Page 2 of 6 FirstFirst 1234 ... LastLast
  1.    05 Aug 2017 #11
    Join Date : Jul 2017
    Posts : 26
    Windows 10 Pro x64
    Thread Starter

    Quote Originally Posted by zbook View Post
    See if you can run windows driver verifier for 36 hours without a bsod.
    Thanks. The BSOD has happened again. So, although I've cleaned up the Folder Lock mess, it has not solved it.

    I did uninstall Malwarebytes, so I don't understand the messages - it is still uninstalled now - I can't find either of the two .sys files you mention. I have done a full search for them, and checked in "Services" to see if they were startup enabled/disabled, but they do not exist.

    I will run the Windows Driver Verifier as you suggest.
    Last edited by Griffinit; 05 Aug 2017 at 15:52. Reason: adding information
      My ComputerSystem Spec
  2.    05 Aug 2017 #12
    Join Date : Apr 2017
    Posts : 8,761
    windows 10 professional version 1607 build 14393.969 64 bit

    Please post the bsod mini dump as they occur for debugging:
    BSOD - Posting Instructions - Windows 10 Forums
      My ComputerSystem Spec
  3.    07 Aug 2017 #13
    Join Date : Jul 2017
    Posts : 26
    Windows 10 Pro x64
    Thread Starter

    Quote Originally Posted by zbook View Post
    Please post the bsod mini dump as they occur for debugging:
    BSOD - Posting Instructions - Windows 10 Forums
    I have contacted Malwarebytes as it has not uninstalled completely despite using their clean up uninstall - given they have a cleanup utility, they are obviously aware of some errors in uninstall - the registry has Malwarebytes scattered all over the place and I have sent them copies of all the Malwarebyte entries.

    Here is the latest BSOD from Hibernate wake up.

    HP-HENRY-07_08_2017_170915_28.zip
      My ComputerSystem Spec
  4.    07 Aug 2017 #14
    Join Date : Apr 2017
    Posts : 8,761
    windows 10 professional version 1607 build 14393.969 64 bit

    There were 3 bsod mini dump files debugged and there was 1 misbehaving driver identified.
    It was a repeat misbehaving driver: MBAMChameleon.sys

    1) open administrative command prompt and type or copy and paste:
    2) sfc /scannow
    3) dism /online /cleanup-image /restorehealth
    4) chkdsk /scan
    When these have completed > right click on the top bar or title bar of the administrative command prompt box > left click on edit then select all > right click on the top bar again > left click on edit then copy > paste into the thread


    4) msconfig (in the pop up system configuration > move the dot from normal startup to selective startup > uncheck load startup items > click service tab > in left lower corner check hide all Microsoft services > in the lower right side click disable all > click apply or ok > do not reboot)


    5) taskmgr (in the pop up task manager > click on the start up tab > click on status so that the column sorts with enable rising to the top > right click on each row with enable and change to disable)


    https://support.microsoft.com/en-us/...oot-in-windows


    How to perform a Clean Boot in Windows 10 - TechNet Articles - United States (English) - TechNet Wiki

    6) shutdown /r (you will reboot the computer so that it is in clean boot)


    These next steps are an attempt to remove Malwarebytes. The drivers list is not displaying the misbehaving driver,
    Please use everything search to confirm that it is still present and the report what you see in the post with an image of the results.

    voidtools

    Search for each:
    malware
    mbam

    7) uninstall Kaspersky software
    8) use the Kaspersky uninstall tool: Removal tool for Kaspersky Lab products (kavremover)
    9) turn on windows defender
    10) install Malwarebytes
    11) uninstall Malwarebytes
    12) recheck everything search for each
    malware
    mbam
    13) report the results into the thread with images.








    Code:
    ffffc380`15394048  fffff803`be422a1fUnable to load image \SystemRoot\system32\drivers\MBAMChameleon.sys, Win32 error 0n2*** WARNING: Unable to verify timestamp for MBAMChameleon.sys*** ERROR: Module load completed but symbols could not be loaded for MBAMChameleon.sys MBAMChameleon+0x2a1f
    mbamchameleon.sys Malwarebytes Chameleon Protection Driver https://www.malwarebytes.org/chameleon/ If using this
      My ComputerSystem Spec
  5.    07 Aug 2017 #15
    Join Date : Jul 2017
    Posts : 26
    Windows 10 Pro x64
    Thread Starter

    I have not yet heard from Malwarebytes. However, this is the information I sent them.

    2017-08-06 00:14:40.673 mb-clean:3.1.0.1014 @ Malwarebytes. All rights reserved.
    2017-08-06 00:14:44.415 Find Malwarebytes 3 installation location from C:\Program Files\Malwarebytes\Anti-Malware\.
    2017-08-06 00:14:45.945 Malwarebytes self-protection module is not installed.
    2017-08-06 00:14:45.957 Launching process:C:\Program Files\Malwarebytes\Anti-Malware\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /log="C:\Users\pamelap\AppData\Local\Temp\Mbam3x.log"
    2017-08-06 00:14:45.958 Failed to launch C:\Program Files\Malwarebytes\Anti-Malware\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /log="C:\Users\pamelap\AppData\Local\Temp\Mbam3x.log", reasonThe system cannot find the file specified.(error=2))
    2017-08-06 00:14:45.959 >>>>>> Starting 2nd phase cleanup for Malwarebytes version 3.0.5.1299 <<<<<<
    2017-08-06 00:14:45.960 HKLM\SYSTEM\CurrentControlSet\Services\ESProtectionDriver does not exist.
    2017-08-06 00:14:45.961 HKLM\SYSTEM\CurrentControlSet\Services\MBAMChameleon does not exist.
    2017-08-06 00:14:45.961 HKLM\SYSTEM\CurrentControlSet\Services\MBAMFarflt does not exist.
    2017-08-06 00:14:45.962 HKLM\SYSTEM\CurrentControlSet\Services\MBAMProtection does not exist.
    2017-08-06 00:14:45.962 HKLM\SYSTEM\CurrentControlSet\Services\MBAMService does not exist.
    2017-08-06 00:14:45.963 HKLM\SYSTEM\CurrentControlSet\Services\MBAMSwissArmy does not exist.
    2017-08-06 00:14:45.963 HKLM\SYSTEM\CurrentControlSet\Services\MBAMWebProtection does not exist.
    2017-08-06 00:14:49.266 Trying to delete path C:\ProgramData\Malwarebytes\
    2017-08-06 00:14:49.267 Cannot delete path C:\ProgramData\Malwarebytes\, reasonThe system cannot find the path specified.(error=3))
    2017-08-06 00:14:49.269 Trying to delete path C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\
    2017-08-06 00:14:49.270 Cannot delete path C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\, reasonThe system cannot find the path specified.(error=3))
    2017-08-06 00:14:49.270 Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\
    2017-08-06 00:14:49.271 Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    2017-08-06 00:14:49.273 Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll
    2017-08-06 00:14:49.274 Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll, reasonAccess is denied.(error=5))
    2017-08-06 00:14:49.274 Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll on reboot
    2017-08-06 00:14:49.275 Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\msvcp120.dll
    2017-08-06 00:14:49.276 Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\msvcr120.dll
    2017-08-06 00:14:49.277 Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\platforms\
    2017-08-06 00:14:49.278 Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\platforms\qwindows.dll
    2017-08-06 00:14:49.279 Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\platforms\
    2017-08-06 00:14:49.280 Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
    2017-08-06 00:14:49.282 Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Gui.dll
    2017-08-06 00:14:49.284 Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Network.dll
    2017-08-06 00:14:49.285 Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Qml.dll
    2017-08-06 00:14:49.287 Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Quick.dll
    2017-08-06 00:14:49.289 Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Widgets.dll
    2017-08-06 00:14:49.291 Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\
    2017-08-06 00:14:49.292 Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\, reasonThe directory is not empty.(error=145))
    2017-08-06 00:14:49.292 Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\ on reboot
    2017-08-06 02:09:41.423 --------END OF LOG FILE ----------
    2017-08-06 02:10:50.560 >>>>>Starting post reboot phase cleanup for Malwarebytes version 3.0.5.1299 <<<<<<<<.
    2017-08-06 02:10:50.825 HKLM\SYSTEM\CurrentControlSet\Services\ESProtectionDriver does not exist.
    2017-08-06 02:10:50.825 HKLM\SYSTEM\CurrentControlSet\Services\MBAMChameleon does not exist.
    2017-08-06 02:10:50.825 HKLM\SYSTEM\CurrentControlSet\Services\MBAMFarflt does not exist.
    2017-08-06 02:10:50.857 HKLM\SYSTEM\CurrentControlSet\Services\MBAMProtection does not exist.
    2017-08-06 02:10:50.857 HKLM\SYSTEM\CurrentControlSet\Services\MBAMService does not exist.
    2017-08-06 02:10:50.888 HKLM\SYSTEM\CurrentControlSet\Services\MBAMSwissArmy does not exist.
    2017-08-06 02:10:50.888 HKLM\SYSTEM\CurrentControlSet\Services\MBAMWebProtection does not exist.
    2017-08-06 02:10:54.091 Trying to delete path C:\ProgramData\Malwarebytes\
    2017-08-06 02:10:54.122 Cannot delete path C:\ProgramData\Malwarebytes\, reasonThe system cannot find the path specified.(error=3))
    2017-08-06 02:10:54.122 Trying to delete path C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\
    2017-08-06 02:10:54.154 Cannot delete path C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\, reasonThe system cannot find the path specified.(error=3))
    2017-08-06 02:10:54.154 Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\
    2017-08-06 02:10:54.154 Cannot delete path C:\Program Files\Malwarebytes\Anti-Malware\, reasonThe system cannot find the path specified.(error=3))
    2017-08-06 02:13:05.218 !!!!!!Failed to open Postreboot file C:\Users\pamelap\AppData\Local\Temp\postreboot.txt
    2017-08-06 02:19:41.115 --------END OF LOG FILE ----------

    REGISTRY ITEMS FOR MALWAREBYTES STILL SHOWING
    =================================================
    Computer\HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe.ApplicationCompany REG_SZ Malwarebytes
    Computer\HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe.FriendlyAppName REG_SZ Malwarebytes

    Computer\HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe.ApplicationCompany REG_SZ Malwarebytes
    Computer\HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe.FriendlyAppName REG_SZ Malwarebytes

    Computer\HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5c2e6c83_0 (default) REG_SZ {2.}\\?\hdaudio#func_01..............HarddiskVolume4\Program Files\Malwarebytes\Anti-M..............
    Computer\HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\d6b30b3e_0 (default) REG_SZ {2.}\\?\hdaudio#func_01..............HarddiskVolume4\Program Files(86)\Malwarebytes\Anti-M..............

    Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit Lastkey REG_SZ Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\mbamser vice.exe

    Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\UFH\SHC 109 REG_MULTI_SZ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Malwarebytes.lnk C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe REG_BINARY .............
    Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\UFH\SHC 72 REG_MULTI_SZ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Malwarebytes.lnk C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe REG_BINARY ............

    Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe REG_BINARY ..........
    Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store C:\Program Files (x86)\Malwarebytes Anti-Malware\mbampt.exe REG_BINARY ..........


    Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store C:\Program Files\Malwarebytes Anti-Malware\assistant.exe REG_BINARY ..........
    Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store C:\Program Files\Malwarebytes Anti-Malware\malwarebytes_assistant.exe REG_BINARY ..........

    Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store C:\Program Files\Malwarebytes Anti-Malware\mbam.exe REG_BINARY ..........
    Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store C:\Program Files\Malwarebytes Anti-Malware\unins000.exe REG_BINARY ..........

    Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store C:\ProgramData\Malwarebytes\MBAMService\instlrupdate\mb3-setup-consumer-3.1.2.1733-1.0.160-1.0.2251.exe

    Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\mbamser vice.exe

    Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION mbam.exe REG_DWORD ....

    Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WARN_ON_SEC_CERT_REV_FAILED mbam.exe REG_DWORD ....

    Computer\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\System\mbamchameleon EventMessageFile REG_SZ C:\Windows\system32\drivers\mbamchameleon.sys

    Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\mbamchameleon EventMessageFile REG_SZ C:\Windows\system32\drivers\mbamchameleon.sys

    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe.ApplicationCompany REG_SZ Malwarebytes
    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe.FriendlyAppName REG_SZ Malwarebytes

    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5c2e6c83_0 (default) REG_SZ {2}.\\?\hdaudio#func_01&ven_10ec&dev_0280&subsys_103c221b&rev_1000#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\singlelineouttopo/00010001|\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbam.exe%b{00000000-0000-0000-0000-000000000000}
    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\d6b30b3e_0 (default) REG_SZ {2}.\\?\hdaudio#func_01&ven_10ec&dev_0280&subsys_103c221b&rev_1000#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\singlelineouttopo/00010001|\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbam.exe%b{00000000-0000-0000-0000-000000000000}

    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit LastKey REG_SZ Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\mbamser vice.exe

    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002\Software\Microsoft\Windows\CurrentVersion\UFH\SHC 109 REG_MULTI_SZ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Malwarebytes.lnk C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe REG_BINARY .............
    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002\Software\Microsoft\Windows\CurrentVersion\UFH\SHC 72 REG_MULTI_SZ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Malwarebytes.lnk C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe REG_BINARY ............

    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store C:\Program Files(86)\Malwarebytes Anti-Malware\mbam.exe REG_BINARY ..........
    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store C:\Program Files(86)\Malwarebytes Anti-Malware\mbampt.exe REG_BINARY ..........

    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store C:\Program Files\Malwarebytes Anti-Malware\mbam.exe REG_BINARY ..........
    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store C:\Program Files\Malwarebytes Anti-Malware\mbampt.exe REG_BINARY ..........
    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store C:\ProgramData\Malwarebytes\MBAMService\instlrupdate\mb3-setup-consumer-3.1.2.1733-1.0.160-1.0.2251.exe REG_BINARY ............

    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe.ApplicationCompany REG_SZ Malwarebytes
    Computer\HKEY_USERS\S-1-5-21-339604962-2008541192-2779379361-1002_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe.FriendlyAppName REG_SZ Malwarebytes


    CODE showing faults
    _______________________



    ffffe181`4338d0a8 fffff801`b970fbd0Unable to load image \??\C:\WINDOWS\system32\drivers\farflt.sys, Win32 error 0n2*** WARNING: Unable to verify timestamp for farflt.sys*** ERROR: Module load completed but symbols could not be loaded for farflt.sys farflt+0xfbd0

    ffffe181`4338d048 fffff80b`c8922a1fUnable to load image \SystemRoot\system32\drivers\MBAMChameleon.sys, Win32 error 0n2*** WARNING: Unable to verify timestamp for MBAMChameleon.sys*** ERROR: Module load completed but symbols could not be loaded for MBAMChameleon.sys MBAMChameleon+0x2a1f

    Event[797]: Log Name: System Source: Service Control Manager Date: 2017-07-18T15:06:23.140 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: HP-Henry Description: A service was installed in the system.Service Name: MBAMChameleonService File Name: C:\WINDOWS\system32\drivers\MBAMChameleon.sysService Type: kernel mode driverService Start Type: boot startService Account:

    ____________________________________________________________________________________________________ ____________________________________________________________________________________________________ ____________________________________________________________________________________________________ ____________________________________________________________________________________________________ ________________________________________________________________________________


    MBAMchameleon.sys does not exist in drivers directory (presume uninstalled) although there are entries for it in the registry.

    I will redo steps 1-4 of your post, although I have done them before.

    I'd rather wait to hear from Malwarebytes as they may have the answer; the msconfig change you specify tends to be hard afterwards to get back to the original so it's last resort for me.
      My ComputerSystem Spec
  6.    08 Aug 2017 #16
    Join Date : Apr 2017
    Posts : 8,761
    windows 10 professional version 1607 build 14393.969 64 bit

    In case it is needed see this video: 3 Ways to Uninstall Malwarebytes' Anti Malware - wikiHow
      My ComputerSystem Spec
  7.    08 Aug 2017 #17
    Join Date : Jul 2017
    Posts : 33
    Windows 10 x64 - Windows 7 SP1 x86

    Could you please provide a Kernel Memory Dump if possible? The directory path is the following:

    Code:
    %systemroot%\MEMORY.DMP
    The file will need to be zipped and then uploaded to a file sharing site such as Dropbox or OneDrive.
      My ComputerSystem Spec
  8.    09 Aug 2017 #18
    Join Date : Jul 2017
    Posts : 26
    Windows 10 Pro x64
    Thread Starter

    Quote Originally Posted by zbook View Post
    I have deleted all traces of Malwarebytes from the registry as per last item on your link, and done a full shutdown and then started the machine up again. It started fine no problems. I then did Hybernate and on waking up from that got the usual error. I attach the .zip file.

    Abaculus, there is no file called MEMORY.DMP. - I think you will find the .dmp files are in the attached .zip file. If not, I don't know where it is.

    Attachment 147995
      My ComputerSystem Spec
  9.    09 Aug 2017 #19
    Join Date : Apr 2017
    Posts : 8,761
    windows 10 professional version 1607 build 14393.969 64 bit

    There was 1 new mini dump and there was no definitive misbehaving driver.

    Intel wireless was identified as a faulting application and a problem signature.

    1) Please temporarily connect the computer via a wired or ethernet cat5e cable or download the replacement driver to the desktop using wifi. Use the HP website with the computer's serial or product number and operating to find the latest wifi drivers.
    If there is a mechanical button please turn off wireless before installing the replacement driver.
    2) Uninstall and reinstall any wireless driver offered on the HP website for your computer's configuration.
    3) report into the thread which driver(s) were updated.
    4) Open administrative command prompt and type: powercfg.exe /hibernate off
    5) The event log has entries: The TPM is defending against dictionary attacks and is in a time-out period.
    View this link for a possible fix: How do I fix ?
    6) Tomorrow once all of the above have been completed plan to restart windows driver verifier. If there are any new bsod post a new zip: BSOD - Posting Instructions - Windows 10 Forums



    Code:
    NETwNb64     Intel(R) Wireless Adap Intel(R) Wireless Adap Kernel        Manual     Running    OK         TRUE        FALSE        741,376           2,134,016   0          05/04/2017 18:04:27    C:\WINDOWS\system32\drivers\Netwbw02.sys         4,096
    Code:
    Name    [00000003] Intel(R) Dual Band Wireless-N 7260Adapter Type    Ethernet 802.3Product Type    Intel(R) Dual Band Wireless-N 7260Installed    YesPNP Device ID    PCI\VEN_8086&DEV_08B1&SUBSYS_C0608086&REV_6B\A4C494FFFF0DFA6B00Last Reset    09/08/2017 16:20Index    3Service Name    NETwNb64IP Address    192.168.1.75, fe80::d545:fae8:32f5:c196IP Subnet    255.255.255.0, 64Default IP Gateway    192.168.1.254DHCP Enabled    YesDHCP Server    192.168.1.254DHCP Lease Expires    10/08/2017 16:21DHCP Lease Obtained    09/08/2017 16:21MAC Address    ‪A4:C4:94:0D:FA:6B‬Memory Address    0xC05FE000-0xC05FFFFFIRQ Channel    IRQ 4294967285Driver    c:\windows\system32\drivers\netwbw02.sys (18.33.7.2, 3.36 MB (3,526,392 bytes), 20/10/2016 04:26)
    Code:
    BugCheck A, {0, 2, 0, fffff8004e6edbf8}*** WARNING: Unable to verify timestamp for win32k.sys*** ERROR: Module load completed but symbols could not be loaded for win32k.sysProbably caused by : memory_corruption
    Code:
    21/07/2017 20:45    Application Error    Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Exception code: 0xc0000409
    Fault offset: 0x000000000022af80
    Faulting process ID: 0x1048
    Faulting application start time: 0x01d3026210fb7555
    Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Report ID: f8be37c5-ca9e-4c16-ab1c-1ad18c2d34b5
    Faulting package full name: 
    Faulting package-relative application ID:21/07/2017 20:39    Application Error    Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Exception code: 0xc0000409
    Fault offset: 0x000000000022af80
    Faulting process ID: 0x106c
    Faulting application start time: 0x01d302601e8d2730
    Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Report ID: 0da462a1-5562-4505-a4f3-2cf4c5ba6db0
    Faulting package full name: 
    Faulting package-relative application ID:09/08/2017 15:16    Application Error    Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Exception code: 0xc0000409
    Fault offset: 0x000000000022af80
    Faulting process ID: 0x113c
    Faulting application start time: 0x01d30ebf6f8f8f1d
    Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Report ID: 245f1da3-4890-4620-93a4-9c36641bfa17
    Faulting package full name: 
    Faulting package-relative application ID:04/08/2017 17:10    Application Error    Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Exception code: 0xc0000409
    Fault offset: 0x000000000022af80
    Faulting process ID: 0x1288
    Faulting application start time: 0x01d30d3f72269e01
    Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Report ID: 3709e4c1-03e3-418e-871b-1e9c2570db88
    Faulting package full name: 
    Faulting package-relative application ID:05/08/2017 22:57    Application Error    Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Exception code: 0xc0000409
    Fault offset: 0x000000000022af80
    Faulting process ID: 0x12c8
    Faulting application start time: 0x01d30e2574fc59ef
    Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Report ID: 7dee3aef-d3a9-42eb-a5bb-2d8a9ae3cb81
    Faulting package full name: 
    Faulting package-relative application ID:04/08/2017 15:33    Application Error    Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Exception code: 0xc0000409
    Fault offset: 0x000000000022af80
    Faulting process ID: 0x1314
    Faulting application start time: 0x01d30d315477cd91
    Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Report ID: 796571d8-07d0-45cf-84b0-4d212e3c161b
    Faulting package full name: 
    Faulting package-relative application ID:04/08/2017 14:50    Application Error    Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Exception code: 0xc0000409
    Fault offset: 0x000000000022af80
    Faulting process ID: 0x1344
    Faulting application start time: 0x01d30c85218e600a
    Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Report ID: 55e86b51-fa5c-4bdb-8f35-7e2988ef1b24
    Faulting package full name: 
    Faulting package-relative application ID:21/07/2017 21:30    Application Error    Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Exception code: 0xc0000409
    Fault offset: 0x000000000022af80
    Faulting process ID: 0x1364
    Faulting application start time: 0x01d302651e4dbf69
    Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Report ID: 1060afb1-9265-4e4b-9b1d-a10d4e6863d1
    Faulting package full name: 
    Faulting package-relative application ID:03/08/2017 17:30    Application Error    Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Exception code: 0xc0000409
    Fault offset: 0x000000000022af80
    Faulting process ID: 0x136c
    Faulting application start time: 0x01d3080a22a49594
    Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Report ID: 60133062-c34e-479c-b729-d5abc6680d41
    Faulting package full name: 
    Faulting package-relative application ID:21/07/2017 20:23    Application Error    Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Exception code: 0xc0000409
    Fault offset: 0x000000000022af80
    Faulting process ID: 0x137c
    Faulting application start time: 0x01d30254dbf1da51
    Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Report ID: 82caa6e8-d86f-4db3-bc9d-536d38b00a21
    Faulting package full name: 
    Faulting package-relative application ID:21/07/2017 21:57    Application Error    Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Exception code: 0xc0000409
    Fault offset: 0x000000000022af80
    Faulting process ID: 0x13bc
    Faulting application start time: 0x01d302695f64e208
    Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Report ID: b3a6f3d6-079d-44db-8a32-b713cc634332
    Faulting package full name: 
    Faulting package-relative application ID:26/07/2017 18:09    Application Error    Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Exception code: 0xc0000409
    Fault offset: 0x000000000022af80
    Faulting process ID: 0x13c8
    Faulting application start time: 0x01d3062cac5483bc
    Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Report ID: ac78929a-cf95-45c0-b098-93a57a5e54d3
    Faulting package full name: 
    Faulting package-relative application ID:06/08/2017 01:09    Application Error    Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
    Exception code: 0xc0000409
    Fault offset: 0x000000000022af80
    Faulting process ID: 0x13e0
    Faulting application start time: 0x01d30e3ef9c96c56
    Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    Report ID: 7fa81eab-be0f-48ad-ad76-cf52e6a0bd00
    Faulting package full name: 
    Faulting package-relative application ID:

    Code:
    Event[20893]:  Log Name: System
      Source: Microsoft-Windows-Kernel-Boot
      Date: 2017-08-09T16:20:57.801
      Event ID: 16
      Task: N/A
      Level: Error
      Opcode: Info
      Keyword: N/A
      User: S-1-5-18
      User Name: NT AUTHORITY\SYSTEM
      Computer: HP-Henry
      Description: 
    Windows failed to resume from hibernate with error status 0xC0000001.
    Code:
    Event[20881]:  Log Name: System
      Source: Microsoft-Windows-TPM-WMI
      Date: 2017-08-09T16:17:39.004
      Event ID: 1026
      Task: N/A
      Level: Information
      Opcode: Info
      Keyword: N/A
      User: S-1-5-18
      User Name: NT AUTHORITY\SYSTEM
      Computer: HP-Henry
      Description: 
    The Trusted Platform Module (TPM) hardware on this computer cannot be provisioned for use automatically.  To set up the TPM interactively use the TPM management console (Start->tpm.msc) and use the action to make the TPM ready.
    
    
    Error: The TPM is defending against dictionary attacks and is in a time-out period.
    Additional Information: 0x100000
    
    
    Event[20882]:
      Log Name: System
      Source: Microsoft-Windows-TPM-WMI
      Date: 2017-08-09T16:17:41.134
      Event ID: 1026
      Task: N/A
      Level: Information
      Opcode: Info
      Keyword: N/A
      User: S-1-5-18
      User Name: NT AUTHORITY\SYSTEM
      Computer: HP-Henry
      Description: 
    The Trusted Platform Module (TPM) hardware on this computer cannot be provisioned for use automatically.  To set up the TPM interactively use the TPM management console (Start->tpm.msc) and use the action to make the TPM ready.
    
    
    Error: The TPM is defending against dictionary attacks and is in a time-out period.
    Additional Information: 0x100000
    Last edited by zbook; 09 Aug 2017 at 15:41.
      My ComputerSystem Spec
  10.    10 Aug 2017 #20
    Join Date : Apr 2017
    Posts : 8,761
    windows 10 professional version 1607 build 14393.969 64 bit
      My ComputerSystem Spec

 
Page 2 of 6 FirstFirst 1234 ... LastLast


Similar Threads
Thread Forum
BSOD immediately after sleep/hibernate V2
This is just a continuation of a previous thread which was marked as too old. See https://www.tenforums.com/bsod-crashes-debugging/63396-bsod-immediately-after-sleep-hibernate.html Had another BSOD immediately after returning from hibernate. I...
BSOD Crashes and Debugging
BSOD immediately after sleep/hibernate
I sometimes get a failure from either Corrupt Page or Memory Management after returning from either sleep mode or hibernate. Always caused by ntoskrnl.exe+142940. I wonder if it might be caused by my trying to log in too soon and the different...
BSOD Crashes and Debugging
Strange behavior after waking from hibernate
Lately my computer has been doing strange things after waking from hibernate. The first time 2 days ago after waking from hibernate my monitor did not wake up and just remained a black screen, yet after i restarted the computer it acted as if i had...
General Support
BSOD waking from sleep or hibernate
Hello! I have BSODs after waking my computer up. Windows 10 upgraded from Windows 8.1. Waking from hibernate generates Kernel_Security_Check_Failure. Waking from sleep generates mostly IRQ NOT EQUAL. Could you please help? Thanks!
BSOD Crashes and Debugging
BSOD resuming from Hibernate
This also happened with Windows 8.x but it persisted after I upgraded to Windows 10. It's an older machine with limited support, but I'd like to try and use it if I can. It's a tank of a laptop. 40024 Thanks
BSOD Crashes and Debugging
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd
All times are GMT -5. The time now is 10:01.
Find Us
Twitter Facebook Google+ Ten Forums iOS App Ten Forums Android App



Windows 10 Forums