DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 10.0.9200.16736 Run by [removed] at 1:50:09 on 2013-11-26 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.1790.840 [GMT -7:00] . AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\ibmpmsvc.exe c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Windows\system32\atiesrxx.exe C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskhost.exe C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe C:\Windows\system32\atashost.exe C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Program Files\LENOVO\HOTKEY\CAMMUTE.exe C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe C:\Program Files\QUALCOMM\QDLService2k\QDLService2kLenovo.exe C:\Program Files\Lenovo\Access Connections\AcSvc.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe C:\Windows\System32\rundll32.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Windows\System32\WUDFHost.exe C:\Program Files\Lenovo\Access Connections\SvcGuiHlpr.exe C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe C:\Windows\System32\TpShocks.exe C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe C:\Windows\System32\rundll32.exe C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe C:\Program Files\Lenovo\Client Security Solution\cssauth.exe C:\Program Files\Lenovo\Zoom\TpScrex.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Social Privacy DNS\dnswatch.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe C:\Program Files\Evernote\Evernote\EvernoteClipper.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe c:\Program Files\Lenovo\System Update\SUService.exe C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Microsoft\BingBar\7.2.241.0\SeaPort.exe C:\WINDOWS\notepad.exe C:\Users\Loreal\Desktop\OTL.exe C:\Windows\notepad.exe C:\Windows\notepad.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com uDefault_Page_URL = hxxp://lenovo.msn.com BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Social Privacy: {91FBEA5C-E3C7-42EA-8C2B-B168189AB5BE} - c:\program files\social privacy\sp.dll BHO: Evernote extension: {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - c:\program files\evernote\evernote\EvernoteIE.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.9012.1008\swg.dll BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL BHO: IePasswordManagerHelper Class: {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - c:\program files\lenovo\client security solution\tvtpwm_ie_com.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\microsoft\bingbar\7.2.241.0\BingExt.dll BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\microsoft\bingbar\7.2.241.0\BingExt.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe mRun: [TpShocks] TpShocks.exe mRun: [cAudioFilterAgent] c:\program files\conexant\caudiofilteragent\cAudioFilterAgent.exe mRun: [SmartAudio] c:\program files\conexant\saii\SAIICpl.exe /t mRun: [PWMTRV] rundll32 c:\progra~1\thinkpad\utilit~1\PWMTR32V.DLL,PwrMgrBkGndMonitor mRun: [Message Center Plus] c:\program files\lenovo\message center plus\MCPLaunch.exe /start mRun: [AcWin7Hlpr] c:\program files\lenovo\access connections\AcTBenabler.exe mRun: [cssauth] "c:\program files\lenovo\client security solution\cssauth.exe" silent mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices mRun: [MSC] "c:\program files\microsoft security client\mssecex.exe" -hide -runkey mRun: [RIMBBLaunchAgent.exe] c:\program files\common files\research in motion\usb drivers\RIMBBLaunchAgent.exe mRun: [dnsshield] c:\program files\social privacy dns\dnswatch.exe mRun: [Updater] c:\programdata\updater\Updater.exe StartupFolder: c:\users\loreal\appdata\roaming\micros~1\windows\startm~1\programs\startup\everno~1.lnk - c:\program files\evernote\evernote\EvernoteClipper.exe StartupFolder: c:\users\loreal\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\thinkpad\bluetooth software\BTTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\openvp~1.lnk - c:\program files\openvpn technologies\openvpn client\core\uiboot.exe mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: Clip Image - c:\program files\evernote\evernote\\evernoteieres\Clip.html?clipAction=4 IE: Clip selection - c:\program files\evernote\evernote\\evernoteieres\Clip.html?clipAction=3 IE: Clip this page - c:\program files\evernote\evernote\\evernoteieres\Clip.html?clipAction=1 IE: Clip URL - c:\program files\evernote\evernote\\evernoteieres\Clip.html?clipAction=0 IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000 IE: New Note - c:\program files\evernote\evernote\\evernoteieres\NewNote.html IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - c:\program files\evernote\evernote\\evernoteieres\AddNote.html IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm IE: {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - c:\program files\lenovo\client security solution\tvtpwm_ie_com.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://1source-intl.webex.com/client/T27L10NSP25/nbr/ieatgpc1.cab TCP: NameServer = 8.8.8.8,8.8.4.4 TCP: NameServer = 192.168.0.1 TCP: Interfaces\{25A65430-3BF6-4C71-BD3C-DE91A259B713} : NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{66A54A2F-4141-46F3-A353-45A2E09042BA} : NameServer = 209.183.33.23 209.183.35.23 TCP: Interfaces\{85F7029A-94FE-49F7-A7A5-7276AD3E1CF8} : NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{85F7029A-94FE-49F7-A7A5-7276AD3E1CF8} : DHCPNameServer = [removed] [removed] [removed] TCP: Interfaces\{C8800C8A-A47C-4AAA-8B95-8DCA77FF0F23} : DHCPNameServer = 192.168.0.1 TCP: Interfaces\{D73CB6D5-9592-46C4-AA24-C3D69CD5B349} : NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{e29ac6c2-7037-11de-816d-806e6f6e6963} : NameServer = 8.8.8.8,8.8.4.4 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL AppInit_DLLs= c:\progra~1\searchprotect\searchprotect\bin\SPVC32Loader.dll SSODL: WebCheck - SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL LSA: Notification Packages = scecli ACGina . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 171064] R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2009-10-9 20520] R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2012-8-13 37664] R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\drivers\smiif32.sys [2009-12-9 13480] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-11-11 172032] R2 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2012-8-13 134456] R2 LENOVO.CAMMUTE;Lenovo Camera Mute;c:\program files\lenovo\hotkey\cammute.exe [2009-12-9 54632] R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\lenovo\hotkey\micmute.exe [2009-12-9 44984] R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-11-26 418376] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-11-26 701512] R2 OpenVPNAccessClient;OpenVPN Access Client;c:\program files\openvpn technologies\openvpn client\core\capiws.exe [2010-8-12 24064] R2 QDLService2kLenovo;Qualcomm Gobi 2000 Download Service (Lenovo);c:\program files\qualcomm\qdlservice2k\QDLService2kLenovo.exe [2010-6-25 332536] R2 TPHKSVC;On Screen Display;c:\program files\lenovo\hotkey\TPHKSVC.exe [2009-12-9 62904] R3 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\7.2.241.0\SeaPort.EXE [2013-7-23 240288] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-11-26 22856] R3 qcfilterlno2k;Gobi 2000 USB Composite Device Filter Driver(05C6-9205);c:\windows\system32\drivers\qcfilterlno2k.sys [2009-12-18 5248] R3 qcusbnetlno2k;Gobi 2000 USB-NDIS miniport(05C6-9205);c:\windows\system32\drivers\qcusbnetlno2k.sys [2010-6-25 374784] R3 qcusbserlno2k;Gobi 2000 USB Device for Legacy Serial Communication(05C6-9205);c:\windows\system32\drivers\qcusbserlno2k.sys [2010-6-25 190592] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2010-4-28 182304] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-4-28 233472] R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [2010-3-9 1006624] R3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\drivers\tapoas.sys [2010-8-3 26112] R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2010-4-28 27320] R3 usbsmi;Integrated Camera;c:\windows\system32\drivers\SMIksdrv.sys [2010-4-28 181120] S2 BBSvc;BingBar Service;c:\program files\microsoft\bingbar\7.2.241.0\BBSvc.EXE [2013-7-23 193696] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 Level Quality Watcher;Level Quality Watcher;c:\program files\level quality watcher\v1.01\levelqualitywatcher32.exe run options=01110010000000000000000000000000 sourceguid=8fb7175f-c1fb-4437-9555-1822df6d4ca1 --> c:\program files\level quality watcher\v1.01\levelqualitywatcher32.exe run options=01110010000000000000000000000000 sourceguid=8FB7175F-C1FB-4437-9555-1822DF6D4CA1 [?] S2 vToolbarUpdater17.1.2;vToolbarUpdater17.1.2;c:\program files\common files\avg secure search\vtoolbarupdater\17.1.2\toolbarupdater.exe --> c:\program files\common files\avg secure search\vtoolbarupdater\17.1.2\ToolbarUpdater.exe [?] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168] S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 74112] S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2012-3-26 214952] S3 PCDSRVC{3037D694-FD904ACA-06000000}_0;PCDSRVC{3037D694-FD904ACA-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor\pcdsrvc.pkms [2009-11-20 20848] S3 Power Manager DBC Service;Power Manager DBC Service;c:\program files\thinkpad\utilities\PWMDBSVC.exe [2010-4-28 75112] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-8-29 52224] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-8-26 1343400] . =============== Created Last 30 ================ . 2013-11-26 07:51:15 62576 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{978836b1-4be4-40a2-9cbc-0ec7d7cbf7a0}\offreg.dll 2013-11-26 07:35:43 -------- d-----w- C:\AdwCleaner 2013-11-26 07:22:16 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-11-26 07:19:02 7772552 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{978836b1-4be4-40a2-9cbc-0ec7d7cbf7a0}\mpengine.dll 2013-11-26 06:27:59 -------- d-----w- c:\users\loreal\appdata\local\ElevatedDiagnostics 2013-11-26 05:13:30 -------- d-----w- c:\program files\Reimage 2013-11-26 05:13:24 -------- d-----w- C:\rei 2013-11-26 02:01:41 -------- d-----w- c:\users\loreal\appdata\roaming\Malwarebytes 2013-11-26 02:01:16 -------- d-----w- c:\programdata\Malwarebytes 2013-11-26 02:01:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2013-11-26 02:00:44 -------- d-----w- c:\users\loreal\appdata\local\Programs 2013-11-25 03:28:58 -------- d-----w- c:\program files\Level Quality Watcher 2013-11-25 03:28:10 -------- d-----w- c:\programdata\RHelpers 2013-11-25 03:28:05 -------- d-----w- c:\programdata\Updater 2013-11-25 03:27:58 -------- d-----w- c:\programdata\TubeDimmer 2013-11-25 03:25:25 -------- d-----w- c:\program files\Social Privacy 2013-11-25 03:25:22 -------- d-----w- c:\program files\Social Privacy DNS 2013-11-25 03:25:04 -------- d-----w- c:\program files\sp 2013-11-25 01:30:25 7772552 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2013-11-19 01:44:37 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys 2013-11-19 01:44:37 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys 2013-11-19 01:44:35 73216 ----a-w- c:\windows\system32\WUDFSvc.dll 2013-11-19 01:44:35 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll 2013-11-19 01:44:33 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll 2013-11-19 01:44:32 613888 ----a-w- c:\windows\system32\WUDFx.dll 2013-11-19 01:44:32 196608 ----a-w- c:\windows\system32\WUDFHost.exe 2013-11-19 01:43:42 5120 ----a-w- c:\windows\system32\wmi.dll 2013-11-19 01:43:42 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2013-11-19 01:43:42 172544 ----a-w- c:\windows\system32\wintrust.dll 2013-11-19 01:43:42 159232 ----a-w- c:\windows\system32\imagehlp.dll 2013-11-19 01:33:58 49152 ----a-w- c:\windows\system32\taskhost.exe 2013-11-19 01:32:03 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-11-19 01:29:18 1505280 ----a-w- c:\windows\system32\d3d11.dll . ==================== Find3M ==================== . 2013-11-19 20:04:24 37664 ----a-w- c:\windows\system32\drivers\avgtpx86.sys 2013-11-19 10:21:30 230048 ------w- c:\windows\system32\MpSigStub.exe 2013-11-19 01:33:24 293376 ----a-w- c:\windows\system32\KernelBase.dll 2013-11-19 01:32:03 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-10-09 11:06:53 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-10-09 11:06:52 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . ============= FINISH: 1:51:27.02 ===============