Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 17th, 2012, 10:11 AM
Brummelchen Brummelchen is offline
Becky! Internet Mail Support
 
Join Date: Jan 2009
Posts: 880
Default eamonm.sys, bluescreen, sandboxie, Adobe

while installing adobe photoshop cs6 into sandboxie windows throws a bluescreen with
Code:
BAD_POOL_HEADER 0x00000019 0x00000020
Code:
eamonm.sys eamonm.sys+1e77c 0x8c01e000 0x8c0ee000 0x000d0000 0x4f577177 07.03.2012 16:32:23 ESET Smart Security Amon monitor 5.2.7.0 ESET C:\Windows\system32\drivers\eamonm.sys fltmgr.sys fltmgr.sys+318a 0x82b45000 0x82b79000 0x00034000 0x4a5bbf11 14.07.2009 01:11:13 Betriebssystem Microsoft® Windows® Microsoft Dateisystem-Filter-Manager 6.1.7600.16385 (win7_rtm.090713-1255) Microsoft Corporation C:\Windows\system32\drivers\fltmgr.sys ntoskrnl.exe ntoskrnl.exe+b4c0d 0x81e43000 0x82255000 0x00412000 0x4f766ae5 31.03.2012 04:24:37 Microsoft® Windows® Operating System NT Kernel & System 6.1.7601.17803 (win7sp1_gdr.120330-1504) Microsoft Corporation C:\Windows\system32\ntoskrnl.exe

Code:
eamonm.sys eamonm.sys+1e77c 0x8be04000 0x8bed4000 0x000d0000 0x4f577177 07.03.2012 16:32:23 ESET Smart Security Amon monitor 5.2.7.0 ESET C:\Windows\system32\drivers\eamonm.sys fltmgr.sys fltmgr.sys+318a 0x82ba0000 0x82bd4000 0x00034000 0x4a5bbf11 14.07.2009 01:11:13 Betriebssystem Microsoft® Windows® Microsoft Dateisystem-Filter-Manager 6.1.7600.16385 (win7_rtm.090713-1255) Microsoft Corporation C:\Windows\system32\drivers\fltmgr.sys ntoskrnl.exe ntoskrnl.exe+b4c0d 0x81e37000 0x82249000 0x00412000 0x4f766ae5 31.03.2012 04:24:37 Microsoft® Windows® Operating System NT Kernel & System 6.1.7601.17803 (win7sp1_gdr.120330-1504) Microsoft Corporation C:\Windows\system32\ntoskrnl.exe

win7/32, eav 5.2.9.1 (german), sandboxie 3.69.01

last days with eset 5.0.94.0 german all was fine.
i try to reproduce with sandboxie 3.68 final and 3.69.03 (latest beta)

#with sb 3.68 final crashes
## 3.69.03 also

Last edited by Brummelchen : May 17th, 2012 at 11:03 AM.
  #2  
Old May 17th, 2012, 10:13 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,225
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Please upload the dumps somewhere and PM me the download links. If necessary, I can provide you with access to our ftp server.
  #3  
Old May 17th, 2012, 11:06 AM
Brummelchen Brummelchen is offline
Becky! Internet Mail Support
 
Join Date: Jan 2009
Posts: 880
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

i can reproduce the crashes with all present versions of sandboxie.
Setup crashes somewhere in the middle of installation, last time i saw
something with "hunspell".
i linked the minidumps - hope that is enough i dont have others due settings.
in normal these where my 2nd to 5ths bluescreen with win7.

i need to go back after i had a view to beta 6.
  #4  
Old May 17th, 2012, 11:17 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,225
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Thank you for the dumps provided, I've passed them to our developers for analysis.
  #5  
Old May 17th, 2012, 12:58 PM
Brummelchen Brummelchen is offline
Becky! Internet Mail Support
 
Join Date: Jan 2009
Posts: 880
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

beta 6 let windows crash too, sorry
Code:
eamonm.sys eamonm.sys+1e7fc 0x8c008000 0x8c0d8000 0x000d0000 0x4f9e3531 30.04.2012 08:46:09 fltmgr.sys fltmgr.sys+318a 0x82b3d000 0x82b71000 0x00034000 0x4a5bbf11 14.07.2009 01:11:13 Betriebssystem Microsoft® Windows® Microsoft Dateisystem-Filter-Manager 6.1.7600.16385 (win7_rtm.090713-1255) Microsoft Corporation C:\Windows\system32\drivers\fltmgr.sys ntoskrnl.exe ntoskrnl.exe+b4c0d 0x81e45000 0x82257000 0x00412000 0x4f766ae5 31.03.2012 04:24:37 Microsoft® Windows® Operating System NT Kernel & System 6.1.7601.17803 (win7sp1_gdr.120330-1504) Microsoft Corporation C:\Windows\system32\ntoskrnl.exe
  #6  
Old May 22nd, 2012, 02:00 PM
hyleaf hyleaf is offline
Infrequent Poster
 
Join Date: May 2012
Posts: 4
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

I have the exact same problem with the latest version of ESET 5.2.9.1 in English, but Smart Security in my case.

Blue Screen with error in eamonm.sys, with an error of PAGE_FAULT_IN_NON_PAGED_AREA.

I'm running windows 7 64 bits, with Sandboxie 3.68 64 bits as well. But I get this error at random times while using Waterfox (firefox 64 bits) sandboxed.

Did not install Adobe Photoshop CS6 yet, but I have CS5 installed for a long time already.

From what I know, hunspell is a spell-checking plugin included in firefox, and on trillian, which I have running as well, but not sandboxed.

Anything else I can help with? How do I get these dumps?

Thanks.

EDIT: Got another crash, and got the minidump file.

Last edited by hyleaf : May 24th, 2012 at 10:43 PM.
  #7  
Old May 30th, 2012, 12:03 PM
hyleaf hyleaf is offline
Infrequent Poster
 
Join Date: May 2012
Posts: 4
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

What is the status of this problem?

I had to revert to 5.0.95 too, because of the problems. I got 2 minidumps from the last crashes, where can I send them? Seems like I cannot PM you Marcos.

Thanks.
  #8  
Old June 5th, 2012, 04:42 AM
bwb1 bwb1 is offline
Regular Poster
 
Join Date: Mar 2010
Location: UK
Posts: 101
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Quote:
Originally Posted by hyleaf
What is the status of this problem?

I had to revert to 5.0.95 too, because of the problems. I got 2 minidumps from the last crashes, where can I send them? Seems like I cannot PM you Marcos.

Thanks.

I too have BSODs with latest version of ESS5 and Sandboxie 3.70. The text says there is a bad_pool_header. As Hyleaf alerted me to this being an ESet problem, I have removed SBIE until a result is found. This occurs on my desktop, but the same set up on my laptop runs together nicely (All running 32 bit versions)

Last edited by bwb1 : June 6th, 2012 at 04:51 AM.
  #9  
Old June 9th, 2012, 04:48 AM
bwb1 bwb1 is offline
Regular Poster
 
Join Date: Mar 2010
Location: UK
Posts: 101
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Quote:
Originally Posted by Marcos
Thank you for the dumps provided, I've passed them to our developers for analysis.

Is there any info on this Marcos please? (FF13/ESS 5.2.9.1/SBIE 3.70 all 32 bit)
  #10  
Old June 10th, 2012, 09:16 AM
Brummelchen Brummelchen is offline
Becky! Internet Mail Support
 
Join Date: Jan 2009
Posts: 880
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Latest Endpoint solution (EEA on win7/64) also crashes bad_pool_header. i hope there is a solution on the run.
  #11  
Old June 14th, 2012, 01:58 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,225
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Quote:
Originally Posted by bwb1
Is there any info on this Marcos please? (FF13/ESS 5.2.9.1/SBIE 3.70 all 32 bit)
Does disabling Device control integration solve the issue for you?
  #12  
Old June 14th, 2012, 01:59 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,225
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Quote:
Originally Posted by Brummelchen
Latest Endpoint solution (EEA on win7/64) also crashes bad_pool_header. i hope there is a solution on the run.
Our developers are on it and trying to figure out the cause of the crash.
  #13  
Old June 15th, 2012, 10:15 AM
Brummelchen Brummelchen is offline
Becky! Internet Mail Support
 
Join Date: Jan 2009
Posts: 880
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Quote:
Does disabling Device control integration solve the issue for you?
i can test this later the day (i hope i find it in the german build)
__________________
-------------------------------------
you can not buy or install security!
  #14  
Old June 18th, 2012, 12:45 PM
hyleaf hyleaf is offline
Infrequent Poster
 
Join Date: May 2012
Posts: 4
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Marcos, I got a bunch more minidumps to help with this.

I had the crashes when using 5.2.9.1 and sandboxie 3.68 while browsing randomly with waterfox (firefox 64 bits) 12. Then I reverted to 5.0.95 and got no more crashes at all.

Some days ago, I updated sandboxie to 3.70, waterfox to 13.0, and then ESS auto-updated to 5.2.9.1. The crashes are almost gone, but I still got it when trying to pay with paypal, twice in a row. All the dumps are as follow:

https://dl.dropbox.com/u/70121451/052412-20326-01.dmp - SB 3.68, Wf 12 and ESS 5.2.9.1
https://dl.dropbox.com/u/70121451/052612-28828-01.dmp - SB 3.68, Wf 12 and ESS 5.2.9.1

https://dl.dropbox.com/u/70121451/061112-19297-01.dmp - SB 3.70, Wf 13 and ESS 5.2.9.1
https://dl.dropbox.com/u/70121451/061112-21652-01.dmp - SB 3.70, Wf 13 and ESS 5.2.9.1

Thanks, hope it helps.

Update:

Decided to do a test.

So, running Sandboxie version 3.72 (64bit version), Waterfox 13 PL1, and ESS 5.2.9.1. When running Waterfox sandboxed, I get a crash when trying to access a paypal page to buy something (for example, when clicking both of the paypal links on this page: http://www.crintsoft.com/MiniLyrics_buy.htm). This is the latest dump: https://dl.dropbox.com/u/70121451/061812-23025-01.dmp

Then, I tried the same pages running not-sandboxed, and got no bluescreens at all.

Anything else I can try to help?

Last edited by hyleaf : June 18th, 2012 at 01:12 PM.
  #15  
Old June 19th, 2012, 04:59 AM
bwb1 bwb1 is offline
Regular Poster
 
Join Date: Mar 2010
Location: UK
Posts: 101
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

5.2.9.1/ FF 13.0.1/SBIE 3.72 crashes the instant FF tried to open in the sandbox. Usual stuff on screen about a bad_pool_header same as always.
  #16  
Old June 19th, 2012, 06:24 AM
traviscn traviscn is offline
Infrequent Poster
 
Join Date: Aug 2003
Posts: 16
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Quote:
Originally Posted by bwb1
5.2.9.1/ FF 13.0.1/SBIE 3.72 crashes the instant FF tried to open in the sandbox. Usual stuff on screen about a bad_pool_header same as always.

Nod32 AV 5.2.9.1/Aurora 15.0a2/SBIE 3.72/Windows 7 Home 64x
no crashes yet.
  #17  
Old June 19th, 2012, 11:00 AM
bwb1 bwb1 is offline
Regular Poster
 
Join Date: Mar 2010
Location: UK
Posts: 101
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Quote:
Originally Posted by Marcos
Does disabling Device control integration solve the issue for you?
Where do I find this please?
  #18  
Old June 24th, 2012, 11:36 AM
bwb1 bwb1 is offline
Regular Poster
 
Join Date: Mar 2010
Location: UK
Posts: 101
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Bump......now my previously OK laptop now crashes with BSOD and the bad_pool_header info, so have uninstalled SBIE on that.
  #19  
Old August 3rd, 2012, 01:09 PM
King Grub's Avatar
King Grub King Grub is offline
Frequent Poster
 
Join Date: Sep 2006
Posts: 758
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Hello!

Was this BSOD also fixed with the 5.0.2126 version? I see information about the Device control BSOD being fixed in the change log, but nothing about this one. I got the bad_pool_header BSOD as the earlier posters in the thread did when using NOD32 with Sandboxie, and since I consider Sandboxie a must, I haven't used NOD32 since (and the bluescreens stopped right away after removing NOD32).
  #20  
Old August 5th, 2012, 11:28 PM
hyleaf hyleaf is offline
Infrequent Poster
 
Join Date: May 2012
Posts: 4
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Quote:
Originally Posted by King Grub
Hello!

Was this BSOD also fixed with the 5.0.2126 version? I see information about the Device control BSOD being fixed in the change log, but nothing about this one. I got the bad_pool_header BSOD as the earlier posters in the thread did when using NOD32 with Sandboxie, and since I consider Sandboxie a must, I haven't used NOD32 since (and the bluescreens stopped right away after removing NOD32).

Same here, had to uninstall ESS until a fix is released. Any word from the developers? Thanks in advance.
  #21  
Old August 8th, 2012, 06:44 AM
King Grub's Avatar
King Grub King Grub is offline
Frequent Poster
 
Join Date: Sep 2006
Posts: 758
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Guess not.
  #22  
Old August 8th, 2012, 09:42 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,225
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Quote:
Originally Posted by King Grub
Hello!
Was this BSOD also fixed with the 5.0.2126 version? I see information about the Device control BSOD being fixed in the change log, but nothing about this one. I got the bad_pool_header BSOD as the earlier posters in the thread did when using NOD32 with Sandboxie, and since I consider Sandboxie a must, I haven't used NOD32 since (and the bluescreens stopped right away after removing NOD32).
Please provide instructions how to reproduce BSOD as I've tried it by opening Firefox in Sandboxie on Win7 x64 as mentioned in another post here but I didn't get any BSOD. I've noticed that the version of Sandboxie that is currently available and that I used for replication was newer than the one mentioned in this thread.
  #23  
Old August 8th, 2012, 11:06 AM
bwb1 bwb1 is offline
Regular Poster
 
Join Date: Mar 2010
Location: UK
Posts: 101
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

I got the BSOD with ESS 5.2.9.1/SBIE 3.72/W7x32/FF13 and 14. I removed SBIE and since then FF13/14 has behaved. The BSOD occurs instantly when you try to open FF in SBIE, and it is the bad_ pool_header matter. This happens on two computers with very similar set ups.

Last edited by bwb1 : August 9th, 2012 at 10:44 AM.
  #24  
Old August 8th, 2012, 11:13 AM
King Grub's Avatar
King Grub King Grub is offline
Frequent Poster
 
Join Date: Sep 2006
Posts: 758
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

For me it wasn't instantly when opening FF, but rather random. It could happen once a day or every other day. After booting up again and visiting the same webpage or doing the same thing in FF, it worked fine. Then a few days later another BSOD with the "bad pool header" pointing at eamonm.sys.

And this on two separate systems, both with Nod32, FF and Sandboxie (including the latest version). Both systems hardware-error free (passes 36 hours of Memtest+, IntelBurnTest with max settings and no problems whatsoever at any other time). Remove Nod32 and the problems went away.

I would really like to use Nod32 again, but I am not prepared to experience more BSODs because of it. There are many good AVs, but only one Sandboxie. That's why I wondered if this issue had been explored and/or corrected with the latest version of the program, even if the release notes didn't say anything about it.
  #25  
Old August 25th, 2012, 12:38 PM
King Grub's Avatar
King Grub King Grub is offline
Frequent Poster
 
Join Date: Sep 2006
Posts: 758
Default Re: eamonm.sys, bluescreen, sandboxie, Adobe

Well, no replies here I guess, but several threads on the Sandboxie forum indicate that the problem is still there, with the latest versions of both products, and it is still the ESET driver that is implacated in the BSOD logs.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:14 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums