Windows 10 Explorer crashes caused by twinui.appcore.dll when using Remote App

  • Thread starter Thread starter ceather93
  • Start date Start date
C

ceather93

Guest
Hi All,

We have multiple machines which are having explorer crashing when they are using a remote app. When I look at the log on these machines the following events are logged. (Below)

I have tried the following:

- Installing the latest updates
- Updating System Drivers
- Recreating Local & Roaming Profile

When the problem occurs the RemoteApp loses focus and the Explorer process on the local machine constantly crashes in short succession. You need to close the remote app for the Explorer.exe process on the workstation to recover.

Below is more info from the crash logs.


Event 1000 Application Error
Faulting application name: explorer.exe, version: 10.0.10240.16942, time stamp: 0x5749188e
Faulting module name: twinui.appcore.dll, version: 10.0.10240.16412, time stamp: 0x55b99e01
Exception code: 0xc0000005
Fault offset: 0x000000000005a58a
Faulting process id: 0x3430
Faulting application start time: 0x01d1c85c9afeaee6
Faulting application path: C:\WINDOWS\explorer.exe
Faulting module path: C:\WINDOWS\System32\twinui.appcore.dll
Report Id: 92db71ca-086b-4519-8c6d-beadb68ec3f8
Faulting package full name:
Faulting package-relative application ID:

Event 1001, Windows Error Reporting
Fault bucket , type 0
Event Name: APPCRASH
Response: Not available
Cab Id: 0

Problem signature:
P1: explorer.exe
P2: 10.0.10240.16942
P3: 5749188e
P4: twinui.appcore.dll
P5: 10.0.10240.16412
P6: 55b99e01
P7: c0000005
P8: 000000000005a58a
P9:
P10:

Attached files:
C:\Users\USER\AppData\Local\Temp\WER9FD4.tmp.appcompat.txt
C:\Users\USER\AppData\Local\Temp\WER9FE5.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_explorer.exe_5827cc1bc748a752e40215ec0407a24b5bf636_738e35a5_cab_19789ff3\memory.hdmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_explorer.exe_5827cc1bc748a752e40215ec0407a24b5bf636_738e35a5_cab_19789ff3\triagedump.dmp

These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_explorer.exe_5827cc1bc748a752e40215ec0407a24b5bf636_738e35a5_cab_19789ff3

Analysis symbol:
Rechecking for solution: 0
Report Id: 92db71ca-086b-4519-8c6d-beadb68ec3f8
Report Status: 4
Hashed bucket:


Loading unloaded module list
.
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(3430.ed8): Access violation - code c0000005 (first/second chance not available)
ntdll!NtWaitForMultipleObjects+0xa:
00007ff8`e4c83dda c3 ret
0:063> .ecxr.
rax=000000000a000014 rbx=0000000080070490 rcx=0000000002f33f50
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=00007ff8d040a58a rsp=00000000129ed950 rbp=00007ff8d040a460
r8=00000000129ed9d0 r9=00007ff8d04f7478 r10=0000000002f352f0
r11=00007ff8e24c0000 r12=0000000000000002 r13=0000000000000000
r14=00000000129ed9d0 r15=00007ff8d040a460
iopl=0 nv up ei pl zr na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010246
twinui_appcore!ViewWrapperBase::IsEqual+0x4a:
00007ff8`d040a58a 488b07 mov rax,qword ptr [rdi] ds:00000000`00000000=????????????????
^ Extra character error in '.ecxr.'
0:063> !analyze -v
*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************

*** ERROR: Symbol file could not be found. Defaulted to export symbols for sppc.dll -
*** WARNING: Unable to verify timestamp for nvwgf2umx.dll
*** ERROR: Module load completed but symbols could not be loaded for nvwgf2umx.dll
*** WARNING: Unable to verify timestamp for DropboxExt64.34.dll
*** ERROR: Module load completed but symbols could not be loaded for DropboxExt64.34.dll

DUMP_CLASS: 2

DUMP_QUALIFIER: 400

CONTEXT: (.ecxr)
rax=000000000a000014 rbx=0000000080070490 rcx=0000000002f33f50
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=00007ff8d040a58a rsp=00000000129ed950 rbp=00007ff8d040a460
r8=00000000129ed9d0 r9=00007ff8d04f7478 r10=0000000002f352f0
r11=00007ff8e24c0000 r12=0000000000000002 r13=0000000000000000
r14=00000000129ed9d0 r15=00007ff8d040a460
iopl=0 nv up ei pl zr na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010246
twinui_appcore!ViewWrapperBase::IsEqual+0x4a:
00007ff8`d040a58a 488b07 mov rax,qword ptr [rdi] ds:00000000`00000000=????????????????
Resetting default scope

FAULTING_IP:
twinui_appcore!ViewWrapperBase::IsEqual+4a
00007ff8`d040a58a 488b07 mov rax,qword ptr [rdi]

EXCEPTION_RECORD: (.exr -1)
ExceptionAddress: 00007ff8d040a58a (twinui_appcore!ViewWrapperBase::IsEqual+0x000000000000004a)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000000
Attempt to read from address 0000000000000000

DEFAULT_BUCKET_ID: NULL_POINTER_READ

PROCESS_NAME: explorer.exe

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.

EXCEPTION_CODE_STR: c0000005

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: 0000000000000000

READ_ADDRESS: 0000000000000000

FOLLOWUP_IP:
twinui_appcore!ViewWrapperBase::IsEqual+4a
00007ff8`d040a58a 488b07 mov rax,qword ptr [rdi]

BUGCHECK_STR: NULL_POINTER_READ

WATSON_BKT_PROCSTAMP: 5749188e

WATSON_BKT_PROCVER: 10.0.10240.16942

PROCESS_VER_PRODUCT: Microsoft® Windows® Operating System

WATSON_BKT_MODULE: twinui.appcore.dll

WATSON_BKT_MODSTAMP: 55b99e01

WATSON_BKT_MODOFFSET: 5a58a

WATSON_BKT_MODVER: 10.0.10240.16412

MODULE_VER_PRODUCT: Microsoft® Windows® Operating System

BUILD_VERSION_STRING: 10.0.10240.16384 (th1.150709-1700)

MODLIST_WITH_TSCHKSUM_HASH: 377c1c116db3472153233155adde9648b6259170

MODLIST_SHA1_HASH: c3300f4d2b25496a6ef90ad21942a61a3277f420

NTGLOBALFLAG: 0

APPLICATION_VERIFIER_FLAGS: 0

DUMP_FLAGS: 94

DUMP_TYPE: 1

APP: explorer.exe

ANALYSIS_SESSION_HOST: <PCNAME>

ANALYSIS_SESSION_TIME: 06-17-2016 16:43:48.0665

ANALYSIS_VERSION: 10.0.10586.567 amd64fre

THREAD_ATTRIBUTES:
OS_LOCALE: ENA

PROBLEM_CLASSES:



NULL_POINTER_READ
Tid [0xed8]
Frame [0x00]: twinui_appcore!ViewWrapperBase::IsEqual


LAST_CONTROL_TRANSFER: from 00007ff8d03bd959 to 00007ff8d040a58a

STACK_TEXT:
00000000`129ed950 00007ff8`d03bd959 : 00000000`129eda00 00000000`00000000 00000000`129ee078 00007ff8`0a000014 : twinui_appcore!ViewWrapperBase::IsEqual+0x4a
00000000`129ed9a0 00007ff8`d03b9dd2 : 00000000`00000000 00000000`02f35138 00007ff8`d03bd910 00000000`02f169e0 : twinui_appcore!CTaskWindow::IsEqualByView+0x49
00000000`129ed9d0 00007ff8`d03bc259 : 00007ff8`00000000 00007ff8`d03b9bf0 00000000`11d8f680 00000000`00000000 : twinui_appcore!CImmersiveApp::MatchByWindow+0x1e2
00000000`129eda60 00007ff8`d03fce7a : 00000000`02f169d8 00000000`00000000 00000000`00000000 00000000`129edba0 : twinui_appcore!CImmersiveApp::IsEqualByHwnd+0x69
00000000`129edab0 00007ff8`c8823416 : 00007ff8`00000000 00000000`00000000 00000000`129edba0 00000000`8002802b : twinui_appcore!CApplicationViewManager::GetViewForHwnd+0x2fa
00000000`129edb60 00007ff8`e253b0b3 : 00000000`00000000 00000000`00000003 00000000`02f18470 00000000`129edbc0 : twinui!VirtualDesktopsApi::GetWindowDesktopId+0x76
00000000`129edba0 00007ff8`e259d903 : 00000000`129ee078 00000000`129edc00 00000000`129ee070 00007ff8`d54b4be8 : rpcrt4!Invoke+0x73
00000000`129edc00 00007ff8`e252aa8d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : rpcrt4!Ndr64StubWorker+0xbe3
00000000`129ee2c0 00007ff8`e4904b1b : 00000000`00000000 00000000`129ee4e0 00007ff8`d54bdbd0 00000000`00000000 : rpcrt4!NdrStubCall3+0xbd
00000000`129ee330 00007ff8`e49b2582 : 00000000`00000001 00000000`05f307a0 00000000`05e14f20 00000000`00000000 : combase!CStdStubBuffer_Invoke+0x6b
00000000`129ee370 00007ff8`e4980835 : 00000000`00000000 00000000`129ee4f0 00000000`129ee458 00000000`00000000 : combase!ObjectMethodExceptionHandlingAction<<lambda_b8ffcec6d47a5635f374132234a8dd15> >+0x62
00000000`129ee3e0 00007ff8`e496f98e : 00007ff8`d52af440 00000000`009e6850 00000000`05f307a0 00007ff8`c8906a80 : combase!DefaultStubInvoke+0x235
00000000`129ee600 00007ff8`e49718d0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`11d8f700 : combase!ServerCall::ContextInvoke+0x46e
00000000`129ee8d0 00007ff8`e49742bf : 00000000`08c15f80 00000000`08c15f80 00000000`06145180 00000000`00000000 : combase!AppInvoke+0x350
00000000`129eea80 00007ff8`e49733f4 : 00000000`06145328 00000000`06145180 00000000`11e6b190 00000000`11e407a0 : combase!ComInvokeWithLockAndIPID+0x54f
00000000`129eed10 00007ff8`e24d4e93 : 00000000`00000000 00000000`00000000 00007ff8`e49725f0 00007ff8`e49725f0 : combase!ThreadInvoke+0xe04
00000000`129eef80 00007ff8`e24d3b1a : 00007ff8`e4ab97a8 00000000`129ef1e0 00000000`129ef1e0 00000000`11e40650 : rpcrt4!DispatchToStubInCNoAvrf+0x33
00000000`129eefd0 00007ff8`e24d4920 : 00000000`11e46400 00000000`11e407a0 00000000`00000000 00000000`11e46400 : rpcrt4!RPC_INTERFACE::DispatchToStubWorker+0x29a
00000000`129ef0e0 00007ff8`e24e9e68 : 00000000`11e46400 00007ff8`e24d3002 00000000`000000b0 00000000`00000000 : rpcrt4!RPC_INTERFACE::DispatchToStubWithObject+0x160
00000000`129ef180 00007ff8`e24ea91f : 00000000`00038f2c 00007ff8`e24e8b90 00000000`00000000 00000000`00a56fd0 : rpcrt4!LRPC_SCALL::DispatchRequest+0x288
00000000`129ef260 00007ff8`e2518063 : 00000000`00000000 00000000`11e0a9d0 00000000`11e40650 00000000`00000000 : rpcrt4!LRPC_SCALL::HandleRequest+0x8df
00000000`129ef350 00007ff8`e25168d9 : 00000000`00a0b160 00000000`11e0a9d0 00000000`00a0b160 00000000`00a0b160 : rpcrt4!LRPC_SASSOCIATION::HandleRequest+0x1e3
00000000`129ef3d0 00007ff8`e2526ca2 : 00000000`00000000 00000000`00a0b268 00007ff8`e4c2aba0 00007ff8`e25b4ea4 : rpcrt4!LRPC_ADDRESS::ProcessIO+0xb29
00000000`129ef520 00007ff8`e4c2b9a9 : 00000000`00000290 00000000`05e71bc0 00007ff8`e2526bf0 00000000`009c3ad0 : rpcrt4!LrpcIoComplete+0xb2
00000000`129ef5c0 00007ff8`e4c299fe : 00000000`00000006 00000000`00000000 00000000`08b84b90 00000000`00000000 : ntdll!TppAlpcpExecuteCallback+0x239
00000000`129ef670 00007ff8`e2ab2d92 : 00000000`00000000 00007ff8`e4c29110 00000000`009c3ad0 00000000`00000000 : ntdll!TppWorkerThread+0x8ee
00000000`129efa70 00007ff8`e4bf9f64 : 00007ff8`e2ab2d70 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x22
00000000`129efaa0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x34


THREAD_SHA1_HASH_MOD_FUNC: e2aa158c3b41d4a9ecd489afdc7240e21216ae52

THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 31700366030a10505a3d311f2a2b8d2f760d9c82

THREAD_SHA1_HASH_MOD: 5fdabe6d486164bae246de3533b847c4c82a370c

FAULT_INSTR_CODE: 48078b48

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: twinui_appcore!ViewWrapperBase::IsEqual+4a

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: twinui_appcore

IMAGE_NAME: twinui.appcore.dll

DEBUG_FLR_IMAGE_TIMESTAMP: 55b99e01

STACK_COMMAND: .ecxr ; kb

BUCKET_ID: NULL_POINTER_READ_twinui_appcore!ViewWrapperBase::IsEqual+4a

PRIMARY_PROBLEM_CLASS: NULL_POINTER_READ_twinui_appcore!ViewWrapperBase::IsEqual+4a

BUCKET_ID_OFFSET: 4a

BUCKET_ID_MODULE_STR: twinui_appcore

BUCKET_ID_MODTIMEDATESTAMP: 55b99e01

BUCKET_ID_MODCHECKSUM: 20d946

BUCKET_ID_MODVER_STR: 10.0.10240.16412

BUCKET_ID_PREFIX_STR: NULL_POINTER_READ_

FAILURE_PROBLEM_CLASS: NULL_POINTER_READ

FAILURE_EXCEPTION_CODE: c0000005

FAILURE_IMAGE_NAME: twinui.appcore.dll

FAILURE_FUNCTION_NAME: ViewWrapperBase::IsEqual

BUCKET_ID_FUNCTION_STR: ViewWrapperBase::IsEqual

FAILURE_SYMBOL_NAME: twinui.appcore.dll!ViewWrapperBase::IsEqual

FAILURE_BUCKET_ID: NULL_POINTER_READ_c0000005_twinui.appcore.dll!ViewWrapperBase::IsEqual

WATSON_STAGEONE_URL: http://watson.microsoft.com/StageOn...412/55b99e01/c0000005/0005a58a.htm?Retriage=1

TARGET_TIME: 2016-06-17T05:53:50.000Z

OSBUILD: 10240

OSSERVICEPACK: 16384

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK: 256

PRODUCT_TYPE: 1

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

OSEDITION: Windows 10 WinNt SingleUserTS

USER_LCID: 0

OSBUILD_TIMESTAMP: 2015-07-10 13:14:53

BUILDDATESTAMP_STR: 150709-1700

BUILDLAB_STR: th1

BUILDOSVER_STR: 10.0.10240.16384

ANALYSIS_SESSION_ELAPSED_TIME: 3e605

ANALYSIS_SOURCE: UM

FAILURE_ID_HASH_STRING: um:null_pointer_read_c0000005_twinui.appcore.dll!viewwrapperbase::isequal

FAILURE_ID_HASH: {d8f123b0-a23e-0711-10bf-e63f8cd301d1}

Followup: MachineOwner
---------

0:063>
ExceptionAddress: 00007ff8d040a58a (twinui_appcore!ViewWrapperBase::IsEqual+0x000000000000004a)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000000

Version=1
EventType=APPCRASH
EventTime=131106162870820353
ReportType=2
Consent=1
UploadTime=131106162908640911
ReportFlags=524288
ReportIdentifier=876c6eb7-344f-11e6-9bcb-64006a6455a0
IntegratorReportIdentifier=22f8861e-e622-449b-8ba5-3bb1783bf31c
NsAppName=explorer.exe
Response.BucketId=ef8a99e3b9f3022531179c60da8e750a
Response.BucketTable=4
Response.LegacyBucketId=120494267394
Response.type=4
Sig[0].Name=Application Name
Sig[0].Value=explorer.exe
Sig[1].Name=Application Version
Sig[1].Value=10.0.10240.16942
Sig[2].Name=Application Timestamp
Sig[2].Value=5749188e
Sig[3].Name=Fault Module Name
Sig[3].Value=twinui.appcore.dll
Sig[4].Name=Fault Module Version
Sig[4].Value=10.0.10240.16412
Sig[5].Name=Fault Module Timestamp
Sig[5].Value=55b99e01
Sig[6].Name=Exception Code
Sig[6].Value=c0000005
Sig[7].Name=Exception Offset
Sig[7].Value=000000000005a58a
DynamicSig[1].Name=OS Version
DynamicSig[1].Value=10.0.10240.2.0.0.256.4
DynamicSig[2].Name=Locale ID
DynamicSig[2].Value=3081
DynamicSig[22].Name=Additional Information 1
DynamicSig[22].Value=e0cd
DynamicSig[23].Name=Additional Information 2
DynamicSig[23].Value=e0cd5eb3dc42e90b04afadd5f337ec6e
DynamicSig[24].Name=Additional Information 3
DynamicSig[24].Value=af24
DynamicSig[25].Name=Additional Information 4
DynamicSig[25].Value=af24bc6816b45f9086170a1b7668b3f3
UI[2]=C:\WINDOWS\explorer.exe
LoadedModule[0]=C:\WINDOWS\explorer.exe
LoadedModule[1]=C:\WINDOWS\SYSTEM32\ntdll.dll
LoadedModule[2]=C:\WINDOWS\system32\KERNEL32.DLL
LoadedModule[3]=C:\WINDOWS\system32\KERNELBASE.dll
LoadedModule[4]=C:\WINDOWS\system32\apphelp.dll
LoadedModule[5]=C:\WINDOWS\system32\msvcrt.dll
LoadedModule[6]=C:\WINDOWS\system32\OLEAUT32.dll
LoadedModule[7]=C:\WINDOWS\system32\combase.dll
LoadedModule[8]=C:\WINDOWS\system32\RPCRT4.dll
LoadedModule[9]=C:\WINDOWS\system32\powrprof.dll
LoadedModule[10]=C:\WINDOWS\system32\USER32.dll
LoadedModule[11]=C:\WINDOWS\system32\GDI32.dll
LoadedModule[12]=C:\WINDOWS\system32\SHCORE.dll
LoadedModule[13]=C:\WINDOWS\system32\SHLWAPI.dll
LoadedModule[14]=C:\WINDOWS\system32\SHELL32.dll
LoadedModule[15]=C:\WINDOWS\system32\windows.storage.dll
LoadedModule[16]=C:\WINDOWS\system32\advapi32.dll
LoadedModule[17]=C:\WINDOWS\system32\sechost.dll
LoadedModule[18]=C:\WINDOWS\system32\kernel.appcore.dll
LoadedModule[19]=C:\WINDOWS\system32\profapi.dll
LoadedModule[20]=C:\WINDOWS\system32\CRYPT32.dll
LoadedModule[21]=C:\WINDOWS\SYSTEM32\PROPSYS.dll
LoadedModule[22]=C:\WINDOWS\system32\MSASN1.dll
LoadedModule[23]=C:\WINDOWS\SYSTEM32\UxTheme.dll
LoadedModule[24]=C:\WINDOWS\SYSTEM32\dwmapi.dll
LoadedModule[25]=C:\WINDOWS\SYSTEM32\TWINAPI.dll
LoadedModule[26]=C:\WINDOWS\SYSTEM32\d3d11.dll
LoadedModule[27]=C:\WINDOWS\SYSTEM32\dcomp.dll
LoadedModule[28]=C:\WINDOWS\SYSTEM32\SspiCli.dll
LoadedModule[29]=C:\WINDOWS\SYSTEM32\USERENV.dll
LoadedModule[30]=C:\WINDOWS\SYSTEM32\SLC.dll
LoadedModule[31]=C:\WINDOWS\SYSTEM32\dxgi.dll
LoadedModule[32]=C:\WINDOWS\SYSTEM32\sppc.dll
LoadedModule[33]=C:\WINDOWS\system32\IMM32.DLL
LoadedModule[34]=C:\WINDOWS\system32\MSCTF.dll
LoadedModule[35]=C:\WINDOWS\SYSTEM32\bcryptPrimitives.dll
LoadedModule[36]=C:\WINDOWS\system32\ole32.dll
LoadedModule[37]=C:\WINDOWS\system32\clbcatq.dll
LoadedModule[38]=C:\WINDOWS\SYSTEM32\WINSTA.dll
LoadedModule[39]=C:\WINDOWS\SYSTEM32\cryptsp.dll
LoadedModule[40]=C:\WINDOWS\SYSTEM32\bcrypt.dll
LoadedModule[41]=C:\WINDOWS\system32\rsaenh.dll
LoadedModule[42]=C:\WINDOWS\SYSTEM32\CRYPTBASE.dll
LoadedModule[43]=C:\Windows\System32\ActXPrxy.dll
LoadedModule[44]=C:\WINDOWS\System32\IDStore.dll
LoadedModule[45]=C:\WINDOWS\System32\wlidprov.dll
LoadedModule[46]=C:\WINDOWS\SYSTEM32\Bcp47Langs.dll
LoadedModule[47]=C:\WINDOWS\SYSTEM32\SETTINGSYNCPOLICY.dll
LoadedModule[48]=C:\WINDOWS\SYSTEM32\policymanager.dll
LoadedModule[49]=C:\WINDOWS\SYSTEM32\msvcp110_win.dll
LoadedModule[50]=C:\WINDOWS\SYSTEM32\XmlLite.dll
LoadedModule[51]=C:\Windows\System32\TokenBroker.dll
LoadedModule[52]=C:\WINDOWS\SYSTEM32\wintypes.dll
LoadedModule[53]=C:\WINDOWS\SYSTEM32\wtsapi32.dll
LoadedModule[54]=C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll
LoadedModule[55]=C:\WINDOWS\SYSTEM32\SndVolSSO.DLL
LoadedModule[56]=C:\WINDOWS\SYSTEM32\HID.DLL
LoadedModule[57]=C:\WINDOWS\System32\MMDevApi.dll
LoadedModule[58]=C:\WINDOWS\System32\DEVOBJ.dll
LoadedModule[59]=C:\WINDOWS\system32\cfgmgr32.dll
LoadedModule[60]=C:\Windows\System32\iertutil.dll
LoadedModule[61]=C:\WINDOWS\SYSTEM32\mrmcorer.dll
LoadedModule[62]=C:\WINDOWS\SYSTEM32\OLEACC.dll
LoadedModule[63]=C:\Windows\System32\Windows.UI.dll
LoadedModule[64]=C:\Windows\System32\NInput.dll
LoadedModule[65]=C:\Windows\System32\vaultcli.dll
LoadedModule[66]=C:\WINDOWS\SYSTEM32\profext.dll
LoadedModule[67]=C:\WINDOWS\SYSTEM32\NTMARTA.dll
LoadedModule[68]=C:\WINDOWS\system32\dataexchange.dll
LoadedModule[69]=C:\WINDOWS\system32\d2d1.dll
LoadedModule[70]=C:\WINDOWS\system32\twinapi.appcore.dll
LoadedModule[71]=C:\WINDOWS\system32\windowscodecs.dll
LoadedModule[72]=C:\WINDOWS\system32\explorerframe.dll
LoadedModule[73]=C:\WINDOWS\system32\coml2.dll
LoadedModule[74]=C:\Windows\System32\TwinUI.dll
LoadedModule[75]=C:\Windows\System32\Windows.UI.Immersive.dll
LoadedModule[76]=C:\Windows\System32\windows.immersiveshell.serviceprovider.dll
LoadedModule[77]=C:\WINDOWS\SYSTEM32\WLDP.DLL
LoadedModule[78]=C:\WINDOWS\system32\WINTRUST.dll
LoadedModule[79]=C:\WINDOWS\System32\twinui.appcore.dll
LoadedModule[80]=C:\WINDOWS\System32\CoreMessaging.dll
LoadedModule[81]=C:\WINDOWS\System32\CoreUIComponents.dll
LoadedModule[82]=C:\WINDOWS\System32\ApplicationFrame.dll
LoadedModule[83]=C:\WINDOWS\SYSTEM32\elscore.dll
LoadedModule[84]=C:\WINDOWS\SYSTEM32\PhotoMetadataHandler.dll
LoadedModule[85]=C:\WINDOWS\SYSTEM32\rmclient.dll
LoadedModule[86]=C:\WINDOWS\System32\wpncore.dll
LoadedModule[87]=C:\WINDOWS\System32\WINHTTP.dll
LoadedModule[88]=C:\WINDOWS\SYSTEM32\NotificationController.dll
LoadedModule[89]=C:\WINDOWS\SYSTEM32\VEEventDispatcher.dll
LoadedModule[90]=C:\WINDOWS\SYSTEM32\urlmon.dll
LoadedModule[91]=C:\Windows\System32\BitsProxy.dll
LoadedModule[92]=C:\WINDOWS\system32\execmodelproxy.dll
LoadedModule[93]=C:\Windows\System32\Windows.Networking.Connectivity.dll
LoadedModule[94]=C:\WINDOWS\System32\npmproxy.dll
LoadedModule[95]=C:\Windows\System32\IPHLPAPI.DLL
LoadedModule[96]=C:\WINDOWS\system32\NSI.dll
LoadedModule[97]=C:\Windows\System32\WINNSI.DLL
LoadedModule[98]=C:\WINDOWS\SYSTEM32\wlanapi.dll
LoadedModule[99]=C:\Windows\System32\wwapi.dll
LoadedModule[100]=C:\WINDOWS\System32\NotificationObjFactory.dll
LoadedModule[101]=C:\Windows\System32\wcmapi.dll
LoadedModule[102]=C:\Windows\System32\msxml6.dll
LoadedModule[103]=C:\WINDOWS\system32\WS2_32.dll
LoadedModule[104]=C:\WINDOWS\SYSTEM32\ondemandconnroutehelper.dll
LoadedModule[105]=C:\WINDOWS\System32\webio.dll
LoadedModule[106]=C:\WINDOWS\system32\mswsock.dll
LoadedModule[107]=C:\WINDOWS\System32\DNSAPI.dll
LoadedModule[108]=C:\Windows\System32\rasadhlp.dll
LoadedModule[109]=C:\WINDOWS\System32\fwpuclnt.dll
LoadedModule[110]=C:\Windows\System32\AboveLockAppHost.dll
LoadedModule[111]=C:\WINDOWS\system32\schannel.DLL
LoadedModule[112]=C:\WINDOWS\SYSTEM32\ntshrui.dll
LoadedModule[113]=C:\WINDOWS\SYSTEM32\srvcli.dll
LoadedModule[114]=C:\WINDOWS\SYSTEM32\cscapi.dll
LoadedModule[115]=C:\WINDOWS\SYSTEM32\netutils.dll
LoadedModule[116]=C:\Windows\System32\Windows.StateRepository.dll
LoadedModule[117]=C:\Windows\System32\StateRepository.Core.dll
LoadedModule[118]=C:\Windows\System32\thumbcache.dll
LoadedModule[119]=C:\WINDOWS\SYSTEM32\MFPlat.DLL
LoadedModule[120]=C:\WINDOWS\SYSTEM32\RTWorkQ.DLL
LoadedModule[121]=C:\WINDOWS\SYSTEM32\AVRT.dll
LoadedModule[122]=C:\Windows\System32\Windows.Gaming.Input.dll
LoadedModule[123]=C:\WINDOWS\SYSTEM32\LINKINFO.dll
LoadedModule[124]=C:\WINDOWS\system32\NetworkExplorer.dll
LoadedModule[125]=C:\WINDOWS\SYSTEM32\MPR.dll
LoadedModule[126]=C:\WINDOWS\System32\drprov.dll
LoadedModule[127]=C:\WINDOWS\System32\ntlanman.dll
LoadedModule[128]=C:\WINDOWS\System32\davclnt.dll
LoadedModule[129]=C:\WINDOWS\System32\DAVHLPR.dll
LoadedModule[130]=C:\Windows\System32\ieframe.dll
LoadedModule[131]=C:\WINDOWS\SYSTEM32\mskeyprotect.dll
LoadedModule[132]=C:\WINDOWS\SYSTEM32\ncrypt.dll
LoadedModule[133]=C:\WINDOWS\SYSTEM32\NTASN1.dll
LoadedModule[134]=C:\WINDOWS\system32\ncryptsslp.dll
LoadedModule[135]=C:\WINDOWS\SYSTEM32\nvwgf2umx.dll
LoadedModule[136]=C:\WINDOWS\SYSTEM32\WINMM.dll
LoadedModule[137]=C:\WINDOWS\SYSTEM32\VERSION.dll
LoadedModule[138]=C:\WINDOWS\SYSTEM32\WINMMBASE.dll
LoadedModule[139]=C:\WINDOWS\SYSTEM32\gpapi.dll
LoadedModule[140]=C:\WINDOWS\system32\NotificationControllerPS.dll
LoadedModule[141]=C:\WINDOWS\System32\UIAnimation.dll
LoadedModule[142]=C:\WINDOWS\SYSTEM32\DPAPI.DLL
LoadedModule[143]=C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll
LoadedModule[144]=C:\Users\USER\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll
LoadedModule[145]=C:\Users\USER\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\MSVCP120.dll
LoadedModule[146]=C:\Users\USER\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\MSVCR120.dll
LoadedModule[147]=C:\Users\USER\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\LoggingPlatform64.DLL
LoadedModule[148]=C:\WINDOWS\SYSTEM32\WININET.dll
LoadedModule[149]=C:\Users\USER\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
LoadedModule[150]=C:\WINDOWS\SYSTEM32\WSOCK32.dll
LoadedModule[151]=C:\WINDOWS\system32\mssprxy.dll
LoadedModule[152]=C:\WINDOWS\SYSTEM32\dsreg.dll
LoadedModule[153]=C:\WINDOWS\system32\WLDAP32.dll
LoadedModule[154]=C:\WINDOWS\SYSTEM32\samcli.dll
LoadedModule[155]=C:\WINDOWS\SYSTEM32\wkscli.dll
LoadedModule[156]=C:\WINDOWS\SYSTEM32\Secur32.dll
LoadedModule[157]=C:\WINDOWS\SYSTEM32\MLANG.dll
LoadedModule[158]=C:\WINDOWS\system32\stobject.dll
LoadedModule[159]=C:\WINDOWS\system32\BatMeter.dll
LoadedModule[160]=C:\WINDOWS\system32\WMICLNT.dll
LoadedModule[161]=C:\Windows\System32\InputSwitch.dll
LoadedModule[162]=C:\WINDOWS\System32\Windows.UI.Shell.dll
LoadedModule[163]=C:\WINDOWS\System32\wincorlib.DLL
LoadedModule[164]=C:\WINDOWS\system32\es.dll
LoadedModule[165]=C:\WINDOWS\system32\prnfldr.dll
LoadedModule[166]=C:\WINDOWS\system32\WINSPOOL.DRV
LoadedModule[167]=C:\WINDOWS\SYSTEM32\sxs.dll
LoadedModule[168]=C:\WINDOWS\System32\DeviceSetupManagerAPI.dll
LoadedModule[169]=C:\WINDOWS\system32\dxp.dll
LoadedModule[170]=C:\WINDOWS\system32\SETUPAPI.dll
LoadedModule[171]=C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.10240.16603_none_89ad014f9af1a159\gdiplus.dll
LoadedModule[172]=C:\WINDOWS\system32\SHDOCVW.dll
LoadedModule[173]=C:\WINDOWS\SYSTEM32\atlthunk.dll
LoadedModule[174]=C:\WINDOWS\system32\Syncreg.dll
LoadedModule[175]=C:\WINDOWS\System32\Actioncenter.dll
LoadedModule[176]=C:\WINDOWS\System32\wevtapi.dll
LoadedModule[177]=C:\WINDOWS\SYSTEM32\msiltcfg.dll
LoadedModule[178]=C:\WINDOWS\SYSTEM32\msi.dll
LoadedModule[179]=C:\WINDOWS\system32\wpdshserviceobj.dll
LoadedModule[180]=C:\Windows\System32\PortableDeviceTypes.dll
LoadedModule[181]=C:\Windows\System32\PortableDeviceApi.dll
LoadedModule[182]=C:\WINDOWS\system32\SettingMonitor.dll
LoadedModule[183]=C:\WINDOWS\system32\SettingSyncCore.dll
LoadedModule[184]=C:\WINDOWS\System32\cscui.dll
LoadedModule[185]=C:\WINDOWS\System32\CSCDLL.dll
LoadedModule[186]=C:\WINDOWS\System32\cscobj.dll
LoadedModule[187]=C:\WINDOWS\System32\srchadmin.dll
LoadedModule[188]=C:\WINDOWS\System32\SyncCenter.dll
LoadedModule[189]=C:\Windows\System32\imapi2.dll
LoadedModule[190]=C:\WINDOWS\SYSTEM32\AUDIOSES.DLL
LoadedModule[191]=C:\WINDOWS\system32\authui.dll
LoadedModule[192]=C:\WINDOWS\System32\pnidui.dll
LoadedModule[193]=C:\WINDOWS\system32\NetworkStatus.dll
LoadedModule[194]=C:\Windows\System32\NetSetupShim.dll
LoadedModule[195]=C:\Windows\System32\NetSetupApi.dll
LoadedModule[196]=C:\WINDOWS\System32\hgcpl.dll
LoadedModule[197]=C:\WINDOWS\System32\DUser.dll
LoadedModule[198]=C:\WINDOWS\System32\provsvc.dll
LoadedModule[199]=C:\WINDOWS\System32\netprofm.dll
LoadedModule[200]=C:\Windows\System32\bthprops.cpl
LoadedModule[201]=C:\Windows\System32\BluetoothApis.dll
LoadedModule[202]=C:\Windows\System32\dhcpcsvc6.DLL
LoadedModule[203]=C:\Windows\System32\dhcpcsvc.DLL
State[0].Key=Transport.DoneStage1
State[0].Value=1
FriendlyEventName=Stopped working
ConsentKey=APPCRASH
AppName=Windows Explorer
AppPath=C:\WINDOWS\explorer.exe
NsPartner=windows
NsGroup=windows8
ApplicationIdentity=92F607A4965196D26152B7C5C0C0A8C0

Chris

More...
 
Back
Top