Failed to update the virus signature database

How do you do that? I have been going through this step by step and following all the suggestions (to no avail). :frowning: I had a fresh install of comodo when I assembled this computer seven months ago, it was working great untill recently, even updating to the newest ver did not work. (cant even get it to update using the safe mode w/downloaded .cav)

Firewall rules should look like this for the Comodo Group

Add, Select, File Groups, Comodo Internet Security and give it the pre-defined policy ā€œoutgoing onlyā€.

My firewall is set like that. I even attempted to set it as a trusted app, but to no avail, it still will not update the database. It does not even attempt to connect to the internet, it just goes to 5% then ā€œFailed to update the virus signature database. Please check your internet connection and try again later.ā€ This computer only had CIS on it, so it cannot be fighting with any other security program. (Had because I installed the other programs listed in the various threads while attempting to trouble shoot the problem)

I just uninstalled the comodo av, and installed Avast!, it didn’t want to update the signatures either until I went into the proxy settings and changed it from ā€œAuto detectā€ to ā€œdirect connectā€. Could the problem with Comodo v be along the same lines?

my guess is you are correct, so in the end the problem is with your proxy settings. You can manually change them in comodo, by going to misc tab at the top.

I was tried to do this, but it has no effect. Will the update to a newest version of CIS from my 4.1.150349.920 fix the problem?

Hi alexey_laa,

Welcome to the forums!

I’m not sure if I understand you correctly are you already running 4.1.x.920?

Yes, I’ve seen , I already have a latest version.

I tried also to update the virus signature base with firewall, switched to ā€œDisabledā€, but CIS still not updated.

Can you test the following?

Can you go to More, Settings, Connection and put the following proxy details in there?

[v] Use HTTP Proxy

Server = 211.115.185.50
Port = 8080

See if that works? It’s just for test… and uses a remote proxy server, this has worked in the past for other users…

I have set the connection to use proxy as described above. The CIS failed to update again. This time the error message was appeared immediately, although with the previous settings it was appeared with a half-minute delay.

Adding a rule (TCP In/Out source, destination port 80 allowed) doesn’t changed anything.

Can my system (WinXPSP2Rus) be not fit to CIS, can the SP3 be recommended?

I have observed also that the HDD indication LED flashes shortly with a period of 1 s. when the update error occurs (if this tells something :slight_smile: ).

Well it should not have anything to do with CIS but yes for general security SP3 is still supported by Microsoft, SP2 is no longer updated…

Did you have any other security software installed, or is there something active that could block the connection?

I don’t use other antivirus software permanently. I use a DrWEB CureIT! utility sometimes, its developer says that it can be run in parallel with other antivirus software.

A Norton antivirus was installed in my system in a past. I’m not sure, maybe it was not uninstalled correctly.

Can the ADSL modem to block a connection? But I never seen this with other software I use.

Can you please try this to see if we can figure out what’s going wrong?

https://forums.comodo.com/guides-cis/how-to-use-wireshark-to-troubleshoot-network-issues-t59409.0.html

I had the same issue. What did help was a hint from another thread (sorry couldn’t find it anymore):

Go to Control Panel → Administrative Tools → Services
Double Click the Service ā€œCOMODO Internet Security Helper Serviceā€ and go to ā€œLog onā€ tab
Click on ā€œBrowseā€ and enter your user name (if you’re an Administrator) and click ā€œokā€
Enter you password twice and click ā€œokā€
Reboot.

Now updates work fine but funnly the window title bar of the update process window is missing.

Really a strange error… especially because the directory "c:\Documents and Settings\All Users\Application Data\COMODO\tmp was writable for all users (that’s where the temporarely downloaded signature file is stored).

I don’t think it was a network problem for me…

Hi neuweiler

Devs would like to know if you have changed ā€œanyā€ security settings on your system like local security policy etc?

Why would the system service no longer have enough permissions to finish AV update??

i had the problem that only applying of the updated virus definitions did not work. So i tried the advice of ā€œneuweilerā€ to change the user to another admin user and now updating works.

p.s. i also deleted the write-protection from the comodo-temp-directory
ā€œc:\Documents and Settings\All Users\Application Data\COMODO\tmpā€

Hi Gohan,

Can you please tell me a bit more about your systems security settings.
Did you tweak any Windows Security stuff from the policy or used other tools?

Can you also expand a bit on the tmp directory what permissions where set, and what did you remove?

Hello all you moderators and volenteers,

I’m here for help with the same issue. I’ve been through this whole thread, and tried just about everything that has been suggested with though, I couldn’t find a misc tab to toggle the setting to direct.

I’ve downloaded wireshark and will work on getting that set up for someone to take a look at.

Again, I have the exact same issue- AV update failed, check internet connection. The best I’ve gotten out of it is 5%, most of the time 0%. I did paste an updated .cav file in scanner and repair manually.

I’d really like to use this stuff, but I am not far away from unistalling it and going back to AVG.

Hi mjb,

If you have created a packet capture please send me a PM where I can download it.
As it’s 23:42 here so I won’t be able to look at it earlier then tomorrow morning tough.

Sorry, I’m not having any success with wireshark either. I haven’t been able to get around the attached error message. I checked the help files, my hardware, google, wireshark.org- nothing. Looks like I’ll need help with wireshark first, before I can get help with CAV. ??? :-\

"the capture session could not be initiated (failed to set hardware filter to promiscuous mode). please check that ā€œ\deviceā€¦ā€ is the proper interface.

[attachment deleted by admin]