NumberSix
June 1st, 2006, 08:14 AM
Sometimes when I try to interrupt a scan, the Pause or Cancel buttons cause Ewido to crash. It seems mainly related to searching files on the hard disk after a certain amount of time (say, after a couple of minutes). Pausing or cancelling shortly after starting a scan doesn't seem to cause it. I'll try to investigate other possibilities later.
For now, here's the error log I got after the last crash. (I had to reload Ewido, as it disappeared out of my System Tray). I'm using a X2 4800+ with 2GB of RAM, 500GB WD HDD and XP Pro 32-bit. My security software includes AVG7, ZoneAlarm Pro, Windows Defender and Spyware Doctor.
//==<ewido anti-malware 4.0>===================================
Exception code: C0000005 ACCESS_VIOLATION
Fault address: 004423E0 01:000413E0 C:\Program Files\ewido anti-malware\ewido.exe
Module Date: 04/27/2006 09:49:51
File Version of C:\Program Files\ewido anti-malware\ewido.exe: 4.0.0.151
Exception Date: 06/01/2006 12:51:35
MiniDump Information Saved to C:\Program Files\ewido anti-malware\ewido.dmp
Registers:
EAX:00000000
EBX:00F4D920
ECX:00000002
EDX:7C90EB94
ESI:00000000
EDI:00000000
CS:EIP:001B:004423E0
SS:ESP:0023:04CCFD44 EBP:04CCFFB0
DS:0023 ES:0023 FS:003B GS:0000
Flags:00010202
Intel specific method
Call stack:
Address Frame Param 0 Param 1 Param 2 Param 3 Logical addr Module
004423E0 04CCFFB0 7C80B50B 00F4D920 773F8B56 DCBAABCD 0001:000413E0 C:\Program Files\ewido anti-malware\ewido.exe
00480D15 04CCFFEC <frame 04CCFFEC not readable>
ImageHelp specific method
Call stack:
Address Frame Param 0 Param 1 Param 2 Param 3 Symbol/Logical address
004423E0 04CCFFB0 7C80B50B 00F4D920 773F8B56 DCBAABCD 0001:000413E0 C:\Program Files\ewido anti-malware\ewido.exe
00480D15 04CCFFEC 00480D0C 00F4D920 00000000 056A9160 0001:0007FD15 C:\Program Files\ewido anti-malware\ewido.exe
Loaded Modules:
Base Size Module
00400000 5F3000 4.00.0000.0151 C:\Program Files\ewido anti-malware\ewido.exe
7C900000 0B0000 5.01.2600.2180 C:\WINDOWS\system32\ntdll.dll
7C800000 0F4000 5.01.2600.2180 C:\WINDOWS\system32\kernel32.dll
76BF0000 00B000 5.01.2600.2180 C:\WINDOWS\system32\PSAPI.DLL
10000000 0E3000 4.00.0000.0007 C:\Program Files\ewido anti-malware\engine.dll
77F60000 076000 6.00.2900.2861 C:\WINDOWS\system32\SHLWAPI.dll
77DD0000 09B000 5.01.2600.2180 C:\WINDOWS\system32\ADVAPI32.dll
77E70000 091000 5.01.2600.2180 C:\WINDOWS\system32\RPCRT4.dll
77F10000 047000 5.01.2600.2818 C:\WINDOWS\system32\GDI32.dll
77D40000 090000 5.01.2600.2622 C:\WINDOWS\system32\USER32.dll
77C10000 058000 7.00.2600.2180 C:\WINDOWS\system32\msvcrt.dll
71AB0000 017000 5.01.2600.2180 C:\WINDOWS\system32\WS2_32.dll
71AA0000 008000 5.01.2600.2180 C:\WINDOWS\system32\WS2HELP.dll
76B40000 02D000 5.01.2600.2180 C:\WINDOWS\system32\WINMM.dll
7C9C0000 816000 6.00.2900.2869 C:\WINDOWS\system32\SHELL32.dll
76380000 005000 5.01.2600.2180 C:\WINDOWS\system32\MSIMG32.dll
763B0000 049000 6.00.2900.2180 C:\WINDOWS\system32\comdlg32.dll
773D0000 102000 6.00.2900.2180 C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\COMCTL32.dll
774E0000 13D000 5.01.2600.2726 C:\WINDOWS\system32\ole32.dll
71AD0000 009000 5.01.2600.2180 C:\WINDOWS\system32\WSOCK32.dll
76D60000 019000 5.01.2600.2180 C:\WINDOWS\system32\iphlpapi.dll
77C00000 008000 5.01.2600.2180 C:\WINDOWS\system32\VERSION.dll
5AD70000 038000 6.00.2900.2180 C:\WINDOWS\system32\uxtheme.dll
77B40000 022000 5.01.2600.2180 C:\WINDOWS\system32\appHelp.dll
76FD0000 07F000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL
77050000 0C5000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
77120000 08C000 5.01.2600.2180 C:\WINDOWS\system32\OLEAUT32.dll
77A20000 054000 5.01.2600.2180 C:\WINDOWS\System32\cscui.dll
76600000 01D000 5.01.2600.2180 C:\WINDOWS\System32\CSCDLL.dll
77920000 0F3000 5.01.2600.2180 C:\WINDOWS\system32\SETUPAPI.dll
769C0000 0B3000 5.01.2600.2180 C:\WINDOWS\system32\USERENV.dll
5A800000 017000 3.06.0000.1003 C:\Program Files\Spyware Doctor\Tools\eg.dat
5A000000 018000 3.06.0000.1039 C:\Program Files\Spyware Doctor\Tools\klg.dat
054F0000 018000 3.06.0000.1069 C:\Program Files\Spyware Doctor\Tools\swpg.dat
71A50000 03F000 5.01.2600.2180 C:\WINDOWS\system32\mswsock.dll
662B0000 058000 5.01.2600.2180 C:\WINDOWS\system32\hnetcfg.dll
71A90000 008000 5.01.2600.2180 C:\WINDOWS\System32\wshtcpip.dll
76F20000 027000 5.01.2600.2180 C:\WINDOWS\system32\DNSAPI.dll
76FB0000 008000 5.01.2600.2180 C:\WINDOWS\System32\winrnr.dll
76F60000 02C000 5.01.2600.2180 C:\WINDOWS\system32\WLDAP32.dll
76FC0000 006000 5.01.2600.2180 C:\WINDOWS\system32\rasadhlp.dll
5B860000 054000 5.01.2600.2180 C:\WINDOWS\system32\netapi32.dll
46FE0000 4E2000 7.00.5346.0005 C:\WINDOWS\system32\ieframe.dll
74C80000 02C000 4.02.5406.0000 C:\WINDOWS\system32\OLEACC.dll
76080000 065000 6.02.3104.0000 C:\WINDOWS\system32\MSVCP60.dll
754D0000 080000 5.131.2600.2180 C:\WINDOWS\system32\CRYPTUI.dll
76C30000 02E000 5.131.2600.2180 C:\WINDOWS\system32\WINTRUST.dll
77A80000 094000 5.131.2600.2180 C:\WINDOWS\system32\CRYPT32.dll
77B20000 012000 5.01.2600.2180 C:\WINDOWS\system32\MSASN1.dll
76C90000 028000 5.01.2600.2180 C:\WINDOWS\system32\IMAGEHLP.dll
771B0000 0B6000 7.00.5346.0005 C:\WINDOWS\system32\WININET.dll
71660000 009000 6.00.5243.0000 C:\WINDOWS\system32\Normaliz.dll
5DCA0000 039000 7.00.5346.0005 C:\WINDOWS\system32\iertutil.dll
76390000 01D000 5.01.2600.2180 C:\WINDOWS\system32\IMM32.dll
7D4A0000 33A000 7.00.5346.0005 C:\WINDOWS\system32\MSHTML.dll
746C0000 029000 3.10.0349.0000 C:\WINDOWS\system32\msls31.dll
63400000 02E000 7.00.5346.0005 C:\WINDOWS\system32\MSRATING.dll
61410000 0C7000 7.00.5346.0005 C:\WINDOWS\system32\urlmon.dll
5DFF0000 033000 7.00.5346.0005 C:\WINDOWS\system32\IEUI.dll
02F40000 013000 1.00.0000.0001 C:\Program Files\ewido anti-malware\shellexecutehook.dll
5F800000 015000 1.01.1347.0000 C:\PROGRA~1\WIFD1F~1\MpShHook.dll
78130000 09B000 4.00.0000.0151 C:\Program Files\ewido anti-malware\ewido.exe
7C420000 087000 4.00.0000.0151 C:\Program Files\ewido anti-malware\ewido.exe
05CC0000 0D2000 7.00.5346.0005 C:\WINDOWS\system32\en-US\ieframe.dll.mui
76F50000 008000 5.01.2600.2180 C:\WINDOWS\system32\WtsApi32.dll
76360000 010000 5.01.2600.2180 C:\WINDOWS\system32\WINSTA.dll
59A60000 0A1000 5.01.2600.2180 C:\WINDOWS\system32\DBGHELP.DLL
For now, here's the error log I got after the last crash. (I had to reload Ewido, as it disappeared out of my System Tray). I'm using a X2 4800+ with 2GB of RAM, 500GB WD HDD and XP Pro 32-bit. My security software includes AVG7, ZoneAlarm Pro, Windows Defender and Spyware Doctor.
//==<ewido anti-malware 4.0>===================================
Exception code: C0000005 ACCESS_VIOLATION
Fault address: 004423E0 01:000413E0 C:\Program Files\ewido anti-malware\ewido.exe
Module Date: 04/27/2006 09:49:51
File Version of C:\Program Files\ewido anti-malware\ewido.exe: 4.0.0.151
Exception Date: 06/01/2006 12:51:35
MiniDump Information Saved to C:\Program Files\ewido anti-malware\ewido.dmp
Registers:
EAX:00000000
EBX:00F4D920
ECX:00000002
EDX:7C90EB94
ESI:00000000
EDI:00000000
CS:EIP:001B:004423E0
SS:ESP:0023:04CCFD44 EBP:04CCFFB0
DS:0023 ES:0023 FS:003B GS:0000
Flags:00010202
Intel specific method
Call stack:
Address Frame Param 0 Param 1 Param 2 Param 3 Logical addr Module
004423E0 04CCFFB0 7C80B50B 00F4D920 773F8B56 DCBAABCD 0001:000413E0 C:\Program Files\ewido anti-malware\ewido.exe
00480D15 04CCFFEC <frame 04CCFFEC not readable>
ImageHelp specific method
Call stack:
Address Frame Param 0 Param 1 Param 2 Param 3 Symbol/Logical address
004423E0 04CCFFB0 7C80B50B 00F4D920 773F8B56 DCBAABCD 0001:000413E0 C:\Program Files\ewido anti-malware\ewido.exe
00480D15 04CCFFEC 00480D0C 00F4D920 00000000 056A9160 0001:0007FD15 C:\Program Files\ewido anti-malware\ewido.exe
Loaded Modules:
Base Size Module
00400000 5F3000 4.00.0000.0151 C:\Program Files\ewido anti-malware\ewido.exe
7C900000 0B0000 5.01.2600.2180 C:\WINDOWS\system32\ntdll.dll
7C800000 0F4000 5.01.2600.2180 C:\WINDOWS\system32\kernel32.dll
76BF0000 00B000 5.01.2600.2180 C:\WINDOWS\system32\PSAPI.DLL
10000000 0E3000 4.00.0000.0007 C:\Program Files\ewido anti-malware\engine.dll
77F60000 076000 6.00.2900.2861 C:\WINDOWS\system32\SHLWAPI.dll
77DD0000 09B000 5.01.2600.2180 C:\WINDOWS\system32\ADVAPI32.dll
77E70000 091000 5.01.2600.2180 C:\WINDOWS\system32\RPCRT4.dll
77F10000 047000 5.01.2600.2818 C:\WINDOWS\system32\GDI32.dll
77D40000 090000 5.01.2600.2622 C:\WINDOWS\system32\USER32.dll
77C10000 058000 7.00.2600.2180 C:\WINDOWS\system32\msvcrt.dll
71AB0000 017000 5.01.2600.2180 C:\WINDOWS\system32\WS2_32.dll
71AA0000 008000 5.01.2600.2180 C:\WINDOWS\system32\WS2HELP.dll
76B40000 02D000 5.01.2600.2180 C:\WINDOWS\system32\WINMM.dll
7C9C0000 816000 6.00.2900.2869 C:\WINDOWS\system32\SHELL32.dll
76380000 005000 5.01.2600.2180 C:\WINDOWS\system32\MSIMG32.dll
763B0000 049000 6.00.2900.2180 C:\WINDOWS\system32\comdlg32.dll
773D0000 102000 6.00.2900.2180 C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\COMCTL32.dll
774E0000 13D000 5.01.2600.2726 C:\WINDOWS\system32\ole32.dll
71AD0000 009000 5.01.2600.2180 C:\WINDOWS\system32\WSOCK32.dll
76D60000 019000 5.01.2600.2180 C:\WINDOWS\system32\iphlpapi.dll
77C00000 008000 5.01.2600.2180 C:\WINDOWS\system32\VERSION.dll
5AD70000 038000 6.00.2900.2180 C:\WINDOWS\system32\uxtheme.dll
77B40000 022000 5.01.2600.2180 C:\WINDOWS\system32\appHelp.dll
76FD0000 07F000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL
77050000 0C5000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
77120000 08C000 5.01.2600.2180 C:\WINDOWS\system32\OLEAUT32.dll
77A20000 054000 5.01.2600.2180 C:\WINDOWS\System32\cscui.dll
76600000 01D000 5.01.2600.2180 C:\WINDOWS\System32\CSCDLL.dll
77920000 0F3000 5.01.2600.2180 C:\WINDOWS\system32\SETUPAPI.dll
769C0000 0B3000 5.01.2600.2180 C:\WINDOWS\system32\USERENV.dll
5A800000 017000 3.06.0000.1003 C:\Program Files\Spyware Doctor\Tools\eg.dat
5A000000 018000 3.06.0000.1039 C:\Program Files\Spyware Doctor\Tools\klg.dat
054F0000 018000 3.06.0000.1069 C:\Program Files\Spyware Doctor\Tools\swpg.dat
71A50000 03F000 5.01.2600.2180 C:\WINDOWS\system32\mswsock.dll
662B0000 058000 5.01.2600.2180 C:\WINDOWS\system32\hnetcfg.dll
71A90000 008000 5.01.2600.2180 C:\WINDOWS\System32\wshtcpip.dll
76F20000 027000 5.01.2600.2180 C:\WINDOWS\system32\DNSAPI.dll
76FB0000 008000 5.01.2600.2180 C:\WINDOWS\System32\winrnr.dll
76F60000 02C000 5.01.2600.2180 C:\WINDOWS\system32\WLDAP32.dll
76FC0000 006000 5.01.2600.2180 C:\WINDOWS\system32\rasadhlp.dll
5B860000 054000 5.01.2600.2180 C:\WINDOWS\system32\netapi32.dll
46FE0000 4E2000 7.00.5346.0005 C:\WINDOWS\system32\ieframe.dll
74C80000 02C000 4.02.5406.0000 C:\WINDOWS\system32\OLEACC.dll
76080000 065000 6.02.3104.0000 C:\WINDOWS\system32\MSVCP60.dll
754D0000 080000 5.131.2600.2180 C:\WINDOWS\system32\CRYPTUI.dll
76C30000 02E000 5.131.2600.2180 C:\WINDOWS\system32\WINTRUST.dll
77A80000 094000 5.131.2600.2180 C:\WINDOWS\system32\CRYPT32.dll
77B20000 012000 5.01.2600.2180 C:\WINDOWS\system32\MSASN1.dll
76C90000 028000 5.01.2600.2180 C:\WINDOWS\system32\IMAGEHLP.dll
771B0000 0B6000 7.00.5346.0005 C:\WINDOWS\system32\WININET.dll
71660000 009000 6.00.5243.0000 C:\WINDOWS\system32\Normaliz.dll
5DCA0000 039000 7.00.5346.0005 C:\WINDOWS\system32\iertutil.dll
76390000 01D000 5.01.2600.2180 C:\WINDOWS\system32\IMM32.dll
7D4A0000 33A000 7.00.5346.0005 C:\WINDOWS\system32\MSHTML.dll
746C0000 029000 3.10.0349.0000 C:\WINDOWS\system32\msls31.dll
63400000 02E000 7.00.5346.0005 C:\WINDOWS\system32\MSRATING.dll
61410000 0C7000 7.00.5346.0005 C:\WINDOWS\system32\urlmon.dll
5DFF0000 033000 7.00.5346.0005 C:\WINDOWS\system32\IEUI.dll
02F40000 013000 1.00.0000.0001 C:\Program Files\ewido anti-malware\shellexecutehook.dll
5F800000 015000 1.01.1347.0000 C:\PROGRA~1\WIFD1F~1\MpShHook.dll
78130000 09B000 4.00.0000.0151 C:\Program Files\ewido anti-malware\ewido.exe
7C420000 087000 4.00.0000.0151 C:\Program Files\ewido anti-malware\ewido.exe
05CC0000 0D2000 7.00.5346.0005 C:\WINDOWS\system32\en-US\ieframe.dll.mui
76F50000 008000 5.01.2600.2180 C:\WINDOWS\system32\WtsApi32.dll
76360000 010000 5.01.2600.2180 C:\WINDOWS\system32\WINSTA.dll
59A60000 0A1000 5.01.2600.2180 C:\WINDOWS\system32\DBGHELP.DLL