This function copies memory allocated to another process into an application-supplied buffer.
BOOL WINAPI Toolhelp32ReadProcessMemory( DWORD th32ProcessID, LPCVOID lpBaseAddress, LPVOID lpBuffer, DWORD cbRead, LPDWORD lpNumberOfBytesRead );
[in] Identifier of the process whose memory is being copied. This parameter can be zero to copy the memory of the current process.
[in] Base address in the specified process to read. Before transferring data, the system verifies that all data in the base address and memory of the specified size is accessible for read access. If this is the case, the function proceeds. Otherwise, the function fails.
[out] Pointer to a buffer that receives the contents of the address space of the specified process.
[in] Number of bytes to read from the specified process.
[in] Pointer to the number of bytes copied to the specified buffer. If this parameter is NULL, it is ignored.
Toolhelp32ReadProcessMemory is a privileged API. Only privileged applications should use this function. For more information, see Privileged APIs.