Home

Unable to understand the memory dump of Windows server 2012

Dayanand Gavas
Occasional Visitor

I have an VM and it was unresponsive so had an memory dump but unable to understand the dump so someone can help me on this please 

......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 80, {4f4454, 0, 0, 0}

Probably caused by : ntkrnlmp.exe ( nt!PpmIdleDefaultExecute+a )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

NMI_HARDWARE_FAILURE (80)
This is typically due to a hardware malfunction. The hardware supplier should
be called.
Arguments:
Arg1: 00000000004f4454
Arg2: 0000000000000000
Arg3: 0000000000000000
Arg4: 0000000000000000

Debugging Details:
------------------


DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT

BUGCHECK_STR: 0x80

PROCESS_NAME: System

CURRENT_IRQL: 0

ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) amd64fre

DPC_STACK_BASE: FFFFF8004FF27FB0

LAST_CONTROL_TRANSFER: from fffff8004e5b641e to fffff8004e42681f

STACK_TEXT:
fffff800`4ff209d8 fffff800`4e5b641e : ffffe001`de358250 ffffe001`de358010 00000000`00000000 fffff800`4e763180 : hal!HalProcessorIdle+0xf
fffff800`4ff209e0 fffff800`4e582cc3 : fffff800`4e763180 fffff800`4ff20a00 00000000`00000000 ffffe001`de358010 : nt!PpmIdleDefaultExecute+0xa
fffff800`4ff20a10 fffff800`4e4c3dd6 : fffff800`4e763180 fffff800`4ff20b4c fffff800`4ff20b50 fffff800`4ff20b58 : nt!PpmIdleExecuteTransition+0x3f3
fffff800`4ff20b10 fffff800`4e5d40fc : fffff800`4e763180 fffff800`4e763180 fffff800`4e7caa00 00000b14`00000000 : nt!PoIdle+0x2f6
fffff800`4ff20c60 00000000`00000000 : fffff800`4ff21000 fffff800`4ff1b000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x2c


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!PpmIdleDefaultExecute+a
fffff800`4e5b641e 33c0 xor eax,eax

SYMBOL_STACK_INDEX: 1

SYMBOL_NAME: nt!PpmIdleDefaultExecute+a

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 5accf215

BUCKET_ID_FUNC_OFFSET: a

FAILURE_BUCKET_ID: 0x80_nt!PpmIdleDefaultExecute

BUCKET_ID: 0x80_nt!PpmIdleDefaultExecute

ANALYSIS_SOURCE: KM

FAILURE_ID_HASH_STRING: km:0x80_nt!ppmidledefaultexecute

FAILURE_ID_HASH: {58acf3bd-67a3-5c4a-6586-345c82c9c5d7}

Followup: MachineOwner

1 Reply
Related Conversations
Extentions Synchronization
ChirmyRam in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies