I’ve got winlock while CIS was running with both antivirus and firewall in training mode. My explorer was replaced with 22CC6C32.exe, taskmgr and userinit were replaced by virus files and also 03014D3F.exe got in system32 somehow. How could that happen?
I’ve submitted them all, can’t attach to topic though.

If you are running in training mode everything is allowed, no alerts just allowed.

Training mode should only be used for very short periods, like when opening a program.


Well my bad on Def+ and Firewall then. But why did Stateful Antivirus mode didn’t help? I guess comodo didn’t know about this particular virus yet, because when I then scanned the file it was clear :slight_smile: