悪代官の伏魔殿掲示板
検索語:
OR  AND

HJTログ
△△のところには本名が入ります


Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 17:02:40, on 2015/09/03
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Users\△△\Downloads\DNS相談用\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll
O2 - BHO: Gravity Space - {8788dd2d-bed5-4071-8439-c822cef57bc8} - C:\Program Files (x86)\Gravity Space\Extensions\8788dd2d-bed5-4071-8439-c822cef57bc8.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll
O2 - BHO: Gem Grab - {f734cfd4-8a48-4098-be39-60e07e3cb01e} - C:\Program Files (x86)\Gem Grab\Extensions\f734cfd4-8a48-4098-be39-60e07e3cb01e.dll (file missing)
O4 - HKLM\..\Run: [RadioController] "C:\Program Files (x86)\RadioController\RfBtnHelper.exe" Start_Run
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - Global Startup: Acer Backup Manager Tray.lnk = C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {53F4962A-8E27-4601-8B01-79A82B4D7FC9} (LoadPrg Class) - https://member.gungho.jp/front/ro/iframe/LoadPrgAx.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{07523651-F710-46D7-84F6-5A1E5424D824}: NameServer = 199.203.131.150,82.163.143.168
O17 - HKLM\System\CCS\Services\Tcpip\..\{22D381DC-DC2B-46D5-A8B3-0477483A6B95}: NameServer = 199.203.131.150,82.163.143.168
O17 - HKLM\System\CCS\Services\Tcpip\..\{3941DFC1-A84E-497B-9C0B-517155D590D8}: NameServer = 199.203.131.150,82.163.143.168
O17 - HKLM\System\CCS\Services\Tcpip\..\{628A4FD7-6614-459E-87B0-4EC70966EC31}: NameServer = 199.203.131.150,82.163.143.168
O17 - HKLM\System\CCS\Services\Tcpip\..\{AB9550D2-3FB9-4925-B83D-8FD036869F5E}: NameServer = 199.203.131.150,82.163.143.168
O17 - HKLM\System\CS1\Services\Tcpip\..\{07523651-F710-46D7-84F6-5A1E5424D824}: NameServer = 199.203.131.150,82.163.143.168
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Qualcomm Atheros Commnucations - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe
O23 - Service: Broadcom Card Reader Service (BrcmCardReader) - Broadcom Corp. - C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe
O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Device Fast-lane Service (DeviceFastLaneService) - Acer Incorporated - C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NTI IScheduleSvc - NTI Corporation - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: Dritek RF Button Command Service (RfButtonDriverService) - Dritek System INC. - C:\Windows\RfBtnSvc64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Users\祐\Downloads\VM\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Wlan Agent - Atheros - C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe

--
End of file - 8557 bytes
  • 癒愛
  • 2015/09/03 (Thu) 17:18:41
CCログ
Acer Backup Manager NTI Corporation 2012/12/19 168 MB 4.0.0.0071
Acer Device Fast-lane Acer Incorporated 2012/12/19 2.43 MB 1.00.3011
Acer Device Fast-lane Acer Incorporated 2012/12/19 1.00.3011
Acer Instant Update Service Acer Incorporated 2012/12/19 9.32 MB 1.00.3013
Acer Power Management Acer Incorporated 2013/01/27 17.2 MB 7.00.3011
Acer Power Management Acer Incorporated 2013/01/27 7.00.3011
Acer Recovery Management Acer Incorporated 2013/01/27 9.84 MB 6.00.3012
AcerCloud Acer Incorporated 2013/01/27 2.01.3125
AcerCloud Acer Incorporated 2013/01/27 2.01.3125
AcerCloud Docs Acer Incorporated 2013/01/27 38.6 MB 1.00.3204
AcerCloud Docs Acer Incorporated 2013/01/27 1.00.3204
Broadcom Card Reader Driver Installer Broadcom Corporation 2013/01/27 3.20 MB 15.4.7.1
CCleaner Piriform 2015/09/03 5.09
clear.fi Media Acer Incorporated 2013/01/27 2.01.3112
clear.fi Media Acer Incorporated 2013/01/27 2.01.3112
clear.fi Photo Acer Incorporated 2013/01/27 2.01.3109
clear.fi Photo Acer Incorporated 2013/01/27 2.01.3109
CPUID HWMonitor 1.28 2015/07/27 2.89 MB
Craving Explorer Version 1.6.17 T-Craft 2015/04/17 23.1 MB 1.6.17.0
CyberLink MediaEspresso 6.5 CyberLink Corp. 2012/12/19 167 MB 6.5.3318_45364
ETDWare PS/2-X64 11.6.16.203_WHQL ELAN Microelectronic Corp. 2015/07/27 11.6.16.203
Identity Card Acer Incorporated 2012/12/19 1.83 MB 2.00.3004
Intel(R) Management Engine Components Intel Corporation 2015/04/17 8.1.0.1252
Intel(R) Processor Graphics Intel Corporation 2015/07/27 10.18.10.3958
Intel(R) Rapid Storage Technology Intel Corporation 2015/09/03 11.5.4.1001
Intel(R) SDK for OpenCL - CPU Only Runtime Package Intel Corporation 2015/07/27 2.0.0.37149
Java 8 Update 51 Oracle Corporation 2015/08/11 77.1 MB 8.0.510
Launch Manager Acer Inc. 2015/07/27 7.0.10
LINE LINE Corporation 2015/08/13 4.1.2.516
Live Updater Acer Incorporated 2012/12/19 3.44 MB 2.00.3006
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2013/01/27 4.84 MB 8.0.59193
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2013/01/27 13.2 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2015/04/17 13.1 MB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2013/01/27 10.2 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2013/01/27 10.1 MB 9.0.30729.4148
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2015/04/25 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2013/01/27 11.1 MB 10.0.40219
Mumble 1.2.8 Thorvald Natvig 2015/07/04 33.8 MB 1.2.8
MyWinLocker Suite Egis Technology Inc. 2012/12/19 6.32 MB 4.0.14.24
Qualcomm Atheros WLAN and Bluetooth Client Installation Program Qualcomm Atheros 2013/01/27 11.30
Ragnarok Gravity 2015/04/17 14.20.0000
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2015/07/27 6.0.1.6657
Recovery Management Acer Incorporated 2013/01/27 9.84 MB 6.00.3012
Revo Uninstaller 1.95 VS Revo Group 2015/07/27 1.95
Shared C Run-time for x64 McAfee 2012/12/19 2.78 MB 10.0.0
Skype(TM) 7.7 Skype Technologies S.A. 2015/08/05 74.2 MB 7.7.103
TeamSpeak 3 Client TeamSpeak Systems GmbH 2015/07/27 3.0.16
Update for Japanese Microsoft IME Postal Code Dictionary Microsoft Corporation 2015/07/28 7.60 MB 15.0.1759
Update for Japanese Microsoft IME Standard Dictionary Microsoft Corporation 2015/07/28 40.3 MB 15.0.1215
Update for Japanese Microsoft IME Standard Extended Dictionary Microsoft Corporation 2015/07/28 11.5 MB 15.0.1215
Visual Studio 2005 Tools for Office Second Edition Runtime Microsoft Corporation 2015/07/27
Visual Studio Tools for the Office system 3.0 Runtime Microsoft Corporation 2015/07/27
VMware Player VMware, Inc 2015/07/28 390 MB 5.0.4

お願いいたします
  • 癒愛
  • 2015/09/03 (Thu) 17:22:09
HPのログ。
Saved date: 2015/09/03 17:38:39
Files detected: 32
Files scanned: 10,472
Processes scanned: 129
Modules scanned: 811
ASEPs scanned: 524
Downloads scanned: 0
Deep analysis: 80/3
---------------------------------------------------------------------------------

Files

---------------------------------------------------------------------------------

File path: c:\program files (x86)\intel\bluetooth\obexsrv.exe
Publisher: Motorola Solutions, Inc.
Signer: Motorola Solutions Inc.
MD5: 96924b1d3060b0c0ffd77d01cb234d9f
SHA-1: 6d049a4753a5f7e981269a018c7b7c6684f6b7c7
Created: 2013/04/23 15:50:46
Detections: 2
Determination: Ignore detections (false positive)
- CMC Antivirus as Trojan.Win32.Krap.1!O (Undefined)
- Rising Antivirus as PE:Malware.XPACK-HIE/Heur!1.9C48 (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\intel\bluetooth\devmonsrv.exe
Publisher: Motorola Solutions, Inc.
Signer: Motorola Solutions Inc.
MD5: e7429ecd0c47cc065eeacf7e9d0e6341
SHA-1: be6a64d1aa51a0dd501024b385b65dcfffe1531d
Created: 2013/06/25 9:01:18
Detections: 1
Determination: Ignore detections (false positive)
- Rising Antivirus as PE:Malware.XPACK-HIE/Heur!1.9C48 (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\daemon tools lite\dtlite.exe
Publisher: DT Soft Ltd
Signer: DT Soft Ltd
MD5: cea0461aae4b8b6216f164501b1b5a10
SHA-1: 828d95418b13c3e5552545518b1ad2f5144603ec
Created: 2011/08/02 16:33:30
Detections: 1
Determination: Ignore detections (false positive)
- CMC Antivirus as Packed.Win32.TDSS.1!O

---------------------------------------------------------------------------------

File path: c:\program files (x86)\cyberlink\powerdvd10\pdvdlaunchpolicy.exe
Publisher: CyberLink Corp.
Signer: CyberLink Corp.
MD5: a6f41bf69b7648d3a545f08cb187378a
SHA-1: b2b07a455fdd1da15076540b8d07b215d4f858f0
Created: 2013/03/08 15:18:52
Detections: 1
Determination: Ignore detections (false positive)
- Bkav FE as HW32.Laneul (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\1423127\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\manifest.json
Publisher:
MD5: 14fd8b222a996bc5d2233516cd78a20c
SHA-1: 3819378d9055c65fab8ddcd1fbfab28a89844980
Created: 2014/08/09 2:35:55
Detections: 1
Determination: Adware
- Reason as PUP.Chrome.Extension (Adware)

---------------------------------------------------------------------------------

File path: c:\users\1423127\appdata\local\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\manifest.json
Publisher:
MD5: 93e34b017b195ac98aba32e64eede9f2
SHA-1: bfa2f63a3c2189cdb8696422f2fd9d4be2f2dbe5
Created: 2015/04/10 18:07:14
Detections: 1
Determination: Adware
- Reason as PUP.Chrome.Extension (Adware)

---------------------------------------------------------------------------------

File path: c:\users\1423127\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\manifest.json
Publisher:
MD5: 2d922aa30def0a058f85601f8acb5ce5
SHA-1: 62f069a274a987013c2c75ad46a4487355b0dea2
Created: 2014/08/09 2:35:52
Detections: 1
Determination: Adware
- Reason as PUP.Chrome.Extension (Adware)

---------------------------------------------------------------------------------

File path: c:\users\1423127\downloads\hijackthis.exe
Publisher: Trend Micro Inc.
MD5: 47811d50390a86a17102d7496e6eabb9
SHA-1: 2623749cdb27887f6746acdee7e8065475f8b541
Created: 2015/09/02 12:46:28
Detections: 2
Determination: Ignore detections (false positive)
- Kingsoft AntiVirus as Win32.HeurC.KVM099.a.(kcloud) (Undefined)
- Rising Antivirus as PE:Trojan.VBInject!1.6546 (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\1423127\downloads\otl.exe
Publisher: OldTimer Tools
MD5: 4adcfee16ee9978f06157634669d36fb
SHA-1: 30b37076552e49276836d02dd73d038c27dbbee9
Created: 2015/09/02 20:23:07
Detections: 2
Determination: Ignore detections (false positive)
- Agnitum Outpost as Packed/PECompact
- Bkav FE as HW32.CDB (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\1423127\downloads\rcsetup151.exe
Publisher: Piriform Ltd
Signer: Piriform Ltd
MD5: 3f9c12e62a0ae1d7a9dbb252195c4c54
SHA-1: 85c2e758dadb8a93064ca5cedf96bc69c021b84c
Created: 2015/02/04 8:38:35
Detections: 3
Determination: Ignore detections (false positive)
- Trend Micro House Call as TROJ_GEN.F47V0320 (Undefined)
- Vba32 AntiVirus as Malware-Cryptor.Win32.General.4 (Undefined)
- ESET NOD32 as Win32/Bundled.Toolbar.Google (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\1423127\desktop\vidplayasetup_v2.exe
Publisher: Playswell, Inc.
Signer: Playswell, Inc.
MD5: 0d5f3e3ff517f1df693ca90659287dc9
SHA-1: 08116ed0d69abafce96e411b9308bddef011f991
Created: 2014/12/30 0:14:37
Detections: 2
Determination: Inconclusive
- Dr.Web as Adware.OpenCandy.4 (Adware)
- ESET NOD32 as Win32/OpenCandy (variant) (Adware)

---------------------------------------------------------------------------------

File path: c:\users\1423127\desktop\xampp\apache\bin\iconv\iso-ir-150.so
Publisher:
MD5: f8a1a3069e3d53d56c4e96c47bb73056
SHA-1: 4694fe4cc05c1904a901afccefc89551a881d8d3
Created: 2015/06/04 9:51:58
Detections: 1
Determination: Ignore detections (false positive)
- Kingsoft AntiVirus as Win32.Troj.Generic.a.(kcloud) (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\1423127\desktop\xampp\mailtodisk\mailtodisk.exe
Publisher:
MD5: 8ce4bccf7757aaf4d5ce07cbb56b0eaa
SHA-1: f7b7f3ee16e1d5f48514e6a90def32a218d972dd
Created: 2015/06/04 9:52:21
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/Egress.c (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\1423127\desktop\xampp\mercurymail\ter32.dll
Publisher: Sub Systems, Inc.
MD5: d62747b06d2b09f25841544663dcac26
SHA-1: 4303e780c71133a0f525919cf04eaa268a04b065
Created: 2015/06/04 9:52:27
Detections: 1
Determination: Ignore detections (false positive)
- Emsisoft Anti-Malware as Win32.Worm.Mabezat.Gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\1423127\desktop\xampp\perl\bin\perl.exe
Publisher:
MD5: 6b407644fc8efe8e40cd644217af3aed
SHA-1: a1c7340cce304477d2b2521a408a3743e3bf6885
Created: 2015/06/04 9:54:38
Detections: 1
Determination: Ignore detections (false positive)
- Vba32 AntiVirus as Trojan.Menti.pfef (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\1423127\desktop\xampp\perl\bin\perl5.16.0.exe
Publisher:
MD5: 47fd5ef3813d2f6e4f4ab5dcc528c0be
SHA-1: a5c6171e8442639c4bd47e7b3ff3b041a3ec3f28
Created: 2015/06/04 9:54:38
Detections: 1
Determination: Ignore detections (false positive)
- Vba32 AntiVirus as Trojan.Menti (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\1423127\desktop\xampp\perl\bin\perl5.16.1.exe
Publisher:
MD5: 6b407644fc8efe8e40cd644217af3aed
SHA-1: a1c7340cce304477d2b2521a408a3743e3bf6885
Created: 2015/06/04 9:54:38
Detections: 1
Determination: Ignore detections (false positive)
- Vba32 AntiVirus as Trojan.Menti.pfef (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\1423127\desktop\xampp\php\extras\openssl\openssl.exe
Publisher:
MD5: 6303df50210416bbdb603b32e0f9e46a
SHA-1: 02235a921c2aac74fc9ac7c7e37692c4c56741cc
Created: 2015/06/04 9:56:03
Detections: 1
Determination: Ignore detections (false positive)
- Bkav FE as HW32.Stranact (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\1423127\desktop\xampp\webalizer\bgd.dll
Publisher:
MD5: 91f7bfe6bc3a80d592c518a5736fc82a
SHA-1: a560e916127da2060363ae80918bd48dca8d9d87
Created: 2015/06/04 9:57:06
Detections: 1
Determination: Ignore detections (false positive)
- Bkav FE as W32.HfsAutoB (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\syswow64\gamemon.des
Publisher: INCA Internet Co., Ltd.
Signer: INCA Internet Co.,Ltd.
MD5: 2b142e2c5619d9441fb288e84840e3de
SHA-1: 0cabdc979477f0b407f10328931cef110694b5e9
Created: 2014/04/11 20:51:44
Detections: 1
Determination: Ignore detections (false positive)
- Rising Antivirus as PE:Malware.XPACK/RDM!5.1

---------------------------------------------------------------------------------

File path: c:\users\1423127\appdata\roaming\iobit\iobit uninstaller\ppuninstallertemp.exe
Publisher:
Signer: IObit Information Technology
MD5: 28ca7d1bb9fbfca2b529d885e61491d8
SHA-1: 7bc41ba0c2fd59e62d8e5c677b4598b6540d8fb0
Created: 2015/02/13 13:27:11
Detections: 1
Determination: Ignore detections (false positive)
- G Data as Win32.Adware.iObit (Adware)

---------------------------------------------------------------------------------

File path: c:\users\1423127\appdata\roaming\iobit\iobit uninstaller\uninstalldisplaytemp.exe
Publisher:
Signer: IObit Information Technology
MD5: 781a75acfb56fc8349bebbdcc027a970
SHA-1: a8c62dbe24fdfa3d7ea003513a2f508a46748fa0
Created: 2015/02/13 13:27:10
Detections: 1
Determination: Ignore detections (false positive)
- G Data as Win32.Adware.iObit (Adware)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\arcsoft\showbiz\esinter.dll
Publisher: ArcSoft Inc.
Signer: ArcSoft, Inc.
MD5: f2f1cb8903f75ba12cc56072ed7bd924
SHA-1: 90e45a9b1b41df65748185d9e17eb4722a70872f
Created: 2012/02/17 14:51:40
Detections: 1
Determination: Ignore detections (false positive)
- Jiangmin as Win32/Virut.bn

---------------------------------------------------------------------------------

File path: c:\program files (x86)\arcsoft\showbiz\kgl.dll
Publisher: ArcSoft Inc.
Signer: ArcSoft, Inc.
MD5: a7d5ff243ee29edac48a66823544e85b
SHA-1: 29946f8df1834c68105ec7494ec17e29e6bc1280
Created: 2011/07/09 2:06:14
Detections: 1
Determination: Ignore detections (false positive)
- Jiangmin as Win32/Virut.bn

---------------------------------------------------------------------------------

File path: c:\program files (x86)\arcsoft\showbiz\magpcmac.dll
Publisher: ArcSoft Inc.
Signer: ArcSoft, Inc.
MD5: 0f927833b7871be85d7031ca98b8f943
SHA-1: edc65926a403832efcff190c0fc0d7a9f382cdf1
Created: 2011/06/27 14:07:52
Detections: 1
Determination: Ignore detections (false positive)
- Jiangmin as Win32/Virut.bn

---------------------------------------------------------------------------------

File path: c:\program files (x86)\arcsoft\showbiz\com.arcsoft.vea.arccodec\ascopp.dll
Publisher: ArcSoft, Inc.
Signer: ArcSoft, Inc.
MD5: 8e6c0ce1ce19649e9bfb25b8fa858c67
SHA-1: ba6b596872ed3380a275fb12d3eb0821d2b4028a
Created: 2011/08/02 16:50:50
Detections: 1
Determination: Ignore detections (false positive)
- Jiangmin as Trojan/Genome.meo (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\arcsoft\showbiz\com.arcsoft.vea.arccodec\asvidencpro.dll
Publisher: ArcSoft Inc.
Signer: ArcSoft, Inc.
MD5: c860aae9ab8b46c5734845c5a816204d
SHA-1: 95b236bff9a1a0dac6bce08ecd44adde24eac2a0
Created: 2011/11/15 8:33:36
Detections: 1
Determination: Ignore detections (false positive)
- ByteHero BDV as Trojan.Malware.Win32.xPack.i (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\arcsoft\totalmedia backup & record\esinter.dll
Publisher: ArcSoft Inc.
Signer: ArcSoft, Inc.
MD5: f2f1cb8903f75ba12cc56072ed7bd924
SHA-1: 90e45a9b1b41df65748185d9e17eb4722a70872f
Created: 2014/02/17 17:52:33
Detections: 1
Determination: Ignore detections (false positive)
- Jiangmin as Win32/Virut.bn

---------------------------------------------------------------------------------

File path: c:\program files (x86)\common files\adobe air\versions\1.0\resources\template.exe
Publisher:
MD5: dd73974e9e89b6b7a78c49e5f87b9376
SHA-1: 6f19b29cf79838f2cda90677212509397a2df817
Created: 2015/08/16 18:03:40
Detections: 1
Determination: Inconclusive
- Avira AntiVirus as W32/Sality.AT (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\cyberlink\powerdvd10\audiofilter\dolbyhph.dll
Publisher: Lake Technology Limited, http://www.lake.com.au
MD5: 442b5be8aa79b0496c5d0234b78e20ce
SHA-1: 9956235bf6fe3a3220c73a84c8f57c951226655a
Created: 2013/04/16 11:39:14
Detections: 1
Determination: Ignore detections (false positive)
- Bkav FE as HW32.CDB (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\daemon tools lite\lang\sky.dll
Publisher:
MD5: bbcb4687f9d735db1999e4e3541c2561
SHA-1: a71d65a11fee8ce786f07640035dd619a16e226a
Created: 2011/08/02 16:32:52
Detections: 1
Determination: Ignore detections (false positive)
- Bkav FE as HW32.Stranfom (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\daemon tools lite\lang\slv.dll
Publisher:
MD5: 0c6d4a502a4a7da18b170d80711ba345
SHA-1: a18505b6a3774e991554d184176dd21773bf6b33
Created: 2011/08/02 16:32:52
Detections: 1
Determination: Ignore detections (false positive)
- Bkav FE as HW32.Stranfom (Undefined)

HPはポータブル版でスキャンしました。
  • odn
  • 2015/09/03 (Thu) 17:40:26
別途セキュリティソフトはご用意なされたほうが良いでしょう
こんばんは、IVNOと申します。
ログを拝見したところ確かにDNS Unlokerには感染しているようですが、
それ以外にも感染しているのが若干見えています。
それらの処置も含めてやっていきましょう。
それと、Windows Defenderは全セキュリティソフト中最低性能であり、
ないよりかはマシという程度の性能しかありません。
できれば有償セキュリティをご検討いただければと思います。
ただし、更新料無料を謳うセキュリティソフトは性能的にWindows Defenderと大差ないので、
それ以外のものをご検討なされたほうが良いです。

それでは作業準備を行いましょう。

まずはじめに連絡事項がございます。
相談いただいてから回答できるまでに、毎回1日かそれ以上かかる可能性もございます。
ご不便をおかけいたしますが、ご理解とご協力を賜りますよう、お願い申し上げます。
また、回答者側から「解決」と通達があるまで、駆除作業は続いております。
そのため、途中でPCの状況が良くなったかのように感じたからと言って、解決のご案内を待たずして作業を中断なされると、
高確率で再発しているのが現状で、再発時にこちらにお戻りになられる方が続出しております。
回答者から「解決」と「自衛策」の案内があるまでは、作業を続けるようにしてください。

それでは以下の説明を熟読し、順番に作業をお願いします。
既に準備した物もあるはずですが、一応説明を再度見ておいてください。

隠しファイルと拡張子を表示設定にしてください(やり方↓)
http://pasofaq.jp/windows/mycomputer/hiddenfile.htm
http://support.microsoft.com/kb/978449/ja

下記のツールをダウンロードして、基本の使い方を把握しておいてください。
ただし、配布サイトで他のソフトウェアをダウンロードしろと勧めてくるような広告も出てくる可能性がありますが、
それらは絶対にクリックしないでください。

GeekUninstaller(通称:GU)
ダウンロード
http://www.geekuninstaller.com/geek.zip
ファイル直リンクです。zipファイルですので使用前に展開してください。
削除の際はそのままごみ箱に処分してください。
解説
http://www.gigafree.net/system/install/geekuninstaller.html

「CCleaner」(通称:CC)
説明↓
http://www.gigafree.net/system/clean/ccleaner.html
http://note.chiebukuro.yahoo.co.jp/detail/n178757
ダウンロード↓
http://www.piriform.com/ccleaner/download/standard
最新バージョンをダウンロードするようにしましょう。
なお、インストール時におまけのアプリも勧めてくることがありますが、それらはチェック外してインストールは避けてください。
削除の際はGUなどでアンインストールしてください。

ここで重要な注意です。
CCは本来は高い性能を持つメンテナンスソフトですが、間違った使い方すると
【操作次第ではWindowsが動作しなくなる可能性もある】
ので、ここでは解析ツールとしてのみ使います。
説明をしっかり読んで、こちらが指示した以外の操作はしないようにしてください。

準備できたら作業を開始しましょう。

まずは以下URLの「Javaアンインストール・ツール」と言う文字をクリックし、
最新バージョンの確認と旧バージョンの削除を行われてください。
https://java.com/ja/download/faq/remove_olderversions.xml
条項に同意しますのボタンを押して数十秒程度お待ちいただくとJavaが起動します。
Javaが旧バージョンである場合はそのまま最新バージョンのダウンロードページに移動します。
Javaが最新バージョンの場合は旧バージョンの削除画面が出現しますので、指示に従って旧バージョンを削除してください。

以降の駆除作業でトラブルが発生しても直ちに復旧できるよう、システムの復元ポイントを手動で作成しましょう。
http://windows.microsoft.com/ja-jp/windows7/create-a-restore-point
しかし、システムの復元はPCにかなりのダメージを与えますので、できれば使わないほうが望ましいです。
システムの復元が必要のない、慎重な作業を心がけましょう。

PCをセーフモードで起動してください(やり方↓)
http://www.pc-master.jp/sousa/s-safemode.html
Windows 8または8.1の方は以下を参考になされてください。
http://121ware.com/qasearch/1007/app/servlet/relatedqa?QID=015917
HJTを起動させ、スキャンを行ってください。
スキャン結果が表示されましたら、以下の項目にチェックを入れてください。
ただし、特にHJTでの作業は一歩間違えれば簡単にPCが起動しなくなるため、
こちらが指示した以外のものは絶対にチェックを入れないでください。

O2 - BHO: Gem Grab - {f734cfd4-8a48-4098-be39-60e07e3cb01e} - C:\Program Files (x86)\Gem Grab\Extensions\f734cfd4-8a48-4098-be39-60e07e3cb01e.dll (file missing)
O17 - HKLM\System\CCS\Services\Tcpip\..\{07523651-F710-46D7-84F6-5A1E5424D824}: NameServer = 199.203.131.150,82.163.143.168
O17 - HKLM\System\CCS\Services\Tcpip\..\{22D381DC-DC2B-46D5-A8B3-0477483A6B95}: NameServer = 199.203.131.150,82.163.143.168
O17 - HKLM\System\CCS\Services\Tcpip\..\{3941DFC1-A84E-497B-9C0B-517155D590D8}: NameServer = 199.203.131.150,82.163.143.168
O17 - HKLM\System\CCS\Services\Tcpip\..\{628A4FD7-6614-459E-87B0-4EC70966EC31}: NameServer = 199.203.131.150,82.163.143.168
O17 - HKLM\System\CCS\Services\Tcpip\..\{AB9550D2-3FB9-4925-B83D-8FD036869F5E}: NameServer = 199.203.131.150,82.163.143.168
O17 - HKLM\System\CS1\Services\Tcpip\..\{07523651-F710-46D7-84F6-5A1E5424D824}: NameServer = 199.203.131.150,82.163.143.168

必要な項目すべてにチェックが入りましたら、Fix checkedをクリックしてください。
上記のFixが完了したら、GUを起動させ、以下を削除してください。

Craving Explorer Version 1.6.17 T-Craft 2015/04/17 23.1 MB 1.6.17.0

GU上に表示されているソフトウェアをダブルクリックで削除できます。
削除が完了したら自動的にスキャンが始まりますので、検出されたごみすべてにチェックを入れてOKを押してください。
GUでのアンインストールが完了しましたらGUを終了させてください。
Windowsインストーラーがどうとかの表示が出た場合はPCを通常モードで再起動し、
その状態で改めて該当ソフトウェアのみをアンインストールしてください。
通常モードとセーフモードを使い分けながらご案内しているすべてのソフトウェアの削除が完了するまで続けてください。
ご案内していたすべてのソフトウェアの削除が完了しましたら、
キーボードの左Ctrlと左Altの間にあるスタートボタンを押しながらRボタンを押します。
ファイル名を指定して実行と言うものが起動しますので、そちらに半角英数で以下を入力してください。

cleanmgr

入力が完了しましたらエンターキーを押してください。
C:ドライブを選択してOKを押します。
スキャンが開始されますので完了するまでお待ちください。
スキャンが完了すると一覧が表示されますので、すべてにチェックを入れてOKを押してください。
ただし、OKを押すとごみ箱の中身を含めてすべて削除されますので、
ごみ箱の中に必要なファイルが入っている場合はご注意ください。

処置が完了しましたらPCを通常モードで再起動させてください。
PCが通常モードで起動したらCCを起動し、「ツール」→「スタートアップ」→「Windows」タブを開いてください。
そこで右下の「テキストとして保存」を押すと、表示の内容がログとして保存できますので、
デスクトップ等、分かりやすい場所に最新のログのみ保存しておきましょう。
続いて「InternetExplorer」タブのログ、導入されておられるのであれば「Firefox」タブ、
同じく導入されておられるのであれば「Google Chrome」タブ、そして「スケジュールされたタスク」タブのログを取得してください。
ただし、「コンテキストメニュー」のログは取得していただく必要がございません。
CCの各ログを取得されましたら、CCは終了させて問題ありません。
取得したCCの各ログを返信欄に貼り付けていただき、ご報告をお願いいたします。
上記ログを確認後、次の作業内容をご案内いたします。
  • IVNO
  • 2015/09/03 (Thu) 17:47:46
Re: DNS Unlockerに感染しました
【HJTのログ】
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 17:31:07, on 2015/09/03
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)


Boot mode: Normal

Running processes:
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
D:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
E:\Users\Owner\Downloads\HijackThis.exe
C:\PROGRA~2\Raptr\raptr_im.exe
D:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Windows\SysWOW64\DllHost.exe

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe" 60
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Raptr] C:\PROGRA~2\Raptr\raptrstub.exe --startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_721577D41E77D440C916E2687EBA0267] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [Steam] "D:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - Global Startup: SteelSeries Engine 3.lnk = C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://D:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - D:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7072 bytes


【CCのログ】
7-Zip 9.20 (x64 edition) Igor Pavlov 2015/08/18 4.44 MB 9.20.00.0
AMD Catalyst Install Manager Advanced Micro Devices, Inc. 2015/08/13 33.5 MB 8.0.916.0
Battlefield 4™ Electronic Arts 2015/08/13 28.1 GB 1.4.2.30944
Battlelog Web Plugins EA Digital Illusions CE AB 2015/08/13 2.7.1
CCleaner Piriform 2015/09/03 5.09
DEFCON Introversion Software 2015/08/22
Don't Starve Klei Entertainment 2015/08/21
Fallout 3 - Game of the Year Edition Bethesda Game Studios 2015/08/15
Fallout 3 - Unofficial Fallout 3 Patch Quarn (quarny@gmail.com) 2015/08/15 v1.2.0
Google Chrome Google Inc. 2015/08/13 44.0.2403.157
Grand Theft Auto V Rockstar North 2015/08/13
Intel(R) Management Engine Components Intel Corporation 2015/08/13 10.0.0.1204
Intel(R) Network Connections 19.0.27.0 Intel 2015/08/13 29.8 MB 19.0.27.0
Intel(R) Processor Graphics Intel Corporation 2014/01/29 10.18.10.3412
Intel(R) Rapid Storage Technology Intel Corporation 2015/08/13 13.0.3.1001
Java 8 Update 60 Oracle Corporation 2015/09/03 20.6 MB 8.0.600.27
LINE LINE Corporation 2015/09/02 4.1.2.525
Malwarebytes Anti-Malware version 1.75.0.1300 Malwarebytes Corporation 2015/09/03 19.3 MB 1.75.0.1300
Microsoft Games for Windows - LIVE Redistributable Microsoft Corporation 2015/08/15 32.7 MB 3.5.92.0
Microsoft Games for Windows Marketplace Microsoft Corporation 2015/08/15 6.03 MB 3.5.67.0
Microsoft Office File Validation Add-In Microsoft Corporation 2015/09/03 7.91 MB 14.0.5130.5003
Microsoft Office Personal 2007 Microsoft Corporation 2015/09/01 12.0.6612.1000
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2015/09/01 4.84 MB 8.0.61001
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2015/08/13 10.2 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2015/09/01 8.78 MB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2015/08/27 15.2 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2015/08/27 12.2 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Corporation 2015/08/13 20.5 MB 11.0.61030.0
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 2015/08/13 17.3 MB 11.0.61030.0
Minecraft Mojang 2015/08/23 1.22 MB 1.0.3.0
Origin Electronic Arts, Inc. 2015/08/13 9.7.2.53208
PunkBuster Services Even Balance, Inc. 2015/08/13 0.993
Python 2.7.9 Python Software Foundation 2015/08/16 56.7 MB 2.7.9150
Raptr 2015/08/13
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2015/08/13 6.0.1.7213
Rockstar Games Social Club Rockstar Games 2015/08/29 1.1.6.5
SoundEngine Free Coderium 2015/08/31 5.2.1.1
Steam Valve Corporation 2015/08/13 2.10.91.91
SteelSeries Engine 3.4.3 SteelSeries ApS 2015/08/23 3.4.3
Tomb Raider Crystal Dynamics 2015/08/21
Update for Japanese Microsoft IME Postal Code Dictionary Microsoft Corporation 2015/08/14 7.60 MB 16.0.1171.1
Update for Japanese Microsoft IME Standard Dictionary Microsoft Corporation 2015/08/14 40.3 MB 16.0.1404.1
Update for Japanese Microsoft IME Standard Extended Dictionary Microsoft Corporation 2015/08/14 11.5 MB 15.0.1215
Update for Japanese Microsoft IME Trending Words Dictionary Microsoft Corporation 2015/08/14 9.00 KB 16.0.1515.1
WinRAR 5.01 (64ビット) win.rar GmbH 2015/08/13 5.01.0
  • TES
  • 2015/09/03 (Thu) 18:22:18