What a .dmp file is and why you have one

A .dmp file is a memory dump — a snapshot of your computer's RAM (memory) at a specific moment, usually captured when something went wrong. Windows creates these files automatically when your system crashes, a program stops responding, or you manually trigger a memory capture. The file contains raw data about what your computer was doing at that instant.

You'll find .dmp files most often in your Windows folder after a crash, or in a folder you specified if you used a debugging tool. They're not documents you open like a Word file or image. Instead, you read them using specialized tools that translate the raw memory data into something human-readable — usually error codes, program names, and technical details about what caused the problem.

Key Takeaways

  • Windows stores crash dump files in C:\Windows\Minidump by default, and you can view them without special software using the Event Viewer built into Windows.
  • The Windows Debugger (WinDbg) is the official tool for detailed analysis, but it requires downloading from Microsoft and learning its command structure.
  • Third-party tools like BlueScreenView show crash information in a simpler table format without needing to learn debugging commands.
  • Most .dmp files contain technical error codes that point to a specific driver or program; searching the error code online often reveals the cause faster than reading the file itself.

Finding your .dmp files on Windows

Windows stores most crash dumps in a single folder: C:\Windows\Minidump. To navigate there, open File Explorer, paste that path into the address bar at the top, and press Enter. You'll see a list of files named something like "Mini010124-01.dmp" with a date stamp.

If you don't see any files there, your system may not have created a dump yet, or dumps may be disabled. You can also check Event Viewer, which logs every crash Windows records. Press Windows key + R, type eventvwr.msc, and press Enter. Navigate to Windows Logs > System, then look for entries marked "Critical" or "Error" with the source "Kernel-Power" or the name of a specific program. These entries often include the dump file name or a summary of what failed.

Reading .dmp files with Event Viewer (simplest method)

Event Viewer is already on your computer and requires no download. Open it as described above, find a crash entry in the System log, and click it. The Details tab shows basic information: the error code, the time of the crash, and sometimes the name of the driver or program involved. This is often enough to identify the problem without opening the .dmp file itself.

The limitation is that Event Viewer shows only a summary. If you need the full memory dump data — which is rare for most users — you'll need one of the tools below. But for a quick answer to "what crashed my computer," Event Viewer is usually sufficient and requires no setup.

Using BlueScreenView for a readable summary

BlueScreenView is a free tool from Nirsoft that reads .dmp files and displays the results in a simple table. Download it from nirsoft.net (search for "BlueScreenView"), extract the .zip file, and run the .exe. The program automatically finds your Minidump folder and lists every crash with the error code, driver name, and date.

Click any crash in the list to see more detail: the exact memory address where the error occurred, the module (program or driver) that caused it, and a stack trace showing what the computer was trying to do. For most users, the driver name alone is enough — if it says "nvlddmkm.sys," that's your NVIDIA graphics driver; if it says "iastor.sys," that's your storage controller. You can then search online for that driver name plus "crash" to find solutions.

BlueScreenView works on Windows 7 through Windows 11 and doesn't require installation, so you can run it from a USB drive if needed.

Using Windows Debugger (WinDbg) for detailed analysis

WinDbg is Microsoft's official debugging tool and the most powerful option, but also the most complex. Download it free from the Microsoft Store or from microsoft.com (search "Windows Debugger"). Launch it, go to File > Open Dump File, and select your .dmp file.

WinDbg will load the dump and display raw memory data. To get useful information, you'll need to run commands. Type !analyze -v and press Enter — this command tells WinDbg to analyze the dump and print a summary. The output includes the bugcheck code (the error number), the faulting module (the program or driver that crashed), and a stack trace showing the sequence of code that led to the crash.

WinDbg is the tool that professional support teams and developers use, so if you contact Microsoft Support or a hardware manufacturer about a crash, they may ask you to run specific WinDbg commands. For everyday troubleshooting, though, BlueScreenView or Event Viewer will give you the answer faster.

What to do once you've read the .dmp file

The .dmp file itself doesn't fix anything — it's just a record. Once you've identified the culprit (usually a driver name or program), your next step depends on what you find. If it's a driver, visit the manufacturer's website (NVIDIA, AMD, Intel, Realtek, etc.) and download the latest version. If it's a program, update or reinstall that program. If it's a Windows system file, run Windows Update to get the latest patches.

You can delete .dmp files safely once you've reviewed them — they take up disk space and Windows will create new ones if another crash occurs. To prevent future dumps from filling your drive, you can also disable dump file creation in Windows settings, though most users leave it on in case you need to troubleshoot a future problem.

Frequently Asked Questions

Can I open a .dmp file with Notepad?

Technically yes, but you'll see only gibberish — raw binary data that's not meant for human eyes. Use Event Viewer, BlueScreenView, or WinDbg instead to translate that data into readable error codes and program names.

What does "Kernel-Power" mean in Event Viewer?

It means the Windows kernel (the core of the operating system) detected a critical error and shut down to prevent damage. The dump file associated with that event contains details about what caused the kernel to fail — usually a bad driver or faulty hardware.

Do I need to keep .dmp files?

No. Once you've reviewed a dump file and identified the problem, you can delete it. Windows will create a new one if another crash occurs. Keeping old dumps wastes disk space and makes it harder to find recent crashes.

Why is my .dmp file so large?

The size depends on how much RAM your computer has. A full dump file can be several gigabytes on a system with 16 GB of RAM. Windows usually creates "minidumps" instead, which are much smaller and contain only the essential information needed to identify the crash.

Can I send a .dmp file to someone for help?

Yes, but it's usually not necessary. The error code and driver name (which you can get from BlueScreenView or Event Viewer in seconds) are usually enough for someone to help you. If you do send a dump file, be aware it contains a snapshot of your memory, which could theoretically include passwords or sensitive data, so only send it to someone you trust.