Wilders Security Forums  

Go Back   Wilders Security Forums > Official Returnil Support Forum > General Returnil discussions
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 25th, 2010, 07:34 PM
caspian's Avatar
caspian caspian is offline
Very Frequent Poster
 
Join Date: Jun 2007
Location: Oz
Posts: 1,806
Default Crash Memory Dump

I am wondering if this has something to do with Returnil. I keep getting this ever so often. The screen turns blue and it says that windows has been stopped....crash memory dump, or something like that. Is this from downloading more than Returnil can handle? My operating system is Vista 64 bit
__________________
A Billion for a Billion

http://www.wfp.org/1billion
  #2  
Old January 25th, 2010, 08:23 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Crash Memory Dump

You could use this tool from Nirsoft to show you the blue screen again and note what is causing the problem.
Quote:
* Automatically scans your current minidump folder and displays the list of all crash dumps, including crash dump date/time and crash details.
* Allows you to view a blue screen which is very similar to the one that Windows displayed during the crash.
* BlueScreenView enumerates the memory addresses inside the stack of the crash, and find all drivers/modules that might be involved in the crash.
* BlueScreenView also allows you to work with another instance of Windows, simply by choosing the right minidump folder (In Advanced Options).
* BlueScreenView automatically locate the drivers appeared in the crash dump, and extract their version resource information, including product name, file version, company, and file description.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #3  
Old January 25th, 2010, 10:02 PM
caspian's Avatar
caspian caspian is offline
Very Frequent Poster
 
Join Date: Jun 2007
Location: Oz
Posts: 1,806
Default Re: Crash Memory Dump

I am not sure if I have enough knowledge to use this but I will give it a try. Thanks!
__________________
A Billion for a Billion

http://www.wfp.org/1billion
  #4  
Old January 25th, 2010, 10:32 PM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,750
Default Re: Crash Memory Dump

Hi caspian,
Please check your system event logs for a critical event at the same time for anything related to RVS. Please let me know the text.

Thanks
Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
  #5  
Old January 28th, 2010, 10:47 AM
caspian's Avatar
caspian caspian is offline
Very Frequent Poster
 
Join Date: Jun 2007
Location: Oz
Posts: 1,806
Default Re: Crash Memory Dump

I am embarrassed to say that I do not know how to do that. But I will google it and see if I can figure it out. Thanks

A question though. When I get a crash memory dump while returnil is active, does that nullify the protection that Returnil would ordinarily offer? I mean is everything still returned to normal after restart? Or could malware get through?

Oh I did notice one ting. Keyscrambler was listed in the blue screen but it just had some numbers listed after it.
__________________
A Billion for a Billion

http://www.wfp.org/1billion
  #6  
Old January 28th, 2010, 11:16 AM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,750
Default Re: Crash Memory Dump

Quote:
When I get a crash memory dump while returnil is active, does that nullify the protection that Returnil would ordinarily offer?

If the virtualization is active, you can verify whether it is still functional in the face of a BSOD by looking in your %system%\Windows\minidump folder. If no minidump file exists for the time of the BSOD, then virtualization is working and why it is often difficult to obtain minidump and kernel memory dump files for analysis.

Quote:
Oh I did notice one ting. Keyscrambler was listed in the blue screen but it just had some numbers listed after it.

This is why I asked you to check for the issue in the Event Viewer. This seems to indicate that the cause of the critical stop is Keyscrambler and not RVS, but it is impossible to say for certain until getting a better look at the error text.

Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
  #7  
Old January 29th, 2010, 06:05 PM
caspian's Avatar
caspian caspian is offline
Very Frequent Poster
 
Join Date: Jun 2007
Location: Oz
Posts: 1,806
Default Re: Crash Memory Dump

I found the event viewer in the control panel. However, I haven't the slightest idea what I am looking out.

But I did get an update titled "Windows Vista Hotfix QFE960884 update resolves an issue with the system crashing when a 1394 storage device is connected". I always have my external hard drive connected. And I usually have a USB stick plugged in as well. So I guess that was the problem. Thanks for the input.
__________________
A Billion for a Billion

http://www.wfp.org/1billion
 

Wilders Security Forums > Official Returnil Support Forum > General Returnil discussions « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:12 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums