OTLログ2(53,000字)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:[b]64bit:[/b] - DPF: {0E15796F-7B3A-4FB3-BF69-7B11D20A4A62}
https://azby.fmworld.net/register/entrance/UserReg.CAB (AzbyClub ユーザー登録用 コントロール)
O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7}
http://sample3.dmm.co.jp/downloader6/DMMDownloader.cab (DMM Downloader)
O16 - DPF: {0E15796F-7B3A-4FB3-BF69-7B11D20A4A62}
https://azby.fmworld.net/register/entrance/UserReg.CAB (AzbyClub ユーザー登録用 コントロール)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.128.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C7E34A04-8911-4175-8EE8-2287095885DF}: DhcpNameServer = 14.193.100.8 14.193.100.40
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DB6A45FD-39E9-4796-86C0-A0F7EFF18C69}: DhcpNameServer = 192.168.128.1
O18:[b]64bit:[/b] - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\osf - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Windows\SysWOW64\skype4com.dll (Skype Technologies)
O18:[b]64bit:[/b] - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\SysNative\igfxdev.dll (Intel Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2014/12/09 08:40:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\マカフィー
[2014/12/08 23:49:04 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\PC-User\Desktop\OTL.exe
[2014/12/08 23:48:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\herdProtect
[2014/12/08 23:48:09 | 000,000,000 | ---D | C] -- C:\Program Files\Reason
[2014/12/08 09:38:38 | 000,129,752 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2014/12/07 19:48:56 | 000,000,000 | ---D | C] -- C:\Users\PC-User\AppData\Local\Apple
[2014/12/07 19:48:33 | 000,000,000 | ---D | C] -- C:\Users\PC-User\AppData\Local\Apple Computer
[2014/12/07 15:01:19 | 000,000,000 | ---D | C] -- C:\Users\PC-User\AppData\Roaming\Malwarebytes
[2014/12/07 15:00:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2014/12/07 15:00:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2014/12/07 14:53:17 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\PC-User\Desktop\mbam-setup-1.75.0.1300.exe
[2014/12/06 23:56:24 | 000,000,000 | ---D | C] -- C:\Users\PC-User\AppData\Local\Adobe
[2014/12/06 23:33:27 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Users\PC-User\Desktop\ATF-Cleaner.exe
[2014/12/06 22:38:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2014/12/06 20:54:48 | 000,000,000 | ---D | C] -- C:\Users\PC-User\AppData\Roaming\Oracle
[2014/12/06 20:50:39 | 000,000,000 | ---D | C] -- C:\Users\PC-User\AppData\Roaming\ProductData
[2014/12/06 20:50:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller
[2014/12/06 20:49:38 | 000,000,000 | ---D | C] -- C:\Users\PC-User\Desktop\iobituninstaller-4-1-5-30
[2014/12/05 07:28:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BurnAware Free
[2014/12/05 07:28:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BurnAware Free
[2014/12/05 07:12:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\cdm
[2014/12/05 07:12:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CD Manipulator
[2014/12/05 05:31:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2014/12/05 05:31:17 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2014/11/28 19:32:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2014/11/28 06:32:41 | 000,000,000 | ---D | C] -- C:\Users\PC-User\Desktop\学科予算27
[2014/11/27 19:04:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\tasks\ImCleanDisabled
[2014/11/24 06:01:53 | 000,000,000 | ---D | C] -- C:\Users\PC-User\AppData\Local\Kinokuniya
[2014/11/23 17:10:49 | 000,000,000 | ---D | C] -- C:\ProgramData\LizardSales
[2014/11/23 04:55:09 | 000,000,000 | ---D | C] -- C:\Users\PC-User\Desktop\TDS_NewYear2014_Mickey用資料
[2014/11/22 17:11:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Moneydown
[2014/11/22 05:23:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/11/22 05:23:42 | 000,093,400 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbamchameleon.sys
[2014/11/22 05:23:41 | 000,064,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2014/11/22 05:23:41 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2014/11/22 05:23:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014/11/22 05:23:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/11/20 09:02:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2014/11/20 09:02:05 | 000,272,808 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaws.exe
[2014/11/20 09:01:57 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaw.exe
[2014/11/20 09:01:57 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\java.exe
[2014/11/20 09:01:57 | 000,098,216 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
[2014/11/20 09:01:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014/11/20 09:01:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2014/11/20 08:13:57 | 000,000,000 | -HSD | C] -- C:\Users\PC-User\AppData\Local\EmieBrowserModeList
[2014/11/20 07:40:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
