Hi, I have various problems on my system (W7 HOME 64-BIT), one of which is random explorer craches (which is the most frustrating). Others issues are : some exe won't run any more when I double-clic on them, others ones create an 'Access violation'' message.. I performed a sfc /scannow command and Windows found corrupted files but was unable to repair them. I tried in safe mode too with same results.
I tried to analyse some dmp files via the Windows debugging tools but i'm not sure if it was correctly executed since some symbol files weren't found. I also tried to update my drivers as suggested on forums (24 of them are outdated) but after a reboot, i got a blue screen so had to perform a system restore. Now my system is back but with the same problems.
I was about to try the verifier command (Driver Verifier Manager) but had to cancel when I read it can cause many crashes to the system. I would take any advices as i'm completly clueless at the moment.
Here's the dump analysis about explorer :
Microsoft (R) Windows Debugger Version 6.3.9600.16384 AMD64 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\Users\ss\Desktop\explorer.exe(1).2660.dmp] User Mini Dump File: Only registers, stack and portions of memory are available ************* Symbol Path validation summary ************** Response Time (ms) Location Deferred srv*c:\mss*http://msdl.microsoft.com/download/symbols Symbol search path is: srv*c:\mss*http://msdl.microsoft.com/download/symbols Executable search path is: Windows 7 Version 7601 (Service Pack 1) MP (4 procs) Free x64 Product: WinNt, suite: SingleUserTS Personal Machine Name: Debug session time: Thu Jun 26 02:11:10.000 2014 (UTC + 2:00) System Uptime: not available Process Uptime: 1 days 3:42:55.000 ................................................................ ................................................................ ............................................................... Loading unloaded module list ................................................................ This dump file has an exception of interest stored in it. The stored exception information can be accessed via .ecxr. (a64.e6c): Unknown exception - code c000041d (first/second chance not available) 00000000`03220fd8 ?? ??? 0:000> !analyze -v ******************************************************************************* * * * Exception Analysis * * * ******************************************************************************* *** ERROR: Symbol file could not be found. Defaulted to export symbols for awmemb64.dll - *** ERROR: Symbol file could not be found. Defaulted to export symbols for ClassicStartMenuDLL.dll - FAULTING_IP: +4b3cf90 00000000`03220fd8 ?? ??? EXCEPTION_RECORD: ffffffffffffffff -- (.exr 0xffffffffffffffff) ExceptionAddress: 0000000003220fd8 ExceptionCode: c000041d ExceptionFlags: 00000001 NumberParameters: 0 CONTEXT: 0000000000000000 -- (.cxr 0x0;r) rax=000000000019eef0 rbx=000000000019e780 rcx=00000000000506e8 rdx=000000000000001c rsi=00000000777c6580 rdi=000000000019ec70 rip=0000000003220fd8 rsp=000000000019ee88 rbp=0000000000000001 r8=0000000000000000 r9=00000000000005b8 r10=00000000000506e8 r11=00000000002c7ed8 r12=0000000000000000 r13=000000000000001c r14=00000000002c7ed8 r15=00000000000506e8 iopl=0 nv up ei pl zr na po nc cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010244 00000000`03220fd8 ?? ??? DEFAULT_BUCKET_ID: APPLICATION_FAULT PROCESS_NAME: explorer.exe ERROR_CODE: (NTSTATUS) 0xc000041d - Une exception non g r e a t d tect e pendant un rappel de l EXCEPTION_CODE: (NTSTATUS) 0xc000041d - Une exception non g r e a t d tect e pendant un rappel de l NTGLOBALFLAG: 0 APPLICATION_VERIFIER_FLAGS: 0 APP: explorer.exe ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) amd64fre IP_ON_HEAP: 0000000003220fd8 The fault address in not in any loaded module, please check your build's rebase log at <releasedir>\bin\build_logs\timebuild\ntrebase.log for module which may contain the address if it were loaded. FAULTING_THREAD: 0000000000000e6c PRIMARY_PROBLEM_CLASS: APPLICATION_FAULT BUGCHECK_STR: APPLICATION_FAULT_APPLICATION_FAULT LAST_CONTROL_TRANSFER: from 0000000077599bd1 to 0000000003220fd8 STACK_TEXT: 00000000`0019ee88 00000000`77599bd1 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`0019ee60 : 0x3220fd8 00000000`0019ee90 00000000`775972cb : 00000000`00000000 00000000`03220fd8 00000000`00000000 00000000`00000000 : user32!UserCallWinProcCheckWow+0x1ad 00000000`0019ef50 00000000`77596829 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000e6c : user32!DispatchClientMessage+0xc3 00000000`0019efb0 00000000`776d11f5 : 00000000`00000000 00000000`002c8d28 00000000`00000060 ffffffff`ffffffff : user32!_fnDWORD+0x2d 00000000`0019f010 00000000`7759908a : 00000000`77599055 00000000`0081c788 00008fe8`00000001 00000000`00000000 : ntdll!KiUserCallbackDispatcherContinue 00000000`0019f098 00000000`77599055 : 00000000`0081c788 00008fe8`00000001 00000000`00000000 00000000`77599712 : user32!NtUserPeekMessage+0xa 00000000`0019f0a0 000007fe`fdff643c : 00000000`00000001 00000000`00070518 00000000`00000000 00000000`00000000 : user32!PeekMessageW+0x105 00000000`0019f0f0 000007fe`fdff6494 : 00000000`04e48020 00000000`04d259a0 00000000`00000000 00000000`00000000 : shell32!CDesktopBrowser::_PeekForAMessage+0x38 00000000`0019f170 000007fe`fdf57795 : 00000000`04d259a0 00000000`04d259a0 00000000`00000000 00000000`00000000 : shell32!CDesktopBrowser::_MessageLoop+0x24 00000000`0019f1b0 00000000`ff300ac1 : 000007fe`fbdd2e60 80000000`04010000 00000000`00000000 00000000`04d259a0 : shell32!SHDesktopMessageLoop+0x7e 00000000`0019f1f0 00000000`ff30b8d5 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : explorer!wWinMain+0xb1e 00000000`0019f8a0 00000000`774759ed : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : explorer!DelayLoadFailureHook+0x208 00000000`0019f960 00000000`776ac541 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0xd 00000000`0019f990 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x1d STACK_COMMAND: ~0s; .ecxr ; kb FOLLOWUP_IP: shell32!CDesktopBrowser::_PeekForAMessage+38 000007fe`fdff643c 85c0 test eax,eax SYMBOL_STACK_INDEX: 7 SYMBOL_NAME: shell32!CDesktopBrowser::_PeekForAMessage+38 FOLLOWUP_NAME: MachineOwner MODULE_NAME: shell32 IMAGE_NAME: shell32.dll DEBUG_FLR_IMAGE_TIMESTAMP: 5330ecd9 FAILURE_BUCKET_ID: APPLICATION_FAULT_c000041d_shell32.dll!CDesktopBrowser::_PeekForAMessage BUCKET_ID: X64_APPLICATION_FAULT_APPLICATION_FAULT_shell32!CDesktopBrowser::_PeekForAMessage+38 ANALYSIS_SOURCE: UM FAILURE_ID_HASH_STRING: um:application_fault_c000041d_shell32.dll!cdesktopbrowser::_peekforamessage FAILURE_ID_HASH: {5739551d-5036-5673-feae-5a9647afaaba} Followup: MachineOwner ---------
Also an Access violation dump :
