MSFN Forum: svchost.exe accessing microsoft exchange server without permission - MSFN Forum

Jump to content


Windows 7 forum rules

If you have questions about customizing Windows 7 that are vLite-specific, please post them in the vLite forum, not here. If you have questions regarding the unattended installation of Windows 7, please post them in the Unattended Windows 7/Server 2008 R2 section.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

svchost.exe accessing microsoft exchange server without permission

#1 User is offline   newprouser 

  • Junior
  • Pip
  • Group: Members
  • Posts: 52
  • Joined: 24-May 08
  • OS:XP Pro x86
  • Country: Country Flag

Posted 27 June 2012 - 03:48 AM

Hey all ,

I have Microsoft Outlook 2010 installed on my win 7 x64 PC to access my company's emails through the exchange server. Now , i haven't saved my credentials, so every time I open outlook , I'm prompted to enter it.

The issue I'm facing is , many times, i see svchost.exe downloading data from the exchange server, even when i have not opened outlook or set outlook to work offline.

I was wondering how it is able to access the data without authenticating, since I had made sure even the credential manager is also empty.

Also this issue seems to happen only in win 7 for some reason. Note: i have not made any changes to outlook configuration.


#2 User is offline   cluberti 

  • Gustatus similis pullus
  • Group: Supervisor
  • Posts: 11,208
  • Joined: 09-September 01
  • OS:Windows RT
  • Country: Country Flag

Posted 28 June 2012 - 05:42 PM

Which svchost is accessing the Exchange server, and what exactly is it accessing? Does it leave any event log entries on either side?

#3 User is offline   newprouser 

  • Junior
  • Pip
  • Group: Members
  • Posts: 52
  • Joined: 24-May 08
  • OS:XP Pro x86
  • Country: Country Flag

Posted 30 June 2012 - 07:47 AM

Quote

Which svchost is accessing the Exchange server


note sure what you mean by "which", since svchost.exe is a system process . Did you mean to ask if svchost is running as which user[NETWORK SERVICE, SYSTEM] ?


Quote

what exactly is it accessing


That is a mystery to me too. I'm was able to see the exe downloading data through comodo firewall. By seeing the destination IP, i concluded it was accessing the exchange server. [I have no other
software/tool which would access that particular IP].


Quote

Does it leave any event log entries on either side

I don't have access to the other side. On my side , i checked the windows logs part in event log. The apps and services logs were way too big. Is there any specific folder/application where i can find the details ?

#4 User is offline   cluberti 

  • Gustatus similis pullus
  • Group: Supervisor
  • Posts: 11,208
  • Joined: 09-September 01
  • OS:Windows RT
  • Country: Country Flag

Posted 30 June 2012 - 03:46 PM

View Postnewprouser, on 30 June 2012 - 07:47 AM, said:

Quote

Which svchost is accessing the Exchange server


note sure what you mean by "which", since svchost.exe is a system process . Did you mean to ask if svchost is running as which user[NETWORK SERVICE, SYSTEM] ?
There are more than 1 svchost process - I was curious as to which one was doing the downloading.

#5 User is offline   Tripredacus 

  • K-Mart-ian Legend
  • Group: Super Moderator
  • Posts: 8,665
  • Joined: 28-April 06
  • OS:Server 2012
  • Country: Country Flag

Posted 02 July 2012 - 07:58 AM

What are you using to know that svchost.exe is downloading data from Exchange?

#6 User is offline   newprouser 

  • Junior
  • Pip
  • Group: Members
  • Posts: 52
  • Joined: 24-May 08
  • OS:XP Pro x86
  • Country: Country Flag

Posted 03 July 2012 - 03:37 AM

View PostTripredacus, on 02 July 2012 - 07:58 AM, said:

What are you using to know that svchost.exe is downloading data from Exchange?



There is a feature in Comodo Firewall program to list all the active connection. I used it to find about svchost.exe accessing exchange server.

#7 User is online   allen2 

  • Not really Newbie
  • PipPipPipPipPipPipPip
  • Group: Members
  • Posts: 1,733
  • Joined: 13-January 06

Posted 03 July 2012 - 12:51 PM

Try using process explorer to check which services (usually many services use the same svchost process) are accessing your exchange server.

#8 User is offline   newprouser 

  • Junior
  • Pip
  • Group: Members
  • Posts: 52
  • Joined: 24-May 08
  • OS:XP Pro x86
  • Country: Country Flag

Posted 04 July 2012 - 01:57 AM

hi allen2,

as you mentioned i'm able to see a dozen processes listed in the svchost.exe accessing the exchange server ... I have attached a screenshot displaying them...

I have that BITS can be used to trasfer data in the background , maybe that could be the culprit ?

Attached File(s)



#9 User is online   allen2 

  • Not really Newbie
  • PipPipPipPipPipPipPip
  • Group: Members
  • Posts: 1,733
  • Joined: 13-January 06

Posted 04 July 2012 - 01:04 PM

Some of those services can be stopped then restarted without causing problems and this way you could check if the issue is still there after stopping each one and thus removing one possible culprit. Here is the list of the services i'd try in the order of the most probable to the less :
BITS
wuauserv
schedule
lanman server
browser
Hope this help. If you don't find it this way, you could try this way to make each service use a different process.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2013 msfn.org
Privacy Policy