Comodo Firewall Pro 2.4.13.153 RC3 Released

Hi Messias

You should find the dump in the \WINDOWS\minidump directory. You might also find an entry in the System Event Log stating where it put the dump.

CFP has produced a warning message when “Exit” is selected from the systray menu for some time and as far as I’m aware, it is not necessary to stop/start cmdagent.exe on installation or at any time for that matter. I’m not sure why you would want to do this.

In addition, CFP 2.4 beta has been specifically “hardened” to prevent a non-user initiated termination. Previously, CFP was (in theory) vulnerable to being terminated by simulated mouse clicks, it no longer is.

I searched for the dumpfile with the search option in Windows. I selected the options to search in all maps (included those windows hides) and found no dumpfile. I then looked for WINDOWS\Minidump directory, but it contained nothing. I then searched for an entry in System Event Log but again found nothing

I got the same bsod with a different stop code but i don’t find a dump file to send.keep searching too.bye

If you don’t have an entry in the System Event Log, then this implies that the Save Dump (SAVEDUMP.EXE) process did not run on start-up & this is not a good sign for a DMP file being generated.

The most common reason that I know of for failing to produce a dump (aside from the BSOD just not producing one), is by not having a PageFile on the C drive (even if it is a small PageFile). Windows needs the C drive PageFile to save the dump to initially (W2k/XP only, not sure about Vista). However, if this was the reason, then you would never produce a dump.

I’ve had other BSOD’s as well. You can see another STOPcode if you look a bit earlier in this forum. I’ve had these since version 2.4.10.131. I guess the changed something that works on most computers, but not on my laptop. But I’ll keep on testing every new release they bring out and keep on giving feedback, until the program works like it is supposed to work

Not a bugreport I know but your Firewall save my machine today.

Today I get after boot up at 1. a warning from McAfee that something try a bufferoverflow on the systemprocess. The strange thing on this alert was, that Mcafee Virusscann didn´t say more.
Only that it was happen, but not which programm make this. Hm…silly I´m was when I think ok, maybe firewall…its beta…who knows…but than I start Iexplorer and than cfp alert me that the programms signatur was changed since last start. :o

Now I´was realy warnend. Scanned my maschine whith the latest dat-files for mcafee.
Found 2 Trojans. I think, problem is solved but after restart…bufferoverflowwarning again.
Hm…now I was thinking thinking about a rootkit. I never get touched with this shit of viruses but a look into the firewall-log in cfp say all to me. Something try hardly to get access into the net over a systemprocess but I have set rules for the systemprocesses on my maschine ^^
In the end, it was a realy a rootkit!
After some rootkitscanners I used I get this piece of shit out of my machine.

A good test for the cfp and it ends successful (S)

Now I have to talk some serious words with my brother who was playing last night on my computer…

I dont appear tp have any of the serious bugs that other people are experiencing, although i still get little lags, etc when closing the firewall window or clicking anything in the interface. A little annoying!

Apart from that good work! Although, i think i will revert to the last stable version and wait for the beta to finish before installing 2.4.

Matt

But I’ve had dumpfiles before. I’ve put dumpfiles on this forum to help you guys find the problem. But the dumpfile dated from an earlier date and hadn’t been modified since.

If that’s the problem, can you tell me how I see if I have a Pagefile on C drive and how to fix it? Maybe then I can retry the whole thing and send a dumpfile.

Which rootkit scanners did you use and which one found the rootkit?

Al

To look at what pagefile(s) you have set-up…

Control Panel → System → Advanced, click Settings in the “Performance” Section. On the Advanced tab the current total physical size & location of all pagefiles are listed.

Sorry, if this is a bit iffy… its from memory for XP.

I did everything you say and found out that the PageFile is enabled for the C drive. so that isn’t the problem I think.

Oops. :-[ Thanks, soyabeaner. You’ve also given Messias something else to check (the dump location) which is good.

I must dust-off my version of XP Pro & downgr… upgrade one of these days. ;D

I also checked the first advanced tab and the settings button in the startup and recovery area. There I found out that windows creates minidumps and stores them where kail said I would find it. So I don’t know what the problem is

I was a little faster kail ;D

Those who have bsods and dump files, please, try to get infos from your events.
To read events from event viewer (skip 1 if got a My Computer icon on your desktop):

  1. push Windows and E buttons (don’t hold it but the same time or hold Win button first :))
  2. right-click on My Computer
  3. choose Manage
  4. go down to Event Viewer
  5. check out System and maybe application events, too

System events should - however, it’s not always quite sure :expressionless: - contain some infos about the bsod events.

Hmm UPHClean seems to be complaining a bit about required drivers. Looking through previous posts it seems like i am not the only one with this problem. Fix pls comodo guys! :slight_smile:

I followed the steps you mentioned but found no information about the BSOD events.

Egemen’s already fixed it… read a bit further.

Ahh yes i see it now. Sorry! (Over enthusiastic noob here (:SHY))

Matt

:frowning: