Ok, system check:
OS: WinXP Pro SP3 running on an Athlon 64 TK55
Firewall: Comodo 3.10
Internet connection: Wireless through a SpeedTouch wireless router/dsl modem @ 4Mbs/384kbs.
BT client: Bitcomet 1.14
I want to emphasize that my BC client is running fine and the port forwarding is going ok too. The thing is, while BC is running I keep finding in the firewall logs (Comodo that is), entries of blocked inbound connection attempts, both on TCP and UDP, on the 2 ports used by Bitcomet and Emule plugin. Except, the application towards which the connections are attempted appears as “Windows Operating System” in the firewall log. Now, I dont’t know if these are legit connection attempts or hack attempts. Besides I don’t know what process does “Windows Operating System” stand for since I have no such entry in my firewall’s network policies list. I can’t imagine why would a BT client, try to connect to another process instead of Bitcomet. But if, anyways this is a legit way to attempt a connection then I should try and find a way to allow this in order to get more peers.
Besides in the logs there are many different IPs which attempt these connections not just a single one, so except for a botnet atack this doesn’t make much sense to me. Any ideas as to why is this happening? I mean is it normal behaviour for BT protocol to involve Windows OS components (not talking here about TCP/IP suite) into achieving connections or it should work just between the two BT clients? Because the BC download works regardless of the fact that these connection are blocked. I’m just thinking that maybe I’m loosing peers this way, which, in the event of not very healthy torrents is a bad thing.
The only entries in my firewall that come close to Windows core components are:
System (which by the way, has an “ask” rule for unmatching requests, so it can’t raise the blocking event)
svchost.exe
explorer.exe
alg.exe
Windows Updater Aplications
I have no idea which one could raise this event, but most important if should be allowed in the firewall.
To mods: If this is not posted in the right section please move it and I’m sorry for the length of the post too.