SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Operating Systems > Windows XP
User Name
Password


Unk Processes Triggers Firewall - continuiously communicates with Linksys Router

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 08-16-2004, 07:14 PM
MarkAbrams's Avatar
MarkAbrams Offline
Junior Member
 
Join Date: Aug 2004
Location: Boston, Ma
Posts: 9
Unk Processes Triggers Firewall - continuiously communicates with Linksys Router

I have an unexplained process that has occured with two PCs on seperate networks.

Both PC are sending a massive about of TCP traffic to the routers even with the internet disconnect at the router and all other devices disconnected.

1) Version of XP - Case 1 - XP Professional Case 2 - XP Home
2) Hardware setup:
Case 1- desktop - 2GHz cpu P4, 1GB Ram, 100GB Disk (90%free) all security patches applied SP1. Linksys Router EtherFast® Cable/DSL Router BGFSR41

Case 2 - IBM laptop T40 Pentium M 1.6GHz, 512MB Ram, 40GB disk (75% free) all secrity patches applied SP1

3) What exactly happened leading up to the problem.

Both PC operate normal until IP packets are transmitted. Once an IP starts - there is continious IP transmissions. SVCHOST:1172 is performing OPEN, READ, QUERY INFORMATIO, CLOSE, ... IEXPLORER.EXE:2868 has same operations, CCEVTMGR.EXE write to Symantec\SNDCON.log - the log is unreadable.

Upto 25% of the CPU is consumed. Disconnecting the Router from the WAN does not stop the problem. Any process that connect to the internet triggers this problem. Other PCs on both networks are uneffected.

Both PC create XML, html, and gif files in C:\WINDOWS\System32\Config\systemprofile\Local Settings\ Teporary Internet Files\Content.IE5\IJ23456P

FILES: WANIPConnection[19] 1kb WANCfg[1].gif 4kb WANCommonInterfaceConfig 1kb rootDesc[7] 3kb Class3SoftwarePublishers[1].crl 8kb Certificate Revokation List ...

The files are created continiously. File Monitor from systeminternals.com shows massive traffic opening, quering and closing files.

Sometimes the symantec firewall says that a new connections is being made but it is usually Local Host.

Colasoft Capsa 4.0 (network sniffer) shows transmissions from each PC on 192.168.1.1:6688 to the router @ 11 packets per second or 2kbs. This is all TCP traffic - no UDP, no IP

Soap Headers showrouter settings: GetCommonLinkProperties NewWANAccessType out WANAccess Type NewLayer1UpstreamMaxBitRate out ...

LINKSYS is clueless - claims its not our router. Symantec is no help either. 2 hrs on hold to listen to a tech say this is the worst its ever been ...

Both PCs have current Symantec AV - Case 1 corporate ed, Case 2 - NIS - both run with full scans in safe mode. Also Spy Sweeper was run on both and both are clean. Firewalls disabled, NAV disabled produces the same results.

In closing I suspect a worm. I have now reformated Case 1 and the problem is gone. I would like to know what this is and any info on how to fix it or isolate the problem would be appreciated.

TIA
Mark



Last edited by MarkAbrams : 08-16-2004 at 09:46 PM.
Reply With Quote

  #2  
Old 08-16-2004, 08:11 PM
Overclocked Doc Offline
Senior Member
 
Join Date: Jul 2004
Location: Canada
Posts: 706
Quote:
SCVHOST
.....have you typed this correctly? Did you mean...SVCHOST? If not that may be your problem. SCVHOST is badnews! SVCHOST is not.
Reply With Quote

  #3  
Old 08-16-2004, 08:37 PM
MarkAbrams's Avatar
MarkAbrams Offline
Junior Member
 
Join Date: Aug 2004
Location: Boston, Ma
Posts: 9
Yes - its a type - SVCHOST is the file

Yes - its was a typeo - SVCHOST is the file

Last edited by MarkAbrams : 08-17-2004 at 10:15 PM.
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
XP, Linksys Router & FTP Problem pinochet Windows XP 3 02-18-2007 05:00 PM
Linksys Router hank3rd Windows XP 0 08-26-2004 06:35 AM
Kerio WinRoute Firewall 6.0.0 RC3 (Beta) Azn_tweaker Software Problems and Useful Utilities 2 05-30-2004 09:16 PM
Linksys router beeboy Chit Chat 5 11-26-2003 06:01 PM
Linksys Router, Firewalls, pop-ups, etc ewright Internet 0 04-10-2003 12:17 PM



All times are GMT -5. The time now is 08:50 PM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.