cmdguard.sys probably causes BSOD when /3gb option is used
The bug/issue
- What you did: i set up in boot.ini options “/3GB /userva=2900 /PAE” , i got BSOD and then analyzed minidump file
with kdfe - it claimed probably caused by cmdguard.sys - What actually happened or you actually saw: windows boots , and on a black screen the mouse pointer appears for a few seconds and then there is a blue screen of death
- What you expected to happen or see: i expected to boot windows normally
- How you tried to fix it & what happened: removed /3bg option and windows booted normally
- If its an application compatibility problem have you tried the application fixes here?: Na
- Details & exact version of any application (execpt CIS) involved with download link: csrss.exe was involved in minidump information
- Whether you can make the problem happen again, and if so exact steps to make it happen: write in boot ini /3bg option
- Any other information (eg your guess regarding the cause, with reasons): NA
Files appended. (Please zip unless screenshots).
- Screenshots illustrating the bug:
- Screenshots of related CIS event logs and the Defense+ Active Processes List:
- A CIS config report or file.
- Crash or freeze dump file:
Your set-up
- CIS version, AV database version & configuration used:5.3.176757.1236, vdb 7481
- a) Have you updated (without uninstall) from CIS 3 or 4: yes
b) if so, have you tried a clean reinstall (without losing settings - if not please do)?: no - a) Have you imported a config from a previous version of CIS: no
b) if so, have U tried a standard config (without losing settings - if not please do)?: no - Have you made any other major changes to the default config? (eg ticked ‘block all unknown requests’, other egs here.): no
- Defense+, Sandbox, Firewall & AV security levels: D+=safe mode , Sandbox= off, Firewall = safe mode, AV = stateful
- OS version, service pack, number of bits, UAC setting, & account type: windopws xp sp3 32, bit , (build 2600.xpsp_sp3_gdr.100427-1636 : service pack 3) , administrator (user is member of administrators), (only account user (in group of administrators) has right to lock pages in memory for awe and /3gb option)
- Other security and utility software installed: no
- Virtual machine used (Please do NOT use Virtual box): no
[attachment deleted by admin]