Quantcast
Viewing all articles
Browse latest Browse all 25525

MSTSC Crashing, faulting NTDLL.DLL

I've seen plenty of these but none that I've come across have particularly helped me.  I have a website that has a link that, when clicked, activates a remote session.  Whenever the remote session attempts to start, the application crashes, faulting ntdll.dll.

Here's the full report:

Version=1
EventType=APPCRASH
EventTime=130439647026768209
ReportType=2
Consent=1
UploadTime=130439647028330903
ReportIdentifier=3746a68c-d61e-11e3-8274-a0d3c1649daf
IntegratorReportIdentifier=3746a68b-d61e-11e3-8274-a0d3c1649daf
NsAppName=mstsc.exe
Response.BucketId=9d51053a0de726f71caf0089c5f1a003
Response.BucketTable=4
Response.LegacyBucketId=85910585471
Response.type=4
Sig[0].Name=Application Name
Sig[0].Value=mstsc.exe
Sig[1].Name=Application Version
Sig[1].Value=6.3.9600.16384
Sig[2].Name=Application Timestamp
Sig[2].Value=5215e2b5
Sig[3].Name=Fault Module Name
Sig[3].Value=ntdll.dll
Sig[4].Name=Fault Module Version
Sig[4].Value=6.3.9600.17031
Sig[5].Name=Fault Module Timestamp
Sig[5].Value=530895af
Sig[6].Name=Exception Code
Sig[6].Value=c0000005
Sig[7].Name=Exception Offset
Sig[7].Value=0000000000065e8e
DynamicSig[1].Name=OS Version
DynamicSig[1].Value=6.3.9600.2.0.0.768.101
DynamicSig[2].Name=Locale ID
DynamicSig[2].Value=1033
DynamicSig[22].Name=Additional Information 1
DynamicSig[22].Value=63ce
DynamicSig[23].Name=Additional Information 2
DynamicSig[23].Value=63ceeeac50cf5b8b7f791d66d3e2b38b
DynamicSig[24].Name=Additional Information 3
DynamicSig[24].Value=bafb
DynamicSig[25].Name=Additional Information 4
DynamicSig[25].Value=bafbbbe46897d1db0fb56c7e37c45a7b
UI[2]=C:\Windows\System32\mstsc.exe
UI[3]=Remote Desktop Connection has stopped working
UI[4]=Windows can check online for a solution to the problem.
UI[5]=Check online for a solution and close the program
UI[6]=Check online for a solution later and close the program
UI[7]=Close the program
LoadedModule[0]=C:\Windows\System32\mstsc.exe
LoadedModule[1]=C:\Windows\SYSTEM32\ntdll.dll
LoadedModule[2]=C:\Windows\system32\KERNEL32.DLL
LoadedModule[3]=C:\Windows\system32\KERNELBASE.dll
LoadedModule[4]=C:\Windows\system32\ADVAPI32.dll
LoadedModule[5]=C:\Windows\system32\GDI32.dll
LoadedModule[6]=C:\Windows\system32\USER32.dll
LoadedModule[7]=C:\Windows\system32\msvcrt.dll
LoadedModule[8]=C:\Windows\system32\ole32.dll
LoadedModule[9]=C:\Windows\system32\OLEAUT32.dll
LoadedModule[10]=C:\Windows\system32\SHELL32.dll
LoadedModule[11]=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1\COMCTL32.dll
LoadedModule[12]=C:\Windows\system32\COMDLG32.dll
LoadedModule[13]=C:\Windows\system32\SHLWAPI.dll
LoadedModule[14]=C:\Windows\system32\CRYPT32.dll
LoadedModule[15]=C:\Windows\System32\WINHTTP.dll
LoadedModule[16]=C:\Windows\System32\credui.dll
LoadedModule[17]=C:\Windows\System32\Secur32.dll
LoadedModule[18]=C:\Windows\System32\CRYPTUI.dll
LoadedModule[19]=C:\Windows\system32\CFGMGR32.dll
LoadedModule[20]=C:\Windows\system32\WS2_32.dll
LoadedModule[21]=C:\Windows\System32\NETAPI32.dll
LoadedModule[22]=C:\Windows\system32\RPCRT4.dll
LoadedModule[23]=C:\Windows\System32\WINMM.dll
LoadedModule[24]=C:\Windows\System32\IPHLPAPI.DLL
LoadedModule[25]=C:\Windows\SYSTEM32\sechost.dll
LoadedModule[26]=C:\Windows\SYSTEM32\combase.dll
LoadedModule[27]=C:\Windows\system32\MSASN1.dll
LoadedModule[28]=C:\Windows\system32\NSI.dll
LoadedModule[29]=C:\Windows\System32\netutils.dll
LoadedModule[30]=C:\Windows\System32\srvcli.dll
LoadedModule[31]=C:\Windows\System32\wkscli.dll
LoadedModule[32]=C:\Windows\System32\WINMMBASE.dll
LoadedModule[33]=C:\Windows\System32\WINNSI.DLL
LoadedModule[34]=C:\Windows\System32\SHCORE.DLL
LoadedModule[35]=C:\Windows\System32\DEVOBJ.dll
LoadedModule[36]=C:\Windows\System32\SSPICLI.DLL
LoadedModule[37]=C:\Windows\system32\IMM32.DLL
LoadedModule[38]=C:\Windows\system32\MSCTF.dll
LoadedModule[39]=C:\Windows\SYSTEM32\kernel.appcore.dll
LoadedModule[40]=C:\Windows\System32\CRYPTBASE.dll
LoadedModule[41]=C:\Windows\System32\bcryptPrimitives.dll
LoadedModule[42]=C:\Windows\system32\uxtheme.dll
LoadedModule[43]=C:\ProgramData\Z@!-2133ded7-d902-4368-add8-1834423173b7.tmp
LoadedModule[44]=C:\Windows\system32\PSAPI.DLL
LoadedModule[45]=C:\Windows\system32\dwmapi.dll
LoadedModule[46]=C:\Windows\SYSTEM32\clbcatq.dll
LoadedModule[47]=C:\Windows\System32\CRYPTSP.dll
LoadedModule[48]=C:\Windows\system32\rsaenh.dll
LoadedModule[49]=C:\Windows\System32\bcrypt.dll
LoadedModule[50]=C:\Windows\SYSTEM32\sxs.dll
LoadedModule[51]=C:\Windows\System32\credssp.dll
LoadedModule[52]=C:\Windows\System32\NTASN1.dll
LoadedModule[53]=C:\Windows\System32\ncrypt.dll
LoadedModule[54]=C:\Windows\SYSTEM32\gpapi.dll
LoadedModule[55]=C:\Windows\System32\PROPSYS.dll
LoadedModule[56]=C:\Windows\System32\mstscax.dll
LoadedModule[57]=C:\Windows\System32\d2d1.dll
LoadedModule[58]=C:\Windows\System32\d3d11.dll
LoadedModule[59]=C:\Windows\System32\MSACM32.dll
LoadedModule[60]=C:\Windows\System32\VERSION.dll
LoadedModule[61]=C:\Windows\system32\SETUPAPI.dll
LoadedModule[62]=C:\Windows\System32\DWrite.dll
LoadedModule[63]=C:\Windows\System32\pdh.dll
LoadedModule[64]=C:\Windows\System32\dxgi.dll
LoadedModule[65]=C:\Windows\system32\explorerframe.dll
LoadedModule[66]=C:\Windows\system32\DUser.dll
LoadedModule[67]=C:\Windows\system32\DUI70.dll
LoadedModule[68]=C:\Windows\system32\WINTRUST.dll
LoadedModule[69]=C:\Windows\System32\DPAPI.dll
LoadedModule[70]=C:\Program Files\Hewlett-Packard\SimplePass\vchannel.dll
LoadedModule[71]=C:\Windows\System32\mfc100.dll
LoadedModule[72]=C:\Windows\System32\MSVCR100.dll
LoadedModule[73]=C:\Windows\System32\MSIMG32.dll
LoadedModule[74]=C:\Windows\System32\MFC100ENU.DLL
LoadedModule[75]=C:\Program Files\Hewlett-Packard\SimplePass\storeng.dll
LoadedModule[76]=C:\Windows\System32\ACTIVEDS.dll
LoadedModule[77]=C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll
LoadedModule[78]=C:\Windows\System32\adsldpc.dll
LoadedModule[79]=C:\Windows\System32\LOGONCLI.DLL
LoadedModule[80]=C:\Windows\system32\WLDAP32.dll
LoadedModule[81]=C:\Windows\System32\DSROLE.DLL
LoadedModule[82]=C:\Windows\System32\SAMCLI.DLL
LoadedModule[83]=C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll
LoadedModule[84]=C:\Windows\System32\WTSAPI32.dll
LoadedModule[85]=C:\Windows\System32\MSVCP100.dll
LoadedModule[86]=C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll
LoadedModule[87]=C:\Windows\system32\MF.dll
LoadedModule[88]=C:\Windows\System32\MFCORE.DLL
LoadedModule[89]=C:\Windows\System32\ksuser.dll
LoadedModule[90]=C:\Windows\system32\MFPlat.dll
LoadedModule[91]=C:\Windows\System32\RTWorkQ.DLL
LoadedModule[92]=C:\Windows\System32\AVRT.dll
LoadedModule[93]=C:\Windows\System32\MSAudDecMFT.dll
LoadedModule[94]=C:\Windows\System32\MMDevApi.dll
LoadedModule[95]=C:\Windows\System32\perfos.dll
LoadedModule[96]=C:\Windows\System32\msxml6.dll
LoadedModule[97]=C:\Windows\system32\NLAapi.dll
LoadedModule[98]=C:\Windows\System32\rasadhlp.dll
LoadedModule[99]=C:\Windows\System32\WINSTA.dll
LoadedModule[100]=C:\Windows\System32\profapi.dll
LoadedModule[101]=C:\Windows\System32\AUDIOSES.DLL
LoadedModule[102]=C:\Windows\SYSTEM32\powrprof.dll
LoadedModule[103]=C:\Windows\System32\dhcpcsvc6.DLL
LoadedModule[104]=C:\Windows\System32\dhcpcsvc.DLL
LoadedModule[105]=C:\Windows\System32\webio.dll
LoadedModule[106]=C:\Windows\system32\mswsock.dll
LoadedModule[107]=C:\Windows\System32\DNSAPI.dll
LoadedModule[108]=C:\Program Files\Bonjour\mdnsNSP.dll
LoadedModule[109]=C:\Windows\System32\fwpuclnt.dll
LoadedModule[110]=C:\Windows\system32\schannel.DLL
LoadedModule[111]=C:\Windows\system32\ncryptsslp.dll
LoadedModule[112]=C:\Windows\system32\msv1_0.DLL
LoadedModule[113]=C:\Windows\System32\cryptdll.dll
LoadedModule[114]=C:\Windows\system32\tspkg.DLL
LoadedModule[115]=C:\Windows\System32\wdmaud.drv
LoadedModule[116]=C:\Windows\System32\msacm32.drv
LoadedModule[117]=C:\Windows\System32\midimap.dll
State[0].Key=Transport.DoneStage1
State[0].Value=1
FriendlyEventName=Stopped working
ConsentKey=APPCRASH
AppName=Remote Desktop Connection
AppPath=C:\Windows\System32\mstsc.exe
NsPartner=windows
NsGroup=windows8
ApplicationIdentity=A985A2F580E1E14BEC155E8CD1820F72

Any help would be greatly appreciated!

-Kyle


Viewing all articles
Browse latest Browse all 25525

Trending Articles