

2.Is the system to compromised to try to save. dat files and cookies listed in the file could clean the system. I need to know if: 1.Deleting the Temp files and Temporary Internet files along with. I hope it's ok to post the saved file from one of the svchost instances because it has obvious concerns.

I haven't looked for specific dll's yet but process explorer found "Mutant" files in every instance of svchost including this: Mutant \BaseNamedObjects\SHIMLIB_LOG_MUTEX. With auto updates on the other ip addresses belong to Microsoft. > The remote ip address netsvcs is contacting belongs to Akamai Technologies when windows auto update is turned off. >Ran svchost.exe fix from Microsoft which is for high cpu use but thought it might help. >Disabled Backgound Intelligent Transfer service but netsvcs still downloads and the BITS service goes back to Automatic after a reboot. It found and removed 1 virus in setup_lib_srf.exe which contained "Downloader" in 2009. >The computer has always had Norton antivirus installed. >Turn off system restore and rescan with AVG while the computer was connected.

Avg found 6 corrupted google toolbar.exe in Temp files. >Scan with Malwarebytes, Security Essentials, MFRT, AVG, TDDSkiller in windows and safe mode when possible. I am using Netbalancer to watch the process. Before I realized the problem, it downloaded 1.4GB. It will download as long as the computer is connected. I am working on an XP Home SP3 computer that constantly downloads using system32\svchost.exe -k netsvcs.
