Windows Tools

MemSnap Examples

Overview | Syntax | Examples | Related Tools Open Command Prompt

Example 1: Generate Snapshot of Memory Resources

To generate a snapshot of memory resources being consumed, type the following at the command line:

memsnap c:\data\memsnap.txt

This command sends the memory data to the Memsnap.txt file in the c:\data directory. Your output will look similar to the following:

Process ID		 Proc.Name Wrkng.Set PagedPool  NonPgdPl  Pagefile	Commit   Handles   Threads
00000000			(null)	 16384		 0		 0		 0		 0		 0		 1
00000008			System	217088		 0		 0	 24576	 24576	 231		35
00000094			SMSS.EXE	356352	5944	1252   1122304   1122304		33		 6
000000AC		 csrss.exe   2297856	 38676	5520   1363968   1363968	 326		10
000000A8		WINLOGON.EXE   3530752	 38376	 62220   5906432   5906432	 359		16
000000DC		services.exe   3375104	 29640	216364   2564096   2564096	 491		30
000000E8		 LSASS.EXE   1232896	 28100	 37176   1961984   1961984	 301		13
0000018C		 svchost.exe   3284992	 27592	 16896   1318912   1318912	 273		 8
000001A8		 SPOOLSV.EXE   3018752	 20436	 12904   2199552   2199552	 104		10
000001C4		Avsynmgr.exe   2412544	 19976	3428   1265664   1265664		98		 4
000001D4		 svchost.exe   2916352	 39148	 62548   3952640   3952640	 398		26
000001F8		regsvc.exe	774144	8056	9548	241664	241664		30		 2
00000208		mstask.exe   2912256	 25596	 15212   1032192   1032192	 138		 6
00000250		 WinMgmt.exe	151552	 15752	3208	651264	651264		90		 3
0000028C		VSStat.exe   1294336	 20264	3324   1228800   1228800		67		 2
00000158		vshwin32.exe   1253376	 22192	5136   2736128   2736128	 107		 7
000002C0		MCSHIELD.EXE   3710976	 13060	 20872   2306048   2306048	 113		16
00000318		Avconsol.exe   2777088	 20944	3948   1413120   1413120		67		 2
0000035C		explorer.exe   2588672	 50452	 18996   4829184   4829184	 334		14
000003E0	 SETI@home.exe  16777216	 26072	5724  16412672  16412672	 126		 3
00000388		 winmine.exe   1069056	 17080	2032	294912	294912		23		 1
000003AC		 cmmon32.exe	720896	 15904	2580	352256	352256		52		 3
00000404			 MDM.EXE   2183168	 18908	3676	692224	692224		81		 4
00000380		 SSEXP.EXE   3584000	 25104	3064   1298432   1298432		60		 4
000004A0		 OUTLOOK.EXE  11087872	 76724	 20362   4177920   4177920	 305		11
00000358		MAPISP32.EXE   4001792	 30036	9032   1421312   1421312	 172		 7
00000438	homesite45.exe  23937024	 50808	 10984  22159360  22159360	 203		 7
00000370			 CMD.EXE	856064	 13628	1616	253952	253952		23		 1
000002A8		 notepad.exe   2146304	 19864	2552	720896	720896		42		 2
0000030C		 memsnap.exe	737280	 12556	1704	307200	307200		18		 1

Example 2: Generate Snapshot of Memory, GDI, and User Resources

To generate a snapshot of memory, GDI, and user resources being consumed, type the following at the command line:

memsnap /g

This command sends the memory data to the Memsnap.log file in the c:\ directory. Your output will look similar to the following:

Process ID		 Proc.Name Wrkng.Set PagedPool  NonPgdPl  Pagefile	Commit   Handles   Threads
00000000			(null)	 16384		 0		 0		 0		 0		 0		 1
00000008			System	217088		 0		 0	 24576	 24576	 231		35
00000094			SMSS.EXE	356352	5944	1252   1122304   1122304		33		 6
000000AC		 csrss.exe   2072576	 37332	5312   1359872   1359872	 327		10
000000A8		WINLOGON.EXE   3530752	 38376	 62220   5906432   5906432	 359		16
000000DC		services.exe   3375104	 29640	216364   2564096   2564096	 491		30
000000E8		 LSASS.EXE   1232896	 28100	 37176   1961984   1961984	 301		13
0000018C		 svchost.exe   3284992	 27592	 16896   1318912   1318912	 273		 8
000001A8		 SPOOLSV.EXE   3026944	 20436	 12904   2199552   2199552	 105		10
000001C4		Avsynmgr.exe   2412544	 19976	3428   1265664   1265664		98		 4
000001D4		 svchost.exe   2916352	 39148	 62548   3952640   3952640	 398		26
000001F8		regsvc.exe	774144	8056	9548	241664	241664		30		 2
00000208		mstask.exe   2912256	 25596	 15212   1032192   1032192	 138		 6
00000250		 WinMgmt.exe	151552	 15752	3208	651264	651264		90		 3
0000028C		VSStat.exe   1294336	 20264	3324   1228800   1228800		67		 2
00000158		vshwin32.exe   1249280	 22192	5136   2736128   2736128	 107		 7
000002C0		MCSHIELD.EXE   3694592	 13060	 20872   2301952   2301952	 113		16
00000318		Avconsol.exe   2777088	 20944	3948   1413120   1413120		67		 2
0000035C		explorer.exe   2416640	 49456	 18424   4546560   4546560	 308		17
000003E0	 SETI@home.exe  16773120	 26072	5724  16412672  16412672	 126		 3
00000388		 winmine.exe   1069056	 17080	2032	294912	294912		23		 1
000003AC		 cmmon32.exe	720896	 15904	2580	352256	352256		52		 3
00000404			 MDM.EXE   2191360	 18940	3780	704512	704512		91		 5
00000380		 SSEXP.EXE   3584000	 25104	3064   1298432   1298432		60		 4
000004A0		 OUTLOOK.EXE  11083776	 76404	 20466   4190208   4190208	 314		12
00000358		MAPISP32.EXE   4001792	 30036	9032   1421312   1421312	 172		 7
00000438	homesite45.exe  23564288	 50808	 10932  21811200  21811200	 204		 7
00000370			 CMD.EXE	856064	 13628	1616	253952	253952		23		 1
000004A4		 memsnap.exe	737280	 12556	1704	307200	307200		18		 1

00000000			(null)	 16384		 0		 0		 0		 0		 0		 1		 0		 0
00000008			System	217088		 0		 0	 24576	 24576	 231		35		 0		 0
00000094			SMSS.EXE	356352	5944	1252   1122304   1122304		33		 6		 0		 0
000000AC		 csrss.exe   2306048	 38604	5520   1372160   1372160	 325		10		 0		 0
000000A8		WINLOGON.EXE   3530752	 38376	 62220   5906432   5906432	 359		16		 8		20
000000DC		services.exe   3375104	 29640	216364   2564096   2564096	 491		30		 1		 6
000000E8		 LSASS.EXE   1232896	 28100	 37176   1961984   1961984	 301		13		 0		 4
0000018C		 svchost.exe   3284992	 27592	 16896   1318912   1318912	 273		 8		 0		 4
000001A8		 SPOOLSV.EXE   3018752	 20436	 12904   2199552   2199552	 104		10		 0		 4
000001C4		Avsynmgr.exe   2412544	 19976	3428   1265664   1265664		98		 4		 0		 4
000001D4		 svchost.exe   2916352	 39148	 62548   3952640   3952640	 398		26		 6		 8
000001F8		regsvc.exe	774144	8056	9548	241664	241664		30		 2		 0		 0
00000208		mstask.exe   2912256	 25596	 15212   1032192   1032192	 138		 6		 1		 4
00000250		 WinMgmt.exe	151552	 15752	3208	651264	651264		90		 3		 0		 4
0000028C		VSStat.exe   1294336	 20264	3324   1228800   1228800		67		 2		29		20
00000158		vshwin32.exe   1253376	 22192	5136   2736128   2736128	 107		 7		 2		 6
000002C0		MCSHIELD.EXE   3710976	 13060	 20872   2306048   2306048	 113		16		 1		 4
00000318		Avconsol.exe   2777088	 20944	3948   1413120   1413120		67		 2		18		63
0000035C		explorer.exe   3923968	 51568	 19152   4935680   4935680	 345		14	 215	 216
000003E0	 SETI@home.exe  17829888	 26072	5776  17465344  17465344	 126		 3		 9		24
00000388		 winmine.exe   1069056	 17080	2032	294912	294912		23		 1		 7		41
000003AC		 cmmon32.exe	720896	 15904	2580	352256	352256		52		 3		14		12
00000404			 MDM.EXE   2174976	 18524	3572	675840	675840		78		 3		 1		 4
00000380		 SSEXP.EXE   3584000	 25104	3064   1294336   1294336		60		 4		68		68
000004A0		 OUTLOOK.EXE  11128832	 76372	 20362   4202496   4202496	 304		11	 140	 215
00000358		MAPISP32.EXE   4014080	 30036	9032   1421312   1421312	 172		 7		 6		29
00000438	homesite45.exe  24576000	 50872	 11080  22794240  22794240	 203		 7	 294	 543
00000370			 CMD.EXE	860160	 13628	1616	258048	258048		23		 1		 0		 4
000002A8		 notepad.exe   2146304	 19864	2552	720896	720896		42		 2		10		25
0000030C		 memsnap.exe	737280	 12556	1704	307200	307200		18		 1		 0		 4

00000000			(null)	 16384		 0		 0		 0		 0		 0		 1		 0		 0
00000008			System	217088		 0		 0	 24576	 24576	 231		35		 0		 0
00000094			SMSS.EXE	356352	5944	1252   1122304   1122304		33		 6		 0		 0
000000AC		 csrss.exe   2269184	 38048	5468   1372160   1372160	 323		10		 0		 0
000000A8		WINLOGON.EXE   3530752	 38376	 62220   5906432   5906432	 359		16		 8		20
000000DC		services.exe   3375104	 29640	216364   2564096   2564096	 491		30		 1		 6
000000E8		 LSASS.EXE   1257472	 28132	 37280   1994752   1994752	 301		14		 0		 4
0000018C		 svchost.exe   3284992	 27592	 16896   1318912   1318912	 273		 8		 0		 4
000001A8		 SPOOLSV.EXE   3018752	 20436	 12904   2199552   2199552	 104		10		 0		 4
000001C4		Avsynmgr.exe   2412544	 19976	3428   1265664   1265664		98		 4		 0		 4
000001D4		 svchost.exe   2916352	 39148	 62548   3952640   3952640	 398		26		 6		 8
000001F8		regsvc.exe	774144	8056	9548	241664	241664		30		 2		 0		 0
00000208		mstask.exe   2912256	 25596	 15212   1032192   1032192	 138		 6		 1		 4
00000250		 WinMgmt.exe	151552	 15752	3208	651264	651264		90		 3		 0		 4
0000028C		VSStat.exe   1294336	 20264	3324   1228800   1228800		67		 2		29		20
00000158		vshwin32.exe   1253376	 22192	5136   2736128   2736128	 107		 7		 2		 6
000002C0		MCSHIELD.EXE   3710976	 13060	 20872   2306048   2306048	 113		16		 1		 4
00000318		Avconsol.exe   2777088	 20944	3948   1413120   1413120		67		 2		18		63
0000035C		explorer.exe   4997120	 51216	 19256   4960256   4960256	 349		15	 215	 217
000003E0	 SETI@home.exe  17829888	 26072	5776  17465344  17465344	 126		 3		 9		24
00000388		 winmine.exe   1069056	 17080	2032	294912	294912		23		 1		 7		41
000003AC		 cmmon32.exe	720896	 15904	2580	352256	352256		52		 3		14		12
00000404			 MDM.EXE   2174976	 18524	3572	675840	675840		78		 3		 1		 4
00000380		 SSEXP.EXE   3584000	 25104	3064   1294336   1294336		60		 4		68		68
000004A0		 OUTLOOK.EXE  11485184	 76596	 20886   4202496   4202496	 311		11	 140	 215
00000358		MAPISP32.EXE   4026368	 30036	9032   1421312   1421312	 172		 7		 6		29
00000438	homesite45.exe  24723456	 50808	 10984  22941696  22941696	 203		 7	 294	 543
00000370			 CMD.EXE	860160	 13628	1616	258048	258048		23		 1		 0		 4
000004BC		 memsnap.exe	733184	 12556	1704	307200	307200		18		 1		 0		 4

Example 3: Generate Snapshot of Memory Resources and Tagging Information

To generate a snapshot of memory resources being consumed with tagging information, type the following at the command line:

memsnap /t c:\data\memsnap.txt

This command sends the memory data to the Memsnap.txt file in the c:\data directory. Your output will look similar to the following:

Process ID		 Proc.Name Wrkng.Set PagedPool  NonPgdPl  Pagefile	Commit   Handles   Threads
00000000			(null)	 16384		 0		 0		 0		 0		 0		 1
00000008			System	217088		 0		 0	 24576	 24576	 231		35
00000094			SMSS.EXE	356352	5944	1252   1122304   1122304		33		 6
000000AC		 csrss.exe   2297856	 38676	5520   1363968   1363968	 326		10
000000A8		WINLOGON.EXE   3530752	 38376	 62220   5906432   5906432	 359		16
000000DC		services.exe   3375104	 29640	216364   2564096   2564096	 491		30
000000E8		 LSASS.EXE   1232896	 28100	 37176   1961984   1961984	 301		13
0000018C		 svchost.exe   3284992	 27592	 16896   1318912   1318912	 273		 8
000001A8		 SPOOLSV.EXE   3018752	 20436	 12904   2199552   2199552	 104		10
000001C4		Avsynmgr.exe   2412544	 19976	3428   1265664   1265664		98		 4
000001D4		 svchost.exe   2916352	 39148	 62548   3952640   3952640	 398		26
000001F8		regsvc.exe	774144	8056	9548	241664	241664		30		 2
00000208		mstask.exe   2912256	 25596	 15212   1032192   1032192	 138		 6
00000250		 WinMgmt.exe	151552	 15752	3208	651264	651264		90		 3
0000028C		VSStat.exe   1294336	 20264	3324   1228800   1228800		67		 2
00000158		vshwin32.exe   1253376	 22192	5136   2736128   2736128	 107		 7
000002C0		MCSHIELD.EXE   3710976	 13060	 20872   2306048   2306048	 113		16
00000318		Avconsol.exe   2777088	 20944	3948   1413120   1413120		67		 2
0000035C		explorer.exe   2588672	 50452	 18996   4829184   4829184	 334		14
000003E0	 SETI@home.exe  16777216	 26072	5724  16412672  16412672	 126		 3
00000388		 winmine.exe   1069056	 17080	2032	294912	294912		23		 1
000003AC		 cmmon32.exe	720896	 15904	2580	352256	352256		52		 3
00000404			 MDM.EXE   2183168	 18908	3676	692224	692224		81		 4
00000380		 SSEXP.EXE   3584000	 25104	3064   1298432   1298432		60		 4
000004A0		 OUTLOOK.EXE  11087872	 76724	 20362   4177920   4177920	 305		11
00000358		MAPISP32.EXE   4001792	 30036	9032   1421312   1421312	 172		 7
00000438	homesite45.exe  23937024	 50808	 10984  22159360  22159360	 203		 7
00000370			 CMD.EXE	856064	 13628	1616	253952	253952		23		 1
000002A8		 notepad.exe   2146304	 19864	2552	720896	720896		42		 2
0000030C		 memsnap.exe	737280	 12556	1704	307200	307200		18		 1

!LogType=memsnap
!ComputerName=TRINA
!buildnumber=2195
!buildtype=retail
!CSDVersion=Service Pack 1
!SystemTime=06\01\2001 20:36:13.0947 (GMT)
!TickCount=72164637
00000000			(null)	 16384		 0		 0		 0		 0		 0		 1
00000008			System	217088		 0		 0	 24576	 24576	 231		35
00000094			SMSS.EXE	356352	5944	1252   1122304   1122304		33		 6
000000AC		 csrss.exe   2400256	 38288	5572   1417216   1417216	 331		10
000000A8		WINLOGON.EXE   3600384	 38376	 62220   5890048   5890048	 359		16
000000DC		services.exe   3375104	 29640	216364   2564096   2564096	 491		30
000000E8		 LSASS.EXE	942080	 28100	 37176   1961984   1961984	 301		13
0000018C		 svchost.exe   3284992	 27592	 16896   1318912   1318912	 273		 8
000001A8		 SPOOLSV.EXE   3018752	 20436	 12904   2199552   2199552	 104		10
000001C4		Avsynmgr.exe   2412544	 19976	3428   1265664   1265664		98		 4
000001D4		 svchost.exe   2916352	 39148	 62548   3952640   3952640	 398		26
000001F8		regsvc.exe	774144	8056	9548	241664	241664		30		 2
00000208		mstask.exe   2912256	 25596	 15212   1032192   1032192	 138		 6
00000250		 WinMgmt.exe	151552	 15752	3208	651264	651264		90		 3
0000028C		VSStat.exe   1294336	 20264	3324   1228800   1228800		67		 2
00000158		vshwin32.exe   1253376	 22192	5136   2736128   2736128	 107		 7
000002C0		MCSHIELD.EXE   3710976	 13060	 20872   2306048   2306048	 113		16
00000318		Avconsol.exe   2777088	 20944	3948   1413120   1413120		67		 2
0000035C		explorer.exe   2166784	 52368	 19568   5013504   5013504	 352		18
000003E0	 SETI@home.exe  16777216	 26072	5724  16412672  16412672	 126		 3
00000388		 winmine.exe   1069056	 17080	2032	294912	294912		23		 1
000003AC		 cmmon32.exe	720896	 15904	2580	352256	352256		52		 3
00000404			 MDM.EXE   2203648	 19324	3884	716800	716800		96		 6
00000380		 SSEXP.EXE   3584000	 25104	3064   1294336   1294336		60		 4
000004A0		 OUTLOOK.EXE  11649024	 77564	 21250   4390912   4390912	 331		14
00000358		MAPISP32.EXE   4026368	 30036	9032   1421312   1421312	 172		 7
00000438	homesite45.exe  25358336	 50860	 11088  23629824  23629824	 221		 7
000004BC			 CMD.EXE	856064	 13628	1616	253952	253952		23		 1
000003C4		 memsnap.exe	749568	 12556	1704	307200	307200		18		 1