Comodo Internet Security 3.9.75615.498 RC2 Bug Reports

Operating system: Windows XP Pro 32-bit SP3
CIS version: updated from RC2 to .499

I tested the update on a RC installed from scratch although I imported the config I was already using (I forgot to test a default config)

Both Protect APR cache and Block gratuitous ARP frames options were enabled
Block Fragmented IP datagrams option was enabled
Do protocol analysis option was enabled

No internet connection was available (I was not able to load any site) and CIS tray icon animation was not displayed (red/green arrows) but nslookup was able to resolve domain names and get IPs whereas ping resulted in destination unreachable errors

Setting CIS Firewall Security Level to Disabled didn’t affect the above mentioned condition in any way.
Before uninstalling .499 I also attemped to uninstall my NIC from device manager to have it reinstalled after a reboot but the issue remained.

1st EDIT: I updated to .499 again to test CIS default config and confirm whenever the System status reported some issues. There is no connection issue this time but activating the previous config was unable to reproduce the issue (so apparently it was not configuration related apparently the previous config worked correctly before rebooting)

2nd EDIT: I rebooted to test my previous config but I got a BSOD (zip attached) on my 1st reboot. After my 2nd reboot I got a lockup after XP welcome screen. After my 3rd reboot I got no lockup but the above mentioned connection issues happened again (CIS status manager reported no error and was a checkmarked green circle).

Before my 4th reboot I activated CIS default config again (namely COMODO-Internet Security configuration) and after rebooting I got no lockup nor any connection issues.

[attachment deleted by admin]

I got a BSOD both times I tried to boot the computer normally. I could not successfully restore the computer from any System Restore point that I tried. I ended up having to restore the computer from a disk image created a week ago. Therefore I have no memory dump to provide you. The only thing I can say is that this Vista computer has NEVER had a BSOD before, ever!

I notice that quite a few people are getting BSODs with this .499 update. Installing this update is taking a real risk, because you don’t know what to expect when you reboot the computer.

BSOD is back. I noticed that if I let the computer sit about 30 seconds at the log in screen I get a BSOD and it will just keep repeating. I am running Vista SP1, dumps attached.

[attachment deleted by admin]

Endymion

i install CIS same as u , all work perfect here mate…

i use also upate to 499 , all went perfect for me , not saying problem not exist :wink:

Updated to version .499 (RC2)… all was smoot until now… :-[

I got a BSOD a bit after boot… And the computer restarted itself
Here is the error in swedish:

Problemsignatur: Problemhändelsens namn: BlueScreen OS-version: 6.0.6001.2.1.0.768.3 Språkvariant-ID: 1053

Ytterligare information om problemet:
BCCode: 1000008e
BCP1: 80000003
BCP2: 82498980
BCP3: 9A784AD4
BCP4: 00000000
OS Version: 6_0_6001
Service Pack: 1_0
Product: 768_1

Filer som hjälper till att beskriva problemet:
C:\Windows\Minidump\Mini050509-02.dmp
C:\Users\Marcus\AppData\Local\Temp\WER-65926-0.sysdata.xml
C:\Users\Marcus\AppData\Local\Temp\WERB96F.tmp.version.txt

switching back to 3.8 for a while…
If you need I can attach/send Mini050509-02.dmp?

I use Vista SP1 (32 bit), apart from CIS I had Windows defender running in the background (realtime protection was however OFF)… =) Anyway cool with a blue screen…

EDIT:: 2 crashes (dmp) attached… (Tried a reeboot first, so my system crashed twice… )

=)

[attachment deleted by admin]

Hi Guys,

We have stopped updating to 499 because of these unexpected BSODs. Tomorrow we will issue a 2 stage update to prevent these.

Sorry for the inconvenience,
Egemen

Thanks for the mmeory dump. We have fixed this issue. It is because of the ARP analysis.

If you are having BSODs pls disable all ARP related defenses in the firewall settings. This is the reson for the BSODs. We have fixed this issue but lets make sure you dont have any other issues.

Thx Egeman that did the trick here on Win 7 beta. Now all you guys go home and enjoy a well deserved rest…:-TU

I had a BSOD with code 0X8E before disabling ARP cache protection.

Thanks, disabling ARP related options solved the connection issue and the bsod

The BSOD was a lucky occurrence as other reboots more often resulted in a lockup after XP welcome screen.

I don’t understand Update to 499 is available for me.

Many thanks working when ARP disable. :smiley:
(Only Firewall defense+ installed.
Before my problem is not BSOD.
Is no internet connection.)

Done.

But persistence of this bug with 499.

When will the issues with false positives be resolved.
Today I got positive report for Klite codec pack 4,70 full. (unclassified malware@17259862)

Exclusions on removable media are still not fixed.

https://forums.comodo.com/anti_virus_bugs/exclusion_not_working_on_removable_media_dvdflash_dr_reports_wont_go_away-t34950.0.html

Yep, I got false positives for Pidgin and Vuze (Azureus) uninstallers in the latest database 1152 with heuristics on High. I think I might switch to Avira Free soon.

Install Hotspot shield (HSS), reboot, several minutes after boot completed HSS (Hsssrv.exe) starts to consume all or most remaining processor cycles. This lasts for 3-4 minutes, then resolves.

  1. Your Operating System: XP SP3 32bit, 4Gb memory
  2. CIS version & settings: RC2 .498. AV:Stateful, FW: Safe, D+ ‘Clean PC’, Normal execution control, BOP=on. Settings imported from RC1
  3. Other Security and Utility Software Installed: CIS, CVE, CIV, CLP, Filezilla, Walllwatcher, Sony Ericsson PC software, Actual Window Manager, Routerstats, Revo, Process Explorer
  4. Step by step description to reproduce the issue: see above - happens on every re-boot.
  5. How you tried to resolve the problem: Nothing except closing Hssserve.exe works - gave VPN network HSS creates full privileges for wide IP range, excluded HSS files from buffer overflow, gave HSS system privileges under D+& allowed HSS memory access to CIS files.
  6. Upload Memory Dumps on crash if you encounter any: NA
  7. Attach screenshots to your posts to clarify the issue further: NA
  8. Any other information you think that might be useful: Functionally HSS is similar to Comodo’s TrustConnect, I think. HSS is an interesting peice of software, structurally - it consists mainly of 3 windows services (& a driver?), and the only GUI is via the web. Maybe this structure presents problems for CIS?

Sorry not willing to risk 499 at present!

CIS slow to initialize on startup. Should be faster.

Not here it isn’t!

Are you improving the ARP protection?

Just to note that I will confirm that this is CIS-related by de-installation of CIS when the revised .499 (RC3?) is issued.