locked
Explorer.exe crashes, ntdll.dll RRS feed

  • Question

  • 1 day.  There are other issues that I suspect are associated with this, explorer.exe does not refresh when a file is created/deleted/moved. Issue persists after performing clean install so I suspect it is one of the programs we are using. All the computers are connected to a domain.

    Event Log error

    Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4Faulting module name: ntdll.dll, version: 6.1.7601.22436, time stamp: 0x521eb03fException code: 0xc0000005Fault offset: 0x0000000000052590Faulting process id: 0x1158Faulting application start time: 0x01ced4a78095df2dFaulting application path: C:\Windows\Explorer.EXEFaulting module path: C:\Windows\SYSTEM32\ntdll.dllReport Id: 1af2bf37-40a8-11e3-ba72-90b11c805e28

    I have tried the following steps:

    • Updated graphics driver (AMD Radeon HD 7000 v13.152.0.0)
    • Ran sfc /scannow (No errors found)
    • Disabled 3rd party extensions with ShellExView (Disabled all non-Microsoft Extensions)
    • Ran chkdsk
    • Ran Windows memory test (passed)
    • Created User-mode dump using registry modification

    Having problems understanding WinDbg. It looks like it is pointing to EXPLORERFRAME.DLL as the problem. Any help in understanding what the Dump file identifies as the problem is appreciated. 

    *******************************************************************************
    *                                                                             *
    *                        Exception Analysis                                   *
    *                                                                             *
    *******************************************************************************
    
    
    FAULTING_IP: 
    ntdll!RtlReportCriticalFailure+62
    00000000`77c54322 eb00            jmp     ntdll!RtlReportCriticalFailure+0x64 (00000000`77c54324)
    
    EXCEPTION_RECORD:  ffffffffffffffff -- (.exr 0xffffffffffffffff)
    ExceptionAddress: 0000000077c54322 (ntdll!RtlReportCriticalFailure+0x0000000000000062)
       ExceptionCode: c0000374
      ExceptionFlags: 00000001
    NumberParameters: 1
       Parameter[0]: 0000000077ccc4b0
    
    DEFAULT_BUCKET_ID:  WRONG_SYMBOLS
    
    PROCESS_NAME:  explorer.exe
    
    ERROR_CODE: (NTSTATUS) 0xc0000374 - A heap has been corrupted.
    
    EXCEPTION_CODE: (NTSTATUS) 0xc0000374 - A heap has been corrupted.
    
    EXCEPTION_PARAMETER1:  0000000077ccc4b0
    
    NTGLOBALFLAG:  0
    
    APPLICATION_VERIFIER_FLAGS:  0
    
    APP:  explorer.exe
    
    MANAGED_STACK: !dumpstack -EE
    No export dumpstack found
    
    PRIMARY_PROBLEM_CLASS:  WRONG_SYMBOLS
    
    BUGCHECK_STR:  APPLICATION_FAULT_WRONG_SYMBOLS
    
    LAST_CONTROL_TRANSFER:  from 0000000077c54906 to 0000000077c54322
    
    STACK_TEXT:  
    00000000`037ee8f0 00000000`77c54906 : 00000000`00000002 00000000`00000023 000007fe`ff7153d8 00000000`00000003 : ntdll!RtlReportCriticalFailure+0x62
    00000000`037ee9c0 00000000`77c554d2 : 00000000`0000000a 00000000`ffffffff 00000000`0bd58660 00000000`0bd58668 : ntdll!RtlpReportHeapFailure+0x26
    00000000`037ee9f0 00000000`77c57114 : 00000000`00150000 00000000`00000000 00000000`00000000 00000000`0000000a : ntdll!RtlpHeapHandleError+0x12
    00000000`037eea20 00000000`77c1b144 : 00000000`08154d40 00000000`00150000 00000000`08154d50 00000000`00000000 : ntdll!RtlpLogHeapFailure+0xa4
    00000000`037eea50 00000000`7783300a : 00000000`0bd586d0 00000000`00000000 00000000`00000000 00000000`00000001 : ntdll! ?? ::FNODOBFM::`string'+0x106d4
    00000000`037eead0 000007fe`fc9e0b50 : 00000000`0bd79a00 00000000`00000000 00000000`0bd79a00 000007fe`efaa1010 : kernel32!HeapFree+0xa
    00000000`037eeb00 000007fe`efaab9d0 : 00000000`08025ff0 00000000`00000000 00000000`00000010 00000000`0000000a : comctl32!DSA_Destroy+0x34
    00000000`037eeb30 000007fe`efb0c29d : 00000000`081c4be0 00000000`00000000 00000000`00000001 00000000`00000000 : EXPLORERFRAME!DSA_Destroy+0x38
    00000000`037eeb60 000007fe`efb0c20b : 00000000`00000000 00000000`0000000a 00000000`00000000 00000000`02cf3530 : EXPLORERFRAME!CPerfTrackProvider::`vector deleting destructor'+0x85
    00000000`037eeb90 000007fe`efb0cf92 : 00000000`02cf3530 00000000`02cf3530 00000000`00000000 000007fe`ff27e5ee : EXPLORERFRAME!CPerfTrackProvider::Release+0x22
    00000000`037eebc0 000007fe`efb0cc20 : 00000000`00000001 00000000`00000000 00000000`00000000 00000000`0bf57790 : EXPLORERFRAME!CShellBrowser::~CShellBrowser+0x360
    00000000`037eebf0 000007fe`efb0c2db : 00000000`00000000 00000000`00000000 00000000`0be50e28 00000000`00000000 : EXPLORERFRAME!CShellBrowser::`scalar deleting destructor'+0x14
    00000000`037eec20 000007fe`efb0d382 : 00000000`0be50e10 00000000`00000000 00000000`00000000 00000000`0be50e28 : EXPLORERFRAME!CShellBrowser::Release+0x25
    00000000`037eec50 000007fe`efb0d290 : 00000000`0be50e28 00000000`00000000 00000000`00000000 000007fe`efab0570 : EXPLORERFRAME!CBrowserHost::_Cleanup+0xb6
    00000000`037eec90 000007fe`efb0d681 : 00000000`02cf35b0 00000000`02cf3530 00000000`00000000 00000000`00000000 : EXPLORERFRAME!CBrowserHost::OnBrowserClosed+0x20
    00000000`037eecc0 000007fe`efb0d4e3 : 00000000`0801b158 00000000`00000001 00000000`02cf3530 00000000`00000001 : EXPLORERFRAME!CShellBrowser::_OnConfirmedClose+0x1f1
    00000000`037eecf0 000007fe`efb0d3ee : 00000000`0be50e20 00000000`0bf57808 00000000`0bf577d8 00000000`00000000 : EXPLORERFRAME!CShellBrowser::OnClose+0xea
    00000000`037eed40 000007fe`efb0c023 : 00000000`0bf2d5e8 00000000`0801b0e0 00000000`00000001 00000000`0c09aca0 : EXPLORERFRAME!CBrowserHost::OnClose+0x26
    00000000`037eed70 000007fe`efb0ddea : 00000000`00000084 0000e61d`00000000 00000100`00000080 00000000`77aa88b8 : EXPLORERFRAME!CExplorerFrame::_OnClose+0x84
    00000000`037eeda0 000007fe`efaa1b44 : 00000000`0801b0e0 00000000`00131208 00000000`00000000 00000000`00000409 : EXPLORERFRAME!CExplorerFrame::v_WndProc+0x106
    00000000`037eee40 00000000`77aa9bd1 : 00000000`00000000 00000000`0000f060 00000000`00000001 00000000`00000000 : EXPLORERFRAME!CImpWndProc::s_WndProc+0x91
    00000000`037eee80 00000000`77aa72cb : 00000000`00000000 000007fe`efaa1ae0 00000000`00000000 00000000`00000000 : user32!UserCallWinProcCheckWow+0x1ad
    00000000`037eef40 00000000`77aa6829 : 00000000`00000409 00000000`00000002 00000000`00000002 00000000`037ef4e8 : user32!DispatchClientMessage+0xc3
    00000000`037eefa0 00000000`77be04e5 : 0000e61d`1aaef117 00000000`00000090 00000000`00000000 00000000`081bd9a8 : user32!_fnDWORD+0x2d
    00000000`037ef000 00000000`77aa685a : 00000000`77aa68a2 00000000`00000000 00000000`0c09ada0 00000100`00000001 : ntdll!KiUserCallbackDispatcherContinue
    00000000`037ef088 00000000`77aa68a2 : 00000000`00000000 00000000`0c09ada0 00000100`00000001 00000000`00000000 : user32!ZwUserMessageCall+0xa
    00000000`037ef090 00000000`77aa760e : 00000000`081d3080 00000000`77aa88b8 00000000`0000f060 00000000`00000112 : user32!RealDefWindowProcWorker+0xa4
    00000000`037ef160 000007fe`fc85795a : 00000000`037ef240 00000000`00000000 00000000`00846290 00000000`00000112 : user32!RealDefWindowProcW+0x5a
    00000000`037ef1a0 000007fe`fc87637a : 00000000`02111398 00000000`77aa75d4 00000000`00000000 00000000`00000112 : uxtheme!DoMsgDefault+0x2a
    00000000`037ef1d0 000007fe`fc85168e : 00000000`021764e0 00000000`00000112 00000000`00000000 00000000`00131208 : uxtheme!OnDwpSysCommand+0x50
    00000000`037ef200 000007fe`fc851445 : 00000000`00000000 00000000`00131208 00000000`0000f060 00000000`00040584 : uxtheme!_ThemeDefWindowProc+0x209
    00000000`037ef2b0 00000000`77aa89d3 : 00000000`00131208 000007fe`fc85133c 00000000`00131208 00000000`00040584 : uxtheme!ThemeDefWindowProcW+0x11
    00000000`037ef2f0 000007fe`efab15b1 : 00000000`00000001 00000000`0801b0e0 00000000`0000f060 000007fe`fc853044 : user32!DefWindowProcW+0xe6
    00000000`037ef340 000007fe`efaa1b44 : 00000000`0801b0e0 00000000`00131208 00000000`00000000 00000000`0000f060 : EXPLORERFRAME!CExplorerFrame::v_WndProc+0xa42
    00000000`037ef3e0 00000000`77aa8971 : 00000000`00000000 00000000`00000014 00000000`00000001 00000000`00040584 : EXPLORERFRAME!CImpWndProc::s_WndProc+0x91
    00000000`037ef420 00000000`77aa72cb : 00000000`00000000 000007fe`efaa1ae0 00000000`00000000 00000000`00000000 : user32!UserCallWinProcCheckWow+0x163
    00000000`037ef4e0 00000000`77aa6829 : 00000000`00000001 00000000`00000000 00000000`00000001 00000000`00000030 : user32!DispatchClientMessage+0xc3
    00000000`037ef540 00000000`77be04e5 : 00000000`00000000 00000000`77be04e5 00000000`80004005 000007fe`efab13ed : user32!_fnDWORD+0x2d
    00000000`037ef5a0 00000000`77aa685a : 00000000`77aa68a2 00000000`00131208 00000000`77aa9aa6 00000000`0000a918 : ntdll!KiUserCallbackDispatcherContinue
    00000000`037ef628 00000000`77aa68a2 : 00000000`00131208 00000000`77aa9aa6 00000000`0000a918 00000000`00040584 : user32!ZwUserMessageCall+0xa
    00000000`037ef630 00000000`77aa760e : 00000000`00000000 00000000`77aa791a 00000000`00000014 00000000`000000a1 : user32!RealDefWindowProcWorker+0xa4
    00000000`037ef700 000007fe`fc85795a : 00000000`037ef7f0 00000000`00000000 00000000`00000000 00000000`000000a1 : user32!RealDefWindowProcW+0x5a
    00000000`037ef740 000007fe`fc876425 : 00000000`037ef7f0 00000000`000000a1 00000000`02111398 00000000`00000000 : uxtheme!DoMsgDefault+0x2a
    00000000`037ef770 000007fe`fc85168e : 00000000`021764e0 00000000`00000000 00000000`00000000 00000000`00131208 : uxtheme!OnDwpNcLButtonDown+0x85
    00000000`037ef7b0 000007fe`fc851445 : 00000000`00000000 00000000`00131208 00000000`00000014 00000000`00040584 : uxtheme!_ThemeDefWindowProc+0x209
    00000000`037ef860 00000000`77aa89d3 : 00000000`77bba9e0 00000000`00846290 00000000`00000020 00000000`00131208 : uxtheme!ThemeDefWindowProcW+0x11
    00000000`037ef8a0 000007fe`efab15b1 : 00000000`00000001 00000000`0801b0e0 00000000`00000014 00000000`00000000 : user32!DefWindowProcW+0xe6
    00000000`037ef8f0 000007fe`efaa1b44 : 00000000`0801b0e0 00000000`00131208 00000000`00000000 00000000`77aa919b : EXPLORERFRAME!CExplorerFrame::v_WndProc+0xa42
    00000000`037ef990 00000000`77aa9bd1 : 00000000`00000000 00000000`0801b0e0 00000000`00000001 00000000`00000000 : EXPLORERFRAME!CImpWndProc::s_WndProc+0x91
    00000000`037ef9d0 00000000`77aa98da : 00000000`037efb40 000007fe`efaa1ae0 000007fe`efbeb550 00000000`00846290 : user32!UserCallWinProcCheckWow+0x1ad
    00000000`037efa90 000007fe`efab04b0 : 00000000`0801b004 00000000`0801b004 000007fe`efaa1ae0 00000000`00000000 : user32!DispatchMessageWorker+0x3b5
    00000000`037efb10 000007fe`efab4925 : 00000000`0801b0e0 00000000`00000015 00000000`00000000 00000000`00000000 : EXPLORERFRAME!CExplorerFrame::FrameMessagePump+0x436
    00000000`037efb90 000007fe`efab509b : 00000000`0801b0e0 00000000`08245fd0 00000000`00000000 00000000`00000000 : EXPLORERFRAME!BrowserThreadProc+0x180
    00000000`037efc10 000007fe`efab5032 : 13052155`00000001 00000000`0bde3e30 00000000`7fffffff 000007fe`fe0e2d40 : EXPLORERFRAME!BrowserNewThreadProc+0x53
    00000000`037efc40 000007fe`efaabe50 : 00000000`0bde4010 00000000`054a51d0 00000000`00000000 000007fe`fe4cf1b4 : EXPLORERFRAME!CExplorerTask::InternalResumeRT+0x12
    00000000`037efc70 000007fe`fe4cf0fb : 80000000`01000000 00000000`037efd00 00000000`0bde4010 00000000`0000000a : EXPLORERFRAME!CRunnableTask::Run+0xda
    00000000`037efca0 000007fe`fe4d2c42 : 00000000`0bde4010 00000000`00000000 00000000`0bde4010 00000000`00000002 : shell32!CShellTask::TT_Run+0x124
    00000000`037efcd0 000007fe`fe4d2d8e : 00000000`0bee0e00 00000000`0bee0e00 00000000`00000000 00000000`00000010 : shell32!CShellTaskThread::ThreadProc+0x1d2
    00000000`037efd70 000007fe`ff26c71e : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : shell32!CShellTaskThread::s_ThreadProc+0x22
    00000000`037efda0 00000000`7782652d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : shlwapi!WrapperThreadProc+0x19b
    00000000`037efea0 00000000`77bbba01 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0xd
    00000000`037efed0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x1d
    
    
    FOLLOWUP_IP: 
    EXPLORERFRAME!DSA_Destroy+38
    000007fe`efaab9d0 eb00            jmp     EXPLORERFRAME!DSA_Destroy+0x3c (000007fe`efaab9d2)
    
    SYMBOL_STACK_INDEX:  7
    
    SYMBOL_NAME:  explorerframe!DSA_Destroy+38
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: EXPLORERFRAME
    
    IMAGE_NAME:  EXPLORERFRAME.dll
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  4ce7c6a8
    
    STACK_COMMAND:  ~20s; .ecxr ; kb
    
    FAILURE_BUCKET_ID:  WRONG_SYMBOLS_c0000374_EXPLORERFRAME.dll!DSA_Destroy
    
    BUCKET_ID:  X64_APPLICATION_FAULT_WRONG_SYMBOLS_explorerframe!DSA_Destroy+38
    
    WATSON_STAGEONE_URL:  http://watson.microsoft.com/StageOne/explorer_exe/6_1_7601_17567/4d672ee4/ntdll_dll/6_1_7601_22436/521eb03f/c0000374/000c4322.htm?Retriage=1
    
    Followup: MachineOwner
    ---------
    
    0:020> !analyze
    *******************************************************************************
    *                                                                             *
    *                        Exception Analysis                                   *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    Probably caused by : EXPLORERFRAME.dll ( explorerframe!DSA_Destroy+38 )
    
    Followup: MachineOwner
    ---------
    

    Tuesday, November 26, 2013 8:36 PM

Answers

  • Hi,

    If clean install an OS reproduce the problem , it is a problem with something other than Windows. It could be driver or hardware.

    If possible, try install Windows 7 in the same model as your PC and see if same issue happens, if the issue didn't reproduce, it is hardware issue.

    Windows Explorer crashes are mostly caused by an incompatible Shell Extension.

    Please Boot the computer in safe mode  to see if we can reproduce issue.

    Advanced startup options (including safe mode):  http://windows.microsoft.com/en-US/windows7/Advanced-startup-options-including-safe-mode

    In addition, you may refer to:

    Windows Explorer may crash in Windows 7 or in Windows Server 2008 R2

    http://support.microsoft.com/kb/2515325

    Hopefully you could resolve the issue soon.

    Regards,

    Blair Deng


    Blair Deng
    TechNet Community Support

    • Marked as answer by Cloud_TS Sunday, December 8, 2013 5:43 PM
    Thursday, November 28, 2013 5:19 AM

All replies

  • Hi

    try to re-register the .DLL
    run, cmd, run as administrator, copy paste this command   "for %d in (*.dll) do regsvr32 -s %d" and enter, restart PC

    but seems this issue happen after clean install, try also checking your HW


    • Edited by britishdhez Wednesday, November 27, 2013 6:22 AM
    Wednesday, November 27, 2013 6:22 AM
  • Hi,

    If clean install an OS reproduce the problem , it is a problem with something other than Windows. It could be driver or hardware.

    If possible, try install Windows 7 in the same model as your PC and see if same issue happens, if the issue didn't reproduce, it is hardware issue.

    Windows Explorer crashes are mostly caused by an incompatible Shell Extension.

    Please Boot the computer in safe mode  to see if we can reproduce issue.

    Advanced startup options (including safe mode):  http://windows.microsoft.com/en-US/windows7/Advanced-startup-options-including-safe-mode

    In addition, you may refer to:

    Windows Explorer may crash in Windows 7 or in Windows Server 2008 R2

    http://support.microsoft.com/kb/2515325

    Hopefully you could resolve the issue soon.

    Regards,

    Blair Deng


    Blair Deng
    TechNet Community Support

    • Marked as answer by Cloud_TS Sunday, December 8, 2013 5:43 PM
    Thursday, November 28, 2013 5:19 AM