お忙しい中申し訳ございません。
スパイウェア?アドウェア??に感染してしまい、対策に困っております。
ネットセキュリティブログさんの対処方法を参照させていただき、手順に従って「hijackthis」と「CCleaner-portable」でログを取得しましたので、対処方法についてアドバイスいただけると幸いです。
ログデータは以下の通りです。
<hijackthis>
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:07:50, on 2014/02/09
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16384)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\CyberLink\RZ Player\Kernel\DMS\CLMSTrayIcon.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\TOSHIBA\TouchFree\TouchFreeTray.exe
C:\Program Files (x86)\Toshiba Places Gadget V4\ToshibaPlacesGadget.exe
C:\Program Files (x86)\TOSHIBA\TKRTL\KarteLite.exe
C:\PROGRA~2\SearchProtect\SearchProtect\bin\cltmng.exe
C:\PROGRA~2\SearchProtect\UI\bin\cltmngui.exe
F:\HijackThis.exe
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\IPSBHO.DLL
O2 - BHO: SaveSense - {71e129ff-6c2a-4984-818c-7e2c998b8d99} - C:\Users\典貢\AppData\Local\SaveSense\SaveSenseIE.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TKRTL] "C:\Program Files (x86)\TOSHIBA\TKRTL\KarteLiteLauncher.exe" -h
O4 - HKLM\..\Run: [TSVU] "c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe"
O4 - HKLM\..\Run: [CLMSTrayIcon] "C:\Program Files (x86)\CyberLink\RZ Player\Kernel\DMS\CLMSTrayIcon.exe"
O4 - HKLM\..\Run: [ToshibaPlacesGadgetV4] "C:\Program Files (x86)\Toshiba Places Gadget V4\GadgetUpdater.exe" /startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [fst_jp_46] "C:\Program Files (x86)\fst_jp_46\fst_jp_46.exe"
O4 - HKLM\..\RunOnce: [upfst_jp_46.exe] C:\Users\典貢\AppData\Local\fst_jp_46\upfst_jp_46.exe -runonce
O4 - Startup: EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
O8 - Extra context menu item: URL をクリップ - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0
O8 - Extra context menu item: このページをクリップ - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=1
O8 - Extra context menu item: 新規ノート - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html
O8 - Extra context menu item: 画像をクリップ - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=4
O8 - Extra context menu item: 選択部分をクリップ - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=3
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Bonjour サービス (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CLHNServiceForToshiba - CyberLink Corp. - C:\Program Files (x86)\CyberLink\RZ Player\Kernel\DMP\CLHNServiceForToshiba.exe
O23 - Service: Search Protect by Conduit Service (CltMngSvc) - Conduit - C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: iPod サービス (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
O23 - Service: OEMRegistrationProgram - Toshiba Corporation - C:\Program Files (x86)\Toshiba\OEM Registration Program\OEMRegistrationProgram.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SaveSenseLive Service (savesenselive) (savesenselive) - SaveSense - C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe
O23 - Service: SaveSenseLive Service (savesenselivem) (savesenselivem) - SaveSense - C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA eco Utility Service - Toshiba Corporation - C:\Program Files\TOSHIBA\Teco\TecoService.exe
O23 - Service: Toshiba Media Server Monitor Service - CyberLink - C:\Program Files (x86)\CyberLink\RZ Player\Kernel\DMS\ToshibaMSMonitorService.exe
O23 - Service: Toshiba Media Server Service - CyberLink - C:\Program Files (x86)\CyberLink\RZ Player\Kernel\DMS\ToshibaMSServer.exe
O23 - Service: TPCHKarteSVC - Toshiba Corporation - C:\Program Files (x86)\TOSHIBA\TKRTL\TPCHKarteSVC.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: View Password (ViewPassword) - Unknown owner - C:\Program Files (x86)\View-Password\ViewPassword152.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10786 bytes
<CCleaner-portable>
Adobe AIR Adobe Systems Incorporated 2013/09/12 3.8.0.870
Adobe Reader XI (11.0.03) - Japanese Adobe Systems Incorporated 2013/09/12 149 MB 11.0.03
Apple Application Support Apple Inc. 2014/02/08 93.2 MB 3.0
Apple Mobile Device Support Apple Inc. 2014/02/08 21.3 MB 7.1.0.32
Apple Software Update Apple Inc. 2014/02/08 2.38 MB 2.1.3.127
Atheros Driver Installation Program Atheros 2014/01/13 10.0
Bonjour Apple Inc. 2014/02/08 2.00 MB 3.0.0.10
CyberLink MediaShow 6 CyberLink Corp. 2014/01/14 672 MB 6.0.5617
DigiBookBrowser Version 1.5.3.87 LECRE Inc. 2013/09/12 8.53 MB 1.5.3.87
DVD Shrink 3.2 DVD Shrink 2014/02/08
dynabookランチャー用バナー 2014/01/14
ebi.BookReader4 eBOOK Initiative Japan Co., Ltd. 2013/09/12 14.7 MB 4.02.14
ebi.SampleContents eBOOK Initiative Japan Co., Ltd. 2013/09/12 4.0.2.14_MSI_T
Evernote v. 5.1.2 Evernote Corp. 2014/02/08 145 MB 5.1.2.2387
FilesFrog Update Checker 2014/02/08
fst_jp_46 FREESOFTTODAY 2014/02/08 11.2 MB
Google Toolbar for Internet Explorer Google Inc. 2014/02/01 7.5.4805.320
i-フィルター 6.0 デジタルアーツ株式会社 2013/09/12 30.3 MB 6.00.24.0122
Intel(R) Management Engine Components Intel Corporation 2014/01/13 9.5.14.1724
Intel(R) Processor Graphics Intel Corporation 2013/10/26 10.18.10.3308
iTunes Apple Inc. 2014/02/08 216 MB 11.1.4.62
LoiLoScope 2 LoiLo inc 2013/09/12 166 MB 2.5.3.2
Microsoft Office Microsoft Corporation 2014/01/14 296 MB 15.0.4454.1510
Microsoft SkyDrive Microsoft Corporation 2014/02/02 25.1 MB 16.4.6013.0910
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2014/02/08 4.84 MB 8.0.61001
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2014/01/14 10.2 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2014/01/14 1.18 MB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2014/02/08 8.79 MB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2014/01/13 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2014/01/13 4.61 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 Microsoft Corporation 2014/01/14 20.4 MB 11.0.50727.1
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 Microsoft Corporation 2014/01/14 17.3 MB 11.0.50727.1
Microsoft Visual C++ 2013 Preview Redistributable (x64) - 12.0.20617 Microsoft Corporation 2014/01/14 20.6 MB 12.0.20617.1
Microsoft Visual C++ 2013 Preview Redistributable (x86) - 12.0.20617 Microsoft Corporation 2014/01/14 17.3 MB 12.0.20617.1
Norton Internet Security Symantec Corporation 2014/02/01 21.1.0.18
OEM Registration Program Toshiba Corporation 2014/01/14 516 KB 1.1.0
PCあんしん点検ユーティリティ Toshiba Corporation 2014/01/14 3.52 MB 2.00.01.01
PC引越ナビ 東芝情報機器株式会社 2013/09/12 12.7 MB 5.0.4
Qualcomm Atheros Bluetooth Suite (64) Qualcomm Atheros 2014/01/13 1.82 MB 8.0.1.306
Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver Qualcomm Atheros Inc. 2014/01/13 2.1.0.21
Realtek Card Reader Realtek Semiconductor Corp. 2014/01/13 6.2.9200.39052
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2014/01/13 6.0.1.7023
Roxio Creator LJ Roxio 2014/01/14 259 MB 12.2.34.25
RZスイート express CyberLink Corp. 2014/01/14 131 MB 1.8.01518
Search Protect Conduit 2014/02/08 2.9.65.0
SpeedyPC Pro SpeedyPC Software 2014/02/08 3.1.13.0
Synaptics Pointing Device Driver Synaptics Incorporated 2014/01/13 46.4 MB 17.0.8.21
TOSHIBA Active Display Off Toshiba Corporation 2014/01/14 17.7 MB 1.3.2.0
TOSHIBA Audio Enhancement Toshiba Corporation 2014/01/14 1.81 MB 2.0.17.0
TOSHIBA Desktop Apps Menu Toshiba Corporation 2014/01/14 600 KB 1.02.01.6407
TOSHIBA Display Utility Toshiba Corporation 2014/01/14 31.9 MB 1.1.5.0
TOSHIBA eco Utility Toshiba Corporation 2014/01/14 24.6 MB 2.2.0.6404
TOSHIBA Function Key Toshiba Corporation 2014/01/13 37.5 MB 1.1.0002.6401
TOSHIBA Manual TOSHIBA CORPORATION 2014/01/14 29.2 MB 0148.01.3001
TOSHIBA PalaDouga TOSHIBA CORPORATION 2013/09/12 478 MB 2013.0201.0002
TOSHIBA Password Utility Toshiba Corporation 2013/09/12 3.36 MB v2.1.0.14
TOSHIBA PC Health Monitor Toshiba Corporation 2014/01/14 28.5 MB 1.9.09.6400
TOSHIBA Recovery Media Creator Toshiba Corporation 2013/09/12 3.1.02.55065006
TOSHIBA Service Station Toshiba Corporation 2014/01/14 2.88 MB 2.6.8
TOSHIBA Speech Synthesis TOSHIBA CORPORATION 2014/01/14 65.0 MB 1.5.2.0
TOSHIBA System Driver Toshiba Corporation 2014/01/13 5.68 MB 1.00.0030
TOSHIBA System Settings Toshiba Corporation 2014/01/13 4.02 MB 1.1.2.32001
TOSHIBA VIDEO PLAYER Toshiba Corporation 2014/01/14 46.7 MB 5.3.27.102
Update for Japanese Microsoft IME Postal Code Dictionary Microsoft Corporation 2014/02/08 4.53 MB 15.0.1157
Update for Japanese Microsoft IME Standard Dictionary Microsoft Corporation 2014/02/08 40.3 MB 16.0.668.1
Update for Japanese Microsoft IME Standard Extended Dictionary Microsoft Corporation 2014/02/08 11.5 MB 15.0.1215
Update for Japanese Microsoft IME Trending Words Dictionary Microsoft Corporation 2014/02/08 13.0 KB 16.0.659.1
View Password View Password 2014/02/08
Windows Live Essentials Microsoft Corporation 2014/02/02 16.4.3508.0205
WinZip 17.5 WinZip Computing, S.L. 2013/09/12 168 MB 17.5.10480
いつもNAVI PC ZENRIN 2013/09/12 6.1.2
おたすけナビ 東芝情報機器株式会社 2013/09/12 16.7 MB 8.0.0
てぶらナビ Toshiba Corporation 2014/01/14 21.3 MB 1.6.6.5
ぱらちゃんV2.3 Toshiba Corporation 2013/09/12 33.8 MB 2.3.17
デジタル貸金庫 デスクトップ版 Toshiba Corporation 2014/01/14 5.98 MB 1.05.000
バックアップナビ クラウド 東芝情報機器株式会社 2013/09/12 5.08 MB 1.0.0
動画で解決!操作ガイド 東芝情報機器株式会社 2013/09/12 15.9 MB 3.0.4
動画で解決!操作ガイド-コンテンツ- 東芝情報機器株式会社 2013/09/12 148 KB 3.0.4
東芝ジェスチャコントローラ TOSHIBA CORPORATION 2014/01/14 25.1 MB 3.1.7.0
東芝プレイスガジェット V4 TOSHIBA CORPORATION 2014/02/01 3.06 MB 4.00.0004
楽しもう!Office ライフ Microsoft Corporation 2014/01/14 636 KB 1.0.0
筆ぐるめ 20 富士ソフト株式会社 2013/09/12 738 MB 20.00.0009
スパイウェアの対処方法をご教授ください
- nori
- 2014/02/09 (Sun) 00:27:48