Kernel_security_check_failure


  1. Posts : 101
    Microsoft Windows 10 Education 64-bit 14393 Multiprocessor Free
       #1

    Kernel_security_check_failure


    Getting BSOD at random parts of the day with the last one happening while I was installing a program called LTspice. Can't seem to force the computer to BSOD by doing any one particular thing. For some reason, only one dump files seems to show up in the folder as the older ones are overwritten every time the computer BSOD.

    Attachment 175783
      My Computers


  2. Posts : 41,472
    windows 10 professional version 1607 build 14393.969 64 bit
       #2

    There were 2 BSOD mini dump files and when debugged they did not display a definitive driver.
    The bugchecks were 139, and 24.
    The logs displayed older bugchecks: 7E, 1A, A, 50.
    The files displayed drive file system corruption.
    Windows fast startup failed.

    For all tests /steps please post images into the thread.
    If there are any problems posting images please use one drive or drop box share links.
    Share OneDrive files and folders - Office Support
    Upload photos and files to OneDrive - OneDrive
    Share OneDrive files and folders - Office Support
    Upload photos and files to OneDrive - OneDrive

    1) Open administrative command prompt and type or copy and paste:
    2) sfc /scannow
    3) dism /online /cleanup-image /restorehealth
    4) When these have completed > right click on the top bar or title bar of the administrative command prompt box > left click on edit then select all > right click on the top bar again > left click on edit then copy > paste into the thread
    5) chkdsk /x /f /r C:
    6) chkdsk /x /f /r D:

    C:\Windows\system32>chkdsk /x /f /r
    The type of the file system is NTFS.
    Cannot lock current drive.


    Chkdsk cannot run because the volume is in use by another
    process. Would you like to schedule this volume to be
    checked the next time the system restarts? (Y/N)

    Type: Y
    reboot
    This may take many hours so plan to run overnight

    7) Use the information in this link to find the chkdsk reports in the event viewer. Copy and paste > notepad > save to desktop > post into the thread:
    Read Chkdsk Log in Event Viewer in Windows 10 Performance Maintenance Tutorials

    8) Make sure that there is no over clocking while troubleshooting.

    9) Sometimes there are problems in the bios that produce bsod.
    The BIOS: Version/Date American Megatrends Inc. P1.60, 6/13/2016
    10) Please check to see if this is the most up to date version.
    11) Open the website for the computer or motherboard manufacturer to view the drivers and post a URL or hyperlink into the thread.

    12) To ensure that there are no improper bios settings please reset the bios.
    13) Sometimes there can be failure to boot after resetting the bios.
    14) Backup the computer files to another drive or to the cloud.
    15) Make a backup image usig Macrium:
    Macrium Software | Macrium Reflect Free:
    Macrium Software | Macrium Reflect Free

    16) And please create a brand new restore point.

    How to Clear Your Computers CMOS to Reset BIOS Settings:
    How to Clear Your Computers CMOS to Reset BIOS Settings
    3 Ways to Reset Your BIOS - wikiHow:
    3 Ways to Reset Your BIOS - wikiHow

    17) If the computer has Ccleaner > click windows tab > scroll down to system and advanced > post an image into the thread

    18) In the left lower corner search type clean > open disk cleanup > scroll up and down > post images into the thread
    19) In the left lower corner search type: system or system control > open system control panel > on the left pane click advanced system settings
    > on the advanced tab under startup and recovery click settings > post an image of the startup and recovery into the thread.
    > on the advanced tab under performance > click on settings > click on advanced tab > under virtual memory click on change > post an image of the virtual memory tab into the thread

    20) Run HDTune on every drivehttp://www.hdtune.com/
    Post images in the thread for results of these tests:
    a) Health (SMART)
    b) Benchmark
    c) Full error scan

    21) For any BSOD please use this version of the log collector and post a new zip into the thread:
    log collector v2-beta08.zip

    22) Run memtest86+ version 5.01 for at least 8 passes.
    Memtest86+ - Advanced Memory Diagnostic Tool
    This may take hours so plan to run it overnight.
    a) Please make sure you use the Memtest86+ version 5.01 with the link below.
    Memtest86+ - Advanced Memory Diagnostic Tool
    The testing is done not by time but by passes.
    The more passes the better.
    There are a significant number of false negatives if fewer than 8 passes are made.
    A false negative is a test pass when there is malfunctioning RAM.
    There is 16 GB of RAM on the computer.
    Memtest86+ version 5.01 testing takes approximately 1 - 2 hours /GB RAM
    Just 1 error is a fail and you can abort testing.
    Then test 1 RAM module at a time in the same DIMM each for 8 or more passes.
    b) When Memtest86+ has completed 8 or more passes use a camera or smart phone camera to take a picture and post an image into the thread.
    Memory problems. - Microsoft Community
    MemTest86+ - Test RAM BSOD Tutorials

    23) Turn off Windows fast startup:
    Turn On or Off Fast Startup in Windows 10 Performance Maintenance Tutorials



    Code:
    Event[3933]:  Log Name: System  Source: Ntfs  Date: 2018-01-02T09:59:40.837  Event ID: 55  Task: N/A  Level: Error  Opcode: Info  Keyword: N/A  User: S-1-5-18  User Name: NT AUTHORITY\SYSTEM  Computer: DESKTOP-2UMU17L  Description: A corruption was discovered in the file system structure on volume C:.The exact nature of the corruption is unknown.  The file system structures need to be scanned online.
    Code:
    Event[789]:  Log Name: System  Source: Microsoft-Windows-Kernel-Boot  Date: 2017-11-08T14:52:24.628  Event ID: 29  Task: N/A  Level: Error  Opcode: Info  Keyword: N/A  User: S-1-5-18  User Name: NT AUTHORITY\SYSTEM  Computer: DESKTOP-2UMU17L  Description: Windows failed fast startup with error status 0xC0000411.
    Code:
    Event[3996]:  Log Name: System  Source: Microsoft-Windows-Ntfs  Date: 2018-01-03T14:05:53.897  Event ID: 98  Task: N/A  Level: Warning  Opcode: Info  Keyword: N/A  User: S-1-5-18  User Name: NT AUTHORITY\SYSTEM  Computer: DESKTOP-2UMU17L  Description: Volume ?? (\Device\HarddiskVolumeShadowCopy6) requires an Online Scan.  An Online Scan will automatically run as part of the next scheduled maintenance task.  Alternatively you may run "CHKDSK /SCAN" locally via the command line, or run "REPAIR-VOLUME <drive:> -SCAN" locally or remotely via PowerShell.
    Code:
    Event[3146]:  Log Name: System  Source: Disk  Date: 2017-12-12T09:02:00.276  Event ID: 51  Task: N/A  Level: Warning  Opcode: N/A  Keyword: Classic  User: N/A  User Name: N/A  Computer: DESKTOP-2UMU17L  Description: An error was detected on device \Device\Harddisk1\DR1 during a paging operation.Event[3147]:  Log Name: System  Source: Disk  Date: 2017-12-12T09:02:00.276  Event ID: 51  Task: N/A  Level: Warning  Opcode: N/A  Keyword: Classic  User: N/A  User Name: N/A  Computer: DESKTOP-2UMU17L  Description: An error was detected on device \Device\Harddisk1\DR1 during a paging operation.
    Code:
    Event[3886]:  Log Name: System  Source: Volsnap  Date: 2018-01-02T09:44:40.372  Event ID: 30  Task: N/A  Level: Warning  Opcode: N/A  Keyword: Classic  User: N/A  User Name: N/A  Computer: DESKTOP-2UMU17L  Description: An unfinished create of a shadow copy of volume C: was deleted.
    Code:
    1/26/2018 3:32 AM    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 1000007e
    P2: ffffffffc0000005
    P3: fffff803be8b5ddd
    P4: fffff40ef3bc62f8
    P5: fffff40ef3bc5b40
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\012518-7812-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-15968-0.sysdata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER47C7.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER47D6.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER47E7.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_1000007e_dd610545af1d09eb5e2b7ffeb3262bdc2d81080_00000000_cab_02c847e6
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 7f768b83-5a07-4232-a17b-401485a87b9b
    Report Status: 4
    Hashed bucket:1/2/2018 3:44 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 139
    P2: 3
    P3: ffff890c16cecda0
    P4: ffff890c16ceccf8
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\010218-8218-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-12484-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER396F.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER397E.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER397F.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_139_f26ee97a41ae76923e9a39e3813751bdb4cdc5a_00000000_cab_02e0398e
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 8294c8d0-fde7-4833-b2d7-79c402c5e181
    Report Status: 4
    Hashed bucket:
    2/5/2018 11:01 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 139
    P2: 3
    P3: ffffeb8fe7475550
    P4: ffffeb8fe74754a8
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\020518-7156-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11093-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3884.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER38B3.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER38C4.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_139_83b5ca84d7e761a44635e12af855c857d9c66fa_00000000_cab_02dc38d2
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: cf24275c-96d7-434c-a94a-67dc008a83e8
    Report Status: 4
    Hashed bucket:
    1/17/2018 9:26 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 1a
    P2: 41792
    P3: ffffb08141d7a258
    P4: 8
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\011718-8218-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-14750-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER42C5.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER42D5.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER42E6.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_1a_c82767e63aa7279162f1b2a6378113ddab5badd_00000000_cab_02e042e5
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: fa8c195f-f1fe-4e44-9e81-ee6973d157e3
    Report Status: 4
    Hashed bucket:
    12/4/2017 6:10 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 24
    P2: af000c0966
    P3: 99237
    P4: 1000000
    P5: 1000000
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120417-7625-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11296-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AD6.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AE6.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AF6.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_24_44ff2898fa3f8e145624aa98a8d112ec3c95816_00000000_cab_02e03b15
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: c6ff02eb-2c60-4c89-9100-91a5aad770db
    Report Status: 4
    Hashed bucket:
    11/7/2017 6:10 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 50
    P2: fffffffffffffff0
    P3: 0
    P4: fffff8023c97f04b
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\110717-8000-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11609-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3894.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER38A4.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER38A5.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_50_6eb44d8f88c698de684f5ce3f4e4fab5f02f20_00000000_cab_02e038a4
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: fa007614-9a2a-4110-a0d5-42f2054c7b9c
    Report Status: 4
    Hashed bucket:
    2/2/2018 9:45 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: a
    P2: 38
    P3: 2
    P4: 0
    P5: fffff801568b2785
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\020218-8015-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11781-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3827.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3836.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3847.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_48fcd539e34bb339738d9274f1fd799c818e3313_00000000_cab_02e03846
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 507bae52-ffaf-49ec-8ec5-fb47efdc3d86
    Report Status: 4
    Hashed bucket:
    12/4/2017 6:38 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 966873f1-6b77-4441-adc1-b1cec5f61021
    
    Problem signature:
    P1: 24
    P2: af000c0966
    P3: 99237
    P4: 1000000
    P5: 1000000
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120417-7625-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11296-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AD6.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AE6.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AF6.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_24_44ff2898fa3f8e145624aa98a8d112ec3c95816_00000000_cab_02e03b15
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: c6ff02eb-2c60-4c89-9100-91a5aad770db
    Report Status: 4
    Hashed bucket:
    12/4/2017 6:17 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 966873f1-6b77-4441-adc1-b1cec5f61021
    
    Problem signature:
    P1: 24
    P2: af000c0966
    P3: 99237
    P4: 1000000
    P5: 1000000
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120417-7625-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11296-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AD6.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AE6.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AF6.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_24_44ff2898fa3f8e145624aa98a8d112ec3c95816_00000000_cab_02e03b15
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: c6ff02eb-2c60-4c89-9100-91a5aad770db
    Report Status: 4
    Hashed bucket:
    12/4/2017 6:10 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 966873f1-6b77-4441-adc1-b1cec5f61021
    
    Problem signature:
    P1: 24
    P2: af000c0966
    P3: 99237
    P4: 1000000
    P5: 1000000
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120417-7625-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11296-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AD6.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AE6.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AF6.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_24_44ff2898fa3f8e145624aa98a8d112ec3c95816_00000000_cab_02e03b15
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: c6ff02eb-2c60-4c89-9100-91a5aad770db
    Report Status: 4
    Hashed bucket:
    Code:
    1/2/2018 3:46 PM    Windows Error Reporting    Fault bucket 0x139_3_CORRUPT_LIST_ENTRY_nt!MiUnlinkUnusedControlArea, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 4e1684ec-31d6-4cc0-bfd6-314b3e83da33
    
    Problem signature:
    P1: 139
    P2: 3
    P3: ffff890c16cecda0
    P4: ffff890c16ceccf8
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\010218-8218-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-12484-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER396F.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER397E.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER397F.tmp.txt
    \\?\C:\Windows\Temp\WER593C.tmp.WERDataCollectionStatus.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_139_f26ee97a41ae76923e9a39e3813751bdb4cdc5a_00000000_cab_15c17589
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 8294c8d0-fde7-4833-b2d7-79c402c5e181
    Report Status: 268435456
    Hashed bucket:2/5/2018 11:01 PM    Windows Error Reporting    Fault bucket 0x139_3_CORRUPT_LIST_ENTRY_ONE_BIT_IMAGE_memory_corruption, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 2a22cc94-fa25-45d8-a9e0-b8cc142522ab
    
    Problem signature:
    P1: 139
    P2: 3
    P3: ffffeb8fe7475550
    P4: ffffeb8fe74754a8
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\020518-7156-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11093-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3884.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER38B3.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER38C4.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_139_83b5ca84d7e761a44635e12af855c857d9c66fa_00000000_cab_1e805d14
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: cf24275c-96d7-434c-a94a-67dc008a83e8
    Report Status: 268435456
    Hashed bucket:
    12/4/2017 6:52 PM    Windows Error Reporting    Fault bucket 0x24_NTFS!NtfsPagingFileIo, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 966873f1-6b77-4441-adc1-b1cec5f61021
    
    Problem signature:
    P1: 24
    P2: af000c0966
    P3: 99237
    P4: 1000000
    P5: 1000000
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\120417-7625-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11296-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AD6.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AE6.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AF6.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_24_44ff2898fa3f8e145624aa98a8d112ec3c95816_00000000_cab_180afc68
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: c6ff02eb-2c60-4c89-9100-91a5aad770db
    Report Status: 268435460
    Hashed bucket:
    Code:
    2/2/2018 9:45 PM    Windows Error Reporting    Fault bucket AV_nt!MmCopyVirtualMemory, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 708ae890-6dd5-40f0-96ba-c70db174d1f2
    
    Problem signature:
    P1: a
    P2: 38
    P3: 2
    P4: 0
    P5: fffff801568b2785
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\020218-8015-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11781-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3827.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3836.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3847.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_a_48fcd539e34bb339738d9274f1fd799c818e3313_00000000_cab_167859b8
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 507bae52-ffaf-49ec-8ec5-fb47efdc3d86
    Report Status: 268435456
    Hashed bucket:11/7/2017 6:10 PM    Windows Error Reporting    Fault bucket AV_R_INVALID_nt!ObfDereferenceObjectWithTag, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 77550f71-ef60-4ede-86ac-3797c2bc6533
    
    Problem signature:
    P1: 50
    P2: fffffffffffffff0
    P3: 0
    P4: fffff8023c97f04b
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\110717-8000-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-11609-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3894.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER38A4.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER38A5.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_50_6eb44d8f88c698de684f5ce3f4e4fab5f02f20_00000000_cab_15286f63
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: fa007614-9a2a-4110-a0d5-42f2054c7b9c
    Report Status: 268435456
    Hashed bucket:
    1/26/2018 3:32 AM    Windows Error Reporting    Fault bucket AV_wdfilter!MpDeleteStreamContext, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 6427ae04-9667-4114-87d5-e6edd986d948
    
    Problem signature:
    P1: 1000007e
    P2: ffffffffc0000005
    P3: fffff803be8b5ddd
    P4: fffff40ef3bc62f8
    P5: fffff40ef3bc5b40
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\012518-7812-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-15968-0.sysdata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER47C7.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER47D6.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER47E7.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_1000007e_dd610545af1d09eb5e2b7ffeb3262bdc2d81080_00000000_cab_19c4a344
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 7f768b83-5a07-4232-a17b-401485a87b9b
    Report Status: 268435456
    Hashed bucket:
    1/17/2018 9:26 PM    Windows Error Reporting    Fault bucket MEMORY_CORRUPTION_ONE_BIT, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 104f0b22-2193-41ce-992a-2d205088e48d
    
    Problem signature:
    P1: 1a
    P2: 41792
    P3: ffffb08141d7a258
    P4: 8
    P5: 0
    P6: 10_0_16299
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\011718-8218-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-14750-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER42C5.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER42D5.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER42E6.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_1a_c82767e63aa7279162f1b2a6378113ddab5badd_00000000_cab_17406e0b
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: fa8c195f-f1fe-4e44-9e81-ee6973d157e3
    Report Status: 268435456
    Hashed bucket:
      My Computer


  3. Posts : 101
    Microsoft Windows 10 Education 64-bit 14393 Multiprocessor Free
    Thread Starter
       #3

    To add some more info. I ran driver verifier and got a BSOD from mbamswissarmy.sys which seems to be part of MalwareBytes. Don't know if this is the problem or just a symptom of a bigger issue.
      My Computers


  4. Posts : 5,169
    64bit Win 10 Pro ver 21H2
       #4

    Hello jag213,

    I would uninstall Malwarebytes if Driver Verifier indicated its driver was misbehaving and see if it makes any difference. If not you can always add it back later.

    From my check of the original set of logfiles I would concentrate on testing memory and hard disks for problems as suggested by @zbook.
      My Computers


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 19:22.
Find Us




Windows 10 Forums