BSOD WIN 8.1U1 0xc000021 [M953]

Hey SilentMusic7 / Devs

With 7.0.317799.4142:

On my machine Win8.1 U1 fresh install no windows updates, RPC error, blue screen etc. can’t log into windows and can’t be removed, had to reinstall windows.

With all windows updates installed, same thing, RPC error, blue screen, etc and had to reinstall windows again :frowning:

(Hate mcafee, want comodo back)

P.S. the same happens with Comodo Anti-Virus for Servers on Windows Server 2012 R2 U1.

Did you install CIS on your Win8.1 U1 machine (or just the FW)?

The following bug report suggests a problem when website filtering is enabled:
https://forums.comodo.com/format-verified-issue-reports-cis/cmdagentexe-process-suspends-and-freeze-computer-m885-t103976.0.html

Do you have the energy to try a re-install with website filtering disabled before the first reboot after installation?

Also, historically, Defense+ has the most incompatibility with Windows Updates. Is it possible to disable HIPS and every option under Behavior Blocker under Advanced Settings before the first reboot after installation?

Installed full CIS - FW, AV, Defense+, Hips
Website Filtering off

Might try testing again without Defense/Hips/BehaveBlock next weekend.

Hi sjc2309,

just to clear things up a bit:

Defense+ indeed IS Comodo’s HIPS module.

Behaviour Blocker (including the option of using Viruscope) and Sandbox are separate, additional layers of security.

Kind regards, REBOL.

wasgij6’s system in his signature: “Win 8.1 Pro (x64) | UAC Disabled | CFW 7.0.317799.4142 | Intel i7 4770k | Asus Maximus VI Formula Mobo | Asus GeForce GTX 780 | G.Skill TridentX 16gb RAM | Samsung 840 SSD”

It’s helpful to know that some Win8.1U1 users are not seeing this problem with all components of Defense+.

Since it is not a processor issue, it could be the BIOS, video card or some 3rd-party software driver. Maybe it would be helpful if forum members running Win8.1U1 list these types of details – even if they are not experiencing the blue screen issue. This could help the developers narrow down the problem so they can reproduce it.

Dch48’s signature: “Avatar FX6327X Desktop, AMD FX-6300 6 core CPU, [AMD] Sapphire R9-270X GPU, Windows 8.1 64 bit, IE11 & Outlook 2007, Comodo Internet Security 7.0 full package, MBAM on Demand”

To cover all possibilities, users may want to report MOBO vendor, BIOS vendor, GPU vendor & model, CPU vendor & model, SATA controller, SATA driver version (such as Intel RST version), Windows 32-bit or 64-bit, and confirm that you are using Windows 8.1 Update (Update 1).

On July 4, just purchased HP 17 Touch Intel 7 with 8.1 64 pre-installed and downloaded updated version of CIS and bought new license. Installed CIS, Geek, cCloud and Backup (plus a folder COMMON). Within 2 minutes first lock up and BSOD with error message "DPC_WATCHDOG_VIOLATION. This is a brand new machine, loaded with 8.1 and updated through WinUpdate, with a brand new CIS. Apparently no solution has been arrived at6 because all of these posts are APRIL. It is now July. I tried to Win Uninstall, IOBit Uninstall, Manually deleting folder and then remaining files plus the COMMON folder. Nothing helps. I cannot keep the laptop up for more than a minute or two before BSOD no matter what I am doing. PC came with 6 mo. McAfee but uninstalled it. Have had no trouble with CIS on my HP 17 Pavilion Win 7 Pro 64 laptop until the laptop blew up. Fortunately have key b/u files to transfervia 128 Gb USB 3.0 stick. But figure to do it one bit at a time. But can’t now. Help. Any move on a fix since April. If so, why isn’t it in current CIS release?

As the error code you are receiving is different it is likely that this is not caused by the same error as that reported in this bug report. Please create a new topic in the main bug reporting section. That way I can better try to understand what may be causing this, and either make suggestions for fixing it or help you to create a formatted bug report.

Thanks.

This report states that it happens (only) on AMD systems, however that’s incomplete. It happens on Intel systems as well. Thus, it might not be dependent of processor. (some users that replied did confirm it)
Please be warry that the report states Windows 8.1u1 and not Windows 8.1. :slight_smile:
It is also unlear if this issue/bug occurs on x86 since tests are done on x64.

