Windows Explorer Crash Error Code c0000374

lwh

Member
Joined
Sep 7, 2016
Posts
5
Windows Explorer crashes when drag-and-dropping files

I am hoping that someone can help me.

Starting this morning Windows Explorer keeps crashing on me when I am dragging and dropping files or taking screenshots.

[FONT=&quot]Here are some of the problems I'm seeing.[/FONT]
[FONT=&quot]Source
Windows Explorer

Summary
Stopped working

Date
‎9/‎7/‎2016 8:09 AM

Status
Report sent

Description
Faulting Application Path: C:\Windows\explorer.exe

Problem signature
Problem Event Name: APPCRASH
Application Name: Explorer.EXE
Application Version: 10.0.14393.0
Application Timestamp: 57899981
Fault Module Name: StackHash_0076
Fault Module Version: 10.0.14393.103
Fault Module Timestamp: 57b7e207
Exception Code: c0000374
Exception Offset: PCH_CA_FROM_ntdll+0x00000000000A59A4
OS Version: 10.0.14393.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 0076
Additional Information 2: 007669c72282bc8577135de9e2d9b35d
Additional Information 3: ff20
Additional Information 4: ff2007d4a78757decd100be128bf010c

Extra information about the problem
Bucket ID: edf8daaaa92d7e2c82237fd64dd52609 (120538520262)[/FONT]

[FONT=&quot]Source
Windows Explorer

Summary
Stopped working

Date
‎9/‎7/‎2016 8:21 AM

Status
Report sent

Description
Faulting Application Path: C:\Windows\explorer.exe

Problem signature
Problem Event Name: APPCRASH
Application Name: explorer.exe
Application Version: 10.0.14393.0
Application Timestamp: 57899981
Fault Module Name: StackHash_5213
Fault Module Version: 10.0.14393.103
Fault Module Timestamp: 57b7e207
Exception Code: c0000374
Exception Offset: PCH_CA_FROM_ntdll+0x00000000000A59A4
OS Version: 10.0.14393.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 5213
Additional Information 2: 521316cef69cedc34121c8c3cda31021
Additional Information 3: 8fb0
Additional Information 4: 8fb0b7515ecf8afe19d41743258b8a92

Extra information about the problem
Bucket ID: 973022c8538696bd8d2bd5fb859764ad (120538983994)[/FONT]
 
[FONT=&quot]Starting this morning Windows Explorer keeps crashing on me when I am dragging and dropping files or taking screenshots.[/FONT]
[FONT=&quot]This is killing me. I've never seen this problem before today. Here are some of the problems I'm seeing.[/FONT]
[FONT=&quot]Source
Windows Explorer

Summary
Stopped working

Date
‎9/‎7/‎2016 8:09 AM

Status
Report sent

Description
Faulting Application Path: C:\Windows\explorer.exe

Problem signature
Problem Event Name: APPCRASH
Application Name: Explorer.EXE
Application Version: 10.0.14393.0
Application Timestamp: 57899981
Fault Module Name: StackHash_0076
Fault Module Version: 10.0.14393.103
Fault Module Timestamp: 57b7e207
Exception Code: c0000374
Exception Offset: PCH_CA_FROM_ntdll+0x00000000000A59A4
OS Version: 10.0.14393.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 0076
Additional Information 2: 007669c72282bc8577135de9e2d9b35d
Additional Information 3: ff20
Additional Information 4: ff2007d4a78757decd100be128bf010c

Extra information about the problem
Bucket ID: edf8daaaa92d7e2c82237fd64dd52609 (120538520262)[/FONT]

[FONT=&quot]Source
Windows Explorer

Summary
Stopped working

Date
‎9/‎7/‎2016 8:21 AM

Status
Report sent

Description
Faulting Application Path: C:\Windows\explorer.exe

Problem signature
Problem Event Name: APPCRASH
Application Name: explorer.exe
Application Version: 10.0.14393.0
Application Timestamp: 57899981
Fault Module Name: StackHash_5213
Fault Module Version: 10.0.14393.103
Fault Module Timestamp: 57b7e207
Exception Code: c0000374
Exception Offset: PCH_CA_FROM_ntdll+0x00000000000A59A4
OS Version: 10.0.14393.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 5213
Additional Information 2: 521316cef69cedc34121c8c3cda31021
Additional Information 3: 8fb0
Additional Information 4: 8fb0b7515ecf8afe19d41743258b8a92

Extra information about the problem
Bucket ID: 973022c8538696bd8d2bd5fb859764ad (120538983994)
[/FONT]
 
Re: Windows Explorer crashes when drag-and-dropping files

Hi lwh. :welcome:

Did the problem disappear?

Hi it has not disappeared as of yet.

I have tried disabling all the shell extensions, used SFC and DMIS command operations, all to no avail. Also I have run multiple virus checks.

Here is a little more information that might help.

