I recently did a Windows Vista update which included SP1, and I noticed that the Comodo Active Connections window initially showed some of the Microsoft IP addresses that my svchost.exe connected to, but then the Active Connections window did not show any connections at all for much of the update and until it completed. Could this be because I have a rule that designates svchost as outgoing only, and I think during the update I may have had it set as UDP only. However, if Windows can only do an update if svchost is set to allow TCP + UDP why did the update continue and, more importantly, why did my PC continue to download the update while showing "no connections" in the Active Connections window?
Also, I have been unable to log in to my Comodo account on my home PC - I can log in, but I get put to the home screen of Comodo forums and am unable to move to CIS firewall help or any where else without it unlogging me from my account and asking me to enter my account credentials again. This makes it impossible for me to post or to view screenshots. But, I can login from a computer different from my home computer ( as I am doing now). Is there a way to contact tech support?
Thanks.
When installing an update it will download first and process afterwards. It makes sense not to see internet activity when the actual update is being deployed.
the only and I think during the update I may have had it set as UDP only. However, if Windows can only do an update if svchost is set to allow TCP + UDP why did the update continue and, more importantly, why did my PC continue to download the update while showing "no connections" in the Active Connections window?Here applies also what I wrote in the above. Once the files are downloaded the actual installation of the update begins. There is most likely no internet traffic then.
I am not sure what you mean with having set svchost.exe to UDP only.
Also, I have been unable to log in to my Comodo account on my home PC - I can log in, but I get put to the home screen of Comodo forums and am unable to move to CIS firewall help or any where else without it unlogging me from my account and asking me to enter my account credentials again. This makes it impossible for me to post or to view screenshots. But, I can login from a computer different from my home computer ( as I am doing now). Is there a way to contact tech support? Thanks.This may be a browser related issue. Try cleaning cache and cookies and restart your browser. Does that help?
Thanks Eric,
I made some changes to Firefox which resolved the Logon issue. But, I should have been more specific in my description of the issue I was having with not seeing any connections at all in the Active Connections window - this was while Firefox was downloading the file (I could see the percentage of file downloaded increase, but no connections in Active Connections). Thus, I worry that svchost or other programs can connect without me knowing about it. What would cause this problem?
Not seeing connections at all in View Active Connections that is not right. Start with running Diagnostics under Miscellaneous. Let it fix when it wants to and let us know what it reports.
What other security programs do yo have running in the background? Try disabling them and see if that helps. When it helps enable them one by one until you find the one that breaks View Active Connections.
At the moment, I do not have any other security software other than Avast Avtivirus; I can try disabling it and doing a windows update, although I suspect that a conflict with Avast is not the problem. I downloaded Windows SP2 today while running Wireshark and having the Comodo Active Connections window open at the same time, and the download exhibited the same unusual behavior of showing connections to Microsoft IP's for the beginning of the download, but then all connections disappeared from both Wireshark and the Active Connections window (the connections disappeared with 14% of file downloaded and I saw no connections throughout the remainder of the file download). The real question is - What would potentially cause this? Could it be a change to the registry that is trying to hide svchost connections from monitoring software like Wireshark, Comodo? Or, is there something I am missing? It may be worth noting that I have a firewall Application Rule for svchost.exe that Allows all outgoing TCP and UDP, and I have been seeing ICMP pings from my modem to my PC being blocked.
Are you sure it is the file download progress bar you are looking at? I am asking because Active Connections and Wireshark behave the same way. Did the update to SP1 succeed?
How did you download the SP2? Did you get it using Windows Update or did you download the off line installer?
I am sure it was the file download window that I was looking at, this is the download window that Firefox provides, and I watched the download percentage increase while there were no connections showing in either Wireshark or Comodo. I observed this behavior during the download of SP1 which is why I ran Wireshark and Active Connections during the download of SP2 and I closely watched the entire download while checking Wireshark and Comodo - and, as I said before there were no connections at all for the majority of the download.
I used Windows update to download; however windows automatic update is disabled on my PC, so when I do an update I manually go into windows update and click on "Check for updates to your computer." At any rate, if there is a connection it should be seen, which puts us back to the question of what would cause this?
Do you have any other security or network related programs running in the background that may interfere? Try disabling them and see what happens.
I do not have any other security or network programs running in the background. It seems to me, the only cause for this unusual behavior exhibited in both Comodo and Wireshark would be a manipulation of the operating system that would allow transparent internet connections that could not be detected by said monitoring programs. I don't know what else it could be. Any thoughts?
The only thing I can think right now would be to thoroughly scan your computer using What to do if you’re infected - eXPerience Rev.3 .
Then do a rootkit scan with Gmer rootkist scanner to see if there are hidden programs on your system. You can get it here: http://www.gmer.net/ .