COMODO Internet Security 5.8.210479.2111 RC2 Bug Reports

But if they aren’t removed (the duplicates), I end up with 56 old files in my list after a couple of weeks (between Firefox and Thunderbird, since I’m beta testing). I know I can clear them manually, but it gets annoying to have to constantly clean up my list.

Sorry, L.A.R. I’d like to jump with my own question on this…

Egemen, what is the reason for having multiple entries for the same file?

Thanks, egemen!

Sure, I know this, sorry for not exact wording in report.

P.S. egemen, what you think about this? I’m not absolutely sure, that this may be considered as bug, in conjunction with the fact, that, if we turning this option on, we will be warned about possible problems, but leaving this checkbox unchecked put us all in very danger… :frowning: And… somewhat violates Comodo’s “default deny” concept…

Thanks a lot for the feedback and the improvements egemen keep the good work going guys

One suggestion Though To Make the Default settings as High as possible so there is no loss of security and keep in mind the usability so that there are less alerts so that most users who lack knowledge can install and forget

THanks

Rare Problem with beta Plz can anyone help ?

https://forums.comodo.com/beta-corner-cis/comodo-firewall-crash-t77078.0.html

  1. The full product and its version
    COMODO Internet Security 5.8.210479.2111 RC2

  2. Your Operating System (32 or 64 bit) and Service Pack revision
    XP SP3 32bit

  3. Other Security and Utility Software Installed
    none

  4. Step by step description to reproduce the issue

(1)
I double clicked on the document file that is in the USB flash drive.

It was sandboxed by CIS.

(2)
I viewed the active process list.

(3)
I checked the list of unrecognized files.

http://i.imgur.com/LDaLA.png

5.There might be a bug for the heuristic command line analysis.

This has been discussed a lot of times but still now CIS always sandboxies .pdf a lot +1 if they fix it

CIS sandboxed that file cause it is from untrusted source not because it is .pdf file.

  1. The full product and its version
    COMODO Internet Security 5.8.210479.2111 RC2

  2. Your Operating System (32 or 64 bit) and Service Pack revision
    Vista 32 bit up to date

  3. Other Security and Utility Software Installed
    None on my VMware;

  4. Step by step description to reproduce the issue
    After update to 5.8.210479.2111 (using CIS) Base Filtering Engine is crashing the i start Windows.
    From Event Viewer:EventData:
    svchost.exe_BFE
    6.0.6001.18000
    47918b89
    RPCRT4.dll
    6.0.6002.18024
    49f05bcc
    c0000005
    000b220c
    628
    01cc832114911424

Enhanced protection mode is enable.

Same issue here, but enhanced protection mode is disabled on my system, and I don’t use VMware but a real enviroment. No other security and utility software installed.

Dave

Yes guys. We are on it.,

Perfect. Thank you :-TU

Thanks there! Nice to know that it’s on the works. Thanks guys for the post about it. I thought i was only me. Just started to check out the beta version and was starting to get annoyed by this.

  1. The full product and its version 5.8.210479.2111 RC2

  2. Your Operating System (32 or 64 bit) and Service Pack revision: windows 7 sp1 32 bit

  3. Other Security and Utility Software Installed: none

  4. Step by step description to reproduce the issue: opened a folder with malware, it was removing the malware and cfp.exe crashed. dump attached

  5. How you tried to resolve the problem: none

  6. Upload Memory Dumps on crash if you encounter any: attached

  7. Attach screenshots to your posts to clarify the issue further: none

  8. Any other information you think that might be useful: none

  9. The CIS Security profile your using, and if you imported a previous version of the config: stock IS configuration

[attachment deleted by admin]

Split the discussion re duplicate files to here.

Hope that’s OK

Mouse

Problem: CFP crash with dump file

[ol]- Your Operating System (32 or 64 bit) and Service Pack revision: XP SP3 32 bit production machine.

  • Other Security and Utility Software Installed: Actual Window manager (not active for CIS), no others likely to be relevant
  • Step by step description to reproduce the issue: Left machine to run overnight. CFP crash dialog visible on waking.
  • How you tried to resolve the problem: Restarted cfp.
  • Upload Memory Dumps on crash if you encounter any: appended
  • Attach screenshots to your posts to clarify the issue further. N/A
  • Any other information you think that might be useful: Was making various changes to D+ setting previous night. But had reverted all to defaults I think before leaving machine overnight. Possibly the number of changes caused the crash.
  • The CIS Security profile you are using, and if you imported a previous version of the config: proactive, updated from default proactive config, with a few app rules, in build 2101[/ol]

[attachment deleted by admin]

There is the bug-report by PAnT0P in russian subforum about WMI hangup with famous “Event ID 10” when “enhanced protection mode” is enabled. Report is not properly formatted, so I’ll try to format it as required.

Original report (in russian)
Autotranslated report.

  1. The full product and its version: CIS v5.8.210479.2111
  2. Your Operating System (32 or 64 bit) and Service Pack revision: Windows 7 SP1 32bit
  3. Other Security and Utility Software Installed Probably none, report’s author mentioned clean windows install.
  4. Step by step description to reproduce the issue: None of special conditions mentioned. The system handgs “by itself” some time after bootup.
  5. How you tried to resolve the problem I advised the report’s author to try solutions from MS (Event ID 10 is logged - Windows Client | Microsoft Learn and Event ID 10 is logged in Application log - Windows Client | Microsoft Learn) and to delete all files from WBEM Repository (%windir%\System32\wbem\Repository) with no effect. There is error logged in system log, stating:
Event filter with query «SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA «Win32_Processor» AND TargetInstance.LoadPercentage > 99″ could not be reactivated in namespace «//./root/CIMV2″ because of error 0×80041003. Events cannot be delivered through this filter until the problem is corrected.
6. Upload Memory Dumps on crash if you encounter any N/A 7. Attach screenshots to your posts to clarify the issue further N/A 8. Any other information you think that might be useful Not reported. 9. The CIS Security profile your using, and if you imported a previous version of the config Not reported exactly, but "Enable enhanced protection mode" checkbox was definitely checked.