Surface Pro 2017, Win 10 Pro x64: Explorer crash (Windows.UI.XamlHost.dll)

Anonymous
2018-01-04T03:56:25+00:00

Hi:

I have periodic explorer crashes on my Surface Pro 2017, Win Pro x64 (it is fully updated). The crash seems to occur periodically after a Hello Windows log-in (this occurs after the computer was sleeping rather than on a fresh boot). It seems to involve Windows.UI.XamlHost.dll based on the below.

When I look in the Event viewer I see errors like this:

Event ID 1000

Faulting application name: explorer.exe, version: 10.0.16299.125, time stamp: 0xfeba44fb

Faulting module name: Windows.UI.XamlHost.dll, version: 10.0.16299.15, time stamp: 0x00f27b8f

Exception code: 0xc0000409

Fault offset: 0x0000000000001db1

Faulting process id: 0x1880

Faulting application start time: 0x01d38282e4131af4

Faulting application path: C:\WINDOWS\explorer.exe

Faulting module path: C:\Windows\System32\Windows.UI.XamlHost.dll

Report Id: 6e835576-b35e-4d24-b6ce-331b05fa2c55

Faulting package full name:

Faulting package-relative application ID:

If I click on Start > type "view all" then click on "View all problem reports Control panel" the "Windows Explorer" "Stopped working" errors and then double click on one I would get something like this:

Source

Windows Explorer

Summary

Stopped working

Date

‎11/‎26/‎2017 10:53 AM

Status

Report sent

Description

Faulting Application Path: C:\Windows\explorer.exe

Problem signature

Problem Event Name: BEX64

Application Name: Explorer.EXE

Application Version: 10.0.16299.15

Application Timestamp: 66e02565

Fault Module Name: Windows.UI.XamlHost.dll

Fault Module Version: 10.0.16299.15

Fault Module Timestamp: 00f27b8f

Exception Offset: 0000000000001db1

Exception Code: c0000409

Exception Data: 0000000000000007

OS Version: 10.0.16299.2.0.0.256.48

Locale ID: 1033

Additional Information 1: 2eb9

Additional Information 2: 2eb9591f0e04c7cfea277e3f34d3348f

Additional Information 3: 9333

Additional Information 4: 9333781589f3ec46cd357f0fda06eea0

Extra information about the problem

Bucket ID: 15f01e3e317a50b7b6bb92d1b9fc4f7c (116455065336)

I am at a loss to understand what the problem is here. I am glad to disable Hello Windows if this would end the problem. Thanks in advance for any help on this!

[Moved from: Windows / Windows 10 / Windows Hello, lock screen & sign-in]

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

68 answers

Sort by: Newest
  1. Anonymous
    2018-02-27T03:20:29+00:00

    Guess it is not edge since I just got another explorer crash (I will note chrome does continue to work after the crash).

    Crash dump: https://1drv.ms/u/s!AoMjGh2ERllBc8EKXkv6nN8BqYk

    overview of crash dump below

    I guess I have to repair Windows as auggy suggested. I assume refresh is what you mean from the link you provided? This very much sucks. It is basically reinstalling everything. I just cannot believe there is no way to understand what is the exact source of this problem. There must be some root cause.

    overview of crashdump:

    FAULTING_IP: 
    Windows_UI_XamlHost!wil::details::ReportFailure+e5
    00007ffa`c8cf1db1 cd29            int     29h
    
    EXCEPTION_RECORD:  ffffffffffffffff -- (.exr 0xffffffffffffffff)
    ExceptionAddress: 00007ffac8cf1db1 (Windows_UI_XamlHost!wil::details::ReportFailure+0x00000000000000e5)
       ExceptionCode: c0000409 (Stack buffer overflow)
      ExceptionFlags: 00000001
    NumberParameters: 1
       Parameter[0]: 0000000000000007
    
    PROCESS_NAME:  explorer.exe
    
    ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application.  This  overrun could potentially allow a malicious user to gain control of this application.
    
    EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application.  This  overrun could potentially allow a malicious user to gain control of this application.
    
    EXCEPTION_PARAMETER1:  0000000000000007
    
    NTGLOBALFLAG:  0
    
    APPLICATION_VERIFIER_FLAGS:  0
    
    FAULTING_THREAD:  00000000000001f4
    
    BUGCHECK_STR:  APPLICATION_FAULT_STACK_BUFFER_OVERRUN_MISSING_GSFRAME_SEHOP
    
    PRIMARY_PROBLEM_CLASS:  STACK_BUFFER_OVERRUN_SEHOP
    
    DEFAULT_BUCKET_ID:  STACK_BUFFER_OVERRUN_SEHOP
    
    LAST_CONTROL_TRANSFER:  from 00007ffac8cf1e09 to 00007ffac8cf1db1
    
    STACK_TEXT:  
    00000000`61e5e740 00007ffa`c8cf1e09 : 0000e4e3`e46767ce 00000000`00000000 00000000`00000000 00007ffa`c8cf9fd8 : Windows_UI_XamlHost!wil::details::ReportFailure+0xe5
    00000000`61e5fc80 00007ffa`c8d08d59 : 00000000`285c6a90 00000000`21105fa0 00000037`00000011 00000000`21197fc0 : Windows_UI_XamlHost!wil::details::ReportFailure_Hr+0x39
    00000000`61e5fce0 00007ffa`c8d028fb : 00000000`00000000 00000000`21105ac0 00000000`21484750 00000000`0000c000 : Windows_UI_XamlHost!wil::details::in1diag3::_FailFast_Hr+0x29
    00000000`61e5fd30 00007ffa`c8d0946c : 00000000`21198030 00000000`00000000 00000000`00000000 00000000`00000000 : Windows_UI_XamlHost!Microsoft::WRL::SimpleActivationFactory::ActivateInstance+0x34b
    00000000`61e5fd60 00007ffa`d5a1d544 : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`00000000 : Windows_UI_XamlHost!ASTAThreadHost::s_ASTAThreadHostStartThreadProc+0x6c
    00000000`61e5fd90 00007ffa`d5ad1fe4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : SHCore!_WrapperThreadProc+0xc4
    00000000`61e5fe70 00007ffa`d633efc1 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x14
    00000000`61e5fea0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x21
    

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-02-22T23:52:38+00:00

    Thanks auggy.

