Debugging 0:019> lmvm PfShellExtension
start end module name
000007fe`e80c0000 000007fe`e80dd000 PfShellExtension (export symbols) PfShellExtension.dll
Loaded symbol image file: PfShellExtension.dll
Mapped memory image file: C:\Program Files (x86)\IObit\Protected Folder\PfShellExtension.dll
Caused by: Image path:
C:\Program Files (x86)\IObit\Protected Folder\PfShellExtension.dllAPPLICATION_FAULT_ACTIONABLE_HEAP_CORRUPTION_heap_failure_buffer_overrun
Image name: PfShellExtension.dll
Timestamp: Mon Nov 19 05:54:49 2012 (50A9BB99)
CheckSum: 00021AA6
ImageSize: 0001D000
File version: 4.2.0.0
Product version: 1.2.0.0
File flags: 0 (Mask 3F)
File OS: 4 Unknown Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04e4
CompanyName: IObit
ProductName: Protected Folder
InternalName: PfShellExtension.dll
OriginalFilename: PfShellExtension.dll
ProductVersion: 1.2.0.0
FileVersion: 4.2.0.0
FileDescription: Protected Folder Shell Extension
LegalCopyright: Copyright© 2005-2012
LegalTrademarks: IObit
FAULTING_IP:
ntdll!RtlReportCriticalFailure+62
00000000`76e3ffc2 eb00 jmp ntdll!RtlReportCriticalFailure+0x64 (00000000`76e3ffc4)
EXCEPTION_RECORD: ffffffffffffffff -- (.exr 0xffffffffffffffff)
ExceptionAddress: 0000000076e3ffc2 (ntdll!RtlReportCriticalFailure+0x0000000000000062)
ExceptionCode: c0000374
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000076eb7470
CONTEXT: 0000000000000000 -- (.cxr 0x0;r)
rax=0000000002520000 rbx=00000000000005e8 rcx=0000000002520000
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=0000000076dcd9fa rsp=0000000003a4b5c8 rbp=ffffffffffffffff
r8=0000000000000000 r9=0000000000000040 r10=0000000000000000
r11=0000000000000286 r12=0000000076eaa678 r13=0000000002510000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000206
ntdll!ZwWaitForSingleObject+0xa:
00000000`76dcd9fa c3 ret
PROCESS_NAME: explorer.exe
ERROR_CODE: (NTSTATUS) 0xc0000374 - Sterta zosta
EXCEPTION_CODE: (NTSTATUS) 0xc0000374 - Sterta zosta
EXCEPTION_PARAMETER1: 0000000076eb7470
NTGLOBALFLAG: 0
APPLICATION_VERIFIER_FLAGS: 0
APP: explorer.exe
ANALYSIS_VERSION: 6.3.9600.17336 (debuggers(dbg).150226-1500) amd64fre
LAST_CONTROL_TRANSFER: from 0000000076e40606 to 0000000076e3ffc2
FAULTING_THREAD: ffffffffffffffff
BUGCHECK_STR: APPLICATION_FAULT_ACTIONABLE_HEAP_CORRUPTION_heap_failure_buffer_overrun
PRIMARY_PROBLEM_CLASS: ACTIONABLE_HEAP_CORRUPTION_heap_failure_buffer_overrun
DEFAULT_BUCKET_ID: ACTIONABLE_HEAP_CORRUPTION_heap_failure_buffer_overrun
STACK_TEXT:
00000000`76eb74d8 00000000`76dda7e9 ntdll!RtlpFreeHeap+0x1649
00000000`76eb74e0 00000000`76c81a7a kernel32!HeapFree+0xa
00000000`76eb74e8 000007fe`e80c66f0 pfshellextension!DllInstall+0x750
00000000`76eb74f0 000007fe`e80c33e8 pfshellextension+0x33e8
00000000`76eb74f8 000007fe`e80c4609 pfshellextension+0x4609
00000000`76eb7500 000007fe`fdf4f28a shell32!HDXA_QueryContextMenu+0x454
00000000`76eb7508 000007fe`fdf4ec05 shell32!CDefFolderMenu::QueryContextMenu+0x625
00000000`76eb7510 000007fe`fe17d3e9 shell32!CDefView::_DoContextMenuPopup+0x19d
00000000`76eb7518 000007fe`fe17dad9 shell32!CDefView::OnSelectionContextMenu+0x109
00000000`76eb7520 000007fe`f241167b explorerframe!UIItemsView::ShowContextMenu+0x303
00000000`76eb7528 000007fe`f240b6f3 explorerframe!CItemsView::ShowContextMenu+0x17
00000000`76eb7530 000007fe`fe184220 shell32!CDefView::_OnContextMenu+0x110
00000000`76eb7538 000007fe`fe0bed6f shell32!CDefView::WndProc+0x889
00000000`76eb7540 000007fe`fdfa0cc7 shell32!CDefView::s_WndProc+0x7c
00000000`76eb7548 00000000`76b79c11 user32!UserCallWinProcCheckWow+0x1ad
00000000`76eb7550 00000000`76b73bd4 user32!CallWindowProcAorW+0xdc
00000000`76eb7558 00000000`76b73b50 user32!CallWindowProcW+0x18
00000000`76eb7560 000007fe`fad81a0b duser!WndBridge::RawWndProc+0xd9
00000000`76eb7568 00000000`76b79c11 user32!UserCallWinProcCheckWow+0x1ad
00000000`76eb7570 00000000`76b772f7 user32!DispatchClientMessage+0xe1
00000000`76eb7578 00000000`76b76839 user32!_fnDWORD+0x2d
00000000`76eb7580 00000000`76dcd8f5 ntdll!KiUserCallbackDispatcherContinue+0x0
00000000`76eb7588 00000000`76b7686a user32!ZwUserMessageCall+0xa
00000000`76eb7590 00000000`76b768b2 user32!RealDefWindowProcWorker+0xa4
00000000`76eb7598 00000000`76b7763a user32!RealDefWindowProcW+0x5a
00000000`76eb75a0 000007fe`fb0f1644 uxtheme!_ThemeDefWindowProc+0x278
00000000`76eb75a8 000007fe`fb0f1445 uxtheme!ThemeDefWindowProcW+0x11
00000000`76eb75b0 00000000`76b789f7 user32!DefWindowProcW+0xe6
00000000`76eb75b8 000007fe`f23bbc6e explorerframe!UIItemsView::WndProc+0x37b
00000000`76eb75c0 000007fe`fadd153a dui70!DirectUI::HWNDElement::StaticWndProc+0x59
00000000`76eb75c8 00000000`76b79c11 user32!UserCallWinProcCheckWow+0x1ad
00000000`76eb75d0 00000000`76b73bd4 user32!CallWindowProcAorW+0xdc
FOLLOWUP_IP:
PfShellExtension!DllInstall+750
000007fe`e80c66f0 85c0 test eax,eax
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: pfshellextension!DllInstall+750
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: PfShellExtension
IMAGE_NAME: PfShellExtension.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 50a9bb99
STACK_COMMAND: dps 76eb74d8 ; kb
FAILURE_BUCKET_ID: ACTIONABLE_HEAP_CORRUPTION_heap_failure_buffer_overrun_c0000374_PfShellExtension.dll!DllInstall
BUCKET_ID: X64_APPLICATION_FAULT_ACTIONABLE_HEAP_CORRUPTION_heap_failure_buffer_overrun_pfshellextension!DllInstall+750
ANALYSIS_SOURCE: UM
FAILURE_ID_HASH_STRING: um:actionable_heap_corruption_heap_failure_buffer_overrun_c0000374_pfshellextension.dll!dllinstall
FAILURE_ID_HASH: {b087f7e1-7aa5-da03-8884-0f3500890282}
Followup: MachineOwner
---------