Logfile of random's system information tool 1.09 (written by random/random)
Run by sonny at 2012-06-19 18:33:52
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 38 GB (52%) free of 72 GB
Total RAM: 3992 MB (34% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:33:59, on 19.6.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16446)
Boot mode: Normal
Running processes:
C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
C:\Program Files (x86)\Digital Line Detect\DLG.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Program Files (x86)\Lenovo\Client Security Solution\password_manager.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Comodo\Dragon\dragon.exe
C:\Program Files (x86)\Comodo\Dragon\dragon.exe
C:\Program Files (x86)\Comodo\Dragon\dragon.exe
C:\Program Files (x86)\Comodo\Dragon\dragon.exe
C:\Program Files (x86)\Comodo\Dragon\dragon.exe
C:\Program Files (x86)\Comodo\Dragon\dragon.exe
C:\Program Files (x86)\Comodo\Dragon\dragon.exe
C:\Program Files (x86)\Comodo\Dragon\dragon.exe
C:\Program Files (x86)\Comodo\Dragon\dragon.exe
C:\Program Files (x86)\Comodo\Dragon\dragon.exe
C:\Program Files (x86)\Comodo\Dragon\dragon.exe
C:\Program Files (x86)\The KMPlayer\KMPlayer.exe
C:\Program Files (x86)\Comodo\Dragon\dragon.exe
C:\Program Files (x86)\Comodo\Dragon\dragon.exe
C:\Program Files\trend micro\sonny.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Web Assistant Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Password Manager Browser Helper Object - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RotateImage] C:\Program Files (x86)\RotateImage\RCIMGDIR.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Full glass.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files (x86)\Digital Line Detect\DLG.exe
O9 - Extra button: (no name) - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O9 - Extra 'Tools' menuitem: Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://fpdownload.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: AcPrfMgrSvc - Lenovo - C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
O23 - Service: AcSvc - Lenovo - C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
O23 - Service: AD Monitor (ADMonitor) - Unknown owner - C:\Windows\system32\ADMonitor.exe (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AuthenTec Fingerprint Service (ATService) - Unknown owner - C:\Windows\system32\ATService.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Lenovo Doze Mode Service (DozeSvc) - Lenovo. - C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Unknown owner - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
O23 - Service: Data Transfer Service (dtsvc) - Unknown owner - C:\Windows\system32\DTS.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cisco EnergyWise Enabler (PwmEWSvc) - Lenovo Group Limited - C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: TSS Core Service (TSSCoreService) - Lenovo - C:\Program Files (x86)\Lenovo\Client Security Solution\tvttcsd.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Web Assistant Updater - Unknown owner - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12256 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\DTS.exe
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\ATService.exe
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
winlogon.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\WLANExt.exe 27751184
\??\C:\Windows\system32\conhost.exe "17124734251833235611955288444-1215354927-793214436-1029436230-1379611205303780295
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe"
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k HsfXAudioService
"C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe"
"C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Lenovo\Client Security Solution\tvttcsd.exe"
"C:\Program Files\Web Assistant\ExtensionUpdaterService.exe"
"C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe"
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
atieclxx
"taskhost.exe"
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe"
"C:\Program Files\Lenovo\Zoom\TpScrex.exe"
"C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
"C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe"
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
"C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE"
"C:\Program Files (x86)\Digital Line Detect\DLG.exe"
"C:\Users\sonny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Full glass.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\RotateImage\RCIMGDIR.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Windows\system32\igfxext.exe -Embedding
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe" /IpNotifyInstance
"C:\Program Files\Lenovo\Client Security Solution\password_manager.exe"
"C:\Program Files (x86)\Lenovo\Client Security Solution\password_manager.exe"
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\Lenovo\System Update\SUService.exe"
"C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe"
"C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /startalways
"C:\Windows\system32\javaw.exe" -cp jts.jar;hsqldb.jar;jcommon-1.0.12.jar;jfreechart-1.0.9.jar;jhall.jar;other.jar;rss.jar -Dsun.java2d.noddraw=true -Xmx512M -XX:MaxPermSize=128M jclient/LoginFrame C:\Jts
"C:\Program Files (x86)\Comodo\Dragon\dragon.exe"
"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtest=ComodoDNSExperiment/inactive/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Hidden/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight8.0/OmniboxSearchSuggest/7/Prefetch/ContentPrefetchPrefetchOn/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --extension-process --channel="5972.1.2094461555\2032853866" /prefetch:3
"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtest=ComodoDNSExperiment/inactive/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Hidden/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight8.0/OmniboxSearchSuggest/7/Prefetch/ContentPrefetchPrefetchOn/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --extension-process --channel="5972.2.651241626\1026782026" /prefetch:3
"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtest=ComodoDNSExperiment/inactive/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Hidden/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight8.0/OmniboxSearchSuggest/7/Prefetch/ContentPrefetchPrefetchOn/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --extension-process --channel="5972.3.112199994\1429726795" /prefetch:3
"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtest=ComodoDNSExperiment/inactive/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Hidden/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight8.0/OmniboxSearchSuggest/7/Prefetch/ContentPrefetchPrefetchOn/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --extension-process --channel="5972.4.2013752836\1325494031" /prefetch:3
"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=gpu-process --channel="5972.5.734509501\9121957" --reduce-gpu-sandbox --disable-image-transport-surface /prefetch:12
"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=plugin --plugin-path="C:\Users\sonny\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.439_0\npbrowserext.dll" --lang=en-US --channel="5972.6.540322317\1221732970" /prefetch:4
"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtest=ComodoDNSExperiment/inactive/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Hidden/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight8.0/OmniboxSearchSuggest/7/Prefetch/ContentPrefetchPrefetchOn/Prerender/ContentPrefetchPrerender2/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --channel="5972.7.488747005\137719569" /prefetch:3
"taskhost.exe"
"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtest=ComodoDNSExperiment/inactive/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Hidden/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight8.0/OmniboxSearchSuggest/7/Prefetch/ContentPrefetchPrefetchOn/Prerender/ContentPrefetchPrerender2/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndDynamic/SpdyImpact/npn_with_spdy/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --channel="5972.11.608245652\907364956" /prefetch:3
"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtest=ComodoDNSExperiment/inactive/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Hidden/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight8.0/OmniboxSearchSuggest/7/Prefetch/ContentPrefetchPrefetchOn/Prerender/ContentPrefetchPrerender2/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndDynamic/SpdyImpact/npn_with_spdy/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --channel="5972.14.1294271963\1074995168" /prefetch:3
"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtest=ComodoDNSExperiment/inactive/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Hidden/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight8.0/OmniboxSearchSuggest/7/Prefetch/ContentPrefetchPrefetchOn/Prerender/ContentPrefetchPrerender2/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndDynamic/SpdyImpact/npn_with_spdy/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --channel="5972.15.1021633874\905853221" /prefetch:3
"C:\Program Files (x86)\The KMPlayer\KMPlayer.exe" -Embedding
"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtest=ComodoDNSExperiment/inactive/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Hidden/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight8.0/OmniboxSearchSuggest/7/Prefetch/ContentPrefetchPrefetchOn/Prerender/ContentPrefetchPrerender2/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndDynamic/SpdyImpact/npn_with_spdy/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --channel="5972.18.1220242562\1986986479" /prefetch:3
"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtest=ComodoDNSExperiment/inactive/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Hidden/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight8.0/OmniboxSearchSuggest/7/Prefetch/ContentPrefetchPrefetchOn/Prerender/ContentPrefetchPrerender2/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndDynamic/SpdyImpact/npn_with_spdy/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --channel="5972.19.618479798\532141369" /prefetch:3
"C:\Users\sonny\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
C:\Windows\tasks\SystemToolsDailyTest.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
Web Assistant - C:\Program Files\Web Assistant\Extension64.dll [2012-05-08 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-06-15 545192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-06-15 193456]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
Web Assistant - C:\Program Files\Web Assistant\Extension32.dll [2012-05-08 162816]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-05-04 453504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BF468356-BB7E-42D7-9F15-4F3B9BCFCED2}]
IePasswordManagerHelper Class - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll [2011-06-10 767288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-05-04 157576]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2012-03-11 9569096]
"cssauth"=C:\Program Files\Lenovo\Client Security Solution\cssauth.exe [2011-06-10 5990200]
"ResetACGauge"=C:\Program Files (x86)\Lenovo\Access Connections\smbhlpr.exe [2012-04-20 154688]
"AcWin7Hlpr"=C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe [2012-04-20 33344]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-03-15 499608]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-12-23 2868496]
"FingerPrintSoftware"=C:\Program Files\Lenovo Fingerprint Software\fpapp.exe [2010-02-05 1582400]
"FingerPrintSoftwareSplashScreen"=C:\Program Files\Lenovo Fingerprint Software\SplashScreen.exe [2010-02-05 107520]
"ATUpdatePBA.ltp"=C:\Windows\SysWOW64\ATUpdatePBA.exe [2010-02-05 226624]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-10-14 162584]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-10-14 386840]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-10-14 417560]
"LENOVO.TPKNRRES"=C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [2010-07-27 62312]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2012-06-15 4786048]
"AdobeBridge"= []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"PWMTRV"=rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor []
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5.5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [2011-01-12 1523360]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-11-27 98304]
"RotateImage"=C:\Program Files (x86)\RotateImage\RCIMGDIR.exe [2008-10-30 55808]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]
"Malwarebytes' Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2012-04-04 462408]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2012-04-04 462408]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Digital Line Detect.lnk - C:\Program Files (x86)\Digital Line Detect\DLG.exe
C:\Users\sonny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Full glass.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard64.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ATFUS]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-10-13 272896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
ACGina
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableCAD"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"DisallowCpl"=1
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-06-19 18:33:52 ----D---- C:\rsit
2012-06-19 18:33:52 ----D---- C:\Program Files\trend micro
2012-06-19 15:09:02 ----D---- C:\Users\sonny\AppData\Roaming\Malwarebytes
2012-06-19 15:08:59 ----D---- C:\ProgramData\Malwarebytes
2012-06-19 15:08:58 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-19 15:08:58 ----A---- C:\Windows\system32\drivers\mbam.sys
2012-06-19 14:57:47 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2012-06-19 14:57:47 ----A---- C:\Windows\system32\FntCache.dll
2012-06-19 14:57:47 ----A---- C:\Windows\system32\d2d1.dll
2012-06-19 14:13:04 ----D---- C:\sh4ldr
2012-06-19 14:13:04 ----D---- C:\Program Files\Enigma Software Group
2012-06-19 14:12:17 ----D---- C:\Windows\18F97AF04F884494AFE25A5702E142CC.TMP
2012-06-19 03:10:45 ----A---- C:\Windows\system32\wups2.dll
2012-06-19 03:10:45 ----A---- C:\Windows\system32\wucltux.dll
2012-06-19 03:10:45 ----A---- C:\Windows\system32\wuauclt.exe
2012-06-19 03:10:44 ----A---- C:\Windows\system32\wuaueng.dll
2012-06-19 03:10:40 ----A---- C:\Windows\system32\wups.dll
2012-06-19 03:10:40 ----A---- C:\Windows\system32\wudriver.dll
2012-06-19 03:10:40 ----A---- C:\Windows\system32\wuapi.dll
2012-06-19 03:10:37 ----A---- C:\Windows\system32\wuwebv.dll
2012-06-19 03:10:37 ----A---- C:\Windows\system32\wuapp.exe
2012-06-17 09:06:00 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2012-06-17 09:03:06 ----D---- C:\Program Files (x86)\Microsoft.NET
2012-06-17 08:47:26 ----D---- C:\Program Files (x86)\MSXML 4.0
2012-06-17 08:46:50 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2012-06-17 08:46:50 ----A---- C:\Windows\system32\qdvd.dll
2012-06-16 18:55:29 ----N---- C:\Windows\SYSWOW64\vxblock.dll
2012-06-16 18:55:29 ----N---- C:\Windows\SYSWOW64\pxwave.dll
2012-06-16 18:55:29 ----N---- C:\Windows\SYSWOW64\pxsfs.dll
2012-06-16 18:55:29 ----N---- C:\Windows\SYSWOW64\pxmas.dll
2012-06-16 18:55:29 ----N---- C:\Windows\SYSWOW64\pxinsi64.exe
2012-06-16 18:55:29 ----N---- C:\Windows\SYSWOW64\pxinsa64.exe
2012-06-16 18:55:29 ----N---- C:\Windows\SYSWOW64\pxhpinst.exe
2012-06-16 18:55:29 ----N---- C:\Windows\SYSWOW64\pxdrv.dll
2012-06-16 18:55:29 ----N---- C:\Windows\SYSWOW64\pxcpyi64.exe
2012-06-16 18:55:29 ----N---- C:\Windows\SYSWOW64\pxcpya64.exe
2012-06-16 18:55:29 ----N---- C:\Windows\SYSWOW64\pxafs.dll
2012-06-16 18:55:29 ----N---- C:\Windows\SYSWOW64\px.dll
2012-06-16 17:35:26 ----D---- C:\Users\sonny\AppData\Roaming\VitySoft
2012-06-16 11:23:54 ----D---- C:\ProgramData\Conexant
2012-06-16 11:15:57 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2012-06-16 11:15:57 ----A---- C:\Windows\system32\drivers\bthport.sys
2012-06-16 11:15:54 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2012-06-16 11:15:54 ----A---- C:\Windows\SYSWOW64\esent.dll
2012-06-16 11:15:54 ----A---- C:\Windows\system32\fsutil.exe
2012-06-16 11:15:54 ----A---- C:\Windows\system32\esent.dll
2012-06-16 11:15:54 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2012-06-16 11:15:54 ----A---- C:\Windows\system32\drivers\storport.sys
2012-06-16 11:15:54 ----A---- C:\Windows\system32\drivers\nvstor.sys
2012-06-16 11:15:54 ----A---- C:\Windows\system32\drivers\nvraid.sys
2012-06-16 11:15:54 ----A---- C:\Windows\system32\drivers\ntfs.sys
2012-06-16 11:15:54 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2012-06-16 11:15:54 ----A---- C:\Windows\system32\drivers\amdxata.sys
2012-06-16 11:15:54 ----A---- C:\Windows\system32\drivers\amdsata.sys
2012-06-16 08:05:28 ----D---- C:\Users\sonny\AppData\Roaming\FontCreator
2012-06-16 07:56:12 ----D---- C:\Program Files\Theme Resource Changer
2012-06-16 07:39:54 ----D---- C:\Program Files\Recuva
2012-06-16 07:18:18 ----D---- C:\Users\sonny\AppData\Roaming\LibreOffice
2012-06-16 07:17:16 ----D---- C:\ProgramData\Premium
2012-06-16 07:16:57 ----D---- C:\Program Files\Web Assistant
2012-06-16 07:16:34 ----D---- C:\ProgramData\InstallMate
2012-06-16 07:04:28 ----D---- C:\Users\sonny\AppData\Roaming\AIMP3
2012-06-16 07:04:26 ----D---- C:\Program Files (x86)\AIMP3
2012-06-16 06:42:31 ----D---- C:\Program Files (x86)\Fried Cookie
2012-06-16 02:13:39 ----D---- C:\Windows\Panther
2012-06-15 22:22:18 ----D---- C:\Windows\SYSWOW64\Wat
2012-06-15 22:22:18 ----D---- C:\Windows\system32\Wat
2012-06-15 22:20:45 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-06-15 22:20:42 ----D---- C:\Windows\system32\Macromed
2012-06-15 22:15:16 ----D---- C:\Program Files\7-Zip
2012-06-15 22:09:25 ----A---- C:\Windows\system32\MRT.exe
2012-06-15 22:02:37 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2012-06-15 22:02:37 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2012-06-15 22:02:37 ----A---- C:\Windows\system32\imagehlp.dll
2012-06-15 22:02:37 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2012-06-15 22:02:36 ----A---- C:\Windows\SYSWOW64\wmi.dll
2012-06-15 22:02:36 ----A---- C:\Windows\system32\wmi.dll
2012-06-15 22:02:36 ----A---- C:\Windows\system32\wintrust.dll
2012-06-15 21:35:50 ----A---- C:\Windows\ib.ini
2012-06-15 21:35:48 ----A---- C:\Windows\GetIe.dll
2012-06-15 21:35:43 ----D---- C:\Jts
2012-06-15 21:34:55 ----D---- C:\ProgramData\Sun
2012-06-15 21:34:14 ----D---- C:\Program Files (x86)\Oracle
2012-06-15 21:33:19 ----A---- C:\Windows\SYSWOW64\npDeployJava1.dll
2012-06-15 21:33:19 ----A---- C:\Windows\SYSWOW64\javaws.exe
2012-06-15 21:33:19 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2012-06-15 21:33:07 ----A---- C:\Windows\SYSWOW64\javaw.exe
2012-06-15 21:33:07 ----A---- C:\Windows\SYSWOW64\java.exe
2012-06-15 21:32:59 ----D---- C:\Program Files (x86)\Java
2012-06-15 19:53:14 ----D---- C:\Users\sonny\AppData\Roaming\PwrMgr
2012-06-15 19:53:04 ----A---- C:\Windows\system32\drivers\ndis.sys
2012-06-15 19:51:51 ----D---- C:\Users\sonny\AppData\Roaming\ATI
2012-06-15 19:51:51 ----D---- C:\ProgramData\ATI
2012-06-15 19:45:18 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2012-06-15 19:45:18 ----A---- C:\Windows\system32\drivers\usbport.sys
2012-06-15 19:45:18 ----A---- C:\Windows\system32\drivers\usbohci.sys
2012-06-15 19:45:18 ----A---- C:\Windows\system32\drivers\usbehci.sys
2012-06-15 19:45:18 ----A---- C:\Windows\system32\drivers\usbd.sys
2012-06-15 19:45:18 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2012-06-15 19:45:17 ----A---- C:\Windows\system32\drivers\usbhub.sys
2012-06-15 19:43:00 ----D---- C:\Program Files (x86)\ThinkVantage
2012-06-15 19:41:36 ----D---- C:\Windows\SYSWOW64\x64
2012-06-15 19:41:36 ----D---- C:\Windows\SYSWOW64\Lang
2012-06-15 19:41:36 ----D---- C:\Program Files (x86)\Intel
2012-06-15 19:41:35 ----A---- C:\Windows\SYSWOW64\heciudlg.exe
2012-06-15 19:41:34 ----A---- C:\Windows\system32\drivers\HECIx64.sys
2012-06-15 19:40:23 ----A---- C:\Windows\system32\UCI64A42.dll
2012-06-15 19:40:22 ----A---- C:\Windows\system32\drivers\CHDRT64.sys
2012-06-15 19:40:22 ----A---- C:\Windows\system32\CX64TP17.dll
2012-06-15 19:39:29 ----A---- C:\Windows\system32\SynTPCo4.dll
2012-06-15 19:39:28 ----A---- C:\Windows\system32\SynCOM.dll
2012-06-15 19:32:24 ----A---- C:\Windows\system32\drivers\smiifx64.sys
2012-06-15 19:31:52 ----D---- C:\Program Files (x86)\RotateImage
2012-06-15 19:31:52 ----D---- C:\Program Files (x86)\Integrated Camera Driver
2012-06-15 19:31:51 ----A---- C:\Windows\system32\RCUVCMNP.dll
2012-06-15 19:31:51 ----A---- C:\Windows\system32\drivers\RCUVCMNP.sys
2012-06-15 19:30:45 ----A---- C:\Windows\SYSWOW64\atipblup.dat
2012-06-15 19:30:45 ----A---- C:\Windows\system32\atipblup.dat
2012-06-15 19:29:07 ----D---- C:\Program Files\ATI
2012-06-15 19:29:04 ----D---- C:\Program Files (x86)\ATI Technologies
2012-06-15 19:28:44 ----A---- C:\Windows\SYSWOW64\iglhsip32.dll
2012-06-15 19:28:44 ----A---- C:\Windows\SYSWOW64\iglhcp32.dll
2012-06-15 19:28:44 ----A---- C:\Windows\system32\iglhsip64.dll
2012-06-15 19:28:44 ----A---- C:\Windows\system32\iglhcp64.dll
2012-06-15 19:28:43 ----A---- C:\Windows\SYSWOW64\igfxexps32.dll
2012-06-15 19:28:43 ----A---- C:\Windows\SYSWOW64\igfxdv32.dll
2012-06-15 19:28:43 ----A---- C:\Windows\SYSWOW64\igdumdx32.dll
2012-06-15 19:28:43 ----A---- C:\Windows\system32\igfxtray.exe
2012-06-15 19:28:43 ----A---- C:\Windows\system32\igfxTMM.dll
2012-06-15 19:28:43 ----A---- C:\Windows\system32\igfxsrvc.exe
2012-06-15 19:28:43 ----A---- C:\Windows\system32\igfxsrvc.dll
2012-06-15 19:28:43 ----A---- C:\Windows\system32\igfxress.dll
2012-06-15 19:28:43 ----A---- C:\Windows\system32\igfxpph.dll
2012-06-15 19:28:43 ----A---- C:\Windows\system32\igfxpers.exe
2012-06-15 19:28:43 ----A---- C:\Windows\system32\igfxext.exe
2012-06-15 19:28:43 ----A---- C:\Windows\system32\igfxexps.dll
2012-06-15 19:28:43 ----A---- C:\Windows\system32\igfxdo.dll
2012-06-15 19:28:43 ----A---- C:\Windows\system32\IGFXDEVLib.dll
2012-06-15 19:28:43 ----A---- C:\Windows\system32\igfxdev.dll
2012-06-15 19:28:42 ----A---- C:\Windows\SYSWOW64\igd10umd32.dll
2012-06-15 19:28:42 ----A---- C:\Windows\system32\drivers\igdpmd64.sys
2012-06-15 19:28:42 ----A---- C:\Windows\system32\drivers\igdkmd64.sys
2012-06-15 19:28:41 ----A---- C:\Windows\SYSWOW64\ig4icd32.dll
2012-06-15 19:28:41 ----A---- C:\Windows\system32\ig4icd64.dll
2012-06-15 19:28:41 ----A---- C:\Windows\system32\hkcmd.exe
2012-06-15 19:28:41 ----A---- C:\Windows\system32\hccutils.dll
2012-06-15 19:28:41 ----A---- C:\Windows\system32\GfxUI.exe
2012-06-15 19:28:41 ----A---- C:\Windows\system32\gfxSrvc.dll
2012-06-15 19:28:41 ----A---- C:\Windows\system32\difx64.exe
2012-06-15 19:28:40 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2012-06-15 19:28:40 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2012-06-15 19:28:40 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2012-06-15 19:28:40 ----A---- C:\Windows\system32\coinst.dll
2012-06-15 19:28:40 ----A---- C:\Windows\system32\atiuxp64.dll
2012-06-15 19:28:40 ----A---- C:\Windows\system32\atiumd6a.dll
2012-06-15 19:28:39 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2012-06-15 19:28:39 ----A---- C:\Windows\SYSWOW64\atipdlxx.dll
2012-06-15 19:28:39 ----A---- C:\Windows\SYSWOW64\atipblag.dat
2012-06-15 19:28:39 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2012-06-15 19:28:39 ----A---- C:\Windows\system32\atiumd64.dll
2012-06-15 19:28:39 ----A---- C:\Windows\system32\atiu9p64.dll
2012-06-15 19:28:39 ----A---- C:\Windows\system32\atitmm64.dll
2012-06-15 19:28:39 ----A---- C:\Windows\system32\atipdl64.dll
2012-06-15 19:28:39 ----A---- C:\Windows\system32\atipblag.dat
2012-06-15 19:28:37 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2012-06-15 19:28:37 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2012-06-15 19:28:37 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2012-06-15 19:28:37 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2012-06-15 19:28:37 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2012-06-15 19:28:37 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2012-06-15 19:28:37 ----A---- C:\Windows\system32\atio6axx.dll
2012-06-15 19:28:37 ----A---- C:\Windows\system32\atimuixx.dll
2012-06-15 19:28:37 ----A---- C:\Windows\system32\atimpc64.dll
2012-06-15 19:28:37 ----A---- C:\Windows\system32\atiicdxx.dat
2012-06-15 19:28:37 ----A---- C:\Windows\system32\atig6txx.dll
2012-06-15 19:28:37 ----A---- C:\Windows\system32\atig6pxx.dll
2012-06-15 19:28:37 ----A---- C:\Windows\system32\atiesrxx.exe
2012-06-15 19:28:37 ----A---- C:\Windows\system32\atiedu64.dll
2012-06-15 19:28:37 ----A---- C:\Windows\system32\atieclxx.exe
2012-06-15 19:28:37 ----A---- C:\Windows\system32\atidxx64.dll
2012-06-15 19:28:37 ----A---- C:\Windows\system32\amdpcom64.dll
2012-06-15 19:28:36 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2012-06-15 19:28:36 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2012-06-15 19:28:36 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2012-06-15 19:28:36 ----A---- C:\Windows\system32\ATIDEMGX.dll
2012-06-15 19:28:36 ----A---- C:\Windows\system32\aticfx64.dll
2012-06-15 19:28:36 ----A---- C:\Windows\system32\aticalrt64.dll
2012-06-15 19:28:36 ----A---- C:\Windows\system32\aticaldd64.dll
2012-06-15 19:28:35 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2012-06-15 19:28:35 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2012-06-15 19:28:35 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2012-06-15 19:28:35 ----A---- C:\Windows\SYSWOW64\ati2edxx.dll
2012-06-15 19:28:35 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2012-06-15 19:28:35 ----A---- C:\Windows\system32\aticalcl64.dll
2012-06-15 19:28:35 ----A---- C:\Windows\system32\atibtmon.exe
2012-06-15 19:28:35 ----A---- C:\Windows\system32\atiapfxx.exe
2012-06-15 19:28:35 ----A---- C:\Windows\system32\atiadlxx.dll
2012-06-15 19:27:56 ----D---- C:\Program Files\DIFX
2012-06-15 19:27:42 ----D---- C:\Program Files\Lenovo Fingerprint Software
2012-06-15 19:27:23 ----D---- C:\Users\sonny\AppData\Roaming\CachedFiles
2012-06-15 19:27:04 ----D---- C:\Program Files\ThinkPad
2012-06-15 19:25:43 ----D---- C:\Program Files (x86)\Digital Line Detect
2012-06-15 19:24:41 ----D---- C:\Program Files (x86)\NetWaiting
2012-06-15 19:24:40 ----D---- C:\Users\sonny\AppData\Roaming\InstallShield
2012-06-15 19:24:25 ----D---- C:\Program Files\CONEXANT
2012-06-15 19:24:11 ----A---- C:\Windows\SYSWOW64\XAudio64.dll
2012-06-15 19:24:11 ----A---- C:\Windows\SYSWOW64\mdmxsdk.dll
2012-06-15 19:24:11 ----A---- C:\Windows\system32\UCI64M41.dll
2012-06-15 19:24:11 ----A---- C:\Windows\system32\drivers\XAudio64.sys
2012-06-15 19:24:11 ----A---- C:\Windows\system32\drivers\mdmxsdk.sys
2012-06-15 19:24:11 ----A---- C:\Windows\system32\drivers\CAXHWAZL.sys
2012-06-15 19:24:11 ----A---- C:\Windows\system32\drivers\CAX_DPV.sys
2012-06-15 19:24:11 ----A---- C:\Windows\system32\drivers\CAX_CNXT.sys
2012-06-15 19:24:02 ----A---- C:\Windows\system32\PROUnstl.exe
2012-06-15 19:23:45 ----A---- C:\Windows\system32\NicInstY.dll
2012-06-15 19:23:45 ----A---- C:\Windows\system32\NicCo36.dll
2012-06-15 19:23:45 ----A---- C:\Windows\system32\e1000msg.dll
2012-06-15 19:23:45 ----A---- C:\Windows\system32\drivers\e1y62x64.sys
2012-06-15 19:23:27 ----A---- C:\Windows\system32\drivers\iaStor.sys
2012-06-15 19:23:03 ----A---- C:\Windows\system32\snymsico.dll
2012-06-15 19:23:03 ----A---- C:\Windows\system32\rixdicon.dll
2012-06-15 19:23:03 ----A---- C:\Windows\system32\drivers\rixdpx64.sys
2012-06-15 19:23:03 ----A---- C:\Windows\system32\drivers\rimspx64.sys
2012-06-15 19:23:03 ----A---- C:\Windows\system32\drivers\rimmpx64.sys
2012-06-15 19:22:31 ----D---- C:\Users\sonny\AppData\Roaming\Intel
2012-06-15 19:22:22 ----D---- C:\ProgramData\Roaming
2012-06-15 19:21:32 ----D---- C:\ProgramData\Intel
2012-06-15 19:21:32 ----D---- C:\Program Files\Intel
2012-06-15 19:21:32 ----D---- C:\Program Files\Common Files\Intel
2012-06-15 19:21:32 ----D---- C:\Program Files (x86)\Cisco
2012-06-15 19:20:32 ----D---- C:\Program Files\Synaptics
2012-06-15 19:20:06 ----A---- C:\Windows\system32\WdfCoInstaller01009.dll
2012-06-15 19:20:05 ----A---- C:\Windows\SYSWOW64\SynTPEnhPS.dll
2012-06-15 19:20:05 ----A---- C:\Windows\SYSWOW64\SynTPCOM.dll
2012-06-15 19:20:05 ----A---- C:\Windows\SYSWOW64\SynCtrl.dll
2012-06-15 19:20:05 ----A---- C:\Windows\SYSWOW64\SynCOM.dll
2012-06-15 19:20:05 ----A---- C:\Windows\system32\SynTPCo9.dll
2012-06-15 19:20:05 ----A---- C:\Windows\system32\SynTPAPI.dll
2012-06-15 19:20:05 ----A---- C:\Windows\system32\SynCtrl.dll
2012-06-15 19:20:05 ----A---- C:\Windows\system32\drivers\SynTP.sys
2012-06-15 19:17:58 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2012-06-15 19:15:00 ----D---- C:\Program Files\Adobe
2012-06-15 19:14:41 ----D---- C:\Program Files\Common Files\Adobe
2012-06-15 19:11:57 ----D---- C:\Windows\SYSWOW64\Macromed
2012-06-15 19:07:39 ----D---- C:\Users\sonny\AppData\Roaming\Macromedia
2012-06-15 18:52:52 ----D---- C:\Users\sonny\AppData\Roaming\TrueCrypt
2012-06-15 18:49:01 ----D---- C:\ProgramData\PC-Doctor for Windows
2012-06-15 18:47:31 ----D---- C:\Users\sonny\AppData\Roaming\PCDr
2012-06-15 18:40:58 ----D---- C:\Users\sonny\AppData\Roaming\Skype
2012-06-15 18:40:53 ----RD---- C:\Program Files (x86)\Skype
2012-06-15 18:40:48 ----D---- C:\ProgramData\Skype
2012-06-15 18:30:35 ----A---- C:\Windows\system32\npDeployJava1.dll
2012-06-15 18:30:35 ----A---- C:\Windows\system32\javaws.exe
2012-06-15 18:30:35 ----A---- C:\Windows\system32\deployJava1.dll
2012-06-15 18:30:23 ----A---- C:\Windows\system32\javaw.exe
2012-06-15 18:30:23 ----A---- C:\Windows\system32\java.exe
2012-06-15 18:30:14 ----D---- C:\Program Files\Java
2012-06-15 18:27:18 ----D---- C:\Program Files (x86)\The KMPlayer
2012-06-15 18:23:08 ----D---- C:\Users\sonny\AppData\Roaming\Update
2012-06-15 18:06:48 ----D---- C:\Users\sonny\AppData\Roaming\Lenovo
2012-06-15 17:59:53 ----D---- C:\Program Files\Lenovo
2012-06-15 17:58:47 ----D---- C:\Windows\Downloaded Installations
2012-06-15 17:57:21 ----D---- C:\ProgramData\Lenovo
2012-06-15 17:57:20 ----D---- C:\Program Files\Common Files\Lenovo
2012-06-15 17:54:18 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2012-06-15 17:54:18 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-06-15 17:54:17 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2012-06-15 17:53:16 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2012-06-15 17:53:16 ----A---- C:\Windows\system32\CPFilters.dll
2012-06-15 17:53:15 ----A---- C:\Windows\SYSWOW64\sbe.dll
2012-06-15 17:53:15 ----A---- C:\Windows\system32\sbe.dll
2012-06-15 17:53:02 ----A---- C:\Windows\system32\tquery.dll
2012-06-15 17:53:02 ----A---- C:\Windows\system32\mssrch.dll
2012-06-15 17:53:01 ----A---- C:\Windows\SYSWOW64\tquery.dll
2012-06-15 17:53:01 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2012-06-15 17:53:01 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2012-06-15 17:53:01 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2012-06-15 17:53:01 ----A---- C:\Windows\system32\SearchIndexer.exe
2012-06-15 17:53:00 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2012-06-15 17:53:00 ----A---- C:\Windows\SYSWOW64\mssph.dll
2012-06-15 17:53:00 ----A---- C:\Windows\system32\SearchFilterHost.exe
2012-06-15 17:53:00 ----A---- C:\Windows\system32\mssvp.dll
2012-06-15 17:53:00 ----A---- C:\Windows\system32\mssphtb.dll
2012-06-15 17:53:00 ----A---- C:\Windows\system32\mssph.dll
2012-06-15 17:52:59 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2012-06-15 17:52:58 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2012-06-15 17:52:58 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2012-06-15 17:52:58 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2012-06-15 17:52:58 ----A---- C:\Windows\system32\msscntrs.dll
2012-06-15 17:52:46 ----N---- C:\Windows\PWMBTHLV.EXE
2012-06-15 17:52:39 ----A---- C:\Windows\system32\shell32.dll
2012-06-15 17:52:36 ----D---- C:\Program Files (x86)\ThinkPad
2012-06-15 17:52:36 ----A---- C:\Windows\SYSWOW64\shell32.dll
2012-06-15 17:52:35 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2012-06-15 17:52:35 ----A---- C:\Windows\system32\ntshrui.dll
2012-06-15 17:52:34 ----A---- C:\Windows\system32\drivers\TPPWR64V.SYS
2012-06-15 17:52:34 ----A---- C:\Windows\system32\drivers\DZHDD64.SYS
2012-06-15 17:52:19 ----A---- C:\Windows\system32\poqexec.exe
2012-06-15 17:52:18 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2012-06-15 17:52:15 ----A---- C:\Windows\system32\mfc42u.dll
2012-06-15 17:52:15 ----A---- C:\Windows\system32\mfc42.dll
2012-06-15 17:52:14 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2012-06-15 17:52:14 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2012-06-15 17:52:09 ----A---- C:\Windows\SYSWOW64\webio.dll
2012-06-15 17:52:09 ----A---- C:\Windows\SYSWOW64\schannel.dll
2012-06-15 17:52:09 ----A---- C:\Windows\system32\schannel.dll
2012-06-15 17:52:09 ----A---- C:\Windows\system32\lsass.exe
2012-06-15 17:52:09 ----A---- C:\Windows\system32\lsasrv.dll
2012-06-15 17:52:09 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-06-15 17:52:09 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-06-15 17:52:09 ----A---- C:\Windows\system32\drivers\cng.sys
2012-06-15 17:52:08 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2012-06-15 17:52:08 ----A---- C:\Windows\SYSWOW64\secur32.dll
2012-06-15 17:52:08 ----A---- C:\Windows\system32\webio.dll
2012-06-15 17:52:08 ----A---- C:\Windows\system32\sspisrv.dll
2012-06-15 17:52:08 ----A---- C:\Windows\system32\sspicli.dll
2012-06-15 17:52:08 ----A---- C:\Windows\system32\secur32.dll
2012-06-15 17:52:03 ----A---- C:\Windows\SYSWOW64\msi.dll
2012-06-15 17:52:03 ----A---- C:\Windows\system32\msi.dll
2012-06-15 17:52:00 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2012-06-15 17:52:00 ----A---- C:\Windows\system32\kerberos.dll
2012-06-15 17:51:42 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2012-06-15 17:51:42 ----A---- C:\Windows\system32\crypt32.dll
2012-06-15 17:51:41 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2012-06-15 17:51:41 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2012-06-15 17:51:41 ----A---- C:\Windows\system32\cryptsvc.dll
2012-06-15 17:51:41 ----A---- C:\Windows\system32\cryptnet.dll
2012-06-15 17:50:18 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-06-15 17:49:44 ----A---- C:\Windows\system32\quartz.dll
2012-06-15 17:49:43 ----A---- C:\Windows\SYSWOW64\quartz.dll
2012-06-15 17:49:37 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2012-06-15 17:49:37 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2012-06-15 17:49:34 ----A---- C:\Windows\system32\profsvc.dll
2012-06-15 17:49:30 ----A---- C:\Windows\system32\dnsapi.dll
2012-06-15 17:49:29 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2012-06-15 17:49:29 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2012-06-15 17:49:29 ----A---- C:\Windows\system32\dnsrslvr.dll
2012-06-15 17:49:29 ----A---- C:\Windows\system32\dnscacheugc.exe
2012-06-15 17:49:24 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2012-06-15 17:49:24 ----A---- C:\Windows\system32\xmllite.dll
2012-06-15 17:49:24 ----A---- C:\Windows\system32\tpinspm.dll
2012-06-15 17:49:24 ----A---- C:\Windows\system32\ibmpmsvc.exe
2012-06-15 17:49:24 ----A---- C:\Windows\system32\drivers\ibmpmdrv.sys
2012-06-15 17:49:18 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-06-15 17:49:18 ----A---- C:\Windows\system32\rdpwsx.dll
2012-06-15 17:49:18 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-06-15 17:48:20 ----A---- C:\Windows\system32\inetcomm.dll
2012-06-15 17:48:19 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2012-06-15 17:48:15 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2012-06-15 17:48:15 ----A---- C:\Windows\system32\msvcrt.dll
2012-06-15 17:47:52 ----A---- C:\Windows\system32\drivers\bowser.sys
2012-06-15 17:47:44 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2012-06-15 17:47:44 ----A---- C:\Windows\system32\oleaut32.dll
2012-06-15 17:47:44 ----A---- C:\Windows\system32\oleacc.dll
2012-06-15 17:47:43 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2012-06-15 17:47:33 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2012-06-15 17:47:33 ----A---- C:\Windows\system32\EncDec.dll
2012-06-15 17:47:29 ----D---- C:\Program Files (x86)\Lenovo
2012-06-15 17:46:57 ----A---- C:\Windows\SYSWOW64\tzres.dll
2012-06-15 17:46:57 ----A---- C:\Windows\system32\tzres.dll
2012-06-15 17:45:40 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-06-15 17:45:40 ----A---- C:\Windows\system32\drivers\psadd.sys
2012-06-15 17:45:10 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2012-06-15 17:45:10 ----A---- C:\Windows\system32\ntdll.dll
2012-06-15 17:44:29 ----A---- C:\Windows\system32\odbccu32.dll
2012-06-15 17:44:29 ----A---- C:\Windows\system32\odbccr32.dll
2012-06-15 17:44:29 ----A---- C:\Windows\system32\odbccp32.dll
2012-06-15 17:44:28 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2012-06-15 17:44:28 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2012-06-15 17:44:28 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2012-06-15 17:44:28 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2012-06-15 17:44:28 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2012-06-15 17:44:28 ----A---- C:\Windows\system32\odbctrac.dll
2012-06-15 17:44:18 ----A---- C:\Windows\explorer.exe
2012-06-15 17:44:17 ----A---- C:\Windows\SYSWOW64\explorer.exe
2012-06-15 17:44:13 ----A---- C:\Windows\system32\DWrite.dll
2012-06-15 17:44:12 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2012-06-15 17:43:29 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2012-06-15 17:43:29 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2012-06-15 17:43:29 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2012-06-15 17:41:32 ----A---- C:\Windows\system32\csrsrv.dll
2012-06-15 17:41:27 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2012-06-15 17:41:12 ----A---- C:\Windows\system32\drivers\afd.sys
2012-06-15 17:40:55 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2012-06-15 17:40:55 ----A---- C:\Windows\system32\XpsPrint.dll
2012-06-15 17:40:48 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2012-06-15 17:40:48 ----A---- C:\Windows\system32\atmfd.dll
2012-06-15 17:40:47 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2012-06-15 17:40:47 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2012-06-15 17:40:47 ----A---- C:\Windows\system32\fontsub.dll
2012-06-15 17:40:47 ----A---- C:\Windows\system32\atmlib.dll
2012-06-15 17:39:48 ----A---- C:\Windows\system32\win32k.sys
2012-06-15 17:39:45 ----A---- C:\Windows\system32\d3d10_1.dll
2012-06-15 17:39:44 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2012-06-15 17:39:43 ----A---- C:\Windows\system32\psisdecd.dll
2012-06-15 17:39:42 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2012-06-15 17:39:38 ----A---- C:\Windows\system32\drivers\srvnet.sys
2012-06-15 17:39:38 ----A---- C:\Windows\system32\drivers\srv2.sys
2012-06-15 17:39:38 ----A---- C:\Windows\system32\drivers\srv.sys
2012-06-15 17:39:33 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2012-06-15 17:38:32 ----A---- C:\Windows\system32\winresume.exe
2012-06-15 17:38:32 ----A---- C:\Windows\system32\winload.exe
2012-06-15 17:38:32 ----A---- C:\Windows\system32\kdusb.dll
2012-06-15 17:38:32 ----A---- C:\Windows\system32\kdcom.dll
2012-06-15 17:38:32 ----A---- C:\Windows\system32\kd1394.dll
2012-06-15 17:38:25 ----A---- C:\Windows\system32\drivers\partmgr.sys
2012-06-15 17:37:59 ----A---- C:\Windows\system32\FXSCOVER.exe
2012-06-15 17:37:41 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2012-06-15 17:37:41 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2012-06-15 17:37:41 ----A---- C:\Windows\SYSWOW64\devobj.dll
2012-06-15 17:37:41 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2012-06-15 17:37:41 ----A---- C:\Windows\system32\umpnpmgr.dll
2012-06-15 17:37:37 ----A---- C:\Windows\system32\KernelBase.dll
2012-06-15 17:37:37 ----A---- C:\Windows\system32\kernel32.dll
2012-06-15 17:37:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-06-15 17:37:36 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-06-15 17:37:36 ----A---- C:\Windows\SYSWOW64\wow32.dll
2012-06-15 17:37:36 ----A---- C:\Windows\SYSWOW64\setup16.exe
2012-06-15 17:37:36 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2012-06-15 17:37:36 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2012-06-15 17:37:36 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2012-06-15 17:37:36 ----A---- C:\Windows\SYSWOW64\instnm.exe
2012-06-15 17:37:36 ----A---- C:\Windows\system32\wow64win.dll
2012-06-15 17:37:36 ----A---- C:\Windows\system32\wow64cpu.dll
2012-06-15 17:37:36 ----A---- C:\Windows\system32\wow64.dll
2012-06-15 17:37:36 ----A---- C:\Windows\system32\winsrv.dll
2012-06-15 17:37:36 ----A---- C:\Windows\system32\ntvdm64.dll
2012-06-15 17:37:36 ----A---- C:\Windows\system32\conhost.exe
2012-06-15 17:37:35 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-