2

Closed

2.7 FileMon crashes 64-bit processes

description

Hello,

I've downloaded the EasyHook 2.7 libraries and am testing the FileMon.exe app using administrator powershell and ProcessMonitor.exe to find PID's.

I've successfully injected 3 different 32-bit applications. Text gets spammed to the console whenever I create and load files.
Whenever I inject a 64-bit application, the target crashes whenever fileMon executes its callback. Target program says something generic, "blah has stopped working", and powershell doesn't produce output.
Same results for 3.5 and 4.0 binaries.

I'm running a 64-bit version of Windows 8.

Might be related to this bug: http://easyhook.codeplex.com/discussions/442177

Suggestions?
Closed Feb 15, 2014 at 6:05 AM by spazzarama
Fixed in changeset 73837

comments

spazzarama wrote Oct 17, 2013 at 9:34 AM

Yes it is related, and the fix included in that discussion works.

wrote Oct 17, 2013 at 9:34 AM

spazzarama wrote Dec 26, 2013 at 2:38 AM

Actually I think this is a separate error - that discussion mentions a fix for when terminating the application.

spazzarama wrote Feb 6, 2014 at 10:00 PM

Same issue as #24838 - currently not compatible with Windwos 8 64-bit processes

wrote Feb 6, 2014 at 10:01 PM

wrote Feb 15, 2014 at 5:59 AM

Fixed on changeset 73837

wrote Feb 15, 2014 at 6:05 AM