This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

BSOD Windows 10

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello. I'm having trouble recently with my laptop. I am getting Blue Screen of death multiple times per day on my laptop. I believe that the issue stems from the Qualcomm Atheros driver which could be infected.

 

So far I've tried:

-aswMBR: I cannot run a full scan with this program because I get a BSOD every single time at the same point during the middle of the scan.

-Farbar Recovery Scan Tool. See the attached log.

 

Here is the OSR Online Log for the info on the latest system crash

 

Here is the log from OSR:

Crash Dump Analysis provided by OSR Open Systems Resources, Inc. (http://www.osr.com)
Online Crash Dump Analysis Service
See http://www.osronline.comfor more information
Windows 8 Kernel Version 17134 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 17134.1.amd64fre.rs4_release.180410-1804
Machine Name:
Kernel base = 0xfffff803`f8e1c000 PsLoadedModuleList = 0xfffff803`f91ca150
Debug session time: Thu Jan 10 00:50:07.319 2019 (UTC - 5:00)
System Uptime: 0 days 11:30:57.550
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Unknown bugcheck code (1d3)
Unknown bugcheck description
Arguments:
Arg1: 00000000000003eb
Arg2: 0000000000000000
Arg3: 0000000000000000
Arg4: 0000000000000000

Debugging Details:
——————

TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT

BUGCHECK_STR: 0x1D3

PROCESS_NAME: WINWORD.EXE

CURRENT_IRQL: 2

LAST_CONTROL_TRANSFER: from fffff80189d8f8a0 to fffff803f8fc60a0

STACK_TEXT:
ffffec8d`82e477f8 fffff801`89d8f8a0 : 00000000`000001d3 00000000`000003eb 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffffec8d`82e47800 fffff801`89d8f461 : 00000000`00000000 00000000`00000019 ffff9283`8a244040 fffff801`89e42bc8 : Qcamain10x64!ath_pcie_bug_check+0x3cc
ffffec8d`82e478b0 fffff801`89d9f35d : ffff9283`ffffffff 00000000`00000000 00000000`00001f45 00000000`00000000 : Qcamain10x64!ath_pci_targ_is_present+0x1f1
ffffec8d`82e47910 fffff801`89d9da8b : ffff9283`8a244040 00000000`00000001 ffff9283`8ad03030 ffff9283`8ae99030 : Qcamain10x64!HIFTargetSleepStateAdjust+0x14d
ffffec8d`82e47980 fffff801`89d867ba : ffff9283`8a371998 00000000`00016001 00000000`00000001 00000000`00000001 : Qcamain10x64!HIFDiagReadAccess+0x47
ffffec8d`82e479b0 fffff801`89d7bf69 : ffff9283`00000000 00000000`00000000 ffff34bf`63a4bde7 fffff801`89e31d50 : Qcamain10x64!OlGetLFTimer+0x4a
ffffec8d`82e479e0 fffff801`89dc5977 : ffff9283`8a371998 ffff9283`8ad03030 ffff9283`8a336030 fffff801`89e6e0b0 : Qcamain10x64!wmi_unified_cmd_send+0x42d
ffffec8d`82e47a50 fffff801`89cb5fe8 : 00000000`00000100 ffffec8d`82e47b10 fffff780`00000014 fffff780`00000014 : Qcamain10x64!ol_ath_hal_mib_stats_detach+0x2fb
ffffec8d`82e47ab0 fffff801`89cb480a : ffff9283`8ae94030 00000000`00025468 ffff9283`8ae94030 00000000`00000001 : Qcamain10x64!MpQueryFwStatistics+0x13c
ffffec8d`82e47b30 fffff801`89ca1065 : 01d4a8a8`573b3122 fffff801`89dd9880 ffffec8d`82e47bf0 fffff780`00000014 : Qcamain10x64!MpCheckLinkQuality+0x166
ffffec8d`82e47b80 fffff801`89cd630a : ffff9283`8a29d030 fffff803`000001f4 00000000`00000001 ffff9283`89dde490 : Qcamain10x64!StaStopWdiPeriodic+0x1c5
ffffec8d`82e47c20 fffff801`874e14dd : ffff9283`8a1eeb58 00000000`00000008 00000000`00000000 ffffa900`67522180 : Qcamain10x64!ndis_timer_handler+0x6a
ffffec8d`82e47c60 fffff803`f8e5bd69 : 00000000`00000006 00000060`868ee400 00000000`0000000a ffffa900`67522180 : ndis!ndisMTimerObjectDpc+0xcd
ffffec8d`82e47cb0 fffff803`f8e5aca7 : 00000000`00000004 848b4827`00000000 00000000`0023c37d 00000000`0000001a : nt!KiProcessExpiredTimerList+0x159
ffffec8d`82e47da0 fffff803`f8fccff5 : 481c0000`01182484 ffffa900`67522180 ffffec8d`8565fa80 00000000`00000000 : nt!KiRetireDpcList+0x4c7
ffffec8d`82e47fb0 fffff803`f8fccdf0 : 00000000`00000000 ffffdc89`6f4eb2e0 ffffdc89`6f4eb2e0 ffffdc89`7511f010 : nt!KxRetireDpcList+0x5
ffffec8d`8565f9d0 fffff803`f8fcc573 : ffff9283`8eea6080 00000000`00000000 00000000`00000000 ffff9283`8e3ba8e0 : nt!KiDispatchInterruptContinue
ffffec8d`8565fa00 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDpcInterrupt+0x2a3


STACK_COMMAND: kb

FOLLOWUP_IP:
Qcamain10x64!ath_pcie_bug_check+3cc
fffff801`89d8f8a0 cc int 3

SYMBOL_STACK_INDEX: 1

SYMBOL_NAME: Qcamain10x64!ath_pcie_bug_check+3cc

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: Qcamain10x64

IMAGE_NAME: Qcamain10x64.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 5811aaef

FAILURE_BUCKET_ID: X64_0x1D3_Qcamain10x64!ath_pcie_bug_check+3cc

BUCKET_ID: X64_0x1D3_Qcamain10x64!ath_pcie_bug_check+3cc

Followup: MachineOwner

 

Remove this program if present in bold via the Control Panel > Programs > Programs and Features.
App Explorer (HKU\S-1-5-19\…\Host App Service) (Version: 0.272.1.295 - SweetLabs)


Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Highlight the entire content of the quote box below and select Copy.

 

Start::
CloseProcesses:
CreateRestorePoint:
C:\Users\Munir Mohamed\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1104616864-340453819-3017920848-1001 -> DefaultScope {AD12DDCC-5463-4660-BE0F-7F8249126C05} URL =
SearchScopes: HKU\S-1-5-21-1104616864-340453819-3017920848-1001 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1104616864-340453819-3017920848-1001 -> {AD12DDCC-5463-4660-BE0F-7F8249126C05} URL =
Task: {0C19EE0B-F419-476D-9AB3-609118CA3DA0} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {577AF594-67C8-4F13-99C5-C53B2A8C1A4F} - System32\Tasks\App Explorer => C:\Users\Munir Mohamed\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [2018-12-11] (SweetLabs, Inc) <==== ATTENTION
C:\Windows\Temp\*.*
Emptytemp:
End::



Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

[external image: zcMPezJ.png]AdwCleaner - Fix Mode
  • Download AdwCleaner and move it to your Desktop
  • Right-click on AdwCleaner.exe and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the EULA (I accept), then click on Scan
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean & Repair button. This will kill all the active processes
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply
~~~~~~~~~~~~
[external image: RQKuhw1.png]RogueKiller
  • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
  • Once done, move the executable file to your Desktop, right-click on it and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply
created by Aura


please post these 3 logs when finished.
Let's check for remnants

you're already running Malwarebytes 3, open Malwarebytes and check for updates.
Then click on the Scan tab and select Threat Scan and click on Start Scan button.
If you don't have Malwarebytes 3 installed yet please download it from Malwarebytes Anti-Malware and install it.
  • If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
    Upon completion of the scan (or after the reboot), click the Reports tab.
    Double-click the Scan Log.
    At the bottom click Export and choose Text file.

    Save the file to your desktop and include its content in your next reply.

    You can access the logs by going in the "Reports" tab, clicking on the latest "Scan" entry (the one with detections), then clicking on the "Export" button in the bottom-left corner and select "Copy to clipboard". After that, all you have to do is paste it here
  • Then click on POST
  • Exit Malwarebytes
  • ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`

    [external image: G0tu5D9.png]Emsisoft Emergency Kit - Fix Mode
    Follow the instructions below to run a scan using the Emsisoft Emergency Kit.
  • Download the Emsisoft Emergency Kit and execute it. From there, click on the Install button to extract the program in the EEK folder;
  • Once the extraction is complete, the EEK folder will open. Right-click on [external image: G0tu5D9.png]start emergency kit scanner.exe and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • EEK will suggest that you run an online update before using the program. Click on Yes to launch it.
  • After the update, click on Malware Scan under 2. Scan and accept to let EEK detect PUPs (click on Yes).
  • Once the scan is complete, make sure that every item in the list is checked, and click on the Quarantine selected button;
  • If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
  • After the restart, open EEK again (in the C:\EEK folder);
  • This time, click on Logs;
  • From there, go under the Quarantine Log tab, and click on the Export button;
  • Save the log on your desktop, then open it, and copy/paste its content in your next reply;
**
Please post these 2 logs when finished.

Also, tell me how the computer is now.
Before trying to find and download any kind of drivers, try running chkdsk and scannow for windows 10
Disk Error Checking
https://www.thewindowsclub.com/disk-error-checking-windows-8

Scan Windows 10 Files with SFC /SCANNOW
http://www.tomshardware.com/faq/id-2866666/scan-windows-files-sfc-scannow.html

*****************************
check the laptop manufacturers website and look for your model and look for updates related to your version.

if you use a usb wireless device you have to update the motherboard bios, cpu chipset drivers, any usb 3.x chipset driver as well as the driver for the actual usb device. (since usb devices depend on all of these components, you never know where the error comes from)

Got a feeling you have a driver related to Qualcomm Atheros Driver that needs to be updated.
https://www.acer.com/ac/en/AU/content/drivers

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI