COMODO Vulnerability Analyzer Version 1.0.0.9 (BETA) Released [Closed]

They seem to be slow at java.com, you can find it here: Download Java Runtime Environment 32-bit 8 update 341 for Windows - Filehippo.com

LA

1.6.0.6 is there, I have installed it since. As usual I had to uninstall 1.6.0.5 which is a nuisance and waste of time.

I do not use internet explorer usually, but I too have 7 rather than 6, I guess 6 left traces behind when I upgraded to 7. :frowning:

Thank you very much for testing the product.

We will try to take care of all FPs mentioned here. This is our first priority.

In response to coltrane’s following remarks:

BTW, when I click Java vulnerability it shows 14 different warnings, first 03 october 2007 . Is that history information of the Java runtime? Because I think 1.6.0.5 is newer than that.
Seems we got it wrong in vulnerability description, it seems to be related to older JRE version. Would be fixed in next update.
And what about the updates? Will the database of the vulnerabilities be updated automatically or only the CVA updates when updates option is selected in Settings tab?

Let me give an insight into functioning of it. We have a thin DB on client and before scanning starts we make sure it matches with DB on the server. So anytime you scan you have the latest from comodo.
Whenever you click on ‘Start’ button you would have seen an update dialog spalshing up, this makes sure that CVA is using latest database. This is diferent than one availale under ‘Miscellaneous → Update’, which is solely for program updates not for database updates.

In response to Soyabeaner’s following remark:

I wonder why there are 2 instances of my Windows Media Player 10 (one in C:\Program Files\Windows Media Player and the other in C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}).

This will be taken care in next version.

There's no close button for the info screen, just the X at the top-right corner.

This too will be taken care in next version.

In response to panic’s following remark:

I'd like to see the vulnerability rating shown on the main screen.

Yes, do agree with you here, that details are hidden as of now and they should be as visible as possible. We do have plans to make it more visible, when you click the application, it should be right there. So we have it in our task list.

I will update here when i get FPs fixed. So you can re-run scanner and see the results.

Thanks
-umesh

Sounds great Umesh!

LA

Hi Everyone,
We plan to have an updated CVA version on 6th May, 2008.
It will have FPs fixed as i mentioned in previous post.

Thanks
-umesh

It’s an annoyance with the Java runtime that the earlier versions have to be removed manually when updating. Many people don’t realise this and they take up a fair chunk of disk space. (:AGY)

Back to the product though it’s another nice addition to the Comodo set,well done! :■■■■

Pretty nice, it told me i had an outdated ProcMon and Divx Player. I didn’t know that!

Very good tool thank you very much.
Work fine for me

Great tool so far… it warned me about updates to thunderbird, pidgin, adobe flash, and probably one other that I had no idea about. It also warned me about ■■■■ for MS products like Excel, Word, Office as a whole which probably needed updating so I ran auto updates. Will see if that takes care of the warnings. I didn’t have the IE6/IE7 problem but I am suffering from the two instances of Java as well. Also told me about .net framework 1 vulnerability when the service pack was already installed like others.

Edit Rescanned, now I have two versions of I.E.7, Adobe Flash is still there even though I can confirm it was updated, Powerpoint is new to the list even though I just ran Auto Update so I’ll have to check on that, and .net is still plaguing me.

One thing I’d like to see added are updates for GTK+ runtime which is required to run Pidgin. Pidgin warned me about it during install so I could update but this might be handy in the future if it could be worked out.

Also wondering if Skype could be added/updated to the list you have. Sorry, I don’t quite know how these things work yet. I know Skype did just get updated (as in today) so I wouldn’t expect you to have it now, but in case its not on the list.

Overall I love it!

Dave

Completely off topic, but there is an alternative to manual removal:
http://prm753.bchea.org/software.html

I think I found another false positive: XNView 1.93.4.
That is installed and it is the latest version.

Hey all,

If you install CVA and then copy the folder C:\PROGRAM FILES\COMODO[b]VULNERABILITY ANALYZER [/b] to a USB drive, it can then be run from the USB drive on any other PC without installing.

Neat tool if you go onsite to fix a PC and/or troubleshoot software issues.

Great work guys!

Ewen :slight_smile:

Too many false positives.

I seriously think Comodo should try to focus on a few core products rather than trying to be everything. It’s better to be a master in a few areas than being a jack in all trades…

Oh come on now. Too many false positives?

I hardly think so. This is a beta and shows a lot of promise. You cannot seriously object to Comodo putting resources into many different areas. I am sure that different people are working on different programs, there is no need at all for them to all fall over each other on the same project.

Comodo has over 250 programmers. All products have their own team. Including this one, This is the first BETA Release off a new comodo product, please give it time to grow.

Josh

Compared to a rival product that i shall not name that is also in beta (and yes, i’m talking about the first beta), yes, there is too many FPs.

A number, if not all FPs reported so far will be fixed upon next release on the 6th!

Eric

Found several of the same False Positives as others. Only one was correct, java
Tried to search for IE6 both by file and by registry keys and could not, been using IE7 since it was a RC

Have a hunch files are being found that are old and not being used. As I mentioned Secunia at the beginning found IE7 in 3 locations C:\ with alpha numeric, the current updated version, and another older version in Windows SDold.

After several months of use the old files should be able to be deleted. Wonder if the complete location and a warning if the file can or cannot be deleted. Checking the last time it was accessed might be one of the ways.

The files that have alpha numeric names or no names is why I just asked for a File Identifier. The other security programs should detect malware but this also could be another tool.

Oh I just uninstalled and reinstalled IE7 (MS quitely updates the versions with out a major release) both versions were identical ! Post both the current version and location and the latest version. In this instance it MUST be the IE8 beta ?

Because of resouce usage, I would prefer to manually run the Vulnerability Analyzer or have it run at startup print a file to screen and then drop out. Again current and new version numbers and full file location with the ability to know if a file could be deleted safely!

Here is a comparison from last night between Comodo Vulnerability Analyzer and Secunia online scan
Oh in Secunia downloaded PSI scan it showed RegScrubXP and RegCleaner at End of Life. Which only means there will no longer be support (these programs run only when I access them)

UncleDoug

[attachment deleted by admin]

Yet another great program from Comodo. Comodo really are doing more to protect our computers than any other company - amazing. (L)

My only feedback is that the updater always crashes (see attached screenshot).

I’m using XP SP2, fully patched, with CFP, BOClean, CMF and NOD32 but doubt any of these are contributing to the crash.

[attachment deleted by admin]

Update process works just fine for me, tho it seems like it’s still crashing Firefox (using 3.0b5 for your information).

Cheers,
Ragwing

For me the updater is doing fine