zonealarm and svchost

Miscellaneous Forums/General Discussion/zonealarm and svchost

I have to give the generic host for win32 services zonealarm-access to the internet in order to be able to resolve urls to IPs, so it's required to surf the we at all.

In the first call it tries to connect to my router only, so maybe I could declare the IP of the router as a local/secure zone and permit acces only for secure zones, to prevent it from being able to connect to the rest of the world.

Is there any security issue resluting from declaring eg. 192.168.1.1 (the LAN router) as a secure zone in zonealarm?

If you have a NAT, no

since svchost is doubious, to say the least, I have watched it a little closer. Downloading sysinternals Process Explorer was a good idea. Now, there are several svchost instances running, infact they seem to act as a firewall wildcard for many shady OS processes, but only the DNS service is making me nervous by producing a lot traffic on the zonealarm IO meter (access every second). So I simply Stop this service using the properties/service tab of the process. THought I will no longer be able to resolve URLs now, but hey, I still can surf, but there is no more traffic caused by svchost!!! What was this traffic good(or bad) for anyway??

Seems like I only need to autostop this service somehow.

There should be a few scvhost.exes processing, I got 6 myself here, never really bothered to look into what each specific instance is supposed to be doing though.

When there is a lot of traffic then I get nervous. Now, after stopping the dns service of the svchost processes, there's nice silence! As long as I don't click something in my browser, there's NO traffic. I like it.

I am really surprised that I'm the only one with this problem. Is there anybody else with zonealarm and XP with this traffic every second?? (If you have Antivir then you probably won't notice since Antivir will use the ports frequently as well)

Wen you run sysinternal´s Process Explorer then it will become obvious: svchost DNS service is causing firewall action every second, the firewall then triggers the antivirus guard due to some disk writing action, guess caching something, basicly the system resources are used every second by about 20%, caused by this DNS "service". What´s the deal??