Comodo Leak Test with result 170/340

I did Comodo Leak Test and my result was 170/340. Here are the ones were I got vulnerable:

  1. RootkitInstallation: ChangeDrvPath
  2. Invasion: Runner
  3. Invasion: RawDisk
  4. Invasion: FileDrop
  5. Injection: SetWinEventHook
  6. Injection: SetWindowsHookEx
  7. Injection: Services
  8. Injection: KnownDlls
  9. InfoSend: DNS Test
  10. Impersonation: Coat
  11. Hijacking: Userinit
  12. Hijacking: SupersedeServiceDll
  13. Hijacking: StartupPrograms
  14. Hijacking: AppinitDlls

How do I protect these?

:-[

What alert did you get when you started the program and what did you answer?

http://img198.imageshack.us/img198/2268/56560596.png

I answered “allow” (permitir)

You need to answer “sandbox” to get the leak tests.

Ok; now I did it with Sandbox and the result was 190/340. Still far from 100%…

Put Defense+ at Paranoid Mode and answer “No” to questions.

At Paranoid Mode I get 210.

Strange… I’ve got 340/340 with CIS 5 beta…

With CIS 5 Beta, Comodo leak test (CLT) is giving strange results in some situations (even with maximum security settings). For example, see this post. I do not know the cause, and as far as I know, the developers have not provided an explanation yet. However, some people are not able to achieve a perfect score with CLT (examples here). We will have to wait for a response from the developers as to why this is happening.

So, is there anything I can do to get 340? My Comodo is Internt Security Premium v4.1.

When testing make sure there are no rules for CLT in Security Policy and My Pending Files. It can influence the results.

How do I see it, Eric?

Removing CLT rules that may have been creating from previously running CLT:

Defense + Security policy

[ol]- Click the “defense+” tab at the top of the CIS window

  • Click the “Advanced” tab on the left of the CIS window
  • Click on “Computer Security Policy”
  • Scroll down the list of files. Select any entry that has “clt.exe” in the application name and click the remove button.
  • click “apply”.[/ol]

Firewall Security policy

[ol]- Click the “firewall” tab at the top of the CIS window

  • Click the “Advanced” tab on the left of the CIS window
  • Click on “Network Security Policy”
  • Scroll down the list of files. Select any entry that has “clt.exe” in the application name and click the remove button.
  • click “apply”.[/ol]

My pending files

[ol]- Click the “defense+” tab at the top of the CIS window

  • Click the “Common Tasks” tab on the left of the CIS window
  • Click on “My Pending files”
  • Scroll down the list of files. Select any entry that has “clt.exe” in the application name and click the remove button.
  • click “close”.[/ol]

My own safe files list

[ol]- Click the “defense+” tab at the top of the CIS window

  • Click the “Common Tasks” tab on the left of the CIS window
  • Click on “My Own Safe files”
  • Scroll down the list of files. Select any entry that has “clt.exe” in the application name and click the remove button.
  • click “close”.[/ol]

Removing the CLT rules as described above will help ensure that your CLT results are accurate.

Next time you run Comodo leak test and an alert appears, make sure that “remember my answer” is unchecked when you answer the alert. This will prevent CIS from creating rules that will affect CLT results the next time you run it.

whoop

Whoop-dee-doo, I did what you said and I’m back to 190. The vulnarable ones are:

  1. RootkitInstallation: ChangeDrvPath
  2. Invasion: Runner
  3. Invasion: RawDisk
  4. Invasion: FileDrop
  5. Injection: SetWinEventHook
  6. Injection: SetWindowsHookEx
  7. Injection: Services
  8. Injection: KnownDlls
  9. InfoSend: DNS Test
  10. Impersonation: DDE
  11. Impersonation: Coat
  12. Hijacking: Userinit
  13. Hijacking: SupersedeServiceDll
  14. Hijacking: StartupPrograms
  15. Hijacking: AppinitDlls

:cry:

Please post the following formation

  1. the version of CIS you are using (go to “more” tab and click “about”)
  2. Your configuration setting (More > configurations)
  3. Your CIS settings: including defense+ mode, image execution setting, firewall mode, antivirus mode, sandbox level.
  4. Are all of your defense + monitoring options selected? (select defense+ > advanced > defense+ settings > monitoring settings tab [all of the boxes should be checked].
  5. Are you running any other security software?
    6)Run diagnostics and see if you find any problems with CIS (More tab > diagnostics). Any problems reported by diagnostics?
  1. 4.1.150349.920

  2. Proactive Security

  3. Antivirus » Just alterations (second option); Firewall » Secure Mode; Defense+ » Paranoic; Sand Box » Active; Image execution settings » Normal (with a check in the option “Detect shellcodes injections”).

  4. Yes, all of them are checked.

  5. Not that I know. I have Advanced System Care, Glary Utilities and CCleaner, but they just work when I want it. Does it count?

  6. It says that it didn’t find any problem with my instalttion.

Do you mean the antivirus is in stateful mode?

Firewall does not have a “secure mode”. Is your firewall set to disabled, training mode, safe mode, custom policy mode, or block all mode?.

As far as I know, the cleaning programs you have installed (Advanced System Care, Glary Utilities and CCleaner) should not affect the function of CIS or CLT.

Try this:

  1. Make sure CLT is not listed in these parts of CIS (see this post again).
  2. Disable the sandbox. Make sure your other settings are as follows: configuration = proactive, defense+ =safe mode, firewall = safe mode, image execution = normal and enable “Detect shellcodes injections”, antivirus = stateful.
  3. Run CLT. The first alert that appears should be a defense+ alert that says “explorer.exe is a safe application. However, the executable clt.exe could not be recognized…” For this alert, make sure “remember my answer” is unchecked, and then click allow.
    4)The CLT program window should appear. from this point onward, if any CIS alert appears, click “block”.
  4. Click the “Test” Button, and remember, click block when a CIS alert appears.
  5. Now check your score. How did you do?

My Comodo is in portuguese, so I don’t know how the Antivirus » Just alterations option look in english. This one:

http://img201.imageshack.us/img201/5792/66958196.png

Is the second option the Stateful one?

Firewall is in Safe mode.

Sorry, I assumed you had the English translation.

Yes, “So Alteracoes” is stateful in the English translation.

Did you try what I suggested in my last post?

Yes:

200/340 now.