Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Dump Windows File Format


  • Please log in to reply
1 reply to this topic

#1 vulcain

vulcain

  • Members
  • 165 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:France
  • Local time:08:06 PM

Posted 13 May 2014 - 08:23 AM

Hello, 
 
Currently I develop for me in python 3.4 a utility to read a dump file. Unfortunately, I do not know the format of the binary file, no problem following data type. 
If it is legal, is it possible to have the file format Dump Windows to finish my utility. 
thank you 
Sincerely,
 


BC AdBot (Login to Remove)

 


#2 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:12:06 PM

Posted 13 May 2014 - 11:56 AM

"dump" has many meanings. The most common would be a simple memory snapshot of a process, in which case the format is going to be dictated by whatever the program from which the dump was taken wants the format to be.

What is your overall scenario? (e.g. what are you trying to accomplish by reading or writing a dump?)

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users