Hi and thanks for the reply.
On my pc when I point at a process I only see the path for that process.
If I open the lower payne and double click a process then this is what I got.
Process CPU Private Bytes Working Set PID Description Company Name
svchost.exe 26.86 484,376 K 501,500 K 1244 Generic Host Process for Win32 Services Microsoft Corporation
mbamservice.exe 0.55 239,344 K 237,184 K 2772 Malwarebytes Anti-Malware Malwarebytes Corporation
firefox.exe 134,388 K 145,288 K 3612 Firefox Mozilla Corporation
MsMpEng.exe 0.77 58,112 K 51,344 K 1360 Antimalware Service Executable Microsoft Corporation
explorer.exe 32,248 K 45,132 K 252 Windows Explorer Microsoft Corporation
svchost.exe 1.98 27,072 K 38,216 K 1396 Generic Host Process for Win32 Services Microsoft Corporation
RTHDCPL.EXE 26,244 K 24,752 K 1016 Realtek HD Audio Control Panel Realtek Semiconductor Corp.
mbam.exe 20,464 K 30,664 K 3404 Malwarebytes Anti-Malware Malwarebytes Corporation
procexp.exe 19.64 21,000 K 29,096 K 2636 Sysinternals Process Explorer Sysinternals - www.sysinternals.com
SDTray.exe 0.01 16,356 K 22,012 K 2212 Spybot - Search & Destroy tray access Safer-Networking Ltd.
wuauclt.exe 0.04 14,656 K 140,644 K 5996 Windows Update Microsoft Corporation
svchost.exe 11,168 K 23,416 K 1052 Generic Host Process for Win32 Services Microsoft Corporation
jqs.exe 0.01 9,576 K 1,472 K 2196 Java Quick Starter Service Oracle Corporation
SDUpdSvc.exe 9,444 K 14,388 K 2108 Spybot-S&D 2 Background update service Safer-Networking Ltd.
rundll32.exe 9,112 K 11,988 K 2056 Run a DLL as an App Microsoft Corporation
svchost.exe 8,232 K 12,692 K 1252 Generic Host Process for Win32 Services Microsoft Corporation
winlogon.exe 7,176 K 3,896 K 820 Windows NT Logon Application Microsoft Corporation
msseces.exe 6,684 K 11,784 K 2136 Microsoft Security Client User Interface Microsoft Corporation
daemonu.exe 6,368 K 9,368 K 3188 NVIDIA Settings Update Manager NVIDIA Corporation
svchost.exe 5,896 K 8,264 K 1692 Generic Host Process for Win32 Services Microsoft Corporation
nvsvc32.exe 5,376 K 7,100 K 3000 NVIDIA Driver Helper Service, Version 320.49 NVIDIA Corporation
WLIDSVC.EXE 4,820 K 8,480 K 1092 Microsoft® Windows Live ID Service Microsoft Corporation
Ctxfihlp.exe 4,804 K 7,988 K 1340 CTXfiHlp MFC Application Creative Technology Ltd
MpCmdRun.exe 4,664 K 5,496 K 1732 Microsoft Malware Protection Command Line Utility Microsoft Corporation
GUI.exe 1.02 4,656 K 7,904 K 2192 GUI MFC Application
spoolsv.exe 4,108 K 6,240 K 1840 Spooler SubSystem App Microsoft Corporation
mbamscheduler.exe 3,840 K 7,872 K 2272 Malwarebytes Anti-Malware Malwarebytes Corporation
MpCmdRun.exe 0.01 3,784 K 5,288 K 5744 Microsoft Malware Protection Command Line Utility Microsoft Corporation
GoogleUpdate.exe 3,624 K 1,936 K 2216 Google Installer Google Inc.
CTxfispi.exe 3,544 K 6,212 K 3256 SPI (Creative X-Fi Module) Creative Technology Ltd
wmiprvse.exe 0.01 3,084 K 7,956 K 3148 WMI Microsoft Corporation
lsass.exe 0.01 2,848 K 6,400 K 876 LSA Shell (Export Version) Microsoft Corporation
svchost.exe 0.04 2,652 K 4,744 K 1564 Generic Host Process for Win32 Services Microsoft Corporation
rapimgr.exe 2,548 K 5,696 K 2640 ActiveSync RAPI Manager Microsoft Corporation
svchost.exe 2,412 K 3,440 K 1436 Generic Host Process for Win32 Services Microsoft Corporation
MpCmdRun.exe 2,360 K 2,940 K 5520 Microsoft Malware Protection Command Line Utility Microsoft Corporation
svchost.exe 2,256 K 5,492 K 180 Generic Host Process for Win32 Services Microsoft Corporation
tsnp2std.exe 2,232 K 5,624 K 1764 tsnp2std Microsoft
ContentTransferWMDetector.exe 2,180 K 4,976 K 1352 Content Transfer Walkman Detector Sony Corporation
vsnp2std.exe 2,156 K 5,664 K 1980 CameraMonitor Application Sonix
nusb3mon.exe 2,120 K 3,944 K 1080 USB 3.0 Monitor NEC Electronics Corporation
NvTmru.exe 2,084 K 4,892 K 2112 NVIDIA NvTmru Application NVIDIA Corporation
FixCamera.exe 2,056 K 5,516 K 1880 CameraFixer MFC Application
svchost.exe 1,972 K 4,492 K 1248 Generic Host Process for Win32 Services Microsoft Corporation
wmiapsrv.exe 1,940 K 4,624 K 4068 WMI Performance Adapter Service Microsoft Corporation
services.exe 0.14 1,904 K 3,724 K 864 Services and Controller app Microsoft Corporation
GoogleCrashHandler.exe 1,888 K 552 K 2512 Google Crash Handler Google Inc.
csrss.exe 0.07 1,792 K 6,128 K 788 Client Server Runtime Process Microsoft Corporation
DLMSession.exe 1,424 K 4,236 K 1620 Autodesk Download Manager Autodesk, Inc.
svchost.exe 1,404 K 3,872 K 1800 Generic Host Process for Win32 Services Microsoft Corporation
wcescomm.exe 1,356 K 5,020 K 2476 ActiveSync Connection Manager Microsoft Corporation
alg.exe 1,212 K 3,664 K 2680 Application Layer Gateway Service Microsoft Corporation
hpztsb12.exe 1,160 K 3,836 K 1104 HP
MDM.EXE 1,132 K 3,364 K 2964 Machine Debug Manager Microsoft Corporation
ctfmon.exe 1,052 K 3,756 K 268 CTF Loader Microsoft Corporation
BCU.exe 0.01 964 K 3,748 K 132 Browser Configuration Utility DeviceVM, Inc.
essvr.exe 932 K 2,308 K 2076
WLIDSVCM.EXE 588 K 2,052 K 3476 Microsoft® Windows Live ID Service Monitor Microsoft Corporation
HPZipm12.exe 556 K 1,840 K 3248 PML Driver HP
BCUService.exe 452 K 1,796 K 1316 Browser Configuration Utility Auto-recovery Service DeviceVM, Inc.
smss.exe 172 K 432 K 720 Windows NT Session Manager Microsoft Corporation
System Idle Process 46.19 0 K 28 K 0
System 1.71 0 K 244 K 4
Interrupts 0.80 0 K 0 K n/a Hardware Interrupts and DPCs
wuauclt.exe 0.04 6,020 K 6,088 K 4100 Windows Update Microsoft Corporation
AM_Delta_Patch_1.179.190.0.exe 0.03 208 K 1,996 K 4340 AntiMalware Definition Update Microsoft Corporation
MpSigStub.exe 0.03 1,728 K 2,544 K 4400 Microsoft Malware Protection Signature Update Stub Microsoft Corporation
Process: svchost.exe Pid: 1244
Type Name
Desktop \Default
Directory \KnownDlls
Directory \Windows
Directory \BaseNamedObjects
Event \BaseNamedObjects\DINPUTWINMM
Event \BaseNamedObjects\userenv: User Profile setup event
Event \BaseNamedObjects\hardwaremixercallback
Event \BaseNamedObjects\crypt32LogoffEvent
Event \BaseNamedObjects\mixercallback
Event \BaseNamedObjects\userenv: Machine Group Policy has been applied
Event \BaseNamedObjects\userenv: User Group Policy has been applied
File C:\WINDOWS\system32
File \Device\KsecDD
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File \Device\WMIDataDevice
File \Device\WMIDataDevice
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
File C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
File C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File \Device\Tcp
File \Device\NamedPipe\ROUTER
File \Device\Tcp
File \Device\Ip
File \Device\Ip
File \Device\Ip
File \Device\NamedPipe\ROUTER
File \Device\Tcp
File \Device\Afd
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\if[3].txt
File \Device\Afd
File \Device\Udp
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\MuseoSans_500_Italic-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\user_sync[1].html
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\buying-clean-electricity[1].txt
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File \Device\KSENUM#00000001
File C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\brands-products-archives[1].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\revicons[1].eot
File C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My
File \Device\Tcp
File \Device\NetBT_Tcpip_{49581C7F-1CFC-4C55-B4EF-8588276CD04B}
File \Device\Afd
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\fontawesome-webfont[1].eot
File \Device\Tcp
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\cities-structures-architecture-archives[1].txt
File \Device\Tcp
File C:\WINDOWS\system32\Macromed\Flash\Flash32_11_9_900_152.ocx
File C:\WINDOWS\system32\stdole2.tlb
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\fontawesome-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\MuseoSans_900_Italic-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\revicons[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\MuseoSans_500-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\st[4]
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\engine[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\engine[2].htm
File \Device\Afd
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\showad[1].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\if[1].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\usersync[2].gif
File C:\WINDOWS\system32\dxtrans.dll
File C:\WINDOWS\system32\dxtmsft.dll
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\showad[5].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\showad[3].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\user_sync[1].html
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[7].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\4651[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\usersync[4].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\net[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\if[3].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\MuseoSans_100-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\MuseoSans_100_Italic-webfont[1].eot
File \Device\Tcp
File \Device\Afd
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\net[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\ba[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\insulation[1].txt
File \Device\Tcp
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[1].txt
File \Device\Afd
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\tt[2].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\st[1]
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[8].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\st[2]
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\user_sync[2].html
File C:\WINDOWS\system32\mshtml.tlb
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\4651[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[10].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\if[1].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\st[1]
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\MuseoSans_300-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\MuseoSans_500-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\MuseoSans_300-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\usersync[3].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\MuseoSans_300_Italic-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\MuseoSans_100_Italic-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\if[2].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\user_sync[1].html
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[3].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\user_sync[3].html
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\MuseoSans_100-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\MuseoSans_900-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\user_sync[2].html
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\st[3]
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\MuseoSans_700-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\user_sync[1].html
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\showad[1].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\showad[1].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\user_sync[4].html
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\MuseoSans_700_Italic-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\user_sync[2].html
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\showad[2].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[2].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\user_sync[3].html
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\ba[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\MuseoSans_500_Italic-webfont[1].eot
File C:\WINDOWS\system32\shdocvw.dll
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\user_sync[2].html
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\user_sync[5].html
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\Pug[1].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\st[1]
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\user_sync[3].html
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\if[2].txt
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\usersync[3].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\showad[4].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\usersync[2].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\user_sync[3].html
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\showad[2].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\showad[1].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\showad[3].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\cfcm[1].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\usersync[1].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\if[4].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\st[4]
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\usersync[4].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\usersync[3].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\usersync[1].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\usersync[1].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\showad[2].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\if[1].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\usersync[2].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\usersync[5].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\Pug[1].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\MuseoSans_700_Italic-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\showad[4].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\st[2]
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\showad[3].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\ba[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\MuseoSans_300_Italic-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\st[3]
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\MuseoSans_700-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\showad[5].js
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\st[2]
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\MuseoSans_900-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\MuseoSans_900_Italic-webfont[1].eot
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\clk[1].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\Pug[1].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\usersync[6].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\usersync[7].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\Pug[1].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\an_brightroll_com[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\tt[1].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\if[3].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\tt[1].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[4].txt
File \Device\Tcp
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\an_brightroll_com[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[5].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\st[3]
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\51462E17-431B-4CC4-B16F-CBB201D0E036[1].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\Pug[1].txt
File \Device\Tcp
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\if[2].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\Pug[2].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\pxj[1].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\st[1]
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[6].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\adoapn_AppNexusDemoActionTag_1[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\pxj[1].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\an_brightroll_com[2].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\if[5].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[9].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\an_brightroll_com[2].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\pxj[2].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\pxj[1].gif
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\PortalServe[2].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\iframe1[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\728x90[1].htm
File C:\WINDOWS\Temp\fla6.tmp
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\aclk[1].htm
File C:\WINDOWS\Temp\fla5.tmp
File C:\WINDOWS\Temp\fla3.tmp
File \Device\Tcp
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\ba[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\iframe1[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\iframe1[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\300x250noads[1].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\PortalServe[1].txt
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\iframe1[1].htm
File C:\WINDOWS\Temp\fla4.tmp
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\ba[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\pixel[1].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\ddc[2].htm
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\videoplayer[1].php
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\ddc[1].htm
File C:\WINDOWS\system32\iepeers.dll
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\skeleton[1].gif
File \Device\Afd
File \Device\Tcp
File \Device\Tcp
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\pixel[1].com
File C:\WINDOWS\system32\wmp.dll
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.23084_x-ww_f3f35550
Key HKLM
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
Key HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Windows
Key HKCR
Key HKU\.DEFAULT
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Key HKCR
Key HKLM\SOFTWARE\Policies
Key HKU\.DEFAULT\Software\Policies
Key HKU\.DEFAULT\Software
Key HKLM\SOFTWARE
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Key HKLM\SOFTWARE\Policies
Key HKU\.DEFAULT\Software\Policies
Key HKU\.DEFAULT\Software
Key HKLM\SOFTWARE
Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9
Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5
Key HKLM\SOFTWARE\Microsoft\Tracing\RASAPI32
Key HKU
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Linkage
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters
Key HKLM\SYSTEM\ControlSet001\Services\NetBT\Parameters\Interfaces
Key HKLM\SYSTEM\ControlSet001\Services\NetBT\Parameters
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Network\Location Awareness
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
Key HKCR
Key HKCR
Key HKLM\SOFTWARE\Microsoft\COM3
Key HKU
Key HKCR
Key HKU
Key HKLM\SOFTWARE\Microsoft\COM3
Key HKLM\SOFTWARE\Microsoft\COM3
Key HKCR\CLSID
Key HKCR
Key HKLM\SOFTWARE\Microsoft\COM3
Key HKU
Key HKLM\SOFTWARE\Microsoft\COM3
Key HKLM\SOFTWARE\Microsoft\COM3
Key HKCR\CLSID
Key HKCR
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Key HKCR
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKCR
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKCR
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKCR
Key HKCR
Key HKCR
Key HKCR
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Locale
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Language Groups
Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKCR
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT
Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA
Key HKU\.DEFAULT
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\CA
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA
Key HKU\.DEFAULT
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed
Key HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates
Key HKCR
Key HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\trust
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust
Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust
Key HKU\.DEFAULT
Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My
Key HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates
Key HKCR
Key HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKCR
Key HKCR
Key HKCR
Key HKCR
Key HKCR
Key HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage
Key HKCR
Key HKLM\SYSTEM\Setup
Key HKCR
Key HKCR
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKCR
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKCR
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKCR
Key HKCR
Key HKCR
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKCR
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Internet Explorer\DOMStorage\Total
Key HKCR\MIME\Database\Content Type\image/gif
Key HKCR\MIME\Database\Content Type\text/html
Key HKCR
Key HKU\.DEFAULT\Software\Microsoft\Internet Explorer\DOMStorage\securepaths.com
Key HKU\.DEFAULT\Software\Microsoft\Internet Explorer\DOMStorage\Total
Key HKU\.DEFAULT\Software\Microsoft\Internet Explorer
Key HKCR\MIME\Database\Content Type\application/x-shockwave-flash
Key HKU\.DEFAULT\Software\Microsoft\Internet Explorer\DOMStorage\securepaths.com
Key HKCR
Key HKLM\SOFTWARE\Microsoft\MediaPlayer\Preferences
Key HKCR\MIME\Database\Content Type\image/png
Key HKCR\MIME\Database\Content Type\text/plain
Key HKCR\MIME\Database\Content Type\image/jpeg
Key HKCR
Key HKU\.DEFAULT\Software\Microsoft\MediaPlayer\Preferences
Key HKU\.DEFAULT\Software\Microsoft\MediaPlayer\Preferences
Key HKCR
Key HKCR
KeyedEvent \KernelObjects\CritSecOutOfMemoryEvent
Mutant \BaseNamedObjects\SHIMLIB_LOG_MUTEX
Mutant \BaseNamedObjects\_!MSFTHISTORY!_
Mutant \BaseNamedObjects\c:!windows!system32!config!systemprofile!local settings!temporary internet files!content.ie5!
Mutant \BaseNamedObjects\c:!windows!system32!config!systemprofile!cookies!
Mutant \BaseNamedObjects\c:!windows!system32!config!systemprofile!local settings!history!history.ie5!
Mutant \BaseNamedObjects\WininetStartupMutex
Mutant \BaseNamedObjects\WininetProxyRegistryMutex
Mutant \BaseNamedObjects\RasPbFile
Mutant \BaseNamedObjects\ZonesCounterMutex
Mutant \BaseNamedObjects\!IETld!Mutex
Mutant \BaseNamedObjects\ZoneAttributeCacheCounterMutex
Mutant \BaseNamedObjects\ZonesCacheCounterMutex
Mutant \BaseNamedObjects\ZoneAttributeCacheCounterMutex
Mutant \BaseNamedObjects\ZonesLockedCacheCounterMutex
Mutant \BaseNamedObjects\!PrivacIE!SharedMemory!Mutex
Mutant \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-18
Mutant \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-18
Mutant \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-18
Mutant \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-18
Mutant \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-18
Mutant \BaseNamedObjects\MidiMapper_modLongMessage_RefCnt
Mutant \BaseNamedObjects\MidiMapper_Configure
Mutant \BaseNamedObjects\!IETld!Mutex
Mutant \BaseNamedObjects\{1B655094-FE2A-433c-A877-FF9793445069}
Mutant \BaseNamedObjects\__DDrawCheckExclMode__
Mutant \BaseNamedObjects\__DDrawExclMode__
Mutant \BaseNamedObjects\DDrawDriverObjectListMutex
Mutant \BaseNamedObjects\DDrawWindowListMutex
Mutant \BaseNamedObjects\http://www.redesignrevolution.com/
Mutant \BaseNamedObjects\http://ads.yahoo.com/
Mutant \BaseNamedObjects\http://c.betrad.com/
Mutant \BaseNamedObjects\http://ad.doubleclick.net/
Mutant \BaseNamedObjects\http://securepaths.com/
Mutant \BaseNamedObjects\InternetExplorerDOMStoreQuota
Port \RPC Control\OLEB3F0659C03AE44F39E2C9AF5C951
Process svchost.exe(1244)
Section \BaseNamedObjects\C:_WINDOWS_system32_config_systemprofile_Local Settings_Temporary Internet Files_Content.IE5_index.dat_9617408
Section \BaseNamedObjects\C:_WINDOWS_system32_config_systemprofile_Cookies_index.dat_409600
Section \BaseNamedObjects\C:_WINDOWS_system32_config_systemprofile_Local Settings_History_History.IE5_index.dat_2555904
Section \BaseNamedObjects\SENS Information Cache
Section \BaseNamedObjects\UrlZonesSM_SYSTEM
Section \BaseNamedObjects\windows_ie_global_counters
Section \BaseNamedObjects\!PrivacIE!SharedMem!Counter
Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-18
Section \BaseNamedObjects\mmGlobalPnpInfo
Section \BaseNamedObjects\WDMAUD_Callbacks
Section \BaseNamedObjects\MSIMGSIZECacheMap
Semaphore \BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}
Semaphore \BaseNamedObjects\shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}
Semaphore \BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}
Thread svchost.exe(1244): 1976
Thread svchost.exe(1244): 1976
Thread svchost.exe(1244): 1976
Thread svchost.exe(1244): 2132
Thread svchost.exe(1244): 456
Thread svchost.exe(1244): 3668
Thread svchost.exe(1244): 3660
Thread svchost.exe(1244): 3660
Thread svchost.exe(1244): 1676
Thread svchost.exe(1244): 456
Thread svchost.exe(1244): 656
Thread svchost.exe(1244): 3200
Thread svchost.exe(1244): 1912
Thread svchost.exe(1244): 3200
Thread svchost.exe(1244): 3768
Thread svchost.exe(1244): 3116
Thread svchost.exe(1244): 3432
Thread svchost.exe(1244): 456
Thread svchost.exe(1244): 4004
Thread svchost.exe(1244): 656
Thread svchost.exe(1244): 2452
Thread svchost.exe(1244): 2104
Thread svchost.exe(1244): 656
Thread svchost.exe(1244): 1676
Thread svchost.exe(1244): 3208
Thread svchost.exe(1244): 3208
Thread svchost.exe(1244): 2448
Thread svchost.exe(1244): 1076
Thread svchost.exe(1244): 3996
Thread svchost.exe(1244): 3996
Thread svchost.exe(1244): 1172
Thread svchost.exe(1244): 3996
Thread svchost.exe(1244): 2248
Thread svchost.exe(1244): 3500
Thread svchost.exe(1244): 3328
Thread svchost.exe(1244): 504
Thread svchost.exe(1244): 1912
Thread svchost.exe(1244): 1468
Thread svchost.exe(1244): 3500
Thread svchost.exe(1244): 208
Thread svchost.exe(1244): 168
Thread svchost.exe(1244): 3500
Thread svchost.exe(1244): 1700
Thread svchost.exe(1244): 3632
Thread svchost.exe(1244): 168
Thread svchost.exe(1244): 3632
Thread svchost.exe(1244): 3632
Thread svchost.exe(1244): 2492
Thread svchost.exe(1244): 2492
Thread svchost.exe(1244): 4052
Thread svchost.exe(1244): 168
Thread svchost.exe(1244): 196
Thread svchost.exe(1244): 512
Thread svchost.exe(1244): 3636
Thread svchost.exe(1244): 2932
Thread svchost.exe(1244): 2152
Thread svchost.exe(1244): 3760
Thread svchost.exe(1244): 1544
Thread svchost.exe(1244): 2152
Thread svchost.exe(1244): 3584
Thread svchost.exe(1244): 3736
Thread svchost.exe(1244): 2152
Thread svchost.exe(1244): 1912
Thread svchost.exe(1244): 1876
Thread svchost.exe(1244): 3320
Thread svchost.exe(1244): 2168
Thread svchost.exe(1244): 3984
Thread svchost.exe(1244): 3732
Thread svchost.exe(1244): 3836
Thread svchost.exe(1244): 2796
Thread svchost.exe(1244): 276
Thread svchost.exe(1244): 2852
Thread svchost.exe(1244): 3812
Thread svchost.exe(1244): 648
Thread svchost.exe(1244): 2092
Thread svchost.exe(1244): 2884
Thread svchost.exe(1244): 2884
Thread svchost.exe(1244): 1952
Thread svchost.exe(1244): 2504
Thread svchost.exe(1244): 2392
Thread svchost.exe(1244): 2736
Thread svchost.exe(1244): 2416
Thread svchost.exe(1244): 3364
Thread svchost.exe(1244): 3540
Thread svchost.exe(1244): 620
Thread svchost.exe(1244): 2292
Thread svchost.exe(1244): 1212
Thread svchost.exe(1244): 2952
Thread svchost.exe(1244): 3792
Thread svchost.exe(1244): 3624
Thread svchost.exe(1244): 1860
Thread svchost.exe(1244): 2024
Thread svchost.exe(1244): 2356
Thread svchost.exe(1244): 1612
Thread svchost.exe(1244): 3384
Thread svchost.exe(1244): 1568
Thread svchost.exe(1244): 1752
Thread svchost.exe(1244): 1488
Thread svchost.exe(1244): 2700
Thread svchost.exe(1244): 1300
Thread svchost.exe(1244): 2120
Thread svchost.exe(1244): 2428
Thread svchost.exe(1244): 2404
Thread svchost.exe(1244): 4056
Thread svchost.exe(1244): 480
Thread svchost.exe(1244): 3316
Thread svchost.exe(1244): 3640
Thread svchost.exe(1244): 2984
Thread svchost.exe(1244): 2980
Thread svchost.exe(1244): 2072
Thread svchost.exe(1244): 3488
Thread svchost.exe(1244): 484
Thread svchost.exe(1244): 4124
Thread svchost.exe(1244): 3444
Thread svchost.exe(1244): 3804
Thread svchost.exe(1244): 3512
Thread svchost.exe(1244): 3508
Thread svchost.exe(1244): 216
Thread svchost.exe(1244): 1188
Thread svchost.exe(1244): 1812
Thread svchost.exe(1244): 448
Thread svchost.exe(1244): 3980
Thread svchost.exe(1244): 2692
Thread svchost.exe(1244): 3348
Thread svchost.exe(1244): 4120
Thread svchost.exe(1244): 2032
Thread svchost.exe(1244): 3372
Thread svchost.exe(1244): 672
Thread svchost.exe(1244): 3380
Thread svchost.exe(1244): 616
Thread svchost.exe(1244): 4356
Thread svchost.exe(1244): 3784
Thread svchost.exe(1244): 1968
Thread svchost.exe(1244): 3120
Thread svchost.exe(1244): 1348
Thread svchost.exe(1244): 2744
Thread svchost.exe(1244): 616
Thread svchost.exe(1244): 4360
Thread svchost.exe(1244): 2028
Thread svchost.exe(1244): 1744
Thread svchost.exe(1244): 3108
Thread svchost.exe(1244): 4116
Thread svchost.exe(1244): 1688
Thread svchost.exe(1244): 3996
Thread svchost.exe(1244): 4292
Thread svchost.exe(1244): 4352
Thread svchost.exe(1244): 656
WindowStation \Windows\WindowStations\Service-0x0-3e7$
WindowStation \Windows\WindowStations\Service-0x0-3e7$
Token NT AUTHORITY\NETWORK SERVICE:3e4
Key HKCR
Any suggestions will be appreciated.