Jump to content

ehdrv.sys sometimes major performance impact in NtDuplicateObject even the protection is paused


Recommended Posts

this is a screenshot of dotTrace

QQ截图20230714010732.jpg

even i stop the protection of eset, by pressing the 'pause protection'. this situlation still exists. (this trace in screenshot is run under protection paused.)

not every time calling NtDuplicateObject has such performance impact.

my program run query process handle info (many times, maybe 200+) every three seconds, usually it should not higher than 500ms, but some times this could tooks up 35+ seconds, so i run a trace on it, and this is the trace result.

is there a way to mitigation this issue? i means even i have already pause the protection (select until reboot).

 

thanks in advance!

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...