Thanks auggy. I just made the change. I will report back and post the dump when it occurs: My crashes are pretty irregular: sometimes as much as a week before it happens.
Again thanks for the suggestion.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi:
I have periodic explorer crashes on my Surface Pro 2017, Win Pro x64 (it is fully updated). The crash seems to occur periodically after a Hello Windows log-in (this occurs after the computer was sleeping rather than on a fresh boot). It seems to involve Windows.UI.XamlHost.dll based on the below.
When I look in the Event viewer I see errors like this:
Event ID 1000
Faulting application name: explorer.exe, version: 10.0.16299.125, time stamp: 0xfeba44fb
Faulting module name: Windows.UI.XamlHost.dll, version: 10.0.16299.15, time stamp: 0x00f27b8f
Exception code: 0xc0000409
Fault offset: 0x0000000000001db1
Faulting process id: 0x1880
Faulting application start time: 0x01d38282e4131af4
Faulting application path: C:\WINDOWS\explorer.exe
Faulting module path: C:\Windows\System32\Windows.UI.XamlHost.dll
Report Id: 6e835576-b35e-4d24-b6ce-331b05fa2c55
Faulting package full name:
Faulting package-relative application ID:
If I click on Start > type "view all" then click on "View all problem reports Control panel" the "Windows Explorer" "Stopped working" errors and then double click on one I would get something like this:
Source
Windows Explorer
Summary
Stopped working
Date
11/26/2017 10:53 AM
Status
Report sent
Description
Faulting Application Path: C:\Windows\explorer.exe
Problem signature
Problem Event Name: BEX64
Application Name: Explorer.EXE
Application Version: 10.0.16299.15
Application Timestamp: 66e02565
Fault Module Name: Windows.UI.XamlHost.dll
Fault Module Version: 10.0.16299.15
Fault Module Timestamp: 00f27b8f
Exception Offset: 0000000000001db1
Exception Code: c0000409
Exception Data: 0000000000000007
OS Version: 10.0.16299.2.0.0.256.48
Locale ID: 1033
Additional Information 1: 2eb9
Additional Information 2: 2eb9591f0e04c7cfea277e3f34d3348f
Additional Information 3: 9333
Additional Information 4: 9333781589f3ec46cd357f0fda06eea0
Extra information about the problem
Bucket ID: 15f01e3e317a50b7b6bb92d1b9fc4f7c (116455065336)
I am at a loss to understand what the problem is here. I am glad to disable Hello Windows if this would end the problem. Thanks in advance for any help on this!
[Moved from: Windows / Windows 10 / Windows Hello, lock screen & sign-in]
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Thanks auggy. I just made the change. I will report back and post the dump when it occurs: My crashes are pretty irregular: sometimes as much as a week before it happens.
Again thanks for the suggestion.
Hi,
It may help to obtain a user mode dump of the Explorer crash to get more information on the crash.
You can configure Windows to create user-mode dumps. Create a System Restore Point first.
If you copy and paste the following in Notepad and save as a .reg file (save with the .reg extension and give it any name such as dump.reg), then right-click the .reg file and select "Merge" to add to the registry, a .dmp file at the time explorer.exe crashes should be created in the C:\CrashDumps folder:
Windows Registry Editor Version 5.00[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\explorer.exe]"DumpFolder"=hex(2):43,00,3a,00,5c,00,43,00,72,00,61,00,73,00,68,00,44,00,75,\00,6d,00,70,00,73,00,00,00
After Explorer (explorer.exe) crashes, can you then make the .dmp file available (provide link) via a public folder on OneDrive or similar site?
Here's a link on using OneDrive:
http://windows.microsoft.com/en-ca/onedrive/share-file-folder
More info on collecting user-mode dumps:
http://msdn.microsoft.com/en-us/library/bb787181(VS.85).aspx
To stop the creation of the user mode dump files run the following registry file:
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\explorer.exe]
You can delete the C:\CrashDumps folder anytime.
No help. Same exact error.
Rather than these generic suggestions lets start by having a specific definition of what this "Windows.UI.XamlHost.dll" module is. It is clearly the source of the problem.
As an aside, every time I checked after this error Edge is unresponsive and has to be restarted via the task manager. I am not sure if this is a cause or effect.
Based on the analysis that you've provided, the cause of the crash is different. To isolate if this is caused by a corrupted user profile, it is better to create a new user account and check if the crash occurs. Click this link on how to create a local user or administrator account in Windows 10.
Keep us in the loop with the result.
Also from analysis of Edge minidump (MicrosoftEdgeCP.exe.mini.****.dmp):
FAULTING_IP:
EdgeContent!wil::details::ReportFailure+3d597
00007ffa`e4722243 cd29 int 29h
EXCEPTION_RECORD: ffffffffffffffff -- (.exr 0xffffffffffffffff)
ExceptionAddress: 00007ffae4722243 (EdgeContent!wil::details::ReportFailure+0x000000000003d597)
ExceptionCode: c0000409 (Stack buffer overflow)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000007
PROCESS_NAME: MicrosoftEdgeCP.exe
ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
EXCEPTION_PARAMETER1: 0000000000000007
NTGLOBALFLAG: 0
APPLICATION_VERIFIER_FLAGS: 0
FAULTING_THREAD: 0000000000004cc4
BUGCHECK_STR: APPLICATION_FAULT_STACK_BUFFER_OVERRUN_MISSING_GSFRAME_SEHOP
PRIMARY_PROBLEM_CLASS: STACK_BUFFER_OVERRUN_SEHOP
DEFAULT_BUCKET_ID: STACK_BUFFER_OVERRUN_SEHOP
LAST_CONTROL_TRANSFER: from 00007ffae46e4ca4 to 00007ffae4722243
STACK_TEXT:
000000f051efe8b0 00007ffae46e4ca4 : 0000000000000000 00007ffae46a7270 0000000000000000 0000000000000000 : EdgeContent!wil::details::ReportFailure+0x3d597
000000f051effdf0 00007ffae4702509 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : EdgeContent!wil::details::ReportFailure_Hr+0x44
000000f051effe50 00007ffae472319e : 0000022a13c2be20 0000000000000000 0000000000000000 0000000000000000 : EdgeContent!wil::details::in1diag3::FailFast_Hr+0x29
000000f051effea0 00007ffb061e1fe4 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : EdgeContent!`anonymous namespace'::MemoryLimitWatchdogThreadProc+0x3b43e
000000f051efff30 00007ffb08d6ef91 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : kernel32!BaseThreadInitThunk+0x14
000000f051efff60 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : ntdll!RtlUserThreadStart+0x21
FOLLOWUP_IP:
EdgeContent!wil::details::ReportFailure+3d597
00007ffa`e4722243 cd29 int 29h
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: EdgeContent!wil::details::ReportFailure+3d597
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: EdgeContent
IMAGE_NAME: EdgeContent.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 0
STACK_COMMAND: ~4s ; kb
FAILURE_BUCKET_ID: STACK_BUFFER_OVERRUN_SEHOP_c0000409_EdgeContent.dll!wil::details::ReportFailure
BUCKET_ID: X64_APPLICATION_FAULT_STACK_BUFFER_OVERRUN_MISSING_GSFRAME_SEHOP_MISSING_GSFRAME_EdgeContent!wil::details::ReportFailure+3d597
WATSON_STAGEONE_URL: http://watson.microsoft.com/00082243.htm?Retriage=1