How can I extract DLL file from memory dump?

前端 未结 3 529
深忆病人
深忆病人 2020-12-19 03:12

I have a memory dump (unmanaged process) . How can I extract (using windbg) one of the dlls loaded into the process ? I mean actually saving the dll file into the disk

3条回答
  •  情话喂你
    2020-12-19 03:57

    You can use the sos.dll inside windbg directory.

    First, load the sos.dll in windbg:

    .load clr10\sos.dll
    

    Then use !sam OR !SaveAllModule to extract the modules on specific disk location:

    !sam c:\notepad
    

提交回复
热议问题