[SOLVED] Sudden BSOD issue

There's actually a recent article at BC about a problem updating to 1903 with an older version of IRST installed so perhaps there's a related issue with the version of Windows 10 you're using.
 
Looking at the latest dump I see a quite old version of the Intel Rapid Storage Technology driver loading.
Code:
5: kd> lmDvm iaStorA
Browse full module list
start end module name
fffff808`5e160000 fffff808`5e6d4000 iaStorA (no symbols)
Loaded symbol image file: iaStorA.sys
Image path: iaStorA.sys
Image name: iaStorA.sys
Browse all global symbols functions data
Timestamp: Wed Nov 4 02:27:49 2015 (5639DDA5)
CheckSum: 00168F4C
ImageSize: 00574000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Information from resource tables:
I've seen a few systems having what seemed to be memory related bugchecks recently where the culprit was masked but updating (or uninstalling) IRST seemed to fix the issue. Is that a service you need on your system? I think it's only truly needed for a RAID setup. My systems seem to run fine without it.
Very nice find! I stopped using IRST a while back due to issues it was causing a couple years ago with some of my SSDs; one SSD was from Crucial and the OEM administrators at their forums recommended removal of IRST. I've had fewer problems all around by using the storage controller drivers Microsoft provides.
 
I'm far from certain it's the fix but hopefully it helps. This will be a good test case as I'm often not certain how closely my suggestions are followed but I'm pretty sure Tekno Venus knows what's what with a computer. ;)
 
All traces of IRST and iaStorA have been removed. No BSOD's yet, but Firefox is still crashing every few minutes along with other programs, so far from solved unfortunately :p By crashing, I mean either just completely quitting or individual tabs crashing. It's not just FF, Chrome does the same

2019-07-28 22_47_55-Window.png

I'm running 1809 at the moment as I put off updating during exam season as couldn't afford any downtime.
 
Last edited:
Also for app crashes - C:\ProgramData\Microsoft\Windows\WER\ReportQueue - contains directories that contain various pieces of info, sometimes dumps.

Example: From - C:\ProgramData\Microsoft\Windows\WER\ReportQueue

I selected this dir - C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.3.9600_17aa96dae3e6d924e4c9a705f9f93824d8ded6_00000000_cab_57b3be51

It contains 2 dumps -
Code:
Microsoft Windows [Version 6.3.9600]
(c) 2013 Microsoft Corporation. All rights reserved.

C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.3.9600_17aa96dae3e6d924e4c9a705f9f93824d8ded6_00000000_cab_57b3be51>dir /a /o:n
Volume in drive C is Windows 8.1 x64
Volume Serial Number is C8D9-F1EF

Directory of C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.3.9600_17aa96dae3e6d924e4c9a705f9f93824d8ded6_00000000_cab_57b3be51

07/20/2019  01:44 PM    <DIR>          .
07/20/2019 01:44 PM <DIR> ..
07/20/2019 01:18 PM 110,087,052 CBS.log
06/29/2019 12:29 PM 4,104,871 CbsPersist_20190629165342.cab
07/10/2019 02:29 PM 765,115 CbsPersist_20190710183640.cab
07/11/2019 12:31 AM 4,101,343 CbsPersist_20190711135710.cab
07/20/2019 10:18 AM 4,726,233 CbsPersist_20190720142530.cab
07/20/2019 10:39 AM 4,125,207 CbsPersist_20190720150922.cab
07/20/2019 01:44 PM 518 FilterList.log
07/20/2019 01:44 PM 49,716,975 [HI]memory.hdmp[/HI]
07/20/2019 01:44 PM 718,345 [HI]minidump.mdmp[/HI]
07/20/2019 10:17 AM 7,600 poqexec.log
07/20/2019 01:44 PM 5,834 Report.wer
03/15/2014 07:50 AM 5,210,112 SCM.EVM
07/20/2019 10:29 AM 30,963,088 Sessions.xml
13 File(s) 214,532,293 bytes
               2 Dir(s)  50,489,348,096 bytes free

There are also Report.wer files (clicking on them opens them in Notepads) in the other directory -

C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash__iu14D2N.tmp_8fb2d6c72a9fd4c1f15cfb9c5edb0b9231fb0_a1d345e9_24c5adf6\Report.wer

Report.wer
file:
Code:
Version=1
EventType=APPCRASH
EventTime=131924041992932251
ReportType=2
Consent=1
UploadTime=131924042019310019
ReportIdentifier=d9335b0b-1c2a-11e9-82ec-a01d48c2bd4c
IntegratorReportIdentifier=d9335b0a-1c2a-11e9-82ec-a01d48c2bd4c
WOW64=1
NsAppName=_iu14D2N.tmp
Response.BucketId=09c3a13158675406769e98421eb9184f
Response.BucketTable=1
Response.LegacyBucketId=109006035689
Response.type=4
Sig[0].Name=Application Name
Sig[0].Value=_iu14D2N.tmp
Sig[1].Name=Application Version
Sig[1].Value=51.1052.0.0
Sig[2].Name=Application Timestamp
Sig[2].Value=57051f89
Sig[3].Name=Fault Module Name
Sig[3].Value=IssSurvey.dll
Sig[4].Name=Fault Module Version
Sig[4].Value=1.0.0.98
Sig[5].Name=Fault Module Timestamp
Sig[5].Value=4797173c
Sig[6].Name=Exception Code
Sig[6].Value=c0000005
Sig[7].Name=Exception Offset
Sig[7].Value=00006e30
DynamicSig[1].Name=OS Version
DynamicSig[1].Value=6.3.9600.2.0.0.768.101
DynamicSig[2].Name=Locale ID
DynamicSig[2].Value=1033
DynamicSig[22].Name=Additional Information 1
DynamicSig[22].Value=899a
DynamicSig[23].Name=Additional Information 2
DynamicSig[23].Value=899a74453d769c6585c1516dfeece5d8
DynamicSig[24].Name=Additional Information 3
DynamicSig[24].Value=dbf1
DynamicSig[25].Name=Additional Information 4
DynamicSig[25].Value=dbf14711944dd56d90e71cb307fcd736
UI[2]=C:\Users\PALMDE~1\AppData\Local\Temp\_iu14D2N.tmp
LoadedModule[0]=C:\Users\PALMDE~1\AppData\Local\Temp\_iu14D2N.tmp
LoadedModule[1]=C:\Windows\SYSTEM32\ntdll.dll
LoadedModule[2]=C:\Windows\SYSTEM32\KERNEL32.DLL
LoadedModule[3]=C:\Windows\SYSTEM32\KERNELBASE.dll
LoadedModule[4]=C:\Windows\SYSTEM32\oleaut32.dll
LoadedModule[5]=C:\Windows\SYSTEM32\advapi32.dll
LoadedModule[6]=C:\Windows\SYSTEM32\user32.dll
LoadedModule[7]=C:\Windows\SYSTEM32\msimg32.dll
LoadedModule[8]=C:\Windows\SYSTEM32\gdi32.dll
LoadedModule[9]=C:\Windows\SYSTEM32\version.dll
LoadedModule[10]=C:\Windows\SYSTEM32\mpr.dll
LoadedModule[11]=C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.18006_none_a9ec6aab013aafee\comctl32.dll
LoadedModule[12]=C:\Windows\SYSTEM32\ole32.dll
LoadedModule[13]=C:\Windows\SYSTEM32\shell32.dll
LoadedModule[14]=C:\Windows\SYSTEM32\comdlg32.dll
LoadedModule[15]=C:\Windows\SYSTEM32\msvcrt.dll
LoadedModule[16]=C:\Windows\SYSTEM32\combase.dll
LoadedModule[17]=C:\Windows\SYSTEM32\RPCRT4.dll
LoadedModule[18]=C:\Windows\SYSTEM32\sechost.dll
LoadedModule[19]=C:\Windows\SYSTEM32\SHLWAPI.dll
LoadedModule[20]=C:\Windows\SYSTEM32\SspiCli.dll
LoadedModule[21]=C:\Windows\SYSTEM32\CRYPTBASE.dll
LoadedModule[22]=C:\Windows\SYSTEM32\SHCORE.DLL
LoadedModule[23]=C:\Windows\SYSTEM32\bcryptPrimitives.dll
LoadedModule[24]=C:\Windows\system32\IMM32.DLL
LoadedModule[25]=C:\Windows\SYSTEM32\MSCTF.dll
LoadedModule[26]=C:\Windows\system32\uxtheme.dll
LoadedModule[27]=C:\Windows\SYSTEM32\kernel.appcore.dll
LoadedModule[28]=C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll
LoadedModule[29]=C:\Windows\system32\dwmapi.dll
LoadedModule[30]=C:\Windows\SYSTEM32\oleacc.dll
LoadedModule[31]=C:\Windows\SYSTEM32\profapi.dll
LoadedModule[32]=C:\Windows\system32\shfolder.dll
LoadedModule[33]=C:\Program Files (x86)\Recover Keys\IssSurvey.dll
LoadedModule[34]=C:\Windows\SYSTEM32\WININET.DLL
LoadedModule[35]=C:\Windows\SYSTEM32\iertutil.dll
LoadedModule[36]=C:\Windows\SYSTEM32\USERENV.dll
State[0].Key=Transport.DoneStage1
State[0].Value=1
FriendlyEventName=Stopped working
ConsentKey=APPCRASH
AppName=Setup//Uninstall
AppPath=C:\Users\PALMDE~1\AppData\Local\Temp\_iu14D2N.tmp
NsPartner=windows
NsGroup=windows8
ApplicationIdentity=AC35E888B93D79BAFC2E821E0063C08D





Also, under your user profile - similar files exist -
C:\Users\PalmDesert\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_AdblockPlusEngin_12e491ebcb5f81fa780f295b23074fb84649288_b746278e_468a9cb8\Report.wer

Report.wer

Code:
Version=1
EventType=APPCRASH
EventTime=131411766907347710
ReportType=2
Consent=1
UploadTime=131411774553045721
ReportIdentifier=8194fa21-4a41-11e7-82cb-a01d48c2bd4c
IntegratorReportIdentifier=8194fa20-4a41-11e7-82cb-a01d48c2bd4c
NsAppName=AdblockPlusEngine.exe
Response.BucketId=50eab4e6c1561df4c712be6ad7f50c51
Response.BucketTable=4
Response.LegacyBucketId=120550140556
Response.type=4
Sig[0].Name=Application Name
Sig[0].Value=AdblockPlusEngine.exe
Sig[1].Name=Application Version
Sig[1].Value=1.5.0.0
Sig[2].Name=Application Timestamp
Sig[2].Value=56017eff
Sig[3].Name=Fault Module Name
Sig[3].Value=StackHash_ab84
Sig[4].Name=Fault Module Version
Sig[4].Value=6.3.9600.18438
Sig[5].Name=Fault Module Timestamp
Sig[5].Value=57ae642e
Sig[6].Name=Exception Code
Sig[6].Value=c0000374
Sig[7].Name=Exception Offset
Sig[7].Value=PCH_89_FROM_ntdll+0x0000000000090C6A
DynamicSig[1].Name=OS Version
DynamicSig[1].Value=6.3.9600.2.0.0.768.101
DynamicSig[2].Name=Locale ID
DynamicSig[2].Value=1033
DynamicSig[22].Name=Additional Information 1
DynamicSig[22].Value=ab84
DynamicSig[23].Name=Additional Information 2
DynamicSig[23].Value=ab847c21e47b716080259ab507c0740c
DynamicSig[24].Name=Additional Information 3
DynamicSig[24].Value=b372
DynamicSig[25].Name=Additional Information 4
DynamicSig[25].Value=b372b0941078f6af1c7c1e0a7a78f3bc
UI[2]=C:\Program Files\Adblock Plus for IE\AdblockPlusEngine.exe
UI[3]=Adblock Plus Engine for Internet Explorer has stopped working
UI[4]=Windows can check online for a solution to the problem.
UI[5]=Check online for a solution and close the program
UI[6]=Check online for a solution later and close the program
UI[7]=Close the program
LoadedModule[0]=C:\Program Files\Adblock Plus for IE\AdblockPlusEngine.exe
LoadedModule[1]=C:\Windows\SYSTEM32\ntdll.dll
LoadedModule[2]=C:\Windows\system32\KERNEL32.DLL
LoadedModule[3]=C:\Windows\system32\KERNELBASE.dll
LoadedModule[4]=C:\Windows\system32\ADVAPI32.dll
LoadedModule[5]=C:\Windows\system32\ole32.dll
LoadedModule[6]=C:\Windows\system32\USER32.dll
LoadedModule[7]=C:\Windows\system32\OLEAUT32.dll
LoadedModule[8]=C:\Windows\system32\GDI32.dll
LoadedModule[9]=C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.18592_none_933383bf47487fd6\gdiplus.dll
LoadedModule[10]=C:\Windows\system32\SHLWAPI.dll
LoadedModule[11]=C:\Windows\SYSTEM32\WINHTTP.dll
LoadedModule[12]=C:\Windows\SYSTEM32\WINMM.dll
LoadedModule[13]=C:\Windows\system32\msvcrt.dll
LoadedModule[14]=C:\Windows\SYSTEM32\sechost.dll
LoadedModule[15]=C:\Windows\system32\RPCRT4.dll
LoadedModule[16]=C:\Windows\SYSTEM32\combase.dll
LoadedModule[17]=C:\Windows\SYSTEM32\WINMMBASE.dll
LoadedModule[18]=C:\Windows\system32\SspiCli.dll
LoadedModule[19]=C:\Windows\SYSTEM32\cfgmgr32.dll
LoadedModule[20]=C:\Windows\SYSTEM32\DEVOBJ.dll
LoadedModule[21]=C:\Windows\system32\IMM32.DLL
LoadedModule[22]=C:\Windows\system32\MSCTF.dll
LoadedModule[23]=C:\Windows\system32\SHELL32.dll
LoadedModule[24]=C:\Windows\SYSTEM32\shcore.dll
LoadedModule[25]=C:\Windows\SYSTEM32\profapi.dll
LoadedModule[26]=C:\Windows\SYSTEM32\ntmarta.dll
LoadedModule[27]=C:\Windows\SYSTEM32\kernel.appcore.dll
LoadedModule[28]=C:\Windows\SYSTEM32\CRYPTBASE.dll
LoadedModule[29]=C:\Windows\SYSTEM32\bcryptPrimitives.dll
LoadedModule[30]=C:\Windows\system32\uxtheme.dll
LoadedModule[31]=C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
LoadedModule[32]=C:\Windows\system32\dwmapi.dll
LoadedModule[33]=C:\Windows\SYSTEM32\IPHLPAPI.DLL
LoadedModule[34]=C:\Windows\system32\NSI.dll
LoadedModule[35]=C:\Windows\SYSTEM32\WINNSI.DLL
LoadedModule[36]=C:\Windows\SYSTEM32\dhcpcsvc6.DLL
LoadedModule[37]=C:\Windows\system32\WS2_32.dll
LoadedModule[38]=C:\Windows\SYSTEM32\dhcpcsvc.DLL
LoadedModule[39]=C:\Windows\SYSTEM32\webio.dll
LoadedModule[40]=C:\Windows\system32\mswsock.dll
LoadedModule[41]=C:\Windows\SYSTEM32\DNSAPI.dll
LoadedModule[42]=C:\Windows\System32\rasadhlp.dll
LoadedModule[43]=C:\Windows\system32\schannel.DLL
LoadedModule[44]=C:\Windows\system32\CRYPT32.dll
LoadedModule[45]=C:\Windows\system32\MSASN1.dll
LoadedModule[46]=C:\Windows\SYSTEM32\ncrypt.dll
LoadedModule[47]=C:\Windows\SYSTEM32\bcrypt.dll
LoadedModule[48]=C:\Windows\SYSTEM32\NTASN1.dll
LoadedModule[49]=C:\Windows\system32\ncryptsslp.dll
LoadedModule[50]=C:\Windows\SYSTEM32\CRYPTSP.dll
LoadedModule[51]=C:\Windows\system32\rsaenh.dll
LoadedModule[52]=C:\Windows\SYSTEM32\gpapi.dll
LoadedModule[53]=C:\Windows\SYSTEM32\DPAPI.DLL
State[0].Key=Transport.DoneStage1
State[0].Value=1
FriendlyEventName=Stopped working
ConsentKey=APPCRASH
AppName=Adblock Plus Engine for Internet Explorer
AppPath=C:\Program Files\Adblock Plus for IE\AdblockPlusEngine.exe
NsPartner=windows
NsGroup=windows8
ApplicationIdentity=0960A2D82EC1F7D2F7D45C4A5E524FF7


Under C:\Users\PalmDesert\AppData\Local\Microsoft\Windows\WER\ReportQueue\AppHang_Microsoft.SkypeA_fd7bf545c465891a08a585239f1c97ed89a42c3_1a1e67db_cab_4c97a5b0

The following exists:
Code:
Microsoft Windows [Version 6.3.9600]
(c) 2013 Microsoft Corporation. All rights reserved.

C:\Users\PalmDesert\AppData\Local\Microsoft\Windows\WER\ReportQueue\AppHang_Microsoft.SkypeA_fd7bf545c465891a08a585239f1c97ed89a42c3_1a1e67db_cab_4c97a5b0>dir /a /o:n
Volume in drive C is Windows 8.1 x64
Volume Serial Number is C8D9-F1EF

Directory of C:\Users\PalmDesert\AppData\Local\Microsoft\Windows\WER\ReportQueue\AppHang_Microsoft.SkypeA_fd7bf545c465891a08a585239f1c97ed89a42c3_1a1e67db_cab_4c97a5b0

06/25/2019  03:24 PM    <DIR>          .
06/25/2019 03:24 PM <DIR> ..
06/25/2019 03:24 PM 25,512,586 [HI]memory.hdmp[/HI]
06/25/2019 03:24 PM 16,658 Report.wer
06/25/2019 03:24 PM 213,466 [HI]triagedump.dmp[/HI]
06/25/2019 03:24 PM 6,276 WERA40B.tmp.WERInternalMetadata.xml
4 File(s) 25,748,986 bytes
               2 Dir(s)  50,488,475,648 bytes free

The above files (some/all -?) appear in the WERCON section of msinfo32 as well as Problem Reports and Solutions.

Regards. . .

John

p.s. check the dates on the files in those 4 directories. Mine go back to 2014 when the laptop was new.

Also - the files and dirs. may appear blue in color denoting that the files are compressed (Remember this in XP?)

It seems since Vista, Microsoft colors certain files and dirs blue by adding the "c" (compressed) file attribute. However, they are fine as-is (blue) to review and copy.
 
Last edited:
The Windbg output of the 2 dumps mentioned in my last post.

Note that the Windbg commands set up in the registry for post-mortem dumps give off a syntax error. Same with dump #2 belowas these are user mode dumps and many of their commands begin with periods (.) instead of (!) that post-mortem dumps use.

Output of the WER Triage dump -
Code:
Microsoft (R) Windows Debugger Version 10.0.17763.132 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\PalmDesert\AppData\Local\Microsoft\Windows\WER\ReportQueue\AppHang_Microsoft.SkypeA_fd7bf545c465891a08a585239f1c97ed89a42c3_1a1e67db_cab_4c97a5b0\[HI]triagedump.dmp[/HI]]
User Mini Triage Dump File: Only registers, stack and portions of memory are available
--------------------------------
The user dump currently examined is a triage dump. Consequently, only a subset of debugger
functionality will be available. If needed, please collect a minidump or a heap dump.
To create a mini user dump use the command: .dump /m <filename>
      To create a full user dump use the command: .dump /ma <filename>

  Triage dumps have certain values on the stack and in the register contexts overwritten with
pattern 0xAAAAAAAA. If you see this value
1. the original value was not NULL
2. the original value was not a direct pointer to a loaded or unloaded image
3. the original value did not point to an object whose VFT points to a loaded or
unloaded image (indirect pointer)
4. the original value did not point to the stack itself or any memory area added to
the dump (TEB, PEB, memory for CLR stackwalk or exceptions, etc.)
5. the original value was not a valid handle value
--------------------------------


************* Path validation summary **************
Response Time (ms) Location
Deferred SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8.1 Version 9600 MP (8 procs) Free x86 compatible
Product: WinNt, suite: SingleUserTS Personal
6.3.9600.18217 (winblue_ltsb.160124-0053)
Machine Name:
Debug session time: Tue Jun 25 15:24:31.000 2019 (UTC - 4:00)
System Uptime: 0 days 5:36:25.242
Process Uptime: 0 days 0:05:40.000
................................................................
..........
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(47c4.47cc): Unknown exception - code dfffffff (first/second chance not available)
eax=00000000 ebx=aaaaaaaa ecx=00000000 edx=00000000 esi=5cf3c10c edi=00000000
eip=7739ddbc esp=0035f884 ebp=0035f8c8 iopl=0 nv up ei pl nz na pe nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000206
ntdll!NtWaitForAlertByThreadId+0xc:
7739ddbc c20800 ret 8
Processing initial command '!analyze -v;r;kv;lmtn;lmtsmn;.bugcheck'
0:000> !analyze -v;r;kv;lmtn;lmtsmn;.bugcheck
*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************

GetUrlPageData2 (WinHttp) failed: 12002.

