Skip to content

Instantly share code, notes, and snippets.

@gortok
Created April 7, 2020 00:44
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save gortok/4e13b9d4f3cfb712c4345d6354f1c641 to your computer and use it in GitHub Desktop.
Save gortok/4e13b9d4f3cfb712c4345d6354f1c641 to your computer and use it in GitHub Desktop.
Babysmash Event Viewer WER file
Version=1
EventType=CLR20r3
EventTime=132306936210374710
ReportType=2
Consent=1
UploadTime=132306936212054996
ReportStatus=268435456
ReportIdentifier=4fe7a0bf-24c9-49bc-a068-c6c791d9d452
Wow64Host=34404
Wow64Guest=332
OriginalFilename=BabySmash.exe
AppSessionGuid=000025bc-0003-0009-bdeb-f71d750cd601
TargetAppId=W:0006d372cb6714ed7d16fcd1bf3f4233d19d00000000!0000fdd9cbbb991f6e10aa4d63e8d926cd150ba4b2c7!BabySmash.exe
TargetAppVer=2015//04//08:21:26:58!163dd2!BabySmash.exe
BootId=4294967295
TargetAsId=43940
IsFatal=4294967295
EtwNonCollectReason=1
Response.BucketId=b554ce8f711da8cf61564e1032609f4b
Response.BucketTable=5
Response.LegacyBucketId=1249271778113527627
Response.type=4
Sig[0].Name=Problem Signature 01
Sig[0].Value=babysmash.exe
Sig[1].Name=Problem Signature 02
Sig[1].Value=1.0.2.0
Sig[2].Name=Problem Signature 03
Sig[2].Value=55259d22
Sig[3].Name=Problem Signature 04
Sig[3].Value=System.Configuration
Sig[4].Name=Problem Signature 05
Sig[4].Value=2.0.0.0
Sig[5].Name=Problem Signature 06
Sig[5].Value=5c7d6dfc
Sig[6].Name=Problem Signature 07
Sig[6].Value=9d
Sig[7].Name=Problem Signature 08
Sig[7].Value=48
Sig[8].Name=Problem Signature 09
Sig[8].Value=IOIBMURHYNRXKW0ZXKYRVFN0BOYYUFOW
DynamicSig[1].Name=OS Version
DynamicSig[1].Value=10.0.18363.2.0.0.256.48
DynamicSig[2].Name=Locale ID
DynamicSig[2].Value=1033
UI[2]=C:\Users\George\AppData\Local\Apps\2.0\Y64QA16Y.80B\M98YXRH6.CL7\baby..tion_844c62deb32b7b40_0001.0001_0b5263efa51d9d27\BabySmash.exe
LoadedModule[0]=C:\Users\George\AppData\Local\Apps\2.0\Y64QA16Y.80B\M98YXRH6.CL7\baby..tion_844c62deb32b7b40_0001.0001_0b5263efa51d9d27\BabySmash.exe
LoadedModule[1]=C:\WINDOWS\SYSTEM32\ntdll.dll
LoadedModule[2]=C:\WINDOWS\SYSTEM32\MSCOREE.DLL
LoadedModule[3]=C:\WINDOWS\System32\KERNEL32.dll
LoadedModule[4]=C:\WINDOWS\System32\KERNELBASE.dll
LoadedModule[5]=C:\WINDOWS\System32\ADVAPI32.dll
LoadedModule[6]=C:\WINDOWS\System32\msvcrt.dll
LoadedModule[7]=C:\WINDOWS\System32\sechost.dll
LoadedModule[8]=C:\WINDOWS\System32\RPCRT4.dll
LoadedModule[9]=C:\WINDOWS\System32\SspiCli.dll
LoadedModule[10]=C:\WINDOWS\System32\CRYPTBASE.dll
LoadedModule[11]=C:\WINDOWS\System32\bcryptPrimitives.dll
LoadedModule[12]=C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
LoadedModule[13]=C:\WINDOWS\System32\SHLWAPI.dll
LoadedModule[14]=C:\WINDOWS\System32\combase.dll
LoadedModule[15]=C:\WINDOWS\System32\ucrtbase.dll
LoadedModule[16]=C:\WINDOWS\System32\GDI32.dll
LoadedModule[17]=C:\WINDOWS\System32\win32u.dll
LoadedModule[18]=C:\WINDOWS\System32\gdi32full.dll
LoadedModule[19]=C:\WINDOWS\System32\msvcp_win.dll
LoadedModule[20]=C:\WINDOWS\System32\USER32.dll
LoadedModule[21]=C:\WINDOWS\System32\IMM32.DLL
LoadedModule[22]=C:\WINDOWS\System32\kernel.appcore.dll
LoadedModule[23]=C:\WINDOWS\SYSTEM32\VERSION.dll
LoadedModule[24]=C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
LoadedModule[25]=C:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9659_none_d08cfd96442b25cc\MSVCR80.dll
LoadedModule[26]=C:\WINDOWS\System32\shell32.dll
LoadedModule[27]=C:\WINDOWS\System32\cfgmgr32.dll
LoadedModule[28]=C:\WINDOWS\System32\shcore.dll
LoadedModule[29]=C:\WINDOWS\System32\windows.storage.dll
LoadedModule[30]=C:\WINDOWS\System32\profapi.dll
LoadedModule[31]=C:\WINDOWS\System32\powrprof.dll
LoadedModule[32]=C:\WINDOWS\System32\UMPDC.dll
LoadedModule[33]=C:\WINDOWS\System32\cryptsp.dll
LoadedModule[34]=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\f6a9799facd58aab04d11863c0101c09\mscorlib.ni.dll
LoadedModule[35]=C:\WINDOWS\System32\ole32.dll
LoadedModule[36]=C:\WINDOWS\system32\uxtheme.dll
LoadedModule[37]=C:\WINDOWS\SYSTEM32\dfshim.dll
LoadedModule[38]=C:\WINDOWS\SYSTEM32\urlmon.dll
LoadedModule[39]=C:\WINDOWS\SYSTEM32\iertutil.dll
LoadedModule[40]=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e174b53f30801b5836c47881e646c80e\System.ni.dll
LoadedModule[41]=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Core\e89e85f01149a76a5f895b2c2427ebe1\System.Core.ni.dll
LoadedModule[42]=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\05d6f71de05773922578068ea2943b19\WindowsBase.ni.dll
LoadedModule[43]=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\f425b508f0f4829d9a224b92897fd6f6\PresentationCore.ni.dll
LoadedModule[44]=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8b2b5488e9f73e0e3e50c9474f5d93ba\PresentationFramework.ni.dll
LoadedModule[45]=C:\Windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll
LoadedModule[46]=C:\WINDOWS\System32\OLEAUT32.dll
LoadedModule[47]=C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
LoadedModule[48]=C:\WINDOWS\System32\psapi.dll
LoadedModule[49]=C:\WINDOWS\System32\MSCTF.dll
LoadedModule[50]=C:\WINDOWS\system32\rsaenh.dll
LoadedModule[51]=C:\WINDOWS\System32\bcrypt.dll
LoadedModule[52]=C:\WINDOWS\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll
LoadedModule[53]=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\7edcdae474b97fe5b2d89fef45240ac4\System.Deployment.ni.dll
LoadedModule[54]=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\2c2faaeb810b28ad2d2d72999fc96900\System.Drawing.ni.dll
LoadedModule[55]=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\526c2035d9b7a5c79decda6877ba14be\System.Windows.Forms.ni.dll
LoadedModule[56]=C:\WINDOWS\SYSTEM32\shfolder.dll
LoadedModule[57]=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\1099cdb8c15e2b6f9341f4200255ed8d\System.Xml.ni.dll
LoadedModule[58]=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\8823dbbec7a3b08debcb790bf1d9fbf6\System.Configuration.ni.dll
LoadedModule[59]=C:\WINDOWS\SYSTEM32\rasapi32.dll
LoadedModule[60]=C:\WINDOWS\SYSTEM32\rasman.dll
LoadedModule[61]=C:\WINDOWS\SYSTEM32\rtutils.dll
LoadedModule[62]=C:\WINDOWS\System32\WS2_32.dll
LoadedModule[63]=C:\WINDOWS\system32\mswsock.dll
LoadedModule[64]=C:\WINDOWS\SYSTEM32\winhttp.dll
LoadedModule[65]=C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL
LoadedModule[66]=C:\WINDOWS\System32\NSI.dll
LoadedModule[67]=C:\WINDOWS\SYSTEM32\dhcpcsvc6.DLL
LoadedModule[68]=C:\WINDOWS\SYSTEM32\dhcpcsvc.DLL
LoadedModule[69]=C:\WINDOWS\SYSTEM32\wininet.dll
LoadedModule[70]=C:\WINDOWS\SYSTEM32\ondemandconnroutehelper.dll
LoadedModule[71]=C:\WINDOWS\SYSTEM32\WINNSI.DLL
LoadedModule[72]=C:\WINDOWS\SYSTEM32\DNSAPI.dll
LoadedModule[73]=C:\WINDOWS\SYSTEM32\DWMAPI.dll
LoadedModule[74]=C:\WINDOWS\SYSTEM32\d3d9.dll
LoadedModule[75]=C:\WINDOWS\SYSTEM32\dxcore.dll
LoadedModule[76]=C:\Windows\System32\rasadhlp.dll
LoadedModule[77]=C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_db678424d2641c3d\nvldumd.dll
LoadedModule[78]=C:\WINDOWS\System32\fwpuclnt.dll
LoadedModule[79]=C:\WINDOWS\System32\crypt32.dll
LoadedModule[80]=C:\WINDOWS\System32\MSASN1.dll
LoadedModule[81]=C:\WINDOWS\System32\WINTRUST.DLL
LoadedModule[82]=C:\WINDOWS\System32\imagehlp.dll
LoadedModule[83]=C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_db678424d2641c3d\nvd3dum.dll
LoadedModule[84]=C:\WINDOWS\SYSTEM32\WINMM.dll
LoadedModule[85]=C:\WINDOWS\SYSTEM32\winmmbase.dll
LoadedModule[86]=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\346b2ea67caa275ff360c5786f2ff3a6\PresentationFramework.Aero.ni.dll
State[0].Key=Transport.DoneStage1
State[0].Value=1
OsInfo[0].Key=vermaj
OsInfo[0].Value=10
OsInfo[1].Key=vermin
OsInfo[1].Value=0
OsInfo[2].Key=verbld
OsInfo[2].Value=18363
OsInfo[3].Key=ubr
OsInfo[3].Value=720
OsInfo[4].Key=versp
OsInfo[4].Value=0
OsInfo[5].Key=arch
OsInfo[5].Value=9
OsInfo[6].Key=lcid
OsInfo[6].Value=1033
OsInfo[7].Key=geoid
OsInfo[7].Value=244
OsInfo[8].Key=sku
OsInfo[8].Value=48
OsInfo[9].Key=domain
OsInfo[9].Value=0
OsInfo[10].Key=prodsuite
OsInfo[10].Value=256
OsInfo[11].Key=ntprodtype
OsInfo[11].Value=1
OsInfo[12].Key=platid
OsInfo[12].Value=10
OsInfo[13].Key=sr
OsInfo[13].Value=0
OsInfo[14].Key=tmsi
OsInfo[14].Value=64439
OsInfo[15].Key=osinsty
OsInfo[15].Value=3
OsInfo[16].Key=iever
OsInfo[16].Value=11.719.18362.0-11.0.180
OsInfo[17].Key=portos
OsInfo[17].Value=0
OsInfo[18].Key=ram
OsInfo[18].Value=32724
OsInfo[19].Key=svolsz
OsInfo[19].Value=475
OsInfo[20].Key=wimbt
OsInfo[20].Value=0
OsInfo[21].Key=blddt
OsInfo[21].Value=190318
OsInfo[22].Key=bldtm
OsInfo[22].Value=1202
OsInfo[23].Key=bldbrch
OsInfo[23].Value=19h1_release
OsInfo[24].Key=bldchk
OsInfo[24].Value=0
OsInfo[25].Key=wpvermaj
OsInfo[25].Value=0
OsInfo[26].Key=wpvermin
OsInfo[26].Value=0
OsInfo[27].Key=wpbuildmaj
OsInfo[27].Value=0
OsInfo[28].Key=wpbuildmin
OsInfo[28].Value=0
OsInfo[29].Key=osver
OsInfo[29].Value=10.0.18362.720.amd64fre.19h1_release.190318-1202
OsInfo[30].Key=buildflightid
OsInfo[30].Value=E9D7DCF3-926E-471A-8D35-C0D4EA197451.1
OsInfo[31].Key=edition
OsInfo[31].Value=Professional
OsInfo[32].Key=ring
OsInfo[33].Key=expid
OsInfo[34].Key=containerid
OsInfo[35].Key=containertype
OsInfo[36].Key=edu
OsInfo[36].Value=0
FriendlyEventName=Stopped working
ConsentKey=CLR20r3
AppName=BabySmash
AppPath=C:\Users\George\AppData\Local\Apps\2.0\Y64QA16Y.80B\M98YXRH6.CL7\baby..tion_844c62deb32b7b40_0001.0001_0b5263efa51d9d27\BabySmash.exe
ReportDescription=Stopped working
ApplicationIdentity=00000000000000000000000000000000
MetadataHash=352236986
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment