Firewall Log



Having problems understanding the workings of 'svchost.exe' service. I have
6 of them on my desktop which uses XP Pro SP2. I'm having trouble
identifying what is happening. Its a home pc, on one router. I've blocked
port 1900 and UPnP on the router and think i've blocked it in Windows
Firewall. Not sure what this is. Below is my result of netstat and tasklist:

UDP 127.0.0.1:1900 *:* 1296
c:\windows\system32\WS2_32.dll
c:\windows\system32\ssdpsrv.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]

Active Connections

Proto Local Address Foreign Address State PID
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 1004
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:990 0.0.0.0:0 LISTENING 324
TCP 127.0.0.1:1025 0.0.0.0:0 LISTENING 1776
TCP 127.0.0.1:1031 0.0.0.0:0 LISTENING 2804
TCP 127.0.0.1:1035 127.0.0.1:27015 ESTABLISHED 1796
TCP 127.0.0.1:1036 0.0.0.0:0 LISTENING 1816
TCP 127.0.0.1:1037 0.0.0.0:0 LISTENING 3896
TCP 127.0.0.1:1038 0.0.0.0:0 LISTENING 3888
TCP 127.0.0.1:5679 0.0.0.0:0 LISTENING 1996
TCP 127.0.0.1:7438 0.0.0.0:0 LISTENING 1996
TCP 127.0.0.1:27015 0.0.0.0:0 LISTENING 608
TCP 127.0.0.1:27015 127.0.0.1:1035 ESTABLISHED 608
TCP 192.168.10.13:139 0.0.0.0:0 LISTENING 4
UDP 0.0.0.0:445 *:* 4
UDP 0.0.0.0:500 *:* 756
UDP 0.0.0.0:1027 *:* 1156
UDP 0.0.0.0:4500 *:* 756
UDP 127.0.0.1:123 *:* 1100
UDP 127.0.0.1:1069 *:* 3036
UDP 127.0.0.1:1900 *:* 1296
UDP 192.168.10.13:123 *:* 1100
UDP 192.168.10.13:137 *:* 4
UDP 192.168.10.13:138 *:* 4
UDP 192.168.10.13:1900 *:* 1296

Image Name PID Services
========================= ====== =============================================
System Idle Process 0 N/A
System 4 N/A
smss.exe 624 N/A
csrss.exe 672 N/A
winlogon.exe 700 N/A
services.exe 744 Eventlog, PlugPlay
lsass.exe 756 PolicyAgent, ProtectedStorage, SamSs
ati2evxx.exe 920 Ati HotKey Poller
svchost.exe 944 DcomLaunch, TermService
svchost.exe 1004 RpcSs
svchost.exe 1100 AudioSrv, CryptSvc, Dhcp, dmserver, ERSvc,
EventSystem, helpsvc, HidServ, lanmanserver,
lanmanworkstation, Netman, Nla, RasMan,
Schedule, seclogon, SENS, SharedAccess,
ShellHWDetection, srservice, TapiSrv,
Themes, TrkWks, W32Time, winmgmt, wscsvc,
wuauserv, WZCSVC
svchost.exe 1156 Dnscache
svchost.exe 1296 LmHosts, RemoteRegistry, SSDPSRV, WebClient
ccSetMgr.exe 1360 ccSetMgr
ccEvtMgr.exe 1452 ccEvtMgr
spoolsv.exe 1640 Spooler
ati2evxx.exe 348 N/A
explorer.exe 452 N/A
AppleMobileDeviceService. 608 Apple Mobile Device
DefWatch.exe 656 DefWatch
mdm.exe 988 MDM
svchost.exe 1188 stisvc
Rtvscan.exe 1712 Symantec AntiVirus
soundman.exe 1768 N/A
CLI.exe 1776 N/A
iTunesHelper.exe 1796 N/A
hpwuSchd2.exe 1808 N/A
ccApp.exe 1816 N/A
VPTray.exe 1836 N/A
LCDMon.exe 1856 N/A
LGDCore.exe 1868 N/A
jusched.exe 1928 N/A
reader_sl.exe 1940 N/A
LCDMedia.exe 1956 N/A
ctfmon.exe 1976 N/A
wcescomm.exe 1996 N/A
hpqtra08.exe 2024 N/A
SetPoint.exe 132 N/A
hpqimzone.exe 296 N/A
rapimgr.exe 324 N/A
KHALMNPR.exe 424 N/A
wmiprvse.exe 2396 N/A
alg.exe 2804 ALG
hpqnrs08.exe 2868 N/A
iPodService.exe 3560 iPod Service
hpqste08.exe 3656 N/A
CLI.exe 3888 N/A
CLI.exe 3896 N/A
wuauclt.exe 2532 N/A
iexplore.exe 3036 N/A
cmd.exe 2384 N/A
netstat.exe 1044 N/A
cmd.exe 3780 N/A
wmiprvse.exe 220 N/A
HPZinw12.exe 388 N/A
tasklist.exe 392 N/A


.



Relevant Pages

  • Re: Airport in battery woes
    ... I'm at a loss to find what's the trouble. ... significant differences in signal strength and network reliability can ... result from simply changing the channel that the router is operating on. ... and there weren't any other wireless networks on either channel! ...
    (comp.sys.mac.portables)
  • Re: Printing Problems: Intel Imac to Apple Laserwriter
    ... OSX 10.4.5 without any trouble. ... Some early Apple LaserWriters used AppleTalk and did not have IP printing ... Even if the printer has IP capability, ... router, then that may be where the trouble is. ...
    (comp.sys.mac.system)
  • Re: Airport in battery woes
    ... No channel gave me any signal gain over another, and there is no interference with other routers in all but a veyr remote part of the house, What is disconcerting is that I decided to try and to make the router broadcast EssID, in case the problem was there, and I then activated WEP, 128 bit, to add a little droplet of security, to my connection, and when I reset the router, at the restart it gained a few Db in strenght ?? ... I'm at a loss to find what's the trouble. ... result from simply changing the channel that the router is operating on. ... and there weren't any other wireless networks on either channel! ...
    (comp.sys.mac.portables)
  • Re: Remote Assistance Failed
    ... I'm running XP Pro SP2 and all current updates. ... > SpeedStream router with port 3389 open. ... Copy/Paste text, ... I do utilize the Windows 2003 RDC instead of the one that came with Windows ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: DNS Problems
    ... It's that IPv4 IP you want to check when you start having trouble looking for the 169 IP or zeroes. ... You may want the check the Gateway IP and the DNS IP that the machine is using, which is further down in the list of IPconfig information. ... If a router is in play, then the router has an Admin screen showing what IP and Gateway and DNS IPit's using. ... cannot resolve http://www.google.com/ to the IP that belongs to ...
    (microsoft.public.windows.vista.general)

Quantcast