[FONT=&quot]Version=1[/FONT]
[FONT=&quot]EventType=APPCRASH[/FONT]
[FONT=&quot]EventTime=131177245041673174[/FONT]
[FONT=&quot]ReportType=2[/FONT]
[FONT=&quot]Consent=1[/FONT]
[FONT=&quot]UploadTime=131177245045284023[/FONT]
[FONT=&quot]ReportFlags=524288[/FONT]
[FONT=&quot]ReportIdentifier=a2efe76a-74f5-11e6-ad68-d0bf9c97400e[/FONT]
[FONT=&quot]IntegratorReportIdentifier=58e035a5-183a-4950-b564-82ab98093fae[/FONT]
[FONT=&quot]NsAppName=explorer.exe[/FONT]
[FONT=&quot]AppSessionGuid=00001398-0001-0002-6eee-d7b60009d201[/FONT]
[FONT=&quot]TargetAppId=W:0000f519feec486de87ed73cb92d3cac802400000000!0000aaecc83ff22939ed9b82c75e95369c9378bb2077!explorer.exe[/FONT]
[FONT=&quot]TargetAppVer=2016//07//16:02:18:41!482a3b!explorer.exe[/FONT]
[FONT=&quot]BootId=4294967295[/FONT]
[FONT=&quot]Response.BucketId=973022c8538696bd8d2bd5fb859764ad[/FONT]
[FONT=&quot]Response.BucketTable=4[/FONT]
[FONT=&quot]Response.LegacyBucketId=120538983994[/FONT]
[FONT=&quot]Response.type=4[/FONT]
[FONT=&quot]Sig[0].Name=Application Name[/FONT]
[FONT=&quot]Sig[0].Value=explorer.exe[/FONT]
[FONT=&quot]Sig[1].Name=Application Version[/FONT]
[FONT=&quot]Sig[1].Value=10.0.14393.0[/FONT]
[FONT=&quot]Sig[2].Name=Application Timestamp[/FONT]
[FONT=&quot]Sig[2].Value=57899981[/FONT]
[FONT=&quot]Sig[3].Name=Fault Module Name[/FONT]
[FONT=&quot]Sig[3].Value=StackHash_5213[/FONT]
[FONT=&quot]Sig[4].Name=Fault Module Version[/FONT]
[FONT=&quot]Sig[4].Value=10.0.14393.103[/FONT]
[FONT=&quot]Sig[5].Name=Fault Module Timestamp[/FONT]
[FONT=&quot]Sig[5].Value=57b7e207[/FONT]
[FONT=&quot]Sig[6].Name=Exception Code[/FONT]
[FONT=&quot]Sig[6].Value=c0000374[/FONT]
[FONT=&quot]Sig[7].Name=Exception Offset[/FONT]
[FONT=&quot]Sig[7].Value=PCH_CA_FROM_ntdll+0x00000000000A59A4[/FONT]
[FONT=&quot]DynamicSig[1].Name=OS Version[/FONT]
[FONT=&quot]DynamicSig[1].Value=10.0.14393.2.0.0.768.101[/FONT]
[FONT=&quot]DynamicSig[2].Name=Locale ID[/FONT]
[FONT=&quot]DynamicSig[2].Value=1033[/FONT]
[FONT=&quot]DynamicSig[22].Name=Additional Information 1[/FONT]
[FONT=&quot]DynamicSig[22].Value=5213[/FONT]
[FONT=&quot]DynamicSig[23].Name=Additional Information 2[/FONT]
[FONT=&quot]DynamicSig[23].Value=521316cef69cedc34121c8c3cda31021[/FONT]
[FONT=&quot]DynamicSig[24].Name=Additional Information 3[/FONT]
[FONT=&quot]DynamicSig[24].Value=8fb0[/FONT]
[FONT=&quot]DynamicSig[25].Name=Additional Information 4[/FONT]
[FONT=&quot]DynamicSig[25].Value=8fb0b7515ecf8afe19d41743258b8a92[/FONT]
[FONT=&quot]UI[2]=C:\WINDOWS\explorer.exe[/FONT]
[FONT=&quot]LoadedModule[0]=C:\WINDOWS\explorer.exe[/FONT]
[FONT=&quot]LoadedModule[1]=C:\WINDOWS\SYSTEM32\ntdll.dll[/FONT]
[FONT=&quot]LoadedModule[2]=C:\WINDOWS\System32\KERNEL32.DLL[/FONT]
[FONT=&quot]LoadedModule[3]=C:\WINDOWS\System32\KERNELBASE.dll[/FONT]
[FONT=&quot]LoadedModule[4]=C:\WINDOWS\System32\msvcrt.dll[/FONT]
[FONT=&quot]LoadedModule[5]=C:\WINDOWS\System32\OLEAUT32.dll[/FONT]
[FONT=&quot]LoadedModule[6]=C:\WINDOWS\System32\ucrtbase.dll[/FONT]
[FONT=&quot]LoadedModule[7]=C:\WINDOWS\System32\combase.dll[/FONT]
[FONT=&quot]LoadedModule[8]=C:\WINDOWS\System32\RPCRT4.dll[/FONT]
[FONT=&quot]LoadedModule[9]=C:\WINDOWS\System32\bcryptPrimitives.dll[/FONT]
[FONT=&quot]LoadedModule[10]=C:\WINDOWS\System32\USER32.dll[/FONT]
[FONT=&quot]LoadedModule[11]=C:\WINDOWS\System32\win32u.dll[/FONT]
[FONT=&quot]LoadedModule[12]=C:\WINDOWS\System32\GDI32.dll[/FONT]
[FONT=&quot]LoadedModule[13]=C:\WINDOWS\System32\gdi32full.dll[/FONT]
[FONT=&quot]LoadedModule[14]=C:\WINDOWS\System32\SHCORE.dll[/FONT]
[FONT=&quot]LoadedModule[15]=C:\WINDOWS\System32\SHLWAPI.dll[/FONT]
[FONT=&quot]LoadedModule[16]=C:\WINDOWS\System32\SHELL32.dll[/FONT]
[FONT=&quot]LoadedModule[17]=C:\WINDOWS\System32\cfgmgr32.dll[/FONT]
[FONT=&quot]LoadedModule[18]=C:\WINDOWS\System32\windows.storage.dll[/FONT]
[FONT=&quot]LoadedModule[19]=C:\WINDOWS\System32\powrprof.dll[/FONT]
[FONT=&quot]LoadedModule[20]=C:\WINDOWS\System32\advapi32.dll[/FONT]
[FONT=&quot]LoadedModule[21]=C:\WINDOWS\System32\sechost.dll[/FONT]
[FONT=&quot]LoadedModule[22]=C:\WINDOWS\System32\kernel.appcore.dll[/FONT]
[FONT=&quot]LoadedModule[23]=C:\WINDOWS\System32\profapi.dll[/FONT]
[FONT=&quot]LoadedModule[24]=C:\WINDOWS\System32\CRYPT32.dll[/FONT]
[FONT=&quot]LoadedModule[25]=C:\WINDOWS\SYSTEM32\PROPSYS.dll[/FONT]
[FONT=&quot]LoadedModule[26]=C:\WINDOWS\System32\MSASN1.dll[/FONT]
[FONT=&quot]LoadedModule[27]=C:\WINDOWS\SYSTEM32\MrmCoreR.dll[/FONT]
[FONT=&quot]LoadedModule[28]=C:\WINDOWS\SYSTEM32\UxTheme.dll[/FONT]
[FONT=&quot]LoadedModule[29]=C:\WINDOWS\SYSTEM32\dwmapi.dll[/FONT]
[FONT=&quot]LoadedModule[30]=C:\WINDOWS\SYSTEM32\TWINAPI.dll[/FONT]
[FONT=&quot]LoadedModule[31]=C:\WINDOWS\SYSTEM32\twinapi.appcore.dll[/FONT]
[FONT=&quot]LoadedModule[32]=C:\WINDOWS\SYSTEM32\SspiCli.dll[/FONT]
[FONT=&quot]LoadedModule[33]=C:\WINDOWS\SYSTEM32\USERENV.dll[/FONT]
[FONT=&quot]LoadedModule[34]=C:\WINDOWS\SYSTEM32\settingsynccore.dll[/FONT]
[FONT=&quot]LoadedModule[35]=C:\WINDOWS\SYSTEM32\bcrypt.dll[/FONT]
[FONT=&quot]LoadedModule[36]=C:\WINDOWS\SYSTEM32\cryptsp.dll[/FONT]
[FONT=&quot]LoadedModule[37]=C:\WINDOWS\System32\IMM32.DLL[/FONT]
[FONT=&quot]LoadedModule[38]=C:\WINDOWS\System32\MSCTF.dll[/FONT]
[FONT=&quot]LoadedModule[39]=C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll[/FONT]
[FONT=&quot]LoadedModule[40]=C:\WINDOWS\System32\ole32.dll[/FONT]
[FONT=&quot]LoadedModule[41]=C:\WINDOWS\System32\clbcatq.dll[/FONT]
[FONT=&quot]LoadedModule[42]=C:\Windows\System32\ActXPrxy.dll[/FONT]
[FONT=&quot]LoadedModule[43]=C:\Windows\System32\SharedStartModel.dll[/FONT]
[FONT=&quot]LoadedModule[44]=C:\Windows\System32\XmlLite.dll[/FONT]
[FONT=&quot]LoadedModule[45]=C:\Windows\System32\VEEventDispatcher.dll[/FONT]
[FONT=&quot]LoadedModule[46]=C:\Windows\System32\CoreMessaging.dll[/FONT]
[FONT=&quot]LoadedModule[47]=C:\Windows\System32\msvcp110_win.dll[/FONT]
[FONT=&quot]LoadedModule[48]=C:\WINDOWS\System32\IDStore.dll[/FONT]
[FONT=&quot]LoadedModule[49]=C:\WINDOWS\System32\SAMLIB.dll[/FONT]
[FONT=&quot]LoadedModule[50]=C:\WINDOWS\SYSTEM32\Bcp47Langs.dll[/FONT]
[FONT=&quot]LoadedModule[51]=C:\Windows\System32\TokenBroker.dll[/FONT]
[FONT=&quot]LoadedModule[52]=C:\Windows\System32\TOKENBINDING.dll[/FONT]
[FONT=&quot]LoadedModule[53]=C:\WINDOWS\SYSTEM32\wintypes.dll[/FONT]
[FONT=&quot]LoadedModule[54]=C:\WINDOWS\SYSTEM32\WINSTA.dll[/FONT]
[FONT=&quot]LoadedModule[55]=C:\Windows\System32\usermgrproxy.dll[/FONT]
[FONT=&quot]LoadedModule[56]=C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.0_none_2d0f50fcbdb171b8\comctl32.dll[/FONT]
[FONT=&quot]LoadedModule[57]=C:\Windows\System32\iertutil.dll[/FONT]
[FONT=&quot]LoadedModule[58]=C:\WINDOWS\SYSTEM32\SndVolSSO.DLL[/FONT]
[FONT=&quot]LoadedModule[59]=C:\Windows\System32\vaultcli.dll[/FONT]
[FONT=&quot]LoadedModule[60]=C:\WINDOWS\System32\MMDevApi.dll[/FONT]
[FONT=&quot]LoadedModule[61]=C:\WINDOWS\System32\DEVOBJ.dll[/FONT]
[FONT=&quot]LoadedModule[62]=C:\WINDOWS\SYSTEM32\OLEACC.dll[/FONT]
[FONT=&quot]LoadedModule[63]=C:\WINDOWS\SYSTEM32\profext.dll[/FONT]
[FONT=&quot]LoadedModule[64]=C:\WINDOWS\SYSTEM32\ntmarta.dll[/FONT]
[FONT=&quot]LoadedModule[65]=C:\Windows\System32\Windows.Web.dll[/FONT]
[FONT=&quot]LoadedModule[66]=C:\Windows\System32\OneDriveSettingSyncProvider.dll[/FONT]
[FONT=&quot]LoadedModule[67]=C:\WINDOWS\system32\windowscodecs.dll[/FONT]
[FONT=&quot]LoadedModule[68]=C:\WINDOWS\System32\Speech_OneCore\Common\sapi_onecore.dll[/FONT]
[FONT=&quot]LoadedModule[69]=C:\WINDOWS\SYSTEM32\urlmon.dll[/FONT]
[FONT=&quot]LoadedModule[70]=C:\WINDOWS\SYSTEM32\WINHTTP.dll[/FONT]
[FONT=&quot]LoadedModule[71]=C:\WINDOWS\SYSTEM32\winmmbase.dll[/FONT]
[FONT=&quot]LoadedModule[72]=C:\WINDOWS\SYSTEM32\policymanager.dll[/FONT]
[FONT=&quot]LoadedModule[73]=C:\WINDOWS\system32\dataexchange.dll[/FONT]
[FONT=&quot]LoadedModule[74]=C:\WINDOWS\system32\d3d11.dll[/FONT]
[FONT=&quot]LoadedModule[75]=C:\WINDOWS\system32\dcomp.dll[/FONT]
[FONT=&quot]LoadedModule[76]=C:\WINDOWS\system32\dxgi.dll[/FONT]
[FONT=&quot]LoadedModule[77]=C:\Windows\System32\Windows.StateRepository.dll[/FONT]
[FONT=&quot]LoadedModule[78]=C:\Windows\System32\StateRepository.Core.dll[/FONT]
[FONT=&quot]LoadedModule[79]=C:\WINDOWS\system32\explorerframe.dll[/FONT]
[FONT=&quot]LoadedModule[80]=C:\Windows\System32\Windows.UI.dll[/FONT]
[FONT=&quot]LoadedModule[81]=C:\Windows\System32\thumbcache.dll[/FONT]
[FONT=&quot]LoadedModule[82]=C:\WINDOWS\SYSTEM32\edputil.dll[/FONT]
[FONT=&quot]LoadedModule[83]=C:\WINDOWS\SYSTEM32\tabbtn.dll[/FONT]
[FONT=&quot]LoadedModule[84]=C:\WINDOWS\System32\coml2.dll[/FONT]
[FONT=&quot]LoadedModule[85]=C:\Windows\System32\TabBtnEx.dll[/FONT]
[FONT=&quot]LoadedModule[86]=C:\Windows\System32\TwinUI.dll[/FONT]
[FONT=&quot]LoadedModule[87]=C:\Windows\System32\windows.immersiveshell.serviceprovider.dll[/FONT]
[FONT=&quot]LoadedModule[88]=C:\Windows\System32\uiautomationcore.dll[/FONT]
[FONT=&quot]LoadedModule[89]=C:\WINDOWS\SYSTEM32\sxs.dll[/FONT]
[FONT=&quot]LoadedModule[90]=C:\WINDOWS\SYSTEM32\WLDP.DLL[/FONT]
[FONT=&quot]LoadedModule[91]=C:\WINDOWS\System32\WINTRUST.dll[/FONT]
[FONT=&quot]LoadedModule[92]=C:\WINDOWS\SYSTEM32\WTSAPI32.dll[/FONT]
[FONT=&quot]LoadedModule[93]=C:\WINDOWS\SYSTEM32\SLC.dll[/FONT]
[FONT=&quot]LoadedModule[94]=C:\WINDOWS\SYSTEM32\sppc.dll[/FONT]
[FONT=&quot]LoadedModule[95]=C:\Windows\System32\taskschd.dll[/FONT]
[FONT=&quot]LoadedModule[96]=C:\Windows\System32\OneCoreCommonProxyStub.dll[/FONT]
[FONT=&quot]LoadedModule[97]=C:\WINDOWS\System32\twinui.appcore.dll[/FONT]
[FONT=&quot]LoadedModule[98]=C:\WINDOWS\system32\twinui.pcshell.dll[/FONT]
[FONT=&quot]LoadedModule[99]=C:\WINDOWS\system32\msvcp_win.dll[/FONT]
[FONT=&quot]LoadedModule[100]=C:\WINDOWS\SYSTEM32\PhotoMetadataHandler.dll[/FONT]
[FONT=&quot]LoadedModule[101]=C:\WINDOWS\System32\ApplicationFrame.dll[/FONT]
[FONT=&quot]LoadedModule[102]=C:\WINDOWS\System32\d2d1.dll[/FONT]
[FONT=&quot]LoadedModule[103]=C:\WINDOWS\SYSTEM32\CoreUIComponents.dll[/FONT]
[FONT=&quot]LoadedModule[104]=C:\WINDOWS\SYSTEM32\rmclient.dll[/FONT]
[FONT=&quot]LoadedModule[105]=C:\Windows\System32\Windows.UI.Immersive.dll[/FONT]
[FONT=&quot]LoadedModule[106]=C:\WINDOWS\System32\wpncore.dll[/FONT]
[FONT=&quot]LoadedModule[107]=C:\WINDOWS\System32\cdp.dll[/FONT]
[FONT=&quot]LoadedModule[108]=C:\WINDOWS\System32\winsqlite3.dll[/FONT]
[FONT=&quot]LoadedModule[109]=C:\WINDOWS\System32\WS2_32.dll[/FONT]
[FONT=&quot]LoadedModule[110]=C:\WINDOWS\System32\ncrypt.dll[/FONT]
[FONT=&quot]LoadedModule[111]=C:\WINDOWS\System32\IPHLPAPI.DLL[/FONT]
[FONT=&quot]LoadedModule[112]=C:\WINDOWS\System32\NTASN1.dll[/FONT]
[FONT=&quot]LoadedModule[113]=C:\WINDOWS\System32\CRYPTBASE.dll[/FONT]
[FONT=&quot]LoadedModule[114]=C:\WINDOWS\SYSTEM32\ntshrui.dll[/FONT]
[FONT=&quot]LoadedModule[115]=C:\WINDOWS\SYSTEM32\srvcli.dll[/FONT]
[FONT=&quot]LoadedModule[116]=C:\Windows\System32\NotificationController.dll[/FONT]
[FONT=&quot]LoadedModule[117]=C:\WINDOWS\SYSTEM32\cscapi.dll[/FONT]
[FONT=&quot]LoadedModule[118]=C:\WINDOWS\SYSTEM32\netutils.dll[/FONT]
[FONT=&quot]LoadedModule[119]=C:\Windows\System32\AboveLockAppHost.dll[/FONT]
[FONT=&quot]LoadedModule[120]=C:\WINDOWS\System32\wpnprv.dll[/FONT]
[FONT=&quot]LoadedModule[121]=C:\WINDOWS\System32\EventAggregation.dll[/FONT]
[FONT=&quot]LoadedModule[122]=C:\WINDOWS\System32\nlaapi.dll[/FONT]
[FONT=&quot]LoadedModule[123]=C:\WINDOWS\System32\npsm.dll[/FONT]
[FONT=&quot]LoadedModule[124]=C:\WINDOWS\System32\netprofm.dll[/FONT]
[FONT=&quot]LoadedModule[125]=C:\WINDOWS\system32\IconCodecService.dll[/FONT]
[FONT=&quot]LoadedModule[126]=C:\WINDOWS\System32\npmproxy.dll[/FONT]
[FONT=&quot]LoadedModule[127]=C:\WINDOWS\SYSTEM32\wkscli.dll[/FONT]
[FONT=&quot]LoadedModule[128]=C:\WINDOWS\SYSTEM32\LINKINFO.dll[/FONT]
[FONT=&quot]LoadedModule[129]=C:\WINDOWS\SYSTEM32\apphelp.dll[/FONT]
[FONT=&quot]LoadedModule[130]=C:\WINDOWS\SYSTEM32\MFPlat.DLL[/FONT]
[FONT=&quot]LoadedModule[131]=C:\WINDOWS\SYSTEM32\RTWorkQ.DLL[/FONT]
[FONT=&quot]LoadedModule[132]=C:\WINDOWS\SYSTEM32\resourcepolicyclient.dll[/FONT]
[FONT=&quot]LoadedModule[133]=C:\WINDOWS\System32\wlidprov.dll[/FONT]
[FONT=&quot]LoadedModule[134]=C:\Windows\System32\Windows.Networking.Connectivity.dll[/FONT]
[FONT=&quot]LoadedModule[135]=C:\WINDOWS\SYSTEM32\NInput.dll[/FONT]
[FONT=&quot]LoadedModule[136]=C:\Windows\System32\NotificationControllerPS.dll[/FONT]
[FONT=&quot]LoadedModule[137]=C:\WINDOWS\system32\execmodelproxy.dll[/FONT]
[FONT=&quot]LoadedModule[138]=C:\WINDOWS\SYSTEM32\igd10iumd64.dll[/FONT]
[FONT=&quot]LoadedModule[139]=C:\WINDOWS\SYSTEM32\daxexec.dll[/FONT]
[FONT=&quot]LoadedModule[140]=C:\WINDOWS\System32\FLTLIB.DLL[/FONT]
[FONT=&quot]LoadedModule[141]=C:\WINDOWS\System32\container.dll[/FONT]
[FONT=&quot]LoadedModule[142]=C:\WINDOWS\SYSTEM32\igdusc64.dll[/FONT]
[FONT=&quot]LoadedModule[143]=C:\WINDOWS\System32\UIAnimation.dll[/FONT]
[FONT=&quot]LoadedModule[144]=C:\Program Files (x86)\Google\Drive\googledrivesync64.dll[/FONT]
[FONT=&quot]LoadedModule[145]=C:\WINDOWS\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_08e394a1a83e212f\MSVCP90.dll[/FONT]
[FONT=&quot]LoadedModule[146]=C:\WINDOWS\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_08e394a1a83e212f\MSVCR90.dll[/FONT]
[FONT=&quot]LoadedModule[147]=C:\WINDOWS\SYSTEM32\dsreg.dll[/FONT]
[FONT=&quot]LoadedModule[148]=C:\WINDOWS\SYSTEM32\DPAPI.DLL[/FONT]
[FONT=&quot]LoadedModule[149]=C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\FileSyncShell64.dll[/FONT]
[FONT=&quot]LoadedModule[150]=C:\WINDOWS\SYSTEM32\WININET.dll[/FONT]
[FONT=&quot]LoadedModule[151]=C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\LoggingPlatform64.DLL[/FONT]
[FONT=&quot]LoadedModule[152]=C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\MSVCR120.dll[/FONT]
[FONT=&quot]LoadedModule[153]=C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\MSVCP120.dll[/FONT]
[FONT=&quot]LoadedModule[154]=C:\WINDOWS\SYSTEM32\VERSION.dll[/FONT]
[FONT=&quot]LoadedModule[155]=C:\WINDOWS\SYSTEM32\WSOCK32.dll[/FONT]
[FONT=&quot]LoadedModule[156]=C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\ClientTelemetry.dll[/FONT]
[FONT=&quot]LoadedModule[157]=C:\WINDOWS\System32\NSI.dll[/FONT]
[FONT=&quot]LoadedModule[158]=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL[/FONT]
[FONT=&quot]LoadedModule[159]=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\ATL100.DLL[/FONT]
[FONT=&quot]LoadedModule[160]=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\MSVCR100.dll[/FONT]
[FONT=&quot]LoadedModule[161]=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\MSVCP100.dll[/FONT]
[FONT=&quot]LoadedModule[162]=C:\WINDOWS\SYSTEM32\wlanapi.dll[/FONT]
[FONT=&quot]LoadedModule[163]=C:\WINDOWS\System32\NotificationObjFactory.dll[/FONT]
[FONT=&quot]LoadedModule[164]=C:\WINDOWS\SYSTEM32\msi.dll[/FONT]
[FONT=&quot]LoadedModule[165]=C:\Windows\System32\wcmapi.dll[/FONT]
[FONT=&quot]LoadedModule[166]=C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll[/FONT]
[FONT=&quot]LoadedModule[167]=C:\WINDOWS\SYSTEM32\webio.dll[/FONT]
[FONT=&quot]LoadedModule[168]=C:\WINDOWS\system32\mswsock.dll[/FONT]
[FONT=&quot]LoadedModule[169]=C:\WINDOWS\SYSTEM32\WINNSI.DLL[/FONT]
[FONT=&quot]LoadedModule[170]=C:\WINDOWS\SYSTEM32\DNSAPI.dll[/FONT]
[FONT=&quot]LoadedModule[171]=C:\Program Files\Bonjour\mdnsNSP.dll[/FONT]
[FONT=&quot]LoadedModule[172]=C:\Windows\System32\rasadhlp.dll[/FONT]
[FONT=&quot]LoadedModule[173]=C:\Windows\System32\msxml6.dll[/FONT]
[FONT=&quot]LoadedModule[174]=C:\WINDOWS\SYSTEM32\D3D10Warp.dll[/FONT]
[FONT=&quot]LoadedModule[175]=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll[/FONT]
[FONT=&quot]LoadedModule[176]=C:\WINDOWS\System32\fwpuclnt.dll[/FONT]
[FONT=&quot]LoadedModule[177]=C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll[/FONT]
[FONT=&quot]LoadedModule[178]=C:\WINDOWS\system32\mssprxy.dll[/FONT]
[FONT=&quot]LoadedModule[179]=C:\WINDOWS\system32\schannel.DLL[/FONT]
[FONT=&quot]LoadedModule[180]=C:\WINDOWS\SYSTEM32\mskeyprotect.dll[/FONT]
[FONT=&quot]LoadedModule[181]=C:\WINDOWS\system32\ncryptsslp.dll[/FONT]
[FONT=&quot]LoadedModule[182]=C:\WINDOWS\system32\rsaenh.dll[/FONT]
[FONT=&quot]LoadedModule[183]=C:\WINDOWS\SYSTEM32\settingsyncpolicy.dll[/FONT]
[FONT=&quot]LoadedModule[184]=C:\WINDOWS\system32\stobject.dll[/FONT]
[FONT=&quot]LoadedModule[185]=C:\WINDOWS\system32\WMICLNT.dll[/FONT]
[FONT=&quot]LoadedModule[186]=C:\Windows\System32\InputSwitch.dll[/FONT]
[FONT=&quot]LoadedModule[187]=C:\WINDOWS\system32\BatMeter.dll[/FONT]
[FONT=&quot]LoadedModule[188]=C:\WINDOWS\System32\SETUPAPI.dll[/FONT]
[FONT=&quot]LoadedModule[189]=C:\WINDOWS\System32\Windows.UI.Shell.dll[/FONT]
[FONT=&quot]LoadedModule[190]=C:\WINDOWS\System32\wincorlib.DLL[/FONT]
[FONT=&quot]LoadedModule[191]=C:\WINDOWS\system32\es.dll[/FONT]
[FONT=&quot]LoadedModule[192]=C:\WINDOWS\system32\prnfldr.dll[/FONT]
[FONT=&quot]LoadedModule[193]=C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll[/FONT]
[FONT=&quot]LoadedModule[194]=C:\WINDOWS\system32\ntoskrnl.exe[/FONT]
[FONT=&quot]LoadedModule[195]=C:\WINDOWS\SYSTEM32\atlthunk.dll[/FONT]
[FONT=&quot]LoadedModule[196]=C:\WINDOWS\System32\shacct.dll[/FONT]
[FONT=&quot]LoadedModule[197]=C:\WINDOWS\System32\Actioncenter.dll[/FONT]
[FONT=&quot]LoadedModule[198]=C:\WINDOWS\System32\wevtapi.dll[/FONT]
[FONT=&quot]LoadedModule[199]=C:\WINDOWS\system32\dxp.dll[/FONT]
[FONT=&quot]LoadedModule[200]=C:\WINDOWS\system32\SHDOCVW.dll[/FONT]
[FONT=&quot]LoadedModule[201]=C:\WINDOWS\SYSTEM32\msiltcfg.dll[/FONT]
[FONT=&quot]LoadedModule[202]=C:\WINDOWS\system32\Syncreg.dll[/FONT]
[FONT=&quot]LoadedModule[203]=C:\WINDOWS\SYSTEM32\AUDIOSES.DLL[/FONT]
[FONT=&quot]LoadedModule[204]=C:\WINDOWS\System32\pnidui.dll[/FONT]
[FONT=&quot]LoadedModule[205]=C:\WINDOWS\system32\wpdshserviceobj.dll[/FONT]
[FONT=&quot]LoadedModule[206]=C:\WINDOWS\SYSTEM32\DWrite.dll[/FONT]
[FONT=&quot]LoadedModule[207]=C:\Windows\System32\NetworkUXBroker.dll[/FONT]
[FONT=&quot]LoadedModule[208]=C:\Windows\System32\PortableDeviceTypes.dll[/FONT]
[FONT=&quot]LoadedModule[209]=C:\Windows\System32\WlanMediaManager.dll[/FONT]
[FONT=&quot]LoadedModule[210]=C:\Windows\System32\EthernetMediaManager.dll[/FONT]
[FONT=&quot]LoadedModule[211]=C:\Windows\System32\Windows.Globalization.dll[/FONT]
[FONT=&quot]LoadedModule[212]=C:\Windows\System32\PortableDeviceApi.dll[/FONT]
[FONT=&quot]LoadedModule[213]=C:\Windows\System32\bthprops.cpl[/FONT]
[FONT=&quot]LoadedModule[214]=C:\Windows\System32\TetheringStation.dll[/FONT]
[FONT=&quot]LoadedModule[215]=C:\Windows\System32\BluetoothApis.dll[/FONT]
[FONT=&quot]LoadedModule[216]=C:\WINDOWS\system32\SettingMonitor.dll[/FONT]
[FONT=&quot]LoadedModule[217]=C:\WINDOWS\System32\imagehlp.dll[/FONT]
[FONT=&quot]LoadedModule[218]=C:\WINDOWS\system32\PackageStateRoaming.dll[/FONT]
[FONT=&quot]LoadedModule[219]=C:\Windows\System32\ieframe.dll[/FONT]
[FONT=&quot]LoadedModule[220]=C:\Windows\System32\NETAPI32.dll[/FONT]
[FONT=&quot]LoadedModule[221]=C:\WINDOWS\SYSTEM32\dhcpcsvc6.DLL[/FONT]
[FONT=&quot]LoadedModule[222]=C:\WINDOWS\SYSTEM32\dhcpcsvc.DLL[/FONT]
[FONT=&quot]LoadedModule[223]=C:\WINDOWS\System32\srchadmin.dll[/FONT]
[FONT=&quot]LoadedModule[224]=C:\Windows\System32\VaultRoaming.dll[/FONT]
[FONT=&quot]LoadedModule[225]=C:\WINDOWS\System32\SyncCenter.dll[/FONT]
[FONT=&quot]LoadedModule[226]=C:\WINDOWS\SYSTEM32\msauserext.dll[/FONT]
[FONT=&quot]LoadedModule[227]=C:\Windows\System32\imapi2.dll[/FONT]
[FONT=&quot]LoadedModule[228]=C:\WINDOWS\SYSTEM32\AuthBroker.dll[/FONT]
[FONT=&quot]LoadedModule[229]=C:\WINDOWS\System32\hgcpl.dll[/FONT]
[FONT=&quot]LoadedModule[230]=C:\WINDOWS\System32\DUser.dll[/FONT]
[FONT=&quot]LoadedModule[231]=C:\WINDOWS\System32\provsvc.dll[/FONT]
[FONT=&quot]LoadedModule[232]=C:\Windows\System32\WiFiProfilesSettingHandler.dll[/FONT]
[FONT=&quot]LoadedModule[233]=C:\Windows\System32\eappcfg.dll[/FONT]
[FONT=&quot]LoadedModule[234]=C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.51_none_7bd61ed3ff8affee\gdiplus.dll[/FONT]
[FONT=&quot]LoadedModule[235]=C:\WINDOWS\system32\SettingSync.dll[/FONT]
[FONT=&quot]LoadedModule[236]=C:\Windows\System32\Windows.System.Launcher.dll[/FONT]
[FONT=&quot]LoadedModule[237]=C:\Windows\System32\WpPortingLibrary.dll[/FONT]
[FONT=&quot]LoadedModule[238]=C:\Windows\System32\dsclient.dll[/FONT]
[FONT=&quot]LoadedModule[239]=C:\WINDOWS\SYSTEM32\Secur32.dll[/FONT]
[FONT=&quot]LoadedModule[240]=C:\WINDOWS\SYSTEM32\MLANG.dll[/FONT]
[FONT=&quot]LoadedModule[241]=C:\WINDOWS\system32\keepaliveprovider.dll[/FONT]
[FONT=&quot]LoadedModule[242]=C:\WINDOWS\SYSTEM32\HID.DLL[/FONT]
[FONT=&quot]LoadedModule[243]=C:\WINDOWS\system32\BrowserSettingSync.dll[/FONT]
[FONT=&quot]LoadedModule[244]=C:\WINDOWS\System32\wscinterop.dll[/FONT]
[FONT=&quot]LoadedModule[245]=C:\WINDOWS\System32\WSCAPI.dll[/FONT]
[FONT=&quot]LoadedModule[246]=C:\WINDOWS\System32\wscui.cpl[/FONT]
[FONT=&quot]LoadedModule[247]=C:\WINDOWS\System32\werconcpl.dll[/FONT]
[FONT=&quot]LoadedModule[248]=C:\WINDOWS\System32\framedynos.dll[/FONT]
[FONT=&quot]LoadedModule[249]=C:\WINDOWS\System32\wer.dll[/FONT]
[FONT=&quot]LoadedModule[250]=C:\WINDOWS\System32\hcproviders.dll[/FONT]
[FONT=&quot]LoadedModule[251]=C:\Windows\System32\ieproxy.dll[/FONT]
[FONT=&quot]LoadedModule[252]=C:\Windows\System32\wpnapps.dll[/FONT]
[FONT=&quot]LoadedModule[253]=C:\WINDOWS\SYSTEM32\usermgrcli.dll[/FONT]
[FONT=&quot]LoadedModule[254]=C:\WINDOWS\System32\TimeBrokerClient.dll[/FONT]
[FONT=&quot]LoadedModule[255]=C:\WINDOWS\system32\Windows.Storage.Search.dll[/FONT]
[FONT=&quot]LoadedModule[256]=C:\WINDOWS\System32\StructuredQuery.dll[/FONT]
[FONT=&quot]LoadedModule[257]=C:\Windows\System32\dlnashext.dll[/FONT]
[FONT=&quot]LoadedModule[258]=C:\Windows\System32\PlayToDevice.dll[/FONT]
[FONT=&quot]LoadedModule[259]=C:\WINDOWS\SYSTEM32\MPR.dll[/FONT]
[FONT=&quot]LoadedModule[260]=C:\WINDOWS\System32\drprov.dll[/FONT]
[FONT=&quot]LoadedModule[261]=C:\WINDOWS\System32\ntlanman.dll[/FONT]
[FONT=&quot]LoadedModule[262]=C:\WINDOWS\System32\davclnt.dll[/FONT]
[FONT=&quot]LoadedModule[263]=C:\WINDOWS\System32\DAVHLPR.dll[/FONT]
[FONT=&quot]LoadedModule[264]=c:\PROGRA~1\mcafee\mqs\shredext.dll[/FONT]
[FONT=&quot]LoadedModule[265]=C:\WINDOWS\SYSTEM32\MSIMG32.dll[/FONT]
[FONT=&quot]LoadedModule[266]=C:\Program Files\Common Files\McAfee\Platform\McRtMui.dll[/FONT]
[FONT=&quot]LoadedModule[267]=C:\Program Files\Common Files\McAfee\Platform\LangSel.dll[/FONT]
[FONT=&quot]LoadedModule[268]=C:\WINDOWS\System32\msxml3.dll[/FONT]
[FONT=&quot]LoadedModule[269]=c:\PROGRA~1\mcafee\mqs\shrcore.dll[/FONT]
[FONT=&quot]LoadedModule[270]=c:\PROGRA~1\COMMON~1\mcafee\platform\core\mccoreps.dll[/FONT]
[FONT=&quot]LoadedModule[271]=C:\Program Files\Common Files\McAfee\SystemCore\mfevtpa.dll[/FONT]
[FONT=&quot]LoadedModule[272]=C:\WINDOWS\System32\PSAPI.DLL[/FONT]
[FONT=&quot]LoadedModule[273]=C:\WINDOWS\SYSTEM32\sfc.dll[/FONT]
[FONT=&quot]LoadedModule[274]=C:\WINDOWS\SYSTEM32\sfc_os.DLL[/FONT]
[FONT=&quot]LoadedModule[275]=C:\Program Files\Common Files\McAfee\SystemCore\mfehida.dll[/FONT]
[FONT=&quot]LoadedModule[276]=C:\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll[/FONT]
[FONT=&quot]LoadedModule[277]=c:\PROGRA~1\mcafee\mqs\shredshm.dll[/FONT]
[FONT=&quot]LoadedModule[278]=C:\WINDOWS\System32\MSWB7.dll[/FONT]
[FONT=&quot]LoadedModule[279]=C:\WINDOWS\system32\DUI70.dll[/FONT]
[FONT=&quot]LoadedModule[280]=C:\WINDOWS\SYSTEM32\globinputhost.dll[/FONT]
[FONT=&quot]LoadedModule[281]=C:\WINDOWS\SYSTEM32\UIRibbonRes.dll[/FONT]
[FONT=&quot]LoadedModule[282]=C:\WINDOWS\system32\NetworkExplorer.dll[/FONT]
[FONT=&quot]LoadedModule[283]=C:\WINDOWS\system32\NetworkItemFactory.dll[/FONT]
[FONT=&quot]LoadedModule[284]=C:\WINDOWS\system32\dtsh.dll[/FONT]
[FONT=&quot]LoadedModule[285]=C:\WINDOWS\system32\FirewallAPI.dll[/FONT]
[FONT=&quot]LoadedModule[286]=C:\WINDOWS\system32\fwbase.dll[/FONT]
[FONT=&quot]LoadedModule[287]=C:\WINDOWS\system32\wbem\wbemprox.dll[/FONT]
[FONT=&quot]LoadedModule[288]=C:\WINDOWS\SYSTEM32\wbemcomn.dll[/FONT]
[FONT=&quot]LoadedModule[289]=C:\WINDOWS\system32\wbem\wbemsvc.dll[/FONT]
[FONT=&quot]LoadedModule[290]=C:\WINDOWS\system32\wbem\fastprox.dll[/FONT]
[FONT=&quot]LoadedModule[291]=C:\WINDOWS\system32\FWPolicyIOMgr.dll[/FONT]
[FONT=&quot]LoadedModule[292]=C:\Windows\System32\FunDisc.dll[/FONT]
[FONT=&quot]LoadedModule[293]=C:\Windows\System32\fdproxy.dll[/FONT]
[FONT=&quot]LoadedModule[294]=C:\WINDOWS\System32\fdwcn.dll[/FONT]
[FONT=&quot]LoadedModule[295]=C:\WINDOWS\System32\wcnapi.dll[/FONT]
[FONT=&quot]LoadedModule[296]=C:\Windows\System32\fdWNet.dll[/FONT]
[FONT=&quot]LoadedModule[297]=C:\Windows\System32\ATL.DLL[/FONT]
[FONT=&quot]LoadedModule[298]=C:\WINDOWS\System32\dfscli.dll[/FONT]
[FONT=&quot]LoadedModule[299]=C:\WINDOWS\SYSTEM32\browcli.dll[/FONT]
[FONT=&quot]LoadedModule[300]=C:\WINDOWS\system32\WINMM.dll[/FONT]
[FONT=&quot]LoadedModule[301]=C:\Program Files\WinRAR\rarext.dll[/FONT]
[FONT=&quot]LoadedModule[302]=c:\PROGRA~1\mcafee\msc\MCCTXM~1.DLL[/FONT]
[FONT=&quot]LoadedModule[303]=c:\PROGRA~1\mcafee\VIRUSS~1\mcctxmnu.dll[/FONT]
[FONT=&quot]LoadedModule[304]=C:\WINDOWS\system32\syncui.dll[/FONT]
[FONT=&quot]LoadedModule[305]=C:\WINDOWS\system32\SYNCENG.dll[/FONT]
[FONT=&quot]LoadedModule[306]=C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat Elements\ContextMenuShim64.dll[/FONT]
[FONT=&quot]LoadedModule[307]=C:\WINDOWS\System32\COMDLG32.dll[/FONT]
[FONT=&quot]LoadedModule[308]=C:\WINDOWS\SYSTEM32\WINSPOOL.DRV[/FONT]
[FONT=&quot]LoadedModule[309]=C:\WINDOWS\system32\twext.dll[/FONT]
[FONT=&quot]LoadedModule[310]=C:\Windows\System32\WorkfoldersShell.dll[/FONT]
[FONT=&quot]LoadedModule[311]=C:\Program Files (x86)\TechSmith\Snagit 12\DLLx64\SnagitShellExt64.dll[/FONT]
[FONT=&quot]LoadedModule[312]=C:\WINDOWS\system32\tquery.dll[/FONT]
[FONT=&quot]LoadedModule[313]=C:\Program Files (x86)\TechSmith\Snagit 12\SnagItShellExtRes.dll[/FONT]
[FONT=&quot]LoadedModule[314]=C:\Program Files (x86)\Google\Drive\contextmenu64.dll[/FONT]
[FONT=&quot]LoadedModule[315]=C:\WINDOWS\WinSxS\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.6161_none_0a1fd3a3a768b895\ATL90.DLL[/FONT]
[FONT=&quot]LoadedModule[316]=C:\Program Files\Windows Defender\shellext.dll[/FONT]
[FONT=&quot]LoadedModule[317]=C:\Program Files\Windows Defender\mpclient.dll[/FONT]
[FONT=&quot]LoadedModule[318]=C:\WINDOWS\SYSTEM32\gpapi.dll[/FONT]
[FONT=&quot]LoadedModule[319]=C:\Program Files\7-Zip\7-zip.dll[/FONT]
[FONT=&quot]LoadedModule[320]=C:\WINDOWS\SYSTEM32\MsftEdit.dll[/FONT]
[FONT=&quot]LoadedModule[321]=C:\WINDOWS\system32\UIRibbon.dll[/FONT]
[FONT=&quot]LoadedModule[322]=C:\WINDOWS\SYSTEM32\samcli.dll[/FONT]
[FONT=&quot]LoadedModule[323]=C:\Windows\System32\playtomenu.dll[/FONT]
[FONT=&quot]State[0].Key=Transport.DoneStage1[/FONT]
[FONT=&quot]State[0].Value=1[/FONT]
[FONT=&quot]FriendlyEventName=Stopped working[/FONT]
[FONT=&quot]ConsentKey=APPCRASH[/FONT]
[FONT=&quot]AppName=Windows Explorer[/FONT]
[FONT=&quot]AppPath=C:\WINDOWS\explorer.exe[/FONT]
[FONT=&quot]NsPartner=windows[/FONT]
[FONT=&quot]NsGroup=windows8[/FONT]
[FONT=&quot]ApplicationIdentity=CFB41A6B3B478DC7A319DC7209D31C8B[/FONT]
[FONT=&quot]MetadataHash=-1552193256[/FONT]
 
Re: Windows Explorer crashes when drag-and-dropping files

Where did you get all this information?

I see loaded modules for windows defender and mcafee antivirus.
Maybe you have both programs enabled...
What did you do before this problem? Have you updated windows?
(After windows update anniversary, I had to remove ashampoo antivirus because windows defender insisted to be activated, that pest! :-))
 
Yes, I disabled all the non-Windows Shell Extensions and that didn't help it either.

I don't get a BSOD, the screen flashes and Windows Explorer crashes, but everything else stays the same
 
Yes, I disabled all the non-Windows Shell Extensions and that didn't help it either.

I don't get a BSOD, the screen flashes and Windows Explorer crashes, but everything else stays the same

it is a crahes and a wer-report is generated, however not very useful to examine.

create a .reg-file from this
Code:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\Explorer.exe]
"DumpFolder"=hex(2):43,00,3a,00,5c,00,4c,00,6f,00,63,00,61,00,6c,00,44,00,75,\
  00,6d,00,70,00,73,00,00,00
"DumpType"=dword:00000002

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe]
"GlobalFlag"=dword:02000100
"PageHeapFlags"=dword:00000003

add it per right-klick to your registry.
Next time the explorer crashes it will / should produce a nice dumpfile which can be inspected, although it might be difficult to track down (Userdump).

The resulting dump will be found in c:\localdumps
thats what we would like to see.

regards
Michael
 
Yes, I disabled all the non-Windows Shell Extensions and that didn't help it either.

I don't get a BSOD, the screen flashes and Windows Explorer crashes, but everything else stays the same

it is a crahes and a wer-report is generated, however not very useful to examine.

create a .reg-file from this
Code:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\Explorer.exe]
"DumpFolder"=hex(2):43,00,3a,00,5c,00,4c,00,6f,00,63,00,61,00,6c,00,44,00,75,\
  00,6d,00,70,00,73,00,00,00
"DumpType"=dword:00000002

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe]
"GlobalFlag"=dword:02000100
"PageHeapFlags"=dword:00000003

add it per right-klick to your registry.
Next time the explorer crashes it will / should produce a nice dumpfile which can be inspected, although it might be difficult to track down (Userdump).

The resulting dump will be found in c:\localdumps
thats what we would like to see.

regards
Michael

Thank you kindly.

I have done as you asked.

I tried to attach the dump file to this message, but it wasn't allowing me to attache. Is that due to file size or do I need to rename it to a different filetype?

In the meantime I put the file here to download

Dropbox - explorer.exe.14328.dmp
 
thx.
downloading and dropbox seems to have a bad day / heavy load today, suggested time 2 hours via a 50K line ... thats heavy ;-)
 
Howdie...

Code:
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(37f8.14f8): Unknown exception - code c0000374 (first/second chance not available)
ntdll!NtWaitForMultipleObjects+0x14:
00007ffa`de1859a4 c3              ret
0:018> dumpchk
Couldn't resolve error at 'mpchk'
0:018> .ecxr
rax=0000000000000000 rbx=00000000c0000374 rcx=0000000000000003
rdx=00007ffade126fe4 rsi=0000000000000001 rdi=00007ffade22f6b0
rip=00007ffade1d73f3 rsp=000000000721ebc0 rbp=0000000000000000
 r8=0000000000000001  r9=0000000013d64eb0 r10=0000000000000000
r11=0000000100000000 r12=0000000013e4d900 r13=0000000000000000
r14=0000000000000000 r15=0000000000000001
iopl=0         nv up ei pl nz na pe nc
cs=0033  ss=002b  ds=002b  es=002b  fs=0053  gs=002b             efl=00000202
ntdll!RtlReportCriticalFailure+0x97:
00007ffa`de1d73f3 eb00            jmp     ntdll!RtlReportCriticalFailure+0x99 (00007ffa`de1d73f5)

the message, ntdll reports an failure, who else...
however, that looks like an Double Fault within User-Environement?
Code:
 # RetAddr           : Args to Child                                                           : Call Site
00 00007ffa`de1d7d4a : 29d89796`8500e4ff 00007ffa`de22f6b0 00000000`00b60000 00000000`13f0bd18 : ntdll!RtlReportCriticalFailure+0x97
01 00007ffa`de18491a : 00000000`00b60000 00000000`00000000 00000000`13f0bd18 00000000`1369a100 : ntdll!RtlpHeapHandleError+0x12
02 00007ffa`de19c840 : 00000000`00000000 446d16b1`0000000e 0000b6c7`9a5c6727 00000064`8c783da4 : ntdll!RtlpLogHeapFailure+0x96
03 00007ffa`c2beab9e : 00000000`80030002 00000000`0721eec0 00000000`00000000 00007ffa`de1174a8 : ntdll!RtlFreeHeap+0x80730
04 00007ffa`c2beaca1 : 00008c1b`db8b90e2 00000000`00b60000 00000000`13e4d968 00007ffa`dafb4b0d : thumbcache!CThumbnailCache::_GetThumbnailInternal+0x24e
05 00007ffa`c2be8a91 : ffffffff`fffffffe 00000000`13d05590 00000000`00000000 00007ffa`daf5dc4e : thumbcache!CThumbnailCache::GetThumbnailPrivate+0x91
06 00007ffa`c2be8d0f : 00000000`80004005 00000000`0721f1c0 00000000`13d05590 00000000`00000000 : thumbcache!CThumbnailCacheAPI::GetThumbnailPrivate+0xd1
07 00007ffa`daf7cf0a : 00000000`13d05590 00000000`0721f089 00000000`13f08e30 00000000`13edf650 : thumbcache!CThumbnailCacheAPI::GetThumbnail+0x2f
08 00007ffa`daf7d0ae : 00000000`13edf650 00000000`0721f140 00000000`00000201 00007ffa`daf7d6da : windows_storage!CSetOperationCallback::_LookupThumbnail+0x132
09 00007ffa`daf7d1ef : 00000000`1219fca0 00007ffa`db5f7c70 00000000`136d5d50 00000000`136d5d50 : windows_storage!CSetOperationCallback::_PrefetchCachedThumbnails+0x122
0a 00007ffa`daf6e270 : 00000000`13b17e90 00000000`13b17de0 00000000`13b17e48 00000000`136d5d50 : windows_storage!CSetOperationCallback::OnNextBatch+0x8f
0b 00007ffa`daf6d278 : 00000000`13b17de0 00000000`0721f330 00000000`00000000 00000000`13b17de0 : windows_storage!CEnumTask::_PushBatchToView+0xb8
0c 00007ffa`daf6b907 : 00000000`04fcc280 00000000`13b17de0 00000000`00000000 00000000`00000000 : windows_storage!CEnumTask::InternalResumeRT+0x178
0d 00007ffa`daf6cd39 : 00000000`000037f8 00000000`13edf9b0 00000000`00000000 00000000`00000009 : windows_storage!CRunnableTask::Run+0xe7
0e 00007ffa`daf6baa8 : 00000000`13f31da0 00000000`0721f450 00000000`13edf9b0 00007ffa`db5c0000 : windows_storage!CShellTask::TT_Run+0x89
0f 00007ffa`daf6e90f : 00000000`13f31da0 00000000`13f31da0 00000000`00000000 00000000`00000000 : windows_storage!CShellTaskThread::ThreadProc+0xd0
10 00007ffa`db5f7c86 : 00007ffa`db5c0000 00000000`00000000 00008c1b`db8b8aa2 00000000`00b60b60 : windows_storage!CShellTaskThread::s_ThreadProc+0x2f
11 00007ffa`de12d9f9 : 00000000`13a161d0 00000000`00b60b60 00000000`00b6ab80 00000000`00000018 : SHCore!ExecuteWorkItemThreadProc+0x16
12 00007ffa`de112caa : 00000001`00010001 00000000`00000000 00000000`00b60b60 00000000`00000001 : ntdll!RtlpTpWorkCallback+0x129
13 00007ffa`db738364 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!TppWorkerThread+0x4aa
14 00007ffa`de145e91 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x14
15 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x21

the real things are going on within thumbcache, seems so?

as not so foolproofed in Userdumps, a candidate causing this might be
Snagit which was active at this period, can you acknowledge?

i would not like to blame McAfee, although might be but its too far from the point of failure.

The Message was: ERROR_CODE: (NTSTATUS) 0xc0000374 - A Heap was damaged.
ACTIONABLE_HEAP_CORRUPTION_heap_failure_invalid_argument_BIASED_HEAP_BLOCK_thumbcache!CThumbnailCache::_GetThumbnailInternal+24e


if anyone has a more precise idea, lets hear from u..
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top