[Resolved]Defense Plus log entry

I have been a user of Comodo Firewall for 3 years now but only just started using Defence+ yesterday.
I think i have pretty well got it sorted but wanted confirmation that i have interpreted some log entries correctly.
I found the relevant post in the forums FAQ

'Access memory' event log entries - how can I suppress these? [v5] - Defense+ / Sandbox FAQ - CIS - Comodo Forum

These are the log entries

2011-01-07 09:10:44 C:\Program Files\Malwarebytes’ Anti-Malware\mbam.exe Access Memory C:\Program Files\Comodo\Comodo Internet Security\cmdagent.exe
2011-01-07 09:14:05 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Access Memory C:\Program Files\Comodo\Comodo Internet Security\cmdagent.exe
2011-01-07 09:14:19 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Access Memory C:\Program Files\Comodo\Comodo Internet Security\cfp.exe

If i am reading this correctly Comodo has blocked SAS & Mbam from scanning Comodo’s memory space (in other words Comodo self defense mechanism is in play)

I really just after re assurance that i am understanding this correctly :slight_smile:

Yes; you are correct;

Jake

Thank you very much Jake, your response is appreciated :slight_smile:

Your Welcome;

Any other questions?

Jake

I assume it is probably best left alone, i don’t feel a great need for SAS & Mbam to be scanning what Comodo is trying to protect ie Comodo memory space

It is best to leave this alone. As each program you allow to access CIS in memory is a breach of its self protection. Suppose the allowed file gets infected then the malware could try to attack CIS.

Only when an application is not functioning properly without having memory access, which seems a bit of a questionable design practice to me, you should allow it.

Thank you for your response Eric it is much appreciated, i thought this was the case just wanted assurance that i was on the right track. HIPS is all very new to me but i think i am getting my head around it :slight_smile:

Thank you again Eric & Jake for your help

Any thing else we can help you with?

Jake

No thanks, i think i have all my queries covered for the time being :slight_smile:

Ok :slight_smile:
If any other issues or questions please dont be afraid to ask;

%lock%

Jake