RE: NCLR need recommendation on improvements.
Yeah, well it did actually! But there was a couple of things i´m unsecure about.
First FW alerted me of DTLite.exe (Daemontools) performing an SQL-injection and something about exceeding memory!? Seems a bit odd that a so widely spread application should perform a SQL-injection!?!? (DL from their HP btw)
That is a False Positive most likely. In Defense+ -> Defense+ Settings -> Execution Control Settings there is an Exclusions button. Click it. In the list that opens add (Add -> Browse) C:\Program Files\DAEMONTools Lite\DTLite.exe if it is not there already.
Second it warned me about nvvsvc trying to execute rundll32. Now thats my nvidia-driver. Also strange thats not in clouds whitelist??
Strange indeed since the real file (C:\Windows\System32\nvvsvc.exe) is digitally signed by nVidia. Check your CIS Logs (Events), find the file and do as others suggested. But make sure you upload the file that triggered the pop-up. If it is a file in another folder it might be malicious.
Third: I´ve been warned a couple of times about computers trying to connect from outside. So far i have denied, but how do i know what types of connections they are? Is it possible there are some updatefunction??
Windows has some services that scan computers on a network (to see if a new shared device is available, for example). So you'll see other computers connecting to you commonly on ports 138, 139, 445 (NetBIOS Name Service), 2869 (I think this is SSDP Discover Service). This means that Windows leaves those ports opened. Unfortunately worms exploit those open ports too.
It depends on how you connect to the internet. You have a router and all in-house computers are connected to it? Or all your computers use the same ISP.
Anyway you should know the IP-s of computers in your home and those IP-s need to be static to properly configure a firewall.
Sharing apps lice DC++ and uTorrent can cause firewall pop-ups when others are trying to connect to you and get the files you share/seed. You need to configure the sharing clients to use a specific port to properly configure a firewall.
Then a general question. At installation i was asked if i would use Comodo´s secure DNS.It sounds good but i´m using a VPN a great deal and don´t know the implications on connection to my VPN with this function activated. Suggestion??
This won't conflict with VPN but you might notice a slowdown depending on your location. IMO currently Comodo DNS doesn't add much to protection. I personally don't have it installed.
Important: The firewall might interfere with your VPN. You had Win7 firewall disabled to be able to use the VPN?
Sorry Laserwraith. I don´t have permission to access your image
Sorry. Changed your permissions so you can view attachments.