Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Question
Friday, June 17, 2016 7:10 AM
Hi All,
We have multiple machines which are having explorer crashing when they are using a remote app. When I look at the log on these machines the following events are logged. (Below)
I have tried the following:
- Installing the latest updates
- Updating System Drivers
- Recreating Local & Roaming Profile
When the problem occurs the RemoteApp loses focus and the Explorer process on the local machine constantly crashes in short succession. You need to close the remote app for the Explorer.exe process on the workstation to recover.
Below is more info from the crash logs.
Event 1000 Application Error
Faulting application name: explorer.exe, version: 10.0.10240.16942, time stamp: 0x5749188e
Faulting module name: twinui.appcore.dll, version: 10.0.10240.16412, time stamp: 0x55b99e01
Exception code: 0xc0000005
Fault offset: 0x000000000005a58a
Faulting process id: 0x3430
Faulting application start time: 0x01d1c85c9afeaee6
Faulting application path: C:\WINDOWS\explorer.exe
Faulting module path: C:\WINDOWS\System32\twinui.appcore.dll
Report Id: 92db71ca-086b-4519-8c6d-beadb68ec3f8
Faulting package full name:
Faulting package-relative application ID:
Event 1001, Windows Error Reporting
Fault bucket , type 0
Event Name: APPCRASH
Response: Not available
Cab Id: 0
Problem signature:
P1: explorer.exe
P2: 10.0.10240.16942
P3: 5749188e
P4: twinui.appcore.dll
P5: 10.0.10240.16412
P6: 55b99e01
P7: c0000005
P8: 000000000005a58a
P9:
P10:
Attached files:
C:\Users\USER\AppData\Local\Temp\WER9FD4.tmp.appcompat.txt
C:\Users\USER\AppData\Local\Temp\WER9FE5.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_explorer.exe_5827cc1bc748a752e40215ec0407a24b5bf636_738e35a5_cab_19789ff3\memory.hdmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_explorer.exe_5827cc1bc748a752e40215ec0407a24b5bf636_738e35a5_cab_19789ff3\triagedump.dmp
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_explorer.exe_5827cc1bc748a752e40215ec0407a24b5bf636_738e35a5_cab_19789ff3
Analysis symbol:
Rechecking for solution: 0
Report Id: 92db71ca-086b-4519-8c6d-beadb68ec3f8
Report Status: 4
Hashed bucket:
Loading unloaded module list
.
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(3430.ed8): Access violation - code c0000005 (first/second chance not available)
ntdll!NtWaitForMultipleObjects+0xa:
00007ff8`e4c83dda c3 ret
0:063> .ecxr.
rax=000000000a000014 rbx=0000000080070490 rcx=0000000002f33f50
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=00007ff8d040a58a rsp=00000000129ed950 rbp=00007ff8d040a460
r8=00000000129ed9d0 r9=00007ff8d04f7478 r10=0000000002f352f0
r11=00007ff8e24c0000 r12=0000000000000002 r13=0000000000000000
r14=00000000129ed9d0 r15=00007ff8d040a460
iopl=0 nv up ei pl zr na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010246
twinui_appcore!ViewWrapperBase::IsEqual+0x4a:
00007ff8`d040a58a 488b07 mov rax,qword ptr [rdi] ds:00000000`00000000=????????????????
^ Extra character error in '.ecxr.'
0:063> !analyze -v
*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************
*** ERROR: Symbol file could not be found. Defaulted to export symbols for sppc.dll -
*** WARNING: Unable to verify timestamp for nvwgf2umx.dll
*** ERROR: Module load completed but symbols could not be loaded for nvwgf2umx.dll
*** WARNING: Unable to verify timestamp for DropboxExt64.34.dll
*** ERROR: Module load completed but symbols could not be loaded for DropboxExt64.34.dll
DUMP_CLASS: 2
DUMP_QUALIFIER: 400
CONTEXT: (.ecxr)
rax=000000000a000014 rbx=0000000080070490 rcx=0000000002f33f50
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=00007ff8d040a58a rsp=00000000129ed950 rbp=00007ff8d040a460
r8=00000000129ed9d0 r9=00007ff8d04f7478 r10=0000000002f352f0
r11=00007ff8e24c0000 r12=0000000000000002 r13=0000000000000000
r14=00000000129ed9d0 r15=00007ff8d040a460
iopl=0 nv up ei pl zr na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010246
twinui_appcore!ViewWrapperBase::IsEqual+0x4a:
00007ff8`d040a58a 488b07 mov rax,qword ptr [rdi] ds:00000000`00000000=????????????????
Resetting default scope
FAULTING_IP:
twinui_appcore!ViewWrapperBase::IsEqual+4a
00007ff8`d040a58a 488b07 mov rax,qword ptr [rdi]
EXCEPTION_RECORD: (.exr -1)
ExceptionAddress: 00007ff8d040a58a (twinui_appcore!ViewWrapperBase::IsEqual+0x000000000000004a)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000000
Attempt to read from address 0000000000000000
DEFAULT_BUCKET_ID: NULL_POINTER_READ
PROCESS_NAME: explorer.exe
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000000
READ_ADDRESS: 0000000000000000
FOLLOWUP_IP:
twinui_appcore!ViewWrapperBase::IsEqual+4a
00007ff8`d040a58a 488b07 mov rax,qword ptr [rdi]
BUGCHECK_STR: NULL_POINTER_READ
WATSON_BKT_PROCSTAMP: 5749188e
WATSON_BKT_PROCVER: 10.0.10240.16942
PROCESS_VER_PRODUCT: Microsoft® Windows® Operating System
WATSON_BKT_MODULE: twinui.appcore.dll
WATSON_BKT_MODSTAMP: 55b99e01
WATSON_BKT_MODOFFSET: 5a58a
WATSON_BKT_MODVER: 10.0.10240.16412
MODULE_VER_PRODUCT: Microsoft® Windows® Operating System
BUILD_VERSION_STRING: 10.0.10240.16384 (th4.150709-1700)
MODLIST_WITH_TSCHKSUM_HASH: 377c1c116db3472153233155adde9648b6259170
MODLIST_SHA1_HASH: c3300f4d2b25496a6ef90ad21942a61a3277f420
NTGLOBALFLAG: 0
APPLICATION_VERIFIER_FLAGS: 0
DUMP_FLAGS: 94
DUMP_TYPE: 1
APP: explorer.exe
ANALYSIS_SESSION_HOST: <PCNAME>
ANALYSIS_SESSION_TIME: 06-17-2016 16:43:48.0665
ANALYSIS_VERSION: 10.0.10586.567 amd64fre
THREAD_ATTRIBUTES:
OS_LOCALE: ENA
PROBLEM_CLASSES:
NULL_POINTER_READ
Tid [0xed8]
Frame [0x00]: twinui_appcore!ViewWrapperBase::IsEqual
LAST_CONTROL_TRANSFER: from 00007ff8d03bd959 to 00007ff8d040a58a
STACK_TEXT:
00000000`129ed950 00007ff8`d03bd959 : 00000000`129eda00 00000000`00000000 00000000`129ee078 00007ff8`0a000014 : twinui_appcore!ViewWrapperBase::IsEqual+0x4a
00000000`129ed9a0 00007ff8`d03b9dd2 : 00000000`00000000 00000000`02f35138 00007ff8`d03bd910 00000000`02f169e0 : twinui_appcore!CTaskWindow::IsEqualByView+0x49
00000000`129ed9d0 00007ff8`d03bc259 : 00007ff8`00000000 00007ff8`d03b9bf0 00000000`11d8f680 00000000`00000000 : twinui_appcore!CImmersiveApp::MatchByWindow+0x1e2
00000000`129eda60 00007ff8`d03fce7a : 00000000`02f169d8 00000000`00000000 00000000`00000000 00000000`129edba0 : twinui_appcore!CImmersiveApp::IsEqualByHwnd+0x69
00000000`129edab0 00007ff8`c8823416 : 00007ff8`00000000 00000000`00000000 00000000`129edba0 00000000`8002802b : twinui_appcore!CApplicationViewManager::GetViewForHwnd+0x2fa
00000000`129edb60 00007ff8`e253b0b3 : 00000000`00000000 00000000`00000003 00000000`02f18470 00000000`129edbc0 : twinui!VirtualDesktopsApi::GetWindowDesktopId+0x76
00000000`129edba0 00007ff8`e259d903 : 00000000`129ee078 00000000`129edc00 00000000`129ee070 00007ff8`d54b4be8 : rpcrt4!Invoke+0x73
00000000`129edc00 00007ff8`e252aa8d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : rpcrt4!Ndr64StubWorker+0xbe3
00000000`129ee2c0 00007ff8`e4904b1b : 00000000`00000000 00000000`129ee4e0 00007ff8`d54bdbd0 00000000`00000000 : rpcrt4!NdrStubCall3+0xbd
00000000`129ee330 00007ff8`e49b2582 : 00000000`00000001 00000000`05f307a0 00000000`05e14f20 00000000`00000000 : combase!CStdStubBuffer_Invoke+0x6b
00000000`129ee370 00007ff8`e4980835 : 00000000`00000000 00000000`129ee4f0 00000000`129ee458 00000000`00000000 : combase!ObjectMethodExceptionHandlingAction<<lambda_b8ffcec6d47a5635f374132234a8dd15> >+0x62
00000000`129ee3e0 00007ff8`e496f98e : 00007ff8`d52af440 00000000`009e6850 00000000`05f307a0 00007ff8`c8906a80 : combase!DefaultStubInvoke+0x235
00000000`129ee600 00007ff8`e49718d0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`11d8f700 : combase!ServerCall::ContextInvoke+0x46e
00000000`129ee8d0 00007ff8`e49742bf : 00000000`08c15f80 00000000`08c15f80 00000000`06145180 00000000`00000000 : combase!AppInvoke+0x350
00000000`129eea80 00007ff8`e49733f4 : 00000000`06145328 00000000`06145180 00000000`11e6b190 00000000`11e407a0 : combase!ComInvokeWithLockAndIPID+0x54f
00000000`129eed10 00007ff8`e24d4e93 : 00000000`00000000 00000000`00000000 00007ff8`e49725f0 00007ff8`e49725f0 : combase!ThreadInvoke+0xe04
00000000`129eef80 00007ff8`e24d3b1a : 00007ff8`e4ab97a8 00000000`129ef1e0 00000000`129ef1e0 00000000`11e40650 : rpcrt4!DispatchToStubInCNoAvrf+0x33
00000000`129eefd0 00007ff8`e24d4920 : 00000000`11e46400 00000000`11e407a0 00000000`00000000 00000000`11e46400 : rpcrt4!RPC_INTERFACE::DispatchToStubWorker+0x29a
00000000`129ef0e0 00007ff8`e24e9e68 : 00000000`11e46400 00007ff8`e24d3002 00000000`000000b0 00000000`00000000 : rpcrt4!RPC_INTERFACE::DispatchToStubWithObject+0x160
00000000`129ef180 00007ff8`e24ea91f : 00000000`00038f2c 00007ff8`e24e8b90 00000000`00000000 00000000`00a56fd0 : rpcrt4!LRPC_SCALL::DispatchRequest+0x288
00000000`129ef260 00007ff8`e2518063 : 00000000`00000000 00000000`11e0a9d0 00000000`11e40650 00000000`00000000 : rpcrt4!LRPC_SCALL::HandleRequest+0x8df
00000000`129ef350 00007ff8`e25168d9 : 00000000`00a0b160 00000000`11e0a9d0 00000000`00a0b160 00000000`00a0b160 : rpcrt4!LRPC_SASSOCIATION::HandleRequest+0x1e3
00000000`129ef3d0 00007ff8`e2526ca2 : 00000000`00000000 00000000`00a0b268 00007ff8`e4c2aba0 00007ff8`e25b4ea4 : rpcrt4!LRPC_ADDRESS::ProcessIO+0xb29
00000000`129ef520 00007ff8`e4c2b9a9 : 00000000`00000290 00000000`05e71bc0 00007ff8`e2526bf0 00000000`009c3ad0 : rpcrt4!LrpcIoComplete+0xb2
00000000`129ef5c0 00007ff8`e4c299fe : 00000000`00000006 00000000`00000000 00000000`08b84b90 00000000`00000000 : ntdll!TppAlpcpExecuteCallback+0x239
00000000`129ef670 00007ff8`e2ab2d92 : 00000000`00000000 00007ff8`e4c29110 00000000`009c3ad0 00000000`00000000 : ntdll!TppWorkerThread+0x8ee
00000000`129efa70 00007ff8`e4bf9f64 : 00007ff8`e2ab2d70 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x22
00000000`129efaa0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x34
THREAD_SHA1_HASH_MOD_FUNC: e2aa158c3b41d4a9ecd489afdc7240e21216ae52
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 31700366030a10505a3d311f2a2b8d2f760d9c82
THREAD_SHA1_HASH_MOD: 5fdabe6d486164bae246de3533b847c4c82a370c
FAULT_INSTR_CODE: 48078b48
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: twinui_appcore!ViewWrapperBase::IsEqual+4a
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: twinui_appcore
IMAGE_NAME: twinui.appcore.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 55b99e01
STACK_COMMAND: .ecxr ; kb
BUCKET_ID: NULL_POINTER_READ_twinui_appcore!ViewWrapperBase::IsEqual+4a
PRIMARY_PROBLEM_CLASS: NULL_POINTER_READ_twinui_appcore!ViewWrapperBase::IsEqual+4a
BUCKET_ID_OFFSET: 4a
BUCKET_ID_MODULE_STR: twinui_appcore
BUCKET_ID_MODTIMEDATESTAMP: 55b99e01
BUCKET_ID_MODCHECKSUM: 20d946
BUCKET_ID_MODVER_STR: 10.0.10240.16412
BUCKET_ID_PREFIX_STR: NULL_POINTER_READ_
FAILURE_PROBLEM_CLASS: NULL_POINTER_READ
FAILURE_EXCEPTION_CODE: c0000005
FAILURE_IMAGE_NAME: twinui.appcore.dll
FAILURE_FUNCTION_NAME: ViewWrapperBase::IsEqual
BUCKET_ID_FUNCTION_STR: ViewWrapperBase::IsEqual
FAILURE_SYMBOL_NAME: twinui.appcore.dll!ViewWrapperBase::IsEqual
FAILURE_BUCKET_ID: NULL_POINTER_READ_c0000005_twinui.appcore.dll!ViewWrapperBase::IsEqual
WATSON_STAGEONE_URL: http://watson.microsoft.com/StageOne/explorer.exe/10.0.10240.16942/5749188e/twinui.appcore.dll/10.0.10240.16412/55b99e01/c0000005/0005a58a.htm?Retriage=1
TARGET_TIME: 2016-06-17T05:53:50.000Z
OSBUILD: 10240
OSSERVICEPACK: 16384
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 256
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt SingleUserTS
USER_LCID: 0
OSBUILD_TIMESTAMP: 2015-07-10 13:14:53
BUILDDATESTAMP_STR: 150709-1700
BUILDLAB_STR: th4
BUILDOSVER_STR: 10.0.10240.16384
ANALYSIS_SESSION_ELAPSED_TIME: 3e605
ANALYSIS_SOURCE: UM
FAILURE_ID_HASH_STRING: um:null_pointer_read_c0000005_twinui.appcore.dll!viewwrapperbase::isequal
FAILURE_ID_HASH: {d8f123b0-a23e-0711-10bf-e63f8cd301d1}
Followup: MachineOwner
0:063>
ExceptionAddress: 00007ff8d040a58a (twinui_appcore!ViewWrapperBase::IsEqual+0x000000000000004a)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000000
Version=1
EventType=APPCRASH
EventTime=131106162870820353
ReportType=2
Consent=1
UploadTime=131106162908640911
ReportFlags=524288
ReportIdentifier=876c6eb7-344f-11e6-9bcb-64006a6455a0
IntegratorReportIdentifier=22f8861e-e622-449b-8ba5-3bb1783bf31c
NsAppName=explorer.exe
Response.BucketId=ef8a99e3b9f3022531179c60da8e750a
Response.BucketTable=4
Response.LegacyBucketId=120494267394
Response.type=4
Sig[0].Name=Application Name
Sig[0].Value=explorer.exe
Sig[1].Name=Application Version
Sig[1].Value=10.0.10240.16942
Sig[2].Name=Application Timestamp
Sig[2].Value=5749188e
Sig[3].Name=Fault Module Name
Sig[3].Value=twinui.appcore.dll
Sig[4].Name=Fault Module Version
Sig[4].Value=10.0.10240.16412
Sig[5].Name=Fault Module Timestamp
Sig[5].Value=55b99e01
Sig[6].Name=Exception Code
Sig[6].Value=c0000005
Sig[7].Name=Exception Offset
Sig[7].Value=000000000005a58a
DynamicSig[1].Name=OS Version
DynamicSig[1].Value=10.0.10240.2.0.0.256.4
DynamicSig[2].Name=Locale ID
DynamicSig[2].Value=3081
DynamicSig[22].Name=Additional Information 1
DynamicSig[22].Value=e0cd
DynamicSig[23].Name=Additional Information 2
DynamicSig[23].Value=e0cd5eb3dc42e90b04afadd5f337ec6e
DynamicSig[24].Name=Additional Information 3
DynamicSig[24].Value=af24
DynamicSig[25].Name=Additional Information 4
DynamicSig[25].Value=af24bc6816b45f9086170a1b7668b3f3
UI[2]=C:\WINDOWS\explorer.exe
LoadedModule[0]=C:\WINDOWS\explorer.exe
LoadedModule[1]=C:\WINDOWS\SYSTEM32\ntdll.dll
LoadedModule[2]=C:\WINDOWS\system32\KERNEL32.DLL
LoadedModule[3]=C:\WINDOWS\system32\KERNELBASE.dll
LoadedModule[4]=C:\WINDOWS\system32\apphelp.dll
LoadedModule[5]=C:\WINDOWS\system32\msvcrt.dll
LoadedModule[6]=C:\WINDOWS\system32\OLEAUT32.dll
LoadedModule[7]=C:\WINDOWS\system32\combase.dll
LoadedModule[8]=C:\WINDOWS\system32\RPCRT4.dll
LoadedModule[9]=C:\WINDOWS\system32\powrprof.dll
LoadedModule[10]=C:\WINDOWS\system32\USER32.dll
LoadedModule[11]=C:\WINDOWS\system32\GDI32.dll
LoadedModule[12]=C:\WINDOWS\system32\SHCORE.dll
LoadedModule[13]=C:\WINDOWS\system32\SHLWAPI.dll
LoadedModule[14]=C:\WINDOWS\system32\SHELL32.dll
LoadedModule[15]=C:\WINDOWS\system32\windows.storage.dll
LoadedModule[16]=C:\WINDOWS\system32\advapi32.dll
LoadedModule[17]=C:\WINDOWS\system32\sechost.dll
LoadedModule[18]=C:\WINDOWS\system32\kernel.appcore.dll
LoadedModule[19]=C:\WINDOWS\system32\profapi.dll
LoadedModule[20]=C:\WINDOWS\system32\CRYPT32.dll
LoadedModule[21]=C:\WINDOWS\SYSTEM32\PROPSYS.dll
LoadedModule[22]=C:\WINDOWS\system32\MSASN1.dll
LoadedModule[23]=C:\WINDOWS\SYSTEM32\UxTheme.dll
LoadedModule[24]=C:\WINDOWS\SYSTEM32\dwmapi.dll
LoadedModule[25]=C:\WINDOWS\SYSTEM32\TWINAPI.dll
LoadedModule[26]=C:\WINDOWS\SYSTEM32\d3d11.dll
LoadedModule[27]=C:\WINDOWS\SYSTEM32\dcomp.dll
LoadedModule[28]=C:\WINDOWS\SYSTEM32\SspiCli.dll
LoadedModule[29]=C:\WINDOWS\SYSTEM32\USERENV.dll
LoadedModule[30]=C:\WINDOWS\SYSTEM32\SLC.dll
LoadedModule[31]=C:\WINDOWS\SYSTEM32\dxgi.dll
LoadedModule[32]=C:\WINDOWS\SYSTEM32\sppc.dll
LoadedModule[33]=C:\WINDOWS\system32\IMM32.DLL
LoadedModule[34]=C:\WINDOWS\system32\MSCTF.dll
LoadedModule[35]=C:\WINDOWS\SYSTEM32\bcryptPrimitives.dll
LoadedModule[36]=C:\WINDOWS\system32\ole32.dll
LoadedModule[37]=C:\WINDOWS\system32\clbcatq.dll
LoadedModule[38]=C:\WINDOWS\SYSTEM32\WINSTA.dll
LoadedModule[39]=C:\WINDOWS\SYSTEM32\cryptsp.dll
LoadedModule[40]=C:\WINDOWS\SYSTEM32\bcrypt.dll
LoadedModule[41]=C:\WINDOWS\system32\rsaenh.dll
LoadedModule[42]=C:\WINDOWS\SYSTEM32\CRYPTBASE.dll
LoadedModule[43]=C:\Windows\System32\ActXPrxy.dll
LoadedModule[44]=C:\WINDOWS\System32\IDStore.dll
LoadedModule[45]=C:\WINDOWS\System32\wlidprov.dll
LoadedModule[46]=C:\WINDOWS\SYSTEM32\Bcp47Langs.dll
LoadedModule[47]=C:\WINDOWS\SYSTEM32\SETTINGSYNCPOLICY.dll
LoadedModule[48]=C:\WINDOWS\SYSTEM32\policymanager.dll
LoadedModule[49]=C:\WINDOWS\SYSTEM32\msvcp110_win.dll
LoadedModule[50]=C:\WINDOWS\SYSTEM32\XmlLite.dll
LoadedModule[51]=C:\Windows\System32\TokenBroker.dll
LoadedModule[52]=C:\WINDOWS\SYSTEM32\wintypes.dll
LoadedModule[53]=C:\WINDOWS\SYSTEM32\wtsapi32.dll
LoadedModule[54]=C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll
LoadedModule[55]=C:\WINDOWS\SYSTEM32\SndVolSSO.DLL
LoadedModule[56]=C:\WINDOWS\SYSTEM32\HID.DLL
LoadedModule[57]=C:\WINDOWS\System32\MMDevApi.dll
LoadedModule[58]=C:\WINDOWS\System32\DEVOBJ.dll
LoadedModule[59]=C:\WINDOWS\system32\cfgmgr32.dll
LoadedModule[60]=C:\Windows\System32\iertutil.dll
LoadedModule[61]=C:\WINDOWS\SYSTEM32\mrmcorer.dll
LoadedModule[62]=C:\WINDOWS\SYSTEM32\OLEACC.dll
LoadedModule[63]=C:\Windows\System32\Windows.UI.dll
LoadedModule[64]=C:\Windows\System32\NInput.dll
LoadedModule[65]=C:\Windows\System32\vaultcli.dll
LoadedModule[66]=C:\WINDOWS\SYSTEM32\profext.dll
LoadedModule[67]=C:\WINDOWS\SYSTEM32\NTMARTA.dll
LoadedModule[68]=C:\WINDOWS\system32\dataexchange.dll
LoadedModule[69]=C:\WINDOWS\system32\d2d1.dll
LoadedModule[70]=C:\WINDOWS\system32\twinapi.appcore.dll
LoadedModule[71]=C:\WINDOWS\system32\windowscodecs.dll
LoadedModule[72]=C:\WINDOWS\system32\explorerframe.dll
LoadedModule[73]=C:\WINDOWS\system32\coml2.dll
LoadedModule[74]=C:\Windows\System32\TwinUI.dll
LoadedModule[75]=C:\Windows\System32\Windows.UI.Immersive.dll
LoadedModule[76]=C:\Windows\System32\windows.immersiveshell.serviceprovider.dll
LoadedModule[77]=C:\WINDOWS\SYSTEM32\WLDP.DLL
LoadedModule[78]=C:\WINDOWS\system32\WINTRUST.dll
LoadedModule[79]=C:\WINDOWS\System32\twinui.appcore.dll
LoadedModule[80]=C:\WINDOWS\System32\CoreMessaging.dll
LoadedModule[81]=C:\WINDOWS\System32\CoreUIComponents.dll
LoadedModule[82]=C:\WINDOWS\System32\ApplicationFrame.dll
LoadedModule[83]=C:\WINDOWS\SYSTEM32\elscore.dll
LoadedModule[84]=C:\WINDOWS\SYSTEM32\PhotoMetadataHandler.dll
LoadedModule[85]=C:\WINDOWS\SYSTEM32\rmclient.dll
LoadedModule[86]=C:\WINDOWS\System32\wpncore.dll
LoadedModule[87]=C:\WINDOWS\System32\WINHTTP.dll
LoadedModule[88]=C:\WINDOWS\SYSTEM32\NotificationController.dll
LoadedModule[89]=C:\WINDOWS\SYSTEM32\VEEventDispatcher.dll
LoadedModule[90]=C:\WINDOWS\SYSTEM32\urlmon.dll
LoadedModule[91]=C:\Windows\System32\BitsProxy.dll
LoadedModule[92]=C:\WINDOWS\system32\execmodelproxy.dll
LoadedModule[93]=C:\Windows\System32\Windows.Networking.Connectivity.dll
LoadedModule[94]=C:\WINDOWS\System32\npmproxy.dll
LoadedModule[95]=C:\Windows\System32\IPHLPAPI.DLL
LoadedModule[96]=C:\WINDOWS\system32\NSI.dll
LoadedModule[97]=C:\Windows\System32\WINNSI.DLL
LoadedModule[98]=C:\WINDOWS\SYSTEM32\wlanapi.dll
LoadedModule[99]=C:\Windows\System32\wwapi.dll
LoadedModule[100]=C:\WINDOWS\System32\NotificationObjFactory.dll
LoadedModule[101]=C:\Windows\System32\wcmapi.dll
LoadedModule[102]=C:\Windows\System32\msxml6.dll
LoadedModule[103]=C:\WINDOWS\system32\WS2_32.dll
LoadedModule[104]=C:\WINDOWS\SYSTEM32\ondemandconnroutehelper.dll
LoadedModule[105]=C:\WINDOWS\System32\webio.dll
LoadedModule[106]=C:\WINDOWS\system32\mswsock.dll
LoadedModule[107]=C:\WINDOWS\System32\DNSAPI.dll
LoadedModule[108]=C:\Windows\System32\rasadhlp.dll
LoadedModule[109]=C:\WINDOWS\System32\fwpuclnt.dll
LoadedModule[110]=C:\Windows\System32\AboveLockAppHost.dll
LoadedModule[111]=C:\WINDOWS\system32\schannel.DLL
LoadedModule[112]=C:\WINDOWS\SYSTEM32\ntshrui.dll
LoadedModule[113]=C:\WINDOWS\SYSTEM32\srvcli.dll
LoadedModule[114]=C:\WINDOWS\SYSTEM32\cscapi.dll
LoadedModule[115]=C:\WINDOWS\SYSTEM32\netutils.dll
LoadedModule[116]=C:\Windows\System32\Windows.StateRepository.dll
LoadedModule[117]=C:\Windows\System32\StateRepository.Core.dll
LoadedModule[118]=C:\Windows\System32\thumbcache.dll
LoadedModule[119]=C:\WINDOWS\SYSTEM32\MFPlat.DLL
LoadedModule[120]=C:\WINDOWS\SYSTEM32\RTWorkQ.DLL
LoadedModule[121]=C:\WINDOWS\SYSTEM32\AVRT.dll
LoadedModule[122]=C:\Windows\System32\Windows.Gaming.Input.dll
LoadedModule[123]=C:\WINDOWS\SYSTEM32\LINKINFO.dll
LoadedModule[124]=C:\WINDOWS\system32\NetworkExplorer.dll
LoadedModule[125]=C:\WINDOWS\SYSTEM32\MPR.dll
LoadedModule[126]=C:\WINDOWS\System32\drprov.dll
LoadedModule[127]=C:\WINDOWS\System32\ntlanman.dll
LoadedModule[128]=C:\WINDOWS\System32\davclnt.dll
LoadedModule[129]=C:\WINDOWS\System32\DAVHLPR.dll
LoadedModule[130]=C:\Windows\System32\ieframe.dll
LoadedModule[131]=C:\WINDOWS\SYSTEM32\mskeyprotect.dll
LoadedModule[132]=C:\WINDOWS\SYSTEM32\ncrypt.dll
LoadedModule[133]=C:\WINDOWS\SYSTEM32\NTASN1.dll
LoadedModule[134]=C:\WINDOWS\system32\ncryptsslp.dll
LoadedModule[135]=C:\WINDOWS\SYSTEM32\nvwgf2umx.dll
LoadedModule[136]=C:\WINDOWS\SYSTEM32\WINMM.dll
LoadedModule[137]=C:\WINDOWS\SYSTEM32\VERSION.dll
LoadedModule[138]=C:\WINDOWS\SYSTEM32\WINMMBASE.dll
LoadedModule[139]=C:\WINDOWS\SYSTEM32\gpapi.dll
LoadedModule[140]=C:\WINDOWS\system32\NotificationControllerPS.dll
LoadedModule[141]=C:\WINDOWS\System32\UIAnimation.dll
LoadedModule[142]=C:\WINDOWS\SYSTEM32\DPAPI.DLL
LoadedModule[143]=C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll
LoadedModule[144]=C:\Users\USER\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileSyncShell64.dll
LoadedModule[145]=C:\Users\USER\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\MSVCP120.dll
LoadedModule[146]=C:\Users\USER\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\MSVCR120.dll
LoadedModule[147]=C:\Users\USER\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\LoggingPlatform64.DLL
LoadedModule[148]=C:\WINDOWS\SYSTEM32\WININET.dll
LoadedModule[149]=C:\Users\USER\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
LoadedModule[150]=C:\WINDOWS\SYSTEM32\WSOCK32.dll
LoadedModule[151]=C:\WINDOWS\system32\mssprxy.dll
LoadedModule[152]=C:\WINDOWS\SYSTEM32\dsreg.dll
LoadedModule[153]=C:\WINDOWS\system32\WLDAP32.dll
LoadedModule[154]=C:\WINDOWS\SYSTEM32\samcli.dll
LoadedModule[155]=C:\WINDOWS\SYSTEM32\wkscli.dll
LoadedModule[156]=C:\WINDOWS\SYSTEM32\Secur32.dll
LoadedModule[157]=C:\WINDOWS\SYSTEM32\MLANG.dll
LoadedModule[158]=C:\WINDOWS\system32\stobject.dll
LoadedModule[159]=C:\WINDOWS\system32\BatMeter.dll
LoadedModule[160]=C:\WINDOWS\system32\WMICLNT.dll
LoadedModule[161]=C:\Windows\System32\InputSwitch.dll
LoadedModule[162]=C:\WINDOWS\System32\Windows.UI.Shell.dll
LoadedModule[163]=C:\WINDOWS\System32\wincorlib.DLL
LoadedModule[164]=C:\WINDOWS\system32\es.dll
