Repeated inbound to access svchost.exe

Hi,

Norton Internet Security (firewall) keeps displaying the following info. dialog:

---------------------------------- Threat Level Low Risk At [datetime stamp] the following communication was detected:

Application: c:\winnt\system32\svchost.exe Protocol: TCP (inbound) Remote Address: 82.35.78.249:1627 Local Address: STAN (XX.MY.IP.XX): epmap(135) This file is not infected with a virus. Autoconfiguration data exists for this application using this type of communication. This application is in the windows folder and is from a known company (Microsoft Corporation). This application does not have a digital signature or the digital signature is invalid.

The same info. but from a different IP address, among many others:

82.140.27.81:1835 82.35.75.99:3480

----------------------------------

The 'recommended' action is to allow the connection?!

I have no idea whether, or indeed why, I should allow these connections. I just installed Norton Internet Security yesterday before that I was using a different firewall.

The same info dialog pops up regularly (with varying IP addresses) and I am unsure what to do -- up to now I've been blocking them all.

Thanks,

MS

read more and respond »

Posted 5 years ago by MS in Networking Firewalls

Report misuse

Image for Repeated inbound to access svchost.exe