PDA

View Full Version : How CIS 5 works for you (CAV)


JoeBlack40
September 7th, 2010, 11:10 AM
~Comment removed~

So.......
Now i run CIS without AV with NOD 32,smooth and light.After some of my tests on VMLite,i realize that CAV still it's not ready.Thats why I'm asking you what do you think about CAV. Although i really like a full suite like CIS.
Seriously,after 20 links at MDL,CAV blocked only 5 of them.
That's a problem,and that's because why other users doesn't use CAV.
Like me,of course.
Thanks-

lordraiden
September 7th, 2010, 11:14 AM
The Cloud behabiour blocker is still not synchronize with CAV, I think we will have to wait until the final version.
If you want to see the performance of the behaviour blocker you can upload the malware here and see what happens http://camas.comodo.com/

Also there is a componet of CAV in the cloud but I am not sure if is working 100%.

I'm waiting until the final version to see how the AV performs. Right now the RC2 is stable enough and only a few bugs have been reported I think that they are focused now in make the cloud work.

Is expected that the BB should work more or less like the ZoneAlarm broswer protection. http://www.zonealarm.com/security/en-eu/zonealarm-computer-security-suite.htm

-{ Quote: "Advanced Download Protection New
* Deep Security Check – Provides an option to run the download in a virtual protected environment to more deeply analyze it for malicious behavior.
" }-

There are some test of Zone Alarm on youtube using this technology with excellent results.

JoeBlack40
September 8th, 2010, 06:28 AM
CIS updated to 5.0.162051.1126.I want to do some tests to see if in the cloud scanning is improved.
Lordraiden,CIS is very stable for me too.Let's hope that with final release,CAV will be more powerful.Although all these malware links were 0 day and not detected by CAV,Defence+ and Sandbox done their job very well.But that is not an excuse for poor detection.

lordraiden
September 8th, 2010, 06:37 AM
-{ Quote: "CIS updated to 5.0.162051.1126.I want to do some tests to see if in the cloud scanning is improved.
Lordraiden,CIS is very stable for me too.Let's hope that with final release,CAV will be more powerful.Although all these malware links were 0 day and not detected by CAV,Defence+ and Sandbox done their job very well.But that is not an excuse for poor detection." }-

Yes, I was testing again CIS yesterday and CAV against 0day malware (15 files more or less) only captured 30% of the files more or less, uploading the same files to CAMAS the detection was much higher i dont remember well but was arround 80% (4 files where not detected but some elements were flaged in red in the repport) so when the Cloud will be working and the detections will be combined, the performance will increase a lot specially for 0daymalware, anyway the files that CAV did not stop were stoped by the sandbox, and after a restart and some scans with different software the computer was 100% clean.

Read this. http://www.wilderssecurity.com/showpost.php?p=1745436&postcount=9 maybe you would like to wait a bit more before test it.

Anyway if you want to check that CAMAS is working
Upload the file here: http://camas.comodo.com/
if the veredict is suspicious should be detected by CIS cloud.
But seems that this will not be working until friday maybe

JoeBlack40
September 8th, 2010, 07:17 AM
Thank you Lordraiden.I think i will wait 'till Friday then.There's no point to do some other tests if it's true about cloud scanning.

J_L
September 8th, 2010, 06:32 PM
Comodo AV full system scan takes forever and seriously lags my system. Tried it multiple times, cancelled but then it froze. CIS was also sandboxing the same processes even though I've added them to my Trusted Files.

Therefore I've officially given up on Comodo Internet Security and re-enabled Windows Firewall.

Espresso
September 8th, 2010, 09:29 PM
-{ Quote: "Therefore I've officially given up on Comodo Internet Security and re-enabled Windows Firewall." }-

That's hardly a replacement. If you don't want your programs sandboxed automatically you can turn that feature off. You can always right click and sandbox new downloads and set up a list of other programs to be always sandboxed.

I'd like to be able to automatically sandbox files in a certain folder only but that doesn't seem possible currently.

JoeBlack40
September 9th, 2010, 04:03 AM
-{ Quote: "CIS was also sandboxing the same processes even though I've added them to my Trusted Files" }-
It happened to me with two programs.The work around,based on Comodo forums,is to put those files in to the Computer Security Policy as installer or updater.And yes,it worked.I don't know why this behavior from CIS or why only with certain files...

lordraiden
September 9th, 2010, 04:59 AM
-{ Quote: "Comodo AV full system scan takes forever and seriously lags my system. Tried it multiple times, cancelled but then it froze. CIS was also sandboxing the same processes even though I've added them to my Trusted Files.

Therefore I've officially given up on Comodo Internet Security and re-enabled Windows Firewall." }-

Did you tried the latest RC? the issue of lag was a know issue of one of the betas and have been already fixed.

J_L
September 9th, 2010, 09:12 PM
-{ Quote: "Did you tried the latest RC? the issue of lag was a know issue of one of the betas and have been already fixed." }-
Tried the latest, the scan lag still occurred for hours. Anyhow, I don't need CIS on my system.

cp4eva
September 10th, 2010, 12:30 AM
I've been using the latest build of CIS 4 for close to a week now and I have been rather surprised at how quiet D+ has been. Regardless of whether or not I like Comodo's policies or tactics, I have to say it's been a pleasant experience. I look forward to trying out v5 (once the bugs have been worked out) :)

JoeBlack40
September 10th, 2010, 07:45 AM
Well,since the first beta release i didn't experienced any lags with CAV while scanning.8)