LoadedModule[165]=C:\WINDOWS\system32\prnfldr.dll
LoadedModule[166]=C:\WINDOWS\system32\WINSPOOL.DRV
LoadedModule[167]=C:\WINDOWS\SYSTEM32\sxs.dll
LoadedModule[168]=C:\WINDOWS\System32\DeviceSetupManagerAPI.dll
LoadedModule[169]=C:\WINDOWS\system32\dxp.dll
LoadedModule[170]=C:\WINDOWS\system32\SETUPAPI.dll
LoadedModule[171]=C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.10240.16603_none_89ad014f9af1a159\gdiplus.dll
LoadedModule[172]=C:\WINDOWS\system32\SHDOCVW.dll
LoadedModule[173]=C:\WINDOWS\SYSTEM32\atlthunk.dll
LoadedModule[174]=C:\WINDOWS\system32\Syncreg.dll
LoadedModule[175]=C:\WINDOWS\System32\Actioncenter.dll
LoadedModule[176]=C:\WINDOWS\System32\wevtapi.dll
LoadedModule[177]=C:\WINDOWS\SYSTEM32\msiltcfg.dll
LoadedModule[178]=C:\WINDOWS\SYSTEM32\msi.dll
LoadedModule[179]=C:\WINDOWS\system32\wpdshserviceobj.dll
LoadedModule[180]=C:\Windows\System32\PortableDeviceTypes.dll
LoadedModule[181]=C:\Windows\System32\PortableDeviceApi.dll
LoadedModule[182]=C:\WINDOWS\system32\SettingMonitor.dll
LoadedModule[183]=C:\WINDOWS\system32\SettingSyncCore.dll
LoadedModule[184]=C:\WINDOWS\System32\cscui.dll
LoadedModule[185]=C:\WINDOWS\System32\CSCDLL.dll
LoadedModule[186]=C:\WINDOWS\System32\cscobj.dll
LoadedModule[187]=C:\WINDOWS\System32\srchadmin.dll
LoadedModule[188]=C:\WINDOWS\System32\SyncCenter.dll
LoadedModule[189]=C:\Windows\System32\imapi2.dll
LoadedModule[190]=C:\WINDOWS\SYSTEM32\AUDIOSES.DLL
LoadedModule[191]=C:\WINDOWS\system32\authui.dll
LoadedModule[192]=C:\WINDOWS\System32\pnidui.dll
LoadedModule[193]=C:\WINDOWS\system32\NetworkStatus.dll
LoadedModule[194]=C:\Windows\System32\NetSetupShim.dll
LoadedModule[195]=C:\Windows\System32\NetSetupApi.dll
LoadedModule[196]=C:\WINDOWS\System32\hgcpl.dll
LoadedModule[197]=C:\WINDOWS\System32\DUser.dll
LoadedModule[198]=C:\WINDOWS\System32\provsvc.dll
LoadedModule[199]=C:\WINDOWS\System32\netprofm.dll
LoadedModule[200]=C:\Windows\System32\bthprops.cpl
LoadedModule[201]=C:\Windows\System32\BluetoothApis.dll
LoadedModule[202]=C:\Windows\System32\dhcpcsvc6.DLL
LoadedModule[203]=C:\Windows\System32\dhcpcsvc.DLL
State[0].Key=Transport.DoneStage1
State[0].Value=1
FriendlyEventName=Stopped working
ConsentKey=APPCRASH
AppName=Windows Explorer
AppPath=C:\WINDOWS\explorer.exe
NsPartner=windows
NsGroup=windows8
ApplicationIdentity=92F607A4965196D26152B7C5C0C0A8C0
Chris
All replies (13)
Monday, June 20, 2016 2:34 AM
Hi Chris,
We need the dump file for further research.
Please upload the dump file onto OneDrive and share the link here so that we can do further analysis.
According to current information, I recommend we can try following steps to fix:
To scan all system files, open a command prompt as an administrator and type:
sfc /scannow
To un-register the twinui.appcore.dll file, open a command prompt as an administrator and type:
regsvr32 /u twinui.appcore.dll
To register the twinui.appcore.dll file, open a command prompt as an administrator and type:
regsvr32 twinui.appcore.dll
Then, see if this issue still persists.
In addition, I noticed the Dropbox is installed which also in loading module parse, we can try to remove it temporality to check the issue also. Please know that some 3rd part application may produce the conflicts which causing your issue.
Please mark the reply as an answer if you find it is helpful.
If you have feedback for TechNet Support, contact [email protected]
Monday, June 20, 2016 6:38 AM
Hi Kate,
Sure here is a link to one of the Dump files: https://1drv.ms/u/s!AnvUTvFIjkX16g0jXAN8ircvvSxp
My OneDrive on this machine is playing up, hopefully that link works for you.
