https://www-secure.symantec.com/connect/forums/tra...
I have been having a problem with my SEP Threat Detection. It seems that every 4 minutes I receive a notification from SEP that it has blocked svchost.exe.
This is a clean computer, I have scanned with antivirus software and antimalware software since this has happened. The problem arose when I decided to switch from Avast antivirus software to SEP as my school has allowed me to download the latest version of it.
I have a Windows 7 Pro, SEP version 12.1.1000.157 RU1.
The pop up notifications are annoying, and I know I dont have a virus. So I consulted https://www-secure.symantec.com/connect/forums/tra... They told me to disable ip6. I did. It seems like my problems are coming from IP4 as you can see by my threat log:
12/30/2012 8:37:56 AM Blocked 3 Outgoing UDP 239.255.255.250 01-00-5E-7F-FF-FA 1900 192.168.0.143 00-10-18-EA-74-75 1900 C:\Windows\System32\svchost.exe LOCAL SERVICE NT AUTHORITY Default 18 12/30/2012 8:36:54 AM 12/30/2012 8:37:00 AM Block UPnP Discovery
12/30/2012 8:37:00 AM Allowed 3 Incoming UDP 0.0.0.0 78-A3-E4-11-C5-87 68 255.255.255.255 FF-FF-FF-FF-FF-FF 67 Admin Argh0812 Default 1 12/30/2012 8:35:59 AM 12/30/2012 8:35:59 AM Allow BOOTP protocol
12/30/2012 8:37:00 AM Allowed 3 Incoming UDP 192.168.0.1 00-1B-11-56-C2-35 67 255.255.255.255 FF-FF-FF-FF-FF-FF 68 Admin Argh0812 Default 1 12/30/2012 8:35:59 AM 12/30/2012 8:35:59 AM Allow BOOTP protocol
12/30/2012 8:36:49 AM Allowed 3 Outgoing IP 239.255.255.250 01-00-5E-7F-FF-FA NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:35:48 AM 12/30/2012 8:35:48 AM Allow IGMP traffic
12/30/2012 8:36:49 AM Allowed 3 Outgoing IP 224.0.0.251 01-00-5E-00-00-FB NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:35:48 AM 12/30/2012 8:35:48 AM Allow IGMP traffic
12/30/2012 8:36:43 AM Allowed 3 Outgoing IP 224.0.0.252 01-00-5E-00-00-FC NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:35:42 AM 12/30/2012 8:35:42 AM Allow IGMP traffic
12/30/2012 8:36:43 AM Allowed 3 Incoming IP 192.168.0.1 00-1B-11-56-C2-35 NA 224.0.0.1 01-00-5E-00-00-01 NA Admin Argh0812 Default 1 12/30/2012 8:35:42 AM 12/30/2012 8:35:42 AM Allow IGMP traffic
12/30/2012 8:35:09 AM Allowed 3 Incoming UDP 192.168.0.1 00-1B-11-56-C2-35 1900 239.255.255.250 01-00-5E-7F-FF-FA 1900 Admin Argh0812 Default 42 12/30/2012 8:34:07 AM 12/30/2012 8:34:13 AM Allow UPnP Discovery from private IP addresses
12/30/2012 8:34:41 AM Allowed 3 Outgoing IP 239.255.255.250 01-00-5E-7F-FF-FA NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:33:39 AM 12/30/2012 8:33:39 AM Allow IGMP traffic
12/30/2012 8:34:41 AM Allowed 3 Incoming IP 192.168.0.102 A4-EE-57-4E-D4-A6 NA 224.0.0.252 01-00-5E-00-00-FC NA Admin Argh0812 Default 1 12/30/2012 8:33:39 AM 12/30/2012 8:33:39 AM Allow IGMP traffic
12/30/2012 8:34:35 AM Allowed 3 Outgoing IP 224.0.0.251 01-00-5E-00-00-FB NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:33:34 AM 12/30/2012 8:33:34 AM Allow IGMP traffic
12/30/2012 8:34:35 AM Allowed 3 Incoming IP 192.168.0.1 00-1B-11-56-C2-35 NA 224.0.0.1 01-00-5E-00-00-01 NA Admin Argh0812 Default 1 12/30/2012 8:33:34 AM 12/30/2012 8:33:34 AM Allow IGMP traffic
12/30/2012 8:32:38 AM Allowed 3 Outgoing IP 224.0.0.252 01-00-5E-00-00-FC NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:31:37 AM 12/30/2012 8:31:37 AM Allow IGMP traffic
12/30/2012 8:32:38 AM Allowed 3 Outgoing IP 239.255.255.250 01-00-5E-7F-FF-FA NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:31:37 AM 12/30/2012 8:31:37 AM Allow IGMP traffic
12/30/2012 8:32:33 AM Allowed 3 Incoming IP 192.168.0.122 68-A8-6D-B7-37-A9 NA 224.0.0.251 01-00-5E-00-00-FB NA Admin Argh0812 Default 1 12/30/2012 8:31:31 AM 12/30/2012 8:31:31 AM Allow IGMP traffic
12/30/2012 8:32:33 AM Allowed 3 Incoming IP 192.168.0.102 A4-EE-57-4E-D4-A6 NA 224.0.0.251 01-00-5E-00-00-FB NA Admin Argh0812 Default 1 12/30/2012 8:31:31 AM 12/30/2012 8:31:31 AM Allow IGMP traffic
12/30/2012 8:32:33 AM Allowed 3 Incoming IP 192.168.0.1 00-1B-11-56-C2-35 NA 224.0.0.1 01-00-5E-00-00-01 NA Admin Argh0812 Default 1 12/30/2012 8:31:31 AM 12/30/2012 8:31:31 AM Allow IGMP traffic
12/30/2012 8:30:36 AM Allowed 3 Incoming UDP 192.168.0.148 00-17-A4-6F-1A-F0 1900 239.255.255.250 01-00-5E-7F-FF-FA 1900 Admin Argh0812 Default 10 12/30/2012 8:29:34 AM 12/30/2012 8:29:34 AM Allow UPnP Discovery from private IP addresses
12/30/2012 8:30:36 AM Allowed 3 Incoming IP 192.168.0.102 A4-EE-57-4E-D4-A6 NA 224.0.0.252 01-00-5E-00-00-FC NA Admin Argh0812 Default 1 12/30/2012 8:29:34 AM 12/30/2012 8:29:34 AM Allow IGMP traffic
12/30/2012 8:30:30 AM Allowed 3 Incoming TCP 192.168.0.1 00-1B-11-56-C2-35 28983 192.168.0.143 00-10-18-EA-74-75 2869 C:\Windows\system32\NTOSKRNL.EXE Admin Argh0812 Default 1 12/30/2012 8:29:29 AM 12/30/2012 8:29:29 AM Allow SSDP from private IP addresses
12/30/2012 8:30:30 AM Allowed 3 Incoming IP 192.168.0.146 00-25-00-3A-C8-2E NA 224.0.0.251 01-00-5E-00-00-FB NA Admin Argh0812 Default 1 12/30/2012 8:29:29 AM 12/30/2012 8:29:29 AM Allow IGMP traffic
12/30/2012 8:30:30 AM Blocked 3 Outgoing UDP 239.255.255.250 01-00-5E-7F-FF-FA 1900 192.168.0.143 00-10-18-EA-74-75 1900 C:\Windows\System32\svchost.exe LOCAL SERVICE NT AUTHORITY Default 18 12/30/2012 8:29:29 AM 12/30/2012 8:29:34 AM Block UPnP Discovery
12/30/2012 8:30:30 AM Allowed 3 Outgoing IP 224.0.0.22 01-00-5E-00-00-16 NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 12 12/30/2012 8:29:29 AM 12/30/2012 8:29:29 AM Allow IGMP traffic
Please help me find a resolution ASAP! Thank you so much for your time. I am brand new to Nortion, so please go into descriptions if you find a solution. Thank you!