Windows 10: Windows 10 Memory dump file

Discus and support Windows 10 Memory dump file in Windows 10 BSOD Crashes and Debugging to solve the problem; I want help here to analyze this Memory.dmp file created. Microsoft R Windows Debugger Version 10.0.21306.1007 AMD64Copyright c Microsoft... Discussion in 'Windows 10 BSOD Crashes and Debugging' started by Bhim Charan Murmu, Mar 25, 2021.

  1. Windows 10 Memory dump file


    I want help here to analyze this Memory.dmp file created.


    [COLOR=rgba30, 30, 30, 1]Microsoft R Windows Debugger Version 10.0.21306.1007 AMD64Copyright c Microsoft Corporation. All rights reserved.Loading Dump File [C:\Windows\MEMORY.DMP]Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.************* Path validation summary **************Response Time ms LocationDeferred srv*Symbol search path is: srv*Executable search path is: Windows 10 Kernel Version 19041 MP 4 procs Free x64Product: WinNt, suite: TerminalServer SingleUserTSEdition build lab: 19041.1.amd64fre.vb_release.191206-1406Machine Name:Kernel base = 0xfffff802`16400000 PsLoadedModuleList = 0xfffff802`1702a490Debug session time: Thu Mar 25 20:56:13.587 2021 UTC + 5:30System Uptime: 5 days 23:19:52.727Loading Kernel Symbols........................................................................................................................................................................................................Loading User SymbolsLoading unloaded module list..................................................For analysis of this file, run [/COLOR][COLOR=rgba0, 0, 255, 1]!analyze -v[/COLOR][COLOR=rgba30, 30, 30, 1]nt!KeBugCheckEx:fffff802`167f5c50 48894c2408 mov qword ptr [rsp+8],rcx ss:fffff682`796ed740=000000000000013a0: kd> !analyze -v******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************KERNEL_MODE_HEAP_CORRUPTION 13aThe kernel mode heap manager has detected corruption in a heap.Arguments:Arg1: 0000000000000012, Type of corruption detectedArg2: ffff9f03eee02100, Address of the heap that reported the corruptionArg3: ffff9f03f276b000, Address at which the corruption was detectedArg4: 0000000000000000Debugging Details:------------------KEY_VALUES_STRING: 1 Key : Analysis.CPU.mSec Value: 18921 Key : Analysis.DebugAnalysisManager Value: Create Key : Analysis.Elapsed.mSec Value: 22862 Key : Analysis.Init.CPU.mSec Value: 2233 Key : Analysis.Init.Elapsed.mSec Value: 11144 Key : Analysis.Memory.CommitPeak.Mb Value: 73 Key : WER.OS.Branch Value: vb_release Key : WER.OS.Timestamp Value: 2019-12-06T14:06:00Z Key : WER.OS.Version Value: 10.0.19041.1BUGCHECK_CODE: 13aBUGCHECK_P1: 12BUGCHECK_P2: ffff9f03eee02100BUGCHECK_P3: ffff9f03f276b000BUGCHECK_P4: 0CORRUPTING_POOL_ADDRESS: ffff9f03f276b000 Nonpaged poolBLACKBOXBSD: 1 [/COLOR][COLOR=rgba0, 0, 255, 1]!blackboxbsd[/COLOR][COLOR=rgba30, 30, 30, 1]BLACKBOXNTFS: 1 [/COLOR][COLOR=rgba0, 0, 255, 1]!blackboxntfs[/COLOR][COLOR=rgba30, 30, 30, 1]BLACKBOXPNP: 1 [/COLOR][COLOR=rgba0, 0, 255, 1]!blackboxpnp[/COLOR][COLOR=rgba30, 30, 30, 1]BLACKBOXWINLOGON: 1PROCESS_NAME: SystemSTACK_TEXT: fffff682`796ed738 fffff802`1698da88 : 00000000`0000013a 00000000`00000012 ffff9f03`eee02100 ffff9f03`f276b000 : nt!KeBugCheckExfffff682`796ed740 fffff802`1698dae8 : 00000000`00000012 fffff682`796ed850 ffff9f03`eee02100 00000000`00000a44 : nt!RtlpHeapHandleError+0x40fffff682`796ed780 fffff802`1698d715 : ffff9f03`f277f4c0 ffff9f03`eee02280 ffff9f03`eee02100 fffff802`1664caf2 : nt!RtlpHpHeapHandleError+0x58fffff682`796ed7b0 fffff802`1682d5df : 00000000`00000000 ffffd38e`14000100 fffff802`17050d40 fffff802`1664cc64 : nt!RtlpLogHeapFailure+0x45fffff682`796ed7e0 fffff802`1664cc64 : 00000000`00000103 00000000`00000000 00000000`00000000 00000000`00000000 : nt!RtlpHpVsContextFree+0x1df48ffffff682`796ed880 fffff802`16db1019 : 00000000`00000000 00000000`00000000 00000000`00000000 01000000`00100000 : nt!ExFreeHeapPool+0x4d4fffff682`796ed960 fffff802`166b95ef : ffff9f03`f277f720 ffff9f03`f277f4e0 ffff9f03`f277f520 00000000`00000000 : nt!ExFreePool+0x9fffff682`796ed990 fffff802`166b6fb0 : 00000000`00000000 ffffd38e`2b58a1d0 ffff9f03`f277f4e0 01000000`00100000 : nt!MiDeleteControlArea+0x77fffff682`796ed9e0 fffff802`16a3e368 : 00000000`000000a6 00000000`000800a1 fffff802`17050d40 ffffd38e`2b58a1d0 : nt!MiDereferenceControlAreaProbe+0x24fffff682`796eda10 fffff802`167843bd : 00000000`00000001 00000000`00000000 fffff682`796edae0 ffff9f03`f277f4e8 : nt!MiSegmentDelete+0xf4fffff682`796eda60 fffff802`167b9249 : 00000000`00000000 fffff802`00000001 00000000`00000000 00000000`00000000 : nt!MiProcessDereferenceList+0xc1fffff682`796edb20 fffff802`16717e85 : ffff9f03`f215b040 ffff9f03`f215b040 00000000`00000080 fffff802`167b9120 : nt!MiDereferenceSegmentThread+0x129fffff682`796edd50 fffff802`167fd2a8 : fffff802`12859180 ffff9f03`f215b040 fffff802`16717e30 00000000`00000000 : nt!PspSystemThreadStartup+0x55fffff682`796edda0 00000000`00000000 : fffff682`796ee000 fffff682`796e8000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28SYMBOL_NAME: nt!ExFreePool+9IMAGE_NAME: Pool_CorruptionMODULE_NAME: [/COLOR][COLOR=rgba0, 0, 255, 1]Pool_Corruption[/COLOR][COLOR=rgba30, 30, 30, 1]STACK_COMMAND: .thread ; .cxr ; kbBUCKET_ID_FUNC_OFFSET: 9FAILURE_BUCKET_ID: 0x13a_12_nt!ExFreePoolOS_VERSION: 10.0.19041.1BUILDLAB_STR: vb_releaseOSPLATFORM_TYPE: x64OSNAME: Windows 10FAILURE_ID_HASH: {0e8bc89c-9b1f-e697-ed6c-83210db041e2}Followup: Pool_corruption---------[/COLOR]

    :)
     
    Bhim Charan Murmu, Mar 25, 2021
    #1
  2. garyinhere, Mar 25, 2021
    #2
  3. Ahhzz Win User
    Windows 10 Tweaks

    Pressing “Windows+Pause Break” (it’s up there next to scroll lock) opens the “System” Window.

    Windows 10: In the new version of Windows, Explorer has a section called Quick Access. This includes your frequent folders and recent files. Explorer defaults to opening this page when you open a new window. If you’d rather open the usual This PC, with links to your drives and library folders, follow these steps:

    • Open a new Explorer window.
    • Click View in the ribbon.
    • Click Options.
    • Under General, next to “Open File Explorer to:” choose “This PC.”
    • Click OK


    credit to Lifehacker.
     
    Ahhzz, Mar 25, 2021
    #3
  4. Windows 10 Memory dump file

    Windows 10 isnt creating memory dumps

    It should still be doing a dump whether it's just from kernel space or kernel plus user space. It's possible the crashes your PC is experiencing are not allowing for a memory dump to be created. It's happened to me before when I've been pushing my overclock to far. Instead of the sad face BSOD I've gotten a hard lockup that prevented a memory dump.

    This might be worth looking over.
    Configure Windows 10 to Create Minidump on BSOD
     
    biffzinker, Mar 25, 2021
    #4
Thema:

Windows 10 Memory dump file

Loading...
  1. Windows 10 Memory dump file - Similar Threads - Memory dump file

  2. Memory Dump File

    in Windows 10 Gaming
    Memory Dump File: My laptop blue screens about once every week and it is always a really quick blue screen flash and then restart so I don't have a chance to read the error message. I can never find my dumpfile after the crash. I have reinstalled windows on my computer and set it to automatic...
  3. Memory Dump File

    in Windows 10 Software and Apps
    Memory Dump File: My laptop blue screens about once every week and it is always a really quick blue screen flash and then restart so I don't have a chance to read the error message. I can never find my dumpfile after the crash. I have reinstalled windows on my computer and set it to automatic...
  4. Windows 10 Memory dump file

    in Windows 10 Gaming
    Windows 10 Memory dump file: I want help here to analyze this Memory.dmp file https://answers.microsoft.com/en-us/windows/forum/all/windows-10-memory-dump-file/e15f0139-df8b-4bce-82b5-bde2355921e8
  5. Windows 10 Memory dump file

    in Windows 10 Software and Apps
    Windows 10 Memory dump file: I want help here to analyze this Memory.dmp file https://answers.microsoft.com/en-us/windows/forum/all/windows-10-memory-dump-file/e15f0139-df8b-4bce-82b5-bde2355921e8
  6. Windows 10 Memory dump file

    in Windows 10 BSOD Crashes and Debugging
    Windows 10 Memory dump file: I want help here to analyze this Memory.dmp file https://answers.microsoft.com/en-us/windows/forum/all/windows-10-memory-dump-file/e15f0139-df8b-4bce-82b5-bde2355921e8
  7. Help with memory dump file

    in Windows 10 BSOD Crashes and Debugging
    Help with memory dump file: I recently swaped to a Ryzen 5 5600x and a B450 MOBO. I've been getting "MEMORY_MANAGEMENT" errors since. I managed to get a MEMORY.dmp file and I would like some help understanding it. Here is the link https://1drv.ms/u/s!ApiL3pED6bMyiAOa-kg1ZW7bDWTP?e=uhzwWg...
  8. PC Crash with Memory Dump File

    in Windows 10 BSOD Crashes and Debugging
    PC Crash with Memory Dump File: Posted about this before, though this time I think I've narrowed down the problem. Just need someone to take a look at the memory dump file to confirm. Basically my PC will sometimes randomly crash, just freezing and then the screen goes black but it just sits there with...
  9. Memory dump

    in Windows 10 Installation and Upgrade
    Memory dump: Does anyone have an idea what this means The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0x0000000000000008, 0x0000000000000002, 0x0000000000000000, 0xfffff80f1d427218). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id:...
  10. Memory dump files PLEASE HELP :(

    in Windows 10 BSOD Crashes and Debugging
    Memory dump files PLEASE HELP :(: Hi all! Last week this problem popped up. I try to copy any text and then paste it and this piece of text gets pasted intead of my text...