Netlogon = C:\WINDOWS\SYSTEM32\LSASS.EXE
Netman = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
NetWorkLogon = RUNDLL32.EXE KB8964225.LOG,START
Nla = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
NtLmSsp = C:\WINDOWS\SYSTEM32\LSASS.EXE
NtmsSvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
NVSvc = C:\WINDOWS\SYSTEM32\NVSVC32.EXE
ose = "C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\SOURCE ENGINE\OSE.EXE"
PlugPlay = C:\WINDOWS\SYSTEM32\SERVICES.EXE
PolicyAgent = C:\WINDOWS\SYSTEM32\LSASS.EXE
ProtectedStorage = C:\WINDOWS\SYSTEM32\LSASS.EXE
RasAuto = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
RasMan = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
RavMonD = C:\WINDOWS\RAVMOND
RDSessMgr = C:\WINDOWS\SYSTEM32\SESSMGR.EXE
RemoteAccess = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
RemoteRegistry = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
RpcLocator = C:\WINDOWS\SYSTEM32\LOCATOR.EXE
RpcSs = C:\WINDOWS\SYSTEM32\SVCHOST -K RPCSS
RSVP = C:\WINDOWS\SYSTEM32\RSVP.EXE
SamSs = C:\WINDOWS\SYSTEM32\LSASS.EXE
SCardSvr = C:\WINDOWS\SYSTEM32\SCARDSVR.EXE
Schedule = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
seclogon = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
SENS = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
SharedAccess = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
ShellHWDetection = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Spooler = C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
srservice = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
SSDPSRV = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
stisvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K IMGSVC
SwPrv = C:\WINDOWS\SYSTEM32\DLLHOST.EXE /PROCESSID:{BE9D868E-DFC5-467A-B38E-9DF50E39C961}
SysmonLog = C:\WINDOWS\SYSTEM32\SMLOGSVC.EXE
TapiSrv = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
TermService = C:\WINDOWS\SYSTEM32\SVCHOST -K DCOMLAUNCH
Themes = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
TlntSvr = C:\WINDOWS\SYSTEM32\TLNTSVR.EXE
TrkWks = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
UMWdf = C:\WINDOWS\SYSTEM32\WDFMGR.EXE
upnphost = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
UPS = C:\WINDOWS\SYSTEM32\UPS.EXE
VSS = C:\WINDOWS\SYSTEM32\VSSVC.EXE
W32Time = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
WebClient = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
WinMessagePool = C:\PROGRAM FILES\DATASERVER.EXE
winmgmt = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
WmdmPmSN = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Wmi = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
WmiApSrv = C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE
wscsvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
wuauserv = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
WZCSVC = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
xmlprov = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
文件驱动
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
FltMgr = C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
MRxDAV = C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
MRxSmb = C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
NetBIOS = C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
Rdbss = C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
sr = C:\WINDOWS\SYSTEM32\DRIVERS\SR.SYS
Srv = C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
系统驱动项
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
a320raid = C:\WINDOWS\SYSTEM32\DRIVERS\A320RAID.SYS
AAC = C:\WINDOWS\SYSTEM32\DRIVERS\AAC.SYS
aar1210 = C:\WINDOWS\SYSTEM32\DRIVERS\AAR1210.SYS
abp480n5 = C:\WINDOWS\SYSTEM32\DRIVERS\ABP480N5.SYS
ac97intc = C:\WINDOWS\SYSTEM32\DRIVERS\AC97INTC.SYS
ACPI = C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
adpu160m = C:\WINDOWS\SYSTEM32\DRIVERS\ADPU160M.SYS
adpu320 = C:\WINDOWS\SYSTEM32\DRIVERS\ADPU320.SYS
aec = C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS
aec6210 = C:\WINDOWS\SYSTEM32\DRIVERS\AEC6210.SYS
