Page 1 of 1

HD Sentinel not loading :(

Posted: 2020.07.29. 09:23
by mfilos
Hi, I've been using HDSentinel for years without issues.
Today I thought about installing it (after downloading latest PRO version from website) in my new laptop.

After installation I have the altered explorer icons as usual but when I try to run the application, it shows the tray icons of temperature and then it doesn't open (it crashes as the icons disappear on mouseover).
I checked the Event Viewer and saw the following issues on HDSentinel crash:

Faulting application name: HDSentinel.exe, version: 5.61.0.0, time stamp: 0x2a425e19
Faulting module name: SophosAmsiProvider.dll, version: 1.2.225.0, time stamp: 0x5e731165
Exception code: 0xc0000409
Fault offset: 0x000e6d77
Faulting process id: 0x784
Faulting application start time: 0x01d66577afea2a2f
Faulting application path: C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe
Faulting module path: C:\Program Files (x86)\Sophos\Sophos AMSI Protection\SophosAmsiProvider.dll
Report Id: 7ea15a8d-3164-402b-8f98-48f91744aaba
Faulting package full name:

Yes I use Sophos Endpoint InterceptX as it's my work's endpoint protection software but I was always using this with HDS for years without issues (so I doubt it's the endpoint protection as I tried disabling it and saw no difference whatsoever).
Saw some previous posts regarding the matter and tried a couple of registry tricks which also didn't solve the issue.
Anything else I can do to try out?

Re: HD Sentinel not loading :(

Posted: 2020.07.29. 13:21
by hdsentinel
Thanks for your message and excuse me for the possible troubles.

I'm afraid the problem is here:

Faulting module name: SophosAmsiProvider.dll, version: 1.2.225.0, time stamp: 0x5e731165

Personally I do not really know/understand why and how, but yes, one other user already reported problem with this kind of protection. Seems it is blocking Hard Disk Sentinel from working correctly.

Not sure, but if possible, please try to contact Sophos (not sure if their software may allow sending samples to analyse) about the situation, as then hopefully if they'll receive similar request from different sources, they may able to check, reproduce and correct this behaviour.

Re: HD Sentinel not loading :(

Posted: 2020.07.30. 13:31
by mfilos
After some communication with Sophos I managed to fixed the problem so I'm posting here for future reference.

This is the info I got with solution provided:
For your information the AMSI is available as an early access program:

Please have a look at the following KB article that should resolve every queries of yours related to Sophos AMSI. also in the article there is a PPT that would help

https://community.sophos.com/products/i ... s-and-amsi
can you please confirm that the issue is fixed with the latest Core and AMSI version, where AMSI is enabled and the AMSI Logging was disabled using the following registry key:

[HKLM\SOFTWARE\Sophos\Sophos AMSIProtection]
"LogLevel"=dword:00000000
("Applying the registry key is currently required but we aim for making this not required once the full version will be released."), this was a requirement for the EAP version but the updated logger probably didn't make it into the version. Full version will be released on october , 2020.

Re: HD Sentinel not loading :(

Posted: 2020.09.20. 11:36
by stefan0n
Hi

I'm experiencing the same problem, probably after a recent Sophos (Home 3.1.2) software update:

Code: Select all

Nome dell'applicazione che ha generato l'errore: HDSentinel.exe, versione: 5.61.0.0, timestamp: 0x2a425e19
Nome del modulo che ha generato l'errore: SophosAmsiProvider.dll, versione: 1.2.225.0, timestamp: 0x5e731165
Codice eccezione: 0xc0000409
Offset errore 0x000e6d77
ID processo che ha generato l'errore: 0x551c
Ora di avvio dell'applicazione che ha generato l'errore: 0x01d68f2ed433ea9a
Percorso dell'applicazione che ha generato l'errore: C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe
Percorso del modulo che ha generato l'errore: C:\Program Files (x86)\Sophos\Sophos AMSI Protection\SophosAmsiProvider.dll
ID segnalazione: 7a6abb8d-64a1-40f5-949a-c5e41b5ea40b
Nome completo pacchetto che ha generato l'errore: 
ID applicazione relativo al pacchetto che ha generato l'errore: 
Unfortunately I've found that the KB link in the mfilos user post isn't working, so I wish to ask if the solution is only in the registry key change. Thanks.