Welcome, Guest. Please login or register.
December 27, 2009, 04:49:01 AM

Login with username, password and session length

345466 Posts
38154 Topics
86637 Members

Latest Member: Komo

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Feedback/Comments/Announcements/News - CIS
| | | |-+  Workaround for the 99% CPU Problem with the latest Virus DB Updates
« previous next »
Pages: [1] 2 3 ... 21 Go Down Print
Author Topic: Workaround for the 99% CPU Problem with the latest Virus DB Updates  (Read 29123 times)
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 2151



« on: October 07, 2009, 10:45:31 AM »

Hello Everyone,

Because of an issue with the latest virus database, some computers might observe significant CPU consumption problems caused by cmdagent.exe.

You might observe this issue if your virus database version is 2525 and later. We have reverted the problematic updates. However, because of the nature of this issue, already affected computers might not function properly to revert the updates back.

For those computers, the following instructions can remediate the issue:

1 - Reboot your computer in safe mode
To enter to the safe mode, you need to press F8 button before Windows starts booting until you see the boot menu. In the boot menu, select the safe mode.
2 - Delete the file in c:\program files\comodo\comodo internet security\scanners\bases.cav
3 - Copy c:\program files\comodo\comodo internet security\repair\bases.cav to c:\program files\comodo\comodo internet security\scanners folder(this action will replace the current bases.cav file with the original bases.cav file that comes with the installation).
4 - Restart your computer and Update your virus database again.

after these 4 steps, everything should go back to normal.


Alternatively, you can manually download the latest bases.cav file from http://download.comodo.com/av/updates311/sigs/bases/BASE_END_USER_v2456.cav and replace the problematic bases.cav with this version.

Directions for System Administrators who use COMODO ESM for managing the endpoints(These directions are NOT for end-users):

1. By using ESM console create a sequence with Set CIS config action that turns off realtime scanner (set it to disabled mode). You can use previously discovered configuration from one of your endpoint computers or try to discover a new one.
2. Create a task from the sequence that was created in the previous step and choose the target endpoint computers for it.
3. Run the task.
4. Go to Task results manager and make sure the task has successfully finished.
5. Create the task with sequence containing the reboot action and with endpoint computers from the previous task
6. Run the task. After target computers got rebooted cmdagent on that computers should not use 100% of CPU
7. Create task with sequence containing discovery getCISconfig action and run it on all endpoint computers from the previous task
8. Go to Task results manager and make sure the task has successfully finished.
9. Open the discovery data you have, choose one of your endpoint computers and make sure the realtime AV scanner is disabled.
10. Create and run AV DB update task for endpoint computers recovered in the previous steps.
11. Change Set CIS config action data from the step 1 to turn on realtime scanner (set it to “on access” or “stateful” mode). Save the sequence containing this action and run the task created on step 2.
 

We are sorry for the inconvenience this might have caused.

Regards,
Egemen


« Last Edit: October 08, 2009, 10:19:17 AM by egemen » Logged
scanreg
Comodo Member
**
Offline Offline

Posts: 30


« Reply #1 on: October 07, 2009, 10:51:42 AM »

Will this eventually work through the normal updating process?

Should a new version of CIS be downloaded?

Thanks
Logged
Silent Assassin
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 362


SILENCE! I'll kill you! ;-)


« Reply #2 on: October 07, 2009, 11:00:50 AM »

Hi Egemen and thanks for the info

Will a reinstall of CIS solve the problem?
Logged

COMODO Polish Localization Team
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 2151



« Reply #3 on: October 07, 2009, 11:09:18 AM »

Hi Egemen and thanks for the info

Will a reinstall of CIS solve the problem?

Sure reinstall wil also fix the issue if you can do that.
Logged
scanreg
Comodo Member
**
Offline Offline

Posts: 30


« Reply #4 on: October 07, 2009, 11:11:01 AM »

Reinstall didn't work for me
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 8373



WWW
« Reply #5 on: October 07, 2009, 11:12:22 AM »

Reinstall didn't work for me

reinstall now will work..

reinstall before the reverting back to old db would not have worked.

thanks and sorry for that guys..

Melih
Logged

vsk
Newbie
*
Offline Offline

Posts: 16


« Reply #6 on: October 07, 2009, 11:20:02 AM »

You do not need to reinstall.
I ve done the workaround and now the computer boots up normal.

Updating the AV-Database failed so far, maybe to many people doing it right now...

