Application Problem
To isolate the problem:
- While the UMH module is enabled, execute the program to try to reproduce the problem. Refer to the following KB to make sure UMH is enabled: Enabling/Disabling User-Mode Hooking (UMH) in OfficeScan (OSCE).
If the problem can be reproduced by enabling UMH, and resolved by disabling UMH, it is a UMH-related problem.
After UMH status changes (enabled/disabled), terminate the process, and then restart the process again. - When the problem has been reproduced, confirm whether the process of this application is running or not. Process Explorer can assist to check and confirm this.
- If the application's process is still running while the problem is being reproduced, collect the UMH debug logs. Below are the reference KBs:
- If the application's process is not running while the problem is being reproduced, collect the application crash log for the UMH module. Refer to the following KB: Collecting logs for the User-Mode Hooking (UMH) module for an application crash issue.
- Provide the execution file of the application's process to Trend Micro Technical Support, if possible.
- Provide an installer of this application to Trend Micro Technical Support, if possible.
System Problem
For system hang:
- Log in using Safe Mode. Refer to Step 1 of the following KB: Collecting logs for the User-Mode Hooking (UMH) module for a system crash issue.
- Navigate to "%windir%\system32\drivers\":
- Rename "TMUMH.sys" to "TMUMH.sys.bak"
- Create a folder in the same place. The folder's name is "TMUMH.sys".
- Reboot the system to normal mode to reproduce the problem.
If the problem fails to reproduce, it is a UMH-related problem.
- For the system hang problem, refer to the following KB: Collecting logs for the User-Mode Hooking (UMH) module for a system hang issue
Rollback the changes to "%windir%\system32\drivers\" to reproduce the problem.
- Remove the "TMUMH.sys" folder.
- Rename "TMUMH.sys.bak" back to "TMUMH.sys".
- Reboot the system to normal mode to reproduce the problem.
- For a system crash problem, refer to the following KB: Collecting logs for the User-Mode Hooking (UMH) module for a system crash issue
Rollback the changes to "%windir%\system32\drivers\" to reproduce the problem.
- Remove the "TMUMH.sys" folder.
- Rename "TMUMH.sys.bak" back to "TMUMH.sys".
- Reboot the system to normal mode to reproduce the problem.
- For the system hang problem, refer to the following KB: Collecting logs for the User-Mode Hooking (UMH) module for a system hang issue