Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 21, 2013, 07:28:01 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663458
Posts
70536
Topics
145194
Members
Latest Member:
Oitagxgu
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Firewall
Help for v3
wscript.exe.....What Is It? Should I Allow it?
« previous
next »
Pages:
[
1
]
Author
Topic: wscript.exe.....What Is It? Should I Allow it? (Read 30310 times)
lordpuffer
Guest
wscript.exe.....What Is It? Should I Allow it?
«
on:
December 14, 2008, 05:57:09 AM »
I am running Vista Home Premium, SP1, 64 bit. I have been getting Comodo telling me that wscript.exe wants to modify a Registry Key. Because Comodo tells me that this is an unsafe application, I kept blocking it ,and checking "remember my answer," however, it still pops up anyway about 5 more times. I don't have any infection whatsoever (I am sure of that), however, because Comodo tells me it is an unsafe application, I keep denying it. I Googled it and found that it is a process relating to Microsoft Windows operating system which allows additional functions to scripting. It also says that you should not disable it. Did I do something wrong by continuously blocking it? I cannot find in the Task Manager where it is running. What should I do? By blocking it, did I turn the process off? Could I have harmed my system? Please advise. Thanks.
Logged
Matty_R
Global Moderator
Comodo's Hero
Offline
Posts: 2524
How long is a piece of string?
Re: wscript.exe.....What Is It? Should I Allow it?
«
Reply #1 on:
December 14, 2008, 06:23:50 AM »
Hi lordpuffer,welcome to the forums,
These sound like D+ alerts alerting you to a script modifying the registry,the reason they are being flagged is the potential is there for wscript.exe to be used for malicious purposes allthough in this case it looks like there safe.
Have a look under Defence+/Advanced/Computer Security Policy------>Look down the list until you find wsript.exe then highlight it and select "Remove"/ APPLY
If like you know your computer is clean next time you get the alert you can select allow.
Matty
Logged
A couple of computers
lordpuffer
Guest
Re: wscript.exe.....What Is It? Should I Allow it?
«
Reply #2 on:
December 15, 2008, 10:24:55 AM »
Hi Matty_R...Thank you very much for the welcome note.....I found wscript.exe and highlighted it and clicked on "Remove" and then on "Apply." Will that mean that it will try to again in Comodo at some point to modify a Registry Key? I know that my system is clean, so I would like to to come up in Comodo so that I can allow it. Thanks so much for the help. (L)
«
Last Edit: December 15, 2008, 10:28:36 AM by lordpuffer
»
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13180
Volunteer Moderator
Re: wscript.exe.....What Is It? Should I Allow it?
«
Reply #3 on:
December 15, 2008, 10:53:09 AM »
I would be cautious with wscript.exe though, it's a script engine than can run good or bad script, so if you apply trust to it and later there is a piece of malware abusing a script using wscript.exe CIS won't alert you that wscript is trying to change you registry. I use vista also and i can't remember that there are any alerts related to wscript.
Only the CIS configuration script from the forum here, it's a cfpv3-config.hta file which uses wscript, have you been running something like this ?
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
lordpuffer
Guest
Re: wscript.exe.....What Is It? Should I Allow it?
«
Reply #4 on:
December 15, 2008, 11:10:45 AM »
Quote from: Ronny on December 15, 2008, 10:53:09 AM
I would be cautious with wscript.exe though, it's a script engine than can run good or bad script, so if you apply trust to it and later there is a piece of malware abusing a script using wscript.exe CIS won't alert you that wscript is trying to change you registry. I use vista also and i can't remember that there are any alerts related to wscript.
Only the CIS configuration script from the forum here, it's a cfpv3-config.hta file which uses wscript, have you been running something like this ?
