悪代官の伏魔殿掲示板
駆除
初めまして、悪代官様。先日知恵袋にて質問にお答え頂いたryoyoungです。ログの英語を見ただけで、こりゃ無理だと、簡単にリカバリーディスクで復旧しようと思っていましたが、それもまた大変だと教えていただき、駆除に挑戦してみたいと思いますので、お忙しいところ、よろしくお願いします。それではログを貼り付けてみますので間違っていたらお知らせください。Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:03:18, on 2014/02/08
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16750)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Baidu\IME\3.5.1.16\BaiduIME.exe
C:\Program Files (x86)\Baidu\IME\3.5.1.16\BaiduPlatform.exe
C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5GC.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe
C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SysMon.Exe
C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\オヤジ\Downloads\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: K7 Web Protection - {08B3B4B6-02DA-4658-8BA6-5974E3EBB03D} - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
O2 - BHO: ifp5toolbar - {0FAF6F52-1AD4-4282-9EA1-3EC884DA7AA3} - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5toolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.7.0_09\bin\ssv.dll
O2 - BHO: Microsoft アカウント サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ViewPassword - {949b3815-2809-4571-9ed9-ce9a1df53914} - C:\Program Files (x86)\ViewPassword\150.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.7.0_09\bin\jp2ssv.dll
O2 - BHO: DVDVideoSoft.WebPageAdjuster - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [iFilter5] "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5GC.exe" /autorun
O4 - HKLM\..\Run: [K7TSStart] C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
O4 - HKLM\..\Run: [K7SystemTray] "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [LPStation] C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
O4 - HKLM\..\Run: [mtvManager] C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvManager.exe /startup
O4 - HKCU\..\Run: [PC Speed Maximizer] C:\Program Files (x86)\PC Speed Maximizer\SPMLauncher.exe
O4 - Global Startup: Continue installation.lnk = ?
O4 - Global Startup: PHOTOfunSTUDIO 5.0 HD Edition.lnk = C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
O4 - Global Startup: クライアントマネージャV.lnk = C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
O8 - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: OneNote に送る(&N) - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: OneNote に送る - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: OneNote に送る(&N) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O9 - Extra 'Tools' menuitem: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} (DMM Downloader) - http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab
O16 - DPF: {4845B7A7-309F-49F4-A2DD-0117707B6E8D} (DVD Toaster ActiveX Control) - https://toast.dvdtoaster.jp/downloads/activex/x86/dvdtoast.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Baidu Japanese IME Service_3.5.1.16 (BaiduJP_IME_Service_3.5.1.16) - Baidu Inc. - C:\Program Files (x86)\Baidu\IME\3.5.1.16\BaiduJPServ.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: Bonjour サービス (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: BWH32S - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
O23 - Service: EzDetector - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: i-フィルター 5.0 Main (IFP5MainService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
O23 - Service: i-フィルター 5.0 Support (IFP5WatchService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: K7Carnivore Service (K7CrvSvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe
O23 - Service: K7Computng - EMail Proxy Server (K7EmlPxy) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7EmlPxy.exe
O23 - Service: K7Firewall Services (K7FWSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7FWSrvc.exe
O23 - Service: K7Privacy Services (K7PSSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7PSSrvc.exe
O23 - Service: K7RealTime AntiVirus Services (K7RTScan) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7RTScan.exe
O23 - Service: K7SpmSrc - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SpmSrc.exe
O23 - Service: K7TotalSecurity Manager (K7TSMngr) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSMngr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: LISMO PIM Service - CASIO SOFT CO. LTD. - C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: I-O DATA mAgicTV Digital (mAgicTVDigital) - I-O DATA DEVICE, INC. - C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NlsSrv32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SD Device Manager - Panasonic Corporation - C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: SonicStage Back-End Service2 - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14786 bytes
Access Help Lenovo 2011/02/09 3.00
Adobe Flash Player 12 ActiveX Adobe Systems Incorporated 2014/02/07 6.00 MB 12.0.0.44
Adobe Reader 9.1 - Japanese Adobe Systems Incorporated 2011/02/09 256 MB 9.1.0
Apple Application Support Apple Inc. 2013/10/01 64.0 MB 2.3.6
Apple Mobile Device Support Apple Inc. 2013/10/01 25.0 MB 7.0.0.117
au ISW11K USB Driver 京セラ株式会社 2012/03/01 1.00.0000
au T008 USB Driver Ver.5.0.0.1 2011/09/24 V5.24.1.0
Baidu IME 3.5 Baidu Japan Inc. 2013/12/13 3.5
Bonjour Apple Inc. 2014/02/03 3.29 MB 1.0.106
BUFFALO エアステーション設定ツール BUFFALO INC. 2011/09/25 2.84 MB 2.0.5
BUFFALO クライアントマネージャV BUFFALO INC. 2011/09/25
BUFFALO パソコン環境表示ツール BUFFALO INC. 2011/09/25 1.0.3
Corel DVD MovieWriter Lenovo Edition Corel Corporation 2011/02/09 320 MB 7.0.0
Corel TVX Corel Corporation 2014/02/03 31.2 MB 2.2-B0.5
Create Recovery Media Lenovo Group Limited 2011/02/09 9.50 MB 1.20.0.00
DVD Decrypter (Remove Only) 2011/02/18
DVD Flick 1.3.0.7 Dennis Meuwissen 2012/05/05 1.3.0.7
DVD Shrink 3.2 DVD Shrink 2011/02/18
EPSONプリンタドライバ・ユーティリティ SEIKO EPSON Corporation 2012/02/25
Free YouTube Download version 3.2.13.925 DVDVideoSoft Ltd. 2013/10/01 101 MB 3.2.13.925
I-O DATA mAgicTV Digital I-O DATA DEVICE,INC. 2014/02/03 1.01.00
i-フィルター 5.0 Digital Arts 2011/02/16 5.00.12.0108
IL Download Manager Image-Line 2011/11/05
Intel(R) Control Center Intel Corporation 2011/02/09 1.2.1.1007
Intel(R) Graphics Media Accelerator Driver Intel Corporation 2011/02/09 8.15.10.2125
Intel(R) Management Engine Components Intel Corporation 2011/02/09 6.0.0.1179
InterVideo WinDVD 8 InterVideo Inc. 2011/02/09 163 MB 8.0.20.199
Java 7 Update 9 Oracle 2013/03/10 130 MB 7.0.90
Java(TM) 6 Update 29 Oracle 2012/03/02 97.0 MB 6.0.290
Jw_cad 2014/01/29
Lenovo Auto Scroll Utility 2011/02/09 1.00
Lenovo Patch Utility Lenovo Group Limited 2013/05/12 1.33 MB 1.3.1.1
Lenovo Patch Utility 64 bit Lenovo Group Limited 2013/05/12 1.35 MB 1.3.1.1
Lenovo System Interface Driver 2013/05/12 1.05
Lenovo System Update Lenovo 2013/07/16 13.4 MB 5.02.0018
Lenovo ThinkVantage Toolbox PC-Doctor, Inc. 2011/02/09 6.0.5717.21
Lenovo Warranty Information Lenovo 2011/02/09 893 KB 1.0.0004.00
Lenovo Welcome Lenovo 2011/02/09
LISMO Port 5.1 Sony Corporation 2013/03/10 110 MB 5.1
Message Center Plus Lenovo Group Limited 2011/02/09 1.70 MB 2.0.0012.00
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 2011/02/27 38.8 MB 4.0.30319
Microsoft Office Home and Business 2010 Microsoft Corporation 2013/11/03 14.0.7015.1000
Microsoft Office Word Viewer 2003 Microsoft Corporation 2014/01/16 105 MB 11.0.8173.0
Microsoft Silverlight Microsoft Corporation 2013/10/10 149 MB 5.1.20913.0
Microsoft SkyDrive Microsoft Corporation 2013/01/15 25.1 MB 16.4.6013.0910
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2011/02/09 1.69 MB 3.1.0000
Microsoft SQL Server Compact 3.5 SP1 English Microsoft Corporation 2011/02/28 2.59 MB 3.5.5692.0
Microsoft SQL Server Compact 3.5 SP1 x64 English Microsoft Corporation 2011/02/28 3.69 MB 3.5.5692.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 Microsoft Corporation 2011/02/26 260 KB 8.0.50727.4053
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 2011/02/26 250 KB 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2014/02/03 2.38 MB 8.0.59193
Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 2011/02/09 840 KB 8.0.61000
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2013/10/01 248 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2011/02/16 784 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 2011/06/20 788 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2011/03/17 234 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2011/02/16 592 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2011/06/20 600 KB 9.0.30729.6161
Mobile Broadband Lenovo 2011/02/09 16.4 MB 3.6.0034
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2011/02/18 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2011/02/18 1.33 MB 4.20.9876.0
PHOTOfunSTUDIO 5.0 HD Edition Panasonic Corporation 2011/02/28 5.00.313
QuickTime Apple Inc. 2012/11/07 73.2 MB 7.72.80.56
Registry Patch to arrange icons in Device and Printers folder of Windows 7 2011/02/09 1.00
Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7 2011/02/09 1.00
Rescue and Recovery Lenovo Group Limited 2013/05/12 101 MB 4.31.0005.00
SAMSUNG USB Driver for Mobile Phones SAMSUNG Electronics Co., Ltd. 2013/08/07 42.9 MB 1.5.16.0
SonicStage 4.4 Sony Corporation 2012/02/15 4.4
Sony Media Library Earth 8.1.00 Sony Corporation 2013/03/10 47.3 MB 8.1.00.11292
ThinkPad Power Management Driver 2011/02/09 1.60.0.4
ThinkPad UltraNav Driver 2011/02/16 46.4 MB 15.0.18.0
ThinkPad Wireless LAN Adapter Software REALTEK Semiconductor Corp. 2011/02/09 1.00.0024.0
ThinkPad 省電力マネージャー 2011/02/09 3.30
ThinkVantage Communications Utility Lenovo 2011/02/09 2.43 MB 1.41
ThinkVantage ハードディスク・アクティブプロテクション・システム Lenovo 2011/02/09 15.6 MB 1.74
USB Video/Audio Device Driver 会社名 2012/07/29 15.4 MB 1.00.0000
ViewPassword ViewPassword Software 2014/01/29
Windows Live Essentials Microsoft Corporation 2013/01/15 16.4.3505.0912
Windows ドライバ パッケージ - I-O DATA DEVICE, INC. GV-MVP/FZ(x64) (11/29/2010 1.8.2.12) I-O DATA DEVICE, INC. 2014/02/03 11/29/2010 1.8.2.12
Windows ドライバ パッケージ - Intel (iaStor) hdc (01/15/2010 9.5.7.1002) Intel 2011/02/09 01/15/2010 9.5.7.1002
Windows ドライバ パッケージ - Intel hdc (06/04/2009 7.0.0.1013) Intel 2011/02/09 06/04/2009 7.0.0.1013
Windows ドライバ パッケージ - Intel System (06/04/2009 1.0.0.0002) Intel 2011/02/09 06/04/2009 1.0.0.0002
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/09 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/10 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel USB (08/20/2009 9.1.1.1020) Intel 2011/02/09 08/20/2009 9.1.1.1020
Windows ドライバ パッケージ - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4) Lenovo 2011/02/09 11/18/2009 1.60.0.4
Windows ドライバ パッケージ - Realtek Semiconductor Corp. HD Audio Driver (06/29/2010 6.0.1.6146) Realtek Semiconductor Corp. 2011/02/09 06/29/2010 6.0.1.6146
インテル(R) ターボ・ブースト・テクノロジー・モニター インテル 2011/02/09 1.13 MB 1.0.186.3
ウイルスセキュリティ ソースネクスト株式会社 2012/09/18 12.00
以上よろしくお願いします。
  • ryoyoung
  • MAIL
  • 2014/02/08 (Sat) 13:53:10
駆除がんばりましょう
実はその書き込みを行ったのは私です。
こんにちは。gimp2.6と申します。

早速ではありますが、作業に入ってゆきましょう。

以下当掲示板の管理人さんの記述のコピペとなります。

------コピペここから------
作業前に最初にお伝えしておきます。
見てのとおり現在相談者さん多数のため、相談受けてから皆さんに順番にレスできるまで、毎回1日かそれ以上かかる可能性もあるので、すみませんがご了承ください。

では以下の説明をよく見てから、順番に作業をお願いします。
既に準備した物もあるはずですが、一応説明を再度見ておいてください。

隠しファイルと拡張子を表示設定にしてください(やり方↓)
http://pasofaq.jp/windows/mycomputer/hiddenfile.htm
http://support.microsoft.com/kb/978449/ja

下記のツールをダウンロードして、基本の使い方を把握しておいてください。
ただし、配布サイトで他のアプリをダウンロードしろと勧めてくるような広告も出てきたらそれらは絶対にクリックしないでください。
「ATF-Cleaner」(通称:ATF)
説明↓
http://freesoft.tvbok.com/freesoft/pc_system/atf-cleaner.html
ダウンロード↓
http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25
中央の赤い文字がダウンロードリンクです。
片付けるときはファイルを直接削除してください。
説明ページではWindowsXpと2000対応と書かれてますが、Win7やVistaにも対応です。

Iobit Uninstaller(通称・IU)
公式ページ↓
http://jp.iobit.com/free/iou.html
解説↓
http://milksizegene.blog.fc2.com/blog-entry-282.html
片付けのときはコントロールパネルからアンインストールですが、ポータブル版をお使いの場合はフォルダごと削除してください。

「CCleaner」(通称:CC)
説明↓
http://www.gigafree.net/system/clean/ccleaner.html
http://note.chiebukuro.yahoo.co.jp/detail/n178757
ダウンロード↓
http://www.piriform.com/ccleaner/download/standard
最新バージョンをダウンロードしてください。なお、インストール時におまけのアプリも勧めてくることがありますが、それらはチェック外してインストールは避けてください。
片付けるときはアンインストールしてください。

ここで重要な注意です。
CCは本来は高い性能を持つメンテナンスソフトですが、間違った使い方すると
【Windowsにダメージを与えてしまうおそれもある】
ので、ここでは解析ツールとしてのみ使います。
説明をしっかり読んで、自分が指示した以外の操作はしないように。

「AdwCleaner」(通称:AC)
http://www.bleepingcomputer.com/download/adwcleaner/dl/125/
ファイル直リンです。アクセスしてファイルをデスクトップにでも保存しておいてください。
片付けるときは起動後に「uninstall」ボタンを押せば自動で削除されます。

準備できたら作業開始です。
------コピペここまで------

以下は問題のあると思われるものです。

PCをセーフモードで起動してください(やり方↓)
http://www.pc-master.jp/sousa/s-safemode.html
まず、IUを利用して以下のソフトウェアをアンインストールしてください。
Baidu IME 3.5 Baidu Japan Inc. 2013/12/13 3.5
Free YouTube Download version 3.2.13.925 DVDVideoSoft Ltd. 2013/10/01 101 MB 3.2.13.925
Java(TM) 6 Update 29 Oracle 2012/03/02 97.0 MB 6.0.290
ViewPassword ViewPassword Software 2014/01/29
IU起動して、該当のアプリを選択して、アンインストール→パワースキャンの順にスキャンして、
残骸ファイル、レジストリも表示されたらそれにチェックして削除です。
なお、IUは削除後ごくまれに異常が出ることもあるので、
もし異常があればWindows標準のシステムの復元で、削除時の復元ポイントに戻してください。

以下1エントリはマルウェアです。
O4 - HKCU\..\Run: [PC Speed Maximizer] C:\Program Files (x86)\PC Speed Maximizer\SPMLauncher.exe
HJTを起動して、スキャン後表示された中の下記エントリをfixしてください。
対象エントリ左の「□」内にチェックして、下部の「Fix checked」を押せばfixされます。
この直後HJT画面が初期化されるので、そこでHJTを終了してください。
対象外の正規エントリを間違ってfixしないように注意です。

それでは、ACを使用して掃除を行いましょう。
ACを起動させ、Scanをクリックします。
スキャンが終了しましたら、Cleanをクリックして掃除を行います。
掃除が完了すると再起動を求められますので、指示に従って通常モードで再起動を行ってください。
これでセーフモードから通常モードに移行します。
再起動が完了すると、ACのログが表示されますので、そちらを一度PC内の分かりやすい場所に保存してください。

以下のソフトウェアのアップデートを行ってください。
Adobe Reader 9.1 - Japanese Adobe Systems Incorporated 2011/02/09 256 MB 9.1.0
Java 7 Update 9 Oracle 2013/03/10 130 MB 7.0.90

その後、CCを起動させてください。
起動したら、「ツール」→」「スタートアップ」→「Windows」タブを開いてください。
そこで右下の「テキストとして保存」を押すと、表示の内容がログとして保存できるので、ログをデスクトップにでも保存しておいてください。
続いて「InternetExplorer」タブ以下の各タブも順番に開いて、そのログもとっておいてください。
ただし、「コンテキストメニュー」のログは取らなくていいです。
CCの各ログをとったらCCは終了してください。

ACとCCのログを両方とも貼り付け、お知らせください。
両ログを確認後、次の作業内容をご案内いたします。
  • gimp2.6
  • MAIL
  • 2014/02/08 (Sat) 14:24:37
Re: 駆除
こんにちは、悪代官様。アホな私はいくつか間違った操作をしてしまったかもしれません(1、ACでアンストールをコントロールパネルのプログラムの削除、ACを起動するのをATFを起動し変な操作を少し・・)一応、ACとCCのログを貼り付けておくりますが、間違っていたらお知らせください。
# AdwCleaner v3.018 - Report created 08/02/2014 at 16:24:08
# Updated 28/01/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : オヤジ - YUNBOO
# Running from : C:\Users\オヤジ\Downloads\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\END
Folder Found C:\Program Files (x86)\MyPC Backup
Folder Found C:\Program Files (x86)\MyPC Backup
Folder Found C:\Program Files (x86)\PC Speed Maximizer
Folder Found C:\Program Files (x86)\Red Sky
Folder Found C:\Program Files (x86)\Searchprotect
Folder Found C:\ProgramData\Babylon
Folder Found C:\ProgramData\IBUpdaterService
Folder Found C:\ProgramData\Uniblue\DriverScanner
Folder Found C:\Users\オヤジ\AppData\Local\Babylon
Folder Found C:\Users\オヤジ\AppData\Local\DownTango
Folder Found C:\Users\オヤジ\AppData\Local\Freesofttoday
Folder Found C:\Users\オヤジ\AppData\Local\OpenCandy
Folder Found C:\Users\オヤジ\AppData\Local\Searchprotect
Folder Found C:\Users\オヤジ\AppData\LocalLow\BabylonToolbar
Folder Found C:\Users\オヤジ\AppData\LocalLow\baidu
Folder Found C:\Users\オヤジ\AppData\LocalLow\SimplyTech
Folder Found C:\Users\オヤジ\AppData\Roaming\Babylon
Folder Found C:\Users\オヤジ\AppData\Roaming\baidu
Folder Found C:\Users\オヤジ\AppData\Roaming\dvdvideosoftiehelpers
Folder Found C:\Users\オヤジ\AppData\Roaming\file scout
Folder Found C:\Users\オヤジ\AppData\Roaming\OpenCandy
Folder Found C:\Users\オヤジ\Documents\PC Speed Maximizer
Folder Found C:\Users\シュー\AppData\LocalLow\BabylonToolbar
Folder Found C:\Users\シュー\AppData\LocalLow\baidu

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\AppDataLow\Software\simplytech
Key Found : HKCU\Software\FreeSoftToday
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Found : HKCU\Software\ProtectedSearch
Key Found : HKCU\Software\TutoTag
Key Found : [x64] HKCU\Software\FreeSoftToday
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : [x64] HKCU\Software\ProtectedSearch
Key Found : [x64] HKCU\Software\TutoTag
Key Found : HKLM\Software\Babylon
Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\WMHelper.DLL
Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Found : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Key Found : HKLM\SOFTWARE\Classes\driverscanner
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\Software\DownTango
Key Found : HKLM\Software\FreeSoftToday
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Found : HKLM\Software\Tutorials
Key Found : HKLM\Software\Uniblue\DriverScanner
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [PC Speed Maximizer]

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16750

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page] - hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar] - hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Bar] - hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Search [Start Page] - hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Search [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL] - hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Search [Search Bar] - hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Search [Search Page] - hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Page] - hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Default_Search_URL] - hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar] - hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page] - hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
Setting Found : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [(Default)] - hxxp://search.certified-toolbar.com?si=41460&bs=true&tid=2996&q=%s
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)] - hxxp://search.certified-toolbar.com?si=41460&bs=true&tid=2996&q=%s

-\\ Google Chrome v

[ File : C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [8175 octets] - [08/02/2014 16:24:08]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [8235 octets] ##########
# AdwCleaner v3.018 - Report created 08/02/2014 at 16:24:50
# Updated 28/01/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : オヤジ - YUNBOO
# Running from : C:\Users\オヤジ\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\IBUpdaterService
Folder Deleted : C:\ProgramData\Uniblue\DriverScanner
Folder Deleted : C:\Program Files (x86)\MyPC Backup
Folder Deleted : C:\Program Files (x86)\PC Speed Maximizer
Folder Deleted : C:\Program Files (x86)\Red Sky
Folder Deleted : C:\Program Files (x86)\Searchprotect
Folder Deleted : C:\Users\オヤジ\AppData\Local\Babylon
Folder Deleted : C:\Users\オヤジ\AppData\Local\DownTango
Folder Deleted : C:\Users\オヤジ\AppData\Local\Freesofttoday
Folder Deleted : C:\Users\オヤジ\AppData\Local\OpenCandy
Folder Deleted : C:\Users\オヤジ\AppData\Local\Searchprotect
Folder Deleted : C:\Users\オヤジ\AppData\LocalLow\BabylonToolbar
Folder Deleted : C:\Users\オヤジ\AppData\LocalLow\baidu
Folder Deleted : C:\Users\オヤジ\AppData\LocalLow\SimplyTech
Folder Deleted : C:\Users\オヤジ\AppData\Roaming\Babylon
Folder Deleted : C:\Users\オヤジ\AppData\Roaming\baidu
Folder Deleted : C:\Users\オヤジ\AppData\Roaming\dvdvideosoftiehelpers
Folder Deleted : C:\Users\オヤジ\AppData\Roaming\file scout
Folder Deleted : C:\Users\オヤジ\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\オヤジ\Documents\PC Speed Maximizer
Folder Deleted : C:\Users\シュー\AppData\LocalLow\BabylonToolbar
Folder Deleted : C:\Users\シュー\AppData\LocalLow\baidu
File Deleted : C:\END

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [PC Speed Maximizer]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\WMHelper.DLL
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\driverscanner
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\FreeSoftToday
Key Deleted : HKCU\Software\ProtectedSearch
Key Deleted : HKCU\Software\TutoTag
Key Deleted : HKCU\Software\AppDataLow\Software\simplytech
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\DownTango
Key Deleted : HKLM\Software\FreeSoftToday
Key Deleted : HKLM\Software\Tutorials
Key Deleted : HKLM\Software\Uniblue\DriverScanner

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16750

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [(Default)]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)]

-\\ Google Chrome v

[ File : C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [8339 octets] - [08/02/2014 16:24:08]
AdwCleaner[S0].txt - [6738 octets] - [08/02/2014 16:24:50]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6798 octets] ##########
有効 HKLM:Run Adobe Reader Speed Launcher Adobe Systems Incorporated "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
有効 HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
有効 HKLM:Run fst_jp_38
有効 HKLM:Run HotKeysCmds Intel Corporation C:\Windows\system32\hkcmd.exe
有効 HKLM:Run iFilter5 デジタルアーツ株式会社 "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5GC.exe" /autorun
有効 HKLM:Run IgfxTray Intel Corporation C:\Windows\system32\igfxtray.exe
有効 HKLM:Run IME14 JPN Setup Microsoft Corporation C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
有効 HKLM:Run K7SystemTray "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
有効 HKLM:Run K7TSStart K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
有効 HKLM:Run LENOVO.TPKNRRES Lenovo Group Limited C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
有効 HKLM:Run LPStation Sony Corporation C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
有効 HKLM:Run mtvManager C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvManager.exe /startup
有効 HKLM:Run Persistence Intel Corporation C:\Windows\system32\igfxpers.exe
有効 HKLM:Run PWMTRV rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
有効 HKLM:Run QuickTime Task Apple Inc. "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
有効 HKLM:Run SunJavaUpdateSched Oracle Corporation "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
有効 HKLM:Run SynTPEnh Synaptics Incorporated %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
有効 HKLM:Run TpShocks Lenovo. TpShocks.exe
有効 Startup Common Continue installation.lnk Red Sky Sp. z o.o. C:\Users\オヤジ\AppData\Local\Temp\Free_files_downloader.exe
有効 Startup Common PHOTOfunSTUDIO 5.0 HD Edition.lnk Panasonic Corporation C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
有効 Startup Common クライアントマネージャV.lnk BUFFALO INC. C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
有効 Extension Bonjour Apple Inc. C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension このコンテンツを引用 Microsoft Corporation C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
無効 Helper Adobe PDF Link Helper Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
有効 Helper ExplorerWnd Helper IObit C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
無効 Helper i-フィルター 5.0 ブラウザヘルパー デジタルアーツ株式会社 C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5toolbar.dll
無効 Helper i-フィルター 5.0 ブラウザヘルパー デジタルアーツ株式会社 C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5toolbar64.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper C:\Program Files\Java\jre6\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre7\bin\ssv.dll
無効 Helper K7 Web Protection K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
無効 Helper Microsoft アカウント サインイン ヘルパー Microsoft Corp. C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
無効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
無効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL
無効 Helper Windows Live ID Sign-in Helper Microsoft Corp. C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 App Google 讀懃エ「 0.0.0.19 譛€蛻昴・繝ヲ繝シ繧カ繝シ C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
有効 Extension K7 WebProtection 2.3 譛€蛻昴・繝ヲ繝シ繧カ繝シ C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlpfamleaodfgmfnggonbfljhjggbdbe\2.3_0
有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task ViewPassword Update C:\Program Files (x86)\ViewPassword\ViewPassword.exe /update
有効 Task {59E8D459-5183-4CE6-9751-16235127E05D} Microsoft Corporation C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{8C2BF804-A884-4C52-8C3B-2A71A808AA98}\setup.exe" -c -IFP5DELETE -removeonly
丁寧に教えてくださったのに、面倒かけます。
  • ryoyoung
  • MAIL
  • 2014/02/10 (Mon) 14:28:54
ちなみに私は悪代官さんではありません・・・
IUでの作業は気が付かなかったみたいではありますが、
そちらは一通りの作業が終わってからすることにしましたので、
現段階では行わなくても問題ありません。

ではMBAMとSASを使って作業を行ってゆきましょう。

Malwarebytes Anti-Malware(通称・MBAM。説明サイト)
http://fine.tok2.com/home/heto2/0700SecurityApp/Malwarebytes/0001.htm
ダウンロード↓(ファイル直リンです。表示して数秒後にダウンロード開始の表示が出ます)
http://www.malwarebytes.org/mwb-download/
注)現在このソフトは日本語対応ですが、インストール時に日本語でインストールすると稀に文字化けすることがあります。この場合は英語でインストール後に日本語化してください。また、インストール後に日本語で文字化け等のバグが出た場合は英語表示にすれば文字化けは解消されます。
MBAM起動して「Settings」タブ→「Language」→「Japanese」で日本語化できます。
片付け時はセーフモードでアンインストールしてください。

SuperAntiSpyware(通称・SAS。説明↓)
http://www.softnavi.com/superantispyware.html
本家のダウンロードサイト↓
http://www.superantispyware.com/
片付け時はセーフモードでコントロールパネルからアンインストールしてください。

ここで使うのはともにFree(無償版)です。

それでは作業を開始します。
PCをセーフモードで起動してから、MBAMとSASを使って順番にスキャンしてください。
まずはMBAMからスキャンを行いましょう。
MBAMを起動させます。
フルスキャンを選択し、スキャン開始をクリックします。
スキャン終了まで30分~1時間程度お待ちください。
スキャンが完了したら、詳細を表示をクリックします。
検出されたものの一覧が出ますので、検出されたものすべてを駆除するため、
検出されたものの左側にあるチェックボックスすべてに余すことなくチェックを入れます。
すべてにチェックを入れたら選択されたアイテムを隔離ボタンを押します。
最後にログが出ますので、ログを分かりやすい場所に保存してください。
ログ保存が完了したら、MBAMを終了させます。

MBAMを終了させたら、SASを起動させてください。
右側にあるSelect Scan Typeの部分をComplete Scanに変更し、
Scan your Computer...をクリックします。
30分~1時間程度かかります。
スキャンが完了したら、をクリックし、一覧を表示させます。
一覧に表示されているものすべてにチェックが入っているのを確認し、
Remove Threatsをクリックします。
最後にログが表示されますので、分かりやすい場所に保存してください。

両アプリでの作業が済んだらそこでPCを通常モードで再起動してください。

取得された2つのログを貼り付け、ご報告をお願いいたします。
  • gimp2.6
  • MAIL
  • 2014/02/10 (Mon) 14:58:42
Re: 駆除
gimp2.6様 お名前間違えて大変すいません。それではログを貼り付けますので、よろしくお願いします。

Malwarebytes Anti-Malware (試用) 1.75.0.1300
www.malwarebytes.org

定義バージョン: v2014.02.10.01

Windows 7 Service Pack 1 x64 NTFS (セーフモード)
Internet Explorer 10.0.9200.16750
オヤジ :: YUNBOO [管理者]

リアルタイム保護: 無効

2014/02/10 16:32:44
mbam-log-2014-02-10 (16-32-44).txt

スキャンタイプ: フルスキャン (C:\|Q:\|)
有効なスキャン領域: メモリ | スタートアップ | レジストリ | ファイルシステム | ヒューリスティック/追加アイテムのスキャン  | ヒューリスティック/Shuriken エンジンを使用してスキャン  | 不審なプログラム (PUP) | 不審な変更 (PUM)
無効なスキャン領域: ピア・ツー・ピアプログラム(P2P)
スキャンしたアイテム数: 212870
経過時間: 1 時間, 1 分, 53 秒 [中止されました]

メモリプロセスの検出: 0
(悪意のあるアイテムは検出されていません。)

メモリモジュールの検出: 0
(悪意のあるアイテムは検出されていません。)

レジストリキーの検出: 0
(悪意のあるアイテムは検出されていません。)

レジストリ値の検出: 0
(悪意のあるアイテムは検出されていません。)

レジストリデータ項目の検出: 0
(悪意のあるアイテムは検出されていません。)

フォルダの検出: 0
(悪意のあるアイテムは検出されていません。)

ファイルの検出: 9
C:\$Recycle.Bin\S-1-5-21-2470042596-1514475608-4269787398-501\$RRSJGM2.exe (Adware.InstallBrain) -> 正常に隔離され削除されました。
C:\AdwCleaner\Quarantine\C\Users\オヤジ\AppData\Roaming\OpenCandy\274529BBAA8646E4B15CC5813E3F171D\GameHouseSupercollapse3_p1v7.exe.vir (PUP.Optional.OpenCandy) -> 正常に隔離され削除されました。
C:\AdwCleaner\Quarantine\C\Users\オヤジ\AppData\Roaming\OpenCandy\OpenCandy_9DE0199CAAD74C9CAAAC8906F032FF5D\LatestDLMgr.exe.vir (PUP.Optional.OpenCandy) -> 正常に隔離され削除されました。
C:\Program Files (x86)\Uninstall Information\Ib\97\3868\ib_uninstall.exe (Adware.InstallBrain) -> 正常に隔離され削除されました。
C:\ProgramData\K7 Computing\K7TSecurity\K7AntiVirus\Quarantine\F7F5BCA4C5BF55E7739E40CD4EED3579.k7v (PUP.Optional.FileScout.A) -> 正常に隔離され削除されました。
C:\Users\Guest\Downloads\FreeYouTubeDownload.exe (PUP.Optional.OpenCandy) -> 正常に隔離され削除されました。
C:\Users\Guest\Downloads\PdfSpeedSetup.exe (Adware.InstallBrain) -> 正常に隔離され削除されました。
C:\Users\Guest\Downloads\SketchUp.exe (PUP.Optional.BundleInstaller.A) -> 正常に隔離され削除されました。
C:\Users\オヤジ\AppData\Local\Temp\Install PDF Speed973868.exe (Adware.InstallBrain) -> 正常に隔離され削除されました。

(終)
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/11/2014 at 09:33 AM

Application Version : 5.7.1018

Core Rules Database Version : 11031
Trace Rules Database Version: 8843

Scan type : Complete Scan
Total Scan Time : 01:05:48

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC Off - Administrator

Memory items scanned : 393
Memory threats detected : 0
Registry items scanned : 73378
Registry threats detected : 0
File items scanned : 76312
File threats detected : 71

Adware.Tracking Cookie
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\MR0KHZX2.txt [ /adultmango.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\EBZ9RHKK.txt [ /adtech.de ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\EBP5AYBG.txt [ /ads.yahoo.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\37B24NOG.txt [ /ad.dmm.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\RVST3PS3.txt [ /t.webtracker.jp ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\P4PGGBKH.txt [ /clickbank.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\SL43VL0X.txt [ /advertising.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\DOC992DW.txt [ /atdmt.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\IWF81WIU.txt [ /nissanfs.112.2o7.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\KFJ04K9X.txt [ /apmebf.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\YKTQN2XE.txt [ /at.atwola.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\60VY6PI2.txt [ /ads.adsrvmedia.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\HOED22EV.txt [ /yieldmanager.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\WRGC6L9D.txt [ /adform.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\JIK51WWP.txt [ /ad-m.asia ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\CR9QKGXY.txt [ /kakakucom.112.2o7.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\QRRESGT4.txt [ /statse.webtrendslive.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\ナヤヘ@ads.us.e-planning[1].txt [ /ads.us.e-planning.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\1ZW6A1V5.txt [ /ana.112.2o7.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\JNY27WEU.txt [ /c.atdmt.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\CGDVI8G5.txt [ /tribalfusion.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\F6D96F3Y.txt [ /sofmap.112.2o7.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\JLZ5THB1.txt [ /female.caribbeancom.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\MLANEC0U.txt [ /cast.trustclick.ne.jp ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\FGS38NKR.txt [ /ru4.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\63M69TV2.txt [ /accounts.google.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\V1UJ035V.txt [ /overture.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\HXLTAEYS.txt [ /doubleclick.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\4R3XB6VR.txt [ /rakuten.112.2o7.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\ナヤヘ@msnportal.112.2o7[1].txt [ /msnportal.112.2o7.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\DS8O1XB8.txt [ /www.adultpeach.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\6YL4H7Y6.txt [ /tacoda.at.atwola.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\Z80TK7V4.txt [ /lucidmedia.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\YZ14JJVC.txt [ /mediaplex.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\X613BLPN.txt [ /revsci.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\4YWYB76Y.txt [ /startspublishing.112.2o7.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\DRJGWIRV.txt [ /ads.custom-click.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\ナヤヘ@imrworldwide[2].txt [ /imrworldwide.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZAGWTGML.txt [ /questionbox.jp.msn.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\62W5U9HE.txt [ /ads.pilpelmedia.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\DBX3FNSA.txt [ /c1.atdmt.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\AIMCZQBK.txt [ /content.yieldmanager.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\05VKNL59.txt [ /track.adform.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\YP4Y4BZB.txt [ /kddi.122.2o7.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\JJH33928.txt [ /ad.nikkansports.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\O8K4BBYB.txt [ /fastclick.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\XLU6VAN7.txt [ /ad.yieldmanager.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\B0P4HIYW.txt [ /www.adultmango.com ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\ER4B0CZI.txt [ /dmm.112.2o7.net ]
C:\Users\オヤジ\AppData\Roaming\Microsoft\Windows\Cookies\Low\3YQNWHLQ.txt [ /www.googleadservices.com ]
ads1.msn.com [ C:\USERS\GUEST\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\M8KNS3HJ ]
female.caribbeancom.com [ C:\USERS\オヤジ\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WDG5BJBL ]
macromedia.com [ C:\USERS\オヤジ\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WDG5BJBL ]
secure-uk.imrworldwide.com [ C:\USERS\オヤジ\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WDG5BJBL ]
tres.trustclick.ne.jp [ C:\USERS\オヤジ\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WDG5BJBL ]
C:\USERS\シュー\APPDATA\LOCAL\TEMP\LOW\COOKIES\シュー@CNT2.MILLIONCOUNTER[1].TXT [ /CNT2.MILLIONCOUNTER ]
ads1.msads.net [ C:\USERS\シュー\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WYFX4JUY ]
cdn1.static1.pornrabbit.com [ C:\USERS\シュー\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WYFX4JUY ]
cdn1b.thumbnails.porntube.com [ C:\USERS\シュー\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WYFX4JUY ]
cdn2b.static.hardsextube.com [ C:\USERS\シュー\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WYFX4JUY ]
cdn3b.static.hardsextube.com [ C:\USERS\シュー\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WYFX4JUY ]
media.adxpansion.com [ C:\USERS\シュー\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WYFX4JUY ]
media1.shufuni.com [ C:\USERS\シュー\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WYFX4JUY ]
tres.trustclick.ne.jp [ C:\USERS\シュー\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WYFX4JUY ]
www.banner-typemessage.com [ C:\USERS\シュー\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WYFX4JUY ]
www.naiadsystems.com [ C:\USERS\シュー\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WYFX4JUY ]
www.pornhub.com [ C:\USERS\シュー\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WYFX4JUY ]
wwwstatic.megaporn.com [ C:\USERS\シュー\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\WYFX4JUY ]
C:\USERS\シュー\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\シュー@KDDI.122.2O7[1].TXT [ /KDDI.122.2O7 ]
C:\USERS\シュー\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\シュー@MSNPORTAL.112.2O7[1].TXT [ /MSNPORTAL.112.2O7 ]

Trojan.Agent/Gen-StartPage
C:\USERS\オヤジ\APPDATA\LOCAL\TEMP\UNTA93A.EXE
  • ryoyoung
  • MAIL
  • 2014/02/11 (Tue) 10:00:21
MBAMが途中で中止されています
>経過時間: 1 時間, 1 分, 53 秒 [中止されました]
MBAMのフルスキャンが完了しておりません。
お手数ではありますが、フルスキャンを完了させ、再度ご報告をお願いいたします。
なお、SASは正常終了の模様ですので、こちらは問題ありません。
  • gimp2.6
  • MAIL
  • 2014/02/11 (Tue) 10:44:54
Re: 駆除
MBAMのログを貼り付けます。よろしくお願いします。
Malwarebytes Anti-Malware (試用) 1.75.0.1300
www.malwarebytes.org

定義バージョン: v2014.02.10.09

Windows 7 Service Pack 1 x64 NTFS (セーフモード)
Internet Explorer 10.0.9200.16750
オヤジ :: YUNBOO [管理者]

リアルタイム保護: 無効

2014/02/11 13:01:02
mbam-log-2014-02-11 (13-01-02).txt

スキャンタイプ: フルスキャン (C:\|Q:\|)
有効なスキャン領域: メモリ | スタートアップ | レジストリ | ファイルシステム | ヒューリスティック/追加アイテムのスキャン  | ヒューリスティック/Shuriken エンジンを使用してスキャン  | 不審なプログラム (PUP) | 不審な変更 (PUM)
無効なスキャン領域: ピア・ツー・ピアプログラム(P2P)
スキャンしたアイテム数: 485327
経過時間: 1 時間, 21 分, 20 秒

メモリプロセスの検出: 0
(悪意のあるアイテムは検出されていません。)

メモリモジュールの検出: 0
(悪意のあるアイテムは検出されていません。)

レジストリキーの検出: 0
(悪意のあるアイテムは検出されていません。)

レジストリ値の検出: 0
(悪意のあるアイテムは検出されていません。)

レジストリデータ項目の検出: 2
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (Hijack.SearchPage) -> 悪: (http://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=) 良: (http://www.google.com) -> 正常に隔離され修復されました。
HKCU\Software\Microsoft\Internet Explorer\SearchURI|(Default) (PUP.Optional.SearchCertifiedTB.A) -> 悪: (http://search.certified-toolbar.com?si=41460&bs=true&tid=2996&q=%s) 良: (http://www.google.com) -> 正常に隔離され修復されました。

フォルダの検出: 0
(悪意のあるアイテムは検出されていません。)

ファイルの検出: 0
(悪意のあるアイテムは検出されていません。)

(終)
  • ryoyoung
  • MAIL
  • 2014/02/11 (Tue) 14:41:13
各種更新他の作業を
こんばんは。
ここの管理人の悪代官という曲者です。
ログを見せてもらったところ、MBAMとSASで掃除もできてますね。
では両アプリはセーフモードでアンインストールしてください。

それではよければ続いて以下の説明をよく読んでから、順番に作業をお願いします。

>Platform: Windows 7 SP1 (WinNT 6.00.3505)
>MSIE: Internet Explorer v10.0 (10.00.9200.16750)
Win7用のIE最新版は現在11です。
Windowsの各種更新(WindowsUpdate)は常に最新に適用しておかないと、それだけで危険な感染はすぐにでも起きますよ。

また、少なくとも下記のアプリは旧バージョンです。
>Adobe Reader 9.1 - Japanese Adobe Systems Incorporated 2011/02/09 256 MB 9.1.0
>i-フィルター 5.0 Digital Arts 2011/02/16 5.00.12.0108
>Java 7 Update 9 Oracle 2013/03/10 130 MB 7.0.90
各種アプリの更新を怠っただけでも、脆弱性を悪用されて深刻な感染はあっさり起きます。
使うなら最新版に更新してください。使わないアプリならアンインストールが安全です。
他にも旧バージョンないか調べて、あれば同様に更新するか、アンインストールしてください。

次にまたCCを起動して、「Windows」タブ内の下記を右クリックから「エントリの削除」してください。
>有効 HKLM:Run fst_jp_38

次に「IE」タブ内の下記も同様に処置です。
>無効 Helper i-フィルター 5.0 ブラウザヘルパー デジタルアーツ株式会社 C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5toolbar.dll
>無効 Helper i-フィルター 5.0 ブラウザヘルパー デジタルアーツ株式会社 C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5toolbar64.dll

続いて「Chrome」タブ内の下記も同様に処置です。
>有効 Task ViewPassword Update C:\Program Files (x86)\ViewPassword\ViewPassword.exe /update

ここまでできたら一度PC再起動してから、またしばらく様子見した後、あらたにHJTとインストール情報のログを取り直してください。

取り直した両ログと状態報告をレスで見せてください。
それを見てからまた調べましょう
  • 悪代官
  • 2014/02/11 (Tue) 20:20:50
Re: 駆除
こんにちは、悪代官様。よろしくお願いします。まず Windows7のIE、Adobe Reader、 Javaはupdateしたつもりです。ただ、i-フィルター (Acerのパソコンに初めから入っていた試供版)は必要ないと思って、だいぶ前からコントロールパネルのプログラムの削除からアンインストールしようとしても、セットアップ中の実行中のエラー(詳細:エラーコード: -5005 : 0x80070002
エラー情報:
>Kernel\KernelMedia.cpp (95)
>SetupNew\setup.cpp (851)
PAPP:i-フィルター 5.0
PVENDOR:Digital Arts (http://www.daj.jp/)
PGUID:8C2BF804-A884-4C52-8C3B-2A71A808AA98
$15.0.0.498
@Windows Vista Service Pack 0 (6000)
IE Version: 9.11.9600.16428
とでまして、削除できません。
あと聞きたい事として、1、CCの操作はセーブモードからですか?2、インストール情報のログはどうやって取るのでしょうか?あたりまえのことでしょうがお願いします。
  • ryoyoung
  • MAIL
  • 2014/02/12 (Wed) 13:01:02
作業の手順を
レスが遅くなってすみません。
では順番にレスしましょうか。

まずi-フィルターですが、これは本来ならセキュリティ上有用なフィルタリングソフトです。
が、現在入っているのは旧バージョンなので、期限が切れていたらまったく使えないわけです。
アンインストールが正常にできないなら、i-フィルターをインストールしたのがご家族の誰かという可能性もあり、インストした方がパスワード設定していたらi-フィルターのアンインストールも設定解除もできないのはおかしくありません。
フィルタリングソフトというのはそういうものですから。
で、この場合はインストした方に今回の状況を説明して、i-フィルターを使うなら最新版に更新するか、使わないならパス解除してアンインストールしてもらうしかないです。
ですが誰もインストしておらず、パスも設定してなければこの点はあたらないので、この場合はとりあえずi-フィルターは置いといて次の作業に進んでください。

CCの起動は通常モードで起動してください。
CCはセーフモードで使えない機能もありますので。

次にインストール情報のログですが、これは最初の投稿時にここに上げた2つのログをとった時の手順です。
HJTと、もうひとつのインストール情報ログですね。
先の時点では
>Access Help Lenovo 2011/02/09 3.00
>Adobe Flash Player 12 ActiveX Adobe Systems Incorporated 2014/02/07 6.00 MB 12.0.0.44
で始まっていた内容のログです。

この手順を思い出しながら作業してください。
ここでの作業では各ツールのログを何度か取り直しながらレスを進めていくので、いったん済ませた作業でもそのあと何度でも行ってもらうこともあります。
このスレのこれまでの経緯も読み直しながら、落ち着いて進めてください
  • 悪代官
  • 2014/02/12 (Wed) 17:57:29
Re: 駆除
ふたつのログを貼り付けました。
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:40:09, on 2014/02/13
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMECMNT.EXE
C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe
C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5GC.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SysMon.Exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe
C:\Users\オヤジ\Downloads\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: K7 Web Protection - {08B3B4B6-02DA-4658-8BA6-5974E3EBB03D} - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Microsoft アカウント サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [K7TSStart] C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
O4 - HKLM\..\Run: [K7SystemTray] "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [LPStation] C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
O4 - HKLM\..\Run: [mtvManager] C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvManager.exe /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iFilter5] "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
O4 - Global Startup: Continue installation.lnk = ?
O4 - Global Startup: クライアントマネージャV.lnk = C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: OneNote に送る(&N) - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: OneNote に送る - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: OneNote に送る(&N) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} (DMM Downloader) - http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab
O16 - DPF: {4845B7A7-309F-49F4-A2DD-0117707B6E8D} (DVD Toaster ActiveX Control) - https://toast.dvdtoaster.jp/downloads/activex/x86/dvdtoast.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: Bonjour サービス (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: BWH32S - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
O23 - Service: EzDetector - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: i-フィルター 5.0 Main (IFP5MainService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
O23 - Service: i-フィルター 5.0 Support (IFP5WatchService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: K7Carnivore Service (K7CrvSvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe
O23 - Service: K7Computng - EMail Proxy Server (K7EmlPxy) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7EmlPxy.exe
O23 - Service: K7Firewall Services (K7FWSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7FWSrvc.exe
O23 - Service: K7Privacy Services (K7PSSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7PSSrvc.exe
O23 - Service: K7RealTime AntiVirus Services (K7RTScan) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7RTScan.exe
O23 - Service: K7SpmSrc - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SpmSrc.exe
O23 - Service: K7TotalSecurity Manager (K7TSMngr) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSMngr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: LISMO PIM Service - CASIO SOFT CO. LTD. - C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: I-O DATA mAgicTV Digital (mAgicTVDigital) - I-O DATA DEVICE, INC. - C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NlsSrv32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SD Device Manager - Panasonic Corporation - C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: SonicStage Back-End Service2 - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13744 bytes

Access Help Lenovo 2011/02/09 3.00
Adobe Flash Player 12 ActiveX Adobe Systems Incorporated 2014/02/07 6.00 MB 12.0.0.44
Adobe Reader XI (11.0.06) - Japanese Adobe Systems Incorporated 2014/02/12 147 MB 11.0.06
Apple Application Support Apple Inc. 2013/10/01 64.0 MB 2.3.6
Apple Mobile Device Support Apple Inc. 2013/10/01 25.0 MB 7.0.0.117
au ISW11K USB Driver 京セラ株式会社 2012/03/01 1.00.0000
au T008 USB Driver Ver.5.0.0.1 2011/09/24 V5.24.1.0
Bonjour Apple Inc. 2014/02/03 3.29 MB 1.0.106
BUFFALO エアステーション設定ツール BUFFALO INC. 2011/09/25 2.84 MB 2.0.5
BUFFALO クライアントマネージャV BUFFALO INC. 2011/09/25
BUFFALO パソコン環境表示ツール BUFFALO INC. 2011/09/25 1.0.3
Corel DVD MovieWriter Lenovo Edition Corel Corporation 2011/02/09 320 MB 7.0.0
Corel TVX Corel Corporation 2014/02/03 31.2 MB 2.2-B0.5
Create Recovery Media Lenovo Group Limited 2011/02/09 9.50 MB 1.20.0.00
DVD Decrypter (Remove Only) 2011/02/18
DVD Flick 1.3.0.7 Dennis Meuwissen 2012/05/05 1.3.0.7
DVD Shrink 3.2 DVD Shrink 2011/02/18
EPSONプリンタドライバ・ユーティリティ SEIKO EPSON Corporation 2012/02/25
I-O DATA mAgicTV Digital I-O DATA DEVICE,INC. 2014/02/03 1.01.00
i-フィルター 5.0 Digital Arts 2011/02/16 5.00.12.0108
IL Download Manager Image-Line 2011/11/05
Intel(R) Control Center Intel Corporation 2011/02/09 1.2.1.1007
Intel(R) Graphics Media Accelerator Driver Intel Corporation 2011/02/09 8.15.10.2125
Intel(R) Management Engine Components Intel Corporation 2011/02/09 6.0.0.1179
InterVideo WinDVD 8 InterVideo Inc. 2011/02/09 163 MB 8.0.20.199
IObit Uninstaller IObit 2014/02/08 3.1.7.2405
Java 7 Update 51 Oracle 2014/02/08 118 MB 7.0.510
Java 7 Update 9 Oracle 2013/03/10 130 MB 7.0.90
Jw_cad 2014/01/29
Lenovo Auto Scroll Utility 2011/02/09 1.00
Lenovo Patch Utility Lenovo Group Limited 2013/05/12 1.33 MB 1.3.1.1
Lenovo Patch Utility 64 bit Lenovo Group Limited 2013/05/12 1.35 MB 1.3.1.1
Lenovo System Interface Driver 2013/05/12 1.05
Lenovo System Update Lenovo 2013/07/16 13.4 MB 5.02.0018
Lenovo ThinkVantage Toolbox PC-Doctor, Inc. 2011/02/09 6.0.5717.21
Lenovo Warranty Information Lenovo 2011/02/09 893 KB 1.0.0004.00
Lenovo Welcome Lenovo 2011/02/09
LISMO Port 5.1 Sony Corporation 2013/03/10 110 MB 5.1
Message Center Plus Lenovo Group Limited 2011/02/09 1.70 MB 2.0.0012.00
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 2011/02/27 38.8 MB 4.0.30319
Microsoft Office Home and Business 2010 Microsoft Corporation 2013/11/03 14.0.7015.1000
Microsoft Office Word Viewer 2003 Microsoft Corporation 2014/01/16 105 MB 11.0.8173.0
Microsoft Silverlight Microsoft Corporation 2013/10/10 149 MB 5.1.20913.0
Microsoft SkyDrive Microsoft Corporation 2013/01/15 25.1 MB 16.4.6013.0910
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2011/02/09 1.69 MB 3.1.0000
Microsoft SQL Server Compact 3.5 SP1 English Microsoft Corporation 2011/02/28 2.59 MB 3.5.5692.0
Microsoft SQL Server Compact 3.5 SP1 x64 English Microsoft Corporation 2011/02/28 3.69 MB 3.5.5692.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 Microsoft Corporation 2011/02/26 260 KB 8.0.50727.4053
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 2011/02/26 250 KB 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2014/02/03 2.38 MB 8.0.59193
Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 2011/02/09 840 KB 8.0.61000
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2013/10/01 248 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2011/02/16 784 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 2011/06/20 788 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2011/03/17 234 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2011/02/16 592 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2011/06/20 600 KB 9.0.30729.6161
Mobile Broadband Lenovo 2011/02/09 16.4 MB 3.6.0034
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2011/02/18 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2011/02/18 1.33 MB 4.20.9876.0
PHOTOfunSTUDIO 5.0 HD Edition Panasonic Corporation 2011/02/28 5.00.313
QuickTime Apple Inc. 2012/11/07 73.2 MB 7.72.80.56
Registry Patch to arrange icons in Device and Printers folder of Windows 7 2011/02/09 1.00
Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7 2011/02/09 1.00
Rescue and Recovery Lenovo Group Limited 2013/05/12 101 MB 4.31.0005.00
SAMSUNG USB Driver for Mobile Phones SAMSUNG Electronics Co., Ltd. 2013/08/07 42.9 MB 1.5.16.0
SonicStage 4.4 Sony Corporation 2012/02/15 4.4
Sony Media Library Earth 8.1.00 Sony Corporation 2013/03/10 47.3 MB 8.1.00.11292
ThinkPad Power Management Driver 2011/02/09 1.60.0.4
ThinkPad UltraNav Driver 2011/02/16 46.4 MB 15.0.18.0
ThinkPad Wireless LAN Adapter Software REALTEK Semiconductor Corp. 2011/02/09 1.00.0024.0
ThinkPad 省電力マネージャー 2011/02/09 3.30
ThinkVantage Communications Utility Lenovo 2011/02/09 2.43 MB 1.41
ThinkVantage ハードディスク・アクティブプロテクション・システム Lenovo 2011/02/09 15.6 MB 1.74
USB Video/Audio Device Driver 会社名 2012/07/29 15.4 MB 1.00.0000
Windows Live Essentials Microsoft Corporation 2013/01/15 16.4.3505.0912
Windows ドライバ パッケージ - I-O DATA DEVICE, INC. GV-MVP/FZ(x64) (11/29/2010 1.8.2.12) I-O DATA DEVICE, INC. 2014/02/03 11/29/2010 1.8.2.12
Windows ドライバ パッケージ - Intel (iaStor) hdc (01/15/2010 9.5.7.1002) Intel 2011/02/09 01/15/2010 9.5.7.1002
Windows ドライバ パッケージ - Intel hdc (06/04/2009 7.0.0.1013) Intel 2011/02/09 06/04/2009 7.0.0.1013
Windows ドライバ パッケージ - Intel System (06/04/2009 1.0.0.0002) Intel 2011/02/09 06/04/2009 1.0.0.0002
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/09 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/10 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel USB (08/20/2009 9.1.1.1020) Intel 2011/02/09 08/20/2009 9.1.1.1020
Windows ドライバ パッケージ - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4) Lenovo 2011/02/09 11/18/2009 1.60.0.4
Windows ドライバ パッケージ - Realtek Semiconductor Corp. HD Audio Driver (06/29/2010 6.0.1.6146) Realtek Semiconductor Corp. 2011/02/09 06/29/2010 6.0.1.6146
インテル(R) ターボ・ブースト・テクノロジー・モニター インテル 2011/02/09 1.13 MB 1.0.186.3
ウイルスセキュリティ ソースネクスト株式会社 2012/09/18 12.00
 
よく読んで、あせらず、落ち着いてですね!
  • ryoyoung
  • MAIL
  • 2014/02/13 (Thu) 12:52:24
ACで確認作業します
作業と報告、ご苦労様です。
各ログも見せてもらったところ、おおむねスムーズに進んでいるようですね。
ではまた説明を読んでから、続きの作業をお願いします。

Javaの旧バージョンである下記はコンパネからアンインストールしてください。最新版だけあればいいです。
>Java 7 Update 9 Oracle 2013/03/10 130 MB 7.0.90

先に使ったACの最新版をまたダウンロードしておいてください。これを使って再度確認作業します。

準備できたらまたPCをセーフモードで起動して、その状態でACでClean作業してください。

PCを再起動後、ACのログをまた保存してからしばらく様子見したあと、ACのログと状態報告をレスください。

これで異常が消えていればあとは掃除程度になるかと思います摁
  • 悪代官
  • 2014/02/13 (Thu) 13:32:49
Re: 駆除
ACのログを貼り付けします。もしかしたら、ACの最新版をダウンロードしようとして、また変なところをクリックしたかもしれません・・・トホホ
# AdwCleaner v3.018 - Report created 13/02/2014 at 15:52:23
# Updated 28/01/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : オヤジ - YUNBOO
# Running from : C:\Users\オヤジ\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16518


-\\ Google Chrome v

[ File : C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [4903 octets] - [13/02/2014 15:47:14]
AdwCleaner[R1].txt - [871 octets] - [13/02/2014 15:51:46]
AdwCleaner[S0].txt - [3095 octets] - [13/02/2014 15:49:51]
AdwCleaner[S1].txt - [793 octets] - [13/02/2014 15:52:23]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [852 octets] ##########
  • ryoyoung
  • MAIL
  • 2014/02/13 (Thu) 16:05:29
ログはよさそうですが
作業と報告、ご苦労様です。
ACログを見たところ、特に不審な痕跡はなさそうですが、

>ACの最新版をダウンロードしようとして、また変なところをクリックしたかもしれません

現在またなにか異常が再発してますか?
ログには出なくても異常が続いていることもあるので、この場合はまた別の角度から調べます。
異常が出てなければ処置は成功しているはずですが、とりあえず状態報告をお願いします
  • 悪代官
  • 2014/02/13 (Thu) 17:25:50
Re: 駆除
今日もまたよろしくお願いします。今のところいろいろサイトを見ても変な広告は出ません。ただ、youtubeなどを見ようとすると(怪しいサイトではありません)「InternetExplorerは動作を停止しました。」「このWebページに問題があるためタブを開きなおしました。」と出たり「お使いのコンピューターを保護するためこのWebページを閉じました。」と出ます。この投稿をするときもWebページを閉ざされます。これは大丈夫なのでしょうか?
  • ryoyoung
  • MAIL
  • 2014/02/14 (Fri) 14:01:18
i-フィルターを削除しましょう
作業と報告、ご苦労様です。

>今のところいろいろサイトを見ても変な広告は出ません。ただ、youtubeなどを見ようとすると(怪しいサイトではありません)「InternetExplorerは動作を停止しました。」「このWebページに問題があるためタブを開きなおしました。」と出たり「お使いのコンピューターを保護するためこのWebページを閉じました。」と出ます

ようつべだけならセキュリティソフトでブロックされた可能性もあります。
ようつべは現在、かなり悪質広告も増えてしまったため、各社のセキュリティソフトでブロックされてもまったくおかしくないのですが、他のサイトでも異常が出るのは妙ですね。

もしかして削除不全に陥ったi-フィルターの影響でしょうか。

ではi-フィルターをアンインストールしてもいいなら、以下の手順で作業してください。

まずブラウザや他のアプリを事前に終了した状態で、CCを起動して、インストール情報の画面を開いてください。

そこで以下を選択して、「エントリの削除」してください。
>i-フィルター 5.0 Digital Arts 2011/02/16 5.00.12.0108

CCではこの手順で、削除不全になったアプリでも強制削除することも可能なので、この手順で処置します。

これができたら一度PCを再起動後、またしばらく様子見した後、状態報告をレスください
  • 悪代官
  • 2014/02/14 (Fri) 17:31:11
Re: 駆除
お忙しところすいません。
CCを起動し、ツールからインストール情報の画面を出し、i-フィルター 5.0 Digital Arts 2011/02/16 5.00.12.0108をエントリーの削除で操作しました。
画面からは消えました。再起動しても、スタートアップに残っていますし、すべてのプログラムにも残っています。
再びCCを起動しスタートアップの画面にi-フィルター がありましたので、これをエントリーの削除で操作し、再起動しました。でも残っています。
まったく同じ文章で投稿しようとしましたらやはり、「お使いのコンピュータを保護するためIEはこのWebページを閉じました。」
「正しく機能しないアドオンまたは悪意のあるアドオンが存在するため、InternetExPlorerはこのWebページを閉じました。」と出て一回目は投稿できませんでした。
とりあえず、CCのインストール情報のログを貼り付けて投稿しますのでよろしくお願いします。
Access Help Lenovo 2011/02/09 3.00
Adobe Flash Player 12 ActiveX Adobe Systems Incorporated 2014/02/07 6.00 MB 12.0.0.44
Adobe Reader XI (11.0.06) - Japanese Adobe Systems Incorporated 2014/02/12 147 MB 11.0.06
Apple Application Support Apple Inc. 2013/10/01 64.0 MB 2.3.6
Apple Mobile Device Support Apple Inc. 2013/10/01 25.0 MB 7.0.0.117
au ISW11K USB Driver 京セラ株式会社 2012/03/01 1.00.0000
au T008 USB Driver Ver.5.0.0.1 2011/09/24 V5.24.1.0
Bonjour Apple Inc. 2014/02/03 3.29 MB 1.0.106
BUFFALO エアステーション設定ツール BUFFALO INC. 2011/09/25 2.84 MB 2.0.5
BUFFALO クライアントマネージャV BUFFALO INC. 2011/09/25
BUFFALO パソコン環境表示ツール BUFFALO INC. 2011/09/25 1.0.3
Corel DVD MovieWriter Lenovo Edition Corel Corporation 2011/02/09 320 MB 7.0.0
Corel TVX Corel Corporation 2014/02/03 31.2 MB 2.2-B0.5
Create Recovery Media Lenovo Group Limited 2011/02/09 9.50 MB 1.20.0.00
DVD Decrypter (Remove Only) 2011/02/18
DVD Flick 1.3.0.7 Dennis Meuwissen 2012/05/05 1.3.0.7
DVD Shrink 3.2 DVD Shrink 2011/02/18
I-O DATA mAgicTV Digital I-O DATA DEVICE,INC. 2014/02/03 1.01.00
IePluginService12.27.0.3326 Cherished Technololgy LIMITED 2014/02/13 12.27.0.3326
IL Download Manager Image-Line 2011/11/05
Intel(R) Control Center Intel Corporation 2011/02/09 1.2.1.1007
Intel(R) Graphics Media Accelerator Driver Intel Corporation 2011/02/09 8.15.10.2125
Intel(R) Management Engine Components Intel Corporation 2011/02/09 6.0.0.1179
InterVideo WinDVD 8 InterVideo Inc. 2011/02/09 163 MB 8.0.20.199
IObit Uninstaller IObit 2014/02/08 3.1.7.2405
Java 7 Update 51 Oracle 2014/02/08 118 MB 7.0.510
Jw_cad 2014/01/29
Lenovo Auto Scroll Utility 2011/02/09 1.00
Lenovo Patch Utility Lenovo Group Limited 2013/05/12 1.33 MB 1.3.1.1
Lenovo Patch Utility 64 bit Lenovo Group Limited 2013/05/12 1.35 MB 1.3.1.1
Lenovo System Interface Driver 2013/05/12 1.05
Lenovo System Update Lenovo 2013/07/16 13.4 MB 5.02.0018
Lenovo ThinkVantage Toolbox PC-Doctor, Inc. 2011/02/09 6.0.5717.21
Lenovo Warranty Information Lenovo 2011/02/09 893 KB 1.0.0004.00
Lenovo Welcome Lenovo 2011/02/09
LISMO Port 5.1 Sony Corporation 2013/03/10 110 MB 5.1
Message Center Plus Lenovo Group Limited 2011/02/09 1.70 MB 2.0.0012.00
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 2011/02/27 38.8 MB 4.0.30319
Microsoft Office Home and Business 2010 Microsoft Corporation 2013/11/03 14.0.7015.1000
Microsoft Office Word Viewer 2003 Microsoft Corporation 2014/01/16 105 MB 11.0.8173.0
Microsoft Silverlight Microsoft Corporation 2013/10/10 149 MB 5.1.20913.0
Microsoft SkyDrive Microsoft Corporation 2013/01/15 25.1 MB 16.4.6013.0910
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2011/02/09 1.69 MB 3.1.0000
Microsoft SQL Server Compact 3.5 SP1 English Microsoft Corporation 2011/02/28 2.59 MB 3.5.5692.0
Microsoft SQL Server Compact 3.5 SP1 x64 English Microsoft Corporation 2011/02/28 3.69 MB 3.5.5692.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 Microsoft Corporation 2011/02/26 260 KB 8.0.50727.4053
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 2011/02/26 250 KB 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2014/02/03 2.38 MB 8.0.59193
Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 2011/02/09 840 KB 8.0.61000
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2013/10/01 248 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2011/02/16 784 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 2011/06/20 788 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2011/03/17 234 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2011/02/16 592 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2011/06/20 600 KB 9.0.30729.6161
Mobile Broadband Lenovo 2011/02/09 16.4 MB 3.6.0034
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2011/02/18 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2011/02/18 1.33 MB 4.20.9876.0
PHOTOfunSTUDIO 5.0 HD Edition Panasonic Corporation 2011/02/28 5.00.313
QuickTime Apple Inc. 2012/11/07 73.2 MB 7.72.80.56
Registry Patch to arrange icons in Device and Printers folder of Windows 7 2011/02/09 1.00
Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7 2011/02/09 1.00
Rescue and Recovery Lenovo Group Limited 2013/05/12 101 MB 4.31.0005.00
SAMSUNG USB Driver for Mobile Phones SAMSUNG Electronics Co., Ltd. 2013/08/07 42.9 MB 1.5.16.0
SonicStage 4.4 Sony Corporation 2012/02/15 4.4
Sony Media Library Earth 8.1.00 Sony Corporation 2013/03/10 47.3 MB 8.1.00.11292
SupTab 2014/02/13 1.1.1.0
sweet-page Browser Protecter sweet-page 2014/02/13
ThinkPad Power Management Driver 2011/02/09 1.60.0.4
ThinkPad UltraNav Driver 2011/02/16 46.4 MB 15.0.18.0
ThinkPad Wireless LAN Adapter Software REALTEK Semiconductor Corp. 2011/02/09 1.00.0024.0
ThinkPad 省電力マネージャー 2011/02/09 3.30
ThinkVantage Communications Utility Lenovo 2011/02/09 2.43 MB 1.41
ThinkVantage ハードディスク・アクティブプロテクション・システム Lenovo 2011/02/09 15.6 MB 1.74
Update for Zip Extractor Update for Zip Extractor 2014/02/13
USB Video/Audio Device Driver 会社名 2012/07/29 15.4 MB 1.00.0000
Windows Live Essentials Microsoft Corporation 2013/01/15 16.4.3505.0912
Windows ドライバ パッケージ - I-O DATA DEVICE, INC. GV-MVP/FZ(x64) (11/29/2010 1.8.2.12) I-O DATA DEVICE, INC. 2014/02/03 11/29/2010 1.8.2.12
Windows ドライバ パッケージ - Intel (iaStor) hdc (01/15/2010 9.5.7.1002) Intel 2011/02/09 01/15/2010 9.5.7.1002
Windows ドライバ パッケージ - Intel hdc (06/04/2009 7.0.0.1013) Intel 2011/02/09 06/04/2009 7.0.0.1013
Windows ドライバ パッケージ - Intel System (06/04/2009 1.0.0.0002) Intel 2011/02/09 06/04/2009 1.0.0.0002
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/09 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/10 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel USB (08/20/2009 9.1.1.1020) Intel 2011/02/09 08/20/2009 9.1.1.1020
Windows ドライバ パッケージ - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4) Lenovo 2011/02/09 11/18/2009 1.60.0.4
Windows ドライバ パッケージ - Realtek Semiconductor Corp. HD Audio Driver (06/29/2010 6.0.1.6146) Realtek Semiconductor Corp. 2011/02/09 06/29/2010 6.0.1.6146
WPM17.8.0.3325 Cherished Technololgy LIMITED 2014/02/13 17.8.0.3325
インテル(R) ターボ・ブースト・テクノロジー・モニター インテル 2011/02/09 1.13 MB 1.0.186.3
ウイルスセキュリティ ソースネクスト株式会社 2012/09/18 12.00

  • ryoyoung
  • MAIL
  • 2014/02/14 (Fri) 18:57:27
新たな感染が見つかってます
作業と報告、ご苦労様です。
まずi-フィルターは削除できたようなのでいいですが、ログを見たところまた別の曲者が入り込んでますね。
>IePluginService12.27.0.3326 Cherished Technololgy LIMITED 2014/02/13 12.27.0.3326
>SupTab 2014/02/13 1.1.1.0
>sweet-page Browser Protecter sweet-page 2014/02/13
>WPM17.8.0.3325 Cherished Technololgy LIMITED 2014/02/13 17.8.0.3325
>Update for Zip Extractor Update for Zip Extractor 2014/02/13
いずれも先のインンストール情報にはなく、2月13日に仕込まれているようで、これがまた新たな異常に絡んでいるかもしれません。
ではまた説明を読んでから、続きの作業をお願いします。

まずACの最新版をまたダウンロードと保存しておいてください。これの作業を再試行します。

PCをセーフモードで起動して、IUを使って以下の5つをアンインストールしてください。
>IePluginService12.27.0.3326 Cherished Technololgy LIMITED 2014/02/13 12.27.0.3326
>SupTab 2014/02/13 1.1.1.0
>sweet-page Browser Protecter sweet-page 2014/02/13
>WPM17.8.0.3325 Cherished Technololgy LIMITED 2014/02/13 17.8.0.3325
>Update for Zip Extractor Update for Zip Extractor 2014/02/13

続いてATFでゴミ掃除したら、ACを起動してまたClean作業してください。

ACの作業が済んだらPCを通常モードで再起動です。
ACのログが出ていたらそれも保存しておいてください。

再起動後、またCCを起動して「Windows」以下の各タブのログを取り直してください。

このあとまたしばらく様子見後、ACとCCの各ログを返信に貼って、状態報告とともにレスください。
  • 悪代官
  • 2014/02/14 (Fri) 20:04:39
やっぱり
やっぱりですか!ACの最新版をダウンロードするとき、変なところをクリックしたようです。今回は慎重にあせらずいきたいので、お伺いします。ATFのゴミ掃除の仕方がわかりません。操作の仕方を教えていただきたいです。お願いします。
  • ryoyoung
  • MAIL
  • 2014/02/15 (Sat) 10:38:02
ATFの使い方につきまして
ATFのご利用方法といたしまして、まずATFを起動します。
Select Allのチェックボックスにチェックを入れ、Empty Selectedをクリックします。

以降の作業は悪代官さんのご指示に従ってください。
  • IVNO
  • MAIL
  • 2014/02/15 (Sat) 13:02:17
Re: 駆除
IVNOさん ATFのご利用方法のお知らせありがとうございました。

  • ryoyoung
  • MAIL
  • 2014/02/15 (Sat) 13:50:03
どっかおかしい?
悪代官様。お忙しい中またよろしくお願いします。
相変わらず、youtubeなどの動画を見ようとするとInternetExPloreは動作を停止し、このWebページを閉じました。と出ます。
今回の問題と関係ないかもしれませが、パソコンを起動するとき、私の導入しているセキュリティーソフト(ウイルスセキュリティー)が「レジストリーに書き込みできません。」と表示されることとは関係ないでしょうか?それとiフィルターは削除できておりません。あとInternetExPloreを起動するときのよくアクセスするサイトにhttp://jp.hao.123.com・・・・やhttp://jp.jst.jstick・・・・のあのよくないサイトがあります。一覧から削除してもアクセスしてないのにまたいつのまにか載っています。とりあえず悪代官さまの指示どうり一通りやりましたので、ログを貼り付けますのでよろしくお願いします。
# AdwCleaner v3.018 - Report created 15/02/2014 at 13:31:46
# Updated 28/01/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : オヤジ - YUNBOO
# Running from : C:\Users\オヤジ\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16518

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]

-\\ Google Chrome v

[ File : C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [4903 octets] - [13/02/2014 15:47:14]
AdwCleaner[R1].txt - [871 octets] - [13/02/2014 15:51:46]
AdwCleaner[R2].txt - [1134 octets] - [15/02/2014 13:31:03]
AdwCleaner[S0].txt - [3095 octets] - [13/02/2014 15:49:51]
AdwCleaner[S1].txt - [931 octets] - [13/02/2014 15:52:23]
AdwCleaner[S2].txt - [992 octets] - [15/02/2014 13:31:46]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1051 octets] ##########
有効 HKLM:Run Adobe ARM Adobe Systems Incorporated "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
有効 HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
有効 HKLM:Run HotKeysCmds Intel Corporation C:\Windows\system32\hkcmd.exe
有効 HKLM:Run iFilter5 デジタルアーツ株式会社 "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5GC.exe" /autorun
有効 HKLM:Run IgfxTray Intel Corporation C:\Windows\system32\igfxtray.exe
有効 HKLM:Run IME14 JPN Setup Microsoft Corporation C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
有効 HKLM:Run K7SystemTray "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
有効 HKLM:Run K7TSStart K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
有効 HKLM:Run LENOVO.TPKNRRES Lenovo Group Limited C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
有効 HKLM:Run LPStation Sony Corporation C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
有効 HKLM:Run mtvManager C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvManager.exe /startup
有効 HKLM:Run Persistence Intel Corporation C:\Windows\system32\igfxpers.exe
有効 HKLM:Run PWMTRV rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
有効 HKLM:Run QuickTime Task Apple Inc. "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
有効 HKLM:Run SynTPEnh Synaptics Incorporated %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
有効 HKLM:Run TpShocks Lenovo. TpShocks.exe
有効 Startup Common Continue installation.lnk Red Sky Sp. z o.o. C:\Users\オヤジ\AppData\Local\Temp\Free_files_downloader.exe
有効 Startup Common PHOTOfunSTUDIO 5.0 HD Edition.lnk Panasonic Corporation C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
有効 Startup Common クライアントマネージャV.lnk BUFFALO INC. C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
有効 Extension Bonjour Apple Inc. C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension このコンテンツを引用 Microsoft Corporation C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
有効 Helper ExplorerWnd Helper IObit C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper C:\Program Files\Java\jre6\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre7\bin\ssv.dll
無効 Helper K7 Web Protection K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
無効 Helper Microsoft アカウント サインイン ヘルパー Microsoft Corp. C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
無効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
無効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL
無効 Helper Windows Live ID Sign-in Helper Microsoft Corp. C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 App Google 讀懃エ「 0.0.0.19 譛€蛻昴・繝ヲ繝シ繧カ繝シ C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
有効 Extension K7 WebProtection 2.3 譛€蛻昴・繝ヲ繝シ繧カ繝シ C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlpfamleaodfgmfnggonbfljhjggbdbe\2.3_0
有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task Digital Sites C:\Users\オヤジ\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE /Check
有効 Task ViewPassword Update C:\Program Files (x86)\ViewPassword\ViewPassword.exe /update
有効 Task {59E8D459-5183-4CE6-9751-16235127E05D} Microsoft Corporation C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{8C2BF804-A884-4C52-8C3B-2A71A808AA98}\setup.exe" -c -IFP5DELETE -removeonly





  • ryoyoung
  • MAIL
  • 2014/02/15 (Sat) 15:10:47
やはりスケジュールに食い込んでますね
レスが遅くなってすみません。

ウイルスセキュリティとi-フィルターでまだ異常が出てますか。
確かにログでわかります。

ではまた以下の手順で作業してください。

またCCを起動して「Windows」タブの下記を右クリックから「無効」にしたあと「エントリの削除」してください。無効化できないときはそのまま削除でもいいです。
>有効 HKLM:Run iFilter5 デジタルアーツ株式会社 "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5GC.exe" /autorun

次に「Chrome」タブの下記も同様に処置してください。
>有効 App Google 讀懃エ「 0.0.0.19 譛€蛻昴・繝ヲ繝シ繧カ繝シ C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0

続いて「スケジュールされたタスク」の下記も同様に処置を。
>有効 Task Digital Sites C:\Users\オヤジ\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE /Check
>有効 Task ViewPassword Update C:\Program Files (x86)\ViewPassword\ViewPassword.exe /update
>有効 Task {59E8D459-5183-4CE6-9751-16235127E05D} Microsoft Corporation C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{8C2BF804-A884-4C52-8C3B-2A71A808AA98}\setup.exe" -c -IFP5DELETE -removeonly

これができたら一度PC再起動後、またしばらく様子見した後に、HJTとインストール情報のログを取り直して、そのログとともに状態報告をレスください。

どうやらスケジュールに食い込んでいたViewPasswordあたりが再発を引き起こしていたようなので、これの処置後に異常が消えれば当たりでしょう
  • 悪代官
  • 2014/02/15 (Sat) 17:22:04
Re: 駆除
お忙しい中またよろしくお願いします。ログを張ります。状態(お使いのコンピュータを保護するためIEはこのWebページを閉じました等)はあまり変わらないようです。何回もすいません・・・
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:04:56, on 2014/02/17
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\EPSON\MyEPSON Connect\mep.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMECMNT.EXE
C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe
C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SysMon.Exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5GC.exe
C:\Users\オヤジ\Downloads\HijackThis.exe
C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: K7 Web Protection - {08B3B4B6-02DA-4658-8BA6-5974E3EBB03D} - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
O2 - BHO: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Microsoft アカウント サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [K7TSStart] C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [LPStation] C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [iFilter5] "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
O4 - HKLM\..\Run: [mtvManager] C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvManager.exe /startup
O4 - HKLM\..\Run: [K7SystemTray] "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series"
O4 - Global Startup: Continue installation.lnk = ?
O4 - Global Startup: PHOTOfunSTUDIO 5.0 HD Edition.lnk = C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
O4 - Global Startup: クライアントマネージャV.lnk = C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: OneNote に送る(&N) - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: OneNote に送る - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: OneNote に送る(&N) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} (DMM Downloader) - http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab
O16 - DPF: {4845B7A7-309F-49F4-A2DD-0117707B6E8D} (DVD Toaster ActiveX Control) - https://toast.dvdtoaster.jp/downloads/activex/x86/dvdtoast.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: Bonjour サービス (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: BWH32S - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EzDetector - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: i-フィルター 5.0 Main (IFP5MainService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
O23 - Service: i-フィルター 5.0 Support (IFP5WatchService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: K7Carnivore Service (K7CrvSvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe
O23 - Service: K7Computng - EMail Proxy Server (K7EmlPxy) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7EmlPxy.exe
O23 - Service: K7Firewall Services (K7FWSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7FWSrvc.exe
O23 - Service: K7Privacy Services (K7PSSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7PSSrvc.exe
O23 - Service: K7RealTime AntiVirus Services (K7RTScan) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7RTScan.exe
O23 - Service: K7SpmSrc - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SpmSrc.exe
O23 - Service: K7TotalSecurity Manager (K7TSMngr) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSMngr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: LISMO PIM Service - CASIO SOFT CO. LTD. - C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: I-O DATA mAgicTV Digital (mAgicTVDigital) - I-O DATA DEVICE, INC. - C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyEPSON Connect Service - SEIKO EPSON CORPORATION - C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NlsSrv32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SD Device Manager - Panasonic Corporation - C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: SonicStage Back-End Service2 - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14688 bytes

Access Help Lenovo 2011/02/09 3.00
Adobe Flash Player 12 ActiveX Adobe Systems Incorporated 2014/02/07 6.00 MB 12.0.0.44
Adobe Reader XI (11.0.06) - Japanese Adobe Systems Incorporated 2014/02/12 147 MB 11.0.06
Apple Application Support Apple Inc. 2013/10/01 64.0 MB 2.3.6
Apple Mobile Device Support Apple Inc. 2013/10/01 25.0 MB 7.0.0.117
au ISW11K USB Driver 京セラ株式会社 2012/03/01 1.00.0000
au T008 USB Driver Ver.5.0.0.1 2011/09/24 V5.24.1.0
Bonjour Apple Inc. 2014/02/03 3.29 MB 1.0.106
BUFFALO エアステーション設定ツール BUFFALO INC. 2011/09/25 2.84 MB 2.0.5
BUFFALO クライアントマネージャV BUFFALO INC. 2011/09/25
BUFFALO パソコン環境表示ツール BUFFALO INC. 2011/09/25 1.0.3
Corel DVD MovieWriter Lenovo Edition Corel Corporation 2011/02/09 320 MB 7.0.0
Corel TVX Corel Corporation 2014/02/03 31.2 MB 2.2-B0.5
Create Recovery Media Lenovo Group Limited 2011/02/09 9.50 MB 1.20.0.00
DVD Decrypter (Remove Only) 2011/02/18
DVD Flick 1.3.0.7 Dennis Meuwissen 2012/05/05 1.3.0.7
DVD Shrink 3.2 DVD Shrink 2011/02/18
Epson E-Photo SEIKO EPSON CORPORATION 2014/02/16 1.4.1.0
Epson E-Web Print SEIKO EPSON CORPORATION 2014/02/16 9.22 MB 1.19.0000
EPSON EP-706A Series プリンター アンインストール SEIKO EPSON Corporation 2014/02/16
Epson Event Manager Seiko Epson Corporation 2014/02/16 42.4 MB 3.10.0017
Epson Print CD SEIKO EPSON CORPORATION 2014/02/16 2.21.00
EPSON Scan Seiko Epson Corporation 2014/02/16
EPSON Scan OCR コンポーネント SEIKO EPSON Corp. 2014/02/16 1.33.0000
EPSON マニュアル SEIKO EPSON CORPORATION 2014/02/16 704 KB 1.32.0.0
EpsonNet Print SEIKO EPSON CORPORATION 2014/02/16 2.6.0
I-O DATA mAgicTV Digital I-O DATA DEVICE,INC. 2014/02/03 1.01.00
IL Download Manager Image-Line 2011/11/05
Intel(R) Control Center Intel Corporation 2011/02/09 1.2.1.1007
Intel(R) Graphics Media Accelerator Driver Intel Corporation 2011/02/09 8.15.10.2125
Intel(R) Management Engine Components Intel Corporation 2011/02/09 6.0.0.1179
InterVideo WinDVD 8 InterVideo Inc. 2011/02/09 163 MB 8.0.20.199
IObit Uninstaller IObit 2014/02/08 3.1.7.2405
Java 7 Update 51 Oracle 2014/02/08 118 MB 7.0.510
Jw_cad 2014/01/29
Lenovo Auto Scroll Utility 2011/02/09 1.00
Lenovo Patch Utility Lenovo Group Limited 2013/05/12 1.33 MB 1.3.1.1
Lenovo Patch Utility 64 bit Lenovo Group Limited 2013/05/12 1.35 MB 1.3.1.1
Lenovo System Interface Driver 2013/05/12 1.05
Lenovo System Update Lenovo 2013/07/16 13.4 MB 5.02.0018
Lenovo ThinkVantage Toolbox PC-Doctor, Inc. 2011/02/09 6.0.5717.21
Lenovo Warranty Information Lenovo 2011/02/09 893 KB 1.0.0004.00
Lenovo Welcome Lenovo 2011/02/09
LISMO Port 5.1 Sony Corporation 2013/03/10 110 MB 5.1
Message Center Plus Lenovo Group Limited 2011/02/09 1.70 MB 2.0.0012.00
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 2011/02/27 38.8 MB 4.0.30319
Microsoft Office Home and Business 2010 Microsoft Corporation 2013/11/03 14.0.7015.1000
Microsoft Office Word Viewer 2003 Microsoft Corporation 2014/01/16 105 MB 11.0.8173.0
Microsoft Silverlight Microsoft Corporation 2013/10/10 149 MB 5.1.20913.0
Microsoft SkyDrive Microsoft Corporation 2013/01/15 25.1 MB 16.4.6013.0910
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2011/02/09 1.69 MB 3.1.0000
Microsoft SQL Server Compact 3.5 SP1 English Microsoft Corporation 2011/02/28 2.59 MB 3.5.5692.0
Microsoft SQL Server Compact 3.5 SP1 x64 English Microsoft Corporation 2011/02/28 3.69 MB 3.5.5692.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 Microsoft Corporation 2011/02/26 260 KB 8.0.50727.4053
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 2011/02/26 250 KB 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2014/02/03 2.38 MB 8.0.59193
Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 2011/02/09 840 KB 8.0.61000
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2013/10/01 248 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2011/02/16 784 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 2011/06/20 788 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2011/03/17 234 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2011/02/16 592 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2011/06/20 600 KB 9.0.30729.6161
Mobile Broadband Lenovo 2011/02/09 16.4 MB 3.6.0034
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2011/02/18 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2011/02/18 1.33 MB 4.20.9876.0
MyEPSON Portal SEIKO EPSON Corporation 2014/02/16
PHOTOfunSTUDIO 5.0 HD Edition Panasonic Corporation 2011/02/28 5.00.313
QuickTime Apple Inc. 2012/11/07 73.2 MB 7.72.80.56
Registry Patch to arrange icons in Device and Printers folder of Windows 7 2011/02/09 1.00
Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7 2011/02/09 1.00
Rescue and Recovery Lenovo Group Limited 2013/05/12 101 MB 4.31.0005.00
SAMSUNG USB Driver for Mobile Phones SAMSUNG Electronics Co., Ltd. 2013/08/07 42.9 MB 1.5.16.0
Software Updater SEIKO EPSON CORPORATION 2014/02/16 8.19 MB 4.2.1
SonicStage 4.4 Sony Corporation 2012/02/15 4.4
Sony Media Library Earth 8.1.00 Sony Corporation 2013/03/10 47.3 MB 8.1.00.11292
ThinkPad Power Management Driver 2011/02/09 1.60.0.4
ThinkPad UltraNav Driver 2011/02/16 46.4 MB 15.0.18.0
ThinkPad Wireless LAN Adapter Software REALTEK Semiconductor Corp. 2011/02/09 1.00.0024.0
ThinkPad 省電力マネージャー 2011/02/09 3.30
ThinkVantage Communications Utility Lenovo 2011/02/09 2.43 MB 1.41
ThinkVantage ハードディスク・アクティブプロテクション・システム Lenovo 2011/02/09 15.6 MB 1.74
USB Video/Audio Device Driver 会社名 2012/07/29 15.4 MB 1.00.0000
Windows Live Essentials Microsoft Corporation 2013/01/15 16.4.3505.0912
Windows ドライバ パッケージ - I-O DATA DEVICE, INC. GV-MVP/FZ(x64) (11/29/2010 1.8.2.12) I-O DATA DEVICE, INC. 2014/02/03 11/29/2010 1.8.2.12
Windows ドライバ パッケージ - Intel (iaStor) hdc (01/15/2010 9.5.7.1002) Intel 2011/02/09 01/15/2010 9.5.7.1002
Windows ドライバ パッケージ - Intel hdc (06/04/2009 7.0.0.1013) Intel 2011/02/09 06/04/2009 7.0.0.1013
Windows ドライバ パッケージ - Intel System (06/04/2009 1.0.0.0002) Intel 2011/02/09 06/04/2009 1.0.0.0002
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/09 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/10 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel USB (08/20/2009 9.1.1.1020) Intel 2011/02/09 08/20/2009 9.1.1.1020
Windows ドライバ パッケージ - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4) Lenovo 2011/02/09 11/18/2009 1.60.0.4
Windows ドライバ パッケージ - Realtek Semiconductor Corp. HD Audio Driver (06/29/2010 6.0.1.6146) Realtek Semiconductor Corp. 2011/02/09 06/29/2010 6.0.1.6146
インテル(R) ターボ・ブースト・テクノロジー・モニター インテル 2011/02/09 1.13 MB 1.0.186.3
ウイルスセキュリティ ソースネクスト株式会社 2012/09/18 12.00
読んde!!ココ パーソナル 2014/02/16
  • ryoyoung
  • MAIL
  • 2014/02/17 (Mon) 11:18:57
HJTから処置してみましょう
またレスが遅くなってすみません。

>状態(お使いのコンピュータを保護するためIEはこのWebページを閉じました等)はあまり変わらないようです

はい、修復できないまま手間ばかりかけてすみません。

それではHJTで処置しましょう。

PCをセーフモードで起動して、HJTでスキャン後、以下のエントリをfixしてください。
>O4 - HKLM\..\Run: [iFilter5] "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
>O23 - Service: i-フィルター 5.0 Main (IFP5MainService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
>O23 - Service: i-フィルター 5.0 Support (IFP5WatchService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe

ここにi-フィルターがまだ残っているので、HJTから処置します。

これができたらPCを通常モードで再起動後、また様子見後に状態報告をレスください
  • 悪代官
  • 2014/02/17 (Mon) 17:11:56
最後までよろしくお願いします。
こちらこそ、操作ミスをしたりしてお手間かけます。最初はリカバリーを考えていたのですが、乗りかかった船です。最後まで頑張ってみたいので、よろしくお願いします。やはりiフィルターは残ったままです。HJTの処置の仕方が間違っていたのか確認ねがいます。
1、HJT起動、scan
2、O4 - HKLM >O23 - Service: i-フィルター 5.0 Main >O23 - Service: i-フィルター 5.0 Support (IFP5WatchService) - デジタルアーツ株式会社にチェックを入れ 
3、FIXcheckedを押しました。
4、FIX3seleteditemsなんとら、かんとらでハイ
5、Unable to createnなんとら、かんとらでOKと操作しました。
でも再起動したらタスクバーに残っています。
ちなみに同じ操作を2度し、fixした後ふたたびscanしましたら、O4 - HKLM\..\Run: [iFilter5] "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorunはありませんでしたが、O23 - Service: i-フィルター 5.0 Main (IFP5MainService) - デジタルアーツ株式会社とO23 - Service: i-フィルター 5.0 Support (IFP5WatchService) - デジタルアーツ株式会社は残っておりました。お時間の都合のよい時でいいのでよろしくお願いします。
  • ryoyoung
  • MAIL
  • 2014/02/17 (Mon) 18:32:48
HJTのログを確認します
作業と報告、ご苦労様です。
HJTのfixでO4エントリは処置できたみたいですがO23エントリが残ったわけですか?
では一応ログを確認しましょう。
再度HJTを起動して、そのログだけとって、それをレスで見せてください。今度は通常モードでの作業でいいです
  • 悪代官
  • 2014/02/17 (Mon) 18:39:56
Re: 駆除
了解しました。HJTのログを張ります。
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:43:52, on 2014/02/17
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\EPSON\MyEPSON Connect\mep.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMECMNT.EXE
C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe
C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5GC.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SysMon.Exe
C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe
C:\Users\オヤジ\Downloads\HijackThis.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMECMNT.EXE

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: K7 Web Protection - {08B3B4B6-02DA-4658-8BA6-5974E3EBB03D} - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
O2 - BHO: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Microsoft アカウント サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [K7TSStart] C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [LPStation] C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [mtvManager] C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvManager.exe /startup
O4 - HKLM\..\Run: [K7SystemTray] "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
O4 - HKLM\..\Run: [iFilter5] "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Continue installation.lnk = ?
O4 - Global Startup: PHOTOfunSTUDIO 5.0 HD Edition.lnk = C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
O4 - Global Startup: クライアントマネージャV.lnk = C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: OneNote に送る(&N) - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: OneNote に送る - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: OneNote に送る(&N) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} (DMM Downloader) - http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab
O16 - DPF: {4845B7A7-309F-49F4-A2DD-0117707B6E8D} (DVD Toaster ActiveX Control) - https://toast.dvdtoaster.jp/downloads/activex/x86/dvdtoast.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: Bonjour サービス (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: BWH32S - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EzDetector - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: i-フィルター 5.0 Main (IFP5MainService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
O23 - Service: i-フィルター 5.0 Support (IFP5WatchService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: K7Carnivore Service (K7CrvSvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe
O23 - Service: K7Computng - EMail Proxy Server (K7EmlPxy) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7EmlPxy.exe
O23 - Service: K7Firewall Services (K7FWSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7FWSrvc.exe
O23 - Service: K7Privacy Services (K7PSSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7PSSrvc.exe
O23 - Service: K7RealTime AntiVirus Services (K7RTScan) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7RTScan.exe
O23 - Service: K7SpmSrc - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SpmSrc.exe
O23 - Service: K7TotalSecurity Manager (K7TSMngr) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSMngr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: LISMO PIM Service - CASIO SOFT CO. LTD. - C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: I-O DATA mAgicTV Digital (mAgicTVDigital) - I-O DATA DEVICE, INC. - C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyEPSON Connect Service - SEIKO EPSON CORPORATION - C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NlsSrv32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SD Device Manager - Panasonic Corporation - C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: SonicStage Back-End Service2 - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 15195 bytes
  • ryoyoung
  • MAIL
  • 2014/02/17 (Mon) 20:48:46
では通常モードでHJT処置を
HJTのログも見せてもらいました。
やはり下記が残ってますね。
>O23 - Service: i-フィルター 5.0 Main (IFP5MainService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
>O23 - Service: i-フィルター 5.0 Support (IFP5WatchService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe

では今度はPCを通常モードでいいので、他のアプリを起動しない状態でHJTでスキャンして、上記のエントリをfixしたあと、一度HJTを終了してから再度起動して、またHJTのログだけ取り直して、それを状態報告とともにレスください。

手探りでの作業になってなかなか進まなくてすみません
  • 悪代官
  • 2014/02/17 (Mon) 21:06:35
Re: 駆除
ご苦労様です。状態は変化なしです。相変わらず、InternetExPloreを起動するときのよくアクセスするサイトにhttp://jp.hao.123.com・・・・やhttp://jp.jst.jstick・・・・が全然アクセスしてないのに載っています。一覧から削除してもまた、いつの間にか載っています。ログを張ります。お手数かけます。
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:15:03, on 2014/02/18
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\EPSON\MyEPSON Connect\mep.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMECMNT.EXE
C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe
C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SysMon.Exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5GC.exe
C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
C:\Users\オヤジ\Downloads\HijackThis.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMECMNT.EXE

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: K7 Web Protection - {08B3B4B6-02DA-4658-8BA6-5974E3EBB03D} - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
O2 - BHO: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Microsoft アカウント サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [K7TSStart] C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [LPStation] C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [mtvManager] C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvManager.exe /startup
O4 - HKLM\..\Run: [K7SystemTray] "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
O4 - HKLM\..\Run: [iFilter5] "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Continue installation.lnk = ?
O4 - Global Startup: PHOTOfunSTUDIO 5.0 HD Edition.lnk = C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
O4 - Global Startup: クライアントマネージャV.lnk = C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: OneNote に送る(&N) - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: OneNote に送る - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: OneNote に送る(&N) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\ifp5lsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} (DMM Downloader) - http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab
O16 - DPF: {4845B7A7-309F-49F4-A2DD-0117707B6E8D} (DVD Toaster ActiveX Control) - https://toast.dvdtoaster.jp/downloads/activex/x86/dvdtoast.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: Bonjour サービス (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: BWH32S - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EzDetector - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: i-フィルター 5.0 Main (IFP5MainService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
O23 - Service: i-フィルター 5.0 Support (IFP5WatchService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: K7Carnivore Service (K7CrvSvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe
O23 - Service: K7Computng - EMail Proxy Server (K7EmlPxy) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7EmlPxy.exe
O23 - Service: K7Firewall Services (K7FWSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7FWSrvc.exe
O23 - Service: K7Privacy Services (K7PSSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7PSSrvc.exe
O23 - Service: K7RealTime AntiVirus Services (K7RTScan) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7RTScan.exe
O23 - Service: K7SpmSrc - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SpmSrc.exe
O23 - Service: K7TotalSecurity Manager (K7TSMngr) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSMngr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: LISMO PIM Service - CASIO SOFT CO. LTD. - C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: I-O DATA mAgicTV Digital (mAgicTVDigital) - I-O DATA DEVICE, INC. - C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyEPSON Connect Service - SEIKO EPSON CORPORATION - C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NlsSrv32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SD Device Manager - Panasonic Corporation - C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: SonicStage Back-End Service2 - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 15129 bytes
  • ryoyoung
  • MAIL
  • 2014/02/18 (Tue) 09:07:33
OTLで調べます
作業と報告、ご苦労様です。
今回はかなりしぶといですね。
ではいよいよ自分が何とか指示できる範囲での最終兵器を使いましょう。

以下のツールを準備してください。
OTL(OldTimer Listit)
これはHJTやCC以上に高い解析力を持つツールで、特に厄介な事例では決定打となったことが多いものです。これを使って調べます。
ファイル直リンなので、DLしたら保存しておいてください。
http://oldtimer.geekstogo.com/OTL.exe
片付けるときは起動後に「Cleanup」ボタンを押せば自動で削除されます。

他のプログラムを起動しない状態でOTLを起動してください。
起動したら、ウィンドウの上の方にある「Scan All Users」にチェックを入れ、以下のコマンドを「Custom Scan/Fixes」にコピペしてください。

%SYSTEMDRIVE%\*.exe
CREATERESTOREPOINT

その後、左上の「Run Scan」を押すとスキャン開始されます。
スキャン開始後、PC環境にもよりますが数分ほどすると、「OTL.txt」と「Extras.txt」がOTL.exeと同じ場所に作成されるはずなので、この2つのファイルをデスクトップあたりに保存しておいてください。
なお、Extras.txtは出ないこともありますが、その場合はOTL.txtだけでもいいです。

このあとOTLのログを返信に貼って、それをレスで見せてください。
OTLでスキャンしただけでは良くも悪くも変化は起きません。
この結果を見て、次回以降の作業で処置することになるでしょう
  • 悪代官
  • 2014/02/18 (Tue) 11:30:34
Re: 駆除
ほんとにお手数かけます!ログを張ります
OTL logfile created on: 2014/02/18 14:42:26 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\オヤジ\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

3.80 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 51.02% Memory free
7.60 Gb Paging File | 5.37 Gb Available in Paging File | 70.63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 454.82 Gb Total Space | 292.17 Gb Free Space | 64.24% Space Free | Partition Type: NTFS
Drive D: | 7.36 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive Q: | 9.77 Gb Total Space | 2.60 Gb Free Space | 26.60% Space Free | Partition Type: NTFS

Computer Name: YUNBOO | User Name: オヤジ | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2014/02/18 14:39:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\オヤジ\Downloads\OTL.exe
PRC - [2013/12/21 15:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/11/11 18:49:06 | 000,208,920 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7rtscan.exe
PRC - [2013/10/25 14:53:10 | 000,243,736 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7fwsrvc.exe
PRC - [2013/10/05 12:43:22 | 000,242,848 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsmngr.exe
PRC - [2013/09/13 15:28:58 | 002,387,520 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\epson\MyEPSON Connect\mep.exe
PRC - [2013/09/03 23:33:16 | 000,335,384 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7pssrvc.exe
PRC - [2013/04/02 17:14:02 | 000,154,136 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7emlpxy.exe
PRC - [2013/03/28 15:55:58 | 001,058,880 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
PRC - [2013/01/01 17:45:46 | 000,163,504 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe
PRC - [2012/12/12 15:28:06 | 005,812,912 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
PRC - [2012/11/29 21:07:14 | 002,197,600 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe
PRC - [2012/10/01 16:17:38 | 000,703,616 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\epson\MyEPSON Connect\mepService.exe
PRC - [2011/12/21 23:16:54 | 000,262,752 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe
PRC - [2011/11/05 20:50:19 | 000,072,800 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SysMon.Exe
PRC - [2011/03/17 20:40:57 | 000,382,360 | ---- | M] (デジタルアーツ株式会社) -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe
PRC - [2011/03/17 20:40:52 | 000,681,368 | ---- | M] (デジタルアーツ株式会社) -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
PRC - [2011/03/17 20:40:36 | 001,922,456 | ---- | M] (デジタルアーツ株式会社) -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5GC.exe
PRC - [2011/03/17 20:40:30 | 000,947,608 | ---- | M] (デジタルアーツ株式会社) -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5control_manager.exe
PRC - [2011/03/17 20:40:27 | 001,172,888 | ---- | M] (デジタルアーツ株式会社) -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5bigbrother.exe
PRC - [2010/12/02 16:08:28 | 000,210,784 | ---- | M] (InterVideo Inc.) -- C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
PRC - [2010/11/01 13:15:46 | 000,053,248 | ---- | M] (I-O DATA DEVICE, INC.) -- C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe
PRC - [2010/08/20 14:21:08 | 001,028,096 | ---- | M] (Lenovo Group Limited) -- C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
PRC - [2010/05/24 10:52:38 | 000,208,760 | ---- | M] (BUFFALO INC.) -- C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
PRC - [2010/04/28 09:58:52 | 000,172,544 | ---- | M] (Panasonic Corporation) -- C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
PRC - [2010/04/20 13:23:32 | 000,074,088 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
PRC - [2010/04/20 13:23:28 | 000,062,312 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
PRC - [2010/04/20 13:23:18 | 000,050,536 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\CamMute.exe
PRC - [2010/04/07 14:37:40 | 000,093,032 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe
PRC - [2010/04/01 14:50:46 | 000,043,960 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
PRC - [2009/11/04 13:45:46 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009/11/04 13:45:44 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009/09/02 19:20:18 | 000,071,064 | ---- | M] (Panasonic Corporation) -- C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe
PRC - [2009/07/09 10:18:24 | 000,126,328 | ---- | M] (BUFFALO INC.) -- C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe
PRC - [2009/07/02 16:55:00 | 000,032,248 | ---- | M] (CASIO SOFT CO. LTD.) -- C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe
PRC - [2009/06/07 13:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\SysWOW64\NlsSrv32.exe
PRC - [2009/05/27 22:09:36 | 000,049,976 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
PRC - [2007/06/15 12:57:42 | 000,145,504 | ---- | M] (B.H.A Corporation) -- C:\Windows\SysWOW64\bgsvcgen.exe
PRC - [2007/01/04 19:48:50 | 000,112,152 | ---- | M] (InterVideo) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2013/10/28 07:46:26 | 004,554,752 | ---- | M] () -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
MOD - [2013/09/05 00:14:10 | 004,300,456 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2013/07/22 07:48:15 | 002,052,096 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll
MOD - [2013/07/22 07:48:15 | 000,425,984 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
MOD - [2012/12/12 14:32:26 | 005,025,792 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
MOD - [2012/10/05 19:53:24 | 003,198,976 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
MOD - [2012/10/05 19:53:24 | 000,630,784 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
MOD - [2011/02/28 21:01:03 | 000,271,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Data.SqlServerCe\3.5.1.0__89845dcd8080cc91\System.Data.SqlServerCe.dll
MOD - [2010/11/13 09:00:19 | 000,348,160 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_ja_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010/11/05 10:58:08 | 000,258,048 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
MOD - [2010/11/05 10:58:05 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2009/07/09 10:18:32 | 000,055,160 | ---- | M] () -- C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32SPS.dll
MOD - [2009/07/02 16:55:00 | 000,024,056 | ---- | M] () -- C:\Program Files (x86)\Sony\LISMO Port\LPPIMTools.dll
MOD - [2009/06/11 06:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009/06/11 06:22:40 | 000,010,752 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
MOD - [2009/05/27 22:09:36 | 000,049,976 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2014/02/06 19:48:45 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2013/05/27 14:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2012/05/17 00:00:00 | 000,144,560 | ---- | M] (Seiko Epson Corporation) [Auto | Running] -- C:\Windows\SysNative\escsvc64.exe -- (EpsonScanSvc)
SRV:[b]64bit:[/b] - [2011/01/13 14:05:46 | 000,047,728 | ---- | M] (Lenovo.) [On_Demand | Stopped] -- C:\Windows\SysNative\TPHDEXLG64.exe -- (TPHDEXLGSVC)
SRV:[b]64bit:[/b] - [2010/04/20 13:23:32 | 000,074,088 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe -- (LENOVO.TPKNRSVC)
SRV:[b]64bit:[/b] - [2010/04/20 13:23:18 | 000,050,536 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\Communications Utility\CamMute.exe -- (LENOVO.CAMMUTE)
SRV:[b]64bit:[/b] - [2010/04/07 14:37:40 | 000,093,032 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC)
SRV:[b]64bit:[/b] - [2009/12/21 10:44:06 | 000,535,552 | ---- | M] (CSR, plc) [Auto | Running] -- C:\Windows\SysNative\HFGService.dll -- (HFGService)
SRV:[b]64bit:[/b] - [2009/11/18 14:04:24 | 000,045,928 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Windows\SysNative\ibmpmsvc.exe -- (IBMPMSVC)
SRV:[b]64bit:[/b] - [2009/09/29 17:25:48 | 000,126,392 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV - [2014/02/08 15:39:42 | 002,151,744 | ---- | M] (IObit) [Auto | Stopped] -- C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe -- (LiveUpdateSvc)
SRV - [2014/02/07 17:48:43 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/12/21 15:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/11/11 18:49:06 | 000,208,920 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7rtscan.exe -- (K7RTScan)
SRV - [2013/10/25 14:53:10 | 000,243,736 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7fwsrvc.exe -- (K7FWSrvc)
SRV - [2013/10/05 12:43:22 | 000,242,848 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsmngr.exe -- (K7TSMngr)
SRV - [2013/09/03 23:33:16 | 000,335,384 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7pssrvc.exe -- (K7PSSrvc)
SRV - [2013/06/26 15:57:38 | 000,022,376 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2013/04/02 17:14:02 | 000,154,136 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7emlpxy.exe -- (K7EmlPxy)
SRV - [2012/12/12 15:28:04 | 000,131,760 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe -- (SonicStage Back-End Service2)
SRV - [2012/11/29 21:07:14 | 002,197,600 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe -- (EzDetector)
SRV - [2012/11/29 13:31:28 | 000,174,176 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2012/10/01 16:17:38 | 000,703,616 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files (x86)\epson\MyEPSON Connect\mepService.exe -- (MyEPSON Connect Service)
SRV - [2012/06/21 20:45:52 | 000,281,216 | ---- | M] (K7 Computing Pvt Ltd) [On_Demand | Stopped] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SpmSrc.exe -- (K7SpmSrc)
SRV - [2011/12/21 23:16:54 | 000,262,752 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe -- (K7CrvSvc)
SRV - [2011/03/17 20:40:57 | 000,382,360 | ---- | M] (デジタルアーツ株式会社) [Auto | Running] -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe -- (IFP5WatchService)
SRV - [2011/03/17 20:40:52 | 000,681,368 | ---- | M] (デジタルアーツ株式会社) [Auto | Running] -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe -- (IFP5MainService)
SRV - [2010/12/02 16:08:28 | 000,210,784 | ---- | M] (InterVideo Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service)
SRV - [2010/11/01 13:15:46 | 000,053,248 | ---- | M] (I-O DATA DEVICE, INC.) [Auto | Running] -- C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe -- (mAgicTVDigital)
SRV - [2010/08/25 03:30:00 | 000,075,112 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe -- (Power Manager DBC Service)
SRV - [2010/08/20 14:21:08 | 001,028,096 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service)
SRV - [2009/11/04 13:45:46 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009/11/04 13:45:44 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009/09/02 19:20:18 | 000,071,064 | ---- | M] (Panasonic Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe -- (SD Device Manager)
SRV - [2009/07/09 10:18:24 | 000,126,328 | ---- | M] (BUFFALO INC.) [Auto | Running] -- C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe -- (BWH32S)
SRV - [2009/07/02 16:55:00 | 000,032,248 | ---- | M] (CASIO SOFT CO. LTD.) [Auto | Running] -- C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe -- (LISMO PIM Service)
SRV - [2009/06/11 06:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/07 13:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\Windows\SysWOW64\NlsSrv32.exe -- (nlsX86cc)
SRV - [2007/12/17 13:21:00 | 000,075,040 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe -- (SSScsiSV)
SRV - [2007/12/17 13:20:56 | 000,107,808 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe -- (SonicStage Back-End Service)
SRV - [2007/06/15 12:57:42 | 000,145,504 | ---- | M] (B.H.A Corporation) [Auto | Running] -- C:\Windows\SysWOW64\bgsvcgen.exe -- (bgsvcgen)
SRV - [2007/01/04 19:48:50 | 000,112,152 | ---- | M] (InterVideo) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2013/10/18 15:02:54 | 001,199,904 | ---- | M] (K7 Computing Pvt Ltd) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\K7Sentry.Sys -- (K7Sentry)
DRV:[b]64bit:[/b] - [2013/09/18 20:45:36 | 000,108,320 | ---- | M] (K7 Computing Pvt Ltd) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\K7FWHlpr.Sys -- (K7FWHlpr)
DRV:[b]64bit:[/b] - [2012/12/13 14:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:[b]64bit:[/b] - [2012/09/12 15:20:04 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:[b]64bit:[/b] - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:[b]64bit:[/b] - [2012/08/15 15:24:54 | 000,056,336 | ---- | M] (Corel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:[b]64bit:[/b] - [2012/03/01 15:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2011/03/11 15:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011/03/11 15:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2011/01/13 14:04:20 | 000,139,888 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsX64.sys -- (Shockprf)
DRV:[b]64bit:[/b] - [2011/01/13 14:02:28 | 000,023,664 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsHM64.sys -- (TPDIGIMN)
DRV:[b]64bit:[/b] - [2010/11/29 20:19:26 | 000,477,432 | ---- | M] (I-O DATA DEVICE, INC.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\gvmvpfz_x64.sys -- (GVMVPFZ)
DRV:[b]64bit:[/b] - [2010/11/29 05:23:18 | 012,252,192 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2010/11/20 22:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010/11/20 20:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2010/11/20 18:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2010/11/15 07:36:50 | 000,175,688 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\t008mdm.sys -- (t008mdm)
DRV:[b]64bit:[/b] - [2010/11/15 07:36:50 | 000,019,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\t008mdfl.sys -- (t008mdfl)
DRV:[b]64bit:[/b] - [2010/11/15 07:36:48 | 000,154,696 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\t008bus.sys -- (t008bus)
DRV:[b]64bit:[/b] - [2010/11/15 07:36:48 | 000,149,064 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\t008kmmo.sys -- (t008kmmo)
DRV:[b]64bit:[/b] - [2010/11/12 10:34:44 | 000,025,072 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- c:\Program Files\PC-Doctor\pcdsrvc_x64.pkms -- (PCDSRVC{127174DC-C366ED8B-06020101}_0)
DRV:[b]64bit:[/b] - [2010/09/07 14:09:34 | 000,015,472 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\smiifx64.sys -- (lenovo.smi)
DRV:[b]64bit:[/b] - [2010/08/25 03:30:00 | 000,013,104 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\TPPWR64V.SYS -- (TPPWRIF)
DRV:[b]64bit:[/b] - [2010/08/20 03:45:28 | 000,654,720 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emBDA64.sys -- (USB28xxBGA)
DRV:[b]64bit:[/b] - [2010/08/20 03:44:48 | 000,943,872 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emOEM64.sys -- (USB28xxOEM)
DRV:[b]64bit:[/b] - [2010/08/17 11:51:50 | 000,143,992 | ---- | M] (Cobalt Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\DTH10_Series.sys -- (DTH10_Series)
DRV:[b]64bit:[/b] - [2010/05/17 17:32:56 | 001,107,488 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192se.sys -- (rtl8192se)
DRV:[b]64bit:[/b] - [2010/04/23 09:17:40 | 000,318,000 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2010/02/26 16:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:[b]64bit:[/b] - [2010/02/03 06:38:30 | 000,271,872 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2010/01/16 05:22:08 | 000,538,136 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:[b]64bit:[/b] - [2009/12/21 10:43:36 | 000,052,224 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAudioHF.sys -- (BthAudioHF)
DRV:[b]64bit:[/b] - [2009/12/21 10:43:00 | 000,078,848 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthav.sys -- (csr_a2dp)
DRV:[b]64bit:[/b] - [2009/11/18 14:04:04 | 000,032,880 | ---- | M] (Lenovo.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ibmpmdrv.sys -- (IBMPMDRV)
DRV:[b]64bit:[/b] - [2009/09/29 17:25:50 | 000,012,728 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:[b]64bit:[/b] - [2009/09/17 12:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:[b]64bit:[/b] - [2009/08/13 08:38:24 | 000,029,184 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcp.sys -- (BthAvrcp)
DRV:[b]64bit:[/b] - [2009/07/14 10:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/14 10:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/14 10:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/07/14 08:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2009/07/02 11:16:02 | 000,040,512 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\psadd.sys -- (psadd)
DRV:[b]64bit:[/b] - [2009/06/11 06:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:[b]64bit:[/b] - [2009/06/11 06:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:[b]64bit:[/b] - [2009/06/11 06:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:[b]64bit:[/b] - [2009/06/11 05:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/11 05:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2008/02/15 15:01:22 | 000,165,120 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfbd.sys -- (tosrfbd)
DRV:[b]64bit:[/b] - [2008/01/31 15:55:24 | 000,088,448 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV:[b]64bit:[/b] - [2008/01/22 20:58:12 | 000,056,320 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TosRfSnd.sys -- (TosRfSnd)
DRV:[b]64bit:[/b] - [2007/11/29 09:45:58 | 000,044,800 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfbnp.sys -- (tosrfbnp)
DRV:[b]64bit:[/b] - [2007/10/18 14:25:00 | 000,051,328 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfusb.sys -- (Tosrfusb)
DRV:[b]64bit:[/b] - [2007/10/02 11:43:08 | 000,076,160 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfcom.sys -- (Tosrfcom)
DRV:[b]64bit:[/b] - [2007/08/17 14:48:40 | 000,018,432 | ---- | M] (BUFFALO INC.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bufeap64.sys -- (Bufeap)
DRV:[b]64bit:[/b] - [2007/01/12 20:28:06 | 000,077,312 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emAudio64.sys -- (emAudio)
DRV:[b]64bit:[/b] - [2006/10/11 16:31:00 | 000,050,688 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosporte.sys -- (tosporte)
DRV:[b]64bit:[/b] - [2005/07/13 06:43:00 | 000,028,160 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfnds.sys -- (tosrfnds)
DRV - [2009/07/14 10:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2007/01/23 15:56:58 | 000,146,432 | ---- | M] (K7 Computing Pvt Ltd) [File_System | Boot | Running] -- C:\Windows\SysWOW64\drivers\K7Sentry.sys -- (K7Sentry)
DRV - [2006/11/21 22:27:16 | 000,009,728 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysWOW64\drivers\K7FWHlpr.sys -- (K7FWHlpr)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{B51E6D5A-A882-4912-A29B-EDB8314596EC}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.bing.com/search?q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/search?q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{D89871C2-CB62-42D8-B61C-D16CC24D22D6}: "URL" = http://search.certified-toolbar.com?si=41460&bs=true&tid=2996&q={searchTerms}


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/jp/ja [binary data]
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.jp/
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


[color=#E56717]========== FireFox ==========[/color]

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@k7computing.com/k7webprotection: C:\Program Files (x86)\\K7 Computing\K7TSecurity\npK7SRNPExt.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\k7srff@k7computing.com: C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SR [2014/02/07 16:29:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\e-webprint@epson.com: C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2014/02/16 18:57:37 | 000,000,000 | ---D | M]


[color=#E56717]========== Chrome ==========[/color]

CHR - homepage: http://www.google.com/
CHR - homepage: http://jp.hao123.com/?tn=epom_pay_hp_04_hao123_jp
CHR - Extension: K7 WebProtection = C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlpfamleaodfgmfnggonbfljhjggbdbe\2.3_0\
CHR - Extension: K7 WebProtection = C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/11 06:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (ExplorerWnd Helper) - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
O2:[b]64bit:[/b] - BHO: (E-Photo) - {60B127CA-8AA4-4DCD-84A8-D18C2B2C4A96} - C:\Program Files (x86)\EPSON Software\E-Photo\EPTBL.dll (SEIKO EPSON CORPORATION)
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (K7 Web Protection) - {08B3B4B6-02DA-4658-8BA6-5974E3EBB03D} - C:\Program Files (x86)\K7 Computing\K7TSecurity\k7srext.dll (K7 Computing Pvt Ltd)
O2 - BHO: (E-Web Print) - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (E-Photo) - {60B127CA-8AA4-4DCD-84A8-D18C2B2C4A96} - C:\Program Files (x86)\EPSON Software\E-Photo\EPTBL.dll (SEIKO EPSON CORPORATION)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (E-Web Print) - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\..\Toolbar\WebBrowser: (no name) - {AEF44653-C059-42CB-A5B7-41C640DA4A67} - No CLSID value found.
O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe (Lenovo Group Limited)
O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [TpShocks] C:\Windows\SysNative\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [iFilter5] C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe (デジタルアーツ株式会社)
O4 - HKLM..\Run: [K7SystemTray] "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe" File not found
O4 - HKLM..\Run: [K7TSStart] C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe (K7 Computing Pvt Ltd)
O4 - HKLM..\Run: [LPStation] C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe (Sony Corporation)
O4 - HKLM..\Run: [mtvManager] C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvManager.exe ()
O4 - HKLM..\Run: [PWMTRV] C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL (Lenovo Group Limited)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series" File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O9:[b]64bit:[/b] - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O9 - Extra Button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll (Apple Inc.)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000020 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab (DMM Downloader)
O16 - DPF: {4845B7A7-309F-49F4-A2DD-0117707B6E8D} https://toast.dvdtoaster.jp/downloads/activex/x86/dvdtoast.cab (DVD Toaster ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 10.51.2)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 1.7.0_09)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.51.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C059A8EC-DFD2-4F21-91C1-A1C6D9343219}: DhcpNameServer = 192.168.11.1
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/11 01:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{a1c8f30f-342e-11e0-be01-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{a1c8f30f-342e-11e0-be01-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe -- [2009/08/11 06:01:24 | 000,267,576 | -HS- | M] (Lenovo Group Limited)
O33 - MountPoints2\{f931b122-03a5-11e1-bc2d-001b41049f1d}\Shell - "" = AutoRun
O33 - MountPoints2\{f931b122-03a5-11e1-bc2d-001b41049f1d}\Shell\AutoRun\command - "" = E:\g_setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (K7TSDbg)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2014/02/17 07:26:36 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Roaming\Epson
[2014/02/16 19:25:01 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\Desktop\エプソンショートカット
[2014/02/16 18:56:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\読んde!!ココ
[2014/02/16 18:56:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Aisoft
[2014/02/16 18:55:05 | 000,000,000 | ---D | C] -- C:\ProgramData\UDL
[2014/02/16 18:44:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\EPSON
[2014/02/16 18:42:33 | 000,558,592 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\ensppmon.dll
[2014/02/16 18:42:33 | 000,535,552 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\ensppui.dll
[2014/02/16 18:42:33 | 000,211,968 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\enspres.dll
[2014/02/16 18:42:33 | 000,211,968 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\enpres.dll
[2014/02/16 18:42:32 | 000,558,592 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\enppmon.dll
[2014/02/16 18:42:32 | 000,535,552 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\enppui.dll
[2014/02/16 18:42:32 | 000,000,000 | ---D | C] -- C:\Program Files\EpsonNet
[2014/02/16 18:35:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software
[2014/02/16 18:35:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EPSON Software
[2014/02/16 18:35:06 | 000,466,432 | ---- | C] (Seiko Epson Corporation) -- C:\Windows\SysNative\esxw2ud.dll
[2014/02/16 18:35:06 | 000,144,560 | ---- | C] (Seiko Epson Corporation) -- C:\Windows\SysNative\escsvc64.exe
[2014/02/16 18:35:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
[2014/02/16 18:35:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\epson
[2014/02/16 18:34:10 | 000,179,712 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\E_ILMBLMJ.DLL
[2014/02/16 18:34:10 | 000,083,968 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\E_ID4BLMJ.DLL
[2014/02/16 18:34:10 | 000,010,752 | ---- | C] (SEIKO EPSON CORP.) -- C:\Windows\SysNative\E_GCINST.DLL
[2014/02/15 08:23:43 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\Desktop\ぱそこん
[2014/02/13 15:38:39 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/02/13 15:21:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2014/02/13 15:20:13 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Roaming\DigitalSites
[2014/02/13 14:24:54 | 000,821,736 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2014/02/13 14:24:54 | 000,746,984 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2014/02/13 10:55:28 | 000,548,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014/02/13 10:54:57 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/02/13 10:54:57 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/02/13 10:54:56 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/02/13 10:54:56 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/02/13 10:54:55 | 000,627,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/02/13 10:54:55 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/02/13 10:54:55 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/02/13 10:54:55 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/02/13 10:54:54 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/02/13 10:54:54 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/02/13 10:54:54 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/02/13 10:54:54 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/02/13 10:54:54 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/02/13 10:54:54 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/02/13 10:54:54 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/02/13 10:54:54 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/02/13 10:54:53 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/02/13 10:54:53 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/02/13 10:54:53 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/02/13 10:54:53 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/02/13 10:54:52 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/02/13 10:54:52 | 001,964,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/02/13 10:54:50 | 005,768,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/02/12 17:55:31 | 002,565,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2014/02/12 17:55:30 | 003,928,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2014/02/12 17:54:41 | 000,658,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe
[2014/02/12 17:54:41 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe
[2014/02/12 17:54:41 | 000,594,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe
[2014/02/12 17:54:40 | 000,572,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe
[2014/02/12 17:54:40 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2014/02/12 17:54:40 | 000,508,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2014/02/12 17:54:39 | 000,553,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe
[2014/02/12 17:54:39 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe
[2014/02/12 17:54:39 | 000,485,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll
[2014/02/12 17:54:39 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll
[2014/02/12 17:54:38 | 000,528,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdrm.dll
[2014/02/12 17:54:38 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll
[2014/02/12 17:54:38 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2014/02/12 17:54:37 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll
[2014/02/12 17:54:37 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll
[2014/02/12 17:54:36 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll
[2014/02/12 17:54:36 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll
[2014/02/12 17:50:04 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll
[2014/02/12 17:50:03 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll
[2014/02/12 10:26:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2014/02/12 10:26:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2014/02/12 09:51:19 | 000,028,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEUDINIT.EXE
[2014/02/12 09:46:13 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2014/02/12 09:46:13 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2014/02/12 09:46:10 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2014/02/12 09:46:10 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2014/02/12 09:46:10 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2014/02/12 09:46:10 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2014/02/12 09:46:10 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2014/02/12 09:46:10 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2014/02/12 09:46:10 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2014/02/12 09:46:10 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2014/02/12 09:46:10 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2014/02/12 09:46:10 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2014/02/12 09:46:09 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2014/02/12 09:46:09 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2014/02/12 09:46:09 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2014/02/12 09:46:09 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2014/02/12 09:46:09 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2014/02/12 09:46:09 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2014/02/12 09:46:09 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2014/02/12 09:46:09 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2014/02/12 09:46:09 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2014/02/12 09:46:09 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014/02/12 09:46:09 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2014/02/12 09:46:09 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2014/02/12 09:46:09 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2014/02/12 09:46:09 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2014/02/12 09:46:08 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2014/02/12 09:46:07 | 001,228,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2014/02/12 09:46:07 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2014/02/12 09:46:07 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2014/02/12 09:46:07 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2014/02/12 09:46:07 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014/02/12 09:46:07 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2014/02/12 09:46:07 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2014/02/12 09:46:07 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2014/02/12 09:46:07 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2014/02/12 09:46:07 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2014/02/12 09:46:07 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2014/02/12 09:46:07 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2014/02/12 09:46:07 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2014/02/12 09:46:07 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2014/02/12 09:46:07 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2014/02/12 09:46:07 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2014/02/12 09:46:07 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2014/02/12 09:46:07 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2014/02/12 09:46:07 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014/02/12 09:46:07 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2014/02/12 09:46:07 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2014/02/12 09:46:07 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2014/02/12 09:46:07 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2014/02/12 09:46:07 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2014/02/12 09:46:07 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2014/02/12 09:46:07 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2014/02/12 09:46:07 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2014/02/12 09:46:07 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2014/02/12 09:46:07 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2014/02/10 16:26:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2014/02/10 16:12:21 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Roaming\Malwarebytes
[2014/02/10 16:11:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/02/08 17:23:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2014/02/08 17:23:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2014/02/08 17:23:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014/02/08 16:13:31 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Roaming\ProductData
[2014/02/08 15:39:50 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Roaming\IObit
[2014/02/08 15:39:47 | 000,000,000 | ---D | C] -- C:\ProgramData\ProductData
[2014/02/08 15:39:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller
[2014/02/08 15:39:47 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2014/02/08 15:39:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit
[2014/02/08 15:26:01 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2014/02/07 17:48:27 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\Documents\写真
[2014/02/06 17:34:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\predm
[2014/02/03 22:07:48 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Local\I-O DATA
[2014/02/03 22:07:41 | 000,000,000 | ---D | C] -- C:\mAgicTVD
[2014/02/03 22:07:41 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Roaming\I-O DATA
[2014/02/03 21:35:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bonjour
[2014/02/03 21:35:36 | 000,036,864 | ---- | C] (TOSHIBA/MEI) -- C:\Windows\SysWow64\SDDEVMGR.dll
[2014/02/03 21:35:35 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\sda
[2014/02/03 21:35:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2014/02/03 21:26:17 | 000,000,000 | ---D | C] -- C:\ProgramData\I-O DATA
[2014/02/03 21:26:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I-O DATA
[2014/02/03 21:26:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\I-O DATA
[2014/02/03 21:25:13 | 000,477,432 | ---- | C] (I-O DATA DEVICE, INC.) -- C:\Windows\SysNative\drivers\gvmvpfz_x64.sys
[2014/02/03 21:25:12 | 000,121,464 | ---- | C] (I-O DATA DEVICE, INC.) -- C:\Windows\SysWow64\ioOutputCallBackFilter.ax
[2014/01/29 20:25:24 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2012/05/05 19:04:59 | 001,667,808 | ---- | C] (猫科研究所 ) -- C:\Users\オヤジ\dvdflick_1.3.0.7_felidlabo-0011.exe
[2012/05/05 18:59:26 | 012,951,423 | ---- | C] (Dennis Meuwissen ) -- C:\Users\オヤジ\dvdflick_setup_1.3.0.7.exe

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2014/02/18 14:47:00 | 000,000,382 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2014/02/18 14:46:00 | 000,000,626 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/02/18 14:46:00 | 000,000,528 | ---- | M] () -- C
  • ryoyoung
  • MAIL
  • 2014/02/18 (Tue) 15:17:47
OTLで処置します
作業と報告、ご苦労様です。
OTLのログを見せてもらいました。
ではOTLで続きの処置をします。

今度はOTLのスクリプトを使って作業します。
このレスの最後に貼るスクリプトを丸ごとコピーして、それをWindowsのメモ帳ファイルに貼り付けて保存しておいてください。

用意できたらPCをまたセーフモードで再起動してOTL起動してください。
起動したらOTLのウインドウ下部にスクリプトを貼り付けて、今度は「Run fix」(赤字のボタン)を押してください。
これでOTLでの処置が開始されます。

しばらく待って処置ができたらPCを通常モードで再起動すると、またOTLのログが出るはずなので、それを保存してから、しばらく様子見の後、OTLのログとともに状態報告をレスください。
OTLのスクリプトは以下になります。破線(-----)を含まない箇所を丸ごとコピーして、それをOTLに貼って作業してください
--------------------------------------------
:OTL
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKLM\..\SearchScopes\{D89871C2-CB62-42D8-B61C-D16CC24D22D6}: "URL" = http://search.certified-toolbar.com?si=41460&bs=true&tid=2996&q={searchTerms}
CHR - homepage: http://jp.hao123.com/?tn=epom_pay_hp_04_hao123_jp
O4 - HKLM..\Run: [iFilter5] C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000020 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\SysWOW64\ifp5lsp.dll (デジタルアーツ株式会社)
[2014/02/13 15:20:13 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Roaming\DigitalSites

:Files

:Commands
[purity]
[createrestorepoint]
[emptytemp]
[reboot]￿
  • 悪代官
  • 2014/02/18 (Tue) 16:38:33
Re: 駆除
ご苦労さんです。OTLで処置しました。状態はやっとIフィルターはタスクバーには表示されなくなりました。youtubeを見ても「InternetExPloreは動作を停止し、このWebページを閉じました。」と出なくなりました。改善したのかな?OTLのログを張ります。よろしくお願いします。
All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D89871C2-CB62-42D8-B61C-D16CC24D22D6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D89871C2-CB62-42D8-B61C-D16CC24D22D6}\ not found.
Use Chrome's Settings page to change the HomePage.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\iFilter5 deleted successfully.
C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5GC.exe moved successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\ deleted successfully.
C:\Windows\SysWOW64\ifp5lsp.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\ deleted successfully.
File C:\Windows\SysWOW64\ifp5lsp.dll not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\ deleted successfully.
File C:\Windows\SysWOW64\ifp5lsp.dll not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\ deleted successfully.
File C:\Windows\SysWOW64\ifp5lsp.dll not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\ deleted successfully.
File C:\Windows\SysWOW64\ifp5lsp.dll not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\ deleted successfully.
File C:\Windows\SysWOW64\ifp5lsp.dll not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\ deleted successfully.
File C:\Windows\SysWOW64\ifp5lsp.dll not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\ deleted successfully.
File C:\Windows\SysWOW64\ifp5lsp.dll not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000020\ deleted successfully.
File C:\Windows\SysWOW64\ifp5lsp.dll not found.
C:\Users\オヤジ\AppData\Roaming\DigitalSites folder moved successfully.
File rity] not found.
File eaterestorepoint] not found.
File ptytemp] not found.
File boot]� not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\: LSP stack updated.

OTL by OldTimer - Version 3.2.69.0 log created on 02192014_083625

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • ryoyoung
  • MAIL
  • 2014/02/19 (Wed) 18:03:16
では状況を再確認します
作業と報告、ご苦労様です。

説明とログを見ても今度は処置できたようですね。
ではOTLも準備時の説明に沿って片づけてください。

これでi-フィルターも片付いたとは思いますが、処置が進んでもその後の作業中にまたあらたな感染受けてしまう事例がこのところやたら増えてきているので、一応確認します。
全体の状況を見直すので、HJTとインストール情報のログと、CCでの各タブのログをまた取り直して、それをレスで見せてください。

この結果で異常もなくなっていればあとはスムーズにいくと思われます
  • 悪代官
  • 2014/02/19 (Wed) 18:19:59
気になります。
パソコンの状態は落ち着いております。ただ前にも書いた通り「InternetExPloreを起動するときのよくアクセスするサイトにhttp://jp.hao.123.com・・・・やhttp://jp.jst.jstick・・・・が全然アクセスしてないのに載っています。一覧から削除してもまた、いつの間にか載っています。」これは大丈夫なのでしょうか?表には全然出てきてませんが・・
ログを張りますよろしくお願いします。
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:24:03, on 2014/02/20
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\EPSON\MyEPSON Connect\mep.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMECMNT.EXE
C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe
C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SysMon.Exe
C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe
C:\Users\オヤジ\Downloads\HijackThis.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMECMNT.EXE

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: K7 Web Protection - {08B3B4B6-02DA-4658-8BA6-5974E3EBB03D} - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
O2 - BHO: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Microsoft アカウント サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [K7TSStart] C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [LPStation] C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [K7SystemTray] "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
O4 - HKLM\..\Run: [iFilter5] "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Continue installation.lnk = ?
O4 - Global Startup: PHOTOfunSTUDIO 5.0 HD Edition.lnk = C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
O4 - Global Startup: クライアントマネージャV.lnk = C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: OneNote に送る(&N) - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: OneNote に送る - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: OneNote に送る(&N) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} (DMM Downloader) - http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab
O16 - DPF: {4845B7A7-309F-49F4-A2DD-0117707B6E8D} (DVD Toaster ActiveX Control) - https://toast.dvdtoaster.jp/downloads/activex/x86/dvdtoast.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: Bonjour サービス (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: BWH32S - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EzDetector - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: i-フィルター 5.0 Main (IFP5MainService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
O23 - Service: i-フィルター 5.0 Support (IFP5WatchService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: K7Carnivore Service (K7CrvSvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe
O23 - Service: K7Computng - EMail Proxy Server (K7EmlPxy) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7EmlPxy.exe
O23 - Service: K7Firewall Services (K7FWSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7FWSrvc.exe
O23 - Service: K7Privacy Services (K7PSSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7PSSrvc.exe
O23 - Service: K7RealTime AntiVirus Services (K7RTScan) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7RTScan.exe
O23 - Service: K7SpmSrc - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SpmSrc.exe
O23 - Service: K7TotalSecurity Manager (K7TSMngr) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSMngr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: LISMO PIM Service - CASIO SOFT CO. LTD. - C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: I-O DATA mAgicTV Digital (mAgicTVDigital) - I-O DATA DEVICE, INC. - C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyEPSON Connect Service - SEIKO EPSON CORPORATION - C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NlsSrv32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SD Device Manager - Panasonic Corporation - C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: SonicStage Back-End Service2 - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14425 bytes

Access Help Lenovo 2011/02/09 3.00
Adobe Flash Player 12 ActiveX Adobe Systems Incorporated 2014/02/20 6.00 MB 12.0.0.44
Adobe Reader XI (11.0.06) - Japanese Adobe Systems Incorporated 2014/02/12 147 MB 11.0.06
Apple Application Support Apple Inc. 2013/10/01 64.0 MB 2.3.6
Apple Mobile Device Support Apple Inc. 2013/10/01 25.0 MB 7.0.0.117
au ISW11K USB Driver 京セラ株式会社 2012/03/01 1.00.0000
au T008 USB Driver Ver.5.0.0.1 2011/09/24 V5.24.1.0
Bonjour Apple Inc. 2014/02/03 3.29 MB 1.0.106
BUFFALO エアステーション設定ツール BUFFALO INC. 2011/09/25 2.84 MB 2.0.5
BUFFALO クライアントマネージャV BUFFALO INC. 2014/02/20
BUFFALO パソコン環境表示ツール BUFFALO INC. 2011/09/25 1.0.3
Corel DVD MovieWriter Lenovo Edition Corel Corporation 2011/02/09 320 MB 7.0.0
Corel TVX Corel Corporation 2014/02/03 31.2 MB 2.2-B0.5
Create Recovery Media Lenovo Group Limited 2011/02/09 9.50 MB 1.20.0.00
DVD Decrypter (Remove Only) 2014/02/20
DVD Flick 1.3.0.7 Dennis Meuwissen 2012/05/05 1.3.0.7
DVD Shrink 3.2 DVD Shrink 2014/02/20
Epson E-Photo SEIKO EPSON CORPORATION 2014/02/16 1.4.1.0
Epson E-Web Print SEIKO EPSON CORPORATION 2014/02/16 9.22 MB 1.19.0000
EPSON EP-706A Series プリンター アンインストール SEIKO EPSON Corporation 2014/02/16
Epson Event Manager Seiko Epson Corporation 2014/02/16 42.4 MB 3.10.0017
Epson Print CD SEIKO EPSON CORPORATION 2014/02/16 2.21.00
EPSON Scan Seiko Epson Corporation 2014/02/20
EPSON Scan OCR コンポーネント SEIKO EPSON Corp. 2014/02/16 1.33.0000
EPSON マニュアル SEIKO EPSON CORPORATION 2014/02/16 704 KB 1.32.0.0
EpsonNet Print SEIKO EPSON CORPORATION 2014/02/16 2.6.0
I-O DATA mAgicTV Digital I-O DATA DEVICE,INC. 2014/02/03 1.01.00
IL Download Manager Image-Line 2014/02/20
Intel(R) Control Center Intel Corporation 2011/02/09 1.2.1.1007
Intel(R) Graphics Media Accelerator Driver Intel Corporation 2011/02/09 8.15.10.2125
Intel(R) Management Engine Components Intel Corporation 2011/02/09 6.0.0.1179
InterVideo WinDVD 8 InterVideo Inc. 2011/02/09 163 MB 8.0.20.199
IObit Uninstaller IObit 2014/02/08 3.1.7.2405
Java 7 Update 51 Oracle 2014/02/08 118 MB 7.0.510
Jw_cad 2014/02/20
Lenovo Auto Scroll Utility 2011/02/09 1.00
Lenovo Patch Utility Lenovo Group Limited 2013/05/12 1.33 MB 1.3.1.1
Lenovo Patch Utility 64 bit Lenovo Group Limited 2013/05/12 1.35 MB 1.3.1.1
Lenovo System Interface Driver 2013/05/12 1.05
Lenovo System Update Lenovo 2013/07/16 13.4 MB 5.02.0018
Lenovo ThinkVantage Toolbox PC-Doctor, Inc. 2011/02/09 6.0.5717.21
Lenovo Warranty Information Lenovo 2011/02/09 893 KB 1.0.0004.00
Lenovo Welcome Lenovo 2011/02/09
LISMO Port 5.1 Sony Corporation 2013/03/10 110 MB 5.1
Message Center Plus Lenovo Group Limited 2011/02/09 1.70 MB 2.0.0012.00
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 2011/02/27 38.8 MB 4.0.30319
Microsoft Office Home and Business 2010 Microsoft Corporation 2014/02/20 14.0.7015.1000
Microsoft Office Word Viewer 2003 Microsoft Corporation 2014/01/16 105 MB 11.0.8173.0
Microsoft Silverlight Microsoft Corporation 2013/10/10 149 MB 5.1.20913.0
Microsoft SkyDrive Microsoft Corporation 2013/01/15 25.1 MB 16.4.6013.0910
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2011/02/09 1.69 MB 3.1.0000
Microsoft SQL Server Compact 3.5 SP1 English Microsoft Corporation 2011/02/28 2.59 MB 3.5.5692.0
Microsoft SQL Server Compact 3.5 SP1 x64 English Microsoft Corporation 2011/02/28 3.69 MB 3.5.5692.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 Microsoft Corporation 2011/02/26 260 KB 8.0.50727.4053
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 2011/02/26 250 KB 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2014/02/03 2.38 MB 8.0.59193
Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 2011/02/09 840 KB 8.0.61000
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2013/10/01 248 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2011/02/16 784 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 2011/06/20 788 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2011/03/17 234 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2011/02/16 592 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2011/06/20 600 KB 9.0.30729.6161
Mobile Broadband Lenovo 2011/02/09 16.4 MB 3.6.0034
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2011/02/18 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2011/02/18 1.33 MB 4.20.9876.0
MyEPSON Portal SEIKO EPSON Corporation 2014/02/20
PHOTOfunSTUDIO 5.0 HD Edition Panasonic Corporation 2011/02/28 5.00.313
QuickTime Apple Inc. 2012/11/07 73.2 MB 7.72.80.56
Registry Patch to arrange icons in Device and Printers folder of Windows 7 2011/02/09 1.00
Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7 2011/02/09 1.00
Rescue and Recovery Lenovo Group Limited 2013/05/12 101 MB 4.31.0005.00
SAMSUNG USB Driver for Mobile Phones SAMSUNG Electronics Co., Ltd. 2013/08/07 42.9 MB 1.5.16.0
Software Updater SEIKO EPSON CORPORATION 2014/02/16 8.19 MB 4.2.1
SonicStage 4.4 Sony Corporation 2012/02/15 4.4
Sony Media Library Earth 8.1.00 Sony Corporation 2013/03/10 47.3 MB 8.1.00.11292
ThinkPad Power Management Driver 2011/02/09 1.60.0.4
ThinkPad UltraNav Driver 2011/02/16 46.4 MB 15.0.18.0
ThinkPad Wireless LAN Adapter Software REALTEK Semiconductor Corp. 2011/02/09 1.00.0024.0
ThinkPad 省電力マネージャー 2014/02/20 3.30
ThinkVantage Communications Utility Lenovo 2011/02/09 2.43 MB 1.41
ThinkVantage ハードディスク・アクティブプロテクション・システム Lenovo 2011/02/09 15.6 MB 1.74
USB Video/Audio Device Driver 会社名 2012/07/29 15.4 MB 1.00.0000
Windows Live Essentials Microsoft Corporation 2013/01/15 16.4.3505.0912
Windows ドライバ パッケージ - I-O DATA DEVICE, INC. GV-MVP/FZ(x64) (11/29/2010 1.8.2.12) I-O DATA DEVICE, INC. 2014/02/03 11/29/2010 1.8.2.12
Windows ドライバ パッケージ - Intel (iaStor) hdc (01/15/2010 9.5.7.1002) Intel 2011/02/09 01/15/2010 9.5.7.1002
Windows ドライバ パッケージ - Intel hdc (06/04/2009 7.0.0.1013) Intel 2011/02/09 06/04/2009 7.0.0.1013
Windows ドライバ パッケージ - Intel System (06/04/2009 1.0.0.0002) Intel 2011/02/09 06/04/2009 1.0.0.0002
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/09 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/10 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel USB (08/20/2009 9.1.1.1020) Intel 2011/02/09 08/20/2009 9.1.1.1020
Windows ドライバ パッケージ - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4) Lenovo 2011/02/09 11/18/2009 1.60.0.4
Windows ドライバ パッケージ - Realtek Semiconductor Corp. HD Audio Driver (06/29/2010 6.0.1.6146) Realtek Semiconductor Corp. 2011/02/09 06/29/2010 6.0.1.6146
インテル(R) ターボ・ブースト・テクノロジー・モニター インテル 2011/02/09 1.13 MB 1.0.186.3
ウイルスセキュリティ ソースネクスト株式会社 2014/02/20 12.00
読んde!!ココ パーソナル 2014/02/16
  • ryoyoung
  • MAIL
  • 2014/02/20 (Thu) 10:35:55
確認しながら次の作業を
作業と報告、ご苦労様です。

>パソコンの状態は落ち着いております。ただ前にも書いた通り「InternetExPloreを起動するときのよくアクセスするサイトにhttp://jp.hao.123.com・・・・やhttp://jp.jst.jstick・・・・が全然アクセスしてないのに載っています

はい、ではまた確認しながら作業をお願いします。
先に使ったACの最新版をまたダウンロードしておいてください。これの作業を再試行します。

以下のアプリを確認してください。
>IL Download Manager Image-Line 2014/02/20

インストールの日付が今日になってますが、これはご自身で入れたものですか?
覚えがなければこれもセーフモードで、IUでアンインストールしてください。

続いてセーフモードでHJTを使って、下記のエントリをfixしてください。
>O4 - HKLM\..\Run: [iFilter5] "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
>O23 - Service: i-フィルター 5.0 Main (IFP5MainService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
>O23 - Service: i-フィルター 5.0 Support (IFP5WatchService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe

ATFでゴミ掃除したあと、またACでClean作業してください。

これができたらPCを通常モードで再起動してから、ACのログを保存後、CCを起動して「Windows」以下の各タブのログを取り直してください。

取り直したACとCCの各ログを返信に貼って、状態報告とともにレスください
  • 悪代官
  • 2014/02/20 (Thu) 11:44:44
Re: 駆除
何度も、何度もすいません。ログを張ります。
# AdwCleaner v3.018 - Report created 20/02/2014 at 13:14:15
# Updated 28/01/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : オヤジ - YUNBOO
# Running from : C:\Users\オヤジ\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16518


-\\ Google Chrome v

[ File : C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [4903 octets] - [13/02/2014 15:47:14]
AdwCleaner[R1].txt - [871 octets] - [13/02/2014 15:51:46]
AdwCleaner[R2].txt - [1134 octets] - [15/02/2014 13:31:03]
AdwCleaner[R3].txt - [1110 octets] - [20/02/2014 13:13:37]
AdwCleaner[S0].txt - [3095 octets] - [13/02/2014 15:49:51]
AdwCleaner[S1].txt - [931 octets] - [13/02/2014 15:52:23]
AdwCleaner[S2].txt - [1131 octets] - [15/02/2014 13:31:46]
AdwCleaner[S3].txt - [1032 octets] - [20/02/2014 13:14:15]

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1092 octets] ##########

Access Help Lenovo 2011/02/09 3.00
Adobe Flash Player 12 ActiveX Adobe Systems Incorporated 2014/02/20 6.00 MB 12.0.0.44
Adobe Reader XI (11.0.06) - Japanese Adobe Systems Incorporated 2014/02/12 147 MB 11.0.06
Apple Application Support Apple Inc. 2013/10/01 64.0 MB 2.3.6
Apple Mobile Device Support Apple Inc. 2013/10/01 25.0 MB 7.0.0.117
au ISW11K USB Driver 京セラ株式会社 2012/03/01 1.00.0000
au T008 USB Driver Ver.5.0.0.1 2011/09/24 V5.24.1.0
Bonjour Apple Inc. 2014/02/03 3.29 MB 1.0.106
BUFFALO エアステーション設定ツール BUFFALO INC. 2011/09/25 2.84 MB 2.0.5
BUFFALO クライアントマネージャV BUFFALO INC. 2014/02/20
BUFFALO パソコン環境表示ツール BUFFALO INC. 2011/09/25 1.0.3
Corel DVD MovieWriter Lenovo Edition Corel Corporation 2011/02/09 320 MB 7.0.0
Corel TVX Corel Corporation 2014/02/03 31.2 MB 2.2-B0.5
Create Recovery Media Lenovo Group Limited 2011/02/09 9.50 MB 1.20.0.00
DVD Decrypter (Remove Only) 2014/02/20
DVD Flick 1.3.0.7 Dennis Meuwissen 2012/05/05 1.3.0.7
DVD Shrink 3.2 DVD Shrink 2014/02/20
Epson E-Photo SEIKO EPSON CORPORATION 2014/02/16 1.4.1.0
Epson E-Web Print SEIKO EPSON CORPORATION 2014/02/16 9.22 MB 1.19.0000
EPSON EP-706A Series プリンター アンインストール SEIKO EPSON Corporation 2014/02/16
Epson Event Manager Seiko Epson Corporation 2014/02/16 42.4 MB 3.10.0017
Epson Print CD SEIKO EPSON CORPORATION 2014/02/16 2.21.00
EPSON Scan Seiko Epson Corporation 2014/02/20
EPSON Scan OCR コンポーネント SEIKO EPSON Corp. 2014/02/16 1.33.0000
EPSON マニュアル SEIKO EPSON CORPORATION 2014/02/16 704 KB 1.32.0.0
EpsonNet Print SEIKO EPSON CORPORATION 2014/02/16 2.6.0
I-O DATA mAgicTV Digital I-O DATA DEVICE,INC. 2014/02/03 1.01.00
Intel(R) Control Center Intel Corporation 2011/02/09 1.2.1.1007
Intel(R) Graphics Media Accelerator Driver Intel Corporation 2011/02/09 8.15.10.2125
Intel(R) Management Engine Components Intel Corporation 2011/02/09 6.0.0.1179
InterVideo WinDVD 8 InterVideo Inc. 2011/02/09 163 MB 8.0.20.199
IObit Uninstaller IObit 2014/02/08 3.1.7.2405
Java 7 Update 51 Oracle 2014/02/08 118 MB 7.0.510
Jw_cad 2014/02/20
Lenovo Auto Scroll Utility 2011/02/09 1.00
Lenovo Patch Utility Lenovo Group Limited 2013/05/12 1.33 MB 1.3.1.1
Lenovo Patch Utility 64 bit Lenovo Group Limited 2013/05/12 1.35 MB 1.3.1.1
Lenovo System Interface Driver 2013/05/12 1.05
Lenovo System Update Lenovo 2013/07/16 13.4 MB 5.02.0018
Lenovo ThinkVantage Toolbox PC-Doctor, Inc. 2011/02/09 6.0.5717.21
Lenovo Warranty Information Lenovo 2011/02/09 893 KB 1.0.0004.00
Lenovo Welcome Lenovo 2011/02/09
LISMO Port 5.1 Sony Corporation 2013/03/10 110 MB 5.1
Message Center Plus Lenovo Group Limited 2011/02/09 1.70 MB 2.0.0012.00
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 2011/02/27 38.8 MB 4.0.30319
Microsoft Office Home and Business 2010 Microsoft Corporation 2014/02/20 14.0.7015.1000
Microsoft Office Word Viewer 2003 Microsoft Corporation 2014/01/16 105 MB 11.0.8173.0
Microsoft Silverlight Microsoft Corporation 2013/10/10 149 MB 5.1.20913.0
Microsoft SkyDrive Microsoft Corporation 2013/01/15 25.1 MB 16.4.6013.0910
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2011/02/09 1.69 MB 3.1.0000
Microsoft SQL Server Compact 3.5 SP1 English Microsoft Corporation 2011/02/28 2.59 MB 3.5.5692.0
Microsoft SQL Server Compact 3.5 SP1 x64 English Microsoft Corporation 2011/02/28 3.69 MB 3.5.5692.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 Microsoft Corporation 2011/02/26 260 KB 8.0.50727.4053
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 2011/02/26 250 KB 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2014/02/03 2.38 MB 8.0.59193
Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 2011/02/09 840 KB 8.0.61000
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2013/10/01 248 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2011/02/16 784 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 2011/06/20 788 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2011/03/17 234 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2011/02/16 592 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2011/06/20 600 KB 9.0.30729.6161
Mobile Broadband Lenovo 2011/02/09 16.4 MB 3.6.0034
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2011/02/18 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2011/02/18 1.33 MB 4.20.9876.0
MyEPSON Portal SEIKO EPSON Corporation 2014/02/20
PHOTOfunSTUDIO 5.0 HD Edition Panasonic Corporation 2011/02/28 5.00.313
QuickTime Apple Inc. 2012/11/07 73.2 MB 7.72.80.56
Registry Patch to arrange icons in Device and Printers folder of Windows 7 2011/02/09 1.00
Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7 2011/02/09 1.00
Rescue and Recovery Lenovo Group Limited 2013/05/12 101 MB 4.31.0005.00
SAMSUNG USB Driver for Mobile Phones SAMSUNG Electronics Co., Ltd. 2013/08/07 42.9 MB 1.5.16.0
Software Updater SEIKO EPSON CORPORATION 2014/02/16 8.19 MB 4.2.1
SonicStage 4.4 Sony Corporation 2012/02/15 4.4
Sony Media Library Earth 8.1.00 Sony Corporation 2013/03/10 47.3 MB 8.1.00.11292
ThinkPad Power Management Driver 2011/02/09 1.60.0.4
ThinkPad UltraNav Driver 2011/02/16 46.4 MB 15.0.18.0
ThinkPad Wireless LAN Adapter Software REALTEK Semiconductor Corp. 2011/02/09 1.00.0024.0
ThinkPad 省電力マネージャー 2014/02/20 3.30
ThinkVantage Communications Utility Lenovo 2011/02/09 2.43 MB 1.41
ThinkVantage ハードディスク・アクティブプロテクション・システム Lenovo 2011/02/09 15.6 MB 1.74
USB Video/Audio Device Driver 会社名 2012/07/29 15.4 MB 1.00.0000
Windows Live Essentials Microsoft Corporation 2013/01/15 16.4.3505.0912
Windows ドライバ パッケージ - I-O DATA DEVICE, INC. GV-MVP/FZ(x64) (11/29/2010 1.8.2.12) I-O DATA DEVICE, INC. 2014/02/03 11/29/2010 1.8.2.12
Windows ドライバ パッケージ - Intel (iaStor) hdc (01/15/2010 9.5.7.1002) Intel 2011/02/09 01/15/2010 9.5.7.1002
Windows ドライバ パッケージ - Intel hdc (06/04/2009 7.0.0.1013) Intel 2011/02/09 06/04/2009 7.0.0.1013
Windows ドライバ パッケージ - Intel System (06/04/2009 1.0.0.0002) Intel 2011/02/09 06/04/2009 1.0.0.0002
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/09 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/10 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel USB (08/20/2009 9.1.1.1020) Intel 2011/02/09 08/20/2009 9.1.1.1020
Windows ドライバ パッケージ - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4) Lenovo 2011/02/09 11/18/2009 1.60.0.4
Windows ドライバ パッケージ - Realtek Semiconductor Corp. HD Audio Driver (06/29/2010 6.0.1.6146) Realtek Semiconductor Corp. 2011/02/09 06/29/2010 6.0.1.6146
インテル(R) ターボ・ブースト・テクノロジー・モニター インテル 2011/02/09 1.13 MB 1.0.186.3
ウイルスセキュリティ ソースネクスト株式会社 2014/02/20 12.00
読んde!!ココ パーソナル 2014/02/16
有効 HKCU:Run EPLTarget\P0000000000000000 SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series"
有効 HKLM:Run Adobe ARM Adobe Systems Incorporated "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
有効 HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
有効 HKLM:Run EEventManager SEIKO EPSON CORPORATION "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
有効 HKLM:Run HotKeysCmds Intel Corporation C:\Windows\system32\hkcmd.exe
有効 HKLM:Run iFilter5 "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
有効 HKLM:Run IgfxTray Intel Corporation C:\Windows\system32\igfxtray.exe
有効 HKLM:Run IME14 JPN Setup Microsoft Corporation C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
有効 HKLM:Run K7SystemTray "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
有効 HKLM:Run K7TSStart K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
有効 HKLM:Run LENOVO.TPKNRRES Lenovo Group Limited C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
有効 HKLM:Run LPStation Sony Corporation C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
有効 HKLM:Run Persistence Intel Corporation C:\Windows\system32\igfxpers.exe
有効 HKLM:Run PWMTRV rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
有効 HKLM:Run QuickTime Task Apple Inc. "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
有効 HKLM:Run SynTPEnh Synaptics Incorporated %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
有効 HKLM:Run TpShocks Lenovo. TpShocks.exe
有効 Startup Common Continue installation.lnk Red Sky Sp. z o.o. C:\Users\オヤジ\AppData\Local\Temp\Free_files_downloader.exe
有効 Startup Common PHOTOfunSTUDIO 5.0 HD Edition.lnk Panasonic Corporation C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
有効 Startup Common クライアントマネージャV.lnk BUFFALO INC. C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
よろしくお願いします。
  • ryoyoung
  • MAIL
  • 2014/02/20 (Thu) 13:29:15
ログが不足しております
gimp2.6改めIVNOです。

>CCを起動して「Windows」以下の各タブのログを取り直してください。
勘違いなされておられるみたいですので、この部分を私のテンプレを使って書き直させていただきますね。

CCを起動させてください。
起動したら、「ツール」→「スタートアップ」→「Windows」タブを開いてください。
そこで右下の「テキストとして保存」を押すと、表示の内容がログとして保存できますので、
デスクトップ等、分かりやすい場所に最新のログのみ保存しておきましょう。
続いて「InternetExplorer」タブのログ、導入されておられるのであれば「Firefox」タブ、
同じく導入されておられるのであれば「Google Chrome」タブ、そして「スケジュールされたタスク」タブのログを取得してください。
ただし、「コンテキストメニュー」のログは取得していただく必要がございません。
CCの各ログを取得されましたら、CCは終了させて問題ありません。
CCのログを返信欄に貼り付けていただき、ご報告をお願いいたします。
  • IVNO
  • MAIL
  • 2014/02/21 (Fri) 00:08:34
Re: 駆除
IVNOさん。助け舟ありがとございます。何度やっても学習能力のない私ですがよろしくお願いします。
CCのログを貼り付けます。
有効 HKCU:Run EPLTarget\P0000000000000000 SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series"
有効 HKLM:Run Adobe ARM Adobe Systems Incorporated "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
有効 HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
有効 HKLM:Run EEventManager SEIKO EPSON CORPORATION "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
有効 HKLM:Run HotKeysCmds Intel Corporation C:\Windows\system32\hkcmd.exe
有効 HKLM:Run iFilter5 "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
有効 HKLM:Run IgfxTray Intel Corporation C:\Windows\system32\igfxtray.exe
有効 HKLM:Run IME14 JPN Setup Microsoft Corporation C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
有効 HKLM:Run K7SystemTray "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
有効 HKLM:Run K7TSStart K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
有効 HKLM:Run LENOVO.TPKNRRES Lenovo Group Limited C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
有効 HKLM:Run LPStation Sony Corporation C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
有効 HKLM:Run Persistence Intel Corporation C:\Windows\system32\igfxpers.exe
有効 HKLM:Run PWMTRV rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
有効 HKLM:Run QuickTime Task Apple Inc. "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
有効 HKLM:Run TpShocks Lenovo. TpShocks.exe
有効 Startup Common Continue installation.lnk Red Sky Sp. z o.o. C:\Users\オヤジ\AppData\Local\Temp\Free_files_downloader.exe
有効 Startup Common PHOTOfunSTUDIO 5.0 HD Edition.lnk Panasonic Corporation C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
有効 Startup Common クライアントマネージャV.lnk BUFFALO INC. C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe

有効 Extension Bonjour Apple Inc. C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension このコンテンツを引用 Microsoft Corporation C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
有効 Helper E-Photo SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Photo\EPTBL.dll
有効 Helper E-Web Print SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
有効 Helper ExplorerWnd Helper IObit C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper C:\Program Files\Java\jre6\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre7\bin\ssv.dll
無効 Helper K7 Web Protection K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
無効 Helper Microsoft アカウント サインイン ヘルパー Microsoft Corp. C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
無効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
無効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL
無効 Helper Windows Live ID Sign-in Helper Microsoft Corp. C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 Toolbar E-Photo SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Photo\EPTBL.dll
有効 Toolbar E-Web Print SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll

有効 Extension K7 WebProtection 2.3 譛€蛻昴・繝ヲ繝シ繧カ繝シ C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlpfamleaodfgmfnggonbfljhjggbdbe\2.3_0

有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task EPSON EP-706A Series Update {8BD34A37-ADC7-417C-9A46-53B2A5F6AEF8} SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLMJ.EXE /EXE:"{8BD34A37-ADC7-417C-9A46-53B2A5F6AEF8}" /F:"Update"
有効 Task {4A17C693-E678-4A3E-A662-5DA104A7DD3C} Microsoft Corporation C:\Windows\system32\pcalua.exe -a C:\Users\オヤジ\Downloads\HijackThis.exe -d C:\Users\オヤジ\Downloads

  • ryoyoung
  • MAIL
  • 2014/02/22 (Sat) 13:39:44
OTLで再スキャンします
またレスが遅くなってすみません。
ではまた説明に沿って続きの作業をお願いします。

またCCを起動して「WIndows」タブ内の下記を右クリックから「エントリの削除」してください。
>有効 HKLM:Run iFilter5 "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun

これができたら先に使ったOTLをまた用意してください。

用意できたら、最初にOTLを使った時の要領でまた以下を入力してスキャンだけしてください。
%SYSTEMDRIVE%\*.exe
CREATERESTOREPOINT

このあとまたOTLのログを返信に貼って、それを見せてください。
OTLを含めて先にやった各作業での見落としがないかを調べます
  • 悪代官
  • 2014/02/22 (Sat) 17:02:42
Re: 駆除
ごくろうさんです。OTLのログを貼り付けましたのでよろしくおねがいします。
OTL logfile created on: 2014/02/22 18:02:50 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\オヤジ\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

3.80 Gb Total Physical Memory | 2.26 Gb Available Physical Memory | 59.47% Memory free
7.60 Gb Paging File | 5.67 Gb Available in Paging File | 74.66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 454.82 Gb Total Space | 291.79 Gb Free Space | 64.16% Space Free | Partition Type: NTFS
Drive D: | 6.95 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive Q: | 9.77 Gb Total Space | 2.60 Gb Free Space | 26.60% Space Free | Partition Type: NTFS

Computer Name: YUNBOO | User Name: オヤジ | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2014/02/22 18:00:19 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\オヤジ\Downloads\OTL.exe
PRC - [2013/12/21 15:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/11/11 18:49:06 | 000,208,920 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7rtscan.exe
PRC - [2013/10/25 14:53:10 | 000,243,736 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7fwsrvc.exe
PRC - [2013/10/05 12:43:22 | 000,242,848 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsmngr.exe
PRC - [2013/09/13 15:28:58 | 002,387,520 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\epson\MyEPSON Connect\mep.exe
PRC - [2013/09/03 23:33:16 | 000,335,384 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7pssrvc.exe
PRC - [2013/04/02 17:14:02 | 000,154,136 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7emlpxy.exe
PRC - [2013/03/28 15:55:58 | 001,058,880 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
PRC - [2013/01/01 17:45:46 | 000,163,504 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe
PRC - [2012/12/12 15:28:06 | 005,812,912 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
PRC - [2012/11/29 21:07:14 | 002,197,600 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe
PRC - [2012/10/01 16:17:38 | 000,703,616 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\epson\MyEPSON Connect\mepService.exe
PRC - [2011/12/21 23:16:54 | 000,262,752 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe
PRC - [2011/11/05 20:50:19 | 000,072,800 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SysMon.Exe
PRC - [2011/03/17 20:40:57 | 000,382,360 | ---- | M] (デジタルアーツ株式会社) -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe
PRC - [2011/03/17 20:40:52 | 000,681,368 | ---- | M] (デジタルアーツ株式会社) -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
PRC - [2011/03/17 20:40:30 | 000,947,608 | ---- | M] (デジタルアーツ株式会社) -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5control_manager.exe
PRC - [2011/03/17 20:40:27 | 001,172,888 | ---- | M] (デジタルアーツ株式会社) -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5bigbrother.exe
PRC - [2010/12/02 16:08:28 | 000,210,784 | ---- | M] (InterVideo Inc.) -- C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
PRC - [2010/11/01 13:15:46 | 000,053,248 | ---- | M] (I-O DATA DEVICE, INC.) -- C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe
PRC - [2010/08/20 14:21:08 | 001,028,096 | ---- | M] (Lenovo Group Limited) -- C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
PRC - [2010/05/24 10:52:38 | 000,208,760 | ---- | M] (BUFFALO INC.) -- C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
PRC - [2010/04/28 09:58:52 | 000,172,544 | ---- | M] (Panasonic Corporation) -- C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
PRC - [2010/04/20 13:23:32 | 000,074,088 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
PRC - [2010/04/20 13:23:28 | 000,062,312 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
PRC - [2010/04/20 13:23:18 | 000,050,536 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\CamMute.exe
PRC - [2010/04/07 14:37:40 | 000,093,032 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe
PRC - [2010/04/01 14:50:46 | 000,043,960 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
PRC - [2009/11/04 13:45:46 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009/11/04 13:45:44 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009/09/02 19:20:18 | 000,071,064 | ---- | M] (Panasonic Corporation) -- C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe
PRC - [2009/07/09 10:18:24 | 000,126,328 | ---- | M] (BUFFALO INC.) -- C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe
PRC - [2009/07/02 16:55:00 | 000,032,248 | ---- | M] (CASIO SOFT CO. LTD.) -- C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe
PRC - [2009/06/07 13:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\SysWOW64\NlsSrv32.exe
PRC - [2009/05/27 22:09:36 | 000,049,976 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
PRC - [2007/06/15 12:57:42 | 000,145,504 | ---- | M] (B.H.A Corporation) -- C:\Windows\SysWOW64\bgsvcgen.exe
PRC - [2007/01/04 19:48:50 | 000,112,152 | ---- | M] (InterVideo) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2013/10/28 07:46:26 | 004,554,752 | ---- | M] () -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
MOD - [2013/09/05 00:14:10 | 004,300,456 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2013/07/22 07:48:15 | 002,052,096 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll
MOD - [2013/07/22 07:48:15 | 000,425,984 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
MOD - [2012/12/12 14:32:26 | 005,025,792 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
MOD - [2012/10/05 19:53:24 | 003,198,976 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
MOD - [2012/10/05 19:53:24 | 000,630,784 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
MOD - [2011/02/28 21:01:03 | 000,271,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Data.SqlServerCe\3.5.1.0__89845dcd8080cc91\System.Data.SqlServerCe.dll
MOD - [2010/11/13 09:00:19 | 000,348,160 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_ja_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010/11/05 10:58:08 | 000,258,048 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
MOD - [2010/11/05 10:58:05 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2009/07/02 16:55:00 | 000,024,056 | ---- | M] () -- C:\Program Files (x86)\Sony\LISMO Port\LPPIMTools.dll
MOD - [2009/06/11 06:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009/06/11 06:22:40 | 000,010,752 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
MOD - [2009/05/27 22:09:36 | 000,049,976 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2014/02/06 19:48:45 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2013/11/11 11:22:20 | 000,066,856 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Windows\SysNative\ibmpmsvc.exe -- (IBMPMSVC)
SRV:[b]64bit:[/b] - [2013/05/27 14:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2012/05/17 00:00:00 | 000,144,560 | ---- | M] (Seiko Epson Corporation) [Auto | Running] -- C:\Windows\SysNative\escsvc64.exe -- (EpsonScanSvc)
SRV:[b]64bit:[/b] - [2011/01/13 14:05:46 | 000,047,728 | ---- | M] (Lenovo.) [On_Demand | Stopped] -- C:\Windows\SysNative\TPHDEXLG64.exe -- (TPHDEXLGSVC)
SRV:[b]64bit:[/b] - [2010/04/20 13:23:32 | 000,074,088 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe -- (LENOVO.TPKNRSVC)
SRV:[b]64bit:[/b] - [2010/04/20 13:23:18 | 000,050,536 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\Communications Utility\CamMute.exe -- (LENOVO.CAMMUTE)
SRV:[b]64bit:[/b] - [2010/04/07 14:37:40 | 000,093,032 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC)
SRV:[b]64bit:[/b] - [2009/12/21 10:44:06 | 000,535,552 | ---- | M] (CSR, plc) [Auto | Running] -- C:\Windows\SysNative\HFGService.dll -- (HFGService)
SRV:[b]64bit:[/b] - [2009/09/29 17:25:48 | 000,126,392 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV - [2014/02/21 20:46:14 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/02/08 15:39:42 | 002,151,744 | ---- | M] (IObit) [Auto | Stopped] -- C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe -- (LiveUpdateSvc)
SRV - [2013/12/21 15:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/11/11 18:49:06 | 000,208,920 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7rtscan.exe -- (K7RTScan)
SRV - [2013/10/25 14:53:10 | 000,243,736 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7fwsrvc.exe -- (K7FWSrvc)
SRV - [2013/10/05 12:43:22 | 000,242,848 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsmngr.exe -- (K7TSMngr)
SRV - [2013/09/03 23:33:16 | 000,335,384 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7pssrvc.exe -- (K7PSSrvc)
SRV - [2013/06/26 15:57:38 | 000,022,376 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2013/04/02 17:14:02 | 000,154,136 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7emlpxy.exe -- (K7EmlPxy)
SRV - [2012/12/12 15:28:04 | 000,131,760 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe -- (SonicStage Back-End Service2)
SRV - [2012/11/29 21:07:14 | 002,197,600 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe -- (EzDetector)
SRV - [2012/11/29 13:31:28 | 000,174,176 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2012/10/01 16:17:38 | 000,703,616 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files (x86)\epson\MyEPSON Connect\mepService.exe -- (MyEPSON Connect Service)
SRV - [2012/06/21 20:45:52 | 000,281,216 | ---- | M] (K7 Computing Pvt Ltd) [On_Demand | Stopped] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SpmSrc.exe -- (K7SpmSrc)
SRV - [2011/12/21 23:16:54 | 000,262,752 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe -- (K7CrvSvc)
SRV - [2011/03/17 20:40:57 | 000,382,360 | ---- | M] (デジタルアーツ株式会社) [Auto | Running] -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe -- (IFP5WatchService)
SRV - [2011/03/17 20:40:52 | 000,681,368 | ---- | M] (デジタルアーツ株式会社) [Auto | Running] -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe -- (IFP5MainService)
SRV - [2010/12/02 16:08:28 | 000,210,784 | ---- | M] (InterVideo Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service)
SRV - [2010/11/01 13:15:46 | 000,053,248 | ---- | M] (I-O DATA DEVICE, INC.) [Auto | Running] -- C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe -- (mAgicTVDigital)
SRV - [2010/08/25 03:30:00 | 000,075,112 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe -- (Power Manager DBC Service)
SRV - [2010/08/20 14:21:08 | 001,028,096 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service)
SRV - [2009/11/04 13:45:46 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009/11/04 13:45:44 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009/09/02 19:20:18 | 000,071,064 | ---- | M] (Panasonic Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe -- (SD Device Manager)
SRV - [2009/07/09 10:18:24 | 000,126,328 | ---- | M] (BUFFALO INC.) [Auto | Running] -- C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe -- (BWH32S)
SRV - [2009/07/02 16:55:00 | 000,032,248 | ---- | M] (CASIO SOFT CO. LTD.) [Auto | Running] -- C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe -- (LISMO PIM Service)
SRV - [2009/06/11 06:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/07 13:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\Windows\SysWOW64\NlsSrv32.exe -- (nlsX86cc)
SRV - [2007/12/17 13:21:00 | 000,075,040 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe -- (SSScsiSV)
SRV - [2007/12/17 13:20:56 | 000,107,808 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe -- (SonicStage Back-End Service)
SRV - [2007/06/15 12:57:42 | 000,145,504 | ---- | M] (B.H.A Corporation) [Auto | Running] -- C:\Windows\SysWOW64\bgsvcgen.exe -- (bgsvcgen)
SRV - [2007/01/04 19:48:50 | 000,112,152 | ---- | M] (InterVideo) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2013/11/11 11:22:20 | 000,054,528 | ---- | M] (Lenovo.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ibmpmdrv.sys -- (IBMPMDRV)
DRV:[b]64bit:[/b] - [2013/10/18 15:02:54 | 001,199,904 | ---- | M] (K7 Computing Pvt Ltd) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\K7Sentry.Sys -- (K7Sentry)
DRV:[b]64bit:[/b] - [2013/10/02 11:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2013/09/18 20:45:36 | 000,108,320 | ---- | M] (K7 Computing Pvt Ltd) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\K7FWHlpr.Sys -- (K7FWHlpr)
DRV:[b]64bit:[/b] - [2013/04/24 01:23:00 | 000,460,528 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2012/12/13 14:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:[b]64bit:[/b] - [2012/09/12 15:20:04 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:[b]64bit:[/b] - [2012/08/23 23:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:[b]64bit:[/b] - [2012/08/15 15:24:54 | 000,056,336 | ---- | M] (Corel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:[b]64bit:[/b] - [2012/03/01 15:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2012/01/10 22:28:18 | 012,311,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2011/03/11 15:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011/03/11 15:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2011/01/13 14:04:20 | 000,139,888 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsX64.sys -- (Shockprf)
DRV:[b]64bit:[/b] - [2011/01/13 14:02:28 | 000,023,664 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsHM64.sys -- (TPDIGIMN)
DRV:[b]64bit:[/b] - [2010/11/29 20:19:26 | 000,477,432 | ---- | M] (I-O DATA DEVICE, INC.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\gvmvpfz_x64.sys -- (GVMVPFZ)
DRV:[b]64bit:[/b] - [2010/11/20 22:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010/11/20 18:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2010/11/15 07:36:50 | 000,175,688 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\t008mdm.sys -- (t008mdm)
DRV:[b]64bit:[/b] - [2010/11/15 07:36:50 | 000,019,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\t008mdfl.sys -- (t008mdfl)
DRV:[b]64bit:[/b] - [2010/11/15 07:36:48 | 000,154,696 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\t008bus.sys -- (t008bus)
DRV:[b]64bit:[/b] - [2010/11/15 07:36:48 | 000,149,064 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\t008kmmo.sys -- (t008kmmo)
DRV:[b]64bit:[/b] - [2010/11/12 10:34:44 | 000,025,072 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- c:\Program Files\PC-Doctor\pcdsrvc_x64.pkms -- (PCDSRVC{127174DC-C366ED8B-06020101}_0)
DRV:[b]64bit:[/b] - [2010/09/07 14:09:34 | 000,015,472 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\smiifx64.sys -- (lenovo.smi)
DRV:[b]64bit:[/b] - [2010/08/25 03:30:00 | 000,013,104 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\TPPWR64V.SYS -- (TPPWRIF)
DRV:[b]64bit:[/b] - [2010/08/20 03:45:28 | 000,654,720 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emBDA64.sys -- (USB28xxBGA)
DRV:[b]64bit:[/b] - [2010/08/20 03:44:48 | 000,943,872 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emOEM64.sys -- (USB28xxOEM)
DRV:[b]64bit:[/b] - [2010/08/17 11:51:50 | 000,143,992 | ---- | M] (Cobalt Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\DTH10_Series.sys -- (DTH10_Series)
DRV:[b]64bit:[/b] - [2010/05/17 17:32:56 | 001,107,488 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192se.sys -- (rtl8192se)
DRV:[b]64bit:[/b] - [2010/02/26 16:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:[b]64bit:[/b] - [2010/02/03 06:38:30 | 000,271,872 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2010/01/16 05:22:08 | 000,538,136 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:[b]64bit:[/b] - [2009/12/21 10:43:36 | 000,052,224 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAudioHF.sys -- (BthAudioHF)
DRV:[b]64bit:[/b] - [2009/12/21 10:43:00 | 000,078,848 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthav.sys -- (csr_a2dp)
DRV:[b]64bit:[/b] - [2009/09/29 17:25:50 | 000,012,728 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:[b]64bit:[/b] - [2009/09/17 12:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:[b]64bit:[/b] - [2009/08/13 08:38:24 | 000,029,184 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcp.sys -- (BthAvrcp)
DRV:[b]64bit:[/b] - [2009/07/14 10:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/14 10:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/14 10:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/07/14 08:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2009/07/02 11:16:02 | 000,040,512 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\psadd.sys -- (psadd)
DRV:[b]64bit:[/b] - [2009/06/11 06:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:[b]64bit:[/b] - [2009/06/11 06:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:[b]64bit:[/b] - [2009/06/11 06:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:[b]64bit:[/b] - [2009/06/11 05:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/11 05:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2008/02/15 15:01:22 | 000,165,120 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfbd.sys -- (tosrfbd)
DRV:[b]64bit:[/b] - [2008/01/31 15:55:24 | 000,088,448 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV:[b]64bit:[/b] - [2008/01/22 20:58:12 | 000,056,320 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TosRfSnd.sys -- (TosRfSnd)
DRV:[b]64bit:[/b] - [2007/11/29 09:45:58 | 000,044,800 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfbnp.sys -- (tosrfbnp)
DRV:[b]64bit:[/b] - [2007/10/18 14:25:00 | 000,051,328 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfusb.sys -- (Tosrfusb)
DRV:[b]64bit:[/b] - [2007/10/02 11:43:08 | 000,076,160 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfcom.sys -- (Tosrfcom)
DRV:[b]64bit:[/b] - [2007/08/17 14:48:40 | 000,018,432 | ---- | M] (BUFFALO INC.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bufeap64.sys -- (Bufeap)
DRV:[b]64bit:[/b] - [2007/01/12 20:28:06 | 000,077,312 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emAudio64.sys -- (emAudio)
DRV:[b]64bit:[/b] - [2006/10/11 16:31:00 | 000,050,688 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosporte.sys -- (tosporte)
DRV:[b]64bit:[/b] - [2005/07/13 06:43:00 | 000,028,160 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfnds.sys -- (tosrfnds)
DRV - [2009/07/14 10:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2007/01/23 15:56:58 | 000,146,432 | ---- | M] (K7 Computing Pvt Ltd) [File_System | Boot | Running] -- C:\Windows\SysWOW64\drivers\K7Sentry.sys -- (K7Sentry)
DRV - [2006/11/21 22:27:16 | 000,009,728 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysWOW64\drivers\K7FWHlpr.sys -- (K7FWHlpr)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{B51E6D5A-A882-4912-A29B-EDB8314596EC}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/search?q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/jp/ja [binary data]
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.jp/
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


[color=#E56717]========== FireFox ==========[/color]

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@k7computing.com/k7webprotection: C:\Program Files (x86)\\K7 Computing\K7TSecurity\npK7SRNPExt.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\k7srff@k7computing.com: C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SR [2014/02/07 16:29:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\e-webprint@epson.com: C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2014/02/16 18:57:37 | 000,000,000 | ---D | M]


[color=#E56717]========== Chrome ==========[/color]

CHR - homepage: http://www.google.com/
CHR - homepage: http://jp.hao123.com/?tn=epom_pay_hp_04_hao123_jp
CHR - Extension: K7 WebProtection = C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlpfamleaodfgmfnggonbfljhjggbdbe\2.3_0\
CHR - Extension: K7 WebProtection = C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/11 06:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (ExplorerWnd Helper) - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
O2:[b]64bit:[/b] - BHO: (E-Photo) - {60B127CA-8AA4-4DCD-84A8-D18C2B2C4A96} - C:\Program Files (x86)\EPSON Software\E-Photo\EPTBL.dll (SEIKO EPSON CORPORATION)
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (K7 Web Protection) - {08B3B4B6-02DA-4658-8BA6-5974E3EBB03D} - C:\Program Files (x86)\K7 Computing\K7TSecurity\k7srext.dll (K7 Computing Pvt Ltd)
O2 - BHO: (E-Web Print) - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (E-Photo) - {60B127CA-8AA4-4DCD-84A8-D18C2B2C4A96} - C:\Program Files (x86)\EPSON Software\E-Photo\EPTBL.dll (SEIKO EPSON CORPORATION)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (E-Web Print) - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\..\Toolbar\WebBrowser: (no name) - {AEF44653-C059-42CB-A5B7-41C640DA4A67} - No CLSID value found.
O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe (Lenovo Group Limited)
O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [TpShocks] C:\Windows\SysNative\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [K7SystemTray] "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe" File not found
O4 - HKLM..\Run: [K7TSStart] C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe (K7 Computing Pvt Ltd)
O4 - HKLM..\Run: [LPStation] C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe (Sony Corporation)
O4 - HKLM..\Run: [PWMTRV] C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL (Lenovo Group Limited)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series" File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O9:[b]64bit:[/b] - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O9 - Extra Button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll (Apple Inc.)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000020 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab (DMM Downloader)
O16 - DPF: {4845B7A7-309F-49F4-A2DD-0117707B6E8D} https://toast.dvdtoaster.jp/downloads/activex/x86/dvdtoast.cab (DVD Toaster ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 10.51.2)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 1.7.0_09)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.51.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C059A8EC-DFD2-4F21-91C1-A1C6D9343219}: DhcpNameServer = 192.168.11.1
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/11 01:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{a1c8f30f-342e-11e0-be01-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{a1c8f30f-342e-11e0-be01-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe -- [2009/08/11 06:01:24 | 000,267,576 | -HS- | M] (Lenovo Group Limited)
O33 - MountPoints2\{f931b122-03a5-11e1-bc2d-001b41049f1d}\Shell - "" = AutoRun
O33 - MountPoints2\{f931b122-03a5-11e1-bc2d-001b41049f1d}\Shell\AutoRun\command - "" = E:\g_setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (K7TSDbg)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2014/02/22 08:59:02 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2014/02/22 08:58:59 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWbPrxy.exe
[2014/02/22 08:58:59 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
[2014/02/22 08:58:59 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2014/02/22 08:58:59 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsRdpWebAccess.dll
[2014/02/22 08:58:59 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
[2014/02/22 08:58:59 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MsRdpWebAccess.dll
[2014/02/22 08:58:59 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprtPS.dll
[2014/02/22 08:58:59 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wksprtPS.dll
[2014/02/22 08:58:59 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2014/02/22 08:58:59 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2014/02/22 08:58:57 | 001,147,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe
[2014/02/22 08:58:57 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
[2014/02/22 08:58:57 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprt.exe
[2014/02/22 08:58:56 | 006,578,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2014/02/22 08:58:56 | 005,698,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2014/02/22 08:58:56 | 001,057,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdvidcrl.dll
[2014/02/22 08:58:56 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdvidcrl.dll
[2014/02/22 08:58:21 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2014/02/22 08:58:19 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2014/02/22 08:58:15 | 003,174,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll
[2014/02/22 08:58:15 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpudd.dll
[2014/02/22 08:58:15 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpendp_winip.dll
[2014/02/22 08:58:15 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpendp_winip.dll
[2014/02/22 08:10:53 | 001,030,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWorkspace.dll
[2014/02/22 08:10:53 | 000,792,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TSWorkspace.dll
[2014/02/22 08:10:39 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2014/02/22 08:10:39 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2014/02/19 08:41:20 | 000,365,976 | ---- | C] (デジタルアーツ株式会社) -- C:\Windows\SysWow64\ifp5lsp.dll
[2014/02/17 07:26:36 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Roaming\Epson
[2014/02/16 19:25:01 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\Desktop\エプソンショートカット
[2014/02/16 18:56:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\読んde!!ココ
[2014/02/16 18:56:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Aisoft
[2014/02/16 18:55:05 | 000,000,000 | ---D | C] -- C:\ProgramData\UDL
[2014/02/16 18:44:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\EPSON
[2014/02/16 18:42:33 | 000,558,592 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\ensppmon.dll
[2014/02/16 18:42:33 | 000,535,552 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\ensppui.dll
[2014/02/16 18:42:33 | 000,211,968 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\enspres.dll
[2014/02/16 18:42:33 | 000,211,968 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\enpres.dll
[2014/02/16 18:42:32 | 000,558,592 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\enppmon.dll
[2014/02/16 18:42:32 | 000,535,552 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\enppui.dll
[2014/02/16 18:42:32 | 000,000,000 | ---D | C] -- C:\Program Files\EpsonNet
[2014/02/16 18:35:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software
[2014/02/16 18:35:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EPSON Software
[2014/02/16 18:35:06 | 000,466,432 | ---- | C] (Seiko Epson Corporation) -- C:\Windows\SysNative\esxw2ud.dll
[2014/02/16 18:35:06 | 000,144,560 | ---- | C] (Seiko Epson Corporation) -- C:\Windows\SysNative\escsvc64.exe
[2014/02/16 18:35:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
[2014/02/16 18:35:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\epson
[2014/02/16 18:34:10 | 000,179,712 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\E_ILMBLMJ.DLL
[2014/02/16 18:34:10 | 000,083,968 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\E_ID4BLMJ.DLL
[2014/02/16 18:34:10 | 000,010,752 | ---- | C] (SEIKO EPSON CORP.) -- C:\Windows\SysNative\E_GCINST.DLL
[2014/02/15 08:23:43 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\Desktop\ぱそこん
[2014/02/13 15:38:39 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/02/13 15:21:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2014/02/13 14:24:54 | 000,821,736 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2014/02/13 14:24:54 | 000,746,984 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2014/02/13 10:55:28 | 000,548,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014/02/13 10:54:57 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/02/13 10:54:57 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/02/13 10:54:56 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/02/13 10:54:56 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/02/13 10:54:55 | 000,627,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/02/13 10:54:55 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/02/13 10:54:55 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/02/13 10:54:55 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/02/13 10:54:54 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/02/13 10:54:54 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/02/13 10:54:54 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/02/13 10:54:54 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/02/13 10:54:54 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/02/13 10:54:54 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/02/13 10:54:54 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/02/13 10:54:54 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/02/13 10:54:53 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/02/13 10:54:53 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/02/13 10:54:53 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/02/13 10:54:53 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/02/13 10:54:52 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/02/13 10:54:52 | 001,964,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/02/13 10:54:50 | 005,768,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/02/12 17:55:31 | 002,565,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2014/02/12 17:55:30 | 003,928,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2014/02/12 17:54:41 | 000,658,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe
[2014/02/12 17:54:41 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe
[2014/02/12 17:54:41 | 000,594,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe
[2014/02/12 17:54:40 | 000,572,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe
[2014/02/12 17:54:40 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2014/02/12 17:54:40 | 000,508,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2014/02/12 17:54:39 | 000,553,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe
[2014/02/12 17:54:39 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe
[2014/02/12 17:54:39 | 000,485,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll
[2014/02/12 17:54:39 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll
[2014/02/12 17:54:38 | 000,528,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdrm.dll
[2014/02/12 17:54:38 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll
[2014/02/12 17:54:38 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2014/02/12 17:54:37 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll
[2014/02/12 17:54:37 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll
[2014/02/12 17:54:36 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll
[2014/02/12 17:54:36 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll
[2014/02/12 17:50:04 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll
[2014/02/12 17:50:03 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll
[2014/02/12 10:26:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2014/02/12 10:26:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2014/02/12 09:51:19 | 000,028,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEUDINIT.EXE
[2014/02/12 09:46:13 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2014/02/12 09:46:13 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2014/02/12 09:46:10 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2014/02/12 09:46:10 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2014/02/12 09:46:10 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2014/02/12 09:46:10 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2014/02/12 09:46:10 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2014/02/12 09:46:10 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2014/02/12 09:46:10 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2014/02/12 09:46:10 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2014/02/12 09:46:10 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2014/02/12 09:46:10 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2014/02/12 09:46:09 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2014/02/12 09:46:09 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2014/02/12 09:46:09 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2014/02/12 09:46:09 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2014/02/12 09:46:09 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2014/02/12 09:46:09 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2014/02/12 09:46:09 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2014/02/12 09:46:09 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2014/02/12 09:46:09 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2014/02/12 09:46:09 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014/02/12 09:46:09 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2014/02/12 09:46:09 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2014/02/12 09:46:09 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2014/02/12 09:46:09 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2014/02/12 09:46:08 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2014/02/12 09:46:07 | 001,228,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2014/02/12 09:46:07 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2014/02/12 09:46:07 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2014/02/12 09:46:07 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2014/02/12 09:46:07 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014/02/12 09:46:07 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2014/02/12 09:46:07 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2014/02/12 09:46:07 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2014/02/12 09:46:07 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2014/02/12 09:46:07 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2014/02/12 09:46:07 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2014/02/12 09:46:07 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2014/02/12 09:46:07 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2014/02/12 09:46:07 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2014/02/12 09:46:07 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2014/02/12 09:46:07 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2014/02/12 09:46:07 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2014/02/12 09:46:07 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2014/02/12 09:46:07 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014/02/12 09:46:07 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2014/02/12 09:46:07 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2014/02/12 09:46:07 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2014/02/12 09:46:07 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2014/02/12 09:46:07 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2014/02/12 09:46:07 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2014/02/12 09:46:07 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2014/02/12 09:46:07 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2014/02/12 09:46:07 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2014/02/12 09:46:07 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2014/02/10 16:26:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2014/02/10 16:12:21 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Roaming\Malwarebytes
[2014/02/10 16:11:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/02/08 17:23:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2014/02/08 17:23:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2014/02/08 17:23:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014/02/08 16:13:31 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Roaming\ProductData
[2014/02/08 15:39:50 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Roaming\IObit
[2014/02/08 15:39:47 | 000,000,000 | ---D | C] -- C:\ProgramData\ProductData
[2014/02/08 15:39:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller
[2014/02/08 15:39:47 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2014/02/08 15:39:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit
[2014/02/08 15:26:01 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2014/02/07 17:48:27 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\Documents\写真
[2014/02/06 17:34:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\predm
[2014/02/03 22:07:48 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Local\I-O DATA
[2014/02/03 22:07:41 | 000,000,000 | ---D | C] -- C:\mAgicTVD
[2014/02/03 22:07:41 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Roaming\I-O DATA
[2014/02/03 21:35:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bonjour
[2014/02/03 21:35:36 | 000,036,864 | ---- | C] (TOSHIBA/MEI) -- C:\Windows\SysWow64\SDDEVMGR.dll
[2014/02/03 21:35:35 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\sda
[2014/02/03 21:35:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2014/02/03 21:26:17 | 000,00
  • ryoyoung
  • MAIL
  • 2014/02/22 (Sat) 18:26:34
再度OTLでfix作業を
作業と報告、ご苦労様です。
ログを見たところ、先に処置できたと思ったhao123などがまだ残ってますね。
ではまたスクリプトを使ってOTLでの作業を再度しましょう。

先の手順でまたセーフモードでOTLを起動して、以下のスクリプトを使って「Run fix」作業してください。

そのあと再起動後、状態報告とOTLの作業後ログをレスください
-----------------------------------------------
:OTL
CHR - homepage: http://jp.hao123.com/?tn=epom_pay_hp_04_hao123_jp
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000020 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab (DMM Downloader)

:Files

:Commands
[purity]
[resethosts]
[emptytemp]
[createrestorepoint]
[reboot]
  • 悪代官
  • 2014/02/22 (Sat) 19:51:32
Re: 駆除
hao123が出なくなって今度こそいいのかな、と思ったらまたよくアクセスサイトにいつの間にか入っていました。どんなもんでしょうか?よろしくお願いします。
All processes killed
========== OTL ==========
Use Chrome's Settings page to change the HomePage.
Starting removal of ActiveX control {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7}
C:\Windows\Downloaded Program Files\DMM Downloader.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0725D9DE-4CB8-4BC3-8219-3E74C0D544F7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0725D9DE-4CB8-4BC3-8219-3E74C0D544F7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{0725D9DE-4CB8-4BC3-8219-3E74C0D544F7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0725D9DE-4CB8-4BC3-8219-3E74C0D544F7}\ not found.
File rity] not found.
File sethosts] not found.
File ptytemp] not found.
File eaterestorepoint] not found.
File boot] not found.

OTL by OldTimer - Version 3.2.69.0 log created on 02242014_085312

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • ryoyoung
  • MAIL
  • 2014/02/24 (Mon) 14:03:18
異常が出るページを教えてください
作業と報告、ご苦労様です。
OTLの結果はとりあえずいいとして、

>hao123が出なくなって今度こそいいのかな、と思ったらまたよくアクセスサイトにいつの間にか入っていました

ということは、現在異常が出るのはそのサイトまたはページということですね?
ではそのページのURLをレスに貼って教えてください。
感染がなくてもサイト側に埋め込まれた広告が原因の事例も多いので、この場合はPC側の問題ではないです。
この場合はそのサイトにアクセスを控えるといった対応になるでしょう
  • 悪代官
  • 2014/02/24 (Mon) 17:14:35
Re: 駆除
すいません。悪代官様。私の説明が間違っていました。

>hao123が出なくなって今度こそいいのかな、と思ったらまたよくアクセスサイトにいつの間にか入っていました

Windows7でInternetExPloreを起動するときに、よくアクセスするサイト(youtubeとかYahooとか)を表示を手助けしてくれるのですが、アクセスしてないのに、hao123とかが表示されます。右クリックで一覧から削除してもまたいつのまにか表示されます。
今のところ、いろいろなサイトを見ても変な広告などは出ませんし、hao123に誘導されることもありません。

別に気にしなくてもよいのであれば、特別問題ないかもしれません(また言葉不足かな・・)。




  • ryoyoung
  • MAIL
  • 2014/02/24 (Mon) 18:04:42
ではまたログを見てみます
>アクセスしてないのに、hao123とかが表示されます。右クリックで一覧から削除してもまたいつのまにか表示されます。

なるほど、それならまだ異常が続いている状態ですね。
ではまた調べ直してみましょう。

全体の状況を見直すので、HJTとインストール情報ログと、CCでの各タブのログをまた取り直して、それらをまた返信に貼って見せてください
  • 悪代官
  • 2014/02/24 (Mon) 18:25:26
Re: 駆除
ご苦労さんです。がんばります。お願いします。

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:23:25, on 2014/02/25
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\EPSON\MyEPSON Connect\mep.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMECMNT.EXE
C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe
C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SysMon.Exe
C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe
C:\Users\オヤジ\Downloads\HijackThis.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMECMNT.EXE

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: K7 Web Protection - {08B3B4B6-02DA-4658-8BA6-5974E3EBB03D} - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
O2 - BHO: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Microsoft アカウント サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [K7TSStart] C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [LPStation] C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [K7SystemTray] "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
O4 - HKLM\..\Run: [iFilter5] "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Continue installation.lnk = ?
O4 - Global Startup: PHOTOfunSTUDIO 5.0 HD Edition.lnk = C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
O4 - Global Startup: クライアントマネージャV.lnk = C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: OneNote に送る(&N) - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: OneNote に送る - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: OneNote に送る(&N) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {4845B7A7-309F-49F4-A2DD-0117707B6E8D} (DVD Toaster ActiveX Control) - https://toast.dvdtoaster.jp/downloads/activex/x86/dvdtoast.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: Bonjour サービス (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: BWH32S - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EzDetector - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: i-フィルター 5.0 Main (IFP5MainService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
O23 - Service: i-フィルター 5.0 Support (IFP5WatchService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: K7Carnivore Service (K7CrvSvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe
O23 - Service: K7Computng - EMail Proxy Server (K7EmlPxy) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7EmlPxy.exe
O23 - Service: K7Firewall Services (K7FWSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7FWSrvc.exe
O23 - Service: K7Privacy Services (K7PSSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7PSSrvc.exe
O23 - Service: K7RealTime AntiVirus Services (K7RTScan) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7RTScan.exe
O23 - Service: K7SpmSrc - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SpmSrc.exe
O23 - Service: K7TotalSecurity Manager (K7TSMngr) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSMngr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: LISMO PIM Service - CASIO SOFT CO. LTD. - C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: I-O DATA mAgicTV Digital (mAgicTVDigital) - I-O DATA DEVICE, INC. - C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyEPSON Connect Service - SEIKO EPSON CORPORATION - C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NlsSrv32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SD Device Manager - Panasonic Corporation - C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: SonicStage Back-End Service2 - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14353 bytes
Access Help Lenovo 2011/02/09 3.00
Adobe Flash Player 12 ActiveX Adobe Systems Incorporated 2014/02/21 6.00 MB 12.0.0.70
Adobe Reader XI (11.0.06) - Japanese Adobe Systems Incorporated 2014/02/12 147 MB 11.0.06
Apple Application Support Apple Inc. 2013/10/01 64.0 MB 2.3.6
Apple Mobile Device Support Apple Inc. 2013/10/01 25.0 MB 7.0.0.117
au ISW11K USB Driver 京セラ株式会社 2012/03/01 1.00.0000
au T008 USB Driver Ver.5.0.0.1 2011/09/24 V5.24.1.0
Bonjour Apple Inc. 2014/02/03 3.29 MB 1.0.106
BUFFALO エアステーション設定ツール BUFFALO INC. 2011/09/25 2.84 MB 2.0.5
BUFFALO クライアントマネージャV BUFFALO INC. 2014/02/20
BUFFALO パソコン環境表示ツール BUFFALO INC. 2011/09/25 1.0.3
Corel DVD MovieWriter Lenovo Edition Corel Corporation 2011/02/09 320 MB 7.0.0
Corel TVX Corel Corporation 2014/02/03 31.2 MB 2.2-B0.5
Create Recovery Media Lenovo Group Limited 2011/02/09 9.50 MB 1.20.0.00
DVD Decrypter (Remove Only) 2014/02/20
DVD Flick 1.3.0.7 Dennis Meuwissen 2012/05/05 1.3.0.7
DVD Shrink 3.2 DVD Shrink 2014/02/20
Epson E-Photo SEIKO EPSON CORPORATION 2014/02/16 1.4.1.0
Epson E-Web Print SEIKO EPSON CORPORATION 2014/02/16 9.22 MB 1.19.0000
EPSON EP-706A Series プリンター アンインストール SEIKO EPSON Corporation 2014/02/16
Epson Event Manager Seiko Epson Corporation 2014/02/16 42.4 MB 3.10.0017
Epson Print CD SEIKO EPSON CORPORATION 2014/02/16 2.21.00
EPSON Scan Seiko Epson Corporation 2014/02/20
EPSON Scan OCR コンポーネント SEIKO EPSON Corp. 2014/02/16 1.33.0000
EPSON マニュアル SEIKO EPSON CORPORATION 2014/02/16 704 KB 1.32.0.0
EpsonNet Print SEIKO EPSON CORPORATION 2014/02/16 2.6.0
I-O DATA mAgicTV Digital I-O DATA DEVICE,INC. 2014/02/03 1.01.00
Intel(R) Control Center Intel Corporation 2011/02/09 1.2.1.1007
Intel(R) Graphics Media Accelerator Driver Intel Corporation 2011/02/09 8.15.10.2125
Intel(R) Management Engine Components Intel Corporation 2011/02/09 6.0.0.1179
InterVideo WinDVD 8 InterVideo Inc. 2011/02/09 163 MB 8.0.20.199
IObit Uninstaller IObit 2014/02/08 3.1.7.2405
Java 7 Update 51 Oracle 2014/02/08 118 MB 7.0.510
Jw_cad 2014/02/20
Lenovo Auto Scroll Utility 2011/02/09 1.00
Lenovo Patch Utility Lenovo Group Limited 2013/05/12 1.33 MB 1.3.1.1
Lenovo Patch Utility 64 bit Lenovo Group Limited 2013/05/12 1.35 MB 1.3.1.1
Lenovo Power Management Driver 2014/02/22 1.67.04.04
Lenovo System Interface Driver 2013/05/12 1.05
Lenovo System Update Lenovo 2013/07/16 13.4 MB 5.02.0018
Lenovo ThinkVantage Toolbox PC-Doctor, Inc. 2011/02/09 6.0.5717.21
Lenovo Warranty Information Lenovo 2011/02/09 893 KB 1.0.0004.00
Lenovo Welcome Lenovo 2011/02/09
LISMO Port 5.1 Sony Corporation 2013/03/10 110 MB 5.1
Message Center Plus Lenovo Group Limited 2011/02/09 1.70 MB 2.0.0012.00
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 2011/02/27 38.8 MB 4.0.30319
Microsoft Office Home and Business 2010 Microsoft Corporation 2014/02/20 14.0.7015.1000
Microsoft Office Word Viewer 2003 Microsoft Corporation 2014/01/16 105 MB 11.0.8173.0
Microsoft Silverlight Microsoft Corporation 2013/10/10 149 MB 5.1.20913.0
Microsoft SkyDrive Microsoft Corporation 2013/01/15 25.1 MB 16.4.6013.0910
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2011/02/09 1.69 MB 3.1.0000
Microsoft SQL Server Compact 3.5 SP1 English Microsoft Corporation 2011/02/28 2.59 MB 3.5.5692.0
Microsoft SQL Server Compact 3.5 SP1 x64 English Microsoft Corporation 2011/02/28 3.69 MB 3.5.5692.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 Microsoft Corporation 2011/02/26 260 KB 8.0.50727.4053
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 2011/02/26 250 KB 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2014/02/03 2.38 MB 8.0.59193
Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 2011/02/09 840 KB 8.0.61000
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2013/10/01 248 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2011/02/16 784 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 2011/06/20 788 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2011/03/17 234 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2011/02/16 592 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2011/06/20 600 KB 9.0.30729.6161
Mobile Broadband Lenovo 2011/02/09 16.4 MB 3.6.0034
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2011/02/18 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2011/02/18 1.33 MB 4.20.9876.0
MyEPSON Portal SEIKO EPSON Corporation 2014/02/20
PHOTOfunSTUDIO 5.0 HD Edition Panasonic Corporation 2011/02/28 5.00.313
QuickTime Apple Inc. 2012/11/07 73.2 MB 7.72.80.56
Registry Patch to arrange icons in Device and Printers folder of Windows 7 2011/02/09 1.00
Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7 2011/02/09 1.00
Rescue and Recovery Lenovo Group Limited 2013/05/12 101 MB 4.31.0005.00
SAMSUNG USB Driver for Mobile Phones SAMSUNG Electronics Co., Ltd. 2013/08/07 42.9 MB 1.5.16.0
Software Updater SEIKO EPSON CORPORATION 2014/02/16 8.19 MB 4.2.1
SonicStage 4.4 Sony Corporation 2012/02/15 4.4
Sony Media Library Earth 8.1.00 Sony Corporation 2013/03/10 47.3 MB 8.1.00.11292
ThinkPad UltraNav Driver 2014/02/22 46.4 MB 16.2.19.7
ThinkPad Wireless LAN Adapter Software REALTEK Semiconductor Corp. 2011/02/09 1.00.0024.0
ThinkPad 省電力マネージャー 2014/02/20 3.30
ThinkVantage Communications Utility Lenovo 2011/02/09 2.43 MB 1.41
ThinkVantage ハードディスク・アクティブプロテクション・システム Lenovo 2011/02/09 15.6 MB 1.74
USB Video/Audio Device Driver 会社名 2012/07/29 15.4 MB 1.00.0000
Windows Live Essentials Microsoft Corporation 2013/01/15 16.4.3505.0912
Windows ドライバ パッケージ - I-O DATA DEVICE, INC. GV-MVP/FZ(x64) (11/29/2010 1.8.2.12) I-O DATA DEVICE, INC. 2014/02/03 11/29/2010 1.8.2.12
Windows ドライバ パッケージ - Intel (iaStor) hdc (01/15/2010 9.5.7.1002) Intel 2011/02/09 01/15/2010 9.5.7.1002
Windows ドライバ パッケージ - Intel hdc (06/04/2009 7.0.0.1013) Intel 2011/02/09 06/04/2009 7.0.0.1013
Windows ドライバ パッケージ - Intel System (06/04/2009 1.0.0.0002) Intel 2011/02/09 06/04/2009 1.0.0.0002
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/09 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/10 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel USB (08/20/2009 9.1.1.1020) Intel 2011/02/09 08/20/2009 9.1.1.1020
Windows ドライバ パッケージ - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4) Lenovo 2011/02/09 11/18/2009 1.60.0.4
Windows ドライバ パッケージ - Realtek Semiconductor Corp. HD Audio Driver (06/29/2010 6.0.1.6146) Realtek Semiconductor Corp. 2011/02/09 06/29/2010 6.0.1.6146
インテル(R) ターボ・ブースト・テクノロジー・モニター インテル 2011/02/09 1.13 MB 1.0.186.3
ウイルスセキュリティ ソースネクスト株式会社 2014/02/20 12.00
読んde!!ココ パーソナル 2014/02/16

有効 HKCU:Run EPLTarget\P0000000000000000 SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series"
有効 HKLM:Run Adobe ARM Adobe Systems Incorporated "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
有効 HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
有効 HKLM:Run EEventManager SEIKO EPSON CORPORATION "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
有効 HKLM:Run HotKeysCmds Intel Corporation C:\Windows\system32\hkcmd.exe
有効 HKLM:Run iFilter5 "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
有効 HKLM:Run IgfxTray Intel Corporation C:\Windows\system32\igfxtray.exe
有効 HKLM:Run IME14 JPN Setup Microsoft Corporation C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
有効 HKLM:Run K7SystemTray "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
有効 HKLM:Run K7TSStart K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
有効 HKLM:Run LENOVO.TPKNRRES Lenovo Group Limited C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
有効 HKLM:Run LPStation Sony Corporation C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
有効 HKLM:Run Persistence Intel Corporation C:\Windows\system32\igfxpers.exe
有効 HKLM:Run PWMTRV rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
有効 HKLM:Run QuickTime Task Apple Inc. "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
有効 HKLM:Run TpShocks Lenovo. TpShocks.exe
有効 Startup Common Continue installation.lnk Red Sky Sp. z o.o. C:\Users\オヤジ\AppData\Local\Temp\Free_files_downloader.exe
有効 Startup Common PHOTOfunSTUDIO 5.0 HD Edition.lnk Panasonic Corporation C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
有効 Startup Common クライアントマネージャV.lnk BUFFALO INC. C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe

有効 HKCU:Run EPLTarget\P0000000000000000 SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series"
有効 HKLM:Run Adobe ARM Adobe Systems Incorporated "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
有効 HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
有効 HKLM:Run EEventManager SEIKO EPSON CORPORATION "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
有効 HKLM:Run HotKeysCmds Intel Corporation C:\Windows\system32\hkcmd.exe
有効 HKLM:Run iFilter5 "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
有効 HKLM:Run IgfxTray Intel Corporation C:\Windows\system32\igfxtray.exe
有効 HKLM:Run IME14 JPN Setup Microsoft Corporation C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
有効 HKLM:Run K7SystemTray "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
有効 HKLM:Run K7TSStart K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
有効 HKLM:Run LENOVO.TPKNRRES Lenovo Group Limited C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
有効 HKLM:Run LPStation Sony Corporation C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
有効 HKLM:Run Persistence Intel Corporation C:\Windows\system32\igfxpers.exe
有効 HKLM:Run PWMTRV rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
有効 HKLM:Run QuickTime Task Apple Inc. "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
有効 HKLM:Run TpShocks Lenovo. TpShocks.exe
有効 Startup Common Continue installation.lnk Red Sky Sp. z o.o. C:\Users\オヤジ\AppData\Local\Temp\Free_files_downloader.exe
有効 Startup Common PHOTOfunSTUDIO 5.0 HD Edition.lnk Panasonic Corporation C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
有効 Startup Common クライアントマネージャV.lnk BUFFALO INC. C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe

有効 Extension K7 WebProtection 2.3 譛€蛻昴・繝ヲ繝シ繧カ繝シ C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlpfamleaodfgmfnggonbfljhjggbdbe\2.3_0

有効 Extension K7 WebProtection 2.3 譛€蛻昴・繝ヲ繝シ繧カ繝シ C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlpfamleaodfgmfnggonbfljhjggbdbe\2.3_0

  • ryoyoung
  • MAIL
  • 2014/02/25 (Tue) 08:39:20
あと2つのログもお願いします
またレスが遅くなってすみません。

各ログを見せてもらいましたが、現在のところ不審なものは見えてませんね。
ただ「IE」タブと「スケジュールされたタスク」のログが出てないので、これも追加で見せてください。
  • 悪代官
  • 2014/02/25 (Tue) 16:34:45
Re: 駆除
また忘れましたか!
度々すいません。

有効 Extension Bonjour Apple Inc. C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension このコンテンツを引用 Microsoft Corporation C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
有効 Helper E-Photo SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Photo\EPTBL.dll
有効 Helper E-Web Print SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
有効 Helper ExplorerWnd Helper IObit C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper C:\Program Files\Java\jre6\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre7\bin\ssv.dll
無効 Helper K7 Web Protection K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
無効 Helper Microsoft アカウント サインイン ヘルパー Microsoft Corp. C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
無効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
無効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL
無効 Helper Windows Live ID Sign-in Helper Microsoft Corp. C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 Toolbar E-Photo SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Photo\EPTBL.dll
有効 Toolbar E-Web Print SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll

有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task EPSON EP-706A Series Update {8BD34A37-ADC7-417C-9A46-53B2A5F6AEF8} SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLMJ.EXE /EXE:"{8BD34A37-ADC7-417C-9A46-53B2A5F6AEF8}" /F:"Update"
有効 Task {4A17C693-E678-4A3E-A662-5DA104A7DD3C} Microsoft Corporation C:\Windows\system32\pcalua.exe -a C:\Users\オヤジ\Downloads\HijackThis.exe -d C:\Users\オヤジ\Downloads

今のところ落ち着いているので、hao123と表示されるのは、気にしなくてもいいということですかね?a
  • ryoyoung
  • MAIL
  • 2014/02/25 (Tue) 17:34:39
では手動目視で確認を
早速の報告ありがとうございます。
追加の炉を見たところ、おかしな痕跡は見えませんね。

では以下の手順で確認作業をお願いします。

まず現在異常が出ているブラウザがIEだけなら、以下の手順で確認です。
インターネットオプションの「プログラム」→「アドオンの管理」を開いてください。

そこで「ツールバーと拡張機能」「検索プロバイダー」「アクセラレータ」の各欄を見て、hao123かそれに該当するもの、またはご自身で入れた覚えもないのに入っていたおかしな検索エンジンが見つかれば、それを「無効」「削除」してください。

このあとまたIEを起動してしばらく様子見後、報告をレスください。

異常発生するブラウザがIEでなくChromeならそのことをまたレスで報告ください。
この場合はChrome用の対処をレスします
  • 悪代官
  • 2014/02/25 (Tue) 17:48:28
Re: 駆除
度々ありがとうございます。IEで「ツールバーと拡張機能」「検索プロバイダー」「アクセラレータ」の各欄を見て、hao123はありませんでしたが、「ツールバーと拡張機能」に利用不可とはなっていましたが、Free youtube downnloadが有効になったおりましたので、無効にしました(悪代官さまの指示で削除したよな?)。
これで一応大丈夫と思って様子見しておりましたら、やっぱしばらくしてhao123が表示されました。
ただパソコンは前にも書いたとおり、いろいろなサイトを見ても今のところ異常はありません。
これで正常に戻っていると思ってもいいのでしょうか?
  • ryoyoung
  • MAIL
  • 2014/02/26 (Wed) 13:55:26
IUから調べてみましょう
レスが遅くなってすみません。

>IEで「ツールバーと拡張機能」「検索プロバイダー」「アクセラレータ」の各欄を見て、hao123はありませんでしたが、「ツールバーと拡張機能」に利用不可とはなっていましたが、Free youtube downnloadが有効になったおりましたので、無効にしました(悪代官さまの指示で削除したよな?)。
>これで一応大丈夫と思って様子見しておりましたら、やっぱしばらくしてhao123が表示されました。

はい、わかりました。やはりかなり巧妙に隠れてますね。

>ただパソコンは前にも書いたとおり、いろいろなサイトを見ても今のところ異常はありません

異常がないならその点はいいですが、削除しても復活するというのは正常ではありませんね。

では今度はIUを使って調べます。
IUを起動して、画面上部の「詳細設定」アイコンをクリックして「プログラムリストをエクスポート」してください。
これでIUでのログが保存可能になりますから、そのログをデスクトップに保存してください。

IUNのこのログはインストール情報ログと同じようなログですが、情報ログよりも詳細な内容が解析可能なのです。
その代りIUでのログはかなり大きくなるので、解析に時間と手間がかかるのですが、今回はこれを調べてみます。

IUのログを取ったら、そのログをまたレスで見せてください。
これを調べてから次の対処を探ります
  • 悪代官
  • 2014/02/26 (Wed) 17:18:38
Re: 駆除
ご面倒かけます。

====================================
Software List
Application Version:3.1.7.2405
Windows 7
Exported Time:02-27-2014 08:19:15
====================================

Software Name: Adobe Flash Player 12 ActiveX
Version: 12.0.0.70
Publisher: Adobe Systems Incorporated
Install Time: 2011/02/09
Size: 6.00 MB
Help info: http://www.adobe.com/go/flashplayer_support/
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
Uninstall Command: C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_70_ActiveX.exe -maintain activex
----------------------------------------------

Software Name: BUFFALO エアステーション設定ツール
Version: 2.0.5
Publisher: BUFFALO INC.
Install Time: 2011/09/25
Size: 2.84 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BUFFALO_AirSet2_is1
Uninstall Command: "C:\Program Files (x86)\BUFFALO\AirSet2\unins000.exe"
----------------------------------------------

Software Name: BUFFALO パソコン環境表示ツール
Version: 1.0.3
Publisher: BUFFALO INC.
Install Time: 2011/09/25
Size: 4.78 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BUFFALO_BPCEnv_is1
Uninstall Command: "C:\Program Files (x86)\BUFFALO\BPCEnv\unins000.exe"
----------------------------------------------

Software Name: DVD Decrypter (Remove Only)
Version: -
Publisher:
Install Time: 2011/02/18
Size: 923.25 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVD Decrypter
Uninstall Command: "C:\Program Files (x86)\DVD Decrypter\uninstall.exe"
----------------------------------------------

Software Name: DVD Flick 1.3.0.7
Version: 1.3.0.7
Publisher: Dennis Meuwissen
Install Time: 2012/05/05
Size: 44.50 MB
Help info: http://www.dvdflick.net
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVD Flick_is1
Uninstall Command: "C:\Program Files (x86)\DVD Flick\unins000.exe"
----------------------------------------------

Software Name: DVD Shrink 3.2
Version: -
Publisher: DVD Shrink
Install Time: 2011/02/18
Size: 969.85 KB
Help info: http://www.dvdshrink.org
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVD Shrink_is1
Uninstall Command: "C:\Program Files (x86)\DVD Shrink\unins000.exe"
----------------------------------------------

Software Name: EPSON Scan
Version: -
Publisher: Seiko Epson Corporation
Install Time: 2014/02/16
Size: 825.86 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EPSON Scanner
Uninstall Command: C:\Program Files (x86)\epson\escndv\setup\setup.exe /r
----------------------------------------------

Software Name: InterVideo WinDVD 8
Version: 8.0.20.199
Publisher: InterVideo Inc.
Install Time: 2011/02/09
Size: 163.07 MB
Help info: http://www.intervideo.com/jsp/Support.jsp/
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}
Uninstall Command: "C:\Program Files (x86)\InstallShield Installation Information\{20471B27-D702-4FE8-8DEC-0702CC8C0A85}\setup.exe" -runfromtemp -l0x0411 -removeonly
----------------------------------------------

Software Name: Corel DVD MovieWriter Lenovo Edition
Version: 7.0.0
Publisher: Corel Corporation
Install Time: 2011/02/09
Size: 320.75 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{50F68032-B5B7-4513-9116-C978DBD8F27A}
Uninstall Command: C:\Program Files (x86)\InstallShield Installation Information\{50F68032-B5B7-4513-9116-C978DBD8F27A}\setup.exe -runfromtemp -l0x0411
----------------------------------------------

Software Name: Corel AVControl v2.2.0.5
Version: 2.2.0.5
Publisher: Corel Corporation
Install Time: 2014/02/03
Size: 39.73 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{B246B33F-6C9F-49E3-A784-B92844C657A0}
Uninstall Command: C:\Program Files (x86)\InstallShield Installation Information\{B246B33F-6C9F-49E3-A784-B92844C657A0}\setup.exe -runfromtemp -l0x0409
----------------------------------------------

Software Name: LISMO Port 5.1
Version: 5.1
Publisher: Sony Corporation
Install Time: 2013/03/10
Size: 110.11 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{B934AEDA-B8BA-4458-A56C-C94897EFABA5}
Uninstall Command: "C:\Program Files (x86)\InstallShield Installation Information\{B934AEDA-B8BA-4458-A56C-C94897EFABA5}\setup.exe" -l0x0411 -removeonly
----------------------------------------------

Software Name: USB Video/Audio Device Driver
Version: 1.00.0000
Publisher: 会社名
Install Time: 2012/07/29
Size: 15.46 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{BCC5DC79-2275-4171-8CEA-39F0DD9ADF58}
Uninstall Command: C:\Program Files (x86)\InstallShield Installation Information\{BCC5DC79-2275-4171-8CEA-39F0DD9ADF58}\setup.exe -runfromtemp -l0x0411
----------------------------------------------

Software Name: Sony Media Library Earth 8.1.00
Version: 8.1.00.11292
Publisher: Sony Corporation
Install Time: 2013/03/10
Size: 47.39 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{CCC78AD3-D315-4DA1-8C12-CC561E69B378}
Uninstall Command: C:\Program Files (x86)\InstallShield Installation Information\{CCC78AD3-D315-4DA1-8C12-CC561E69B378}\IS_Setup.exe -l0x0411 /z"UNINSTALL"
----------------------------------------------

Software Name: Corel TVX
Version: 2.2-B0.5
Publisher: Corel Corporation
Install Time: 2014/02/03
Size: 31.23 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{F11125AD-C9D4-4BD9-92EF-D656B00E8FEC}
Uninstall Command: C:\Program Files (x86)\InstallShield Installation Information\{F11125AD-C9D4-4BD9-92EF-D656B00E8FEC}\setup.exe -runfromtemp -l0x0411
----------------------------------------------

Software Name: Direct DiscRecorder
Version: 1.00.0000
Publisher: Corel Corporation
Install Time: 2011/02/09
Size: 154.00 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{F2004B8D-7791-4B35-A3FA-D8CA8BB4DD81}
Uninstall Command: C:\Program Files (x86)\InstallShield Installation Information\{F2004B8D-7791-4B35-A3FA-D8CA8BB4DD81}\setup.exe -runfromtemp -l0x0411
----------------------------------------------

Software Name: IObit Uninstaller
Version: 3.1.7.2405
Publisher: IObit
Install Time: 2014/02/08
Size: 22.65 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IObitUninstall
Uninstall Command: "C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallDisplay.exe" uninstall_start
----------------------------------------------

Software Name: Jw_cad
Version: -
Publisher:
Install Time: 2011/02/18
Size: 1.21 GB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Jw_win
Uninstall Command: C:\Users\Guest\Desktop\install.exe -u
----------------------------------------------

Software Name: Lenovo Welcome
Version: -
Publisher: Lenovo
Install Time: 2011/02/09
Size: 14.85 MB
Help info: http://www.lenovo.com/support
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Lenovo Welcome_is1
Uninstall Command: "C:\Program Files (x86)\Lenovo\Lenovo Welcome\unins000.exe"
----------------------------------------------

Software Name: MyEPSON Portal
Version: -
Publisher: SEIKO EPSON Corporation
Install Time:
Size: 8.48 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyEPSON Connect
Uninstall Command: MsiExec.exe /X{3361D415-BA35-4143-B301-661991BA6219}
----------------------------------------------

Software Name: Microsoft Office Home and Business 2010
Version: 14.0.7015.1000
Publisher: Microsoft Corporation
Install Time: 2013/02/22
Size: 537.43 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office14.EssentialsR
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe" /uninstall ESSENTIALSR /dll OSETUP.DLL
----------------------------------------------

Software Name: BUFFALO クライアントマネージャV
Version: -
Publisher: BUFFALO INC.
Install Time: 2009/07/14
Size:
Help info: http://buffalo.jp/
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UN900119
Uninstall Command: C:\Windows\UN900119.EXE /U
----------------------------------------------

Software Name: Windows Live Essentials
Version: 16.4.3505.0912
Publisher: Microsoft Corporation
Install Time: 2011/02/09
Size: 224.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinLiveSuite
Uninstall Command: C:\Program Files (x86)\Windows Live\Installer\wlarp.exe
----------------------------------------------

Software Name: Bonjour
Version: 1.0.106
Publisher: Apple Inc.
Install Time: 2014/02/03
Size: 3.29 MB
Help info: http://www.apple.com/jp/support/
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{07287123-B8AC-41CE-8346-3D777245C35B}
Uninstall Command: MsiExec.exe /X{07287123-B8AC-41CE-8346-3D777245C35B}
----------------------------------------------

Software Name: QuickTime
Version: 7.72.80.56
Publisher: Apple Inc.
Install Time: 2012/11/07
Size: 73.26 MB
Help info: http://www.apple.com/jp/support/
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0E64B098-8018-4256-BA23-C316A43AD9B0}
Uninstall Command: MsiExec.exe /X{0E64B098-8018-4256-BA23-C316A43AD9B0}
----------------------------------------------

Software Name: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Version: 9.0.30729.4148
Publisher: Microsoft Corporation
Install Time: 2011/02/16
Size: 592.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Uninstall Command: MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
----------------------------------------------

Software Name: Lenovo System Update
Version: 5.02.0018
Publisher: Lenovo
Install Time: 2013/07/16
Size: 13.42 MB
Help info: http://www.lenovo.com/support
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{25C64847-B900-48AD-A164-1B4F9B774650}
Uninstall Command: MsiExec.exe /X{25C64847-B900-48AD-A164-1B4F9B774650}
----------------------------------------------

Software Name: Java 7 Update 51
Version: 7.0.510
Publisher: Oracle
Install Time: 2014/02/08
Size: 118.64 MB
Help info: http://java.com/help
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83217051FF}
Uninstall Command: MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217051FF}
----------------------------------------------

Software Name: Epson E-Photo
Version: 1.4.1.0
Publisher: SEIKO EPSON CORPORATION
Install Time: 2014/02/16
Size: 63.76 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{271A8D71-CA24-4B06-94A4-D41F4358D49B}
Uninstall Command: "C:\Program Files (x86)\InstallShield Installation Information\{271A8D71-CA24-4B06-94A4-D41F4358D49B}\setup.exe" -runfromtemp -l0x0411 UNINST -removeonly
----------------------------------------------

Software Name: Epson Event Manager
Version: 3.10.0017
Publisher: Seiko Epson Corporation
Install Time: 2014/02/16
Size: 42.48 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2970697F-2A11-4588-8B7F-97322D1CCF3C}
Uninstall Command: MsiExec.exe /X{2970697F-2A11-4588-8B7F-97322D1CCF3C}
----------------------------------------------

Software Name: EpsonNet Print
Version: 2.6.0
Publisher: SEIKO EPSON CORPORATION
Install Time: 2014/02/16
Size: 3.44 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3E31400D-274E-4647-916C-2CACC3741799}
Uninstall Command: "C:\Program Files (x86)\InstallShield Installation Information\{3E31400D-274E-4647-916C-2CACC3741799}\ENPSETUP.EXE" -runfromtemp -l0x0411 -EPSON -removeonly
----------------------------------------------

Software Name: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Version: 9.0.30729
Publisher: Microsoft Corporation
Install Time: 2011/03/17
Size: 234.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}
Uninstall Command: MsiExec.exe /X{402ED4A1-8F5B-387A-8688-997ABF58B8F2}
----------------------------------------------

Software Name: Mobile Broadband
Version: 3.6.0034
Publisher: Lenovo
Install Time: 2011/02/09
Size: 16.50 MB
Help info: http://www.lenovo.com/support
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4330AAE7-1893-42F9-BC38-539A1A60530B}
Uninstall Command: MsiExec.exe /X{4330AAE7-1893-42F9-BC38-539A1A60530B}
----------------------------------------------

Software Name: Apple Application Support
Version: 2.3.6
Publisher: Apple Inc.
Install Time: 2013/10/01
Size: 64.05 MB
Help info: http://www.apple.com/jp/support/
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{46F044A5-CE8B-4196-984E-5BD6525E361D}
Uninstall Command: MsiExec.exe /X{46F044A5-CE8B-4196-984E-5BD6525E361D}
----------------------------------------------

Software Name: Create Recovery Media
Version: 1.20.0.00
Publisher: Lenovo Group Limited
Install Time: 2011/02/09
Size: 9.50 MB
Help info: http://www.lenovo.com/think/support
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{50DC5136-21E8-48BC-97E5-1AD055F6B0B6}
Uninstall Command: MsiExec.exe /X{50DC5136-21E8-48BC-97E5-1AD055F6B0B6}
----------------------------------------------

Software Name: Cisco LEAP Module
Version: 1.0.19
Publisher: Cisco Systems, Inc.
Install Time: 2011/02/09
Size: 644.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{51C7AD07-C3F6-4635-8E8A-231306D810FE}
Uninstall Command: MsiExec.exe /X{51C7AD07-C3F6-4635-8E8A-231306D810FE}
----------------------------------------------

Software Name: EPSON Scan OCR コンポーネント
Version: 1.33.0000
Publisher: SEIKO EPSON Corp.
Install Time: 2014/02/16
Size: 1.99 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}
Uninstall Command: C:\Program Files (x86)\InstallShield Installation Information\{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}\SETUP.EXE -runfromtemp -l0x0011 -removeonly
----------------------------------------------

Software Name: Cisco EAP-FAST Module
Version: 2.2.14
Publisher: Cisco Systems, Inc.
Install Time: 2011/02/09
Size: 1.55 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
Uninstall Command: MsiExec.exe /X{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
----------------------------------------------

Software Name: Intel(R) Management Engine Components
Version: 6.0.0.1179
Publisher: Intel Corporation
Install Time: 2011/02/09
Size: 12.30 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}
Uninstall Command: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
----------------------------------------------

Software Name: 読んde!!ココ パーソナル
Version: -
Publisher:
Install Time: 2014/02/16
Size: 11.46 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{680979B2-3EAD-4219-B32C-7A6BC02B39F9}
Uninstall Command: RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\Aisoft\Yonde\SetupPsnl\setup.exe" -l0x11 anything -removeonly
----------------------------------------------

Software Name: Software Updater
Version: 4.2.1
Publisher: SEIKO EPSON CORPORATION
Install Time: 2014/02/16
Size: 8.20 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6DFBE8A2-CDBF-453E-B34C-32F202FCEE4C}
Uninstall Command: MsiExec.exe /X{6DFBE8A2-CDBF-453E-B34C-32F202FCEE4C}
----------------------------------------------

Software Name: Microsoft Visual C++ 2005 Redistributable
Version: 8.0.61001
Publisher: Microsoft Corporation
Install Time: 2011/06/17
Size: 300.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Uninstall Command: MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
----------------------------------------------

Software Name: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Version: 8.0.50727.4053
Publisher: Microsoft Corporation
Install Time: 2011/02/26
Size: 250.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{770657D0-A123-3C07-8E44-1C83EC895118}
Uninstall Command: MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
----------------------------------------------

Software Name: au ISW11K USB Driver
Version: 1.00.0000
Publisher: 京セラ株式会社
Install Time: 2012/03/01
Size: 2.79 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{773630AE-20CF-445C-BD3B-9AA788D3AA41}
Uninstall Command: "C:\Program Files (x86)\InstallShield Installation Information\{773630AE-20CF-445C-BD3B-9AA788D3AA41}\setup.exe" -runfromtemp -l0x0411 -removeonly
----------------------------------------------

Software Name: EPSON マニュアル
Version: 1.32.0.0
Publisher: SEIKO EPSON CORPORATION
Install Time: 2014/02/16
Size: 704.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}
Uninstall Command: MsiExec.exe /X {84CECC1B-21EF-41B1-9A91-3E724E5D99D3}
----------------------------------------------

Software Name: MSXML 4.0 SP2 (KB954430)
Version: 4.20.9870.0
Publisher: Microsoft Corporation
Install Time: 2011/02/18
Size: 1.28 MB
Help info: http://support.microsoft.com/kb/954430
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Uninstall Command: MsiExec.exe /X{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
----------------------------------------------

Software Name: Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2553145
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-0018-0411-0000-0000000FF1CE}_Office14.EssentialsR_{E0DE768A-BCAA-448C-9658-68D9AFFFB98A}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0018-0411-0000-0000000FF1CE}" "{E0DE768A-BCAA-448C-9658-68D9AFFFB98A}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.16 MB
Help info: http://support.microsoft.com/kb/2687567
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-001A-0411-0000-0000000FF1CE}_Office14.EssentialsR_{BB0E5F8B-7540-4F63-95E1-CB530B09D182}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001A-0411-0000-0000000FF1CE}" "{BB0E5F8B-7540-4F63-95E1-CB530B09D182}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2850079
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-001F-0409-0000-0000000FF1CE}_Office14.EssentialsR_{B5C70C99-B109-42FD-B219-FF12CA543F19}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0409-0000-0000000FF1CE}" "{B5C70C99-B109-42FD-B219-FF12CA543F19}" "1041" "0"
----------------------------------------------

Software Name: Security Update for Microsoft Office 2010 (KB2760781) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2760781
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-001F-0411-0000-0000000FF1CE}_Office14.EssentialsR_{D8F774D2-5189-4408-8307-B0E53F9AAB21}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0411-0000-0000000FF1CE}" "{D8F774D2-5189-4408-8307-B0E53F9AAB21}" "1041" "0"
----------------------------------------------

Software Name: Security Update for Microsoft Office 2010 (KB2687413) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2687413
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-0028-0411-0000-0000000FF1CE}_Office14.EssentialsR_{9AD8D8D3-3EF5-47F5-80E6-6F2311BB3445}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0028-0411-0000-0000000FF1CE}" "{9AD8D8D3-3EF5-47F5-80E6-6F2311BB3445}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2810071
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-002A-0000-1000-0000000FF1CE}_Office14.EssentialsR_{001E8BF3-EDC3-4D5E-9C11-1D0E599B6497}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-002A-0000-1000-0000000FF1CE}" "{001E8BF3-EDC3-4D5E-9C11-1D0E599B6497}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.16 MB
Help info: http://support.microsoft.com/kb/2837595
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-002A-0000-1000-0000000FF1CE}_Office14.EssentialsR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-002A-0000-1000-0000000FF1CE}" "{51CCA922-A0CC-47C4-8910-6936D97CAC2E}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2760598
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-002A-0000-1000-0000000FF1CE}_Office14.EssentialsR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-002A-0000-1000-0000000FF1CE}" "{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2589352
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-002A-0000-1000-0000000FF1CE}_Office14.EssentialsR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-002A-0000-1000-0000000FF1CE}" "{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.16 MB
Help info: http://support.microsoft.com/kb/2760601
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-002A-0000-1000-0000000FF1CE}_Office14.EssentialsR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-002A-0000-1000-0000000FF1CE}" "{F9F5A080-AF38-4966-9A6B-C43DCA465035}" "1041" "0"
----------------------------------------------

Software Name: Security Update for Microsoft Office 2010 (KB2553284) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2553284
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-006E-0411-0000-0000000FF1CE}_Office14.EssentialsR_{B68AD5BB-E118-4A04-8147-8CAA473EA622}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-006E-0411-0000-0000000FF1CE}" "{B68AD5BB-E118-4A04-8147-8CAA473EA622}" "1041" "0"
----------------------------------------------

Software Name: Microsoft Office Word Viewer 2003
Version: 11.0.8173.0
Publisher: Microsoft Corporation
Install Time: 2014/01/16
Size: 105.19 MB
Help info: http://www.microsoft.com/support
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90850411-6000-11D3-8CFE-0150048383C9}
Uninstall Command: MsiExec.exe /X{90850411-6000-11D3-8CFE-0150048383C9}
----------------------------------------------

Software Name: Security Update for Microsoft Office 2010 (KB2826035) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2826035
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{0241FB40-015F-42AC-A711-1AE59E346B51}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{0241FB40-015F-42AC-A711-1AE59E346B51}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2589375
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{287A1E92-9E41-4BC1-8920-B3D0E9220800}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2760631
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{35698CB7-AAA2-4577-B505-DBFF504AEF23}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{35698CB7-AAA2-4577-B505-DBFF504AEF23}" "1041" "0"
----------------------------------------------

Software Name: Security Update for Microsoft Office 2010 (KB2687423) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2687423
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{4D6FE7B6-559F-4DAC-92CF-A01C24046AEB}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{4D6FE7B6-559F-4DAC-92CF-A01C24046AEB}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.16 MB
Help info: http://support.microsoft.com/kb/2817369
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2794737
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{5AA578BB-759C-40FD-9661-A737C0884541}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{5AA578BB-759C-40FD-9661-A737C0884541}" "1041" "0"
----------------------------------------------

Software Name: Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2850016
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{7AC3F78E-ECA0-45F4-A9CC-3E885DA23662}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{7AC3F78E-ECA0-45F4-A9CC-3E885DA23662}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft PowerPoint 2010 (KB2775360) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.16 MB
Help info: http://support.microsoft.com/kb/2775360
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{80F56E3F-1D47-4E45-B6E0-FEF4E919F4F9}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{80F56E3F-1D47-4E45-B6E0-FEF4E919F4F9}" "1041" "0"
----------------------------------------------

Software Name: Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/982726
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{81FB7C60-565A-4869-9D90-3BE1D270E8B7}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{81FB7C60-565A-4869-9D90-3BE1D270E8B7}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2810066
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{8C55AA83-54C2-4236-A622-78440A411DC5}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{8C55AA83-54C2-4236-A622-78440A411DC5}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2597087
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{9D69691D-823D-4C3E-9B12-563A3F520366}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{9D69691D-823D-4C3E-9B12-563A3F520366}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2589298
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}" "1041" "0"
----------------------------------------------

Software Name: Security Update for Microsoft Excel 2010 (KB2826033) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2826033
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{DC8EDDCF-2031-4C8D-916C-64058A3ACA95}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{DC8EDDCF-2031-4C8D-916C-64058A3ACA95}" "1041" "0"
----------------------------------------------

Software Name: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2687455
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft Office 2010 (KB2837583) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.16 MB
Help info: http://support.microsoft.com/kb/2837583
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{E21274CE-CA0C-49FA-93F4-DC292A052264}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{E21274CE-CA0C-49FA-93F4-DC292A052264}" "1041" "0"
----------------------------------------------

Software Name: Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2837593
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{E78E2B68-8FD1-42EE-BB74-99A4D9E6222D}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{E78E2B68-8FD1-42EE-BB74-99A4D9E6222D}" "1041" "0"
----------------------------------------------

Software Name: Security Update for Microsoft Office 2010 (KB2826023) 32-Bit Edition
Version: -
Publisher: Microsoft
Install Time: 2013/02/22
Size: 131.14 MB
Help info: http://support.microsoft.com/kb/2826023
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{EC2CA755-17D8-4392-A91E-FD4D2DD31072}
Uninstall Command: "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0013-0000-0000-0000000FF1CE}" "{EC2CA755-17D8-4392-A91E-FD4D2DD31072}" "1041" "0"
----------------------------------------------

Software Name: Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Version: 1
Publisher: Microsoft Corporation
Install Time: 2014/02/26
Size: 422.81 MB
Help info: http://support.microsoft.com/kb/2898869
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB2898869
Uninstall Command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\v4.5.50938\setup.exe /uninstallpatch {BD0F9F7E-62B2-3971-9E2E-B87B832CE89D}
----------------------------------------------

Software Name: Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Version: 1
Publisher: Microsoft Corporation
Install Time: 2014/02/26
Size: 422.81 MB
Help info: http://support.microsoft.com/kb/2901126
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB2901126
Uninstall Command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\v4.5.50938\setup.exe /uninstallpatch {513BC47F-0560-33C2-A029-C5387642233A}
----------------------------------------------

Software Name: PHOTOfunSTUDIO 5.0 HD Edition
Version: 5.00.313
Publisher: Panasonic Corporation
Install Time: 2011/02/28
Size: 157.30 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{959282E3-55A9-49D8-B885-D27CF8A2FD82}
Uninstall Command: "C:\Program Files (x86)\InstallShield Installation Information\{959282E3-55A9-49D8-B885-D27CF8A2FD82}\setup.exe" -runfromtemp -l0x0411 -z"Uninstall" -removeonly
----------------------------------------------

Software Name: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Version: 9.0.30729.6161
Publisher: Microsoft Corporation
Install Time: 2011/06/20
Size: 600.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Uninstall Command: MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
----------------------------------------------

Software Name: ThinkPad Wireless LAN Adapter Software
Version: 1.00.0024.0
Publisher: REALTEK Semiconductor Corp.
Install Time: 2011/02/09
Size: 6.04 MB
Help info: http://www.realtek.com.tw
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9D3D2C60-A55F-4fed-B2B9-17394396DF01}
Uninstall Command: C:\Program Files (x86)\InstallShield Installation Information\{9D3D2C60-A55F-4fed-B2B9-17394396DF01}\Install.exe -uninst -l0x11
----------------------------------------------

Software Name: SonicStage 4.4
Version: 4.4
Publisher: Sony Corporation
Install Time: 2012/02/15
Size: 35.07 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A0EB195B-5876-48E6-879D-33D4B2102610}
Uninstall Command: C:\Program Files (x86)\InstallShield Installation Information\{A0EB195B-5876-48E6-879D-33D4B2102610}\setup.exe -runfromtemp -l0x0011 /z UNINSTALL -removeonly
----------------------------------------------

Software Name: Adobe Reader XI (11.0.06) - Japanese
Version: 11.0.06
Publisher: Adobe Systems Incorporated
Install Time: 2014/02/12
Size: 147.11 MB
Help info: http://www.adobe.co.jp/support/main.html
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1041-7B44-AB0000000001}
Uninstall Command: MsiExec.exe /X{AC76BA86-7AD7-1041-7B44-AB0000000001}
----------------------------------------------

Software Name: Lenovo Patch Utility
Version: 1.3.1.1
Publisher: Lenovo Group Limited
Install Time: 2013/05/12
Size: 1.33 MB
Help info: http://www.lenovo.com/support
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD32F5E9-6BDD-480A-8B7B-95571D04691C}
Uninstall Command: MsiExec.exe /X{AD32F5E9-6BDD-480A-8B7B-95571D04691C}
----------------------------------------------

Software Name: Rescue and Recovery
Version: 4.31.0005.00
Publisher: Lenovo Group Limited
Install Time: 2013/05/12
Size: 101.75 MB
Help info: http://www.lenovo.com/think/support
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B383F243-0ABC-4E56-AA30-923B8D85076E}
Uninstall Command: MsiExec.exe /X{B383F243-0ABC-4E56-AA30-923B8D85076E}
----------------------------------------------

Software Name: Access Help
Version: 3.00
Publisher: Lenovo
Install Time: 2011/02/09
Size: 12.12 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C6FA39A7-26B1-480A-BC74-6D17531AC222}
Uninstall Command: "C:\Program Files (x86)\InstallShield Installation Information\{C6FA39A7-26B1-480A-BC74-6D17531AC222}\setup.exe" -runfromtemp -l0x0011 -removeonly
----------------------------------------------

Software Name: Epson E-Web Print
Version: 1.19.0000
Publisher: SEIKO EPSON CORPORATION
Install Time: 2014/02/16
Size: 9.23 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CEC98C2A-9ED5-49DA-9F3A-92434E0A4FA3}
Uninstall Command: MsiExec.exe /X{CEC98C2A-9ED5-49DA-9F3A-92434E0A4FA3}
----------------------------------------------

Software Name: Epson Print CD
Version: 2.21.00
Publisher: SEIKO EPSON CORPORATION
Install Time: 2014/02/16
Size: 47.51 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D16A31F9-276D-4968-A753-FFEAC56995D0}
Uninstall Command: "C:\Program Files (x86)\InstallShield Installation Information\{D16A31F9-276D-4968-A753-FFEAC56995D0}\setup.exe" -runfromtemp -removeonly
----------------------------------------------

Software Name: ThinkPad 省電力マネージャー
Version: 3.30
Publisher:
Install Time: 2011/02/09
Size: 1.09 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}
Uninstall Command: RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}\SETUP.EXE" -l0x11 -AddRemove
----------------------------------------------

Software Name: Microsoft SQL Server Compact 3.5 SP1 English
Version: 3.5.5692.0
Publisher: Microsoft Corporation
Install Time: 2011/02/28
Size: 2.59 MB
Help info: http://go.microsoft.com/fwlink/?LinkId=81488
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}
Uninstall Command: MsiExec.exe /X{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}
----------------------------------------------

Software Name: Cisco PEAP Module
Version: 1.1.6
Publisher: Cisco Systems, Inc.
Install Time: 2011/02/09
Size: 1.24 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
Uninstall Command: MsiExec.exe /X{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
----------------------------------------------

Software Name: Microsoft SQL Server 2005 Compact Edition [ENU]
Version: 3.1.0000
Publisher: Microsoft Corporation
Install Time: 2011/02/09
Size: 1.70 MB
Help info: http://www.microsoft.com/sql/everywhere
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Uninstall Command: MsiExec.exe /X{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
----------------------------------------------

Software Name: Intel(R) Graphics Media Accelerator Driver
Version: 8.15.10.2125
Publisher: Intel Corporation
Install Time: 2011/02/09
Size: 74.22 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
Uninstall Command: C:\Program Files (x86)\Intel\Intel(R) Graphics Media Accelerator Driver\Uninstall\setup.exe -uninstall
----------------------------------------------

Software Name: MSXML 4.0 SP2 (KB973688)
Version: 4.20.9876.0
Publisher: Microsoft Corporation
Install Time: 2011/02/18
Size: 1.33 MB
Help info: http://support.microsoft.com/kb/973688
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Uninstall Command: MsiExec.exe /X{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
----------------------------------------------

Software Name: Intel(R) Control Center
Version: 1.2.1.1007
Publisher: Intel Corporation
Install Time: 2011/02/09
Size: 1.46 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}
Uninstall Command: C:\Program Files (x86)\Intel\Intel Control Center\uninstaller\SetupICC.exe -uninstall -force -confirm
----------------------------------------------

Software Name: Message Center Plus
Version: 2.0.0012.00
Publisher: Lenovo Group Limited
Install Time: 2011/02/09
Size: 1.71 MB
Help info: http://www.lenovo.com/think/support
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FD331A3B-F7A5-4C31-B8D4-DF413C85AF7A}
Uninstall Command: MsiExec.exe /X{FD331A3B-F7A5-4C31-B8D4-DF413C85AF7A}
----------------------------------------------

Software Name: Lenovo Warranty Information
Version: 1.0.0004.00
Publisher: Lenovo
Install Time: 2011/02/09
Size: 893.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}
Uninstall Command: MsiExec.exe /X{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}
----------------------------------------------

Software Name: I-O DATA mAgicTV Digital
Version: 1.01.00
Publisher: I-O DATA DEVICE,INC.
Install Time: 2014/02/03
Size: 131.55 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FEDADF0F-3E60-476E-9685-83198307482C}
Uninstall Command: C:\Program Files (x86)\InstallShield Installation Information\{FEDADF0F-3E60-476E-9685-83198307482C}\Setup.exe -runfromtemp -l0x0011 -removeonly
----------------------------------------------

Software Name: ウイルスセキュリティ
Version: 12.00
Publisher: ソースネクスト株式会社
Install Time: 2011/03/23
Size: 361.67 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ウイルスセキュリティ
Uninstall Command: C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurityUninstall.exe
----------------------------------------------

Software Name: Microsoft SkyDrive
Version: 16.4.6013.0910
Publisher: Microsoft Corporation
Install Time: 2013/01/15
Size: 25.14 MB
Help info: http://go.microsoft.com/fwlink/?LinkID=215117
Registry Key: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SkyDriveSetup.exe
Uninstall Command: C:\Users\オヤジ\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveSetup.exe /uninstall
----------------------------------------------

Software Name: Windows ドライバ パッケージ - Realtek Semiconductor Corp. HD Audio Driver (06/29/2010 6.0.1.6146)
Version: 06/29/2010 6.0.1.6146
Publisher: Realtek Semiconductor Corp.
Install Time:
Size:
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\03A7DBDC77B53F52C7EA041F531310CFC5E2AD9E
Uninstall Command: C:\PROGRA~1\DIFX\8730326CFC0D32D8\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\hdxrt.inf_amd64_neutral_8237eec4c6b39ec3\hdxrt.inf
----------------------------------------------

Software Name: Windows ドライバ パッケージ - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4)
Version: 11/18/2009 1.60.0.4
Publisher: Lenovo
Install Time: 2011/02/09
Size: 148.74 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\114EB224AD576F278686036AA9E1EFB7847E3935
Uninstall Command: C:\PROGRA~1\DIFX\8730326CFC0D32D8\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\ibmpmdrv.inf_amd64_neutral_33148031f86fba35\ibmpmdrv.inf
----------------------------------------------

Software Name: Windows ドライバ パッケージ - Intel hdc (06/04/2009 7.0.0.1013)
Version: 06/04/2009 7.0.0.1013
Publisher: Intel
Install Time: 2011/02/09
Size: 44.90 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1AE98C75AE2DD1284F66876FA76F46BFDF6B9D31
Uninstall Command: C:\PROGRA~1\DIFX\8730326CFC0D32D8\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\ibexahci.inf_amd64_neutral_6f34ba52659bc3bc\ibexahci.inf
----------------------------------------------

Software Name: Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022)
Version: 10/28/2009 9.1.1.1022
Publisher: Intel
Install Time: 2011/02/09
Size: 65.25 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\573C3C32A1DB5625CA00E633E584E8A0E6383672
Uninstall Command: C:\PROGRA~1\DIFX\8730326CFC0D32D8\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\ibexcore.inf_amd64_neutral_ffc77108eccfbcd4\ibexcore.inf
----------------------------------------------

Software Name: Windows ドライバ パッケージ - I-O DATA DEVICE, INC. GV-MVP/FZ(x64) (11/29/2010 1.8.2.12)
Version: 11/29/2010 1.8.2.12
Publisher: I-O DATA DEVICE, INC.
Install Time: 2014/02/03
Size: 3.16 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8BD686A7F72F0304D2BC7739CA27C417975A75B8
Uninstall Command: C:\PROGRA~1\DIFX\D5ACB5E27756780D\dpinst.exe /d /u C:\Windows\System32\DriverStore\FileRepository\gvmvpfz_x64.inf_amd64_neutral_9a142b0b7cbe96a1\gvmvpfz_x64.inf
----------------------------------------------

Software Name: Windows ドライバ パッケージ - Intel USB (08/20/2009 9.1.1.1020)
Version: 08/20/2009 9.1.1.1020
Publisher: Intel
Install Time: 2011/02/09
Size: 34.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\A7B0B8D913E4DC2FA0B31E392E1512A901CA66B9
Uninstall Command: C:\PROGRA~1\DIFX\8730326CFC0D32D8\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\ibexusb.inf_amd64_neutral_48b6f41914370c44\ibexusb.inf
----------------------------------------------

Software Name: au T008 USB Driver Ver.5.0.0.1
Version: V5.24.1.0
Publisher:
Install Time: 2011/09/24
Size: 720.48 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\au T008
Uninstall Command: C:\Program Files\FUJITSU\au T008\t008Uninstall.exe
----------------------------------------------

Software Name: Windows ドライバ パッケージ - Intel (iaStor) hdc (01/15/2010 9.5.7.1002)
Version: 01/15/2010 9.5.7.1002
Publisher: Intel
Install Time: 2011/02/09
Size: 564.70 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\C39A7AFB5CAF49F10B9573FFE2E981F1AB2074B6
Uninstall Command: C:\PROGRA~1\DIFX\8730326CFC0D32D8\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_amd64_neutral_5d42c6448888c5bd\iaahci.inf
----------------------------------------------

Software Name: Windows ドライバ パッケージ - Intel System (06/04/2009 1.0.0.0002)
Version: 06/04/2009 1.0.0.0002
Publisher: Intel
Install Time: 2011/02/09
Size: 37.10 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E7B58217635B8F723D4744A328A4B3237DB35FA9
Uninstall Command: C:\PROGRA~1\DIFX\8730326CFC0D32D8\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\ibexsmb.inf_amd64_neutral_5a95aa2fb35a2451\ibexsmb.inf
----------------------------------------------

Software Name: Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7
Version: 1.00
Publisher:
Install Time:
Size:
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EnablePS
Uninstall Command: Rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 130 C:\Program Files\Lenovo\EnablePS\EnablePS.inf
----------------------------------------------

Software Name: EPSON EP-706A Series プリンター アンインストール
Version: -
Publisher: SEIKO EPSON Corporation
Install Time: 2009/07/14
Size: 49.15 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EPSON EP-706A Series
Uninstall Command: C:\Windows\system32\spool\DRIVERS\x64\3\E_IINSLMJ.EXE /R /APD /P:"EPSON EP-706A Series"
----------------------------------------------

Software Name: Lenovo System Interface Driver
Version: 1.05
Publisher:
Install Time:
Size:
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LENOVO.SMIIF
Uninstall Command: RunDll32.exe setupapi.dll,InstallHinfSection DefaultUninstall.NTamd64 130 C:\Program Files\Lenovo\SMIIF\lnvsmi.inf
----------------------------------------------

Software Name: Lenovo Auto Scroll Utility
Version: 1.00
Publisher:
Install Time: 2011/02/09
Size: 157.24 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LenovoAutoScrollUtility
Uninstall Command: rundll32.exe "C:\Program Files\Lenovo\VIRTSCRL\cleanup.dll",InfUninstall DefaultUninstall.LH 132 C:\Program Files\Lenovo\VIRTSCRL\tpdu_vs.inf
----------------------------------------------

Software Name: Microsoft .NET Framework 4 Client Profile
Version: 4.0.30319
Publisher: Microsoft Corporation
Install Time: 2011/02/27
Size: 38.80 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 4 Client Profile
Uninstall Command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /x64 /parameterfolder Client
----------------------------------------------

Software Name: Lenovo ThinkVantage Toolbox
Version: 6.0.5717.21
Publisher: PC-Doctor, Inc.
Install Time: 2011/02/09
Size: 126.56 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC-Doctor for Windows
Uninstall Command: C:\Program Files\PC-Doctor\uninst.exe
----------------------------------------------

Software Name: Lenovo Power Management Driver
Version: 1.67.04.04
Publisher:
Install Time:
Size:
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Power Management Driver
Uninstall Command: RunDll32.exe tpinspm.dll,Uninstall
----------------------------------------------

Software Name: ThinkPad UltraNav Driver
Version: 16.2.19.7
Publisher:
Install Time:
Size: 46.44 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SynTPDeinstKey
Uninstall Command: rundll32.exe "%ProgramFiles%\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
----------------------------------------------

Software Name: Registry Patch to arrange icons in Device and Printers folder of Windows 7
Version: 1.00
Publisher:
Install Time:
Size:
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\W7DevOR
Uninstall Command: Rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 130 C:\Program Files\Lenovo\W7DevOR\DevORApply.inf
----------------------------------------------

Software Name: Microsoft Visual C++ 2005 Redistributable (x64)
Version: 8.0.56336
Publisher: Microsoft Corporation
Install Time: 2011/02/09
Size: 708.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{071c9b48-7c32-4621-a0ac-3f809523288f}
Uninstall Command: MsiExec.exe /X{071c9b48-7c32-4621-a0ac-3f809523288f}
----------------------------------------------

Software Name: Apple Mobile Device Support
Version: 7.0.0.117
Publisher: Apple Inc.
Install Time: 2013/10/01
Size: 25.08 MB
Help info: http://www.apple.com/support/
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}
Uninstall Command: MsiExec.exe /X{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}
----------------------------------------------

Software Name: インテル(R) ターボ・ブースト・テクノロジー・モニター
Version: 1.0.186.3
Publisher: インテル
Install Time: 2011/02/09
Size: 1.13 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}
Uninstall Command: MsiExec.exe /X{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}
----------------------------------------------

Software Name: ThinkVantage ハードディスク・アクティブプロテクション・システム
Version: 1.74
Publisher: Lenovo
Install Time: 2011/02/09
Size: 15.61 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}
Uninstall Command: MsiExec.exe /X{46A84694-59EC-48F0-964C-7E76E9F8A2ED}
----------------------------------------------

Software Name: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Version: 9.0.30729.4148
Publisher: Microsoft Corporation
Install Time: 2011/02/16
Size: 784.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Uninstall Command: MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
----------------------------------------------

Software Name: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Version: 9.0.30729.6161
Publisher: Microsoft Corporation
Install Time: 2011/06/20
Size: 788.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
Uninstall Command: MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
----------------------------------------------

Software Name: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Version: 9.0.30729
Publisher: Microsoft Corporation
Install Time: 2013/10/01
Size: 248.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8220EEFE-38CD-377E-8595-13398D740ACE}
Uninstall Command: "C:\Program Files (x86)\Uninstall Information\Ib\97\3868\ib_uninstall.exe" /PUninstall="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8220EEFE-38CD-377E-8595-13398D740ACE}" /reg=64
----------------------------------------------

Software Name: ThinkVantage Communications Utility
Version: 1.41
Publisher: Lenovo
Install Time: 2011/02/09
Size: 2.44 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{88C6A6D9-324C-46E8-BA87-563D14021442}_is1
Uninstall Command: "C:\Program Files\Lenovo\Communications Utility\unins000.exe"
----------------------------------------------

Software Name: Microsoft Silverlight
Version: 5.1.20913.0
Publisher: Microsoft Corporation
Install Time: 2013/10/10
Size: 149.87 MB
Help info: http://go.microsoft.com/fwlink/?LinkID=91955
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Uninstall Command: MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
----------------------------------------------

Software Name: Microsoft .NET Framework 4.5.1
Version: 4.5.50938
Publisher: Microsoft Corporation
Install Time: 2014/02/25
Size: 38.80 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033
Uninstall Command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\v4.5.50938\\Setup.exe /repair /x86 /x64
----------------------------------------------

Software Name: Lenovo Patch Utility 64 bit
Version: 1.3.1.1
Publisher: Lenovo Group Limited
Install Time: 2013/05/12
Size: 1.35 MB
Help info: http://www.lenovo.com/think/support
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ABE4638D-D208-4061-9F26-E3E11E3A1E0C}
Uninstall Command: MsiExec.exe /X{ABE4638D-D208-4061-9F26-E3E11E3A1E0C}
----------------------------------------------

Software Name: Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
Version: 8.0.50727.4053
Publisher: Microsoft Corporation
Install Time: 2011/02/26
Size: 260.00 KB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}
Uninstall Command: MsiExec.exe /X{B6E3757B-5E77-3915-866A-CCFC4B8D194C}
----------------------------------------------

Software Name: SAMSUNG USB Driver for Mobile Phones
Version: 1.5.16.0
Publisher: SAMSUNG Electronics Co., Ltd.
Install Time: 2013/08/07
Size: 42.96 MB
Help info: -
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}
Uninstall Command: C:\Program Files\SAMSUNG\USB Drivers\Uninstall.exe
----------------------------------------------

Software Name: Microsoft SQL Server Compact 3.5 SP1 x64 English
Version: 3.5.5692.0
Publisher: Microsoft Corporation
Install Time: 2011/02/28
Size: 3.69 MB
Help info: http://go.microsoft.com/fwlink/?LinkId=81488
Registry Key
  • ryoyoung
  • MAIL
  • 2014/02/27 (Thu) 08:24:19
ログが途切れてますね
作業と報告、ご苦労様です。
ログを見せてもらったところ、途中で途切れてるようです。
お手数ですが残りの部分も全部追加で見せてください。
  • 悪代官
  • 2014/02/27 (Thu) 09:06:27
Re: 駆除
すいません。残りを添付します。
Software Name: Microsoft SQL Server Compact 3.5 SP1 x64 English
Version: 3.5.5692.0
Publisher: Microsoft Corporation
Install Time: 2011/02/28
Size: 3.69 MB
Help info: http://go.microsoft.com/fwlink/?LinkId=81488
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F83779DF-E1F5-43A2-A7BE-732F856FADB7}
Uninstall Command: MsiExec.exe /X{F83779DF-E1F5-43A2-A7BE-732F856FADB7}
----------------------------------------------

====================================
Browser Plug-ins List
Application Version:3.1.7.2405
Windows 7
Exported Time:02-27-2014 08:19:15
====================================

====================================
Browser: Internet Explorer
====================================

************************************
Toolbar
************************************

Name: E-Web Print
Version: 1.10.0.0
Description: ewps_tb
Publisher: SEIKO EPSON Corporation
Architecture: 32-bit
----------------------------------------------

Name: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004
Version:
Description:
Publisher:
Architecture: 32-bit
----------------------------------------------

Name: OneNote に送る
Version:
Description:
Publisher:
Architecture: 32-bit
----------------------------------------------

Name: OneNote リンク ノート(K)
Version:
Description:
Publisher:
Architecture: 32-bit
----------------------------------------------

Name: Bonjour
Version: 1.0.6.2
Description: Bonjour Explorer Bar
Publisher: Apple Inc.
Architecture: 32-bit
----------------------------------------------

Name: E-Photo
Version: 1.1.0.0
Description: E-Photo (TBL x64)
Publisher: SEIKO EPSON Corporation
Architecture: 64-bit
----------------------------------------------

Name: OneNote に送る
Version:
Description:
Publisher:
Architecture: 64-bit
----------------------------------------------

Name: OneNote リンク ノート(K)
Version:
Description:
Publisher:
Architecture: 64-bit
----------------------------------------------

Name: Free YouTube Download
Version:
Description:
Publisher:
Architecture: 64-bit
----------------------------------------------

************************************
BHO
************************************

Name: K7 Web Protection
Version: 12. 0. 1. 27
Description: K7 Web Protection Browser Extension
Publisher: K7 Computing Pvt Ltd
Architecture: 32-bit
----------------------------------------------

Name: Java(tm) Plug-In SSV Helper
Version: 10.51.2.13
Description: Java(TM) Platform SE binary
Publisher: Oracle America, Inc.
Architecture: 32-bit
----------------------------------------------

Name: Microsoft アカウント サインイン ヘルパー
Version: 7.250.4311.0
Description: Microsoft® Windows Live ID Login Helper
Publisher: Microsoft Corporation
Architecture: 32-bit
----------------------------------------------

Name: Office Document Cache Handler
Version: 14.0.7011.1000
Description: Microsoft Office Document Cache Handler
Publisher: Microsoft Corporation
Architecture: 32-bit
----------------------------------------------

Name: Java(tm) Plug-In 2 SSV Helper
Version: 10.51.2.13
Description: Java(TM) Platform SE binary
Publisher: Oracle America, Inc.
Architecture: 32-bit
----------------------------------------------

Name: Windows Live ID Sign-in Helper
Version: 7.250.4311.0
Description: Microsoft® Windows Live ID Login Helper
Publisher: Microsoft Corporation
Architecture: 64-bit
----------------------------------------------

Name: Office Document Cache Handler
Version: 14.0.7011.1000
Description: Microsoft Office Document Cache Handler
Publisher: Microsoft Corporation
Architecture: 64-bit
----------------------------------------------

Name: Java(tm) Plug-In 2 SSV Helper
Version:
Description:
Publisher:
Architecture: 64-bit
----------------------------------------------

************************************
ActiveX
************************************

Name: DVD Toaster ActiveX Control
Version: 1.0.0.80
Description: DVD Toaster ActiveX Control
Publisher: WebStream Corporation
Architecture: 32-bit
----------------------------------------------

Name: Java Plug-in 10.51.2
Version:
Description:
Publisher: Oracle America, Inc.
Architecture: 32-bit
----------------------------------------------

Name: Java Plug-in 1.6.0_29
Version:
Description:
Publisher: Oracle America, Inc.
Architecture: 32-bit
----------------------------------------------

Name: Java Plug-in 1.7.0_09
Version:
Description:
Publisher: Oracle America, Inc.
Architecture: 32-bit
----------------------------------------------

Name: Windows Media Player
Version: 12.0.7601.17514
Description: Windows Media Player Extension
Publisher: Microsoft Corporation
Architecture: 32-bit
----------------------------------------------

Name: XML DOM Document
Version:
Description:
Publisher:
Architecture: 32-bit
----------------------------------------------

Name: QuickTime Object
Version:
Description:
Publisher:
Architecture: 32-bit
----------------------------------------------

Name: Shell Name Space
Version: 11.00.9600.16428
Description: インターネット ブラウザー
Publisher: Microsoft Corporation
Architecture: 32-bit
----------------------------------------------

Name: Windows Media Player
Version:
Description:
Publisher:
Architecture: 32-bit
----------------------------------------------

Name: Microsoft Web Browser
Version: 11.00.9600.16428
Description: インターネット ブラウザー
Publisher: Microsoft Corporation
Architecture: 32-bit
----------------------------------------------

Name: XML DOM Document 6.0
Version:
Description:
Publisher:
Architecture: 32-bit
----------------------------------------------

Name: XML HTTP 6.0
Version:
Description:
Publisher:
Architecture: 32-bit
----------------------------------------------

Name: RMGetLicense Class
Version: 11.0.7601.17514
Description: DRM ActiveX Network Object
Publisher: Microsoft Corporation
Architecture: 32-bit
----------------------------------------------

Name: Adobe PDF Reader
Version: 11.0.06.70
Description: PDF Browser Control
Publisher: Adobe Systems, Incorporated
Architecture: 32-bit
----------------------------------------------

Name: Microsoft アカウント サインイン コントロール
Version: 7.250.4311.0
Description: Microsoft® Windows Live ID Login Helper
Publisher: Microsoft Corporation
Architecture: 32-bit
----------------------------------------------

Name: Shockwave Flash Object
Version:
Description:
Publisher:
Architecture: 32-bit
----------------------------------------------

Name: Microsoft Silverlight
Version: 5.1.20913.0
Description: 5.1.20913.0
Publisher: Microsoft Corporation
Architecture: 32-bit
----------------------------------------------

Name: XML HTTP Request
Version:
Description:
Publisher:
Architecture: 32-bit
----------------------------------------------

Name: XML HTTP
Version:
Description:
Publisher:
Architecture: 32-bit
----------------------------------------------

Name: Windows Media Player
Version: 12.0.7601.17514
Description: Windows Media Player Extension
Publisher: Microsoft Corporation
Architecture: 64-bit
----------------------------------------------

Name: XML DOM Document
Version:
Description:
Publisher:
Architecture: 64-bit
----------------------------------------------

Name: Shell Name Space
Version: 11.00.9600.16428
Description: インターネット ブラウザー
Publisher: Microsoft Corporation
Architecture: 64-bit
----------------------------------------------

Name: Windows Media Player
Version:
Description:
Publisher:
Architecture: 64-bit
----------------------------------------------

Name: Microsoft Web Browser
Version: 11.00.9600.16428
Description: インターネット ブラウザー
Publisher: Microsoft Corporation
Architecture: 64-bit
----------------------------------------------

Name: XML DOM Document 6.0
Version:
Description:
Publisher:
Architecture: 64-bit
----------------------------------------------

Name: XML HTTP 6.0
Version:
Description:
Publisher:
Architecture: 64-bit
----------------------------------------------

Name: RMGetLicense Class
Version: 11.0.7601.17514
Description: DRM ActiveX Network Object
Publisher: Microsoft Corporation
Architecture: 64-bit
----------------------------------------------

Name: Windows Live ID Sign-in Control
Version: 7.250.4311.0
Description: Microsoft® Windows Live ID Login Helper
Publisher: Microsoft Corporation
Architecture: 64-bit
----------------------------------------------

Name: Shockwave Flash Object
Version:
Description:
Publisher:
Architecture: 64-bit
----------------------------------------------

Name: Microsoft Silverlight
Version: 5.1.20913.0
Description: 5.1.20913.0
Publisher: Microsoft Corporation
Architecture: 64-bit
----------------------------------------------

Name: XML HTTP Request
Version:
Description:
Publisher:
Architecture: 64-bit
----------------------------------------------

Name: XML HTTP
Version:
Description:
Publisher:
Architecture: 64-bit
----------------------------------------------

====================================
Browser: Google Chrome
====================================

====================================
Browser: Mozilla FireFox
====================================

====================================
Browser: Opera
====================================


  • ryoyoung
  • MAIL
  • 2014/02/27 (Thu) 09:46:57
DVD Toasterも確認を
残りのログも見せてもらいました。
どうやら尻尾が見えかけてきたようです。

ではまた説明を読んでから、続きの作業をお願いします。

先の手順でまたIUを起動して、画面上部の「ブラウザプラグイン」を開いてください。

そこで表示されている中の下記を確認です。
>Name: Free YouTube Download
見つけたら上記にチェックして、IU画面下部の「削除」を押して削除してください。

そしてもうひとつ、以下も確認してください。もしこれをご自身で入れた覚えがなければこれも処置してください。
>Name: DVD Toaster ActiveX Control
ご自身で入れたものなら、どこで入れたかと、入れた時期と異常発生の時期が同じかどうかをレスで教えてください。
どうもこれも素性がはっきりしないので判断に迷ってましたが、可能なら一度削除してみることを推奨です。

このあとまた状態を様子見後、状態報告をレスください
  • 悪代官
  • 2014/02/27 (Thu) 11:27:35
Re: 駆除
またよろしくおねがいします。
IUを起動し、「ブラウザプラグイン」を開きましたが、DVD Toaster ActiveX Controlはありましたが、 Free YouTube Downloadはよく見ましたが、見つかりません。メイン画面のプログラムにもありません。セーフモードで起動すればよかったのでしょうか?
お手数でしょうがもう一度返信お願いします。
ちなみに、このパソコンは家族3人の使い回しです。DVD Toaster ActiveX Controlはたぶん、Dmm.Comだと思います。異常発生時期とは重ならないと思いますが削除しようと思います。Free YouTube Downloadは他の二人のうちの一人だと思います。

  • ryoyoung
  • MAIL
  • 2014/02/27 (Thu) 14:09:01
該当ユーザーでログインして作業をお願いします
作業と報告、ご苦労様です。

>このパソコンは家族3人の使い回しです。DVD Toaster ActiveX Controlはたぶん、Dmm.Comだと思います。異常発生時期とは重ならないと思いますが削除しようと思います。Free YouTube Downloadは他の二人のうちの一人だと思います

なるほど、そういうことでしたか。
ではここで改めて説明しましょう。

この種のトラブル時の処置には基本的に異常が起きた時にPCを使っていたユーザーでログインして対処することになります。
また、そのPCの「管理者権限」を持つユーザーでログインして作業しないとまったく処置さえ出来ないことも多いのです。
これはWindowsの仕様によるためです。

なので別ユーザーでログインして処置しようとしても、別ユーザーでの操作はできないのは普通です。
すべての解析と処置をするなら、管理者権限ユーザーでPCを起動して作業する必要があるのです。

そのPCのユーザー全員が管理者権限を持っているなら作業自体は可能かと思いますが、異常を起こしているプログラムの処置や削除はそのユーザーでログインして作業してもらう必要があるので、該当アプリのアンインストールや削除は管理者か該当ユーザーでログインして実行してください.
Free YouTube Downloadもそれを入れたユーザーでログインして削除してもらってください。
  • 悪代官
  • 2014/02/27 (Thu) 14:52:24
これからは
3人で使い回ししていることを初めにお知らせしておくべきでした。申し訳ございません。
自宅にこのWindow7のノートパソコンと別のXPのディスクトップがありまして普段はXPの方を私が使っておりました。
このたびXPのサポートが終了ということでこの7のノート1台にしようと家族から返してもらったところ、このような変な広告が出るようになっていたわけです。
私が管理者権限をもっているユーザです。
他の二人は標準ユーザとguestユーザになっております。
他の二人にはパソコンが変になっていることを知らせておりますし、それを直すことでダウンロードしたもの等削除されてもいいかどうかは了承をとっております。
とりあえず、 DVD Toaster ActiveX Controlは削除しておきます。
IUに表れていないFree YouTube Downloadは該当ユーザでログインし、IUを起動し、削除してもいいのでしょうか?
これからもどうかご享受おねがいします。
  • ryoyoung
  • MAIL
  • 2014/02/27 (Thu) 16:55:38
ではまた確認しながら調べてください
説明を見せていただきました。
管理者権限はご自身でお持ちということですね。
では引き続き作業しましょう。

>IUに表れていないFree YouTube Downloadは該当ユーザでログインし、IUを起動し、削除してもいいのでしょうか?

はい、まずはその手順で作業してみてください。
ただゲストユーザーではアンインストールできないかもしれないので、その場合はryoyoungさんのユーザーでログインして削除してください。
DVD ToasterはIUに出ないということなので、以下の手順で確認してください。

IU起動して「ブラウザプラグイン」を開いてください。

そこで表示された中をよく見て、上記が見つかればそれにチェックを入れてIUで「削除」すれば削除できるはずです。
ActiveXに隠れていたので簡単には見つからなかったようですね。

Free YouTube DownloadはIUメイン画面で「すべてのプログラム」から探してみてください。
これで見つからなければこちらはとりあえずスルーでいいです。

このあとまた状態報告をお願いします
  • 悪代官
  • 2014/02/27 (Thu) 17:08:25
Re: 駆除
ご苦労さんです。
説明不足だったみたいですが、「ブラウザプラグイン」にDVD Toasterがありましたので、削除しました。
逆にFree YouTube Downloadが管理者の私、他の二人にも「ブラウザプラグイン」、「すべてのプログラム」にもありませんでした。
ただ、今気づいたのですが、覚えのないアイコン(たぶん他の二人のうちの一人がダウンロードした)DVDVideoSoftがディスクトップにありました。
スタート画面のすべてのプログラムの中にも当然ありまして、それをクリックしますとRocket SubscriptionとUninstallとなっています。
Uninstallで削除してもいいのでしょうか?
インターネットで調べてみましたら、DVDVideoSoft Limited製の画像・動画・音声ファイル変換ソフト41種のセット「FreeStudio」の中にFree YouTube Downloadがありました。
※IEで「ツールバーと拡張機能」には無効となっておりますが、Free YouTube Downloadはありますし、相変わらずアクセスしてないのに、hao123とかが表示されます。右クリックで一覧から削除してもまたいつのまにか表示されます。


  • ryoyoung
  • 2014/02/28 (Fri) 13:44:44
Re: 駆除
ご苦労さんです
DVDVideoSoftを開いてみましたら、DVDVideoSoft Limited社のWebサイトにつなぎいろんなソフトをダウンロードできるものでした。
そこからFree YouTube Downloadをダウンロードしたのだろうと思います。
  • ryoyoung
  • 2014/02/28 (Fri) 14:14:06
本当に巧妙に入り込まれてますね
またレスが遅くなってすみません。

>DVDVideoSoftを開いてみましたら、DVDVideoSoft Limited社のWebサイトにつなぎいろんなソフトをダウンロードできるものでした。
>そこからFree YouTube Downloadをダウンロードしたのだろうと思います

はい、DVDVideoSoft社のアプリは以前からこの掲示板だけでもトラブルに絡んでいたことが多かったので、自分の私見では多くの場合削除推奨としています。
今回もやはりこれが絡んでいたようですね。
ではやはりこれもIUでアンインストールしてください。
本体であるこれをアンインストールしてなかったので何度でも復活してたわけですが、自分も今回はこれのことを忘れてました。

>DVDVideoSoftがディスクトップにありました
>クリックしますとRocket SubscriptionとUninstallとなっています

これでUninstallを選択して実行してください。かなりおかしな形で仕込まれてたみたいですが、これで削除できるはずです。

このあとまた先に処置できなかった部分も見直してから、そのあとまた状態報告をください
  • 悪代官
  • 2014/02/28 (Fri) 16:52:29
まだどこかに?
ご苦労様です。
DVDVideoSoftのUninstallはショートカットなんとかと出てうまく出来なかったみたいです。
IUを起動してもDVDVideoSoft、Free YouTube Downloadは「ブラウザプラグイン」、「すべてのプログラム」にも見つかりませんでした。
そしてやはりまだ、IEで「アドオンの管理」の「ツールバーと拡張機能」に無効にはなってますが、Free YouTube Downloadがあります。
それと前ほどではありませんが、やはりhao123がたまに出ますということは完治ではないのですよね?
これからはどのようにすればよいのでしょうか?
ほんとに何度もお世話になります。
  • ryoyoung
  • 2014/03/01 (Sat) 13:32:26
OTLでまた解析してみます
またレスが遅くなってすみません。
まだ異常続いているということですね。
とすると自分がまた見落とした疑いもあるので、先の作業を見直してみましょう。

お手数ですがOTLでまた以下を入力して
%SYSTEMDRIVE%\*.exe
CREATERESTOREPOINT

「Run scan」して、そのログをとったらそれをレスで見せてください。

これも確認ですが、OTLでの「Run scan」時はPCは通常モードで行ってください。

なかなか処置できないまま手間ばかり取らせてすみません
  • 悪代官
  • 2014/03/01 (Sat) 17:11:09
Re: 駆除
いえいえ、こちらこそ言葉不足というか、説明不足とかわかりづらくて何度も申し訳ございません。
OTLのログをとるまえに、ちょっとお聞きしたいことがあるのでおしえてください。
前からあったのかもしれませんが、ディスクトップにContinueInstallationという私が覚えのないショートカットがありまして
それを右クリックしますと、リンク先が私(管理者)¥AppDdate¥Lacal¥Temp¥Free-Faies-downLoaderとなっておりまして
¥AppDdate¥Lacal¥Tempを見てみたところ怪しいのが
Free-Faies-downLoader,アプリケーション、サイズ4315KB
Vit-Sweet-PaGe、アプリケーション、サイズ860KB
あと更新日時が同じ日の2013/10/1にDVDVidioSoft,Is-Bukro.tmp.がありました。
またこの中の2012/07/22の同じ日にVidio284~Vidio6932のなんと6500あまりの約900KBのサイズのファイルがありました。
これは異常じゃないのでしょうか?
開いて中身を確認しても大丈夫でしょうか(たぶん家族のうちの一人がいれたもの?)
IUのシュレッダーで選択してして削除してもいいのでしょうか(ツールバーにUのマークがあります)
また的はずれの質問でしたか?

  • ryoyoung
  • 2014/03/01 (Sat) 18:35:49
どれだけ「種」をまかれているのやら
>ContinueInstallationという私が覚えのないショートカットがありまして
> それを右クリックしますと、リンク先が私(管理者)¥AppDdate¥Lacal¥Temp¥Free-Faies-downLoaderとなっておりまして
>¥AppDdate¥Lacal¥Tempを見てみたところ怪しいのが
>Free-Faies-downLoader,アプリケーション、サイズ4315KB
> Vit-Sweet-PaGe、アプリケーション、サイズ860KB
>あと更新日時が同じ日の2013/10/1にDVDVidioSoft,Is-Bukro.tmp.がありました。

はい、詳しい説明ありがとうございます。よく調べてくれましたね。
どうもそれも隠れて入り込んだ一味のようです。
一体どれだけ手の込んだ手口で入り込んだのやら…

ではそれはIUで削除してください。
そのあとまたOTLのスキャンをお願いします。

削除してもしても復活するのは、こうやって復活のための種を残されていたためでしょうか。
この調子だとまだ種が複数隠れている疑いさえありますね
  • 悪代官
  • 2014/03/01 (Sat) 18:44:18
Re: 駆除
お忙しいなか、またよろしくお願いします。
これを機会にcleanにしたいので、怪しいものはすべて教えてください(他の二人の家族にも了解とってあります)。

OTLのログを添付します。

OTL logfile created on: 2014/03/03 8:50:53 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\オヤジ\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

3.80 Gb Total Physical Memory | 1.99 Gb Available Physical Memory | 52.35% Memory free
7.60 Gb Paging File | 5.42 Gb Available in Paging File | 71.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 454.82 Gb Total Space | 289.91 Gb Free Space | 63.74% Space Free | Partition Type: NTFS
Drive D: | 5.57 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive Q: | 9.77 Gb Total Space | 2.60 Gb Free Space | 26.60% Space Free | Partition Type: NTFS

Computer Name: YUNBOO | User Name: オヤジ | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2014/02/22 18:00:19 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\オヤジ\Downloads\OTL.exe
PRC - [2013/12/21 15:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/11/11 18:49:06 | 000,208,920 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7rtscan.exe
PRC - [2013/10/25 14:53:10 | 000,243,736 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7fwsrvc.exe
PRC - [2013/10/05 12:43:22 | 000,242,848 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsmngr.exe
PRC - [2013/09/13 15:28:58 | 002,387,520 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\epson\MyEPSON Connect\mep.exe
PRC - [2013/09/03 23:33:16 | 000,335,384 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7pssrvc.exe
PRC - [2013/04/02 17:14:02 | 000,154,136 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7emlpxy.exe
PRC - [2013/03/28 15:55:58 | 001,058,880 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
PRC - [2013/01/01 17:45:46 | 000,163,504 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe
PRC - [2012/12/12 15:28:06 | 005,812,912 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
PRC - [2012/11/29 21:07:14 | 002,197,600 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe
PRC - [2012/10/01 16:17:38 | 000,703,616 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\epson\MyEPSON Connect\mepService.exe
PRC - [2011/12/21 23:16:54 | 000,262,752 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe
PRC - [2011/11/05 20:50:19 | 000,072,800 | ---- | M] (K7 Computing Pvt Ltd) -- C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SysMon.Exe
PRC - [2011/03/17 20:40:57 | 000,382,360 | ---- | M] (デジタルアーツ株式会社) -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe
PRC - [2011/03/17 20:40:52 | 000,681,368 | ---- | M] (デジタルアーツ株式会社) -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
PRC - [2011/03/17 20:40:30 | 000,947,608 | ---- | M] (デジタルアーツ株式会社) -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5control_manager.exe
PRC - [2011/03/17 20:40:27 | 001,172,888 | ---- | M] (デジタルアーツ株式会社) -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5bigbrother.exe
PRC - [2010/12/02 16:08:28 | 000,210,784 | ---- | M] (InterVideo Inc.) -- C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
PRC - [2010/11/01 13:15:46 | 000,053,248 | ---- | M] (I-O DATA DEVICE, INC.) -- C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe
PRC - [2010/08/20 14:21:08 | 001,028,096 | ---- | M] (Lenovo Group Limited) -- C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
PRC - [2010/05/24 10:52:38 | 000,208,760 | ---- | M] (BUFFALO INC.) -- C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
PRC - [2010/04/28 09:58:52 | 000,172,544 | ---- | M] (Panasonic Corporation) -- C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
PRC - [2010/04/20 13:23:32 | 000,074,088 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
PRC - [2010/04/20 13:23:28 | 000,062,312 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
PRC - [2010/04/20 13:23:18 | 000,050,536 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\CamMute.exe
PRC - [2010/04/07 14:37:40 | 000,093,032 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe
PRC - [2010/04/01 14:50:46 | 000,043,960 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
PRC - [2009/11/04 13:45:46 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009/11/04 13:45:44 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009/09/02 19:20:18 | 000,071,064 | ---- | M] (Panasonic Corporation) -- C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe
PRC - [2009/07/09 10:18:24 | 000,126,328 | ---- | M] (BUFFALO INC.) -- C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe
PRC - [2009/07/02 16:55:00 | 000,032,248 | ---- | M] (CASIO SOFT CO. LTD.) -- C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe
PRC - [2009/06/07 13:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\SysWOW64\NlsSrv32.exe
PRC - [2009/05/27 22:09:36 | 000,049,976 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
PRC - [2007/06/15 12:57:42 | 000,145,504 | ---- | M] (B.H.A Corporation) -- C:\Windows\SysWOW64\bgsvcgen.exe
PRC - [2007/01/04 19:48:50 | 000,112,152 | ---- | M] (InterVideo) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2014/02/25 20:12:50 | 000,689,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlServ#\7661deb9f27c70ff9f468bee2b6dac94\System.Data.SqlServerCe.ni.dll
MOD - [2014/02/25 19:36:09 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\8bc548587e91ecf0552a40e47bbf99cc\System.Windows.Forms.ni.dll
MOD - [2014/02/25 19:35:58 | 000,628,224 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\faf3ae85f2470505e1b32d2154de60ef\System.EnterpriseServices.ni.dll
MOD - [2014/02/25 19:35:57 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\cd3556d1162e8f7df77611c9c4253f7c\System.Transactions.ni.dll
MOD - [2014/02/25 19:35:56 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\fe1942c05eda4f9744f80afb4ae76a2d\System.Data.ni.dll
MOD - [2014/02/25 19:35:53 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5c24d3b0041ebf4f48a93615b9fa3de9\System.Drawing.ni.dll
MOD - [2014/02/25 19:35:42 | 005,464,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\217ece46920546d718414291d463bb1c\System.Xml.ni.dll
MOD - [2014/02/25 19:35:39 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\5b6ddf934128d538cd5cd77bf4209b93\System.Configuration.ni.dll
MOD - [2014/02/25 19:35:38 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b3a78269847005365001c33870cd121f\System.ni.dll
MOD - [2014/02/25 19:35:34 | 011,499,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ede2c6c842840e009f01bcc74fa4c457\mscorlib.ni.dll
MOD - [2013/09/05 00:14:10 | 004,300,456 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/11/13 09:00:19 | 000,348,160 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_ja_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010/11/05 10:58:05 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2009/07/09 10:18:32 | 000,055,160 | ---- | M] () -- C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32SPS.dll
MOD - [2009/07/02 16:55:00 | 000,024,056 | ---- | M] () -- C:\Program Files (x86)\Sony\LISMO Port\LPPIMTools.dll
MOD - [2009/06/11 06:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009/05/27 22:09:36 | 000,049,976 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2014/02/06 19:48:45 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2013/11/11 11:22:20 | 000,066,856 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Windows\SysNative\ibmpmsvc.exe -- (IBMPMSVC)
SRV:[b]64bit:[/b] - [2013/05/27 14:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2013/04/15 08:00:02 | 000,152,640 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE -- (EPSON_PM_RPCV4_06)
SRV:[b]64bit:[/b] - [2012/05/17 00:00:00 | 000,144,560 | ---- | M] (Seiko Epson Corporation) [Auto | Running] -- C:\Windows\SysNative\escsvc64.exe -- (EpsonScanSvc)
SRV:[b]64bit:[/b] - [2011/01/13 14:05:46 | 000,047,728 | ---- | M] (Lenovo.) [On_Demand | Stopped] -- C:\Windows\SysNative\TPHDEXLG64.exe -- (TPHDEXLGSVC)
SRV:[b]64bit:[/b] - [2010/04/20 13:23:32 | 000,074,088 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe -- (LENOVO.TPKNRSVC)
SRV:[b]64bit:[/b] - [2010/04/20 13:23:18 | 000,050,536 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\Communications Utility\CamMute.exe -- (LENOVO.CAMMUTE)
SRV:[b]64bit:[/b] - [2010/04/07 14:37:40 | 000,093,032 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC)
SRV:[b]64bit:[/b] - [2009/12/21 10:44:06 | 000,535,552 | ---- | M] (CSR, plc) [Auto | Running] -- C:\Windows\SysNative\HFGService.dll -- (HFGService)
SRV:[b]64bit:[/b] - [2009/09/29 17:25:48 | 000,126,392 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV - [2014/02/21 20:46:14 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/02/08 15:39:42 | 002,151,744 | ---- | M] (IObit) [Auto | Stopped] -- C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe -- (LiveUpdateSvc)
SRV - [2013/12/21 15:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/11/11 18:49:06 | 000,208,920 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7rtscan.exe -- (K7RTScan)
SRV - [2013/10/25 14:53:10 | 000,243,736 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7fwsrvc.exe -- (K7FWSrvc)
SRV - [2013/10/05 12:43:22 | 000,242,848 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsmngr.exe -- (K7TSMngr)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/09/03 23:33:16 | 000,335,384 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7pssrvc.exe -- (K7PSSrvc)
SRV - [2013/06/26 15:57:38 | 000,022,376 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2013/04/02 17:14:02 | 000,154,136 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\k7emlpxy.exe -- (K7EmlPxy)
SRV - [2012/12/12 15:28:04 | 000,131,760 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe -- (SonicStage Back-End Service2)
SRV - [2012/11/29 21:07:14 | 002,197,600 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe -- (EzDetector)
SRV - [2012/11/29 13:31:28 | 000,174,176 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2012/10/01 16:17:38 | 000,703,616 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files (x86)\epson\MyEPSON Connect\mepService.exe -- (MyEPSON Connect Service)
SRV - [2012/06/21 20:45:52 | 000,281,216 | ---- | M] (K7 Computing Pvt Ltd) [On_Demand | Stopped] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SpmSrc.exe -- (K7SpmSrc)
SRV - [2011/12/21 23:16:54 | 000,262,752 | ---- | M] (K7 Computing Pvt Ltd) [Auto | Running] -- C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe -- (K7CrvSvc)
SRV - [2011/03/17 20:40:57 | 000,382,360 | ---- | M] (デジタルアーツ株式会社) [Auto | Running] -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe -- (IFP5WatchService)
SRV - [2011/03/17 20:40:52 | 000,681,368 | ---- | M] (デジタルアーツ株式会社) [Auto | Running] -- C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe -- (IFP5MainService)
SRV - [2010/12/02 16:08:28 | 000,210,784 | ---- | M] (InterVideo Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service)
SRV - [2010/11/01 13:15:46 | 000,053,248 | ---- | M] (I-O DATA DEVICE, INC.) [Auto | Running] -- C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe -- (mAgicTVDigital)
SRV - [2010/08/25 03:30:00 | 000,075,112 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe -- (Power Manager DBC Service)
SRV - [2010/08/20 14:21:08 | 001,028,096 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service)
SRV - [2009/11/04 13:45:46 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009/11/04 13:45:44 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009/09/02 19:20:18 | 000,071,064 | ---- | M] (Panasonic Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe -- (SD Device Manager)
SRV - [2009/07/09 10:18:24 | 000,126,328 | ---- | M] (BUFFALO INC.) [Auto | Running] -- C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe -- (BWH32S)
SRV - [2009/07/02 16:55:00 | 000,032,248 | ---- | M] (CASIO SOFT CO. LTD.) [Auto | Running] -- C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe -- (LISMO PIM Service)
SRV - [2009/06/11 06:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/07 13:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\Windows\SysWOW64\NlsSrv32.exe -- (nlsX86cc)
SRV - [2007/12/17 13:21:00 | 000,075,040 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe -- (SSScsiSV)
SRV - [2007/12/17 13:20:56 | 000,107,808 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe -- (SonicStage Back-End Service)
SRV - [2007/06/15 12:57:42 | 000,145,504 | ---- | M] (B.H.A Corporation) [Auto | Running] -- C:\Windows\SysWOW64\bgsvcgen.exe -- (bgsvcgen)
SRV - [2007/01/04 19:48:50 | 000,112,152 | ---- | M] (InterVideo) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2013/11/11 11:22:20 | 000,054,528 | ---- | M] (Lenovo.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ibmpmdrv.sys -- (IBMPMDRV)
DRV:[b]64bit:[/b] - [2013/10/18 15:02:54 | 001,199,904 | ---- | M] (K7 Computing Pvt Ltd) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\K7Sentry.Sys -- (K7Sentry)
DRV:[b]64bit:[/b] - [2013/10/02 11:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2013/09/18 20:45:36 | 000,108,320 | ---- | M] (K7 Computing Pvt Ltd) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\K7FWHlpr.Sys -- (K7FWHlpr)
DRV:[b]64bit:[/b] - [2013/04/24 01:23:00 | 000,460,528 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2012/12/13 14:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:[b]64bit:[/b] - [2012/09/12 15:20:04 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:[b]64bit:[/b] - [2012/08/23 23:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:[b]64bit:[/b] - [2012/08/15 15:24:54 | 000,056,336 | ---- | M] (Corel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:[b]64bit:[/b] - [2012/03/01 15:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2012/01/10 22:28:18 | 012,311,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2011/03/11 15:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011/03/11 15:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2011/01/13 14:04:20 | 000,139,888 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsX64.sys -- (Shockprf)
DRV:[b]64bit:[/b] - [2011/01/13 14:02:28 | 000,023,664 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsHM64.sys -- (TPDIGIMN)
DRV:[b]64bit:[/b] - [2010/11/29 20:19:26 | 000,477,432 | ---- | M] (I-O DATA DEVICE, INC.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\gvmvpfz_x64.sys -- (GVMVPFZ)
DRV:[b]64bit:[/b] - [2010/11/20 22:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010/11/20 18:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2010/11/15 07:36:50 | 000,175,688 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\t008mdm.sys -- (t008mdm)
DRV:[b]64bit:[/b] - [2010/11/15 07:36:50 | 000,019,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\t008mdfl.sys -- (t008mdfl)
DRV:[b]64bit:[/b] - [2010/11/15 07:36:48 | 000,154,696 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\t008bus.sys -- (t008bus)
DRV:[b]64bit:[/b] - [2010/11/15 07:36:48 | 000,149,064 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\t008kmmo.sys -- (t008kmmo)
DRV:[b]64bit:[/b] - [2010/11/12 10:34:44 | 000,025,072 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- c:\Program Files\PC-Doctor\pcdsrvc_x64.pkms -- (PCDSRVC{127174DC-C366ED8B-06020101}_0)
DRV:[b]64bit:[/b] - [2010/09/07 14:09:34 | 000,015,472 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\smiifx64.sys -- (lenovo.smi)
DRV:[b]64bit:[/b] - [2010/08/25 03:30:00 | 000,013,104 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\TPPWR64V.SYS -- (TPPWRIF)
DRV:[b]64bit:[/b] - [2010/08/20 03:45:28 | 000,654,720 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emBDA64.sys -- (USB28xxBGA)
DRV:[b]64bit:[/b] - [2010/08/20 03:44:48 | 000,943,872 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emOEM64.sys -- (USB28xxOEM)
DRV:[b]64bit:[/b] - [2010/08/17 11:51:50 | 000,143,992 | ---- | M] (Cobalt Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\DTH10_Series.sys -- (DTH10_Series)
DRV:[b]64bit:[/b] - [2010/05/17 17:32:56 | 001,107,488 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192se.sys -- (rtl8192se)
DRV:[b]64bit:[/b] - [2010/02/26 16:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:[b]64bit:[/b] - [2010/02/03 06:38:30 | 000,271,872 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2010/01/16 05:22:08 | 000,538,136 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:[b]64bit:[/b] - [2009/12/21 10:43:36 | 000,052,224 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAudioHF.sys -- (BthAudioHF)
DRV:[b]64bit:[/b] - [2009/12/21 10:43:00 | 000,078,848 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthav.sys -- (csr_a2dp)
DRV:[b]64bit:[/b] - [2009/09/29 17:25:50 | 000,012,728 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:[b]64bit:[/b] - [2009/09/17 12:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:[b]64bit:[/b] - [2009/08/13 08:38:24 | 000,029,184 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcp.sys -- (BthAvrcp)
DRV:[b]64bit:[/b] - [2009/07/14 10:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/14 10:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/14 10:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/07/14 08:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2009/07/02 11:16:02 | 000,040,512 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\psadd.sys -- (psadd)
DRV:[b]64bit:[/b] - [2009/06/11 06:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:[b]64bit:[/b] - [2009/06/11 06:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:[b]64bit:[/b] - [2009/06/11 06:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:[b]64bit:[/b] - [2009/06/11 05:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/11 05:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2008/02/15 15:01:22 | 000,165,120 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfbd.sys -- (tosrfbd)
DRV:[b]64bit:[/b] - [2008/01/31 15:55:24 | 000,088,448 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV:[b]64bit:[/b] - [2008/01/22 20:58:12 | 000,056,320 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TosRfSnd.sys -- (TosRfSnd)
DRV:[b]64bit:[/b] - [2007/11/29 09:45:58 | 000,044,800 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfbnp.sys -- (tosrfbnp)
DRV:[b]64bit:[/b] - [2007/10/18 14:25:00 | 000,051,328 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfusb.sys -- (Tosrfusb)
DRV:[b]64bit:[/b] - [2007/10/02 11:43:08 | 000,076,160 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfcom.sys -- (Tosrfcom)
DRV:[b]64bit:[/b] - [2007/08/17 14:48:40 | 000,018,432 | ---- | M] (BUFFALO INC.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bufeap64.sys -- (Bufeap)
DRV:[b]64bit:[/b] - [2007/01/12 20:28:06 | 000,077,312 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emAudio64.sys -- (emAudio)
DRV:[b]64bit:[/b] - [2006/10/11 16:31:00 | 000,050,688 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosporte.sys -- (tosporte)
DRV:[b]64bit:[/b] - [2005/07/13 06:43:00 | 000,028,160 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfnds.sys -- (tosrfnds)
DRV - [2009/07/14 10:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2007/01/23 15:56:58 | 000,146,432 | ---- | M] (K7 Computing Pvt Ltd) [File_System | Boot | Running] -- C:\Windows\SysWOW64\drivers\K7Sentry.sys -- (K7Sentry)
DRV - [2006/11/21 22:27:16 | 000,009,728 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysWOW64\drivers\K7FWHlpr.sys -- (K7FWHlpr)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{B51E6D5A-A882-4912-A29B-EDB8314596EC}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/search?q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/jp/ja [binary data]
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.jp/
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


[color=#E56717]========== FireFox ==========[/color]

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@k7computing.com/k7webprotection: C:\Program Files (x86)\\K7 Computing\K7TSecurity\npK7SRNPExt.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\k7srff@k7computing.com: C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SR [2014/02/07 16:29:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\e-webprint@epson.com: C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2014/02/16 18:57:37 | 000,000,000 | ---D | M]


[color=#E56717]========== Chrome ==========[/color]

CHR - homepage: http://www.google.com/
CHR - homepage: http://jp.hao123.com/?tn=epom_pay_hp_04_hao123_jp
CHR - Extension: K7 WebProtection = C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlpfamleaodfgmfnggonbfljhjggbdbe\2.3_0\
CHR - Extension: K7 WebProtection = C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/11 06:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (ExplorerWnd Helper) - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
O2:[b]64bit:[/b] - BHO: (E-Photo) - {60B127CA-8AA4-4DCD-84A8-D18C2B2C4A96} - C:\Program Files (x86)\EPSON Software\E-Photo\EPTBL.dll (SEIKO EPSON CORPORATION)
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (K7 Web Protection) - {08B3B4B6-02DA-4658-8BA6-5974E3EBB03D} - C:\Program Files (x86)\K7 Computing\K7TSecurity\k7srext.dll (K7 Computing Pvt Ltd)
O2 - BHO: (E-Web Print) - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (E-Photo) - {60B127CA-8AA4-4DCD-84A8-D18C2B2C4A96} - C:\Program Files (x86)\EPSON Software\E-Photo\EPTBL.dll (SEIKO EPSON CORPORATION)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (E-Web Print) - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\..\Toolbar\WebBrowser: (no name) - {AEF44653-C059-42CB-A5B7-41C640DA4A67} - No CLSID value found.
O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe (Lenovo Group Limited)
O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [TpShocks] C:\Windows\SysNative\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [iFilter5] "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun File not found
O4 - HKLM..\Run: [K7SystemTray] "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe" File not found
O4 - HKLM..\Run: [K7TSStart] C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe (K7 Computing Pvt Ltd)
O4 - HKLM..\Run: [LPStation] C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe (Sony Corporation)
O4 - HKLM..\Run: [PWMTRV] C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL (Lenovo Group Limited)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series" File not found
O4 - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000..\Run: [EPLTarget\P0000000000000001] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000001" /M "EP-706A Series" File not found
O4 - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000..\Run: [EPLTarget\P0000000000000002] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000002" /M "EP-706A Series" File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-2470042596-1514475608-4269787398-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O9:[b]64bit:[/b] - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O9 - Extra Button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll (Apple Inc.)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000020 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {4845B7A7-309F-49F4-A2DD-0117707B6E8D} https://toast.dvdtoaster.jp/downloads/activex/x86/dvdtoast.cab (DVD Toaster ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 10.51.2)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 1.7.0_09)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.51.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C059A8EC-DFD2-4F21-91C1-A1C6D9343219}: DhcpNameServer = 192.168.11.1
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/11 01:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{5b12fb2c-3430-11e0-bed1-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{5b12fb2c-3430-11e0-bed1-806e6f6e6963}\Shell\AutoRun\command - "" = D:\InstallNavi.exe
O33 - MountPoints2\{a1c8f30f-342e-11e0-be01-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{a1c8f30f-342e-11e0-be01-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe -- [2009/08/11 06:01:24 | 000,267,576 | -HS- | M] (Lenovo Group Limited)
O33 - MountPoints2\{f931b122-03a5-11e1-bc2d-001b41049f1d}\Shell - "" = AutoRun
O33 - MountPoints2\{f931b122-03a5-11e1-bc2d-001b41049f1d}\Shell\AutoRun\command - "" = E:\g_setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (K7TSDbg)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2014/03/02 16:28:53 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Local\Adobe
[2014/02/26 08:37:44 | 006,574,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2014/02/26 08:37:44 | 005,694,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2014/02/25 17:57:07 | 000,000,000 | ---D | C] -- C:\Windows\Migration
[2014/02/25 08:39:40 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\Desktop\ログ1
[2014/02/24 08:53:12 | 000,000,000 | ---D | C] -- C:\_OTL
[2014/02/24 08:34:58 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\Desktop\ログ
[2014/02/22 08:59:02 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2014/02/22 08:58:59 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWbPrxy.exe
[2014/02/22 08:58:59 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
[2014/02/22 08:58:59 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2014/02/22 08:58:59 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsRdpWebAccess.dll
[2014/02/22 08:58:59 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
[2014/02/22 08:58:59 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MsRdpWebAccess.dll
[2014/02/22 08:58:59 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprtPS.dll
[2014/02/22 08:58:59 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wksprtPS.dll
[2014/02/22 08:58:59 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2014/02/22 08:58:59 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2014/02/22 08:58:57 | 001,147,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe
[2014/02/22 08:58:57 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
[2014/02/22 08:58:57 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprt.exe
[2014/02/22 08:58:56 | 001,057,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdvidcrl.dll
[2014/02/22 08:58:56 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdvidcrl.dll
[2014/02/22 08:58:21 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2014/02/22 08:58:19 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2014/02/22 08:58:15 | 003,174,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll
[2014/02/22 08:58:15 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpudd.dll
[2014/02/22 08:58:15 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpendp_winip.dll
[2014/02/22 08:58:15 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpendp_winip.dll
[2014/02/22 08:10:53 | 001,030,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWorkspace.dll
[2014/02/22 08:10:53 | 000,792,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TSWorkspace.dll
[2014/02/22 08:10:39 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2014/02/22 08:10:39 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2014/02/19 08:41:20 | 000,365,976 | ---- | C] (デジタルアーツ株式会社) -- C:\Windows\SysWow64\ifp5lsp.dll
[2014/02/17 07:26:36 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\AppData\Roaming\Epson
[2014/02/16 19:25:01 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\Desktop\エプソンショートカット
[2014/02/16 18:56:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\読んde!!ココ
[2014/02/16 18:56:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Aisoft
[2014/02/16 18:55:05 | 000,000,000 | ---D | C] -- C:\ProgramData\UDL
[2014/02/16 18:44:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\EPSON
[2014/02/16 18:42:33 | 000,558,592 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\ensppmon.dll
[2014/02/16 18:42:33 | 000,535,552 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\ensppui.dll
[2014/02/16 18:42:33 | 000,211,968 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\enspres.dll
[2014/02/16 18:42:33 | 000,211,968 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\enpres.dll
[2014/02/16 18:42:32 | 000,558,592 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\enppmon.dll
[2014/02/16 18:42:32 | 000,535,552 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\enppui.dll
[2014/02/16 18:42:32 | 000,000,000 | ---D | C] -- C:\Program Files\EpsonNet
[2014/02/16 18:35:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software
[2014/02/16 18:35:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EPSON Software
[2014/02/16 18:35:06 | 000,466,432 | ---- | C] (Seiko Epson Corporation) -- C:\Windows\SysNative\esxw2ud.dll
[2014/02/16 18:35:06 | 000,144,560 | ---- | C] (Seiko Epson Corporation) -- C:\Windows\SysNative\escsvc64.exe
[2014/02/16 18:35:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
[2014/02/16 18:35:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\epson
[2014/02/16 18:34:10 | 000,179,712 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\E_ILMBLMJ.DLL
[2014/02/16 18:34:10 | 000,083,968 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\SysNative\E_ID4BLMJ.DLL
[2014/02/16 18:34:10 | 000,010,752 | ---- | C] (SEIKO EPSON CORP.) -- C:\Windows\SysNative\E_GCINST.DLL
[2014/02/15 08:23:43 | 000,000,000 | ---D | C] -- C:\Users\オヤジ\Desktop\ぱそこん
[2014/02/13 15:38:39 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/02/13 15:21:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2014/02/13 14:24:54 | 000,821,736 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2014/02/13 14:24:54 | 000,746,984 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2014/02/13 10:55:28 | 000,548,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014/02/13 10:54:57 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/02/13 10:54:57 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/02/13 10:54:56 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/02/13 10:54:56 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/02/13 10:54:55 | 000,627,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/02/13 10:54:55 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/02/13 10:54:55 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/02/13 10:54:55 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/02/13 10:54:54 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/02/13 10:54:54 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/02/13 10:54:54 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/02/13 10:54:54 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/02/13 10:54:54 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/02/13 10:54:54 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/02/13 10:54:54 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/02/13 10:54:54 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/02/13 10:54:53 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/02/13 10:54:53 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/02/13 10:54:53 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/02/13 10:54:53 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/02/13 10:54:52 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/02/13 10:54:52 | 001,964,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/02/13 10:54:50 | 005,768,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/02/12 17:55:31 | 002,565,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2014/02/12 17:55:30 | 003,928,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2014/02/12 17:54:41 | 000,658,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe
[2014/02/12 17:54:41 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe
[2014/02/12 17:54:41 | 000,594,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe
[2014/02/12 17:54:40 | 000,572,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe
[2014/02/12 17:54:40 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2014/02/12 17:54:40 | 000,508,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2014/02/12 17:54:39 | 000,553,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe
[2014/02/12 17:54:39 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe
[2014/02/12 17:54:39 | 000,485,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll
[2014/02/12 17:54:39 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll
[2014/02/12 17:54:38 | 000,528,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdrm.dll
[2014/02/12 17:54:38 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll
[2014/02/12 17:54:38 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2014/02/12 17:54:37 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll
[2014/02/12 17:54:37 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll
[2014/02/12 17:54:36 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll
[2014/02/12 17:54:36 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll
[2014/02/12 17:50:04 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll
[2014/02/12 17:50:03 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll
[2014/02/12 10:26:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2014/02/12 10:26:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2014/02/12 09:51:19 | 000,028,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEUDINIT.EXE
[2014/02/12 09:46:13 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2014/02/12 09:46:13 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2014/02/12 09:46:10 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2014/02/12 09:46:10 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2014/02/12 09:46:10 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2014/02/12 09:46:10 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2014/02/12 09:46:10 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2014/02/12 09:46:10 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2014/02/12 09:46:10 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2014/02/12 09:46:10 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2014/02/12 09:46:10 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2014/02/12 09:46:10 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2014/02/12 09:46:09 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2014/02/12 09:46:09 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2014/02/12 09:46:09 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2014/02/12 09:46:09 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2014/02/12 09:46:09 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2014/02/12 09:46:09 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2014/02/12 09:46:09 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2014/02/12 09:46:09 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2014/02/12 09:46:09 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2014/02/12 09:46:09 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014/02/12 09:46:09 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2014/02/12 09:46:09 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2014/02/12 09:46:09 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2014/02/12 09:46:09 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2014/02/12 09:46:08 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2014/02/12 09:46:07 | 001,228,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2014/02/12 09:46:07 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2014/02/12 09:46:07 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2014/02/12 09:46:07 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2014/02/12 09:46:07 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014/02/12 09:46:07 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2014/02/12 09:46:07 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2014/02/12 09:46:07 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2014/02/12 09:46:07 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2014/02/12 09:46:07 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2014/02/12 09:46:07 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2014/02/12 09:46:07 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2014/02/12 09:46:07 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2014/02/12 09:46:07 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2014/02/12 09:46:07 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2014/02/12 09:46:07 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2014/02/12 09:46:07 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2014/02/12 09:46:07 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2014/02/12 09:46:07 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014/02/12 09:46:07 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2014/02/12 09:46:07 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2014/02/12 09:46:07 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2014/02/12 09:46:07 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2014/02/12 09:46:07 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2014/02/12 09:46:07 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2014/02/12 09:46:07 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2014/02/12 09:46:07 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2014/02/12 09:46:07 | 000,013,824 | ---- |
  • ryoyoung
  • 2014/03/03 (Mon) 09:15:11
Delta-homes発見。またOTLで処置します
レスが遅くなってすみません。
ログを見たところ、また感染が見つかったので、先にやった手順で以下のスクリプトを使ってOTLで「Run fix」作業してください。
作業後にまた様子見後、状態報告をレスください。
-------------------------------------------
:OTL
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
CHR - homepage: http://jp.hao123.com/?tn=epom_pay_hp_04_hao123_jp
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000020 - C:\Windows\SysNative\ifp5lsp64.dll (デジタルアーツ株式会社)

:Files

:Commands
[purity]
[createrestorepoint]
[emptytemp]
[reboot]
  • 悪代官
  • 2014/03/03 (Mon) 17:40:51
復活
お忙しいなか、何度もありがとうございます。
同じ作業をした記憶がありますが、また復活したのはなぜなんでしょうか?

ログを添付します
All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Use Chrome's Settings page to change the HomePage.
File rity] not found.
File eaterestorepoint] not found.
File ptytemp] not found.
File boot] not found.

OTL by OldTimer - Version 3.2.69.0 log created on 03032014_181702

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • ryoyoung
  • 2014/03/03 (Mon) 18:30:51
ではまた状態確認です
早速の作業と報告、ご苦労様です。

>同じ作業をした記憶がありますが、また復活したのはなぜなんでしょうか?

はい、今回OTLで見つけて処置した物は、先に処置した物とは別物です。
つまりどこかのサイトで油断して拾ってしまったのが原因というわけです。
今回OTLで処置した以下のエントリですが、
>IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}

これはここ数週間で爆発的に被害拡大中の「Delta-homes」というサイト関連のエントリです。
これは先の処置時にはまだなかったはずのもので、やはり前の処置後に仕込まれたと考えられます。

ではお手数ですがまた状況を見直します。
またHJTとインスト情報ログと、CCでの各タブのログを返信に貼って、それを状態報告とともにレスで見せてください。

他の方でも一旦処置ができたあとにまた別の感染を食らう事例が相次いでます。
スレが解決してもしなくても、信頼できないサイトへのアクセスは控えてくださいい
  • 悪代官
  • 2014/03/03 (Mon) 19:32:28
Re: 駆除
ご苦労さんです。何度も何度もお手数かけます。ログと写真を添付します。
写真は前にも書きましたが、一覧から削除してもいつの間にかhao123...が復活してます

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:35:49, on 2014/03/04
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMECMNT.EXE
C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\k7tsecurity.exe
C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SysMon.Exe
C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe
C:\Program Files (x86)\EPSON\MyEPSON Connect\mep.exe
C:\Users\オヤジ\Downloads\HijackThis.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMECMNT.EXE

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: K7 Web Protection - {08B3B4B6-02DA-4658-8BA6-5974E3EBB03D} - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
O2 - BHO: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Microsoft アカウント サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [K7TSStart] C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [LPStation] C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [K7SystemTray] "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
O4 - HKLM\..\Run: [iFilter5] "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series"
O4 - HKCU\..\Run: [EPLTarget\P0000000000000001] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000001" /M "EP-706A Series"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Continue installation.lnk = ?
O4 - Global Startup: PHOTOfunSTUDIO 5.0 HD Edition.lnk = C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
O4 - Global Startup: クライアントマネージャV.lnk = C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: OneNote に送る(&N) - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: OneNote に送る - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: OneNote に送る(&N) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {4845B7A7-309F-49F4-A2DD-0117707B6E8D} (DVD Toaster ActiveX Control) - https://toast.dvdtoaster.jp/downloads/activex/x86/dvdtoast.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: Bonjour サービス (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: BWH32S - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EzDetector - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\EzDetector\EzDetector.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: i-フィルター 5.0 Main (IFP5MainService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5main_service.exe
O23 - Service: i-フィルター 5.0 Support (IFP5WatchService) - デジタルアーツ株式会社 - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5watcher.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: K7Carnivore Service (K7CrvSvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe
O23 - Service: K7Computng - EMail Proxy Server (K7EmlPxy) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7EmlPxy.exe
O23 - Service: K7Firewall Services (K7FWSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7FWSrvc.exe
O23 - Service: K7Privacy Services (K7PSSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7PSSrvc.exe
O23 - Service: K7RealTime AntiVirus Services (K7RTScan) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7RTScan.exe
O23 - Service: K7SpmSrc - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SpmSrc.exe
O23 - Service: K7TotalSecurity Manager (K7TSMngr) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSMngr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: LISMO PIM Service - CASIO SOFT CO. LTD. - C:\Program Files (x86)\Sony\LISMO Port\LismoPimSrv.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: I-O DATA mAgicTV Digital (mAgicTVDigital) - I-O DATA DEVICE, INC. - C:\Program Files (x86)\I-O DATA\mAgicTVD\mtvdsv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyEPSON Connect Service - SEIKO EPSON CORPORATION - C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NlsSrv32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SD Device Manager - Panasonic Corporation - C:\Program Files (x86)\Common Files\Panasonic\SDApf2\SDDevMgr.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: SonicStage Back-End Service2 - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14511 bytes

Access Help Lenovo 2011/02/09 3.00
Adobe Flash Player 12 ActiveX Adobe Systems Incorporated 2014/02/21 6.00 MB 12.0.0.70
Adobe Reader XI (11.0.06) - Japanese Adobe Systems Incorporated 2014/02/12 147 MB 11.0.06
Apple Application Support Apple Inc. 2013/10/01 64.0 MB 2.3.6
Apple Mobile Device Support Apple Inc. 2013/10/01 25.0 MB 7.0.0.117
au ISW11K USB Driver 京セラ株式会社 2012/03/01 1.00.0000
au T008 USB Driver Ver.5.0.0.1 2011/09/24 V5.24.1.0
Bonjour Apple Inc. 2014/02/03 3.29 MB 1.0.106
BUFFALO エアステーション設定ツール BUFFALO INC. 2011/09/25 2.84 MB 2.0.5
BUFFALO クライアントマネージャV BUFFALO INC. 2014/02/20
BUFFALO パソコン環境表示ツール BUFFALO INC. 2011/09/25 1.0.3
Corel DVD MovieWriter Lenovo Edition Corel Corporation 2011/02/09 320 MB 7.0.0
Corel TVX Corel Corporation 2014/02/03 31.2 MB 2.2-B0.5
Create Recovery Media Lenovo Group Limited 2011/02/09 9.50 MB 1.20.0.00
DVD Decrypter (Remove Only) 2014/02/20
DVD Flick 1.3.0.7 Dennis Meuwissen 2012/05/05 1.3.0.7
DVD Shrink 3.2 DVD Shrink 2014/02/20
Epson Connect Printer Setup SEIKO EPSON CORPORATION 2014/03/03 8.32 MB 1.1.1
Epson E-Photo SEIKO EPSON CORPORATION 2014/02/16 1.4.1.0
Epson E-Web Print SEIKO EPSON CORPORATION 2014/02/16 9.22 MB 1.19.0000
EPSON EP-706A Series プリンター アンインストール SEIKO EPSON Corporation 2014/02/16
Epson Event Manager Seiko Epson Corporation 2014/02/16 42.4 MB 3.10.0017
Epson Print CD SEIKO EPSON CORPORATION 2014/02/16 2.21.00
EPSON Scan Seiko Epson Corporation 2014/02/20
EPSON Scan OCR コンポーネント SEIKO EPSON Corp. 2014/02/16 1.33.0000
EPSON マニュアル SEIKO EPSON CORPORATION 2014/03/02 708 KB 1.32.0.0
EpsonNet Print SEIKO EPSON CORPORATION 2014/02/16 2.6.0
I-O DATA mAgicTV Digital I-O DATA DEVICE,INC. 2014/02/03 1.01.00
Intel(R) Control Center Intel Corporation 2011/02/09 1.2.1.1007
Intel(R) Graphics Media Accelerator Driver Intel Corporation 2011/02/09 8.15.10.2125
Intel(R) Management Engine Components Intel Corporation 2011/02/09 6.0.0.1179
InterVideo WinDVD 8 InterVideo Inc. 2011/02/09 163 MB 8.0.20.199
IObit Uninstaller IObit 2014/02/08 3.1.7.2405
Java 7 Update 51 Oracle 2014/02/08 118 MB 7.0.510
Jw_cad 2014/02/20
Lenovo Auto Scroll Utility 2011/02/09 1.00
Lenovo Patch Utility Lenovo Group Limited 2013/05/12 1.33 MB 1.3.1.1
Lenovo Patch Utility 64 bit Lenovo Group Limited 2013/05/12 1.35 MB 1.3.1.1
Lenovo Power Management Driver 2014/02/22 1.67.04.04
Lenovo System Interface Driver 2013/05/12 1.05
Lenovo System Update Lenovo 2013/07/16 13.4 MB 5.02.0018
Lenovo ThinkVantage Toolbox PC-Doctor, Inc. 2011/02/09 6.0.5717.21
Lenovo Warranty Information Lenovo 2011/02/09 893 KB 1.0.0004.00
Lenovo Welcome Lenovo 2011/02/09
LISMO Port 5.1 Sony Corporation 2013/03/10 110 MB 5.1
Message Center Plus Lenovo Group Limited 2011/02/09 1.70 MB 2.0.0012.00
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 2011/02/27 38.8 MB 4.0.30319
Microsoft .NET Framework 4.5.1 Microsoft Corporation 2014/02/25 38.8 MB 4.5.50938
Microsoft Office Home and Business 2010 Microsoft Corporation 2014/02/20 14.0.7015.1000
Microsoft Office Word Viewer 2003 Microsoft Corporation 2014/01/16 105 MB 11.0.8173.0
Microsoft Silverlight Microsoft Corporation 2013/10/10 149 MB 5.1.20913.0
Microsoft SkyDrive Microsoft Corporation 2013/01/15 25.1 MB 16.4.6013.0910
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2011/02/09 1.69 MB 3.1.0000
Microsoft SQL Server Compact 3.5 SP1 English Microsoft Corporation 2011/02/28 2.59 MB 3.5.5692.0
Microsoft SQL Server Compact 3.5 SP1 x64 English Microsoft Corporation 2011/02/28 3.69 MB 3.5.5692.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 Microsoft Corporation 2011/02/26 260 KB 8.0.50727.4053
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 2011/02/26 250 KB 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2014/02/03 2.38 MB 8.0.59193
Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 2011/02/09 840 KB 8.0.61000
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2013/10/01 248 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2011/02/16 784 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 2011/06/20 788 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2011/03/17 234 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2011/02/16 592 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2011/06/20 600 KB 9.0.30729.6161
Mobile Broadband Lenovo 2011/02/09 16.4 MB 3.6.0034
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2011/02/18 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2011/02/18 1.33 MB 4.20.9876.0
MyEPSON Portal SEIKO EPSON Corporation 2014/02/20
PHOTOfunSTUDIO 5.0 HD Edition Panasonic Corporation 2011/02/28 5.00.313
QuickTime Apple Inc. 2012/11/07 73.2 MB 7.72.80.56
Registry Patch to arrange icons in Device and Printers folder of Windows 7 2011/02/09 1.00
Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7 2011/02/09 1.00
Rescue and Recovery Lenovo Group Limited 2013/05/12 101 MB 4.31.0005.00
SAMSUNG USB Driver for Mobile Phones SAMSUNG Electronics Co., Ltd. 2013/08/07 42.9 MB 1.5.16.0
Software Updater SEIKO EPSON CORPORATION 2014/02/16 8.19 MB 4.2.1
SonicStage 4.4 Sony Corporation 2012/02/15 4.4
Sony Media Library Earth 8.1.00 Sony Corporation 2013/03/10 47.3 MB 8.1.00.11292
ThinkPad UltraNav Driver 2014/02/22 46.4 MB 16.2.19.7
ThinkPad Wireless LAN Adapter Software REALTEK Semiconductor Corp. 2011/02/09 1.00.0024.0
ThinkPad 省電力マネージャー 2014/02/20 3.30
ThinkVantage Communications Utility Lenovo 2011/02/09 2.43 MB 1.41
ThinkVantage ハードディスク・アクティブプロテクション・システム Lenovo 2011/02/09 15.6 MB 1.74
USB Video/Audio Device Driver 会社名 2012/07/29 15.4 MB 1.00.0000
Windows Live Essentials Microsoft Corporation 2013/01/15 16.4.3505.0912
Windows ドライバ パッケージ - I-O DATA DEVICE, INC. GV-MVP/FZ(x64) (11/29/2010 1.8.2.12) I-O DATA DEVICE, INC. 2014/02/03 11/29/2010 1.8.2.12
Windows ドライバ パッケージ - Intel (iaStor) hdc (01/15/2010 9.5.7.1002) Intel 2011/02/09 01/15/2010 9.5.7.1002
Windows ドライバ パッケージ - Intel hdc (06/04/2009 7.0.0.1013) Intel 2011/02/09 06/04/2009 7.0.0.1013
Windows ドライバ パッケージ - Intel System (06/04/2009 1.0.0.0002) Intel 2011/02/09 06/04/2009 1.0.0.0002
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/09 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/10 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel USB (08/20/2009 9.1.1.1020) Intel 2011/02/09 08/20/2009 9.1.1.1020
Windows ドライバ パッケージ - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4) Lenovo 2011/02/09 11/18/2009 1.60.0.4
Windows ドライバ パッケージ - Realtek Semiconductor Corp. HD Audio Driver (06/29/2010 6.0.1.6146) Realtek Semiconductor Corp. 2011/02/09 06/29/2010 6.0.1.6146
インテル(R) ターボ・ブースト・テクノロジー・モニター インテル 2011/02/09 1.13 MB 1.0.186.3
ウイルスセキュリティ ソースネクスト株式会社 2014/02/20 12.00
読んde!!ココ パーソナル 2014/02/16

有効 HKCU:Run EPLTarget\P0000000000000000 SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series"
有効 HKCU:Run EPLTarget\P0000000000000001 SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000001" /M "EP-706A Series"
有効 HKLM:Run Adobe ARM Adobe Systems Incorporated "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
有効 HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
有効 HKLM:Run EEventManager SEIKO EPSON CORPORATION "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
有効 HKLM:Run HotKeysCmds Intel Corporation C:\Windows\system32\hkcmd.exe
有効 HKLM:Run iFilter5 "C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5gc.exe" /autorun
有効 HKLM:Run IgfxTray Intel Corporation C:\Windows\system32\igfxtray.exe
有効 HKLM:Run IME14 JPN Setup Microsoft Corporation C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
有効 HKLM:Run K7SystemTray "C:\Program Files (x86)\K7 Computing\Common\K7SysTry.exe"
有効 HKLM:Run K7TSStart K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
有効 HKLM:Run LENOVO.TPKNRRES Lenovo Group Limited C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
有効 HKLM:Run LPStation Sony Corporation C:\Program Files (x86)\Common Files\Sony Shared\AVLib\LPStation\LPStation.exe
有効 HKLM:Run Persistence Intel Corporation C:\Windows\system32\igfxpers.exe
有効 HKLM:Run PWMTRV rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
有効 HKLM:Run QuickTime Task Apple Inc. "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
有効 HKLM:Run TpShocks Lenovo. TpShocks.exe
有効 Startup Common Continue installation.lnk C:\Users\オヤジ\AppData\Local\Temp\Free_files_downloader.exe
有効 Startup Common PHOTOfunSTUDIO 5.0 HD Edition.lnk Panasonic Corporation C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
有効 Startup Common クライアントマネージャV.lnk BUFFALO INC. C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe

有効 Extension Bonjour Apple Inc. C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension このコンテンツを引用 Microsoft Corporation C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
有効 Helper E-Photo SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Photo\EPTBL.dll
有効 Helper E-Web Print SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
有効 Helper ExplorerWnd Helper IObit C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper C:\Program Files\Java\jre6\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre7\bin\ssv.dll
無効 Helper K7 Web Protection K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
無効 Helper Microsoft アカウント サインイン ヘルパー Microsoft Corp. C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
無効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
無効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL
無効 Helper Windows Live ID Sign-in Helper Microsoft Corp. C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 Toolbar E-Photo SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Photo\EPTBL.dll
有効 Toolbar E-Web Print SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll

有効 Extension K7 WebProtection 2.3 譛€蛻昴・繝ヲ繝シ繧カ繝シ C:\Users\オヤジ\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlpfamleaodfgmfnggonbfljhjggbdbe\2.3_0

有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task EPSON EP-706A Series Update {3CCE4E60-A2F7-43A7-90D2-D645490A4004} SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLMJ.EXE /EXE:"{3CCE4E60-A2F7-43A7-90D2-D645490A4004}" /F:"Update"
有効 Task EPSON EP-706A Series Update {4EE7B136-5E16-4979-80E5-BA838D442F80} SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLMJ.EXE /EXE:"{4EE7B136-5E16-4979-80E5-BA838D442F80}" /F:"Update"
有効 Task EPSON EP-706A Series Update {8BD34A37-ADC7-417C-9A46-53B2A5F6AEF8} SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLMJ.EXE /EXE:"{8BD34A37-ADC7-417C-9A46-53B2A5F6AEF8}" /F:"Update"
有効 Task {4A17C693-E678-4A3E-A662-5DA104A7DD3C} Microsoft Corporation C:\Windows\system32\pcalua.exe -a C:\Users\オヤジ\Downloads\HijackThis.exe -d C:\Users\オヤジ\Downloads

  • ryoyoung
  • 2014/03/04 (Tue) 09:05:12
今回の作業が判断の分かれ目です
またレスが遅くなってすみません。
画像も見せてもらいました。現在の状況としてはIEの「お気に入り」で何度削除してもhaoが復活する状態ですね。

ログを見たところ、またおかしなものが見つかったのでこれを処置しましょう。

CC起動して「Windows」タブ内の下記を右クリックから「無効」「エントリの削除」してください。
>有効 Startup Common Continue installation.lnk C:\Users\オヤジ\AppData\Local\Temp\Free_files_downloader.exe
こんなエントリ、少なくとも自分は正常には見えません。処置するに越したことはなさそうです。

これができたらまたIEでお気に入りからhaoを削除してから、一度PCを再起動後、またしばらく様子見した後に状態報告をレスください。

それとここでお伝えしておきます。
最初の投稿から1か月経過してますが、アドウェアばかりとはいえここまで復活を繰り返す異常な挙動を見せる事例は珍しいといえます。

ryoyoungさんが手間を承知でここまで頑張って作業してくれた努力を無にしたくはないので自分もリカバリは避けたいと思いますが、もし【本物の】危険マルウェアが潜伏してそれが他のマルウェアを外部から次々呼び込んでいるとしたら、これ以上時間かけるのは自分としてもまず避けるのが安全と思います。

この結果で何か糸口か変化が見えたらあと一息の作業も試してみますが、まだ再発を繰り返すようならリカバリの判断も視野に入れておいてください
  • 悪代官
  • 2014/03/04 (Tue) 17:47:28
Re: 駆除
悪代官さま。毎度いそがしいところほんとうにありがとうございます。
今指示されたCCでの処置をいたしました。
正直何度か心が折れそうでした。
一番最初にレスしたのですが、ほんとうはリカバリーを考えておりました。
でも忙しい中、無知な私にいろいろ丁寧にサポートいただいた好意を無駄にはしたく無かったからです。
これで少し様子を見まして、また再発するのであれば、遠慮せずリカバリの指示をください。
このパソコンを使いまわしておる家族にも了解はとってあります。

  • ryoyoung
  • 2014/03/04 (Tue) 18:17:39
リカバリーの前に一つだけ
何回もお世話になります。
やっぱり添付した画像のようにhao123が表示されるようになりました。
リカバリーしようと思ってます。
その前に一つだけお尋ねしたいのですが
同じことを聞くようで申し訳ございませんが、今のところ異常はこのhao123の表示だけです。
変な広告や、IEの異常停止もなくなりました。
それでもやはり何度も復活するということはこのままこのパソコンを使用していると、また次々と悪意のあるものを呼び込んでしまうということなのでしょうか?
この点だけお忙しいでしょうがよろしく教えてもらえれば助かります。
  • ryoyoung
  • 2014/03/06 (Thu) 08:36:34
最後にJRTを試してみましょう
レスが遅くなってすみません。

>やっぱり添付した画像のようにhao123が表示されるようになりました。
>リカバリーしようと思ってます。

はい、何度も手間をかけながら片付かなくて申し訳ありません。

>今のところ異常はこのhao123の表示だけです。
>変な広告や、IEの異常停止もなくなりました。
>それでもやはり何度も復活するということはこのままこのパソコンを使用していると、また次々と悪意のあるものを呼び込んでしまうということなのでしょうか?

はい、これまで相談受けた方の中には、haoの検索が使いやすいのでそのまま使うという方もいました。
なのでこれについては各ユーザーさんの判断にお任せすることになりますが、海外の検索エンジンの中には検索でヒットしたページの安全性が十分検証されていないところがあり、これがGoogleやMsn等の大手検索とはもっとも違っているところです。
自分としては日本国内では聞きなれない検索エンジンの使用はお勧めできないというのはこのあたりを考慮したためです。
検索でヒットしたリンク先の安全性を判断できる方なら自己責任で使うのもありでしょう。

今回自分から自分からリカバリも提案した理由は、単なる検索エンジンといってもここまで設定の固定と復活を繰り返す事例は他に見ていないからです。
haoについては多少うざいことはあってもせいぜい数回のレスと作業すれば設定変更と修復もできるのが普通でした。
が、今回は各種セキュリティアプリにHJTやCCを使い、CCを含めた操作で設定確認と変更を実行しても、またこの種の事例で解析にもっとも期待できたOTLでさえも効かない結果でした。

広告やスポンサーサイトへの誘導のためといってもここまで食い込んでいるのは異常です。
もしかしたらhaoを隠れ蓑にして、別の更に巧妙かつ危険なマルウェアの存在があっても不思議ないかもしれません。

それと、日本の大手メーカー製でなくショップブランドやBTOのPCでは、低価格販売の代わりに一部スポンサーのアプリが入っていることもあります。
現在自分が使っている某PCにも、初期状態で海外メーカー関係のトップページがIEのトップに設定され、検索エンジンにもやはり見慣れない検索が入ってました。
メーカーによっては初期設定でhaoを入れているところもあるようなので、PC購入時からこれらが入っていることも今ではおかしくないでしょう。
ですが初期設定で入っていても落ち着いて作業すればそれらの検索も削除可能です。
それができないのはやはり異常な状態と言わざるを得ないのです。

リカバリの意向が固まったなら確かにそれがもっとも安全確実ですが、よければ最後に悪あがきしてみますか?
往生際が悪いのが悪代官ですし。

以下のサイト様の説明をよく読んでください。
http://milksizegene.blog.fc2.com/blog-entry-311.html

説明を見終えたら、その説明に沿って以下のツールを準備してください。
Junkware Removal Tool(JRT)
http://thisisudax.org/downloads/JRT.exe
ファイル直リンです。保存しておいてください。

準備できたら先のサイトの説明に沿って、JRTを実行してください。

これで検出されたものがあればそれを処置後、一度PC再起動後に、ブラウザを起動してしばらく様子見してから、その状態報告とJRTのログをレスください。

このJRTはAC同様にかなり高い処置力を持つツールですが、ACでも効かなかったものにどこまで効くかの自信がなかったので、今回の場合は自分は勧めませんでした。

この作業後にも検出や変化がなければ、リカバリの準備にかかってもらうことになるでしょう
  • 悪代官
  • 2014/03/06 (Thu) 13:04:21
最後の悪あがき
ご苦労さんです。
最後の悪あがき頑張ってみようとしましたが、私が導入しているウイルスセキュリティーZEROで・アクセス拒否「Webサイトの保護」機能によってブロックされました。と表示されましてアクセスできませんでした。
ウイルスセキュリティーZEROの機能を無効にしてアクセスしてもよいのでしょうか?
また、またレスお願いします。

  • ryoyoung
  • 2014/03/06 (Thu) 13:54:12
往生際が悪いと言えば
ダウンロードは、セーフモードとインターネットで行うことで、セキュリティソフトの干渉を受けずにダウンロードできます。
この場合はセキュリティソフトが邪魔していますので、一時的に無効にすべきです。

もっとも、リカバリ以外の別の手段としまして、私が遠隔操作で手を下すと言う手段も残っていますね。
遠隔操作でも良いと言うことでしたら、ご連絡ください。
  • IVNO
  • MAIL
  • 2014/03/06 (Thu) 14:11:16
Re: 駆除
IVNOさん。
ありがとうございます。
JRTの検査ログを添付しますが、この後どうすればいいのでしょうか?

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows 7 Home Premium x64
Ran by オヤジ on 2014/03/06 at 15:26:17.94
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\AboutURLs\\Tabs



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\baidu



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 2014/03/06 at 15:32:29.99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • ryoyoung
  • 2014/03/06 (Thu) 15:42:08
状態報告の後、遠隔作業の判断を
作業と報告、ご苦労様です。

JRTのログを見たところ、まだ隠れていたらしいBaiduのレジストリ残骸が出てますね。
>Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\baidu

これもJRTで処置されてるのでいいですが、作業後にブラウザを起動して、異常は続いてますか?
それで異常が解消していればリカバリは待ってください。

このあとIVNOさんが案内されたように遠隔での解析と処置をご希望ならその旨レスください。
遠隔作業は自分にはできるかどうかの不安があるのも確かですが、うちのネット回線自体がかなり不安定で1時間のうちに何度も切れるだけでなく、ひどい時だと切れたまま2日もつながらなかったこともあるほど回線状態がよくないので、自分では遠隔作業は手が出せないのです。
何度プロバイダ変えても同じだし、NTTの局舎から遠くて伝送損失も多いのが致命的な地区なので、光にでもしない限りあきらめるしかないのが現状です。

IVNOさんなら遠隔作業も含めて自分よりも頼りになるので、ご希望なら頼んで見て損はないでしょう
  • 悪代官
  • 2014/03/06 (Thu) 16:06:51
リカバリーします
ご苦労様です。
haoちゃんやっぱり現れました(こう何度もしつこく出てくるとちゃん付けしたくなります)
やっぱり悪代官さんが前におっしゃったとおり、いくつもの種がまかれ、複雑に入りくんでいるのでしょうね。
それとIVNOさんご厚意ありがとうございます。でも今回は遠隔作業でなくて、リカバリーを選択しようと思います
知恵袋で質問し、このサイトを紹介いただき、初めて掲示板でのやりとりをしました。
悪いプログラムを作る人もいれば、それに感染した人を無償で助けてくれる人もいる。
社会の縮図を見たようなものでした。
一ヶ月以上も長い間、本当にお世話になりました。
インターネットのセキュリティーの大切さを、私を含め、これを使っていた家族にも今回の経験を参考にして伝えたいと思います。
リカバリーの決断をします(人生もリカバリーできたらなあ・・・)
ありがとうございました
  • ryoyoung
  • 2014/03/06 (Thu) 16:53:19
ではデータのバックアップから準備を
作業と報告、ご苦労様です。

最後の悪あがきもかないませんでしたか。
悪代官にとって夜8時45分も過ぎた感がありますね。

では残念ながら、リカバリの準備を進めてください。
必要データのバックアップが済み次第、取扱い説明書に沿ってリカバリです。

リカバリ自体はよほどやり方を間違えない限り1時間もかからず済みます。

リカバリ後のほうが少し手間と時間かかることになります。

まずはWIndowsUpdateですね。
これの各種更新を全部適用するわけで、途中何度か再起動をしながら最新にするまでWUだけで2時間か数時間は見ておいてください。
Win7のSPもしっかり適用です。
それができたらアンチウイルスソフトも最新状態に更新です。
この2つは最優先で更新してください。

更新が全部できて更新するプログラムがなくなった時点で、一度アンチウイルスソフトでフルスキャン(完全スキャン)して、それで何も検出がなければリカバリ後の基本的な自衛準備が整ったことになります。

ここまでできたらHJTとインストール情報のログをそこで取り直して、そのログを返信で見せてください。
この状態で見落としがあったら自衛も十分にならないので、見落としがあったらそれも埋めるための指示をします。

リカバリ作業は時間かかるだけでまったく難しくはないので、ここまできたらあとはのんびり進めていいです
  • 悪代官
  • 2014/03/06 (Thu) 17:59:51
複雑なユーザーアカウント作成が原因
こんにちは。
おそらくですが、複雑なユーザーアカウントによるドコで感染
したのか判らなくて「復活」しているケースでしょう。

リカバリー後は、なるべく複雑な環境にならない形が良いのかも
しれません。
今、現在IBMのパソコンを利用しているのならば、安くネット用で
1台 3万円位のノートパソコンを与えるのも一つの手段です。
実質、安く購入している方を知っていますので根気よく探すと見つかる
そうです。(しかも業務用中々良いパソコン)

とりあえず、家族に伝えておいたほうが良い内容としては、
良くホームページの中に宣伝しているフリーソフトがあるけれど、
そういうのは、確実とは言えないけど危ないものも多いです。

多分、急いでいたりするとそういう所からダウンロードとかして
いると知らない間に入り込んでいる事があるかもしれません。
確定とは言えないけど危険性が増しているのでご注意を。
(画像参照)
  • 三毛猫
  • 2014/03/06 (Thu) 19:26:25
ユーザー名でまたひとつ案内です
三毛猫さん、レスありがとうございます。
ユーザーアカウントのことで自分も思い出したことがあります。

ryoyoungさん、今後はPCのユーザー名を設定するときは2バイト文字(漢字、ひらがな、カタカナ等)は避けて設定してください。

2バイト文字でユーザー名登録すると、ここで使ったような各種解析ツールのログが文字化けすることがあるのですが、それだけでなく普通のアプリでも正常に動作しない不具合も起きるのです。
これはWindowsの仕様によるものなので今のところユーザー側では回避できません。

たとえばアルファベットでも「AKUDAIKAN」では2バイト文字になりますが、「AKUDAIKAN」なら1バイト文字ですからバグも出ません。
これも今後のPC安定使用のために覚えておくといいです
  • 悪代官
  • 2014/03/06 (Thu) 20:02:13
Re: 駆除
悪代官様始めみなさんアドバイスありがとうございました。
リカバリー後、HJTとインストール情報のログを取り直して添付しますのでまたその時はよろしくお願いします。
  • ryoyoung
  • 2014/03/06 (Thu) 20:24:10
誰もこのことに触れておりませんので
念のために、リカバリを行い、すべてのドライバやアップデートを適用させた段階で、
すべてのアカウントに対しシステムの復元ポイントを手動で作成されることをおすすめいたします。

スタートボタンからコンピュータを右クリックし、プロパティを開きます。
システム情報が表示されますので、システムの保護をクリックします。
下部に作成ボタンがありますので、分かりやすい名前をつけて復元ポイントを作成してください。
復元ポイントの利用はPCへのダメージが大きいため、あまり利用したくはない手段ではありますが、
万一のために保険をかけておくことは、やっておいて損のない行為です。
  • IVNO
  • MAIL
  • 2014/03/07 (Fri) 12:31:39
Re: 駆除
三毛猫さん、IVNOさんありがとうございます。
ただいまリカバリー中で別のパソコンから投稿しています。
三毛猫さんのいうとおり
>複雑なユーザーアカウントによるドコで感染したのか判らなくて「復活」しているケースでしょう
そのためこんなに手間をかけたのだと思います。
そしてそれを監督出来ずに野放しした私が一番の原因でしょう。
リカバリー後はみなさんの指示通り対応していきたいと思います
  • ryoyoung
  • 2014/03/07 (Fri) 15:12:00
Re: 駆除
またお世話になります。
リカバリーしました。
一応、指示されたことは一通りやったつもりですが、私のことですから見落としているかもしれません。
生まれ変わった姿をご覧ください。

ログを添付します(問題がありませんように・・・)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:00:33, on 2014/03/08
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16533)
Boot mode: Normal

Running processes:
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SysMon.Exe
C:\Users\yunbo\AppData\Local\SOURCENEXT\SSS3\3.08.01\Statistics.exe
C:\Users\yunbo\AppData\Local\SOURCENEXT\SSS3\3.08.01\Message.exe
C:\Program Files (x86)\Microsoft\BingDesktop\BDExtHost.exe
C:\Program Files (x86)\Microsoft\BingDesktop\BDAppHost.exe
C:\Program Files (x86)\Microsoft\BingDesktop\BDRuntimeHost.exe
C:\Windows\SysWOW64\jusched.exe
C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe
C:\Users\yunbo\Downloads\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: K7 Web Protection - {08B3B4B6-02DA-4658-8BA6-5974E3EBB03D} - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
O2 - BHO: Windows Live ID サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
O4 - HKLM\..\Run: [Sourcenext.SSS.Launcher] "C:\Program Files (x86)\SOURCENEXT\ソースネクスト アップデート3\Launcher.exe" UpdateTool.exe
O4 - HKLM\..\Run: [K7TSStart] C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Global Startup: クライアントマネージャV.lnk = C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: BWH32S - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\clientmgrv\bin\BWH32S.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: K7Carnivore Service (K7CrvSvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7CrvSvc.exe
O23 - Service: K7Computng - EMail Proxy Server (K7EmlPxy) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7EmlPxy.exe
O23 - Service: K7Firewall Services (K7FWSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7FWSrvc.exe
O23 - Service: K7Privacy Services (K7PSSrvc) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7PSSrvc.exe
O23 - Service: K7RealTime AntiVirus Services (K7RTScan) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7RTScan.exe
O23 - Service: K7SpmSrc - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SpmSrc.exe
O23 - Service: K7TotalSecurity Manager (K7TSMngr) - K7 Computing Pvt Ltd - C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSMngr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: オン スクリーン表示 (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9371 bytes

Access Help Lenovo 2011/02/09 3.00
Bing Bar Microsoft Corporation 2014/03/07 464 KB 7.1.361.0
Bing デスクトップ Microsoft Corporation 2014/03/07 16.0 MB 1.3.347.0
BUFFALO エアステーション設定ガイド 2014/03/07
BUFFALO エアステーション設定ツール BUFFALO INC. 2014/03/07 2.0.0
BUFFALO クライアントマネージャV 2014/03/07
BUFFALO パソコン環境表示ツール BUFFALO INC. 2014/03/07 1.0.2
CCleaner Piriform 2014/03/08 4.11
Corel Burn.Now Lenovo Edition Corel Corporation 2011/02/09 81.0 MB 4.5.0
Corel DVD MovieWriter Lenovo Edition Corel Corporation 2011/02/09 320 MB 7.0.0
Create Recovery Media Lenovo Group Limited 2011/02/09 9.50 MB 1.20.0.00
Intel(R) Control Center Intel Corporation 2014/03/07 1.2.1.1007
Intel(R) Graphics Media Accelerator Driver Intel Corporation 2014/03/08 8.15.10.2125
Intel(R) Management Engine Components Intel Corporation 2014/03/08 6.0.0.1179
InterVideo WinDVD 8 InterVideo Inc. 2011/02/09 163 MB 8.0.20.199
Java(TM) 6 Update 17 Sun Microsystems, Inc. 2011/02/09 97.6 MB 6.0.170
Java(TM) 6 Update 17 (64-bit) Sun Microsystems, Inc. 2011/02/09 90.8 MB 6.0.170
Lenovo Auto Scroll Utility 2011/02/09 1.00
Lenovo Power Management Driver 2014/03/07 1.67.04.05
Lenovo System Interface Driver 2011/02/09 1.02
Lenovo ThinkVantage Toolbox PC-Doctor, Inc. 2011/02/09 6.0.5717.21
Lenovo Warranty Information Lenovo 2011/02/09 893 KB 1.0.0004.00
Lenovo Welcome Lenovo 2011/02/09
Message Center Plus Lenovo Group Limited 2011/02/09 1.70 MB 2.0.0012.00
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 2014/03/07 38.8 MB 4.0.30319
Microsoft .NET Framework 4 Client Profile Language Pack - 日本語 Microsoft Corporation 2014/03/07 2.93 MB 4.0.30319
Microsoft Silverlight Microsoft Corporation 2014/03/07 50.6 MB 5.1.20913.0
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2011/02/09 1.69 MB 3.1.0000
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2014/03/07 300 KB 8.0.61001
Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 2011/02/09 840 KB 8.0.61000
Mobile Broadband Lenovo 2011/02/09 16.4 MB 3.6.0034
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2014/03/07 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2014/03/07 1.33 MB 4.20.9876.0
Realtek Ethernet Controller Driver For Windows Vista and Later Realtek 2011/02/09 1.00.0010
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2011/02/09 6.0.1.6146
Realtek USB 2.0 Card Reader Realtek Semiconductor Corp. 2011/02/09 6.1.7600.30113
Registry Patch to arrange icons in Device and Printers folder of Windows 7 2011/02/09 1.00
Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7 2011/02/09 1.00
System Update Lenovo 2011/02/09 11.5 MB 4.00.0032
ThinkPad UltraNav Driver 2014/03/07 46.4 MB 16.2.19.7
ThinkPad Wireless LAN Adapter Software REALTEK Semiconductor Corp. 2011/02/09 1.00.0024.0
ThinkPad 省電力マネージャー 2011/02/09 3.30
ThinkVantage Communications Utility Lenovo 2011/02/09 2.43 MB 1.41
ThinkVantage System Update 2014/03/07
ThinkVantage ハードディスク・アクティブプロテクション・システム Lenovo 2011/02/09 15.6 MB 1.74
Windows Live Essentials Microsoft Corporation 2011/02/09 15.4.3502.0922
Windows ドライバ パッケージ - Intel (iaStor) hdc (01/15/2010 9.5.7.1002) Intel 2011/02/09 01/15/2010 9.5.7.1002
Windows ドライバ パッケージ - Intel hdc (06/04/2009 7.0.0.1013) Intel 2011/02/09 06/04/2009 7.0.0.1013
Windows ドライバ パッケージ - Intel System (06/04/2009 1.0.0.0002) Intel 2011/02/09 06/04/2009 1.0.0.0002
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2011/02/09 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel System (10/28/2009 9.1.1.1022) Intel 2014/03/08 10/28/2009 9.1.1.1022
Windows ドライバ パッケージ - Intel USB (08/20/2009 9.1.1.1020) Intel 2011/02/09 08/20/2009 9.1.1.1020
Windows ドライバ パッケージ - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4) Lenovo 2011/02/09 11/18/2009 1.60.0.4
Windows ドライバ パッケージ - Realtek Semiconductor Corp. HD Audio Driver (06/29/2010 6.0.1.6146) Realtek Semiconductor Corp. 2011/02/09 06/29/2010 6.0.1.6146
インテル(R) ターボ・ブースト・テクノロジー・モニター インテル 2011/02/09 1.13 MB 1.0.186.3
ウイルスセキュリティ ソースネクスト株式会社 2014/03/08 12.00
オン スクリーン表示 2011/02/09 6.10.00
ソースネクスト アップデート 3.0 SOURCENEXT 2014/03/08 10.0 MB 8.00.0000
リモート接続用の Windows Live Mesh ActiveX コントロール (日本語) Microsoft Corporation 2011/02/09 5.57 MB 15.4.5722.2
  • ryoyoung
  • 2014/03/08 (Sat) 15:14:14
さすがにきれいになりましたね
作業と報告、ご苦労様です。
リカバリ後ということでかなりログもきれいになってますね。
では以下の説明を読んでから、また作業をお願いします。

>MSIE: Internet Explorer v9.00 (9.00.8112.16533)
IE最新版の11への更新がまだできてないようですね。これを含めてWindowsの各種更新はしっかりと。

また、以下も使うなら最新版に更新してください。
>Java(TM) 6 Update 17 Sun Microsystems, Inc. 2011/02/09 97.6 MB 6.0.170
>Java(TM) 6 Update 17 (64-bit) Sun Microsystems, Inc. 2011/02/09 90.8 MB 6.0.170
使わないならアンインストールが安全です。
これらの更新不備による脆弱性は感染の重要な要因になります。

これができたら、またしばらくPC状態を様子見の後、CCで「Windows」以下の各タブのログをまたとって、それを状態報告とともにレスください。

この様子見の時点で再発などもなくなってれば、あとはログ次第で峠は越えられるはずです
  • 悪代官
  • 2014/03/08 (Sat) 17:31:07
Re: 駆除
リカバリー後まで面倒見ていただきありがとうございます。
javaは削除しました。
今のところ私にストーカーしていたhao123は姿をあらわしていませんし、パソコンも異常なく動作しております。
ログを添付します(また隠れていたりして?・・)

有効 HKCU:Run EPLTarget\P0000000000000000 SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILMJ.EXE /EPT "EPLTarget\P0000000000000000" /M "EP-706A Series"
有効 HKLM:Run BingDesktop Microsoft Corp. C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
有効 HKLM:Run EEventManager SEIKO EPSON CORPORATION "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
有効 HKLM:Run HotKeysCmds Intel Corporation C:\Windows\system32\hkcmd.exe
有効 HKLM:Run IgfxTray Intel Corporation C:\Windows\system32\igfxtray.exe
有効 HKLM:Run IME14 JPN Setup Microsoft Corporation C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
有効 HKLM:Run iTunesHelper Apple Inc. "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
有効 HKLM:Run K7TSStart K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity.exe
有効 HKLM:Run LENOVO.TPKNRRES Lenovo Group Limited C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
有効 HKLM:Run Persistence Intel Corporation C:\Windows\system32\igfxpers.exe
有効 HKLM:Run PWMTRV rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
有効 HKLM:Run RtHDVCpl Realtek Semiconductor C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
有効 HKLM:Run Sourcenext.SSS.Launcher SOURCENEXT CORPORATION "C:\Program Files (x86)\SOURCENEXT\ソースネクスト アップデート3\Launcher.exe" UpdateTool.exe
有効 HKLM:Run TPHOTKEY Lenovo Group Limited C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
有効 HKLM:Run TpShocks Lenovo. TpShocks.exe
有効 Startup Common クライアントマネージャV.lnk BUFFALO INC. C:\Program Files (x86)\BUFFALO\clientmgrv\bin\cmvMain.exe
有効 Startup User OneNote 2010 画面の領域の取り込みと起動.lnk Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE

有効 Extension OneNote に送る Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension このコンテンツを引用 Microsoft Corporation C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
有効 Helper Bing Bar Helper Microsoft Corporation. C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll
有効 Helper E-Photo SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Photo\EPTBL.dll
有効 Helper E-Web Print SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper Sun Microsystems, Inc. C:\Program Files\Java\jre6\bin\jp2ssv.dll
有効 Helper K7 Web Protection K7 Computing Pvt Ltd C:\Program Files (x86)\K7 Computing\K7TSecurity\K7SRExt.dll
有効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
有効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
有効 Helper Windows Live ID Sign-in Helper Microsoft Corp. C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 Helper Windows Live ID サインイン ヘルパー Microsoft Corp. C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 Toolbar Bing Bar Microsoft Corporation. "C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll"
有効 Toolbar E-Photo SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Photo\EPTBL.dll
有効 Toolbar E-Web Print SEIKO EPSON CORPORATION C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll

有効 Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task MCP Lenovo Information Products (Shenzhen) Co.,Ltd "C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe" /start
有効 Task PCDEventLauncher PC-Doctor, Inc. "C:\Program Files\PC-Doctor\sessionchecker.exe"
有効 Task PCDoctorBackgroundMonitorTask PC-Doctor, Inc. C:\Program Files\PC-Doctor\uaclauncher.exe -backgroundmon scripts\backgroundmon.xml -st PCDoctorBackgroundMonitorTask --ignoresecondarysplash --runsilently
有効 Task PMTask Lenovo Group Limited C:\PROGRA~2\ThinkPad\UTILIT~1\PwmIdTsv.exe
有効 Task SidebarExecute Microsoft Corporation C:\Program Files\Windows Sidebar\sidebar.exe /addGadget
有効 Task Synaptics TouchPad Enhancements Synaptics Incorporated \Program Files\Synaptics\SynTP\SynTPEnh.exe
有効 Task SystemToolsDailyTest PC-Doctor, Inc. C:\Program Files\PC-Doctor\pcdrcui.exe -silentenumeration -st SystemToolsDailyTest
有効 Task {8E9DE279-7ABC-482E-A431-FFAC86286016} Microsoft Corporation C:\Windows\system32\pcalua.exe -a C:\Users\yunbo\Downloads\HijackThis.exe -d C:\Users\yunbo\Downloads

  • ryoyoung
  • 2014/03/10 (Mon) 15:09:57
今度は「解決」でいいでしょう
またレスが遅くなってすみません。

>今のところ私にストーカーしていたhao123は姿をあらわしていませんし、パソコンも異常なく動作しております

はい、さすがに今度はhaoも掃除できたようですね。
ではちょっと追加の作業をお願いします。

CCを起動して「IE」タブ内の下記を右クリックから「無効」「エントリの削除」してください。
>有効 Helper Java(tm) Plug-In 2 SSV Helper C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
>有効 Helper Java(tm) Plug-In 2 SSV Helper Sun Microsystems, Inc. C:\Program Files\Java\jre6\bin\jp2ssv.dll
見てのとおりこれはJavaの残骸です。本体はアンインストールしたので不要でしょうから処置します。

これができたら掃除と、リカバリ後の基本設定はできたはずです。
あとは作業ツールを準備時の説明に沿って片づけたら、以後の自衛も整えながら「解決」でしょう。

今回はhaoを含めて、単なる広告や不審画面での異常だけとは思えないほど異常な動きを見せました。
ユーザーアカウントの設定もあるかもしれませんが、この種の曲者プログラムによるトラブルは日ごとに対策逃れの改変も多いため、それまでに通用していた対処がいきなり効かなくなることも平気であります。
広告料のためとはいえ、ここまでユーザーのPCに食い込んで削除を阻害するような性質になったとしたらもうアドウェアの範疇を超えているかもしれないので、そろそろ大手各社のセキュリティソフトでも削除はできないとしても何らかの歯止めは検討してほしいところです。

リカバリ後でも以後の自衛を怠ると、更に危険な感染もありえます。
まずは怪しいサイトやよくわからないリンクを安易にクリックしないだけでもかなりの自衛効果は得られるので、そこから先はわかる範囲から少しずつでもPC環境と自衛意識を固めて行ってください。

結局リカバリでの対処になってしまって本当にすみませんでした。
それでもPC自体はきれいな初期状態になったので、以後はそのクリーンな状態をできるだけ維持していってください。

お疲れ様でした。
以後は安全で快適なPCライフをどうぞ
  • 悪代官
  • 2014/03/10 (Mon) 17:33:26
ありがとうございました
こちらこそ、長い間いろいろお手を煩わせて申し訳ごさいませんでした。
お忙しいのに手間ひま惜しまず何度も教えていただき、貴重な体験をさせてもらいました。
このサイトに出会えたことは本当にうれしく思います。
悪代官様はじめ、皆さんのご健勝、ご健康をお祈りします(本物のウイルスに気をつけて!)。
ありがとうございました。
  • ryoyoung
  • 2014/03/10 (Mon) 18:07:37

返信フォーム






プレビュー (投稿前に内容を確認)