| | |
(tough one) Algorithm for the datestamp on a BSOD – Reputation pts will be awarded!
![]() |
(tough one) Algorithm for the datestamp on a BSOD – Reputation pts will be awarded!
0
#1 Jan 31st, 2008
Hello All,
I am troubleshooting a problem with a 2k3 server that has been throwing Blue Screens. I am trying to figure out how to translate the datestamp to an actual time. Does anyone know the algorithm for windows DateStamp or how to figure out what time this DateStamp is for "45ed063d"?
Thanks,
AJZ
I am troubleshooting a problem with a 2k3 server that has been throwing Blue Screens. I am trying to figure out how to translate the datestamp to an actual time. Does anyone know the algorithm for windows DateStamp or how to figure out what time this DateStamp is for "45ed063d"?
Thanks,
AJZ
•
•
Join Date: Jan 2008
Posts: 6
Reputation:
Solved Threads: 0
Re: (tough one) Algorithm for the datestamp on a BSOD – Reputation pts will be awarded!
0
#2 Jan 31st, 2008
Re: (tough one) Algorithm for the datestamp on a BSOD – Reputation pts will be awarded!
0
#3 Feb 1st, 2008
•
•
Join Date: Jan 2008
Posts: 6
Reputation:
Solved Threads: 0
Re: (tough one) Algorithm for the datestamp on a BSOD – Reputation pts will be awarded!
0
#4 Feb 1st, 2008
Sorry, but that's not a proper basis on which to conduct any form of investigation: whilst it's correct to say that the content of the dump are important it is NOT correct to say [or imply] that the time is unimportant. This is especially true if one is seeing repeated events of a similar type on the same machine, or a spread of events across multiple machines.
Knowing precisely when an event occurs can help one to track causes.
In IT Forensics, just as in any other branch of forensics, one NEVER EVER throws any of the evidence away.
Knowing precisely when an event occurs can help one to track causes.
In IT Forensics, just as in any other branch of forensics, one NEVER EVER throws any of the evidence away.
Re: (tough one) Algorithm for the datestamp on a BSOD – Reputation pts will be awarded!
0
#5 Feb 1st, 2008
Re: (tough one) Algorithm for the datestamp on a BSOD – Reputation pts will be awarded!
0
#6 Feb 1st, 2008
rneuschul, evidence is one thing, but this is not forensic casework. DimaYasny is correct. the MiniDump is the first step (as well as looking at the Event Viewer) to diagnosing a BSOD.
zelkea, what I would suggest, is that you go into the dump settings and change it from a mini dump to a full complete memory dump, you will get far more information.
There is also software that you can download to analyze the dump logs and interpenetrate the information for you.
zelkea, what I would suggest, is that you go into the dump settings and change it from a mini dump to a full complete memory dump, you will get far more information.
There is also software that you can download to analyze the dump logs and interpenetrate the information for you.
Michael
Forensic IT Consultant / Designer | My DaniWeb Blog
Quis custodiet ipsos custodes?
Forensic IT Consultant / Designer | My DaniWeb Blog
Quis custodiet ipsos custodes?
Re: (tough one) Algorithm for the datestamp on a BSOD – Reputation pts will be awarded!
0
#7 Feb 1st, 2008
Hey Guys,
Hehe the confusion in my troubleshooting steps is due to that fact I did not post everything I have done up to this point (following the KISS philosophy in trying to get an answer to my question). I have already reviewed the memory.dmp and events on this box that indicated our backup software as being the culprit.
Rneuschul is correct, the exact time is important to me reason being is the backup software in question backs up lets say transaction for simplicity and the system is crashing when it hits a corrupt/orphaned transaction which are known to exist (long story but unavoidable). Therefore, if I am able to figure out the exact time the server is crashing I can use that information with other logs to track down the corrupted/orphaned transaction and fix it.
Michael,
I have been using Microsoft Debug Tools and dumpchk is there another application you would recommend?
AJZ
Hehe the confusion in my troubleshooting steps is due to that fact I did not post everything I have done up to this point (following the KISS philosophy in trying to get an answer to my question). I have already reviewed the memory.dmp and events on this box that indicated our backup software as being the culprit.
Rneuschul is correct, the exact time is important to me reason being is the backup software in question backs up lets say transaction for simplicity and the system is crashing when it hits a corrupt/orphaned transaction which are known to exist (long story but unavoidable). Therefore, if I am able to figure out the exact time the server is crashing I can use that information with other logs to track down the corrupted/orphaned transaction and fix it.
•
•
•
•
There is also software that you can download to analyze the dump logs and interpenetrate the information for you.
I have been using Microsoft Debug Tools and dumpchk is there another application you would recommend?
AJZ
![]() |
Other Threads in the Windows NT / 2000 / XP Forum
- Previous Thread: Unable to connect a 2003 server to a 2000 Domain
- Next Thread: can't get internet to work
| Thread Tools | Search this Thread |
.net 3.5 3daccelertion 64bit 2010 activedirectory alaris android application arm auto black blue book bsod canonical cellphones chinese codeplex collaboration combofix computer computerfreezes crash deployments desktop desktops domain dotnetnuke drive error errors explorer fax folder fonts freeze gadgets hardware home intel killprocess laptop laptops latitude lcd linux load mac markshuttleworth memory microsoft minimalizes mobile monitor netbooks opensource operatingsystems options oracle osinstallationproblem outlook partition patch port product program proxy raid rds reformat remotedesktopconnection retail screen security server. slowperformance sp1 sp3 spyware studios ubuntu unreadable update upgrade usb verizon virtual virus vpn vulnerability wab webos weecam window windows windows7 windowsxp worm xp






