Hi BD. . .
If you wish to upload the dump (be sure to zip it), I'll be glad to take a look at it, but fear it is a user-mode dump and will contain information like:
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(115cd0.115f20): Access violation - code c0000005
In fact, the info you provided from your last post does contain a 0xc5 exception code (which translates to "memory access violation" -
Code:
Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4
Faulting module name: msutb.dll, version: 6.1.7600.16385, time stamp: 0x4a5bdfba
Exception code: 0xc0000005
The faulting module named -
msutb.dll has a version number of 6.1.7600 on it, which tells us that it is a Windows 7 Microsoft driver. The chances that something is wrong with this module is next to zero.
You can also look in "WER" - Windows Error Reporting for crash info, located -
- C:\Users\<username>\AppData\Local\Microsoft\Windows\WER\ReportArchive
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive
Look for folders that contain the word "Explorer"; then files named "Report.wer"
Here is a "Report.wer" for an Explorer crash on my system -
Code:
Version=1
EventType=APPCRASH
EventTime=130556688343609523
ReportType=2
Consent=1
UploadTime=130826993058447713
ReportFlags=524288
ReportIdentifier=05238ec1-4091-11e4-8272-a01d48c2bd4c
IntegratorReportIdentifier=05238ec0-4091-11e4-8272-a01d48c2bd4c
NsAppName=Explorer.EXE
Response.BucketId=1bd5447ef5b399740a9f41edaf77f212
Response.BucketTable=4
Response.LegacyBucketId=85956908666
Response.type=4
Sig[0].Name=Application Name
Sig[0].Value=Explorer.EXE
Sig[1].Name=Application Version
Sig[1].Value=6.3.9600.17284
Sig[2].Name=Application Timestamp
Sig[2].Value=53f816dc
Sig[3].Name=Fault Module Name
Sig[3].Value=SHELL32.dll
Sig[4].Name=Fault Module Version
Sig[4].Value=6.3.9600.17238
Sig[5].Name=Fault Module Timestamp
Sig[5].Value=53d0c68a
Sig[6].Name=Exception Code
Sig[6].Value=c0000005
Sig[7].Name=Exception Offset
Sig[7].Value=0000000000070dc5
DynamicSig[1].Name=OS Version
DynamicSig[1].Value=6.3.9600.2.0.0.768.101
DynamicSig[2].Name=Locale ID
DynamicSig[2].Value=1033
DynamicSig[22].Name=Additional Information 1
DynamicSig[22].Value=3e17
DynamicSig[23].Name=Additional Information 2
DynamicSig[23].Value=3e179755734daace86fa3c8a1f47dbd1
DynamicSig[24].Name=Additional Information 3
DynamicSig[24].Value=43db
DynamicSig[25].Name=Additional Information 4
DynamicSig[25].Value=43dbcfdf8ba64123edc76bb3d6888be7
UI[2]=C:\Windows\Explorer.EXE
LoadedModule[0]=C:\Windows\Explorer.EXE
LoadedModule[1]=C:\Windows\SYSTEM32\ntdll.dll
LoadedModule[2]=C:\Windows\system32\KERNEL32.DLL
LoadedModule[3]=C:\Windows\system32\KERNELBASE.dll
LoadedModule[4]=C:\Windows\system32\apphelp.dll
LoadedModule[5]=C:\Windows\system32\msvcrt.dll
LoadedModule[6]=C:\Windows\system32\OLEAUT32.dll
LoadedModule[7]=C:\Windows\SYSTEM32\combase.dll
LoadedModule[8]=C:\Windows\SYSTEM32\powrprof.dll
LoadedModule[9]=C:\Windows\SYSTEM32\advapi32.dll
LoadedModule[10]=C:\Windows\system32\USER32.dll
LoadedModule[11]=C:\Windows\system32\GDI32.dll
LoadedModule[12]=C:\Windows\SYSTEM32\SHCORE.dll
LoadedModule[13]=C:\Windows\system32\SHLWAPI.dll
LoadedModule[14]=C:\Windows\system32\SHELL32.dll
LoadedModule[15]=C:\Windows\SYSTEM32\UxTheme.dll
LoadedModule[16]=C:\Windows\SYSTEM32\dwmapi.dll
LoadedModule[17]=C:\Windows\SYSTEM32\TWINAPI.dll
LoadedModule[18]=C:\Windows\SYSTEM32\d3d11.dll
LoadedModule[19]=C:\Windows\SYSTEM32\dcomp.dll
LoadedModule[20]=C:\Windows\SYSTEM32\SspiCli.dll
LoadedModule[21]=C:\Windows\SYSTEM32\sechost.dll
LoadedModule[22]=C:\Windows\SYSTEM32\USERENV.dll
LoadedModule[23]=C:\Windows\SYSTEM32\PROPSYS.dll
LoadedModule[24]=C:\Windows\system32\RPCRT4.dll
LoadedModule[25]=C:\Windows\SYSTEM32\SLC.dll
LoadedModule[26]=C:\Windows\SYSTEM32\profapi.dll
LoadedModule[27]=C:\Windows\SYSTEM32\dxgi.dll
LoadedModule[28]=C:\Windows\SYSTEM32\sppc.dll
LoadedModule[29]=C:\Windows\system32\IMM32.DLL
LoadedModule[30]=C:\Windows\system32\MSCTF.dll
LoadedModule[31]=C:\Windows\SYSTEM32\kernel.appcore.dll
LoadedModule[32]=C:\Windows\SYSTEM32\CRYPTBASE.dll
LoadedModule[33]=C:\Windows\SYSTEM32\bcryptPrimitives.dll
LoadedModule[34]=C:\Windows\system32\ole32.dll
LoadedModule[35]=C:\Windows\SYSTEM32\clbcatq.dll
LoadedModule[36]=C:\Windows\SYSTEM32\WINSTA.dll
LoadedModule[37]=C:\Windows\SYSTEM32\Bcp47Langs.dll
LoadedModule[38]=C:\Windows\System32\IDStore.dll
LoadedModule[39]=C:\Windows\System32\SAMLIB.dll
LoadedModule[40]=C:\Windows\SYSTEM32\SETTINGSYNCPOLICY.dll
LoadedModule[41]=C:\Windows\SYSTEM32\DUI70.dll
LoadedModule[42]=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1\Comctl32.dll
LoadedModule[43]=C:\Windows\SYSTEM32\DUser.dll
LoadedModule[44]=C:\Windows\SYSTEM32\SndVolSSO.DLL
LoadedModule[45]=C:\Windows\SYSTEM32\HID.DLL
LoadedModule[46]=C:\Windows\System32\MMDevApi.dll
LoadedModule[47]=C:\Windows\System32\DEVOBJ.dll
LoadedModule[48]=C:\Windows\SYSTEM32\cfgmgr32.dll
LoadedModule[49]=C:\Windows\SYSTEM32\OLEACC.dll
LoadedModule[50]=C:\Windows\SYSTEM32\D3D10Warp.dll
LoadedModule[51]=C:\Windows\system32\twinui.dll
LoadedModule[52]=C:\Windows\SYSTEM32\twinapi.appcore.dll
LoadedModule[53]=C:\Windows\system32\XmlLite.dll
LoadedModule[54]=C:\Windows\system32\Windows.UI.Immersive.dll
LoadedModule[55]=C:\Windows\SYSTEM32\ntmarta.dll
LoadedModule[56]=C:\Windows\SYSTEM32\CRYPTSP.dll
LoadedModule[57]=C:\Windows\system32\rsaenh.dll
LoadedModule[58]=C:\Windows\SYSTEM32\bcrypt.dll
LoadedModule[59]=C:\Windows\System32\actxprxy.dll
LoadedModule[60]=C:\Windows\system32\windowscodecs.dll
LoadedModule[61]=C:\Windows\system32\explorerframe.dll
LoadedModule[62]=C:\Windows\SYSTEM32\tabbtn.dll
LoadedModule[63]=C:\Windows\System32\TabBtnEx.dll
LoadedModule[64]=C:\Windows\System32\windows.immersiveshell.serviceprovider.dll
LoadedModule[65]=C:\Program Files\Common Files\microsoft shared\ink\TipBand.dll
LoadedModule[66]=C:\Windows\SYSTEM32\WLDP.DLL
LoadedModule[67]=C:\Windows\SYSTEM32\WTSAPI32.dll
LoadedModule[68]=C:\Windows\System32\twinui.appcore.dll
LoadedModule[69]=C:\Windows\System32\wpncore.dll
LoadedModule[70]=C:\Windows\system32\dwrite.dll
LoadedModule[71]=C:\Windows\System32\UIAnimation.dll
LoadedModule[72]=C:\Windows\SYSTEM32\igd10iumd64.dll
LoadedModule[73]=C:\Windows\SYSTEM32\ncrypt.dll
LoadedModule[74]=C:\Windows\SYSTEM32\NTASN1.dll
LoadedModule[75]=C:\Windows\SYSTEM32\igdusc64.dll
LoadedModule[76]=C:\Windows\System32\wlidprov.dll
LoadedModule[77]=C:\Windows\System32\thumbcache.dll
LoadedModule[78]=C:\Windows\System32\Windows.Networking.Connectivity.dll
LoadedModule[79]=C:\Windows\System32\InputSwitch.dll
LoadedModule[80]=C:\Windows\system32\stobject.dll
LoadedModule[81]=C:\Windows\system32\BatMeter.dll
LoadedModule[82]=C:\Windows\SYSTEM32\sxs.dll
LoadedModule[83]=C:\Windows\system32\SETUPAPI.dll
LoadedModule[84]=C:\Windows\system32\WINTRUST.dll
LoadedModule[85]=C:\Windows\system32\CRYPT32.dll
LoadedModule[86]=C:\Windows\system32\MSASN1.dll
LoadedModule[87]=C:\Windows\System32\WININET.dll
LoadedModule[88]=C:\Windows\System32\iertutil.dll
LoadedModule[89]=C:\Windows\SYSTEM32\Secur32.dll
LoadedModule[90]=C:\Windows\system32\es.dll
LoadedModule[91]=C:\Windows\system32\prnfldr.dll
LoadedModule[92]=C:\Windows\system32\WINSPOOL.DRV
LoadedModule[93]=C:\Windows\system32\wevtapi.dll
LoadedModule[94]=C:\Windows\system32\dxp.dll
LoadedModule[95]=C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17227_none_932c0e57474f5080\gdiplus.dll
LoadedModule[96]=C:\Windows\system32\SHDOCVW.dll
LoadedModule[97]=C:\Windows\System32\Actioncenter.dll
LoadedModule[98]=C:\Windows\SYSTEM32\ntshrui.dll
LoadedModule[99]=C:\Windows\SYSTEM32\srvcli.dll
LoadedModule[100]=C:\Windows\system32\Syncreg.dll
LoadedModule[101]=C:\Windows\SYSTEM32\cscapi.dll
LoadedModule[102]=C:\Windows\SYSTEM32\netutils.dll
LoadedModule[103]=C:\Windows\SYSTEM32\LINKINFO.dll
LoadedModule[104]=C:\Windows\System32\npmproxy.dll
LoadedModule[105]=C:\Windows\System32\IPHLPAPI.DLL
LoadedModule[106]=C:\Windows\system32\NSI.dll
LoadedModule[107]=C:\Windows\System32\WINNSI.DLL
LoadedModule[108]=C:\Windows\system32\IconCodecService.dll
LoadedModule[109]=C:\Windows\SYSTEM32\wlanapi.dll
LoadedModule[110]=C:\Windows\System32\WinTypes.dll
LoadedModule[111]=C:\Windows\System32\wcmapi.dll
LoadedModule[112]=C:\Windows\system32\wpdshserviceobj.dll
LoadedModule[113]=C:\Windows\System32\PortableDeviceTypes.dll
LoadedModule[114]=C:\Windows\System32\PortableDeviceApi.dll
LoadedModule[115]=C:\Windows\system32\SettingMonitor.dll
LoadedModule[116]=C:\Program Files\Windows Portable Devices\SqmApi.dll
LoadedModule[117]=C:\Windows\System32\srchadmin.dll
LoadedModule[118]=C:\Windows\system32\mssprxy.dll
LoadedModule[119]=C:\Windows\System32\SyncCenter.dll
LoadedModule[120]=C:\Windows\System32\imapi2.dll
LoadedModule[121]=C:\Windows\System32\ieframe.dll
LoadedModule[122]=C:\Windows\SYSTEM32\AUDIOSES.DLL
LoadedModule[123]=C:\Windows\system32\authui.dll
LoadedModule[124]=C:\Windows\SYSTEM32\urlmon.dll
LoadedModule[125]=C:\Windows\System32\AltTab.dll
LoadedModule[126]=C:\Windows\system32\Windows.UI.Search.dll
LoadedModule[127]=C:\Windows\system32\wincorlib.DLL
LoadedModule[128]=C:\Windows\system32\WSClient.dll
LoadedModule[129]=C:\Windows\system32\UIAutomationCore.DLL
LoadedModule[130]=C:\Windows\system32\WSShared.dll
LoadedModule[131]=C:\Windows\system32\WSSync.dll
LoadedModule[132]=C:\Windows\system32\wer.dll
LoadedModule[133]=C:\Windows\system32\elscore.dll
LoadedModule[134]=C:\Windows\system32\NetworkExplorer.dll
LoadedModule[135]=C:\Windows\System32\pnidui.dll
LoadedModule[136]=C:\Windows\system32\NetworkStatus.dll
LoadedModule[137]=C:\Windows\System32\MrmCoreR.dll
LoadedModule[138]=C:\Windows\System32\Windows.UI.dll
LoadedModule[139]=C:\Windows\System32\NInput.dll
LoadedModule[140]=C:\Windows\System32\netprofm.dll
LoadedModule[141]=C:\Windows\system32\WS2_32.dll
LoadedModule[142]=C:\Program Files\a3b4\utils\salextx64.dll
LoadedModule[143]=C:\Windows\SYSTEM32\ondemandconnroutehelper.dll
LoadedModule[144]=C:\Windows\System32\Windows.UI.Xaml.dll
LoadedModule[145]=C:\Windows\SYSTEM32\winhttp.dll
LoadedModule[146]=C:\Program Files\a3\utils\salextx64.dll
LoadedModule[147]=C:\Windows\system32\mswsock.dll
LoadedModule[148]=C:\Program Files\a3.2\utils\salextx64.dll
LoadedModule[149]=C:\Windows\SYSTEM32\DNSAPI.dll
LoadedModule[150]=C:\Windows\System32\rasadhlp.dll
LoadedModule[151]=C:\Windows\System32\bthprops.cpl
LoadedModule[152]=C:\Windows\System32\BluetoothApis.dll
LoadedModule[153]=C:\Windows\system32\searchfolder.dll
LoadedModule[154]=C:\Windows\SYSTEM32\d2d1.dll
LoadedModule[155]=C:\Windows\System32\StructuredQuery.dll
LoadedModule[156]=C:\Windows\System32\dhcpcsvc6.DLL
LoadedModule[157]=C:\Windows\System32\dhcpcsvc.DLL
LoadedModule[158]=C:\Windows\System32\msxml6.dll
LoadedModule[159]=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
LoadedModule[160]=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\MSVCR100.dll
LoadedModule[161]=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\MSVCP100.dll
LoadedModule[162]=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\ATL100.DLL
LoadedModule[163]=C:\Windows\System32\fwpuclnt.dll
LoadedModule[164]=C:\Windows\SYSTEM32\msi.dll
LoadedModule[165]=C:\Windows\SYSTEM32\MLANG.dll
LoadedModule[166]=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
LoadedModule[167]=C:\Windows\System32\EhStorShell.dll
LoadedModule[168]=C:\Windows\SYSTEM32\MsftEdit.dll
LoadedModule[169]=C:\Windows\SYSTEM32\MSIMG32.dll
LoadedModule[170]=C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
LoadedModule[171]=C:\Windows\System32\shacct.dll
LoadedModule[172]=C:\Windows\System32\samcli.dll
LoadedModule[173]=C:\Windows\system32\wkscli.dll
LoadedModule[174]=C:\Windows\System32\hgcpl.dll
LoadedModule[175]=C:\Windows\System32\provsvc.dll
LoadedModule[176]=C:\Windows\SYSTEM32\apprepapi.dll
LoadedModule[177]=C:\Windows\SYSTEM32\tbs.dll
LoadedModule[178]=C:\Windows\SYSTEM32\pcacli.dll
LoadedModule[179]=C:\Windows\SYSTEM32\MPR.dll
LoadedModule[180]=C:\Windows\System32\sfc_os.dll
LoadedModule[181]=C:\Program Files\Internet Explorer\ieproxy.dll
LoadedModule[182]=C:\Windows\SYSTEM32\msiltcfg.dll
LoadedModule[183]=C:\Windows\SYSTEM32\VERSION.dll
LoadedModule[184]=C:\Windows\system32\DEVRTL.dll
LoadedModule[185]=C:\Windows\SYSTEM32\WINMM.dll
LoadedModule[186]=C:\Windows\SYSTEM32\WINMMBASE.dll
LoadedModule[187]=C:\Windows\SYSTEM32\wdmaud.drv
LoadedModule[188]=C:\Windows\SYSTEM32\ksuser.dll
LoadedModule[189]=C:\Windows\SYSTEM32\AVRT.dll
LoadedModule[190]=C:\Windows\SYSTEM32\msacm32.drv
LoadedModule[191]=C:\Windows\SYSTEM32\MSACM32.dll
LoadedModule[192]=C:\Program Files (x86)\TechSmith\Snagit 12\SnagItShellExtRes.dll
LoadedModule[193]=C:\Windows\System32\wscinterop.dll
LoadedModule[194]=C:\Windows\System32\WSCAPI.dll
LoadedModule[195]=C:\Windows\System32\wscui.cpl
LoadedModule[196]=C:\Windows\System32\werconcpl.dll
LoadedModule[197]=C:\Windows\System32\framedynos.dll
LoadedModule[198]=C:\Windows\System32\wercplsupport.dll
LoadedModule[199]=C:\Windows\System32\hcproviders.dll
LoadedModule[200]=C:\Windows\System32\van.dll
LoadedModule[201]=C:\Windows\system32\wshbth.dll
LoadedModule[202]=C:\Windows\SYSTEM32\datusage.dll
LoadedModule[203]=C:\Windows\SYSTEM32\SrumAPI.dll
LoadedModule[204]=C:\Windows\system32\windows.globalization.fontgroups.dll
LoadedModule[205]=C:\Windows\System32\Windows.Web.dll
LoadedModule[206]=C:\Windows\System32\wpc.dll
LoadedModule[207]=C:\Windows\System32\NETAPI32.dll
LoadedModule[208]=C:\Windows\system32\Normaliz.dll
LoadedModule[209]=C:\Windows\System32\Windows.Devices.Geolocation.dll
LoadedModule[210]=C:\Windows\System32\MSWB7.dll
LoadedModule[211]=C:\Windows\System32\threadpoolwinrt.dll
LoadedModule[212]=C:\Windows\system32\ElsLad.dll
LoadedModule[213]=C:\Windows\SYSTEM32\PhotoMetadataHandler.dll
LoadedModule[214]=C:\Windows\system32\timedate.cpl
LoadedModule[215]=C:\Windows\system32\ATL.DLL
LoadedModule[216]=C:\Windows\System32\qmgrprxy.dll
LoadedModule[217]=C:\Windows\System32\WorkfoldersShell.dll
LoadedModule[218]=C:\Windows\SYSTEM32\UIRibbonRes.dll
LoadedModule[219]=C:\Windows\System32\SkydriveShell.dll
LoadedModule[220]=C:\Windows\System32\dlnashext.dll
LoadedModule[221]=C:\Windows\System32\DevDispItemProvider.dll
LoadedModule[222]=C:\Windows\system32\imagehlp.dll
LoadedModule[223]=C:\Windows\System32\comsvcs.dll
LoadedModule[224]=C:\Windows\SYSTEM32\VirtDisk.dll
LoadedModule[225]=C:\Windows\SYSTEM32\FLTLIB.DLL
LoadedModule[226]=C:\Windows\SYSTEM32\netjoin.dll
LoadedModule[227]=C:\Windows\system32\igfxrENU.lrc
LoadedModule[228]=C:\Windows\system32\windowscodecsext.dll
LoadedModule[229]=C:\Windows\SYSTEM32\mscms.dll
LoadedModule[230]=C:\Windows\System32\msxml3.dll
LoadedModule[231]=C:\Program Files (x86)\CyberLink\YouCam\CLCredProv\x64\CLCredProv.dll
LoadedModule[232]=C:\Windows\system32\themeui.dll
LoadedModule[233]=C:\Windows\SYSTEM32\webservices.dll
LoadedModule[234]=C:\Windows\system32\DeviceCenter.dll
LoadedModule[235]=C:\Windows\SYSTEM32\printui.dll
LoadedModule[236]=C:\Windows\SYSTEM32\puiapi.dll
LoadedModule[237]=C:\Windows\System32\nlaapi.dll
LoadedModule[238]=C:\Windows\system32\zipfldr.dll
LoadedModule[239]=C:\Windows\system32\UIRibbon.dll
LoadedModule[240]=C:\Windows\system32\wpdshext.dll
LoadedModule[241]=C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll
LoadedModule[242]=C:\Windows\system32\syncui.dll
LoadedModule[243]=C:\Windows\system32\SYNCENG.dll
LoadedModule[244]=C:\Windows\system32\twext.dll
LoadedModule[245]=C:\Program Files (x86)\TechSmith\Snagit 12\DLLx64\SnagitShellExt64.dll
LoadedModule[246]=C:\Windows\system32\COMDLG32.dll
LoadedModule[247]=C:\Program Files\7-Zip\7-zip.dll
LoadedModule[248]=C:\Windows\SYSTEM32\CHARTV.dll
State[0].Key=Transport.DoneStage1
State[0].Value=1
FriendlyEventName=Stopped working
ConsentKey=APPCRASH
AppName=Windows Explorer
AppPath=C:\Windows\Explorer.EXE
NsPartner=windows
NsGroup=windows8
ApplicationIdentity=346CB44573137696C511B752A176C0D0
Again, it being a user-mode crash v. kernel-mode (post-mortem), there is little that I can do with it.
As for the Nirsoft apps -
shexview.exe - ShellExView - go down the list and start disabling non-Microsoft shells. You can tell which are Microsoft by the version number - 6.1.7600 or 6.1.7601. It is likely that a 3rd party shell is at the root of your problem.
Any luck with System Restore? Do you have restore points that are ~1 month old to bring the system back to a point prior to the start of the Explorer crashes?
Regards. . .
John
EDIT: I would also recommend that you run
sfc /scannow - type or paste it into an Admin CMD screen.