EventWnd preventing shutdown/restart [NBZ]

The bug/issue

  1. What you did: restart or turn off computer
  2. What actually happened or you actually saw: “End Program - EventWnd” dialog pops up for a program not repsonding
  3. What you expected to happen or see: computer to restart normally.
  4. How you tried to fix it & what happened: no additional debugging – only started with change of uninstalling 5.1 and installing 5.3
  5. If its an application compatibility problem have you tried the application fixes here?:
  6. Details & exact version of any application (execpt CIS) involved with download link:
  7. Whether you can make the problem happen again, and if so exact steps to make it happen:
  8. Any other information (eg your guess regarding the cause, with reasons): I had Comodo 5.1 installed on my netbook and working well. I uninstalled and installed 5.3 a few days ago. Now, whenever I shut down the computer or go to reset, it pulls up a window saying “EventWnd cannot close”. I can manually close it and the computer will continue to do what it’s supposed to do, but this wasn’t happening under 5.1. The netbook is running WinXP SP3. This problems seems to happen for a lot of people specifically with netbook based on a search for “EventWnd” in google.

Files appended. (Please zip unless screenshots).

  1. Screenshots illustrating the bug:
  2. Screenshots of related CIS event logs and the Defense+ Active Processes List:
  3. A CIS config report or file.
  4. Crash or freeze dump file:

Your set-up

  1. CIS version, AV database version & configuration used: 5.3.175888.1227 , DB 7392
  2. a) Have you updated (without uninstall) from CIS 3 or 4: no
    b) if so, have you tried a clean reinstall (without losing settings - if not please do)?:
  3. a) Have you imported a config from a previous version of CIS: no
    b) if so, have U tried a standard config (without losing settings - if not please do)?:
  4. Have you made any other major changes to the default config? (eg ticked ‘block all unknown requests’, other egs here.): no
  5. Defense+, Sandbox, Firewall & AV security levels: D+= , Sandbox= , Firewall = , AV = proactive defaults
  6. OS version, service pack, number of bits, UAC setting, & account type: WinXP Pro SP3 32-bit, main account (so administrator privileges)
  7. Other security and utility software installed: none
  8. Virtual machine used (Please do NOT use Virtual box): none

EDIT: Update to bug format
EDIT: updated format to supply answers to other questions

Could you please edit your first post and fill in the missing information.

  1. OS version, service pack, number of bits= x 32 or x 64, UAC setting, & account type= Admin or Limited: WinXP Pro SP3

  2. Virtual machine used (Please do NOT use Virtual box):= yes (if which one) or no

Thank you


Could you please supply the missing information as I cannot move the topic to Verified until you do.

Thank you


Thank you for your bug report in the required format.

Moved to verified.

Thank you


Well, it’s in the requested format, but I haven’t seen any help/comments/progress.

It disappeared for awhile, but it started up again today. I’m going to guess that it relates to something in the virus files, since otherwise it wouldn’t make sense to come and go.