Trend Micro Security

PUA.Win32.Auslogics.AG

2020年1月10日

 プラットフォーム:

Windows

 危険度:
 感染確認数:
 システムへの影響:
 情報漏えい:


  • マルウェアタイプ: 潜在的に迷惑なアプリケーション
  • 破壊活動の有無: なし
  • 暗号化:  
  • 感染報告の有無: はい

  概要


マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。


  詳細

ファイルサイズ 394,752 bytes
タイプ EXE
メモリ常駐 はい
発見日 2020年1月10日

侵入方法

マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。

インストール

マルウェアは、以下のプロセスを追加します。

  • "%User Temp%\2AC02BED-480E-4564-9122-78206DF1326C_fixmypc_setup.exe" /verysilent /execute /FromStubInstall /stubwindow:131438 /LOG /AutoCSOffer /DisplayOffers /showurl /urlparams:dt=56&dc=FixMyPC
  • "%User Temp%\2AC02BED-480E-4564-9122-78206DF1326C_fixmypc_setup.exe" /verysilent /execute /FromStubInstall /stubwindow:131438 /LOG /AutoCSOffer /DisplayOffers /showurl /urlparams:dt=4&dc=FixMyPC
  • "%User Temp%\is-UFDCM.tmp\2AC02BED-480E-4564-9122-78206DF1326C_fixmypc_setup.tmp" /SL5="$20188,16282106,414208,%User Temp%\2AC02BED-480E-4564-9122-78206DF1326C_fixmypc_setup.exe" /verysilent /execute /FromStubInstall /stubwindow:131438 /LOG /AutoCSOffer /DisplayOffers /showurl /urlparams:dt=56&dc=FixMyPC
  • "%User Temp%\is-7NCAO.tmp\2AC02BED-480E-4564-9122-78206DF1326C_fixmypc_setup.tmp" /SL5="$50188,16282106,414208,%User Temp%\2AC02BED-480E-4564-9122-78206DF1326C_fixmypc_setup.exe" /verysilent /execute /FromStubInstall /stubwindow:131438 /LOG /AutoCSOffer /DisplayOffers /showurl /urlparams:dt=4&dc=FixMyPC
  • %User Temp%\is-8B0SQ.tmp\DefaultBrowserFinder.exe "TweakBit" "PCRepairKit" "pc-repair-kit" "1.x"
  • %User Temp%\is-8B0SQ.tmp\reader.exe "%User Temp%\2AC02BED-480E-4564-9122-78206DF1326C_fixmypc_setup.exe" "(x32)HKEY_LOCAL_MACHINE\Software\TweakBit\PCRepairKit\1.x\Settings"
  • "%System%\regsvr32.exe" /s "%Program Files%\TweakBit\PCRepairKit\BrowserCareHelper.Agent.x64.dll"
  • "%System%\regsvr32.exe" /s "%Program Files%\TweakBit\PCRepairKit\BrowserCareHelper.Agent.x32.dll"
  • %Program Files%\TweakBit\PCRepairKit\PCRepairKit.exe /Install /Language:"ENU" /AutoStart /SendInfo /AutoScan

(註:%User Temp%フォルダは、現在ログオンしているユーザの一時フォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local\Temp" です。. %Program Files%フォルダは、デフォルトのプログラムファイルフォルダです。C:\Program Files in Windows 2000(32-bit)、Server 2003(32-bit)、XP、Vista(64-bit)、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Program Files"です。また、Windows XP(64-bit)、Vista(64-bit)、7(64-bit)、8(64-bit)、8.1(64-bit)、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Program Files(x86)" です。)

マルウェアは、以下のフォルダを作成します。

  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit
  • %User Temp%\PCRepairKit.madExcept
  • %All Users Profile%\TweakBit\PCRepairKit
  • %All Users Profile%\TweakBit\PCRepairKit\1.x
  • %User Temp%\Tweakbit
  • %Program Files%\TweakBit
  • %Program Files%\TweakBit\PCRepairKit\Data
  • %User Temp%\is-8B0SQ.tmp\_isetup
  • %Program Files%\TweakBit\PCRepairKit\Lang
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit
  • %All Users Profile%\TweakBit
  • %Program Files%\TweakBit\PCRepairKit
  • %All Users Profile%\TweakBit\PCRepairKit\1.x\Data

(註:%All Users Profile%フォルダは、ユーザの共通プロファイルフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\All Users” です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\ProgramData” です。. %User Temp%フォルダは、現在ログオンしているユーザの一時フォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local\Temp" です。. %Program Files%フォルダは、デフォルトのプログラムファイルフォルダです。C:\Program Files in Windows 2000(32-bit)、Server 2003(32-bit)、XP、Vista(64-bit)、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Program Files"です。また、Windows XP(64-bit)、Vista(64-bit)、7(64-bit)、8(64-bit)、8.1(64-bit)、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Program Files(x86)" です。)

他のシステム変更

マルウェアは、以下のファイルを削除します。

  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit on the Web.pif
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\Uninstall PCRepairKit.pif
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit on the Web.lnk
  • %Desktop%\TweakBit PCRepairKit.pif
  • %User Temp%\PCRepairKit.madExcept
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit.url
  • %Program Files%\TweakBit\PCRepairKit\is-GPSNP.tmp
  • %Desktop%\TweakBit PCRepairKit.url
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit.pif
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\Uninstall PCRepairKit.url

(註:%All Users Profile%フォルダは、ユーザの共通プロファイルフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\All Users” です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\ProgramData” です。. %Desktop%フォルダは、現在ログオンしているユーザのデスクトップです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Desktop" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\Desktop" です。. %User Temp%フォルダは、現在ログオンしているユーザの一時フォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local\Temp" です。. %Program Files%フォルダは、デフォルトのプログラムファイルフォルダです。C:\Program Files in Windows 2000(32-bit)、Server 2003(32-bit)、XP、Vista(64-bit)、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Program Files"です。また、Windows XP(64-bit)、Vista(64-bit)、7(64-bit)、8(64-bit)、8.1(64-bit)、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Program Files(x86)" です。)

マルウェアは、以下のレジストリキーを追加します。

HKEY_LOCAL_MACHINE\Software\Auslogics\
Google Analytics Package\1.x\Settings

HKEY_CURRENT_USER\Software\Microsoft\
RestartManager\Session0000

HKEY_LOCAL_MACHINE\Software\TweakBit\
PCRepairKit\1.x\Settings

HKEY_LOCAL_MACHINE\Software\TweakBit\
ATUpdaters\1.x\Settings

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}\
TypeLib

HKEY_CLASSES_ROOT\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}

HKEY_CLASSES_ROOT\AppID\{93469602-4134-4012-A6BC-FD34B37A0C36}

HKEY_CLASSES_ROOT\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\
InprocServer32

HKEY_CLASSES_ROOT\BCAgentCOM32.BCAgent32

HKEY_CLASSES_ROOT\BCAgentCOM32.BCAgent32\Clsid

HKEY_CLASSES_ROOT\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\
ProgID

HKEY_CLASSES_ROOT\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\
Version

HKEY_CLASSES_ROOT\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\
TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{F53488B2-F26B-BB1A-1AB8-6A73422D1D3C}\Version

マルウェアは、以下のレジストリ値を追加します。

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Auslogics\Google Analytics Package\1.x\
Settings
ClientID = "{6D2D75F7-624A-4797-B427-C41EBFD338C3}"

HKEY_CURRENT_USER\Software\Microsoft\
RestartManager\Session0000
Owner = "\xd4\x02\x00\x00\xde,v\xed(P\xd5\x01"

HKEY_CURRENT_USER\Software\Microsoft\
RestartManager\Session0000
SessionHash = "{random characters}"

HKEY_CURRENT_USER\Software\Microsoft\
RestartManager\Session0000
Sequence = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit\PCRepairKit\1.x\
Settings
General.Language = "ENU"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit\PCRepairKit\1.x\
Settings
General.URLSource = "pc-repair-kit"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit\PCRepairKit\1.x\
Settings
General.Cookie = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit\PCRepairKit\1.x\
Settings
General.Cookie = "ui_lite"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit\PCRepairKit\1.x\
Settings
App.Application.PurchaseUrlParam = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit\PCRepairKit\1.x\
Settings
General.DoNotAddUtmToUrls = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit
ClientID = "{82F25A94-BBFA-43C5-A968-9BE9223ACE11}"

HKEY_CURRENT_USER\Software\Microsoft\
RestartManager\Session0000
RegFiles0000 = "\x00\x00\x00\x00:\xef\xb0\x80\x05\xe1\x80\x80t\xe2\xa1\x97"

HKEY_CURRENT_USER\Software\Microsoft\
RestartManager\Session0000
RegFilesHash = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit\ATUpdaters\1.x\
Settings
Shared.Blocking.PCRepairKit = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
Inno Setup: Setup Version = "5.5.9 (u)"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
Inno Setup: App Path = "%Program Files%\TweakBit\PCRepairKit"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
InstallLocation = "%Program Files%\TweakBit\PCRepairKit"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
Inno Setup: Icon Group = "TweakBit\PCRepairKit"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
Inno Setup: User = "{username}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
Inno Setup: Language = "en"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
DisplayName = "TweakBit PCRepairKit"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
DisplayIcon = "%Program Files%\TweakBit\PCRepairKit\PCRepairKit.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
UninstallString = "%Program Files%\TweakBit\PCRepairKit\unins000.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
QuietUninstallString = "%Program Files%\TweakBit\PCRepairKit\unins000.exe /SILENT"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
DisplayVersion = "1.8.4.19"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
Publisher = "Tweakbit Pty Ltd"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
URLInfoAbout = "http://www.{BLOCKED}it.com/support/contact"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
HelpLink = "http://www.{BLOCKED}it.com/en/support.php"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
URLUpdateInfo = "http://www.{BLOCKED}it.com/pc-repair-kit"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
Contact = "info@tweakbit.com"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
NoModify = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
NoRepair = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
InstallDate = "20190811"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
MajorVersion = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
MinorVersion = "8"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
VersionMajor = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
VersionMinor = "8"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
EstimatedSize = "57537"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
UninstallString = "%Program Files%\TweakBit\PCRepairKit\unins000.exe /compability"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}
(Default) = "IBCAgent32"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}\
ProxyStubClsid32
(Default) = "{00020424-0000-0000-C000-000000000046}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}\
TypeLib
(Default) = "{F2C6F7D1-ED32-49E5-9919-C51E9E2FD453}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}\
TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}
AppID = "{93469602-4134-4012-A6BC-FD34B37A0C36}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{93469602-4134-4012-A6BC-FD34B37A0C36}
DllSurrogate = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}
(Default) = "TweakBit BCAgent32"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\
InprocServer32
(Default) = "%Program Files%\TweakBit\PCREPA~1\BROWSE~3.DLL"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\
InprocServer32
ThreadingModel = "Free"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
BCAgentCOM32.BCAgent32
(Default) = "TweakBit BCAgent32"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
BCAgentCOM32.BCAgent32\Clsid
(Default) = "{93469602-4134-4012-A6BC-FD34B37A0C36}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\
ProgID
(Default) = "BCAgentCOM32.BCAgent32"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\
Version
(Default) = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\
TypeLib
(Default) = "{F2C6F7D1-ED32-49E5-9919-C51E9E2FD453}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F53488B2-F26B-BB1A-1AB8-6A73422D1D3C}\
Version
Assembly = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit\PCRepairKit\1.x\
Settings
General.InstallDateTime = "8=)\x00\x18U\xe5@"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit\PCRepairKit\1.x\
Settings
(Default) = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit\PCRepairKit\1.x\
Settings
App.Application.FileName = "%Program Files%\TweakBit\PCRepairKit\PCRepairKit.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit\PCRepairKit\1.x\
Settings
Application.AutoScan.Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit\PCRepairKit\1.x\
Settings
Application.AutoScan.TimeStamp = "\x00\xa0:\xf5Q\x89'@"

マルウェアは、以下のレジストリキーを削除します。

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
TweakBit\PCRepairKit\1.x\
Settings\General.DefWebBrowser

作成活動

マルウェアは、以下のファイルを作成します。

  • %Program Files%\TweakBit\PCRepairKit\is-VEABU.tmp
  • %Program Files%\TweakBit\PCRepairKit\BrowserCareHelper.Agent.x32.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\cookies.sqlite
  • %Desktop%\Resume TweakBit FixMyPC Installation.lnk
  • %User Temp%\Tweakbit\Setup Stub 2019-8-11.log
  • %Program Files%\TweakBit\PCRepairKit\is-IODD5.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\enu.lng
  • %Program Files%\TweakBit\PCRepairKit\ATUpdatersHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\TweakManager.exe
  • %Program Files%\TweakBit\PCRepairKit\Lang\esp.lng
  • %User Temp%\is-8B0SQ.tmp\CommonForms.Site.dll
  • %Program Files%\TweakBit\PCRepairKit\SystemInformationHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Data\is-RKP9D.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-NMQ0I.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\hmthinfo.mdict
  • %Program Files%\TweakBit\PCRepairKit\is-P82PR.tmp
  • %User Temp%\Setup Log 2019-08-11 #001.txt
  • %Program Files%\TweakBit\PCRepairKit\TaskSchedulerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-8R6RS.tmp
  • %Program Files%\TweakBit\PCRepairKit\WizardHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-HPEFU.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\is-31IMU.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\cmpdw.dict
  • %User Temp%\is-8B0SQ.tmp\WizardHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-7B6JU.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-AMT36.tmp
  • %User Temp%\is-8B0SQ.tmp\$$$Cookies150087392
  • %Program Files%\TweakBit\PCRepairKit\Data\hsysfiles.mdict
  • %Program Files%\TweakBit\PCRepairKit\is-5HRDQ.tmp
  • %Program Files%\TweakBit\PCRepairKit\unins000.msg
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\cookies.sqlite-wal
  • %Program Files%\TweakBit\PCRepairKit\vcl160.bpl
  • %Program Files%\TweakBit\PCRepairKit\Data\is-QNJ91.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-DJS94.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-4FAQD.tmp
  • %User Temp%\is-8B0SQ.tmp\ita.lng
  • %Program Files%\TweakBit\PCRepairKit\GoogleAnalyticsHelper.dll
  • %User Temp%\is-8B0SQ.tmp\AxComponentsVCL.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-ESBDC.tmp
  • %User Temp%\is-8B0SQ.tmp\PCRepairKit.exe
  • %User Temp%\is-8B0SQ.tmp\fra.lng
  • %Program Files%\TweakBit\PCRepairKit\is-I2E56.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-PEMO1.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-0VMKQ.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\is-K9RTU.tmp
  • %User Temp%\is-8B0SQ.tmp\$$$Databases.db150099716
  • %Program Files%\TweakBit\PCRepairKit\is-NGC60.tmp
  • %User Temp%\is-8B0SQ.tmp\AxComponentsRTL.bpl
  • %Program Files%\TweakBit\PCRepairKit\CommonForms.Routine.dll
  • %Program Files%\TweakBit\PCRepairKit\is-K0414.tmp
  • %User Temp%\2AC02BED-480E-4564-9122-78206DF1326C_fixmypc_setup.exe
  • %User Temp%\is-8B0SQ.tmp\rtl160.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-0QIUO.tmp
  • %User Temp%\is-8B0SQ.tmp\reader.exe
  • %User Temp%\is-8B0SQ.tmp\deu.lng
  • %AppDataLocal%\GDIPFONTCACHEV1.DAT
  • %Program Files%\TweakBit\PCRepairKit\AxComponentsRTL.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-5QSLG.tmp
  • %Program Files%\TweakBit\PCRepairKit\RescueCenterHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Localizer.dll
  • %Program Files%\TweakBit\PCRepairKit\is-03UCH.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-TO1K0.tmp
  • %User Temp%\is-8B0SQ.tmp\sqlite3.dll
  • %Program Files%\TweakBit\PCRepairKit\is-T24CS.tmp
  • %Program Files%\TweakBit\PCRepairKit\TweakManagerHelper.dll
  • %User Temp%\is-8B0SQ.tmp\$$$Databases.db150087580
  • %Program Files%\TweakBit\PCRepairKit\is-8JTP6.tmp
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\places.sqlite-shm
  • %Program Files%\TweakBit\PCRepairKit\Data\database.dat
  • %Program Files%\TweakBit\PCRepairKit\BrowserCareHelper.Agent.x64.dll
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\Uninstall PCRepairKit.lnk
  • %Program Files%\TweakBit\PCRepairKit\DiskWipeHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\rdboot64.exe
  • %Program Files%\TweakBit\PCRepairKit\DebugHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\sqlite3.dll
  • %Program Files%\TweakBit\PCRepairKit\Lang\ptb.lng
  • %Program Files%\TweakBit\PCRepairKit\rtl160.bpl
  • %Program Files%\TweakBit\PCRepairKit\Lang\fra.lng
  • %Program Files%\TweakBit\PCRepairKit\is-QLRLO.tmp
  • %Program Files%\TweakBit\PCRepairKit\PCRepairKit.exe
  • %Program Files%\TweakBit\PCRepairKit\is-9MN18.tmp
  • %Program Files%\TweakBit\PCRepairKit\CommonForms.Site.dll
  • %Program Files%\TweakBit\PCRepairKit\PCRepairKit.url
  • %Program Files%\TweakBit\PCRepairKit\is-NCQ1R.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-MF3B9.tmp
  • %Program Files%\TweakBit\PCRepairKit\CFAHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-CMJBL.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\cmpdw.dict-journal
  • %Program Files%\TweakBit\PCRepairKit\is-ILH6E.tmp
  • %Program Files%\TweakBit\PCRepairKit\RescueCenter.exe
  • %Program Files%\TweakBit\PCRepairKit\unins000.exe
  • %Program Files%\TweakBit\PCRepairKit\is-KOJMV.tmp
  • %User Temp%\is-8B0SQ.tmp\GoogleAnalyticsHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-LBFK3.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\is-J7IIT.tmp
  • %User Temp%\is-8B0SQ.tmp\downloader.exe
  • %Program Files%\TweakBit\PCRepairKit\InternetOptimizerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-D561F.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-3C9OS.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-JFCNJ.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\ita.lng
  • %Program Files%\TweakBit\PCRepairKit\ATPopupsHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Data\main.ini
  • %Program Files%\TweakBit\PCRepairKit\unins000.dat
  • %Program Files%\TweakBit\PCRepairKit\Data\compromised_passwords.txt
  • %Program Files%\TweakBit\PCRepairKit\Data\hbwlists.mdict
  • %Program Files%\TweakBit\PCRepairKit\is-SGSRC.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-N3CD0.tmp
  • %Program Files%\TweakBit\PCRepairKit\DiskCleanerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\DuplicateFileFinder.exe
  • %Program Files%\TweakBit\PCRepairKit\ReportHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\rdboot32.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\cookies.sqlite-shm
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\places.sqlite-wal
  • %User Temp%\is-8B0SQ.tmp\vcl160.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-G304I.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-C9SC9.tmp
  • %Program Files%\TweakBit\PCRepairKit\RegistryCleanerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-COBCC.tmp
  • %Program Files%\TweakBit\PCRepairKit\vclimg160.bpl
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-E8GNF.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-MMU6S.tmp
  • %User Temp%\is-8B0SQ.tmp\CFAHelper.dll
  • %User Temp%\is-8B0SQ.tmp\$$$Cookies150099654
  • %Program Files%\TweakBit\PCRepairKit\is-O0HBL.tmp
  • %Program Files%\TweakBit\PCRepairKit\MalwareHeuristicHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\VolumesHelper.dll
  • %User Temp%\is-8B0SQ.tmp\esp.lng
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-1EDMR.tmp
  • %User Temp%\is-8B0SQ.tmp\main.ini
  • %Desktop%\TweakBit PCRepairKit.lnk
  • %Program Files%\TweakBit\PCRepairKit\is-KNJKE.tmp
  • %Program Files%\TweakBit\PCRepairKit\InternetOptimizer.exe
  • %Program Files%\TweakBit\PCRepairKit\Data\is-8G72R.tmp
  • %Program Files%\TweakBit\PCRepairKit\AxComponentsVCL.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-H3DOI.tmp
  • %Program Files%\TweakBit\PCRepairKit\CommonForms.dll
  • %Program Files%\TweakBit\PCRepairKit\is-N8SGU.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\deu.lng
  • %Program Files%\TweakBit\PCRepairKit\RegistryDefrag.exe
  • %Program Files%\TweakBit\PCRepairKit\is-B3R9Q.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-FARA7.tmp
  • %Program Files%\TweakBit\PCRepairKit\Downloader.exe
  • %Program Files%\TweakBit\PCRepairKit\Data\hwscheme.mdict
  • %Program Files%\TweakBit\PCRepairKit\Data\security_db.dat
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit on the Web.url
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit.lnk
  • %Program Files%\TweakBit\PCRepairKit\RegistryDefragHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\AxBrowsers.dll
  • %Program Files%\TweakBit\PCRepairKit\is-7PV02.tmp
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\places.sqlite
  • %Program Files%\TweakBit\PCRepairKit\FileShredder.exe
  • %Program Files%\TweakBit\PCRepairKit\RescueCenterForm.dll
  • %Program Files%\TweakBit\PCRepairKit\DuplicateFileFinderHelper.dll
  • %User Temp%\is-8B0SQ.tmp\Localizer.dll
  • %Program Files%\TweakBit\PCRepairKit\MalwareDetectionHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Data\is-TQBOU.tmp
  • %User Temp%\is-8B0SQ.tmp\vclimg160.bpl
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-6A9AA.tmp
  • %Program Files%\TweakBit\PCRepairKit\SpywareCheckerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-OLRFP.tmp
  • %Program Files%\TweakBit\PCRepairKit\SendDebugLog.exe
  • %Program Files%\TweakBit\PCRepairKit\Data\is-7IV7K.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-5OJ6U.tmp
  • %Program Files%\TweakBit\PCRepairKit\BrowserCareHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-7EI90.tmp
  • %User Temp%\is-8B0SQ.tmp\ptb.lng

(註:%Program Files%フォルダは、デフォルトのプログラムファイルフォルダです。C:\Program Files in Windows 2000(32-bit)、Server 2003(32-bit)、XP、Vista(64-bit)、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Program Files"です。また、Windows XP(64-bit)、Vista(64-bit)、7(64-bit)、8(64-bit)、8.1(64-bit)、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Program Files(x86)" です。. %Application Data%フォルダは、現在ログオンしているユーザのアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Roaming" です。. %Desktop%フォルダは、現在ログオンしているユーザのデスクトップです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Desktop" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\Desktop" です。. %User Temp%フォルダは、現在ログオンしているユーザの一時フォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local\Temp" です。. %AppDataLocal%フォルダは、ローカルアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local" です。. %All Users Profile%フォルダは、ユーザの共通プロファイルフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\All Users” です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\ProgramData” です。)

その他

マルウェアは、以下の不正なWebサイトにアクセスします。

  • http://www.{BLOCKED}-analytics.com/collect
  • http://downloads.{BLOCKED}it.com/en/fix-my-pc/mb/fix-my-pc-setup.exe
  • http://dynamicdownloads.{BLOCKED}it.com/prk/def/pc-repair-kit-setup
  • http://{BLOCKED}it.com

このウイルス情報は、自動解析システムにより作成されました。


  対応方法

対応検索エンジン: 9.850

手順 1

Windows XP、Windows Vista および Windows 7 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。

手順 2

「PUA.Win32.Auslogics.AG」で検出したファイル名を確認し、そのファイルを終了します。

[ 詳細 ]

  • すべての実行中プロセスが、Windows のタスクマネージャに表示されない場合があります。この場合、"Process Explorer" などのツールを使用しマルウェアのファイルを終了してください。"Process Explorer" については、こちらをご参照下さい。
  • 検出ファイルが、Windows のタスクマネージャまたは "Process Explorer" に表示されるものの、削除できない場合があります。この場合、コンピュータをセーフモードで再起動してください。
    セーフモードについては、こちらをご参照下さい。
  • 検出ファイルがタスクマネージャ上で表示されない場合、次の手順にお進みください。

手順 3

不明なレジストリキーを削除します。

[ 詳細 ]

警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。

  • In HKEY_LOCAL_MACHINE\Software\Auslogics\Google Analytics Package\1.x
    • Settings
  • In HKEY_CURRENT_USER\Software\Microsoft\RestartManager
    • Session0000
  • In HKEY_LOCAL_MACHINE\Software\TweakBit\PCRepairKit\1.x
    • Settings
  • In HKEY_LOCAL_MACHINE\Software\TweakBit\ATUpdaters\1.x
    • Settings
  • In HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall
    • {5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}
    • TypeLib
  • In HKEY_CLASSES_ROOT\CLSID
    • {93469602-4134-4012-A6BC-FD34B37A0C36}
  • In HKEY_CLASSES_ROOT\AppID
    • {93469602-4134-4012-A6BC-FD34B37A0C36}
  • In HKEY_CLASSES_ROOT\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}
    • InprocServer32
  • In HKEY_CLASSES_ROOT
    • BCAgentCOM32.BCAgent32
  • In HKEY_CLASSES_ROOT\BCAgentCOM32.BCAgent32
    • Clsid
  • In HKEY_CLASSES_ROOT\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}
    • ProgID
  • In HKEY_CLASSES_ROOT\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}
    • Version
  • In HKEY_CLASSES_ROOT\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F53488B2-F26B-BB1A-1AB8-6A73422D1D3C}
    • Version

手順 4

このレジストリ値を削除します。

[ 詳細 ]

警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。

  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Auslogics\Google Analytics Package\1.x\Settings
    • ClientID = "{6D2D75F7-624A-4797-B427-C41EBFD338C3}"
  • In HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
    • Owner = "\xd4\x02\x00\x00\xde,v\xed(P\xd5\x01"
  • In HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
    • SessionHash = "{random characters}"
  • In HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
    • Sequence = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit\PCRepairKit\1.x\Settings
    • General.Language = "ENU"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit\PCRepairKit\1.x\Settings
    • General.URLSource = "pc-repair-kit"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit\PCRepairKit\1.x\Settings
    • General.Cookie = ""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit\PCRepairKit\1.x\Settings
    • General.Cookie = "ui_lite"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit\PCRepairKit\1.x\Settings
    • App.Application.PurchaseUrlParam = ""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit\PCRepairKit\1.x\Settings
    • General.DoNotAddUtmToUrls = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit
    • ClientID = "{82F25A94-BBFA-43C5-A968-9BE9223ACE11}"
  • In HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
    • RegFiles0000 = "\x00\x00\x00\x00:\xef\xb0\x80\x05\xe1\x80\x80t\xe2\xa1\x97"
  • In HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
    • RegFilesHash = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit\ATUpdaters\1.x\Settings
    • Shared.Blocking.PCRepairKit = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • Inno Setup: Setup Version = "5.5.9 (u)"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • Inno Setup: App Path = "%Program Files%\TweakBit\PCRepairKit"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • InstallLocation = "%Program Files%\TweakBit\PCRepairKit"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • Inno Setup: Icon Group = "TweakBit\PCRepairKit"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • Inno Setup: User = "{username}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • Inno Setup: Language = "en"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • DisplayName = "TweakBit PCRepairKit"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • DisplayIcon = "%Program Files%\TweakBit\PCRepairKit\PCRepairKit.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • UninstallString = "%Program Files%\TweakBit\PCRepairKit\unins000.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • QuietUninstallString = "%Program Files%\TweakBit\PCRepairKit\unins000.exe /SILENT"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • DisplayVersion = "1.8.4.19"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • Publisher = "Tweakbit Pty Ltd"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • URLInfoAbout = "http://www.{BLOCKED}it.com/support/contact"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • HelpLink = "http://www.{BLOCKED}it.com/en/support.php"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • URLUpdateInfo = "http://www.{BLOCKED}it.com/pc-repair-kit"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • Contact = "info@tweakbit.com"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • NoModify = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • NoRepair = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • InstallDate = "20190811"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • MajorVersion = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • MinorVersion = "8"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • VersionMajor = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • VersionMinor = "8"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • EstimatedSize = "57537"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1
    • UninstallString = "%Program Files%\TweakBit\PCRepairKit\unins000.exe /compability"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}
    • (Default) = "IBCAgent32"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}\ProxyStubClsid32
    • (Default) = "{00020424-0000-0000-C000-000000000046}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}\TypeLib
    • (Default) = "{F2C6F7D1-ED32-49E5-9919-C51E9E2FD453}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A3310BE-83DD-4E80-AC51-E8DCA30FFEDB}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}
    • AppID = "{93469602-4134-4012-A6BC-FD34B37A0C36}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{93469602-4134-4012-A6BC-FD34B37A0C36}
    • DllSurrogate = ""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}
    • (Default) = "TweakBit BCAgent32"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\InprocServer32
    • (Default) = "%Program Files%\TweakBit\PCREPA~1\BROWSE~3.DLL"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\InprocServer32
    • ThreadingModel = "Free"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BCAgentCOM32.BCAgent32
    • (Default) = "TweakBit BCAgent32"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BCAgentCOM32.BCAgent32\Clsid
    • (Default) = "{93469602-4134-4012-A6BC-FD34B37A0C36}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\ProgID
    • (Default) = "BCAgentCOM32.BCAgent32"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\Version
    • (Default) = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{93469602-4134-4012-A6BC-FD34B37A0C36}\TypeLib
    • (Default) = "{F2C6F7D1-ED32-49E5-9919-C51E9E2FD453}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F53488B2-F26B-BB1A-1AB8-6A73422D1D3C}\Version
    • Assembly = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit\PCRepairKit\1.x\Settings
    • General.InstallDateTime = "8=)\x00\x18U\xe5@"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit\PCRepairKit\1.x\Settings
    • (Default) = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit\PCRepairKit\1.x\Settings
    • App.Application.FileName = "%Program Files%\TweakBit\PCRepairKit\PCRepairKit.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit\PCRepairKit\1.x\Settings
    • Application.AutoScan.Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit\PCRepairKit\1.x\Settings
    • Application.AutoScan.TimeStamp = "\x00\xa0:\xf5Q\x89'@"

手順 5

以下のファイルを検索し削除します。

[ 詳細 ]
コンポーネントファイルが隠しファイル属性の場合があります。[詳細設定オプション]をクリックし、[隠しファイルとフォルダの検索]のチェックボックスをオンにし、検索結果に隠しファイルとフォルダが含まれるようにしてください。
  • %Program Files%\TweakBit\PCRepairKit\is-VEABU.tmp
  • %Program Files%\TweakBit\PCRepairKit\BrowserCareHelper.Agent.x32.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\cookies.sqlite
  • %Desktop%\Resume TweakBit FixMyPC Installation.lnk
  • %User Temp%\Tweakbit\Setup Stub 2019-8-11.log
  • %Program Files%\TweakBit\PCRepairKit\is-IODD5.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\enu.lng
  • %Program Files%\TweakBit\PCRepairKit\ATUpdatersHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\TweakManager.exe
  • %Program Files%\TweakBit\PCRepairKit\Lang\esp.lng
  • %User Temp%\is-8B0SQ.tmp\CommonForms.Site.dll
  • %Program Files%\TweakBit\PCRepairKit\SystemInformationHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Data\is-RKP9D.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-NMQ0I.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\hmthinfo.mdict
  • %Program Files%\TweakBit\PCRepairKit\is-P82PR.tmp
  • %User Temp%\Setup Log 2019-08-11 #001.txt
  • %Program Files%\TweakBit\PCRepairKit\TaskSchedulerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-8R6RS.tmp
  • %Program Files%\TweakBit\PCRepairKit\WizardHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-HPEFU.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\is-31IMU.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\cmpdw.dict
  • %User Temp%\is-8B0SQ.tmp\WizardHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-7B6JU.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-AMT36.tmp
  • %User Temp%\is-8B0SQ.tmp\$Cookies150087392
  • %Program Files%\TweakBit\PCRepairKit\Data\hsysfiles.mdict
  • %Program Files%\TweakBit\PCRepairKit\is-5HRDQ.tmp
  • %Program Files%\TweakBit\PCRepairKit\unins000.msg
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\cookies.sqlite-wal
  • %Program Files%\TweakBit\PCRepairKit\vcl160.bpl
  • %Program Files%\TweakBit\PCRepairKit\Data\is-QNJ91.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-DJS94.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-4FAQD.tmp
  • %User Temp%\is-8B0SQ.tmp\ita.lng
  • %Program Files%\TweakBit\PCRepairKit\GoogleAnalyticsHelper.dll
  • %User Temp%\is-8B0SQ.tmp\AxComponentsVCL.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-ESBDC.tmp
  • %User Temp%\is-8B0SQ.tmp\PCRepairKit.exe
  • %User Temp%\is-8B0SQ.tmp\fra.lng
  • %Program Files%\TweakBit\PCRepairKit\is-I2E56.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-PEMO1.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-0VMKQ.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\is-K9RTU.tmp
  • %User Temp%\is-8B0SQ.tmp\$Databases.db150099716
  • %Program Files%\TweakBit\PCRepairKit\is-NGC60.tmp
  • %User Temp%\is-8B0SQ.tmp\AxComponentsRTL.bpl
  • %Program Files%\TweakBit\PCRepairKit\CommonForms.Routine.dll
  • %Program Files%\TweakBit\PCRepairKit\is-K0414.tmp
  • %User Temp%\2AC02BED-480E-4564-9122-78206DF1326C_fixmypc_setup.exe
  • %User Temp%\is-8B0SQ.tmp\rtl160.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-0QIUO.tmp
  • %User Temp%\is-8B0SQ.tmp\reader.exe
  • %User Temp%\is-8B0SQ.tmp\deu.lng
  • %AppDataLocal%\GDIPFONTCACHEV1.DAT
  • %Program Files%\TweakBit\PCRepairKit\AxComponentsRTL.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-5QSLG.tmp
  • %Program Files%\TweakBit\PCRepairKit\RescueCenterHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Localizer.dll
  • %Program Files%\TweakBit\PCRepairKit\is-03UCH.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-TO1K0.tmp
  • %User Temp%\is-8B0SQ.tmp\sqlite3.dll
  • %Program Files%\TweakBit\PCRepairKit\is-T24CS.tmp
  • %Program Files%\TweakBit\PCRepairKit\TweakManagerHelper.dll
  • %User Temp%\is-8B0SQ.tmp\$Databases.db150087580
  • %Program Files%\TweakBit\PCRepairKit\is-8JTP6.tmp
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\places.sqlite-shm
  • %Program Files%\TweakBit\PCRepairKit\Data\database.dat
  • %Program Files%\TweakBit\PCRepairKit\BrowserCareHelper.Agent.x64.dll
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\Uninstall PCRepairKit.lnk
  • %Program Files%\TweakBit\PCRepairKit\DiskWipeHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\rdboot64.exe
  • %Program Files%\TweakBit\PCRepairKit\DebugHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\sqlite3.dll
  • %Program Files%\TweakBit\PCRepairKit\Lang\ptb.lng
  • %Program Files%\TweakBit\PCRepairKit\rtl160.bpl
  • %Program Files%\TweakBit\PCRepairKit\Lang\fra.lng
  • %Program Files%\TweakBit\PCRepairKit\is-QLRLO.tmp
  • %Program Files%\TweakBit\PCRepairKit\PCRepairKit.exe
  • %Program Files%\TweakBit\PCRepairKit\is-9MN18.tmp
  • %Program Files%\TweakBit\PCRepairKit\CommonForms.Site.dll
  • %Program Files%\TweakBit\PCRepairKit\PCRepairKit.url
  • %Program Files%\TweakBit\PCRepairKit\is-NCQ1R.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-MF3B9.tmp
  • %Program Files%\TweakBit\PCRepairKit\CFAHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-CMJBL.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\cmpdw.dict-journal
  • %Program Files%\TweakBit\PCRepairKit\is-ILH6E.tmp
  • %Program Files%\TweakBit\PCRepairKit\RescueCenter.exe
  • %Program Files%\TweakBit\PCRepairKit\unins000.exe
  • %Program Files%\TweakBit\PCRepairKit\is-KOJMV.tmp
  • %User Temp%\is-8B0SQ.tmp\GoogleAnalyticsHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-LBFK3.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\is-J7IIT.tmp
  • %User Temp%\is-8B0SQ.tmp\downloader.exe
  • %Program Files%\TweakBit\PCRepairKit\InternetOptimizerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-D561F.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-3C9OS.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-JFCNJ.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\ita.lng
  • %Program Files%\TweakBit\PCRepairKit\ATPopupsHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Data\main.ini
  • %Program Files%\TweakBit\PCRepairKit\unins000.dat
  • %Program Files%\TweakBit\PCRepairKit\Data\compromised_passwords.txt
  • %Program Files%\TweakBit\PCRepairKit\Data\hbwlists.mdict
  • %Program Files%\TweakBit\PCRepairKit\is-SGSRC.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-N3CD0.tmp
  • %Program Files%\TweakBit\PCRepairKit\DiskCleanerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\DuplicateFileFinder.exe
  • %Program Files%\TweakBit\PCRepairKit\ReportHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\rdboot32.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\cookies.sqlite-shm
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\places.sqlite-wal
  • %User Temp%\is-8B0SQ.tmp\vcl160.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-G304I.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-C9SC9.tmp
  • %Program Files%\TweakBit\PCRepairKit\RegistryCleanerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-COBCC.tmp
  • %Program Files%\TweakBit\PCRepairKit\vclimg160.bpl
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-E8GNF.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-MMU6S.tmp
  • %User Temp%\is-8B0SQ.tmp\CFAHelper.dll
  • %User Temp%\is-8B0SQ.tmp\$Cookies150099654
  • %Program Files%\TweakBit\PCRepairKit\is-O0HBL.tmp
  • %Program Files%\TweakBit\PCRepairKit\MalwareHeuristicHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\VolumesHelper.dll
  • %User Temp%\is-8B0SQ.tmp\esp.lng
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-1EDMR.tmp
  • %User Temp%\is-8B0SQ.tmp\main.ini
  • %Desktop%\TweakBit PCRepairKit.lnk
  • %Program Files%\TweakBit\PCRepairKit\is-KNJKE.tmp
  • %Program Files%\TweakBit\PCRepairKit\InternetOptimizer.exe
  • %Program Files%\TweakBit\PCRepairKit\Data\is-8G72R.tmp
  • %Program Files%\TweakBit\PCRepairKit\AxComponentsVCL.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-H3DOI.tmp
  • %Program Files%\TweakBit\PCRepairKit\CommonForms.dll
  • %Program Files%\TweakBit\PCRepairKit\is-N8SGU.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\deu.lng
  • %Program Files%\TweakBit\PCRepairKit\RegistryDefrag.exe
  • %Program Files%\TweakBit\PCRepairKit\is-B3R9Q.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-FARA7.tmp
  • %Program Files%\TweakBit\PCRepairKit\Downloader.exe
  • %Program Files%\TweakBit\PCRepairKit\Data\hwscheme.mdict
  • %Program Files%\TweakBit\PCRepairKit\Data\security_db.dat
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit on the Web.url
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit.lnk
  • %Program Files%\TweakBit\PCRepairKit\RegistryDefragHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\AxBrowsers.dll
  • %Program Files%\TweakBit\PCRepairKit\is-7PV02.tmp
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\places.sqlite
  • %Program Files%\TweakBit\PCRepairKit\FileShredder.exe
  • %Program Files%\TweakBit\PCRepairKit\RescueCenterForm.dll
  • %Program Files%\TweakBit\PCRepairKit\DuplicateFileFinderHelper.dll
  • %User Temp%\is-8B0SQ.tmp\Localizer.dll
  • %Program Files%\TweakBit\PCRepairKit\MalwareDetectionHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Data\is-TQBOU.tmp
  • %User Temp%\is-8B0SQ.tmp\vclimg160.bpl
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-6A9AA.tmp
  • %Program Files%\TweakBit\PCRepairKit\SpywareCheckerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-OLRFP.tmp
  • %Program Files%\TweakBit\PCRepairKit\SendDebugLog.exe
  • %Program Files%\TweakBit\PCRepairKit\Data\is-7IV7K.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-5OJ6U.tmp
  • %Program Files%\TweakBit\PCRepairKit\BrowserCareHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-7EI90.tmp
  • %User Temp%\is-8B0SQ.tmp\ptb.lng
$Cookies150087392
  • %Program Files%\TweakBit\PCRepairKit\Data\hsysfiles.mdict
  • %Program Files%\TweakBit\PCRepairKit\is-5HRDQ.tmp
  • %Program Files%\TweakBit\PCRepairKit\unins000.msg
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\cookies.sqlite-wal
  • %Program Files%\TweakBit\PCRepairKit\vcl160.bpl
  • %Program Files%\TweakBit\PCRepairKit\Data\is-QNJ91.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-DJS94.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-4FAQD.tmp
  • %User Temp%\is-8B0SQ.tmp\ita.lng
  • %Program Files%\TweakBit\PCRepairKit\GoogleAnalyticsHelper.dll
  • %User Temp%\is-8B0SQ.tmp\AxComponentsVCL.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-ESBDC.tmp
  • %User Temp%\is-8B0SQ.tmp\PCRepairKit.exe
  • %User Temp%\is-8B0SQ.tmp\fra.lng
  • %Program Files%\TweakBit\PCRepairKit\is-I2E56.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-PEMO1.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-0VMKQ.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\is-K9RTU.tmp
  • %User Temp%\is-8B0SQ.tmp\$Databases.db150099716
  • %Program Files%\TweakBit\PCRepairKit\is-NGC60.tmp
  • %User Temp%\is-8B0SQ.tmp\AxComponentsRTL.bpl
  • %Program Files%\TweakBit\PCRepairKit\CommonForms.Routine.dll
  • %Program Files%\TweakBit\PCRepairKit\is-K0414.tmp
  • %User Temp%\2AC02BED-480E-4564-9122-78206DF1326C_fixmypc_setup.exe
  • %User Temp%\is-8B0SQ.tmp\rtl160.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-0QIUO.tmp
  • %User Temp%\is-8B0SQ.tmp\reader.exe
  • %User Temp%\is-8B0SQ.tmp\deu.lng
  • %AppDataLocal%\GDIPFONTCACHEV1.DAT
  • %Program Files%\TweakBit\PCRepairKit\AxComponentsRTL.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-5QSLG.tmp
  • %Program Files%\TweakBit\PCRepairKit\RescueCenterHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Localizer.dll
  • %Program Files%\TweakBit\PCRepairKit\is-03UCH.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-TO1K0.tmp
  • %User Temp%\is-8B0SQ.tmp\sqlite3.dll
  • %Program Files%\TweakBit\PCRepairKit\is-T24CS.tmp
  • %Program Files%\TweakBit\PCRepairKit\TweakManagerHelper.dll
  • %User Temp%\is-8B0SQ.tmp\$Databases.db150087580
  • %Program Files%\TweakBit\PCRepairKit\is-8JTP6.tmp
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\places.sqlite-shm
  • %Program Files%\TweakBit\PCRepairKit\Data\database.dat
  • %Program Files%\TweakBit\PCRepairKit\BrowserCareHelper.Agent.x64.dll
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\Uninstall PCRepairKit.lnk
  • %Program Files%\TweakBit\PCRepairKit\DiskWipeHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\rdboot64.exe
  • %Program Files%\TweakBit\PCRepairKit\DebugHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\sqlite3.dll
  • %Program Files%\TweakBit\PCRepairKit\Lang\ptb.lng
  • %Program Files%\TweakBit\PCRepairKit\rtl160.bpl
  • %Program Files%\TweakBit\PCRepairKit\Lang\fra.lng
  • %Program Files%\TweakBit\PCRepairKit\is-QLRLO.tmp
  • %Program Files%\TweakBit\PCRepairKit\PCRepairKit.exe
  • %Program Files%\TweakBit\PCRepairKit\is-9MN18.tmp
  • %Program Files%\TweakBit\PCRepairKit\CommonForms.Site.dll
  • %Program Files%\TweakBit\PCRepairKit\PCRepairKit.url
  • %Program Files%\TweakBit\PCRepairKit\is-NCQ1R.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-MF3B9.tmp
  • %Program Files%\TweakBit\PCRepairKit\CFAHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-CMJBL.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\cmpdw.dict-journal
  • %Program Files%\TweakBit\PCRepairKit\is-ILH6E.tmp
  • %Program Files%\TweakBit\PCRepairKit\RescueCenter.exe
  • %Program Files%\TweakBit\PCRepairKit\unins000.exe
  • %Program Files%\TweakBit\PCRepairKit\is-KOJMV.tmp
  • %User Temp%\is-8B0SQ.tmp\GoogleAnalyticsHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-LBFK3.tmp
  • %Program Files%\TweakBit\PCRepairKit\Data\is-J7IIT.tmp
  • %User Temp%\is-8B0SQ.tmp\downloader.exe
  • %Program Files%\TweakBit\PCRepairKit\InternetOptimizerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-D561F.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-3C9OS.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-JFCNJ.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\ita.lng
  • %Program Files%\TweakBit\PCRepairKit\ATPopupsHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Data\main.ini
  • %Program Files%\TweakBit\PCRepairKit\unins000.dat
  • %Program Files%\TweakBit\PCRepairKit\Data\compromised_passwords.txt
  • %Program Files%\TweakBit\PCRepairKit\Data\hbwlists.mdict
  • %Program Files%\TweakBit\PCRepairKit\is-SGSRC.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-N3CD0.tmp
  • %Program Files%\TweakBit\PCRepairKit\DiskCleanerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\DuplicateFileFinder.exe
  • %Program Files%\TweakBit\PCRepairKit\ReportHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\rdboot32.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\cookies.sqlite-shm
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\places.sqlite-wal
  • %User Temp%\is-8B0SQ.tmp\vcl160.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-G304I.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-C9SC9.tmp
  • %Program Files%\TweakBit\PCRepairKit\RegistryCleanerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-COBCC.tmp
  • %Program Files%\TweakBit\PCRepairKit\vclimg160.bpl
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-E8GNF.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-MMU6S.tmp
  • %User Temp%\is-8B0SQ.tmp\CFAHelper.dll
  • %User Temp%\is-8B0SQ.tmp\$Cookies150099654
  • %Program Files%\TweakBit\PCRepairKit\is-O0HBL.tmp
  • %Program Files%\TweakBit\PCRepairKit\MalwareHeuristicHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\VolumesHelper.dll
  • %User Temp%\is-8B0SQ.tmp\esp.lng
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-1EDMR.tmp
  • %User Temp%\is-8B0SQ.tmp\main.ini
  • %Desktop%\TweakBit PCRepairKit.lnk
  • %Program Files%\TweakBit\PCRepairKit\is-KNJKE.tmp
  • %Program Files%\TweakBit\PCRepairKit\InternetOptimizer.exe
  • %Program Files%\TweakBit\PCRepairKit\Data\is-8G72R.tmp
  • %Program Files%\TweakBit\PCRepairKit\AxComponentsVCL.bpl
  • %Program Files%\TweakBit\PCRepairKit\is-H3DOI.tmp
  • %Program Files%\TweakBit\PCRepairKit\CommonForms.dll
  • %Program Files%\TweakBit\PCRepairKit\is-N8SGU.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\deu.lng
  • %Program Files%\TweakBit\PCRepairKit\RegistryDefrag.exe
  • %Program Files%\TweakBit\PCRepairKit\is-B3R9Q.tmp
  • %Program Files%\TweakBit\PCRepairKit\is-FARA7.tmp
  • %Program Files%\TweakBit\PCRepairKit\Downloader.exe
  • %Program Files%\TweakBit\PCRepairKit\Data\hwscheme.mdict
  • %Program Files%\TweakBit\PCRepairKit\Data\security_db.dat
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit on the Web.url
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit.lnk
  • %Program Files%\TweakBit\PCRepairKit\RegistryDefragHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\AxBrowsers.dll
  • %Program Files%\TweakBit\PCRepairKit\is-7PV02.tmp
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\places.sqlite
  • %Program Files%\TweakBit\PCRepairKit\FileShredder.exe
  • %Program Files%\TweakBit\PCRepairKit\RescueCenterForm.dll
  • %Program Files%\TweakBit\PCRepairKit\DuplicateFileFinderHelper.dll
  • %User Temp%\is-8B0SQ.tmp\Localizer.dll
  • %Program Files%\TweakBit\PCRepairKit\MalwareDetectionHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\Data\is-TQBOU.tmp
  • %User Temp%\is-8B0SQ.tmp\vclimg160.bpl
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-6A9AA.tmp
  • %Program Files%\TweakBit\PCRepairKit\SpywareCheckerHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-OLRFP.tmp
  • %Program Files%\TweakBit\PCRepairKit\SendDebugLog.exe
  • %Program Files%\TweakBit\PCRepairKit\Data\is-7IV7K.tmp
  • %Program Files%\TweakBit\PCRepairKit\Lang\is-5OJ6U.tmp
  • %Program Files%\TweakBit\PCRepairKit\BrowserCareHelper.dll
  • %Program Files%\TweakBit\PCRepairKit\is-7EI90.tmp
  • %User Temp%\is-8B0SQ.tmp\ptb.lng
  • [探す場所]の一覧から[マイコンピュータ]を選択し、[検索]を押します。
  • 検索が終了したら、ファイルを選択し、SHIFT+DELETE を押します。これにより、ファイルが完全に削除されます。
    註:ファイル名の入力欄のタイトルは、Windowsのバージョンによって異なります。(例:ファイルやフォルダ名の検索の場合やファイル名のすべてまたは一部での検索)
  • Windows Vista、7、Server 2008、8、8.1 および Server 2012 の場合:

    1. Windowsエクスプローラ画面を開きます。
      • Windows Vista、7 および Server 2008 の場合:
        • [スタート]-[コンピューター]を選択します。
      • Windows 8、8.1 および Server 2012 の場合:
        • 画面の左隅を右クリックし、[エクスプローラー]を選択します。
    2. [コンピューターの検索]に、以下を入力します。
      • %Program Files%\TweakBit\PCRepairKit\is-VEABU.tmp
      • %Program Files%\TweakBit\PCRepairKit\BrowserCareHelper.Agent.x32.dll
      • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\cookies.sqlite
      • %Desktop%\Resume TweakBit FixMyPC Installation.lnk
      • %User Temp%\Tweakbit\Setup Stub 2019-8-11.log
      • %Program Files%\TweakBit\PCRepairKit\is-IODD5.tmp
      • %Program Files%\TweakBit\PCRepairKit\Lang\enu.lng
      • %Program Files%\TweakBit\PCRepairKit\ATUpdatersHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\TweakManager.exe
      • %Program Files%\TweakBit\PCRepairKit\Lang\esp.lng
      • %User Temp%\is-8B0SQ.tmp\CommonForms.Site.dll
      • %Program Files%\TweakBit\PCRepairKit\SystemInformationHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\Data\is-RKP9D.tmp
      • %Program Files%\TweakBit\PCRepairKit\is-NMQ0I.tmp
      • %Program Files%\TweakBit\PCRepairKit\Data\hmthinfo.mdict
      • %Program Files%\TweakBit\PCRepairKit\is-P82PR.tmp
      • %User Temp%\Setup Log 2019-08-11 #001.txt
      • %Program Files%\TweakBit\PCRepairKit\TaskSchedulerHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\is-8R6RS.tmp
      • %Program Files%\TweakBit\PCRepairKit\WizardHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\is-HPEFU.tmp
      • %Program Files%\TweakBit\PCRepairKit\Data\is-31IMU.tmp
      • %Program Files%\TweakBit\PCRepairKit\Data\cmpdw.dict
      • %User Temp%\is-8B0SQ.tmp\WizardHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\is-7B6JU.tmp
      • %Program Files%\TweakBit\PCRepairKit\is-AMT36.tmp
      • %User Temp%\is-8B0SQ.tmp\$Cookies150087392
      • %Program Files%\TweakBit\PCRepairKit\Data\hsysfiles.mdict
      • %Program Files%\TweakBit\PCRepairKit\is-5HRDQ.tmp
      • %Program Files%\TweakBit\PCRepairKit\unins000.msg
      • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\cookies.sqlite-wal
      • %Program Files%\TweakBit\PCRepairKit\vcl160.bpl
      • %Program Files%\TweakBit\PCRepairKit\Data\is-QNJ91.tmp
      • %Program Files%\TweakBit\PCRepairKit\is-DJS94.tmp
      • %Program Files%\TweakBit\PCRepairKit\is-4FAQD.tmp
      • %User Temp%\is-8B0SQ.tmp\ita.lng
      • %Program Files%\TweakBit\PCRepairKit\GoogleAnalyticsHelper.dll
      • %User Temp%\is-8B0SQ.tmp\AxComponentsVCL.bpl
      • %Program Files%\TweakBit\PCRepairKit\is-ESBDC.tmp
      • %User Temp%\is-8B0SQ.tmp\PCRepairKit.exe
      • %User Temp%\is-8B0SQ.tmp\fra.lng
      • %Program Files%\TweakBit\PCRepairKit\is-I2E56.tmp
      • %Program Files%\TweakBit\PCRepairKit\is-PEMO1.tmp
      • %Program Files%\TweakBit\PCRepairKit\Lang\is-0VMKQ.tmp
      • %Program Files%\TweakBit\PCRepairKit\Data\is-K9RTU.tmp
      • %User Temp%\is-8B0SQ.tmp\$Databases.db150099716
      • %Program Files%\TweakBit\PCRepairKit\is-NGC60.tmp
      • %User Temp%\is-8B0SQ.tmp\AxComponentsRTL.bpl
      • %Program Files%\TweakBit\PCRepairKit\CommonForms.Routine.dll
      • %Program Files%\TweakBit\PCRepairKit\is-K0414.tmp
      • %User Temp%\2AC02BED-480E-4564-9122-78206DF1326C_fixmypc_setup.exe
      • %User Temp%\is-8B0SQ.tmp\rtl160.bpl
      • %Program Files%\TweakBit\PCRepairKit\is-0QIUO.tmp
      • %User Temp%\is-8B0SQ.tmp\reader.exe
      • %User Temp%\is-8B0SQ.tmp\deu.lng
      • %AppDataLocal%\GDIPFONTCACHEV1.DAT
      • %Program Files%\TweakBit\PCRepairKit\AxComponentsRTL.bpl
      • %Program Files%\TweakBit\PCRepairKit\is-5QSLG.tmp
      • %Program Files%\TweakBit\PCRepairKit\RescueCenterHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\Localizer.dll
      • %Program Files%\TweakBit\PCRepairKit\is-03UCH.tmp
      • %Program Files%\TweakBit\PCRepairKit\is-TO1K0.tmp
      • %User Temp%\is-8B0SQ.tmp\sqlite3.dll
      • %Program Files%\TweakBit\PCRepairKit\is-T24CS.tmp
      • %Program Files%\TweakBit\PCRepairKit\TweakManagerHelper.dll
      • %User Temp%\is-8B0SQ.tmp\$Databases.db150087580
      • %Program Files%\TweakBit\PCRepairKit\is-8JTP6.tmp
      • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\places.sqlite-shm
      • %Program Files%\TweakBit\PCRepairKit\Data\database.dat
      • %Program Files%\TweakBit\PCRepairKit\BrowserCareHelper.Agent.x64.dll
      • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\Uninstall PCRepairKit.lnk
      • %Program Files%\TweakBit\PCRepairKit\DiskWipeHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\rdboot64.exe
      • %Program Files%\TweakBit\PCRepairKit\DebugHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\sqlite3.dll
      • %Program Files%\TweakBit\PCRepairKit\Lang\ptb.lng
      • %Program Files%\TweakBit\PCRepairKit\rtl160.bpl
      • %Program Files%\TweakBit\PCRepairKit\Lang\fra.lng
      • %Program Files%\TweakBit\PCRepairKit\is-QLRLO.tmp
      • %Program Files%\TweakBit\PCRepairKit\PCRepairKit.exe
      • %Program Files%\TweakBit\PCRepairKit\is-9MN18.tmp
      • %Program Files%\TweakBit\PCRepairKit\CommonForms.Site.dll
      • %Program Files%\TweakBit\PCRepairKit\PCRepairKit.url
      • %Program Files%\TweakBit\PCRepairKit\is-NCQ1R.tmp
      • %Program Files%\TweakBit\PCRepairKit\is-MF3B9.tmp
      • %Program Files%\TweakBit\PCRepairKit\CFAHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\is-CMJBL.tmp
      • %Program Files%\TweakBit\PCRepairKit\Data\cmpdw.dict-journal
      • %Program Files%\TweakBit\PCRepairKit\is-ILH6E.tmp
      • %Program Files%\TweakBit\PCRepairKit\RescueCenter.exe
      • %Program Files%\TweakBit\PCRepairKit\unins000.exe
      • %Program Files%\TweakBit\PCRepairKit\is-KOJMV.tmp
      • %User Temp%\is-8B0SQ.tmp\GoogleAnalyticsHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\is-LBFK3.tmp
      • %Program Files%\TweakBit\PCRepairKit\Data\is-J7IIT.tmp
      • %User Temp%\is-8B0SQ.tmp\downloader.exe
      • %Program Files%\TweakBit\PCRepairKit\InternetOptimizerHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\is-D561F.tmp
      • %Program Files%\TweakBit\PCRepairKit\is-3C9OS.tmp
      • %Program Files%\TweakBit\PCRepairKit\is-JFCNJ.tmp
      • %Program Files%\TweakBit\PCRepairKit\Lang\ita.lng
      • %Program Files%\TweakBit\PCRepairKit\ATPopupsHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\Data\main.ini
      • %Program Files%\TweakBit\PCRepairKit\unins000.dat
      • %Program Files%\TweakBit\PCRepairKit\Data\compromised_passwords.txt
      • %Program Files%\TweakBit\PCRepairKit\Data\hbwlists.mdict
      • %Program Files%\TweakBit\PCRepairKit\is-SGSRC.tmp
      • %Program Files%\TweakBit\PCRepairKit\is-N3CD0.tmp
      • %Program Files%\TweakBit\PCRepairKit\DiskCleanerHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\DuplicateFileFinder.exe
      • %Program Files%\TweakBit\PCRepairKit\ReportHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\rdboot32.exe
      • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\cookies.sqlite-shm
      • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\places.sqlite-wal
      • %User Temp%\is-8B0SQ.tmp\vcl160.bpl
      • %Program Files%\TweakBit\PCRepairKit\is-G304I.tmp
      • %Program Files%\TweakBit\PCRepairKit\is-C9SC9.tmp
      • %Program Files%\TweakBit\PCRepairKit\RegistryCleanerHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\Lang\is-COBCC.tmp
      • %Program Files%\TweakBit\PCRepairKit\vclimg160.bpl
      • %Program Files%\TweakBit\PCRepairKit\Lang\is-E8GNF.tmp
      • %Program Files%\TweakBit\PCRepairKit\is-MMU6S.tmp
      • %User Temp%\is-8B0SQ.tmp\CFAHelper.dll
      • %User Temp%\is-8B0SQ.tmp\$Cookies150099654
      • %Program Files%\TweakBit\PCRepairKit\is-O0HBL.tmp
      • %Program Files%\TweakBit\PCRepairKit\MalwareHeuristicHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\VolumesHelper.dll
      • %User Temp%\is-8B0SQ.tmp\esp.lng
      • %Program Files%\TweakBit\PCRepairKit\Lang\is-1EDMR.tmp
      • %User Temp%\is-8B0SQ.tmp\main.ini
      • %Desktop%\TweakBit PCRepairKit.lnk
      • %Program Files%\TweakBit\PCRepairKit\is-KNJKE.tmp
      • %Program Files%\TweakBit\PCRepairKit\InternetOptimizer.exe
      • %Program Files%\TweakBit\PCRepairKit\Data\is-8G72R.tmp
      • %Program Files%\TweakBit\PCRepairKit\AxComponentsVCL.bpl
      • %Program Files%\TweakBit\PCRepairKit\is-H3DOI.tmp
      • %Program Files%\TweakBit\PCRepairKit\CommonForms.dll
      • %Program Files%\TweakBit\PCRepairKit\is-N8SGU.tmp
      • %Program Files%\TweakBit\PCRepairKit\Lang\deu.lng
      • %Program Files%\TweakBit\PCRepairKit\RegistryDefrag.exe
      • %Program Files%\TweakBit\PCRepairKit\is-B3R9Q.tmp
      • %Program Files%\TweakBit\PCRepairKit\is-FARA7.tmp
      • %Program Files%\TweakBit\PCRepairKit\Downloader.exe
      • %Program Files%\TweakBit\PCRepairKit\Data\hwscheme.mdict
      • %Program Files%\TweakBit\PCRepairKit\Data\security_db.dat
      • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit on the Web.url
      • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit.lnk
      • %Program Files%\TweakBit\PCRepairKit\RegistryDefragHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\AxBrowsers.dll
      • %Program Files%\TweakBit\PCRepairKit\is-7PV02.tmp
      • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\places.sqlite
      • %Program Files%\TweakBit\PCRepairKit\FileShredder.exe
      • %Program Files%\TweakBit\PCRepairKit\RescueCenterForm.dll
      • %Program Files%\TweakBit\PCRepairKit\DuplicateFileFinderHelper.dll
      • %User Temp%\is-8B0SQ.tmp\Localizer.dll
      • %Program Files%\TweakBit\PCRepairKit\MalwareDetectionHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\Data\is-TQBOU.tmp
      • %User Temp%\is-8B0SQ.tmp\vclimg160.bpl
      • %Program Files%\TweakBit\PCRepairKit\Lang\is-6A9AA.tmp
      • %Program Files%\TweakBit\PCRepairKit\SpywareCheckerHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\is-OLRFP.tmp
      • %Program Files%\TweakBit\PCRepairKit\SendDebugLog.exe
      • %Program Files%\TweakBit\PCRepairKit\Data\is-7IV7K.tmp
      • %Program Files%\TweakBit\PCRepairKit\Lang\is-5OJ6U.tmp
      • %Program Files%\TweakBit\PCRepairKit\BrowserCareHelper.dll
      • %Program Files%\TweakBit\PCRepairKit\is-7EI90.tmp
      • %User Temp%\is-8B0SQ.tmp\ptb.lng
    3. ファイルが表示されたら、そのファイルを選択し、SHIFT+DELETE を押します。これにより、ファイルが完全に削除されます。
      註:Windows 7 において上記の手順が正しく行われない場合、マイクロソフトのWebサイトをご確認ください。

  • 手順 6

    以下のフォルダを検索し削除します。

    [ 詳細 ]
    フォルダが隠しフォルダ属性に設定されている場合があります。[詳細設定オプション]をクリックし、[隠しファイルとフォルダの検索]のチェックボックスをオンにし、検索結果に隠しファイルとフォルダが含まれるようにしてください。
    • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit
    • %User Temp%\PCRepairKit.madExcept
    • %All Users Profile%\TweakBit\PCRepairKit
    • %All Users Profile%\TweakBit\PCRepairKit\1.x
    • %User Temp%\Tweakbit
    • %Program Files%\TweakBit
    • %Program Files%\TweakBit\PCRepairKit\Data
    • %User Temp%\is-8B0SQ.tmp\_isetup
    • %Program Files%\TweakBit\PCRepairKit\Lang
    • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit
    • %All Users Profile%\TweakBit
    • %Program Files%\TweakBit\PCRepairKit
    • %All Users Profile%\TweakBit\PCRepairKit\1.x\Data

    手順 7

    最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、ウイルス検索を実行してください。「PUA.Win32.Auslogics.AG」と検出したファイルはすべて削除してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。

    手順 8

    以下のファイルをバックアップを用いて修復します。なお、マイクロソフト製品に関連したファイルのみ修復されます。このマルウェア/グレイウェア/スパイウェアが同社製品以外のプログラムをも削除した場合には、該当プログラムを再度インストールする必要があります。

    • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit on the Web.pif
    • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\Uninstall PCRepairKit.pif
    • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit on the Web.lnk
    • %Desktop%\TweakBit PCRepairKit.pif
    • %User Temp%\PCRepairKit.madExcept
    • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit.url
    • %Program Files%\TweakBit\PCRepairKit\is-GPSNP.tmp
    • %Desktop%\TweakBit PCRepairKit.url
    • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\TweakBit PCRepairKit.pif
    • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\TweakBit\PCRepairKit\Uninstall PCRepairKit.url

    手順 9

    以下の削除されたレジストリキーまたはレジストリ値をバックアップを用いて修復します。

    ※註:マイクロソフト製品に関連したレジストリキーおよびレジストリ値のみが修復されます。このマルウェアもしくはアドウェア等が同社製品以外のプログラムも削除した場合には、該当プログラムを再度インストールする必要があります。

    • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TweakBit\PCRepairKit\1.x\Settings
      • General.DefWebBrowser


    ご利用はいかがでしたか? アンケートにご協力ください