App Review COMODO Internet Security Pro 2027

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
Shadowra

Shadowra

Level 42
Thread author
Verified
Top Poster
Content Creator
Malware Tester
Well-known
High Reputation
Forum Veteran
Sep 2, 2021
3,101
39,684
4,080
29
France
COMODO is an American publisher, well known among computer geeks.
The software presents itself as a totally free security suite, offering defensive shields: anti-malware, firewall, HIPS and a sandbox.
We got the software first, so here's our test!

Let’s take a closer look at all of this.



Interface :

The interface is identical to that of the 2026 version. The new feature is in the configuration: Comodo now includes EDR!
In fact, the EDR will detect dangerous behavior and attempt to mitigate the ongoing attack. This is a major plus.
The antivirus is also trying to become a bit more accessible to beginners, even though it remains geared toward advanced users.
During installation, I accepted Comodo’s secure DNS and cloud-based scanning.

Malware URL : 8/8
Comodo does not block any websites using its web filtering or DNS. Only one piece of malware is blocked by its anti-malware engine.
Other malware is sent to the sandbox without attacking the system.

Malware Pack : 109 out of 162 threats remain
COMODO's anti-malware is clearly bad, and it has been for years.
On the other hand, Comodo's strength is its sandbox!
Even when I threw some major challenges at it (like two ransomware samples that locked up the system and were difficult for me to deal with so I could continue the test), the machine held up.
And we started from a tough spot! Between Trojans, attacks, and computer worms, the memory was completely saturated!
But the sandbox is NOT perfect. ConnectWise slips through undetected because it’s signed (so Comodo trusts it) and the machine is riddled with traces of infections detected by Comodo itself during a quick scan and by other scanning tools (KVRT even detects a memory infection!!)

Final scan :
Comodo 5
Symantec : 14
Emsisoft : 14
KVRT : 12 (Memory infected !!)
Eset : 9

Final opinion:

It's hard to give it a rating.
Comodo is a good basic product, but it has several drawbacks:
- Very poor anti-malware protection
- The sandbox is good but won't prevent a memory infection or a registry entry made by malware (you can see the traces in JS/VBS scripts)
- Web filtering is nonexistent

Given these shortcomings, I don’t really see Comodo as a complete suite. But it could work as a backup alongside another antimalware program.
 
This result was expected for CIS default settings (Internet Security configuration). It auto-contains the unrecognized files (also digitally signed) that are less than 3 days old. CIS can also skip containing the signed malware if the signer is on the Trusted Vendor List. There can also be some false negatives (Valkyrie Snadbox bypassed). I am not sure which was the case in the video. In the case of a false negative, the malware would be auto-contained as a 0-day (the Comodo Valkyrie analysis can take some days).
That is why the recommended setup for CIS (on MT and Wilders Security forums) is Proactive Security configuration + reduced Trusted Vendor List (false negatives can still bypass the auto-containment in the test).
Comodo auto-containment with Internet Security configuration was tested many times by SE Labs, and the results were similar to those in the video.

SE Labs 2024 (Consumer):

total samples ........................... 300 100
Avast Free Antivirus ............... 0 ...... 0
Comodo Antivirus .................. 0 ..... 7
Kaspersky Plus ......................... 0 ..... 0
McAfee Total Protection ...... 0 ..... 1
Microsoft Defender ............... 3 ..... 0
Norton360 ................................ 0 ..... 2
Panda Free/Dome .................. 4 ......13
Sophos Home Premium ...... 0 ...... 0
Webroot Antivirus ................. 2 ...... 9

As we can see, the result for commodity malware (the first scoring column) is perfect, but not for targeted attacks (the second scoring column).
 
Last edited:
The malware that bypassed CIS has the hash:
5be3d0c61d7c148eb9af81065b064b3ec8ae0f80138e201255d679ef6ebe7537
It was uploaded to VT 5 days ago under the name: BankChatClient_Installer.msi

CIS was bypassed because the attack uses benign binaries: msiexec.exe, rundll32.exe, etc. + ScreenConnect.InstallerActions.dll
The last file (hash: a45ba86c5d13aa8e814e4cb0860b5b2a39ce9677b0d980947f6fe31676051cb2) is undetected by most AVs (uploaded to VT over 3 months, one year ago). It is most probably a false negative (Valkyrie bypass).
So, the successful infection is most probably caused by poor detection (initial MSI file) combined with a false negative (DLL binary).
The MSI runs rundll32 to execute the DLL. If the DLL is false negative, it is not auto-contained.
If the DLL was unknown, the Script Analysis restrictions would cause auto-containment.

It is worth mentioning that CIS + SmartScreen for Explorer could score perfectly in this test.
 
Last edited:
I've used Comodo in the past for quite & while & with success, but at the moment I'm doing far better with Kaspersky Standard or McAfee, both are trouble free, cost the price of a couple of coffee's, require little attention & just do the job, & do it very well indeed, the video was not a compete surprise to me, that's how I see it, no offense to those who use & like Comodo, in my view times have changed, I'm starting to feel the same regarding Emsisoft a product I used for many years :)
 
I've used Comodo in the past for quite & while & with success, but at the moment I'm doing far better with Kaspersky Standard or McAfee, both are trouble free, cost the price of a couple of coffee's, require little attention & just do the job, & do it very well indeed, the video was not a compete surprise to me, that's how I see it, no offense to those who use & like Comodo, in my view times have changed, I'm starting to feel the same regarding Emsisoft a product I used for many years :)
Every time someone mentions Kaspersky, I just say "Why, why, why" ...

If they ever get approved again, they'll show themselves to be the most popular security software available, the sales receipts will be off the charts.

I love my country, but damn I'm tired of the people in my Gov who make dumbass decisions, day in and day out. No common sense...

They're like some idiot standing on the corner with a doomsday sign, stating Kaspersky is going to destroy the world, meanwhile every other country keeps using it.
 
It is most probably a false negative (Valkyrie bypass).

Here is the Valkyrie verdict for dropped DLL:

1785146871268.png


Any.Run screenshot:

1785147659877.png


Valkyrie can have a problem with such malware, because the executables are not entirely malicious but can read some non-executable malicious configuration information embedded in the MSI installation. As we can see from the screenshot below, Valkyrie detected the initial MSI malware 26.07.2026:

1785148464932.png
 
Last edited:
CIS auto-containment may likely have a general issue with ConnectWise malware delivered via MSI installations. It would be interesting to see if additional hardening of the LOLBin msiexec.exe via Script Analysis settings could force malware auto-containment.
Without additional hardening, the Comodo users must rely on SmartScreen for Explorer or use the Comodo Firewall + AV with better detection.
 
It was great to see the CIS test. Comodo's strength has always been its sandbox! I've always liked that, and the firewall is good, too. Unfortunately, Comodo falls short in web protection and malware detection rates. As @Khushal said in his post #2 This should settle the debate! BTW @Shadowra Thank you so much for the review. I enjoyed your video—as always, the music was handpicked, and the video editing was top-notch. I’d already been missing your videos; they’re such a pleasure to watch. Congratulations on the great video. ;) 💯
 
CIS auto-containment may likely have a general issue with ConnectWise malware delivered via MSI installations.
Am I missing something here? Comodo worked as expected and as per its design!
Isn't ConnectWise legitimate software? Kaspersky detected ConnectWise files as "legitimate software that criminals can use."
The "Don't virtualize files/folders" containment setting appears to be the reason for the remnants in the "Shared Space" folder.

Comodo had a bug; it didn't contain MSI installers. I'm unsure if it affected the default or all configs and if they fixed it.
 
Am I missing something here? Comodo worked as expected and as per its design!
Isn't ConnectWise legitimate software? Kaspersky detected ConnectWise files as "legitimate software that criminals can use."
The "Don't virtualize files/folders" containment setting appears to be the reason for the remnants in the "Shared Space" folder.

ConnectWise is a remote admin tool that can be abused by the MSI installer when it uses non-executable malicious configuration information.
CIS can auto-contain the unrecognized executable content initiated by the MSI installer, but in this case, that content is trusted by Comodo.
CIS tries to force auto-containment of MSI installer actions via Comodo Script Analysis by restricting the msiexec.exe LOLBin, which hosts MSI files.
However, the default settings are ineffective in the case of ConnectWise malware (MSI installer).

Comodo had a bug; it didn't contain MSI installers. I'm unsure if it affected the default or all configs and if they fixed it.

It is not a bug but a security design. MSI file can be auto-contained only when it is opened by something already sandboxed. Normally, when you open an unrecognized MSI file, the system executes msiexec.exe, which takes control over the installation. Some actions can be auto-contained and some not, depending on the executable content and Script Analysis settings.

In many cases, the MSI installer tries to execute PowerShell or Windows Script Host scripts, and they can be auto-contained. The same is true when the installation runs rundll32.exe to execute unrecognized DLLs. Such actions are restricted via Comodo Script Analysis.

But Script Analysis is ineffective when the MSI installer uses the Trusted vulnerable executable + DLL hijacking or runs LOLBins + Trusted DLLs that read the malicious configuration of remote admin tools. There are probably some other possibilities of abusing trusted binaries (like Electron applications with modified Node.js, etc.).

The msiexec.exe LOLBin can be additionally hardened in CIS against abuses, but I never tested how effective it can be.
 
Last edited: