svchost issues

I read alot about svchost issues but I can’t seem to fix my problem.
Every time I start up windows (XP) I get a list of CPF security warnings.
Mostly about svchost.exe saying that the parent application (system process) refuses communication with Comodo Firewall. In this security warning window there is no option to remember my choice!
The destination adresses are :
IP Listen Port : nbsess (139) - TCP
IP : 255.255.255 Port : nbname (137) - UDP
IP : 255.255.255 Port : bootp (67) - UDP

And sometimes, I don’t know if it’s related to the above, I completely lose my internet connection?

Can anybody tell me please how to fix this.

Can you please tell us about your CPF version + OS Version + Other Security software installed + network connection type

System should not be the parent of svchost.exe. It should be services.exe.

Egemen

I’m not at home at the moment but I use latest CPF version (2.3.5.62).
On windows XP Pro with NOD32 Antivirus on broadband connection.
In fact one (only one) of the security warnings mentions services.exe as parent.

And btw I use to Deny the action.

Can anybody please try to answer my question, because otherwise i’m afraid I have to remove Comodo Firewall, because this is way to annoying…

If you deny svchost.exe, where the parent is services.exe, then you will break Windows Update & maybe some other things as well.

As for the other svchost.exe, where System is the parent, messages… at this point, no idea. Any chance you can post some examples from CPFs log of these errors?

It’s probably best to export your CPF log into an HTML file & cut ‘n’ paste the entries in question from there.

In addition, when Egemen asked about your Net connection type… you said you had a broadband connection. You’ll need to expand on that (ADSL modem, router, etc…). The messages you posted (nbsess, nbname & bootp) can all be generated/needed by certain types of hardware (routers, etc…). Some of the messages might be explained if your XP system is currently set-up for file-sharing.

Well here’s the log file :
Comodo Firewall Logs

 	Date Created: 22:33:07 18-09-2006

Log Scope: Today
Date/Time :2006-09-18 17:58:18
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (svchost.exe)
Application: C:\WINDOWS\system32\svchost.exe
Parent: services.exe
Protocol: UDP Out
Destination: 207.46.130.100:ntp(123)
Details: The parent services.exe refuses communication with Comodo Firewall.
Date/Time :2006-09-18 17:58:18
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (svchost.exe)
Application: C:\WINDOWS\system32\svchost.exe
Parent: services.exe
Protocol: UDP Out
Destination: 207.46.232.189:ntp(123)
Details: The parent services.exe refuses communication with Comodo Firewall.
Date/Time :2006-09-18 17:58:18
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (svchost.exe)
Application: C:\WINDOWS\system32\svchost.exe
Parent: services.exe
Protocol: UDP Out
Destination: 255.255.255.255:bootp(67)
Details: The parent services.exe refuses communication with Comodo Firewall.
Date/Time :2006-09-18 17:57:57
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (svchost.exe)
Application: C:\WINDOWS\system32\svchost.exe
Parent: [System Process]
Protocol: TCP In
Destination: 0.0.0.0:nbsess(139)
Details: The parent [System Process] refuses communication with Comodo Firewall.

End of The Report

My connection type is an ADSL USB modem

If my XP system is currently set-up for file-sharing i don’t know…

OK, the first 2 are Clock Synchronization attempts (trying to make aure your time is correct) using NTP (Network Time Protocol) & both IPs were… Microsoft.

Details: The parent services.exe refuses communication with Comodo Firewall.

This is not so good.

The bootp (UDP 67) might be XP trying to talk to your ADSL USB modem (what’s the actual make of your modem?) or part of XP File Sharing… which given nbsess (TCP 139) is almost certainly active.

Before we go any further… I think you’re going to need to check both the Application & Component Monitors & tell me what you currently have set to blocked. This is the first step.

USB modem is ASUS brand Type AAM 6000 UG
Where can I set the file sharing in XP?

App & Comp Monitors both have nothing blocked!

Erm… this is based on memory alone (I don’t have access to an XP system)… something like… Start button > Settings > Control Panel > Network/Dial-up Connections (?) > right click the connection you use & select properties. Now, there should be a Network tab, click on it & find an entry that should say something like “File & Printer Sharing for Microsoft Networks”, uncheck it. OK, yes to whatever & close. You’ll need to drop your connection for this to work. You might even want a reboot, not sure about that.

App & Comp Monitors both have nothing blocked!

OK, worry about that later (unless someone else can jump in here?). In the mean time please answer the following questions…

Did CPF ever work correctly? If so, what happened around the time it stopped working?
Have you created any Zones?
Did you ask CPF to deny (remembered) anything?

I’m currently having a problem trying to research that ASUS modem… most of the pages that I can find are not in english, which for me isn’t very useful & their google english translations are fairly awful.

btw file and printer sharing was disabled.

CPF started given me security warnings right from the start.
At first I allowed them, later on I found out that Denying didn’t affect my system.

I haven’t created any zones and off course I have instructed CPF to remember, but don’t ask me what is was …

And indeed the Asus modem seems to be a rather uncommon modem :frowning:

OK.

CPF started given me security warnings right from the start. At first I allowed them, later on I found out that Denying didn't affect my system.

Well, given your current situation, are you sure about that? :wink:

Also, if you did deny stuff… I wonder why you cannot see any of the remembered blocks in either the Application or Component Monitors?

I haven't created any zones and off course I have instructed CPF to remember, but don't ask me what is was ....

OK. But, what was it? (joking)

And indeed the Asus modem seems to be a rather uncommon modem :(

There is lots of stuff on them out there. But, it’s just not in english thats all. But, given the above, whilst there might be some slight configuration issues with the modem, I don’t think it’s the main cause of your woes. You’ve probably accidentally denied something important. I just don’t understand why you can’t see it in CPF.

Are you comfortable working with the registry? If not, the only other way out that I can think of is a un-install/install of CPF I’m afraid.

Or… wait until someone else on the forum has a better idea.

Some of our users reported in our Turkish forums that an unknown trojan modifying system services is causing this exact behavior. And CPF’s behavior analysis is constantly raising this alert.
They used Windows Worms Doors Cleaner 1.4.1 to verify and fix the issue. Please try to use it and let us know if your case is the same.

Egemen

I have used Worms Doors Cleaner 1.4.1.

DCOM is now disabled
RPC Locator is now disabled
and NetBIOS is disabled

UPNP and messenger were already disabled.

But still CPF keeps popping up the security warnings.

Otherwise I will do a re-install.

I have re-installed CPF but the problems remain.

I did however find out that allowing one of the security warnings closes the ADSL connection window (saying that the computer will be registered in the network) that otherwise sometimes stayed open (although connection was made).

Can you show us the screenshot of process explorer from www.sysinternals.com when you see this alert?

Thx,
Egemen

Voila this are the screenshots of process explorer

[attachment deleted by admin]

Any ideas???

I could not see anything wrong. You can select skip parent check option for svchost.exe to see if it solves the problem.

Egemen

Gonna try that …

This indeed solves my problems, but what about security? Does this setting impose any threat??