So it happened, a serious Windows System Crash aka BSOD (Blue Screen Of Death). There may be hundreds of reasons why your Windows System has crashed but event logs just say that it crashed and wasn’t shut down clean – obvious!
We need to look a bit deeper in order to see what probably caused that behaviour. Let’s start with why it crashes. Windows crash most of time when:
- a faulty or bad written driver wants to execute code outside its address range or tries to use different IRQ that it suppose to
- a system service that is using a driver to perform specific tasks fails, thus driver fails. Services like this are often Firewalls and other parts of antivirus software. The work that way in order to avoid being stopped by a virus or user. You can disable it or set it to allow everything but it is working anyway
- memory error. Faulty RAM can be problematic to narrow down but keep this in mind, that RAM sometimes just fails
- other hardware error. Most of the parts that would be devices needing dedicated drivers, thus we are going to point 1
Ok so what to do if it crashes?
Mostly, ordinary reset would do the job. Trust me. Windows these days is a bit smarter that in Xp and previous era and can disable problematic drivers and services automatically. If after restart, or sometimes 2 or 3 Windows loads up and some service, software or device isn’t working. That was probably accused by Windows of crashing. Try to find newer/fixed versions.
But this is not the point! We WANT to know what caused this!
So, there are two most used by me and free tools to debug BSOD:
First one is quite easy to use. Just download, open as administrator and it should automatically find crash dumps and point to file that caused this. The thing is, it often blames ntoskrnl.exe which is Windows Kernel… Ok. So Kernel Crashed, and what next?
Next is more advanced tool, but litte harder to use. I personally prefer WinDbg over BlueScreenView but is completely up to you.
First you need to download Windows SDK and install only Debugging Tools for Windows from install options.
Then when you open WinDbg, you need to provided “symbols path” by selecting File->Symbols File Path or by pressing CTRL+S
Paste below code:
It should look like: