NOTE: Provided video is AVI format using Microsoft Video 1 codec. It should be viewable using Windows Media Player, VLC Player or Classic Media Player.

Yes. Reproducible every time - at will. Co-confirmed by EricJH on W8.1 x64.

1: Launch any malware sample detected by signature.
2: AV module generates alert.
3: Select “Ignore Once.”
4: Multiple, additional alerts will appear - totaling from 2 to 10+ alerts; number of alerts varies with malware sample.
5: For each additional alert select “Ignore Once.”

Executed malware sample that is detected by signature. Selected “Ignore Once” from within AV alert. Multiple, subsequent alerts were generated. Each time I selected “Ignore Once.”

I expected when I selected “Ignore Once” there would be no additional AV alerts; I expected only one AV alert when selecting “Ignore Once.”

Not Applicable.

Yes. Malware sample attached.

Specific to W8.1 OS. Best guess: It appears when user selects “Ignore Once” the AV alert is acting similar to a HIPS alert. Cause unknown.

Exact CIS version & configuration: - Proactive Security.

Yes. Configuration file attached.

No. Clean install of CIS.

 Current installation is a clean install of both Windows OS and CIS; only Windows OS and CIS currently installed on system.

 Yes.  Issue is independent of configuration.  Issue is dependent upon OS - W8.1 x64.

Windows 8.1 x86-64 (OEM) Toshiba\AMD, “Always Notify,” Administrator, No VM used.

a=None. b=None.


  1. CIS Configuration File
  2. Malware Sample (Adware; QJMonkey, zipped, password “infected”)
  3. Video (OneDrive link, zipped, 5.42 MB: Microsoft OneDrive - Access files anywhere. Create docs with free Office Online.

NOTE: Video can be viewed using Windows Media Player, VLC Player or Classic Media Player

Constant, non stop nagging about this problem even if “ignore and add to exclusion” it will keep asking over and over and over again. The only solution is for me to switch to another directory.

This happens with me too. W8.1 PRO X64 Fully updated and CIS in lastest version. The comodo ask me every time to call a gekkbuddy to remove threats for me, and always detects virus from my folders on ignore list.

