OK, I’ve installed Comodo V2 first just recently. Then found V3 and installed it. V3 deleted V2 and then rebooted and I had to install V3 again. As all this was happening, the AV I’m using is EAV Antivirus Suite Free Edition V5.61 (www.your-soft.com).
During the INSTALL, the AV claimed that GUARD32.DLL was ‘infected’. I let it go through and install.
Since then whenever I boot, Right after the WinXP black screen with the blue squares moving in a box, I get the screen that you’d see if CHKDSK were to run. Dark blue bar on the top with Windows XP on the right and same bar on the bottom with a lighter blue in the middle. The words ‘Please Wait’ appears and then directly after that, dots. They keep adding. Something is going on and the number of dots are not always the same.
Trying to track this down I first thought it was CHKNTFS finding dirty bits, but that doesn’t appear to be the case? I checked my other computers and the REGISTRY values are the same on the systems.
Next I looked at My Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager in the Registry. I see something odd compared to the other system. I have a PendingFileRenameOperations Key. The data is
??\c:\windows\system32\guard32.dl
??\c:\windows\system32\guard32.dl
??\c:\windows\system32\guard32.dl
??\c:\windows\system32\guard32.dl
??\c:\windows\system32\guard32.dl
It seems to grow on each boot?
I do have a GUARD32.DLL on the system (but no GUARD32.DL),
c:>dir guard32.* /s
Volume in drive C is Drive_C_SATA
Volume Serial Number is 880F-4DB4
Directory of c:\Program Files\COMODO\Firewall\Repair
03/10/2008 08:58 AM 139,008 guard32.dll
1 File(s) 139,008 bytes
Directory of c:\WINDOWS\system32
03/10/2008 08:58 AM 139,008 guard32.dll
1 File(s) 139,008 bytes
Total Files Listed:
2 File(s) 278,016 bytes
0 Dir(s) 49,228,763,136 bytes free
I deleted that KEY, system booted WITHOUT that annoying screen. However, when I looked in the Registry after boot, the key was back?
I looked at my CURRENTVERSION3, and that key WAS NOT there? It was in CURRENTVERSION2 however?
Any ideas or suggestions? Is this caused by the AV or the FW?
Thanks,
IrvS