Keeps popping up for Firefox

I’ve configured the firewall to skip the parent check for Firefox. If I close the firewall window and re-open it to confirm, the rule is still there. The next time I open Firefox, the firewall prompt does not appear. Everything is great.

But something happens a little while later, and when I open Firefox some other time, Comodo will prompt me again. When I go to look at the rule, the Skip parent check option is no longer selected.

I’m really tired of answering this prompt. How do I get it to let Firefox go forever?


not sure, did you read the popups close, so firefox might calls new dll s that you MIGHT allow or not,

or firefox is called by a service, whatever …

check if that helps


All components listed in the image need to be set to allow (click the header called “Company” to sort them alphabetically):

If it still doesn’t work, it could be due to one of your plugins. I’d suggest launching Firefox in the Safe Mode, (Firefox Safe Mode, not Windows Safe Mode) which you can do via Start → All Programs → Mozilla Firefox → “Firefox (Safe Mode)”. In this configuration, the browser doesn’t load any plugins.

[attachment deleted by admin]

elmonty, there are a number of different aspects to the security CFP provides, and thus different reasons why you might continue seeing a popup alert for Firefox.

It would help tremendously if you would capture and post a screenshot so that we can see what you’re seeing, with these alerts.




it took me time also, like good old browseui.dll, read popups close if theres no subbutton to allow a dll.

just checkmark remember wont help unless you click the “subbutton” on popup.

might this is the problem ifnot, you might overseen a incident.


What is happening is that the “Skip parent check” option, which I have selected, keeps getting unchecked by itself. See the attached before and after images.

[attachment deleted by admin]

Here are more… (this is what I have to put up with)…

[attachment deleted by admin]


[attachment deleted by admin]


what does your virscanner say?



When I select “Skip parent check”. I expect it to do so.

[attachment deleted by admin]


what is teenspirit?

well theres in advanced “program analysis”. i think most popups refer there.

it just skips, when the parent not changes, or you add each time a app rule for each parent.

its some complex might i could help you into a bit.


PS use google: skip parent check

elmonty, here’s what you’re coming up against; it’s kind of a complex issue.

Apparently you’re starting firefox from one of these other apps (thus the different parent showing). Under normal circumstances, you wouldn’t see this exact issue happening. However, each one of these new “parent” applications is taking some other action - special messages, hooking, OLE automation, etc (all part of application behavior analysis). When you select Allow w/Remember, you create a rule for that scenario. Unfortunately (from user standpoint) this has a higher level of detail than the more general rule you created; thus, the more general rule is overwritten by the more detailed rule.

There are two things you can do to help eliminate those.

  1. In your hand-created firefox rule, check the box for “Skip Advanced Security Checks” - that should disable ABA for firefox.
  2. If you are not using a local proxy (you’ll know if you are), disable loopback checks - go to Security/Advanced/Miscellaneous and make sure both boxes are checked “Skip Loopback…” - TCP & UDP (only one is by default, for local proxy security).

While this should help your scenario, it will also decrease your security for firefox (in the event it really is hijacked). If you know each of these applications that is using FF, I’d forget about the whole “skip parent” thing and let it create a separate rule for each parent application (and NOT disable those advanced checks). That way you have a greater level of security.

Hope that helps,


Thanks, Little Mac. That was a very informative reply. Pretty much any application that has a link to its own website will launch the default browser, which in my case is Firefox.

TeenSpirit is a music library organizer, and it has embedded links to not only its own web site, but also to several music-related sites.

I’ve previously tried “Skip Advanced Security Check”, but that also gets reset by itself.

If you go to Security/Advanced/Miscellaneous, where is your Alert Frequency level set?

Also (I know this is a bunch of work), have you tried creating individual rules by hand, to specify each possible parent? Then set each one for “Skip Advanced Checks.”

Oh, and reboot afterwards.


Here are the current settings.

Manually creating a rule for every application that wants to link to the web is too much work.

[attachment deleted by admin]

If you’re not using a local proxy server (which you’d know if you were), then you should check both “Skip Loopback…” boxes. Only one is checked by default, to mitigate some security risk associated with the use of a local proxy.

I noticed that at least one of your popups was related to the loopback; this should help. Moving the Alert Frequency to Very Low should help a little more.

I don’t think you’re going to get away with pre-creating a single rule for the browser, given your scenario. Each different application that tries to utilize it is taking actions that are/could be of a suspicious nature, thus generating an Application Behavior Analysis (ABA) alert. When you Allow w/Remember, the “exception” to the rule is significantly different enough that it requires a separate rule, as the current rule-handling structure is not complex enough to address it otherwise.

However, if you don’t try to “fight” it, and Allow w/Remember for each alert, after you’ve run the gamut of alerts, you shouldn’t see any more until something changes (application updates, etc). To give you a little hope, v3 has a better architecture on this, allowing a greater level of control.


This thing is still popping up repeatedly for the same application(s) that I’ve told it before to shut up. It’s the most annoying thing. Free or not, it’s not worth the constant nagging.