Repeated svchost.exe firewall alerts

I upgraded to NIS 2012 today as I was sick of my CPU being hammered during & after idle due to the infamous ccsvchst.exe bug.

 

Now I have a new problem in that I'm being presented with regular security alerts due to svchost.exe, informing me that:

 

"Host Process for Windows Services is attempting to access the Internet. - This program has been modified since it was last Used."

 

The path for the exe is correct (C:\Windows\System32\) and it's not infected (my system is perfectly fine).

 

I've set the firewall rule repeatedly to "Allow always" and have even tried setting up a custom rule to allow outbound access only but I'm still being presented with these annoying alerts every 5-10 minutes or so (I presume from running Firefox).

 

I can only assume that I'm getting this repeatedly because Norton thinks the exe has been modified and therefore the user should be asked to confirm the firewall rule that was used for the last known version of the exe. This is normally useful, but in this case, it's setting off a problem that I can't fix!

 

I don't want to use or turn on "Automatic Program Control" in the firewall settings as, frankly, I dont trust it and I like having complete control over my system.

 

Does anyone know how I can fix this or add an exception to NIS so that it just ignores internet activity for C:\Windows\System32\svchost.exe?