10-03-2009 10:20 PM - edited 10-03-2009 10:45 PM
I have two machines using NIS2010 at the moment, both running Windows 7. I have a bunch of messages in my history for "Unauthorized Access Logged". Here is the full message:
Severity: Medium
Activity: Unauthorized access logged (Access Process Data)
Recommended Action: No Action Required
Under Advanced Details:
Actor: C:\WINDOWS\SYSTEM32\CONHOST.EXE
Target: \Device\Harddisk\ProgramFiles (x86)\Norton Online\AddOns\Norton Safety Minder\Engine\1.1.5.15\TampMon.exe
Conhost.exe is a new binary with Windows 7, so my hope / guess is its a false positive? Anyone else experience this thus far?
EDIT: I should note that NIS2010 is not throwing an alert for these, they are just in the History, and appear sporadically (1-2 times an hour though).
10-03-2009 11:49 PM
CountryGuy wrote:I have two machines using NIS2010 at the moment, both running Windows 7. I have a bunch of messages in my history for "Unauthorized Access Logged". Here is the full message:
Severity: Medium
Activity: Unauthorized access logged (Access Process Data)
Recommended Action: No Action Required
Under Advanced Details:
Actor: C:\WINDOWS\SYSTEM32\CONHOST.EXE
Target: \Device\Harddisk\ProgramFiles (x86)\Norton Online\AddOns\Norton Safety Minder\Engine\1.1.5.15\TampMon.exe
Conhost.exe is a new binary with Windows 7, so my hope / guess is its a false positive? Anyone else experience this thus far?
EDIT: I should note that NIS2010 is not throwing an alert for these, they are just in the History, and appear sporadically (1-2 times an hour though).
Message Edited by CountryGuy on 10-04-2009 01:45 AM
I think your assessment is correct and this is not an issue to worry about - looks like a false positive.
We look forward to the time when the Power of Love will replace the Love of Power. Then will our world know the blessings of peace. ~William Ewart Gladstone
10-04-2009 12:58 AM
10-31-2009 05:34 PM
10-31-2009 10:12 PM
