"...the examiner found a hit in C:\Windows\MEMORY.DMP. This file stores debug information when a system failure occurs."
Seems to be generated on a previous system failure.
Seems to be generated on a previous system failure.
http://www.forensicswiki.org/wiki/Tools:Memory_Imaging
Anecdotally, I've heard from forensic practitioners that the KnTTools are very solid (and, importantly, unlikely to crash a running system during acquisition), but they're not free.