0% found this document useful (0 votes)
117 views

Feb Crashlog

The document contains details of two access violation exceptions that occurred when executing the Questionaut.exe file located in the user's temp folder. Both exceptions have the same error code and fault address, and occurred when accessing address 00409C99 in the Questionaut.exe module. The call stacks for both exceptions are also identical, indicating the same code path caused both access violations.

Uploaded by

Mad Raja
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
117 views

Feb Crashlog

The document contains details of two access violation exceptions that occurred when executing the Questionaut.exe file located in the user's temp folder. Both exceptions have the same error code and fault address, and occurred when accessing address 00409C99 in the Questionaut.exe module. The call stacks for both exceptions are also identical, indicating the same code path caused both access violations.

Uploaded by

Mad Raja
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
You are on page 1/ 2

//=====================================================

C:\Users\user\AppData\Local\Temp\Rar$EX00.384\Questionaut.exe
Exception code: C0000005 ACCESS_VIOLATION
Fault address: 00409C99 01:00008C99 C:\Users\user\AppData\Local\Temp\Rar$EX00.3
84\Questionaut.exe
Registers:
EAX:00000000
EBX:0040CAEB
ECX:00000000
EDX:00000578
ESI:0012CA84
EDI:75F67BC9
CS:EIP:001B:00409C99
SS:ESP:0023:0012C1A8 EBP:0012C244
DS:0023 ES:0023 FS:003B GS:0000
Flags:00010246
Call stack:
Address Frame
Logical addr Module
00409C99 0012C244 0001:00008C99 C:\Users\user\AppData\Local\Temp\Rar$EX00.384\
Questionaut.exe
00487232 0012C264 0001:00086232 C:\Users\user\AppData\Local\Temp\Rar$EX00.384\
Questionaut.exe
00486244 0012C2C4 0001:00085244 C:\Users\user\AppData\Local\Temp\Rar$EX00.384\
Questionaut.exe
0048644C 0012C2E0 0001:0008544C C:\Users\user\AppData\Local\Temp\Rar$EX00.384\
Questionaut.exe
75F686EF 0012C30C 0001:000176EF C:\Windows\system32\USER32.dll
75F68876 0012C384 0001:00017876 C:\Windows\system32\USER32.dll
75F670F4 0012C3E0 0001:000160F4 C:\Windows\system32\USER32.dll
75F6738F 0012C408 0001:0001638F C:\Windows\system32\USER32.dll
76E4642E 0012C490 0001:0004542E C:\Windows\SYSTEM32\ntdll.dll
00485B17 0012C4D4 0001:00084B17 C:\Users\user\AppData\Local\Temp\Rar$EX00.384\
Questionaut.exe
0040A813 0012FED8 0001:00009813 C:\Users\user\AppData\Local\Temp\Rar$EX00.384\
Questionaut.exe
0048BC5C 0012FF88 0001:0008AC5C C:\Users\user\AppData\Local\Temp\Rar$EX00.384\
Questionaut.exe
753E1174 0012FF94 0001:00050174 C:\Windows\system32\kernel32.dll
76E5B3F5 0012FFD4 0001:0005A3F5 C:\Windows\SYSTEM32\ntdll.dll
76E5B3C8 0012FFEC 0001:0005A3C8 C:\Windows\SYSTEM32\ntdll.dll
//=====================================================
C:\Users\user\AppData\Local\Temp\Rar$EX01.655\Questionaut.exe
Exception code: C0000005 ACCESS_VIOLATION
Fault address: 00409C99 01:00008C99 C:\Users\user\AppData\Local\Temp\Rar$EX01.6
55\Questionaut.exe
Registers:
EAX:00000000
EBX:0040CAEB
ECX:00000000
EDX:00000578
ESI:0012CA84
EDI:75F67BC9
CS:EIP:001B:00409C99
SS:ESP:0023:0012C1A8 EBP:0012C244
DS:0023 ES:0023 FS:003B GS:0000
Flags:00010246

Call stack:
Address Frame
00409C99 0012C244
Questionaut.exe
00487232 0012C264
Questionaut.exe
00486244 0012C2C4
Questionaut.exe
0048644C 0012C2E0
Questionaut.exe
75F686EF 0012C30C
75F68876 0012C384
75F670F4 0012C3E0
75F6738F 0012C408
76E4642E 0012C490
00485B17 0012C4D4
Questionaut.exe
0040A813 0012FED8
Questionaut.exe
0048BC5C 0012FF88
Questionaut.exe
753E1174 0012FF94
76E5B3F5 0012FFD4
76E5B3C8 0012FFEC

Logical addr Module


0001:00008C99 C:\Users\user\AppData\Local\Temp\Rar$EX01.655\
0001:00086232 C:\Users\user\AppData\Local\Temp\Rar$EX01.655\
0001:00085244 C:\Users\user\AppData\Local\Temp\Rar$EX01.655\
0001:0008544C C:\Users\user\AppData\Local\Temp\Rar$EX01.655\
0001:000176EF
0001:00017876
0001:000160F4
0001:0001638F
0001:0004542E
0001:00084B17

C:\Windows\system32\USER32.dll
C:\Windows\system32\USER32.dll
C:\Windows\system32\USER32.dll
C:\Windows\system32\USER32.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Users\user\AppData\Local\Temp\Rar$EX01.655\

0001:00009813 C:\Users\user\AppData\Local\Temp\Rar$EX01.655\
0001:0008AC5C C:\Users\user\AppData\Local\Temp\Rar$EX01.655\
0001:00050174 C:\Windows\system32\kernel32.dll
0001:0005A3F5 C:\Windows\SYSTEM32\ntdll.dll
0001:0005A3C8 C:\Windows\SYSTEM32\ntdll.dll

You might also like