btw here is the dump file of one of the crashes
Loading Dump File [C:\Windows\Minidump\032219-7453-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 17763 MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 17763.1.amd64fre.rs5_release.180914-1434
Machine Name:
Kernel base = 0xfffff805
26ab6000 PsLoadedModuleList = 0xfffff805
26ed0a50
Debug session time: Fri Mar 22 22:16:51.106 2019 (UTC + 1:00)
System Uptime: 0 days 0:00:31.783
Loading Kernel Symbols
...............................................................
................................................................
..........................................
Loading User Symbols
Loading unloaded module list
........
***
***
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff80527378292, fffff6835b4c9ae0, 0}
Probably caused by : ntkrnlmp.exe ( nt!EtwpTrackBinaryForSession+5a )
Followup: MachineOwner
---------
0: kd> !analyze -v
***
***
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80527378292, Address of the instruction which caused the bugcheck
Arg3: fffff6835b4c9ae0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
KEY_VALUES_STRING: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 17763.1.amd64fre.rs5_release.180914-1434
SYSTEM_PRODUCT_NAME: To Be Filled By O.E.M.
SYSTEM_SKU: To Be Filled By O.E.M.
SYSTEM_VERSION: To Be Filled By O.E.M.
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: P1.60
BIOS_DATE: 11/05/2018
BASEBOARD_MANUFACTURER: ASRock
BASEBOARD_PRODUCT: B450M Pro4
BASEBOARD_VERSION:
DUMP_TYPE: 2
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff80527378292
BUGCHECK_P3: fffff6835b4c9ae0
BUGCHECK_P4: 0
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
FAULTING_IP:
nt!EtwpTrackBinaryForSession+5a
fffff805
27378292 8b4b10 mov ecx,dword ptr [rbx+10h]
CONTEXT: fffff6835b4c9ae0 -- (.cxr 0xfffff6835b4c9ae0)
rax=0000000000000082 rbx=006d006500740073 rcx=0000000000680070
rdx=0000000000000004 rsi=ffffb10a5e663a00 rdi=0000000000000082
rip=fffff80527378292 rsp=fffff6835b4ca4d0 rbp=ffffb10a5e663600
r8=0000000000000046 r9=0000000000000000 r10=ffffb10a58276cc0
r11=ffff858a53ce1b30 r12=0000000000000200 r13=fffff6835b4ca548
r14=0000000000000082 r15=ffffb10a5e6638c0
iopl=0 nv up ei pl nz na pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00210203
nt!EtwpTrackBinaryForSession+0x5a:
fffff805
27378292 8b4b10 mov ecx,dword ptr [rbx+10h] ds:002b:006d0065
00740083=????????
Resetting default scope
CPU_COUNT: c
CPU_MHZ: d42
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 8
CPU_STEPPING: 2
BLACKBOXBSD: 1 (!blackboxbsd)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: OneDrive.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-161S72E
ANALYSIS_SESSION_TIME: 03-22-2019 22:34:36.0890
ANALYSIS_VERSION: 10.0.17763.132 x86fre
LAST_CONTROL_TRANSFER: from fffff805272140fd to fffff80527378292
STACK_TEXT:
fffff683
5b4ca4d0 fffff805
272140fd : ffffb10a
5e663600 fffff683
5b4ca620 ffffb10a
58a2d4e8 00000000
00000000 : nt!EtwpTrackBinaryForSession+0x5a
fffff683
5b4ca520 fffff805
27253b8f : ffffb10a
588fdb01 ffffb10a
588fdb01 fffff683
5b4ca848 00000000
00000020 : nt!EtwpProviderArrivalCallback+0x1d5b91
fffff683
5b4ca7a0 fffff805
270dcdba : 00000000
00000000 00000000
00000000 00000000
00000000 00000000
00000000 : nt!EtwpAddRegEntryToGroup+0x176d4f
fffff683
5b4ca8c0 fffff805
270dcad9 : 00000000
00000000 fffff683
5b4cab80 00000000
00000000 00000000
00000800 : nt!EtwpSetProviderTraitsCommon+0x29a
fffff683
5b4ca970 fffff805
2716483d : ffffb10a
62719d30 00000000
0000001e 00000000
50777445 ffffb10a
62719d30 : nt!EtwpSetProviderTraitsUm+0x165
fffff683
5b4ca9f0 fffff805
26c78d85 : 00000000
0000001e 00000000
0078b7d0 00000000
00000018 00000000
0078b758 : nt!NtTraceControl+0x2cd
fffff683
5b4caa90 00007ff9
38022dd4 : 00000000
00000000 00000000
00000000 00000000
00000000 00000000
00000000 : nt!KiSystemServiceCopyEnd+0x25
00000000
0068e1a8 00000000
00000000 : 00000000
00000000 00000000
00000000 00000000
00000000 00000000
00000000 : 0x00007ff9
38022dd4
THREAD_SHA1_HASH_MOD_FUNC: 8cfb222ec320c8a472009a432fe1e000d16f5ea3
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: ae5dc5e7e1135e26410912aea39043bd343787d0
THREAD_SHA1_HASH_MOD: 30a3e915496deaace47137d5b90c3ecc03746bf6
FOLLOWUP_IP:
nt!EtwpTrackBinaryForSession+5a
fffff805`27378292 8b4b10 mov ecx,dword ptr [rbx+10h]
FAULT_INSTR_CODE: 49104b8b
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!EtwpTrackBinaryForSession+5a
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 10.0.17763.253
STACK_COMMAND: .cxr 0xfffff6835b4c9ae0 ; kb
BUCKET_ID_FUNC_OFFSET: 5a
FAILURE_BUCKET_ID: 0x3B_nt!EtwpTrackBinaryForSession
BUCKET_ID: 0x3B_nt!EtwpTrackBinaryForSession
PRIMARY_PROBLEM_CLASS: 0x3B_nt!EtwpTrackBinaryForSession
TARGET_TIME: 2019-03-22T21:16:51.000Z
OSBUILD: 17763
OSSERVICEPACK: 253
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 784
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
BUILDDATESTAMP_STR: 180914-1434
BUILDLAB_STR: rs5_release
BUILDOSVER_STR: 10.0.17763.1.amd64fre.rs5_release.180914-1434
ANALYSIS_SESSION_ELAPSED_TIME: 138c
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x3b_nt!etwptrackbinaryforsession
FAILURE_ID_HASH: {f845f069-25f1-8ca8-c8ca-e1181043caec}
Followup: MachineOwner
---------