I set svchost.exe to allow and log so i could see where it was going else it would be listed as a windows system application i didn’t just allow all outbound connections and i don’t just set random rules just for the hell of it. It asked for an incoming connection and as i didn’t know why i blocked it, if you are telling me that i should have just allowed it then i don’t think you should be giving advice out on this forum.

essexboy thank you very, very much for your help, much appreciated.

We really need someone who knows the comodo firewall - I have just checked my AIS settings and svchost is under system

I have just revisited the CF log as it shows open ports and all I found was this one legitimate item

[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
“AllowInboundEchoRequest”= 1 (0x1)

It is a legitimate windows process however, it can be disabled http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/hnw_icmp_disable.mspx?mfr=true