HIPS rules disappear randomly [M1897]

Please note you can upgrade to V6 / V7 from V5.12 as during the upgrade the rules are changed, but you cannot import any configurations into V6 / V7 from V5.12.

I have done a upgrade from V5.12 to V6 to V7 but please note if you do it that way certain new features like webfilter may not work.

I have not done V5.12 to V7 but it should not be a problem for most users, that said it has been posted that the upgrade failed for some members.

Dennis

This morning after I updated CIS to .4426 I was getting an Alert on Restart of my PC. In the logs for D+ was noted that System was trying to write to a Log File… Digging further I compare this PC to another and lo/behold under HIPS Rules I find that all of the standard rules are missing, e.g. the groups Windows System Applications, Windows Updater Applications, COMODO Internet Security, All Applications, etc.

How to repair this CIS installation 8.1.0.4426 so these settings are there again?

If you have exported and saved your configuration, you could re-import it from your saved file. Alternatively, you can import the default configuration(s) from the CIS program folder (you will have to set up your configuration again if you choose the latter).

c:\Program Files\COMODO\Comodo Internet Security\COMODO - Firewall Security.cfgx
c:\Program Files\COMODO\Comodo Internet Security\COMODO - Internet Security.cfgx
c:\Program Files\COMODO\Comodo Internet Security\COMODO - Proactive Security.cfgx

Thanks I will import the standard config–I don’t trust my old settings any more!

:wink:

Hmmmm… I too have observed that the HIPS rule I created are missing from time to time. I do save my config and import them again. I thought that I am only the one that’s experiencing this. Now aside from re-importing back my HIPS saved config is there anything that I can check here. As I said it’s from time to time. I would know when a file from a second partition cannot be accessed and windows would throw a pop-up saying I do not have enough privileges etc. Then when I check the HIPS settings it’s all gone and I ahve to import the saved config again>restart again. It repeats that way, I get a pop-up that I do not have enough enough privileges etc…When I disable HIPS all is okay.

I was to change firewalls later but since I saw this one I may change my mind. is this a bug or something…? It was not so when I was using the earlier version 8.

Also I just saw this,

Originally posted by [b]scooble77[/b] Re: "you have not enough priviledge" Reply 2 --https://forums.comodo.com/defense-sandbox-help-cis/you-have-not-enough-priviledge-t108761.0.html The message "you have not enough priviledge" still appears unless HIPS is in disable mode.
Originally posted by [b]The Dragonfly[/b] Re: Comodo 8.0 HIPS not working properly - https://forums.comodo.com/defense-sandbox-help-cis/comodo-80-hips-not-working-properly-t109559.0.html Then there has be to something with this new version then. Because the HIPS feature in safe mode is not working properly. For time being I reverted back 7.0. Unless there is a way to make HIPS as it was in the previous version. I'm not touching 8.0 at all.

Seems it’s related… I do not remember seeing this issue with ver7 before either. HIPS just went somewhat not remembering it’s rules(even when one has been created).

Anyone please…?

Is this necroing? Are there newer threads about this? Because this was what turned up as newer on a search… (Also found this, with no replies, from a year ago: https://forums.comodo.com/defense-sandbox-help-cis/hips-forgets-rules-t103233.0.html )

Anyway, just noticed this problem, that HIPS doesn’t seem to remember anything after reboot. Being in clean PC mode and set to create rules for safe applications, it recreates rules as needed after that, but any special settings, more specifically apps set to allowed, are no longer like that, and if there’d be anything not known as safe by it I imagine I’d have problems.

I’ve been trying Comodo Firewall paired with other antivirus products this year (after 10 years on Bitdefender, with the firewall included there no longer usable since the 2012 edition finally bit the bullet), first it was with Bitdefender, then Kaspersky, now G DATA, obviously just the antivirus edition for each, and I didn’t see this problem before, but now it’s there. I’m quite sure that right after installing G DATA it wasn’t there, as I purged it to clear entries for Kaspersky (and I think also BD, hadn’t purged it when I made that switch), but so I’m not entirely sure exactly when it started happening, but now it does whenever I reboot.

And no, I don’t have good settings exported, so that’s down as a solution…

Please, help me.
Everytime I restart or shutdown my PC, the HIPS configurations resets. Even the Windows System Applications, Windows Updater Applications, COMODO Internet Security, All Applications, etc rules just disappears from HIPS rules. Not only them, but all my programs.
What is going on? I use Comodo Firewall with the last update version.
I always used Comodo Firewall since version 3 an this never happened before! Please, help me! :frowning:

I would suggest a clean install. Before you do that export your settings to a folder that is not part of the CIS installation folder.

What you describe could be caused by crashing of cmdagen.exe or cis.exe. The Windows logs may shine a light here.

I am wondering if the problem would go away if you would install the previous version. Would you be willing to give that a try?

I have a similar problem. My problem is sometimes when i open advanced tasks>advanced setings and enter on hips rules, all the rules i had previously are gone… The same happens in firewall program rules.
Yesterday i follow these all the steps in this link:
https://forums.comodo.com/install-setup-configuration-help-cis/most-effective-way-to-reinstallupdate-cis-to-avoidfix-problems-t58620.0.html;msg410589#msg410589

Except the part that usage of the additional remove tool.

At the moment i’am using comodo internet security 8.2.0.4674 in windows 7 ultimate only firewall and hips defense +.
In advanced settings on the defense + i use safety mode an in the checkbox in front off “create rules for safe applications” selected.
In the firewall mode i choose “custom rules” and also the same selection as i did in the “create rules for safe applications” selected, and config the level of alerts to “medium”.

I don’t know how to solve the problem without reinstalling the operating system again.

I should mention that all the problems begins in the past when the latest update was made.

I’ve noticed the problem because the firewall gave me an allert that new update was available when i had already installed that update.

Maybe you could try importing a default configuration file in case yours is corrupted. They are located in the CIS program directory:

c:\Program Files\Comodo\Comodo Internet Security\COMODO - Firewall Security.cfgx
c:\Program Files\Comodo\Comodo Internet Security\COMODO - Internet Security.cfgx
c:\Program Files\Comodo\Comodo Internet Security\COMODO - Proactive Security.cfgx

Hello.
First of all, thank you for answering.
I did a Clean Installation and apparently the issue is now gone. I used the latest version (8.2.0.4674) of the setup to do it.
Before I did this, I was using the version 7.x.x (I don’t remember the last numbers of the version) and the issue would continue to persist. But now It’s gone! I’m using the 8.2.0.4674 version. :smiley:
Thank you for your help. I’m starting to believe that my problem was solved! ;D

The problem is likely caused by incidental crashes of cmdagent.exe and cis.exe. Best thing is to make back ups of your configuration. In case of need you can also use system restore; the configuration settings are stored in the registry.

No. I was wrong… The problem persists. I’ve just restarted my PC and the rules got empty again. What is going on?! Is this a BUG or something? Only HIPS rules that’s getting reseted. Firewall rules stills there, and the List of Files on the Reputation section stills the same as well. It’s only with HIPS rules. When this happens program even says that “System” was not recognized when it tries to save a file, modify a registry key, log in into Steam, reboot the PC and anything that “System” tries to do. I need to “allow” System in order for the alerts to stop. The default rules simply disappears (Windows System Applications, Windows Updater Applications, COMODO Internet Security, All Applications and others).

Is there a way to report this BUG/Issue to the developers?
Because I had to do a Clean Installation again in order to return the default rules (Windows System Applications, Windows Updater Applications, COMODO Internet Security, All Applications, etc).

Hi there. You’re not alone.
I’m having a similar issue here.
My issue was almost like yours, but when I tried to restart my PC this exactly same thing used to happen. I did a Clean Installation and my problem apparently stopped. But now it’s not when I restart my PC, this RANDOMLY happens. I don’t know how to fix it. I think it’s a BUG or something. I’m trying to find help too.

I’m sorry if I’m resurrecting this topic. But in my case, HIPS Rules reset occurs randomly after a system boot or with a reboot. I came to think I was the only one with this problem. Even “System” is not recognized by the program anymore. :frowning:

Loosing rules typically happens when cmdagent.exe or cis.exe crashes. Can you check the Windows logs in Event Viewer to see if it reports crashes?

Do you have other security programs installed that run in the background alongside CIS?

Instead of reinstalling you can import and activate a factory default configuration. They can be found in the CIS installation folder. For the time being also consider to make backups of your active configuration.

I took a look at the Windows logs and there was no crash there.

I’m using Avira Antivirus. I looked in the Avira logs something related to COMODO but found nothing. I always used the Avira along with COMODO and this has never happened in version 5x.

Yeah, I know how to restore the default settings, I know how to back up my settings, but restoring my configuration does not seem to have helped.

This INDEED is a BUG and developers should fix it ASAP. :frowning:
I thought I was the only one with this problem.
The COMODO is already aware of this issue?

Can you see if there are CIS dumps in folder c:\ProgramData\Comodo\CisDumps?

Please don’t bump old topics. You have your own topic.