

There are certainly technical ways to catch it but it is a bit easier to do it if you are in front of the PC. With regards to the CMD popping up occasionally. Scan your PC for viruses, threats and unwanted/unsafe applications - remove if anything found.īut I do not find anything big or serious to worry about. If you would like to scan your PC for threats with even additional software, you may use the free ESET Online scanner You might want to uninstall WildTangent - some professionals consider it a potentially unwanted software

+ " WildTangentHelper" "WildTangentHelper: WildTangent Helper Service" "(Verified) WildTangent Inc" "c:\program files (x86)\wildtangent games\integration\wildtangenthelperservice.exe" " 19:56" "" + "\ AdobeAAMUpdater-1.0-MicrosoftAccount-(email) "Adobe Updater Startup Utility" "(Verified) Adobe Systems Incorporated" "c:\program files (x86)\common files\adobe\oobe\pdapp\uwa\updaterstartuputility.exe" " 08:32" "" + "\ Adobe Uninstaller" "Adobe Creative Cloud" "(Verified) Adobe Inc." "c:\program files (x86)\adobe\adobe creative cloud\acc\creative cloud.exe" " 12:36" "" + "\ Adobe Flash Player NPAPI Notifier" "Adobe® Flash® Player Installer/Uninstaller 32.0 r0" "(Verified) Adobe Inc." "c:\windows\syswow64\macromed\flash\flashutil32_32_0_0_330_plugin.exe" " 00:33" "" + " HPMessageService" "HP Message Service" "(Verified) HP Inc." "c:\program files (x86)\hp\hp system event\hpmsgsvc.exe" " 03:24" "" "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run" + " cmd.exe" "Processore dei comandi di Windows" "(Verified) Microsoft Windows" "c:\windows\system32\cmd.exe" " 07:19" "" "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell"

Make sure that only the following are selected: Once it is ready, you will see the word Ready in the lower left side. Once Autoruns is started, it will need some seconds (could be a minute) to gather the snapshot, wait for it. Run Microsoft Autoruns with Administrator rights (right click -> Run as Administrator).Īgree with the standard license agreement from Microsoft.

This is definitely not related to the charging process, something is happening in the background.ĭownload Autoruns (from Microsoft) from this URL =>
