i try to no i browse my physical memory for exe files and i wanna know how i can find out
wich name this exe has ?? is ther a posibility to find out?
Example output of my programm:
Physical ADDRESS: 0x0003CFFF
4D5A
OffsetPE: D0
PE? is PE
Maschine ID: 4C01
DATETIME: B1130000
## its just gets the PE header in the right way
Physical ADDRESS: 0x003FCFE1
4D5A
OffsetPE: 80
PE? is NE
Maschine ID: 9800
DATETIME: 07800000