any verification that those files are actually malicious?? any VT links??

I see the file has a valid Digital Signature. I haven’t used CIS for a long time, but from memory, it would allow any file with a valid Digital Signature to run by default?

I wonder if he would share the test file so that we can conform what exactly is the problem ?

No. It allows whitelisted unsigned applications and trusted vendors.
Having digitally signed application doesn’t mean it is automatically trusted.
Comodo team has to evaluate the vendor first.


Link not working

I think only the .dll is malicious, because of the dll load vulnerability it get’s executed during ‘install’ of the legal flashplayer and drive-by-infects the system.
Aigle is a credible reporter, he knows what he’s doing. He reported before that CIS doesn’t handle .dll load vulnerabilities at best.

Yes, that must be it. From memory, since version 5, CIS does not protect against (malicious) DLL loading. Faronics Anti-Executable version 3 also did not protect against this (a change from version 2), but I understand they have re-implemented it back in version 4.

The question is whether Comodo will do the same with a future version. In my opinion, not protecting against DLL loading leaves a huge hole in the protection CIS provides.

hopefully it will come back in v6

Software simple as ActivPort Scanner and Network portscan, CIS 5.8 in custom ports 135, 139, 445 remain open and without any warning of the firewall, another disadvantage observed in CIS 5.8 is that if I allow a stranger to D + ask DNS software, the PC is unprotected from attacks from the web, because it seems that the firewall does not monitor anything at all.

