After a Trend Micro worry Free 9 upgrade from Trend Micro WorryFree 8, we now see a client with a crash in TmProxy32.dll.

It crashes out the browser and renders it useless.

I am currently working with Trend Support looking for a solution.

We have 2 workarounds at the moment.

  • Use the Internet Explorer 64 bit – Which leaves you safe and protected
  • Use the Internet Explorer 32 bit but under the add on’s, disable the TmIEPlugInBHO Class (Version 5.82.0.1081) – Which does not leave you safe and protected.

We have so far found one sure fire way to create the crash.

Windows 2008 R2 64bit enterprise server in Remote Desktop hosting mode using IE9 32bit browser and clicking the second tab with the default IE multi-tab setting set to show new tab (Under Tools – internet options – General Tab and then select the tab behaviour to a new page).

Open IE, let the default page come up then click the second tab and click a most popular site (As listed by IE9).

 

The error comes up as:

 

Internet Explorer has stopped working

  • Windows can check online for a solution and close the program
  • Close the program
  • Debug the program

 

Faulting application name: iexplore.exe, version: 9.0.8112.16490, time stamp: 0x51955cca

Faulting module name: TmProxy32.dll, version: 5.82.0.1081, time stamp: 0x52df52ed

Exception code: 0xc000000d

Fault offset: 0x0001e452

Faulting process id: 0x6438

Faulting application start time: 0x01cf7975ee091613

Faulting application path: C:\Program Files (x86)\Internet Explorer\iexplore.exe

Faulting module path: C:\Program Files (x86)\Trend Micro\Security Agent\TmProxy32.dll

Report Id: b9113ce2-e569-11e3-9b0b-e839352523ea

 

 

The event log shows

 

Log Name:     Application

Source:       Application Error

Date:         27/05/2014 4:10:00 PM

Event ID:     1000

Task Category: (100)

Level:         Error

Keywords:     Classic

User:         N/A

Computer:     ADLTS02.jhg.local

Description:

Faulting application name: iexplore.exe, version: 9.0.8112.16490, time stamp: 0x51955cca

Faulting module name: TmProxy32.dll, version: 5.82.0.1081, time stamp: 0x52df52ed

Exception code: 0xc000000d

Fault offset: 0x0001e452

Faulting process id: 0x6438

Faulting application start time: 0x01cf7975ee091613

Faulting application path: C:\Program Files (x86)\Internet Explorer\iexplore.exe

Faulting module path: C:\Program Files (x86)\Trend Micro\Security Agent\TmProxy32.dll

Report Id: b9113ce2-e569-11e3-9b0b-e839352523ea

 

The Windows Error reporting logs contains:

 

Version=1

EventType=BEX

EventTime=130456429019247176

ReportType=2

Consent=1

ReportIdentifier=937c35e3-e561-11e3-a983-441ea13d400a

IntegratorReportIdentifier=937c35e2-e561-11e3-a983-441ea13d400a

WOW64=1

Response.type=4

Sig[0].Name=Application Name

Sig[0].Value=iexplore.exe

Sig[1].Name=Application Version

Sig[1].Value=9.0.8112.16490

Sig[2].Name=Application Timestamp

Sig[2].Value=51955cca

Sig[3].Name=Fault Module Name

Sig[3].Value=TmProxy32.dll

Sig[4].Name=Fault Module Version

Sig[4].Value=5.82.0.1081

Sig[5].Name=Fault Module Timestamp

Sig[5].Value=52df52ed

Sig[6].Name=Exception Offset

Sig[6].Value=0001e452

Sig[7].Name=Exception Code

Sig[7].Value=c000000d

Sig[8].Name=Exception Data

Sig[8].Value=00000000

DynamicSig[1].Name=OS Version

DynamicSig[1].Value=6.1.7601.2.1.0.18.10

DynamicSig[2].Name=Locale ID

DynamicSig[2].Value=3081

DynamicSig[22].Name=Additional Information 1

DynamicSig[22].Value=cb1a

DynamicSig[23].Name=Additional Information 2

DynamicSig[23].Value=cb1a56b584ba5e1bcbdf4857a81c9eeb

DynamicSig[24].Name=Additional Information 3

DynamicSig[24].Value=2892

DynamicSig[25].Name=Additional Information 4

DynamicSig[25].Value=2892bce1c4b270ff21520e12f4242258

UI[2]=C:\Program Files (x86)\Internet Explorer\iexplore.exe

UI[3]=Internet Explorer has stopped working

UI[4]=Windows can check online for a solution to the problem.

UI[5]=Check online for a solution and close the program

UI[6]=Check online for a solution later and close the program

UI[7]=Close the program

LoadedModule[0]=C:\Program Files (x86)\Internet Explorer\iexplore.exe

LoadedModule[1]=C:\Windows\SysWOW64\ntdll.dll

LoadedModule[2]=C:\Windows\syswow64\kernel32.dll

LoadedModule[3]=C:\Windows\syswow64\KERNELBASE.dll

LoadedModule[4]=C:\Windows\syswow64\ADVAPI32.dll

LoadedModule[5]=C:\Windows\syswow64\msvcrt.dll

LoadedModule[6]=C:\Windows\SysWOW64\sechost.dll

LoadedModule[7]=C:\Windows\syswow64\RPCRT4.dll

LoadedModule[8]=C:\Windows\syswow64\SspiCli.dll

LoadedModule[9]=C:\Windows\syswow64\CRYPTBASE.dll

LoadedModule[10]=C:\Windows\syswow64\USER32.dll

LoadedModule[11]=C:\Windows\syswow64\GDI32.dll

LoadedModule[12]=C:\Windows\syswow64\LPK.dll

LoadedModule[13]=C:\Windows\syswow64\USP10.dll

LoadedModule[14]=C:\Windows\syswow64\SHLWAPI.dll

LoadedModule[15]=C:\Windows\syswow64\SHELL32.dll

LoadedModule[16]=C:\Windows\syswow64\ole32.dll

LoadedModule[17]=C:\Windows\syswow64\urlmon.dll

LoadedModule[18]=C:\Windows\syswow64\OLEAUT32.dll

LoadedModule[19]=C:\Windows\syswow64\iertutil.dll

LoadedModule[20]=C:\Windows\syswow64\WININET.dll

LoadedModule[21]=C:\Windows\syswow64\Normaliz.dll

LoadedModule[22]=C:\Windows\system32\IMM32.DLL

LoadedModule[23]=C:\Windows\syswow64\MSCTF.dll

LoadedModule[24]=C:\Windows\system32\IEFRAME.dll

LoadedModule[25]=C:\Windows\syswow64\PSAPI.DLL

LoadedModule[26]=C:\Windows\system32\OLEACC.dll

LoadedModule[27]=C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll

LoadedModule[28]=C:\Windows\syswow64\comdlg32.dll

LoadedModule[29]=C:\Program Files (x86)\Internet Explorer\IEShims.dll

LoadedModule[30]=C:\Windows\system32\Secur32.dll

LoadedModule[31]=C:\Windows\system32\profapi.dll

LoadedModule[32]=C:\Windows\syswow64\WS2_32.dll

LoadedModule[33]=C:\Windows\syswow64\NSI.dll

LoadedModule[34]=C:\Windows\system32\dnsapi.DLL

LoadedModule[35]=C:\Windows\system32\iphlpapi.DLL

LoadedModule[36]=C:\Windows\system32\WINNSI.DLL

LoadedModule[37]=C:\Windows\system32\RpcRtRemote.dll

LoadedModule[38]=C:\Windows\system32\MSHTML.dll

LoadedModule[39]=C:\Windows\system32\VERSION.dll

LoadedModule[40]=C:\Windows\system32\d2d1.dll

LoadedModule[41]=C:\Windows\system32\DWrite.dll

LoadedModule[42]=C:\Windows\system32\dxgi.dll

LoadedModule[43]=C:\Windows\system32\dwmapi.dll

LoadedModule[44]=C:\Windows\system32\CRYPTSP.dll

LoadedModule[45]=C:\Windows\syswow64\WINTRUST.dll

LoadedModule[46]=C:\Windows\syswow64\CRYPT32.dll

LoadedModule[47]=C:\Windows\syswow64\MSASN1.dll

LoadedModule[48]=C:\Windows\system32\d3d10_1.dll

LoadedModule[49]=C:\Windows\system32\d3d10_1core.dll

LoadedModule[50]=C:\Windows\system32\rsaenh.dll

LoadedModule[51]=C:\Windows\syswow64\CLBCatQ.DLL

LoadedModule[52]=C:\Program Files (x86)\Internet Explorer\ieproxy.dll

LoadedModule[53]=C:\Windows\system32\apphelp.dll

LoadedModule[54]=C:\Program Files (x86)\Trend Micro\Security Agent\TmIEPlg32.dll

LoadedModule[55]=C:\Program Files (x86)\Trend Micro\Security Agent\TmProxy32.dll

FriendlyEventName=Stopped working

ConsentKey=BEX

AppName=Internet Explorer

AppPath=C:\Program Files (x86)\Internet Explorer\iexplore.exe