If you click on System it will open a new window at the bottom which shows the details of System process. Then When you File, Save As, Save it saves it as system.txt. This is mine (check out the new stuff on the bottom):
Process PID CPU Private Bytes Working Set Description Company Name
System Idle Process 0 85.43 0 K 24 K
WmiPrvSE.exe 4156 8,448 K 16,168 K WMI Provider Host Microsoft Corporation
procexp64.exe 11268 3.74 32,672 K 50,400 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
waterfox.exe 10656 3.47 922,924 K 954,012 K Waterfox Waterfox
Interrupts n/a 0.96 0 K 0 K Hardware Interrupts and DPCs
Picasa3.exe 10012 0.58 77,904 K 87,528 K Picasa Google Inc.
ExpressTray.exe 3024 0.43 76,364 K 65,044 K Express Tray Garmin Ltd or its subsidiaries
svchost.exe 1100 0.01 21,940 K 37,244 K Host Process for Windows Services Microsoft Corporation
System 4 0.48 784 K 32,772 K
csrss.exe 668 0.30 10,124 K 14,796 K Client Server Runtime Process Microsoft Corporation
taskmgr.exe 9708 0.28 2,696 K 9,260 K Windows Task Manager Microsoft Corporation
svchost.exe 5972 0.16 63,160 K 62,180 K Host Process for Windows Services Microsoft Corporation
explorer.exe 2176 1.19 73,404 K 106,684 K Windows Explorer Microsoft Corporation
iexplore.exe 8936 0.10 74,144 K 91,396 K Internet Explorer Microsoft Corporation
CCC.exe 4672 0.08 96,152 K 20,000 K Catalyst Control Center: Host application ATI Technologies Inc.
ABService.exe 2040 < 0.01 4,444 K 8,484 K AOMEI Backupper Schedule task service AOMEI Tech Co., Ltd.
AvastSvc.exe 1640 0.07 300,236 K 43,324 K avast! Service Avast Software s.r.o.
AvastUI.exe 3144 0.06 24,904 K 25,548 K avast! Antivirus Avast Software s.r.o.
MOM.exe 4480 0.04 38,320 K 5,288 K Catalyst Control Center: Monitoring program Advanced Micro Devices Inc.
PDFProFiltSrvPP.exe 2064 0.03 1,188 K 3,600 K PDFPro IFilter Service Nuance Communications, Inc.
lsass.exe 728 0.01 4,672 K 11,992 K Local Security Authority Process Microsoft Corporation
lsm.exe 736 2,564 K 4,312 K Local Session Manager Service Microsoft Corporation
dllhost.exe 3440 0.02 8,040 K 12,644 K COM Surrogate Microsoft Corporation
iexplore.exe 9952 0.01 8,320 K 27,448 K Internet Explorer Microsoft Corporation
schedhlp.exe 2528 1,124 K 3,988 K Seagate Scheduler Helper Seagate
soffice.bin 4312 0.01 73,392 K 134,108 K OpenOffice 4.0.1 Apache Software Foundation
DiscWizardMonitor.exe 3884 0.05 3,600 K 5,972 K Seagate DiscWizard Monitor Seagate
svchost.exe 1388 < 0.01 5,516 K 9,992 K Host Process for Windows Services Microsoft Corporation
BrYNSvc.exe 2708 0.07 5,116 K 10,172 K BrYNCSvc Brother Industries, Ltd.
unchecky_bg.exe 3500 < 0.01 1,100 K 5,476 K Unchecky Background Process RaMMicHaeL
CouponPrinterService.exe 3620 < 0.01 3,544 K 10,124 K Coupon Printer Service Coupons.com Inc.
