Windows 10 explorer.exe corrupção da pilha ntdll.dll quando aberto da barra de tarefas

3

Eu tenho um problema estranho com o File Explorer. Se eu o executar clicando no ícone fixado na barra de tarefas, ele não será aberto e o explorer.exe será reiniciado após alguns segundos. Se eu pressionar Windows + e , ele abrirá corretamente.

O Visualizador de Eventos mostra isso:

Faulting application name: explorer.exe, version: 10.0.14393.0, time stamp: 0x57899981
Faulting module name: ntdll.dll, version: 10.0.14393.0, time stamp: 0x578997b2
Exception code: 0xc0000374
Fault offset: 0x00000000000f73e3
Faulting process ID: 0xb28
Faulting application start time: 0x01d1fa2b5e3c55e2
Faulting application path: C:\WINDOWS\explorer.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report ID: 7cee4732-0e54-425a-ad3e-85f25a098c17
Faulting package full name: 
Faulting package-relative application ID: 

Eu importei uma chave de registro para criar dumps e abri-a em windmg. Correndo! Analise -v apenas me mostra um monte de heap_corruption, e eu não sei o suficiente sobre windmg para saber o que procurar. Se alguém puder me dar um ponteiro, ou se você quiser o arquivo dmp (7-zipado), me avise. Muito obrigado.

    
por Paul 19.08.2016 / 17:30

1 resposta

2

Olhando para o despejo, mostra que um driver nvidia causa a falha:

0:092> !heap -p -a 00000000145e7870
    address 00000000145e7870 found in
    _HEAP @ 145e0000
              HEAP_ENTRY Size Prev Flags            UserPtr UserSize - state
        00000000145e7820 0021 0000  [00]   00000000145e7870    001a0 - (busy)
        7ffe3e34401f verifier!AVrfDebugPageHeapAllocate+0x000000000000039f
        7ffe460ceefb ntdll!RtlDebugAllocateHeap+0x000000000003c357
        7ffe460bc586 ntdll!RtlpAllocateHeap+0x0000000000082f86
        7ffe46037ad7 ntdll!RtlpAllocateHeapInternal+0x0000000000000727
        7ffe3e362ed7 verifier!AVrfpRtlAllocateHeap+0x00000000000000e7
        7ffe26fb40f7 nv3dappshext!DllInstall+0x000000000007873f
        7ffe26f37973 nv3dappshext+0x0000000000007973
        7ffe26f37f6d nv3dappshext+0x0000000000007f6d
        7ffe26f37fa5 nv3dappshext+0x0000000000007fa5
        7ffe26fa4168 nv3dappshext!DllInstall+0x00000000000687b0
        7ffe26fa50be nv3dappshext!DllInstall+0x0000000000069706
        7ffe26f3de49 nv3dappshext!DllInstall+0x0000000000002491
        7ffe26f3edbc nv3dappshext!DllInstall+0x0000000000003404
        7ffe4444773b shell32!DllCanUnloadNow+0x000000000000079b
        7ffe444436c4 shell32!SHRestricted+0x0000000000001e64
        7ffe4359e13f shlwapi!SHInvokeCommandOnContextMenu2+0x00000000000000d7
        7ffe4359e034 shlwapi!SHInvokeCommandWithFlagsAndSite+0x00000000000000b4
        7ff679e811ba explorer!LaunchNewInstanceWithOptionalElevate+0x000000000000012a
        7ff679e896be explorer!CTaskBand::CLauncherTask::_Launch+0x000000000000016a
        7ff679e8aa0c explorer!CTaskBand::CLauncherTask::_ThreadProc+0x0000000000000038
        7ff679e8abee explorer!CTaskBand::CLauncherTask::s_ThreadProc+0x000000000000000e
        7ffe43235aad +0x0000000000000135
        7ffe3e35d684 verifier!AVrfpStandardThreadFunction+0x0000000000000044
        7ffe440a8364 kernel32!BaseThreadInitThunk+0x0000000000000014
        7ffe46065e91 ntdll!RtlUserThreadStart+0x0000000000000021

O driver é de 2012,

Image path: C:\Windows\System32\nv3dappshext.dll
Image name: nv3dappshext.dll
Browse all global symbols  functions  data
Timestamp:        Wed Aug 22 21:53:10 2012 (503538A6)
CheckSum:         000DA2D4
ImageSize:        000E5000
File version:     8.17.13.604
Product version:  8.17.13.604
File flags:       0 (Mask 3F)
File OS:          4 Unknown Win32
File type:        2.0 Dll
File date:        00000000.00000000
Translations:     0409.04e4
CompanyName:      NVIDIA Corporation
ProductName:      NVIDIA Shell Extensions
InternalName:     Nv3DAppShExt.dll
OriginalFilename: Nv3DAppShExt.dll
ProductVersion:   8.17.13.0604
FileVersion:      8.17.13.0604
FileDescription:  NVIDIA Shell Extensions
LegalCopyright:   (C) 2012 NVIDIA Corporation. All rights reserved.

atualize o driver para uma versão testada com o Windows 10. Importe o arquivo uninstall.reg para desativar o verificador de aplicativos e a geração de despejo.

    
por 22.08.2016 / 17:58