cmd_fw_installer_138430009_eb.exe
Sources: observed in the EchoTrail lab on Windows 11.
Summary
COMODO Internet Security (COMODO Internet Security, COMODO)
cmd_fw_installer_138430009_eb.exe is not in the 2025 snapshot. It was observed in EchoTrail's behavior lab on Windows 11 24H2 on 2026-09-28 installed from manual_url package https://download.comodo.com/cis/download/installs/1000/partners/cmd_fw_installer_138430009_eb.exe?af=17225.
Get this in your tools
The same record for cmd_fw_installer_138430009_eb.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/cmd_fw_installer_138430009_eb.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\lab\in
Top Hashes (SHA256)
- 9b6394b0d1da147c5c718ebf3aba211ce2d4aefc63eb0dc80ed5cfc0db269bcd
Process Ancestry
Top Grandparents
Top Parents
Top Children
Lab record
- Installed from
- manual_url https://download.comodo.com/cis/download/installs/1000/partners/cmd_fw_installer_138430009_eb.exe?af=17225
- Publisher
- Comodo Security Solutions, Inc.
- Persistence
- none
- Network
- none
- Command lines
- 1 pattern (1 launch)
- DLL loads
- 54 patterns (55 loads)
- Registry writes
- 8 patterns (12 writes)
- File writes
- 1 pattern (35 writes)
- HTTP requests
- 0 patterns (0 requests)
- TLS connections
- 0 patterns (0 handshakes)
- Named pipes
- 0 patterns (0 events)
- Process access
- 0 patterns (0 events)
- Driver loads
- 0 patterns (0 loads)
- PowerShell blocks
- 0 patterns (0 blocks)
- Remote threads
- 0 patterns (0 events)
- Audit events
- 1 pattern (1 event)
Full record on Team.
Ask Rocky about cmd_fw_installer_138430009_eb.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for cmd_fw_installer_138430009_eb.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.