[AM] 32. c:\windows\system32\netman.dll
Microsoft Corporation
Network Connections Manager
.text,.data,.rsrc,.reloc,
Nla
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 33. c:\windows\system32\mswsock.dll
Microsoft Corporation
Microsoft Windows Sockets 2.0 Service Provider
.text,SANONTCP,.data,.rsrc,.reloc,
NtLmSsp
[AM] 31. c:\windows\system32\lsass.exe
Microsoft Corporation
LSA Shell (Export Version)
.text,.data,.rsrc,
NtmsSvc
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[A ] 34. c:\windows\system32\ntmssvc.dll
Microsoft Corporation
Removable Storage Manager
.text,.data,.rsrc,.reloc,
ose
[A ] 35. c:\program files\common files\microsoft shared\source engine\ose.exe
Microsoft Corporation
Office Source Engine
.text,.data,.rsrc,
PlugPlay
[AM] 16. c:\windows\system32\services.exe
Microsoft Corporation
Services and Controller app
.text,.data,.rsrc,
PolicyAgent
[AM] 31. c:\windows\system32\lsass.exe
Microsoft Corporation
LSA Shell (Export Version)
.text,.data,.rsrc,
ProtectedStorage
[AM] 31. c:\windows\system32\lsass.exe
Microsoft Corporation
LSA Shell (Export Version)
.text,.data,.rsrc,
RasAuto
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[A ] 36. c:\windows\system32\rasauto.dll
Microsoft Corporation
Remote Access AutoDial Manager
.text,.data,.rsrc,.reloc,
RasMan
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 37. c:\windows\system32\rasmans.dll
Microsoft Corporation
Remote Access Connection Manager
.text,.data,.rsrc,.reloc,
RDSessMgr
[A ] 38. c:\windows\system32\sessmgr.exe
Microsoft Corporation
Microsoft(R) Remote Desktop Help Session Manager
.text,.data,.rsrc,
RemoteAccess
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[A ] 39. c:\windows\system32\mprdim.dll
Microsoft Corporation
Dynamic Interface Manager
.text,.data,.rsrc,.reloc,
RemoteRegistry
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[A ] 40. c:\windows\system32\regsvc.dll
Microsoft Corporation
Remote Registry Service
.text,.data,.rsrc,.reloc,
RpcLocator
[A ] 41. c:\windows\system32\locator.exe
Microsoft Corporation
Rpc Locator
.text,.data,.rsrc,
RpcSs
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 11. c:\windows\system32\rpcss.dll
Microsoft Corporation
Distributed COM Services
.text,.data,.rsrc,.reloc,
[AM] 11. c:\windows\system32\rpcss.dll
Microsoft Corporation
Distributed COM Services
.text,.data,.rsrc,.reloc,
RsRavMon
[AM] 42. c:\program files\rising\rav\ravmond.exe
Beijing Rising Information Technology Co., Ltd.
ravmond
.text,.rdata,.data,.rsrc,
RSVP
[A ] 43. c:\windows\system32\rsvp.exe
Microsoft Corporation
Microsoft RSVP
.text,.data,.rsrc,
SamSs
[AM] 31. c:\windows\system32\lsass.exe
Microsoft Corporation
LSA Shell (Export Version)
.text,.data,.rsrc,
SCardSvr
[A ] 44. c:\windows\system32\scardsvr.exe
Microsoft Corporation
Smart Card Resource Management Server
.text,.data,.rsrc,
Schedule
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 45. c:\windows\system32\schedsvc.dll
Microsoft Corporation
Task Scheduler Engine
.text,.data,.rsrc,.reloc,
seclogon
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 46. c:\windows\system32\seclogon.dll
Microsoft Corporation
Secondary Logon Service DLL
.text,.data,.rsrc,.reloc,
SENS
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 47. c:\windows\system32\sens.dll
Microsoft Corporation
System Event Notification Service (SENS)
.text,.data,.rsrc,.reloc,
SharedAccess
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 48. c:\windows\system32\ipnathlp.dll
Microsoft Corporation
Microsoft NAT Helper Components
.text,.data,.rsrc,.reloc,
ShellHWDetection
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 18. c:\windows\system32\shsvcs.dll
Microsoft Corporation
Windows Shell Services Dll
.text,.data,.rsrc,.reloc,
Spooler
[AM] 49. c:\windows\system32\spoolsv.exe
Microsoft Corporation
Spooler SubSystem App
.text,.data,.rsrc,
srservice
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[A ] 50. c:\windows\system32\srsvc.dll
Microsoft Corporation
System Restore Service
.text,.data,.rsrc,.reloc,
SSDPSRV
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 51. c:\windows\system32\ssdpsrv.dll
Microsoft Corporation
SSDP Service DLL
.text,.data,.rsrc,.reloc,
stisvc
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[A ] 52. c:\windows\system32\wiaservc.dll
Microsoft Corporation
Still Image Devices Service
.text,.data,.rsrc,.reloc,
SwPrv
[A ] 9. c:\windows\system32\dllhost.exe
Microsoft Corporation
COM Surrogate
.text,.data,.rsrc,
SysmonLog
[A ] 53. c:\windows\system32\smlogsvc.exe
Microsoft Corporation
Performance Logs and Alerts Service
.text,.data,.rsrc,
TapiSrv
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 54. c:\windows\system32\tapisrv.dll
Microsoft Corporation
Microsoft(R) Windows(TM) Telephony Server
.text,.data,.rsrc,.reloc,
TermService
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 55. c:\windows\system32\termsrv.dll
Microsoft Corporation
Terminal Server Service
.text,.data,.rsrc,.reloc,
Themes
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 18. c:\windows\system32\shsvcs.dll
Microsoft Corporation
Windows Shell Services Dll
.text,.data,.rsrc,.reloc,
TlntSvr
[A ] 56. c:\windows\system32\tlntsvr.exe
Microsoft Corporation
Telnet
.text,.data,.rsrc,
TrkWks
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 57. c:\windows\system32\trkwks.dll
Microsoft Corporation
Distributed Link Tracking Client
.text,.data,.rsrc,.reloc,
UMWdf
[A ] 58. c:\windows\system32\wdfmgr.exe
Microsoft Corporation
Windows User Mode Driver Manager
.text,.data,.rsrc,
upnphost
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[A ] 59. c:\windows\system32\upnphost.dll
Microsoft Corporation
UPnP Device Host
.text,.orpc,.data,.rsrc,.reloc,
UPS
[A ] 60. c:\windows\system32\ups.exe
Microsoft Corporation
UPS Service
.text,.data,.rsrc,
VSS
[A ] 61. c:\windows\system32\vssvc.exe
Microsoft Corporation
Microsoft(R) Volume Shadow Copy Service
.text,.data,.rsrc,
W32Time
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 62. c:\windows\system32\w32time.dll
Microsoft Corporation
Windows Time Service
.text,.data,.rsrc,.reloc,
WebClient
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 63. c:\windows\system32\webclnt.dll
Microsoft Corporation
Web DAV Service DLL
.text,.data,.rsrc,.reloc,
[A ] 64. c:\windows\system32\davclnt.dll
Microsoft Corporation
Web DAV Client DLL
.text,.data,.rsrc,.reloc,
winmgmt
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 65. c:\windows\system32\wbem\wmisvc.dll
Microsoft Corporation
WMI
.text,.data,.rsrc,.reloc,
WmdmPmSN
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[A ] 66. c:\windows\system32\mspmsnsv.dll
Microsoft Corporation
Microsoft Media Device Service Provider
.text,.data,.rsrc,.reloc,
Wmi
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 67. c:\windows\system32\advapi32.dll
Microsoft Corporation
Advanced Windows 32 Base API
.text,.data,.rsrc,.reloc,
WmiApSrv
[A ] 68. c:\windows\system32\wbem\wmiapsrv.exe
Microsoft Corporation
WMI Performance Adapter Service
.text,.data,.rsrc,
wscsvc
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[A ] 69. c:\windows\system32\wscsvc.dll
Microsoft Corporation
Windows Security Center Service
.text,.data,.rsrc,.reloc,
wuauserv
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 70. c:\windows\system32\wuauserv.dll
Microsoft Corporation
Windows Update AutoUpdate Service
.text,.data,.rsrc,.reloc,
WZCSVC
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[AM] 71. c:\windows\system32\wzcsvc.dll
Microsoft Corporation
Wireless Zero Configuration Service
.text,.data,.rsrc,.reloc,
xmlprov
[AM] 1. c:\windows\system32\svchost.exe
Microsoft Corporation
Generic Host Process for Win32 Services
.text,.data,.rsrc,
[A ] 72. c:\windows\system32\xmlprov.dll
Microsoft Corporation
Network Provisioning Service
.text,.data,.rsrc,.reloc,
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
ac97intc
[A ] 73. c:\windows\system32\drivers\ac97intc.sys
Intel Corporation
Intel(r) Integrated Controller Hub Audio Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
ACPI
[A ] 74. c:\windows\system32\drivers\acpi.sys
Microsoft Corporation
ACPI Driver for NT
.text,.rdata,.data,PAGE,PAGE,INIT,.rsrc,.reloc,
ACPIEC
[A ] 75. c:\windows\system32\drivers\acpiec.sys
Microsoft Corporation
ACPI Embedded Controller Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
aec
[A ] 76. c:\windows\system32\drivers\aec.sys
Microsoft Corporation
Microsoft Acoustic Echo Canceller
.text,.rdata,.data,PAGE,PAGEDATA,PAGECONS,INIT,.rsrc,.reloc,
AFD
[A ] 77. c:\windows\system32\drivers\afd.sys
Microsoft Corporation
Ancillary Function Driver for WinSock
.text,.rdata,.data,PAGE,PAGEAFD,PAGESAN,INIT,.rsrc,.reloc,
agp440
[A ] 78. c:\windows\system32\drivers\agp440.sys
Microsoft Corporation
440 NT AGP Filter
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
AmdK8
[A ] 79. c:\windows\system32\drivers\amdk8.sys
Advanced Micro Devices
AMD Processor Driver
.text,.rdata,.data,PAGE,PAGELK,INIT,.rsrc,.reloc,
AsyncMac
[A ] 80. c:\windows\system32\drivers\asyncmac.sys
Microsoft Corporation
MS Remote Access serial network driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
atapi
[A ] 81. c:\windows\system32\drivers\atapi.sys
Microsoft Corporation
IDE/ATAPI Port Driver
.text,NONPAGE,.rdata,.data,PAGESCAN,PAGE,INIT,.rsrc,.reloc,
audstub
[A ] 82. c:\windows\system32\drivers\audstub.sys
Microsoft Corporation
AudStub Driver
.text,.rdata,PAGE,INIT,.rsrc,.reloc,
Beep
[A ] 83. c:\windows\system32\drivers\beep.sys
Microsoft Corporation
BEEP Driver
.text,.rdata,INIT,.rsrc,.reloc,
cbidf2k
[A ] 84. c:\windows\system32\drivers\cbidf2k.sys
Microsoft Corporation
CardBus/PCMCIA IDE Miniport Driver
.text,.rdata,INIT,.rsrc,.reloc,
Cdaudio
[A ] 85. c:\windows\system32\drivers\cdaudio.sys
Microsoft Corporation
CD-ROM Audio Filter Driver
.text,.rdata,PAGECDNC,PAGECDOT,INIT,.rsrc,.reloc,
Cdrom
[A ] 86. c:\windows\system32\drivers\cdrom.sys
Microsoft Corporation
SCSI CD-ROM Driver
.text,.rdata,.data,PAGE,PAGEHIT2,PAGEHITA,PAGETOSH,PAGE,INIT,.rsrc,.reloc,
Disk
[A ] 87. c:\windows\system32\drivers\disk.sys
Microsoft Corporation
PnP Disk Driver
.text,.rdata,.data,PAGE,PAGE,INIT,.rsrc,.reloc,
dmboot
[A ] 88. c:\windows\system32\drivers\dmboot.sys
Microsoft Corp., Veritas Software
NT Disk Manager Startup Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
dmio
[A ] 89. c:\windows\system32\drivers\dmio.sys
Microsoft Corp., Veritas Software
NT Disk Manager I/O Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
dmload
[A ] 90. c:\windows\system32\drivers\dmload.sys
Microsoft Corp., Veritas Software.
NT Disk Manager Startup Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
DMusic
[A ] 91. c:\windows\system32\drivers\dmusic.sys
Microsoft Corporation
Microsoft Kernel DLS Synthesizer
.text,.rdata,.data,INIT,.rsrc,.reloc,
drmkaud
[A ] 92. c:\windows\system32\drivers\drmkaud.sys
Microsoft Corporation
Microsoft Kernel DRM Audio Descrambler Filter
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
Fdc
[A ] 93. c:\windows\system32\drivers\fdc.sys
Microsoft Corporation
Floppy Disk Controller Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
FETNDIS
[A ] 94. c:\windows\system32\drivers\fetnd5.sys
VIA Technologies, Inc.
NDIS 5.0 miniport driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
Fips
[A ] 95. c:\windows\system32\drivers\fips.sys
Microsoft Corporation
FIPS Crypto Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
Flpydisk
[A ] 96. c:\windows\system32\drivers\flpydisk.sys
Microsoft Corporation
Floppy Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
FsVga
[A ] 97. c:\windows\system32\drivers\fsvga.sys
Microsoft Corporation
Full Screen Video Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
Ftdisk
[A ] 98. c:\windows\system32\drivers\ftdisk.sys
Microsoft Corporation
FT Disk Driver
.text,.rdata,.data,PAGE,PAGELK,INIT,.rsrc,.reloc,
gameenum
[A ] 99. c:\windows\system32\drivers\gameenum.sys
Microsoft Corporation
Game Port Enumerator
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
Gpc
[A ] 100. c:\windows\system32\drivers\msgpc.sys
Microsoft Corporation
MS General Packet Classifier
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,