Welcome, Guest. Please login or register.
December 24, 2009, 07:30:45 PM

Login with username, password and session length

345020 Posts
38087 Topics
86494 Members

Latest Member: rayko

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Anti Virus Help
| | | | |-+  Is antivirus stopping itself?
« previous next »
Pages: 1 [2] Go Down Print
Author Topic: Is antivirus stopping itself?  (Read 801 times)
EricJH
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 4261



« Reply #15 on: July 15, 2009, 04:35:00 PM »

The only thing I can think of right now is to do a clean install. Uninstall CIS, reboot and continue with the following tutorial:
Start with exporting your configuration to a folder that is not part of the Comodo folder under Program Files. This way you can restore your configuration after the reinstall.

Quote
Uninstall CIS and reboot. Then run Comodo System Cleaner to get rid off registry keys.

Then delete the Comodo folders under Program Files, Program Files\Common Files, C:\Documents and Settings\All Users\Application Data\ .
For Vista/Win7
Users\%username%\appdata\local\,  Users\%username%\appdata\roaming\  and  \Users\%username%\appdata\local\virtual store

To be even more thorough open Device Manager and set it to show hidden devices under menu option View. Then see if there are Comodo driver(s) left in non Plug and Play drivers. If so select the driver --> click right --> uninstall and reboot.

Now delete the following:
     C:\boot.ini.comodofirewall (this file may not exist). 
          WARNING: Do not mistakenly remove the original “boot.ini”.
     C:\WINDOWS\system32\drivers\cmdGuard.sys
     C:\WINDOWS\system32\drivers\cmdhlp.sys
     C:\WINDOWS\system32\drivers\inspect.sys
     C:\WINDOWS\system32\guard32.dl


 a.  HKEY_CURRENT_USER\Software\ComodoGroup\CFP and HKEY_CURRENT_USER\Software\ComodoGroup\Comodo Internet Security
    b.  HKEY_LOCAL_MACHINE\SOFTWARE\ComodoGroup\CDI\1 *
         *(If you have other Comodo products installed, delete only the values
           for CFP)
    c.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
         \cmdAgent
    d.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
         \cmdGuard
    e.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdHlp
    f.   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Inspect
    g.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services
         \cmdAgent
    h.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services
         \cmdGuard
    i.   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdHlp
    j.   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Inspect
    k.  KEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services
         \cmdAgent
    l.   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services
         \cmdGuard
   m.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cmdHlp
    n.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Inspect
    o.  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdAgent
    p.  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdGuard
    q.  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdHlp
    r.   HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
          \Inspect
    s.  HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro
    t.   HKEY_USERS\S-1-5-21-1202660629-746137067-2145843811-1003\Software\ComodoGroup\CFP
    u.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDAGENT *
    v.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDGUARD *
   w.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDHLP *
    x.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INSPECT *
    y.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDAGENT *
    z.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDGUARD *
  aa.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDHLP *
  bb.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INSPECT *
  cc.   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CMDAGENT *
  dd.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CMDGUARD *
  ee.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CMDHLP *
   ff.   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_INSPECT *
  gg.  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDAGENT *
  hh.  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDGUARD *
    ii.  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDHLP *
   jj.   HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INSPECT *
  kk.  HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\CFP_Setup_3.0.14.276_XP_Vista_x32
    ll.  HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\CFP_Setup_3.0.14.276_XP_Vista_x64
mm.  HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\CFPLog
 nn.  HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\CPFFileSubmission
 oo.  HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro

*Note: It may not be possible to remove these "LEGACY" keys.  If you cannot delete them, leave them in the registry.  However, I have subsequently found that you MAY be able to remove these keys in Safe Mode by using a third-party registry tool.  To permanently remove them may also require modifying the Permissions for each key.  See: http://forums.comodo.com/help_for_v3/comprehensive_instructions_for_completely_removing_comodo_firewall_pro_info-t17220.0.html;msg119226#msg119226

Now you should be good to go
Logged

Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
DLBarron
Comodo Member
**
Offline Offline

Posts: 36


« Reply #16 on: July 18, 2009, 07:32:21 AM »

I went through Eric's steps a couple of days ago, so far everything looks fine.
Most of the steps were not needed, the uninstall process seems to clean just about everything out, which impresses me.  A lot of uninstalls (dare I say, most uninstalls) leave little bits here and there which I find irritating.
Logged
Tags:
Pages: 1 [2] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.039 seconds with 19 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com