    Explorer just crashed again (or at least all folders closed) and yet there was no crashdump.

    I have concluded this is due to Edge browser. I am installing Chrome and will stop using Edge. I am hopeful that will work. Honestly this is one of the worst computers I have ever owned. I so regret not buying a Dell or Lenovo.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-02-22T13:38:50+00:00

    As the Windows.UI.XamlHost.dll appears to be at the latest version the issue may be with the Windows.UI.XamlHost.dll itself so I would suggest at this point to do a "repair" installation of Windows:

    https://www.tenforums.com/tutorials/16397-repair-install-windows-10-place-upgrade.html

    As a general precaution back up any critical files prior to attempting a repair.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-02-21T15:50:40+00:00

    Another three days another explorer crash.

    Here is the crash dump: https://1drv.ms/u/s!AoMjGh2ERllBcv2MJby9acqVBGQ

    Of course it is the exact same problem (some details below).

    Just as with every time this has happened, Edge browser is unresponsive just after. I am 100% sure these are two sides of the same problem. Is there anyway to put Edge in some kind of safe mode (or perhaps it needs a special upgrade or perhaps I could install it)?

    One other item is that I have tracked down the offending file,

    C:\Windows\SysWOW64\Windows.UI.XamlHost.dll

    and it has a time stamp 9/29/2017, 9:43AM.

    Is there a more recent version of this???

    This whole situation is beyond frustrating. Does anyone know how to get in touch with Microsoft about this? I mean this is their hardware and it is giving an incomprehensible error message. I feel bad consuming other people's time (especially auggy!) but there has been basically no progress on this.

    FAULTING_IP:

    Windows_UI_XamlHost!wil::details::ReportFailure+e5

    00007ffa`c6d51db1 cd29            int     29h

    EXCEPTION_RECORD:  ffffffffffffffff -- (.exr 0xffffffffffffffff)

    ExceptionAddress: 00007ffac6d51db1 (Windows_UI_XamlHost!wil::details::ReportFailure+0x00000000000000e5)

       ExceptionCode: c0000409 (Stack buffer overflow)

      ExceptionFlags: 00000001

    NumberParameters: 1

       Parameter[0]: 0000000000000007

    PROCESS_NAME:  explorer.exe

    ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application.  This  overrun could potentially allow a malicious user to gain control of this application.

    EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application.  This  overrun could potentially allow a malicious user to gain control of this application.

    EXCEPTION_PARAMETER1:  0000000000000007

    NTGLOBALFLAG:  0

    APPLICATION_VERIFIER_FLAGS:  0

    FAULTING_THREAD:  00000000000052dc

    BUGCHECK_STR:  APPLICATION_FAULT_STACK_BUFFER_OVERRUN_MISSING_GSFRAME_SEHOP

    PRIMARY_PROBLEM_CLASS:  STACK_BUFFER_OVERRUN_SEHOP

    DEFAULT_BUCKET_ID:  STACK_BUFFER_OVERRUN_SEHOP

    LAST_CONTROL_TRANSFER:  from 00007ffac6d51e09 to 00007ffac6d51db1

    STACK_TEXT: 

    0000000050cde630 00007ffac6d51e09 : 0000477f14da5dda 0000000000000000 0000000000000000 00007ffac6d59fd8 : Windows_UI_XamlHost!wil::details::ReportFailure+0xe5

    0000000050cdfb70 00007ffac6d68d59 : 000000003b98ee90 0000000031181ae0 0000003700000011 0000000005148300 : Windows_UI_XamlHost!wil::details::ReportFailure_Hr+0x39

    0000000050cdfbd0 00007ffac6d628fb : 0000000000000000 0000000016989f00 000000003111c230 000000000000c000 : Windows_UI_XamlHost!wil::details::in1diag3::_FailFast_Hr+0x29

    0000000050cdfc20 00007ffac6d6946c : 00000000313582a0 0000000000000000 0000000000000000 0000000000000000 : Windows_UI_XamlHost!Microsoft::WRL::SimpleActivationFactory::ActivateInstance+0x34b

    0000000050cdfc50 00007ffad5a1d544 : 0000000000000000 0000000000000001 0000000000000000 0000000000000000 : Windows_UI_XamlHost!ASTAThreadHost::s_ASTAThreadHostStartThreadProc+0x6c

    0000000050cdfc80 00007ffad5ad1fe4 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : SHCore!_WrapperThreadProc+0xc4

    0000000050cdfd60 00007ffad633efc1 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : kernel32!BaseThreadInitThunk+0x14

    0000000050cdfd90 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : ntdll!RtlUserThreadStart+0x21

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-02-18T16:27:57+00:00

    You're welcome, and good luck!

    Was this answer helpful?

    0 comments No comments