(If an entry is included in the fixlist, the process will be closed. The file will
not be moved.)
(If an entry is included in the fixlist, the registry item will be restored to
default or removed. The file will not be moved.)
Internet Explorer:
==================
HKU\S-1-5-21-1977530393-1560855581-2334280851-1001\Software\Microsoft\Internet
Explorer\Main,Start Page =
SearchScopes: HKU\S-1-5-21-1977530393-1560855581-2334280851-1001 -> DefaultScope
{FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?
q={searchTerms}&fr=ntg&product_id=%7BA976E640-3901-4CD1-B7E0-
DEF3020C06A8%7D&gp=811041
SearchScopes: HKU\S-1-5-21-1977530393-1560855581-2334280851-1001 -> {FFEBBF0A-C22C-
4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?
q={searchTerms}&fr=ntg&product_id=%7BA976E640-3901-4CD1-B7E0-
DEF3020C06A8%7D&gp=811041
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8}
-> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2016-12-11]
(Internet Download Manager, Tonec Inc.)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} ->
C:\Program Files\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft
Corporation)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} ->
C:\Program Files (x86)\Common
Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2013-12-21] (Adobe Systems
Incorporated)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-
ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-
31] (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-
665D8EE6A077} -> C:\Program Files (x86)\Common
Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2013-12-21] (Adobe Systems
Incorporated)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-
17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
[2016-12-11] (Internet Download Manager, Tonec Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-
2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll
[2015-08-01] (Microsoft Corporation)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910}
-> C:\Program Files (x86)\Common
Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-12-21] (Adobe Systems
Incorporated)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-
A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL
[2015-08-01] (Microsoft Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-
665D8EE6A077} -> C:\Program Files (x86)\Common
Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-12-21] (Adobe Systems
Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-
0819E2EAAC93} - C:\Program Files (x86)\Common
Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2013-12-21] (Adobe Systems
Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-
0819E2EAAC93} - C:\Program Files (x86)\Common
Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-12-21] (Adobe Systems
Incorporated)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program
Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program
Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-08-01] (Microsoft
Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program
Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files
(x86)\Microsoft Office\Office16\MSOSB.DLL [2015-08-01] (Microsoft Corporation)
FireFox:
========
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] -
C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat
11.0\Acrobat\Browser\WCFirefoxExtn [2017-05-12] [not signed]
FF HKU\S-1-5-21-1977530393-1560855581-2334280851-1001\...\SeaMonkey\Extensions:
[mozilla_cc@internetdownloadmanager.com] - C:\Users\Haryo
S\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Haryo S\AppData\Roaming\IDM\idmmzcc5 [2017-06-02]
[not signed]
FF HKU\S-1-5-21-1977530393-1560855581-2334280851-1001\...\SeaMonkey\Extensions:
[mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet
Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download
Manager\idmmzcc2.xpi [2017-01-26]
FF Plugin: @microsoft.com/SharePoint,version=14.0 ->
C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program
Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program
Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common
Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe
Systems)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 ->
C:\Program Files (x86)\Intel\Intel(R) Management Engine
Components\IPT\npIntelWebAPIIPT.dll [2015-08-25] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files
(x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[2015-08-25] (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla
Firefox\plugins\npmeetingjoinpluginoc.dll [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 ->
C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-08-01] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files
(x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-07-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files
(x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-07-17] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat
11.0\Acrobat\Air\nppdf32.dll [2013-12-21] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common
Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe
Systems)
FF Plugin HKU\S-1-5-21-1977530393-1560855581-2334280851-1001:
@unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Haryo
S\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-05-09] (Unity
Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla
firefox\plugins\npMeetingJoinPluginOC.dll [2015-07-31] (Microsoft Corporation)
Chrome:
=======
CHR HomePage: Default -> inline.go.mail.ru
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR DefaultSearchURL: Default -> hxxps://inline.go.mail.ru/search?
inline_comp=dse&q={searchTerms}&fr=chxtn12.0.23
CHR DefaultSearchKeyword: Default -> inline.go.mail.ru
CHR DefaultSuggestURL: Default -> hxxp://suggests.go.mail.ru/chrome?q={searchTerms}
CHR Profile: C:\Users\Haryo S\AppData\Local\Google\Chrome\User Data\Default [2017-
07-22]
CHR Extension: (Google Slides) - C:\Users\Haryo S\AppData\Local\Google\Chrome\User
Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-07-17]
CHR Extension: (Google Docs) - C:\Users\Haryo S\AppData\Local\Google\Chrome\User
Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-07-17]
CHR Extension: (Google Drive) - C:\Users\Haryo S\AppData\Local\Google\Chrome\User
Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-07-17]
CHR Extension: (YouTube) - C:\Users\Haryo S\AppData\Local\Google\Chrome\User
Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-07-17]
CHR Extension: (Adobe Acrobat) - C:\Users\Haryo S\AppData\Local\Google\Chrome\User
Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-07-17]
CHR Extension: (Google Sheets) - C:\Users\Haryo S\AppData\Local\Google\Chrome\User
Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-07-17]
CHR Extension: (Google Docs Offline) - C:\Users\Haryo
S\AppData\Local\Google\Chrome\User
Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-07-17]
CHR Extension: (Gmail) - C:\Users\Haryo S\AppData\Local\Google\Chrome\User
Data\Default\Extensions\kmhopmchchfpfdcdjodmpfaaphdclmlj [2017-07-17]
CHR Extension: (IDM Integration Module) - C:\Users\Haryo
S\AppData\Local\Google\Chrome\User
Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2017-07-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Haryo
S\AppData\Local\Google\Chrome\User
Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-07-17]
CHR Extension: (Gmail) - C:\Users\Haryo S\AppData\Local\Google\Chrome\User
Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-07-17]
CHR Extension: (Chrome Media Router) - C:\Users\Haryo
S\AppData\Local\Google\Chrome\User
Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-17]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program
Files (x86)\Internet Download Manager\IDMGCExt.crx [2017-05-25]
CHR HKLM-x32\...\Chrome\Extension: [bhjhnafpiilpffhglajcaepjbnbjemci] -
hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program
Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2013-
12-21]
CHR HKLM-x32\...\Chrome\Extension: [epgjfmblhacacphaljkdcjllkomdcjpc] -
hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hcadgijmedbfgciegjomfpjcdchlhnif] -
hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [iinglghmhcgdgjjlafobajghjamdchik] -
hxxps://clients2.google.com/service/update2/crx
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)