悪代官の伏魔殿掲示板
プラウザが勝手に開かれます。
はじめまして。
数日前から、edgeを開くとヒントが180ページ以上開かれてしまいます。
対処方法がわからないので相談させていただきました。
よろしくおねがいいたします。
下記にHJTとCCのログを貼り付けましたので、よろしくお願いいたします。

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 14:31:50, on 2019/06/22
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.17134.0001)


Boot mode: Normal

Running processes:
C:\Users\sho50\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files\WinZip\WZUpdateNotifier.exe
C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe
C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingServiceTrayIcon.exe
C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\sho50\AppData\Local\Microsoft\Windows\INetCache\IE\YPUKV64R\HijackThis.exe

F2 - REG:system.ini: UserInit=
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: Trend ツールバー - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX2] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe /FORCE
O4 - HKLM\..\Run: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
O4 - HKCU\..\Run: [OneDrive] "C:\Users\sho50\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [iCloudServices] "C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe"
O4 - Global Startup: WinZip Preloader.lnk = C:\Program Files\WinZip\WzPreloader.exe
O4 - Global Startup: WinZip アップデート通知ツール.lnk = C:\Program Files\WinZip\WZUpdateNotifier.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
O18 - Protocol: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Trend Micro Solution Platform (Amsp) - Trend Micro Inc. - C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
O23 - Service: Bonjour サービス (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_8376c6862d7a4bc1\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_8376c6862d7a4bc1\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google Inc. - C:\Program Files (x86)\Google\Chrome\Application\74.0.3729.169\elevation_service.exe
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem28.inf,%SERVICE_NAME%;Intel Bluetooth Service (ibtsiva) - Unknown owner - C:\WINDOWS\system32\ibtsiva (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_8376c6862d7a4bc1\igfxCUIService.exe
O23 - Service: Canon インクジェットプリンタ/スキャナ/ファクス使用状況調査プログラム (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Online Connect - Intel Corporation - C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe
O23 - Service: Intel(R) Online Connect Helper - Intel Corporation - C:\Program Files\Intel\Intel(R) Online Connect\iocHelperService.exe
O23 - Service: Intel(R) Online Connect Software Asset Manager - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe
O23 - Service: Intel(R) Online Connect Access Legacy CS Loader (Intel(R) TechnologyAccessLegacyCSLoader) - Intel(R) Corporation - C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe
O23 - Service: Intel(R) Online Connect Access (Intel(R) TechnologyAccessService) - Intel(R) Corporation - C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LLHDClient - Intercom, Inc. - C:\Program Files (x86)\Intercom\LAPLINK HelpDesk Client\LLHDClient.exe
O23 - Service: LLHDCloader - Intercom, Inc. - C:\Program Files (x86)\Intercom\LAPLINK HelpDesk Client\LLHDCldr.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: OEMRegistrationProgram - Toshiba Client Solutions Co., Ltd. - C:\Program Files (x86)\Toshiba\OEM Registration Program\OEMRegistrationProgram.exe
O23 - Service: Platinum Host Service - Trend Micro Inc. - C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - CyberLink - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: SMITS - Unknown owner - C:\Windows\SysWOW64\SMITSC.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: The Desktop Weather Service (TheDesktopWeatherService) - Unknown owner - C:\Program Files (x86)\WeatherTool\2.0.1.5000020\WeatherService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: TMachInfo - Toshiba Client Solutions Co., Ltd. - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA eco Utility Service - Toshiba Client Solutions Co., Ltd. - C:\Program Files\TOSHIBA\Teco\TecoService.exe
O23 - Service: TOSRMService - Toshiba Client Solutions Co., Ltd. - C:\Program Files (x86)\TOSHIBA\TOSHIBA System Driver\RMService.exe
O23 - Service: TPCH Service (TPCHSrv) - Toshiba Client Solutions Co., Ltd. - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: TStationSrv - Toshiba Client Solutions Co., Ltd. - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TStationSrv.exe
O23 - Service: TVコネクトスイート ダビングサービス (TVCSDubbingService) - sMedio Inc - C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingService.exe
O23 - Service: @oem17.inf,%WBFService_SvcDesc%;Synaptics FP WBF Policy Service (valWBFPolicyService) - Unknown owner - C:\WINDOWS\system32\valWBFPolicyService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%systemroot%\system32\xbgmsvc.exe,-100 (xbgm) - Unknown owner - C:\WINDOWS\system32\xbgmsvc.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - IntelR Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 14064 bytes

3D Builder Microsoft Corporation 2019/05/29 16.1.1431.0
3D ビューアー Microsoft Corporation 2019/03/07 6.1903.4012.0
Apple Application Support(32 ビット) Apple Inc. 2018/03/30 137 MB 6.4
Apple Application Support(64 ビット) Apple Inc. 2018/03/30 153 MB 6.4
Apple Software Update Apple Inc. 2017/12/21 7.31 MB 2.5.0.1
Bluetooth(R) Link Toshiba Client Solutions Co., Ltd. 2017/02/19 41.8 MB 5.4.1.1
Bonjour Apple Inc. 2017/03/20 3.28 MB 3.1.0.1
Candy Crush Soda Saga king.com 2019/05/29 1.140.300.0
Canon Easy-WebPrint EX Canon Inc. 2018/06/09 1.7.0.0
Canon IJ Network Scanner Selector EX2 Canon Inc. 2018/06/09 2.0.5.3
Canon IJ Printer Assistant Tool Canon Inc. 2018/06/09 1.00.3.51
Canon IJ Scan Utility Canon Inc. 2018/06/09 1.4.0.16
CANON iMAGE GATEWAY 無料会員登録 Canon Inc. 2018/06/09 1.1.0
Canon My Image Garden Canon Inc. 2018/06/09 3.6.1
Canon My Image Garden Design Files Canon Inc. 2018/06/09 3.6.0
Canon Quick Menu Canon Inc. 2018/06/09 2.8.5
Canon TS8130 series MP Drivers Canon Inc. 2018/06/09 1.01
Canon TS8130 series 電子マニュアル(取扱説明書) Canon Inc. 2018/06/09 1.1.0
Canon インクジェットプリンター/スキャナ/ファクス使用状況調査プログラム Canon Inc. 2018/06/09 5.5.0
CCleaner Piriform 2019/06/22 5.58
CyberLink PhotoDirector 7 CyberLink Corp. 2018/06/09 586 MB 7.0.8317.0
CyberLink Power2Go 8 CyberLink Corp. 2017/02/19 98.9 MB 8.0.0.4707
CyberLink PowerDirector 14 CyberLink Corp. 2018/06/09 1.45 GB 14.0.3411.0
CyberLink Screen Recorder CyberLink Corp. 2018/06/09 26.5 MB 1.0.0.2321
CyberLink SeeQVault Player CyberLink Corp. 2017/02/19 73.6 MB 12.1.6106.55
dynabookサウンドエンジン by Audyssey Audyssey Laboratories 2017/02/19 2.69 MB 1.1.58.0
Facebook Facebook Inc 2019/03/27 186.2191.46880.0
GOM Player GOM & Company 2019/04/27 2.3.40.5302
Google Chrome Google Inc. 2019/05/23 373 MB 74.0.3729.169
Groove ミュージック Microsoft Corporation 2019/04/04 10.19031.11411.0
HEVC Video Extensions from Device Manufacturer Microsoft Corporation 2019/01/05 1.0.13209.0
i-フィルター 6.0 デジタルアーツ株式会社 2017/02/19 79.9 MB 6.00.39.0150
iCloud Apple Inc. 2018/03/30 153 MB 7.4.0.111
Intel(R) Management Engine Components Intel Corporation 2017/02/19 11.6.0.1039
Intel(R) Network Connections Drivers Intel 2018/06/09 1.78 MB 21.1
Intel(R) Processor Graphics Intel Corporation 21.20.16.4550
Intel(R) Rapid Storage Technology Intel Corporation 2017/02/19 15.2.0.1020
iTunes Apple Inc. 2019/05/30 12095.7.41059.0
JSバックアップ(64bit) 株式会社情報スペース 2017/02/19 35.3 MB 2.0.4.0
LAPLINK ヘルプデスク クライアント Intercom, Inc. 2018/06/09 17.6 MB 2.16
Lhaplus 2018/06/24
LINE LINE Corporation 2019/06/20 5.17.2.0
LoiLoScope 2 LoiLo inc 2017/02/19 166 MB 2.5.5.0
Media Player by sMedio TrueLink+ sMedio 2019/02/02 3.4.33.0
Microsoft Office Home and Business Premium - ja-jp Microsoft Corporation 2019/06/15 1.01 GB 16.0.11629.20246
Microsoft OneDrive Microsoft Corporation 2019/06/08 130 MB 19.086.0502.0006
Microsoft Pay Microsoft Corporation 2018/03/29 2.2.18065.0
Microsoft Solitaire Collection Microsoft Studios 2019/06/17 4.4.6132.0
Microsoft Sticky Notes Microsoft Corporation 2019/05/24 3.6.73.0
Microsoft Store Microsoft Corporation 2019/06/05 11905.1001.4.0
Microsoft Store エクスペリエンス ホスト Microsoft Corporation 2019/01/31 11811.1001.18.0
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2017/02/19 6.96 MB 8.0.59193
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2017/02/19 1.10 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2017/02/19 4.45 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2017/02/19 3.80 MB 9.0.30729.4148
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2017/02/19 1.04 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2017/02/19 3.74 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Corporation 2018/06/09 20.5 MB 11.0.61030.0
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 2018/06/09 17.3 MB 11.0.61030.0
Microsoft ニュース Microsoft Corporation 2019/04/04 4.30.10924.0
Minecraft Microsoft Studios 2019/05/24 1.11.402.0
OEM Registration Program Toshiba Client Solutions Co., Ltd. 2017/02/19 8.00 KB 1.2.1
Office Microsoft Corporation 2019/03/26 18.1903.1152.0
OneNote Microsoft Corporation 2019/06/15 16001.11727.20076.0
PC引越ナビ Toshiba Client Solutions Co., Ltd. 2017/02/19 24.0 MB 5.2.4
People Microsoft Corporation 2019/04/17 10.1902.633.0
Print 3D Microsoft Corporation 2019/04/24 3.3.791.0
Realtek Card Reader Realtek Semiconductor Corp. 2017/02/19 11.0 MB 10.0.14393.31231
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2018/06/09 51.5 MB 6.0.1.8351
Skype Skype 2019/06/03 14.46.60.0
sMedio TrueLink+ Phone sMedio 2019/03/07 2.0.67.0
Synaptics Pointing Device Driver Synaptics Incorporated 2018/06/09 46.4 MB 19.4.3.182
Synaptics WBF DDK 5111 Synaptics 2017/02/19 26.0 MB 4.5.329.0
The Desktop Weather 2.0.1.5000020 Baidu Japan Inc. 2019/03/15 2.0.1.5000020
TOSHIBA Blu-ray Disc Player Toshiba Client Solutions Co., Ltd. 2017/02/19 105 MB 3.0.0.23
TOSHIBA eco Utility Toshiba Client Solutions Co., Ltd. 2017/02/19 50.6 MB 3.1.3.6401
TOSHIBA Manual Toshiba Client Solutions Co., Ltd. 2017/02/19 1.42 MB 0235.01.4101
TOSHIBA PalaDouga Toshiba Client Solutions Co., Ltd. 2017/02/19 933 MB 2016.0201.0002
TOSHIBA Password Utility Toshiba Client Solutions Co., Ltd. 2017/02/19 16.2 MB 9.03.04.01
TOSHIBA Recovery Media Creator Toshiba Client Solutions Co., Ltd. 2017/02/19 24.0 MB 3.4.00.9001
TOSHIBA Service Station Toshiba Client Solutions Co., Ltd. 2017/02/19 30.2 MB 5.0.2.6403
TOSHIBA System Driver Toshiba Client Solutions Co., Ltd. 2017/02/19 13.8 MB 2.03.0003.03
TOSHIBA System Settings Toshiba Client Solutions Co., Ltd. 2017/02/19 88.8 MB 3.1.6.6400
Trend Micro Titanium トレンドマイクロ株式会社 2019/02/17 450 MB 15.0
TruRecorder Toshiba Client Solutions Co., Ltd. 2019/04/17 2.2.38.0
TVコネクトスイート sMedio 2019/01/26 2.4.51.0
TVコネクトスイート ダビング設定ユーティリティ sMedio Inc. 2017/02/19 9.53 MB 1.0.1.2
Twitter Twitter Inc. 2018/09/09 6.1.4.1000
Update for Windows 10 for x64-based Systems (KB4023057) Microsoft Corporation 2019/06/22 1.41 MB 2.59.0.0
Web メディア拡張機能 Microsoft Corporation 2018/12/13 1.0.13321.0
WinZip 20.5 WinZip Computing, S.L. 2017/02/19 757 MB 20.5.12148
Xbox Game bar Microsoft Corporation 2019/06/15 1.42.12001.0
Xbox Game Speech Window Microsoft Corporation 2017/12/15 1.21.13002.0
Xbox gaming overlay Microsoft Corporation 2018/10/29 1.16.1012.0
Xbox Identity Provider Microsoft Corporation 2019/06/08 12.54.4001.0
Xbox Live Microsoft Corporation 2018/12/10 1.24.10001.0
Xbox 本体コンパニオン Microsoft Corporation 2019/06/04 48.54.3003.0
あんしんWeb by Internet SagiWall for dynabook BB繧ス繝輔ヨ繧オ繝シ繝薙せ譬ェ蠑丈シ夂、セ 2019/01/15 2.2.0.5
おたすけナビ Toshiba Client Solutions Co., Ltd. 2017/02/19 36.5 MB 8.1.5
ぱらちゃんV2.3 Toshiba Client Solutions Co., Ltd. 2017/02/19 10.0 MB 2.3.50
ぱらちゃんカフェ 譚ア闃晄ュ蝣ア讖溷勣譬ェ蠑丈シ夂、セ 2017/03/19 1.1.0.3
アプリ インストーラー Microsoft Corporation 2019/05/29 1.0.31351.0
アラーム & クロック Microsoft Corporation 2019/05/02 10.1903.1006.0
インテル(R) ワイヤレス Bluetooth(R) Intel Corporation 2017/02/19 17.7 MB 19.11.1639.0649
インテル® PROSet/Wireless ソフトウェア Intel Corporation 2018/12/07 366 MB 20.90.0
ウイルスバスター クラウド トレンドマイクロ株式会社 2019/02/17 450 MB 15.0
カメラ Microsoft Corporation 2019/05/09 2019.425.30.0
シュフーチラシアプリ for TOSHIBA TOPPAN PRINTING CO.,LTD. 2017/03/28 1.4.2.0
トレンドマイクロ Airサポート トレンドマイクロ株式会社 2019/02/17 6.0
バックアップナビ クラウド Toshiba Client Solutions Co., Ltd. 2017/11/05 10.8 MB 1.4.5
パラダイス・ベイ king.com 2018/12/15 3.9.0.0
ヒント Microsoft Corporation 2018/10/09 6.15.12641.0
フィードバック Hub Microsoft Corporation 2019/04/08 1.1811.10862.0
フォト Microsoft Corporation 2019/06/08 2019.19041.16510.0
ペイント 3D Microsoft Corporation 2019/04/12 5.1904.8017.0
ボイス レコーダー Microsoft Corporation 2019/03/26 10.1902.633.0
マップ Microsoft Corporation 2019/04/11 5.1902.843.0
メッセージング Microsoft Corporation 2019/05/24 4.1901.10241.1000
メール/カレンダー Microsoft Corporation 2019/05/31 16005.11629.20174.0
モバイル通信プラン Microsoft Corporation 2019/05/22 5.1905.1232.0
問い合わせ Microsoft Corporation 2019/04/19 10.1706.20381.0
天気 Microsoft Corporation 2019/02/12 4.28.10351.0
思い出フォトビューア 譚ア闃昴け繝ゥ繧、繧「繝ウ繝医た繝ェ繝・繝シ繧キ繝ァ繝ウ 譬ェ蠑丈シ夂、セ 2019/04/24 5.2.28.0
思い出フォトビューア クッキングプラス 譚ア闃昴け繝ゥ繧、繧「繝ウ繝医た繝ェ繝・繝シ繧キ繝ァ繝ウ 譬ェ蠑丈シ夂、セ 2019/04/24 2.2.24.0
日本語 ローカル エクスペリエンス パック Microsoft Corporation 2019/06/12 17134.35.50.0
映画 & テレビ Microsoft Corporation 2019/04/04 10.19031.11411.0
東芝スクリーンミラーリング for Windows PC/タブレット APUSONE Technology Inc. 2017/02/19 4.31 MB 1.1.17.9
楽しもう!Office ライフ Microsoft Corporation 2017/07/28 1.0.34.0
楽天gateway 讌ス螟ゥ譬ェ蠑丈シ夂、セ 2017/07/31 3.1.3.0
筆ぐるめ 24 富士ソフト株式会社 2017/02/19 1.36 GB 24.00.0103
電卓 Microsoft Corporation 2019/06/12 10.1904.42.0
  • sho
  • 2019/06/22 (Sat) 14:53:19
The Desktop Weather←これの削除から
こんばんは。
ここの管理人の悪代官です。
まずは説明をログを見せていただきました。

>数日前から、edgeを開くとヒントが180ページ以上開かれてしまいます。

確かに妙な症状ですがログを見ると元凶かどうかは断定できないもののよくない点はいくつか見つかってます。
順番に調べながら進めましょうか。

まず最初にお伝えしておきます。
見てのとおり現在相談者さん多数のため、相談受けてから皆さんに順番にレスできるまで、毎回1日かそれ以上かかる可能性もあるので、すみませんがご了承ください。

では以下の説明をよく見てから、順番に作業をお願いします。
既に準備した物もあるはずですが、一応説明を再度見ておいてください。

隠しファイルと拡張子を表示設定にしてください(やり方↓)
http://pasofaq.jp/windows/mycomputer/hiddenfile.htm
http://support.microsoft.com/kb/978449/ja

下記のツールをダウンロードして、基本の使い方を把握しておいてください。
ただし、配布サイトで他のアプリをダウンロードしろと勧めてくるような広告も出てきたらそれらは絶対にクリックしないでください。
「GeekUninstaller」(通称:GU)
説明ページ↓
http://www.gigafree.net/system/install/geekuninstaller.html
ダウンロード↓
http://www.geekuninstaller.com/download
「download free」をクリック、保存後、解凍してください。
片付ける時はフォルダごと手動で削除してください。

「CCleaner」(通称:CC)
説明↓
http://www.gigafree.net/system/clean/ccleaner.html
http://note.chiebukuro.yahoo.co.jp/detail/n178757
ダウンロード↓
https://www.piriform.com/ccleaner/builds
最新バージョンの「ポータブル版」(Portable)をダウンロード後、解凍して起動してください。
片付けるときはそのフォルダを削除すればいいです。

ここで重要な注意です。
CCは本来は高い性能を持つメンテナンスソフトですが、間違った使い方すると
【Windowsにダメージを与えてしまうおそれもある】
ので、ここでは解析ツールとしてのみ使います。
説明をしっかり読んで、自分が指示した以外の操作はしないように。

準備できたら作業開始です。
なお、このあとの作業で探しても見つからないものはスルーして進めていいですが、指示した対象外の物は絶対にいじらないようによく見て作業してください。

また、作業のうえで削除指示するものもあるはずですが、ご自身で必要として入れたものがあればそれの削除は保留して、次のレスでその旨を教えてください。

最初にWindowsUpdateの確認して、必要な更新があればそれを全部更新してください。
ですがそこで更新ができないようならこの後に説明する作業はせずに更新失敗の旨をレスで教えてください。
WUが正常にできなくすることで、感染の解析処置を阻害してくる危険なマルウェアが激増しているためです。
Windowsの各種更新(WindowsUpdate)は常に最新に適用しておかないと、それだけで危険な感染はすぐにでも起きますよ。

なお、Windows10への更新はユーザー自身がよほど必要でなければ非推奨です。
http://www.japan-secure.com/entry/Windows_Update_7.html
http://www.japan-secure.com/entry/how_to_suppress_the_free_upgrade_of_Windows_10.html

少なくとも下記のアプリは旧バージョンです。

>WinZip 20.5 WinZip Computing, S.L. 2017/02/19 757 MB 20.5.12148

各種アプリの更新を怠っただけでも、脆弱性を悪用されて深刻な感染はあっさり起きます。
使うなら最新版に更新してください。使わないアプリならアンインストールが安全です。
他にも旧バージョンないか調べて、あれば同様に更新するか、アンインストールしてください。

それと下記フィルタリングソフトの有効期限を確認です。
>i-フィルター 6.0 デジタルアーツ株式会社 2017/02/19 79.9 MB 6.00.39.0150

これ自体はセキュリティ的にも有用なものですが、期限が切れたものだとまったく役に立ちませんので、その場合はアンインストールしたほうが安全です。
次回レス時に期限を教えてください。まだ期限が残っているならそのまま使っておいて構いません。

ここでWindowsの標準機能である「システムの復元」での復元ポイントをひとつ、手動で作成しておいてください。
これはこの後の作業で、間違って対象外のものをいじってしまうとそれだけでWindowsに深刻な不具合を起こすこともあるので、万一の際に復元可能にしておくためです。
http://windows.microsoft.com/ja-jp/windows7/create-a-restore-point

今度はPCをセーフモードで起動してください(やり方↓)
http://www.pc-master.jp/sousa/s-safemode.html
Win8の場合は以下を参考に。
http://freesoft.tvbok.com/win8/tips-and-tools/safemode.html

セーフモードでGUを使って、下記をアンインストールしてください。
>GOM Player GOM & Company 2019/04/27 2.3.40.5302

>The Desktop Weather 2.0.1.5000020 Baidu Japan Inc. 2019/03/15 2.0.1.5000020

これらは当掲示板の過去相談でも色々とトラブルに絡んでいたことが多いモノです。
ご自身で入れた覚えがなくいつの間にか入っていたなら遠慮なく削除していいでしょう。

HJTを起動させ、スキャンを行ってください。
スキャン結果が表示されましたら、以下の項目にチェックを入れてください。
ただし、特にHJTでの作業は一歩間違えれば簡単にPCが起動しなくなるため、こちらが指示した以外のものは絶対にチェックを入れないでください。
>O23 - Service: The Desktop Weather Service (TheDesktopWeatherService) - Unknown owner - C:\Program Files (x86)\WeatherTool\2.0.1.5000020\WeatherService.exe

必要な項目すべてにチェックが入りましたら、Fix checkedをクリックしてください。
探しても見つからないものはスルーして進めていいです。

マイコンピュータのCドライブを開いて、下記のフォルダを探して、見つかればゴミ箱に削除してください。
C:\Program Files (x86)\WeatherTool
探してもなくなっていればいいですが、見つかったのに削除できないときは無理に進めずキャンセルしてそのことを次回レス時に教えてください。

ここでPCを通常モードで再起動してから、スタートメニューの「アクセサリ」→「システムツール」から「ディスククリーンアップ」を起動してください。
起動したら対象ドライブでCドライブを選択してスキャンして、表示された中の「ダウンロードされたプログラムファイル」「インターネット一時ファイル」「一時ファイル」の項目だけチェックを入れてから「OK」「ファイルの削除」を押してください。
これを実行すると選択した部分のゴミファイルが掃除されます。

これを実行することで作業時にスキャンで検出される無駄なゴミファイルも減るのでその分かなり時間や解析も楽になるのです。
「ごみ箱」など他の項目にチェックしないのは、間違って正常なファイルを削除しないためと、もし正常なファイルを削除してごみ箱に入れても戻せるようにするための措置です。

続いてCCを起動してください。
起動したら、「ツール」→」「スタートアップ」→「Windows」タブを開いてください。
そこで右下の「テキストとして保存」を押すと、表示の内容がログとして保存できるので、ログをデスクトップにでも保存しておいてください。

次に「スケジュールされたタスク」タブと「コンテキストメニュー」タブのログも同じ要領で保存してください。

続いて今度はCC画面の左側にある「Browser Plugin」の項目から「InternetExplorer」タブ以下の各タブも順番に開いて、そのログもとっておいてください。

CCの各ログをとったらCCは終了してください。

このあとブラウザを起動して、数時間ほどPC状態を様子見したあと、あらたにHJTとCCでのインストール情報ログを取り直してください。

取り直した両ログと、CCの各ログを返信に貼って、状態報告とともにレスください。
それらを見てから続きの作業を指示します。

上記作業で本題の異常が治まるとは思えませんが、もし治まってもそこで解決にはなりませんから早合点せずレスをお願いします
  • 悪代官
  • 2019/06/22 (Sat) 21:29:20
Re: プラウザが勝手に開かれます。
レスありがとうございます。
セーフモードができず時間がかかってしまいました。

HJTのthe desktop weather はなかったので、HJTはスキャンできませんでした。
CCは行ったので乗せさせていただきます。

WINDOWS
有効 HKCU:Run CCleaner Smart Cleaning Piriform Software Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run OneDrive Microsoft Corporation "C:\Users\sho50\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
有効 HKLM:Run CLMLServer_For_P2G8 CyberLink "C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
有効 HKLM:Run SecurityHealth Microsoft Corporation %ProgramFiles%\Windows Defender\MSASCuiL.exe
有効 HKLM:Run TCrdMain Toshiba Client Solutions Co., Ltd. C:\Program Files\Toshiba\System Setting\TCrdMain_Win8.exe
有効 HKLM:Run TecoResident Toshiba Client Solutions Co., Ltd. C:\Program Files\TOSHIBA\Teco\TecoResident.exe
有効 HKLM:Run TosWaitSrv Toshiba Client Solutions Co., Ltd. %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
有効 HKLM:Run Trend Micro Client Framework Trend Micro Inc. "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe"
有効 HKLM:Run Trend Micro Titanium Trend Micro Inc. "C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe" -ReFlush "none" "none"
有効 HKLM:Run VizorHtmlDialog.exe Trend Micro Inc. "C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe" "DEF" "EULA" "C:\Program Files\Trend Micro\Titanium\www\Installer.cmpt\resources\common.lproj\preinstall_01_welcome_trial.html" -set Step Trial -set Skip 1


スケジュールされたタスク
有効 Task CCleanerSkipUAC Piriform Software Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7 Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe" --automatic
有効 Task IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7-Logon Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe" --automatic
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic
有効 Task OneDrive Standalone Update Task-S-1-5-21-1460922254-185261916-941432131-1001 Microsoft Corporation %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
有効 Task RTKCPL Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
有効 Task Service Station Toshiba Client Solutions Co., Ltd. "C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe" /hide
有効 Task TPIP Toshiba Client Solutions Co., Ltd. "C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe"

コンテキストメニュー

有効 Directory PowerShell ウィンドウをここに開く(S) powershell.exe -noexit -command Set-Location '%V'
有効 Directory ファイルの所有権
有効 Drive Lhaplus C:\Program Files (x86)\Lhaplus\LplsShlx64.dll
有効 Drive PowerShell ウィンドウをここに開く(S) powershell.exe -noexit -command Set-Location '%V'
有効 File Lhaplus C:\Program Files (x86)\Lhaplus\LplsShlx64.dll
有効 File {48F45200-91E6-11CE-8A4F-0080C81A28D4} Trend Micro Inc. C:\Program Files\Trend Micro\UniClient\UiFrmwrk\tmdshell.dll
有効 Folder Lhaplus C:\Program Files (x86)\Lhaplus\LplsShlx64.dll
有効 Folder {48F45200-91E6-11CE-8A4F-0080C81A28D4} Trend Micro Inc. C:\Program Files\Trend Micro\UniClient\UiFrmwrk\tmdshell.dll

browserPlugins(IE)
有効 Extension Lync Click to Call Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll
有効 Helper Skype for Business Browser Helper Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll

browserPlugins(firefox)
有効 App Gmail 8.2 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0
有効 App Google ドライブ 14.2 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.2_1
有効 App YouTube 4.2.8 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0
有効 Extension Google オフライン ドキュメント 1.7 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_0
有効 Extension スプレッドシート 1.2 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0
有効 Extension スライド 0.10 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0
有効 Extension ドキュメント 0.10 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1

windows(数時間後)
有効 HKCU:Run CCleaner Smart Cleaning Piriform Software Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run OneDrive Microsoft Corporation "C:\Users\sho50\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
有効 HKLM:Run CLMLServer_For_P2G8 CyberLink "C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
有効 HKLM:Run SecurityHealth Microsoft Corporation %ProgramFiles%\Windows Defender\MSASCuiL.exe
有効 HKLM:Run TCrdMain Toshiba Client Solutions Co., Ltd. C:\Program Files\Toshiba\System Setting\TCrdMain_Win8.exe
有効 HKLM:Run TecoResident Toshiba Client Solutions Co., Ltd. C:\Program Files\TOSHIBA\Teco\TecoResident.exe
有効 HKLM:Run TosWaitSrv Toshiba Client Solutions Co., Ltd. %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
有効 HKLM:Run Trend Micro Client Framework Trend Micro Inc. "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe"
有効 HKLM:Run Trend Micro Titanium Trend Micro Inc. "C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe" -ReFlush "none" "none"
有効 HKLM:Run VizorHtmlDialog.exe Trend Micro Inc. "C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe" "DEF" "EULA" "C:\Program Files\Trend Micro\Titanium\www\Installer.cmpt\resources\common.lproj\preinstall_01_welcome_trial.html" -set Step Trial -set Skip 1

スケジュールされたタスク(数時間後)
有効 Task CCleanerSkipUAC Piriform Software Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7 Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe" --automatic
有効 Task IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7-Logon Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe" --automatic
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic
有効 Task OneDrive Standalone Update Task-S-1-5-21-1460922254-185261916-941432131-1001 Microsoft Corporation %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
有効 Task RTKCPL Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
有効 Task Service Station Toshiba Client Solutions Co., Ltd. "C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe" /hide
有効 Task TPIP Toshiba Client Solutions Co., Ltd. "C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe"


コンテキストメニュー(数時間後)
有効 Directory PowerShell ウィンドウをここに開く(S) powershell.exe -noexit -command Set-Location '%V'
有効 Directory ファイルの所有権
有効 Drive Lhaplus C:\Program Files (x86)\Lhaplus\LplsShlx64.dll
有効 Drive PowerShell ウィンドウをここに開く(S) powershell.exe -noexit -command Set-Location '%V'
有効 File Lhaplus C:\Program Files (x86)\Lhaplus\LplsShlx64.dll
有効 File {48F45200-91E6-11CE-8A4F-0080C81A28D4} Trend Micro Inc. C:\Program Files\Trend Micro\UniClient\UiFrmwrk\tmdshell.dll
有効 Folder Lhaplus C:\Program Files (x86)\Lhaplus\LplsShlx64.dll
有効 Folder {48F45200-91E6-11CE-8A4F-0080C81A28D4} Trend Micro Inc.

browserPlugins(数時間後)
有効 Extension Lync Click to Call Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll
有効 Helper Skype for Business Browser Helper Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll

browserPlugins(firefox数時間後)
有効 App Gmail 8.2 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0
有効 App Google ドライブ 14.2 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.2_1
有効 App YouTube 4.2.8 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0
有効 Extension Google オフライン ドキュメント 1.7 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_0
有効 Extension スプレッドシート 1.2 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0
有効 Extension スライド 0.10 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0
有効 Extension ドキュメント 0.10 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1

何か足りない作業等ございましたらご教示いただければと思います。
よろしくお願いいたします。
  • sho
  • 2019/07/09 (Tue) 07:23:42
今度は2つのツールでスキャンを
レスが遅くなってすみません。

>セーフモードができず時間がかかってしまいました。

>HJTのthe desktop weather はなかったので、HJTはスキャンできませんでした

はい、できないところはそのまま飛ばしておいていいです。

CCの各ログを見せてもらいました。
こちらでも今のところは不審な痕跡は見えませんね。
現在はEdgeの異常は続いてますか?
そのことも次回レス時に教えてください。

では続きの作業もお願いしましょう。

次は下記のツールを準備してください。
「AdwCleaner」(通称:AC)
http://www.bleepingcomputer.com/download/adwcleaner/dl/125/
ファイル直リンです。アクセスしてファイルをデスクトップにでも保存しておいてください。
片付けるときは起動後に「設定」欄の最下段にある「アンインストール」ボタンを押せば自動で削除されます。
使い方は下記サイト様に詳しい説明があるのでサンショウウオ↓
http://www.japan-secure.com/entry/adwcleaner.html

Malwarebytes' Anti-Malware(通称・MBAM)
本家サイト
http://www.malwarebytes.org/

ダウンロード
https://www.malwarebytes.org/mwb-download/thankyou/
ファイル直リンです。保存しておいてください。

使い方の説明サイト
http://www.gigafree.net/security/MalwarebytesAnti-MalwareFree.html

準備できたらMBAMをインストールとアップデートまでしておいてください。
ただし、ここではまだスキャンはしないように。

続いてここで一度ACを起動してください。
起動するとまず定義の更新が行われるはずなので、更新だけしてから、それができたらACは一旦終了してください。
ここではスキャンもしなくていいです。

両ツールのアップデートができたらディスククリーンアップを使ってゴミファイルの掃除したあと、PCをセーフモードで再起動してしてください。

続いてPCをセーフモード起動してから、先に一度起動したACを再度起動してください。
起動したら今度は「スキャン」したあと、そのスキャン終了後に検出されたものがあったら「除去」を押してください。
表示された画面で「はい」を選択すると処置開始されます。

処置完了したらそこでPCを通常モードで再起動してください。

再起動後にACのあらたなログが出るので、それをデスクトップにでも保存しておいてください。
ですが、もし作業後にログが出ないorわからない場合はマイコンピュータのCドライブを開くとその直下に以下のような名前のファイルが作成されているので、それがACのログです。
>AdwCleaner[英数字].txt
同じような名前のログが複数ある時は、作成日時が作業処置時のファイルが対象のログです。

ACでの作業ができたら次はMBAMの作業です。
またセーフモード起動してからMBAM起動してスキャンしてください。
MBAM起動したら「スキャン」タブで「カスタムスキャン」選択後、Cドライブを含む全ドライブを選択してください。
それとルートキットスキャンの項目もチェック入れておいてください。

この形でスキャンすると時間はかかりますができるだけ細かくスキャンするためです。

両ツールのスキャンの順番はどちらからでもいいですが、なにか検出されたらそれを選択して「remove」(隔離)したあと、再起動を促す表示が出たらそこで一度PCを再起動してください。
もし再起動表示が出ないときは手動で再起動してください。

またMBAMスキャン終了後、画面右下にその結果を知らせるメッセージが出るので、それを押すとその結果が表示されるはずです。
そこで「ログを保存」を押すとそのログが保存可能になります。
そのログをデスクトップにでも保存しておいてください。
このログ確認が特に重要なので、忘れないようにお願いします。

このあとしばらくPC状態を様子見後、作業後に保存したACとMBAMのログを返信に貼り付けて、それを状態報告とともにレスで見せてください。
  • 悪代官
  • 2019/07/10 (Wed) 22:06:18
Re: プラウザが勝手に開かれます。
レスいただきありがとうございます。
現在はブラウザが出ることはなくなりました。ありがとうございます。
それとは違う事象が出たので報告致します。
Edgeを開くと、上のURL入力欄の下カーソルを連打された状態になる事があります。
今の症状はそれだけです。

保存したACとMBAMのログを乗せさせていただきます
ACが本日名義が二つあったのでどちらも載せます。

MBAMがカスタムする前に一度スキャンしてしまったので、一応二つ乗せさせていただきます。
よろしくお願いいたします。

AdwCleaner[C01]
# -------------------------------
# Malwarebytes AdwCleaner 7.2.1.0
# -------------------------------
# Build: 06-26-2018
# Database: 2018-06-19.4
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 07-13-2019
# Duration: 00:00:01
# OS: Windows 10 Home
# Cleaned: 6
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\Users\Public\Documents\Guid

***** [ Files ] *****

Deleted C:\END

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\jp.hao123.com
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\hao123.com
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\jp.hao123.com
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\hao123.com

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [3534 octets] - [22/06/2019 14:27:51]
AdwCleaner[S01].txt - [2221 octets] - [13/07/2019 12:41:40]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########

AdwCleaner[S01]
# -------------------------------
# Malwarebytes AdwCleaner 7.2.1.0
# -------------------------------
# Build: 06-26-2018
# Database: 2018-06-19.4
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 07-13-2019
# Duration: 00:00:10
# OS: Windows 10 Home
# Scanned: 41296
# Detected: 6


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.Legacy C:\Users\Public\Documents\Guid

***** [ Files ] *****

PUP.Optional.Legacy C:\END

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\jp.hao123.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\hao123.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\jp.hao123.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\hao123.com

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.


AdwCleaner[S00].txt - [3534 octets] - [22/06/2019 14:27:51]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S01].txt ##########


Malwarebytes
www.malwarebytes.com

-ログの詳細-
スキャン日付: 2019/07/13
スキャン時間: 13:15
ログファイル: cc8894b7-a524-11e9-a4de-000000000000.json

-ソフトウェア情報-
バージョン: 3.8.3.2965
コンポーネントバージョン: 1.0.613
パッケージバージョンをアップデート: 1.0.11530
ライセンス: トライアル版

-システム情報-
OS: Windows 10 (Build 17134.885)
CPU: x64
ファイルシステム: NTFS
ユーザー: LAPTOP-QCSS294P\sho50

-スキャン結果の概要-
スキャンタイプ: 脅威のスキャン
スキャン開始日時: マニュアル
結果: 完了
スキャンされたオブジェクト: 294051
検出された脅威: 1
隔離された脅威: 1
経過時間: 1 分 8 秒

-スキャンオプション-
メモリ: 有効
スタートアップ: 有効
ファイルシステム: 有効
アーカイブ: 有効
ルートキット: 無効
ヒューリスティック: 有効
PUP: 検出
PUM: 検出

-スキャンの詳細-
プロセス: 0
(悪意のあるアイテムは検出されませんでした)

モジュール: 0
(悪意のあるアイテムは検出されませんでした)

レジストリキー: 0
(悪意のあるアイテムは検出されませんでした)

レジストリ値: 0
(悪意のあるアイテムは検出されませんでした)

レジストリデータ: 0
(悪意のあるアイテムは検出されませんでした)

データストリーム: 0
(悪意のあるアイテムは検出されませんでした)

フォルダ: 0
(悪意のあるアイテムは検出されませんでした)

ファイル: 1
PUP.Optional.OneSafePCCleaner, C:\USERS\SHO50\DOWNLOADS\ONESAFE_PC_CLEANER.EXE, 隔離済み, [2759], [122326],1.0.11530

物理セクタ: 0
(悪意のあるアイテムは検出されませんでした)

WMI: 0
(悪意のあるアイテムは検出されませんでした)


(end)

MBAMレポート(カスタムスキャン)
Malwarebytes
www.malwarebytes.com

-ログの詳細-
スキャン日付: 2019/07/13
スキャン時間: 13:17
ログファイル: 2b4fca00-a525-11e9-ac93-000000000000.json

-ソフトウェア情報-
バージョン: 3.8.3.2965
コンポーネントバージョン: 1.0.613
パッケージバージョンをアップデート: 1.0.11530
ライセンス: トライアル版

-システム情報-
OS: Windows 10 (Build 17134.885)
CPU: x64
ファイルシステム: NTFS
ユーザー: LAPTOP-QCSS294P\sho50

-スキャン結果の概要-
スキャンタイプ: カスタムスキャン
スキャン開始日時: マニュアル
結果: 完了
スキャンされたオブジェクト: 448175
検出された脅威: 0
隔離された脅威: 0
経過時間: 49 分 9 秒

-スキャンオプション-
メモリ: 有効
スタートアップ: 有効
ファイルシステム: 有効
アーカイブ: 有効
ルートキット: 有効
ヒューリスティック: 有効
PUP: 検出
PUM: 検出

-スキャンの詳細-
プロセス: 0
(悪意のあるアイテムは検出されませんでした)

モジュール: 0
(悪意のあるアイテムは検出されませんでした)

レジストリキー: 0
(悪意のあるアイテムは検出されませんでした)

レジストリ値: 0
(悪意のあるアイテムは検出されませんでした)

レジストリデータ: 0
(悪意のあるアイテムは検出されませんでした)

データストリーム: 0
(悪意のあるアイテムは検出されませんでした)

フォルダ: 0
(悪意のあるアイテムは検出されませんでした)

ファイル: 0
(悪意のあるアイテムは検出されませんでした)

物理セクタ: 0
(悪意のあるアイテムは検出されませんでした)

WMI: 0
(悪意のあるアイテムは検出されませんでした)


(end)
  • sho
  • 2019/07/13 (Sat) 17:16:03
ACが旧バージョンのようです
今日もレスが遅くなってすみません。
さっきまで風呂入ってました(ウチの風呂には由美○おるはいません

両ツールのログを見せてもらいました。
ACのログを見ると、IEに悪名高いhao123が食い込んでましたね。
ACでそれを隔離したならいいですが、まだうまくスキャンできてないようです。
ACの定義が昨年6月の古いデータしか入ってないので、それ以降の細心マルウェアは入り込んでいても検出できない状態です。

># Database: 2018-06-19.4

AC本体も旧バージョンを間違ってダウンロードしたようですね。

># Malwarebytes AdwCleaner 7.2.1.0

現在の最新版は7.3のはずです。

お手数ですが再度最新版をDLし直して、それで再スキャンをお願いします。
ACを起動すると画面の左上にバージョンが表示されますから、「7.3.0」になっていれば最新版です。
使い方は先の手順と同じなので、再スキャンが終わったらその結果ログをまたレスで見せてください。

自分の説明がわかりにくくて失礼しました。
しまった、こいつはうっかりだぁ!(←それ悪代官ポジションじゃないから
  • 悪代官
  • 2019/07/13 (Sat) 20:54:38
Re: プラウザが勝手に開かれます。
ご返信ありがとうございます。
悪代官と由美かおるはセットにしてはいけませんね(笑)

ACを再度ダウンロードいたしましたので、スキャンしたものをのせさせていただきます。
二つありましたので今回も二つ乗せます。

[C00]というログ
# -------------------------------
# Malwarebytes AdwCleaner 7.3.0.0
# -------------------------------
# Build: 04-04-2019
# Database: 2019-04-03.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 07-14-2019
# Duration: 00:00:01
# OS: Windows 10 Home
# Cleaned: 0
# Failed: 4


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Not Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\hao123.com
Not Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\jp.hao123.com
Not Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\hao123.com
Not Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\jp.hao123.com

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [2120 octets] - [14/07/2019 17:00:49]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

[S00]というログ
# -------------------------------
# Malwarebytes AdwCleaner 7.3.0.0
# -------------------------------
# Build: 04-04-2019
# Database: 2019-04-03.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 07-14-2019
# Duration: 00:00:08
# OS: Windows 10 Home
# Scanned: 27198
# Detected: 4


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\hao123.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\jp.hao123.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\hao123.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\jp.hao123.com

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.



########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########


よろしくお願いいたします!
  • sho
  • 2019/07/14 (Sun) 17:08:38
OTLで掘り下げて調べます
作業と報告、ご苦労様です。
最新版ACでのスキャン結果も見せてもらいました。

やはりhao123は検出されてますね。
では対象に全部チェックが入った状態で「クリーニング&リペア」を押してください。
これで処置後に一度PC再起動すれば対象は隔離できます。
隔離した時点では「削除」はされずあくまで隔離フォルダに格納されている状態ですが、動くことはなくなっているので無害になっています。
そのあと再度ACでスキャンし直して、同じモノが検出されなくなっていれば再発なしとなります。

ですがここで解決と見るのはまだ早いので、もう少し調べます。
haoはPC内の深い所に食いこむのは過去の相談でもわかってます。

以下のツールを準備してください。
OTL(OldTimer Listit)
「Download」ボタンからDLしたら保存しておいてください。
http://oldtimer.geekstogo.com/OTL.exe
片付けるときは起動後に「Cleanup」ボタンを押せば自動で削除されます。
ただし、Windows10をお使いの場合は本体ファイルをそのまま削除すればいいです。

他のプログラムを起動しない状態でOTLを起動してください。
起動したら、ウィンドウの上の方にある「Scan All Users」にチェックを入れ、以下のコマンドを「Custom Scan/Fixes」にコピペしてください。

SHOWHIDDEN
%windir%\tasks\*.job
DRIVES
BASESERVICES
%SYSTEMDRIVE%\*.exe
ACTIVEX
CREATERESTOREPOINT

その後、左上の「Run Scan」を押すとスキャン開始されます。
スキャン開始後、PC環境にもよりますが数分ほどすると、「OTL.txt」と「Extras.txt」がOTL.exeと同じ場所に作成されるはずなので、この2つのファイルをデスクトップあたりに保存しておいてください。
なお、Extras.txtは出ないこともありますが、その場合はOTL.txtだけでもいいです。

このあとOTLログを丸ごと返信に貼り付けてレスで見せてください。
ただしOTLログはかなり長くなるため、一度に送信してもfc2の文字数制限で途切れます。
なのでログも適当なところで1万文字以内に分割して、複数回に分けてレス送信してください。
1万文字を越えた投稿はfc2の文字数制限で途切れてしまうためです。
http://www1.odn.ne.jp/megukuma/count.htm

OTLでスキャンしただけでは何も変化は起きません。
この結果を見て、検出されたものを次回以降の作業で処置することになるはずです
  • 悪代官
  • 2019/07/14 (Sun) 21:14:24
Re: プラウザが勝手に開かれます。
お世話になります。
出張で作業が停滞しておりました。遅くなって申し訳ありません。

OTLとEXTRAを貼らせていただきます。
よろしくお願いいたします。
  • sho
  • 2019/07/23 (Tue) 23:08:01
Re: プラウザが勝手に開かれます。
OTL(1)

OTL logfile created on: 2019/07/23 22:29:50 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\sho50\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.17134.0)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

7.93 Gb Total Physical Memory | 5.40 Gb Available Physical Memory | 68.08% Memory free
22.43 Gb Paging File | 19.82 Gb Available in Paging File | 88.34% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 221.82 Gb Total Space | 50.79 Gb Free Space | 22.90% Space Free | Partition Type: NTFS
Drive D: | 3.58 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: LAPTOP-QCSS294P | User Name: sho50 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - File not found --
PRC - [2019/07/23 22:19:13 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\sho50\Desktop\OTL.exe
PRC - [2019/07/04 17:54:37 | 000,662,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\fontdrvhost.exe
PRC - [2019/07/03 22:44:45 | 001,589,368 | ---- | M] (Microsoft Corporation) -- C:\Users\sho50\AppData\Local\Microsoft\OneDrive\OneDrive.exe
PRC - [2019/06/26 11:07:16 | 004,000,080 | ---- | M] (Malwarebytes) -- C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
PRC - [2019/02/28 13:03:58 | 000,689,952 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe
PRC - [2019/02/28 13:03:40 | 000,172,320 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
PRC - [2018/01/18 04:45:12 | 000,324,544 | ---- | M] (Realtek Semiconductor) -- C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
PRC - [2016/11/21 15:36:04 | 000,013,312 | ---- | M] () -- C:\Windows\SysWOW64\SMITSC.exe
PRC - [2016/11/08 19:40:46 | 000,177,440 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
PRC - [2016/11/08 19:40:20 | 000,419,616 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2016/10/17 20:00:02 | 000,173,288 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe
PRC - [2016/10/17 20:00:00 | 000,496,872 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe
PRC - [2015/08/05 15:47:20 | 000,117,712 | ---- | M] (sMedio Inc.) -- C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingServiceTrayIcon.exe
PRC - [2015/08/05 15:47:16 | 000,118,224 | ---- | M] (sMedio Inc) -- C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingService.exe
PRC - [2014/11/20 18:24:05 | 000,110,344 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
PRC - [2011/06/29 10:44:04 | 000,008,704 | ---- | M] (Intercom, Inc.) -- C:\Program Files (x86)\Intercom\LAPLINK HelpDesk Client\LLHDCldr.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2018/04/12 08:34:47 | 000,364,200 | ---- | M] () -- C:\Windows\SysWOW64\InputHost.dll
MOD - [2014/07/04 13:35:48 | 000,627,672 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
MOD - [2014/07/04 12:35:48 | 000,016,856 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - File not found [On_Demand | Stopped] -- C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe -- (Amsp)
SRV:[b]64bit:[/b] - [2019/07/04 13:25:01 | 003,401,216 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:[b]64bit:[/b] - [2019/07/04 13:24:31 | 000,153,600 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dssvc.dll -- (DsSvc)
SRV:[b]64bit:[/b] - [2019/07/04 13:21:43 | 001,220,608 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\Unistore.dll -- (UnistoreSvc)
SRV:[b]64bit:[/b] - [2019/06/26 13:00:14 | 006,744,288 | ---- | M] (Malwarebytes) [Auto | Running] -- C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe -- (MBAMService)
SRV:[b]64bit:[/b] - [2019/06/13 16:46:09 | 000,713,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SharedRealitySvc.dll -- (SharedRealitySvc)
SRV:[b]64bit:[/b] - [2019/06/13 15:44:39 | 001,033,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ClipSVC.dll -- (ClipSVC)
SRV:[b]64bit:[/b] - [2019/06/13 15:10:04 | 001,400,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TokenBroker.dll -- (TokenBroker)
SRV:[b]64bit:[/b] - [2019/06/11 11:37:42 | 000,363,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\rempl\sedsvc.exe -- (sedsvc)
SRV:[b]64bit:[/b] - [2019/06/07 19:40:47 | 001,364,992 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\bcastdvruserservice.dll -- (BcastDVRUserService)
SRV:[b]64bit:[/b] - [2019/06/07 14:18:57 | 000,686,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2019/05/17 14:33:56 | 003,091,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:[b]64bit:[/b] - [2019/05/17 14:33:39 | 001,487,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\InstallService.dll -- (InstallService)
SRV:[b]64bit:[/b] - [2019/05/17 14:31:35 | 001,027,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\usermgr.dll -- (UserManager)
SRV:[b]64bit:[/b] - [2019/05/17 14:31:23 | 001,383,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\usocore.dll -- (UsoSvc)
SRV:[b]64bit:[/b] - [2019/05/03 15:00:17 | 000,090,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe -- (diagnosticshub.standardcollector.service)
SRV:[b]64bit:[/b] - [2019/05/03 14:56:29 | 000,773,632 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:[b]64bit:[/b] - [2019/04/19 13:36:47 | 000,827,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
SRV:[b]64bit:[/b] - [2019/04/19 13:35:53 | 001,458,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dosvc.dll -- (DoSvc)
SRV:[b]64bit:[/b] - [2019/04/19 13:35:22 | 000,784,896 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ngcsvc.dll -- (NgcSvc)
SRV:[b]64bit:[/b] - [2019/03/14 16:50:42 | 000,847,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:[b]64bit:[/b] - [2019/03/14 16:50:38 | 000,947,200 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:[b]64bit:[/b] - [2019/02/28 13:04:24 | 004,110,624 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService)
SRV:[b]64bit:[/b] - [2019/02/28 13:04:08 | 000,311,584 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:[b]64bit:[/b] - [2019/02/28 13:03:58 | 000,689,952 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:[b]64bit:[/b] - [2019/02/28 13:03:40 | 000,172,320 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:[b]64bit:[/b] - [2019/02/16 16:27:02 | 001,364,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lpasvc.dll -- (wlpasvc)
SRV:[b]64bit:[/b] - [2019/02/06 11:25:27 | 000,507,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\svchost.exe -- (WpnUserService_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\svchost.exe -- (UserDataSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\svchost.exe -- (UnistoreSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (PrintWorkflowUserSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\svchost.exe -- (PimIndexMaintenanceSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\svchost.exe -- (OneSyncSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (MessagingService_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (DevicesFlowUserSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (DevicePickerUserSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\svchost.exe -- (CDPUserSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (BluetoothUserService_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (BcastDVRUserService_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:22:57 | 000,392,704 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WaaSMedicSvc.dll -- (WaaSMedicSvc)
SRV:[b]64bit:[/b] - [2019/01/09 14:22:42 | 000,266,752 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\CapabilityAccessManager.dll -- (camsvc)
SRV:[b]64bit:[/b] - [2019/01/01 15:42:29 | 002,247,680 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:[b]64bit:[/b] - [2018/12/08 17:04:40 | 000,885,760 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\CoreMessaging.dll -- (CoreMessagingRegistrar)
SRV:[b]64bit:[/b] - [2018/12/08 16:36:32 | 000,356,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dusmsvc.dll -- (DusmSvc)
SRV:[b]64bit:[/b] - [2018/12/08 16:36:23 | 000,153,600 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\RMapi.dll -- (RmSvc)
SRV:[b]64bit:[/b] - [2018/11/09 11:20:34 | 000,092,160 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\tzautoupdate.dll -- (tzautoupdate)
SRV:[b]64bit:[/b] - [2018/11/09 11:20:24 | 000,399,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\BthAvctpSvc.dll -- (BthAvctpSvc)
SRV:[b]64bit:[/b] - [2018/11/09 11:18:30 | 000,514,048 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\BTAGService.dll -- (BTAGService)
SRV:[b]64bit:[/b] - [2018/11/09 11:16:04 | 000,308,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\EnterpriseAppMgmtSvc.dll -- (EntAppSvc)
SRV:[b]64bit:[/b] - [2018/11/01 15:59:14 | 000,241,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tetheringservice.dll -- (icssvc)
SRV:[b]64bit:[/b] - [2018/11/01 15:57:53 | 000,835,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\PhoneService.dll -- (PhoneSvc)
SRV:[b]64bit:[/b] - [2018/11/01 15:57:04 | 000,281,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:[b]64bit:[/b] - [2018/10/21 16:14:53 | 000,632,320 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cdpsvc.dll -- (CDPSvc)
SRV:[b]64bit:[/b] - [2018/10/21 16:14:29 | 000,453,632 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\cdpusersvc.dll -- (CDPUserSvc)
SRV:[b]64bit:[/b] - [2018/09/28 02:47:28 | 000,510,464 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\IntelCpHeciSvc.exe -- (cphs)
SRV:[b]64bit:[/b] - [2018/09/28 02:47:28 | 000,505,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\IntelCpHDCPSvc.exe -- (cplspcon)
SRV:[b]64bit:[/b] - [2018/09/28 02:47:16 | 000,413,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\igfxCUIService.exe -- (igfxCUIService2.0.0.0)
SRV:[b]64bit:[/b] - [2018/09/08 12:24:26 | 000,463,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:[b]64bit:[/b] - [2018/08/03 12:41:01 | 000,061,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\hvhostsvc.dll -- (HvHost)
SRV:[b]64bit:[/b] - [2018/07/14 13:23:08 | 000,760,888 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SecurityHealthService.exe -- (SecurityHealthService)
SRV:[b]64bit:[/b] - [2018/07/14 12:54:10 | 000,262,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\PushToInstall.dll -- (PushToInstall)
SRV:[b]64bit:[/b] - [2018/07/14 12:53:02 | 000,681,984 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WFDSConMgrSvc.dll -- (WFDSConMgrSvc)
SRV:[b]64bit:[/b] - [2018/07/06 15:58:32 | 000,091,136 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\moshost.dll -- (MapsBroker)
SRV:[b]64bit:[/b] - [2018/06/15 13:41:49 | 000,235,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:[b]64bit:[/b] - [2018/06/09 15:25:35 | 001,456,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WpcDesktopMonSvc.dll -- (WpcMonSvc)
SRV:[b]64bit:[/b] - [2018/06/09 01:06:33 | 000,976,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Spectrum.exe -- (spectrum)
SRV:[b]64bit:[/b] - [2018/06/08 18:29:32 | 004,970,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\Windows.StateRepository.dll -- (StateRepository)
SRV:[b]64bit:[/b] - [2018/06/08 17:59:09 | 000,673,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FrameServer.dll -- (FrameServer)
SRV:[b]64bit:[/b] - [2018/06/08 17:56:37 | 000,858,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FlightSettings.dll -- (wisvc)
SRV:[b]64bit:[/b] - [2018/06/08 17:55:04 | 000,667,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:[b]64bit:[/b] - [2018/05/10 21:37:48 | 000,541,896 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\WINDOWS\SysNative\ibtsiva.exe -- (ibtsiva)
SRV:[b]64bit:[/b] - [2018/04/12 08:35:21 | 000,681,984 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\RDXService.dll -- (RetailDemo)
SRV:[b]64bit:[/b] - [2018/04/12 08:35:21 | 000,427,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WalletService.dll -- (WalletService)
SRV:[b]64bit:[/b] - [2018/04/12 08:35:21 | 000,400,896 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\Windows.Devices.Picker.dll -- (DevicePickerUserSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:43 | 000,824,832 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NaturalAuth.dll -- (NaturalAuthentication)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:43 | 000,590,336 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SmsRouterSvc.dll -- (SmsRouter)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:43 | 000,121,344 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:41 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:40 | 000,013,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:39 | 000,219,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DiagSvc.dll -- (diagsvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:38 | 000,671,744 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:37 | 000,303,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\TieringEngineService.exe -- (TieringEngineService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:37 | 000,198,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:34 | 001,273,344 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SensorDataService.exe -- (SensorDataService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:33 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\PrintWorkflowService.dll -- (PrintWorkflowUserSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:25 | 000,058,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:24 | 000,081,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:24 | 000,027,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:23 | 000,167,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:22 | 000,335,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NetSetupSvc.dll -- (NetSetupSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:22 | 000,089,088 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:19 | 000,750,080 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\DevicesFlowBroker.dll -- (DevicesFlowUserSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:19 | 000,195,584 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\Windows.SharedPC.AccountManager.dll -- (shpamsvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,712,192 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SensorService.dll -- (SensorService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,057,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dmwappushsvc.dll -- (dmwappushservice)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,023,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 001,495,040 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\UserDataService.dll -- (UserDataSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,582,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NgcCtnrSvc.dll -- (NgcCtnrSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,345,600 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,280,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wpnservice.dll -- (WpnService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,185,856 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\PimIndexMaintenance.dll -- (PimIndexMaintenanceSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,176,128 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBrokerSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,096,768 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\WpnUserService.dll -- (WpnUserService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,058,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\xboxgipsvc.dll -- (XboxGipSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,044,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lfsvc.dll -- (lfsvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:10 | 001,248,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SEMgrSvc.dll -- (SEMgrSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:10 | 000,376,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:10 | 000,048,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\LicenseManagerSvc.dll -- (LicenseManager)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:10 | 000,033,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DevQueryBroker.dll -- (DevQueryBroker)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:08 | 001,308,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XblGameSave.dll -- (XblGameSave)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:08 | 000,167,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\embeddedmodesvc.dll -- (embeddedmode)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:08 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GraphicsPerfSvc.dll -- (GraphicsPerfSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:08 | 000,059,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\xbgmsvc.exe -- (xbgm)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:08 | 000,031,744 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Windows.WARP.JITService.dll -- (WarpJITSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:07 | 001,115,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XblAuthManager.dll -- (XblAuthManager)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:06 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AJRouter.dll -- (AJRouter)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 001,148,928 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XboxNetApiSvc.dll -- (XboxNetApiSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,411,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vac.dll -- (VacSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,199,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\LanguageOverlayServer.dll -- (LxpSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,163,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SgrmBroker.exe -- (SgrmBroker)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,052,224 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\MessagingService.dll -- (MessagingService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:02 | 000,464,384 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\Microsoft.Bluetooth.UserService.dll -- (BluetoothUserService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:02 | 000,063,488 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ipxlatcfg.dll -- (IpxlatCfgSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 002,197,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,309,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvcext.dll -- (vmicvss)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,309,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvcext.dll -- (vmicrdv)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvmsession)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:47 | 003,441,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:[b]64bit:[/b] - [2018/04/11 06:05:00 | 000,324,608 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\APHostService.dll -- (OneSyncSvc)
SRV:[b]64bit:[/b] - [2018/03/29 00:28:20 | 000,287,240 | ---- | M] (Synaptics Incorporated) [Auto | Running] -- C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe -- (SynTPEnhService)
SRV:[b]64bit:[/b] - [2018/03/11 03:20:00 | 000,495,616 | ---- | M] () [Disabled | Stopped] -- C:\Windows\SysNative\OpenSSH\ssh-agent.exe -- (ssh-agent)
SRV:[b]64bit:[/b] - [2018/01/18 04:45:12 | 000,324,544 | ---- | M] (Realtek Semiconductor) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe -- (RtkAudioService)
SRV:[b]64bit:[/b] - [2016/11/21 06:24:12 | 000,091,680 | ---- | M] (Synaptics Incorporated) [Auto | Running] -- C:\Windows\SysNative\valWBFPolicyService.exe -- (valWBFPolicyService)
SRV:[b]64bit:[/b] - [2016/11/16 11:06:04 | 000,219,568 | ---- | M] (Toshiba Client Solutions Co., Ltd.) [Auto | Running] -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\TStationSrv.exe -- (TStationSrv)
SRV:[b]64bit:[/b] - [2016/11/08 16:50:02 | 000,064,776 | ---- | M] (Toshiba Client Solutions Co., Ltd.) [Auto | Running] -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV:[b]64bit:[/b] - [2016/11/01 17:18:02 | 000,034,528 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files\Intel\Intel(R) Online Connect\iocHelperService.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2016/11/01 17:18:02 | 000,025,312 | ---- | M] (Intel Corporation) [On_Demand | Start_Pending] -- C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2016/10/17 20:00:02 | 000,173,288 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2016/10/17 20:00:00 | 000,496,872 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2016/10/13 21:42:24 | 000,630,048 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2016/07/20 14:58:04 | 000,992,480 | ---- | M] (Toshiba Client Solutions Co., Ltd.) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV:[b]64bit:[/b] - [2016/07/18 14:33:14 | 000,338,208 | ---- | M] (Toshiba Client Solutions Co., Ltd.) [Auto | Running] -- C:\Program Files\TOSHIBA\Teco\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV:[b]64bit:[/b] - [2015/10/05 13:33:13 | 000,614,664 | ---- | M] (CyberLink) [Auto | Running] -- C:\Program Files\CyberLink\Shared files\RichVideo64.exe -- (RichVideo64)
SRV:[b]64bit:[/b] - [2015/07/30 06:38:26 | 000,241,632 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\Titanium\TiMiniService.exe -- (TiMiniService)
SRV - [2019/07/13 08:11:51 | 001,098,224 | ---- | M] (Google LLC) [On_Demand | Stopped] -- C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\elevation_service.exe -- (GoogleChromeElevationService)
SRV - [2019/07/10 05:05:17 | 002,455,544 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1906.3-0\NisSrv.exe -- (WdNisSvc)
SRV - [2019/07/10 05:05:17 | 000,110,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1906.3-0\MsMpEng.exe -- (WinDefend)
SRV - [2019/07/04 13:18:19 | 000,965,632 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\Unistore.dll -- (UnistoreSvc)
SRV - [2019/06/13 13:44:26 | 001,003,008 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\TokenBroker.dll -- (TokenBroker)
SRV - [2019/05/17 15:19:08 | 001,110,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\InstallService.dll -- (InstallService)
SRV - [2019/04/19 13:38:40 | 000,593,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
SRV - [2018/12/08 16:45:30 | 000,567,256 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\CoreMessaging.dll -- (CoreMessagingRegistrar)
SRV - [2018/09/28 02:47:28 | 000,510,464 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\IntelCpHeciSvc.exe -- (cphs)
SRV - [2018/09/28 02:47:28 | 000,505,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\IntelCpHDCPSvc.exe -- (cplspcon)
SRV - [2018/09/28 02:47:16 | 000,413,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\igfxCUIService.exe -- (igfxCUIService2.0.0.0)
SRV - [2018/06/08 18:09:43 | 004,469,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\Windows.StateRepository.dll -- (StateRepository)
SRV - [2018/06/08 17:54:26 | 000,729,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\FlightSettings.dll -- (wisvc)
SRV - [2018/04/12 08:35:22 | 000,312,832 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\Windows.Devices.Picker.dll -- (DevicePickerUserSvc)
SRV - [2018/04/12 08:34:57 | 000,138,240 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\PrintWorkflowService.dll -- (PrintWorkflowUserSvc)
SRV - [2018/04/12 08:34:45 | 000,072,192 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysWOW64\tzautoupdate.dll -- (tzautoupdate)
SRV - [2018/04/12 08:34:45 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2018/04/12 08:33:47 | 003,441,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2016/11/21 15:36:04 | 000,013,312 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\SMITSC.exe -- (SMITS)
SRV - [2016/11/08 19:40:46 | 000,177,440 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service)
SRV - [2016/11/08 19:40:20 | 000,419,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2016/10/14 17:00:36 | 000,018,152 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe -- (Intel(R)
SRV - [2016/07/13 16:13:20 | 000,337,112 | ---- | M] (Toshiba Client Solutions Co., Ltd.) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\TOSHIBA System Driver\RMService.exe -- (TOSRMService)
SRV - [2016/04/12 13:35:58 | 000,016,384 | ---- | M] (Toshiba Client Solutions Co., Ltd.) [Auto | Stopped] -- C:\Program Files (x86)\TOSHIBA\OEM Registration Program\OEMRegistrationProgram.exe -- (OEMRegistrationProgram)
SRV - [2015/08/05 15:47:16 | 000,118,224 | ---- | M] (sMedio Inc) [Auto | Running] -- C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingService.exe -- (TVCSDubbingService)
SRV - [2015/07/17 09:27:52 | 000,319,360 | ---- | M] (Intercom, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Intercom\LAPLINK HelpDesk Client\LLHDClient.exe -- (LLHDClient)
SRV - [2011/06/29 10:44:04 | 000,008,704 | ---- | M] (Intercom, Inc.) [Auto | Running] -- C:\Program Files (x86)\Intercom\LAPLINK HelpDesk Client\LLHDCldr.exe -- (LLHDCloader)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2019/07/23 22:25:10 | 000,073,584 | ---- | M] (Malwarebytes) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtection)
DRV:[b]64bit:[/b] - [2019/07/23 22:25:08 | 000,224,408 | ---- | M] (Malwarebytes) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\farflt.sys -- (MBAMFarflt)
DRV:[b]64bit:[/b] - [2019/07/23 22:25:08 | 000,116,112 | ---- | M] (Malwarebytes) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebProtection)
DRV:[b]64bit:[/b] - [2019/07/23 22:25:04 | 000,275,232 | ---- | M] (Malwarebytes) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV:[b]64bit:[/b] - [2019/07/23 22:23:43 | 000,199,768 | ---- | M] (Malwarebytes) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\MbamChameleon.sys -- (MBAMChameleon)
DRV:[b]64bit:[/b] - [2019/07/10 05:05:17 | 000,367,032 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\wd\WdFilter.sys -- (WdFilter)
DRV:[b]64bit:[/b] - [2019/07/10 05:05:17 | 000,054,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wd\WdNisDrv.sys -- (WdNisDrv)
DRV:[b]64bit:[/b] - [2019/07/10 05:05:17 | 000,047,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\wd\WdBoot.sys -- (WdBoot)
DRV:[b]64bit:[/b] - [2019/06/26 13:00:48 | 000,020,936 | ---- | M] (Malwarebytes) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\MbamElam.sys -- (MbamElam)
DRV:[b]64bit:[/b] - [2019/06/07 14:58:50 | 000,076,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hvservice.sys -- (hvservice)
DRV:[b]64bit:[/b] - [2019/06/07 14:57:00 | 000,383,504 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:[b]64bit:[/b] - [2019/05/17 16:07:32 | 000,105,272 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:[b]64bit:[/b] - [2019/05/17 14:36:02 | 000,228,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winnat.sys -- (WinNat)
DRV:[b]64bit:[/b] - [2019/05/17 14:33:34 | 000,787,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WdiWiFi.sys -- (wdiwifi)
DRV:[b]64bit:[/b] - [2019/05/03 15:43:05 | 000,177,128 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:[b]64bit:[/b] - [2019/05/03 15:32:10 | 000,164,664 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:[b]64bit:[/b] - [2019/03/14 23:33:58 | 000,082,432 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\storqosflt.sys -- (storqosflt)
DRV:[b]64bit:[/b] - [2019/03/14 17:57:04 | 000,611,640 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:[b]64bit:[/b] - [2019/03/14 17:28:15 | 000,152,072 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\wcifs.sys -- (wcifs)
DRV:[b]64bit:[/b] - [2019/03/14 16:55:51 | 000,414,720 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\cldflt.sys -- (CldFlt)
DRV:[b]64bit:[/b] - [2019/03/06 18:04:46 | 000,945,464 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refsv1.sys -- (ReFSv1)
DRV:[b]64bit:[/b] - [2019/03/06 18:03:04 | 001,921,848 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)
DRV:[b]64bit:[/b] - [2019/03/04 20:07:18 | 008,835,768 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Netwtw06.sys -- (Netwtw06)
DRV:[b]64bit:[/b] - [2019/01/09 14:42:08 | 000,092,704 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bindflt.sys -- (bindflt)
DRV:[b]64bit:[/b] - [2019/01/08 16:32:04 | 000,153,328 | ---- | M] (Malwarebytes) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mbae64.sys -- (ESProtectionDriver)
DRV:[b]64bit:[/b] - [2018/12/08 17:04:38 | 000,058,168 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iorate.sys -- (iorate)
DRV:[b]64bit:[/b] - [2018/12/08 16:38:30 | 000,083,456 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\wcnfs.sys -- (wcnfs)
DRV:[b]64bit:[/b] - [2018/12/08 16:36:56 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mmcss.sys -- (MMCSS)
DRV:[b]64bit:[/b] - [2018/11/09 11:49:37 | 000,565,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:[b]64bit:[/b] - [2018/11/09 11:21:11 | 000,112,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:[b]64bit:[/b] - [2018/10/21 16:19:52 | 000,036,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vhf.sys -- (vhf)
DRV:[b]64bit:[/b] - [2018/09/28 02:47:28 | 000,635,384 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\intcdaud.inf_amd64_3b876fb0bfb3390a\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2018/09/28 02:47:12 | 014,072,744 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2018/08/09 13:55:01 | 000,230,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2018/08/03 12:47:12 | 000,128,920 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\scmbus.sys -- (scmbus)
DRV:[b]64bit:[/b] - [2018/08/03 12:40:48 | 000,228,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Ucx01000.sys -- (Ucx01000)
DRV:[b]64bit:[/b] - [2018/08/03 12:39:58 | 000,075,160 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:[b]64bit:[/b] - [2018/08/03 12:17:05 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgid.sys -- (vmgid)
DRV:[b]64bit:[/b] - [2018/06/15 16:10:52 | 000,048,544 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storufs.sys -- (storufs)
DRV:[b]64bit:[/b] - [2018/06/15 14:08:14 | 000,072,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\WindowsTrustedRT.sys -- (WindowsTrustedRT)
DRV:[b]64bit:[/b] - [2018/06/15 13:44:07 | 000,295,424 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xboxgip.sys -- (xboxgip)
DRV:[b]64bit:[/b] - [2018/06/08 19:31:08 | 000,029,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:[b]64bit:[/b] - [2018/05/10 21:37:48 | 000,136,728 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ibtusb.sys -- (ibtusb)
DRV:[b]64bit:[/b] - [2018/05/10 14:05:04 | 000,035,560 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AppleLowerFilter.sys -- (AppleLowerFilter)
DRV:[b]64bit:[/b] - [2018/05/10 14:05:04 | 000,020,640 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AppleKmdfFilter.sys -- (AppleKmdfFilter)
DRV:[b]64bit:[/b] - [2018/04/13 01:34:17 | 000,037,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2018/04/13 01:34:15 | 000,057,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpatialGraphFilter.sys -- (SpatialGraphFilter)
DRV:[b]64bit:[/b] - [2018/04/13 01:34:13 | 000,030,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:43 | 000,119,808 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\irda.sys -- (irda)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:40 | 000,091,544 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:40 | 000,060,320 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\bam.sys -- (bam)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:32 | 000,128,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:32 | 000,084,480 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:32 | 000,039,424 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\afunix.sys -- (afunix)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:32 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:28 | 000,254,464 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:25 | 000,088,472 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:22 | 000,175,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NetAdapterCx.sys -- (NetAdapterCx)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:22 | 000,034,208 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:20 | 000,217,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:20 | 000,209,816 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:19 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\applockerfltr.sys -- (applockerfltr)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:15 | 000,021,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdmCompanionFilter.sys -- (WdmCompanionFilter)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,282,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ufx01000.sys -- (Ufx01000)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,154,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,152,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmTcpciCx.sys -- (UcmTcpciCx0101)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,128,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmCx.sys -- (UcmCx0101)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,075,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,067,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urscx01000.sys -- (UrsCx01000)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,039,328 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\cnghwassist.sys -- (cnghwassist)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IndirectKmd.sys -- (IndirectKmd)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshwnclx.sys -- (HwNClx0101)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,169,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,082,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,055,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,128,000 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,063,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SgrmAgent.sys -- (SgrmAgent)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\gpuenergydrv.sys -- (GpuEnergyDrv)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:58 | 000,030,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,140,192 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,127,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,063,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,055,808 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\filecrypt.sys -- (FileCrypt)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Udecx.sys -- (UdeCx)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,039,840 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\ramdisk.sys -- (Ramdisk)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ipt.sys -- (IPT)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,434,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,287,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,097,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmUcsi.sys -- (UcmUcsi)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,054,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,050,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,050,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidinterrupt.sys -- (hidinterrupt)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xinputhid.sys -- (xinputhid)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\buttonconverter.sys -- (buttonconverter)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,026,112 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,018,472 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\WindowsTrustedRTProxy.sys -- (WindowsTrustedRTProxy)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:51 | 000,144,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ufxsynopsys.sys -- (ufxsynopsys)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:51 | 000,098,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UfxChipidea.sys -- (UfxChipidea)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:51 | 000,086,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys -- (BthLEEnum)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:51 | 000,029,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urschipidea.sys -- (UrsChipidea)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:51 | 000,028,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urssynopsys.sys -- (UrsSynopsys)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:51 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\genericusbfn.sys -- (genericusbfn)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 001,836,952 | ---- | M] (Chelsio Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cht4vx64.sys -- (cht4vbd)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,885,144 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAVC.sys -- (iaStorAVC)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,842,648 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mlx4_bus.sys -- (mlx4_bus)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,526,232 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ibbus.sys -- (ibbus)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,505,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mausbhost.sys -- (mausbhost)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,321,432 | ---- | M] (Chelsio Communications) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\cht4sx64.sys -- (cht4iscsi)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,305,560 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,197,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc.sys -- (netvsc)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,156,056 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,108,952 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndfltr.sys -- (ndfltr)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,105,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pmem.sys -- (pmem)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,104,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvdimm.sys -- (nvdimm)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,079,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,072,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,064,920 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winverbs.sys -- (WinVerbs)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,064,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,063,488 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,061,848 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\percsas3i.sys -- (percsas3i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,058,776 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\percsas2i.sys -- (percsas2i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,056,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mausbip.sys -- (mausbip)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,047,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,038,304 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bttflt.sys -- (bttflt)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,035,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,033,184 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\hvcrash.sys -- (hvcrash)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,033,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SDFRd.sys -- (SDFRd)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,032,152 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winmad.sys -- (WinMad)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,031,128 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,028,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,018,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\swenum.inf_amd64_ea7b19c04e7a8136\swenum.sys -- (swenum)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,016,288 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volume.sys -- (volume)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,013,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 003,419,032 | ---- | M] (QLogic Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 001,135,520 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,533,912 | ---- | M] (QLogic Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,259,480 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,145,816 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\ItSas35i.sys -- (ItSas35i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,128,408 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3i.sys -- (LSI_SAS3i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,124,312 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2i.sys -- (LSI_SAS2i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,123,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\capimg.sys -- (CapImg)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,107,416 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,104,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rhproxy.sys -- (rhproxy)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,083,360 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,082,848 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,082,328 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\megasas35i.sys -- (megasas35i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,075,160 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\MegaSas2i.sys -- (megasas2i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,064,408 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,063,904 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,038,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,027,032 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,020,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AcpiDev.sys -- (AcpiDev)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pnpmem.sys -- (PNPMEM)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,009,728 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,174,592 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_I2C_BXT_P.sys -- (iaLPSS2i_I2C_BXT_P)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,171,520 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_I2C.sys -- (iaLPSS2i_I2C)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,118,680 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,113,152 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,091,648 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iai2c.sys -- (iai2c)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,088,576 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_GPIO2_BXT_P.sys -- (iaLPSS2i_GPIO2_BXT_P)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,079,360 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iaLPSS2i_GPIO2.sys -- (iaLPSS2i_GPIO2)
DRV:[b]64bit:[/b] - [2018/04/
  • sho
  • 2019/07/23 (Tue) 23:13:55
Re: プラウザが勝手に開かれます。
OTL(2)

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=PRTOS1&src=IE11TR&pc=TBTE
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=PRTOS1&src=IE11TR&pc=TBTE


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://toshibaplaces.jp/tps/ [binary data]
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba17win10.msn.com/?pc=TBTE

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://toshibaplaces.jp/tps/ [binary data]
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba17win10.msn.com/?pc=TBTE

IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,IE11DefaultsFRECompletionTime = BB E2 D1 7A 19 30 D5 01 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,IE11DefaultsFREConfigUpdateTimestamp = 6C B2 91 C3 D6 40 D5 01 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://toshibaplaces.jp/tps/ [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba17win10.msn.com/?pc=TBTE
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = 4D 07 FA 86 91 2A D5 01 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = 01 00 00 00 2A 00 00 00 F1 E0 2F BD 98 8B 5D 53 C9 71 5B CA 85 7E B3 A3 67 FC 34 CE C3 72 B4 58 97 35 7D 76 A0 89 20 E4 34 70 67 3E DB 19 28 EE CF 55 02 00 00 00 10 00 00 00 41 2F 25 32 62 6A 73 34 34 63 7A 66 38 25 33 64 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[color=#E56717]========== FireFox ==========[/color]

FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll (Google LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll (Google LLC)



[color=#E56717]========== Chrome ==========[/color]

CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.2_1\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7519.422.0.3_0\

O1 HOSTS File: ([2016/07/16 20:45:37 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O4:[b]64bit:[/b] - HKLM..\Run: [] File not found
O4:[b]64bit:[/b] - HKLM..\Run: [SecurityHealth] C:\Program Files\Windows Defender\MSASCuiL.exe (Microsoft Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [TCrdMain] C:\Program Files\TOSHIBA\System Setting\TCrdMain_Win8.exe (Toshiba Client Solutions Co., Ltd.)
O4:[b]64bit:[/b] - HKLM..\Run: [TecoResident] C:\Program Files\TOSHIBA\Teco\TecoResident.exe (Toshiba Client Solutions Co., Ltd.)
O4:[b]64bit:[/b] - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (Toshiba Client Solutions Co., Ltd.)
O4:[b]64bit:[/b] - HKLM..\Run: [Trend Micro Client Framework] C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe (Trend Micro Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe (Trend Micro Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [VizorHtmlDialog.exe] C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [CLMLServer_For_P2G8] C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink)
O4 - HKU\S-1-5-19..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1460922254-185261916-941432131-1001..\Run: [CCleaner Smart Cleaning] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Software Ltd)
O4 - HKU\S-1-5-21-1460922254-185261916-941432131-1001..\Run: [OneDrive] C:\Users\sho50\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1460922254-185261916-941432131-1001..\RunOnce: [Application Restart #0] C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingServiceTrayIcon.exe (sMedio Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DSCAutomationHostEnabled = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableFullTrustStartupTasks = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUwpStartupTasks = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SupportFullTrustStartupTasks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SupportUwpStartupTasks = 1
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.3.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{406fe38c-c20f-4157-aa17-bc878f6bffb5}: DhcpNameServer = 192.168.0.1 192.168.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7cb959f8-1ae5-4608-9757-b23f04f03130}: DhcpNameServer = 192.168.3.1
O18:[b]64bit:[/b] - Protocol\Handler\mso-minsb.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\mso-minsb-roaming.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\osf.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\osf-roaming.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - U
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
ActiveX:[b]64bit:[/b] {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:[b]64bit:[/b] {C6658531-8DB9-3115-B6D1-F89B57830CFC} - .NET Framework
ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {B82EE9BD-ADE2-3058-8091-78419781EC8E} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2019/07/23 22:25:10 | 000,073,584 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2019/07/23 22:25:08 | 000,224,408 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\farflt.sys
[2019/07/23 22:25:08 | 000,116,112 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2019/07/23 22:25:04 | 000,275,232 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbamswissarmy.sys
[2019/07/23 22:19:13 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\sho50\Desktop\OTL.exe
[2019/07/20 06:11:52 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\sMedio
[2019/07/14 16:58:21 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2019/07/14 16:57:48 | 007,025,360 | ---- | C] (Malwarebytes) -- C:\Users\sho50\Desktop\AdwCleaner.exe
[2019/07/13 12:35:21 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\mbam
[2019/07/13 12:35:07 | 000,199,768 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MbamChameleon.sys
[2019/07/13 12:34:59 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\mbamtray
[2019/07/13 12:34:51 | 000,020,936 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MbamElam.sys
[2019/07/13 12:34:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
[2019/07/13 12:34:49 | 000,153,328 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbae64.sys
[2019/07/13 12:34:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2019/07/13 12:34:44 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes
[2019/07/13 12:32:48 | 064,552,472 | ---- | C] (Malwarebytes ) -- C:\Users\sho50\Desktop\mb3-setup-consumer-3.8.3.2965-1.0.613-1.0.11520.exe
[2019/07/13 03:14:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office ツール
[2019/07/11 07:12:50 | 007,519,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Protection.PlayReady.dll
[2019/07/11 07:12:50 | 006,570,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
[2019/07/11 07:12:49 | 025,857,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\edgehtml.dll
[2019/07/11 07:12:44 | 022,017,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\edgehtml.dll
[2019/07/11 07:12:43 | 009,084,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2019/07/11 07:12:42 | 007,589,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Chakra.dll
[2019/07/11 07:12:42 | 007,436,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\windows.storage.dll
[2019/07/11 07:12:41 | 005,625,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StartTileData.dll
[2019/07/11 07:12:40 | 005,784,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Chakra.dll
[2019/07/11 07:12:40 | 004,847,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_nt.dll
[2019/07/11 07:12:40 | 001,721,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\appraiser.dll
[2019/07/11 07:12:40 | 001,616,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppobjs.dll
[2019/07/11 07:12:39 | 006,044,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\windows.storage.dll
[2019/07/11 07:12:39 | 004,718,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.pcshell.dll
[2019/07/11 07:12:39 | 003,614,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kfull.sys
[2019/07/11 07:12:38 | 006,586,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2019/07/11 07:12:38 | 004,861,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2019/07/11 07:12:38 | 004,385,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EdgeContent.dll
[2019/07/11 07:12:38 | 004,038,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2019/07/11 07:12:38 | 003,292,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\combase.dll
[2019/07/11 07:12:38 | 002,882,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\win32kfull.sys
[2019/07/11 07:12:37 | 003,401,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2019/07/11 07:12:37 | 000,740,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2019/07/11 07:12:37 | 000,513,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepic.dll
[2019/07/11 07:12:36 | 005,657,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2019/07/11 07:12:36 | 004,771,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InputService.dll
[2019/07/11 07:12:36 | 003,700,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2019/07/11 07:12:35 | 002,871,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aitstatic.exe
[2019/07/11 07:12:35 | 002,479,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\combase.dll
[2019/07/11 07:12:35 | 001,035,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ApplyTrustOffline.exe
[2019/07/11 07:12:35 | 000,810,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2019/07/11 07:12:34 | 003,318,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2019/07/11 07:12:34 | 003,202,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll
[2019/07/11 07:12:34 | 002,370,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WebRuntimeManager.dll
[2019/07/11 07:12:34 | 002,166,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kbase.sys
[2019/07/11 07:12:34 | 001,219,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvix64.exe
[2019/07/11 07:12:34 | 000,951,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppcext.dll
[2019/07/11 07:12:34 | 000,900,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\slui.exe
[2019/07/11 07:12:34 | 000,896,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sppcext.dll
[2019/07/11 07:12:34 | 000,767,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppcommdlg.dll
[2019/07/11 07:12:34 | 000,415,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\aepic.dll
[2019/07/11 07:12:33 | 008,627,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll
[2019/07/11 07:12:33 | 002,899,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2019/07/11 07:12:33 | 002,571,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2019/07/11 07:12:33 | 001,400,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TokenBroker.dll
[2019/07/11 07:12:33 | 001,215,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationController.dll
[2019/07/11 07:12:33 | 001,027,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvax64.exe
[2019/07/11 07:12:33 | 000,637,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2019/07/11 07:12:33 | 000,511,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dcntel.dll
[2019/07/11 07:12:33 | 000,464,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\invagent.dll
[2019/07/11 07:12:33 | 000,164,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CompatTelRunner.exe
[2019/07/11 07:12:33 | 000,071,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32appinventorycsp.dll
[2019/07/11 07:12:32 | 003,554,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\InputService.dll
[2019/07/11 07:12:32 | 001,631,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32full.dll
[2019/07/11 07:12:32 | 001,626,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\enterprisecsps.dll
[2019/07/11 07:12:32 | 001,453,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gdi32full.dll
[2019/07/11 07:12:32 | 001,376,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ole32.dll
[2019/07/11 07:12:32 | 001,175,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncCore.dll
[2019/07/11 07:12:32 | 000,922,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Security.Authentication.Web.Core.dll
[2019/07/11 07:12:32 | 000,808,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EdgeManager.dll
[2019/07/11 07:12:32 | 000,607,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TextInputFramework.dll
[2019/07/11 07:12:32 | 000,324,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\acmigration.dll
[2019/07/11 07:12:31 | 007,990,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll
[2019/07/11 07:12:31 | 002,546,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UpdateAgent.dll
[2019/07/11 07:12:31 | 002,176,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.onecore.dll
[2019/07/11 07:12:31 | 001,663,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GdiPlus.dll
[2019/07/11 07:12:31 | 001,566,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxPackaging.dll
[2019/07/11 07:12:31 | 001,561,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.desktop.dll
[2019/07/11 07:12:31 | 001,549,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2019/07/11 07:12:31 | 001,471,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GdiPlus.dll
[2019/07/11 07:12:31 | 001,459,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2019/07/11 07:12:31 | 001,048,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Internal.Shell.Broker.dll
[2019/07/11 07:12:31 | 001,033,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ClipSVC.dll
[2019/07/11 07:12:31 | 000,916,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusUpdateHandlers.dll
[2019/07/11 07:12:31 | 000,894,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\webplatstorageserver.dll
[2019/07/11 07:12:31 | 000,567,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\daxexec.dll
[2019/07/11 07:12:31 | 000,566,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\phoneactivate.exe
[2019/07/11 07:12:30 | 001,427,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxPackaging.dll
[2019/07/11 07:12:30 | 001,260,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2019/07/11 07:12:30 | 001,141,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2019/07/11 07:12:30 | 001,127,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nettrace.dll
[2019/07/11 07:12:30 | 001,003,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TokenBroker.dll
[2019/07/11 07:12:30 | 000,986,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncHost.exe
[2019/07/11 07:12:30 | 000,953,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncCore.dll
[2019/07/11 07:12:30 | 000,776,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wer.dll
[2019/07/11 07:12:30 | 000,767,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dnsapi.dll
[2019/07/11 07:12:30 | 000,734,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentClient.dll
[2019/07/11 07:12:30 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SharedRealitySvc.dll
[2019/07/11 07:12:30 | 000,624,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PsmServiceExtHost.dll
[2019/07/11 07:12:30 | 000,608,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\EdgeManager.dll
[2019/07/11 07:12:30 | 000,559,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
[2019/07/11 07:12:30 | 000,545,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hal.dll
[2019/07/11 07:12:30 | 000,532,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\QuietHours.dll
[2019/07/11 07:12:30 | 000,510,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\policymanager.dll
[2019/07/11 07:12:30 | 000,506,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\edgeIso.dll
[2019/07/11 07:12:30 | 000,493,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcryptprimitives.dll
[2019/07/11 07:12:30 | 000,356,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcryptprimitives.dll
[2019/07/11 07:12:30 | 000,251,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppwinob.dll
[2019/07/11 07:12:30 | 000,093,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wldp.dll
[2019/07/11 07:12:29 | 002,406,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AcGenral.dll
[2019/07/11 07:12:29 | 001,609,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2019/07/11 07:12:29 | 001,339,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TaskFlowDataEngine.dll
[2019/07/11 07:12:29 | 001,328,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpx.dll
[2019/07/11 07:12:29 | 001,130,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msvproc.dll
[2019/07/11 07:12:29 | 001,098,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msvproc.dll
[2019/07/11 07:12:29 | 000,983,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2019/07/11 07:12:29 | 000,832,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncHost.exe
[2019/07/11 07:12:29 | 000,790,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fontdrvhost.exe
[2019/07/11 07:12:29 | 000,785,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pkeyhelper.dll
[2019/07/11 07:12:29 | 000,765,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdh.dll
[2019/07/11 07:12:29 | 000,723,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll
[2019/07/11 07:12:29 | 000,681,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Security.Authentication.Web.Core.dll
[2019/07/11 07:12:29 | 000,544,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2019/07/11 07:12:29 | 000,433,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotification.exe
[2019/07/11 07:12:29 | 000,392,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\daxexec.dll
[2019/07/11 07:12:29 | 000,362,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Storage.ApplicationData.dll
[2019/07/11 07:12:29 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AcGenral.dll
[2019/07/11 07:12:29 | 000,080,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wldp.dll
[2019/07/11 07:12:28 | 001,220,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Unistore.dll
[2019/07/11 07:12:28 | 001,217,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcore.dll
[2019/07/11 07:12:28 | 001,076,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\efscore.dll
[2019/07/11 07:12:28 | 001,063,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SecConfig.efi
[2019/07/11 07:12:28 | 000,871,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.BackgroundMediaPlayback.dll
[2019/07/11 07:12:28 | 000,869,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Playback.BackgroundMediaPlayer.dll
[2019/07/11 07:12:28 | 000,849,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Playback.MediaPlayer.dll
[2019/07/11 07:12:28 | 000,766,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicensingWinRT.dll
[2019/07/11 07:12:28 | 000,713,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MSVideoDSP.dll
[2019/07/11 07:12:28 | 000,665,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wer.dll
[2019/07/11 07:12:28 | 000,662,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fontdrvhost.exe
[2019/07/11 07:12:28 | 000,660,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LicensingWinRT.dll
[2019/07/11 07:12:28 | 000,648,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.BackgroundMediaPlayback.dll
[2019/07/11 07:12:28 | 000,646,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Playback.BackgroundMediaPlayer.dll
[2019/07/11 07:12:28 | 000,630,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Playback.MediaPlayer.dll
[2019/07/11 07:12:28 | 000,622,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdh.dll
[2019/07/11 07:12:28 | 000,604,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\securekernel.exe
[2019/07/11 07:12:28 | 000,568,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tcblaunch.exe
[2019/07/11 07:12:28 | 000,523,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dmenrollengine.dll
[2019/07/11 07:12:28 | 000,443,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\policymanager.dll
[2019/07/11 07:12:28 | 000,361,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DeviceEnroller.exe
[2019/07/11 07:12:28 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\edgeIso.dll
[2019/07/11 07:12:28 | 000,322,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotificationUx.exe
[2019/07/11 07:12:28 | 000,302,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CXHProvisioningServer.dll
[2019/07/11 07:12:28 | 000,295,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TDLMigration.dll
[2019/07/11 07:12:28 | 000,287,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Storage.ApplicationData.dll
[2019/07/11 07:12:28 | 000,130,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rmclient.dll
[2019/07/11 07:12:27 | 001,076,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdpcore.dll
[2019/07/11 07:12:27 | 000,965,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Unistore.dll
[2019/07/11 07:12:27 | 000,761,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nshwfp.dll
[2019/07/11 07:12:27 | 000,755,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Core.TextInput.dll
[2019/07/11 07:12:27 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\nshwfp.dll
[2019/07/11 07:12:27 | 000,581,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MSVideoDSP.dll
[2019/07/11 07:12:27 | 000,578,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\webplatstorageserver.dll
[2019/07/11 07:12:27 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nltest.exe
[2019/07/11 07:12:27 | 000,501,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rastls.dll
[2019/07/11 07:12:27 | 000,462,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdedit.exe
[2019/07/11 07:12:27 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dmenrollengine.dll
[2019/07/11 07:12:27 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpclip.exe
[2019/07/11 07:12:27 | 000,416,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanapi.dll
[2019/07/11 07:12:27 | 000,394,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InputSwitch.dll
[2019/07/11 07:12:27 | 000,330,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptprov.dll
[2019/07/11 07:12:27 | 000,328,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanapi.dll
[2019/07/11 07:12:27 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxAllUserStore.dll
[2019/07/11 07:12:27 | 000,310,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wc_storage.dll
[2019/07/11 07:12:27 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptprov.dll
[2019/07/11 07:12:27 | 000,239,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vdsbas.dll
[2019/07/11 07:12:27 | 000,236,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EditionUpgradeManagerObj.dll
[2019/07/11 07:12:27 | 000,221,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\EditionUpgradeManagerObj.dll
[2019/07/11 07:12:27 | 000,209,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wermgr.exe
[2019/07/11 07:12:27 | 000,194,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\skci.dll
[2019/07/11 07:12:27 | 000,191,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wermgr.exe
[2019/07/11 07:12:27 | 000,153,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dssvc.dll
[2019/07/11 07:12:27 | 000,146,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicensingUI.exe
[2019/07/11 07:12:27 | 000,137,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcrypt.dll
[2019/07/11 07:12:27 | 000,134,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvloader.dll
[2019/07/11 07:12:27 | 000,115,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kdnet.dll
[2019/07/11 07:12:27 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\profext.dll
[2019/07/11 07:12:27 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ngcpopkeysrv.dll
[2019/07/11 07:12:27 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationControllerPS.dll
[2019/07/11 07:12:27 | 000,101,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rmclient.dll
[2019/07/11 07:12:27 | 000,101,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\changepk.exe
[2019/07/11 07:12:27 | 000,094,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2019/07/11 07:12:27 | 000,091,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpfve.sys
[2019/07/11 07:12:27 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KdsCli.dll
[2019/07/11 07:12:27 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\offreg.dll
[2019/07/11 07:12:27 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\offreg.dll
[2019/07/11 07:12:27 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TokenBrokerUI.dll
[2019/07/11 07:12:27 | 000,036,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DeviceCensus.exe
[2019/07/11 07:12:26 | 000,677,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\HeadTrackerStorage.dll
[2019/07/11 07:12:26 | 000,582,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Core.TextInput.dll
[2019/07/11 07:12:26 | 000,508,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_Notifications.dll
[2019/07/11 07:12:26 | 000,450,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rastls.dll
[2019/07/11 07:12:26 | 000,409,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanmsm.dll
[2019/07/11 07:12:26 | 000,371,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\InputSwitch.dll
[2019/07/11 07:12:26 | 000,251,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msIso.dll
[2019/07/11 07:12:26 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DesktopSwitcherDataModel.dll
[2019/07/11 07:12:26 | 000,230,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
[2019/07/11 07:12:26 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\enrollmentapi.dll
[2019/07/11 07:12:26 | 000,181,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EditionUpgradeHelper.dll
[2019/07/11 07:12:26 | 000,178,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dmvdsitf.dll
[2019/07/11 07:12:26 | 000,172,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\enrollmentapi.dll
[2019/07/11 07:12:26 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dmvdsitf.dll
[2019/07/11 07:12:26 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mdmmigrator.dll
[2019/07/11 07:12:26 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InputLocaleManager.dll
[2019/07/11 07:12:26 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\splwow64.exe
[2019/07/11 07:12:26 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSysprep.dll
[2019/07/11 07:12:26 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\profext.dll
[2019/07/11 07:12:26 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RjvMDMConfig.dll
[2019/07/11 07:12:26 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MDMAgent.exe
[2019/07/11 07:12:26 | 000,093,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSReset.exe
[2019/07/11 07:12:26 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TpmTasks.dll
[2019/07/11 07:12:26 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UpgradeResultsUI.exe
[2019/07/11 07:12:26 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TokenBrokerUI.dll
[2019/07/11 07:12:26 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\werdiagcontroller.dll
[2019/07/10 05:05:18 | 000,367,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdFilter.sys
[2019/07/10 05:05:18 | 000,054,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdNisDrv.sys
[2019/07/10 05:05:18 | 000,047,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdBoot.sys
[2019/07/09 22:54:17 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Macromedia
[2019/07/08 23:47:42 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Geek Uninstaller
[2019/07/08 23:42:17 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\sho50\Desktop\HijackThis.exe
[2019/07/08 23:40:08 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Google
[2019/07/08 23:38:38 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2019/07/08 23:33:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2019/07/08 23:30:46 | 000,000,000 | ---D | C] -- C:\Users\sho50\Desktop\geek (3)
[2019/07/08 23:28:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lhaplus
[2019/07/08 23:28:23 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Programs
[2019/07/08 23:12:57 | 000,000,000 | ---D | C] -- C:\ProgramData\UniqueId
[2019/07/07 13:53:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2019/07/07 13:53:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2019/06/29 18:08:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel
[2019/06/29 18:06:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\DriverData\Intel\Wlan
[2019/06/29 18:06:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\DriverData\Intel\Wlan\Router
[2019/06/29 18:06:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\DriverData\Intel
[2019/06/29 14:22:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2019/06/29 13:57:08 | 000,000,000 | ---D | C] -- C:\Program Files\rempl
[2019/06/29 06:16:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\MRT
[2019/06/29 06:08:21 | 000,000,000 | ---D | C] -- C:\Program Files\UNP
[2019/06/26 00:52:25 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Microsoft Help
[2019/06/24 22:47:09 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\PlaceholderTileLogoFolder
[2019/06/24 22:45:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Packages
[2019/06/24 22:32:59 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\DBG
[2019/06/24 22:31:04 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Power2Go8
[2019/06/24 22:31:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft OneDrive
[2019/06/24 22:30:58 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Comms
[2019/06/24 22:29:41 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\MicrosoftEdge
[2019/06/24 22:29:37 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Publishers
[2019/06/24 22:29:30 | 000,000,000 | R--D | C] -- C:\Users\sho50\Searches
[2019/06/24 22:29:29 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\VirtualStore
[2019/06/24 22:29:29 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Packages
[2019/06/24 22:29:29 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Adobe
[2019/06/24 22:29:28 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Intel
[2019/06/24 22:29:28 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\ConnectedDevicesPlatform
[2019/06/24 22:29:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Intel
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\デスクトップ
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\スタート メニュー
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\Templates
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\Documents
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\Application Data
[2019/06/24 21:09:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\wd
[2019/06/24 21:07:27 | 000,000,000 | --SD | C] -- C:\Users\sho50\AppData\Roaming\Microsoft
[2019/06/24 21:07:27 | 000,000,000 | R--D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
[2019/06/24 21:07:27 | 000,000,000 | R--D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2019/06/24 21:07:27 | 000,000,000 | R--D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2019/06/24 21:07:27 | 000,000,000 | R--D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start
  • sho
  • 2019/07/23 (Tue) 23:15:32
Re: プラウザが勝手に開かれます。
OTL(3)

Menu\Programs\Accessibility
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\スタート メニュー
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\AppData\Local\Temporary Internet Files
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Templates
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\SendTo
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Recent
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\PrintHood
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\NetHood
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Documents\My Videos
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Documents\My Pictures
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Documents\My Music
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\My Documents
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Local Settings
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\AppData\Local\History
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Cookies
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Application Data
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\AppData\Local\Application Data
[2019/06/24 21:07:27 | 000,000,000 | -H-D | C] -- C:\Users\sho50\AppData
[2019/06/24 21:07:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Temp
[2019/06/24 21:07:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\Roaming
[2019/06/24 21:07:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Microsoft
[2019/06/24 21:07:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2019/06/24 20:58:32 | 000,000,000 | ---D | C] -- C:\ProgramData\USOShared
[2019/06/24 20:58:31 | 002,752,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PrintConfig.dll
[2019/06/24 20:57:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Synaptics
[2019/06/24 20:57:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Audyssey Labs
[2019/06/24 20:57:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\RTCOM
[2019/06/24 20:57:05 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2019/06/24 20:56:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2019/06/24 20:56:54 | 000,146,384 | ---- | C] (Khronos Group) -- C:\WINDOWS\SysNative\OpenCL.DLL
[2019/06/24 20:56:54 | 000,121,296 | ---- | C] (Khronos Group) -- C:\WINDOWS\SysWow64\OpenCL.DLL
[2019/06/24 20:56:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VulkanRT
[2019/06/24 20:56:51 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2019/06/24 20:56:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel
[2019/06/24 20:56:41 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2019/06/24 20:56:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SleepStudy
[2019/06/24 20:55:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\InfusedApps
[2019/06/24 20:55:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\Panther
[2019/06/24 20:55:18 | 000,000,000 | ---D | C] -- C:\Windows.old
[2019/06/24 20:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServiceProfiles
[2019/06/24 20:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Microsoft
[2019/06/24 20:54:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sda
[2019/06/24 20:53:41 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2019/06/24 20:52:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\Setup
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\zu-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\zu-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\yo-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\yo-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\XPSViewer
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\xh-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\xh-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\wo-SN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\wo-SN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Media Player
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\vi-VN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\vi-VN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\uz-Latn-UZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\uz-Latn-UZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ur-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ur-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ug-CN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ug-CN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tt-RU
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tt-RU
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tn-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tn-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tk-TM
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tk-TM
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ti-ET
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ti-ET
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tg-Cyrl-TJ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tg-Cyrl-TJ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\te-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\te-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ta-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sw-KE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sw-KE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sr-Cyrl-RS
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sr-Cyrl-RS
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sr-Cyrl-BA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sr-Cyrl-BA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sq-AL
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sq-AL
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\si-LK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sd-Arab-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sd-Arab-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\rw-RW
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\rw-RW
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\quz-PE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\quz-PE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\quc-Latn-GT
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\quc-Latn-GT
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\prs-AF
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\prs-AF
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\pa-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\pa-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\pa-Arab-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\pa-Arab-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\or-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\or-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\OpenSSH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\OCR
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\nso-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\nso-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\nn-NO
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\nn-NO
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ne-NP
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ne-NP
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mt-MT
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mt-MT
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ms-MY
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ms-MY
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mr-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mr-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mn-MN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mn-MN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ml-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ml-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mk-MK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mk-MK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mi-NZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mi-NZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\MailContactsCalendarSync
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\MailContactsCalendarSync
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\lo-LA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\lo-LA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\lb-LU
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\lb-LU
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ky-KG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ky-KG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ku-Arab-IQ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ku-Arab-IQ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\kok-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\kok-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\kn-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\kn-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\km-KH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\km-KH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\kk-KZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\kk-KZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ka-GE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ka-GE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\is-IS
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\is-IS
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ig-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ig-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\id-ID
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\id-ID
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\hy-AM
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\hy-AM
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\hi-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\hi-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ha-Latn-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ha-Latn-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\gu-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\gu-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\gl-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\gl-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\gd-GB
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\gd-GB
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ga-IE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ga-IE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\fil-PH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\fil-PH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\fa-IR
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\fa-IR
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\eu-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\eu-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\cy-GB
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\cy-GB
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\chr-CHER-US
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\chr-CHER-US
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ca-ES-valencia
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ca-ES-valencia
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ca-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ca-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\bs-Latn-BA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\bs-Latn-BA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\bn-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\bn-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\bn-BD
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\bn-BD
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\be-BY
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\be-BY
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\az-Latn-AZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\az-Latn-AZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\as-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\as-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\am-ET
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\af-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\af-ZA
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\winrm
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\WCN
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sysprep
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\slmgr
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Printing_Admin_Scripts
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ja
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\winrm
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WCN
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers\UMDF
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\slmgr
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Printing_Admin_Scripts
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers\ja-JP
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers\UMDF\en-US
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers\en-US
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\en
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\0409
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\UMDF\ja-JP
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\ja-JP
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\ja-JP
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ja
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\UMDF\en-US
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\en-US
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\en-US
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\en
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\DigitalLocker
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\0409
[2019/06/24 20:49:02 | 000,835,688 | ---- | C] (Adobe) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2019/06/24 20:49:02 | 000,179,816 | ---- | C] (Adobe) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2019/06/24 20:47:26 | 000,208,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msclmd.dll
[2019/06/24 20:47:23 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msclmd.dll
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\UNP
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysWow64\Nui
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\Nui
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysWow64\F12
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\F12
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\dsc
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysWow64\DiagSvcs
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\DiagSvcs
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysWow64\Configuration
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\Configuration
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\zh-TW
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\zh-TW
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\zh-CN
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\zh-CN
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\WinMetadata
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WinMetadata
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\winevt
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\WindowsPowerShell
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WindowsPowerShell
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WinBioPlugIns
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WinBioDatabase
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Web
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WDI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\wbem
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\wbem
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\WaaS
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Vss
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\uk-UA
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\uk-UA
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tr-TR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tr-TR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\tracing
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\th-TH
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\th-TH
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\TextInput
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Tasks
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Tasks
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\TAPI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ta-lk
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ta-in
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWOW64
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SystemResources
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SystemResetPlatform
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SystemApps
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sv-SE
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sv-SE
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sru
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sru
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sr-Latn-RS
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sr-Latn-RS
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sppui
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sppui
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\spp
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\spp
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\spool
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Speech_OneCore
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Speech_OneCore
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Speech_OneCore
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Speech
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System\Speech
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Speech
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Speech
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\SMI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sl-SI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sl-SI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sk-SK
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sk-SK
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SKB
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\si-lk
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ShellExperiences
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\ShellExperiences
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\ShellComponents
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\setup
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\setup
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServiceState
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\security
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SecureBootUpdates
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\schemas
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SchCache
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ru-RU
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ru-RU
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ro-RO
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ro-RO
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\restore
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\restore
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\rescache
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Recovery
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Recovery
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\RasToast
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\RasToast
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ras
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ras
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\pt-PT
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\pt-PT
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\pt-BR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\pt-BR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ProximityToast
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\PointOfService
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\pl-PL
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\pl-PL
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\oobe
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\oobe
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\nl-NL
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\nl-NL
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\networklist
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\networklist
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\NDF
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\NDF
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\nb-NO
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\nb-NO
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\my-mm
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\MUI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\MUI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Msdtc
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\MsDtc
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\MSDRM
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\MSDRM
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\migwiz
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\migwiz
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\migration
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\migration
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Macromed
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Macromed
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\lv-LV
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\lv-LV
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\lt-LT
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\lt-LT
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\LogFiles
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\LogFiles
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Licenses
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Licenses
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ko-KR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ko-KR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ja-JP
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ja-jp
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\it-IT
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\it-IT
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Ipmi
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Ipmi
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\InstallShield
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\InputMethod
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\InputMethod
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\inetsrv
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\inetsrv
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\IME
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\IME
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\icsxml
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\icsxml
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\hydrogen
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\hu-HU
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\hu-HU
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\hr-HR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\hr-HR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\he-IL
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\he-IL
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\GroupPolicyUsers
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\GroupPolicyUsers
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\GroupPolicy
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\GroupPolicy
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\FxsTmp
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\FxsTmp
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\fr-FR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\fr-FR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\fr-CA
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\fr-CA
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\fi-FI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\fi-FI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\et-EE
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\et-EE
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\etc
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\es-MX
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\es-MX
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\es-ES
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\es-ES
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\en-US
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\en-US
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\en-GB
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\en-GB
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\el-GR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\el-GR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\DriverStore
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\DriverState
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\DriverData
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\downlevel
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\downlevel
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Dism
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Dism
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\de-DE
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\de-DE
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\DDFs
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\da-DK
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\da-DK
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\cs-CZ
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\cs-CZ
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\config
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\com
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\com
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\CodeIntegrity
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\catroot2
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\catroot
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Bthprops
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Bthprops
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Boot
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\bg-BG
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\bg-BG
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ar-SA
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ar-SA
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\appraiser
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\AppLocker
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\AppLocker
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\am-et
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\AdvancedInstallers
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\AdvancedInstallers
[2019/06/24 20:47:18 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft
[2019/06/24 20:47:18 | 000,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2019/06/24 20:47:18 | 000,000,000 | R-SD | C] -- C:\WINDOWS\media
[2019/06/24 20:47:18 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\Program Files\Windows Defender
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\Program Files
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\Program Files (x86)
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\WINDOWS\PrintDialog
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\WINDOWS\Microsoft.NET
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\WINDOWS\ImmersiveControlPanel
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\WINDOWS\assembly
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
[2019/06/24 20:47:18 | 000,000,000 | -HSD | C] -- C:\Program Files\Windows Sidebar
[2019/06/24 20:47:18 | 000,000,000 | -HSD | C] -- C:\Program Files (x86)\Windows Sidebar
[2019/06/24 20:47:18 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2019/06/24 20:47:18 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsApps
[2019/06/24 20:47:18 | 000,000,000 | -H-D | C] -- C:\ProgramData
[2019/06/24 20:47:18 | 000,000,000 | -H-D | C] -- C:\WINDOWS\LanguageOverlayCache
[2019/06/24 20:47:18 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ELAMBKUP
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\WindowsPowerShell
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WindowsPowerShell
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsHolographicDevices
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Security
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Portable Devices
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Photo Viewer
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Photo Viewer
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\windows nt
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\windows nt
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Multimedia Platform
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Multimedia Platform
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Mail
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Mail
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Defender
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\ProgramData\USOPrivate
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\system
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\system
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Sysprep
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\ProgramData\SoftwareDistribution
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Services
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1991-06.com.microsoft
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Provisioning
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\prefetch
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\PolicyDefinitions
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\PLA
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Performance
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\PerfLogs
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\ModemLogs
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Migration
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\microsoft shared
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\microsoft shared
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\LiveKernelReports
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\L2Schemas
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\internet explorer
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Internet Explorer
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\InputMethod
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\IME
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\IdentityCRL
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Globalization
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\GameBarPresenceWriter
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\diagnostics
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\debug
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Branding
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Boot
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\bcastdvr
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppReadiness
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\apppatch
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\appcompat
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins
[2019/06/24 20:47:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\UMDF
[2019/06/24 20:47:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers
[2019/06/24 20:46:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\INF
[2019/06/24 20:44:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\CbsTemp
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\Windows
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\Users
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SMI
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\servicing
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\DriverStore
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\config
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\CatRoot
[2019/06/24 20:42:51 | 000,000,000 | -H-D | C] -- C:\$SysReset

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2019/07/23 22:29:46 | 001,447,762 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2019/07/23 22:29:46 | 000,699,960 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2019/07/23 22:29:46 | 000,481,536 | ---- | M] () -- C:\WINDOWS\SysNative\perfh011.dat
[2019/07/23 22:29:46 | 000,132,900 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2019/07/23 22:29:46 | 000,132,468 | ---- | M] () -- C:\WINDOWS\SysNative\perfc011.dat
[2019/07/23 22:26:58 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2019/07/23 22:25:10 | 000,073,584 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2019/07/23 22:25:08 | 000,224,408 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\farflt.sys
[2019/07/23 22:25:08 | 000,116,112 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2019/07/23 22:25:04 | 000,275,232 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbamswissarmy.sys
[2019/07/23 22:24:58 | 016,777,216 | -HS- | M] () -- C:\swapfile.sys
[2019/07/23 22:24:54 | 3406,987,264 | -HS- | M] () -- C:\hiberfil.sys
[2019/07/23 22:23:43 | 000,199,768 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MbamChameleon.sys
[2019/07/23 22:23:41 | 000,000,214 | ---- | M] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job
[2019/07/23 22:19:13 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\sho50\Desktop\OTL.exe
[2019/07/16 07:03:55 | 000,002,257 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2019/07/15 07:38:27 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
[2019/07/14 16:57:48 | 007,025,360 | ---- | M] (Malwarebytes) -- C:\Users\sho50\Desktop\AdwCleaner.exe
[2019/07/13 12:34:50 | 000,001,923 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2019/07/13 12:33:28 | 064,552,472 | ---- | M] (Malwarebytes ) -- C:\Users\sho50\Desktop\mb3-setup-consumer-3.8.3.2965-1.0.613-1.0.11520.exe
[2019/07/13 03:08:26 | 000,272,352 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2019/07/10 05:05:17 | 000,367,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdFilter.sys
[2019/07/10 05:05:17 | 000,054,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdNisDrv.sys
[2019/07/10 05:05:17 | 000,047,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdBoot.sys
[2019/07/08 23:52:37 | 000,002,353 | ---- | M] () -- C:\Users\sho50\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2019/07/08 23:42:18 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\sho50\Desktop\HijackThis.exe
[2019/07/08 23:38:41 | 000,000,874 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2019/07/08 23:28:41 | 000,001,071 | ---- | M] () -- C:\Users\sho50\Desktop\Lhaplus.lnk
[2019/07/08 23:08:17 | 002,098,176 | ---- | M] () -- C:\WINDOWS\SysNative\UserMgrLog.etl
[2019/07/08 23:08:17 | 000,147,456 | ---- | M] () -- C:\WINDOWS\SysNative\umstartup.etl
[2019/07/07 12:53:14 | 001,062,912 | ---- | M] () -- C:\WINDOWS\SysNative\UserMgrLogBackup.etl
[2019/07/07 12:53:14 | 000,024,576 | ---- | M] () -- C:\WINDOWS\SysNative\umstartup000.etl
[2019/07/04 18:43:27 | 000,094,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2019/07/04 18:40:51 | 000,790,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fontdrvhost.exe
[2019/07/04 18:40:33 | 001,631,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32full.dll
[2019/07/04 18:40:32 | 001,616,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppobjs.dll
[2019/07/04 18:22:58 | 000,131,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\splwow64.exe
[2019/07/04 18:22:43 | 000,128,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSysprep.dll
[2019/07/04 18:21:11 | 008,627,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll
[2019/07/04 18:20:08 | 001,609,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2019/07/04 18:19:44 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpclip.exe
[2019/07/04 18:18:59 | 003,614,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kfull.sys
[2019/07/04 18:18:11 | 001,663,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GdiPlus.dll
[2019/07/04 17:56:04 | 001,453,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gdi32full.dll
[2019/07/04 17:54:37 | 000,662,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fontdrvhost.exe
[2019/07/04 17:41:01 | 007,990,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll
[2019/07/04 17:37:57 | 002,882,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\win32kfull.sys
[2019/07/04 17:36:56 | 001,471,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GdiPlus.dll
[2019/07/04 14:00:29 | 001,035,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ApplyTrustOffline.exe
[2019/07/04 13:58:29 | 001,328,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpx.dll
[2019/07/04 13:58:09 | 001,219,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvix64.exe
[2019/07/04 13:58:06 | 000,416,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanapi.dll
[2019/07/04 13:57:57 | 001,027,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvax64.exe
[2019/07/04 13:57:57 | 000,568,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tcblaunch.exe
[2019/07/04 13:57:57 | 000,194,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\skci.dll
[2019/07/04 13:57:57 | 000,134,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvloader.dll
[2019/07/04 13:57:18 | 000,362,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Storage.ApplicationData.dll
[2019/07/04 13:57:16 | 000,986,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncHost.exe
[2019/07/04 13:57:15 | 000,776,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wer.dll
[2019/07/04 13:57:14 | 000,723,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll
[2019/07/04 13:57:13 | 000,209,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wermgr.exe
[2019/07/04 13:57:05 | 003,292,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\combase.dll
[2019/07/04 13:57:03 | 000,137,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcrypt.dll
[2019/07/04 13:57:00 | 000,091,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpfve.sys
[2019/07/04 13:56:32 | 007,436,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\windows.storage.dll
[2019/07/04 13:56:32 | 000,493,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcryptprimitives.dll
[2019/07/04 13:56:27 | 009,084,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2019/07/04 13:56:26 | 007,519,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Protection.PlayReady.dll
[2019/07/04 13:56:26 | 002,571,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2019/07/04 13:56:21 | 001,141,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2019/07/04 13:56:21 | 000,983,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2019/07/04 13:56:20 | 001,566,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxPackaging.dll
[2019/07/04 13:56:20 | 000,734,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentClient.dll
[2019/07/04 13:56:13 | 000,713,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MSVideoDSP.dll
[2019/07/04 13:56:10 | 001,459,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2019/07/04 13:56:10 | 001,260,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2019/07/04 13:56:10 | 000,767,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dnsapi.dll
[2019/07/04 13:56:05 | 000,604,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\securekernel.exe
[2019/07/04 13:56:03 | 000,115,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kdnet.dll
[2019/07/04 13:43:21 | 000,191,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wermgr.exe
[2019/07/04 13:43:17 | 000,287,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Storage.ApplicationData.dll
[2019/07/04 13:43:03 | 000,832,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncHost.exe
[2019/07/04 13:43:02 | 000,328,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanapi.dll
[2019/07/04 13:43:01 | 000,665,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wer.dll
[2019/07/04 13:42:46 | 002,479,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\combase.dll
[2019/07/04 13:42:13 | 006,044,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\windows.storage.dll
[2019/07/04 13:42:13 | 000,356,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcryptprimitives.dll
[2019/07/04 13:42:07 | 001,427,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxPackaging.dll
[2019/07/04 13:42:03 | 006,570,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
[2019/07/04 13:41:58 | 000,559,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
[2019/07/04 13:37:42 | 025,857,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\edgehtml.dll
[2019/07/04 13:33:43 | 022,017,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\edgehtml.dll
[2019/07/04 13:26:50 | 000,310,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wc_storage.dll
[2019/07/04 13:26:46 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TpmTasks.dll
[2019/07/04 13:26:18 | 004,385,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EdgeContent.dll
[2019/07/04 13:25:57 | 000,295,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TDLMigration.dll
[2019/07/04 13:25:34 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\offreg.dll
[2019/07/04 13:25:22 | 007,589,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Chakra.dll
[2019/07/04 13:25:07 | 004,861,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2019/07/04 13:25:01 | 003,401,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2019/07/04 13:24:31 | 000,153,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dssvc.dll
[2019/07/04 13:24:16 | 000,462,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdedit.exe
[2019/07/04 13:24:11 | 000,567,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\daxexec.dll
[2019/07/04 13:23:05 | 001,217,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcore.dll
[2019/07/04 13:22:48 | 001,549,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2019/07/04 13:22:47 | 002,176,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.onecore.dll
[2019/07/04 13:22:28 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\werdiagcontroller.dll
[2019/07/04 13:22:18 | 001,175,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncCore.dll
[2019/07/04 13:22:01 | 001,561,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.desktop.dll
[2019/07/04 13:22:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\profext.dll
[2019/07/04 13:21:45 | 000,124,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\profext.dll
[2019/07/04 13:21:43 | 001,220,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Unistore.dll
[2019/07/04 13:21:39 | 005,784,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Chakra.dll
[2019/07/04 13:21:39 | 003,202,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll
[2019/07/04 13:21:33 | 000,324,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxAllUserStore.dll
[2019/07/04 13:21:09 | 002,166,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kbase.sys
[2019/07/04 13:21:02 | 000,059,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\offreg.dll
[2019/07/04 13:20:53 | 000,392,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\daxexec.dll
[2019/07/04 13:20:38 | 000,330,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptprov.dll
[2019/07/04 13:20:14 | 000,544,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2019/07/04 13:19:21 | 000,230,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
[2019/07/04 13:18:53 | 000,953,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncCore.dll
[2019/07/04 13:18:44 | 001,076,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdpcore.dll
[2019/07/04 13:18:19 | 000,965,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Unistore.dll
[2019/07/04 13:18:14 | 000,275,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptprov.dll
[2019/07/04 12:01:57 | 000,001,312 | ---- | M] () -- C:\WINDOWS\SysNative\tcbres.wim
[2019/06/26 13:00:48 | 000,020,936 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MbamElam.sys
[2019/06/24 23:43:26 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2019/06/24 22:30:44 | 000,001,417 | ---- | M] () -- C:\Users\sho50\Desktop\Microsoft Edge.lnk
[2019/06/24 22:08:07 | 000,000,013 | RHS- | M] () -- C:\WINDOWS\SysNative\drivers\fbd.sys
[2019/06/24 21:09:10 | 000,010,984 | ---- | M] () -- C:\Users\sho50\Desktop\削除されたアプリ.html
[2019/06/24 21:08:35 | 000,023,208 | ---- | M] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2019/06/24 20:57:19 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_wbf_vfs_0010_01_09_00.Wdf
[2019/06/24 20:57:14 | 000,004,862 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\rtkhdasetting.zip
[2019/06/24 20:57:12 | 000,000,000 | -H-- | M] () -- C:\ProgramData\DP45977C.lfl
[2019/06/24 20:56:54 | 000,000,000 | ---- | M] () -- C:\WINDOWS\SysNative\GfxValDisplayLog.bin
[2019/06/24 20:56:40 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_SynTP_01011.Wdf
[2019/06/24 20:49:56 | 000,144,624 | ---- | M] () -- C:\WINDOWS\SysNative\perfi011.dat
[2019/06/24 20:49:56 | 000,033,402 | ---- | M] () -- C:\WINDOWS\SysNative\perfd011.dat
[2019/06/24 20:46:14 | 000,215,943 | ---- | M] () -- C:\WINDOWS\SysWow64\dssec.dat
[2019/06/24 20:46:14 | 000,208,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msclmd.dll
[2019/06/24 20:46:14 | 000,003,683 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\etc\lmhosts.sam
[2019/06/24 20:46:14 | 000,000,741 | ---- | M] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2019/06/24 20:46:13 | 000,297,062 | ---- | M] () -- C:\WINDOWS\SysNative\perfi009.dat
[2019/06/24 20:46:13 | 000,229,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msclmd.dll
[2019/06/24 20:46:13 | 000,215,943 | ---- | M] () -- C:\WINDOWS\SysNative\dssec.dat
[2019/06/24 20:46:13 | 000,033,424 | ---- | M] () -- C:\WINDOWS\SysNative\perfd009.dat
[2019/06/24 20:46:13 | 000,017,346 | ---- | M] () -- C:\WINDOWS\SysNative\OEMDefaultAssociations.xml
[2019/06/24 20:46:13 | 000,000,858 | ---- | M] () -- C:\WINDOWS\SysNative\DefaultQuestions.json
[2019/06/24 20:46:13 | 000,000,741 | ---- | M] () -- C:\WINDOWS\SysNative\NOISE.DAT

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2019/07/15 07:38:27 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
[2019/07/13 12:34:50 | 000,001,923 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2019/07/13 03:14:42 | 000,002,469 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
[2019/07/13 03:14:42 | 000,002,462 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
[2019/07/13 03:14:42 | 000,002,412 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
[2019/07/13 03:14:42 | 000,002,398 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
[2019/07/13 03:14:42 | 000,002,394 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
[2019/07/11 07:12:26 | 000,001,312 | ---- | C] () -- C:\WINDOWS\SysNative\tcbres.wim
[2019/07/08 23:38:41 | 000,000,874 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2019/07/08 23:38:37 | 000,002,353 | ---- | C] () -- C:\Users\sho50\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2019/07/08 23:38:37 | 000,002,298 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[2019/07/08 23:38:37 | 000,002,257 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2019/07/08 23:28:41 | 000,001,071 | ---- | C] () -- C:\Users\sho50\Desktop\Lhaplus.lnk
[2019/07/08 23:08:47 | 000,000,214 | ---- | C] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job
[2019/07/07 12:30:53 | 002,098,176 | ---- | C] () -- C:\WINDOWS\SysNative\UserMgrLog.etl
[2019/07/07 12:30:53 | 001,062,912 | ---- | C] () -- C:\WINDOWS\SysNative\UserMgrLogBackup.etl
[2019/07/07 12:30:51 | 000,147,456 | ---- | C] () -- C:\WINDOWS\SysNative\umstartup.etl
[2019/07/07 12:30:51 | 000,024,576 | ---- | C] () -- C:\WINDOWS\SysNative\umstartup000.etl
[2019/06/24 23:43:26 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2019/06/24 22:08:07 | 000,000,013 | RHS- | C] () -- C:\WINDOWS\SysNative\drivers\fbd.sys
[2019/06/24 21:15:24 | 001,447,762 | ---- | C] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2019/06/24 21:09:10 | 000,010,984 | ---- | C] () -- C:\Users\sho50\Desktop\削除されたアプリ.html
[2019/06/24 21:08:35 | 000,023,208 | ---- | C] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2019/06/24 21:07:55 | 3406,987,264 | -HS- | C] () -- C:\hiberfil.sys
[2019/06/24 21:07:27 | 000,002,312 | ---- | C] () -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
[2019/06/24 21:07:27 | 000,000,352 | ---- | C] () -- C:\Users\sho50\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2019/06/24 21:07:27 | 000,000,334 | ---- | C] () -- C:\Users\sho50\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2019/06/24 21:07:05 | 000,001,576 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2019/06/24 20:57:19 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_wbf_vfs_0010_01_09_00.Wdf
[2019/06/24 20:57:14 | 000,004,862 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\rtkhdasetting.zip
[2019/06/24 20:57:12 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
[2019/06/24 20:56:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SysNative\GfxValDisplayLog.bin
[2019/06/24 20:56:40 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_SynTP_01011.Wdf
[2019/06/24 20:56:01 | 000,272,352 | ---- | C] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2019/06/24 20:55:23 | 000,165,846 | ---- | C] () -- C:\WINDOWS\SysWow64\license.rtf
[2019/06/24 20:55:23 | 000,165,846 | ---- | C] () -- C:\WINDOWS\SysNative\license.rtf
[2019/06/24 20:54:58 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2019/06/24 20:50:04 | 000,481,536 | ---- | C] () -- C:\WINDOWS\SysNative\perfh011.dat
[2019/06/24 20:50:04 | 000,144,624 | ---- | C] () -- C:\WINDOWS\SysNative\perfi011.dat
[2019/06/24 20:50:04 | 000,132,468 | ---- | C] () -- C:\WINDOWS\SysNative\perfc011.dat
[2019/06/24 20:50:04 | 000,033,402 | ---- | C] () -- C:\WINDOWS\SysNative\perfd011.dat
[2019/06/24 20:48:39 | 000,699,960 | ---- | C] () -- C:\WINDOWS\SysNative\perfh009.dat
[2019/06/24 20:48:39 | 000,297,062 | ---- | C] () -- C:\WINDOWS\SysNative\perfi009.dat
[2019/06/24 20:48:39 | 000,132,900 | ---- | C] () -- C:\WINDOWS\SysNative\perfc009.dat
[2019/06/24 20:48:39 | 000,033,424 | ---- | C] () -- C:\WINDOWS\SysNative\perfd009.dat
[2019/06/24 20:47:26 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2019/06/24 20:47:26 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2019/06/24 20:47:23 | 000,017,346 | ---- | C] () -- C:\WINDOWS\SysNative\OEMDefaultAssociations.xml
[2019/06/24 20:47:23 | 000,003,683 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\etc\lmhosts.sam
[2019/06/24 20:47:23 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysNative\NOISE.DAT
[2019/06/24 20:47:22 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysNative\dssec.dat
[2019/06/24 20:47:22 | 000,000,858 | ---- | C] () -- C:\WINDOWS\SysNative\DefaultQuestions.json
[2018/09/28 02:47:34 | 000,168,400 | ---- | C] () -- C:\WINDOWS\SysWow64\libGLESv2.dll
[2018/09/28 02:47:32 | 000,149,456 | ---- | C] () -- C:\WINDOWS\SysWow64\libEGL.dll
[2018/09/28 02:47:32 | 000,133,584 | ---- | C] () -- C:\WINDOWS\SysWow64\libGLESv1_CM.dll
[2018/06/21 04:58:22 | 000,232,248 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkaninfo-1-999-0-0-0.exe
[2018/06/21 04:58:22 | 000,232,248 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkaninfo.exe
[2018/06/21 04:58:08 | 000,833,848 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkan-1-999-0-0-0.dll
[2018/06/21 04:58:08 | 000,833,848 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkan-1.dll
[2018/06/14 07:08:48 | 002,841,312 | ---- | C] () -- C:\WINDOWS\SysWow64\Windows.Mirage.dll
[2018/06/09 15:25:38 | 000,018,716 | ---- | C] () -- C:\WINDOWS\SysWow64\srms-apr.dat
[2018/04/12 08:34:55 | 000,518,144 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2018/04/12 08:34:50 | 000,054,272 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2018/04/12 0
  • sho
  • 2019/07/23 (Tue) 23:16:11
Re: プラウザが勝手に開かれます。
再送します。OTL(1)

OTL logfile created on: 2019/07/23 22:29:50 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\sho50\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.17134.0)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

7.93 Gb Total Physical Memory | 5.40 Gb Available Physical Memory | 68.08% Memory free
22.43 Gb Paging File | 19.82 Gb Available in Paging File | 88.34% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 221.82 Gb Total Space | 50.79 Gb Free Space | 22.90% Space Free | Partition Type: NTFS
Drive D: | 3.58 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: LAPTOP-QCSS294P | User Name: sho50 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - File not found --
PRC - [2019/07/23 22:19:13 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\sho50\Desktop\OTL.exe
PRC - [2019/07/04 17:54:37 | 000,662,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\fontdrvhost.exe
PRC - [2019/07/03 22:44:45 | 001,589,368 | ---- | M] (Microsoft Corporation) -- C:\Users\sho50\AppData\Local\Microsoft\OneDrive\OneDrive.exe
PRC - [2019/06/26 11:07:16 | 004,000,080 | ---- | M] (Malwarebytes) -- C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
PRC - [2019/02/28 13:03:58 | 000,689,952 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe
PRC - [2019/02/28 13:03:40 | 000,172,320 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
PRC - [2018/01/18 04:45:12 | 000,324,544 | ---- | M] (Realtek Semiconductor) -- C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
PRC - [2016/11/21 15:36:04 | 000,013,312 | ---- | M] () -- C:\Windows\SysWOW64\SMITSC.exe
PRC - [2016/11/08 19:40:46 | 000,177,440 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
PRC - [2016/11/08 19:40:20 | 000,419,616 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2016/10/17 20:00:02 | 000,173,288 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe
PRC - [2016/10/17 20:00:00 | 000,496,872 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe
PRC - [2015/08/05 15:47:20 | 000,117,712 | ---- | M] (sMedio Inc.) -- C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingServiceTrayIcon.exe
PRC - [2015/08/05 15:47:16 | 000,118,224 | ---- | M] (sMedio Inc) -- C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingService.exe
PRC - [2014/11/20 18:24:05 | 000,110,344 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
PRC - [2011/06/29 10:44:04 | 000,008,704 | ---- | M] (Intercom, Inc.) -- C:\Program Files (x86)\Intercom\LAPLINK HelpDesk Client\LLHDCldr.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2018/04/12 08:34:47 | 000,364,200 | ---- | M] () -- C:\Windows\SysWOW64\InputHost.dll
MOD - [2014/07/04 13:35:48 | 000,627,672 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
MOD - [2014/07/04 12:35:48 | 000,016,856 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - File not found [On_Demand | Stopped] -- C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe -- (Amsp)
SRV:[b]64bit:[/b] - [2019/07/04 13:25:01 | 003,401,216 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:[b]64bit:[/b] - [2019/07/04 13:24:31 | 000,153,600 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dssvc.dll -- (DsSvc)
SRV:[b]64bit:[/b] - [2019/07/04 13:21:43 | 001,220,608 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\Unistore.dll -- (UnistoreSvc)
SRV:[b]64bit:[/b] - [2019/06/26 13:00:14 | 006,744,288 | ---- | M] (Malwarebytes) [Auto | Running] -- C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe -- (MBAMService)
SRV:[b]64bit:[/b] - [2019/06/13 16:46:09 | 000,713,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SharedRealitySvc.dll -- (SharedRealitySvc)
SRV:[b]64bit:[/b] - [2019/06/13 15:44:39 | 001,033,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ClipSVC.dll -- (ClipSVC)
SRV:[b]64bit:[/b] - [2019/06/13 15:10:04 | 001,400,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TokenBroker.dll -- (TokenBroker)
SRV:[b]64bit:[/b] - [2019/06/11 11:37:42 | 000,363,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\rempl\sedsvc.exe -- (sedsvc)
SRV:[b]64bit:[/b] - [2019/06/07 19:40:47 | 001,364,992 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\bcastdvruserservice.dll -- (BcastDVRUserService)
SRV:[b]64bit:[/b] - [2019/06/07 14:18:57 | 000,686,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2019/05/17 14:33:56 | 003,091,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:[b]64bit:[/b] - [2019/05/17 14:33:39 | 001,487,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\InstallService.dll -- (InstallService)
SRV:[b]64bit:[/b] - [2019/05/17 14:31:35 | 001,027,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\usermgr.dll -- (UserManager)
SRV:[b]64bit:[/b] - [2019/05/17 14:31:23 | 001,383,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\usocore.dll -- (UsoSvc)
SRV:[b]64bit:[/b] - [2019/05/03 15:00:17 | 000,090,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe -- (diagnosticshub.standardcollector.service)
SRV:[b]64bit:[/b] - [2019/05/03 14:56:29 | 000,773,632 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:[b]64bit:[/b] - [2019/04/19 13:36:47 | 000,827,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
SRV:[b]64bit:[/b] - [2019/04/19 13:35:53 | 001,458,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dosvc.dll -- (DoSvc)
SRV:[b]64bit:[/b] - [2019/04/19 13:35:22 | 000,784,896 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ngcsvc.dll -- (NgcSvc)
SRV:[b]64bit:[/b] - [2019/03/14 16:50:42 | 000,847,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:[b]64bit:[/b] - [2019/03/14 16:50:38 | 000,947,200 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:[b]64bit:[/b] - [2019/02/28 13:04:24 | 004,110,624 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService)
SRV:[b]64bit:[/b] - [2019/02/28 13:04:08 | 000,311,584 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:[b]64bit:[/b] - [2019/02/28 13:03:58 | 000,689,952 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:[b]64bit:[/b] - [2019/02/28 13:03:40 | 000,172,320 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:[b]64bit:[/b] - [2019/02/16 16:27:02 | 001,364,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lpasvc.dll -- (wlpasvc)
SRV:[b]64bit:[/b] - [2019/02/06 11:25:27 | 000,507,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\svchost.exe -- (WpnUserService_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\svchost.exe -- (UserDataSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\svchost.exe -- (UnistoreSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (PrintWorkflowUserSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\svchost.exe -- (PimIndexMaintenanceSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\svchost.exe -- (OneSyncSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (MessagingService_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (DevicesFlowUserSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (DevicePickerUserSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\svchost.exe -- (CDPUserSvc_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (BluetoothUserService_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:39:42 | 000,085,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (BcastDVRUserService_6fd1c)
SRV:[b]64bit:[/b] - [2019/01/09 14:22:57 | 000,392,704 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WaaSMedicSvc.dll -- (WaaSMedicSvc)
SRV:[b]64bit:[/b] - [2019/01/09 14:22:42 | 000,266,752 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\CapabilityAccessManager.dll -- (camsvc)
SRV:[b]64bit:[/b] - [2019/01/01 15:42:29 | 002,247,680 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:[b]64bit:[/b] - [2018/12/08 17:04:40 | 000,885,760 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\CoreMessaging.dll -- (CoreMessagingRegistrar)
SRV:[b]64bit:[/b] - [2018/12/08 16:36:32 | 000,356,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dusmsvc.dll -- (DusmSvc)
SRV:[b]64bit:[/b] - [2018/12/08 16:36:23 | 000,153,600 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\RMapi.dll -- (RmSvc)
SRV:[b]64bit:[/b] - [2018/11/09 11:20:34 | 000,092,160 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\tzautoupdate.dll -- (tzautoupdate)
SRV:[b]64bit:[/b] - [2018/11/09 11:20:24 | 000,399,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\BthAvctpSvc.dll -- (BthAvctpSvc)
SRV:[b]64bit:[/b] - [2018/11/09 11:18:30 | 000,514,048 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\BTAGService.dll -- (BTAGService)
SRV:[b]64bit:[/b] - [2018/11/09 11:16:04 | 000,308,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\EnterpriseAppMgmtSvc.dll -- (EntAppSvc)
SRV:[b]64bit:[/b] - [2018/11/01 15:59:14 | 000,241,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tetheringservice.dll -- (icssvc)
SRV:[b]64bit:[/b] - [2018/11/01 15:57:53 | 000,835,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\PhoneService.dll -- (PhoneSvc)
SRV:[b]64bit:[/b] - [2018/11/01 15:57:04 | 000,281,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:[b]64bit:[/b] - [2018/10/21 16:14:53 | 000,632,320 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cdpsvc.dll -- (CDPSvc)
SRV:[b]64bit:[/b] - [2018/10/21 16:14:29 | 000,453,632 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\cdpusersvc.dll -- (CDPUserSvc)
SRV:[b]64bit:[/b] - [2018/09/28 02:47:28 | 000,510,464 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\IntelCpHeciSvc.exe -- (cphs)
SRV:[b]64bit:[/b] - [2018/09/28 02:47:28 | 000,505,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\IntelCpHDCPSvc.exe -- (cplspcon)
SRV:[b]64bit:[/b] - [2018/09/28 02:47:16 | 000,413,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\igfxCUIService.exe -- (igfxCUIService2.0.0.0)
SRV:[b]64bit:[/b] - [2018/09/08 12:24:26 | 000,463,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:[b]64bit:[/b] - [2018/08/03 12:41:01 | 000,061,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\hvhostsvc.dll -- (HvHost)
SRV:[b]64bit:[/b] - [2018/07/14 13:23:08 | 000,760,888 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SecurityHealthService.exe -- (SecurityHealthService)
SRV:[b]64bit:[/b] - [2018/07/14 12:54:10 | 000,262,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\PushToInstall.dll -- (PushToInstall)
SRV:[b]64bit:[/b] - [2018/07/14 12:53:02 | 000,681,984 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WFDSConMgrSvc.dll -- (WFDSConMgrSvc)
SRV:[b]64bit:[/b] - [2018/07/06 15:58:32 | 000,091,136 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\moshost.dll -- (MapsBroker)
SRV:[b]64bit:[/b] - [2018/06/15 13:41:49 | 000,235,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:[b]64bit:[/b] - [2018/06/09 15:25:35 | 001,456,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WpcDesktopMonSvc.dll -- (WpcMonSvc)
SRV:[b]64bit:[/b] - [2018/06/09 01:06:33 | 000,976,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Spectrum.exe -- (spectrum)
SRV:[b]64bit:[/b] - [2018/06/08 18:29:32 | 004,970,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\Windows.StateRepository.dll -- (StateRepository)
SRV:[b]64bit:[/b] - [2018/06/08 17:59:09 | 000,673,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FrameServer.dll -- (FrameServer)
SRV:[b]64bit:[/b] - [2018/06/08 17:56:37 | 000,858,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FlightSettings.dll -- (wisvc)
SRV:[b]64bit:[/b] - [2018/06/08 17:55:04 | 000,667,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:[b]64bit:[/b] - [2018/05/10 21:37:48 | 000,541,896 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\WINDOWS\SysNative\ibtsiva.exe -- (ibtsiva)
SRV:[b]64bit:[/b] - [2018/04/12 08:35:21 | 000,681,984 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\RDXService.dll -- (RetailDemo)
SRV:[b]64bit:[/b] - [2018/04/12 08:35:21 | 000,427,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WalletService.dll -- (WalletService)
SRV:[b]64bit:[/b] - [2018/04/12 08:35:21 | 000,400,896 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\Windows.Devices.Picker.dll -- (DevicePickerUserSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:43 | 000,824,832 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NaturalAuth.dll -- (NaturalAuthentication)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:43 | 000,590,336 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SmsRouterSvc.dll -- (SmsRouter)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:43 | 000,121,344 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:41 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:40 | 000,013,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:39 | 000,219,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DiagSvc.dll -- (diagsvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:38 | 000,671,744 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:37 | 000,303,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\TieringEngineService.exe -- (TieringEngineService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:37 | 000,198,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:34 | 001,273,344 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SensorDataService.exe -- (SensorDataService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:33 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\PrintWorkflowService.dll -- (PrintWorkflowUserSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:25 | 000,058,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:24 | 000,081,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:24 | 000,027,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:23 | 000,167,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:22 | 000,335,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NetSetupSvc.dll -- (NetSetupSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:22 | 000,089,088 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:19 | 000,750,080 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\DevicesFlowBroker.dll -- (DevicesFlowUserSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:19 | 000,195,584 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\Windows.SharedPC.AccountManager.dll -- (shpamsvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,712,192 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SensorService.dll -- (SensorService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,057,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dmwappushsvc.dll -- (dmwappushservice)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,023,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 001,495,040 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\UserDataService.dll -- (UserDataSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,582,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NgcCtnrSvc.dll -- (NgcCtnrSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,345,600 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,280,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wpnservice.dll -- (WpnService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,185,856 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\PimIndexMaintenance.dll -- (PimIndexMaintenanceSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,176,128 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBrokerSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,096,768 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\WpnUserService.dll -- (WpnUserService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,058,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\xboxgipsvc.dll -- (XboxGipSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,044,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lfsvc.dll -- (lfsvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:10 | 001,248,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SEMgrSvc.dll -- (SEMgrSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:10 | 000,376,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:10 | 000,048,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\LicenseManagerSvc.dll -- (LicenseManager)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:10 | 000,033,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DevQueryBroker.dll -- (DevQueryBroker)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:08 | 001,308,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XblGameSave.dll -- (XblGameSave)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:08 | 000,167,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\embeddedmodesvc.dll -- (embeddedmode)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:08 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GraphicsPerfSvc.dll -- (GraphicsPerfSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:08 | 000,059,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\xbgmsvc.exe -- (xbgm)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:08 | 000,031,744 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Windows.WARP.JITService.dll -- (WarpJITSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:07 | 001,115,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XblAuthManager.dll -- (XblAuthManager)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:06 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AJRouter.dll -- (AJRouter)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 001,148,928 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XboxNetApiSvc.dll -- (XboxNetApiSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,411,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vac.dll -- (VacSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,199,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\LanguageOverlayServer.dll -- (LxpSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,163,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SgrmBroker.exe -- (SgrmBroker)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,052,224 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\MessagingService.dll -- (MessagingService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:02 | 000,464,384 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\Microsoft.Bluetooth.UserService.dll -- (BluetoothUserService)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:02 | 000,063,488 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ipxlatcfg.dll -- (IpxlatCfgSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 002,197,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,309,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvcext.dll -- (vmicvss)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,309,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvcext.dll -- (vmicrdv)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvmsession)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:47 | 003,441,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:[b]64bit:[/b] - [2018/04/11 06:05:00 | 000,324,608 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\APHostService.dll -- (OneSyncSvc)
SRV:[b]64bit:[/b] - [2018/03/29 00:28:20 | 000,287,240 | ---- | M] (Synaptics Incorporated) [Auto | Running] -- C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe -- (SynTPEnhService)
SRV:[b]64bit:[/b] - [2018/03/11 03:20:00 | 000,495,616 | ---- | M] () [Disabled | Stopped] -- C:\Windows\SysNative\OpenSSH\ssh-agent.exe -- (ssh-agent)
SRV:[b]64bit:[/b] - [2018/01/18 04:45:12 | 000,324,544 | ---- | M] (Realtek Semiconductor) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe -- (RtkAudioService)
SRV:[b]64bit:[/b] - [2016/11/21 06:24:12 | 000,091,680 | ---- | M] (Synaptics Incorporated) [Auto | Running] -- C:\Windows\SysNative\valWBFPolicyService.exe -- (valWBFPolicyService)
SRV:[b]64bit:[/b] - [2016/11/16 11:06:04 | 000,219,568 | ---- | M] (Toshiba Client Solutions Co., Ltd.) [Auto | Running] -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\TStationSrv.exe -- (TStationSrv)
SRV:[b]64bit:[/b] - [2016/11/08 16:50:02 | 000,064,776 | ---- | M] (Toshiba Client Solutions Co., Ltd.) [Auto | Running] -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV:[b]64bit:[/b] - [2016/11/01 17:18:02 | 000,034,528 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files\Intel\Intel(R) Online Connect\iocHelperService.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2016/11/01 17:18:02 | 000,025,312 | ---- | M] (Intel Corporation) [On_Demand | Start_Pending] -- C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2016/10/17 20:00:02 | 000,173,288 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2016/10/17 20:00:00 | 000,496,872 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2016/10/13 21:42:24 | 000,630,048 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2016/07/20 14:58:04 | 000,992,480 | ---- | M] (Toshiba Client Solutions Co., Ltd.) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV:[b]64bit:[/b] - [2016/07/18 14:33:14 | 000,338,208 | ---- | M] (Toshiba Client Solutions Co., Ltd.) [Auto | Running] -- C:\Program Files\TOSHIBA\Teco\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV:[b]64bit:[/b] - [2015/10/05 13:33:13 | 000,614,664 | ---- | M] (CyberLink) [Auto | Running] -- C:\Program Files\CyberLink\Shared files\RichVideo64.exe -- (RichVideo64)
SRV:[b]64bit:[/b] - [2015/07/30 06:38:26 | 000,241,632 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\Titanium\TiMiniService.exe -- (TiMiniService)
SRV - [2019/07/13 08:11:51 | 001,098,224 | ---- | M] (Google LLC) [On_Demand | Stopped] -- C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\elevation_service.exe -- (GoogleChromeElevationService)
SRV - [2019/07/10 05:05:17 | 002,455,544 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1906.3-0\NisSrv.exe -- (WdNisSvc)
SRV - [2019/07/10 05:05:17 | 000,110,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1906.3-0\MsMpEng.exe -- (WinDefend)
SRV - [2019/07/04 13:18:19 | 000,965,632 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\Unistore.dll -- (UnistoreSvc)
SRV - [2019/06/13 13:44:26 | 001,003,008 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\TokenBroker.dll -- (TokenBroker)
SRV - [2019/05/17 15:19:08 | 001,110,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\InstallService.dll -- (InstallService)
SRV - [2019/04/19 13:38:40 | 000,593,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
SRV - [2018/12/08 16:45:30 | 000,567,256 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\CoreMessaging.dll -- (CoreMessagingRegistrar)
SRV - [2018/09/28 02:47:28 | 000,510,464 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\IntelCpHeciSvc.exe -- (cphs)
SRV - [2018/09/28 02:47:28 | 000,505,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\IntelCpHDCPSvc.exe -- (cplspcon)
SRV - [2018/09/28 02:47:16 | 000,413,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\igfxCUIService.exe -- (igfxCUIService2.0.0.0)
SRV - [2018/06/08 18:09:43 | 004,469,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\Windows.StateRepository.dll -- (StateRepository)
SRV - [2018/06/08 17:54:26 | 000,729,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\FlightSettings.dll -- (wisvc)
SRV - [2018/04/12 08:35:22 | 000,312,832 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\Windows.Devices.Picker.dll -- (DevicePickerUserSvc)
SRV - [2018/04/12 08:34:57 | 000,138,240 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\PrintWorkflowService.dll -- (PrintWorkflowUserSvc)
SRV - [2018/04/12 08:34:45 | 000,072,192 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysWOW64\tzautoupdate.dll -- (tzautoupdate)
SRV - [2018/04/12 08:34:45 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2018/04/12 08:33:47 | 003,441,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2016/11/21 15:36:04 | 000,013,312 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\SMITSC.exe -- (SMITS)
SRV - [2016/11/08 19:40:46 | 000,177,440 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service)
SRV - [2016/11/08 19:40:20 | 000,419,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2016/10/14 17:00:36 | 000,018,152 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe -- (Intel(R)
SRV - [2016/07/13 16:13:20 | 000,337,112 | ---- | M] (Toshiba Client Solutions Co., Ltd.) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\TOSHIBA System Driver\RMService.exe -- (TOSRMService)
SRV - [2016/04/12 13:35:58 | 000,016,384 | ---- | M] (Toshiba Client Solutions Co., Ltd.) [Auto | Stopped] -- C:\Program Files (x86)\TOSHIBA\OEM Registration Program\OEMRegistrationProgram.exe -- (OEMRegistrationProgram)
SRV - [2015/08/05 15:47:16 | 000,118,224 | ---- | M] (sMedio Inc) [Auto | Running] -- C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingService.exe -- (TVCSDubbingService)
SRV - [2015/07/17 09:27:52 | 000,319,360 | ---- | M] (Intercom, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Intercom\LAPLINK HelpDesk Client\LLHDClient.exe -- (LLHDClient)
SRV - [2011/06/29 10:44:04 | 000,008,704 | ---- | M] (Intercom, Inc.) [Auto | Running] -- C:\Program Files (x86)\Intercom\LAPLINK HelpDesk Client\LLHDCldr.exe -- (LLHDCloader)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2019/07/23 22:25:10 | 000,073,584 | ---- | M] (Malwarebytes) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtection)
DRV:[b]64bit:[/b] - [2019/07/23 22:25:08 | 000,224,408 | ---- | M] (Malwarebytes) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\farflt.sys -- (MBAMFarflt)
DRV:[b]64bit:[/b] - [2019/07/23 22:25:08 | 000,116,112 | ---- | M] (Malwarebytes) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebProtection)
DRV:[b]64bit:[/b] - [2019/07/23 22:25:04 | 000,275,232 | ---- | M] (Malwarebytes) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV:[b]64bit:[/b] - [2019/07/23 22:23:43 | 000,199,768 | ---- | M] (Malwarebytes) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\MbamChameleon.sys -- (MBAMChameleon)
DRV:[b]64bit:[/b] - [2019/07/10 05:05:17 | 000,367,032 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\wd\WdFilter.sys -- (WdFilter)
DRV:[b]64bit:[/b] - [2019/07/10 05:05:17 | 000,054,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wd\WdNisDrv.sys -- (WdNisDrv)
DRV:[b]64bit:[/b] - [2019/07/10 05:05:17 | 000,047,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\wd\WdBoot.sys -- (WdBoot)
DRV:[b]64bit:[/b] - [2019/06/26 13:00:48 | 000,020,936 | ---- | M] (Malwarebytes) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\MbamElam.sys -- (MbamElam)
DRV:[b]64bit:[/b] - [2019/06/07 14:58:50 | 000,076,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hvservice.sys -- (hvservice)
DRV:[b]64bit:[/b] - [2019/06/07 14:57:00 | 000,383,504 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:[b]64bit:[/b] - [2019/05/17 16:07:32 | 000,105,272 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:[b]64bit:[/b] - [2019/05/17 14:36:02 | 000,228,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winnat.sys -- (WinNat)
DRV:[b]64bit:[/b] - [2019/05/17 14:33:34 | 000,787,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WdiWiFi.sys -- (wdiwifi)
DRV:[b]64bit:[/b] - [2019/05/03 15:43:05 | 000,177,128 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:[b]64bit:[/b] - [2019/05/03 15:32:10 | 000,164,664 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:[b]64bit:[/b] - [2019/03/14 23:33:58 | 000,082,432 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\storqosflt.sys -- (storqosflt)
DRV:[b]64bit:[/b] - [2019/03/14 17:57:04 | 000,611,640 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:[b]64bit:[/b] - [2019/03/14 17:28:15 | 000,152,072 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\wcifs.sys -- (wcifs)
DRV:[b]64bit:[/b] - [2019/03/14 16:55:51 | 000,414,720 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\cldflt.sys -- (CldFlt)
DRV:[b]64bit:[/b] - [2019/03/06 18:04:46 | 000,945,464 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refsv1.sys -- (ReFSv1)
DRV:[b]64bit:[/b] - [2019/03/06 18:03:04 | 001,921,848 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)
DRV:[b]64bit:[/b] - [2019/03/04 20:07:18 | 008,835,768 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Netwtw06.sys -- (Netwtw06)
DRV:[b]64bit:[/b] - [2019/01/09 14:42:08 | 000,092,704 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bindflt.sys -- (bindflt)
DRV:[b]64bit:[/b] - [2019/01/08 16:32:04 | 000,153,328 | ---- | M] (Malwarebytes) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mbae64.sys -- (ESProtectionDriver)
DRV:[b]64bit:[/b] - [2018/12/08 17:04:38 | 000,058,168 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iorate.sys -- (iorate)
DRV:[b]64bit:[/b] - [2018/12/08 16:38:30 | 000,083,456 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\wcnfs.sys -- (wcnfs)
DRV:[b]64bit:[/b] - [2018/12/08 16:36:56 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mmcss.sys -- (MMCSS)
DRV:[b]64bit:[/b] - [2018/11/09 11:49:37 | 000,565,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:[b]64bit:[/b] - [2018/11/09 11:21:11 | 000,112,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:[b]64bit:[/b] - [2018/10/21 16:19:52 | 000,036,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vhf.sys -- (vhf)
DRV:[b]64bit:[/b] - [2018/09/28 02:47:28 | 000,635,384 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\intcdaud.inf_amd64_3b876fb0bfb3390a\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2018/09/28 02:47:12 | 014,072,744 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2018/08/09 13:55:01 | 000,230,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2018/08/03 12:47:12 | 000,128,920 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\scmbus.sys -- (scmbus)
DRV:[b]64bit:[/b] - [2018/08/03 12:40:48 | 000,228,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Ucx01000.sys -- (Ucx01000)
DRV:[b]64bit:[/b] - [2018/08/03 12:39:58 | 000,075,160 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:[b]64bit:[/b] - [2018/08/03 12:17:05 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgid.sys -- (vmgid)
DRV:[b]64bit:[/b] - [2018/06/15 16:10:52 | 000,048,544 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storufs.sys -- (storufs)
DRV:[b]64bit:[/b] - [2018/06/15 14:08:14 | 000,072,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\WindowsTrustedRT.sys -- (WindowsTrustedRT)
DRV:[b]64bit:[/b] - [2018/06/15 13:44:07 | 000,295,424 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xboxgip.sys -- (xboxgip)
DRV:[b]64bit:[/b] - [2018/06/08 19:31:08 | 000,029,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:[b]64bit:[/b] - [2018/05/10 21:37:48 | 000,136,728 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ibtusb.sys -- (ibtusb)
DRV:[b]64bit:[/b] - [2018/05/10 14:05:04 | 000,035,560 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AppleLowerFilter.sys -- (AppleLowerFilter)
DRV:[b]64bit:[/b] - [2018/05/10 14:05:04 | 000,020,640 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AppleKmdfFilter.sys -- (AppleKmdfFilter)
DRV:[b]64bit:[/b] - [2018/04/13 01:34:17 | 000,037,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2018/04/13 01:34:15 | 000,057,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpatialGraphFilter.sys -- (SpatialGraphFilter)
DRV:[b]64bit:[/b] - [2018/04/13 01:34:13 | 000,030,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:43 | 000,119,808 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\irda.sys -- (irda)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:40 | 000,091,544 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:40 | 000,060,320 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\bam.sys -- (bam)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:32 | 000,128,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:32 | 000,084,480 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:32 | 000,039,424 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\afunix.sys -- (afunix)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:32 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:28 | 000,254,464 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:25 | 000,088,472 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:22 | 000,175,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NetAdapterCx.sys -- (NetAdapterCx)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:22 | 000,034,208 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:20 | 000,217,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:20 | 000,209,816 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:19 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\applockerfltr.sys -- (applockerfltr)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:15 | 000,021,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdmCompanionFilter.sys -- (WdmCompanionFilter)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,282,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ufx01000.sys -- (Ufx01000)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,154,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,152,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmTcpciCx.sys -- (UcmTcpciCx0101)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,128,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmCx.sys -- (UcmCx0101)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,075,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,067,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urscx01000.sys -- (UrsCx01000)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,039,328 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\cnghwassist.sys -- (cnghwassist)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IndirectKmd.sys -- (IndirectKmd)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshwnclx.sys -- (HwNClx0101)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,169,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,082,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:12 | 000,055,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,128,000 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,063,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SgrmAgent.sys -- (SgrmAgent)
DRV:[b]64bit:[/b] - [2018/04/12 08:34:04 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\gpuenergydrv.sys -- (GpuEnergyDrv)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:58 | 000,030,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,140,192 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,127,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,063,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,055,808 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\filecrypt.sys -- (FileCrypt)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Udecx.sys -- (UdeCx)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,039,840 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\ramdisk.sys -- (Ramdisk)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:54 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ipt.sys -- (IPT)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,434,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,287,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,097,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmUcsi.sys -- (UcmUcsi)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,054,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,050,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,050,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidinterrupt.sys -- (hidinterrupt)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xinputhid.sys -- (xinputhid)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\buttonconverter.sys -- (buttonconverter)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,026,112 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:52 | 000,018,472 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\WindowsTrustedRTProxy.sys -- (WindowsTrustedRTProxy)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:51 | 000,144,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ufxsynopsys.sys -- (ufxsynopsys)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:51 | 000,098,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UfxChipidea.sys -- (UfxChipidea)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:51 | 000,086,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys -- (BthLEEnum)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:51 | 000,029,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urschipidea.sys -- (UrsChipidea)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:51 | 000,028,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urssynopsys.sys -- (UrsSynopsys)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:51 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\genericusbfn.sys -- (genericusbfn)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 001,836,952 | ---- | M] (Chelsio Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cht4vx64.sys -- (cht4vbd)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,885,144 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAVC.sys -- (iaStorAVC)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,842,648 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mlx4_bus.sys -- (mlx4_bus)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,526,232 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ibbus.sys -- (ibbus)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,505,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mausbhost.sys -- (mausbhost)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,321,432 | ---- | M] (Chelsio Communications) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\cht4sx64.sys -- (cht4iscsi)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,305,560 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,197,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc.sys -- (netvsc)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,156,056 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,108,952 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndfltr.sys -- (ndfltr)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,105,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pmem.sys -- (pmem)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,104,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvdimm.sys -- (nvdimm)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,079,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,072,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,064,920 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winverbs.sys -- (WinVerbs)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,064,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,063,488 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,061,848 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\percsas3i.sys -- (percsas3i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,058,776 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\percsas2i.sys -- (percsas2i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,056,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mausbip.sys -- (mausbip)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,047,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,038,304 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bttflt.sys -- (bttflt)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,035,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,033,184 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\hvcrash.sys -- (hvcrash)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,033,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SDFRd.sys -- (SDFRd)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,032,152 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winmad.sys -- (WinMad)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,031,128 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,028,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,018,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\swenum.inf_amd64_ea7b19c04e7a8136\swenum.sys -- (swenum)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,016,288 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volume.sys -- (volume)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,013,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:49 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 003,419,032 | ---- | M] (QLogic Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 001,135,520 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,533,912 | ---- | M] (QLogic Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,259,480 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,145,816 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\ItSas35i.sys -- (ItSas35i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,128,408 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3i.sys -- (LSI_SAS3i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,124,312 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2i.sys -- (LSI_SAS2i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,123,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\capimg.sys -- (CapImg)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,107,416 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,104,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rhproxy.sys -- (rhproxy)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,083,360 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,082,848 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,082,328 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\megasas35i.sys -- (megasas35i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,075,160 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\MegaSas2i.sys -- (megasas2i)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,064,408 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,063,904 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,038,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,027,032 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,020,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AcpiDev.sys -- (AcpiDev)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pnpmem.sys -- (PNPMEM)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:48 | 000,009,728 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,174,592 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_I2C_BXT_P.sys -- (iaLPSS2i_I2C_BXT_P)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,171,520 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_I2C.sys -- (iaLPSS2i_I2C)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,118,680 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,113,152 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,091,648 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iai2c.sys -- (iai2c)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,088,576 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_GPIO2_BXT_P.sys -- (iaLPSS2i_GPIO2_BXT_P)
DRV:[b]64bit:[/b] - [2018/04/12 08:33:45 | 000,079,360 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iaLPSS2i_GPIO2.sys -- (iaLPSS2i_GPIO2)
DRV:[b]64bi
  • sho
  • 2019/07/23 (Tue) 23:23:41
Re: プラウザが勝手に開かれます。
OTL(2)再送

E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=PRTOS1&src=IE11TR&pc=TBTE
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=PRTOS1&src=IE11TR&pc=TBTE


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://toshibaplaces.jp/tps/ [binary data]
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba17win10.msn.com/?pc=TBTE

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://toshibaplaces.jp/tps/ [binary data]
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba17win10.msn.com/?pc=TBTE

IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,IE11DefaultsFRECompletionTime = BB E2 D1 7A 19 30 D5 01 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,IE11DefaultsFREConfigUpdateTimestamp = 6C B2 91 C3 D6 40 D5 01 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://toshibaplaces.jp/tps/ [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba17win10.msn.com/?pc=TBTE
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = 4D 07 FA 86 91 2A D5 01 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = 01 00 00 00 2A 00 00 00 F1 E0 2F BD 98 8B 5D 53 C9 71 5B CA 85 7E B3 A3 67 FC 34 CE C3 72 B4 58 97 35 7D 76 A0 89 20 E4 34 70 67 3E DB 19 28 EE CF 55 02 00 00 00 10 00 00 00 41 2F 25 32 62 6A 73 34 34 63 7A 66 38 25 33 64 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[color=#E56717]========== FireFox ==========[/color]

FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll (Google LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll (Google LLC)



[color=#E56717]========== Chrome ==========[/color]

CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.2_1\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7519.422.0.3_0\

O1 HOSTS File: ([2016/07/16 20:45:37 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O4:[b]64bit:[/b] - HKLM..\Run: [] File not found
O4:[b]64bit:[/b] - HKLM..\Run: [SecurityHealth] C:\Program Files\Windows Defender\MSASCuiL.exe (Microsoft Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [TCrdMain] C:\Program Files\TOSHIBA\System Setting\TCrdMain_Win8.exe (Toshiba Client Solutions Co., Ltd.)
O4:[b]64bit:[/b] - HKLM..\Run: [TecoResident] C:\Program Files\TOSHIBA\Teco\TecoResident.exe (Toshiba Client Solutions Co., Ltd.)
O4:[b]64bit:[/b] - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (Toshiba Client Solutions Co., Ltd.)
O4:[b]64bit:[/b] - HKLM..\Run: [Trend Micro Client Framework] C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe (Trend Micro Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe (Trend Micro Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [VizorHtmlDialog.exe] C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [CLMLServer_For_P2G8] C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink)
O4 - HKU\S-1-5-19..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1460922254-185261916-941432131-1001..\Run: [CCleaner Smart Cleaning] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Software Ltd)
O4 - HKU\S-1-5-21-1460922254-185261916-941432131-1001..\Run: [OneDrive] C:\Users\sho50\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1460922254-185261916-941432131-1001..\RunOnce: [Application Restart #0] C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingServiceTrayIcon.exe (sMedio Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DSCAutomationHostEnabled = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableFullTrustStartupTasks = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUwpStartupTasks = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SupportFullTrustStartupTasks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SupportUwpStartupTasks = 1
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.3.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{406fe38c-c20f-4157-aa17-bc878f6bffb5}: DhcpNameServer = 192.168.0.1 192.168.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7cb959f8-1ae5-4608-9757-b23f04f03130}: DhcpNameServer = 192.168.3.1
O18:[b]64bit:[/b] - Protocol\Handler\mso-minsb.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\mso-minsb-roaming.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\osf.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\osf-roaming.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - U
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
ActiveX:[b]64bit:[/b] {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:[b]64bit:[/b] {C6658531-8DB9-3115-B6D1-F89B57830CFC} - .NET Framework
ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {B82EE9BD-ADE2-3058-8091-78419781EC8E} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2019/07/23 22:25:10 | 000,073,584 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2019/07/23 22:25:08 | 000,224,408 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\farflt.sys
[2019/07/23 22:25:08 | 000,116,112 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2019/07/23 22:25:04 | 000,275,232 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbamswissarmy.sys
[2019/07/23 22:19:13 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\sho50\Desktop\OTL.exe
[2019/07/20 06:11:52 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\sMedio
[2019/07/14 16:58:21 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2019/07/14 16:57:48 | 007,025,360 | ---- | C] (Malwarebytes) -- C:\Users\sho50\Desktop\AdwCleaner.exe
[2019/07/13 12:35:21 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\mbam
[2019/07/13 12:35:07 | 000,199,768 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MbamChameleon.sys
[2019/07/13 12:34:59 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\mbamtray
[2019/07/13 12:34:51 | 000,020,936 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MbamElam.sys
[2019/07/13 12:34:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
[2019/07/13 12:34:49 | 000,153,328 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbae64.sys
[2019/07/13 12:34:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2019/07/13 12:34:44 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes
[2019/07/13 12:32:48 | 064,552,472 | ---- | C] (Malwarebytes ) -- C:\Users\sho50\Desktop\mb3-setup-consumer-3.8.3.2965-1.0.613-1.0.11520.exe
[2019/07/13 03:14:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office ツール
[2019/07/11 07:12:50 | 007,519,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Protection.PlayReady.dll
[2019/07/11 07:12:50 | 006,570,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
[2019/07/11 07:12:49 | 025,857,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\edgehtml.dll
[2019/07/11 07:12:44 | 022,017,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\edgehtml.dll
[2019/07/11 07:12:43 | 009,084,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2019/07/11 07:12:42 | 007,589,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Chakra.dll
[2019/07/11 07:12:42 | 007,436,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\windows.storage.dll
[2019/07/11 07:12:41 | 005,625,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StartTileData.dll
[2019/07/11 07:12:40 | 005,784,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Chakra.dll
[2019/07/11 07:12:40 | 004,847,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_nt.dll
[2019/07/11 07:12:40 | 001,721,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\appraiser.dll
[2019/07/11 07:12:40 | 001,616,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppobjs.dll
[2019/07/11 07:12:39 | 006,044,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\windows.storage.dll
[2019/07/11 07:12:39 | 004,718,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.pcshell.dll
[2019/07/11 07:12:39 | 003,614,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kfull.sys
[2019/07/11 07:12:38 | 006,586,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2019/07/11 07:12:38 | 004,861,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2019/07/11 07:12:38 | 004,385,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EdgeContent.dll
[2019/07/11 07:12:38 | 004,038,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2019/07/11 07:12:38 | 003,292,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\combase.dll
[2019/07/11 07:12:38 | 002,882,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\win32kfull.sys
[2019/07/11 07:12:37 | 003,401,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2019/07/11 07:12:37 | 000,740,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2019/07/11 07:12:37 | 000,513,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepic.dll
[2019/07/11 07:12:36 | 005,657,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2019/07/11 07:12:36 | 004,771,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InputService.dll
[2019/07/11 07:12:36 | 003,700,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2019/07/11 07:12:35 | 002,871,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aitstatic.exe
[2019/07/11 07:12:35 | 002,479,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\combase.dll
[2019/07/11 07:12:35 | 001,035,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ApplyTrustOffline.exe
[2019/07/11 07:12:35 | 000,810,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2019/07/11 07:12:34 | 003,318,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2019/07/11 07:12:34 | 003,202,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll
[2019/07/11 07:12:34 | 002,370,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WebRuntimeManager.dll
[2019/07/11 07:12:34 | 002,166,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kbase.sys
[2019/07/11 07:12:34 | 001,219,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvix64.exe
[2019/07/11 07:12:34 | 000,951,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppcext.dll
[2019/07/11 07:12:34 | 000,900,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\slui.exe
[2019/07/11 07:12:34 | 000,896,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sppcext.dll
[2019/07/11 07:12:34 | 000,767,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppcommdlg.dll
[2019/07/11 07:12:34 | 000,415,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\aepic.dll
[2019/07/11 07:12:33 | 008,627,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll
[2019/07/11 07:12:33 | 002,899,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2019/07/11 07:12:33 | 002,571,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2019/07/11 07:12:33 | 001,400,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TokenBroker.dll
[2019/07/11 07:12:33 | 001,215,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationController.dll
[2019/07/11 07:12:33 | 001,027,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvax64.exe
[2019/07/11 07:12:33 | 000,637,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2019/07/11 07:12:33 | 000,511,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dcntel.dll
[2019/07/11 07:12:33 | 000,464,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\invagent.dll
[2019/07/11 07:12:33 | 000,164,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CompatTelRunner.exe
[2019/07/11 07:12:33 | 000,071,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32appinventorycsp.dll
[2019/07/11 07:12:32 | 003,554,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\InputService.dll
[2019/07/11 07:12:32 | 001,631,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32full.dll
[2019/07/11 07:12:32 | 001,626,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\enterprisecsps.dll
[2019/07/11 07:12:32 | 001,453,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gdi32full.dll
[2019/07/11 07:12:32 | 001,376,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ole32.dll
[2019/07/11 07:12:32 | 001,175,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncCore.dll
[2019/07/11 07:12:32 | 000,922,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Security.Authentication.Web.Core.dll
[2019/07/11 07:12:32 | 000,808,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EdgeManager.dll
[2019/07/11 07:12:32 | 000,607,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TextInputFramework.dll
[2019/07/11 07:12:32 | 000,324,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\acmigration.dll
[2019/07/11 07:12:31 | 007,990,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll
[2019/07/11 07:12:31 | 002,546,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UpdateAgent.dll
[2019/07/11 07:12:31 | 002,176,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.onecore.dll
[2019/07/11 07:12:31 | 001,663,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GdiPlus.dll
[2019/07/11 07:12:31 | 001,566,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxPackaging.dll
[2019/07/11 07:12:31 | 001,561,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.desktop.dll
[2019/07/11 07:12:31 | 001,549,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2019/07/11 07:12:31 | 001,471,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GdiPlus.dll
[2019/07/11 07:12:31 | 001,459,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2019/07/11 07:12:31 | 001,048,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Internal.Shell.Broker.dll
[2019/07/11 07:12:31 | 001,033,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ClipSVC.dll
[2019/07/11 07:12:31 | 000,916,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusUpdateHandlers.dll
[2019/07/11 07:12:31 | 000,894,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\webplatstorageserver.dll
[2019/07/11 07:12:31 | 000,567,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\daxexec.dll
[2019/07/11 07:12:31 | 000,566,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\phoneactivate.exe
[2019/07/11 07:12:30 | 001,427,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxPackaging.dll
[2019/07/11 07:12:30 | 001,260,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2019/07/11 07:12:30 | 001,141,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2019/07/11 07:12:30 | 001,127,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nettrace.dll
[2019/07/11 07:12:30 | 001,003,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TokenBroker.dll
[2019/07/11 07:12:30 | 000,986,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncHost.exe
[2019/07/11 07:12:30 | 000,953,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncCore.dll
[2019/07/11 07:12:30 | 000,776,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wer.dll
[2019/07/11 07:12:30 | 000,767,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dnsapi.dll
[2019/07/11 07:12:30 | 000,734,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentClient.dll
[2019/07/11 07:12:30 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SharedRealitySvc.dll
[2019/07/11 07:12:30 | 000,624,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PsmServiceExtHost.dll
[2019/07/11 07:12:30 | 000,608,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\EdgeManager.dll
[2019/07/11 07:12:30 | 000,559,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
[2019/07/11 07:12:30 | 000,545,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hal.dll
[2019/07/11 07:12:30 | 000,532,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\QuietHours.dll
[2019/07/11 07:12:30 | 000,510,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\policymanager.dll
[2019/07/11 07:12:30 | 000,506,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\edgeIso.dll
[2019/07/11 07:12:30 | 000,493,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcryptprimitives.dll
[2019/07/11 07:12:30 | 000,356,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcryptprimitives.dll
[2019/07/11 07:12:30 | 000,251,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppwinob.dll
[2019/07/11 07:12:30 | 000,093,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wldp.dll
[2019/07/11 07:12:29 | 002,406,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AcGenral.dll
[2019/07/11 07:12:29 | 001,609,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2019/07/11 07:12:29 | 001,339,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TaskFlowDataEngine.dll
[2019/07/11 07:12:29 | 001,328,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpx.dll
[2019/07/11 07:12:29 | 001,130,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msvproc.dll
[2019/07/11 07:12:29 | 001,098,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msvproc.dll
[2019/07/11 07:12:29 | 000,983,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2019/07/11 07:12:29 | 000,832,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncHost.exe
[2019/07/11 07:12:29 | 000,790,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fontdrvhost.exe
[2019/07/11 07:12:29 | 000,785,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pkeyhelper.dll
[2019/07/11 07:12:29 | 000,765,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdh.dll
[2019/07/11 07:12:29 | 000,723,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll
[2019/07/11 07:12:29 | 000,681,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Security.Authentication.Web.Core.dll
[2019/07/11 07:12:29 | 000,544,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2019/07/11 07:12:29 | 000,433,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotification.exe
[2019/07/11 07:12:29 | 000,392,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\daxexec.dll
[2019/07/11 07:12:29 | 000,362,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Storage.ApplicationData.dll
[2019/07/11 07:12:29 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AcGenral.dll
[2019/07/11 07:12:29 | 000,080,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wldp.dll
[2019/07/11 07:12:28 | 001,220,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Unistore.dll
[2019/07/11 07:12:28 | 001,217,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcore.dll
[2019/07/11 07:12:28 | 001,076,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\efscore.dll
[2019/07/11 07:12:28 | 001,063,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SecConfig.efi
[2019/07/11 07:12:28 | 000,871,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.BackgroundMediaPlayback.dll
[2019/07/11 07:12:28 | 000,869,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Playback.BackgroundMediaPlayer.dll
[2019/07/11 07:12:28 | 000,849,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Playback.MediaPlayer.dll
[2019/07/11 07:12:28 | 000,766,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicensingWinRT.dll
[2019/07/11 07:12:28 | 000,713,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MSVideoDSP.dll
[2019/07/11 07:12:28 | 000,665,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wer.dll
[2019/07/11 07:12:28 | 000,662,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fontdrvhost.exe
[2019/07/11 07:12:28 | 000,660,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LicensingWinRT.dll
[2019/07/11 07:12:28 | 000,648,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.BackgroundMediaPlayback.dll
[2019/07/11 07:12:28 | 000,646,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Playback.BackgroundMediaPlayer.dll
[2019/07/11 07:12:28 | 000,630,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Playback.MediaPlayer.dll
[2019/07/11 07:12:28 | 000,622,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdh.dll
[2019/07/11 07:12:28 | 000,604,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\securekernel.exe
[2019/07/11 07:12:28 | 000,568,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tcblaunch.exe
[2019/07/11 07:12:28 | 000,523,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dmenrollengine.dll
[2019/07/11 07:12:28 | 000,443,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\policymanager.dll
[2019/07/11 07:12:28 | 000,361,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DeviceEnroller.exe
[2019/07/11 07:12:28 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\edgeIso.dll
[2019/07/11 07:12:28 | 000,322,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotificationUx.exe
[2019/07/11 07:12:28 | 000,302,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CXHProvisioningServer.dll
[2019/07/11 07:12:28 | 000,295,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TDLMigration.dll
[2019/07/11 07:12:28 | 000,287,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Storage.ApplicationData.dll
[2019/07/11 07:12:28 | 000,130,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rmclient.dll
[2019/07/11 07:12:27 | 001,076,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdpcore.dll
[2019/07/11 07:12:27 | 000,965,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Unistore.dll
[2019/07/11 07:12:27 | 000,761,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nshwfp.dll
[2019/07/11 07:12:27 | 000,755,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Core.TextInput.dll
[2019/07/11 07:12:27 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\nshwfp.dll
[2019/07/11 07:12:27 | 000,581,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MSVideoDSP.dll
[2019/07/11 07:12:27 | 000,578,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\webplatstorageserver.dll
[2019/07/11 07:12:27 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nltest.exe
[2019/07/11 07:12:27 | 000,501,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rastls.dll
[2019/07/11 07:12:27 | 000,462,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdedit.exe
[2019/07/11 07:12:27 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dmenrollengine.dll
[2019/07/11 07:12:27 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpclip.exe
[2019/07/11 07:12:27 | 000,416,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanapi.dll
[2019/07/11 07:12:27 | 000,394,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InputSwitch.dll
[2019/07/11 07:12:27 | 000,330,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptprov.dll
[2019/07/11 07:12:27 | 000,328,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanapi.dll
[2019/07/11 07:12:27 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxAllUserStore.dll
[2019/07/11 07:12:27 | 000,310,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wc_storage.dll
[2019/07/11 07:12:27 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptprov.dll
[2019/07/11 07:12:27 | 000,239,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vdsbas.dll
[2019/07/11 07:12:27 | 000,236,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EditionUpgradeManagerObj.dll
[2019/07/11 07:12:27 | 000,221,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\EditionUpgradeManagerObj.dll
[2019/07/11 07:12:27 | 000,209,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wermgr.exe
[2019/07/11 07:12:27 | 000,194,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\skci.dll
[2019/07/11 07:12:27 | 000,191,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wermgr.exe
[2019/07/11 07:12:27 | 000,153,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dssvc.dll
[2019/07/11 07:12:27 | 000,146,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicensingUI.exe
[2019/07/11 07:12:27 | 000,137,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcrypt.dll
[2019/07/11 07:12:27 | 000,134,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvloader.dll
[2019/07/11 07:12:27 | 000,115,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kdnet.dll
[2019/07/11 07:12:27 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\profext.dll
[2019/07/11 07:12:27 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ngcpopkeysrv.dll
[2019/07/11 07:12:27 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationControllerPS.dll
[2019/07/11 07:12:27 | 000,101,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rmclient.dll
[2019/07/11 07:12:27 | 000,101,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\changepk.exe
[2019/07/11 07:12:27 | 000,094,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2019/07/11 07:12:27 | 000,091,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpfve.sys
[2019/07/11 07:12:27 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KdsCli.dll
[2019/07/11 07:12:27 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\offreg.dll
[2019/07/11 07:12:27 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\offreg.dll
[2019/07/11 07:12:27 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TokenBrokerUI.dll
[2019/07/11 07:12:27 | 000,036,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DeviceCensus.exe
[2019/07/11 07:12:26 | 000,677,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\HeadTrackerStorage.dll
[2019/07/11 07:12:26 | 000,582,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Core.TextInput.dll
[2019/07/11 07:12:26 | 000,508,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_Notifications.dll
[2019/07/11 07:12:26 | 000,450,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rastls.dll
[2019/07/11 07:12:26 | 000,409,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanmsm.dll
[2019/07/11 07:12:26 | 000,371,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\InputSwitch.dll
[2019/07/11 07:12:26 | 000,251,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msIso.dll
[2019/07/11 07:12:26 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DesktopSwitcherDataModel.dll
[2019/07/11 07:12:26 | 000,230,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
[2019/07/11 07:12:26 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\enrollmentapi.dll
[2019/07/11 07:12:26 | 000,181,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EditionUpgradeHelper.dll
[2019/07/11 07:12:26 | 000,178,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dmvdsitf.dll
[2019/07/11 07:12:26 | 000,172,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\enrollmentapi.dll
[2019/07/11 07:12:26 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dmvdsitf.dll
[2019/07/11 07:12:26 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mdmmigrator.dll
[2019/07/11 07:12:26 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InputLocaleManager.dll
[2019/07/11 07:12:26 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\splwow64.exe
[2019/07/11 07:12:26 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSysprep.dll
[2019/07/11 07:12:26 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\profext.dll
[2019/07/11 07:12:26 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RjvMDMConfig.dll
[2019/07/11 07:12:26 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MDMAgent.exe
[2019/07/11 07:12:26 | 000,093,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSReset.exe
[2019/07/11 07:12:26 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TpmTasks.dll
[2019/07/11 07:12:26 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UpgradeResultsUI.exe
[2019/07/11 07:12:26 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TokenBrokerUI.dll
[2019/07/11 07:12:26 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\werdiagcontroller.dll
[2019/07/10 05:05:18 | 000,367,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdFilter.sys
[2019/07/10 05:05:18 | 000,054,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdNisDrv.sys
[2019/07/10 05:05:18 | 000,047,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdBoot.sys
[2019/07/09 22:54:17 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Macromedia
[2019/07/08 23:47:42 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Geek Uninstaller
[2019/07/08 23:42:17 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\sho50\Desktop\HijackThis.exe
[2019/07/08 23:40:08 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Google
[2019/07/08 23:38:38 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2019/07/08 23:33:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2019/07/08 23:30:46 | 000,000,000 | ---D | C] -- C:\Users\sho50\Desktop\geek (3)
[2019/07/08 23:28:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lhaplus
[2019/07/08 23:28:23 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Programs
[2019/07/08 23:12:57 | 000,000,000 | ---D | C] -- C:\ProgramData\UniqueId
[2019/07/07 13:53:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2019/07/07 13:53:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2019/06/29 18:08:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel
[2019/06/29 18:06:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\DriverData\Intel\Wlan
[2019/06/29 18:06:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\DriverData\Intel\Wlan\Router
[2019/06/29 18:06:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\DriverData\Intel
[2019/06/29 14:22:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2019/06/29 13:57:08 | 000,000,000 | ---D | C] -- C:\Program Files\rempl
[2019/06/29 06:16:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\MRT
[2019/06/29 06:08:21 | 000,000,000 | ---D | C] -- C:\Program Files\UNP
[2019/06/26 00:52:25 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Microsoft Help
[2019/06/24 22:47:09 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\PlaceholderTileLogoFolder
[2019/06/24 22:45:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Packages
[2019/06/24 22:32:59 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\DBG
[2019/06/24 22:31:04 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Power2Go8
[2019/06/24 22:31:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft OneDrive
[2019/06/24 22:30:58 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Comms
[2019/06/24 22:29:41 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\MicrosoftEdge
[2019/06/24 22:29:37 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Publishers
[2019/06/24 22:29:30 | 000,000,000 | R--D | C] -- C:\Users\sho50\Searches
[2019/06/24 22:29:29 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\VirtualStore
[2019/06/24 22:29:29 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Packages
[2019/06/24 22:29:29 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Adobe
[2019/06/24 22:29:28 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Intel
[2019/06/24 22:29:28 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\ConnectedDevicesPlatform
[2019/06/24 22:29:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Intel
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\デスクトップ
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\スタート メニュー
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\Templates
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\Documents
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\Application Data
[2019/06/24 21:09:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\wd
[2019/06/24 21:07:27 | 000,000,000 | --SD | C] -- C:\Users\sho50\AppData\Roaming\Microsoft
[2019/06/24 21:07:27 | 000,000,000 | R--D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
[2019/06/24 21:07:27 | 000,000,000 | R--D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2019/06/24 21:07:27 | 000,000,000 | R--D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2019/06/24 21:07:27 | 000,000,000 | R--D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\スタート メニュー
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\AppData\Local\Temporary Internet Files
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Templates
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\SendTo
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Recent
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\PrintHood
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\NetHood
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Documents\My Videos
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Documents\My Pictures
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Documents\My Music
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\My Documents
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Local Settings
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\AppData\Local\History
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Cookies
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Application Data
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\AppData\Local\Application Data
[2019/06/24 21:07:27 | 000,000,000 | -H-D | C] -- C:\Users\sho50\AppData
[2019/06/24 21:07:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Temp
[2019/06/24 21:07:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\Roaming
[2019/06/24 21:07:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Microsoft
[2019/06/24 21:07:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2019/06/24 20:58:32 | 000,000,000 | ---D | C] -- C:\ProgramData\USOShared
[2019/06/24 20:58:31 | 002,752,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PrintConfig.dll
[2019/06/24 20:57:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Synaptics
[2019/06/24 20:57:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Audyssey Labs
[2019/06/24 20:57:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\RTCOM
[2019/06/24 20:57:05 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2019/06/24 20:56:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2019/06/24 20:56:54 | 000,146,384 | ---- | C] (Khronos Group) -- C:\WINDOWS\SysNative\OpenCL.DLL
[2019/06/24 20:56:54 | 000,121,296 | ---- | C] (Khronos Group) -- C:\WINDOWS\SysWow64\OpenCL.DLL
[2019/06/24 20:56:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VulkanRT
[2019/06/24 20:56:51 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2019/06/24 20:56:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel
[2019/06/24 20:56:41 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2019/06/24 20:56:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SleepStudy
[2019/06/24 20:55:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\InfusedApps
[2019/06/24 20:55:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\Panther
[2019/06/24 20:55:18 | 000,000,000 | ---D | C] -- C:\Windows.old
[2019/06/24 20:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServiceProfiles
[2019/06/24 20:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Microsoft
[2019/06/24 20:54:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sda
[2019/06/24 20:53:41 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2019/06/24 20:52:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\Setup
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\zu-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\zu-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\yo-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\yo-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\XPSViewer
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\xh-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\xh-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\wo-SN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\wo-SN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Media Player
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\vi-VN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\vi-VN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\uz-Latn-UZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\uz-Latn-UZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ur-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ur-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ug-CN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ug-CN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tt-RU
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tt-RU
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tn-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tn-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tk-TM
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tk-TM
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ti-ET
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ti-ET
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tg-Cyrl-TJ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tg-Cyrl-TJ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\te-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\te-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ta-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sw-KE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sw-KE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sr-Cyrl-RS
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sr-Cyrl-RS
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sr-Cyrl-BA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sr-Cyrl-BA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sq-AL
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sq-AL
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\si-LK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sd-Arab-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sd-Arab-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\rw-RW
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\rw-RW
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\quz-PE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\quz-PE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\quc-Latn-GT
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\quc-Latn-GT
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\prs-AF
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\prs-AF
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\pa-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\pa-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\pa-Arab-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\pa-Arab-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\or-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\or-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\OpenSSH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\OCR
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\nso-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\nso-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\nn-NO
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\nn-NO
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ne-NP
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ne-NP
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mt-MT
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mt-MT
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ms-MY
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ms-MY
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mr-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mr-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mn-MN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mn-MN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ml-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ml-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mk-MK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mk-MK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mi-NZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mi-NZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\MailContactsCalendarSync
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\MailContactsCalendarSync
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\lo-LA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\lo-LA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\lb-LU
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\lb-LU
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ky-KG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ky-KG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ku-Arab-IQ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ku-Arab-IQ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\kok-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\kok-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\kn-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\kn-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\km-KH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\km-KH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\kk-KZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\kk-KZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ka-GE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ka-GE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\is-IS
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\is-IS
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ig-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ig-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\id-ID
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\id-ID
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\hy-AM
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\hy-AM
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\hi-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\hi-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ha-Latn-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ha-Latn-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\gu-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\gu-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\gl-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\gl-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\gd-GB
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\gd-GB
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ga-IE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ga-IE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\fil-PH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\fil-PH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\fa-IR
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\fa-IR
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\eu-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\eu-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\cy-GB
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\cy-GB
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\chr-CHER-US
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\chr-CHER-US
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ca-ES-valencia
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ca-ES-valencia
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ca-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ca-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\bs-Latn-BA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\bs-Latn-BA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\bn-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\bn-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\bn-BD
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\bn-BD
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\be-BY
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\be-BY
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\az-Latn-AZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\az-Latn-AZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\as-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\as-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\am-ET
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\af-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\af-ZA
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\winrm
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\WCN
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sysprep
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\slmgr
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Printing_Admin_Scripts
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ja
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\winrm
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WCN
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers\UMDF
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\slmgr
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Printing_Admin_Scripts
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers\ja-JP
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers\UMDF\en-US
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers\en-US
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\en
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\0409
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\UMDF\ja-JP
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\ja-JP
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\ja-JP
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ja
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\UMDF\en-US
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\en-US
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\en-US
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\en
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\DigitalLocker
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\0409
[2019/06/24 20:49:02 | 000,835,688 | ---- | C] (Adobe) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2019/06/24 20:49:02 | 000,179,816 | ---- | C] (Adobe) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2019/06/24 20:47:26 | 000,208,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msclmd.dll
[2019/06/24 20:47:23 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msclmd.dll
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\UNP
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysWow64\Nui
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\Nui
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysWow64\F12
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\F12
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\dsc
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysWow64\DiagSvcs
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\DiagSvcs
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysWow64\Configuration
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\Configuration
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\zh-TW
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\zh-TW
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\zh-CN
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\zh-CN
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\WinMetadata
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WinMetadata
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\winevt
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] --

  • sho
  • 2019/07/23 (Tue) 23:25:14
Re: プラウザが勝手に開かれます。
OTL(3)再送

C:\WINDOWS\SysWow64\WindowsPowerShell
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WindowsPowerShell
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WinBioPlugIns
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WinBioDatabase
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Web
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WDI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\wbem
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\wbem
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\WaaS
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Vss
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\uk-UA
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\uk-UA
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tr-TR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tr-TR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\tracing
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\th-TH
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\th-TH
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\TextInput
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Tasks
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Tasks
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\TAPI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ta-lk
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ta-in
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWOW64
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SystemResources
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SystemResetPlatform
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SystemApps
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sv-SE
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sv-SE
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sru
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sru
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sr-Latn-RS
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sr-Latn-RS
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sppui
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sppui
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\spp
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\spp
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\spool
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Speech_OneCore
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Speech_OneCore
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Speech_OneCore
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Speech
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System\Speech
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Speech
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Speech
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\SMI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sl-SI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sl-SI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sk-SK
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sk-SK
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SKB
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\si-lk
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ShellExperiences
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\ShellExperiences
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\ShellComponents
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\setup
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\setup
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServiceState
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\security
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SecureBootUpdates
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\schemas
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SchCache
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ru-RU
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ru-RU
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ro-RO
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ro-RO
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\restore
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\restore
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\rescache
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Recovery
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Recovery
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\RasToast
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\RasToast
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ras
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ras
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\pt-PT
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\pt-PT
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\pt-BR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\pt-BR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ProximityToast
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\PointOfService
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\pl-PL
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\pl-PL
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\oobe
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\oobe
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\nl-NL
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\nl-NL
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\networklist
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\networklist
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\NDF
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\NDF
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\nb-NO
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\nb-NO
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\my-mm
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\MUI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\MUI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Msdtc
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\MsDtc
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\MSDRM
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\MSDRM
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\migwiz
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\migwiz
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\migration
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\migration
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Macromed
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Macromed
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\lv-LV
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\lv-LV
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\lt-LT
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\lt-LT
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\LogFiles
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\LogFiles
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Licenses
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Licenses
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ko-KR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ko-KR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ja-JP
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ja-jp
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\it-IT
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\it-IT
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Ipmi
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Ipmi
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\InstallShield
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\InputMethod
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\InputMethod
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\inetsrv
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\inetsrv
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\IME
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\IME
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\icsxml
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\icsxml
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\hydrogen
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\hu-HU
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\hu-HU
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\hr-HR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\hr-HR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\he-IL
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\he-IL
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\GroupPolicyUsers
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\GroupPolicyUsers
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\GroupPolicy
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\GroupPolicy
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\FxsTmp
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\FxsTmp
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\fr-FR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\fr-FR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\fr-CA
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\fr-CA
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\fi-FI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\fi-FI
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\et-EE
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\et-EE
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\etc
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\es-MX
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\es-MX
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\es-ES
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\es-ES
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\en-US
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\en-US
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\en-GB
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\en-GB
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\el-GR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\el-GR
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\DriverStore
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\DriverState
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\DriverData
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\downlevel
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\downlevel
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Dism
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Dism
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\de-DE
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\de-DE
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\DDFs
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\da-DK
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\da-DK
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\cs-CZ
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\cs-CZ
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\config
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\com
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\com
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\CodeIntegrity
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\catroot2
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\catroot
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Bthprops
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Bthprops
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Boot
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\bg-BG
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\bg-BG
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ar-SA
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ar-SA
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\appraiser
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\AppLocker
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\AppLocker
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\am-et
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\AdvancedInstallers
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\AdvancedInstallers
[2019/06/24 20:47:18 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft
[2019/06/24 20:47:18 | 000,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2019/06/24 20:47:18 | 000,000,000 | R-SD | C] -- C:\WINDOWS\media
[2019/06/24 20:47:18 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\Program Files\Windows Defender
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\Program Files
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\Program Files (x86)
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\WINDOWS\PrintDialog
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\WINDOWS\Microsoft.NET
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\WINDOWS\ImmersiveControlPanel
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\WINDOWS\assembly
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
[2019/06/24 20:47:18 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
[2019/06/24 20:47:18 | 000,000,000 | -HSD | C] -- C:\Program Files\Windows Sidebar
[2019/06/24 20:47:18 | 000,000,000 | -HSD | C] -- C:\Program Files (x86)\Windows Sidebar
[2019/06/24 20:47:18 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2019/06/24 20:47:18 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsApps
[2019/06/24 20:47:18 | 000,000,000 | -H-D | C] -- C:\ProgramData
[2019/06/24 20:47:18 | 000,000,000 | -H-D | C] -- C:\WINDOWS\LanguageOverlayCache
[2019/06/24 20:47:18 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ELAMBKUP
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\WindowsPowerShell
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WindowsPowerShell
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsHolographicDevices
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Security
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Portable Devices
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Photo Viewer
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Photo Viewer
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\windows nt
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\windows nt
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Multimedia Platform
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Multimedia Platform
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Mail
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Mail
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Defender
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\ProgramData\USOPrivate
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\system
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\system
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Sysprep
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\ProgramData\SoftwareDistribution
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Services
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1991-06.com.microsoft
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Provisioning
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\prefetch
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\PolicyDefinitions
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\PLA
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Performance
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\PerfLogs
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\ModemLogs
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Migration
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\microsoft shared
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\microsoft shared
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\LiveKernelReports
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\L2Schemas
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\internet explorer
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Internet Explorer
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\InputMethod
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\IME
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\IdentityCRL
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Globalization
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\GameBarPresenceWriter
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\diagnostics
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\debug
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Branding
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\Boot
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\bcastdvr
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppReadiness
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\apppatch
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\appcompat
[2019/06/24 20:47:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins
[2019/06/24 20:47:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\UMDF
[2019/06/24 20:47:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers
[2019/06/24 20:46:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\INF
[2019/06/24 20:44:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\CbsTemp
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\Windows
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\Users
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SMI
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\servicing
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\DriverStore
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\config
[2019/06/24 20:43:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\CatRoot
[2019/06/24 20:42:51 | 000,000,000 | -H-D | C] -- C:\$SysReset

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2019/07/23 22:29:46 | 001,447,762 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2019/07/23 22:29:46 | 000,699,960 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2019/07/23 22:29:46 | 000,481,536 | ---- | M] () -- C:\WINDOWS\SysNative\perfh011.dat
[2019/07/23 22:29:46 | 000,132,900 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2019/07/23 22:29:46 | 000,132,468 | ---- | M] () -- C:\WINDOWS\SysNative\perfc011.dat
[2019/07/23 22:26:58 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2019/07/23 22:25:10 | 000,073,584 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2019/07/23 22:25:08 | 000,224,408 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\farflt.sys
[2019/07/23 22:25:08 | 000,116,112 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2019/07/23 22:25:04 | 000,275,232 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbamswissarmy.sys
[2019/07/23 22:24:58 | 016,777,216 | -HS- | M] () -- C:\swapfile.sys
[2019/07/23 22:24:54 | 3406,987,264 | -HS- | M] () -- C:\hiberfil.sys
[2019/07/23 22:23:43 | 000,199,768 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MbamChameleon.sys
[2019/07/23 22:23:41 | 000,000,214 | ---- | M] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job
[2019/07/23 22:19:13 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\sho50\Desktop\OTL.exe
[2019/07/16 07:03:55 | 000,002,257 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2019/07/15 07:38:27 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
[2019/07/14 16:57:48 | 007,025,360 | ---- | M] (Malwarebytes) -- C:\Users\sho50\Desktop\AdwCleaner.exe
[2019/07/13 12:34:50 | 000,001,923 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2019/07/13 12:33:28 | 064,552,472 | ---- | M] (Malwarebytes ) -- C:\Users\sho50\Desktop\mb3-setup-consumer-3.8.3.2965-1.0.613-1.0.11520.exe
[2019/07/13 03:08:26 | 000,272,352 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2019/07/10 05:05:17 | 000,367,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdFilter.sys
[2019/07/10 05:05:17 | 000,054,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdNisDrv.sys
[2019/07/10 05:05:17 | 000,047,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdBoot.sys
[2019/07/08 23:52:37 | 000,002,353 | ---- | M] () -- C:\Users\sho50\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2019/07/08 23:42:18 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\sho50\Desktop\HijackThis.exe
[2019/07/08 23:38:41 | 000,000,874 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2019/07/08 23:28:41 | 000,001,071 | ---- | M] () -- C:\Users\sho50\Desktop\Lhaplus.lnk
[2019/07/08 23:08:17 | 002,098,176 | ---- | M] () -- C:\WINDOWS\SysNative\UserMgrLog.etl
[2019/07/08 23:08:17 | 000,147,456 | ---- | M] () -- C:\WINDOWS\SysNative\umstartup.etl
[2019/07/07 12:53:14 | 001,062,912 | ---- | M] () -- C:\WINDOWS\SysNative\UserMgrLogBackup.etl
[2019/07/07 12:53:14 | 000,024,576 | ---- | M] () -- C:\WINDOWS\SysNative\umstartup000.etl
[2019/07/04 18:43:27 | 000,094,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2019/07/04 18:40:51 | 000,790,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fontdrvhost.exe
[2019/07/04 18:40:33 | 001,631,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32full.dll
[2019/07/04 18:40:32 | 001,616,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppobjs.dll
[2019/07/04 18:22:58 | 000,131,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\splwow64.exe
[2019/07/04 18:22:43 | 000,128,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSysprep.dll
[2019/07/04 18:21:11 | 008,627,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll
[2019/07/04 18:20:08 | 001,609,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2019/07/04 18:19:44 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpclip.exe
[2019/07/04 18:18:59 | 003,614,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kfull.sys
[2019/07/04 18:18:11 | 001,663,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GdiPlus.dll
[2019/07/04 17:56:04 | 001,453,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gdi32full.dll
[2019/07/04 17:54:37 | 000,662,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fontdrvhost.exe
[2019/07/04 17:41:01 | 007,990,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll
[2019/07/04 17:37:57 | 002,882,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\win32kfull.sys
[2019/07/04 17:36:56 | 001,471,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GdiPlus.dll
[2019/07/04 14:00:29 | 001,035,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ApplyTrustOffline.exe
[2019/07/04 13:58:29 | 001,328,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpx.dll
[2019/07/04 13:58:09 | 001,219,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvix64.exe
[2019/07/04 13:58:06 | 000,416,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanapi.dll
[2019/07/04 13:57:57 | 001,027,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvax64.exe
[2019/07/04 13:57:57 | 000,568,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tcblaunch.exe
[2019/07/04 13:57:57 | 000,194,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\skci.dll
[2019/07/04 13:57:57 | 000,134,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvloader.dll
[2019/07/04 13:57:18 | 000,362,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Storage.ApplicationData.dll
[2019/07/04 13:57:16 | 000,986,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncHost.exe
[2019/07/04 13:57:15 | 000,776,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wer.dll
[2019/07/04 13:57:14 | 000,723,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll
[2019/07/04 13:57:13 | 000,209,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wermgr.exe
[2019/07/04 13:57:05 | 003,292,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\combase.dll
[2019/07/04 13:57:03 | 000,137,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcrypt.dll
[2019/07/04 13:57:00 | 000,091,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpfve.sys
[2019/07/04 13:56:32 | 007,436,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\windows.storage.dll
[2019/07/04 13:56:32 | 000,493,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcryptprimitives.dll
[2019/07/04 13:56:27 | 009,084,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2019/07/04 13:56:26 | 007,519,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Protection.PlayReady.dll
[2019/07/04 13:56:26 | 002,571,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2019/07/04 13:56:21 | 001,141,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2019/07/04 13:56:21 | 000,983,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2019/07/04 13:56:20 | 001,566,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxPackaging.dll
[2019/07/04 13:56:20 | 000,734,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentClient.dll
[2019/07/04 13:56:13 | 000,713,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MSVideoDSP.dll
[2019/07/04 13:56:10 | 001,459,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2019/07/04 13:56:10 | 001,260,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2019/07/04 13:56:10 | 000,767,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dnsapi.dll
[2019/07/04 13:56:05 | 000,604,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\securekernel.exe
[2019/07/04 13:56:03 | 000,115,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kdnet.dll
[2019/07/04 13:43:21 | 000,191,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wermgr.exe
[2019/07/04 13:43:17 | 000,287,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Storage.ApplicationData.dll
[2019/07/04 13:43:03 | 000,832,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncHost.exe
[2019/07/04 13:43:02 | 000,328,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanapi.dll
[2019/07/04 13:43:01 | 000,665,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wer.dll
[2019/07/04 13:42:46 | 002,479,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\combase.dll
[2019/07/04 13:42:13 | 006,044,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\windows.storage.dll
[2019/07/04 13:42:13 | 000,356,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcryptprimitives.dll
[2019/07/04 13:42:07 | 001,427,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxPackaging.dll
[2019/07/04 13:42:03 | 006,570,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
[2019/07/04 13:41:58 | 000,559,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
[2019/07/04 13:37:42 | 025,857,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\edgehtml.dll
[2019/07/04 13:33:43 | 022,017,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\edgehtml.dll
[2019/07/04 13:26:50 | 000,310,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wc_storage.dll
[2019/07/04 13:26:46 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TpmTasks.dll
[2019/07/04 13:26:18 | 004,385,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EdgeContent.dll
[2019/07/04 13:25:57 | 000,295,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TDLMigration.dll
[2019/07/04 13:25:34 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\offreg.dll
[2019/07/04 13:25:22 | 007,589,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Chakra.dll
[2019/07/04 13:25:07 | 004,861,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2019/07/04 13:25:01 | 003,401,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2019/07/04 13:24:31 | 000,153,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dssvc.dll
[2019/07/04 13:24:16 | 000,462,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdedit.exe
[2019/07/04 13:24:11 | 000,567,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\daxexec.dll
[2019/07/04 13:23:05 | 001,217,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcore.dll
[2019/07/04 13:22:48 | 001,549,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2019/07/04 13:22:47 | 002,176,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.onecore.dll
[2019/07/04 13:22:28 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\werdiagcontroller.dll
[2019/07/04 13:22:18 | 001,175,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncCore.dll
[2019/07/04 13:22:01 | 001,561,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.desktop.dll
[2019/07/04 13:22:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\profext.dll
[2019/07/04 13:21:45 | 000,124,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\profext.dll
[2019/07/04 13:21:43 | 001,220,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Unistore.dll
[2019/07/04 13:21:39 | 005,784,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Chakra.dll
[2019/07/04 13:21:39 | 003,202,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll
[2019/07/04 13:21:33 | 000,324,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxAllUserStore.dll
[2019/07/04 13:21:09 | 002,166,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kbase.sys
[2019/07/04 13:21:02 | 000,059,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\offreg.dll
[2019/07/04 13:20:53 | 000,392,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\daxexec.dll
[2019/07/04 13:20:38 | 000,330,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptprov.dll
[2019/07/04 13:20:14 | 000,544,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2019/07/04 13:19:21 | 000,230,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
[2019/07/04 13:18:53 | 000,953,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncCore.dll
[2019/07/04 13:18:44 | 001,076,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdpcore.dll
[2019/07/04 13:18:19 | 000,965,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Unistore.dll
[2019/07/04 13:18:14 | 000,275,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptprov.dll
[2019/07/04 12:01:57 | 000,001,312 | ---- | M] () -- C:\WINDOWS\SysNative\tcbres.wim
[2019/06/26 13:00:48 | 000,020,936 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MbamElam.sys
[2019/06/24 23:43:26 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2019/06/24 22:30:44 | 000,001,417 | ---- | M] () -- C:\Users\sho50\Desktop\Microsoft Edge.lnk
[2019/06/24 22:08:07 | 000,000,013 | RHS- | M] () -- C:\WINDOWS\SysNative\drivers\fbd.sys
[2019/06/24 21:09:10 | 000,010,984 | ---- | M] () -- C:\Users\sho50\Desktop\削除されたアプリ.html
[2019/06/24 21:08:35 | 000,023,208 | ---- | M] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2019/06/24 20:57:19 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_wbf_vfs_0010_01_09_00.Wdf
[2019/06/24 20:57:14 | 000,004,862 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\rtkhdasetting.zip
[2019/06/24 20:57:12 | 000,000,000 | -H-- | M] () -- C:\ProgramData\DP45977C.lfl
[2019/06/24 20:56:54 | 000,000,000 | ---- | M] () -- C:\WINDOWS\SysNative\GfxValDisplayLog.bin
[2019/06/24 20:56:40 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_SynTP_01011.Wdf
[2019/06/24 20:49:56 | 000,144,624 | ---- | M] () -- C:\WINDOWS\SysNative\perfi011.dat
[2019/06/24 20:49:56 | 000,033,402 | ---- | M] () -- C:\WINDOWS\SysNative\perfd011.dat
[2019/06/24 20:46:14 | 000,215,943 | ---- | M] () -- C:\WINDOWS\SysWow64\dssec.dat
[2019/06/24 20:46:14 | 000,208,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msclmd.dll
[2019/06/24 20:46:14 | 000,003,683 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\etc\lmhosts.sam
[2019/06/24 20:46:14 | 000,000,741 | ---- | M] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2019/06/24 20:46:13 | 000,297,062 | ---- | M] () -- C:\WINDOWS\SysNative\perfi009.dat
[2019/06/24 20:46:13 | 000,229,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msclmd.dll
[2019/06/24 20:46:13 | 000,215,943 | ---- | M] () -- C:\WINDOWS\SysNative\dssec.dat
[2019/06/24 20:46:13 | 000,033,424 | ---- | M] () -- C:\WINDOWS\SysNative\perfd009.dat
[2019/06/24 20:46:13 | 000,017,346 | ---- | M] () -- C:\WINDOWS\SysNative\OEMDefaultAssociations.xml
[2019/06/24 20:46:13 | 000,000,858 | ---- | M] () -- C:\WINDOWS\SysNative\DefaultQuestions.json
[2019/06/24 20:46:13 | 000,000,741 | ---- | M] () -- C:\WINDOWS\SysNative\NOISE.DAT

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2019/07/15 07:38:27 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
[2019/07/13 12:34:50 | 000,001,923 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2019/07/13 03:14:42 | 000,002,469 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
[2019/07/13 03:14:42 | 000,002,462 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
[2019/07/13 03:14:42 | 000,002,412 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
[2019/07/13 03:14:42 | 000,002,398 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
[2019/07/13 03:14:42 | 000,002,394 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
[2019/07/11 07:12:26 | 000,001,312 | ---- | C] () -- C:\WINDOWS\SysNative\tcbres.wim
[2019/07/08 23:38:41 | 000,000,874 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2019/07/08 23:38:37 | 000,002,353 | ---- | C] () -- C:\Users\sho50\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2019/07/08 23:38:37 | 000,002,298 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[2019/07/08 23:38:37 | 000,002,257 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2019/07/08 23:28:41 | 000,001,071 | ---- | C] () -- C:\Users\sho50\Desktop\Lhaplus.lnk
[2019/07/08 23:08:47 | 000,000,214 | ---- | C] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job
[2019/07/07 12:30:53 | 002,098,176 | ---- | C] () -- C:\WINDOWS\SysNative\UserMgrLog.etl
[2019/07/07 12:30:53 | 001,062,912 | ---- | C] () -- C:\WINDOWS\SysNative\UserMgrLogBackup.etl
[2019/07/07 12:30:51 | 000,147,456 | ---- | C] () -- C:\WINDOWS\SysNative\umstartup.etl
[2019/07/07 12:30:51 | 000,024,576 | ---- | C] () -- C:\WINDOWS\SysNative\umstartup000.etl
[2019/06/24 23:43:26 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2019/06/24 22:08:07 | 000,000,013 | RHS- | C] () -- C:\WINDOWS\SysNative\drivers\fbd.sys
[2019/06/24 21:15:24 | 001,447,762 | ---- | C] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2019/06/24 21:09:10 | 000,010,984 | ---- | C] () -- C:\Users\sho50\Desktop\削除されたアプリ.html
[2019/06/24 21:08:35 | 000,023,208 | ---- | C] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2019/06/24 21:07:55 | 3406,987,264 | -HS- | C] () -- C:\hiberfil.sys
[2019/06/24 21:07:27 | 000,002,312 | ---- | C] () -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
[2019/06/24 21:07:27 | 000,000,352 | ---- | C] () -- C:\Users\sho50\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2019/06/24 21:07:27 | 000,000,334 | ---- | C] () -- C:\Users\sho50\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2019/06/24 21:07:05 | 000,001,576 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2019/06/24 20:57:19 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_wbf_vfs_0010_01_09_00.Wdf
[2019/06/24 20:57:14 | 000,004,862 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\rtkhdasetting.zip
[2019/06/24 20:57:12 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
[2019/06/24 20:56:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SysNative\GfxValDisplayLog.bin
[2019/06/24 20:56:40 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_SynTP_01011.Wdf
[2019/06/24 20:56:01 | 000,272,352 | ---- | C] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2019/06/24 20:55:23 | 000,165,846 | ---- | C] () -- C:\WINDOWS\SysWow64\license.rtf
[2019/06/24 20:55:23 | 000,165,846 | ---- | C] () -- C:\WINDOWS\SysNative\license.rtf
[2019/06/24 20:54:58 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2019/06/24 20:50:04 | 000,481,536 | ---- | C] () -- C:\WINDOWS\SysNative\perfh011.dat
[2019/06/24 20:50:04 | 000,144,624 | ---- | C] () -- C:\WINDOWS\SysNative\perfi011.dat
[2019/06/24 20:50:04 | 000,132,468 | ---- | C] () -- C:\WINDOWS\SysNative\perfc011.dat
[2019/06/24 20:50:04 | 000,033,402 | ---- | C] () -- C:\WINDOWS\SysNative\perfd011.dat
[2019/06/24 20:48:39 | 000,699,960 | ---- | C] () -- C:\WINDOWS\SysNative\perfh009.dat
[2019/06/24 20:48:39 | 000,297,062 | ---- | C] () -- C:\WINDOWS\SysNative\perfi009.dat
[2019/06/24 20:48:39 | 000,132,900 | ---- | C] () -- C:\WINDOWS\SysNative\perfc009.dat
[2019/06/24 20:48:39 | 000,033,424 | ---- | C] () -- C:\WINDOWS\SysNative\perfd009.dat
[2019/06/24 20:47:26 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2019/06/24 20:47:26 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2019/06/24 20:47:23 | 000,017,346 | ---- | C] () -- C:\WINDOWS\SysNative\OEMDefaultAssociations.xml
[2019/06/24 20:47:23 | 000,003,683 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\etc\lmhosts.sam
[2019/06/24 20:47:23 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysNative\NOISE.DAT
[2019/06/24 20:47:22 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysNative\dssec.dat
[2019/06/24 20:47:22 | 000,000,858 | ---- | C] () -- C:\WINDOWS\SysNative\DefaultQuestions.json
[2018/09/28 02:47:34 | 000,168,400 | ---- | C] () -- C:\WINDOWS\SysWow64\libGLESv2.dll
[2018/09/28 02:47:32 | 000,149,456 | ---- | C] () -- C:\WINDOWS\SysWow64\libEGL.dll
[2018/09/28 02:47:32 | 000,133,584 | ---- | C] () -- C:\WINDOWS\SysWow64\libGLESv1_CM.dll
[2018/06/21 04:58:22 | 000,232,248 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkaninfo-1-999-0-0-0.exe
[2018/06/21 04:58:22 | 000,232,248 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkaninfo.exe
[2018/06/21 04:58:08 | 000,833,848 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkan-1-999-0-0-0.dll
[2018/06/21 04:58:08 | 000,833,848 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkan-1.dll
[2018/06/14 07:08:48 | 002,841,312 | ---- | C] () -- C:\WINDOWS\SysWow64\Windows.Mirage.dll
[2018/06/09 15:25:38 | 000,018,716 | ---- | C] () -- C:\WINDOWS\SysWow64\srms-apr.dat
[2018/04/12 08:34:55 | 000,518,144 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2018/04/12 08:34:50 | 000,054,272 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2018/04/12 08:34:49 | 000,002,404 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2018/04/12 08:34:47 | 000,364,200 | ---- | C] () -- C:\WINDOWS\SysWow64\InputHost.dll
[2018/04/12 08:34:46 | 003,575,808 | ---- | C] () -- C:\WINDOWS\SysWow64\Windows.UI.Input.Inking.Analysis.dll
[2018/04/12 08:34:46 | 000,025,600 | ---- | C] () -- C:\WINDOWS\SysWow64\Windows.WARP.JITService.exe
[2018/04/12 08:34:45 | 000,329,216 | ---- | C] () -- C:\WINDOWS\SysWow64\ssdm.dll
[2018/04/12 08:34:45 | 000,223,232 | ---- | C] () -- C:\WINDOWS\SysWow64\HeatCore.dll
[2018/04/12 08:34:45 | 000,167,640 | ---- | C] () -- C:\WINDOWS\SysWow64\chs_singlechar_pinyin.dat
[2018/04/12 08:34:45 | 000,111,616 | ---- | C] () -- C:\WINDOWS\SysWow64\WindowsDefaultHeatProcessor.dll
[2018/04/12 08:34:45 | 000,055,808 | ---- | C] () -- C:\WINDOWS\SysWow64\xboxgipsynthetic.dll
[2018/04/12 08:34:36 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2018/04/12 08:34:30 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\windows.storage.dll -- [2019/07/04 13:56:32 | 007,436,536 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\windows.storage.dll -- [2019/07/04 13:42:13 | 006,044,008 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2018/04/12 08:34:40 | 000,973,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2018/04/12 08:34:55 | 000,785,408 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2018/04/12 08:34:40 | 000,524,288 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== Custom Scans ==========[/color]
[2019/07/13 12:34:44 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2019/06/24 20:55:28 | 000,000,000 | -H-D | M] -- C:\Recovery
[2019/02/17 16:02:22 | 000,000,000 | -H-D | M] -- C:\TMRescueDisk
[2019/06/24 21:03:38 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
[2017/02/19 01:45:43 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
[2019/07/23 06:49:30 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsApps
[2019/06/24 21:00:50 | 000,000,000 | -H-D | M] -- C:\Program Files\Intel\WiFi\bin\WLANProfiles
[2019/07/15 07:41:59 | 000,000,000 | -H-D | M] -- C:\ProgramData\Apple Computer\iTunes\SC Info
[2019/06/24 21:05:27 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVDSQV12.exe
[2017/02/19 01:55:58 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\ToGo
[2019/06/29 18:08:46 | 000,000,000 | -H-D | M] -- C:\ProgramData\Intel\Wireless\Settings
[2019/06/29 18:08:43 | 000,000,000 | -H-D | M] -- C:\ProgramData\Intel\Wireless\WLANProfiles
[2019/06/24 20:47:18 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc
[2019/06/24 21:10:39 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrccache\downloads
[2019/06/24 20:47:18 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc\DMProfiles
[2019/06/24 20:47:18 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc\Profiles
[2017/02/19 01:51:46 | 000,000,000 | -H-D | M] -- C:\ProgramData\Roaming\Intel\Wireless\Settings
[2019/02/17 16:02:22 | 000,000,000 | -H-D | M] -- C:\TMRescueDisk\Config
[2019/02/17 16:02:22 | 000,000,000 | -H-D | M] -- C:\TMRescueDisk\MBR
[2019/02/17 16:02:22 | 000,000,000 | -H-D | M] -- C:\TMRescueDisk\VBR
[2019/02/17 16:02:22 | 000,000,000 | -H-D | M] -- C:\TMRescueDisk\Config\2019-02-17-07-02-22
[2019/02/17 16:02:22 | 000,000,000 | -H-D | M] -- C:\TMRescueDisk\MBR\2019-02-17-07-02-22
[2019/02/17 16:02:22 | 000,000,000 | -H-D | M] -- C:\TMRescueDisk\VBR\4f494d44
[2019/02/17 16:02:22 | 000,000,000 | -H-D | M] -- C:\TMRescueDisk\VBR\4f494d44\2019-02-17-07-02-22
[2019/06/24 21:09:41 | 000,000,000 | -H-D | M] -- C:\Users\Default
[2019/07/15 07:41:59 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Apple Computer\iTunes\SC Info
[2019/06/24 21:05:27 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVDSQV12.exe
[2017/02/19 01:55:58 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\ToGo
[2019/06/29 18:08:46 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Intel\Wireless\Settings
[2019/06/29 18:08:43 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Intel\Wireless\WLANProfiles
[2019/06/24 20:47:18 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc
[2019/06/24 21:10:39 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\Windows\DeviceMetadataCache\dmrccache\downloads
[2019/06/24 20:47:18 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc\DMProfiles
[2019/06/24 20:47:18 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc\Profiles
[2017/02/19 01:51:46 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Roaming\Intel\Wireless\Settings
[2017/02/19 02:20:32 | 000,000,000 | -H-D | M] -- C:\Users\Default\AppData
[2017/02/19 01:51:46 | 000,000,000 | -H-D | M] -- C:\Users\Default\Roaming\Intel\Wireless\Settings
[2019/06/24 21:09:02 | 000,000,000 | -H-D | M] -- C:\Users\defaultuser0\AppData
[2017/03/19 12:42:50 | 000,000,000 | -H-D | M] -- C:\Users\defaultuser0\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2017/02/19 01:51:46 | 000,000,000 | -H-D | M] -- C:\Users\defaultuser0\Roaming\Intel\Wireless\Settings
[2019/07/13 03:08:40 | 000,000,000 | RH-D | M] -- C:\Users\Public\AccountPictures
[2019/07/13 12:34:50 | 000,000,000 | -H-D | M] -- C:\Users\Public\Desktop
[2019/07/20 06:11:52 | 000,000,000 | RH-D | M] -- C:\Users\Public\Libraries
[2017/02/19 01:51:46 | 000,000,000 | -H-D | M] -- C:\Users\Public\Roaming\Intel\Wireless\Settings
[2019/06/24 21:09:01 | 000,000,000 | -H-D | M] -- C:\Users\sho50\AppData
[2018/02/08 05:34:39 | 000,000,000 | -H-D | M] -- C:\Users\sho50\MicrosoftEdgeBackups
[2017/07/30 14:10:16 | 000,000,000 | -H-D | M] -- C:\Users\sho50\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~
[2019/06/24 22:30:45 | 000,000,000 | RH-D | M] -- C:\Users\sho50\AppData\Local\Microsoft\Windows\Burn\Burn
[2019/06/24 22:34:17 | 000,000,000 | -H-D | M] -- C:\Users\sho50\AppData\Local\Microsoft\Windows\INetCache\Virtualized
[2019/06/24 22:29:29 | 000,000,000 | -H-D | M] -- C:\Users\sho50\AppData\Local\Microsoft\Windows\INetCookies\PrivacIE
[2019/06/24 22:29:29 | 000,000,000 | -H-D | M] -- C:\Users\sho50\AppData\Local\Microsoft\Windows\INetCookies\DNTException\Low
[2019/06/24 22:29:29 | 000,000,000 | -H-D | M] -- C:\Users\sho50\AppData\Local\Microsoft\Windows\INetCookies\PrivacIE\Low
[2019/06/24 22:29:28 | 000,000,000 | -H-D | M] -- C:\Users\sho50\AppData\Roaming\Intel\Wireless\Settings
[2019/06/24 23:29:01 | 000,000,000 | -H-D | M] -- C:\Users\sho50\AppData\Roaming\Intel\Wireless\WLANProfiles
[2019/06/24 21:08:59 | 000,000,000 | -H-D | M] -- C:\Users\sho50\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2018/09/02 09:31:53 | 000,000,000 | -H-D | M] -- C:\Users\sho50\Apple\MobileSync
[2017/02/19 01:51:46 | 000,000,000 | -H-D | M] -- C:\Users\sho50\Roaming\Intel\Wireless\Settings
[2019/06/24 21:08:58 | 000,000,000 | RH-D | M] -- C:\Windows.old\Users\Default
[2019/07/15 07:41:59 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\All Users\Apple Computer\iTunes\SC Info
[2019/06/24 21:05:27 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVDSQV12.exe
[2017/02/19 01:55:58 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\ToGo
[2019/06/29 18:08:46 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\All Users\Intel\Wireless\Settings
[2019/06/29 18:08:43 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\All Users\Intel\Wireless\WLANProfiles
[2019/06/24 20:47:18 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\All Users\Microsoft\WwanSvc
[2019/06/24 21:10:39 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\All Users\Microsoft\Windows\DeviceMetadataCache\dmrccache\downloads
[2019/06/24 20:47:18 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\All Users\Microsoft\WwanSvc\DMProfiles
[2019/06/24 20:47:18 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\All Users\Microsoft\WwanSvc\Profiles
[2017/02/19 01:51:46 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\All Users\Roaming\Intel\Wireless\Settings
[2018/04/12 08:38:20 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\Default\AppData
[2019/06/24 21:09:02 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\defaultuser0\AppData
[2017/03/19 12:42:39 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\defaultuser0\AppData\Roaming\Intel\Wireless\Settings
[2017/03/19 12:42:39 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\defaultuser0\AppData\Roaming\Intel\Wireless\WLANProfiles
[2017/03/19 12:42:50 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\defaultuser0\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2017/02/19 01:51:46 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\defaultuser0\Roaming\Intel\Wireless\Settings
[2019/06/13 19:50:36 | 000,000,000 | RH-D | M] -- C:\Windows.old\Users\Public\AccountPictures
[2019/06/24 20:55:20 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\Public\Desktop
[2018/06/09 15:30:02 | 000,000,000 | RH-D | M] -- C:\Windows.old\Users\Public\Libraries
[2017/05/14 23:18:31 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\Public\CyberLink\OLReg
[2017/05/14 23:18:31 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\Public\CyberLink\OLReg\HKEY_CLASS_ROOT\CLSID\{A2540FA5-4E6F-4a42-A327-D947EC8F2323}\Version\7.0
[2017/02/19 01:51:46 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\Public\Roaming\Intel\Wireless\Settings
[2019/06/24 21:09:01 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\sho50\AppData
[2019/03/10 17:36:59 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\sho50\AppData\Local\Microsoft\Media Player\アート キャッシュ
[2018/06/16 16:00:14 | 000,000,000 | RH-D | M] -- C:\Windows.old\Users\sho50\AppData\Local\Microsoft\Windows\Burn\Burn
[2019/06/23 14:51:07 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\sho50\AppData\Local\Microsoft\Windows\INetCache\Content.MSO
[2019/06/23 14:51:08 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\sho50\AppData\Local\Microsoft\Windows\INetCache\Content.Word
[2019/04/13 07:20:20 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\sho50\AppData\Local\Microsoft\Windows\INetCache\Virtualized
[2017/03/19 12:55:17 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\sho50\AppData\Local\Microsoft\Windows\INetCookies\PrivacIE
[2017/03/19 12:55:17 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\sho50\AppData\Local\Microsoft\Windows\INetCookies\DNTException\Low
[2017/03/19 12:55:17 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\sho50\AppData\Local\Microsoft\Windows\INetCookies\PrivacIE\Low
[2018/06/16 16:00:14 | 000,000,000 | RH-D | M] -- C:\Windows.old\Users\sho50\AppData\Local\Packages\AppleInc.iTunes_nzyj5cx40ttqa\LocalCache\Local\Microsoft\Windows\Burn\Burn
[2017/03/19 12:55:14 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\sho50\AppData\Roaming\Intel\Wireless\Settings
[2017/03/19 12:55:14 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\sho50\AppData\Roaming\Intel\Wireless\WLANProfiles
[2019/06/24 20:35:17 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\sho50\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2017/02/19 01:51:46 | 000,000,000 | -H-D | M] -- C:\Windows.old\Users\sho50\Roaming\Intel\Wireless\Settings
[2019/07/13 12:34:51 | 000,000,000 | -H-D | M] -- C:\Windows\ELAMBKUP
[2019/06/24 20:47:18 | 000,000,000 | -H-D | M] -- C:\Windows\LanguageOverlayCache
[2019/06/24 20:55:06 | 000,000,000 | -H-D | M] -- C:\Windows\ServiceProfiles\LocalService\AppData
[2019/06/24 20:56:02 | 000,000,000 | -H-D | M] -- C:\Windows\ServiceProfiles\NetworkService\AppData
[2019/06/24 21:05:46 | 000,000,000 | -H-D | M] -- C:\WINDOWS\SysNative\WLANProfiles

[color=#A23BEC]< %windir%\tasks\*.job >[/color]
[2019/07/23 22:23:41 | 000,000,214 | ---- | M] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job

[color=#E56717]========== Drive Information ==========[/color]

Physical Drives
---------------

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: TOSHIBA THNSNK256GVN8
Partitions: 4
Status: OK
Status Info: 0

Partitions
---------------

DeviceID: Disk #0, Partition #0
PartitionType: GPT: System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 260.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: GPT: Basic Data
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 222.00GB
Starting Offset: 290455552
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: GPT: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: False
Size: 2.00GB
Starting Offset: 238472396800
Hidden sectors: 0


DeviceID: Disk #0, Partition #3
PartitionType: GPT: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: False
Size: 15.00GB
Starting Offset: 240155361280
Hidden sectors: 0


[color=#E56717]========== Base Services ==========[/color]
No service found with a name of AeLookupSvc
SRV:[b]64bit:[/b] - [2018/04/12 08:34:06 | 000,166,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:14 | 000,091,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:07 | 001,374,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:[b]64bit:[/b] - [2019/05/03 14:54:44 | 000,778,752 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:22 | 000,089,088 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV - [2018/04/12 08:34:50 | 000,070,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:20 | 000,486,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV - [2018/04/12 08:34:51 | 000,331,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
  • sho
  • 2019/07/23 (Tue) 23:26:54
Re: プラウザが勝手に開かれます。
OTL(4)再送

SRV:[b]64bit:[/b] - [2018/04/13 01:34:16 | 000,133,632 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:20 | 000,094,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV:[b]64bit:[/b] - [2019/07/04 13:20:11 | 001,156,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:[b]64bit:[/b] - [2019/03/14 16:54:29 | 000,354,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV - [2019/03/14 17:15:31 | 000,318,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV:[b]64bit:[/b] - [2019/07/04 13:22:41 | 000,300,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:41 | 000,109,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\eapsvc.dll -- (Eaphost)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:27 | 000,033,792 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV - [2018/04/12 08:34:51 | 000,029,696 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:34 | 000,604,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:24 | 000,441,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:[b]64bit:[/b] - [2018/04/12 08:34:40 | 000,467,456 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv)
No service found with a name of MMCSS
SRV:[b]64bit:[/b] - [2018/04/12 08:34:44 | 000,262,656 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:[b]64bit:[/b] - [2019/02/06 11:25:27 | 000,507,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:32 | 000,367,616 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:20 | 000,030,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:15 | 000,119,296 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:41 | 000,768,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
No service found with a name of ProtectedStorage
No service found with a name of EMDMgmt
SRV:[b]64bit:[/b] - [2018/04/12 08:34:33 | 000,104,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:[b]64bit:[/b] - [2019/04/19 13:34:35 | 000,935,936 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:[b]64bit:[/b] - [2019/07/04 13:20:11 | 001,156,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:[b]64bit:[/b] - [2018/10/21 16:18:06 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:[b]64bit:[/b] - [2018/10/21 16:45:36 | 000,058,088 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:43 | 000,266,240 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:[b]64bit:[/b] - [2019/05/17 14:30:51 | 000,276,992 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:23 | 000,613,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV - [2018/04/12 08:34:51 | 000,564,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV:[b]64bit:[/b] - [2019/06/07 14:17:05 | 000,889,344 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:36 | 000,308,224 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV - [2018/04/12 08:35:00 | 000,254,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:36 | 000,069,632 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:[b]64bit:[/b] - [2019/04/19 13:37:20 | 000,397,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:40 | 001,540,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:[b]64bit:[/b] - [2019/07/04 13:23:46 | 001,765,888 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (Audiosrv)
SRV:[b]64bit:[/b] - [2019/06/07 14:18:57 | 000,686,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2018/04/12 08:33:53 | 000,146,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
SRV - [2019/07/10 05:05:17 | 000,110,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1906.3-0\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2019/06/13 15:09:04 | 001,854,976 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (EventLog)
SRV:[b]64bit:[/b] - [2019/07/04 13:19:37 | 000,886,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (mpssvc)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:24 | 000,611,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:[b]64bit:[/b] - [2018/08/03 17:24:26 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\msiexec.exe -- (msiserver)
SRV - [2018/08/03 16:32:30 | 000,060,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysWow64\msiexec.exe -- (msiserver)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:40 | 000,224,256 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:[b]64bit:[/b] - [2019/06/13 15:10:40 | 002,912,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:[b]64bit:[/b] - [2018/04/12 08:34:44 | 000,252,928 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:[b]64bit:[/b] - [2019/07/04 13:22:33 | 002,587,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (WlanSvc)
SRV:[b]64bit:[/b] - [2019/06/13 15:11:42 | 000,271,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

< End of report >
  • sho
  • 2019/07/23 (Tue) 23:28:12
OTLの最初の方は10000超えたので、再送の方を見てください。
最初の3つくらいの投稿は、文字数オーバーして消えてしまったので見ないでいただいて大丈夫です。
  • sho
  • 2019/07/23 (Tue) 23:30:51
Re: プラウザが勝手に開かれます。
Extras(1)

OTL Extras logfile created on: 2019/07/23 22:29:50 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\sho50\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.17134.0)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

7.93 Gb Total Physical Memory | 5.40 Gb Available Physical Memory | 68.08% Memory free
22.43 Gb Paging File | 19.82 Gb Available in Paging File | 88.34% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 221.82 Gb Total Space | 50.79 Gb Free Space | 22.90% Space Free | Partition Type: NTFS
Drive D: | 3.58 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: LAPTOP-QCSS294P | User Name: sho50 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- Reg Error: Key error.
htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Powershell] -- powershell.exe -noexit -command Set-Location '%V' (Microsoft Corporation)
Directory [UpdateEncryptionSettings] -- Reg Error: Key error.
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Powershell] -- powershell.exe -noexit -command Set-Location '%V' (Microsoft Corporation)
Directory [UpdateEncryptionSettings] -- Reg Error: Key error.
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\CBP]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\DPA]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 5F C6 7B A8 85 2A D5 01 [binary data]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = [binary data]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\CBP]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\DPA]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[color=#E56717]========== Authorized Applications List ==========[/color]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00713F03-47DF-4911-97FC-BFAAA869E5DB}" = lport=8088 | protocol=17 | dir=in | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.110.540.0_x86__zpdnekdrzrea0\spotify.exe |
"{1FC39D70-A42E-4B40-893E-B79288FF5983}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{3417B9C3-A6B8-45FB-8B9D-768A30DDAFF0}" = lport=139 | protocol=6 | dir=in | app=system |
"{34FD3371-E52A-48D0-A4EB-B265E9B0278E}" = lport=138 | protocol=17 | dir=in | app=system |
"{38D6F0D9-0281-4D46-86D6-D3D4A31EBF2F}" = lport=8088 | protocol=6 | dir=in | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.110.540.0_x86__zpdnekdrzrea0\spotify.exe |
"{39CDB454-EDE8-4D59-A611-C086331D889C}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6C35ED63-3133-41B4-A551-1CC37573FF96}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7A91DEE2-CB60-4757-977D-67B1A937C14B}" = rport=139 | protocol=6 | dir=out | app=system |
"{86D9C5C4-02CA-45E7-8381-3E6C5FABC243}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{87A809D7-F27F-4AF2-9B01-B185C1D90D2A}" = rport=138 | protocol=17 | dir=out | app=system |
"{8DA280EE-153F-4AF0-AB31-C8074839C045}" = lport=57621 | protocol=17 | dir=in | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.110.540.0_x86__zpdnekdrzrea0\spotify.exe |
"{A542C713-23C8-4036-8E18-A093A6C00D64}" = lport=137 | protocol=17 | dir=in | app=system |
"{B8E74792-017D-416A-AC21-8FE4F216BF92}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C3F7095F-8C8B-4C6A-B4FB-F9BF6104B46A}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\root\office16\outlook.exe |
"{D299C0E5-EF7A-4CD1-8ABA-6C2B6321444D}" = rport=445 | protocol=6 | dir=out | app=system |
"{D61AA5F1-571C-4D43-9F61-1619733C8408}" = rport=137 | protocol=17 | dir=out | app=system |
"{FB3E9992-1047-410F-BFF2-50DA7F766F17}" = lport=445 | protocol=6 | dir=in | app=system |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03DB0824-AC2F-4BC0-9FCA-6F8C9D6A29D2}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.17134.112_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} |
"{04CFAB31-3535-49BF-89A7-69865BDF4E1C}" = dir=out | name=@{microsoft.lockapp_10.0.17134.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} |
"{06003856-C7CE-4102-BCE7-1BE643D546AB}" = protocol=6 | dir=in | app=c:\program files\windowsapps\appleinc.itunes_12095.7.41059.0_x64__nzyj5cx40ttqa\itunes.exe |
"{06F0D3FC-47E1-4AA4-A455-3963B5FB8B4D}" = dir=out | name=@{microsoft.windows.apprep.chxapp_1000.17134.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.apprep.chxapp/resources/displayname} |
"{071B88E9-2F03-4BC0-AED3-A6CC34072AC7}" = dir=out | name=@{microsoft.windows.holographicfirstrun_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.holographicfirstrun/resources/pkgdisplayname} |
"{07F3422C-4FBE-4E2C-9192-C82DF435E9D4}" = dir=out | name=@{microsoft.windows.parentalcontrols_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.parentalcontrols/resources/displayname} |
"{0846667B-A6C5-4E42-81EC-9941024FD2FC}" = dir=out | name=@{microsoft.windowscamera_2019.425.30.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscamera/lenssdk/resources/appstorename} |
"{09777DBB-72C4-48AF-A874-6EB69AAF89DE}" = dir=out | name=xbox game bar plugin |
"{0B62D0D8-6478-4FD3-B98D-012FD57CE159}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} |
"{0C267BD9-4312-4331-9CC5-97CF7F65097A}" = dir=in | name=@{microsoft.ppiprojection_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{0D15783E-AC2A-4968-8364-83D8C9925D8D}" = dir=in | name=@{microsoft.zunemusic_10.19031.11411.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{0E103F04-8729-43AF-92BB-55A88F018FD6}" = dir=in | name=print 3d |
"{0EF43858-6C5D-4C8D-AA23-D300878A31A6}" = dir=in | name=@{microsoft.desktopappinstaller_1.0.31351.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.desktopappinstaller/resources/appdisplayname} |
"{0F69A02C-87B2-4B19-8FBC-5981776D768E}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{11C1B9FD-DD88-485E-AED3-9E84885C3576}" = protocol=17 | dir=in | app=c:\program files\windowsapps\appleinc.itunes_12095.7.41059.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe |
"{1267D66D-97D2-4775-AD15-5735613B3E6F}" = dir=out | name=楽しもう!office ライフ |
"{1269855F-9584-48C1-B61B-20AEA754519D}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} |
"{13536002-BBE3-434C-91AE-65E340C7FBD8}" = dir=out | name=@{microsoft.xboxapp_48.55.9001.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxapp/xboxapp.resource/resources/app_title} |
"{150DAD10-0645-4A00-85D8-65A93B55D461}" = dir=out | name=microsoft sticky notes |
"{158F1EED-7AF0-4AA9-9890-2AEB859D8BA2}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{16783039-EB5B-4FF3-8606-BDB3CAB5485C}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.14393.447_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} |
"{16DC0CD6-62EE-4CAD-9A0D-A5019AE55C79}" = dir=in | name=win32webviewhost |
"{17281701-1144-4FDA-B011-EA4FBF538436}" = dir=out | name=candy crush friends |
"{1990B046-C177-48CB-BF3B-7C55F4513914}" = dir=out | name=@{microsoft.windows.sechealthui_10.0.17134.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.windows.sechealthui/resources/packagedisplayname} |
"{1BC16B4E-9537-4512-9B72-73E8B0F4447E}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.17134.112_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} |
"{1C73EC92-31FB-4412-AC5C-D39411C80D4B}" = dir=out | name=@{microsoft.ppiprojection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{21747574-0FFE-48D6-9458-E4E42808E2FC}" = dir=in | app=c:\program files\cyberlink\powerdirector14\pdr10.exe |
"{21D9AE1A-759B-4168-802C-8AAAB6728931}" = dir=out | name=@{microsoft.windowsfeedbackhub_1.1811.10862.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsfeedbackhub/resources/appstorename} |
"{222BDD3F-C5B9-4BA9-978B-5A82A2774561}" = dir=out | name=@{windows.contactsupport_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} |
"{24750689-013B-441C-8D68-88E07CBDB87B}" = dir=out | name=spotify music |
"{2603FFE9-632D-47F5-A767-5D5199F9A9BB}" = protocol=6 | dir=in | app=c:\program files\windowsapps\appleinc.itunes_12095.7.41059.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe |
"{27A8E7BE-73E4-4044-8FE5-1E56DBFD0779}" = dir=in | name=思い出フォトビューア クッキングプラス |
"{29E249B6-70A4-4048-A0A0-E0E1B62A3393}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{2C588676-108C-459C-AAD3-0EF349D01955}" = protocol=17 | dir=in | app=c:\program files\windowsapps\appleinc.itunes_12095.7.41059.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe |
"{2DEA586E-3682-422F-9673-87ED893BF3A8}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{300D13C9-78F4-436C-84A3-3A259593E25C}" = dir=out | name=@{microsoft.gethelp_10.1706.20381.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.gethelp/resources/appdisplayname} |
"{30696D25-ADB7-4560-9C83-266CD646E547}" = dir=in | name=@{microsoft.ppiprojection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{31B1AC2F-791D-4AD1-8143-AE16A5067BEC}" = dir=out | name=@{microsoft.windowscalculator_10.1905.30.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscalculator/resources/appstorename} |
"{3490B541-72CC-4922-A8A7-705B4181EF99}" = dir=out | name=@{microsoft.windows.cortana_1.10.8.17134_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} |
"{355AA552-CE83-404F-866F-E52E4FD38EED}" = protocol=6 | dir=in | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.110.540.0_x86__zpdnekdrzrea0\spotify.exe |
"{37A8F65D-9BC1-41E3-B157-AAC77776446C}" = dir=out | name=@{microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/appmanifest_outlookdesktop_displayname} |
"{384B0407-E0A9-4E14-BFDB-6BBAD77D5027}" = dir=out | name=@{microsoft.accountscontrol_10.0.14393.447_neutral__cw5n1h2txyewy?ms-resource://microsoft.accountscontrol/resources/displayname} |
"{3B8CD071-D423-49F5-B46D-B75D351AEA57}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.17134.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{3C30FA9B-971D-402A-8A9C-571BFE88B434}" = dir=out | name=onenote |
"{3D2E106D-F35F-4247-85F2-A351C9B43DBD}" = dir=in | app=c:\program files\js backup\jsbackuppc.exe |
"{3E8A0D3B-8ACA-4D6E-A557-05806CD08E4B}" = protocol=17 | dir=in | app=c:\program files\windowsapps\appleinc.itunes_12095.7.41059.0_x64__nzyj5cx40ttqa\itunes.exe |
"{3F2EFBEC-660D-4CD6-BE6F-5C75CCDF5A89}" = dir=out | name=shell input application |
"{414CBEBB-E14F-4F63-AB17-4EAB6714205C}" = dir=in | name=@{microsoft.windowsfeedbackhub_1.1811.10862.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsfeedbackhub/resources/appstorename} |
"{43C356F9-BD19-4EA9-A631-0DDA540273D8}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{49D7DA72-22FC-46B2-A1DB-5BD4D4D602C4}" = dir=out | name=@{microsoft.messaging_4.1901.10241.1000_x64__8wekyb3d8bbwe?ms-resource://microsoft.messaging/resources/appstorename} |
"{4A81D737-BD7F-4E99-9C23-EC792F6410B4}" = dir=out | name=media player by smedio truelink+ |
"{4B222D7C-1356-44DC-9B59-65A27EA9D826}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.17134.112_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} |
"{4CADD7FF-B042-45D9-B97A-9D0E89658094}" = dir=in | name=smedio truelink+ phone |
"{4EC0F5DE-F352-4054-8312-F2F7C827FD3A}" = dir=in | name=@{microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/appmanifest_outlookdesktop_displayname} |
"{51A2689E-2A15-4DD1-87B6-3EE61318C90F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{51DA66DC-E820-41E5-B451-EF4B2C641D19}" = dir=out | name=@{microsoft.storepurchaseapp_11811.1001.18.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.storepurchaseapp/resources/displaytitle} |
"{54016CC1-421E-4919-B5EF-323E301DAE64}" = dir=out | name=@{microsoft.windowsmaps_5.1902.843.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsmaps/resources/appstorename} |
"{5499F2B8-C2D8-4FF3-9DE4-7B3FF4439A1B}" = dir=out | name=@{microsoft.people_10.1902.633.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.people/resources/appstorename} |
"{563C8542-08B5-45D8-A520-DBFEDB8F3190}" = dir=in | name=@{microsoft.microsoftedge_42.17134.1.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{56AC529C-5CBF-4062-9D27-EAD51A87C4C1}" = dir=in | name=@{microsoft.windows.cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} |
"{578FBAA9-76CD-4761-BECE-837387E536F9}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{5A989E6B-6904-48CC-B843-591B7AD6DF1A}" = dir=out | name=@{microsoft.zunevideo_10.19031.11411.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{5C41F8DC-C016-403B-8FB9-C82CDF063EE6}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{5D0754F5-09BE-490B-983B-A8CA148EA9F3}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{5DD59C9A-ACF4-4036-9315-93E8203AF111}" = dir=out | name=smedio truelink+ phone |
"{5EF38E07-6EEB-47FE-83DD-0B1BF7489699}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} |
"{604C6595-52B2-4FDC-98BD-869C8CBD9B29}" = dir=in | name=microsoft sticky notes |
"{615B11FE-2534-4BDB-8F69-ACF1F8C887DF}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{620C9A24-2559-48F2-8EAF-D9B4D0A13A28}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{6210497F-6B98-458A-AB77-A851AAC2F657}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{62231FB4-36C4-41A8-93B8-B5A17760E28D}" = dir=out | name=netflix |
"{642708C6-3838-4B29-849E-8C992A8CDDBF}" = dir=in | name=@{microsoft.microsoftedge_38.14393.0.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{65854719-CA9C-4EEB-A1C4-2F28DDF1C096}" = dir=in | name=onenote |
"{66806ACE-9540-4F2F-93AF-5DADD50CBEEE}" = dir=out | name=@{microsoft.getstarted_6.15.12641.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.getstarted/resources/appstorename} |
"{6a052b0e-c276-4a61-9a64-628d132aee0d}" = protocol=6 | dir=in | app=c:\program files (x86)\toshiba\screen mirroring\screen mirroring.exe |
"{6C8859FB-A63E-43BF-8CF7-D7A9D4F2DCD7}" = dir=in | name=@{microsoft.ppiprojection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{6F72DC7D-D190-470A-80D6-974DCA8B8DE7}" = dir=out | name=windows_ie_ac_001 |
"{73D4C1CC-7753-4CBC-B2D5-F22BD70676BE}" = dir=out | name=@{microsoft.microsoftedge_38.14393.0.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{75831159-3015-481A-9062-63D50B241B3F}" = dir=out | name=@{microsoft.lockapp_10.0.17134.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} |
"{774657EF-A7C9-4623-AFBA-A492003A01F8}" = protocol=6 | dir=in | app=c:\program files\windowsapps\appleinc.itunes_12095.7.41059.0_x64__nzyj5cx40ttqa\amds64\applemobiledeviceprocess.exe |
"{7C4F181A-72E6-4FE8-8A77-700351501FF3}" = dir=out | name=smedio truelink+ phone |
"{7DEEA06B-A503-4E12-BBB1-8F0DC0575135}" = dir=in | name=@{microsoft.windows.cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} |
"{8102991F-6CB6-426E-94CB-B97E9428EBA2}" = dir=out | name=@{microsoft.accountscontrol_10.0.17134.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.accountscontrol/resources/displayname} |
"{81059D08-87C0-4C09-ADBE-A70E02FB3FDA}" = dir=out | name=思い出フォトビューア クッキングプラス |
"{8105EB08-D406-4F89-B3AC-6014A9F0413A}" = dir=out | name=@{0d9a1b2d.pdfreaderuwp_1.9.719.0_x64__jhretta7p24aw?ms-resource://0d9a1b2d.pdfreaderuwp/model/appname} |
"{817A4DEA-5DF5-4BF5-922F-7B0CA7250CDD}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} |
"{823D30E6-C050-43EF-AAE0-F58BEE274F58}" = dir=out | name=@{microsoft.xboxidentityprovider_12.54.26001.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxidentityprovider/resources/displayname} |
"{8240169C-81BD-41C6-AB66-34DDB076B215}" = protocol=17 | dir=out | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.110.540.0_x86__zpdnekdrzrea0\spotify.exe |
"{8323B9FE-062C-4BDB-80D7-486A54B902B7}" = dir=in | name=@{microsoft.windowsstore_11905.1001.4.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} |
"{8884902A-CC02-46D3-929B-4DFF94CFE90B}" = protocol=6 | dir=out | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.110.540.0_x86__zpdnekdrzrea0\spotify.exe |
"{8968E753-D2B8-4C1C-AA81-B7E283E5C7DB}" = dir=in | name=netflix |
"{8A267A83-D46E-46DD-9D6E-9EE1F896E99D}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{8D660BCC-2A5D-4515-8AD9-D4CC9B65A668}" = dir=in | name=@{microsoft.windows.cortana_1.10.8.17134_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} |
"{90399B88-96FA-424F-B458-C0EA0329D9EB}" = dir=in | app=c:\program files (x86)\cyberlink\seeqvault player\movie\powerdvd cinema\powerdvdcinema12.exe |
"{92440B52-15E7-4D7E-9AC7-5CE6EF7FC39C}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.17134.112_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} |
"{925DFC2E-07E0-41C0-8A0C-EB1876FBF2AD}" = dir=out | name=@{microsoft.xboxgamecallableui_1000.17134.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxgamecallableui/resources/pkgdisplayname} |
"{932AC3AC-CD87-451F-A106-0E9CE7682CBC}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{93CE2F78-B98C-4CD1-A39F-AE00C4393540}" = dir=in | name=@{microsoft.zunevideo_10.19031.11411.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{94F5121A-7331-4857-BF8D-B79C07893EF0}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} |
"{961420D6-A1C3-4EF8-A443-F73F2462C113}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{979A90B5-1932-4570-9122-21E6C0716C99}" = dir=in | name=smedio truelink+ phone |
"{98049E18-E459-4CBC-A81A-74953D63470F}" = dir=out | name=@{microsoft.windows.oobenetworkcaptiveportal_10.0.17134.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.windows.oobenetworkcaptiveportal/resources/appdisplayname} |
"{980F8072-37B2-4A2C-ABF9-356C6DAF1F5A}" = dir=out | name=@{microsoft.zunemusic_10.19031.11411.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{98DDF439-7C0C-4B9F-9472-299ED0BD1BC5}" = dir=out | name=@{microsoft.mspaint_5.1904.8017.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.mspaint/resources/appname} |
"{98E5C2A9-78FF-4916-B647-8AD70C10993D}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.17134.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{99BE45D6-ABF2-4D15-A924-1738DDB4D59D}" = dir=out | name=win32webviewhost |
"{9A125D6A-E7B4-4245-8131-FB12DAA94B8B}" = dir=out | name=candy crush saga |
"{9B20147D-5D48-4293-815B-D53E06FE15DD}" = dir=out | name=@{microsoft.desktopappinstaller_1.0.31351.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.desktopappinstaller/resources/appdisplayname} |
"{9EC17AB4-86CE-4F1C-AF97-606DC099303C}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.17134.112_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} |
"{9FA2E616-B67D-4DE7-80D5-EC821BD23704}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{A0046514-FD85-49A7-8372-6E402C0A0AB1}" = dir=in | app=c:\program files (x86)\smedio\tvconnectsuite\bin\tvconnectsuite.exe |
"{A074E75F-D3CB-433C-9C6F-CC63016D026D}" = dir=in | name=tvコネクトスイート |
"{A4856001-6458-4E82-9F22-F32811DD4697}" = dir=out | name=思い出フォトビューア |
"{A58BB5C6-75E0-4013-859E-361C580450B1}" = dir=in | name=思い出フォトビューア |
"{A778650D-5F37-4BCC-A03D-577D86E36E4E}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} |
"{A8D1793F-92D7-4D51-B431-334EED4DB803}" = dir=out | name=@{microsoft.windowsstore_11905.1001.4.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} |
"{A96F1882-4C16-48FC-A82C-A015B2793CE2}" = protocol=17 | dir=in | app=c:\program files\windowsapps\appleinc.itunes_12095.7.41059.0_x64__nzyj5cx40ttqa\itunes.exe |
"{AA1526D4-2A5E-46E1-82BE-FC86D9A64413}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{AAAB0865-5570-4437-931E-B4FD20DE7418}" = dir=in | name=@{microsoft.xboxapp_48.55.9001.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxapp/xboxapp.resource/resources/app_title} |
"{AF6EF613-61CB-4077-9CCD-18F578EB4414}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{AF96C643-7847-4602-A085-E90FE3C2C1C6}" = dir=out | name=@{microsoft.windows.photos_2019.19051.16210.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} |
"{B0110712-6649-4C83-A0DA-C69C962CAC35}" = dir=out | name=@{microsoft.ppiprojection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{B20F01CF-79BB-45A8-BE78-852C97788E14}" = dir=out | name=xbox gaming overlay |
"{B22267B5-5202-4847-A7ED-E89D7330D6F0}" = dir=out | name=trurecorder |
"{B2E7AFF7-F6AD-448A-AAFF-B75FDB3B60F7}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.17134.112_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} |
"{B4BBE25E-7979-454F-8A45-7D9882F4E9D2}" = dir=out | name=@{microsoft.windows.apprep.chxapp_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.apprep.chxapp/resources/displayname} |
"{B63EC61C-77DA-4499-92F8-D2C18AFE87C7}" = dir=in | app=c:\program files (x86)\smedio\tvconnectsuite\bin\tvcsdubbingservice.exe |
"{B70CD7C2-A93B-477B-97D4-AC7262B362B1}" = dir=out | name=@{microsoft.lockapp_10.0.14393.0_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} |
"{B718864A-F227-40E1-9E73-C1F6B12AF87B}" = dir=out | name=@{microsoft.ppiprojection_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{B774E946-C8C6-4568-9C15-6CC0AA625252}" = dir=out | name=windows_ie_ac_001 |
"{B7827519-FE47-4FD7-AFD4-C648A2FF37F5}" = dir=in | name=@{microsoft.oneconnect_5.1906.1791.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.oneconnect/oneconnectstrings/oneconnect/appstorename} |
"{B8C8DB8F-3A18-4C13-B634-EE1FBC2111B7}" = dir=out | name=@{microsoft.xboxgamecallableui_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxgamecallableui/resources/pkgdisplayname} |
"{B8F9A78B-D600-45F5-84DA-637C4979E6A6}" = dir=out | name=microsoft solitaire collection |
"{B9790230-76C7-4C6F-BEAD-90572CD4CF26}" = dir=in | name=@{microsoft.windows.photos_2019.19051.16210.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} |
"{BC232F9C-9EA5-40DA-98AF-1A32A00B43CF}" = dir=out | name=print 3d |
"{BCB74668-B6C2-4040-9FC9-659282241306}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{C269B969-CB04-4572-946A-9CE4C2179323}" = dir=out | name=シュフーチラシアプリ for toshiba |
"{c2bd9ce1-3f97-4afe-9c26-eefb98daa5d6}" = protocol=17 | dir=in | app=c:\program files (x86)\toshiba\screen mirroring\screen mirroring.exe |
"{C482C675-5C57-4B97-83B1-7F8CE74C54F5}" = dir=out | name=microsoft pay |
"{C6E699EC-2254-4922-908A-1FD38B8763F9}" = dir=out | name=@{microsoft.bingnews_4.31.11905.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/applicationtitlewithtagline} |
"{C74D0172-8D5D-4B8F-8A30-DC8262A7B9BD}" = dir=out | name=@{microsoft.ppiprojection_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{CA64AEEF-F473-48D9-9D52-B85EDB97F8C7}" = protocol=6 | dir=in | app=c:\program files\windowsapps\appleinc.itunes_12095.7.41059.0_x64__nzyj5cx40ttqa\itunes.exe |
"{CB17160A-EB8B-4DBF-B015-EDA303C018D0}" = dir=out | name=@{microsoft.lockapp_10.0.17134.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} |
"{CC4E068B-E40A-415E-9917-78EDB74D60CC}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{CD3D096B-6EEA-4E50-B405-32533812DEDF}" = dir=out | name=@{microsoft.lockapp_10.0.17134.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} |
"{D35799A6-4B05-4C38-9773-C9B57876A2C2}" = dir=out | name=@{microsoft.microsoft3dviewer_6.1903.4012.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoft3dviewer/common.view.uwp/resources/storeappname} |
"{D5EDAEF2-FDC0-45E4-925B-A9A7F8B9654B}" = dir=out | name=@{microsoft.lockapp_10.0.17134.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} |
"{D8154EFC-5874-41E8-98FF-482103192F72}" = dir=out | name=@{microsoft.lockapp_10.0.17134.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} |
"{D9305281-6E88-482A-863D-ADA660F6E8D4}" = dir=out | name=xbox tcui |
"{D9A8C288-6595-4507-8CE8-6C2BC8CD2B7B}" = dir=out | name=@{microsoft.oneconnect_5.1906.1791.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.oneconnect/oneconnectstrings/oneconnect/appstorename} |
"{D9E1C043-BABC-4AC7-81FE-3E472DFBE88D}" = protocol=6 | dir=in | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.110.540.0_x86__zpdnekdrzrea0\spotify.exe |
"{DAB4E335-CCBE-4BBF-9982-46E74853C8A9}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} |
"{DCAFEA56-6928-4745-814B-5DB5EAF7CA84}" = dir=in | name=@{windows.contactsupport_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} |
"{DE3580F4-78BF-4C2D-BC43-EB8B825D9ABC}" = dir=out | name=@{microsoft.windows.parentalcontrols_1000.17134.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.parentalcontrols/resources/displayname} |
"{DF61A102-3224-4EB4-BEBF-650167D63200}" = dir=in | name=media player by smedio truelink+ |
"{E17ABDD5-79A3-4DA4-AA0F-32142F9BB439}" = dir=in | name=skype |
"{E28DEDFF-153A-4042-9271-583AA09D0992}" = dir=out | name=あんしんweb by internet sagiwall for dynabook |
"{E2DA431B-7050-4952-A3B6-16F54995EAB4}" = dir=in | name=@{microsoft.ppiprojection_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{E4E94870-3A21-4ACB-B80E-6383C6F72CDC}" = dir=in | name=microsoft solitaire collection |
"{E6ECDCE9-19B6-4474-A35F-73B29D420B23}" = dir=out | name=@{microsoft.bingweather_4.31.11905.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} |
"{E721D739-6295-486B-B594-9D0B5B7F8B21}" = dir=out | name=@{microsoft.windows.cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} |
"{EB318A32-7FA0-4CBC-9D38-5CE8CC704210}" = dir=out | name=tvコネクトスイート |
"{EC386CF6-815D-49D7-A966-036291412C9A}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.17134.112_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} |
"{EE8C1988-F985-4F96-B1EF-F5A3678E2C3C}" = dir=out | name=@{microsoft.windows.cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} |
"{F3ACF47A-7C41-4666-B13B-76618B69F1FD}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{F40C3AD5-5928-4303-A31B-48B267950451}" = dir=out | name=@{microsoft.windows.peopleexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.peopleexperiencehost/resources/pkgdisplayname} |
"{F42EBCC9-CB3C-4226-AB4A-D9AD852BEBEE}" = dir=out | name=skype |
"{F657B284-881E-450C-ABC7-DC17B2DACBBA}" = dir=in | name=@{microsoft.messaging_4.1901.10241.1000_x64__8wekyb3d8bbwe?ms-resource://microsoft.messaging/resources/appstorename} |
"{FA9D1F83-5C3A-4E6A-88A0-EC8251E7DCE3}" = dir=out | name=楽天gateway |
"{FC3206C6-D26C-47E9-B559-3CBC49BCEF38}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{FCA80B1B-FF21-4258-BA9F-9CE62D4F84F0}" = dir=out | name=office |
"{FD44494D-77CE-4A47-8C26-622AC9544AE5}" = dir=out | name=@{microsoft.lockapp_10.0.17134.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} |
"{FD8B14E2-84F8-4A88-A480-EEEFDA70F669}" = protocol=6 | dir=in | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.110.540.0_x86__zpdnekdrzrea0\spotify.exe |
"{FDBD204E-6708-404A-8A87-F21346B171E0}" = dir=out | name=@{microsoft.microsoftedge_42.17134.1.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{FEC689D6-4E59-4121-BE89-7A69FA678E05}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} |
"{FF5D0556-D6B5-4C02-8220-22FBE6868837}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.17134.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0DC0AEB8-2DE9-49F5-BE46-0CEE25F759F9}" = Intel® Online Connect Access
"{14507E89-9B14-4B95-91E5-8ED26646120B}" = Microsoft VC++ redistributables repacked.
"{19EF6E72-C59B-4EAC-B370-F504800EB8F5}" = Intel(R) Management Engine Components
"{1CEAC85D-2590-4760-800F-8DE5E91F3700}" = Intel(R) Management Engine Components
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{299A1ADD-CD05-405A-8F2F-4BE5B1FD93E8}" = TOSHIBA Product Improvement Program
"{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1" = Malwarebytes バージョン 3.8.3.2965
"{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
"{3A86092C-3E9F-4184-821F-FBDED23A917F}" = Intel(R) Chipset Device Software
"{409CB30E-E457-4008-9B1A-ED1B9EA21140}" = Intel(R) Rapid Storage Technology
"{490572F9-2AD8-4C1B-A771-12C2063ED356}" = Synaptics WBF DDK 5111
"{541DB02F-808F-47D1-A2C8-8A015366347C}" = Intel® Online Connect
"{72EFCFA8-3923-451D-AF52-7CE9D87BC2A1}" = TOSHIBA eco Utility
"{7CC39E74-D4EE-4954-AACB-B0D6F5C320CB}" = JSバックアップ(64bit)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90160000-008F-0000-1000-0000000FF1CE}" = Office 16 Click-to-Run Licensing Component
"{90160000-00DD-0000-1000-0000000FF1CE}" = Office 16 Click-to-Run Extensibility Component 64-bit Registration
"{936D21BF-3344-4B20-BC4C-3B67580C19F5}" = Bluetooth(R) Link
"{9B359E4B-1B62-4075-9D27-969FF952A2D3}" = Intel(R) Management Engine Components
"{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}" = ウイルスバスター クラウド
"{ABBD4BA9-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro Titanium
"{AF3E59AC-D274-4FA2-91C0-BB8D549FA369}" = Intel® PROSet/Wireless WiFi Software
"{B040D5C9-C9AA-430A-A44E-696656012E61}" = TOSHIBA System Settings
"{B36B82CF-9729-4B02-B1BE-0D12A10C0626}" = Intel(R) Management Engine Components
"{BD1A5CE8-4E70-4AD4-8C27-C59436AB14DC}" = dynabookサウンドエンジン by Audyssey
"{CD4B9E2C-4295-4920-82F2-C87113822E32}" = TOSHIBA Password Utility
"{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
"{DF96959B-6886-4379-B60E-27B05269C0CF}" = TOSHIBA Manual
"{EBE12EC7-60DF-41C2-AAC8-0B2586F15C96}" = Intel(R) Rapid Storage Technology
"{f0c2df6a-d387-41c4-b386-c7c6ce46fd87}" = Intel(R) PRO/Wireless Driver
"{F255C3B6-F053-4592-9325-34898BF5EB46}" = Intel® Trusted Connect Service Client
"{F9943B88-9ED0-4FD5-A9AC-D34B94D694DF}" = TOSHIBA Service Station
"{FF07604E-C860-40E9-A230-E37FA41F103A}" = TOSHIBA Blu-ray Disc Player
"CCleaner" = CCleaner
"HomeBusinessPipcRetail - ja-jp" = Microsoft Office Home and Business Premium - ja-jp
"PROSet" = Intel(R) Network Connections Drivers
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08E8726C-DD63-4700-A532-268AECB47BDC}" = 筆ぐるめ 24
"{124276A6-F01A-46DD-96C6-981FFC7498F1}" = OEM Registration Program
"{1E6A96A1-2BAB-43EF-8087-30437593C66C}" = TOSHIBA System Driver
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{34B74395-A3EB-4AC4-897F-1D9AED0EB476}" = おたすけナビ
"{4480E009-FC3C-4A43-AE8D-46E939762DD8}" = Microsoft VC++ redistributables repacked.
"{4FA94F64-1A00-4426-BF58-D08EB592CE1B}" = Intel(R) Online Connect Software Asset Manager
"{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}" = Realtek Card Reader
"{5f5c7829-a6ba-4fc6-9f47-d068f51ed99b}" = インテル® チップセット デバイス ソフトウェア
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{665C6B96-45AB-49E0-9938-E397B09D09F4}" = 東芝スクリーンミラーリング
"{6BADCD73-E925-46F7-A295-FF2448632728}" = CyberLink PowerDirector 14
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716C8275-A4A9-48CB-88C0-9829334CA3C5}" = Toshiba Quality Application
"{7984FCA5-1BB6-46e6-91E2-ED5C301AF11A}" = CyberLink PhotoDirector 7
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{90160000-008C-0000-0000-0000000FF1CE}" = Office 16 Click-to-Run Extensibility Component
"{90160000-008C-0411-0000-0000000FF1CE}" = Office 16 Click-to-Run Localization Component
"{90A2E386-DF65-4F88-A232-8AAE2563D7B3}" = CyberLink Screen Recorder
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A3EC99D-7590-4C4F-B2CD-323AD663CD4D}" = インテル(R) ワイヤレス Bluetooth(R)
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
"{CAB75FFC-2377-4B95-A8FA-C9234B812A92}_is1" = LoiLoScope 2
"{CEBA8D58-1084-4420-BF34-918B804ABE0E}" = PC引越ナビ
"{DC0729F8-3DA0-4baa-93F3-7F146E513574}" = CyberLink SeeQVault Player
"{DE4E4EC1-86DF-4C66-A411-F607B565A985}" = TVコネクトスイート ダビング設定ユーティリティ
"{e2b029f6-aed3-4900-902e-bfeafd421893}" = インテル® PROSet/Wireless ソフトウェア
"{E6A85262-B47B-4F07-9C79-9F99ACEF3D5A}" = TOSHIBA PalaDouga
"{EC79FB34-D65C-4415-8F04-A0E9ABE12814}" = ウイルスバスター登録ツール
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E331DC-17F5-424F-A808-D1E49C4DBBCC}" = バックアップナビ クラウド
"{F66DC99B-ACED-4EEA-9378-061494F2CE0C}" = ぱらちゃんV2.3
"{FA573BC8-9E4C-4B4B-8696-3C6836967249}" = ウイルスバスター登録ツール
"Google Chrome" = Google Chrome
"InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8
"InstallShield_{665C6B96-45AB-49E0-9938-E397B09D09F4}" = 東芝スクリーンミラーリング for Windows PC/タブレット
"InstallShield_{716C8275-A4A9-48CB-88C0-9829334CA3C5}" = Toshiba Quality Application
"InstallShield_{DC0729F8-3DA0-4baa-93F3-7F146E513574}" = CyberLink SeeQVault Player
"LAPLINK HelpDesk Client" = LAPLINK ヘルプデスク クライアント
"Lhaplus" = Lhaplus

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"OneDriveSetup.exe" = Microsoft OneDrive

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"OneDriveSetup.exe" = Microsoft OneDrive

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"OneDriveSetup.exe" = Microsoft OneDrive

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2019/07/13 1:20:53 | Computer Name = LAPTOP-QCSS294P | Source = COM | ID = 10031
Description =

Error - 2019/07/13 1:20:53 | Computer Name = LAPTOP-QCSS294P | Source = COM | ID = 10031
Description =

Error - 2019/07/14 3:29:12 | Computer Name = LAPTOP-QCSS294P | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: Windows.WARP.JITService.exe、バージョン: 0.0.0.0、タイム
スタンプ: 0xbf3928ce 障害が発生しているモジュール名: d3d10warp.dll、バージョン: 10.0.17134.619、タイム スタンプ:
0xe17c1dbf 例外コード: 0xc0000409 障害オフセット: 0x0000000000043ef8 障害が発生しているプロセス ID: 0x2cec 障害が発生しているアプリケーションの開始時刻:
0x01d53a14a6e9cd9f 障害が発生しているアプリケーション パス: C:\WINDOWS\system32\Windows.WARP.JITService.exe
障害が発生しているモジュール
パス: C:\WINDOWS\system32\d3d10warp.dll レポート ID: 014c5326-d8ca-4a82-bec1-dc12ee36d234
障害が発生しているパッケージの完全な名前:
? 障害が発生しているパッケージに関連するアプリケーション ID: ?

Error - 2019/07/17 7:27:32 | Computer Name = LAPTOP-QCSS294P | Source = COM | ID = 10031
Description =

Error - 2019/07/17 7:27:32 | Computer Name = LAPTOP-QCSS294P | Source = COM | ID = 10031
Description =

Error - 2019/07/19 11:30:34 | Computer Name = LAPTOP-QCSS294P | Source = COM | ID = 10031
Description =

Error - 2019/07/19 11:30:34 | Computer Name = LAPTOP-QCSS294P | Source = COM | ID = 10031
Description =

Error - 2019/07/23 9:21:47 | Computer Name = LAPTOP-QCSS294P | Source = COM | ID = 10031
Description =

Error - 2019/07/23 9:21:47 | Computer Name = LAPTOP-QCSS294P | Source = COM | ID = 10031
Description =

Error - 2019/07/23 9:31:57 | Computer Name = LAPTOP-QCSS294P | Source = VSS | ID = 8193
Description =

[ System Events ]
Error - 2019/07/23 9:25:31 | Computer Name = LAPTOP-QCSS294P | Source = DCOM | ID = 10016
Description =

Error - 2019/07/23 9:25:59 | Computer Name = LAPTOP-QCSS294P | Source = DCOM | ID = 10016
Description =

Error - 2019/07/23 9:25:59 | Computer Name = LAPTOP-QCSS294P | Source = DCOM | ID = 10016
Description =

Error - 2019/07/23 9:29:00 | Computer Name = LAPTOP-QCSS294P | Source = DCOM | ID = 10016
Description =

Error - 2019/07/23 9:29:00 | Computer Name = LAPTOP-QCSS294P | Source = DCOM | ID = 10016
Description =

Error - 2019/07/23 9:29:00 | Computer Name = LAPTOP-QCSS294P | Source = DCOM | ID = 10016
Description =

Error - 2019/07/23 9:29:00 | Computer Name = LAPTOP-QCSS294P | Source = DCOM | ID = 10016
Description =

Error - 2019/07/23 9:29:00 | Computer Name = LAPTOP-QCSS294P | Source = DCOM | ID = 10016
Description =

Error - 2019/07/23 9:29:01 | Computer Name = LAPTOP-QCSS294P | Source = DCOM | ID = 10016
Description =

Error - 2019/07/23 9:41:06 | Computer Name = LAPTOP-QCSS294P | Source = DCOM | ID = 10016
Description =


< End of report >
  • sho
  • 2019/07/23 (Tue) 23:32:48
C:\ProgramData\DP45977C.lfl←これを掃除しましょう
作業と報告、ご苦労様です。
OTLスキャンログを見せてもらいました。
長いログの投稿も手間取ったでしょうがおかげでだいぶ見えてきました。

6月24日に作成された↓ですが
>[2019/06/24 20:57:12 | 000,000,000 | -H-- | M] () -- C:\ProgramData\DP45977C.lfl

このDP45977C.lflというのは当掲示板の過去投稿で何度か見つかっているモノで、いささか行儀よくない代物らしいです。

では見つかったゴミをOTLでそうじにかかりましょう。
またOTLを使って作業します。

このレスの最後にスクリプトを貼っておくので、それを丸ごとコピーして、それをWindowsのメモ帳ファイルに貼り付けて保存しておいてください。

用意できたらPCをまたセーフモードで再起動してOTL起動してください。
起動したらOTLのウインドウ下部にスクリプトを貼り付けて、今度は「Run fix」(赤字のボタン)を押してください。
これでOTLでの処置が開始されます。

しばらく待って処置ができたらPCを通常モードで再起動すると、またOTLのログが出るはずなので、それを保存してから、しばらく様子見の後、OTLのログとともに状態報告をレスください。
OTLのスクリプトは以下になります。破線(-----)を含まない箇所を丸ごとコピーして、それをOTLに貼って作業してください
------------------------------------------
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,IE11DefaultsFRECompletionTime = BB E2 D1 7A 19 30 D5 01 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,IE11DefaultsFREConfigUpdateTimestamp = 6C B2 91 C3 D6 40 D5 01 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = 4D 07 FA 86 91 2A D5 01 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = 01 00 00 00 2A 00 00 00 F1 E0 2F BD 98 8B 5D 53 C9 71 5B CA 85 7E B3 A3 67 FC 34 CE C3 72 B4 58 97 35 7D 76 A0 89 20 E4 34 70 67 3E DB 19 28 EE CF 55 02 00 00 00 10 00 00 00 41 2F 25 32 62 6A 73 34 34 63 7A 66 38 25 33 64 [binary data]
[2019/06/24 20:57:12 | 000,000,000 | -H-- | M] () -- C:\ProgramData\DP45977C.lfl

:Files
C:\ProgramData\DP45977C.lfl

:reg

:Commands
[purity]
[resethosts]
[emptytemp]
[createrestorepoint]
[reboot]
------------------------------------------
  • 悪代官
  • 2019/07/24 (Wed) 16:28:16
Re: プラウザが勝手に開かれます。
レスありがとうございます。
セーフモードでOTLにてRun fixしたら、すぐに再起動しました。
そのあとに出たログを貼らせていただきます。

All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\IE11DefaultsFRECompletionTime| /E : value set successfully!
HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\IE11DefaultsFREConfigUpdateTimestamp| /E : value set successfully!
HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page_TIMESTAMP| /E : value set successfully!
HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy| /E : value set successfully!
C:\ProgramData\DP45977C.lfl moved successfully.
File rity] not found.
File sethosts] not found.
File ptytemp] not found.
File eaterestorepoint] not found.
File boot] not found.

OTL by OldTimer - Version 3.2.69.0 log created on 07242019_185413

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • sho
  • 2019/07/24 (Wed) 18:57:57
異常なければ全体の洗い直しを
早速の作業と報告、ご苦労様です。
処置後のOTLログも見せてもらいましたが、対象は無事掃除できましたね。
successfully(処置完了)になってます。

一応Cドライブを手動目視で開いて、下記が復活していないか見てください。
>C:\ProgramData\DP45977C.lfl

復活してなければいいですが、復活しているなら教えてください。

それと現在異常が出ているかどうかも教えてください。

異常なければ全体の洗い直ししましょう。
お手数ですがまたHJTログと、CCでインストール情報と各タブのログを取り直して、それらをレスで見せてください。

処置の取りこぼしや新たな問題がないかも含めて全体を再確認します
  • 悪代官
  • 2019/07/24 (Wed) 19:57:15
Re: プラウザが勝手に開かれます。
レスありがとうございます。
一応Cドライブを手動目視で開いて、下記が復活していないか見てください。
>C:\ProgramData\DP45977C.lfl
これは、Cドライブに上記のフォルダがあるかどうかということですか?
(初心者ですみません・・・
  • sho
  • 2019/07/25 (Thu) 00:31:54
Re: プラウザが勝手に開かれます。
追記ですが、Edgeを開くと、タブがたくさん勝手に開かれる症状が再発してしまいました。

  • sho
  • 2019/07/25 (Thu) 00:34:15
またEdgeの不安定さが出ましたか
またレスが遅くなってすみません。
こうやって敵を焦らしてから隙を突いて倒すのが悪代官の策略です(←いったい何と戦ってるんだ

>>C:\ProgramData\DP45977C.lfl
>これは、Cドライブに上記のフォルダがあるかどうかということですか?

はい、マイコンピュータのCドライブの上記パスに存在しているかどうかです。
通常はProgramDataは非表示なので、作業開始時に案内した隠しファイル表示設定していれば表示されます。
ProgramDataフォルダに上記ファイルなくなっていればそれでいいです。

>追記ですが、Edgeを開くと、タブがたくさん勝手に開かれる症状が再発してしまいました。

これですが、あちこちで散見するトラブルのようですね。
ちょっと他の方から教えていただいたのですが、Edgeのリセットすることで修復できる可能性があります。
ただし環境によってはEdgeがクラッシュして修復もできなくなるバグもあるそうで、実行するなら事前にお気に入りや必要データのバックアップしたうえで、失敗したらOSの初期化も覚悟の上で判断したほうがいいでしょう。
アクティビティ情報にブラウザでの閲覧履歴やファイル表示履歴もクラウドベースで保存されているそうでそれらも削除することになりますね。

自分の私見としてはEdgeというよりWin10そのものがまだ不安定な部分抱えていてWindowsUpdateでの修正も追いつかないまま多くのユーザーがトラブル対応に迷っていることもあるので、可能ならEdge以外のブラウザを使用推奨します。
メジャー系ブラウザのChromeかFirefoxかVivaldiのうちから選ぶのがいいでしょう。

複数のブラウザを入れておくのは特定のブラウザが壊れたり設定改ざんされて正常に使えなくなった際に、他のブラウザで必要な情報や修復プログラムをダウンロードすることが可能になります。
Chromeは既にお使いなのであとはFFやVVも入れるかは判断お任せします。
他のブラウザを使うならEdgeは今はいじらずそのままにしてMS側の修正を待つのもありです
  • 悪代官
  • 2019/07/25 (Thu) 19:07:34
Re: プラウザが勝手に開かれます。
レスありがとうございます。

またIEのプラウザがたくさん出てきました
  • sho
  • 2019/07/25 (Thu) 19:54:18
Re: プラウザが勝手に開かれます。
とりあえず#16635580で案内したHJTとCCの各ログを取り直したらそれを見せてもらえますか。
スタートアップの確認してみましょう
  • 悪代官
  • 2019/07/25 (Thu) 21:46:27
Re: プラウザが勝手に開かれます。
一番最初のログの作業でしょうか?

HJT
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 11:46:31, on 2019/07/27
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.17134.0001)


Boot mode: Normal

Running processes:
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Users\sho50\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingServiceTrayIcon.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\sho50\Desktop\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\sho50\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Trend Micro Solution Platform (Amsp) - Trend Micro Inc. - C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\elevation_service.exe
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem34.inf,%SERVICE_NAME%;Intel Bluetooth Service (ibtsiva) - Unknown owner - C:\WINDOWS\system32\ibtsiva (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\igfxCUIService.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Online Connect - Intel Corporation - C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe
O23 - Service: Intel(R) Online Connect Helper - Intel Corporation - C:\Program Files\Intel\Intel(R) Online Connect\iocHelperService.exe
O23 - Service: Intel(R) Online Connect Software Asset Manager - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe
O23 - Service: Intel(R) Online Connect Access Legacy CS Loader (Intel(R) TechnologyAccessLegacyCSLoader) - Intel(R) Corporation - C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe
O23 - Service: Intel(R) Online Connect Access (Intel(R) TechnologyAccessService) - Intel(R) Corporation - C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LLHDClient - Intercom, Inc. - C:\Program Files (x86)\Intercom\LAPLINK HelpDesk Client\LLHDClient.exe
O23 - Service: LLHDCloader - Intercom, Inc. - C:\Program Files (x86)\Intercom\LAPLINK HelpDesk Client\LLHDCldr.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: OEMRegistrationProgram - Toshiba Client Solutions Co., Ltd. - C:\Program Files (x86)\Toshiba\OEM Registration Program\OEMRegistrationProgram.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - CyberLink - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: SMITS - Unknown owner - C:\Windows\SysWOW64\SMITSC.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: TiMiniService - Trend Micro Inc. - C:\Program Files\Trend Micro\Titanium\TiMiniService.exe
O23 - Service: TMachInfo - Toshiba Client Solutions Co., Ltd. - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA eco Utility Service - Toshiba Client Solutions Co., Ltd. - C:\Program Files\TOSHIBA\Teco\TecoService.exe
O23 - Service: TOSRMService - Toshiba Client Solutions Co., Ltd. - C:\Program Files (x86)\TOSHIBA\TOSHIBA System Driver\RMService.exe
O23 - Service: TPCH Service (TPCHSrv) - Toshiba Client Solutions Co., Ltd. - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: TStationSrv - Toshiba Client Solutions Co., Ltd. - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TStationSrv.exe
O23 - Service: TVコネクトスイート ダビングサービス (TVCSDubbingService) - sMedio Inc - C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingService.exe
O23 - Service: @oem17.inf,%WBFService_SvcDesc%;Synaptics FP WBF Policy Service (valWBFPolicyService) - Unknown owner - C:\WINDOWS\system32\valWBFPolicyService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%systemroot%\system32\xbgmsvc.exe,-100 (xbgm) - Unknown owner - C:\WINDOWS\system32\xbgmsvc.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - IntelR Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 12072 bytes

CC
3D ビューアー Microsoft Corporation 2019/06/28 6.1903.4012.0
Bluetooth(R) Link Toshiba Client Solutions Co., Ltd. 2017/02/19 27.1 MB 5.4.1.1
Candy Crush Friends king.com 2019/06/30 1.15.13.0
Candy Crush Saga king.com 2019/07/16 1.1550.4.0
CCleaner Piriform 2019/07/08 5.59
CyberLink PhotoDirector 7 CyberLink Corp. 2019/06/24 586 MB 7.0.8317.0
CyberLink Power2Go 8 CyberLink Corp. 2017/02/19 199 MB 8.0.0.4707
CyberLink PowerDirector 14 CyberLink Corp. 2019/06/24 1.46 GB 14.0.3411.0
CyberLink Screen Recorder CyberLink Corp. 2019/06/24 26.0 MB 1.0.0.2321
CyberLink SeeQVault Player CyberLink Corp. 2017/02/19 168 MB 12.1.6106.55
dynabookサウンドエンジン by Audyssey Audyssey Laboratories 2017/02/19 2.33 MB 1.1.58.0
Google Chrome Google LLC 2019/07/16 75.0.3770.142
Groove ミュージック Microsoft Corporation 2019/06/28 10.19031.11411.0
HEVC Video Extensions from Device Manufacturer Microsoft Corporation 2019/06/29 1.0.13209.0
Intel(R) Management Engine Components Intel Corporation 2017/02/19 11.6.0.1039
Intel(R) Network Connections Drivers Intel 2019/06/24 916 KB 21.1
Intel(R) Processor Graphics Intel Corporation 2019/06/24 21.20.16.4550
Intel(R) Rapid Storage Technology Intel Corporation 2017/02/19 15.2.0.1020
iTunes Apple Inc. 2019/07/24 12096.3.41072.0
JSバックアップ(64bit) 株式会社情報スペース 2017/02/19 23.2 MB 2.0.4.0
LAPLINK ヘルプデスク クライアント Intercom, Inc. 2019/06/24 2.16
Lhaplus 2019/07/08
LoiLoScope 2 LoiLo inc 2017/02/19 166 MB 2.5.5.0
Malwarebytes バージョン 3.8.3.2965 Malwarebytes 2019/07/13 179 MB 3.8.3.2965
Media Player by sMedio TrueLink+ sMedio 2019/06/29 3.4.33.0
Microsoft Office Home and Business Premium - ja-jp Microsoft Corporation 2019/07/13 16.0.11727.20244
Microsoft OneDrive Microsoft Corporation 2019/07/03 131 MB 19.103.0527.0003
Microsoft Pay Microsoft Corporation 2019/06/24 2.1.18009.0
Microsoft Solitaire Collection Microsoft Studios 2019/06/28 4.4.6132.0
Microsoft Sticky Notes Microsoft Corporation 2019/07/25 3.6.76.0
Microsoft Store Microsoft Corporation 2019/06/29 11905.1001.4.0
Microsoft Store エクスペリエンス ホスト Microsoft Corporation 2019/06/28 11811.1001.18.0
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2017/02/19 4.84 MB 8.0.59193
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2017/02/19 13.2 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2017/02/19 10.2 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2017/02/19 10.1 MB 9.0.30729.4148
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2017/02/19 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2017/02/19 11.1 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Corporation 2019/06/24 20.5 MB 11.0.61030.0
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 2019/06/24 17.3 MB 11.0.61030.0
Microsoft ニュース Microsoft Corporation 2019/07/19 4.31.11905.0
Netflix Netflix, Inc. 2019/07/07 6.93.478.0
OEM Registration Program Toshiba Client Solutions Co., Ltd. 2017/02/19 4.00 KB 1.2.1
Office Microsoft Corporation 2019/06/29 18.1903.1152.0
OneNote Microsoft Corporation 2019/07/21 16001.11901.20096.0
PC引越ナビ Toshiba Client Solutions Co., Ltd. 2017/02/19 13.7 MB 5.2.4
PDF Reader Kdan Mobile Software Ltd. 2019/07/22 1.9.719.0
People Microsoft Corporation 2019/06/29 10.1902.633.0
Print 3D Microsoft Corporation 2019/06/29 3.3.791.0
Realtek Card Reader Realtek Semiconductor Corp. 2017/02/19 14.6 MB 10.0.14393.31231
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2019/06/24 6.0.1.8351
Skype Skype 2019/07/25 14.50.38.0
sMedio TrueLink+ Phone sMedio 2019/07/27 2.0.69.0
Spotify Spotify AB 2019/07/03 1.110.540.0
Synaptics Pointing Device Driver Synaptics Incorporated 2019/06/24 46.4 MB 19.4.3.182
Synaptics WBF DDK 5111 Synaptics 2017/02/19 18.8 MB 4.5.329.0
TOSHIBA Blu-ray Disc Player Toshiba Client Solutions Co., Ltd. 2017/02/19 106 MB 3.0.0.23
TOSHIBA eco Utility Toshiba Client Solutions Co., Ltd. 2017/02/19 25.3 MB 3.1.3.6401
TOSHIBA Manual Toshiba Client Solutions Co., Ltd. 2017/02/19 25.3 MB 0235.01.4101
TOSHIBA PalaDouga Toshiba Client Solutions Co., Ltd. 2017/02/19 0.96 GB 2016.0201.0002
TOSHIBA Password Utility Toshiba Client Solutions Co., Ltd. 2017/02/19 8.10 MB 9.03.04.01
TOSHIBA Recovery Media Creator Toshiba Client Solutions Co., Ltd. 2017/02/19 3.4.00.9001
TOSHIBA Service Station Toshiba Client Solutions Co., Ltd. 2017/02/19 17.2 MB 5.0.2.6403
TOSHIBA System Driver Toshiba Client Solutions Co., Ltd. 2017/02/19 6.91 MB 2.03.0003.03
TOSHIBA System Settings Toshiba Client Solutions Co., Ltd. 2017/02/19 62.5 MB 3.1.6.6400
TruRecorder Toshiba Client Solutions Co., Ltd. 2019/06/29 2.2.38.0
TVコネクトスイート sMedio 2019/06/29 2.4.51.0
TVコネクトスイート ダビング設定ユーティリティ sMedio Inc. 2017/02/19 4.76 MB 1.0.1.2
Update for Windows 10 for x64-based Systems (KB4023057) Microsoft Corporation 2019/06/29 1.41 MB 2.59.0.0
Web メディア拡張機能 Microsoft Corporation 2019/06/29 1.0.13321.0
Xbox Game bar Microsoft Corporation 2019/07/14 1.43.12001.0
Xbox Game Speech Window Microsoft Corporation 2019/06/28 1.21.13002.0
Xbox gaming overlay Microsoft Corporation 2019/06/29 1.16.1012.0
Xbox Identity Provider Microsoft Corporation 2019/07/10 12.54.26001.0
Xbox Live Microsoft Corporation 2019/06/28 1.24.10001.0
Xbox 本体コンパニオン Microsoft Corporation 2019/07/27 48.55.24001.0
あんしんWeb by Internet SagiWall for dynabook BB繧ス繝輔ヨ繧オ繝シ繝薙せ譬ェ蠑丈シ夂、セ 2019/06/29 2.2.0.5
おたすけナビ Toshiba Client Solutions Co., Ltd. 2017/02/19 38.9 MB 8.1.5
ぱらちゃんV2.3 Toshiba Client Solutions Co., Ltd. 2017/02/19 21.6 MB 2.3.50
ぱらちゃんカフェ 譚ア闃晄ュ蝣ア讖溷勣譬ェ蠑丈シ夂、セ 2019/06/29 1.1.0.3
アプリ インストーラー Microsoft Corporation 2019/06/29 1.0.31351.0
アラーム & クロック Microsoft Corporation 2019/06/29 10.1903.1006.0
インテル(R) ワイヤレス Bluetooth(R) Intel Corporation 2017/02/19 8.88 MB 19.11.1639.0649
インテル® PROSet/Wireless ソフトウェア Intel Corporation 2019/06/29 372 MB 21.0.0
ウイルスバスター クラウド トレンドマイクロ株式会社 2017/02/19 450 MB 10.0
ウイルスバスター登録ツール Trend Micro Inc. 2019/06/24 1.00
カメラ Microsoft Corporation 2019/06/29 2019.425.30.0
シュフーチラシアプリ for TOSHIBA TOPPAN PRINTING CO.,LTD. 2019/06/29 1.4.2.0
バックアップナビ クラウド Toshiba Client Solutions Co., Ltd. 2017/02/19 3.92 MB 1.4.4
ヒント Microsoft Corporation 2019/06/29 6.15.12641.0
フィードバック Hub Microsoft Corporation 2019/06/29 1.1811.10862.0
フォト Microsoft Corporation 2019/07/10 2019.19051.16210.0
ペイント 3D Microsoft Corporation 2019/06/29 5.1904.8017.0
ボイス レコーダー Microsoft Corporation 2019/06/29 10.1902.633.0
マップ Microsoft Corporation 2019/06/29 5.1902.843.0
メッセージング Microsoft Corporation 2019/06/29 4.1901.10241.1000
メール/カレンダー Microsoft Corporation 2019/07/10 16005.11629.20316.0
モバイル通信プラン Microsoft Corporation 2019/07/10 5.1906.1791.0
問い合わせ Microsoft Corporation 2019/06/28 10.1706.20381.0
天気 Microsoft Corporation 2019/07/21 4.31.11905.0
思い出フォトビューア 譚ア闃昴け繝ゥ繧、繧「繝ウ繝医た繝ェ繝・繝シ繧キ繝ァ繝ウ 譬ェ蠑丈シ夂、セ 2019/06/29 5.2.28.0
思い出フォトビューア クッキングプラス 譚ア闃昴け繝ゥ繧、繧「繝ウ繝医た繝ェ繝・繝シ繧キ繝ァ繝ウ 譬ェ蠑丈シ夂、セ 2019/06/29 2.2.24.0
日本語 ローカル エクスペリエンス パック Microsoft Corporation 2019/07/16 17134.36.51.0
映画 & テレビ Microsoft Corporation 2019/06/29 10.19031.11411.0
東芝スクリーンミラーリング for Windows PC/タブレット APUSONE Technology Inc. 2017/02/19 8.88 MB 1.1.17.9
楽しもう!Office ライフ Microsoft Corporation 2019/06/29 1.0.34.0
楽天gateway 讌ス螟ゥ譬ェ蠑丈シ夂、セ 2019/07/01 3.1.3.0
筆ぐるめ 24 富士ソフト株式会社 2017/02/19 1.48 GB 24.00.0103
電卓 Microsoft Corporation 2019/07/22 10.1905.30.0

よろしくお願いいたします。
  • sho
  • 2019/07/27 (Sat) 11:50:41
CCの追加ログもお願いします
作業と報告、ご苦労様です。
HJTログとインストール情報ログを見せてもらいましたが、こちらは今のところおかしなところは見えませんね。
残りのCCでの「スタートアップ」と「ブラウザプラグイン」の各ログも取り直したらそれも追加で見せてもらえますか。
2019/07/09 (Tue) 07:23:42のレスで見せてもらったログの取り直しです。

それと、「スケジュールされたタスク」タブで表示されたエントリを全部「無効」にしておいてください。
  • 悪代官
  • 2019/07/28 (Sun) 20:28:33
Re: プラウザが勝手に開かれます。
レスありがとうございます。

startup
有効 HKCU:Run CCleaner Smart Cleaning Piriform Software Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run OneDrive Microsoft Corporation "C:\Users\sho50\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
有効 HKLM:Run CLMLServer_For_P2G8 CyberLink "C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
有効 HKLM:Run SecurityHealth Microsoft Corporation %ProgramFiles%\Windows Defender\MSASCuiL.exe
有効 HKLM:Run TCrdMain Toshiba Client Solutions Co., Ltd. C:\Program Files\Toshiba\System Setting\TCrdMain_Win8.exe
有効 HKLM:Run TecoResident Toshiba Client Solutions Co., Ltd. C:\Program Files\TOSHIBA\Teco\TecoResident.exe
有効 HKLM:Run TosWaitSrv Toshiba Client Solutions Co., Ltd. %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
有効 HKLM:Run Trend Micro Client Framework Trend Micro Inc. "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe"
有効 HKLM:Run Trend Micro Titanium Trend Micro Inc. "C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe" -ReFlush "none" "none"
有効 HKLM:Run VizorHtmlDialog.exe Trend Micro Inc. "C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe" "DEF" "EULA" "C:\Program Files\Trend Micro\Titanium\www\Installer.cmpt\resources\common.lproj\preinstall_01_welcome_trial.html" -set Step Trial -set Skip 1

スケジュールされたタスク
有効 Task CCleanerSkipUAC Piriform Software Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7 Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe" --automatic
有効 Task IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7-Logon Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe" --automatic
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic
有効 Task OneDrive Standalone Update Task-S-1-5-21-1460922254-185261916-941432131-1001 Microsoft Corporation %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
有効 Task RTKCPL Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
有効 Task Service Station Toshiba Client Solutions Co., Ltd. "C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe" /hide
有効 Task TPIP Toshiba Client Solutions Co., Ltd. "C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe"

コンテキストメニュー
有効 Directory PowerShell ウィンドウをここに開く(S) powershell.exe -noexit -command Set-Location '%V'
有効 Directory ファイルの所有権
有効 Drive Lhaplus C:\Program Files (x86)\Lhaplus\LplsShlx64.dll
有効 Drive PowerShell ウィンドウをここに開く(S) powershell.exe -noexit -command Set-Location '%V'
有効 File Lhaplus C:\Program Files (x86)\Lhaplus\LplsShlx64.dll
有効 File MBAMShlExt Malwarebytes C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll
有効 File {48F45200-91E6-11CE-8A4F-0080C81A28D4} Trend Micro Inc. C:\Program Files\Trend Micro\UniClient\UiFrmwrk\tmdshell.dll
有効 Folder Lhaplus C:\Program Files (x86)\Lhaplus\LplsShlx64.dll
有効 Folder MBAMShlExt Malwarebytes C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll
有効 Folder {48F45200-91E6-11CE-8A4F-0080C81A28D4} Trend Micro Inc. C:\Program Files\Trend Micro\UniClient\UiFrmwrk\tmdshell.dll

Windowsサービス
有効 Service Cyberlink RichVideo64 Service(CRVS) CyberLink "C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
無効 Service Google Chrome Elevation Service Google LLC "C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\elevation_service.exe"
有効 Service Google Update サービス (gupdate) Google Inc. "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc
無効 Service Google Update サービス (gupdatem) Google Inc. "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc
有効 Service Intel Bluetooth Service C:\WINDOWS\system32\ibtsiva
無効 Service Intel(R) Capability Licensing Service TCP IP Interface Intel(R) Corporation "C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe"
有効 Service Intel(R) Content Protection HDCP Service Intel Corporation C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\IntelCpHDCPSvc.exe
無効 Service Intel(R) Content Protection HECI Service Intel Corporation C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\IntelCpHeciSvc.exe
有効 Service Intel(R) Dynamic Application Loader Host Interface Service Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
有効 Service Intel(R) HD Graphics Control Panel Service Intel Corporation C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_643b5570f4e39494\igfxCUIService.exe
有効 Service Intel(R) Management and Security Application Local Management Service Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
無効 Service Intel(R) Online Connect Intel Corporation "C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe"
有効 Service Intel(R) Online Connect Access Intel(R) Corporation "C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe"
有効 Service Intel(R) Online Connect Access Legacy CS Loader Intel(R) Corporation "C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe"
有効 Service Intel(R) Online Connect Helper Intel Corporation "C:\Program Files\Intel\Intel(R) Online Connect\iocHelperService.exe"
無効 Service Intel(R) Online Connect Software Asset Manager Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe"
有効 Service Intel(R) PROSet/Wireless Event Log Intel(R) Corporation "C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
有効 Service Intel(R) PROSet/Wireless Registry Service Intel(R) Corporation "C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
有効 Service Intel(R) PROSet/Wireless Zero Configuration Service Intel® Corporation "C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
無効 Service LLHDClient Intercom, Inc. "C:\Program Files (x86)\Intercom\LAPLINK HelpDesk Client\LLHDClient.exe"
有効 Service LLHDCloader Intercom, Inc. "C:\Program Files (x86)\Intercom\LAPLINK HelpDesk Client\LLHDCldr.exe"
有効 Service Malwarebytes Service Malwarebytes "C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe"
無効 Service Mozilla Maintenance Service Mozilla Foundation "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe"
有効 Service OEMRegistrationProgram Toshiba Client Solutions Co., Ltd. "C:\Program Files (x86)\Toshiba\OEM Registration Program\OEMRegistrationProgram.exe"
無効 Service OpenSSH Authentication Agent C:\WINDOWS\System32\OpenSSH\ssh-agent.exe
有効 Service Realtek Audio Service Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
有効 Service SMITS C:\Windows\SysWOW64\SMITSC.exe
有効 Service Synaptics FP WBF Policy Service Synaptics Incorporated C:\WINDOWS\system32\valWBFPolicyService.exe
有効 Service SynTPEnh Caller Service Synaptics Incorporated "C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
有効 Service TiMiniService Trend Micro Inc. "C:\Program Files\Trend Micro\Titanium\TiMiniService.exe"
有効 Service TMachInfo Toshiba Client Solutions Co., Ltd. "C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe"
有効 Service TOSHIBA eco Utility Service Toshiba Client Solutions Co., Ltd. "C:\Program Files\TOSHIBA\Teco\TecoService.exe"
有効 Service TOSRMService Toshiba Client Solutions Co., Ltd. "C:\Program Files (x86)\TOSHIBA\TOSHIBA System Driver\RMService.exe"
無効 Service TPCH Service Toshiba Client Solutions Co., Ltd. "C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe"
無効 Service Trend Micro Solution Platform Trend Micro Inc. "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 -ad -bt=60000
有効 Service TStationSrv Toshiba Client Solutions Co., Ltd. "C:\Program Files\TOSHIBA\TOSHIBA Service Station\TStationSrv.exe"
有効 Service TVコネクトスイート ダビングサービス sMedio Inc "C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingService.exe"
有効 Service Update Orchestrator Service
無効 Service Wireless PAN DHCP Server Intel Corporation "C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe"

ブラウザプラグイン(IE)
有効 Extension Lync Click to Call Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll
有効 Helper Skype for Business Browser Helper Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll

ブラウザプラグイン(FF)
有効 Extension Amazon.com.au 1.1 default-release Firefox 68.0.1
有効 Extension Bing 1.0 default-release Firefox 68.0.1
有効 Extension DuckDuckGo 1.0 default-release Firefox 68.0.1
有効 Extension Firefox Monitor 3.0 default-release Firefox 68.0.1 C:\Program Files\Mozilla Firefox\browser\features\fxmonitor@mozilla.org.xpi
有効 Extension Firefox Screenshots 39.0.0 Mozilla <screenshots-feedback@mozilla.com> default-release Firefox 68.0.1 C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi
有効 Extension Form Autofill 1.0 default-release Firefox 68.0.1 C:\Program Files\Mozilla Firefox\browser\features\formautofill@mozilla.org.xpi
有効 Extension Google 1.0 default-release Firefox 68.0.1
有効 Extension Twitter 1.0 default-release Firefox 68.0.1
有効 Extension Web Compat 4.3.2 default-release Firefox 68.0.1 C:\Program Files\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
無効 Extension WebCompat Reporter 1.1.0 Thomas Wisniewski <twisniewski@mozilla.com> default-release Firefox 68.0.1 C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi
有効 Extension Wikipedia (en) 1.0 default-release Firefox 68.0.1
有効 Extension Yahoo! JAPAN 1.0 default-release Firefox 68.0.1
有効 Extension ヤフオク! 1.2 default-release Firefox 68.0.1
有効 Extension 教えて!goo 1.0 default-release Firefox 68.0.1
有効 Extension 楽天市場 1.2 default-release Firefox 68.0.1
有効 Plugin 4.10.1440.18 Google Inc. default-release Firefox 68.0.1 C:\Users\sho50\AppData\Roaming\Mozilla\Firefox\Profiles\au2hd7rs.default-release\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll
有効 Plugin OpenH264 Video Codec 1.8.1 Mozilla Corporation default-release Firefox 68.0.1 C:\Users\sho50\AppData\Roaming\Mozilla\Firefox\Profiles\au2hd7rs.default-release\gmp-gmpopenh264\1.8.1\gmpopenh264.dll

ブラウザプラグイン(GC)
有効 App Gmail 8.2 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0
有効 App Google ドライブ 14.2 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.2_1
有効 App YouTube 4.2.8 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0
有効 Extension Google オフライン ドキュメント 1.7 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_0
有効 Extension スプレッドシート 1.2 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0
有効 Extension スライド 0.10 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0
有効 Extension ドキュメント 0.10 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1

よろしくお願いいたします。
  • sho
  • 2019/07/28 (Sun) 23:14:38
IEをリセットしましょう
作業と報告、ご苦労様です。

CCでの各タブログも見せてもらいました。

スケジュールのエントリは全部無効にされていると思いますがまだでしたら一応無効化しておくよう推奨です。

CCで「ブラウザプラグイン」タブのうち、下記の中で必要でないエントリは無効化推奨です。
>有効 Extension Amazon.com.au 1.1 default-release Firefox 68.0.1

>有効 Extension ヤフオク! 1.2 default-release Firefox 68.0.1

>有効 Extension 教えて!goo 1.0 default-release Firefox 68.0.1

>有効 Extension 楽天市場 1.2 default-release Firefox 68.0.1

>有効 Extension Google 1.0 default-release Firefox 68.0.1

>有効 Extension Twitter 1.0 default-release Firefox 68.0.1

>有効 Plugin 4.10.1440.18 Google Inc. default-release Firefox 68.0.1 C:\Users\sho50\AppData\Roaming\Mozilla\Firefox\Profiles\au2hd7rs.default-release\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll

次にIEも一度リセットしましょう。

インターネットオプションの「詳細設定」タブを開いて「リセットボタンを押すとIEが一度初期化されます。
この操作を行うとIEに不正に仕込まれた不審拡張や設定等が初期状態に修正可能になります。
全ての事例に有効な保証はありませんが感染を疑われる際はリセットも対処法のひとつです。

ここまでできたら一度PC再起動後、またブラウザ異常の有無を教えてください
  • 悪代官
  • 2019/07/29 (Mon) 08:27:54
Re: IEをリセットしましょう
悪代官様

ご連絡が大変遅くなり申し訳ありません。

ご指摘いただいた作業を実施いたしました。
IEタブが沢山出てきてはいませんが、URL入力欄がずっと点滅しております。(キーボードでどこか入力すると止まります)

FFでもそのような症状がありました。

よろしくお願い致します。
  • sho
  • 2019/08/12 (Mon) 21:08:03
Chromeでは起きませんか?
こんばんは。
またレスが遅れてごめんなさい。

>IEタブが沢山出てきてはいませんが、URL入力欄がずっと点滅しております。(キーボードでどこか入力すると止まります)

>FFでもそのような症状がありました。

IEとFFで出ているその症状ですが、Chromeでは出てないわけですか?
試しにFFでプライベートモード、IEでInPrivateモードで起動しても同じ症状か確認してみてください。

それと一応CCで各タブのログを取って、それも見せてもらえますか。
また現在ブラウザのスタートページに設定しているURLもレスに貼って見せてください。
念の為トップは「hxxp」と加工して直リン避けた状態で貼ってください。

URL欄点滅といってもマルウェアによる異常の恐れはまず薄いと思いますので、あまり不安がらずに確認をすすめてください。

ブラウザ上だけでなくメモ帳やOfficeの入力でも同様に点滅症状が出るとしたら考えられるのはキーボード不良ですかね。
自分もガタが来たキーボードやマウスを使っていてある日文字入力が反転したり1クリックで2度以上連打の反応が出たりの不具合もあったので、この場合は単純にキーボードやマウスの交換で解決しました。
  • 悪代官
  • 2019/08/13 (Tue) 20:37:52
Re: プラウザが勝手に開かれます。
こんばんは。
またしても遅くなり申し訳ございません。

Chromeでは症状が出ませんでした。
プライベートモードでFF、IEを起動したら症状は起こりませんでした。
(本日普通に開いたら症状は起こりませんでした)

IE
無効 Extension Lync Click to Call Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll
無効 Helper Skype for Business Browser Helper Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll

FF
有効 Extension Amazon.com.au 1.1 default-release Firefox 68.0.2
有効 Extension Bing 1.0 default-release Firefox 68.0.2
有効 Extension DuckDuckGo 1.0 default-release Firefox 68.0.2
有効 Extension Firefox Monitor 3.0 default-release Firefox 68.0.2 C:\Program Files\Mozilla Firefox\browser\features\fxmonitor@mozilla.org.xpi
有効 Extension Firefox Screenshots 39.0.0 Mozilla <screenshots-feedback@mozilla.com> default-release Firefox 68.0.2 C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi
有効 Extension Form Autofill 1.0 default-release Firefox 68.0.2 C:\Program Files\Mozilla Firefox\browser\features\formautofill@mozilla.org.xpi
有効 Extension Google 1.0 default-release Firefox 68.0.2
有効 Extension Twitter 1.0 default-release Firefox 68.0.2
有効 Extension Web Compat 5.0.2 default-release Firefox 68.0.2 C:\Users\sho50\AppData\Roaming\Mozilla\Firefox\Profiles\au2hd7rs.default-release\features\{87c05dbd-81df-4c14-9603-d43ab23de3e5}\webcompat@mozilla.org.xpi
無効 Extension WebCompat Reporter 1.1.0 Thomas Wisniewski <twisniewski@mozilla.com> default-release Firefox 68.0.2 C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi
有効 Extension Wikipedia (en) 1.0 default-release Firefox 68.0.2
有効 Extension Yahoo! JAPAN 1.0 default-release Firefox 68.0.2
有効 Extension ヤフオク! 1.2 default-release Firefox 68.0.2
有効 Extension 教えて!goo 1.0 default-release Firefox 68.0.2
有効 Extension 楽天市場 1.2 default-release Firefox 68.0.2
有効 Plugin 4.10.1440.18 Google Inc. default-release Firefox 68.0.2 C:\Users\sho50\AppData\Roaming\Mozilla\Firefox\Profiles\au2hd7rs.default-release\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll
有効 Plugin OpenH264 Video Codec 1.8.1 Mozilla Corporation default-release Firefox 68.0.2 C:\Users\sho50\AppData\Roaming\Mozilla\Firefox\Profiles\au2hd7rs.default-release\gmp-gmpopenh264\1.8.1\gmpopenh264.dll

GC
有効 App Gmail 8.2 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0
有効 App Google ドライブ 14.2 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.2_1
有効 App YouTube 4.2.8 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0
有効 Extension Google オフライン ドキュメント 1.7 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1
有効 Extension スプレッドシート 1.2 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0
有効 Extension スライド 0.10 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0
有効 Extension ドキュメント 0.10 ユーザー 1 C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1

IEのトップページ
http://www.msn.com/ja-jp/?cobrand=toshiba17win10.msn.com&ocid=TOSHIBADHP17&pc=TBTE

GCのトップページ
https://www.google.com/?gws_rd=ssl

すみません。FFのトップページのURLがどこで見るのかわかりませんでした・・・

よろしくお願いいたします。
  • sho
  • 2019/08/22 (Thu) 22:45:17
FFのご案内です
こんばんは、IVNOと申します。
悪代官さんに代わりましてご案内いたします。

ご案内と言っても、画像を添付したので見てくださいって内容です。
私でもCCのブラウザープラグインの項目の処置に関するご案内はできるのですが、そこは現状を把握なされている悪代官さんにお任せしたいと思いますので、正式な返答については今しばらくお待ちください。
ただ私が思うにその点滅と言うのは、恐らく東芝さんが提供しているシステムドライバが、最新のWindows 10に適合しておらず、不具合が生じた結果ではないかと思います。
ですので、東芝さんのサポートページから、現在ご利用の端末のアップデートファイルをダウンロード、インストールなされることをお勧めします。
具体的には、以下URLの手順でアップデートが可能です。
https://dynabook.com/assistpc/beginner/study/driver.htm
  • IVNO
  • 2019/08/23 (Fri) 01:18:49
Re: プラウザが勝手に開かれます。
IVNO様

ご対応ありがとうございます。
ご指摘いただいたようにアップデートをしました。

ありがとうございました。
  • sho
  • 2019/08/25 (Sun) 11:23:44
点滅は東芝のドライバー絡みでしたか
レスが遅くなってごめんなさい。

IVNOさん、フォローありがとうございます。
URL点滅は東芝のドライバー絡みでしたか。
その症状の情報は自分は知りませんでしたがおかげで助かりました。

shoさん、ドライバのアップデートされて件の症状も現在は解消しましたか?

FFのトップページURLもIVNOさんご案内の手順でCCから確認可能ですが、おそらくこれはもう異常とは関係ないでしょう。

IEのトップである下記ページもhttp://www.msn.com/ja-jp/?cobrand=toshiba17win10.msn.com&ocid=TOSHIBADHP17&pc=TBTE

東芝製PCの初期設定のはずなので、普通のmsnトップページに変更しておくといいでしょう。
https://www.msn.com/ja-jp

YahooとかGoogleとかのページをトップにしたければそれでもかまいませんが、一応注意しておくと検索に便利だからといってha○123や海外のおかしな検索エンジンをトップに設定するのは十分気を付けましょう。
GoogleやMicrosoftのURLを一文字二文字変えただけの偽サイトもありふれているのでそういった偽サイトにアクセスするだけでも危険はあります。

余談ですが世界的に評価が高い某社のセキュリティソフトではそのweb判定機能で当掲示板が警告対象になっています。
これはサーバーのfc2がいろんな事情で批判出ていたせいかもしれませんが、fc2の他サイトで警告が出ずウチのサイトだけが警告対象ならそれはひとえに管理人の人徳ゆえでしょう(爆

ではFFのトップページと、現時点での異常の有無だけ教えてください
  • 悪代官
  • 2019/08/25 (Sun) 20:42:43

返信フォーム






プレビュー (投稿前に内容を確認)