This just popped up with 360 Total Security. A registry change was about to be made but was blocked by the program, and then these processes wanted to start up. Is anything fishy going on?
The log provided by 360 Total Security is provided below.
2016-03-13 10:30:42 Process Creation [Auto-blocked]
Details:
Process: C:\windows\Sysnative\services.exe
Action: Process creation
Path: C:\windows\Sysnative\taskhost.exe
2016-03-13 10:25:47 Process Creation [Auto-blocked]
Details:
Process: C:\windows\Sysnative\services.exe
Action: Process creation
Path: C:\windows\Sysnative\raserver.exe
2016-03-13 10:22:52 Modify driver or service [Blocked]
Detailed description:
Registry: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\SERVICES\MSMPSVC\[FailureCommand]
Content: C:\windows\system32\mrt.exe /EHB /ServiceFailure "CAMP=4.9.218.0;approximate-> Engine=1.1.12505.0;AVSIG=1.215.1414.0;ASSIG=1.215.1414.0" /StartService /q
Process: C:\windows\Sysnative\services.exe
Parent Process:C:\windows\system32\wininit.exe , (103)
The log provided by 360 Total Security is provided below.
2016-03-13 10:30:42 Process Creation [Auto-blocked]
Details:
Process: C:\windows\Sysnative\services.exe
Action: Process creation
Path: C:\windows\Sysnative\taskhost.exe
2016-03-13 10:25:47 Process Creation [Auto-blocked]
Details:
Process: C:\windows\Sysnative\services.exe
Action: Process creation
Path: C:\windows\Sysnative\raserver.exe
2016-03-13 10:22:52 Modify driver or service [Blocked]
Detailed description:
Registry: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\SERVICES\MSMPSVC\[FailureCommand]
Content: C:\windows\system32\mrt.exe /EHB /ServiceFailure "CAMP=4.9.218.0;approximate-> Engine=1.1.12505.0;AVSIG=1.215.1414.0;ASSIG=1.215.1414.0" /StartService /q
Process: C:\windows\Sysnative\services.exe
Parent Process:C:\windows\system32\wininit.exe , (103)