Comodo HIPS found this...

Status
Not open for further replies.

128BPM

Level 2
Thread author
Verified
Feb 21, 2018
90
I eliminated the M$ signatures in the TLV and then I activated Paranoid mode. My intention was to know what processes the system was performing in background.
The HIPS found this:

Capture.JPG

My question is whether this is a normal system process?

Thanks.


Note: I have win 7 64
 
Last edited:

cruelsister

Level 42
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,147
Please don't use Paranoid mode! Trust me, it will drive you absolutely insane and will not increase your protection over the settings I recommend (if you want to absolutely HATE Comodo, use Paranoid Mode).

As to what Paranoid Mode finds, God Alone Knows...
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361

JoseyWales

Level 1
Verified
Jul 23, 2018
33
Greetings to All- for a short intro, I've worked with computers since 1980 (Times Sinclair/Commodore 64)..studied DOS 5 extensively in the day...familiar with AA/SA/UAC settings for system setups and usage...I'm the average 'safe' user with the internet...I have a fair (lay) understanding as far as being 'safe' with one's system and setup. I am a fan of ZoneAlarm's latest Suite and now I'm here attempting to digest the vast details that cover Comodo's design and diverse methods of securing its host system. And I must add that my short term memory forces me to come back here again and again ....

Its only been this summer that I discovered the Comodo series of system securities. I had two incidents using ver 10 when my system would cease to startup/reboot... not confused about running multiple security setups unless they are bundled from the same author/company. My guess was that somehow I must have triggered the wrong setting(s) in Comodo 10 suite, so it was back to loading a fresh os..and I use a hardening method of killing alot of services, killing any and all Ivp6 incoming plus blocking unwanted events in Win8's FW. Once I'm satisfied and all updates are implemented, my last step is to load ZoneAlarm's suite.

So I've come back a couple of months later wanting to give Comodo another go...I discover that ver11 is out and the full suite is available, so I opt in.

To teach myself the how's and why's with Comodo, I use two programs to experiment- Steam and Thunderbird. So, with the help of all those posting here, and a large thanks to the same, I signed on hoping that I can contribute to answering some posts while raising questions that may fall out of the box categories.

Thanking you ahead for your postings and research-
Josey
 

Attachments

  • Comodo_Fog.png
    Comodo_Fog.png
    489.9 KB · Views: 624

AtlBo

Level 28
Verified
Top Poster
Content Creator
Well-known
Dec 29, 2014
1,711
My question is whether this is a normal system process?

@cruelaiater is as always correct. Paranoid mode alerts for all the possible HIPS rules for each and every process that starts. Those I have talked to who use it expect 1000 alerts a day until they have allowed and remembered all the safe elements. HIPS for unrecognized combined with the cloud and Comodo's TVL are powerful enough in HIPS Safe Mode to give you a look at the activities of anything Comodo doesn't auto-approve (isn't Comodo trusted or trusted by you). Also, remember, you have the container there to catch anything unrecognized. So HIPS is just about seeing what unrecognized want to do basically...as far as I can see anyway.

That is a Windows process btw. With all the changes to Windows coming through updates, I imagine that Paranoid must be really almost impossible to use in Windows 10. Still there are some who love the Paranoid mode here at MTs...once they have the system "trained" lol...
 
D

Deleted member 178

Paranoid Mode isn't supposed to be used directly out of the box, you have preliminary works to do; but once all is set, there is no match to its protection , there is no windows/doors left open in the house, unlike other settings you may use with comodo..

In the past when Comodo staff mistakenly whitelisted a malware, guess what was the only module that caught it: HIPS on Paranoid.

When i was on v8 i use paranoid all the time, get some alerts from time to time, but not the big alert rain like some said.
 
5

509322

I eliminated the M$ signatures in the TLV and then I activated Paranoid mode. My intention was to know what processes the system was performing in background.
The HIPS found this:

View attachment 185719

My question is whether this is a normal system process?

Thanks.


Note: I have win 7 64

Do you not know whether or not your system is clean ?

If you don't, then it is too little. too late.

A ton of Windows stuff can be rated as potentially malicious. If you cannot differentiate them from the real malicious actions, then you shouldn't be using HIPS at all.

Learn HIPS on a known clean system. If you don't know whether or not your system is clean, then you should clean install Windows.
 
Last edited by a moderator:

JoseyWales

Level 1
Verified
Jul 23, 2018
33
Do you not know whether or not your system is clean ?
If you don't, then it is too little. too late.
A ton of Windows stuff can be rated as potentially malicious. If you cannot differentiate them from the real malicious actions, then you shouldn't be using HIPS at all.
Learn HIPS on a known clean system. If you don't know whether or not your system is clean, then you should clean install Windows.

I have to agree. The sure way to give Comodo its best run (as with any trusted security suite) is to let Comodo be the very first application loaded into your windows os environment. Once installed, Comodo must examine every file that Windows installs so it can sign and record it for future comparisons. And Im willing to skip windows updating for now and let comodo handle any wrong doings (using paranoid HIPS)...there was the 'rain' of alerts for the first hour, then things settled down and all has been good. This is the point of Lockdown- allow HIPS to home in and train on a clean windows...then proceed with your needed app installations...home in and train...etc etc- after running paranoid hips for a few days (when all apps are loaded/processed)...all of Comodo will be completely trained and will grow with the cloud as intended.. just be sure you think about that mile long list of trusted vendors and trusted files. Personally, I opt to NOT Trust approved files coming into the system by Trusted vendors.
 

128BPM

Level 2
Thread author
Verified
Feb 21, 2018
90
An apology to all for not answering, I have not entered the forum a long time ago.

Do you not know whether or not your system is clean ?

If you don't, then it is too little. too late.

A ton of Windows stuff can be rated as potentially malicious. If you cannot differentiate them from the real malicious actions, then you shouldn't be using HIPS at all.

Learn HIPS on a known clean system. If you don't know whether or not your system is clean, then you should clean install Windows.

Hi @Lockdown,

I have some years of using Comodo Hips (from win 98) and my system is static, I think that in all this time I have fine tuned the Hips.
I rarely have alerts and this was one of them, so I suspected :cautious:
 
  • Like
Reactions: JB007 and ZeroDay
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top