A
A
AndreyKu2012-06-16 22:41:45
Windows
AndreyKu, 2012-06-16 22:41:45

How to remove and analyze process dumps?

Hello. Please tell me how you can dump processes (Windows) for further comparison of their differences. The better it is to compare dumps and how with what tool, after identifying different bytes, you can edit them “live”.
Thank you in advance for your help.

Answer the question

In order to leave comments, you need to log in

1 answer(s)
Y
Yuri Popov, 2012-06-17
@DjPhoeniX

IDA Pro perfectly saves dumps, shows the assembler code, the state of the registers (during debugging), and also shows the functions imported from the DLL.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question