Why does CIS check internet each time I open a file?

I have CIS v12.2.2.8012.
I have everything disabled except Firewall.
Auto-containment - disabled.
HIPS - disabled.
File Ratings - disabled.
VirusScope - disabled.
Website filtering - disabled.

Every time I open a file, like just simple .pdf file, CIS tries to go to the internet (and blocked by my firewall rules) and because it is blocked my computer freeze for 5 seconds while CIS is trying to check something over the internet!!!
EACH TIME!

Why CIS needs to check something over the internet???
How can I disabled this BS??? I only need a firewall feature, I don’t need to check my files!!!

Here is a screenshot of the problem:

Thank you.

No one knows the answer.
CIS is basically spying on its users, and silence…

hi @gebef88966, one of the security layers of CIS is Trusted Vendor validation. It checks vendor’s CRL through OCSP.

If you check the destination IP, you can easily find that it belongs to digicert CRL and OCSP servers.

3 Likes

Great, now can you answer my questions?
Why does it happen when I try to open a file?
How can I disabled this?

UPDATE: It is also very cute, that I had zero replies in 2 days, but your 28 minutes old comment already has 2 likes.

It’s obviously checking the file certificate validity in the cloud. Not sure why it still happens with all those options disabled in the settings.

You can, however, always create a global block rule to that IP Address or a specific block rule for cmdagent.exe blocking outbound . to that IP address if it’s an issue though you are disabling a further security layer. You can always just check the certificates yourself online or submit with virustotal.com

Malware recently has been digitally certified and in a few cases recently only Comodo caught the malware while it remained undetected. For Example this Pikadot variation
VirusTotal Link which was only detected by a few initially. Human Analysist At Verdict.Valkyrie identified it as Malware a day later but thanks to Comodo not trusting the certificate, it was immediately flagged up as untrusted. Valkyrie Analysis

Anyway, create a block rule for any connections you don’t want to allow and consider running CF element in Custom Mode if your wanting more firewall control.3

CF Containment alert:

I can’t create global rule, it is not just one IP, CIS is trying to access many different IPs.
And blocking it actually cause the problem!
CIS freezes my file on opening (any file), for 5 seconds while trying to check something over the internet multiple times while being blocked!

Can you also confirm you have Automatic Updates disabled and your OS and CF version number?

I have CF.8012 running at my end on Win11 (23H2)haven’t noticed any lag with opening any files at my end but if you can provide more detailed information I can try and reproduce at my end.

Do you have any other security software running? The cmdagent lag may be because it’s not whitelisted by your AV or other security products.

Yes, updates are disabled, even check for updates is disabled.
OS Windows 11, CIS v12.2.2.8012.

No other security apps.
Block cmdagent.exe traffic and see, if you have any lags, trying to open different files or apps.
I didn’t have any lags, until I decided to remove all the default firewall rules and actually block CIS.

Thanks. I’ll have a look when I get time. I suspect you deleting the default rules might be part of the problem. Did you delete all of the global rules or all of the application rules or both?

I removed only default application rules.
It is not supposed to be a problem, as I said I have only firewall enabled, CIS shouldn’t try to access internet at all.

Okay. So presuming then that you made a new set of rules for Windows Applications and whatever metro apps you use.

I’ve got a lot on this evening but will try and see if I can replicate at my end tomorrow.

Tested at my end. Removed all Application rules with only cmdagent.exe block rule.

Disabled updates, containment, hips, file rating, website filtering and viruscope. No lag found at my end and cmdagent blocked see below screenshots.

Unable to replicate your lag issue with any application or file.

Honestly, if your not wanting to use CF’s security capabilities and just want a blocking firewall with nothing else, you might want to look at Windows Firewall Control which is a front end for the Built In Windows Firewall and is very effective at blocking outgoing and incoming for anything there isn’t a rule for and a product I use in between CF installs.

Sceenshots

cmdagent.exe Firewall Blocks:

Perhaps you can provide more technical information for @ilgaz so Comodo Staff can check at their end.

I don’t know what else to provide. Let’s assume that the freeze happens only for me.
The problem remains the same: why is CIS trying to access the internet when opening a file?

P.S. I had lots of Untrusted files in my File rating and lag wasn’t observed with opening an untrusted file either. Might be worth checking if you happen to have cmdagent.exe as Untrusted / Unrecognized in the File Rating list.

On to test some other products and the new Beta so will leave it with Devs to check at their end but the issue could not be reproduced at my end.

Ok, I’ve checked your screenshots and I found some difference with Containment Settings.
In my case “Detect programs which require elevated privileges” was checked, it shouldn’t influence anything, cause "Enable Auto-containment’ was still off.

But it looks like it helped with opening regular PDF/DOC files. I will check that more.

But if I open some installer application, CIS is still trying to access the internet and installer freezes.

Also in File Rating- > File List, there is a list of all the executable files I was opening with the date and rating.
Why?
My File Rating settings is off.

Okay.

I did run the Firewall in Safe Mode but that shouldn’t affect anything.

It may be if you are running CF in Safe Mode rather than custom but the file rating automatically adds files for trusted vendors on first installation. You can remove all of the the Trusted Vendors under that section and then remove all the files in the file list but you’ll get a lot of firewall popups even for every Windows system application connecting out.

When CF is configured using the CruelSister Configuration https://www.youtube.com/watch?v=psnLH–rvFQ, it’ll block and contain even the latest ransomeware and you don’t need an AV but the barebones firewall element is effective, I just don’t understand why you would only use that element of CF rather than it’s full capabilities.

I’m running firewall in Custom mode.

I don’t need anything except firewall, because antivirus and all the bells and whistles just slow down the computer and provide no benefits to me.

I cleaned Vendor List and File List and CIS started to fill these list back right away.

Anyway, CIS is still trying to access the internet, when I open a file and run a program.
Not all the time, but for time to time though.

Why is CIS trying to access the internet on file open???
This is like the main question.
I guess, you were able to replicate that.

UPDATE:
I guess, considering that File Rating → File List started to have files again and some of them have Unrecognized rating, that CIS is only trying to check these file over the internet, cause freezes for me.

For example, if I try to open a PDF file, my PDF reader is Unrecognized and CIS tries to check it and cause the freeze of the reader on launch.

Ah Okay.

It barely slows your system even with full CIS installed though some experienced increased disk usage for cmdagent and the cavwp (web filtering) processes

By comparison Malwarebytes Windows Firewall Control uses 63mb and that’s just a built in firewall UI / controller.

As to why it’s still connecting out is out of my scope of knowledge so perhaps the Devs can answer that.

Re: Update
Just change them all to Trusted if you trust all of those files and if you are vetting every file you download and run.

CF works best without too much tweaking but hopefully the Devs can provide further information or assistance.

Yeah, well, I’m not going to change every .exe file to Trusted manually.
CIS is not suppose to access the internet, if feature is disabled.
Period.

Thank you for your help Eric! :slight_smile:

1 Like

I only have a few applications as trusted and also cleared out all the trusted vendors / certificates (outside of a few Intel/Comodo/Microsoft ones). I do not see the behaviour you are experiencing on 8012.

Unrecognized files will fill up after a while with 100s of applications as ‘unknown’. But CIS does not connect to the internet to check these files (at least it doesn’t show up as doing anything) so I am curious as to what configuration option has done that.

I suppose what you could do is export your configuration setting and have someone at Comodo take a look at it, as I would assume it contains every Comodo setting+file rating. (Which of course you’d have to clean if there is something there you do not want to disclose.)

Perhaps try exporting your configuratin then re-importing it and check the settings to see if there might be a UI-bug where an option is shown as disabled when it is in fact enabled (probably under file rating / certificate list…).