aec6260 = C:\WINDOWS\SYSTEM32\DRIVERS\AEC6260.SYS
aec6280 = C:\WINDOWS\SYSTEM32\DRIVERS\AEC6280.SYS
AEC6290 = C:\WINDOWS\SYSTEM32\DRIVERS\AEC6290.SYS
AEC67160 = C:\WINDOWS\SYSTEM32\DRIVERS\AEC67160.SYS
AEC671X = C:\WINDOWS\SYSTEM32\DRIVERS\AEC671X.SYS
AEC6880 = C:\WINDOWS\SYSTEM32\DRIVERS\AEC6880.SYS
AEC6890 = C:\WINDOWS\SYSTEM32\DRIVERS\AEC6890.SYS
aec68x5 = C:\WINDOWS\SYSTEM32\DRIVERS\AEC68X5.SYS
AFD = C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
agp440 = C:\WINDOWS\SYSTEM32\DRIVERS\AGP440.SYS
Aha154x = C:\WINDOWS\SYSTEM32\DRIVERS\AHA154X.SYS
aic78u2 = C:\WINDOWS\SYSTEM32\DRIVERS\AIC78U2.SYS
aic78xx = C:\WINDOWS\SYSTEM32\DRIVERS\AIC78XX.SYS
AliIde = C:\WINDOWS\SYSTEM32\DRIVERS\ALIIDE.SYS
AmdK6 = C:\WINDOWS\SYSTEM32\DRIVERS\AMDK6.SYS
AmdK7 = C:\WINDOWS\SYSTEM32\DRIVERS\AMDK7.SYS
AmdK8 = C:\WINDOWS\SYSTEM32\DRIVERS\AMDK8.SYS
amsint = C:\WINDOWS\SYSTEM32\DRIVERS\AMSINT.SYS
arc = C:\WINDOWS\SYSTEM32\DRIVERS\ARC.SYS
asc = C:\WINDOWS\SYSTEM32\DRIVERS\ASC.SYS
asc3550 = C:\WINDOWS\SYSTEM32\DRIVERS\ASC3550.SYS
AsyncMac = C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
atapi = C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
Atmarpc = C:\WINDOWS\SYSTEM32\DRIVERS\ATMARPC.SYS
ATSpy = C:\WINDOWS\SYSTEM32\ATSPY.SYS
audstub = C:\WINDOWS\SYSTEM32\DRIVERS\AUDSTUB.SYS
cbidf = C:\WINDOWS\SYSTEM32\DRIVERS\CBIDF2K.SYS
Cdrom = C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
CmdIde = C:\WINDOWS\SYSTEM32\DRIVERS\CMDIDE.SYS
CnxEtP = C:\WINDOWS\SYSTEM32\DRIVERS\CNXETP.SYS
CnxEtU = C:\WINDOWS\SYSTEM32\DRIVERS\CNXETU.SYS
CnxTgN = C:\WINDOWS\SYSTEM32\DRIVERS\CNXTGN.SYS
CnxTgNL = C:\WINDOWS\SYSTEM32\DRIVERS\CNXTGNL.SYS
CnxTgNP = C:\WINDOWS\SYSTEM32\DRIVERS\CNXTGNP.SYS
Cpqarray = C:\WINDOWS\SYSTEM32\DRIVERS\CPQARRAY.SYS
Crusoe = C:\WINDOWS\SYSTEM32\DRIVERS\CRUSOE.SYS
dac2w2k = C:\WINDOWS\SYSTEM32\DRIVERS\DAC2W2K.SYS
dac960nt = C:\WINDOWS\SYSTEM32\DRIVERS\DAC960NT.SYS
Disk = C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
dmboot = C:\WINDOWS\SYSTEM32\DRIVERS\DMBOOT.SYS
dmio = C:\WINDOWS\SYSTEM32\DRIVERS\DMIO.SYS
dmload = C:\WINDOWS\SYSTEM32\DRIVERS\DMLOAD.SYS
DMusic = C:\WINDOWS\SYSTEM32\DRIVERS\DMUSIC.SYS
dpti2o = C:\WINDOWS\SYSTEM32\DRIVERS\DPTI2O.SYS
drmkaud = C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
elxstor = C:\WINDOWS\SYSTEM32\DRIVERS\ELXSTOR.SYS
FASTSX = C:\WINDOWS\SYSTEM32\DRIVERS\FASTSX.SYS
fasttrak = C:\WINDOWS\SYSTEM32\DRIVERS\FASTTRAK.SYS
fasttx2k = C:\WINDOWS\SYSTEM32\DRIVERS\FASTTX2K.SYS
fasttx2k2 = C:\WINDOWS\SYSTEM32\DRIVERS\FASTTX2K2.SYS
Fdc = C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
FETNDIS = C:\WINDOWS\SYSTEM32\DRIVERS\FETND5.SYS
FETNDISB = C:\WINDOWS\SYSTEM32\DRIVERS\FETND5B.SYS
FsVga = C:\WINDOWS\SYSTEM32\DRIVERS\FSVGA.SYS
Ftdisk = C:\WINDOWS\SYSTEM32\DRIVERS\FTDISK.SYS
gameenum = C:\WINDOWS\SYSTEM32\DRIVERS\GAMEENUM.SYS
Gpc = C:\WINDOWS\SYSTEM32\DRIVERS\MSGPC.SYS
HidUsb = C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
HpCISSs = C:\WINDOWS\SYSTEM32\DRIVERS\HPCISSS.SYS
hpn = C:\WINDOWS\SYSTEM32\DRIVERS\HPN.SYS
Hpt366 = C:\WINDOWS\SYSTEM32\DRIVERS\HPT366.SYS
HPT371 = C:\WINDOWS\SYSTEM32\DRIVERS\HPT371.SYS
hpt374 = C:\WINDOWS\SYSTEM32\DRIVERS\HPT374.SYS
hpt3xx = C:\WINDOWS\SYSTEM32\DRIVERS\HPT3XX.SYS
hptmv = C:\WINDOWS\SYSTEM32\DRIVERS\HPTMV.SYS
hptpro = C:\WINDOWS\SYSTEM32\DRIVERS\HPTPRO.SYS
HTTP = C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
i2omp = C:\WINDOWS\SYSTEM32\DRIVERS\I2OMP.SYS
i8042prt = C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
iaStor = C:\WINDOWS\SYSTEM32\DRIVERS\IASTOR.SYS
iirsp = C:\WINDOWS\SYSTEM32\DRIVERS\IIRSP.SYS
Imapi = C:\WINDOWS\SYSTEM32\DRIVERS\IMAPI.SYS
ini910u = C:\WINDOWS\SYSTEM32\DRIVERS\INI910U.SYS
IntelIde = C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
Ip6Fw = C:\WINDOWS\SYSTEM32\DRIVERS\IP6FW.SYS
IpFilterDriver = C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
IpInIp = C:\WINDOWS\SYSTEM32\DRIVERS\IPINIP.SYS
IpNat = C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
IPSec = C:\WINDOWS\SYSTEM32\DRIVERS\IPSEC.SYS
IRENUM = C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.