Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #376  
Old September 9th, 2011, 10:07 AM
Cyrano2 Cyrano2 is offline
Regular Poster
 
Join Date: Mar 2010
Location: Spain
Posts: 93
Default Re: COMODO Internet Security 5.x Thread

Updated .
__________________
Real-Time: EMET 4 (Beta) / Comodo Firewall 6.1.x
Browser: Chrome (Adblock Plus, HTTPS Everywhere and TrafficLight)
On-demand: Norton ConnectSafe (Router) / Macrium Reflect Free / Malwarebytes Anti-Malware (Weekly) / Hitman Pro (Monthly)
  #377  
Old September 9th, 2011, 02:12 PM
lordraiden's Avatar
lordraiden lordraiden is offline
Very Frequent Poster
 
Join Date: Jan 2006
Posts: 2,193
Default Re: COMODO Internet Security 5.x Thread

A review of the beta with an AV test

http://translate.google.com/translat...l-detectiei%2F
__________________
Comodo Internet Security (No AV)
ZeroVulnerabilityLabs ExploitShield | Trusteer Rapport | TrueCrypt | EMET | Secunia PSI
Firefox: Addon security and privacy collection: https://addons.mozilla.org/en-us/fir...den/favorites/
  #378  
Old September 9th, 2011, 03:07 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: COMODO Internet Security 5.x Thread

Well that's nice. Would have been nice to see false positives.

edit: A false positive test, I don't want false positives =p
__________________
  #379  
Old September 9th, 2011, 06:18 PM
NormanN NormanN is offline
Regular Poster
 
Join Date: Jan 2011
Posts: 67
Default Re: COMODO Internet Security 5.x Thread

Greetings. I was having problems with OA and am giving the CIS Beta a shot. I like it so far. There are so many options available, can somebody point me to a config guide for *5.8*? I'm on Proactive, Restricted Sandbox, All Cloud and Vendor options selected, Safe/Safe, AV Hueristics at Medium....Phew! I don't mind answering pop ups, but don't want Paranoid mode. I also put WMP, VLC, Foxit, and irfanview in a permanent Restricted sandbox. What about download folders? Just a little overwhelmed and confused...but having choices is good!

Thanks,

N

PS: Read this entire thread and other CIS ones as well...still a little unsure of settings.
  #380  
Old September 9th, 2011, 06:42 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: COMODO Internet Security 5.x Thread

I don't believe you can add a downloads folder (or any folder) to a sandbox.

You can check out my sig for my specific CIS config. I would suggest you sandbox Java, any instant messaging programs, or anything that touches the internet.

I personally leave autosandboxing off. If I find something suspicious I right click and sandbox it.
__________________
  #381  
Old September 9th, 2011, 06:45 PM
1chaoticadult's Avatar
1chaoticadult 1chaoticadult is offline
Very Frequent Poster
 
Join Date: Oct 2010
Location: Chaotic Land
Posts: 2,219
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by Hungry Man
I don't believe you can add a downloads folder (or any folder) to a sandbox.

Nope you can't I confirm it.
__________________
OS Hardening + Applocker + ExploitShield + EMET + HitmanPro
  #382  
Old September 9th, 2011, 07:13 PM
Romagnolo1973's Avatar
Romagnolo1973 Romagnolo1973 is offline
Frequent Poster
 
Join Date: Feb 2009
Location: Italy - Ravenna
Posts: 409
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by NormanN
Greetings. I was having problems with OA and am giving the CIS Beta a shot. I like it so far. There are so many options available, can somebody point me to a config guide for *5.8*? I'm on Proactive, Restricted Sandbox, All Cloud and Vendor options selected, Safe/Safe, AV Hueristics at Medium....Phew! I don't mind answering pop ups, but don't want Paranoid mode. I also put WMP, VLC, Foxit, and irfanview in a permanent Restricted sandbox. What about download folders? Just a little overwhelmed and confused...but having choices is good!

Thanks,

N

PS: Read this entire thread and other CIS ones as well...still a little unsure of settings.
I make an "how to" for CIS 5 but is in Italian language, but if you want just translate with google if it can help you understanding CIS setting better
http://www.hwupgrade.it/forum/showthread.php?t=2247452
__________________
Roboscan Internet Security + HitmanPro + Sumo Updater
Sorry For My Bad English I'm Italian
  #383  
Old September 9th, 2011, 07:45 PM
J_L's Avatar
J_L J_L is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 4,820
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by NormanN
What about download folders? Just a little overwhelmed and confused...but having choices is good!
Keep "Treat unrecognized files as", and most of your unknown downloads will be sandboxed. Of course, it extends beyond downloads, and affect every program that executes.
__________________
  #384  
Old September 9th, 2011, 07:47 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: COMODO Internet Security 5.x Thread

I prefer to leave the autosandboxing alone as most of the time I have legitimate applications and not malware on my system.
__________________
  #385  
Old September 9th, 2011, 07:53 PM
1chaoticadult's Avatar
1chaoticadult 1chaoticadult is offline
Very Frequent Poster
 
Join Date: Oct 2010
Location: Chaotic Land
Posts: 2,219
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by Hungry Man
I prefer to leave the autosandboxing alone as most of the time I have legitimate applications and not malware on my system.

LOL. You know you liked those autosandbox popups
__________________
OS Hardening + Applocker + ExploitShield + EMET + HitmanPro
  #386  
Old September 9th, 2011, 07:56 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: COMODO Internet Security 5.x Thread

Haha, well it was certainly effective. But with full virtualization not supported things like BlackDay and GPCode could break through. Manually sandboxing them works perfectly. That's what I prefer.
__________________
  #387  
Old September 9th, 2011, 08:00 PM
1chaoticadult's Avatar
1chaoticadult 1chaoticadult is offline
Very Frequent Poster
 
Join Date: Oct 2010
Location: Chaotic Land
Posts: 2,219
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by Hungry Man
Haha, well it was certainly effective. But with full virtualization not supported things like BlackDay and GPCode could break through. Manually sandboxing them works perfectly. That's what I prefer.

Yea definitely. Full virtualization in autosandboxing will be something to look forward to in the near future.
__________________
OS Hardening + Applocker + ExploitShield + EMET + HitmanPro
  #388  
Old September 9th, 2011, 08:01 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: COMODO Internet Security 5.x Thread

Yeah I might even turn it back on.
__________________
  #389  
Old September 9th, 2011, 08:01 PM
1chaoticadult's Avatar
1chaoticadult 1chaoticadult is offline
Very Frequent Poster
 
Join Date: Oct 2010
Location: Chaotic Land
Posts: 2,219
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by Hungry Man
Yeah I might even turn it back on.

It would be tempting to.
__________________
OS Hardening + Applocker + ExploitShield + EMET + HitmanPro
  #390  
Old September 9th, 2011, 09:44 PM
J_L's Avatar
J_L J_L is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 4,820
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by Hungry Man
I prefer to leave the autosandboxing alone as most of the time I have legitimate applications and not malware on my system.
That's why Comodo has a whitelist. It's very easy not getting prompts again for the current installation.
__________________
  #391  
Old September 9th, 2011, 09:48 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: COMODO Internet Security 5.x Thread

It does have a whitelist and that's great but it's not really enough and not really necessary for me.

