User Mode Process Dumper (userdump) 可以为任何Win32程序制作内存镜像,包括系统核心进程csrss.exe, winlogon.exe, services.exe等等均可以制作,不需要附加任何工具和跟踪程序,Dump下来的文件可以用各种Debug工具来处理.
Dump by specifying PID or process name from command line
Dump automatically when process being monitored caused exceptions
Dump automatically when process being monitored exited
Dump by pressing hot key sequence