MemSnap Examples |
|
Open Command Prompt |
To generate a snapshot of memory resources being consumed, type the following at the command line:
memsnap c:\data\memsnap.txt
This command sends the memory data to the Memsnap.txt file in the c:\data directory. Your output will look similar to the following:
Process ID Proc.Name Wrkng.Set PagedPool NonPgdPl Pagefile Commit Handles Threads
00000000 (null) 16384 0 0 0 0 0 1
00000008 System 217088 0 0 24576 24576 231 35
00000094 SMSS.EXE 356352 5944 1252 1122304 1122304 33 6
000000AC csrss.exe 2297856 38676 5520 1363968 1363968 326 10
000000A8 WINLOGON.EXE 3530752 38376 62220 5906432 5906432 359 16
000000DC services.exe 3375104 29640 216364 2564096 2564096 491 30
000000E8 LSASS.EXE 1232896 28100 37176 1961984 1961984 301 13
0000018C svchost.exe 3284992 27592 16896 1318912 1318912 273 8
000001A8 SPOOLSV.EXE 3018752 20436 12904 2199552 2199552 104 10
000001C4 Avsynmgr.exe 2412544 19976 3428 1265664 1265664 98 4
000001D4 svchost.exe 2916352 39148 62548 3952640 3952640 398 26
000001F8 regsvc.exe 774144 8056 9548 241664 241664 30 2
00000208 mstask.exe 2912256 25596 15212 1032192 1032192 138 6
00000250 WinMgmt.exe 151552 15752 3208 651264 651264 90 3
0000028C VSStat.exe 1294336 20264 3324 1228800 1228800 67 2
00000158 vshwin32.exe 1253376 22192 5136 2736128 2736128 107 7
000002C0 MCSHIELD.EXE 3710976 13060 20872 2306048 2306048 113 16
00000318 Avconsol.exe 2777088 20944 3948 1413120 1413120 67 2
0000035C explorer.exe 2588672 50452 18996 4829184 4829184 334 14
000003E0 SETI@home.exe 16777216 26072 5724 16412672 16412672 126 3
00000388 winmine.exe 1069056 17080 2032 294912 294912 23 1
000003AC cmmon32.exe 720896 15904 2580 352256 352256 52 3
00000404 MDM.EXE 2183168 18908 3676 692224 692224 81 4
00000380 SSEXP.EXE 3584000 25104 3064 1298432 1298432 60 4
000004A0 OUTLOOK.EXE 11087872 76724 20362 4177920 4177920 305 11
00000358 MAPISP32.EXE 4001792 30036 9032 1421312 1421312 172 7
00000438 homesite45.exe 23937024 50808 10984 22159360 22159360 203 7
00000370 CMD.EXE 856064 13628 1616 253952 253952 23 1
000002A8 notepad.exe 2146304 19864 2552 720896 720896 42 2
0000030C memsnap.exe 737280 12556 1704 307200 307200 18 1
To generate a snapshot of memory, GDI, and user resources being consumed, type the following at the command line:
memsnap /g
This command sends the memory data to the Memsnap.log file in
the
Process ID Proc.Name Wrkng.Set PagedPool NonPgdPl Pagefile Commit Handles Threads
00000000 (null) 16384 0 0 0 0 0 1
00000008 System 217088 0 0 24576 24576 231 35
00000094 SMSS.EXE 356352 5944 1252 1122304 1122304 33 6
000000AC csrss.exe 2072576 37332 5312 1359872 1359872 327 10
000000A8 WINLOGON.EXE 3530752 38376 62220 5906432 5906432 359 16
000000DC services.exe 3375104 29640 216364 2564096 2564096 491 30
000000E8 LSASS.EXE 1232896 28100 37176 1961984 1961984 301 13
0000018C svchost.exe 3284992 27592 16896 1318912 1318912 273 8
000001A8 SPOOLSV.EXE 3026944 20436 12904 2199552 2199552 105 10
000001C4 Avsynmgr.exe 2412544 19976 3428 1265664 1265664 98 4
