none
File explorer crashing and File share issue RRS feed

  • Question

  • Hi 

    I am facing an issue with one of the user in our environment who is having a non-SOE image in a dell Precision 3430 Small Form Factor Windows 10 Enterprise Build 16299 . Machine is joined in domain and able to access resources. But inspite of being a high resource CPU , the machine is having occasional slowness in accessing files and folders. I was thinking it due to network share folder access . But when the issue happens it is not necessary that user is trying to access a share d folder , though most of the resources including My Documents ( except desktop ) are in shared folder. Today user complained about File explorer hang and I got event for the first time but no events for the second. I have a attached a word document with the details that I have collected. 

    I had added a registry entry to collect dump files. But they are also not getting generated even when though explorer crashed. I have attached the registry changes and the event details. 

    Any help or suggestion is Welcome. 

    13-09-2019

    Event ID 1000

    Microsoft.Notes.exe

    2.1.18.0

    5aba81d8

    CoreUIComponents.dll

    10.0.16299.1004

    3b386c3c

    c0000005

    000000000008e80e

    1f78

    01d567535822ce31

    C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_2.1.18.0_x64__8wekyb3d8bbwe\Microsoft.Notes.exe

    C:\Windows\SYSTEM32\CoreUIComponents.dll

    12447b1e-0cc8-449a-8a42-395f9023e8d8

    Microsoft.MicrosoftStickyNotes_2.1.18.0_x64__8wekyb3d8bbwe

    App

    The handle is invalid

    Event ID 1002

    The description for Event ID 1002 from source Application Hang cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

    If the event originated on another computer, the display information had to be saved with the event.

    The following information was included with the event:

    explorer.exe

    10.0.16299.637

    1c98

    01d5675357e1fd30

    83

    C:\Windows\explorer.exe

    ab77ea0f-a0c8-4f0f-a0e6-9aabbf752ebf

    The handle is invalid



    Regards Midhin


    • Edited by midhin t g Friday, September 13, 2019 3:39 AM screenshot of registry settin
    Friday, September 13, 2019 3:36 AM

All replies

  • Hi midhin t g.

    The exception code "c0000005" indicates a memory access violation. Did you make any change on the system after which the problem occurred?
    Is there any .DMP file created by Windows after that problem? If you can find it, upload it to your OneDrive, make it publicly available and post the URL here, so we can try to analyze it and suggest you a solution.

    Bye.


    Luigi Bruno
    MCP, MOS, MTA, MCTS, MCSA, MCSE

    Friday, September 13, 2019 9:15 AM
  • Hi 

    I had not made any change initially . As per the image below  created registry changes to  create dump file , but nothing got created . Two days back I run the proc dump utility command and waiting for any crash to happen.

     


    Regards Midhin

    Monday, September 16, 2019 12:33 AM
  • Hi

    Since the picture are damaged and would you please upload the pictures again?

    Only from the log, we can predict that there is something wrong with your Microsoft.Notes.exe, so try to reload this app and see whether it’s OK.

    Besides, you can refer to the following link:

    https://docs.microsoft.com/en-us/sysinternals/downloads/procdump

    Best regards

    Kiki Shi


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Monday, September 16, 2019 9:19 AM
  • Dump file uploaded here. 

    https://1drv.ms/u/s!AkhrCZ8ePFjqnm7JfPkXbnVnE45K?e=6E9Ho5 


    Regards Midhin

    Tuesday, September 17, 2019 3:14 AM
  • Hi

    Keep us updated with your progress.

    Best regards,

    Kiki Shi


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Friday, September 20, 2019 9:13 AM
  • Issue is still happening . I had uploaded the dump file in previous reply 

    Regards Midhin

    Friday, September 20, 2019 12:58 PM
  • Hi,

    Due to the dump file are too large to download, suggest that you can use winDbg to analyse the issue.

    More details you can refer to the following link:

    https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/debugger-download-tools

    Hope can help you.

    Best regards,

    Kiki Shi


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Monday, September 23, 2019 6:32 AM
  • Hi 

    Can you help 

    Dump file uploaded here. 

    https://1drv.ms/u/s!AkhrCZ8ePFjqnm7JfPkXbnVnE45K?e=6E9Ho5 


    Regards Midhin

    Monday, September 23, 2019 10:35 PM
  • Hi

    These are the analysis result of your dump file by winDbg:

    0:000> !analyze -v

    *******************************************************************************

    *                                                                             *

    *                        Exception Analysis                                   *

    *                                                                             *

    *******************************************************************************

    Unable to load image C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE, Win32 error 0n2

    *** WARNING: Unable to verify timestamp for EXCEL.EXE

    *** WARNING: Unable to verify timestamp for mso40uiwin32client.dll

    *** WARNING: Unable to verify timestamp for ClientTelemetry.dll

    *** WARNING: Unable to verify timestamp for mso98win32client.dll

    Unable to load image C:\Windows\System32\spool\drivers\x64\3\KOAYTJ_R.DLL, Win32 error 0n2

