BSOD Crash Analyser

Parse Windows minidumps (.dmp) and diagnose Blue Screen stop codes locally. Zero server uploads.

Or Search Stop Code Manually
πŸ”„

Random Reboots

Uncover why your PC abruptly restarted, froze during gaming, or encountered a blue screen crash.

Decode Stop Codes β†’
🧩

Faulty Driver Culprits

Pinpoint the exact third-party driver (graphics, Wi-Fi, audio, or anti-cheat) responsible for the system halt.

Identify .sys files β†’
βš™οΈ

Hardware vs Software

Distinguish physical RAM failures and failing SSDs from simple Windows corrupted system binaries.

Actionable checklist β†’
πŸ”’

100% In-Browser Privacy

Crash dumps contain volatile memory slices. Your .dmp file is parsed purely inside local browser memory.

Zero cloud uploads β†’

1 How to Locate & Analyse a Crash Dump

  1. β€’ Open File Explorer: Press Win+E and go to C:\Windows\Minidump\.
  2. β€’ Drop or Paste: Drag the newest .dmp file onto the zone above, or paste it with Ctrl+V.
  3. β€’ Manual Search: Don't have the file? Simply type your Stop Code (e.g. 0x1A or DPC_WATCHDOG_VIOLATION) in the search box.
  4. β€’ Follow the Checklist: Review the decoded BugCheck code, suspect driver, and step-by-step remediation guide.

β˜… Crash Diagnostics Tips

  • βœ” ntoskrnl.exe is rarely the true cause: The kernel halts the system to protect your data when a third-party driver corrupts memory.
  • βœ” Disable RAM XMP/EXPO first: Unstable memory overclocks are the #1 cause of 0x1A MEMORY_MANAGEMENT and 0x7F.
  • βœ” Clean GPU drivers with DDU: Video TDR crashes (0x116) are almost always fixed by reinstalling graphics drivers in Safe Mode.
  • βœ” Copy summary for forums: Click Copy Summary to get clean, formatted output ready to paste into Reddit or Microsoft Answers.
βš™οΈ Under the Hood: Binary Minidump Parsing & Specifications
Show technical details

Microsoft Windows writes crash dumps according to structured binary layouts. 64-bit kernel memory dumps begin with the standard PAGE signature coupled with the DU64 identifier (_DMP_HEADER64), whereas small minidumps implement the MDMP signature (0x504D444D).

BWTools mounts the binary file directly into an HTML5 ArrayBuffer and walks stream directories via a low-level DataView, parsing the ExceptionStream (Stream 6), SystemInfoStream (Stream 7), and ModuleListStream (Stream 4) without allocating external debugger processes.

Dump Structure Magic Signature Supported Architecture Typical Size Extracted Telemetry
Windows Small Minidump MDMP (0x504D444D) x64, ARM64, x86 256 KB – 2 MB BugCheck, 4 Arguments, System Drivers
64-Bit Kernel Dump PAGE + DU64 AMD64 / x64 500 MB – 2 GB Header BugCheck, OS Build, CPU Count
32-Bit Kernel Dump PAGE + DUMP i386 / x86 Legacy 150 MB – 800 MB Legacy BugCheck & Memory Map
Event Log Query Plain Text / Hex Universal < 50 KB Stop String Matching, Remediation Checklist

❓ Frequently Asked Questions

Why do some minidumps show 0x1000007F instead of 0x0000007F?

Windows Error Reporting (WER) frequently sets the high bit mask 0x10000000 when generating small memory dumps. 0x1000007F corresponds to UNEXPECTED_KERNEL_MODE_TRAP (0x7F). BWTools automatically identifies and strips this mask to match the canonical Microsoft BugCheck database.

What does Trap Code 0x00000008 (Double Fault) indicate?

A Double Fault occurs when the CPU attempts to trigger an exception handler while handling an earlier exception, resulting in an unrecoverable hardware halt. This almost always indicates either kernel stack overflow caused by recursive filter drivers (antivirus, VPN, or drive encryption) or physical memory/CPU cache instability.

Where are Windows Blue Screen crash dumps stored?

By default, Windows writes compact minidump snapshots to C:\Windows\Minidump\. Larger full-memory snapshots are written directly to C:\Windows\MEMORY.DMP. If the folder appears empty, ensure that your system has "Write debugging information" configured to "Small memory dump (256 KB)" within Advanced System Settings.

Why does my crash point to ntoskrnl.exe?

ntoskrnl.exe is the core Windows operating system kernel. When a third-party driver corrupts system memory or executes an invalid operation, the kernel catches the fault and triggers the Blue Screen to prevent data loss. The kernel is almost never defective itself; the true cause is usually an unverified third-party driver, unstable RAM timings, or a failing SSD.

Summary copied to clipboard!