okay, I am no longer getting BSOD's which means that I am no longer getting crash dump files, either. BUT,... I am getting freezes and system restarts with the same 6 events written in the event viewer over and over:
Log Name: System
Source: EventLog
Date: 7/10/2019 7:53:05 AM
Event ID: 6008
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: GOLIATH
Description:
The previous system shutdown at 7:49:50 AM on 7/10/2019 was unexpected.
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="EventLog" />
<EventID Qualifiers="32768">6008</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-07-10T14:53:05.590302900Z" />
<EventRecordID>796</EventRecordID>
<Channel>System</Channel>
<Computer>GOLIATH</Computer>
<Security />
</System>
<EventData>
<Data>7:49:50 AM</Data>
<Data>7/10/2019</Data>
<Data>
</Data>
<Data>
</Data>
<Data>15</Data>
<Data>
</Data>
<Data>
</Data>
<Binary>E307070003000A000700310032009C02E307070003000A000E00310032009C023C0000003C000000000000000000000000000000000000000000000000000000</Binary>
</EventData>
</Event>
--------------------------------------------------------------------------------------------------
Log Name: System
Source: Microsoft-Windows-Kernel-Power
Date: 7/10/2019 7:52:59 AM
Event ID: 41
Task Category: (63)
Level: Critical
Keywords: (70368744177664),(2)
User: SYSTEM
Computer: GOLIATH
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331c3b3a-2005-44c2-ac5e-77220c37d6b4}" />
<EventID>41</EventID>
<Version>6</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000400000000002</Keywords>
<TimeCreated SystemTime="2019-07-10T14:52:59.609452000Z" />
<EventRecordID>810</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>GOLIATH</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="BugcheckCode">0</Data>
<Data Name="BugcheckParameter1">0x0</Data>
<Data Name="BugcheckParameter2">0x0</Data>
<Data Name="BugcheckParameter3">0x0</Data>
<Data Name="BugcheckParameter4">0x0</Data>
<Data Name="SleepInProgress">0</Data>
<Data Name="PowerButtonTimestamp">0</Data>
<Data Name="BootAppStatus">0</Data>
<Data Name="Checkpoint">0</Data>
<Data Name="ConnectedStandbyInProgress">false</Data>
<Data Name="SystemSleepTransitionsToOn">0</Data>
<Data Name="CsEntryScenarioInstanceId">0</Data>
<Data Name="BugcheckInfoFromEFI">false</Data>
<Data Name="CheckpointStatus">0</Data>
</EventData>
</Event>
-------------------------------------------------------------------------------------------------------------------------------
Log Name: Security
Source: Microsoft-Windows-Eventlog
Date: 7/10/2019 7:53:05 AM
Event ID: 1101
Task Category: Event processing
Level: Error
Keywords: Audit Success
User: N/A
Computer: GOLIATH
Description:
Audit events have been dropped by the transport. 0
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Eventlog" Guid="{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" />
<EventID>1101</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>101</Task>
<Opcode>0</Opcode>
<Keywords>0x4020000000000000</Keywords>
<TimeCreated SystemTime="2019-07-10T14:53:05.715302500Z" />
<EventRecordID>1940</EventRecordID>
<Correlation />
<Execution ProcessID="1684" ThreadID="1872" />
<Channel>Security</Channel>
<Computer>GOLIATH</Computer>
<Security />
</System>
<UserData>
<AuditEventsDropped xmlns="
http://manifests.microsoft.com/win/2004/08/windows/eventlog">
<Reason>0</Reason>
</AuditEventsDropped>
</UserData>
</Event>
------------------------------------------------------------------------------------------------------
Log Name: System
Source: Service Control Manager
Date: 7/10/2019 7:53:13 AM
Event ID: 7023
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: GOLIATH
Description:
The WMPNetworkSvc service terminated with the following error:
An attempt was made to reference a token that does not exist.
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
<EventID Qualifiers="49152">7023</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2019-07-10T14:53:13.454599500Z" />
<EventRecordID>841</EventRecordID>
<Correlation />
<Execution ProcessID="780" ThreadID="976" />
<Channel>System</Channel>
<Computer>GOLIATH</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">WMPNetworkSvc</Data>
<Data Name="param2">%%1008</Data>
<Binary>57004D0050004E006500740077006F0072006B005300760063000000</Binary>
</EventData>
</Event>
-------------------------------------------------------------------------------------------------------------------------------------------
Log Name: Microsoft-Windows-PrintService/Admin
Source: Microsoft-Windows-PrintService
Date: 7/10/2019 7:53:13 AM
Event ID: 232
Task Category: Installing a printer driver
Level: Warning
Keywords: Printer Setup,Print Driver
User: SYSTEM
Computer: GOLIATH
Description:
An attempt was made to upgrade installed printer driver 'Microsoft Software Printer Driver' to an older version of the driver, which is unsupported. If the older version of the driver is required, please delete the current version (via Print Management or Print Server Properties) and try again.
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-PrintService" Guid="{747ef6fd-e535-4d16-b510-42c90f6873a1}" />
<EventID>232</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>19</Task>
<Opcode>13</Opcode>
<Keywords>0x8000000000000300</Keywords>
<TimeCreated SystemTime="2019-07-10T14:53:13.757172700Z" />
<EventRecordID>13</EventRecordID>
<Correlation />
<Execution ProcessID="3308" ThreadID="5932" />
<Channel>Microsoft-Windows-PrintService/Admin</Channel>
<Computer>GOLIATH</Computer>
<Security UserID="S-1-5-18" />
</System>
<UserData>
<SetupV4 xmlns="
http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events">
<DriverName>Microsoft Software Printer Driver</DriverName>
<InfPath>C:\WINDOWS\System32\DriverStore\FileRepository\prnms011.inf_amd64_abd7305d050d145e\prnms011.inf</InfPath>
<RequiredClassDriver>-</RequiredClassDriver>
<HResult>0x1</HResult>
</SetupV4>
</UserData>
</Event>
-----------------------------------------------------------------------------------------
Log Name: Microsoft-Windows-User Device Registration/Admin
Source: Microsoft-Windows-User Device Registration
Date: 7/10/2019 7:54:22 AM
Event ID: 360
Task Category: None
Level: Warning
Keywords:
User: GOLIATH\D-day
Computer: GOLIATH
Description:
Windows Hello for Business provisioning will not be launched.
Device is AAD joined ( AADJ or DJ++ ): Not Tested
User has logged on with AAD credentials: No
Windows Hello for Business policy is enabled: Not Tested
Windows Hello for Business post-logon provisioning is enabled: Not Tested
Local computer meets Windows hello for business hardware requirements: Not Tested
User is not connected to the machine via Remote Desktop: Yes
User certificate for on premise auth policy is enabled: Not Tested
Machine is governed by none policy.
See
https://go.microsoft.com/fwlink/?linkid=832647 for more details.
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-User Device Registration" Guid="{23b8d46b-67dd-40a3-b636-d43e50552c6d}" />
<EventID>360</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2019-07-10T14:54:22.471029200Z" />
<EventRecordID>19</EventRecordID>
<Correlation />
<Execution ProcessID="3876" ThreadID="3800" />
<Channel>Microsoft-Windows-User Device Registration/Admin</Channel>
<Computer>GOLIATH</Computer>
<Security UserID="S-1-5-21-1315368951-107084884-1376090125-1001" />
</System>
<EventData>
<Data Name="Message">Windows Hello for Business provisioning will not be launched.</Data>
<Data Name="DeviceIsJoined">Not Tested</Data>
<Data Name="AADPrt">No</Data>
<Data Name="NgcPolicyEnabled">Not Tested</Data>
<Data Name="NgcPostLogonProvisioningEnabled">Not Tested</Data>
<Data Name="NgcHardwarePolicyMet">Not Tested</Data>
<Data Name="UserIsRemote">Yes</Data>
<Data Name="LogonCertRequired">Not Tested</Data>
<Data Name="MachinePolicySource">none</Data>
</EventData>
</Event>