<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Comment Feed for Channel 9 - Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks/RSS"></atom:link>
	<image>
		<url>http://media.ch9.ms/ch9/8332/bebdd717-f1b6-4047-a43f-1b2176198332/DefragTools15_220.jpg</url>
		<title>Channel 9 - Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
		<link></link>
	</image>
	<description>In this episode of Defrag Tools, Chad Beeder and Larry Larsen&amp;nbsp;discuss analyzing kernel mode bugchecks (colloquially known as&amp;nbsp;Blue Screens of Death) using&amp;nbsp;WinDbg from the&amp;nbsp;Debugging Tools For Windows. We use these commands: !analyze -v .hh .trap !pte !process !thread .formats .process .thread k ~ .reload Make sure you watch Defrag Tools Episode #1 for instructions on how to get the Debugging Tools for Windows and how to set the required environment variables for symbols and source code resolution. Resources:  Debugging Tools for Windows How to generate a kernel or a complete memory dump file in Windows Server 2008 and Windows Server 2008 R2 Windows Internals book tools (including NotMyFault) Timeline: [00:50] - What is a bugcheck (blue screen)?[03:23] - Different types of memory dump files (complete, kernel-only, mini)[05:16] - Windows Error Reporting[07:17] - Configuring your system for a memory dump[07:54] - Enabling &amp;quot;Complete memory dump&amp;quot; option on Windows 7 and Server 2008 R2; see KB 969028[10:45] - Looking at a 32-bit memory dump created by NotMyFault[12:04] - Symbol path[13:21] - Step 1 is always: !analyze -v[15:40] - Looking up bug check descriptions&amp;nbsp;- Windows Debugger Help (.hh)[19:45] - Looking at the trap frame (.trap)[20:18] - Why did a memory access fail? (Using !pte command to look at virtual memory mappings)[22:15] - What is a trap frame? (64-bit systems&amp;nbsp;do not store all registers in trap frames; see&amp;nbsp;blog post here) [26:50] - Showing all running processes with !process 0 0[28:48] - View more details on a specific process with !process[31:43] - Converting between numerical formats with .formats[32:55] - Switching the debugger&amp;nbsp;into a process or thread context: use .process or .thread[35:10] - Switching between CPUs (~ command)[38:13] - Next week: Driver Verifier </description>
	<link></link>
	<language>en</language>
	<pubDate>Sun, 19 May 2013 11:44:15 GMT</pubDate>
	<lastBuildDate>Sun, 19 May 2013 11:44:15 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<item>
		<title>Re: Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
		<description>
			<![CDATA[<p><em><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#time=03m23s">[03:23]</a> - Different types of memory dump files (complete, kernel-only, mini)</em></p><p><em><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#time=07m17s">[07:17]</a> - Configuring your system for a memory dump</em></p><p><span>please also explain what the new &quot;Automatic dump&quot; option under Windows 8 does in the next episodes <br></span></p><p><span>Win7 got a hotfix to create dumps without page file:<br></span></p><p><span><strong>A hotfix is available that enables a Windows 7-based computer to create a memory dump file without a page file</strong><br><a href="http://support.microsoft.com/kb/2716542/en-us">http&#58;&#47;&#47;support.microsoft.com&#47;kb&#47;2716542&#47;en-us</a></span></p><p><span>But for me the fix doesn't work.<br></span></p><p><em><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#time=15m40s">[15:40]</a> - Looking up bug check descriptions</em></p><p>I'm using this site:</p><p><a href="http://msdn.microsoft.com/en-us/library/hh994433%28v=vs.85%29.aspx">http&#58;&#47;&#47;msdn.microsoft.com&#47;en-us&#47;library&#47;hh994433&#37;28v&#61;vs.85&#37;29.aspx</a></p><p>Btw, there are still some bugchecks missing which are only listed in the bugcodes.h from the WDK. Will those one be published? If not, why?</p><p>&nbsp;</p><p>posted by MagicAndre1981</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634889371839614261</link>
		<pubDate>Mon, 19 Nov 2012 15:53:03 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634889371839614261</guid>
		<dc:creator>MagicAndre1981</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
		<description>
			<![CDATA[<p>Gangster Chad serves you up BSOD lyrics. <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-5.gif?v=c9' alt='Wink' /></p><p>posted by windev</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634889618154628924</link>
		<pubDate>Mon, 19 Nov 2012 22:43:35 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634889618154628924</guid>
		<dc:creator>windev</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
		<description>
			<![CDATA[<p>Chad I see in the windows internal 6th edition that the virtual address space for 32-bit x86 is 0x00000000 - 0x7fffffff for user process and 0x80000000 - 0xffffffff for protected operating system memory.</p><p>What are the values for a 64-bit x64 system?</p><p>I agree with Andrew that was an awesome demo. Can't wait for more!!!</p><p>posted by dcrearer</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634889748627796069</link>
		<pubDate>Tue, 20 Nov 2012 02:21:02 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634889748627796069</guid>
		<dc:creator>dcrearer</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634889371839614261">MagicAndre1981</a>: This episode was taped before Windows 8 official release. We may talk more about the Windows 8 &quot;Automatic memory dump&quot;&nbsp;setting in the future, but for now there is a pretty good <a href="http://blogs.technet.com/b/askcore/archive/2012/09/12/windows-8-and-windows-server-2012-automatic-memory-dump.aspx">blog post from the Windows Server Core Team</a> which goes into detail&nbsp;about this feature.</p><p>I haven't tried the KB 2716542 hotfix to allow&nbsp;memory dumps without a&nbsp;page file,&nbsp;but based on what I can see about it, you may also need to set &quot;DedicatedDumpFile&quot; in the registry to get it to work. (See <a href="http://support.microsoft.com/kb/969028/">KB 969028</a>&nbsp;for details on DedicatedDumpFile.) I would not recommend running without a page file in most cases, however. This is really intended for specialized&nbsp;systems (i.e. embedded systems) which run a limited set of applications with known memory requirements.</p><p>I'm not sure about the bugchecks which are listed in bugcodes.h but not documented. I'd&nbsp;guess that they aren't widely used (or deprecated in current Windows versions), or&nbsp;they may&nbsp;only be&nbsp;used in checked or internal debug builds of Windows. In any event, it's highly unlikely you'd see them in real-world scenarios.</p><p>posted by ChadBeeder</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634889756104448927</link>
		<pubDate>Tue, 20 Nov 2012 02:33:30 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634889756104448927</guid>
		<dc:creator>ChadBeeder</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634889748627796069">dcrearer</a>: I don't have a 6th Edition Windows Internals handy at the moment, but in my 5th Edition copy, there is a chart of the x64 address space layout, so hopefully it's still there!<br><br>On x64,&nbsp;user process address&nbsp;space&nbsp;is 0x0000000000000000 - 0x000007FFFFFEFFFF (8TB minus 64KB).<br>System space is from 0xFFFF080000000000 - 0xFFFFFFFFFFFFFFFF.</p><p>We will do more episodes on debugging. Thanks for watching!</p><p>posted by ChadBeeder</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634889764626583000</link>
		<pubDate>Tue, 20 Nov 2012 02:47:42 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634889764626583000</guid>
		<dc:creator>ChadBeeder</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
		<description>
			<![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a href="/Niners/ChadBeeder">ChadBeeder</a> wrote</p><p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634889371839614261">MagicAndre1981</a>: This episode was taped before Windows 8 official release. We may talk more about the Windows 8 &quot;Automatic memory dump&quot;&nbsp;setting in the future, but for now there is a pretty good <a href="http://blogs.technet.com/b/askcore/archive/2012/09/12/windows-8-and-windows-server-2012-automatic-memory-dump.aspx">blog post from the Windows Server Core Team</a> which goes into detail&nbsp;about this feature.</p><p>I haven't tried the KB 2716542 hotfix to allow&nbsp;memory dumps without a&nbsp;page file,&nbsp;but based on what I can see about it, you may also need to set &quot;DedicatedDumpFile&quot; in the registry to get it to work. (See <a href="http://support.microsoft.com/kb/969028/">KB 969028</a>&nbsp;for details on DedicatedDumpFile.) I would not recommend running without a page file in most cases, however. This is really intended for specialized&nbsp;systems (i.e. embedded systems) which run a limited set of applications with known memory requirements.</p><p>I'm not sure about the bugchecks which are listed in bugcodes.h but not documented. I'd&nbsp;guess that they aren't widely used (or deprecated in current Windows versions), or&nbsp;they may&nbsp;only be&nbsp;used in checked or internal debug builds of Windows. In any event, it's highly unlikely you'd see them in real-world scenarios.</p><p></p></div></blockquote><p></p><p>I've already read the blog post, but other users not. So you should also explain it here.</p><p>I must say I've reduced the size of the page file to 2048 - 4096 MB. Does the fix only work for Systems without a pagefile or does it also work for smaller page files? I don't want to waste 16GB of space on my SSD.</p><p>the bugchecks that are missing are mostly ones which were added since Vista. From 0x13x and 0x14x there are a lot of undocumented bugchecks.</p><p>posted by MagicAndre1981</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634891625427493476</link>
		<pubDate>Thu, 22 Nov 2012 06:29:02 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634891625427493476</guid>
		<dc:creator>MagicAndre1981</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634891625427493476">MagicAndre1981</a>: Did you try adding the DedicatedDumpFile setting?</p><p>Yeah, it&nbsp;looks like&nbsp;the people in charge of maintaining the debugger help file haven't gotten around to documenting all those newer bugchecks. Bugcodes.h contains the most definitive list of&nbsp;codes used by Windows components. Of course, third-party drivers are free to use any bugcheck code they want.</p><p>posted by ChadBeeder</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634895786593041217</link>
		<pubDate>Tue, 27 Nov 2012 02:04:19 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634895786593041217</guid>
		<dc:creator>ChadBeeder</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
		<description>
			<![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a href="/Niners/ChadBeeder">ChadBeeder</a> wrote</p><p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634891625427493476">MagicAndre1981</a>: Did you try adding the DedicatedDumpFile setting?</p><p></p></div></blockquote><p></p><p>yes, but this makes it even worse. Now the Dedicated dump is 16GB and I have still my normal pagefile. So this is no option.</p><p></p><blockquote><div class="quoteText"><p></p><p><a href="/Niners/ChadBeeder">ChadBeeder</a> wrote</p><p>Yeah, it&nbsp;looks like&nbsp;the people in charge of maintaining the debugger help file haven't gotten around to documenting all those newer bugchecks. Bugcodes.h contains the most definitive list of&nbsp;codes used by Windows components.</p><p></p></div></blockquote><p></p><p>will they ever add those missing bugchecks to the documentation? Have you asked them?</p><p>posted by MagicAndre1981</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634899477042858603</link>
		<pubDate>Sat, 01 Dec 2012 08:35:04 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634899477042858603</guid>
		<dc:creator>MagicAndre1981</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634899477042858603">MagicAndre1981</a>: Yes, I've asked.&nbsp;A few of the newer bugchecks have been added to the documentation, but it's not clear every single one needs to be&nbsp;added. A lot of these bugchecks are rarely, if ever, seen in the wild. If there are specific ones that need to be documented, we can ask for them.</p><p>posted by ChadBeeder</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634899837350966591</link>
		<pubDate>Sat, 01 Dec 2012 18:35:35 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634899837350966591</guid>
		<dc:creator>ChadBeeder</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
		<description>
			<![CDATA[<p>@ChadBeeder</p><p>I've seen some of them and the only useful information came from<strong> !analyze -show BUGCHECKNUMBER</strong> in WinDbg. The next confusing thing is that the new bugcodes.h no longer contains the MessageText with some information. What I want to know is thebugcheck VHD_BOOT_HOST_VOLUME_NOT_ENOUGH_SPACE (136). Can I see from the parameters, how much free space I need to boot the VHD?</p><p>Can you also ask the Debugger Team 2 things? <br><br>1.) Sometimes I have the issue that the text is displayed twice:</p><p><img src="https://dl.dropbox.com/u/5749744/Bilder/Channel9/Defrag-Tools/WinDbg/WinDbg_doubled_text.png" alt=""></p><p>this happens randomly after stopping a former debug session with SHIFT&#43;F5.</p><p>2.) the new Dbghelper DLLs are slow to process the PDBs. It takes much longer to load them with the new DLLs from Win8 SDK. replacing them with old ones fixes the slow loading. I noticed this most when using xperfview.</p><p>posted by MagicAndre1981</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634900359101736823</link>
		<pubDate>Sun, 02 Dec 2012 09:05:10 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634900359101736823</guid>
		<dc:creator>MagicAndre1981</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634900359101736823">MagicAndre1981</a>:</p><p>#1 - This&nbsp;happens when a Event or Output Callback from an extension is not behaving.&nbsp;Try loading with <strong>Windbg -WX</strong> to see if it goes away.</p><p>#2 - This might relate to the new inline support. Can you collect a xPerf of the two scenarios?</p><p>posted by windev</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634903463705340770</link>
		<pubDate>Wed, 05 Dec 2012 23:19:30 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634903463705340770</guid>
		<dc:creator>windev</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #15 - WinDbg - Bugchecks (BSOD)</title>
		<description>
			<![CDATA[<p>#1 it happens very randomly, so I have no idea if -WX fixes it. And the dumps are different ones, so I never use the same WS again.</p><p>#2 which flags should I capture? Here is also an user who has this issue:</p><p><a href="http://randomascii.wordpress.com/2012/10/04/xperf-symbol-loading-pitfalls/">http&#58;&#47;&#47;randomascii.wordpress.com&#47;2012&#47;10&#47;04&#47;xperf-symbol-loading-pitfalls&#47;</a></p><p>posted by MagicAndre1981</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634903811699695832</link>
		<pubDate>Thu, 06 Dec 2012 08:59:29 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-15-WinDbg-Bugchecks#c634903811699695832</guid>
		<dc:creator>MagicAndre1981</dc:creator>
	</item>
</channel>
</rss>