glmcdona / Process-Dump

Windows tool for dumping malware PE files from memory back to disk for analysis.
http://split-code.com/processdump.html
MIT License
1.63k stars 261 forks source link

Latest build of Process Dump close monitor is crashing csrss.exe #10

Open glmcdona opened 7 years ago

glmcdona commented 7 years ago

Latest version of Process Dump close monitor (pd64.exe -closemon) is crashing csrss.exe on both x86 and x64.

glmcdona commented 7 years ago

Committed a temporary fix to avoid csrss.exe crashes. Haven't been able to identify the root problem. A similar problem still repros on an XP machine I have where commandline processor and other apps are crashing. 64bit windows 7 works fine. This is still an important issue.