Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, August 9, 2009

Drop-Dead-Quick Blue Screen of Death Diagnosis Utility

Posted on 8:34 PM by Unknown

Almost anyone who has been around a Windows system has seen the dreaded BSOD.

It’s a puzzling display of hex-code, and techno-babble that will often cause the sweetest tea-sipping granny to curse the Viking god of war and send him running for cover.

Even many geeks would rather just offer up a “looks like you need to wipe it and reload the system” with a shrug than to try to pick apart the Rosetta Stone of words and code offered.

Sure, with patience and some basic understanding, one can copy down (or pull from a crash dump log) the error, do some Google work, and often find a solution. But come on, how many mere mortals would do that?

Brilliant freeware utility programmer Nir Sofer has just made this process much more delicate and refined.  How easy to get to the bottom of a BSOD you ask? Well, so easy a caveman can…oh…well, you’ve seen the commercials by now.

  • BlueScreenView - View blue screen of death (STOP error) information – freeware utility – NirSoft.

BlueScreenView requires no “installation” thus is portable between systems, and it works with Windows XP, Windows Server 2003, Windows Server 2008, Windows Vista, and Windows 7, “…as long as Windows is configured to save minidump files during BSOD crashes.”  Per Mr. Sofer.

image

Above: Dump display of a particular crash on my Vista system (BSOD XP Style display in lower pane).

image

Above: Dump display showing suspected driver causing crash in detail view in lower pane.

BlueScreenView features as described by Nir on the product page are…

  • Automatically scans your current minidump folder and displays the list of all crash dumps, including crash dump date/time and crash details.
  • Allows you to view a blue screen which is very similar to the one that Windows displayed during the crash.
  • BlueScreenView enumerates the memory addresses inside the stack of the crash, and find all drivers/modules that might be involved in the crash.
  • BlueScreenView also allows you to work with another instance of Windows, simply by choosing the right minidump folder (In Advanced Options).
  • BlueScreenView automatically locate the drivers appeared in the crash dump, and extract their version resource information, including product name, file version, company, and file description.

That 4th one there is really cool.  I actually was running the tool on my VHD booted Win7 system (x64 bit). Unfortunately, the tool doesn’t currently support x64 bit system dumps, but I simply pointed it to the minidump folder on my Vista system (showing in the program’s title bar as on the D: drive (really the C: but as I’m VHD booting, it becomes the "D:”) and it was able to pull up the records just fine.

That’s very important if, say the system does a hard-crash, and you can’t get it up.  Or maybe the system crashed and your significant-other/customer didn’t bother to leave any notes for you and just reset the system leaving you nothing but a scowl and smorgasbord of “it BSOD, Fix it!” on the table before you.

Now you can maybe boot the system with a Win PE disk, with this app unpacked on a USB stick, point it at the minidump folder and retrieve the BSOD history, along with the details.  Save the results in a log file back to the attached USB stick and then do your research and plan your solution-attack. Sweet!

While this information would be very useful to a system admin or desktop support tech, it could also be of use to an forensic examiner as it might provide some clues on the system history or patterns of operating system issues or remnants.

Armed with the information obtained from the BlueScreenView utility, just drop in any any one of these awesome BSOD decoding websites (or Google) and you are good to start the solutioning.

  • Troubleshooting Windows STOP Messages - James A. Eshelman

  • Understanding and Decoding BSOD (blue screen of death) Messages - Taranfx: Technology Blog

  • The ABC of Blue-Screen Dump Analysis - All Your Base Are Belong To Us

Miscellany

Not directly related but seemed better to post here then in the previous Microsoft Linkfest post.

  • Two Minute Drill: Debugging – lm, not just Alphabet Neighbors – Ask the Performance Team blog

  • Two Minute Drill: Debugging and the k* Commands  – Ask the Performance Team blog

  • Converting Perfmon timestamps to a readable format in Excel - the back room tech

Thank you Nir!

--Claus V.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Microsoft, troubleshooting, utilities | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Utility Gumbo
    There’s a lot in this pot.  Probably something everyone can find to enjoy. I’m serving it up tonight out of the back of the truck on the s...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • Windows 8 Linkage: A Bit Behind the Ball
    CC attribution: behind the eight ball by Ed Schipul on flickr . OK. Confession time. I’m more than a bit exhausted this weekend. Besides a...
  • Interesting Malware in Email Attempt - URL Scanner Links
    Last weekend I spent some time with extended family helping confirm for them that their on-line email account got hacked and had been used t...
  • This Week in Security and Forensics: Beware the cake!
    Cube Party! image used with permission from John Walker at "rockpapershotgun.com" Yeah, the cake is a Portal thing.  Let’s d...
  • Windows 8 Linkage: “Passage Public Metro” version
    cc image credit image by david.nikonvscanon on flickr So Claus, where do you stand on Windows 8 at this point? Well, to be honest, I’m re...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ►  2013 (83)
    • ►  November (8)
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ▼  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ▼  August (21)
      • Utility & Miscellany
      • Network Capture Tools and Utilities
      • Java Silent Install Notes
      • Utility Gumbo
      • Rapid-Fire Security and Response Linkpost
      • Inspiring Designs #2
      • GSD Hurricane Tracking Links – 2009
      • Search & Acquire by File Type Solutions
      • QuickPost: Bootable USB Stick
      • Devio: Remote drive access and acquisition
      • Tip: Managing Flash Cookies
      • Tip: Add Google’s Beta Search to browsers
      • Adobe Tip: Add filename to footer
      • Focus on Forensics Linkfest
      • Blog reboot – version 4.0
      • Around the (MS) Office pool
      • Drop-Dead-Quick Blue Screen of Death Diagnosis Uti...
      • Windows Linkfest Mowdown
      • Browser Linkfest Blowout
      • Mounting VHD files in Windows for fun and exploration
      • Virtual PC and XP Mode Linkage
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile