There was one mini and memory dump with bugcheck A.
Prior BSOD dumps had bugchecks:
A
6B
1) Open Ccleaner > click windows tab > scroll down to system and advanced > post an image into the thread
2) In the left lower corner search type: system or system control > open system control panel > on the left pane click advanced system settings
a) > on the advanced tab under startup and recovery > click settings > post an image of the startup and recovery into the thread.
b) > on the advanced tab under performance > click on settings > under performance options > click on the advanced tab > under virtual memory > click on change > post an image of the virtual memory tab into the thread
3) Open administrative command prompt and type or copy and paste:
4) sfc /scannow
5) dism /online /cleanup-image /restorehealth
6) chkdsk /scan
7) When these have completed > right click on the top bar or title bar of the administrative command prompt box > left click on edit then select all > right click on the top bar again > left click on edit then copy > paste into the thread
3) Run HD Tune: (free edition)
http://www.hdtune.com/
Post images of the test results for these tabs:
a) Health (SMART)
b) Benchmark
c) Full error scan
4) Open device manager > click view > show hidden devices > expand all rows > look for any row that displays an unknown device or an icon that is a yellow triangle with a black exclamation mark > post an image into the thread
5) For each BSOD run the beta log collector and post new zips into the thread
6) For each BSOD use file explorer to find c:\windows\memory.dmp > zip > post share links into the thread
7) Uninstall Malwarebytes:
Malwarebytes Cleanup Utility download and instr... | Official Malwarebytes Support
Uninstall Malwarebytes software from my Windows... | Official Malwarebytes Support
Malwarebytes Cleanup Utility FAQs | Official Malwarebytes Support
8) Uninstall Drop box > reinstall drop box
Code:
Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 ROOT\NET\0001 This device is disabled.
Code:
Event[4713]: Log Name: System
Source: Disk
Date: 2018-05-01T01:51:35.214
Event ID: 11
Task: N/A
Level: Error
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: DESKTOP-VFSHM7E
Description:
The driver detected a controller error on \Device\Harddisk2\DR2.
Code:
Event[4705]: Log Name: System
Source: Disk
Date: 2018-05-01T01:44:45.198
Event ID: 51
Task: N/A
Level: Warning
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: DESKTOP-VFSHM7E
Description:
An error was detected on device \Device\Harddisk1\DR4 during a paging operation.
Code:
Event[14027]:
Log Name: System
Source: Service Control Manager
Date: 2018-05-07T19:59:34.254
Event ID: 7000
Task: N/A
Level: Error
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: NIXWORKSTATION
Description:
The Malwarebytes Anti-Exploit service failed to start due to the following error:
Malwarebytes Anti-Exploit is not a valid Win32 application.
Code:
Event[9603]: Log Name: Application
Source: DbxSvc
Date: 2018-05-07T20:12:01.541
Event ID: 300
Task: N/A
Level: Error
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: NIXWORKSTATION
Description:
ReadEventLog failed: (1500) The event log file is corrupted.
Code:
Name Intel Chipset SATA RAID ControllerManufacturer Intel Corporation
Status OK
PNP Device ID PCI\VEN_8086&DEV_2822&SUBSYS_07A91028&REV_31\3&11583659&0&B8
Memory Address 0xED1C0000-0xED1C7FFF
Memory Address 0xED1D9000-0xED1D90FF
I/O Port 0x0000F090-0x0000F097
I/O Port 0x0000F080-0x0000F083
I/O Port 0x0000F060-0x0000F07F
Memory Address 0xED100000-0xED17FFFF
IRQ Channel IRQ 4294967294
IRQ Channel IRQ 4294967293
IRQ Channel IRQ 4294967292
IRQ Channel IRQ 4294967291
IRQ Channel IRQ 4294967290
IRQ Channel IRQ 4294967289
IRQ Channel IRQ 4294967288
IRQ Channel IRQ 4294967287
IRQ Channel IRQ 4294967286
Driver c:\windows\system32\drivers\iastoravc.sys (15.44.0.1010, 864.40 KB (885,144 bytes), 04/11/2018 07:33 PM)
Code:
iastoravc Intel Chipset SATA RAID Controller c:\windows\system32\drivers\iastoravc.sys Kernel Driver Yes Boot Running OK Normal No Yes
Code:
05/06/2018 11:01 PM Windows Error Reporting Fault bucket , type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 0
Problem signature:
P1: 6b
P2: ffffffffc000000d
P3: 3
P4: 0
P5: 0
P6: 10_0_17134
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\050618-10625-01.dmp
\\?\C:\Windows\TEMP\WER-27890-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8174.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8185.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8193.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER81C3.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_6b_7c6bd5891255ea14e1d17f858e14278d7513_00000000_cab_038881c2
Analysis symbol:
Rechecking for solution: 0
Report Id: d9c569f6-d3de-494e-903c-5b0800b94f17
Report Status: 4
Hashed bucket:
Cab Guid: 005/06/2018 10:10 PM Windows Error Reporting Fault bucket , type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 0
Problem signature:
P1: a
P2: ffff97cbc0000000
P3: 2
P4: 0
P5: fffff8002ec4d700
P6: 10_0_17134
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\050618-14531-01.dmp
\\?\C:\Windows\TEMP\WER-37015-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERA8E2.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERA902.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERA911.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERA931.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_f1ad3d49c85326f4f96d43d49fd296f72bd0c4_00000000_cab_0398a930
Analysis symbol:
Rechecking for solution: 0
Report Id: e568f28a-d04d-4736-86bd-d04fc1b71268
Report Status: 4
Hashed bucket:
Cab Guid: 0
05/06/2018 08:45 AM Windows Error Reporting Fault bucket , type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 0
Problem signature:
P1: a
P2: ffffdc6e00000000
P3: 2
P4: 0
P5: fffff8026c4d3700
P6: 10_0_17134
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\050618-10296-01.dmp
\\?\C:\Windows\TEMP\WER-18062-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5747.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5758.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5767.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5777.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_3129bf2e09f47c76a2c4e8fd3d4f9a2ea48dc_00000000_cab_03685786
Analysis symbol:
Rechecking for solution: 0
Report Id: 1cae06b1-8e33-4136-a4d7-afdcabbf28bd
Report Status: 4
Hashed bucket:
Cab Guid: 0
05/06/2018 08:46 AM Windows Error Reporting Fault bucket , type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 0
Problem signature:
P1: a
P2: ffffdc6e00000000
P3: 2
P4: 0
P5: fffff8026c4d3700
P6: 10_0_17134
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\050618-10296-01.dmp
\\?\C:\Windows\TEMP\WER-18062-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5747.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5758.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5767.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5777.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_3129bf2e09f47c76a2c4e8fd3d4f9a2ea48dc_00000000_cab_03685786
Analysis symbol:
Rechecking for solution: 0
Report Id: 1cae06b1-8e33-4136-a4d7-afdcabbf28bd
Report Status: 6
Hashed bucket:
Cab Guid: 0
05/07/2018 11:58 PM Windows Error Reporting Fault bucket , type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 0
Problem signature:
P1: a
P2: ffffe20000000000
P3: 2
P4: 0
P5: fffff801a66ec700
P6: 10_0_17134
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\050718-14687-01.dmp
\\?\C:\Windows\TEMP\WER-25375-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER77B0.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER77C1.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER77CF.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER77E0.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_13aa19c95ce75923546f1921ccb338c8ce44740_00000000_cab_039877ef
Analysis symbol:
Rechecking for solution: 0
Report Id: fe8365c4-766a-45ee-8872-4165316c6c11
Report Status: 4
Hashed bucket:
Cab Guid: 0
05/05/2018 04:30 AM Windows Error Reporting Fault bucket , type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 0
Problem signature:
P1: a
P2: ffffe3f1c0000000
P3: 2
P4: 0
P5: fffff801eeeeb700
P6: 10_0_17134
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\050518-10281-01.dmp
\\?\C:\Windows\TEMP\WER-18250-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER57E4.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER57F4.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5803.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5813.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_41c184b233bf293721716d236394dba1a7b39d_00000000_cab_03605812
Analysis symbol:
Rechecking for solution: 0
Report Id: b85ecbca-0706-4a71-85ee-d328532e98e6
Report Status: 4
Hashed bucket:
Cab Guid: 0
05/04/2018 10:30 PM Windows Error Reporting Fault bucket , type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 0
Problem signature:
P1: a
P2: fffffa0000000000
P3: 2
P4: 0
P5: fffff8029c043700
P6: 10_0_17134
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\050418-11500-01.dmp
\\?\C:\Windows\TEMP\WER-20968-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6EF6.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6F06.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6F15.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6F74.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_8fe884db6a2d72246380e2d81161d9dae799f24_00000000_cab_03886f73
Analysis symbol:
Rechecking for solution: 0
Report Id: 75f75d69-93a5-4599-bcda-472b1e7b45c0
Report Status: 4
Hashed bucket:
Cab Guid: 0
Code:
05/06/2018 11:01 PM Windows Error Reporting Fault bucket 0x6B_nt!IoInitSystemPreDrivers, type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 5e53d8d6-1d42-4a86-a1aa-d34417e3f4f3
Problem signature:
P1: 6b
P2: ffffffffc000000d
P3: 3
P4: 0
P5: 0
P6: 10_0_17134
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\050618-10625-01.dmp
\\?\C:\Windows\TEMP\WER-27890-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8174.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8185.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8193.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER81C3.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_6b_7c6bd5891255ea14e1d17f858e14278d7513_00000000_cab_35ac947f
Analysis symbol:
Rechecking for solution: 0
Report Id: d9c569f6-d3de-494e-903c-5b0800b94f17
Report Status: 268435456
Hashed bucket:
Cab Guid: 0
Code:
05/05/2018 04:30 AM Windows Error Reporting Fault bucket AV_nt!MmFreeContiguousMemory, type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 2c079a0a-72cb-4235-a95e-ef14f2244654
Problem signature:
P1: a
P2: ffffe3f1c0000000
P3: 2
P4: 0
P5: fffff801eeeeb700
P6: 10_0_17134
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\050518-10281-01.dmp
\\?\C:\Windows\TEMP\WER-18250-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER57E4.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER57F4.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5803.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5813.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_a_41c184b233bf293721716d236394dba1a7b39d_00000000_cab_23b88e55
Analysis symbol:
Rechecking for solution: 0
Report Id: b85ecbca-0706-4a71-85ee-d328532e98e6
Report Status: 268435456
Hashed bucket:
Cab Guid: 005/07/2018 11:58 PM Windows Error Reporting Fault bucket AV_nt!MmFreeContiguousMemory, type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 6821be1d-6b36-4d2b-bbed-407e31182caa
Problem signature:
P1: a
P2: ffffe20000000000
P3: 2
P4: 0
P5: fffff801a66ec700
P6: 10_0_17134
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\050718-14687-01.dmp
\\?\C:\Windows\TEMP\WER-25375-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER77B0.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER77C1.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER77CF.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER77E0.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_a_13aa19c95ce75923546f1921ccb338c8ce44740_00000000_cab_27689971
Analysis symbol:
Rechecking for solution: 0
Report Id: fe8365c4-766a-45ee-8872-4165316c6c11
Report Status: 268435456
Hashed bucket:
Cab Guid: 0
05/06/2018 10:10 PM Windows Error Reporting Fault bucket AV_nt!MmFreeContiguousMemory, type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 80122cba-bd85-47d8-add1-8869b4c91b73
Problem signature:
P1: a
P2: ffff97cbc0000000
P3: 2
P4: 0
P5: fffff8002ec4d700
P6: 10_0_17134
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\050618-14531-01.dmp
\\?\C:\Windows\TEMP\WER-37015-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERA8E2.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERA902.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERA911.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERA931.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_a_f1ad3d49c85326f4f96d43d49fd296f72bd0c4_00000000_cab_3b34db3d
Analysis symbol:
Rechecking for solution: 0
Report Id: e568f28a-d04d-4736-86bd-d04fc1b71268
Report Status: 268435456
Hashed bucket:
Cab Guid: 0
05/04/2018 10:30 PM Windows Error Reporting Fault bucket AV_nt!MmFreeContiguousMemory, type 0
Event Name: BlueScreen
Response: Not available
Cab Id: dbbcf43d-4a4e-4433-89cb-9e94ead74512
Problem signature:
P1: a
P2: fffffa0000000000
P3: 2
P4: 0
P5: fffff8029c043700
P6: 10_0_17134
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\050418-11500-01.dmp
\\?\C:\Windows\TEMP\WER-20968-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6EF6.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6F06.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6F15.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6F74.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_a_8fe884db6a2d72246380e2d81161d9dae799f24_00000000_cab_25a099de
Analysis symbol:
Rechecking for solution: 0
Report Id: 75f75d69-93a5-4599-bcda-472b1e7b45c0
Report Status: 268435456
Hashed bucket:
Cab Guid: 0
05/06/2018 08:54 AM Windows Error Reporting Fault bucket AV_nt!MmFreeContiguousMemory, type 0
Event Name: BlueScreen
Response: Not available
Cab Id: f0ec9885-5fac-42d8-8281-d141b79491bd
Problem signature:
P1: a
P2: ffffdc6e00000000
P3: 2
P4: 0
P5: fffff8026c4d3700
P6: 10_0_17134
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\050618-10296-01.dmp
\\?\C:\Windows\TEMP\WER-18062-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5747.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5758.tmp.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5767.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5777.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_a_3129bf2e09f47c76a2c4e8fd3d4f9a2ea48dc_00000000_cab_1aac3afe
Analysis symbol:
Rechecking for solution: 0
Report Id: 1cae06b1-8e33-4136-a4d7-afdcabbf28bd
Report Status: 268435462
Hashed bucket:
Cab Guid: 0