Lately I had an idea to simply detect loaded kernel drivers which hide their presence after their execution. I'm sure this method is already known/used but because I never read of it I decided to write it down.
You have to reboot your box and start the system with enabled boot logging - hit F8 before Windoze boot screen and select the entry "
Enable Boot Logging". Another possibilty to boot with enabled logging is to hand the
/BOOTLOG option to the Windoze kernel as a parameter by editing the `boot.ini' file.