Topic: The list of loaded DLL units
All kind time of days! OS Win 8.1 x64 Is 2 utilities: ProcessHacker and ListDlls64 from Russinovicha. ListDlls64 reads the list loaded in process DLL from PEB'a, and ProcessHacker receives the process list through NtQueryVirtualMemory (MemoryBasicInformation), i.e. through VAD. These lists differ. There is a sensation that some DLL on address space of process, instead of are loaded through LoadLibrary... For example, at process svchost.exe are present wevtapi.dll, winlogon.exe, tquery.dll, which miss in PEB. Such piece is tracked on all OS since Vista. On XP the such did not note. Somebody can prompt for what and how it is made? Thankful in advance!