Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 20, 2013, 04:27:33 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663157
Posts
70501
Topics
145157
Members
Latest Member:
Cobalt60
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
Help - CIS
Defense+ / Sandbox Help - CIS
Need some Defense+ help please...
« previous
next »
Pages:
[
1
]
2
Author
Topic: Need some Defense+ help please... (Read 3443 times)
aguyonapc
Newbie
Offline
Posts: 13
Need some Defense+ help please...
«
on:
February 20, 2012, 09:06:06 PM »
I have some folders blocked (Computer Security Policy -> Blocked Files) and when I look in the defense+ events list I see many programs trying to access them. explorer.exe, notepad.exe, iexplorer.exe, and some other programs I've installed are all trying to access the blocked folders. Anyone know what may be going on here? I'm running Windows7 64bit.
Logged
aguyonapc
Newbie
Offline
Posts: 13
Re: Need some Defense+ help please...
«
Reply #1 on:
February 21, 2012, 01:02:03 PM »
Does anyone know what's going on here?
It may or may not be a big deal, but it's got me curious.
Maybe my first post didn't fully explain.
In Defense+ -> View Defense+ Events I see...
Application: C:\Windows\explorer.exe
Flags: Block File
Target: target is the blocked folder
I'm also seeing iexplore.exe, notepad.exe, and some other programs like photoshop giving the same thing.
I can't figure out what is causing it. The ones that have me most confused are notepad.exe and iexplore.exe as I have no idea why they'd be trying to access my folders.
«
Last Edit: February 21, 2012, 01:05:31 PM by aguyonapc
»
Logged
aguyonapc
Newbie
Offline
Posts: 13
Re: Need some Defense+ help please...
«
Reply #2 on:
February 24, 2012, 01:34:15 PM »
So far, the programs that have tried to access the blocked folders...
explorer.exe
iexplore.exe
notepad.exe
wmplayer.exe
photoshop.exe (and some other art software I use)
Azureus.exe
cfplogvw.exe
Is there a reason these programs should try to access blocked folders? Some of them at seemingly random times? Photoshop and other art software I can understand, and they only do it when I open them. Wmplayer and Vuze only do it when I open them too, but I'm not sure why. The other programs I do not understand why they would try to access a blocked folder.
Logged
clockwork
Comodo's Hero
Offline
Posts: 1919
Oxygen requires Chuck Norris to live
Re: Need some Defense+ help please...
«
Reply #3 on:
February 27, 2012, 10:05:32 AM »
Quote from: aguyonapc on February 24, 2012, 01:34:15 PM
explorer.exe
iexplore.exe
notepad.exe
wmplayer.exe
photoshop.exe (and some other art software I use)
Azureus.exe
cfplogvw.exe
Is there a reason these programs should try to access blocked folders?
Important would be, which folders? And why did you block them?
Logged
"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
aguyonapc
Newbie
Offline
Posts: 13
Re: Need some Defense+ help please...
«
Reply #4 on:
February 27, 2012, 11:32:49 PM »
Well they are folders on my work partition containing my work files and stuff.
They're blocked so people can't access them (at least that's the idea).
I'm not sure why something like notepad.exe or iexplore.exe would try to access them.
Logged
Arsh de Grand
Comodo Family Member
Offline
Posts: 64
Helper
Re: Need some Defense+ help please...
«
Reply #5 on:
February 28, 2012, 01:37:45 PM »
umm it seams you got key-logger or rootkit in your system . or may be its just normal .
Logged
windows 7 ultimate x64 l KIS 12 l CCC l Intel i5 l HD 500 GB l RAM 4 GB DDR3
Graphic ATI Mobility Radeon HD 5470 1 GB l Google chrome l mawarebytes l hitman pro.
clockwork
Comodo's Hero
Offline
Posts: 1919
Oxygen requires Chuck Norris to live
Re: Need some Defense+ help please...
«
Reply #6 on:
February 28, 2012, 05:45:29 PM »
Quote from: Arsh de Grand on February 28, 2012, 01:37:45 PM
umm it seams you got key-logger or rootkit in your system . or may be its just normal .
One of the most random answers i have seen
Quote from: aguyonapc on February 27, 2012, 11:32:49 PM
Well they are folders on my work partition containing my work files and stuff.
They're blocked so people can't access them (at least that's the idea).
You should not use a host intrusion program to manage access to folders for people who are using your computer. Have you tested the effectivity, and the possible side effects? Better use something like truecrypt.
Quote from: aguyonapc on February 27, 2012, 11:32:49 PM
I'm not sure why something like notepad.exe or iexplore.exe would try to access them.
I can not explain this. Just in case, make a virus scan.
When did this start?
Logged
"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
John Buchanan
The greatest victory comes from the battle within.
Global Moderator
Comodo's Hero
Offline
Posts: 5419
Personal Dragons can be defeated. Improve yourself
Re: Need some Defense+ help please...
«
Reply #7 on:
February 28, 2012, 06:26:41 PM »
" One of the most random answers i have seen"
Forgive. No disrespect intended.
but ROFL! It just came out funny.
«
Last Edit: February 28, 2012, 06:33:28 PM by John Buchanan
»
Logged
Please follow
Comodo Forum Policy
aguyonapc
Newbie
Offline
Posts: 13
Re: Need some Defense+ help please...
«
Reply #8 on:
February 29, 2012, 03:56:51 PM »
Quote from: clockwork on February 28, 2012, 05:45:29 PM
You should not use a host intrusion program to manage access to folders for people who are using your computer. Have you tested the effectivity, and the possible side effects? Better use something like truecrypt.
It's just something I do sometimes when a certain person may be near my pc. She would have no idea how to get around it. I know it's not the best way, but it's quick.
Quote from: clockwork on February 28, 2012, 05:45:29 PM
I can not explain this. Just in case, make a virus scan.
When did this start?
I'm not sure exactly when it started.
I noticed it a few weeks ago, but I wasn't really paying attention to things at the time.
I have scanned with a bunch of scanners (Malwarebytes, Superantispyware, ESET Online, Hitman Pro, Bit Defender, ect...). None show anything. Have also done a rootkit scan (gmer) but don't know how to interpret the results.
Logged
clockwork
Comodo's Hero
Offline
Posts: 1919
Oxygen requires Chuck Norris to live
Re: Need some Defense+ help please...
«
Reply #9 on:
February 29, 2012, 05:39:47 PM »
If a person who uses a security product would need to block "files" without indication, to notice an infection by locking in the logs of these volunteer blocks, we would be lost
(I dont exclude possibillities with this. Just say, we would be lost
)
Did you use your "art software" for something in those folders? What happens if you move these folders, or giving them other names?
Quote from: aguyonapc on February 24, 2012, 01:34:15 PM
Is there a reason these programs should try to access blocked folders?
The programs dont know that these folders are blocked. The question should be: What function do these programs have to access folders, and when are they doing this?
True crypt is free. You could inform yourself about its benefits.
Logged
"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
aguyonapc
Newbie
Offline
Posts: 13
Re: Need some Defense+ help please...
«
Reply #10 on:
February 29, 2012, 06:54:31 PM »
Quote from: clockwork on February 29, 2012, 05:39:47 PM
The question should be: What function do these programs have to access folders, and when are they doing this?
That's more or less what I need to know... why would they do this?
I can understand why photoshop and stuff like that might want to access the files.
notepad.exe and iexplore.exe are the ones that have me most curious as I can't think of a reason.
I do use TrueCrypt for some things, but just blocking folders through Comodo is quick and easy.
Maybe I should just stop doing it that way.
«
Last Edit: February 29, 2012, 06:56:27 PM by aguyonapc
»
Logged
clockwork
Comodo's Hero
Offline
Posts: 1919
Oxygen requires Chuck Norris to live
Re: Need some Defense+ help please...
«
Reply #11 on:
March 02, 2012, 04:57:24 PM »
Quote from: clockwork on February 29, 2012, 05:39:47 PM
What happens if you move these folders, or giving them other names?
That way we would at least know if they try to access them still, and when this would start.
Logged
"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
aguyonapc
Newbie
Offline
Posts: 13
Re: Need some Defense+ help please...
«
Reply #12 on:
March 02, 2012, 06:08:35 PM »
If I try to move a blocked folder I get this D+ event...
Application: C:\Windows\explorer.exe
Flags: Block File
Target: target is the blocked folder
I also get a windows message saying 'Folder Access Denied'.
If I click on 'Continue' and put in my admin password I get this...
Application: C:\Windows\System32\dllhost.exe
Flags: Block File
Target: target is the blocked folder
I will unblock the folders, rename them, and then block them again to see what happens.
It seems to be happening to any folder I block with comodo.
Logged
clockwork
Comodo's Hero
Offline
Posts: 1919
Oxygen requires Chuck Norris to live
Re: Need some Defense+ help please...
«
Reply #13 on:
March 02, 2012, 07:23:53 PM »
No, i meant, move the folders or rename them, so we can see the behaviour of the files that try to access them.
If nothing is logged then, the files had a specific "reason".
Of course, dont forget to make the rules for that path too
Logged
"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
aguyonapc
Newbie
Offline
Posts: 13
Re: Need some Defense+ help please...
«
Reply #14 on:
March 02, 2012, 09:00:44 PM »
So far I have no new entries in my D+ log since renaming the folders.
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.056 seconds with 23 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com