Two Files in C's Whitelist but not Trusted thru Autorun Analyzer [V6][M208]

This bug report is for CCE, which is bundled with CIS.

I run Comodo Autorun Analyzer and select the option to “Hide Safe Entries”. The problem is that two files which are confirmed to be in Comodo’s whitelist are listed as Unknown.


A. THE BUG/ISSUE:

  1. What you did:
    I open CCE and then open Comodo Autorun Analyzer. I check the option to “Hide Safe Entries” and let it complete its scan.
  2. What actually happened or you actually saw:
    After the scan all files but two are listed as Trusted and thus not shown. However, I received confirmation from Comodo in this post that the two files are actually in Comodo’s whitelist.
  3. What you expected to happen or see:
    I had expected that because the two files are in Comodo’s whitelist that they would be rated as Trusted and therefore not shown.
  4. How you tried to fix it & what happened:
    NA
  5. If a software compatibility problem have you tried the compatibility fixes (link in format)?:
    NA
  6. Details & exact version of any software (except CIS) involved (with download link unless malware):
    NA
  7. Whether you can make the problem happen again, and if so precise steps to make it happen:
    This happens every time I let Comodo Autorun Analyzer analyze my computer and hide the trusted files.
  8. Any other information (eg your guess regarding the cause, with reasons):
    It’s possible that this is a cloud issue, but I’m not sure. By the way, Valkyrie links to the two files in question can be found here. Also, I checked again and the SHA1 of the files listed in Comodo Autoruns does still match the SHA1 of those Valkyrie reports.
    B. FILES APPENDED. (Please zip unless screenshots).:
  9. A diagnostics report file (Click ‘?’ in top right of main GUI) Required for all issues):
    Attached.
  10. Screenshots of the 6.0 Killswitch Process Tab (see Advanced tasks ~ Watch Activity) or 5.x Active Process List. If accessible, required for all issues::
    Attached.
  11. Screenshots illustrating the bug:
    Attached.
  12. Screenshots of related CIS event logs:
    NA
  13. A CIS config report or file:
    NA
  14. Crash or freeze dump file:
    NA
  15. Screenshot of More~About page. Can be used instead of typed product and AV database version:
    Information provided below.

C. YOUR SETUP:

  1. CIS version, AV database version & configuration:
    Comodo Internet Security Version 6.0.260739.2674
    Database 14831
  2. a) Have you updated (without uninstall) from a previous version of CIS:
    No
    b) if so, have you tried a clean reinstall (without losing settings - if not please do)?:
    NA
  3. a) Have you imported a config from a previous version of CIS:
    No
    b) if so, have U tried a standard config (without losing settings - if not please do)?:
    NA
  4. Have you made any other major changes to the default config? (eg ticked ‘block all unknown requests’, other egs here.):
    No changes have been made to Comodo Autoruns Analyzer (besides checking the option to “Hide Safe Entries”. Also, I’ve seen this same behavior for Comodo Autoruns Analyzer regardless of the configuration of CIS.
  5. Defense+, Sandbox, Firewall & AV security levels:
    NA
  6. OS version, service pack, number of bits, UAC setting, & account type:
    Windows 7 x64 (Service Pack 1); UAC is disabled
  7. Other security and utility software currently installed:
    Just Comodo System Utilities and CCleaner.
  8. Other security software previously installed at any time since Windows was last installed:
    No
  9. Virtual machine used (Please do NOT use Virtual box)[color=blue]:
    Not a virtual machine.

[attachment deleted by admin]

Hi Chiron

Thanks for this, certainly would be interested to know any dev response.

Would you mind adding config details and account type/ UAC. Config can be config file if changes complex.

Many thanks in anticipation

Mouse

Done. However, I originally chose not to attach a config file as at the moment I have altered my config from default. However, as noted in my bug report I have seen this behavior regardless of the config of CIS. That said, I’ve now attached a config file.

I just wanted to make it obvious to Comodo devs that this bug appears to be independent of the configuration of CIS.

Thanks for appending them, appreciated.

Thank you very much for your report in standard format, with all information supplied. The care you have taken is much appreciated by Comodo, and will increase the likelihood that this bug can be fixed.

Developers may or may or may not communicate with you in the forum or by PM/IM, depending on time availability and need. Because you have supplied complete information they may be able to replicate and fix the bug without doing so.

Many thanks again

Mouse

This bug still exists in version 6.0.264710.2708. Hence I am adding a new post with the new format.

A. THE BUG/ISSUE (Varies from issue to issue)
[ol]- Summary - Give a clear summary in the topic title, NOT here.

  • Can U reproduce the problem & if so how reliably?:I can reproduce the problem every time.
  • If U can, exact steps to reproduce. If not, exactly what U did & what happened:To reproduce this all I have to do is go to CIS and open CCE. Then I open Comodo Autoruns Analyzer. I then check the option to “Hide Safe Entries” and wait until it has categorized every file.
  • If not obvious, what U expected to happen: After the scan all files but two are listed as Trusted and thus not shown. However, I received confirmation from Comodo in this post that the two files are actually in Comodo’s whitelist. Valkyrie links to the two files, for testing purposes, can be found here. Thus, they should have been hidden as well.
  • If a software compatibility problem have U tried the conflict FAQ?: Not a software compatibility.
  • Any software except CIS/OS involved? If so - name, & exact version: Just the version of CCE bundled with CIS.
  • Any other information, eg your guess at the cause, how U tried to fix it etc: I’m not sure.
  • Always attach - Diagnostics file, Watch Activity process list, (dump if freeze/crash). If complex - CIS logs & config, screenshots, video, zipped program (not m’ware) I have attached a screenshot of the two files shown in Comodo Autoruns Analyzer.
    [/ol]

B. YOUR SETUP (Likely the same for each issue, so you can copy forward)
[ol]- CIS version & configuration: CIS 6.0.264710.2708. Database 15112. Default configuration.

  • Modules enabled & level. D+/HIPS, Autosandbox/BBlocker, Firewall, & AV: Everything is default.
  • Have U made any other changes to the default config? (egs here.): Everything is default.
  • Have U updated (without uninstall) from a previous version of CIS: No, it was a clean reinstall.
    [li]if so, have U tried a a clean reinstall - if not please do?: NA
    [/li]- Have U imported a config from a previous version of CIS: No
    [li]if so, have U tried a standard config - if not please do: NA
    [/li]- OS version, SP, 32/64 bit, UAC setting, account type, & VM used: Windows 7 x64 (Service Pack 1), UAC is disabled, administrator account, not a virtual machine.
  • Other security/sandbox software a) currently installed b) installed since OS: None.
    [/ol]

[attachment deleted by admin]

W8 x64 CIS 6.0.264710.708
Non default config with fully virtual enabled
I am also seeing the autorun entry
-\Microsoft\Windows\NetTrace\GatherNetworkInfo
-Unknown C:\Windows\System32\gatherNetworkInfo.vbs
as in above report.
Should I create a separate report ?
Config attached

[attachment deleted by admin]

If they are on Comodo’s whitelist, please just post here to say so. (To confirm see what Chiron did)

Some Ms files are not whitelistsed

Best wishes

Mike

Win 7 64

https://forums.comodo.com/news-announcements-feedback-cis/submit-applications-here-to-be-whitelisted-2013-t89867.105.html

https://forums.comodo.com/news-announcements-feedback-cis/submit-applications-here-to-be-whitelisted-2013-t89867.150.html

https://forums.comodo.com/news-announcements-feedback-cis/submit-applications-here-to-be-whitelisted-2013-t89867.240.html

Still Unknown

Thanks Naren

Mouse

Still Unknown…

This is still not fixed with version 6.1.275152.2801.

Windows 7 x64
Comodo Firewall newest Update

https://forums.comodo.com/news-announcements-feedback-cis/submit-applications-here-to-be-whitelisted-2013-t89867.0.html;msg677614#msg677614

https://forums.comodo.com/news-announcements-feedback-cis/submit-applications-here-to-be-whitelisted-2013-t89867.0.html;msg677628#msg677628

[attachment deleted by admin]

[quote author=Chiron link=topic=90228.msg677653#msg677653 date=1366379205]
Is this CCE as opened from CIS Version 6.1.275152.2801?

Yes

If so I’m also using Windows 7 x64, but I have CIS installed and not Comodo Firewall. I wonder if that could, for whatever reason, be the difference.

I don’t think because it’s the same installation like CIS

Sorry, my English is not good

This is a very good point. I should have noted that on my system as well, the CIS Autorun Analyzer sees it as safe. It’s only through CCE that the file is flagged as unknown.

CCE vs 2.5.242177.201(AutorunAnalyzer) is this file safe but by AutorunAnalyzer opened by Comodo Firewall is the unkown

This is still not fixed with CIS version 6.1.276867.2813.

Tracker updated, thanks.

This is not fixed with CIS version 6.2.282872.2847.

I have received feedback from the devs that they have confirmed this bug and that it will be fixed (although there are no promises as to when the fix will be available).

This is not fixed for CIS version 6.3.294583.2937.

I have updated the tracker.