[merged topic]CIS feedback

There’s nothing wrong with that.

If you had said Windows task scheduler, that would have helped. I know how to manage that. It’s pretty easy . Just saying try task scheduler implies that CIS has one which it doesn’t.

The screenshot you have mentioned, I have just removed both the checks under Active & I haven’t seen any scheduled scan running yet. So I think just removing the checks under Active disables scheduled scan.

I didn’t change anything under windows task scheduler & no scheduled scan yet. Dont know if disabling in the GUI also disables in the task scheduler.

Does scheduled scan runs silently or scan window appears?

You do not have to untick them.

Just click edit and check schedule both mine are set not to run.

Edit All I have in task scheduler is Update (program) to run 10/02/13 every 7 days + Welcome disabled

OK.

What about task scheduler entry mentioned here?

Oh right! I guess lateral thinking is out of the question then 88)

If you are taking about the initial scan that is a registry entry runs every boot until it succeeds to finish.

All others can be set by clicking edit in CIS/Security Settings/Antivirus/scans then setting the schedule not to run.

Where did you see I said there is something wrong with flash player making a scheduled task or another program for that matter ??? It is up to the user to check or not to check if there are or are not scheduled tasks that he needs or does not need.

You see or you see not but some users try to know what’s going on on their rigs.

Now I want to suggest that the whole scheduled scan thing is too complicated in the current GUI. Most people wouldn’t even know that there were scheduled scans set up by default. It should be clearly delineated somewhere easily seen (without 4 or 5 mouse clicks to get to it) that Scheduled Scans exist and give the option there to enable or disable or edit them. It should be in the main Scan screen with Quick, Full, Rating, Custom, and then a separate entry of Scheduled. It should not be buried deep within the Advanced settings.

I was reading this help article, and find very interesting and amazing how CIS works for us and protect us under the hood from untrusted applications:

Firstly, the files undergo another antivirus scan on our servers.

If the scan discovers the file to be malicious (for example, heuristics discover it is a brand new variant) then it is designated as malware. This result is sent back to the local installation of CIS and the local and global black-list is updated.

If the scan does not detect that the file is malicious then it passes onto the the next stage of inspection - behavior monitoring.

The behavior analysis system is a cloud based service that is used to help determine whether a file exhibits malicious behavior. Once submitted to the system, the unknown executable will be automatically run in a virtual environment and all actions that it takes will be monitored. For example, processes spawned, files and registry key modifications, host state changes and network activity will be recorded.

If these behaviors are found to be malicious then the signature of the executable is automatically added to the antivirus black list.

If no malicious behavior is recorded then the file is placed into ‘Unrecognized Files’ and will be submitted to our technicians for further checks. Note: Behavior Analysis can identify malicious files and add to the global black list, but it cannot declare that a file is ‘safe’. The status of ‘safe’ can only be given to a file after more in-depth checks by our technicians.

In either case, the result is reported back to your CIS installation in approximately 15 minutes. If the executable was not found to be malicious then it will be run in the auto-sandbox. It will simultaneously be added to the ‘Unrecognized Files’ list and uploaded to our technicians for analysis. If is discovered to be a threat then CIS will show an AV alert to the user. From this alert the user can opt to quarantine, clean (delete) or disinfect the malicious file. This new threat will be automatically added to the global black list database and therefore benefit all CIS users.

Imagine when the power of Valkyrie is added in above’s process…
And perhaps with DACS (although apparently is not needed :azn:)…

Does anybody else know what additions are currently under development, project, analysis, etc?
Share it here, so we all can have an idea of future stronger CIS.

Firstly, the files undergo another antivirus scan on our servers.

Can someone please more explanation about it?

Cloud lookup (filerating) safe, malicious, unknown

The Advanced Heuristics detectors of Valkyrie are already used to generate signs, waiting for Static …
Asked Staff, they had some FPs from them so we’ll have to wait a little bit more …

In fact scan with another antivirus on Comodo servers, Is one of process files detection? Is it means that other antivirus software are installed on Comodo servers, similar VT&etc?

Hi all,

I am a user of “comodo firewall” since version 4. I put the version 6 a few days ago and I wanted to give my opinion.

A big thank you to the entire team of “Comodo”. I’m very happy with this version 6. Different than version 5, so you must have a new habit.

There is one point that I miss is the visualization of connections being directly on the “home page” Firewall (as in version 5).

I have not yet understood the operation of the “Kiosk” … but I will study this in detail.

Again thank you all and sorry for my bad english :slight_smile:

I have noticed a slight “blocking” (sometimes) 19.x Firefox … and sometimes a “freez” … I have to “killed” the application and start it again!?

I’ll look on the forum if I’m the only … and if not … if I find a solution :azn:

You can try https://forums.comodo.com/antivirus-help-cis/comodo-antivirus-and-firefox-problem-t84668.0.html;msg605096#msg605096

I agree CIS 6 is the best release yet. 1 Because I like the interface. 2 Because I think it’s more usable, and 3 Because It’s FREE!!!

Background: i used to use ESET smart security on my old windows xp 32bit and i loved it, was perfect… then i got a computer with windows 7 64bit and i read http://www.matousec.com and realised ESET 64bit wasnt doing so good compared to others so i gave comodo 5.10 a go and after a bit of a learning curve i really liiked it.

So earlier today i upgraded to version 6, my first thoughts:

i can tell the new design and default settings are meant to make it easier for stupid people to use your product, umm i mean ‘casuals’ this i understand as i see it right across the board regards other similar software and computers in general.

i can no longer submit a file to you guys for analysis unless it is already in quarantine? why is this?

where is the network traffic monitor? did you remove it? if so why?

Seems the sandbox features have been built on alot, this is something i never used as i have sandboxie installed and even it i dont use alot.

Documentation seems alot less unless you go online.

The basic settings seem very basic, you need to use the advanced settings to do pretty much anything.

what is “trustconnect” i cant see any documentation on this or alerts regarding it.

Under firewall settings: “set alert freq. level” i have the 5 settings and no documentation telling me what each one is, luckily from version 5.10 i kinda remember this is related to general rules such as ‘allow/block all outgoing’ ‘allow/block outgoing to this ip’ ‘allow/block outgoing to this ip and port’ where is the documentation telling me exactly what these 5 settings do? On a related note i always found the popup windows the weakest point of Comodo compared to ESET smart security… i should be able to decide if i want to allow/block all, specify a certain ip/port only etc from the popup like in ESET instead of having to go into the menu later.

Under the enable firewall setting, i understand training mode will allow all rules without user interaction but what is the difference between safe mode and custom ruleset? it should tell you this in the writing under the option when you change it.

In general you should be able to right click on each option and select a “what is this?” to find out more info… eg. in the antivirus setttings, what is “enable cache builder” and in the enable HIPS there is 4 different modes, it should detail to you what each mode is when you change it in the writing underneath but it does not…

Thats my thoughts for now, i will post more in a few days when im more used to this version but so far i think its a mixed bag compared to version 5.10

edit: one more thing, i decided to install comodo dragon with my upgrade to have a look at it and it didnt let me pick the directory that i wanted to install it to, instead it installed to a directory of its choice… i really hate this.

thanks for the feedback!

Sandbox is not about you using it manually or not…

its about catching any unknown file and automatically sandboxing it so that if that unknown file turns out to be malware then its running in the Sandbox…its a patented high level security technology.

It would be great if you could compile all your wishes into wishlists we have so that our devs can consider them please…
again, thank you for your feedback.

Melih

Hi,

I changed the settings and now it’s all ok ;D

[attachment deleted by admin]