27931: Creating Process Dumps with ProcDump

Also read in:

Translate to:

Operating Systems:

How to create crash/hang process dumps using ProcDump

Introduction

ProcDump (procdump.exe), a Windows Sysinternals tool. It allows you to create dumps of the processes in any scenario that may arise while troubleshooting issues with Acronis products.

(!) When Procdump captures the dump file, it does not kill the running process.

Solution

To create a dump with ProcDump, do the following:

  1. Download ProcDump from Windows Sysinternals site;
  2. Create a folder where dumps will be stored (e.g. C:\Dumps\);
  3. Unzip the archive and put the procdump.exe in to the created directory;
  4. Open Windows command-line: Hit Start -> Run and type in cmd. We recommend to run cmd with administrative privileges (right-click -> run as administrator), otherwise the utility might not find the required process;
  5. In CMD, switch to the newly created folder using the cd command:

    cd <path_to_folder> 

    For example: cd C:\Dumps

  6. Depending on the nature of the issue (immediate process crash, hanging process, lock-up etc.) choose what options are to be used with ProcDump. See the most common examples below:

    A. Situations when processes are crashing (e.g. right upon starting, or they crash randomly) can be universally handled by the following command:

    procdump -e -w -ma <process_name>

    E.g. if you have service_process.exe crashing, the command will look like:

    procdump -e -w -ma service_process.exe

    => this will execute ProcDump to monitor for the process to start (if it's not running yet) and create a full process memory dump as soon as it encounters unhandled exception and crashes.

    B. If you need to create a dump file of the running process in its current state (e.g. if there is a suspicion the process hangs or it is necessary to understand why the service uses a lot of resources, etc.), then the command is even simpler:

    procdump -ma <process_name>

    or using PID (useful if multiple processes with the same name are running):

    procdump -ma <process_PID> (where process_PID is the process identifier)

    E.g. in case mms.exe seems to be hanging, the following command can be used:

    procdump -ma mms.exe

    or

    procdump -ma 3255 (if 3255 is the process identifier)

    (!) The full list of the parameters can be found in on the ProcDump download page or by issuing command procdump /? ;

  7. Once the necessary dumps are created, you can locate them in the same folder where ProcDump resides (e.g. C:\Dumps\);
  8. Compress the process dump into a .zip file;
  9. It is recommended to collect a fresh output of AcronisInfo Utility;
  10. Send the dump file (with the Acronis info output) to Acronis Customer Central via FTP: see Uploading Files to Acronis FTP Server. A unique FTP link tied to your case can be provided by the Support Engineer assigned to your case.

More information

To collect dump files of multiple processes with a given name:

  1. Navigate to the directory where procdump.exe is located.
  2. Execute:
    for /f "tokens=2 delims=," %F in ('tasklist /nh /fi "imagename eq <process>.exe" /fo csv') do procdump -ma %~F SP_%~F.dmp
    where <process> is the name of the process(es) you are collecting dumps of, for example service_process.exe

    Or create a batch file with this command:
    for /f "tokens=2 delims=," %%F in ('tasklist /nh /fi "imagename eq <process>.exe" /fo csv') do procdump -ma %%~F SP_%%~F.dmp
    where <process> is the name of the process(es) you are collecting dumps of, for example service_process.exe

Please also check the Process Explorer tool which can be useful for dumps creation:

http://technet.microsoft.com/en-en/sysinternals/bb896653.aspx

This tool detects which dump (32/64 Bit) should be created automatically.

See also:

 

Tags: 

You are reporting a typo in the following text:
Simply click the "Send typo report" button to complete the report. You can also include a comment.
CAPTCHA
This question is for testing whether or not you are a human visitor and to prevent automated spam submissions.
2 + 6 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.