BSOD on startup every day - Trying to identify specific causation

YELDUR 1 Reputation point
2021-10-15T13:38:02.73+00:00

Hi all,

For the past week or so I've been experiencing BSODs whenever I power on the computer first during the day; after we REACH the Windows splash screen, I have no further issues, even when restarting.

rom reviewing the Event Logs I can see one in there stating the following:

"The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly."
followed closely by:
"The driver \Driver\WudfRd failed to load for the device PCI\VEN_5853&DEV_1003\1&1a590e2c&0&03."

So far as far as causation goes, this is the only thing throwing flags, as I've successfully performed Windows Memory Diagnostics with no issues being found, system file checks with no corruption being found, and lastly checking in on the device manager and checking all tabs to ensure nothing in there is throwing errors. As far as I can tell, these issues began this week.

I know that this week I plugged in a new keyboard that is different to that of my old one, and in doing so I needed to download some more drivers for it, however I went from a Roccat Aimo 120 to a Roccat Aimo 100, to which the only real difference is the fact that the 100 doesn't have a hand wrest with the keyboard. Besides that, it doesn't appear any different specification wise, so I'm unclear on whether this is the cause. I also changed my power plan on the rig from Balanced to Performance, though I don't expect this to be the cause.

Originally I believed perhaps that drivers were the issue, however, now I'm not so sure.

To cut a long story short, I ran a bugcheck analysis using the Windows Debug tools which threw me the following:

12: kd> !analyze -v
***

    *
    Bugcheck Analysis *
    *

***

MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041792, A corrupt PTE has been detected. Parameter 2 contains the address of
the PTE. Parameters 3/4 contain the low/high parts of the PTE.
Arg2: ffff83816716da08
Arg3: 0000800000000000
Arg4: 0000000000000000

Debugging Details:
------------------


KEY_VALUES_STRING: 1

Key : Analysis.CPU.mSec
Value: 3249

Key : Analysis.DebugAnalysisManager
Value: Create

Key : Analysis.Elapsed.mSec
Value: 10478

Key : Analysis.Init.CPU.mSec
Value: 1249

Key : Analysis.Init.Elapsed.mSec
Value: 65592

Key : Analysis.Memory.CommitPeak.Mb
Value: 73

Key : MemoryManagement.PFN
Value: 800000000

Key : WER.OS.Branch
Value: vb_release

Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z

Key : WER.OS.Version
Value: 10.0.19041.1


BUGCHECK_CODE: 1a

BUGCHECK_P1: 41792

BUGCHECK_P2: ffff83816716da08

BUGCHECK_P3: 800000000000

BUGCHECK_P4: 0

MEMORY_CORRUPTOR: ONE_BIT

BLACKBOXNTFS: 1 (!blackboxntfs)


CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: autochk.exe

STACK_TEXT:
ffff988d4679f388 fffff8054624423a : 000000000000001a 0000000000041792 ffff83816716da08 0000800000000000 : nt!KeBugCheckEx
ffff988d4679f390 fffff80546242a6f : ffff8688b7883700 0000000000000000 ffff868800000002 0000000000000000 : nt!MiDeleteVa+0x153a
ffff988d4679f490 fffff80546212c10 : 0000000000000001 ffff988d00000000 ffff8688b7883550 ffff8688b7910080 : nt!MiDeletePagablePteRange+0x48f
ffff988d4679f7a0 fffff80546252277 : 000000002ce2db4f 0000000000000000 ffff868800000000 fffff80500000000 : nt!MiDeleteVad+0x360
ffff988d4679f8b0 fffff805465f908c : ffff988d00000000 0000000000000000 ffff988d4679fa10 000002ce2db30000 : nt!MiFreeVadRange+0xa3
ffff988d4679f910 fffff805465f8b65 : 00007ff70784b980 000002ce44f49e50 ffff988d4679fad8 0000000000000000 : nt!MmFreeVirtualMemory+0x4ec
ffff988d4679fa60 fffff80546408bb8 : ffff8688b7910080 ffff868800000001 0000000000000000 ffff868800000000 : nt!NtFreeVirtualMemory+0x95
ffff988d4679fac0 00007ffa4676d134 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!KiSystemServiceCopyEnd+0x28
000000e2f757a4b8 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : 0x00007ffa`4676d134


MODULE_NAME: hardware

IMAGE_NAME: memory_corruption

STACK_COMMAND: .thread ; .cxr ; kb

FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT

OS_VERSION: 10.0.19041.1

BUILDLAB_STR: vb_release

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {e3faf315-c3d0-81db-819a-6c43d23c63a7}

Followup: MachineOwner

I work in tech, but I am by no means a master, and to be frank, I don't know what I'm reading here. I can gather that it is telling me that there's something wrong with memory, in that it's seeing corruption, but other than that I'm honestly not too sure.

Here's the event log that prompted me finding these issues:

Event ID 1001

The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001a (0x0000000000041792, 0xffff83816716da08, 0x0000800000000000, 0x0000000000000000). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 15812135-3f48-42c4-b474-5b9fd5a5cf7e.

If there's any more information required, please don't hesitate to ask and I will do my best to gather it for you.

Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments

71 answers

Sort by: Most helpful
  1. Docs 16,871 Reputation points
    2021-10-25T02:32:17.403+00:00

    Okay.

    When possible:

    a) flash the BIOS
    b) clean ports and fans > monitor temperatures
    c) view the owners manual to see if there are optimal DIMM slots when using only one RAM module
    d) test one RAM module at a time in the same DIMM
    e) if one works without crashes then test all DIMM with the same RAM module
    f) the above may be able to rule in / rule out malfunctioning RAM and or motherboard
    g) if there are no further misbehaving drivers then the focus is on hardware
    (any additional debugging is just to make sure there are no further misbehaving drivers)
    h) make free backup images (once you're familiar with the product you can decide whether to pay for the software enhancements in the different versions)

    Temperatures can be monitored with Speccy, HW Monitor, or SpeedFan

    Unexpected shutdowns should be seen with a :( window.
    Sometimes there can be missed shutdowns so also use:
    https://www.howtogeek.com/166911/reliability-monitor-is-the-best-windows-troubleshooting-tool-you-arent-using/

    .
    .
    .
    .
    .
    Please remember to vote and to mark the replies as answers if they help.

    On the bottom of each post there is:

    Propose as answer = answered the question

    On the left side of each post: Vote = a helpful post
    .
    .
    .
    .
    .

    Was this answer helpful?

    1 person found this answer helpful.

  2. Docs 16,871 Reputation points
    2021-10-25T01:57:05.917+00:00

    The free time over the next few weeks is unpredictable.

    The week of Nov 1 will be much busier than this coming week.

    The following week at this moment is unknown but there are are many tasks before the upcoming holiday weeks.

    So I can plan to troubleshoot any time but it may need to be adjusted.

    Use this link to make free or pay backup images:

    https://www.tenforums.com/tutorials/61026-backup-restore-macrium-reflect.html

    .
    .
    .
    .
    .
    Please remember to vote and to mark the replies as answers if they help.

    On the bottom of each post there is:

    Propose as answer = answered the question

    On the left side of each post: Vote = a helpful post
    .
    .
    .
    .
    .

    Was this answer helpful?

    1 person found this answer helpful.

  3. Docs 16,871 Reputation points
    2021-10-25T01:13:54.037+00:00

    All overclocks should be returned to stock when troubleshooting.

    Overclocks can be a common cause of unexpected shutdowns and restarts.

    In addition high temperatures are another cause of unexpected shutdowns and restarts.

    So both of these should be addressed before the troubleshooting of drivers and hardware.

    I'll have more time than I had expected for some days this coming week.

    The following week I'll be much busier.

    If you can post V2 and memory dumps then I''ll be able to debug them when there is time.

    Most of the troubleshooting that you cannot do will be completed (debugging dump files) soon.

    For the hardware you must rule in or rule out RAM and motherboard.

    RAM modules can be tested one at a time in the same DIMM.

    If only one causes unexpected shutdowns and restarts then you've found the culprit.

    If both when tested one at a time cause unexpected shutdowns and restarts then you still need to continue testing RAM and motherboard.

    There are multiple websites that are related to overclocking.

    Once the troubleshooting has completed you can open a thread in one of them for BIOS settings.

    But you'll want at least two weeks (the more the better) of documented computer stability before overclocking.

    .
    .
    .
    .
    .
    Please remember to vote and to mark the replies as answers if they help.

    On the bottom of each post there is:

    Propose as answer = answered the question

    On the left side of each post: Vote = a helpful post
    .
    .
    .
    .
    .

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  4. YELDUR 1 Reputation point
    2021-10-17T03:20:09.403+00:00

    For the reference of Docs, here is what the testing suggests thus far:

    1)

    Microsoft Windows [Version 10.0.19042.1288]
    (c) Microsoft Corporation. All rights reserved.
    
    C:\WINDOWS\system32>sfc /scannow
    
    Beginning system scan.  This process will take some time.
    
    Beginning verification phase of system scan.
    Verification 100% complete.
    
    Windows Resource Protection did not find any integrity violations.
    
    C:\WINDOWS\system32>dism /online /cleanup-image /restorehealth
    
    Deployment Image Servicing and Management tool
    Version: 10.0.19041.844
    
    Image Version: 10.0.19042.1288
    
    [==========================100.0%==========================] The restore operation completed successfully.
    The operation completed successfully.
    

    2)

    Microsoft Windows [Version 10.0.19042.1288]
    (c) Microsoft Corporation. All rights reserved.
    
    C:\WINDOWS\system32>wmic recoveros set autoreboot = false
    Updating property(s) of '\\DESKTOP-DSA3D75\ROOT\CIMV2:Win32_OSRecoveryConfiguration.Name="Microsoft Windows 10 Home|C:\\WINDOWS|\\Device\\Harddisk0\\Partition4"'
    Property(s) update successful.
    
    C:\WINDOWS\system32>wmic recoveros set debuginfotype = 7
    Updating property(s) of '\\DESKTOP-DSA3D75\ROOT\CIMV2:Win32_OSRecoveryConfiguration.Name="Microsoft Windows 10 Home|C:\\WINDOWS|\\Device\\Harddisk0\\Partition4"'
    Property(s) update successful.
    
    C:\WINDOWS\system32>wmic recoveros get autoreboot
    AutoReboot
    FALSE
    
    
    C:\WINDOWS\system32>wmic recoveros get debuginfotype
    DebugInfoType
    7
    
    
    C:\WINDOWS\system32>wmic computersystem where name=%computername% set automaticmanagedpagefile=true
    Unexpected switch at this level.
    
    C:\WINDOWS\system32>wmic computersystem where name=%computername% get automaticmanagedpagefile
    Unexpected switch at this level.
    
    C:\WINDOWS\system32>bcdedit /enum {badmemory}
    
    RAM Defects
    -----------
    identifier        {badmemory}
    
    C:\WINDOWS\system32>powercfg -h off
    
    C:\WINDOWS\system32>
    

    3) (No results for C: yet as it obviously can't dismount the volume the OS is on, so as you suggested this will run on next boot)

    C:\WINDOWS\system32>chkdsk /r /v d:
    The type of the file system is NTFS.
    
    Chkdsk cannot run because the volume is in use by another
    process.  Chkdsk may run if this volume is dismounted first.
    ALL OPENED HANDLES TO THIS VOLUME WOULD THEN BE INVALID.
    Would you like to force a dismount on this volume? (Y/N) y
    Volume dismounted.  All opened handles to this volume are now invalid.
    Volume label is Games/Other.
    
    Stage 1: Examining basic file system structure ...
      329472 file records processed.
    File verification completed.
     Phase duration (File record verification): 1.21 seconds.
      41 large file records processed.
     Phase duration (Orphan file record recovery): 0.00 milliseconds.
      0 bad file records processed.
     Phase duration (Bad file record checking): 0.49 milliseconds.
    
    Stage 2: Examining file name linkage ...
      1341 reparse records processed.
      362248 index entries processed.
    Index verification completed.
     Phase duration (Index verification): 1.97 seconds.
      0 unindexed files scanned.
     Phase duration (Orphan reconnection): 45.95 milliseconds.
      0 unindexed files recovered to lost and found.
     Phase duration (Orphan recovery to lost and found): 0.44 milliseconds.
      1341 reparse records processed.
     Phase duration (Reparse point and Object ID verification): 4.45 milliseconds.
    
    Stage 3: Examining security descriptors ...
    Cleaning up 24 unused index entries from index $SII of file 9.
    Cleaning up 24 unused index entries from index $SDH of file 9.
    Cleaning up 24 unused security descriptors.
    Security descriptor verification completed.
     Phase duration (Security descriptor verification): 1.49 milliseconds.
      16389 data files processed.
     Phase duration (Data attribute verification): 0.19 milliseconds.
    CHKDSK is verifying Usn Journal...
      37990192 USN bytes processed.
    Usn Journal verification completed.
     Phase duration (USN journal verification): 53.12 milliseconds.
    
    Stage 4: Looking for bad clusters in user file data ...
      329456 files processed.
    File data verification completed.
     Phase duration (User file recovery): 10.75 minutes.
    
    Stage 5: Looking for bad, free clusters ...
      25776148 free clusters processed.
    Free space verification is complete.
     Phase duration (Free space recovery): 0.00 milliseconds.
    
    Windows has scanned the file system and found no problems.
    No further action is required.
    
     976744447 KB total disk space.
     873086000 KB in 283880 files.
        91064 KB in 16390 indexes.
         0 KB in bad sectors.
        462787 KB in use by the system.
        65536 KB occupied by the log file.
     103104596 KB available on disk.
    
       4096 bytes in each allocation unit.
     244186111 total allocation units on disk.
      25776149 allocation units available on disk.
    Total duration: 10.80 minutes (648543 ms).
    

    Was this answer helpful?

    0 comments No comments

  5. YELDUR 1 Reputation point
    2021-10-16T11:47:09.263+00:00

    Hi everyone,

    I have booted up the machine today and was not met with a BSOD, or a repair, however, the machine did reboot from a bugcheck just like before, I've gathered the MiniDump file like before and am posting it here:

    0: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    INTERNAL_POWER_ERROR (a0)
    The power policy manager experienced a fatal error.
    Arguments:
    Arg1: 000000000000010e, The disk subsystem returned corrupt data while reading from the
     hibernation file.
    Arg2: 000000000000000a
    Arg3: 000000000000f794, Incorrect checksum
    Arg4: 000000000000e2f1, Previous disk read's checksum
    
    Debugging Details:
    ------------------
    
    
    KEY_VALUES_STRING: 1
    
        Key  : Analysis.CPU.mSec
        Value: 2265
    
        Key  : Analysis.DebugAnalysisManager
        Value: Create
    
        Key  : Analysis.Elapsed.mSec
        Value: 6154
    
        Key  : Analysis.Init.CPU.mSec
        Value: 608
    
        Key  : Analysis.Init.Elapsed.mSec
        Value: 80411
    
        Key  : Analysis.Memory.CommitPeak.Mb
        Value: 70
    
    
    DUMP_FILE_ATTRIBUTES: 0x9
      Hiber Crash Dump
      Kernel Generated Triage Dump
    
    BUGCHECK_CODE:  a0
    
    BUGCHECK_P1: 10e
    
    BUGCHECK_P2: a
    
    BUGCHECK_P3: f794
    
    BUGCHECK_P4: e2f1
    
    CUSTOMER_CRASH_COUNT:  1
    
    STACK_TEXT:  
    ffff9806`717a7608 fffff805`2f9a13d4     : 00000000`000000a0 00000000`0000010e 00000000`0000000a 00000000`0000f794 : nt!KeBugCheckEx
    ffff9806`717a7610 fffff805`2f9aebf1     : 00000000`00000001 ffffd208`fc959a90 00000005`c1b61000 ffffd209`41c3e000 : nt!PopHiberChecksumHiberFileData+0x10784
    ffff9806`717a7670 fffff805`2f9a09ad     : 00000000`00000000 ffffe584`ac235f38 00000000`00000001 00000000`00000001 : nt!PopRequestRead+0x7d
    ffff9806`717a76e0 fffff805`2f98fde0     : 0000b461`8930c9e4 ffffe584`ac235f38 00000000`00000000 00000000`00000000 : nt!PopRestoreHiberContext+0x10a75
    ffff9806`717a7770 fffff805`2f98fb1e     : fffff805`2fc503a0 ffff9806`717a78f0 fffff805`2fc503a0 00000000`00000100 : nt!PopHandleNextState+0x210
    ffff9806`717a77c0 fffff805`2f98f89b     : 00000000`00000100 fffff805`2fc503a0 00000079`80c46556 00000000`00989680 : nt!PopIssueNextState+0x1a
    ffff9806`717a77f0 fffff805`2f992ba9     : ffff9806`717a7a00 00000000`00000018 00000000`00000000 fffff805`2f99292f : nt!PopInvokeSystemStateHandler+0x33b
    ffff9806`717a79f0 fffff805`2f99263a     : ffffffff`00000000 ffffffff`ffffffff 00000000`00000000 00000000`00000000 : nt!PopEndMirroring+0x1e9
    ffff9806`717a7ab0 fffff805`2f992325     : 00000000`00000000 00000000`00000000 00000000`00000001 00000000`00000000 : nt!MmDuplicateMemory+0x2be
    ffff9806`717a7b40 fffff805`2f355855     : ffffd209`031af000 ffffd209`031af040 fffff805`2f9921f0 00000000`00000001 : nt!PopTransitionToSleep+0x135
    ffff9806`717a7bd0 fffff805`2f3fe818     : ffff8081`a5200180 ffffd209`031af040 fffff805`2f355800 00000000`00000000 : nt!PspSystemThreadStartup+0x55
    ffff9806`717a7c20 00000000`00000000     : ffff9806`717a8000 ffff9806`717a1000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
    
    
    SYMBOL_NAME:  nt!PopHiberChecksumHiberFileData+10784
    
    MODULE_NAME: nt
    
    IMAGE_NAME:  ntkrnlmp.exe
    
    IMAGE_VERSION:  10.0.19041.1237
    
    STACK_COMMAND:  .thread ; .cxr ; kb
    
    BUCKET_ID_FUNC_OFFSET:  10784
    
    FAILURE_BUCKET_ID:  0xa0_10e_nt!PopHiberChecksumHiberFileData
    
    OSPLATFORM_TYPE:  x64
    
    OSNAME:  Windows 10
    
    FAILURE_ID_HASH:  {28ba2091-a476-6f77-2dec-6241bccd4685}
    
    Followup:     MachineOwner
    ---------
    

    On the bright side it appears different to that of what we've been seeing previously. I've ran another chkdsk on the C: and D: drives which discovered no issues at all.

    We have a couple more errors inside the Event Log, here they are in order (top comes first, bottom came last):

    Event ID 10029
    The activation of the CLSID Windows.Media.Capture.AppCaptureManager timed out waiting for the service BcastDVRUserService_4c8f0a2 to stop.

    Event ID 29

    Windows failed fast startup with error status 0xC0000001.

    Event ID 6008

    The previous system shutdown at 3:52:34 AM on 10/16/2021 was unexpected.

    Event ID 41

    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.

    Event ID 1001

    The computer has rebooted from a bugcheck. The bugcheck was: 0x000000a0 (0x000000000000010e, 0x000000000000000a, 0x000000000000f794, 0x000000000000e2f1). A dump was saved in: C:\WINDOWS\Minidump\101621-9000-01.dmp. Report Id: af119261-f2ed-4e8e-be4b-0c021838a51c.

    Event ID 10005

    DCOM got error "87" attempting to start the service GamingServices with arguments "Unavailable" in order to run the server:
    {3E8C9ABE-9226-4609-BF5B-60288A391DEE}

    No BSOD, but issues appear to be continuing even when loading up into a clean boot environment unfortunately, and after uninstalling Citrix.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.