Author Topic: Entries in self defense log  (Read 2126 times)

0 Members and 1 Guest are viewing this topic.

Dch48

  • Guest
Entries in self defense log
« on: October 07, 2010, 07:53:45 AM »
I just discovered these entries in my Avast self defense log.

6/24/2010 2:45:34 AM   Write access to file \Device\HarddiskVolume1\Program Files\Alwil Software\Avast5\AvastUI.exe denied. [C:\WINDOWS\Explorer.EXE]
6/28/2010 11:40:54 PM   Write access to registry key \REGISTRY\MACHINE\System\CurrentControlSet\Services\avast! Antivirus\ denied. [C:\WINDOWS\system32\services.exe]
6/28/2010 11:40:56 PM   Write access to registry key \REGISTRY\MACHINE\System\CurrentControlSet\Services\avast! Mail Scanner\ denied. [C:\WINDOWS\system32\services.exe]
6/28/2010 11:40:56 PM   Write access to registry key \REGISTRY\MACHINE\System\CurrentControlSet\Services\avast! Web Scanner\ denied. [C:\WINDOWS\system32\services.exe]
7/9/2010 5:57:40 PM   Write access to registry key \REGISTRY\MACHINE\Software\ALWIL Software\Avast\5.0\ denied. [C:\DOCUME~1\Donald\LOCALS~1\Temp\is-PRJ36.tmp\siw-setup.tmp]
7/9/2010 5:57:47 PM   Write access to registry key \REGISTRY\MACHINE\Software\ALWIL Software\Avast\5.0\ denied. [C:\DOCUME~1\Donald\LOCALS~1\Temp\is-PRJ36.tmp\siw-setup.tmp]
7/29/2010 5:27:39 PM   Write access to registry key \REGISTRY\MACHINE\System\CurrentControlSet\Services\avast! Antivirus\ denied. [C:\WINDOWS\system32\services.exe]
9/8/2010 6:00:23 PM   Write access to registry key \REGISTRY\MACHINE\System\CurrentControlSet\Services\avast! Antivirus\ denied. [C:\WINDOWS\system32\services.exe]
9/8/2010 6:00:24 PM   Write access to registry key \REGISTRY\MACHINE\System\CurrentControlSet\Services\avast! Mail Scanner\ denied. [C:\WINDOWS\system32\services.exe]
9/8/2010 6:00:24 PM   Write access to registry key \REGISTRY\MACHINE\System\CurrentControlSet\Services\avast! Web Scanner\ denied. [C:\WINDOWS\system32\services.exe]
9/15/2010 3:16:51 PM   Write access to registry key \REGISTRY\MACHINE\System\CurrentControlSet\Services\avast! Antivirus\ denied. [C:\WINDOWS\system32\services.exe]
9/15/2010 3:16:51 PM   Write access to registry key \REGISTRY\MACHINE\System\CurrentControlSet\Services\avast! Mail Scanner\ denied. [C:\WINDOWS\system32\services.exe]
9/15/2010 3:16:51 PM   Write access to registry key \REGISTRY\MACHINE\System\CurrentControlSet\Services\avast! Web Scanner\ denied. [C:\WINDOWS\system32\services.exe]



What could be going on and is it anything to worry about?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Entries in self defense log
« Reply #1 on: October 07, 2010, 05:02:42 PM »
Unfortunately there are many such tools that rather than use read access they open a file or registry key with write permissions and it is that which is being blocked, the potential to modify avast files or registry entries (rather than an actual attack).

Personally I wouldn't be worrying about them as the entries in the log show that those attempts have been blocked.

For instance if I open one of the protected logs with a text editor other than notepad it will try to open with write permission and this is blocked.
19/01/2010 22:40:38   Write access to file \Device\HarddiskVolume1\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\log\selfdef.log denied. [C:\Program Files\JGsoft\EditPadLite\EditPadLite.exe]

This was me just opening the selfdef.log to see what it had in it some time ago (I have .log files set to be opened with editpad lite) ;D

Many registry scanners do the same thing when seeking out redundant registry keys they are opened with write permission.
24/01/2010 01:14:42   Write access to registry key \REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\aswUpdSv\ denied. [E:\Utilities-Non-Registry\~\RegSeeker\RS1-55\RegSeeker.exe]
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security