Thu, Jan 23, 4:30 PM CST

Renderosity Forums / Poser - OFFICIAL



Welcome to the Poser - OFFICIAL Forum

Forum Coordinators: RedPhantom

Poser - OFFICIAL F.A.Q (Last Updated: 2025 Jan 22 9:27 pm)



Subject: My McAfee Firewall caught my Poser 4.0.3 trying to access the internet


Anthony Appleyard ( ) posted Fri, 19 September 2003 at 5:51 PM · edited Thu, 23 January 2025 at 10:28 AM

I have Poser 4.0.3 without PPP. I have just bought and installed McAfee Viruscan and McAfee Firewall. After that, calling my Poser causes every time a firewall warning that ....Poser.exe tried to access the internet. What's happening? My McAfee Viruscan says that my Poser.exe is not infected.


Crescent ( ) posted Fri, 19 September 2003 at 5:59 PM

It's another "feature" of Poser. It's just trying to make sure that there aren't any other copies of Poser with the same s/n running on your local network. Just tell McAfee to stop the request and not give you pop-ups in the future. Poser will still run properly. Cheers!


MachineClaw ( ) posted Fri, 19 September 2003 at 5:59 PM

Poser is trying to check the network for another instance of Poser to verify that it is legal. It's normal. On a network you can only have legal versions running at the same time, so if you had 1 copy of poser runing on 2 computers on a network, Poser goes and checks to see if it is the same version, if it is poser will shutdown and only allow 1 to be running at the same time, if it's a different serial then poser checks and verifys and lets you run both. Its a normal thing with Poser don't be scared. just set McAfee to allow Poser.exe to do it's thing and the messege will not appear again.


OneShot ( ) posted Fri, 19 September 2003 at 6:04 PM

No this is a built in pirate scheme for PPP. It is actual trying to look on your network to see if you are running more than one license on several machines. Since Poser 4 is on a dual booting disk I've installed it on both my Mac and PC. I'm 95% Mac but for those 5% of Poser file that won't load correctly at 1st on the Mac I use the PC. If I try to have both Posers running at the same time I'll get a warning saying you running the same license on two computers. It's not sending information back to CL. Hope this helps.


Nance ( ) posted Fri, 19 September 2003 at 9:55 PM

I thought that one of the last P4 patches eliminated the net checking 'feature'. Not so?


CODY ( ) posted Fri, 19 September 2003 at 11:54 PM

file_76862.jpg

Well I gotta disagree....... It aint' alright!!! Because when Poser tries to "get out"...Thats when the DistributedCOM services thing...starts "listing"!!!!! I've deleted the file but to no avail!!! It only does it once in great blue moon. I just feel that it's wrong!!!


lmckenzie ( ) posted Sat, 20 September 2003 at 7:00 AM

Cody, If you want to disable DCOM, here's the info from MS. Beware, some things may stop working but you can always reenable DCOM. "You can disable DCOM through Dcomcnfg.exe or Component Services: Using Dcomcnfg.exe, follow these steps: From the Windows Start menu, click Run, type Dcomcnfg.exe, and then click OK. On the Default Properties tab, clear the Enable Distributed COM on this computer check box. Using Component Services, follow these steps: From the Windows Start menu, point to Programs, point to Administrative Tools, and click Component Services. Click to expand the Component Services and Computers nodes. Right-click My Computer, and then click Properties. On the Default Properties tab, clear the Enable Distributed COM on this computer check box." If you're using Win98, you'll have to download Dcomcnfg.exe from MS.

"Democracy is a pathetic belief in the collective wisdom of individual ignorance." - H. L. Mencken


randym77 ( ) posted Sat, 20 September 2003 at 10:00 AM

Interesting. I always wondered what that was about. I thought it had something to do with Content Paradise. I've set Zone Alarm to automatically block both PP and P5 from accessing the net, and everything works just fine.


layingback ( ) posted Sat, 20 September 2003 at 1:04 PM

Yep. In ZA, allow Poser 4/PP access to the local network (for it's declared looking-for-copy-of-itself routine), but to Ask for access to the Internet - and guess what? It tries to access the Internet! P5 SR3 - with Content Paradise DISABLED entirely (it's not even loaded) - does exactly the same thing... Really these days the rational policy is to prohibit all apps whose primary function is not comm related from accessing the Internet, and then enable only after you notice non-functioning features. You have to assume that apps are more likely to call home than not. And the problem is the only reliable way to discover what they are trying to send is with a packet sniffer - which means you have to let it send it first to find out!


stewer ( ) posted Sat, 20 September 2003 at 2:37 PM

and guess what? It tries to access the Internet! What address?


CODY ( ) posted Sat, 20 September 2003 at 5:06 PM

Imckenzie....As long ZA say's it's being blocked I'm comfortable with that,More-so than I am turning it off. I also run SPYBOT-search and destroy,,,I went looking last nite to see if it showed up, But it doesn't find it even when ZA shows it running and you scan the system with SPYBOT. As a side note...I noticed a 100% improvment in stability when on-line with SPYBOT...I've tried all the other firewalls and such,,,But being on a dial-up(YES STILL!!!) I became upset with constant D/L'd upgrades in the middle of down-loading files!! And knock on wood...in the 3 years I've used ZA, Only once has it ever blocked a "Virus filled E-mail"...and that was from somebody I knew... :-(.....


layingback ( ) posted Sat, 20 September 2003 at 7:38 PM

stewer, OK, I see what's happening. It accesses the local network and sends requests on Port 11423. And then it opens a Listening port on 11423. ZA correctly identifies the outgoing as a local network access. But the listening as it's to all URL addresses (.) not just limited to the loacl network, gets classified as Internet Access I assume. So it's not anything to be alarmed about - other than its sets off alarms! Re the DCOM removal instructions above: Steve Gibson at www.grc.com has The DCOMbobulator to do this. It'll run a test, and disable / re-enable DCOm on a click of a button. Small program (29KB), no install, just run it. Most significantly it'll also test whether M$ patch worked or not if you've installed it. Includes full instructions.


CODY ( ) posted Sat, 20 September 2003 at 7:51 PM

THERE YA GO............... Simply annoying..... It's just one of those things that should'nt be happin'!!!


lmckenzie ( ) posted Sun, 21 September 2003 at 7:56 AM

Yes, I'm on dial-up as well. I use SpyBoy and AdAware both. DCOM is a Windows service so it's not going to sho up on a SpyBot scan. It's necessary for some software to run. If your system runs fine with it blocked or disabled, that's what I'd do. I just read an article that says some Creative SoundBlaster and other hardawre setups has installed adware so you can't really trust anyone these days. Fortunately, CL hasn't sunk that low - yet...

"Democracy is a pathetic belief in the collective wisdom of individual ignorance." - H. L. Mencken


Jim Burton ( ) posted Sun, 21 September 2003 at 10:35 AM

Anthony- As you probably already know, you can click on the buttons that say "don't allow it" and "I know about this program" and McAfee will not let it try to connect any more- that is what I did. Did it for Poser 5, too.


DarkMatter_ ( ) posted Sun, 21 September 2003 at 2:22 PM

It's just s[y ware programmed in the Curious Labs updater, the METACREATINS updater never had the spyware and it did all the same things the curious labs updater does, If you don't like it you can ask around to see if anyone knows where you can still get the metacreations patch.


DarkMatter_ ( ) posted Sun, 21 September 2003 at 2:35 PM

I went back to the metacreations patch because I still have it on cdrom, Now I can run poser on my work computer without the little spy kicking my ip ass.


DarkMatter_ ( ) posted Sun, 21 September 2003 at 2:38 PM

You must have upgraded recently with curiouslabs patch that has all the spy ware in it, That searches the internet for other copys of the poser cd install on your system, If there is another instance of poser 4 having been run from another ip address the spyware will shut you down and poser will not open again, I installed my poser 4 at work as well as home and that little curiouslabs spy shut me down at both locations, I had to contact curious labs for help or use poser reinstalled offline, After using soap a file cleaner to remove the spy registration file from my computer. I like the Metacreations version much more better.


DarkMatter_ ( ) posted Sun, 21 September 2003 at 2:48 PM

But see no One will tell you this because it's a no no to tell you that you can circumvent curious labs security measures programmed into thier patch.


Norbert ( ) posted Mon, 22 September 2003 at 2:09 AM

Yeah.. That's a lot worse than selling an unfinished computer program to thousands of people, just because you need the money. There's somthing real effin' hypocritical in all of this. (From CL, that is..)


Privacy Notice

This site uses cookies to deliver the best experience. Our own cookies make user accounts and other features possible. Third-party cookies are used to display relevant ads and to analyze how Renderosity is used. By using our site, you acknowledge that you have read and understood our Terms of Service, including our Cookie Policy and our Privacy Policy.