So I am downloading base.av manual.

http://download.comodo.com/av/updates311/sigs/bases/BASE_END_USER_v2456.cav

Checksum MD5 / SHA1xxx would be very nice !!!
« Last Edit: October 07, 2009, 11:24:05 AM by vsk » Logged
lallero
Newbie
*
Offline Offline

Posts: 13


« Reply #7 on: October 07, 2009, 11:30:13 AM »

The AV portion of CIS definetly needs more work if just a definition update can cause all this.
I had installed CIS for a few of my friends' pc's and have had them call today reporting that they can't use their pc's, and since they aren't the most computer savvy people, I had to go and fix the problem (uninstall CIS in safe mode in this case, as there was no sureway fix at the time).

If this happened as a result of a version update of Comodo, then fine, no big deal, it's just a bug and I'm on-site to fix it as I'm doing the update, but since it was caused by a mere definition update that gets pushed to your pc in the background, well, I'm not impressed. I hope Comodo will implement safeguards to prevent this from happening in the future.

I imagine today may have been a huge mess for people who manage multiple pc's in multiple locations with CIS installed...  Sad

Now pondering if I should just install the firewall for now, hmm.

Edit: Also, it was quite funny when one of my friends called and said he thought he might have a virus and I had to explain "err.. no, actually the problem is your anti-virusRoll Eyes
« Last Edit: October 07, 2009, 11:34:43 AM by lallero » Logged
DangerousDan
Newbie
*
Offline Offline

Posts: 5


« Reply #8 on: October 07, 2009, 11:37:14 AM »

This morning, I ran into this problem.  Cry  After several hard resets and attempts to correct this problem without access to the net, I decided that in order to have enough cycles to access the internet and discover whether anyone had a solution to the problem, it would be necessary to temporarily disable cmdagent.exe by renaming it to cmdagent.ZZZ.  Very shortly after logging onto forums.comodo.com, I found this thread and read about the work-around.  After a reboot, I discovered that the work-around worked, and cmdagent has now been restored and the software has even replaced bases.cav, but I wasn't terribly comfortable on the net with a dead command agent.  The firewall and anti-virus appeared to be still working, according to CFP.EXE, but were they?  What does cmdagent.exe do when it is doing its job?
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5239



« Reply #9 on: October 07, 2009, 11:46:55 AM »

Hi Dan,

It's the engine of the product, cfp.exe is just the configuration and reporting tool so to speak...
Logged

Forum Volunteer - Any concerns? Please send me a PM and/or review the Forum Policy !
Graham1
Comodo's Hero
*****
Offline Offline

Posts: 889



« Reply #10 on: October 07, 2009, 11:51:31 AM »

So glad I found this thread Smiley. Have been fighting this one on/off all day at work and was about to give up Cry. Thanks for the reponse and advice Thumb Up. Hopefully, I'll have a more productive day tommorow Grin.

Smiley
Logged
boombaard
Comodo Family Member
***
Offline Offline

Posts: 67


« Reply #11 on: October 07, 2009, 11:53:03 AM »

I have to say I'm fairly shocked & appalled by the carelessness displayed here.

Do I really have to reboot again in safemode to delete the bases.cav, or will it be overwritten by later updates too, as long as I just wait?

Secondly, I don't know how the core affinities work, but is it possible to only allow cmdagent access to 1 core, so that people with more than 1 have less of a problem with continued usability if this happens again?
« Last Edit: October 07, 2009, 12:21:55 PM by boombaard » Logged

Windows7 b7600 x64 Professional
AMD64 x2 7750BE (Un-OC)
MSI 790GX (IGP enabled)
4GB Kingston ValueRam
SB X-Fi XtremeMusic
rambo
Comodo's Hero
*****
Offline Offline

Posts: 502


« Reply #12 on: October 07, 2009, 11:55:38 AM »

Do i avoid the problem if i don't update my second computer for a few days?
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5239



« Reply #13 on: October 07, 2009, 12:00:28 PM »

Currently the AV will only update to version 2524 and not higher so at the moment you can't cause trouble on a system that hasn't been updated to 2526 and 2527...
Logged

Forum Volunteer - Any concerns? Please send me a PM and/or review the Forum Policy !
rambo
Comodo's Hero
*****
Offline Offline

Posts: 502


« Reply #14 on: October 07, 2009, 12:07:43 PM »

OK,thanks
Logged
Tags: Virus database updates  2526  2527  100% CPU  cmdagent.exe 
Pages: [1] 2 3 ... 21 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.091 seconds with 19 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com