Diagnostics Tracking Service
Summary
Stopped working
Date
4/25/2015 5:24 AM
Status
Report sent
Description
Faulting Application Path: C:\Windows\System32\svchost.exe
Problem signature
Problem Event Name: BEX64
Application Name: svchost.exe_DiagTrack
Application Version: 6.3.9600.17415
Application Timestamp: 54504177
Fault Module Name: ntdll.dll
Fault Module Version: 6.3.9600.17736
Fault Module Timestamp: 550f4336
Exception Offset: 0000000000101e60
Exception Code: c000000d
Exception Data: 0000000000000000
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 5fed
Additional Information 2: 5fed1dc19b0b5b8869f78830d2f9c33f
Additional Information 3: d13f
Additional Information 4: d13fcc6b4725d4006af6fc4cc03ae846
Extra information about the problem
Bucket ID: 41c3d5e6ac6eef2be103571164aebd61 (81833233978)
John
Please run a system file check (SFC) & DISM if you are on win 8 or higherAll instructions are in our Wiki article below...
Should you have any questions please ask us.
System file check (SFC) Scan and Repair System Files
Date
4/27/2015 8:28 PM
Status
Report sent
Description
Faulting Application Path: C:\Windows\System32\svchost.exe
Problem signature
Problem Event Name: BEX64
Application Name: svchost.exe_DiagTrack
Application Version: 6.3.9600.17415
Application Timestamp: 54504177
Fault Module Name: ntdll.dll
Fault Module Version: 6.3.9600.17736
Fault Module Timestamp: 550f4336
Exception Offset: 0000000000101e60
Exception Code: c000000d
Exception Data: 0000000000000000
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 5fed
Additional Information 2: 5fed1dc19b0b5b8869f78830d2f9c33f
Additional Information 3: d13f
Additional Information 4: d13fcc6b4725d4006af6fc4cc03ae846
Extra information about the problem
Bucket ID: 41c3d5e6ac6eef2be103571164aebd61 (81833233978)
- Edited by Johnp57 20 hours 37 minutes ago
John
And the results of SFC & DISM were?
SFC found files but was unable to correct them It seems to happen only when I either shut down or rebooted
after defrag. When I reboot sometimes it will say wait till an app finishes click cancel to stop reboot but before i can click it close and rebooted after reboot then i was getting the ntdll.dll bex64 error I have been letting the computer run maintenance daily but for some reason after letting it run unattended I will come back to a computer that looks off (screen off no led lit on kb and laptop appears shutoff ) after trying hitting space key move mouse and tapping pw nothing but when i try power button it says after wards windows did not shutdown correctly here is last night reboot :
Source
Diagnostics Tracking Service
Summary
Stopped working
Date
4/27/2015 8:28 PM
Status
Report sent
Description
Faulting Application Path: C:\Windows\System32\svchost.exe
Problem signature
Problem Event Name: BEX64
Application Name: svchost.exe_DiagTrack
Application Version: 6.3.9600.17415
Application Timestamp: 54504177
Fault Module Name: ntdll.dll
Fault Module Version: 6.3.9600.17736
Fault Module Timestamp: 550f4336
Exception Offset: 0000000000101e60
Exception Code: c000000d
Exception Data: 0000000000000000
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 5fed
Additional Information 2: 5fed1dc19b0b5b8869f78830d2f9c33f
Additional Information 3: d13f
Additional Information 4: d13fcc6b4725d4006af6fc4cc03ae846
Extra information about the problem
Bucket ID: 41c3d5e6ac6eef2be103571164aebd61 (81833233978)
John
It is like pulling teeth. Did you run DISM? What were the results?
Date
4/27/2015 8:28 PM
Status
Report sent
Description
Faulting Application Path: C:\Windows\System32\svchost.exe
Problem signature
Problem Event Name: BEX64
Application Name: svchost.exe_DiagTrack
Application Version: 6.3.9600.17415
Application Timestamp: 54504177
Fault Module Name: ntdll.dll
Fault Module Version: 6.3.9600.17736
Fault Module Timestamp: 550f4336
Exception Offset: 0000000000101e60
Exception Code: c000000d
Exception Data: 0000000000000000
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 5fed
Additional Information 2: 5fed1dc19b0b5b8869f78830d2f9c33f
Additional Information 3: d13f
Additional Information 4: d13fcc6b4725d4006af6fc4cc03ae846
Extra information about the problem
Bucket ID: 41c3d5e6ac6eef2be103571164aebd61 (81833233978)
- Edited by Johnp57 Tuesday, April 28, 2015 10:45 AM
Date
4/27/2015 8:28 PM
Status
Report sent
Description
Faulting Application Path: C:\Windows\System32\svchost.exe
Problem signature
Problem Event Name: BEX64
Application Name: svchost.exe_DiagTrack
Application Version: 6.3.9600.17415
Application Timestamp: 54504177
Fault Module Name: ntdll.dll
Fault Module Version: 6.3.9600.17736
Fault Module Timestamp: 550f4336
Exception Offset: 0000000000101e60
Exception Code: c000000d
Exception Data: 0000000000000000
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 5fed
Additional Information 2: 5fed1dc19b0b5b8869f78830d2f9c33f
Additional Information 3: d13f
Additional Information 4: d13fcc6b4725d4006af6fc4cc03ae846
Extra information about the problem
Bucket ID: 41c3d5e6ac6eef2be103571164aebd61 (81833233978)
- Edited by Johnp57 Tuesday, April 28, 2015 10:45 AM
Date
4/27/2015 8:28 PM
Status
Report sent
Description
Faulting Application Path: C:\Windows\System32\svchost.exe
Problem signature
Problem Event Name: BEX64
Application Name: svchost.exe_DiagTrack
Application Version: 6.3.9600.17415
Application Timestamp: 54504177
Fault Module Name: ntdll.dll
Fault Module Version: 6.3.9600.17736
Fault Module Timestamp: 550f4336
Exception Offset: 0000000000101e60
Exception Code: c000000d
Exception Data: 0000000000000000
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 5fed
Additional Information 2: 5fed1dc19b0b5b8869f78830d2f9c33f
Additional Information 3: d13f
Additional Information 4: d13fcc6b4725d4006af6fc4cc03ae846
Extra information about the problem
Bucket ID: 41c3d5e6ac6eef2be103571164aebd61 (81833233978)
- Edited by Johnp57 Tuesday, April 28, 2015 10:45 AM
Date
4/27/2015 8:28 PM
Status
Report sent
Description
Faulting Application Path: C:\Windows\System32\svchost.exe
Problem signature
Problem Event Name: BEX64
Application Name: svchost.exe_DiagTrack
Application Version: 6.3.9600.17415
Application Timestamp: 54504177
Fault Module Name: ntdll.dll
Fault Module Version: 6.3.9600.17736
Fault Module Timestamp: 550f4336
Exception Offset: 0000000000101e60
Exception Code: c000000d
Exception Data: 0000000000000000
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 5fed
Additional Information 2: 5fed1dc19b0b5b8869f78830d2f9c33f
Additional Information 3: d13f
Additional Information 4: d13fcc6b4725d4006af6fc4cc03ae846
Extra information about the problem
Bucket ID: 41c3d5e6ac6eef2be103571164aebd61 (81833233978)
- Edited by Johnp57 Tuesday, April 28, 2015 10:45 AM
DISM WORKED and said fixed errors no problem start up this morning or first reboot how ever after check for
update defender I rebooteSource
Diagnostics Tracking Service
Summary
Stopped working
Date
4/29/2015 10:10 AM
Status
Report sent
Description
Faulting Application Path: C:\Windows\System32\svchost.exe
Problem signature
Problem Event Name: BEX64
Application Name: svchost.exe_DiagTrack
Application Version: 6.3.9600.17415
Application Timestamp: 54504177
Fault Module Name: ntdll.dll
Fault Module Version: 6.3.9600.17736
Fault Module Timestamp: 550f4336
Exception Offset: 0000000000101e60
Exception Code: c000000d
Exception Data: 0000000000000000
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 5fed
Additional Information 2: 5fed1dc19b0b5b8869f78830d2f9c33f
Additional Information 3: d13f
Additional Information 4: d13fcc6b4725d4006af6fc4cc03ae846
Extra information about the problem
Bucket ID: 41c3d5e6ac6eef2be103571164aebd61 (81833233978)
d
Hi,
It would be better to make system repair for test to fix this problem.
Source
Diagnostics Tracking Service
Summary
Stopped working
Date
5/4/2015 3:53 PM
Status
Report sent
Description
Faulting Application Path: C:\Windows\System32\svchost.exe
Problem signature
Problem Event Name: BEX64
Application Name: svchost.exe_DiagTrack
Application Version: 6.3.9600.17415
Application Timestamp: 54504177
Fault Module Name: ntdll.dll
Fault Module Version: 6.3.9600.17736
Fault Module Timestamp: 550f4336
Exception Offset: 0000000000101e60
Exception Code: c000000d
Exception Data: 0000000000000000
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 5fed
Additional Information 2: 5fed1dc19b0b5b8869f78830d2f9c33f
Additional Information 3: d13f
Additional Information 4: d13fcc6b4725d4006af6fc4cc03ae846
Extra information about the problem
Bucket ID: 41c3d5e6ac6eef2be103571164aebd61 (81833233978)
Source
Defraggler
Summary
Stopped working
Date
5/4/2015 6:35 PM
Status
Report sent
Description
Faulting Application Path: C:\Program Files\Defraggler\defraggler64.exe
Problem signature
Problem Event Name: BEX64
Application Name: defraggler64.exe
Application Version: 2.19.0.982
Application Timestamp: 54ef3a4f
Fault Module Name: dbghelp.dll_unloaded
Fault Module Version: 6.3.9600.17787
Fault Module Timestamp: 551b69ca
Exception Offset: 0000000000113a70
Exception Code: c0000005
Exception Data: 0000000000000008
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Additional Information 1: fd0a
Additional Information 2: fd0ad00033a12d76503e89d8bd3bdc8f
Additional Information 3: 7ed1
Additional Information 4: 7ed17301b40201fd56c386b271032cbd
Extra information about the problem
Bucket ID: 01ec41304c366bf7ee91d1553f1a1d70 (81854305673)
I have run SFC and Dism both say all ok
My question is now why can I reboot sometimes with no error but when I let the laptop do Maintenance from he Action Center daily unattended the system sometimes I get this.
The previous system shutdown at 11:29:47 AM on 5/4/2015 was unexpected.
THIS MORNING REBOOT IS NTDLL.DLL the culprit ?
Summary
Stopped working
Date
5/5/2015 6:47 AM
Status
Report sent
Description
Faulting Application Path: C:\Windows\System32\svchost.exe
Problem signature
Problem Event Name: BEX64
Application Name: svchost.exe_DiagTrack
Application Version: 6.3.9600.17415
Application Timestamp: 54504177
Fault Module Name: ntdll.dll
Fault Module Version: 6.3.9600.17736
Fault Module Timestamp: 550f4336
Exception Offset: 0000000000101e60
Exception Code: c000000d
Exception Data: 0000000000000000
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 5fed
Additional Information 2: 5fed1dc19b0b5b8869f78830d2f9c33f
Additional Information 3: d13f
Additional Information 4: d13fcc6b4725d4006af6fc4cc03ae846
Extra information about the problem
Bucket ID: 41c3d5e6ac6eef2be103571164aebd61 (81833233978)
Source
TOSHIBA PC Health Monitor
Summary
Stopped working
Date
5/5/2015 6:48 AM
Status
Report sent
Description
Faulting Application Path: C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
Problem signature
Problem Event Name: APPCRASH
Application Name: TPCHSrv.exe
Application Version: 1.0.0.30
Application Timestamp: 5388f40b
Fault Module Name: ntdll.dll
Fault Module Version: 6.3.9600.17736
Fault Module Timestamp: 550f4336
Exception Code: c0000005
Exception Offset: 000000000003d85e
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Additional Information 1: 0153
Additional Information 2: 01530bd571e369465b46e32a5c4f85c2
Additional Information 3: 4074
Additional Information 4: 40743d482acaca46039998365a2c43a7
Extra information about the problem
Bucket ID: 51d92063829a429117ff266d0148f4ed (86060681954)
Hi, Johnp57,
According to these information, the app, such as C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe, C:\Program Files\Defraggler\defraggler64.exe is not Windows built-in application. Please try to uninstall these app for test.
Actually, according to the name Defraggler, your former issue is most probably caused by this app.
Windows
Summary
Shut down unexpectedly
Date
5/9/2015 1:54 PM
Status
Solution available
Problem signature
Problem Event Name: BlueScreen
Code: 9f
Parameter 1: 3
Parameter 2: ffffe00048584e40
Parameter 3: fffff801ed185960
Parameter 4: ffffe0004f44ee10
OS version: 6_3_9600
Service Pack: 0_0
Product: 768_1
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Extra information about the problem
Bucket ID: 0x9F_3_SETPOWER_IMAGE_tunnel.sys
Please follow our instructions for finding and uploading the files we need to help you fix your computer. They can be found here If you have any questions about the procedure please ask
http://1drv.ms/1cDutPf MSINFO32
ran sfc
ran dism
ran sfc
result says found and fixed after last sfc
have cbs.log if need
JP
Thanks but we need the DMPS
http://1drv.ms/1AP3BBi
Graphics driver info
Last night I was checking email on my windows 8 tablet and as I was shutting it off I thought I'd look at it's Action center to see if any thing on it
I noticed the same error on it about a week before (the last time I used it)
They both are windows 8.1 and the only thing I saw in common was in MSCONFIG
selective start up was checked as default rather then normal
DMP FILE 5/11/2015
http://1drv.ms/1GYZzs7
MINIDUMP 5/11/2015
http://1drv.ms/1Fg4KsF
here is Dumps files
JP
These were Related toL1C63x64.sys Qualcomm Atheros Ar81xx series PCI-E Gigabit Ethernet Controller from Qualcomm Atheros Co., Ltd. I would completely remove the current driver and install the newest driver available
Microsoft (R) Windows Debugger Version 6.3.9600.17298 AMD64 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\Users\zigza\Desktop\MEMORY.DMP] Kernel Bitmap Dump File: Only kernel address space is available ************* Symbol Path validation summary ************** Response Time (ms) Location Deferred SRV*D:\Symbols*http://msdl.microsoft.com/download/symbols Symbol search path is: SRV*D:\Symbols*http://msdl.microsoft.com/download/symbols Executable search path is: Windows 8 Kernel Version 9600 MP (4 procs) Free x64 Product: WinNt, suite: TerminalServer SingleUserTS Personal Built by: 9600.17736.amd64fre.winblue_r9.150322-1500 Machine Name: Kernel base = 0xfffff803`08a8c000 PsLoadedModuleList = 0xfffff803`08d65850 Debug session time: Mon May 11 10:46:19.083 2015 (UTC - 4:00) System Uptime: 0 days 2:44:10.857 Loading Kernel Symbols ............................................................... ................................................................ ................................. Loading User Symbols Loading unloaded module list ........ ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 9F, {3, ffffe000ac9ae060, fffff8030a785960, ffffe000b0073810} Probably caused by : pci.sys Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* DRIVER_POWER_STATE_FAILURE (9f) A driver has failed to complete a power IRP within a specific time. Arguments: Arg1: 0000000000000003, A device object has been blocking an Irp for too long a time Arg2: ffffe000ac9ae060, Physical Device Object of the stack Arg3: fffff8030a785960, nt!TRIAGE_9F_POWER on Win7 and higher, otherwise the Functional Device Object of the stack Arg4: ffffe000b0073810, The blocked IRP Debugging Details: ------------------ DRVPOWERSTATE_SUBCODE: 3 IMAGE_NAME: pci.sys DEBUG_FLR_IMAGE_TIMESTAMP: 53d0f1d4 MODULE_NAME: pci FAULTING_MODULE: fffff80122400000 pci DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT BUGCHECK_STR: 0x9F PROCESS_NAME: System CURRENT_IRQL: 2 ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre DPC_STACK_BASE: FFFFF8030A78CFB0 STACK_TEXT: fffff803`0a785928 fffff803`08c94782 : 00000000`0000009f 00000000`00000003 ffffe000`ac9ae060 fffff803`0a785960 : nt!KeBugCheckEx fffff803`0a785930 fffff803`08c946a2 : ffffe000`b152d230 00000000`00000002 ffffe000`b152d268 fffff803`08b30391 : nt!PopIrpWatchdogBugcheck+0xde fffff803`0a785990 fffff803`08b322d8 : 00000000`00000000 fffff803`0a785ae0 00000000`00000001 00000000`00000002 : nt!PopIrpWatchdog+0x32 fffff803`0a7859e0 fffff803`08be07ea : fffff803`08d8f180 fffff803`08d8f180 fffff803`08de8a00 ffffe000`b30f8080 : nt!KiRetireDpcList+0x4f8 fffff803`0a785c60 00000000`00000000 : fffff803`0a786000 fffff803`0a780000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a STACK_COMMAND: kb FOLLOWUP_NAME: MachineOwner IMAGE_VERSION: 6.3.9600.17238 FAILURE_BUCKET_ID: 0x9F_3_POWER_DOWN_L1C63x64_IMAGE_pci.sys BUCKET_ID: 0x9F_3_POWER_DOWN_L1C63x64_IMAGE_pci.sys ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:0x9f_3_power_down_l1c63x64_image_pci.sys FAILURE_ID_HASH: {f819618d-04b8-e5ef-a00e-d488d01749b9} Followup: MachineOwner --------- 0: kd> !irp ffffe000b0073810, Irp is active with 4 stacks 3 is current (= 0xffffe000b0073970) No Mdl: No System Buffer: Thread 00000000: Irp stack trace. cmd flg cl Device File Completion-Context [ 0, 0] 0 0 00000000 00000000 00000000-00000000 Args: 00000000 00000000 00000000 00000000 [ 0, 0] 0 0 00000000 00000000 00000000-00000000 Args: 00000000 00000000 00000000 00000000 >[ 16, 2] 0 e1 ffffe000afbe5050 00000000 fffff80308e09b44-ffffe000b152d230 Success Error Cancel pending *** ERROR: Module load completed but symbols could not be loaded for L1C63x64.sys \Driver\L1C nt!PopSystemIrpCompletion Args: 00014400 00000000 00000004 00000002 [ 0, 0] 0 0 00000000 00000000 00000000-ffffe000b152d230 Args: 00000000 00000000 00000000 00000000
http://1drv.ms/1FiQTSk
today crash?
http://1drv.ms/1JeDdaY
Memory.dmp of today bootup
Windows
Summary
Shut down unexpectedly
Date
5/14/2015 9:06 AM
Status
Solution available
Problem signature
Problem Event Name: BlueScreen
Code: 9f
Parameter 1: 3
Parameter 2: ffffe0010e5dce20
Parameter 3: fffff80207385960
Parameter 4: ffffe00111cb1010
OS version: 6_3_9600
Service Pack: 0_0
Product: 768_1
OS Version: 6.3.9600.2.0.0.768.101
Locale ID: 1033
Extra information about the problem
Bucket ID: 0x9F_3_UNBIND_PROTOCOL_IMAGE_ndis.sys
Source: Service Control Manager
Date: 5/14/2015 3:45:09 PM
Event ID: 7031
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Spock
Description:
The Diagnostics Tracking Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
<EventID Qualifiers="49152">7031</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2015-05-14T19:45:09.022997200Z" />
<EventRecordID>28737</EventRecordID>
<Correlation />
<Execution ProcessID="636" ThreadID="804" />
<Channel>System</Channel>
<Computer>Spock</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">Diagnostics Tracking Service</Data>
<Data Name="param2">1</Data>
<Data Name="param3">30000</Data>
<Data Name="param4">1</Data>
<Data Name="param5">Restart the service</Data>
<Binary>440069006100670054007200610063006B000000</Binary>
</EventData>
</Event>
JP
Neither of the links are working. Try it again
Oops Sorry my bad I think I deleted them by error but I think it's been solved as I found out my printer
was not configuring Scan to Computer correctly. I ran HP Print Dr and followed it recommendation that I change the Dynamic to a static address on the net then it installed the scan to PC service and since then I have not had this error on boot up or reboot.
Thanks for helping me solve!
- Marked as answer by Johnp57 11 hours 11 minutes ago