D+ Misrporting certain permissions?

For some reason sometimes the D+ will be telling me “for example” that the MMC want access to a file on my G drive when i was executing Computer Management… now i have executed this before hand on a fresh install/boot on the highest settings of D+ and confirmed every action. Now why would D+ be reporting that its accessing some file on a different drive? especially when its just launching MMC for computer management. Reason this concerds me is that file was indeed a malicious file “no it was not actually executed” which i was analyzing “and no open program or process had the file loaded into memory or anything”. So why is D+ reporting these things? there has also been times that the D+ would tell me something like Pidging or Mirc would access everything else in memory as well. once again “my pc is not infected and these are legitimate programs as ive checked the MD5 of the .exes and what not” this is all done off a fresh format not too long ago.

currently on x64 win 7 but have seen this happen on 32 bit and xp as well. this is also on the proactive maximum settings when installed as well.

this is what im talking about, i have no idea why ff would be executing this ever.






Can you repost the first image in its original size?

I will move this to the help board as this seems more like a help request than a bug report.

The original size can be found over here

You have put CIS in Paranoid Mode and what you then see is basically all that is happening underneath the hood of Windows. Part of these techniques that are being reported are both used by legitimate as well as malware programs. This makes things look much more scary than they are.

When you read the alerts you will often see something along the lines “if this is an every day program you can choose to allow it” or “if this is an every day program you can safely allow this”. Since you say you can vouch for the programs coming from a regular source and even did hash checks there is nothing to worry about.

Putting a HIPS in paranoid mode make the uninitiated user totally nuts…:smiley:

As to why FF would want to execute an executable related to Microsoft Visual Studio I cannot comment. But it is not harmful in its self.

This is how D+ will protect your system. If another program tries to change FF you will be notified. If a website tries to exploit as buffer overflow in FF you will be alerted by the BO protection and will give you the possibility to terminate FF before it can do any harm.

When you know the FF you installed is from a a regular source and clean and no other program tried to mess with FF you know you are safe.

I hope this clears up things for you. Let us know if you have more questions.