LordPE Deluxe is one of the greatest tools for making process dump on memory for along time. It was developed by yoda. Here it is what this tools can do:
+ Dump process from memory and save as file.
+ Dump process module
+ Get Basic information about PE header.
+ Rebuild any PE file (realign, wipe relocation, rebuild import table, etc)
Author website can be reach at http://y0da.cjb.net but it no longer exist I guess. You can try get it from here.
minh muon dow lik nay
ReplyDeleteThanks for visiting here. You can download it from here:
ReplyDeletehttp://www.woodmann.com/collaborative/tools/index.php/LordPE
It has a Virus :(
ReplyDeleteThanks for visiting here.
ReplyDeleteBTW, LordPE file does not contain any viruses. It's probably your antivirus software give a false positive alert. This is happened because LordPE file has been compressed with well known EXE file compressor called y0da crypter. Which is commonly use by virus creator/author to compress their program. It is recommended to you to disable your antivirus first before running it.