Share via

Windows Mini Dump BSOD help please

Anonymous
2021-11-23T00:13:12+00:00

Sorry I've been frustrated with these bsods lately. But would you mind to check out this minidump? Would really appreciate it thanks!

Microsoft (R) Windows Debugger Version 10.0.22473.1005 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\WINDOWS\Minidump\112221-6968-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 22000 MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Machine Name:
Kernel base = 0xfffff801`60a1d000 PsLoadedModuleList = 0xfffff801`616466b0
Debug session time: Mon Nov 22 19:07:47.989 2021 (UTC - 5:00)
System Uptime: 0 days 0:01:16.768
Loading Kernel Symbols
...............................................................
................................................................
..............................................
Loading User Symbols
Loading unloaded module list
........
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff801`60e32590 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:ffffc000`61f1e7a0=000000000000003d
11: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

INTERRUPT_EXCEPTION_NOT_HANDLED (3d)
Arguments:
Arg1: ffffc00061f1f788
Arg2: ffffc00061f1efa0
Arg3: 0000000000000000
Arg4: 0000000000000000

Debugging Details:
------------------

KEY_VALUES_STRING: 1

    Key  : AV.Fault
    Value: Read

    Key  : Analysis.CPU.mSec
    Value: 3296

    Key  : Analysis.DebugAnalysisManager
    Value: Create

    Key  : Analysis.Elapsed.mSec
    Value: 3414

    Key  : Analysis.Init.CPU.mSec
    Value: 843

    Key  : Analysis.Init.Elapsed.mSec
    Value: 8299

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 87

FILE_IN_CAB:  112221-6968-01.dmp

DUMP_FILE_ATTRIBUTES: 0x8
  Kernel Generated Triage Dump

BUGCHECK_CODE:  3d

BUGCHECK_P1: ffffc00061f1f788

BUGCHECK_P2: ffffc00061f1efa0

BUGCHECK_P3: 0

BUGCHECK_P4: 0

EXCEPTION_RECORD:  ffffc00061f1f788 -- (.exr 0xffffc00061f1f788)
ExceptionAddress: fffff80160cf2131 (nt!KiInsertQueueDpc+0x00000000000002b1)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

CONTEXT:  ffffc00061f1efa0 -- (.cxr 0xffffc00061f1efa0)
rax=ffffac0aa299ada0 rbx=ffffc00061eb4180 rcx=f7ffac0ab5fb99e0
rdx=0000000000000020 rsi=ffffc00061eb74c0 rdi=fffff80161648b40
rip=fffff80160cf2131 rsp=ffffc00061f1f9c0 rbp=ffffc00061eb4180
 r8=fffff80160c5a1f0  r9=ffffac0aa29f92d0 r10=ffffffffffffffff
r11=0000000000000040 r12=00000000000000ff r13=000000000000ffff
r14=0000000000001331 r15=0000000000000001
iopl=0         nv up ei pl zr na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010246
nt!KiInsertQueueDpc+0x2b1:
fffff801`60cf2131 488b4108        mov     rax,qword ptr [rcx+8] ds:002b:f7ffac0a`b5fb99e8=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

READ_ADDRESS: fffff80161722450: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
 ffffffffffffffff 

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.

EXCEPTION_CODE_STR:  c0000005

EXCEPTION_STR:  0xc0000005

TRAP_FRAME:  ffffac0ab4ee9080 -- (.trap 0xffffac0ab4ee9080)
Unable to read trap frame at ffffac0a`b4ee9080

STACK_TEXT:  
ffffc000`61f1f9c0 fffff801`60cf50fe     : 00000000`00001300 00000000`00000000 00000000`2dc1f0bb 00000000`00000000 : nt!KiInsertQueueDpc+0x2b1
ffffc000`61f1fac0 fffff801`60cf63a2     : ffffa80c`e58b5ab0 00000000`00000000 fffff801`61648508 00000000`00000000 : nt!KiUpdateTime+0x6ee
ffffc000`61f1feb0 fffff801`60cf3cd2     : ffffa80c`e58b5ab0 ffffac0a`a294f210 ffffac0a`00000000 00000000`00000000 : nt!KeClockInterruptNotify+0x272
ffffc000`61f1ff40 fffff801`60caa6a0     : 00000000`2dd8accd ffffac0a`a294f160 00000000`00000001 ffffac0a`a2946040 : nt!HalpTimerClockInterrupt+0xe2
ffffc000`61f1ff70 fffff801`60e3419a     : ffffa80c`e58b5b30 ffffac0a`a294f160 00000000`00000000 ffffc000`61ec3000 : nt!KiCallInterruptServiceRoutine+0xa0
ffffc000`61f1ffb0 fffff801`60e34767     : 00000001`61eb0000 fffff801`ffffffff 00000000`2dd82515 00000000`00000000 : nt!KiInterruptSubDispatchNoLockNoEtw+0xfa
ffffa80c`e58b5ab0 fffff801`60e3649a     : 00000000`00000000 ffffc000`61ec0340 ffffac0a`b4ee9080 00000000`0000094c : nt!KiInterruptDispatchNoLockNoEtw+0x37
ffffa80c`e58b5c40 00000000`00000000     : ffffa80c`e58b6000 ffffa80c`e58b0000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a

SYMBOL_NAME:  nt!KiInsertQueueDpc+2b1

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  10.0.22000.318

STACK_COMMAND:  .cxr 0xffffc00061f1efa0 ; kb

BUCKET_ID_FUNC_OFFSET:  2b1

FAILURE_BUCKET_ID:  0x3D_c0000005_nt!KiInsertQueueDpc

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {8c8a417d-0eeb-8fb0-28ee-419636fb2cb9}

Followup:     MachineOwner
Windows for home | Windows 11 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

4 answers

Sort by: Most helpful
  1. Anonymous
    2021-11-23T03:52:12+00:00

    It's just the same process with Windows 11.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2021-11-23T02:18:52+00:00

    Sorry, however, is it plus or just normal? The link you sent me is for plus which I think is for non win 11?(Not completely sure sorry if I’m wrong)

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2021-11-23T00:54:01+00:00

    Hi hinfungcheng,

    I'm Paul and I'm here to help you with your concern.

    The dump file report indicates "MEMORY_CORRUPTION". This issue might be caused by faulty RAM/Memory.

    I recommend that you test the RAM using MEMTest86. Make sure to have at least 8 full passes for a near conclusive result.

    Follow the guide from the link below.

    https://www.tenforums.com/tutorials/14201-memte...

    Let me know the result.

    Thanks.


    Standard Disclaimer: There are links to non-Microsoft websites.

    The pages appear to be providing accurate, safe information. Watch out for ads on the sites that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the sites before you decide to download and install it.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2021-11-23T00:19:09+00:00

    Another one just in case

    2.
    Microsoft (R) Windows Debugger Version 10.0.22473.1005 AMD64
    Copyright (c) Microsoft Corporation. All rights reserved.
    
    Loading Dump File [C:\WINDOWS\Minidump\112221-7656-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available
    
    Symbol search path is: srv*
    Executable search path is: 
    Windows 10 Kernel Version 22000 MP (12 procs) Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS
    Machine Name:
    Kernel base = 0xfffff802`54a1d000 PsLoadedModuleList = 0xfffff802`556466b0
    Debug session time: Mon Nov 22 19:15:30.248 2021 (UTC - 5:00)
    System Uptime: 0 days 0:06:04.027
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ..............................................
    Loading User Symbols
    Loading unloaded module list
    ........
    For analysis of this file, run !analyze -v
    nt!KeBugCheckEx:
    fffff802`54e32590 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:ffffb906`8166f200=000000000000000a
    6: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    IRQL_NOT_LESS_OR_EQUAL (a)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high.  This is usually
    caused by drivers using improper addresses.
    If a kernel debugger is available get the stack backtrace.
    Arguments:
    Arg1: fffff78008000014, memory referenced
    Arg2: 00000000000000ff, IRQL
    Arg3: 00000000000000e2, bitfield :
    bit 0 : value 0 = read operation, 1 = write operation
    bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
    Arg4: fffff80254c3ec1b, address which referenced memory
    
    Debugging Details:
    ------------------
    
    KEY_VALUES_STRING: 1
    
        Key  : Analysis.CPU.mSec
        Value: 3984
    
        Key  : Analysis.DebugAnalysisManager
        Value: Create
    
        Key  : Analysis.Elapsed.mSec
        Value: 6170
    
        Key  : Analysis.Init.CPU.mSec
        Value: 843
    
        Key  : Analysis.Init.Elapsed.mSec
        Value: 26836
    
        Key  : Analysis.Memory.CommitPeak.Mb
        Value: 79
    
    FILE_IN_CAB:  112221-7656-01.dmp
    
    DUMP_FILE_ATTRIBUTES: 0x8
      Kernel Generated Triage Dump
    
    BUGCHECK_CODE:  a
    
    BUGCHECK_P1: fffff78008000014
    
    BUGCHECK_P2: ff
    
    BUGCHECK_P3: e2
    
    BUGCHECK_P4: fffff80254c3ec1b
    
    READ_ADDRESS: fffff80255722450: Unable to get MiVisibleState
    Unable to get NonPagedPoolStart
    Unable to get NonPagedPoolEnd
    Unable to get PagedPoolStart
    Unable to get PagedPoolEnd
    unable to get nt!MmSpecialPagesInUse
     fffff78008000014 
    
    CUSTOMER_CRASH_COUNT:  1
    
    PROCESS_NAME:  System
    
    TRAP_FRAME:  ffffb9068166f340 -- (.trap 0xffffb9068166f340)
    NOTE: The trap frame does not contain all registers.
    Some register values may be zeroed or incorrect.
    rax=00000000d9112f01 rbx=0000000000000000 rcx=00000000d910e0d6
    rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
    rip=fffff80254c3ec1b rsp=ffffb9068166f4d8 rbp=ffffb9068166f569
     r8=00000000d9112f1e  r9=fffff78008000014 r10=fffff78000000358
    r11=ffffd37d4e800000 r12=0000000000000000 r13=0000000000000000
    r14=0000000000000000 r15=0000000000000000
    iopl=0         nv up di pl zr na po nc
    nt!KiComputeNewSystemTime+0x2f:
    fffff802`54c3ec1b 4d8b09          mov     r9,qword ptr [r9] ds:fffff780`08000014=????????????????
    Resetting default scope
    
    STACK_TEXT:  
    ffffb906`8166f1f8 fffff802`54e451a9     : 00000000`0000000a fffff780`08000014 00000000`000000ff 00000000`000000e2 : nt!KeBugCheckEx
    ffffb906`8166f200 fffff802`54e41300     : ffffe380`628434c0 ffffe380`62840180 00000000`00000206 fffff802`54cf2314 : nt!KiBugCheckDispatch+0x69
    ffffb906`8166f340 fffff802`54c3ec1b     : fffff802`54c3eacc 00000000`00000000 ffffb906`8166f570 fffff780`00000340 : nt!KiPageFault+0x440
    ffffb906`8166f4d8 fffff802`54c3eacc     : 00000000`00000000 ffffb906`8166f570 fffff780`00000340 ffffce21`e9d47536 : nt!KiComputeNewSystemTime+0x2f
    ffffb906`8166f4e0 fffff802`54cf8d7c     : ffffe380`6269f180 ffffffff`ffffffff 00000000`00000000 00000000`00000000 : nt!KiUpdateTimeAssist+0x5c
    ffffb906`8166f520 fffff802`54cf72bf     : 00000000`00000019 00000000`00000003 ffffe380`6269f180 00000000`00000001 : nt!KeResumeClockTimerFromIdle+0x19c
    ffffb906`8166f5d0 fffff802`54cf6926     : fffff802`54e2e550 fffff802`54c3056a 00000000`00000000 00000000`00000000 : nt!PpmIdleExecuteTransition+0x80f
    ffffb906`8166fa70 fffff802`54e36494     : 00000000`00000000 ffffe380`626ab340 ffffbe04`9f4c7080 00000000`000006a4 : nt!PoIdle+0x3a6
    ffffb906`8166fc40 00000000`00000000     : ffffb906`81670000 ffffb906`8166a000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x54
    
    CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
        fffff80254c3ec07 - nt!KiComputeNewSystemTime+1b
    [ 00:08 ]
    1 error : !nt (fffff80254c3ec07)
    
    MODULE_NAME: memory_corruption
    
    IMAGE_NAME:  memory_corruption
    
    MEMORY_CORRUPTOR:  ONE_BIT
    
    STACK_COMMAND:  .cxr; .ecxr ; kb
    
    FAILURE_BUCKET_ID:  MEMORY_CORRUPTION_ONE_BIT
    
    OSPLATFORM_TYPE:  x64
    
    OSNAME:  Windows 10
    
    FAILURE_ID_HASH:  {e3faf315-c3d0-81db-819a-6c43d23c63a7}
    
    Followup:     memory_corruption
    ---------
    

    Was this answer helpful?

    0 comments No comments