悪代官の伏魔殿掲示板
「by CloudScout」というバナー広告に入れ替わる


お手数をお掛けしますが、よろしくお願いします。

□経緯
2014/12/10の夜、GoogleChromeにて、下記ページの「DVD Decrypter」の下のリンクからダウンロードしたものをインストールしようとした際に、正規のインストーラーとは別のインストーラーが起動したことに気付かず、正規のインストーラーと思い込んだままインストールを実行してしまったようだ。
ttp://note.chiebukuro.yahoo.co.jp/detail/n34796

「DVD Decrypter」
ttp://www.gufairu.com/dvd-decrypter?mkwid=52B1Dkn1_dc&pcrid=21882821561&kword=dvdコピー無料ソフト&match=b


インストールを実行中にESET SMART SECURITY7が29件ほど、以下の脅威を検出した

Win32/AdWare.EoRezo.AUの亜種 アプリケーション
Win32/Adware.EoRezo.AJの亜種 アプリケーション
Win32/Adware.Salus.C アプリケーション
Win32/Adware.SpeedingUpMyPC.T.genの亜種 アプリケーション
Win32/AdWare.Linkular.AJ アプリケーション


「DVD Decrypter」のインストーラーはインストールせずに終了した。

その後、コントロールパネルからプログラムのアンインストール画面を表示し、インストール日でソートした後、2014/12/10の日付でインストールした覚えのないプログラムが3件あったので、それらをアンインストールした

アンインストールしたソフトウエアの名前は覚えていないが、
1つは、デスクトップ リモートコントロール のような名称
もう一つは下記にある「CloudScout」に似た名称だったような気がする

また、2014/12/10の日付でFlashPlayer15がインストールされていたが、検索すると16が最新版だったようなので、16をインストールした。

その後、ESET SMART SECURITY7でコンピュータの検査をCドライブについて実行したが、脅威は検出されなかった。
ただし、ログを見ると「(ファイル名)を開く際にエラーが発生しました[4] 」「[4] ファイルを開くことができません。ほかのアプリケーションまたはオペレーティングシステムが使用中の可能性があります。」と多数表示されている。

また、Microsoft Safety Scannerをダウンロードして実行したが、異常はなかった。

これらの経緯の前から表示していたFirefoxにも異変が見られた。(いつの時点かは覚えていない)
・ツールバーのアドオンや拡張機能の並び順が変わる
・Firefoxがアップグレードした後などに表示されるページのようなタブが出現


コントロールパネルの信頼性モニターを確認すると、ESET SMART SECURITY7が脅威を検出した時刻に、
・警告2件「Google Update Helper アプリケーションの再構成に失敗しました」が2件
・重要なイベント「Plugin Container for Firefox 動作が停止しました」
が記録されていた。


2014/12/11行ったこと
・Windows Defenderでフルスキャンを行ったが、異常は無かった


□症状
上記を行ったが、以下の症状が残った。

GoogleChrome、Firefox、IEにて
WEBページを開くと、最初の数秒は正規のバナー広告が表示されるが、その後、下部に「by CloudScout」と表記されたバナー広告が表示され、一定期間ごとに広告が入れ替わる
「by CloudScout」広告が表示されているWEBページは常に更新状態

また、WEBページをクリックまたはテキストを選択しようとしてもできず、別のタブが開き、意図していないページが表示されることがあり、それらはアンチウイルスソフトやFlashPaperのようなソフトウエアのインストールを促すサイトであるようだ。

管理者権限のある別のユーザーアカウントでも同様。



□質問ほか

1.HJTとCCのログは管理者権限のないユーザーアカウントで実行していますが、管理者権限のあるユーザーアカウントで実行したほうがよいでしょうか。

普段は管理者権限のないユーザーアカウントでPCを利用しており、2014/12/10の夜も管理者権限のないユーザーアカウントを利用していました。

2.CCleanerがタスクバーに常駐し、「CCleanerアラート」「Cleaning can save ○GB of disk space」と表示されます。

このメッセージは無視して構わないということでいいですか?。
常駐しないように設定変更してよいですか?

3.リカバリが一番確実ということなら、今までリカバリしたことがないので少々不安ですがリカバリしようかと思うのですが、どうでしょうか。

Windows7のバックアップ機能で指定フォルダのバックアップを外付けHDDに作成しており、数日前にバックアップしたデータがあります。
ただ、バックアップできていないデータも多少あると思うので、それらを別の外付けHDDにバックアップし、リカバリが済んでからスキャンを行って異常がなければ復元しようかと思います。

リカバリしてもウィルスが残るということもあるのでしょうか?

ある程度、どのようなウィルスに感染したのか把握してからリカバリを行ったほうがよいのでしょうか?



□HJTログ
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 23:50:16, on 2014/12/11
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
CHROME: 39.0.2171.95
FIREFOX: 34.0.5 (x86 ja)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Mindjet\MindManager 8\MmReminderService.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Windows\SSDriver\fi5110\SsWiaChecker.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\BUFFALO\BuffaloTools\BuffaloTools.exe
C:\Users\7y84qMCp\AppData\Local\Apps\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaConverter.exe
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaRenderer.exe
C:\Program Files\TrueCrypt\TrueCrypt.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Users\7y84qMCp\Desktop\相談用2014-12-11\ソフトウエア\HijackThis.exe

R3 - URLSearchHook: (no name) - {2ACECADE-0BC7-4C6F-95CF-A221CC161B52} - (no file)
R3 - URLSearchHook: (no name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: 楽天ツールバー ブラウザヘルパ オブジェクト - {227B8061-B95B-4092-9C9B-6CE5759EE8E5} - C:\Program Files (x86)\RakutenToolbar\RTBHelper_32.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll (file missing)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: CmjBrowserHelperObject Object - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O2 - BHO: RoboForm BHO - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Google Analytics オプトアウト アドオン - {75EF13CE-B59E-41ba-8A5A-A944031BD8B4} - C:\Program Files (x86)\Google\Google Analytics Opt-Out\gaoptout.dll
O2 - BHO: PhishWall - {8CA7E745-EF75-4E7B-BB86-8065C0CE29CA} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
O2 - BHO: Windows Live ID サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Soda PDF 5 IE Helper - {C737F472-1193-4281-BF53-A00B67AB3E19} - C:\Program Files (x86)\Soda PDF 5\PDFIEHelper.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: PhishWall - {BB62FFF4-41CB-4AFC-BB8C-2A4D4B42BBDC} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
O3 - Toolbar: 楽天ツールバー - {4FD20E5F-825F-476F-8B45-5E3FF6502692} - C:\Program Files (x86)\RakutenToolbar\RakutenToolbar_32.dll
O3 - Toolbar: Soda PDF 5 IE Toolbar - {F335ABA2-FDB4-4644-92B2-5CC4B0FC91D6} - C:\Program Files (x86)\Soda PDF 5\PDFIEPlugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 8\MMReminderService.exe
O4 - HKLM\..\Run: [CSPTL-CANONMJ] C:\Program Files (x86)\CMJ\CSPTL-CANONMJ\CSPTL-CANONMJ.exe
O4 - HKLM\..\Run: [Google Japanese Input Prelauncher] "C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe" --mode=prelaunch_processes
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ScanSnap WIA Service Checker] C:\Windows\SSDriver\fi5110\SsWiaChecker.exe
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [FeliCa Launcher] "C:\Program Files (x86)\Sony\FeliCa Launcher\FeliCaLauncher.exe" /AutoStart
O4 - HKLM\..\Run: [BuffaloTools] C:\Program Files (x86)\BUFFALO\BuffaloTools\BuffaloTools.exe
O4 - HKLM\..\Run: [Eject Utility] C:\Program Files (x86)\BUFFALO\Eject_Utility\Eject_Utility.exe
O4 - HKLM\..\Run: [Backup Utility TaskTray Tool] "C:\Program Files (x86)\BUFFALO\Backup_Utility\BUTray.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\7y84qMCp\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RakutenToolbarHelper] C:\Program Files (x86)\RakutenToolbarHelper\RakutenToolbarHelper.exe
O4 - HKCU\..\RunOnce: [Adobe Speed Launcher] 1418289137
O4 - Startup: bkchime.lnk = 7y84qMCp\80.FreeProgram\11.2013\bkchime-0.3.4-1\bkchime.exe
O4 - Startup: CLaunch.lnk = 7y84qMCp\80.FreeProgram\11.2013\cl64_322\CLaunch.exe
O4 - Startup: Clibor.lnk = 7y84qMCp\80.FreeProgram\12.2014\clibor\Clibor.exe
O4 - Startup: Dropbox.lnk = 7y84qMCp\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: EmEditor.lnk = C:\Program Files\EmEditor\emedtray.exe
O4 - Startup: EvernoteClipper.lnk = 7y84qMCp\AppData\Local\Apps\Evernote\Evernote\EvernoteClipper.exe
O4 - Global Startup: ScanSnap Manager.lnk = C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe
O4 - Global Startup: ScanSnap Organizer PDF変換.lnk = C:\Program Files (x86)\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe
O8 - Extra context menu item: Adobe PDF に変換 - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: JWord でサイト検索 - res://C:\Program Files (x86)\JWord\Plugin2\jwdsrch.dll/300
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: RF ツールバー表示 - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: RF フォーム保存 - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: RF フォーム記入 - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RF メニューカスタマイズ - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: URL をクリップ - C:\Users\7y84qMCp\AppData\Local\Apps\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0
O8 - Extra context menu item: このページをクリップ - C:\Users\7y84qMCp\AppData\Local\Apps\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1
O8 - Extra context menu item: リンクの参照先を Adobe PDF に変換 - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: リンクの参照先を既存の PDF に追加 - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: 新規ノート - C:\Users\7y84qMCp\AppData\Local\Apps\Evernote\Evernote\\EvernoteIERes\NewNote.html
O8 - Extra context menu item: 既存の PDF に追加 - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: 画像をクリップ - C:\Users\7y84qMCp\AppData\Local\Apps\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4
O8 - Extra context menu item: 選択部分をクリップ - C:\Users\7y84qMCp\AppData\Local\Apps\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Mindjet MindManager に送信 - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O9 - Extra button: フォーム記入 - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra 'Tools' menuitem: RF フォーム記入 - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: 保存 - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra 'Tools' menuitem: RF フォーム保存 - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: ツールバー表示 - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra 'Tools' menuitem: RF ツールバー表示 - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: @C:\Users\7y84qMCp\AppData\Local\Apps\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Users\7y84qMCp\AppData\Local\Apps\Evernote\Evernote\\EvernoteIERes\AddNote.html (HKCU)
O9 - Extra 'Tools' menuitem: @C:\Users\7y84qMCp\AppData\Local\Apps\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Users\7y84qMCp\AppData\Local\Apps\Evernote\Evernote\\EvernoteIERes\AddNote.html (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://qtinstall.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {0C687FA8-9672-4D77-9AF5-FD6B49C7EDC0} (TTimePlug Control) - http://shangrila.dotbook.jp/update/t-time_plug/T-TimePlugIn.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{534735A2-0DDC-4253-9130-2F8EE4F3DCFE}: NameServer = 31.168.224.106,5.135.12.52
O17 - HKLM\System\CCS\Services\Tcpip\..\{9070DD1E-0137-4A0A-A35A-EC32FB9EAB10}: NameServer = 31.168.224.106,5.135.12.52
O17 - HKLM\System\CCS\Services\Tcpip\..\{E1159A60-0C42-4206-8E45-F388EF9330D3}: NameServer = 31.168.224.106,5.135.12.52
O17 - HKLM\System\CCS\Services\Tcpip\..\{E18D3B35-A78A-4B30-82EA-E3CD6906B2A5}: NameServer = 31.168.224.106,5.135.12.52
O17 - HKLM\System\CS1\Services\Tcpip\..\{534735A2-0DDC-4253-9130-2F8EE4F3DCFE}: NameServer = 31.168.224.106,5.135.12.52
O17 - HKLM\System\CS2\Services\Tcpip\..\{534735A2-0DDC-4253-9130-2F8EE4F3DCFE}: NameServer = 31.168.224.106,5.135.12.52
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Active File Monitor V10 (AdobeActiveFileMonitor10.0) - Adobe Systems Incorporated - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour サービス (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CSPTL-CANONMJService - キヤノンマーケティングジャパン株式会社 - C:\Program Files (x86)\CMJ\CSPTL-CANONMJ\CSPTL-CANONMJService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: @C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe,-100 (GoogleIMEJaCacheService) - Google Inc. - C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe
O23 - Service: Google アップデート サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod サービス (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NFC Proxy Service (NFCProxyService) - Sony Corporation - C:\Program Files (x86)\Sony\NFC Proxy Service\bin\NFCProxyService.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Riverbed Technology, Inc. - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SecureBrain PhishWall Update - SecureBrain Corporation - C:\Program Files (x86)\SecureBrain\PhishWall\sbpwupdx.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soda PDF 5 Helper Service - LULU Software Limited - C:\Program Files (x86)\Soda PDF 5\HelperService.exe
O23 - Service: Soda PDF 5 Service - LULU Software Limited - C:\Program Files (x86)\Soda PDF 5\ConversionService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 21300 bytes



□CCログ

ABBYY FineReader for ScanSnap (TM) 4.1 ABBYY 2012/06/05 268 MB 8.02.650.72520
Adobe Acrobat X Standard - Japanese Adobe Systems 2014/12/11 4.62 GB 10.1.13
Adobe AIR Adobe Systems Incorporated 2013/12/28 3.9.0.1380
Adobe Community Help Adobe Systems Incorporated. 2013/09/25 3.5.23
Adobe Flash Player 15 ActiveX Adobe Systems Incorporated 2014/12/10 6.00 MB 15.0.0.246
Adobe Flash Player 16 NPAPI Adobe Systems Incorporated 2014/12/10 6.00 MB 16.0.0.235
Adobe PDF iFilter 9 for 64-bit platforms Adobe 2013/11/30 44.6 MB 9.0.0
Adobe Photoshop Elements 10 Adobe Systems Incorporated 2013/09/25 2.60 GB 10.0
Adobe Reader 64-bit fixes Leo Davidson / Pretentious Name 2013/11/30 3.02 MB
Adobe Reader XI (11.0.09) - Japanese Adobe Systems Incorporated 2014/09/20 203 MB 11.0.09
Apple Application Support Apple Inc. 2012/04/20 61.0 MB 2.1.7
Apple Mobile Device Support Apple Inc. 2012/04/20 24.9 MB 5.1.1.4
Apple Software Update Apple Inc. 2012/03/16 2.38 MB 2.1.3.127
ArcSoft MediaImpression 2 ArcSoft 2013/09/15 2.0.14.672
ArcSoft Scan-n-Stitch Deluxe ArcSoft 2013/09/15 1.1.2.35
Bonjour Apple Inc. 2012/04/20 2.00 MB 3.0.0.10
BUFFALO BuffaloTools ランチャー 2013/04/15
BUFFALO DiskFormatter2 2013/04/17
BUFFALO ecoマネージャー for HD 2013/04/17
BUFFALO Eject Utility 2013/04/15
BUFFALO TurboCopy 2013/04/15
BUFFALO ブロードステーション IP設定ユーティリティ BUFFALO INC. 2013/01/01
Canon Easy-PhotoPrint EX 2012/03/22
Canon Easy-WebPrint EX Canon Inc. 2012/10/17 1.3.5.0
Canon iP2700 series Printer Driver Canon Inc. 2013/12/21
Canon Utilities Solution Menu 2012/10/27
Canon マイ プリンタ 2012/03/22
CCleaner Piriform 2014/12/11 5.00
Craving Explorer Version 1.5.0 T-Craft / tuck 2013/05/04 15.2 MB 1.5.0.0
CyberLink LabelPrint CyberLink Corp. 2011/06/14 31.8 MB 2.5.3624
CyberLink Media Suite CyberLink Corp. 2011/06/14 36.4 MB 8.0.2813
CyberLink MediaShow CyberLink Corp. 2011/06/14 387 MB 5.1.2109n
CyberLink Power2Go CyberLink Corp. 2011/06/14 184 MB 7.0.0.1607
CyberLink PowerBackup CyberLink Corp. 2012/03/09 2.5.6023
CyberLink PowerDirector CyberLink Corp. 2011/06/14 592 MB 8.0.4110
CyberLink PowerDVD 10 CyberLink Corp. 2011/06/14 165 MB 10.0.2731.02
Daum PotPlayer 1.5.34115 x64 Edition 2012/09/30
Document Capture Pro Seiko Epson Corporation 2013/09/15 34.1 MB 1.01.0000
Dropbox Dropbox, Inc. 2014/11/14 2.10.52
Electric Mobile Simulator Lite version v1.4a Electric Plum, LLC 2012/07/14 39.7 MB v1.4a
EmEditor Professional (64-bit) Emurasoft, Inc. 2013/08/07 21.9 MB 13.0.4
Epson Copy Utility 3.5 2013/09/15 3.5.0.0
Epson Event Manager Seiko Epson Corporation 2013/09/15 42.4 MB 3.01.0009
EPSON GT-S640/F740 ユーザーズガイド 2013/09/15
EPSON GT-X820 ユーザーズガイド 2013/09/25
EPSON Scan Seiko Epson Corporation 2013/09/15
EPSON Scan OCR コンポーネント SEIKO EPSON Corp. 2013/09/15 1.21.0001
ESET Smart Security ESET, spol s r. o. 2014/03/20 100 MB 7.0.302.31
Evernote v. 5.7.2 Evernote Corp. 2014/11/24 230 MB 5.7.2.5753
Faveset Klink Faveset LLC 2013/06/25 6.33 MB
FeliCa Launcher Sony Corporation 2012/09/20 1.4.0.5
FeliCa Port Software Sony Corporation 2012/09/20 4.4.8.10
FenrirFS 2.4.5 Fenrir Inc. 2012/07/25 25.6 MB
Google Analytics オプトアウト アドオン Google Inc. 2014/04/15 654 KB 0.9.6.0
Google Chrome Google Inc. 2012/03/16 39.0.2171.95
Google Drive Google, Inc. 2014/11/08 34.6 MB 1.18.7821.2489
Google Toolbar for Internet Explorer Google Inc. 2014/04/01 7.5.5111.1712
Google 日本語入力 Google Inc. 2014/01/08 83.0 MB 1.13.1641.0
honto 2.5.3 Dai Nippon Printing Co., Ltd. 2014/08/30 34.6 MB 2.5.3.0
i-mode HTML Simulator II 2012/09/20
IETester v0.5.2 (remove only) Core Services 2013/09/13 0.5.2
Intel(R) Management Engine Components Intel Corporation 2012/03/09 7.0.0.1144
Intel(R) Rapid Storage Technology Intel Corporation 2012/03/09 10.5.0.1026
iTunes Apple Inc. 2012/04/20 156 MB 10.6.1.7
Java 7 Update 71 Oracle 2014/11/12 119 MB 7.0.710
JavaFX 2.1.1 Oracle Corporation 2012/07/15 20.8 MB 2.1.1
Kobo Kobo Inc. 2014/09/26 3.5.2
Lhaplus 2012/03/17
LibreOffice 3.5 The Document Foundation 2012/03/22 530 MB 3.5.1.102
Lunascape6 (All Users) Lunascape 2012/03/16 6.6.0.25173
Mendeley Desktop 1.5.1 Mendeley Ltd. 2012/05/15 1.5.1
Microsoft .NET Framework 4.5.1 Microsoft Corporation 2014/02/26 38.8 MB 4.5.50938
Microsoft .NET Framework 4.5.1 (日本語) Microsoft Corporation 2014/02/26 2.93 MB 4.5.50938
Microsoft Excel 2010 Microsoft Corporation 2013/12/11 14.0.7015.1000
Microsoft Silverlight Microsoft Corporation 2014/07/25 249 MB 5.1.30514.0
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2011/06/09 1.69 MB 3.1.0000
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2012/03/16 298 KB 8.0.56336
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2011/06/09 608 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2011/06/14 586 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2012/03/16 600 KB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2012/07/26 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2012/07/26 15.0 MB 10.0.40219
Microsoft Visual J# 2.0 Redistributable Package Microsoft Corporation 2012/06/05
Microsoft Visual J# 2.0 日本語 Language Pack Microsoft Corporation 2012/06/05
Microsoft マウス キーボード センター Microsoft Corporation 2014/06/22 2.3.188.0
Mindjet MindManager 8 Mindjet 2012/03/16 114 MB 8.2.382
MiNDPiECE v1.0r3 (build428) KANTETSU WORKS 2012/03/16
Mobilizer UNKNOWN 2012/07/14 0.9.5
Mozilla Firefox 34.0.5 (x86 ja) Mozilla 2014/12/11 82.1 MB 34.0.5
Mozilla Maintenance Service Mozilla 2014/07/17 341 KB 30.0
Mozilla Thunderbird 11.0 (x86 ja) Mozilla 2012/03/17 38.0 MB 11.0
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2012/06/06 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2012/06/06 1.33 MB 4.20.9876.0
NextFTP 2012/06/09
NVIDIA 3D Vision コントローラー ドライバー 344.65 NVIDIA Corporation 2014/11/12 344.65
NVIDIA 3D Vision ドライバー 344.65 NVIDIA Corporation 2014/11/12 344.65
NVIDIA GeForce Experience 2.1.4 NVIDIA Corporation 2014/11/12 2.1.4
NVIDIA HD オーディオ ドライバー 1.3.32.1 NVIDIA Corporation 2014/11/12 1.3.32.1
NVIDIA PhysX システム ソフトウェア 9.14.0702 NVIDIA Corporation 2014/11/12 9.14.0702
NVIDIA グラフィックス ドライバー 344.65 NVIDIA Corporation 2014/11/12 344.65
Opera 12.17 Opera Software ASA 2014/05/07 12.17.1863
Opera Stable 24.0.1558.53 Opera Software ASA 2014/09/03 24.0.1558.53
PC/SC Activator for Type B Sony Corporation 2012/09/20 1.2.1.0
PdaNet+ for Android 4.12 June Fabrics Technology Inc 2013/06/25 3.53 MB
PDF Split And Merge Basic Andrea Vacondio 2013/09/17 16.1 MB 2.2.2
PDF-XChange 3 Tracker Software 2012/03/16
PhishWall SecureBrain Corporation 2013/03/11 3.5.2
Poedit Vaclav Slavik 2012/07/30 1.4.6
RealPlayer RealNetworks 2012/04/26
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2012/03/09 6.0.1.6383
Renesas Electronics USB 3.0 Host Controller Driver Renesas Electronics Corporation 2012/03/09 1.22 MB 2.1.16.0
RoboForm 7-9-11-1 (All Users) Siber Systems 2014/11/12 20.0 MB 7-9-11-1
Safari Apple Inc. 2012/03/16 104 MB 5.34.54.16
SAMSUNG USB Driver for Mobile Phones SAMSUNG Electronics Co., Ltd. 2013/06/25 42.7 MB 1.4.4.0
Scan to Microsoft SharePoint KnowledgeLake 2012/06/05 10.4 MB 3.4.1
ScanSnap Manager PFU 2012/06/05 V5.1L51
ScanSnap Organizer PFU 2012/06/05 V4.1L50
SFCard Viewer 2 Sony Corporation 2012/10/27 2.4.1.2
Shuriken 2007 株式会社ジャストシステム 2012/03/18
Shuriken Windows 7 対応モジュール 株式会社ジャストシステム 2012/03/18 35.0 KB 1.0.0
Skype(TM) 6.18 Skype Technologies S.A. 2014/08/04 25.9 MB 6.18.106
Sleipnir Version 3.0.13 Fenrir Inc. 2012/03/16 107 MB 3.0.13
SMPlayer 14.9.0 (x64) Ricardo Villalba 2014/11/27 14.9.0
Soda PDF 5 LULU Software Limited 2013/09/17 100 MB 5.1.210.11318
StreamTransport version: 1.1.2.0 2014/03/24 4.55 MB
Tera Term 4.77 2013/04/22 9.58 MB
Tether ClockworkMod 2013/06/25 8.07 MB 1.0.1
TogglDesktop Toggl 2013/12/02 40.6 MB 4.94.0
TrueCrypt TrueCrypt Foundation 2012/03/17 7.1a
tsoft 別のウィンドウで開くExcel2007 0.3.12.0103 tsoft 2013/08/02 0.3.12.0103
Video Download Capture V4.5.3 Apowersoft 2013/07/26 81.8 MB 4.5.3
Widget Manager Sony Corporation 2012/09/20 2.4
Windows Live Essentials Microsoft Corporation 2011/06/09 15.4.3502.0922
Windows Media Player Firefox Plugin Microsoft Corp 2012/04/14 296 KB 1.0.0.8
WinPcap 4.1.3 Riverbed Technology, Inc. 2013/07/30 4.1.0.2980
WinRAR 5.01 (64ビット) win.rar GmbH 2014/11/04 5.01.0
XTRM Runtime.06 XTRM CORPORATION 2012/07/26
YTD Video Downloader 4.0 GreenTree Applications SRL 2013/05/04 4.0
はがきデザインキット Japan Post Co., Ltd. 2013/11/21 v7.0.1
やさしく家計簿 エントリー for ScanSnap メディアドライブ株式会社 2012/06/05 1.0.1.0
らくちんCDダイレクトプリント for Canon 2012/03/22
カシミール 3D DAN杉本 2014/06/06 9.1.5
カシミール 3D 基盤地図情報(標高)プラグイン DAN杉本 2014/06/06 1.2.0
キヤノンお知らせメッセンジャー キヤノンマーケティングジャパン株式会社 2013/04/20 8.12 MB 2.0.2.0
リモート接続用の Windows Live Mesh ActiveX コントロール (日本語) Microsoft Corporation 2011/06/09 5.57 MB 15.4.5722.2
名刺ファイリングOCR V3.1 PFU 2012/06/05 3.1.50.1
楽天ツールバー 2013/05/10 2013.032901
読んde!!ココ パーソナル 2013/09/25
読取革命Lite パナソニック ソリューションテクノロジー株式会社 2012/03/22 25.5 MB 1.08.0000

以上です。
  • penpen
  • 2014/12/12 (Fri) 00:59:02
実は悩んでおります
こんにちは、IVNOと申します。
ウイルス感染が確認されたことに加え、現段階でPCに導入されている、
Safariや旧バージョンのSkype等のセキュリティ面での脆弱性が認められるものもあり、
加えてログそのものも少々怪しいため、リカバリにするかどうか悩んでおります。
処置を行う前にPCの中をもっと切り込んで探ってみることにしましょう。

それでは作業準備を行いましょう。

まずはじめに連絡事項がございます。
相談いただいてから回答できるまでに、毎回1日かそれ以上かかる可能性もございます。
ご不便をおかけいたしますが、ご理解とご協力を賜りますよう、お願い申し上げます。
また、回答者側から「解決」と通達があるまで、駆除作業は続いております。
そのため、途中でPCの状況が良くなったかのように感じたからと言って、解決のご案内を待たずして作業を中断なされると、
高確率で再発しているのが現状で、再発時にこちらにお戻りになられる方が続出しております。
回答者から「解決」と「自衛策」の案内があるまでは、作業を続けるようにしてください。

それでは以下の説明を熟読し、順番に作業をお願いします。
既に準備した物もあるはずですが、一応説明を再度見ておいてください。

隠しファイルと拡張子を表示設定にしてください(やり方↓)
http://pasofaq.jp/windows/mycomputer/hiddenfile.htm
http://support.microsoft.com/kb/978449/ja

以下のソフトウェアをご用意ください。

HerdProtect(通称:HP)
http://www.herdprotect.com/downloads.aspx
インストール版でもポータブル版でも構いません。
インストール版の場合、アンインストールの際は、セーフモードでIUを利用してアンインストールされてください。
また、トレンドマイクロのウイルスバスターとの相性が悪いとの報告も受けております。
相性の問題でスキャンが正常にできないときは、その旨をご報告ください。
さらに、本ソフトウェアにより検出されたものすべてがマルウェアと言うわけではありません。
HPは駆除機能もありますが、まずは駆除は行わず、検出のみに使用いたします。

OldTimer Listit(通称:OTL)
http://oldtimer.geekstogo.com/OTL.exe
直リンクです。デスクトップ等、分かりやすい場所に保存してください。
削除する際は起動後に「Cleanup」ボタンを押すことにより、自動的に削除されます。

準備ができましたら作業を開始しましょう。

まずは、Javaをご利用の方は以下URLの「Javaアンインストール・ツール」と言う文字をクリックし、
最新版の確認と旧バージョンの削除を行われてください。
https://java.com/ja/download/faq/remove_olderversions.xml

Javaの処置が完了した方、Javaを導入されていない方は以下から作業をお願いいたします。

以降の駆除作業でトラブルが発生しても直ちに復旧できるよう、システムの復元ポイントを手動で作成しましょう。
http://windows.microsoft.com/ja-jp/windows7/create-a-restore-point
しかし、システムの復元はPCにかなりのダメージを与えますので、できれば使わないほうが望ましいです。
システムの復元が必要のない、慎重な作業を心がけましょう。

まずゲームのインストーラーなど、極端に重たいファイルがある場合は、
そちらの不要ファイルを事前にPC内から手動削除し、ごみ箱からも消しておいてください。
これらをHPが不審プログラムとして拾うと、1日や2日は平気でスキャンにかかってしまいます。
PCが通常モードで起動していることを確認し、HerdProtectを起動させます。
ソフトウェアの特性として、ファイルのスキャンにインターネット回線を利用します。
インターネット回線がご利用できないセーフモード時では正常に動作しませんので、
セーフモードで起動中の場合は通常モードに切り替えてください。
Scanボタンがありますので、こちらを押してスキャンを行ってください。
スキャンに必要な情報を収集したり、発見された不審なソフトウェアを
各種セキュリティソフトで調査している間は、スキャン作業が停止します。
スキャンが進行しないからと言ってフリーズしたわけではありませんので、
スキャンが完了するまで今しばらくお待ちください。
スキャンが完了しましたらスキャン結果が表示されますので、
画面右上にあるSave resultsという文字をクリックしてログを出力してください。
ログは任意のお名前をつけて、分かりやすいところに保存してください。

以下をメモ帳にコピペしてください。

------コピペこの下より------
%windir%\tasks\*.job
DRIVES
BASESERVICES
%SYSTEMDRIVE%\*.exe
CREATERESTOREPOINT
------コピペこの上まで------

コピペが完了しましたら、任意のお名前をつけて分かりやすい場所に保存されてください。
保存が完了しましたら、PCをセーフモードで起動してください(やり方↓)
http://www.pc-master.jp/sousa/s-safemode.html
OTLを起動させ、表示画面上部中央にあるScan All Usersにチェックを入れてください。
設定が完了しましたら、Custom Scan/Fixesの項目内に先ほど保存したメモ帳の内容を貼り付けてください。
コピペが完了しましたらメモ帳を終了させ、[Run Scan]をクリックしてスキャンを行ってください。
スキャン完了まで数分程度かかりますので、今しばらくお待ちください。
スキャンが完了しましたら、OTLを保存した場所と同じところに、
OTL.txtとExtras.txtが出力されますので、こちら2つと先に保存したHPのログを貼り付けてご連絡ください。
なお、OTLもHPもその特性上、非常に長文となりがちです。
こちらの掲示板の文字数上限がひらがな換算で約3万文字、ローマ字換算で約6万文字です。
(より正確には件名を含めてJIS換算65,535バイトまで。全角文字・全角記号2バイト、
半角文字・半角記号1バイト、絵文字等特殊文字3バイト)
確実に文字数オーバーとなりますので、余裕を見て5万5千文字程度になるように、
以下のURLの文字数カウンター等で確認しつつ、ログを分割されてご連絡ください。
http://www2u.biglobe.ne.jp/~yuichi/rest/strcount.html
  • IVNO
  • MAIL
  • 2014/12/12 (Fri) 12:03:07
HPログ
IVNO様、返信ありがとうございます。
連絡事項、了解しました。


□HPログ

Saved date: 2014/12/12 19:31:30
Files detected: 68
Files scanned: 10,407
Processes scanned: 105
Modules scanned: 774
ASEPs scanned: 492
Downloads scanned: 0
Deep analysis: 199/3
---------------------------------------------------------------------------------

Files

---------------------------------------------------------------------------------

File path: c:\program files (x86)\real\realplayer\update\realsched.exe
Publisher: RealNetworks, Inc.
Signer: RealNetworks, Inc.
MD5: 2cfa297e8ee94c4c7c41a65f6ab75816
SHA-1: f4be4a20a7f07c34c7fc4ab0096e13bf12d2ff9c
Created: 2012/04/26 17:23:00
Detections: 1
Determination: Ignore detections (false positive)
- Boost by Reason as UnneededApp.Startup.RealNetworks.J

---------------------------------------------------------------------------------

File path: c:\program files (x86)\common files\arcsoft\connection service\bin\acdaemon.exe
Publisher: ArcSoft Inc.
Signer: ArcSoft, Inc.
MD5: a7810b302294793de88542aae177d1b1
SHA-1: 78d806370b16de5afacd076901ec4eb7635d1009
Created: 2013/09/15 2:05:17
Detections: 1
Determination: Ignore detections (false positive)
- Boost by Reason as UnneededApp.Startup.ArcSoft.I

---------------------------------------------------------------------------------

File path: c:\program files (x86)\pfu\scansnap\driver\pfusscommon.dll
Publisher: PFU LIMITED
MD5: 8794d9b2178a42f61f5cf2f881f9fc12
SHA-1: e9565390d31c9c0bf00367f9091ab937497e76c1
Created: 2012/06/05 17:01:03
Detections: 1
Determination: Ignore detections (false positive)
- Bkav FE as HW32.Laneul (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\cyberlink\power2go\msvcr71.dll
Publisher: Microsoft Corporation
Signer: CyberLink
MD5: a1a6fc56a1d0dadc164637fe43c40605
SHA-1: 2c66dea7b3062113ee644a03c01c4c115036dc80
Created: 2010/08/03 15:39:38
Detections: 1
Determination: Ignore detections (false positive)
- Bkav FE as HW32.Laneul (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\real\realupgrade\realupgrade.exe
Publisher: RealNetworks, Inc.
Signer: RealNetworks, Inc.
MD5: eb32663781b051b8e8394c92f9a62a14
SHA-1: 78bc7f8993669b4c628c3d93f726ee74816b0c63
Created: 2012/03/30 15:39:40
Detections: 1
Determination: Ignore detections (false positive)
- Boost by Reason as UnneededApp.Task.RealNetworks.L

---------------------------------------------------------------------------------

File path: c:\program files (x86)\real\realplayer\rpshellsearch.dll
Publisher: RealNetworks, Inc.
Signer: RealNetworks, Inc.
MD5: 349da22c6041814caafef472b65352f2
SHA-1: 2ff1371c7601a5784545b6646d1a68e16064f0f6
Created: 2012/04/26 17:23:17
Detections: 1
Determination: Ignore detections (false positive)
- Boost by Reason as UnneededApp.Handler.RealNetworks.N

---------------------------------------------------------------------------------

File path: c:\program files (x86)\real\realplayer\rpshell.dll
Publisher: RealNetworks, Inc.
Signer: RealNetworks, Inc.
MD5: 1efe683c6601479a474b7f5c03baf00e
SHA-1: be38622dffb08be71235c83b82e4173e5d26673e
Created: 2012/04/26 17:23:04
Detections: 1
Determination: Ignore detections (false positive)
- Boost by Reason as UnneededApp.RealNetworks.H

---------------------------------------------------------------------------------

File path: c:\program files (x86)\real\realplayer\netscape6\nprjplug.dll
Publisher: RealNetworks, Inc.
MD5: 19f4fce71557ebae19ce84bb4e077244
SHA-1: fc597499880117210d2c339cb025249b07e0a146
Created: 2012/04/26 17:23:19
Detections: 1
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Virus/Win32.Xpaj.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\googleupdate.exe.old3ce55
Publisher: Google Inc.
Signer: Google Inc
MD5: f02a533f517eb38333cb12a9e8963773
SHA-1: 258810d71436c5157cd0752bd13ce1de20f27eb2
Created: 2012/03/16 17:28:16
Detections: 1
Determination: Ignore detections (false positive)
- F-Prot as W32/Ransom.AD2.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\googleupdatesetup.exe5b856
Publisher: Google Inc.
Signer: Google Inc
MD5: a6f8d4fbc12177a75ab4c06d059229b6
SHA-1: 3403381c7fef04c040a96f0d19c6311b4826ad75
Created: 2013/09/13 15:17:40
Detections: 1
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Trojan/Win32.Generic (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\jre-7u51-windows-i586-iftw.exe
Publisher: Oracle Corporation
Signer: Sun Microsystems, Inc.
MD5: 5e8cb14f5264af82f66008306e56eaa8
SHA-1: 71ea58f2182f0cb5905bdda9867bba64c3848e7e
Created: 2013/12/20 2:06:54
Detections: 1
Determination: Ignore detections (false positive)
- XVirus List as Win.Detected (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\91a5tmp\dvd-decrypter-3.5.4.0.exe
Publisher:
MD5: 78d806097da8e8b8d595827cccddf6d9
SHA-1: 4cd617d8bdad9b2175b1cf688780945ec5f2335d
Created: 2014/12/10 19:22:00
Detections: 1
Determination: Ignore detections (false positive)
- XVirus List as Win.Detected (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\91a6tmp\vopackage.exe
Publisher:
MD5: dcc5d2ba63afd7fcade24a107e042633
SHA-1: 10923dbb409415da26ade6e9614295b8fd05365b
Created: 2014/12/10 19:22:02
Detections: 4
Determination: Adware
- McAfee Web Gateway as BehavesLike.Win32.Downloader.fc (Undefined)
- Rising Antivirus as NS:PUF.SilenceInstaller!1.9DDF (Undefined)
- Qihoo 360 Security as HEUR/QVM42.0.Malware.Gen (Undefined)
- Reason Heuristics as Adware.CMI.J (Adware)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\91a7tmp\setup.exe
Publisher: Xfyncgjzxbtxf & co.
Signer: Derzany Network
MD5: b5d34883c3a3ea7c7c795df9ac1bf350
SHA-1: f388079a9a30067916edcf8ab2fbfa91da093322
Created: 2014/12/10 19:22:00
Detections: 1
Determination: Adware
- Reason Heuristics as PUP.Installer.DerzanyNetwork.F (Adware)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\91aatmp\setup.exe
Publisher:
MD5: b92a43019a30a2ea990e91d56be97197
SHA-1: 41a4bcc481a51105d8636d1f3941c82026b37853
Created: 2014/12/10 19:22:00
Detections: 2
Determination: Inconclusive
- Clam AntiVirus as Win.Adware.Agent-32803 (Adware)
- McAfee Web Gateway as BehavesLike.Win32.Downloader.tc (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\comh.131593\googleupdate.exe
Publisher: globalUpdate
MD5: d858ba2ee718b1db1ced20646e641d08
SHA-1: 01c53fbc0030066fe9032fec431d9ea26b5811cc
Created: 2014/12/10 19:23:51
Detections: 1
Determination: Ignore detections (false positive)
- Qihoo 360 Security as Malware.QVM10.Gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\comh.131593\goopdate.dll
Publisher: globalUpdate
MD5: a8a32fe07817511aa30d05b46fe44549
SHA-1: 7fa369cc6af80f935bf91646dcc78e5f746c2ce4
Created: 2014/12/10 19:23:51
Detections: 1
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Trojan/Win32.SGeneric (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\comh.131593\npgoogleupdate4.dll
Publisher: globalUpdate
MD5: 8cc38d4600b4f51c4d54abdfd6889701
SHA-1: e66ace4eecf64cce06dab2d2ac00aa48774c4b1e
Created: 2014/12/10 19:23:51
Detections: 1
Determination: Inconclusive
- Avira AntiVirus as TR/Trash.Gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\mp970swin64ns102jp\win\res\cms_lib\data\instmsvcrt.exe
Publisher: canon
MD5: 43c6d6fd101d9cc5d3fd0c7687398465
SHA-1: b18943f0ee071f332db798484016d6b30855b4c0
Created: 2006/01/16 17:39:46
Detections: 1
Determination: Inconclusive
- Dr.Web as BackDoor.Tdss.6486 (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\mp970swin64ns102jp\win\res\message\croatian\msetres.dll
Publisher:
MD5: 2d741abbe361831e539c412e5d8817a6
SHA-1: 9e38018cd7e8440da645029ebf9c1741568f8668
Created: 2003/06/05 11:29:00
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/AutoRun.VB.bae (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\mp970swin64ns102jp\win\res\message\english\msetres.dll
Publisher:
MD5: 2d741abbe361831e539c412e5d8817a6
SHA-1: 9e38018cd7e8440da645029ebf9c1741568f8668
Created: 2003/06/05 11:29:00
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/AutoRun.VB.bae (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\mp970swin64ns102jp\win\res\message\estonian\msetres.dll
Publisher:
MD5: 2d741abbe361831e539c412e5d8817a6
SHA-1: 9e38018cd7e8440da645029ebf9c1741568f8668
Created: 2003/06/05 11:29:00
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/AutoRun.VB.bae (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\mp970swin64ns102jp\win\res\message\hungarian\msetres.dll
Publisher:
MD5: 237bafa5fd2c673f8c14b9542420ff86
SHA-1: a637a5d6d0f1d7182edda360b0733f84402d75cb
Created: 2003/06/05 11:57:38
Detections: 1
Determination: Ignore detections (false positive)
- Sunbelt AntiMalware as Trojan.Win32.Generic!BT (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\mp970swin64ns102jp\win\res\message\latvian\msetres.dll
Publisher:
MD5: 2d741abbe361831e539c412e5d8817a6
SHA-1: 9e38018cd7e8440da645029ebf9c1741568f8668
Created: 2003/06/05 11:29:00
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/AutoRun.VB.bae (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\mp970swin64ns102jp\win\res\message\lithuanian\msetres.dll
Publisher:
MD5: 2d741abbe361831e539c412e5d8817a6
SHA-1: 9e38018cd7e8440da645029ebf9c1741568f8668
Created: 2003/06/05 11:29:00
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/AutoRun.VB.bae (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\mp970swin64ns102jp\win\res\message\slovak\msetres.dll
Publisher:
MD5: 2d741abbe361831e539c412e5d8817a6
SHA-1: 9e38018cd7e8440da645029ebf9c1741568f8668
Created: 2003/06/05 11:29:00
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/AutoRun.VB.bae (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\mp970swin64ns102jp\win\res\message\slovenian\msetres.dll
Publisher:
MD5: 2d741abbe361831e539c412e5d8817a6
SHA-1: 9e38018cd7e8440da645029ebf9c1741568f8668
Created: 2003/06/05 11:29:00
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/AutoRun.VB.bae (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\mp970swin64ns102jp\win\res\message\spanish\msetres.dll
Publisher:
MD5: 0791d6f2f6aa4d5002d490cd707b22c3
SHA-1: 8fb8015e68953627810ab9a16e9b6ec30edd1cb8
Created: 2003/06/05 12:26:52
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/AutoRun.VB.bae (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\mp970swin64ns102jp\win\res\message\ukrainian\msetres.dll
Publisher:
MD5: 2d741abbe361831e539c412e5d8817a6
SHA-1: 9e38018cd7e8440da645029ebf9c1741568f8668
Created: 2003/06/05 11:29:00
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/AutoRun.VB.bae (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\start_seq\start_seq1.exe
Publisher: BUFFALO INC.
Signer: BUFFALO INC.
MD5: e2e814cec4c60e800eaf5b3607206509
SHA-1: 97932bbb835f471298d82193bd928de867fd18b7
Created: 2013/04/15 2:19:36
Detections: 1
Determination: Ignore detections (false positive)
- ByteHero BDV as Trojan.Malware.Win32.xPack.m (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\start_seq\start_seq2.exe
Publisher: BUFFALO INC.
Signer: BUFFALO INC.
MD5: e2e814cec4c60e800eaf5b3607206509
SHA-1: 97932bbb835f471298d82193bd928de867fd18b7
Created: 2013/04/15 2:19:36
Detections: 1
Determination: Ignore detections (false positive)
- ByteHero BDV as Trojan.Malware.Win32.xPack.m (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\{42d9ecd6-867c-48f8-9f15-3ad9425caa82}\googleupdate.exe
Publisher: Google Inc.
Signer: Google Inc
MD5: f02a533f517eb38333cb12a9e8963773
SHA-1: 258810d71436c5157cd0752bd13ce1de20f27eb2
Created: 2012/03/16 18:14:36
Detections: 1
Determination: Ignore detections (false positive)
- F-Prot as W32/Ransom.AD2.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\temp\{5f4ad21c-27f2-4e4c-b38e-dacb0178210c}\googleupdate.exe
Publisher: Google Inc.
Signer: Google Inc
MD5: f02a533f517eb38333cb12a9e8963773
SHA-1: 258810d71436c5157cd0752bd13ce1de20f27eb2
Created: 2012/03/16 17:28:12
Detections: 1
Determination: Ignore detections (false positive)
- F-Prot as W32/Ransom.AD2.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\syswow64\bwcontexthandler.dll
Publisher:
MD5: f4a1b4d4ccfd8eeef0259fae58cfae5c
SHA-1: 0136a1323e4f85c773e86e62caeb6dc90182179b
Created: 2009/07/14 8:42:10
Detections: 1
Determination: Ignore detections (false positive)
- Emsisoft Anti-Malware as Gen:Variant.Kazy.182960 (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\syswow64\iscsicpl.dll
Publisher: Microsoft Corporation
MD5: f945adcef203e6104aec8ec9c337cfd0
SHA-1: 85fe50b2c2fcbec2c09c5039c8f8c1d38523780a
Created: 2009/07/14 8:46:13
Detections: 1
Determination: Ignore detections (false positive)
- Bkav FE as W32.HfsAutoA (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\syswow64\netprof.dll
Publisher: Microsoft Corporation
MD5: 1fda175324fac331dc41b076103e7123
SHA-1: b791c2096df2ab3c6315e454022ac64c9fdb102d
Created: 2009/07/14 8:56:36
Detections: 1
Determination: Ignore detections (false positive)
- Bkav FE as W32.HfsAutoA (Undefined)

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\acrobat_10.1.4\3671\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 3cb07566302bceeb898de270a0bec175
SHA-1: 3c79cfc02e2e9877e164d1a7e856fa6bddb34c2f
Created: 2012/12/03 16:35:28
Detections: 1
Determination: Ignore detections (false positive)
- Rising Antivirus as PE:Malware.Sality!6.EDB (Undefined)

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\acrobat_10.1.6\14233\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\acrobat_10.1.6\27468\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\acrobat_10.1.6\6642\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\reader\9.4\arm\28503\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: b8e421c0890356cd4a793d8a346d9096
SHA-1: 30e85d80d9cefa4c55b33a1bfb6e0507a34267fa
Created: 2012/01/03 16:37:53
Detections: 2
Determination: Ignore detections (false positive)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I
- Antiy Labs AVL as Backdoor/Win32.Swrort.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\reader\9.4\arm\29963\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: b8e421c0890356cd4a793d8a346d9096
SHA-1: 30e85d80d9cefa4c55b33a1bfb6e0507a34267fa
Created: 2012/01/03 16:37:53
Detections: 2
Determination: Ignore detections (false positive)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I
- Antiy Labs AVL as Backdoor/Win32.Swrort.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\acrobat_10.1.4\3671\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 3cb07566302bceeb898de270a0bec175
SHA-1: 3c79cfc02e2e9877e164d1a7e856fa6bddb34c2f
Created: 2012/12/03 16:35:28
Detections: 1
Determination: Ignore detections (false positive)
- Rising Antivirus as PE:Malware.Sality!6.EDB (Undefined)

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\acrobat_10.1.6\14233\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\acrobat_10.1.6\27468\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\acrobat_10.1.6\6642\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\reader\9.4\arm\28503\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: b8e421c0890356cd4a793d8a346d9096
SHA-1: 30e85d80d9cefa4c55b33a1bfb6e0507a34267fa
Created: 2012/01/03 16:37:53
Detections: 2
Determination: Ignore detections (false positive)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I
- Antiy Labs AVL as Backdoor/Win32.Swrort.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\reader\9.4\arm\29963\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: b8e421c0890356cd4a793d8a346d9096
SHA-1: 30e85d80d9cefa4c55b33a1bfb6e0507a34267fa
Created: 2012/01/03 16:37:53
Detections: 2
Determination: Ignore detections (false positive)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I
- Antiy Labs AVL as Backdoor/Win32.Swrort.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\ue7vwrgw\appdata\local\microsoft\bass.dll
Publisher: Un4seen Developments
MD5: 8005750ec63eb5292884ad6183ae2e77
SHA-1: c83e31655e271cd9ef5bff62b10f8d51eb3ebf29
Created: 2013/07/26 17:14:45
Detections: 1
Determination: Ignore detections (false positive)
- Bkav FE as HW32.CDB (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files\daum\potplayer\mediainfo64.dll
Publisher: MediaArea.net
Signer: MediaArea.net
MD5: a523c7ae5b205a41d66bbec6e5d73b89
SHA-1: 9776ea95a601d00709ce44913272d6a1913adb60
Created: 2012/09/10 14:41:28
Detections: 1
Determination: Ignore detections (false positive)
- Emsisoft Anti-Malware as Gen:Trojan.Heur.FU.euW@a0Q59To (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\adobe\flash player\addins\airappinstaller\airappinstaller.exe
Publisher: Adobe Systems Inc.
Signer: Adobe Systems Incorporated
MD5: 77d4a137779db57638c9cb9048973b68
SHA-1: 7aedcb82953805344a0989b27afe7b80e3dbb0b9
Created: 2013/11/21 1:10:31
Detections: 1
Determination: Ignore detections (false positive)
- Rising Antivirus as PE:Malware.XPACK/RDM!5.1

---------------------------------------------------------------------------------

File path: c:\program files (x86)\aisoft\yonde\ydblock.dll
Publisher:
MD5: 22a65561ccdc8fc07be78edaf27b4cf7
SHA-1: 0e4ccf7cd92ceb03f04bf717f41e41a07a45bbeb
Created: 2013/09/15 2:03:15
Detections: 1
Determination: Ignore detections (false positive)
- IKARUS anti.virus as Trojan.Win32.Agent (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\apowersoft\video download capture\faac.exe
Publisher:
Signer: APOWERSOFT LIMITED
MD5: 7cbc489d9621888cb9920380689b5e15
SHA-1: be1627659e7aa9970e61b229ec8f1c4866fe6fed
Created: 2013/07/26 17:14:31
Detections: 4
Determination: Ignore detections (false positive)
- The Hacker as Posible_Worm32 (Undefined)
- Trend Micro House Call as TROJ_GEN.F47V1022 (Undefined)
- Trend Micro as PAK_Generic.001
- ViRobot as Trojan.Win32.A.Vilsel.150528.C[UPX] (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\apowersoft\video download capture\lame.exe
Publisher:
Signer: APOWERSOFT LIMITED
MD5: 5003df4e9cb7da5614f75fbd191692fd
SHA-1: 77be07626d71a0158aa237b827a53f2ec6866dae
Created: 2013/07/26 17:14:31
Detections: 2
Determination: Ignore detections (false positive)
- Trend Micro House Call as PAK_Generic.001
- Trend Micro as PAK_Generic.001

---------------------------------------------------------------------------------

File path: c:\program files (x86)\arcsoft\mediaimpression 2\captureengine.dll
Publisher: ArcSoft
Signer: ArcSoft, Inc.
MD5: 581dda6870e61fcb7a3f2b83df2c83f3
SHA-1: 7079748a6102eb289fcd6abd5fe74cb90f1014eb
Created: 2013/09/15 2:05:28
Detections: 1
Determination: Ignore detections (false positive)
- Prevx as Medium Risk Malware (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\arcsoft\mediaimpression 2\spotremove.dll
Publisher:
MD5: 5788c2f118a15443c4f6779351fb195e
SHA-1: 65eeaad16e7ee762890d109db00f7dd609df10dd
Created: 2013/09/15 2:05:37
Detections: 1
Determination: Ignore detections (false positive)
- Prevx as Medium Risk Malware (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\arcsoft\mediaimpression 2\plugins\action\slideshow\newmakeslideshow.dll
Publisher: ArcSoft Inc.
Signer: ArcSoft, Inc.
MD5: 2505befe8067f4387f11a2a9d5aeaed0
SHA-1: bffa190ff5f195b0522e5f200c2ba357da0ff901
Created: 2013/09/15 2:06:08
Detections: 1
Determination: Ignore detections (false positive)
- Prevx as Medium Risk Malware (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\buffalo\turbocopy\tpfccore.dll
Publisher: BUFFALO INC.
MD5: e17f9d8fe968a3d8e9556b93336aa9a9
SHA-1: 92ba02320c0dbe6e168f6b78bea9882a06e47816
Created: 2013/04/15 2:53:40
Detections: 1
Determination: Ignore detections (false positive)
- Rising Antivirus as PE:Trojan.Win32.Obfuscated.fqw!1075217832 (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\buffalo\turbocopy1\tcpyinst.exe
Publisher: BUFFALO INC.
Signer: BUFFALO INC.
MD5: de2ac0336409f320d2cd755ec2fbd4c1
SHA-1: 5b36ca8690d46a4be5cd218605d32f7fe5262b4f
Created: 2013/04/15 2:19:37
Detections: 1
Determination: Ignore detections (false positive)
- ByteHero BDV as Trojan.Malware.Win32.xPack.l (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\buffalo\turbocopy1\turbocopycheck.exe
Publisher: BUFFALO INC.
Signer: BUFFALO INC.
MD5: bcd7405070882fe303f58e07fab2666e
SHA-1: 6d43720885588c35453e2eddf3591e62a11a61ac
Created: 2013/04/15 2:19:37
Detections: 1
Determination: Ignore detections (false positive)
- ByteHero BDV as Trojan.Malware.Win32.xPack.m (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\buffalo\turbocopy1\x64\tpfccore.dll
Publisher: BUFFALO INC.
MD5: e17f9d8fe968a3d8e9556b93336aa9a9
SHA-1: 92ba02320c0dbe6e168f6b78bea9882a06e47816
Created: 2013/04/15 2:19:37
Detections: 1
Determination: Ignore detections (false positive)
- Rising Antivirus as PE:Trojan.Win32.Obfuscated.fqw!1075217832 (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\common files\adobe air\versions\1.0\resources\airappinstaller.exe
Publisher: Adobe Systems Inc.
Signer: Adobe Systems Incorporated
MD5: 77d4a137779db57638c9cb9048973b68
SHA-1: 7aedcb82953805344a0989b27afe7b80e3dbb0b9
Created: 2013/12/28 23:05:28
Detections: 1
Determination: Ignore detections (false positive)
- Rising Antivirus as PE:Malware.XPACK/RDM!5.1

---------------------------------------------------------------------------------

File path: c:\program files (x86)\common files\business objects\2.7\bin\crpe32_res_fr.dll
Publisher: Business Objects
MD5: 2b551a8a563c2bfd172ca15892f460b8
SHA-1: 3f953114c8ea590fa00142bede36ecb0b08408cb
Created: 2005/11/24 6:03:14
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/Olmarik.yx (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\common files\pfu\scansnap\scantooffice\scan2mailconfig.exe
Publisher: PFU LIMITED
MD5: 975bb9266d1e176a143018a55be9ea8f
SHA-1: 20de50c465612102d8c54241c0fcd65f1fe5924f
Created: 2012/06/05 17:00:37
Detections: 1
Determination: Ignore detections (false positive)
- AegisLab AV Signature as W32.W.Mabezat (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\common files\pfu\scansnap\scantooffice\scantocrop.exe
Publisher: PFU LIMITED
MD5: 13d24501ef5ce1aff3efe030ce3294fe
SHA-1: c3370551a9d6627fd9869387f0ebe0342ba1d1de
Created: 2012/06/05 17:00:38
Detections: 1
Determination: Ignore detections (false positive)
- Baidu Antivirus as [14:08:34] (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\common files\pfu\scansnap\scantooffice\scantoevjpg.exe
Publisher: PFU LIMITED
MD5: c9541de6fa26400d13bca2979a45648c
SHA-1: 81bf9186455d248bd7039547443b246c3776472b
Created: 2012/06/05 17:00:39
Detections: 1
Determination: Ignore detections (false positive)
- AegisLab AV Signature as W32.Expiro (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\common files\pfu\scansnap\scantooffice\scantoevpdf.exe
Publisher: PFU LIMITED
MD5: 4da7eda068cc349858a446a1f44ff4f3
SHA-1: f40c6b882fedc24e38320d36523e57517bba93ad
Created: 2012/06/05 17:00:39
Detections: 1
Determination: Ignore detections (false positive)
- AegisLab AV Signature as W32.Sality (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\common files\pfu\scansnap\scantooffice\scantopictureconfig.exe
Publisher: PFU LIMITED
MD5: dd32333d1f667d4ce3a3622595864f9f
SHA-1: 16bb9112306447bf542d7db3e5927985e181f2df
Created: 2012/06/05 17:00:40
Detections: 2
Determination: Ignore detections (false positive)
- AegisLab AV Signature as Troj.W32.Gen (Undefined)
- Emsisoft Anti-Malware as Android.Adware.Wapsx (Adware)

□HPログ以上です。
  • penpen
  • 2014/12/12 (Fri) 20:49:32
OTLログ1
□OTLログ1

OTL logfile created on: 2014/12/12 20:01:23 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\7y84qMCp\Desktop\相談用2014-12-11\ソフトウエア\OTL
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

7.98 Gb Total Physical Memory | 7.19 Gb Available Physical Memory | 90.15% Memory free
15.95 Gb Paging File | 15.22 Gb Available in Paging File | 95.42% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 685.05 Gb Free Space | 73.55% Space Free | Partition Type: NTFS

Computer Name: PC | User Name: uE7VWrGW | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2014/12/12 17:31:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\7y84qMCp\Desktop\相談用2014-12-11\ソフトウエア\OTL\OTL.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2014/11/22 11:35:29 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2014/11/07 02:14:48 | 001,148,744 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService)
SRV:[b]64bit:[/b] - [2014/11/07 02:14:44 | 019,819,848 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc)
SRV:[b]64bit:[/b] - [2013/09/12 12:06:22 | 001,337,752 | ---- | M] (ESET) [Auto | Stopped] -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe -- (ekrn)
SRV:[b]64bit:[/b] - [2013/05/27 14:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2012/05/17 00:00:00 | 000,144,560 | ---- | M] (Seiko Epson Corporation) [Auto | Stopped] -- C:\Windows\SysNative\escsvc64.exe -- (EpsonScanSvc)
SRV:[b]64bit:[/b] - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:[b]64bit:[/b] - [2009/07/14 10:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2014/12/11 09:47:09 | 000,114,800 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/12/10 21:20:58 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/12/03 10:06:32 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/11/07 02:14:48 | 001,795,912 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2014/11/04 05:25:06 | 000,410,952 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2014/08/10 17:50:13 | 000,093,800 | ---- | M] (SecureBrain Corporation) [Auto | Stopped] -- C:\Program Files (x86)\SecureBrain\PhishWall\sbpwupdx.exe -- (SecureBrain PhishWall Update)
SRV - [2014/03/21 07:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2013/12/18 01:56:16 | 000,754,712 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe -- (GoogleIMEJaCacheService)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/07/17 12:27:58 | 001,098,056 | ---- | M] (LULU Software Limited) [Auto | Stopped] -- C:\Program Files (x86)\Soda PDF 5\HelperService.exe -- (Soda PDF 5 Helper Service)
SRV - [2013/07/17 12:27:58 | 000,794,440 | ---- | M] (LULU Software Limited) [Auto | Stopped] -- C:\Program Files (x86)\Soda PDF 5\ConversionService.exe -- (Soda PDF 5 Service)
SRV - [2013/04/04 09:39:12 | 000,007,680 | ---- | M] (キヤノンマーケティングジャパン株式会社) [Auto | Stopped] -- C:\Program Files (x86)\CMJ\CSPTL-CANONMJ\CSPTL-CANONMJService.exe -- (CSPTL-CANONMJService)
SRV - [2013/03/01 10:48:58 | 000,118,520 | ---- | M] (Riverbed Technology, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WinPcap\rpcapd.exe -- (rpcapd)
SRV - [2011/11/15 09:22:00 | 000,470,528 | ---- | M] (Sony Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Sony\NFC Proxy Service\bin\NFCProxyService.exe -- (NFCProxyService)
SRV - [2011/09/14 22:06:38 | 000,169,624 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor10.0)
SRV - [2011/04/30 00:32:54 | 000,013,592 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2010/11/17 13:21:56 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010/11/17 13:21:54 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/03/18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2014/11/07 06:02:48 | 000,197,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:[b]64bit:[/b] - [2014/11/07 02:14:43 | 000,019,784 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
DRV:[b]64bit:[/b] - [2014/10/04 04:23:02 | 000,038,216 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:[b]64bit:[/b] - [2014/03/19 15:23:28 | 000,050,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:[b]64bit:[/b] - [2013/10/02 11:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2013/09/17 14:17:38 | 000,239,320 | ---- | M] (ESET) [File_System | System | Stopped] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:[b]64bit:[/b] - [2013/09/17 14:17:38 | 000,220,232 | ---- | M] (ESET) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\epfw.sys -- (epfw)
DRV:[b]64bit:[/b] - [2013/09/17 14:17:38 | 000,168,256 | ---- | M] (ESET) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:[b]64bit:[/b] - [2013/09/17 14:17:38 | 000,062,136 | ---- | M] (ESET) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\epfwwfp.sys -- (epfwwfp)
DRV:[b]64bit:[/b] - [2013/09/17 14:17:38 | 000,044,120 | ---- | M] (ESET) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\EpfwLWF.sys -- (EpfwLWF)
DRV:[b]64bit:[/b] - [2013/08/20 07:02:12 | 000,204,568 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:[b]64bit:[/b] - [2013/08/20 07:02:12 | 000,103,576 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:[b]64bit:[/b] - [2013/03/09 18:31:42 | 000,031,232 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:[b]64bit:[/b] - [2013/03/01 10:49:12 | 000,036,600 | ---- | M] (Riverbed Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
DRV:[b]64bit:[/b] - [2012/08/23 23:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2012/08/23 23:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2012/03/17 00:55:12 | 000,231,376 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\truecrypt.sys -- (truecrypt)
DRV:[b]64bit:[/b] - [2012/03/01 15:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2011/11/25 01:25:52 | 000,015,360 | ---- | M] (June Fabrics Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pneteth.sys -- (pneteth)
DRV:[b]64bit:[/b] - [2011/10/23 22:48:50 | 000,031,232 | ---- | M] (Faveset LLC) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tapklink.sys -- (tapklink)
DRV:[b]64bit:[/b] - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2011/06/02 14:47:22 | 000,177,640 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdm.sys -- (ssadmdm)
DRV:[b]64bit:[/b] - [2011/06/02 14:47:22 | 000,157,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus)
DRV:[b]64bit:[/b] - [2011/06/02 14:47:22 | 000,016,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV:[b]64bit:[/b] - [2011/04/26 11:07:36 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:[b]64bit:[/b] - [2011/04/13 18:30:54 | 000,207,872 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:[b]64bit:[/b] - [2011/04/13 18:30:50 | 000,087,552 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:[b]64bit:[/b] - [2011/03/11 15:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011/03/11 15:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2010/12/21 14:55:02 | 000,036,328 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadadb.sys -- (androidusb)
DRV:[b]64bit:[/b] - [2010/11/22 16:09:06 | 000,303,408 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mv91xx.sys -- (mv91xx)
DRV:[b]64bit:[/b] - [2010/11/22 16:09:06 | 000,024,880 | ---- | M] (Marvell Semiconductor Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mv91cons.sys -- (mv91cons)
DRV:[b]64bit:[/b] - [2010/11/21 12:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2010/11/21 12:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010/10/19 16:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:[b]64bit:[/b] - [2010/09/09 10:55:26 | 000,041,064 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sonyfelicaportm.sys -- (sonyfelicaportm)
DRV:[b]64bit:[/b] - [2010/09/07 10:37:26 | 000,121,432 | ---- | M] (JMicron Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID)
DRV:[b]64bit:[/b] - [2010/08/04 11:18:54 | 000,110,824 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Sonyddpu.sys -- (Sonyddpu)
DRV:[b]64bit:[/b] - [2010/03/19 03:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:[b]64bit:[/b] - [2010/01/20 10:08:22 | 000,016,000 | ---- | M] (BUFFALO INC.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bautpw64.sys -- (bautpw64)
DRV:[b]64bit:[/b] - [2009/11/18 07:12:00 | 000,032,344 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MBfilt64.sys -- (MBfilt)
DRV:[b]64bit:[/b] - [2009/07/14 10:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/14 10:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/14 10:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/07/14 09:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:[b]64bit:[/b] - [2009/07/14 06:59:33 | 005,020,672 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/11 05:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009/07/14 10:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\uE7VWrGW\Desktop
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=MOCJ&bmod=MOCJ
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.roboform.com
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MOCJ_jaJP475JP475
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1000\..\SearchScopes\{A9EA69E2-75E6-4E55-8FF3-E9045BBF40E3}: "URL" = http://search.jword.jp/cns.dll?type=jwd&fm=10&agent=&bypass=2&partner=AP&lang=utf8&name={searchTerms}
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\7y84qMCp\Desktop
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=MOCJ&bmod=MOCJ
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No CLSID value found
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\..\URLSearchHook: {2ACECADE-0BC7-4C6F-95CF-A221CC161B52} - No CLSID value found
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MOCJ_jaJP475JP475
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\..\SearchScopes\{84D1C035-8CC6-47D2-BDB9-CFA818C560DA}: "URL" = http://search.jword.jp/cns.dll?type=jwd&fm=10&agent=&bypass=2&partner=AP&lang=utf8&name={searchTerms}
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\..\SearchScopes\{A9EA69E2-75E6-4E55-8FF3-E9045BBF40E3}: "URL" = http://search.jword.jp/cns.dll?type=jwd&fm=10&agent=&bypass=2&partner=AP&lang=utf8&name={searchTerms}
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 199.200.120.37:7808

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.startup.homepage: "http://start.roboform.com"
FF - user.js - File not found

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.3.37: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.3.37: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.3.37: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.3.37: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.3.37: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\uE7VWrGW\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\uE7VWrGW\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\PROGRAM FILES\ESET\ESET SMART SECURITY\MOZILLA THUNDERBIRD [2014/03/20 20:02:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/04/26 17:23:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2014/12/11 06:52:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\FFSodaPDF5Converter@sodapdf.com: C:\Program Files (x86)\Soda PDF 5\FFSoda5Ext [2013/09/17 04:36:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2014/11/12 19:49:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/12/12 18:36:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012/03/17 23:12:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014/03/20 20:02:48 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2014/11/12 19:49:25 | 000,000,000 | ---D | M]

[2012/03/16 17:32:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\uE7VWrGW\AppData\Roaming\mozilla\Extensions
[2013/09/13 15:18:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\uE7VWrGW\AppData\Roaming\mozilla\Firefox\Profiles\1ga4id9q.default\extensions
[2014/12/11 09:46:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/12/11 09:47:10 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[color=#E56717]========== Chrome ==========[/color]

CHR - default_search_provider: (Enabled)
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://start.roboform.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\uE7VWrGW\AppData\Local\Google\Chrome\Application\36.0.1985.143\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\uE7VWrGW\AppData\Local\Google\Chrome\Application\36.0.1985.143\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\uE7VWrGW\AppData\Local\Google\Chrome\Application\36.0.1985.143\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\uE7VWrGW\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.31.137.7_0\McChPlg.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Windows Liveツ・Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~2\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\uE7VWrGW\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google 讀懃エ「 = C:\Users\uE7VWrGW\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\uE7VWrGW\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Google 繧ヲ繧ゥ繝ャ繝・ヨ = C:\Users\uE7VWrGW\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Evernote Web Clipper = C:\Users\uE7VWrGW\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\6.2.6_0\
CHR - Extension: Gmail = C:\Users\uE7VWrGW\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: RoboForm = C:\Users\uE7VWrGW\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob\7.9.9.2_0\

O1 HOSTS File: ([2013/05/15 22:17:40 | 000,000,822 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (楽天ツールバー ブラウザヘルパ オブジェクト) - {227B8061-B95B-4092-9C9B-6CE5759EE8E5} - C:\Program Files (x86)\RakutenToolbar\RTBHelper_64.dll (Rakuten Inc.)
O2:[b]64bit:[/b] - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL File not found
O2:[b]64bit:[/b] - BHO: (RoboForm Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O2:[b]64bit:[/b] - BHO: (Google Analytics オプトアウト アドオン) - {75EF13CE-B59E-41ba-8A5A-A944031BD8B4} - C:\Program Files\Google\Google Analytics Opt-Out\gaoptout_x64.dll (Google, Inc.)
O2:[b]64bit:[/b] - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (楽天ツールバー ブラウザヘルパ オブジェクト) - {227B8061-B95B-4092-9C9B-6CE5759EE8E5} - C:\Program Files (x86)\RakutenToolbar\RTBHelper_32.dll (Rakuten Inc.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll File not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (CmjBrowserHelperObject Object) - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll (Mindjet)
O2 - BHO: (RoboForm Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Google Analytics オプトアウト アドオン) - {75EF13CE-B59E-41ba-8A5A-A944031BD8B4} - C:\Program Files (x86)\Google\Google Analytics Opt-Out\gaoptout.dll (Google, Inc.)
O2 - BHO: (PhishWall) - {8CA7E745-EF75-4E7B-BB86-8065C0CE29CA} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll (SecureBrain Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Soda PDF 5 IE Helper) - {C737F472-1193-4281-BF53-A00B67AB3E19} - C:\Program Files (x86)\Soda PDF 5\PDFIEHelper.dll (LULU Software Limited)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (楽天ツールバー) - {4FD20E5F-825F-476F-8B45-5E3FF6502692} - C:\Program Files (x86)\RakutenToolbar\RakutenToolbar_64.dll (Rakuten Inc.)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (&RoboForm Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (楽天ツールバー) - {4FD20E5F-825F-476F-8B45-5E3FF6502692} - C:\Program Files (x86)\RakutenToolbar\RakutenToolbar_32.dll (Rakuten Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (PhishWall) - {BB62FFF4-41CB-4AFC-BB8C-2A4D4B42BBDC} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll (SecureBrain Corporation)
O3 - HKLM\..\Toolbar: (Soda PDF 5 IE Toolbar) - {F335ABA2-FDB4-4644-92B2-5CC4B0FC91D6} - C:\Program Files (x86)\Soda PDF 5\PDFIEPlugin.dll (LULU Software Limited)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:[b]64bit:[/b] - HKU\S-1-5-21-3766951078-1282058513-496642304-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:[b]64bit:[/b] - HKU\S-1-5-21-3766951078-1282058513-496642304-1000\..\Toolbar\WebBrowser: (&RoboForm Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-21-3766951078-1282058513-496642304-1000\..\Toolbar\WebBrowser: (&RoboForm Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3:[b]64bit:[/b] - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:[b]64bit:[/b] - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\..\Toolbar\WebBrowser: (&RoboForm Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\..\Toolbar\WebBrowser: (&RoboForm Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-21-3766951078-1282058513-496642304-1003\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4:[b]64bit:[/b] - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:[b]64bit:[/b] - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:[b]64bit:[/b] - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:[b]64bit:[/b] - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:[b]64bit:[/b] - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [Backup Utility TaskTray Tool] "C:\Program Files (x86)\BUFFALO\Backup_Utility\BUTray.exe" File not found
O4 - HKLM..\Run: [BuffaloTools] C:\Program Files (x86)\BUFFALO\BuffaloTools\BuffaloTools.exe (BUFFALO INC.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [CSPTL-CANONMJ] C:\Program Files (x86)\CMJ\CSPTL-CANONMJ\CSPTL-CANONMJ.exe (キヤノンマーケティングジャパン株式会社)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Eject Utility] C:\Program Files (x86)\BUFFALO\Eject_Utility\Eject_Utility.exe (BUFFALO INC.)
O4 - HKLM..\Run: [FeliCa Launcher] C:\Program Files (x86)\Sony\FeliCa Launcher\FeliCaLauncher.exe (Sony Corporation)
O4 - HKLM..\Run: [Google Japanese Input Prelauncher] C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe (Google Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 8\MmReminderService.exe (Mindjet)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ScanSnap WIA Service Checker] C:\Windows\SSDriver\fi5110\SsWiaChecker.exe (PFU LIMITED)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3766951078-1282058513-496642304-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-3766951078-1282058513-496642304-1000..\Run: [RakutenToolbarHelper] C:\Program Files (x86)\RakutenToolbarHelper\RakutenToolbarHelper.exe (Rakuten Inc.)
O4 - HKU\S-1-5-21-3766951078-1282058513-496642304-1000..\Run: [RoboForm] C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKU\S-1-5-21-3766951078-1282058513-496642304-1003..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-3766951078-1282058513-496642304-1003..\Run: [RakutenToolbarHelper] C:\Program Files (x86)\RakutenToolbarHelper\RakutenToolbarHelper.exe (Rakuten Inc.)
O4 - HKU\S-1-5-21-3766951078-1282058513-496642304-1003..\Run: [RoboForm] C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-3766951078-1282058513-496642304-1000..\RunOnce: [Adobe Speed Launcher] 1418267868 File not found
O4 - Startup: C:\Users\7y84qMCp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bkchime.lnk = File not found
O4 - Startup: C:\Users\7y84qMCp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CLaunch.lnk = File not found
O4 - Startup: C:\Users\7y84qMCp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Clibor.lnk = File not found
O4 - Startup: C:\Users\7y84qMCp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = File not found
O4 - Startup: C:\Users\7y84qMCp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EmEditor.lnk = File not found
O4 - Startup: C:\Users\7y84qMCp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = File not found
O4 - Startup: C:\Users\uE7VWrGW\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:[b]64bit:[/b] - Extra context menu item: RF ツールバー表示 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComShowToolbar.html File not found
O8:[b]64bit:[/b] - Extra context menu item: RF フォーム記入 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComFillForms.html File not found
O8:[b]64bit:[/b] - Extra context menu item: RF フォーム保存 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComSavePass.html File not found
O8:[b]64bit:[/b] - Extra context menu item: RF メニューカスタマイズ - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComCustomizeIEMenu.html File not found
O8 - Extra context menu item: RF ツールバー表示 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComShowToolbar.html File not found
O8 - Extra context menu item: RF フォーム記入 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComFillForms.html File not found
O8 - Extra context menu item: RF フォーム保存 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComSavePass.html File not found
O8 - Extra context menu item: RF メニューカスタマイズ - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComCustomizeIEMenu.html File not found
O9:[b]64bit:[/b] - Extra Button: フォーム記入 - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : RF フォーム記入 - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:[b]64bit:[/b] - Extra Button: 保存 - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : RF フォーム保存 - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:[b]64bit:[/b] - Extra Button: ツールバー表示 - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : RF ツールバー表示 - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9 - Extra Button: Mindjet MindManager に送信 - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll (Mindjet)
O9 - Extra Button: フォーム記入 - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : RF フォーム記入 - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: 保存 - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : RF フォーム保存 - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: ツールバー表示 - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : RF ツールバー表示 - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://qtinstall.apple.com/qtactivex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {0C687FA8-9672-4D77-9AF5-FD6B49C7EDC0} http://shangrila.dotbook.jp/update/t-time_plug/T-TimePlugIn.cab (TTimePlug Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.3.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{534735A2-0DDC-4253-9130-2F8EE4F3DCFE}: NameServer = 31.168.224.106,5.135.12.52
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9070DD1E-0137-4A0A-A35A-EC32FB9EAB10}: NameServer = 31.168.224.106,5.135.12.52
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E1159A60-0C42-4206-8E45-F388EF9330D3}: DhcpNameServer = 192.168.3.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E1159A60-0C42-4206-8E45-F388EF9330D3}: NameServer = 31.168.224.106,5.135.12.52
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E18D3B35-A78A-4B30-82EA-E3CD6906B2A5}: NameServer = 31.168.224.106,5.135.12.52
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084

  • penpen
  • 2014/12/12 (Fri) 20:52:44
OTLログ2
□OTLログ2

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2014/12/12 19:55:20 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2014/12/12 18:21:17 | 000,000,000 | ---D | C] -- C:\Program Files\Reason
[2014/12/12 17:44:42 | 000,772,544 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2014/12/12 17:44:42 | 000,687,544 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2014/12/11 10:14:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2014/12/11 10:14:38 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2014/12/11 09:46:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2014/12/11 06:29:12 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appraiser
[2014/12/11 06:13:44 | 004,121,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2014/12/11 06:13:44 | 003,209,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2014/12/10 21:37:28 | 000,000,000 | ---D | C] -- C:\Users\uE7VWrGW\AppData\Local\NPE
[2014/12/10 21:37:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2014/12/10 19:23:52 | 000,000,000 | ---D | C] -- C:\Users\uE7VWrGW\AppData\Local\globalUpdate
[2014/12/10 19:23:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\globalUpdate
[2014/12/10 18:51:14 | 000,718,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/12/10 18:51:14 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/12/10 18:51:14 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2014/12/10 18:51:14 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014/12/10 18:51:14 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2014/12/10 18:51:14 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/12/10 18:51:14 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/12/10 18:51:14 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/12/10 18:51:14 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/12/10 18:51:13 | 002,052,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/12/10 18:51:13 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/12/10 18:51:13 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/12/10 18:51:12 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2014/12/10 18:51:12 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/12/10 18:51:12 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/12/10 18:51:12 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/12/10 18:51:12 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/12/10 18:51:12 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2014/12/10 18:51:12 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/12/10 18:51:12 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/12/10 18:51:12 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/12/10 18:51:11 | 002,125,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/12/10 18:51:11 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2014/12/10 18:51:10 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/12/10 18:51:10 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014/12/10 18:51:10 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/12/10 18:51:10 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/12/10 18:51:10 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2014/12/10 18:51:09 | 006,039,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/12/10 18:51:09 | 001,359,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2014/12/10 18:51:09 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/12/10 18:51:09 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014/12/10 18:51:08 | 000,580,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014/12/10 18:51:08 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/12/10 18:51:08 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2014/12/10 18:23:24 | 001,232,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aitstatic.exe
[2014/12/10 18:23:24 | 001,083,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2014/12/10 18:23:24 | 000,830,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appraiser.dll
[2014/12/10 18:23:24 | 000,741,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\invagent.dll
[2014/12/10 18:23:24 | 000,413,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll
[2014/12/10 18:23:24 | 000,396,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\devinv.dll
[2014/12/10 18:23:24 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepic.dll
[2014/12/10 18:23:23 | 000,227,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2014/12/10 18:21:58 | 001,424,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll
[2014/12/10 18:16:45 | 000,165,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\charmap.exe
[2014/12/10 18:16:45 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\charmap.exe
[2014/12/10 18:16:43 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSManMigrationPlugin.dll
[2014/12/10 18:16:43 | 000,310,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmWmiPl.dll
[2014/12/10 18:16:43 | 000,266,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSManHTTPConfig.exe
[2014/12/10 18:16:42 | 000,248,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManMigrationPlugin.dll
[2014/12/10 18:16:42 | 000,214,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmWmiPl.dll
[2014/12/10 18:16:42 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManHTTPConfig.exe
[2014/12/10 18:16:42 | 000,181,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmAuto.dll
[2014/12/10 18:16:42 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmAuto.dll
[2014/11/27 03:11:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMPlayer
[2014/11/19 04:31:16 | 001,217,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FM20.DLL

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2014/12/12 19:56:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/12/12 19:56:12 | 2129,919,999 | -HS- | M] () -- C:\hiberfil.sys
[2014/12/12 19:52:04 | 000,000,626 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/12/12 19:49:28 | 000,030,496 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/12/12 19:49:28 | 000,030,496 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/12/12 19:42:10 | 000,000,686 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1cef293c8757a17.job
[2014/12/12 19:34:00 | 000,000,712 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3766951078-1282058513-496642304-1003UA1cf8bb8a33b50de.job
[2014/12/12 19:24:00 | 000,000,712 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3766951078-1282058513-496642304-1000UA1cf1ccc5e9ff9fb.job
[2014/12/11 12:24:00 | 000,000,660 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3766951078-1282058513-496642304-1000Core1cf1ccc5e85cad8.job
[2014/12/11 10:14:40 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/12/11 06:52:28 | 000,002,044 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Acrobat X Standard.lnk
[2014/12/10 21:20:58 | 000,701,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014/12/10 21:20:58 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014/12/09 03:34:00 | 000,000,660 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3766951078-1282058513-496642304-1003Core1ce7fa574d63e39.job
[2014/12/04 11:50:55 | 000,413,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll
[2014/12/04 11:50:45 | 000,741,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\invagent.dll
[2014/12/04 11:50:40 | 000,396,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\devinv.dll
[2014/12/04 11:50:38 | 000,830,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\appraiser.dll
[2014/12/04 11:50:37 | 000,227,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2014/12/04 11:50:37 | 000,192,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aepic.dll
[2014/12/04 11:44:48 | 001,083,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2014/12/02 08:28:44 | 001,232,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aitstatic.exe
[2014/12/01 15:59:08 | 001,313,238 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/12/01 15:59:08 | 000,654,270 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/12/01 15:59:08 | 000,411,178 | ---- | M] () -- C:\Windows\SysNative\perfh011.dat
[2014/12/01 15:59:08 | 000,122,224 | ---- | M] () -- C:\Windows\SysNative\perfc011.dat
[2014/12/01 15:59:08 | 000,122,142 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/11/22 12:06:11 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/11/22 11:50:39 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/11/22 11:50:10 | 000,580,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014/11/22 11:49:54 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/11/22 11:48:20 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2014/11/22 11:40:41 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/11/22 11:37:10 | 000,633,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/11/22 11:35:43 | 000,144,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/11/22 11:35:29 | 000,114,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/11/22 11:34:51 | 000,814,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/11/22 11:34:07 | 006,039,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/11/22 11:26:31 | 000,968,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2014/11/22 11:22:40 | 000,490,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014/11/22 11:14:16 | 000,077,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2014/11/22 11:09:12 | 000,199,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/11/22 11:08:06 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014/11/22 11:07:17 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/11/22 11:06:32 | 000,047,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/11/22 11:05:02 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2014/11/22 11:05:01 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2014/11/22 10:58:54 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/11/22 10:56:40 | 000,478,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/11/22 10:55:16 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/11/22 10:54:30 | 000,620,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/11/22 10:49:29 | 000,718,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/11/22 10:49:28 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/11/22 10:47:10 | 001,359,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2014/11/22 10:46:58 | 002,125,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/11/22 10:40:04 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2014/11/22 10:36:14 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/11/22 10:35:24 | 000,076,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014/11/22 10:22:49 | 002,052,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/11/22 10:21:57 | 001,155,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2014/11/22 10:03:42 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/11/22 09:54:44 | 000,710,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/11/19 04:31:16 | 001,217,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\FM20.DLL
[2014/11/13 22:29:14 | 000,000,690 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA1cf4d81edaddbf2.job
[2014/11/12 23:08:52 | 000,370,536 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2014/12/11 10:14:40 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/12/11 06:52:28 | 000,002,044 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Acrobat X Standard.lnk
[2014/02/26 10:48:19 | 001,292,086 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/04/17 20:47:32 | 000,012,910 | ---- | C] () -- C:\Windows\UN120911.INI
[2013/04/17 20:28:04 | 000,014,907 | ---- | C] () -- C:\Windows\UN080616.INI
[2013/04/15 02:54:09 | 000,005,721 | ---- | C] () -- C:\Windows\UN120119.INI
[2013/04/15 02:53:40 | 000,014,252 | ---- | C] () -- C:\Windows\UN091114.INI
[2013/04/15 02:53:34 | 000,013,773 | ---- | C] () -- C:\Windows\UN091201.INI
[2013/03/01 10:47:36 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009/07/14 13:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/06/25 11:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/25 10:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 10:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 12:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 10:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC]< %windir%\tasks\*.job >[/color]
[2014/12/12 19:52:04 | 000,000,626 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/12/12 19:42:10 | 000,000,686 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1cef293c8757a17.job
[2014/11/13 22:29:14 | 000,000,690 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA1cf4d81edaddbf2.job
[2014/12/11 12:24:00 | 000,000,660 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3766951078-1282058513-496642304-1000Core1cf1ccc5e85cad8.job
[2014/12/12 19:24:00 | 000,000,712 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3766951078-1282058513-496642304-1000UA1cf1ccc5e9ff9fb.job
[2014/12/09 03:34:00 | 000,000,660 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3766951078-1282058513-496642304-1003Core1ce7fa574d63e39.job
[2014/12/12 19:34:00 | 000,000,712 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3766951078-1282058513-496642304-1003UA1cf8bb8a33b50de.job

[color=#E56717]========== Drive Information ==========[/color]

Physical Drives
---------------

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: ST1000DM003-9YN162
Partitions: 2
Status: OK
Status Info: 0

Partitions
---------------

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 931.00GB
Starting Offset: 105906176
Hidden sectors: 0


[color=#E56717]========== Base Services ==========[/color]
SRV:[b]64bit:[/b] - [2009/07/14 10:40:01 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc)
SRV:[b]64bit:[/b] - [2013/02/27 14:47:10 | 000,070,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:[b]64bit:[/b] - [2009/07/14 10:38:55 | 000,079,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:51 | 000,849,920 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:00 | 000,705,024 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:[b]64bit:[/b] - [2014/04/12 11:19:05 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (KeyIso)
SRV:[b]64bit:[/b] - [2009/07/14 10:40:50 | 000,402,944 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV - [2009/07/14 10:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV:[b]64bit:[/b] - [2012/07/05 07:13:27 | 000,136,704 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:[b]64bit:[/b] - [2014/07/07 11:06:31 | 000,187,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV - [2014/07/07 10:40:07 | 000,143,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\cryptsvc.dll -- (CryptSvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:00 | 000,317,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV - [2010/11/21 12:24:09 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV:[b]64bit:[/b] - [2011/03/03 15:24:16 | 000,183,296 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:[b]64bit:[/b] - [2009/07/14 10:40:35 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\eapsvc.dll -- (EapHost)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:00 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV - [2009/07/14 10:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:48 | 000,501,248 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:[b]64bit:[/b] - [2009/07/14 10:41:54 | 000,524,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:52 | 000,459,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netprofm.dll -- (netprofm)
SRV - [2009/07/14 10:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\netprofm.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2012/10/04 02:44:21 | 000,303,104 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:53 | 000,025,600 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:[b]64bit:[/b] - [2011/05/24 20:42:55 | 000,404,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:[b]64bit:[/b] - [2012/02/11 15:36:02 | 000,559,104 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
SRV:[b]64bit:[/b] - [2014/04/12 11:19:05 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV:[b]64bit:[/b] - [2009/07/14 10:41:53 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:17 | 000,344,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:[b]64bit:[/b] - [2014/04/12 11:19:05 | 000,031,232 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:58 | 000,097,280 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:48 | 000,236,032 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:55 | 000,370,688 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV - [2010/11/21 12:24:03 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV:[b]64bit:[/b] - [2010/11/21 12:24:16 | 001,110,016 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:32 | 000,316,928 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV - [2010/11/21 12:24:00 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:[b]64bit:[/b] - [2012/05/01 14:40:20 | 000,209,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:55 | 001,600,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:[b]64bit:[/b] - [2014/10/03 11:11:51 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\audiosrv.dll -- (AudioSrv)
SRV:[b]64bit:[/b] - [2014/10/03 11:11:51 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\audiosrv.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2010/11/21 12:25:06 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
SRV:[b]64bit:[/b] - [2013/05/27 14:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:55 | 001,646,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (eventlog)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:28 | 000,828,416 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:48 | 000,580,096 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:15 | 000,128,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver)
SRV - [2010/11/21 12:24:28 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:56 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:[b]64bit:[/b] - [2014/05/15 01:23:46 | 002,477,536 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:09 | 000,252,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:56 | 000,886,784 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlansvc.dll -- (Wlansvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:32 | 000,118,784 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

< End of report >

OTLログ以上です
  • penpen
  • 2014/12/12 (Fri) 20:54:14
OTL Extrasログ
□OTL Extrasログ

OTL Extras logfile created on: 2014/12/12 20:01:23 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\7y84qMCp\Desktop\相談用2014-12-11\ソフトウエア\OTL
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

7.98 Gb Total Physical Memory | 7.19 Gb Available Physical Memory | 90.15% Memory free
15.95 Gb Paging File | 15.22 Gb Available in Paging File | 95.42% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 685.05 Gb Free Space | 73.55% Space Free | Partition Type: NTFS

Computer Name: PC | User Name: uE7VWrGW | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.txt[@ = emeditor.txt] -- C:\Program Files\EmEditor\EMEDITOR.EXE (Emurasoft, Inc.)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
.txt [@ = emeditor.txt] -- C:\Program Files\EmEditor\EMEDITOR.EXE (Emurasoft, Inc.)

