Regarding Comodo

Status
Not open for further replies.

Overkill

Level 31
Verified
Honorary Member
Feb 15, 2012
2,128
Okay, it's been awhile since using Comodo and the settings are different and some are gone. Where do I set the sandbox to "Fully Virtualized"? I don't see that anywhere!

Also, from top to bottom how do you have CF configured?
 
  • Like
Reactions: Cats-4_Owners-2
H

hjlbx

Okay, it's been awhile since using Comodo and the settings are different and some aren't the same. Where do I set the sandbox to "Fully Virtualized"?

"Run Virtually" is now the default setting for the auto-sandbox. It can be accessed by double-clicking on the Unrecognized file rule listed on the auto-sandbox rules pane.

For greatest security set it to "Untrusted."

However, even at default settings ("Run Virtually"), file system and registry access outside the sandbox are redirected to the virtual container, plus other suspicious activities are blocked - like accessing raw disk, raw memory or system services. It is precisely this sandbox design that explains why many malwares will not even run inside Comodo sandbox. NOTE: This design cannot be modified by the user... it is the way Comodo engineering implemented the virtual container and the basic rules that govern its behaviors.
 

Overkill

Level 31
Verified
Honorary Member
Feb 15, 2012
2,128
"Run Virtually" is now the default setting for the auto-sandbox. It can be accessed by double-clicking on the Unrecognized file rule listed on the auto-sandbox rules pane.

For greatest security set it to "Untrusted."

However, even at default settings ("Run Virtually"), file system and registry access outside the sandbox are redirected to the virtual container, plus other suspicious activities are blocked - like accessing raw disk, raw memory or system services. It is precisely this sandbox design that explains why many malwares will not even run inside Comodo sandbox. NOTE: This design cannot be modified by the user... it is the way Comodo engineering implemented the virtual container and the basic rules that govern its behaviors.
AHHH I see, so in auto sandbox settings I set the 3 bottom "run virtually" options to untrusted?
 
H

hjlbx

AHHH I see, so in auto sandbox settings I set the 3 bottom "run virtually" options to untrusted?

Just for Unrecognized files... you want them to be treated as Untrusted when run inside the sandbox (auto-sandboxed by CIS). Only change the Unrecognized file auto-sandbox rule - and here is why:

For Malicious and Suspicious locations just leave them at Blocked setting... you want these files to be Blocked.

If you change the setting for Malicious and Suspicious locations to Run Virtually you will create an auto-sandbox rule that will permit malware not detected by Comodo AV - or your AV of choice - to run on your system ! In that case, the default sandbox might not be able to protect your system against some malwares !
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
how to enable Full V in Comodo 8?
Is it done by removing the check from "do not virtualize access to the specified file/folders"?
 
  • Like
Reactions: Dirk41

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
thanks.
I also noticed that HIPS is off by default.
 

Av Gurus

Level 29
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Sep 22, 2014
1,767
thanks.
I also noticed that HIPS is off by default.
If you turn on Proactive mode in configuration (recommended) Hips will be turned on.
You can always turn it on/off manuali
 
  • Like
Reactions: Dirk41

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
If you turn on Proactive mode in configuration (recommended) Hips will be turned on.
You can always turn it on/off manuali
Their help says that Proactive mode puts it in some kind of super-protection state, with all the settings maxed out. Will it interfere with normal functioning of the computer, and with productivity? I'm just wondering whether Proactive is more trouble than it's worth.
 
  • Like
Reactions: _CyberGhosT_

Av Gurus

Level 29
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Sep 22, 2014
1,767
It should not be.
If you are not frendly with Comodo just turn off hips and you should be fine.
 
D

Deleted member 178

Their help says that Proactive mode puts it in some kind of super-protection state, with all the settings maxed out. Will it interfere with normal functioning of the computer, and with productivity? I'm just wondering whether Proactive is more trouble than it's worth.

All setting aren't max out, but it is the safest configuration. Most CIS' bypasses i heard were made against default settings.
 
  • Like
Reactions: 1qay1qay

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
thanks guys, I will give it a try.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top