The logs displayed several BSOD.
There was 1 mini dump.
The bugchecks were 1a and 12b
Bugcheck 12b typically indicates problems with hardware.
There is mismatched RAM.
The logs indicated possible problems with drive file system corruption and paging errors.
1) For all steps please post images into the thread.
2) For any problems posting images please use one drive or drop box share links.
3) Make sure that there is no over clocking during the troubleshooting process.
4) Open administrative command prompt and type or copy and paste:
5) sfc /scannow
6) dism /online /cleanup-image /restorehealth
7) When these have completed > right click on the top bar or title bar of the administrative command prompt box > left click on edit then select all > right click on the top bar again > left click on edit then copy > paste into the thread
8) chkdsk /x /f /r
This may take many hours so plan to run overnight.
C:\Windows\system32>chkdsk /x /f /r
The type of the file system is NTFS.
Cannot lock current drive.
Chkdsk cannot run because the volume is in use by another
process. Would you like to schedule this volume to be
checked the next time the system restarts? (Y/N)
Type: Y
reboot
9) Use the information in this link to find the chkdsk report in the event viewer. Copy and paste the report > notepad > save to the desktop > post the report into the thead:
Read Chkdsk Log in Event Viewer in Windows 10 Windows 10 Tutorials
10) Run HD Tune:
http://www.hdtune.com/
Post images into the thread for the results of each of these tabs:
a) Health: (SMART)
b) Benchmark
c) Full error scan
11) Run memtest86+ version 5.01 for at least 8 passes.
Memtest86+ - Advanced Memory Diagnostic Tool
This may take hours so plan to run it overnight.
a) Please make sure you use the Memtest86+ version 5.01 with the link below.
Memtest86+ - Advanced Memory Diagnostic Tool
The testing is done not by time but by passes.
The more passes the better.
There are a significant number of false negatives if fewer than 8 passes are made.
A false negative is a test pass when there is malfunctioning RAM.
There is 8 GB of RAM on the computer.
Memtest86+ version 5.01 testing takes approximately 1 - 2 hours /GB RAM
Just 1 error is a fail and you can abort testing.
Then test 1 RAM module at a time in the same DIMM each for 8 or more passes.
b) When Memtest86+ has completed 8 or more passes use a camera or smart phone camera to take a picture and post an image into the thread.
Memory problems. - Microsoft Community
MemTest86+ - Test RAM Windows 10 Tutorials
12) Uninstall Symantec/Norton AV:
Uninstall Symantec Endpoint Protection
Uninstall and Reinstall Norton product using the Norton Remove and Reinstall tool
13) Turn on windows defender
14) During the troubleshooting process please do not reinstall any AV products.
In 2 weeks the AV product can be reinstalled if there are no more BSOD.
The longer you can wait to reinstall the stronger the cause and effect for a new BSOD related to a re-installation.
If there is a recurrent BSOD then find an alternative AV product.
If there are no BSOD then continue using the AV product.
15) For any BSOD please post a new zip into the thread:
log collector v2-beta08.zip
16) In the left lower corner search type: system > open system control panel > on the left pane click advanced system settings > under startup and recovery click settings > under system failure > un-check automatically restart > also make sure that write debugging information is automatic memory dump > reboot
Code:
2/25/2018 1:44 AM Windows Error Reporting Fault bucket , type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 0
Problem signature:
P1: 12b
P2: ffffffffc00002c4
P3: 3ef
P4: 86320f0
P5: ffffe48187efe000
P6: 10_0_16299
P7: 0_0
P8: 768_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\022418-17421-01.dmp
\\?\C:\Windows\TEMP\WER-29906-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERDD12.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERDD13.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERDD62.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_12b_cee4435726b6b2458cca58a1e0f81ebbbb6cd190_00000000_cab_030cdd6f
Analysis symbol:
Rechecking for solution: 0
Report Id: f07d1137-0080-4b71-8e4b-1435898efa73
Report Status: 4
Hashed bucket:1/26/2018 3:25 PM Windows Error Reporting Fault bucket , type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 0
Problem signature:
P1: 1a
P2: 61941
P3: 15e80960178
P4: 9
P5: ffffa5054c2a7360
P6: 10_0_16299
P7: 0_0
P8: 768_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\012618-5734-01.dmp
\\?\C:\Windows\TEMP\WER-11125-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3A88.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AA7.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AB8.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_1a_1ce6729835bfa4a7b6dbf5eebb3cb4e6308191ec_00000000_cab_03343ab7
Analysis symbol:
Rechecking for solution: 0
Report Id: 3ad6b454-a9f7-463b-abea-05f3658edf4f
Report Status: 4
Hashed bucket:
1/26/2018 3:53 PM Windows Error Reporting Fault bucket , type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 0
Problem signature:
P1: 1a
P2: 61941
P3: 24c3b6c0090
P4: 9
P5: fffffc0bd24ca360
P6: 10_0_16299
P7: 0_0
P8: 768_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\012618-5515-01.dmp
\\?\C:\Windows\TEMP\WER-10484-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER37C9.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER37D8.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER37F9.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_1a_c7fbdeceb67053de3bc2c82d0276aaa4d964753_00000000_cab_033037f8
Analysis symbol:
Rechecking for solution: 0
Report Id: 8d5780bc-6aa5-4588-847a-4e398ec5a8db
Report Status: 4
Hashed bucket:
1/26/2018 3:26 PM Windows Error Reporting Fault bucket , type 0
Event Name: BlueScreen
Response: Not available
Cab Id: e6d32c82-cb53-4aca-8345-d6df55a40907
Problem signature:
P1: 1a
P2: 61941
P3: 15e80960178
P4: 9
P5: ffffa5054c2a7360
P6: 10_0_16299
P7: 0_0
P8: 768_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\012618-5734-01.dmp
\\?\C:\Windows\TEMP\WER-11125-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3A88.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AA7.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3AB8.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_1a_1ce6729835bfa4a7b6dbf5eebb3cb4e6308191ec_00000000_cab_03343ab7
Analysis symbol:
Rechecking for solution: 0
Report Id: 3ad6b454-a9f7-463b-abea-05f3658edf4f
Report Status: 4
Hashed bucket:
Code:
2/10/2018 7:36 PM Windows Error Reporting Fault bucket , type 0
Event Name: LiveKernelEvent
Response: Not available
Cab Id: 0
Problem signature:
P1: 144
P2: 3003
P3: ffffb08033148808
P4: 40010002
P5: 0
P6: 10_0_16299
P7: 0_0
P8: 768_1
P9:
P10:
Attached files:
\\?\C:\Windows\LiveKernelReports\USBHUB3\USBHUB3-20180210-1436.dmp
\\?\C:\Windows\TEMP\WER-169080890-0.sysdata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1373.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1373.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER13C2.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_144_9ad67fe1422904fefd2d9a9f2e3172854b7113_00000000_cab_39c81eae
Analysis symbol:
Rechecking for solution: 0
Report Id: 20c1d326-f16c-4c36-b3e7-568d52868e6c
Report Status: 2147491840
Hashed bucket:2/10/2018 7:36 PM Windows Error Reporting Fault bucket , type 0
Event Name: LiveKernelEvent
Response: Not available
Cab Id: 0
Problem signature:
P1: 144
P2: 3003
P3: ffffb08033148808
P4: 40010002
P5: 0
P6: 10_0_16299
P7: 0_0
P8: 768_1
P9:
P10:
Attached files:
\\?\C:\Windows\LiveKernelReports\USBHUB3\USBHUB3-20180210-1436.dmp
\\?\C:\Windows\TEMP\WER-169080890-0.sysdata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1373.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1373.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER13C2.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_144_9ad67fe1422904fefd2d9a9f2e3172854b7113_00000000_cab_3e9813d1
Analysis symbol:
Rechecking for solution: 0
Report Id: 20c1d326-f16c-4c36-b3e7-568d52868e6c
Report Status: 4
Hashed bucket:
Code:
1/26/2018 3:56 PM Windows Error Reporting Fault bucket 0x1a_61941_EraserUtilRebootDrv!unknown_function, type 0
Event Name: BlueScreen
Response: Not available
Cab Id: c7dd995c-487e-4a65-a52a-0e8eb043271a
Problem signature:
P1: 1a
P2: 61941
P3: 24c3b6c0090
P4: 9
P5: fffffc0bd24ca360
P6: 10_0_16299
P7: 0_0
P8: 768_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\012618-5515-01.dmp
\\?\C:\Windows\TEMP\WER-10484-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER37C9.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER37D8.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER37F9.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_1a_c7fbdeceb67053de3bc2c82d0276aaa4d964753_00000000_cab_179e745b
Analysis symbol:
Rechecking for solution: 0
Report Id: 8d5780bc-6aa5-4588-847a-4e398ec5a8db
Report Status: 268435456
Hashed bucket: