Jump to content

Saving a Memory Dump in Windows Vista, Windows 2008, and Windows 7


Recommended Posts

This is a quick guide on how to save a Memory Dump from Malwarebytes' Anti-Malware on Windows Vista, Windows 2008, and Windows 7 (this tutorial does not apply to Windows XP, Windows 2003, or Windows 2000). I will also include some instructions on how to get Memory Dump file to us, as it will be too large to attach it to a reply on the forums.

Before beginning, you may want to run a utility such as ATF Cleaner (no longer online) to clean out your temp files (ignore the warning on the download page that says it's for Windows XP and Windows 2000 only, they just haven't updated their download page in a very long time, and ATF Cleaner works just fine on Windows Vista and Windows 7). This will make it easier to find the Memory Dump after you have saved it.

Step 1

Press
Ctrl
+
Shift
+
Esc
on your keyboard (all at the same time) to open the Task Manager.

Step 2

Switch to the
Processes
tab (see screenshot below).

image.png.3416086c8524ab287b3e8e7c8d55519a.png

Step 3

Click the button in the lower-left that says
Shows processes from all users
(see screenshot below), otherwise Windows will not allow you to save the Memory Dump (this step does not apply if you have disabled the UAC in Windows).

image.png.6b953c6ad02a3514c6364894519a33d5.png

Step 4

Find
mbam.exe
in the list of processes (see screenshot below). Note that this list should be in alphabetical order.

image.png.337689496e79c6cd8b8e336a17993189.png

Step 5

After you have found
mbam.exe
in the list, please right-click on it, and select
Create Dump File
from the list (see screenshot below).

image.png.aff3051ba4744f55fd92734af7e8a8dc.png

Step 6

Once it's done saving the Memory Dump, it will pop up a little box that tells you where that memory dump was saved (see screenshot below).

image.png.a4e67d9900c4c7acc6f5104ce30aead3.png

Using your mouse, please highlight the part of the path to the file before where it says /mbam.DMP (see screenshot below).

image.png.d7a5dc1cfa02813a2eaaac65aebb328e.png

After highlighting as seen in the screenshot above, please copy (you may have to use the keyboard shortcut Ctrl + C in order to copy it) the part that you have highlighted. You can click to close the notification after copying.

Step 7

Click on the
Start
button (the little round Windows Logo button in the lower-left corner of the screen), and paste the path you had copied into the
Search
field at the bottom of the Start Menu (see screenshot below) and then press
Enter
on your keyboard to open the folder where the Memory Dump was saved. Note that if you didn't copy the path to where the Memory Dump was saved correctly, then you can repeat steps 1-6 as many times as you need to in order to get it right.

image.png.14b4c91d6c045f59a2bb6c1d6ac97032.png

Step 8

Find the Memory Dump file in the list of files. It should be called
mbam.DMP
and the list will be in alphabetical order (see screenshot below). Once you find it, take note of the size. It's way too big to send to us in a reasonable amount of time, so we'll show you have to take care of that.

image.png.a255d5162a65b81d821017ef68b05268.png

Step 9

Right-click on the
mbam.DMP
file, go to
Send to
, and then click on
Compressed (zipped) folder
in order to make the Memory Dump smaller (see screenshot below).

image.png.9f6d21e7a57edd918451a24788b77007.png

(Note that if you have a utility such as 7-Zip, WinRar, WinZip, etc. that you may use them to do this as well. We will accept most compressed archive formats, although we do prefer 7z, RAR, and ZIP. GZip and BZip2 are also fine for single files like this. Essentially, as long as 7-Zip and WinRar can both open it, we should be OK with it.)

Step 10

You'll note that, once it's done, it will have created a new file. This new file is a ZIP Archive that contains the Memory Dump file, but also made it smaller, and now it is in a better format to send over the Internet (see screenshot below). Please cut and paste this new file onto your desktop so that you will have easy access to it when sending it to us.

image.png.fbaa51571cb85966a5fe22f391ce64e3.png

Step 11

Unless you have some sort of online file storage that allows you to give us a link to download the Memory Dump, then you will need to use one of the free FileSharing services such as
or
(you can ignore all of their ads about paying for the 'Pro'/'Premium' service, as you will only be sending us the one file). Once you have uploaded the ZIP Archive with the Memory Dump inside it, please send us your link either by posting it on the forums, or by whatever method the person assisting you requested that you send them your link.
Once we have received your link, our developers will take a look at your Memory Dump as soon as they can.
Edited by GT500
Fix missing images.
Link to post
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.