BSOD Crash Analyser
Parse Windows minidumps (.dmp) and diagnose Blue Screen stop codes locally. Zero server uploads.
Analysing binary dump structure...
Reading headers and stream directories...
UNEXPECTED_KERNEL_MODE_TRAP
The CPU generated a trap exception that the kernel failed to intercept.
Critical Finding: CPU Double Fault (0x00000008)
A Double Fault occurs when the CPU attempts to process an interrupt while the kernel stack is already exhausted or corrupted. This is an immediate catastrophic halt, typically caused by kernel stack overflow (recursive filter/antivirus drivers) or unstable memory timings.
Crash Arguments & BugCheck Parameters
Arg1 - Arg4Loaded Kernel Drivers & Third-Party Modules
0 Modulesπ§ Tailored Troubleshooting Checklist
Random Reboots
Uncover why your PC abruptly restarted, froze during gaming, or encountered a blue screen crash.
Faulty Driver Culprits
Pinpoint the exact third-party driver (graphics, Wi-Fi, audio, or anti-cheat) responsible for the system halt.
Hardware vs Software
Distinguish physical RAM failures and failing SSDs from simple Windows corrupted system binaries.
100% In-Browser Privacy
Crash dumps contain volatile memory slices. Your .dmp file is parsed purely inside local browser memory.
1 How to Locate & Analyse a Crash Dump
-
β’
Open File Explorer: Press Win+E and go to
C:\Windows\Minidump\. -
β’
Drop or Paste: Drag the newest
.dmpfile onto the zone above, or paste it with Ctrl+V. - β’ Manual Search: Don't have the file? Simply type your Stop Code (e.g. 0x1A or DPC_WATCHDOG_VIOLATION) in the search box.
- β’ Follow the Checklist: Review the decoded BugCheck code, suspect driver, and step-by-step remediation guide.
β Crash Diagnostics Tips
- β ntoskrnl.exe is rarely the true cause: The kernel halts the system to protect your data when a third-party driver corrupts memory.
-
β
Disable RAM XMP/EXPO first: Unstable memory overclocks are the #1 cause of
0x1A MEMORY_MANAGEMENTand0x7F. -
β
Clean GPU drivers with DDU: Video TDR crashes (
0x116) are almost always fixed by reinstalling graphics drivers in Safe Mode. - β Copy summary for forums: Click Copy Summary to get clean, formatted output ready to paste into Reddit or Microsoft Answers.
βοΈ
Under the Hood: Binary Minidump Parsing & Specifications
Show technical details
Hide
Microsoft Windows writes crash dumps according to structured binary layouts. 64-bit kernel memory dumps begin with the standard PAGE signature coupled with the DU64 identifier (_DMP_HEADER64), whereas small minidumps implement the MDMP signature (0x504D444D).
BWTools mounts the binary file directly into an HTML5 ArrayBuffer and walks stream directories via a low-level DataView, parsing the ExceptionStream (Stream 6), SystemInfoStream (Stream 7), and ModuleListStream (Stream 4) without allocating external debugger processes.
| Dump Structure | Magic Signature | Supported Architecture | Typical Size | Extracted Telemetry |
|---|---|---|---|---|
| Windows Small Minidump | MDMP (0x504D444D) | x64, ARM64, x86 | 256 KB β 2 MB | BugCheck, 4 Arguments, System Drivers |
| 64-Bit Kernel Dump | PAGE + DU64 | AMD64 / x64 | 500 MB β 2 GB | Header BugCheck, OS Build, CPU Count |
| 32-Bit Kernel Dump | PAGE + DUMP | i386 / x86 Legacy | 150 MB β 800 MB | Legacy BugCheck & Memory Map |
| Event Log Query | Plain Text / Hex | Universal | < 50 KB | Stop String Matching, Remediation Checklist |
β Frequently Asked Questions
Why do some minidumps show 0x1000007F instead of 0x0000007F?
Windows Error Reporting (WER) frequently sets the high bit mask 0x10000000 when generating small memory dumps. 0x1000007F corresponds to UNEXPECTED_KERNEL_MODE_TRAP (0x7F). BWTools automatically identifies and strips this mask to match the canonical Microsoft BugCheck database.
What does Trap Code 0x00000008 (Double Fault) indicate?
A Double Fault occurs when the CPU attempts to trigger an exception handler while handling an earlier exception, resulting in an unrecoverable hardware halt. This almost always indicates either kernel stack overflow caused by recursive filter drivers (antivirus, VPN, or drive encryption) or physical memory/CPU cache instability.
Where are Windows Blue Screen crash dumps stored?
By default, Windows writes compact minidump snapshots to C:\Windows\Minidump\. Larger full-memory snapshots are written directly to C:\Windows\MEMORY.DMP. If the folder appears empty, ensure that your system has "Write debugging information" configured to "Small memory dump (256 KB)" within Advanced System Settings.
Why does my crash point to ntoskrnl.exe?
ntoskrnl.exe is the core Windows operating system kernel. When a third-party driver corrupts system memory or executes an invalid operation, the kernel catches the fault and triggers the Blue Screen to prevent data loss. The kernel is almost never defective itself; the true cause is usually an unverified third-party driver, unstable RAM timings, or a failing SSD.