MCH 4 (2.8.0.2 and 2.8.0.9)
Posted: Thu Dec 15, 2016 9:51 am
Hello Madshi!
Customers of my MCH applications report that they cannot start some applications when my codehook service is running and Kaspersky AV is installed. On my test system I get the following runtime error when an application starts:
One interesting thing: Faulting instruction pointer is always 0x43eb0...
MCH 3 does not make any problems in conjunction with Kaspersky AV.
Any idea?
Customers of my MCH applications report that they cannot start some applications when my codehook service is running and Kaspersky AV is installed. On my test system I get the following runtime error when an application starts:
Code: Select all
STACK_TEXT:
00000000`0009e598 00000000`50de6a28 : 00000000`00000000 00000000`00000004 00000000`00000008 00000000`7ff8415f : 0x43eb0
00000000`0009e5a0 00000000`50de69df : 00000000`00000000 00000000`00800000 00000000`00792c50 00000000`00000000 : wow64!Wow64ApcRoutineInternal+0x40
00000000`0009e620 00007ff8`40309b5e : 71b00214`71b00000 00000000`00000000 00000000`00000000 00000000`50de69c0 : wow64!Wow64ApcRoutine+0x1f
00000000`0009e660 00007ff8`403065d4 : 00007ff8`4026ddc5 00000000`00790000 00000000`00000050 00000000`00000006 : ntdll!KiUserApcDispatch+0x2e
00000000`0009eb58 00007ff8`4026ddc5 : 00000000`00790000 00000000`00000050 00000000`00000006 00007ff8`40298097 : ntdll!NtMapViewOfSection+0x14
00000000`0009eb60 00007ff8`4026da52 : 00000000`00000040 00000000`0009ec60 00000000`00000000 00000000`00792ac8 : ntdll!LdrpMapViewOfSection+0xb5
00000000`0009ec00 00007ff8`4026d925 : 00000000`00792a80 00007ff8`4026de00 00000000`00008600 00000000`d02dfd33 : ntdll!LdrpMapImage+0x72
00000000`0009eca0 00007ff8`4026d47e : 00000000`00000000 00000000`c0000135 00000000`00792a80 00000000`00792a80 : ntdll!LdrpMapDllWithSectionHandle+0x2d
00000000`0009ece0 00007ff8`4026d236 : 00000000`00000000 00000000`00000040 00000000`00000000 00000000`0009ee70 : ntdll!LdrpLoadKnownDll+0xe6
00000000`0009ed40 00007ff8`4028701c : 00000000`0009ee64 00000000`0009ef20 00000000`0009ee70 00000000`0009f100 : ntdll!LdrpFindOrPrepareLoadingModule+0xa6
00000000`0009eda0 00007ff8`40286add : 00000000`0009ee70 00000000`0009f000 00000000`00000000 00000000`00000001 : ntdll!LdrpLoadDllInternal+0x110
00000000`0009ee20 00007ff8`40269efc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!LdrpLoadDll+0xf1
00000000`0009efc0 00007ff8`40266e2e : 00000000`00000000 00000000`00000000 00000000`00000003 00000000`002f0000 : ntdll!LdrLoadDll+0x8c
00000000`0009f0c0 00007ff8`402f29d7 : 00000000`00400100 00000000`00000000 00000000`00000000 00000000`002f0000 : ntdll!LdrpLoadWow64+0x6e
00000000`0009f350 00007ff8`40328986 : 00000000`00000000 00007ff8`402e9e59 00000000`00000000 00000000`00000001 : ntdll!LdrpInitializeProcess+0x1517
00000000`0009f750 00007ff8`402d9fae : 00000000`0009f820 00000000`00000000 00000000`00000000 00000000`002f0000 : ntdll!_LdrpInitialize+0x4e982
00000000`0009f7d0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!LdrInitializeThunk+0xe
MODULE_NAME: wow64
IMAGE_NAME: wow64.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 57899aec
STACK_COMMAND: dt ntdll!LdrpLastDllInitializer BaseDllName ; dt ntdll!LdrpFailureData ; .ecxr ; kb
FAILURE_BUCKET_ID: SOFTWARE_NX_FAULT_c0000005_wow64.dll!Wow64ApcRoutineInternal
BUCKET_ID: SOFTWARE_NX_FAULT_BAD_IP_wow64!Wow64ApcRoutineInternal+40
PRIMARY_PROBLEM_CLASS: SOFTWARE_NX_FAULT_BAD_IP_wow64!Wow64ApcRoutineInternal+40
FAILURE_EXCEPTION_CODE: c0000005
FAILURE_IMAGE_NAME: wow64.dll
BUCKET_ID_IMAGE_STR: wow64.dll
FAILURE_MODULE_NAME: wow64
BUCKET_ID_MODULE_STR: wow64
FAILURE_FUNCTION_NAME: Wow64ApcRoutineInternal
BUCKET_ID_FUNCTION_STR: Wow64ApcRoutineInternal
BUCKET_ID_OFFSET: 40
BUCKET_ID_MODTIMEDATESTAMP: 57899aec
BUCKET_ID_MODCHECKSUM: 52b95
BUCKET_ID_MODVER_STR: 6.2.14393.0
BUCKET_ID_PREFIX_STR: SOFTWARE_NX_FAULT_BAD_IP_
FAILURE_PROBLEM_CLASS: SOFTWARE_NX_FAULT
FAILURE_SYMBOL_NAME: wow64.dll!Wow64ApcRoutineInternal
WATSON_STAGEONE_URL: http://watson.microsoft.com/StageOne/iron.exe/1.0.0.0/52eaf40f/unknown/0.0.0.0/bbbbbbb4/c0000005/00043eb0.htm?Retriage=1
TARGET_TIME: 2016-12-15T09:37:36.000Z
OSBUILD: 14393
OSSERVICEPACK: 479
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt SingleUserTS
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
BUILDDATESTAMP_STR: 161110-2025
BUILDLAB_STR: rs1_release
BUILDOSVER_STR: 10.0.14393.479
ANALYSIS_SESSION_ELAPSED_TIME: 471
ANALYSIS_SOURCE: UM
FAILURE_ID_HASH_STRING: um:software_nx_fault_c0000005_wow64.dll!wow64apcroutineinternal
FAILURE_ID_HASH: {329ea9c8-9139-97e8-a383-4689b3177d12}
MCH 3 does not make any problems in conjunction with Kaspersky AV.
Any idea?