Welcome, Guest. Please login or register.
November 14, 2009, 10:18:26 AM

Login with username, password and session length

334672 Posts
37002 Topics
83891 Members

Latest Member: ISRAL

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  wscript.exe alert
« previous next »
Pages: [1] Go Down Print
Author Topic: wscript.exe alert  (Read 860 times)
rawrzar
Newbie
*
Offline Offline

Posts: 2


« on: July 01, 2009, 01:26:24 PM »

Hello,

I just got an alert from Defense+ that wscript.exe is trying to modify a protected registry key.  I googled it and it says that it is a microsoft application and should not be disabled, so I allowed it.  However, more requests keep popping up.  It is trying to modify different things in:
HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates
such as CA, TrustedPeople, Disallowed,
I found out that wscript.exe can also be used by a virus.  Is this the case?

Edit:
After blocking the request a few more times, it is now trying to connect to the Internet.
Also, cscript.exe is trying to create a new file or directory
« Last Edit: July 01, 2009, 01:39:07 PM by rawrzar » Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5320


I'm not a complete idiot, some bits are missing.


« Reply #1 on: July 01, 2009, 01:56:30 PM »

Hi rawrzar, welcome to forums.. sorry, it's under such a circumstance.

I'm no expert on this, you'll need to wait for those, but I do know that wscript.exe can indeed be abused, rather easily in fact. It's the basic scripting language for Windows.

Do you have something like Process Explorer? If not, grab it. Process Explorer will probably tell you what the script file is that is being run on wscript.exe and the command-line start-up of the process. Find the file & block it in CIS.

You should probably also use something like HijackThis to see what is trying to start on startup. And there is a autothingy HijackThis log file analysis here.

Also, check you AV & update the virus definitions & run a full scan.

There also many other apps you can run.. more of that later perhaps.

PS If you find wscript.exe running using Process Explorer, note script filename & kill the process.

edit
« Last Edit: July 01, 2009, 02:03:59 PM by kail » Logged

Vista Business x32+SP2 with CIS 3.12 & Firefox 3.5 & Becky! 2.52
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
rawrzar
Newbie
*
Offline Offline

Posts: 2


« Reply #2 on: July 01, 2009, 03:49:42 PM »

Hello kail,

Thank you for your help.  Using Process Explorer, I found that HP Health Check was responsible for the script.  After searching around, I found that many people have come across this, and I didn't realize that the Health Check was running automatically. Thanks again.
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5320


I'm not a complete idiot, some bits are missing.


« Reply #3 on: July 01, 2009, 04:16:03 PM »

No problem, good tool Process Explorer. You should also check out AutoRuns, it's by the same guys.
Logged

Vista Business x32+SP2 with CIS 3.12 & Firefox 3.5 & Becky! 2.52
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.031 seconds with 17 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com