Share via

Help with minidump analysis please!

Anonymous
2023-03-12T10:38:39+00:00

I have just installed Windows 11 and now getting BSOD.

ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
An attempt was made to write to readonly memory.  The guilty driver is on the
stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the BugCheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: ffffc28002de3538, Virtual address for the attempted write.
Arg2: 8a00000000200121, PTE contents.
Arg3: ffffa682f4dd1ad0, (reserved)
Arg4: 000000000000000a, (reserved)

Debugging Details:
------------------

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 1437

    Key  : Analysis.DebugAnalysisManager
    Value: Create

    Key  : Analysis.Elapsed.mSec
    Value: 1634

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 0

    Key  : Analysis.IO.Write.Mb
    Value: 0

    Key  : Analysis.Init.CPU.mSec
    Value: 187

    Key  : Analysis.Init.Elapsed.mSec
    Value: 9372

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 86

    Key  : Bugcheck.Code.DumpHeader
    Value: 0xbe

    Key  : Bugcheck.Code.Register
    Value: 0xbe

    Key  : Dump.Attributes.AsUlong
    Value: 1008

    Key  : Dump.Attributes.DiagDataWrittenToHeader
    Value: 1

    Key  : Dump.Attributes.ErrorCode
    Value: 0

    Key  : Dump.Attributes.KernelGeneratedTriageDump
    Value: 1

    Key  : Dump.Attributes.LastLine
    Value: Dump completed successfully.

    Key  : Dump.Attributes.ProgressPercentage
    Value: 0

FILE_IN_CAB:  031223-8203-01.dmp

DUMP_FILE_ATTRIBUTES: 0x1008
  Kernel Generated Triage Dump

BUGCHECK_CODE:  be

BUGCHECK_P1: ffffc28002de3538

BUGCHECK_P2: 8a00000000200121

BUGCHECK_P3: ffffa682f4dd1ad0

BUGCHECK_P4: a

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

TRAP_FRAME:  ffffa682f4dd1ad0 -- (.trap 0xffffa682f4dd1ad0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=3fffffffffffffff
rdx=ffffa150a85427f8 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8047624696f rsp=ffffa682f4dd1c60 rbp=0000000000000000
 r8=0000000000000000  r9=ffffa682f4dd1d20 r10=0000fffff804762b
r11=ffffc67e9b200000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz ac po cy
nt!MiWsleFlush+0x17f:
fffff804`7624696f f0490fba6f183f  lock bts qword ptr [r15+18h],3Fh ds:00000000`00000018=????????????????
Resetting default scope

STACK_TEXT:  
ffffa682`f4dd1958 fffff804`764c0350     : 00000000`000000be ffffc280`02de3538 8a000000`00200121 ffffa682`f4dd1ad0 : nt!KeBugCheckEx
ffffa682`f4dd1960 fffff804`7625769f     : 8a000000`00200121 00000000`00000003 ffffa682`f4dd1a69 00000000`00000000 : nt!MiRaisedIrqlFault+0x15fe90
ffffa682`f4dd19b0 fffff804`76439829     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x3af
ffffa682`f4dd1ad0 fffff804`7624696f     : 00000000`00040246 fffff804`762b9e9d 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x369
ffffa682`f4dd1c60 fffff804`762466f0     : fffff804`76c69380 fffff804`7eb92000 00000000`00000000 ffffa682`f4dd1d20 : nt!MiWsleFlush+0x17f
ffffa682`f4dd1d00 fffff804`762b7c9a     : ffffa682`f4dd23e0 ffffa17c`023f5c90 ffffa682`f4dd22e0 fffff804`76c69380 : nt!MiFreeWsleList+0xf0
ffffa682`f4dd1ed0 fffff804`7625bdf8     : 00000000`00000000 00000000`00000000 fffff804`76c69380 00000000`00000000 : nt!MiAgeWorkingSetTail+0x14a
ffffa682`f4dd1f10 fffff804`7625b9ed     : ffffa17c`00000000 00000000`00000000 00000000`00000000 fffff804`76c69380 : nt!MiWalkPageTablesRecursively+0xd38
ffffa682`f4dd1fa0 fffff804`7625b9ed     : ffffa150`00000000 00000000`00000000 00000000`00000001 fffff804`76c69380 : nt!MiWalkPageTablesRecursively+0x92d
ffffa682`f4dd2030 fffff804`7625b9ed     : ffffa150`00000000 00000000`00000000 00000000`00000002 fffff804`76c69380 : nt!MiWalkPageTablesRecursively+0x92d
ffffa682`f4dd20c0 fffff804`7627eab1     : 00000000`00000000 ffff9089`00000000 00000000`00000003 fffff804`76c69380 : nt!MiWalkPageTablesRecursively+0x92d
ffffa682`f4dd2150 fffff804`7627e53e     : ffffa682`f4dd23e0 ffff9089`00000002 00000000`00000001 00000000`00000000 : nt!MiWalkPageTables+0x371
ffffa682`f4dd2250 fffff804`7627dbd8     : 00000000`0000000a 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiAgeWorkingSet+0x45e
ffffa682`f4dd2760 fffff804`7627d53e     : fffff804`00000000 ffffa682`f4dd2a20 00000000`00000000 00000000`00000000 : nt!MiTrimOrAgeWorkingSet+0x298
ffffa682`f4dd2840 fffff804`763058f8     : 00000000`00000000 fffff804`76c6ae40 fffff804`76c6ae40 ffff9089`ebc572f0 : nt!MiProcessWorkingSets+0x76e
ffffa682`f4dd2a00 fffff804`763caf70     : 00000000`00000006 00000000`00000006 00000000`ffffffff ffff9089`ebded1c0 : nt!MiWorkingSetManager+0xe8
ffffa682`f4dd2ac0 fffff804`7620f4a7     : ffff9089`ebda9040 00000000`00000080 fffff804`76c6ae40 00000000`00000000 : nt!KeBalanceSetManager+0x150
ffffa682`f4dd2bb0 fffff804`7642dbb4     : fffff804`70ca8180 ffff9089`ebda9040 fffff804`7620f450 00000000`00000000 : nt!PspSystemThreadStartup+0x57
ffffa682`f4dd2c00 00000000`00000000     : ffffa682`f4dd3000 ffffa682`f4dcc000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x34

SYMBOL_NAME:  nt!MiRaisedIrqlFault+15fe90

MODULE_NAME: nt

IMAGE_VERSION:  10.0.22621.1265

STACK_COMMAND:  .cxr; .ecxr ; kb

IMAGE_NAME:  ntkrnlmp.exe

BUCKET_ID_FUNC_OFFSET:  15fe90

FAILURE_BUCKET_ID:  AV_nt!MiRaisedIrqlFault

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {3b24175f-7f5b-9c9f-8aaf-822c248bf0f5}

Followup:     MachineOwner
Windows for home | Windows 11 | Devices and drivers

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

1 answer

Sort by: Most helpful
  1. DaveM121 891.1K Reputation points Independent Advisor
    2023-03-12T11:10:44+00:00

    Hi Karl,

    I am Dave, I will help you with this.

    Please upload any minidump files you have, I will check those to see if they provide any insight into a potential cause of the system crashes.

    Open Windows File Explorer.

    Navigate to C:\Windows\Minidump

    Copy any minidump files onto your Desktop, then zip those up.

    Upload the zip file to the Cloud (OneDrive, DropBox... etc.), then choose to share those and get a share link.

    Then post the link here to the zip file, so we can take a look for you.

    Was this answer helpful?

    0 comments No comments