Forum Home
Press F1
 
Thread ID: 115783 2011-02-03 03:49:00 System Resources tuiruru (12277) Press F1
Post ID Timestamp Content User
1174903 2011-02-03 04:36:00 Attached is a screen shot of my System Resources Meter.

Your PC is bored, give it something to do.
pctek (84)
1174904 2011-02-03 04:43:00 Your PC is bored, give it something to do.

:D
icow (15313)
1174905 2011-02-03 06:27:00 Hi again

Erm - it's a laptop not a PC if that's important .

HJT log below . Two pics of my System Resource meter next to Task Manager . This was when the wireless connection was off so there was no Chrome bouncing around in the background .



Logfile of Trend Micro HijackThis v2 . 0 . 4
Scan saved at 7:20:46 p . m . , on 3/02/2011
Platform: Windows Vista SP2 (WinNT 6 . 00 . 1906)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Windows\System32\smss . exe
C:\Windows\system32\csrss . exe
C:\Windows\system32\wininit . exe
C:\Windows\system32\csrss . exe
C:\Windows\system32\services . exe
C:\Windows\system32\lsass . exe
C:\Windows\system32\lsm . exe
C:\Windows\system32\svchost . exe
C:\Windows\system32\TAMSvr . exe
C:\Windows\system32\winlogon . exe
C:\Program Files\Zentimo\ZentimoService . exe
C:\Windows\Microsoft . Net\Framework\v3 . 0\WPF\Presen tationFontCache . exe
C:\Windows\system32\svchost . exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent . exe
C:\Windows\system32\svchost . exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng . exe
C:\Windows\system32\Ati2evxx . exe
C:\Windows\System32\svchost . exe
C:\Windows\System32\svchost . exe
C:\Windows\system32\svchost . exe
C:\Windows\system32\svchost . exe
C:\Windows\system32\SLsvc . exe
C:\Windows\system32\svchost . exe
C:\Windows\system32\Ati2evxx . exe
C:\Windows\System32\spoolsv . exe
C:\Windows\system32\taskeng . exe
C:\Windows\system32\svchost . exe
C:\Windows\system32\svchost . exe
C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator . exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs . exe
C:\Program Files\COMODO\COMODO BackUp\COSService . exe
C:\Program Files\COMODO\COMODO Programs Manager\CPMService . exe
C:\Program Files\Common Files\MAGIX Services\Database_60405\bin\FABS . exe
C:\Windows\system32\svchost . exe
C:\Program Files\Spyware Terminator\sp_rsser . exe
C:\Windows\system32\svchost . exe
C:\Program Files\COMODO\COMODO BackUp\SynchronizationService . exe
C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv . exe
C:\Windows\system32\TODDSrv . exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv . exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv . exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv . exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr . exe
C:\Windows\System32\svchost . exe
C:\Windows\system32\SearchIndexer . exe
C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv . exe
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv . exe
C:\Windows\system32\Dwm . exe
C:\Windows\Explorer . EXE
C:\Windows\system32\taskeng . exe
C:\Program Files\Process Lasso\processgovernor . exe
C:\Program Files\Process Lasso\processlasso . exe
C:\Program Files\Synaptics\SynTP\SynTPEnh . exe
C:\Windows\RtHDVCpl . exe
C:\Windows\system32\wbem\wmiprvse . exe
C:\Program Files\TrueSuite Access Manager\usbnotify . exe
C:\Program Files\TrueSuite Access Manager\PwdBank . exe
C:\Program Files\ATI Technologies\ATI . ACE\Core-Static\MOM . exe
C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan . exe
C:\Program Files\COMODO\COMODO Internet Security\cfp . exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield . Exe
C:\Windows\tsnp2std . exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol . exe
C:\Program Files\Microsoft Security Client\msseces . exe
C:\Windows\ehome\ehtray . exe
C:\Program Files\Rainlendar2\Rainlendar2 . exe
C:\Program Files\xNeat Clipboard Manager\xNeatClipMngr . exe
C:\Program Files\NetMeter\NetMeter . exe
C:\Program Files\Zentimo\Zentimo . exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD . exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier . exe
C:\Windows\system32\wbem\unsecapp . exe
C:\Windows\ehome\ehmsas . exe
C:\Windows\system32\wbem\wmiprvse . exe
C:\Program Files\WinSplit Revolution\WinSplit . exe
C:\Program Files\TOSHIBA\HDMICtrlMan\HCMSoundChanger . exe
C:\Program Files\Just Gestures\JustGestures . exe
C:\Program Files\Sticky Password\stpass . exe
C:\Program Files\Aston2\Aston2 . exe
C:\Program Files\AltDesk\AltDesk . exe
C:\Program Files\Gmail Notifier\Gmail Notifier . exe
C:\Program Files\SysResources Manager\SysResManager . exe
C:\Program Files\Windows Media Player\wmpnscfg . exe
C:\Program Files\Belvedere\Belvedere . exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng . exe
C:\Program Files\ATI Technologies\ATI . ACE\Core-Static\CCC . exe
C:\Program Files\Synaptics\SynTP\SynTPHelper . exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp . exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid . exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp . exe
C:\Windows\system32\wuauclt . exe
C:\Windows\System32\svchost . exe
C:\Windows\system32\vssvc . exe
C:\Windows\System32\svchost . exe
C:\Windows\system32\taskeng . exe
C:\Windows\system32\msiexec . exe
C:\Program Files\IconSort\IconSort . exe
C:\Program Files\HJT\Trend Micro\HiJackThis\HiJackThis . exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = . microsoft . com/fwlink/?LinkId=69157" target="_blank">go . microsoft . com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = . microsoft . com/fwlink/?LinkId=54896" target="_blank">go . microsoft . com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = . microsoft . com/fwlink/?LinkId=54896" target="_blank">go . microsoft . com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = . microsoft . com/fwlink/?LinkId=69157" target="_blank">go . microsoft . com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper . dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin . dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32 . dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin . dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5 . 6 . 5805 . 1910\s wg . dll
O2 - BHO: (no name) - {C90DBB52-46E0-4E65-92BC-799ADEE54C86} - C:\PROGRA~1\Flash2X\FLASHP~1\FLASHP~1 . DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv . dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32 . dll
O4 - HKLM\ . . \Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui . exe -hide
O4 - HKLM\ . . \Run: [NDSTray . exe] NDSTray . exe
O4 - HKLM\ . . \Run: [cfFncEnabler . exe] cfFncEnabler . exe
O4 - HKLM\ . . \Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh . exe
O4 - HKLM\ . . \Run: [RtHDVCpl] RtHDVCpl . exe
O4 - HKLM\ . . \Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI . ACE\Core-Static\CLIStart . exe"
O4 - HKLM\ . . \Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain . EXE
O4 - HKLM\ . . \Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON . exe
O4 - HKLM\ . . \Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView . exe
O4 - HKLM\ . . \Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain . exe
O4 - HKLM\ . . \Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng . exe /START
O4 - HKLM\ . . \Run: [UsbMonitor] "C:\Program Files\TrueSuite Access Manager\usbnotify . exe"
O4 - HKLM\ . . \Run: [PwdBank] "C:\Program Files\TrueSuite Access Manager\PwdBank . exe"
O4 - HKLM\ . . \Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan . exe
O4 - HKLM\ . . \Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp . exe" -h
O4 - HKLM\ . . \Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield . exe"
O4 - HKLM\ . . \Run: [tsnp2std] C:\Windows\tsnp2std . exe
O4 - HKLM\ . . \Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol . exe -expressboot
O4 - HKLM\ . . \Run: [TrayServer] C:\Program Files\MAGIX\Movie_Edit_Pro_17_Plus_Download_Versio n\TrayServer_en . exe
O4 - HKLM\ . . \Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces . exe" -hide -runkey
O4 - HKCU\ . . \Run: [ehTray . exe] C:\Windows\ehome\ehTray . exe
O4 - HKCU\ . . \Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2 . exe
O4 - HKCU\ . . \Run: [xNeat Clipboard Manager] C:\Program Files\xNeat Clipboard Manager\xNeatClipMngr . exe
O4 - HKCU\ . . \Run: [ShowBatteryBar] "C:\Program Files\BatteryBar\ShowBatteryBar . exe" show
O4 - HKCU\ . . \Run: [C:\Program Files\NetMeter\NetMeter . exe] C:\Program Files\NetMeter\NetMeter . exe
O4 - HKCU\ . . \Run: [Zentimo xStorage Manager] C:\Program Files\Zentimo\Zentimo . exe /startup
O4 - HKCU\ . . \Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD . exe
O4 - HKCU\ . . \Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier . exe"
O4 - HKCU\ . . \Run: [Google Update] "C:\Users\John Warren\AppData\Local\Google\Update\GoogleUpdate . ex e" /c
O4 - HKCU\ . . \Run: [Winsplit] C:\Program Files\WinSplit Revolution\WinSplit . exe
O4 - HKCU\ . . \Run: [Just Gestures] C:\Program Files\Just Gestures\JustGestures . exe
O4 - HKCU\ . . \Run: [StickyPassword] C:\Program Files\Sticky Password\stpass . exe
O4 - HKCU\ . . \Run: [Aston2] "C:\Program Files\Aston2\Aston2 . exe"
O4 - HKCU\ . . \Run: [AltDesk] C:\Program Files\AltDesk\AltDesk . exe
O4 - HKCU\ . . \Run: [SysResources Manager] "C:\Program Files\SysResources Manager\SysResManager . exe"
O4 - HKCU\ . . \Run: [Gmail Notifier . exe] C:\Program Files\Gmail Notifier\Gmail Notifier . exe /startup
O4 - HKUS\S-1-5-19\ . . \Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar . exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\ . . \Run: [WindowsWelcomeCenter] rundll32 . exe oobefldr . dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\ . . \Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar . exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: AutorunsDisabled
O4 - Global Startup: Belvedere . lnk = C:\Program Files\Belvedere\Belvedere . exe
O4 - Global Startup: Bluetooth Manager . lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos . scr/200
O8 - Extra context menu item: Google Sidewiki . . . - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E117 12C84EA7E12B . dll/cmsidewiki . html
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin . dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin . dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - . adobe . com/NOS/getPlusPlus/1 . 6/gp . cab" target="_blank">platformdl . adobe . com
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin . dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1 . DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1 . DLL C:\Windows\system32\guard32 . dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO . dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui . dll
O23 - Service: Ati External Event Utility - ATI Technologies Inc . - C:\Windows\system32\Ati2evxx . exe
O23 - Service: Authentec memory manager service (Authentec memory manager) - AuthenTec Inc . - C:\Windows\system32\TAMSvr . exe
O23 - Service: COMODO System - Cleaner Service (Cleaner_Validator) - Unknown owner - C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator . exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent . exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs . exe
O23 - Service: Comodo Online Storage Service (COSService . exe) - Unknown owner - C:\Program Files\COMODO\COMODO BackUp\COSService . exe
O23 - Service: COMODO Programs Manager Service (CPMService) - Unknown owner - C:\Program Files\COMODO\COMODO Programs Manager\CPMService . exe
O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files\Common Files\MAGIX Services\Database_60405\bin\FABS . exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\Common Files\MAGIX Services\Database_60405\bin\fbserver . exe
O23 - Service: Google Desktop Manager 5 . 9 . 1005 . 12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop . exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc . - C:\Program Files\Google\Update\GoogleUpdate . exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService . exe
O23 - Service: MAGIX StartUp Analyze Service - MAGIX AG - C:\Program Files\MAGIX\PC_Check_Tuning_2011_Download_Version\ MXSAS . exe
O23 - Service: Remote Packet Capture Protocol v . 0 (experimental) (rpcapd) - CACE Technologies, Inc . - C:\Program Files\WinPcap\rpcapd . exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer . exe
O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv . exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler . com - C:\Program Files\Spyware Terminator\sp_rsser . exe
O23 - Service: Comodo BackUp Service (SynchronizationService . exe) - Unknown owner - C:\Program Files\COMODO\COMODO BackUp\SynchronizationService . exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv . exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv . exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv . exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv . exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv . exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc . - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr . exe
O23 - Service: Zentimo Assistant (ZentimoService) - Unknown owner - C:\Program Files\Zentimo\ZentimoService . exe

--
End of file - 14691 bytes
tuiruru (12277)
1174906 2011-02-03 06:33:00 One word. COMODO

The screen shots don't really show anything. Its under the processes Tab is where you want to look.

You have to many processes running as well, an average of 97.
wainuitech (129)
1174907 2011-02-03 06:42:00 These dont have to be in startup

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"

O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot

O4 - HKCU\..\Run: [SysResources Manager] "C:\Program Files\SysResources Manager\SysResManager.exe"

O4 - Startup: AutorunsDisabled

I would uninstall COMODO System Cleaner
Speedy Gonzales (78)
1174908 2011-02-03 06:53:00 Here's what's running in the processes box if you can zoom in on it.

dl-web.dropbox.com

svchost seems to be doing a lot - is that OK?
tuiruru (12277)
1174909 2011-02-03 06:56:00 I would uninstall COMODO System Cleaner
Yeah, they've made it really bloated compared with what it was with all the stuff running in the background :groan:
tuiruru (12277)
1174910 2011-02-03 06:56:00 Attach the pic here. Dont think people will log into Dropbox to look at it Speedy Gonzales (78)
1174911 2011-02-03 07:05:00 here it is - not sure you'll be able to read it. Uploading it here has shrunk it. The original is 433kb
The dropbox link works for me - is that cos it's mine?
tuiruru (12277)
1174912 2011-02-03 07:12:00 Youre right, I cant read it. By the looks of it, you have to log in to view the pic on dropbox Speedy Gonzales (78)
1 2 3 4