(Windows 10) Windows Explorer Keeps Crashing

J

Joost Ziff

Hi,


For a while now in windows 10, Windows explorer will keep on crashing for various reasons, when I open files in notepad, open certain folders, open certain files, etc. It used to completely reboot the shell, but now that I've clicked the option for Explorer to open separate processes, it just crashes the open window.


Here is the !analyze -v of the dump file of one of the crashes. Let me know if I need to provide any other information:

This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(12a8.26b4): Access violation - code c0000005 (first/second chance not available)
ntdll!NtWaitForMultipleObjects+0x14:
00007ff9`aac8aa04 c3 ret
0:009> !analyze -v
*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************

*** ERROR: Symbol file could not be found. Defaulted to export symbols for seafile_ext64.dll -
GetUrlPageData2 (WinHttp) failed: 12002.

KEY_VALUES_STRING: 1


TIMELINE_ANALYSIS: 1

Timeline: !analyze.Start
Name: <blank>
Time: 2018-09-02T00:37:24.379Z
Diff: 94379 mSec

Timeline: Dump.Current
Name: <blank>
Time: 2018-09-02T00:35:50.0Z
Diff: 0 mSec

Timeline: Process.Start
Name: <blank>
Time: 2018-09-02T00:35:47.0Z
Diff: 3000 mSec


DUMP_CLASS: 2

DUMP_QUALIFIER: 400

CONTEXT: (.ecxr)
rax=0000000000000017 rbx=9fffe49300000000 rcx=0000000000000000
rdx=000000006da36616 rsi=0000000000000017 rdi=000000000518e850
rip=00007ff9aa62cc50 rsp=000000000608f038 rbp=000000006da36616
r8=0000000000000017 r9=0000000000000002 r10=000000000516af00
r11=8101010101010100 r12=0000000000c0adc0 r13=0000000000000001
r14=0000000000000000 r15=0000000000000064
iopl=0 nv up ei pl nz na pe cy
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010203
msvcrt!memcmp+0x90:
00007ff9`aa62cc50 488b01 mov rax,qword ptr [rcx] ds:00000000`00000000=????????????????
Resetting default scope

FAULTING_IP:
msvcrt!memcmp+90
00007ff9`aa62cc50 488b01 mov rax,qword ptr [rcx]

EXCEPTION_RECORD: (.exr -1)
ExceptionAddress: 00007ff9aa62cc50 (msvcrt!memcmp+0x0000000000000090)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000000
Attempt to read from address 0000000000000000

DEFAULT_BUCKET_ID: NULL_POINTER_READ

PROCESS_NAME: explorer.exe

FOLLOWUP_IP:
msvcrt!memcmp+90
00007ff9`aa62cc50 488b01 mov rax,qword ptr [rcx]

READ_ADDRESS: 0000000000000000

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.

EXCEPTION_CODE_STR: c0000005

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: 0000000000000000

WATSON_BKT_PROCSTAMP: 4031a9f8

WATSON_BKT_PROCVER: 10.0.17134.165

PROCESS_VER_PRODUCT: Microsoft® Windows® Operating System

WATSON_BKT_MODULE: msvcrt.dll

WATSON_BKT_MODSTAMP: 5cbba6fd

WATSON_BKT_MODOFFSET: 5cc50

WATSON_BKT_MODVER: 7.0.17134.1

MODULE_VER_PRODUCT: Microsoft® Windows® Operating System

BUILD_VERSION_STRING: 17134.1.amd64fre.rs4_release.180410-1804

MODLIST_WITH_TSCHKSUM_HASH: e529a5842093059dbf6e91deb13330099ea46f0d

MODLIST_SHA1_HASH: 32f998c617ac49e3fb51843f9df90858ab29ca55

NTGLOBALFLAG: 0

APPLICATION_VERIFIER_FLAGS: 0

DUMP_FLAGS: 94

DUMP_TYPE: 1

ANALYSIS_SESSION_HOST: WINDELL-UMI0KS3

ANALYSIS_SESSION_TIME: 09-02-2018 02:37:24.0379

ANALYSIS_VERSION: 10.0.17134.1 amd64fre

THREAD_ATTRIBUTES:
OS_LOCALE: ENU

PROBLEM_CLASSES:

ID: [0n309]
Type: [@ACCESS_VIOLATION]
Class: Addendum
Scope: BUCKET_ID
Name: Omit
Data: Omit
PID: [Unspecified]
TID: [0x26b4]
Frame: [0] : msvcrt!memcmp

ID: [0n281]
Type: [INVALID_POINTER_READ]
Class: Primary
Scope: BUCKET_ID
Name: Add
Data: Omit
PID: [Unspecified]
TID: [0x26b4]
Frame: [0] : msvcrt!memcmp

ID: [0n296]
Type: [NULL_POINTER_READ]
Class: Primary
Scope: DEFAULT_BUCKET_ID (Failure Bucket ID prefix)
BUCKET_ID
Name: Add
Data: Omit
PID: [0x12a8]
TID: [0x26b4]
Frame: [0] : msvcrt!memcmp

BUGCHECK_STR: APPLICATION_FAULT_NULL_POINTER_READ_INVALID_POINTER_READ

PRIMARY_PROBLEM_CLASS: APPLICATION_FAULT

LAST_CONTROL_TRANSFER: from 000000006d9afc57 to 00007ff9aa62cc50

STACK_TEXT:
00000000`0608f038 00000000`6d9afc57 : 00000000`0608f0d0 00000000`6d987c33 00000000`0516b186 00000000`0516b186 : msvcrt!memcmp+0x90
00000000`0608f040 00000000`6da2f610 : 00000000`6da34ae0 00000000`00000012 00000000`0516afb0 00000000`066fd4c0 : seafile_ext64!DllGetClassObject+0x2e77c
00000000`0608f090 00000000`6d985c44 : 00000000`0518e850 00000000`6da36616 00000000`00000009 00000000`00000000 : seafile_ext64!DllGetClassObject+0xae135
00000000`0608f0c0 00000000`6d9a09b9 : 00000000`0608f400 00000000`0608f330 00000000`0608f310 00000000`6d9a0c32 : seafile_ext64!DllGetClassObject+0x4769
00000000`0608f2d0 00000000`6d981bb3 : 00000000`0608f400 00000000`0608f3e0 00000000`00000000 00000000`00000000 : seafile_ext64!DllGetClassObject+0x1f4de
00000000`0608f3c0 00000000`6d982456 : 00000000`0515b6b0 00000000`0608f4c0 00000000`00000010 00000000`00000000 : seafile_ext64!DllGetClassObject+0x6d8
00000000`0608f480 00000000`6d9846c3 : 00000000`0515b6b0 00000000`0608f5e0 00000000`00000000 00000000`00000000 : seafile_ext64!DllGetClassObject+0xf7b
00000000`0608f520 00007ff9`a89201dc : 00000000`0515b6b0 00000000`066802a0 00000000`00000011 00000000`0000000c : seafile_ext64!DllGetClassObject+0x31e8
00000000`0608f630 00007ff9`a89200e6 : 00000000`0608f7a0 00000000`066802a0 00000000`00000011 00000000`00000064 : shell32!CFSIconOverlayManager::_GetFileOverlayInfo+0xe0
00000000`0608f690 00007ff9`a709b022 : 00000000`00000000 00000000`0608f738 00000000`00000011 00000000`0663ffe0 : shell32!CFSIconOverlayManager::GetFileOverlayInfo+0x46
00000000`0608f6d0 00007ff9`a7082050 : 00000000`00000000 00000000`00000000 00007ff9`aa070000 00000000`0669b960 : windows_storage!CFSFolder::_GetOverlayInfo+0x14a
00000000`0608f780 00007ff9`a7081ee8 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`066e7160 : windows_storage!CIconOverlayTask::DispatchTasks+0xf0
00000000`0608f800 00007ff9`a7107aef : 00000000`00000000 00000000`055b9160 00000000`06678e00 ffffffff`fffffffe : windows_storage!CIconOverlayTask::InternalResumeRT+0x158
00000000`0608f8a0 00007ff9`a70fe61c : 00000000`000012a8 00000000`05530780 00000000`06678e90 00000000`0000000b : windows_storage!CRunnableTask::Run+0x11f
00000000`0608f8f0 00007ff9`a70fd343 : ffffffff`fffffffe 00000000`00000000 ffffffff`fffffffe 00000000`06663eb0 : windows_storage!CShellTask::TT_Run+0x80
00000000`0608f920 00007ff9`a70fd04f : 00000000`05530780 00000000`05530780 00000000`00000000 00000000`00000000 : windows_storage!CShellTaskThread::ThreadProc+0xcb
00000000`0608f9d0 00007ff9`aa0a7056 : 00000000`00b80b30 00000000`00000000 00002655`f094fd15 00000000`7ffe0386 : windows_storage!CShellTaskThread::s_ThreadProc+0x2f
00000000`0608fa00 00007ff9`aac2f3c5 : 00000000`0542b0f0 00000000`7ffe0386 00000000`00000001 00007ff9`00000004 : SHCore!ExecuteWorkItemThreadProc+0x16
00000000`0608fa30 00007ff9`aac0fa50 : 00000000`00000000 00000000`0515f350 00007ff9`aa0a7040 00000000`00000000 : ntdll!RtlpTpWorkCallback+0x165
00000000`0608fb10 00007ff9`a9fc3034 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!TppWorkerThread+0x730
00000000`0608fe00 00007ff9`aac61431 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x14
00000000`0608fe30 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x21


THREAD_SHA1_HASH_MOD_FUNC: c8147c717c9af95a25339b7733d5b580b2945074

THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 683c82098084cdbc02c9871a5a6b347cb7ef79ef

THREAD_SHA1_HASH_MOD: e85c9ded519b0cf7732afa6db7d36a3d492db1f3

FAULT_INSTR_CODE: 48018b48

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: msvcrt!memcmp+90

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: msvcrt

IMAGE_NAME: msvcrt.dll

DEBUG_FLR_IMAGE_TIMESTAMP: 5cbba6fd

STACK_COMMAND: ~9s ; .ecxr ; kb

FAILURE_BUCKET_ID: NULL_POINTER_READ_c0000005_msvcrt.dll!memcmp

BUCKET_ID: APPLICATION_FAULT_NULL_POINTER_READ_INVALID_POINTER_READ_msvcrt!memcmp+90

FAILURE_EXCEPTION_CODE: c0000005

FAILURE_IMAGE_NAME: msvcrt.dll

BUCKET_ID_IMAGE_STR: msvcrt.dll

FAILURE_MODULE_NAME: msvcrt

BUCKET_ID_MODULE_STR: msvcrt

FAILURE_FUNCTION_NAME: memcmp

BUCKET_ID_FUNCTION_STR: memcmp

BUCKET_ID_OFFSET: 90

BUCKET_ID_MODTIMEDATESTAMP: 5cbba6fd

BUCKET_ID_MODCHECKSUM: a9508

BUCKET_ID_MODVER_STR: 7.0.17134.1

BUCKET_ID_PREFIX_STR: APPLICATION_FAULT_NULL_POINTER_READ_INVALID_POINTER_READ_

FAILURE_PROBLEM_CLASS: APPLICATION_FAULT

FAILURE_SYMBOL_NAME: msvcrt.dll!memcmp

WATSON_STAGEONE_URL: http://watson.microsoft.com/StageOn...4.1/5cbba6fd/c0000005/0005cc50.htm?Retriage=1

TARGET_TIME: 2018-09-02T00:35:50.000Z

OSBUILD: 17134

OSSERVICEPACK: 1

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK: 768

PRODUCT_TYPE: 1

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

OSEDITION: Windows 10 WinNt SingleUserTS Personal

USER_LCID: 0

OSBUILD_TIMESTAMP: 2020-08-28 06:38:41

BUILDDATESTAMP_STR: 180410-1804

BUILDLAB_STR: rs4_release

BUILDOSVER_STR: 10.0.17134.1.amd64fre.rs4_release.180410-1804

ANALYSIS_SESSION_ELAPSED_TIME: 11a40

ANALYSIS_SOURCE: UM

FAILURE_ID_HASH_STRING: um:null_pointer_read_c0000005_msvcrt.dll!memcmp

FAILURE_ID_HASH: {079a16d6-a0a6-379a-5b0b-a776ae44ba02}

Followup: MachineOwner
---------

Continue reading...
 

Similar threads

S
Replies
0
Views
386
Simon ElfvingKristensen
S
Replies
0
Views
410
ソンウンホ
C
Replies
0
Views
342
ChristopherScroggins1
C
Back
Top Bottom