Windows 10: Constant BSODs caused by ntoskrnl.exe

Discus and support Constant BSODs caused by ntoskrnl.exe in Windows 10 BSOD Crashes and Debugging to solve the problem; There was 1 bsod mini dump file debugged which did not display a definitive misbehaving driver. Continue using windows drive verifier to create more... Discussion in 'Windows 10 BSOD Crashes and Debugging' started by cemarv25, Aug 2, 2017.

  1. zbook New Member

    Constant BSODs caused by ntoskrnl.exe


    There was 1 bsod mini dump file debugged which did not display a definitive misbehaving driver.
    Continue using windows drive verifier to create more mini dump files.
    Once there are no longer any bsod plan to run windows driver for 36 hours of typical computer use.

    Rocket League is a frequently faulting application. Can this be uninstalled while you are troubleshooting bsod?


    Code: BugCheck 20, {0, ffff, 0, 0}*** WARNING: Unable to verify timestamp for win32k.sys*** ERROR: Module load completed but symbols could not be loaded for win32k.sysProbably caused by : memory_corruption[/quote]
     
    zbook, Aug 11, 2017
    #31
  2. cemarv25 Win User

    Well, it just keeps showing the amd psp driver.

    On Sat 8/12/2017 11:00:00 AM your computer crashed
    crash dump file: C:\Windows\Minidump\081217-8828-01.dmp
    This was probably caused by the following module: amdpsp.sys (amdpsp+0x1702B)
    Bugcheck code: 0xC4 (0x2000, 0xFFFFF80D4CE5702B, 0x0, 0x544545)
    Error: DRIVER_VERIFIER_DETECTED_VIOLATION
    file path: C:\Windows\system32\drivers\amdpsp.sys
    product: Advanced Micro Devices, Inc. amdpsp sys
    company: Advanced Micro Devices, Inc.
    description: amdpsp sys
    Bug check description: This is the general bug check code for fatal errors found by Driver Verifier.
    This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
    A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: amdpsp.sys (amdpsp sys, Advanced Micro Devices, Inc. ).
    Google query: Advanced Micro Devices, Inc. DRIVER_VERIFIER_DETECTED_VIOLATION



    On Sat 8/12/2017 11:00:00 AM your computer crashed
    crash dump file: C:\Windows\memory.dmp
    This was probably caused by the following module: amdpsp.sys (amdpsp+0x1702B)
    Bugcheck code: 0xC4 (0x2000, 0xFFFFF80D4CE5702B, 0x0, 0x544545)
    Error: DRIVER_VERIFIER_DETECTED_VIOLATION
    file path: C:\Windows\system32\drivers\amdpsp.sys
    product: Advanced Micro Devices, Inc. amdpsp sys
    company: Advanced Micro Devices, Inc.
    description: amdpsp sys
    Bug check description: This is the general bug check code for fatal errors found by Driver Verifier.
    This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
    A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: amdpsp.sys (amdpsp sys, Advanced Micro Devices, Inc. ).
    Google query: Advanced Micro Devices, Inc. DRIVER_VERIFIER_DETECTED_VIOLATION



    On Sat 8/12/2017 10:33:07 AM your computer crashed
    crash dump file: C:\Windows\Minidump\081217-9640-01.dmp
    This was probably caused by the following module: amdpsp.sys (amdpsp+0x1702B)
    Bugcheck code: 0xC4 (0x2000, 0xFFFFF80EFC67702B, 0x0, 0x544545)
    Error: DRIVER_VERIFIER_DETECTED_VIOLATION
    file path: C:\Windows\system32\drivers\amdpsp.sys
    product: Advanced Micro Devices, Inc. amdpsp sys
    company: Advanced Micro Devices, Inc.
    description: amdpsp sys
    Bug check description: This is the general bug check code for fatal errors found by Driver Verifier.
    This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
    A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: amdpsp.sys (amdpsp sys, Advanced Micro Devices, Inc. ).
    Google query: Advanced Micro Devices, Inc. DRIVER_VERIFIER_DETECTED_VIOLATION



    On Sat 8/12/2017 10:25:16 AM your computer crashed
    crash dump file: C:\Windows\Minidump\081217-15703-01.dmp
    This was probably caused by the following module: ntoskrnl.exe (nt+0x16C560)
    Bugcheck code: 0x50 (0xFFFFA5013514DB08, 0x2, 0xFFFFF802F02C24A3, 0x2)
    Error: PAGE_FAULT_IN_NONPAGED_AREA
    file path: C:\Windows\system32\ntoskrnl.exe
    product: Microsoft® Windows® Operating System
    company: Microsoft Corporation
    description: NT Kernel & System
    Bug check description: This indicates that invalid system memory has been referenced.
    This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
    The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



    On Fri 8/11/2017 8:21:09 PM your computer crashed
    crash dump file: C:\Windows\Minidump\081117-10031-01.dmp
    This was probably caused by the following module: amdpsp.sys (amdpsp+0x1702B)
    Bugcheck code: 0xC4 (0x2000, 0xFFFFF80E4D49702B, 0x0, 0x544545)
    Error: DRIVER_VERIFIER_DETECTED_VIOLATION
    file path: C:\Windows\system32\drivers\amdpsp.sys
    product: Advanced Micro Devices, Inc. amdpsp sys
    company: Advanced Micro Devices, Inc.
    description: amdpsp sys
    Bug check description: This is the general bug check code for fatal errors found by Driver Verifier.
    This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
    A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: amdpsp.sys (amdpsp sys, Advanced Micro Devices, Inc. ).
    Google query: Advanced Micro Devices, Inc. DRIVER_VERIFIER_DETECTED_VIOLATION
     
    cemarv25, Aug 11, 2017
    #32
  3. zbook New Member
    Please open the Asus website > enter the computer's serial or product number with operating system > view all drivers > make images and post into the thread.

    Please reinstall the AMD chip set drivers to see if this fixes the bsods.



    Code: Event[7482]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2017-08-11T19:37:09.827 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: Driver Management concluded the process to install driver amdpsp.inf_amd64_2c8bb141af1bb3b0\amdpsp.inf for Device Instance ID PCI\VEN_1022&DEV_1456&SUBSYS_14561022&REV_00\4&C93BEE2&0&0239 with the following status: 0x0.[/quote] Code: Event[7480]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2017-08-11T19:37:09.725 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: Driver Management has concluded the process to add Service amdpsp for Device Instance ID PCI\VEN_1022&DEV_1456&SUBSYS_14561022&REV_00\4&C93BEE2&0&0239 with the following status: 0.[/quote] Code: Event[7477]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2017-08-11T19:36:42.676 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: Driver Management concluded the process to install driver amdpsp.inf_amd64_13665d7332e0ee05\amdpsp.inf for Device Instance ID PCI\VEN_1022&DEV_1456&SUBSYS_14561022&REV_00\4&C93BEE2&0&0239 with the following status: 0x0.[/quote] Code: Event[7473]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2017-08-11T19:36:42.613 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: Driver Management has concluded the process to add Service amdpsp for Device Instance ID PCI\VEN_1022&DEV_1456&SUBSYS_14561022&REV_00\4&C93BEE2&0&0239 with the following status: 0.[/quote] Code: Event[7472]: Log Name: System Source: Service Control Manager Date: 2017-08-11T19:36:42.612 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: A service was installed in the system.Service Name: AMD PSP ServiceService File Name: system32\DRIVERS\amdpsp.sysService Type: kernel mode driverService Start Type: boot startService Account:[/quote]

    Code: amdpsp AMD PSP Service AMD PSP Service Kernel System Running OK TRUE FALSE 4,096 131,072 0 6/5/2017 3:23:56 PM C:\Windows\system32\DRIVERS\amdpsp.sys 4,096[/quote]
     
    zbook, Aug 11, 2017
    #33
  4. cemarv25 Win User

    Constant BSODs caused by ntoskrnl.exe

    I went and updated the chipset drivers. I should also say that inside the setup for updating those drivers, I you click on "custom install", you can select the AMD PSP drivers. After that, I activated driver verifier again, and it showed me that the mouse driver had failed, so I uninstalled and re-installed it. Then, after I had activated the verifier, it crashed again, but this time it didn't say "driver verifier detected violation", it said "irql not less or equal". I checked if the verifier was running in command prompt with verifier /querysettings and it is indeed running.
     
    cemarv25, Aug 12, 2017
    #34
  5. zbook New Member
    In the latest zip there were 5 bsod mini dump files.
    The last 2 were without windows driver verifier and did not display any definitive misbehaving drivers.
    The amdpsp driver may have been before or after the latest re-installation of the chip set drivers.
    With time zone changes it had a 8/12/2017 date.
    There was 1 new misbehaving driver detected: ElcMouLFlt.sys

    1) Open device manager > expand mice and other pointing devices > post an image of what is visible
    The database displays Kaspersky and that name typically is for antivirus products.
    So a posted image will be useful for others that may view this thread in the future.
    In the above post you had indicated that you had already troubleshooted this misbehaving driver. But if you kept the same mouse and replaced the driver an image may be useful.


    3) restart windows driver verifier and post any new bsod mini dump files with an updated zip


    See if one of these links has the driver for the Elecom mouse:
    http://www.elecom.co.jp/global/downl...ows/index.html

    http://www.elecom.co.jp/global/downl...use_assistant/



    Code: ElcMouLFlt ELECOM USB Mouse Lower ELECOM USB Mouse Lower Kernel Manual Stopped OK FALSE FALSE 4,096 8,192 0 10/4/2010 5:30:57 PM C:\Windows\system32\drivers\ElcMouLFlt.sys 4,096[/quote] Code: amdpsp AMD PSP Service AMD PSP Service Kernel Boot Running OK TRUE FALSE 4,096 131,072 0 6/5/2017 3:25:16 PM C:\Windows\system32\DRIVERS\amdpsp.sys 4,096[/quote]
    Code: BugCheck C4, {2000, fffff80d4ce5702b, 0, 544545}*** WARNING: Unable to verify timestamp for amdpsp.sys*** ERROR: Module load completed but symbols could not be loaded for amdpsp.sysProbably caused by : memory_corruption[/quote] Code: BugCheck C4, {2000, fffff80f16a916f6, 0, 0}*** WARNING: Unable to verify timestamp for ElcMouLFlt.sys*** ERROR: Module load completed but symbols could not be loaded for ElcMouLFlt.sysProbably caused by : ElcMouLFlt.sys ( ElcMouLFlt+16f6 )[/quote] ElcMouLFlt.sys Kaspersky Lower Mouse Device Filter driver http://usa.kaspersky.com/downloads/

    amdpsp.sys

    Code: BugCheck C4, {2000, fffff80a6339702b, 0, 544545}*** WARNING: Unable to verify timestamp for amdpsp.sys*** ERROR: Module load completed but symbols could not be loaded for amdpsp.sysProbably caused by : memory_corruption[/quote] Code: BugCheck 50, {ffff8f67f4f0d810, 0, fffff802fe8604c0, 2}Could not read faulting driver nameProbably caused by : memory_corruption[/quote] Code: BugCheck A, {ffffffffffffffdf, 2, 0, fffff801dc5973a1}Probably caused by : ntkrnlmp.exe ( nt!ViIrpDatabaseFindPointer+45 )[/quote]
     
    zbook, Aug 13, 2017
    #35
  6. cemarv25 Win User
    When I uninstalled and reinstalled the mouse driver, it changed to HID- compilant mouse (as you can see in the image). I also don't have any antivirus, as this is a new PC (I know I should've installed one). I restarted the driver verifier, and nothing happened. Today I got another two blue screens, without any sign of the verifier detecting a bad driver. I will leave the zip file and the device manager image here.
     
    cemarv25, Aug 14, 2017
    #36
  7. zbook New Member
    There was no definitive misbehaving driver in the latest bsod mini dump file.

    1) Turn on Windows defender.
    2) perform windows updates
    3) Download and install the free edition (not trial) for Malwarebytes
    4) Run the windows defender as a quick scan now
    5) Run windows defender as a full scan overnight.
    6) Run a Malwarebytes scan.
    The Malwarebytes will scan for PUPs.
    7) After all of the malware scans have completed create a brand new restore point
    8) start windows driver verifier to find misbehaving drivers
    Microsoft Community
    Microsoft Community
    Enable and Disable Driver Verifier in Windows 10 Windows 10 Performance Maintenance Tutorials
     
    zbook, Aug 14, 2017
    #37
  8. cemarv25 Win User

    Constant BSODs caused by ntoskrnl.exe

    I did all the scans with Windows Defender and Malwarebytes. Malwarebytes did find PUP (DriverAgent from before I reinstalled Windows again), and since I don't need it, I let Malwarebytes delete it. Then, I restarted driver verifier. I didn't get any crashes for two days so I went and reinstalled Rocket League. Today, just when I decided to make a post thanking you for your help, thinking the problem was solved, it crashed again. I restarted driver verifier, and this time it did detect a violation. I went to WhoCrashed, and saw that the responsible was mbae64.sys. I'll let you do your thing.
    PD: I guess my PC doesn't want me to thank you so I'll thank you in advance for all your patience and help, Thanks!
     
    cemarv25, Aug 16, 2017
    #38
  9. zbook New Member
    The bsod were seen in some of the logs however one of the events was crash dump failed.
    When a crash dump fails there is no mini dump file to debug.
    It's unclear how whocrashed was able to process the dump.
    If it was that means that it had had to exist.
    So make sure that if Ccleaner is being used that the settings are modified so that it does not delete dump files.
    Please post into the thread the whocrashed result.
    The mbam is malwarebytes. So it may need to be uninstalled.
    It did find a PUP.
    The Rocket League crash was reported in the windows events.
    When it crashed it involved Nvidia.
    So this may need some more testing to see whether the Nvidia driver was a cause of the dump as there were more crashes than dumps. With more mini dump files to debug the misbehaving driver may become apparent when using windows driver verifier again.


    To make sure any possible malware is addressed run these scanners on the computer and post the results into the thread:
    Downloads - AdwCleaner - ToolsLib
    SUPERAntiSpyware | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!
    Free Virus Scan | Online Virus Scan from ESET ESET

    Are you using Intel Speedstep?

    Code: Event[10123]: Log Name: System Source: volmgr Date: 2017-08-16T15:57:05.593 Event ID: 46 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: DESKTOP-N44VCA9 Description: Crash dump initialization failed![/quote] Code: Event[10287]: Log Name: System Source: Microsoft-Windows-StartupRepair Date: 2017-08-16T16:05:20.953 Event ID: 1002 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: Startup Repair failed.[/quote] Code: Event[10270]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2017-08-16T16:05:14.408 Event ID: 35 Task: N/A Level: Error Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: Performance power management features on processor 10 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.[/quote] Code: Event[10268]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2017-08-16T16:05:14.408 Event ID: 35 Task: N/A Level: Error Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: Performance power management features on processor 9 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.[/quote] Code: Event[10266]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2017-08-16T16:05:14.408 Event ID: 35 Task: N/A Level: Error Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: Performance power management features on processor 8 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.[/quote]
    Code: Event[10264]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2017-08-16T16:05:14.407 Event ID: 35 Task: N/A Level: Error Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: Performance power management features on processor 7 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.[/quote]
    Code: Event[10209]: Log Name: System Source: Service Control Manager Date: 2017-08-16T16:03:28.903 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: DESKTOP-N44VCA9 Description: The mrxsmb service depends on the rdbss service which failed to start because of the following error: A device attached to the system is not functioning.[/quote]



    Code: 8/16/2017 10:08 PM Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: c4 P2: 2006 P3: ffffc400b0857ef8 P4: fffff8025e8d01b0 P5: ffff9780eae4f6b8 P6: 10_0_15063 P7: 0_0 P8: 256_1 P9: P10: Attached files: \\?\C:\Windows\Minidump\081617-8125-01.dmp \\?\C:\Windows\Temp\WER-8359-0.sysdata.xml \\?\C:\Windows\MEMORY.DMP \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER28D5.tmp.WERInternalMetadata.xml These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_c4_9914c188b69621b8d2704518562ea78d2191d1_00000000_cab_2ff2e3de Analysis symbol: Rechecking for solution: 0 Report Id: 1a2763a2-6989-48b0-b0a2-64181b05c672 Report Status: 2049 Hashed bucket:8/16/2017 10:03 PM Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: c4 P2: 2006 P3: ffffc400b0857ef8 P4: fffff8025e8d01b0 P5: ffff9780eae4f6b8 P6: 10_0_15063 P7: 0_0 P8: 256_1 P9: P10: Attached files: \\?\C:\Windows\Minidump\081617-8125-01.dmp \\?\C:\Windows\Temp\WER-8359-0.sysdata.xml \\?\C:\Windows\MEMORY.DMP \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER28D5.tmp.WERInternalMetadata.xml These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_c4_9914c188b69621b8d2704518562ea78d2191d1_00000000_02cc28e4 Analysis symbol: Rechecking for solution: 0 Report Id: 1a2763a2-6989-48b0-b0a2-64181b05c672 Report Status: 4 Hashed bucket:8/16/2017 9:57 PM Windows Error Reporting Fault bucket 109089991477, type 1 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: NVIDIA Share.exe P2: 59.3071.1634.2 P3: 5978c893 P4: libcef.dll P5: 3.3071.1634.0 P6: 59498c26 P7: c0000005 P8: 01df0a00 P9: P10: Attached files: \\?\C:\Users\Cesar\AppData\Local\Temp\WER9964.tmp.WERDataCollectionStatus.txt \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERACF9.tmp.csv \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERAD19.tmp.txt These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_NVIDIA Share.exe_fecadec545c26c3eedb7268451b6bc74cc11991_b98ed6fd_3020d8eb Analysis symbol: Rechecking for solution: 0 Report Id: 6088b033-ff5c-4177-add1-546f61200259 Report Status: 268435456 Hashed bucket: 503347b1bbb676ff0a32c37cb5dba55b8/16/2017 9:55 PM Windows Error Reporting Fault bucket , type 0 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: RocketLeague.exe P2: 1.0.10897.0 P3: 59656779 P4: RocketLeague.exe P5: 1.0.10897.0 P6: 59656779 P7: c0000005 P8: 000fb411 P9: P10: Attached files: \\?\C:\Users\Cesar\AppData\Local\Temp\WEREE62.tmp.WERDataCollectionStatus.txt \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1EB.tmp.csv \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1FB.tmp.txt These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_RocketLeague.exe_5458689a1639c6eb4ea8503990b227c99b13_422dd9cd_1042183d Analysis symbol: Rechecking for solution: 0 Report Id: d8069970-da3b-4505-aa21-2a7a54b2978e Report Status: 97 Hashed bucket:8/16/2017 9:54 PM Windows Error Reporting Fault bucket 109032282452, type 1 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: RocketLeague.exe P2: 1.0.10897.0 P3: 59656779 P4: MSVCR100.dll P5: 10.0.40219.325 P6: 4df2be1e P7: c0000005 P8: 00001ed7 P9: P10: Attached files: \\?\C:\Users\Cesar\AppData\Local\Temp\WERF52D.tmp.WERDataCollectionStatus.txt \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8B4.tmp.csv \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER8C4.tmp.txt These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_RocketLeague.exe_3f5b0662e45e1ae81bb79aeb8d54a8679ef4c40_422dd9cd_2c7d33e8 Analysis symbol: Rechecking for solution: 0 Report Id: e2538b40-b1ef-4c3f-a19d-286361fe536d Report Status: 268435456 Hashed bucket: 4b39c1e8d82872d1af98a4a69dac8e628/16/2017 9:53 PM Windows Error Reporting Fault bucket 120796282341, type 4 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: dwm.exe P2: 10.0.15063.0 P3: 982d0cc7 P4: dwmcore.dll P5: 10.0.15063.483 P6: 460f87da P7: c0000005 P8: 00000000000d6670 P9: P10: Attached files: \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5197.tmp.WERInternalMetadata.xml These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_dwm.exe_23cfb1be8d2daa5691af1d2d7ffc6d69732f89_9adbe171_27c456a8 Analysis symbol: Rechecking for solution: 0 Report Id: 62da2a6c-e06a-4942-b1e5-09d86320abd1 Report Status: 268435456 Hashed bucket: 574401dcfe9d4bb238a778dcc20e91878/16/2017 9:53 PM Windows Error Reporting Fault bucket , type 0 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: dwm.exe P2: 10.0.15063.0 P3: 982d0cc7 P4: dwmcore.dll P5: 10.0.15063.483 P6: 460f87da P7: c0000005 P8: 00000000000d6670 P9: P10: Attached files: These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_dwm.exe_23cfb1be8d2daa5691af1d2d7ffc6d69732f89_9adbe171_10e44fa3 Analysis symbol: Rechecking for solution: 0 Report Id: 62da2a6c-e06a-4942-b1e5-09d86320abd1 Report Status: 4 Hashed bucket: 8/16/2017 9:57 PM Application Error Faulting application name: NVIDIA Share.exe, version: 59.3071.1634.2, time stamp: 0x5978c893 Faulting module name: libcef.dll, version: 3.3071.1634.0, time stamp: 0x59498c26 Exception code: 0xc0000005 Fault offset: 0x01df0a00 Faulting process id: 0xfac Faulting application start time: 0x01d316daa7faa9fa Faulting application path: C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe Faulting module path: C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll Report Id: 6088b033-ff5c-4177-add1-546f61200259 Faulting package full name: Faulting package-relative application ID:8/16/2017 9:55 PM Application Error Faulting application name: RocketLeague.exe, version: 1.0.10897.0, time stamp: 0x59656779 Faulting module name: RocketLeague.exe, version: 1.0.10897.0, time stamp: 0x59656779 Exception code: 0xc0000005 Fault offset: 0x000fb411 Faulting process id: 0x2be8 Faulting application start time: 0x01d316da532e446e Faulting application path: C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe Faulting module path: C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe Report Id: d8069970-da3b-4505-aa21-2a7a54b2978e Faulting package full name: Faulting package-relative application ID:8/16/2017 9:54 PM Application Error Faulting application name: RocketLeague.exe, version: 1.0.10897.0, time stamp: 0x59656779 Faulting module name: MSVCR100.dll, version: 10.0.40219.325, time stamp: 0x4df2be1e Exception code: 0xc0000005 Fault offset: 0x00001ed7 Faulting process id: 0x2464 Faulting application start time: 0x01d316da243562ca Faulting application path: C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe Faulting module path: C:\Windows\SYSTEM32\MSVCR100.dll Report Id: e2538b40-b1ef-4c3f-a19d-286361fe536d Faulting package full name: Faulting package-relative application ID:8/16/2017 9:53 PM Application Error Faulting application name: dwm.exe, version: 10.0.15063.0, time stamp: 0x982d0cc7 Faulting module name: dwmcore.dll, version: 10.0.15063.483, time stamp: 0x460f87da Exception code: 0xc0000005 Fault offset: 0x00000000000d6670 Faulting process id: 0x474 Faulting application start time: 0x01d316d97801985d Faulting application path: C:\Windows\system32\dwm.exe Faulting module path: C:\Windows\system32\dwmcore.dll Report Id: 62da2a6c-e06a-4942-b1e5-09d86320abd1 Faulting package full name: Faulting package-relative application ID:[/quote]
     
    zbook, Aug 16, 2017
    #39
  10. Since memtest passed and every bsod dump show memory_corruption without showing specific drivers as cause, i recommend to have an focus on disk drives and disk controller drivers.

    Can you provide us with the kernel memory dump please? Its located in C:\Windows\MEMORY.DMP.
    You can upload it to an cloud service like dropbox or onedrive.
     
    BSODHunter, Aug 16, 2017
    #40
  11. zbook New Member
    1) run one of the SMART tests on your drives:

    a) CrystalDiskInfo - Software - Crystal Dew World:
    Download Center - Crystal Dew World
    CrystalDiskMark - Software - Crystal Dew World
    Software - Crystal Dew World

    b) HD Tune: HD Tune website

    c) Hard Disk Sentinel - HDD health and temperature monitoring: Hard Disk Sentinel - HDD health and temperature monitoring

    2) When the SMART test has completed open the Microsoft snipping tool and make images of the results to post into the thread.
    Take Screenshot in Windows 10 Windows 10 General Tips Tutorials

    Check the health
    scan for errors, no quick scan but full scan
    run a benchmark.

    It may take some time, but please take the time you need to perform it properly.
    When above is done please make screenshots of the following
    the health,
    the error scan,
    the benchmark incl. following
    transfer rate,
    access time,
    burst rate,
    cpu usage.
    Take Screenshot in Windows 10 Windows 10 General Tips Tutorials

    3) Run Sea tools for windows on your drive using SMART, short and long generic tests:

    How to use SeaTools for Windows
    http://www.seagate.com/support/downl...ls-win-master/
    How to use SeaTools for Windows
    http://www.seagate.com/support/downloads/seatools/
     
    zbook, Aug 17, 2017
    #41
  12. Chris95 Win User
    Hello, Mister! I had the EXACT same problem as you caused by ntoskrnl.exe, shown in whocrashed.
    Found your thread on Google just 2days back and found myself a fix for it.
    - Fix? FAULTY/NOT SUPPORTED RAM BRICKS! HARDWARE!

    The chaos all started when I first upgraded from DDR3 8GB (1866mhz - bios shows 1333 for some reason though?) to DDR3 16GB (1600mhz). Crashes, BSODs and lots of unusual glitches. THEN I upgraded my gpu from Radeons 7950 to GTX1080 and got myself some significant performance boosts on my rig, but the crashes and glitches still persisted.

    I tried reformatting clean windows 10 several times. At first I was sure it was because of my drivers, but it all worked out great after I changed my ram back to the old ones. (8GB, 4gb on each, 2sticks) Now I can FINALLY play games with my friends in piece.

    MY SETUP

    Motherboard: P8H61-I LX R2.0
    CPU: i7-3770 (non-k)
    GPU: GTX 1080
    PSU: 600w

    Hope my solution gets you the same benefits as I did.
    - Chris
     
    Chris95, Aug 18, 2017
    #42
  13. cemarv25 Win User

    Constant BSODs caused by ntoskrnl.exe

    I don't think so
    I uploaded an image with all of these, and got no errors, nor bad health results.
    Could this actually be an option? I don't see any of the Team Vulcan 32GB (8Gx4) kits, and the tests I ran with memtest were 16GB and then 16GB.
     
    cemarv25, Aug 18, 2017
    #43
  14. zbook New Member
    Please confirm that windows defender is on and post the results into the thread.
    Please post images of the 3 antivirus scans from post #37.
    Perform windows updates and post any failed KB# with error code.
    Open file explorer > this PC > local C: drive and scan for mwac.sys then post an image of the results into the thread.



    Code: BugCheck C4, {2000, fffff80d8584a25c, 0, 444c534b}*** WARNING: Unable to verify timestamp for MpKsla9c5b15e.sys*** ERROR: Module load completed but symbols could not be loaded for MpKsla9c5b15e.sysProbably caused by : MpKsla9c5b15e.sys ( MpKsla9c5b15e+a25c )[/quote] Code: MpKsla9c5b15 MpKsla9c5b15e MpKsla9c5b15e Kernel System Running OK TRUE FALSE 8,192 16,384 0 5/19/2015 7:50:37 PM \??\C:\ProgramData\Microsoft\Windows Defender\De 8,192[/quote] mwac.sys Malwarebytes Web Access Control
    If it's blamed in a BSOD, it may be due to an outdated version of BitDefender 2016. Ensure that BitDefender is updated to the latest version. Fix came out around 02 July 2016 Support: Welcome | Official Malwarebytes Support
    Download: Free Cyber Security & Anti-Malware Software
    Code: 8/17/2017 9:41 PM Application Error Faulting application name: mbamservice.exe, version: 3.1.0.479, time stamp: 0x58f6af02 Faulting module name: ScanControllerImpl.dll, version: 3.0.0.715, time stamp: 0x593eed6b Exception code: 0xc0000005 Fault offset: 0x00000000000d558c Faulting process id: 0xd28 Faulting application start time: 0x01d316df7f1a4fbd Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe Faulting module path: C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\ScanControllerImpl.dll Report Id: 5d7c6d17-fcd5-44f5-b6ad-26716afe77fb Faulting package full name: Faulting package-relative application ID:[/quote] MpKsla51ccaa0.sys May be dynamic update driver for Microsoft Security Essentials Unknown driver from this post: http://www.sevenforums.com/crashes-d...-problems.html or Windows Update MpKsla9247ba8.sys May be dynamic update driver for Microsoft Security Essentials Unknown driver from this post: http://www.techsupportforum.com/foru...38-550287.html or Windows Update MpKslaab054de.sys May be dynamic update driver for Microsoft Security Essentials Unknown driver from this post: http://www.sevenforums.com/crashes-d...-7-32-bit.html or Windows Update

    Code: 8/18/2017 8:38 PM Windows Error Reporting Fault bucket , type 0 Event Name: StoreAgentScanForUpdatesFailure0 Response: Not available Cab Id: 0 Problem signature: P1: Update; P2: 8024402c P3: 15063 P4: 540 P5: Windows.Desktop P6: P7: P8: P9: P10: Attached files: These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Update;_85f6442782cd14381fecacea6b41bdc96cee5cfc_00000000_1e430c55 Analysis symbol: Rechecking for solution: 0 Report Id: 9d9a19f5-9c91-40e8-989e-74e245569b23 Report Status: 4 Hashed bucket:8/18/2017 8:38 PM Windows Error Reporting Fault bucket , type 0 Event Name: WindowsUpdateFailure3 Response: Not available Cab Id: 0 Problem signature: P1: 10.0.15063.502 P2: 8024402c P3: 00000000-0000-0000-0000-000000000000 P4: Scan P5: 0 P6: 0 P7: 8024500b P8: Update;taskhostw P9: {855E8A7C-ECB4-4CA3-B045-1DFA50104289} P10: 0 Attached files: These files may be available here: Analysis symbol: Rechecking for solution: 0 Report Id: d42f51be-11c5-4680-8610-b6ba8b83f2a8 Report Status: 1074003968 Hashed bucket:8/18/2017 8:38 PM Windows Error Reporting Fault bucket , type 0 Event Name: WindowsUpdateFailure3 Response: Not available Cab Id: 0 Problem signature: P1: 10.0.15063.502 P2: 8024402c P3: 00000000-0000-0000-0000-000000000000 P4: Scan P5: 0 P6: 0 P7: 8024500b P8: Update;taskhostw P9: {855E8A7C-ECB4-4CA3-B045-1DFA50104289} P10: 0 Attached files: These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_10.0.15063.502_e9f44ee9b7ed7ed27cdd8f1edd669f1138b45aa7_00000000_1f6f0c55 Analysis symbol: Rechecking for solution: 0 Report Id: d42f51be-11c5-4680-8610-b6ba8b83f2a8 Report Status: 4 Hashed bucket:8/18/2017 9:59 PM Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: d1 P2: fffff8e3ee98fcf4 P3: 2 P4: 0 P5: fffff803ee98329f P6: 10_0_15063 P7: 0_0 P8: 256_1 P9: P10: Attached files: \\?\C:\Windows\Minidump\081817-18375-01.dmp \\?\C:\Windows\Temp\WER-19046-0.sysdata.xml \\?\C:\Windows\MEMORY.DMP \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5582.tmp.WERInternalMetadata.xml \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER55B1.tmp.csv \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER55C2.tmp.txt These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_d1_3987895aad6d28fea131cf166cafb2f17aa9f1_00000000_cab_226457d4 Analysis symbol: Rechecking for solution: 0 Report Id: 6d42f781-8e8c-45ea-8d60-dbdb62aa9c56 Report Status: 2049 Hashed bucket:8/18/2017 9:59 PM Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: d1 P2: fffff8e3ee98fcf4 P3: 2 P4: 0 P5: fffff803ee98329f P6: 10_0_15063 P7: 0_0 P8: 256_1 P9: P10: Attached files: \\?\C:\Windows\Minidump\081817-18375-01.dmp \\?\C:\Windows\Temp\WER-19046-0.sysdata.xml \\?\C:\Windows\MEMORY.DMP \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER5582.tmp.WERInternalMetadata.xml \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER55B1.tmp.csv \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER55C2.tmp.txt These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_d1_3987895aad6d28fea131cf166cafb2f17aa9f1_00000000_035455c1 Analysis symbol: Rechecking for solution: 0 Report Id: 6d42f781-8e8c-45ea-8d60-dbdb62aa9c56 Report Status: 4 Hashed bucket:[/quote]
    Code: Event[10912]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2017-08-18T15:58:50.689 Event ID: 35 Task: N/A Level: Error Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: Performance power management features on processor 11 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.[/quote] Code: Event[10848]: Log Name: System Source: Microsoft-Windows-Time-Service Date: 2017-08-18T14:51:45.769 Event ID: 158 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: DESKTOP-N44VCA9 Description: The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.[/quote] Code: Event[10829]: Log Name: System Source: Microsoft-Windows-StartupRepair Date: 2017-08-18T14:35:07.812 Event ID: 1002 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: Startup Repair failed. Event[10830]: Log Name: System Source: Microsoft-Windows-StartupRepair Date: 2017-08-18T14:35:07.812 Event ID: 1123 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: Windows was unable to determine the problem. Error code: 0xc4 Event[10831]: Log Name: System Source: Microsoft-Windows-StartupRepair Date: 2017-08-18T14:35:07.812 Event ID: 1208 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: DESKTOP-N44VCA9 Description: Restored system to an earlier restore point.[/quote] Code: Event[10708]: Log Name: System Source: Service Control Manager Date: 2017-08-17T16:47:00.575 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: DESKTOP-N44VCA9 Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading[/quote] Code: Event[10704]: Log Name: System Source: Service Control Manager Date: 2017-08-17T16:46:59.951 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: DESKTOP-N44VCA9 Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading[/quote] Code: Event[10700]: Log Name: System Source: Service Control Manager Date: 2017-08-17T16:46:59.930 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: DESKTOP-N44VCA9 Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading[/quote] Code: Event[10696]: Log Name: System Source: Service Control Manager Date: 2017-08-17T16:46:59.888 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: DESKTOP-N44VCA9 Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading[/quote]
     
    zbook, Aug 18, 2017
    #44
  15. cemarv25 Win User
    I think everything is on the screenshot. If not, tell me. Do I click on clean the threats, or are they something I could need?
    Attachment 149625
     
    cemarv25, Aug 19, 2017
    #45
Thema:

Constant BSODs caused by ntoskrnl.exe

Loading...
  1. Constant BSODs caused by ntoskrnl.exe - Similar Threads - Constant BSODs caused

  2. Constant BSOD by Ntoskrnl?

    in Windows 10 Gaming
    Constant BSOD by Ntoskrnl?: I am having constant blue screenheres the things ive already done to fix it uninstall display drivers and reinstalclean install of windows 11 24h2run memtest and passed all 4 run driver verifier Im thinking its one of my driver but i dont know which so im uploading them here...
  3. Constant BSOD by Ntoskrnl?

    in Windows 10 Software and Apps
    Constant BSOD by Ntoskrnl?: I am having constant blue screenheres the things ive already done to fix it uninstall display drivers and reinstalclean install of windows 11 24h2run memtest and passed all 4 run driver verifier Im thinking its one of my driver but i dont know which so im uploading them here...
  4. BSOD caused by ntoskrnl

    in Windows 10 Gaming
    BSOD caused by ntoskrnl: Struggling with frequent BSODs on my PC lately. I've found the cause to be ntoskrnl.exe but couldn't figure out anything besides that. Appreciate any help on this.HERE's the link dump files here:...
  5. BSOD caused by ntoskrnl

    in Windows 10 Software and Apps
    BSOD caused by ntoskrnl: Struggling with frequent BSODs on my PC lately. I've found the cause to be ntoskrnl.exe but couldn't figure out anything besides that. Appreciate any help on this.HERE's the link dump files here:...
  6. Constant BSOD ntoskrnl

    in Windows 10 Gaming
    Constant BSOD ntoskrnl: Hello,I have an issue where I am constantly getting BSODs. I have reformatted and clean installed Windows.During boot, the laptop goes through one or two BSODs before finally being able to log in to Windows. Oddly enough, when gaming or playing video files, the system will...
  7. Constant BSOD ntoskrnl

    in Windows 10 Software and Apps
    Constant BSOD ntoskrnl: Hello,I have an issue where I am constantly getting BSODs. I have reformatted and clean installed Windows.During boot, the laptop goes through one or two BSODs before finally being able to log in to Windows. Oddly enough, when gaming or playing video files, the system will...
  8. Constant BSOD ntoskrnl

    in Windows 10 BSOD Crashes and Debugging
    Constant BSOD ntoskrnl: Hello,I have an issue where I am constantly getting BSODs. I have reformatted and clean installed Windows.During boot, the laptop goes through one or two BSODs before finally being able to log in to Windows. Oddly enough, when gaming or playing video files, the system will...
  9. BSOD ntoskrnl..exe

    in Windows 10 BSOD Crashes and Debugging
    BSOD ntoskrnl..exe: My computer has crashed a few times often when i play games. I bought more ram because i thought that it was the issue but it didn't help. It did work a few days but then the crashes came back. After that i fixed the BSOD´s by lowering the graphics and the resolution on the...
  10. BSOD ntoskrnl..exe+1b35e0

    in Windows 10 BSOD Crashes and Debugging
    BSOD ntoskrnl..exe+1b35e0: Help. Getting 4-5 of these a day. Running latest Windows 10 Pro, Xibo signboard, Docker with Xibo server. Always the same 'Caused By Address'. Put in new memory, ran memory test, no errors, all drivers up to date. Change disk type to AHCA, made sure windows driver was...
Tags:

Users found this page by searching for:

  1. amdpsp.sys driver verifier violation