1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Computer running almost 100% with no active programs.

Discussion in 'Malware and Virus Removal Archive' started by pilotgal8, 2010/10/28.

Thread Status:
Not open for further replies.
  1. 2010/10/28
    pilotgal8 Lifetime Subscription

    pilotgal8 Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    459
    Likes Received:
    0
    [Inactive] Computer running almost 100% with no active programs.

    DDS logs here,


    DDS (Ver_09-06-26.01) - NTFSx86
    Run by Rosemary at 9:22:56.53 on Thu 10/28/2010
    Internet Explorer: 8.0.6001.18702
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2045.838 [GMT -4:00]

    AV: AVG Anti-Virus Free Edition 2011 *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    ============== Running Processes ===============

    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    svchost.exe
    C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    C:\Program Files\iolo\common\lib\ioloServiceManager.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\RealVNC\VNC4\WinVNC4.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\WINDOWS\system32\fxssvc.exe
    C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
    C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
    C:\WINDOWS\system32\rsvp.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
    C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
    C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
    C:\Program Files\Quicken2010\bagent.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    C:\PROGRA~1\AVG\AVG10\avgrsx.exe
    C:\Program Files\AVG\AVG10\avgcsrvx.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\WINDOWS\System32\vssvc.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\Program Files\AVG\AVG10\avgtray.exe
    C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
    C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    C:\Program Files\AVG\AVG10\avgwdsvc.exe
    C:\Program Files\AVG\AVG10\avgnsx.exe
    C:\Program Files\AVG\AVG10\avgemcx.exe
    C:\Program Files\AVG\AVG10\avgchsvx.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\Data\Sysclean Utilities\DDS\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.goodsearch.com/
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: GhosteryBHO Class: {237eb6da-3fea-4dd2-8a61-a901b5c489d7} - c:\program files\ghosteryieplugin\GhosteryBrowserHelperObjec.dll
    BHO: Yahooo Search Protection: {25bc7718-0bfa-40ea-b381-4b2d9732d686} - c:\program files\yahoo!\search protection\ysp.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
    uRun: [PxDotNetLoader] "c:\program files\fidelity investments\fidelity active trader\system\ATPStartupAssistant.exe "
    uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
    uRun: [QuickenScheduledUpdates] c:\program files\quicken2010\bagent.exe
    uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [ehTray] c:\windows\ehome\ehtray.exe
    mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe "
    mRun: [IntelAudioStudio] "c:\program files\intel audio studio\IntelAudioStudio.exe" TRAY
    mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe "
    mRun: [CCUTRAYICON] c:\program files\intel\inteldh\ccu\CCU_TrayIcon.exe
    mRun: [NMSSupport] "c:\program files\common files\intel\inteldh\nms\support\IntelHCTAgent.exe" /startup
    mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup
    mRun: [Samsung PanelMgr] c:\windows\samsung\panelmgr\SSMMgr.exe /autorun
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe "
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe "
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe "
    mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
    mRun: [Carbonite Backup] c:\program files\carbonite\carbonite backup\CarboniteUI.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {237EB6DA-3FEA-4DD2-8A61-A901B5C489D7} - {237EB6DA-3FEA-4DD2-8A61-A901B5C489D7} - c:\program files\ghosteryieplugin\GhosteryBrowserHelperObjec.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
    Trusted Zone: bankatlantic.com
    Trusted Zone: facebook.com
    Trusted Zone: fundsexpress.com
    Trusted Zone: ibmsecu.org
    Trusted Zone: intuit.com\ttlc
    Trusted Zone: turbotax.com
    DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://download.macromedia.com/pub/shockwave/cabs/authorware/awswax70.cab
    DPF: {2703049B-D81D-4763-A3C6-AF8932FCBD8F} - hxxps://am.hrblock.com/ActivexComponent/CheckFileStatus.CAB
    DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} - hxxp://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISWebManager.CAB
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1182539247843
    DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182539214796
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\intuit\quickbooks 2009\HelpAsyncPluggableProtocol.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
    Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
    Handler: x-atng - {7e8717b0-d862-11d5-8c9e-00010304f989} - c:\program files\fidelity investments\fidelity active trader\system\atngprot.dll
    Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
    Notify: AtiExtEvent - Ati2evxx.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
    SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

    ============= SERVICES / DRIVERS ===============

    R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
    R0 zmNTMon;zmNTMon;c:\windows\system32\drivers\ZmNTMon.sys [2007-12-3 5760]
    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 249424]
    R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 298448]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-6 67656]
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2010-10-11 6104656]
    R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-9-10 265400]
    R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2009-9-29 13088]
    R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2010-1-12 711352]
    R2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2010-1-12 711352]
    R2 MCLServiceATL;Intel(R) Application Tracker;c:\program files\intel\inteldh\intel media server\shells\MCLServiceATL.exe [2006-11-10 170456]
    R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
    R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]
    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]
    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 26192]
    S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys --> c:\windows\system32\drivers\Lbd.sys [?]
    S2 SSPORT;SSPORT;\??\c:\windows\system32\drivers\ssport.sys --> c:\windows\system32\drivers\SSPORT.sys [?]
    S3 zmNTZip;zmNTZip;c:\program files\ontrack\zipmagic\zmNTZip.sys [2007-12-3 155576]

    ============== File Associations ===============

    JSEFile=NOTEPAD.EXE %1

    =============== Created Last 30 ================

    2010-10-18 02:57 74,703 a------- c:\windows\system32\mfc45.dll
    2010-10-16 12:41 <DIR> --d----- c:\docume~1\rosemary\applic~1\AVG10
    2010-10-16 12:39 <DIR> --d----- c:\windows\system32\drivers\AVG
    2010-10-16 12:39 <DIR> --d----- c:\docume~1\alluse~1\applic~1\AVG10
    2010-10-16 09:50 <DIR> --d----- c:\docume~1\alluse~1\applic~1\MFAData
    2010-10-13 11:22 3,283 a------- c:\windows\system32\wbem\Outlook_01cb6aea6b973cda.mof
    2010-10-13 05:20 953,856 -------- c:\windows\system32\dllcache\mfc40u.dll
    2010-10-13 05:18 617,472 -------- c:\windows\system32\dllcache\comctl32.dll

    ==================== Find3M ====================

    2010-09-18 12:23 974,848 a------- c:\windows\system32\mfc42u.dll
    2010-09-18 12:23 974,848 a------- c:\windows\system32\dllcache\mfc42u.dll
    2010-09-18 02:53 974,848 a------- c:\windows\system32\mfc42.dll
    2010-09-18 02:53 974,848 a------- c:\windows\system32\dllcache\mfc42.dll
    2010-09-18 02:53 954,368 a------- c:\windows\system32\mfc40.dll
    2010-09-18 02:53 954,368 a------- c:\windows\system32\dllcache\mfc40.dll
    2010-09-18 02:53 953,856 -------- c:\windows\system32\mfc40u.dll
    2010-09-15 04:50 472,808 a------- c:\windows\system32\deployJava1.dll
    2010-09-13 16:27 25,680 a------- c:\windows\system32\drivers\AVGIDSEH.sys
    2010-09-07 03:49 298,448 a------- c:\windows\system32\drivers\avgtdix.sys
    2010-09-07 03:48 249,424 a------- c:\windows\system32\drivers\avgldx86.sys
    2010-09-07 03:48 26,064 a------- c:\windows\system32\drivers\avgrkx86.sys
    2010-09-06 04:04 14,088 ac------ c:\windows\system32\drivers\PROCEXP141.SYS
    2010-09-01 07:51 285,824 a------- c:\windows\system32\atmfd.dll
    2010-09-01 07:51 285,824 -------- c:\windows\system32\dllcache\atmfd.dll
    2010-08-31 09:42 1,852,800 a------- c:\windows\system32\win32k.sys
    2010-08-31 09:42 1,852,800 -------- c:\windows\system32\dllcache\win32k.sys
    2010-08-27 04:02 119,808 a------- c:\windows\system32\t2embed.dll
    2010-08-27 04:02 119,808 -------- c:\windows\system32\dllcache\t2embed.dll
    2010-08-27 01:57 99,840 a------- c:\windows\system32\srvsvc.dll
    2010-08-27 01:57 99,840 -------- c:\windows\system32\dllcache\srvsvc.dll
    2010-08-26 09:39 357,248 a------- c:\windows\system32\dllcache\srv.sys
    2010-08-26 08:52 5,120 a------- c:\windows\system32\xpsp4res.dll
    2010-08-26 08:22 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe
    2010-08-26 07:08 13,312 -------- c:\windows\system32\dllcache\iecompat.dll
    2010-08-25 23:36 10,841,088 a------- c:\windows\system32\dllcache\wmp.dll
    2010-08-23 12:12 617,472 -------- c:\windows\system32\comctl32.dll
    2010-08-17 09:17 58,880 a------- c:\windows\system32\spoolsv.exe
    2010-08-16 04:45 590,848 a------- c:\windows\system32\rpcrt4.dll
    2010-08-16 04:45 590,848 -------- c:\windows\system32\dllcache\rpcrt4.dll
    2009-10-19 14:17 4,732,319 ac------ c:\docume~1\rosemary\applic~1\family.zip
    2007-06-23 18:04 552 ac------ c:\docume~1\rosemary\applic~1\wklnhst.dat

    ============= FINISH: 9:25:47.51 ===============




    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-06-26.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 6/22/2007 2:13:23 PM
    System Uptime: 10/26/2010 9:51:00 AM (48 hours ago)

    Motherboard: Intel Corporation | | D975XBX
    Processor: Intel(R) Pentium(R) D CPU 3.20GHz | J3E1 | 3200/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 233 GiB total, 193.567 GiB free.
    D: is CDROM ()
    E: is Removable
    F: is Removable
    G: is Removable
    H: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP1: 8/6/2010 5:42:44 AM - System Checkpoint
    RP2: 8/7/2010 6:05:24 AM - System Checkpoint
    RP3: 8/8/2010 9:16:20 AM - System Checkpoint
    RP4: 8/9/2010 3:15:19 PM - System Checkpoint
    RP5: 8/10/2010 6:07:20 PM - Software Distribution Service 3.0
    RP6: 8/11/2010 2:20:04 AM - Software Distribution Service 3.0
    RP7: 8/11/2010 8:30:50 AM - Removed Windows Live Sync
    RP8: 8/11/2010 8:31:05 AM - Software Distribution Service 3.0
    RP9: 8/11/2010 6:12:28 PM - Removed Windows Live Sign-in Assistant
    RP10: 8/16/2010 1:07:34 PM - Avg Update
    RP11: 8/21/2010 9:50:22 AM - System Checkpoint
    RP12: 8/24/2010 11:57:15 AM - System Checkpoint
    RP13: 9/15/2010 7:24:08 AM - Software Distribution Service 3.0
    RP14: 9/22/2010 6:37:55 AM - Printer Driver CC PDF Virtual Printer Installed
    RP15: 9/23/2010 9:17:35 AM - Avg Update
    RP16: 9/23/2010 9:19:06 AM - Avg Update
    RP17: 10/3/2010 12:38:46 PM - System Checkpoint
    RP18: 10/5/2010 8:22:38 AM - Avg Update
    RP19: 10/6/2010 4:49:00 PM - Software Distribution Service 3.0
    RP20: 10/7/2010 9:11:21 PM - Software Distribution Service 3.0
    RP21: 10/13/2010 3:37:43 AM - System Checkpoint
    RP22: 10/13/2010 5:22:15 AM - Software Distribution Service 3.0
    RP23: 10/16/2010 9:48:33 AM - Removed Microsoft Office Live Add-in 1.3
    RP24: 10/16/2010 10:00:19 AM - Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    RP25: 10/16/2010 10:00:37 AM - Installed AVG 2011
    RP26: 10/16/2010 10:02:16 AM - Removed AVG Free 9.0
    RP27: 10/16/2010 12:38:38 PM - Installed AVG 2011
    RP28: 10/16/2010 12:42:42 PM - Installed Java(TM) 6 Update 22
    RP29: 10/16/2010 5:38:14 PM - Software Distribution Service 3.0
    RP30: 10/19/2010 2:59:11 PM - Software Distribution Service 3.0
    RP31: 10/20/2010 3:41:01 PM - System Checkpoint
    RP32: 10/25/2010 6:48:34 PM - System Checkpoint
    RP33: 10/26/2010 8:10:04 PM - System Checkpoint

    ==== Installed Programs ======================


    2000 TurboTax for Windows
    2001 TurboTax for Windows
    7200
    7200_Help
    7200Trb
    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Photoshop 7.0
    Adobe Product/Adobe Studio Update 10/2001
    Adobe Reader 8.1.2 Security Update 1 (KB403742)
    Adobe Reader 9.4.0
    Advanced Analyzer
    AiO_Scan
    AiOSoftware
    AnswerWorks 4.0 Runtime - English
    AnswerWorks 5.0 English Runtime
    ATI Display Driver
    Avery Wizard 3.1
    AVG 2011
    Broderbund Media Manager
    BufferChm
    Carbonite
    Compatibility Pack for the 2007 Office system
    Copy
    Coupon Printer for Windows
    CP_AtenaShokunin1Config
    cp_dwShrek2Albums1
    cp_dwShrek2Cards1
    CreativeProjects
    CreativeProjectsTemplates
    Critical Update for Windows Media Player 11 (KB959772)
    CueTour
    Debugging Tools for Windows
    Debugging Tools for Windows (x86)
    Destinations
    Director
    DocProc
    DocumentViewer
    doPDF 5.0 printer
    EasyCleaner
    Fax
    Fidelity Active Trader Pro®
    Ghostery IE Plugin
    Gleim EA Test Prep 2010 WebDeploy
    Google Earth
    Google Updater
    GoToMeeting 4.0.0.320
    High Definition Audio Driver Package - KB888111
    Hotfix for Microsoft .NET Framework 3.0 (KB932471)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 10 (KB903157)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB2158563)
    Hotfix for Windows XP (KB915800-v4)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB954708)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    HP Extended Capabilities 4.7
    HP Image Zone 4.7
    HP Officejet 7200 series
    HP Product Assistant
    HP Product Detection
    HP PSC & OfficeJet 4.7
    HP Update
    HPSystemDiagnostics
    InstantShare
    Intel Audio Studio 2.0
    Intel(R) Matrix Storage Manager
    Intel(R) PRO Network Connections Drivers
    Intel(R) Quick Resume Technology Drivers
    Intel® Viivâ„¢ Software
    Intuit Entitlement Client
    iolo technologies' System Mechanic Professional
    ItsDeductible Express
    Java Auto Updater
    Java(TM) 6 Update 22
    LaserJet 1020 series
    Macromedia Shockwave Player
    Malwarebytes' Anti-Malware
    MarketResearch
    MediaShow 3.0
    Microsoft .NET Framework 1.0 Hotfix (KB953295)
    Microsoft .NET Framework 1.0 Hotfix (KB979904)
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Base Smart Card Cryptographic Service Provider Package
    Microsoft Choice Guard
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Digital Image Library 9 - Blocker
    Microsoft Digital Image Standard 2006
    Microsoft Digital Image Standard 2006 Editor
    Microsoft Digital Image Standard 2006 Library
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
    Microsoft Office 2003 Primary Interop Assemblies
    Microsoft Office Outlook Connector
    Microsoft Office Professional Edition 2003
    Microsoft Silverlight
    Microsoft Streets & Trips 2006
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual Studio 2005 Tools for Office Runtime
    Microsoft Web Publishing Wizard 1.52
    Microsoft Works Suite 2006 Setup Launcher
    mIRC
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP2 Parser and SDK
    MSXML 6.0 Parser (KB933579)
    OIB4 Training Install Kit
    Ontrack ZipMagic 4.0
    OrchidWiz Encyclopedia
    OrderReminder HP LaserJet 1020
    PanoStandAlone
    PCI SoftV92 Modem
    PDF Creator (Remove Only)
    Pdf995
    PhotoGallery
    PowerDVD
    PowerProducer
    PowerStarter
    ProductContext
    ProSeries Basic Edition 2007
    QFolder
    QuickBooks
    QuickBooks Premier: Accountant Edition 2007
    QuickBooks Pro 2009
    Quicken 2010
    QuoteTracker
    Readme
    SafeCast Shared Components
    Samsung CLP-310 Series
    Scan
    ScannerCopy
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Windows Internet Explorer 8 (KB2183461)
    Security Update for Windows Internet Explorer 8 (KB2360131)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows Media Player (KB2378111)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB975558)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Search 4 - KB963093
    Security Update for Windows XP (KB2079403)
    Security Update for Windows XP (KB2115168)
    Security Update for Windows XP (KB2121546)
    Security Update for Windows XP (KB2160329)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB2259922)
    Security Update for Windows XP (KB2279986)
    Security Update for Windows XP (KB2286198)
    Security Update for Windows XP (KB2296011)
    Security Update for Windows XP (KB2347290)
    Security Update for Windows XP (KB2360937)
    Security Update for Windows XP (KB2387149)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB963027)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969897)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB972260)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974455)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB976325)
    Security Update for Windows XP (KB977165)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB979687)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB980436)
    Security Update for Windows XP (KB981322)
    Security Update for Windows XP (KB981349)
    Security Update for Windows XP (KB981852)
    Security Update for Windows XP (KB981957)
    Security Update for Windows XP (KB981997)
    Security Update for Windows XP (KB982132)
    Security Update for Windows XP (KB982214)
    Security Update for Windows XP (KB982381)
    Security Update for Windows XP (KB982665)
    Security Update for Windows XP (KB982802)
    Shockwave
    SigmaTel Audio
    SkinsHP1
    Spelling Dictionaries Support For Adobe Reader 8
    SpywareBlaster 4.1
    SUPERAntiSpyware Free Edition
    SupportSoft Assisted Service
    TaxCut Premium + State + Efile 2008
    TrayApp
    TurboTax 2008
    TurboTax 2008 wgaiper
    TurboTax 2008 WinPerFedFormset
    TurboTax 2008 WinPerProgramHelp
    TurboTax 2008 WinPerReleaseEngine
    TurboTax 2008 WinPerTaxSupport
    TurboTax 2008 WinPerUserEducation
    TurboTax 2008 wrapper
    TurboTax 2009
    TurboTax 2009 wgaiper
    TurboTax 2009 WinPerFedFormset
    TurboTax 2009 WinPerReleaseEngine
    TurboTax 2009 WinPerTaxSupport
    TurboTax 2009 wnciper
    TurboTax 2009 wrapper
    TurboTax Deluxe 2004
    TurboTax Deluxe 2005
    TurboTax Deluxe 2007
    TurboTax Deluxe Deduction Maximizer 2006
    TurboTax ItsDeductible 2005
    TurboTax ItsDeductible 2006
    Tweak UI
    Unload
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Windows (KB971513)
    Update for Windows Internet Explorer 8 (KB2362765)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows Internet Explorer 8 (KB982632)
    Update for Windows Internet Explorer 8 (KB982664)
    Update for Windows Media Player 10 (KB913800)
    Update for Windows Media Player 10 (KB926251)
    Update for Windows XP (KB2141007)
    Update for Windows XP (KB2345886)
    Update for Windows XP (KB943729)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951618-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    Update for Windows XP (KB976749)
    Update for Windows XP (KB978207)
    Update for Windows XP (KB980182)
    Update Rollup 2 for Windows XP Media Center Edition 2005
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    Visual Studio 2005 Tools for Office Second Edition Runtime
    VNC 4.0
    WebFldrs XP
    WebReg
    WexTech AnswerWorks
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Imaging Component
    Windows Internet Explorer 8
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Presentation Foundation
    Windows Search 4.0
    Windows XP Media Center Edition 2005 KB908250
    Windows XP Media Center Edition 2005 KB925766
    Windows XP Media Center Edition 2005 KB973768
    Windows XP Service Pack 3
    Works Upgrade
    XML Paper Specification Shared Components Pack 1.0
    Yahoo! Messenger
    Yahoo! Search Protection
    Yahoo! Software Update

    ==== Event Viewer Messages From Past Week ========

    10/27/2010 1:10:16 PM, error: Removable Storage Service [15] - RSM cannot manage library PhysicalDrive1. The database is corrupt.
    10/25/2010 3:13:44 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the CarboniteService service, but this action failed with the following error: An instance of the service is already running.
    10/25/2010 3:13:19 PM, error: Service Control Manager [7031] - The CarboniteService service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    10/25/2010 3:12:47 PM, error: Service Control Manager [7031] - The CarboniteService service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    10/25/2010 3:12:47 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Beep Lbd
    10/25/2010 3:12:22 PM, error: Service Control Manager [7023] - The Intel(R) Quick Resume technology service terminated with the following error: The system could not find the environment option that was entered.
    10/25/2010 3:12:18 PM, error: Service Control Manager [7023] - The HID Input Service service terminated with the following error: The specified module could not be found.
    10/25/2010 3:12:18 PM, error: Service Control Manager [7000] - The SSPORT service failed to start due to the following error: The system cannot find the file specified.
    10/25/2010 3:12:18 PM, error: Service Control Manager [7000] - The DgiVecp service failed to start due to the following error: The system cannot find the file specified.
    10/25/2010 3:11:51 PM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 0016761F508E has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    10/22/2010 1:08:50 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service CarboniteService with arguments " " in order to run the server: {36471C67-6A93-4434-92CC-4C614CD06666}

    ==== End Of File ===========================
     
  2. 2010/10/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Download Process Explorer: http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
    Unzip ProcessExplorer.zip, and double click on procexp.exe to run the program.
    Click on View > Select Colunms.
    In addition to already pre-selected options, make sure, the Command Line is selected, and press OK.
    Go File>Save As, and save the report as Procexp.txt.
    Paste the content into your next reply.
     

  3. to hide this advert.

  4. 2010/10/28
    pilotgal8 Lifetime Subscription

    pilotgal8 Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    459
    Likes Received:
    0
    Process PID CPU Private Bytes Working Set Description Company Name Command Line
    System Idle Process 0 80.30 0 K 28 K
    Interrupts n/a 0 K 0 K Hardware Interrupts
    DPCs n/a 13.64 0 K 0 K Deferred Procedure Calls
    System 4 0.76 0 K 109,644 K
    smss.exe 652 172 K 428 K Windows NT Session Manager Microsoft Corporation \SystemRoot\System32\smss.exe
    csrss.exe 864 1,852 K 5,836 K Client Server Runtime Process Microsoft Corporation C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
    winlogon.exe 920 13,396 K 2,196 K Windows NT Logon Application Microsoft Corporation winlogon.exe
    services.exe 964 1.47 1,960 K 4,840 K Services and Controller app Microsoft Corporation C:\WINDOWS\system32\services.exe
    ati2evxx.exe 1152 860 K 3,112 K ATI External Event Utility EXE Module ATI Technologies Inc. C:\WINDOWS\system32\Ati2evxx.exe
    svchost.exe 1172 0.74 3,444 K 6,652 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost -k DcomLaunch
    CCU_Engine.exe 2960 3,616 K 5,672 K Intel® Viivâ„¢ Settings Intel Corporation "C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe" -Embedding
    svchost.exe 1240 2,516 K 6,344 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost -k rpcss
    svchost.exe 1372 24,748 K 40,368 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe 1452 1,588 K 3,976 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost.exe -k NetworkService
    svchost.exe 1600 1,220 K 3,316 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost.exe -k LocalService
    spoolsv.exe 1776 4,880 K 8,900 K Spooler SubSystem App Microsoft Corporation C:\WINDOWS\system32\spoolsv.exe
    svchost.exe 380 1,360 K 3,888 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost.exe -k LocalService
    AlertService.exe 412 1,784 K 5,344 K Intel® Alert Service Intel Corporation "C:\Program Files\Intel\IntelDH\CCU\AlertService.exe "
    CDAC11BA.EXE 476 332 K 1,228 K Macrovision RTS Service Macrovision C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    CarboniteService.exe 500 0.74 31,292 K 50,572 K Carbonite Secure Backup Engine Carbonite, Inc. (www.carbonite.com) "C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe "
    IAANTmon.exe 620 412 K 1,504 K RAID Monitor Intel Corporation "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe "
    IntuitUpdateService.exe 632 43,324 K 1,980 K Intuit Update Service Intuit Inc. "C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe "
    ioloServiceManager.exe 112 23,816 K 14,368 K "C:\Program Files\iolo\common\lib\ioloServiceManager.exe "
    jqs.exe 1192 2,260 K 1,852 K Java(TM) Quick Starter Service Sun Microsystems, Inc. "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf "
    RichVideo.exe 1320 840 K 3,100 K RichVideo Module "C:\Program Files\CyberLink\Shared Files\RichVideo.exe "
    svchost.exe 1484 1,520 K 4,032 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost.exe -k LocalService
    svchost.exe 1844 2,444 K 4,384 K Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost.exe -k imgsvc
    winvnc4.exe 176 924 K 3,316 K VNC Server for Win32 RealVNC Ltd. "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service
    searchindexer.exe 464 21,532 K 32,252 K Microsoft Windows Search Indexer Microsoft Corporation C:\WINDOWS\system32\SearchIndexer.exe /Embedding
    searchprotocolhost.exe 3340 4,980 K 6,348 K Microsoft Windows Search Protocol Host Microsoft Corporation "C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe228_ Global\UsGthrCtrlFltPipeMssGthrPipe228 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot) " "C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
    searchfilterhost.exe 5540 3,008 K 4,752 K Microsoft Windows Search Filter Host Microsoft Corporation "C:\WINDOWS\system32\SearchFilterHost.exe" 0 588 592 600 65536 596
    YahooAUService.exe 1624 5,908 K 8,688 K AutoUpater Service Module Yahoo! Inc. "C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe "
    fxssvc.exe 2236 1,640 K 3,856 K Fax Service Microsoft Corporation C:\WINDOWS\system32\fxssvc.exe
    ISSM.exe 2260 3,064 K 4,052 K Intel Software services manager Intel Corparation "C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe "
    MCLServiceATL.exe 2272 3,092 K 4,188 K MCL Application Tracker Intel Corparation "C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe "
    mcrdsvc.exe 2316 864 K 3,156 K MCRD Device Service Microsoft Corporation C:\WINDOWS\ehome\mcrdsvc.exe
    mediaserver.exe 2900 17,692 K 22,120 K "C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe "
    Remote UI Service.exe 3072 3,976 K 6,384 K Remote UI Service Intel Corparation "C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe "
    rsvp.exe 3972 3,456 K 1,456 K Microsoft RSVP Microsoft Corporation C:\WINDOWS\system32\rsvp.exe
    alg.exe 4068 1,236 K 3,748 K Application Layer Gateway Service Microsoft Corporation C:\WINDOWS\System32\alg.exe
    dllhost.exe 6036 3,020 K 8,360 K COM Surrogate Microsoft Corporation C:\WINDOWS\SYSTEM32\DLLHOST.EXE /PROCESSID:{02D4B3F1-FD88-11D1-960D-00805FC79235}
    msdtc.exe 6016 1,932 K 5,240 K MS DTC console program Microsoft Corporation C:\WINDOWS\system32\msdtc.exe
    AVGIDSAgent.exe 2864 20,708 K 13,836 K AVG IDS application AVG Technologies CZ, s.r.o. "C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe "
    avgwdsvc.exe 2064 11,752 K 20,232 K AVG Watchdog Service AVG Technologies CZ, s.r.o. "C:\Program Files\AVG\AVG10\avgwdsvc.exe "
    avgnsx.exe 4244 9,940 K 2,004 K AVG Online Shield Service AVG Technologies CZ, s.r.o. "C:\Program Files\AVG\AVG10\avgnsx.exe "
    avgemcx.exe 5708 1,464 K 5,044 K AVG E-mail Scanner AVG Technologies CZ, s.r.o. "C:\Program Files\AVG\AVG10\avgemcx.exe "
    avgchsvx.exe 3352 18,612 K 256 K AVG Cache Server AVG Technologies CZ, s.r.o.
    PresentationFontCache.exe 4648 15,392 K 15,172 K PresentationFontCache.exe Microsoft Corporation c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
    lsass.exe 976 4,596 K 2,920 K LSA Shell (Export Version) Microsoft Corporation C:\WINDOWS\system32\lsass.exe
    ati2evxx.exe 1568 1,012 K 3,716 K ATI External Event Utility EXE Module ATI Technologies Inc. Ati2evxx.exe -Client
    taskmgr.exe 2712 1,480 K 5,572 K Windows TaskManager Microsoft Corporation taskmgr.exe
    explorer.exe 2016 2.21 32,084 K 18,684 K Windows Explorer Microsoft Corporation C:\WINDOWS\Explorer.EXE
    ehtray.exe 444 2,324 K 10,796 K Media Center Tray Applet Microsoft Corporation "C:\WINDOWS\ehome\ehtray.exe"
    IAAnotif.exe 3516 3,684 K 5,476 K Event Monitor User Notification Tool Intel Corporation "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
    CCU_TrayIcon.exe 3508 1,124 K 4,316 K Intel® Viivâ„¢ Settings Intel Corporation "C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe"
    IntelHCTAgent.exe 3524 5,848 K 8,604 K Network monitor for Intel® Hub Connect Technology Intel Corporation "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
    SSMMgr.exe 3644 2,692 K 4,580 K "C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe" /autorun
    jusched.exe 844 852 K 2,992 K Java(TM) Update Scheduler Sun Microsystems, Inc. "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    CarboniteUI.exe 1904 33,352 K 44,424 K Carbonite User Interface Carbonite, Inc. "C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe"
    bagent.exe 3740 6,692 K 12,544 K Quicken Background Agent Intuit Inc. "C:\Program Files\Quicken2010\bagent.exe"
    SUPERANTISPYWARE.EXE 308 72,584 K 564 K SUPERAntiSpyware Application SUPERAntiSpyware.com "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
    ctfmon.exe 1660 944 K 3,472 K CTF Loader Microsoft Corporation "C:\WINDOWS\system32\ctfmon.exe"
    hpqtra08.exe 1516 2,004 K 6,628 K HP Digital Imaging Monitor Hewlett-Packard Co. "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"
    qbupdate.exe 968 12,376 K 20,272 K QuickBooks Automatic Update Intuit Inc. "C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe"
    WindowsSearch.exe 3836 6,008 K 12,404 K Windows Search System Tray Microsoft Corporation "C:\Program Files\Windows Desktop Search\WindowsSearch.exe" /startup
    msimn.exe 4552 24,312 K 21,712 K Outlook Express Microsoft Corporation "C:\Program Files\Outlook Express\msimn.exe"
    iexplore.exe 4220 15,152 K 22,396 K Internet Explorer Microsoft Corporation "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
    iexplore.exe 4488 43,300 K 51,780 K Internet Explorer Microsoft Corporation "C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:4220 CREDAT:79873
    iexplore.exe 4500 50,852 K 64,208 K Internet Explorer Microsoft Corporation "C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:4220 CREDAT:145410
    EXCEL.EXE 5180 6,980 K 3,160 K Microsoft Office Excel Microsoft Corporation "C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE" /e
    procexp.exe 1476 2.94 14,516 K 18,228 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com "C:\Data\Sysclean Utilities\ProcessExplorer\ProcessExplorer\procexp.exe"
    Ymsgr_tray.exe 5500 19,236 K 6,268 K Yahoo! Messenger Tray Yahoo! Inc. "C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe" -ymsgr
    hpqgalry.exe 5516 20,572 K 13,592 K Hewlett-Packard Co. "C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe" -s
    avgrsx.exe 5168 1,028 K 452 K AVG Resident Shield Service AVG Technologies CZ, s.r.o.
    avgcsrvx.exe 5200 19,020 K 320 K AVG Scanning Core Module - Server Part AVG Technologies CZ, s.r.o. C:\Program Files\AVG\AVG10\avgcsrvx.exe /pipeName=dbeb0c50-07e9-442d-bbda-8b7f9b0bc11e /coreSdkOptions=30 /logConfFile= "C:\Documents and Settings\All Users\Application Data\AVG10\temp\1525af47-6e10-4c4e-95ae-3d24a88efb1a-1430-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath= "C:\Program Files\AVG\AVG10\" /registryPath= "SYSTEM\CurrentControlSet\Services\Avg\Avg10" /tempPath= "C:\Documents and Settings\All Users\Application Data\AVG10\temp\ "
    avgtray.exe 764 4,056 K 6,828 K AVG Tray Monitor AVG Technologies CZ, s.r.o. "C:\Program Files\AVG\AVG10\avgtray.exe "
    AVGIDSMonitor.exe 4700 5.15 1,092 K 4,540 K AVG IDS application AVG Technologies CZ, s.r.o. "C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe "
    SMTrayNotify.exe 2476 6,512 K 10,936 K "C:\Program Files\iolo\System Mechanic Professional\SMTrayNotify.exe" SMTN_DOWNLOADUPDATE
     
  5. 2010/10/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    System Idle Process (CPU NOT used) is listed at 80.30%, which is not perfect, but it's far from your statement saying "computer is running at 100% ", so you'll need to elaborate little bit more.

    Here are processes taking your CPU cycles:

    services.exe 1.47%
    svchost.exe 0.74%
    CarboniteService.exe 0.74%
    explorer.exe 2.21%
    procexp.exe 2.94%
    AVGIDSMonitor.exe 5.15%
     
  6. 2010/10/28
    pilotgal8 Lifetime Subscription

    pilotgal8 Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    459
    Likes Received:
    0
    Hi Broni,

    At my first post it was running 97% with one explorer window open & one web site. Response time to open a web page was almost 30 sec.
    With 2 gig memory, I'm not used to this slow response. I keep my startup menu lean, just so I can use my fast machine.

    Should I stop Carbonite during the day & restart it when I'm finished for the evening?
    Any suggestions.
     
  7. 2010/10/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  8. 2010/10/28
    pilotgal8 Lifetime Subscription

    pilotgal8 Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    459
    Likes Received:
    0
    I user Carbonite for auto backups. So I think you're saying don't let it run during the day, only when I've finished productive use & can let it backup overnight?

    If I halt using AVG, will Superantispyware do the same job?
     
  9. 2010/10/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No, you have to have some AV program.
    I suggest, you uninstall AVG, using AVG Remover: http://www.avg.com/download-tools and you go with one of these:
    - Avast! free antivirus: http://www.avast.com/eng/download-avast-home.html
    - Avira free antivirus: http://www.free-av.com/en/download/1/avira_antivir_personal__free_antivirus.html
    See, if your computer will behave better.

    Online backup is not the greatest idea.
    It eats your system resources, you can't guarantee its safety 100% and what would happen, if the company goes belly up?
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.