Hello, I have activated HIPS again, as it feels strange to have CIS without HIPS.
Sandbox and Viruscope are off, they have messed up a few installations and I feel them not necessary to be there all the time.
HIPS is in safe mode although a deep scan with CIS and with Malwarebites gave a virus free result (heuristic medium, scan for rootkits).
Today I got two warnings for files I had never heard about, which in internet I read are log files, but I could not find out “logs of what?”.
Which program is using these logs and for which purpose and why now (HIPS is active since a while). I feel like, spied.
Here the screenshots: I could not see the screenshots in the preview so I have posted and I see now, they were attached at the bottom.
Well, should I worry? Should I allow and let remember? Should I put HIPS in Clean PC? Make a Rule? Drink a Tee?
You need to add the file group windows system applications to the HIPS rules and treat it as a windows system application ruleset. Go to HIPS rules and add a new rule, then next to name click browse file groups, select Windows System Applications, then next to Use ruleset select Windows System Application. It should look like the attached picture.
You mean rulesets?
I had three I think, because now with this new one I have four, look at the new attachment.
Could you think of any reason why this windows system thing was not automatically created? I suppose it may have been responsible also for a warning I sometimes saw when turning off the pc, something about system trying to do something, I could never really read well or make a screenshot, because the system was turned off immediately after.
Yes the individual voices inside the group Windows System are the same I have here.
I do not have the Windows Updater group. Is that important? I did not have any problems with Windows Update.
Apart for the fact that I notice now that I do not receive notifications when new updates are available, but it may depend on something else.
I will repeat myself, but, why do you have the Windows System voice automatically there, while I had to create it manually. What went wrong in my Comodo?
Could be a corrupt configuration when updating to newer versions of CIS over an existing install, but judging by your HIPS rules I’m guessing you have “create rules for safe applications” enabled in HIPS settings which removes all default rules and creates new rules as needed.
But I do not understand. In the online help guide it says:
Create rules for safe applications - Automatically creates rules for safe applications in HIPS Ruleset (Default = Disabled).
And also given the following explanation, I had understood that if I selected this option CIS would automatically create rules, otherwise I should create them all manually or by answering “allow” to a popup each time.
I am thousand light-years far from the competence of you guys, so I do not have this ability of creating special rules (as I may know how, but I ignore which rules I should create). This means, I would not hesitate restoring the original profile by doing what you say, or by uninstalling/reinstalling, if the original profile would have safer rules and a more fritctionless experience.
Eventually I will just have to answer “allow and remember” again for some things, no big deal. Done it already.
But I would like to know:
would I have any advantage if I restore the original profile?
read my last post. What did I misunderstood? Why I have the impression that what you told me is the opposite of what the help guide says?
Yes by your very statement “have safer rules and a more frictionless experience” as you wouldn’t have to worry about needing to create rules manually or answer alerts for windows applications and other applications that are deemed safe by comodo.
2) read my last post. What did I misunderstood? Why I have the impression that what you told me is the opposite of what the help guide says?
The help guide is correct but doesn't state that existing rules are deleted so it's not clear if that's intentional or a bug when setting the option to create rules for safe applications.
I am afraid what it says in the help guide and what actually happens for everyone is not the same
Most users have no problems like me even when I try to pester CIS
But others have problems one of them is disappearing rules, the advantage of importing a fresh profile is everything is correct, disadvantage is you lose all your rules that you have added which can be quite considerable.
If you choose a different name for the profile it will not overwrite the existing one, or at least it should not.
I thank you for the answers, but either you did not understand my question or I your answers.
In my understanding the Guide says that I have to select the option “create rules for safe applications” to “instruct CIS to begin learning the behavior of safe applications so that it can automatically generate the ‘Allow’ rules.”
I have understood that you are saying that if one does NOT select the “create rules” he will have the advantage of not having to create rules manually or answer to the popups. Which sounds like the opposite of what the guide is saying.
That is what I meant with “what am I misunderstanding?”.
I can’t find anything about Trusted Vendors, and I find Cloud only in the options of the Antivirus Scans.
What if I uninstall and reinstall Comodo and we make it shorter?
After all, I have created no rule.
Just allowing. I can do that again if necessary.
As far as that would make things easier in the future.