Defense+ - Computer Security Policy

Dear Sirs

My home PC (Windows 7 Home Premium Service Pack 1) is installed with Comodo Internet Security v5.3.50343.1263, the Personal Firewall v5.3.181415.1237 and Defense+ of which are enabled.

I am puzzled by a Defense+ alert warning (C:\Windows\System32\wdi\LogFiles\shutdownckcl.etl) for each shutdown, even though I have added the following computer security policy:
C:\Windows\System32\wdi\LogFiles*.*

I appreciate it much if any advice will be given to get rid of this annoying warning.

Yours faithfully
AChung

Hey :slight_smile:

You could try to add it in exclusions. ( I assume you know what I mean.)

Regards,
Valentin N

Try changing C:\Windows\System32\wdi\LogFiles*.* to C:\Windows\System32\wdi\LogFiles*.

Hi, Valentin

Thank you for your response.

Do you mean the “exclusions” in Defense + Settings > Execution Control Settings > Detect shellcode injection (ie buffer overflow protection)?

I look forward to having your early clarfication.

Regards,
AChung

Dear Eric

Thank you for your good advice.

Regards,
AChung

That’s the exclusion I mean :).

Dear Valentin

Thank you for your confirmation.

However, the exclusion C:\Windows\System32\wdi\LogFiles* seems to be ineffective as there is still a defense+ alert for C:\Windows\System32\wdi\LogFiles\shutdownckll.etl before the system shutdown. Should this warning be ignored?

Regards,
AChung

I find it a bit strange; I don’t get such warning not even in paranoid mode. If you got this on a clean computer you can press ignore. I suggest you make a quick scan with malwarebytes to make sure that you’re pc is clean.

Regards,
Valentin N

Can you check the system file integrity? Follow this guideline: http://www.howtogeek.com/howto/windows-vista/verify-the-integrity-of-windows-vista-system-files/ . It is for Vista but it works the same in Win 7.

Hi, Valentin and Eric

Thank you for your good advice.

I always utilise Malawarebytes’ Antimalware and SUPERAntiSpyware to scan my home PC subsequent to the daily updates. As a result, my system is reported of malware and spyware free on each occasion. This is reinforced by Windows Defender on-demand scanning with the latest definition update.

As directed by Eric, I have tried “sfc /scannow” and the result is “Windows Resource Protection did not find any integrity violations”

I note that the Defense+ alert often displays after my home PC to Windows 7 Service Pack 1 has been upgraded. Apparently, the current version of Comodo Internet Security does not remember my answer, ie OK to allow, should an alert arise. Any conflict with the latest operating system?

Regards,
AChung

Hey AChung

I suggest you turn Windows Defender off.

I think that my CIS also forgot my answers after I installed SP1 and but after doing the answering procedure and now it’s working normally.

Regards,
Valentin N

Hi, Valentin

Windows Defender is set to “manual” instead of “automatic” on the Administrative Tools > Services. I guess this may not be appropriate to my PC after upgrading to Windows 7 Service Pack 1.

Strange as Comodo Internet Security is back to “normal” after I have adjusted its Defense+ security level to Clean PC Mode from Safe Mode. Then, I do not see the annoying Defense+ alert on the shutdown. God bless!

Cheers,
AChung