- Jan 29, 2016
- 812
Hope you all enjoyed the video
Thanks for watching
For any that feel the need to pair CF with an AV, note that the only difference you will notice is that the amount of things that Comodo will sandbox is inversely proportional to the quality (and timeliness) of the AV's definitions.
For example, use an AV that is not all that good (like Clam) and Comodo will sandbox a bunch; use something like Qihoo or VS and less work will be done by the Sandbox (less with VS, obviously). But with any combination the baseline excellent protection level will be the same.
Safe1st- very nice video, and I thank you for taking the time to do it! But a few things:
1). Malwarebytes is detecting things in the Comodo quarantine folder because of the way Comodo places them there. When the Comodo AV detects something it will quarantine it by changing the file name to some random string and will remove the extension (so it can't ever be run); but it will maintain the file ID (the SHA256). Therefore MB is just doing it's thing of dumb detection- alerting you to a file ID without knowing if the file can be run or not.
This pretty much typifies how traditional AV's work (and why I disklike them so much)- an example would be that you would recognize me if I wore my Black dress, but would have no idea who I was if I wore my Red dress.
2). Comodo with the sandbox at the default Partially Limited will allow malware artifacts to be dumped into Temp, as well as allowing various environmental changes to be made; changing the sandbox level to Restricted or Untrusted would prevent these things (I'll be releasing a video this weekend on just this- and I hope you guys like listening to Chill).
3). Unless you are testing something in the sandbox (or have your browser sandboxed), the Firewall settings should be set to prevent anything in the sandbox from connecting out (just like Sandboxie). That setting will be seen at 2:22 of this video- Check the "Do NOT show popup alerts" and change to Block Requests.
For any that feel the need to pair CF with an AV, note that the only difference you will notice is that the amount of things that Comodo will sandbox is inversely proportional to the quality (and timeliness) of the AV's definitions.
For example, use an AV that is not all that good (like Clam) and Comodo will sandbox a bunch; use something like Qihoo or VS and less work will be done by the Sandbox (less with VS, obviously). But with any combination the baseline excellent protection level will be the same.