svchost.exe 784 < 0.01 203,528 K 213,100 K Host Process for Windows Services Microsoft Corporation
svchost.exe 672 0.01 12,568 K 21,344 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1472 0.10 17,096 K 19,684 K Host Process for Windows Services Microsoft Corporation
spoolsv.exe 1740 < 0.01 9,880 K 17,592 K Spooler SubSystem App Microsoft Corporation
conhost.exe 12028 < 0.01 1,292 K 4,400 K Console Window Host Microsoft Corporation
notepad.exe 8376 < 0.01 16,824 K 31,716 K Notepad Microsoft Corporation
notepad.exe 11976 < 0.01 1,548 K 5,488 K Notepad Microsoft Corporation
notepad.exe 3004 < 0.01 1,648 K 5,824 K Notepad Microsoft Corporation
PresentationFontCache.exe 4364 < 0.01 27,008 K 19,132 K PresentationFontCache.exe Microsoft Corporation
winlogon.exe 468 2,884 K 7,384 K Windows Logon Application Microsoft Corporation
wininit.exe 656 1,548 K 4,476 K Windows Start-Up Application Microsoft Corporation
unsecapp.exe 4112 1,760 K 5,932 K Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation
unchecky_svc.exe 6092 2,508 K 5,776 K Unchecky Service RaMMicHaeL
TeamViewer_Service.exe 2236 4,944 K 12,772 K TeamViewer 10 TeamViewer GmbH
svchost.exe 1208 3,300 K 7,296 K Host Process for Windows Services Microsoft Corporation
svchost.exe 596 0.03 24,512 K 21,644 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1776 11,652 K 14,144 K Host Process for Windows Services Microsoft Corporation
svchost.exe 848 0.02 4,448 K 9,576 K Host Process for Windows Services Microsoft Corporation
svchost.exe 940 0.05 4,624 K 8,320 K Host Process for Windows Services Microsoft Corporation
svchost.exe 796 2,504 K 7,264 K Host Process for Windows Services Microsoft Corporation
soffice.exe 3420 1,732 K 5,220 K OpenOffice 4.0.1 Apache Software Foundation
smss.exe 452 468 K 1,120 K Windows Session Manager Microsoft Corporation
sesvc.exe 2088 28,780 K 21,588 K ShadowExplorer www.shadowexplorer.com
services.exe 704 0.02 5,292 K 9,012 K Services and Controller app Microsoft Corporation
SearchIndexer.exe 3796 45,284 K 30,940 K Microsoft Windows Search Indexer Microsoft Corporation
schedul2.exe 2164 2,064 K 5,620 K Seagate Scheduler 2 Seagate
scalc.exe 2084 956 K 3,324 K OpenOffice Calc Apache Software Foundation
RAVCpl64.exe 1324 8,976 K 10,448 K Realtek HD Audio Manager Realtek Semiconductor
procexp.exe 11128 2,020 K 6,892 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
pptd40nt.exe 1688 1,340 K 4,208 K PaperPort Print to Desktop for NT Nuance Communications, Inc.
pdfPro5Hook.exe 3756 1,424 K 4,756 K PdfCreateHook Application Nuance Communications, Inc.
mDNSResponder.exe 1156 2,528 K 5,744 K Bonjour Service Apple Inc.
jusched.exe 3248 4,188 K 11,872 K Java Update Scheduler Oracle Corporation
ISUSPM.exe 3824 9,164 K 26,784 K Acresso Software Manager Acresso Corporation
GoogleUpdate.exe 3716 2,148 K 652 K Google Installer Google Inc.
Garmin.Cartography.MapUpdate.CoreService.exe 1392 33,132 K 48,220 K Garmin Core Update Service Garmin Ltd or its subsidiaries
explorer.exe 2832 28,380 K 42,968 K Windows Explorer Microsoft Corporation
dwm.exe 3384 1,732 K 6,276 K Desktop Window Manager Microsoft Corporation
csrss.exe 576 < 0.01 2,180 K 4,632 K Client Server Runtime Process Microsoft Corporation
cmd.exe 11568 2,224 K 3,160 K Windows Command Processor Microsoft Corporation
BrCtrlCntr.exe 1068 1,908 K 7,020 K ControlCenter Main Process Brother Industries, Ltd.
BrCcUxSys.exe 3176 1,628 K 6,060 K ControlCenter UX System Brother Industries, Ltd.
atiesrxx.exe 988 1,428 K 4,208 K AMD External Events Service Module AMD
atieclxx.exe 1364 1,964 K 5,740 K AMD External Events Client Module AMD
armsvc.exe 1888 1,176 K 3,868 K Adobe Acrobat Update Service Adobe Systems Incorporated
agent.exe 2732 4,484 K 11,644 K Acresso Software Manager Agent Acresso Corporation
AERTSr64.exe 1908 996 K 2,636 K Andrea filters APO access service (64-bit) Andrea Electronics Corporation
Process: System Pid: 4
Type Name
ALPC Port \PowerMonitorPort
ALPC Port \PowerPort
ALPC Port \SeRmCommandPort
Desktop \Disconnect
Desktop \Disconnect
Directory \GLOBAL??
Directory \Device\Harddisk0
Directory \Windows\WindowStations
Directory \Sessions\1\Windows\WindowStations
Directory \Sessions\0\DosDevices\00000000-000003e4
Directory \Sessions\0\DosDevices\00000000-000003e5
Directory \Sessions\0\DosDevices\00000000-0006cc89
Directory \Device\Http
Directory \Device\ammntdev
Directory \Sessions\0\DosDevices\00000000-0006ccae
Event \EFSInitEvent
Event \UniqueSessionIdEvent
Event \UniqueInteractiveSessionIdEvent
Event \Sessions\1\BaseNamedObjects\EventShutDownCSRSS
Event \BaseNamedObjects\aswstmbfeevnt
Event \BaseNamedObjects\aswstmbferefresh
Event \KernelObjects\LowMemoryCondition
Event \LanmanServerAnnounceEvent
File C:\Windows\System32\config\TxR\{016888cd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
File C:\Windows\System32\config\TxR\{016888cd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
File \Device\Tcp
File C:\Windows\System32\config\SYSTEM.LOG2
File C:\Windows\System32\config\RegBack\SYSTEM
File \clfs
File C:\Windows\System32\config\SOFTWARE.LOG2
File C:\Windows\System32\config\RegBack\DEFAULT
File X:\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf
File C:\Windows\System32\config\SOFTWARE
File X:\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000001
File \clfs
File \clfs
File \Device\Mup
File \clfs
File \clfs
File X:\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000002
File C:\Windows\System32\config\RegBack\SOFTWARE
File \clfs
File X:\$Extend\$RmMetadata\$Txf
File C:\Windows\System32\config\SYSTEM.LOG1
File C:\Windows\System32\config\DEFAULT
File C:\Windows\System32\wdi\LogFiles\WdiContextLog.etl.002
File C:\Windows\System32\config\SYSTEM
File C:\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000002
File C:\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf
File C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
File \clfs
File C:\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000001
File C:\Windows\System32\config\TxR\{016888cd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
File \clfs
File C:\$Extend\$RmMetadata\$Txf
File \clfs
File \clfs
File \clfs
File C:\Windows\System32\config\SOFTWARE.LOG1
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
File C:\System Volume Information\{34631cf6-09ab-11e5-9f9f-60eb69f488ad}{3808876b-c176-4e48-b7ae-04046e6cc752}
File \clfs
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
File C:\Windows\bootstat.dat
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
File \Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD
File \Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD.LOG
File \Device\KsecDD
File C:\Windows\System32\config\DEFAULT.LOG1
File C:\pagefile.sys
File C:\Windows\System32\config\DEFAULT.LOG2
File C:\Windows\System32\en-US\win32k.sys.mui
File C:\Windows\ehome\malgunmc.ttf
File C:\Windows\ehome\WTVGOTHIC-S.ttc
File C:\Windows\ehome\malgunmc.ttf
File C:\Windows\ehome\WTVGOTHIC-S.ttc
File C:\Windows\System32\config\SECURITY
File C:\Windows\System32\config\RegBack\SECURITY
File C:\Windows\System32\config\SECURITY.LOG1
File C:\Windows\System32\config\SECURITY.LOG2
File C:\Program Files (x86)\Nuance\PaperPort\bin\Resource\fonts\zdingbats.ttf
File C:\Windows\System32\config\RegBack\SAM
File C:\Windows\System32\config\SAM
File C:\Windows\System32\config\SAM.LOG1
File C:\Windows\System32\config\SAM.LOG2
File \Device\HarddiskVolume3
File C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2
File C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
File C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1
File C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{b9206c4a-884b-11e4-84ee-806e6f6e6963}.TM.blf
File C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{b9206c4a-884b-11e4-84ee-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms
File C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{b9206c4a-884b-11e4-84ee-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms
File \clfs
File \clfs
File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{b9206c4e-884b-11e4-84ee-60eb69f488ad}.TM.blf
File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1
File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG2
File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{b9206c4e-884b-11e4-84ee-60eb69f488ad}.TMContainer00000000000000000001.regtrans-ms
File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{b9206c4e-884b-11e4-84ee-60eb69f488ad}.TMContainer00000000000000000002.regtrans-ms
File \clfs
File \clfs
File C:\Program Files (x86)\Nuance\PaperPort\bin\Resource\fonts\zdingbats.ttf
File \Device\Tcp
File \Device\Tcp
File C:\Windows\CSC\v2.0.6
File C:\Windows\CSC
File C:\Windows\CSC\v2.0.6\temp
File \Device\HarddiskVolume3?
File C:\Windows\CSC\v2.0.6\pq
File C:\Windows\CSC\v2.0.6\namespace
File \Device\HarddiskVolume3?
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\Tcp
File C:\Windows\System32\drivers\en-US\ntfs.sys.mui
File \Device\Tcp
File C:\Users\Ron\AppData\Local\Microsoft\Windows\UsrClass.dat{80577e3d-bc95-11e4-9384-60eb69f488ad}.TMContainer00000000000000000002.regtrans-ms
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\Tcp
File \clfs
File \Device\Tcp
File \Device\Tcp
File \clfs
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File C:\Users\Ron\ntuser.dat.LOG2
File C:\Users\Ron\AppData\Local\Microsoft\Windows\UsrClass.dat{80577e3d-bc95-11e4-9384-60eb69f488ad}.TM.blf
File C:\Users\Ron\ntuser.dat
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File C:\Users\Ron\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
File C:\Users\Ron\ntuser.dat{7f81c707-bc92-11e4-a6df-60eb69f488ad}.TMContainer00000000000000000001.regtrans-ms
File C:\Users\Ron\ntuser.dat{7f81c707-bc92-11e4-a6df-60eb69f488ad}.TMContainer00000000000000000002.regtrans-ms
File C:\Users\Ron\ntuser.dat{7f81c707-bc92-11e4-a6df-60eb69f488ad}.TM.blf
File \clfs
File C:\Users\Ron\ntuser.dat.LOG1
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Mup
File \Device\Mup
File C:\ProgramData\AVAST Software\Avast\Fonts\OpenSans-Bold.ttf
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\NamedPipe\
File \Device\NamedPipe\
File \Device\Tcp
File \Device\aswSnx
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File C:\Windows\System32\wfp\wfpdiag.etl
File \Device\Tcp
File C:\Users\Ron\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2
File C:\Users\Ron\AppData\Local\Temp\acrord32_sbx\[email protected]
File \Device\Tcp
File \clfs
File \Device\Tcp
File C:\ProgramData\AVAST Software\Avast\Fonts\OpenSans-Italic.ttf
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File C:\Users\Ron\AppData\Local\Microsoft\Windows\UsrClass.dat{80577e3d-bc95-11e4-9384-60eb69f488ad}.TMContainer00000000000000000001.regtrans-ms
File \Device\Udp
File C:\Users\Ron\AppData\Local\Microsoft\Windows\UsrClass.dat
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File C:\System Volume Information\Syscache.hve.LOG1
File \Device\Tcp
File C:\System Volume Information\Syscache.hve
File C:\System Volume Information\Syscache.hve.LOG2
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File C:\ProgramData\AVAST Software\Avast\Fonts\OpenSans-Light.ttf
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File C:\ProgramData\AVAST Software\Avast\Fonts\RobotoCondensed-Regular.ttf
File C:\ProgramData\AVAST Software\Avast\Fonts\OpenSans-Regular.ttf
File C:\ProgramData\AVAST Software\Avast\Fonts\RobotoCondensed-Bold.ttf
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\HarddiskVolume3
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File C:\Users\Ron\AppData\Local\Temp\acrord32_sbx\[email protected]
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Udp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\NetBT_Tcpip_{BC84A6B9-5917-4C43-BB0C-677211465A7A}
File \Device\Tcp
File \Device\Tcp
File C:\Users\Ron\AppData\Local\Temp\acrord32_sbx\[email protected]
File C:\Users\Ron\AppData\Local\Temp\acrord32_sbx\[email protected]
File C:\Windows\System32\config\TxR\{016888cc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.1.regtrans-ms
File C:\Windows\System32\config\TxR\{016888cc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.3.regtrans-ms
File C:\Windows\System32\config\TxR\{016888cc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.0.regtrans-ms
File \clfs
File C:\Windows\System32\config\TxR\{016888cc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.2.regtrans-ms
File C:\Windows\System32\config\TxR\{016888cc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.blf
File C:\Users\Ron\AppData\Local\Temp\acrord32_sbx\[email protected]
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTNT Kernel Logger.etl
FilterConnectionPort \SnxVlabCommPort
FilterConnectionPort \SnxCommPort
FilterConnectionPort \aswFsBlkPort
FilterConnectionPort \aswPort
Key HKLM\SYSTEM\ControlSet001\Control\hivelist
Key \REGISTRY
Key HKLM\HARDWARE\DESCRIPTION\System\MultifunctionAdapter
Key HKLM\SYSTEM\ControlSet001\Control\SESSION MANAGER\MEMORY MANAGEMENT\PrefetchParameters
Key HKLM\SYSTEM\ControlSet001\Control\ProductOptions
Key HKLM\SYSTEM\Setup
Key HKLM\SYSTEM\ControlSet001
Key HKLM\SYSTEM\ControlSet001\Enum
Key HKLM\SYSTEM\ControlSet001\Control\CLASS
Key HKLM\SYSTEM\ControlSet001\services
Key HKLM\SYSTEM\ControlSet001\Control\WMI\Security
Key HKLM\SYSTEM\ControlSet001\services\aswSnx
Key HKLM\SYSTEM\ControlSet001\services\aswSP
Key HKLM\SYSTEM\ControlSet001\Control\FileSystem
Key HKLM\SYSTEM\ControlSet001\Control\Lsa
Key HKLM\SYSTEM\ControlSet001\Control\Lsa
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
Key HKLM\SYSTEM\ControlSet001\services\TCPIP6\Parameters
Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 1
Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 2
Key HKLM\SYSTEM\ControlSet001\Control\PCW\Security
Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 0
Key HKLM\SYSTEM\ControlSet001\services\Disk
Key HKLM\SYSTEM\ControlSet001
Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 3
Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 4
Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 5
Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 6
Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 7
Key HKLM\SYSTEM\ControlSet001\Control\FileSystem
Key HKLM\SYSTEM\ControlSet001\Policies
Key HKLM\SYSTEM\RNG
Key HKLM\SYSTEM\ControlSet001\services\NDIS\IfTypes\23
Key HKLM\SYSTEM\ControlSet001\services\NDIS\IfTypes\1
Key HKLM\SYSTEM\ControlSet001\services\NDIS\IfTypes\131
Key HKLM\SYSTEM\ControlSet001\services\NDIS\IfTypes\24
Key HKLM\SYSTEM\ControlSet001\services\NDIS\IfTypes\6
Key HKLM\SYSTEM\ControlSet001\services\NDIS\IfTypes\71
Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\Order
Key HKLM\SYSTEM\ControlSet001\services\Mup
Key HKLM\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001
Key HKLM\SYSTEM\ControlSet001\services\NDProxy
Key HKLM\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000
Key HKLM\SOFTWARE\Policies\Microsoft\Windows
Key HKLM\SYSTEM\ControlSet001\Control\DeviceClasses\{28d78fad-5a12-11d1-ae5b-0000f803a8c2}\##?#USB#VID_04F9&PID_0331&MI_00#6&16ff43d0&5&0000#{28d78fad-5a12-11d1-ae5b-0000f803a8c2}\#\Device Parameters
Key HKLM\SYSTEM\ControlSet001\Control\SESSION MANAGER\Quota System
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine
Key HKLM\SYSTEM\ControlSet001\services\NativeWifiP
Key HKLM\SYSTEM\ControlSet001\services\NativeWifiP\Parameters
Key HKLM\SYSTEM\ControlSet001\services\NativeWifiP\Parameters\Adapters