KEY_VALUES_STRING: 1


STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1

Timeline: !analyze.Start
Name: <blank>
Time: 2019-07-29T13:13:29.512Z
    Diff: -1379628784 mSec

Timeline: Dump.Current
Name: <blank>
Time: 2019-06-25T19:24:31.0Z
    Diff: 0 mSec

Timeline: Process.Start
Name: <blank>
Time: 2019-06-25T19:18:51.0Z
    Diff: 340000 mSec

Timeline: OS.Boot
Name: <blank>
Time: 2019-06-25T13:48:06.0Z
    Diff: 20185000 mSec


DUMP_CLASS: 2

DUMP_QUALIFIER: 400

CONTEXT:  (.cxr;r)
Resetting default scope
eax=00000000 ebx=aaaaaaaa ecx=00000000 edx=00000000 esi=5cf3c10c edi=00000000
eip=7739ddbc esp=0035f884 ebp=0035f8c8 iopl=0 nv up ei pl nz na pe nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000206
ntdll!NtWaitForAlertByThreadId+0xc:
7739ddbc c20800          ret     8

FAULTING_IP:
+0
00000000 ??              ???

EXCEPTION_RECORD:  (.exr -1)
ExceptionAddress: 00000000
ExceptionCode: dfffffff
ExceptionFlags: 00000001
NumberParameters: 0

BUGCHECK_STR:  dfffffff

DEFAULT_BUCKET_ID:  APPLICATION_HANG

ERROR_CODE: (NTSTATUS) 0xdfffffff - <Unable to get error code text>

EXCEPTION_CODE: (NTSTATUS) 0xdfffffff - <Unable to get error code text>

EXCEPTION_CODE_STR:  dfffffff

WATSON_BKT_PROCSTAMP:  5450355f

WATSON_BKT_PROCVER:  6.3.9600.17415

PROCESS_VER_PRODUCT:  Microsoft® Windows® Operating System

WATSON_BKT_MODULE:  unknown

WATSON_BKT_MODVER:  0.0.0.0

WATSON_BKT_MODOFFSET:  0

WATSON_BKT_MODSTAMP:  bbbbbbb4

BUILD_VERSION_STRING:  6.3.9600.18217 (winblue_ltsb.160124-0053)

MODLIST_WITH_TSCHKSUM_HASH:  75ef59c2a43156f3c1089b9e0f239c505634cf8c

MODLIST_SHA1_HASH:  56b549917b7d2aa32542a96cd2f8d6ed21634f32

NTGLOBALFLAG:  0

PROCESS_BAM_CURRENT_THROTTLED: 0

PROCESS_BAM_PREVIOUS_THROTTLED: 0

PRODUCT_TYPE:  1

SUITE_MASK:  784

DUMP_FLAGS:  102c6

DUMP_TYPE:  11

PROCESS_NAME:  unknown

ANALYSIS_SESSION_HOST:  SYSNATIVEFORUMS

ANALYSIS_SESSION_TIME:  07-29-2019 09:13:29.0512

ANALYSIS_VERSION: 10.0.17763.132 amd64fre

DERIVED_WAIT_CHAIN:    00 47c4.47cc Unknown

WAIT_CHAIN_COMMAND:  ~0s;k;;

THREAD_ATTRIBUTES:
BLOCKING_THREAD:  000047cc

THREAD_SHA1_HASH_MOD_FUNC:  602bac48fd91daf66616cd30b491fc4a797d1150

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  4c967cf1bc8afa190221992a470decb0e4458dc7

LAST_CONTROL_TRANSFER:  from 773648e0 to 7739ddbc

STACK_TEXT:  
0035f880 773648e0 5cf3c10c 00000000 00418628 ntdll!NtWaitForAlertByThreadId+0xc
0035f8c8 5ceea1c0 00418628 5cf3c10c 00000000 ntdll!RtlSleepConditionVariableSRW+0xe8
0035f8f0 5cee9f8b 5cef5d10 aaaaaaaa aaaaaaaa twinapi_appcore!PsmRegisterAppStateChangeNotification+0x160
0035f924 5cee9e67 00000000 02a730e8 003f2eb8 twinapi_appcore!Windows::ApplicationModel::Core::CoreApplication::RegisterWithPSM+0x32
0035f944 5cee99a1 003f2eb8 003f4600 aaaaaaaa twinapi_appcore!Windows::ApplicationModel::Core::CoreApplication::InitializeApplicationServer+0x177
0035fa94 5cf04fa5 003f2eb8 003f4600 aaaaaaaa twinapi_appcore!Windows::ApplicationModel::Core::CoreApplicationFactory::RunInternal+0x1c1
0035faac 008e9fef 02a72f14 003f2eb8 003f4600 twinapi_appcore!Windows::ApplicationModel::Core::CoreApplicationFactory::RunFrameworkViewSourceWithBackgroundFactoryAndThreadingModel+0x15
0035fb04 008e9e3b 00967004 00000000 aaaaaaaa WWAHost!Host::Run+0x127
0035fb1c 008e97b3 008e9720 008e9720 7f763000 WWAHost!RunHost+0x6f
0035fb2c 77166a14 7f763000 771669f0 aaaaaaaa WWAHost!mainCRTStartup+0x93
0035fb40 773bad8f 7f763000 aaaaaaaa 00000000 kernel32!BaseThreadInitThunk+0x24
0035fb88 773bad5a aaaaaaaa 773a00b0 00000000 ntdll!__RtlUserThreadStart+0x2f
0035fb98 00000000 008e9720 7f763000 00000000 ntdll!_RtlUserThreadStart+0x1b


THREAD_SHA1_HASH_MOD:  70239857dbd62811e176fe9beb033948aa9d99fd

FOLLOWUP_IP:
twinapi_appcore!PsmRegisterAppStateChangeNotification+160
5ceea1c0 807e1d00        cmp     byte ptr [esi+1Dh],0

FAULT_INSTR_CODE:  1d7e80

SYMBOL_STACK_INDEX:  2

SYMBOL_NAME:  twinapi_appcore!PsmRegisterAppStateChangeNotification+160

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: twinapi_appcore

IMAGE_NAME:  twinapi.appcore.dll

DEBUG_FLR_IMAGE_TIMESTAMP:  54503954

STACK_COMMAND:  ~0s ; .ecxr ; kb

BUCKET_ID:  dfffffff_twinapi_appcore!PsmRegisterAppStateChangeNotification+160

PRIMARY_PROBLEM_CLASS:  dfffffff_twinapi_appcore!PsmRegisterAppStateChangeNotification+160

FAILURE_EXCEPTION_CODE:  dfffffff

FAILURE_IMAGE_NAME:  twinapi.appcore.dll

BUCKET_ID_IMAGE_STR:  twinapi.appcore.dll

FAILURE_MODULE_NAME:  twinapi_appcore

BUCKET_ID_MODULE_STR:  twinapi_appcore

FAILURE_FUNCTION_NAME:  PsmRegisterAppStateChangeNotification

BUCKET_ID_FUNCTION_STR:  PsmRegisterAppStateChangeNotification

BUCKET_ID_OFFSET:  160

BUCKET_ID_MODTIMEDATESTAMP:  54503954

BUCKET_ID_MODCHECKSUM:  7ceaf

BUCKET_ID_MODVER_STR:  6.3.9600.17415

BUCKET_ID_PREFIX_STR:  dfffffff_

FAILURE_PROBLEM_CLASS:  dfffffff_twinapi_appcore!PsmRegisterAppStateChangeNotification+160

FAILURE_SYMBOL_NAME:  twinapi.appcore.dll!PsmRegisterAppStateChangeNotification

FAILURE_BUCKET_ID:  APPLICATION_HANG_dfffffff_twinapi.appcore.dll!PsmRegisterAppStateChangeNotification

WATSON_STAGEONE_URL:  http://watson.microsoft.com/StageOne/unknown/6.3.9600.17415/5450355f/unknown/0.0.0.0/bbbbbbb4/dfffffff/00000000.htm?Retriage=1

TARGET_TIME:  2019-06-25T19:24:31.000Z

OSBUILD:  9600

OSSERVICEPACK:  19358

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

OSPLATFORM_TYPE:  x86

OSNAME:  Windows 8.1

OSEDITION:  Windows 8.1 WinNt SingleUserTS Personal

OS_LOCALE: 

USER_LCID:  0

OSBUILD_TIMESTAMP:  2019-05-05 22:08:24

BUILDDATESTAMP_STR:  160124-0053

BUILDLAB_STR:  winblue_ltsb

BUILDOSVER_STR:  6.3.9600.18217

ANALYSIS_SESSION_ELAPSED_TIME:  1aa13

ANALYSIS_SOURCE:  UM

FAILURE_ID_HASH_STRING:  um:application_hang_dfffffff_twinapi.appcore.dll!psmregisterappstatechangenotification

