Sorry it's taken so long. I did as you said and this is the PE log when I'm running firefox in safemode.
Process PID CPU Description Company Name Command Line
System Idle Process 0 93.39
procexp.exe 1984 2.99 Sysinternals Process Explorer Sysinternals -
www.sysinternals.com "c:\Users\Bob\Documents\Process Explorer\procexp.exe"
svchost.exe 1008 2.24 Host Process for Windows Services Microsoft Corporation C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
services.exe 608 1.49 Services and Controller app Microsoft Corporation C:\Windows\system32\services.exe
wuauclt.exe 2796 Windows Update Automatic Updates Microsoft Corporation "C:\Windows\system32\wuauclt.exe"
wmpnscfg.exe 3164 Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation "C:\Program Files\Windows Media Player\wmpnscfg.exe"
wmpnetwk.exe 3200 Windows Media Player Network Sharing Service Microsoft Corporation "C:\Program Files\Windows Media Player\wmpnetwk.exe"
winlogon.exe 704 Windows Logon Application Microsoft Corporation winlogon.exe
wininit.exe 564 Windows Start-Up Application Microsoft Corporation wininit.exe
TrustedInstaller.exe 1784 Windows Modules Installer Microsoft Corporation C:\Windows\servicing\TrustedInstaller.exe
taskeng.exe 2784 Task Scheduler Engine Microsoft Corporation taskeng.exe {169456CF-BB5B-4D12-AA77-1B76038A520C}
taskeng.exe 2144 Task Scheduler Engine Microsoft Corporation taskeng.exe {BD59BD6B-5C28-409B-AED2-B5F4885BA333}
System 4
svchost.exe 1040 Host Process for Windows Services Microsoft Corporation C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
svchost.exe 1060 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k netsvcs
svchost.exe 1500 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k NetworkService
svchost.exe 1324 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k LocalService
svchost.exe 864 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k rpcss
svchost.exe 808 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k DcomLaunch
svchost.exe 1228 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k GPSvcGroup
svchost.exe 1760 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
svchost.exe 1948 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k bthsvcs
svchost.exe 2028 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
svchost.exe 280 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k imgsvc
svchost.exe 1480 Host Process for Windows Services Microsoft Corporation C:\Windows\System32\svchost.exe -k WerSvcGroup
spoolsv.exe 1724 Spooler SubSystem App Microsoft Corporation C:\Windows\System32\spoolsv.exe
smss.exe 388 Windows Session Manager Microsoft Corporation \SystemRoot\System32\smss.exe
SLsvc.exe 1284 Microsoft Software Licensing Service Microsoft Corporation C:\Windows\system32\SLsvc.exe
SearchIndexer.exe 860 Microsoft Windows Search Indexer Microsoft Corporation C:\Windows\system32\SearchIndexer.exe /Embedding
OrbTray.exe 2836 Orb Orb Networks "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe"
Orb.exe 3436 Orb Application Orb Networks, Inc. "C:\Program Files\Orb Networks\Orb\bin\Orb.exe"
msdtc.exe 2492 MS DTCconsole program Microsoft Corporation C:\Windows\System32\msdtc.exe
msconfig.exe 2960 System Configuration Utility Microsoft Corporation "C:\Windows\System32\msconfig.exe" /auto
lsm.exe 632 Local Session Manager Service Microsoft Corporation C:\Windows\system32\lsm.exe
lsass.exe 620 Local Security Authority Process Microsoft Corporation C:\Windows\system32\lsass.exe
Interrupts n/a Hardware Interrupts
firefox.exe 3136 Firefox Mozilla Corporation "C:\Program Files\Mozilla Firefox\firefox.exe" "-safe-mode"
explorer.exe 2808 Windows Explorer Microsoft Corporation C:\Windows\Explorer.EXE
dwm.exe 2752 Desktop Window Manager Microsoft Corporation "C:\Windows\system32\Dwm.exe"
DPCs n/a Deferred Procedure Calls
dllhost.exe 652 COM Surrogate Microsoft Corporation C:\WINDOWS\SYSTEM32\DLLHOST.EXE /PROCESSID:{BDFEFE06-0F3F-44F4-984D-3BF2A1CA8D75}
dllhost.exe 2236 COM Surrogate Microsoft Corporation C:\WINDOWS\SYSTEM32\DLLHOST.EXE /PROCESSID:{02D4B3F1-FD88-11D1-960D-00805FC79235}
csrss.exe 576 Client Server Runtime Process Microsoft Corporation C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
csrss.exe 524 Client Server Runtime Process Microsoft Corporation C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
audiodg.exe 1192 Windows Audio Device Graph Isolation Microsoft Corporation C:\Windows\system32\AUDIODG.EXE 0x304
This is the PE log when I run firefox normally, it's down to only a few %Process PID CPU Description Company Name Command Line
System Idle Process 0 96.66
procexp.exe 1984 2.25 Sysinternals Process Explorer Sysinternals -
www.sysinternals.com "c:\Users\Bob\Documents\Process Explorer\procexp.exe"
services.exe 608 1.50 Services and Controller app Microsoft Corporation C:\Windows\system32\services.exe
wuauclt.exe 2796 Windows Update Automatic Updates Microsoft Corporation "C:\Windows\system32\wuauclt.exe"
wmpnscfg.exe 3164 Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation "C:\Program Files\Windows Media Player\wmpnscfg.exe"
wmpnetwk.exe 3200 Windows Media Player Network Sharing Service Microsoft Corporation "C:\Program Files\Windows Media Player\wmpnetwk.exe"
winlogon.exe 704 Windows Logon Application Microsoft Corporation winlogon.exe
wininit.exe 564 Windows Start-Up Application Microsoft Corporation wininit.exe
TrustedInstaller.exe 1784 Windows Modules Installer Microsoft Corporation C:\Windows\servicing\TrustedInstaller.exe
taskeng.exe 2784 Task Scheduler Engine Microsoft Corporation taskeng.exe {169456CF-BB5B-4D12-AA77-1B76038A520C}
taskeng.exe 2144 Task Scheduler Engine Microsoft Corporation taskeng.exe {BD59BD6B-5C28-409B-AED2-B5F4885BA333}
System 4
svchost.exe 1500 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k NetworkService
svchost.exe 1040 Host Process for Windows Services Microsoft Corporation C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
svchost.exe 808 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k DcomLaunch
svchost.exe 1760 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
svchost.exe 1008 Host Process for Windows Services Microsoft Corporation C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
svchost.exe 1060 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k netsvcs
svchost.exe 1324 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k LocalService
svchost.exe 864 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k rpcss
svchost.exe 1228 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k GPSvcGroup
svchost.exe 1948 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k bthsvcs
svchost.exe 2028 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
svchost.exe 280 Host Process for Windows Services Microsoft Corporation C:\Windows\system32\svchost.exe -k imgsvc
svchost.exe 1480 Host Process for Windows Services Microsoft Corporation C:\Windows\System32\svchost.exe -k WerSvcGroup
spoolsv.exe 1724 Spooler SubSystem App Microsoft Corporation C:\Windows\System32\spoolsv.exe
smss.exe 388 Windows Session Manager Microsoft Corporation \SystemRoot\System32\smss.exe
SLsvc.exe 1284 Microsoft Software Licensing Service Microsoft Corporation C:\Windows\system32\SLsvc.exe
SearchIndexer.exe 860 Microsoft Windows Search Indexer Microsoft Corporation C:\Windows\system32\SearchIndexer.exe /Embedding
OrbTray.exe 2836 Orb Orb Networks "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe"
Orb.exe 3436 Orb Application Orb Networks, Inc. "C:\Program Files\Orb Networks\Orb\bin\Orb.exe"
notepad.exe 3432 Notepad Microsoft Corporation "C:\Windows\system32\NOTEPAD.EXE" C:\Users\Bob\Documents\Process Explorer\ProcexpFFsafemode.txt
msdtc.exe 2492 MS DTCconsole program Microsoft Corporation C:\Windows\System32\msdtc.exe
msconfig.exe 2960 System Configuration Utility Microsoft Corporation "C:\Windows\System32\msconfig.exe" /auto
lsm.exe 632 Local Session Manager Service Microsoft Corporation C:\Windows\system32\lsm.exe
lsass.exe 620 Local Security Authority Process Microsoft Corporation C:\Windows\system32\lsass.exe
Interrupts n/a Hardware Interrupts
firefox.exe 3308 Firefox Mozilla Corporation "C:\Program Files\Mozilla Firefox\firefox.exe"
explorer.exe 2808 Windows Explorer Microsoft Corporation C:\Windows\Explorer.EXE
dwm.exe 2752 Desktop Window Manager Microsoft Corporation "C:\Windows\system32\Dwm.exe"
DPCs n/a Deferred Procedure Calls
dllhost.exe 652 COM Surrogate Microsoft Corporation C:\WINDOWS\SYSTEM32\DLLHOST.EXE /PROCESSID:{BDFEFE06-0F3F-44F4-984D-3BF2A1CA8D75}
dllhost.exe 2236 COM Surrogate Microsoft Corporation C:\WINDOWS\SYSTEM32\DLLHOST.EXE /PROCESSID:{02D4B3F1-FD88-11D1-960D-00805FC79235}
csrss.exe 576 Client Server Runtime Process Microsoft Corporation C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
csrss.exe 524 Client Server Runtime Process Microsoft Corporation C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
audiodg.exe 1192 Windows Audio Device Graph Isolation Microsoft Corporation C:\Windows\system32\AUDIODG.EXE 0x304