Windows System Crash Analysis (BSOD)

You are all probably aware of the MEMORY.DMP files in the windows directory. You may also be aware of the Windows\MiniDump directory. These files are created when there is a critical system error usually resulting in an automated reboot or BSOD.

The Memory.DMP file contains debugging information plus the contents of your system’s RAM. This file is overwritten each time a crash occurs. The MiniDump directory contains the same debugging information as MEMORY.DMP but does not include the RAM contents. The MiniDumps are not overwritten so they can be used as a historical reference for identifying crash events.

So the question is how do you use these file???? There is a tool from Microsoft designed to do just that! It is called WinDbg and is part of the Debugging Tools for Windows. (http://www.microsoft.com/whdc/devtools/debugging/)

Download and install this tool. There is an x86 and an x64 version. Once the program is installed open it and choose the file menu then Symbol File Path.

Enter the following: http://msdl.microsoft.com/download/symbols/

This will download the necessary symbols as needed. Symbols are a link between the binary application code and programming language which generated the code.

Once this is done you can choose File – Open Crash Dump. This will open both Memory.DMP and MiniDumps. Once opened the program will begin some analysis.

Click on the !analyze –v link to do a verbose analysis. This may give more information as to the reason for the crash. The faulting application code is listed in the default analysis.

Enjoy!

Acronis Universal Restore BSOD

I encountered a problem this week when using a newer version of Acronis (9.7) to create an image, and then using an older release (9.5) to restore it. Acronis does not detect that there is a version mismatch between the image and the restore software. However, in my case, it caused a BSOD pointing towards a driver problem. Using the correct version to backup and restore resolved the problem. Infact, I tested both 9.5 and 9.7 on this system, and as long as you used the same version for backup and restore it will work fine. It just doesn’t handle cross version very well.

Dell BSOD Stop Error 0x000000d1 IAStor.sys

notebook, and two persons on white backgroundI recently assisted a client who was having a problem with his Dell computer blue screening every time he ran a disk degfrag.  I asked him to document the error code and then let me know what it was reporting.  A quick check for the error code on the web revealed that this is apparently a well documented error which affect Dell systems (and perhaps others) and is the result of a bad driver from Intel via Dell. Below is the link to probably the most comprehensive review of this issue.

http://www.ydeologi.com/2006/04/26/dell-dimension-e510-iastorsys-windows-xp-blue-screen-error-stop-code-0x000000d1

Powered by WordPress.com.

Up ↑