Welcome, Guest. Please login or register.
Did you miss your activation email?
June 20, 2013, 01:28:59 AM

Login with username, password and session length

669183 Posts
71153 Topics
145755 Members

Latest Member: kenix

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Defense+ / Sandbox Help - CIS
| | | | |-+  System is trying to modify ...
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: System is trying to modify ...  (Read 5565 times)
cska133
Comodo's Hero
*****
Offline Offline

Posts: 297


System is trying to modify ...
« on: March 11, 2012, 06:03:55 PM »

I wanted to go to bed and switch the PC when in the middle of the sutting dowm Difense+ popped upsomething about that system is traying to modufy/creat folder... then PC went off.
I was curious and suspicious and started PC again. Then Defense+ popped up again (see screenshots).
I didnt take any action in Comodo.
Since then my Wifi is crashing every minute (it looses connectivity) after it connets again

whats is going on???


PC: the last popup System2 is coming every 10min


* system.png (32.82 KB, 387x458 - viewed 48 times.)

* System-log.png (13.54 KB, 981x118 - viewed 26 times.)

* system2.png (30.26 KB, 391x454 - viewed 41 times.)
« Last Edit: March 11, 2012, 06:18:41 PM by cska133 » Logged
aim4it
Comodo Family Member
***
Offline Offline

Posts: 92


Re: System is trying to modify ...
« Reply #1 on: March 12, 2012, 10:04:27 AM »

I had a similar problem, getting a protect file popup for shutdown.etl even when I had automatically create rules of safe applications checked.  I manually had to edit the auto generated rule and gave it access to the entire LogFile/* directory.
Logged
cska133
Comodo's Hero
*****
Offline Offline

Posts: 297


Re: System is trying to modify ...
« Reply #2 on: March 12, 2012, 11:26:54 AM »

yes exactly, when I shotdown Comodo pops up  something about shutdown.etl. Then it pops up every 10min that system is trying to modify the conteds of C:\Windows

I dont know why all this popups are coming suddenlly, nothing has changed yesterday Huh

Quote
I manually had to edit the auto generated rule and gave it access to the entire LogFile/* directory.
How you did this?

PS: I tried to repair Comodo via Control Panel, but the option for repair is greyed out and not active Huh Huh Huh Is this normal?Huh
Logged
aim4it
Comodo Family Member
***
Offline Offline

Posts: 92


Re: System is trying to modify ...
« Reply #3 on: March 12, 2012, 12:31:03 PM »

I'll check my defense+ rules when I get home, at my university at the moment.
Logged
cska133
Comodo's Hero
*****
Offline Offline

Posts: 297


Re: System is trying to modify ...
« Reply #4 on: March 12, 2012, 04:43:04 PM »

the popup is coming every 10min.
Dont know to allow or to block? If I create rule where should I find this rule for editing or removing it later?
Logged
clockwork
Comodo's Hero
*****
Offline Offline

Posts: 1942


Oxygen requires Chuck Norris to live


Re: System is trying to modify ...
« Reply #5 on: March 13, 2012, 01:50:41 AM »

In defense +, computer security settings.

But wait.
If you control the allready existing list, you may notice the entry "system" under "windows system applications" as a predefined rule. This rule would allow the real system "file" to modify folders and so on. You should not get that question!

Thats why i would say: Click on the file name on top in the question window that you get all ten minutes, to verify where the file is located.
And until this situation is cleared up, its very suspicious that you get a question about a system "file", which would have been covered by an existing rule for the original allready!
Logged

"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
aim4it
Comodo Family Member
***
Offline Offline

Posts: 92


Re: System is trying to modify ...
« Reply #6 on: March 13, 2012, 09:24:06 AM »

If you run Defense+ in paranoid mode you will get this popup, even with automatically create rules for trusted applications checked.  My guess is the shutdown action changes the state of CIS and rules cannot be created during the shutdown process, hence this popup occurs and the rule can't be automatically learned.

Although I never got the popup for \System, just for a few .etl files windows tries to update with during the shutdown event.
« Last Edit: March 13, 2012, 09:26:02 AM by aim4it » Logged
cska133
Comodo's Hero
*****
Offline Offline

Posts: 297


Re: System is trying to modify ...
« Reply #7 on: March 13, 2012, 11:16:36 AM »

I run Defense+ in Safe mode.

Quote
Thats why i would say: Click on the file name on top in the question window that you get all ten minutes, to verify where the file is located.
I know that. Look on the 3rd screenshot in my first post. When I clicked on System there I thing it came the properties windows pointing to C:\Windows. I am not sure, have to look again when I am home later. On the second icon on the popup I can not click.