It's a great feature, I may use it again one day, and I see its value... for now I've got it off.
__________________
  #392  
Old September 10th, 2011, 09:42 AM
abels's Avatar
abels abels is offline
Regular Poster
 
Join Date: Apr 2007
Location: Danang, VN
Posts: 91
Default Re: COMODO Internet Security 5.x Thread

I have this issue with Comodo Firewall: when I run an unrecognized file in the first time CF automatically force it to run in sandbox, but when I run that file in the second time CF automatically add the file to Trust Files and run it outside sandbox.
__________________
Comodo Internet Security v6

Last edited by abels : September 10th, 2011 at 09:50 AM.
  #393  
Old September 10th, 2011, 10:10 AM
lordraiden's Avatar
lordraiden lordraiden is offline
Very Frequent Poster
 
Join Date: Jan 2006
Posts: 2,193
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by abels
I have this issue with Comodo Firewall: when I run an unrecognized file in the first time CF automatically force it to run in sandbox, but when I run that file in the second time CF automatically add the file to Trust Files and run it outside sandbox.

Maybe you clicked on "do not sandbox this file again"
Or the file was recognized trusted by the Cloud and automatically added to the trusted list.

Have you check that the file is actually in the "trusted file list"? the second time that you open a file (in a short period of time) the popups informing that the file has been sandboxed does not appear but the file is sandboxed anyway, you can see it in the summary tab at the Defense+ section
__________________
Comodo Internet Security (No AV)
ZeroVulnerabilityLabs ExploitShield | Trusteer Rapport | TrueCrypt | EMET | Secunia PSI
Firefox: Addon security and privacy collection: https://addons.mozilla.org/en-us/fir...den/favorites/
  #394  
Old September 10th, 2011, 10:25 AM
NormanN NormanN is offline
Regular Poster
 
Join Date: Jan 2011
Posts: 67
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by Romagnolo1973
I make an "how to" for CIS 5 but is in Italian language, but if you want just translate with google if it can help you understanding CIS setting better
http://www.hwupgrade.it/forum/showthread.php?t=2247452


I read it, thanks...very informative. I'm still researching the sandbox feature. I like how you can set unrecognized files to a certain level. but separately set internet facing apps to a lower level. Now if I could just figure out what the best levels are for both! I wish the 'Run Sandboxed' option worked on a shortcut. I also wish there was a recovery feature for downloads, instead of having to navigate the VirtualRoot folder. I have Sandboxie as well, but am trying to streamline my setup. One last question: How do I go back to a clean slate as far as the 'rules' go?...I want to retrain the software. Can I just 'Remove' all the rules for both FW and D+ and then restart? Will it auto-populate the built in rules (Windows System, Windows Update, etc...)?

NN
  #395  
Old September 10th, 2011, 10:29 AM
lordraiden's Avatar
lordraiden lordraiden is offline
Very Frequent Poster
 
Join Date: Jan 2006
Posts: 2,193
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by NormanN
I read it, thanks...very informative. I'm still researching the sandbox feature. I like how you can set unrecognized files to a certain level. but separately set internet facing apps to a lower level. Now if I could just figure out what the best levels are for both! I wish the 'Run Sandboxed' option worked on a shortcut. I also wish there was a recovery feature for downloads, instead of having to navigate the VirtualRoot folder. I have Sandboxie as well, but am trying to streamline my setup. One last question: How do I go back to a clean slate as far as the 'rules' go?...I want to retrain the software. Can I just 'Remove' all the rules for both FW and D+ and then restart? Will it auto-populate the built in rules (Windows System, Windows Update, etc...)?

NN

You can not give different levels for internet apps and unrecognized apps.

If you delete all the rules after restart and use the programs the lists will be populated again with the trusted/recognized software without showing any popup. I would not delete the rules from "computer security policy" - "D+ rules" (if you are not sure about what you are doing, I mean you can delete the rules for apps, but be carefull with the rules for windows and CIS, I don't know if those kind of rules can be easily recovered, the same goes for the firewall rules specially the SYSTEM rules), but you can delete all the files from the trusted file list. Take a look to the option "create rules for safe applications"

