Short question: I don't have “\Device\NamedPipe\atsvc” - when I purge, it's gone. Is this a temporary device, or can I live without protecting it?
As for me i have "all entries are valid" when trying to purge. What i did: created new group "Windows Management" under "my protected files" and added entry "\Device\NamedPipe\atsvc" (without quotes) to that group.
- new group under "my protected files": Windows Management, which contains entry \Device\NamedPipe\atsvc (to add it to your settings, simply copy-paste title)
- group Windows Management under "my protected com interfaces" contains new entry {5CE34C0D-0DC9-4C1F-897C-DAA1B78CEE7C}
- group important keys under "my protected registry keys" contains new entry *\SOFTWARE\Classes\CLSID*
- minor change: group "all applications" -> access rights -> interprocess memory accesses -> ask, allowed applications: %windir%\system32\ctfmon.exe
たとえばfirefoxを起動するとたまに explorer.exe has tried tu use C:/../firefox.exe through OLE Automation, which can be used to hijack other applications とでてきて再登録されます。 特に何もせず普通にショートカットから起動しているだけなのですが、 これが出るタイミングもよくわからないのですが これってどういうことなんですかね?
AMD 64x2 5000 (AM2) Windows XP Prof 64 bit edition, SP2 and latest updates AV: AVast 4.8, FW: CIS 3.5.54375.427 Administrator account
After letting COMODO Firewall Pro update, I noticed that there are 2 registry entries in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run : COMODO Firewall Pro and COMODO Internet Security. Both with the same value to run cfp.exe -h
Is the COMODO Firewall Pro keyname suppose to stay or did the updater miss it during "clean-up" (or un-install) ?
Comodo Family Member(回答)
Re: CIS Update dual registry entry
It definitely shouldn't be there. Apparently it's a bug. I always clean install for every update, so I only have:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "COMODO Internet Security"="\"C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe\" -h"
We have issued an update to upgrade CIS to 3.5.55810.432. The release notes will be refelected in the web site.
FIXED! AV updating does not use internet explorer proxy settings FIXED! Defense+ does not protect WOW3264 registry keys FIXED! Defense+ reports truncated function name for some hooks FIXED! Cmdagent.exe consumes 100% memory when firefox.exe is run FIXED! Windows gives unsigned driver alert while installing CIS firewall drivers IMRPOVED! AV scanning takes long time while scanning certain files
You should be getting the update notifications from your updaters shortly.
Training Mode: Defense+ will monitor and learn the activity of any and all executables and create automatic 'Allow' rules until the security level is adjusted. You will not receive any Defense+ alerts in 'Training Mode'. If you choose the 'Training Mode' setting, we advise that you are 100% sure that all applications and executables installed on your computer are safe to run.
Tip: This mode can be used as the “Gaming Mode”. It is handy to use this setting temporarily when you are running an (unknown but trusted) application or Games for the first time. This will suppress all Defense+ alerts while the firewall learns the components of the application that need to run on your machine and automatically create 'Allow' rules for them. Afterwards, you can switch back to 'Train with Safe Mode' mode).
初心者でも分かるFirewall編(改訂版) >>4 Stealth Ports WizardでNICを選択しGlobalRulesのルールを作る(これでステルスポート機能完全装備) 細かく許可ルール作る人はAlert me to incoming connections - stealth my ports on a per-case basis
Product Result Comodo Internet Security ---------------340/340 Kaspersky Internet Security -------------270/340 Agnitum Outpost Firewall Pro ------------250/340 Jetico Personal Firewall Sunbelt Personal Firewall ---------------50/340 Avira Premium Security Suite ------------90/340 Online Armor Personal Firewall -----------290-340/340 Online Armor Free ----------------------290-340/340 Norton Internet Security 2009 ----------50/340 BitDefender Internet Security -----------20/340 ZoneAlarm Pro Firewall ------------------220/340 ZoneAlarm Free Firewall -----------------40/340 Iolo Personal Firewall Panda AV Plus Firewall GoldTach Personal Firewall ---------------40/340 AVG AntiVirus Plus Firewall --------------20/340 Spyware Terminator 2.5 -----------------80/340 F-Secure Internet Security 2009 ---------20/340
COMODOのヘルプも古いんだろう Alert SettingsでもThis computer is an internet connection gateway (i.e. an ICS Server)と Enable Alerts for loopback requestsの2つも載ってないし これもいつ加わったんだか知らないけど
http://www.matousec.com/projects/firewall-challenge/ 2008-11-30: We have received a suggestion from Comodo Security Solutions, Inc., the vendor of Comodo InternetSecurity, on how to improve the configuration of their product in order to pass more tests. The suggested change included switching Comodo Internet Security configuration to "COMODO - Proactive Security",which can be done via the product's tray icon. Since our rules say thatthe tests are performed aginst the highest usable security configuration, we retested Comodo Internet Security3.5.55810.432 and corrected its results. Its new score is 90%, which is much better score than previouslypublished incorrect value of 84%. Weapologize to Comodo and all our visitors for this mistake.
Server Central Network SCN-4 (NET-205-234-128-0-1) 205.234.128.0 - 205.234.255.255 CacheNetworks, Inc. CACHENETWORKS-ANYCAST-2 (NET-205-234-175-0-1) 205.234.175.0 - 205.234.175.255
IMPROVED! Virus database updating FIXED! Defense+ does not prevent process access in memory FIXED! Defense+ does not properly protect some processes in Windows XP 64 FIXED! Signed executables could not be recognized in 64 bit operating systems FIXED! AV updates does not work in Windows Vista under certain circumstances FIXED! Windows security center still reports CIS after uninstallation FIXED! Cmdagent.exe crashes while being uninstalled in Windows Vista/XP 64