PDA

View Full Version : Fixed: Comodo Internet EvilEye!



Barry777
2009-05-08, 20:57
I've been using Spybot for a long time now & among my other security software, I was using the older Comodo Firewall for 2000/XP. I just updated to the latest Firewall in their Internet Security Suite, this is a very strong firewall using HIPS. I was shocked today in receiving the message from Spybot that it had terminated EvilEye in Comodo! I actually choose to allow knowing Comodo to be reliable. Here is a copy of the log below"

5/9/2009 1:55:08 AM Allowed (based on user decision) value "COMODO Internet Security" (new data: ""D:\Program Files\Comodo\COMODO Internet Security\cfp.exe" -h") added in System Startup global entry!
5/9/2009 1:55:08 AM Encountered and terminated EvilEye in D:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe!
5/9/2009 1:55:08 AM Allowed (based on user decision) value "DefaultUserName" (new data: "Downloads") changed in Winlogon!

I googled this issue & found nothing. Then, I scanned the file cmdagent.exe online with Totalscan (using multiple anti-viris/spyware engines) & none found a problem with the file. So either this is a false positive or Spybot's staff knows something about why Comodo is really offering "free" security software... hehe. Comments please

Thanks,
Barry

drragostea
2009-05-09, 01:44
I'm positive this is a FP. The detectives should resolve this in the next upcoming update (scheduled for Wednesday, May 13th).

Have a good day.

Buster
2009-05-11, 12:29
Hello Barry,

please send the Comodo executable file to detections@spybot.info for further analysis. This way we will be able to reproduce and fix this false positive. Thanks in advance!

best,
buster!