HelpReadProcessMemory slowing my proog

Posts 1–4 of 4 · Page 1 of 1
ReadProcessMemory slowing my prog
Hi everyone,
I finally completed my memory scanner with some help, the scan work but it take a lot of time.
The part that is slowing the prog :
Code:
        for (currentAddress = lpAddress ; currentAddress < ((lpAddress + dwSize))-sizeof(value);currentAddress++)
        {
            if (ReadProcessMemory(phandle,(void*)currentAddress,&value,sizeof(value),0) != 0)
            {
                if (value == searchfor)
                {
                    printf(" 0x%08X", currentAddress);
                    tableau[found]=currentAddress;
                    if (found < (MAXADDR-1))
                        found++;
                }
            }
        }
if (ReadProcessMemory(phandle,(void*)currentAddress,& value,sizeof(value),0) != 0)


Assume ram is like 1,000,000 bytes long (actually much much bigger).

Is it faster to call ReadProcessMemory() 1,000,000 times and read 1 byte each time
or,
is it faster to call ReadProcessMemory() 1,000 times and read 1000 bytes each time.

1000 function calls vs 1 million.


This is why it's taking so long.
It might be faster to copy all of it, then do your processing after, one large copy.

Edit: Modern processors have instructions to increase the speed of large data copies, they also are other ways to do it without having to copy across the processes.
use a loop and virtualqueryex to figure out where each mem region is and how large.
read each mem region via one call to readprocessmemory


edit: looks like you already have the region's size ('dwsize' in your code) -- make sure you have a buffer large enough to hold the memory region's data (hint: keep track of 'maxBufferSize'. and use new/delete as needed) and call rpm. Then use another for loop() to iterate over the buffer and check for your 'value'.
Posts 1–4 of 4 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us