Welcome, Guest. Please login or register.
Did you miss your activation email?
May 18, 2013, 06:50:42 AM

Login with username, password and session length

662843 Posts
70564 Topics
153233 Members

Latest Member: Madelaine

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Defense+ / Sandbox Help - CIS
| | | | |-+  (Confuision)The Defence + has blocked X suspicious attempt(s) so far [RESOLVED]
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: (Confuision)The Defence + has blocked X suspicious attempt(s) so far [RESOLVED]  (Read 6602 times)
Nosnibor
Comodo Loves me
****
Offline Offline

Posts: 173


Live Long And Prosper. God Bless The CPU.


« on: November 07, 2008, 10:17:39 PM »

(R) Hello everyone Wave I'm a little confused about some listings in the "Defence + Events" log Huh On the main screen of CF (Ver 3.5.54375.427) near the bottom left corner under the heading "Proactive Defence" it say "The Defence + has blocked X suspicious attempt(s) so far.) Shocked When i click on the blue link indicating how many items that have been blocked the "Defense + Events" log pops up and this is where the CONFUSION starts Embarrassed The help files on this log differes from the actual log Roll Eyes as in the log it shows under the heading "Action" different actions such as - "Changed Defense + Mode" - "Send Message" - "Access Memory" ect ect.  But it doesn't indicate weather or not the item  was "Alowed" or "Denied". How do i get the log to display if the action was allower or denied?
« Last Edit: November 09, 2008, 12:07:10 AM by 3xist » Logged

Model: Hewlett Packard COMPAQ Presario V5305WM Laptop
OS: Windows XP Professional Media Center Edition (SP3)
Processor: x86 Family 15 Model 44 Stepping 2 Authentic AMD Mobile Sempron 1994 MHz
Memory: 1536MB (1.5GB)
The BEST phone carrier hxxp://www.magicjack.com
Dennis2
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6582



« Reply #1 on: November 08, 2008, 07:45:46 AM »

(R) Hello everyone Wave I'm a little confused about some listings in the "Defence + Events" log Huh On the main screen of CF (Ver 3.5.54375.427) near the bottom left corner under the heading "Proactive Defence" it say "The Defence + has blocked X suspicious attempt(s) so far.) Shocked When i click on the blue link indicating how many items that have been blocked the "Defense + Events" log pops up and this is where the CONFUSION starts Embarrassed The help files on this log differes from the actual log Roll Eyes as in the log it shows under the heading "Action" different actions such as - "Changed Defense + Mode" - "Send Message" - "Access Memory" ect ect.  But it doesn't indicate weather or not the item  was "Alowed" or "Denied". How do i get the log to display if the action was allower or denied?
Unless you make a allow rule to log in the firewall all log entries are blocked actions.
Mode changes are there so it remind's you how you have change the settings for Firewall and Defence+
Dennis
« Last Edit: November 08, 2008, 07:48:13 AM by Dennis2 » Logged

Moderator: Aims Forum a friendly place. Any concerns? Please PM me and/or review the Forum Policy 2012Updated.
System:Windows 7 SP1(UAC)x32, LUA, CIS6.2813, Sandboxie 3.76
Vista Home P.(UAC)x32 SP2, LUA,C. 5.12.
Nosnibor
Comodo Loves me
****
Offline Offline

Posts: 173


Live Long And Prosper. God Bless The CPU.


« Reply #2 on: November 08, 2008, 06:29:58 PM »

(R) Sorry but I'm a little confused Embarrassed Under "Miscellaneous" - "Settings" - "Logging" the "Disable" box for "Firewall Logging" and "Defense + Logging" are NOT checked indicating that logging IS anabled. I've looked all through CF but I can't seem to find the setting I'm looking for. How do I configure the Defense + Log to indicate weather the event is allowed or blocked???
« Last Edit: November 08, 2008, 06:50:27 PM by 3xist » Logged

Model: Hewlett Packard COMPAQ Presario V5305WM Laptop
OS: Windows XP Professional Media Center Edition (SP3)
Processor: x86 Family 15 Model 44 Stepping 2 Authentic AMD Mobile Sempron 1994 MHz
Memory: 1536MB (1.5GB)
The BEST phone carrier hxxp://www.magicjack.com
3xist
Guest
« Reply #3 on: November 08, 2008, 06:54:16 PM »

Nosnibor.

