LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices


Reply
  Search this Thread
Old 12-30-2009, 05:16 PM   #1
Billy Makk
Member
 
Registered: Dec 2009
Location: Kalamazoo, MI
Posts: 39

Rep: Reputation: 15
Question svchost trying to connect to net (blocked)


I have AVG internet security suite + firewall, running on Windows Vista.
My firewall keeps detecting and blocking svchost connection to a remote port, (unauthorized by me). While being glad that its being blocked, I still need to stop whatever is going on. I was reading that this might be the remnants of a w32.welchia.worm. The only info I could find on it was for WIN2000 and WINXP. When I am logged on to the net, it seems to continue trying to to make a connection to a remote IP, port 137 and 138, among a couple of other ports, and seems to be using alot of my CPU. Just today, (at a guess cuz I didnt want to count them all), there has been at least 50 blocked attempts to this remote IP. Can anyone tell me how to fix this, or where I might find the software required to rid my system of this problem?
I will appreciate your help.
Bill

Last edited by Billy Makk; 12-30-2009 at 06:16 PM. Reason: Better detailed info
 
Old 12-30-2009, 08:58 PM   #2
kbp
Senior Member
 
Registered: Aug 2009
Posts: 3,790

Rep: Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653
svchost is a generic service that many MS services use, just going by the ports it looks like it uses MS Networking (netbios) to communicate.

If you download Process Explorer from Sysinternals/MS you should be able to work out exactly which service it is and decide from there whether to allow or block it

cheers

(funny... I thought this was a Linux forum )
 
Old 12-31-2009, 09:09 AM   #3
Billy Makk
Member
 
Registered: Dec 2009
Location: Kalamazoo, MI
Posts: 39

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by kbp View Post
svchost is a generic service that many MS services use, just going by the ports it looks like it uses MS Networking (netbios) to communicate.

If you download Process Explorer from Sysinternals/MS you should be able to work out exactly which service it is and decide from there whether to allow or block it

cheers

(funny... I thought this was a Linux forum )
Yea, I know this is a Linux Forum. I've found that the users of LQ seem to have better knowledge than any other forum I've tried.
Thanks for your thoughts. I'll post what I can find out later.
Bill
 
Old 12-31-2009, 03:20 PM   #4
Billy Makk
Member
 
Registered: Dec 2009
Location: Kalamazoo, MI
Posts: 39

Original Poster
Rep: Reputation: 15
Thumbs up

Quote:
Originally Posted by kbp View Post
svchost is a generic service that many MS services use, just going by the ports it looks like it uses MS Networking (netbios) to communicate.

If you download Process Explorer from Sysinternals/MS you should be able to work out exactly which service it is and decide from there whether to allow or block it

cheers

(funny... I thought this was a Linux forum )
Thanks, I got it resolved. Turns out that these IP addresses are mostly MS updates. Odd that it says that they were outgoing connections being blocked.
Anyway, thx again and Happy New Year
Bill
 
Old 12-31-2009, 04:30 PM   #5
lleb
Senior Member
 
Registered: Dec 2005
Location: Florida
Distribution: CentOS/Fedora/Pop!_OS
Posts: 2,983

Rep: Reputation: 551Reputation: 551Reputation: 551Reputation: 551Reputation: 551Reputation: 551
yes your OS is sending a request to MS update servers to see if there is anything new it needs to download (automatic updates) to update the OS or any other MS product you have installed on that system. surprising that it is using port 137/139 as those (mentioned above) are known ports and a lot of firewalls block them as standard safety as not many home users or even business use nettbios any more as just about all LANs have moved to the much more robust TCP/IP stack.

the old netbui(sp?) is left over from the WINS servers of winNT 4 and older as well as part of Novel networks. I think even Novel networking is now TCP/IP, but i could be wrong there.
 
Old 01-01-2010, 02:43 PM   #6
Billy Makk
Member
 
Registered: Dec 2009
Location: Kalamazoo, MI
Posts: 39

Original Poster
Rep: Reputation: 15
Thumbs up

Quote:
Originally Posted by lleb View Post
yes your OS is sending a request to MS update servers to see if there is anything new it needs to download (automatic updates) to update the OS or any other MS product you have installed on that system. surprising that it is using port 137/139 as those (mentioned above) are known ports and a lot of firewalls block them as standard safety as not many home users or even business use nettbios any more as just about all LANs have moved to the much more robust TCP/IP stack.

the old netbui(sp?) is left over from the WINS servers of winNT 4 and older as well as part of Novel networks. I think even Novel networking is now TCP/IP, but i could be wrong there.
Thx. I just updated with MS service pack 2. That in itself seems to have greatly reduced my CPU usage.
Happy new yr
Bill
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
3 nics, connect to internet, share to local net, and connect to local net. Not workin linux-i386 Linux - Networking 2 09-15-2009 09:13 PM
Mod recent blocked related question (netfilter). WHO IS BLOCKED CarLost Linux - Security 6 07-29-2008 03:53 PM
Gaim Won't Connect Saying Connection Would Have Blocked! ejan Linux - Software 7 05-06-2007 08:56 AM
Windowx XP svchost.exe fifty General 1 09-29-2004 03:52 PM
i want to connect to icq .But my administrator has blocked it. s_diptiman Linux - Security 3 10-07-2003 07:06 AM

LinuxQuestions.org > Forums > Non-*NIX Forums > General

All times are GMT -5. The time now is 03:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration