Hey,
i have ctds in cruise, when flying over certain premium airports.
Yesterday i was cruising above LFPG and as i was exactly above it, i had a CTD.
Whats interesting is:
The Windows Event Log does not show a specific dll, but always exactly one second before ctd there is a Windows Defender Security Logon Event.
I did had many CTD Causes and am pretty experienced with them, since i know how to fix most causes, but for that issue i did not found a solution.
Feels like either MSFS trying to verify if i have the premium version, and then has some error with that, or that the streamed package is somehow checked by defender, which leads to the ctd.
Version:
Newest SU2 Beta (had this issue before also)
Airplane:
Happend with native ini a320neo and now with fenix a320
Reproducable:
For me yes, its always at the same exact location. Had this a few months ago above EHAM, now above LFPG.
These are the crash events:
.NET Runtime Crash
{
“Event”: {
“System”: {
“Provider”: {
“_Name”: “.NET Runtime”
},
“EventID”: {
“_Qualifiers”: “0”,
“__text”: “1026”
},
“Version”: “0”,
“Level”: “2”,
“Task”: “0”,
“Opcode”: “0”,
“Keywords”: “0x80000000000000”,
“TimeCreated”: {
“_SystemTime”: “2025-04-06T21:57:33.1963052Z”
},
“EventRecordID”: “31538”,
“Correlation”: “”,
“Execution”: {
“_ProcessID”: “21700”,
“_ThreadID”: “0”
},
“Channel”: “Application”,
“Computer”: “A350”,
“Security”: “”
},
“EventData”: {
“Data”: “Anwendung: FlightSimulator2024.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: Ausnahmecode c0000005, Ausnahmeadresse 00007FF657ADC973”
},
“_xmlns”: “http://schemas.microsoft.com/win/2004/08/events/event”,
“__text”: “-”
}
}
Flight Simulator Crash
{
“Event”: {
“System”: {
“Provider”: {
“_Name”: “Application Error”,
“_Guid”: “{a0e9b465-b939-57d7-b27d-95d8e925ff57}”
},
“EventID”: “1000”,
“Version”: “0”,
“Level”: “2”,
“Task”: “100”,
“Opcode”: “0”,
“Keywords”: “0x8000000000000000”,
“TimeCreated”: {
“_SystemTime”: “2025-04-06T21:57:36.9383050Z”
},
“EventRecordID”: “31539”,
“Correlation”: “”,
“Execution”: {
“_ProcessID”: “10136”,
“_ThreadID”: “5876”
},
“Channel”: “Application”,
“Computer”: “A350”,
“Security”: {
“_UserID”: “S-1-5-21-1008757500-230732946-3943199233-1003”
}
},
“EventData”: {
“Data”: [
{
“_Name”: “AppName”,
“__text”: “FlightSimulator2024.exe”
},
{
“_Name”: “AppVersion”,
“__text”: “1.4.10.0”
},
{
“_Name”: “AppTimeStamp”,
“__text”: “00000000”
},
{
“_Name”: “ModuleName”,
“__text”: “FlightSimulator2024.exe”
},
{
“_Name”: “ModuleVersion”,
“__text”: “1.4.10.0”
},
{
“_Name”: “ModuleTimeStamp”,
“__text”: “00000000”
},
{
“_Name”: “ExceptionCode”,
“__text”: “c0000005”
},
{
“_Name”: “FaultingOffset”,
“__text”: “0000000002b9c973”
},
{
“_Name”: “ProcessId”,
“__text”: “0x54c4”
},
{
“_Name”: “ProcessCreationTime”,
“__text”: “0x1dba72d101c645f”
},
{
“_Name”: “AppPath”,
“__text”: “C:\Program Files\WindowsApps\Microsoft.Limitless_1.4.10.0_x64__8wekyb3d8bbwe\FlightSimulator2024.exe”
},
{
“_Name”: “ModulePath”,
“__text”: “C:\Program Files\WindowsApps\Microsoft.Limitless_1.4.10.0_x64__8wekyb3d8bbwe\FlightSimulator2024.exe”
},
{
“_Name”: “IntegratorReportId”,
“__text”: “803e79bf-5621-4497-afdb-ee33038c54e4”
},
{
“_Name”: “PackageFullName”,
“__text”: “Microsoft.Limitless_1.4.10.0_x64__8wekyb3d8bbwe”
},
{
“_Name”: “PackageRelativeAppId”,
“__text”: “App”
}
]
},
“_xmlns”: “http://schemas.microsoft.com/win/2004/08/events/event”
}
}
Windows Error Reporting Info
{
“Event”: {
“System”: {
“Provider”: {
“_Name”: “Windows Error Reporting”,
“_Guid”: “{0ead09bd-2157-539a-8d6d-c87f95b64d70}”
},
“EventID”: “1001”,
“Version”: “0”,
“Level”: “4”,
“Task”: “0”,
“Opcode”: “0”,
“Keywords”: “0x8000000000000000”,
“TimeCreated”: {
“_SystemTime”: “2025-04-06T21:57:41.4762648Z”
},
“EventRecordID”: “31540”,
“Correlation”: “”,
“Execution”: {
“_ProcessID”: “10136”,
“_ThreadID”: “5876”
},
“Channel”: “Application”,
“Computer”: “A350”,
“Security”: {
“_UserID”: “S-1-5-21-1008757500-230732946-3943199233-1003”
}
},
“EventData”: {
“Data”: [
{
“_Name”: “Bucket”,
“__text”: “2157681764844360071”
},
{
“_Name”: “BucketType”,
“__text”: “5”
},
{
“_Name”: “EventName”,
“__text”: “MoAppCrash”
},
{
“_Name”: “Response”,
“__text”: “Nicht verfügbar”
},
{
“_Name”: “CabId”,
“__text”: “0”
},
{
“_Name”: “P1”,
“__text”: “Microsoft.Limitless_1.4.10.0_x64__8wekyb3d8bbwe”
},
{
“_Name”: “P2”,
“__text”: “praid:App”
},
{
“_Name”: “P3”,
“__text”: “1.4.10.0”
},
{
“_Name”: “P4”,
“__text”: “00000000”
},
{
“_Name”: “P5”,
“__text”: “FlightSimulator2024.exe”
},
{
“_Name”: “P6”,
“__text”: “1.4.10.0”
},
{
“_Name”: “P7”,
“__text”: “00000000”
},
{
“_Name”: “P8”,
“__text”: “c0000005”
},
{
“_Name”: “P9”,
“__text”: “0000000002b9c973”
},
{
“_Name”: “P10”
},
{
“_Name”: “AttachedFiles”,
“__text”: “\\?\C:\Users\Fabia\AppData\Local\Packages\Microsoft.Limitless_8wekyb3d8bbwe\LocalState\AsoboReport-Crash.txt \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER.0b896010-cfba-450a-9cfa-31a8ce4713a6.tmp.dmp \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER.0e7166ae-1a49-4827-804d-50144d92e69d.tmp.WERInternalMetadata.xml \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER.1a0e37c3-17c0-40a8-beba-4fc741b65beb.tmp.csv \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER.fc4e4a1d-c28f-4750-8e9d-0039d52f3661.tmp.txt \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER.07cab43f-a19a-4653-bdfd-4e4caed30c21.tmp.xml”
},
{
“_Name”: “StorePath”,
“__text”: “\\?\C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Microsoft.Limitl_8b6220d6d1ff642c617635d3f2f3ba2ffa7cc5ce_4be6cddf_299d5a38-be41-4572-8118-153cf2bde9e7”
},
{
“_Name”: “AnalysisSymbol”
},
{
“_Name”: “Rechecking”,
“__text”: “0”
},
{
“_Name”: “ReportId”,
“__text”: “803e79bf-5621-4497-afdb-ee33038c54e4”
},
{
“_Name”: “ReportStatus”,
“__text”: “268435456”
},
{
“_Name”: “HashedBucket”,
“__text”: “9ea251e234c66fe6edf1a0221be2d187”
},
{
“_Name”: “CabGuid”,
“__text”: “0”
}
]
},
“_xmlns”: “http://schemas.microsoft.com/win/2004/08/events/event”
}
}
Possible Related Windows Security Event 1
{
“Event”: {
“System”: {
“Provider”: {
“_Name”: “Microsoft-Windows-Security-Auditing”,
“_Guid”: “{54849625-5478-4994-a5ba-3e3b0328c30d}”
},
“EventID”: “4624”,
“Version”: “3”,
“Level”: “0”,
“Task”: “12544”,
“Opcode”: “0”,
“Keywords”: “0x8020000000000000”,
“TimeCreated”: {
“_SystemTime”: “2025-04-06T21:57:33.1975929Z”
},
“EventRecordID”: “573763”,
“Correlation”: {
“_ActivityID”: “{fbc21cf5-a72c-0002-681d-c2fb2ca7db01}”
},
“Execution”: {
“_ProcessID”: “1632”,
“_ThreadID”: “8176”
},
“Channel”: “Security”,
“Computer”: “A350”,
“Security”: “”
},
“EventData”: {
“Data”: [
{
“_Name”: “SubjectUserSid”,
“__text”: “S-1-5-18”
},
{
“_Name”: “SubjectUserName”,
“__text”: “A350$”
},
{
“_Name”: “SubjectDomainName”,
“__text”: “WORKGROUP”
},
{
“_Name”: “SubjectLogonId”,
“__text”: “0x3e7”
},
{
“_Name”: “TargetUserSid”,
“__text”: “S-1-5-18”
},
{
“_Name”: “TargetUserName”,
“__text”: “SYSTEM”
},
{
“_Name”: “TargetDomainName”,
“__text”: “NT-AUTORITÄT”
},
{
“_Name”: “TargetLogonId”,
“__text”: “0x3e7”
},
{
“_Name”: “LogonType”,
“__text”: “5”
},
{
“_Name”: “LogonProcessName”,
“__text”: “Advapi”
},
{
“_Name”: “AuthenticationPackageName”,
“__text”: “Negotiate”
},
{
“_Name”: “WorkstationName”,
“__text”: “-”
},
{
“_Name”: “LogonGuid”,
“__text”: “{00000000-0000-0000-0000-000000000000}”
},
{
“_Name”: “TransmittedServices”,
“__text”: “-”
},
{
“_Name”: “LmPackageName”,
“__text”: “-”
},
{
“_Name”: “KeyLength”,
“__text”: “0”
},
{
“_Name”: “ProcessId”,
“__text”: “0x644”
},
{
“_Name”: “ProcessName”,
“__text”: “C:\Windows\System32\services.exe”
},
{
“_Name”: “IpAddress”,
“__text”: “-”
},
{
“_Name”: “IpPort”,
“__text”: “-”
},
{
“_Name”: “ImpersonationLevel”,
“__text”: “%%1833”
},
{
“_Name”: “RestrictedAdminMode”,
“__text”: “-”
},
{
“_Name”: “RemoteCredentialGuard”,
“__text”: “-”
},
{
“_Name”: “TargetOutboundUserName”,
“__text”: “-”
},
{
“_Name”: “TargetOutboundDomainName”,
“__text”: “-”
},
{
“_Name”: “VirtualAccount”,
“__text”: “%%1843”
},
{
“_Name”: “TargetLinkedLogonId”,
“__text”: “0x0”
},
{
“_Name”: “ElevatedToken”,
“__text”: “%%1842”
}
]
},
“_xmlns”: “http://schemas.microsoft.com/win/2004/08/events/event”
}
}
Possible Related Windows Security Event 2
{
“Event”: {
“System”: {
“Provider”: {
“_Name”: “Microsoft-Windows-Security-Auditing”,
“_Guid”: “{54849625-5478-4994-a5ba-3e3b0328c30d}”
},
“EventID”: “4672”,
“Version”: “0”,
“Level”: “0”,
“Task”: “12548”,
“Opcode”: “0”,
“Keywords”: “0x8020000000000000”,
“TimeCreated”: {
“_SystemTime”: “2025-04-06T21:57:33.1975968Z”
},
“EventRecordID”: “573764”,
“Correlation”: {
“_ActivityID”: “{fbc21cf5-a72c-0002-681d-c2fb2ca7db01}”
},
“Execution”: {
“_ProcessID”: “1632”,
“_ThreadID”: “8176”
},
“Channel”: “Security”,
“Computer”: “A350”,
“Security”: “”
},
“EventData”: {
“Data”: [
{
“_Name”: “SubjectUserSid”,
“__text”: “S-1-5-18”
},
{
“_Name”: “SubjectUserName”,
“__text”: “SYSTEM”
},
{
“_Name”: “SubjectDomainName”,
“__text”: “NT-AUTORITÄT”
},
{
“_Name”: “SubjectLogonId”,
“__text”: “0x3e7”
},
{
“_Name”: “PrivilegeList”,
“__text”: “SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege”
}
]
},
“_xmlns”: “http://schemas.microsoft.com/win/2004/08/events/event”
}
}