Main Menu

[SOLVED] CTD after injecting

Started by unc1rlm, August 15, 2020, 12:35:35 PM

Previous topic - Next topic

unc1rlm

Kaiii3...we're kewl for now..i hit connect..it connected...i clicked on inject and i waited a while and it crashed but I will leave that alone..Thanks..I will wait till you get other stuff done..

Thanks,
BobM.
BobM.

Kaiii3

logs please, must be some reason for a crash ::evilgrin::

unc1rlm

BobM.

Kaiii3

if CTD: please the windows logs as well

unc1rlm

#4
this pc..the client where it is installed?  duh..

Log Name:      Application
Source:        Windows Error Reporting
Date:          8/15/2020 8:33:08 AM
Event ID:      1001
Task Category: None
Level:         Information
Keywords:      Classic
User:          N/A
Computer:      CLIENT
Description:
Fault bucket 1913647542231179340, type 5
Event Name: CLR20r3
Response: Not available
Cab Id: 0

Problem signature:
P1: AIGTech - Traffic Controller.exe
P2: 0.3.1.3
P3: a49e03a1
P4: AIGTech - Traffic Controller
P5: 0.3.1.3
P6: a49e03a1
P7: 55
P8: 0
P9: System.NullReferenceException
P10:

Attached files:
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1595.tmp.dmp
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER243C.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER24BA.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER24C7.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER26CC.tmp.txt

These files may be available here:
\\?\C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_AIGTech - Traffi_3c33d4dc52767726c688f2b9f2e5233fee518851_c19dfe47_7f41e5d6-de41-4362-af75-0f7b35f9be04

Analysis symbol:
Rechecking for solution: 0
Report Id: 8c228703-5f50-4f4c-8877-fb75de83e974
Report Status: 268435456
Hashed bucket: b91428c105a225517a8ea44cfbfd204c
Cab Guid: 0
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Windows Error Reporting" />
    <EventID Qualifiers="0">1001</EventID>
    <Version>0</Version>
    <Level>4</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2020-08-15T12:33:08.7774467Z" />
    <EventRecordID>2141</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>CLIENT</Computer>
    <Security />
  </System>
  <EventData>
    <Data>1913647542231179340</Data>
    <Data>5</Data>
    <Data>CLR20r3</Data>
    <Data>Not available</Data>
    <Data>0</Data>
    <Data>AIGTech - Traffic Controller.exe</Data>
    <Data>0.3.1.3</Data>
    <Data>a49e03a1</Data>
    <Data>AIGTech - Traffic Controller</Data>
    <Data>0.3.1.3</Data>
    <Data>a49e03a1</Data>
    <Data>55</Data>
    <Data>0</Data>
    <Data>System.NullReferenceException</Data>
    <Data>
    </Data>
    <Data>
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1595.tmp.dmp
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER243C.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER24BA.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER24C7.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER26CC.tmp.txt</Data>
    <Data>\\?\C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_AIGTech - Traffi_3c33d4dc52767726c688f2b9f2e5233fee518851_c19dfe47_7f41e5d6-de41-4362-af75-0f7b35f9be04</Data>
    <Data>
    </Data>
    <Data>0</Data>
    <Data>8c228703-5f50-4f4c-8877-fb75de83e974</Data>
    <Data>268435456</Data>
    <Data>b91428c105a225517a8ea44cfbfd204c</Data>
    <Data>0</Data>
  </EventData>
</Event>


BobM.
BobM.

Kaiii3


unc1rlm

never done this...what windows event one you need?

BobM.
BobM.

Kaiii3

in case of a CTD all AIGTech tools are generating normally 2 entries with the same timestamp in the windows event viewer

unc1rlm

let me crash it again...lol

BobM.
BobM.

unc1rlm

#9
Update we are good...


Thanks,
BobM.
BobM.