Author Topic: 5.8 too many Defense+ Alerts  (Read 5101 times)

Offline coyote2

  • Comodo Member
  • **
  • Posts: 33
5.8 too many Defense+ Alerts
« on: November 03, 2011, 12:25:16 PM »
Upon upgrading to 5.8 of the free firewall, I'm getting huge numbers of Defense+ alerts.  Even from components of the firewall itself!  (And when I try to change Windows settings in system components like "Scheduled Tasks".)

I have read the sticky on 5.8's changes at
http://forums.comodo.com/defense-sandbox-faq-cis/alert-reducing-settings-in-cis-why-how-when-to-use-draft-v58-onwards-t76410.0.html, but I'm still lost as to how to get back to the pre-5.8 situation.  (In part because, even as far as I understand that sticky, I can't find the settings alluded to.)

My Firewall and Defense+ Security levels = "Safe Mode".  I see the Sandbox got Disabled, so I just Enabled it (I don't imagine that will reduce the number of alerts I'm getting).

Windows XP Pro 32-bit sp3; also running Norton Antivirus 2012.
« Last Edit: November 03, 2011, 12:54:00 PM by coyote2 »

Offline Chiron

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 11566
Re: 5.8 too many Defense+ Alerts
« Reply #1 on: November 03, 2011, 01:28:40 PM »
It sounds to me like something could be wrong with your install. What happens when you run the diagnostics?

Offline coyote2

  • Comodo Member
  • **
  • Posts: 33
Re: 5.8 too many Defense+ Alerts
« Reply #2 on: November 03, 2011, 01:39:57 PM »
It sounds to me like something could be wrong with your install. What happens when you run the diagnostics?
I just tried it: "The diagnostics utility did not find any problems with your installation."

At least it does now finally seem to be (at least sometimes) learning; perhaps with time the alerts will wane, much as they did when I installed the product for the first time years ago.

Offline Chiron

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 11566
Re: 5.8 too many Defense+ Alerts
« Reply #3 on: November 03, 2011, 01:58:00 PM »
On my system I get very few alerts. Were you saying that your Comodo Firewall was giving you alerts for things that Comodo Firewall was doing? ???

What adjustments, if any, did you make to the default settings?

Offline coyote2

  • Comodo Member
  • **
  • Posts: 33
Re: 5.8 too many Defense+ Alerts
« Reply #4 on: November 03, 2011, 02:04:11 PM »
On my system I get very few alerts. Were you saying that your Comodo Firewall was giving you alerts for things that Comodo Firewall was doing? ???
Yes; for example, on system bootup, when Comodo checked for updates, I got a Defense+ alert.
Quote
What adjustments, if any, did you make to the default settings?
Other than the Security Levels I just mentioned, I don't think I have made any changes to the default settings.

Offline Chiron

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 11566
Re: 5.8 too many Defense+ Alerts
« Reply #5 on: November 03, 2011, 02:26:11 PM »
There may have been a problem with your installation. By that I mean that Comodo Firewall may not have installed properly.

Other than that it could be a problem with Norton Antivirus. I don't seem to remember Norton Antivirus playing well with other security programs, but this is just a guess.

Also, what version of Comodo Firewall did you have installed before 5.8?

If you do decide to reinstall Comodo Firewall then I would advise following the advice I give on this page and then configuring it as I describe in this article.

Thank you.

Offline captainsticks

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 9010
    • Comodo Help
Re: 5.8 too many Defense+ Alerts
« Reply #6 on: November 03, 2011, 03:11:06 PM »
A view of D+ event logs or alert logs could assist in finding a cause for the alerts.
A good read guaranteed.
Forum Policy - Updated on January 3, 2013
PrivDog: The Dog that not only barks at uninvited guests, but rather destroys the intruder.

Offline coyote2

  • Comodo Member
  • **
  • Posts: 33
Re: 5.8 too many Defense+ Alerts
« Reply #7 on: November 03, 2011, 07:35:09 PM »
A view of D+ event logs or alert logs could assist in finding a cause for the alerts.

Thank you very much for your reply, captainsticks!

I exported my D+ Events for today to .htm (the only format offered), but that can't be attached here.  Any suggestions, please?
« Last Edit: November 03, 2011, 07:39:12 PM by coyote2 »

Offline coyote2

  • Comodo Member
  • **
  • Posts: 33
Re: 5.8 too many Defense+ Alerts
« Reply #8 on: November 03, 2011, 07:37:10 PM »
Other than that it could be a problem with Norton Antivirus. I don't seem to remember Norton Antivirus playing well with other security programs, but this is just a guess.

Thank you very much for your reply, Chiron!

All was well until 5.8

Quote
Also, what version of Comodo Firewall did you have installed before 5.8?

It was 5.5...1383
« Last Edit: November 03, 2011, 07:42:46 PM by coyote2 »

Offline captainsticks

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 9010
    • Comodo Help
Re: 5.8 too many Defense+ Alerts
« Reply #9 on: November 03, 2011, 08:59:13 PM »
I exported my D+ Events for today to .htm (the only format offered), but that can't be attached here.  Any suggestions, please?
Hi Coyote2,
An attached screenshot of the logs would be another way.

A good read guaranteed.
Forum Policy - Updated on January 3, 2013
PrivDog: The Dog that not only barks at uninvited guests, but rather destroys the intruder.

Offline coyote2

  • Comodo Member
  • **
  • Posts: 33
Re: 5.8 too many Defense+ Alerts
« Reply #10 on: November 03, 2011, 09:12:26 PM »
Hi Coyote2,
An attached screenshot of the logs would be another way.
Screenshot of the bottom of today's Defense+ Event log attached.  I'll happily post any number of additional screens if that would be helpful.

Offline captainsticks

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 9010
    • Comodo Help
Re: 5.8 too many Defense+ Alerts
« Reply #11 on: November 04, 2011, 06:12:09 AM »
Hi Coyote2,
Thanks for the screenshot, you could also post/attach your Configuration Changes logs and Alerts Displayed logs for the Entire Period and this might show where it all started.
Please Zip the HTML files to attach to your post.

Also in case of a corrupt configuration you could choose an alternative configuration to see if that calms the monster.
Right click Comodo icon and choose between proactive/firewall configurations.
Thanks.
A good read guaranteed.
Forum Policy - Updated on January 3, 2013
PrivDog: The Dog that not only barks at uninvited guests, but rather destroys the intruder.

Offline coyote2

  • Comodo Member
  • **
  • Posts: 33
Re: 5.8 too many Defense+ Alerts
« Reply #12 on: November 04, 2011, 09:34:04 AM »
Hi Coyote2,
Thanks for the screenshot, you could also post/attach your Configuration Changes logs and Alerts Displayed logs for the Entire Period and this might show where it all started.
Please Zip the HTML files to attach to your post.

Also in case of a corrupt configuration you could choose an alternative configuration to see if that calms the monster.
Right click Comodo icon and choose between proactive/firewall configurations.
Thanks.
Thank you very much, captainsticks!  Zipped logs are attached.

Offline coyote2

  • Comodo Member
  • **
  • Posts: 33
Re: 5.8 too many Defense+ Alerts
« Reply #13 on: November 04, 2011, 11:14:46 AM »
Thank you very much, captainsticks!  Zipped logs are attached.
Never mind, sorry!!!

I just restored a backup image (of my system drive, taken just before I updated my video card drivers a couple days ago), which resolved the problem.  

Perhaps it was just that update attempt which went wrong; I'll try it once more and perhaps all will remain well.

Offline captainsticks

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 9010
    • Comodo Help
Re: 5.8 too many Defense+ Alerts
« Reply #14 on: November 04, 2011, 03:34:12 PM »
Hi Coyote2,
No sorry required, it doesn't matter who solves the problem it is nice to see it fixed :-TU.
Thanks for taking the time to produce the logs.
All the best for the future, thanks from Captainsticks.
A good read guaranteed.
Forum Policy - Updated on January 3, 2013
PrivDog: The Dog that not only barks at uninvited guests, but rather destroys the intruder.

 

Seo4Smf 2.0 © SmfMod.Com | Smf Destek