This project is read-only.


2.7 FileMon crashes 64-bit processes



I've downloaded the EasyHook 2.7 libraries and am testing the FileMon.exe app using administrator powershell and ProcessMonitor.exe to find PID's.

I've successfully injected 3 different 32-bit applications. Text gets spammed to the console whenever I create and load files.
Whenever I inject a 64-bit application, the target crashes whenever fileMon executes its callback. Target program says something generic, "blah has stopped working", and powershell doesn't produce output.
Same results for 3.5 and 4.0 binaries.

I'm running a 64-bit version of Windows 8.

Might be related to this bug:

Closed Feb 15, 2014 at 7:05 AM by spazzarama
Fixed in changeset 73837


spazzarama wrote Oct 17, 2013 at 10:34 AM

Yes it is related, and the fix included in that discussion works.

wrote Oct 17, 2013 at 10:34 AM

spazzarama wrote Dec 26, 2013 at 3:38 AM

Actually I think this is a separate error - that discussion mentions a fix for when terminating the application.

spazzarama wrote Feb 6, 2014 at 11:00 PM

Same issue as #24838 - currently not compatible with Windwos 8 64-bit processes

wrote Feb 6, 2014 at 11:01 PM

wrote Feb 15, 2014 at 6:59 AM

Fixed on changeset 73837

wrote Feb 15, 2014 at 7:05 AM