Please confirm that windows defender is on and post the results into the thread.
Please post images of the 3 antivirus scans from post #37.
Perform windows updates and post any failed KB# with error code.
Open file explorer > this PC > local C: drive and scan for mwac.sys then post an image of the results into the thread.
Code:
BugCheck C4, {2000, fffff80d8584a25c, 0, 444c534b}*** WARNING: Unable to verify timestamp for MpKsla9c5b15e.sys*** ERROR: Module load completed but symbols could not be loaded for MpKsla9c5b15e.sysProbably caused by : MpKsla9c5b15e.sys ( MpKsla9c5b15e+a25c )
Code:
MpKsla9c5b15 MpKsla9c5b15e MpKsla9c5b15e Kernel System Running OK TRUE FALSE 8,192 16,384 0 5/19/2015 7:50:37 PM \??\C:\ProgramData\Microsoft\Windows Defender\De 8,192
Code:
8/17/2017 9:41 PM Application Error Faulting application name: mbamservice.exe, version: 3.1.0.479, time stamp: 0x58f6af02
Faulting module name: ScanControllerImpl.dll, version: 3.0.0.715, time stamp: 0x593eed6b
Exception code: 0xc0000005
Fault offset: 0x00000000000d558c
Faulting process id: 0xd28
Faulting application start time: 0x01d316df7f1a4fbd
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\ScanControllerImpl.dll
Report Id: 5d7c6d17-fcd5-44f5-b6ad-26716afe77fb
Faulting package full name:
Faulting package-relative application ID:
Code:
8/18/2017 8:38 PM Windows Error Reporting Fault bucket , type 0
Event Name: StoreAgentScanForUpdatesFailure0
Response: Not available
Cab Id: 0
Problem signature:
P1: Update;
P2: 8024402c
P3: 15063
P4: 540
P5: Windows.Desktop
P6:
P7:
P8:
P9:
P10:
Attached files:
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Update;_85f6442782cd14381fecacea6b41bdc96cee5cfc_00000000_1e430c55
Analysis symbol:
Rechecking for solution: 0
Report Id: 9d9a19f5-9c91-40e8-989e-74e245569b23
Report Status: 4
Hashed bucket:8/18/2017 8:38 PM Windows Error Reporting Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0
Problem signature:
P1: 10.0.15063.502
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 0
P7: 8024500b
P8: Update;taskhostw
P9: {855E8A7C-ECB4-4CA3-B045-1DFA50104289}
P10: 0
Attached files:
These files may be available here:
Analysis symbol:
Rechecking for solution: 0
Report Id: d42f51be-11c5-4680-8610-b6ba8b83f2a8
Report Status: 1074003968
Hashed bucket:8/18/2017 8:38 PM Windows Error Reporting Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0
Problem signature:
P1: 10.0.15063.502
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 0
P7: 8024500b
P8: Update;taskhostw
P9: {855E8A7C-ECB4-4CA3-B045-1DFA50104289}
P10: 0
Attached files:
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_10.0.15063.502_e9f44ee9b7ed7ed27cdd8f1edd669f1138b45aa7_00000000_1f6f0c55
Analysis symbol:
Rechecking for solution: 0
Report Id: d42f51be-11c5-4680-8610-b6ba8b83f2a8
Report Status: 4
Hashed bucket:8/18/2017 9:59 PM Windows Error Reporting Fault bucket , type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 0
Problem signature:
P1: d1
P2: fffff8e3ee98fcf4
P3: 2
P4: 0
P5: fffff803ee98329f
P6: 10_0_15063
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\081817-18375-01.dmp
\\?\C:\Windows\Temp\WER-19046-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5582.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER55B1.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER55C2.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_d1_3987895aad6d28fea131cf166cafb2f17aa9f1_00000000_cab_226457d4
Analysis symbol:
Rechecking for solution: 0
Report Id: 6d42f781-8e8c-45ea-8d60-dbdb62aa9c56
Report Status: 2049
Hashed bucket:8/18/2017 9:59 PM Windows Error Reporting Fault bucket , type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 0
Problem signature:
P1: d1
P2: fffff8e3ee98fcf4
P3: 2
P4: 0
P5: fffff803ee98329f
P6: 10_0_15063
P7: 0_0
P8: 256_1
P9:
P10:
Attached files:
\\?\C:\Windows\Minidump\081817-18375-01.dmp
\\?\C:\Windows\Temp\WER-19046-0.sysdata.xml
\\?\C:\Windows\MEMORY.DMP
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5582.tmp.WERInternalMetadata.xml
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER55B1.tmp.csv
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER55C2.tmp.txt
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_d1_3987895aad6d28fea131cf166cafb2f17aa9f1_00000000_035455c1
Analysis symbol:
Rechecking for solution: 0
Report Id: 6d42f781-8e8c-45ea-8d60-dbdb62aa9c56
Report Status: 4
Hashed bucket:
Code:
Event[10912]: Log Name: System
Source: Microsoft-Windows-Kernel-Processor-Power
Date: 2017-08-18T15:58:50.689
Event ID: 35
Task: N/A
Level: Error
Opcode: Info
Keyword: N/A
User: S-1-5-18
User Name: NT AUTHORITY\SYSTEM
Computer: DESKTOP-N44VCA9
Description:
Performance power management features on processor 11 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.
Code:
Event[10848]: Log Name: System
Source: Microsoft-Windows-Time-Service
Date: 2017-08-18T14:51:45.769
Event ID: 158
Task: N/A
Level: Information
Opcode: Info
Keyword: N/A
User: S-1-5-19
User Name: NT AUTHORITY\LOCAL SERVICE
Computer: DESKTOP-N44VCA9
Description:
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.
Code:
Event[10829]: Log Name: System
Source: Microsoft-Windows-StartupRepair
Date: 2017-08-18T14:35:07.812
Event ID: 1002
Task: N/A
Level: Information
Opcode: Info
Keyword: N/A
User: S-1-5-18
User Name: NT AUTHORITY\SYSTEM
Computer: DESKTOP-N44VCA9
Description:
Startup Repair failed.
Event[10830]:
Log Name: System
Source: Microsoft-Windows-StartupRepair
Date: 2017-08-18T14:35:07.812
Event ID: 1123
Task: N/A
Level: Information
Opcode: Info
Keyword: N/A
User: S-1-5-18
User Name: NT AUTHORITY\SYSTEM
Computer: DESKTOP-N44VCA9
Description:
Windows was unable to determine the problem. Error code: 0xc4
Event[10831]:
Log Name: System
Source: Microsoft-Windows-StartupRepair
Date: 2017-08-18T14:35:07.812
Event ID: 1208
Task: N/A
Level: Information
Opcode: Info
Keyword: N/A
User: S-1-5-18
User Name: NT AUTHORITY\SYSTEM
Computer: DESKTOP-N44VCA9
Description:
Restored system to an earlier restore point.
Code:
Event[10708]: Log Name: System
Source: Service Control Manager
Date: 2017-08-17T16:47:00.575
Event ID: 7000
Task: N/A
Level: Error
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: DESKTOP-N44VCA9
Description:
The eapihdrv service failed to start due to the following error:
This driver has been blocked from loading
Code:
Event[10704]: Log Name: System
Source: Service Control Manager
Date: 2017-08-17T16:46:59.951
Event ID: 7000
Task: N/A
Level: Error
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: DESKTOP-N44VCA9
Description:
The eapihdrv service failed to start due to the following error:
This driver has been blocked from loading
Code:
Event[10700]: Log Name: System
Source: Service Control Manager
Date: 2017-08-17T16:46:59.930
Event ID: 7000
Task: N/A
Level: Error
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: DESKTOP-N44VCA9
Description:
The eapihdrv service failed to start due to the following error:
This driver has been blocked from loading
Code:
Event[10696]: Log Name: System
Source: Service Control Manager
Date: 2017-08-17T16:46:59.888
Event ID: 7000
Task: N/A
Level: Error
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: DESKTOP-N44VCA9
Description:
The eapihdrv service failed to start due to the following error:
This driver has been blocked from loading