+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
BIOS
[A ] 8. c:\windows\system32\drivers\bios.sys
BIOSTAR Group
I/O Interface driver file
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
HDAudBus
[A ] 9. c:\windows\system32\drivers\hdaudbus.sys
Windows (R) Server 2003 DDK provider
High Definition Audio Bus Driver v1.0a
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
IntcAzAudAddService
[A ] 10. c:\windows\system32\drivers\rtkhdaud.sys
Realtek Semiconductor Corp.
Realtek(r) High Definition Audio Function Driver
.text,CODE,.rdata,.data,.data1,PAGE,INIT,.rsrc,.reloc,
NPF
[A ] 11. c:\windows\system32\drivers\npf.sys
Politecnico di Torino
NPF Driver - TME extensions
.text,.rdata,.data,INIT,.rsrc,.reloc,
nvata
[A ] 12. c:\windows\system32\drivers\nvata.sys
NVIDIA Corporation
NVIDIA? nForce(TM) IDE Performance Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
NVENETFD
[A ] 13. c:\windows\system32\drivers\nvenetfd.sys
NVIDIA Corporation
NVIDIA Networking Function Driver.
.text,.rdata,.data,INIT,.rsrc,.reloc,
nvnetbus
[A ] 14. c:\windows\system32\drivers\nvnetbus.sys
NVIDIA Corporation
NVIDIA Networking Bus Driver.
.text,.rdata,.data,INIT,.rsrc,.reloc,
RsAntiSpyware
[A ] 15. c:\windows\system32\drivers\rsboot.sys
Beijing Rising Technology Co., Ltd.
Anti-RootKit Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
Secdrv
[A ] 16. c:\windows\system32\drivers\secdrv.sys
.text,.data,INIT,.reloc,
+ 系统登陆自运行
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
AtiExtEvent
[AM] 17. c:\windows\system32\ati2evxx.dll
ATI Technologies Inc.
ATI External Event Utility DLL Module
.text,.rdata,.data,.rsrc,.reloc,
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
application/octet-stream
[AM] 18. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
application/x-complus
[AM] 18. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
application/x-msdownload
[AM] 18. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 19. c:\windows\system32\hticons.dll
Hilgraeve, Inc.
HyperTerminal Applet Library
.text,.data,.rsrc,.reloc,
WinRAR shell extension
[A ] 20. c:\program files\winrar\rarext.dll
.text,.data,.tls,.idata,.edata,.rsrc,.reloc,
ShellLink for Application References
[A ] 21. c:\windows\system32\dfshim.dll
Microsoft Corporation
Application Deployment Support Library
.text,.data,.rsrc,.reloc,
Shell Icon Handler for Application References
[A ] 21. c:\windows\system32\dfshim.dll
Microsoft Corporation
Application Deployment Support Library
.text,.data,.rsrc,.reloc,
Catalyst Context Menu extension
[A ] 22. c:\program files\ati technologies\ati.ace\atiacmxx.dll
ACE Context Menu
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{754FB7D8-B8FE-4810-B363-A788CD060F1F}
[AM] 23. c:\program files\internet explorer\plugins\system64.sys
.packed,.RLPack,
入口点在最后一个节;
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 24. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,