Random system crash with blue screen

Hi, 

I am facing with a random system crash in my PC with a blue screen and not able to understand why. I am attaching the mini dump below. Appreciate if any of you guys can point me out what to look to resolve this issue 


Microsoft (R) Windows Debugger Version 10.0.19041.1 X86

Copyright (c) Microsoft Corporation. All rights reserved.



Loading Dump File [C:\Windows\Minidump\052620-26000-01.dmp]

Mini Kernel Dump File: Only registers and stack trace are available



************* Path validation summary **************

Response                         Time (ms)     Location

Deferred                                       srv*c:\MyServerSymbols*https://msdl.microsoft.com/download/symbols

Symbol search path is: srv*c:\MyServerSymbols*https://msdl.microsoft.com/download/symbols

Executable search path is: 

Windows 10 Kernel Version 18362 MP (8 procs) Free x64

Product: WinNt, suite: TerminalServer SingleUserTS

Built by: 18362.1.amd64fre.19h1_release.190318-1202

Machine Name:

Kernel base = 0xfffff803`37800000 PsLoadedModuleList = 0xfffff803`37c48170

Debug session time: Tue May 26 22:12:36.148 2020 (UTC + 4:00)

System Uptime: 4 days 3:57:21.826

Loading Kernel Symbols

...............................................................

................................................................

.......................................................

Loading User Symbols

Loading unloaded module list

..................................................

For analysis of this file, run !analyze -v

2: kd> !analyze -v

*******************************************************************************

*                                                                             *

*                        Bugcheck Analysis                                    *

*                                                                             *

*******************************************************************************


ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)

An attempt was made to write to readonly memory.  The guilty driver is on the

stack trace (and is typically the current instruction pointer).

When possible, the guilty driver's name (Unicode string) is printed on

the bugcheck screen and saved in KiBugCheckDriver.

Arguments:

Arg1: ffffec8c0200da80, Virtual address for the attempted write.

Arg2: 8a00000004700021, PTE contents.

Arg3: ffff9f8372405100, (reserved)

Arg4: 000000000000000a, (reserved)


Debugging Details:

------------------


*** WARNING: Unable to verify timestamp for win32k.sys


KEY_VALUES_STRING: 1


    Key  : Analysis.CPU.Sec

    Value: 4


    Key  : Analysis.DebugAnalysisProvider.CPP

    Value: Create: 8007007e on DESKTOP-OO6FDD8


    Key  : Analysis.DebugData

    Value: CreateObject


    Key  : Analysis.DebugModel

    Value: CreateObject


    Key  : Analysis.Elapsed.Sec

    Value: 32


    Key  : Analysis.Memory.CommitPeak.Mb

    Value: 71


    Key  : Analysis.System

    Value: CreateObject



BUGCHECK_CODE:  be


BUGCHECK_P1: ffffec8c0200da80


BUGCHECK_P2: 8a00000004700021


BUGCHECK_P3: ffff9f8372405100


BUGCHECK_P4: a


BLACKBOXBSD: 1 (!blackboxbsd)



BLACKBOXNTFS: 1 (!blackboxntfs)



BLACKBOXPNP: 1 (!blackboxpnp)



BLACKBOXWINLOGON: 1


CUSTOMER_CRASH_COUNT:  1


PROCESS_NAME:  System


TRAP_FRAME:  ffff9f8372405100 -- (.trap 0xffff9f8372405100)

NOTE: The trap frame does not contain all registers.

Some register values may be zeroed or incorrect.

rax=ffffec8000000000 rbx=0000000000000000 rcx=000000000004d738

rdx=0000000180401b50 rsi=0000000000000000 rdi=0000000000000000

rip=fffff803378b405c rsp=ffff9f8372405290 rbp=0000000fffffffff

 r8=fffffff000000000  r9=0000000000000001 r10=0000000fffffffff

r11=0000000000000000 r12=0000000000000000 r13=0000000000000000

r14=0000000000000000 r15=0000000000000000

iopl=0         nv up ei pl nz na pe nc

nt!MiUnlinkFreeOrZeroedPage+0x3ec:

fffff803`378b405c 48310cd0        xor     qword ptr [rax+rdx*8],rcx ds:ffffec8c`0200da80=????????????????

Resetting default scope


STACK_TEXT:  

ffff9f83`72404f18 fffff803`37a001e7 : 00000000`000000be ffffec8c`0200da80 8a000000`04700021 ffff9f83`72405100 : nt!KeBugCheckEx

ffff9f83`72404f20 fffff803`378c92ea : 8a000000`04700021 00000000`00000003 ffff9f83`72405060 00000000`00000000 : nt!MiRaisedIrqlFault+0x19e437

ffff9f83`72404f60 fffff803`379d041e : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x48a

ffff9f83`72405100 fffff803`378b405c : fffff803`37c6a440 00000000`00000010 00000000`00000000 ffffef80`000077a0 : nt!KiPageFault+0x35e

ffff9f83`72405290 fffff803`378b3929 : 00000000`003c7238 00000000`00000000 ffffec80`00000000 00000000`00000000 : nt!MiUnlinkFreeOrZeroedPage+0x3ec

ffff9f83`72405310 fffff803`378b2f71 : 00000000`00000000 00000000`00000001 00000000`00000000 fffff803`00000000 : nt!MiCoalesceFreePages+0x379

ffff9f83`72405390 fffff803`378aed16 : 00000000`003c7232 8a000003`c7232863 ffff8b0b`00000001 ffffd845`00000000 : nt!MiInsertPageInFreeOrZeroedList+0x231

ffff9f83`72405470 fffff803`378ac599 : 00000000`00000001 00000000`004d9eec 00002000`00000080 00000000`00000001 : nt!MiPfnShareCountIsZero+0x396

ffff9f83`724054d0 fffff803`378b54d9 : fffff803`37c68cc0 004dbeec`00002084 ffffd845`85963d90 00000000`00000000 : nt!MiDeleteValidSystemPage+0x1f9

ffff9f83`72405570 fffff803`3783538e : 00000000`00000000 ffff9f83`72405851 ffff8b0b`27e00100 00000000`000000fe : nt!MiDeleteSystemPagableVm+0x289

ffff9f83`72405740 fffff803`37835266 : 00000000`00000000 ffff9f83`724058e1 ffff8b0b`27e00100 00000000`00001000 : nt!MmFreePoolMemory+0xf6

ffff9f83`724057d0 fffff803`378351fa : 00000000`00000000 00000000`00000001 00000000`00000040 00000000`00000086 : nt!RtlpHpEnvFreeVA+0x12

ffff9f83`72405800 fffff803`378a9cd7 : 00000000`00001600 ffff8b0b`37300000 ffff8b0b`27e00100 00000000`0000003f : nt!RtlpHpFreeVA+0x3a

ffff9f83`72405840 fffff803`378a77a8 : ffff8b0b`2c700000 ffff8b0b`2c700000 ffff8b0b`27e00100 00000000`00000000 : nt!RtlpHpSegMgrCommit+0x207

ffff9f83`72405930 fffff803`378a625d : ffff8b0b`00007fff ffff8b0b`00000002 00000000`00000000 fffff803`000000fe : nt!RtlpHpSegPageRangeCommit+0x124

ffff9f83`724059c0 fffff803`37841f1c : ffff8b0b`00000000 00000000`00000000 ffff8b0b`2c700040 ffff8b0b`27e00340 : nt!RtlpHpSegPageRangeCoalesce+0x22d

ffff9f83`72405a40 fffff803`37841db8 : ffff8b0b`27e000ff ffff8b0b`27e00000 ffff8b0b`27e00280 ffff8b0b`27e00280 : nt!RtlpHpSegContextCompact+0x13c

ffff9f83`72405ab0 fffff803`378a45b1 : 00000000`00000003 ffff8b0b`27e00000 ffff8b0b`27e00000 ffff8b0b`32f2bb20 : nt!RtlpHpHeapCompact+0x84

ffff9f83`72405ae0 fffff803`378f43b5 : 00000000`00000000 ffffd984`00000002 ffffd984`0000003f 00000000`00000002 : nt!ExpHpCompactionRoutine+0x211

ffff9f83`72405b70 fffff803`3786bcd5 : ffffd984`59695040 00000000`00000080 ffffd984`40860080 00000000`00000080 : nt!ExpWorkerThread+0x105

ffff9f83`72405c10 fffff803`379c9998 : ffffa281`ad200180 ffffd984`59695040 fffff803`3786bc80 00730065`006c0069 : nt!PspSystemThreadStartup+0x55

ffff9f83`72405c60 00000000`00000000 : ffff9f83`72406000 ffff9f83`72400000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28



SYMBOL_NAME:  nt!MiRaisedIrqlFault+19e437


MODULE_NAME: nt


IMAGE_VERSION:  10.0.18362.836


STACK_COMMAND:  .thread ; .cxr ; kb


IMAGE_NAME:  memory_corruption


BUCKET_ID_FUNC_OFFSET:  19e437


FAILURE_BUCKET_ID:  0xBE_nt!MiRaisedIrqlFault


OS_VERSION:  10.0.18362.1


BUILDLAB_STR:  19h1_release


OSPLATFORM_TYPE:  x64


OSNAME:  Windows 10


FAILURE_ID_HASH:  {1c5b4d11-09e0-def3-d2d0-70a11d69b92d}


Followup:     MachineOwner

---------

 

Hi Ashan,
Unfortunately there is no information in this text about faulty driver.
Please run sfc /scannow command and check if it will find some errors.
Run driver verifier and share memory dumps to OneDrive for analysis.
https://support.microsoft.com/en-us/help/244617...
------------------
if you'll find someone's post helpful, mark it as an answer and rate it please. This will help other users to find answers to their similar questions.

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Hi Igor, 

Thanks for your reply. 

I have attached the minidump and the MOMORY.dmp file to below location 

https://1drv.ms/u/s!AhepJuXZM-rJnU7rogB6k2z8y6sj?e=7WN8me

Please let me know if you could identify the issue 

I will run the Driver Verifier and will keep you posted 

Regards, 

Ashan,  

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Unfortunately I see: This item might not exist or is no longer available
------------------
if you'll find someone's post helpful, mark it as an answer and rate it please. This will help other users to find answers to their similar questions.

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

 
 

Question Info


Last updated March 10, 2023 Views 509 Applies to: