cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
223
Views
3
Helpful
2
Replies

CSA 4.5.1.639 - What would be causing this activity on mulitple machines

kerraj2004
Level 1
Level 1

Dont know why or what keeps causing this to trigger. Should it be denied or allowed?

The Process 'C:\WINDOWS\SYSTEM32\cmd.exe' (user) attemped to access 'C:\WINDOWS\SYSTEM32\drivers\etc\services'. The attempted access was a write (operation = OPEN/ WRITE).

The user was queried and a 'Yes' response was received.

2 Replies 2

tsteger1
Level 8
Level 8

Could be FTP or some other networking process looking at the services file. Might want to talk to the user saying "yes" and see what they are doing to trigger it.

Thanks, it is something at boot. I will also look at the msconfig.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: