We are seeing reports of machines with a critical error when installing the patch KB5006667 (October 12, 2021— OS Build 18363.1854). Once installed, (it seems after Teams is started or setup and running), explorer.exe crashes, restarts and crashes again. This happens over and over with no stopping.
Initial troubleshooting shows it seems to be profile related; however, this has not been fully flushed.
It affects both desktops and laptops.
Any one else seen this issue? Any assistance on this issue would be great!
---------------------------------------------------------------------
Event Logs show:
Repair attempts:
SFC /Scannow
DISM /restore health
Profile Rebuild
Reimage
<Moderator Notes: Please use the "spoiler" tags around long log excerpts>
Initial troubleshooting shows it seems to be profile related; however, this has not been fully flushed.
It affects both desktops and laptops.
Any one else seen this issue? Any assistance on this issue would be great!
---------------------------------------------------------------------
Event Logs show:
Event ID: 1000
Application Logs:
Faulting application name: explorer.exe, version: 10.0.18362.1832, time stamp: 0xd924b84e
Faulting module name: explorer.exe, version: 10.0.18362.1832, time stamp: 0xd924b84e
Exception code: 0xc0000005
Fault offset: 0x00000000000c5e7e
Faulting process id: 0x23d8
Faulting application start time: 0x01d7c1dbd903cc1c
Faulting application path: C:\windows\explorer.exe
Faulting module path: C:\windows\explorer.exe
Report Id: cb299350-6154-4888-8b0e-e7207487d25e
Faulting package full name:
Faulting package-relative application ID:
Event ID: 1002
The shell stopped unexpectedly and explorer.exe was restarted.
---------------------------------------------------------------------
Debug of Crash Dump files show :
CONTEXT: (.ecxr)
rax=0000000041f00000 rbx=0000000000000000 rcx=0000000000000000
rdx=41f0000041f00000 rsi=000000000f548dc0 rdi=0000000000000001
rip=00007ff7a3ca5e7e rsp=0000000003a8e730 rbp=0000000003a8f0f0
r8=0000000000000000 r9=0000000003a8e401 r10=00000ffef478be0e
r11=0000000000004000 r12=000000000f548e40 r13=000000000f2522d0
r14=0000000000000000 r15=0000000003a8eab8
iopl=0 nv up ei pl nz na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010206
explorer!winrt::impl::consume_Windows_UI_Composition_IVisual<winrt::Windows::UI::Composition::IVisual>::Size+0xa:
00007ff7
Resetting default scope
EXCEPTION_RECORD: (.exr -1)
ExceptionAddress: 00007ff7a3ca5e7e (explorer!winrt::impl::consume_Windows_UI_Composition_IVisual<winrt::Windows::UI::Composition::IVisual>::Size+0x000000000000000a)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000000
Attempt to read from address 0000000000000000
PROCESS_NAME: explorer.exe
READ_ADDRESS: 0000000000000000
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000000
STACK_TEXT:
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
00000000
SYMBOL_NAME: explorer!winrt::impl::consume_Windows_UI_Composition_IVisual<winrt::Windows::UI::Composition::IVisual>::Size+a
MODULE_NAME: explorer
IMAGE_NAME: explorer.exe
STACK_COMMAND: ~9s ; .ecxr ; kb
FAILURE_BUCKET_ID: NULL_POINTER_READ_c0000005_explorer.exe!winrt::impl::consume_Windows_UI_Composition_IVisual_winrt::Windows::UI::Composition::IVisual_::Size
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {ecfb512f-84af-701b-90e3-f4302a145f3e}
---------------------------------------------------------------------
Enviorment Setup:
Win10 – 1909 (OSBuild 18363.1801) - Pre Patch
Win10 - 1909 (OSBuild 18363.1854) - Post Patch
Enterprise enviorment
HP Series Machines (x360/810/840/850 Laptops > 800/Zseries Dekstops)
Application Logs:
Faulting application name: explorer.exe, version: 10.0.18362.1832, time stamp: 0xd924b84e
Faulting module name: explorer.exe, version: 10.0.18362.1832, time stamp: 0xd924b84e
Exception code: 0xc0000005
Fault offset: 0x00000000000c5e7e
Faulting process id: 0x23d8
Faulting application start time: 0x01d7c1dbd903cc1c
Faulting application path: C:\windows\explorer.exe
Faulting module path: C:\windows\explorer.exe
Report Id: cb299350-6154-4888-8b0e-e7207487d25e
Faulting package full name:
Faulting package-relative application ID:
Event ID: 1002
The shell stopped unexpectedly and explorer.exe was restarted.
---------------------------------------------------------------------
Debug of Crash Dump files show :
CONTEXT: (.ecxr)
rax=0000000041f00000 rbx=0000000000000000 rcx=0000000000000000
rdx=41f0000041f00000 rsi=000000000f548dc0 rdi=0000000000000001
rip=00007ff7a3ca5e7e rsp=0000000003a8e730 rbp=0000000003a8f0f0
r8=0000000000000000 r9=0000000003a8e401 r10=00000ffef478be0e
r11=0000000000004000 r12=000000000f548e40 r13=000000000f2522d0
r14=0000000000000000 r15=0000000003a8eab8
iopl=0 nv up ei pl nz na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010206
explorer!winrt::impl::consume_Windows_UI_Composition_IVisual<winrt::Windows::UI::Composition::IVisual>::Size+0xa:
00007ff7
a3ca5e7e 488b01 mov rax,qword ptr [rcx] ds:00000000
00000000=????????????????Resetting default scope
EXCEPTION_RECORD: (.exr -1)
ExceptionAddress: 00007ff7a3ca5e7e (explorer!winrt::impl::consume_Windows_UI_Composition_IVisual<winrt::Windows::UI::Composition::IVisual>::Size+0x000000000000000a)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000000
Attempt to read from address 0000000000000000
PROCESS_NAME: explorer.exe
READ_ADDRESS: 0000000000000000
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000000
STACK_TEXT:
00000000
03a8e730 00007ff7
a3ca7f83 : 0000000041f00000 00000000
00000000 0000000003a8e7b8 00000000
00000001 : explorer!winrt::impl::consume_Windows_UI_Composition_IVisual<winrt::Windows::UI::Composition::IVisual>::Size+0xa00000000
03a8e760 00007ff7
a3c9f5ad : 41f0000041f00000 00000000
03a8ea38 00000000014afc00 00000000
03a8eab8 : explorer!Feeds::ACColumn::Setup+0x51300000000
03a8e880 00007ff7
a3c9c7c7 : 0000000003a8ee48 00000000
0f55ac01 000000000f55aca0 00000000
0d1f5e90 : explorer!Feeds::TimelineContent::Start+0x4f900000000
03a8ed40 00007ff7
a3c95c49 : 0000000000000000 00000000
00000000 0000edaf88e64c01 00007fff
00000000 : explorer!Feeds::FeedsDynamicContentInternal::UpdateTimeline+0x33f00000000
03a8f000 00007ff7
a3c94a9a : 0000000000000042 00000000
0151dee8 0000000000000000 00007fff
b94d31c7 : explorer!Feeds::FeedsDynamicContent::UpdateContent+0x2100000000
03a8f050 00007ff7
a3c98f95 : 0000000000000113 00000000
0151dee8 000000000a56f050 00000000
0000000f : explorer!Feeds::FeedsDynamicContent::OnTimer+0xca00000000
03a8f090 00007ff7
a3c99534 : 00000000001a0376 00000000
00000113 0000000000000000 00000000
00000000 : explorer!Feeds::FeedsContent::_WndProc+0x11d00000000
03a8f130 00007fff
b94d5c0d : 00000000001a0376 00000000
00000001 0000000000000001 00000000
00000000 : explorer!Feeds::FeedsContent::s_WndProc+0x19400000000
03a8f200 00007fff
b94d58de : 00000000001a0376 00007ff7
a3c993a0 00000000001a0376 00000000
00000113 : user32!UserCallWinProcCheckWow+0x2bd00000000
03a8f390 00007fff
a241bbc9 : 0000000003a8f5c0 00000000
001a0376 0000000000000001 00000000
00000000 : user32!CallWindowProcW+0x8e00000000
03a8f3e0 00007fff
a241b8d8 : 0000000000000001 00000000
00000113 0000000000000000 00000000
0f2f9c80 : comctl32!CallNextSubclassProc+0x8900000000
03a8f450 00007fff
a241bbc9 : 0000000001b01700 00007fff
b94d31c7 0000000000000000 00000000
0150a698 : comctl32!TTSubclassProc+0xb800000000
03a8f500 00007fff
a241b9f2 : 0000000000000001 00000000
00000001 00000000001a0376 00007fff
b1bb02c2 : comctl32!CallNextSubclassProc+0x8900000000
03a8f570 00007fff
b94d5c0d : 0000000000000001 00000000
00000001 0000000000000001 00000000
00000000 : comctl32!MasterSubclassProc+0xa200000000
03a8f610 00007fff
b94d5602 : 0000000001ae4ac0 00007fff
a241b950 00000000001a0376 00000000
03a8f850 : user32!UserCallWinProcCheckWow+0x2bd00000000
03a8f7a0 00007ff7
a3bf67e0 : 00007fffa241b950 00007ff7
a3f02090 0000000000000000 00000000
00000003 : user32!DispatchMessageWorker+0x1e200000000
03a8f820 00007ff7
a3bf665d : 000000000129f200 00000000
03a8f979 000000000171d640 00000000
0000282a : explorer!CTray::_MessageLoop+0x17000000000
03a8f8d0 00007fff
b7d4d2c5 : 0000000000000000 00000000
03a8f979 000000000171d640 00000000
00000000 : explorer!CTray::MainThreadProc+0x4d00000000
03a8f900 00007fff
b7a67c24 : 0000000000000001 00000000
0171d640 0000000000000000 00000000
00000000 : SHCore!_WrapperThreadProc+0xf500000000
03a8f9e0 00007fff
b996d721 : 0000000000000000 00000000
00000000 0000000000000000 00000000
00000000 : kernel32!BaseThreadInitThunk+0x1400000000
03a8fa10 00000000
00000000 : 0000000000000000 00000000
00000000 0000000000000000 00000000
00000000 : ntdll!RtlUserThreadStart+0x21SYMBOL_NAME: explorer!winrt::impl::consume_Windows_UI_Composition_IVisual<winrt::Windows::UI::Composition::IVisual>::Size+a
MODULE_NAME: explorer
IMAGE_NAME: explorer.exe
STACK_COMMAND: ~9s ; .ecxr ; kb
FAILURE_BUCKET_ID: NULL_POINTER_READ_c0000005_explorer.exe!winrt::impl::consume_Windows_UI_Composition_IVisual_winrt::Windows::UI::Composition::IVisual_::Size
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {ecfb512f-84af-701b-90e3-f4302a145f3e}
---------------------------------------------------------------------
Enviorment Setup:
Win10 – 1909 (OSBuild 18363.1801) - Pre Patch
Win10 - 1909 (OSBuild 18363.1854) - Post Patch
Enterprise enviorment
HP Series Machines (x360/810/840/850 Laptops > 800/Zseries Dekstops)
Repair attempts:
SFC /Scannow
DISM /restore health
Profile Rebuild
Reimage
<Moderator Notes: Please use the "spoiler" tags around long log excerpts>
Last edited by a moderator: