Hi Alistar,
I see those in the loaded modules, but I'm interested to know how you picked these out specifically - is this something you have seen before?
: kd> lmv m TmXPFlt
start end module name
fffff801`b2c91000 fffff801`b2cfd000 TmXPFlt (deferred)
Image path: \??\C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmXPFlt.sys
Image name: TmXPFlt.sys
Timestamp: Sat Aug 30 14:11:38 2014 (5401CD8A)
CheckSum: 0005DDB6
ImageSize: 0006C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
3: kd> lmv m TMEBC64
start end module name
fffff801`b101b000 fffff801`b102a000 TMEBC64 (deferred)
Image path: \SystemRoot\system32\DRIVERS\TMEBC64.sys
Image name: TMEBC64.sys
Timestamp: Mon Jul 01 14:02:09 2013 (51D17DD1)
CheckSum: 00019AD9
ImageSize: 0000F000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
3: kd> lmv m TmPreFlt
start end module name
fffff801`b299d000 fffff801`b29ad000 TmPreFlt (deferred)
Image path: \??\C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmPreFlt.sys
Image name: TmPreFlt.sys
Timestamp: Sat Aug 30 14:11:25 2014 (5401CD7D)
CheckSum: 0001438F
ImageSize: 00010000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
3: kd> lmvm TmPreFlt
... all loaded modules;
3: kd> lm
start end module name
fffff800`041b6000 fffff800`041bf000 kd (deferred)
fffff800`05210000 fffff800`05999000 nt (pdb symbols) c:\symbols\ntkrnlmp.pdb\6E60CE642F39465DAF09219706DE11471\ntkrnlmp.pdb
fffff800`05999000 fffff800`05a09000 hal (deferred)
fffff801`b0e00000 fffff801`b0e88000 CI (deferred)
fffff801`b0e8d000 fffff801`b0ef3000 mcupdate_GenuineIntel (deferred)
fffff801`b0ef3000 fffff801`b0f01000 werkernel (deferred)
fffff801`b0f01000 fffff801`b0f62000 CLFS (deferred)
fffff801`b0f62000 fffff801`b0f84000 tm (deferred)
fffff801`b0f84000 fffff801`b0f99000 PSHED (deferred)
fffff801`b0f99000 fffff801`b0fa3000 BOOTVID (deferred)
fffff801`b0fa3000 fffff801`b1000000 msrpc (deferred)
fffff801`b1000000 fffff801`b101b000 mountmgr (deferred)
fffff801`b101b000 fffff801`b102a000 TMEBC64 (deferred)
fffff801`b102a000 fffff801`b1034000 atapi (deferred)
fffff801`b105f000 fffff801`b112e000 Wdf01000 (deferred)
fffff801`b112e000 fffff801`b113f000 WDFLDR (deferred)
fffff801`b113f000 fffff801`b1157000 acpiex (deferred)
fffff801`b1157000 fffff801`b1162000 WppRecorder (deferred)
fffff801`b1162000 fffff801`b11ec000 ACPI (deferred)
fffff801`b11ec000 fffff801`b11f6000 WMILIB (deferred)
fffff801`b1200000 fffff801`b125f000 volmgrx (deferred)
fffff801`b125f000 fffff801`b126e000 PCIIDEX (deferred)
fffff801`b1274000 fffff801`b1300000 cng (deferred)
fffff801`b131b000 fffff801`b1337000 pdc (deferred)
fffff801`b1337000 fffff801`b134f000 partmgr (deferred)
fffff801`b134f000 fffff801`b13b8000 spaceport (deferred)
fffff801`b13b8000 fffff801`b13cd000 volmgr (deferred)
fffff801`b13cd000 fffff801`b13e6000 vmci (deferred)
fffff801`b13e6000 fffff801`b13fc000 vsock (deferred)
fffff801`b1400000 fffff801`b1478000 NETIO (deferred)
fffff801`b1478000 fffff801`b1482000 msisadrv (deferred)
fffff801`b1482000 fffff801`b14ca000 pci (deferred)
fffff801`b14ca000 fffff801`b14d7000 vdrvroot (deferred)
fffff801`b14d7000 fffff801`b14e0000 intelide (deferred)
fffff801`b14e5000 fffff801`b15fd000 NDIS (deferred)
fffff801`b1600000 fffff801`b164c000 netbt (deferred)
fffff801`b167a000 fffff801`b16af000 ataport (deferred)
fffff801`b16af000 fffff801`b16cc000 lsi_sas (deferred)
fffff801`b16cc000 fffff801`b172b000 storport (deferred)
fffff801`b172b000 fffff801`b1787000 fltmgr (deferred)
fffff801`b1787000 fffff801`b17b5000 quota (deferred)
fffff801`b17b5000 fffff801`b17d7000 datascrn (deferred)
fffff801`b17d7000 fffff801`b17e5000 cbafilt (deferred)
fffff801`b1800000 fffff801`b1861000 dxgmms1 (deferred)
fffff801`b1861000 fffff801`b1a57000 Ntfs (deferred)
fffff801`b1a57000 fffff801`b1a73000 ksecdd (deferred)
fffff801`b1a73000 fffff801`b1a83000 pcw (deferred)
fffff801`b1a83000 fffff801`b1a8e000 Fs_Rec (deferred)
fffff801`b1a8e000 fffff801`b1abf000 ksecpkg (deferred)
fffff801`b1abf000 fffff801`b1b14000 CLASSPNP (deferred)
fffff801`b1b14000 fffff801`b1b42000 cdrom (deferred)
fffff801`b1b42000 fffff801`b1bb8000 dedup (deferred)
fffff801`b1bb8000 fffff801`b1bcf000 ahcache (deferred)
fffff801`b1c00000 fffff801`b1c4f000 volsnap (deferred)
fffff801`b1c4f000 fffff801`b1c66000 mup (deferred)
fffff801`b1c66000 fffff801`b1c72000 ndistapi (deferred)
fffff801`b1c72000 fffff801`b1c8e000 disk (deferred)
fffff801`b1c8e000 fffff801`b1ca3000 crashdmp (deferred)
fffff801`b1ccc000 fffff801`b1cd5000 Null (deferred)
fffff801`b1cda000 fffff801`b1f4e000 tcpip (deferred)
fffff801`b1f4e000 fffff801`b1fba000 fwpkclnt (deferred)
fffff801`b1fba000 fffff801`b1fdf000 wfplwfs (deferred)
fffff801`b1fdf000 fffff801`b1fed000 BasicRender (deferred)
fffff801`b1fed000 fffff801`b1ff8000 ws2ifsl (deferred)
fffff801`b2200000 fffff801`b2220000 tdx (deferred)
fffff801`b2229000 fffff801`b23aa000 dxgkrnl (deferred)
fffff801`b23aa000 fffff801`b23bc000 watchdog (deferred)
fffff801`b23bc000 fffff801`b23ce000 BasicDisplay (deferred)
fffff801`b23ce000 fffff801`b23e2000 Npfs (deferred)
fffff801`b23e2000 fffff801`b23ee000 Msfs (deferred)
fffff801`b23ee000 fffff801`b23fc000 TDI (deferred)
fffff801`b2400000 fffff801`b240c000 mssmbios (deferred)
fffff801`b240c000 fffff801`b2432000 dfsc (deferred)
fffff801`b2439000 fffff801`b24cb000 afd (deferred)
fffff801`b24cb000 fffff801`b24f5000 pacer (deferred)
fffff801`b24f5000 fffff801`b2506000 netbios (deferred)
fffff801`b2506000 fffff801`b2553000 tmcomm (deferred)
fffff801`b2553000 fffff801`b25c3000 rdbss (deferred)
fffff801`b25c3000 fffff801`b25dc000 wanarp (deferred)
fffff801`b25dc000 fffff801`b25ea000 nsiproxy (deferred)
fffff801`b25ea000 fffff801`b25f6000 npsvctrig (deferred)
fffff801`b2600000 fffff801`b2606380 CmBatt (deferred)
fffff801`b2607000 fffff801`b2613000 BATTC (deferred)
fffff801`b2613000 fffff801`b2631000 intelppm (deferred)
fffff801`b2631000 fffff801`b263b000 pnpmem (deferred)
fffff801`b263b000 fffff801`b265c000 raspptp (deferred)
fffff801`b265c000 fffff801`b2680000 rasl2tp (deferred)
fffff801`b2680000 fffff801`b268b000 NdisVirtualBus (deferred)
fffff801`b268b000 fffff801`b26a6000 raspppoe (deferred)
fffff801`b26a6000 fffff801`b26e3000 ndiswan (deferred)
fffff801`b26e3000 fffff801`b2700000 rassstp (deferred)
fffff801`b2700000 fffff801`b271f000 AgileVpn (deferred)
fffff801`b271f000 fffff801`b272e000 CompositeBus (deferred)
fffff801`b272e000 fffff801`b2739000 kdnic (deferred)
fffff801`b2739000 fffff801`b274a000 umbus (deferred)
fffff801`b274a000 fffff801`b2769000 i8042prt (deferred)
fffff801`b2769000 fffff801`b2779000 kbdclass (deferred)
fffff801`b2779000 fffff801`b2781000 vmmouse (deferred)
fffff801`b2781000 fffff801`b2791000 mouclass (deferred)
fffff801`b2791000 fffff801`b27dc000 vm3dmp (deferred)
fffff801`b27dc000 fffff801`b27f3000 vmxnet3n61x64 (deferred)
fffff801`b27f3000 fffff801`b27fd000 vmgencounter (deferred)
fffff801`b27fd000 fffff801`b27fe600 swenum (deferred)
fffff801`b2800000 fffff801`b28a9000 peauth (deferred)
fffff801`b28ca000 fffff801`b2918000 ks (deferred)
fffff801`b2918000 fffff801`b2923000 rdpbus (deferred)
fffff801`b2923000 fffff801`b293a000 NDProxy (deferred)
fffff801`b293a000 fffff801`b2946000 dump_diskdump (deferred)
fffff801`b2946000 fffff801`b2963000 dump_LSI_SAS (deferred)
fffff801`b2963000 fffff801`b296af00 HIDPARSE (deferred)
fffff801`b296b000 fffff801`b2979000 monitor (deferred)
fffff801`b2979000 fffff801`b299d000 luafv (deferred)
fffff801`b299d000 fffff801`b29ad000 TmPreFlt (deferred)
fffff801`b2a00000 fffff801`b2a39000 mrxsmb20 (deferred)
fffff801`b2a59000 fffff801`b2c91000 VSApiNt (deferred)
fffff801`b2c91000 fffff801`b2cfd000 TmXPFlt (deferred)
fffff801`b2cfd000 fffff801`b2d11000 lltdio (deferred)
fffff801`b2d11000 fffff801`b2d29000 rspndr (deferred)
fffff801`b2d29000 fffff801`b2d49000 bowser (deferred)
fffff801`b2d49000 fffff801`b2d60000 mpsdrv (deferred)
fffff801`b2d60000 fffff801`b2dcc000 mrxsmb (deferred)
fffff801`b2e00000 fffff801`b2e09000 vmmemctl (deferred)
fffff801`b2e09000 fffff801`b2e54000 mrxsmb10 (deferred)
fffff801`b2e54000 fffff801`b2e64000 condrv (deferred)
fffff801`b2e64000 fffff801`b2e6f000 secdrv (deferred)
fffff801`b2e6f000 fffff801`b2eb2000 srvnet (deferred)
fffff801`b2eb2000 fffff801`b2ec4000 tcpipreg (deferred)
fffff801`b2efe000 fffff801`b2ff8000 HTTP (deferred)
fffff801`b3038000 fffff801`b30e4000 srv2 (deferred)
fffff801`b30e4000 fffff801`b3172000 srv (deferred)
fffff801`b3172000 fffff801`b319f000 tunnel (deferred)
fffff801`b319f000 fffff801`b31aa000 rdpvideominiport (deferred)
fffff801`b31aa000 fffff801`b31de000 rdpdr (deferred)
fffff801`b31de000 fffff801`b31eb000 terminpt (deferred)
fffff960`0014b000 fffff960`0055a000 win32k (deferred)
fffff960`006cd000 fffff960`006d6000 TSDDD (deferred)
fffff960`00838000 fffff960`00873000 cdd (deferred)
Unloaded modules:
fffff801`b301b000 fffff801`b3024000 cpuz136_x64.
fffff801`b3012000 fffff801`b301b000 cpuz136_x64.
fffff801`b3009000 fffff801`b3012000 cpuz136_x64.
fffff801`b3000000 fffff801`b3009000 cpuz136_x64.
fffff801`b31f4000 fffff801`b31fd000 cpuz136_x64.
fffff801`b31eb000 fffff801`b31f4000 cpuz136_x64.
fffff801`b1ca3000 fffff801`b1caf000 dump_storpor
fffff801`b1caf000 fffff801`b1ccc000 dump_LSI_SAS
fffff801`b1c66000 fffff801`b1c72000 hwpolicy.sys
fffff801`b1300000 fffff801`b131b000 sacdrv.sys
3: kd> lm TmXPFlt
Cheers,
Jon