locked
Explorer is Consistently Hanging - ntdll.dll RRS feed

  • Question

  • We have a user who is experiencing Explorer.exe crashing (and not reopening) about once a week for the past month. The PC's event log is filled with ID 1002s of Explorer.EXE application hang (about once a day):

    The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
     Process ID: 303c
     Start Time: 01d0de6475c14853
     Termination Time: 15
     Application Path: C:\windows\Explorer.EXE
     Report Id: 37b4360c-4a61-11e5-8a15-f8b156b0dcf5

    This PC was recently reimaged a few months ago with a known good image (other users are not experiencing issues with this image on the same model of PC). Our environemnt is very controlled and our users do not have administrative privileges. I setup usermode dumping on her PC last week and only one dump has been created since. Below is the DebugDiag crash/hang analysis for the dump. I'm not very good at reading these, however, in thread 24 it looks like some application tried to create a temp folder and a heap memory error was then thrown. Could anyone provide a more clear interpreation of what is happening here?



     
     Analysis Summary  
     

    Type

    Description

    Recommendation

       Error In explorer.exe.12000.dmp the assembly instruction at ntdll!RtlReportCriticalFailure+57 in C:\Windows\System32\ntdll.dll from Microsoft Corporation has caused an unknown exception (0xc0000374) on thread 24


    Please follow up with vendor Microsoft Corporation for problem resolution concerning the following file: C:\Windows\System32\ntdll.dll.
     
     
     
     


     
     Analysis Details  
      


     

    Table Of Contents
    \explorer.exe.12000.dmp
       Top 5 threads by CPU time
       Thread report
       Well-Known COM STA Threads Report
       Faulting Module Information Report for explorer.exe.12000.dmp



     
    Report for explorer.exe.12000.dmp

    Type of Analysis Performed   Combined Crash/Hang Analysis
    Machine Name   CHD05DPC2QRRCZ
    Operating System   Windows 7Service Pack 1
    Number Of Processors   4
    Process ID   12000
    Process Image   C:\Windows\explorer.exe
    System Up-Time   4 day(s) 20:38:52
    Process Up-Time   00:25:44
    Processor Type   X86
    Process Bitness   32-Bit


    Top 5 Threads by CPU time
    Note - Times include both user mode and kernel mode for each thread
    Thread ID: 0     Total CPU Time: 00:00:00.982     Entry Point for Thread: explorer!wWinMainCRTStartup
    Thread ID: 2     Total CPU Time: 00:00:00.405     Entry Point for Thread: shlwapi!WrapperThreadProc
    Thread ID: 10     Total CPU Time: 00:00:00.264     Entry Point for Thread: shlwapi!WrapperThreadProc
    Thread ID: 9     Total CPU Time: 00:00:00.124     Entry Point for Thread: shlwapi!WrapperThreadProc
    Thread ID: 14     Total CPU Time: 00:00:00.062     Entry Point for Thread: shlwapi!WrapperThreadProc



    Thread report



    Thread 0 - System ID 9768

    Entry point   explorer!wWinMainCRTStartup
    Create time   8/17/2015 10:02:00 AM
    Time spent in user mode   0 Days 00:00:00.561
    Time spent in kernel mode   0 Days 00:00:00.421




    Function

    ntdll!KiFastSystemCallRet
    user32!NtUserWaitMessage+c
    shell32!SHDesktopMessageLoop+29
    explorer!wWinMain+551
    explorer!_initterm_e+1b1
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 1 - System ID 14240

    Entry point   ntdll!TppWaiterpThread
    Create time   8/17/2015 10:02:00 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForMultipleObjects+c
    ntdll!TppWaiterpThread+33d
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 2 - System ID 892

    Entry point   shlwapi!WrapperThreadProc
    Create time   8/17/2015 10:02:00 AM
    Time spent in user mode   0 Days 00:00:00.109
    Time spent in kernel mode   0 Days 00:00:00.296




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForMultipleObjects+c
    KERNELBASE!WaitForMultipleObjectsEx+100
    kernel32!WaitForMultipleObjectsExImplementation+e0
    user32!RealMsgWaitForMultipleObjectsEx+13c
    duser!CoreSC::Wait+59
    duser!CoreSC::WaitMessage+54
    duser!MphWaitMessageEx+2b
    user32!__ClientWaitMessageExMPH+1e
    ntdll!KiUserCallbackDispatcher+2e
    user32!NtUserWaitMessage+c
    explorer!CTray::MainThreadProc+8a
    shlwapi!WrapperThreadProc+1b5
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 3 - System ID 14248

    Entry point   msvcrt!_endthreadex+6f
    Create time   8/17/2015 10:02:00 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForMultipleObjects+c
    KERNELBASE!WaitForMultipleObjectsEx+100
    kernel32!WaitForMultipleObjectsExImplementation+e0
    user32!RealMsgWaitForMultipleObjectsEx+13c
    duser!CoreSC::Wait+59
    duser!CoreSC::xwProcessNL+aa
    duser!GetMessageExA+44
    duser!ResourceManager::SharedThreadProc+b6
    msvcrt!_endthreadex+44
    msvcrt!_endthreadex+ce
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 4 - System ID 14076

    Entry point   shlwapi!WrapperThreadProc
    Create time   8/17/2015 10:02:00 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.046




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForMultipleObjects+c
    KERNELBASE!WaitForMultipleObjectsEx+100
    kernel32!WaitForMultipleObjectsExImplementation+e0
    user32!RealMsgWaitForMultipleObjectsEx+13c
    shell32!CMsgWaitForManyObjects::Wait+8d
    shell32!CChangeNotify::_MessagePump+86
    shell32!CChangeNotify::s_ThreadProc+4f
    shlwapi!WrapperThreadProc+1b5
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 5 - System ID 12240

    Entry point   msiltcfg!WorkerThread
    Create time   8/17/2015 10:02:00 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForMultipleObjects+c
    KERNELBASE!WaitForMultipleObjectsEx+100
    kernel32!WaitForMultipleObjectsExImplementation+e0
    kernel32!WaitForMultipleObjects+18
    msiltcfg!WorkerThread+d6
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 6 - System ID 13392

    Entry point   shlwapi!WrapperThreadProc
    Create time   8/17/2015 10:02:00 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    user32!NtUserGetMessage+c
    explorer!CSoundWnd::s_ThreadProc+3a
    shlwapi!WrapperThreadProc+1b5
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 7 - System ID 13048

    Entry point   shlwapi!WrapperThreadProc
    Create time   8/17/2015 10:02:01 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    user32!NtUserGetMessage+c
    shell32!MessagePumpThreadProc+3b
    shlwapi!WrapperThreadProc+1b5
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 8 - System ID 13764

    Entry point   shlwapi!WrapperThreadProc
    Create time   8/17/2015 10:02:05 AM
    Time spent in user mode   0 Days 00:00:00.015
    Time spent in kernel mode   0 Days 00:00:00.046




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForMultipleObjects+c
    KERNELBASE!WaitForMultipleObjectsEx+100
    kernel32!WaitForMultipleObjectsExImplementation+e0
    user32!RealMsgWaitForMultipleObjectsEx+13c
    duser!CoreSC::Wait+59
    duser!CoreSC::xwProcessNL+aa
    duser!MphProcessMessage+5e
    user32!__ClientGetMessageMPH+30
    ntdll!KiUserCallbackDispatcher+2e
    user32!NtUserGetMessage+c
    stobject!SysTrayMain+1ed
    stobject!CSysTray::s_SysTrayThreadProc+14
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 9 - System ID 13196

    Entry point   shlwapi!WrapperThreadProc
    Create time   8/17/2015 10:02:05 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.124




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForMultipleObjects+c
    KERNELBASE!WaitForMultipleObjectsEx+100
    kernel32!WaitForMultipleObjectsExImplementation+e0
    user32!RealMsgWaitForMultipleObjectsEx+13c
    stobject!CSSOSharedThread::ThreadProc+55
    shlwapi!WrapperThreadProc+1b5
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 10 - System ID 13160

    Entry point   shlwapi!WrapperThreadProc
    Create time   8/17/2015 10:02:06 AM
    Time spent in user mode   0 Days 00:00:00.046
    Time spent in kernel mode   0 Days 00:00:00.218




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForMultipleObjects+c
    KERNELBASE!WaitForMultipleObjectsEx+100
    kernel32!WaitForMultipleObjectsExImplementation+e0
    user32!RealMsgWaitForMultipleObjectsEx+13c
    stobject!CSSOSharedThread::ThreadProc+55
    shlwapi!WrapperThreadProc+1b5
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 11 - System ID 12236

    Entry point   MMDevAPI!CDeviceEnumerator::PnpNotificationThreadWrapper
    Create time   8/17/2015 10:02:06 AM
    Time spent in user mode   0 Days 00:00:00.015
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForMultipleObjects+c
    KERNELBASE!WaitForMultipleObjectsEx+100
    kernel32!WaitForMultipleObjectsExImplementation+e0
    user32!RealMsgWaitForMultipleObjectsEx+13c
    MMDevAPI!CDeviceEnumerator::PnpNotificationThread+2a3
    MMDevAPI!CDeviceEnumerator::PnpNotificationThreadWrapper+d
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 12 - System ID 13528

    Entry point   shlwapi!WrapperThreadProc
    Create time   8/17/2015 10:02:06 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    user32!NtUserGetMessage+c
    AltTab!RunMessagePump+31
    AltTab!AltTabRun+72
    AltTab!CAltTabSSO::_ThreadProc+1f
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 13 - System ID 9940

    Entry point   ntdll!TppWorkerThread
    Create time   8/17/2015 10:02:06 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForWorkViaWorkerFactory+c
    ntdll!TppWorkerThread+216
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 14 - System ID 13520

    Entry point   shlwapi!WrapperThreadProc
    Create time   8/17/2015 10:02:07 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.062




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForMultipleObjects+c
    KERNELBASE!WaitForMultipleObjectsEx+100
    kernel32!WaitForMultipleObjectsExImplementation+e0
    user32!RealMsgWaitForMultipleObjectsEx+13c
    stobject!CSSOSharedThread::ThreadProc+55
    shlwapi!WrapperThreadProc+1b5
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 15 - System ID 12616

    Entry point   ole32!CRpcThreadCache::RpcWorkerThreadEntry
    Create time   8/17/2015 10:02:07 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    ntdll!NtWaitForSingleObject+c
    KERNELBASE!WaitForSingleObjectEx+98
    kernel32!WaitForSingleObjectExImplementation+75
    kernel32!WaitForSingleObject+12
    ole32!CDllHost::MTAWorkerLoop+2b
    ole32!CDllHost::WorkerThread+d0
    ole32!DLLHostThreadEntry+d
    ole32!CRpcThread::WorkerLoop+26
    ole32!CRpcThreadCache::RpcWorkerThreadEntry+16
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 16 - System ID 12092

    Entry point   FXSST!WaitForRestartThread
    Create time   8/17/2015 10:02:10 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.015




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForMultipleObjects+c
    KERNELBASE!WaitForMultipleObjectsEx+100
    kernel32!WaitForMultipleObjectsExImplementation+e0
    kernel32!WaitForMultipleObjects+18
    FXSST!WaitForRestartThread+cf
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 17 - System ID 9516

    Entry point   ntdll!TppWorkerThread
    Create time   8/17/2015 10:19:15 AM
    Time spent in user mode   0 Days 00:00:00.015
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForWorkViaWorkerFactory+c
    ntdll!TppWorkerThread+216
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 18 - System ID 12448

    Entry point   ole32!CRpcThreadCache::RpcWorkerThreadEntry
    Create time   8/17/2015 10:21:57 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwDelayExecution+c
    KERNELBASE!SleepEx+65
    KERNELBASE!Sleep+f
    ole32!CROIDTable::WorkerThreadLoop+14
    ole32!CRpcThreadCache::RpcWorkerThreadEntry+16
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 19 - System ID 12252

    Entry point   ntdll!TppWorkerThread
    Create time   8/17/2015 10:21:57 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.031




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForMultipleObjects+c
    KERNELBASE!WaitForMultipleObjectsEx+100
    kernel32!WaitForMultipleObjectsExImplementation+e0
    user32!RealMsgWaitForMultipleObjectsEx+13c
    user32!MsgWaitForMultipleObjects+1f
    shell32!CShellTaskScheduler::_TT_MsgWaitForMultipleObjects+b4
    shell32!CShellTaskScheduler::TT_TransitionThreadToRunningOrTerminating+96
    shell32!CShellTaskThread::ThreadProc+10c
    shell32!CShellTaskThread::s_ThreadProc+1b
    shlwapi!ExecuteWorkItemThreadProc+e
    ntdll!RtlpTpWorkCallback+11d
    ntdll!TppWorkerThread+572
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 20 - System ID 14252

    Entry point   winmm!mciwindow
    Create time   8/17/2015 10:22:10 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.031




    Function

    ntdll!KiFastSystemCallRet
    user32!NtUserGetMessage+c
    winmm!mciwindow+102
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 21 - System ID 12196

    Entry point   GdiPlus!DllRefCountSafeThreadThunk
    Create time   8/17/2015 10:22:37 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForMultipleObjects+c
    KERNELBASE!WaitForMultipleObjectsEx+100
    kernel32!WaitForMultipleObjectsExImplementation+e0
    user32!RealMsgWaitForMultipleObjectsEx+13c
    user32!MsgWaitForMultipleObjects+1f
    GdiPlus!BackgroundThreadProc+59
    GdiPlus!DllRefCountSafeThreadThunk+10
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 22 - System ID 13132

    Entry point   ntdll!TppWorkerThread
    Create time   8/17/2015 10:25:16 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForWorkViaWorkerFactory+c
    ntdll!TppWorkerThread+216
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 23 - System ID 14292

    Entry point   ntdll!TppWorkerThread
    Create time   8/17/2015 10:25:46 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForWorkViaWorkerFactory+c
    ntdll!TppWorkerThread+216
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 24 - System ID 13676

    Entry point   msvcr71!_threadstartex
    Create time   8/17/2015 10:25:56 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.015


    This thread is not fully resolved and may or may not be a problem. Further analysis of these threads may be required.



    Function

    ntdll!KiFastSystemCallRet
    ntdll!NtWaitForSingleObject+c
    ntdll!RtlReportExceptionEx+14b
    ntdll!RtlReportException+86
    ntdll!RtlpTerminateFailureFilter+14
    ntdll!RtlReportCriticalFailure+67
    ntdll!RtlpReportHeapFailure+21
    ntdll!RtlpLogHeapFailure+a1
    ntdll!RtlFreeHeap+64
    KERNELBASE!LocalFree+27
    KMPSDPMiddleLayer!CPSDPDocument::CreateTempDocumentFolder+1a2
    KMPSDPMiddleLayer!CPSDPDocument::GetThumbnail+301
    PSDP_ExplorerPlugIn!DllUnregisterServer+3280a
    mfc71u!_AfxThreadEntry+e6
    msvcr71!_threadstartex+6f
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 25 - System ID 13792

    Entry point   msvcr71!_threadstartex
    Create time   8/17/2015 10:26:13 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000


    This thread is not fully resolved and may or may not be a problem. Further analysis of these threads may be required.



    Function

    ntdll!KiFastSystemCallRet
    ntdll!NtWaitForSingleObject+c
    KERNELBASE!WaitForSingleObjectEx+98
    kernel32!WaitForSingleObjectExImplementation+75
    kernel32!WaitForSingleObject+12
    KMPSDPMiddleLayer!CPSDPRoot::GetChildListForDocViewSetting+665
    PSDP_ExplorerPlugIn!DllUnregisterServer+3280a
    mfc71u!_AfxThreadEntry+e6
    msvcr71!_threadstartex+6f
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 26 - System ID 13704

    Entry point   msvcr71!_threadstartex
    Create time   8/17/2015 10:26:22 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000


    This thread is not fully resolved and may or may not be a problem. Further analysis of these threads may be required.



    Function

    ntdll!KiFastSystemCallRet
    ntdll!NtWaitForSingleObject+c
    KERNELBASE!WaitForSingleObjectEx+98
    kernel32!WaitForSingleObjectExImplementation+75
    kernel32!WaitForSingleObject+12
    KMPSDPMiddleLayer!CPSDPRoot::GetChildListForDocViewSetting+665
    PSDP_ExplorerPlugIn!DllUnregisterServer+3280a
    mfc71u!_AfxThreadEntry+e6
    msvcr71!_threadstartex+6f
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top



    Thread 27 - System ID 13012

    Entry point   ntdll!TppWorkerThread
    Create time   8/17/2015 10:27:16 AM
    Time spent in user mode   0 Days 00:00:00.000
    Time spent in kernel mode   0 Days 00:00:00.000




    Function

    ntdll!KiFastSystemCallRet
    ntdll!ZwWaitForWorkViaWorkerFactory+c
    ntdll!TppWorkerThread+216
    kernel32!BaseThreadInitThunk+e
    ntdll!__RtlUserThreadStart+70
    ntdll!_RtlUserThreadStart+1b


    Back to Top

    Well-Known COM STA Threads Report



    STA Name   

    Thread ID   

    Thread Status   

    Call Status

    Main STA    0 Unknown     



    Exception Information
    In explorer.exe.12000.dmp the assembly instruction at ntdll!RtlReportCriticalFailure+57 in C:\Windows\System32\ntdll.dll from Microsoft Corporation has caused an unknown exception (0xc0000374) on thread 24




    Module Information

    Image Name: C:\Windows\System32\ntdll.dll   Symbol Type:  PDB
    Base address: 0x00905a4d   Time Stamp:  Tue Mar 17 00:55:34 2015  
    Checksum: 0xfffffbe4   Comments:   
    COM DLL: False   Company Name:  Microsoft Corporation
    ISAPIExtension: False   File Description:  NT Layer DLL
    ISAPIFilter: False   File Version:  6.1.7601.18798 (win7sp1_gdr.150316-1654)
    Managed DLL: False   Internal Name:  ntdll.dll
    VB DLL: False   Legal Copyright:  © Microsoft Corporation. All rights reserved.
    Loaded Image Name:  ntdll.dll   Legal Trademarks:   
    Mapped Image Name:     Original filename:  ntdll.dll
    Module name:  ntdll   Private Build:   
    Single Threaded:  False   Product Name:  Microsoft® Windows® Operating System
    Module Size:  1.25 MBytes   Product Version:  6.1.7601.18798
    Symbol File Name:  c:\symbols\ntdll.pdb\E3C1142BAD004AB1A930386A8D557B992\ntdll.pdb   Special Build:  &

     

     
     
     
     


     
     Analysis Rule Summary  
     

    Rule Name

    Status

    Details

    CrashHangAnalysis Completed   
     
     


    Friday, August 28, 2015 1:55 PM

All replies

  • Hi Jboykin,

    Windows Explorer crashes are mostly caused by an incompatible Shell Extension. you can set Windows Error Reporting Service,

    [HKLM\Software\Microsoft\Windows\Windows Error Reporting\LocalDumps\explorer.exe\]

    In the explorer.exe key, create a REG_EXPAND_SZ value named DumpFolder and set the data for the value to %systemdrive%\expdumps, Ensure the %systemdrive%\expdumps folder exists

    Create a Dword(32-bit)value, name “DumpType”set the value data to 2

    When the next crash, then zip the dump file, upload it to Skydrive or other tools for us to view the detailed information.

    More details for your reference: 

    Collecting User-Mode Dumps

    Best regards,


    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com.

    Niko Cheng
    TechNet Community Support

    Monday, August 31, 2015 8:20 AM
  • Hi Niko,

    Below is a OneDrive link to the full user mode dump for the above crash/hang analysis.

    http://1drv.ms/1fRDl4D

    Monday, August 31, 2015 6:14 PM