Wut, why not just use PE Tools? Attach the process through PE Tools and dump whatever you're looking for within the process.
Does anybody know what dumpers I can use for a 64 BIT machine?
Wut, why not just use PE Tools? Attach the process through PE Tools and dump whatever you're looking for within the process.
Reversing is the only way to move forward.
Use loadlib posted here before, it will virutalize the module so you can attach PE Tools to the loadlib process and select it then hit dump full.
WizdomNKush (02-24-2013)
Search the section. There are many methods released.
/Solved
/Closed
I Read All Of My PM's & VM'sIf you need help with anything, just let me know.
Staff Administrator Since 10.13.2019
Publicist Since 04.04.2015
Middleman Since 04.14.2014
Global Moderator Since 08.01.2013
Premium Since 05.29.2013
Minion+ Since 04.18.2013
Combat Arms Minion Since 12.26.2012
Contributor Since 11.16.2012
Member Since 05.11.2010