I have not been running that (CIS configuration script)....But as I said, I did Google wscript.exe and it did say that it is a legitimate , although not important part of the OS.....But it did say not to disable it. I just felt that not allowing it to do what is supposed to do, which seems to be to modify a Registry Key, may cause some problems with the OS. I don't know why Comodo is showing it as an unsafe application, but I ran 4 different spyware/adware/malware scans (SuperAntiSpyware, Ad-Aware, Spybot and Windows Defender) and found nothing, and Avira Antivir found nothing, so I'm pretty sure that I'm clean. What do you suggest? By doing what Matty_R told me above, did I just give it free reign to do whatever it wants to do? If so, how do I reverse what I did? Or should I block it again? To be honest, I'm not sure what the best thing is to do.
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13180
Volunteer Moderator
Re: wscript.exe.....What Is It? Should I Allow it?
«
Reply #5 on:
December 15, 2008, 01:31:06 PM »
It's not that wscript.exe is the problem, it's the kind of script it executes.
Something like a batch file running a batch file with dir *.* in it won't hurt as one with a del *.* /q /s will.
You can't blame the batch processor for that, it's the one who build the script!
Me personal i have this one always alerting and then if i know i executed something that could have something to do with wscript i'll allow it only then without using the remember option.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
lordpuffer
Guest
Re: wscript.exe.....What Is It? Should I Allow it?
«
Reply #6 on:
December 15, 2008, 01:43:55 PM »
Thanks....I'll follow your suggestion and do that....Can you please explain how, after I already followed the above and did what Matty_R posted (no disrespect intended to Matty_R)?
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13180
Volunteer Moderator
Re: wscript.exe.....What Is It? Should I Allow it?
«
Reply #7 on:
December 15, 2008, 01:51:39 PM »
No prob, open the GUI goto Defense+, Advanced, Computer Security Policy, if you click on that you get a new window with all you "learned" applications in it, look for c:\windows\system32\wscript.exe, select it and press the remove button on the right, now press apply and it should alert you the next time it's trying to run/access files/registry etc.
As i said before, i don't have it prompting on my vista box, so if it comes back we should try to find out why it's running...
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
lordpuffer
Guest
Re: wscript.exe.....What Is It? Should I Allow it?
«
Reply #8 on:
December 15, 2008, 02:36:43 PM »
Quote from: Ronny on December 15, 2008, 01:51:39 PM
No prob, open the GUI goto Defense+, Advanced, Computer Security Policy, if you click on that you get a new window with all you "learned" applications in it, look for c:\windows\system32\wscript.exe, select it and press the remove button on the right, now press apply and it should alert you the next time it's trying to run/access files/registry etc.
As i said before, i don't have it prompting on my vista box, so if it comes back we should try to find out why it's running...
That's what Matty_R instructed me above what to do.....So I guess I did remove it already and it will alert me the next time it tried to run...Thanks
Logged
Matty_R
Global Moderator
Comodo's Hero
Offline
Posts: 2524
How long is a piece of string?
Re: wscript.exe.....What Is It? Should I Allow it?
«
Reply #9 on:
December 15, 2008, 02:51:54 PM »
Hi lordpuffer,
In this case it may be an idea to have a pen and paper handy for next time the alert pops-up,as the last few times you had it you denied it with no adverse effects it doesn`t seem to effect anything serious so just write down the wording of the alert "wscript.exe is trying to modify the protected registry key ........." then block it but don`t have "remember my answer" ticked,
This will help in finding out why you are getting this alert,
Cheers,
Matty
Logged
A couple of computers
lordpuffer
Guest
Re: wscript.exe.....What Is It? Should I Allow it?
«
Reply #10 on:
December 15, 2008, 03:00:02 PM »
Quote from: Matty_R on December 15, 2008, 02:51:54 PM
Hi lordpuffer,
In this case it may be an idea to have a pen and paper handy for next time the alert pops-up,as the last few times you had it you denied it with no adverse effects it doesn`t seem to effect anything serious so just write down the wording of the alert "wscript.exe is trying to modify the protected registry key ........." then block it but don`t have "remember my answer" ticked,
This will help in finding out why you are getting this alert,
Cheers,
Matty
Thanks...I will. I appreciate the help.
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.043 seconds with 22 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com