Welcome, Guest. Please login or register.
December 30, 2009, 08:41:54 PM

Login with username, password and session length

346341 Posts
38275 Topics
86915 Members

Latest Member: Cristy666

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Archive Boards
| |-+  Comodo Firewall
| | |-+  Help for v2
| | | |-+  Firewall Still Logs After Disabling
« previous next »
Pages: [1] 2 3 Go Down Print
Author Topic: Firewall Still Logs After Disabling  (Read 5915 times)
Soyabeaner
Legendary
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7655



« on: November 20, 2006, 03:40:33 PM »

I disabled logging from Application Monitor and Network Monitor and cleared all existing logs.  After rebooting it still logs windows media player (which I exclusively blocked in App Mon) whenever it starts (but only once during the computer's active session).  Any clues as to whether it's a known bug?
« Last Edit: February 08, 2007, 07:37:28 AM by soyabeaner » Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5325


I'm not a complete idiot, some bits are missing.


« Reply #1 on: November 20, 2006, 03:50:16 PM »

 Wave
Can you post an example Log entry here please. Remember to mask any private IP addresses. Thanks.
Logged

Vista Business x32+SP2 with CIS 3.12 & Firefox 3.5 & Becky! 2.52
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
Soyabeaner
Legendary
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7655



« Reply #2 on: November 20, 2006, 03:58:26 PM »

I had to reboot to generate this:

Date/Time :2006-11-20 15:55:52Severity :MediumReporter :Application MonitorDescription: Application Access Denied (wmplayer.exe:206.xx.xxx.xx:dns(53))Application: C:\Program Files\Windows Media Player\wmplayer.exeParent: C:\WINDOWS\explorer.exeProtocol: UDP OutDestination: 206.xx.xxx.xx:dns(53)

Date/Time :2006-11-20 15:55:50Severity :MediumReporter :Application MonitorDescription: Application Access Denied (wmplayer.exe:206.xx.xxx.xxx:dns(53))Application: C:\Program Files\Windows Media Player\wmplayer.exeParent: C:\WINDOWS\explorer.exeProtocol: UDP OutDestination: 206.xx.xxx.xxx:dns(53)

Date/Time :2006-11-20 15:55:50Severity :HighReporter :Application MonitorDescription: Application Access Denied (wmplayer.exe:206.xx.xxx.xx:dns(53))Application: C:\Program Files\Windows Media Player\wmplayer.exeParent: C:\WINDOWS\explorer.exeProtocol: UDP OutDestination: 206.xx.xxx.xx:dns(53)
Logged
Soyabeaner
Legendary
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7655



« Reply #3 on: November 20, 2006, 04:04:50 PM »

Another discovery:

You know the default selection in the logs is Today, right?  Well, when I select another one like Last 7 Days and it cleared the log!
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5325


I'm not a complete idiot, some bits are missing.


« Reply #4 on: November 20, 2006, 04:13:01 PM »

Can you get it back by closing & reopening the CPF front-end?
Logged

Vista Business x32+SP2 with CIS 3.12 & Firefox 3.5 & Becky! 2.52
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
Soyabeaner
Legendary
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7655



« Reply #5 on: November 20, 2006, 04:17:14 PM »

I if select back to Today the log is still not there.  However, this time instead of rebooting my computer I closed and restarted CPF and those original entries returned.  I had WMP running during the CPF restart, so I thought how about closing WMP and restart WMP, and guess what?  A new 2-set log entry (the high warning wasn't there this time, only the 2 mediums) were added on top of the old 3.

Then I repeated the (WMP not CPF restart) process and it generated another 2 new medium logs.  Subsequent tests doesn't generate any more WMP logs.  There doesn't appear to be any pattern.
« Last Edit: November 20, 2006, 04:35:57 PM by soyabeaner » Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5325


I'm not a complete idiot, some bits are missing.


« Reply #6 on: November 20, 2006, 04:36:43 PM »

I see! OK, sorry. Yes, you're right. CPF does not save log entries between reboots. However, it does when it is manually closed before the reboot (thats currently the only known workaround). What is your OS? Are you running User Profile Hive Cleanup (aka UPHClean)? Also, just confirm your CPF version? Thanks.
Logged

Vista Business x32+SP2 with CIS 3.12 & Firefox 3.5 & Becky! 2.52
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
Soyabeaner
Legendary
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7655



« Reply #7 on: November 20, 2006, 04:42:01 PM »

Quote
CPF does not save log entries between reboots

Actually, that's kind of what I want. Grin, but more specifically I want CPF to not log at all.  Seems to be a small bug ATM.  My CPF is the latest stable 2.3.6.81.  OS is XP SP2.  Ever since the upgrade from SP1 to SP2 I uninstalled UPHClean because any logging off problems were gone Wave.
« Last Edit: November 20, 2006, 04:49:37 PM by soyabeaner » Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5325


I'm not a complete idiot, some bits are missing.


« Reply #8 on: November 20, 2006, 05:23:14 PM »

Sorry, I forgot about WMP. If you know what a HijackThis is.. have you run that to see if WMP is sneaking in on startup.
Logged

Vista Business x32+SP2 with CIS 3.12 & Firefox 3.5 & Becky! 2.52
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
Soyabeaner
Legendary
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7655



« Reply #9 on: November 20, 2006, 05:30:47 PM »

I'm proud to state that my HijackThis log has been clean for over a year (at least I think it is Smiley).  If there's anything new I would know, or do you want to take a look?

Also, I only connect to the internet after everything is loaded, including CPF.  If there's no net connection then WMP doesn't attempt any outgoing connections.  Once I'm logged on the net WMP appears to know and then the attempted connections and then the CPF logs...
« Last Edit: November 20, 2006, 05:51:23 PM by soyabeaner » Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5325


I'm not a complete idiot, some bits are missing.


« Reply #10 on: November 20, 2006, 06:39:03 PM »

OK. Then I recommend that you goto Comodo Support, register on their system (if you haven't already) & raise a ticket on this. Remember to give them all the details & there is no need to mask your private IP.
Logged

Vista Business x32+SP2 with CIS 3.12 & Firefox 3.5 & Becky! 2.52
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
Soyabeaner
Legendary
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7655



« Reply #11 on: November 20, 2006, 06:48:18 PM »

Thanks for your responses, kail. Smiley

I have submitted that ticket.
« Last Edit: November 20, 2006, 07:48:10 PM by soyabeaner » Logged
Soyabeaner
Legendary
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7655



« Reply #12 on: January 14, 2007, 11:23:38 AM »

Yes, I mean bytes... Wink

I tried to reproduce you log problem, but I couldn't...

Do you have these sevices in administrative tools on manual start?
WMDM PMSP Service
Windows Media Player Network Sharing Service
Try that

Have you unchecked WMPNSCFG in msconfig/autostart?
Try that too.
Reboot your PC and see if there is some change.

I've never even seen those names, let alone have those services.  And this doesn't happen at every computer startup/boot; it happens at every CPF startup.  My services are running at minimum essentials (I've tinkered with this for a very long time so I know).  Also, this isn't limited to WMP but any application that makes internet connections, for which I've created a block ANY ANY TCP/UDP IN/OUT Application rule.

What's weird is that after some time (I don't know exactly the duration because it seems random), say at least 30 min to 1 hour, all subsequent start up of WMP doesn't generate any logs as desired.
« Last Edit: January 14, 2007, 11:27:58 AM by soyabeaner » Logged
AOwL
Comodo SuperHero
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2349


Comodo Firewall Pro - Be safe, use protection...


WWW
« Reply #13 on: January 14, 2007, 12:37:28 PM »

Hmm...
As I said I can't reproduce this, so hopefully Comodo can help you.
By the way, do you have WMP11?
Sorry I can't help.
I can only say one thing...
Use Foobar instead... Grin Grin
Logged

WinXP SP2 HE - IE7 - FF 2 - TB - CFP 2.4 - NOD32 - BoClean -ST - AMD64x2 - 3Gb Ram - 1.5Tb HD
Soyabeaner
Legendary
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7655



« Reply #14 on: January 14, 2007, 12:39:00 PM »

WMP 10 and Winamp (which also created the same results if I blocked it).  Again, it's definitely not which apps I use but something to do with my system and/or CPF.  It would be silly to pick another audio player just for something this trivial Tongue.  I only stick with WMP because I think the audio quality is better, but that's another debate.

Maybe there should be an option to size the log to 0 MB Smiley
« Last Edit: January 14, 2007, 12:47:54 PM by soyabeaner » Logged
Tags:
Pages: [1] 2 3 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in -0 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com