Addition
Addition
(Only the adware programs with "Hidden" flag could be added to the fixlist to
unhide them. The adware programs should be uninstalled manually.)
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1977530393-1560855581-2334280851-1001_Classes\CLSID\
{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program
Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-1977530393-1560855581-2334280851-1001_Classes\CLSID\
{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program
Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-1977530393-1560855581-2334280851-1001_Classes\CLSID\
{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program
Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-1977530393-1560855581-2334280851-1001_Classes\CLSID\
{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program
Files\Autodesk\AutoCAD 2016\en-US\acadficn.dll (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-
64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll
[2015-08-14] (Tonec Inc.)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] ->
{36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-
02-06] (Autodesk, Inc.)
ContextMenuHandlers01: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-
40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk
Shared\AcShellEx\AcShellExtension.dll [2015-02-06] (Autodesk)
ContextMenuHandlers01: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-
18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat
Elements\ContextMenuShim64.dll [2012-09-24] (Adobe Systems Inc.)
ContextMenuHandlers01: [BtSendToMenuEx] -> {CF24E6B8-F148-4BCB-9108-ADF313966E80}
=> -> No File
ContextMenuHandlers01: [FencesShellExt] -> {1984DD45-52CF-49cd-AB77-18F378FEA264}
=> C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2016-09-17] (Stardock)
ContextMenuHandlers01: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} =>
C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal)
ContextMenuHandlers01: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => ->
No File
ContextMenuHandlers04: [FencesShellExt] -> {1984DD45-52CF-49cd-AB77-18F378FEA264}
=> C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2016-09-17] (Stardock)
ContextMenuHandlers05: [FencesShellExt] -> {1984DD45-52CF-49cd-AB77-18F378FEA264}
=> C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2016-09-17] (Stardock)
ContextMenuHandlers05: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => ->
No File
ContextMenuHandlers05: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} =>
C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_463164d40c3d26ce\i
gfxDTCM.dll [2016-11-30] (Intel Corporation)
ContextMenuHandlers05: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-
BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-06-28] (NVIDIA Corporation)
ContextMenuHandlers06: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-
18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat
Elements\ContextMenuShim64.dll [2012-09-24] (Adobe Systems Inc.)
ContextMenuHandlers06: [FencesShellExt] -> {1984DD45-52CF-49cd-AB77-18F378FEA264}
=> C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2016-09-17] (Stardock)
ContextMenuHandlers06: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} =>
C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal)
ContextMenuHandlers06: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => ->
No File
ContextMenuHandlers1_S-1-5-21-1977530393-1560855581-2334280851-1001: [qingshellext]
-> {67F4D210-BFC2-4ADD-9A2A-C9B9E1F42C4F} => -> No File
ContextMenuHandlers4_S-1-5-21-1977530393-1560855581-2334280851-1001: [qingshellext]
-> {67F4D210-BFC2-4ADD-9A2A-C9B9E1F42C4F} => -> No File
ContextMenuHandlers5_S-1-5-21-1977530393-1560855581-2334280851-1001: [qingshellext]
-> {67F4D210-BFC2-4ADD-9A2A-C9B9E1F42C4F} => -> No File
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
Task: {039E399F-7FDF-4F8D-9E1D-31472334A90C} -
System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} =>
C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-06-21]
(NVIDIA Corporation)
Task: {08806AAE-9F1E-4E4D-9A47-1F9B69A6991E} -
System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} =>
C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-06-21]
(NVIDIA Corporation)
Task: {21549E07-7095-4AC8-A221-F753743ECB40} -
System32\Tasks\TweakBit\PCRepairKit\Start PCRepairKit n logon => C:\Program Files
(x86)\TweakBit\PCRepairKit\PCRepairKit.exe [2017-03-15] (TweakBit) <==== ATTENTION
Task: {28E26AD7-2BC3-414F-BDB2-68EBE4643AD4} -
System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe
/NOUACCHECK
Task: {2FA90DC6-40B4-4E2F-834B-5A6961DE14C4} -
System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program
Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2015-07-31]
(Microsoft Corporation)
Task: {48DF3444-10D0-4205-A21A-AD928B73504D} -
System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files
(x86)\Google\Update\GoogleUpdate.exe [2017-07-17] (Google Inc.)
Task: {49BC102C-99DC-49D4-9A82-C8A8D0FB5A95} -
System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program
Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation)
Task: {58F49B15-63FC-4761-9B39-4C5EED3E620D} -
System32\Tasks\RtHDVBg_ListenToDevice => C:\Program
Files\Realtek\Audio\HDA\RAVBg64.exe [2016-01-15] (Realtek Semiconductor)
Task: {618B7AC2-DEE0-45D7-80C7-92B57FD173E2} - System32\Tasks\ATK Package
A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe
[2015-03-11] (ASUSTek Computer Inc.)
Task: {6A558243-CDE9-4DB9-BC71-B85C2EA22924} - System32\Tasks\NVIDIA GeForce
Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files
(x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe
[2017-06-21] (NVIDIA Corporation)
Task: {7B40C5AD-4EAA-408B-A03E-7B54DC29FE62} - System32\Tasks\EPSON L310 Series
Update {08613D78-0D46-4989-9E3A-FC780CE18305} =>
C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSN4E.EXE [2013-11-22] (SEIKO EPSON
CORPORATION)
Task: {7C8DB95B-B21F-4FE8-BBB9-70FC32E1F4E7} - System32\Tasks\ASUS Smart Gesture
Launcher => C:\Program Files (x86)\ASUS\ASUS Smart
Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2015-12-15] (AsusTek)
Task: {8348AC73-ED32-48D6-9E2A-DD9022E5817A} -
System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program
Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-06-21] (NVIDIA
Corporation)
Task: {8629EA0C-AF12-4F63-AC59-59CB283E1355} - System32\Tasks\ASUS\ASUS Product
Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2015-05-15] (ASUSTek
Computer Inc.)
Task: {87BD22C7-8994-4556-B211-431EB1839FE8} - System32\Tasks\ASUS Live Update2 =>
C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-08-02] ()
Task: {999B296E-3926-409E-8818-B9FB131554D0} -
System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program
Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation)
Task: {A720164C-C9A4-4632-B3FB-256D2AD2E5F2} -
System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files
(x86)\Google\Update\GoogleUpdate.exe [2017-07-17] (Google Inc.)
Task: {B24F1FB8-E273-4FCA-ADDD-B3148B9D687A} - System32\Tasks\CCleanerSkipUAC =>
C:\Program Files\CCleaner\CCleaner.exe [2017-06-13] (Piriform Ltd)
Task: {B5395F00-D79D-4E6A-B410-6A8FFA3C1183} -
System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program
Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-06-21] (NVIDIA
Corporation)
Task: {B640E07A-2058-48B1-8BA8-0807FE959AEB} -
System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} =>
C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-06-21]
(NVIDIA Corporation)
Task: {B6581306-2C94-4CED-82E0-ACC1B163E1A8} - System32\Tasks\NvTmRep_{B2FE1952-
0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update
Core\NvTmRep.exe [2017-06-21] (NVIDIA Corporation)
Task: {C7CE7E2F-BFDE-45C3-8C03-50337F66C5DE} - System32\Tasks\ATK Package
36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe
[2015-03-11] (ASUSTek Computer Inc.)
Task: {D62517A7-CF46-4EED-B00F-56F6C9610BE4} - System32\Tasks\EPSON L310 Series
Update {6BD42DE0-5A33-4CBF-93BE-EF8B608790AA} =>
C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSN4E.EXE [2013-11-22] (SEIKO EPSON
CORPORATION)
Task: {E70DF3DF-71D5-4516-8CF9-DB1551A3865B} - System32\Tasks\ASUS USB Charger Plus
=> C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2015-05-26]
(ASUSTek Computer Inc.)
Task: {E7D405F6-EF8A-4788-A001-EA36A9E6E5B7} - System32\Tasks\jooringcommrtsm =>
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" jooring.com/mrtsm
<==== ATTENTION
Task: {EC338AC6-8F00-423A-B02A-8768E6D33ADA} - System32\Tasks\ASUS Live Update1 =>
C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-08-02] ()
Task: {F72CE796-8889-44E0-8364-A2458E70261F} - System32\Tasks\RTKCPL => C:\Program
Files\Realtek\Audio\HDA\RAVCpl64.exe [2016-01-15] (Realtek Semiconductor)
Task: {FE315E0B-1824-4254-B52C-3790626FF164} - System32\Tasks\Update Checker =>
C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-08-02] ()
Task: {FFAF8E06-D8C4-41EC-B627-5A8C7FDA5C41} - System32\Tasks\NvTmMon_{B2FE1952-
0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update
Core\NvTmMon.exe [2017-06-21] (NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The
file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\EPSON L310 Series Update {08613D78-0D46-4989-9E3A-
FC780CE18305}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSN4E.EXE:/EXE:
{08613D78-0D46-4989-9E3A-FC780CE18305} /F:UpdateWORKGROUP\DESKTOP-FHHLETL$Searches
for EPSON software updates, and notifies you when updates are available.If this
task is disabled or stopped, your EPSON software will not be automatically kept up
to date.Thi
Task: C:\WINDOWS\Tasks\EPSON L310 Series Update {6BD42DE0-5A33-4CBF-93BE-
EF8B608790AA}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSN4E.EXE:/EXE:
{6BD42DE0-5A33-4CBF-93BE-EF8B608790AA} /F:UpdateWORKGROUP\DESKTOP-FHHLETL$Searches
for EPSON software updates, and notifies you when updates are available.If this
task is disabled or stopped, your EPSON software will not be automatically kept up
to date.Thi
(If an entry is included in the fixlist, only the ADS will be removed.)
(If an entry is included in the fixlist, it will be removed from the registry. The
"AlternateShell" will be restored.)
(If an entry is included in the fixlist, the registry item will be restored to
default or removed.)
HKU\S-1-5-21-1977530393-1560855581-2334280851-1001\Software\Classes\.scr:
AutoCADScriptFile =>
(If an entry is included in the fixlist, it will be removed from the registry.)
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
HKU\S-1-5-21-1977530393-1560855581-2334280851-1000\Control Panel\Desktop\\Wallpaper
-> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-1977530393-1560855581-2334280851-1001\Control Panel\Desktop\\Wallpaper
-> d:\Users\Haryo S\Pictures\4001_WallpaperPlay_asus-walp-c-6-541_1920x1080.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System =>
(ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled:
Warn)
Windows Firewall is enabled.
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
Application errors:
==================
Error: (07/20/2017 07:54:06 PM) (Source: Application Error) (EventID: 1000)
(User: )
Description: Faulting application name: AUDIODG.EXE, version: 10.0.15063.447, time
stamp: 0xe365c782
Faulting module name: ICEsoundAPO64.dll, version: 1.0.0.19, time stamp: 0x56713f0a
Exception code: 0xc0000005
Fault offset: 0x000000000003b5b5
Faulting process id: 0xfb4
Faulting application start time: 0x01d301470db3161b
Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
Faulting module path: C:\WINDOWS\system32\ICEsoundAPO64.dll
Report Id: 94170cb3-d2d7-4947-b3e1-412b4c0ed45b
Faulting package full name:
Faulting package-relative application ID:
System errors:
=============
Error: (07/22/2017 01:10:05 PM) (Source: DCOM) (EventID: 10016) (User: NT
AUTHORITY)
Description: The application-specific permission settings do not grant Local
Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC)
running in the application container Unavailable SID (Unavailable). This security
permission can be modified using the Component Services administrative tool.
CodeIntegrity:
===================================
Date: 2017-07-19 14:16:43.773
Description: Code Integrity determined that a process
(\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to
load
\Device\HarddiskVolume2\Windows\System32\DriverStore\FileRepository\nvami.inf_amd64
_15b1a77b889ed915\nvinitx.dll that did not meet the Custom 3 / Antimalware signing
level requirements.
Date: 2017-07-19 14:16:43.694
Description: Code Integrity determined that a process
(\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to
load \Device\HarddiskVolume2\Program Files\Common Files\microsoft
shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing
level requirements.
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: AE6D18FC)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=222.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=503 MB) - (Type=27)
========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: B99C18CD)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=42)
========================================================
Disk: 2 (Size: 971.5 MB) (Disk ID: 0D7B1BA4)
Partition 1: (Not Active) - (Size=971 MB) - (Type=0C)