Welcome, Guest. Please login or register.
August 21, 2008, 09:34:38 AM

Login with username, password and session length

184898 Posts
21467 Topics
52061 Members

Latest Member: gafanhoto-san

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Help for v3
| | | |-+  Windows Operating System / System Idle Process in Logs [Merged Threads]
« previous next »
Pages: [1] 2 3 ... 19 Go Down Print
Author Topic: Windows Operating System / System Idle Process in Logs [Merged Threads]  (Read 13887 times)
Bros
Newbie
*
Offline Offline

Posts: 23


« on: November 20, 2007, 04:13:05 PM »

I recently installed comodo firewall 3 and while looking through the new gui i suddenly notice a lot of connection blocked i check the log and its all a bunch of incoming tcp from seemingly random ip's for system idle proccess
what can this be?

Additional Information:
comodo firewall version:3.0.1
os: windows xp sp2
internet: adsl shared through home lan
other secuirty program: avast antivirus 4.7.1074
permissions level: admin
« Last Edit: November 23, 2007, 10:18:23 PM by Soyabeaner » Logged
Goose18
Comodo's Hero
*****
Offline Offline

Posts: 1083



« Reply #1 on: November 20, 2007, 04:53:49 PM »

I also am getting around 100 of these alerts too.. wonder if anyone knows why?
Logged

Avast! 4.8, BOClean, CFP3 and did i mention Avast! 4.8 Grin  OH guess what!!! Avast! 4.8 Grin


System Specs:  Pentium 4 with HT 3.06 Ghz,  1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB
Soyabeaner
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6863


Akagi


« Reply #2 on: November 20, 2007, 04:57:14 PM »

I got them as well, but I disabled the logging on it Smiley.  Depending on how you set your rules (I shouldn't have picked expert on everything Cry), the application rules now have the ability to log blocked connection attempts.
Logged
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #3 on: November 21, 2007, 01:40:46 AM »

Don't remember seeing this in Beta, but I'm getting a lot of blocked inbound connection from various IP's to SIP. Any thoughts?
« Last Edit: December 20, 2007, 10:46:53 AM by Japo » Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3641


I'm not grumpy, just misunderstood.


« Reply #4 on: November 21, 2007, 02:38:16 AM »

Really? I've always had blocks against System Idle in probably every release. Although Egemen might have said.. I'm vague on this. I've asked previously what it was, but I can't remember if I got an answer. It's not reference in the Help. I've assumed, up to now, that System Idle means "no associated process".. and/or maybe a Global Block. Smiley
Logged

XP Pro+SP3 and Vista Bus+SP1 with CFP 3.0.25.378 & AntiVir PE 8.1 & Firefox 3.0.1
__
Will computers ever be as smart as humans? Probably.. very, very briefly.
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #5 on: November 21, 2007, 02:43:56 AM »

Hi Kail, I guess the block does come under the Global Rule, but I'm curious as to what, exactly, it's doing. I've never seen this in any firewall I've used. Almost as soon as I logged on to the Net, I got inundated with these block events.

I've put Wireshark on the case, maybe it'll reveal something.
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
ocky
Comodo Loves me
****
Offline Offline

Posts: 110



« Reply #6 on: November 21, 2007, 06:20:35 AM »

Have just installed and am also seeing plenty System Idle Process blocks. Even testing at
Shields Up (via dial-up to bypass router), shows all the Shields Up source ports as SIP blocks.
Logged
shinobiteno
Comodo Family Member
***
Offline Offline

Posts: 54



« Reply #7 on: November 21, 2007, 07:16:48 AM »

AFAIK SIP is only required to be configured for tunneling and can be safely blocked for other things.
Always blocked it, since it always tried to make outbound DHCP calls to some unknown(for me) locations.
Logged

ahuramazda
Newbie
*
Offline Offline

Posts: 4


« Reply #8 on: November 21, 2007, 04:42:01 PM »

I'm also getting this "system Idle process" blocked in my log for version 3.   I've never seen it in any firewalls I've used either.  What does it do and what is it blocking?
Logged
AuraWolf
Newbie
*
Offline Offline

Posts: 6


« Reply #9 on: November 21, 2007, 05:04:43 PM »

I've noticed this as well.  The SIP from what I understand has to do with process' in your own computer, nothing with the internet.  Under Firewall-Advanced-Network Security Policy the system is outgoing only and blocks unmatching requests.  I don't know what it means but I, personally, don't think it's going to hurt the system.
Logged
AnotherOne
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 665


« Reply #10 on: November 21, 2007, 05:43:56 PM »

If you look at the TaskManager processes window, SIP is the process that nominally uses all the system resources that are not being used by other processes.  I think it is a RAM scavenger, picking up RAM from other processes as a housekeeping action.  I don't get the blocks on my system, but I have configured it for local and multicasting privileges.  The multicasting IP range is from 224.0.0.0 to 224.0.0.255 and 239.0.0.0 to 239.255.255.255 for local multicasting and 224.0.1.0 to 238.255.255.255 for Internet multicasting.  If you are seeing remote IP's not in the multicasting range, you should try stealthing your ports.  There is also the possibility of torrent servers polling your computer to see if it is available and probably others that I know nothing about.
Logged

What do you mean, my shoes are on the wrong feet???  These are the only feet I've got!
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #11 on: November 21, 2007, 06:07:40 PM »

'System Idle Processes' reflects the percentage of time your Processor has nothing to do, that's all.  Generally this value has a high value 90 plus.

I can see no reason why this process should be trying to connect to the Internet, as it's a local system process.

As I said the IPs  and ports it's attempting to connect to are totally random. I don't use P2P or IM... 

Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
gibran
Forum Member
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3321


Sometimes words are meaningless indeed...


« Reply #12 on: November 21, 2007, 07:32:48 PM »

What those entries look like?
Logged

Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #13 on: November 21, 2007, 08:13:11 PM »

Hi gibran, here's a couple.
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
ice
Newbie
*
Offline Offline

Posts: 4


« Reply #14 on: November 21, 2007, 08:15:49 PM »

I have the same problem like Toggie.
Logged
Tags: strange connection blocks lots of block system idle proccess strange block 
Pages: [1] 2 3 ... 19 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.238 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com