Vba32 AntiRootKit Log File

TEST 00:41:30 11-04-2010
Microsoft Windows XP Professional Service Pack 3 (build 2600)
AntiRootKit version 3.12.5.0
AntiVirus checking is OFF
Sign checking is ON
AntiRootKit driver is working in ordinary mode

Kernel-Mode Hooks

ModuleTypeNumberNameStateBase ValueCurrent ValueDriver
No hooks found

Kernel-Mode Notificators

TypeStateCurrent AddressDriver
No notificators installed

Driver Input/Output Handler's Hooks (IRP & FastIo)

Driver ObjectHandler NameStateCurrent AddressDriver
!Unnamed DriverObject!IRP_MJ_PNPHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_SET_QUOTAHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_QUERY_QUOTAHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_DEVICE_CHANGEHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_SYSTEM_CONTROLHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_POWERHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_SET_SECURITYHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_QUERY_SECURITYHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_CREATE_MAILSLOTHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_CLEANUPHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_LOCK_CONTROLHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_SHUTDOWNHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_INTERNAL_DEVICE_CONTROLHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_DEVICE_CONTROLHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_FILE_SYSTEM_CONTROLHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_DIRECTORY_CONTROLHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_SET_VOLUME_INFORMATIONHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_QUERY_VOLUME_INFORMATIONHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_FLUSH_BUFFERSHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_SET_EAHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_QUERY_EAHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_SET_INFORMATIONHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_QUERY_INFORMATIONHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_WRITEHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_READHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_CLOSEHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_CREATE_NAMED_PIPEHidden IRP handler 0x81BE7AC8[Unknown Handler]
!Unnamed DriverObject!IRP_MJ_CREATEHidden IRP handler 0x81BE7AC8[Unknown Handler]

Kernel modules

ModuleFull PathStateBase AddressModule SizeInformation
!Unnamed DriverObject!!Unnamed DriverObject!File doesn't exist Hidden in memory 0x81BE9B36000000
ntdll.dll
C:\WINDOWS\system32\ntdll.dll
Signed 0x7C900000733184
im9ssmie
C:\WINDOWS\system32\drivers\im9ssmie.sys
Signed 0xB27EB000065536
kmixer.sys
C:\WINDOWS\system32\drivers\kmixer.sys
Signed 0xB1E82000176128
pxtdipowC:\DOCUME~1\1\LOCALS~1\Temp\pxtdipow.sysFile doesn't exist 0xB1ED5000094208
HTTP
C:\WINDOWS\System32\Drivers\HTTP.sys
Signed 0xB20F7000266240
Srv
C:\WINDOWS\system32\DRIVERS\srv.sys
Signed 0xB24A8000356352
VMMEMCTL
C:\Program Files\VMware\VMware Tools\Drivers\memctl\vmmemctl.sys
Signed 0xF8BB8000008192
vmdesched-driver
C:\WINDOWS\system32\Drivers\vmdesched.sys
Signed 0xF8A2A000024576
ParVdm
C:\WINDOWS\System32\Drivers\ParVdm.SYS
Signed 0xF8BAA000008192
MRxDAV
C:\WINDOWS\system32\DRIVERS\mrxdav.sys
Signed 0xB254F000184320
sysaudio
C:\WINDOWS\system32\drivers\sysaudio.sys
Signed 0xF876A000061440
wdmaud
C:\WINDOWS\system32\drivers\wdmaud.sys
Signed 0xB2762000086016
Fastfat
C:\WINDOWS\System32\Drivers\Fastfat.SYS
Signed 0xB2777000147456
Ndisuio
C:\WINDOWS\system32\DRIVERS\ndisuio.sys
Signed 0xB2AA7000016384
vmx_fb.dll
C:\WINDOWS\System32\vmx_fb.dll
Signed 0xBF9D6000212992
dxgthk.sys
C:\WINDOWS\System32\drivers\dxgthk.sys
Signed 0xF8CBE000004096
dxg.sys
C:\WINDOWS\System32\drivers\dxg.sys
Signed 0xBF9C4000073728
watchdog.sys
C:\WINDOWS\System32\watchdog.sys
Signed 0xF89F2000020480
Dxapi.sys
C:\WINDOWS\System32\drivers\Dxapi.sys
Signed 0xF829E000012288
Win32k
C:\WINDOWS\System32\win32k.sys
Signed 0xBF8000001851392
mouhid
C:\WINDOWS\system32\DRIVERS\mouhid.sys
Signed 0xF82B6000012288
HIDPARSE.SYS
C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
Signed 0xF89EA000028672
HIDCLASS.SYS
C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS
Signed 0xF890A000036864
hidusb
C:\WINDOWS\system32\DRIVERS\hidusb.sys
Signed 0xF82BA000012288
usbccgp
C:\WINDOWS\system32\DRIVERS\usbccgp.sys
Signed 0xF89E2000032768
Cdfs
C:\WINDOWS\System32\Drivers\Cdfs.SYS
Signed 0xF88FA000065536
Wanarp
C:\WINDOWS\system32\DRIVERS\wanarp.sys
Signed 0xF88CA000036864
IpNat
C:\WINDOWS\system32\DRIVERS\ipnat.sys
Signed 0xB2C23000155648
Fips
C:\WINDOWS\System32\Drivers\Fips.SYS
Signed 0xF88BA000045056
MRxSmb
C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Signed 0xB2C49000458752
Rdbss
C:\WINDOWS\system32\DRIVERS\rdbss.sys
Signed 0xB2CE1000176128
vmdebug
C:\WINDOWS\system32\Drivers\vmdebug.sys
Signed 0xF889A000036864
vmhgfs
C:\WINDOWS\System32\DRIVERS\vmhgfs.sys
Signed 0xB2D0C000122880
NetBIOS
C:\WINDOWS\system32\DRIVERS\netbios.sys
Signed 0xF888A000036864
AFD
C:\WINDOWS\System32\drivers\afd.sys
Signed 0xB2D2A000139264
WS2IFSL
C:\WINDOWS\System32\drivers\ws2ifsl.sys
Signed 0xF839D000012288
NetBT
C:\WINDOWS\system32\DRIVERS\netbt.sys
Signed 0xB2D4C000163840
Tcpip
C:\WINDOWS\system32\DRIVERS\tcpip.sys
Signed 0xB2D74000364544
IPSec
C:\WINDOWS\system32\DRIVERS\ipsec.sys
Signed 0xB2DCD000077824
RasAcd
C:\WINDOWS\system32\DRIVERS\rasacd.sys
Signed 0xF83A1000012288
Npfs
C:\WINDOWS\System32\Drivers\Npfs.SYS
Signed 0xF89DA000032768
Msfs
C:\WINDOWS\System32\Drivers\Msfs.SYS
Signed 0xF89D2000020480
RDPCDD
C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Signed 0xF8BB6000008192
mnmdd
C:\WINDOWS\System32\Drivers\mnmdd.SYS
Signed 0xF8BB4000008192
VgaSave
C:\WINDOWS\System32\drivers\vga.sys
Signed 0xF89CA000024576
Beep
C:\WINDOWS\System32\Drivers\Beep.SYS
Signed 0xF8BB2000008192
Null
C:\WINDOWS\System32\Drivers\Null.SYS
Signed 0xF8DE0000004096
Fs_Rec
C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Signed 0xF8BB0000008192
gameenum
C:\WINDOWS\system32\DRIVERS\gameenum.sys
Signed 0xF8B8A000012288
USBD.SYS
C:\WINDOWS\system32\DRIVERS\USBD.SYS
Signed 0xF8BAE000008192
usbhub
C:\WINDOWS\system32\DRIVERS\usbhub.sys
Signed 0xF887A000061440
Flpydisk
C:\WINDOWS\system32\DRIVERS\flpydisk.sys
Signed 0xF89BA000020480
NDProxy
C:\WINDOWS\System32\Drivers\NDProxy.SYS
Signed 0xF885A000040960
mssmbios
C:\WINDOWS\system32\DRIVERS\mssmbios.sys
Signed 0xF8B62000016384
Update
C:\WINDOWS\system32\DRIVERS\update.sys
Signed 0xF8170000385024
swenum
C:\WINDOWS\system32\DRIVERS\swenum.sys
Signed 0xF8BAC000008192
TermDD
C:\WINDOWS\system32\DRIVERS\termdd.sys
Signed 0xF884A000040960
rdpdr
C:\WINDOWS\system32\DRIVERS\rdpdr.sys
Signed 0xF826E000196608
Raspti
C:\WINDOWS\system32\DRIVERS\raspti.sys
Signed 0xF89A2000020480
Ptilink
C:\WINDOWS\system32\DRIVERS\ptilink.sys
Signed 0xF899A000020480
Gpc
C:\WINDOWS\system32\DRIVERS\msgpc.sys
Signed 0xF883A000036864
PSched
C:\WINDOWS\system32\DRIVERS\psched.sys
Signed 0xF82C6000069632
TDI.SYS
C:\WINDOWS\system32\DRIVERS\TDI.SYS
Signed 0xF8992000020480
PptpMiniport
C:\WINDOWS\system32\DRIVERS\raspptp.sys
Signed 0xF882A000049152
RasPppoe
C:\WINDOWS\system32\DRIVERS\raspppoe.sys
Signed 0xF881A000045056
NdisWan
C:\WINDOWS\system32\DRIVERS\ndiswan.sys
Signed 0xF82D7000094208
NdisTapi
C:\WINDOWS\system32\DRIVERS\ndistapi.sys
Signed 0xF8B46000012288
Rasl2tp
C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
Signed 0xF880A000053248
audstub
C:\WINDOWS\system32\DRIVERS\audstub.sys
Signed 0xF8DAE000004096
intelppm
C:\WINDOWS\system32\DRIVERS\intelppm.sys
Signed 0xF87FA000040960
CmBatt
C:\WINDOWS\system32\DRIVERS\CmBatt.sys
Signed 0xF8B42000016384
usbehci
C:\WINDOWS\system32\DRIVERS\usbehci.sys
Signed 0xF898A000032768
drmk.sys
C:\WINDOWS\system32\drivers\drmk.sys
Signed 0xF87EA000061440
portcls.sys
C:\WINDOWS\system32\drivers\portcls.sys
Signed 0xF82EE000147456
es1371
C:\WINDOWS\system32\drivers\es1371mp.sys
Signed 0xF87DA000040960
vmxnet
C:\WINDOWS\system32\DRIVERS\vmxnet.sys
Signed 0xF8982000032768
USBPORT.SYS
C:\WINDOWS\system32\DRIVERS\USBPORT.SYS
Signed 0xF8312000147456
usbuhci
C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Signed 0xF897A000024576
VIDEOPRT.SYS
C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Signed 0xF8336000081920
vmx_svga
C:\WINDOWS\system32\DRIVERS\vmx_svga.sys
Signed 0xF8972000024576
vmci
C:\WINDOWS\system32\DRIVERS\vmci.sys
Signed 0xF87CA000057344
ks.sys
C:\WINDOWS\system32\DRIVERS\ks.sys
Signed 0xF834A000143360
redbook
C:\WINDOWS\system32\DRIVERS\redbook.sys
Signed 0xF87BA000061440
Cdrom
C:\WINDOWS\system32\DRIVERS\cdrom.sys
Signed 0xF87AA000065536
Fdc
C:\WINDOWS\system32\DRIVERS\fdc.sys
Signed 0xF896A000028672
serenum
C:\WINDOWS\system32\DRIVERS\serenum.sys
Signed 0xF8B3E000016384
Serial
C:\WINDOWS\system32\DRIVERS\serial.sys
Signed 0xF879A000065536
Parport
C:\WINDOWS\system32\DRIVERS\parport.sys
Signed 0xF836D000081920
Mouclass
C:\WINDOWS\system32\DRIVERS\mouclass.sys
Forged file 0xF8962000024576
vmmouse
C:\WINDOWS\system32\DRIVERS\vmmouse.sys
Signed 0xF8BA6000008192
Kbdclass
C:\WINDOWS\system32\DRIVERS\kbdclass.sys
Signed 0xF895A000028672
i8042prt
C:\WINDOWS\system32\DRIVERS\i8042prt.sys
Signed 0xF878A000053248
agp440
C:\WINDOWS\System32\Drivers\agp440.sys
Signed 0xF86EA000045056
Mup
C:\WINDOWS\System32\Drivers\Mup.sys
Signed 0xF83DA000106496
NDIS
C:\WINDOWS\System32\Drivers\NDIS.sys
Signed 0xF83F4000184320
Ntfs
C:\WINDOWS\System32\Drivers\Ntfs.sys
Signed 0xF8421000577536
KSecDD
C:\WINDOWS\System32\Drivers\KSecDD.sys
Signed 0xF84AE000094208
FltMgr
C:\WINDOWS\System32\Drivers\fltMgr.sys
Signed 0xF84C5000131072
CLASSPNP.SYS
C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Signed 0xF86DA000053248
Disk
C:\WINDOWS\System32\Drivers\disk.sys
Signed 0xF86CA000036864
SCSIPORT.SYS
C:\WINDOWS\system32\DRIVERS\SCSIPORT.SYS
Signed 0xF84E5000098304
vmscsi
C:\WINDOWS\System32\Drivers\vmscsi.sys
Signed 0xF8AB6000012288
atapi
C:\WINDOWS\System32\Drivers\atapi.sys
Signed 0xF84FD000098304
VolSnap
C:\WINDOWS\System32\Drivers\VolSnap.sys
Signed 0xF86BA000053248
PartMgr
C:\WINDOWS\System32\Drivers\PartMgr.sys
Signed 0xF8922000020480
dmio
C:\WINDOWS\System32\Drivers\dmio.sys
Signed 0xF8515000155648
dmload
C:\WINDOWS\System32\Drivers\dmload.sys
Signed 0xF8BA0000008192
Ftdisk
C:\WINDOWS\System32\Drivers\ftdisk.sys
Signed 0xF853B000126976
MountMgr
C:\WINDOWS\System32\Drivers\MountMgr.sys
Signed 0xF86AA000045056
PCIIDEX.SYS
C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Signed 0xF891A000028672
IntelIde
C:\WINDOWS\System32\Drivers\intelide.sys
Signed 0xF8B9E000008192
BATTC.SYS
C:\WINDOWS\system32\DRIVERS\BATTC.SYS
Signed 0xF8AB2000016384
Compbatt
C:\WINDOWS\System32\Drivers\compbatt.sys
Signed 0xF8AAE000012288
isapnp
C:\WINDOWS\System32\Drivers\isapnp.sys
Signed 0xF869A000040960
PCI
C:\WINDOWS\System32\Drivers\pci.sys
Signed 0xF855A000069632
WMILIB.SYS
C:\WINDOWS\system32\DRIVERS\WMILIB.SYS
Signed 0xF8B9C000008192
ACPI
C:\WINDOWS\System32\Drivers\ACPI.sys
Signed 0xF856B000188416
BOOTVID.dll
C:\WINDOWS\system32\BOOTVID.dll
Signed 0xF8AAA000012288
kdcom.dll
C:\WINDOWS\system32\KDCOM.DLL
Signed 0xF8B9A000008192
ACPI_HAL
C:\WINDOWS\system32\hal.dll
Signed 0x806D0000135168
RAW
C:\WINDOWS\system32\ntkrnlpa.exe
Signed 0x804D70002068480

Processes

PidEprocessShort NameFull PathStateInformation
07800x81A58620jucheck.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
Signed
40280x81D6E020Vba32arkit.exe
C:\Documents and Settings\1\Рабочий стол\Vba32arkit\Vba32arkit.exe
Signed
25880x81D23620wmiapsrv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
Signed
05880x81D05C10wscntfy.exe
C:\WINDOWS\system32\wscntfy.exe
Signed
04040x81F32548alg.exe
C:\WINDOWS\system32\alg.exe
Signed
05240x81DFADA0VMUpgradeHelper
C:\Program Files\VMware\VMware Tools\VMUpgradeHelper.exe
Signed
03080x81D3E990vmtoolsd.exe
C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
Signed
01840x81D25228jqs.exe
C:\Program Files\Java\jre6\bin\jqs.exe
Signed
20080x81D27898svchost.exe
C:\WINDOWS\system32\svchost.exe
Signed
18960x8209BA50ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
Signed
18880x81FE75F8jusched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
Signed
18800x820E67A8VMwareUser.exe
C:\Program Files\VMware\VMware Tools\VMwareUser.exe
Signed
18720x8209F6F0VMwareTray.exe
C:\Program Files\VMware\VMware Tools\VMwareTray.exe
Signed
16600x81D4A1E0spoolsv.exe
C:\WINDOWS\system32\spoolsv.exe
Signed
15360x81BCE020explorer.exe
C:\WINDOWS\explorer.exe
Signed
12640x8203C578svchost.exe
C:\WINDOWS\system32\svchost.exe
Signed
11160x81BBCDA0svchost.exe
C:\WINDOWS\system32\svchost.exe
Signed
10600x81BBBDA0svchost.exe
C:\WINDOWS\system32\svchost.exe
Signed
09600x8211D790svchost.exe
C:\WINDOWS\system32\svchost.exe
Signed
08760x82036788svchost.exe
C:\WINDOWS\system32\svchost.exe
Signed
08600x8208C360vmacthlp.exe
C:\Program Files\VMware\VMware Tools\vmacthlp.exe
Signed
06960x82088020lsass.exe
C:\WINDOWS\system32\lsass.exe
Signed
06840x81CB9740services.exe
C:\WINDOWS\system32\services.exe
Signed
06360x81C88A18winlogon.exe
C:\WINDOWS\system32\winlogon.exe
Signed
06040x8209C458csrss.exe
C:\WINDOWS\system32\csrss.exe
Signed
05400x81CB25F0smss.exe
C:\WINDOWS\system32\smss.exe
Signed
00040x821C87C0System

Autorun objects

NameImage PathStateInformation
Autostart Keys
CTFMON.EXE
C:\WINDOWS\system32\ctfmon.exeSigned
SunJavaUpdateSched
"C:\Program Files\Java\jre6\bin\jusched.exe"Signed
VMware Tools
"C:\Program Files\VMware\VMware Tools\VMwareTray.exe"Signed
VMware User Process
"C:\Program Files\VMware\VMware Tools\VMwareUser.exe"Signed
CTFMON.EXE
C:\WINDOWS\system32\CTFMON.EXESigned
CTFMON.EXE
C:\WINDOWS\system32\CTFMON.EXESigned
CTFMON.EXE
C:\WINDOWS\system32\CTFMON.EXESigned
CTFMON.EXE
C:\WINDOWS\system32\CTFMON.EXESigned
CTFMON.EXE
C:\WINDOWS\system32\ctfmon.exeSigned
Windows WinLogon
Shell
Explorer.exeSigned
UIHost
logonui.exeSigned
Userinit
C:\WINDOWS\system32\userinit.exe,Signed
VmApplet
rundll32 shell32,Control_RunDLL "sysdm.cpl"Signed
Browser Helper Objects
{DBC80044-A445-435b-BC74-9C25C1C588A9}C:\Program Files\Java\jre6\bin\jp2ssv.dllSigned
{E7E6F031-17CE-4C07-BC86-EABFE594F69C}C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
ActiveX
<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}C:\WINDOWS\system32\ieudinit.exeSigned
>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}C:\WINDOWS\inf\unregmp2.exe /ShowWMPSigned
>{26923b43-4d38-484f-9b9e-de460746276c}C:\WINDOWS\system32\ie4uinit.exe -UserIconConfigSigned
>{60B49E34-C7CC-11D0-8953-00A0C90347FF}"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUPSigned
>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROSRunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUPSigned
>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}%systemroot%\system32\shmgrate.exe OCInstallUserConfigOESigned
{2C7339CF-2B09-4501-B3F3-F3508C9228ED}%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dllSigned
{44BBA840-CC51-11CF-AAFA-00AA00B6015C}"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /installSigned
{44BBA842-CC51-11CF-AAFA-00AA00B6015B}rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NTSigned
{5945c046-1e7d-11d1-bc44-00c04fd912be}rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUserSigned
{6BF52A52-394A-11d3-B153-00C04F79FAA6}rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStubSigned
{7790769C-0471-11d2-AF11-00C04FA35D02}"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /installSigned
{89820200-ECBD-11cf-8B85-00AA005B4340}regsvr32.exe /s /n /i:U shell32.dllSigned
{89820200-ECBD-11cf-8B85-00AA005B4383}C:\WINDOWS\system32\ie4uinit.exe -BaseSettingsSigned
WinLogon Notify
{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}
gptext.dllSigned
{0E28E245-9368-4853-AD84-6DA3BA35BB75}
gpprefcl.dllSigned
{17D89FEC-5C44-4972-B12D-241CAEF74509}
gpprefcl.dllSigned
{1A6364EB-776B-4120-ADE1-B63A406A76B5}
gpprefcl.dllSigned
{25537BA6-77A8-11D2-9B6C-0000F8080861}
fdeploy.dllSigned
{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
dskquota.dllSigned
{3A0DBA37-F8B2-4356-83DE-3E90BD5C261F}
gpprefcl.dllSigned
{426031c0-0b47-4852-b0ca-ac3d37bfcb39}
gptext.dllSigned
{42B5FAAE-6536-11d2-AE5A-0000F87571E3}
gptext.dllSigned
{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}
C:\WINDOWS\system32\iedkcs32.dllSigned
{5794DAFD-BE60-433f-88A2-1A31939AC01F}
gpprefcl.dllSigned
{6232C319-91AC-4931-9385-E70C2B099F0E}
gpprefcl.dllSigned
{6A4C88C6-C502-4f74-8F60-2CB23EDC24E2}
gpprefcl.dllSigned
{7150F9BF-48AD-4da4-A49C-29EF4A8369BA}
gpprefcl.dllSigned
{728EE579-943C-4519-9EF7-AB56765798ED}
gpprefcl.dllSigned
{74EE6C03-5363-4554-B161-627540339CAB}
gpprefcl.dllSigned
{7B849a69-220F-451E-B3FE-2CB811AF94AE}
C:\WINDOWS\system32\iedkcs32.dllSigned
{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
scecli.dllSigned
{91FBB303-0CD5-4055-BF42-E512A681B325}
gpprefcl.dllSigned
{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
C:\WINDOWS\system32\iedkcs32.dllSigned
{A3F3E39B-5D83-4940-B954-28315B82F0A8}
gpprefcl.dllSigned
{AADCED64-746C-4633-A97C-D61349046527}
gpprefcl.dllSigned
{B087BE9D-ED37-454f-AF9C-04291E351182}
gpprefcl.dllSigned
{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}
scecli.dllSigned
{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}
dot3gpclnt.dllSigned
{BC75B1ED-5833-4858-9BB8-CBF0B166DF9D}
gpprefcl.dllSigned
{C418DD9D-0D14-4efb-8FBF-CFE535C8FAC7}
gpprefcl.dllSigned
{C631DF4C-088F-4156-B058-4375F0853CD8}
%SystemRoot%\System32\cscui.dllSigned
{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
C:\WINDOWS\system32\iedkcs32.dllSigned
{E47248BA-94CC-49c4-BBB5-9EB7F05183D0}
gpprefcl.dllSigned
{E4F48E54-F38D-4884-BFB9-D4D2E5729C18}
gpprefcl.dllSigned
{E5094040-C46C-4115-B030-04FB2E545B00}
gpprefcl.dllSigned
{E62688F0-25FD-4c90-BFF5-F508B9D2E31F}
gpprefcl.dllSigned
{F9C77450-3A41-477E-9310-9ACD617BD9E3}
gpprefcl.dllSigned
{c6dc5466-785a-11d2-84d0-00c04fb169f7}
appmgmts.dllSigned
{e437bc1c-aa7d-11d2-a382-00c04f991e27}
gptext.dllSigned
ScCertProp
wlnotify.dllSigned
Schedule
wlnotify.dllSigned
SensLogn
WlNotify.dllSigned
TPSvc
TPSvc.dllSigned
WgaLogon
WgaLogon.dll
crypt32chain
crypt32.dllSigned
cryptnet
cryptnet.dllSigned
cscdll
cscdll.dllSigned
dimsntfy
%SystemRoot%\System32\dimsntfy.dllSigned
sclgntfy
sclgntfy.dllSigned
termsrv
wlnotify.dllSigned
wlballoon
wlnotify.dllSigned
Security Providers
SecurityProvidersmsapsspc.dll, schannel.dll, digest.dll, msnsspc.dllSigned
Value Run Keys
SCRNSAVE.EXE
C:\WINDOWS\System32\logon.scrSigned
MVB
mvfs32.dll
Debugger
drwtsn32 -p %ld -e %ld -gSigned
CScript
%SystemRoot%\System32\cscript.exeSigned
WScript
%SystemRoot%\System32\wscript.exeSigned
ProviderPath
%SystemRoot%\system32\ntmarta.dllSigned
BootExecute
autocheck autochk *Signed
StartupPrograms
rdpclipSigned
SCRNSAVE.EXE
logon.scrSigned
MVB
mvfs32.dll
SCRNSAVE.EXE
logon.scrSigned
MVB
mvfs32.dll
SCRNSAVE.EXE
%SystemRoot%\System32\logon.scrSigned
MVB
mvfs32.dll
SCRNSAVE.EXE
%SystemRoot%\System32\logon.scrSigned
MVB
mvfs32.dll
SCRNSAVE.EXE
C:\WINDOWS\System32\logon.scrSigned
MVB
mvfs32.dll
Shared Task Scheduler
{438755C2-A8BA-11D1-B96B-00A0C90312E1}%SystemRoot%\system32\browseui.dllSigned
{8C7461EF-2B13-11d2-BE35-3078302C2030}%SystemRoot%\system32\browseui.dllSigned
Shell Execute Hooks
{AEB6717E-7E19-11d0-97EE-00C04FD91972}shell32.dllSigned
Shell Service Object Delay Load
CDBurn%SystemRoot%\system32\SHELL32.dllSigned
PostBootReminder%SystemRoot%\system32\SHELL32.dllSigned
SysTrayC:\WINDOWS\system32\stobject.dllSigned
WebCheckC:\WINDOWS\system32\webcheck.dllSigned
My Computer (Backup, Cleanup, Defrag utilities)
BackupPath
%SystemRoot%\system32\ntbackup.exeSigned
CleanupPath
%SystemRoot%\system32\cleanmgr.exe /D %cSigned
DefragPath
%systemroot%\system32\dfrg.msc %c:Signed
Utility Managers
MagnifierMagnify.exeSigned
On-Screen Keyboardosk.exeSigned
LSP Providers
MSAFD NetBIOS [\Device\NetBT_Tcpip_{236BE07E-9D2A-43F8-A74B-35AF89688FAC}] DATAGRAM 1%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip_{236BE07E-9D2A-43F8-A74B-35AF89688FAC}] SEQPACKET 1%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7E45E89C-3192-4D1E-BF79-6EC61D78F78E}] DATAGRAM 2%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7E45E89C-3192-4D1E-BF79-6EC61D78F78E}] SEQPACKET 2%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip_{F4C20D33-CF7B-4A04-9B35-E97EC5B3F29D}] DATAGRAM 0%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip_{F4C20D33-CF7B-4A04-9B35-E97EC5B3F29D}] SEQPACKET 0%SystemRoot%\system32\mswsock.dllSigned
MSAFD Tcpip [RAW/IP]%SystemRoot%\system32\mswsock.dllSigned
MSAFD Tcpip [TCP/IP]%SystemRoot%\system32\mswsock.dllSigned
MSAFD Tcpip [UDP/IP]%SystemRoot%\system32\mswsock.dllSigned
RSVP TCP Service Provider%SystemRoot%\system32\rsvpsp.dllSigned
RSVP UDP Service Provider%SystemRoot%\system32\rsvpsp.dllSigned
VMCI sockets DGRAMC:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll
VMCI sockets STREAMC:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll
Shell Spawning
Applications"C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1Signed
CLSID"C:\Program Files\Internet Explorer\iexplore.exe"Signed
Drive%SystemRoot%\Explorer.exeSigned
Folder%SystemRoot%\Explorer.exe /e,/idlist,%I,%LSigned
Folder%SystemRoot%\Explorer.exe /idlist,%I,%LSigned
InternetShortcut"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %lSigned
Unknown%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1Signed
batfile"%1" %*Signed
comfile"%1" %*Signed
cplfilerundll32.exe shell32.dll,Control_RunDLL "%1",%*Signed
exefile"%1" %*Signed
htafileC:\WINDOWS\system32\mshta.exe "%1" %*Signed
inffile%SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1Signed
jsefile%SystemRoot%\System32\WScript.exe "%1" %*Signed
jsfile%SystemRoot%\System32\WScript.exe "%1" %*Signed
piffile"%1" %*Signed
regfileregedit.exe "%1"Signed
scrfile"%1"Signed
scrfile"%1" /SSigned
txtfile%SystemRoot%\system32\NOTEPAD.EXE %1Signed
vbefile%SystemRoot%\System32\WScript.exe "%1" %*Signed
vbsfile%SystemRoot%\System32\WScript.exe "%1" %*Signed
wsffile%SystemRoot%\System32\WScript.exe "%1" %*Signed
wshfile%SystemRoot%\System32\WScript.exe "%1" %*Signed

Drivers\Services (from Registry)

Name and DescriptionImage PathStartStateInformation
AbiosdskDISABLED
abp480n5DISABLED
ACPI
system32\DRIVERS\ACPI.sysBOOTSigned
ACPIECDISABLED
adpu160mDISABLED
aec
system32\drivers\aec.sysDEMANDSigned
AFD
\SystemRoot\System32\drivers\afd.sysSYSTEMSigned
agp440
system32\DRIVERS\agp440.sysBOOTSigned
Aha154xDISABLED
aic78u2DISABLED
aic78xxDISABLED
Alerter
%SystemRoot%\system32\svchost.exe -k LocalServiceDISABLEDSigned
ALG
%SystemRoot%\System32\alg.exeDEMANDSigned
AliIdeDISABLED
amsintDISABLED
AppMgmt
%SystemRoot%\system32\svchost.exe -k netsvcsDEMANDSigned
ascDISABLED
asc3350pDISABLED
asc3550DISABLED
AsyncMac
system32\DRIVERS\asyncmac.sysDEMANDSigned
atapi
system32\DRIVERS\atapi.sysBOOTSigned
AtdiskDISABLED
Atmarpc
system32\DRIVERS\atmarpc.sysDEMANDSigned
AudioSrv
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
audstub
system32\DRIVERS\audstub.sysDEMANDSigned
BattC
BeepSYSTEM
BITS
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
Browser
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
cbidf2kDISABLED
cd20xrntDISABLED
CdaudioSYSTEM
CdfsDISABLED
Cdrom
system32\DRIVERS\cdrom.sysSYSTEMSigned
ChangerSYSTEM
CiSvc
%SystemRoot%\system32\cisvc.exeDEMANDSigned
ClipSrv
%SystemRoot%\system32\clipsrv.exeDISABLEDSigned
CmBatt
system32\DRIVERS\CmBatt.sysDEMANDSigned
CmdIdeDISABLED
Compbatt
system32\DRIVERS\compbatt.sysBOOTSigned
COMSysApp
C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}DEMANDSigned
ContentFilter
ContentIndex
CpqarrayDISABLED
CryptSvc
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
dac2w2kDISABLED
dac960ntDISABLED
DcomLaunch
%SystemRoot%\system32\svchost -k DcomLaunchAUTOSigned
Dhcp
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
Disk
system32\DRIVERS\disk.sysBOOTSigned
dmadmin
%SystemRoot%\System32\dmadmin.exe /comDEMANDSigned
dmbootSystem32\drivers\dmboot.sysDISABLEDSigned
dmio
System32\drivers\dmio.sysBOOTSigned
dmloadSystem32\drivers\dmload.sysBOOTSigned
dmserver
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
DMusic
system32\drivers\DMusic.sysDEMANDSigned
Dnscache
%SystemRoot%\system32\svchost.exe -k NetworkServiceAUTOSigned
Dot3svc
%SystemRoot%\System32\svchost.exe -k dot3svcDEMANDSigned
dpti2oDISABLED
drmkaud
system32\drivers\drmkaud.sysDEMANDSigned
EapHost
%SystemRoot%\System32\svchost.exe -k eapsvcsDEMANDSigned
ERSvc
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
es1371
system32\drivers\es1371mp.sysDEMANDSigned
Eventlog
%SystemRoot%\system32\services.exeAUTOSigned
EventSystem
C:\WINDOWS\system32\svchost.exe -k netsvcsDEMANDSigned
FastfatDISABLED
FastUserSwitchingCompatibility
%SystemRoot%\System32\svchost.exe -k netsvcsDEMANDSigned
Fdc
system32\DRIVERS\fdc.sysDEMANDSigned
FipsSYSTEM
Flpydisk
system32\DRIVERS\flpydisk.sysDEMANDSigned
FltMgr
system32\DRIVERS\fltMgr.sysBOOTSigned
Fs_RecSYSTEM
Ftdisk
system32\DRIVERS\ftdisk.sysBOOTSigned
gameenum
system32\DRIVERS\gameenum.sysDEMANDSigned
Gpc
system32\DRIVERS\msgpc.sysDEMANDSigned
helpsvc
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
HidServ
%SystemRoot%\System32\svchost.exe -k netsvcsDISABLEDSigned
hidusb
system32\DRIVERS\hidusb.sysDEMANDSigned
hkmsvc
%SystemRoot%\System32\svchost.exe -k netsvcsDEMANDSigned
hpnDISABLED
HTTP
System32\Drivers\HTTP.sysDEMANDSigned
HTTPFilter
%SystemRoot%\System32\svchost.exe -k HTTPFilterDEMANDSigned
i2omgmtSYSTEM
i2ompDISABLED
i8042prt
system32\DRIVERS\i8042prt.sysSYSTEMSigned
im9ssmie
\??\C:\WINDOWS\system32\drivers\im9ssmie.sysDEMANDSigned
Imapi
system32\DRIVERS\imapi.sysSYSTEMSigned
ImapiService
C:\WINDOWS\system32\imapi.exeDEMANDSigned
inetaccs
ini910uDISABLED
Inport
IntelIdesystem32\DRIVERS\intelide.sysBOOTSigned
intelppm
system32\DRIVERS\intelppm.sysSYSTEMSigned
Ip6Fw
system32\DRIVERS\Ip6Fw.sysDEMANDSigned
IpFilterDriver
system32\DRIVERS\ipfltdrv.sysDEMANDSigned
IpInIp
system32\DRIVERS\ipinip.sysDEMANDSigned
IpNat
system32\DRIVERS\ipnat.sysDEMANDSigned
IPSec
system32\DRIVERS\ipsec.sysSYSTEMSigned
IRENUM
system32\DRIVERS\irenum.sysDEMANDSigned
ISAPISearch
isapnp
system32\DRIVERS\isapnp.sysBOOTSigned
JavaQuickStarterService
"C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"AUTO
Kbdclass
system32\DRIVERS\kbdclass.sysSYSTEMSigned
kmixer
system32\drivers\kmixer.sysDEMANDSigned
KSecDDBOOT
LanmanServer
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
lanmanworkstation
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
lbrtfdcSYSTEM
ldap
LicenseService
LmHosts
%SystemRoot%\system32\svchost.exe -k LocalServiceAUTOSigned
Messenger
%SystemRoot%\system32\svchost.exe -k netsvcsDISABLEDSigned
mnmddSYSTEM
mnmsrvc
C:\WINDOWS\system32\mnmsrvc.exeDEMANDSigned
ModemDEMAND
Mouclass
system32\DRIVERS\mouclass.sysSYSTEMForged file
mouhid
system32\DRIVERS\mouhid.sysDEMANDSigned
MountMgrBOOT
mraid35xDISABLED
MRxDAV
system32\DRIVERS\mrxdav.sysDEMANDSigned
MRxSmb
system32\DRIVERS\mrxsmb.sysSYSTEMSigned
MSDTC
C:\WINDOWS\system32\msdtc.exeDEMANDSigned
MsfsSYSTEM
MSIServer
C:\WINDOWS\system32\msiexec.exe /VDEMANDSigned
MSKSSRV
system32\drivers\MSKSSRV.sysDEMANDSigned
MSPCLOCK
system32\drivers\MSPCLOCK.sysDEMANDSigned
MSPQM
system32\drivers\MSPQM.sysDEMANDSigned
mssmbios
system32\DRIVERS\mssmbios.sysDEMANDSigned
Mup
BOOT
napagent
%SystemRoot%\System32\svchost.exe -k netsvcsDEMANDSigned
NDIS
BOOT
NdisTapi
system32\DRIVERS\ndistapi.sysDEMANDSigned
Ndisuio
system32\DRIVERS\ndisuio.sysDEMANDSigned
NdisWan
system32\DRIVERS\ndiswan.sysDEMANDSigned
NDProxy
DEMAND
NetBIOS
system32\DRIVERS\netbios.sysSYSTEMSigned
NetBT
system32\DRIVERS\netbt.sysSYSTEMSigned
NetDDE
%SystemRoot%\system32\netdde.exeDISABLEDSigned
NetDDEdsdm
%SystemRoot%\system32\netdde.exeDISABLEDSigned
Netlogon
%SystemRoot%\system32\lsass.exeDEMANDSigned
Netman
%SystemRoot%\System32\svchost.exe -k netsvcsDEMANDSigned
Nla
%SystemRoot%\system32\svchost.exe -k netsvcsDEMANDSigned
NpfsSYSTEM
NtfsDISABLED
NtLmSsp
%SystemRoot%\system32\lsass.exeDEMANDSigned
NtmsSvc
%SystemRoot%\system32\svchost.exe -k netsvcsDEMANDSigned
NullSYSTEM
NwlnkFlt
system32\DRIVERS\nwlnkflt.sysDEMANDSigned
NwlnkFwd
system32\DRIVERS\nwlnkfwd.sysDEMANDSigned
Parport
system32\DRIVERS\parport.sysDEMANDSigned
PartMgrBOOT
ParVdmAUTO
PCI
system32\DRIVERS\pci.sysBOOTSigned
PCIDumpSYSTEM
PCIIdeDISABLED
PcmciaDISABLED
PCnet
system32\DRIVERS\pcntpci5.sysDEMANDSigned
PDCOMPDEMAND
PDFRAMEDEMAND
PDRELIDEMAND
PDRFRAMEDEMAND
perc2DISABLED
perc2hibDISABLED
PerfDisk
PerfNet
PerfOS
PerfProc
PlugPlay
%SystemRoot%\system32\services.exeAUTOSigned
PolicyAgent
%SystemRoot%\system32\lsass.exeAUTOSigned
PptpMiniport
system32\DRIVERS\raspptp.sysDEMANDSigned
ProtectedStorage
%SystemRoot%\system32\lsass.exeAUTOSigned
PSched
system32\DRIVERS\psched.sysDEMANDSigned
Ptilink
system32\DRIVERS\ptilink.sysDEMANDSigned
ql1080DISABLED
Ql10wntDISABLED
ql12160DISABLED
ql1240DISABLED
ql1280DISABLED
RasAcd
system32\DRIVERS\rasacd.sysSYSTEMSigned
RasAuto
%SystemRoot%\system32\svchost.exe -k netsvcsDEMANDSigned
Rasl2tp
system32\DRIVERS\rasl2tp.sysDEMANDSigned
RasMan
%SystemRoot%\system32\svchost.exe -k netsvcsDEMANDSigned
RasPppoe
system32\DRIVERS\raspppoe.sysDEMANDSigned
Raspti
system32\DRIVERS\raspti.sysDEMANDSigned
Rdbss
system32\DRIVERS\rdbss.sysSYSTEMSigned
RDPCDDSystem32\DRIVERS\RDPCDD.sysSYSTEMSigned
RDPDD
rdpdr
system32\DRIVERS\rdpdr.sysDEMANDSigned
RDPNP
RDPWDDEMAND
RDSessMgr
C:\WINDOWS\system32\sessmgr.exeDEMANDSigned
redbook
system32\DRIVERS\redbook.sysSYSTEMSigned
RemoteAccess
%SystemRoot%\system32\svchost.exe -k netsvcsDISABLEDSigned
RemoteRegistry
%SystemRoot%\system32\svchost.exe -k LocalServiceAUTOSigned
RpcLocator
%SystemRoot%\system32\locator.exeDEMANDSigned
RpcSs
%SystemRoot%\system32\svchost -k rpcssAUTOSigned
RSVP
%SystemRoot%\system32\rsvp.exeDEMANDSigned
SamSs
%SystemRoot%\system32\lsass.exeAUTOSigned
SCardSvr
%SystemRoot%\System32\SCardSvr.exeDEMANDSigned
Schedule
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
Secdrv
system32\DRIVERS\secdrv.sysDEMANDSigned
seclogon
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
SENS
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
serenum
system32\DRIVERS\serenum.sysDEMANDSigned
Serial
system32\DRIVERS\serial.sysSYSTEMSigned
SfloppySYSTEM
ShadowBOOT
SharedAccess
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
ShellHWDetection
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
SimbadDISABLED
SparrowDISABLED
splitter
system32\drivers\splitter.sysDEMANDSigned
Spooler
%SystemRoot%\system32\spoolsv.exeAUTOSigned
sr
\SystemRoot\system32\DRIVERS\sr.sysDISABLEDSigned
srservice
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
Srv
system32\DRIVERS\srv.sysDEMANDSigned
SSDPSRV
%SystemRoot%\system32\svchost.exe -k LocalServiceDEMANDSigned
stisvc
%SystemRoot%\system32\svchost.exe -k imgsvcDEMANDSigned
swenum
system32\DRIVERS\swenum.sysDEMANDSigned
swmidi
system32\drivers\swmidi.sysDEMANDSigned
SwPrv
C:\WINDOWS\system32\dllhost.exe /Processid:{6B1ADF90-CACC-422A-9E67-0C199B20D06B}DEMANDSigned
symc810DISABLED
symc8xxDISABLED
sym_hiDISABLED
sym_u3DISABLED
sysaudio
system32\drivers\sysaudio.sysDEMANDSigned
SysmonLog
%SystemRoot%\system32\smlogsvc.exeDEMANDSigned
TapiSrv
%SystemRoot%\System32\svchost.exe -k netsvcsDEMANDSigned
Tcpip
system32\DRIVERS\tcpip.sysSYSTEMSigned
TDPIPEDEMAND
TDTCPDEMAND
TermDD
system32\DRIVERS\termdd.sysSYSTEMSigned
TermService
%SystemRoot%\System32\svchost -k DComLaunchDEMANDSigned
Themes
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
TlntSvr
C:\WINDOWS\system32\tlntsvr.exeDISABLEDSigned
TosIdeDISABLED
TPAutoConnSvc
"C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe"DEMANDSigned
TrkWks
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
TSDDD
UdfsDISABLED
ultraDISABLED
Update
system32\DRIVERS\update.sysDEMANDSigned
upnphost
%SystemRoot%\system32\svchost.exe -k LocalServiceDEMANDSigned
UPS
%SystemRoot%\System32\ups.exeDEMANDSigned
usbccgp
system32\DRIVERS\usbccgp.sysDEMANDSigned
usbehci
system32\DRIVERS\usbehci.sysDEMANDSigned
usbhub
system32\DRIVERS\usbhub.sysDEMANDSigned
usbuhci
system32\DRIVERS\usbuhci.sysDEMANDSigned
VgaSave\SystemRoot\System32\drivers\vga.sysSYSTEMSigned
ViaIdeDISABLED
vmci
system32\DRIVERS\vmci.sysDEMANDSigned
vmdebug
\??\C:\WINDOWS\system32\Drivers\vmdebug.sysSYSTEMSigned
vmdesched
"C:\Program Files\VMware\VMware Tools\vmdesched.exe"DEMANDSigned
vmdesched-driver
\??\C:\WINDOWS\system32\Drivers\vmdesched.sysAUTOSigned
vmhgfsSystem32\DRIVERS\vmhgfs.sysSYSTEMSigned
VMMEMCTL
\??\C:\Program Files\VMware\VMware Tools\Drivers\memctl\vmmemctl.sysAUTOSigned
vmmouse
system32\DRIVERS\vmmouse.sysDEMANDSigned
vmrawdsk
\??\C:\Program Files\VMware\VMware Tools\vmrawdsk.sysSYSTEM
vmscsi
system32\DRIVERS\vmscsi.sysBOOTSigned
VMTools
"C:\Program Files\VMware\VMware Tools\vmtoolsd.exe"AUTOSigned
VMUpgradeHelper
"C:\Program Files\VMware\VMware Tools\VMUpgradeHelper.exe" /serviceAUTOSigned
VMware Physical Disk Helper Service
"C:\Program Files\VMware\VMware Tools\vmacthlp.exe"AUTOSigned
vmxnet
system32\DRIVERS\vmxnet.sysDEMANDSigned
vmx_svgasystem32\DRIVERS\vmx_svga.sysDEMANDSigned
VolSnapBOOT
VSS
%SystemRoot%\System32\vssvc.exeDEMANDSigned
W32Time
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
W3SVC
Wanarp
system32\DRIVERS\wanarp.sysDEMANDSigned
WDICADEMAND
wdmaud
system32\drivers\wdmaud.sysDEMANDSigned
WebClient
%SystemRoot%\system32\svchost.exe -k LocalServiceAUTOSigned
winmgmt
%systemroot%\system32\svchost.exe -k netsvcsAUTOSigned
WinsockDEMAND
WinSock2
WinTrust
WmdmPmSN
%SystemRoot%\System32\svchost.exe -k netsvcsDEMANDSigned
Wmi
%SystemRoot%\System32\svchost.exe -k netsvcsDEMANDSigned
WmiApRpl
WmiApSrv
C:\WINDOWS\system32\wbem\wmiapsrv.exeDEMANDSigned
WS2IFSL
\SystemRoot\System32\drivers\ws2ifsl.sysSYSTEMSigned
wscsvc
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
wuauserv
%systemroot%\system32\svchost.exe -k netsvcsAUTOSigned
WZCSVC
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
xmlprov
%SystemRoot%\System32\svchost.exe -k netsvcsDEMANDSigned
{F4C20D33-CF7B-4A04-9B35-E97EC5B3F29D}
pxtdipow\??\C:\DOCUME~1\1\LOCALS~1\Temp\pxtdipow.sysDEMAND

Copyright © 1993-2010 VirusBlokAda Ltd. All Rights Reserved