Problem with Downloads with WebShield [Outpost 1.0 FREE Issues]

Here it is:

[1596] Open new addresses 81EA28A0 0.0.0.0:2700(6)
[1596] Conn=00000000 (81EA28A0), Prot 0, Process MOZILLA.EXE, Local 0.0.0.0:2700, Remote 0.0.0.0:0
[1596] Process connect to 2700 → 127.0.0.1:12080 (outgoing)
[1596] Open new addresses 82233458 0.0.0.0:2701(6)
[1596] Conn=00000000 (82233458), Prot 0, Process ASHWEBSV.EXE, Local 0.0.0.0:2701, Remote 0.0.0.0:0
[1596] Process connect to 2701 → 140.211.166.204:80 (outgoing)
[1032] *OnEndOfRequest for http://download.mozilla.org/?product=firefox&os=win&lang=en-US
[1032] No body sent so far, flushing all
[1032] *OnEndOfRequest - returning 134217730
[1596] Process ASHWEBSV.EXE disconnect from 140.211.166.204:80 (incoming)
[1596] Process ASHWEBSV.EXE disconnect from 127.0.0.1:2700 (incoming)
[1596] Process MOZILLA.EXE disconnect from 127.0.0.1:12080 (incoming)
[1596] TDI_MSG_CLOSE_CONNECTION 82246538
[1596] – unknown
[1596] TDI_MSG_CLOSE_ADDRESS 81EA28A0
[1596] – unknown
[1596] TDI_MSG_CLOSE_CONNECTION 8221DC08
[1596] – unknown
[1596] Address info 822FAC18(0) 0.0.0.0:0->127.0.0.1:12080 added
[1596] TDI_MSG_CLOSE_CONNECTION 81E65F90
[1596] – unknown
[1596] TDI_MSG_CLOSE_ADDRESS 82233458
[1596] – unknown
[1596] Open new addresses 82233458 0.0.0.0:2702(6)
[1596] Conn=00000000 (82233458), Prot 0, Process MOZILLA.EXE, Local 0.0.0.0:2702, Remote 0.0.0.0:0
[1596] Process connect to 2702 → 127.0.0.1:12080 (outgoing)
[1596] Open new addresses 82246538 0.0.0.0:2703(6)
[1596] Conn=00000000 (82246538), Prot 0, Process ASHWEBSV.EXE, Local 0.0.0.0:2703, Remote 0.0.0.0:0
[1596] Process connect to 2703 → 64.202.105.103:80 (outgoing)
[1032] *OnEndOfRequest for http://mozilla.mirrors.hoobly.com/firefox/releases/1.0/win32/en-US/Firefox%20Setup%201.0.exe
[1032] Calling g_pfnAavmCheckFile
[1032] Object clean
[1032] File opened OK
[1032] xfer buffer allocated
[1032] Writing rest of data - body
[EEF94849] Bad MDL diagnostic 90: 1: 00040110-81654000-0003C09A-00000000 [81EA91B0]

