To troubleshoot daily crashes, first make sure Windows is saving usable dump files, then inspect them with WinDbg.
- Configure memory dump collection:
- Open Advanced system settings.
- On the Advanced tab, under Startup and Recovery, select Settings.
- Under Write debugging information, select Automatic memory dump.
- Select OK, then restart the PC.
- Dump files are typically saved in:
- %SystemRoot%\MEMORY.DMP for automatic, kernel, complete, and active dumps
- %SystemRoot%\Minidump for small memory dumps
- Verify the dump files exist after the next crash:
- Small memory dumps are stored in %SystemRoot%\Minidump.
- A small memory dump contains the stop message, parameters, loaded drivers, processor context, process and thread information, and the kernel-mode call stack.
- Analyze the dump with WinDbg:
- Copy the dump file to another PC if needed.
- Download the Windows 10 SDK.
- During setup, choose Debugging Tools for Windows.
- Open WinDbg.
- Go to File > Symbol File Path.
- If internet access is available, set the symbol path to:
https://msdl.microsoft.com/download/symbols - Select Open Crash Dump and open the
.dmpfile.
- If the crashes continue and only small dumps are being created, keep them all:
- Windows stores multiple small dump files with distinct date-based names in %SystemRoot%\Minidump.
- This helps compare repeated crashes over time.
- If a dump file appears unreadable or analysis fails:
- Use DumpChk to verify the dump file is valid and not corrupted.
- For general isolation steps while collecting dumps:
- Consider a clean boot to rule out background software.
- Consider rolling back a device driver if crashes started after a driver change.
- A problematic driver can also be temporarily disabled in some cases.
The most useful next step is to open one of the minidumps in WinDbg and identify whether the crash points to a driver, memory corruption, or another component.