    *** WARNING: Unable to verify timestamp for KOAYTJ_R.DLL

    *** WARNING: Unable to verify timestamp for AppVIsvSubsystems64.dll

    *** WARNING: Unable to verify timestamp for VBE7.DLL

    *** WARNING: Unable to verify timestamp for nvwgf2umx_cfg.dll

    Failed to request MethodData, not in JIT code range

    KEY_VALUES_STRING: 1

        Key  : Analysis.CPU.Sec

        Value: 73

        Key  : Analysis.DebugAnalysisProvider.CPP

        Value: Create: 8007007e on MININT-R5VN7PC

        Key  : Analysis.DebugData

        Value: CreateObject

        Key  : Analysis.DebugModel

        Value: CreateObject

        Key  : Analysis.Elapsed.Sec

        Value: 1029

        Key  : Analysis.Memory.CommitPeak.Mb

        Value: 279

        Key  : Analysis.System

        Value: CreateObject

        Key  : CLR.Engine

        Value: CLR

        Key  : CLR.Version

        Value: 4.0.30319.0

        Key  : Timeline.Process.Start.DeltaSec

        Value: 84655

    NTGLOBALFLAG:  0

    PROCESS_BAM_CURRENT_THROTTLED: 0

    PROCESS_BAM_PREVIOUS_THROTTLED: 0

    APPLICATION_VERIFIER_FLAGS:  0

    MISSING_CLR_SYMBOL: 0

    CONTEXT:  (.ecxr)

    rax=00000091c79e6450 rbx=00000000c0000374 rcx=0000000000000003

    rdx=00007ffb6fe65b09 rsi=0000000000000001 rdi=00007ffb6ff9c6e0

    rip=00007ffb6ff3843b rsp=00000091c79e6470 rbp=000001f9737bfc40

    r8=00007ffb6c24cc5b  r9=000001f92154cdf8 r10=0000000000000000

    r11=000000012dd16000 r12=000001f97759a670 r13=0000000000000000

    r14=0000000000000000 r15=0000000000000000

    iopl=0         nv up ei pl nz na po nc

    cs=0033  ss=002b  ds=002b  es=002b  fs=0053  gs=002b             efl=00000206

    ntdll!RtlReportCriticalFailure+0x97:

    00007ffb`6ff3843b eb00            jmp     ntdll!RtlReportCriticalFailure+0x99 (00007ffb`6ff3843d)

    Resetting default scope

    EXCEPTION_RECORD:  (.exr -1)

    ExceptionAddress: 00007ffb6ff3843b (ntdll!RtlReportCriticalFailure+0x0000000000000097)

       ExceptionCode: c0000374

      ExceptionFlags: 00000001

    NumberParameters: 1

       Parameter[0]: 00007ffb6ff9c6e0

    PROCESS_NAME:  EXCEL.EXE

    ERROR_CODE: (NTSTATUS) 0xc0000374 - A heap has been corrupted.

    EXCEPTION_CODE_STR:  c0000374

    EXCEPTION_PARAMETER1:  00007ffb6ff9c6e0

    ADDITIONAL_DEBUG_TEXT:  Followup set based on attribute [Heap_Error_Type] from Frame:[0] on thread:[PSEUDO_THREAD] ; Followup set based on attribute [Is_ChosenCrashFollowupThread] from Frame:[0] on thread:[PSEUDO_THREAD]

    FAULTING_THREAD:  ffffffff

    STACK_TEXT: 

    00000000`00000000 00000000`00000000 mso20win32client!unknown_function+0x0

    SYMBOL_NAME:  mso20win32client!unknown_function

    MODULE_NAME: mso20win32client

    IMAGE_NAME:  mso20win32client.dll

    STACK_COMMAND:  !heap ; ** Pseudo Context ** ManagedPseudo ** Value: 1be2daf07a0 ** ; kb

    FAILURE_BUCKET_ID:  HEAP_CORRUPTION_ACTIONABLE_BlockNotBusy_DOUBLE_FREE_c0000374_mso20win32client.dll!unknown_function

    OS_VERSION:  10.0.16299.637

    BUILDLAB_STR:  rs3_release_svc

    OSPLATFORM_TYPE:  x64

    OSNAME:  Windows 10

    FAILURE_ID_HASH:  {6120d133-e51a-ecc4-e221-531d4da14a7a}

    Followup:     MachineOwner

    ---------

    As we can see , ERROR_CODE: (NTSTATUS) 0xc0000374

    I suggest that you refer to the following link for more help about the error code:

    https://answers.microsoft.com/en-us/windows/forum/windows_7-performance/random-explorer-crash/99414dea-9ff2-47de-877a-494e0e66d62c?auth=1&page=2

    Hope can help you.

    Have a nice day!

    Best regards,

    Kiki Shi



    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Friday, September 27, 2019 7:29 AM
  • Hi,

    I am very happy to help you. Would you mind letting me know the update of the problem?  If you think the answer is helpful, please mark it as a reply, which will help more users get valid information.

    Have a nice day=.=

    Best regards,

    Kiki Shi


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Friday, October 4, 2019 3:18 AM