[2014/11/14 20:24:55 | 000,714,208 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2014/11/14 20:24:55 | 000,106,976 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2014/11/12 22:12:57 | 000,500,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll
[2014/11/12 22:12:57 | 000,394,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AUDIOKSE.dll
[2014/11/12 22:12:57 | 000,344,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AUDIOKSE.dll
[2014/11/12 22:12:56 | 000,482,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll
[2014/11/12 22:12:56 | 000,272,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\audiodg.exe
[2014/11/12 22:12:56 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll
[2014/11/12 22:12:56 | 000,108,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EncDump.dll
[2014/11/12 22:12:52 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dpapisrv.dll
[2014/11/12 22:12:51 | 000,104,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptsslp.dll
[2014/11/12 22:12:51 | 000,088,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptsslp.dll
[2014/11/12 22:11:57 | 003,547,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2014/11/12 22:11:56 | 001,441,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2014/11/12 22:11:55 | 000,445,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certcli.dll
[2014/11/12 22:11:55 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certcli.dll
[2014/11/12 22:11:54 | 000,736,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\adtschema.dll
[2014/11/12 22:11:54 | 000,736,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adtschema.dll
[2014/11/12 22:11:53 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rfxvmt.dll
[2014/11/12 22:11:53 | 000,027,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys
[2014/11/12 22:11:52 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msaudite.dll
[2014/11/12 22:11:52 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msaudite.dll
[2014/11/12 22:11:51 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2014/11/12 22:09:56 | 000,789,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\oleaut32.dll
[2014/11/12 22:09:53 | 003,320,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2014/11/12 22:09:53 | 002,773,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2014/11/12 22:09:52 | 002,459,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2014/11/12 22:09:51 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msihnd.dll
[2014/11/12 22:09:50 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msihnd.dll
[2014/11/12 22:09:50 | 000,116,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\consent.exe
[2014/11/12 22:09:39 | 000,894,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2014/11/12 22:09:38 | 001,714,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2014/11/12 22:09:38 | 000,723,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2014/11/12 22:09:37 | 000,407,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2014/11/12 22:09:37 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
[2014/11/12 22:09:37 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
[2014/11/12 22:09:37 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
[2014/11/12 22:09:37 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
[2014/11/12 22:09:37 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll
[2014/11/12 22:09:36 | 000,055,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2014/11/12 22:09:36 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll
[2014/11/12 22:09:36 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
[2014/11/12 22:09:36 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
[2014/11/12 22:09:36 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wups.dll
[2014/11/12 22:09:36 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuaext.dll
[2014/11/12 22:07:56 | 001,519,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\user32.dll
[2014/11/12 22:07:54 | 000,258,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdFilter.sys
[2014/11/12 22:07:53 | 000,114,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdNisDrv.sys
[2014/11/12 22:07:52 | 000,035,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdBoot.sys
[2014/11/12 22:07:49 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winshfhc.dll
[2014/11/12 22:07:49 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winshfhc.dll
[2014/11/12 22:04:11 | 006,040,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2014/11/12 22:04:03 | 002,865,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2014/11/12 22:04:02 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll
[2014/11/12 22:04:02 | 000,812,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2014/11/12 22:04:02 | 000,661,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2014/11/12 22:04:01 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2014/11/12 22:04:01 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieui.dll
[2014/11/12 22:04:00 | 002,051,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2014/11/12 22:04:00 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript9diag.dll
[2014/11/12 22:04:00 | 000,580,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2014/11/12 22:04:00 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieui.dll
[2014/11/12 22:03:59 | 002,124,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2014/11/12 22:03:59 | 000,799,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2014/11/12 22:03:59 | 000,708,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2014/11/12 22:03:59 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtmsft.dll
[2014/11/12 22:03:59 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2014/11/12 22:03:58 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwproxystub.dll
[2014/11/12 22:03:54 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2014/11/12 22:03:54 | 000,340,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\html.iec
[2014/11/12 22:03:54 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msrating.dll
[2014/11/12 22:03:54 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msrating.dll
[2014/11/12 22:03:54 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2014/11/12 22:03:54 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieUnatt.exe
[2014/11/12 22:03:54 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieUnatt.exe
[2014/11/12 22:03:54 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollector.exe
[2014/11/12 22:03:54 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesysprep.dll
[2014/11/12 22:03:54 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hlink.dll
[2014/11/12 22:03:54 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesysprep.dll
[2014/11/12 22:03:53 | 000,417,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\html.iec
[2014/11/12 22:03:53 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iexpress.exe
[2014/11/12 22:03:53 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\occache.dll
[2014/11/12 22:03:53 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2014/11/12 22:03:53 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\IEAdvpack.dll
[2014/11/12 22:03:53 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inseng.dll
[2014/11/12 22:03:53 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2014/11/12 22:03:53 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inseng.dll
[2014/11/12 22:03:53 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2014/11/12 22:03:53 | 000,087,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdc.ocx
[2014/11/12 22:03:53 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\JavaScriptCollectionAgent.dll
[2014/11/12 22:03:53 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2014/11/12 22:03:53 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdc.ocx
[2014/11/12 22:03:53 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\JavaScriptCollectionAgent.dll
[2014/11/12 22:03:52 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\occache.dll
[2014/11/12 22:03:52 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pngfilt.dll
[2014/11/12 22:03:52 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2014/11/12 22:03:52 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imgutil.dll
[2014/11/12 22:03:52 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieetwproxystub.dll
[2014/11/12 22:03:52 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\licmgr10.dll
[2014/11/12 22:03:52 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\licmgr10.dll
[2014/11/12 22:03:51 | 000,237,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\url.dll
[2014/11/12 22:03:51 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\url.dll
[2014/11/12 22:03:51 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wextract.exe
[2014/11/12 22:03:51 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\IEAdvpack.dll
[2014/11/12 22:03:51 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesetup.dll
[2014/11/12 22:03:51 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\pngfilt.dll
[2014/11/12 22:03:51 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iernonce.dll
[2014/11/12 22:03:51 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iernonce.dll
[2014/11/12 22:03:50 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iexpress.exe
[2014/11/12 22:03:50 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wextract.exe
[2014/11/12 22:03:50 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesetup.dll
[2014/11/12 22:03:50 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshta.exe
[2014/11/12 22:03:50 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeedssync.exe
[2014/11/12 22:03:50 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msfeedssync.exe
[2014/11/12 22:02:53 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2014/11/12 22:02:53 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2014/11/12 22:02:52 | 000,537,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2014/11/12 22:02:52 | 000,304,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2014/11/12 22:02:51 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepic.dll
[2014/11/12 22:02:49 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\packager.dll
[2014/11/12 22:02:49 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\packager.dll
[2014/11/12 22:01:43 | 007,484,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2014/11/12 22:01:40 | 002,714,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers.dll
[2014/11/12 22:01:39 | 013,424,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2014/11/12 22:01:30 | 001,053,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\localspl.dll
[2014/11/12 22:01:30 | 000,941,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFMediaEngine.dll
[2014/11/12 22:01:26 | 000,836,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmp4srcsnk.dll
[2014/11/12 22:01:20 | 011,820,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2014/11/12 22:01:19 | 000,799,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFMediaEngine.dll
[2014/11/12 22:01:19 | 000,670,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
[2014/11/12 22:01:18 | 000,822,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32spl.dll
[2014/11/12 22:01:16 | 000,474,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\netio.sys
[2014/11/12 22:01:15 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiobj.dll
[2014/11/12 22:01:15 | 000,334,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiobj.dll
[2014/11/12 22:01:12 | 000,545,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\untfs.dll
[2014/11/12 22:01:12 | 000,428,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\FWPKCLNT.SYS
[2014/11/12 22:01:11 | 000,485,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\untfs.dll
[2014/11/12 22:01:10 | 000,615,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FXSCOMEX.dll
[2014/11/12 22:01:07 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FXSAPI.dll
[2014/11/12 22:01:06 | 000,239,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\FXSAPI.dll
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2014/12/09 08:34:45 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/12/09 08:32:40 | 3315,400,704 | -HS- | M] () -- C:\hiberfil.sys
[2014/12/09 08:32:40 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2014/12/09 07:52:39 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2014/12/09 03:52:45 | 000,000,739 | ---- | M] () -- C:\WINDOWS\SysWow64\bscs.ini
[2014/12/09 03:49:32 | 000,004,799 | ---- | M] () -- C:\WINDOWS\SysWow64\LOCALSERVICE.INI
[2014/12/09 03:49:29 | 000,000,043 | ---- | M] () -- C:\WINDOWS\SysWow64\LOCALDEVICE.INI
[2014/12/08 23:49:04 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\PC-User\Desktop\OTL.exe
[2014/12/08 23:48:10 | 000,001,133 | ---- | M] () -- C:\Users\Public\Desktop\herdProtect.lnk
[2014/12/08 23:13:45 | 000,083,311 | ---- | M] () -- C:\Users\PC-User\Desktop\Dsc_1045a.jpg
[2014/12/08 22:37:15 | 000,029,561 | ---- | M] () -- C:\Users\PC-User\Desktop\Dsc_1043.jpg
[2014/12/08 22:36:53 | 000,036,783 | ---- | M] () -- C:\Users\PC-User\Desktop\Dsc_1048.jpg
[2014/12/08 22:36:10 | 000,344,526 | ---- | M] () -- C:\Users\PC-User\Desktop\DSC_1045.JPG
[2014/12/08 22:35:23 | 000,043,481 | ---- | M] () -- C:\Users\PC-User\Desktop\IMG_1996.jpg
[2014/12/08 22:34:56 | 000,051,098 | ---- | M] () -- C:\Users\PC-User\Desktop\Dsc_0265.jpg
[2014/12/08 22:34:23 | 000,014,299 | ---- | M] () -- C:\Users\PC-User\Desktop\imae.jpeg
[2014/12/08 22:34:00 | 000,014,001 | ---- | M] () -- C:\Users\PC-User\Desktop\mage.jpeg
[2014/12/08 22:19:20 | 000,030,717 | ---- | M] () -- C:\Users\PC-User\Desktop\image.jpeg
[2014/12/08 22:18:24 | 000,067,219 | ---- | M] () -- C:\Users\PC-User\Desktop\IMG_7864.jpg
[2014/12/08 21:09:09 | 000,016,695 | ---- | M] () -- C:\Users\PC-User\Documents\mcafee.jpg
[2014/12/07 15:00:15 | 000,001,121 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/12/07 14:53:17 | 010,285,040 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\PC-User\Desktop\mbam-setup-1.75.0.1300.exe
[2014/12/07 14:24:11 | 000,058,822 | ---- | M] () -- C:\Users\PC-User\Desktop\pspbrwse.jbf
[2014/12/07 14:22:07 | 001,214,727 | ---- | M] () -- C:\Users\PC-User\Desktop\IMG_4041.JPG
[2014/12/07 12:52:11 | 000,087,596 | ---- | M] () -- C:\Users\PC-User\Desktop\1417673663705.jpg
[2014/12/07 12:51:41 | 000,091,837 | ---- | M] () -- C:\Users\PC-User\Desktop\SubstandardFullSizeRender.jpg
[2014/12/06 23:33:27 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Users\PC-User\Desktop\ATF-Cleaner.exe
[2014/12/06 23:09:35 | 000,000,296 | ---- | M] () -- C:\WINDOWS\tasks\Uninstaller_SkipUac_PC-User.job
[2014/12/06 20:50:24 | 000,001,244 | ---- | M] () -- C:\Users\Public\Desktop\IObit Uninstaller.lnk
[2014/12/06 20:13:43 | 000,000,222 | ---- | M] () -- C:\Users\PC-User\AppData\Roaming\burnaware.ini
[2014/12/05 07:35:32 | 000,000,952 | -HS- | M] () -- C:\ProgramData\KGyGaAvL.sys
[2014/12/05 07:28:13 | 000,001,066 | ---- | M] () -- C:\Users\Public\Desktop\BurnAware Free.lnk
[2014/12/05 07:12:34 | 000,000,949 | ---- | M] () -- C:\Users\PC-User\Desktop\CD Manipulator.lnk
[2014/12/05 06:56:58 | 003,405,946 | ---- | M] () -- C:\Users\PC-User\Desktop\seahawks.wav
[2014/12/05 06:47:52 | 000,292,333 | ---- | M] () -- C:\Users\PC-User\Desktop\seahawks.wma
[2014/12/05 05:50:17 | 000,000,834 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/12/04 09:53:58 | 000,185,344 | ---- | M] () -- C:\Users\PC-User\Desktop\請求書・領収書.jtd
[2014/12/03 22:39:04 | 000,191,255 | ---- | M] () -- C:\Users\PC-User\Desktop\IMG_1725.jpg
[2014/12/02 05:37:35 | 000,240,026 | ---- | M] () -- C:\Users\PC-User\Documents\kawaii.jpg
[2014/12/02 05:04:20 | 000,031,567 | ---- | M] () -- C:\Users\PC-User\Desktop\1417415477212.jpg
[2014/12/02 03:12:53 | 000,049,326 | ---- | M] () -- C:\Users\PC-User\Desktop\IMG_5791.jpg
[2014/11/29 05:59:38 | 000,114,295 | ---- | M] () -- C:\Users\PC-User\Documents\dame.jpg
[2014/11/29 05:57:12 | 000,727,980 | ---- | M] () -- C:\Users\PC-User\Desktop\日本伝統.pdf
[2014/11/29 02:31:20 | 001,496,524 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2014/11/29 02:31:20 | 000,722,476 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2014/11/29 02:31:20 | 000,500,892 | ---- | M] () -- C:\WINDOWS\SysNative\perfh011.dat
[2014/11/29 02:31:20 | 000,135,664 | ---- | M] () -- C:\WINDOWS\SysNative\perfc011.dat
[2014/11/29 02:31:20 | 000,135,592 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2014/11/29 02:26:02 | 000,064,088 | ---- | M] () -- C:\Users\PC-User\Desktop\IMG_5231.jpg
[2014/11/29 02:25:45 | 000,062,364 | ---- | M] () -- C:\Users\PC-User\Desktop\IMG_5416.jpg
[2014/11/28 19:32:07 | 605,851,158 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2014/11/27 19:30:06 | 000,000,004 | ---- | M] () -- C:\Users\PC-User\AppData\Roaming\appdataFr2.bin
[2014/11/23 04:13:18 | 000,008,926 | ---- | M] () -- C:\Users\PC-User\Documents\高校ラベルデータ1.lcx
[2014/11/22 05:51:14 | 000,076,518 | ---- | M] () -- C:\Users\PC-User\Documents\tokyo.jpg
[2014/11/21 17:04:06 | 004,031,216 | ---- | M] () -- C:\Users\PC-User\Desktop\TDS_NewYear2014_AMB_141121_Demo.mp3
[2014/11/21 06:14:26 | 000,064,216 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2014/11/21 06:14:12 | 000,093,400 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbamchameleon.sys
[2014/11/21 05:51:37 | 000,714,208 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2014/11/21 05:51:37 | 000,106,976 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2014/11/20 09:01:50 | 000,098,216 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
[2014/11/20 09:01:48 | 000,272,808 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaws.exe
[2014/11/20 09:01:48 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaw.exe
[2014/11/20 09:01:47 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\java.exe
[2014/11/18 06:26:06 | 000,060,397 | ---- | M] () -- C:\Users\PC-User\Documents\age1.jpg
[2014/11/17 03:48:06 | 000,018,714 | ---- | M] () -- C:\Users\PC-User\Documents\SONY_DVD_RECORDER_VOLUME タイトル 1.mp4
[2014/11/16 21:38:05 | 349,798,608 | ---- | M] () -- C:\Users\PC-User\Documents\SONY_DVD_RECORDER_VOLUME (1).mp4
[2014/11/16 20:10:44 | 434,266,889 | ---- | M] () -- C:\Users\PC-User\Documents\SONY_DVD_RECORDER_VOLUME.mp4
[2014/11/16 06:28:17 | 456,001,932 | ---- | M] () -- C:\Users\PC-User\Documents\SONY_DVD_RECORDER_VOLUME.avi
[2014/11/16 05:56:39 | 013,729,254 | ---- | M] () -- C:\Users\PC-User\Documents\ikimatsu.avi
[2014/11/16 05:47:27 | 002,059,160 | ---- | M] () -- C:\Users\PC-User\Documents\nimura.avi
[2014/11/15 03:14:51 | 000,022,437 | ---- | M] () -- C:\Users\PC-User\Documents\youtube.wlmp
[2014/11/14 20:22:40 | 005,145,536 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2014/11/14 19:36:52 | 000,185,856 | ---- | M] () -- C:\Users\PC-User\Desktop\請求書・領収書.$td
[2014/11/13 20:50:54 | 000,002,638 | ---- | M] () -- C:\Users\PC-User\Documents\マイ ムービー.wlmp
[2014/11/13 06:41:21 | 000,106,785 | ---- | M] () -- C:\Users\PC-User\Documents\束帯修正.wlmp
[2014/11/13 05:37:04 | 000,029,775 | ---- | M] () -- C:\Users\PC-User\Documents\DSC_4594.jpg
[2014/11/13 05:34:43 | 001,098,976 | ---- | M] () -- C:\Users\PC-User\Documents\pspbrwse.jbf
[2014/11/11 21:22:10 | 000,019,972 | ---- | M] () -- C:\Users\PC-User\Documents\vz.jpg
[2014/11/09 11:38:33 | 000,080,632 | ---- | M] () -- C:\Users\PC-User\Documents\asadon.jpg
[2014/11/09 11:20:13 | 000,044,208 | ---- | M] () -- C:\Users\PC-User\Documents\twit.jpg
[2014/11/09 11:16:41 | 000,070,415 | ---- | M] () -- C:\Users\PC-User\Documents\den.jpg
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2014/12/08 23:48:10 | 000,001,133 | ---- | C] () -- C:\Users\Public\Desktop\herdProtect.lnk
[2014/12/08 22:37:44 | 000,083,311 | ---- | C] () -- C:\Users\PC-User\Desktop\Dsc_1045a.jpg
[2014/12/08 22:36:10 | 000,344,526 | ---- | C] () -- C:\Users\PC-User\Desktop\DSC_1045.JPG
[2014/12/08 22:36:00 | 000,029,561 | ---- | C] () -- C:\Users\PC-User\Desktop\Dsc_1043.jpg
[2014/12/08 22:35:52 | 000,036,783 | ---- | C] () -- C:\Users\PC-User\Desktop\Dsc_1048.jpg
[2014/12/08 22:19:46 | 000,014,001 | ---- | C] () -- C:\Users\PC-User\Desktop\mage.jpeg
[2014/12/08 22:19:38 | 000,014,299 | ---- | C] () -- C:\Users\PC-User\Desktop\imae.jpeg
[2014/12/08 22:19:20 | 000,030,717 | ---- | C] () -- C:\Users\PC-User\Desktop\image.jpeg
[2014/12/08 22:19:01 | 000,051,098 | ---- | C] () -- C:\Users\PC-User\Desktop\Dsc_0265.jpg
[2014/12/08 22:17:39 | 000,067,219 | ---- | C] () -- C:\Users\PC-User\Desktop\IMG_7864.jpg
[2014/12/08 22:17:39 | 000,043,481 | ---- | C] () -- C:\Users\PC-User\Desktop\IMG_1996.jpg
[2014/12/08 21:09:09 | 000,016,695 | ---- | C] () -- C:\Users\PC-User\Documents\mcafee.jpg
[2014/12/07 14:22:06 | 001,214,727 | ---- | C] () -- C:\Users\PC-User\Desktop\IMG_4041.JPG
[2014/12/06 23:09:35 | 000,000,296 | ---- | C] () -- C:\WINDOWS\tasks\Uninstaller_SkipUac_PC-User.job
[2014/12/05 07:28:33 | 000,000,222 | ---- | C] () -- C:\Users\PC-User\AppData\Roaming\burnaware.ini
[2014/12/05 07:28:13 | 000,001,066 | ---- | C] () -- C:\Users\Public\Desktop\BurnAware Free.lnk
[2014/12/05 07:12:34 | 000,000,949 | ---- | C] () -- C:\Users\PC-User\Desktop\CD Manipulator.lnk
[2014/12/05 06:56:58 | 003,405,946 | ---- | C] () -- C:\Users\PC-User\Desktop\seahawks.wav
[2014/12/05 06:47:52 | 000,292,333 | ---- | C] () -- C:\Users\PC-User\Desktop\seahawks.wma
[2014/12/05 05:31:56 | 000,000,834 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/12/04 22:15:52 | 000,087,596 | ---- | C] () -- C:\Users\PC-User\Desktop\1417673663705.jpg
[2014/12/04 00:32:41 | 000,091,837 | ---- | C] () -- C:\Users\PC-User\Desktop\SubstandardFullSizeRender.jpg
[2014/12/03 22:39:03 | 000,191,255 | ---- | C] () -- C:\Users\PC-User\Desktop\IMG_1725.jpg
[2014/12/02 05:49:41 | 000,058,822 | ---- | C] () -- C:\Users\PC-User\Desktop\pspbrwse.jbf
[2014/12/02 05:37:27 | 000,240,026 | ---- | C] () -- C:\Users\PC-User\Documents\kawaii.jpg
[2014/12/02 04:36:45 | 000,031,567 | ---- | C] () -- C:\Users\PC-User\Desktop\1417415477212.jpg
[2014/12/02 03:11:49 | 000,049,326 | ---- | C] () -- C:\Users\PC-User\Desktop\IMG_5791.jpg
[2014/11/29 05:59:38 | 000,114,295 | ---- | C] () -- C:\Users\PC-User\Documents\dame.jpg
[2014/11/29 05:57:02 | 000,727,980 | ---- | C] () -- C:\Users\PC-User\Desktop\日本伝統.pdf
[2014/11/29 02:24:50 | 000,064,088 | ---- | C] () -- C:\Users\PC-User\Desktop\IMG_5231.jpg
[2014/11/29 02:24:40 | 000,062,364 | ---- | C] () -- C:\Users\PC-User\Desktop\IMG_5416.jpg
[2014/11/28 19:32:07 | 605,851,158 | ---- | C] () -- C:\WINDOWS\MEMORY.DMP
[2014/11/23 18:17:16 | 000,000,004 | ---- | C] () -- C:\Users\PC-User\AppData\Roaming\appdataFr2.bin
[2014/11/23 04:55:09 | 004,031,216 | ---- | C] () -- C:\Users\PC-User\Desktop\TDS_NewYear2014_AMB_141121_Demo.mp3
[2014/11/22 05:51:04 | 000,076,518 | ---- | C] () -- C:\Users\PC-User\Documents\tokyo.jpg
[2014/11/22 05:23:53 | 000,001,121 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/11/17 03:48:05 | 000,018,714 | ---- | C] () -- C:\Users\PC-User\Documents\SONY_DVD_RECORDER_VOLUME タイトル 1.mp4
[2014/11/16 21:24:42 | 349,798,608 | ---- | C] () -- C:\Users\PC-User\Documents\SONY_DVD_RECORDER_VOLUME (1).mp4
[2014/11/16 19:55:39 | 434,266,889 | ---- | C] () -- C:\Users\PC-User\Documents\SONY_DVD_RECORDER_VOLUME.mp4
[2014/11/16 06:13:21 | 456,001,932 | ---- | C] () -- C:\Users\PC-User\Documents\SONY_DVD_RECORDER_VOLUME.avi
[2014/11/16 05:56:16 | 013,729,254 | ---- | C] () -- C:\Users\PC-User\Documents\ikimatsu.avi
[2014/11/16 05:47:18 | 002,059,160 | ---- | C] () -- C:\Users\PC-User\Documents\nimura.avi
[2014/11/14 21:59:56 | 000,022,437 | ---- | C] () -- C:\Users\PC-User\Documents\youtube.wlmp
[2014/11/13 05:37:04 | 000,029,775 | ---- | C] () -- C:\Users\PC-User\Documents\DSC_4594.jpg
[2014/11/12 22:01:05 | 000,389,176 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2014/11/11 21:22:10 | 000,019,972 | ---- | C] () -- C:\Users\PC-User\Documents\vz.jpg
[2014/11/09 13:46:41 | 000,106,785 | ---- | C] () -- C:\Users\PC-User\Documents\束帯修正.wlmp
[2014/11/09 11:38:33 | 000,080,632 | ---- | C] () -- C:\Users\PC-User\Documents\asadon.jpg
[2014/11/09 11:20:13 | 000,044,208 | ---- | C] () -- C:\Users\PC-User\Documents\twit.jpg
[2014/11/09 11:16:41 | 000,070,415 | ---- | C] () -- C:\Users\PC-User\Documents\den.jpg
[2014/03/18 19:00:08 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014/03/18 18:59:44 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2014/01/29 23:02:22 | 000,077,312 | ---- | C] () -- C:\WINDOWS\SysWow64\igdde32.dll
[2013/08/23 00:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013/08/23 00:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013/08/22 23:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013/08/22 16:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013/08/22 12:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2013/08/22 08:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013/08/22 08:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
[2013/08/13 14:00:29 | 000,000,435 | ---- | C] () -- C:\Users\PC-User\.swfinfo
[2013/06/21 05:19:01 | 000,000,110 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2013/04/24 16:38:28 | 000,000,952 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2013/04/06 06:30:41 | 000,002,362 | ---- | C] () -- C:\WINDOWS\Yonde.ini
[2013/04/06 06:30:41 | 000,001,419 | ---- | C] () -- C:\WINDOWS\Ydcrd.ini
[2013/04/05 20:23:21 | 000,000,046 | ---- | C] () -- C:\WINDOWS\JSCFG.INI
[2013/04/05 20:22:56 | 000,010,076 | ---- | C] () -- C:\WINDOWS\JSSETUP.INI
[2013/02/21 11:38:32 | 000,272,928 | ---- | C] () -- C:\WINDOWS\SysWow64\igvpkrng600.bin
[2013/02/21 11:38:08 | 000,963,452 | ---- | C] () -- C:\WINDOWS\SysWow64\igcodeckrng600.bin
[2013/02/19 19:10:19 | 000,004,799 | ---- | C] () -- C:\WINDOWS\SysWow64\LOCALSERVICE.INI
[2013/02/19 19:10:19 | 000,000,043 | ---- | C] () -- C:\WINDOWS\SysWow64\LOCALDEVICE.INI
[2013/02/19 19:04:03 | 000,040,958 | ---- | C] () -- C:\WINDOWS\SysWow64\drivers\RT3298.BIN
[2013/02/19 19:04:02 | 000,014,161 | ---- | C] () -- C:\WINDOWS\SysWow64\RaCoInst.dat
[2013/02/19 18:59:51 | 000,030,088 | ---- | C] () -- C:\WINDOWS\snuvcdsm.exe
[2013/02/19 18:59:51 | 000,015,497 | ---- | C] () -- C:\WINDOWS\snp2uvc.ini
[color=#E56717]========== ZeroAccess Check ==========[/color]
[2014/12/09 06:52:55 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/08/31 09:15:33 | 021,197,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/08/31 07:59:13 | 018,723,112 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013/08/22 18:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/22 11:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013/08/22 18:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
[color=#E56717]========== Custom Scans ==========[/color]
[color=#A23BEC]< %windir%\tasks\*.job >[/color]
[2014/10/25 06:05:07 | 000,000,708 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/10/25 06:05:07 | 000,000,712 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/08/19 11:52:14 | 000,000,264 | ---- | M] () -- C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job
[2014/12/06 23:09:35 | 000,000,296 | ---- | M] () -- C:\WINDOWS\tasks\Uninstaller_SkipUac_PC-User.job
[color=#E56717]========== Drive Information ==========[/color]
Physical Drives
---------------
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD7500BPVT-16HXZT3
Partitions: 7
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: USB Mass Storage Device USB Device
Partitions: 0
Status: OK
Status Info: 0
Partitions
---------------
DeviceID: Disk #0, Partition #0
PartitionType: GPT: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: False
Size: 768.00MB
Starting Offset: 1048576
Hidden sectors: 0
DeviceID: Disk #0, Partition #1
PartitionType: GPT: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: False
Size: 768.00MB
Starting Offset: 806354944
Hidden sectors: 0
DeviceID: Disk #0, Partition #2
PartitionType: GPT: System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 260.00MB
Starting Offset: 1611661312
Hidden sectors: 0
DeviceID: Disk #0, Partition #3
PartitionType: GPT: Basic Data
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 338.00GB
Starting Offset: 2018508800
Hidden sectors: 0
DeviceID: Disk #0, Partition #4
PartitionType: GPT: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: False
Size: 450.00MB
Starting Offset: 364877185024
Hidden sectors: 0
DeviceID: Disk #0, Partition #5
PartitionType: GPT: Basic Data
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 338.00GB
Starting Offset: 365349044224
Hidden sectors: 0
DeviceID: Disk #0, Partition #6
PartitionType: GPT: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: False
Size: 20.00GB
Starting Offset: 728679579648
Hidden sectors: 0
[color=#E56717]========== Base Services ==========[/color]
SRV:[b]64bit:[/b] - [2014/03/18 18:59:52 | 000,208,896 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc)
SRV:[b]64bit:[/b] - [2014/10/08 16:30:59 | 000,110,080 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:[b]64bit:[/b] - [2013/08/22 18:53:13 | 000,092,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:[b]64bit:[/b] - [2013/08/22 19:19:14 | 001,017,856 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:[b]64bit:[/b] - [2014/04/30 13:14:19 | 000,827,392 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:[b]64bit:[/b] - [2013/08/22 18:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV - [2013/08/22 11:48:12 | 000,044,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2013/08/22 18:40:30 | 000,468,992 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV - [2013/08/22 11:38:29 | 000,329,728 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV:[b]64bit:[/b] - [2014/07/24 18:21:23 | 000,134,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:[b]64bit:[/b] - [2013/08/22 19:01:39 | 000,129,536 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV:[b]64bit:[/b] - [2014/03/18 18:59:43 | 000,753,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:[b]64bit:[/b] - [2014/04/30 13:23:54 | 000,353,280 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV - [2014/04/30 12:46:07 | 000,285,696 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV:[b]64bit:[/b] - [2014/03/04 16:13:06 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:[b]64bit:[/b] - [2013/08/22 18:44:18 | 000,107,008 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\eapsvc.dll -- (Eaphost)
SRV:[b]64bit:[/b] - [2013/08/22 20:34:06 | 000,032,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV - [2013/08/22 13:05:54 | 000,029,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV:[b]64bit:[/b] - [2014/03/18 18:59:57 | 000,433,664 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:[b]64bit:[/b] - [2013/08/22 18:35:27 | 000,403,456 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:[b]64bit:[/b] - [2014/03/27 12:15:43 | 000,718,336 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv)
SRV:[b]64bit:[/b] - [2013/08/22 18:54:27 | 000,070,656 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS)
SRV:[b]64bit:[/b] - [2013/08/22 18:05:22 | 000,254,976 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:[b]64bit:[/b] - [2013/08/22 18:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2013/08/22 18:35:48 | 000,387,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:[b]64bit:[/b] - [2013/08/22 22:25:35 | 000,029,184 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:[b]64bit:[/b] - [2014/03/06 18:19:44 | 000,115,200 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:[b]64bit:[/b] - [2014/07/24 17:18:34 | 000,795,136 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
No service found with a name of ProtectedStorage
No service found with a name of EMDMgmt
SRV:[b]64bit:[/b] - [2013/08/22 20:22:30 | 000,101,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:[b]64bit:[/b] - [2014/03/18 18:59:57 | 000,534,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:[b]64bit:[/b] - [2014/03/18 18:59:43 | 000,753,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:[b]64bit:[/b] - [2013/08/22 20:32:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:[b]64bit:[/b] - [2013/08/22 22:25:35 | 000,045,008 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:[b]64bit:[/b] - [2014/04/09 12:33:54 | 000,135,168 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:[b]64bit:[/b] - [2014/07/24 18:03:18 | 000,324,096 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:[b]64bit:[/b] - [2013/08/22 18:24:27 | 000,629,760 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV - [2013/08/22 11:27:04 | 000,564,736 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV:[b]64bit:[/b] - [2014/08/02 09:18:31 | 001,212,928 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:[b]64bit:[/b] - [2013/08/22 19:55:30 | 000,306,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV - [2013/08/22 12:33:38 | 000,248,320 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV:[b]64bit:[/b] - [2013/08/22 19:00:18 | 000,050,688 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:[b]64bit:[/b] - [2014/07/24 18:02:28 | 000,220,160 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:[b]64bit:[/b] - [2014/03/27 12:10:11 | 001,436,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:[b]64bit:[/b] - [2014/10/07 10:46:06 | 000,911,360 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\audiosrv.dll -- (Audiosrv)
SRV:[b]64bit:[/b] - [2014/10/07 10:54:27 | 000,226,304 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
No service found with a name of SDRSVC
SRV:[b]64bit:[/b] - [2014/09/22 12:05:56 | 000,023,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2013/08/22 18:44:27 | 001,669,632 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (EventLog)
SRV:[b]64bit:[/b] - [2013/08/22 18:23:55 | 000,878,080 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
SRV:[b]64bit:[/b] - [2013/08/22 19:39:20 | 000,634,368 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:[b]64bit:[/b] - [2013/08/22 20:23:10 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\msiexec.exe -- (msiserver)
SRV - [2013/08/22 12:56:51 | 000,055,808 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysWow64\msiexec.exe -- (msiserver)
SRV:[b]64bit:[/b] - [2013/08/22 18:48:04 | 000,220,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:[b]64bit:[/b] - [2014/10/18 15:38:57 | 003,557,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:[b]64bit:[/b] - [2013/08/22 19:30:45 | 000,258,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:[b]64bit:[/b] - [2014/07/24 17:32:47 | 001,532,416 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wlansvc.dll -- (WlanSvc)
SRV:[b]64bit:[/b] - [2013/08/22 18:54:22 | 000,284,160 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)
[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 220 bytes -> C:\Users\PC-User\OneDrive:ms-properties
< End of report >