Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
August 30, 2008, 07:05:58 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
187293
Posts
21672
Topics
52497
Members
Latest Member:
cyberdiver
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo BOClean Anti-Malware
Administrator cannot update [Resolved]
« previous
next »
Pages:
[
1
]
2
Author
Topic: Administrator cannot update [Resolved] (Read 3170 times)
vjk
Newbie
Offline
Posts: 9
Administrator cannot update [Resolved]
«
on:
May 31, 2007, 09:59:51 AM »
v4.23 (and v4.22) Win2K + NOD32 + SpywareBlaster+Sygate v5.5
BOClean announces:
"ERROR!!! UNAVAILABLE! Check connection or firewall settings, site might be down." or
"ERROR!!! NOT connected. Check connection or firewall settings."
- when in fact it should be checking for and downloading an update. This is an old issue that goes back to October of 2006. When a manual update is attempted - 4.23 throws the analogous Comodo branded error message.
As far as I can tell, neither is a valid error message, as the program never attempts to connect - which can be verified by the firewall logs. At the same time, you can download psc-exam.exe from
ftp://ftp.nsclean.com/pub/psc-exam.exe
- so FTP is not being blocked. Sygate does not have the application blocked or a rule in place to prevent access.
If connected as a user - there are no issues. Checks and updates both via autoupdater and manually via the tray menu. You can browse the net with Firefox 2.0.0.4. regardless of user name.
This makes working as administrator to reconfigure or update a box extremely difficult, as BOClean pegs the CPU at 100% as it tries and fails to make a connection, which effectively makes the box unusable until BOClean releases the CPU.
Help in resolving this would be nice.
«
Last Edit: June 07, 2007, 04:17:46 AM by ~cat~
»
Logged
Jbob
Comodo Member
Offline
Posts: 37
Re: Administrator cannot update
«
Reply #1 on:
May 31, 2007, 02:01:40 PM »
Fwiw if I block the BOC updater(4.23) at my firewall(ZA) I get this message:
"ERROR!!! NOT connected. Check connection or firewall settings." so that appears to be a valid message.
I'll repeat here basically what I said over at Securecomp, try another Admin profile and not just the default Administrator profile created during the Win2K install. Although you didn't mention Win2K in this post. And just for grins I'd try it by turning off Sygate.
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6011
Re: Administrator cannot update
«
Reply #2 on:
May 31, 2007, 02:06:27 PM »
Comodo uses different servers, and at points it may update via a different address. If you have set the IP to a specific one in your firewall (and note, 4.23 is not from the old nsclean servers, but I believe 4.22 still is), this may play into it, and it is just happenstance that it does this when the Admin logs in. Not saying that's it, but it's something to keep in mind.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Jbob
Comodo Member
Offline
Posts: 37
Re: Administrator cannot update
«
Reply #3 on:
May 31, 2007, 02:10:42 PM »
LM The OPs issue is not one of not being able to update but updating while logged in as Administrator. The update works ok as a User but not while logged in as Admin.
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6011
Re: Administrator cannot update
«
Reply #4 on:
May 31, 2007, 02:50:47 PM »
I saw that, Jbob.
Other users have reported similar issues; some apparently have come from directing the application to a single set IP in their FW; sometimes it would be blocked, sometimes it wouldn't. Would probably be too much coincidence in this case, but you never know...
Also, vjk, You may want to post in this thread to let Kevin know
http://forums.comodo.com/index.php/topic,8915.0.html
in case he needs/wants some other info from you. He's requested all "odd" things be reported to him there so he can just keep an eye on one single thread...
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Jbob
Comodo Member
Offline
Posts: 37
Re: Administrator cannot update
«
Reply #5 on:
May 31, 2007, 03:37:34 PM »
That's interesting about the single set IP. Incidentally the OP has posted on another forum that creating a new Admin profile has solved the update issue. Of course that doesn't answer why it is the default Admin profile that has the issue. Maybe this will be another clue for those that are having updating issues.
I'm wondering Sygate?
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6011
Re: Administrator cannot update
«
Reply #6 on:
May 31, 2007, 03:55:52 PM »
I should probably clarify about the IP thing... I don't mean sometimes the FW blocks the IP and sometimes it doesn't. I mean that sometimes the update server is that IP and sometimes it's a different one.
Comodo confirms that they are using a number of different servers and hosting companies due to the volume against their system (ain't public demand great?), and frequently drop various ones from rotation. They advised against users setting a single address for updates, as it may not be "live" at any given time.
Quote from: Comodo
The DNS records for the servers are in the format:
<continent><number>.download.comodo.com
Ex: eu1.download.comodo.com
They went on to say that thus, using download.comodo.com will guarantee a live, local server.
So that's what I'm getting at. Glad that creating a new Admin account resolved the issue; it would be good for Kevin to know, so that can be taken into account (if it's an issue he's not aware of).
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
vjk
Newbie
Offline
Posts: 9
Re: Administrator cannot update
«
Reply #7 on:
May 31, 2007, 09:12:41 PM »
The new user with administrator rights did *not* resolve any issue - it's a work-around and nothing more.
It simply shows that the problem is that BOClean cannot deal with the *default* user in Win2K and that changing the configuration of the default Administrator account can stop BOClean from updating itself. No update - no protection. It aint rocket science and it aint Sygate even if you really really want it to be.
Logged
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: Administrator cannot update
«
Reply #8 on:
May 31, 2007, 10:59:46 PM »
Sounded to me like the image you're restoring from may have issues, a corrupted admin account perhaps?
Try it with a fresh install from a MS disk and see.
«
Last Edit: May 31, 2007, 11:02:20 PM by ~cat~
»
Logged
Parched dry and thirsty, knee deep in the river of life.
vjk
Newbie
Offline
Posts: 9
Re: Administrator cannot update
«
Reply #9 on:
June 01, 2007, 08:39:00 AM »
Sounds to me like corruption is a real stretch.
First off, you have 3 machines for which autoupdate does not work - period - and all three exhibit slightly different symptoms for the manual update. On one of the machines, is what appears to be BOClean attempting to download via FTP using notepad - which Sygate than flags and asks if it should be allowed. Sygate logs all the manual updates but there is nary a whiff of any attempts by the auto updater.
And this problem was documented more than 8 months ago with a detailed trouble report.
I think the gruntwork has been done on this puppy, and I am not about to start rebuilding a box from scratch because someone may want to believe 3 default administrators on three different machines are corrupted, when all the evidence points to sloppy code and there are the screen shots to prove it.
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6011
Re: Administrator cannot update
«
Reply #10 on:
June 01, 2007, 10:29:06 AM »
vjk,
If you have not done so already, please let Kevin know by posting in this thread:
http://forums.comodo.com/index.php/topic,8915.0.html
A brief scenario and link to this topic should be sufficient.
Tnx,
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: Administrator cannot update
«
Reply #11 on:
June 01, 2007, 12:32:14 PM »
Quote from: vjk on June 01, 2007, 08:39:00 AM
I think the gruntwork has been done on this puppy, and I am not about to start rebuilding a box from scratch because someone may want to believe 3 default administrators on three different machines are corrupted, ...
I'm sorry, I thought you stated either here or at Securecomp that all 3 boxes were installed from the same image.
Logged
Parched dry and thirsty, knee deep in the river of life.
jasper2408
Global Moderator
Comodo's Hero
Offline
Posts: 651
Re: Administrator cannot update
«
Reply #12 on:
June 01, 2007, 12:43:52 PM »
Quote from: ~cat~ on June 01, 2007, 12:32:14 PM
I'm sorry, I thought you stated either here or at Securecomp that all 3 boxes were installed from the same image.
I'm not saying that you didn't do this as this is just a suggestion to look at and it may not be the problem, but, if the boxes are all on the same network(using the same DNS server)were installed from the same image then did you run sysprep on the boxes before putting them on the network?
I have seen that small detail cause some very weird problems with permissions and DNS servers. The same SID on all the boxes is not good. Sometimes the problems won't show up til weeks later.
jasper
Logged
CFP 3.0.22.327beta CMF Avast Pro SAS Pro Sandboxie Win XP PRO SP2 (x32)
vjk
Newbie
Offline
Posts: 9
Re: Administrator cannot update
«
Reply #13 on:
June 01, 2007, 09:34:16 PM »
Quote from: ~cat~ on June 01, 2007, 12:32:14 PM
I'm sorry, I thought you stated either here or at Securecomp that all 3 boxes were installed from the same image.
We restore from a known good Acronis image of an individual installation. Each machine has a current image and archive - and the images are usually done in 1 month increments - roughly in sync with the MS patch cycle. We typically retain 3-6 months of images for each machine. When something like this comes up, it is relatively easy to isolate a "culprit" by restoring a previous image. If I recall correctly, that was what was done when this first came up - and it was determined that that the issue did not exist prior to 4.22.002. The issue has remained the same since then. The images for the three boxes we are testing here are totally unrelated to one another - they are exclusive to the machines they image. Your point on corruption is well taken, but it would likely have to be a systemic MS thing - maybe related to their patches - and in that case could therefore be found on all three boxes. That, however, would not be related to the imaging process.
Logged
Kevin McAleavey
Administrator
Comodo's Hero
Offline
Posts: 299
Snag a nasty? NO problem! =)
Re: Administrator cannot update
«
Reply #14 on:
June 04, 2007, 08:20:08 PM »
Definitely one of the stranger ones I've heard of. One of our (former) customers contacted me and said that he'd been through this a while ago and offered this advice that might be the solution for you. Normally the only thing that would cause that problem is the connection being blocked by a firewall. But there's one OTHER thing that could do that and that was what I was reminded of since I'd never seen that one.
If either Outlook Express or Internet Explorer is placed into "offline mode" and left that way, that would cause what you describe under Win2000 ... in order to reduce the amount of code and ensure compatibility with so many different firewalls with different interpretations of what is "safe" and what isn't, we designed the autoupdate (and the manual one as well, it's the same code) to use the WININET library in Windows (since you can't remove it and it's there anyway). And to further ensure compatibility no matter what's thrown our way, the ftp download is done using whatever is PRESET for IE/Outlook Express because some firewalls required odd settings in those as well. By doing things this way, then whatever was required externally would simply be picked up by BOClean's updater and used with no further complications.
UNLESS perhaps on those machines in question, either IE or Outlook Express was put into "offline" mode and left that way. So give that a shot, it's the only thing I can think of if everything else is working and there's no firewall or other configuration blocking FTP ...
Logged
"I reject your reality and substitute my own." - (Adam Savage, "MYTHBUSTERS" TV show)
Tags:
Update Issues
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in -0 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com