[SOLVED] Cumulative update 5006667 - Crashes explorer.exe constantly

dylandy29

Reputable
Jun 5, 2018
3
0
4,510
We are seeing reports of machines with a critical error when installing the patch KB5006667 (October 12, 2021— OS Build 18363.1854). Once installed, (it seems after Teams is started or setup and running), explorer.exe crashes, restarts and crashes again. This happens over and over with no stopping.

Initial troubleshooting shows it seems to be profile related; however, this has not been fully flushed.
It affects both desktops and laptops.

Any one else seen this issue? Any assistance on this issue would be great!

---------------------------------------------------------------------
Event Logs show:
Event ID: 1000
Application Logs:
Faulting application name: explorer.exe, version: 10.0.18362.1832, time stamp: 0xd924b84e
Faulting module name: explorer.exe, version: 10.0.18362.1832, time stamp: 0xd924b84e
Exception code: 0xc0000005
Fault offset: 0x00000000000c5e7e
Faulting process id: 0x23d8
Faulting application start time: 0x01d7c1dbd903cc1c
Faulting application path: C:\windows\explorer.exe
Faulting module path: C:\windows\explorer.exe
Report Id: cb299350-6154-4888-8b0e-e7207487d25e
Faulting package full name:
Faulting package-relative application ID:

Event ID: 1002
The shell stopped unexpectedly and explorer.exe was restarted.

---------------------------------------------------------------------

Debug of Crash Dump files show :

CONTEXT: (.ecxr)
rax=0000000041f00000 rbx=0000000000000000 rcx=0000000000000000
rdx=41f0000041f00000 rsi=000000000f548dc0 rdi=0000000000000001
rip=00007ff7a3ca5e7e rsp=0000000003a8e730 rbp=0000000003a8f0f0
r8=0000000000000000 r9=0000000003a8e401 r10=00000ffef478be0e
r11=0000000000004000 r12=000000000f548e40 r13=000000000f2522d0
r14=0000000000000000 r15=0000000003a8eab8
iopl=0 nv up ei pl nz na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010206
explorer!winrt::impl::consume_Windows_UI_Composition_IVisual<winrt::Windows::UI::Composition::IVisual>::Size+0xa:
00007ff7a3ca5e7e 488b01 mov rax,qword ptr [rcx] ds:0000000000000000=????????????????
Resetting default scope

EXCEPTION_RECORD: (.exr -1)
ExceptionAddress: 00007ff7a3ca5e7e (explorer!winrt::impl::consume_Windows_UI_Composition_IVisual<winrt::Windows::UI::Composition::IVisual>::Size+0x000000000000000a)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000000
Attempt to read from address 0000000000000000

PROCESS_NAME: explorer.exe

READ_ADDRESS: 0000000000000000

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.

EXCEPTION_CODE_STR: c0000005

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: 0000000000000000

STACK_TEXT:
0000000003a8e730 00007ff7a3ca7f83 : 0000000041f00000 0000000000000000 0000000003a8e7b8 0000000000000001 : explorer!winrt::impl::consume_Windows_UI_Composition_IVisual<winrt::Windows::UI::Composition::IVisual>::Size+0xa
0000000003a8e760 00007ff7a3c9f5ad : 41f0000041f00000 0000000003a8ea38 00000000014afc00 0000000003a8eab8 : explorer!Feeds::ACColumn::Setup+0x513
0000000003a8e880 00007ff7a3c9c7c7 : 0000000003a8ee48 000000000f55ac01 000000000f55aca0 000000000d1f5e90 : explorer!Feeds::TimelineContent::Start+0x4f9
0000000003a8ed40 00007ff7a3c95c49 : 0000000000000000 0000000000000000 0000edaf88e64c01 00007fff00000000 : explorer!Feeds::FeedsDynamicContentInternal::UpdateTimeline+0x33f
0000000003a8f000 00007ff7a3c94a9a : 0000000000000042 000000000151dee8 0000000000000000 00007fffb94d31c7 : explorer!Feeds::FeedsDynamicContent::UpdateContent+0x21
0000000003a8f050 00007ff7a3c98f95 : 0000000000000113 000000000151dee8 000000000a56f050 000000000000000f : explorer!Feeds::FeedsDynamicContent::OnTimer+0xca
0000000003a8f090 00007ff7a3c99534 : 00000000001a0376 0000000000000113 0000000000000000 0000000000000000 : explorer!Feeds::FeedsContent::_WndProc+0x11d
0000000003a8f130 00007fffb94d5c0d : 00000000001a0376 0000000000000001 0000000000000001 0000000000000000 : explorer!Feeds::FeedsContent::s_WndProc+0x194
0000000003a8f200 00007fffb94d58de : 00000000001a0376 00007ff7a3c993a0 00000000001a0376 0000000000000113 : user32!UserCallWinProcCheckWow+0x2bd
0000000003a8f390 00007fffa241bbc9 : 0000000003a8f5c0 00000000001a0376 0000000000000001 0000000000000000 : user32!CallWindowProcW+0x8e
0000000003a8f3e0 00007fffa241b8d8 : 0000000000000001 0000000000000113 0000000000000000 000000000f2f9c80 : comctl32!CallNextSubclassProc+0x89
0000000003a8f450 00007fffa241bbc9 : 0000000001b01700 00007fffb94d31c7 0000000000000000 000000000150a698 : comctl32!TTSubclassProc+0xb8
0000000003a8f500 00007fffa241b9f2 : 0000000000000001 0000000000000001 00000000001a0376 00007fffb1bb02c2 : comctl32!CallNextSubclassProc+0x89
0000000003a8f570 00007fffb94d5c0d : 0000000000000001 0000000000000001 0000000000000001 0000000000000000 : comctl32!MasterSubclassProc+0xa2
0000000003a8f610 00007fffb94d5602 : 0000000001ae4ac0 00007fffa241b950 00000000001a0376 0000000003a8f850 : user32!UserCallWinProcCheckWow+0x2bd
0000000003a8f7a0 00007ff7a3bf67e0 : 00007fffa241b950 00007ff7a3f02090 0000000000000000 0000000000000003 : user32!DispatchMessageWorker+0x1e2
0000000003a8f820 00007ff7a3bf665d : 000000000129f200 0000000003a8f979 000000000171d640 000000000000282a : explorer!CTray::_MessageLoop+0x170
0000000003a8f8d0 00007fffb7d4d2c5 : 0000000000000000 0000000003a8f979 000000000171d640 0000000000000000 : explorer!CTray::MainThreadProc+0x4d
0000000003a8f900 00007fffb7a67c24 : 0000000000000001 000000000171d640 0000000000000000 0000000000000000 : SHCore!_WrapperThreadProc+0xf5
0000000003a8f9e0 00007fffb996d721 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : kernel32!BaseThreadInitThunk+0x14
0000000003a8fa10 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : ntdll!RtlUserThreadStart+0x21


SYMBOL_NAME: explorer!winrt::impl::consume_Windows_UI_Composition_IVisual<winrt::Windows::UI::Composition::IVisual>::Size+a

MODULE_NAME: explorer

IMAGE_NAME: explorer.exe

STACK_COMMAND: ~9s ; .ecxr ; kb

FAILURE_BUCKET_ID: NULL_POINTER_READ_c0000005_explorer.exe!winrt::impl::consume_Windows_UI_Composition_IVisual_winrt::Windows::UI::Composition::IVisual_::Size

OS_VERSION: 10.0.18362.1

BUILDLAB_STR: 19h1_release

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {ecfb512f-84af-701b-90e3-f4302a145f3e}
---------------------------------------------------------------------
Enviorment Setup:
Win10 – 1909 (OSBuild 18363.1801) - Pre Patch
Win10 - 1909 (OSBuild 18363.1854) - Post Patch

Enterprise enviorment
HP Series Machines (x360/810/840/850 Laptops > 800/Zseries Dekstops)


Repair attempts:
SFC /Scannow
DISM /restore health
Profile Rebuild
Reimage

<Moderator Notes: Please use the "spoiler" tags around long log excerpts>
 
Last edited by a moderator:
Solution
Found/Fixed:

Disable news and interests:
  1. Disable it from the UI: Right click task bar-> news and interests->turn off.
Corresponding registry:
Computer\HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\ REG_DWORD name: ShellFeedsTaskbarViewMode Value: 2
  1. Use GPO to disable :
Computer Configuration > Administrative Templates > Windows Components > News and interests > Disable news and interests on the taskbar

dylandy29

Reputable
Jun 5, 2018
3
0
4,510
Found/Fixed:

Disable news and interests:
  1. Disable it from the UI: Right click task bar-> news and interests->turn off.
Corresponding registry:
Computer\HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\ REG_DWORD name: ShellFeedsTaskbarViewMode Value: 2
  1. Use GPO to disable :
Computer Configuration > Administrative Templates > Windows Components > News and interests > Disable news and interests on the taskbar
 
Solution

TRENDING THREADS