[1032] Everything OK
[1032] Closing body file handle
[1032] *OnEndOfRequest - returning 134217730
[1596] [EEF94849] Bad MDL diagnostic 90: 1: 00040110-81654000-0003C09A-00000000 [81EA91B0]
[1596] Process MOZILLA.EXE disconnect from 127.0.0.1:12080 (incoming)
[1596] TDI_MSG_CLOSE_CONNECTION 81E65F90
[1596] – unknown
[1596] TDI_MSG_CLOSE_ADDRESS 82233458
[1596] – unknown
[1596] Process ASHWEBSV.EXE disconnect from 127.0.0.1:2702 (incoming)
[1596] TDI_MSG_CLOSE_CONNECTION 81EA91B0
[1596] – unknown
[1596] Address info 822FAC18(0) 0.0.0.0:0->127.0.0.1:12080 added
[1596] Process ASHWEBSV.EXE disconnect from 64.202.105.103:80 (incoming)
[1596] TDI_MSG_CLOSE_CONNECTION 8234E9C8
[1596] – unknown
[1596] TDI_MSG_CLOSE_ADDRESS 82246538
[1596] – unknown
[1596] Process MOZILLA.EXE disconnect from 66.193.254.46:80 (incoming)
[1596] TDI_MSG_CLOSE_CONNECTION 81CE1168
[1596] – unknown
[1596] TDI_MSG_CLOSE_ADDRESS 81760130
[1596] – unknown
[1596] Open new addresses 82221888 0.0.0.0:2704(6)
[1596] Conn=00000000 (82221888), Prot 0, Process MOZILLA.EXE, Local 0.0.0.0:2704, Remote 0.0.0.0:0
[1596] Process connect to 2704 → 127.0.0.1:12080 (outgoing)
[1596] Open new addresses 82262B18 0.0.0.0:2705(6)
[1596] Conn=00000000 (82262B18), Prot 0, Process ASHWEBSV.EXE, Local 0.0.0.0:2705, Remote 0.0.0.0:0
[1596] Process connect to 2705 → 67.15.62.22:80 (outgoing)
[1032] *OnEndOfRequest for http://forum.avast.com/index.php?action=post;topic=11318.15;num_replies=19
[1032] Calling g_pfnAavmCheckFile
[1032] Object clean
[1032] File opened OK
[1032] xfer buffer allocated
[1032] Was check-encoded, sending the rest
[1032] Writing rest of data - body
[1032] Chunked encoded - writing last chunk
[1032] Everything OK
[1032] Closing body file handle
[1032] *OnEndOfRequest - returning 134217730
[1596] Process ASHWEBSV.EXE disconnect from 67.15.62.22:80 (incoming)
[1596] Process ASHWEBSV.EXE disconnect from 127.0.0.1:2704 (incoming)
[1596] Process MOZILLA.EXE disconnect from 127.0.0.1:12080 (incoming)
[1596] TDI_MSG_CLOSE_CONNECTION 82202B78
[1596] – unknown
[1596] TDI_MSG_CLOSE_ADDRESS 82221888
[1596] – unknown
[1596] TDI_MSG_CLOSE_CONNECTION 8221DC08
[1596] – unknown
[1596] Address info 822FAC18(0) 0.0.0.0:0->127.0.0.1:12080 added
[1596] TDI_MSG_CLOSE_CONNECTION 822FC518
[1596] – unknown
[1596] TDI_MSG_CLOSE_ADDRESS 82262B18
[1596] – unknown

Can you use the Processes tab of Task Manager to find out which process has the PID (process ID) value of 1596???

This column is not shown in Task Manager by default. Use the View → Select Columns option to enable it.

Thanks!
Vlk

It is the Outpost Firewall “outpost.exe”.

Hmm, this really looks like an Outpost problem… Outpost is reporting this:

[EEF94849] Bad MDL diagnostic 90: 1: 00040110-81654000-0003C09A-00000000 [81EA91B0]

which probably means it can’t let the data thru. Maybe they’re coming too fast? :-
Anyway, if I were you, I’d try to uninstall (and possibly reinstall) Outpost and see if it helps (I’d bet my hat it will :)).
Maybe a clean install will resolve the issue…

BTW I’m SHOCKED that Outpost is dumping so much info in its release build - not really a common (neat) programming practice… :-\ ;D

Cheers
Vlk

Hi Vlk,

here is the “DebugView” with Shudown of Outpost:
[1032] *OnEndOfRequest for http://www.mozilla.org/
[1032] No body sent so far, flushing all
[1032] *OnEndOfRequest - returning 134217730
[1032] *OnEndOfRequest for http://download.mozilla.org/?product=firefox&os=win&lang=en-US
[1032] No body sent so far, flushing all
[1032] *OnEndOfRequest - returning 134217730
[1032] *OnEndOfRequest for http://ftp-mozilla.netscape.com/pub/mozilla.org/firefox/releases/1.0/win32/en-US/Firefox%20Setup%201.0.exe
[1032] Calling g_pfnAavmCheckFile
[1032] Object clean
[1032] File opened OK
[1032] xfer buffer allocated
[1032] Writing rest of data - body
!dbg no buffer: EEF93290<-EEF94849 ebp:EE2299B0
[1032] Everything OK
[1032] Closing body file handle
[1032] *OnEndOfRequest - returning 134217730
[1032] *OnEndOfRequest for http://forum.avast.com/index.php?action=post;topic=11318.15;num_replies=22
[1032] Calling g_pfnAavmCheckFile
[1032] Object clean
[1032] File opened OK
[1032] xfer buffer allocated
[1032] Was check-encoded, sending the rest
[1032] Writing rest of data - body
[1032] Chunked encoded - writing last chunk
[1032] Everything OK
[1032] Closing body file handle
[1032] *OnEndOfRequest - returning 134217730

All Outpost processes are killed, all services are killed and still that error!! I am hardly considered to reinstall this things again, but I don’t really know if it would be the solution, what a mess ???

