prosím o kontrolu logu
Napsal: 11 črc 2012 18:51
Dobrý den, prosím o kontrolu. Počítač je poslední dobou dost pomalý, pokud nenajdete v logu zlý a zákeřný zpomalovač, poraďte mi prosím vhodný program, který je spuštěný zbytečně a kterého se můžu zbavit.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Tom at 2012-07-11 19:39:29
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 4 GB (12%) free of 31 GB
Total RAM: 2006 MB (29% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:39:44, on 11.7.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Tom.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Tom\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {816BE035-1450-40D0-8A3B-BA7825A83A77} (IASRunner Class) - http://support.lenovo.com/Resources/Len ... etect2.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Unknown owner - C:\Windows\system32\AEADISRV.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Lenovo Doze Mode Service (DozeSvc) - Lenovo. - C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cisco EnergyWise Enabler (PwmEWSvc) - Lenovo Group Limited - C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)
--
End of file - 10508 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-aa08c705-162c-47d8-8d2e-f3df9db8519e -SystemEventPortName:HostProcess-99806327-6db9-49c8-aa87-94c4cc146d78 -IoCancelEventPortName:HostProcess-e2f14876-5474-410a-9354-2d8a13d2037f -NonStateChangingEventPortName:HostProcess-2f067386-8de5-4d5e-b3ba-89e43efc1fa4 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:7a7e2440-00f1-4c50-a440-c74a1643706f
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\WLANExt.exe 24685744
\??\C:\Windows\system32\conhost.exe "2026204343-1582324584656782472616727084-649726411137039322447095992-1457329553
"C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\AEADISRV.EXE
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\DRIVERS\xaudio64.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"taskhost.exe"
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe"
"C:\Program Files\Lenovo\Zoom\TpScrex.exe"
C:\Windows\system32\igfxext.exe -Embedding
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\TpShocks.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe"
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe"
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Windows\system32\igfxext.exe -Embedding
"C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE"
"C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe" -CtxID "#Hewlett-Packard#hp psc 1310 series#1338998168" -Startup
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe" -Embedding
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe" -Embedding
"C:\Program Files (x86)\Lenovo\System Update\SUService.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"taskhost.exe"
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --extension-process --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.0.1299991171\647181662" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --extension-process --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.2.1838172971\724005046" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.3.1980022217\2097728874" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.4.1846849285\1204767279" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.5.1342774967\93363410" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.6.100831398\991015969" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.7.1730759798\1272731160" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.8.1682045023\1142580100" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.9.815049710\1347908251" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2584.10.242993328\805475195" /prefetch:12
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.11.1633320949\1574081156" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.12.289187858\1422252698" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.13.625965586\1850747544" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.14.1350940555\1946262654" /prefetch:3
C:\Windows\system32\rundll32.exe "C:\Users\Tom\AppData\Local\Google\Chrome\APPLIC~1\200113~1.47\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Tom\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll" --lang=cs --channel="2584.16.235564512\1184146762" --flash-broker=5316 /prefetch:4
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.19.1572352751\968195120" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.21.1956068844\1643355534" /prefetch:3
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe84_ Global\UsGthrCtrlFltPipeMssGthrPipe84 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\AUDIODG.EXE 0x2c4
"C:\Users\Tom\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1476183158-4169381185-3047861550-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1476183158-4169381185-3047861550-1001UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-07-03 1387952]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20 328248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-05-04 453504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-07-03 1160792]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-05-04 157576]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20 509496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-07-03 1387952]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-07-03 1160792]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-12-23 2868496]
"PSQLLauncher"=C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe [2011-07-14 85832]
"TpShocks"=C:\Windows\system32\TpShocks.exe [2011-03-29 380776]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-30 165912]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-30 385560]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-30 363544]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Tom\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-15 116648]
"GoogleDriveSync"=C:\Program Files (x86)\Google\Drive\googledrivesync.exe [2012-06-20 12163848]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-04-17 3671872]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-07-03 4273976]
"SoundMAXPnP"=C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [2009-05-18 1314816]
"PWMTRV"=rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]
"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"hpqSRMon"=C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [2008-07-22 150528]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-08-06 260608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll [2011-07-14 136008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableCAD"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 3 months======
2012-07-11 19:39:32 ----D---- C:\Program Files\trend micro
2012-07-11 19:39:29 ----D---- C:\rsit
2012-07-10 14:51:04 ----D---- C:\Users\Tom\AppData\Roaming\wargaming.net
2012-07-09 06:41:46 ----D---- C:\Users\Tom\AppData\Roaming\JGoodies
2012-07-09 06:40:48 ----D---- C:\Program Files (x86)\JGoodies
2012-07-09 06:29:54 ----D---- C:\Program Files (x86)\Intel
2012-07-09 06:29:54 ----A---- C:\Windows\SYSWOW64\CSVer.dll
2012-07-09 06:28:12 ----D---- C:\Windows\SYSWOW64\Lang
2012-07-09 06:27:56 ----D---- C:\Intel
2012-07-09 06:27:26 ----A---- C:\Windows\system32\igfxtray.exe
2012-07-09 06:27:25 ----A---- C:\Windows\system32\igfxsrvc.exe
2012-07-09 06:27:18 ----A---- C:\Windows\system32\igfxpers.exe
2012-07-09 06:27:18 ----A---- C:\Windows\system32\igfxext.exe
2012-07-09 06:27:17 ----A---- C:\Windows\system32\igfxcfg.exe
2012-07-09 06:27:04 ----A---- C:\Windows\system32\hkcmd.exe
2012-07-09 06:27:04 ----A---- C:\Windows\system32\difx64.exe
2012-07-09 06:27:03 ----D---- C:\DRIVERS
2012-07-06 13:24:00 ----D---- C:\Users\Tom\AppData\Roaming\FileZilla
2012-07-06 13:23:21 ----D---- C:\Program Files (x86)\FileZilla FTP Client
2012-07-05 21:14:29 ----D---- C:\Users\Tom\AppData\Roaming\Miranda
2012-07-05 21:14:09 ----D---- C:\Program Files (x86)\Miranda IM
2012-07-02 22:48:07 ----D---- C:\Users\Tom\AppData\Roaming\ImgBurn
2012-07-02 22:18:53 ----D---- C:\Program Files (x86)\ImgBurn
2012-07-02 20:57:21 ----D---- C:\Program Files (x86)\Oracle
2012-07-02 20:57:16 ----A---- C:\Windows\SYSWOW64\javaws.exe
2012-07-02 20:57:02 ----A---- C:\Windows\SYSWOW64\javaw.exe
2012-07-02 20:57:02 ----A---- C:\Windows\SYSWOW64\java.exe
2012-07-01 10:01:41 ----D---- C:\ProgramData\MindGems
2012-06-29 21:14:53 ----D---- C:\Users\Tom\AppData\Roaming\Aegisub
2012-06-29 21:14:24 ----D---- C:\Program Files (x86)\Aegisub
2012-06-24 13:04:05 ----A---- C:\Windows\system32\drivers\sptd.sys
2012-06-24 13:02:08 ----RHD---- C:\Users\Tom\AppData\Roaming\SecuROM
2012-06-24 13:02:05 ----A---- C:\Windows\SYSWOW64\CmdLineExt.dll
2012-06-24 12:59:01 ----D---- C:\Program Files (x86)\Ubisoft
2012-06-21 15:08:35 ----D---- C:\Program Files (x86)\Tropico
2012-06-19 19:45:06 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2012-06-19 19:45:06 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2012-06-19 19:45:06 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2012-06-19 19:45:06 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-06-19 19:45:06 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2012-06-19 19:45:06 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-06-19 19:45:05 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-06-19 19:45:05 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-06-19 19:45:05 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-06-19 19:45:04 ----A---- C:\Windows\system32\D3DX9_43.dll
2012-06-19 19:45:04 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-06-19 19:45:03 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2012-06-19 19:45:03 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2012-06-19 19:45:03 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-06-19 19:45:03 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-06-19 19:45:02 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2012-06-19 19:45:02 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-06-19 19:45:01 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2012-06-19 19:45:01 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2012-06-19 19:44:59 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2012-06-19 19:44:59 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-06-19 19:44:58 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2012-06-19 19:44:58 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-06-19 19:44:57 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2012-06-19 19:44:57 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-06-19 19:44:50 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2012-06-19 19:44:50 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2012-06-19 19:44:50 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-06-19 19:44:50 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-06-19 19:44:49 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-06-19 19:44:49 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2012-06-19 19:44:49 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-06-19 19:44:49 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-06-19 19:44:48 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2012-06-19 19:44:48 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2012-06-19 19:44:48 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-06-19 19:44:48 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-06-19 19:44:47 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2012-06-19 19:44:47 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-06-19 19:44:46 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2012-06-19 19:44:46 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2012-06-19 19:44:46 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2012-06-19 19:44:46 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-06-19 19:44:46 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-06-19 19:44:46 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-06-19 19:44:45 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2012-06-19 19:44:45 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-06-19 19:44:45 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-06-19 19:44:45 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-06-19 19:44:45 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-06-19 19:44:45 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-06-19 19:44:44 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2012-06-19 19:44:44 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2012-06-19 19:44:44 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-06-19 19:44:44 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-06-19 19:44:44 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-06-19 19:44:44 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-06-19 19:44:43 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2012-06-19 19:44:43 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-06-19 19:44:42 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2012-06-19 19:44:42 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2012-06-19 19:44:42 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2012-06-19 19:44:42 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2012-06-19 19:44:42 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-06-19 19:44:42 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-06-19 19:44:42 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-06-19 19:44:42 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-06-19 19:44:41 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2012-06-19 19:44:41 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2012-06-19 19:44:41 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-06-19 19:44:41 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-06-19 19:44:40 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2012-06-19 19:44:40 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2012-06-19 19:44:40 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-06-19 19:44:40 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-06-19 19:44:39 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2012-06-19 19:44:39 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2012-06-19 19:44:39 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-06-19 19:44:39 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-06-19 19:44:38 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2012-06-19 19:44:38 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2012-06-19 19:44:38 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2012-06-19 19:44:38 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-06-19 19:44:38 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-06-19 19:44:38 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-06-19 19:44:37 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2012-06-19 19:44:37 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-06-19 19:44:36 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2012-06-19 19:44:36 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2012-06-19 19:44:36 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2012-06-19 19:44:36 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-06-19 19:44:36 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-06-19 19:44:36 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-06-19 19:44:35 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2012-06-19 19:44:35 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2012-06-19 19:44:35 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-06-19 19:44:35 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-06-19 19:44:34 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2012-06-19 19:44:34 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2012-06-19 19:44:34 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-06-19 19:44:34 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-06-19 19:44:32 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2012-06-19 19:44:32 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2012-06-19 19:44:32 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2012-06-19 19:44:32 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-06-19 19:44:32 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-06-19 19:44:32 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-06-19 19:44:31 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2012-06-19 19:44:31 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-06-19 19:44:30 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2012-06-19 19:44:30 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2012-06-19 19:44:30 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-06-19 19:44:30 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-06-19 19:44:28 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2012-06-19 19:44:28 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2012-06-19 19:44:28 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2012-06-19 19:44:28 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-06-19 19:44:28 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2012-06-19 19:44:28 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-06-19 19:44:27 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2012-06-19 19:44:27 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2012-06-19 19:44:27 ----A---- C:\Windows\system32\d3dx10_34.dll
2012-06-19 19:44:27 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2012-06-19 19:44:26 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2012-06-19 19:44:26 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2012-06-19 19:44:26 ----A---- C:\Windows\system32\xinput1_3.dll
2012-06-19 19:44:26 ----A---- C:\Windows\system32\d3dx9_34.dll
2012-06-19 19:44:25 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2012-06-19 19:44:25 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2012-06-19 19:44:25 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2012-06-19 19:44:25 ----A---- C:\Windows\system32\xactengine2_7.dll
2012-06-19 19:44:25 ----A---- C:\Windows\system32\d3dx10_33.dll
2012-06-19 19:44:25 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2012-06-19 19:44:24 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2012-06-19 19:44:24 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2012-06-19 19:44:24 ----A---- C:\Windows\system32\xactengine2_6.dll
2012-06-19 19:44:24 ----A---- C:\Windows\system32\d3dx9_33.dll
2012-06-19 19:44:22 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2012-06-19 19:44:22 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2012-06-19 19:44:22 ----A---- C:\Windows\system32\xactengine2_5.dll
2012-06-19 19:44:22 ----A---- C:\Windows\system32\d3dx10.dll
2012-06-19 19:44:21 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2012-06-19 19:44:21 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2012-06-19 19:44:21 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2012-06-19 19:44:21 ----A---- C:\Windows\system32\xactengine2_4.dll
2012-06-19 19:44:21 ----A---- C:\Windows\system32\x3daudio1_1.dll
2012-06-19 19:44:21 ----A---- C:\Windows\system32\d3dx9_32.dll
2012-06-19 19:44:20 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2012-06-19 19:44:20 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2012-06-19 19:44:20 ----A---- C:\Windows\system32\xactengine2_3.dll
2012-06-19 19:44:20 ----A---- C:\Windows\system32\d3dx9_31.dll
2012-06-19 19:44:19 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2012-06-19 19:44:19 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2012-06-19 19:44:19 ----A---- C:\Windows\system32\xinput1_2.dll
2012-06-19 19:44:19 ----A---- C:\Windows\system32\xactengine2_2.dll
2012-06-19 19:44:18 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2012-06-19 19:44:18 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2012-06-19 19:44:18 ----A---- C:\Windows\system32\xinput1_1.dll
2012-06-19 19:44:18 ----A---- C:\Windows\system32\xactengine2_1.dll
2012-06-19 19:44:16 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2012-06-19 19:44:16 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2012-06-19 19:44:16 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2012-06-19 19:44:16 ----A---- C:\Windows\system32\xactengine2_0.dll
2012-06-19 19:44:16 ----A---- C:\Windows\system32\x3daudio1_0.dll
2012-06-19 19:44:16 ----A---- C:\Windows\system32\d3dx9_30.dll
2012-06-19 19:44:15 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2012-06-19 19:44:15 ----A---- C:\Windows\system32\d3dx9_29.dll
2012-06-19 19:44:14 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2012-06-19 19:44:14 ----A---- C:\Windows\system32\d3dx9_28.dll
2012-06-19 19:44:13 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2012-06-19 19:44:13 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2012-06-19 19:44:13 ----A---- C:\Windows\system32\d3dx9_27.dll
2012-06-19 19:44:13 ----A---- C:\Windows\system32\d3dx9_26.dll
2012-06-19 19:44:12 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2012-06-19 19:44:12 ----A---- C:\Windows\system32\d3dx9_25.dll
2012-06-19 19:44:10 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2012-06-19 19:44:10 ----A---- C:\Windows\system32\d3dx9_24.dll
2012-06-19 19:40:24 ----D---- C:\Windows\SYSWOW64\directx
2012-06-19 19:30:04 ----A---- C:\Windows\ipuninst.exe
2012-06-19 19:29:31 ----D---- C:\Program Files\BlackIsle
2012-06-19 19:27:35 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2012-06-19 19:27:29 ----D---- C:\Users\Tom\AppData\Roaming\DAEMON Tools Lite
2012-06-19 19:27:11 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2012-06-19 19:26:45 ----D---- C:\ProgramData\DAEMON Tools Lite
2012-06-19 08:13:59 ----A---- C:\Windows\system32\wups2.dll
2012-06-19 08:13:59 ----A---- C:\Windows\system32\wucltux.dll
2012-06-19 08:13:59 ----A---- C:\Windows\system32\wuaueng.dll
2012-06-19 08:13:59 ----A---- C:\Windows\system32\wuauclt.exe
2012-06-19 08:13:48 ----A---- C:\Windows\system32\wups.dll
2012-06-19 08:13:48 ----A---- C:\Windows\system32\wudriver.dll
2012-06-19 08:13:48 ----A---- C:\Windows\system32\wuapi.dll
2012-06-19 08:13:36 ----A---- C:\Windows\system32\wuwebv.dll
2012-06-19 08:13:35 ----A---- C:\Windows\system32\wuapp.exe
2012-06-13 21:49:38 ----A---- C:\Windows\system32\mshtmled.dll
2012-06-13 21:49:37 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-06-13 21:49:36 ----A---- C:\Windows\SYSWOW64\url.dll
2012-06-13 21:49:36 ----A---- C:\Windows\system32\url.dll
2012-06-13 21:49:35 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-06-13 21:49:34 ----A---- C:\Windows\system32\urlmon.dll
2012-06-13 21:49:33 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-06-13 21:49:33 ----A---- C:\Windows\system32\iertutil.dll
2012-06-13 21:49:32 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-06-13 21:49:32 ----A---- C:\Windows\system32\ieui.dll
2012-06-13 21:49:31 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2012-06-13 21:49:31 ----A---- C:\Windows\system32\ieUnatt.exe
2012-06-13 21:49:30 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-06-13 21:49:30 ----A---- C:\Windows\system32\wininet.dll
2012-06-13 21:49:29 ----A---- C:\Windows\system32\jsproxy.dll
2012-06-13 21:49:27 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-06-13 21:49:27 ----A---- C:\Windows\system32\jscript9.dll
2012-06-13 21:49:26 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-06-13 21:49:26 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-06-13 21:49:26 ----A---- C:\Windows\system32\jscript.dll
2012-06-13 21:49:22 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-06-13 21:49:20 ----A---- C:\Windows\system32\mshtml.dll
2012-06-13 21:49:18 ----A---- C:\Windows\system32\ieframe.dll
2012-06-13 21:49:16 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-06-13 20:35:34 ----A---- C:\Windows\system32\rdpwsx.dll
2012-06-13 20:35:34 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-06-13 20:35:33 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-06-13 20:35:18 ----A---- C:\Windows\system32\profsvc.dll
2012-06-13 20:35:00 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-06-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2012-06-13 20:34:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2012-06-13 20:34:55 ----A---- C:\Windows\system32\win32k.sys
2012-06-13 20:34:51 ----A---- C:\Windows\system32\rdpcorets.dll
2012-06-13 20:34:49 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2012-06-13 20:34:32 ----A---- C:\Windows\system32\msi.dll
2012-06-13 20:34:31 ----A---- C:\Windows\SYSWOW64\msi.dll
2012-06-13 20:34:27 ----A---- C:\Windows\system32\crypt32.dll
2012-06-13 20:34:26 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2012-06-13 20:34:26 ----A---- C:\Windows\system32\cryptsvc.dll
2012-06-13 20:34:25 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2012-06-13 20:34:25 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2012-06-13 20:34:25 ----A---- C:\Windows\system32\cryptnet.dll
2012-06-06 17:58:14 ----D---- C:\ProgramData\WEBREG
2012-06-06 17:58:13 ----D---- C:\Users\Tom\AppData\Roaming\HP
2012-06-06 15:18:31 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2012-06-06 15:18:31 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2012-06-06 15:18:31 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2012-06-06 15:18:31 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-06-06 15:18:30 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-06-06 15:12:37 ----D---- C:\Program Files (x86)\Room Arranger
2012-06-03 17:41:15 ----D---- C:\Program Files (x86)\uTorrent
2012-06-03 17:40:30 ----D---- C:\Users\Tom\AppData\Roaming\uTorrent
2012-06-01 14:42:33 ----D---- C:\Users\Tom\AppData\Roaming\Audacity
2012-06-01 14:42:21 ----D---- C:\Program Files (x86)\Audacity
2012-06-01 14:40:06 ----D---- C:\Program Files\GIMP 2
2012-05-30 15:17:28 ----D---- C:\Program Files (x86)\MSXML 4.0
2012-05-28 16:04:36 ----D---- C:\ProgramData\HP Product Assistant
2012-05-28 16:04:00 ----D---- C:\Windows\SYSWOW64\spool
2012-05-28 16:03:14 ----D---- C:\Windows\SYSWOW64\Macromed
2012-05-28 15:59:14 ----D---- C:\Program Files (x86)\HP
2012-05-28 15:59:12 ----HD---- C:\Config.Msi
2012-05-28 15:57:05 ----D---- C:\Program Files\HP
2012-05-28 15:56:14 ----N---- C:\Windows\hpomdl19.dat
2012-05-28 15:56:14 ----A---- C:\Windows\hpoins19.dat
2012-05-28 15:55:47 ----A---- C:\Windows\system32\hpzids40.dll
2012-05-28 15:55:41 ----A---- C:\Windows\system32\hpowiav1.dll
2012-05-28 15:55:41 ----A---- C:\Windows\system32\hpovst01.dll
2012-05-28 15:55:41 ----A---- C:\Windows\system32\hpotscl1.dll
2012-05-28 15:55:40 ----A---- C:\Windows\system32\hpotiop1.dll
2012-05-28 15:37:14 ----D---- C:\ProgramData\HP
2012-05-27 22:52:59 ----D---- C:\Users\Tom\AppData\Roaming\.minecraft
2012-05-27 22:49:15 ----D---- C:\ProgramData\Sun
2012-05-27 22:48:34 ----A---- C:\Windows\SYSWOW64\npDeployJava1.dll
2012-05-27 22:48:34 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2012-05-27 22:48:02 ----D---- C:\Program Files (x86)\Java
2012-05-23 17:16:49 ----D---- C:\Program Files (x86)\Google
2012-05-22 19:19:57 ----D---- C:\Users\Tom\AppData\Roaming\vlc
2012-05-20 19:02:00 ----D---- C:\Users\Tom\AppData\Roaming\WinRAR
2012-05-20 19:01:51 ----D---- C:\Program Files\WinRAR
2012-05-18 13:28:01 ----A---- C:\Windows\system32\drivers\Axtmvprt.sys
2012-05-18 13:28:01 ----A---- C:\Windows\system32\drivers\Axtmvmdm.sys
2012-05-18 13:28:01 ----A---- C:\Windows\system32\drivers\Axtmvflt.sys
2012-05-18 13:27:56 ----D---- C:\Program Files\Axesstel
2012-05-17 18:17:18 ----A---- C:\Windows\system32\drivers\usbohci.sys
2012-05-17 18:17:17 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2012-05-17 18:17:17 ----A---- C:\Windows\system32\drivers\usbport.sys
2012-05-17 18:17:17 ----A---- C:\Windows\system32\drivers\usbehci.sys
2012-05-17 18:17:17 ----A---- C:\Windows\system32\drivers\usbd.sys
2012-05-17 18:17:17 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2012-05-17 18:17:16 ----A---- C:\Windows\system32\drivers\usbhub.sys
2012-05-17 18:08:14 ----A---- C:\Windows\system32\drivers\ndis.sys
2012-05-17 14:36:16 ----D---- C:\Windows\system32\SPReview
2012-05-17 12:43:43 ----D---- C:\Windows\CheckSur
2012-05-17 12:00:35 ----D---- C:\Windows\system32\EventProviders
2012-05-17 11:50:00 ----A---- C:\Windows\system32\netfxperf.dll
2012-05-17 11:49:59 ----A---- C:\Windows\system32\dfshim.dll
2012-05-17 11:49:44 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2012-05-17 11:49:37 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2012-05-17 11:49:37 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2012-05-17 11:49:36 ----A---- C:\Windows\system32\mstscax.dll
2012-05-17 11:49:36 ----A---- C:\Windows\system32\d3d10warp.dll
2012-05-17 11:49:30 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2012-05-17 11:49:25 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2012-05-17 11:49:24 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2012-05-17 11:49:23 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2012-05-17 11:49:23 ----A---- C:\Windows\system32\tssrvlic.dll
2012-05-17 11:49:23 ----A---- C:\Windows\system32\sysmain.dll
2012-05-17 11:49:23 ----A---- C:\Windows\system32\RDVGHelper.exe
2012-05-17 11:49:20 ----A---- C:\Windows\SYSWOW64\pmcsnap.dll
2012-05-17 11:49:19 ----A---- C:\Windows\system32\MSVidCtl.dll
2012-05-17 11:49:12 ----A---- C:\Windows\system32\mscoree.dll
2012-05-17 11:49:11 ----A---- C:\Windows\system32\mmcndmgr.dll
2012-05-17 11:49:09 ----A---- C:\Windows\system32\secproc_isv.dll
2012-05-17 11:49:09 ----A---- C:\Windows\system32\mf.dll
2012-05-17 11:49:08 ----A---- C:\Windows\system32\RMActivate_isv.exe
2012-05-17 11:49:07 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2012-05-17 11:49:07 ----A---- C:\Windows\system32\secproc.dll
2012-05-17 11:49:07 ----A---- C:\Windows\system32\RMActivate.exe
2012-05-17 11:49:06 ----A---- C:\Windows\system32\xpsservices.dll
2012-05-17 11:49:03 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2012-05-17 11:49:02 ----A---- C:\Windows\SYSWOW64\secproc.dll
2012-05-17 11:49:02 ----A---- C:\Windows\system32\rpcrt4.dll
2012-05-17 11:49:00 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2012-05-17 11:48:59 ----A---- C:\Windows\SYSWOW64\PushPrinterConnections.exe
2012-05-17 11:48:59 ----A---- C:\Windows\SYSWOW64\ppcsnap.dll
2012-05-17 11:48:58 ----A---- C:\Windows\system32\schedsvc.dll
2012-05-17 11:48:58 ----A---- C:\Windows\system32\ole32.dll
2012-05-17 11:48:52 ----A---- C:\Windows\system32\spwizui.dll
2012-05-17 11:48:50 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2012-05-17 11:48:46 ----A---- C:\Windows\system32\taskschd.dll
2012-05-17 11:48:45 ----A---- C:\Windows\system32\RacEngn.dll
2012-05-17 11:48:45 ----A---- C:\Windows\system32\diagperf.dll
2012-05-17 11:48:44 ----A---- C:\Windows\system32\wevtsvc.dll
2012-05-17 11:48:43 ----A---- C:\Windows\SYSWOW64\mf.dll
2012-05-17 11:48:43 ----A---- C:\Windows\system32\ExplorerFrame.dll
2012-05-17 11:48:41 ----A---- C:\Windows\system32\vssapi.dll
2012-05-17 11:48:41 ----A---- C:\Windows\system32\msxml3.dll
2012-05-17 11:48:39 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2012-05-17 11:48:38 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2012-05-17 11:48:37 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2012-05-17 11:48:35 ----A---- C:\Windows\system32\UIRibbon.dll
2012-05-17 11:48:35 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2012-05-17 11:48:25 ----A---- C:\Windows\system32\WsmSvc.dll
2012-05-17 11:48:24 ----A---- C:\Windows\system32\WMVCORE.DLL
2012-05-17 11:48:23 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2012-05-17 11:48:23 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2012-05-17 11:48:22 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2012-05-17 11:48:21 ----A---- C:\Windows\system32\PresentationHost.exe
2012-05-17 11:48:20 ----A---- C:\Windows\system32\rdpdd.dll
2012-05-17 11:48:19 ----A---- C:\Windows\system32\MPSSVC.dll
2012-05-17 11:48:18 ----A---- C:\Windows\system32\spreview.exe
2012-05-17 11:48:18 ----A---- C:\Windows\system32\spinstall.exe
2012-05-17 11:48:17 ----A---- C:\Windows\system32\CertEnroll.dll
2012-05-17 11:48:15 ----A---- C:\Windows\system32\WinSAT.exe
2012-05-17 11:48:11 ----A---- C:\Windows\system32\WMVDECOD.DLL
2012-05-17 11:48:09 ----A---- C:\Windows\system32\d3d9.dll
2012-05-17 11:48:08 ----A---- C:\Windows\system32\msxml6.dll
2012-05-17 11:48:07 ----A---- C:\Windows\SYSWOW64\RacEngn.dll
2012-05-17 11:48:07 ----A---- C:\Windows\system32\IKEEXT.DLL
2012-05-17 11:48:06 ----A---- C:\Windows\system32\SearchFolder.dll
2012-05-17 11:48:05 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2012-05-17 11:48:04 ----A---- C:\Windows\SYSWOW64\AuthFWSnapin.dll
2012-05-17 11:48:00 ----A---- C:\Windows\system32\gpsvc.dll
2012-05-17 11:47:57 ----A---- C:\Windows\system32\VSSVC.exe
2012-05-17 11:47:55 ----A---- C:\Windows\system32\dwmcore.dll
2012-05-17 11:47:54 ----A---- C:\Windows\system32\dbgeng.dll
2012-05-17 11:47:53 ----A---- C:\Windows\system32\drivers\http.sys
2012-05-17 11:47:51 ----A---- C:\Windows\SYSWOW64\rdvgumd32.dll
2012-05-17 11:47:48 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2012-05-17 11:47:45 ----A---- C:\Windows\SYSWOW64\ole32.dll
2012-05-17 11:47:45 ----A---- C:\Windows\system32\TSWorkspace.dll
2012-05-17 11:47:45 ----A---- C:\Windows\system32\actxprxy.dll
2012-05-17 11:47:44 ----A---- C:\Windows\system32\audiosrv.dll
2012-05-17 11:47:43 ----A---- C:\Windows\system32\qmgr.dll
2012-05-17 11:47:41 ----A---- C:\Windows\system32\gpprefcl.dll
2012-05-17 11:47:40 ----A---- C:\Windows\system32\termsrv.dll
2012-05-17 11:47:39 ----A---- C:\Windows\system32\mstsc.exe
2012-05-17 11:47:37 ----A---- C:\Windows\system32\netlogon.dll
2012-05-17 11:47:37 ----A---- C:\Windows\system32\imapi2fs.dll
2012-05-17 11:47:36 ----A---- C:\Windows\SYSWOW64\vssapi.dll
2012-05-17 11:47:36 ----A---- C:\Windows\system32\winhttp.dll
2012-05-17 11:47:36 ----A---- C:\Windows\system32\d3d11.dll
2012-05-17 11:47:35 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2012-05-17 11:47:35 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2012-05-17 11:47:35 ----A---- C:\Windows\system32\msv1_0.dll
2012-05-17 11:47:34 ----A---- C:\Windows\system32\QAGENTRT.DLL
2012-05-17 11:47:34 ----A---- C:\Windows\system32\propsys.dll
2012-05-17 11:47:33 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2012-05-17 11:47:33 ----A---- C:\Windows\system32\wbengine.exe
2012-05-17 11:47:33 ----A---- C:\Windows\system32\setupapi.dll
2012-05-17 11:47:33 ----A---- C:\Windows\system32\rpcss.dll
2012-05-17 11:47:33 ----A---- C:\Windows\system32\PushPrinterConnections.exe
2012-05-17 11:47:31 ----A---- C:\Windows\system32\authui.dll
2012-05-17 11:47:30 ----A---- C:\Windows\system32\werconcpl.dll
2012-05-17 11:47:30 ----A---- C:\Windows\system32\taskeng.exe
2012-05-17 11:47:30 ----A---- C:\Windows\system32\odbc32.dll
2012-05-17 11:47:25 ----A---- C:\Windows\system32\user32.dll.bak
2012-05-17 11:47:25 ----A---- C:\Windows\system32\user32.dll
2012-05-17 11:47:24 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2012-05-17 11:47:24 ----A---- C:\Windows\system32\WSDApi.dll
2012-05-17 11:47:24 ----A---- C:\Windows\system32\drivers\netio.sys
2012-05-17 11:47:23 ----A---- C:\Windows\system32\umrdp.dll
2012-05-17 11:47:23 ----A---- C:\Windows\system32\LSCSHostPolicy.dll
2012-05-17 11:47:23 ----A---- C:\Windows\system32\drivers\tdx.sys
2012-05-17 11:47:23 ----A---- C:\Windows\system32\dhcpcore.dll
2012-05-17 11:47:23 ----A---- C:\Windows\system32\certmgr.dll
2012-05-17 11:47:22 ----A---- C:\Windows\SYSWOW64\wer.dll
2012-05-17 11:47:22 ----A---- C:\Windows\system32\scavengeui.dll
2012-05-17 11:47:22 ----A---- C:\Windows\system32\drivers\netbt.sys
2012-05-17 11:47:21 ----A---- C:\Windows\SYSWOW64\certcli.dll
2012-05-17 11:47:21 ----A---- C:\Windows\system32\tsmf.dll
2012-05-17 11:47:21 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2012-05-17 11:47:21 ----A---- C:\Windows\system32\localspl.dll
2012-05-17 11:47:20 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2012-05-17 11:47:20 ----A---- C:\Windows\system32\ncsi.dll
2012-05-17 11:47:20 ----A---- C:\Windows\system32\msdrm.dll
2012-05-17 11:47:19 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2012-05-17 11:47:19 ----A---- C:\Windows\system32\shlwapi.dll
2012-05-17 11:47:19 ----A---- C:\Windows\system32\msdtctm.dll
2012-05-17 11:47:19 ----A---- C:\Windows\system32\framedynos.dll
2012-05-17 11:47:18 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2012-05-17 11:47:18 ----A---- C:\Windows\system32\rdpshell.exe
2012-05-17 11:47:18 ----A---- C:\Windows\system32\netshell.dll
2012-05-17 11:47:17 ----A---- C:\Windows\SYSWOW64\tcpmonui.dll
2012-05-17 11:47:17 ----A---- C:\Windows\system32\wmicmiplugin.dll
2012-05-17 11:47:17 ----A---- C:\Windows\system32\netcfgx.dll
2012-05-17 11:47:16 ----A---- C:\Windows\system32\ws2_32.dll
2012-05-17 11:47:16 ----A---- C:\Windows\system32\winlogon.exe
2012-05-17 11:47:16 ----A---- C:\Windows\system32\usp10.dll
2012-05-17 11:47:16 ----A---- C:\Windows\system32\nlasvc.dll
2012-05-17 11:47:16 ----A---- C:\Windows\system32\appmgr.dll
2012-05-17 11:47:15 ----A---- C:\Windows\system32\lsm.exe
2012-05-17 11:47:15 ----A---- C:\Windows\system32\dxgi.dll
2012-05-17 11:47:15 ----A---- C:\Windows\system32\drivers\csc.sys
2012-05-17 11:47:15 ----A---- C:\Windows\system32\comdlg32.dll
2012-05-17 11:47:14 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2012-05-17 11:47:14 ----A---- C:\Windows\system32\Query.dll
2012-05-17 11:47:14 ----A---- C:\Windows\system32\mswsock.dll
2012-05-17 11:47:14 ----A---- C:\Windows\system32\apphelp.dll
2012-05-17 11:47:13 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2012-05-17 11:47:13 ----A---- C:\Windows\SYSWOW64\dot3api.dll
2012-05-17 11:47:13 ----A---- C:\Windows\system32\wpdshext.dll
2012-05-17 11:47:13 ----A---- C:\Windows\system32\drvstore.dll
2012-05-17 11:47:13 ----A---- C:\Windows\system32\azroles.dll
2012-05-17 11:47:11 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2012-05-17 11:47:11 ----A---- C:\Windows\SYSWOW64\setupapi.dll
2012-05-17 11:47:11 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2012-05-17 11:47:11 ----A---- C:\Windows\system32\Vault.dll
2012-05-17 11:47:11 ----A---- C:\Windows\system32\QAGENT.DLL
2012-05-17 11:47:11 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2012-05-17 11:47:11 ----A---- C:\Windows\system32\BFE.DLL
2012-05-17 11:47:10 ----A---- C:\Windows\system32\samsrv.dll
2012-05-17 11:47:10 ----A---- C:\Windows\system32\DShowRdpFilter.dll
2012-05-17 11:47:10 ----A---- C:\Windows\system32\cmd.exe
2012-05-17 11:47:09 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2012-05-17 11:47:09 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2012-05-17 11:47:09 ----A---- C:\Windows\system32\win32spl.dll
2012-05-17 11:47:09 ----A---- C:\Windows\system32\lpksetup.exe
2012-05-17 11:47:08 ----A---- C:\Windows\SYSWOW64\netlogon.dll
2012-05-17 11:47:08 ----A---- C:\Windows\system32\cscsvc.dll
2012-05-17 11:47:07 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2012-05-17 11:47:07 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2012-05-17 11:47:07 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2012-05-17 11:47:07 ----A---- C:\Windows\system32\rdpclip.exe
2012-05-17 11:47:06 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2012-05-17 11:47:06 ----A---- C:\Windows\system32\WebClnt.dll
2012-05-17 11:47:05 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2012-05-17 11:47:05 ----A---- C:\Windows\SYSWOW64\Query.dll
2012-05-17 11:47:05 ----A---- C:\Windows\SYSWOW64\gpprefcl.dll
2012-05-17 11:47:05 ----A---- C:\Windows\system32\Wldap32.dll
2012-05-17 11:47:05 ----A---- C:\Windows\system32\WindowsCodecs.dll
2012-05-17 11:47:05 ----A---- C:\Windows\system32\sxs.dll
2012-05-17 11:47:05 ----A---- C:\Windows\system32\mcbuilder.exe
2012-05-17 11:47:05 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2012-05-17 11:47:05 ----A---- C:\Windows\system32\cscobj.dll
2012-05-17 11:47:04 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2012-05-17 11:47:04 ----A---- C:\Windows\system32\taskcomp.dll
2012-05-17 11:47:04 ----A---- C:\Windows\system32\mfds.dll
2012-05-17 11:47:03 ----A---- C:\Windows\SYSWOW64\upnp.dll
2012-05-17 11:47:03 ----A---- C:\Windows\SYSWOW64\mmcndmgr.dll
2012-05-17 11:47:03 ----A---- C:\Windows\SYSWOW64\DShowRdpFilter.dll
2012-05-17 11:47:03 ----A---- C:\Windows\system32\pnidui.dll
2012-05-17 11:47:03 ----A---- C:\Windows\system32\ipsmsnap.dll
2012-05-17 11:47:03 ----A---- C:\Windows\system32\hgprint.dll
2012-05-17 11:47:02 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2012-05-17 11:47:02 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2012-05-17 11:47:02 ----A---- C:\Windows\system32\webservices.dll
2012-05-17 11:47:02 ----A---- C:\Windows\system32\SessEnv.dll
2012-05-17 11:47:02 ----A---- C:\Windows\system32\rdpendp.dll
2012-05-17 11:47:01 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2012-05-17 11:47:01 ----A---- C:\Windows\SYSWOW64\imapi2fs.dll
2012-05-17 11:47:01 ----A---- C:\Windows\SYSWOW64\authui.dll
2012-05-17 11:47:01 ----A---- C:\Windows\system32\winsta.dll
2012-05-17 11:47:01 ----A---- C:\Windows\system32\spoolsv.exe
2012-05-17 11:47:00 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2012-05-17 11:47:00 ----A---- C:\Windows\system32\sqlsrv32.dll
2012-05-17 11:47:00 ----A---- C:\Windows\system32\fveapi.dll
2012-05-17 11:47:00 ----A---- C:\Windows\system32\dot3api.dll
2012-05-17 11:46:59 ----A---- C:\Windows\SYSWOW64\usp10.dll
2012-05-17 11:46:59 ----A---- C:\Windows\SYSWOW64\shlwapi.dll
2012-05-17 11:46:59 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2012-05-17 11:46:58 ----A---- C:\Windows\SYSWOW64\mcbuilder.exe
2012-05-17 11:46:58 ----A---- C:\Windows\system32\prncache.dll
2012-05-17 11:46:58 ----A---- C:\Windows\system32\gdi32.dll
2012-05-17 11:46:58 ----A---- C:\Windows\system32\drivers\volsnap.sys
2012-05-17 11:46:58 ----A---- C:\Windows\system32\drivers\msrpc.sys
2012-05-17 11:46:57 ----A---- C:\Windows\system32\schtasks.exe
2012-05-17 11:46:56 ----A---- C:\Windows\SYSWOW64\userenv.dll
2012-05-17 11:46:56 ----A---- C:\Windows\SYSWOW64\certmgr.dll
2012-05-17 11:46:56 ----A---- C:\Windows\system32\WMNetMgr.dll
2012-05-17 11:46:56 ----A---- C:\Windows\system32\wlanpref.dll
2012-05-17 11:46:56 ----A---- C:\Windows\system32\vpnike.dll
2012-05-17 11:46:55 ----A---- C:\Windows\SYSWOW64\xpsservices.dll
2012-05-17 11:46:55 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2012-05-17 11:46:55 ----A---- C:\Windows\SYSWOW64\drvstore.dll
2012-05-17 11:46:55 ----A---- C:\Windows\system32\userenv.dll
2012-05-17 11:46:55 ----A---- C:\Windows\system32\drivers\rdbss.sys
2012-05-17 11:46:54 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2012-05-17 11:46:54 ----A---- C:\Windows\system32\tspubwmi.dll
2012-05-17 11:46:54 ----A---- C:\Windows\system32\photowiz.dll
2012-05-17 11:46:54 ----A---- C:\Windows\system32\evr.dll
2012-05-17 11:46:54 ----A---- C:\Windows\system32\drivers\1394ohci.sys
2012-05-17 11:46:53 ----A---- C:\Windows\system32\IPSECSVC.DLL
2012-05-17 11:46:53 ----A---- C:\Windows\system32\framedyn.dll
2012-05-17 11:46:52 ----A---- C:\Windows\system32\FXSSVC.exe
2012-05-17 11:46:52 ----A---- C:\Windows\system32\AudioSes.dll
2012-05-17 11:46:51 ----A---- C:\Windows\SYSWOW64\cmd.exe
2012-05-17 11:46:51 ----A---- C:\Windows\system32\SyncCenter.dll
2012-05-17 11:46:51 ----A---- C:\Windows\system32\sppobjs.dll
2012-05-17 11:46:51 ----A---- C:\Windows\system32\aepdu.dll
2012-05-17 11:46:50 ----A---- C:\Windows\system32\mfreadwrite.dll
2012-05-17 11:46:49 ----A---- C:\Windows\system32\tscfgwmi.dll
2012-05-17 11:46:47 ----A---- C:\Windows\system32\srvsvc.dll
2012-05-17 11:46:45 ----A---- C:\Windows\system32\shsvcs.dll
2012-05-17 11:46:45 ----A---- C:\Windows\system32\rdpinit.exe
2012-05-17 11:46:45 ----A---- C:\Windows\system32\aeinv.dll
2012-05-17 11:46:43 ----A---- C:\Windows\SYSWOW64\framedynos.dll
2012-05-17 11:46:43 ----A---- C:\Windows\system32\vmicsvc.exe
2012-05-17 11:46:43 ----A---- C:\Windows\system32\fde.dll
2012-05-17 11:46:42 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2012-05-17 11:46:42 ----A---- C:\Windows\SYSWOW64\propsys.dll
2012-05-17 11:46:41 ----A---- C:\Windows\SYSWOW64\Wldap32.dll
2012-05-17 11:46:41 ----A---- C:\Windows\SYSWOW64\mfds.dll
2012-05-17 11:46:41 ----A---- C:\Windows\system32\WinSATAPI.dll
2012-05-17 11:46:41 ----A---- C:\Windows\system32\stobject.dll
2012-05-17 11:46:41 ----A---- C:\Windows\system32\imapi2.dll
2012-05-17 11:46:40 ----A---- C:\Windows\system32\localsec.dll
2012-05-17 11:46:39 ----A---- C:\Windows\system32\netdiagfx.dll
2012-05-17 11:46:39 ----A---- C:\Windows\system32\credui.dll
2012-05-17 11:46:38 ----A---- C:\Windows\SYSWOW64\rdpendp.dll
2012-05-17 11:46:38 ----A---- C:\Windows\system32\bcryptprimitives.dll
2012-05-17 11:46:37 ----A---- C:\Windows\SYSWOW64\user32.dll.bak
2012-05-17 11:46:37 ----A---- C:\Windows\SYSWOW64\user32.dll
2012-05-17 11:46:37 ----A---- C:\Windows\system32\iphlpsvc.dll
2012-05-17 11:46:37 ----A---- C:\Windows\system32\drivers\vmbus.sys
2012-05-17 11:46:37 ----A---- C:\Windows\system32\drivers\udfs.sys
2012-05-17 11:46:37 ----A---- C:\Windows\system32\cdd.dll
2012-05-17 11:46:36 ----A---- C:\Windows\system32\inetpp.dll
2012-05-17 11:46:35 ----A---- C:\Windows\system32\tcpipcfg.dll
2012-05-17 11:46:35 ----A---- C:\Windows\system32\QSHVHOST.DLL
2012-05-17 11:46:35 ----A---- C:\Windows\system32\netid.dll
2012-05-17 11:46:35 ----A---- C:\Windows\system32\drivers\fltMgr.sys
2012-05-17 11:46:34 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2012-05-17 11:46:34 ----A---- C:\Windows\SYSWOW64\azroles.dll
2012-05-17 11:46:34 ----A---- C:\Windows\system32\spp.dll
2012-05-17 11:46:34 ----A---- C:\Windows\system32\davclnt.dll
2012-05-17 11:46:34 ----A---- C:\Windows\system32\cscui.dll
2012-05-17 11:46:34 ----A---- C:\Windows\system32\biocpl.dll
2012-05-17 11:46:33 ----A---- C:\Windows\SYSWOW64\appmgr.dll
2012-05-17 11:46:33 ----A---- C:\Windows\system32\msinfo32.exe
2012-05-17 11:46:32 ----A---- C:\Windows\system32\gameux.dll
2012-05-17 11:46:31 ----A---- C:\Windows\system32\scansetting.dll
2012-05-17 11:46:31 ----A---- C:\Windows\system32\printui.dll
2012-05-17 11:46:30 ----A---- C:\Windows\SYSWOW64\themeui.dll
2012-05-17 11:46:30 ----A---- C:\Windows\SYSWOW64\credui.dll
2012-05-17 11:46:30 ----A---- C:\Windows\system32\pla.dll
2012-05-17 11:46:30 ----A---- C:\Windows\splwow64.exe
2012-05-17 11:46:29 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2012-05-17 11:46:29 ----A---- C:\Windows\SYSWOW64\spp.dll
2012-05-17 11:46:29 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2012-05-17 11:46:29 ----A---- C:\Windows\SYSWOW64\dhcpcore.dll
2012-05-17 11:46:29 ----A---- C:\Windows\system32\PhotoScreensaver.scr
2012-05-17 11:46:28 ----A---- C:\Windows\system32\wusa.exe
2012-05-17 11:46:28 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2012-05-17 11:46:28 ----A---- C:\Windows\system32\aitagent.exe
2012-05-17 11:46:27 ----A---- C:\Windows\system32\wiaservc.dll
2012-05-17 11:46:27 ----A---- C:\Windows\system32\vds.exe
2012-05-17 11:46:27 ----A---- C:\Windows\system32\drivers\pci.sys
2012-05-17 11:46:26 ----A---- C:\Windows\system32\AdmTmpl.dll
2012-05-17 11:46:25 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2012-05-17 11:46:25 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2012-05-17 11:46:25 ----A---- C:\Windows\SYSWOW64\basecsp.dll
2012-05-17 11:46:25 ----A---- C:\Windows\system32\rpchttp.dll
2012-05-17 11:46:25 ----A---- C:\Windows\system32\mscms.dll
2012-05-17 11:46:24 ----A---- C:\Windows\SYSWOW64\NaturalLanguage6.dll
2012-05-17 11:46:24 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2012-05-17 11:46:24 ----A---- C:\Windows\SYSWOW64\dbghelp.dll
2012-05-17 11:46:23 ----A---- C:\Windows\system32\PkgMgr.exe
2012-05-17 11:46:23 ----A---- C:\Windows\system32\FirewallControlPanel.dll
2012-05-17 11:46:23 ----A---- C:\Windows\system32\drivers\rasl2tp.sys
2012-05-17 11:46:22 ----A---- C:\Windows\system32\XpsRasterService.dll
2012-05-17 11:46:22 ----A---- C:\Windows\system32\wisptis.exe
2012-05-17 11:46:21 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2012-05-17 11:46:21 ----A---- C:\Windows\system32\ocsetup.exe
2012-05-17 11:46:20 ----A---- C:\Windows\SYSWOW64\evr.dll
2012-05-17 11:46:20 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2012-05-17 11:46:19 ----A---- C:\Windows\SYSWOW64\WinSATAPI.dll
2012-05-17 11:46:19 ----A---- C:\Windows\system32\sppwinob.dll
2012-05-17 11:46:18 ----A---- C:\Windows\SYSWOW64\calc.exe
2012-05-17 11:46:18 ----A---- C:\Windows\system32\ocsetapi.dll
2012-05-17 11:46:18 ----A---- C:\Windows\system32\DXP.dll
2012-05-17 11:46:18 ----A---- C:\Windows\system32\drivers\volmgr.sys
2012-05-17 11:46:17 ----A---- C:\Windows\system32\wpdbusenum.dll
2012-05-17 11:46:17 ----A---- C:\Windows\system32\eapp3hst.dll
2012-05-17 11:46:17 ----A---- C:\Windows\system32\ci.dll
2012-05-17 11:46:16 ----A---- C:\Windows\SYSWOW64\sqlsrv32.dll
2012-05-17 11:46:16 ----A---- C:\Windows\system32\drivers\msdsm.sys
2012-05-17 11:46:15 ----A---- C:\Windows\system32\wcncsvc.dll
2012-05-17 11:46:15 ----A---- C:\Windows\system32\upnp.dll
2012-05-17 11:46:15 ----A---- C:\Windows\system32\mprapi.dll
Logfile of random's system information tool 1.09 (written by random/random)
Run by Tom at 2012-07-11 19:39:29
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 4 GB (12%) free of 31 GB
Total RAM: 2006 MB (29% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:39:44, on 11.7.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Tom.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Tom\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {816BE035-1450-40D0-8A3B-BA7825A83A77} (IASRunner Class) - http://support.lenovo.com/Resources/Len ... etect2.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Unknown owner - C:\Windows\system32\AEADISRV.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Lenovo Doze Mode Service (DozeSvc) - Lenovo. - C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cisco EnergyWise Enabler (PwmEWSvc) - Lenovo Group Limited - C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)
--
End of file - 10508 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-aa08c705-162c-47d8-8d2e-f3df9db8519e -SystemEventPortName:HostProcess-99806327-6db9-49c8-aa87-94c4cc146d78 -IoCancelEventPortName:HostProcess-e2f14876-5474-410a-9354-2d8a13d2037f -NonStateChangingEventPortName:HostProcess-2f067386-8de5-4d5e-b3ba-89e43efc1fa4 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:7a7e2440-00f1-4c50-a440-c74a1643706f
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\WLANExt.exe 24685744
\??\C:\Windows\system32\conhost.exe "2026204343-1582324584656782472616727084-649726411137039322447095992-1457329553
"C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\AEADISRV.EXE
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\DRIVERS\xaudio64.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"taskhost.exe"
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe"
"C:\Program Files\Lenovo\Zoom\TpScrex.exe"
C:\Windows\system32\igfxext.exe -Embedding
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\TpShocks.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe"
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe"
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Windows\system32\igfxext.exe -Embedding
"C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE"
"C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe" -CtxID "#Hewlett-Packard#hp psc 1310 series#1338998168" -Startup
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe" -Embedding
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe" -Embedding
"C:\Program Files (x86)\Lenovo\System Update\SUService.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"taskhost.exe"
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --extension-process --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.0.1299991171\647181662" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --extension-process --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.2.1838172971\724005046" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.3.1980022217\2097728874" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.4.1846849285\1204767279" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.5.1342774967\93363410" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.6.100831398\991015969" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.7.1730759798\1272731160" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.8.1682045023\1142580100" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.9.815049710\1347908251" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2584.10.242993328\805475195" /prefetch:12
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.11.1633320949\1574081156" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.12.289187858\1422252698" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.13.625965586\1850747544" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.14.1350940555\1946262654" /prefetch:3
C:\Windows\system32\rundll32.exe "C:\Users\Tom\AppData\Local\Google\Chrome\APPLIC~1\200113~1.47\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Tom\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll" --lang=cs --channel="2584.16.235564512\1184146762" --flash-broker=5316 /prefetch:4
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.19.1572352751\968195120" /prefetch:3
"C:\Users\Tom\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/SILENT/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight1.0/OmniboxSearchSuggest/15/Prerender/ContentPrefetchPrerender2/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/spdy3/UMA-Uniformity-Trial-1-Percent/group_84/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --disable-accelerated-2d-canvas --channel="2584.21.1956068844\1643355534" /prefetch:3
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe84_ Global\UsGthrCtrlFltPipeMssGthrPipe84 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\AUDIODG.EXE 0x2c4
"C:\Users\Tom\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1476183158-4169381185-3047861550-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1476183158-4169381185-3047861550-1001UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-07-03 1387952]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20 328248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-05-04 453504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-07-03 1160792]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-05-04 157576]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20 509496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-07-03 1387952]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-07-03 1160792]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-12-23 2868496]
"PSQLLauncher"=C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe [2011-07-14 85832]
"TpShocks"=C:\Windows\system32\TpShocks.exe [2011-03-29 380776]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-30 165912]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-30 385560]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-30 363544]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Tom\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-15 116648]
"GoogleDriveSync"=C:\Program Files (x86)\Google\Drive\googledrivesync.exe [2012-06-20 12163848]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-04-17 3671872]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-07-03 4273976]
"SoundMAXPnP"=C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [2009-05-18 1314816]
"PWMTRV"=rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]
"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"hpqSRMon"=C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [2008-07-22 150528]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-08-06 260608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll [2011-07-14 136008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableCAD"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 3 months======
2012-07-11 19:39:32 ----D---- C:\Program Files\trend micro
2012-07-11 19:39:29 ----D---- C:\rsit
2012-07-10 14:51:04 ----D---- C:\Users\Tom\AppData\Roaming\wargaming.net
2012-07-09 06:41:46 ----D---- C:\Users\Tom\AppData\Roaming\JGoodies
2012-07-09 06:40:48 ----D---- C:\Program Files (x86)\JGoodies
2012-07-09 06:29:54 ----D---- C:\Program Files (x86)\Intel
2012-07-09 06:29:54 ----A---- C:\Windows\SYSWOW64\CSVer.dll
2012-07-09 06:28:12 ----D---- C:\Windows\SYSWOW64\Lang
2012-07-09 06:27:56 ----D---- C:\Intel
2012-07-09 06:27:26 ----A---- C:\Windows\system32\igfxtray.exe
2012-07-09 06:27:25 ----A---- C:\Windows\system32\igfxsrvc.exe
2012-07-09 06:27:18 ----A---- C:\Windows\system32\igfxpers.exe
2012-07-09 06:27:18 ----A---- C:\Windows\system32\igfxext.exe
2012-07-09 06:27:17 ----A---- C:\Windows\system32\igfxcfg.exe
2012-07-09 06:27:04 ----A---- C:\Windows\system32\hkcmd.exe
2012-07-09 06:27:04 ----A---- C:\Windows\system32\difx64.exe
2012-07-09 06:27:03 ----D---- C:\DRIVERS
2012-07-06 13:24:00 ----D---- C:\Users\Tom\AppData\Roaming\FileZilla
2012-07-06 13:23:21 ----D---- C:\Program Files (x86)\FileZilla FTP Client
2012-07-05 21:14:29 ----D---- C:\Users\Tom\AppData\Roaming\Miranda
2012-07-05 21:14:09 ----D---- C:\Program Files (x86)\Miranda IM
2012-07-02 22:48:07 ----D---- C:\Users\Tom\AppData\Roaming\ImgBurn
2012-07-02 22:18:53 ----D---- C:\Program Files (x86)\ImgBurn
2012-07-02 20:57:21 ----D---- C:\Program Files (x86)\Oracle
2012-07-02 20:57:16 ----A---- C:\Windows\SYSWOW64\javaws.exe
2012-07-02 20:57:02 ----A---- C:\Windows\SYSWOW64\javaw.exe
2012-07-02 20:57:02 ----A---- C:\Windows\SYSWOW64\java.exe
2012-07-01 10:01:41 ----D---- C:\ProgramData\MindGems
2012-06-29 21:14:53 ----D---- C:\Users\Tom\AppData\Roaming\Aegisub
2012-06-29 21:14:24 ----D---- C:\Program Files (x86)\Aegisub
2012-06-24 13:04:05 ----A---- C:\Windows\system32\drivers\sptd.sys
2012-06-24 13:02:08 ----RHD---- C:\Users\Tom\AppData\Roaming\SecuROM
2012-06-24 13:02:05 ----A---- C:\Windows\SYSWOW64\CmdLineExt.dll
2012-06-24 12:59:01 ----D---- C:\Program Files (x86)\Ubisoft
2012-06-21 15:08:35 ----D---- C:\Program Files (x86)\Tropico
2012-06-19 19:45:06 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2012-06-19 19:45:06 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2012-06-19 19:45:06 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2012-06-19 19:45:06 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-06-19 19:45:06 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2012-06-19 19:45:06 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-06-19 19:45:05 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-06-19 19:45:05 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-06-19 19:45:05 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-06-19 19:45:04 ----A---- C:\Windows\system32\D3DX9_43.dll
2012-06-19 19:45:04 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-06-19 19:45:03 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2012-06-19 19:45:03 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2012-06-19 19:45:03 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-06-19 19:45:03 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-06-19 19:45:02 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2012-06-19 19:45:02 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-06-19 19:45:01 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2012-06-19 19:45:01 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2012-06-19 19:44:59 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2012-06-19 19:44:59 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-06-19 19:44:58 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2012-06-19 19:44:58 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-06-19 19:44:57 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2012-06-19 19:44:57 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-06-19 19:44:50 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2012-06-19 19:44:50 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2012-06-19 19:44:50 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-06-19 19:44:50 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-06-19 19:44:49 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-06-19 19:44:49 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2012-06-19 19:44:49 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-06-19 19:44:49 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-06-19 19:44:48 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2012-06-19 19:44:48 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2012-06-19 19:44:48 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-06-19 19:44:48 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-06-19 19:44:47 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2012-06-19 19:44:47 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-06-19 19:44:46 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2012-06-19 19:44:46 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2012-06-19 19:44:46 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2012-06-19 19:44:46 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-06-19 19:44:46 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-06-19 19:44:46 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-06-19 19:44:45 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2012-06-19 19:44:45 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-06-19 19:44:45 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-06-19 19:44:45 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-06-19 19:44:45 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-06-19 19:44:45 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-06-19 19:44:44 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2012-06-19 19:44:44 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2012-06-19 19:44:44 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-06-19 19:44:44 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-06-19 19:44:44 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-06-19 19:44:44 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-06-19 19:44:43 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2012-06-19 19:44:43 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-06-19 19:44:42 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2012-06-19 19:44:42 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2012-06-19 19:44:42 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2012-06-19 19:44:42 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2012-06-19 19:44:42 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-06-19 19:44:42 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-06-19 19:44:42 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-06-19 19:44:42 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-06-19 19:44:41 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2012-06-19 19:44:41 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2012-06-19 19:44:41 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-06-19 19:44:41 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-06-19 19:44:40 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2012-06-19 19:44:40 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2012-06-19 19:44:40 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-06-19 19:44:40 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-06-19 19:44:39 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2012-06-19 19:44:39 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2012-06-19 19:44:39 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-06-19 19:44:39 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-06-19 19:44:38 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2012-06-19 19:44:38 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2012-06-19 19:44:38 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2012-06-19 19:44:38 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-06-19 19:44:38 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-06-19 19:44:38 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-06-19 19:44:37 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2012-06-19 19:44:37 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-06-19 19:44:36 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2012-06-19 19:44:36 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2012-06-19 19:44:36 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2012-06-19 19:44:36 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-06-19 19:44:36 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-06-19 19:44:36 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-06-19 19:44:35 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2012-06-19 19:44:35 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2012-06-19 19:44:35 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-06-19 19:44:35 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-06-19 19:44:34 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2012-06-19 19:44:34 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2012-06-19 19:44:34 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-06-19 19:44:34 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-06-19 19:44:32 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2012-06-19 19:44:32 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2012-06-19 19:44:32 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2012-06-19 19:44:32 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-06-19 19:44:32 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-06-19 19:44:32 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-06-19 19:44:31 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2012-06-19 19:44:31 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-06-19 19:44:30 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2012-06-19 19:44:30 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2012-06-19 19:44:30 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-06-19 19:44:30 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-06-19 19:44:28 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2012-06-19 19:44:28 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2012-06-19 19:44:28 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2012-06-19 19:44:28 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-06-19 19:44:28 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2012-06-19 19:44:28 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-06-19 19:44:27 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2012-06-19 19:44:27 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2012-06-19 19:44:27 ----A---- C:\Windows\system32\d3dx10_34.dll
2012-06-19 19:44:27 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2012-06-19 19:44:26 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2012-06-19 19:44:26 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2012-06-19 19:44:26 ----A---- C:\Windows\system32\xinput1_3.dll
2012-06-19 19:44:26 ----A---- C:\Windows\system32\d3dx9_34.dll
2012-06-19 19:44:25 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2012-06-19 19:44:25 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2012-06-19 19:44:25 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2012-06-19 19:44:25 ----A---- C:\Windows\system32\xactengine2_7.dll
2012-06-19 19:44:25 ----A---- C:\Windows\system32\d3dx10_33.dll
2012-06-19 19:44:25 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2012-06-19 19:44:24 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2012-06-19 19:44:24 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2012-06-19 19:44:24 ----A---- C:\Windows\system32\xactengine2_6.dll
2012-06-19 19:44:24 ----A---- C:\Windows\system32\d3dx9_33.dll
2012-06-19 19:44:22 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2012-06-19 19:44:22 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2012-06-19 19:44:22 ----A---- C:\Windows\system32\xactengine2_5.dll
2012-06-19 19:44:22 ----A---- C:\Windows\system32\d3dx10.dll
2012-06-19 19:44:21 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2012-06-19 19:44:21 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2012-06-19 19:44:21 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2012-06-19 19:44:21 ----A---- C:\Windows\system32\xactengine2_4.dll
2012-06-19 19:44:21 ----A---- C:\Windows\system32\x3daudio1_1.dll
2012-06-19 19:44:21 ----A---- C:\Windows\system32\d3dx9_32.dll
2012-06-19 19:44:20 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2012-06-19 19:44:20 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2012-06-19 19:44:20 ----A---- C:\Windows\system32\xactengine2_3.dll
2012-06-19 19:44:20 ----A---- C:\Windows\system32\d3dx9_31.dll
2012-06-19 19:44:19 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2012-06-19 19:44:19 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2012-06-19 19:44:19 ----A---- C:\Windows\system32\xinput1_2.dll
2012-06-19 19:44:19 ----A---- C:\Windows\system32\xactengine2_2.dll
2012-06-19 19:44:18 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2012-06-19 19:44:18 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2012-06-19 19:44:18 ----A---- C:\Windows\system32\xinput1_1.dll
2012-06-19 19:44:18 ----A---- C:\Windows\system32\xactengine2_1.dll
2012-06-19 19:44:16 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2012-06-19 19:44:16 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2012-06-19 19:44:16 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2012-06-19 19:44:16 ----A---- C:\Windows\system32\xactengine2_0.dll
2012-06-19 19:44:16 ----A---- C:\Windows\system32\x3daudio1_0.dll
2012-06-19 19:44:16 ----A---- C:\Windows\system32\d3dx9_30.dll
2012-06-19 19:44:15 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2012-06-19 19:44:15 ----A---- C:\Windows\system32\d3dx9_29.dll
2012-06-19 19:44:14 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2012-06-19 19:44:14 ----A---- C:\Windows\system32\d3dx9_28.dll
2012-06-19 19:44:13 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2012-06-19 19:44:13 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2012-06-19 19:44:13 ----A---- C:\Windows\system32\d3dx9_27.dll
2012-06-19 19:44:13 ----A---- C:\Windows\system32\d3dx9_26.dll
2012-06-19 19:44:12 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2012-06-19 19:44:12 ----A---- C:\Windows\system32\d3dx9_25.dll
2012-06-19 19:44:10 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2012-06-19 19:44:10 ----A---- C:\Windows\system32\d3dx9_24.dll
2012-06-19 19:40:24 ----D---- C:\Windows\SYSWOW64\directx
2012-06-19 19:30:04 ----A---- C:\Windows\ipuninst.exe
2012-06-19 19:29:31 ----D---- C:\Program Files\BlackIsle
2012-06-19 19:27:35 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2012-06-19 19:27:29 ----D---- C:\Users\Tom\AppData\Roaming\DAEMON Tools Lite
2012-06-19 19:27:11 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2012-06-19 19:26:45 ----D---- C:\ProgramData\DAEMON Tools Lite
2012-06-19 08:13:59 ----A---- C:\Windows\system32\wups2.dll
2012-06-19 08:13:59 ----A---- C:\Windows\system32\wucltux.dll
2012-06-19 08:13:59 ----A---- C:\Windows\system32\wuaueng.dll
2012-06-19 08:13:59 ----A---- C:\Windows\system32\wuauclt.exe
2012-06-19 08:13:48 ----A---- C:\Windows\system32\wups.dll
2012-06-19 08:13:48 ----A---- C:\Windows\system32\wudriver.dll
2012-06-19 08:13:48 ----A---- C:\Windows\system32\wuapi.dll
2012-06-19 08:13:36 ----A---- C:\Windows\system32\wuwebv.dll
2012-06-19 08:13:35 ----A---- C:\Windows\system32\wuapp.exe
2012-06-13 21:49:38 ----A---- C:\Windows\system32\mshtmled.dll
2012-06-13 21:49:37 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-06-13 21:49:36 ----A---- C:\Windows\SYSWOW64\url.dll
2012-06-13 21:49:36 ----A---- C:\Windows\system32\url.dll
2012-06-13 21:49:35 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-06-13 21:49:34 ----A---- C:\Windows\system32\urlmon.dll
2012-06-13 21:49:33 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-06-13 21:49:33 ----A---- C:\Windows\system32\iertutil.dll
2012-06-13 21:49:32 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-06-13 21:49:32 ----A---- C:\Windows\system32\ieui.dll
2012-06-13 21:49:31 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2012-06-13 21:49:31 ----A---- C:\Windows\system32\ieUnatt.exe
2012-06-13 21:49:30 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-06-13 21:49:30 ----A---- C:\Windows\system32\wininet.dll
2012-06-13 21:49:29 ----A---- C:\Windows\system32\jsproxy.dll
2012-06-13 21:49:27 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-06-13 21:49:27 ----A---- C:\Windows\system32\jscript9.dll
2012-06-13 21:49:26 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-06-13 21:49:26 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-06-13 21:49:26 ----A---- C:\Windows\system32\jscript.dll
2012-06-13 21:49:22 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-06-13 21:49:20 ----A---- C:\Windows\system32\mshtml.dll
2012-06-13 21:49:18 ----A---- C:\Windows\system32\ieframe.dll
2012-06-13 21:49:16 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-06-13 20:35:34 ----A---- C:\Windows\system32\rdpwsx.dll
2012-06-13 20:35:34 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-06-13 20:35:33 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-06-13 20:35:18 ----A---- C:\Windows\system32\profsvc.dll
2012-06-13 20:35:00 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-06-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2012-06-13 20:34:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2012-06-13 20:34:55 ----A---- C:\Windows\system32\win32k.sys
2012-06-13 20:34:51 ----A---- C:\Windows\system32\rdpcorets.dll
2012-06-13 20:34:49 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2012-06-13 20:34:32 ----A---- C:\Windows\system32\msi.dll
2012-06-13 20:34:31 ----A---- C:\Windows\SYSWOW64\msi.dll
2012-06-13 20:34:27 ----A---- C:\Windows\system32\crypt32.dll
2012-06-13 20:34:26 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2012-06-13 20:34:26 ----A---- C:\Windows\system32\cryptsvc.dll
2012-06-13 20:34:25 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2012-06-13 20:34:25 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2012-06-13 20:34:25 ----A---- C:\Windows\system32\cryptnet.dll
2012-06-06 17:58:14 ----D---- C:\ProgramData\WEBREG
2012-06-06 17:58:13 ----D---- C:\Users\Tom\AppData\Roaming\HP
2012-06-06 15:18:31 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2012-06-06 15:18:31 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2012-06-06 15:18:31 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2012-06-06 15:18:31 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-06-06 15:18:30 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-06-06 15:12:37 ----D---- C:\Program Files (x86)\Room Arranger
2012-06-03 17:41:15 ----D---- C:\Program Files (x86)\uTorrent
2012-06-03 17:40:30 ----D---- C:\Users\Tom\AppData\Roaming\uTorrent
2012-06-01 14:42:33 ----D---- C:\Users\Tom\AppData\Roaming\Audacity
2012-06-01 14:42:21 ----D---- C:\Program Files (x86)\Audacity
2012-06-01 14:40:06 ----D---- C:\Program Files\GIMP 2
2012-05-30 15:17:28 ----D---- C:\Program Files (x86)\MSXML 4.0
2012-05-28 16:04:36 ----D---- C:\ProgramData\HP Product Assistant
2012-05-28 16:04:00 ----D---- C:\Windows\SYSWOW64\spool
2012-05-28 16:03:14 ----D---- C:\Windows\SYSWOW64\Macromed
2012-05-28 15:59:14 ----D---- C:\Program Files (x86)\HP
2012-05-28 15:59:12 ----HD---- C:\Config.Msi
2012-05-28 15:57:05 ----D---- C:\Program Files\HP
2012-05-28 15:56:14 ----N---- C:\Windows\hpomdl19.dat
2012-05-28 15:56:14 ----A---- C:\Windows\hpoins19.dat
2012-05-28 15:55:47 ----A---- C:\Windows\system32\hpzids40.dll
2012-05-28 15:55:41 ----A---- C:\Windows\system32\hpowiav1.dll
2012-05-28 15:55:41 ----A---- C:\Windows\system32\hpovst01.dll
2012-05-28 15:55:41 ----A---- C:\Windows\system32\hpotscl1.dll
2012-05-28 15:55:40 ----A---- C:\Windows\system32\hpotiop1.dll
2012-05-28 15:37:14 ----D---- C:\ProgramData\HP
2012-05-27 22:52:59 ----D---- C:\Users\Tom\AppData\Roaming\.minecraft
2012-05-27 22:49:15 ----D---- C:\ProgramData\Sun
2012-05-27 22:48:34 ----A---- C:\Windows\SYSWOW64\npDeployJava1.dll
2012-05-27 22:48:34 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2012-05-27 22:48:02 ----D---- C:\Program Files (x86)\Java
2012-05-23 17:16:49 ----D---- C:\Program Files (x86)\Google
2012-05-22 19:19:57 ----D---- C:\Users\Tom\AppData\Roaming\vlc
2012-05-20 19:02:00 ----D---- C:\Users\Tom\AppData\Roaming\WinRAR
2012-05-20 19:01:51 ----D---- C:\Program Files\WinRAR
2012-05-18 13:28:01 ----A---- C:\Windows\system32\drivers\Axtmvprt.sys
2012-05-18 13:28:01 ----A---- C:\Windows\system32\drivers\Axtmvmdm.sys
2012-05-18 13:28:01 ----A---- C:\Windows\system32\drivers\Axtmvflt.sys
2012-05-18 13:27:56 ----D---- C:\Program Files\Axesstel
2012-05-17 18:17:18 ----A---- C:\Windows\system32\drivers\usbohci.sys
2012-05-17 18:17:17 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2012-05-17 18:17:17 ----A---- C:\Windows\system32\drivers\usbport.sys
2012-05-17 18:17:17 ----A---- C:\Windows\system32\drivers\usbehci.sys
2012-05-17 18:17:17 ----A---- C:\Windows\system32\drivers\usbd.sys
2012-05-17 18:17:17 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2012-05-17 18:17:16 ----A---- C:\Windows\system32\drivers\usbhub.sys
2012-05-17 18:08:14 ----A---- C:\Windows\system32\drivers\ndis.sys
2012-05-17 14:36:16 ----D---- C:\Windows\system32\SPReview
2012-05-17 12:43:43 ----D---- C:\Windows\CheckSur
2012-05-17 12:00:35 ----D---- C:\Windows\system32\EventProviders
2012-05-17 11:50:00 ----A---- C:\Windows\system32\netfxperf.dll
2012-05-17 11:49:59 ----A---- C:\Windows\system32\dfshim.dll
2012-05-17 11:49:44 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2012-05-17 11:49:37 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2012-05-17 11:49:37 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2012-05-17 11:49:36 ----A---- C:\Windows\system32\mstscax.dll
2012-05-17 11:49:36 ----A---- C:\Windows\system32\d3d10warp.dll
2012-05-17 11:49:30 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2012-05-17 11:49:25 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2012-05-17 11:49:24 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2012-05-17 11:49:23 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2012-05-17 11:49:23 ----A---- C:\Windows\system32\tssrvlic.dll
2012-05-17 11:49:23 ----A---- C:\Windows\system32\sysmain.dll
2012-05-17 11:49:23 ----A---- C:\Windows\system32\RDVGHelper.exe
2012-05-17 11:49:20 ----A---- C:\Windows\SYSWOW64\pmcsnap.dll
2012-05-17 11:49:19 ----A---- C:\Windows\system32\MSVidCtl.dll
2012-05-17 11:49:12 ----A---- C:\Windows\system32\mscoree.dll
2012-05-17 11:49:11 ----A---- C:\Windows\system32\mmcndmgr.dll
2012-05-17 11:49:09 ----A---- C:\Windows\system32\secproc_isv.dll
2012-05-17 11:49:09 ----A---- C:\Windows\system32\mf.dll
2012-05-17 11:49:08 ----A---- C:\Windows\system32\RMActivate_isv.exe
2012-05-17 11:49:07 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2012-05-17 11:49:07 ----A---- C:\Windows\system32\secproc.dll
2012-05-17 11:49:07 ----A---- C:\Windows\system32\RMActivate.exe
2012-05-17 11:49:06 ----A---- C:\Windows\system32\xpsservices.dll
2012-05-17 11:49:03 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2012-05-17 11:49:02 ----A---- C:\Windows\SYSWOW64\secproc.dll
2012-05-17 11:49:02 ----A---- C:\Windows\system32\rpcrt4.dll
2012-05-17 11:49:00 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2012-05-17 11:48:59 ----A---- C:\Windows\SYSWOW64\PushPrinterConnections.exe
2012-05-17 11:48:59 ----A---- C:\Windows\SYSWOW64\ppcsnap.dll
2012-05-17 11:48:58 ----A---- C:\Windows\system32\schedsvc.dll
2012-05-17 11:48:58 ----A---- C:\Windows\system32\ole32.dll
2012-05-17 11:48:52 ----A---- C:\Windows\system32\spwizui.dll
2012-05-17 11:48:50 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2012-05-17 11:48:46 ----A---- C:\Windows\system32\taskschd.dll
2012-05-17 11:48:45 ----A---- C:\Windows\system32\RacEngn.dll
2012-05-17 11:48:45 ----A---- C:\Windows\system32\diagperf.dll
2012-05-17 11:48:44 ----A---- C:\Windows\system32\wevtsvc.dll
2012-05-17 11:48:43 ----A---- C:\Windows\SYSWOW64\mf.dll
2012-05-17 11:48:43 ----A---- C:\Windows\system32\ExplorerFrame.dll
2012-05-17 11:48:41 ----A---- C:\Windows\system32\vssapi.dll
2012-05-17 11:48:41 ----A---- C:\Windows\system32\msxml3.dll
2012-05-17 11:48:39 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2012-05-17 11:48:38 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2012-05-17 11:48:37 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2012-05-17 11:48:35 ----A---- C:\Windows\system32\UIRibbon.dll
2012-05-17 11:48:35 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2012-05-17 11:48:25 ----A---- C:\Windows\system32\WsmSvc.dll
2012-05-17 11:48:24 ----A---- C:\Windows\system32\WMVCORE.DLL
2012-05-17 11:48:23 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2012-05-17 11:48:23 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2012-05-17 11:48:22 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2012-05-17 11:48:21 ----A---- C:\Windows\system32\PresentationHost.exe
2012-05-17 11:48:20 ----A---- C:\Windows\system32\rdpdd.dll
2012-05-17 11:48:19 ----A---- C:\Windows\system32\MPSSVC.dll
2012-05-17 11:48:18 ----A---- C:\Windows\system32\spreview.exe
2012-05-17 11:48:18 ----A---- C:\Windows\system32\spinstall.exe
2012-05-17 11:48:17 ----A---- C:\Windows\system32\CertEnroll.dll
2012-05-17 11:48:15 ----A---- C:\Windows\system32\WinSAT.exe
2012-05-17 11:48:11 ----A---- C:\Windows\system32\WMVDECOD.DLL
2012-05-17 11:48:09 ----A---- C:\Windows\system32\d3d9.dll
2012-05-17 11:48:08 ----A---- C:\Windows\system32\msxml6.dll
2012-05-17 11:48:07 ----A---- C:\Windows\SYSWOW64\RacEngn.dll
2012-05-17 11:48:07 ----A---- C:\Windows\system32\IKEEXT.DLL
2012-05-17 11:48:06 ----A---- C:\Windows\system32\SearchFolder.dll
2012-05-17 11:48:05 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2012-05-17 11:48:04 ----A---- C:\Windows\SYSWOW64\AuthFWSnapin.dll
2012-05-17 11:48:00 ----A---- C:\Windows\system32\gpsvc.dll
2012-05-17 11:47:57 ----A---- C:\Windows\system32\VSSVC.exe
2012-05-17 11:47:55 ----A---- C:\Windows\system32\dwmcore.dll
2012-05-17 11:47:54 ----A---- C:\Windows\system32\dbgeng.dll
2012-05-17 11:47:53 ----A---- C:\Windows\system32\drivers\http.sys
2012-05-17 11:47:51 ----A---- C:\Windows\SYSWOW64\rdvgumd32.dll
2012-05-17 11:47:48 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2012-05-17 11:47:45 ----A---- C:\Windows\SYSWOW64\ole32.dll
2012-05-17 11:47:45 ----A---- C:\Windows\system32\TSWorkspace.dll
2012-05-17 11:47:45 ----A---- C:\Windows\system32\actxprxy.dll
2012-05-17 11:47:44 ----A---- C:\Windows\system32\audiosrv.dll
2012-05-17 11:47:43 ----A---- C:\Windows\system32\qmgr.dll
2012-05-17 11:47:41 ----A---- C:\Windows\system32\gpprefcl.dll
2012-05-17 11:47:40 ----A---- C:\Windows\system32\termsrv.dll
2012-05-17 11:47:39 ----A---- C:\Windows\system32\mstsc.exe
2012-05-17 11:47:37 ----A---- C:\Windows\system32\netlogon.dll
2012-05-17 11:47:37 ----A---- C:\Windows\system32\imapi2fs.dll
2012-05-17 11:47:36 ----A---- C:\Windows\SYSWOW64\vssapi.dll
2012-05-17 11:47:36 ----A---- C:\Windows\system32\winhttp.dll
2012-05-17 11:47:36 ----A---- C:\Windows\system32\d3d11.dll
2012-05-17 11:47:35 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2012-05-17 11:47:35 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2012-05-17 11:47:35 ----A---- C:\Windows\system32\msv1_0.dll
2012-05-17 11:47:34 ----A---- C:\Windows\system32\QAGENTRT.DLL
2012-05-17 11:47:34 ----A---- C:\Windows\system32\propsys.dll
2012-05-17 11:47:33 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2012-05-17 11:47:33 ----A---- C:\Windows\system32\wbengine.exe
2012-05-17 11:47:33 ----A---- C:\Windows\system32\setupapi.dll
2012-05-17 11:47:33 ----A---- C:\Windows\system32\rpcss.dll
2012-05-17 11:47:33 ----A---- C:\Windows\system32\PushPrinterConnections.exe
2012-05-17 11:47:31 ----A---- C:\Windows\system32\authui.dll
2012-05-17 11:47:30 ----A---- C:\Windows\system32\werconcpl.dll
2012-05-17 11:47:30 ----A---- C:\Windows\system32\taskeng.exe
2012-05-17 11:47:30 ----A---- C:\Windows\system32\odbc32.dll
2012-05-17 11:47:25 ----A---- C:\Windows\system32\user32.dll.bak
2012-05-17 11:47:25 ----A---- C:\Windows\system32\user32.dll
2012-05-17 11:47:24 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2012-05-17 11:47:24 ----A---- C:\Windows\system32\WSDApi.dll
2012-05-17 11:47:24 ----A---- C:\Windows\system32\drivers\netio.sys
2012-05-17 11:47:23 ----A---- C:\Windows\system32\umrdp.dll
2012-05-17 11:47:23 ----A---- C:\Windows\system32\LSCSHostPolicy.dll
2012-05-17 11:47:23 ----A---- C:\Windows\system32\drivers\tdx.sys
2012-05-17 11:47:23 ----A---- C:\Windows\system32\dhcpcore.dll
2012-05-17 11:47:23 ----A---- C:\Windows\system32\certmgr.dll
2012-05-17 11:47:22 ----A---- C:\Windows\SYSWOW64\wer.dll
2012-05-17 11:47:22 ----A---- C:\Windows\system32\scavengeui.dll
2012-05-17 11:47:22 ----A---- C:\Windows\system32\drivers\netbt.sys
2012-05-17 11:47:21 ----A---- C:\Windows\SYSWOW64\certcli.dll
2012-05-17 11:47:21 ----A---- C:\Windows\system32\tsmf.dll
2012-05-17 11:47:21 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2012-05-17 11:47:21 ----A---- C:\Windows\system32\localspl.dll
2012-05-17 11:47:20 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2012-05-17 11:47:20 ----A---- C:\Windows\system32\ncsi.dll
2012-05-17 11:47:20 ----A---- C:\Windows\system32\msdrm.dll
2012-05-17 11:47:19 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2012-05-17 11:47:19 ----A---- C:\Windows\system32\shlwapi.dll
2012-05-17 11:47:19 ----A---- C:\Windows\system32\msdtctm.dll
2012-05-17 11:47:19 ----A---- C:\Windows\system32\framedynos.dll
2012-05-17 11:47:18 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2012-05-17 11:47:18 ----A---- C:\Windows\system32\rdpshell.exe
2012-05-17 11:47:18 ----A---- C:\Windows\system32\netshell.dll
2012-05-17 11:47:17 ----A---- C:\Windows\SYSWOW64\tcpmonui.dll
2012-05-17 11:47:17 ----A---- C:\Windows\system32\wmicmiplugin.dll
2012-05-17 11:47:17 ----A---- C:\Windows\system32\netcfgx.dll
2012-05-17 11:47:16 ----A---- C:\Windows\system32\ws2_32.dll
2012-05-17 11:47:16 ----A---- C:\Windows\system32\winlogon.exe
2012-05-17 11:47:16 ----A---- C:\Windows\system32\usp10.dll
2012-05-17 11:47:16 ----A---- C:\Windows\system32\nlasvc.dll
2012-05-17 11:47:16 ----A---- C:\Windows\system32\appmgr.dll
2012-05-17 11:47:15 ----A---- C:\Windows\system32\lsm.exe
2012-05-17 11:47:15 ----A---- C:\Windows\system32\dxgi.dll
2012-05-17 11:47:15 ----A---- C:\Windows\system32\drivers\csc.sys
2012-05-17 11:47:15 ----A---- C:\Windows\system32\comdlg32.dll
2012-05-17 11:47:14 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2012-05-17 11:47:14 ----A---- C:\Windows\system32\Query.dll
2012-05-17 11:47:14 ----A---- C:\Windows\system32\mswsock.dll
2012-05-17 11:47:14 ----A---- C:\Windows\system32\apphelp.dll
2012-05-17 11:47:13 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2012-05-17 11:47:13 ----A---- C:\Windows\SYSWOW64\dot3api.dll
2012-05-17 11:47:13 ----A---- C:\Windows\system32\wpdshext.dll
2012-05-17 11:47:13 ----A---- C:\Windows\system32\drvstore.dll
2012-05-17 11:47:13 ----A---- C:\Windows\system32\azroles.dll
2012-05-17 11:47:11 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2012-05-17 11:47:11 ----A---- C:\Windows\SYSWOW64\setupapi.dll
2012-05-17 11:47:11 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2012-05-17 11:47:11 ----A---- C:\Windows\system32\Vault.dll
2012-05-17 11:47:11 ----A---- C:\Windows\system32\QAGENT.DLL
2012-05-17 11:47:11 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2012-05-17 11:47:11 ----A---- C:\Windows\system32\BFE.DLL
2012-05-17 11:47:10 ----A---- C:\Windows\system32\samsrv.dll
2012-05-17 11:47:10 ----A---- C:\Windows\system32\DShowRdpFilter.dll
2012-05-17 11:47:10 ----A---- C:\Windows\system32\cmd.exe
2012-05-17 11:47:09 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2012-05-17 11:47:09 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2012-05-17 11:47:09 ----A---- C:\Windows\system32\win32spl.dll
2012-05-17 11:47:09 ----A---- C:\Windows\system32\lpksetup.exe
2012-05-17 11:47:08 ----A---- C:\Windows\SYSWOW64\netlogon.dll
2012-05-17 11:47:08 ----A---- C:\Windows\system32\cscsvc.dll
2012-05-17 11:47:07 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2012-05-17 11:47:07 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2012-05-17 11:47:07 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2012-05-17 11:47:07 ----A---- C:\Windows\system32\rdpclip.exe
2012-05-17 11:47:06 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2012-05-17 11:47:06 ----A---- C:\Windows\system32\WebClnt.dll
2012-05-17 11:47:05 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2012-05-17 11:47:05 ----A---- C:\Windows\SYSWOW64\Query.dll
2012-05-17 11:47:05 ----A---- C:\Windows\SYSWOW64\gpprefcl.dll
2012-05-17 11:47:05 ----A---- C:\Windows\system32\Wldap32.dll
2012-05-17 11:47:05 ----A---- C:\Windows\system32\WindowsCodecs.dll
2012-05-17 11:47:05 ----A---- C:\Windows\system32\sxs.dll
2012-05-17 11:47:05 ----A---- C:\Windows\system32\mcbuilder.exe
2012-05-17 11:47:05 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2012-05-17 11:47:05 ----A---- C:\Windows\system32\cscobj.dll
2012-05-17 11:47:04 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2012-05-17 11:47:04 ----A---- C:\Windows\system32\taskcomp.dll
2012-05-17 11:47:04 ----A---- C:\Windows\system32\mfds.dll
2012-05-17 11:47:03 ----A---- C:\Windows\SYSWOW64\upnp.dll
2012-05-17 11:47:03 ----A---- C:\Windows\SYSWOW64\mmcndmgr.dll
2012-05-17 11:47:03 ----A---- C:\Windows\SYSWOW64\DShowRdpFilter.dll
2012-05-17 11:47:03 ----A---- C:\Windows\system32\pnidui.dll
2012-05-17 11:47:03 ----A---- C:\Windows\system32\ipsmsnap.dll
2012-05-17 11:47:03 ----A---- C:\Windows\system32\hgprint.dll
2012-05-17 11:47:02 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2012-05-17 11:47:02 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2012-05-17 11:47:02 ----A---- C:\Windows\system32\webservices.dll
2012-05-17 11:47:02 ----A---- C:\Windows\system32\SessEnv.dll
2012-05-17 11:47:02 ----A---- C:\Windows\system32\rdpendp.dll
2012-05-17 11:47:01 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2012-05-17 11:47:01 ----A---- C:\Windows\SYSWOW64\imapi2fs.dll
2012-05-17 11:47:01 ----A---- C:\Windows\SYSWOW64\authui.dll
2012-05-17 11:47:01 ----A---- C:\Windows\system32\winsta.dll
2012-05-17 11:47:01 ----A---- C:\Windows\system32\spoolsv.exe
2012-05-17 11:47:00 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2012-05-17 11:47:00 ----A---- C:\Windows\system32\sqlsrv32.dll
2012-05-17 11:47:00 ----A---- C:\Windows\system32\fveapi.dll
2012-05-17 11:47:00 ----A---- C:\Windows\system32\dot3api.dll
2012-05-17 11:46:59 ----A---- C:\Windows\SYSWOW64\usp10.dll
2012-05-17 11:46:59 ----A---- C:\Windows\SYSWOW64\shlwapi.dll
2012-05-17 11:46:59 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2012-05-17 11:46:58 ----A---- C:\Windows\SYSWOW64\mcbuilder.exe
2012-05-17 11:46:58 ----A---- C:\Windows\system32\prncache.dll
2012-05-17 11:46:58 ----A---- C:\Windows\system32\gdi32.dll
2012-05-17 11:46:58 ----A---- C:\Windows\system32\drivers\volsnap.sys
2012-05-17 11:46:58 ----A---- C:\Windows\system32\drivers\msrpc.sys
2012-05-17 11:46:57 ----A---- C:\Windows\system32\schtasks.exe
2012-05-17 11:46:56 ----A---- C:\Windows\SYSWOW64\userenv.dll
2012-05-17 11:46:56 ----A---- C:\Windows\SYSWOW64\certmgr.dll
2012-05-17 11:46:56 ----A---- C:\Windows\system32\WMNetMgr.dll
2012-05-17 11:46:56 ----A---- C:\Windows\system32\wlanpref.dll
2012-05-17 11:46:56 ----A---- C:\Windows\system32\vpnike.dll
2012-05-17 11:46:55 ----A---- C:\Windows\SYSWOW64\xpsservices.dll
2012-05-17 11:46:55 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2012-05-17 11:46:55 ----A---- C:\Windows\SYSWOW64\drvstore.dll
2012-05-17 11:46:55 ----A---- C:\Windows\system32\userenv.dll
2012-05-17 11:46:55 ----A---- C:\Windows\system32\drivers\rdbss.sys
2012-05-17 11:46:54 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2012-05-17 11:46:54 ----A---- C:\Windows\system32\tspubwmi.dll
2012-05-17 11:46:54 ----A---- C:\Windows\system32\photowiz.dll
2012-05-17 11:46:54 ----A---- C:\Windows\system32\evr.dll
2012-05-17 11:46:54 ----A---- C:\Windows\system32\drivers\1394ohci.sys
2012-05-17 11:46:53 ----A---- C:\Windows\system32\IPSECSVC.DLL
2012-05-17 11:46:53 ----A---- C:\Windows\system32\framedyn.dll
2012-05-17 11:46:52 ----A---- C:\Windows\system32\FXSSVC.exe
2012-05-17 11:46:52 ----A---- C:\Windows\system32\AudioSes.dll
2012-05-17 11:46:51 ----A---- C:\Windows\SYSWOW64\cmd.exe
2012-05-17 11:46:51 ----A---- C:\Windows\system32\SyncCenter.dll
2012-05-17 11:46:51 ----A---- C:\Windows\system32\sppobjs.dll
2012-05-17 11:46:51 ----A---- C:\Windows\system32\aepdu.dll
2012-05-17 11:46:50 ----A---- C:\Windows\system32\mfreadwrite.dll
2012-05-17 11:46:49 ----A---- C:\Windows\system32\tscfgwmi.dll
2012-05-17 11:46:47 ----A---- C:\Windows\system32\srvsvc.dll
2012-05-17 11:46:45 ----A---- C:\Windows\system32\shsvcs.dll
2012-05-17 11:46:45 ----A---- C:\Windows\system32\rdpinit.exe
2012-05-17 11:46:45 ----A---- C:\Windows\system32\aeinv.dll
2012-05-17 11:46:43 ----A---- C:\Windows\SYSWOW64\framedynos.dll
2012-05-17 11:46:43 ----A---- C:\Windows\system32\vmicsvc.exe
2012-05-17 11:46:43 ----A---- C:\Windows\system32\fde.dll
2012-05-17 11:46:42 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2012-05-17 11:46:42 ----A---- C:\Windows\SYSWOW64\propsys.dll
2012-05-17 11:46:41 ----A---- C:\Windows\SYSWOW64\Wldap32.dll
2012-05-17 11:46:41 ----A---- C:\Windows\SYSWOW64\mfds.dll
2012-05-17 11:46:41 ----A---- C:\Windows\system32\WinSATAPI.dll
2012-05-17 11:46:41 ----A---- C:\Windows\system32\stobject.dll
2012-05-17 11:46:41 ----A---- C:\Windows\system32\imapi2.dll
2012-05-17 11:46:40 ----A---- C:\Windows\system32\localsec.dll
2012-05-17 11:46:39 ----A---- C:\Windows\system32\netdiagfx.dll
2012-05-17 11:46:39 ----A---- C:\Windows\system32\credui.dll
2012-05-17 11:46:38 ----A---- C:\Windows\SYSWOW64\rdpendp.dll
2012-05-17 11:46:38 ----A---- C:\Windows\system32\bcryptprimitives.dll
2012-05-17 11:46:37 ----A---- C:\Windows\SYSWOW64\user32.dll.bak
2012-05-17 11:46:37 ----A---- C:\Windows\SYSWOW64\user32.dll
2012-05-17 11:46:37 ----A---- C:\Windows\system32\iphlpsvc.dll
2012-05-17 11:46:37 ----A---- C:\Windows\system32\drivers\vmbus.sys
2012-05-17 11:46:37 ----A---- C:\Windows\system32\drivers\udfs.sys
2012-05-17 11:46:37 ----A---- C:\Windows\system32\cdd.dll
2012-05-17 11:46:36 ----A---- C:\Windows\system32\inetpp.dll
2012-05-17 11:46:35 ----A---- C:\Windows\system32\tcpipcfg.dll
2012-05-17 11:46:35 ----A---- C:\Windows\system32\QSHVHOST.DLL
2012-05-17 11:46:35 ----A---- C:\Windows\system32\netid.dll
2012-05-17 11:46:35 ----A---- C:\Windows\system32\drivers\fltMgr.sys
2012-05-17 11:46:34 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2012-05-17 11:46:34 ----A---- C:\Windows\SYSWOW64\azroles.dll
2012-05-17 11:46:34 ----A---- C:\Windows\system32\spp.dll
2012-05-17 11:46:34 ----A---- C:\Windows\system32\davclnt.dll
2012-05-17 11:46:34 ----A---- C:\Windows\system32\cscui.dll
2012-05-17 11:46:34 ----A---- C:\Windows\system32\biocpl.dll
2012-05-17 11:46:33 ----A---- C:\Windows\SYSWOW64\appmgr.dll
2012-05-17 11:46:33 ----A---- C:\Windows\system32\msinfo32.exe
2012-05-17 11:46:32 ----A---- C:\Windows\system32\gameux.dll
2012-05-17 11:46:31 ----A---- C:\Windows\system32\scansetting.dll
2012-05-17 11:46:31 ----A---- C:\Windows\system32\printui.dll
2012-05-17 11:46:30 ----A---- C:\Windows\SYSWOW64\themeui.dll
2012-05-17 11:46:30 ----A---- C:\Windows\SYSWOW64\credui.dll
2012-05-17 11:46:30 ----A---- C:\Windows\system32\pla.dll
2012-05-17 11:46:30 ----A---- C:\Windows\splwow64.exe
2012-05-17 11:46:29 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2012-05-17 11:46:29 ----A---- C:\Windows\SYSWOW64\spp.dll
2012-05-17 11:46:29 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2012-05-17 11:46:29 ----A---- C:\Windows\SYSWOW64\dhcpcore.dll
2012-05-17 11:46:29 ----A---- C:\Windows\system32\PhotoScreensaver.scr
2012-05-17 11:46:28 ----A---- C:\Windows\system32\wusa.exe
2012-05-17 11:46:28 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2012-05-17 11:46:28 ----A---- C:\Windows\system32\aitagent.exe
2012-05-17 11:46:27 ----A---- C:\Windows\system32\wiaservc.dll
2012-05-17 11:46:27 ----A---- C:\Windows\system32\vds.exe
2012-05-17 11:46:27 ----A---- C:\Windows\system32\drivers\pci.sys
2012-05-17 11:46:26 ----A---- C:\Windows\system32\AdmTmpl.dll
2012-05-17 11:46:25 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2012-05-17 11:46:25 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2012-05-17 11:46:25 ----A---- C:\Windows\SYSWOW64\basecsp.dll
2012-05-17 11:46:25 ----A---- C:\Windows\system32\rpchttp.dll
2012-05-17 11:46:25 ----A---- C:\Windows\system32\mscms.dll
2012-05-17 11:46:24 ----A---- C:\Windows\SYSWOW64\NaturalLanguage6.dll
2012-05-17 11:46:24 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2012-05-17 11:46:24 ----A---- C:\Windows\SYSWOW64\dbghelp.dll
2012-05-17 11:46:23 ----A---- C:\Windows\system32\PkgMgr.exe
2012-05-17 11:46:23 ----A---- C:\Windows\system32\FirewallControlPanel.dll
2012-05-17 11:46:23 ----A---- C:\Windows\system32\drivers\rasl2tp.sys
2012-05-17 11:46:22 ----A---- C:\Windows\system32\XpsRasterService.dll
2012-05-17 11:46:22 ----A---- C:\Windows\system32\wisptis.exe
2012-05-17 11:46:21 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2012-05-17 11:46:21 ----A---- C:\Windows\system32\ocsetup.exe
2012-05-17 11:46:20 ----A---- C:\Windows\SYSWOW64\evr.dll
2012-05-17 11:46:20 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2012-05-17 11:46:19 ----A---- C:\Windows\SYSWOW64\WinSATAPI.dll
2012-05-17 11:46:19 ----A---- C:\Windows\system32\sppwinob.dll
2012-05-17 11:46:18 ----A---- C:\Windows\SYSWOW64\calc.exe
2012-05-17 11:46:18 ----A---- C:\Windows\system32\ocsetapi.dll
2012-05-17 11:46:18 ----A---- C:\Windows\system32\DXP.dll
2012-05-17 11:46:18 ----A---- C:\Windows\system32\drivers\volmgr.sys
2012-05-17 11:46:17 ----A---- C:\Windows\system32\wpdbusenum.dll
2012-05-17 11:46:17 ----A---- C:\Windows\system32\eapp3hst.dll
2012-05-17 11:46:17 ----A---- C:\Windows\system32\ci.dll
2012-05-17 11:46:16 ----A---- C:\Windows\SYSWOW64\sqlsrv32.dll
2012-05-17 11:46:16 ----A---- C:\Windows\system32\drivers\msdsm.sys
2012-05-17 11:46:15 ----A---- C:\Windows\system32\wcncsvc.dll
2012-05-17 11:46:15 ----A---- C:\Windows\system32\upnp.dll
2012-05-17 11:46:15 ----A---- C:\Windows\system32\mprapi.dll