BSOD at random times 2-3 times per day with different errors

Chirven

Commendable
Jul 28, 2016
11
0
1,510
Hey all. I have been getting BSODs everyday for a couple months now. At first, since the BSODs started at around the same time as I received my new motherboard and cpu (MSI PC Mate Z97 + Intel i5-4690K), I thought the BSODs were caused by this new hardware, but I am not certain as I updated drivers around the time too. At the moment the BSODs could be caused by anything.
I have:
Ran memtest overnight with a successful pass.
Changed power settings to high.
Installed latest intel chipset drivers from intel's auto updater.
Installed latest BIOS.
Installed as many additional drivers from my motherboard's webpage.
Uninstalled graphics drivers (for my AMD HD 7870 GHz edition) and reinstalled.
Completely reinstalled windows by formatting by HDD and installing a fresh copy of windows on to that.

My PC specs are as follows:
MSI PC Mate Z97
Intel Core i5-4690K
AMD Radeon HD 7870 Ghz Edition
16gb (4x4) of Patriot Viper 3 DDR3
Seagate Barracuda 1TB 3.5" 7200RPM
Antec TP-650C

Here are thew last 5 .dmp files but as mentioned earlier the errors seem to always be different:
http://www.mediafire.com/download/or78tddfo77bt0h/dmp_files.zip

.dmp files on drive:
https://drive.google.com/folderview?id=0BzgSuwGhlWk4NUcwZW1id1Vlc1U&usp=sharing


Thanks in advance!
 
Solution
the third bugcheck was also a memory corruption in the ntkernel.

CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
fffff801ae8ff161-fffff801ae8ff162 2 bytes - nt!MiResolvePrivateZeroFault+211
[ 80 f6:00 93 ]
fffff801ae8ff18a-fffff801ae8ff18c 3 bytes - nt!MiResolvePrivateZeroFault+23a (+0x29)
[ 40 fb f6:80 49 93 ]
fffff801ae8ff1a9 - nt!MiResolvePrivateZeroFault+259 (+0x1f)
[ fa:95 ]
fffff801ae8ff84a - nt!MiCompletePrivateZeroFault+51a (+0x6a1)
[ fa:95 ]
fffff801ae8ff8df-fffff801ae8ff8e1 3 bytes - nt!MiCompletePrivateZeroFault+5af (+0x95)
[ 40 fb f6:80 49 93 ]
fffff801ae9028c3-fffff801ae9028c4 2 bytes - nt!MmAccessFault+b43 (+0x2fe4)
[ 80 f6:00 93 ]
fffff801aea07036-fffff801aea07037 2 bytes - nt! ...
the third bugcheck was also a memory corruption in the ntkernel.

CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
fffff801ae8ff161-fffff801ae8ff162 2 bytes - nt!MiResolvePrivateZeroFault+211
[ 80 f6:00 93 ]
fffff801ae8ff18a-fffff801ae8ff18c 3 bytes - nt!MiResolvePrivateZeroFault+23a (+0x29)
[ 40 fb f6:80 49 93 ]
fffff801ae8ff1a9 - nt!MiResolvePrivateZeroFault+259 (+0x1f)
[ fa:95 ]
fffff801ae8ff84a - nt!MiCompletePrivateZeroFault+51a (+0x6a1)
[ fa:95 ]
fffff801ae8ff8df-fffff801ae8ff8e1 3 bytes - nt!MiCompletePrivateZeroFault+5af (+0x95)
[ 40 fb f6:80 49 93 ]
fffff801ae9028c3-fffff801ae9028c4 2 bytes - nt!MmAccessFault+b43 (+0x2fe4)
[ 80 f6:00 93 ]
fffff801aea07036-fffff801aea07037 2 bytes - nt! ?? ::FNODOBFM::`string'+22da6 (+0x104773)
[ ff f6:7f 93 ]
14 errors : !nt (fffff801ae8ff161-fffff801aea07037)

generally when you have bad ram, it messes up different drivers because windows loads the drivers in to RAM in different orders on each boot. This looks like something is targeting the nt kernel for corruption. I would be looking for malware/rootkits and viruses.

-------------
second bugcheck was in USB code, anything attached to the USB ports could cause this bug.
no corrupted nt kernel in this bugcheck.
one very suspect driver installed:
C:\Users\benel\AppData\Local\Temp\ESEADriver2.sys Thu May 19 22:07:38 2016
uninstall if you have not done so:
https://www.reddit.com/r/GlobalOffensive/comments/1r2uca/how_to_uninstall_esea_client_remove_kernal_driver/

you might change your memory dump type to kernel memory dump, it will save the logs and info on the USB ports.
I have seen a system that was running some corsair link software that was logging 8 thousand USB error entries a second.
but you have to provide the kernel memory dump to check them. it just caused strange problems.

-chrome was running, you might turn off all chrome extensions
then start cmd.exe as an admin then run
sfc.exe /scannow
dism.exe /online /cleanup-image /restorehealth

this has a good chance to repair files if they are corrupted before they are loaded into memory.
if you have run memtest and it passes then you need to run a malwarebytes scan and a rootkit scan.
the system was up for 41 minutes before it bugchecked.

---------
system bugchecked because the windows kernel was modified in memory.
42 errors

CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
fffff801704482ca-fffff801704482cb 2 bytes - nt!MiDeleteBatch+6a
[ 80 fa:00 ed ]
fffff8017044832d-fffff8017044832e 2 bytes - nt!MiDeleteBatch+cd (+0x63)
[ 80 fa:00 ed ]
fffff801704483c7-fffff801704483c8 2 bytes - nt!MiDeleteBatch+167 (+0x9a)
[ 80 fa:00 ed ]
fffff80170448557-fffff80170448558 2 bytes - nt!MiInsertLargePageInFreeOrZeroList+57 (+0x190)
[ 80 fa:00 ed ]
fffff8017044880d-fffff8017044880e 2 bytes - nt!MiDeletePteRun+bd (+0x2b6)
[ 80 f6:00 b6 ]
fffff80170448821-fffff80170448822 2 bytes - nt!MiDeletePteRun+d1 (+0x14)
[ 80 fa:00 ed ]
fffff801704488c5-fffff801704488c6 2 bytes - nt!MiDeletePteRun+175 (+0xa4)
[ 80 fa:00 ed ]
fffff8017044895b-fffff8017044895c 2 bytes - nt!MiDeletePteRun+20b (+0x96)
[ 80 fa:00 ed ]
fffff801704489f6-fffff801704489f7 2 bytes - nt!MiDeletePteRun+2a6 (+0x9b)
[ 80 fa:00 ed ]
fffff80170448b29-fffff80170448b2a 2 bytes - nt!MiDeletePteRun+3d9 (+0x133)
[ 80 fa:00 ed ]
fffff80170448c9b-fffff80170448c9c 2 bytes - nt!MiDeletePteRun+54b (+0x172)
[ 80 f6:00 b6 ]
fffff80170448f3c-fffff80170448f3d 2 bytes - nt!MiInsertPageInList+6c (+0x2a1)
[ 80 fa:00 ed ]
fffff80170449812-fffff80170449814 3 bytes - nt!MiPfnShareCountIsZero+192 (+0x8d6)
[ 40 fb f6:00 5b b6 ]
fffff80170449836-fffff80170449837 2 bytes - nt!MiPfnShareCountIsZero+1b6 (+0x24)
[ 80 f6:00 b6 ]
fffff80170449856-fffff80170449859 4 bytes - nt!MiPfnShareCountIsZero+1d6 (+0x20)
[ a0 7d fb f6:80 2d 5b b6 ]
fffff80170449868-fffff8017044986c 5 bytes - nt!MiPfnShareCountIsZero+1e8 (+0x12)
[ d0 be 7d fb f6:c0 96 2d 5b b6 ]
fffff801704835ef-fffff801704835f0 2 bytes - nt!MiDeleteVirtualAddresses+9ff (+0x39d87)
[ 80 f6:00 b6 ]
fffff801705131fd-fffff801705131fe 2 bytes - nt!MiPurgeZeroList+6d (+0x8fc0e)
[ 80 fa:00 ed ]
42 errors : !nt (fffff801704482ca-fffff801705131fe)

machine info:
Vendor American Megatrends Inc.
BIOS Version V4.11
BIOS Starting Address Segment f000
BIOS Release Date 02/16/2016
Manufacturer MSI
Product Z97 PC Mate(MS-7850)
Version 1.0
Chassis Type Desktop
Version 1.0
Processor Version Intel(R) Core(TM) i5-4690K CPU @ 3.50GHz
Processor Voltage 8ch - 1.2V
External Clock 100MHz
Max Speed 3800MHz
Current Speed 3500MHz





 
Solution