version 25H2
Last edited:
version 25H2
Windows 11 25H2 26200.7019
I use this config and have the issue on 2 machines, each one with the same config. I don't know if a COMODO config contains sensitive info, but I can share it with you if you want to make further testsBack to the topic.
There is an important question for users who applied the config: Windows Defender + Comodo Firewall. Some people prefer it over CIS for good reasons.
Are the issues with Windows Updates serious problems or not?
The update KB5067036 is probably unimportant. What about other (past) updates on Windows 11?
I use this config and have the issue on 2 machines, each one with the same config. I don't know if a COMODO config contains sensitive info, but I can share it with you if you want to make further tests
Update: latest security update. I used a COMODO installation where i configured it with my config without importing the file and the update was successful. HIPS ON.OK. Please, send me the link via Direct messages.
Comodo config can contain some paths that include your username or the names of some installed applications.
The config contains your username, which you can replace in all places using Notepad. If you created a folder named after yourself and excluded it in Comodo, search for that name and replace it in all instances with Notepad.I don't know if a COMODO config contains sensitive info
I use this config and have the issue on 2 machines, each one with the same config. I don't know if a COMODO config contains sensitive info, but I can share it with you if you want to make further tests
I had so many problems with WU lately on 24H2, updated to 25H2 and update issues fixed. Maybe time to do a in place upgrade?
Yeah maybe, but it's MS in all it's glory. I couldn't even update to 25H2 online, updates stuck @ 46% for hours, had to discount the internet and do an offline install.You are an optimist.![]()
I honestly have no particular software installed. Anyway, now that I configured comodo from zero it seems to work again... Anyway on those machines Windows Defender was always enabledI imported your CFW config and disabled Microsoft Defender (just like @rashmi did). The updates were successful (on Admin account and SUA).
View attachment 292939
So far, nothing suggests that your issues with updates were caused by CFW misconfiguration. If I correctly recall, you used this config for a few years without problems. It may require some adjustments if you installed some new devices, drivers, etc.
I noticed that Comodo was smart enough to correct your user profile folder name to that used in my VM.
Your config also blocked the installation of Microsoft Store application (NanaZip). So I installed 7-Zip to unpack DefenderCotrol.
Edit.
The updates can sometimes fail due to hidden conflicts with installed software. In your case, this could happen if different software is installed on the Admin account and SUA.
I had the issue also on 24H2Just an observation, looking at screenshots the people who don't get WU errors or problems with Comodo with certain updates have 25H2.
I had so many problems with WU lately on 24H2, updated to 25H2 and update issues fixed. Maybe time to do a in place upgrade?
Finally, the issue has been identified. It was not Firewall but AV. I ran the test twice with the same result (Install error - 0x80070005).
The reported tests show that enabling/disabling other modules (HIPS, Auto-containment, VirusScope, Firewall, Script Analysis, Website Filtering) did not cause the KB5067036 update error. But whenever one of the disabled modules was the Antivirus module, the update failed.
In fact, the issue is quite similar to that from the OP (the same update KB5067036 and the same error). In my case (last two tests), I used CIS Proactive config with disabled HIPS and AV modules, which is almost the same setup as the Comodo Firewall config in the OP. However, I did not use the silent setup, and all tests were run on the default Admin account.
I also ran two additional tests with the installed Comodo Firewall application (Proactive config with disabled HIPS), and the KB5067036 failed as in the OP.
It is strange, but all of this suggests that the active AV component's absence may be the cause of the issue in both CIS and Comodo Firewall.
net stop wuauserv
net stop cryptSvc
net stop bits
net stop msiserver
ren C:\Windows\SoftwareDistribution SoftwareDistribution.old
ren C:\Windows\System32\catroot2 catroot2.old
net start wuauserv
net start cryptSvc
net start bits
net start msiserver
netsh winsock reset
Not on my CF systems (WD and WF enabled):The problem can be related to the hidden conflict with Microsoft Defender
I've KB5068861 (26200.7171) installed on my real system, but I might uninstall and reinstall it to confirm failure/success with the Comodo + Defender combo. For the test, I'll use my settings in #Post69 and enable Defender.The problem can be related to the hidden conflict with Microsoft Defender. The updates were installed flawlessly when one of the following conditions was true:
- Microsoft Defender was disabled (tested with DefenderControl, not recommended on the real machine).
- Microsoft was enabled, but "Dev drive protection" was OFF and the system drive (usually C: ) was temporarily added to the Exclusions.
Not on my CF systems (WD and WF enabled):
View attachment 292995
I've KB5068861 (26200.7171) installed on my real system, but I might uninstall and reinstall it to confirm failure/success with the Comodo + Defender combo. For the test, I'll use my settings in #Post69 and enable Defender.
This error has also been reported in non-Comodo systems (to the extent that MSFT has posted a Fix. Couple this with the fact that it does not happen to many systems with Comodo installed.
Logic dictates that the issue resides elsewhere.