+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
aracpi
[A ] 16. c:\windows\system32\drivers\aracpi.sys
Microsoft Corporation
Microsoft AR ACPI Driver (Beta 2 Release 2)
.text,.rdata,.data,INIT,.rsrc,.reloc,
arhidfltr
[A ] 17. c:\windows\system32\drivers\arhidfltr.sys
Microsoft Corporation
Microsoft AR HID Filter Driver (Beta 2 Release 2)
.text,.rdata,.data,INIT,.rsrc,.reloc,
arkbcfltr
[A ] 18. c:\windows\system32\drivers\arkbcfltr.sys
Microsoft Corporation
Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
armoucfltr
[A ] 19. c:\windows\system32\drivers\armoucfltr.sys
Microsoft Corporation
Microsoft AR PS/2 Mouse Filter Driver (Beta 2 Release 2)
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
ARPolicy
[A ] 20. c:\windows\system32\drivers\arpolicy.sys
Microsoft Corporation
Microsoft AR Policy Driver (Beta 2 Release 2)
.text,.rdata,.data,INIT,.rsrc,.reloc,
BaseTDI
[A ] 21. c:\windows\system32\drivers\basetdi.sys
Beijing Rising Technology Co., Ltd.
basetdi
.text,.rdata,.data,INIT,.rsrc,.reloc,
bb-run
[A ] 22. c:\windows\system32\drivers\bb-run.sys
Promise Technology, Inc.
Promise Disk Accelerator
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
CMB8100
[A ] 23. c:\windows\system32\drivers\certclient.dat
.text,.rdata,.data,INIT,.reloc,
CMBProtector
[A ] 24. c:\windows\system32\drivers\cmbprotector.dat
.text,.rdata,.data,INIT,.reloc,
CnsStd
[A ] 25. c:\windows\system32\drivers\cnsstd.sys
国风因特软件(北京)有限公司
.text,.rdata,.data,INIT,.rsrc,.reloc,
ExpScaner
[A ] 26. c:\program files\rising\rav\expscan.sys
ExpScan.sys
.text,.rdata,.data,INIT,.rsrc,.reloc,
ft2kEnum
[A ] 27. c:\windows\system32\drivers\ic2kenum.sys
OEM Corporation
ic2k Bus Enumerator
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
ftsata2
[A ] 28. c:\windows\system32\drivers\ftsata2.sys
Promise Technology, Inc.
Promise Driver for Windows Server 2003
.text,.rdata,.data,INIT,.rsrc,.reloc,
GTVD500
[A ] 29. c:\windows\system32\drivers\gtvd500.sys
Prolific Technology Inc.
USB-to-Serial Cable Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
HDAudBus
[A ] 30. c:\windows\system32\drivers\hdaudbus.sys
Windows (R) Server 2003 DDK provider
High Definition Audio Bus Driver v1.0a
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
HookCont
[A ] 31. c:\program files\rising\rav\hookcont.sys
Rising
HookCont
.text,.rdata,.data,INIT,.rsrc,.reloc,
HookReg
[A ] 32. c:\program files\rising\rav\hookreg.sys
.text,.rdata,.data,INIT,.rsrc,.reloc,
HookSys
[A ] 33. c:\program files\rising\rav\hooksys.sys
Rising
Hooksys
.text,.rdata,.data,INIT,.rsrc,.reloc,
iaStor
[A ] 34. c:\windows\system32\drivers\iastor.sys
Intel Corporation
Intel Matrix Storage Manager driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
IntcAzAudAddService
[A ] 35. c:\windows\system32\drivers\rtkhdaud.sys
Realtek Semiconductor Corp.
Realtek(r) High Definition Audio Function Driver
.text,CODE,.rdata,.data,.data1,PAGE,INIT,.rsrc,.reloc,
lgjfnap
[A ] 36. c:\windows\system32\drivers\lgjfnap.sys
北京三七二一科技有限公司
sys 应用程序
.text,.rdata,.data,INIT,.rsrc,.reloc,
MEMSCAN
[A ] 37. c:\program files\rising\rav\memscan.sys
Beijing Rising Technology Co., Ltd.
MemScan Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
MHNDRV
[A ] 38. c:\windows\system32\drivers\mhndrv.sys
Microsoft Corporation
Microsoft Multimedia Home Network (MHN) Support Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
Ps2
[A ] 39. c:\windows\system32\drivers\ps2.sys
Hewlett-Packard Company
PS2 SYS
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
PxHelp20
[A ] 40. c:\windows\system32\drivers\pxhelp20.sys
Sonic Solutions
Px Engine Device Driver for Windows 2000/XP
.text,.rdata,.data,INIT,.rsrc,.reloc,
QKeyService
[A ] 41. c:\windows\system32\keycrypt.sys
Tencent Technology (Shenzhen) Company Limited
KeyCrypt Device Driver
.text,.rdata,.data,.CRT,.STL,INIT,.rsrc,.reloc,
R5BaseSmc
[A ] 42. c:\windows\system32\drivers\smccard.sys
OEM
This is used by SRC 2000 Readers
page,.text,init,.rdata,.data,INIT,.rsrc,.reloc,
Reader_Device
[A ] 43. c:\windows\system32\drivers\usbic2k.sys
OEM
This is used by SRC 2000 Readers
page,.text,init,.rdata,.data,INIT,.rsrc,.reloc,
RsAntiSpyware
[A ] 44. c:\windows\system32\drivers\rsboot.sys
Beijing Rising Technology Co., Ltd.
Anti-RootKit Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
RsNTGDI
[A ] 45. c:\windows\system32\drivers\rsntgdi.sys
Beijing Rising Technology Co., Ltd.
RsNTGDI
.text,.rdata,INIT,.rsrc,.reloc,
RSPPSYS
[A ] 46. c:\program files\rising\rav\rsppsys.sys
Rising
RSPPSYS.SYS
.text,.rdata,.data,INIT,.rsrc,.reloc,
RTL8023xp
[A ] 47. c:\windows\system32\drivers\rtnicxp.sys
Realtek Semiconductor Corporation
Realtek 10/100/1000 NDIS 5.1 Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
Secdrv
[A ] 48. c:\windows\system32\drivers\secdrv.sys
.text,.data,INIT,.reloc,
SYMIDSCO
[A ] 49. c:\progra~1\common~1\symant~1\symcdata\idsdefs\20050901.036\symidsco.sys
TesSafe
[A ] 50. c:\windows\system32\tessafe.sys
.text,.rdata,.data,INIT,.reloc,
token
[A ] 51. c:\windows\system32\drivers\eps2kt1.sys
USB Smart Card Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
WudfPf
[A ] 52. c:\windows\system32\drivers\wudfpf.sys
Microsoft Corporation
Windows Driver Foundation - User-mode Driver Framework Platform Driver
.text,.rdata,.data,PAGE,.edata,INIT,.rsrc,.reloc,
WudfRd
[A ] 53. c:\windows\system32\drivers\wudfrd.sys
Microsoft Corporation
Windows Driver Foundation - User-mode Driver Framework Reflector
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
ZSMC301b
[A ] 54. c:\windows\system32\drivers\usbvm31b.sys
VM
Video streaming and Capture Device Driver
.text,.data,PAGECONS,INIT,.rsrc,.reloc,
+ 文件系统驱动
+ HKLM\System\CurrentControlSet\Services
CnsMinKP
[A ] 55. c:\windows\system32\drivers\cnsminkp.sys
+ 系统登陆自运行
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
WgaLogon
[AM] 56. c:\windows\system32\wgalogon.dll
Microsoft Corporation
Windows 正版增值计划通知
.text,.data,.rsrc,.reloc,
+ HKCU\Control Panel\Desktop
Scrnsave.exe
[A ] 57. c:\program files\oberon media\insaniquarium deluxe\insaniquarium.scr
.text,.rdata,.data,.rsrc,