Welcome, Guest. Please login or register.
November 08, 2009, 02:07:57 PM

Login with username, password and session length

333367 Posts
36850 Topics
83510 Members

Latest Member: zsozso

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Install / Setup / Configuration Help
| | | | |-+  PC won't boot after update
« previous next »
Pages: [1] Go Down Print
Author Topic: PC won't boot after update  (Read 308 times)
dunkers
Newbie
*
Offline Offline

Posts: 14


« on: July 04, 2009, 05:38:57 AM »

This morning CIS says there's an update and do I want to go for it, so like I fool I say OK and off we go. One reboot later the PC is borked big time and the only way I can get in is to run in safe mode. A lot of messing about later I've manually disabled enough of CIS that I can get to the desktop in normal mode.

Similar thing happened here previously:

Crash on boot

The culprit there was D+, which I've resolved by having that disabled. I checked CIS after the update and it was still disabled. I can run CIS now (after disabling all CIS context menus, services, etc) and it is still disabled. Nevertheless, if I allow CIS to come up at boot the PC spontaneously reboots around the time that CIS would appear in the task tray.

CIS says it is 3.10.102194.530
Windows is XPPro SP2
Logged
dunkers
Newbie
*
Offline Offline

Posts: 14


« Reply #1 on: July 04, 2009, 05:45:00 AM »

Oops. Sorry for the bad link to a different thread.

Essentially, when my PC gets to the deskstop and starts to populate the tasktray, the screen goes black and the PC has rebooted to the BIOS. No warning, no pause, just instant reboot. In my original post, which I can't find right now, I traced this to D+ and found that if that was disabled the rest of CIS would work OK, which is how I've been running it ever since. Now I've done the upgrade I get the same problem (i.e. instant no warning reboot) even though D+ is still allegedly disabled.

Any chance of being able to downgrade back to the previous version?
Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 780



« Reply #2 on: July 04, 2009, 05:46:59 AM »

do you have any other security software running?
Logged

http://www.youtube.com/languy99

Software Reviews For All
dunkers
Newbie
*
Offline Offline

Posts: 14


« Reply #3 on: July 04, 2009, 06:00:05 AM »

Not AV. I do have these:

Process Explorer: http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
Security Task Manager: http://www.neuber.com/taskmanager/
Logged
dunkers
Newbie
*
Offline Offline

Posts: 14


« Reply #4 on: July 06, 2009, 09:30:44 AM »

So, is it possible to downgrade? I really need to have some AV working.
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 4156



« Reply #5 on: July 06, 2009, 04:47:35 PM »

Try the following clean install procedure:
Start with exporting your configuration to a folder that is not part of the Comodo folder under Program Files. This way you can restore your configuration after the reinstall.

Quote
Uninstall CIS and reboot. Then run Comodo System Cleaner to get rid off registry keys.

Then delete the Comodo folders under Program Files, Program Files\Common Files, C:\Documents and Settings\All Users\Application Data\ .
For Vista/Win7
Users\%username%\appdata\local\,  Users\%username%\appdata\roaming\  and  \Users\%username%\appdata\local\virtual store

To be even more thorough open Device Manager and set it to show hidden devices under menu option View. Then see if there are Comodo driver(s) left in non Plug and Play drivers. If so select the driver --> click right --> uninstall and reboot.

Now delete the following:
     C:\boot.ini.comodofirewall (this file may not exist). 
          WARNING: Do not mistakenly remove the original “boot.ini”.
     C:\WINDOWS\system32\drivers\cmdGuard.sys
     C:\WINDOWS\system32\drivers\cmdhlp.sys
     C:\WINDOWS\system32\drivers\inspect.sys
     C:\WINDOWS\system32\guard32.dl


 a.  HKEY_CURRENT_USER\Software\ComodoGroup\CFP and HKEY_CURRENT_USER\Software\ComodoGroup\Comodo Internet Security
    b.  HKEY_LOCAL_MACHINE\SOFTWARE\ComodoGroup\CDI\1 *
         *(If you have other Comodo products installed, delete only the values
           for CFP)
    c.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
         \cmdAgent
    d.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
         \cmdGuard
    e.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdHlp
    f.   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Inspect
    g.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services
         \cmdAgent
    h.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services
         \cmdGuard
    i.   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdHlp
    j.   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Inspect
    k.  KEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services
         \cmdAgent
    l.   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services
         \cmdGuard
   m.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cmdHlp
    n.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Inspect
    o.  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdAgent
    p.  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdGuard
    q.  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdHlp
    r.   HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
          \Inspect
    s.  HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro
    t.   HKEY_USERS\S-1-5-21-1202660629-746137067-2145843811-1003\Software\ComodoGroup\CFP
    u.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDAGENT *
    v.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDGUARD *
   w.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDHLP *
    x.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INSPECT *
    y.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDAGENT *
    z.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDGUARD *
  aa.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDHLP *
  bb.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INSPECT *
  cc.   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CMDAGENT *
  dd.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CMDGUARD *
  ee.  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CMDHLP *
   ff.   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_INSPECT *
  gg.  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDAGENT *
  hh.  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDGUARD *
    ii.  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDHLP *
   jj.   HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INSPECT *
  kk.  HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\CFP_Setup_3.0.14.276_XP_Vista_x32
    ll.  HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\CFP_Setup_3.0.14.276_XP_Vista_x64
mm.  HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\CFPLog
 nn.  HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\CPFFileSubmission
 oo.  HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro

*Note: It may not be possible to remove these "LEGACY" keys.  If you cannot delete them, leave them in the registry.  However, I have subsequently found that you MAY be able to remove these keys in Safe Mode by using a third-party registry tool.  To permanently remove them may also require modifying the Permissions for each key.  See: http://forums.comodo.com/help_for_v3/comprehensive_instructions_for_completely_removing_comodo_firewall_pro_info-t17220.0.html;msg119226#msg119226

Now you should be good to go
Logged

Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
dunkers
Newbie
*
Offline Offline

Posts: 14


« Reply #6 on: July 07, 2009, 11:41:11 AM »

Thanks for the instructions. However, I'm a bit concerned about running the cleaner because it picks up 2571 errors. To pick an item at random that I can check, it warns about:

 File Extentions -> HKEY_CLASSES_ROOT\.a52

The a52 extension is set by VLC (the open source video player) and on checking the actual registry key there is nothing obviously wrong:

Code:
[HKEY_CLASSES_ROOT\.a52]

[HKEY_CLASSES_ROOT\.a52\shell]

[HKEY_CLASSES_ROOT\.a52\shell\AddToPlaylistVLC]
[at]="Add to VLC media player's Playlist"

[HKEY_CLASSES_ROOT\.a52\shell\AddToPlaylistVLC\command]
[at]="E:\\Video\\VideoLAN\\vlc.exe --started-from-file --playlist-enqueue \"%1\""

[HKEY_CLASSES_ROOT\.a52\shell\PlayWithVLC]
[at]="Play with VLC media player"

[HKEY_CLASSES_ROOT\.a52\shell\PlayWithVLC\command]
[at]="E:\\Video\\VideoLAN\\vlc.exe --started-from-file --no-playlist-enqueue \"%1\""

If I create a file - test.a52 - it has the VLC icon attached, and if I right click it then select 'Open with...' it correctly shows VLC as the recommended program.

Is there somewhere that the cleaner will tell me why it thinks this key has an error? And if I select 'clean' what will it do - clean whatever error is there or delete this key? As you might imagine, I'm loath to either let the cleaner vape all this stuff or go through each of the 2571 errors to determine if it's valid or not.
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 4156



« Reply #7 on: July 07, 2009, 12:03:04 PM »

I don't know why the scanner flags the VLC entries; it looks like a false positive to me.

You can untick the entries that are linked to VLC so the cleaner won't delete them. In case you would delete the VLC entries you can restore them by running the VLC installer again or manually restoring the file association under Control Panel --> Folder options (when on XP).

Comodo System Cleaner also will make a back up by default and also has Registry Protection. Read the help file to learn about the latter.

When you still feel unsure about using the cleaner you can skip using it and follow the manual procedure.
Logged

Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.043 seconds with 20 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com