Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of

Deckard's System Scanner v20070711.54 Run by Frank Khan on 2007-07-16 at 12:10:19 Computer is in Normal Mode. -- HijackThis (run as Frank Khan.exe) Logfile of Trend Micro HijackThis v2.0.2 Scan saved BTW all of MBAM's current dll and executable files, once installed, are also digitally signed and their hashes are verifiable on Virus Total FWIW - About an hour ago, I downloaded Yo he optado por bloquear los Puertos TCP y UDP de entrada de svchost.exe en las reglas avanzadas de COMODO siguiendo este consejo, pero no se si he hecho lo correcto. Tambien he visto que no ponen las IP del ordenador propio salvo en las TCP y UDP de entrada.

I also moved my svchost.exe rule below Comodo's generated Windows Updater rule.Now I am seeing all these tcp port 80 connections from svchost.exe being blocked. Sunday, February 03, 2013 1:57 PM Reply | Quote 0 Sign in to vote Do you have the same software running on both machines? up vote 5 down vote SysInternals Process Explorer can do this for you. If you choose to participate, the online survey will be presented to you when you leave the Technet Web site.Would you like to participate?

Esto en el Manual de mi cortafuegos no lo indica. I try to update the system using IE8 and firewall detects all the connections and I check the IP addresses and then the update is successful and ...

These port numbers thatsvchost.exe tries to get connected to are all unofficial, unassigned and not registered port numbers, like,svchost.exe doesn't try to get connected to port 80, 21, or 443

You should be able to trace the stack back to the DLL that implements the service. http://copyprotecteddvd.net/comodo-firewall/comodo-firewall-pro-ghost.html in your reply 0 khany Madrid - Spain Jul 2007 edited Jul 2007 Hi Peku006, Please find information you requested. Appears to me that WIN 7 is worse at crypic diali-outs that XP ever was.I wish Comodo would enhance the firewall to control process spawning like Sophos and WIN 7 firewall A case like this could easily cost hundreds of thousands of dollars.

I too am quite interested.I too endorse CurrPorts from NirSoft.net as sometimes it's a bit easier to trap an IP address that's elusive.

Accordingly, I don't think it has anything to do with Roadrunner.The however did resolve in TCPView's WhoIs to a Roadrunner backbone server in Caliifornia. Once the license accepted, reset to 100%. 0 khany Madrid - Spain Jul 2007 edited Jul 2007 Hello peku006, I have followed your instructions and the KAspersky scan says that I IMHO the IP addresses you mention have no known relationship with Malwarebyte's Content Delivery Networks.At some point you may wish to Wireshark trap/record the exchanges you suspect and submit for scrutiny.As

Only one I previously observed doing that was Emmisoft Anti-Malware when their servers connect to Ikarus servers for additional definition updates.

No suspicious modules being used, etc.I am begining to believe that MBAM Pro has some serious problems of late. I will double verify this connection later this afternoon when I log on my home PC.I haven't downloaded CurrPorts yet. Please do an online scan with Kaspersky Online Scanner. hace poco me dejaste este manual que me ayudo mucho a entender el COMODO y a configurar las reglas para programas p2p.

Right now I'm using PE 12.00, and at this moment I can't check whether the "Service" column was there in the previous version, but it should be worth a try. –TataBlack Click on Apply, Apply and OK to exit and you should be good to go. Perhaps you ha such an application installed... check over here More on this later.

Yo he puesto Any...es correcto? Even if the port is open, the alert message indicates that your firewall has blocked the attempt to access it. They are an excellent way to make the Firewall and Defence+ more secure than the installation default setting for the beginner. The connection, as stated above, is using standard DHCP protocols and ports and it's originating at a trusted source.

Windows Internal Firewall is disabled. Back to top BC AdBot (Login to Remove) BleepingComputer.com Register to remove ads #2 boopme boopme To Insanity and Beyond Global Moderator 67,076 posts OFFLINE Gender:Male Location:NJ USA Local Once the scanner is installed and the definitions downloaded, click Next. I hope this is what you wanted.

Anyway I did not see any malformed dial-out from svchost.exe to 24.xx.xx.xx IP that I had seen in the past after the MBAM def. After a couple of repeats of the same I can connect.

netstat -o lists active TCP connections and includes the process ID (PID) for each connection.

It may take some time to complete so please be patient.When the scan is finished, a message box will say "The scan completed successfully. The scan will begin and "Scan in progress" will show at the top. cachefly.net --> Go Daddy Netherlands B.V.