- Apr 13, 2013
- 3,224
svchost is utilized by many applications, including various types of malware. For CF, if it is spawned by something either malicious or just Unknown it will also be contained as will any command line arguments that can arise from it (similar to any Lolbin); thus specific restrictions are not needed and should not be done.Also regarding my question about svchost, that a safe rule would be ignored if the parent process was malware, correct?
Aside from blocking Network access for any application that (for whatever reason) one does not want to call Home, further rules should be avoided.