rkinner, thanks
here is text from procexp
sorry but can't find button to attach file to this msg - where is it?
PROCEXP
Process CPU Private Bytes Working Set PID Description Company Name VirusTotal Verified Signer
System Idle Process 97.43 0 K 24 K 0
System 0.55 140 K 728 K 4
procexp64.exe 0.34 44,744 K 70,880 K 3236 Sysinternals Process Explorer Sysinternals - www.sysinternals.com 0/56 (Verified) Microsoft Corporation
WmiPrvSE.exe 0.31 7,092 K 11,788 K 6212 WMI Provider Host Microsoft Corporation 0/59 (Verified) Microsoft Windows
Speccy64.exe 0.25 32,160 K 56,560 K 1536 Speccy Piriform Ltd 0/58 (Verified) Piriform Ltd
Interrupts 0.21 0 K 0 K n/a Hardware Interrupts and DPCs
taskmgr.exe 0.17 4,136 K 11,448 K 1652 Windows Task Manager Microsoft Corporation 0/59 (Verified) Microsoft Windows
svchost.exe 0.10 39,060 K 55,352 K 464 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
rf-chrome-nm-host.exe 0.07 16,168 K 25,576 K 7024 rf-chrome-nm-host Siber Systems Inc. 0/59 (Verified) Siber Systems
chrome.exe 0.06 150,232 K 166,132 K 6096 Google Chrome Google Inc. 0/59 (Verified) Google Inc
LCore.exe 0.06 33,392 K 48,008 K 4152 Logitech Gaming Framework Logitech Inc. 0/59 (Verified) Logitech Inc
chrome.exe 0.05 124,744 K 199,180 K 5412 Google Chrome Google Inc. 0/59 (Verified) Google Inc
mbam.exe 0.05 28,920 K 50,112 K 3584 Malwarebytes Anti-Malware Malwarebytes 0/58 (Verified) Malwarebytes Corporation
id_tray.exe 0.05 38,300 K 49,840 K 4916 IDrive Tray Prosoftnet 0/58 (Verified) Pro Softnet Corporation
explorer.exe 0.04 39,904 K 66,000 K 2732 Windows Explorer Microsoft Corporation 0/58 (Verified) Microsoft Windows
vpnui.exe 0.04 6,184 K 17,404 K 4788 Cisco AnyConnect User Interface Cisco Systems, Inc. 0/57 (Verified) Cisco Systems
csrss.exe 0.03 66,028 K 37,472 K 720 Client Server Runtime Process Microsoft Corporation 0/59 (Verified) Microsoft Windows
dllhost.exe 0.02 3,336 K 8,120 K 6708 COM Surrogate Microsoft Corporation 0/59 (Verified) Microsoft Windows
id_service.exe 0.02 69,388 K 50,468 K 5704 IDrive Service Prosoftnet 0/55 (Verified) Pro Softnet Corporation
WmiPrvSE.exe 0.02 26,188 K 32,480 K 4108 WMI Provider Host Microsoft Corporation 0/59 (Verified) Microsoft Windows
svchost.exe 0.02 6,496 K 8,132 K 2444 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
robotaskbaricon.exe 0.01 13,704 K 25,332 K 4860 RoboForm TaskBar Icon Siber Systems 0/58 (Verified) Siber Systems
CCleaner64.exe 0.01 9,228 K 16,744 K 4500 CCleaner Piriform Ltd 0/58 (Verified) Piriform Ltd
chrome.exe 0.01 131,828 K 217,064 K 7492 Google Chrome Google Inc. 0/59 (Verified) Google Inc
svchost.exe 0.01 6,368 K 10,308 K 172 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
nis.exe 0.01 125,540 K 29,840 K 3292 Norton Internet Security Symantec Corporation 0/59 (Verified) Symantec Corporation
GWX_control_panel.exe 0.01 2,356 K 7,784 K 3252 GWX Control Panel - Closes and configures the 'Get Windows 10' system tray application. UltimateOutsider 0/54 (Verified) Josh Mayfield
LCDClock.exe 0.01 4,876 K 9,948 K 4820 Logitech LCD Clock/Performance Monitor Logitech Inc. 0/56 (Verified) Logitech Inc
svchost.exe < 0.01 21,572 K 24,612 K 456 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
LCDMedia.exe < 0.01 8,000 K 10,240 K 4368 Logitech G-series Media Display Logitech Inc. 0/57 (Verified) Logitech Inc
chrome.exe < 0.01 35,180 K 40,376 K 6656 Google Chrome Google Inc. 0/59 (Verified) Google Inc
svchost.exe < 0.01 5,880 K 10,120 K 6084 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
WmiApSrv.exe < 0.01 2,740 K 6,972 K 6856 WMI Performance Reverse Adapter Microsoft Corporation 0/59 (Verified) Microsoft Windows
J2GDllCmd.exe < 0.01 1,136 K 4,172 K 4604 eFax Messenger - DLL Command Utility j2 Global, Inc. 2/57 (No signature was present in the subject) j2 Global, Inc.
chrome.exe < 0.01 111,344 K 78,676 K 4824 Google Chrome Google Inc. 0/59 (Verified) Google Inc
FSCAppServ.exe < 0.01 2,952 K 4,760 K 1576 Intel® Desktop Boards Fan Speed Control Instrumentation Service Intel Corporation 0/57 (Verified) Channel Innovations and Solutions Division
PDFProFiltSrvPP.exe < 0.01 2,968 K 7,696 K 2364 PDFPro IFilter Service Nuance Communications, Inc. 0/56 (Verified) Nuance Communications
cvpnd.exe < 0.01 2,984 K 7,416 K 1980 Cisco Systems VPN Client Cisco Systems, Inc. 0/59 (Verified) Cisco Systems
taskhost.exe < 0.01 21,700 K 13,644 K 3808 Host Process for Windows Tasks Microsoft Corporation 0/59 (Verified) Microsoft Windows
EvernoteClipper.exe < 0.01 2,012 K 6,228 K 4256 Evernote Clipper Evernote Corp., 305 Walnut Street, Redwood City, CA 94063 0/59 (Verified) EVERNOTE CORPORATION
svchost.exe < 0.01 9,900 K 17,468 K 564 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
svchost.exe < 0.01 25,684 K 18,676 K 1316 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
officeclicktorun.exe < 0.01 30,176 K 39,900 K 1884 Microsoft Office Click-to-Run Microsoft Corporation 0/59 (Verified) Microsoft Corporation
nis.exe < 0.01 26,936 K 10,724 K 4728 Norton Internet Security Symantec Corporation 0/59 (Verified) Symantec Corporation
SearchIndexer.exe < 0.01 54,032 K 48,196 K 5320 Microsoft Windows Search Indexer Microsoft Corporation 0/57 (Verified) Microsoft Windows
nvxdsync.exe < 0.01 13,068 K 25,816 K 1716 NVIDIA User Experience Driver Component NVIDIA Corporation 0/58 (Verified) NVIDIA Corporation
SearchProtocolHost.exe < 0.01 5,664 K 12,968 K 5780 Microsoft Windows Search Protocol Host Microsoft Corporation 0/59 (Verified) Microsoft Windows
explorer.exe < 0.01 130,400 K 56,660 K 6720 Windows Explorer Microsoft Corporation 0/58 (Verified) Microsoft Windows
svchost.exe < 0.01 10,960 K 22,208 K 628 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
spoolsv.exe < 0.01 9,396 K 15,840 K 1484 Spooler SubSystem App Microsoft Corporation 0/58 (Verified) Microsoft Windows
WUDFHost.exe 2,484 K 6,712 K 2476 Windows Driver Foundation - User-mode Driver Framework Host Process Microsoft Corporation 0/59 (Verified) Microsoft Windows
WmiPrvSE.exe 13,596 K 22,460 K 3328 WMI Provider Host Microsoft Corporation 0/59 (Verified) Microsoft Windows
winlogon.exe 4,212 K 8,708 K 1412 Windows Logon Application Microsoft Corporation 0/59 (Verified) Microsoft Windows
wininit.exe 2,084 K 5,196 K 696 Windows Start-Up Application Microsoft Corporation 0/59 (Verified) Microsoft Windows
vpnagent.exe 6,456 K 15,412 K 1288 VPN Agent Service Cisco Systems, Inc. 0/56 (Verified) Cisco Systems
taskeng.exe 2,724 K 6,216 K 7780 Task Scheduler Engine Microsoft Corporation 0/59 (Verified) Microsoft Windows
svchost.exe 21,296 K 15,904 K 5976 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
svchost.exe 6,420 K 12,056 K 888 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
svchost.exe 13,864 K 18,772 K 1564 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
svchost.exe 2,836 K 6,508 K 1384 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
svchost.exe 3,556 K 7,028 K 1132 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
svchost.exe 4,852 K 8,252 K 1260 Host Process for Windows Services Microsoft Corporation 0/57 (Verified) Microsoft Windows
smss.exe 784 K 1,492 K 368 Windows Session Manager Microsoft Corporation 0/59 (Verified) Microsoft Windows
services.exe 6,872 K 11,192 K 756 Services and Controller app Microsoft Corporation 0/59 (Verified) Microsoft Windows
SearchFilterHost.exe 2,984 K 6,224 K 7592 Microsoft Windows Search Filter Host Microsoft Corporation 0/59 (Verified) Microsoft Windows
rundll32.exe 2,200 K 1,380 K 5820 Windows host process (Rundll32) Microsoft Corporation 0/58 (Verified) Microsoft Windows
rundll32.exe 8,760 K 8,500 K 4564 Windows host process (Rundll32) Microsoft Corporation 0/58 (Verified) Microsoft Windows
RAVCpl64.exe 9,636 K 11,912 K 3140 Realtek HD Audio Manager Realtek Semiconductor 0/59 (Verified) Realtek Semiconductor Corp
procexp.exe 2,568 K 7,644 K 876 Sysinternals Process Explorer Sysinternals - www.sysinternals.com 0/57 (Verified) Microsoft Corporation
PrintIsolationHost.exe 1,968 K 5,016 K 1428 PrintIsolationHost Microsoft Corporation 0/58 (Verified) Microsoft Windows
prevhost.exe 4,308 K 9,956 K 3972 Preview Handler Surrogate Host Microsoft Corporation 0/58 (Verified) Microsoft Windows
pptd40nt.exe 2,960 K 7,892 K 4248 PaperPort Print to Desktop for NT Nuance Communications, Inc. 0/58 (Verified) Nuance Communications
ONENOTEM.EXE 5,556 K 1,568 K 4692 Send to OneNote Tool Microsoft Corporation 0/56 (Verified) Microsoft Corporation
nvvsvc.exe 3,848 K 8,836 K 960 NVIDIA Driver Helper Service, Version 372.90 NVIDIA Corporation 0/56 (Verified) NVIDIA Corporation
nvscpapisvr.exe 2,776 K 6,184 K 988 Stereo Vision Control Panel API Server NVIDIA Corporation 0/57 (Verified) NVIDIA Corporation
mbamservice.exe 411,712 K 321,248 K 2220 Malwarebytes Anti-Malware Malwarebytes 0/58 (Verified) Malwarebytes Corporation
mbamscheduler.exe 5,444 K 11,012 K 2116 Malwarebytes Anti-Malware Malwarebytes 0/59 (Verified) Malwarebytes Corporation
lsm.exe 3,344 K 5,292 K 788 Local Session Manager Service Microsoft Corporation 0/59 (Verified) Microsoft Windows
lsass.exe 8,472 K 15,348 K 780 Local Security Authority Process Microsoft Corporation 0/58 (Verified) Microsoft Windows
LogiRegistryService.exe 1,964 K 5,176 K 2064 Logitech Surround Sound Service Logitech Inc. 0/56 (Verified) Logitech Inc
jusched.exe 2,988 K 8,280 K 4448 Java Update Scheduler Oracle Corporation 0/56 (Verified) Oracle America
jucheck.exe 4,864 K 12,500 K 4928 Java Update Checker Oracle Corporation 0/59 (Verified) Oracle America
J2GTray.exe 3,388 K 7,700 K 5040 eFax Messenger - Tray j2 Global, Inc. 0/55 (No signature was present in the subject) j2 Global, Inc.
id_bglaunch.exe 25,872 K 25,084 K 4296 IDrive Background Prosoftnet 0/59 (Verified) Pro Softnet Corporation
GoogleUpdate.exe 2,360 K 1,632 K 1952 Google Installer Google Inc. 1/59 (Verified) Google Inc
dwm.exe 3,024 K 7,288 K 3956 Desktop Window Manager Microsoft Corporation 0/58 (Verified) Microsoft Windows
CTAudSvc.exe 1,436 K 4,684 K 1104 Creative Audio Service Creative Technology Ltd 0/56 (No signature was present in the subject) Creative Technology Ltd
csrss.exe 2,696 K 5,224 K 588 Client Server Runtime Process Microsoft Corporation 0/59 (Verified) Microsoft Windows
conhost.exe 1,884 K 4,480 K 6892 Console Window Host Microsoft Corporation 0/58 (Verified) Microsoft Windows
conhost.exe 1,876 K 4,472 K 6700 Console Window Host Microsoft Corporation 0/58 (Verified) Microsoft Windows
conathst.exe 3,060 K 7,388 K 7056 Web Browser (Norton Identity Safe native host) Symantec Corporation 0/59 (Verified) Symantec Corporation
cmd.exe 2,572 K 3,480 K 6620 Windows Command Processor Microsoft Corporation 0/59 (Verified) Microsoft Windows
cmd.exe 2,568 K 3,376 K 6864 Windows Command Processor Microsoft Corporation 0/59 (Verified) Microsoft Windows
chrome.exe 173,524 K 175,436 K 5328 Google Chrome Google Inc. 0/59 (Verified) Google Inc
chrome.exe 46,388 K 54,212 K 4664 Google Chrome Google Inc. 0/59 (Verified) Google Inc
chrome.exe 39,976 K 50,188 K 6500 Google Chrome Google Inc. 0/59 (Verified) Google Inc
chrome.exe 28,660 K 35,736 K 4288 Google Chrome Google Inc. 0/59 (Verified) Google Inc
chrome.exe 2,668 K 6,572 K 4516 Google Chrome Google Inc. 0/59 (Verified) Google Inc
chrome.exe 27,428 K 32,300 K 6336 Google Chrome Google Inc. 0/59 (Verified) Google Inc
chrome.exe 27,772 K 32,380 K 6176 Google Chrome Google Inc. 0/59 (Verified) Google Inc
chrome.exe 2,024 K 5,004 K 4996 Google Chrome Google Inc. 0/59 (Verified) Google Inc
chrome.exe 201,700 K 23,612 K 6896 Google Chrome Google Inc. 0/59 (Verified) Google Inc
audiodg.exe 15,984 K 17,488 K 1064 Windows Audio Device Graph Isolation Microsoft Corporation 0/59 (Verified) Microsoft Windows
armsvc.exe 1,324 K 4,208 K 1784 Adobe Acrobat Update Service Adobe Systems Incorporated 0/59 (Verified) Adobe Systems
Process: System Idle Process Pid: 0
Name Description Company Name Path VirusTotal Verified Signer