Tuesday, August 5, 2008

How to read the small memory dump files that Windows creates for debugging

 

How to read the small memory dump files that Windows creates for debugging

 

Article ID: 315263

Last Review: December 3, 2007

Revision: 4.5

This article was previously published under Q315263

SUMMARY

This step-by-step article describes how to examine a small memory dump file. You can use this file to determine why your computer has stopped responding.

Small memory dump files

A small memory dump file records the smallest set of useful information that may help identify why your computer has stopped unexpectedly. This option requires a paging file of at least 2 megabytes (MB) on the boot volume. On computers that are running Microsoft Windows 2000 or later, Windows create a new file every time your computer stops unexpectedly. A history of these files is stored in a folder.
This dump file type includes the following information:
  • The Stop message and its parameters and other data
  • A list of loaded drivers
  • The processor context (PRCB) for the processor that stopped
  • The process information and kernel context (EPROCESS) for the process that stopped
  • The process information and kernel context (ETHREAD) for the thread that stopped
  • The Kernel-mode call stack for the thread that stopped

The small memory dump file can be useful when hard disk space is limited. However, because of the limited information that is included, errors that were not directly caused by the thread that was running at the time of the problem may not be discovered by an analysis of this file.
If a second problem occurs and if Windows creates a second small memory dump file, Windows preserves the previous file. Windows gives each file a distinct, date-encoded file name. For example, Mini022900-01.dmp is the first memory dump file that was generated on February 29, 2000. Windows keeps a list of all the small memory dump files in the %SystemRoot%\Minidump folder.

Follow link for complete KB Article on how to view the Minidump files.

How to read the small memory dump files that Windows creates for debugging

No comments:

Blog Archive