LIVE_SYSTEM_DUMP
Code: 0x161 (353)
As HRESULT:- S: 0 (Success)
- C: 0 (Microsoft-defined)
- N: 0 (Not an NTSTATUS value)
- Facility: 0x000 (FACILITY_NULL: Default)
- Code: 0x0161 (353)
- Sev: 0 (STATUS_SEVERITY_SUCCESS)
- C: 0 (Microsoft-defined)
- Facility: 0x000 (Default)
- Code: 0x0161 (353)
Parameters
| Parameter | Description |
|---|---|
| 1 | 0x005461736b6d6772, which is a hexadecimal encoding of the text string 'Taskmgr'. |
| 2 | Reserved |
| 3 | Reserved |
| 4 | Reserved |
Description
The LIVE_SYSTEM_DUMP live dump has a value of 0x00000161. This indicates that the system administrator requested the collection of a live system memory dump.
(This code can never be used for a real bug check; it is used to identify live dumps.)
Remarks
Starting in Windows 22H2, version 25276, Task manager can be used to create a live system memory dump. For more information, see Task Manager live memory dump.
See also
Article text from the Windows driver documentation (opens in a new tab), by Microsoft, under the CC BY 4.0 (opens in a new tab) licence.
Associated Modules
| Module | Code | Found in | Description |
|---|---|---|---|
| EventCreate.exe | 0x161 | 78.11011 | %1 |
| KernelBase.dll | 0x161 | 78.1 | The maximum number of sessions has been reached. |
| kernel32.dll | 0x161 | 78.11011 | The maximum number of sessions has been reached. |
| webservices.dll | 0x161 | 78.11011 | The mime boundary '%1' was not be found, or it was not followed by CR/LF. |
| 4 entries | |||