-
Notifications
You must be signed in to change notification settings - Fork 279
Open
Description
while using pd with pid NNN
I've observed some strange behaviour in produced dlls..
here is an example:
original kernel32.dll module:
and this is what being produced by pd64 -pid 3464 (one of the chrome.exe child process)
the appended (fake?) entries list is huge (as you see it has 1361 imported dlls!)
majority of added records are duplicates (eg kernel32.dll LZDone
eg here is the end:
so the question is:
is it possible to determine the real effective and of table and not append some fake records?
seen it almost on all dumped dlls....
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels