Alert from CNET Staff

 Attention forum users:  We want you to try out the new CNET forums platform! Click here to read the details. Thanks!

Computer help forum: UDP Port 1900 15 times a minute?

by: WildClay September 11, 2010 7:11 AM PDT

Like this

0 people like this thread

Staff pick

UDP Port 1900 15 times a minute?

by WildClay - 9/11/10 7:11 AM

System: HP a362n, 3GHz, 2G RAM (hardware drivers current)
Network: Comcast Broadband (no perforamnce issues on speed tests)
Cable Modem: RCA (no errors)
Router: Cisco WRT54G2 (no errors, updates current)
Nic: RealTec Ethernet
OS: XP Home Edition 2002, SP3 -- MS updates current
Firewall: Norton Internet Security (NIS)
AV: Norton, p/o NIS
MS Defender active.
MS Firewall not active.

Sorry for the long back story, but leads to where I am now, so I thought it might help in answering the actual questions.

I was looking at TeamView client and saw it was the most popular remote support software by CNet downloads, while on their site I ran the light client TeamViewQS.exe to get an idea of what the client side would look like. I don't think it is related to this, but worth mentioning as it is what has lead me to asking about it.

There were so many great reviews, I failed to look at the 8 bad reviews out of over 500 that rated it a 5. After seeing that it looked just right for my need, I decided to read the bad reviews before installing the TeamView Host, these 8 were not kind at all and claimed to brought their machines under attack as soon as they installed it. So I did not install the full TeamView.

Concerned the fast client may have done something, I opened Nortons History to look at the Firewall Activity, and noticed that 15 times a minute, consistantly, I get and inbound UDP packet trying to get to port 1900, the Norton Firewall rule blocks it.

Actions since discovering this in the Norton log:
- Full system Virus scan w/latest signatures
- System Restore to the point before I tried the TeamView Client
- Reviewed System Logs though the event viewer -- Nothing unusual in any of the logs, Security Audits all passed.
- Reviewed Defender Running Programs, nothing out of place
- Reviewed Start-up Programs (Through Defender and TUT) all good
- From cmd box, ran ipconfig /release then /renew
- Verified I got a new IP address
- Rebooted
- Alert stopped in NIS Firewall Logs for a few minutes then started again. (meaning a few minutes after the full boot to where the system was idle)

TUT = The Ultimate Troubleshooter, slightly larger claim than what it does obviously happy

From SystemInternals, TCPView output on this:

Process / Protocol / Local Address / Remote Address / State
svchost.exe:1996 / UDP / / *:* / blank

svchost.exe:1996 / UDP / zzz-zz:1900 / *:* / blank

The state for both is blank, it is not listening or anything else.
Where zzz-zz is my machine name and ss is the state I live in and they are correct.

Given that the NIS firewall is blocking this but I have no issue with my service, I am not sure why comcast is listed or why they might be trying to hit that port every 4 seconds, if that is what it means?

Norton Internet Security Message -- In the log it has "info" status.

Alert Summary:
Info -- Rule "Default Block UPnP Discovery" stealthed (, Port ssdp(1900). Inbound UDP packet. - Date & Time - Status: Detected -- Action: None required. Blocked.


Advanced Details (NIS Label):
Category - Firewall - Activities
Rule - "Default Block UPnP Discovery" stealthed (, Port ssdp(1900). Ibound UDP packet.
Local Address, service is (, Port ssdp(1900) ).
Remote Address, service is (, Port(2240) ).
Process Name is "C:\WINDOWS\system32\svchost.exe".


Looking at my TCP/IP Port Connections I see this listed:
Protocol: UDP
Local IP: (my IP address after the renew)
Local Port: 1900
Remote IP: blank
Remote Port: blank
Remote Host Name: blank
State: blank (for other things it is Listen or Established...)
Process: svchost.exe


Q1. Does any one know why I would be getting this attempt to reach this UDP Port 15 times a minues, every 4 seconds?

I have no issues with internet performance, system performance, no errors in any logs, passed full system scan.

Q2. If this is from Comcast, should I allow this in NIS and in Defender?

Q3. If NIS is blocking this every 4 seconds I would think just the logging alone must be nipping some performance, even if I am not seeing it, so if I allowed it from Comcast, should I make explicit to them and still block all others? This would stop the blocking and logging for anything but Comcast.

Q4. I noticed when I brought up Network Setup Wizard by mistake instead of Network connections, that MS Defender detects an attempt to make a registry change to enable the port by the same instance of svchost.exe, to which I can pick Allow or Deny. I did not go into the Set-Up Wizard, just the do you want to panel at the start up of it.

Is this needed for anything if my network is already set-up and running?

Q5. Should I block this at my router, and if so, what exactly should I set up to block?

Thanks for any info, I hunted around and got all kinds of answers but no "theme" so I have no idea which one is right, except that it is a network discovery service similar to PnP for hardware, auto-detection and config of network stuff?

Some say disable it, it is a network discovery service XP starts but is not needed, others say it is other PC's on my Comcast network "loop" doing some kind of broadcast, and others say never disable it or you will have issues and the list of the alleged issues vary from person to person.

So I am hoping the right answers are here, again thanks and sorry for the long read.

Forum Icon Legend

  • UnreadUnread
  • ReadRead
  • Locked threadLocked thread
  • ModeratorModerator
  • CNET StaffCNET Staff
  • Samsung StaffSamsung Staff
  • Norton Authorized Support TeamNorton Authorized Support Team
  • AVG StaffAVG Staff
  • avast! Staffavast! Staff
  • Webroot Support TeamWebroot Support Team
  • Acer Customer Experience TeamAcer Customer Experience Team
  • Windows Outreach TeamWindows Outreach Team
  • DISH staffDISH staff
  • Dell StaffDell Staff
  • Intel StaffIntel Staff
  • QuestionQuestion
  • Resolved questionResolved question
  • General discussionGeneral discussion
  • TipTip
  • Alert or warningAlert or warning
  • PraisePraise
  • RantRant

You are e-mailing the following post: Post Subject

Your e-mail address is used only to let the recipient know who sent the e-mail and in case of transmission error. Neither your address nor the recipient's address will be used for any other purpose.

Sorry, there was a problem emailing this post. Please try again.

Submit Email Cancel

Thank you. Sent email to


Thank you. Sent email to


You are reporting the following post: Post Subject

If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.

Offensive: Sexually explicit or offensive language

Spam: Advertisements or commercial links

Disruptive posting: Flaming or offending other users

Illegal activities: Promote cracked software, or other illegal content

Sorry, there was a problem submitting your post. Please try again.

Submit Report Cancel

Your message has been submitted and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.


Your message has been submitted and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.


You are posting a reply to: Post Subject

The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to the CNET Forums policies for details. All submitted content is subject to CBS Interactive Site Terms of Use.

You are currently tracking this discussion. Click here to manage your tracked discussions.

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

Sorry, there was a problem submitting your post. Please try again.

Sorry, there was a problem generating the preview. Please try again.

Duplicate posts are not allowed in the forums. Please edit your post and submit again.

Submit Reply Preview Cancel

Thank you, , your post has been submitted and will appear on our site shortly.