RealSecure Network, RealSecure Server Sensor, BlackICE Agent for Server, BlackICE Server Protection, BlackICE PC Protection, Proventia Network MFS, IBM Security Server Protection for Windows, Proventia Desktop, Proventia Network IDS, Proventia-G 1.1 and earlier, RealSecure Desktop Protector 3.6, Proventia Server IPS for Linux technology, Proventia Network IPS, Virtual Server Protection for Vmware:
This signature detects attempts to write files to the Windows\System32\ directory.This may indicate an attempt to modify or install software in a protected directory.
RealSecure Network, RealSecure Server Sensor, Proventia Network MFS, IBM Security Server Protection for Windows, Proventia Desktop, Proventia Network IDS, Proventia-G 1.1 and earlier, Proventia Server IPS for Linux technology, Proventia Network IPS, Virtual Server Protection for Vmware: This signature may trigger on legitimate directory write operations such asupdates to exisiting Windows\System32\ binaries.
Medium
RealSecure Network: XPU 24.3, RealSecure Server Sensor: XPU 24.3, BlackICE Agent for Server: 3.6eof, BlackICE Server Protection: 3.6.cpa, BlackICE PC Protection: 3.6cpa, Proventia Network MFS: XPU 1.42, IBM Security Server Protection for Windows: 1.0.914.0, IBM Security Server Protection for Windows: 2.1.14.2400, Proventia Desktop: 8.0.614.1, Proventia Network IDS: XPU 24.3, Proventia-G 1.1 and earlier: XPU 24.3, RealSecure Desktop Protector 3.6: eob, Proventia Server IPS for Linux technology: 1.0, Proventia Network IPS: XPU 1.42, RealSecure Desktop: eob, Virtual Server Protection for Vmware: 1.0
Microsoft Windows
Suspicious Activity
An attempt to write a file to the Windows System32 directory has been detected. Files held in the Windows System directories are of a critical nature, and should be owned by the system administrator. Ordinary users should only have read access to them. These files should never be deleted. The files stored in this repository should not be manually changed. Creation of files in the Windows System32 directory may indicate the presence of a worm, virus, or Trojan on the system.
Examine the source address to determine if this is malicious activity.
ISS X-Force
Microsoft Windows System32 write file to the directory has been detected
http://www.iss.net/security_center/static/16627.php