A. THE BUG/ISSUE (Varies from issue to issue)
[ol]- Summary - Give a clear summary in the topic subject, NOT here.
-
Can U reproduce the problem & if so how reliably?:
-
If U can, exact steps to reproduce. If not, exactly what U did & what happened:
-
If not obvious, what U expected to happen:
-
If a software compatibility problem have U tried the conflict FAQ?:
-
Any software except CIS/OS involved? If so - name, & exact version:
-
Any other information, eg your guess at the cause, how U tried to fix it etc:
-
Always attach - Diagnostics file, Watch Activity process list, dump if freeze/crash. (If complex - CIS logs & config, screenshots, video, zipped program - not m’ware)
[/ol]
B. YOUR SETUP (Likely the same for each issue, so you can copy forward)
[ol]- Exact CIS version & configuration:
-
Modules enabled & level. D+/HIPS, Autosandbox/BBlocker, Firewall, & AV:
-
Have U made any other changes to the default config? (egs here.):
-
Have U updated (without uninstall) from a CIS 5?:
[li]if so, have U tried a a clean reinstall - if not please do?:
[/li]- Have U imported a config from a previous version of CIS:
[li]if so, have U tried a standard config - if not please do:
[/li]- OS version, SP, 32/64 bit, UAC setting, account type, V.Machine used:
-
Other security/s’box software a) currently installed b) installed since OS: a= b=
[/ol]
Win 7 Professional
NL
Same error
partly in Dutch below
I have these errors in pairs with the same date and time
I have these errors in every 1 or 2 minutes
The first of these errors occurred for the first time
on 12-6-2013 10:06:11 12 of june
after a (major?) Windows Update.
when the computer was restarted / rebooted
I cannot relate these errors to any recognizable faulty behavior of my laptop
- Don’t know if relevant, but
just before restart after the above mentioned Windows Update there was an error:
De service Group Policy Client is niet juist afgesloten na de ontvangst van een besturingselement voor afsluiten
The service Group Policy Client is not closed/ … in the correct way after receiving a ‘besturingselement voor afsluiten’
/ order to close down ?
Did Comodo or Microsoft perhaps inadvertently change permissions of CFRMD.sys ?
I looked at the current permissions of CFRMD.sys
in c:\Windows\System32\drivers\
Names of Groups and Users
SYSTEM
Administrators
Gebruikers (means Users in Dutch)
Many other files in c:\Windows\System32\drivers
also have TrustedInstaller listed
Is CFRMD.sys
also supposed to have TrustedInstaller listed with permissions ?
- I’m next also going to check my Seagate disk with Seatools etc.
Seagate
ST95005620AS
and check for new firmware
Are other people using same disk ?
Logboeknaam: System
Bron: Microsoft-Windows-FilterManager
Datum: 15-6-2013 21:44:24
Gebeurtenis-id:4
Taakcategorie: Geen
Niveau: Waarschuwing
Trefwoorden:
Gebruiker: Med… < Took the rest out, don’t know if it’s too unique and revealing>
Computer: Med < Took the rest out, don’t know if it’s too unique and revealing>
Beschrijving:
Kan bestandssysteemfilter ‘CFRMD’ (versie 6.1, 2012-07-17T07:05:30.000000000Z) niet aan volume ‘\Device\Harddisk0\DR0’ koppelen. Een ongebruikelijke uiteindelijke status 0xc01c0016 is geretourneerd. Dit filter en/of de bijbehorende toepassingen moeten deze toestand kunnen verwerken. Neem contact op met het leverancier als de toestand zich blijft voordoen.
Gebeurtenis-XML:
4
0
3
0
0
0x8000000000000000
83769
System
Medlap
0xc01c0016
6
1
5
CFRMD
2012-07-17T07:05:30.000000000Z
21
\Device\Harddisk0\DR0