Skip to content

Failures to dump (winpmem 4.0 rc2) related to pagefile size. #37

Open
@WarrenArthur

Description

@WarrenArthur

Greetings,

Report RE: WinPmem 4.0 RC (x64)

Summary:

When the pagefile on an Azure virtual machine, located on the secondary disk) is larger than 4GB, winpmem fails to dump. When it is <= 4GB, the dump works as expected.
The winpmem command is a regular dump, no additional arguments are presented to it.
This behavior is consistent.

The output on the console is as follows:
WinPmem64 Extracting driver to C:\Users\tadmin\AppData\Local\Temp\pmeB59A.tmp Driver Unloaded. Deleting C:\Users\tadmin\AppData\Local\Temp\pmeB59A.tmp Driver Unloaded.
The produced dump-file is present, but completely empty.
Is it possible to either fix this issue, or have winpmem at least output some more informative errors ?

Attachments:

WinDbg "Timeless Debugger" traces of two failures on the same machine.
Traces.zip

Machine details:

Installed Physical Memory (RAM) 4,00 GB
Total Physical Memory 4,00 GB
Available Physical Memory 1,96 GB
Total Virtual Memory 10,0 GB
Available Virtual Memory 7,53 GB
Page File Space 6,00 GB
Page File D:\pagefile.sys
Kernel DMA Protection Off
Virtualization-based security Not enabled
Hardware Abstraction Layer Version = "10.0.19041.964"
PCR7 Configuration Binding Not Possible
BaseBoard Version 7.0
BaseBoard Product Virtual Machine
BaseBoard Manufacturer Microsoft Corporation
BIOS Mode Legacy
SMBIOS Version 2.3
BIOS Version/Date American Megatrends Inc. 090008, 7.12.2018
Processor Intel(R) Xeon(R) Platinum 8272CL CPU @ 2.60GHz,
2594 Mhz, 2 Core(s), 2 Logical Processor(s)
System Type x64-based PC
System Manufacturer Microsoft Corporation
System Model Virtual Machine
System Name win10-21h1
OS Name Microsoft Windows 10 Pro
Version 10.0.19043 Build 19043
Experience Windows Feature Experience Pack 120.2212.2020.0

Memory Details:

Resource Device Status
0x0000-0x9FFFF System board OK
0xFFFC0000-0xFFFFFFFF System board OK
0xFEC00000-0xFEC00FFF Motherboard resources OK
0xFEE00000-0xFEE00FFF Motherboard resources OK
0xFF800000-0xFFFFFFFF Microsoft Hyper-V Video OK
0xE0000000-0xFFFFFFFF PCI Bus OK
0xF8000000-0xFBFFFFFF Microsoft Hyper-V S3 Cap OK
0xA0000-0xBFFFF PCI Bus OK
0xC0000-0xDFFFF System board OK
0xE0000-0xFFFFF System board OK
0x100000-0x3FFFFFFF System board OK
0x40000000-0xFFFBFFFF PCI Bus OK

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions