<?xml version="1.0"?><?xml-stylesheet type="text/xsl" href="/rss.xsl"?><rss version="2.0"><channel><title>WehnTrust</title><link>http://wehntrust.codeplex.com/project/feeds/rss</link><description>WehnTrust is a Host-based Intrusion Prevention System &amp;#40;HIPS&amp;#41; for Windows 2000, XP, and Server 2003.  It includes support for exploit mitigations that are designed to make exploitation more difficult by preventing the use of specific exploitation techniques and by making exploitation unreliable.</description><item><title>Source code checked in, #80132</title><link>http://wehntrust.codeplex.com/SourceControl/changeset/changes/80132</link><description>Upgrade&amp;#58; New Version of LabDefaultTemplate.xaml. To upgrade your build definitions, please visit the following link&amp;#58; http&amp;#58;&amp;#47;&amp;#47;go.microsoft.com&amp;#47;fwlink&amp;#47;&amp;#63;LinkId&amp;#61;254563</description><author>Project Collection Service Accounts</author><pubDate>Mon, 01 Oct 2012 21:49:39 GMT</pubDate><guid isPermaLink="false">Source code checked in, #80132 20121001094939P</guid></item><item><title>Source code checked in, #80131</title><link>http://wehntrust.codeplex.com/SourceControl/changeset/changes/80131</link><description>Checked in by server upgrade</description><author>Project Collection Service Accounts</author><pubDate>Mon, 01 Oct 2012 21:43:10 GMT</pubDate><guid isPermaLink="false">Source code checked in, #80131 20121001094310P</guid></item><item><title>Created Issue: Uninstalling, Randcache folder [10504]</title><link>http://wehntrust.codeplex.com/workitem/10504</link><description>After uninstalling WehnTrust I found Randcache folder in windows base folder.&lt;br /&gt;</description><author>merliner</author><pubDate>Mon, 24 Sep 2012 08:17:38 GMT</pubDate><guid isPermaLink="false">Created Issue: Uninstalling, Randcache folder [10504] 20120924081738A</guid></item><item><title>Source code checked in, #55373</title><link>http://wehntrust.codeplex.com/SourceControl/changeset/changes/55373</link><description>Checked in by server upgrade</description><author>_TFSSERVICE</author><pubDate>Mon, 02 Aug 2010 22:49:34 GMT</pubDate><guid isPermaLink="false">Source code checked in, #55373 20100802104934P</guid></item><item><title>Commented Issue: WehnTrust causes a BSOD on Windows XP Home SP3 [2161]</title><link>http://wehntrust.codeplex.com/WorkItem/View.aspx?WorkItemId=2161</link><description>After installing WehnTrust 1.2 and rebooting I get a BSOD &amp;#40;Page Fault in NonPaged Area&amp;#41;. Tried rebooting and still got the same BSOD.&lt;br /&gt;&lt;br /&gt;Rebooted using Last Known Good and got a message from WehnTrust about system files being changed and that it had resynchronized them and needed a reboot. I did and this time the system booted. But when I tried to access the WehnTrust controls through the tray icon got a message that the driver wasn&amp;#39;t properly installed.&lt;br /&gt;&lt;br /&gt;So I decided to uninstall WehnTrust and got a message that the driver failed to uninstall, code 1060.&lt;br /&gt;&lt;br /&gt;I&amp;#39;d like to use this program so what can I do to get it to install properly&amp;#63;&lt;br /&gt;&lt;br /&gt;Thanks&amp;#33;&lt;br /&gt;Comments: ** Comment from web user: scott_hardy ** &lt;p&gt;I had a somewhat uglier version of this.&lt;/p&gt;&lt;p&gt;Last week I installed wehntrust on a dual-boot XPSP3&amp;#47;Linux system, running on an AMD-based Acer Aspire 5516 laptop. On rebooting XP, got a BSOD for maybe an 8th of a second, followed by another reboot. Retries produced identical results. I had to go into safe mode and restore in order to be able to use the XP side of the system again. &lt;/p&gt;</description><author>scott_hardy</author><pubDate>Wed, 24 Feb 2010 05:40:54 GMT</pubDate><guid isPermaLink="false">Commented Issue: WehnTrust causes a BSOD on Windows XP Home SP3 [2161] 20100224054054A</guid></item><item><title>Created Issue: WehnTrust.exe crashed</title><link>http://wehntrust.codeplex.com/WorkItem/View.aspx?WorkItemId=3576</link><description>v1.2 crashed&lt;br /&gt;crashdump attached&lt;br /&gt;</description><author>stephendhill</author><pubDate>Sun, 19 Apr 2009 17:52:33 GMT</pubDate><guid isPermaLink="false">Created Issue: WehnTrust.exe crashed 20090419055233P</guid></item><item><title>Created Issue: SearchProtocolHost.exe crashes</title><link>http://wehntrust.codeplex.com/WorkItem/View.aspx?WorkItemId=3575</link><description>SearchProtocolHost.exe crashes with v1.2&amp;#58;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Microsoft &amp;#40;R&amp;#41; DrWtsn32&lt;br /&gt;Copyright &amp;#40;C&amp;#41; 1985-2001 Microsoft Corp. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Application exception occurred&amp;#58;&lt;br /&gt;        App&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;SearchProtocolHost.exe &amp;#40;pid&amp;#61;1728&amp;#41;&lt;br /&gt;        When&amp;#58; 19&amp;#47;04&amp;#47;2009 &amp;#64; 17&amp;#58;33&amp;#58;43.864&lt;br /&gt;        Exception number&amp;#58; c0000005 &amp;#40;access violation&amp;#41;&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; System Information &amp;#60;----&amp;#42;&lt;br /&gt;        Computer Name&amp;#58; HILLLAP1&lt;br /&gt;        User Name&amp;#58; Administrator&lt;br /&gt;        Terminal Session Id&amp;#58; 0&lt;br /&gt;        Number of Processors&amp;#58; 2&lt;br /&gt;        Processor Type&amp;#58; x86 Family 15 Model 2 Stepping 9&lt;br /&gt;        Windows Version&amp;#58; 5.1&lt;br /&gt;        Current Build&amp;#58; 2600&lt;br /&gt;        Service Pack&amp;#58; 3&lt;br /&gt;        Current Type&amp;#58; Multiprocessor Free&lt;br /&gt;        Registered Organization&amp;#58; &lt;br /&gt;        Registered Owner&amp;#58; Stephen Hill&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; Task List &amp;#60;----&amp;#42;&lt;br /&gt;   0 System Process&lt;br /&gt;   4 System&lt;br /&gt; 552 smss.exe&lt;br /&gt;1148 csrss.exe&lt;br /&gt;1176 winlogon.exe&lt;br /&gt;1228 services.exe&lt;br /&gt;1240 lsass.exe&lt;br /&gt;1396 Ati2evxx.exe&lt;br /&gt;1412 svchost.exe&lt;br /&gt;1488 svchost.exe&lt;br /&gt;1544 svchost.exe&lt;br /&gt;1624 svchost.exe&lt;br /&gt;1884 svchost.exe&lt;br /&gt; 292 spoolsv.exe&lt;br /&gt; 424 sched.exe&lt;br /&gt; 540 svchost.exe&lt;br /&gt; 992 GoogleUpdate.exe&lt;br /&gt; 796 avguard.exe&lt;br /&gt; 820 btwdins.exe&lt;br /&gt; 896 fsssvc.exe&lt;br /&gt;1524 jqs.exe&lt;br /&gt;2056 SeaPort.exe&lt;br /&gt;2296 SMAgent.exe&lt;br /&gt;2364 svchost.exe&lt;br /&gt;2448 WehnServ.exe&lt;br /&gt;2668 SearchIndexer.exe&lt;br /&gt;2740 CALMAIN.exe&lt;br /&gt;2768 fxssvc.exe&lt;br /&gt;1408 alg.exe&lt;br /&gt;2168 Ati2evxx.exe&lt;br /&gt;2856 Explorer.EXE&lt;br /&gt;1688 SOUNDMAN.EXE&lt;br /&gt;1932 SMax4PNP.exe&lt;br /&gt; 812 AGRSMMSG.exe&lt;br /&gt;3572 avgnt.exe&lt;br /&gt;1064 VCDDaemon.exe&lt;br /&gt;1300 fsui.exe&lt;br /&gt;4080 jusched.exe&lt;br /&gt;1004 ctfmon.exe&lt;br /&gt;1016 BTTray.exe&lt;br /&gt;2936 WindowsSearch.exe&lt;br /&gt; 656 BTSTAC&amp;#126;1.EXE&lt;br /&gt;3716 iexplore.exe&lt;br /&gt;2932 iexplore.exe&lt;br /&gt; 868 taskmgr.exe&lt;br /&gt;4060 Explorer.EXE&lt;br /&gt;3796 udefrag-gui.exe&lt;br /&gt;3384 cmd.exe&lt;br /&gt; 400 ultradefrag.exe&lt;br /&gt;1732 firefox.exe&lt;br /&gt;1728 SearchProtocolHost.exe&lt;br /&gt;3748 drwtsn32.exe&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; Module List &amp;#60;----&amp;#42;&lt;br /&gt;&amp;#40;000000006ce90000 - 000000006cf42000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;ntdll.dll&lt;br /&gt;&amp;#40;000000006d2c0000 - 000000006d309000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;GDI32.dll&lt;br /&gt;&amp;#40;000000006d310000 - 000000006d406000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;kernel32.dll&lt;br /&gt;&amp;#40;000000006d410000 - 000000006d4a1000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;USER32.dll&lt;br /&gt;&amp;#40;000000006d4b0000 - 000000006d54b000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;ADVAPI32.dll&lt;br /&gt;&amp;#40;000000006d550000 - 000000006d5e2000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;RPCRT4.dll&lt;br /&gt;&amp;#40;000000006d5f0000 - 000000006d601000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;Secur32.dll&lt;br /&gt;&amp;#40;000000006d630000 - 000000006d688000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;msvcrt.dll&lt;br /&gt;&amp;#40;000000006d690000 - 000000006d725000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;CRYPT32.dll&lt;br /&gt;&amp;#40;000000006d730000 - 000000006d742000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;MSASN1.dll&lt;br /&gt;&amp;#40;000000006d770000 - 000000006d7c5000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;NETAPI32.dll&lt;br /&gt;&amp;#40;000000006d9b0000 - 000000006d9b8000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;VERSION.dll&lt;br /&gt;&amp;#40;000000006dac0000 - 000000006daee000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;WINTRUST.dll&lt;br /&gt;&amp;#40;000000006daf0000 - 000000006db18000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;IMAGEHLP.dll&lt;br /&gt;&amp;#40;000000006db50000 - 000000006db6d000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;IMM32.DLL&lt;br /&gt;&amp;#40;000000006dc80000 - 000000006dd1a000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;comctl32.dll&lt;br /&gt;&amp;#40;000000006ddb0000 - 000000006e5c7000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;SHELL32.dll&lt;br /&gt;&amp;#40;000000006e5d0000 - 000000006e646000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;SHLWAPI.dll&lt;br /&gt;&amp;#40;000000006e780000 - 000000006e883000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;WinSxS&amp;#92;x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83&amp;#92;comctl32.dll&lt;br /&gt;&amp;#40;000000006e900000 - 000000006ea3d000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;ole32.dll&lt;br /&gt;&amp;#40;000000006ea40000 - 000000006ea62000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;Apphelp.dll&lt;br /&gt;&amp;#40;000000006efc0000 - 000000006f04b000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;OLEAUT32.dll&lt;br /&gt;&amp;#40;0000000072960000 - 0000000072966000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;MSSHooks.dll&lt;br /&gt;&amp;#40;0000000074930000 - 0000000074ab5000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;TQUERY.DLL&lt;br /&gt;&amp;#40;0000000074d30000 - 0000000074deb000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;PROPSYS.dll&lt;br /&gt;&amp;#40;0000000078060000 - 0000000078090000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;SearchProtocolHost.exe&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; State Dump for Thread Id 0x8d8 &amp;#60;----&amp;#42;&lt;br /&gt;&lt;br /&gt;eax&amp;#61;00000000 ebx&amp;#61;7ffdd000 ecx&amp;#61;47a0ffb0 edx&amp;#61;6ce9e514 esi&amp;#61;4d5ab89c edi&amp;#61;2a38e228&lt;br /&gt;eip&amp;#61;77c7c919 esp&amp;#61;47a0ffc4 ebp&amp;#61;47a0fff0 iopl&amp;#61;0         nv up ei pl zr na po nc&lt;br /&gt;cs&amp;#61;001b  ss&amp;#61;0023  ds&amp;#61;0023  es&amp;#61;0023  fs&amp;#61;003b  gs&amp;#61;0000             efl&amp;#61;00000246&lt;br /&gt;&lt;br /&gt;function&amp;#58; &amp;#60;nosymbols&amp;#62;&lt;br /&gt;No prior disassembly possible&lt;br /&gt;        77c7c919 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c91b &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c91d &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c91f &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c921 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c923 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c925 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c927 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c929 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;FAULT -&amp;#62;77c7c919 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;Error 0x00000001&lt;br /&gt;        77c7c91b &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c91d &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c91f &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c921 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c923 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c925 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c927 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c929 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c92b &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        77c7c92d &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; Stack Back Trace &amp;#60;----&amp;#42;&lt;br /&gt;&amp;#42;&amp;#42;&amp;#42; ERROR&amp;#58; Symbol file could not be found.  Defaulted to export symbols for C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;kernel32.dll - &lt;br /&gt;WARNING&amp;#58; Stack unwind information not available. Following frames may be wrong.&lt;br /&gt;ChildEBP RetAddr  Args to Child              &lt;br /&gt;47a0ffc0 6d327077 2a38e228 4d5ab89c 7ffdd000 0x77c7c919&lt;br /&gt;47a0fff0 00000000 77c7c919 00000000 78746341 kernel32&amp;#33;RegisterWaitForInputIdle&amp;#43;0x49&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; Raw Stack Dump &amp;#60;----&amp;#42;&lt;br /&gt;0000000047a0ffc4  77 70 32 6d 28 e2 38 2a - 9c b8 5a 4d 00 d0 fd 7f  wp2m&amp;#40;.8&amp;#42;..ZM....&lt;br /&gt;0000000047a0ffd4  05 00 00 c0 c8 ff a0 47 - e8 fb a0 47 1c c0 f6 6c  .......G...G...l&lt;br /&gt;0000000047a0ffe4  d8 9a 34 6d 80 70 32 6d - 00 00 00 00 00 00 00 00  ..4m.p2m........&lt;br /&gt;0000000047a0fff4  00 00 00 00 19 c9 c7 77 - 00 00 00 00 41 63 74 78  .......w....Actx&lt;br /&gt;0000000047a10004  20 00 00 00 01 00 00 00 - 98 24 00 00 c4 00 00 00   ........&amp;#36;......&lt;br /&gt;0000000047a10014  00 00 00 00 20 00 00 00 - 00 00 00 00 14 00 00 00  .... ...........&lt;br /&gt;0000000047a10024  01 00 00 00 06 00 00 00 - 34 00 00 00 14 01 00 00  ........4.......&lt;br /&gt;0000000047a10034  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................&lt;br /&gt;0000000047a10044  00 00 00 00 00 00 00 00 - 02 00 00 00 00 00 00 00  ................&lt;br /&gt;0000000047a10054  00 00 00 00 00 00 00 00 - 14 02 00 00 9c 01 00 00  ................&lt;br /&gt;0000000047a10064  00 00 00 00 5b 49 59 2d - b0 03 00 00 32 00 00 00  ....&amp;#91;IY-....2...&lt;br /&gt;0000000047a10074  e4 03 00 00 d2 02 00 00 - 00 00 00 00 e4 02 02 83  ................&lt;br /&gt;0000000047a10084  b8 06 00 00 46 00 00 00 - 00 07 00 00 ea 02 00 00  ....F...........&lt;br /&gt;0000000047a10094  00 00 00 00 d2 d5 8c d1 - ec 09 00 00 46 00 00 00  ............F...&lt;br /&gt;0000000047a100a4  34 0a 00 00 ea 02 00 00 - 00 00 00 00 2e ad 6a d8  4.............j.&lt;br /&gt;0000000047a100b4  20 0d 00 00 46 00 00 00 - 68 0d 00 00 04 03 00 00   ...F...h.......&lt;br /&gt;0000000047a100c4  10 00 00 00 04 00 00 00 - d4 00 00 00 02 00 00 00  ................&lt;br /&gt;0000000047a100d4  01 00 00 00 14 01 00 00 - 8c 0f 00 00 01 00 00 00  ................&lt;br /&gt;0000000047a100e4  02 00 00 00 a0 10 00 00 - 2c 03 00 00 01 00 00 00  ........,.......&lt;br /&gt;0000000047a100f4  04 00 00 00 cc 13 00 00 - 50 10 00 00 02 00 00 00  ........P.......&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; State Dump for Thread Id 0x470 &amp;#60;----&amp;#42;&lt;br /&gt;&lt;br /&gt;eax&amp;#61;00000000 ebx&amp;#61;4838fed0 ecx&amp;#61;4838ff7c edx&amp;#61;00000000 esi&amp;#61;00000000 edi&amp;#61;7ffdd000&lt;br /&gt;eip&amp;#61;6ce9e514 esp&amp;#61;4838fea8 ebp&amp;#61;4838ff44 iopl&amp;#61;0         nv up ei pl zr na po nc&lt;br /&gt;cs&amp;#61;001b  ss&amp;#61;0023  ds&amp;#61;0023  es&amp;#61;0023  fs&amp;#61;003b  gs&amp;#61;0000             efl&amp;#61;00000246&lt;br /&gt;&lt;br /&gt;&amp;#42;&amp;#42;&amp;#42; ERROR&amp;#58; Symbol file could not be found.  Defaulted to export symbols for C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;ntdll.dll - &lt;br /&gt;function&amp;#58; ntdll&amp;#33;KiFastSystemCallRet&lt;br /&gt;        6ce9e4fa e829000000       call    ntdll&amp;#33;RtlRaiseException &amp;#40;6ce9e528&amp;#41;&lt;br /&gt;        6ce9e4ff 8b0424           mov     eax,&amp;#91;esp&amp;#93;&lt;br /&gt;        6ce9e502 8be5             mov     esp,ebp&lt;br /&gt;        6ce9e504 5d               pop     ebp&lt;br /&gt;        6ce9e505 c3               ret&lt;br /&gt;        6ce9e506 8da42400000000   lea     esp,&amp;#91;esp&amp;#93;&lt;br /&gt;        6ce9e50d 8d4900           lea     ecx,&amp;#91;ecx&amp;#93;&lt;br /&gt;        ntdll&amp;#33;KiFastSystemCall&amp;#58;&lt;br /&gt;        6ce9e510 8bd4             mov     edx,esp&lt;br /&gt;        6ce9e512 0f34             sysenter&lt;br /&gt;        ntdll&amp;#33;KiFastSystemCallRet&amp;#58;&lt;br /&gt;        6ce9e514 c3               ret&lt;br /&gt;        6ce9e515 8da42400000000   lea     esp,&amp;#91;esp&amp;#93;&lt;br /&gt;        6ce9e51c 8d642400         lea     esp,&amp;#91;esp&amp;#93;&lt;br /&gt;        ntdll&amp;#33;KiIntSystemCall&amp;#58;&lt;br /&gt;        6ce9e520 8d542408         lea     edx,&amp;#91;esp&amp;#43;0x8&amp;#93;&lt;br /&gt;        6ce9e524 cd2e             int     2e&lt;br /&gt;        6ce9e526 c3               ret&lt;br /&gt;        6ce9e527 90               nop&lt;br /&gt;        ntdll&amp;#33;RtlRaiseException&amp;#58;&lt;br /&gt;        6ce9e528 55               push    ebp&lt;br /&gt;        6ce9e529 8bec             mov     ebp,esp&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; Stack Back Trace &amp;#60;----&amp;#42;&lt;br /&gt;&amp;#42;&amp;#42;&amp;#42; ERROR&amp;#58; Symbol file could not be found.  Defaulted to export symbols for C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;ADVAPI32.dll - &lt;br /&gt;WARNING&amp;#58; Stack unwind information not available. Following frames may be wrong.&lt;br /&gt;ChildEBP RetAddr  Args to Child              &lt;br /&gt;4838ff44 6d4d8631 00000002 4838ff6c 00000000 ntdll&amp;#33;KiFastSystemCallRet&lt;br /&gt;4838ffb4 6d31b729 00000000 6cea3bbf 00000000 ADVAPI32&amp;#33;WmiFreeBuffer&amp;#43;0x24e&lt;br /&gt;4838ffec 00000000 6d4d848a 00000000 00000000 kernel32&amp;#33;GetModuleFileNameA&amp;#43;0x1ba&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; Raw Stack Dump &amp;#60;----&amp;#42;&lt;br /&gt;000000004838fea8  4a df e9 6c 90 95 31 6d - 02 00 00 00 d0 fe 38 48  J..l..1m......8H&lt;br /&gt;000000004838feb8  01 00 00 00 01 00 00 00 - 04 ff 38 48 e0 2e 22 48  ..........8H..&amp;#34;H&lt;br /&gt;000000004838fec8  60 66 52 6d 00 10 00 00 - 50 00 00 00 5c 00 00 00  &amp;#96;fRm....P...&amp;#92;...&lt;br /&gt;000000004838fed8  c0 fe 38 48 d0 39 50 c0 - dc ff 38 48 d8 9a 34 6d  ..8H.9P...8H..4m&lt;br /&gt;000000004838fee8  50 0b 32 6d 00 10 00 00 - 14 00 00 00 01 00 00 00  P.2m............&lt;br /&gt;000000004838fef8  00 00 00 00 00 00 00 00 - 10 00 00 00 00 a2 2f 4d  ..............&amp;#47;M&lt;br /&gt;000000004838ff08  ff ff ff ff 00 10 00 00 - 00 d0 fd 7f 00 e0 fd 7f  ................&lt;br /&gt;000000004838ff18  dc ff 38 48 04 ff 38 48 - d0 fe 38 48 06 00 00 00  ..8H..8H..8H....&lt;br /&gt;000000004838ff28  02 00 00 00 c4 fe 38 48 - 06 00 00 00 dc ff 38 48  ......8H......8H&lt;br /&gt;000000004838ff38  d8 9a 34 6d 80 96 31 6d - 00 00 00 00 b4 ff 38 48  ..4m..1m......8H&lt;br /&gt;000000004838ff48  31 86 4d 6d 02 00 00 00 - 6c ff 38 48 00 00 00 00  1.Mm....l.8H....&lt;br /&gt;000000004838ff58  e0 93 04 00 01 00 00 00 - bf 3b ea 6c 00 00 00 00  .........&amp;#59;.l....&lt;br /&gt;000000004838ff68  00 00 00 00 50 00 00 00 - 5c 00 00 00 00 10 00 00  ....P...&amp;#92;.......&lt;br /&gt;000000004838ff78  e0 2e 22 48 00 00 00 00 - 00 10 00 00 e8 3e 22 48  ..&amp;#34;H.........&amp;#62;&amp;#34;H&lt;br /&gt;000000004838ff88  00 67 52 6d 28 00 00 00 - e0 66 52 6d 00 10 00 00  .gRm&amp;#40;....fRm....&lt;br /&gt;000000004838ff98  00 00 00 00 00 67 52 6d - e0 2e 22 48 e0 66 52 6d  .....gRm..&amp;#34;H.fRm&lt;br /&gt;000000004838ffa8  e5 03 00 00 00 10 00 00 - e8 3e 22 48 ec ff 38 48  .........&amp;#62;&amp;#34;H..8H&lt;br /&gt;000000004838ffb8  29 b7 31 6d 00 00 00 00 - bf 3b ea 6c 00 00 00 00  &amp;#41;.1m.....&amp;#59;.l....&lt;br /&gt;000000004838ffc8  00 00 00 00 00 e0 fd 7f - 14 6d 2b c0 c0 ff 38 48  .........m&amp;#43;...8H&lt;br /&gt;000000004838ffd8  28 c3 0a 87 1c c0 f6 6c - d8 9a 34 6d 30 b7 31 6d  &amp;#40;......l..4m0.1m&lt;br /&gt;</description><author>stephendhill</author><pubDate>Sun, 19 Apr 2009 16:36:16 GMT</pubDate><guid isPermaLink="false">Created Issue: SearchProtocolHost.exe crashes 20090419043616P</guid></item><item><title>Created Issue: msfeedssync.exe crashes</title><link>http://wehntrust.codeplex.com/WorkItem/View.aspx?WorkItemId=3574</link><description>msfeedssync.exe crashes with wehntrust v1.2.&lt;br /&gt;user.dmp file attached&lt;br /&gt;&lt;br /&gt;Dr Watson log&amp;#58;&lt;br /&gt;&lt;br /&gt;Microsoft &amp;#40;R&amp;#41; DrWtsn32&lt;br /&gt;Copyright &amp;#40;C&amp;#41; 1985-2001 Microsoft Corp. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Application exception occurred&amp;#58;&lt;br /&gt;        App&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;msfeedssync.exe &amp;#40;pid&amp;#61;2536&amp;#41;&lt;br /&gt;        When&amp;#58; 19&amp;#47;04&amp;#47;2009 &amp;#64; 10&amp;#58;35&amp;#58;19.336&lt;br /&gt;        Exception number&amp;#58; c0000005 &amp;#40;access violation&amp;#41;&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; System Information &amp;#60;----&amp;#42;&lt;br /&gt;        Computer Name&amp;#58; HILLLAP1&lt;br /&gt;        User Name&amp;#58; Administrator&lt;br /&gt;        Terminal Session Id&amp;#58; 0&lt;br /&gt;        Number of Processors&amp;#58; 2&lt;br /&gt;        Processor Type&amp;#58; x86 Family 15 Model 2 Stepping 9&lt;br /&gt;        Windows Version&amp;#58; 5.1&lt;br /&gt;        Current Build&amp;#58; 2600&lt;br /&gt;        Service Pack&amp;#58; 3&lt;br /&gt;        Current Type&amp;#58; Multiprocessor Free&lt;br /&gt;        Registered Organization&amp;#58; &lt;br /&gt;        Registered Owner&amp;#58; Stephen Hill&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; Task List &amp;#60;----&amp;#42;&lt;br /&gt;   0 System Process&lt;br /&gt;   4 System&lt;br /&gt; 552 smss.exe&lt;br /&gt; 604 csrss.exe&lt;br /&gt;1180 winlogon.exe&lt;br /&gt;1228 services.exe&lt;br /&gt;1240 lsass.exe&lt;br /&gt;1412 Ati2evxx.exe&lt;br /&gt;1428 svchost.exe&lt;br /&gt;1524 svchost.exe&lt;br /&gt;1580 svchost.exe&lt;br /&gt;1848 svchost.exe&lt;br /&gt;1900 svchost.exe&lt;br /&gt; 488 spoolsv.exe&lt;br /&gt; 580 sched.exe&lt;br /&gt; 736 svchost.exe&lt;br /&gt; 948 Ati2evxx.exe&lt;br /&gt;1004 GoogleUpdate.exe&lt;br /&gt;1084 Explorer.EXE&lt;br /&gt;1808 SOUNDMAN.EXE&lt;br /&gt;1704 SMax4PNP.exe&lt;br /&gt;1920 AGRSMMSG.exe&lt;br /&gt;1936 avgnt.exe&lt;br /&gt;1968 VCDDaemon.exe&lt;br /&gt;1988 fsui.exe&lt;br /&gt;1996 jusched.exe&lt;br /&gt;2020 ctfmon.exe&lt;br /&gt; 208 BTTray.exe&lt;br /&gt; 220 WindowsSearch.exe&lt;br /&gt; 276 Explorer.EXE&lt;br /&gt; 632 avguard.exe&lt;br /&gt; 660 btwdins.exe&lt;br /&gt; 740 fsssvc.exe&lt;br /&gt; 832 BTSTAC&amp;#126;1.EXE&lt;br /&gt;1672 jqs.exe&lt;br /&gt;2088 firefox.exe&lt;br /&gt;2176 SeaPort.exe&lt;br /&gt;2428 SMAgent.exe&lt;br /&gt;2516 svchost.exe&lt;br /&gt;2620 WehnServ.exe&lt;br /&gt;2792 SearchIndexer.exe&lt;br /&gt;2920 CALMAIN.exe&lt;br /&gt;2968 fxssvc.exe&lt;br /&gt; 800 alg.exe&lt;br /&gt; 920 SearchProtocolHost.exe&lt;br /&gt;1352 taskmgr.exe&lt;br /&gt;1492 wuauclt.exe&lt;br /&gt;3300 udefrag-gui.exe&lt;br /&gt;3276 SearchFilterHost.exe&lt;br /&gt;1560 cmd.exe&lt;br /&gt;3608 ultradefrag.exe&lt;br /&gt;1000 msiexec.exe&lt;br /&gt;2536 msfeedssync.exe&lt;br /&gt; 628 dwwin.exe&lt;br /&gt;3264 drwtsn32.exe&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; Module List &amp;#60;----&amp;#42;&lt;br /&gt;&amp;#40;0000000067c30000 - 0000000067c36000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;msfeedssync.exe&lt;br /&gt;&amp;#40;0000000079c90000 - 0000000079d42000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;ntdll.dll&lt;br /&gt;&amp;#40;000000007a060000 - 000000007a0a9000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;GDI32.dll&lt;br /&gt;&amp;#40;000000007a0b0000 - 000000007a1a6000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;kernel32.dll&lt;br /&gt;&amp;#40;000000007a1b0000 - 000000007a241000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;USER32.dll&lt;br /&gt;&amp;#40;000000007a250000 - 000000007a2eb000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;ADVAPI32.dll&lt;br /&gt;&amp;#40;000000007a2f0000 - 000000007a382000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;RPCRT4.dll&lt;br /&gt;&amp;#40;000000007a390000 - 000000007a3a1000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;Secur32.dll&lt;br /&gt;&amp;#40;000000007a3d0000 - 000000007a428000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;msvcrt.dll&lt;br /&gt;&amp;#40;000000007a750000 - 000000007a758000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;VERSION.dll&lt;br /&gt;&amp;#40;000000007a870000 - 000000007a88d000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;IMM32.DLL&lt;br /&gt;&amp;#40;000000007a9a0000 - 000000007aa3a000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;comctl32.dll&lt;br /&gt;&amp;#40;000000007b2f0000 - 000000007b366000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;SHLWAPI.dll&lt;br /&gt;&amp;#40;000000007b460000 - 000000007b563000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;WinSxS&amp;#92;x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83&amp;#92;comctl32.dll&lt;br /&gt;&amp;#40;000000007b5e0000 - 000000007b71d000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;ole32.dll&lt;br /&gt;&amp;#40;000000007b720000 - 000000007b742000&amp;#58; C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;Apphelp.dll&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; State Dump for Thread Id 0x284 &amp;#60;----&amp;#42;&lt;br /&gt;&lt;br /&gt;eax&amp;#61;00000000 ebx&amp;#61;7ffd7000 ecx&amp;#61;2a81ffb0 edx&amp;#61;79c9e514 esi&amp;#61;47cef0dc edi&amp;#61;4407f3b0&lt;br /&gt;eip&amp;#61;78b91c85 esp&amp;#61;2a81ffc4 ebp&amp;#61;2a81fff0 iopl&amp;#61;0         nv up ei pl zr na po nc&lt;br /&gt;cs&amp;#61;001b  ss&amp;#61;0023  ds&amp;#61;0023  es&amp;#61;0023  fs&amp;#61;003b  gs&amp;#61;0000             efl&amp;#61;00000246&lt;br /&gt;&lt;br /&gt;function&amp;#58; &amp;#60;nosymbols&amp;#62;&lt;br /&gt;No prior disassembly possible&lt;br /&gt;        78b91c85 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c87 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c89 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c8b &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c8d &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c8f &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c91 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c93 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c95 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;FAULT -&amp;#62;78b91c85 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;Error 0x00000001&lt;br /&gt;        78b91c87 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c89 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c8b &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c8d &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c8f &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c91 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c93 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c95 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c97 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;        78b91c99 &amp;#63;&amp;#63;               &amp;#63;&amp;#63;&amp;#63;&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; Stack Back Trace &amp;#60;----&amp;#42;&lt;br /&gt;&amp;#42;&amp;#42;&amp;#42; ERROR&amp;#58; Symbol file could not be found.  Defaulted to export symbols for C&amp;#58;&amp;#92;WINDOWS&amp;#92;system32&amp;#92;kernel32.dll - &lt;br /&gt;WARNING&amp;#58; Stack unwind information not available. Following frames may be wrong.&lt;br /&gt;ChildEBP RetAddr  Args to Child              &lt;br /&gt;2a81ffc0 7a0c7077 4407f3b0 47cef0dc 7ffd7000 0x78b91c85&lt;br /&gt;2a81fff0 00000000 78b91c85 00000000 78746341 kernel32&amp;#33;RegisterWaitForInputIdle&amp;#43;0x49&lt;br /&gt;&lt;br /&gt;&amp;#42;----&amp;#62; Raw Stack Dump &amp;#60;----&amp;#42;&lt;br /&gt;000000002a81ffc4  77 70 0c 7a b0 f3 07 44 - dc f0 ce 47 00 70 fd 7f  wp.z...D...G.p..&lt;br /&gt;000000002a81ffd4  05 00 00 c0 c8 ff 81 2a - e8 fb 81 2a 1c c0 d6 79  .......&amp;#42;...&amp;#42;...y&lt;br /&gt;000000002a81ffe4  d8 9a 0e 7a 80 70 0c 7a - 00 00 00 00 00 00 00 00  ...z.p.z........&lt;br /&gt;000000002a81fff4  00 00 00 00 85 1c b9 78 - 00 00 00 00 41 63 74 78  .......x....Actx&lt;br /&gt;000000002a820004  20 00 00 00 01 00 00 00 - 98 24 00 00 c4 00 00 00   ........&amp;#36;......&lt;br /&gt;000000002a820014  00 00 00 00 20 00 00 00 - 00 00 00 00 14 00 00 00  .... ...........&lt;br /&gt;000000002a820024  01 00 00 00 06 00 00 00 - 34 00 00 00 14 01 00 00  ........4.......&lt;br /&gt;000000002a820034  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................&lt;br /&gt;000000002a820044  00 00 00 00 00 00 00 00 - 02 00 00 00 00 00 00 00  ................&lt;br /&gt;000000002a820054  00 00 00 00 00 00 00 00 - 14 02 00 00 9c 01 00 00  ................&lt;br /&gt;000000002a820064  00 00 00 00 5b 49 59 2d - b0 03 00 00 32 00 00 00  ....&amp;#91;IY-....2...&lt;br /&gt;000000002a820074  e4 03 00 00 d2 02 00 00 - 00 00 00 00 e4 02 02 83  ................&lt;br /&gt;000000002a820084  b8 06 00 00 46 00 00 00 - 00 07 00 00 ea 02 00 00  ....F...........&lt;br /&gt;000000002a820094  00 00 00 00 d2 d5 8c d1 - ec 09 00 00 46 00 00 00  ............F...&lt;br /&gt;000000002a8200a4  34 0a 00 00 ea 02 00 00 - 00 00 00 00 2e ad 6a d8  4.............j.&lt;br /&gt;000000002a8200b4  20 0d 00 00 46 00 00 00 - 68 0d 00 00 04 03 00 00   ...F...h.......&lt;br /&gt;000000002a8200c4  10 00 00 00 04 00 00 00 - d4 00 00 00 02 00 00 00  ................&lt;br /&gt;000000002a8200d4  01 00 00 00 14 01 00 00 - 8c 0f 00 00 01 00 00 00  ................&lt;br /&gt;000000002a8200e4  02 00 00 00 a0 10 00 00 - 2c 03 00 00 01 00 00 00  ........,.......&lt;br /&gt;000000002a8200f4  04 00 00 00 cc 13 00 00 - 50 10 00 00 02 00 00 00  ........P.......&lt;br /&gt;</description><author>stephendhill</author><pubDate>Sun, 19 Apr 2009 09:37:58 GMT</pubDate><guid isPermaLink="false">Created Issue: msfeedssync.exe crashes 20090419093758A</guid></item><item><title>Commented Issue: wuauclt.exe crashes</title><link>http://www.codeplex.com/wehntrust/WorkItem/View.aspx?WorkItemId=2069</link><description>OS&amp;#58; Windows XP SP2&amp;#47;SP3&lt;br /&gt;Version&amp;#58; WehnTrust 1.2&lt;br /&gt;&lt;br /&gt;wuauclt.exe crashes 3 times in a row about every 10-20 minutes unless exempted from ASLR. I can &amp;#34;reproduce&amp;#34; this about 50&amp;#37; of the time on my home and work machines.&lt;br /&gt;&lt;br /&gt;I will reply with a screenshot the next time it happens.&lt;br /&gt;Comments: ** Comment from web user: slow ** &lt;p&gt;Can you throw us specific instructions or give everybody a link with direction on how to configure your environment to get these please.&lt;/p&gt;</description><author>slow</author><pubDate>Tue, 02 Sep 2008 15:43:40 GMT</pubDate><guid isPermaLink="false">Commented Issue: wuauclt.exe crashes 20080902034340P</guid></item><item><title>Created Issue: WehnTrust causes a BSOD on Windows XP Home SP3</title><link>http://www.codeplex.com/wehntrust/WorkItem/View.aspx?WorkItemId=2161</link><description>After installing WehnTrust 1.2 and rebooting I get a BSOD &amp;#40;Page Fault in NonPaged Area&amp;#41;. Tried rebooting and still got the same BSOD.&lt;br /&gt;&lt;br /&gt;Rebooted using Last Known Good and got a message from WehnTrust about system files being changed and that it had resynchronized them and needed a reboot. I did and this time the system booted. But when I tried to access the WehnTrust controls through the tray icon got a message that the driver wasn&amp;#39;t properly installed.&lt;br /&gt;&lt;br /&gt;So I decided to uninstall WehnTrust and got a message that the driver failed to uninstall, code 1060.&lt;br /&gt;&lt;br /&gt;I&amp;#39;d like to use this program so what can I do to get it to install properly&amp;#63;&lt;br /&gt;&lt;br /&gt;Thanks&amp;#33;&lt;br /&gt;</description><author>Tipperton</author><pubDate>Sat, 23 Aug 2008 15:02:08 GMT</pubDate><guid isPermaLink="false">Created Issue: WehnTrust causes a BSOD on Windows XP Home SP3 20080823030208P</guid></item><item><title>Commented Issue: Crashdump</title><link>http://www.codeplex.com/wehntrust/WorkItem/View.aspx?WorkItemId=2086</link><description>Can you upload a crashdump&amp;#63;&lt;br /&gt;Comments: ** Comment from web user: skape ** &lt;p&gt;Look who can&amp;#39;t use codeplex properly &amp;#58;&amp;#41;&lt;/p&gt;</description><author>skape</author><pubDate>Sat, 16 Aug 2008 16:21:33 GMT</pubDate><guid isPermaLink="false">Commented Issue: Crashdump 20080816042133P</guid></item><item><title>Commented Issue: wuauclt.exe crashes</title><link>http://www.codeplex.com/wehntrust/WorkItem/View.aspx?WorkItemId=2069</link><description>OS&amp;#58; Windows XP SP2&amp;#47;SP3&lt;br /&gt;Version&amp;#58; WehnTrust 1.2&lt;br /&gt;&lt;br /&gt;wuauclt.exe crashes 3 times in a row about every 10-20 minutes unless exempted from ASLR. I can &amp;#34;reproduce&amp;#34; this about 50&amp;#37; of the time on my home and work machines.&lt;br /&gt;&lt;br /&gt;I will reply with a screenshot the next time it happens.&lt;br /&gt;Comments: ** Comment from web user: skape ** &lt;p&gt;Can you upload a crashdump&amp;#63;&lt;/p&gt;</description><author>skape</author><pubDate>Sat, 16 Aug 2008 16:20:10 GMT</pubDate><guid isPermaLink="false">Commented Issue: wuauclt.exe crashes 20080816042010P</guid></item><item><title>Closed Issue: Crashdump</title><link>http://www.codeplex.com/wehntrust/WorkItem/View.aspx?WorkItemId=2086</link><description>Can you upload a crashdump&amp;#63;&lt;br /&gt;</description><author>skape</author><pubDate>Sat, 16 Aug 2008 16:19:50 GMT</pubDate><guid isPermaLink="false">Closed Issue: Crashdump 20080816041950P</guid></item><item><title>Created Issue: Crashdump</title><link>http://www.codeplex.com/wehntrust/WorkItem/View.aspx?WorkItemId=2086</link><description>Can you upload a crashdump&amp;#63;&lt;br /&gt;</description><author>skape</author><pubDate>Sat, 16 Aug 2008 16:19:31 GMT</pubDate><guid isPermaLink="false">Created Issue: Crashdump 20080816041931P</guid></item><item><title>Commented Issue: wuauclt.exe crashes</title><link>http://www.codeplex.com/wehntrust/WorkItem/View.aspx?WorkItemId=2069</link><description>OS&amp;#58; Windows XP SP2&amp;#47;SP3&lt;br /&gt;Version&amp;#58; WehnTrust 1.2&lt;br /&gt;&lt;br /&gt;wuauclt.exe crashes 3 times in a row about every 10-20 minutes unless exempted from ASLR. I can &amp;#34;reproduce&amp;#34; this about 50&amp;#37; of the time on my home and work machines.&lt;br /&gt;&lt;br /&gt;I will reply with a screenshot the next time it happens.&lt;br /&gt;Comments: ** Comment from web user: slow ** &lt;p&gt;I can reproduce this as well, but only in weird cases. I usually run windows as a standard user account wuauclt never crashes when I login as standard user, but if I log off and log in again as local admin wuauclt crashes almost every time &amp;#40;95&amp;#37; of the time&amp;#41;. For me it gets into an inf loop of &amp;#34;click here to close&amp;#34;-&amp;#62;crashes again instantly-&amp;#62;&amp;#34;click here to close&amp;#34;-&amp;#62;etc.&lt;/p&gt;</description><author>slow</author><pubDate>Thu, 14 Aug 2008 15:36:01 GMT</pubDate><guid isPermaLink="false">Commented Issue: wuauclt.exe crashes 20080814033601P</guid></item><item><title>Commented Issue: wuauclt.exe crashes</title><link>http://www.codeplex.com/wehntrust/WorkItem/View.aspx?WorkItemId=2069</link><description>OS&amp;#58; Windows XP SP2&amp;#47;SP3&lt;br /&gt;Version&amp;#58; WehnTrust 1.2&lt;br /&gt;&lt;br /&gt;wuauclt.exe crashes 3 times in a row about every 10-20 minutes unless exempted from ASLR. I can &amp;#34;reproduce&amp;#34; this about 50&amp;#37; of the time on my home and work machines.&lt;br /&gt;&lt;br /&gt;I will reply with a screenshot the next time it happens.&lt;br /&gt;Comments: ** Comment from web user: dguido ** &lt;p&gt;Second screenshot&lt;/p&gt;</description><author>dguido</author><pubDate>Thu, 14 Aug 2008 15:33:15 GMT</pubDate><guid isPermaLink="false">Commented Issue: wuauclt.exe crashes 20080814033315P</guid></item><item><title>Commented Issue: wuauclt.exe crashes</title><link>http://www.codeplex.com/wehntrust/WorkItem/View.aspx?WorkItemId=2069</link><description>OS&amp;#58; Windows XP SP2&amp;#47;SP3&lt;br /&gt;Version&amp;#58; WehnTrust 1.2&lt;br /&gt;&lt;br /&gt;wuauclt.exe crashes 3 times in a row about every 10-20 minutes unless exempted from ASLR. I can &amp;#34;reproduce&amp;#34; this about 50&amp;#37; of the time on my home and work machines.&lt;br /&gt;&lt;br /&gt;I will reply with a screenshot the next time it happens.&lt;br /&gt;Comments: ** Comment from web user: dguido ** &lt;p&gt;First screenshot&lt;/p&gt;</description><author>dguido</author><pubDate>Thu, 14 Aug 2008 15:32:54 GMT</pubDate><guid isPermaLink="false">Commented Issue: wuauclt.exe crashes 20080814033254P</guid></item><item><title>Created Issue: wuauclt.exe crashes</title><link>http://www.codeplex.com/wehntrust/WorkItem/View.aspx?WorkItemId=2069</link><description>OS&amp;#58; Windows XP SP2&amp;#47;SP3&lt;br /&gt;Version&amp;#58; WehnTrust 1.2&lt;br /&gt;&lt;br /&gt;wuauclt.exe crashes 3 times in a row about every 10-20 minutes unless exempted from ASLR. I can &amp;#34;reproduce&amp;#34; this about 50&amp;#37; of the time on my home and work machines.&lt;br /&gt;&lt;br /&gt;I will reply with a screenshot the next time it happens.&lt;br /&gt;</description><author>dguido</author><pubDate>Thu, 14 Aug 2008 15:18:56 GMT</pubDate><guid isPermaLink="false">Created Issue: wuauclt.exe crashes 20080814031856P</guid></item><item><title>Updated Wiki: Home</title><link>http://www.codeplex.com/wehntrust/Wiki/View.aspx?title=Home&amp;version=13</link><description>&lt;div class="wikidoc"&gt;
&lt;b&gt;Overview&lt;/b&gt;&lt;br /&gt;WehnTrust is a Host-based Intrusion Prevention System &amp;#40;HIPS&amp;#41; for Windows 2000, XP, and Server 2003.  It includes support for exploit mitigations that are designed to make exploitation more difficult by preventing the use of specific exploitation techniques and by making exploitation unreliable.