It is strange because as I alredy asked in http://forums.comodo.com/install-setup-configuration-help-cis/how-can-i-repair-cis-t82802.0.html my Repair option is greayed out and can not be repaired
Logged
clockwork
Comodo's Hero
*****
Offline Offline

Posts: 1942


Oxygen requires Chuck Norris to live


Re: System is trying to modify ...
« Reply #8 on: March 13, 2012, 05:21:52 PM »

As you use safe mode, you should not get a question about the REAL system "file".
Can you verify that you have the predefined rule section for windows applications in the defense+ list? There are greyed things listed, like system, %windir%\system32\svchost.exe, ....
Logged

"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
BoredNow
Comodo's Hero
*****
Offline Offline

Posts: 344



Re: System is trying to modify ...
« Reply #9 on: March 13, 2012, 07:56:48 PM »

Take a look at this...

http://serverfault.com/questions/237637/what-is-stored-in-windir-system32-logfiles-wmi-rtbackup

if anyone would like to 'translate' this into simple english that would be nice.

Also, take a look a my thread from last Oct.

https://forums.comodo.com/defense-sandbox-help-cis/system-could-not-be-recognized-t78016.0.html;msg557902#msg557902
« Last Edit: March 13, 2012, 08:02:46 PM by BoredNow » Logged

HP pavilion media center 2006
Windows 7 64bit - Standard Acct.
EMET 3
CIS-5.10
Sandboxie 3.76
Radaghast
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 4068



Re: System is trying to modify ...
« Reply #10 on: March 13, 2012, 09:05:00 PM »

Take a look at this...

http://serverfault.com/questions/237637/what-is-stored-in-windir-system32-logfiles-wmi-rtbackup

if anyone would like to 'translate' this into simple english that would be nice.

I think he's just trying to illustrate the mechanism behind data collection for etl files, which are a standard part of the OS performance and reliability ecosystem. I think the reason D+ has a problem with these, sometimes, is when a a trace file is created with a new name, but that would need further investigation...
Logged

“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
cska133
Comodo's Hero
*****
Offline Offline

Posts: 297


Re: System is trying to modify ...
« Reply #11 on: March 14, 2012, 05:32:37 PM »

Quote
Can you verify that you have the predefined rule section for windows applications in the defense+ list? There are greyed things listed, like system, %windir%\system32\svchost.exe
where exactly do I have to look, could you please explain (maybe with Screenshot better)

thanks
Logged
clockwork
Comodo's Hero
*****
Offline Offline

Posts: 1942


Oxygen requires Chuck Norris to live


Re: System is trying to modify ...
« Reply #12 on: March 15, 2012, 10:58:02 AM »

Defense+ rules list
There are your games, programs ect listed with notification about what kind of rules they got (custom, trusted, blocked).
Scroll down until you see the entry tree "windows system applications". Its a collapseable tree entry. It contains:
system
%windir%\system32\svchost.exe
%windir%\system32\services.exe
%windir%\system32\smss.exe
and so on

Do you have it?

The predefined policy "windows system applications" which these entries under the same name tree in the defense+ list have, allows to modify, allows everything apart from starting other files without question under safe mode.
Thats why i have doubts, that your question is about the real system "file", when you have that tree in the defense+ rule list (default).
« Last Edit: March 15, 2012, 11:07:33 AM by clockwork » Logged

"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
BoredNow
Comodo's Hero
*****
Offline Offline

Posts: 344



Re: System is trying to modify ...
« Reply #13 on: March 15, 2012, 02:19:41 PM »

Sorry to jump in here but since I have been getting the same "System can not be recognized" warning.

Please take a look at these screen shots...I no longer have any Predefined Policies since the latest
update...(5.10)



* Capture1.JPG (49.21 KB, 552x242 - viewed 18 times.)

* Capture2.JPG (24.67 KB, 688x245 - viewed 19 times.)
Logged

HP pavilion media center 2006
Windows 7 64bit - Standard Acct.
EMET 3
CIS-5.10
Sandboxie 3.76
mouse1
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7521


Re: System is trying to modify ...
« Reply #14 on: March 17, 2012, 05:05:06 AM »

Sorry to jump in here but since I have been getting the same "System can not be recognized" warning.

Please take a look at these screen shots...I no longer have any Predefined Policies since the latest
update...(5.10)

Does anyone else with this problem have no predefined policies?

If so its probably some form of update problem.

I'd suggest a bare metal re-installation as per Chiron's FAQ: Most effective way to re-install.

Best wishes

Mouse
Logged

Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.052 seconds with 23 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com