Yes, it was the Defense+ portion of the Comodo firewall that reported the attempt to modify a log and the registry.
Virustotal.com didn't quite say it was safe. What it actually said was, "Probably harmless! There are strong indicators suggesting that this file is safe to use." And on the
additional information tab under Advanced heuristic and reputation engines it said, "Symantec reputation Suspicious.Insight" which linked to:
http://www.symantec.com/security_response/writeup.jsp?docid=2010-021223-0550-99
The Symantec writeup says in part: "The Suspicious.Insight detection, therefore, is meant to inform the user that a given application is unproven and not yet well known to Symantec’s tens of millions of users."
I'm 99.9% convinced from replies in this thread and links to Microsoft announcements that it is a legitimate update. But it is weird that both Comodo and Symantec still flagged it as suspicious and not widely known or trusted when it had been rolling out for
over a month.
It doesn't help that anyone looking for possible explanations finds references to the Flame virus and realizes the first signs of a new variant of the Flame virus might be similar. Seems like better communication between Microsoft and security software
vendors would be helpful.