Welcome![Sign In][Sign Up]
Location:
Downloads SourceCode Embeded-SCM Develop Windows CE
Title: dmp Download
 Description: KeCapturePersistentThreadState capture the current thread, get _DUMP_HEADER structure content, which is interesting is the content of the DumpHead-> PsLoadedModuleList, DumpHead-> PsActiveProcessHead, DumpHead-> PfnDataBase... The next step is to _DUMP_HEADER structure content wrote a DMP files, ZwCreateFile- > ZwWriteFile...
 Downloaders recently: [More information of uploader 王明]
 To Search:
File list (Check if you may need any files):
模仿dmp文件转存.txt
    

CodeBus www.codebus.net