HHHH
HHHH
(Only the adware programs with "Hidden" flag could be added to the fixlist to
unhide them. The adware programs should be uninstalled manually.)
Packages:
=========
Music -> C:\Program Files\WindowsApps\
Microsoft.ZuneMusic_2.6.672.0_x64__8wekyb3d8bbwe [2023-07-12] (Microsoft
Corporation) [MS Ad]
Skype -> C:\Program Files\WindowsApps\
Microsoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5c [2023-07-12] (Skype) [MS Ad]
Video -> C:\Program Files\WindowsApps\
Microsoft.ZuneVideo_2.6.446.0_x64__8wekyb3d8bbwe [2023-07-12] (Microsoft
Corporation) [MS Ad]
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3957642251-2528715432-444061663-1001_Classes\CLSID\
{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\
igfxEM.exe (Intel(R) pGFX 2020 -> Intel Corporation)
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-
E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\
IDMShellExt64.dll [2021-03-03] (Tonec Inc. -> Tonec FZE)
ContextMenuHandlers1: [Atheros] -> {B8952421-0E55-400B-94A6-FA858FC0A39F} => C:\
Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvAppExt.dll [2014-04-02]
(Qualcomm Atheros -> Qualcomm®Atheros®) [File not signed]
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\
Program Files\WinRAR\rarext.dll [2023-05-29] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>
C:\Program Files\WinRAR\rarext32.dll [2023-05-29] (win.rar GmbH -> Alexander
Roshal)
ContextMenuHandlers3: [FTShellContext] -> {AFF81F7B-6942-40c4-AADA-7214EF7B6DD1} =>
C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ShellContextExt.dll [2014-
04-02] (Qualcomm Atheros -> Qualcomm®Atheros®) [File not signed]
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} => -> No
File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>
-> No File
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No
File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No
File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\
WINDOWS\system32\igfxDTCM.dll [2021-03-17] (Microsoft Windows Hardware
Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>
-> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\
Program Files\WinRAR\rarext.dll [2023-05-29] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>
C:\Program Files\WinRAR\rarext32.dll [2023-05-29] (win.rar GmbH -> Alexander
Roshal)
2014-04-02 02:25 - 2014-04-02 02:25 - 000011264 _____ () [File not signed] C:\
Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\
ActivateDesktopDebugger\ActivateDesktopDebugger.dll
2014-04-02 02:22 - 2014-04-02 02:22 - 000086016 _____ () [File not signed] C:\
Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Map\MAP.dll
2014-04-02 02:29 - 2014-04-02 02:29 - 000033408 _____ (Qualcomm Atheros ->
Qualcomm®Atheros®) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\
Bluetooth Suite\CommApi.dll
2014-04-02 02:29 - 2014-04-02 02:29 - 000203392 _____ (Qualcomm Atheros ->
Qualcomm®Atheros®) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\
Bluetooth Suite\FolderViewImpl.dll
2014-04-02 02:29 - 2014-04-02 02:29 - 000085632 _____ (Qualcomm Atheros ->
Qualcomm®Atheros®) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\
Bluetooth Suite\GattI.dll
2014-04-02 02:29 - 2014-04-02 02:29 - 000126592 _____ (Qualcomm Atheros ->
Qualcomm®Atheros®) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\
Bluetooth Suite\gatts.DLL
2014-04-02 02:29 - 2014-04-02 02:29 - 000083072 _____ (Qualcomm Atheros ->
Qualcomm®Atheros®) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\
Bluetooth Suite\Handsfree.dll
2014-04-02 02:29 - 2014-04-02 02:29 - 000034432 _____ (Qualcomm Atheros ->
Qualcomm®Atheros®) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\
Bluetooth Suite\ipc.dll
2014-04-02 02:30 - 2014-04-02 02:30 - 000063104 _____ (Qualcomm Atheros ->
Qualcomm®Atheros®) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\
Bluetooth Suite\ModuleManager.dll
2014-04-02 02:30 - 2014-04-02 02:30 - 001067648 _____ (Qualcomm Atheros ->
Qualcomm®Atheros®) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\
Bluetooth Suite\OutlookLib.dll
2014-04-02 02:30 - 2014-04-02 02:30 - 000027264 _____ (Qualcomm Atheros ->
Qualcomm®Atheros®) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\
Bluetooth Suite\TCPConnection.dll
2014-04-02 02:30 - 2014-04-02 02:30 - 000116352 _____ (Qualcomm Atheros ->
Qualcomm®Atheros®) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\
Bluetooth Suite\utils.dll
2014-04-02 02:23 - 2014-04-02 02:23 - 000308224 _____ (Qualcomm Atheros
Commnucations) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth
Suite\Modules\LE\LE.dll
2014-04-02 02:24 - 2014-04-02 02:24 - 000210432 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Audio\
audio.dll
2014-04-02 02:25 - 2014-04-02 02:25 - 000162304 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\
BasicPrintProfile\BPP.dll
2014-04-02 02:25 - 2014-04-02 02:25 - 000177152 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\BIP\BIP.dll
2014-04-02 02:22 - 2014-04-02 02:22 - 000018432 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\DID\DId.dll
2014-04-02 02:22 - 2014-04-02 02:22 - 000035840 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\FAX\Fax.dll
2014-04-02 02:24 - 2014-04-02 02:24 - 000421888 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\
FileTransfer\FileTransfer.dll
2014-04-02 02:24 - 2014-04-02 02:24 - 000096256 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\GapSdp\
GapSdp.dll
2014-04-02 02:19 - 2014-04-02 02:19 - 000097792 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\goep\
goep.dll
2014-04-02 02:22 - 2014-04-02 02:22 - 000029696 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\HCRP\
Hcrp.dll
2014-04-02 02:23 - 2014-04-02 02:23 - 000142848 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\
HealthDevice\HDP.dll
2014-04-02 02:25 - 2014-04-02 02:25 - 000091136 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\L2capLib\
l2caplib.dll
2014-04-02 02:25 - 2014-04-02 02:25 - 000066048 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\
OppOperation\OppOperation.dll
2014-04-02 02:24 - 2014-04-02 02:24 - 000067072 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\pbap\
pbap.dll
2014-04-02 02:25 - 2014-04-02 02:25 - 000063488 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\RfcommLib\
rfcommlib.dll
2014-04-02 02:24 - 2014-04-02 02:24 - 000097280 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\sap\sap.dll
2014-04-02 02:25 - 2014-04-02 02:25 - 000087552 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\SesMgr\
sesmgr.dll
2014-04-02 02:24 - 2014-04-02 02:24 - 000055296 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\spp\spp.dll
2014-04-02 02:23 - 2014-04-02 02:23 - 000064512 _____ (Qualcomm®Atheros®) [File not
signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Sync\
Sync.dll
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
HKU\S-1-5-21-3957642251-2528715432-444061663-1001\Control Panel\Desktop\\Wallpaper
-> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System =>
(ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled:
RequireAdmin)
Windows Firewall is enabled.
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
Application errors:
==================
Error: (07/16/2023 05:06:02 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the
IVssWriterCallback interface. hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or
requestor process.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {aebc17f6-496b-42f8-877b-8c2618194949}
Error: (07/15/2023 07:32:56 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program wwahost.exe version 6.3.9600.17415 stopped interacting
with Windows and was closed. To see if more information about the problem is
available, check the problem history in the Action Center control panel.
Error: (07/15/2023 07:32:55 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program PhotosApp.exe version 6.3.9600.17418 stopped interacting
with Windows and was closed. To see if more information about the problem is
available, check the problem history in the Action Center control panel.
Report Id:
Termination Time: 15
System errors:
=============
Error: (07/16/2023 05:07:12 AM) (Source: DCOM) (EventID: 10010) (User: YAOMH)
Description: The server {BB6DF56B-CACE-11DC-9992-0019B93A3A84} did not register
with DCOM within the required timeout.
Error: (07/16/2023 05:05:12 AM) (Source: DCOM) (EventID: 10010) (User: YAOMH)
Description: The server {1ECCA34C-E88A-44E3-8D6A-8921BDE9E452} did not register
with DCOM within the required timeout.
Windows Defender:
================
Date: 2023-07-16 04:57:52.854
Description:
Windows Defender has detected malware or other potentially unwanted software.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/
AutoKMS&threatid=2147685180&enterprise=0
Name: HackTool:Win32/AutoKMS
Severity: High
Category: Tool
Path: file:_C:\Users\YAOMH1\Downloads\Working KMS\Working KMS\KMS Server.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Users\YAOMH1\Downloads\Windows_Repair_Toolbox\Downloads\Malware
Removal\NPE64.exe
Signature Version: AV: 1.393.473.0, AS: 1.393.473.0, NIS: 119.0.0.0
Engine Version: AM: 1.1.23060.1005, NIS: 2.1.14600.4
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: ED041E76)
Partition 1: (Active) - (Size=270.4 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=195.3 GB) - (Type=07 NTFS)