Alerts delay for minutes before popping up, then sometimes close instntly [M960]

A. THE BUG/ISSUE (Varies from issue to issue)

  • Summary - Give a clear summary in the topic subject, NOT here.
  • Can U reproduce the problem & if so how reliably?:
    Yes, it happens every time.
  • If U can, exact steps to reproduce. If not, exactly what U did & what happened:
    1:Open a new program that requests internet access.
    2:Expect a popup from Comodo that asks me to give the app permission to connect to the internet.
    3:Maybe 1-4 minutes later, the popup finally appears. Sometimes, multiple popups appear all at once, as if they were stuck in a queue that suddenly released everything at once.
  • If not obvious, what U expected to happen:
    The alert popup should happen immediately when an app tries to connect.
  • If a software compatibility problem have U tried the conflict FAQ?:
    This is a fresh install of the latest version.
  • Any software except CIS/OS involved? If so - name, & exact version:
  • Any other information, eg your guess at the cause, how U tried to fix it etc:
    I think the problem started after I configured some advanced settings to make Private Internet Access VPN work without an annoying popup every time it starts:
  1. Protected Objects: I created an object with 5 paths, 2 of which have asterisk wildcards.
  2. Defense+ Ruleset: I created a ruleset for the Protected Object.
  3. HIPS Rule: I made a rule for the Protected Object.
  4. Firewall Ruleset: I made a ruleset that blocks based on MAC address.
  5. Firewall Application Rule: I made a rule for the Defense+ Protected Object using the custom Firewall Ruleset.

Useful screenshots are also attached to this post.


  • Exact CIS version & configuration:
  • Modules enabled & level. D+/HIPS, Autosandbox/BBlocker, Firewall, & AV:
    Firewall enabled
    HIPS disabled
  • Have U made any other changes to the default config? (egs here.):
    Yes, I have attached my config file to this post so you can see everything.
  • Have U updated (without uninstall) from CIS 5 or CIS6?:
    [list type=lower-alpha][li]if so, have U tried a a clean reinstall - if not please do?:
    [/li]- Have U imported a config from a previous version of CIS:
    [li]if so, have U tried a standard config - if not please do:
    I don’t know what that means. I need my current config/rules to work as they are.
    [/li]- OS version, SP, 32/64 bit, UAC setting, account type, V.Machine used:
    Win 8 64, UAC disabled, Admin account
  • Other security/s’box software a) currently installed b) installed since OS, including initial trial security software included with system:
    a=none b=none

[attachment deleted by admin]

Thank you for submitting this. However, please fill out section B of the format. This contains important information.

If you have any questions about how to do this please feel free to ask.

Thank you.

updated first post

Okay, thank you for updating the format in the first post. It looks great. :smiley:

Let me clarify a few things. First, are you sure that this behavior does not occur if you use the default settings?

Second, does this behavior have anything to do with temporarily disabling any modules of CIS? I’m asking this only because there is a similar bug report which showed similar behavior when the Behavior Blocker was temporarily disabled. As soon as the timer ran out all of the alerts would show up, regardless of whether it was re-enabled in-between or not.


I am having similar problems, alters do not show up when the program requests to connect to the internet, only much later. As such, this renders my computer useless as I cannot use the internet. Please fix it without delay.

Does this happen on your computer if you do a clean reinstall, and do not change any settings?

i have the same alert delay problem, and sometimes the alert hangs for minutes and i’m unable to click anything until it disappears, before using 7.0.315459.4132 i uninstalled an old version of comodo, i also uninstalled privdog and comodo dragon that got installed with comodo 7, auto sandbox and hips are disabled, i’m using windows 7 sp 1 32 bit
below is a screenshot of my firewall settings

If anyone is using paranoid mode please let me know. The reason I ask is that there is already a related bug, but it only affects those using paranoid mode. I would like to rule that out.


if I remember right, the problem did not happen with default settings. I was able to add several application rules through alerts without problems. Then I added the rules I mentioned in my report, and the problem started. I attached my config to the first post.

I don’t think I have anything “temporarily disabled.” Some things are permanently disabled though. Firewall is Custom Ruleset, Auto Sandbox is Disabled, HIPS is disabled. I tried setting HIPS to Training Mode and then try to cause an alert, but that did not help.

I experience the bug without using paranoid mode. I am still having the problem btw. I’ll see if I can undo my settings one by one to see if that fixes anything.

Thank you very much for your report in standard format, with all information supplied. The care you have taken is much appreciated by Comodo, and will increase the likelihood that this bug can be fixed.

Developers may or may not communicate with you in the forum or by PM/IM, depending on time availability and need. Because you have supplied complete information they may be able to replicate and fix the bug without doing so.

Many thanks again.

I have HIPS and Auto-Sandbox disabled, using Custom Ruleset for firewall.

Additional behavior details:

I changed the firewall from Custom Ruleset to Safe Mode, and it worked correctly twice. I changed it back to Custom Ruleset and the problem was back. I changed it back to Safe Mode expecting it to work correctly, and it still failed. I Exited Comodo Firewall and reopened it, and it worked every time in either Firewall mode for a few minutes. Then, I left it in Custom Ruleset mode while I started to write this reply. While writing this reply, I tested it again and the problem was back.

It seems that restarting Comodo fixes the issue for a few minutes and then somehow Comodo Firewall broke by itself and this bug started happening again without me changing any settings.

Now, I told CF to Exit and it didn’t do anything. It’s like it wasn’t able to exit yet. After about 30 seconds, it asked me if I wanted to exit and finally exited properly. I think all the alerts that were queued up popped up all at once and then closed themselves immediately. MAYBE when Comodo is Exiting, one of the functions it runs kills some frozen process, which suddenly fixes the problem and lets the alerts come up.

I opened CF again, and it is behaving properly again. Probably in a couple of minutes, the problem will come back.

Any questions?

I’m not entirely sure what is causing this. It’s possible it’s a change which is unrelated to changing it from Safe Mode to Custom Ruleset. I’m really not sure.

However, if the devs are unable to replicate it with the config you attached to the first post, I will respond back and ask you to try a few things. For now, I think it’s best to wait for the devs, unless you were willing to do a clean install and slowly make changes until you narrow down which one causes this. Would you be willing to try that?


I’d rather give the devs a chance to figure it out first because my config is kind of advanced and difficult to set up.

I attached lots of useful screenshots to this post. Can you include it with the bug report?

[attachment deleted by admin]

Sure. I’ve now added it to the first post.

I’m copying and pasting here what I wrote on the other thread:

Several others are reporting the alert notification problem on the bug forum, so it is not something specific to me; what none is realizing thus far is that the firewall in effect is not blocking all internet traffic as expected. You should immediately address this as it represents a colossal security hole.

I have Utorrrent not defined on the Custom Ruleset so that every time I launch it I am asked to grant it permission. It has been like this for years without issue. However now, before the alert shows up so that I can authorize it, a big torrent with normally many sources will start uploading and downloading from a small number of peers, when all activity should be blocked!!! After the alert finally shows up (if it does) and I authorize the program to access to the internet, the torrent will connect to the many other sources and resume downloading at full speed.

Thanks for letting me know about this. However, this sounds like a different issue. Thus, if you would like to report this please create a new bug reporting topic. We can discuss it there.

Thank you.

A quick note, even after blocking the Utorren when the alter shows up, the downloading and uploading continue!! The firewall is indeed broken and leaves users completely exposed.

Please create a new topic for this. This bug report is not the correct place to discuss this.