Surprising fact: a single stop code can cut work short—Windows shows a full-screen crash to prevent data loss, and many crashes trace to drivers, disk errors, or malware.
My goal was simple: restore a stable Windows system and protect my data by isolating the root cause without making risky changes.
The blue screen of death (BSOD) is Windows intentionally stopping a failing system. The on-screen stop code, and any named file, give the first diagnostic clues.
Booting to Safe Mode loaded only core services. From there I ran a malware scan, rolled back drivers, used SFC and DISM to repair system files, and checked storage and memory with CHKDSK and the Windows Memory Diagnostic.
If recent updates or new hardware preceded the crash, rolling those changes back often stabilizes the computer. When basic repairs fail, the Windows Recovery Environment and Startup Repair can help.
Key Takeaways
- Use stop codes and file names on the BSOD as your first clues.
- Boot to Safe Mode to run scans and roll back recent changes safely.
- Scan for malware first, then repair system files with SFC/DISM.
- Check disk health (CHKDSK) and RAM (Windows Memory Diagnostic) for hardware causes.
- If needed, use Startup Repair or the recovery environment to restore boot stability.
For a step-by-step guide on common remedies, see a trusted walkthrough at how to fix the blue screen of.
Why your screen turned blue: BSOD basics, virus ties, and user intent today
A BSOD is Windows halting after a critical failure, often from drivers, storage corruption, or malware tampering with system files. On Windows 10/11, note the on-screen stop code and QR code, then use Safe Mode, scans, and targeted repairs to prevent repeat crashes.
What it means: A system crash happens when the operating system finds a condition it cannot safely continue from. Common triggers are incompatible drivers, bad updates, NTFS corruption, failing RAM, and sometimes malware that alters system files.
![]()
Timing matters. If the blue screen came after a driver install, update, or new hardware, that change is likely the cause. One-off crashes can be benign. Repeating crashes demand action: gather the stop code, note any named .sys file, and start diagnostics from Safe Mode.
| Stop code type | Likely cause | First action | When to escalate |
|---|---|---|---|
| Storage / NTFS | Disk errors, file system corruption | Run CHKDSK and check SMART | Drive failures or repeated NTFS codes |
| Memory | Faulty RAM or driver misuse | Run Windows Memory Diagnostic | Persistent DATA_BUS_ERROR or PAGE_FAULT codes |
| Driver / GPU | Outdated or incompatible drivers | Rollback or update drivers in Safe Mode | VIDEO_TDR loops or hardware errors |
| Malware-related | System file tampering or memory exhaustion | Full antivirus scan in Safe Mode | Recurrent crashes after cleaning |
For deeper reading on memory-related stop codes, see the page fault walkthrough.
Diagnose the crash first: read the stop code, retrace changes, and gather clues
Start by capturing the stop code and any named driver shown on the crash page; those identifiers point you to the subsystem at fault.
Photograph or note the on-screen stop code and any referenced .sys or file name. Common codes include CRITICAL_PROCESS_DIED (0x000000EF), IRQL_NOT_LESS_OR_EQUAL (0x0000000A), and NTFS_FILE_SYSTEM (0x00000024).
Then, map codes to categories. Memory and IRQL errors often implicate drivers or RAM. NTFS errors suggest disk or file system corruption. TDR or video timeouts point to GPU drivers or device timeouts.

- List recent changes: Windows updates, driver installs, new hardware, or software. Treat recent changes as test candidates for rollback.
- Use Event Viewer: Open Windows Logs > System and filter by Error/Warning around the crash time to find corroborating messages.
- Collect minidumps: Minidump files hold stack traces that reveal the failing module for deeper analysis.
- Run OEM diagnostics: Pre-boot vendor tools (example: Dell SupportAssist Pre-Boot) can check disks, memory, and components quickly.
Tip: Keep changes minimal and reversible so you can confirm cause without adding variables.
Get into Safe Mode to stabilize Windows and start troubleshooting
AI-Overview: Use Shift + Restart from the sign-in screen or Settings > System (Update & Security on Windows 10) > Recovery > Advanced startup to boot Safe Mode. Choose plain Safe Mode to isolate third-party services, add Networking to download updates or antivirus definitions, or pick the Command Prompt option for direct CLI repairs.
When the operating system behaves unpredictably, booting to Safe Mode reduces variables. It loads essential drivers only, so third-party services and many device drivers stay offline.

How to reach Safe Mode (two quick paths)
From the sign-in screen: hold Shift while you select Restart. Then choose Troubleshoot > Advanced options > Startup Settings > Restart and pick 4, 5, or 6.
From a working desktop: open Settings > System (or Update & Security on Windows 10) > Recovery > Advanced startup > Restart now. Follow Troubleshoot > Advanced options > Startup Settings and choose the variant you need.
Which Safe Mode should you pick?
- Safe Mode (4): Isolate third-party drivers and services to see if the system stays stable.
- Safe Mode with Networking (5): Use this when you must download updated antivirus definitions, drivers, or Microsoft files for DISM repairs.
- Safe Mode with Command Prompt (6): Choose this if the desktop is unstable but you need to run
sfc /scannow, DISM, orchkdskmanually.
“Keep peripherals disconnected except keyboard and mouse — nonessential devices can reintroduce the problem.”
If Windows won’t reach Safe Mode by normal restart, force three failed boots to trigger the Windows Recovery Environment automatically. While you work, keep the device on stable power to avoid file system damage.
For users who see repeated stop errors at startup, consult the sign-in troubles walkthrough for additional recovery options.
How to fix blue screen virus issues from Safe Mode
AI-Overview: In Safe Mode, run a full antivirus scan to remove malware and PUAs, then repair Windows with SFC and DISM. Reboot, rescan, and confirm the system stays stable before addressing drivers or hardware.
Begin in Safe Mode to isolate malicious processes and protect critical files during cleanup. Use Safe Mode with Networking if you must update definitions. If you cannot connect, use an offline scanner on a clean USB.
Run a full antivirus scan and remove PUAs to stop recurring crashes
Start with a full antivirus scan using updated signatures. Remove identified threats and potentially unwanted applications (PUAs) that inject drivers or hijack startup.
Quarantine anything suspicious. Don’t restore quarantined items until you verify they are false positives.

Repair corrupted system files with SFC and DISM
Open an elevated Command Prompt and run these commands in order:
sfc /scannow— checks and replaces damaged system files.DISM /Online /Cleanup-Image /RestoreHealth— repairs the component store if SFC cannot complete.
Run SFC again after DISM finishes. These commands restore core Windows files so the OS can stop recurring errors caused by corrupted binaries.
Quarantine, reboot, and rescan to verify a clean system
Reboot after repairs so Windows loads clean components. Then run another full scan to ensure no threat reappears at startup.
Keep logs of what was found and which files were repaired. If infections return, move to driver rollbacks and hardware checks.
| Step | Action | When to use |
|---|---|---|
| Scan | Full AV scan + remove PUAs | First step in Safe Mode with Networking |
| Repair | SFC then DISM commands | If SFC reports unfixable files |
| Verify | Reboot and rescan | After repairs before driver updates |
Stabilize system files, drivers, and storage
AI-Overview: Undo recent driver changes first—start with GPU, storage, and network adapters. Then test RAM with Windows Memory Diagnostic and scan the drive with CHKDSK (use /r to repair bad sectors) to rule out hardware-backed crashes.
Start by reverting recent device changes and validating hardware to remove common sources of system instability.
How do I roll back or update a problem driver?
Open Device Manager, find the suspect adapter, then choose Properties > Driver > Roll Back Driver when available. This reverses a recent driver update quickly.
If Roll Back is unavailable, download a prior stable driver from the vendor site and install it cleanly. Prioritize graphics, storage, and network adapters—these drivers most often appear in crash traces and minidumps.

How do I check RAM and the hard drive?
Run Windows Memory Diagnostic: search the tool, choose Restart now and check for problems, and repeat with the Extended test (press F1) if you suspect intermittent RAM faults.
For disks, open an elevated Command Prompt. Type chkdsk to scan, then run chkdsk /r to repair logical errors and relocate bad sectors on a hard drive or SSD.
Note: PAGE_FAULT_IN_NONPAGED_AREA, DATA_BUS_ERROR, and NTFS_FILE_SYSTEM codes often point to RAM or disk faults. Replace or reseat failing components promptly.
| Action | What to do | When to use |
|---|---|---|
| Driver rollback | Device Manager → Properties → Roll Back Driver; or install previous vendor driver | After a recent driver update or if minidump names a driver |
| Memory test | Windows Memory Diagnostic → Restart now; use Extended for thorough testing | If you see memory-related stop codes or random crashes |
| Disk check | chkdsk to scan; chkdsk /r to repair sectors and file system errors | When Event Viewer shows disk warnings or NTFS errors |
| Physical check | Reseat RAM sticks, storage cables, and expansion cards; confirm firmware is current | For intermittent faults or after hardware changes |
After stabilizing: test the system for several reboots before applying new driver updates. If you need more recovery options, see Microsoft’s troubleshooting guide: how to resolve startup errors.
If Windows still crashes: recovery tools and advanced fixes
When Windows keeps failing to boot, the Recovery Environment gives targeted tools to rebuild startup files and recover access. Use this path when Safe Mode and scans do not stop the repeated BSOD errors.
Trigger the environment by interrupting boot three times or by choosing Advanced startup from Settings. Then select Troubleshoot > Advanced options and run Startup Repair. This tool rewrites boot records and fixes common startup corruption.

Run disk and firmware checks
Open the elevated Command Prompt from Advanced options and run chkdsk /r on the system drive to scan sectors and recover readable data. This command helps when NTFS or I/O errors trigger stop codes.
If you see INACCESSIBLE_BOOT_DEVICE errors, review BIOS/UEFI storage mode and restore defaults if settings were changed. Mismatched controller modes (RAID vs. AHCI) often block booting.
- Keep BitLocker keys handy—repairs may prompt recovery on encrypted drives.
- Use vendor recovery tools when available to automate driver and firmware checks; see Dell’s recovery resource for examples: Dell recovery options.
- Disconnect peripherals during repair and reconnect one at a time to isolate problematic hardware or drivers.
Note: If errors persist after these steps, back up data and prepare for a clean Windows install—persistent failures may indicate failing hardware beyond repair.
Prevent the next BSOD: maintenance, updates, and safe computing habits
Preventing future crashes starts with steady maintenance and a simple update routine. Keep the operating system, drivers, and firmware current. Monitor temperature and remove unnecessary software to reduce instability.
Schedule regular updates for Windows and device drivers to patch compatibility gaps and known bugs. Firmware and BIOS updates from the vendor often resolve hidden hardware issues that cause blue screens.

Control heat: clean dust, ensure good airflow, and avoid aggressive overclocking. Overheating stresses components and triggers sporadic failures in the system.
Trim startup items and uninstall unused software to lower conflicts. Keep a small, trusted security toolkit and run periodic SFC/DISM and CHKDSK checks to catch corruption early.
“Document a stable baseline: record driver and firmware versions so you can restore a known-good state quickly.”
- Keep automated updates and weekly driver checks.
- Back up critical files with versioned copies and test restores.
- When repeated problems persist after scans and driver stabilization, prepare for a clean Windows reinstall and reintroduce apps slowly.
For guidance on persistent malware that keeps returning, see our walkthrough on removing recurring threats: remove persistent malware.
Conclusion
AI-Overview: Treat BSOD troubleshooting like a short investigation: collect the stop code, boot into Safe Mode, remove active threats, repair system files with SFC/DISM, stabilize drivers, and test disks and memory. If problems persist, use Startup Repair or the Windows Recovery Environment and consider a clean reinstall after a secure backup.
You now have a reproducible checklist. Identify the stop code and recent changes. Work in Safe Mode so scans and repairs run without repeated crashes.
Neutralize active threats first, then repair core files. Roll back or update drivers in small steps. Confirm hard drive and memory health with CHKDSK (/r) and Windows Memory Diagnostic. If booting fails, run Recovery Environment tools or OEM diagnostics. Back up essentials and perform a clean reinstall when software remediation cannot restore stability.