cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
226
Views
3
Helpful
2
Replies

CSA 4.5.1.639 - What would be causing this activity on mulitple machines

kerraj2004
Level 1
Level 1

Dont know why or what keeps causing this to trigger. Should it be denied or allowed?

The Process 'C:\WINDOWS\SYSTEM32\cmd.exe' (user) attemped to access 'C:\WINDOWS\SYSTEM32\drivers\etc\services'. The attempted access was a write (operation = OPEN/ WRITE).

The user was queried and a 'Yes' response was received.

2 Replies 2

tsteger1
Level 8
Level 8

Could be FTP or some other networking process looking at the services file. Might want to talk to the user saying "yes" and see what they are doing to trigger it.

Thanks, it is something at boot. I will also look at the msconfig.