Microsoft (R) Windows Debugger Version 6.3.9600.16384 AMD64 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\Users\ss\Desktop\Aidsoid Viewer.exe.5176.dmp] User Mini Dump File: Only registers, stack and portions of memory are available ************* Symbol Path validation summary ************** Response Time (ms) Location Deferred http://msdl.microsoft.com/download/symbols Symbol search path is: http://msdl.microsoft.com/download/symbols Executable search path is: Windows 7 Version 7601 (Service Pack 1) MP (4 procs) Free x86 compatible Product: WinNt, suite: SingleUserTS Personal Machine Name: Debug session time: Wed Jun 25 00:14:57.000 2014 (UTC + 2:00) System Uptime: not available Process Uptime: 0 days 0:00:19.000 ................................................................ Loading unloaded module list .. This dump file has an exception of interest stored in it. The stored exception information can be accessed via .ecxr. (1438.12e8): Access violation - code c0000005 (first/second chance not available) eax=00000000 ebx=0018df94 ecx=00000000 edx=00000000 esi=00000002 edi=00000000 eip=7788015d esp=0018df44 ebp=0018dfe0 iopl=0 nv up ei pl zr na pe nc cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00200246 ntdll!NtWaitForMultipleObjects+0x15: 7788015d 83c404 add esp,4 0:000> !analyze -v ******************************************************************************* * * * Exception Analysis * * * ******************************************************************************* *** WARNING: Unable to verify timestamp for Aidsoid Viewer.exe *** ERROR: Module load completed but symbols could not be loaded for Aidsoid Viewer.exe Unable to load image C:\Windows\System32\ieframe.dll, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ieframe.dll *** ERROR: Symbol file could not be found. Defaulted to export symbols for awmemb.dll - *** ERROR: Symbol file could not be found. Defaulted to export symbols for Flash32_13_0_0_214.ocx - FAULTING_IP: Aidsoid_Viewer+191db 004191db 8b7308 mov esi,dword ptr [ebx+8] EXCEPTION_RECORD: ffffffff -- (.exr 0xffffffffffffffff) ExceptionAddress: 004191db (Aidsoid_Viewer+0x000191db) ExceptionCode: c0000005 (Access violation) ExceptionFlags: 00000000 NumberParameters: 2 Parameter[0]: 00000000 Parameter[1]: 88000008 Attempt to read from address 88000008 CONTEXT: 00000000 -- (.cxr 0x0;r) eax=00000000 ebx=0018df94 ecx=00000000 edx=00000000 esi=00000002 edi=00000000 eip=7788015d esp=0018df44 ebp=0018dfe0 iopl=0 nv up ei pl zr na pe nc cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00200246 ntdll!NtWaitForMultipleObjects+0x15: 7788015d 83c404 add esp,4 DEFAULT_BUCKET_ID: INVALID_POINTER_READ PROCESS_NAME: Aidsoid Viewer.exe ERROR_CODE: (NTSTATUS) 0xc0000005 - L EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - L EXCEPTION_PARAMETER1: 00000000 EXCEPTION_PARAMETER2: 88000008 READ_ADDRESS: 88000008 FOLLOWUP_IP: Aidsoid_Viewer+191db 004191db 8b7308 mov esi,dword ptr [ebx+8] NTGLOBALFLAG: 0 APPLICATION_VERIFIER_FLAGS: 0 APP: aidsoid viewer.exe ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) amd64fre LAST_CONTROL_TRANSFER: from 778996ba to 0018ea0c FAULTING_THREAD: ffffffff PRIMARY_PROBLEM_CLASS: INVALID_POINTER_READ BUGCHECK_STR: APPLICATION_FAULT_INVALID_POINTER_READ IP_ON_STACK: +191db 0018ea0c 20903702f18b and byte ptr [eax-740EFDC9h],dl STACK_TEXT: 004191db 004191db aidsoid_viewer+0x191db STACK_COMMAND: dps 4191db ; kb SYMBOL_STACK_INDEX: 0 SYMBOL_NAME: aidsoid_viewer+191db FOLLOWUP_NAME: MachineOwner MODULE_NAME: Aidsoid_Viewer IMAGE_NAME: Aidsoid Viewer.exe DEBUG_FLR_IMAGE_TIMESTAMP: 2a425e19 FAILURE_BUCKET_ID: INVALID_POINTER_READ_c0000005_Aidsoid_Viewer.exe!Unknown BUCKET_ID: APPLICATION_FAULT_INVALID_POINTER_READ_aidsoid_viewer+191db ANALYSIS_SOURCE: UM FAILURE_ID_HASH_STRING: um:invalid_pointer_read_c0000005_aidsoid_viewer.exe!unknown FAILURE_ID_HASH: {8ac0c61f-411a-8b4e-ba11-f43585a741fd} Followup: MachineOwner ---------