1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Computer runs very slow

Discussion in 'Malware and Virus Removal Archive' started by natalia, 2010/11/07.

  1. 2010/11/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Well, there is not really much, you can do about it.
    Bumping RAM up may help.
     
  2. 2010/11/09
    natalia

    natalia Inactive Thread Starter

    Joined:
    2010/11/07
    Messages:
    34
    Likes Received:
    0
    OTL:
    All processes killed
    ========== OTL ==========
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ deleted successfully.
    C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
    C:\WINDOWS\002757_.tmp deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter s\FirewallPolicy\StandardProfile\\ "EnableFirewall" |dword:00000001 /E : value set successfully!
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 32768 bytes

    User: LocalService
    ->Temp folder emptied: 65536 bytes
    ->Temporary Internet Files folder emptied: 67 bytes

    User: NetworkService
    ->Temp folder emptied: 1488 bytes
    ->Temporary Internet Files folder emptied: 32835 bytes

    User: RkUnhooker

    User: User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 233888 bytes
    ->Java cache emptied: 56390 bytes
    ->FireFox cache emptied: 61431535 bytes
    ->Flash cache emptied: 459 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 1325 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
    RecycleBin emptied: 10282 bytes

    Total Files Cleaned = 59.00 mb


    [EMPTYFLASH]

    User: Administrator

    User: All Users

    User: Default User

    User: LocalService

    User: NetworkService

    User: RkUnhooker

    User: User
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.17.3 log created on 11092010_133731

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
     

  3. to hide this advert.

  4. 2010/11/09
    natalia

    natalia Inactive Thread Starter

    Joined:
    2010/11/07
    Messages:
    34
    Likes Received:
    0
    Security Check:
    Results of screen317's Security Check version 0.99.5
    Windows XP Service Pack 3
    Internet Explorer 8
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    Microsoft Security Essentials
    Antivirus up to date!
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    Java 2 Runtime Environment, SE v1.4.2_05
    Adobe Reader 7.0
    Out of date Adobe Reader installed!
    Mozilla Firefox (3.6.3) Firefox Out of Date!
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Windows Defender MSMpEng.exe
    Microsoft Security Essentials msseces.exe
    ````````````````````````````````
    DNS Vulnerability Check:

    Request Timed Out (Wireless Internet connection/Disconnected Internet/Proxy?)

    ``````````End of Log````````````
     
  5. 2010/11/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It looks like you didn't follow my reply #19 regarding updating Java and removing old versions.
    Please, do it now.

    Update Firefox to the current 3.6.12 version.

    Update Adobe Reader

    You can download it from http://www.adobe.com/products/acrobat/readstep2.html
    After installing the latest Adobe Reader, uninstall all previous versions.
    Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

    Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
    It's a much smaller file to download and uses a lot less resources than Adobe Reader.
    Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or other garbage.
    On this page:

    [​IMG]

    make sure, you have both boxes UN-checked AND (important!) click on Decline button
     
  6. 2010/11/09
    natalia

    natalia Inactive Thread Starter

    Joined:
    2010/11/07
    Messages:
    34
    Likes Received:
    0
    When I attempt to run the website you provided in post #19, the webpage became unresponsive and I've to end Mozilla Firefox.
    I'll update the Firefox and Adobe Reader later...

    And....... After I've replied to this thread, the browser redirects itself to the advertisments pages and it is loading continously......... I've to go back to the webpage to see the thread.
     
    Last edited: 2010/11/09
  7. 2010/11/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    If something like this happens, you have to let me know, not just skip it.
    Which site? For Java update, or for JavaRa?
     
  8. 2010/11/09
    natalia

    natalia Inactive Thread Starter

    Joined:
    2010/11/07
    Messages:
    34
    Likes Received:
    0
    Java Update
    JavaRa no problem
     
  9. 2010/11/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  10. 2010/11/09
    natalia

    natalia Inactive Thread Starter

    Joined:
    2010/11/07
    Messages:
    34
    Likes Received:
    0
    the website is working well.... :)
    JavaRa log:
    JavaRa 1.16 Removal Log.

    Report follows after line.

    ------------------------------------

    The JavaRa removal process was started on Wed Nov 10 12:03:51 2010

    Found and removed: C:\Program Files\Java\j2re1.4.2_05

    Found and removed: C:\WINDOWS\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142050}

    Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142050}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410205

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410205

    Found and removed: SOFTWARE\Classes\JavaPlugin.142_05

    Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_04

    Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_05

    Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_05

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_05

    Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}

    Found and removed: Software\Classes\JavaPlugin.142_04

    Found and removed: Software\Classes\JavaPlugin.142_05

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACB9B14518A96D117A58000B0D410205

    Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

    ------------------------------------

    Finished reporting.
     
  11. 2010/11/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Now....Eset scan...
     
  12. 2010/11/09
    natalia

    natalia Inactive Thread Starter

    Joined:
    2010/11/07
    Messages:
    34
    Likes Received:
    0
    Eset report will prepare tomorrow because the school dismissed......
     
  13. 2010/11/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No problem :)
     
  14. 2010/11/10
    natalia

    natalia Inactive Thread Starter

    Joined:
    2010/11/07
    Messages:
    34
    Likes Received:
    0
    I've ran Eset Online Scanner, but it found no threats.....
    And 2 wuauclt.exe is running on the background and It eats up a lot of memory usage. Mozilla Firefox also takes a long time now to start.
     
  15. 2010/11/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    wuauclt.exe is a part of Windows Updates.
    I said before:
    Let's check couple of things....

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    64-bit users go HERE
    • Double-click SystemLook.exe to run it.
    • Vista users:: Right click on SystemLook.exe, click Run As Administrator
    • Copy the content of the following box into the main textfield:
      Code:
      :filefind
      wuauclt.exe
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    ===============================================================

    Download Process Explorer: http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
    Unzip ProcessExplorer.zip, and double click on procexp.exe to run the program.
    Click on View > Select Colunms.
    In addition to already pre-selected options, make sure, the Command Line is selected, and press OK.
    Go File>Save As, and save the report as Procexp.txt.
    Attach the file to your next reply.
     
  16. 2010/11/10
    natalia

    natalia Inactive Thread Starter

    Joined:
    2010/11/07
    Messages:
    34
    Likes Received:
    0
    System LOOK:
    SystemLook 04.09.10 by jpshortstuff
    Log created at 10:36 on 11/11/2010 by User
    Administrator - Elevation successful

    ========== filefind ==========

    Searching for "wuauclt.exe "
    C:\WINDOWS\ERDNT\cache\wuauclt.exe --a---- 53472 bytes [03:49 09/11/2010] [11:24 06/08/2009] 62BB79160F86CD962F312C68C6239BFD
    C:\WINDOWS\ServicePackFiles\i386\wuauclt.exe ------- 111104 bytes [07:12 29/12/2008] [21:42 13/04/2008] ED7262E52C31CF1625B65039102BC16C
    C:\WINDOWS\system32\wuauclt.exe --a---- 53472 bytes [01:56 01/04/2005] [11:24 06/08/2009] 62BB79160F86CD962F312C68C6239BFD
    C:\WINDOWS\system32\dllcache\wuauclt.exe --a---- 53472 bytes [01:56 01/04/2005] [11:24 06/08/2009] 62BB79160F86CD962F312C68C6239BFD

    -= EOF =-
     
  17. 2010/11/10
    natalia

    natalia Inactive Thread Starter

    Joined:
    2010/11/07
    Messages:
    34
    Likes Received:
    0
    Process Explorer:
    Process PID CPU Private Bytes Working Set Description Company Name Command Line
    System Idle Process 0 96.92 0 K 28 K
    Interrupts n/a 1.54 0 K 0 K Hardware Interrupts
    DPCs n/a 0 K 0 K Deferred Procedure Calls
    System 4 0 K 56 K
    smss.exe 668 172 K 112 K Windows NT Session Manager Microsoft Corporation \SystemRoot\System32\smss.exe
    csrss.exe 724 1,856 K 1,524 K Client Server Runtime Process Microsoft Corporation C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
    winlogon.exe 748 7,984 K 1,100 K Windows NT Logon Application Microsoft Corporation winlogon.exe
    services.exe 796 1,892 K 1,604 K Services and Controller app Microsoft Corporation C:\WINDOWS\system32\services.exe
    svchost.exe 952 3,184 K 808 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe 1020 1,888 K 1,360 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost -k rpcss
    MsMpEng.exe 1076 169,476 K 45,180 K AntiMalware Service Executable Microsoft Corporation "C:\Program Files\Microsoft Security Essentials\MsMpEng.exe "
    svchost.exe 1120 21,788 K 16,980 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe 1232 1,724 K 1,472 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost.exe -k NetworkService
    svchost.exe 1308 1,708 K 732 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost.exe -k LocalService
    spoolsv.exe 1948 3,588 K 1,544 K Spooler SubSystem App Microsoft Corporation C:\WINDOWS\system32\spoolsv.exe
    CNAB4RPK.EXE 624 596 K 176 K Canon Advanced Printing Technology RPC Server Process CANON INC. C:\WINDOWS\system32\CNAB4RPK.EXE
    svchost.exe 568 1,500 K 176 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost.exe -k LocalService
    CLCapSvc.exe 612 4,556 K 404 K CLCapSvc Module "c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe "
    CLMLServer.exe 712 452 K 128 K NT CLMLServer Cyberlink "C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe "
    CLMLService.exe 916 12,404 K 1,364 K Cyberlink MediaLibrary NT Service Cyberlink CLMLService.exe
    HidService.exe 908 1,624 K 204 K c:\APPS\HIDSERVICE\HIDSERVICE.exe
    jqs.exe 1212 2,172 K 1,412 K Java(TM) Quick Starter Service Sun Microsystems, Inc. "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf "
    MDM.EXE 1164 1,076 K 468 K Machine Debug Manager Microsoft Corporation "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE "
    SMAgent.exe 1644 660 K 152 K SoundMAX service agent component Analog Devices, Inc. "C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe "
    wdfmgr.exe 1712 1,656 K 136 K Windows User Mode Driver Manager Microsoft Corporation C:\WINDOWS\system32\wdfmgr.exe
    CLSched.exe 196 1,148 K 432 K CLSched Module "c:\APPS\Powercinema\Kernel\TV\CLSched.exe "
    alg.exe 2348 1,304 K 204 K Application Layer Gateway Service Microsoft Corporation C:\WINDOWS\System32\alg.exe
    lsass.exe 808 3,944 K 1,052 K LSA Shell (Export Version) Microsoft Corporation C:\WINDOWS\system32\lsass.exe
    explorer.exe 1688 17,792 K 13,008 K Windows Explorer Microsoft Corporation C:\WINDOWS\Explorer.EXE
    msseces.exe 1300 4,444 K 1,112 K Microsoft Security Essentials User Interface Microsoft Corporation "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
    jusched.exe 1672 964 K 112 K Java(TM) Update Scheduler Sun Microsystems, Inc. "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    ctfmon.exe 1740 1,020 K 484 K CTF Loader Microsoft Corporation "C:\WINDOWS\system32\ctfmon.exe"
    taskmgr.exe 296 1,540 K 2,116 K Windows TaskManager Microsoft Corporation C:\WINDOWS\system32\taskmgr.exe
    firefox.exe 1716 67,876 K 69,300 K Firefox Mozilla Corporation "C:\Program Files\Mozilla Firefox\firefox.exe"
    procexp.exe 2708 1.54 7,960 K 8,236 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com "C:\Documents and Settings\User\Desktop\procexp.exe "
     
  18. 2010/11/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    wuauclt.exe is in correct location and I can't see it running in Process Explorer.
    Maybe you caught it, while it was checking for Windows updates.

    Are you experiencing same issues right at this moment?
     
  19. 2010/11/10
    natalia

    natalia Inactive Thread Starter

    Joined:
    2010/11/07
    Messages:
    34
    Likes Received:
    0
    AW! the two processes is nowhere seen......... but Mozilla Firefox still running slowly.....
     
  20. 2010/11/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Close Firefox. Go Start>All Programs>Mozilla Firefox, click on Mozilla Firefox (safe mode). Same thing?
     
  21. 2010/11/10
    natalia

    natalia Inactive Thread Starter

    Joined:
    2010/11/07
    Messages:
    34
    Likes Received:
    0
    HMM... It's faster than before......
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.