Solved How do I use WinDBG to properly analyze a kernal memory dump?

ThatBenderGuy

New member
Local time
3:19 PM
Messages
23
I've started getting in to analyzing my own memory dumps with WinDBG but the problem is I don't know which commands to use to properly utilize its features. For instance, (forgive me if I sound noobish about this I'm new to analyzing them) how do I view the call stacks for seeing if the probable cause lies in there?

For instance just opening the Kernel Dump in WinDbg tells me the probable cause is "ntkrnlmp.exe" But I doubt that it's the real cause of the BSOD.

Any tips would be appreciated and I apologize if this is in the wrong topic.

EDIT:
Also could anyone tell me if this driver seems to be the cause of this particular blue screen? This is the call stacks

fffff880`04306790 fffff880`04e1e9d3 dxgmms1!VIDMM_GLOBAL::ReferenceAllocationForSubmission+0xa3
fffff880`043067d0 fffff880`04e387d9 dxgmms1!VIDMM_GLOBAL::PrepareDmaBuffer+0xe1b
fffff880`043069a0 fffff880`04e38514 dxgmms1!VidSchiSubmitRenderCommand+0x241
fffff880`04306b90 fffff880`04e38012 dxgmms1!VidSchiSubmitQueueCommand+0x50
fffff880`04306bc0 fffff800`0332d73a dxgmms1!VidSchiWorkerThread+0xd6
fffff880`04306c00 fffff800`030828e6 nt!PspSystemThreadStartup+0x5a
fffff880`04306c40 00000000`00000000 nt!KxStartSystemThread+0x16

Thanks again for any information
 

My Computer My Computer

At a glance

Windows 7 Professional 64-bitIntel Core i3 212012.0GB Dual-Channel DDR3 @ 686MHz2047MB NVIDIA GeForce GTX 650 Ti BOOST (EVGA)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional 64-bit
CPU
Intel Core i3 2120
Motherboard
ASUSTeK P8Z77-M
Memory
12.0GB Dual-Channel DDR3 @ 686MHz
Graphics Card(s)
2047MB NVIDIA GeForce GTX 650 Ti BOOST (EVGA)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
DELL E228WFP
Screen Resolution
1680x1050
Hard Drives
149GB Seagate SATA
932GB Seagate SATA
Antivirus
Malware-Bytes
Browser
Google Chrome

My Computer My Computer

At a glance

Win 10 Pro x64Intel I5-2500K @3.3GHz16GB G.Skill Ripjaws X (4x4GB)EVGA GeForce 750 Ti SC 2GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
Thanks for the links, WinDbg actually told me that the probable cause for my latest one wasn't a driver but it said the probable cause was "Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+1df )"

That's the first time I've ever seen that type of possible cause, it's usually a .sys file. What on earth does "Pool_Corruption" mean?
 

My Computer My Computer

At a glance

Windows 7 Professional 64-bitIntel Core i3 212012.0GB Dual-Channel DDR3 @ 686MHz2047MB NVIDIA GeForce GTX 650 Ti BOOST (EVGA)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional 64-bit
CPU
Intel Core i3 2120
Motherboard
ASUSTeK P8Z77-M
Memory
12.0GB Dual-Channel DDR3 @ 686MHz
Graphics Card(s)
2047MB NVIDIA GeForce GTX 650 Ti BOOST (EVGA)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
DELL E228WFP
Screen Resolution
1680x1050
Hard Drives
149GB Seagate SATA
932GB Seagate SATA
Antivirus
Malware-Bytes
Browser
Google Chrome
The probably caused by can be misleading, specially when it points out a microsoft driver. Pool Corruption is a reference to memory,

The bugcheck is also important to look at, the link I gave you for that will show you usual causes for that bugcheck.

The other link with the !thread command is useful for digging deeper than the "Probably caused by" output.

Looking at the Kernel dump in your other thread here, http://www.sevenforums.com/bsod-hel...eague-legends-ntoskrnl-exe-4.html#post2799325

It has a bugcheck of 3b,

Code:
BugCheck 3B, {c0000005, fffff8000309a97c, fffff8800ab88ff0, 0}

Probably caused by : ntkrnlmp.exe ( nt!KeWaitForSingleObject+17c )

Followup: MachineOwner
---------

And the probably caused by is a microsoft file, you can be 99% sure that is not the actual cause.

Looking at the bugcheck 3b usual causes here, BSOD Index

Usual causes: System service, Device driver, graphics driver, ?memory

The next step is look for an offending driver, testing your RAM with Memtest86+ would be good too to rule that out.

Try the instructions for the !thread command I pointed you to here,

http://www.sevenforums.com/crash-lockup-debug-how/277355-debugging-bsod-my-way.html#post2329908

You will see a few drivers, let me know what you find.
 

My Computer My Computer

At a glance

Win 10 Pro x64Intel I5-2500K @3.3GHz16GB G.Skill Ripjaws X (4x4GB)EVGA GeForce 750 Ti SC 2GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
ntkrnlmp.exe is the kernel memory handler for 64-bit address (Non-PAE). As already mentioned by Derek, this is rarely the "cause" of the error. More often than not, it's the "result" of bad data passed to it. As in the example above, it accepted a string object or pool address. The rest is a domino effect but more often than not, it's caused by an errant driver. Not always the video driver, but usually is when the DX driver is involved. Can also be malware, an AV scanner or temperature related (physical memory starts breaking down).

The suggestions given by Derek are right on track and I can't add any more. :geek:
 

My Computer My Computer

At a glance

Windows 7 Pro-x64i7-2600 3.4GHz - 3.8GHz Turbo8Gb - 2x4GB, Muskin 991770 PC3-1333Integrated Intel HD 2000
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
Alright guys thanks for all your help!
 

My Computer My Computer

At a glance

Windows 7 Professional 64-bitIntel Core i3 212012.0GB Dual-Channel DDR3 @ 686MHz2047MB NVIDIA GeForce GTX 650 Ti BOOST (EVGA)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional 64-bit
CPU
Intel Core i3 2120
Motherboard
ASUSTeK P8Z77-M
Memory
12.0GB Dual-Channel DDR3 @ 686MHz
Graphics Card(s)
2047MB NVIDIA GeForce GTX 650 Ti BOOST (EVGA)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
DELL E228WFP
Screen Resolution
1680x1050
Hard Drives
149GB Seagate SATA
932GB Seagate SATA
Antivirus
Malware-Bytes
Browser
Google Chrome
Back
Top