- Jan 28, 2013
- 319
As there have been a number of threads concerning the Pro's and Con's of Comodo products lately. just wanted to share my preferred setup in detail, and the reasons for it.
Comodo security products (for the Home) come in two flavors- Comodo Internet Security (CIS) and Comodo Firewall (CF). The difference is that CIS has a local antivirus module (note that they both have a Cloud scanner). As has been discussed elsewhere, the AV component of Comodo is at best middle of the pack (detractors would say that although the AV protection is unmatched by any it is bettered by all); this being said I do not see any need to either suggest installing or further discussing CIS.
So concentrating on Comodo Firewall it can be seen that CF has 3 basic components:
1). A Cloud Scanner- as noted above, it is of dubious value and can be shut off; but as it really doesn't interfere with anything, why bother?
2). A HIPS component- I suppose it is adequate, but unnecessary with a proper Sandbox setting.
3). The Auto-sandbox- Superb with settings of either Untrusted (which I don't care for) or Full V (which I covet).
Installation and setup- really easy. After install and reboot (good idea to click Custom install to avoid Dragon, PrivDog, etc):
1). Right Click the Comodo icon in the tray and select Advanced View.
2). Right Click the icon again and:
a). Uncheck the "Show Widget" (I hate widgets and so should you).
b). Make sure Firewall is in "Safe Mode"
c). Sets Hips to Disable
d). Set Auto-Sandbox to "Fully Virtualized".
3). Open up the main GUI, click Tasks, then click Sandbox Tasks. Right click on Reset Sandbox and select "Add to Taskbar". The reset function is now on the main GUI ribbon.
4). Open up the main GUI, Click Tasks, then click Advanced Tasks, then click Open Advanced settings:
a). Uncheck "Play Sound"
b). Uncheck "Show Notification messages" (this is optional- anything running in Full V will have a Green Border around it, so why bother getting a popup telling you this is done?).
That's pretty much all. CF should be silent from then on and will only alert when a non-whitelisted program tries to run and/or tries to connect to the net. If an application that you know is Safe gets sandboxed, just open up the main GUI, click on Sandboxed Apps, right click the program you know is safe and select Add to Trusted.
Now try to get infected.
I've been using the Free version of malware bytes , So it is only on-demand.Elemec- First off, what settings are you using for Comodo? As you have Qihoo TS installed (I hop at default), there would be absolutely no need for the Comodo HIPS module to be enabled (assuming that you have it active). As for Malwarebytes, you don't mention if you have it as Real-time or not. My STRONG suggestion is just keep MB as an on-demand app.
In short,
1), CF- HIPS off, Sandbox on. Change the Configuration setting to Proactive.
2). Qihoo TS 6- keep this at Default setting! There is no need to activate BD and (God forbid) Avira.
3). Disable Malwarebytes if you are using it as a real-time protector.
Please evaluate the above and inform us if any issues persist (also tell us the current settings that you are using so I can be mean to you).
Alright , Here the full info about it.
[EDIT] : For enable Full virtualized mode , Do i just change sandbox setting by unmarking " Dont virtualize specific programs " ?
If you do not set a restriction level, CIS will automatically apply a level of 'Fully Virtualized'.
- Fully Virtualized - The application will be run in a virtual environment completely isolated from your operating system and files on the rest of your computer.
The "proactive mode" already active the full sandbox automatically.Alright , Here the full info about it.
I'm using all the configurations/settings you said on your post , With exception of the " Full virtualized " One.
I'm using the proactive mode.
Default 360 total security.
Free-Malwarebytes Only On-Demand
[EDIT] : For enable Full virtualized mode , Do i just change sandbox setting by unmarking " Dont virtualize specific programs " ?
Sorry I wasn't clear regarding the sandbox. In past versions, there were different levels of protection afforded by the sandbox- Partially Limited, Limited, Restricted, Untrusted, Full V- with the default being Partially Limited. With version 8, the default is now Full Virtualization- so as long as you enable the sandbox you are set (nothing else is needed or should be done).
(Helpful Hint- Right click the Comodo icon in the tray and click on "Advanced View". It will close and when you Right click on it again you will not only see that you now have easy access to HIPS and Sandbox things. Also, the main GUI is a bit more informative)
Regarding the importance (and the reason) for changing the configuration from "Firewall Security" to "Proactive Security"- at default settings of the sandbox ONLY FILES RUN FROM THE DOWNLOAD DIRECTORY WILL BE SANDBOXED (forgive the caps, but this is of extreme importance). One can change the settings so that potentially troublesome files found anywhere on your system will be sandboxed in one of two ways:
1). In Sandbox settings, edit the Origin of the first "Run Virtually" listing from "Internet" to "Any", or
2). Just change the configuration from Firewall security to Proactive security. This has an added benefit as it
will protect all critical COM interfaces (ignore the "Internet Security" configuration as this really only pertains to CIS- with the local AV).
If I was in any way unclear (as I tend to be), please ask anything you may want to know (don't be shy).
M