I did another 2 hour 15 minutes listening to the same radio station on Sunday afternoon. ( when America is in bed ). I checked the expert info after 1 hour 45 mins of capture and had NO malformed packets and NO packets listed as DCERPC packets.
Total captured packets from the same radio station during this time was 644,000 packets.
Stats on this data were:
Previous segment lost > 3414 counts
Out of order segments > 206 counts
Fast retransmissions > 1965 counts
Wireshark was seriously struggling at 2 hour 15 minutes of capture. The live capture display window was 17 minutes behind the actual time. It took another 17 minutes or so to stop the capture after I hit the stop capture command. I aborted the save command since my computer was struggling doing the save. The file created was over 226MB in size.
Looks like my computer needs more memory
My conclusions are that the original DCERPC packets are to be treated as suspect but I doubt if they were the actual cause of Wireshark crashing. I reckon that was down to the original capture file being too large.