Jump to content

AdwCleaner 7.1.1 Crash (Debug log)


Recommended Posts

DebugDiag Analysis Report 


   Dumps: 
0/0 


   Rules: 
0/0 


 

0

Error
 


0

Warning
 


0

Information
 


0

Notification
  

 


Analysis Summary
 

 Error 


Description Recommendation 

In adwcleaner_7.1.0.0.exe.7864.dmp the assembly instruction at msvcrt!memcpy+5a in C:\Windows\SysWOW64\msvcrt.dll from Microsoft Corporation has caused an access violation exception (0xC0000005) when trying to read from memory location 0x01a7c000 on thread 10
 Please follow up with the vendor Microsoft Corporation for C:\Windows\SysWOW64\msvcrt.dll
 
The following threads in adwcleaner_7.1.0.0.exe.7864.dmp are blocked by an unhandled exception

( 10 )

7,69% of threads blocked (1 threads)

 Please see the Recovered Call Stack for thread 10 based on the restored exception and context record passed to the exception filter. 
 

 


Analysis Details 


CrashHangAnalysis

Report for adwcleaner_7.1.0.0.exe.7864.dmp

Type of Analysis Performed   Combined Crash/Hang Analysis 
Machine Name    
Operating System   Windows 7Service Pack 1 
Number Of Processors    
Process ID   7864 
Process Image   C:\Users\***\Downloads\adwcleaner_7.1.0.0.exe 
Command Line   "C:\Users\***\Downloads\adwcleaner_7.1.0.0.exe"  
System Up-Time   00:00:00 
Process Up-Time   00:00:12 
Processor Type   X86 
Process Bitness   32-Bit 

Top 5 Threads by CPU time


Note - Times include both user mode and kernel mode for each thread 
Extended thread information (including thread CPU times) is unavailable in this dump 


CLR Information

Thread Report


•Thread 2
•3
•7
•12

4 Threads (30% of all threads) have this same call stack.
Note: Grouping of identical threads can be disabled in the 'Preferences' tab of the Analysis Options


Thread 2 - System ID 7468

Thread 3 - System ID 5176

Thread 7 - System ID 4068

Thread 12 - System ID 6492

ntdll!NtWaitForWorkViaWorkerFactory+12 
ntdll!TppWorkerThread+209 
kernel32!BaseThreadInitThunk+e 
ntdll!__RtlUserThreadStart+70 
ntdll!_RtlUserThreadStart+1b 

•Thread 5
•11

2 Threads (15% of all threads) have this same call stack.
Note: Grouping of identical threads can be disabled in the 'Preferences' tab of the Analysis Options


Thread 5 - System ID 1284


This thread is not fully resolved and may or may not be a problem. Further analysis of these threads may be required.

Thread 11 - System ID 4972


This thread is not fully resolved and may or may not be a problem. Further analysis of these threads may be required.

ntdll!ZwWaitForMultipleObjects+15 
KERNELBASE!WaitForMultipleObjectsEx+100 
kernel32!WaitForMultipleObjectsExImplementation+e0 
user32!RealMsgWaitForMultipleObjectsEx+14d 
adwcleaner_7_1_0_0+17e724 
adwcleaner_7_1_0_0+14965f 
adwcleaner_7_1_0_0+11c964 
adwcleaner_7_1_0_0+8c9de1 
kernel32!BaseThreadInitThunk+e 
ntdll!__RtlUserThreadStart+70 
ntdll!_RtlUserThreadStart+1b 


Thread 0 - System ID 7136


This thread is not fully resolved and may or may not be a problem. Further analysis of these threads may be required.

ntdll!ZwWaitForMultipleObjects+15 
KERNELBASE!WaitForMultipleObjectsEx+100 
kernel32!WaitForMultipleObjectsExImplementation+e0 
user32!RealMsgWaitForMultipleObjectsEx+14d 
adwcleaner_7_1_0_0+17e724 
adwcleaner_7_1_0_0+713954 
adwcleaner_7_1_0_0+11939 
adwcleaner_7_1_0_0+1199b 
adwcleaner_7_1_0_0+8c0d1b 
kernel32!BaseThreadInitThunk+e 
ntdll!__RtlUserThreadStart+70 
ntdll!_RtlUserThreadStart+1b 


Thread 1 - System ID 4336

ntdll!ZwWaitForMultipleObjects+15 
ntdll!TppWaiterpThread+32e 
kernel32!BaseThreadInitThunk+e 
ntdll!__RtlUserThreadStart+70 
ntdll!_RtlUserThreadStart+1b 


Thread 4 - System ID 2024

ntdll!ZwDelayExecution+15 
KERNELBASE!SleepEx+65 
KERNELBASE!Sleep+f 
ole32!CROIDTable::WorkerThreadLoop+14 
ole32!CRpcThreadCache::RpcWorkerThreadEntry+16 
kernel32!BaseThreadInitThunk+e 
ntdll!__RtlUserThreadStart+70 
ntdll!_RtlUserThreadStart+1b 


Thread 6 - System ID 7332

ntdll!ZwWaitForMultipleObjects+15 
kernel32!BaseThreadInitThunk+e 
ntdll!__RtlUserThreadStart+70 
ntdll!_RtlUserThreadStart+1b 


Thread 8 - System ID 1768


This thread is not fully resolved and may or may not be a problem. Further analysis of these threads may be required.

ntdll!NtWaitForSingleObject+15 
KERNELBASE!WaitForSingleObjectEx+98 
kernel32!WaitForSingleObjectExImplementation+75 
adwcleaner_7_1_0_0+1bf2b4 
adwcleaner_7_1_0_0+1bf3cc 
adwcleaner_7_1_0_0+11c964 
adwcleaner_7_1_0_0+8c9de1 
kernel32!BaseThreadInitThunk+e 
ntdll!__RtlUserThreadStart+70 
ntdll!_RtlUserThreadStart+1b 


Thread 9 - System ID 3768

ntdll!ZwRemoveIoCompletion+15 
kernel32!BaseThreadInitThunk+e 
ntdll!__RtlUserThreadStart+70 
ntdll!_RtlUserThreadStart+1b 


Thread 10 - System ID 6892


This thread is blocked by an unhandled exception

ntdll!ZwWaitForMultipleObjects+15 
KERNELBASE!WaitForMultipleObjectsEx+100 
kernel32!WaitForMultipleObjectsExImplementation+e0 
kernel32!WaitForMultipleObjects+18 
kernel32!WerpReportFaultInternal+186 
kernel32!WerpReportFault+70 
kernel32!BasepReportFault+20 
kernel32!UnhandledExceptionFilter+1af 
ntdll!__RtlUserThreadStart+62 
ntdll!_RtlUserThreadStart+1b 
Could not restore the exception information passed to the exception filter. Crash analysis unavailable.

Well-Known COM STA Threads Report


STA Name   

Thread ID   

Thread Status   

Call Status

Main STA    0 In-Call (bad symbols)    not fully resolved and may or may not be a problem. Further analysis of this thread may be required 


Exception Information


MSVCRT!MEMCPY+5AIn adwcleaner_7.1.0.0.exe.7864.dmp the assembly instruction at msvcrt!memcpy+5a in C:\Windows\SysWOW64\msvcrt.dll from Microsoft Corporation has caused an access violation exception (0xC0000005) when trying to read from memory location 0x01a7c000 on thread 10


Module Information 

Image Name: C:\Windows\SysWOW64\msvcrt.dll   Symbol Type:  PDB 
Base address: 0x00905a4d   Time Stamp:  Fri Dec 16 08:45:38 2011  
Checksum: 0x00000000   Comments:   
COM DLL: False   Company Name:  Microsoft Corporation 
ISAPIExtension: False   File Description:  Windows NT CRT DLL 
ISAPIFilter: False   File Version:  7.0.7601.17744 (win7sp1_gdr.111215-1535) 
Managed DLL: False   Internal Name:  msvcrt.dll 
VB DLL: False   Legal Copyright:  Â© Microsoft Corporation. All rights reserved. 
Loaded Image Name:  msvcrt.dll   Legal Trademarks:   
Mapped Image Name:  c:\symbols\msvcrt.dll\4EEAF722ac000\msvcrt.dll   Original filename:  msvcrt.dll 
Module name:  msvcrt   Private Build:   
Single Threaded:  False   Product Name:  Microsoft® Windows® Operating System 
Module Size:  688 KBytes   Product Version:  7.0.7601.17744 
Symbol File Name:  c:\symbols\msvcrt.pdb\F1D253F9555C46DF8076400A52B3A9292\msvcrt.pdb   Special Build:  & 


