Fix Explorer Crashes Linked To Shell Extension Malware
A sudden File Explorer crash can indicate a damaged Windows component, a faulty context-menu utility, or malicious code loaded through a shell extension. The problem often appears when opening folders, right-clicking files, viewing thumbnails, or connecting a USB drive.
Shell extension malware is especially disruptive because Explorer loads these components automatically. A careful process can separate a defective third-party add-on from a trojan, worm, spyware component, or browser-related infection without immediately deleting important system files.
Recognise The Crash Pattern
Note what happens immediately before Explorer closes. A crash only when right-clicking a ZIP file may point to a context-menu handler, while failures when opening image folders can involve thumbnail providers or preview handlers. If crashes began after installing a free utility, codec pack, PDF tool, or unofficial driver, that software deserves attention.
Check whether Windows displays an error such as “Windows Explorer has stopped working” or restarts explorer.exe without a message. Reliability Monitor can provide useful clues: press Start, search for “reliability”, and inspect application failures involving Explorer or a named DLL. Event Viewer under Windows Logs and Application may also identify the extension involved.
Protect Files Before Making Changes
Copy essential documents, photos and work files to an external drive or a trusted cloud account before removing anything. If the computer is used for tax records, client information or small-business accounts in Sydney, Melbourne or elsewhere, avoid opening sensitive files while the system may be infected. Disconnecting from the internet during manual cleanup can limit remote access and additional downloads.
Create a restore point if Windows remains stable enough, but do not treat System Restore as a complete malware remedy. Record suspicious filenames, installation dates and digital publishers. Avoid uploading private documents or unknown business files to public scanning services, since doing so may create a separate privacy issue under Australia’s Privacy Act.
Isolate The Suspicious Extension
Start Windows in Safe Mode, where many third-party shell components are not loaded. From Settings, open System, Recovery and Advanced startup, then choose Restart now. Select Troubleshoot, Advanced options, Startup Settings and Restart, followed by the Safe Mode option. If Explorer is too unstable, the same recovery environment can be reached from the sign-in screen by holding Shift while selecting Restart.
In Safe Mode, uninstall recently added software through Apps rather than deleting random DLL files. Microsoft’s Autoruns and reputable shell-extension viewers can reveal non-Microsoft handlers, but download them from official sources and review each entry carefully. Disable a suspicious item first, restart normally, and test Explorer. Registry locations such as HKEY_CLASSES_ROOT\*\shellex and HKEY_CLASSES_ROOT\Directory\shellex should be edited only after exporting a backup.
| Finding |
Safer response |
What it may indicate |
| Crash follows a recent utility installation |
Uninstall or disable that utility |
Buggy or incompatible extension |
| Unknown publisher loads from AppData or Temp |
Scan, quarantine and investigate the file |
Possible trojan or persistence mechanism |
| Explorer crashes only during right-click actions |
Disable context-menu handlers in batches |
Damaged menu integration |
| Crashes continue in Safe Mode |
Repair Windows and run offline scans |
System corruption or deeper infection |
Scan For The Underlying Threat
Return to normal Windows only long enough to update security tools from trusted sources. Run Microsoft Defender’s Full scan, followed by Defender Offline if malicious software appears persistent. Offline scanning is useful because it checks the system before normal startup processes can conceal files or restart them.
A second-opinion scan can identify threats missed by a single engine. For a coordinated workflow, use this guide to combine Malwarebytes and HitmanPro, then quarantine detections and restart when instructed. Do not run several real-time antivirus products simultaneously, as they can interfere with each other.
Repair Windows After Removal
Once suspicious software has been quarantined, open Windows Terminal or Command Prompt as administrator and run sfc /scannow. This checks protected Windows files and replaces corrupted versions. If SFC reports that it could not repair everything, run:
DISM /Online /Cleanup-Image /RestoreHealth
Restart the computer and run SFC again. If Explorer still fails, create a temporary local Windows account and test it there. A clean profile suggests damaged user settings or per-user shell registrations rather than a system-wide problem. Resetting folder view settings or removing a recently installed cloud-storage integration may then resolve the remaining crashes.
Confirm Recovery And Reduce Risk
Test common Explorer actions: opening Downloads, browsing network folders, right-clicking files, viewing images, extracting an archive and attaching a document to an email. Re-enable disabled extensions one at a time, restarting after each change. Restore only entries with a known publisher, a legitimate installation source and a clear purpose.
Keep Windows, browsers and archive utilities patched, and avoid pirated software or “crack” activators frequently distributed with malware. Australian users should also be cautious with unsolicited parcel, banking and myGov-themed downloads, especially when using shared NBN connections or public Wi-Fi. If the infection involved a self-spreading network component, background reading on worm threats can help explain how it moved between devices.
Enable Microsoft Defender, use standard user accounts for everyday work, and maintain offline backups that are disconnected after use. For a business affected in Perth, Canberra or another Australian location, preserve logs and seek qualified incident-response advice before wiping devices; this can support reporting obligations and help determine whether personal information was exposed.