You're D+ behavior is fine. Try running some leak tests, and block them. You will then see D+ Alerts.

Josh
Logged
Nosnibor
Comodo Loves me
****
Offline Offline

Posts: 173


Live Long And Prosper. God Bless The CPU.


« Reply #4 on: November 08, 2008, 07:07:19 PM »

(R) Leak test?Huh What are those and how do I find one?
Logged

Model: Hewlett Packard COMPAQ Presario V5305WM Laptop
OS: Windows XP Professional Media Center Edition (SP3)
Processor: x86 Family 15 Model 44 Stepping 2 Authentic AMD Mobile Sempron 1994 MHz
Memory: 1536MB (1.5GB)
The BEST phone carrier hxxp://www.magicjack.com
3xist
Guest
« Reply #5 on: November 08, 2008, 07:15:24 PM »

http://www.testmypcsecurity.com/securitytests/firewall_test_suite.html And Discussion thread is here: http://forums.comodo.com/feedbackcommentsannouncementsnews_cis/comodo_leak_test_suite_release_with_34_tests-t29688.0.html

Smiley

Josh
Logged
Nosnibor
Comodo Loves me
****
Offline Offline

Posts: 173


Live Long And Prosper. God Bless The CPU.


« Reply #6 on: November 08, 2008, 07:20:31 PM »

(R) Hey thanks I'll check it out. Cheers
Logged

Model: Hewlett Packard COMPAQ Presario V5305WM Laptop
OS: Windows XP Professional Media Center Edition (SP3)
Processor: x86 Family 15 Model 44 Stepping 2 Authentic AMD Mobile Sempron 1994 MHz
Memory: 1536MB (1.5GB)
The BEST phone carrier hxxp://www.magicjack.com
3xist
Guest
« Reply #7 on: November 08, 2008, 07:27:33 PM »

No worries.

Allow the program to open then just block every D+ Alert, And report back here if your D+ Logs are recorded. Smiley Here are my D+ Logs\Events for the leak tests. Smiley

Josh


* sshot-1.png (60.96 KB, 811x567 - viewed 8 times.)
Logged
Nosnibor
Comodo Loves me
****
Offline Offline

Posts: 173


Live Long And Prosper. God Bless The CPU.


« Reply #8 on: November 08, 2008, 09:00:40 PM »

(R) Ok I think I understand the logs now Thinking Please varify if the following statements are correct or not....(1) If it's listed in "Firewall Events" with Blocked  under "Action" it's a blocked item (the only thing listed in the "Firewall Events" are blocked items?)....(2) If it's listed in "Defense + Events" it's also a blocked item (the only thing listed in the "Defense + Events" are blocked items?)

Just a note to add....after doing the leak test i got a score of 320/340 with;
"Hijacking : ChangeDebuggerPath----Vulnerable"
"Hijacking : StartupPrograms----Vulnerable"

Logged

Model: Hewlett Packard COMPAQ Presario V5305WM Laptop
OS: Windows XP Professional Media Center Edition (SP3)
Processor: x86 Family 15 Model 44 Stepping 2 Authentic AMD Mobile Sempron 1994 MHz
Memory: 1536MB (1.5GB)
The BEST phone carrier hxxp://www.magicjack.com
3xist
Guest
« Reply #9 on: November 08, 2008, 09:03:08 PM »

(R) Ok I think I understand the logs now Thinking Please varify if the following statements are correct or not....(1) If it's listed in "Firewall Events" with Blocked  under "Action" it's a blocked item (the only thing listed in the "Firewall Events" are blocked items?)....(2) If it's listed in "Defense + Events" it's also a blocked item (the only thing listed in the "Defense + Events" are blocked items?)

Just a note to add....after doing the leak test i got a score of 320/340 with;
"Hijacking : ChangeDebuggerPath----Vulnerable"
"Hijacking : StartupPrograms----Vulnerable"



Okay.

In CIS, Make sure you have Defense+ & Firewall in Safe Mode. Also be sure your Configuration is "COMODO - Proactive Security" Configuration by right clicking the tray icon and choosing Configuration.

Also Block All D+ Alerts, with "Remember my Answer" ticked - You will then get 340/340. Smiley

Josh
Logged
Nosnibor
Comodo Loves me
****
Offline Offline

Posts: 173


Live Long And Prosper. God Bless The CPU.


« Reply #10 on: November 08, 2008, 09:32:19 PM »

(R) Yes both are set to "Safe Mode" Smiler Also I just read in the help file on "Configuration" but doesn't explain the difference between "Optimum Security"(the setting it's on now) and "Proactive Security Thinking Could you explain the differance please Embarrassed
Logged

Model: Hewlett Packard COMPAQ Presario V5305WM Laptop
OS: Windows XP Professional Media Center Edition (SP3)
Processor: x86 Family 15 Model 44 Stepping 2 Authentic AMD Mobile Sempron 1994 MHz
Memory: 1536MB (1.5GB)
The BEST phone carrier hxxp://www.magicjack.com
3xist
Guest
« Reply #11 on: November 08, 2008, 09:42:44 PM »

(R) Yes both are set to "Safe Mode" Smiler Also I just read in the help file on "Configuration" but doesn't explain the difference between "Optimum Security"(the setting it's on now) and "Proactive Security Thinking Could you explain the differance please Embarrassed

Optimum Security - Is a Configuration you either imported from CFP 3.0x to CIS 3.5x, Or you made your own configuration, etc.

Proactive Security - In CIS, This Activates the full power of Defense+. Image Execution is Normal & All Settings in Defense+>Advanced>Defense+ Settings>Monitor Settings are ticked. In "Internet Security" Configuration, Image Execution is disabled & Only some Monitor Settings are ticked, Which is why most people only get a 80% success rate.

However, It's not vulnerable - Internet Security Configuration is there for those with a good AV, And only want some power of D+. Proactive is like CFP 3.0 Default. 

Josh
Logged
Nosnibor
Comodo Loves me
****
Offline Offline

Posts: 173


Live Long And Prosper. God Bless The CPU.


« Reply #12 on: November 08, 2008, 11:32:19 PM »

(R) Ok I changed settings to what you recomended and now I get a score of 340/340 Bounce ....but....a new problem has started since changing settings Sad I have a touch pad mouse on my LapTop and whenever I use the scroll function of my touchpad(sliding my finger up and/or down on the side of the touch pad) I get a "Defence +" allert" that say...."SynTPEnh.exe is trying to modify the user interface of IEXPLORE.EXE"....or the IEXPLORE.EXE is changed to match whatever program screen I'm on. The alert isn't realy the problem at hand but what is....is the fact that when this alert pops up my touchpad(mouse) is COMPLEATLY FROZEN untill the alert goes away which is 120sec.  What did I do wrong now lol.
Logged

Model: Hewlett Packard COMPAQ Presario V5305WM Laptop
OS: Windows XP Professional Media Center Edition (SP3)
Processor: x86 Family 15 Model 44 Stepping 2 Authentic AMD Mobile Sempron 1994 MHz
Memory: 1536MB (1.5GB)
The BEST phone carrier hxxp://www.magicjack.com
3xist
Guest
« Reply #13 on: November 08, 2008, 11:43:09 PM »

(R) Ok I changed settings to what you recomended and now I get a score of 340/340 Bounce ....but....a new problem has started since changing settings Sad I have a touch pad mouse on my LapTop and whenever I use the scroll function of my touchpad(sliding my finger up and/or down on the side of the touch pad) I get a "Defence +" allert" that say...."SynTPEnh.exe is trying to modify the user interface of IEXPLORE.EXE"....or the IEXPLORE.EXE is changed to match whatever program screen I'm on. The alert isn't realy the problem at hand but what is....is the fact that when this alert pops up my touchpad(mouse) is COMPLEATLY FROZEN untill the alert goes away which is 120sec.  What did I do wrong now lol.

Just add it as a Trusted Application to the Computer Security Policy.

Josh
Logged
Nosnibor
Comodo Loves me
****
Offline Offline

Posts: 173


Live Long And Prosper. God Bless The CPU.


« Reply #14 on: November 09, 2008, 12:03:51 AM »

(R) Done and all is well Bounce from the bottom of my heart Hug I thank you for all your help Cheers
Logged

Model: Hewlett Packard COMPAQ Presario V5305WM Laptop
OS: Windows XP Professional Media Center Edition (SP3)
Processor: x86 Family 15 Model 44 Stepping 2 Authentic AMD Mobile Sempron 1994 MHz
Memory: 1536MB (1.5GB)
The BEST phone carrier hxxp://www.magicjack.com
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.052 seconds with 23 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com