Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Internet extremely slow.


  • Please log in to reply
29 replies to this topic

#1 rpm2

rpm2

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:36 AM

Posted 13 January 2017 - 01:51 PM

I think I have been infected. Internet speed has slowed tremendously. I have ran Malwarebytes, CCleaner and have Panda as anti virus. Most everything else seems to be fine. Emails are downloading slowly. I have Hughesnet as internet provider. Trying to listen to Pandora and music continues to stop. If I don't follow up on this until Monday, it is because I will be out of the office in 2 hrs. I will do followups on Monday morning.

 

I have a Dell T5500 with Win 7. Running Firefox as browse and Thunderbird email

 

Thanks

Robert

 

 



BC AdBot (Login to Remove)

 


#2 rpm2

rpm2
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:36 AM

Posted 16 January 2017 - 07:14 AM

Can someone please help me with my problem mentioned above. Thanks Robert



#3 rpm2

rpm2
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:36 AM

Posted 16 January 2017 - 07:46 AM

Here is a link to another forum post that is the same as my problem. The internet connection is my problem also. I don't want to post in his topic to confuse anyone of his results compared to mine.

 

https://www.bleepingcomputer.com/forums/t/635603/unusual-delay-when-booting/



#4 buddy215

buddy215

  • Moderator
  • 13,196 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:10:36 AM

Posted 16 January 2017 - 08:12 AM

What did MBAM find and remove?

 

please post the MBAM report in your next reply.
Restart MBAM

  • Click on the History tab >> Application Logs.
  • Double click on the scan log which shows the Date and time of the scan that showed the infections.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply.

 

Use the programs below to help in diagnosing the problem(s) and to remove adware and malware.

 

Download 51a5f31352b88-icon_MBAR.pngMalwarebytes Anti-Rootkit (MBAR) to your desktop.

  • Warning! Malwarebytes Anti-Rootkit needs to be run from an account with administrator rights.
  • Double click on downloaded file. OK self extracting prompt.
  • MBAR will start. Click "Next" to continue.
  • Click in the following screen "Update" to obtain the latest malware definitions.
  • Once the update is complete select "Next" and click "Scan".
  • When the scan is finished and no malware has been found select "Exit".
  • If malware was detected, make sure to check all the items and click "Cleanup". Reboot your computer.
  • Open the MBAR folder located on your Desktop and paste the content of the following files in your next reply:
  • "mbar-log-{date} (xx-xx-xx).txt"
  • "system-log.txt"
  • NOTE. If you see This version requires you to completely exit the Anti Malware application message right click on the Malwarebytes Anti-Malware icon in the system tray and click on Exit.

 

Download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  • download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message

Post the three lists mentioned below using CCleaner.

Open CCleaner and click on Tools. Choose Startups. On that page you will see a list of Windows Startups and at the top tabs for each browser and Scheduled Tasks.

At the bottom right of that page you will see a button when clicked will allow you to Copy and Paste the list of Windows Startups and Scheduled Tasks into your next

post. Please do that.

 

Open CCleaner and click on Tools. Choose Uninstall. On that page you will see a list of programs installed on your computer and at the bottom right of that page you

will see a button when clicked will allow you to Copy and Paste that list in your next post. Please do that.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#5 rpm2

rpm2
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:36 AM

Posted 16 January 2017 - 10:25 AM

Here is my scan from Friday.

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 1/13/2017
Scan Time: 3:34 PM
Logfile:
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2017.01.13.12
Rootkit Database: v2016.11.20.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Robert Bruner

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 309870
Time Elapsed: 10 min, 30 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)



#6 rpm2

rpm2
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:36 AM

Posted 16 January 2017 - 10:27 AM

Moving to MBAR download and run.



#7 rpm2

rpm2
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:36 AM

Posted 16 January 2017 - 02:07 PM

Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org

Database version:
  main:    v2017.01.16.05
  rootkit: v2016.11.20.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.18499
Robert Bruner :: ROBERT [administrator]

1/16/2017 10:27:40 AM
mbar-log-2017-01-16 (10-27-40).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 310322
Time elapsed: 10 minute(s), 35 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
 



#8 rpm2

rpm2
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:36 AM

Posted 16 January 2017 - 02:09 PM

3 threats found. When computer rebooted, problem was still there.

 

 

# AdwCleaner v6.042 - Logfile created 16/01/2017 at 14:00:15
# Updated on 06/01/2017 by Malwarebytes
# Database : 2017-01-15.1 [Server]
# Operating System : Windows 7 Professional Service Pack 1 (X64)
# Username : Robert Bruner - ROBERT
# Running from : C:\Users\Robert Bruner\Desktop\AdwCleaner.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support



***** [ Services ] *****



***** [ Folders ] *****

[-] Folder deleted: C:\Users\Robert Bruner\AppData\Roaming\download Manager


***** [ Files ] *****

[-] File deleted: C:\Users\Robert Bruner\AppData\Roaming\Mozilla\Firefox\Profiles\174klpv6.default\searchplugins\Askcom.xml


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Shortcuts ] *****



***** [ Scheduled Tasks ] *****



***** [ Registry ] *****



***** [ Web browsers ] *****

[-] Chrome preferences cleaned:


*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [1015 Bytes] - [16/01/2017 14:00:15]
C:\AdwCleaner\AdwCleaner[S0].txt - [1482 Bytes] - [16/01/2017 13:59:07]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1161 Bytes] ##########



#9 buddy215

buddy215

  • Moderator
  • 13,196 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:10:36 AM

Posted 16 January 2017 - 02:22 PM

3 threats found. When computer rebooted, problem was still there.

 

Found by what program...? What threats?


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#10 rpm2

rpm2
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:36 AM

Posted 16 January 2017 - 02:36 PM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.0 (12.05.2016)
Operating System: Windows 7 Professional x64
Ran by Robert Bruner (Administrator) on Mon 01/16/2017 at 14:33:14.88
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 44

Successfully deleted: C:\Users\Robert Bruner\AppData\Local\crashrpt (Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Roaming\Mozilla\Firefox\Profiles\174klpv6.default\user.js (File)
Successfully deleted: C:\Windows\system32\Tasks\PCDEventLauncherTask (Task)
Successfully deleted: C:\Windows\wininit.ini (File)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\01K1ACAS (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0WMEE6QE (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\90D52DSR (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9J7UGTHL (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BPT8QHJ4 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CFRXVMCQ (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E0VQFMCH (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F0K0Y577 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F956GMKM (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J49JRQYG (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L5Q5FMC4 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OKK55R2E (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RU77L13Y (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S3MVZJ7B (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y40R0XDV (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Robert Bruner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZRKMA3KW (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\01K1ACAS (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0WMEE6QE (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\90D52DSR (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9J7UGTHL (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BPT8QHJ4 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CFRXVMCQ (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E0VQFMCH (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F0K0Y577 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F956GMKM (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J49JRQYG (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L5Q5FMC4 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OKK55R2E (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RU77L13Y (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S3MVZJ7B (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y40R0XDV (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZRKMA3KW (Temporary Internet Files Folder)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 01/16/2017 at 14:34:39.70
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 



#11 rpm2

rpm2
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:36 AM

Posted 16 January 2017 - 02:41 PM

3 threats found by AdwCleaner

 

At least that is what AdwCleaner posted as it was running.


Edited by rpm2, 16 January 2017 - 02:42 PM.


#12 buddy215

buddy215

  • Moderator
  • 13,196 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:10:36 AM

Posted 16 January 2017 - 02:55 PM

Okay...so far...nothing that would cause any serious problem.

 

After posting the three lists using CCleaner, perform a scan and post a link to the results or post the results using

Speccy - System Information - Free Download  Use the portable version to avoid any bundled adware.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#13 rpm2

rpm2
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:36 AM

Posted 16 January 2017 - 02:58 PM

Windows Startup

 

Yes    HKCU:Run    CCleaner Monitoring    Piriform Ltd    "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
Yes    HKCU:Run    RESTART_STICKY_NOTES    Microsoft Corporation    C:\Windows\System32\StikyNot.exe
Yes    HKCU:Run    SpybotPostWindows10UpgradeReInstall    Safer-Networking Ltd.    "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
Yes    HKLM:Run    FileOpenBroker    FileOpen Systems Inc.    C:\Program Files\FileOpen\Services\FileOpenBroker64.exe
Yes    HKLM:Run    HP LaserJet Professional M1530 MFP Series Fax    Hewlett-Packard Company    C:\Program Files\HP\HP LaserJet Professional M1530 MFP Series\Fax Driver\hppfaxprintersrv.exe "HP LaserJet Professional M1530 MFP Series Fax"
Yes    HKLM:Run    Intuit SyncManager    Intuit Inc. All rights reserved.    C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup
Yes    HKLM:Run    PSUAMain    Panda Security, S.L.    "C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe" /LaunchSysTray
Yes    HKLM:Run    SoundMAXPnP    Analog Devices, Inc.    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
Yes    HKLM:Run    ToolboxFX    Hewlett-Packard Company    "C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
Yes    Startup Common    FAH.lnk    WinZip Computing, S.L.    C:\Program Files\WinZip\FAHConsole.exe
Yes    Startup Common    Intuit Data Protect.lnk    Intuit Inc.    C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
Yes    Startup Common    QuickBooks Update Agent.lnk    Intuit Inc.    C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
Yes    Startup Common    QuickBooks_Standard_21.lnk    Intuit Inc.    C:\Program Files (x86)\Intuit\QuickBooks 2014\QBW32.EXE
Yes    Startup Common    SolidWorks 2013 Fast Start.lnk    Flexera Software, Inc.    C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
Yes    Startup Common    SolidWorks Background Downloader.lnk    Dassault Systèmes SolidWorks Corp.    C:\Program Files (x86)\Common Files\SolidWorks Installation Manager\BackgroundDownloading\sldBgDwld.exe
Yes    Startup Common    Update Notifier.lnk    WinZip    C:\Program Files\WinZip\WZUpdateNotifier.exe
Yes    Startup Common    WinZip Preloader.lnk    WinZip Computing, S.L.    C:\Program Files\WinZip\WzPreloader.exe
 



#14 rpm2

rpm2
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:36 AM

Posted 16 January 2017 - 03:08 PM

Scheduled Task

 

Yes    Task    Adobe Acrobat Update Task    Adobe Systems Incorporated    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Yes    Task    CCleanerSkipUAC    Piriform Ltd    "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
Yes    Task    HPLJCustParticipation    Hewlett Packard    "C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe"
Yes    Task    WinZip Update Notifier    WinZip    "C:\Program Files\WinZip\WZUpdateNotifier.exe"
Yes    Task    WinZipBackGroundToolsTask    WinZip Computing, S.L.    C:\Program Files\WinZip\WzBGTools.exe
Yes    Task    {0337FEF8-DA51-470E-A43E-90E07EA248E0}    Microsoft Corporation    C:\Windows\system32\pcalua.exe -a "F:\Solidworks 2013\SW2013_SP0.0_64bits_Crack_[hispargentino]\SW2013_SP0.0_[hispargentino]\setup.exe" -d "F:\Solidworks 2013\SW2013_SP0.0_64bits_Crack_[hispargentino]\SW2013_SP0.0_[hispargentino]"
Yes    Task    {1A2BC75E-D919-4A5B-93F3-B6ADA5C52D6A}    Microsoft Corporation    C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
 



#15 buddy215

buddy215

  • Moderator
  • 13,196 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:10:36 AM

Posted 16 January 2017 - 03:22 PM

Suggest Disabling these Windows Startups: Use CCleaner by clicking on each item and choosing Disable on the right.

Yes    HKCU:Run    CCleaner Monitoring    Piriform Ltd    "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
Yes    HKCU:Run    RESTART_STICKY_NOTES    Microsoft Corporation    C:\Windows\System32\StikyNot.exe
Yes    HKCU:Run    SpybotPostWindows10UpgradeReInstall    Safer-Networking Ltd.    "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
Yes    HKLM:Run    FileOpenBroker    FileOpen Systems Inc.    C:\Program Files\FileOpen\Services\FileOpenBroker64.exe
Yes    HKLM:Run    HP LaserJet Professional M1530 MFP Series Fax    Hewlett-Packard Company    C:\Program Files\HP\HP LaserJet Professional M1530 MFP Series\Fax Driver\hppfaxprintersrv.exe "HP LaserJet Professional M1530 MFP Series Fax"

es    HKLM:Run    ToolboxFX    Hewlett-Packard Company    "C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
Yes    Startup Common    FAH.lnk    WinZip Computing, S.L.    C:\Program Files\WinZip\FAHConsole.exe

Yes    Startup Common    QuickBooks Update Agent.lnk    Intuit Inc.    C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
Yes    Startup Common    QuickBooks_Standard_21.lnk    Intuit Inc.    C:\Program Files (x86)\Intuit\QuickBooks 2014\QBW32.EXE
Yes    Startup Common    SolidWorks 2013 Fast Start.lnk    Flexera Software, Inc.    C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
Yes    Startup Common    SolidWorks Background Downloader.lnk    Dassault Systèmes SolidWorks Corp.    C:\Program Files (x86)\Common Files\SolidWorks Installation Manager\BackgroundDownloading\sldBgDwld.exe
Yes    Startup Common    Update Notifier.lnk    WinZip    C:\Program Files\WinZip\WZUpdateNotifier.exe
Yes    Startup Common    WinZip Preloader.lnk    WinZip Computing, S.L.    C:\Program Files\WinZip\WzPreloader.exe

 

Disable these Tasks: Use CCleaner by clicking on each item and choosing Disable on the right.

Yes    Task    HPLJCustParticipation    Hewlett Packard    "C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe"
Yes    Task    WinZip Update Notifier    WinZip    "C:\Program Files\WinZip\WZUpdateNotifier.exe"
Yes    Task    WinZipBackGroundToolsTask    WinZip Computing, S.L.    C:\Program Files\WinZip\WzBGTools.exe
Yes    Task    {0337FEF8-DA51-470E-A43E-90E07EA248E0}    Microsoft Corporation    C:\Windows\system32\pcalua.exe -a "F:\Solidworks 2013\SW2013_SP0.0_64bits_Crack_[hispargentino]\SW2013_SP0.0_[hispargentino]\setup.exe" -d "F:\Solidworks 2013\SW2013_SP0.0_64bits_Crack_[hispargentino]\SW2013_SP0.0_[hispargentino]"
Yes    Task    {1A2BC75E-D919-4A5B-93F3-B6ADA5C52D6A}    Microsoft Corporation    C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\


Edited by buddy215, 16 January 2017 - 03:23 PM.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users