&lt;br /&gt; &lt;br /&gt;&lt;b&gt;Download&lt;/b&gt;&lt;br /&gt;&lt;a href="http://www.codeplex.com/wehntrust/Release/ProjectReleases.aspx?ReleaseId=16198" class="externalLink"&gt;WehnTrust 1.2&lt;span class="externalLinkIcon"&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt; &lt;br /&gt;&lt;b&gt;How it works&lt;/b&gt;&lt;br /&gt;WehnTrust randomizes the base addresses of memory allocations to make it more difficult to exploit software vulnerabilities such as buffer overflows.  This technique is commonly known as Address Space Layout Randomization (ASLR) and was originally conceived by the &lt;a href="http://pax.grsecurity.net" class="externalLink"&gt;PaX team&lt;span class="externalLinkIcon"&gt;&lt;/span&gt;&lt;/a&gt;.  Microsoft has recently incorporated support for ASLR into Windows Vista and Windows Server 2008.  In addition to ASLR, WehnTrust generically mitigates SEH overwrites by dynamically validating a thread's exception handler chain prior to allowing exceptions to be dispatched.  &lt;br /&gt; &lt;br /&gt;&lt;b&gt;Recommendations&lt;/b&gt;&lt;br /&gt;Using WehnTrust in combination with &lt;a href="http://en.wikipedia.org/wiki/Data_Execution_Prevention" class="externalLink"&gt;hardware-enforced DEP&lt;span class="externalLinkIcon"&gt;&lt;/span&gt;&lt;/a&gt; (non-executable pages) as included with Windows XP SP2 and Windows Server 2003 provides the greatest level of security.  Non-executable pages help to counter some of the inherent weaknesses of ASLR.&lt;br /&gt; &lt;br /&gt;&lt;b&gt;Features&lt;/b&gt;&lt;br /&gt;The following features are included:&lt;br /&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/ASLR" class="externalLink"&gt;Address Space Layout Randomization&lt;span class="externalLinkIcon"&gt;&lt;/span&gt;&lt;/a&gt; (ASLR)&lt;/li&gt;&lt;ul&gt;
&lt;li&gt;Randomized image file mappings (relocations required)&lt;/li&gt;&lt;li&gt;Randomized memory allocations (e.g. VirtualAlloc)&lt;/li&gt;&lt;li&gt;Randomized PEB/TEB&lt;/li&gt;&lt;li&gt;Basic brute force detection and prevention&lt;/li&gt;
&lt;/ul&gt;&lt;li&gt;&lt;a href="http://uninformed.org/?v=5&amp;amp;a=2&amp;amp;t=sumry" class="externalLink"&gt;SEH Overwrite Prevention&lt;span class="externalLinkIcon"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/Format_string_vulnerability" class="externalLink"&gt;Format string vulnerability&lt;span class="externalLinkIcon"&gt;&lt;/span&gt;&lt;/a&gt; prevention&lt;/li&gt;&lt;li&gt;Logging and notification of exploitation attempts&lt;/li&gt;&lt;ul&gt;
&lt;li&gt;Balloon tip nofication&lt;/li&gt;&lt;li&gt;Native windows event logging&lt;/li&gt;
&lt;/ul&gt;&lt;li&gt;Application and image file exemptions&lt;/li&gt;
&lt;/ul&gt; &lt;br /&gt;&lt;b&gt;License&lt;/b&gt;&lt;br /&gt;WehnTrust is licensed under the WehnTrust Software License 1.0.&lt;br /&gt; &lt;br /&gt;&lt;b&gt;Thanks&lt;/b&gt;&lt;br /&gt;We would like to thank the following people for sharing their knowledge, help, and support during the development of WehnTrust: the PaX team, Erik Cabetas, Richard Johnson, HD Moore, Patrick Stach, Jarkko Turkulainen , Martin Zeiser.&lt;br /&gt;
&lt;/div&gt;</description><author>skape</author><pubDate>Mon, 11 Aug 2008 08:42:33 GMT</pubDate><guid isPermaLink="false">Updated Wiki: Home 20080811084233A</guid></item><item><title>Updated Release: WehnTrust 1.2 (Aug 10, 2008)</title><link>http://www.codeplex.com/wehntrust/Release/ProjectReleases.aspx?ReleaseId=16198</link><description>&lt;div&gt;
WehnTrust 1.2&lt;br&gt;
&lt;/div&gt;</description><author></author><pubDate>Mon, 11 Aug 2008 08:41:25 GMT</pubDate><guid isPermaLink="false">Updated Release: WehnTrust 1.2 (Aug 10, 2008) 20080811084125A</guid></item></channel></rss>