Jump to content

Recommended Posts

Posted

Good Morning all,

I'm having an issue with a Win 8.1 box that constantly crashes every few seconds when accessing the desktop, or anything else that needs the desktop to run. The error in the Application log is:

Faulting application name: explorer.exe, version: 6.3.9600.16441, time stamp: 0x5265dec8
Faulting module name: KERNELBASE.dll, version: 6.3.9600.16496, time stamp: 0x52b3f283
Exception code: 0xc06d007e
Fault offset: 0x0000000000005a88
Faulting process id: 0x5bc
Faulting application start time: 0x01cf47721bd5b117
Faulting application path: C:\WINDOWS\explorer.exe
Faulting module path: C:\WINDOWS\system32\KERNELBASE.dll
Report Id: 5c05ffbc-b365-11e3-beaf-7054d27f87a0
Faulting package full name:
Faulting package-relative application ID:

So far the troubleshooting I have done so far is: Restored to an earlier date that did not have the issue. Created a new Windows Profile. Updated the system drivers. So far, no change.

Researching the issue online points to analyzing the crash dump. I have uploaded one to the following location:

https://onedrive.live.com/redir?resid=807BB7EC55C6E53E!107&authkey=!ACgpngBQ98E7TG8&ithint=file%2c.rar

I would be very appreciative if someone is able to do so, I'd rather not keep shooting in the dark if I can help it. Thanks!

-Kyle


Posted (edited)

the Explorer crashes because of a Norton DLL (bushell.dll) which displays overlay icons:

********************************************************************************                                                                             ** Exception Analysis                                                          **                                                                             *********************************************************************************** ERROR: Symbol file could not be found. Defaulted to export symbols for bushell.dll -*** ERROR: Symbol file could not be found. Defaulted to export symbols for sppc.dll -FAULTING_IP:KERNELBASE!RaiseException+6800007ffe`294f5a88 488b8c24c0000000 mov rcx,qword ptr [rsp+0C0h]EXCEPTION_RECORD: ffffffffffffffff -- (.exr 0xffffffffffffffff)ExceptionAddress: 00007ffe294f5a88 (KERNELBASE!RaiseException+0x0000000000000068)ExceptionCode: c06d007eExceptionFlags: 00000000NumberParameters: 1Parameter[0]: 000000001282b250CONTEXT: 0000000000000000 -- (.cxr 0x0;r)rax=0000000016c20000 rbx=0000000000000000 rcx=0000000016c20000rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000rip=00007ffe2beb6b2a rsp=0000000012829b48 rbp=000000001282ab60r8=0000000000001000 r9=0000000000000000 r10=0000000000000040r11=0000000000000286 r12=0000000000000000 r13=000000000000000br14=0000000016c10000 r15=0000000000000000iopl=0 nv up ei pl nz na pe cycs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000203ntdll!NtWaitForMultipleObjects+0xa:00007ffe`2beb6b2a c3 retDEFAULT_BUCKET_ID: INVALID_POINTER_READPROCESS_NAME: explorer.exeERROR_CODE: (NTSTATUS) 0xc06d007e - <Unable to get error code text>EXCEPTION_CODE: (NTSTATUS) 0xc06d007e - <Unable to get error code text>EXCEPTION_PARAMETER1: 000000001282b250NTGLOBALFLAG: 2000100APPLICATION_VERIFIER_FLAGS: 48004APP: explorer.exeSTACK_TEXT:ntdll!NtWaitForMultipleObjectsntdll!RtlReportExceptionExntdll!RtlReportExceptionntdll!LdrpCalloutExceptionFilterntdll!LdrpInitializeNode$filt$1ntdll!_C_specific_handlerntdll!RtlpExecuteHandlerForExceptionntdll!RtlDispatchExceptionntdll!RtlRaiseExceptionKERNELBASE!RaiseExceptionbushell!DllRegisterServerbushell!DllRegisterServerbushell!DllRegisterServerbushell!std::_Init_locks::operator=msvcr100!inittermbushell!std::_Init_locks::operator=bushell!std::_Init_locks::operator=verifier!AVrfpStandardDllEntryPointRoutinentdll!LdrpCallInitRoutinentdll!LdrpInitializeNodentdll!LdrpInitializeGraphntdll!LdrpPrepareModuleForExecutionntdll!LdrpLoadDllntdll!LdrLoadDllverifier!AVrfpLdrLoadDllKERNELBASE!LoadLibraryExWcombase!LoadLibraryWithLoggingcombase!CClassCache::CDllPathEntry::LoadDllcombase!CClassCache::CDllPathEntry::Createcombase!CClassCache::CClassEntry::CreateDllClassEntrycombase!CClassCache::GetClassObjectActivatorcombase!CClassCache::GetClassObjectcombase!CServerContextActivator::CreateInstancecombase!ActivationPropertiesIn::DelegateCreateInstancecombase!CApartmentActivator::CreateInstancecombase!CProcessActivator::CCICallbackcombase!CProcessActivator::AttemptActivationcombase!CProcessActivator::ActivateByContextcombase!CProcessActivator::CreateInstancecombase!ActivationPropertiesIn::DelegateCreateInstancecombase!CClientContextActivator::CreateInstancecombase!ActivationPropertiesIn::DelegateCreateInstancecombase!ICoCreateInstanceExcombase!CComActivator::DoCreateInstancecombase!CoCreateInstanceshell32!_SHCoCreateInstanceshell32!SHExtCoCreateInstanceshell32!DCA_SHExtCoCreateInstanceshell32!CFSIconOverlayManager::_s_LoadIconOverlayIdentifiersshell32!CFSIconOverlayManager::LoadNonloadedOverlayIdentifiersshell32!EnableExternalOverlayIdentifiersshell32!CFSIconOverlayManager::RefreshOverlayImagesshell32!GetIconOverlayManagerImplshell32!CFSFolder::_GetOverlayInfoshell32!CDesktopFolder::GetOverlayIndexshell32!CRegFolder::GetOverlayIndexshell32!CIconOverlayTask::InternalResumeRTshell32!CRunnableTask::Runshell32!CShellTaskThread::ThreadProcshell32!CShellTaskThread::s_ThreadProcSHCore!ExecuteWorkItemThreadProcntdll!RtlpTpWorkCallbackntdll!TppWorkerThreadkernel32!BaseThreadInitThunkntdll!RtlUserThreadStartIMAGE_NAME: bushell.dllFAILURE_ID_HASH_STRING: um:invalid_pointer_read_c06d007e_bushell.dll!dllregisterserverLoaded symbol image file: bushell.dllImage path: C:\Program Files (x86)\Norton 360\Engine64\20.4.0.40\bushell.dllImage name: bushell.dllTimestamp: Wed May 29 04:40:33 2013 (51A56AA1)CheckSum: 0028C07AImageSize: 0028B000File version: 7.4.0.18Product version: 7.4.0.0File flags: 0 (Mask 3F)File OS: 40004 NT Win32File type: 1.0 AppFile date: 00000000.00000000Translations: 0409.04b0CompanyName: Symantec CorporationProductName: BackupInternalName: BUShell.dllOriginalFilename: BUShell.dllProductVersion: 7.4FileVersion: 7.4.0.18FileDescription: Backup ShellLegalCopyright: Copyright ? 2013 Symantec Corporation. All rights reserved.

Disable the icons in the Norton options or remove the tool.

Run this uninstall.reg to disable the dup creation and AppVerifier:

http://cid-128fc518635be2dc.skydrive.live.com/self.aspx/.Public/MS%20Foren/Registry/WER%5E_Explorer_full_uninstall.reg

Edited by MagicAndre1981
Posted

Thank you Andre, and thanks for the time to run the debugger and pinpoint the issue. Your expertise is well appreciated!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...