COMODO Internet Security 8.2.0.4508 is released!

Status
Not open for further replies.
Y

yigido

Thread author
guys, could you please test "File Submit" feature?
Does it able to upload files to Comodo?
You can find "File Submit" here
XpX68vT.png
 
H

hjlbx

Thread author
Yigido, I have some advanced technical questions. Could we do some trouble-shooting via PM ?

File submit has been fixed for a long time now...
 

zeusc4

Level 4
Verified
Feb 2, 2013
164
Thank you for the post!

Dear friends, we are waiting for your feedbacks for our new release. Most importantly, we would like to get your feedbacks about new AV egine and new file rating list.

Thanks in advance

Kind Regards
Buket
new engine ? or old engine with small improve ?

btw i like to see quick software updates from comodo like now comodo do
 
S

starchild76

Thread author
new engine ? or old engine with small improve ?

  • Improved:
Antivirus Engine:

• RAR 5 archives support
• Unicode support to RAR5 module added.
• Make CIS AV update process lighter on system resources & optimization merging of AV-bases
• Support new 7-zip version

plus some under the hood improvements , I guess which are not listed you can ask @BuketB for more details on this ;)
 
D

Deleted member 2913

Thread author
CIS uninstall doesn't remove ADS from files.
I think CIS uninstall should remove ADS from files.
And would be good if disabling ADS option asks the users to remove/keep already applied ADS to files.

I use Bvckup 2 to backup files to external HDD.
Bvckup 2 has delta backup feature i.e only new & modified stuff is backed up after 1st backup.
I do backup weekly or once in 15 days.

Would this ADS thing create probs for Bvckup 2, especially delta backup feature?
modify_inline.gif
 
Last edited by a moderator:
H

hjlbx

Thread author
What precisely is Comodo's ADS issue ?

I haven't looked it up on the Comodo forum.

Can someone help me out and explain it so I don't have to dig around the Comodo forum ?
 

cruelsister

Level 43
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
It's Metadata created by Comodo when files are run, done to increase the efficiency of the sandboxing procedure. In (really) short it's a file identifier added to executables and dll's. The addition will change the applications timestamp and one may get some alert when copying such a file from the NTFS file system (where ADS is native) to a FAT partition- this is predominantly seen when copying a file from your computer to a flash drive (an alert will pop up that the file has properties that can't be copied, but what is actually occurring is that the metadata is being stripped off when the file is copied), but other than taking up some little extra space on the HD the Streams are totally benign.

Just as an FYI, for any that use Internet Explorer, metadata is created fairly often under the favicon stream which assists IE to identify the identity of a website, as well as Zone.Identifier for downloaded programs.

The fact that some malware authors will backdoor legitimate files with malware (like rootkits) hidden in an attached created ADS has made some nervous about any Stream. Personally I don't see this as a reason to disable useful sandboxing functionality (but that's just me).
 
  • Like
Reactions: Cats-4_Owners-2
H

hjlbx

Thread author
That's no biggee...

OneDrive rips the ADS away and so does restoring some files from quarantine - like with Emsi.

I just wasn't sure what was up... and too lazy to search Comodo's forum.

Thanks @cruelsister
 
H

hjlbx

Thread author
I've been testing Webroot and Comodo.

I'm testing both against the two most recent Virussign packs.

Webroot: 85 % upon scan, additional 3 to 12 % upon execution (All Cloud-based query system).

Comodo: 80 % upon scan, additional 1 to 2 % upon execution (AV Cloud lookup; Heuristics).

Even with its improved AV scan engine, Comodo is still lags behind.

Despite this fact, CIS is less problematic than it was back in version 7.

It's resource usage is low during normal workload on my W8.1 system.

It's improving... testament to all the work put in by the dedicated core of users.

They're talented, pretty tough... and thorough.
 

viktik

Level 25
Verified
Well-known
Sep 17, 2013
1,492
after comdo cloud lookup , it says safe files have been moved to local Comodo certified files database.
there is file list.
Where is local Comodo certified files database?



COMODO_FIREWALL_8_2_CLOUD_LOOPKUP_08_04_2015_14.jpg
 

Nirv5668

Level 2
Verified
Mar 21, 2015
88
I've been testing Webroot and Comodo.

I'm testing both against the two most recent Virussign packs.

Webroot: 85 % upon scan, additional 3 to 12 % upon execution (All Cloud-based query system).

Comodo: 80 % upon scan, additional 1 to 2 % upon execution (AV Cloud lookup; Heuristics).

Even with its improved AV scan engine, Comodo is still lags behind.

Despite this fact, CIS is less problematic than it was back in version 7.

It's resource usage is low during normal workload on my W8.1 system.

It's improving... testament to all the work put in by the dedicated core of users.

They're talented, pretty tough... and thorough.
Interesting- I thought both of these software had novel protection ideas, but it looked like with the right settings, Comodo was much more solid on protection. So, if I understand correctly, even if Comodo doesn't detect on scan or execution, it would still run sandboxed (on default settings as well). In Webroot, if it doesn't detect, you just have the rollback feature where you have allowed your real system to become infected, keystrokes recorded, etc. and then rely on rollback to undue changes (which doesn't work 100% in informal testing). It would be interesting to compare rollback to viruscope (sort of like rollback?)- which I think would be more apples to apples, but you would have to turn off HIPS and sandbox in Comodo to make this 'even' and just test viruscope (which kind of makes it seem like Comodo provides more security layers even with lower detection). Not sure though, they are both really interesting and I was wondering how they compared, so thanks for the test!

I'm also finding that Comodo is running really well on my PC (8.1). I hope they fixed the RAT bypasses that were posted on youtube (ex: , but there were others). My only other concern is how the trusted file system could be manipulated in Comodo...could a file be classified as trusted but turn out to be malicious? Maybe by not executing in Comodo's testing environment? Or by infecting a previously trusted file? But, I don't know if this is technically possible/feasible.
 

Nirv5668

Level 2
Verified
Mar 21, 2015
88
I'm shocked, considering that idiot told me he could charge for using their support and he told an out-right-lie! I do apologize and retrack my statement.
I am really glad I read this! I just saw a rebate deal for Kaspersky and sent it to a friend who likes this type of suite...but fully not supporting 64-bit is scary and lying about it is even worse. I have to say, the support ticket system with Comodo (support.comodo.com), which is free and available with free version, has been way better than I expected! Not sure I would know if/when they were lying, but so far they are quick, helpful, and will give clear direct answers to questions.

I love comodo with its many layers i dont care about their lack in signatures I feel safe with comodo customized for max protection I use secureAplus with it though
Interesting, I haven't tried secureAplus, but just had a look at their website. If I understand, it maintains a whitelist based on 10 AV cloud scanners...does its whitelist suggestions ever differ from Comodo's or do you use it for decisions on unknown applications?
 
Last edited by a moderator:

Billcomputerman123

Level 5
Verified
Feb 12, 2015
207
Interesting, I haven't tried secureAplus, but just had a look at their website. If I understand, it maintains a whitelist based on 10 AV cloud scanners...does its whitelist suggestions ever differ from Comodo's or do you use it for decisions on unknown applications?
nah i use it for signatures lol because of comodos lack in signatures but it works along side other avs not that i can notice
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top