meschubert
December 29th, 2007, 07:26 PM
I would like to offer what appears to be a repeatable scenario related to slow file transfers and explorer.exe instability to the Eset support people.
I can generate an unlimited number of the following types of hangs with V3.0.621.0:
Virus signature database: 2755 (20071229)
Update module: 1019 (20071030)
Antivirus and antispyware scanner module: 1101 (20071217)
Advanced heuristics module: 1068 (20071119)
Archive support module: 1067 (20071227)
Cleaner module: 1024 (20071217)
Example #1:
Description:
A problem caused this program to stop interacting with Windows.
Problem signature:
Problem Event Name: AppHangXProcB1
Application Name: explorer.exe
Application Version: 6.0.6000.16549
Application Timestamp: 46d230c5
Hang Signature: e1f2
Hang Type: 132
Waiting on Application Name: ekrn.exe:AmonPort
Waiting on Application Version: 0.0.0.0
OS Version: 6.0.6000.2.0.0.256.1
Locale ID: 1033
Additional Hang Signature 1: 35ac14a99d41431ac2b15bf6cf1748fc
Additional Hang Signature 2: d168
Additional Hang Signature 3: 4180a50a86208072c3e410ec781698ae
Additional Hang Signature 4: 2017
Additional Hang Signature 5: 583e1a4e8a17e81d2a0793c5863b3f94
Additional Hang Signature 6: d0db
Additional Hang Signature 7: 2e192edd046a818338c431ecf59ca942
Read our privacy statement:
http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0409
---------------------------------------------------------------------
Example #2
Description:
A problem caused this program to stop interacting with Windows.
Problem signature:
Problem Event Name: AppHangXProcB1
Application Name: explorer.exe
Application Version: 6.0.6000.16549
Application Timestamp: 46d230c5
Hang Signature: ed3b
Hang Type: 129
Waiting on Application Name: ekrn.exe:AmonPort
Waiting on Application Version: 0.0.0.0
OS Version: 6.0.6000.2.0.0.256.1
Locale ID: 1033
Additional Hang Signature 1: dc44c19cf50594e30550683bcfcb33a5
Additional Hang Signature 2: cc28
Additional Hang Signature 3: f8a03c1fedd93530e035667c9021c616
Additional Hang Signature 4: 5c3d
Additional Hang Signature 5: 026a5d019acb76ce0825fb9387f59b10
Additional Hang Signature 6: dc1a
Additional Hang Signature 7: 4bad92cb9f7340ed8a11a1462569d4dc
Read our privacy statement:
http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0409
Description:
A problem caused this program to stop interacting with Windows.
--------------------------------------------------------------
Example #3
Problem signature:
Problem Event Name: AppHangB1
Application Name: explorer.exe
Application Version: 6.0.6000.16549
Application Timestamp: 46d230c5
Hang Signature: 9f69
Hang Type: 0
OS Version: 6.0.6000.2.0.0.256.1
Locale ID: 1033
Additional Hang Signature 1: 7ddba8aa251f02bd2c8406defb92bc72
Additional Hang Signature 2: 88cf
Additional Hang Signature 3: 78da7a6016398044448c2831a395d320
Additional Hang Signature 4: 9f69
Additional Hang Signature 5: 7ddba8aa251f02bd2c8406defb92bc72
Additional Hang Signature 6: 88cf
Additional Hang Signature 7: 78da7a6016398044448c2831a395d320
Read our privacy statement:
http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0409
--------------------------------------------------------------
Example #4
Description:
A problem caused this program to stop interacting with Windows.
Problem signature:
Problem Event Name: AppHangXProcB1
Application Name: explorer.exe
Application Version: 6.0.6000.16549
Application Timestamp: 46d230c5
Hang Signature: 95ee
Hang Type: 129
Waiting on Application Name: ekrn.exe:AmonPort
Waiting on Application Version: 0.0.0.0
OS Version: 6.0.6000.2.0.0.256.1
Locale ID: 1033
Additional Hang Signature 1: ac126d603a845dbf74dcf17c758ec389
Additional Hang Signature 2: f3f5
Additional Hang Signature 3: d46cd87a70dbb3e530af91f5aaee3769
Additional Hang Signature 4: c941
Additional Hang Signature 5: 1c934992d9bb9e6abf9c6beb6f4b60ad
Additional Hang Signature 6: 1b22
Additional Hang Signature 7: 6a90fe125cebee5a91b973a13832e73b
Read our privacy statement:
http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0409
If you look at post #88 in the “New version 3.0.621 available” thread, you will see that I had this problem suddenly appear with V3.0.566.0 after a couple weeks of trouble free use. I erroneously associated the upgrade to V3.0.621 with fixing the issue even though I knew the assumption was weak because of a full Microsoft Windows PC Restore not solving the problem prior to the upgrade.
I unintentionally recreated the issue this morning and I now know how to repeat it at will. It is detectable with transfers of certain large files while having Heuristics enabled for “Real-time file system protection” under specific conditions. Enabling Advanced heuristics exacerbates the issue to the point of getting the hangs I listed above.
This only becomes apparent under specific circumstances for very specific files that I can send along with similar larger files that do not cause the issues. If I had to venture a guess, the heuristics is getting caught up in something specific in these files, possibly the way the vendor implements their licensing.
The conditions are very specific, but it may lead to a solution of the “larger” issue. If someone from Eset support is interested in my sending the files and additional information regarding the conditions, please send me a PM.
Mark
I can generate an unlimited number of the following types of hangs with V3.0.621.0:
Virus signature database: 2755 (20071229)
Update module: 1019 (20071030)
Antivirus and antispyware scanner module: 1101 (20071217)
Advanced heuristics module: 1068 (20071119)
Archive support module: 1067 (20071227)
Cleaner module: 1024 (20071217)
Example #1:
Description:
A problem caused this program to stop interacting with Windows.
Problem signature:
Problem Event Name: AppHangXProcB1
Application Name: explorer.exe
Application Version: 6.0.6000.16549
Application Timestamp: 46d230c5
Hang Signature: e1f2
Hang Type: 132
Waiting on Application Name: ekrn.exe:AmonPort
Waiting on Application Version: 0.0.0.0
OS Version: 6.0.6000.2.0.0.256.1
Locale ID: 1033
Additional Hang Signature 1: 35ac14a99d41431ac2b15bf6cf1748fc
Additional Hang Signature 2: d168
Additional Hang Signature 3: 4180a50a86208072c3e410ec781698ae
Additional Hang Signature 4: 2017
Additional Hang Signature 5: 583e1a4e8a17e81d2a0793c5863b3f94
Additional Hang Signature 6: d0db
Additional Hang Signature 7: 2e192edd046a818338c431ecf59ca942
Read our privacy statement:
http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0409
---------------------------------------------------------------------
Example #2
Description:
A problem caused this program to stop interacting with Windows.
Problem signature:
Problem Event Name: AppHangXProcB1
Application Name: explorer.exe
Application Version: 6.0.6000.16549
Application Timestamp: 46d230c5
Hang Signature: ed3b
Hang Type: 129
Waiting on Application Name: ekrn.exe:AmonPort
Waiting on Application Version: 0.0.0.0
OS Version: 6.0.6000.2.0.0.256.1
Locale ID: 1033
Additional Hang Signature 1: dc44c19cf50594e30550683bcfcb33a5
Additional Hang Signature 2: cc28
Additional Hang Signature 3: f8a03c1fedd93530e035667c9021c616
Additional Hang Signature 4: 5c3d
Additional Hang Signature 5: 026a5d019acb76ce0825fb9387f59b10
Additional Hang Signature 6: dc1a
Additional Hang Signature 7: 4bad92cb9f7340ed8a11a1462569d4dc
Read our privacy statement:
http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0409
Description:
A problem caused this program to stop interacting with Windows.
--------------------------------------------------------------
Example #3
Problem signature:
Problem Event Name: AppHangB1
Application Name: explorer.exe
Application Version: 6.0.6000.16549
Application Timestamp: 46d230c5
Hang Signature: 9f69
Hang Type: 0
OS Version: 6.0.6000.2.0.0.256.1
Locale ID: 1033
Additional Hang Signature 1: 7ddba8aa251f02bd2c8406defb92bc72
Additional Hang Signature 2: 88cf
Additional Hang Signature 3: 78da7a6016398044448c2831a395d320
Additional Hang Signature 4: 9f69
Additional Hang Signature 5: 7ddba8aa251f02bd2c8406defb92bc72
Additional Hang Signature 6: 88cf
Additional Hang Signature 7: 78da7a6016398044448c2831a395d320
Read our privacy statement:
http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0409
--------------------------------------------------------------
Example #4
Description:
A problem caused this program to stop interacting with Windows.
Problem signature:
Problem Event Name: AppHangXProcB1
Application Name: explorer.exe
Application Version: 6.0.6000.16549
Application Timestamp: 46d230c5
Hang Signature: 95ee
Hang Type: 129
Waiting on Application Name: ekrn.exe:AmonPort
Waiting on Application Version: 0.0.0.0
OS Version: 6.0.6000.2.0.0.256.1
Locale ID: 1033
Additional Hang Signature 1: ac126d603a845dbf74dcf17c758ec389
Additional Hang Signature 2: f3f5
Additional Hang Signature 3: d46cd87a70dbb3e530af91f5aaee3769
Additional Hang Signature 4: c941
Additional Hang Signature 5: 1c934992d9bb9e6abf9c6beb6f4b60ad
Additional Hang Signature 6: 1b22
Additional Hang Signature 7: 6a90fe125cebee5a91b973a13832e73b
Read our privacy statement:
http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0409
If you look at post #88 in the “New version 3.0.621 available” thread, you will see that I had this problem suddenly appear with V3.0.566.0 after a couple weeks of trouble free use. I erroneously associated the upgrade to V3.0.621 with fixing the issue even though I knew the assumption was weak because of a full Microsoft Windows PC Restore not solving the problem prior to the upgrade.
I unintentionally recreated the issue this morning and I now know how to repeat it at will. It is detectable with transfers of certain large files while having Heuristics enabled for “Real-time file system protection” under specific conditions. Enabling Advanced heuristics exacerbates the issue to the point of getting the hangs I listed above.
This only becomes apparent under specific circumstances for very specific files that I can send along with similar larger files that do not cause the issues. If I had to venture a guess, the heuristics is getting caught up in something specific in these files, possibly the way the vendor implements their licensing.
The conditions are very specific, but it may lead to a solution of the “larger” issue. If someone from Eset support is interested in my sending the files and additional information regarding the conditions, please send me a PM.
Mark