You can make a shortcut to your desktop to the virtualroot folder

You can make right click on any app and click on "run in Comodo sandbox"
__________________
Comodo Internet Security (No AV)
ZeroVulnerabilityLabs ExploitShield | Trusteer Rapport | TrueCrypt | EMET | Secunia PSI
Firefox: Addon security and privacy collection: https://addons.mozilla.org/en-us/fir...den/favorites/

Last edited by lordraiden : September 10th, 2011 at 10:35 AM.
  #396  
Old September 10th, 2011, 10:35 AM
abels's Avatar
abels abels is offline
Regular Poster
 
Join Date: Apr 2007
Location: Danang, VN
Posts: 91
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by lordraiden
Maybe you clicked on "do not sandbox this file again"
Or the file was recognized trusted by the Cloud and automatically added to the trusted list.

Have you check that the file is actually in the "trusted file list"? the second time that you open a file (in a short period of time) the popups informing that the file has been sandboxed does not appear but the file is sandboxed anyway, you can see it in the summary tab at the Defense+ section

I didn't click "do not sandbox this file again". The file is just a test file which automatically duplicates itself and in the second time it really affects my system. I think the file is trusted by the cloud as you said. Thanks
__________________
Comodo Internet Security v6
  #397  
Old September 10th, 2011, 10:38 AM
lordraiden's Avatar
lordraiden lordraiden is offline
Very Frequent Poster
 
Join Date: Jan 2006
Posts: 2,193
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by abels
I didn't click "do not sandbox this file again". The file is just a test file which automatically duplicates itself and in the second time it really affects my system. I think the file is trusted by the cloud as you said. Thanks

And there is nothing in the "Active process list (sandboxed only)" or in the "unrecognized file list"?

Name:  Capture.PNG
Views: 241
Size:  89.6 KB
__________________
Comodo Internet Security (No AV)
ZeroVulnerabilityLabs ExploitShield | Trusteer Rapport | TrueCrypt | EMET | Secunia PSI
Firefox: Addon security and privacy collection: https://addons.mozilla.org/en-us/fir...den/favorites/
  #398  
Old September 10th, 2011, 10:47 AM
abels's Avatar
abels abels is offline
Regular Poster
 
Join Date: Apr 2007
Location: Danang, VN
Posts: 91
Default Re: COMODO Internet Security 5.x Thread

There is nothing in the Active process list and unrecognized file list, It is automatically added to trust files. I have tried to remove it from trust files but when I run it, CF added it to trust files again. This is the file: -http://www.mediafire.com/?avss5d51zqhn8z1-
__________________
Comodo Internet Security v6
  #399  
Old September 10th, 2011, 10:55 AM
lordraiden's Avatar
lordraiden lordraiden is offline
Very Frequent Poster
 
Join Date: Jan 2006
Posts: 2,193
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by abels
There is nothing in the Active process list and unrecognized file list, It is automatically added to trust files. I have tried to remove it from trust files but when I run it, CF added it to trust files again. This is the file: -http://www.mediafire.com/?avss5d51zqhn8z1-

The files is not moved to my trusted file list, delete the rule and when the first popups appears check if you have checked the checkbox "add to trusted files" before you click ok.

Nobody should download it unless you want to fill you desktop of empty folders, although you can rapidly delete them via explorer
__________________
Comodo Internet Security (No AV)
ZeroVulnerabilityLabs ExploitShield | Trusteer Rapport | TrueCrypt | EMET | Secunia PSI
Firefox: Addon security and privacy collection: https://addons.mozilla.org/en-us/fir...den/favorites/
  #400  
Old September 10th, 2011, 11:13 AM
NormanN NormanN is offline
Regular Poster
 
Join Date: Jan 2011
Posts: 67
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by lordraiden
You can not give different levels for internet apps and unrecognized apps.

Just to make sure I was clear. I have the 'Unrecognized Files' slider set to 'Restricted', but I manually sand boxed .pdf readers, media players, browsers, etc... as 'Limited'. In the D+ Summary it shows the files as 'Limited' and 'Trusted'.

NN
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:48 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums