Constant BSODs caused by ntoskrnl.exe

Page 5 of 5 FirstFirst ... 345

  1. Posts : 23
    Windows 10 Pro (64 bits)
    Thread Starter
       #41

    Are you using Intel Speedstep?
    I don't think so
    It may take some time, but please take the time you need to perform it properly.
    When above is done please make screenshots of the following
    the health,
    the error scan,
    the benchmark incl. following
    transfer rate,
    access time,
    burst rate,
    cpu usage.
    I uploaded an image with all of these, and got no errors, nor bad health results.
    Hello, Mister! I had the EXACT same problem as you caused by ntoskrnl.exe, shown in whocrashed.
    Found your thread on Google just 2days back and found myself a fix for it.
    - Fix? FAULTY/NOT SUPPORTED RAM BRICKS! HARDWARE!
    Could this actually be an option? I don't see any of the Team Vulcan 32GB (8Gx4) kits, and the tests I ran with memtest were 16GB and then 16GB.
      My Computer


  2. Posts : 41,452
    windows 10 professional version 1607 build 14393.969 64 bit
       #42

    Please confirm that windows defender is on and post the results into the thread.
    Please post images of the 3 antivirus scans from post #37.
    Perform windows updates and post any failed KB# with error code.
    Open file explorer > this PC > local C: drive and scan for mwac.sys then post an image of the results into the thread.



    Code:
    BugCheck C4, {2000, fffff80d8584a25c, 0, 444c534b}*** WARNING: Unable to verify timestamp for MpKsla9c5b15e.sys*** ERROR: Module load completed but symbols could not be loaded for MpKsla9c5b15e.sysProbably caused by : MpKsla9c5b15e.sys ( MpKsla9c5b15e+a25c )
    Code:
    MpKsla9c5b15 MpKsla9c5b15e          MpKsla9c5b15e          Kernel        System     Running    OK         TRUE        FALSE        8,192             16,384      0          5/19/2015 7:50:37 PM   \??\C:\ProgramData\Microsoft\Windows Defender\De 8,192
    mwac.sys Malwarebytes Web Access Control
    If it's blamed in a BSOD, it may be due to an outdated version of BitDefender 2016. Ensure that BitDefender is updated to the latest version. Fix came out around 02 July 2016
    Support: http://www.malwarebytes.org/support/consumer/
    Download: http://www.malwarebytes.org/downloads/

    Code:
    8/17/2017 9:41 PM    Application Error    Faulting application name: mbamservice.exe, version: 3.1.0.479, time stamp: 0x58f6af02
    Faulting module name: ScanControllerImpl.dll, version: 3.0.0.715, time stamp: 0x593eed6b
    Exception code: 0xc0000005
    Fault offset: 0x00000000000d558c
    Faulting process id: 0xd28
    Faulting application start time: 0x01d316df7f1a4fbd
    Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
    Faulting module path: C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\ScanControllerImpl.dll
    Report Id: 5d7c6d17-fcd5-44f5-b6ad-26716afe77fb
    Faulting package full name: 
    Faulting package-relative application ID:
    MpKsla51ccaa0.sys May be dynamic update driver for Microsoft Security Essentials Unknown driver from this post: http://www.sevenforums.com/crashes-d...-problems.html or Windows Update
    MpKsla9247ba8.sys May be dynamic update driver for Microsoft Security Essentials Unknown driver from this post: http://www.techsupportforum.com/foru...38-550287.html or Windows Update
    MpKslaab054de.sys May be dynamic update driver for Microsoft Security Essentials Unknown driver from this post: http://www.sevenforums.com/crashes-d...-7-32-bit.html or Windows Update


    Code:
    8/18/2017 8:38 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: StoreAgentScanForUpdatesFailure0
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: Update;
    P2: 8024402c
    P3: 15063
    P4: 540
    P5: Windows.Desktop
    P6: 
    P7: 
    P8: 
    P9: 
    P10: 
    
    Attached files:
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Update;_85f6442782cd14381fecacea6b41bdc96cee5cfc_00000000_1e430c55
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 9d9a19f5-9c91-40e8-989e-74e245569b23
    Report Status: 4
    Hashed bucket:8/18/2017 8:38 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: WindowsUpdateFailure3
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 10.0.15063.502
    P2: 8024402c
    P3: 00000000-0000-0000-0000-000000000000
    P4: Scan
    P5: 0
    P6: 0
    P7: 8024500b
    P8: Update;taskhostw
    P9: {855E8A7C-ECB4-4CA3-B045-1DFA50104289}
    P10: 0
    
    Attached files:
    
    These files may be available here:
    
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: d42f51be-11c5-4680-8610-b6ba8b83f2a8
    Report Status: 1074003968
    Hashed bucket:8/18/2017 8:38 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: WindowsUpdateFailure3
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: 10.0.15063.502
    P2: 8024402c
    P3: 00000000-0000-0000-0000-000000000000
    P4: Scan
    P5: 0
    P6: 0
    P7: 8024500b
    P8: Update;taskhostw
    P9: {855E8A7C-ECB4-4CA3-B045-1DFA50104289}
    P10: 0
    
    Attached files:
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_10.0.15063.502_e9f44ee9b7ed7ed27cdd8f1edd669f1138b45aa7_00000000_1f6f0c55
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: d42f51be-11c5-4680-8610-b6ba8b83f2a8
    Report Status: 4
    Hashed bucket:8/18/2017 9:59 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: d1
    P2: fffff8e3ee98fcf4
    P3: 2
    P4: 0
    P5: fffff803ee98329f
    P6: 10_0_15063
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\Windows\Minidump\081817-18375-01.dmp
    \\?\C:\Windows\Temp\WER-19046-0.sysdata.xml
    \\?\C:\Windows\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5582.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER55B1.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER55C2.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_d1_3987895aad6d28fea131cf166cafb2f17aa9f1_00000000_cab_226457d4
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 6d42f781-8e8c-45ea-8d60-dbdb62aa9c56
    Report Status: 2049
    Hashed bucket:8/18/2017 9:59 PM    Windows Error Reporting    Fault bucket , type 0
    Event Name: BlueScreen
    Response: Not available
    Cab Id: 0
    
    Problem signature:
    P1: d1
    P2: fffff8e3ee98fcf4
    P3: 2
    P4: 0
    P5: fffff803ee98329f
    P6: 10_0_15063
    P7: 0_0
    P8: 256_1
    P9: 
    P10: 
    
    Attached files:
    \\?\C:\Windows\Minidump\081817-18375-01.dmp
    \\?\C:\Windows\Temp\WER-19046-0.sysdata.xml
    \\?\C:\Windows\MEMORY.DMP
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5582.tmp.WERInternalMetadata.xml
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER55B1.tmp.csv
    \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER55C2.tmp.txt
    
    These files may be available here:
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_d1_3987895aad6d28fea131cf166cafb2f17aa9f1_00000000_035455c1
    
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 6d42f781-8e8c-45ea-8d60-dbdb62aa9c56
    Report Status: 4
    Hashed bucket:

    Code:
    Event[10912]:  Log Name: System
      Source: Microsoft-Windows-Kernel-Processor-Power
      Date: 2017-08-18T15:58:50.689
      Event ID: 35
      Task: N/A
      Level: Error
      Opcode: Info
      Keyword: N/A
      User: S-1-5-18
      User Name: NT AUTHORITY\SYSTEM
      Computer: DESKTOP-N44VCA9
      Description: 
    Performance power management features on processor 11 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.
    Code:
    Event[10848]:  Log Name: System
      Source: Microsoft-Windows-Time-Service
      Date: 2017-08-18T14:51:45.769
      Event ID: 158
      Task: N/A
      Level: Information
      Opcode: Info
      Keyword: N/A
      User: S-1-5-19
      User Name: NT AUTHORITY\LOCAL SERVICE
      Computer: DESKTOP-N44VCA9
      Description: 
    The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.
    Code:
    Event[10829]:  Log Name: System
      Source: Microsoft-Windows-StartupRepair
      Date: 2017-08-18T14:35:07.812
      Event ID: 1002
      Task: N/A
      Level: Information
      Opcode: Info
      Keyword: N/A
      User: S-1-5-18
      User Name: NT AUTHORITY\SYSTEM
      Computer: DESKTOP-N44VCA9
      Description: 
    Startup Repair failed.
    
    
    Event[10830]:
      Log Name: System
      Source: Microsoft-Windows-StartupRepair
      Date: 2017-08-18T14:35:07.812
      Event ID: 1123
      Task: N/A
      Level: Information
      Opcode: Info
      Keyword: N/A
      User: S-1-5-18
      User Name: NT AUTHORITY\SYSTEM
      Computer: DESKTOP-N44VCA9
      Description: 
    Windows was unable to determine the problem. Error code: 0xc4
    
    
    Event[10831]:
      Log Name: System
      Source: Microsoft-Windows-StartupRepair
      Date: 2017-08-18T14:35:07.812
      Event ID: 1208
      Task: N/A
      Level: Information
      Opcode: Info
      Keyword: N/A
      User: S-1-5-18
      User Name: NT AUTHORITY\SYSTEM
      Computer: DESKTOP-N44VCA9
      Description: 
    Restored system to an earlier restore point.
    Code:
    Event[10708]:  Log Name: System
      Source: Service Control Manager
      Date: 2017-08-17T16:47:00.575
      Event ID: 7000
      Task: N/A
      Level: Error
      Opcode: N/A
      Keyword: Classic
      User: N/A
      User Name: N/A
      Computer: DESKTOP-N44VCA9
      Description: 
    The eapihdrv service failed to start due to the following error: 
    This driver has been blocked from loading
    Code:
    Event[10704]:  Log Name: System
      Source: Service Control Manager
      Date: 2017-08-17T16:46:59.951
      Event ID: 7000
      Task: N/A
      Level: Error
      Opcode: N/A
      Keyword: Classic
      User: N/A
      User Name: N/A
      Computer: DESKTOP-N44VCA9
      Description: 
    The eapihdrv service failed to start due to the following error: 
    This driver has been blocked from loading
    Code:
    Event[10700]:  Log Name: System
      Source: Service Control Manager
      Date: 2017-08-17T16:46:59.930
      Event ID: 7000
      Task: N/A
      Level: Error
      Opcode: N/A
      Keyword: Classic
      User: N/A
      User Name: N/A
      Computer: DESKTOP-N44VCA9
      Description: 
    The eapihdrv service failed to start due to the following error: 
    This driver has been blocked from loading
    Code:
    Event[10696]:  Log Name: System
      Source: Service Control Manager
      Date: 2017-08-17T16:46:59.888
      Event ID: 7000
      Task: N/A
      Level: Error
      Opcode: N/A
      Keyword: Classic
      User: N/A
      User Name: N/A
      Computer: DESKTOP-N44VCA9
      Description: 
    The eapihdrv service failed to start due to the following error: 
    This driver has been blocked from loading
      My Computer


  3. Posts : 23
    Windows 10 Pro (64 bits)
    Thread Starter
       #43

    Please confirm that windows defender is on and post the results into the thread.
    Please post images of the 3 antivirus scans from post #37.
    Perform windows updates and post any failed KB# with error code.
    Open file explorer > this PC > local C: drive and scan for mwac.sys then post an image of the results into the thread.
    I think everything is on the screenshot. If not, tell me. Do I click on clean the threats, or are they something I could need?
    Attachment 149625
      My Computer


  4. Posts : 41,452
    windows 10 professional version 1607 build 14393.969 64 bit
       #44

    1) Please confirm that there has never been malware found only PUPs.
    2) Quarantine everything that was found and then delete.
    3) Uninstall Malwarebytes during the troubleshooting
    4) Perform these scans:
    a) tdsskiller: https://usa.kaspersky.com/downloads/tdsskiller
    b) zemana antimalware: Zemana Anti-Malware | Advanced Malware Removal Software
    d) run windows defender advanced scan: offline scan
    5) Uninstall all antivirus products and just use windows defender during the troubleshooting process.
    Last edited by zbook; 19 Aug 2017 at 23:54.
      My Computer


  5. Posts : 23
    Windows 10 Pro (64 bits)
    Thread Starter
       #45

    Here is the memory.dmp file i was asked in post #38
    Microsoft OneDrive - Access files anywhere. Create docs with free Office Online.
      My Computer


  6. Posts : 41,452
    windows 10 professional version 1607 build 14393.969 64 bit
       #46

    The memory.dmp when debugged did not display a definitive misbehaving driver.

    After you complete the above remaining scans plan to use this tool to find misbehaving drivers. It will help by producing bsod which will be debugged and may enable differentiating misbehaving hardware from software and hardware drivers.

    Windows driver verifier is a tool that is used to find misbehaving drivers.
    It will repetitively produce bsod until misbehaving drivers are fixed or until it is turned off.
    Before using it you must know how to turn off windows driver verifier.
    There are 3 methods and all are done with the windows recovery or advanced troubleshooting menu.
    1) startup options (not startup repair) > #6 safe mode with command prompt: type: verifier /reset
    2) command prompt > Administrator X: \windows\system32\cmd.exe: > type: verifier /bootmode resetonbootfail
    3) restore
    The restore method leads to a lost of the mini dump file and little progress is made in the troubleshooting.
    To practice using the windows advanced recovery open administrative command prompt and type or copy and paste:
    shutdown /r /o /f /t 00

    To have time to view the bsod windows during each dump > system control panel > advanced system settings > startup and recovery settings > un-check automatically restart
    During each windows driver verifier bsod there is a stop code typically driver verifer detected violation and sometimes the misbehaving driver is displayed in the form *.sys. If you see the driver please record it and post it in the thread.
    Please download and install both bluescreenview and whocrashed.
    Blue screen of death (STOP error) information in dump files.
    http://www.resplendence.com/whocrashed
    After each bsod you will uninstall each misbehaving driver. Then you can restart windows driver verifier and look for another misbehaving driver or reinstall a new copy of the misbehaving driver. The methods should end up with the same result and it is personal preference whether you uninstall all misbehaving driver first and reinstall drivers later or reinstall after each misbehaving driver is uninstalled.
    After each bsod you will return to the desktop top and run bluescreenview and whocrashed and you can post a new zip so that we can guide you through the process: BSOD - Posting Instructions - Windows 10 Forums
    Once all bsod have been fixed you will run windows driver verifier for an additional 36 hours of typical computer use. If there are no more bsod troubleshooting and preventative maintenance will have been completed.

    Before using windows driver verifier:
    1) create a brand new restore point
    2) backup files to another drive or to the cloud
    3) create a backup image using Macrium: Macrium Software | Your Image is Everything
    4) place the backup image on another drive

    The first link has the customized testing settings and the second link has the methods to turn on and off windows driver verifier.
    Please read both so that you are comfortable using the tool.

    1) Driver Verifier-- tracking down a mis-behaving driver. - Microsoft Community

    2) Enable and Disable Driver Verifier in Windows 10 Windows 10 Performance Maintenance Tutorials

    3) Microsoft Community
      My Computer


  7. Posts : 41,452
    windows 10 professional version 1607 build 14393.969 64 bit
       #47

    Please download and install: Intel processor identification utility > Click CPU technologies tab > post image into the thread.
      My Computer


  8. Posts : 926
    Windows 10 Pro
       #48

    Something I found in the MEMORY.DMP:

    Code:
    >[IRP_MJ_FILE_SYSTEM_CONTROL(d), N/A(0)]
                1  1 ffff800bd7a4d030 ffff800bebe84ef0 00000000-00000000    pending
               \FileSystem\NTFS
                Args: 00000018 0000000c 00090240 00000000

    Looks strange for me. At this point I really recommend a clean install of Windows 10

    Clean Install Windows 10 Windows 10 Installation Upgrade Tutorials
      My Computer


  9. Posts : 23
    Windows 10 Pro (64 bits)
    Thread Starter
       #49

    So, it's been 4 days since my last post, and you're probably asking "where did he go?". Well, since that last post, i decided to take out 16GB (2x8) sticks of RAM. I haven't had any crashes since. I guess this specific model (Team Vulcan 16gb (2x8gb) DDR4 2400, model #: TLGD416G2400HC14DC01) isn't supposed to be paired with another of these. I want to thank y'all for helping me along this troubleshoot, and to say sorry for any inconveniences this caused. Have a good one!
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 13:24.
Find Us




Windows 10 Forums