Operating System: Windows 10 (10.0.10240) 64 bits version
Program used: RogueKillerX64
Anti-Virus: Bitdefender Anti-Virus Plus 2016Hello,
I tried today your software on my computer because I have two really strange issues: The Right-Click menu when I try to
Run as an Administrator on the Task-bar icons is literally empty. I can see the "menu" box but there is no more commands in it... just an empty box, expect
Open or
Run but that's all. And when I click on a picture, it says something like
"photoviewer.dll is not a valid win32 application."Your Software find some issues but if I click on the
Delete button, at the end it says:
No replacement found | [Hidden.ADS][[[ADS]]] C:\Windows\explorer.exe:$CmdTcIDHonestly, I was like: Wait, what?... The heck?!
... um, are you kidding me? Hmm...
I did of course some research on the Internet before that but I'm still literally stuck with this "Hidden.ADS" crap. I can't do anything to remove this stuff anymore. I also tried
Malwarebyte, HerdProtect and many other programs out there, I mean MANY other programs, even
Windows Repair (as an administrator, indeed). What can I do now and most importantly; how can I recover my Right-Click menu when I click on icons, on the task-bar and how to fix the
PhotoViewer.dll too because I tried the
regsrv32 command and tried also the
SFC/SCANNOW command... no nothing, no corrupted files, no issues or anything like that. Well, according to Windows 10 anyway. This is really weird, isn't?...
OK, here is the report:
************************************
RogueKiller V11.0.5.0 (x64) [Dec 28 2015] (Free) by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
http://forum.adlice.comWebsite :
http://www.adlice.com/fr/logiciels/roguekiller/Blog :
http://www.adlice.comOperating System : Windows 10 (10.0.10240) 64 bits version
Started in : Normal mode
User : bob [Administrator]
Started from : C:\Users\bob\Desktop\RogueKillerX64.exe
Mode : Scan -- Date : 01/02/2016 20:35:10
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 0 ¤¤¤
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 1 ¤¤¤
[Hidden.ADS][[[ADS]]] C:\Windows\explorer.exe:$CmdTcID -> Found
¤¤¤ Hosts File : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost
¤¤¤ Antirootkit : 38 (Driver: Loaded) ¤¤¤
[IAT:Addr(Hook.IEAT)] (explorer.exe) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ user32.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ ole32.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ shlwapi.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ msctf.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ shell32.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ uxtheme.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ dwmapi.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ comctl32.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ explorerframe.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ twinui.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ ApplicationFrame.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ ntshrui.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ NetworkExplorer.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ GdiPlus.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ stobject.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ batmeter.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ InputSwitch.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ prnfldr.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ authui.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ hgcpl.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ duser.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ werconcpl.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ Windows.Internal.Shell.Broker.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ CoreSync_x64.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ DropboxExt64.28.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ bdshellext.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ fshredctx.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ RarExt.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ WDContextMenuHandler.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ comdlg32.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ cavshell.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ syncui.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ nvapi64.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ dui70.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ UIRibbon.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ Mp3tagShell64.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
[IAT:Addr(Hook.IEAT)] (explorer.exe @ NppShell_06.dll) gdi32!DeleteDC : Unknown @ 0x7ff9d9a80000
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: SiImage SCSI Disk Device +++++
--- User ---
[MBR] 925393a67b854881010d785b3b10133a
[BSP] ce319fb6e48e010e77555d689865ec78 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 686809 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([1] Fonction incorrecte. )
+++++ PhysicalDrive1: WDC WD10EADS-00M2B0 +++++
--- User ---
[MBR] f3c4f4e4206427766d62e2997f5d46f4
[BSP] 78766fa964bb992566fb2a6d7431ab8a : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 953767 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive2: SAMSUNG HD103UJ +++++
--- User ---
[MBR] 998dcfb892c750f736f4286512afafe8
[BSP] 33b5e3cd6006c1550d745345851f5d42 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 953859 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive3: KINGSTON SV300S37A240G SCSI Disk Device +++++
--- User ---
[MBR] 371158cd48cfe19cd47b2d455f7b07e6
[BSP] cff4b84e072c9c9773d0b0bdddd5b409 : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 63 | Size: 228935 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive4: INTEL SSDSA2M160G2GC +++++
--- User ---
[MBR] 9c42c00b6f4eb62782cbbb7fc96776c0
[BSP] c2e1dc03f373daf4482a2591c847ae4e : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 152625 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive5: WDC WD20EZRX-00D8PB0 +++++
--- User ---
[MBR] dd0f6844155e5daa73be52440e546055
[BSP] 1357a024c95c3b5816bbf738c798c2e8 : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1907727 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive6: WDC WD20EZRX-00D8PB0 +++++
--- User ---
[MBR] 416e1fe56091204aef411557c5b6531b
[BSP] 05b893730d48b75d3922b2b68422782c : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1907727 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
************************************
Thank you in advance for your help and I wish you an Happy New Year 2016!
CoolOliver.