Endpoint Protection

 View Only
  • 1.  SVCHOST.EXE and Endpoint Protection

    Posted Oct 22, 2013 03:58 PM

    Operating system: windows 8 64-bit operating system. SEP version 12.1.12015.2015. Updated as of today.
    SEP keeps creating a popup that states "traffic has been blocked from this application: SVCHOST.EXE."

    I have disabled IP6, searched for imposter SVCHOST.EXE and many other things to stop whatever this is from happening. It still happens every couple minutes, continuously. Some sources say it is SEP acting funny over no threat. Some sources say that it is malicious.

    I tried a system recovery after it started, which failed.

    How can I eliminate this "high risk?" Please help

     



  • 2.  RE: SVCHOST.EXE and Endpoint Protection

    Posted Oct 22, 2013 04:08 PM

    Look in the Traffic log at the time this popup occurs and see what's going on. Specifically, the port assocoated with it.

    I've seen this happen with MS updates as well so it could be a false positive.



  • 3.  RE: SVCHOST.EXE and Endpoint Protection

    Posted Oct 23, 2013 12:07 AM


  • 4.  RE: SVCHOST.EXE and Endpoint Protection

    Posted Oct 23, 2013 02:58 AM

    Hi

    Kindly upgrade to SEP 12.1.3 and observe

    Regards

     



  • 5.  RE: SVCHOST.EXE and Endpoint Protection