This is a read-only archive. No new posts or registrations. Privacy Page
Software

Need Help, XP slowing

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Desktop running Xp getting slower and slower.

One thing I've noticed is one of the svc hosts is using a lot of cpu usage and memory.

Before when I started pc and looked at task manager there would be high usage for a couple of minutes then cpu usage would go all the way down, now usage continues.

Take a look at the running processes with Process Explorer, see what under svchost is doing it, may help figure out what is going on.

Hi and thanks for the reply.

On my pc when I point at a process I only see the path for that process.

If I open the lower payne and double click a process then this is what I got.

 

Process    CPU    Private Bytes    Working Set    PID    Description    Company Name
svchost.exe    26.86    484,376 K    501,500 K    1244    Generic Host Process for Win32 Services    Microsoft Corporation
mbamservice.exe    0.55    239,344 K    237,184 K    2772    Malwarebytes Anti-Malware    Malwarebytes Corporation
firefox.exe        134,388 K    145,288 K    3612    Firefox    Mozilla Corporation
MsMpEng.exe    0.77    58,112 K    51,344 K    1360    Antimalware Service Executable    Microsoft Corporation
explorer.exe        32,248 K    45,132 K    252    Windows Explorer    Microsoft Corporation
svchost.exe    1.98    27,072 K    38,216 K    1396    Generic Host Process for Win32 Services    Microsoft Corporation
RTHDCPL.EXE        26,244 K    24,752 K    1016    Realtek HD Audio Control Panel    Realtek Semiconductor Corp.
mbam.exe        20,464 K    30,664 K    3404    Malwarebytes Anti-Malware    Malwarebytes Corporation
procexp.exe    19.64    21,000 K    29,096 K    2636    Sysinternals Process Explorer    Sysinternals - www.sysinternals.com
SDTray.exe    0.01    16,356 K    22,012 K    2212    Spybot - Search & Destroy tray access    Safer-Networking Ltd.
wuauclt.exe    0.04    14,656 K    140,644 K    5996    Windows Update    Microsoft Corporation
svchost.exe        11,168 K    23,416 K    1052    Generic Host Process for Win32 Services    Microsoft Corporation
jqs.exe    0.01    9,576 K    1,472 K    2196    Java Quick Starter Service    Oracle Corporation
SDUpdSvc.exe        9,444 K    14,388 K    2108    Spybot-S&D 2 Background update service    Safer-Networking Ltd.
rundll32.exe        9,112 K    11,988 K    2056    Run a DLL as an App    Microsoft Corporation
svchost.exe        8,232 K    12,692 K    1252    Generic Host Process for Win32 Services    Microsoft Corporation
winlogon.exe        7,176 K    3,896 K    820    Windows NT Logon Application    Microsoft Corporation
msseces.exe        6,684 K    11,784 K    2136    Microsoft Security Client User Interface    Microsoft Corporation
daemonu.exe        6,368 K    9,368 K    3188    NVIDIA Settings Update Manager    NVIDIA Corporation
svchost.exe        5,896 K    8,264 K    1692    Generic Host Process for Win32 Services    Microsoft Corporation
nvsvc32.exe        5,376 K    7,100 K    3000    NVIDIA Driver Helper Service, Version 320.49    NVIDIA Corporation
WLIDSVC.EXE        4,820 K    8,480 K    1092    Microsoft® Windows Live ID Service    Microsoft Corporation
Ctxfihlp.exe        4,804 K    7,988 K    1340    CTXfiHlp MFC Application    Creative Technology Ltd
MpCmdRun.exe        4,664 K    5,496 K    1732    Microsoft Malware Protection Command Line Utility    Microsoft Corporation
GUI.exe    1.02    4,656 K    7,904 K    2192    GUI MFC Application    
spoolsv.exe        4,108 K    6,240 K    1840    Spooler SubSystem App    Microsoft Corporation
mbamscheduler.exe        3,840 K    7,872 K    2272    Malwarebytes Anti-Malware    Malwarebytes Corporation
MpCmdRun.exe    0.01    3,784 K    5,288 K    5744    Microsoft Malware Protection Command Line Utility    Microsoft Corporation
GoogleUpdate.exe        3,624 K    1,936 K    2216    Google Installer    Google Inc.
CTxfispi.exe        3,544 K    6,212 K    3256    SPI (Creative X-Fi Module)    Creative Technology Ltd
wmiprvse.exe    0.01    3,084 K    7,956 K    3148    WMI    Microsoft Corporation
lsass.exe    0.01    2,848 K    6,400 K    876    LSA Shell (Export Version)    Microsoft Corporation
svchost.exe    0.04    2,652 K    4,744 K    1564    Generic Host Process for Win32 Services    Microsoft Corporation
rapimgr.exe        2,548 K    5,696 K    2640    ActiveSync RAPI Manager    Microsoft Corporation
svchost.exe        2,412 K    3,440 K    1436    Generic Host Process for Win32 Services    Microsoft Corporation
MpCmdRun.exe        2,360 K    2,940 K    5520    Microsoft Malware Protection Command Line Utility    Microsoft Corporation
svchost.exe        2,256 K    5,492 K    180    Generic Host Process for Win32 Services    Microsoft Corporation
tsnp2std.exe        2,232 K    5,624 K    1764    tsnp2std Microsoft     
ContentTransferWMDetector.exe        2,180 K    4,976 K    1352    Content Transfer Walkman Detector    Sony Corporation
vsnp2std.exe        2,156 K    5,664 K    1980    CameraMonitor Application    Sonix
nusb3mon.exe        2,120 K    3,944 K    1080    USB 3.0 Monitor    NEC Electronics Corporation
NvTmru.exe        2,084 K    4,892 K    2112    NVIDIA NvTmru Application    NVIDIA Corporation
FixCamera.exe        2,056 K    5,516 K    1880    CameraFixer MFC Application    
svchost.exe        1,972 K    4,492 K    1248    Generic Host Process for Win32 Services    Microsoft Corporation
wmiapsrv.exe        1,940 K    4,624 K    4068    WMI Performance Adapter Service    Microsoft Corporation
services.exe    0.14    1,904 K    3,724 K    864    Services and Controller app    Microsoft Corporation
GoogleCrashHandler.exe        1,888 K    552 K    2512    Google Crash Handler    Google Inc.
csrss.exe    0.07    1,792 K    6,128 K    788    Client Server Runtime Process    Microsoft Corporation
DLMSession.exe        1,424 K    4,236 K    1620    Autodesk Download Manager    Autodesk, Inc.
svchost.exe        1,404 K    3,872 K    1800    Generic Host Process for Win32 Services    Microsoft Corporation
wcescomm.exe        1,356 K    5,020 K    2476    ActiveSync Connection Manager    Microsoft Corporation
alg.exe        1,212 K    3,664 K    2680    Application Layer Gateway Service    Microsoft Corporation
hpztsb12.exe        1,160 K    3,836 K    1104        HP
MDM.EXE        1,132 K    3,364 K    2964    Machine Debug Manager    Microsoft Corporation
ctfmon.exe        1,052 K    3,756 K    268    CTF Loader    Microsoft Corporation
BCU.exe    0.01    964 K    3,748 K    132    Browser Configuration Utility    DeviceVM, Inc.
essvr.exe        932 K    2,308 K    2076        
WLIDSVCM.EXE        588 K    2,052 K    3476    Microsoft® Windows Live ID Service Monitor    Microsoft Corporation
HPZipm12.exe        556 K    1,840 K    3248    PML Driver    HP
BCUService.exe        452 K    1,796 K    1316    Browser Configuration Utility Auto-recovery Service    DeviceVM, Inc.
smss.exe        172 K    432 K    720    Windows NT Session Manager    Microsoft Corporation
System Idle Process    46.19    0 K    28 K    0        
System    1.71    0 K    244 K    4        
Interrupts    0.80    0 K    0 K    n/a    Hardware Interrupts and DPCs    
wuauclt.exe    0.04    6,020 K    6,088 K    4100    Windows Update    Microsoft Corporation
AM_Delta_Patch_1.179.190.0.exe    0.03    208 K    1,996 K    4340    AntiMalware Definition Update    Microsoft Corporation
MpSigStub.exe    0.03    1,728 K    2,544 K    4400    Microsoft Malware Protection Signature Update Stub    Microsoft Corporation

Process: svchost.exe Pid: 1244

Type    Name
Desktop    \Default
Directory    \KnownDlls
Directory    \Windows
Directory    \BaseNamedObjects
Event    \BaseNamedObjects\DINPUTWINMM
Event    \BaseNamedObjects\userenv:  User Profile setup event
Event    \BaseNamedObjects\hardwaremixercallback
Event    \BaseNamedObjects\crypt32LogoffEvent
Event    \BaseNamedObjects\mixercallback
Event    \BaseNamedObjects\userenv: Machine Group Policy has been applied
Event    \BaseNamedObjects\userenv: User Group Policy has been applied
File    C:\WINDOWS\system32
File    \Device\KsecDD
File    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File    \Device\WMIDataDevice
File    \Device\WMIDataDevice
File    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
File    C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
File    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File    \Device\Tcp
File    \Device\NamedPipe\ROUTER
File    \Device\Tcp
File    \Device\Ip
File    \Device\Ip
File    \Device\Ip
File    \Device\NamedPipe\ROUTER
File    \Device\Tcp
File    \Device\Afd
File    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\if[3].txt
File    \Device\Afd
File    \Device\Udp
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\MuseoSans_500_Italic-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\user_sync[1].html
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\buying-clean-electricity[1].txt
File    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File    \Device\KSENUM#00000001
File    C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\brands-products-archives[1].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\revicons[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My
File    \Device\Tcp
File    \Device\NetBT_Tcpip_{49581C7F-1CFC-4C55-B4EF-8588276CD04B}
File    \Device\Afd
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\fontawesome-webfont[1].eot
File    \Device\Tcp
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\cities-structures-architecture-archives[1].txt
File    \Device\Tcp
File    C:\WINDOWS\system32\Macromed\Flash\Flash32_11_9_900_152.ocx
File    C:\WINDOWS\system32\stdole2.tlb
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\fontawesome-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\MuseoSans_900_Italic-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\revicons[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\MuseoSans_500-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\st[4]
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\engine[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\engine[2].htm
File    \Device\Afd
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\showad[1].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\if[1].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\usersync[2].gif
File    C:\WINDOWS\system32\dxtrans.dll
File    C:\WINDOWS\system32\dxtmsft.dll
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\showad[5].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\showad[3].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\user_sync[1].html
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[7].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\4651[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\usersync[4].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\net[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\if[3].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\MuseoSans_100-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\MuseoSans_100_Italic-webfont[1].eot
File    \Device\Tcp
File    \Device\Afd
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\net[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\ba[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\insulation[1].txt
File    \Device\Tcp
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[1].txt
File    \Device\Afd
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\tt[2].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\st[1]
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[8].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\st[2]
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\user_sync[2].html
File    C:\WINDOWS\system32\mshtml.tlb
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\4651[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[10].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\if[1].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\st[1]
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\MuseoSans_300-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\MuseoSans_500-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\MuseoSans_300-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\usersync[3].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\MuseoSans_300_Italic-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\MuseoSans_100_Italic-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\if[2].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\user_sync[1].html
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[3].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\user_sync[3].html
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\MuseoSans_100-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\MuseoSans_900-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\user_sync[2].html
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\st[3]
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\MuseoSans_700-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\user_sync[1].html
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\showad[1].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\showad[1].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\user_sync[4].html
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\MuseoSans_700_Italic-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\user_sync[2].html
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\showad[2].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[2].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\user_sync[3].html
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\ba[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\MuseoSans_500_Italic-webfont[1].eot
File    C:\WINDOWS\system32\shdocvw.dll
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\user_sync[2].html
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\user_sync[5].html
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\Pug[1].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\st[1]
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\user_sync[3].html
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\if[2].txt
File    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\usersync[3].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\showad[4].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\usersync[2].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\user_sync[3].html
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\showad[2].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\showad[1].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\showad[3].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\cfcm[1].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\usersync[1].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\if[4].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\st[4]
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\usersync[4].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\usersync[3].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\usersync[1].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\usersync[1].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\showad[2].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\if[1].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\usersync[2].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\usersync[5].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\Pug[1].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\MuseoSans_700_Italic-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\showad[4].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\st[2]
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\showad[3].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\ba[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\MuseoSans_300_Italic-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\st[3]
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\MuseoSans_700-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\showad[5].js
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\st[2]
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\MuseoSans_900-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\MuseoSans_900_Italic-webfont[1].eot
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\clk[1].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\Pug[1].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\usersync[6].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\usersync[7].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\Pug[1].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\an_brightroll_com[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\tt[1].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\if[3].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\tt[1].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[4].txt
File    \Device\Tcp
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\an_brightroll_com[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[5].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\st[3]
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\51462E17-431B-4CC4-B16F-CBB201D0E036[1].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\Pug[1].txt
File    \Device\Tcp
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\if[2].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\Pug[2].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\pxj[1].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\st[1]
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[6].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\adoapn_AppNexusDemoActionTag_1[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\pxj[1].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\an_brightroll_com[2].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\if[5].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\if[9].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\an_brightroll_com[2].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\pxj[2].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\pxj[1].gif
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\PortalServe[2].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\iframe1[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\728x90[1].htm
File    C:\WINDOWS\Temp\fla6.tmp
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\aclk[1].htm
File    C:\WINDOWS\Temp\fla5.tmp
File    C:\WINDOWS\Temp\fla3.tmp
File    \Device\Tcp
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\ba[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\iframe1[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\iframe1[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\300x250noads[1].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\PortalServe[1].txt
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\iframe1[1].htm
File    C:\WINDOWS\Temp\fla4.tmp
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\ba[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\pixel[1].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\ddc[2].htm
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QACGEPE7\videoplayer[1].php
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O0WL7E48\ddc[1].htm
File    C:\WINDOWS\system32\iepeers.dll
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I0H64HE5\skeleton[1].gif
File    \Device\Afd
File    \Device\Tcp
File    \Device\Tcp
File    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ND4JJQA\pixel[1].com
File    C:\WINDOWS\system32\wmp.dll
File    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.23084_x-ww_f3f35550
Key    HKLM
Key    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
Key    HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Windows
Key    HKCR
Key    HKU\.DEFAULT
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Key    HKCR
Key    HKLM\SOFTWARE\Policies
Key    HKU\.DEFAULT\Software\Policies
Key    HKU\.DEFAULT\Software
Key    HKLM\SOFTWARE
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Key    HKLM\SOFTWARE\Policies
Key    HKU\.DEFAULT\Software\Policies
Key    HKU\.DEFAULT\Software
Key    HKLM\SOFTWARE
Key    HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9
Key    HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5
Key    HKLM\SOFTWARE\Microsoft\Tracing\RASAPI32
Key    HKU
Key    HKLM\SYSTEM\ControlSet001\Services\Tcpip\Linkage
Key    HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters
Key    HKLM\SYSTEM\ControlSet001\Services\NetBT\Parameters\Interfaces
Key    HKLM\SYSTEM\ControlSet001\Services\NetBT\Parameters
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Network\Location Awareness
Key    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
Key    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
Key    HKCR
Key    HKCR
Key    HKLM\SOFTWARE\Microsoft\COM3
Key    HKU
Key    HKCR
Key    HKU
Key    HKLM\SOFTWARE\Microsoft\COM3
Key    HKLM\SOFTWARE\Microsoft\COM3
Key    HKCR\CLSID
Key    HKCR
Key    HKLM\SOFTWARE\Microsoft\COM3
Key    HKU
Key    HKLM\SOFTWARE\Microsoft\COM3
Key    HKLM\SOFTWARE\Microsoft\COM3
Key    HKCR\CLSID
Key    HKCR
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Key    HKCR
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKCR
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKCR
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKCR
Key    HKCR
Key    HKCR
Key    HKCR
Key    HKLM\SYSTEM\ControlSet001\Control\Nls\Locale
Key    HKLM\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts
Key    HKLM\SYSTEM\ControlSet001\Control\Nls\Language Groups
Key    HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKCR
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root
Key    HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT
Key    HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA
Key    HKU\.DEFAULT
Key    HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
Key    HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKLM\SOFTWARE\Microsoft\SystemCertificates\CA
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed
Key    HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA
Key    HKU\.DEFAULT
Key    HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed
Key    HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed
Key    HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates
Key    HKCR
Key    HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates
Key    HKLM\SOFTWARE\Microsoft\SystemCertificates\trust
Key    HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust
Key    HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust
Key    HKU\.DEFAULT
Key    HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My
Key    HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates
Key    HKCR
Key    HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKCR
Key    HKCR
Key    HKCR
Key    HKCR
Key    HKCR
Key    HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage
Key    HKCR
Key    HKLM\SYSTEM\Setup
Key    HKCR
Key    HKCR
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKCR
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKCR
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKCR
Key    HKCR
Key    HKCR
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKCR
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\DOMStorage\Total
Key    HKCR\MIME\Database\Content Type\image/gif
Key    HKCR\MIME\Database\Content Type\text/html
Key    HKCR
Key    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\DOMStorage\securepaths.com
Key    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\DOMStorage\Total
Key    HKU\.DEFAULT\Software\Microsoft\Internet Explorer
Key    HKCR\MIME\Database\Content Type\application/x-shockwave-flash
Key    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\DOMStorage\securepaths.com
Key    HKCR
Key    HKLM\SOFTWARE\Microsoft\MediaPlayer\Preferences
Key    HKCR\MIME\Database\Content Type\image/png
Key    HKCR\MIME\Database\Content Type\text/plain
Key    HKCR\MIME\Database\Content Type\image/jpeg
Key    HKCR
Key    HKU\.DEFAULT\Software\Microsoft\MediaPlayer\Preferences
Key    HKU\.DEFAULT\Software\Microsoft\MediaPlayer\Preferences
Key    HKCR
Key    HKCR
KeyedEvent    \KernelObjects\CritSecOutOfMemoryEvent
Mutant    \BaseNamedObjects\SHIMLIB_LOG_MUTEX
Mutant    \BaseNamedObjects\_!MSFTHISTORY!_
Mutant    \BaseNamedObjects\c:!windows!system32!config!systemprofile!local settings!temporary internet files!content.ie5!
Mutant    \BaseNamedObjects\c:!windows!system32!config!systemprofile!cookies!
Mutant    \BaseNamedObjects\c:!windows!system32!config!systemprofile!local settings!history!history.ie5!
Mutant    \BaseNamedObjects\WininetStartupMutex
Mutant    \BaseNamedObjects\WininetProxyRegistryMutex
Mutant    \BaseNamedObjects\RasPbFile
Mutant    \BaseNamedObjects\ZonesCounterMutex
Mutant    \BaseNamedObjects\!IETld!Mutex
Mutant    \BaseNamedObjects\ZoneAttributeCacheCounterMutex
Mutant    \BaseNamedObjects\ZonesCacheCounterMutex
Mutant    \BaseNamedObjects\ZoneAttributeCacheCounterMutex
Mutant    \BaseNamedObjects\ZonesLockedCacheCounterMutex
Mutant    \BaseNamedObjects\!PrivacIE!SharedMemory!Mutex
Mutant    \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-18
Mutant    \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-18
Mutant    \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-18
Mutant    \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-18
Mutant    \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-18
Mutant    \BaseNamedObjects\MidiMapper_modLongMessage_RefCnt
Mutant    \BaseNamedObjects\MidiMapper_Configure
Mutant    \BaseNamedObjects\!IETld!Mutex
Mutant    \BaseNamedObjects\{1B655094-FE2A-433c-A877-FF9793445069}
Mutant    \BaseNamedObjects\__DDrawCheckExclMode__
Mutant    \BaseNamedObjects\__DDrawExclMode__
Mutant    \BaseNamedObjects\DDrawDriverObjectListMutex
Mutant    \BaseNamedObjects\DDrawWindowListMutex
Mutant    \BaseNamedObjects\http://www.redesignrevolution.com/
Mutant    \BaseNamedObjects\http://ads.yahoo.com/
Mutant    \BaseNamedObjects\http://c.betrad.com/
Mutant    \BaseNamedObjects\http://ad.doubleclick.net/
Mutant    \BaseNamedObjects\http://securepaths.com/
Mutant    \BaseNamedObjects\InternetExplorerDOMStoreQuota
Port    \RPC Control\OLEB3F0659C03AE44F39E2C9AF5C951
Process    svchost.exe(1244)
Section    \BaseNamedObjects\C:_WINDOWS_system32_config_systemprofile_Local Settings_Temporary Internet Files_Content.IE5_index.dat_9617408
Section    \BaseNamedObjects\C:_WINDOWS_system32_config_systemprofile_Cookies_index.dat_409600
Section    \BaseNamedObjects\C:_WINDOWS_system32_config_systemprofile_Local Settings_History_History.IE5_index.dat_2555904
Section    \BaseNamedObjects\SENS Information Cache
Section    \BaseNamedObjects\UrlZonesSM_SYSTEM
Section    \BaseNamedObjects\windows_ie_global_counters
Section    \BaseNamedObjects\!PrivacIE!SharedMem!Counter
Section    \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-18
Section    \BaseNamedObjects\mmGlobalPnpInfo
Section    \BaseNamedObjects\WDMAUD_Callbacks
Section    \BaseNamedObjects\MSIMGSIZECacheMap
Semaphore    \BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}
Semaphore    \BaseNamedObjects\shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}
Semaphore    \BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}
Thread    svchost.exe(1244): 1976
Thread    svchost.exe(1244): 1976
Thread    svchost.exe(1244): 1976
Thread    svchost.exe(1244): 2132
Thread    svchost.exe(1244): 456
Thread    svchost.exe(1244): 3668
Thread    svchost.exe(1244): 3660
Thread    svchost.exe(1244): 3660
Thread    svchost.exe(1244): 1676
Thread    svchost.exe(1244): 456
Thread    svchost.exe(1244): 656
Thread    svchost.exe(1244): 3200
Thread    svchost.exe(1244): 1912
Thread    svchost.exe(1244): 3200
Thread    svchost.exe(1244): 3768
Thread    svchost.exe(1244): 3116
Thread    svchost.exe(1244): 3432
Thread    svchost.exe(1244): 456
Thread    svchost.exe(1244): 4004
Thread    svchost.exe(1244): 656
Thread    svchost.exe(1244): 2452
Thread    svchost.exe(1244): 2104
Thread    svchost.exe(1244): 656
Thread    svchost.exe(1244): 1676
Thread    svchost.exe(1244): 3208
Thread    svchost.exe(1244): 3208
Thread    svchost.exe(1244): 2448
Thread    svchost.exe(1244): 1076
Thread    svchost.exe(1244): 3996
Thread    svchost.exe(1244): 3996
Thread    svchost.exe(1244): 1172
Thread    svchost.exe(1244): 3996
Thread    svchost.exe(1244): 2248
Thread    svchost.exe(1244): 3500
Thread    svchost.exe(1244): 3328
Thread    svchost.exe(1244): 504
Thread    svchost.exe(1244): 1912
Thread    svchost.exe(1244): 1468
Thread    svchost.exe(1244): 3500
Thread    svchost.exe(1244): 208
Thread    svchost.exe(1244): 168
Thread    svchost.exe(1244): 3500
Thread    svchost.exe(1244): 1700
Thread    svchost.exe(1244): 3632
Thread    svchost.exe(1244): 168
Thread    svchost.exe(1244): 3632
Thread    svchost.exe(1244): 3632
Thread    svchost.exe(1244): 2492
Thread    svchost.exe(1244): 2492
Thread    svchost.exe(1244): 4052
Thread    svchost.exe(1244): 168
Thread    svchost.exe(1244): 196
Thread    svchost.exe(1244): 512
Thread    svchost.exe(1244): 3636
Thread    svchost.exe(1244): 2932
Thread    svchost.exe(1244): 2152
Thread    svchost.exe(1244): 3760
Thread    svchost.exe(1244): 1544
Thread    svchost.exe(1244): 2152
Thread    svchost.exe(1244): 3584
Thread    svchost.exe(1244): 3736
Thread    svchost.exe(1244): 2152
Thread    svchost.exe(1244): 1912
Thread    svchost.exe(1244): 1876
Thread    svchost.exe(1244): 3320
Thread    svchost.exe(1244): 2168
Thread    svchost.exe(1244): 3984
Thread    svchost.exe(1244): 3732
Thread    svchost.exe(1244): 3836
Thread    svchost.exe(1244): 2796
Thread    svchost.exe(1244): 276
Thread    svchost.exe(1244): 2852
Thread    svchost.exe(1244): 3812
Thread    svchost.exe(1244): 648
Thread    svchost.exe(1244): 2092
Thread    svchost.exe(1244): 2884
Thread    svchost.exe(1244): 2884
Thread    svchost.exe(1244): 1952
Thread    svchost.exe(1244): 2504
Thread    svchost.exe(1244): 2392
Thread    svchost.exe(1244): 2736
Thread    svchost.exe(1244): 2416
Thread    svchost.exe(1244): 3364
Thread    svchost.exe(1244): 3540
Thread    svchost.exe(1244): 620
Thread    svchost.exe(1244): 2292
Thread    svchost.exe(1244): 1212
Thread    svchost.exe(1244): 2952
Thread    svchost.exe(1244): 3792
Thread    svchost.exe(1244): 3624
Thread    svchost.exe(1244): 1860
Thread    svchost.exe(1244): 2024
Thread    svchost.exe(1244): 2356
Thread    svchost.exe(1244): 1612
Thread    svchost.exe(1244): 3384
Thread    svchost.exe(1244): 1568
Thread    svchost.exe(1244): 1752
Thread    svchost.exe(1244): 1488
Thread    svchost.exe(1244): 2700
Thread    svchost.exe(1244): 1300
Thread    svchost.exe(1244): 2120
Thread    svchost.exe(1244): 2428
Thread    svchost.exe(1244): 2404
Thread    svchost.exe(1244): 4056
Thread    svchost.exe(1244): 480
Thread    svchost.exe(1244): 3316
Thread    svchost.exe(1244): 3640
Thread    svchost.exe(1244): 2984
Thread    svchost.exe(1244): 2980
Thread    svchost.exe(1244): 2072
Thread    svchost.exe(1244): 3488
Thread    svchost.exe(1244): 484
Thread    svchost.exe(1244): 4124
Thread    svchost.exe(1244): 3444
Thread    svchost.exe(1244): 3804
Thread    svchost.exe(1244): 3512
Thread    svchost.exe(1244): 3508
Thread    svchost.exe(1244): 216
Thread    svchost.exe(1244): 1188
Thread    svchost.exe(1244): 1812
Thread    svchost.exe(1244): 448
Thread    svchost.exe(1244): 3980
Thread    svchost.exe(1244): 2692
Thread    svchost.exe(1244): 3348
Thread    svchost.exe(1244): 4120
Thread    svchost.exe(1244): 2032
Thread    svchost.exe(1244): 3372
Thread    svchost.exe(1244): 672
Thread    svchost.exe(1244): 3380
Thread    svchost.exe(1244): 616
Thread    svchost.exe(1244): 4356
Thread    svchost.exe(1244): 3784
Thread    svchost.exe(1244): 1968
Thread    svchost.exe(1244): 3120
Thread    svchost.exe(1244): 1348
Thread    svchost.exe(1244): 2744
Thread    svchost.exe(1244): 616
Thread    svchost.exe(1244): 4360
Thread    svchost.exe(1244): 2028
Thread    svchost.exe(1244): 1744
Thread    svchost.exe(1244): 3108
Thread    svchost.exe(1244): 4116
Thread    svchost.exe(1244): 1688
Thread    svchost.exe(1244): 3996
Thread    svchost.exe(1244): 4292
Thread    svchost.exe(1244): 4352
Thread    svchost.exe(1244): 656
WindowStation    \Windows\WindowStations\Service-0x0-3e7$
WindowStation    \Windows\WindowStations\Service-0x0-3e7$
Token    NT AUTHORITY\NETWORK SERVICE:3e4
Key    HKCR
 

Any suggestions will be appreciated.

Sorry, they changed to different software for this forum and it no longer matchs the directions. I'll see if I can fix it.  Thanks for letting me know.

 

I see several candidates for looking at:

Gui.exe
FixCamera.exe
BCU.exe
vsnp2std.exe

Spybot, especially Tea Timer

GoogleUpdate.exe
GoogleCrashHandler.exe

 

Try disabling them via msconfig Start and Services tab, see if that helps.

I couldn't find GUI.exe and on Spybot I wasn't sure where tea timer was but there were two lines of spybot so disabled both along with the others you mentioned.

It seemed to help somewhat but I wouldn't say fixed the problem.

Like I said before if I let the pc sit idle for a couple of minutes and then through task manager looked at processes the cpu usage would be 0 or 1 percent.

Now that I've noticed things slowing if I look at processes the cpu usage will be anywhere from 10 to 50 percent.

So if you don't mind help me understand the best way to troubleshoot this. Would it be stopping various processes to see if one makes a difference but of course if it's more than one process if you don't disable the correct ones at the same time it would be hard to tell the difference or could this be virus spyware maleware etc related?

How much free space is there on your boot drive?
 
See here for tips on freeing up some space: Immediate - How to clean up your hard drive to increase free space
and here: LONG TERM - How to free up space on your hard drive
 
Next, try the following:
 

How does it behave if you boot to Safe Mode with Networking? If better then something is starting at boot that is causing the problem.

Advanced startup options - XP
Advanced startup options - Vista
Advanced startup options - Windows 7
Advanced startup options - Windows 8

Use msconfig to determine what is causing the problem

These are good tutorials on using msconfig in XP, Vista or Windows 7:
How to use msconfig in Windows XP
How to use msconfig in Windows Vista
How to use msconfig in Windows 7 and Windows 8

Click on Start then Run, type msconfig and press Enter.
Click on the Startup tab (for Windows 8, the Startup tab has a link to open Task Manager/Startup tab. Use that.), record what is currently starting then click the Disable All button.
Reboot and see if it runs better.
If yes then use msconfig to enable several items at a time till you find the culprit.

If no, start msconfig and click on the Services tab.
Check the Hide All Microsoft Services box, record what is currently starting then click the Disable All button.
Again, do a regular boot, see if it runs normal.
If yes then use msconfig to enable services till you find the culprit.

Once you've found the culprit, uninstall it or find out how to eliminate it from your system. Simply disabling it in msconfig is a temporary fix at best.
Enable everything else you disabled.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI