An option to dump closed modules that were loaded AFTER -closemon was initiated would be great for detecting and dumping modules... it seems this program only hooks and dumps modules that were loaded at the time closemon was initiated.
what do you think, should this be most effective for detecting malware if it only dumped unhashed modules?
Great little program! This thing is very useful.