Hello, I suggest even more colors or maybe darker or lighter derivate of current pop up colors for obvious malicious behavior, like below:
Picture Note: It is installation attempt of rootkit (driver part) of rustok-trojan (variant)
BTW. Great work Comodo :-TU This is superb detection and behavior description of one of most sophisticated piece of malware…
Even better though, in the long term, would be a text description of what each item does. There would be a text description for each protected registry key, COM interface, protected file/folder, etc. Comodo would provide descriptions for the default items. This text description would have to be user-editable because users can add custom registry keys, COM interfaces, and files/folders to be protected.
If you (offchu), OK and Cancel replace with Allow and Block (with Default on Block) treatcast rating will be then in favor of Blocked 100%, (which is right answer BTW)
The Alert should also remember previous choices. So if log is picked then the next alert should also have log picked. With the exception of edit rule, i don’t think you want to edit every single rule :D.
Do you guys pay attention to the alert description? And how CFP alerts about the virus hiding itself? Another real life example about the effectiveness of D+.
When you have Treat As option, Allow/Block can not be proper. Because a predefined set, can result in blocking the currently active popup, but if the user clicks on Allow button, he will think he will be allowing while the predefined poicy will block it.
This was the only reason we did not keep Allow/Block buttons when we had Treat As option. However, we may have this Treat As button with a dropdownlist plus Allow and Block buttons.
Actually, I liked putting Treat As as a dropdown button. What do you think?