Updated: October 2026
When a PC blue-screens at random and the drivers check out, RAM is the cheapest part to rule out. Windows already ships a test for it, though it hides the result and a clean pass proves less than it looks. Here's how to run the Windows Memory Diagnostic tool, find what it logged, and decide when to reach for MemTest86 or a screwdriver instead.
When the RAM Is Worth Testing
Bad memory rarely fails in one clean way. It corrupts whatever happens to sit on the broken cells, so the symptoms look random.
Test the RAM when you see stop codes that change from crash to crash: MEMORY_MANAGEMENT, PFN_LIST_CORRUPT, IRQL_NOT_LESS_OR_EQUAL, each blaming a different driver. Other signs are zip files that fail their CRC check, installers that crash at a different point every time, and crashes that only show up under load. Any PC that just had RAM added, swapped, or overclocked with an XMP profile belongs on the list too.
Servers and workstations with ECC memory are different. They correct single-bit errors on the fly and log them, so check the System log and the vendor's management controller (iDRAC, iLO and the like) for corrected-error warnings before you book downtime for a boot test.
If one driver shows up in every dump, start there instead. Our guide to the blue screen of death covers reading the dump and finding it.
How to Run Windows Memory Diagnostic
Press Win+R, type mdsched.exe and press Enter. Windows offers two choices: restart now and check, or check the next time the PC starts. Save open work first, because the test runs outside Windows after a reboot.
The blue test screen starts with the defaults: the Standard test mix and two passes. Press F1 to change them. Tab moves between the three settings, and F10 applies them.
- Test mix. Basic runs three quick tests. Standard, the default, adds five more. Extended adds another batch of patterns and can run for hours on a machine with a lot of RAM.
- Cache. Default lets each test pick. Leave it alone unless you're chasing a specific fault.
- Pass count. Two by default. Zero means it loops until you stop it, which suits an overnight run.
For a first look, Standard with two passes is fine. For a PC that crashes once a week, run Extended overnight. Keep laptops on AC power, and press Esc if you need to cancel.
Microsoft's ITOpsTalk channel walks through the tool, the options and the results in a few minutes.
The three mixes trade time for coverage. Match the mix to how often the fault shows up.
Running It on a Machine You Can't Touch
The test runs before Windows loads, so your remote session drops the moment the PC restarts. You won't see the progress screen. You'll see the result once the machine is back online.
You don't need the user to click anything either. The memory tester is a boot entry of its own, listed as {memdiag} in Microsoft's BCD reference. From an elevated prompt, bcdedit /bootsequence {memdiag} sets it for the next boot only, and shutdown /r /t 0 starts it. The PC runs the default test, boots back into Windows and logs the result.
This r/sysadmin thread asks the same question about a machine behind TeamViewer. The top reply is the built-in tool, and the reason is that it doesn't need a USB stick in the port.
Schedule it for after hours and tell the user the PC will restart. OpenFrame can push the bcdedit line and the results query below as scripts across a client's devices, so a fleet check is one job instead of a remote session per PC.
Where to Find Windows Memory Diagnostic Results
After the reboot, Windows shows the result as a notification once someone signs in. It disappears in seconds, and nobody sees it on a remote machine. The copy that stays is in the System event log.
Open Event Viewer, go to Windows Logs, then System, and choose Filter Current Log. Pick MemoryDiagnostics-Results as the event source. Event 1201 says the test detected no errors. Event 1202 says it found hardware problems. Each run also writes a companion event at the same second, 1101 or 1102, and that one carries the detail. Our memory diagnostic results guide covers missing events and what each field means.
The 1202 message doesn't say which module failed. It tells you the memory has a problem, and the isolation steps further down tell you where.
PowerShell gets you there faster, and it works remotely:
Get-WinEvent -FilterHashtable @{LogName='System'; ProviderName='Microsoft-Windows-MemoryDiagnostics-Results'} | Select-Object TimeCreated, Id, Message
No event at all means the test didn't finish. Someone pressed Esc, the power dropped, or the PC never booted into the tester. Check the time on the newest event too, so you're not reading last year's pass.
What a Pass Proves, and What It Doesn't
A fail is worth acting on. Memory tests don't invent errors, so a 1202 means at least one module, slot or memory setting is bad. Pull the sticks apart and find which one, as shown below.
A pass is weaker. It covers one run, at boot, with the machine cool and nothing else loaded. A stick that fails when it's warm, or only at XMP speed, can pass a morning test and crash the same afternoon.
It also cuts the other way between tools. In this r/techsupport thread from April 2026, the built-in tool flagged hardware errors while the poster's technician ran MemTest86 several times and found nothing. The RAM went back under RMA, and the manufacturer found the errors.
So act on any failing test, whichever tool ran it, and treat a pass as one data point. If the crashes continue, keep testing.
MemTest86 and the One-Stick Test
When the built-in tool passes and the crashes don't stop, boot MemTest86 or the open-source Memtest86+ from a USB stick. Both run more patterns, loop through several passes, and show the failing address as it happens. They need someone at the keyboard, or at least a USB stick in the port.
Before a long test, reset memory to its default speed. If the crashes stop with XMP off, the modules may be fine and the overclock isn't stable on that board.
Then isolate. Remove all but one stick, and test it, or use the PC normally for a day. Swap in the next stick, same slot. If one stick fails in every slot, replace the stick. If every stick fails in one slot, the fault is the slot or the board. Reseat each module firmly on the way, since a stick that's half out of its slot can fail the same way a broken one does.
Test First, Then Order Parts
Run Windows Memory Diagnostic, read event 1201 or 1202 instead of waiting for a notification, and treat a pass as one data point. Escalate to MemTest86 and one-stick tests when the crashes continue. Replace a module only once one stick fails on its own, so the new part fixes the fault instead of hiding a bad slot.
If the RAM comes back clean every way you test it, look at the operating system next. Our DISM RestoreHealth guide covers repairing a corrupted Windows image.

"Fae" Grace Meadows
Lead AI Fairy
Some things defy easy explanation: magic dust, the northern lights… and Flamingo’s AI Angels. Think Charlie’s Angels, reimagined with automation brains and serious RMM (Remote Monitoring & Management) chops. Weird? A little. Effective? Absolutely. That’s the job.
