This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Win2008R2 64bit WireShark APPCRASH

0

I cannot get any version of WireShark v1.8.3 (32bit or 64bit) to run on a Win2008R2. The error below occurs when the WireShark is starting, how can I get it to work??? I also tried to go back a version and still it wouldn't work...

Problem signature: Problem Event Name: APPCRASH Application Name: wireshark.exe Application Version: 1.8.3.45256 Application Timestamp: 506b148f Fault Module Name: StackHash_3184 Fault Module Version: 6.1.7601.17725 Fault Module Timestamp: 4ec4aa8e Exception Code: c0000374 Exception Offset: 00000000000c40f2 OS Version: 6.1.7601.2.1.0.272.7 Locale ID: 1033 Additional Information 1: 3184 Additional Information 2: 31843cf121481c946ab29ceb8ed6d936 Additional Information 3: 9983 Additional Information 4: 9983a7843ed160e25bc3c9f876f45c8f

Log Name: Application
Source: Application Error
Date: 10/22/2012 9:19:24 AM
Event ID: 1000
Task Category: (100)
Level: Error
Keywords: Classic
User: N/A
Computer:
Description:
Faulting application name: wireshark.exe, version: 1.8.3.45256, time stamp: 0x506b148f
Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e
Exception code: 0xc0000374
Fault offset: 0x00000000000c40f2
Faulting process id: 0x39fc
Faulting application start time: 0x01cdb0603bbba52c
Faulting application path: C:\Program Files\Wireshark\wireshark.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 7a0e6f0d-1c53-11e2-a35f-6431504ae268
Event Xml: <event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"> <system> <provider name="Application Error"/> <eventid qualifiers="0">1000</eventid> <level>2</level> <task>100</task> <keywords>0x80000000000000</keywords> <timecreated systemtime="2012-10-22T14:19:24.000000000Z"/> <eventrecordid>16734</eventrecordid> <channel>Application</channel> <computer></computer> <security/> </system> <eventdata> <data>wireshark.exe</data> <data>1.8.3.45256</data> <data>506b148f</data> <data>ntdll.dll</data> <data>6.1.7601.17725</data> <data>4ec4aa8e</data> <data>c0000374</data> <data>00000000000c40f2</data> <data>39fc</data> <data>01cdb0603bbba52c</data> <data>C:\Program Files\Wireshark\wireshark.exe</data> <data>C:\Windows\SYSTEM32\ntdll.dll</data> <data>7a0e6f0d-1c53-11e2-a35f-6431504ae268</data> </eventdata> </event>

Version=1
EventType=APPCRASH
EventTime=129953891640935850
ReportType=2
Consent=1
ReportIdentifier=7a0e6f0e-1c53-11e2-a35f-6431504ae268
IntegratorReportIdentifier=7a0e6f0d-1c53-11e2-a35f-6431504ae268
Response.type=4
Sig[0].Name=Application Name
Sig[0].Value=wireshark.exe
Sig[1].Name=Application Version
Sig[1].Value=1.8.3.45256
Sig[2].Name=Application Timestamp
Sig[2].Value=506b148f
Sig[3].Name=Fault Module Name
Sig[3].Value=StackHash_3184
Sig[4].Name=Fault Module Version
Sig[4].Value=6.1.7601.17725
Sig[5].Name=Fault Module Timestamp
Sig[5].Value=4ec4aa8e
Sig[6].Name=Exception Code
Sig[6].Value=c0000374
Sig[7].Name=Exception Offset
Sig[7].Value=00000000000c40f2
DynamicSig[1].Name=OS Version
DynamicSig[1].Value=6.1.7601.2.1.0.272.7
DynamicSig[2].Name=Locale ID
DynamicSig[2].Value=1033
DynamicSig[22].Name=Additional Information 1
DynamicSig[22].Value=3184
DynamicSig[23].Name=Additional Information 2
DynamicSig[23].Value=31843cf121481c946ab29ceb8ed6d936
DynamicSig[24].Name=Additional Information 3
DynamicSig[24].Value=9983
DynamicSig[25].Name=Additional Information 4
DynamicSig[25].Value=9983a7843ed160e25bc3c9f876f45c8f
UI[2]=C:\Program Files\Wireshark\wireshark.exe
UI[3]=Wireshark has stopped working
UI[4]=Windows can check online for a solution to the problem.
UI[5]=Check online for a solution and close the program
UI[6]=Check online for a solution later and close the program
UI[7]=Close the program
LoadedModule[0]=C:\Program Files\Wireshark\wireshark.exe
LoadedModule[1]=C:\Windows\SYSTEM32\ntdll.dll
LoadedModule[2]=C:\Windows\system32\kernel32.dll
LoadedModule[3]=C:\Windows\system32\KERNELBASE.dll
LoadedModule[4]=C:\Program Files\Wireshark\wiretap-1.8.0.dll
LoadedModule[5]=C:\Program Files\Wireshark\libglib-2.0-0.dll
LoadedModule[6]=C:\Windows\system32\ADVAPI32.dll
LoadedModule[7]=C:\Windows\system32\msvcrt.dll
LoadedModule[8]=C:\Windows\SYSTEM32\sechost.dll
LoadedModule[9]=C:\Windows\system32\RPCRT4.dll
LoadedModule[10]=C:\Program Files\Wireshark\libintl-8.dll
LoadedModule[11]=C:\Windows\system32\ole32.dll
LoadedModule[12]=C:\Windows\system32\GDI32.dll
LoadedModule[13]=C:\Windows\system32\USER32.dll
LoadedModule[14]=C:\Windows\system32\LPK.dll
LoadedModule[15]=C:\Windows\system32\USP10.dll
LoadedModule[16]=C:\Windows\system32\SHELL32.dll
LoadedModule[17]=C:\Windows\system32\SHLWAPI.dll
LoadedModule[18]=C:\Windows\system32\WINMM.dll
LoadedModule[19]=C:\Windows\system32\WS2_32.dll
LoadedModule[20]=C:\Windows\system32\NSI.dll
LoadedModule[21]=C:\Program Files\Wireshark\libwsutil.dll
LoadedModule[22]=C:\Program Files\Wireshark\libgmodule-2.0-0.dll
LoadedModule[23]=C:\Windows\system32\MSVCR100.dll
LoadedModule[24]=C:\Program Files\Wireshark\zlib1.dll
LoadedModule[25]=C:\Program Files\Wireshark\libwireshark.dll
LoadedModule[26]=C:\Program Files\Wireshark\libcares-2.dll
LoadedModule[27]=C:\Program Files\Wireshark\libgcrypt-11.dll
LoadedModule[28]=C:\Program Files\Wireshark\libgpg-error-0.dll
LoadedModule[29]=C:\Program Files\Wireshark\libgnutls-26.dll
LoadedModule[30]=C:\Program Files\Wireshark\libtasn1-3.dll
LoadedModule[31]=C:\Program Files\Wireshark\libsmi-2.dll
LoadedModule[32]=C:\Program Files\Wireshark\libGeoIP-1.dll
LoadedModule[33]=C:\Program Files\Wireshark\lua5.1.dll
LoadedModule[34]=C:\Windows\system32\COMDLG32.dll
LoadedModule[35]=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\COMCTL32.dll
LoadedModule[36]=C:\Program Files\Wireshark\libgtk-win32-2.0-0.dll
LoadedModule[37]=C:\Program Files\Wireshark\libgdk-win32-2.0-0.dll
LoadedModule[38]=C:\Program Files\Wireshark\libcairo-2.dll
LoadedModule[39]=C:\Program Files\Wireshark\libfontconfig-1.dll
LoadedModule[40]=C:\Program Files\Wireshark\libfreetype-6.dll
LoadedModule[41]=C:\Program Files\Wireshark\libxml2-2.dll
LoadedModule[42]=C:\Windows\system32\MSIMG32.dll
LoadedModule[43]=C:\Program Files\Wireshark\libpixman-1-0.dll
LoadedModule[44]=C:\Program Files\Wireshark\libpng15-15.dll
LoadedModule[45]=C:\Program Files\Wireshark\libgdk_pixbuf-2.0-0.dll
LoadedModule[46]=C:\Program Files\Wireshark\libgio-2.0-0.dll
LoadedModule[47]=C:\Program Files\Wireshark\libgobject-2.0-0.dll
LoadedModule[48]=C:\Program Files\Wireshark\libffi-5.dll
LoadedModule[49]=C:\Windows\system32\DNSAPI.dll
LoadedModule[50]=C:\Program Files\Wireshark\libjasper-1.dll
LoadedModule[51]=C:\Program Files\Wireshark\libjpeg-8.dll
LoadedModule[52]=C:\Program Files\Wireshark\libtiff-5.dll
LoadedModule[53]=C:\Program Files\Wireshark\liblzma-5.dll
LoadedModule[54]=C:\Windows\system32\IMM32.dll
LoadedModule[55]=C:\Windows\system32\MSCTF.dll
LoadedModule[56]=C:\Program Files\Wireshark\libpango-1.0-0.dll
LoadedModule[57]=C:\Program Files\Wireshark\libpangocairo-1.0-0.dll
LoadedModule[58]=C:\Program Files\Wireshark\libpangoft2-1.0-0.dll
LoadedModule[59]=C:\Program Files\Wireshark\libpangowin32-1.0-0.dll
LoadedModule[60]=C:\Program Files\Wireshark\libatk-1.0-0.dll
LoadedModule[61]=C:\Windows\system32\WINSPOOL.DRV
LoadedModule[62]=C:\Windows\system32\riched20.dll
LoadedModule[63]=C:\Windows\system32\wpcap.dll
LoadedModule[64]=C:\Windows\system32\packet.dll
LoadedModule[65]=C:\Windows\system32\VERSION.dll
LoadedModule[66]=C:\Windows\system32\iphlpapi.dll
LoadedModule[67]=C:\Windows\system32\WINNSI.DLL
LoadedModule[68]=C:\Windows\system32\CRYPTBASE.dll
LoadedModule[69]=C:\Windows\system32\SspiCli.dll
LoadedModule[70]=C:\Program Files\Wireshark\lib\gtk-2.0\2.10.0\engines\libwimp.dll
LoadedModule[71]=C:\Windows\system32\uxtheme.dll
LoadedModule[72]=C:\Windows\system32\CRYPTSP.dll
LoadedModule[73]=C:\Windows\system32\NETAPI32.DLL
LoadedModule[74]=C:\Windows\system32\netutils.dll
LoadedModule[75]=C:\Windows\system32\srvcli.dll
LoadedModule[76]=C:\Windows\system32\wkscli.dll
LoadedModule[77]=C:\Program Files\Wireshark\plugins\1.8.3\asn1.dll
LoadedModule[78]=C:\Program Files\Wireshark\plugins\1.8.3\docsis.dll
LoadedModule[79]=C:\Program Files\Wireshark\plugins\1.8.3\ethercat.dll
LoadedModule[80]=C:\Program Files\Wireshark\plugins\1.8.3\gryphon.dll
LoadedModule[81]=C:\Program Files\Wireshark\plugins\1.8.3\irda.dll
LoadedModule[82]=C:\Program Files\Wireshark\plugins\1.8.3\m2m.dll
LoadedModule[83]=C:\Program Files\Wireshark\plugins\1.8.3\mate.dll
LoadedModule[84]=C:\Program Files\Wireshark\plugins\1.8.3\opcua.dll
LoadedModule[85]=C:\Program Files\Wireshark\plugins\1.8.3\profinet.dll
LoadedModule[86]=C:\Program Files\Wireshark\plugins\1.8.3\stats_tree.dll
LoadedModule[87]=C:\Program Files\Wireshark\plugins\1.8.3\unistim.dll
LoadedModule[88]=C:\Program Files\Wireshark\plugins\1.8.3\wimax.dll
LoadedModule[89]=C:\Program Files\Wireshark\plugins\1.8.3\wimaxasncp.dll
LoadedModule[90]=C:\Windows\system32\dhcpcsvc.DLL
LoadedModule[91]=C:\Windows\system32\dhcpcsvc6.DLL
FriendlyEventName=Stopped working
ConsentKey=APPCRASH
AppName=Wireshark
AppPath=C:\Program Files\Wireshark\wireshark.exe

asked 22 Oct '12, 07:16

mgh1472's gravatar image

mgh1472
1112
accept rate: 0%

edited 22 Oct '12, 07:40


One Answer:

0

First of all, you should not just post tons of debug lines here. This is a Q&A Site, and not the bug tracker (where this would indeed help in some cases). So you should probably open a bug there: http://bugs.wireshark.org

If the problem you have is actually not just happening at the start of Wireshark but after capturing for a while you might just have encountered the good old out-of-memory trouble, see http://wiki.wireshark.org/KnownBugs/OutOfMemory. In that case you do not need to open a bug report.

answered 22 Oct '12, 08:25

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%

Alrighty then...

(22 Oct '12, 09:03) mgh1472