Use “Process Hacker” or SysInternals “Process Explorer” to find out which applications have active internet connections and which applications produce this heavy data traffic.
Only IP 199.66.201.17 relates directly to Comodo the other IP do not, maybe you have some other background applications running that consume so much traffic (torrent client perhaps?).
Decimal: 3343042833
Hostname: cima.security.comodo.com
ASN: 35838
ISP: Comodo Group Inc.
Services: Datacenter
Assignment: Likely Static IP
Country: United States
State/Region: New Jersey
City: Clifton
This is the case for the @ 199.66.201.16:
IP Details For: 199.66.201.16
Decimal: 3343042832
Hostname: no-dns-yet.ccanet.co.uk
ASN: 35838
ISP: Comodo Group Inc.
Services: Datacenter
Assignment: Likely Static IP
Country: United States
State/Region: New Jersey
City: Clifton
In the document referenced above only the @ 199.66.201.16 is mentioned.
This is definitely a Comodo thing - did some research of my own
With Telemetry and Cloud lookup disabled - why is there a need for Comodo telemetry in Scheduled tasks?
You can delete it - but it comes back on every boot.
Can anybody enlighten me on this?
This is not honest behaviour.
There are many threads across the web - even I’m getting doubts on Comodo now after more than a decade of use.
User Peerblock to check Comodo behaviour - its pinging 199.66.201.16 every few seconds?
Why the need to ping Comodo DataCenter even when Telemetry is disabled?
Why are there so many malware with Comodo certificates?
would like a comment from the CEO on this?
I appreciate your interest, which I feel is just hogwash - this issue has been posted by others too, even as far back as 2019.
Still no solution from your end.
Excluding 3rd party forums, even here there are similar threads older than mine - no one received a solution till date.
Which points to this being deliberate…!
I’m yet to receive any answers to my queries - this thing about OS version / CIS version is another hogwash.
Task scheduler is deliberate and has nothing to do with os /cis versions.
Thank you for reporting, kindly provide us exactly what you did and what heppened or provide us steps to reproduce so that we will check and report this to the team.
The post linked to explains that no data should be sent by the scheduled task if data collection is disabled in the settings. This doesn’t answer the OP’s question as to why CIS connects to several server IPs when telemetry is set to disabled.
On my laptop (see attachment) the 3 sites on which cmdagent.exe has connected since this morning.
The setting “Send anonymous program usage statistics to COMODO” is unchecked on my laptop.
One question: do you ask yourself the same type of questions about your AV?