Ive got annoying problem with my Defense+ module of CFP. I got one stubborn program called Foxit Reader that every rule im trying to teach D+ is not working. My D+ module is running at Paranoid Mode (like always). Ive noticed this change since ive upgraded my CFP (i use automatic update). Whats more, i had a rule for this program in previous version of CFP and it was working perfectly normal. Every time im trying to open some PDF file the D+ module shows me pop up’s with the same 3 questionns:
Access the screen directly
Access the keyboard directly
Access the Service Control Manager
and every time im checking the checkbox to remember my answer.
When im trying to open PDF file from internet through the Firefox i also get one more question: firefox execute Foxit Reader. I also check the checkbox but everytime it happens again. And at Firefox rule everytime im creating new rule through the pop-up. A new rule is beeing added to run executable: Foxit reader. So i got many same rules.
What ive tried to do? Ive tried:
-switching to train mode (only change was the popup didnt apper but after switching back to paranoid mode the pop-up still appears)
-using trusted application policy - no change, still pop-up
-adding rule manually by specifying the running process and location
-changing rules manually
What ive changed at Advanced options? Ive changed:
-added some new predefined security policies
-checked to trust the applications digitally signed by Trusted software vendors
-block all the unkown requests when application is closed
My observations? Ive observed:
-at previous version the rule for Foxit reader that was created automatically was something like that:
“C:\Program Files\blablalba”
and current version is:
“C:\PROGRA~1\blablabla”
The defense+ module appers to ignore the rule for this program at all.
One more thing (dont know if this is connected to this problem). Despite i was at Paranoid Mode (only existing rules are appliable) at start of system ive noticed the Defense+ was creating new rule (Paranoid mode cannot create new rules. Is this due to “Trust the applications digitally signed by trusted software vendors” option checked?)
This is a known issue and was discussed here. CFP 3.0.18.309 is supposted to fix this issue and it did for most people having this problem, including me. I suggest you to make a ‘clean installation’ and don’t import any settings from previous version.
I’ve made a clean install and the problem still occures. The diffrence is that the last time the rule somehow was remembered for explorer.exe executing foxit, now pop-up appears even when using the windows explorator.
AQQ.exe is also started by windows with 8.3 path (C:\PROGRA~1\AQQ\AQQ.exe) and i’m not having any problems with it. It’s still all about foxit reader.
I haven’t imported any previous settings. And i don’t know what more should i search for.
UPDATE:
I’ve found that similar thing happens to MS Word Viewer.
2. Operating System information (including Service Pack Version)
Microsoft Windows XP SP2 PL, x86-32
3. Actively-running security and utility applications
Avira Antivir
4. Specific symptoms of the bug, and steps you can take to reproduce it (step by step).
Defense+ doesn’t remember the rules.
Open PDF by Foxit Reader or DOC by Word Viewer.
That is all
5. Specific steps you have taken to try to resolve it.
I’have tried all the combinations of adding a new rule and\or deleting old rule. No change.
6. Brief description of your Defense+ and Firewall+ mode (Custom, Train with safe) plus mention if you modified any setting in ADVANCED section of D+ and F+
Defense+ mode: “Paranoid mode”
Changes made at ADVANCED section:
added new predefined security policies
chekced option: “Block all the unknown requests if application is closed”
Firewall mode: “Custom policy mode”
added new predefined security policies
7. If you pc reboots or you have a BSOD post in BSODs: Please add your minidump files here
My computer doesn’t reboot or BSOD so N/A
I’m interested if there is any progress in solving this bug. I still experience it with those two programs (Foxit Reader and MS Word Viewer). The only new observation is that this problem doesn’t occur while the D+ module is at “Clean PC” mode (trouble still comes up with “Training” mode on). Don’t force me to install Adobre Reader
OK every time I write a post I usually try to work out a solution. I found the rules used by D+ module at register and i tried to change some things. I am totally unsure if it was it but that worked for me. Here what I have tried to do and what helped:
Tried:
-delete both entries about foxit (with C:\progra~1 and with c:\program files…). Not helped
-done the same at D+. Not helped.
-changed the short form(with tilde) to normal form. Not helped
I think this helped:
-found entry with long form (no tildes)
-changed everything to short form(every catalogue/file that was longer than 8.3)
(C:\Program files\Foxit Reader\Foxit Reader.exe to C:\Progra~1\Foxitr~\Foxitr~1.exe)
-changed back to long form
Of course every time u want to change something at rules at register you have to turn off firewall (otherwise it will write back the old rules).
I am sure something there had to help because as i said i had a fresh install of Comodo (not update) and this problem still occurred.
P.S.
Ive deleted all rules from D+ module about Foxit (through D+ rules manager). Restarted the firewall (BTW firewall crashed and I’ve send some info to you ) and tried again the Foxit. Everything works fine now. This is bizarre. :THNK
Hope the bug will not come up again. (L)
EDIT: Today after restart problem came up again (:AGY)
OK this is the most bizarre i found about Comodo. Before my fun with register D+ module always added rule for C:\PROGRA~1\Foxit Reader\Foxit Reader.exe. Now it always adds C:\Program Files\Foxit Reader\Foxit Reader.exe and guess what? Everything works fine. BUT. Before my fun with register i also added rule for Foxit manually (by Add->Select->Running Processes/Browse and it also added C:\Program Files\Foxit Reader\Foxit Reader.exe but somehow it didn’t work. I don’t know why. It’s your part of the job guys. I have done my part (:KWL)
P.S. I have not forgotten about NOT using Clean PC mode. I am at Paranoid (my favourite one ) mode
OK I don’t get any regularity in it. Bug is back again and again a rule for C:\Progra~1\Foxit Reader\Foxit Reader.exe is added to service Foxit reader (despite existence of earlier automatically added working for some time full name rule).
EDIT: Despite I block Foxit every time it pops me up it works normally (opens PDF and can use screen display, keyboard, disk etc). Will try to play with register again
The trick with changing C:\PROGRA~1\Foxit Reader\Foxit Reader.exe to C:\Program Files\Foxit Reader\Foxit Reader.exe at register with temporarily switched off firewall worked for me again.
Hi, I’ve installed AVG 8 and the same bug occurs with it. It is even worse than with Foxit because AVG every few minutes is trying to execute sth and i can’t create rules for this. Will have to go back to avira.
Version 3.0.24.368. Bug still occurs. It only occurs when after the system reboot I have opened some PDF through Firefox (when i create rule a new rule with shortened path is added to rule list).
No I don’t feel the need for Paranoid mode and yes O read PDF with Firefox all the time. PDF’s download then when done Foxit opens up. Is Foxit a trusted app in both the firewall and D+?