Jump to content

is this legit? NgcFirst\ConsecutiveSwitchCount


Recommended Posts

after logging in using PIN after a restart and 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{D6886603-9D2F-4EB2-B667-1971041FA96B}\S-1-5-21-229674073-691441657-888200982-1001\NgcFirst\ConsecutiveSwitchCount

Quote

Time;Application;Operation;Target;Action;Rule;Additional information
4/14/2021 8:44:57 PM;C:\Windows\System32\svchost.exe;Modify startup settings;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{D6886603-9D2F-4EB2-B667-1971041FA96B}\S-1-5-21-229674073-691441657-888200982-1001\NgcFirst\ConsecutiveSwitchCount;allowed;Automatic mode;

 

this came up on ESET HIPS, never seen this popping up before.

after doing some internet search, this came up

https://forum.eset.com/topic/23588-hips-alert-for-host-process/?_fromLogin=1

 

Edited by migs_k
Link to comment
Share on other sites

20 minutes ago, migs_k said:

This thread ended with the issue being related to Eset LiveGrid connectivity. Check your Eset Event log for any entries realted to this status.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...