DMMSPY sample screen shot
(Taken immediately after DmmSpy has started, with no other programs running, except built-in Windows components, and those pieces that run from Startup)..

To understand the output, take a look at the last line in the upper listview control. It tells you that the module called VSHWIN32.EXE residing in the file G:\PROGRAM FILES\MCAFEE\VIRUSSCAN\WSHWIN32.EXE executed an instruction cmp word ptr [eax+00000828[, 0 at address 14F:403251. The lower right listview shows that at the time of this instruction, eax register contained the value C6456D10. Finally, the lower left listview shows, that this instruction with the same run-time values was executed 53 times, that it has accessed the memory address C6457538, and that the address belongs to a VxD called VSHIELD. Because this machine happens to run Mcafee Anti-Virus software, it all makes sense.

 

Last updated: October 08, 1997.
Copyright @ 1997 Alex Shmidt. All rights reserved.