  

 

Analysis Rule Summary 
 

Rule Name Status Details 

CrashHangAnalysis - v (2.2.0.14) Completed   
 


close


 

close


 


 
Table of Contents


CrashHangAnalysis


Report for adwcleaner_7.1.0.0.exe.7864.dmp


Top 5 Threads by CPU time

Thread Report


Well-Known COM STA Threads Report
 

 

Edited by Makinero
Link to post
Share on other sites

  • Staff

***This is an automated reply***

Hi,

Thanks for posting in the AdwCleaner Help forum.

Someone will reply shortly, but in the meantime here are a few resources which may help resolve your issue:

Thanks in advance for your patience.

-The Malwarebytes Forum Team

Link to post
Share on other sites

Could we get a little more information to help in investigating this issue--

NOTE: The tools and the information obtained is safe and not harmful to your privacy or your computer, please allow the programs to run if blocked by your system.

  • Download Malwarebytes Support Tool
  • Once the file is downloaded, open your Downloads folder/location of the downloaded file
  • Double-click mb-support-X.X.X.XXXX.exe to run the program
    • You may be prompted by User Account Control (UAC) to allow changes to be made to your computer. Click Yes to consent.
  • Place a checkmark next to Accept License Agreement and click Next
  • You will be presented with a page stating, "Welcome to the Malwarebytes Support Tool!"
  • Click the Advanced Options link
    welcome mbst.png
  • Click the Gather Logs button
    gatherlogs.png
  • A progress bar will appear and the program will proceed to gather troubleshooting information from your computer
  • Upon completion, click OK
  • A file named mbst-grab-results.zip will be saved to your Desktop
  • Please attach the file in your next reply. Click "Reveal Hidden Contents" below for details on how to attach a file:
      Hide contents

    To save attachments, please click the link as shown below. You can click and drag the files to this bar or you can click the choose files, then browse to where your files are located, select them and click the Open button.

    _mb_attach.jpg.a0465aaafd6cae688aa38ab16

     

    After posting your new post, make sure you click the Follow button near the top right of this page, and select the option "An email when new content is posted Change how the notification is sent" so that you're alerted by email when someone has replied to your post.

    _mb_follow.jpg.7868cc281f66ac22e919c2c48

    _mb_follow_options.jpg.dcb79fc10aa35beb0

Edited by vbarytskyy
Link to post
Share on other sites

In the log I found in the file name - my password and username MOJ and password members129, and other information that may leak.
No other information is required, everything can be read from the DUMP file.

 Error 


Description Recommendation 

In adwcleaner_7.1.0.0.exe.7864.dmp the assembly instruction at msvcrt!memcpy+5a in C:\Windows\SysWOW64\msvcrt.dll from Microsoft Corporation has caused an access violation exception (0xC0000005) when trying to read from memory location 0x01a7c000 on thread 10
 Please follow up with the vendor Microsoft Corporation for C:\Windows\SysWOW64\msvcrt.dll
 
The following threads in adwcleaner_7.1.0.0.exe.7864.dmp are blocked by an unhandled exception

I'm not an expert or developer, but the DUMP file has enabled me to get a lot of information and solve the problem quickly. I regret that having a log with DUMP you can not read anything and not suggest solving the problem. Having a DUMP file you can 100% solve each error. Now it is working :)

 

Screen_Shot_05-02-18_at_10.59_AM.jpg

Link to post
Share on other sites

  • 1 month later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.