Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected and In Over My Head! Help!


  • Please log in to reply
30 replies to this topic

#1 morrigans1

morrigans1

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:14 PM

Posted 11 November 2017 - 02:53 PM

Hello~

 

I'm in trouble with my comp.  Every time I turn it on, I seem to have a different experience.  Very unpredictable and unstable.

 

I'm running on Windows 10 (with components of 10 creators release...what a joke!), and I use Kaspersky as my protection (along with all logs below).

 

I have run CC Cleaner, and got all of the extraneous junk out of the way.

 

Here are my logs:

 

MBAM-

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 11/11/17
Scan Time: 9:25 AM
Log File: 33fe2566-c6ec-11e7-b6f1-34e6d781b304.json
Administrator: Yes
 
-Software Information-
Version: 3.2.2.2029
Components Version: 1.0.212
Update Package Version: 1.0.3230
License: Free
 
-System Information-
OS: Windows 10 (Build 15063.674)
CPU: x64
File System: NTFS
User: System
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 429058
Threats Detected: 6
Threats Quarantined: 2
Time Elapsed: 50 min, 53 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 6
PUP.Optional.Conduit, C:\USERS\KIMBERLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\Web Data, Replaced, [579], [454832],1.0.3230
PUP.Optional.Conduit, C:\USERS\KIMBERLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\Web Data, Replaced, [579], [454832],1.0.3230
PUP.Optional.Conduit, C:\USERS\KIMBERLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\Secure Preferences, Removal Failed, [579], [454832],1.0.3230
PUP.Optional.Conduit, C:\USERS\KJORD_000\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\Web Data, Removal Failed, [579], [454832],1.0.3230
PUP.Optional.Conduit, C:\USERS\KJORD_000\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\Web Data, Removal Failed, [579], [454832],1.0.3230
PUP.Optional.Conduit, C:\USERS\KJORD_000\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\Secure Preferences, Removal Failed, [579], [454832],1.0.3230
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)
 
 
ADW CLEANER- 
# AdwCleaner 7.0.4.0 - Logfile created on Sat Nov 11 17:45:38 2017
# Updated on 2017/27/10 by Malwarebytes 
# Database: 11-10-2017.1
# Running on Windows 10 Home (X64)
# Mode: scan
 
***** [ Services ] *****
 
No malicious services found.
 
***** [ Folders ] *****
 
No malicious folders found.
 
***** [ Files ] *****
 
No malicious files found.
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
No malicious tasks found.
 
***** [ Registry ] *****
 
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\TypeLib\{B944FF5E-EC87-4E1E-8C49-2FF3BC573997}
PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-890854813-854748282-2031434319-1001\Software\Classes\TypeLib\{B944FF5E-EC87-4E1E-8C49-2FF3BC573997}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{08613A51-6E3E-43CC-9ECF-DD58B5837341}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{153EDC41-A2CC-4BEB-9EC8-008242389E50}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{188028B8-D91D-4BE2-BABA-68E32BDE4420}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{28E74F15-18C2-465E-B545-6CC738121C68}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{2BF6042B-B9B1-46D9-A3F8-9C987FADD4C6}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{40A222E2-93B1-45F9-9B07-0D1160A31A6C}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{6325A84C-E746-4007-A9C5-E4C1A50ED61F}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{9BCA87A0-5B8F-4500-A5AF-EA1279714FDF}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{BB17DE65-B548-48C2-AC73-1FD1996C7261}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{C77D3EEF-FDCA-4D37-B0D2-5FF650E07825}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{EA70EB31-CBAD-4862-AFDA-DCFCC32722ED}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{EC9100F8-5918-4F1B-9CC1-4D34A64E0FE0}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{F1A1ABE3-F454-4DD9-B520-01F2EEC5F0DD}
PUP.Optional.Legacy, [Value] - HKU\S-1-5-21-890854813-854748282-2031434319-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run | ShopAtHomeUpdater
PUP.Optional.Legacy, [Value] - HKU\S-1-5-21-890854813-854748282-2031434319-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112017092646826\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run | ShopAtHomeUpdater
PUP.Optional.Legacy, [Value] - HKU\S-1-5-21-890854813-854748282-2031434319-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112017101525176\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run | ShopAtHomeUpdater
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\AppID\ShopAtHomeHelper.EXE
 
 
***** [ Firefox (and derivatives) ] *****
 
PUP.Optional.Legacy, Plugin found: Avira SafeSearch Plus - Avira
 
 
***** [ Chromium (and derivatives) ] *****
 
PUP.Optional.Legacy, Plugin found: Alexa Traffic Rank - 
PUP.Optional.Legacy, Plugin found: Alexa Traffic Rank - 
PUP.Optional.Legacy, Plugin found: Instapaper - 
PUP.Optional.Legacy, Plugin found: Instapaper - 
PUP.Optional.Legacy, Plugin found: Avira SafeSearch Plus - 
PUP.Optional.Legacy, SearchProvider found: Conduit Search - conduit.search
PUP.Optional.Legacy, SearchProvider found: Conduit Search - conduit.search
PUP.Optional.Legacy, Startpage found: http://www.msn.com/?pc=U142&ocid=U142DHP
PUP.Optional.Legacy, Startpage found: http://www.msn.com/?pc=U142&ocid=U142DHP
PUP.Optional.Legacy, Startpage found: http://www.msn.com/?pc=U142&ocid=U142DHP
PUP.Optional.Legacy, Startpage found: http://www.msn.com/?pc=U142&ocid=U142DHP
 
/!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271 
 
 
*************************
 
 
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########

 

 

JRT TOOL-

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Home x64 
Ran by Kimberly (Administrator) on Sat 11/11/2017 at 13:35:59.00
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 0 
 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 11/11/2017 at 13:38:13.15
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
STARTUP AND SCHEDULED TASKS-
Yes HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
No HKCU:Run DellSystemDetect Dell C:\Users\Kimberly\AppData\Local\Apps\2.0\6X1T6EK6.8G3\5TX9EW41.2A1\dell..tion_831211ca63b981c5_0008.0005_9a48d74816d64e41\DellSystemDetect.exe 4zZn5oeQk9WMM5ZBt7fsYA==
Yes HKCU:Run OneDrive Microsoft Corporation "C:\Users\Kimberly\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
No HKCU:Run RoboForm Siber Systems "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
No HKCU:Run Userfeel Userfeel "C:\Users\Kimberly\AppData\Local\Userfeel\update.exe" --processStart "Userfeel.exe" --process-start-args "--hidden"
Yes HKCU:RunOnce Application Restart #4 Google Inc. C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  --flag-switches-begin --flag-switches-end --restore-last-session -- https://store.kaspersky.com/store/kasperus/en_US/buy/ThemeID.38735700/productID.2740217500/pgm.4852390800/OfferID.59651165901/affiliate.DREmail_NAM_Cart_Retention_May17_CTR_v3?CAMPAIGN=EMA1674434
No HKLM:Run Adobe Creative Cloud Adobe Systems Incorporated "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
Yes HKLM:Run AdobeAAMUpdater-1.0 Adobe Systems Incorporated "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
No HKLM:Run Avira System Speedup User Starter Avira Operations GmbH & Co. KG "C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe"
No HKLM:Run Dropbox Dropbox, Inc. "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
No HKLM:Run EKIJ5000StatusMonitor Eastman Kodak Company C:\WINDOWS\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe
Yes HKLM:Run IAStorIcon Intel Corporation "C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" 60
No HKLM:Run Logitech Download Assistant Microsoft Corporation C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
Yes HKLM:Run RtHDVBg_MAXX6 Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX6
Yes HKLM:Run RTHDVCPL Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
Yes HKLM:Run SecurityHealth Microsoft Corporation %ProgramFiles%\Windows Defender\MSASCuiL.exe
Yes HKLM:Run SynTPEnh Synaptics Incorporated %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
No Startup User EvernoteClipper.lnk Evernote Corp., 305 Walnut Street, Redwood City, CA 94063 C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
No Startup User Send to OneNote.lnk Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
No Startup User zSpeedup.lnk C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe
 
 
 
Scheduled Tasks-
Yes Task AviraScoutUpdateTaskMachineCore Avira Operations GmbH & Co. KG C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe /c
Yes Task AviraScoutUpdateTaskMachineUA Avira Operations GmbH & Co. KG C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe /ua /installsource scheduler
Yes Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
Yes Task CreateExplorerShellUnelevatedTask Microsoft Corporation C:\WINDOWS\explorer.exe /NOUACCHECK
Yes Task DropboxUpdateTaskMachineCore Dropbox, Inc. C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
Yes Task DropboxUpdateTaskMachineUA Dropbox, Inc. C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
Yes Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
Yes Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
Yes Task OneDrive Standalone Update Task-S-1-5-21-890854813-854748282-2031434319-1001 Microsoft Corporation %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Yes Task PCDDataUploadTask "uaclauncher.exe" -lloc dataupload --ignoresecondarysplash --runsilently --skipidlewait
Yes Task Run RoboForm TaskBar Icon Siber Systems C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe /autoupdate=8.4.1.1
Yes Task SystemToolsDailyTest "uaclauncher.exe" -silentenumeration -st SystemToolsDailyTest --ignoresecondarysplash --runsilently
 
 
INSTALLED PROGRAMS-
I cannot create a list either through CC Cleaner Uninstall Method, or via directly accessing the the Installed Programs through the Control Panel.  Not sure what to do about that.  Also, when I tried to grab a copy of my installed programs, I uninstalled the program "Userfeel" (a survey site).  I will check the above logs to see if any of the legacy files are attached to it.  If they are, I will re-run and check on them to see if they have dropped off the logs.  
 
One thing, I have not yet deleted the 39 legacy items picked up on the ADW Scan.  I honestly do not know what to do with them.  I attempted to quarantine them, but was not provided with that option. This is my first run in with them....after being online as an "early adopter" way, way back in the very beginning, when we didn't even know to call it an "internet"!! Go figure!  If they can be deleted in one shot, I will do that right away.   
 
I really appreciate you guys being here!  What a blessing!!  I can't thank you all enough.  I've been in and around this site for a long time, I've just never had to post anything for myself before.  I've been pretty lucky!  Maybe it's just old age.....
 
Thanks,
Kim J

 



BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • Moderator
  • 13,518 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:14 PM

Posted 11 November 2017 - 04:35 PM

Rerun AdwCleaner and click on Clean when the scan finishes. Allow it to delete all that it found.

 

You should be able to post the list of installed programs by following instructions below.

Open CCleaner and click on Tools. Choose Uninstall. On that page you will see a list of programs installed on your computer and at the bottom right of that page you

will see a button when clicked will allow you to Copy and Paste that list in your next post. Please do that.

 

I am reviewing the other two lists and will soon offer suggestions.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#3 buddy215

buddy215

  • Moderator
  • 13,518 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:14 PM

Posted 11 November 2017 - 04:56 PM

Suggest Disabling these items: Use CCleaner by clicking on each item and choosing Disable on the right.

Yes HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR

Yes HKCU:Run OneDrive Microsoft Corporation "C:\Users\Kimberly\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background

Yes HKCU:RunOnce Application Restart #4 Google Inc. C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  --flag-switches-begin --flag-switches-end --restore-last-session -- https://store.kaspersky.com/store/kasperus/en_US/buy/ThemeID.38735700/productID.2740217500/pgm.4852390800/OfferID.59651165901/affiliate.DREmail_NAM_Cart_Retention_May17_CTR_v3?CAMPAIGN=EMA1674434

Yes HKLM:Run AdobeAAMUpdater-1.0 Adobe Systems Incorporated "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

 

Disable these Tasks: Use CCleaner by clicking on each item and choosing Disable on the right.

Yes Task AviraScoutUpdateTaskMachineCore Avira Operations GmbH & Co. KG C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe /c

Yes Task AviraScoutUpdateTaskMachineUA Avira Operations GmbH & Co. KG C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe /ua /installsource scheduler
Yes Task CreateExplorerShellUnelevatedTask Microsoft Corporation C:\WINDOWS\explorer.exe /NOUACCHECK
Yes Task DropboxUpdateTaskMachineCore Dropbox, Inc. C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
Yes Task DropboxUpdateTaskMachineUA Dropbox, Inc. C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
Yes Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
Yes Task OneDrive Standalone Update Task-S-1-5-21-890854813-854748282-2031434319-1001 Microsoft Corporation %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Yes Task PCDDataUploadTask "uaclauncher.exe" -lloc dataupload --ignoresecondarysplash --runsilently --skipidlewait
Yes Task Run RoboForm TaskBar Icon Siber Systems C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe /autoupdate=8.4.1.1
Yes Task SystemToolsDailyTest "uaclauncher.exe" -silentenumeration -st SystemToolsDailyTest --ignoresecondarysplash --runsilently
 
Run a new scan using Malwarebytes after completing AdwCleaner scan and the above. Please post the results.

Edited by buddy215, 11 November 2017 - 04:56 PM.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#4 morrigans1

morrigans1
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:14 PM

Posted 11 November 2017 - 05:22 PM

Thank you!

I actually am familiar with the instructions for grabbing the list of installed programs through CC cleaner; however, when I went to do that I did not have the option in the lower right corner (or anywhere else).

I then went to my desktop, opened up the programs list, right clicked CC Cleaner, and got the "uninstall" option.  What that did was take me straight to the control panel list of programs, and I was at a dead end.  I don't know if there is another place I can get it from.  I tried to Ctrl A the list and copy it, that was a no-go.  I've never had any issues like this.

Also, I installed a new CC Cleaner.  Mine was a carryover from an older comp.

 

Thanks,

Kim



#5 buddy215

buddy215

  • Moderator
  • 13,518 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:14 PM

Posted 11 November 2017 - 05:27 PM

I've no idea why you can't see that button. Go ahead with the other instructions.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#6 morrigans1

morrigans1
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:14 PM

Posted 11 November 2017 - 05:40 PM

I'm on my 2nd ADW Scan....no change after cleaning.  One more time to reboot, then I will send over.

Thanks!



#7 morrigans1

morrigans1
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:14 PM

Posted 11 November 2017 - 05:50 PM

Ok, Here you go...

# AdwCleaner 7.0.4.0 - Logfile created on Sat Nov 11 22:41:36 2017
# Updated on 2017/27/10 by Malwarebytes 
# Database: 11-10-2017.1
# Running on Windows 10 Home (X64)
# Mode: scan
 
***** [ Services ] *****
 
No malicious services found.
 
***** [ Folders ] *****
 
No malicious folders found.
 
***** [ Files ] *****
 
No malicious files found.
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
No malicious tasks found.
 
***** [ Registry ] *****
 
No malicious registry entries found.
 
***** [ Firefox (and derivatives) ] *****
 
PUP.Optional.Legacy, Plugin found: Avira SafeSearch Plus - Avira
 
 
***** [ Chromium (and derivatives) ] *****
 
PUP.Optional.Legacy, Plugin found: Alexa Traffic Rank - 
PUP.Optional.Legacy, Plugin found: Alexa Traffic Rank - 
PUP.Optional.Legacy, Plugin found: Instapaper - 
PUP.Optional.Legacy, Plugin found: Instapaper - 
PUP.Optional.Legacy, SearchProvider found: Conduit Search - conduit.search
PUP.Optional.Legacy, SearchProvider found: Conduit Search - conduit.search
PUP.Optional.Legacy, Startpage found: http://www.msn.com/?pc=U142&ocid=U142DHP
PUP.Optional.Legacy, Startpage found: https://encrypted.google.com
PUP.Optional.Legacy, Startpage found: http://www.msn.com/?pc=U142&ocid=U142DHP
PUP.Optional.Legacy, Startpage found: https://encrypted.google.com
 
/!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271 
 
 
*************************
 
C:/AdwCleaner/AdwCleaner[C0].txt - [21533 B] - [2017/11/11 22:22:56]
C:/AdwCleaner/AdwCleaner[C1].txt - [8346 B] - [2017/11/11 22:32:52]
C:/AdwCleaner/AdwCleaner[S0].txt - [5438 B] - [2017/11/11 17:45:38]
C:/AdwCleaner/AdwCleaner[S1].txt - [2604 B] - [2017/11/11 22:32:10]
 
 
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt ##########


#8 morrigans1

morrigans1
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:14 PM

Posted 11 November 2017 - 05:52 PM

HA....Got the startup programs

Yes HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
No HKCU:Run DellSystemDetect Dell C:\Users\Kimberly\AppData\Local\Apps\2.0\6X1T6EK6.8G3\5TX9EW41.2A1\dell..tion_831211ca63b981c5_0008.0005_9a48d74816d64e41\DellSystemDetect.exe 4zZn5oeQk9WMM5ZBt7fsYA==
Yes HKCU:Run OneDrive Microsoft Corporation "C:\Users\Kimberly\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
No HKCU:Run RoboForm Siber Systems "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
No HKCU:Run Userfeel Userfeel "C:\Users\Kimberly\AppData\Local\Userfeel\update.exe" --processStart "Userfeel.exe" --process-start-args "--hidden"
Yes HKCU:RunOnce Application Restart #4 Google Inc. C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  --flag-switches-begin --flag-switches-end --restore-last-session -- https://store.kaspersky.com/store/kasperus/en_US/buy/ThemeID.38735700/productID.2740217500/pgm.4852390800/OfferID.59651165901/affiliate.DREmail_NAM_Cart_Retention_May17_CTR_v3?CAMPAIGN=EMA1674434
No HKLM:Run Adobe Creative Cloud Adobe Systems Incorporated "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
Yes HKLM:Run AdobeAAMUpdater-1.0 Adobe Systems Incorporated "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
No HKLM:Run Avira System Speedup User Starter Avira Operations GmbH & Co. KG "C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe"
No HKLM:Run Dropbox Dropbox, Inc. "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
No HKLM:Run EKIJ5000StatusMonitor Eastman Kodak Company C:\WINDOWS\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe
Yes HKLM:Run IAStorIcon Intel Corporation "C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" 60
No HKLM:Run Logitech Download Assistant Microsoft Corporation C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
Yes HKLM:Run RtHDVBg_MAXX6 Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX6
Yes HKLM:Run RTHDVCPL Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
Yes HKLM:Run SecurityHealth Microsoft Corporation %ProgramFiles%\Windows Defender\MSASCuiL.exe
Yes HKLM:Run SynTPEnh Synaptics Incorporated %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
No Startup User EvernoteClipper.lnk Evernote Corp., 305 Walnut Street, Redwood City, CA 94063 C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
No Startup User Send to OneNote.lnk Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
No Startup User zSpeedup.lnk C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe


#9 morrigans1

morrigans1
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:14 PM

Posted 11 November 2017 - 05:55 PM

OH, I'm sorry, Hold on...You needed the programs 

 

3D Builder Microsoft Corporation 10/28/2017 15.0.2911.0
Adobe Creative Cloud Adobe Systems Incorporated 8/28/2017 480 MB 3.9.1.335
Adobe Photoshop Express Adobe Systems Incorporated 9/25/2017 1.3.5.74
Adobe Reader XI (11.0.22) Adobe Systems Incorporated 8/23/2017 369 MB 11.0.22
Adobe Shockwave Player 12.2 Adobe Systems, Inc. 8/29/2017 35.1 MB 12.2.9.199
Adventure of Stars Lili Games 10/19/2016 1.1.0.5
Alarms & Clock Microsoft Corporation 10/6/2017 10.1709.2621.0
Amazon Kindle Amazon 8/28/2017 1.20.1.47037
App Installer Microsoft Corporation 2/19/2017 1.0.10332.0
Avira Avira Operations GmbH & Co. KG 10/30/2017 18.3 MB 1.2.98.37213
Avira Antivirus Avira Operations GmbH & Co. KG 11/11/2017 761 MB 15.0.32.12
Avira Phantom VPN Avira Operations GmbH & Co. KG 10/28/2017 18.8 MB 2.11.3.29834
Avira Scout Avira Operations GmbH & Co. KG 5/18/2017 300 MB 17.6.3071.2851
Avira Software Updater Avira Operations GmbH & Co. KG 11/8/2017 174 MB 2.0.4.724
Avira System Speedup Avira Operations GmbH & Co. KG 10/7/2017 42.6 MB 4.2.1.6365
Calculator Microsoft Corporation 10/9/2017 10.1709.2703.0
Camera Microsoft Corporation 10/27/2017 2017.921.10.0
Canon IJ Network Scanner Selector EX2 Canon Inc. 8/28/2017 4.09 MB 2.0.0.19
Canon IJ Scan Utility Canon Inc. 8/28/2017 75.6 MB 1.3.1.4
Canon Inkjet Print Utility Canon Inc. 7/25/2017 2.6.0.5
Canon Inkjet Printer/Scanner/Fax Extended Survey Program Canon Inc. 8/28/2017 5.3.1
Canon MG3000 series MP Drivers Canon Inc. 8/28/2017 1.01
Canon MG3000 series User Registration ‭Canon Inc. 8/28/2017
CCleaner Piriform 11/11/2017 22.3 MB 5.36
Color Splash Effects Photo Editor Queenloft 11/8/2016 1.3.0.1
Community Showcase Natural Landscapes 3 Microsoft Corporation 10/11/2017 1.0.0.0
Dell Digital Delivery Dell Products, LP 9/9/2016 6.67 MB 3.1.1002.0
Dell SupportAssist Dell 11/11/2017 117 MB 2.0.6875.668
Dell SupportAssistAgent Dell 9/30/2017 319 MB 2.0.3.10
Dell System Detect Dell 8/28/2017 8.5.0.4
Dropbox Dropbox, Inc. 11/8/2017 199 MB 39.3.48
Evernote Evernote 9/15/2017 6.7.5741.0
Evernote v. 6.4.2 Evernote Corp. 11/9/2016 211 MB 6.4.2.3788
Facebook Facebook Inc 10/16/2017 140.1135.47783.0
Feedback Hub Microsoft Corporation 10/19/2017 1.1708.2831.0
Get Office Microsoft Corporation 7/22/2017 17.8414.5925.0
Google Chrome Google Inc. 9/9/2016 353 MB 62.0.3202.89
GoToAssist Corporate Citrix Systems, Inc. 5/24/2017 46.1 MB 11.9.0.1230
Groove Music Microsoft Corporation 11/11/2017 10.17084.21621.0
iHeartRadio iHeartMedia. 5/18/2017 6.0.31.0
Intel® Management Engine Components Intel Corporation 9/9/2016 11.0.0.1158
Intel® Processor Graphics Intel Corporation 2/28/2017 20.19.15.4531
Intel® Rapid Storage Technology Intel Corporation 9/9/2016 14.8.1.1043
Intel® PROSet/Wireless Software Intel Corporation 10/5/2017 241 MB 19.60.0
Intel® Security Assist Intel Corporation 9/9/2016 3.45 MB 1.0.0.532
Kaspersky Secure Connection Kaspersky Lab 10/16/2017 24.8 MB 17.0.0.611
Kaspersky Total Security Kaspersky Lab 10/16/2017 98.4 MB 18.0.0.405
Mail and Calendar Microsoft Corporation 11/11/2017 17.8700.40645.0
Malwarebytes version 3.2.2.2029 Malwarebytes 10/11/2017 212 MB 3.2.2.2029
Maps Microsoft Corporation 10/18/2017 5.1708.2764.0
Messaging Microsoft Corporation 8/28/2017 3.26.24002.0
Microsoft Office 365 - en-us Microsoft Corporation 11/10/2017 1.00 GB 16.0.8625.2121
Microsoft OneDrive Microsoft Corporation 11/4/2017 100 MB 17.3.7076.1026
Microsoft Silverlight Microsoft Corporation 6/16/2017 101 MB 5.1.50907.0
Microsoft Solitaire Collection Microsoft Studios 11/1/2017 3.18.10182.0
Microsoft Sticky Notes Microsoft Corporation 5/18/2017 1.8.0.0
Microsoft Store Microsoft Corporation 11/10/2017 11710.1001.27.0
Microsoft Support and Recovery Assistant for Office 365 Microsoft Corporation 8/28/2017 16.0.1630.0
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 10/12/2016 4.92 MB 8.0.56336
Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 10/12/2016 10.2 MB 8.0.61000
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 10/12/2016 1.63 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 10/12/2016 830 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 10/12/2016 3.14 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 10/12/2016 2.49 MB 9.0.30729.6161
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 Microsoft Corporation 10/12/2016 18.0 MB 10.0.40219
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 Microsoft Corporation 10/12/2016 16.6 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Corporation 8/28/2017 20.5 MB 11.0.61030.0
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 8/28/2017 17.3 MB 11.0.61030.0
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 Microsoft Corporation 8/28/2017 20.5 MB 12.0.30501.0
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 Microsoft Corporation 8/28/2017 17.1 MB 12.0.30501.0
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 Microsoft Corporation 8/28/2017 22.4 MB 14.0.23918.0
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 Microsoft Corporation 8/28/2017 18.7 MB 14.0.23918.0
Mixed Reality Viewer Microsoft Corporation 9/28/2017 2.1709.8012.0
Movies & TV Microsoft Corporation 10/18/2017 10.17092.13511.0
Mozilla Firefox 46.0 (x64 en-US) Mozilla 8/28/2017 100 MB 46.0
Mozilla Maintenance Service Mozilla 8/28/2017 251 KB 46.0
Netflix Netflix, Inc. 11/10/2017 6.41.202.0
OneNote Microsoft Corporation 11/1/2017 17.8625.21151.0
Paid Wi-Fi & Cellular Microsoft Corporation 9/20/2017 2.1709.2484.0
Paint 3D Microsoft Corporation 11/11/2017 3.1710.30027.0
Pandora Pandora Media Inc 9/20/2017 11.5.4.0
People Microsoft Corporation 11/1/2017 10.2.2791.0
Phone Microsoft Corporation 9/9/2016 1.10.15000.0
Photo Splash Editor Cidade 9/14/2016 1.1.0.0
Photos Microsoft Corporation 10/5/2017 2017.39081.15820.0
PicsArt PicsArt Inc. 11/11/2017 5.11.1.0
Pin It Button Pinterest 9/14/2016 1.39.5.0
Readiy Nishro Tech LLC. 10/19/2016 33.1.0.0
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 8/29/2017 40.9 MB 6.0.1.7737
RoboForm 8-4-3-3 (All Users) Siber Systems 10/23/2017 20.0 MB 8-4-3-3
Skype Skype 11/7/2017 12.8.480.0
Store Experience Host Microsoft Corporation 11/10/2017 11710.1710.30001.0
SupportAssist Driver Update Dell Inc. 10/7/2017 1.3.0.0
Text On Photos Queenloft 9/14/2016 1.1.0.0
The Weather Channel The Weather Channel. 5/18/2017 2016.614.87.0
Tips Microsoft Corporation 11/1/2017 5.12.2691.0
Twitter Twitter Inc. 7/6/2017 5.8.1.0
Voice Recorder Microsoft Corporation 10/9/2017 10.1709.2703.0
Wallet Microsoft Corporation 8/28/2017 1.0.16328.0
Weather Microsoft Corporation 8/31/2017 4.21.2212.0
Windows 10 Update and Privacy Settings Microsoft Corporation 6/29/2017 2.10 MB 1.0.14.0
World Numerology Portal World Numerology 5/26/2017 109 MB 0.0.0.1
XAML UI Controls Agustin Dana 5/27/2017 2.3.1.0
Xbox Microsoft Corporation 11/3/2017 33.34.30002.0
Xbox Game bar Microsoft Corporation 11/7/2017 1.22.30001.0
Xbox Game Speech Window Microsoft Corporation 8/28/2017 1.14.2002.0
Xbox Identity Provider Microsoft Corporation 7/12/2017 11.29.23003.0

I apologize for that. Hope that helped.

Kim 



#10 morrigans1

morrigans1
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:14 PM

Posted 11 November 2017 - 06:11 PM

Hi,

Here is the most recent ADW scan after I disabled the list of items and tasks listed above.

# AdwCleaner 7.0.4.0 - Logfile created on Sat Nov 11 23:10:01 2017
# Updated on 2017/27/10 by Malwarebytes 
# Database: 11-10-2017.1
# Running on Windows 10 Home (X64)
# Mode: scan
 
***** [ Services ] *****
 
No malicious services found.
 
***** [ Folders ] *****
 
No malicious folders found.
 
***** [ Files ] *****
 
No malicious files found.
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
No malicious tasks found.
 
***** [ Registry ] *****
 
No malicious registry entries found.
 
***** [ Firefox (and derivatives) ] *****
 
PUP.Optional.Legacy, Plugin found: Avira SafeSearch Plus - Avira
 
 
***** [ Chromium (and derivatives) ] *****
 
PUP.Optional.Legacy, Plugin found: Alexa Traffic Rank - 
PUP.Optional.Legacy, Plugin found: Alexa Traffic Rank - 
PUP.Optional.Legacy, Plugin found: Instapaper - 
PUP.Optional.Legacy, Plugin found: Instapaper - 
PUP.Optional.Legacy, SearchProvider found: Conduit Search - conduit.search
PUP.Optional.Legacy, SearchProvider found: Conduit Search - conduit.search
PUP.Optional.Legacy, Startpage found: http://www.msn.com/?pc=U142&ocid=U142DHP
PUP.Optional.Legacy, Startpage found: https://encrypted.google.com
PUP.Optional.Legacy, Startpage found: http://www.msn.com/?pc=U142&ocid=U142DHP
PUP.Optional.Legacy, Startpage found: https://encrypted.google.com
 
/!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271 
 
 
*************************
 
C:/AdwCleaner/AdwCleaner[C0].txt - [21533 B] - [2017/11/11 22:22:56]
C:/AdwCleaner/AdwCleaner[C1].txt - [8346 B] - [2017/11/11 22:32:52]
C:/AdwCleaner/AdwCleaner[C2].txt - [8484 B] - [2017/11/11 22:42:24]
C:/AdwCleaner/AdwCleaner[S0].txt - [5438 B] - [2017/11/11 17:45:38]
C:/AdwCleaner/AdwCleaner[S1].txt - [2604 B] - [2017/11/11 22:32:10]
C:/AdwCleaner/AdwCleaner[S2].txt - [2742 B] - [2017/11/11 22:41:36]
 
 
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt ##########


#11 buddy215

buddy215

  • Moderator
  • 13,518 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:14 PM

Posted 11 November 2017 - 07:13 PM

Rerun AdwCleaner and be sure to click on Clean when scan finishes.

 

You missed some items to Disable. I'm in no hurry...I'm enjoying the football games.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#12 buddy215

buddy215

  • Moderator
  • 13,518 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:14 PM

Posted 11 November 2017 - 07:28 PM

Uninstall or update Adobe Reader XI (11.0.22) Adobe Systems Incorporated 8/23/2017 369 MB 11.0.22

Uninstall These Programs:

Avira Scout Avira Operations GmbH & Co. KG 5/18/2017 300 MB 17.6.3071.2851

Avira Software Updater Avira Operations GmbH & Co. KG 11/8/2017 174 MB 2.0.4.724

Avira System Speedup Avira Operations GmbH & Co. KG 10/7/2017 42.6 MB 4.2.1.6365

Kaspersky Secure Connection Kaspersky Lab 10/16/2017 24.8 MB 17.0.0.611(Uninstall if you don't intend to purchase...you have Avira...keep only one antivirus)
Kaspersky Total Security Kaspersky Lab 10/16/2017 98.4 MB 18.0.0.405 (Uninstall if you don't intend to purchase...you have Avira...keep only one antivirus)

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#13 morrigans1

morrigans1
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:14 PM

Posted 11 November 2017 - 08:03 PM

Thanks!  I purchased Kaspersky, so I will delete Avira.  

Not too sure how I overlooked the others.  

 

Appreciate your patience....



#14 buddy215

buddy215

  • Moderator
  • 13,518 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:14 PM

Posted 11 November 2017 - 08:22 PM

Instructions for uninstalling Avira from Windows 10...hope its not too late.

 

Note
To be able to uninstall Avira completely together with the Avira Management Panel, it is necessary to first uninstall all other installed Avira programs including the Antivirus.

 

 

  1. Click the Windows icon in the lower left hand corner of your screen → Settings → System → Apps & features .
  2. Click first on "Avira Antivirus" and subsequently on Uninstall.
  3. Confirm the following product uninstall notification with Uninstall.
  4. Confirm the request of the “User Account Control” with Yes.
  5. Confirm the request of the Avira setup with Yes.
  6. The Avira Setup will take some minutes to uninstall the product.
  7. Confirm the notification to restart your system with Yes.
  8. After the reboot of your PC the Avira product is completely removed.

If the conventional removal is not feasible, please read the following article:
Instructions for manual uninstallation.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#15 morrigans1

morrigans1
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:14 PM

Posted 11 November 2017 - 08:47 PM

I'm confused....

Did you want me to disable all of these below :

No Extension Add to Evernote 5 C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\AddNote.html
No Extension Fill Forms Siber Systems Inc. C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
No Extension Fill Forms Siber Systems Inc. C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
Yes Extension Lync Click to Call Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
No Extension OneNote Linked Notes Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
No Extension OneNote Linked Notes Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
No Extension Save Siber Systems Inc. C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
No Extension Save Siber Systems Inc. C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
No Extension Send to OneNote Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
No Extension Send to OneNote Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll
Yes Extension Show Toolbar Siber Systems Inc. C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
Yes Extension Show Toolbar Siber Systems Inc. C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
No Helper Evernote extension Evernote Corp., 305 Walnut Street, Redwood City, CA 94063 C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
Yes Helper Kaspersky Protection C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 18.0.0\x64\IEExt\ie_plugin.dll
Yes Helper Lync Browser Helper Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
Yes Helper RoboForm Toolbar Helper Siber Systems Inc. C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
Yes Helper RoboForm Toolbar Helper Siber Systems Inc. C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
No Toolbar Kaspersky Protection Toolbar C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 18.0.0\x64\IEExt\ie_plugin.dll
No Toolbar RoboForm Toolbar Siber Systems Inc. C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
No Toolbar RoboForm Toolbar Siber Systems Inc. C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users