BSODs: Please add your minidump files here(v3)

!ot!
The following software is incompatible with CIS

McAfee Personal Firewall Plus
Norton Personal Firewall
Outpost Firewall Pro
Trend Micro PC-cillin Internet Security
Sunbelt Personal Firewall
Sygate Personal Firewall
Tiny Desktop Firewall
Trend Micro Internet Security
Zone Alarm
Process Guard
Pro Security
System Safe Monitor
Dynamic Security Agent
Blue Coat K9 Web Protection

Snoopfree will be added.

**NOTE, the attached file is a minidump *.dmp file. i changed the file extension so i could attach it. Please change it back, cheers.

  1. Windows XP Home 32bit Service Pack 3.

  2. Avast 4.8 Free Home Edition, Spybot S&D 1.6.2, SnoopFree 1.0, Comodo Memory Firewal 1.0, Sandboxie 3.36.

  3. Comodo Internet Security 3.9, cmdguard.sys is the affected driver.

  4. Description of the problem: BSOD on boot, sometimes a quiet crash where no BSOD is present. ive ran the crash dump through Windows debugging tools and it points to cmdguard.sys as the culprit.

  5. Steps to reproduce? i just installed the most recent version of CIS. i also reinstalled with the same problems. :slight_smile:

  6. i dont have time to run gmer right now but im almost certain its not because of a rootkit. however ill run one later and ill update my post if i find one.

Please get back to me if it’s possible. O0

Thanks.

[attachment deleted by admin]

Hello Nightmare,

This is a confirmed conflict with Snoopfree, only solution is to uninstall one of the two.
Snoopfree assumes that all hooks are bad, and removes them causing CIS to BSOD.

If you run CIS 3.9 you no longer need the stand-alone Comodo Memory Firewall it’s build in CIS.

1.Windows Version/Bit and Service Packs - Win Vista 32bit SP 1
2.Your realtime Antivirus/version,Spyware remover/Version, other Security Software/Version - DrWeb for Windows ver 5.0.1.02160, CIS ver 3.9.95478.509
3.Affected Driver/Software and Version - dunno
4.Brief description of the problem
After surfing the internet for a while (“a while” can be up to half an hour) the system hangs up for a second or two, then bsod apears immidiatley. Bsod never appeared when not connected to internet.
5.Steps to reproduce the bug (if applicable) - no particular steps. More often BSOD appears when uTorrent is running
6.Gmer report (download) Only for 32bit platforms - attached

[attachment deleted by admin]

  1. XP 32 SP3
  2. CIS 3.9 (Firewall, D+, CAV)
  3. See Event Viewer attachment
  4. Crash/reboot at any time (has happened while uninstalling a program, surfing, or scanning with CAV)
  5. Unknown/seemingly random

Edit: New dump added. I was viewing a program’s access rights in D+ and cfp.exe crashed (not Windows). Also mailed to cpfbugs at comodo.com.

[attachment deleted by admin]

Hi… Is this is a new issue specific to v3.9 only? Because i am being able to install v3.5 without any problem, with no need to disable SnoopFree. Incidentally, i am unable to install v3.9 even after disabling Snoopfree service from admin> services.

My original post is here:
https://forums.comodo.com/install_setup_configuration_help/help_plz_v39_crashing_system_on_install_v35_installing_normally-t40564.0.html

I was surprised to know that SnoopFree installs a driver “snopfree.sys” that is important enough to be loaded even in the safe mode. I thought it was only meant to be a software to prevent unauthorized screen access. Thats the only warning messages it ever gives.

Edit: As the incomaptibility is with v3.9 only, is there any fundamental difference between how v3.5 installs and how the newer version does?

1.Windows Vista SP1
2.AVG Free v8.5.339, Comodo Firewall v3.9.95478.509
3.See below.
4.everytime i try to launch my game via browser, it crashes and give me a BSOD.
the game is “ijjiGunZ” which uses nprotect. im guessing its conflicting with nprotect and not gunz itself because other online games work fine. i am on ffox3, my av is off, so is my firewall
this is what came on screen.

Problem signature: Problem Event Name: BlueScreen OS Version: xxx Locale ID: xxx

Additional information about the problem:
BCCode: f4
BCP1: 00000003
BCP2: 8FB80020
BCP3: 8FB8016C
BCP4: 82684430
OS Version: xxx
Service Pack: 1_0
Product: xxx

Files that help describe the problem:
C:\Windows\Minidump\Mini030709-01.dmp
C:\Users\xxx\AppData\Local\Temp\WER-72634-0.sysdata.xml
C:\Users\xxx\AppData\Local\Temp\WER8870.tmp.versio n.txt

Read our privacy statement:
Search Microsoft.com

this is the minidump file:


http://dl.getdropbox.com/u/129686/Mini030709-01.dmp

5.Steps to reproduce the bug | by running the game.
6.

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-02 13:57:15
Windows 6.0.6001 Service Pack 1

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 8624B1F8

AttachedDevice \Driver\tdx \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

according to TSF, cmdguard.sys caused the problem…

my bsod report is now complete. gmer report is attached.

Gentlemen, I’ve got some news…

After uninstallation of CIS and removing inspect.sys everything was OK… For a short period…
BSOD problem reappeared after installing VirtualBox.
After some system examination and internet search I assumed that network adapter driver could be the problem (in device manager and Pcwizard it seemed to be Raltek rtl-8618)
. After updating the driver (in device manager it became Realtek PCIe GBE Family Controller) I xeperienced no problems. After reinstalling CIS I had no BSOD for about 3 hours. I tried to reproduce some steps that usually caused the system crash… No problems till now.
I will continue testing…

bsod (IRQL_NOT_LESS_OR_EQUAL ) caused by inspect.sys

  1. WinXP sp3 32 bit, core2duo
  2. Security Software: only CIS, Firewall enabled, D+ disbled, antivirus doesn’t installed
  3. CIS 3.9.9.95478.509 and earlier
  4. when installing or uninstalling VMware Workstation (different builds, for example VMware-workstation-6.5.2-156735.exe) in stage “Network drivers…”
  5. Install vmware workst., then when CIS is running, begin uninstalling of this product

[attachment deleted by admin]

XP PRO x64 (fully updated)
IOBit Advanced SystemCare PRO (resident in memory)
G Data Internet Security (only antivirus on demand, firewall, AV,… all is disabled but processes are visible in the task)

included : 23 crash dumps ! ??? :-\

[attachment deleted by admin]

previous dumps : downloaded 0 times ??

new ones, from today :

please tell me what’s wrong and what i/you can do about it !

[attachment deleted by admin]

My problems continue also, but no more Windows crashes. A reboot gets me going again but this is not normal, I had no problem with 3.9 RC2.

Previous posts:
https://forums.comodo.com/install_setup_configuration_help/cmdagentexe_causing_problems-t40435.0.html
https://forums.comodo.com/bug_report_cis/bsods_please_add_your_minidump_files_here-t26981.0.html;msg294311#msg294311

Can anyone help, please?

still 0 download… nobody investigate minidumps posted in the forum?

btw why when Comodo crash, minidumps are sended by email (outlook or email client) not like suspicious files samples by direct connection?

Normally they do quite fast, maybe yours is already fixed for the next version… I’m not sure…

For the crash report, that will be because when it was build like that for version 3.0.x of CFP… and the underlying processes for submit suspicious files has crashed… so it can’t be used.

ok that’s what i thought…

i’m still waiting an answer of a developper to tell me what is wrong with those dumps :

  1. Vista Ultimate 32bit no SPs
  2. Eset NOD32 3.0.261, Spybot 1.6.2
  3. Vista self is affected
  4. Install CIS 3.9.95478.909 was successfull, after restart came STOP c21a. In protected mode it
    comes not, but CIS does not start. The diagnosis can not help. The same problem was in february
    2009 with CIS 3.8.65951.477. The last good CIS was 3.5.57173.439.
  5. Every restart, WER- or MINIDUMP-files will not be created.
  6. Gmer report will be attached (but how to do?).

P.S.: I´ve uninstalled CIS 3.9.95478.909 and reinstalled without Defense+ in the last minutes and the result is: no BSOD! I think, Defense+ was the reason for BSOD.

[attachment deleted by admin]

more dumps…

why no words from the support ?

[attachment deleted by admin]

  1. Vista 64bit
  2. CIS latest Version 3.9.95478.509 (D+ temporally disabled, Network costum policiy, AV highest level)
  3. inspect.sys
  4. 0x000000D1, BSOD IRQ not less or equal.
  5. Not able to reproduce, happens when i couldn’t need it.

Uses Vista for 1 week now and regulary gets BSOD with inspect.sys as noted file.

[attachment deleted by admin]

  1. Win XP SP3 32 bit with updates
  2. CIS 3.9.95478.509 (Firewall only), Avast Home 4.8 (p2p shield disabled), NetLimiter 2.0.10.1 Pro (Firewall disabled)
  3. tcpip.sys
  4. I have patched version of tcpip.sys for increasing limit of half-open connections. I usually get BSOD after some time of working uTorrent or other p2p program (probably when limit exceeded). It points to tcpip.sys and sometimes writes “PAGE_FAULT_IN_NONPAGED_AREA” (but not always). WinDbg shows that problem “Probably caused by : cmdhlp.sys ( cmdhlp+190d )”
  5. I’ve tried to change limit from 100 to 200 - same result.

P.S. Sorry for my English

[attachment deleted by admin]