CIS 5 Defense plus is not functioning properly [NBZ]

TOPIC TITLE
When login using limited user access right in windows xp pro sp3 (latest updated) then Comodo Internet Security Says that

Defense + is not functioning properly and run diagonistic check.


The bug/issue

  1. What you did:Logged in with user that has limited user after successfully installing CIS from admin account.

  2. What actually happened or you actually saw:

  3. What you expected to happen or see:Comodo Internet Security Says that Defense + is not functioning properly and run

           diagonistic check.
    
  4. How you tried to fix it & what happened:I ran diagonistic check but it find no problems.

  5. If its an application compatibility problem have you tried the application fixes?:no

  6. Details (exact version) of any application involved with download link:NA

  7. Whether you can make the problem happen again, and if so exact steps to make it happen:just login with limited user

     								rights.
    
  8. Any other information (eg your guess regarding the cause, with reasons):yes,
    1)I check C:\Documents and Settings\All Users\Application Data\Comodo folder to check its permission are full access to all

users.
2)I created new user with limited access and same thing happened.
3)logging in as administrator or user with admin rights gives no problems.

Files appended. (Please zip unless screenshots).

  1. Screenshots illustrating the bug:Yes , I have detail screenshots.
  2. Screenshots of related event logs and the active processes list:Yes , active process list was alomost empty see yourself.
  3. A CIS config report or file. ya , am going to attach config file with it.
  4. Crash or freeze dump file:No crash happen as firewall and antivirus works fine in limited user access.

Your set-up

  1. CIS version, AV database version & configuration used:posting screen shot of version info (Its 5x)
  2. a) Have you updated (without uninstall) from CIS 3 or 4, if so b) have you tried reinstalling?:No
  3. a) Have you imported a config from a previous version of CIS, if so b) have U tried a preset config?:NO
  4. Other major changes to the default config (eg ticked ‘block all unknown requests’, others here. )No
  5. Defense+ and Sandbox OR Firewall security level:Enabled and both firewall and defense + is in training mode.
  6. OS version, service pack, no of bits, UAC setting, & account type:WINXP Pro , SP3 , 32-bit , NA , Problem with user acct
  7. Other security and utility software running:I disabled all other security softwares but did not helped.
  8. Virtual machine used (Please do NOT use Virtual box):No

[attachment deleted by admin]

I will look into your problem. Have you used the diagnotis tool that CIS has?

Thank for your Bug report, could you please list what other Security and utility software you have installed.

7. Other security and utility software running:

Thank you

Please also check under Start ~ Control Panel ~ Administrative tools ~ Services, and see if the CIS helper service has started.

If it has not there is a work-around

Best wishes

Mouse

Other software running are (important ones)

  1. Zemana Antikeylogger 1.9.2.210
  2. Blue coat K9 filter 4.0.288
  3. Threatfire 4.7.0.17
  4. AVG Link scanner 8.5.365
  5. hp digital imaging monitor
  6. teatimer.exe (spybot resident)
  7. daemon tool lite

CIS helper service is also runing successfully.

Thank you for the bug report, Much appreciated.

Also thank you for providing rest of info and checking CIS service.

Moving to format verified.

Dennis

Do anyone out there is looking in my matter.
Actually i tried to run diagnostic check again but it say everything’s OK plus i created new limited user and tried to log on but same problem of defense plus not functioning.

I do not no that what i am about to report is another bug i think it might just be related to this problem

In event Viewer I am getting error in crypt32. see below

Failed auto update retrieval of third-party root list sequence number from: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt with error: This operation returned because the timeout period expired.
I have windows update set to notify me of any high security alerts, but not to download them or install.
This is working fine.
According to Microsft this error is because of Root Certificates component and suggest to remove or Update it.But I checked it removed it but still error is there than updated but same error again.

If removed my firewall (Comodo CIS firewall with defense plus), as this was the only thing i could think off.

Now i am not getting any errors, and crypt32 has now updated.
Seems that Again, Comodo is messing with Windows Updates.

Are you using fast user switching. I can create this error under XP32 by using fast user switching to switch between User and Admin accounts.

Best wishes

Mouse

No i am not using fast user switching though i do have multiple user both with limited rights and admins.

Failed auto update retrieval of third-party root list sequence number from: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt with error: This operation returned because the timeout period expired.

Failed auto update retrieval of third-party root list sequence number from: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt with error: This network connection does not exist.

Failed auto update retrieval of third-party root list sequence number from: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt with error: The specified server cannot perform the requested operation.

These are three error messages that i got using cis5 , so when why it did not came after comodo uninstall please i love CIS and love to have a solution for all of my problem that i have already reported (hopefully in next update or so…)

  1. defense plus is not functioning properly when login with limited rights user
  2. These error messages in apps logs in event viewer
    3)No firewall logs

thread fire could be the problem

I’m interested in your comment regarding these event log entries as I have them as well. I’f you don’t mind could you create a new bug report on these? Only if you are sure they don’t occur with CIS uninstalled of course.

?I think you or someone else reported the log entry issue elsewhere? Basically you don’t get any unless CIS refuses a connection. Outbound connections for trusted files are allowed by default. Also these is a genuine problem with not all packets being logged under specific circumastances - also reported, and in format verified I thiink

Hey and Welcome cooldude 777! :slight_smile:

you can get Failed auto update when windows tries to install an update that is already installed. Could you list which Security software are active; you can only have one AV with realtime protection, only one firewall active and only one HIPS-technologyzed software. For instance, you can’t have Spyterminator and CIS active at the same time since both uses HIPS-tech. Same goes with CIS and Zemana Antikeylogger.

I hope you understand the point I am trying to say.

Regards,
Valentin

Good news solved
In event Viewer error messages of crypt32. see below

Failed auto update retrieval of third-party root list sequence number from: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt with error: This operation returned because the timeout period expired.

Failed auto update retrieval of third-party root list sequence number from: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt with error: This network connection does not exist.

Failed auto update retrieval of third-party root list sequence number from: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt with error: The specified server cannot perform the requested operation.

These error messages come when using CIS Version 5.0.162636.1135

AND IS RESOLVED IN VERSION 5.0.163652.1142

IS the D+ is not functioning properly error in limited user accounts solved too?

Best wishes

Mouse

NO CIS 5 Defense plus is not functioning properly ISSUE NOT SOLVED REMAIN . HOPE It May get solved in newer Version released.

sorry if this is !ot! and ignorant but have you tried to make clean re-installation of CIS?

Regards,
Valentin N

Sorry to answer late as i am occasional surfer .
To answer your question yes i did tried it.But same problem prevails. :-\

Because i was very busy with my job and study and family i was not able to reply.
But i used my holiday on this AND SOLVED THE PROBLEM AND NOW DEFENSE + IS working the problem was erupted because when i installed CIS 5 I was Tightening my desktop security to highest level actucally i was studying Local Security Policy → User Rights Where i removed Users group From Bypass Directory Traversal Checking Property.
THIS WAS IT To FAIL Defense plus In LIMITED USER ACCOUNT.
Yesterday i added Specific User to it and Defense + start working Normally.
I think Dependency (by Comodo User Agent) on Directory Transverse can be removed by developer and regard it as minor bug.
i am attaching some pics of issue.
Thank YOU For all YOUR COOPERATION
Love help to Improve CIS to make it best Product.

[attachment deleted by admin]