Comodo Internet Security 2013?

Discussion in 'other anti-virus software' started by ahinterl, Jan 3, 2013.

Thread Status:
Not open for further replies.
  1. guest

    guest Guest


    Yes you are right. if file is safe, autosubmit or manuel submit result is not fast. Actually i never see whitelisted file which is uploaded by autosubmit options.
    But i see blacklisted files many times. Blacklist generation is easy. It upload files to CIMA and result turn back within 2-3 minutes. it is very powerful i think.

    But safe file dedection is not easy, it need manuel analysis.

    And i think autosubmit is for malware files not for safe files. They just collect files and checking for malicious activity.


    it will change user to user.
    i think there is not better free alternatives. is there better paid alternatives?
    maybe but they will not perfect also. CIS has some problems but all others have some problems.

    i used kaspersky.
    Vulnerability scan dedect 1 vulnerability but doesnt show anything.
    i report it forum;
    http://forum.kaspersky.com/index.php?showtopic=255182
    there is no help since 1.02.2013


    User want/believe to Perfect CIS but it isnt. And also others.
     
  2. spywar

    spywar Registered Member

    Joined:
    Oct 23, 2012
    Posts:
    583
    Location:
    Paris
    Test it yourself ..
     
  3. spywar

    spywar Registered Member

    Joined:
    Oct 23, 2012
    Posts:
    583
    Location:
    Paris
    It's quite simple :
    You run an unknown file (never seen by Comodo i.e not already submitted)
    It's submitted to CIMA
    if it finds suspicious activity it generates a signature ..
    That works pretty well as you can see here http://www.comodo.com/home/internet-security/updates/vdp/database.php
    Now we need to think about number of FPs generated every day ...
     
  4. guest

    guest Guest

    You are talking about FP,
    Actually i never see FP on my computer.
    There are many unknown files, CIS want to sandbox them but i never get FP alert from their AV.
     
  5. spywar

    spywar Registered Member

    Joined:
    Oct 23, 2012
    Posts:
    583
    Location:
    Paris
    Uhhhh on your pc maybe it's ok but what about the others 50 M users ? ......
     
  6. guest

    guest Guest

  7. spywar

    spywar Registered Member

    Joined:
    Oct 23, 2012
    Posts:
    583
    Location:
    Paris
  8. guest

    guest Guest

    in this case, i never see example on my computers.
    but i am with you, because there are same situation for unknown files.

    v1 unknown, i sent sample them, whitelisted
    v2 released, and everything start again. because it is unknown.

    i hope they can fix your problem.
     
  9. spywar

    spywar Registered Member

    Joined:
    Oct 23, 2012
    Posts:
    583
    Location:
    Paris
    Only a FileRep system can deal with that issue (automatic whitelisting by prevalance...)
     
  10. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    I've being trying CIS without TVL for a day. I've deleted "vendor.n" and the TVL is clean now. BB Auto-Sandbox is in "Limited". HIPS is on, in "Safe Mode". All apps are launched without any popup. I thought there must be an avalanche of popups. Or maybe I missed something?
     
  11. atomomega

    atomomega Registered Member

    Joined:
    Jul 27, 2010
    Posts:
    1,290
    Also, for HIPS make sure the box that says "Do NOT show popup alerts" is not checked. And for the BB make sure the box that says "Detect installers and show privilege alerts" is checked.
     
  12. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    They are implemented, of course. The checkbox 'Create rules for safe applications' is unchecked.

    There are dozens of rules in the "HIPS Rules" for my apps. This is why no popups.

    I also disabled all boxes in the "File Rating Settings".

    Have I done all to disable TVL?
     
  13. atomomega

    atomomega Registered Member

    Joined:
    Jul 27, 2010
    Posts:
    1,290
    As far as I know, yes. I also deleted the vendor.n file and all TVL was gone.
     
  14. spywar

    spywar Registered Member

    Joined:
    Oct 23, 2012
    Posts:
    583
    Location:
    Paris
    Is Cloud Lookup still on ? If yes that's a normal behavior.
     
  15. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Now:
    1. "vendor.n" deleted and OS is rebooted
    2. TVL is empty
    3. Cloud Lookup and all other boxes on "File Rating Settings" are clear

    Shouldn't I miss anything?

    Still no popups for my routine apps maybe because there are dozens of rules in the "HIPS Rules" and hundreds in "Trusted Files". Am I right?
     
  16. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Check explorer.exe permissions in HIPS rules? Is it allowed to execute any exe?
     
  17. atomomega

    atomomega Registered Member

    Joined:
    Jul 27, 2010
    Posts:
    1,290
    What's the downside of running as Fully Virtualyzed versus running as Untrusted?
     
  18. KelvinW4

    KelvinW4 Registered Member

    Joined:
    Oct 11, 2011
    Posts:
    1,199
    Location:
    Los Angeles, California
    The files are not really written on the real drive, unlike untrusted. So what ever files you want to recover....... ;)
     
  19. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    The rule is "Ask". Is it OK?
     

    Attached Files:

  20. atomomega

    atomomega Registered Member

    Joined:
    Jul 27, 2010
    Posts:
    1,290
    Ok, thank you. :)
     
  21. wasgij6

    wasgij6 Registered Member

    Joined:
    Mar 29, 2011
    Posts:
    321
    under exclusions is says modify 44/0, that means you have 44 exes that are allowed to be run (from explorer.exe) without an alert this happens when CIS asks to execute a file and you allow it and click remember your answer.
     
  22. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Thanks a lot!

    I've examined the list and excluded some apps which I won't use. All the rest were my routine apps and "shell32.dll" (btw why "dll" in "exe"?).
     
  23. blacknight

    blacknight Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    3,351
    Location:
    Europe, UE citizen

    If you didn't already set, better set "ask " also system32\msiexec.exe.
     
  24. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    No, it is not set. But anyway it will ask if needed, isn't it?
    BTW isn't it for installers *.msi?
     
  25. avman1995

    avman1995 Registered Member

    Joined:
    Sep 24, 2012
    Posts:
    944
    Location:
    india
    REMOVED.
     
    Last edited: Mar 24, 2013
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.