Share via

Help to interpret and diagnose crash-log

Anonymous
2023-01-22T17:57:29+00:00

I swapped my RAM and M.2 SSD on my desktop. Afterwards, i did a clean Windows installation on my new SSD.
I do some video processing on my computer. After starting a process, it runs for a couple of hours before the computer crashes and reboots.
I need some help interpreting the crashlog, and figuring out why the computer crashes

012223-8078-01.dmp:

Microsoft (R) Windows Debugger Version 10.0.25200.1003 AMD64 Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Windows\Minidump\012223-8078-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv* Executable search path is: Windows 10 Kernel Version 22621 MP (8 procs) Free x64 Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0xfffff8066d200000 PsLoadedModuleList = 0xfffff8066de13010 Debug session time: Sun Jan 22 12:13:48.890 2023 (UTC + 1:00) System Uptime: 0 days 5:07:55.584 Loading Kernel Symbols ............................................................... ................................................................ ................................................................ ....................... Loading User Symbols Loading unloaded module list ............. For analysis of this file, run !analyze -v nt!KeBugCheckEx: fffff8066d628f20 48894c2408 mov qword ptr [rsp+8],rcx ss:ffffa00e430b6de0=000000000000001e 1: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * *******************************************************************************

KMODE_EXCEPTION_NOT_HANDLED (1e) This is a very common BugCheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: ffffffffc0000005, The exception code that was not handled Arg2: fffff8066d4579ec, The address that the exception occurred at Arg3: 0000000000000000, Parameter 0 of the exception Arg4: 0000000000000014, Parameter 1 of the exception

Debugging Details:

************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ExceptionRecord *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: ContextRecord *** *** *** *************************************************************************

KEY_VALUES_STRING: 1

Key  : Analysis.CPU.mSec
Value: 2609

Key  : Analysis.DebugAnalysisManager
Value: Create

Key  : Analysis.Elapsed.mSec
Value: 13377

Key  : Analysis.IO.Other.Mb
Value: 15

Key  : Analysis.IO.Read.Mb
Value: 0

Key  : Analysis.IO.Write.Mb
Value: 32

Key  : Analysis.Init.CPU.mSec
Value: 531

Key  : Analysis.Init.Elapsed.mSec
Value: 128085

Key  : Analysis.Memory.CommitPeak.Mb
Value: 99

Key  : Bugcheck.Code.DumpHeader
Value: 0x1e

Key  : Bugcheck.Code.Register
Value: 0x1e

Key  : Dump.Attributes.AsUlong
Value: 1008

Key  : Dump.Attributes.DiagDataWrittenToHeader
Value: 1

Key  : Dump.Attributes.ErrorCode
Value: 0

Key  : Dump.Attributes.KernelGeneratedTriageDump
Value: 1

Key  : Dump.Attributes.LastLine
Value: Dump completed successfully.

Key  : Dump.Attributes.ProgressPercentage
Value: 0

FILE_IN_CAB: 012223-8078-01.dmp

DUMP_FILE_ATTRIBUTES: 0x1008 Kernel Generated Triage Dump

BUGCHECK_CODE: 1e

BUGCHECK_P1: ffffffffc0000005

BUGCHECK_P2: fffff8066d4579ec

BUGCHECK_P3: 0

BUGCHECK_P4: 14

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: 0000000000000014

READ_ADDRESS: fffff8066df1c468: Unable to get MiVisibleState Unable to get NonPagedPoolStart Unable to get NonPagedPoolEnd Unable to get PagedPoolStart Unable to get PagedPoolEnd unable to get nt!MmSpecialPagesInUse 0000000000000014

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXPNP: 1 (!blackboxpnp)

BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: ffmpeg.exe

TRAP_FRAME: ffff800000000000 -- (.trap 0xffff800000000000) Unable to read trap frame at ffff8000`00000000

STACK_TEXT:
ffffa00e430b6dd8 fffff8066d413e0b : 000000000000001e ffffffffc0000005 fffff8066d4579ec 0000000000000000 : nt!KeBugCheckEx ffffa00e430b6de0 fffff8066d63e6fc : 0000000000001000 ffffa5897d0a2100 ffff800000000000 ffffa5897d0a2840 : nt!KiDispatchException+0x7eb ffffa00e430b74c0 fffff8066d639c0e : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!KiExceptionDispatch+0x13c ffffa00e430b76a0 fffff8066d4579ec : 0000000000000111 ffffa5897d0a2780 ffffeb00dbc3dd40 ffffa00e430b7858 : nt!KiPageFault+0x44e ffffa00e430b7830 fffff8066d45746b : 000000001b76e701 000001b700000000 ffffa00e00000003 0000000000000000 : nt!MiUserFault+0x19c ffffa00e430b78c0 fffff8066d639b29 : 0000000000000014 0000000000000000 000000000000dc80 ffffa58900000000 : nt!MmAccessFault+0x13b ffffa00e430b79e0 00007ffae3c9c70c : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!KiPageFault+0x369 000000a6b02fe920 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : 0x00007ffa`e3c9c70c

SYMBOL_NAME: nt!MiUserFault+19c

MODULE_NAME: nt

IMAGE_VERSION: 10.0.22621.1105

STACK_COMMAND: .cxr; .ecxr ; kb

IMAGE_NAME: ntkrnlmp.exe

BUCKET_ID_FUNC_OFFSET: 19c

FAILURE_BUCKET_ID: AV_R_nt!MiUserFault

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {b681fbe1-68ca-2a0a-e118-d33cbf3db9d5}

Followup: MachineOwner

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

5 answers

Sort by: Most helpful
  1. Anonymous
    2023-01-22T19:41:10+00:00

    Hi Simon, glad to help!

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-01-22T19:26:14+00:00

    Thank you. Il give that a go

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-01-22T19:20:14+00:00

    Hi Simon,

    Your minidump file just indicates memory (RAM) corruption while the ffmpeg encoder was running, no specific driver is listed

    The best option is to download the widely available free utility MemTest86, then run a full 4 pass scan with that to test your RAM for physical errors

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2023-01-22T19:11:19+00:00

    Here you go:
    012223-8078-01.dmp

    I also ran the Windows Memory Diagnostic tool for good meassure. It didnt encounter any errors

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2023-01-22T18:28:52+00:00

    Hi Simon,

    I am Dave, I will help you with this.

    Please upload any minidump files you have, I will check those to see if they provide any insight into a potential cause of the system crashes.

    Open Windows File Explorer.

    Navigate to C:\Windows\Minidump

    Copy any minidump files onto your Desktop, then zip those up.

    Upload the zip file to the Cloud (OneDrive, DropBox... etc.), then choose to share those and get a share link.

    Then post the link here to the zip file, so we can take a look for you.

    Was this answer helpful?

    0 comments No comments