IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Check SystemInternals
They have a "listdlls.exe" program which lists the path of dlls and who is running them

[link|http://www.sysinternals.com/ntw2k/utilities.shtml|http://www.sysintern...k/utilities.shtml]

The outlook looks like this:

ListDLLs V2.23 - DLL lister for Win9x/NT
Copyright (C) 1997-2000 Mark Russinovich
[link|http://www.sysinternals.com|http://www.sysinternals.com]

-----------------------------------------------------------------------------
System pid: 8
Command line: <no command line>
-----------------------------------------------------------------------------
SMSS.EXE pid: 164
Command line: \\SystemRoot\\System32\\smss.exe

Base Size Version Path
0x48580000 0xe000 \\SystemRoot\\System32\\smss.exe
0x77f80000 0x7d000 5.00.2195.6899 C:\\WINNT\\system32\\ntdll.dll
0x68010000 0xf0000 5.00.2195.6894 C:\\WINNT\\System32\\sfcfiles.dll
-----------------------------------------------------------------------------
CSRSS.EXE pid: 188
Command line: C:\\WINNT\\system32\\csrss.exe ObjectDirectory=\\Windows SharedSect
=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll
nsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitializatio
ProfileControl=Off MaxRequestThreads=16

Base Size Version Path
0x5fff0000 0x4000 \\??\\C:\\WINNT\\system32\\csrss.exe

0x77f80000 0x7d000 5.00.2195.6899 C:\\WINNT\\system32\\ntdll.dll
0x5ff90000 0xc000 5.00.2195.6601 C:\\WINNT\\system32\\CSRSRV.dll
0x5ffa0000 0xd000 5.00.2195.6824 C:\\WINNT\\system32\\basesrv.dll
0x5ffb0000 0x3f000 5.00.2195.6826 C:\\WINNT\\system32\\winsrv.dll
0x77e10000 0x65000 5.00.2195.6897 C:\\WINNT\\system32\\USER32.dll
0x7c570000 0xb8000 5.00.2195.6897 C:\\WINNT\\system32\\KERNEL32.DLL
0x77f40000 0x3e000 5.00.2195.6898 C:\\WINNT\\system32\\GDI32.DLL
-----------------------------------------------------------------------------
WINLOGON.EXE pid: 184
Command line: winlogon.exe

Base Size Version Path
0x01000000 0x2e000 \\??\\C:\\WINNT\\system32\\winlogon.exe
0x77f80000 0x7d000 5.00.2195.6899 C:\\WINNT\\system32\\ntdll.dll
0x78000000 0x45000 6.01.9844.0000 C:\\WINNT\\system32\\MSVCRT.DLL
0x7c570000 0xb8000 5.00.2195.6897 C:\\WINNT\\system32\\KERNEL32.dll
0x7c2d0000 0x62000 5.00.2195.6876 C:\\WINNT\\system32\\ADVAPI32.DLL
0x77d30000 0x71000 5.00.2195.6904 C:\\WINNT\\system32\\RPCRT4.DLL
0x77f40000 0x3e000 5.00.2195.6898 C:\\WINNT\\system32\\GDI32.DLL
0x77e10000 0x65000 5.00.2195.6897 C:\\WINNT\\system32\\USER32.DLL
0x7c0f0000 0x61000 5.00.2195.6794 C:\\WINNT\\system32\\USERENV.DLL
0x769a0000 0x7000 5.00.2195.6661 C:\\WINNT\\system32\\NDDEAPI.DLL
0x76980000 0x1b000 5.00.2195.6673 C:\\WINNT\\system32\\SFC.DLL
0x68010000 0xf0000 5.00.2195.6894 C:\\WINNT\\system32\\sfcfiles.dll
-- More --
New Cool! Will try tonight.
jb4
shrub\ufffdbish (Am., from shrub + rubbish, after the derisive name for America's 43 president; 2003) n. 1. a form of nonsensical political doubletalk wherein the speaker attempts to defend the indefensible by lying, obfuscation, or otherwise misstating the facts; GIBBERISH. 2. any of a collection of utterances from America's putative 43rd president. cf. BULLSHIT

     OK, Continuing on... - (jb4) - (4)
         Did you run AV? -NT - (deSitter) - (1)
             Re: Did you run AV? - (jb4)
         Check SystemInternals - (hnick) - (1)
             Cool! Will try tonight. -NT - (jb4)

Holy cran.
32 ms