Comodo doesn't remember settings for applications on encrypted volume?

I have Windows 7 x32 and on my E drive, which is encrypted with True Crypt, i have applications that i have set to start on Windows start up but Comodo doesn’t remember the settings for these applications and every time i start Windows it is displaying the same notifications.
Why Comodo is not remembering the settings? I think the problem is that the applications are on a encrypted volume but i don’t know why this should be a problem.

Any solution for this? I have lot of portable apps that starts on this encrypted drive on windows startup and it is pretty annoying to answer the same notifications every time.

And i even can’t set a delay for comodo on windows startup because if i delete the startup entry in the registry it has another startup entry in the scheduled tasks which is recreated every time, even if i delete it.

Settings not sticking can be a result of corrupted CIS files or config files, have you tried reinstalling CIS following Chiron’s guide?

I don’t think the problem is with corrupted files because before encrypting the drive i didn’t have this problem.

Are you saying that applications starting from the encrypted drive is not a problem and comodo should remember the settings? The difference now is that the drive is mounted every time on Windows logon by True Crypt, and dismounted on shutdown.

I’m actually not sure about that, first time I read I thought you had everything on the same drive and that was encrypted, I now see that is not the case.

Is the drive mounted with the same drive letter each time?

I encrypted my E drive and after that i removed the drive letter from it and on Windows logon i set True Crypt to assign the letter E when it mounts the drive. My portable apps were in E:\PortableApps so now the path stay the same when the drive is mounted.

What module of CIS is showing the alerts? (Firewall? HIPS?) Do you have specific application rules for them set up? When you answer the alerts, do you tick “Remember my answer”?

The alerts are mostly from HIPS and “Remember my answer” is ticked on alert window. Also, in HIPS Rules option window all of these applications are showing up as Allowed Application.

Can you take a screenshot of (or export) the Defense+ logs and upload it here?

I cleared the old logs and restarted the PC and this is the log after the restart:

[attachment deleted by admin]

Hmm, does the application rules say the file is located at E:\PortableApps\FirefoxPortable\FirefoxPortable.exe or \Device\TrueCryptVolumeE\PortableApps\FirefoxPortable\FirefoxPortable.exe? Because the latter is how CIS recognizes the path it seems like, you might have to create specific rules for each application in that fashion, although it’s weird if CIS doesn’t add that path automatically…

Edit: Is it only applications on the E drive that has this issue? No application on the C drive?

The application rule say that the file is located in E:\PortableApps\FirefoxPortable\FirefoxPortable.exe but if i try to change the path manually to \Device\TrueCryptVolumeE\PortableApps\FirefoxPortable\FirefoxPortable.exe it doesn’t want to save the change.

The problem is only with the applications on the encrypted E drive.

Weird, I get no issues when pasting “\Device\TrueCryptVolumeE\PortableApps\FirefoxPortable\FirefoxPortable.exe” into the application field…

Which version of CIS are you using?

Do you pasting the path with the quotes or without them? Because if i paste the path with quotes it saves it. It also save it if i use wild card sign in front *\Device\TrueCryptVolumeE\PortableApps\FirefoxPortable\FirefoxPortable.exe

I am using only Comodo Firewall. The version is 8.1.0.4426

Check screenshot, I don’t use either quotes or wildcard.

[attachment deleted by admin]

Well, for me it doesn’t work, it doesn’t want to save the path. Any idea why? I am using Windows 7 x32.

Honestly I don’t know why it won’t work, but it would explain why it keeps asking, because it’s trying to create an application rule for \Device\TrueCryptVolumeE\PortableApps\FirefoxPortable\FirefoxPortable.exe but not being able to… You can create a bug report for this here using this format

I will reinstall comodo first before filing bug report to see if this will help. But why Comodo recognizes the path for the mounted volume as \Device\TrueCryptVolumeE\PortableApps and not as E:\PortableApps? Is that a bug too?

Also, how can i set a startup delay for comodo on windows logon? Since it doesn’t have a integrated option for this i used Autoruns from sysinternal and disabled the registry entry for autostartup on logon, but it has also one option in the windows scheduled tasks for autostart that is recreated even if i delete it. How can i permanently disable this autorun scheduled task?

Actually that may in and of itself be a bug, but I don’t know, worth reporting either way.

I don’t know about delay auto-start.

Does Comodo even support encrypted drives? I would think the encryption software would make it difficult to mount the file system properly.

Also what part of CIS are you trying to auto delay? The idea of security software to make it load early in the boot process so viruses/rookits can’t sneak in early. If you prevent cmdagent from running you’d disable rule enforcement.