readme.txt

(15 KB) Pobierz


BlueScreenView v1.45
Copyright (c) 2009 - 2011 Nir Sofer
Web site: http://www.nirsoft.net



Description
===========

BlueScreenView scans all your minidump files created during 'blue screen
of death' crashes, and displays the information about all crashes in one
table. For each crash, BlueScreenView displays the minidump filename, the
date/time of the crash, the basic crash information displayed in the blue
screen (Bug Check Code and 4 parameters), and the details of the driver
or module that possibly caused the crash (filename, product name, file
description, and file version).
For each crash displayed in the upper pane, you can view the details of
the device drivers loaded during the crash in the lower pane.
BlueScreenView also mark the drivers that their addresses found in the
crash stack, so you can easily locate the suspected drivers that possibly
caused the crash.



Versions History
================


* Version 1.45:
  o You can now choose to open only a specific dump file - from the
    user interface or from command-line.
  o You can now also specify the MiniDump folder or MiniDump file as
    a single parameter, and BlueScreenView will be opened with the right
    dump file/folder, for example: BlueScreenView.exe
    C:\windows\minidump\Mini011209-01.dmp

* Version 1.40:
  o Added 'Raw Data' mode on the lower pane, which displays the
    processor registers and memory hex dump.

* Version 1.35:
  o Added 'Crash Address' column.
  o Added 3 columns that display that last 3 calls found in the stack
    (Only for 32-bit crashes)

* Version 1.32:
  o Added 'Mark Odd/Even Rows' option, under the View menu. When it's
    turned on, the odd and even rows are displayed in different color, to
    make it easier to read a single line.

* Version 1.31:
  o Added 'Google Search - Bug Check+Driver' for searching in Google
    the driver name and bug check code of the selected blue screen.

* Version 1.30:
  o Added 'Dump File Size' column.

* Version 1.29:
  o You can now send the list of blue screen crashes to stdout by
    specifying an empty filename ("") in the command-line of all save
    parameters.
    For example: bluescreenview.exe /stab "" > c:\temp\blue_screens.txt

* Version 1.28:
  o Added 'Add Header Line To CSV/Tab-Delimited File' option. When
    this option is turned on, the column names are added as the first
    line when you export to csv or tab-delimited file.

* Version 1.27:
  o Fixed issue: removed the wrong encoding from the xml string,
    which caused problems to some xml viewers.

* Version 1.26:
  o Fixed 'DumpChk' mode to work properly when DumpChk processing
    takes more than a few seconds.

* Version 1.25:
  o Added 'DumpChk' mode, which displays the output of Microsoft
    DumpChk utility (DumpChk.exe). You can set the right path and
    parameters of DumpChk in 'Advanced Options' window. By default,
    BlueScreenView tries to run DumpChk from '%programfiles%\Debugging
    Tools for Windows'
  o The default MiniDump folder is now taken from
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl

* Version 1.20:
  o Added 3 new columns in the upper pane: Processors Count, Major
    Version, Minor Version.
  o Added 'Explorer Copy' option, which allows you to copy dump files
    to the clipboard and then paste them into Explorer window.

* Version 1.15:
  o Added option to view the blue screen list of multiple computers
    on your network. The computer names are specified in a simple text
    file. (See below).
  o Added Combo-Box to easily choose the MiniDump folders available
    in the hard-disks currently attached to your computer.
  o Added 'Computer Name' and 'Full Path' columns.

* Version 1.11:
  o Added /sort command-line option.

* Version 1.10:
  o Added accelerator keys for allowing you to toggle between modes
    more easily.
  o Added command-line options for saving the crash dumps list to
    text/csv/html/xml file.
  o Added command-line option for opening BlueScreenView with the
    desired MiniDump folder.
  o Fixed focus problems when opening the 'Advanced Options' window.
  o Added 'default' button to the 'Advanced Options' window.
  o Added 'processor' column - 32-bit or x64.

* Version 1.05 - Added support for x64 MiniDump files.
* Version 1.00 - First release.



BlueScreenView Features
=======================


* Automatically scans your current minidump folder and displays the
  list of all crash dumps, including crash dump date/time and crash
  details.
* Allows you to view a blue screen which is very similar to the one
  that Windows displayed during the crash.
* BlueScreenView enumerates the memory addresses inside the stack of
  the crash, and find all drivers/modules that might be involved in the
  crash.
* BlueScreenView also allows you to work with another instance of
  Windows, simply by choosing the right minidump folder (In Advanced
  Options).
* BlueScreenView automatically locate the drivers appeared in the crash
  dump, and extract their version resource information, including product
  name, file version, company, and file description.



System Requirements
===================


* BlueScreenView works with Windows XP, Windows Server 2003, Windows
  Server 2008, Windows Vista, and Windows 7, as long as Windows is
  configured to save minidump files during BSOD crashes. If your system
  doesn't create MiniDump files on a blue screen crash, try to configure
  it according to the following article: How to configure Windows to
  create MiniDump files on BSOD
* BlueScreenView can read the MiniDump files of both 32-bit and x64
  systems.



Using BlueScreenView
====================

BlueScreenView doesn't require any installation process or additional dll
files. In order to start using it, simply run the executable file -
BlueScreenView.exe
After running BlueScreenView, it automatically scans your MiniDump folder
and display all crash details in the upper pane.



Crashes Information Columns (Upper Pane)
========================================


* Dump File: The MiniDump filename that stores the crash data.
* Crash Time: The created time of the MiniDump filename, which also
  matches to the date/time that the crash occurred.
* Bug Check String: The crash error string. This error string is
  determined according to the Bug Check Code, and it's also displayed in
  the blue screen window of Windows.
* Bug Check Code: The bug check code, as displayed in the blue screen
  window.
* Parameter 1/2/3/4: The 4 crash parameters that are also displayed in
  the blue screen of death.
* Caused By Driver: The driver that probably caused this crash.
  BlueScreenView tries to locate the right driver or module that caused
  the blue screen by looking inside the crash stack. However, be aware
  that the driver detection mechanism is not 100% accurate, and you
  should also look in the lower pane, that display all drivers/modules
  found in the stack. These drivers/modules are marked in pink color.
* Caused By Address: Similar to 'Caused By Driver' column, but also
  display the relative address of the crash.
* File Description: The file description of the driver that probably
  caused this crash. This information is loaded from the version resource
  of the driver.
* Product Name: The product name of the driver that probably caused
  this crash. This information is loaded from the version resource of the
  driver.
* Company: The company name of the driver that probably caused this
  crash. This information is loaded from the version resource of the
  driver.
* File Version: The file version of the driver that probably caused
  this crash. This information is loaded from the version resource of the
  driver.
* Crash Address:The memory address that the crash occurred. (The
  address in the EIP/RIP processor register) In some crashes, this value
  might be identical to 'Caused By Address' value, while in others, the
  crash address is different from the driver that caused the crash.
* Stack Address 1 - 3: The last 3 addresses found in the call stack. Be
  aware that in some crashes, these values will be empty. Also, the stack
  addresses list is currently not supported for 64-bit crashes.



Drivers Information Columns (Lower Pane)
========================================


* Filename: The driver/module filename
* Address In Stack: The memory address of this driver that was found in
  the stack.
* From Address: First memory address of this driver.
* To Address: Last memory address of this driver.
* Size: Driver size in memory.
* Time Stamp: Time stamp of this driver.
* Time String: Time stamp of this driver, displayed in date/time format.
* Product Name: Product name of this driver, loaded from the version
  resource of the driver.
* File Description: File description of this driver, loaded from the
  version resource of the driver.
* File Version: File version of this driver, loaded from the version
  resource of the driver.
* Company: Company name of this driver, loaded from the version
  resource of the driver.
* Full Path: Full path of the driver filename.



Lower Pane Modes
================

Currently, the lower pane has 4 different display modes. You can change
the display mode of the lower pane from Options->Lower Pane Mode menu.
1. All Drivers: Displays all the drivers that were loaded during the
   crash that you selected in the upper pane. The drivers/module that
   their memory addresses found in the stack, are marked in pink color.
2. Only Drivers Found In Stack: Displays only the modules/drivers that
   their memory addresses found in t...
Zgłoś jeśli naruszono regulamin