Jump to content

Windows 10 21H2 19044.1466 - Faulting module name: KERNELBASE.dll - Exception code: 0xc0000409


VictorC

Recommended Posts

Hello everybody,

I will try to describe my problem as accurately as possible. When updating KB5009543, the system notified me of a new NVIDIA driver. I installed it without first restarting after the windows update.
After the reboot, everything seemed to work. But that was not the case.
The explorer.exe started to restart every 15 minutes and the toolbar search stopped working. The search dialog just doesn't open at all.
So I tried the known procedures. In particular, I used a process monitor to check if SearchApp.exe had corrupted registry rights, etc. Everything seemed normal.
So I tried to fix the help of sfc /scannow - it didn't help.
DISM / Online / Cleanup-Image / ScanHealth also didn't help.
In the end, I decided to upgrade Windows inplace, which completed correctly, but the result = same error, same problem.
This exhausted my knowledge and I was stuck.
I would like to ask you for help if someone understands the situation better and can advise me how to fix the problem ...
Here is all the data I collected.
There are only three applications that crash = Explorer.exe, SearchApp.exe, and StartMenuExperienceHost.exe
I turned on the creation of dmp files and tried to analyze them using WinDbg, but unfortunately I couldn't find what the problem was and how to fix it.
Unfortunately, I only have a bit backup of the system from October 2021, and saving restore points has been disabled for unknown reasons, so I don't have any.
Maybe there Is an expert who can help me?
Many thanks in advance! Victor

Faulting application name: explorer.exe, version: 10.0.19041.1415, timestamp: 0x2d7da47f
Faulting module name: KERNELBASE.dll, version: 10.0.19041.1466, timestamp: 0xe01c7650
Exception code: 0xc0000409
Error offset: 0x000000000010b362
Faulting process ID: 0x729c
Faulting Application Start Time: 0x01d80ee0c5319bfd
Path to the missing application: C: \ Windows \ explorer.exe
Path to the faulting module: C: \ Windows \ System32 \ KERNELBASE.dll
Message ID: abadaa8b-cac2-4340-ad33-3946e8eaa1ff
Full name of the faulty package:
Application ID related to the missing package:
Faulting application name: StartMenuExperienceHost.exe, version: 0.0.0.0, timestamp: 0x4fe0bcb3
Faulting module name: KERNELBASE.dll, version: 10.0.19041.1466, timestamp: 0xe01c7650
Exception code: 0xc0000409
Error offset: 0x000000000010b362
Faulting process ID: 0x6b20
Faulting Application Start Time: 0x01d80ee2e88372e5
Faulting Application Path: C: \ WINDOWS \ SystemApps \ Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy \ StartMenuExperienceHost.exe
Path to the faulting module: C: \ Windows \ System32 \ KERNELBASE.dll
Message ID: d39ce9e0-f8ec-4dfd-a815-2f3d4bfd1dc8
Full name of the missing package: Microsoft.Windows.StartMenuExperienceHost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy
Application ID related to the missing package: App
Faulting application name: SearchApp.exe, version: 10.0.19041.1387, timestamp: 0xa2342d13
Faulting module name: KERNELBASE.dll, version: 10.0.19041.1466, timestamp: 0xe01c7650
Exception code: 0xc0000409
Error offset: 0x000000000010b362
Failing process ID: 0x6bbc
Faulting Application Start Time: 0x01d80ee3257e1e91
Faulting Application Path: C: \ WINDOWS \ SystemApps \ Microsoft.Windows.Search_cw5n1h2txyewy \ SearchApp.exe
Path to the faulting module: C: \ Windows \ System32 \ KERNELBASE.dll
Message ID: eb21abbc-61ce-4678-9243-961db2b68728
Full name of the missing package: Microsoft.Windows.Search_1.14.2.19041_neutral_neutral_cw5n1h2txyewy
Application ID related to the missing package: CortanaUI

Microsoft (R) Windows Debugger Version 10.0.22000.194 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\CrashDumps\explorer.exe.28936.dmp]
User Mini Dump File with Full Memory: Only application data is available


************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 10 Version 19044 MP (12 procs) Free x64
Product: WinNt, suite: SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Debug session time: Fri Jan 21 17:35:55.000 2022 (UTC + 1:00)
System Uptime: 0 days 9:16:05.819
Process Uptime: 0 days 0:15:00.000
................................................................
................................................................
................................................................
................................................................
.............................................................
Loading unloaded module list
.............................
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(7108.6914): Security check failure or stack buffer overrun - code c0000409 (first/second chance not available)
Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT 
For analysis of this file, run !analyze -v
KERNELBASE!RaiseFailFastException+0x152:
00007fff`4d48b362 0f1f440000      nop     dword ptr [rax+rax]
0:095> !analyze -v
*******************************************************************************
*                                                                             *
*                        Exception Analysis                                   *
*                                                                             *
*******************************************************************************

*** WARNING: Unable to verify checksum for StartMenuDLL.dll
DEBUG_FLR_EXCEPTION_CODE(8000ffff) and the ".exr -1" ExceptionCode(c0000409) don't match

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 159390

    Key  : Analysis.DebugAnalysisManager
    Value: Create

    Key  : Analysis.Elapsed.mSec
    Value: 164046

    Key  : Analysis.Init.CPU.mSec
    Value: 249

    Key  : Analysis.Init.Elapsed.mSec
    Value: 5157

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 563

    Key  : CLR.BuiltBy
    Value: NET48REL1LAST_C

    Key  : CLR.Engine
    Value: CLR

    Key  : CLR.Version
    Value: 4.8.4420.0

    Key  : FailFast.Name
    Value: FATAL_APP_EXIT

    Key  : FailFast.Type
    Value: 7

    Key  : Timeline.OS.Boot.DeltaSec
    Value: 33365

    Key  : Timeline.Process.Start.DeltaSec
    Value: 900

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Timestamp
    Value: 2019-12-06T14:06:00Z

    Key  : WER.OS.Version
    Value: 10.0.19041.1

    Key  : WER.Process.Version
    Value: 10.0.19041.1415


NTGLOBALFLAG:  0

PROCESS_BAM_CURRENT_THROTTLED: 0

PROCESS_BAM_PREVIOUS_THROTTLED: 0

APPLICATION_VERIFIER_FLAGS:  0

CONTEXT:  (.ecxr)
rax=000000000325d7b0 rbx=000000000325dd30 rcx=000000000325d7b0
rdx=0000000000000000 rsi=000000000325dd30 rdi=000000000325d7b0
rip=00007fff4d48b362 rsp=000000000325d6d0 rbp=0000000000000001
 r8=0000000000000000  r9=0000000000000000 r10=00000fffe9a91643
r11=0000000000000008 r12=00000000067924d0 r13=000000000325f820
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz na po nc
cs=0033  ss=002b  ds=002b  es=002b  fs=0053  gs=002b             efl=00000204
KERNELBASE!RaiseFailFastException+0x152:
00007fff`4d48b362 0f1f440000      nop     dword ptr [rax+rax]
Resetting default scope

EXCEPTION_RECORD:  (.exr -1)
ExceptionAddress: 00007fff4d48b362 (KERNELBASE!RaiseFailFastException+0x0000000000000152)
   ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  ExceptionFlags: 00000001
NumberParameters: 3
   Parameter[0]: 0000000000000007
   Parameter[1]: ffffffff8000ffff
   Parameter[2]: 00000000000000ec
Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT 

PROCESS_NAME:  explorer.exe

EXCEPTION_CODE_STR:  8000ffff

STACK_TEXT:  
00000000`0325d6d0 00007fff`15413f55     : 00000000`00000000 00007fff`4d48b210 00000000`00000000 00000000`0325fce0 : KERNELBASE!RaiseFailFastException+0x152
00000000`0325dcb0 00007fff`15414020     : 00000000`0325de60 00000000`00000000 00000000`0325def0 00000000`0325faf0 : StartTileData!wil::details::WilDynamicLoadRaiseFailFastException+0x55
00000000`0325dce0 00007fff`15413fff     : 00000000`00000000 00000000`00000001 00000000`0325e200 00000000`0122af60 : StartTileData!wil::details::WilRaiseFailFastException+0x18
00000000`0325dd10 00007fff`15412e5e     : 00007fff`1529fca8 00000000`00000003 00000000`0325fce0 00000000`00000000 : StartTileData!wil::details::WilFailFast+0x93
00000000`0325dde0 00007fff`15413194     : 00000000`00000001 00000000`011e0000 00000000`00000065 00007fff`4d3c96db : StartTileData!wil::details::ReportFailure+0x116
00000000`0325f320 00007fff`15412178     : 00000000`011fe9a0 00007fff`00800000 00000000`00004900 00007fff`4d295e1a : StartTileData!wil::details::ReportFailure_Hr+0x44
00000000`0325f380 00007fff`153e7e51     : 00000000`29df5194 00000000`00000000 00000000`011e0000 00000000`315e8018 : StartTileData!wil::details::in1diag3::FailFast_Unexpected+0x2c
00000000`0325f3d0 00007fff`1529fca8     : 00000000`31082430 00000000`0325fce0 00000000`311718b0 00000000`31172ad0 : StartTileData!std::_Hash<std::_Uset_traits<DataStoreCache::DataItemIdentifier,std::_Uhash_compare<DataStoreCache::DataItemIdentifier,std::hash<DataStoreCache::DataItemIdentifier>,std::equal_to<DataStoreCache::DataItemIdentifier> >,std::allocator<DataStoreCache::DataItemIdentifier>,0> >::_Insert_unverified<DataStoreCache::DataItemIdentifier,std::_List_unchecked_const_iterator<std::_List_val<std::_List_simple_types<DataStoreCache::DataItemIdentifier> >,std::_Iterator_base0> >+0x147d31
00000000`0325f780 00007fff`152eeae4     : 00000000`00000000 00000000`29c67bc0 00000000`0b6f2310 00000000`00000000 : StartTileData!WindowsInternal::Shell::CDSProperties::CDSTilePropertiesBatched::ReconcileTileLifetime+0x298
00000000`0325fa20 00007fff`152e4b20     : 00000000`29592d00 00000000`29592bb0 00000000`00000000 00000000`00000000 : StartTileData!WindowsInternal::Shell::CDSProperties::CDSTilePropertiesBatched::SetInitializationStage+0x54
00000000`0325fa50 00007fff`4e69e0b6     : 00000000`00000001 00000000`0b6f2310 00000000`01fd53f0 00000000`00000000 : StartTileData!<lambda_dedf2a98ad79067948dfc47d22b090e4>::operator()+0x220
00000000`0325fba0 00007fff`4e677295     : 00000000`0b6f23e0 00000000`0325fce0 00000000`0b6f2310 00000000`00000000 : SHCore!WorkThreadManager::CThread::RunCurrentTaskUnderLock+0x62
00000000`0325fbe0 00007fff`4e677170     : 00000000`00000000 00000000`00000001 00000000`29622c30 00000000`00000000 : SHCore!WorkThreadManager::CThread::ThreadProc+0xf5
00000000`0325fe70 00007fff`4e675971     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : SHCore!WorkThreadManager::CThread::s_ExecuteThreadProc+0x18
00000000`0325fea0 00007fff`4ef07034     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : SHCore!<lambda_9844335fc14345151eefcc3593dd6895>::<lambda_invoker_cdecl>+0x11
00000000`0325fed0 00007fff`4f862651     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x14
00000000`0325ff00 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x21


SYMBOL_NAME:  KERNELBASE!RaiseFailFastException+152

MODULE_NAME: KERNELBASE

IMAGE_NAME:  KERNELBASE.dll

STACK_COMMAND:  ~95s ; .ecxr ; kb

FAILURE_BUCKET_ID:  FAIL_FAST_FATAL_APP_EXIT_8000ffff_KERNELBASE.dll!RaiseFailFastException

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

IMAGE_VERSION:  10.0.19041.1466

FAILURE_ID_HASH:  {cb8699b5-42c9-a434-f7ea-cd5150ef8f73}

Followup:     MachineOwner
---------

Microsoft (R) Windows Debugger Version 10.0.22000.194 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\CrashDumps\StartMenuExperienceHost.exe.30780.dmp]
User Mini Dump File with Full Memory: Only application data is available


************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 10 Version 19044 MP (12 procs) Free x64
Product: WinNt, suite: SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Debug session time: Fri Jan 21 17:36:14.000 2022 (UTC + 1:00)
System Uptime: 0 days 9:16:24.617
Process Uptime: 0 days 0:00:01.000
................................................................
........................................................
Loading unloaded module list
.....
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(783c.7870): Security check failure or stack buffer overrun - code c0000409 (first/second chance not available)
Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT 
For analysis of this file, run !analyze -v
KERNELBASE!RaiseFailFastException+0x152:
00007fff`4d48b362 0f1f440000      nop     dword ptr [rax+rax]
0:011> !analyze -v
*******************************************************************************
*                                                                             *
*                        Exception Analysis                                   *
*                                                                             *
*******************************************************************************

DEBUG_FLR_EXCEPTION_CODE(8000ffff) and the ".exr -1" ExceptionCode(c0000409) don't match

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 2952

    Key  : Analysis.DebugAnalysisManager
    Value: Create

    Key  : Analysis.Elapsed.mSec
    Value: 3457

    Key  : Analysis.Init.CPU.mSec
    Value: 343

    Key  : Analysis.Init.Elapsed.mSec
    Value: 7543

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 357

    Key  : FailFast.Name
    Value: FATAL_APP_EXIT

    Key  : FailFast.Type
    Value: 7

    Key  : Timeline.OS.Boot.DeltaSec
    Value: 33384

    Key  : Timeline.Process.Start.DeltaSec
    Value: 1

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Timestamp
    Value: 2019-12-06T14:06:00Z

    Key  : WER.OS.Version
    Value: 10.0.19041.1


NTGLOBALFLAG:  0

PROCESS_BAM_CURRENT_THROTTLED: 0

PROCESS_BAM_PREVIOUS_THROTTLED: 0

APPLICATION_VERIFIER_FLAGS:  0

CONTEXT:  (.ecxr)
rax=00000068ad2fd6c0 rbx=00000068ad2fdc40 rcx=00000068ad2fd6c0
rdx=0000000000000000 rsi=00000068ad2fdc40 rdi=00000068ad2fd6c0
rip=00007fff4d48b362 rsp=00000068ad2fd5e0 rbp=0000000000000001
 r8=0000000000000000  r9=0000000000000000 r10=00000fffe9a91643
r11=0000000000000008 r12=0000019f20f296a0 r13=00000068ad2ff730
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz na po nc
cs=0033  ss=002b  ds=002b  es=002b  fs=0053  gs=002b             efl=00000204
KERNELBASE!RaiseFailFastException+0x152:
00007fff`4d48b362 0f1f440000      nop     dword ptr [rax+rax]
Resetting default scope

EXCEPTION_RECORD:  (.exr -1)
ExceptionAddress: 00007fff4d48b362 (KERNELBASE!RaiseFailFastException+0x0000000000000152)
   ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  ExceptionFlags: 00000001
NumberParameters: 3
   Parameter[0]: 0000000000000007
   Parameter[1]: ffffffff8000ffff
   Parameter[2]: 00000000000000ec
Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT 

PROCESS_NAME:  StartMenuExperienceHost.exe

EXCEPTION_CODE_STR:  8000ffff

STACK_TEXT:  
00000068`ad2fd5e0 00007fff`15413f55     : 00000000`00000000 00007fff`4d48b210 00000000`00000000 00000068`ad2ffbf0 : KERNELBASE!RaiseFailFastException+0x152
00000068`ad2fdbc0 00007fff`15414020     : 00000068`ad2fdd70 00000000`00000000 00000068`ad2fde00 00000068`ad2ffa00 : StartTileData!wil::details::WilDynamicLoadRaiseFailFastException+0x55
00000068`ad2fdbf0 00007fff`15413fff     : 00000000`00000000 00000000`00000001 00000068`ad2fe200 0000019f`13667cf0 : StartTileData!wil::details::WilRaiseFailFastException+0x18
00000068`ad2fdc20 00007fff`15412e5e     : 00007fff`1529fca8 00000000`00000003 00000068`ad2ffbf0 00000000`00000000 : StartTileData!wil::details::WilFailFast+0x93
00000068`ad2fdcf0 00007fff`15413194     : 00000000`00001000 00000000`00001000 00000000`00000065 00007fff`4d3c96db : StartTileData!wil::details::ReportFailure+0x116
00000068`ad2ff230 00007fff`15412178     : 00000000`01000000 00000000`00000000 00000000`00004900 00007fff`4d295e1a : StartTileData!wil::details::ReportFailure_Hr+0x44
00000068`ad2ff290 00007fff`153e7e51     : 00000000`00000007 00007fff`4f8333ea 00000000`00000004 00000000`00000073 : StartTileData!wil::details::in1diag3::FailFast_Unexpected+0x2c
00000068`ad2ff2e0 00007fff`1529fca8     : 0000019f`1f459550 00000068`ad2ffbf0 0000019f`20f30440 0000019f`20f665c0 : StartTileData!std::_Hash<std::_Uset_traits<DataStoreCache::DataItemIdentifier,std::_Uhash_compare<DataStoreCache::DataItemIdentifier,std::hash<DataStoreCache::DataItemIdentifier>,std::equal_to<DataStoreCache::DataItemIdentifier> >,std::allocator<DataStoreCache::DataItemIdentifier>,0> >::_Insert_unverified<DataStoreCache::DataItemIdentifier,std::_List_unchecked_const_iterator<std::_List_val<std::_List_simple_types<DataStoreCache::DataItemIdentifier> >,std::_Iterator_base0> >+0x147d31
00000068`ad2ff690 00007fff`152eeae4     : 00000000`00000000 0000019f`15bf9a40 0000019f`13711ec0 00007fff`1566f478 : StartTileData!WindowsInternal::Shell::CDSProperties::CDSTilePropertiesBatched::ReconcileTileLifetime+0x298
00000068`ad2ff930 00007fff`152e4b20     : 0000019f`173b8e00 0000019f`173b9280 0000019f`1f4c2a70 00007fff`1566e200 : StartTileData!WindowsInternal::Shell::CDSProperties::CDSTilePropertiesBatched::SetInitializationStage+0x54
00000068`ad2ff960 00007fff`4e69e0b6     : 00000000`00000001 0000019f`13711ec0 00000000`01fddaf3 00000000`00000000 : StartTileData!<lambda_dedf2a98ad79067948dfc47d22b090e4>::operator()+0x220
00000068`ad2ffab0 00007fff`4e677295     : 0000019f`13711f90 00000068`ad2ffbf0 0000019f`13711ec0 00000000`00001cff : SHCore!WorkThreadManager::CThread::RunCurrentTaskUnderLock+0x62
00000068`ad2ffaf0 00007fff`4e677170     : 00000000`00000000 00000000`00000001 0000019f`1f56ff10 00000000`00000000 : SHCore!WorkThreadManager::CThread::ThreadProc+0xf5
00000068`ad2ffd80 00007fff`4e675971     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : SHCore!WorkThreadManager::CThread::s_ExecuteThreadProc+0x18
00000068`ad2ffdb0 00007fff`4ef07034     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : SHCore!<lambda_9844335fc14345151eefcc3593dd6895>::<lambda_invoker_cdecl>+0x11
00000068`ad2ffde0 00007fff`4f862651     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x14
00000068`ad2ffe10 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x21


SYMBOL_NAME:  KERNELBASE!RaiseFailFastException+152

MODULE_NAME: KERNELBASE

IMAGE_NAME:  KERNELBASE.dll

STACK_COMMAND:  ~11s ; .ecxr ; kb

FAILURE_BUCKET_ID:  FAIL_FAST_FATAL_APP_EXIT_8000ffff_KERNELBASE.dll!RaiseFailFastException

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

IMAGE_VERSION:  10.0.19041.1466

FAILURE_ID_HASH:  {cb8699b5-42c9-a434-f7ea-cd5150ef8f73}

Followup:     MachineOwner
---------

Microsoft (R) Windows Debugger Version 10.0.22000.194 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\CrashDumps\SearchApp.exe.30096.dmp]
User Mini Dump File with Full Memory: Only application data is available


************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 10 Version 19044 MP (12 procs) Free x64
Product: WinNt, suite: SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Debug session time: Fri Jan 21 17:45:49.000 2022 (UTC + 1:00)
System Uptime: 0 days 9:25:59.943
Process Uptime: 0 days 0:01:57.000
................................................................
................................................................
.........................................
Loading unloaded module list
.
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(7590.76b0): Security check failure or stack buffer overrun - code c0000409 (first/second chance not available)
Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT 
For analysis of this file, run !analyze -v
KERNELBASE!RaiseFailFastException+0x152:
00007fff`4d48b362 0f1f440000      nop     dword ptr [rax+rax]
0:048> !analyze -v
*******************************************************************************
*                                                                             *
*                        Exception Analysis                                   *
*                                                                             *
*******************************************************************************

DEBUG_FLR_EXCEPTION_CODE(8000ffff) and the ".exr -1" ExceptionCode(c0000409) don't match

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 186046

    Key  : Analysis.DebugAnalysisManager
    Value: Create

    Key  : Analysis.Elapsed.mSec
    Value: 185942

    Key  : Analysis.Init.CPU.mSec
    Value: 343

    Key  : Analysis.Init.Elapsed.mSec
    Value: 4191

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 410

    Key  : FailFast.Name
    Value: FATAL_APP_EXIT

    Key  : FailFast.Type
    Value: 7

    Key  : Timeline.OS.Boot.DeltaSec
    Value: 33959

    Key  : Timeline.Process.Start.DeltaSec
    Value: 117

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Timestamp
    Value: 2019-12-06T14:06:00Z

    Key  : WER.OS.Version
    Value: 10.0.19041.1

    Key  : WER.Process.Version
    Value: 10.0.19041.1387


NTGLOBALFLAG:  0

PROCESS_BAM_CURRENT_THROTTLED: 0

PROCESS_BAM_PREVIOUS_THROTTLED: 0

APPLICATION_VERIFIER_FLAGS:  0

CONTEXT:  (.ecxr)
rax=00000005e23fd360 rbx=00000005e23fd8e0 rcx=00000005e23fd360
rdx=0000000000000000 rsi=00000005e23fd8e0 rdi=00000005e23fd360
rip=00007fff4d48b362 rsp=00000005e23fd280 rbp=0000000000000001
 r8=0000000000000000  r9=0000000000000000 r10=00000fffe9a91643
r11=0000000000000008 r12=000001b632a1cea0 r13=00000005e23ff3d0
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz na pe nc
cs=0033  ss=002b  ds=002b  es=002b  fs=0053  gs=002b             efl=00000200
KERNELBASE!RaiseFailFastException+0x152:
00007fff`4d48b362 0f1f440000      nop     dword ptr [rax+rax]
Resetting default scope

EXCEPTION_RECORD:  (.exr -1)
ExceptionAddress: 00007fff4d48b362 (KERNELBASE!RaiseFailFastException+0x0000000000000152)
   ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  ExceptionFlags: 00000001
NumberParameters: 3
   Parameter[0]: 0000000000000007
   Parameter[1]: ffffffff8000ffff
   Parameter[2]: 00000000000000ec
Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT 

PROCESS_NAME:  SearchApp.exe

EXCEPTION_CODE_STR:  8000ffff

STACK_TEXT:  
00000005`e23fd280 00007fff`15413f55     : 00000000`00000000 00007fff`4d48b210 00000000`00000000 00000005`e23ff890 : KERNELBASE!RaiseFailFastException+0x152
00000005`e23fd860 00007fff`15414020     : 00000005`e23fda10 00000000`00000000 00000005`e23fdaa0 00000005`e23ff6a0 : StartTileData!wil::details::WilDynamicLoadRaiseFailFastException+0x55
00000005`e23fd890 00007fff`15413fff     : 00000000`00000000 00000000`00000001 00000005`e23fde00 000001ae`24047260 : StartTileData!wil::details::WilRaiseFailFastException+0x18
00000005`e23fd8c0 00007fff`15412e5e     : 00007fff`1529fca8 00000000`00000003 00000005`e23ff890 00000000`00000000 : StartTileData!wil::details::WilFailFast+0x93
00000005`e23fd990 00007fff`15413194     : 000001ae`23e10100 00000000`00001000 00000000`00000065 00007fff`4d3c96db : StartTileData!wil::details::ReportFailure+0x116
00000005`e23feed0 00007fff`15412178     : 000001ae`2400e0b0 00000000`00001000 00000000`00004900 00007fff`4d295e1a : StartTileData!wil::details::ReportFailure_Hr+0x44
00000005`e23fef30 00007fff`153e7e51     : 000001b6`32e39884 00000000`0000000c 000001ae`23e10100 000001b6`45000000 : StartTileData!wil::details::in1diag3::FailFast_Unexpected+0x2c
00000005`e23fef80 00007fff`1529fca8     : 000001b6`32747a50 00000005`e23ff890 000001b6`44ff8680 000001b6`44ff9b40 : StartTileData!std::_Hash<std::_Uset_traits<DataStoreCache::DataItemIdentifier,std::_Uhash_compare<DataStoreCache::DataItemIdentifier,std::hash<DataStoreCache::DataItemIdentifier>,std::equal_to<DataStoreCache::DataItemIdentifier> >,std::allocator<DataStoreCache::DataItemIdentifier>,0> >::_Insert_unverified<DataStoreCache::DataItemIdentifier,std::_List_unchecked_const_iterator<std::_List_val<std::_List_simple_types<DataStoreCache::DataItemIdentifier> >,std::_Iterator_base0> >+0x147d31
00000005`e23ff330 00007fff`152eeae4     : 00000000`00000000 000001b6`323fc640 000001ae`24111d40 00007fff`1566f478 : StartTileData!WindowsInternal::Shell::CDSProperties::CDSTilePropertiesBatched::ReconcileTileLifetime+0x298
00000005`e23ff5d0 00007fff`152e4b20     : 000001ae`304077c0 000001ae`30407730 000001ae`26d06070 00007fff`4f8348d0 : StartTileData!WindowsInternal::Shell::CDSProperties::CDSTilePropertiesBatched::SetInitializationStage+0x54
00000005`e23ff600 00007fff`4e69e0b6     : 00000000`00000001 000001ae`24111d40 00000000`0206a1a7 00000000`00000000 : StartTileData!<lambda_dedf2a98ad79067948dfc47d22b090e4>::operator()+0x220
00000005`e23ff750 00007fff`4e677295     : 000001ae`24111e10 00000005`e23ff890 000001ae`24111d40 00000000`00000000 : SHCore!WorkThreadManager::CThread::RunCurrentTaskUnderLock+0x62
00000005`e23ff790 00007fff`4e677170     : 00000000`00000000 00000000`00000001 000001ae`26d06070 00000000`00000000 : SHCore!WorkThreadManager::CThread::ThreadProc+0xf5
00000005`e23ffa20 00007fff`4e675971     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : SHCore!WorkThreadManager::CThread::s_ExecuteThreadProc+0x18
00000005`e23ffa50 00007fff`4ef07034     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : SHCore!<lambda_9844335fc14345151eefcc3593dd6895>::<lambda_invoker_cdecl>+0x11
00000005`e23ffa80 00007fff`4f862651     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x14
00000005`e23ffab0 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x21


SYMBOL_NAME:  KERNELBASE!RaiseFailFastException+152

MODULE_NAME: KERNELBASE

IMAGE_NAME:  KERNELBASE.dll

STACK_COMMAND:  ~48s ; .ecxr ; kb

FAILURE_BUCKET_ID:  FAIL_FAST_FATAL_APP_EXIT_8000ffff_KERNELBASE.dll!RaiseFailFastException

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

IMAGE_VERSION:  10.0.19041.1466

FAILURE_ID_HASH:  {cb8699b5-42c9-a434-f7ea-cd5150ef8f73}

Followup:     MachineOwner
---------

 

Link to comment
Share on other sites

  • 6 months later...

I have the EXACT same problem for the most part.

My search bar is working though. I have indexing disabled and the Windows Search service disabled.

Quote

The explorer.exe started to restart every 15 minutes and the toolbar search stopped working.

Exact same problem here. Explorer keeps restarting every 15-20min. I literally did a complete and fresh reinstall of Windows two days ago hoping to fix this exact problem, and it happened again just two minutes ago. Right after I finished setting up my computer how I like it. I am really bummed because I can't find a solution anywhere on the net.

From my event logs:
 

Faulting application name: Explorer.EXE, version: 10.0.19041.1806, time stamp: 0xa02987c8
Faulting module name: SHELL32.dll, version: 10.0.19041.1806, time stamp: 0x70c04167
Exception code: 0xc0000005
Fault offset: 0x000000000056a779
Faulting process id: 0x1c54
Faulting application start time: 0x01d89fd8bf9b8860
Faulting application path: C:\Windows\Explorer.EXE
Faulting module path: C:\Windows\System32\SHELL32.dll
Report Id: 08a4aeea-7911-40a0-9781-68886fbd4e2a
Faulting package full name: 
Faulting package-relative application ID: 
Faulting application name: SearchApp.exe, version: 10.0.19041.1806, time stamp: 0xe2377848
Faulting module name: KERNELBASE.dll, version: 10.0.19041.1826, time stamp: 0x299341e8
Exception code: 0xc0000409
Fault offset: 0x000000000010fb62
Faulting process id: 0x2694
Faulting application start time: 0x01d8a10d9b144df6
Faulting application path: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: b7644185-4b52-47d9-9876-0934f833a493
Faulting package full name: Microsoft.Windows.Search_1.14.6.19041_neutral_neutral_cw5n1h2txyewy
Faulting package-relative application ID: CortanaUI


If anyone stumbles across this and previously managed to fix the problem, please register an account and post what you can. This is driving me (and I'm sure quite a few other people) nuts.

I want to mention one last thing. My CPU is overclocked a bit. I'm running at 4.9Ghz. I'm wondering/concerned if maybe I am under-volted.

@VictorC Do you have any kind of overclock running on your system?
 

Link to comment
Share on other sites

On 7/26/2022 at 7:24 PM, visusys said:

@VictorC Do you have any kind of overclock running on your system?

 

Hello,
no, my CPU is not overclocked, everything is in default... but still haveing the problem :-( nothing helped.....
VicC

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...