Problems With Browsers

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Zoreiana, Dec 19, 2015.

  1. Zoreiana

    Zoreiana Private E-2

    About a week ago I have opened a couple of .exe files which I should NOT have done. This has resulted in my Waterfox browser continually crashing. I also use Chrome, and I got a message that some add-on or other was not permitted to run. Chrome does not crash, but it runs much slower than usual.

    In a desperate and amateur attempt to fix things, I created more problems. I downloaded a number of antivirus programs (Webroot, Spybot, Avira, AVG, and finally settled on Bitdefender). I was lax at removing previous one before loading the next one, so I have likely had two or three of them running simultaneously for a few days. This "apparently" did not make computer performance worse, but it did not make it better. I have also uninstalled and reinstalled Waterfox several times, and attempted to eradicate the Firefox folder off the computer altogether, without success.

    I normally use Malwarebytes and CCleaner, so I ran those many times as well. On the first run Malwarebytes identified about 500 threats, but after that was returning clean logs. The browser performance did not improve. I also unfortunately tried to fix registry errors with CCleaner, and lost a bunch of desktop icons. I no longer have ones for volume and battery charge.

    I have followed the procedure to remove malware described here, but again I made some errors. I did not use the suggested settings with Hitman, and likely removed a bunch of useful stuff.

    Before doing the scans, I had a pirated copy of Microsoft Office, which I tried to unianstall and delete but again failed.

    I have uploaded the scan logs. Hope to hear from you soon.

    Thank you!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    
    :Files
    C:\WINDOWS\system32\tasks\AutoKMS
    C:\WINDOWS\system32\tasks\Nuezgik
    C:\WINDOWS\system32\tasks\Xsoeehma
    C:\ProgramData\Xsoeehma
    C:\ProgramData\9a3622d0-1977-0
    C:\ProgramData\9a3622d0-7d01-1
    C:\ProgramData\Avg
    C:\ProgramData\Avira
    C:\ProgramData\cbce07f0-11c7-0
    C:\ProgramData\cbce07f0-2e25-1
    C:\ProgramData\Panda Security
    C:\ProgramData\Spybot - Search & Destroy
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Waterfox.lnk
    C:\Program Files (x86)\AVG
    C:\Program Files (x86)\Avira
    C:\Program Files (x86)\Spybot - Search & Destroy 2
    C:\WINDOWS\TEMP\*.*
    C:\Users\Admin\AppData\Local\Temp\*.*
    
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "SpybotPostWindows10UpgradeReInstall"=-
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "AvgUi"=-
    
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "AvgUi"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, Win7, 8 or 10, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. Zoreiana

    Zoreiana Private E-2

    Thank you for the very fast reply, much appreciated!

    1. I ran everything as instructed, EXCEPT I was not 100% sure how to disable Bitdefender. I turned autopilot off, do not know if that was sufficient.
    2. Waterfox performs better. It took much longer and more intensive use to crash. I normally run Forge of Empires browser game on it. Also, when it crashed, it was able to close itself as opposed to me having to close it with task manager.
    3. Some odd system quirks are happening. Display brightness adjusts itself to maximum setting randomly, and sometimes I can not adjust it from dektop (the display settings window crashes), but have to go to Control Panel.
    4. I am still missing a number of buttons that normally appear on startup, such as "eject disk", system power, system volume.
     

    Attached Files:

  4. Zoreiana

    Zoreiana Private E-2

    Forgot about an important symptom. I am a regular CCleaner user because Forge of Empires does fill browser caches fairly quickly. It is normal for me to clean about 400-500 megs every two days or so. Ever since the problem started, the caches would fill much faster. After three-four hours of internet use I would have more than a gig of browser caches of whichever browser I would use, either Waterfox, or Chrome. Waterfox browser would fill quite a bit faster than Chrome browser.

    Right now it appears that this problem has been greatly reduced. I have used Waterfox intensely for two hours and only had about 150 megabytes of cache files.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually none of the problems that you are mentioning really sound like malware. They sound more like software conflicts or issues that often occur from performing registry cleaning or running system performance tweakers. However there are a few things that did not get removed with the last fix so let's continue and we will run a couple other tools too just to be on the safe side. Also we will run a program named Windows Repair to see if it helps.

    First see if you can find and delete the below folders which failed to delete. Let me know your results.

    C:\WINDOWS\system32\tasks\AutoKMS
    C:\WINDOWS\system32\tasks\Nuezgik
    C:\WINDOWS\system32\tasks\Safer-Networking
    C:\WINDOWS\system32\tasks\Xsoeehma
    C:\ProgramData\Xsoeehma

    Now run the below no matter what happens with the above.

    Please download the latest version of FRST the below link.

    Farbar Recovery Scan Tool and save it to your Desktop.

    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the + Repairs tab.
    • Then click the + Open Repairs button down on the bottom right.
    • This will automatically begin a registry backup, so wait for it to complete and when it finishes, you will see a list of many possible different repairs and they are all selected by default. At the bottom of this form there is a not so obvious Unselect All Repairs check box which is to the right of a check box with a green check mark in it. Please click the Unselect All Repairs box. The green check mark box is to Select All Repairs. The ony way you see what these boxes are is when your mouse hovers over them.
    • Now select the following repair options ( the numbers at the begin are the current repair numbers but this is subject to change.)
      • 01 - Reset Registry Permissions
      • 02 - Reset File Permissions
      • 03 - Reset Service Permissions
      • 04 - Register System Files
      • 05 - Repair WMI
      • 10 - Remove Policies Set By Infections
      • 13 - Network
      • 14 - Repair Proxy Settings
      • 15 - Repair Windows Updates
      • 21 - Repair MSI (Windows Installer)
      • 23 - Repair File Associations (12 )
      • 26 - Restore Important Windows Services
      • 27 - Set Windows Services To Default Startup
    • Now on the right side under the When Repairs Complete title, check the box for Restart/Shutdown System and then make sure the Restart System radio button is enabled not the Shutdown System button.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start Repairs button at the lower right.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished. If it does not then reboot it yourself.
     
  6. Zoreiana

    Zoreiana Private E-2

    Thanks again!
    These files/folders were deleted without issues:

    C:\WINDOWS\system32\tasks\AutoKMS
    C:\WINDOWS\system32\tasks\Nuezgik
    C:\WINDOWS\system32\tasks\Safer-Networking
    C:\WINDOWS\system32\tasks\Xsoeehma

    This file (or folder ) was not at specified location :C:\ProgramData\Xsoeehma.

    Farbar logs are attached.

    I ran Windows repair till the end. I have noticed there was an option to repair icons (I did not choose it as I was not instructed to). Some of my system icons are still missing (I do not have system power and volume button on the right side of taskbar).

    Also, after Windows Repair the computer took very long time to boot, which might be normal. I will be testing browsers next day or so.

    Thanks again!
     

    Attached Files:

  7. Zoreiana

    Zoreiana Private E-2

    Waterfox is still crashing. Basically the window blinks once in a while as I work, then eventually the "Not responding" message shows up on top, and it crashes. I do not think it changed from before I started this whole process.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can try having Windows Repair fix your icons but not sure that it will help.

    Again I don't think your problems are due to malware based on all previous logs and your current logs. More likely due to system errors or software conflicts etc with Waterfox.
    But you do still have a bunch of left overs from all the antivirus programs that you installed ( bad idea ) and some other junk too. So let's try to fix this stuff up. I may be sending you to the Software Forum soon for your problems with Waterfox.


    Download this attached fixlist.txt file found at the bottom of this message and save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Please attach the above two log first before you continue with the below.

    Also at this point, I want to double check the status of things we tried to remove above by having you run another scan with FRST like in my last message and attach the new FRST.txt log.
     

    Attached Files:

  9. Zoreiana

    Zoreiana Private E-2

    Attaching the logs. I have a question. MGtools are installed directly in C:\, but the logs for some reason pop up on the desktop. Why is that?
     

    Attached Files:

  10. Zoreiana

    Zoreiana Private E-2

    Argh I have done everything as instructed, but then did not hit post. Luckily, I have saved fixlogs as two separate files.

    Two things:

    1. Google chrome runs normally, it is just Waterfox that is having major issues. I would like to get Waterfox fixed, as it is the fastest browser that I have used on this computer so far. Trying out Microsoft Edge right now.

    2. For some reason, while MGtools are installed in root C:\MGtools directory, the logs file appears on the desktop. Why is that?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should try asking about this in the Software Forum because it is not a malware problem. My suggestion would be to uninstall it completely!!! This means uninstall and then delete all relate folders and shortcuts links to make sure all addons/extensions are removed. Make sure registry info is cleaned up too ( an uninstaller program like Revo Uninstaller. may help with this )

    It creates the original at C:\MGlogs.zip and then copies to the Desktop for convenience because some people have a difficult time getting to the root folder but the Desktop seems easier for them. ;)

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps. Please complete all of the below final instructions before running any other scans to avoid false detections of things we have already quarantined or left overs from system restore.
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  12. Zoreiana

    Zoreiana Private E-2

    Thank you for your help!

    I have actually uninstalled Waterfox yesterday, and then manually searched the drive for all Firefox/Waterfox folders and deleted everything I could find. I have shredded the deleted files. Then reinstalled Waterfox. Somehow, it managed to import my settings from Firefox. I am lost as to from where ??? I had hidden files showing when I was deleting everything. I have the feeling some junk program or something attached itself to Waterfox and just will not leave.

    But I digress. I will do all suggested steps, and see if maybe Revo Uninstaller will help with this.

    Major thanks for all your help!!!!
     
  13. Zoreiana

    Zoreiana Private E-2

    Ok, as you have figured out by now, I am only about 10% competent :).

    I am running Windows 10, so with some pain I found System restore, deleted all old restore points, and created a new restore point. I hope that is what I was in fact supposed to do. Moving on to last step.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    From the below folders and registry keys.

    C:\Program Files (x86)\Mozilla Firefox
    C:\Users\Admin\AppData\Roaming\Mozilla
    [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox]

    And also the below shortcut needed to be removed for Waterfox too because shortcuts can carry infections.

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Waterfox.lnk
     
  15. Zoreiana

    Zoreiana Private E-2

    1. Revo Uninstaller did not see Waterfox as an installed program, so I un-installed it using Control Panel Uninstal.
    2. C:\Program Files (x86)\Mozilla Firefox - was not there (I have "show hidden files " on).
    3. C:\Users\Admin\AppData\Roaming\Mozilla - done
    4. I do not know how to do
    [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox]
    5. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Waterfox.lnk - was not there.

    6. I do not know if this is related, but yesterday Yahoo Mail for some reason put my account into quarantine. Might have been some problem on their end, but I have used Yahoo Mail through Waterfox in the last week or so.

    Please advise on how I can make sure that all of Waterfox/firefox is deleted. I am very suspicious of that program. Also, I run Windows 10. It has a feature that when it thinks a program is suspicious, it brightens the displayto 100%. I originally did not know what was happening when it did that. Now I know it only did that when I tried to run Waterfox. Once I closed Waterfox, the display brightness would return to pre-set value.

    Thank you!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below registry patch should remove these.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Not related as far as I can tell, but perhaps something that we have already cleaned up had caused an issue previously with Yahoo.
     
  17. Zoreiana

    Zoreiana Private E-2

    "The keys and values have been successfully added to the registry". Please let me know if I need to do anything else before I can try to reinstall Waterfox. My other browsers are performing abysmally. Thanks! :)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    We already did all we needed back in message number 11 ( I assume you finished all of those now ? ). So give Waterfox a try again if you still want to use it.
     
  19. Zoreiana

    Zoreiana Private E-2

    Yes, I did everything. Waterfox is still unstable. When it works, it works much faster than Chrome or Eagle. But it flickers when it loads pages (or even as I am writing this), and then after a few pages altogether crashes. So I need to post this problem in the software forum?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but before doing so perhaps you should look into uninstalling BitDefender first. You have both BitDefender and Windows Defender running which you should not have. So if you uninstall ( not disable ) BitDefender and check to see if there is any change.
     
  21. Zoreiana

    Zoreiana Private E-2

    Ack. I did not realize that. I was under impression that Windows Defender was designed to disable itself once a different Antivirus program was installed. I also am under impression that BitDefender might be a better antivirus program than Windows Defender. Then again Windows Defender supposedly has a firewall built in, which I do not think that BitDefender has. I am actually thoroughly confused regarding these issues. I will try un-installing BitDefender and see, but the problems with Waterfox started well before I went and installed a gamut of antivirus programs (the latter one was an ignorant and bad move, as I now know).
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let me know the results of the uninstall! I'm also not sure it will resolve your problems but based on your logs, the issue is not from malware. I don't use Waterfox so I cannot comment either way. But I never found Firefox to be an improvement over IE.

    Yes Windows Defender is supposed to disable when another security program is installed but per your logs this did not happen.
     
  23. Zoreiana

    Zoreiana Private E-2

    Firefox was not an improvement over IE, Waterfox was. Especially for browser games. Huge difference. Might also be because I am using a very low end computer, the difference on high speed one might be minimal, for me its night and day.

    Anyways, when I was uninstalling the BitDefender, I got a message that the computer was not protected and that Windows Defender was off. Uninstalled successfully, but Waterfox is still crashing. I am going to try and see if I can install an older version of Waterfox if I can find it, maybe the most recent one has problems.

    I also have an odd little box popping up every time I start computer, I do not remember what it says exactly, I would like to take a screenshot of it and save it to show it to you, but I am not sure how to do that. I used to just paste my screenshots into Power Point, but I do not have it at the moment.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Interesting since it was running. Your logs had showed the below for BitDefender:

    bdagent.exe "C:\Program Files\Bitdefender\Bitdefender 2016\bdagent.exe"
    bdwtxag.exe "C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxag.exe"
    bdwtxcr.exe "C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxcr.exe" --parent-window=0 chrome-extension://dhhejlifdlcgcmogbggeomfodgklfaem/
    ProductAgentService.exe "C:\Program Files\Bitdefender Agent\ProductAgentService.exe"

    And the below for Windows Defender:
    MpCmdRun.exe "C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey D3F09444-9646-6F18-4CE8-CC2721F2AB20 -Reinvoke
    MsMpEng.exe

    You will have to tell me exactly what it says. Creating screen shots is dependent upon when the popup occurs. If it is before you login then you don't have the ability to run a screen snapshot program yet. If after you login then there are dozens of free tools to do this. Power Point files cannot be attached to messages.
     
  25. Zoreiana

    Zoreiana Private E-2

    Hmm. So I uninstalled the BitDefender, and went back to older version of Waterfox, which is still not stable, but better than the most recent one.

    The box pops up after the login, and has the title "Server busy". It has a yellow triangle exclamation mark sign. Then there is a message "This action can not be completed because the other program is busy. Chose "Switch to" to activate the other program and correct the problem." Underneath, there are three buttons, "Switch to", "Retry" and "Cancel". The Cancel button is not active. Hitting either "Switch to" or "Retry" closes the box.

    I haven't a slightest idea what that means.
     
    Last edited: Jan 1, 2016
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps it is related to one of the below startup processes you load each time you start your PC. These showed in your logs among other startups. The CrazyTalk Serve line seems like a good candidate.

    • O4 - HKLM\..\Run: [RadioController] "C:\Program Files (x86)\RadioController\RfBtnHelper.exe" Start_Run
    • O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
    • O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
    • O4 - HKLM\..\Run: [DelaypluginInstall] C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
    • O4 - HKLM\..\Run: [CrazyTalk Serve] rundll32.exe C:\WINDOWS\system32\CrazyTalk.dll,DllServeMediaFile
    • O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    • O4 - HKCU\..\Run: [Dropbox Update] "C:\Users\Admin\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
    • O4 - HKCU\..\Run: [OneDrive] "C:\Users\Admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
    • O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
    • O4 - HKCU\..\Run: [AcerPortal] "C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe" startup
    • O4 - HKCU\..\Run: [RemoteFilesTrayIcon] "C:\Program Files (x86)\Acer\abFiles\abFilesTrayIcon.exe" --hideUI
    • O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
    • O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
    • O4 - Startup: Dropbox.lnk = Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe
    • O4 - Startup: MEGAsync.lnk = Admin\AppData\Local\MEGAsync\MEGAsync.exe
    • O4 - Global Startup: Acer Backup Manager Tray.lnk = C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
    Again this is not a malware problem.
     
  27. Zoreiana

    Zoreiana Private E-2

    Thank you for pointing that out, I went and disabled about half of that stuff on startup. Which made my computer a whole lot faster.

    I think I am OK now. Thank you for all the help and patience with me!
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds