Windows 10: BSOD Hal.dll with IRQL_NOT_LESS_OR_EQUAL and SYSTEM_SERVICE_EXCEPTION

Page 2 of 4 FirstFirst 1234 LastLast
  1.    08 Jul 2018 #11

    I've also now done steps #10-15. So I should be up to date with all of these steps 1-15 now.
      My ComputerSystem Spec


  2. Posts : 20,730
    windows 10 professional version 1607 build 14393.969 64 bit
       08 Jul 2018 #12

    If there are any BSOD then run the beta log collector and post a new zip into the thread.
    And look for c:\windows\memory.dmp > zip > post a one drive or drop box share link into the thread.
      My ComputerSystem Spec

  3.    08 Jul 2018 #13

    hi zbook,

    Based on your previous post I've done those 6 steps.
    Here are the 2 dmp files
    https://1drv.ms/u/s!AmTSH13ggSmRhjS8ViKwjDdFSlDc
    https://1drv.ms/u/s!AmTSH13ggSmRhjP_91aY3MSjIagv

    I could not find the memory.dmp file.

    I ran the disk check again and the issue did not come up again.

    Avast is uninstalled and defender is on.

    I should note that my computer was especially difficult on Friday morning. I was swapping RAM around, unplugging hard drives and couldn't get past a black screen. Eventually it started with 2 sticks in the 2 middle slots and only 2 hard drives. That is what my current setup is right now, though I was running the previous day with all 4 RAM sticks and 4 HDs in. I'll need to plug back in the HDs tomorrow so I'll see if that causes the issue again.

    Thanks for the speedy replies!
      My ComputerSystem Spec


  4. Posts : 20,730
    windows 10 professional version 1607 build 14393.969 64 bit
       08 Jul 2018 #14

    The links for the dump files were opened and they displayed ntstatus error codes.
    So that may be the reason for the log collector not being able to collect them.

    For the RAM, DIMM, and motherboard plan testing when you can run testing for 1 - 2 hours /GB RAM.
    Label each RAM module and label each DIMM.
    The RAM modules in the computer now are matched and are 8 GB each.
    Testing can be done 1 RAM module at a time in the same DIMM.
    Alternatively if pairs of RAM modules are tested the pairs can be tested in the paired DIMMs for 8 or more passes.
    Using this method all RAM modules are tested in the same DIMMs.
    Once RAM modules pass testing they can be moved to different DIMMs to test the DIMMs.
    The testing of 1 RAM module at a time will test the integrity of the RAM module whereas the testing of 2 RAM modules simultaneously can check the multichannel capability of the motherboard.
    The optimal test would be to check all RAM modules in all DIMM simultaneously for 8 or more passes.
    Again this is both a test condition and time issue.
    The opening post had 24 GB RAM. That may take 24 - 48 hours of continuous testing for just 8 passes.
    The more the passes the better the testing conditions.


    This is the typical testing for RAM / DIMM /MB with links:
    Run memtest86+ version 5.01 for at least 8 passes.
    Memtest86+ - Advanced Memory Diagnostic Tool
    This may take hours so plan to run it overnight.
    a) Please make sure you use the Memtest86+ version 5.01 with the link below.
    Memtest86+ - Advanced Memory Diagnostic Tool
    The testing is done not by time but by passes.
    The more passes the better.
    There are a significant number of false negatives if fewer than 8 passes are made.
    A false negative is a test pass when there is malfunctioning RAM.
    There is 24 GB of RAM on the computer.
    Memtest86+ version 5.01 testing takes approximately 1 - 2 hours /GB RAM
    Just 1 error is a fail and you can abort testing.
    Then test 1 RAM module at a time in the same DIMM each for 8 or more passes.
    b) When Memtest86+ version 5.01 has completed 8 or more passes use a camera or smart phone camera to take a picture and post an image into the thread.
    Memory problems. - Microsoft Community
    MemTest86+ - Test RAM | Windows 10 Tutorials
      My ComputerSystem Spec

  5.    13 Jul 2018 #15

    Well I went all week without a BSOD and then just got one 15minutes ago. It was a SYSTEM_SERVICE_EXCEPTION. I plugged in my MIDI Keyboard about 2hrs ago too so maybe that's related. Here is my beta log collector file and I found the Memory.dmp file too.
    I have not run the MemTest yet because I can't do it during the week. It was taking 16hrs just for one stick of 8GB ram. So I'll get it setup after work today and hopefully it'll be done come work Monday morning.

    https://1drv.ms/u/s!AmTSH13ggSmRhjUth8LI8AQ20tMp

    https://1drv.ms/u/s!AmTSH13ggSmRhjYYbUcMymLdectx
      My ComputerSystem Spec


  6. Posts : 20,730
    windows 10 professional version 1607 build 14393.969 64 bit
       13 Jul 2018 #16

    As above test the RAM / DIMM / MB with memtest86+ version 5.01 and post images of the test results for 8 or more passes into the thread.

    Next week plan to uninstall and reinstall some drivers pending the outcome of the memtest86+ version 5.01 results.

    Code:
    6/18/2018 6:35 PM	Windows Error Reporting	Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 10d
    P2: 8
    P3: 5a75f9367d78
    P4: 1
    P5: ffffa58a0032fe10
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\061818-25484-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-338578-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6847.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6857.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6895.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER68D4.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_10d_ef6b92aba09e3a45153224c1519a9bacb3d25b90_00000000_cab_01a168d3
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 371356b8-fc18-4ac7-8e0b-e7a0542cad5d
    Report Status: 4
    Hashed bucket: 
    Cab Guid: 07/13/2018 6:24 PM	Windows Error Reporting	Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 3b
    P2: c0000005
    P3: fffff8001dd859db
    P4: ffff890c62fb66c0
    P5: 0
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\071318-25265-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-346640-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER7A38.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER7A59.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER7A86.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER7AC6.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_3b_b54e603340fd3f2acbe45693d0c134f6e7a14fd_00000000_cab_03ad7ac5
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 7b14a9d0-7083-4e53-a43c-d20aec3c145f
    Report Status: 4
    Hashed bucket: 
    Cab Guid: 06/13/2018 12:44 PM	Windows Error Reporting	Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 3b
    P2: c0000005
    P3: fffff801644209db
    P4: ffff8607f5a04dc0
    P5: 0
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\061318-62578-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-528171-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER456E.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER457F.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER45EB.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER462B.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_3b_f957121419b38557f5281debd5b32c8a9adb7e6_00000000_cab_028c462a
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 5532127a-0b25-42ec-bce6-9162fee7ef39
    Report Status: 4
    Hashed bucket: 
    Cab Guid: 06/20/2018 9:08 PM	Windows Error Reporting	Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 3b
    P2: c0000005
    P3: fffff801ecb939db
    P4: fffff903972430c0
    P5: 0
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\062018-41734-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-180718-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERA90.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERAB0.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERB2C.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERB5C.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_3b_5aa48c2e71ee1a1cc45d54536573881a9585e66_00000000_cab_01ff0b5b
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 6eea3f51-65f5-45ab-bf3a-2c58ac35d690
    Report Status: 4
    Hashed bucket: 
    Cab Guid: 06/21/2018 11:15 AM	Windows Error Reporting	Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: a
    P2: 100000010329
    P3: 2
    P4: 0
    P5: fffff802f42339db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\062018-28515-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-29928250-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF41A.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF43A.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF458.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF498.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_cb8d9a74d2e9c6b63ec39c2ac31721fb76c42d4_00000000_cab_005cf4a6
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 9f786caf-d1d9-48df-bcaa-2609e644d455
    Report Status: 4
    Hashed bucket: 
    Cab Guid: 06/13/2018 1:01 PM	Windows Error Reporting	Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: a
    P2: 100000010329
    P3: 2
    P4: 0
    P5: fffff803f19969db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\061318-63593-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-275937-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6BB6.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6BC7.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6C43.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6C63.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_c9e53931835b4648fbeba82635e454ca0d5382f_00000000_cab_02906c72
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 84b04156-d8d6-4487-bd3c-ee92f181e867
    Report Status: 4
    Hashed bucket: 
    Cab Guid: 06/22/2018 2:48 PM	Windows Error Reporting	Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: a
    P2: 1000000de
    P3: 2
    P4: 0
    P5: fffff801936289db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\062218-32968-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-406328-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER765B.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER767B.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER76F7.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER7737.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_f7c2962dcd28592a98e358fadbba3d78784a2f_00000000_cab_03fa7746
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 811de7ef-7a14-447f-ad79-c3bc38edede6
    Report Status: 4
    Hashed bucket: 
    Cab Guid: 06/21/2018 7:22 PM	Windows Error Reporting	Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: a
    P2: 2d
    P3: 2
    P4: 0
    P5: fffff8002a0239db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\062118-35078-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-13143656-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERBBF0.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERBC10.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERBC8C.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERBCDB.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_5122bd7d885d6b7983ca171d8bcca5d4a1413f0_00000000_cab_033cbcda
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 160e4dc9-5529-4c3e-b0b4-f554b2dec11e
    Report Status: 4
    Hashed bucket: 
    Cab Guid: 06/12/2018 9:33 PM	Windows Error Reporting	Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: a
    P2: 2f
    P3: 2
    P4: 0
    P5: fffff803541979db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\061218-37562-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-393671-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER48E3.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER4903.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER497F.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER49AF.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_c631bd5c22cf5fdb3649d1625370faec13c6962a_00000000_cab_01e649bd
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 6b301d9f-51b9-4916-90a8-d5593ffbc27b
    Report Status: 4
    Hashed bucket: 
    Cab Guid: 05/17/2018 6:37 PM	Windows Error Reporting	Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: a
    P2: 327
    P3: 2
    P4: 0
    P5: fffff800d55899db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\051718-90312-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-670250-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8665.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8685.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER86E2.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8722.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_c028ceae1887f2b819468715c888117ab68b198c_00000000_cab_03ae8721
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 395183f2-ad39-4097-a907-12108e788940
    Report Status: 4
    Hashed bucket: 
    Cab Guid: 05/23/2018 4:00 PM	Windows Error Reporting	Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: a
    P2: c80000002c
    P3: 2
    P4: 0
    P5: fffff803926309db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\052318-29187-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-49156-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF2CC.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF2DC.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF31A.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF33A.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_a_c05c37bbd78b5ca1121ee28969579e384ed517_00000000_cab_03a4f349
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 4158b535-8cb8-4a64-94f3-d4a5414aa690
    Report Status: 4
    Hashed bucket: 
    Cab Guid: 0
    Code:
    6/18/2018 6:36 PM	Windows Error Reporting	Fault bucket 0x10D_8_1394ohci!IoWorkers::FlushWdfDmaTransaction, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 23d1ddaa-7f70-41f6-a972-99fb609d47d9
    
    Problem signature:
    P1: 10d
    P2: 8
    P3: 5a75f9367d78
    P4: 1
    P5: ffffa58a0032fe10
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\061818-25484-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-338578-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6847.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6857.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6895.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER68D4.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_10d_ef6b92aba09e3a45153224c1519a9bacb3d25b90_00000000_cab_24025324
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 371356b8-fc18-4ac7-8e0b-e7a0542cad5d
    Report Status: 268435456
    Hashed bucket: 
    Cab Guid: 07/13/2018 6:24 PM	Windows Error Reporting	Fault bucket 0x3B_hal!HalPutScatterGatherList, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: be5d9485-9001-45f8-85fa-7b6a1a011b80
    
    Problem signature:
    P1: 3b
    P2: c0000005
    P3: fffff8001dd859db
    P4: ffff890c62fb66c0
    P5: 0
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\071318-25265-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-346640-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER7A38.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER7A59.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER7A86.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER7AC6.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_3b_b54e603340fd3f2acbe45693d0c134f6e7a14fd_00000000_cab_26b9b28e
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 7b14a9d0-7083-4e53-a43c-d20aec3c145f
    Report Status: 268435456
    Hashed bucket: 
    Cab Guid: 06/20/2018 9:08 PM	Windows Error Reporting	Fault bucket 0x3B_hal!HalPutScatterGatherList, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: f97fa22c-816f-4e15-a34f-ae953af41c87
    
    Problem signature:
    P1: 3b
    P2: c0000005
    P3: fffff801ecb939db
    P4: fffff903972430c0
    P5: 0
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\062018-41734-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-180718-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERA90.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERAB0.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERB2C.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERB5C.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_3b_5aa48c2e71ee1a1cc45d54536573881a9585e66_00000000_cab_19d74883
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 6eea3f51-65f5-45ab-bf3a-2c58ac35d690
    Report Status: 268435456
    Hashed bucket: 
    Cab Guid: 06/13/2018 1:00 PM	Windows Error Reporting	Fault bucket 0x3B_hal!HalPutScatterGatherList, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: fb12000d-b546-49a0-b413-de71e1e7e5a5
    
    Problem signature:
    P1: 3b
    P2: c0000005
    P3: fffff801644209db
    P4: ffff8607f5a04dc0
    P5: 0
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\061318-62578-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-528171-0.sysdata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER456E.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER457F.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER45EB.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER462B.tmp.txt
    \\?\C:\Windows\Temp\WER4151.tmp.WERDataCollectionStatus.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_3b_f957121419b38557f5281debd5b32c8a9adb7e6_00000000_cab_0d8b4ba0
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 5532127a-0b25-42ec-bce6-9162fee7ef39
    Report Status: 268435456
    Hashed bucket: 
    Cab Guid: 0
    Code:
    5/17/2018 6:37 PM	Windows Error Reporting	Fault bucket AV_hal!HalPutScatterGatherList, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 2c06d78e-4423-4c86-aab6-5125fc87fcb3
    
    Problem signature:
    P1: a
    P2: 327
    P3: 2
    P4: 0
    P5: fffff800d55899db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\051718-90312-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-670250-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8665.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8685.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER86E2.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8722.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_a_c028ceae1887f2b819468715c888117ab68b198c_00000000_cab_1e6eb41c
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 395183f2-ad39-4097-a907-12108e788940
    Report Status: 268435456
    Hashed bucket: 
    Cab Guid: 05/23/2018 4:00 PM	Windows Error Reporting	Fault bucket AV_hal!HalPutScatterGatherList, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 44692f57-d41a-43c8-b4be-6d6d3b03ab2b
    
    Problem signature:
    P1: a
    P2: c80000002c
    P3: 2
    P4: 0
    P5: fffff803926309db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\052318-29187-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-49156-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF2CC.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF2DC.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF31A.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF33A.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_a_c05c37bbd78b5ca1121ee28969579e384ed517_00000000_cab_15e1299b
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 4158b535-8cb8-4a64-94f3-d4a5414aa690
    Report Status: 268435456
    Hashed bucket: 
    Cab Guid: 06/22/2018 2:48 PM	Windows Error Reporting	Fault bucket AV_hal!HalPutScatterGatherList, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 7a4db734-93c2-46ea-b47d-d365cf5b7d4c
    
    Problem signature:
    P1: a
    P2: 1000000de
    P3: 2
    P4: 0
    P5: fffff801936289db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\062218-32968-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-406328-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER765B.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER767B.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER76F7.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER7737.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_a_f7c2962dcd28592a98e358fadbba3d78784a2f_00000000_cab_29eed748
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 811de7ef-7a14-447f-ad79-c3bc38edede6
    Report Status: 268435456
    Hashed bucket: 
    Cab Guid: 06/13/2018 1:10 PM	Windows Error Reporting	Fault bucket AV_hal!HalPutScatterGatherList, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 94477620-39b9-45f4-95dd-4e62417cd844
    
    Problem signature:
    P1: a
    P2: 100000010329
    P3: 2
    P4: 0
    P5: fffff803f19969db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\061318-63593-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-275937-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6BB6.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6BC7.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6C43.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER6C63.tmp.txt
    \\?\C:\Windows\Temp\WERA4F8.tmp.WERDataCollectionStatus.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_a_c9e53931835b4648fbeba82635e454ca0d5382f_00000000_cab_0cf0dab5
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 84b04156-d8d6-4487-bd3c-ee92f181e867
    Report Status: 268435456
    Hashed bucket: 
    Cab Guid: 06/21/2018 7:22 PM	Windows Error Reporting	Fault bucket AV_hal!HalPutScatterGatherList, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: b6329e97-8e09-4e9d-81d7-ccc1ff999e8c
    
    Problem signature:
    P1: a
    P2: 2d
    P3: 2
    P4: 0
    P5: fffff8002a0239db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\062118-35078-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-13143656-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERBBF0.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERBC10.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERBC8C.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERBCDB.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_a_5122bd7d885d6b7983ca171d8bcca5d4a1413f0_00000000_cab_339cec47
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 160e4dc9-5529-4c3e-b0b4-f554b2dec11e
    Report Status: 268435456
    Hashed bucket: 
    Cab Guid: 06/12/2018 9:33 PM	Windows Error Reporting	Fault bucket AV_hal!HalPutScatterGatherList, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: b8eb5eef-4960-40df-abde-65ccdb635555
    
    Problem signature:
    P1: a
    P2: 2f
    P3: 2
    P4: 0
    P5: fffff803541979db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\061218-37562-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-393671-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER48E3.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER4903.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER497F.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER49AF.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_a_c631bd5c22cf5fdb3649d1625370faec13c6962a_00000000_cab_2e2e6cc6
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 6b301d9f-51b9-4916-90a8-d5593ffbc27b
    Report Status: 268435456
    Hashed bucket: 
    Cab Guid: 06/21/2018 11:15 AM	Windows Error Reporting	Fault bucket AV_hal!HalPutScatterGatherList, type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: e48ee6a9-c20c-4bff-970a-f84a0aaeec44
    
    Problem signature:
    P1: a
    P2: 100000010329
    P3: 2
    P4: 0
    P5: fffff802f42339db
    P6: 10_0_17134
    P7: 0_0
    P8: 768_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\WINDOWS\Minidump\062018-28515-01.dmp
    \\?\C:\WINDOWS\TEMP\WER-29928250-0.sysdata.xml
    \\?\C:\WINDOWS\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF41A.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF43A.tmp.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF458.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERF498.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_a_cb8d9a74d2e9c6b63ec39c2ac31721fb76c42d4_00000000_cab_04053058
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 9f786caf-d1d9-48df-bcaa-2609e644d455
    Report Status: 268435456
    Hashed bucket: 
    Cab Guid: 0
      My ComputerSystem Spec

  7. philc43's Avatar
    Posts : 3,590
    64bit Win 10 Pro ver 1809 Build 17763.1 and W10 Insider Build 18252
       13 Jul 2018 #17

    The most recent crash dump seems to pinpoint the fireface_64.sys driver as noted at the beginning of this thread. (RME Fireface UFX device)

    Code:
    BugCheck 3B, {c0000005, fffff8001dd859db, ffff890c62fb66c0, 0}
    
    *** WARNING: Unable to verify timestamp for fireface_64.sys
    *** ERROR: Module load completed but symbols could not be loaded for fireface_64.sys
    Probably caused by : 1394ohci.sys ( 1394ohci!IsochTx::Release+172 )

    Code:
    4: kd> lmvm fireface_64
    Browse full module list
    start             end                 module name
    fffff80b`75ef0000 fffff80b`75f12000   fireface_64 T (no symbols)           
        Loaded symbol image file: fireface_64.sys
        Image path: \SystemRoot\system32\drivers\fireface_64.sys
        Image name: fireface_64.sys
        Browse all global symbols  functions  data
        Timestamp:        Mon May  7 00:25:52 2018 (5AEFFF80)
        CheckSum:         000247F3
        ImageSize:        00022000
        Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
        Information from resource tables:
      My ComputersSystem Spec

  8.    14 Jul 2018 #18

    Ok I just did the 2 sticks I already had in there since I had a BSOD with these. 8 passes no errors. I'll leave these 2 in there for now and test my other 16GB of RAM later.

    It's interesting the Fireface driver is having issues. That particular company is known for having best-in-the-industry drivers. I also just updated the firmware and drivers for that device and switched from connecting it to my computer via Firewire to USB. I've had BSODs with it connected via Firewire and USB now.

    I remember a couple years ago I went in and made a regedit about one of the IRQL numbers. Don't remember the specifics. But I've reformatted this computer 3 or 4 times since then so I assume that would reset those. But thought I would mention that since I have had IRQL errors.

    Click image for larger version. 

Name:	20180714_145521.jpg 
Views:	0 
Size:	2.61 MB 
ID:	195771
    Attached Thumbnails Attached Thumbnails 20180714_145521.jpg  
    Last edited by ItsThatGuy; 14 Jul 2018 at 15:05. Reason: rotating picture
      My ComputerSystem Spec

  9. Ztruker's Avatar
    Posts : 6,389
    Windows 10 Pro X64 17134.191
       14 Jul 2018 #19

    Run your pic through an image editor and invert it.
      My ComputersSystem Spec


  10. Posts : 20,730
    windows 10 professional version 1607 build 14393.969 64 bit
       14 Jul 2018 #20

    After all of the RAM modules have been tested perform the following steps:

    1) Uninstall the Nvidia GPU driver using DDU (display driver uninstaller)
    2) Re-install the Nvidia GPU driver from the Nvidia website
    3) Make sure that you check the clean install box and if available install the physx driver.
    Display Driver Uninstaller Download version 17.0.8.2 (or a newer version if available)
    Display Driver Uninstaller: How to use - Windows 7 Help Forums
    NVIDIA
    Download Display Driver Uninstaller - MajorGeeks
    4) Uninstall and reinstall: fireface_64.sys


    Code:
    nvlddmkm.sys Sun Jun 24 10:38:02 2018 (5B2FBADA)
    Code:
    fireface_64.sys Mon May 07 02:25:52 2018 (5AEFFF80)

    Code:
    Name	NVIDIA GeForce GTX 970
    PNP Device ID	PCI\VEN_10DE&DEV_13C2&SUBSYS_29743842&REV_A1\4&DE2C59F&0&0010
    Adapter Type	GeForce GTX 970, NVIDIA compatible
    Adapter Description	NVIDIA GeForce GTX 970
    Adapter RAM	(1,048,576) bytes
    Installed Drivers	C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_485c1c3102021986\nvldumdx.dll,C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_485c1c3102021986\nvldumdx.dll,C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_485c1c3102021986\nvldumdx.dll,C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_485c1c3102021986\nvldumdx.dll
    Driver Version	24.21.13.9836
    INF File	oem39.inf (Section076 section)
    Color Planes	Not Available
    Color Table Entries	4294967296
    Resolution	1920 x 1080 x 60 hertz
    Bits/Pixel	32
    Memory Address	0xFD000000-0xFDFFFFFF
    Memory Address	0xC0000000-0xCFFFFFFF
    Memory Address	0xD0000000-0xD1FFFFFF
    I/O Port	0x0000E000-0x0000E07F
    IRQ Channel	IRQ 24
    I/O Port	0x000003B0-0x000003BB
    I/O Port	0x000003C0-0x000003DF
    Memory Address	0xA0000-0xBFFFF
    Driver	c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_485c1c3102021986\nvlddmkm.sys (24.21.13.9836, 16.40 MB (17,200,392 bytes), 7/6/2018 3:59 PM)
    Code:
    nvlddmkm	nvlddmkm	c:\windows\system32\driverstore\filerepository\nv_dispi.inf_amd64_485c1c3102021986\nvlddmkm.sys	Kernel Driver	Yes	Manual	Running	OK	Ignore	No	Yes
    Code:
    nvlddmkm     nvlddmkm               nvlddmkm               Kernel        Manual     Running    OK         TRUE        FALSE        7,446,528         7,270,400   0          6/24/2018 11:38:02 AM  C:\WINDOWS\system32\DriverStore\FileRepository\n 36,864
    Code:
    Name	RME Fireface UFX
    Manufacturer	RME
    Status	OK
    PNP Device ID	1394\RME!&FIREFACE_UFX\000A350215744623
    Driver	c:\windows\system32\drivers\fireface_64.sys (3.1.24.0, 131.93 KB (135,096 bytes), 7/8/2018 4:06 PM)
    Code:
    
    fireface64	RME Fireface Audio Device	c:\windows\system32\drivers\fireface_64.sys	Kernel Driver	Yes	Manual	Running	OK	Normal	No	Yes
    Code:
    fireface64   RME Fireface Audio Dev RME Fireface Audio Dev Kernel        Manual     Running    OK         TRUE        FALSE        0                 86,016      0          5/7/2018 3:25:52 AM    C:\WINDOWS\system32\drivers\fireface_64.sys      4,096
      My ComputerSystem Spec


 
Page 2 of 4 FirstFirst 1234 LastLast

Related Threads
So, I've been on windows 10 for at least 6 months now, I've had the occasional crash and BSOD but nothing like whats been happening recently. I was getting all kinds of System Service exceptions and I decided to reinstall windows 10 to see if that...
Hey, my computer has been doing this for a while now, but it will go for bursts with it working. However lately the blue screens have become a lot more common and has made the computer just unusable. Attached are my dmp files. 77126
Solved BSOD - SYSTEM_SERVICE_EXCEPTION (ks.sys) in BSOD Crashes and Debugging
Fresh install of Win10 Pro and it's crashing quickly. I am guessing it has to be a driver that came with the MB since I haven't had time to install anything else. But, I have no idea which one. I'd be grateful for someone to look at the bug...
SYSTEM_SERVICE_EXCEPTION and other BSOD in BSOD Crashes and Debugging
Dear all, I am trying to identify which drivers are causing these crashes. Could anyone give me hand or explain the method to identify the bug and understand which driver is missing? I have posted here the relevant files. Microsoft OneDrive -...
BSOD System_Service_Exception. Please Help! in BSOD Crashes and Debugging
Hi, I'm looking to get some help a BSOD that just popped up again today. First, a little background. Specs: Intel Core i7-4790, EVGA GeForce GTX 950, Cooler Master HAF 912 - System Build - PCPartPicker I built this machine about 3 weeks...
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd
All times are GMT -5. The time now is 05:52.
Find Us