Activ 是一个驱动过滤器,实时监视活动的驱动,显示它安装的路径
Activ is a filter driver that allows monitoring of the runtime activity on a computer where it is installed. It can monitor in real-time:
- processes start/stop, reporting process name, ID and command line;
- loading of images (DLLs), reporting image name, process ID where this image is loaded into, image base address and size;
- Registry functions execution, reporting key and value names as well as status of the execution.