In my last post regarding Windows 7’s new “auto-elevate” flag (and potential issues with such a system), I mentioned compiling a list of all the flagged binaries. Well, here it is.
Please note this list is not inclusive of binaries found in the Windows Side-by-Side (WinSXS) folders or of 64-bit binaries. Interesting binaries, from a elevate-my-own-code standpoint, are highlighted in yellow.
Item count: 68 (filtered out 78 additional binaries)
- Program Files/Windows Media Player/wmpconfig.exe (removed in build 7022)
- Windows/System32/AdapterTroubleshooter.exe
- Windows/System32/BdeUnlockWizard.exe
- Windows/System32/BitLockerWizardElev.exe
- Windows/System32/bthudtask.exe
- Windows/System32/chkntfs.exe
- Windows/System32/cleanmgr.exe
- Windows/System32/cliconfg.exe
- Windows/System32/CompMgmtLauncher.exe
- Windows/System32/ComputerDefaults.exe
- Windows/System32/control.exe
- Windows/System32/dccw.exe
- Windows/System32/dcomcnfg.exe
- Windows/System32/DeviceEject.exe
- Windows/System32/DeviceProperties.exe
- Windows/System32/dfrgui.exe
- Windows/System32/diskpart.exe
- Windows/System32/diskraid.exe
- Windows/System32/djoin.exe
- Windows/System32/DriverStore/FileRepository/bth.inf_x86_neutral_fa7077fa81991fb6/fsquirt.exe
- Windows/System32/eudcedit.exe
- Windows/System32/eventvwr.exe
- Windows/System32/FXSUNATD.exe
- Windows/System32/hdwwiz.exe
- Windows/System32/ieUnatt.exe
- Windows/System32/iscsicli.exe
- Windows/System32/iscsicpl.exe
- Windows/System32/lpksetup.exe
- Windows/System32/MdSched.exe
- Windows/System32/mmc.exe
- Windows/System32/msconfig.exe
- Windows/System32/msdt.exe
- Windows/System32/msra.exe
- Windows/System32/MultiDigiMon.exe
- Windows/System32/Netplwiz.exe
- Windows/System32/newdev.exe
- Windows/System32/ntprint.exe
- Windows/System32/ocsetup.exe
- Windows/System32/odbcad32.exe
- Windows/System32/oobe/setupsqm.exe
- Windows/System32/OptionalFeatures.exe
- Windows/System32/PDMSetup.exe
- Windows/System32/perfmon.exe
- Windows/System32/printui.exe
- Windows/System32/recdisc.exe
- Windows/System32/rrinstaller.exe
- Windows/System32/rstrui.exe
- Windows/System32/rundll32.exe
- Windows/System32/sdbinst.exe
- Windows/System32/sdclt.exe
- Windows/System32/shrpubw.exe
- Windows/System32/slui.exe
- Windows/System32/SndVol.exe
- Windows/System32/syskey.exe
- Windows/System32/sysprep/sysprep.exe
- Windows/System32/SystemPropertiesAdvanced.exe
- Windows/System32/SystemPropertiesComputerName.exe
- Windows/System32/SystemPropertiesDataExecutionPrevention.exe
- Windows/System32/SystemPropertiesHardware.exe
- Windows/System32/SystemPropertiesPerformance.exe
- Windows/System32/SystemPropertiesProtection.exe
- Windows/System32/SystemPropertiesRemote.exe
- Windows/System32/taskmgr.exe
- Windows/System32/tcmsetup.exe
- Windows/System32/TpmInit.exe
- Windows/System32/verifier.exe
- Windows/System32/wisptis.exe
- Windows/System32/wusa.exe

Pingback: List of Windows 7 (Build 7000) auto-elevated executables » Kristan Kenney’s Digital Life
Pingback: Short: Windows 7 (beta build 7022) white list loses one - Within Windows
Pingback: Cranial Trauma » Windows 7, UAC & VMware
Pingback: Windows 7 Has 62 Uplifting EXEs | The Minority Report
Pingback: Dan Griffin’s Blog » Interesting Windows 7 UAC vulnerability
Pingback: Windows 7 UAC whitelist: Code-injection Issue | Cupfighter.net
Pingback: Windows 7 UAC whitelist: Code-injection Issue (and more) « Jasper Blog
Pingback: 荷兰猪的天下 » bypass win7 UAC
Pingback: » Short: Windows 7 Release Candidate auto-elevate white list Within Windows