Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 20, 2013, 01:28:59 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
669183
Posts
71153
Topics
145755
Members
Latest Member:
kenix
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
Help - CIS
Defense+ / Sandbox Help - CIS
System is trying to modify ...
« previous
next »
Pages:
[
1
]
2
Author
Topic: System is trying to modify ... (Read 5565 times)
cska133
Comodo's Hero
Offline
Posts: 297
System is trying to modify ...
«
on:
March 11, 2012, 06:03:55 PM »
I wanted to go to bed and switch the PC when in the middle of the sutting dowm Difense+ popped upsomething about that system is traying to modufy/creat folder... then PC went off.
I was curious and suspicious and started PC again. Then Defense+ popped up again (see screenshots).
I didnt take any action in Comodo.
Since then my Wifi is crashing every minute (it looses connectivity) after it connets again
whats is going on???
PC: the last popup System2 is coming every 10min
system.png
(32.82 KB, 387x458 - viewed 48 times.)
System-log.png
(13.54 KB, 981x118 - viewed 26 times.)
system2.png
(30.26 KB, 391x454 - viewed 41 times.)
«
Last Edit: March 11, 2012, 06:18:41 PM by cska133
»
Logged
aim4it
Comodo Family Member
Offline
Posts: 92
Re: System is trying to modify ...
«
Reply #1 on:
March 12, 2012, 10:04:27 AM »
I had a similar problem, getting a protect file popup for shutdown.etl even when I had automatically create rules of safe applications checked. I manually had to edit the auto generated rule and gave it access to the entire LogFile/* directory.
Logged
cska133
Comodo's Hero
Offline
Posts: 297
Re: System is trying to modify ...
«
Reply #2 on:
March 12, 2012, 11:26:54 AM »
yes exactly, when I shotdown Comodo pops up something about shutdown.etl. Then it pops up every 10min that system is trying to modify the conteds of C:\Windows
I dont know why all this popups are coming suddenlly, nothing has changed yesterday
Quote
I manually had to edit the auto generated rule and gave it access to the entire LogFile/* directory.
How you did this?
PS: I tried to repair Comodo via Control Panel, but the option for repair is greyed out and not active
Is this normal?
Logged
aim4it
Comodo Family Member
Offline
Posts: 92
Re: System is trying to modify ...
«
Reply #3 on:
March 12, 2012, 12:31:03 PM »
I'll check my defense+ rules when I get home, at my university at the moment.
Logged
cska133
Comodo's Hero
Offline
Posts: 297
Re: System is trying to modify ...
«
Reply #4 on:
March 12, 2012, 04:43:04 PM »
the popup is coming every 10min.
Dont know to allow or to block? If I create rule where should I find this rule for editing or removing it later?
Logged
clockwork
Comodo's Hero
Offline
Posts: 1942
Oxygen requires Chuck Norris to live
Re: System is trying to modify ...
«
Reply #5 on:
March 13, 2012, 01:50:41 AM »
In defense +, computer security settings.
But wait.
If you control the allready existing list, you may notice the entry "system" under "windows system applications" as a predefined rule. This rule would allow the real system "file" to modify folders and so on. You should not get that question!
Thats why i would say: Click on the file name on top in the question window that you get all ten minutes, to verify where the file is located.
And until this situation is cleared up, its very suspicious that you get a question about a system "file", which would have been covered by an existing rule for the original allready!
Logged
"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
aim4it
Comodo Family Member
Offline
Posts: 92
Re: System is trying to modify ...
«
Reply #6 on:
March 13, 2012, 09:24:06 AM »
If you run Defense+ in paranoid mode you will get this popup, even with automatically create rules for trusted applications checked. My guess is the shutdown action changes the state of CIS and rules cannot be created during the shutdown process, hence this popup occurs and the rule can't be automatically learned.
Although I never got the popup for \System, just for a few .etl files windows tries to update with during the shutdown event.
«
Last Edit: March 13, 2012, 09:26:02 AM by aim4it
»
Logged
cska133
Comodo's Hero
Offline
Posts: 297
Re: System is trying to modify ...
«
Reply #7 on:
March 13, 2012, 11:16:36 AM »
I run Defense+ in Safe mode.
Quote
Thats why i would say: Click on the file name on top in the question window that you get all ten minutes, to verify where the file is located.
I know that. Look on the 3rd screenshot in my first post. When I clicked on System there I thing it came the properties windows pointing to C:\Windows. I am not sure, have to look again when I am home later. On the second icon on the popup I can not click.
It is strange because as I alredy asked in
http://forums.comodo.com/install-setup-configuration-help-cis/how-can-i-repair-cis-t82802.0.html
my Repair option is greayed out and can not be repaired
Logged
clockwork
Comodo's Hero
Offline
Posts: 1942
Oxygen requires Chuck Norris to live
Re: System is trying to modify ...
«
Reply #8 on:
March 13, 2012, 05:21:52 PM »
As you use safe mode, you should not get a question about the REAL system "file".
Can you verify that you have the predefined rule section for windows applications in the defense+ list? There are greyed things listed, like system, %windir%\system32\svchost.exe, ....
Logged
"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
BoredNow
Comodo's Hero
Offline
Posts: 344
Re: System is trying to modify ...
«
Reply #9 on:
March 13, 2012, 07:56:48 PM »
Take a look at this...
http://serverfault.com/questions/237637/what-is-stored-in-windir-system32-logfiles-wmi-rtbackup
if anyone would like to 'translate' this into simple english that would be nice.
Also, take a look a my thread from last Oct.
https://forums.comodo.com/defense-sandbox-help-cis/system-could-not-be-recognized-t78016.0.html;msg557902#msg557902
«
Last Edit: March 13, 2012, 08:02:46 PM by BoredNow
»
Logged
HP pavilion media center 2006
Windows 7 64bit - Standard Acct.
EMET 3
CIS-5.10
Sandboxie 3.76
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4068
Re: System is trying to modify ...
«
Reply #10 on:
March 13, 2012, 09:05:00 PM »
Quote from: BoredNow on March 13, 2012, 07:56:48 PM
Take a look at this...
http://serverfault.com/questions/237637/what-is-stored-in-windir-system32-logfiles-wmi-rtbackup
if anyone would like to 'translate' this into simple english that would be nice.
I think he's just trying to illustrate the mechanism behind data collection for etl files, which are a standard part of the OS performance and reliability ecosystem. I think the reason D+ has a problem with these, sometimes, is when a a trace file is created with a new name, but that would need further investigation...
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
cska133
Comodo's Hero
Offline
Posts: 297
Re: System is trying to modify ...
«
Reply #11 on:
March 14, 2012, 05:32:37 PM »
Quote
Can you verify that you have the predefined rule section for windows applications in the defense+ list? There are greyed things listed, like system, %windir%\system32\svchost.exe
where exactly do I have to look, could you please explain (maybe with Screenshot better)
thanks
Logged
clockwork
Comodo's Hero
Offline
Posts: 1942
Oxygen requires Chuck Norris to live
Re: System is trying to modify ...
«
Reply #12 on:
March 15, 2012, 10:58:02 AM »
Defense+ rules list
There are your games, programs ect listed with notification about what kind of rules they got (custom, trusted, blocked).
Scroll down until you see the entry tree "windows system applications". Its a collapseable tree entry. It contains:
system
%windir%\system32\svchost.exe
%windir%\system32\services.exe
%windir%\system32\smss.exe
and so on
Do you have it?
The predefined policy "windows system applications" which these entries under the same name tree in the defense+ list have, allows to modify, allows everything apart from starting other files without question under safe mode.
Thats why i have doubts, that your question is about the real system "file", when you have that tree in the defense+ rule list (default).
«
Last Edit: March 15, 2012, 11:07:33 AM by clockwork
»
Logged
"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
BoredNow
Comodo's Hero
Offline
Posts: 344
Re: System is trying to modify ...
«
Reply #13 on:
March 15, 2012, 02:19:41 PM »
Sorry to jump in here but since I have been getting the same "System can not be recognized" warning.
Please take a look at these screen shots...I no longer have any Predefined Policies since the latest
update...(5.10)
Capture1.JPG
(49.21 KB, 552x242 - viewed 18 times.)
Capture2.JPG
(24.67 KB, 688x245 - viewed 19 times.)
Logged
HP pavilion media center 2006
Windows 7 64bit - Standard Acct.
EMET 3
CIS-5.10
Sandboxie 3.76
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 7521
Re: System is trying to modify ...
«
Reply #14 on:
March 17, 2012, 05:05:06 AM »
Quote from: BoredNow on March 15, 2012, 02:19:41 PM
Sorry to jump in here but since I have been getting the same "System can not be recognized" warning.
Please take a look at these screen shots...I no longer have any Predefined Policies since the latest
update...(5.10)
Does anyone else with this problem have no predefined policies?
If so its probably some form of update problem.
I'd suggest a bare metal re-installation as per Chiron's FAQ:
Most effective way to re-install
.
Best wishes
Mouse
Logged
Please see the
Introduction to the sandbox
.
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.052 seconds with 23 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com