Surface Pro 2017, Win 10 Pro x64: Explorer crash (Windows.UI.XamlHost.dll)

Anonymous
2018-01-04T03:56:25+00:00

Hi:

I have periodic explorer crashes on my Surface Pro 2017, Win Pro x64 (it is fully updated). The crash seems to occur periodically after a Hello Windows log-in (this occurs after the computer was sleeping rather than on a fresh boot). It seems to involve Windows.UI.XamlHost.dll based on the below.

When I look in the Event viewer I see errors like this:

Event ID 1000

Faulting application name: explorer.exe, version: 10.0.16299.125, time stamp: 0xfeba44fb

Faulting module name: Windows.UI.XamlHost.dll, version: 10.0.16299.15, time stamp: 0x00f27b8f

Exception code: 0xc0000409

Fault offset: 0x0000000000001db1

Faulting process id: 0x1880

Faulting application start time: 0x01d38282e4131af4

Faulting application path: C:\WINDOWS\explorer.exe

Faulting module path: C:\Windows\System32\Windows.UI.XamlHost.dll

Report Id: 6e835576-b35e-4d24-b6ce-331b05fa2c55

Faulting package full name:

Faulting package-relative application ID:

If I click on Start > type "view all" then click on "View all problem reports Control panel" the "Windows Explorer" "Stopped working" errors and then double click on one I would get something like this:

Source

Windows Explorer

Summary

Stopped working

Date

‎11/‎26/‎2017 10:53 AM

Status

Report sent

Description

Faulting Application Path: C:\Windows\explorer.exe

Problem signature

Problem Event Name: BEX64

Application Name: Explorer.EXE

Application Version: 10.0.16299.15

Application Timestamp: 66e02565

Fault Module Name: Windows.UI.XamlHost.dll

Fault Module Version: 10.0.16299.15

Fault Module Timestamp: 00f27b8f

Exception Offset: 0000000000001db1

Exception Code: c0000409

Exception Data: 0000000000000007

OS Version: 10.0.16299.2.0.0.256.48

Locale ID: 1033

Additional Information 1: 2eb9

Additional Information 2: 2eb9591f0e04c7cfea277e3f34d3348f

Additional Information 3: 9333

Additional Information 4: 9333781589f3ec46cd357f0fda06eea0

Extra information about the problem

Bucket ID: 15f01e3e317a50b7b6bb92d1b9fc4f7c (116455065336)

I am at a loss to understand what the problem is here. I am glad to disable Hello Windows if this would end the problem. Thanks in advance for any help on this!

[Moved from: Windows / Windows 10 / Windows Hello, lock screen & sign-in]

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

68 answers

Sort by: Oldest
  1. Anonymous
    2018-02-06T15:23:28+00:00

    Thanks ElmerJohn.

    I rebooted my machine and am going to see what happens now before resetting or other significant steps. I will report back on the thread as I see more.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-02-09T02:45:49+00:00

    Still having the problem. I list below a link to the Crash Dump and also copied the relevant error message from the event viewer. 

    Everything here (and in all of my posts) involve Windows.UI.XamlHost.dll. I think to diagnose what is going on we need to know what this is. I have no clue. What exactly does this do?

    Crash Dump:

    https://1drv.ms/u/s!AoMjGh2ERllBbS6VGmbRCg06uUQ

    Event Viewer message:

    Log Name:      Application

    Source:        Application Error

    Date:          2/8/2018 4:53:22 PM

    Event ID:      1000

    Task Category: (100)

    Level:         Error

    Keywords:      Classic

    User:          N/A

    Computer:      DESKTOP-UHI1BND

    Description:

    Faulting application name: Explorer.EXE, version: 10.0.16299.214, time stamp: 0x9b99aba6

    Faulting module name: Windows.UI.XamlHost.dll, version: 10.0.16299.15, time stamp: 0x00f27b8f

    Exception code: 0xc0000409

    Fault offset: 0x0000000000001db1

    Faulting process id: 0x1758

    Faulting application start time: 0x01d39e93ceb3043c

    Faulting application path: C:\WINDOWS\Explorer.EXE

    Faulting module path: C:\Windows\System32\Windows.UI.XamlHost.dll

    Report Id: f8d5916c-b481-4bb5-9319-2fa1391a0656

    Faulting package full name:

    Faulting package-relative application ID:

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

      <System>

        <Provider Name="Application Error" />

        <EventID Qualifiers="0">1000</EventID>

        <Level>2</Level>

        <Task>100</Task>

        <Keywords>0x80000000000000</Keywords>

        <TimeCreated SystemTime="2018-02-08T21:53:22.407335800Z" />

        <EventRecordID>12487</EventRecordID>

        <Channel>Application</Channel>

        <Computer>DESKTOP-UHI1BND</Computer>

        <Security />

      </System>

      <EventData>

        <Data>Explorer.EXE</Data>

        <Data>10.0.16299.214</Data>

        <Data>9b99aba6</Data>

        <Data>Windows.UI.XamlHost.dll</Data>

        <Data>10.0.16299.15</Data>

        <Data>00f27b8f</Data>

        <Data>c0000409</Data>

        <Data>0000000000001db1</Data>

        <Data>1758</Data>

        <Data>01d39e93ceb3043c</Data>

        <Data>C:\WINDOWS\Explorer.EXE</Data>

        <Data>C:\Windows\System32\Windows.UI.XamlHost.dll</Data>

        <Data>f8d5916c-b481-4bb5-9319-2fa1391a0656</Data>

        <Data>

        </Data>

        <Data>

        </Data>

      </EventData>

    </Event>

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-02-10T16:08:10+00:00

    I am pretty sure this is due to something with the Edge Browser: I seem to have small hiccups with it at some point before each of the Explorer crashes.

    I also see many Bluetooth hub errors in event viewer. Only blue tooth device I am using is my Microsoft keyboard.

    Again if someone has any idea what Windows.UI.XamlHost.dll is, then we might have some insights on this?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-02-11T23:11:34+00:00

    Here is what I can see in my most recent CrashDump (posted 8 Feb 2018):

    FAULTING_IP:

    Windows_UI_XamlHost!wil::details::ReportFailure+e5

    00007ffa`d0a31db1 cd29            int     29h

    EXCEPTION_RECORD:  ffffffffffffffff -- (.exr 0xffffffffffffffff)

    ExceptionAddress: 00007ffad0a31db1 (Windows_UI_XamlHost!wil::details::ReportFailure+0x00000000000000e5)

       ExceptionCode: c0000409 (Stack buffer overflow)

      ExceptionFlags: 00000001

    NumberParameters: 1

       Parameter[0]: 0000000000000007

    PROCESS_NAME:  explorer.exe

    ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application.  This  overrun could potentially allow a malicious user to gain control of this application.

    EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application.  This  overrun could potentially allow a malicious user to gain control of this application.

    EXCEPTION_PARAMETER1:  0000000000000007

    NTGLOBALFLAG:  0

    APPLICATION_VERIFIER_FLAGS:  0

    FAULTING_THREAD:  0000000000002408

    BUGCHECK_STR:  APPLICATION_FAULT_STACK_BUFFER_OVERRUN_MISSING_GSFRAME_SEHOP

    PRIMARY_PROBLEM_CLASS:  STACK_BUFFER_OVERRUN_SEHOP

    DEFAULT_BUCKET_ID:  STACK_BUFFER_OVERRUN_SEHOP

    LAST_CONTROL_TRANSFER:  from 00007ffad0a31e09 to 00007ffad0a31db1

    STACK_TEXT: 

    000000004ec7e640 00007ffad0a31e09 : 0000ffc12b0f1af4 0000000000000000 0000000000000000 00007ffad0a39fd8 : Windows_UI_XamlHost!wil::details::ReportFailure+0xe5

    000000004ec7fb80 00007ffad0a48d59 : 0000000018bfd2c0 000000002551b4c0 0000003700000011 0000000025414af0 : Windows_UI_XamlHost!wil::details::ReportFailure_Hr+0x39

    000000004ec7fbe0 00007ffad0a428fb : 0000000000000000 0000000025344770 0000000025ad22f0 000000000000c000 : Windows_UI_XamlHost!wil::details::in1diag3::_FailFast_Hr+0x29

    000000004ec7fc30 00007ffad0a4946c : 0000000025395c90 0000000000000000 0000000000000000 0000000000000000 : Windows_UI_XamlHost!Microsoft::WRL::SimpleActivationFactory::ActivateInstance+0x34b

    000000004ec7fc60 00007ffad5a1d544 : 0000000000000000 0000000000000001 0000000000000000 0000000000000000 : Windows_UI_XamlHost!ASTAThreadHost::s_ASTAThreadHostStartThreadProc+0x6c

    000000004ec7fc90 00007ffad5ad1fe4 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : SHCore!_WrapperThreadProc+0xc4

    000000004ec7fd70 00007ffad633efc1 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : kernel32!BaseThreadInitThunk+0x14

    000000004ec7fda0 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : ntdll!RtlUserThreadStart+0x21

    FOLLOWUP_IP:

    Windows_UI_XamlHost!wil::details::ReportFailure+e5

    00007ffa`d0a31db1 cd29            int     29h

    SYMBOL_STACK_INDEX:  0

    SYMBOL_NAME:  Windows_UI_XamlHost!wil::details::ReportFailure+e5

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: Windows_UI_XamlHost

    IMAGE_NAME:  Windows.UI.XamlHost.dll

    DEBUG_FLR_IMAGE_TIMESTAMP:  f27b8f

    STACK_COMMAND:  ~198s ; kb

    FAILURE_BUCKET_ID:  STACK_BUFFER_OVERRUN_SEHOP_c0000409_Windows.UI.XamlHost.dll!wil::details::ReportFailure

    BUCKET_ID:  X64_APPLICATION_FAULT_STACK_BUFFER_OVERRUN_MISSING_GSFRAME_SEHOP_MISSING_GSFRAME_Windows_UI_XamlHost!wil::details::ReportFailure+e5

    WATSON_STAGEONE_URL:  http://watson.microsoft.com/00001db1.htm?Retriage=1

    Followup: MachineOwner

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-02-12T12:49:33+00:00

    The Windows.UI.XamlHost.dll is a central component of Windows involved in many functions.

    Can you provide the most recent dump file?

    Also, can you provide the following information which may help determine any issue(s):

    Windows Key + R > type msinfo32 in the "Open" box  > OK > File > Save > then save as an .nfo file

    Then make the resulting .nfo file available via OneDrive.

    Also, can you do the following:

    Windows Key + R > type eventvwr in the "Open" box > OK > expand "Custom Views" and then right-click "Administrative Events" > select "Save all events in Custom View As" and save as an .evtx file

    Then make the resulting .evtx file available via OneDrive.

    Was this answer helpful?

    0 comments No comments