000001D4 svchost.exe 2916352 39148 62548 3952640 3952640 398 26
000001F8 regsvc.exe 774144 8056 9548 241664 241664 30 2
00000208 mstask.exe 2912256 25596 15212 1032192 1032192 138 6
00000250 WinMgmt.exe 151552 15752 3208 651264 651264 90 3
0000028C VSStat.exe 1294336 20264 3324 1228800 1228800 67 2
00000158 vshwin32.exe 1249280 22192 5136 2736128 2736128 107 7
000002C0 MCSHIELD.EXE 3694592 13060 20872 2301952 2301952 113 16
00000318 Avconsol.exe 2777088 20944 3948 1413120 1413120 67 2
0000035C explorer.exe 2416640 49456 18424 4546560 4546560 308 17
000003E0 SETI@home.exe 16773120 26072 5724 16412672 16412672 126 3
00000388 winmine.exe 1069056 17080 2032 294912 294912 23 1
000003AC cmmon32.exe 720896 15904 2580 352256 352256 52 3
00000404 MDM.EXE 2191360 18940 3780 704512 704512 91 5
00000380 SSEXP.EXE 3584000 25104 3064 1298432 1298432 60 4
000004A0 OUTLOOK.EXE 11083776 76404 20466 4190208 4190208 314 12
00000358 MAPISP32.EXE 4001792 30036 9032 1421312 1421312 172 7
00000438 homesite45.exe 23564288 50808 10932 21811200 21811200 204 7
00000370 CMD.EXE 856064 13628 1616 253952 253952 23 1
000004A4 memsnap.exe 737280 12556 1704 307200 307200 18 1
00000000 (null) 16384 0 0 0 0 0 1 0 0
00000008 System 217088 0 0 24576 24576 231 35 0 0
00000094 SMSS.EXE 356352 5944 1252 1122304 1122304 33 6 0 0
000000AC csrss.exe 2306048 38604 5520 1372160 1372160 325 10 0 0
000000A8 WINLOGON.EXE 3530752 38376 62220 5906432 5906432 359 16 8 20
000000DC services.exe 3375104 29640 216364 2564096 2564096 491 30 1 6
000000E8 LSASS.EXE 1232896 28100 37176 1961984 1961984 301 13 0 4
0000018C svchost.exe 3284992 27592 16896 1318912 1318912 273 8 0 4
000001A8 SPOOLSV.EXE 3018752 20436 12904 2199552 2199552 104 10 0 4
000001C4 Avsynmgr.exe 2412544 19976 3428 1265664 1265664 98 4 0 4
000001D4 svchost.exe 2916352 39148 62548 3952640 3952640 398 26 6 8
000001F8 regsvc.exe 774144 8056 9548 241664 241664 30 2 0 0
00000208 mstask.exe 2912256 25596 15212 1032192 1032192 138 6 1 4
00000250 WinMgmt.exe 151552 15752 3208 651264 651264 90 3 0 4
0000028C VSStat.exe 1294336 20264 3324 1228800 1228800 67 2 29 20
00000158 vshwin32.exe 1253376 22192 5136 2736128 2736128 107 7 2 6
000002C0 MCSHIELD.EXE 3710976 13060 20872 2306048 2306048 113 16 1 4
00000318 Avconsol.exe 2777088 20944 3948 1413120 1413120 67 2 18 63
0000035C explorer.exe 3923968 51568 19152 4935680 4935680 345 14 215 216
000003E0 SETI@home.exe 17829888 26072 5776 17465344 17465344 126 3 9 24
00000388 winmine.exe 1069056 17080 2032 294912 294912 23 1 7 41
000003AC cmmon32.exe 720896 15904 2580 352256 352256 52 3 14 12
00000404 MDM.EXE 2174976 18524 3572 675840 675840 78 3 1 4
00000380 SSEXP.EXE 3584000 25104 3064 1294336 1294336 60 4 68 68
000004A0 OUTLOOK.EXE 11128832 76372 20362 4202496 4202496 304 11 140 215
00000358 MAPISP32.EXE 4014080 30036 9032 1421312 1421312 172 7 6 29
00000438 homesite45.exe 24576000 50872 11080 22794240 22794240 203 7 294 543
00000370 CMD.EXE 860160 13628 1616 258048 258048 23 1 0 4
