Why Is svchost In My Router????


Go Back   Computer Help Articles > Windows XP Security Admin
User Name
Password
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 01-05-2006, 04:19 AM
Wilbert
 
Posts: n/a
Default Why Is svchost In My Router????

Yesterday by chance I discovered an entry in my router's persistent port
forwarding screen. The description is "svchost (192.168.2.2:1032) 41670
UDP", public port is 41670 and forwarding to private port 1032. My pc's ip
is 192.168.2.2. I removed the entry but after rebooting my machine it was
back.

I checked the registry (I'm using Windows XP Pro complete w/ all updates)
and found this entry:
HKLM\SOFTWARE\Microsoft\DirectPlayNATHelp\DPNHUPnP \ActiveNATMappings\svchost
(192.168.2.2:1032) 41670 UDP. The data is in binary format.

Does anyone know if this entry is being put there by a legit Windows process
or should I be concerned?

Reply With Quote
  #2  
Old 01-05-2006, 04:19 AM
Vanguard \(NPI\)
 
Posts: n/a
Default Re: Why Is svchost In My Router????

"Wilbert" <Wilbert@discussions.microsoft.com> wrote in message
news:8BC8E23E-8AF5-4729-AEDD-4FC9BFEF7DA8@microsoft.com...
> Yesterday by chance I discovered an entry in my router's persistent port
> forwarding screen. The description is "svchost (192.168.2.2:1032) 41670
> UDP", public port is 41670 and forwarding to private port 1032. My pc's
> ip
> is 192.168.2.2. I removed the entry but after rebooting my machine it was
> back.
>
> I checked the registry (I'm using Windows XP Pro complete w/ all updates)
> and found this entry:
> HKLM\SOFTWARE\Microsoft\DirectPlayNATHelp\DPNHUPnP \ActiveNATMappings\svchost
> (192.168.2.2:1032) 41670 UDP. The data is in binary format.
>
> Does anyone know if this entry is being put there by a legit Windows
> process
> or should I be concerned?
>



Windows, or any OS, can't be putting entries into your router without your
permission. The router will require you to login (if you don't have it
password protected for its login then now is a good time to enable that
option in the router). Maybe you enabled an option in your router that
opens this port, like maybe letting it pass or send UDP requests for UPnP.
Seems your router wants this definition but you never mentioned WHICH router
(brand and model) that you have so no one familiar with it can help.

http://www.iana.org/assignments/port-numbers lists "BBN IAD" for ports
1030-1032, but that abbreviation is worthless (IANA isn't known for explicit
and informative titling of their port number assignments). Although IANA
assigns common uses of port numbers, that doesn't preclude any software from
using whatever port it wants.

You might want to visit the web site for whatever router that you have to
see why they require using and opening this port. It is likely tied to some
function you have enabled in the router.

--
_________________________________________________
| ** Reply to the newsgroup. Share with others ** |
| E-mail: Remove "NIX" and add "#LAH" to Subject. |
|_________________________________________________ |


Reply With Quote
  #3  
Old 01-05-2006, 04:19 AM
Wilbert
 
Posts: n/a
Default Re: Why Is svchost In My Router????

Thanks Vanguard for your reply. I'm using the Microsoft MN-500 wireless
router, although my pc is wired to it.

"Vanguard (NPI)" wrote:

> "Wilbert" <Wilbert@discussions.microsoft.com> wrote in message
> news:8BC8E23E-8AF5-4729-AEDD-4FC9BFEF7DA8@microsoft.com...
> > Yesterday by chance I discovered an entry in my router's persistent port
> > forwarding screen. The description is "svchost (192.168.2.2:1032) 41670
> > UDP", public port is 41670 and forwarding to private port 1032. My pc's
> > ip
> > is 192.168.2.2. I removed the entry but after rebooting my machine it was
> > back.
> >
> > I checked the registry (I'm using Windows XP Pro complete w/ all updates)
> > and found this entry:
> > HKLM\SOFTWARE\Microsoft\DirectPlayNATHelp\DPNHUPnP \ActiveNATMappings\svchost
> > (192.168.2.2:1032) 41670 UDP. The data is in binary format.
> >
> > Does anyone know if this entry is being put there by a legit Windows
> > process
> > or should I be concerned?
> >

>
>
> Windows, or any OS, can't be putting entries into your router without your
> permission. The router will require you to login (if you don't have it
> password protected for its login then now is a good time to enable that
> option in the router). Maybe you enabled an option in your router that
> opens this port, like maybe letting it pass or send UDP requests for UPnP.
> Seems your router wants this definition but you never mentioned WHICH router
> (brand and model) that you have so no one familiar with it can help.
>
> http://www.iana.org/assignments/port-numbers lists "BBN IAD" for ports
> 1030-1032, but that abbreviation is worthless (IANA isn't known for explicit
> and informative titling of their port number assignments). Although IANA
> assigns common uses of port numbers, that doesn't preclude any software from
> using whatever port it wants.
>
> You might want to visit the web site for whatever router that you have to
> see why they require using and opening this port. It is likely tied to some
> function you have enabled in the router.
>
> --
> _________________________________________________
> | ** Reply to the newsgroup. Share with others ** |
> | E-mail: Remove "NIX" and add "#LAH" to Subject. |
> |_________________________________________________ |
>
>
>

Reply With Quote
  #4  
Old 01-05-2006, 04:19 AM
Wilbert
 
Posts: n/a
Default Re: Why Is svchost In My Router????

Somebody suggested to me that I disable the Universal Plug and Play Device
Host service, which I did and the problem went away. After removing that
entry in the router and in the registry, I rebooted a few times and the entry
did not come back. Obviously, it was put there by UPnP.


"Vanguard (NPI)" wrote:

> "Wilbert" <Wilbert@discussions.microsoft.com> wrote in message
> news:8BC8E23E-8AF5-4729-AEDD-4FC9BFEF7DA8@microsoft.com...
> > Yesterday by chance I discovered an entry in my router's persistent port
> > forwarding screen. The description is "svchost (192.168.2.2:1032) 41670
> > UDP", public port is 41670 and forwarding to private port 1032. My pc's
> > ip
> > is 192.168.2.2. I removed the entry but after rebooting my machine it was
> > back.
> >
> > I checked the registry (I'm using Windows XP Pro complete w/ all updates)
> > and found this entry:
> > HKLM\SOFTWARE\Microsoft\DirectPlayNATHelp\DPNHUPnP \ActiveNATMappings\svchost
> > (192.168.2.2:1032) 41670 UDP. The data is in binary format.
> >
> > Does anyone know if this entry is being put there by a legit Windows
> > process
> > or should I be concerned?
> >

>
>
> Windows, or any OS, can't be putting entries into your router without your
> permission. The router will require you to login (if you don't have it
> password protected for its login then now is a good time to enable that
> option in the router). Maybe you enabled an option in your router that
> opens this port, like maybe letting it pass or send UDP requests for UPnP.
> Seems your router wants this definition but you never mentioned WHICH router
> (brand and model) that you have so no one familiar with it can help.
>
> http://www.iana.org/assignments/port-numbers lists "BBN IAD" for ports
> 1030-1032, but that abbreviation is worthless (IANA isn't known for explicit
> and informative titling of their port number assignments). Although IANA
> assigns common uses of port numbers, that doesn't preclude any software from
> using whatever port it wants.
>
> You might want to visit the web site for whatever router that you have to
> see why they require using and opening this port. It is likely tied to some
> function you have enabled in the router.
>
> --
> _________________________________________________
> | ** Reply to the newsgroup. Share with others ** |
> | E-mail: Remove "NIX" and add "#LAH" to Subject. |
> |_________________________________________________ |
>
>
>

Reply With Quote
  #5  
Old 01-05-2006, 04:29 AM
Sparda
 
Posts: n/a
Default Re: Why Is svchost In My Router????

"" wrote:
> Yesterday by chance I discovered an entry in my router's
> persistent port
> forwarding screen. The description is "svchost
> (192.168.2.2:1032) 41670
> UDP", public port is 41670 and forwarding to private port
> 1032. My pc's ip
> is 192.168.2.2. I removed the entry but after rebooting my
> machine it was
> back.
>
> I checked the registry (I'm using Windows XP Pro complete w/
> all updates)
> and found this entry:
> HKLMSOFTWAREMicrosoftDirectPlayNATHelpDPNHUPnPActi veNATMa
> ppingssvchost
>
> (192.168.2.2:1032) 41670 UDP. The data is in binary format.
>
> Does anyone know if this entry is being put there by a legit
> Windows process
> or should I be concerned?


You should be concerned reguradless of whether it is "ligitimate" or
not, you should take messurs to stop such activits, in this case the
best would be to install a good firewall, I would personaly recomend
ZoneAlarm.

ZoneAlarm:
http://www.zonelabs.com/store/conten...btop nav_zass

--
Posted using the http://www.windowsforumz.com interface, at author's request
Articles individually checked for conformance to usenet standards
Topic URL: http://www.windowsforumz.com/svchost...ict442036.html
Visit Topic URL to contact author (reg. req'd). Report abuse: http://www.windowsforumz.com/eform.php?p=1492689
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
New router connects to net, but... Dave Bachmann Windows XP Network Web 6 01-05-2006 04:14 AM
Adding switch to existing router setting goscottie@gmail.com Windows XP Network Web 5 01-05-2006 04:11 AM
DSL vs Cable router setup Hugh Windows XP Network Web 2 01-05-2006 04:11 AM
Wireless router RD Windows XP Hardware 0 01-05-2006 02:23 AM
Wireless Router Works but the one with wires does not John Wilson Windows XP Hardware 5 01-05-2006 02:16 AM


All times are GMT. The time now is 07:05 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd. SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.

Why Is svchost In My Router????