kdawg2k14 Posted March 24, 2014 Posted March 24, 2014 Good Morning all,I'm having an issue with a Win 8.1 box that constantly crashes every few seconds when accessing the desktop, or anything else that needs the desktop to run. The error in the Application log is:Faulting application name: explorer.exe, version: 6.3.9600.16441, time stamp: 0x5265dec8Faulting module name: KERNELBASE.dll, version: 6.3.9600.16496, time stamp: 0x52b3f283Exception code: 0xc06d007eFault offset: 0x0000000000005a88Faulting process id: 0x5bcFaulting application start time: 0x01cf47721bd5b117Faulting application path: C:\WINDOWS\explorer.exeFaulting module path: C:\WINDOWS\system32\KERNELBASE.dllReport Id: 5c05ffbc-b365-11e3-beaf-7054d27f87a0Faulting package full name:Faulting package-relative application ID:So far the troubleshooting I have done so far is: Restored to an earlier date that did not have the issue. Created a new Windows Profile. Updated the system drivers. So far, no change.Researching the issue online points to analyzing the crash dump. I have uploaded one to the following location:https://onedrive.live.com/redir?resid=807BB7EC55C6E53E!107&authkey=!ACgpngBQ98E7TG8&ithint=file%2c.rarI would be very appreciative if someone is able to do so, I'd rather not keep shooting in the dark if I can help it. Thanks!-Kyle
MagicAndre1981 Posted March 24, 2014 Posted March 24, 2014 (edited) the Explorer crashes because of a Norton DLL (bushell.dll) which displays overlay icons:******************************************************************************** ** Exception Analysis ** *********************************************************************************** ERROR: Symbol file could not be found. Defaulted to export symbols for bushell.dll -*** ERROR: Symbol file could not be found. Defaulted to export symbols for sppc.dll -FAULTING_IP:KERNELBASE!RaiseException+6800007ffe`294f5a88 488b8c24c0000000 mov rcx,qword ptr [rsp+0C0h]EXCEPTION_RECORD: ffffffffffffffff -- (.exr 0xffffffffffffffff)ExceptionAddress: 00007ffe294f5a88 (KERNELBASE!RaiseException+0x0000000000000068)ExceptionCode: c06d007eExceptionFlags: 00000000NumberParameters: 1Parameter[0]: 000000001282b250CONTEXT: 0000000000000000 -- (.cxr 0x0;r)rax=0000000016c20000 rbx=0000000000000000 rcx=0000000016c20000rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000rip=00007ffe2beb6b2a rsp=0000000012829b48 rbp=000000001282ab60r8=0000000000001000 r9=0000000000000000 r10=0000000000000040r11=0000000000000286 r12=0000000000000000 r13=000000000000000br14=0000000016c10000 r15=0000000000000000iopl=0 nv up ei pl nz na pe cycs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000203ntdll!NtWaitForMultipleObjects+0xa:00007ffe`2beb6b2a c3 retDEFAULT_BUCKET_ID: INVALID_POINTER_READPROCESS_NAME: explorer.exeERROR_CODE: (NTSTATUS) 0xc06d007e - <Unable to get error code text>EXCEPTION_CODE: (NTSTATUS) 0xc06d007e - <Unable to get error code text>EXCEPTION_PARAMETER1: 000000001282b250NTGLOBALFLAG: 2000100APPLICATION_VERIFIER_FLAGS: 48004APP: explorer.exeSTACK_TEXT:ntdll!NtWaitForMultipleObjectsntdll!RtlReportExceptionExntdll!RtlReportExceptionntdll!LdrpCalloutExceptionFilterntdll!LdrpInitializeNode$filt$1ntdll!_C_specific_handlerntdll!RtlpExecuteHandlerForExceptionntdll!RtlDispatchExceptionntdll!RtlRaiseExceptionKERNELBASE!RaiseExceptionbushell!DllRegisterServerbushell!DllRegisterServerbushell!DllRegisterServerbushell!std::_Init_locks::operator=msvcr100!inittermbushell!std::_Init_locks::operator=bushell!std::_Init_locks::operator=verifier!AVrfpStandardDllEntryPointRoutinentdll!LdrpCallInitRoutinentdll!LdrpInitializeNodentdll!LdrpInitializeGraphntdll!LdrpPrepareModuleForExecutionntdll!LdrpLoadDllntdll!LdrLoadDllverifier!AVrfpLdrLoadDllKERNELBASE!LoadLibraryExWcombase!LoadLibraryWithLoggingcombase!CClassCache::CDllPathEntry::LoadDllcombase!CClassCache::CDllPathEntry::Createcombase!CClassCache::CClassEntry::CreateDllClassEntrycombase!CClassCache::GetClassObjectActivatorcombase!CClassCache::GetClassObjectcombase!CServerContextActivator::CreateInstancecombase!ActivationPropertiesIn::DelegateCreateInstancecombase!CApartmentActivator::CreateInstancecombase!CProcessActivator::CCICallbackcombase!CProcessActivator::AttemptActivationcombase!CProcessActivator::ActivateByContextcombase!CProcessActivator::CreateInstancecombase!ActivationPropertiesIn::DelegateCreateInstancecombase!CClientContextActivator::CreateInstancecombase!ActivationPropertiesIn::DelegateCreateInstancecombase!ICoCreateInstanceExcombase!CComActivator::DoCreateInstancecombase!CoCreateInstanceshell32!_SHCoCreateInstanceshell32!SHExtCoCreateInstanceshell32!DCA_SHExtCoCreateInstanceshell32!CFSIconOverlayManager::_s_LoadIconOverlayIdentifiersshell32!CFSIconOverlayManager::LoadNonloadedOverlayIdentifiersshell32!EnableExternalOverlayIdentifiersshell32!CFSIconOverlayManager::RefreshOverlayImagesshell32!GetIconOverlayManagerImplshell32!CFSFolder::_GetOverlayInfoshell32!CDesktopFolder::GetOverlayIndexshell32!CRegFolder::GetOverlayIndexshell32!CIconOverlayTask::InternalResumeRTshell32!CRunnableTask::Runshell32!CShellTaskThread::ThreadProcshell32!CShellTaskThread::s_ThreadProcSHCore!ExecuteWorkItemThreadProcntdll!RtlpTpWorkCallbackntdll!TppWorkerThreadkernel32!BaseThreadInitThunkntdll!RtlUserThreadStartIMAGE_NAME: bushell.dllFAILURE_ID_HASH_STRING: um:invalid_pointer_read_c06d007e_bushell.dll!dllregisterserverLoaded symbol image file: bushell.dllImage path: C:\Program Files (x86)\Norton 360\Engine64\20.4.0.40\bushell.dllImage name: bushell.dllTimestamp: Wed May 29 04:40:33 2013 (51A56AA1)CheckSum: 0028C07AImageSize: 0028B000File version: 7.4.0.18Product version: 7.4.0.0File flags: 0 (Mask 3F)File OS: 40004 NT Win32File type: 1.0 AppFile date: 00000000.00000000Translations: 0409.04b0CompanyName: Symantec CorporationProductName: BackupInternalName: BUShell.dllOriginalFilename: BUShell.dllProductVersion: 7.4FileVersion: 7.4.0.18FileDescription: Backup ShellLegalCopyright: Copyright ? 2013 Symantec Corporation. All rights reserved.Disable the icons in the Norton options or remove the tool.Run this uninstall.reg to disable the dup creation and AppVerifier:http://cid-128fc518635be2dc.skydrive.live.com/self.aspx/.Public/MS%20Foren/Registry/WER%5E_Explorer_full_uninstall.reg Edited March 24, 2014 by MagicAndre1981
kdawg2k14 Posted March 26, 2014 Author Posted March 26, 2014 Thank you Andre, and thanks for the time to run the debugger and pinpoint the issue. Your expertise is well appreciated!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now