FAILURE_ID_HASH:  {7de8fdd5-27aa-89af-a07b-62b761423cf3}

Followup:     MachineOwner
---------

eax=00000000 ebx=aaaaaaaa ecx=00000000 edx=00000000 esi=5cf3c10c edi=00000000
eip=7739ddbc esp=0035f884 ebp=0035f8c8 iopl=0 nv up ei pl nz na pe nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000206
ntdll!NtWaitForAlertByThreadId+0xc:
7739ddbc c20800 ret 8
# ChildEBP RetAddr Args to Child
00 0035f880 773648e0 5cf3c10c 00000000 00418628 ntdll!NtWaitForAlertByThreadId+0xc (FPO: [2,0,0])
01 0035f8c8 5ceea1c0 00418628 5cf3c10c 00000000 ntdll!RtlSleepConditionVariableSRW+0xe8 (FPO: [4,10,0])
02 0035f8f0 5cee9f8b 5cef5d10 aaaaaaaa aaaaaaaa twinapi_appcore!PsmRegisterAppStateChangeNotification+0x160 (FPO: [Non-Fpo])
03 0035f924 5cee9e67 00000000 02a730e8 003f2eb8 twinapi_appcore!Windows::ApplicationModel::Core::CoreApplication::RegisterWithPSM+0x32 (FPO: [Non-Fpo])
04 0035f944 5cee99a1 003f2eb8 003f4600 aaaaaaaa twinapi_appcore!Windows::ApplicationModel::Core::CoreApplication::InitializeApplicationServer+0x177 (FPO: [Non-Fpo])
05 0035fa94 5cf04fa5 003f2eb8 003f4600 aaaaaaaa twinapi_appcore!Windows::ApplicationModel::Core::CoreApplicationFactory::RunInternal+0x1c1 (FPO: [Non-Fpo])
06 0035faac 008e9fef 02a72f14 003f2eb8 003f4600 twinapi_appcore!Windows::ApplicationModel::Core::CoreApplicationFactory::RunFrameworkViewSourceWithBackgroundFactoryAndThreadingModel+0x15 (FPO: [Non-Fpo])
07 0035fb04 008e9e3b 00967004 00000000 aaaaaaaa WWAHost!Host::Run+0x127 (FPO: [Non-Fpo])
08 0035fb1c 008e97b3 008e9720 008e9720 7f763000 WWAHost!RunHost+0x6f (FPO: [Non-Fpo])
09 0035fb2c 77166a14 7f763000 771669f0 aaaaaaaa WWAHost!mainCRTStartup+0x93 (FPO: [0,0,4])
0a 0035fb40 773bad8f 7f763000 aaaaaaaa 00000000 kernel32!BaseThreadInitThunk+0x24 (FPO: [Non-Fpo])
0b 0035fb88 773bad5a aaaaaaaa 773a00b0 00000000 ntdll!__RtlUserThreadStart+0x2f (FPO: [SEH])
0c 0035fb98 00000000 008e9720 7f763000 00000000 ntdll!_RtlUserThreadStart+0x1b (FPO: [Non-Fpo])
start end module name
008e0000 0097c000 WWAHost WWAHost.exe Tue Oct 28 17:31:27 2014 (5450355F)
57530000 5755b000 Windows_Storage_ApplicationData Windows.Storage.ApplicationData.dll Mon Jan 1 20:09:40 2018 (5A4B0604)
57a80000 57b09000 FirewallAPI FirewallAPI.dll Thu Aug 9 09:59:02 2018 (5B6C72D6)
57b10000 57b75000 MFReadWrite MFReadWrite.dll Tue Oct 28 17:45:53 2014 (545038C1)
57b80000 57bff000 Windows_Networking Windows.Networking.dll Tue Oct 28 17:47:06 2014 (5450390A)
57c00000 57ccc000 msvcr120_app msvcr120_app.dll Fri Oct 4 19:43:41 2013 (524F7CDD)
57cd0000 57d41000 msvcp120_app msvcp120_app.dll Fri Oct 4 19:43:51 2013 (524F7CE7)
57d50000 57d8c000 vccorlib120_app vccorlib120_app.DLL Fri Oct 4 22:55:15 2013 (524FA9C3)
57d90000 58c14000 LibWrap LibWrap.dll Fri Aug 16 07:37:40 2013 (520E3934)
58c20000 58c39000 vaultcli vaultcli.dll Tue Oct 28 18:00:06 2014 (54503C16)
58c40000 58c6a000 WwaApi WwaApi.dll Tue Oct 28 19:00:56 2014 (54504A58)
58c70000 58c8f000 biwinrt biwinrt.dll Tue Oct 28 18:00:06 2014 (54503C16)
58c90000 58cef000 Windows_UI Windows.UI.dll Sat Apr 9 14:50:05 2016 (5709790D)
58cf0000 58d19000 rometadata rometadata.dll Mon Aug 5 21:10:23 2013 (5200772F)
58d20000 58de6000 MrmCoreR MrmCoreR.dll Sat Feb 7 15:49:12 2015 (54D6A478)
5ce00000 5ce87000 WinTypes WinTypes.dll Sun Apr 16 00:01:36 2017 (58F316D0)
5ced0000 5cf4b000 twinapi_appcore twinapi.appcore.dll Tue Oct 28 17:48:20 2014 (54503954)
5d030000 5d050000 RTWorkQ RTWorkQ.dll Tue Oct 28 17:57:32 2014 (54503B7C)
5d050000 5d114000 mfplat mfplat.dll Thu Nov 13 21:08:19 2014 (54658E43)
60cf0000 60d32000 dcomp dcomp.dll Tue Oct 28 18:00:01 2014 (54503C11)
60d40000 60d4e000 msimtf msimtf.dll Tue Oct 28 17:58:34 2014 (54503BBA)
60f80000 613d2000 jscript9 jscript9.dll Wed Apr 24 19:40:21 2019 (5CC11E15)
61420000 6146f000 ninput ninput.dll Tue Oct 28 17:55:25 2014 (54503AFD)
61470000 61575000 actxprxy actxprxy.dll Mon Feb 25 22:20:09 2019 (5C74DA99)
627c0000 63c21000 mshtml mshtml.dll Wed Apr 24 20:30:31 2019 (5CC129D7)
64d90000 64e30000 apphelp apphelp.dll Tue Oct 28 19:00:11 2014 (54504A2B)
671b0000 672fd000 urlmon urlmon.dll Wed Apr 24 19:14:25 2019 (5CC11801)
6d300000 6d39e000 winhttp winhttp.dll Thu Dec 27 08:30:27 2018 (5C24FE23)
6d3b0000 6d3ba000 secur32 secur32.dll Tue Oct 28 18:06:19 2014 (54503D8B)
6d3c0000 6d5f6000 iertutil iertutil.dll Wed Apr 24 20:09:13 2019 (5CC124D9)
6d600000 6daa3000 wininet wininet.dll Wed Apr 24 19:18:07 2019 (5CC118DF)
6db80000 6dbcd000 Bcp47Langs Bcp47Langs.dll Tue Oct 28 18:04:08 2014 (54503D08)
6e340000 6e380000 powrprof powrprof.dll Tue Oct 28 18:04:54 2014 (54503D36)
6e3e0000 6e433000 MMDevAPI MMDevAPI.dll Tue Oct 28 17:55:23 2014 (54503AFB)
6e490000 6e876000 d2d1 d2d1.dll Thu Aug 6 09:18:03 2015 (55C388BB)
6e880000 6f516000 igd10iumd32 igd10iumd32.dll Mon Sep 9 10:30:48 2013 (522E05C8)
6f730000 6f8b1000 DWrite DWrite.dll Fri May 12 09:13:46 2017 (5915DF3A)
6f8f0000 6fc4e000 igdusc32 igdusc32.dll Mon Sep 9 10:20:09 2013 (522E0349)
6fc50000 6fc79000 ntasn1 ntasn1.dll Tue Oct 28 18:05:46 2014 (54503D6A)
6fc80000 6fca0000 ncrypt ncrypt.dll Sat Mar 10 08:38:03 2018 (5AA409EB)
6fca0000 6fd09000 dxgi dxgi.dll Tue Oct 28 18:02:24 2014 (54503CA0)
6fd10000 6fee9000 d3d11 d3d11.dll Thu Aug 11 09:06:53 2016 (57ACA29D)
70230000 7024e000 bcrypt bcrypt.dll Sat Nov 19 09:22:21 2016 (58308A4D)
70250000 70280000 rsaenh rsaenh.dll Fri Jan 8 08:52:44 2016 (568FE95C)
70280000 70299000 cryptsp cryptsp.dll Tue Oct 28 18:06:22 2014 (54503D8E)
70440000 7045b000 userenv userenv.dll Tue Oct 28 18:00:57 2014 (54503C49)
70470000 7055d000 uxtheme uxtheme.dll Tue Oct 10 07:58:33 2017 (59DCE019)
70560000 7057a000 dwmapi dwmapi.dll Tue Oct 28 17:58:22 2014 (54503BAE)
705d0000 705da000 avrt avrt.dll Tue Oct 28 18:06:13 2014 (54503D85)
741f0000 74211000 devobj devobj.dll Tue Oct 28 18:03:21 2014 (54503CD9)
74870000 748ed000 tiptsf tiptsf.dll Tue Oct 28 17:49:08 2014 (54503984)
74900000 7490f000 profapi profapi.dll Tue Oct 28 18:06:11 2014 (54503D83)
74910000 7499b000 SHCore SHCore.dll Thu Jan 22 18:47:03 2015 (54C1B627)
74a10000 74a19000 kernel_appcore kernel.appcore.dll Tue Oct 28 18:04:26 2014 (54503D1A)
74ad0000 74b24000 bcryptPrimitives bcryptPrimitives.dll Mon Jan 1 20:14:56 2018 (5A4B0740)
74b30000 74b3a000 CRYPTBASE CRYPTBASE.dll Tue Oct 28 19:01:15 2014 (54504A6B)
74b40000 74c93000 user32 user32.dll Wed Nov 9 09:25:02 2016 (58235BEE)
74ca0000 74d1c000 advapi32 advapi32.dll Mon Jan 1 20:57:22 2018 (5A4B1132)
74f80000 750fd000 combase combase.dll Fri Dec 7 19:43:37 2018 (5C0B3DE9)
75100000 75141000 sechost sechost.dll Thu Mar 19 20:20:59 2015 (550B921B)
75160000 75187000 imm32 imm32.dll Tue Oct 28 18:59:48 2014 (54504A14)
75190000 75253000 msvcrt msvcrt.dll Tue Oct 28 19:04:30 2014 (54504B2E)
75460000 75572000 msctf msctf.dll Sat Sep 9 08:39:42 2017 (59B40B3E)
75580000 755bc000 cfgmgr32 cfgmgr32.dll Tue Oct 28 18:06:02 2014 (54503D7A)
755c0000 756e9000 ole32 ole32.dll Sat Apr 6 15:19:59 2019 (5CA9260F)
75820000 758f7000 KERNELBASE KERNELBASE.dll Sun May 5 19:12:42 2019 (5CCF981A)
75910000 759ca000 rpcrt4 rpcrt4.dll Thu Feb 21 08:30:58 2019 (5C6ED242)
759d0000 75adc000 gdi32 gdi32.dll Sat Mar 9 08:35:21 2019 (5C83EB49)
75ae0000 75afe000 sspicli sspicli.dll Sat Aug 20 15:55:19 2016 (57B8DFD7)
75b00000 76dbb000 shell32 shell32.dll Sun Apr 14 08:16:49 2019 (5CB34EE1)
76e30000 76ec6000 oleaut32 oleaut32.dll Fri Mar 15 19:47:23 2019 (5C8C63BB)
770a0000 770e5000 shlwapi shlwapi.dll Tue Oct 28 17:43:08 2014 (5450381C)
77150000 77290000 kernel32 kernel32.dll Sun May 5 19:08:24 2019 (5CCF9718)
77360000 774cf000 ntdll ntdll.dll Mon Jan 1 21:02:54 2018 (5A4B127E)
start end module name
61470000 61575000 actxprxy actxprxy.dll Mon Feb 25 22:20:09 2019 (5C74DA99)
74ca0000 74d1c000 advapi32 advapi32.dll Mon Jan 1 20:57:22 2018 (5A4B1132)
64d90000 64e30000 apphelp apphelp.dll Tue Oct 28 19:00:11 2014 (54504A2B)
705d0000 705da000 avrt avrt.dll Tue Oct 28 18:06:13 2014 (54503D85)
6db80000 6dbcd000 Bcp47Langs Bcp47Langs.dll Tue Oct 28 18:04:08 2014 (54503D08)
70230000 7024e000 bcrypt bcrypt.dll Sat Nov 19 09:22:21 2016 (58308A4D)
74ad0000 74b24000 bcryptPrimitives bcryptPrimitives.dll Mon Jan 1 20:14:56 2018 (5A4B0740)
58c70000 58c8f000 biwinrt biwinrt.dll Tue Oct 28 18:00:06 2014 (54503C16)
75580000 755bc000 cfgmgr32 cfgmgr32.dll Tue Oct 28 18:06:02 2014 (54503D7A)
74f80000 750fd000 combase combase.dll Fri Dec 7 19:43:37 2018 (5C0B3DE9)
74b30000 74b3a000 CRYPTBASE CRYPTBASE.dll Tue Oct 28 19:01:15 2014 (54504A6B)
70280000 70299000 cryptsp cryptsp.dll Tue Oct 28 18:06:22 2014 (54503D8E)
6e490000 6e876000 d2d1 d2d1.dll Thu Aug 6 09:18:03 2015 (55C388BB)
6fd10000 6fee9000 d3d11 d3d11.dll Thu Aug 11 09:06:53 2016 (57ACA29D)
60cf0000 60d32000 dcomp dcomp.dll Tue Oct 28 18:00:01 2014 (54503C11)
741f0000 74211000 devobj devobj.dll Tue Oct 28 18:03:21 2014 (54503CD9)
70560000 7057a000 dwmapi dwmapi.dll Tue Oct 28 17:58:22 2014 (54503BAE)
6f730000 6f8b1000 DWrite DWrite.dll Fri May 12 09:13:46 2017 (5915DF3A)
6fca0000 6fd09000 dxgi dxgi.dll Tue Oct 28 18:02:24 2014 (54503CA0)
57a80000 57b09000 FirewallAPI FirewallAPI.dll Thu Aug 9 09:59:02 2018 (5B6C72D6)
759d0000 75adc000 gdi32 gdi32.dll Sat Mar 9 08:35:21 2019 (5C83EB49)
6d3c0000 6d5f6000 iertutil iertutil.dll Wed Apr 24 20:09:13 2019 (5CC124D9)
6e880000 6f516000 igd10iumd32 igd10iumd32.dll Mon Sep 9 10:30:48 2013 (522E05C8)
6f8f0000 6fc4e000 igdusc32 igdusc32.dll Mon Sep 9 10:20:09 2013 (522E0349)
75160000 75187000 imm32 imm32.dll Tue Oct 28 18:59:48 2014 (54504A14)
60f80000 613d2000 jscript9 jscript9.dll Wed Apr 24 19:40:21 2019 (5CC11E15)
77150000 77290000 kernel32 kernel32.dll Sun May 5 19:08:24 2019 (5CCF9718)
74a10000 74a19000 kernel_appcore kernel.appcore.dll Tue Oct 28 18:04:26 2014 (54503D1A)
75820000 758f7000 KERNELBASE KERNELBASE.dll Sun May 5 19:12:42 2019 (5CCF981A)
57d90000 58c14000 LibWrap LibWrap.dll Fri Aug 16 07:37:40 2013 (520E3934)
5d050000 5d114000 mfplat mfplat.dll Thu Nov 13 21:08:19 2014 (54658E43)
57b10000 57b75000 MFReadWrite MFReadWrite.dll Tue Oct 28 17:45:53 2014 (545038C1)
6e3e0000 6e433000 MMDevAPI MMDevAPI.dll Tue Oct 28 17:55:23 2014 (54503AFB)
58d20000 58de6000 MrmCoreR MrmCoreR.dll Sat Feb 7 15:49:12 2015 (54D6A478)
75460000 75572000 msctf msctf.dll Sat Sep 9 08:39:42 2017 (59B40B3E)
627c0000 63c21000 mshtml mshtml.dll Wed Apr 24 20:30:31 2019 (5CC129D7)
60d40000 60d4e000 msimtf msimtf.dll Tue Oct 28 17:58:34 2014 (54503BBA)
57cd0000 57d41000 msvcp120_app msvcp120_app.dll Fri Oct 4 19:43:51 2013 (524F7CE7)
57c00000 57ccc000 msvcr120_app msvcr120_app.dll Fri Oct 4 19:43:41 2013 (524F7CDD)
75190000 75253000 msvcrt msvcrt.dll Tue Oct 28 19:04:30 2014 (54504B2E)
6fc80000 6fca0000 ncrypt ncrypt.dll Sat Mar 10 08:38:03 2018 (5AA409EB)
61420000 6146f000 ninput ninput.dll Tue Oct 28 17:55:25 2014 (54503AFD)
6fc50000 6fc79000 ntasn1 ntasn1.dll Tue Oct 28 18:05:46 2014 (54503D6A)
77360000 774cf000 ntdll ntdll.dll Mon Jan 1 21:02:54 2018 (5A4B127E)
755c0000 756e9000 ole32 ole32.dll Sat Apr 6 15:19:59 2019 (5CA9260F)
76e30000 76ec6000 oleaut32 oleaut32.dll Fri Mar 15 19:47:23 2019 (5C8C63BB)
6e340000 6e380000 powrprof powrprof.dll Tue Oct 28 18:04:54 2014 (54503D36)
74900000 7490f000 profapi profapi.dll Tue Oct 28 18:06:11 2014 (54503D83)
58cf0000 58d19000 rometadata rometadata.dll Mon Aug 5 21:10:23 2013 (5200772F)
75910000 759ca000 rpcrt4 rpcrt4.dll Thu Feb 21 08:30:58 2019 (5C6ED242)
70250000 70280000 rsaenh rsaenh.dll Fri Jan 8 08:52:44 2016 (568FE95C)
5d030000 5d050000 RTWorkQ RTWorkQ.dll Tue Oct 28 17:57:32 2014 (54503B7C)
75100000 75141000 sechost sechost.dll Thu Mar 19 20:20:59 2015 (550B921B)
6d3b0000 6d3ba000 secur32 secur32.dll Tue Oct 28 18:06:19 2014 (54503D8B)
74910000 7499b000 SHCore SHCore.dll Thu Jan 22 18:47:03 2015 (54C1B627)
75b00000 76dbb000 shell32 shell32.dll Sun Apr 14 08:16:49 2019 (5CB34EE1)
770a0000 770e5000 shlwapi shlwapi.dll Tue Oct 28 17:43:08 2014 (5450381C)
75ae0000 75afe000 sspicli sspicli.dll Sat Aug 20 15:55:19 2016 (57B8DFD7)
74870000 748ed000 tiptsf tiptsf.dll Tue Oct 28 17:49:08 2014 (54503984)
5ced0000 5cf4b000 twinapi_appcore twinapi.appcore.dll Tue Oct 28 17:48:20 2014 (54503954)
671b0000 672fd000 urlmon urlmon.dll Wed Apr 24 19:14:25 2019 (5CC11801)
74b40000 74c93000 user32 user32.dll Wed Nov 9 09:25:02 2016 (58235BEE)
70440000 7045b000 userenv userenv.dll Tue Oct 28 18:00:57 2014 (54503C49)
70470000 7055d000 uxtheme uxtheme.dll Tue Oct 10 07:58:33 2017 (59DCE019)
58c20000 58c39000 vaultcli vaultcli.dll Tue Oct 28 18:00:06 2014 (54503C16)
57d50000 57d8c000 vccorlib120_app vccorlib120_app.DLL Fri Oct 4 22:55:15 2013 (524FA9C3)
57b80000 57bff000 Windows_Networking Windows.Networking.dll Tue Oct 28 17:47:06 2014 (5450390A)
57530000 5755b000 Windows_Storage_ApplicationData Windows.Storage.ApplicationData.dll Mon Jan 1 20:09:40 2018 (5A4B0604)
58c90000 58cef000 Windows_UI Windows.UI.dll Sat Apr 9 14:50:05 2016 (5709790D)
6d300000 6d39e000 winhttp winhttp.dll Thu Dec 27 08:30:27 2018 (5C24FE23)
6d600000 6daa3000 wininet wininet.dll Wed Apr 24 19:18:07 2019 (5CC118DF)
5ce00000 5ce87000 WinTypes WinTypes.dll Sun Apr 16 00:01:36 2017 (58F316D0)
58c40000 58c6a000 WwaApi WwaApi.dll Tue Oct 28 19:00:56 2014 (54504A58)
008e0000 0097c000 WWAHost WWAHost.exe Tue Oct 28 17:31:27 2014 (5450355F)
^ Syntax error in '!analyze -v;r;kv;lmtn;lmtsmn;.bugcheck'


This is simply a user-mode dump, I believe -

Code:
Microsoft (R) Windows Debugger Version 10.0.17763.132 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\PalmDesert\AppData\Local\Microsoft\Windows\WER\ReportQueue\AppHang_Microsoft.SkypeA_fd7bf545c465891a08a585239f1c97ed89a42c3_1a1e67db_cab_4c97a5b0\[HI]memory.hdmp[/HI]]
User Mini Dump File: Only registers, stack and portions of memory are available


************* Path validation summary **************
Response Time (ms) Location
Deferred SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8.1 Version 9600 MP (8 procs) Free x86 compatible
Product: WinNt, suite: SingleUserTS Personal
6.3.9600.18217 (winblue_ltsb.160124-0053)
Machine Name:
Debug session time: Tue Jun 25 15:24:29.000 2019 (UTC - 4:00)
System Uptime: 0 days 5:36:23.823
Process Uptime: 0 days 0:05:38.000
................................................................
..........
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(47c4.47cc): Unknown exception - code dfffffff (first/second chance not available)
Processing initial command '!analyze -v;r;kv;lmtn;lmtsmn;.bugcheck'
eax=00000000 ebx=00000003 ecx=00000000 edx=00000000 esi=5cf3c10c edi=00000000
eip=7739ddbc esp=0035f884 ebp=0035f8c8 iopl=0 nv up ei pl nz na pe nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000206
ntdll!NtWaitForAlertByThreadId+0xc:
7739ddbc c20800 ret 8
0:000> !analyze -v;r;kv;lmtn;lmtsmn;.bugcheck
*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************

GetUrlPageData2 (WinHttp) failed: 12002.

KEY_VALUES_STRING: 1


STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1

Timeline: !analyze.Start
Name: <blank>
Time: 2019-07-29T13:13:32.57Z
    Diff: -1379624239 mSec

Timeline: Dump.Current
Name: <blank>
Time: 2019-06-25T19:24:29.0Z
    Diff: 0 mSec

Timeline: Process.Start
Name: <blank>
Time: 2019-06-25T19:18:51.0Z
    Diff: 338000 mSec

Timeline: OS.Boot
Name: <blank>
Time: 2019-06-25T13:48:06.0Z
    Diff: 20183000 mSec


DUMP_CLASS: 2

DUMP_QUALIFIER: 400

CONTEXT:  (.cxr;r)
Resetting default scope
eax=00000000 ebx=00000003 ecx=00000000 edx=00000000 esi=5cf3c10c edi=00000000
eip=7739ddbc esp=0035f884 ebp=0035f8c8 iopl=0 nv up ei pl nz na pe nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000206
ntdll!NtWaitForAlertByThreadId+0xc:
7739ddbc c20800          ret     8

FAULTING_IP:
+0
00000000 ??              ???

EXCEPTION_RECORD:  (.exr -1)
ExceptionAddress: 00000000
ExceptionCode: dfffffff
ExceptionFlags: 00000001
NumberParameters: 0

BUGCHECK_STR:  dfffffff

DEFAULT_BUCKET_ID:  APPLICATION_HANG

ERROR_CODE: (NTSTATUS) 0xdfffffff - <Unable to get error code text>

EXCEPTION_CODE: (NTSTATUS) 0xdfffffff - <Unable to get error code text>

EXCEPTION_CODE_STR:  dfffffff

WATSON_BKT_PROCSTAMP:  5450355f

WATSON_BKT_PROCVER:  6.3.9600.17415

PROCESS_VER_PRODUCT:  Microsoft® Windows® Operating System

WATSON_BKT_MODULE:  unknown

WATSON_BKT_MODVER:  0.0.0.0

WATSON_BKT_MODOFFSET:  0

WATSON_BKT_MODSTAMP:  bbbbbbb4

BUILD_VERSION_STRING:  6.3.9600.18217 (winblue_ltsb.160124-0053)

MODLIST_WITH_TSCHKSUM_HASH:  75ef59c2a43156f3c1089b9e0f239c505634cf8c

MODLIST_SHA1_HASH:  56b549917b7d2aa32542a96cd2f8d6ed21634f32

NTGLOBALFLAG:  0

PROCESS_BAM_CURRENT_THROTTLED: 0

PROCESS_BAM_PREVIOUS_THROTTLED: 0

APPLICATION_VERIFIER_FLAGS:  0

PRODUCT_TYPE:  1

SUITE_MASK:  784

DUMP_FLAGS:  d96

DUMP_TYPE:  0

PROCESS_NAME:  unknown

ANALYSIS_SESSION_HOST:  SYSNATIVEFORUMS

ANALYSIS_SESSION_TIME:  07-29-2019 09:13:32.0057

ANALYSIS_VERSION: 10.0.17763.132 amd64fre

DERIVED_WAIT_CHAIN:    00 47c4.47cc Unknown

WAIT_CHAIN_COMMAND:  ~0s;k;;

THREAD_ATTRIBUTES:
BLOCKING_THREAD:  000047cc

THREAD_SHA1_HASH_MOD_FUNC:  602bac48fd91daf66616cd30b491fc4a797d1150

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  4c967cf1bc8afa190221992a470decb0e4458dc7

LAST_CONTROL_TRANSFER:  from 773648e0 to 7739ddbc

STACK_TEXT:  
0035f880 773648e0 5cf3c10c 00000000 00418628 ntdll!NtWaitForAlertByThreadId+0xc
0035f8c8 5ceea1c0 00418628 5cf3c10c 00000000 ntdll!RtlSleepConditionVariableSRW+0xe8
0035f8f0 5cee9f8b 5cef5d10 00000003 00000003 twinapi_appcore!PsmRegisterAppStateChangeNotification+0x160
0035f924 5cee9e67 00000000 02a730e8 003f2eb8 twinapi_appcore!Windows::ApplicationModel::Core::CoreApplication::RegisterWithPSM+0x32
0035f944 5cee99a1 003f2eb8 003f4600 00000001 twinapi_appcore!Windows::ApplicationModel::Core::CoreApplication::InitializeApplicationServer+0x177
0035fa94 5cf04fa5 003f2eb8 003f4600 00000001 twinapi_appcore!Windows::ApplicationModel::Core::CoreApplicationFactory::RunInternal+0x1c1
0035faac 008e9fef 02a72f14 003f2eb8 003f4600 twinapi_appcore!Windows::ApplicationModel::Core::CoreApplicationFactory::RunFrameworkViewSourceWithBackgroundFactoryAndThreadingModel+0x15
0035fb04 008e9e3b 00967004 00000000 00000001 WWAHost!Host::Run+0x127
0035fb1c 008e97b3 008e9720 008e9720 7f763000 WWAHost!RunHost+0x6f
0035fb2c 77166a14 7f763000 771669f0 a2edd07a WWAHost!mainCRTStartup+0x93
0035fb40 773bad8f 7f763000 97d5d980 00000000 kernel32!BaseThreadInitThunk+0x24
0035fb88 773bad5a ffffffff 773a00b0 00000000 ntdll!__RtlUserThreadStart+0x2f
0035fb98 00000000 008e9720 7f763000 00000000 ntdll!_RtlUserThreadStart+0x1b


THREAD_SHA1_HASH_MOD:  70239857dbd62811e176fe9beb033948aa9d99fd

FOLLOWUP_IP:
twinapi_appcore!PsmRegisterAppStateChangeNotification+160
5ceea1c0 807e1d00        cmp     byte ptr [esi+1Dh],0

FAULT_INSTR_CODE:  1d7e80

SYMBOL_STACK_INDEX:  2

SYMBOL_NAME:  twinapi_appcore!PsmRegisterAppStateChangeNotification+160

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: twinapi_appcore

IMAGE_NAME:  twinapi.appcore.dll

DEBUG_FLR_IMAGE_TIMESTAMP:  54503954

STACK_COMMAND:  ~0s ; .ecxr ; kb

BUCKET_ID:  dfffffff_twinapi_appcore!PsmRegisterAppStateChangeNotification+160

PRIMARY_PROBLEM_CLASS:  dfffffff_twinapi_appcore!PsmRegisterAppStateChangeNotification+160

FAILURE_EXCEPTION_CODE:  dfffffff

FAILURE_IMAGE_NAME:  twinapi.appcore.dll

BUCKET_ID_IMAGE_STR:  twinapi.appcore.dll

FAILURE_MODULE_NAME:  twinapi_appcore

BUCKET_ID_MODULE_STR:  twinapi_appcore

FAILURE_FUNCTION_NAME:  PsmRegisterAppStateChangeNotification

BUCKET_ID_FUNCTION_STR:  PsmRegisterAppStateChangeNotification

BUCKET_ID_OFFSET:  160

BUCKET_ID_MODTIMEDATESTAMP:  54503954

BUCKET_ID_MODCHECKSUM:  7ceaf

BUCKET_ID_MODVER_STR:  6.3.9600.17415

BUCKET_ID_PREFIX_STR:  dfffffff_

FAILURE_PROBLEM_CLASS:  dfffffff_twinapi_appcore!PsmRegisterAppStateChangeNotification+160

FAILURE_SYMBOL_NAME:  twinapi.appcore.dll!PsmRegisterAppStateChangeNotification

FAILURE_BUCKET_ID:  APPLICATION_HANG_dfffffff_twinapi.appcore.dll!PsmRegisterAppStateChangeNotification

WATSON_STAGEONE_URL:  http://watson.microsoft.com/StageOne/unknown/6.3.9600.17415/5450355f/unknown/0.0.0.0/bbbbbbb4/dfffffff/00000000.htm?Retriage=1

TARGET_TIME:  2019-06-25T19:24:29.000Z

OSBUILD:  9600

OSSERVICEPACK:  19358

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

OSPLATFORM_TYPE:  x86

OSNAME:  Windows 8.1

OSEDITION:  Windows 8.1 WinNt SingleUserTS Personal

OS_LOCALE: 

USER_LCID:  0

OSBUILD_TIMESTAMP:  2019-05-05 22:08:24

BUILDDATESTAMP_STR:  160124-0053

BUILDLAB_STR:  winblue_ltsb

BUILDOSVER_STR:  6.3.9600.18217

ANALYSIS_SESSION_ELAPSED_TIME:  1a639

ANALYSIS_SOURCE:  UM

FAILURE_ID_HASH_STRING:  um:application_hang_dfffffff_twinapi.appcore.dll!psmregisterappstatechangenotification

FAILURE_ID_HASH:  {7de8fdd5-27aa-89af-a07b-62b761423cf3}

Followup:     MachineOwner
---------

eax=00000000 ebx=00000003 ecx=00000000 edx=00000000 esi=5cf3c10c edi=00000000
eip=7739ddbc esp=0035f884 ebp=0035f8c8 iopl=0 nv up ei pl nz na pe nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000206
ntdll!NtWaitForAlertByThreadId+0xc:
7739ddbc c20800 ret 8
# ChildEBP RetAddr Args to Child
00 0035f880 773648e0 5cf3c10c 00000000 00418628 ntdll!NtWaitForAlertByThreadId+0xc (FPO: [2,0,0])
01 0035f8c8 5ceea1c0 00418628 5cf3c10c 00000000 ntdll!RtlSleepConditionVariableSRW+0xe8 (FPO: [4,10,0])
02 0035f8f0 5cee9f8b 5cef5d10 00000003 00000003 twinapi_appcore!PsmRegisterAppStateChangeNotification+0x160 (FPO: [Non-Fpo])
03 0035f924 5cee9e67 00000000 02a730e8 003f2eb8 twinapi_appcore!Windows::ApplicationModel::Core::CoreApplication::RegisterWithPSM+0x32 (FPO: [Non-Fpo])
04 0035f944 5cee99a1 003f2eb8 003f4600 00000001 twinapi_appcore!Windows::ApplicationModel::Core::CoreApplication::InitializeApplicationServer+0x177 (FPO: [Non-Fpo])
05 0035fa94 5cf04fa5 003f2eb8 003f4600 00000001 twinapi_appcore!Windows::ApplicationModel::Core::CoreApplicationFactory::RunInternal+0x1c1 (FPO: [Non-Fpo])
06 0035faac 008e9fef 02a72f14 003f2eb8 003f4600 twinapi_appcore!Windows::ApplicationModel::Core::CoreApplicationFactory::RunFrameworkViewSourceWithBackgroundFactoryAndThreadingModel+0x15 (FPO: [Non-Fpo])
07 0035fb04 008e9e3b 00967004 00000000 00000001 WWAHost!Host::Run+0x127 (FPO: [Non-Fpo])
08 0035fb1c 008e97b3 008e9720 008e9720 7f763000 WWAHost!RunHost+0x6f (FPO: [Non-Fpo])
09 0035fb2c 77166a14 7f763000 771669f0 a2edd07a WWAHost!mainCRTStartup+0x93 (FPO: [0,0,4])
0a 0035fb40 773bad8f 7f763000 97d5d980 00000000 kernel32!BaseThreadInitThunk+0x24 (FPO: [Non-Fpo])
0b 0035fb88 773bad5a ffffffff 773a00b0 00000000 ntdll!__RtlUserThreadStart+0x2f (FPO: [SEH])
0c 0035fb98 00000000 008e9720 7f763000 00000000 ntdll!_RtlUserThreadStart+0x1b (FPO: [Non-Fpo])
start end module name
008e0000 0097c000 WWAHost WWAHost.exe Tue Oct 28 17:31:27 2014 (5450355F)
57530000 5755b000 Windows_Storage_ApplicationData Windows.Storage.ApplicationData.dll Mon Jan 1 20:09:40 2018 (5A4B0604)
57a80000 57b09000 FirewallAPI FirewallAPI.dll Thu Aug 9 09:59:02 2018 (5B6C72D6)
57b10000 57b75000 MFReadWrite MFReadWrite.dll Tue Oct 28 17:45:53 2014 (545038C1)
57b80000 57bff000 Windows_Networking Windows.Networking.dll Tue Oct 28 17:47:06 2014 (5450390A)
57c00000 57ccc000 msvcr120_app msvcr120_app.dll Fri Oct 4 19:43:41 2013 (524F7CDD)
57cd0000 57d41000 msvcp120_app msvcp120_app.dll Fri Oct 4 19:43:51 2013 (524F7CE7)
57d50000 57d8c000 vccorlib120_app vccorlib120_app.DLL Fri Oct 4 22:55:15 2013 (524FA9C3)
57d90000 58c14000 LibWrap LibWrap.dll Fri Aug 16 07:37:40 2013 (520E3934)
58c20000 58c39000 vaultcli vaultcli.dll Tue Oct 28 18:00:06 2014 (54503C16)
58c40000 58c6a000 WwaApi WwaApi.dll Tue Oct 28 19:00:56 2014 (54504A58)
58c70000 58c8f000 biwinrt biwinrt.dll Tue Oct 28 18:00:06 2014 (54503C16)
58c90000 58cef000 Windows_UI Windows.UI.dll Sat Apr 9 14:50:05 2016 (5709790D)
58cf0000 58d19000 rometadata rometadata.dll Mon Aug 5 21:10:23 2013 (5200772F)
58d20000 58de6000 MrmCoreR MrmCoreR.dll Sat Feb 7 15:49:12 2015 (54D6A478)
5ce00000 5ce87000 WinTypes WinTypes.dll Sun Apr 16 00:01:36 2017 (58F316D0)
5ced0000 5cf4b000 twinapi_appcore twinapi.appcore.dll Tue Oct 28 17:48:20 2014 (54503954)
5d030000 5d050000 RTWorkQ RTWorkQ.dll Tue Oct 28 17:57:32 2014 (54503B7C)
5d050000 5d114000 mfplat mfplat.dll Thu Nov 13 21:08:19 2014 (54658E43)
60cf0000 60d32000 dcomp dcomp.dll Tue Oct 28 18:00:01 2014 (54503C11)
60d40000 60d4e000 msimtf msimtf.dll Tue Oct 28 17:58:34 2014 (54503BBA)
60f80000 613d2000 jscript9 jscript9.dll Wed Apr 24 19:40:21 2019 (5CC11E15)
61420000 6146f000 ninput ninput.dll Tue Oct 28 17:55:25 2014 (54503AFD)
61470000 61575000 actxprxy actxprxy.dll Mon Feb 25 22:20:09 2019 (5C74DA99)
627c0000 63c21000 mshtml mshtml.dll Wed Apr 24 20:30:31 2019 (5CC129D7)
64d90000 64e30000 apphelp apphelp.dll Tue Oct 28 19:00:11 2014 (54504A2B)
671b0000 672fd000 urlmon urlmon.dll Wed Apr 24 19:14:25 2019 (5CC11801)
6d300000 6d39e000 winhttp winhttp.dll Thu Dec 27 08:30:27 2018 (5C24FE23)
6d3b0000 6d3ba000 secur32 secur32.dll Tue Oct 28 18:06:19 2014 (54503D8B)
6d3c0000 6d5f6000 iertutil iertutil.dll Wed Apr 24 20:09:13 2019 (5CC124D9)
6d600000 6daa3000 wininet wininet.dll Wed Apr 24 19:18:07 2019 (5CC118DF)
6db80000 6dbcd000 Bcp47Langs Bcp47Langs.dll Tue Oct 28 18:04:08 2014 (54503D08)
6e340000 6e380000 powrprof powrprof.dll Tue Oct 28 18:04:54 2014 (54503D36)
6e3e0000 6e433000 MMDevAPI MMDevAPI.dll Tue Oct 28 17:55:23 2014 (54503AFB)
6e490000 6e876000 d2d1 d2d1.dll Thu Aug 6 09:18:03 2015 (55C388BB)
6e880000 6f516000 igd10iumd32 igd10iumd32.dll Mon Sep 9 10:30:48 2013 (522E05C8)
6f730000 6f8b1000 DWrite DWrite.dll Fri May 12 09:13:46 2017 (5915DF3A)
6f8f0000 6fc4e000 igdusc32 igdusc32.dll Mon Sep 9 10:20:09 2013 (522E0349)
6fc50000 6fc79000 ntasn1 ntasn1.dll Tue Oct 28 18:05:46 2014 (54503D6A)
6fc80000 6fca0000 ncrypt ncrypt.dll Sat Mar 10 08:38:03 2018 (5AA409EB)
6fca0000 6fd09000 dxgi dxgi.dll Tue Oct 28 18:02:24 2014 (54503CA0)
6fd10000 6fee9000 d3d11 d3d11.dll Thu Aug 11 09:06:53 2016 (57ACA29D)
70230000 7024e000 bcrypt bcrypt.dll Sat Nov 19 09:22:21 2016 (58308A4D)
70250000 70280000 rsaenh rsaenh.dll Fri Jan 8 08:52:44 2016 (568FE95C)
70280000 70299000 cryptsp cryptsp.dll Tue Oct 28 18:06:22 2014 (54503D8E)
70440000 7045b000 userenv userenv.dll Tue Oct 28 18:00:57 2014 (54503C49)
70470000 7055d000 uxtheme uxtheme.dll Tue Oct 10 07:58:33 2017 (59DCE019)
70560000 7057a000 dwmapi dwmapi.dll Tue Oct 28 17:58:22 2014 (54503BAE)
705d0000 705da000 avrt avrt.dll Tue Oct 28 18:06:13 2014 (54503D85)
741f0000 74211000 devobj devobj.dll Tue Oct 28 18:03:21 2014 (54503CD9)
74870000 748ed000 tiptsf tiptsf.dll Tue Oct 28 17:49:08 2014 (54503984)
74900000 7490f000 profapi profapi.dll Tue Oct 28 18:06:11 2014 (54503D83)
74910000 7499b000 SHCore SHCore.dll Thu Jan 22 18:47:03 2015 (54C1B627)
74a10000 74a19000 kernel_appcore kernel.appcore.dll Tue Oct 28 18:04:26 2014 (54503D1A)
74ad0000 74b24000 bcryptPrimitives bcryptPrimitives.dll Mon Jan 1 20:14:56 2018 (5A4B0740)
74b30000 74b3a000 CRYPTBASE CRYPTBASE.dll Tue Oct 28 19:01:15 2014 (54504A6B)
74b40000 74c93000 user32 user32.dll Wed Nov 9 09:25:02 2016 (58235BEE)
74ca0000 74d1c000 advapi32 advapi32.dll Mon Jan 1 20:57:22 2018 (5A4B1132)
74f80000 750fd000 combase combase.dll Fri Dec 7 19:43:37 2018 (5C0B3DE9)
75100000 75141000 sechost sechost.dll Thu Mar 19 20:20:59 2015 (550B921B)
75160000 75187000 imm32 imm32.dll Tue Oct 28 18:59:48 2014 (54504A14)
75190000 75253000 msvcrt msvcrt.dll Tue Oct 28 19:04:30 2014 (54504B2E)
75460000 75572000 msctf msctf.dll Sat Sep 9 08:39:42 2017 (59B40B3E)
75580000 755bc000 cfgmgr32 cfgmgr32.dll Tue Oct 28 18:06:02 2014 (54503D7A)
755c0000 756e9000 ole32 ole32.dll Sat Apr 6 15:19:59 2019 (5CA9260F)
75820000 758f7000 KERNELBASE KERNELBASE.dll Sun May 5 19:12:42 2019 (5CCF981A)
75910000 759ca000 rpcrt4 rpcrt4.dll Thu Feb 21 08:30:58 2019 (5C6ED242)
759d0000 75adc000 gdi32 gdi32.dll Sat Mar 9 08:35:21 2019 (5C83EB49)
75ae0000 75afe000 sspicli sspicli.dll Sat Aug 20 15:55:19 2016 (57B8DFD7)
75b00000 76dbb000 shell32 shell32.dll Sun Apr 14 08:16:49 2019 (5CB34EE1)
76e30000 76ec6000 oleaut32 oleaut32.dll Fri Mar 15 19:47:23 2019 (5C8C63BB)
770a0000 770e5000 shlwapi shlwapi.dll Tue Oct 28 17:43:08 2014 (5450381C)
77150000 77290000 kernel32 kernel32.dll Sun May 5 19:08:24 2019 (5CCF9718)
77360000 774cf000 ntdll ntdll.dll Mon Jan 1 21:02:54 2018 (5A4B127E)
start end module name
61470000 61575000 actxprxy actxprxy.dll Mon Feb 25 22:20:09 2019 (5C74DA99)
74ca0000 74d1c000 advapi32 advapi32.dll Mon Jan 1 20:57:22 2018 (5A4B1132)
64d90000 64e30000 apphelp apphelp.dll Tue Oct 28 19:00:11 2014 (54504A2B)
705d0000 705da000 avrt avrt.dll Tue Oct 28 18:06:13 2014 (54503D85)
6db80000 6dbcd000 Bcp47Langs Bcp47Langs.dll Tue Oct 28 18:04:08 2014 (54503D08)
70230000 7024e000 bcrypt bcrypt.dll Sat Nov 19 09:22:21 2016 (58308A4D)
74ad0000 74b24000 bcryptPrimitives bcryptPrimitives.dll Mon Jan 1 20:14:56 2018 (5A4B0740)
58c70000 58c8f000 biwinrt biwinrt.dll Tue Oct 28 18:00:06 2014 (54503C16)
75580000 755bc000 cfgmgr32 cfgmgr32.dll Tue Oct 28 18:06:02 2014 (54503D7A)
74f80000 750fd000 combase combase.dll Fri Dec 7 19:43:37 2018 (5C0B3DE9)
74b30000 74b3a000 CRYPTBASE CRYPTBASE.dll Tue Oct 28 19:01:15 2014 (54504A6B)
70280000 70299000 cryptsp cryptsp.dll Tue Oct 28 18:06:22 2014 (54503D8E)
6e490000 6e876000 d2d1 d2d1.dll Thu Aug 6 09:18:03 2015 (55C388BB)
6fd10000 6fee9000 d3d11 d3d11.dll Thu Aug 11 09:06:53 2016 (57ACA29D)
60cf0000 60d32000 dcomp dcomp.dll Tue Oct 28 18:00:01 2014 (54503C11)
741f0000 74211000 devobj devobj.dll Tue Oct 28 18:03:21 2014 (54503CD9)
70560000 7057a000 dwmapi dwmapi.dll Tue Oct 28 17:58:22 2014 (54503BAE)
6f730000 6f8b1000 DWrite DWrite.dll Fri May 12 09:13:46 2017 (5915DF3A)
6fca0000 6fd09000 dxgi dxgi.dll Tue Oct 28 18:02:24 2014 (54503CA0)
57a80000 57b09000 FirewallAPI FirewallAPI.dll Thu Aug 9 09:59:02 2018 (5B6C72D6)
759d0000 75adc000 gdi32 gdi32.dll Sat Mar 9 08:35:21 2019 (5C83EB49)
6d3c0000 6d5f6000 iertutil iertutil.dll Wed Apr 24 20:09:13 2019 (5CC124D9)
6e880000 6f516000 igd10iumd32 igd10iumd32.dll Mon Sep 9 10:30:48 2013 (522E05C8)
6f8f0000 6fc4e000 igdusc32 igdusc32.dll Mon Sep 9 10:20:09 2013 (522E0349)
75160000 75187000 imm32 imm32.dll Tue Oct 28 18:59:48 2014 (54504A14)
60f80000 613d2000 jscript9 jscript9.dll Wed Apr 24 19:40:21 2019 (5CC11E15)
77150000 77290000 kernel32 kernel32.dll Sun May 5 19:08:24 2019 (5CCF9718)
74a10000 74a19000 kernel_appcore kernel.appcore.dll Tue Oct 28 18:04:26 2014 (54503D1A)
75820000 758f7000 KERNELBASE KERNELBASE.dll Sun May 5 19:12:42 2019 (5CCF981A)
57d90000 58c14000 LibWrap LibWrap.dll Fri Aug 16 07:37:40 2013 (520E3934)
5d050000 5d114000 mfplat mfplat.dll Thu Nov 13 21:08:19 2014 (54658E43)
57b10000 57b75000 MFReadWrite MFReadWrite.dll Tue Oct 28 17:45:53 2014 (545038C1)
6e3e0000 6e433000 MMDevAPI MMDevAPI.dll Tue Oct 28 17:55:23 2014 (54503AFB)
58d20000 58de6000 MrmCoreR MrmCoreR.dll Sat Feb 7 15:49:12 2015 (54D6A478)
75460000 75572000 msctf msctf.dll Sat Sep 9 08:39:42 2017 (59B40B3E)
627c0000 63c21000 mshtml mshtml.dll Wed Apr 24 20:30:31 2019 (5CC129D7)
60d40000 60d4e000 msimtf msimtf.dll Tue Oct 28 17:58:34 2014 (54503BBA)
57cd0000 57d41000 msvcp120_app msvcp120_app.dll Fri Oct 4 19:43:51 2013 (524F7CE7)
57c00000 57ccc000 msvcr120_app msvcr120_app.dll Fri Oct 4 19:43:41 2013 (524F7CDD)
75190000 75253000 msvcrt msvcrt.dll Tue Oct 28 19:04:30 2014 (54504B2E)
6fc80000 6fca0000 ncrypt ncrypt.dll Sat Mar 10 08:38:03 2018 (5AA409EB)
61420000 6146f000 ninput ninput.dll Tue Oct 28 17:55:25 2014 (54503AFD)
6fc50000 6fc79000 ntasn1 ntasn1.dll Tue Oct 28 18:05:46 2014 (54503D6A)
77360000 774cf000 ntdll ntdll.dll Mon Jan 1 21:02:54 2018 (5A4B127E)
755c0000 756e9000 ole32 ole32.dll Sat Apr 6 15:19:59 2019 (5CA9260F)
76e30000 76ec6000 oleaut32 oleaut32.dll Fri Mar 15 19:47:23 2019 (5C8C63BB)
6e340000 6e380000 powrprof powrprof.dll Tue Oct 28 18:04:54 2014 (54503D36)
74900000 7490f000 profapi profapi.dll Tue Oct 28 18:06:11 2014 (54503D83)
58cf0000 58d19000 rometadata rometadata.dll Mon Aug 5 21:10:23 2013 (5200772F)
75910000 759ca000 rpcrt4 rpcrt4.dll Thu Feb 21 08:30:58 2019 (5C6ED242)
70250000 70280000 rsaenh rsaenh.dll Fri Jan 8 08:52:44 2016 (568FE95C)
5d030000 5d050000 RTWorkQ RTWorkQ.dll Tue Oct 28 17:57:32 2014 (54503B7C)
75100000 75141000 sechost sechost.dll Thu Mar 19 20:20:59 2015 (550B921B)
6d3b0000 6d3ba000 secur32 secur32.dll Tue Oct 28 18:06:19 2014 (54503D8B)
74910000 7499b000 SHCore SHCore.dll Thu Jan 22 18:47:03 2015 (54C1B627)
75b00000 76dbb000 shell32 shell32.dll Sun Apr 14 08:16:49 2019 (5CB34EE1)
770a0000 770e5000 shlwapi shlwapi.dll Tue Oct 28 17:43:08 2014 (5450381C)
75ae0000 75afe000 sspicli sspicli.dll Sat Aug 20 15:55:19 2016 (57B8DFD7)
74870000 748ed000 tiptsf tiptsf.dll Tue Oct 28 17:49:08 2014 (54503984)
5ced0000 5cf4b000 twinapi_appcore twinapi.appcore.dll Tue Oct 28 17:48:20 2014 (54503954)
671b0000 672fd000 urlmon urlmon.dll Wed Apr 24 19:14:25 2019 (5CC11801)
74b40000 74c93000 user32 user32.dll Wed Nov 9 09:25:02 2016 (58235BEE)
70440000 7045b000 userenv userenv.dll Tue Oct 28 18:00:57 2014 (54503C49)
70470000 7055d000 uxtheme uxtheme.dll Tue Oct 10 07:58:33 2017 (59DCE019)
58c20000 58c39000 vaultcli vaultcli.dll Tue Oct 28 18:00:06 2014 (54503C16)
57d50000 57d8c000 vccorlib120_app vccorlib120_app.DLL Fri Oct 4 22:55:15 2013 (524FA9C3)
57b80000 57bff000 Windows_Networking Windows.Networking.dll Tue Oct 28 17:47:06 2014 (5450390A)
57530000 5755b000 Windows_Storage_ApplicationData Windows.Storage.ApplicationData.dll Mon Jan 1 20:09:40 2018 (5A4B0604)
58c90000 58cef000 Windows_UI Windows.UI.dll Sat Apr 9 14:50:05 2016 (5709790D)
6d300000 6d39e000 winhttp winhttp.dll Thu Dec 27 08:30:27 2018 (5C24FE23)
6d600000 6daa3000 wininet wininet.dll Wed Apr 24 19:18:07 2019 (5CC118DF)
5ce00000 5ce87000 WinTypes WinTypes.dll Sun Apr 16 00:01:36 2017 (58F316D0)
58c40000 58c6a000 WwaApi WwaApi.dll Tue Oct 28 19:00:56 2014 (54504A58)
008e0000 0097c000 WWAHost WWAHost.exe Tue Oct 28 17:31:27 2014 (5450355F)
^ Syntax error in '!analyze -v;r;kv;lmtn;lmtsmn;.bugcheck'
 
No improvement today, and have now tried the new RAM in both slots. Have also updated BIOS now

Dumps from today, including a few ProcDump dumps and WER reports: https://stephenfoulds.com/2019-07-29.zip
So many "normal" dumps - (3) 0x1e, 0x7e (exceptions thrown) - all with 0xc0000005 exception code = "access denied"

Then there is a 0xf7 - A driver has overrun a stack-based buffer.

Then one I saw the other day that rarely appears, but I believe is very important - bugcheck 0x1 - APC Index Mismatch -

APC_INDEX_MISMATCH (1)
This is a kernel internal error. The most common reason to see this
bugcheck is when a filesystem or a driver has a mismatched number of
calls to disable and re-enable APCs. The key data item is the
Thread->CombinedApcDisable field. This consists of two separate 16-bit
fields, the SpecialApcDisable and the KernelApcDisable. A negative value
of either indicates that a driver has disabled special or normal APCs
(respectively) without re-enabling them; a positive value indicates that
a driver has enabled special or normal APCs (respectively) too many times.

A 0x1 dump showed up yesterday too, I believe.
 
Oh... that is not a good sign.

It definitely is hardware failure then if D/V has not BSOD'd your system yet.
 
Please check if it occurs in Safe Mode with networking.
I'm unable to make it crash in Safe Mode which is interesting.

I did stress test in safe mode, but since stress tests don't trigger the crashes in normal mode I was unsurprised that it didn't crash it in safe mode either.

Crashes still occur after a clean boot. I really don't think this is software.

I wonder if there's an issue with M.2 SSDs in this motherboard. I might see how it performs using a SATA SSD
 
I wonder if there's an issue with M.2 SSDs in this motherboard. I might see how it performs using a SATA SSD
Well, I can discount that.

At the weekend, for a backup I cloned my ADATA SSD to a SATA SSD. I just booted off that backup SSD (and made sure the ADATA SSD was disabled in Device Manager) and no difference, still crashing.

I didn't remove the ADATA SSD physically as it's a right pain to get to, but I highly doubt it'll make a difference.
 
I did a quick bit of research for others with similar behavior. Three out of three times it was related to RAM issues (incompatibility, a faulty stick, etc.), so if the RAM itself is fine and compatible with the motherboard, it could be the motherboard slots failed EDIT: or the RAM traces went bad. Hopefully it's not a CPU issue with the cache.
 
Unfortunately I'm leaning towards the same conclusion.... :(

Super frustratingly, I bought all the components for this PC on the 23rd July 2016, making them barely over 3yrs old and outside the warranty period. Would have to speak to ASUS and see how much repair/replacement would cost if I had to go that route.
 
These types of hardware failures are always frustrating. Trial and error is about the only way to find out what it is once you narrow it down to 2-3 components. Too bad you don't own a PC shop where you can just throw components in and see if it fixes it.
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top