> Source: [sk180853](https://support.checkpoint.com/results/sk/sk180853)

# sk180853 - "On startup" programs on Windows 11 22h2 are removed from the application tray after a boot

| Property | Value |
|----------|-------|
| Solution ID | sk180853 |
| Date Created | 2023-04-13 |
| Last Modified | 2023-04-18 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Windows |

## Symptoms

- On Windows 11 22h2, a program which is included and set up to start automatically after logging in disappears from the application tray.

## Cause

Anti-Ransomware blocks the execution of startup programs. This issue is specific to on-the-fly injects and only may affect processes that were launched prior to EFR's initiation.  

In Windows 11 22h2, Microsoft made changes to the Thread Local Storage initialization flow for the WOW64 process in `ntdll`. As the CPHNT64 process relies on TLS, it encounters a memory access violation, causing the application to unexpectedly exit because TLS is not correctly initialized when the library is loaded into the process.  

The WOW64 process unexpectedly exits when injected with CPHNT64, and this problem is caused by modifications in the loader logic in `ntdll` for Windows 11 22h2.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue - improved Endpoint Security Client package.

A Support Engineer will make sure the Endpoint Security Client is compatible with your environment before providing it.  
For faster resolution and verification, collect the [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk90445) file from the Endpoint Security Client involved in the case.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
