Unsolved
This post is more than 5 years old
2 Intern
•
2.2K Posts
0
15189
June 10th, 2008 23:00
Loosen Up Comodo Firewall?
Good grief Charlie Brown...this program even chokes on Windows Updates. :smileysurprised: Even though I was in Installation Mode I was still presented with about 25 alert windows all concerned with MRT.exe, which is the Malicious Software Removal Tool. I would think after seeing this file before that the firewall program has enough "brains" to make a rule about it. Perhaps the settings are too tight or would that make a difference? My Comodo settings are:
Security Level== Safe Mode
Defense + Security Level==Clean PC Mode. Any ideas on this one?
No Events found!


joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
June 11th, 2008 00:00
Dale:
I also put CFP 3.0.25.378 into installation mode, and was unable to update at MS Updates. Got an error that suggested it might be a firewall problem, but didn't get any firewall alerts. Figured maybe it was a server congestion problem, as CFP 3.x hasn't interfered with MSU updates before.
After reading your post, I disabled my CFP firewall and HIPS (Defense+), went to MSU and successfully downloaded/installed all updates. A reboot was required, after which I re-enabled the FW (to Safe mode) and the D+ (to Clean PC Mode).
If you are behind a hardware FW (NAT router) as I am, you might try this.
KathiMR
282 Posts
0
June 11th, 2008 04:00
I just installed Comodo Firewall and right after doing so and running the suggested scan I got an alert in the little bar at the bottom that there were updates. But then it was weird because the little icon, when I passed my mouse over it kept showing 0% download.
And during the process I was getting those same messages and then after awhile I caught on to install mode, but then for some things like when I was installing Avast I decided to say it was a trusted aplication.
But the MS critical updates for XP apparently installed as I later finally did get some message telling me that I needed to restart the computer for them to take effect.
And the little update shield icon isn't showing down there so I guess they did get installed.
I also had just a bit of a challenge with Avast since it took me a bunch of the little alerts until I noticed the install mode option. But then there was another part that had a different file name so I had to click on it to see that it was from Alwil and thus part of the program.
But just now as i was typing this I first got an alert from Avast that the virus database had been updated, then I noticed one of those alerts from Comodo that didn't recognize it. I selected to treat it as an updater. Then it asked if I wanted to go into installer mode to make it fully effective. I said yes. And then just now it warned me it was still in installer mode and asked if I wanted to go back to normal and I said yes.
So I guess I need to get used to it and maybe it needs to learn my programs. I haven't tried my most important ones yet so I guess I should try that and make sure I can use it ok.
In checking further in the program I found a notice that 347 files are waiting for review in the My Pending Files. So it wanted to me decide what to do with them such as move to my safe files which I did for the ones I could identify.
I found a bunch associated with the installation of Avast as well as others for magicJack and for A2. Many of them include temp or .tmp so I guess they are temporary files.
But also there were a bunch from Microsoft update or microsoft.
But besides those, there are still a bunch there that I don't know what to do with. some system 32 quartz, etc. I guess for now I'll just leave them alone. And learn more about the program and what the implications of those in the my pending files is.
So I don't really understand yet what that is all about, whether that means that those files were not put where they could be used or what. And I think most or all of them were ones that I allowed either by being in installation mode or otherwise clicking on a choice to allow them. So I don't understand why they ended up there.
And I sure hope this doesn't continue. But it could just be that I need to read more about how the program works.