I have run SFC and it was clean.
I will try re-registering the DLL and get back to you. I will disable DropBox too but if we have other staff with this problem who do not have DropBox.
Thanks
Chris
Tuesday, June 21, 2016 6:19 AM
Those things didn't seem to help, I noticed that just prior to the event this is also logged. Which leads to be believe the problem might be caused by .NET?
Application: Explorer.EXE
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: exception code c0000005, exception address 00007FF8594DA58A
Chris
Tuesday, June 21, 2016 7:52 AM
Hi,
Would you please let me know what remote app you used? Windows store app, right?
Would you mind to register the metro style components with following powershell command to see if it can fix your issue?
Get-AppXPackage | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register "$($_.InstallLocation)\AppXManifest.xml"}
Please mark the reply as an answer if you find it is helpful.
If you have feedback for TechNet Support, contact [email protected]
Tuesday, June 21, 2016 10:05 PM
Hi Kate,
It is a remote app via Windows Server 2012 R2. (Internal RDS collection)
I've also tried that powershell command already to reinstall the metro components. It reduces the amount of application errors in the application log but the crashes still occur seemingly randomly.
Did you have any luck downloading the DMP file?
Regards
Chris
Chris
Friday, June 24, 2016 9:25 AM
Yes, I have, but I noticed that it's just related to virtual desktop components. Have you set any virtual desktop on your Client PC? I mean this:
Would you mind to let me know what the app name is? If this is 3rd party one, try this configuration:
https://technet.microsoft.com/en-us/magazine/ff432698.aspx
Did you use build-in Access RemoteApp and Desktop to connect to your Remote app?
Would you please make sure to update both clients (check your build number could be 10586.420 as the latest version) and server host and check the issue again?
If the RemoteApp cause all client crash, I consider if there is any compatible issue on such app.
Please mark the reply as an answer if you find it is helpful.
If you have feedback for TechNet Support, contact [email protected]
Friday, June 24, 2016 5:04 PM
0:063> !analyze -v
*******************************************************************************
* *
* Exception Analysis *
* *
********************************************************************************** ERROR: Symbol file could not be found. Defaulted to export symbols for sppc.dll -
*** WARNING: Unable to verify timestamp for nvwgf2umx.dll
*** ERROR: Module load completed but symbols could not be loaded for nvwgf2umx.dll
*** WARNING: Unable to verify timestamp for DropboxExt64.34.dll
*** ERROR: Module load completed but symbols could not be loaded for DropboxExt64.34.dll
Two third party modules referenced, nvwgf2umx.dll and DropboxExt64.34.dll.
The nvwgf2umx.dll is a component of the NVIDIA graphics driver so if the issue persists try updating the NVIDIA graphics to the most recent version.
If the issue still persists try uninstalling and reinstalling Dropbox using the latest version.
Monday, June 27, 2016 5:15 AM
Kate,
I will check the machine but I do not believe so. The remote app is delivered using the built in Windows functionality as in your post.
Thanks
Auggy,
Thanks. The crashes have happened across multiple devices (for example this one is a Dell Desktop) but it also occurs on a Surface Pro 4 with the same DLL file causing the crashing (Twinappui.dll). I will see if DropBox is installed on the Surface device.
For now I've upgraded the problematic devices to Windows 10 1511 update with the latest patch. The application the are running via RemoteApp is a Microsoft ERP package so it was critical that it would work without triggering explorer to crash. I will see if that makes any difference for now.
Regards,
Chris
Chris
Monday, June 27, 2016 10:52 AM
Hi,
Thanks for your reply, please let me know your test results and hope we can get the root cause of this issue.
Please mark the reply as an answer if you find it is helpful.
If you have feedback for TechNet Support, contact [email protected]
Tuesday, June 28, 2016 5:58 AM
Hi Kate,
Since upgrading two test users with the issue to build 1511 (In place upgrade) they haven't had the crash once. I will continue to monitor for a few more days to see if the issue reoccurs.
This isn't an ideal solution but we were planning to Move to 1511 anyway at some point.
Regards
Chris
Chris
Thursday, June 30, 2016 2:50 AM
Hi Chris,
Since the upgrade can fix your issue, I consider that your scenario might be caused by system corrupted files. SFC scan has limitations to scan core system files, please try this command to repair system components, if not work, we can test if the upgrade repair as below guide and see if it can work for you.
Dism /online /cleanup-image /startcomponentcleanup
Dism /Online /Cleanup-Image /RestoreHealth
The guide for upgrade repair:
https://neosmart.net/wiki/windows-10-repair-installation/
Let me know once you get any updates.
Please mark the reply as an answer if you find it is helpful.
If you have feedback for TechNet Support, contact [email protected]
Wednesday, January 8, 2020 1:19 PM
Hi,
I just did the following:
1. Open Regedit
2. Navigate to Key HKLM\System\CurrentControlSet\control\lsa
3. Add DWORD LsaLookupCacheMaxSize
4. Set value to 0
5. Delete the key LsaLookupCacheMaxSize
7. Log in as the user
I have understood that this key "clear" the local cache.
Thank you very much!
Alexandre Smialoski
Alexandre Smialoski
Thursday, March 5, 2020 1:15 PM
Thank you Alexander. That tip worked for me too.
Florian