I've developed a little tool which lists at the moment only Processes and Services. Also the header can read out some information about the OS. (Architecture, system, ServicePack, etc.)
First, a ToDo List:
ProcessesServicesDrivers- RegistrySection
- FilesSection
- FixSection
- Expand the Whitelist
- Design
- Icon
Known Bugs:
Still some file path errors (under Services) - explanation to this will follow tomorrow (29.10.2013)Too high Net.Framework (At the moment 4.5!)Bug with listing DriversAnother bug with listing drivers
Example Log (08.11.2013):
MVS - Machiavelli's Scanner - Version 1.0.0.1. MVS Logfile created on: 28.11.2013 18:58:10 Logfile saved under = C:\Users\Machiavelli\Desktop\MVS.txt Running from C:\Users\Machiavelli\Desktop\MVS.exe SYSTEM => Microsoft Windows 8.1 64 bit === Processes === C:\Users\Machiavelli\AppData\Local\Google\Chrome\Application\chrome.exe [ 9444 ] (Google Inc.) C:\Users\Machiavelli\AppData\Local\Google\Chrome\Application\chrome.exe [ 11608 ] (Google Inc.) C:\Users\Machiavelli\AppData\Local\Google\Chrome\Application\chrome.exe [ 8972 ] (Google Inc.) C:\WINDOWS\system32\taskhostex.exe [ 10804 ] (Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe [ 10212 ] (Microsoft Corporation) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\Packages\Debugger\X64\msvsmon.exe [ 12568 ] (Microsoft Corporation) C:\Users\Machiavelli\AppData\Local\Google\Chrome\Application\chrome.exe [ 6856 ] (Google Inc.) c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [ 8420 ] (Microsoft Corporation) C:\WINDOWS\system32\DllHost.exe [ 7432 ] (Microsoft Corporation) C:\Users\Machiavelli\AppData\Local\Google\Chrome\Application\chrome.exe [ 1664 ] (Google Inc.) C:\Users\Machiavelli\AppData\Local\Google\Chrome\Application\chrome.exe [ 6820 ] (Google Inc.) c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [ 10176 ] (Microsoft Corporation) C:\WINDOWS\system32\conhost.exe [ 6628 ] (Microsoft Corporation) C:\Users\Machiavelli\Desktop\MVS.exe [ 5640 ] () C:\Program Files\AVAST Software\Avast\avastui.exe [ 5436 ] (AVAST Software) C:\Users\Machiavelli\AppData\Local\Google\Chrome\Application\chrome.exe [ 5832 ] (Google Inc.) C:\Users\Machiavelli\documents\visual studio 2012\Projects\MVS\MVS\bin\Debug\MVS.vshost.exe [ 8576 ] (Microsoft Corporation) C:\Users\Machiavelli\AppData\Local\Google\Chrome\Application\chrome.exe [ 9560 ] (Google Inc.) C:\Users\Machiavelli\AppData\Local\Google\Chrome\Application\chrome.exe [ 5812 ] (Google Inc.) C:\Program Files (x86)\Microsoft SDKs\Windows\v8.0A\bin\NETFX 4.0 Tools\MSBuildTaskHost.exe [ 10340 ] (Microsoft Corporation) C:\Program Files\Oracle\VirtualBox\VBoxSVC.exe [ 9548 ] (Oracle Corporation) C:\WINDOWS\Explorer.EXE [ 8168 ] (Microsoft Corporation) C:\Users\Machiavelli\AppData\Roaming\Dropbox\bin\Dropbox.exe [ 6392 ] (Dropbox, Inc.) C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [ 10180 ] (Oracle Corporation) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\WDExpress.exe [ 14040 ] (Microsoft Corporation) C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [ 10864 ] (Oracle Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\LiveComm.exe [ 2112 ] (Microsoft Corporation) C:\Users\Machiavelli\AppData\Local\Google\Chrome\Application\chrome.exe [ 11832 ] (Google Inc.) C:\WINDOWS\syswow64\wwahost.exe [ 1384 ] (Microsoft Corporation) === Services === SRV - [ AdobeFlashPlayerUpdateSvc | Adobe Flash Player Update Service | Stopped] - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe - [10.09.2013 14:45:42 | 257416 | (Adobe Systems Incorporated)] SRV - [ AMD FUEL Service | AMD FUEL Service | Running] - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe /launchService => File not found! SRV - [ avast! Antivirus | avast! Antivirus | Running] - C:\Program Files\AVAST Software\Avast\AvastSvc.exe - [01.11.2013 11:10:56 | 50344 | (AVAST Software)] SRV - [ MBAMScheduler | MBAMScheduler | Running] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe - [11.11.2013 19:10:48 | 418376 | (Malwarebytes Corporation)] SRV - [ MBAMService | MBAMService | Stopped] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe - [11.11.2013 19:10:48 | 701512 | (Malwarebytes Corporation)] SRV - [ MozillaMaintenance | Mozilla Maintenance Service | Stopped] - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe - [28.10.2013 11:32:50 | 119408 | (Mozilla Foundation)] SRV - [ Steam Client Service | Steam Client Service | Stopped] - C:\Program Files (x86)\Common Files\Steam\SteamService.exe - [18.07.2013 08:00:01 | 566696 | (Valve Corporation)] SRV - [ VsEtwService120 | Visual Studio ETW-Ereignisauflistungsdienst | Stopped] - C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe - [05.10.2013 00:58:24 | 87728 | (Microsoft Corporation)] SRV - [ WinDefend | Windows Defender-Dienst | Stopped] - C:\Program Files\Windows Defender\MsMpEng.exe - [22.08.2013 13:30:34 | 23840 | (Microsoft Corporation)] === Drivers === DRV - [ aswFsBlk | 2 | 38984] - C:\WINDOWS\system32\drivers\aswFsBlk.sys (AVAST Software) DRV - [ aswMonFlt | 2 | 84328] - C:\WINDOWS\system32\drivers\aswMonFlt.sys (AVAST Software) DRV - [ aswRdr | 1 | 92544] - C:\WINDOWS\system32\drivers\aswRdr2.sys (AVAST Software) DRV - [ aswSnx | 1 | 1032416] - C:\WINDOWS\system32\drivers\aswSnx.sys (AVAST Software) DRV - [ aswSP | 1 | 409832] - C:\WINDOWS\system32\drivers\aswSP.sys (AVAST Software) DRV - [ MBAMProtector | 3 | 25928] - C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation) DRV - [ speedfan | 2 | 28664] - C:\WINDOWS\SysWOW64\speedfan.sys (Almico Software) DRV - [ VBoxDrv | 1 | 252688] - C:\Windows\system32\DRIVERS\VBoxDrv.sys (Oracle Corporation) DRV - [ VBoxNetAdp | 3 | 140560] - C:\Windows\system32\DRIVERS\VBoxNetAdp.sys (Oracle Corporation) DRV - [ VBoxNetFlt | 3 | 154896] - C:\Windows\system32\DRIVERS\VBoxNetFlt.sys (Oracle Corporation) DRV - [ VBoxUSBMon | 1 | 126736] - C:\Windows\system32\DRIVERS\VBoxUSBMon.sys (Oracle Corporation) DRV - [ aswMBR | 3 | File not found ] - C:\Users\MACHIA~1\AppData\Local\Temp\aswMBR.sys
Instructions:
- Start the program as Administrator
- Click on the button Scan
- Wait a while
- A log is produced in the same location where the exe file is saved
- Please post that log
Changelog:
Version 1.0.0.
- Tool lists Processes and Services
Version 1.0.0.1
- Tool lists Drivers
- Fixed a bug (if the file doesn't exist a error message pop up)
- Another bug (Didn't list all drivers)
- Fixed a formatting issues with the drivers
Attached Files
Edited by Machiavelli, 28 November 2013 - 11:59 AM.