Advice Request Comodo Internet Security Setup/configuration thread

Please provide comments and solutions that are helpful to the author of this topic.

Does this thread helped/informed you?


  • Total voters
    94
Status
Not open for further replies.

Raul90

Level 14
Feb 5, 2012
658
Very informative thread here. I have EAM alongside CIS with HIPS and MBAE free there are no issues. The issue that I did encounter was in the HIPS feature whenever I update to the latest version. Even-though I have imported the previous config the HIPS module seems not to be functioning properly. First I had to do the rules creation from scratch. Later when I updated from ver8.2.0.4703 to ver8.2.0.4792 I imported a saved config then activated it. Afterwards used the "Paranoid Mode". Ran a frequent program I block in CIS and let CIS HIPS throw it's pop-ups. After that I switch to "Safe Mode". Ran all I frequently block in CIS and wallah HIPS was functioning again.
 

void011

Level 2
Verified
Nov 25, 2015
51
Is it fine if I set default download folder as Shared Folder to keep downloaded files from sandboxed browser? Should I cover Shared Folder by Appguard in case there's no way else?
*just moved back to Windows :D*
 
D

Deleted member 178

Thread author
Is it fine if I set default download folder as Shared Folder to keep downloaded files from sandboxed browser? Should I cover Shared Folder by Appguard in case there's no way else?

yes and yes
 
  • Like
Reactions: void011

aseu2k15

Level 1
Verified
Nov 26, 2015
44
Anyone has issue with CIS latest and Chrome? The browser won't launch, when I click chrome shortcut it just loading a second and nothing happen. But when adding chrome.exe to HIPS "Detect Shellcode Injections" exclusion, chrome worked!
I found this issue on previous version and the chrome hot fix has out.
Happened again on this lastest version?
 
D

Deleted member 178

Thread author
Anyone has issue with CIS latest and Chrome? The browser won't launch, when I click chrome shortcut it just loading a second and nothing happen. But when adding chrome.exe to HIPS "Detect Shellcode Injections" exclusion, chrome worked!
I found this issue on previous version and the chrome hot fix has out.
Happened again on this lastest version?

Yes i gad the issue and i solved it as you did; we have the issue because of HMPA.

i removed Comodo, too much hassle and tweaks to get it secured enough...
 
H

hjlbx

Thread author
Added both but still crashing when launched. I don't even get to see the gui. Weird.
Btw have this issue on 2 different configurations. One with Comodo firewall and with beta comodo cloud antivirus. I am on windows 10 so it might be that. Are you on another windows version if i may ask?

W8.1

@SHvFl I am not on MT often as of late so my responses are delayed.
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
No worries mate. I am on windows 10 so it might be that. I would create a bug report but crashing does the same for me i think. Kinda. Thanks for your answer.
 

Dan E

Level 1
Verified
Oct 7, 2015
24
is it better to use comodo in proactive or internet security mode in your opinion? I have noticed the hips on comodo less sensitive in the antivirus mode its seeming like.
 
  • Like
Reactions: Moose

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
is it better to use comodo in proactive or internet security mode in your opinion? I have noticed the hips on comodo less sensitive in the antivirus mode its seeming like.
Proactive gives the most protection.
 
  • Like
Reactions: Dan E and Moose

DracusNarcrym

Level 20
Verified
Top Poster
Well-known
Oct 16, 2015
970
is it better to use comodo in proactive or internet security mode in your opinion? I have noticed the hips on comodo less sensitive in the antivirus mode its seeming like.
Just like @SHvFl said above, the Proactive Security configuration is much more secure than the Internet Security configuration.
 
  • Like
Reactions: Dan E and Moose

pneuma1985

Level 4
Verified
Aug 30, 2015
189
I recently have been noticing an issue with the apr protocol within network intrusions. The source IP and destination IP are both my IP address but its being blocked or considered an intrusion? Why would that be? Have about 16 so far everytime I reboot the machine they tick away as intrusions...
 
  • Like
Reactions: DracusNarcrym

DracusNarcrym

Level 20
Verified
Top Poster
Well-known
Oct 16, 2015
970
I recently have been noticing an issue with the apr protocol within network intrusions. The source IP and destination IP are both my IP address but its being blocked or considered an intrusion? Why would that be? Have about 16 so far everytime I reboot the machine they tick away as intrusions...
If an application, which you have completely blocked from making any connections (by creating a block rule for it in the Firewall), attempts to connect to any destination IP, even the local one, then that attempt WILL be blocked too. (this is usually not a bad thing)
 
  • Like
Reactions: pneuma1985
H

hjlbx

Thread author
I recently have been noticing an issue with the apr protocol within network intrusions. The source IP and destination IP are both my IP address but its being blocked or considered an intrusion? Why would that be? Have about 16 so far everytime I reboot the machine they tick away as intrusions...

@pneuma1985

You have anti-ARP Spoofing enabled. That is why you are seeing log entries of firewall blocks of your IP address.

Unless you are using a local area network you have no need of this protection - and it is doing nothing for your system protection wise; if you are using a standard home cable network then anti-ARP Spoofing is not necessary.

To make those log entries disappear, disable anti-ARP Spoofing.
 

pneuma1985

Level 4
Verified
Aug 30, 2015
189
How do I get an installer to work if comodo doesn't recognize it and constantly sandboxes it? I've tried adding rules to HIPS and exclusions etc I don't get it It keeps opening the installer I want to open in a sandbox no matter what I do. I currently am trying to install my HTC Drivers on my host machine they install just fine on my VM I do dev work on... What gives I tried checking the differences in settings with my CIS and there is no difference I don't get it... I tried adding the rule for the .exe that my VM has doesnt work b/c it autolaunches the installer itself in a sandbox and then error's b/c it's sandboxed. Any help would be much appreciated. Can someone please explain the exact way I go about this adding an exclusion so it doesn't sandbox an installer it doesnt recognize?
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top