I think that Comodo should be a plan for svchost processes in the firewall. Unfortunately now there is no monitoring on svchost by firewall. It is protected only by AV and D+. But if the infection it, can easily pass the firewall, Without any monitoring by the firewall.