hi
i will write dumper to dump process memory , only process memory and it Dlls ( not windows well known Dll ) to file.
can write dumper in kernel mode? it's better to write in user mode or kernel mode ?
user mode dumper can dump all process ( access is denied problem:) ) ?
what is best method for Differentiation process private dll and windows well known Dll ? with name or signature or path ,.....
some article and explanation please
very thanks
i will write dumper to dump process memory , only process memory and it Dlls ( not windows well known Dll ) to file.
can write dumper in kernel mode? it's better to write in user mode or kernel mode ?
user mode dumper can dump all process ( access is denied problem:) ) ?
what is best method for Differentiation process private dll and windows well known Dll ? with name or signature or path ,.....
some article and explanation please
very thanks
@R00tkitSMM