dalem29
2 Intern
•
2.2K Posts
0
June 11th, 2008 17:00
I forgot to mention that the Windows Updates downloaded OK, but I am just annoyed that I have to babysit the machine on these security program updates. If the Comodo Firewall is really running that tight a ship, I guess that is OK, but hopefully they can make it a bit user friendly over time, especially with the Installation Mode option...about 30 seconds after you turn it on it is asking if you want to continue in that mode...before you are even done with the installation or update. Comodo's BOClean finally automatically updated yesterday, 6-10, after being installed for over a week. Still no luck with the Comodo firewall update. Always get the message below. It connects enough to say that an update is available and then:
Error 106: Update could not be completed. Not able to connect to Internet, please check your Internet connection settings.The machine I am writing on now, an 8400, will become the backup computer over the weekend as I hook up my XPS 420. I have Online Armor downloaded and will start using that for test purposes, and then start with Comodo on the new machine and see how that goes. And like you KathiMR, I find "My Pending Files" a tad confusing. My favorite option up to now has just been to ignore them and wish they would go away. A lot of them look important and I am afraid to delete them. At any rate...these security programs are free to one and all and I can't really complain if there are a few glitches and minor problems along the way. Maybe whine a little, but not complain. :smileyvery-happy:
joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
June 11th, 2008 23:00
For a complete explanation of My Pending Files, open this module and click on ? What do these settings do? Below is a short summary:
My Pending Files is just a registry list of new or modified Program Files that CPF detects in Clean Mode when you install new software, or upgrade to a newer version. It detects all program files (exe, dll, etc) including some that were only created temporarily during the install, and subsequently deleted during the install process.
The purpose of the Purge button is to identify the dead registry entries that point to these now non-existent (i.e. invalid) files, and to delete them from the registry. It is always safe to click on the Purge button, which will usually shorten the list, sometimes considerably. What is left are valid files (i.e. files that exist on your PC; valid does not imply they are safe).
Consider My Pending Files as just another layer of defense, that allows you to double-check that what you have installed is trustworthy, and to let CFP identify them as such. I always run it after every new or upgrade installation of software.
For example, I just downloaded/installed the latest SpwareBlaster 4.1
- I view "My Pending Files" and see 5 new entries (2 .tmp, 2 .exe, and one .dll)
- I click on [Purge] and the 2 .tmp files entries are gone, since they referred to temp files created/deleted during the install, and thus are not valid files still existing on my PC.
- Since I know I just installed a new SpywareBlaster, I assume that the 3 valid (i.e. files that actually exist) files remaining (spywareblaster.exe, sbautoupdate.exe, and SQLite3SB.dll) are "safe".
-Thus I checkmark all 3, and click on [Move to] and select "My own safe files".
- CFP now recognizes these as safe; My Pending Files is once again empty.
- Alternatively, if I have suspicions about the validity of any file remaining after [Purge], I checkmark it and click on [Lookup...]
- A new window opens, and tells me if it is recognized as safe (whereupon it is removed to My Safe Files) or bad (in which case it is quarantined) or unknown (in which case you will be offered to upload the suspect file to Comodo for analysis).
It sounds complicated, but is in fact easy.
If you have been ignoring My Pending Files for some time, but are satisfied your PC actually is clean of malware, I would suggest you:
1) Run Disk Cleanup
2) Open My Pending Files, and click on [Purge]>[Yes]
3) At the top left corner in My Pending Files, checkmark the box next to All? \ File Path
4) Click [Move to] and select My Own Safe Files.
dalem29
2 Intern
•
2.2K Posts
0
June 12th, 2008 02:00
KathiMR
282 Posts
0
June 12th, 2008 03:00
OK, i just got the alert again. It said svchost (I think that was the name or close) is trying to access the internet. It is a safe program but another computer is trying to connect.
When I clicked on the program it just said it was a generic program or something like that.
So apparently this is a program that others use, but I don't know who is trying to connect. I remember something about in Norton you could click on the, I forget the name, but the numerical address of the computer and it would show who that address was allocated to in most cases. So sometimes I found it was my isp (or maybe it was another user of my isp, I wasn't sure which).
I'm guessing its probably ok and I guess if I ok it, other features in Comodo or Avast or A2 would block suspicious behavior--is that right?
joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
June 12th, 2008 03:00
It's not for nothing that I've been saying that CFP 3 demands a lot of the user.
Having made the considerable investment in time required to learn the ropes, I still think it a good product, but it is certainly neither intuitive nor user-friendly, particularly when compared to the free Online Armor FW.
KathiMR
282 Posts
0
June 12th, 2008 03:00
OK, thanks for the clarification. I just did the purge and there are still about 5 files that all look related as they all end in quartz.dll. They are all in C Windows and the first 2 are system 32 and the others have a weird alpha-numeric string.
They all show as unknown files. I guess I made a mistake by okaying the Windows update right while I was in the midst of installing other software. I'm guessing these may be part of that, but what do you do with unknown files? Do you go ahead and submit them to Comodo?
I imagine that you are better able to identify some of these than some of the rest of us. I already sent the oens that I could identify as belonging to Avast, or the Windows update to the safe files and now the temp ones have disappeared.
Thanks so much for clarifying about them. I figured in the normal course of things those would go away but wasn't sure what would happen to the ones in Comodo.
Plus while I was busy with something else an alert came up that something was trying to access the internet and asked me about it. Since I was in the middle of running a net on the radio, I didn't have time to click for more info. It was something like syshost or something that looked vaguely familiar and I'm guessing that it might have been one of my programs trying to update itself.
That went away and it shows that one suspicious thing was blocked.
If we get an alert like that that we don't respond to one way or the other, I guess it will time out and block it, but if it is an updater or something, will it be blocked the next time because we didn't respond, or will the alert come up next time it tries so there is the oppty to look it up and then allow if it is associated with a legitimate program?
Thanks for you help with all this (and other issues as well) Joe53. It is very helpful!
I'm assuming that the amount of alerts may lessen as it learns and I learn. I forget what mode its in, but I didn't change it, other than allowing the install mode which of course reverts back after a short time.
I figure that when I don't know, defaults are usually the safe option.
joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
June 13th, 2008 01:00
Svchost.exe is a valid and generic Windows process that hosts many services, and is constantly communicating with the net. Since your Comodo is still learning, this is most likely what the alert was for, considering the other info you give, and you are probably OK.
However, there are malware circulating on the internet which use the same name - svchost.exe. The legit svchost.exe will be present in the %windir%\system32 folder, typically C:\WINDOWS\SYSTEM32\.
If svchost throws up another firewall alert, click on the application: svchost.exe to open a properties window that will confirm the location; if as above, then click on Remember my answer, and Allow.
--------------------
In general, you cannot assume that your other defensive programs will detect malware that you mistakenly allow to connect in a firewall alert. By definition, your real-time AV/anti-malware should have detected it already.
If ever in doubt about a process CFP detects that you do not recognize, it is always safe to block it (once), after noting its location, and giving this info in a question in this or the Comodo forum. (Don't check Remember my answer in this scenario, however).
KathiMR
282 Posts
0
June 13th, 2008 08:00
Thanks. I think that's where it was so I allowed it a couple of times.
I can see it is learning, but as the other person said, its kind of strange that comodo doesn't recognize major programs and stuff. It has alerted on Excel.exe and Winword.exe as unknown programs! A bit surprised by that but I just told it ok.
I still need to get used to when to just allow it and when to chose one of the other options such as trusted program--but that isn't always available. And it also was alerting when I tried to print, but I could see hp in the name, plus of course I knew I had given it the print command.
And then when I was trying to print in a rush to print something for my Dad's dr before dashing out the door late, woudldn't you know the printer first needed a new black cartridge (which I should have changed the night before) but then it wanted to align it and for some weird reason after printing the alignment page and putting it on the screen it wouldn't align. Not sure what that is about since it has always done it before, it seemed to have trouble scanning, but I just scanned something I think it was the day before ok, so don't know what was going on. Unless comodo somehow interfered with it, or maybe the printer is having issues. Of course its not brand new.
Its funny that the one big program that I was concerned about--our co software with the uploads and downloads didn't seem to have any problem. I don't remember whether it even asked for permission.
I guess Comodo and I will keep learning each other's behaviors for awhile.