J B Posted September 27, 2021 Report Share Posted September 27, 2021 Hello, I have noticed that crashdumps labelled dllhost.exe.<number>.dmp have been accumulating. I opened several of the files and they all contain an exception generated by acrobat_compat. The text produced by the analyze command of WinDbg is below, since there doesn't seem to be a means of attaching a text file. Nitro Pro version 13.47.4.957, but I noticed this thing happening with version 12 also. Best regards, JB ----begin---- Loading Dump File [C:~\AppData\Local\CrashDumps\dllhost.exe(1).4148.dmp] User Mini Dump File: Only registers, stack and portions of memory are available ************* Path validation summary ************** Response Time (ms) Location Deferred srv* Symbol search path is: srv* Executable search path is: Windows 10 Version 19043 MP (64 procs) Free x64 Product: WinNt, suite: SingleUserTS Edition build lab: 19041.1.amd64fre.vb_release.191206-1406 Machine Name: Debug session time: Sun Sep 26 10:29:40.000 2021 (UTC + 1:00) System Uptime: not available Process Uptime: 1 days 0:35:04.000 ................................................. Loading unloaded module list ............................ This dump file has an exception of interest stored in it. The stored exception information can be accessed via .ecxr. (1034.5530): Access violation - code c0000005 (first/second chance not available) For analysis of this file, run !analyze -v ntdll!NtWaitForMultipleObjects+0x14: 00007ffe`216ed8c4 c3 ret 0:001> !analyze -v ******************************************************************************* * * * Exception Analysis * * * ******************************************************************************* KEY_VALUES_STRING: 1 Key : AV.Dereference Value: NullClassPtr Key : AV.Fault Value: Write Key : Analysis.CPU.mSec Value: 1108 Key : Analysis.DebugAnalysisManager Value: Create Key : Analysis.Elapsed.mSec Value: 21991 Key : Analysis.Init.CPU.mSec Value: 1077 Key : Analysis.Init.Elapsed.mSec Value: 175821 Key : Analysis.Memory.CommitPeak.Mb Value: 117 Key : Timeline.Process.Start.DeltaSec Value: 88504 Key : WER.OS.Branch Value: vb_release Key : WER.OS.Timestamp Value: 2019-12-06T14:06:00Z Key : WER.OS.Version Value: 10.0.19041.1 Key : WER.Process.Version Value: 10.0.19041.546 NTGLOBALFLAG: 0 APPLICATION_VERIFIER_FLAGS: 0 CONTEXT: (.ecxr) rax=0000000000000000 rbx=00007ffe0484b350 rcx=00007ffe0484b350 rdx=00000000fffffffa rsi=0000000000000000 rdi=0000000000000000 rip=00007ffe216b3416 rsp=000000487edff010 rbp=000001fd228b6d00 r8=0000000000000000 r9=00007ffe0484b300 r10=0000ea4fbba63349 r11=0000ea4fbba631ed r12=0000000000000000 r13=000000487e764000 r14=0000000000000001 r15=0000000000000000 iopl=0 nv up ei pl nz ac pe cy cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010213 ntdll!RtlpWaitOnCriticalSection+0xa6: 00007ffe`216b3416 ff4024 inc dword ptr [rax+24h] ds:00000000`00000024=???????? Resetting default scope EXCEPTION_RECORD: (.exr -1) ExceptionAddress: 00007ffe216b3416 (ntdll!RtlpWaitOnCriticalSection+0x00000000000000a6) ExceptionCode: c0000005 (Access violation) ExceptionFlags: 00000000 NumberParameters: 2 Parameter[0]: 0000000000000001 Parameter[1]: 0000000000000024 Attempt to write to address 0000000000000024 PROCESS_NAME: dllhost.exe WRITE_ADDRESS: 0000000000000024 ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s. EXCEPTION_CODE_STR: c0000005 EXCEPTION_PARAMETER1: 0000000000000001 EXCEPTION_PARAMETER2: 0000000000000024 STACK_TEXT: 00000048`7edff010 00007ffe`2167fcb4 : 000001fd`228b78c0 00000000`00000000 00000000`fffffffa 00007ffe`20f9dd76 : ntdll!RtlpWaitOnCriticalSection+0xa6 00000048`7edff0f0 00007ffe`2167fae2 : 000001fd`24aec360 00000048`7edff2a0 00007ffe`0484b350 00007ffe`216a07b0 : ntdll!RtlpEnterCriticalSectionContended+0x1c4 00000048`7edff150 00007ffe`047f1c16 : 00000000`00000000 00007ffe`1f0d98bb 80004002`00000000 000001fd`00000001 : ntdll!RtlEnterCriticalSection+0x42 00000048`7edff180 00007ffe`047f1ad8 : 000001fd`228b6d28 00007ffe`0484b350 00002dbc`533d4312 00000048`7edff2e8 : acrobat_compat!ASGetErrorString+0xb46 00000048`7edff1e0 00007ffe`1ef142d6 : 0000cca1`7acc338a 00007ffe`216bacd7 00000000`00000000 00007ffe`1ef160ae : acrobat_compat!ASGetErrorString+0xa08 00000048`7edff220 00007ffe`1ef141fb : 00000000`00000000 00000048`7edff2e8 00000000`00000000 00007ffe`1eff0e40 : ucrtbase!<lambda_f03950bc5685219e0bcd2087efbe011e>::operator()+0xa6 00000048`7edff270 00007ffe`1ef141b4 : 00000000`00000000 00000000`00000000 00007ffe`0020001e 00000048`7edff2d8 : ucrtbase!__crt_seh_guarded_call<int>::operator()<<lambda_7777bce6b2f8c936911f934f8298dc43>,<lambda_f03950bc5685219e0bcd2087efbe011e> &,<lambda_3883c3dff614d5e0c5f61bb1ac94921c> >+0x3b 00000048`7edff2a0 00007ffe`0482b16e : 00007ffe`0484b6a8 00000048`00000002 00000000`00000002 00000048`7edff2d0 : ucrtbase!execute_onexit_table+0x34 00000048`7edff2d0 00007ffe`0482b294 : 00000000`00000001 00007ffe`21669800 00000000`00000000 00007ffe`090c33d5 : acrobat_compat!ASFileSysLegacyNameFromPathAsASText+0x3227e 00000048`7edff300 00007ffe`21669a1d : 00007ffe`047f0000 00000000`00000000 00000000`00000000 00000000`7ffe0385 : acrobat_compat!ASFileSysLegacyNameFromPathAsASText+0x323a4 00000048`7edff360 00007ffe`216ba9cb : 000001fd`22870ad0 00007ffe`047f0000 00007ffe`00000000 00000000`00000000 : ntdll!LdrpCallInitRoutine+0x61 00000048`7edff3d0 00007ffe`216ba427 : 000001fd`228bbed0 000001fd`22870b70 000001fd`249f3c30 000001fd`228bbed0 : ntdll!LdrpProcessDetachNode+0x107 00000048`7edff4a0 00007ffe`216ba678 : 000001fd`00000000 000001fd`249f3c30 00007ffe`217bb240 000001fd`228bc290 : ntdll!LdrpUnloadNode+0x3f 00000048`7edff4f0 00007ffe`2165fd0a : 000001fd`00000001 000001fd`228bc290 00000048`7edff970 000001fd`228697e8 : ntdll!LdrpUnloadNode+0x290 00000048`7edff540 00007ffe`2165fc84 : 00000000`00000000 00000048`00000001 00000000`00000000 00007ffe`20f5f418 : ntdll!LdrpDecrementModuleLoadCountEx+0x72 00000048`7edff570 00007ffe`1f0a5d3e : 00007ffe`09090000 000001fd`00000009 000001fd`228711f0 00000048`7edff978 : ntdll!LdrUnloadDll+0x94 00000048`7edff5a0 00007ffe`20f5f498 : 00000048`7edff978 00000048`7edff978 00000048`7edff650 00007ffe`20fc3d09 : KERNELBASE!FreeLibrary+0x1e 00000048`7edff5d0 00007ffe`20f44348 : 00000000`00000001 00000000`00000000 00000000`00000000 00000000`00000001 : combase!CClassCache::CDllPathEntry::CFinishObject::Finish+0x28 00000048`7edff600 00007ffe`20f43955 : 00000048`7edff650 00000000`00000001 00000048`7edff650 00000000`00000001 : combase!CClassCache::CFinishComposite::Finish+0x4c 00000048`7edff630 00007ffe`20f79679 : 00005530`00000003 00000000`00000000 00000000`ffffffff 00000000`00000000 : combase!CClassCache::FreeUnused+0xdd 00000048`7edff9e0 00007ffe`203df15e : 00000000`00000001 00000000`80006010 00000000`00000000 000001fd`228580c0 : combase!CoFreeUnusedLibrariesEx+0x89 00000048`7edffa20 00007ffe`203de16b : 000001fd`228580c0 00007ffe`20f78e90 000001fd`2309fc20 00007ffe`00000113 : user32!UserCallWinProc+0x2ae 00000048`7edffba0 00007ffe`20f792f1 : 00000048`7edffc60 000001fd`228580c0 00000000`000108a0 00000000`00040005 : user32!DispatchMessageWorker+0x18b 00000048`7edffc20 00007ffe`20f791e0 : 000001fd`228580c0 00007ffe`211e66f0 00000000`00000100 00007ffe`211e66f0 : combase!CDllHost::STAWorkerLoop+0xad 00000048`7edffca0 00007ffe`20faae50 : 000001fd`228580c0 000001fd`22842100 00000000`00000000 00000000`00000000 : combase!CDllHost::WorkerThread+0xd4 00000048`7edffce0 00007ffe`20faadd9 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : combase!CRpcThread::WorkerLoop+0x4c 00000048`7edffd40 00007ffe`21497034 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : combase!CRpcThreadCache::RpcWorkerThreadEntry+0x29 00000048`7edffd70 00007ffe`216a2651 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x14 00000048`7edffda0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x21 SYMBOL_NAME: acrobat_compat!ASGetErrorString+b46 MODULE_NAME: acrobat_compat IMAGE_NAME: acrobat_compat.dll STACK_COMMAND: ~1s ; .ecxr ; kb FAILURE_BUCKET_ID: NULL_CLASS_PTR_WRITE_c0000005_acrobat_compat.dll!ASGetErrorString OS_VERSION: 10.0.19041.1 BUILDLAB_STR: vb_release OSPLATFORM_TYPE: x64 OSNAME: Windows 10 IMAGE_VERSION: 13.47.4.957 FAILURE_ID_HASH: {cbc3bd7d-dccd-260c-4dcc-7bd144ddbee9} Followup: MachineOwner --------- ----end---- Link to comment Share on other sites More sharing options...
Suggestion
J B
Hello,
I have noticed that crashdumps labelled dllhost.exe.<number>.dmp have been accumulating.
I opened several of the files and they all contain an exception generated by acrobat_compat.
The text produced by the analyze command of WinDbg is below, since there doesn't seem to be a means of attaching a text file.
Nitro Pro version 13.47.4.957, but I noticed this thing happening with version 12 also.
Best regards, JB
----begin----
Link to comment
Share on other sites
0 replies to this suggestion
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now