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine
Key HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-22
Key HKLM\SYSTEM\ControlSet001\services\HTTP\Parameters\UrlAclInfo
Key HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}
Key HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters
Key HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{CD92F713-932C-408C-8949-BB093689FC55}
Key HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{BC84A6B9-5917-4C43-BB0C-677211465A7A}
Key HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\PersistentRoutes
Key \REGISTRY\A\{1FCA8D79-39FF-11E5-9029-60EB69F488AD}\DefaultObjectStore\IndexTable
Key \REGISTRY\A\{1FCA8D79-39FF-11E5-9029-60EB69F488AD}\DefaultObjectStore\LruList
Key \REGISTRY\A\{1FCA8D79-39FF-11E5-9029-60EB69F488AD}\DefaultObjectStore\ObjectTable
Key HKLM\SYSTEM\ControlSet001\services\NativeWifiP\Parameters\Adapters\{BC84A6B9-5917-4C43-BB0C-677211465A7A}\ExtSTA
Key \REGISTRY\A\{1FCA8D79-39FF-11E5-9029-60EB69F488AD}
Key \REGISTRY\A\{1FCA8D79-39FF-11E5-9029-60EB69F488AD}\DefaultObjectStore
Key HKLM\SYSTEM\ControlSet001\services\NativeWifiP\Parameters\Adapters\{BC84A6B9-5917-4C43-BB0C-677211465A7A}\ExtSTAMib
Key \REGISTRY\A\{1FCA8D79-39FF-11E5-9029-60EB69F488AD}\DefaultObjectStore\IndexTable\FileIdIndex-{db706c49-4a85-4a06-afee-b494c1a7a51a}
Process System(4)
Process smss.exe(452)
Process System(4)
Process GoogleUpdate.exe(3716)
Process svchost.exe(672)
Process wininit.exe(656)
Process lsass.exe(728)
Process lsass.exe(728)
Process lsass.exe(728)
Process lsass.exe(728)
Process services.exe(704)
Process services.exe(704)
Process lsm.exe(736)
Process svchost.exe(848)
Process svchost.exe(940)
Process services.exe(704)
Process svchost.exe(848)
Process svchost.exe(848)
Process svchost.exe(940)
Process atiesrxx.exe(988)
Process atiesrxx.exe(988)
Process winlogon.exe(468)
Process svchost.exe(596)
Process svchost.exe(784)
Process svchost.exe(596)
Process svchost.exe(596)
Process svchost.exe(1100)
Process svchost.exe(596)
Process svchost.exe(672)
Process svchost.exe(784)
Process svchost.exe(784)
Process svchost.exe(784)
Process svchost.exe(1208)
Process svchost.exe(672)
Process svchost.exe(784)
Process explorer.exe(2832)
Process svchost.exe(1472)
Process atieclxx.exe(1364)
Process svchost.exe(672)
Process atieclxx.exe(1364)
Process RAVCpl64.exe(1324)
Process svchost.exe(672)
Process DiscWizardMonitor.exe(3884)
Process svchost.exe(672)
Process agent.exe(2732)
Process soffice.bin(4312)
Process ExpressTray.exe(3024)
Process jusched.exe(3248)
Process AvastSvc.exe(1640)
Process AvastSvc.exe(1640)
Process AvastSvc.exe(1640)
Process svchost.exe(1100)
Process spoolsv.exe(1740)
Process spoolsv.exe(1740)
Process svchost.exe(1776)
Process sesvc.exe(2088)
Process svchost.exe(1776)
Process svchost.exe(1472)
Process AERTSr64.exe(1908)
Process armsvc.exe(1888)
Process armsvc.exe(1888)
Process ABService.exe(2040)
Process ABService.exe(2040)
Process AERTSr64.exe(1908)
Process mDNSResponder.exe(1156)
Process svchost.exe(1388)
Process mDNSResponder.exe(1156)
Process Garmin.Cartography.MapUpdate.CoreService.exe(1392)
Process Garmin.Cartography.MapUpdate.CoreService.exe(1392)
Process svchost.exe(1776)
Process Garmin.Cartography.MapUpdate.CoreService.exe(1392)
Process svchost.exe(1388)
Process svchost.exe(1388)
Process svchost.exe(1388)
Process svchost.exe(1388)
Process svchost.exe(1388)
Process svchost.exe(1388)
Process svchost.exe(1388)
Process svchost.exe(1388)
Process svchost.exe(1388)
Process svchost.exe(1388)
Process svchost.exe(1388)
Process PDFProFiltSrvPP.exe(2064)
Process svchost.exe(784)
Process PDFProFiltSrvPP.exe(2064)
Process schedul2.exe(2164)
Process schedul2.exe(2164)
Process TeamViewer_Service.exe(2236)
Process svchost.exe(672)
Process svchost.exe(784)
Process svchost.exe(1100)
Process svchost.exe(672)
Process TeamViewer_Service.exe(2236)
Process spoolsv.exe(1740)
Process spoolsv.exe(1740)
Process svchost.exe(672)
Process spoolsv.exe(1740)
Process services.exe(704)
Process svchost.exe(672)
Process sesvc.exe(2088)
Process unchecky_bg.exe(3500)
Process CouponPrinterService.exe(3620)
Process svchost.exe(596)
Process SearchIndexer.exe(3796)
Process svchost.exe(672)
Process explorer.exe(2176)
Process AvastUI.exe(3144)
Process RAVCpl64.exe(1324)
Process MOM.exe(4480)
Process svchost.exe(5972)
Process ISUSPM.exe(3824)
Process schedhlp.exe(2528)
Process jusched.exe(3248)
Process ISUSPM.exe(3824)
Process svchost.exe(1388)
Process PresentationFontCache.exe(4364)
Process svchost.exe(672)
Process jusched.exe(3248)
Process svchost.exe(672)
Process unchecky_svc.exe(6092)
Process AvastUI.exe(3144)
Process CCC.exe(4672)
Process WmiPrvSE.exe(4156)
Process dwm.exe(3384)
Process ExpressTray.exe(3024)
Process BrYNSvc.exe(2708)
Process svchost.exe(672)
Process schedhlp.exe(2528)
Process BrYNSvc.exe(2708)
Process explorer.exe(2176)
Process svchost.exe(672)
Process svchost.exe(672)
Process svchost.exe(672)
Process CouponPrinterService.exe(3620)
Process svchost.exe(672)
Process DiscWizardMonitor.exe(3884)
Process AvastUI.exe(3144)
Process svchost.exe(796)
Process svchost.exe(672)
Process pptd40nt.exe(1688)
Process svchost.exe(672)
Process CCC.exe(4672)
Process pptd40nt.exe(1688)
Process ExpressTray.exe(3024)
Process CCC.exe(4672)
Process PresentationFontCache.exe(4364)
Process BrCcUxSys.exe(3176)
Process unsecapp.exe(4112)
Process MOM.exe(4480)
Process agent.exe(2732)
Process svchost.exe(1100)
Process dllhost.exe(3440)
Process svchost.exe(672)
Process ISUSPM.exe(3824)
Process soffice.bin(4312)
Process svchost.exe(1472)
Process soffice.bin(4312)
Process notepad.exe(8376)
Process iexplore.exe(9952)
Process Picasa3.exe(10012)
Process procexp64.exe(11268)
Process iexplore.exe(8936)
Process iexplore.exe(8936)
Process waterfox.exe(10656)
Process procexp64.exe(11268)
Process taskmgr.exe(9708)
Process svchost.exe(784)
Process iexplore.exe(9952)
Process waterfox.exe(10656)
Process Picasa3.exe(10012)
Process Picasa3.exe(10012)
Section \Win32kCrossSessionGlobals
Section \Device\PhysicalMemory
Session \KernelObjects\Session0
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Thread System(4): 160
Thread System(4): 512
Thread System(4): 684
Thread System(4): 1220
Thread System(4): 1224
Thread System(4): 1732
Thread System(4): 1728
Thread System(4): 1736
Thread System(4): 1808
Thread System(4): 1828
Thread System(4): 1788
Thread System(4): 3860
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\NETWORK SERVICE:3e4
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\NETWORK SERVICE:3e4
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\ANONYMOUS LOGON:26398
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\ANONYMOUS LOGON:3e6
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\SYSTEM:3e7
Token OneGuy\Ron:6ccae