(Solution Found) DCOM Exploit getting through COMODO Firewall. Blocked by !avast

Hello. I have Comodo firewall W D+ and avast antivirus. I have been getting a lot of “DCOM Exploit” attacks for the last week which are by passing COMODO but thankfully avast is blocking the attack.

What and who may be attacking my computer and why isn’t comodo blocking it?

P.S. If it helps us all figure this out i also posted on COMODO forum (including many screen shots)about this problem linking the 2 together. Here is the link https://forums.comodo.com/firewall-help/dcom-exploit-getting-through-comodo-firewall-blocked-by-avast-t52004.0.html;msg370961

Do you happen to have file and printer sharing enabled as that may open port 135 as that is the port normally used for the DCOM exploit attempts.

Why comodo isn’t catching this before avast is beyond me.

er…um…er…I’m not sure

Check the windows help and support on your OS and search for file and printer sharing, that should point you to the area where it can be set or disabled. I believe that by default it may be enabled.

@ the OP: just don’t take into account all the bs they told you on Comodo forums about “two firewalls”, ie, neither the Network shield not the Web shield are firewalls, and they do not conflict with any firewall ::slight_smile: my god seems these guys there have absolutely no idea about avast “free” components ;D I’ve used Avast 4 & 5 a long time together with Comodo firewall&def+…no issue whatsoever.

As to your DCOM exploit issue, it could be FPs from the network shield, you need to give more details about the sites you visit when the avast alerts come. As to why Comodo Internet security doesn’t stop those, it’s their problem. But again, if you got FPs, that’s another story.

@ “DavidR” – I checked “Windows Firewall” which is off. Under “Exceptions” it indicates that “File and Printer sharing” is Disabled. I didn’t turn it off. It was already off.

@“Logos” – What is FPs ??? As to details “about the sites you visit when the avast alerts come” there are none ??? The alert happens even when i dont have a web page open ??? “As to why Comodo Internet security doesn’t stop those, it’s their problem” Well right now there problem is affecting MY COMPUTER ::slight_smile:

“FP” = false positive (a wrongly detected threat), as to the sites, the IP mentioned there (in your own pic) at least triggered the network shield alert:

https://forums.comodo.com/firewall-help/dcom-exploit-getting-through-comodo-firewall-blocked-by-avast-t52004.0.html;msg370985#msg370985

and again, “As to why Comodo Internet security doesn’t stop those, it’s their problem” , because you’ve been asking here why Comodo didn’t stop the threat am I right ? ::slight_smile:

What and who may be attacking my computer and why isn't comodo blocking it?

O I’M SO CONFUSED As i’m not sure if this problem is avast FP or a COMODO leak

It’s not a Comodo leak I don’t think. Go to this link press continue then select all service ports and let and scan it should take only a minute and a half at most. https://www.grc.com/x/ne.dll?bh0bkyd2 report back if everything is green or not and if one block is red tell us what the port is.

With help from the COMODO Forum 8) I think the fix has been found ;D https://forums.comodo.com/firewall-help/dcom-exploit-getting-through-comodo-firewall-blocked-by-avast-t52004.0.html

:frowning: i failed the test badly

I haven’t seen any of those in ages, but at one time I was getting occasional (supposed) DCOMs blocked by the network shield which had slipped past the firewall – ZA, then Comodo. Don’t remember seeing any since I switched to the PC Tools firewall.

Generally the advice here was that if it had been detected and blocked by avast, don’t worry about it.

lol thats like saying “the water tap isn’t leaking, it’s just dripping. Don’t worry about it till it’s gushing”

Poor advise dont you think

P.S. The problem at hand has been solved (thank you COMODO Forum) so i’ll end this thread

Your analogy doesn’t hold water (sorry couldn’t help myself), what does it matter if your firewall blocks it (which it should) and doesn’t raise a pop-up or the network shield does alert because the avast network shield happens to be intercepting the traffic before your firewall.

So it wouldn’t matter if it were a drip or a flood, if your firewall was blocking it you would be none the wiser as it doesn’t notify you.

Correct! But my firewall was not blocking it and avast was blocking it but…with avast blocking it i was getting lots and Lots and LOTS of avast warning pop ups which were VERY anoing.

Problem now fixed. No more pop ups. No problem with avast. It was a setting in COMODO

END