Surface Pro 2017, Win 10 Pro x64: Explorer crash (Windows.UI.XamlHost.dll)

Anonymous
2018-01-04T03:56:25+00:00

Hi:

I have periodic explorer crashes on my Surface Pro 2017, Win Pro x64 (it is fully updated). The crash seems to occur periodically after a Hello Windows log-in (this occurs after the computer was sleeping rather than on a fresh boot). It seems to involve Windows.UI.XamlHost.dll based on the below.

When I look in the Event viewer I see errors like this:

Event ID 1000

Faulting application name: explorer.exe, version: 10.0.16299.125, time stamp: 0xfeba44fb

Faulting module name: Windows.UI.XamlHost.dll, version: 10.0.16299.15, time stamp: 0x00f27b8f

Exception code: 0xc0000409

Fault offset: 0x0000000000001db1

Faulting process id: 0x1880

Faulting application start time: 0x01d38282e4131af4

Faulting application path: C:\WINDOWS\explorer.exe

Faulting module path: C:\Windows\System32\Windows.UI.XamlHost.dll

Report Id: 6e835576-b35e-4d24-b6ce-331b05fa2c55

Faulting package full name:

Faulting package-relative application ID:

If I click on Start > type "view all" then click on "View all problem reports Control panel" the "Windows Explorer" "Stopped working" errors and then double click on one I would get something like this:

Source

Windows Explorer

Summary

Stopped working

Date

‎11/‎26/‎2017 10:53 AM

Status

Report sent

Description

Faulting Application Path: C:\Windows\explorer.exe

Problem signature

Problem Event Name: BEX64

Application Name: Explorer.EXE

Application Version: 10.0.16299.15

Application Timestamp: 66e02565

Fault Module Name: Windows.UI.XamlHost.dll

Fault Module Version: 10.0.16299.15

Fault Module Timestamp: 00f27b8f

Exception Offset: 0000000000001db1

Exception Code: c0000409

Exception Data: 0000000000000007

OS Version: 10.0.16299.2.0.0.256.48

Locale ID: 1033

Additional Information 1: 2eb9

Additional Information 2: 2eb9591f0e04c7cfea277e3f34d3348f

Additional Information 3: 9333

Additional Information 4: 9333781589f3ec46cd357f0fda06eea0

Extra information about the problem

Bucket ID: 15f01e3e317a50b7b6bb92d1b9fc4f7c (116455065336)

I am at a loss to understand what the problem is here. I am glad to disable Hello Windows if this would end the problem. Thanks in advance for any help on this!

[Moved from: Windows / Windows 10 / Windows Hello, lock screen & sign-in]

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

68 answers

Sort by: Newest
  1. Anonymous
    2018-01-31T13:57:09+00:00

    Dropbox shows up :

    *** ERROR: Symbol file could not be found.  Defaulted to export symbols for sppc.dll -

    *** WARNING: Unable to verify timestamp for DropboxExt64.19.0.dll

    *** ERROR: Module load completed but symbols could not be loaded for DropboxExt64.19.0.dll

    *** WARNING: Unable to verify timestamp for igd10iumd64.dll

    *** ERROR: Module load completed but symbols could not be loaded for igd10iumd64.dll

    GetUrlPageData2 (WinHttp) failed: 12002.

    Probably caused by : Windows.UI.XamlHost.dll ( Windows_UI_XamlHost!wil::details::ReportFailure+e5)

    I also suggest to uninstall Notepad++ as the NppShell_06.dll has been known to cause Explorer crashes albeit usually on a right-click.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-01-31T13:36:57+00:00

    Can do auggy.

    Can you see DropBox or Notepad++ listed in the CrashDump? I could not see them listed as a potential problem.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-01-31T03:08:23+00:00

    The error looks similar to the previous one so can you temporarily uninstall Dropbox and Notepad++ and see if the error re-occurs.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-01-30T16:41:02+00:00

    Here is what I can see in my Crash Dump that I linked to above:

    FAULTING_IP:

    Windows_UI_XamlHost!wil::details::ReportFailure+e5

    00007ffe`8bbb1db1 cd29            int     29h

    EXCEPTION_RECORD:  ffffffffffffffff -- (.exr 0xffffffffffffffff)

    ExceptionAddress: 00007ffe8bbb1db1 (Windows_UI_XamlHost!wil::details::ReportFailure+0x00000000000000e5)

       ExceptionCode: c0000409 (Stack buffer overflow)

      ExceptionFlags: 00000001

    NumberParameters: 1

       Parameter[0]: 0000000000000007

    PROCESS_NAME:  explorer.exe

    ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application.  This  overrun could potentially allow a malicious user to gain control of this application.

    EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application.  This  overrun could potentially allow a malicious user to gain control of this application.

    EXCEPTION_PARAMETER1:  0000000000000007

    NTGLOBALFLAG:  0

    APPLICATION_VERIFIER_FLAGS:  0

    FAULTING_THREAD:  000000000000159c

    BUGCHECK_STR:  APPLICATION_FAULT_STACK_BUFFER_OVERRUN_MISSING_GSFRAME_SEHOP

    PRIMARY_PROBLEM_CLASS:  STACK_BUFFER_OVERRUN_SEHOP

    DEFAULT_BUCKET_ID:  STACK_BUFFER_OVERRUN_SEHOP

    LAST_CONTROL_TRANSFER:  from 00007ffe8bbb1e09 to 00007ffe8bbb1db1

    STACK_TEXT: 

    000000005f2ce220 00007ffe8bbb1e09 : 00005ef9219e0fc4 0000000000000000 0000000000000000 00007ffe8bbb9fd8 : Windows_UI_XamlHost!wil::details::ReportFailure+0xe5

    000000005f2cf760 00007ffe8bbc8d59 : 0000000017c382f0 000000001cb07d50 0000003700000011 000000001cefb330 : Windows_UI_XamlHost!wil::details::ReportFailure_Hr+0x39

    000000005f2cf7c0 00007ffe8bbc28fb : 0000000000000000 000000001cb088f0 000000002e768080 000000000000c000 : Windows_UI_XamlHost!wil::details::in1diag3::_FailFast_Hr+0x29

    000000005f2cf810 00007ffe8bbc946c : 000000001cefb640 0000000000000000 0000000000000000 0000000000000000 : Windows_UI_XamlHost!Microsoft::WRL::SimpleActivationFactory::ActivateInstance+0x34b

    000000005f2cf840 00007ffe9728d544 : 0000000000000000 0000000000000001 0000000000000000 0000000000000000 : Windows_UI_XamlHost!ASTAThreadHost::s_ASTAThreadHostStartThreadProc+0x6c

    000000005f2cf870 00007ffe97fe1fe4 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : SHCore!_WrapperThreadProc+0xc4

    000000005f2cf950 00007ffe9817efb1 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : kernel32!BaseThreadInitThunk+0x14

    000000005f2cf980 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : ntdll!RtlUserThreadStart+0x21

    FOLLOWUP_IP:

    Windows_UI_XamlHost!wil::details::ReportFailure+e5

    00007ffe`8bbb1db1 cd29            int     29h

    SYMBOL_STACK_INDEX:  0

    SYMBOL_NAME:  Windows_UI_XamlHost!wil::details::ReportFailure+e5

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: Windows_UI_XamlHost

    IMAGE_NAME:  Windows.UI.XamlHost.dll

    DEBUG_FLR_IMAGE_TIMESTAMP:  f27b8f

    STACK_COMMAND:  ~236s ; kb

    FAILURE_BUCKET_ID:  STACK_BUFFER_OVERRUN_SEHOP_c0000409_Windows.UI.XamlHost.dll!wil::details::ReportFailure

    BUCKET_ID:  X64_APPLICATION_FAULT_STACK_BUFFER_OVERRUN_MISSING_GSFRAME_SEHOP_MISSING_GSFRAME_Windows_UI_XamlHost!wil::details::ReportFailure+e5

    WATSON_STAGEONE_URL:  http://watson.microsoft.com/00001db1.htm?Retriage=1

    Followup: MachineOwner

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-01-30T16:05:35+00:00

    Thanks ConiGL I really appreciate the link!

    I will try a few of the suggestions there though I think my problem might be a bit different (there is a note about Windows.UI.Xaml.dll but it seems related to another application; honestly I have no clue I cannot really figure out ehat is going on here). Auggy has had some insights on the dump file, hopefully he can give it a look and see if there is a connection, of if he has other suggestions.

    Again thank you!

    Was this answer helpful?

    0 comments No comments