4000 to 5000 TCP hits in my Firewall log??

Aug 11, 2006 7 Replies
4000 to 5000 TCP hits in my Firewall log?? open original image

We have a small office network (5 computers) and each has PC-cillin Internet Security 2006 installed. On 1 computer the firewall log is showing 4000 to 5000 entries every day. All of these are from the same computer on our network, all are directed to port 135. However, a virus scan of that computer comes up clean (with PC-cillin, McAfee's online scanner & MS's Malicious software tool). Can anyone tell me what is going on here? Is there anyway to stop it?



Some typical entries in the log are: Type Time Protocol Source IP Address Source Port Destination IP Address Destination Port Application Path Application Description Description Firewall 0:00:17 TCP 192.168.1.154 2630 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic Host Process for Win32 Services Security rule matched Firewall 0:00:20 TCP 192.168.1.154 2630 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic Host Process for Win32 Services Security rule matched Firewall 0:00:26 TCP 192.168.1.154 2630 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic Host Process for Win32 Services Security rule matched Firewall 0:01:11 TCP 192.168.1.154 2633 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic Host Process for Win32 Services Security rule matched Firewall 0:01:14 TCP 192.168.1.154 2633 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic Host Process for Win32 Services Security rule matched Firewall 0:01:20 TCP 192.168.1.154 2633 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic Host Process for Win32 Services Security rule matched Firewall 0:02:05 TCP 192.168.1.154 2634 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic Host Process for Win32 Services Security rule matched Firewall 0:02:08 TCP 192.168.1.154 2634 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic Host Process for Win32 Services Security rule matched Firewall 0:02:14 TCP 192.168.1.154 2634 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic Host Process for Win32 Services Security rule matched Firewall 0:02:59 TCP 192.168.1.154 2635 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic Host Process for Win32 Services Security rule matched



Thanks for any help,



Pdarrah



ports 135-139 + 445 are specific ports used by MS. add a rule, allow tcp/udp $your-lan-address/24 ports 135-139,445 ignore, nolog

eg: 139/445 are use for file/print sharing

Firewall 0:00:17 TCP 192.168.1.154 2630 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic

Firewall 0:00:20 TCP 192.168.1.154 2630 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic

Firewall 0:00:26 TCP 192.168.1.154 2630 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic

Firewall 0:01:11 TCP 192.168.1.154 2633 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic

Firewall 0:01:14 TCP 192.168.1.154 2633 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic

Firewall 0:01:20 TCP 192.168.1.154 2633 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic

Firewall 0:02:05 TCP 192.168.1.154 2634 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic

Firewall 0:02:08 TCP 192.168.1.154 2634 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic

Firewall 0:02:14 TCP 192.168.1.154 2634 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic

Firewall 0:02:59 TCP 192.168.1.154 2635 192.168.1.100 135 C:\\WINDOWS\\SYSTEM32\\SVCHOST.EXE Generic

Hi Jeff - Does this mean that I shouldn't be concerned about this? The other computer isn't trying to "attack" this one? Why would this only be occuring on one machine on the network. The other 5 machines only have 100 to 200 ICMP entries each day - nothing like this....

Thanks,

pdarrah

this is normal for MS, *BUT* you must enforce the access to only your lan segment(s). ALL perimeter access *MUST* be denied!

see

formatting link

Thanks Jeff - I have read through the links you sent and I do see that traffic within the local network for port 135 could be "normal". What has me concerned however is that we are talking about 3 to 4 of these per minute. Each entry is identical except for the time logged and the "Source Port" which slowly increments up from 1025 up to 4998 and then starts over again. It has been doing this for nearly 2 weeks (I just noticed the other day and have been trying to figure it out ever since!) It just looks like it is looking for a way to sneek in. The firewall is blocking it, but I assume this is using system resources and if there is something wrong with the other PC (it seems to be running very slowly) I would like to fix it.

pdarrah

this defines the behavior of a client application; these ports (better said sockets) on the source machine with the 135 as the destination or the 'well known' service that resides(if active) there.

run every AV you have on the source machine.

that's the correct default behavior

not really (for the firewall IF you disregard these and avoid logging)

get these two tools installed on that machine and run under the Admin account: Curports 1.03 at

formatting link
will show which process is using specific port(s)

Process Explorer at

formatting link
better TaskMonitor you can sort by task name, cpu usage and get detail info re the task/threads rigth click a process->properties and the details are just amazing

Totally silly to install such personal firewall crap on the workstations. Filter on the perimeter. The LAN is usually trusted and usually one wants that these machines can commnicate with each other.

Absolutely normal Microsoft network noise.

Normal Microsoft network noise.

Several:

- Use another operating system

- Uninstall the firewall simulation, whose output you don't understand anyway

- filter at the perimeter

- pay someone, who knows what he's doing.

Wolfgang

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required