How can I dump the memory of a process in Windows 7?

18,733

Solution 1

just "right click" the process in the taskmanager and select "create memory dump"

alt text

Solution 2

Simplest is probably procdump from SysInternals.

The Debugging Tools for Windows gives more advanced options (e.g. automatically dump the process on certain conditions).

Share:
18,733
abmv
Author by

abmv

Updated on September 17, 2022

Comments

  • abmv
    abmv over 1 year

    Are there any tools to dump the running application from memory in Windows 7?

  • abmv
    abmv almost 14 years
    can i still be able to run that file?
  • akira
    akira almost 14 years
    @abmv: "run" as in .. start the dump? or do you ask if the dumping process stops the process? if it is the latter: dumping the memory does not stop the process.
  • abmv
    abmv almost 14 years
    well i'm looking for something like PROCDUMP32
  • akira
    akira almost 14 years
    @abmv: well, that is not what you asked for in the first place. a good tool for reverse engineering is "ida pro" (hex-rays.com/idapro).
  • abmv
    abmv almost 14 years
    i guess the word dump was misleading thanks for you reply
  • Breakthrough
    Breakthrough almost 13 years
    Do note that you can only do this on Windows 6.x variants (Win7/Vista/2008). Win5.x cannot do this without Process Explorer from SysInternals.
  • akira
    akira almost 13 years
    yep, but thats what OP wanted :)