000002A8 notepad.exe 2146304 19864 2552 720896 720896 42 2 10 25
0000030C memsnap.exe 737280 12556 1704 307200 307200 18 1 0 4
00000000 (null) 16384 0 0 0 0 0 1 0 0
00000008 System 217088 0 0 24576 24576 231 35 0 0
00000094 SMSS.EXE 356352 5944 1252 1122304 1122304 33 6 0 0
000000AC csrss.exe 2269184 38048 5468 1372160 1372160 323 10 0 0
000000A8 WINLOGON.EXE 3530752 38376 62220 5906432 5906432 359 16 8 20
000000DC services.exe 3375104 29640 216364 2564096 2564096 491 30 1 6
000000E8 LSASS.EXE 1257472 28132 37280 1994752 1994752 301 14 0 4
0000018C svchost.exe 3284992 27592 16896 1318912 1318912 273 8 0 4
000001A8 SPOOLSV.EXE 3018752 20436 12904 2199552 2199552 104 10 0 4
000001C4 Avsynmgr.exe 2412544 19976 3428 1265664 1265664 98 4 0 4
000001D4 svchost.exe 2916352 39148 62548 3952640 3952640 398 26 6 8
000001F8 regsvc.exe 774144 8056 9548 241664 241664 30 2 0 0
00000208 mstask.exe 2912256 25596 15212 1032192 1032192 138 6 1 4
00000250 WinMgmt.exe 151552 15752 3208 651264 651264 90 3 0 4
0000028C VSStat.exe 1294336 20264 3324 1228800 1228800 67 2 29 20
00000158 vshwin32.exe 1253376 22192 5136 2736128 2736128 107 7 2 6
000002C0 MCSHIELD.EXE 3710976 13060 20872 2306048 2306048 113 16 1 4
00000318 Avconsol.exe 2777088 20944 3948 1413120 1413120 67 2 18 63
0000035C explorer.exe 4997120 51216 19256 4960256 4960256 349 15 215 217
000003E0 SETI@home.exe 17829888 26072 5776 17465344 17465344 126 3 9 24
00000388 winmine.exe 1069056 17080 2032 294912 294912 23 1 7 41
000003AC cmmon32.exe 720896 15904 2580 352256 352256 52 3 14 12
00000404 MDM.EXE 2174976 18524 3572 675840 675840 78 3 1 4
00000380 SSEXP.EXE 3584000 25104 3064 1294336 1294336 60 4 68 68
000004A0 OUTLOOK.EXE 11485184 76596 20886 4202496 4202496 311 11 140 215
00000358 MAPISP32.EXE 4026368 30036 9032 1421312 1421312 172 7 6 29
00000438 homesite45.exe 24723456 50808 10984 22941696 22941696 203 7 294 543
00000370 CMD.EXE 860160 13628 1616 258048 258048 23 1 0 4
000004BC memsnap.exe 733184 12556 1704 307200 307200 18 1 0 4
To generate a snapshot of memory resources being consumed with tagging information, type the following at the command line:
memsnap /t c:\data\memsnap.txt
This command sends the memory data to the Memsnap.txt file in
the
Process ID Proc.Name Wrkng.Set PagedPool NonPgdPl Pagefile Commit Handles Threads
00000000 (null) 16384 0 0 0 0 0 1
00000008 System 217088 0 0 24576 24576 231 35
00000094 SMSS.EXE 356352 5944 1252 1122304 1122304 33 6
000000AC csrss.exe 2297856 38676 5520 1363968 1363968 326 10
000000A8 WINLOGON.EXE 3530752 38376 62220 5906432 5906432 359 16
000000DC services.exe 3375104 29640 216364 2564096 2564096 491 30
000000E8 LSASS.EXE 1232896 28100 37176 1961984 1961984 301 13
0000018C svchost.exe 3284992 27592 16896 1318912 1318912 273 8
000001A8 SPOOLSV.EXE 3018752 20436 12904 2199552 2199552 104 10
000001C4 Avsynmgr.exe 2412544 19976 3428 1265664 1265664 98 4
000001D4 svchost.exe 2916352 39148 62548 3952640 3952640 398 26
000001F8 regsvc.exe 774144 8056 9548 241664 241664 30 2
00000208 mstask.exe 2912256 25596 15212 1032192 1032192 138 6
00000250 WinMgmt.exe 151552 15752 3208 651264 651264 90 3
0000028C VSStat.exe 1294336 20264 3324 1228800 1228800 67 2
00000158 vshwin32.exe 1253376 22192 5136 2736128 2736128 107 7
000002C0 MCSHIELD.EXE 3710976 13060 20872 2306048 2306048 113 16
00000318 Avconsol.exe 2777088 20944 3948 1413120 1413120 67 2
0000035C explorer.exe 2588672 50452 18996 4829184 4829184 334 14
000003E0 SETI@home.exe 16777216 26072 5724 16412672 16412672 126 3
00000388 winmine.exe 1069056 17080 2032 294912 294912 23 1
000003AC cmmon32.exe 720896 15904 2580 352256 352256 52 3
00000404 MDM.EXE 2183168 18908 3676 692224 692224 81 4
00000380 SSEXP.EXE 3584000 25104 3064 1298432 1298432 60 4
000004A0 OUTLOOK.EXE 11087872 76724 20362 4177920 4177920 305 11
00000358 MAPISP32.EXE 4001792 30036 9032 1421312 1421312 172 7
00000438 homesite45.exe 23937024 50808 10984 22159360 22159360 203 7
00000370 CMD.EXE 856064 13628 1616 253952 253952 23 1
000002A8 notepad.exe 2146304 19864 2552 720896 720896 42 2
0000030C memsnap.exe 737280 12556 1704 307200 307200 18 1
!LogType=memsnap
!ComputerName=TRINA
!buildnumber=2195
!buildtype=retail
!CSDVersion=Service Pack 1
!SystemTime=06\01\2001 20:36:13.0947 (GMT)
!TickCount=72164637
00000000 (null) 16384 0 0 0 0 0 1
00000008 System 217088 0 0 24576 24576 231 35
00000094 SMSS.EXE 356352 5944 1252 1122304 1122304 33 6
000000AC csrss.exe 2400256 38288 5572 1417216 1417216 331 10
000000A8 WINLOGON.EXE 3600384 38376 62220 5890048 5890048 359 16
000000DC services.exe 3375104 29640 216364 2564096 2564096 491 30
000000E8 LSASS.EXE 942080 28100 37176 1961984 1961984 301 13
0000018C svchost.exe 3284992 27592 16896 1318912 1318912 273 8
000001A8 SPOOLSV.EXE 3018752 20436 12904 2199552 2199552 104 10
000001C4 Avsynmgr.exe 2412544 19976 3428 1265664 1265664 98 4
000001D4 svchost.exe 2916352 39148 62548 3952640 3952640 398 26
000001F8 regsvc.exe 774144 8056 9548 241664 241664 30 2
00000208 mstask.exe 2912256 25596 15212 1032192 1032192 138 6
00000250 WinMgmt.exe 151552 15752 3208 651264 651264 90 3
0000028C VSStat.exe 1294336 20264 3324 1228800 1228800 67 2
00000158 vshwin32.exe 1253376 22192 5136 2736128 2736128 107 7
000002C0 MCSHIELD.EXE 3710976 13060 20872 2306048 2306048 113 16
00000318 Avconsol.exe 2777088 20944 3948 1413120 1413120 67 2
0000035C explorer.exe 2166784 52368 19568 5013504 5013504 352 18
000003E0 SETI@home.exe 16777216 26072 5724 16412672 16412672 126 3
00000388 winmine.exe 1069056 17080 2032 294912 294912 23 1
000003AC cmmon32.exe 720896 15904 2580 352256 352256 52 3
00000404 MDM.EXE 2203648 19324 3884 716800 716800 96 6
00000380 SSEXP.EXE 3584000 25104 3064 1294336 1294336 60 4
000004A0 OUTLOOK.EXE 11649024 77564 21250 4390912 4390912 331 14
00000358 MAPISP32.EXE 4026368 30036 9032 1421312 1421312 172 7
00000438 homesite45.exe 25358336 50860 11088 23629824 23629824 221 7
000004BC CMD.EXE 856064 13628 1616 253952 253952 23 1
000003C4 memsnap.exe 749568 12556 1704 307200 307200 18 1