Welcome, Guest. Please login or register.
March 19, 2010, 09:21:06 PM

Login with username, password and session length

373063 Posts
41378 Topics
94054 Members

Latest Member: concon

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Defense+ / Sandbox Help - CIS
| | | | |-+  defense+ shellcode injection & modify key...should i be very worried?
« previous next »
Pages: [1] Go Down Print
Author Topic: defense+ shellcode injection & modify key...should i be very worried?  (Read 552 times)
emhami2009
Newbie
*
Offline Offline

Posts: 9


« on: November 17, 2009, 12:34:26 PM »

Hello,

I am attaching a jpeg copy of the print screen showing my defense+ events - I wonder if anyone could tell me if I should be really worried about the 2 that keep occurring regularly:

1)   shellcode injection from svchost.exe (when i get the warning it talks of a possible buffer overflow attack - & i have learnt that it is best not to respond - as if i tell it to tell it to stop svchost the computer becomes unresponsive - but to just close all windows & reboot)

2)  the 'modify key' question keeps on popping up when i close down  - if i get time - sometimes it flies lff the screen too quickly - i block this request.


many thanks for any help/advice you are able to give me.

Em.
Logged
aditya_dmj
Comodo Loves me
****
Offline Offline

Posts: 102


« Reply #1 on: November 24, 2009, 07:05:16 AM »

try disabling D+ for a while( untick shell execution part) .
if there is one, thesvchost will crash as it run protected under DEP.( you will know wether it is for real or False alert).No harm to computer wil be done except hanging and you have to reboot.

--Second strange thing is services is modifying controlset002( does this happens just after reboot),if it happens just after reboot you can allow it.

-Probably in past you have made use of "last known good configuration".

-About ShelCodeExecution ,(it appears so ,i am not sure some program is trying to achieve elevated privilege). try disabling mbam and super antispyware for a while.

Regards

Adi
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 5810



« Reply #2 on: November 29, 2009, 08:00:14 PM »

What OS are you using? Is it up to date with all the latest updates?

The shellcode injection error message may also indicate an error rather than an attack. When this message occurs a buffer overflow (BO) was found. The BO is a type of error in a program; this type of error can also exploited by malware.

When scanning your computer with several antimalware and rootkit scanners doesn't show malware it is safe to assume you found a crash of svchost.exe.
Logged

Please read: Introduction to the Sandbox

Using CIS v4 and always the latest snapshot of Opera browser.

AMD Phenom 925 quad core with 4 GB RAM on MSI 785G E53
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.199 seconds with 20 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com