AV-rsaenh.dll

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Hello,
IE is blowing up whenever I try to run Windows Update. Having limited
debugging skills, I was hoping someone could help me fix this:

0:000> !analyze -
*******************************************************************************
*
*
* Exception Analysis
*
*

*******************************************************************************


FAULTING_IP:
ntdll!RtlEnterCriticalSection+11
7c901016 f0ff4204 lock inc dword ptr [edx+4]

EXCEPTION_RECORD: ffffffff -- (.exr ffffffffffffffff)
ExceptionAddress: 7c901016 (ntdll!RtlEnterCriticalSection+0x00000011)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000001
Parameter[1]: 0063004c
Attempt to write to address 0063004c

FAULTING_THREAD: 000004c4

DEFAULT_BUCKET_ID: STRING_DEREFERENCE

PROCESS_NAME: iexplore.exe

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced
memo
ry at "0x%08lx". The memory could not be "%s".

WRITE_ADDRESS: 0063004c

BUGCHECK_STR: ACCESS_VIOLATION

LAST_CONTROL_TRANSFER: from 7c80ee07 to 7c901016

STACK_TEXT:
0013c3a8 7c80ee07 00630048 00000000 00630034
ntdll!RtlEnterCriticalSection+0x11
WARNING: Stack unwind information not available. Following frames may be
wrong.
0013c3f4 0ffeb9c4 00630034 00000000 046214e8 kernel32!FindClose+0x30
0013c408 0ffed6c1 04584cfc 00000020 04584ce0 rsaenh!FreeContainerInfo+0xb9
0013c4f0 0ffdd53e 00000001 046214e8 00000020 rsaenh!ReadContainerInfo+0x477
0013c518 0ffdeb3e 04584ce0 046214e8 00000028 rsaenh!OpenUserKeyGroup+0x24
0013c564 0ffded6e 0463ccd8 00000028 0013c59c rsaenh!NTagLogonUser+0x23a
0013c588 77de8307 0013c5e4 0463ccd8 00000028 rsaenh!CPAcquireContext+0x34
0013c650 77de8675 0013c728 0463ccd8 0463cc78
ADVAPI32!CryptAcquireContextA+0x619

0013c6b8 08331088 0013c728 045723c0 082bcc90
ADVAPI32!CryptAcquireContextW+0xa4
0013c820 082ff4db 0013c904 0013cb10 0013caa8
LegitCheckControl!DllUnregisterServ
er+0x65898
0013c824 0013c904 0013cb10 0013caa8 0013cad0
LegitCheckControl!DllUnregisterServ
er+0x33ceb
0013c828 0013cb10 0013caa8 0013cad0 00000000 0x13c904
0013c904 00000000 00000000 00000000 00000000 0x13cb10


FOLLOWUP_IP:
rsaenh!FreeContainerInfo+b9
0ffeb9c4 5f pop edi

SYMBOL_STACK_INDEX: 2

SYMBOL_NAME: rsaenh!FreeContainerInfo+b9

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: rsaenh

IMAGE_NAME: rsaenh.dll

DEBUG_FLR_IMAGE_TIMESTAMP: 40eb5d28

STACK_COMMAND: ~0s ; kb

FAILURE_BUCKET_ID: ACCESS_VIOLATION_rsaenh!FreeContainerInfo+b9

BUCKET_ID: ACCESS_VIOLATION_rsaenh!FreeContainerInfo+b9

Followup: MachineOwner
 
Hi thewanz,

Looks like a "Memory could not be read" error that has been problematic of
the MSN search toolbar, though the newer Google toolbars also have had
similar blocking problems.

Disable all your toolbars (Control Panel>Internet Options - Advanced tab -
uncheck "Enable third-party browser extensions") and then restart IE to see
if the problem persists, then you will know it is a toolbar add-on that is
causing the problem. Uninstall the toolbars and/or check for updates from
the toolbar vendor.

Regards.
thewanz said:
Hello,
IE is blowing up whenever I try to run Windows Update. Having limited
debugging skills, I was hoping someone could help me fix this:

0:000> !analyze -v
*******************************************************************************
*
*
* Exception Analysis
*
*
*
*******************************************************************************


FAULTING_IP:
ntdll!RtlEnterCriticalSection+11
7c901016 f0ff4204 lock inc dword ptr [edx+4]

EXCEPTION_RECORD: ffffffff -- (.exr ffffffffffffffff)
ExceptionAddress: 7c901016 (ntdll!RtlEnterCriticalSection+0x00000011)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000001
Parameter[1]: 0063004c
Attempt to write to address 0063004c

FAULTING_THREAD: 000004c4

DEFAULT_BUCKET_ID: STRING_DEREFERENCE

PROCESS_NAME: iexplore.exe

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx"
referenced
memo
ry at "0x%08lx". The memory could not be "%s".

WRITE_ADDRESS: 0063004c

BUGCHECK_STR: ACCESS_VIOLATION

LAST_CONTROL_TRANSFER: from 7c80ee07 to 7c901016

STACK_TEXT:
0013c3a8 7c80ee07 00630048 00000000 00630034
ntdll!RtlEnterCriticalSection+0x11
WARNING: Stack unwind information not available. Following frames may be
wrong.
0013c3f4 0ffeb9c4 00630034 00000000 046214e8 kernel32!FindClose+0x30
0013c408 0ffed6c1 04584cfc 00000020 04584ce0 rsaenh!FreeContainerInfo+0xb9
0013c4f0 0ffdd53e 00000001 046214e8 00000020
rsaenh!ReadContainerInfo+0x477
0013c518 0ffdeb3e 04584ce0 046214e8 00000028 rsaenh!OpenUserKeyGroup+0x24
0013c564 0ffded6e 0463ccd8 00000028 0013c59c rsaenh!NTagLogonUser+0x23a
0013c588 77de8307 0013c5e4 0463ccd8 00000028 rsaenh!CPAcquireContext+0x34
0013c650 77de8675 0013c728 0463ccd8 0463cc78
ADVAPI32!CryptAcquireContextA+0x619

0013c6b8 08331088 0013c728 045723c0 082bcc90
ADVAPI32!CryptAcquireContextW+0xa4
0013c820 082ff4db 0013c904 0013cb10 0013caa8
LegitCheckControl!DllUnregisterServ
er+0x65898
0013c824 0013c904 0013cb10 0013caa8 0013cad0
LegitCheckControl!DllUnregisterServ
er+0x33ceb
0013c828 0013cb10 0013caa8 0013cad0 00000000 0x13c904
0013c904 00000000 00000000 00000000 00000000 0x13cb10


FOLLOWUP_IP:
rsaenh!FreeContainerInfo+b9
0ffeb9c4 5f pop edi

SYMBOL_STACK_INDEX: 2

SYMBOL_NAME: rsaenh!FreeContainerInfo+b9

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: rsaenh

IMAGE_NAME: rsaenh.dll

DEBUG_FLR_IMAGE_TIMESTAMP: 40eb5d28

STACK_COMMAND: ~0s ; kb

FAILURE_BUCKET_ID: ACCESS_VIOLATION_rsaenh!FreeContainerInfo+b9

BUCKET_ID: ACCESS_VIOLATION_rsaenh!FreeContainerInfo+b9

Followup: MachineOwner
 
I've uninstalled all 3rd party toolbars, rebooted and I get the same break in
the very same place. Any other ideas?

thx,
Wnz

Rob ^_^ said:
Hi thewanz,

Looks like a "Memory could not be read" error that has been problematic of
the MSN search toolbar, though the newer Google toolbars also have had
similar blocking problems.

Disable all your toolbars (Control Panel>Internet Options - Advanced tab -
uncheck "Enable third-party browser extensions") and then restart IE to see
if the problem persists, then you will know it is a toolbar add-on that is
causing the problem. Uninstall the toolbars and/or check for updates from
the toolbar vendor.

Regards.
thewanz said:
Hello,
IE is blowing up whenever I try to run Windows Update. Having limited
debugging skills, I was hoping someone could help me fix this:

0:000> !analyze -v
*******************************************************************************
*
*
* Exception Analysis
*
*
*
*******************************************************************************


FAULTING_IP:
ntdll!RtlEnterCriticalSection+11
7c901016 f0ff4204 lock inc dword ptr [edx+4]

EXCEPTION_RECORD: ffffffff -- (.exr ffffffffffffffff)
ExceptionAddress: 7c901016 (ntdll!RtlEnterCriticalSection+0x00000011)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000001
Parameter[1]: 0063004c
Attempt to write to address 0063004c

FAULTING_THREAD: 000004c4

DEFAULT_BUCKET_ID: STRING_DEREFERENCE

PROCESS_NAME: iexplore.exe

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx"
referenced
memo
ry at "0x%08lx". The memory could not be "%s".

WRITE_ADDRESS: 0063004c

BUGCHECK_STR: ACCESS_VIOLATION

LAST_CONTROL_TRANSFER: from 7c80ee07 to 7c901016

STACK_TEXT:
0013c3a8 7c80ee07 00630048 00000000 00630034
ntdll!RtlEnterCriticalSection+0x11
WARNING: Stack unwind information not available. Following frames may be
wrong.
0013c3f4 0ffeb9c4 00630034 00000000 046214e8 kernel32!FindClose+0x30
0013c408 0ffed6c1 04584cfc 00000020 04584ce0 rsaenh!FreeContainerInfo+0xb9
0013c4f0 0ffdd53e 00000001 046214e8 00000020
rsaenh!ReadContainerInfo+0x477
0013c518 0ffdeb3e 04584ce0 046214e8 00000028 rsaenh!OpenUserKeyGroup+0x24
0013c564 0ffded6e 0463ccd8 00000028 0013c59c rsaenh!NTagLogonUser+0x23a
0013c588 77de8307 0013c5e4 0463ccd8 00000028 rsaenh!CPAcquireContext+0x34
0013c650 77de8675 0013c728 0463ccd8 0463cc78
ADVAPI32!CryptAcquireContextA+0x619

0013c6b8 08331088 0013c728 045723c0 082bcc90
ADVAPI32!CryptAcquireContextW+0xa4
0013c820 082ff4db 0013c904 0013cb10 0013caa8
LegitCheckControl!DllUnregisterServ
er+0x65898
0013c824 0013c904 0013cb10 0013caa8 0013cad0
LegitCheckControl!DllUnregisterServ
er+0x33ceb
0013c828 0013cb10 0013caa8 0013cad0 00000000 0x13c904
0013c904 00000000 00000000 00000000 00000000 0x13cb10


FOLLOWUP_IP:
rsaenh!FreeContainerInfo+b9
0ffeb9c4 5f pop edi

SYMBOL_STACK_INDEX: 2

SYMBOL_NAME: rsaenh!FreeContainerInfo+b9

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: rsaenh

IMAGE_NAME: rsaenh.dll

DEBUG_FLR_IMAGE_TIMESTAMP: 40eb5d28

STACK_COMMAND: ~0s ; kb

FAILURE_BUCKET_ID: ACCESS_VIOLATION_rsaenh!FreeContainerInfo+b9

BUCKET_ID: ACCESS_VIOLATION_rsaenh!FreeContainerInfo+b9

Followup: MachineOwner
 
Back
Top