Surface Pro 2017, Win 10 Pro x64: Explorer crash (Windows.UI.XamlHost.dll)

Anonymous
2018-01-04T03:56:25+00:00

Hi:

I have periodic explorer crashes on my Surface Pro 2017, Win Pro x64 (it is fully updated). The crash seems to occur periodically after a Hello Windows log-in (this occurs after the computer was sleeping rather than on a fresh boot). It seems to involve Windows.UI.XamlHost.dll based on the below.

When I look in the Event viewer I see errors like this:

Event ID 1000

Faulting application name: explorer.exe, version: 10.0.16299.125, time stamp: 0xfeba44fb

Faulting module name: Windows.UI.XamlHost.dll, version: 10.0.16299.15, time stamp: 0x00f27b8f

Exception code: 0xc0000409

Fault offset: 0x0000000000001db1

Faulting process id: 0x1880

Faulting application start time: 0x01d38282e4131af4

Faulting application path: C:\WINDOWS\explorer.exe

Faulting module path: C:\Windows\System32\Windows.UI.XamlHost.dll

Report Id: 6e835576-b35e-4d24-b6ce-331b05fa2c55

Faulting package full name:

Faulting package-relative application ID:

If I click on Start > type "view all" then click on "View all problem reports Control panel" the "Windows Explorer" "Stopped working" errors and then double click on one I would get something like this:

Source

Windows Explorer

Summary

Stopped working

Date

‎11/‎26/‎2017 10:53 AM

Status

Report sent

Description

Faulting Application Path: C:\Windows\explorer.exe

Problem signature

Problem Event Name: BEX64

Application Name: Explorer.EXE

Application Version: 10.0.16299.15

Application Timestamp: 66e02565

Fault Module Name: Windows.UI.XamlHost.dll

Fault Module Version: 10.0.16299.15

Fault Module Timestamp: 00f27b8f

Exception Offset: 0000000000001db1

Exception Code: c0000409

Exception Data: 0000000000000007

OS Version: 10.0.16299.2.0.0.256.48

Locale ID: 1033

Additional Information 1: 2eb9

Additional Information 2: 2eb9591f0e04c7cfea277e3f34d3348f

Additional Information 3: 9333

Additional Information 4: 9333781589f3ec46cd357f0fda06eea0

Extra information about the problem

Bucket ID: 15f01e3e317a50b7b6bb92d1b9fc4f7c (116455065336)

I am at a loss to understand what the problem is here. I am glad to disable Hello Windows if this would end the problem. Thanks in advance for any help on this!

[Moved from: Windows / Windows 10 / Windows Hello, lock screen & sign-in]

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

68 answers

Sort by: Newest
  1. Anonymous
    2018-03-02T22:58:49+00:00

    Thanks auggy that is my next step.

    I am going to try a few more small tweaks with some reboots, though pretty sure that will not help. Then it is a repair. Ugh I guess I will basically be starting over from scratch, reinstalling everything.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-03-02T03:12:48+00:00

    The error is still caused by the Windows.UI.XamlHost.dll :

    *** ERROR: Symbol file could not be found.  Defaulted to export symbols for sppc.dll -

    GetUrlPageData2 (WinHttp) failed: 12002.

    Probably caused by : Windows.UI.XamlHost.dll ( Windows_UI_XamlHost!wil::details::ReportFailure+e5 )

    I would still recommend a repair of Windows as the SFC may not be infallible or the issue may be outside the scope of the SFC.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-03-01T15:43:41+00:00

    I am not sure if anyone is following this thread but another explorer crash (I mean I did get a whole three days without one).

    Does anyone know if there is a way to contact Microsoft to get support? 

    crash dump: https://1drv.ms/u/s!AoMjGh2ERllBdHPnkaxHmDOpilM

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-02-27T05:07:25+00:00

    Sorry one more item:

    It seems *every* time the Surface goes through the Hello Windows login I get an Event ID 10016 error in the event viewer: they are of the form listed below. I have 2000 of these (!) since November. No clue if this is related to my problem but this cannot be a good sign. Anyone know what these are?

    Log Name:      System

    Source:        Microsoft-Windows-DistributedCOM

    Date:          2/27/2018 12:03:51 AM

    Event ID:      10016

    Task Category: None

    Level:         Error

    Keywords:      Classic

    User:          LOCAL SERVICE

    Computer:      DESKTOP-UHI1BND

    Description:

    The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 

    {D63B10C5-BB46-4990-A94F-E40B9D520160}

     and APPID 

    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}

     to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

      <System>

        <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />

        <EventID Qualifiers="0">10016</EventID>

        <Version>0</Version>

        <Level>2</Level>

        <Task>0</Task>

        <Opcode>0</Opcode>

        <Keywords>0x8080000000000000</Keywords>

        <TimeCreated SystemTime="2018-02-27T05:03:51.565362000Z" />

        <EventRecordID>11427</EventRecordID>

        <Correlation />

        <Execution ProcessID="876" ThreadID="8028" />

        <Channel>System</Channel>

        <Computer>DESKTOP-UHI1BND</Computer>

        <Security UserID="S-1-5-19" />

      </System>

      <EventData>

        <Data Name="param1">application-specific</Data>

        <Data Name="param2">Local</Data>

        <Data Name="param3">Activation</Data>

        <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>

        <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>

        <Data Name="param6">NT AUTHORITY</Data>

        <Data Name="param7">LOCAL SERVICE</Data>

        <Data Name="param8">S-1-5-19</Data>

        <Data Name="param9">LocalHost (Using LRPC)</Data>

        <Data Name="param10">Unavailable</Data>

        <Data Name="param11">Unavailable</Data>

      </EventData>

    </Event>

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-02-27T03:48:11+00:00

    Oh and sorry one other confusion:

    if there is an issue with windows should this not come up with a system file check?

    I just did it again and all is clean:

    C:\WINDOWS\system32>sfc /scannow

    Beginning system scan.  This process will take some time.

    Beginning verification phase of system scan.

    Verification 100% complete.

    Windows Resource Protection did not find any integrity violations

    Was this answer helpful?

    0 comments No comments