UDP on ports 1026,1027 svchost.exe only sometimes?
I was noticing my firewall on some UDP request activates my "svchost.exe" program and then my firwall blocks it when it attempts to connect "outgoing" is blocked as well asthe incoming request, what I want to know is, why on some requests the "svchost.exe" activates and others in does not, on all of these, UDP ports I am not initiating any of the request, it is the "nosey" China.net computers , here is an example of what I am talking about:
Alert
Source IP Address 61.152.158.152 The IP address of the computer that sent the packet which caused the alert.
Source Port 49387 The port used by the source computer when sending the packet.
Destination IP xxx.xxx.xxx.xxx(me loacally)
The IP address of the computer to which the packet was sent.
Destination Port 1026 The port on the destination computer used to receive the packet.
Transport Layer Protocol UDP The protocol that allows data to be transported between software programs on different computers.
Network Layer Protocol IP The protocol that allows two networked computers to locate each other on a network.
Link Layer Protocol Ethernet The protocol that allows two directly linked computers to share a
network cable.
Alert Date Jun-07-2005 11:00:59 AM PDT The time when ZoneAlarm Pro detected the alert on your computer.
Alert Count 1
ok that was copied ,obviously from Zonlabs alert "more info" now the next set of data is stating the svchost.exe program has activated..this is what I dont understand, as far as I have test all my ports are "stealth".....
Inside the firewall alert
Alert property Alert property value Technical explanation
Source IP Address 221.211.255.8 The IP address of the computer that sent the packet which caused the alert.
Source Port 32920 The port used by the source computer when sending the packet.
Destination IP xxx.xxx.xxx.xxx The IP address of the computer to which the packet was sent.
Destination Port 1027 The port on the destination computer used to receive the packet.
Transport Layer Protocol UDP The protocol that allows data to be transported between software programs on different computers.
Network Layer Protocol IP The protocol that allows two networked computers to locate each other on a network.
Link Layer Protocol Ethernet The protocol that allows two directly linked computers to share a network cable.
Program Name Generic Host Process for Win32 Services A program on your computer. This program either attempted to send an IP packet over the Internet or is waiting for an incoming packet.
(I think these are simply ports scans from the nosey china servers and/or looking for there "bots" but how does it make my single computer on dialup through earthlink activate svchost.exe on some port scans versus others?
File Name svchost.exe <---see this is what I am talking about?
The executable file on your computer that launches and runs Generic Host Process for Win32 Services.
Alert Date Jun-07-2005 11:09:35 AM PDT The time when ZoneAlarm Pro detected the alert on your computer.
Alert Count 1 Number of times this connection attempt repeated its attempt on your machine
To sum it all up why does the svchost.exe launch on similar port scans "UDP 1027" and "UDP 1026" but NOT everyone? Does this have something to do with STEALTH and NOt STEALTH ports, ?
update my ports are closed but,...
Im running ZoneAlarm Pro, on a OS XP-Home(not by choice) on some Alerts I notice the User Data ?Protocol, the way I understand it this protocol allows "launching" of programs/software/files between 2 computers ....
Any way I am aware of for example" RealPlayer" may try to initiate a "call home" to transfer data for whatever reasons,although I think this type of svchost.exe is probably safe, and not after sensitive data,etc,... This is not whats going on.
Here is a summary of what my firewall told me as basic as I can understand it:
ZoneAlarm blocked traffic to port 1026 on your machine from port 39093 on a remote computer whose IP address is 61.152.158.151 On this Alert the svchost.exe did not launch...ok great! Thats what I want to see right? Oh, and there was no Domain name or info just ther IP traced back the Bejing Area, I thinking this is typical I see this all the time,
What got my attention was sometimes the svchost.exe atempts to launch but ZA-blocks it, I was wonder why or for what reasons this could happen I pretty sure my machine is "clean" but who really knows, hah? My machine doesn't accept incoming connections, if it doesn't, then How would it know to launch svchost.exe this is my real question?(unless maybe svchost.exe is always listening...? I read the Micrsoft article
stealth
ZoneAlarm blocked traffic to port 1027 on your machine from port 39093 on a remote computer whose IP address is 61.XXX.xxx.xxx( I have to get the exact IP but it too traces back to Bejing AREA as best I can tell, svchost.exe atempts to launch but ZA-blocks it in this above example, I pretty sure it does it for BOTH 1026 and 1027.
Not sure maybe it is a setting on my Firewall doing it?
I have recently decide to let ZA make "smart decision for me" now that is going right back to manal, but I set it this way because sometimes there are sooo many programs Process I dont know what is what!
It does not represent,
whether there actually is no service listening on the port I guess this is my reall question?
Everthing seems to run fine Processors is NOT overloaded, no strange programs, etc,....
I have tried diffrent setting too,
Another intresting fact is when I use my windows ME machine and ZA FREE, it does not show any svchost.exe program launches unless I know what it is , like an update( port 135 DCOM) or something OBvious,...
Maybe this is normail(hoping so) and it is common with XP Home, I tried the cmd for
a while later for example simple