OK this was exhausting - as the 2nd computer we will name Dell2 (1 is infected cpu is HP_d220).
Results from ProCexe - test one - I will go to step 2 and 3 now.
(just to let you know the 2nd computer Dell2 has never been hooked up online, since the short while I've had it, also the taskmgr is Working on that cpu).
Process PID
CPU Private Bytes
Working Set
Description Company Name
Path Command Line
System Idle Process
0 85.94
0 K 16 K
System 4
1.56 0 K
348 K
Interrupts n/a
< 0.01 0 K
0 K Hardware Interrupts and DPCs
smss.exe 556
168 K 416 K
Windows NT Session Manager
Microsoft Corporation
C:\WINDOWS\system32\smss.exe
\SystemRoot\System32\smss.exe
csrss.exe 852
1.56 1,680 K
4,336 K Client Server Runtime Process
Microsoft Corporation
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
880 8,040 K
1,772 K Windows NT Logon Application
Microsoft Corporation
C:\WINDOWS\system32\winlogon.exe
winlogon.exe
services.exe
924 1,736 K
3,576 K Services and Controller app
Microsoft Corporation
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\services.exe
svchost.exe
1092 2,972 K
4,868 K Generic Host Process for Win32 Services
Microsoft Corporation
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
hpgs2wnf.exe
3516 864 K
3,304 K hpgs2wnf Module
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe -Embedding
wmiprvse.exe
3780 2,276 K
4,836 K WMI
Microsoft Corporation
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
svchost.exe
1172 1,792 K
4,332 K Generic Host Process for Win32 Services
Microsoft Corporation
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost -k rpcss
svchost.exe
1212 6.25
17,644 K 29,972 K
Generic Host Process for Win32 Services
Microsoft Corporation
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
1244 2,340 K
3,336 K Generic Host Process for Win32 Services
Microsoft Corporation
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
1416 4,900 K
7,228 K Generic Host Process for Win32 Services
Microsoft Corporation
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
svchost.exe
1456 1,456 K
3,884 K Generic Host Process for Win32 Services
Microsoft Corporation
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
LEXBCES.EXE
1556 2,368 K
3,424 K LexBce Service
Lexmark International, Inc.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXBCES.EXE
LEXPPS.EXE
1584 992 K
3,196 K LEXPPS.EXE
Lexmark International, Inc.
C:\WINDOWS\system32\LEXPPS.EXE
LEXPPS.EXE
spoolsv.exe
1592 3,640 K
5,784 K Spooler SubSystem App
Microsoft Corporation
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
1716 1,276 K
3,788 K Generic Host Process for Win32 Services
Microsoft Corporation
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
avgwdsvc.exe
1748 6,372 K
14,204 K AVG Watchdog Service
AVG Technologies CZ, s.r.o.
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
"C:\Program Files\AVG\AVG2012\avgwdsvc.exe"
avgnsx.exe
172 3,904 K
876 K AVG Online Shield Service
AVG Technologies CZ, s.r.o.
C:\Program Files\AVG\AVG2012\avgnsx.exe
"C:\Program Files\AVG\AVG2012\avgnsx.exe"
avgemcx.exe
184 2,404 K
5,372 K AVG E-mail Scanner
AVG Technologies CZ, s.r.o.
C:\Program Files\AVG\AVG2012\avgemcx.exe
"C:\Program Files\AVG\AVG2012\avgemcx.exe"
jqs.exe 1836
1,928 K 1,404 K
Java(TM) Quick Starter Service
Sun Microsystems, Inc.
C:\Program Files\Java\jre6\bin\jqs.exe
"C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
mbamservice.exe
1888 3,700 K
6,132 K Malwarebytes' Anti-Malware
Malwarebytes Corporation
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe"
pdfsvc.exe
1928 1,072 K
4,232 K Dispatcher
PDF Complete Inc
C:\Program Files\PDF Complete\pdfsvc.exe
"C:\Program Files\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
SDFSSvc.exe
1992 25,608 K
29,748 K Spybot-S&D 2 Scanner Service
Safer-Networking Ltd.
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe"
svchost.exe
576 2,428 K
4,284 K Generic Host Process for Win32 Services
Microsoft Corporation
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
SDUpdSvc.exe
812 6,140 K
10,828 K Spybot-S&D 2 Background update service
Safer-Networking Ltd.
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe"
avgidsagent.exe
1232 1.56
10,744 K 11,012 K
AVG Identity Protection Service
AVG Technologies CZ, s.r.o.
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
"C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe"
alg.exe 2076
1,116 K 3,588 K
Application Layer Gateway Service
Microsoft Corporation
C:\WINDOWS\system32\alg.exe
C:\WINDOWS\System32\alg.exe
lsass.exe 936
3,752 K 1,372 K
LSA Shell (Export Version)
Microsoft Corporation
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\lsass.exe
avgrsx.exe 608
14,172 K 1,612 K
AVG Resident Shield Service
AVG Technologies CZ, s.r.o.
C:\Program Files\AVG\AVG2012\avgrsx.exe
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /boot
avgcsrvx.exe
648 11,212 K
288 K AVG Scanning Core Module - Server Part
AVG Technologies CZ, s.r.o.
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe /pipeName=7f86093d-14db-4806-bb07-6a661a65b279 /coreSdkOptions=286 /logConfFile="C:\Documents and Settings\All Users\Application Data\AVG2012\temp\c1580728-2460-4725-9e36-5d3db9c3d573-260-oopp.tmp" /loggerName=AVG.RS.Core
/binaryPath="C:\Program Files\AVG\AVG2012" /registryPath="SYSTEM\CurrentControlSet\Services\Avg\Avg2012" /tempPath="C:\Documents and Settings\All Users\Application Data\AVG2012\temp"
explorer.exe 3000
23,256 K 14,008 K
Windows Explorer
Microsoft Corporation
C:\WINDOWS\explorer.exe
C:\WINDOWS\Explorer.EXE
PDVDServ.exe
3236 812 K
3,040 K PowerDVD RC Service
Cyberlink Corp.
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
avgtray.exe 3304
4,692 K 9,856 K
AVG Tray Monitor
AVG Technologies CZ, s.r.o.
C:\Program Files\AVG\AVG2012\avgtray.exe
"C:\Program Files\AVG\AVG2012\avgtray.exe"
hpgs2wnd.exe
3348 880 K
3,412 K hpgs2wnd
Hewlett-Packard
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
"C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe"
SDTray.exe 3356
7,908 K 12,688 K
Spybot - Search & Destroy tray access
Safer-Networking Ltd.
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"
ctfmon.exe 3444
900 K 3,512 K
CTF Loader Microsoft Corporation
C:\WINDOWS\system32\ctfmon.exe
"C:\WINDOWS\system32\ctfmon.exe"
SpotifyWebHelper.exe
3568 1,060 K
3,592 K C:\Documents and Settings\Lawerance\Application Data\Spotify\Data\SpotifyWebHelper.exe
"C:\Documents and Settings\Lawerance\Application Data\Spotify\Data\SpotifyWebHelper.exe"
QWDLLS.EXE 3712
12,736 K 16,276 K
Quicken Load DLLs
Intuit C:\Program Files\QUICKENW\QWDLLS.EXE
"C:\Program Files\QUICKENW\QWDLLS.EXE"
chrome.exe 3200
58,456 K 30,204 K
Google Chrome
Google Inc. C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe"
chrome.exe 3848
20,948 K 18,040 K
Google Chrome
Google Inc. C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/9/OneClickSignIn/Standard/Prerender/PrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwnd10/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_87/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warmest_socket/
--extension-process --renderer-print-preview --disable-webgl --disable-pepper-3d-for-untrusted-use --disable-gl-multisampling --disable-accelerated-compositing --disable-accelerated-2d-canvas --disable-accelerated-video-decode --channel="3200.1.231458350\1118979807"
/prefetch:3
chrome.exe 3856
23,456 K 22,108 K
Google Chrome
Google Inc. C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/9/OneClickSignIn/Standard/Prerender/PrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwnd10/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_87/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warmest_socket/
--extension-process --renderer-print-preview --disable-webgl --disable-pepper-3d-for-untrusted-use --disable-gl-multisampling --disable-accelerated-compositing --disable-accelerated-2d-canvas --disable-accelerated-video-decode --channel="3200.2.784945174\104968079"
/prefetch:3
chrome.exe 2908
6,044 K 8,288 K
Google Chrome
Google Inc. C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Documents and Settings\Lawerance\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2210_0\plugins/avgnpss.dll"
--lang=en-US --channel="3200.3.1239025483\1318064346" /prefetch:4
chrome.exe 1272
11,100 K 12,412 K
Google Chrome
Google Inc. C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="3200.5.1023128251\2003911640" --lang=en-US --ignored=" --type=renderer " /prefetch:13
chrome.exe 980
3.13 101,460 K
102,860 K Google Chrome
Google Inc.
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/9/OneClickSignIn/Standard/Prerender/PrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwnd10/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_87/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warmest_socket/
--renderer-print-preview --disable-accelerated-2d-canvas --disable-flash-fullscreen-3d --channel="3200.7.72836906\427320667" /prefetch:3
wordpad.exe 1884
1,860 K 1,940 K
WordPad MFC Application
Microsoft Corporation
C:\Program Files\Windows NT\Accessories\wordpad.exe
"C:\Program Files\Windows NT\Accessories\WORDPAD.EXE" "C:\Documents and Settings\Lawerance\Desktop\MyyFiles_4\CLUES_Master List.rtf"
wordpad.exe 4032
5,232 K 1,060 K
WordPad MFC Application
Microsoft Corporation
C:\Program Files\Windows NT\Accessories\wordpad.exe
"C:\Program Files\Windows NT\Accessories\wordpad.exe"
procexp.exe 3400
9,732 K 15,444 K
Sysinternals Process Explorer
Sysinternals - www.sysinternals.com
C:\Documents and Settings\Lawerance\Desktop\procexp.exe
"C:\Documents and Settings\Lawerance\Desktop\procexp.exe"