that might help. GOOD LUCK.
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 6380
Volunteer Moderator
Re: Constant attempts to connect to svchost.exe
«
Reply #2 on:
December 26, 2009, 02:16:49 PM »
Looks like it has to do with uTorrent, this will cause "incoming" traffic and it will probably be or have been listening on this port that shows up in your logging.
Can you check you uTorrent network settings and see how it's configured?
Maybe post a screenshot of it here...
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
and/or review the
Forum Policy - update 1st March 2010!
cheber
Newbie
Offline
Posts: 22
Re: Constant attempts to connect to svchost.exe
«
Reply #3 on:
December 27, 2009, 11:43:15 AM »
You might be right that it's an old utorrent port, I don't really remember what it was before. I changed the utorrent port because for some reason it got with conflict with TOR (though I don't run a relay anymore). But that was weeks ago. Between that I've had the server offline 3-4 days, though I guess it's possible I got the old IP adress from the DHCP server.
The utorrent settings are standard, only thing that's changed is the port.
I did a release and renew to get a new IP address and I thought that get rid of it, but it's still same "hammering" on port 56453. Though I guess it could yet again be an IP address I've already used with port 56453.
«
Last Edit: December 28, 2009, 06:06:17 PM by cheber
»
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 6380
Volunteer Moderator
Re: Constant attempts to connect to svchost.exe
«
Reply #4 on:
December 27, 2009, 11:57:34 AM »
You can create a block rule without logging on the global rules Network Security Policy so it' won't log the attempts anymore but still block it.
Block
In
UDP
Source Any
Source port Any
Destination Any
Destination port = 56453
And move it all the way up to the top so it's the very first rule on the Global Rules.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
and/or review the
Forum Policy - update 1st March 2010!
cheber
Newbie
Offline
Posts: 22
Re: Constant attempts to connect to svchost.exe
«
Reply #5 on:
December 28, 2009, 06:05:59 PM »
Ok, I might do that. Thanks.
But I was mostly curious why it happens. I knew already that clients will try to connect to old utorrent ports, but I didn't knew that would go on for weeks and even if you changed IP address.
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 6380
Volunteer Moderator
Re: Constant attempts to connect to svchost.exe
«
Reply #6 on:
December 29, 2009, 05:04:08 AM »
Well i have a system that's always on, an uTorrent on a single port, and even if i don't run uTorrent i get loads of hits on my port that's not active, i guess depending on how much you share(d) the more you get hits to that/those port(s)...
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
and/or review the
Forum Policy - update 1st March 2010!
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.07 seconds with 19 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com