App Review Comodo Firewall vs A CryptoCurrency Miner Part 2

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

cruelsister

Level 42
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,149


At 1:53 of the video I opened the Network Intrusions section of Comodo by accident (the Firewall was Disabled, nothing would show up here) instead of the OutBound Connection section (which would show the malware was not connecting out).

But no matter, as is explained in the text box that followed (Point 3) the malware could not get out due to a specific HIPS block.
 

tonibalas

Level 40
Verified
Honorary Member
Top Poster
Well-known
Sep 26, 2014
2,973
Thank you for the video, a very nice review of Comodo HIPS.
When i had CFW installed at some point i disabled the sandbox and i had HIPS enabled.
As a novice user i learned some things about what processes are trying to do, a great lesson in my opinion.
I might install it again since CFW was stable in my system.
Of course when i had sandbox disabled and i was testing stuff i had Shadow Defender enabled just to be safe;)
 

EASTER

Level 4
Verified
Well-known
May 9, 2017
145
yes, extremely useful video for all I think.

What fascinates me about CFW 10 is this.

You have a somewhat modularized suite of sorts where nearly if not all components relay their respective user (or machine) selected rules (based on various responses) to the FILE LIST and even that can be broken down into it's various levels etc. Beautiful!!

I think I got that right, CS is obviously way more detailed (even in brief!) and already well seasoned as well as generous in taking the extra effort to help everyone go the next (and/or) extra steps offered in this program.

One question escapes me though. is there a way to also clear the BLOCKED list? or is that by design.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
the malware could not get out due to a specific HIPS block.
I actually noticed today, as I was fuddling around, that HIPS in proactive mode produces some interesting network blocks, and it does not produce the same blocks in firewall mode.

On my system, there was a network block for svchost and dasHost, both trusted Windows processes. (I was not testing malware samples, just regular PC use.)
Don't know why it did that, but it is showing its alertness...
 

novocaine

Level 5
Verified
Well-known
Aug 19, 2016
200
@cruelsister, you may get another bracelet from Melih very soon :D

Capture.jpg


Capture1.jpg
 

cruelsister

Level 42
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,149
Dear God, did they do this again? I have the Comodo info popups disabled by default so I had no clue. If this keeps up I suppose I should have some sort of snazzy video introduction with Graphics and Swelling, Ominous Music:

THE GODESS OF GLOOM
THE PRINCESS OF DARKNESS
THE COLD HEARTED SLAYER OF MALWARE

On second thought I'll pass and continue to do low quality half-assed stuff.

Fortunately I'll be out on the Hamptons for two weeks (have to love working for an investment Bank with beach front properties), and when I come back I hope I'll be back down to my usual 200 viewers!
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top