Fix it now
Event ID 1000 is the Application Error record: it names the process that died, the module that was executing when it died, an exception code and an offset. 0xc0000005 is an access violation. The module name is the lead worth following; the exception code only says how it died, not who killed it.
- Open Event Viewer, go to Windows Logs then Application, and filter for Event ID 1000. Open the newest entry and write down the faulting module name.
- Disable the add-ins: in the affected application go to File > Options > Add-ins, set Manage to COM Add-ins, click Go, clear the list and restart. Repeat with the application’s other add-in list in the same box.
- Restart normally and confirm the crash has gone before you change anything else.
- Re-enable one add-in at a time, restarting after each, until the crash comes back. That one is your answer.
- If it crashes with every add-in off, set the default printer to a driver-free target such as Microsoft Print to PDF and try again.
- If it still crashes, run an Online Repair: Settings > Apps > Apps & features, select your Office entry, choose Modify, then Online Repair.
Office keeps its own record of components that have crashed and can disable one silently. An add-in that has vanished from the active list has usually been parked there rather than uninstalled, so check that list before you conclude it was never installed.
If the application starts twice in a row and no new Event ID 1000 appears, you are done. The next section explains how to read the event and when the module name is worth nothing.
Why it happens
Two entries are written for the same crash and they come from different places. Event ID 1000 comes from the Application Error provider and names the failing process, the module executing at the moment of failure, the exception code and an offset. Event ID 1001 comes from Windows Error Reporting and records that the crash was captured. Worth knowing: the same id, 1001, from the Microsoft-Windows-WER-SystemErrorReporting provider means a kernel crash instead – so read the provider name, not just the number.
The exception code tells you the manner of death. 0xc0000005 is STATUS_ACCESS_VIOLATION: an instruction referenced memory that could not be read or written. 0xc0000006 is STATUS_IN_PAGE_ERROR, where the required data was not placed into memory because of an I/O error – which points at storage or at a file that is not really there, such as an online-only placeholder or a disconnected network path. Those two want completely different investigations, and the code is the only thing that separates them.
The faulting module is a strong lead only when it belongs to something other than Office. A third-party file name points at that product. A print driver file points at the default printer. A display driver file points at graphics acceleration. When the module is a core Windows library such as ntdll, or one of Office’s own shared libraries, the real offender is something that damaged the process earlier and the name is close to useless – and that is exactly the case where bisecting the add-ins beats any amount of reading.
A COM add-in is failing during load
You have this one if It crashes within seconds of launch, every time, and the faulting module traces to a named product.
- Disable every COM add-in under File > Options > Add-ins, then restart and confirm the crash has gone.
- Re-enable one at a time, restarting between each, and stop at the one that brings it back.
- Look for an updated build of that add-in, or remove it.
- Check the list where Office parks components it has disabled after a crash, because the one you are looking for may already be in it.
The default printer or its driver
You have this one if Word and Outlook crash at launch while applications that never ask about a printer are fine, or the faulting module is a driver file.
- Set the default printer to Microsoft Print to PDF, turn off the option that lets Windows manage the default, and relaunch.
- If that fixes it, remove the problem queue and reinstall it with a current driver from the manufacturer.
- Where the queue is shared from a server, install the driver locally and connect the printer by its own port instead.
Damaged templates, startup items or stored settings
You have this one if One application crashes and the others are fine, and it still crashes with the add-ins off.
- Change the template rather than deleting it, so it can be put back. For Word that is File > Options > Add-ins with Manage set to Templates.
- Empty the application’s startup folder of anything dropped there, and check the alternate startup location in its advanced options.
- For Outlook, create a fresh mail profile and start with that, without deleting the old one until the new one proves stable.
- Test with a brand new Windows account. If the crash does not follow, the fault is in the old profile rather than the installation.
Graphics acceleration or a display driver
You have this one if It crashes on launch or on the first redraw, often across several Office applications at once, with a graphics module named in the event.
- In any Office application that still starts, turn on the option to disable hardware graphics acceleration in the advanced options.
- Update the display driver from the hardware vendor rather than through generic update channels.
- On a remote session or virtual desktop, check the remote display driver too; it is a graphics driver like any other.
The file or the installation cannot be read
You have this one if The exception code is 0xc0000006 rather than 0xc0000005, or it only crashes opening files from one location.
- Copy the file locally and open the copy. Online-only cloud placeholders and disconnected network paths both produce this.
- Check the drive holding the installation and review the System log for disk warnings.
- If the installation itself is on a failing disk, deal with the disk before repairing Office, not after.
Full reference
Reading the event
| Field | What to do with it |
|---|---|
| Faulting application name | Confirms which process died, which matters when several Office applications are open |
| Faulting module name | The lead, when it belongs to something other than Office or Windows |
| Exception code | 0xc0000005 is an access violation; 0xc0000006 is an in-page error and a different investigation |
| Fault offset | Only meaningful with matching debug symbols; worth quoting to a vendor and useless on its own |
Which event, from which provider
| Event | Provider | What it records |
|---|---|---|
| 1000 | Application Error | An application crashed, with the module and exception |
| 1001 | Windows Error Reporting | The application crash was captured and bucketed |
| 1001 | Microsoft-Windows-WER-SystemErrorReporting | A kernel crash, which is a different problem entirely |
| 1002 | Application Hang | The application stopped responding rather than crashed |
Where the module name leads
| Faulting module belongs to | Where to look first |
|---|---|
| A third-party product you recognise | That vendor’s Office add-in: disable it and look for an update |
| A printer driver | The default printer; switch it and retest |
| A display or graphics driver | Hardware graphics acceleration, and the driver version |
| A core Windows library such as ntdll | Nothing directly. Bisect the add-ins instead |
| An Office library, crashing in one application only | That application’s templates, startup folder and stored settings |
Collecting a dump when the vendor asks for one
Windows can be told to write a dump automatically when a process crashes. The values live under HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps: DumpFolder sets where they go and defaults to %LOCALAPPDATA%\CrashDumps, DumpCount limits how many are kept and defaults to ten, and DumpType chooses a mini dump or a full one. Microsoft is clear that this fires after a crash and prior to termination – it is not the mechanism for a process that has merely stopped responding, which you capture by hand from Task Manager instead.
When only one user is affected
- Test with a second Windows account on the same machine before touching the installation.
- Compare the add-ins loaded under each account; COM add-ins register per user as well as per machine.
- Compare the default printer, which is per user.
- For Outlook, test a new mail profile, which is the single most productive check in that application.
- If the crash does not follow the user, stop investigating Office and rebuild the profile.
An Online Repair removes and reinstalls the product. It takes time, needs the account the installation was activated with, and will not remove the add-in, printer or template that caused the crash. Plan it rather than starting it on impulse, and do the ten minutes of add-in bisection first.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
Event ID 1000 |
Application Error: the record naming the failing process, the module executing at the time, the exception code and the offset | Microsoft Learn |
Event ID 1001 |
Windows Error Reporting recording the application crash. The same id from the WER system error reporting provider means a kernel crash instead | Microsoft Learn |
0xc0000005 |
STATUS_ACCESS_VIOLATION: an instruction referenced memory that could not be read or written | Microsoft Learn |
0xc0000006 |
STATUS_IN_PAGE_ERROR: the required data could not be placed into memory because of an I/O error | Microsoft Learn |
Confirm the fix worked
- Start every affected Office application twice in a row, normally rather than with add-ins disabled.
- Refresh the Application log and confirm no new Event ID 1000 has been written for those processes.
- Confirm the add-ins you intended to keep are listed as active, and that none has been parked in the disabled list again.
- Print a test page from the affected application if the printer was involved.
- Have the person who reported it work normally for a day before you close the ticket.
Questions people ask about this
Does a crash like this mean my Office licence is invalid?
No, and this costs nothing to fix. Licensing problems produce activation prompts and reduced functionality, not access violations. A crashing process is a code fault in Office or in something loaded into it.
Should I just reinstall Office straight away?
Not first. A reinstall takes an hour and usually leaves the add-in, printer or template that caused the crash exactly where it was. Ten minutes of add-in bisection identifies the cause and often makes the reinstall unnecessary.
What does the offset in the event mean?
It is the address inside the module where execution stopped, and it is meaningful only with the matching debug symbols. Quote it to the vendor by all means; it will tell you nothing on its own.
The crash only happens for one user on a shared machine.
Then the fault is in that user’s profile rather than the installation. Compare the add-ins loaded under each account and the default printer, and test with a brand new Windows account before touching the install.
The event says the faulting module is ntdll.dll. What do I do with that?
Nothing directly. A core Windows library named as the faulting module usually means something else damaged the process earlier and this is where it finally fell over. Go straight to bisecting the add-ins rather than researching the module.