Sgt.Schumann and Vlk,

Please excuse my jumping in here, but Sgt.Schumann , you’re using a very old version of Outpost. That version was great for it’s day, but had quite a few weird problems. In fact, IIRC, one of them was disabling it didn’t really disable it.

I’d suggest upgrading to the new V2.5 version (it has a 30 free trial - then its pay up or give up :wink: ) and see if your download will work. Since you’re behind a router, if you feel safe enough you could “Exit and shutdown” Outpost and try the D/L. Just don’t forget to restart OP.

If your girlfriend isn’t using the same version of OP on her computer and she is getting the same problem, then I’m pretty sure that OP is not the problem.

NOTING THAT NEW POST MADE WHILE BABLING ABOVE

That extra info is another problem with the old Outpost.!

HTH

Again, Outpost was dumping this info

!dbg no buffer: EEF93290<-EEF94849 ebp:EE2299B0

(even though it should’ve been disabled). Well I’m guessing it’s Outpost in this case (but who else? Do you have any other filter installed?).

Clearly, Outpost interferes with the communication stream even though it’s turned off… not good for debugging :wink:

I did already “Exit and shutdown” in Outpost (since I am behind a router and I have nothing to “fear”) and the same problems still occur . There were no more outpost-task and no more servicea running, but I’am still having the same problems. So I suppose that Outpost is not the problem …
the next step could “to deinstall the Outpost Firewall completely”, but I do not want to do really that thing … and actually I don’t think that this is the problem (PLEASE correct me, if I am false!!!)

If the last debug dumps were captured with Outpost disabled, then yes, I still think Outpost is interfering with the HTTP traffic. Please see my previous post.

Even though you disable/kill all its processes, there’s still the kernel-driver active and it cannot be “killed” - it can only be uninstalled (or deleted/renamed, if you can find it - it’s a *.sys file).

Thanks
Vlk

Hi *,

seems like Outpost is the problem, even it is “shut down”, whatis quite strange in my eyes :frowning:

I’ll try out tomorrow evening again (if I will have hopefully the time), since it is now time to go to bed, and I should be in office tomorrow.

Thanks for your help today!!

Greetings
Sgt. Schumann

Good night, and thanks for your help. Hopefully we’ll find a solution. :slight_smile:
Cheers Vlk

Sgt.Schumann,

I agree with Vlk on this one completely. I’d uninstall that old version of OP, reboot and give it another try. I expect that it will work then.

I highly reccommend the latest OutPost Pro v2.5. I use it with Avast v4.6.603 with no problems (actually better than v4.5!) If you can’t flip the cash after 30 days, I’d suggest using some other free fire wall (sorry Agnitum :-[) since OP version 1.x just doesn’t cut it in my book these days.

Have a good night and better luck tomorrow!

Thank you all,

indeed the old Outpost version is the problem, even it is “shut down” and no more processes “seem” to run (thanks Vlk).

The bad guy is the “FILNTNT.SYS”. Apparently the kernel-driver.

When I rename this guy, I get an error message at startup, but when I “shutdown Ouptost” afterwards, the “download-problem” is not existing anymore. Nice to know!!

Thank you (especially Vlk)!!!

But still I have to now to consider to deinstall Outpost (WebShield enabled) or not (WebShield disabled)…

Well WebShield is a pretty standard network application so if your Outpost is having problems with this program, it may interfere with others as well… Hence, I’d probably recommend something else (there’s a number of nice free alternatives).

Thanks
Vlk

Thank you for your great support.

Tomorrow I will propably kill that Ouptost-Thing…

Gute Nacht :slight_smile:

Now I deinstalled Outpost from my machine.
No more errors occur with enabled WebShield. :slight_smile:

Since the need of a Personal-Firewall behind a router is indeed questionable, I will now do without a PFW.

Since the need of a Personal-Firewall behind a router is indeed questionable, I will now do without a PFW.

Unless your router provides outbound protection, I would suggest that you still need some form of protection.

What do you recommend?

Some backround information:
I am only using Mozilla and Firefox as browser.
Mozilla is also my mail-client.
IE is “disabled” cause I told him to use an non-existent proxy (localhost, port 4711).
I am sitting behind a router.
Outpost (now deinstalled) was only configurated for looking at outbound traffic (because of the router).

If you want it free, I’d suggest Kerio Personal Firewall http://www.kerio.com/kpf_home.html .
Not only that I know the folks that programmed it (they’re based over here in Pilsen) but it’s also quite stable fw IMHO…

Cheers
Vlk