Welcome, Guest. Please login or register.
March 19, 2010, 06:48:32 PM

Login with username, password and session length

373014 Posts
41370 Topics
94044 Members

Latest Member: megatrom

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Defense+ / Sandbox Help - CIS
| | | | |-+  D+ event ... services.exe modifying registry key
« previous next »
Pages: [1] Go Down Print
Author Topic: D+ event ... services.exe modifying registry key  (Read 1282 times)
piattj
Newbie
*
Offline Offline

Posts: 4


« on: December 07, 2009, 08:30:14 AM »

Hi

I am new to this forum but recognise the talent in the pool.

I see the Comodo summary showing a number of suspicious attempts blocked by D+ each day and in D+ tab I see a lot of events relating to services.exe modifying registry key, ie...
services.exe ...modify key...HKLM\SYSTEM\ControlSet001\services\BITS\start.

My question is... does this represent a security issue? Is D+ acting in a valid / appropriate way or should this action be allowed? If so, how and why?

Thanks!
Logged
piattj
Newbie
*
Offline Offline

Posts: 4


« Reply #1 on: December 15, 2009, 12:19:33 PM »

Any views or advice on this topic please? Thanks...

...D+ logs a number of suspicious attempts blocked by D+ each day and these events relate to services.exe modifying registry key ...services.exe trying to modify the key HKLM\SYSTEM\ControlSet001\services\BITS\start.

My question is... does this represent a security issue? Is D+ acting in a valid / appropriate way or should this action be allowed? If so, how and why?
Logged
piattj
Newbie
*
Offline Offline

Posts: 4


« Reply #2 on: December 15, 2009, 12:40:20 PM »

D+ logfile entries as below... any advice? Please?

Date/Time   Application   Action   Target
15-Dec-09 8:27:54 AM   C:\Windows\System32\services.exe   Modify Key   HKLM\SYSTEM\ControlSet001\services\BITS\Start
15-Dec-09 8:28:07 AM   C:\Windows\System32\services.exe   Modify Key   HKLM\SYSTEM\ControlSet001\services\BITS\Start
15-Dec-09 8:35:43 AM   C:\Windows\System32\services.exe   Modify Key   HKLM\SYSTEM\ControlSet001\services\BITS\Start
15-Dec-09 10:37:28 AM   C:\Windows\System32\services.exe   Modify Key   HKLM\SYSTEM\ControlSet001\services\BITS\Start
15-Dec-09 10:37:55 AM   C:\Windows\System32\services.exe   Modify Key   HKLM\SYSTEM\ControlSet001\services\BITS\Start
15-Dec-09 10:47:55 AM   C:\Windows\System32\services.exe   Modify Key   HKLM\SYSTEM\ControlSet001\services\BITS\Start
15-Dec-09 10:57:55 AM   C:\Windows\System32\services.exe   Modify Key   HKLM\SYSTEM\ControlSet001\services\BITS\Start
15-Dec-09 11:07:55 AM   C:\Windows\System32\services.exe   Modify Key   HKLM\SYSTEM\ControlSet001\services\BITS\Start
15-Dec-09 11:17:55 AM   C:\Windows\System32\services.exe   Modify Key   HKLM\SYSTEM\ControlSet001\services\BITS\Start
15-Dec-09 11:27:55 AM   C:\Windows\System32\services.exe   Modify Key   HKLM\SYSTEM\ControlSet001\services\BITS\Start
15-Dec-09 11:37:55 AM   C:\Windows\System32\services.exe   Modify Key   HKLM\SYSTEM\ControlSet001\services\BITS\Start
15-Dec-09 11:47:55 AM   C:\Windows\System32\services.exe   Modify Key   HKLM\SYSTEM\ControlSet001\services\BITS\Start
15-Dec-09 11:57:55 AM   C:\Windows\System32\services.exe   Modify Key   HKLM\SYSTEM\ControlSet001\services\BITS\Start
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2001


The only thing i ask for are eggs.


WWW
« Reply #3 on: December 15, 2009, 02:27:03 PM »

Are you on windows 7?
Logged
piattj
Newbie
*
Offline Offline

Posts: 4


« Reply #4 on: December 16, 2009, 12:09:57 PM »

Yes, Win7 Professional (64 bit)...
Logged
SS26
Comodo's Hero
*****
Offline Offline

Posts: 1666


« Reply #5 on: December 16, 2009, 12:59:51 PM »

If i'm right BITS is a legitimate system service named Background Intilligent Transfer Service.  It should not be blocked by Def+.  If You do not trust this system service, it can be switched off with the help of Windows Control panel applet.

To get rid of Def+ block rule for this service:
- backup current Comodo config: main program window > Miscellaneous > Managing config > export config which is active;

- then: main program window > Defense+ > advanced > Computer security policy > locate entry %windir%\system32\services.exe > Edit > access rights > protected registry keys > modify > blocked exceptions > delete corresponding entry (HKLM\SYSTEM\ControlSet001\services\BITS\Start);
Logged
Creasy
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 858


I'm watching you.


« Reply #6 on: December 17, 2009, 01:24:55 AM »

Hi

I am new to this forum but recognise the talent in the pool.

I see the Comodo summary showing a number of suspicious attempts blocked by D+ each day and in D+ tab I see a lot of events relating to services.exe modifying registry key, ie...
services.exe ...modify key...HKLM\SYSTEM\ControlSet001\services\BITS\start.

My question is... does this represent a security issue? Is D+ acting in a valid / appropriate way or should this action be allowed? If so, how and why?

Thanks!


It should be allowed.

read this please.
https://forums.comodo.com/defense_help/servicesexe_is_blocked_every_time-t46548.0.html

Logged

Wrong messages are dangerous, but wrong interpretation of correct messages is even more dangerous.-Andre Kostolany-
I'm a MAN!!
I'm not a girl!
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.051 seconds with 21 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com