Actually, this is quite urgent priority bug report. Just some thoughts.

Additional information :

  1. CIS installation ran without problems. CIS drivers are (maybe) not loaded.
  2. Disabled all modules/features just to eliminate some posibilites. After that, Restart computer system.
  3. BSOD/Crash occurs with automatic restart. (Check attachment- “First Crash.zip”)
  4. After restart, Everything seems OK. Diagnostics did not find any errors. (Attached in “First Crash.zip” in attachment)
    note:: modules/features are still disabled.
  5. Attempt a manual restart just for ‘fixed status’ confirmation.
  6. Run CIS from tray icon. A message appears “COMODO Security Agent could not be started. Would you like to run diagnostics tool to fix this error?”. (Check attachment- “error message 1.png”)
  7. Select “Yes”. Another error pops up:“Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.” Press "OK. BSOD again (while doing diagnostics). After restart, Everything seems OK. (Check attachment- “Second Crash.zip”)

OK then. Perhaps, we can conclude : After each BSOD, Everything is OK. Maybe cmdguard.sys fails to load and it’s OK.

A bit deeper now,

  1. Go to : C:\Windows\System32\drivers and rename cmdguard.sys & Restart computer system.
  2. BSOD stopped (even after multiple restarts).

Issue seems to be related to cmdguard.sys :slight_smile:

[attachment deleted by admin]

Work-around / Additional Information,

Just install CIS and switch to “Proactive Security”. No more crashes.
Note: Switching back to default configuration will restore this issue.

That’s all.

qmarius, thank you. I have linked this additional information in the tracker.

Hi
I’m a member of COMODO, could you please supply the dump file of the BSOD? Many thanks.

Hi xuhongmei,

Complete memory dump : here.

Thank you.

This my friends, is what we call not taking the time to properly do your job. Did you launch a game? Did you try to type something? Did you invoke the GPU or graphics driver at all? After each restart, did you browse the internet until it crashed 10 mins later?? I don’t think so…

Just when you think it’s fixed, it’s only a matter of time before it BSODs again…

False. Crashes still no matter which configuration one selects.

ohh just an update: my free licence for Bitdefender expired so I’m back to dealing with this.

I had almost forgot what it was like to BSOD 88)

It’s been months, and you mean to tell me NOBODY fixed this? :-TD :-TD :-TD

I exited running applications and waited without doing anything. Does not seem like a conflict with any other driver/application.

Actually, it did stop in my case.

Hi qmarius,

There are some guard.dll files(in the attachment) you could replace the file in your computer, rename the guard64.dll file in your computer first, the location of guard64.dll is “C:\Windows\System32”, and reboot after this operation. Please use the guard64.dll one by one, , until it could work. Many thanks. Hope it could help.

And could you please send me the file version of ntdll.dll in folder system32? Right click the ntdll.dll->Properties->Details-> File version

Thank you very much

[attachment deleted by admin]

Hi guys,

Anyone having stable reproduction can try it and let us know the results asap, thanks.

Regards
Haibo

I’m not using Windows 8.1u1 anymore. Sorry, it was just a test phase.

If it helps,

  1. DVD SHA1 : 4652dc6ebfebe02c6a63e167c36e3faedfb93999
  2. Latest updates (important+optional) at the moment I posted the message. 27-07-2014, 18:34:42
  3. I installed CIS after updates+drivers. This is important.
  4. I used Microsoft Toolkit 2.5.2 activation methods just for some tests. This might cause the conflict (?).
  5. Acer Aspire V3-771G. Drivers here.

I have this issue too. I recently upgraded from 8 to 8.1U1 and got BSOD after restart. I assumed the Windows upgrade went wrong so I then completely formatted my PC and installed a clean copy of 8.1U1, installed all updates, installed a few programs and Comodo Firewall, and got more BSODs. Once I uninstalled Comodo, BSODs went away. I’m also waiting for Comodo to fix this issue before I can install it on my system again.

It’s kind of worrisome that this ticket was opened 4 months ago and hasn’t been fixed. Has Comodo been able to reproduce this problem? Do you need more information?