[HKEY_USERS\S-1-5-21-3766951078-1282058513-496642304-1003\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML.7y84qMCp] -- Reg Error: Key error. File not found

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[color=#E56717]========== Authorized Applications List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03367EA4-39AE-49A4-82FE-1C59C4C25F92}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{04E5A73C-AE1F-43B2-9639-C79E49D386D1}" = rport=10243 | protocol=6 | dir=out | app=system |
"{07AC1B17-D9DD-4F4B-B65E-B09049DF6497}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe |
"{0AD7F3AB-0406-4282-9E2F-158708B4E299}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{24B61050-4D4B-4720-AE41-EA37F1BA3937}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{267E83E0-0A36-4180-BA20-440730B331E1}" = rport=137 | protocol=17 | dir=out | app=system |
"{46514A52-EFD3-428D-9656-EE0B2B3FB441}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4CF99673-CA92-4C90-BCB0-9288FE58E800}" = lport=139 | protocol=6 | dir=in | app=system |
"{4D7C5A5C-D1FC-4629-9AC6-C3F78363A6AA}" = lport=445 | protocol=6 | dir=in | app=system |
"{4DD7D590-48C6-49C4-B2CD-8823FC6EB867}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{568690B7-30AC-4D5E-8D0A-03B875615145}" = rport=445 | protocol=6 | dir=out | app=system |
"{59CB239B-6B23-40A8-A8C8-55A0587E2D11}" = lport=47984 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{762AEA19-37C9-4A70-A389-5CBF48E54CD1}" = lport=2869 | protocol=6 | dir=in | app=system |
"{87A0CC15-D528-4470-82CF-CB7905495063}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{97958022-38C3-4D39-8369-E3582AAFFA54}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9BF8B71F-F810-4981-8CFA-0BEB5919EB6E}" = rport=138 | protocol=17 | dir=out | app=system |
"{ACE513D4-BB93-4668-A63E-3E34D8246CCC}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B2E4C173-AB04-41D5-9DD6-D1E3972CFE02}" = lport=10243 | protocol=6 | dir=in | app=system |
"{B5A8517B-B27E-443A-8A87-C158A44F6E3B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{B724F0B1-3F2B-47D4-B07F-0EC08677966D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BD411963-FFE7-4C10-B411-0AE534132AF6}" = lport=138 | protocol=17 | dir=in | app=system |
"{BEC5B926-0977-45F4-867F-9B6BA96B3402}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{CBC80E0B-8235-42CB-BC7B-C2E16CCED908}" = rport=139 | protocol=6 | dir=out | app=system |
"{CDDBCBB6-6494-40A8-950F-7213DED9960B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DC4B0F49-5738-4050-B751-960AF0C8B992}" = lport=137 | protocol=17 | dir=in | app=system |
"{E97D4D58-262D-4806-978A-031EFF53A377}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{ED52FE8B-57DD-42F2-8A64-2BDD7F929DAA}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{F8F36158-E608-4A81-B714-4497A5A47C63}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe |
"{FF351E5A-60BA-45DF-82CA-63FAA435A403}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{079985C6-BF53-4790-9513-A0F36B3E8C05}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{07C36BCD-F714-4DED-9EBF-C3774ED1B2CF}" = dir=out | app=c:\program files (x86)\apowersoft\video download capture\apowersoftsrv.dll |
"{0FEAC8FD-B381-4FB8-AAD9-8C16393414BA}" = dir=out | app=c:\program files (x86)\apowersoft\video download capture\apowersoftdump.dll |
"{1270258D-E6A8-4657-B308-A166F933EDDD}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{13317556-D389-4A42-B2FA-2C7957379583}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1353806F-ABEE-405A-93D7-9B4A3E77F80D}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{1B08327E-0712-49C3-83AD-AFF784F67B9F}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe |
"{1BF6F7E7-9E72-441F-ACC3-30344E4F2252}" = protocol=6 | dir=in | app=c:\program files (x86)\clockworkmod\tether\win32\node.exe |
"{1CEBAE74-EDBD-40AF-A46A-9098F845A1B7}" = protocol=17 | dir=in | app=c:\users\7y84qmcp\appdata\roaming\dropbox\bin\dropbox.exe |
"{2306A424-BFD4-40CC-B104-0B3239136D16}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{25D3DA75-3AF5-4F4C-9EAE-239CA46D47A4}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{268651A0-2A1B-4B9D-9623-B51EC0A98484}" = dir=out | app=c:\program files (x86)\apowersoft\video download capture\apowersoftac.dll |
"{285AAA3B-A28C-43B5-945F-F92F25A46221}" = dir=out | app=c:\program files (x86)\apowersoft\video download capture\apowersoftplayer.dll |
"{29F149BA-0D2E-4579-937A-B2F60BECF915}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{2C09EA7C-9788-4919-9F08-52388FCD2EF7}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2C580828-D76C-4FF3-BBDC-C09739F993BD}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{2F52D314-E7F8-49DB-B1CA-5AD488169DAB}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{2FBCD65A-66F7-4858-99DB-ED7076B3F7C1}" = dir=out | app=c:\program files (x86)\apowersoft\video download capture\video download capture.exe |
"{369A776C-380A-45D8-BB6F-0B7919724C7D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{3A90E08C-AB0B-4EF4-AACA-356DCBFA4EB9}" = protocol=6 | dir=out | app=system |
"{3A9AB65F-03C2-4694-B5C7-EAFE6A035E9B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{45F7A51F-1247-4FC0-B848-E9465E485B9E}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{4C99FD8B-D5CF-407C-ACBB-53E7C781F1FD}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe |
"{5241AED6-B337-433D-AF48-FD04DD7928F2}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{5517B89E-69EA-4601-B290-F12EF315795D}" = dir=in | app=c:\program files (x86)\apowersoft\video download capture\apowersoftplayer.dll |
"{597087E8-60A7-4349-9EBB-A74FC5179FF3}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{5B640CA7-979C-415A-9BB8-A05F08232922}" = dir=in | app=c:\program files (x86)\apowersoft\video download capture\video download capture.exe |
"{5B8A7C18-EDFB-4222-A3D2-6D904A2E442E}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{5E6310F1-7A44-45DA-B7AA-A6F0A8A04132}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5FB30B1F-0B90-42B8-B413-E842F443CC23}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{77BC0546-EFDD-45EF-BEEC-6354A79DAB32}" = dir=in | app=c:\program files (x86)\apowersoft\video download capture\apowersoftac.dll |
"{79D21D64-3206-4B93-B993-B3213EB148B7}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{81D0422D-CBD5-47B0-B7BF-97FE0F878AC1}" = dir=out | app=c:\program files (x86)\apowersoft\video download capture\apowersoftdownloaderhelp.dll |
"{85B53895-A432-4817-8FD1-87B9E986D052}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9A8897D3-1180-4D1E-BF09-2CBBC446D145}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9FECA422-9C41-4634-B6C4-4FC03965A23F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A5E0769B-5C30-43DB-92A9-8BFEEAC3BEE0}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{AC9CE915-7257-4B46-AD9B-BD81C2AFF881}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AF7499B9-829B-46D5-A10F-D3F32F6B59CD}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{AFA74251-3FE4-4670-B401-6CBA3F358E5A}" = dir=in | app=c:\program files (x86)\apowersoft\video download capture\apowersoftdownloaderhelp.dll |
"{B058B6B6-7D39-4BC9-AC09-E90AD85489E2}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{B2B1B835-1171-4D32-AA47-8D8F93192D5E}" = protocol=17 | dir=in | app=c:\program files (x86)\clockworkmod\tether\win32\node.exe |
"{B4B6D530-DD39-499E-BFC1-D6D7F0581259}" = dir=in | app=c:\program files (x86)\buffalo\broadstationutility\lpsetup.exe |
"{B7F945DF-D513-41E4-8C1A-3D3A76146B2C}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{BCF85B01-2B47-4359-A0F2-E5291D5C1A25}" = protocol=6 | dir=in | app=c:\users\7y84qmcp\appdata\roaming\dropbox\bin\dropbox.exe |
"{C4A21540-4195-48D2-9E8E-9D3B30BE9F08}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr8.exe |
"{CC89B04A-6964-4C53-B357-008CDB23B39C}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{D4A95CC9-518C-429D-B301-2A0259B68A67}" = dir=in | app=c:\program files (x86)\apowersoft\video download capture\apowersoftsrv.dll |
"{E0173208-0E10-490F-AEA8-E175596AF6C8}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{E2661B8C-22D6-4FB7-AF4C-3C8F069D9144}" = dir=in | app=c:\program files (x86)\apowersoft\video download capture\apowersoftdump.dll |
"{ED1B1B20-9712-4AB7-AEB6-50CCE7360255}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F59D2545-3BCD-42F0-AC56-EAA3E095277B}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{FB0AFA9D-E8A0-451C-95A5-2B37128C0B64}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{FDD1D8C7-4D50-4A27-A8EF-900EFDA3A3C6}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{FFCC16E2-2487-40D0-BA00-8D3BACA4D16A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{D23A9060-3144-465B-9E5F-97146A5FE0EA}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"UDP Query User{9D889A20-4A7E-4F16-B2A9-2631EAD6C7A0}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2700_series" = Canon iP2700 series Printer Driver
"{1AAF6669-31B2-3840-9346-F0F653840FD1}" = Microsoft .NET Framework 4.5.1 (JPN)
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{23D2AFC7-C01E-4413-9D9A-0BABF52569BF}" = Microsoft マウス キーボード センター
"{3BF2C0A8-2C44-4A36-AA96-3BD6FB7BB01F}" = Windows Live Remote Client Resources
"{54C5B89F-0A8C-4C07-A51D-7380974DA459}" = Windows Live Remote Service Resources
"{5EA12CF3-8162-47F6-ACAF-45AD03EFB08F}" = Adobe PDF iFilter 9 for 64-bit platforms
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{634345DF-42AC-4967-83CD-09DF2A81FABA}" = ESET Smart Security
"{6A1E4EFB-3EE0-40A0-9D6D-E865370289DB}" = Google 日本語入力
"{6D80AAE7-FF65-4950-B1CA-3A7EA4995574}_is1" = Adobe Reader 64-bit fixes
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{82CD33B2-1DE6-4663-B6F0-1592B2376F78}" = VS10Runtimex64
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-0028-0411-1000-0000000FF1CE}" = Microsoft Office IME (Japanese) 2010
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0411-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Japanese) 2010
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1041" = Microsoft .NET Framework 4.5.1 (日本語)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981A60AC-D8B8-40FF-9E3D-ADB739E0E584}" = Google Analytics オプトアウト アドオン
"{AFA65883-1CE2-4742-8240-9C37DF0B865E}" = EmEditor Professional (64-bit)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision ドライバー 344.65
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA コントロール パネル 344.65
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA グラフィックス ドライバー 344.65
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 2.1.4
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision コントローラー ドライバー 344.65
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX システム ソフトウェア 9.14.0702
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 16.13.65
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService" = NVIDIA GeForce Experience Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD オーディオ ドライバー 1.3.32.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 16.13.65
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController" = SHIELD Wireless Controller Driver
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.26
"{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}" = Apple Mobile Device Support
"{C91B24F6-1629-11E2-B696-21676188709B}" = PDF Split And Merge Basic
"{CF8FFD12-602B-422D-AF1D-511B411E7632}" = iTunes
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"CCleaner" = CCleaner
"Microsoft Mouse and Keyboard Center" = Microsoft マウス キーボード センター
"NextFTP" = NextFTP
"PDF-XChange 3_is1" = PDF-XChange 3
"PotPlayer64" = Daum PotPlayer 1.5.34115 x64 Edition
"SMPlayer" = SMPlayer 14.9.0 (x64)
"WinRAR archiver" = WinRAR 5.01 (64ビット)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01BC213E-4E69-4EC1-88AA-A12D3C4B3224}" = ScanSnap
"{04F7693D-A295-4C49-8939-54BE0E2AEF1E}" =   for ScanSnap
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E6F4C0D-6F84-46EE-A3DC-E66E9BD3D801}" = ScanSnap Organizer
"{0E8E4718-0702-4D33-B007-5E95849BAB3C}" = LibreOffice 3.5
"{10AB1F40-BDEC-4A8D-B427-30F9429378B0}" = Windows Live Movie Maker
"{11D08055-939C-432b-98C3-E072478A0CD7}" = PSE10 STI Installer
"{12A8EB36-3380-45AA-BFEC-4C098C8F1D47}" = Shuriken Windows 7 対応モジュール
"{148C8BF9-E1B4-445D-AC67-2CABAE63949A}" = Epson Event Manager
"{15D95497-8F76-41E5-8894-EDDB59E39BD9}" = Windows Live メール
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YTD Video Downloader 4.0
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
"{1FCD587F-ACBF-41BF-8CFF-4FDC99330037}" = FeliCa Port Software
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{22D3A614-482C-444A-932C-9DA1B8ECDFD2}" = Elements 10 Organizer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{238FC2D2-3EB3-4796-B342-5731AA37B720}" = キヤノンお知らせメッセンジャー
"{26A24AE4-039D-4CA4-87B4-2F03217071FF}" = Java 7 Update 71
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{3C9D008D-3716-4C3F-90CD-38ED57568FAB}_is1" = Video Download Capture V4.5.3
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{402ED4A1-8F5B-387A-8688-997ABF58B8F2}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A44D100-B4A1-4615-A440-F3ABBDE8EF03}" = Scan to Microsoft SharePoint
"{4A7A784D-58BD-4CC9-8529-150511D190F2}" = TogglDesktop
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{52E225FC-FCB4-41F7-837B-6E37FB05BD7B}" = Adobe AIR
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}" = EPSON Scan OCR コンポーネント
"{57F7717F-8808-4262-8595-6546397F0D7D}" = Mindjet MindManager 8
"{5AC54C83-060F-9610-CC29-9310CBDF80CB}" = Mobilizer
"{5E32882F-6150-4105-B3F2-7030A0502317}" = 読取革命Lite
"{6370C211-AAC3-4823-AA33-0294A9C8EE1E}" = PC/SC Activator for Type B
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{675D8E1E-2388-4718-902C-E5FC4888AC0E}" = Windows Live Essentials
"{680979B2-3EAD-4219-B32C-7A6BC02B39F9}" = 読んde!!ココ パーソナル
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{68EB2C37-083A-4303-B5D8-41FA67E50B8F}_is1" = Poedit
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C3F8916-D6A5-4A31-9DA8-80C973CE437F}" = Windows Live Writer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7134EF35-DA07-41F8-A71F-66709E194BB5}" = Windows Live Mesh
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype(TM) 6.18
"{7E6EF310-CEB1-49B8-9304-4842671D8A63}" = Soda PDF 5
"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"{8235271A-817F-2AD5-E875-30C0387E8646}" = はがきデザインキット
"{824E88CC-98B2-4DE6-9370-4589070C741C}" = honto
"{88A686A9-D687-4295-B633-50D8A4B88371}" = Windows Live Writer Resources
"{8A66A2C8-0032-4949-8D99-C293A3EACF79}" = Windows Live Photo Common
"{8C0B0C9E-60E6-48CD-8080-615A6D271C0F}" = PhishWall
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8CA12FDB-8280-11DF-9B68-005056C00008}" = やさしく家計簿 エントリー for ScanSnap
"{8D59BE38-3A4F-4525-AD0D-8980E9E31EFA}" = Windows Live フォト ギャラリー
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F178A65-9254-45B8-A7A7-3A89F1BB2B45}" = Windows Live UX Platform Language Pack
"{8FD2C828-0172-4343-9979-D7DC33E7B384}" = 名刺ファイリングOCR V3.1
"{90140000-0016-0411-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Japanese) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0411-0000-0000000FF1CE}" = Microsoft Office Proof (Japanese) 2010
"{90140000-0028-0411-0000-0000000FF1CE}" = Microsoft Office IME (Japanese) 2010
"{90140000-002C-0411-0000-0000000FF1CE}" = Microsoft Office Proofing (Japanese) 2010
"{90140000-006E-0411-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Japanese) 2010
"{901ACF4B-7DDB-4DE2-A9D7-6C1DA40671EE}" = TogglDesktop
"{91140000-0016-0000-0000-0000000FF1CE}" = Microsoft Office Excel 2010
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9FB9600E-F5BB-49BB-B817-17ED05CBDD03}" = Microsoft Visual J# 2.0 Redistributable Language Pack - JPN
"{A08BAD08-9AA3-410F-98F3-C92C8EE37218}" = Safari
"{A127C3C0-055E-38CF-B38F-1E85F8BBBFFE}" = Adobe Community Help
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}" = Epson Copy Utility 3.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC471450-12F7-11D7-A712-004026516285}" = Shuriken 2007
"{AC76BA86-1041-0000-BA7E-000000000005}" = Adobe Acrobat X Standard - Japanese
"{AC76BA86-7AD7-1041-7B44-AB0000000001}" = Adobe Reader XI (11.0.10) - Japanese
"{ADD5DB49-72CF-11D8-9D75-000129760D75}" = CyberLink PowerBackup
"{AEFF5C47-5FB7-4080-8FB1-EF5601FFE336}" = SFCard Viewer 2
"{B05B64BA-D9C8-47B9-A2CB-A1F8E796C843}" = Windows Live Messenger
"{B455E95A-B804-439F-B533-336B1635AE97}" = NVIDIA PhysX
"{B4A1C6E5-6D00-48C5-A2FA-167E4FF72408}_is1" = カシミール 3D
"{B4A3C072-87AF-4937-880D-3D7997111C0D}" = Document Capture Pro
"{BAF0CA91-4642-46C8-9BCD-C93B61508701}" = リモート接続用の Windows Live Mesh ActiveX コントロール (日本語)
"{BB702484-7F83-442C-8E3C-56D2565B6823}" = OCR V3.1
"{C3FB4DFD-C3D6-B86C-DD97-1FB9E393833B}" = Widget Manager
"{C4C122A7-0B57-4369-BCB9-2F41C6656343}_is1" = カシミール 3D 基盤地図情報(標高)プラグイン
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C5C67EA4-16FA-473C-B274-904A71162DE4}" = Tether
"{C60F3836-333A-4AE2-B526-CFDBA143A9BA}" = Google Drive
"{C84FDE5B-424C-45EA-B03B-805E7EB9362B}" = i-mode HTML Simulator II
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DBCDB997-EEEB-4BE9-BAFF-26B4094DBDE6}" = ScanSnap Manager
"{DBE0D8C3-EB2B-4887-ABAE-D69795ED6DD0}" = ScanSnap
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E58F3B88-3B3E-4F85-9323-04789D979C15}" = ScanSnap Organizer
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{ED839EC7-1AD9-4F4E-8B6C-AC3A70CFDECB}" = FeliCa Launcher
"{EE549AF9-8FAA-4584-83B2-ECF1BC9DC1FF}" = Adobe Photoshop Elements 10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1" = StreamTransport version: 1.1.2.0
"{FB410000-0002-0000-0000-074957833700}" = ABBYY FineReader for ScanSnap (TM) 4.1
"{FB46F473-333E-4A06-A777-31C54188593E}" = ArcSoft MediaImpression 2
"{FB57263E-706F-11E4-A65F-00163E98E7D6}" = Evernote v. 5.7.2
"{FC926E5F-198A-4C8C-955F-406AB3801251}_is1" = Electric Mobile Simulator Lite version v1.4a
"{FF8455A9-21E8-457D-AC64-510A705D53B3}" = ArcSoft Scan-n-Stitch Deluxe
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 15 ActiveX
"Adobe Flash Player NPAPI" = Adobe Flash Player 16 NPAPI
"Adobe Photoshop Elements 10" = Adobe Photoshop Elements 10
"AI RoboForm" = RoboForm 7-9-11-1 (All Users)
"CanonMyPrinter" = Canon マイ プリンタ
"CanonSolutionMenu" = Canon Utilities Solution Menu
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.springbox.mobilizer" = Mobilizer
"CravingExplorer_is1" = Craving Explorer Version 1.5.0
"designKit.702840F10216893FC3494B731E825B33666733D6.1" = はがきデザインキット
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"EPSON GT-S640_F740 Useg" = EPSON GT-S640/F740 ユーザーズガイド
"EPSON GT-X820 Useg" = EPSON GT-X820 ユーザーズガイド
"EPSON Scanner" = EPSON Scan
"Faveset Klink" = Faveset Klink
"FenrirFS_is1" = FenrirFS 2.4.5
"FenrirSleipnirV3_is1" = Sleipnir Version 3.0.13
"IETester" = IETester v0.5.2 (remove only)
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"jp.co.sony.FloqManager.67214E46FCFDE4AEBD54F1EC69B7612199F5C5BE.1" = Widget Manager
"Kobo" = Kobo
"Lhaplus" = Lhaplus
"Lunascape6" = Lunascape6 (All Users)
"MediaNavigation.CDDirectPrint" = らくちんCDダイレクトプリント for Canon
"Mendeley Desktop" = Mendeley Desktop 1.5.1
"Microsoft Visual J# 2.0 Redistributable Language Pack - JPN" = Microsoft Visual J# 2.0 日本語 Language Pack
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"MiNDPiECE_is1" = MiNDPiECE v1.0r3 (build428)
"Mozilla Firefox 34.0.5 (x86 ja)" = Mozilla Firefox 34.0.5 (x86 ja)
"Mozilla Thunderbird 11.0 (x86 ja)" = Mozilla Thunderbird 11.0 (x86 ja)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.EXCELR" = Microsoft Excel 2010
"Opera 12.17.1863" = Opera 12.17
"PdaNet_is1" = PdaNet+ for Android 4.12
"RakutenToolbar" = 楽天ツールバー
"RealPlayer 15.0" = RealPlayer
"Tera Term_is1" = Tera Term 4.77
"TrueCrypt" = TrueCrypt
"UN080616" = BUFFALO ecoマネージャー for HD
"UN091114" = BUFFALO TurboCopy
"UN091201" = BUFFALO BuffaloTools ランチャー
"UN120119" = BUFFALO Eject Utility
"UN120911" = BUFFALO DiskFormatter2
"UN900109" = BUFFALO ブロードステーション IP設定ユーティリティ
"WinLiveSuite" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1.3
"XTRM CORPORATION/XTRM Runtime_is1" = XTRM Runtime.06

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-3766951078-1282058513-496642304-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-3766951078-1282058513-496642304-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"Opera 24.0.1558.53" = Opera Stable 24.0.1558.53
"別のウィンドウで開くExcel2007" = tsoft 別のウィンドウで開くExcel2007 0.3.12.0103

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2014/12/10 17:31:52 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2014/12/11 5:12:31 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2014/12/11 6:00:49 | Computer Name = PC | Source = Windows Backup | ID = 4103
Description =

Error - 2014/12/12 3:54:37 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2014/12/12 5:29:47 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2014/12/12 5:34:46 | Computer Name = PC | Source = MsiInstaller | ID = 1024
Description =

Error - 2014/12/12 6:00:04 | Computer Name = PC | Source = Windows Backup | ID = 4103
Description =

Error - 2014/12/12 6:40:57 | Computer Name = PC | Source = NvStreamSvc | ID = 131073
Description =

Error - 2014/12/12 6:43:36 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2014/12/12 6:58:02 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 2014/12/12 6:56:54 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2014/12/12 6:56:55 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2014/12/12 6:56:57 | Computer Name = PC | Source = DCOM | ID = 10005
Description =

Error - 2014/12/12 6:56:57 | Computer Name = PC | Source = DCOM | ID = 10005
Description =

Error - 2014/12/12 6:56:57 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2014/12/12 6:56:58 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2014/12/12 6:56:58 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2014/12/12 6:56:58 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2014/12/12 6:56:58 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2014/12/12 6:56:58 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068


< End of report >

OTL Extrasログ以上です。
  • penpen
  • 2014/12/12 (Fri) 20:56:00
リカバリが安全でしょう
ログを確認いたしましたが、業務用途でのご利用もありそうなこともありますし、
どうにも解せないログですので、ここは安全優先でリカバリを行いましょう。
なお今回の感染原因んは、DVD Decripterなどのマルチメディア系ソフトウェア経由です。
これらマルチメディア系ソフトウェアは無料のものはほぼすべてにマルウェアが仕込まれています。

PCからインターネット回線を物理的に遮断してください。
PCをセーフモードで起動させ、USBフラッシュドライブや外付けHDDなど、
外部メディアをすべてフォーマットしてください。
その後フォーマットが完了した外部メディアに必要最低限のデータのみを移し、
物理的にPCから取り外してください。
セーフモードではマルウェアが動作しにくいため、外部メディアへの感染の可能性は薄いですが、
通常モードだとフォーマットしてもあっさりと再感染するので注意が必要です。
必要最低限のデータがバックアップできましたらPCのリカバリを行い、
インターネット回線を復旧させてセキュリティソフトとWindowsの更新を行ってください。
幾度か更新を行い、更新項目がなくなるまで更新を繰り返してください。
更新作業が完了しましたら、そこで外付けメディアにバックアップしたデータを復旧します。
以上の手順でリカバリを行われてください。
  • IVNO
  • MAIL
  • 2014/12/13 (Sat) 02:29:23
場所について完全に間違われているようなので。<補足>
まず、今回知恵袋に貼られていたURLはフィッシングサイトの傾向もあるようです。
トレンドマイクロが検知していました。
また既に公式サイトでは、閉鎖をし姿を隠しながらミラーサイトのみを残すという
形式をサイト開発者が取られていたため、既にダウンロードされたソフトは手を加
えられた偽物ソフトという事になります。

ですので、公式の隠れたミラーを探せば感染は防げたという事になります。
まぁ、グレーな部分もあり仕方の無い所でもあります。

ですので、動画・サウンド波形系統のサイトは見極めが必要な場合があり、
全てが悪いという訳ではありません。

ここで、間違われやすいのは、soundengine_freeかな。公式が悪いように
書かれた事もあった関係なのか公式サイトではダウンロード出来なくなっている
ようです。>元々あそこは迷子になりやすいのでダウンロードを窓の杜に絞ってし
まったのかもしれないが・・・・。こんな感じです。
  • 三毛猫
  • 2014/12/13 (Sat) 10:45:23
リカバリほか質問
IVNO様、三毛猫様、返信ありがとうございます。


IVNO様、ログ確認ありがとうございます。

リカバリを行うことにします。

Web制作に用いられるソフトは、アフィリエイトを行っていたとき、利用しておりました。(ここ1年ほど休止中です)


いくつか質問させてください。


1.「今回の感染原因は、DVD Decripterなどのマルチメディア系ソフトウェア経由です」について。

「DVD Decripterなど」という意味は、2014/12/10のDVD Decripterのインストーラーによる感染の前に、ほかのマルチメディア系ソフトウエア経由でマルウェアに感染していた、ということでしょうか。

つまり、2014/12/10以前にこのPCで扱ったデータも感染の可能性があるという理解でよいですか。


2.メディア系データの扱い

P2Pは利用していないし、過去にも利用したことがないのですが、信頼度の低いサイトからメディア系データをダウンロードしたものがあります。
これらのデータはバックアップしないほうがよいですか。
または、リカバリ後のPCでは利用しないほうがよいですか。


3.バックアップ済みのデータの扱い

「1.」とも関連しますが、2014/12/10より前に外付けHDDにバックアップしたデータは復旧に利用しないほうがよいという理解でよいですか。
ちなみに、外付けHDDは利用するときだけ、コンセントの電源をONにしています。物理的にはUSBで接続したままの状態。


4.外部メディアのフォーマットについて

最初にすべての外部メディアをフォーマットする必要がありますか?
外付けHDDだけに保存しているデータがあり、PCの内蔵HDDの容量を超えてしまうので、1台の外付けHDDをフォーマットした後、データを保存している外付けHDDからデータを移動して、というようにバックアップを行ってもよいですか。


5.TrueCryptで作成した暗号化ボリューム内のデータの扱い

内蔵HDD内に暗号化ボリュームがあります。
また、外付けHDDやUSBメモリにデータを保存する場合、多くの場合、暗号化ボリュームを作成するか、外部メデイアごと暗号化して、その中に保存しています。
暗号化ボリュームは使用するときだけマウントして利用しています。

これらのデータは、
a.暗号化ボリュームのまま、フォーマット済みの外部メディアに移動させるだけでよいのか、
b.セーフモードでTrueCryptを使って新たに暗号化ボリュームを作成し、そこに昔の暗号化ボリュームをマウントして内部のデータを移動させるほうがよいのか、
どちらでしょうか?

<想定した手順例>
a.PCネット回線遮断→PCセーフモード起動→移動先外部メディアをフォーマット→内蔵HDD内やフォーマットの済んでいない外部メディア内の暗号化ボリュームをフォーマット済の外部メディアに移動→PCから取り外し

b.PCネット回線遮断→PCセーフモード起動→移動先外部メディアをフォーマット→内蔵HDD内にTrueCryptで新しい暗号化ボリューム(=Y)を作成→内蔵HDD内やフォーマットの済んでいない外部メディア内の暗号化ボリュームをマウントし内部のデータを先ほど作成したYに移動→Yをフォーマット済の外部メディアに移動→PCから取り外し


6.Evernoteのデータの扱い

EvernoteをPCとクラウドとAndroidスマホの間で同期しています。
現状、Androidスマホに異常は見られません。
Evernoteの実際のデータ量は分かりませんが、データ保存先のフォルダは7.5GBとなっています。

使用中のアカウントを継続利用してもよいですか。

データについてはクラウドに保存してあるデータをリカバリ後ダウンロードしても構わないですか。

それともエクスポート機能を使って、エクスポートしたデータをリカバリ後、新しいアカウントにインポートして利用するほうがよいですか。


7.Dropboxのデータの扱い

PCとDropboxをクラウドとAndroidスマホの間で同期しています。
こちらは最近利用したばかりで、PDFを数個同期している程度で、アカウントの変更は比較的容易です。

アカウント・データについてどうするのがよいですか。


8.Androidスマホの扱い

GoogleDriveを1、2ヶ月前ほど、試しに少しの期間、PCとクラウドとAndroidスマホの間でPDFを数個同期させたことがありましたが、その後、PCではログアウトしたつもりだったのですが、確認するとアカウントは設定されたままでした。タスクバーにアイコンは表示されていなかったので同期はされていなかったのではないかと思います。Drive専用に取得したアカウントで利用しており、今後利用しないのでアカウントを削除しましたが、確認するとAndroidスマホ側でも2014/12/14時点でクラウドとの同期がありました。

スマホはそのまま継続利用してもよいですか。


9.リカバリ後のパスワード変更について

ネットバンキングやネットショッピングなどのパスワード変更は必要ですか。

2014/12/10の感染以降はネットバンキングやネットショッピングは行っていません。
パスワードはブラウザでは保存しないようにしています。
ネットバンキングを除くパスワードはPCのロボフォームで管理しています。
2014/12/10の感染以降もPCのロボフォームをログイン状態で使用していた時間があります。
ネットバンキングのパスワードについては外付けUSBのTrueCryptの暗号化ボリューム内のロボフォームに保管しています。


10.リカバリについての確認

mouse computerのPCを使用しています。
win7sp1のオペレーティングシステムインストールディスクが付属しているタイプです。
このディスクでOSを再インストールすることがリカバリであるという理解で間違いありませんか?

ttps://www2.mouse-jp.co.jp/ssl/user_support2/sc_faq_documents.asp?FaqID=2937
ttp://ykr.ykr414.com/2012/01/06/nextgear-micro-im500ba-recovery-review/




三毛猫様、補足ありがとうございます。

「場所」というのは、ダウンロード元という意味で合っていますか?

私もダウンロード元が公式かどうか確認しなかったことも問題があったと思っています。

今までのフリーソフト利用を振り返ってみると、フリーソフトが紹介されているページにダウンロード元のリンクが記載されていた場合、ダウンロード元の精査を行わずにダウンロードすることが多かったと思うので、今回のような事態になるのは時間の問題だったと思います。

あと、有料ソフトでも公式サイトではなく、Vectorやcnetなどで配布しているソフトもあって、今回もそのような感覚でダウンロードしてしまった部分もあり、Vectorやcnetなどの準公式的なサイトとの区別がいい加減だったというのもあります。

知恵袋も誰でも登録と作成ができるわけなので、偽物ソフトを作成した人が、知恵袋のアカウントを作成して、第三者を装ってノートを作成することも可能ですね。知恵袋以外でもそのような可能性があります。ダウンロード前に知恵袋の作者のプロフィールの確認もしませんでした。ただ、書かれているプロフィールの正しさの判断も難しいです。そういったことの認識が甘かったのが原因の一つだと思っています。


ちなみに、動画再生ソフトやコーデックパックで問題のないものはありますか?

過去ログを見ていたところ、
悪代官 2014/10/20 (Mon) 21:19:33
http://other-place.bbs.fc2.com/?act=reply&tid=5391108


動画再生については下記が現在便利で対応ファイルも多いので一考を。
ttp://freesoft.tvbok.com/freesoft/player/mpc-hc.html

とありますが、こちらは大丈夫でしょうか。

MPC-HCのほか、「インストールしてあると便利なコーデックパック」が紹介されていますが、アドウェアの同梱があるようなのでコーデックパックは止めたほうがよいですか?


以上です。よろしくお願いします。
  • penpen
  • 2014/12/14 (Sun) 04:55:07
Re: 質問について
<一つ気になる所があったので追記>
まさかと思うんだけど、Win100%という雑誌の中でたまに「無法地帯」特集
という晒し感じでURLを公開している所があるけれど、そういう系統?
もし、その傾向が強いものはバックアップは捨てたほうが無難。
<追記おしまい>

IVNOさんは、元々グレー部分が多いソフトについてのソフトは
排除している確率も個人的に強いのでしょう。その旨の案内も
含まれていると思われます。mixiなどのコミュではよくある傾
向です。

また、おそらく完全に業務用と勘違いされている事もあるでしょう。
建築関係のお勉強等されていますか?>学生や資格取得を目指してい
たのならば、入っていて当たり前のソフトかと思います。

外部接続のハードディスク等を一度初期化してというのは、おそらく
個人的にお勉強で使われていたようなソフト類の痕跡が見え隠れした
事からかと推測します。

その為、どの時点での感染確率が高いのかという事については、
知恵袋でURLをクリックした時点での感染率が一番高いと思い
ますが、どのファイルをバックアップすべきなのかというのは、
一度、ウイルス対策ソフトでのサポートにて相談されるのが
妥当なのかなぁと思います。

また、下記の件ですが・・・私的意見を言わせて頂ければ全く
お役に立ちません。市販のブルーレイディスクは再生不能です。

>動画再生については下記が現在便利で対応ファイルも多いので一考を。
>ttp://freesoft.tvbok.com/freesoft/player/mpc-hc.html

市販ソフトのCyberLink の最新版を購入してアップグレードすれば、
Windows 7までは確かメディアプレーヤーでの再生もフォローしてく
れていた筈です。お金はかかりますが、その方が安全性は高まります。

MP4等の再生なら、昔はMP4 Splitterを入れていたり、ffdshowを
入れたりするのが一般的ですが、時代の流れは速いのでどれが安全で
良いCodecなのかは流石に・・・・ごめんなさい。

Windows8になると、メディアプレーヤーは再生されなくなるので、
私は、下記のCodecを使っています。mpeg2未搭載なので、仕方の無
い事です。それをフォローして貰ってます。
http://www.gigafree.net/media/codecpackage/STANDARDCodecs.html
  • 三毛猫
  • 2014/12/14 (Sun) 10:50:54
ご質問の件です
まずは一つ目の質問からです。
私が感染した日時に近いと見ているのは2013年7月です。
セキュリティ上の感染リスクが確認されるのは2012年3月ですね。
よってこの日時以降のものには感染リスクが伴います。
感染したのがアドウェアならまだ良いのですが、
トロイの木馬型ウイルス等である場合はどこに感染したか分かりません。
ログの状態が妙であることから、私はトロイ系が潜っていると判断しました。
これがリカバリをご案内する理由です。

二つ目の質問につきましては、メディア系と言うのがオーディオや動画である場合、
これらの中に仕込まれたトロイの木馬等に感染する可能性があるのです。
これはコンテナと言う箱の中に音楽だったり動画だったりを入れる仕組みがあり、
その箱の中にはなんでも収納することができるのです。
よってその箱の中にウイルスを収納することも可能なため、
これらのファイルに関してはバックアップはお勧めしません。
コンテナと言う方法を採用していない画像ファイルなどはまず安全でしょう。

三つ目の質問につきましては、可能ならPCをセーフモードで起動させ、
外付けメディアをすべてフォーマットすることをお勧めします。
これは外付けメディアそのものにウイルス等が感染している可能性があるため、
それをそのままリカバリ後のPCに接続すると、外部メディア経由で感染する可能性があるのです。
それを未然に防ぐため、ウイルスの稼働しにくいセーフモードでフォーマットし、
そこにデータをバックアップした後、外付けメディアを物理的に取り外し、
PCをリカバリすると言う流れとなります。
よっていずれにせよ現段階のバックアップ済みデータは消えると思われます。

四つ目の質問につきましては、感染のリスクのないデータのみを移動させてください。
この際にも必ずセーフモードでファイルを移動させるようにしてください。
バックアップデータに関しては大掛かりな取捨選択が必要になるかと思われます。

五つ目の質問につきましては、そもそもTrueCryptの作者が、
「TrueCryptは安全ではないため別のツールに変更することを強く推奨する」
と言っておられますし、このソフトウェアを利用し続けるのは避けるべきです。
暗号化されたボリューム内のデータはセキュリティソフトでチェック後、
外付けメディアにバックアップを行ってからフォーマットする形が良いでしょう。
またボリュームのマウントの際にほかの外部メディアに感染する可能性があります。
ですので、アンマウントされた状態のときにその他の外部メディアをすべて取り外し、
その後単独でマウントを行ってください。
また外部メディアを挿入する際はShiftキーを押しながら挿入することで、
自動実行を悪用したウイルス感染を防ぐことが可能です。
外部メディアへのバックアップの際は暗号化されていないとは思いますが、
これについては仕方ないものとお考えいただければと思います。

六つ目の質問につきまして、こちらは一度PC上に保存されているデータを
セキュリティソフトでチェックの上、DVD-R DLなどに書き起こして保存し、
それをバックアップとすると良いかと思われます。
既存のアカウントは停止処理を行い、新たにアカウントを作り直すと良いでしょう。

七つ目の質問は六つ目と同様の処置で可能です。

八つ目の質問につきましては、スマートフォンでは動作しないものの、
PCに入り込むと感染するマルウェアがかなり多いです。
よって、安全優先で行くならばそちらのデータは破棄が望ましいですが、
これはご自身でご判断いただければと思います。
いずれにせよPC用のセキュリティソフトにてチェックは必要です。

九つ目の質問につきましては必須です。
リカバリ完了後にPCとセキュリティソフトの更新を行い、
その後すぐにすべてのパスワードを変更なされてください。

最後の質問につきまして、リカバリは再セットアップとも言われます。
よってそちらのディスクを用いてWindowsの再セットアップを行うことが、
リカバリを行うことと同義となります。
つまり、工場出荷時の状態に戻す作業をリカバリと言います。
  • IVNO
  • MAIL
  • 2014/12/14 (Sun) 13:33:49
Re: 念の為のお知らせです。
まぁ、バックアップに関しては、ちょっと神経質?と思われる部分も存在していそうです。
多分、殆どの人は知らないと思われるけど、スマホで流行したパスドラは、本来インストール
してはいけないと指定しているセキュリティ会社(secroid.jp)もあります。それと同じ事柄
を言っているようなものなので。

なぜか、開発時にRoot権限に当たるギリギリの開発設計にしたという理由から。
root権限で実行する(root権限取得ユーザーIDの取得を含む)とかが関係している
のかもしれません。

でも、これらをインストールするかどうかは、ユーザー自身です。結構死亡ソフト
多くて驚かれると思います。
まさに、企業にとっては、そんなつもりじゃなかったのに・・・・・の状態で最近
ではチェックされないソフトも多いという話もチラホラと。

まぁ、バックアップについては、ESETセキュリティサポートで、もう少し情報仕入れたほうが無
難かもしれません。大概は、全てのバックアップデーターをフルスキャンかけてセキリティソフト
が反応しなければ、安全上問題は無いという答えが貰えると思います。→実話話。

元々、あまりレジストリを触らない形で処理を行っているセキリティ会社が多いので、色々と手段
の違いが出てしまう模様。特にトレンドマイクロは、普通に迷惑会社が用意したアンインストール
でアンインストして残るなら、本格的に調べましょうという形を取られているようです。
その後は、有料サポートになる確率が高そうな予感。最近、このケースどのソフト会社も多いと思う。

<さらに追記>
多分、スマホにもEsetかどこかのメーカーセキリティが入っていると思うけど、そのソフトにも
アプリの権限チェック機能がある事を祈りたいです。その機能を有効にしたまま下記のソフトを
インストールしてチェックすると、内容が合いません。ちょっと食い違っているなぁと思われたか
もしれませんが、現に、ここのサイトとメーカーでのチェック機能の違いが発生している事が起こ
りやすい形になってしまっているのです。

ソフト名 Trust Go Ad Drtector トレンドマイクロモバイルも引っ掛かる。

<追記>
>ログの状態が妙であることから、私はトロイ系が潜っていると判断しました。

この点についてそう判断をしているのならば、同じくESETでも何らかの傾向が判断される筈です。
リカバリーには反対はしません。その傾向があるかないか専門家のチェックを受けられてから、
作業をやられたほうが、個人の判断と専門家の判断が一致したという事になり、心おきなく作業出
来るでしょう。
  • 三毛猫
  • 2014/12/14 (Sun) 19:54:44
IVNO様、ご回答ありがとうございます
IVNO様、ご回答ありがとうございます。

返信遅れまして申し訳ありません。

インターネットに接続すると、AdOptionsの広告が出るようになりました。
以前使用していたPC(Windows Vista)があるので、Updateなどを済ませてこちらから接続しています。


2012年3月というとそのPCを購入した月なので、購入当初からということになりますね。
導入したソフトか前のPCが既に感染していたということでしょうか。


昔のログだったので報告していませんでしたが、ESET SMART SECURITY7の隔離のログが2件ありました。

隔離オブジェクトの数:2

日時2013/06/11 21:00:34
ファイル名 C:\User\7y84qMCp\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0106c6
サイズ 34.0KB
理由 JS/Kryptik.ALG トロイの木馬
合計 1

日時2014/07/05 1:29:58
ファイル名 C:\User\7y84qMCp\Desktop\A61c.tmp
サイズ 410.3KB
理由 Win32/AdWare.Linkular.AJ アプリケーション
合計 1


以下、質問や確認したい点があるのでよろしくお願いします。

11.自動再生

Windowsの設定で自動再生をOFFにしておけば、外部メディアを挿入する際のShiftキー押しは不要ですか?

http://windows.microsoft.com/ja-jp/windows/change-autoplay-settings#1TC=windows-7


12.外部メディアとバックアップデータ

・現在使用している外部メディアで、リカバリ後のPCで利用したい外部メディアは、セーフモード下のPCにてフォーマットを行ったものに限定する
・バックアップしたい、感染リスクのないデータはセーフモード下でファイルをフォーマット済の外部メディアに移動させる

ということですよね?

ということは、
外部メディアでバックアップに利用しないものは、
リカバリ後のPCや別のPCで、セーフモード下でフォーマットすれば、その外部メディアはリカバリ後の通常モードで利用できますか?


あと、
PCは、ウィルスが感染したA機(Windows7)と以前使用していたB機(Windows Vista)の2台があるので、
A機の感染リスクのないデータのうち、当面必要なデータを所定の手順で外付けHDD「Z」に待避させて、その他のデータを外付けHDD「Y」に待避
「Y」に待避したデータでA機で利用したくなったデータは、B機をセーフモードで起動し、データをセキュリティソフトで検査のあと、
セーフモード下でフォーマットした別の外部メディアに移動し、その外部メディアをA機に接続する
という形で利用することも可能ですか?


13.TrueCrypt内のデータの移動手順

以下の手順でよいでしょうか。

a.PCをセーフモードで起動
b.外部メディアがすべて取り外されているのを確認
c.TrueCryptの暗号化ボリュームを保存している外部メディアを接続
d.TrueCryptの暗号化ボリュームをマウントする
e.TrueCryptの暗号化ボリューム内のデータをセキュリティソフトで検査する
f.TrueCryptの暗号化ボリューム内のデータを内蔵HDDか外部メディアに移動する
g.セーフモード下でフォーマットした外部メディアを接続(または、cの外部メディアをフォーマットする)
h.fのデータをgの外部メディアに移動


14.ルーター経由の感染

「12.」で記載したように、PCが2台あります。
「2012年3月」から感染リスクが確認されるということは、B機も感染している可能性があります。

A機をリカバリ後、A機とB機をルーターに接続すると、B機のウィルスがA機に感染する可能性がありますか?
ルーターに接続するのをどちらか1台に限定し同時には接続しないようにし、ファイル共有やクラウドのアカウントの共有をしなければ、
B機のウィルスがA機に感染することはありませんか?


15.ブラウザだけで利用しているEvernoteやDropboxアカウント

「6.」や「7.」のアカウント以外に、PCやスマホに同期せず、ブラウザだけで利用しているEvernoteやDropboxアカウントがあります。
こちらのアカウントやデータも、「6.」の回答と同様な処置を行うべきですか?


16.Androidスマホ(「8.」の回答について)

リカバリ後、Evernote、dropboxの同期をPCとクラウドとAndroidスマホで再開したいと考えています。
この場合、データ破棄が望ましいというのは、
単にAndroidスマホ内のEvernoteやdropbox、GoogleDriveのデータを破棄すればよいのか、
そのほか全体のデータを破棄&初期化が望ましいということでしょうか?


17.デジカメやスマホで利用している外部メディア

デジカメやスマホで利用している外部メディアで、PCと接続する可能性のあるものもフォーマットが望ましいかと思いますが、
このフォーマットはPC側でセーフモード下でフォーマットしたのち、デジカメなどで再フォーマットする方がよいのでしょうか?


18.動画サイトの閲覧

動画系ファイルはコンテナという仕組みがあり、ウィルス感染リスクが高いとのことですが、
Youtubeなどの動画サイトで動画を再生しただけでもウィルスに感染する可能性があるのですか?


19.TrueCryptの代替となるようなソフトウエアをご存じですか?


以上、よろしくお願いします。
  • penpen
  • 2014/12/19 (Fri) 05:47:29
三毛猫様、ご返信ありがとうございます
三毛猫様、ご返信ありがとうございます。

PC系雑誌は購入も立ち読みもしないので、どのような系統なのか分からないので何とも言えません。
YouTubeや海外動画サイトもその系統の可能性がありますか?

建築系の勉強はしてないです。

フリーソフトはインストーラーを使用しないものを利用していることがあるので、
そのソフトの動作に必要なソフトが痕跡のように見えてしまっているのでしょうか。

ウイルス対策ソフトのサポートを利用するという発想がなかったので、
今のところ、サポートへは連絡していませんが、
むだ骨になるような気がして。

動画再生ソフトの件は参考になりました。

リカバリに抵抗はないです。
立ち上がりの速度なども遅くなった気がするし、ちょうどいい機会かなと。

問題は、リカバリ後のPCをどのように使うかということですよね。
どちらかというと少々心配性なので、できるだけ不安は排除しておきたいという考えです。
PCが2台あるので、用途を使い分けようかなと思います。
  • penpen
  • 2014/12/19 (Fri) 06:20:52
Re:質問の件
私がお勉強しているのかなぁと思ったのは、
カシミール 3Dと基盤地図情報(標高)プラグイン
があったからです。

さて、ご審問の件

雑誌系はあまり読まないとの事、却ってそのほうが
安全な事は確定ですが、今、そのサイトを紹介して
いる記事みたら、まぁ見事にここの禁止品使ってま
した~という結論のようです。

multirecommend.web.fc2.com/jmp3up.info20121113.html

という訳でhttp抜き。この系統に限られてしまうと
いう事はないんだけど、転載廻りが多すぎるし、
本当に出所不明な事が多いと思うので。>廃棄オススメ。

>フリーソフトはインストーラーを使用しないものを
>利用していることがあるので、
>そのソフトの動作に必要なソフトが痕跡のように見
>えてしまっているのでしょうか

この見え方は、OldTimer で判る事が多いようです。
ただ、この見方はINVOさんのほうが詳しいと思う
ので、私からはちょっと言えない部分でもあります。

>ウイルス対策ソフトのサポートを利用するという発想
>がなかった。
>むだ骨になるような気がして

うーん、その傾向が今多いのかなぁ。だからこそ、
なんでも連絡くださいという形になってしまった
のか、それとも企業のバトルになってしまう形が
見え隠れしている事もあって、広告の存在には手
出しが難しいのか判断しにくい部分でもあるよう
です。

まぁイザという時にはきちんと教えて貰う事が出
来るので今度はきちんと利用したほうが良いでし
ょう。今回は、過去に検出された傾向があるので、
確実にリカバリーが確定しました。

企業バトル
http://gigazine.net/news/20141219-viber-eset-battle/
(解決するまでは、使わないほうが無難でしょう)

不安を軽くしたいというのであれば、不必要なも
のはダウンロードしないこと。
特に、PCとスマホで共有されているものが多いよ
うですが、よく調べないと「アレ」という漏洩が
増えているようです。(下記のようなケースも含む)
例 https://www.ipa.go.jp/security/txt/2014/12outline.html

本当に、「不必要なものはダウンロードしない」しかない
みたいです。(苦笑)特に、下記のサイトからダウンロード
すると最悪になるケース有。

BrotherSoft・Softonic・Trailsframework・
UpdateStar・Toggle・Download366・Gufairu・
Download786でダウンロードしてはいけない。
上記のサイトは、アドウェアをてんこ盛りいたします。

  • 三毛猫
  • 2014/12/19 (Fri) 17:17:53
遅くなりました
少々風邪で思考回路がまとまっておりません。
過去のスキャンからも分かりますが、
悪意のあるWebページを閲覧した記録が出ています。

JS/Kryptik.ALG

こちらはWebページの構築に使われるJavascriptと呼ばれるプログラミング言語ですが、
このJavasriptを悪用することにより、Webを閲覧した人PCにウイルスをばら撒くなど、
二次災害の基盤として用いられたと言うことが分かります。
この手の感染がつまり、「Webページを閲覧するだけで感染する」タイプですね。
恐らくまだPC内にはこれによって潜り込んだウイルスがいるかと思います。
今回のログの異変についてもこのあたりが差し金となっている可能性がありますが、
あれでしたら一度通常の処置を行ってみるのも一つでしょう。
しかし途中でやはりリカバリと言う結論に至る可能性が高いのはご留意ください。

その他の質問につきましてすべて回答するのは体力的にきついですので、
ざっとまとめて回答させていただきますね。
まず感染の疑いのあるPCに入っているデータを移動させた媒体あるいはサービスに関して、
こちらは可能な限り破棄が望ましいでしょう。
WebサービスもPC上のデータのやり取りですので同様です。
USB経由の感染と言う可能性もありますので、過去にそのPCに接続したことのあるUSBや、
そのUSBを使ったことのあるPCに関しては、安全策としてリカバリがベストでしょう。
YouTubeなどの動画サイトですが、YouTubeやニコニコ動画については、
再変換と言う処置をサーバー上で行っていますが、条件によっては再変換されないものもあります。
今回問題となるのは、この再変換が行われていない場合の動画に関してですが、
一般ユーザーの公開するユーザー撮影の動画ならこの手の感染は薄いでしょう。
しかし一点、アニメなどの視聴率が高いものを餌として感染を狙う人も少なからずいます。
この傾向は特にP2Pに多いため、P2Pでの動画取得は非常に危険です。
なお再変換が行われた動画につきましては、こちらのリスクはありませんが、
どれが再変換されてどれが再変換されていないかを調べることはできません。
ただ一般的にYouTubeは大半が再変換されていますから、
まだYouTubeに関しては安全な方だと言えそうです。
同じ理由でニコニコ動画に関しても、再変換を回避する目的で作られたもの以外は、
基本的に再変換がかかっています。
再変換を嫌う傾向があるのは、ボカロ曲などの自主性作品が主ですので、
こちらもそこまでのリスクはないと思われます。
問題はその他動画サイトですね。
ルーター経由での感染はものすごく稀です。
ルーター経由ではまず感染しないと思っても良いくらいです。
ただしファイルの同期などを行っている場合はルーター関係なく危険です。
有名な仮想ディスク作成ソフトとしてはVirtualBoxやVMwareなどが有名ですね。
Microsoft提供のWindows Virtual PCもありますが、こちらは私はよく分かっていません。
  • IVNO
  • MAIL
  • 2014/12/20 (Sat) 16:40:47
外部メディアのフォーマットの形式
IVNO様、三毛猫様、返信ありがとうございます。

Vista機が電源は入るがWindowsが起動しない状態になりまして、マザーボードのボタン電池を変えたところ、数回は通常通り起動したものの、結局Windowsが起動しない状態になり、スマホから書き込みしています。

スマホからなので簡潔に質問だけ失礼します。

外部メディアのフォーマットの形式はクイックフォーマットよりも、通常のフォーマットの方がよいのですか?
  • penpen
  • 2014/12/24 (Wed) 18:49:14
通常フォーマットで
クイックフォーマットはデータをただ削除するだけなのですが、
このデータ削除とは、上書きができなかったデータを他のデータで上書きできるようにしただけの状態となりますので、
実際にはメディア内にファイルが残っている状態となるわけです。
動作しないようにはされていますが、削除されることを前提として作られたウイルスの場合、この状態でも動作します。
媒体によって異なったりはしますが、まだ確率的にはクイックフォーマットでないほうが安全です。
  • IVNO
  • MAIL
  • 2014/12/24 (Wed) 19:27:52
遅くなりました
リカバリ自体はだいぶ前に済んで、最低限のファイルは内蔵HDDにコピーして、ブラウザも正常通りです。

その後、電源を入れても電源ランプが点灯するだけというハード的なトラブルが一時的に発生しました。これは、PCケース内部のクリーニングとメモリ・グラフィックボードの取り付けし直しで、今は解決しています。

念のため、ログを確認していただいたほうがよいかと思うのですが、HJTとCCのログを提示すればよいでしょうか?
  • penpen
  • 2015/01/28 (Wed) 06:59:15
ログの取得を
リカバリ作業お疲れ様です。
電源を入れてもランプが点灯するだけと言う症状には心当たりがあるのですが、
こちらはメモリに負荷をかけた際に発生しやすい症状の一つであり、
残留電荷の放出により解決できるケースが多いです。
残留電荷とは、電源を切っているのにPC内部に残って流れ続ける電気のことです。
この残留電荷の影響により、本来電気が流れないはずの場所に電気が橋渡しされ、
結果として異常動作を引き起こしたと言うことになります。
このような状態になった場合は感電の恐れもありますため、
電源ケーブルを取り外してから電源ボタンを投入することにより残留電荷を放出させてください。
つまりPC内に蓄積された電力をほかの電力供給源を絶った状態で電源を投入することにより、
一切を消化させてしまおうと言うことですね。
以降の同様な事例の際の解決策となりましたら。
それではお手数ではありますが、HJTのログ、CCのインストール情報ログを取得し、
それらを貼り付けてご連絡をお願いいたします。
  • IVNO
  • MAIL
  • 2015/01/28 (Wed) 15:38:57
ログ
ご返信ありがとうございます。
今後、同様なトラブルが発生したら、まずはその方法を試してみたいと思います。

では以下ログになります。

□HJT

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 0:53:40, on 2015/01/29
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)

FIREFOX: 35.0.1 (x86 ja)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaConverter.exe
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaRenderer.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome-nm-host.exe
C:\Program Files (x86)\Evernote\Evernote\Evernote.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\Identities.exe
C:\Users\dEaAD2sZ\Desktop\clibor\clibor\Clibor.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\dEaAD2sZ\Desktop\ウィルスチェック\HJT\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: RoboForm BHO - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Windows Live ID サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Google Japanese Input Prelauncher] "C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe" --mode=prelaunch_processes
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - Startup: EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: RF ツールバー表示 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComShowToolbar.html
O8 - Extra context menu item: RF フォーム保存 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComSavePass.html
O8 - Extra context menu item: RF フォーム記入 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComFillForms.html
O8 - Extra context menu item: RF メニューカスタマイズ - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: URL をクリップ - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0
O8 - Extra context menu item: このページをクリップ - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1
O8 - Extra context menu item: 新規ノート - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html
O8 - Extra context menu item: 画像をクリップ - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4
O8 - Extra context menu item: 選択部分をクリップ - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: フォーム記入 - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra 'Tools' menuitem: RF フォーム記入 - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: 保存 - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra 'Tools' menuitem: RF フォーム保存 - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: ツールバー表示 - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra 'Tools' menuitem: RF ツールバー表示 - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Active File Monitor V10 (AdobeActiveFileMonitor10.0) - Adobe Systems Incorporated - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe,-100 (GoogleIMEJaCacheService) - Google Inc. - C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe
O23 - Service: Google アップデート サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NFC Proxy Service (NFCProxyService) - Sony Corporation - C:\Program Files (x86)\Sony\NFC Proxy Service\bin\NFCProxyService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12883 bytes


□CC

Adobe Acrobat X Standard - Japanese Adobe Systems 2015/01/08 1.83 GB 10.1.13
Adobe AIR Adobe Systems Incorporated 2015/01/08 2.6.0.19140
Adobe Community Help Adobe Systems Incorporated. 2015/01/08 3.5.23
Adobe Flash Player 16 ActiveX Adobe Systems Incorporated 2015/01/26 6.00 MB 16.0.0.296
Adobe PDF iFilter 11 for 64-bit platforms Adobe 2015/01/08 48.3 MB 11.0.00
Adobe Photoshop Elements 10 Adobe Systems Incorporated 2015/01/08 2.60 GB 10.0
Adobe Reader 64-bit fixes Leo Davidson / Pretentious Name 2015/01/08 3.02 MB
Adobe Reader XI (11.0.10) - Japanese Adobe Systems Incorporated 2015/01/08 203 MB 11.0.10
Canon Easy-PhotoPrint EX Canon Inc. 2015/01/07 4.5.0
Canon Easy-WebPrint EX Canon Inc. 2015/01/07 1.5.0.0
Canon iP2700 series Printer Driver Canon Inc. 2015/01/07
Canon My Image Garden Canon Inc. 2015/01/07 3.0.1
Canon My Image Garden Design Files Canon Inc. 2015/01/07 3.0.0
CCleaner Piriform 2015/01/29 5.02
CPUID HWMonitor 1.26 2015/01/23 2.87 MB
EmEditor (64-bit) Emurasoft, Inc. 2015/01/06 21.6 MB 14.7.1
Epson Copy Utility 3.5 2015/01/08 3.5.0.0
Epson Event Manager Seiko Epson Corporation 2015/01/08 42.4 MB 3.01.0005
EPSON GT-X820 ユーザーズガイド 2015/01/08
EPSON Scan Seiko Epson Corporation 2015/01/08
EPSON Scan OCR コンポーネント SEIKO EPSON Corp. 2015/01/08 1.21.0001
ESET Smart Security ESET, spol s r. o. 2015/01/06 111 MB 8.0.304.6
Evernote v. 5.8.1 Evernote Corp. 2015/01/07 231 MB 5.8.1.6061
Google Chrome Google Inc. 2015/01/06 40.0.2214.93
Google 日本語入力 Google Inc. 2015/01/06 84.1 MB 1.13.1641.0
honto 2.8.0 Dai Nippon Printing Co., Ltd. 2015/01/28 35.0 MB 2.8.0.0
HWiNFO64 Version 4.48 Martin Mal勛 - REALiX 2015/01/23 3.05 MB 4.48
Intel(R) Management Engine Components Intel Corporation 2015/01/06 7.0.0.1144
Intel(R) Rapid Storage Technology Intel Corporation 2015/01/06 10.6.0.1002
Microsoft .NET Framework 4.5.1 Microsoft Corporation 2015/01/06 38.8 MB 4.5.50938
Microsoft .NET Framework 4.5.1 (日本語) Microsoft Corporation 2015/01/06 2.93 MB 4.5.50938
Microsoft Excel 2010 Microsoft Corporation 2015/01/06 14.0.4763.1000
Microsoft Silverlight Microsoft Corporation 2015/01/06 20.4 MB 4.0.50401.0
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2015/01/06 1.69 MB 3.1.0000
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2015/01/08 11.1 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 2015/01/08 17.3 MB 11.0.61030.0
Microsoft マウス キーボード センター Microsoft Corporation 2015/01/06 2.3.188.0
Mozilla Firefox 35.0.1 (x86 ja) Mozilla 2015/01/28 82.9 MB 35.0.1
Mozilla Maintenance Service Mozilla 2015/01/06 214 KB 34.0.5
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2015/01/08 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2015/01/08 1.33 MB 4.20.9876.0
NFC Port Software Sony Corporation 2015/01/08 5.3.6.7
NVIDIA 3D Vision コントローラー ドライバー 306.23 NVIDIA Corporation 2015/01/06 306.23
NVIDIA 3D Vision ドライバー 340.52 NVIDIA Corporation 2015/01/06 340.52
NVIDIA HD オーディオ ドライバー 1.3.30.1 NVIDIA Corporation 2015/01/06 1.3.30.1
NVIDIA PhysX システム ソフトウェア 9.12.0604 NVIDIA Corporation 2015/01/06 9.12.0604
NVIDIA Update 10.4.0 NVIDIA Corporation 2015/01/06 10.4.0
NVIDIA グラフィックス ドライバー 340.52 NVIDIA Corporation 2015/01/06 340.52
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2015/01/06 6.0.1.6526
Renesas Electronics USB 3.0 Host Controller Driver Renesas Electronics Corporation 2015/01/06 1.22 MB 2.1.16.0
RoboForm 7-9-12-2 (All Users) Siber Systems 2015/01/22 20.0 MB 7-9-12-2
Shuriken 2014体験版 株式会社ジャストシステム 2015/01/07 69.7 MB 12.9.0
ThumbGensPack 2014年12月22日 11:48:18 2015/01/08
Windows Live Essentials Microsoft Corporation 2015/01/06 15.4.3538.0513
リモート接続用の Windows Live Mesh ActiveX コントロール (日本語) Microsoft Corporation 2015/01/06 5.57 MB 15.4.5722.2
読んde!!ココ パーソナル 2015/01/08

以上です。
  • penpen
  • 2015/01/29 (Thu) 01:29:35
つなぎのレスです
こんにちは。
ここの管理人の悪代官です。
IVNOさんがご多忙なので、貧乏な自分がつなぎのレスします。

ログを見せていただきましたが、さすがにリカバリ後だけあってきれいになってますね。

それでは念のためもう少し深く見てみましょうか。
先に使ったOTLを再度用意して、また下記をコピペで貼り付けてスキャンしてから、その結果ログをレスで見せてください。

%windir%\tasks\*.job
DRIVES
BASESERVICES
%SYSTEMDRIVE%\*.exe
CREATERESTOREPOINT

この結果ログを見て、変なものが残ってなければセーフかと思います
  • 悪代官
  • 2015/01/29 (Thu) 14:27:24
OTLログ1
悪代官様、ご返信ありがとうございます。

OTLのログになります。

OTL logfile created on: 2015/01/31 0:05:11 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\dEaAD2sZ\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

7.98 Gb Total Physical Memory | 7.29 Gb Available Physical Memory | 91.35% Memory free
15.95 Gb Paging File | 15.30 Gb Available in Paging File | 95.89% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 765.43 Gb Free Space | 82.18% Space Free | Partition Type: NTFS

Computer Name: PC | User Name: ZexqTTA3 | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2015/01/30 23:41:45 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\dEaAD2sZ\Desktop\OTL.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2015/01/06 21:03:44 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2014/10/01 14:40:28 | 001,349,576 | ---- | M] (ESET) [Auto | Stopped] -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe -- (ekrn)
SRV:[b]64bit:[/b] - [2013/05/27 14:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2012/05/17 00:00:00 | 000,144,560 | ---- | M] (Seiko Epson Corporation) [Auto | Stopped] -- C:\Windows\SysNative\escsvc64.exe -- (EpsonScanSvc)
SRV:[b]64bit:[/b] - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:[b]64bit:[/b] - [2009/07/14 10:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2015/01/28 06:42:22 | 000,114,800 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2015/01/26 17:30:09 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015/01/06 21:58:13 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2014/12/03 10:06:32 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/07/03 02:44:41 | 000,411,936 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2014/03/21 07:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2013/12/18 01:56:16 | 000,754,712 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe -- (GoogleIMEJaCacheService)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012/09/19 09:18:38 | 000,474,624 | ---- | M] (Sony Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Sony\NFC Proxy Service\bin\NFCProxyService.exe -- (NFCProxyService)
SRV - [2011/09/14 22:06:38 | 000,169,624 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor10.0)
SRV - [2011/05/20 10:10:26 | 000,013,592 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2010/11/17 13:21:56 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010/11/17 13:21:54 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2015/01/23 00:23:34 | 000,026,528 | ---- | M] (REALiX(tm)) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\HWiNFO64A.SYS -- (HWiNFO32)
DRV:[b]64bit:[/b] - [2014/09/22 07:20:06 | 000,243,440 | ---- | M] (ESET) [File_System | System | Stopped] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:[b]64bit:[/b] - [2014/09/22 07:20:06 | 000,222,280 | ---- | M] (ESET) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\epfw.sys -- (epfw)
DRV:[b]64bit:[/b] - [2014/09/22 07:20:06 | 000,169,280 | ---- | M] (ESET) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:[b]64bit:[/b] - [2014/09/22 07:20:06 | 000,063,160 | ---- | M] (ESET) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\epfwwfp.sys -- (epfwwfp)
DRV:[b]64bit:[/b] - [2014/09/22 07:20:06 | 000,044,632 | ---- | M] (ESET) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\EpfwLWF.sys -- (EpfwLWF)
DRV:[b]64bit:[/b] - [2014/08/19 22:14:52 | 000,197,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:[b]64bit:[/b] - [2014/03/19 15:23:28 | 000,050,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:[b]64bit:[/b] - [2013/10/02 11:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2012/08/23 23:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2012/08/23 23:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2012/03/29 20:12:26 | 000,042,048 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sonyfelicaportm.sys -- (sonyfelicaportm)
DRV:[b]64bit:[/b] - [2012/03/01 15:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2012/01/12 10:36:02 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2012/01/12 10:36:02 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2011/12/03 07:06:04 | 000,023,832 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorF.sys -- (iaStorF)
DRV:[b]64bit:[/b] - [2011/12/03 07:06:00 | 000,565,528 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:[b]64bit:[/b] - [2011/11/23 23:02:20 | 000,648,808 | ---- | M] (Realtek ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2011/09/23 18:59:08 | 000,290,600 | ---- | M] (Advanced Micro Devices, Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ahcix64s.sys -- (ahcix64s)
DRV:[b]64bit:[/b] - [2011/05/20 09:53:44 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:[b]64bit:[/b] - [2011/04/13 18:30:54 | 000,207,872 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:[b]64bit:[/b] - [2011/04/13 18:30:50 | 000,087,552 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:[b]64bit:[/b] - [2010/11/21 12:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2010/11/21 12:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:[b]64bit:[/b] - [2010/08/04 11:18:54 | 000,110,824 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Sonyddpu.sys -- (Sonyddpu)
DRV:[b]64bit:[/b] - [2010/03/19 03:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:[b]64bit:[/b] - [2009/07/14 10:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/14 10:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/14 10:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/11 05:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/14 10:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=MOCJ&bmod=MOCJ
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?brand=MOCJ&bmod=MOCJ
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=MOCJ&bmod=MOCJ
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?brand=MOCJ&bmod=MOCJ
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\ZexqTTA3\Desktop
IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=MOCJ&bmod=MOCJ
IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.co.jp/
IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1000\..\SearchScopes,DefaultScope = {68298B50-3BD8-48C0-A860-EE4AB2523B04}
IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1000\..\SearchScopes\{68298B50-3BD8-48C0-A860-EE4AB2523B04}: "URL" = https://www.google.com/search?q={searchTerms}
IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\dEaAD2sZ\Desktop
IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.co.jp/
IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/ja-jp/?ocid=iehp
IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = ja-JP
IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = DC 8F 37 41 45 2A D0 01 [binary data]
IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1002\..\SearchScopes,DefaultScope = {D6CA8907-1D8A-4233-BDF9-6AC0269E727C}
IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1002\..\SearchScopes\{D6CA8907-1D8A-4233-BDF9-6AC0269E727C}: "URL" = http://www.google.co.jp/search?hl=ja&q={searchTerms}&lr=lang_ja
IE - HKU\S-1-5-21-1099055701-4194996230-893242877-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.isUS: false
FF - prefs.js..browser.startup.homepage: "https://www.google.co.jp/"
FF - prefs.js..extensions.enabledAddons: web2pdfextension%40web2pdf.adobedotcom:1.2
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:34.0.5
FF - user.js - File not found

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll File not found
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2015/01/08 01:11:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2015/01/22 23:21:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2015/01/22 23:21:31 | 000,000,000 | ---D | M]

[2015/01/06 23:14:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ZexqTTA3\AppData\Roaming\Mozilla\Extensions
[2015/01/06 23:33:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ZexqTTA3\AppData\Roaming\Mozilla\Firefox\Profiles\5a62awbj.default\extensions
[2015/01/28 06:42:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2015/01/28 06:42:23 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

O1 HOSTS File: ([2009/06/11 06:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2:[b]64bit:[/b] - BHO: (RoboForm Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (RoboForm Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Evernote extension) - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (&RoboForm Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (&RoboForm Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1099055701-4194996230-893242877-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3:[b]64bit:[/b] - HKU\S-1-5-21-1099055701-4194996230-893242877-1000\..\Toolbar\WebBrowser: (&RoboForm Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-21-1099055701-4194996230-893242877-1000\..\Toolbar\WebBrowser: (&RoboForm Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3:[b]64bit:[/b] - HKU\S-1-5-21-1099055701-4194996230-893242877-1002\..\Toolbar\WebBrowser: (&RoboForm Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-21-1099055701-4194996230-893242877-1002\..\Toolbar\WebBrowser: (&RoboForm Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:[b]64bit:[/b] - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:[b]64bit:[/b] - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Google Japanese Input Prelauncher] C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe (Google Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1099055701-4194996230-893242877-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-1099055701-4194996230-893242877-1000..\Run: [RoboForm] C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKU\S-1-5-21-1099055701-4194996230-893242877-1002..\Run: [RoboForm] C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\dEaAD2sZ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:[b]64bit:[/b] - Extra context menu item: Google サイドウィキ... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html File not found
O8:[b]64bit:[/b] - Extra context menu item: RF ツールバー表示 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComShowToolbar.html File not found
O8:[b]64bit:[/b] - Extra context menu item: RF フォーム記入 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComFillForms.html File not found
O8:[b]64bit:[/b] - Extra context menu item: RF フォーム保存 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComSavePass.html File not found
O8:[b]64bit:[/b] - Extra context menu item: RF メニューカスタマイズ - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComCustomizeIEMenu.html File not found
O8:[b]64bit:[/b] - Extra context menu item: URL をクリップ - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0 File not found
O8:[b]64bit:[/b] - Extra context menu item: このページをクリップ - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=1 File not found
O8:[b]64bit:[/b] - Extra context menu item: ブックマークをクリップ - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0 File not found
O8:[b]64bit:[/b] - Extra context menu item: 画像をクリップ - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=4 File not found
O8:[b]64bit:[/b] - Extra context menu item: 新規ノート - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html ()
O8:[b]64bit:[/b] - Extra context menu item: 選択部分をクリップ - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=3 File not found
O8 - Extra context menu item: Google サイドウィキ... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html File not found
O8 - Extra context menu item: RF ツールバー表示 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComShowToolbar.html File not found
O8 - Extra context menu item: RF フォーム記入 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComFillForms.html File not found
O8 - Extra context menu item: RF フォーム保存 - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComSavePass.html File not found
O8 - Extra context menu item: RF メニューカスタマイズ - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComCustomizeIEMenu.html File not found
O8 - Extra context menu item: URL をクリップ - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0 File not found
O8 - Extra context menu item: このページをクリップ - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=1 File not found
O8 - Extra context menu item: ブックマークをクリップ - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0 File not found
O8 - Extra context menu item: 画像をクリップ - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=4 File not found
O8 - Extra context menu item: 新規ノート - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html ()
O8 - Extra context menu item: 選択部分をクリップ - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=3 File not found
O9:[b]64bit:[/b] - Extra Button: フォーム記入 - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : RF フォーム記入 - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:[b]64bit:[/b] - Extra Button: 保存 - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : RF フォーム保存 - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:[b]64bit:[/b] - Extra Button: ツールバー表示 - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : RF ツールバー表示 - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:[b]64bit:[/b] - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\AddNote.html ()
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\AddNote.html ()
O9 - Extra Button: フォーム記入 - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : RF フォーム記入 - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: 保存 - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : RF フォーム保存 - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: ツールバー表示 - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : RF ツールバー表示 - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html ()
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html ()
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.3.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2B6F2420-FD04-40B6-A911-773620365763}: DhcpNameServer = 192.168.3.1
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084
  • penpen
  • 2015/01/31 (Sat) 01:55:52
OTLログ2
OTLログ2

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2015/01/30 16:05:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2015/01/30 03:01:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2015/01/30 03:01:06 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2015/01/30 03:01:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2015/01/29 00:58:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2015/01/29 00:58:24 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2015/01/28 23:40:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\honto
[2015/01/28 23:40:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\honto
[2015/01/28 06:42:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2015/01/23 00:23:34 | 000,026,528 | ---- | C] (REALiX(tm)) -- C:\Windows\SysNative\drivers\HWiNFO64A.SYS
[2015/01/23 00:22:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HWiNFO64
[2015/01/23 00:22:50 | 000,000,000 | ---D | C] -- C:\Program Files\HWiNFO64
[2015/01/23 00:22:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2015/01/23 00:22:38 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
[2015/01/23 00:22:23 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Local\Programs
[2015/01/22 23:40:01 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\Desktop\openhardwaremonitor-v0.7.1-beta
[2015/01/14 17:45:09 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncsi.dll
[2015/01/14 17:45:07 | 005,553,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2015/01/14 17:45:07 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWbPrxy.exe
[2015/01/14 17:45:06 | 003,971,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2015/01/14 17:45:06 | 003,916,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2015/01/14 17:45:05 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2015/01/14 17:45:05 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2015/01/14 17:45:05 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll
[2015/01/08 20:42:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ThumbGensPack
[2015/01/08 19:23:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 64-bit fixes
[2015/01/08 19:23:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe Reader 64-bit fixes
[2015/01/08 19:19:29 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2015/01/08 02:01:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2015/01/08 01:57:00 | 000,000,000 | ---D | C] -- C:\ProgramData\EPSON
[2015/01/08 01:46:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2015/01/08 01:46:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2015/01/08 01:43:34 | 000,055,856 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\PxHlpa64.sys
[2015/01/08 01:43:34 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdralw2k.sys
[2015/01/08 01:43:34 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdr4_xp.sys
[2015/01/08 01:43:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared
[2015/01/08 01:43:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2015/01/08 01:25:00 | 001,069,088 | ---- | C] (Sony Corporation) -- C:\Windows\SysNative\NFCPort.cpl
[2015/01/08 01:25:00 | 000,000,000 | ---D | C] -- C:\Program Files\Sony
[2015/01/08 01:25:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NFCポート
[2015/01/08 01:24:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Sony Shared
[2015/01/08 01:24:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sony Shared
[2015/01/08 01:17:34 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Roaming\Epson
[2015/01/08 01:04:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\読んde!!ココ
[2015/01/08 01:04:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Aisoft
[2015/01/08 01:03:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2015/01/08 01:03:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson Software
[2015/01/08 01:03:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Epson Software
[2015/01/08 01:01:35 | 000,266,240 | ---- | C] (SEIKO EPSON CORP.) -- C:\Windows\SysWow64\esinta1.dll
[2015/01/08 01:01:35 | 000,236,544 | ---- | C] (SEIKO EPSON CORP.) -- C:\Windows\SysNative\esxuina1.dll
[2015/01/08 01:01:35 | 000,144,560 | ---- | C] (Seiko Epson Corporation) -- C:\Windows\SysNative\escsvc64.exe
[2015/01/08 01:01:35 | 000,093,696 | ---- | C] (Seiko Epson Corporation.) -- C:\Windows\SysNative\esxw2_a1.dll
[2015/01/08 01:01:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
[2015/01/08 01:01:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\epson
[2015/01/08 00:56:41 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2015/01/08 00:54:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2015/01/08 00:54:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2015/01/08 00:54:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2015/01/08 00:25:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2015/01/07 23:51:49 | 001,721,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WdfCoInstaller01009.dll
[2015/01/07 23:51:49 | 000,110,824 | ---- | C] (Sony Corporation) -- C:\Windows\SysNative\drivers\Sonyddpu.sys
[2015/01/07 23:51:49 | 000,042,048 | ---- | C] (Sony Corporation) -- C:\Windows\SysNative\drivers\sonyfelicaportm.sys
[2015/01/07 23:51:49 | 000,023,616 | ---- | C] (Sony Corporation) -- C:\Windows\SysNative\felicaport_cls.dll
[2015/01/07 23:51:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony
[2015/01/07 18:27:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shuriken 2014
[2015/01/07 18:27:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Justsystem
[2015/01/07 18:27:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Justsystems
[2015/01/07 18:27:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Justsystem
[2015/01/07 18:22:32 | 056,106,416 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Users\ZexqTTA3\Desktop\shuriken2014_tr.exe
[2015/01/07 18:02:52 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Local\Evernote
[2015/01/07 18:02:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
[2015/01/07 18:02:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Evernote
[2015/01/07 17:27:38 | 000,000,000 | ---D | C] -- C:\ProgramData\RoboForm
[2015/01/07 17:27:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
[2015/01/07 17:27:37 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\Documents\My RoboForm Data
[2015/01/07 17:11:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Siber Systems
[2015/01/07 03:14:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\CANON
[2015/01/07 03:11:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
[2015/01/07 03:11:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Canon
[2015/01/07 03:11:06 | 000,000,000 | ---D | C] -- C:\Program Files\Canon
[2015/01/07 02:51:07 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonBJ
[2015/01/07 02:51:05 | 000,000,000 | -H-D | C] -- C:\Windows\SysNative\CanonIJ Uninstaller Information
[2015/01/07 02:51:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon iP2700 series
[2015/01/07 02:51:02 | 000,385,024 | ---- | C] (CANON INC.) -- C:\Windows\SysNative\CNMLMA4.DLL
[2015/01/07 02:51:01 | 000,245,760 | ---- | C] (CANON INC.) -- C:\Windows\SysNative\CNMIUA4.DLL
[2015/01/07 02:50:57 | 000,000,000 | -H-D | C] -- C:\Program Files\CanonBJ
[2015/01/06 23:30:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Emurasoft
[2015/01/06 23:29:52 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Local\Emurasoft
[2015/01/06 23:29:46 | 000,000,000 | ---D | C] -- C:\Program Files\EmEditor
[2015/01/06 23:22:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2015/01/06 23:14:12 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Roaming\Mozilla
[2015/01/06 23:14:12 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Local\Mozilla
[2015/01/06 23:14:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2015/01/06 23:14:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2015/01/06 22:58:50 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2015/01/06 22:58:50 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2015/01/06 22:52:33 | 003,179,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll
[2015/01/06 22:52:33 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2015/01/06 22:52:11 | 006,584,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2015/01/06 22:52:11 | 005,703,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2015/01/06 22:36:49 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Roaming\Macromedia
[2015/01/06 22:36:32 | 000,701,616 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2015/01/06 22:36:32 | 000,071,344 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2015/01/06 22:36:31 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2015/01/06 22:36:30 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2015/01/06 22:35:49 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Local\Adobe
[2015/01/06 22:33:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft マウス キーボード センター
[2015/01/06 22:33:26 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Mouse and Keyboard Center
[2015/01/06 22:32:56 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2015/01/06 22:32:55 | 001,147,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe
[2015/01/06 22:32:55 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
[2015/01/06 22:32:55 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprt.exe
[2015/01/06 22:32:55 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
[2015/01/06 22:32:55 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2015/01/06 22:32:55 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsRdpWebAccess.dll
[2015/01/06 22:32:55 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
[2015/01/06 22:32:55 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MsRdpWebAccess.dll
[2015/01/06 22:32:55 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprtPS.dll
[2015/01/06 22:32:55 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wksprtPS.dll
[2015/01/06 22:32:55 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2015/01/06 22:32:55 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2015/01/06 22:32:54 | 001,057,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdvidcrl.dll
[2015/01/06 22:32:54 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdvidcrl.dll
[2015/01/06 22:31:09 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpendp_winip.dll
[2015/01/06 22:31:09 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\TsUsbGD.sys
[2015/01/06 22:31:09 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2015/01/06 22:31:08 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpudd.dll
[2015/01/06 22:31:08 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpendp_winip.dll
[2015/01/06 22:30:04 | 000,609,240 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe
[2015/01/06 22:15:17 | 002,777,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2vdec.dll
[2015/01/06 22:15:17 | 002,285,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msmpeg2vdec.dll
[2015/01/06 22:13:40 | 001,424,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll
[2015/01/06 22:13:39 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2015/01/06 22:13:30 | 002,871,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2015/01/06 22:13:30 | 002,616,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe
[2015/01/06 22:13:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDYAK.DLL
[2015/01/06 22:13:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDYAK.DLL
[2015/01/06 22:13:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDTAT.DLL
[2015/01/06 22:13:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDTAT.DLL
[2015/01/06 22:13:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDRU1.DLL
[2015/01/06 22:13:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDBASH.DLL
[2015/01/06 22:13:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDRU1.DLL
[2015/01/06 22:13:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDRU.DLL
[2015/01/06 22:13:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDRU.DLL
[2015/01/06 22:13:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDBASH.DLL
[2015/01/06 22:13:26 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll
[2015/01/06 22:13:26 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll
[2015/01/06 22:13:13 | 003,928,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2015/01/06 22:13:12 | 002,565,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2015/01/06 22:12:14 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\splwow64.exe
[2015/01/06 22:09:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2015/01/06 22:09:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
[2015/01/06 22:08:36 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2015/01/06 22:08:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2015/01/06 22:08:17 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Local\Microsoft Help
[2015/01/06 22:08:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2015/01/06 22:08:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2015/01/06 22:07:53 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2015/01/06 22:02:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2015/01/06 22:01:35 | 000,000,000 | ---D | C] -- C:\temp
[2015/01/06 21:58:44 | 016,122,344 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2015/01/06 21:58:44 | 001,760,104 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco64.dll
[2015/01/06 21:58:44 | 001,482,600 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco64.dll
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\2C0A
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0C0A
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0C04
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0816
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0804
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0424
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\041F
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\041E
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\041D
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\041B
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0419
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0416
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0415
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0414
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0413
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0412
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0410
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\040E
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\040D
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\040C
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\040B
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\040A
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0409
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0408
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0407
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0406
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0405
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0404
[2015/01/06 21:57:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0401
[2015/01/06 21:56:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Renesas Electronics
[2015/01/06 21:56:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Renesas Electronics
[2015/01/06 21:55:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Downloaded Installations
[2015/01/06 21:54:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel Corporation
[2015/01/06 21:50:56 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Roaming\Intel Corporation
[2015/01/06 21:49:01 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
[2015/01/06 21:48:46 | 000,557,848 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\iaStor.sys
[2015/01/06 21:48:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\postureAgent
[2015/01/06 21:46:55 | 000,000,000 | ---D | C] -- C:\Intel
[2015/01/06 21:46:51 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2015/01/06 21:46:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel
[2015/01/06 21:46:50 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Roaming\InstallShield
[2015/01/06 21:44:18 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\AppData\Local\EmieUserList
[2015/01/06 21:44:18 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\AppData\Local\EmieSiteList
[2015/01/06 21:44:18 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\AppData\Local\EmieBrowserModeList
[2015/01/06 21:42:27 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Roaming\Adobe
[2015/01/06 21:41:12 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Local\NVIDIA
[2015/01/06 21:25:58 | 000,000,000 | --SD | C] -- C:\Windows\SysNative\CompatTel
[2015/01/06 21:25:58 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appraiser
[2015/01/06 21:21:06 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2015/01/06 21:21:05 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2015/01/06 21:21:05 | 011,410,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2015/01/06 21:21:04 | 014,631,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2015/01/06 21:12:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2015/01/06 21:12:46 | 000,000,000 | ---D | C] -- C:\Windows\Migration
[2015/01/06 21:07:51 | 000,028,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEUDINIT.EXE
[2015/01/06 21:03:50 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2015/01/06 21:03:48 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2015/01/06 21:03:48 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2015/01/06 21:03:48 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2015/01/06 21:03:48 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2015/01/06 21:03:48 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2015/01/06 21:03:48 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2015/01/06 21:03:48 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2015/01/06 21:03:48 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2015/01/06 21:03:47 | 002,052,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2015/01/06 21:03:47 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2015/01/06 21:03:47 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2015/01/06 21:03:47 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2015/01/06 21:03:47 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2015/01/06 21:03:47 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2015/01/06 21:03:47 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2015/01/06 21:03:47 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2015/01/06 21:03:47 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2015/01/06 21:03:47 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2015/01/06 21:03:47 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2015/01/06 21:03:47 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2015/01/06 21:03:47 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2015/01/06 21:03:47 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2015/01/06 21:03:47 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2015/01/06 21:03:47 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2015/01/06 21:03:47 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2015/01/06 21:03:47 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2015/01/06 21:03:46 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2015/01/06 21:03:46 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2015/01/06 21:03:46 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2015/01/06 21:03:46 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2015/01/06 21:03:46 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2015/01/06 21:03:46 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2015/01/06 21:03:46 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2015/01/06 21:03:46 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2015/01/06 21:03:46 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2015/01/06 21:03:46 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2015/01/06 21:03:46 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2015/01/06 21:03:46 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2015/01/06 21:03:46 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2015/01/06 21:03:46 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2015/01/06 21:03:46 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2015/01/06 21:03:45 | 006,039,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2015/01/06 21:03:45 | 002,125,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2015/01/06 21:03:45 | 001,359,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2015/01/06 21:03:45 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2015/01/06 21:03:45 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2015/01/06 21:03:45 | 000,718,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2015/01/06 21:03:45 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2015/01/06 21:03:45 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2015/01/06 21:03:45 | 000,580,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2015/01/06 21:03:45 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2015/01/06 21:03:45 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2015/01/06 21:03:45 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2015/01/06 21:03:45 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2015/01/06 21:03:45 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2015/01/06 21:03:45 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2015/01/06 21:03:45 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2015/01/06 21:03:45 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2015/01/06 21:03:45 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2015/01/06 21:03:45 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2015/01/06 21:03:45 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2015/01/06 21:03:45 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2015/01/06 21:03:45 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2015/01/06 21:03:45 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2015/01/06 21:03:45 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2015/01/06 21:03:45 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2015/01/06 21:03:44 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2015/01/06 21:03:44 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2015/01/06 21:03:44 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2015/01/06 21:03:44 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2015/01/06 21:03:44 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2015/01/06 21:03:44 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2015/01/06 21:03:44 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2015/01/06 21:03:44 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2015/01/06 21:03:44 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2015/01/06 21:03:44 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2015/01/06 20:59:30 | 001,682,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll
[2015/01/06 20:59:30 | 001,158,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll
[2015/01/06 20:59:30 | 000,522,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll
[2015/01/06 20:59:30 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll
[2015/01/06 20:59:30 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2015/01/06 20:59:30 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2015/01/06 20:59:30 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2015/01/06 20:59:30 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2015/01/06 20:59:30 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2015/01/06 20:59:30 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2015/01/06 20:59:30 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2015/01/06 20:59:30 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2015/01/06 20:59:30 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2015/01/06 20:59:30 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2015/01/06 20:59:29 | 001,643,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2015/01/06 20:59:29 | 001,238,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10.dll
[2015/01/06 20:59:29 | 000,648,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll
[2015/01/06 20:59:29 | 000,363,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll
[2015/01/06 20:59:29 | 000,333,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll
[2015/01/06 20:59:29 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10core.dll
[2015/01/06 20:59:29 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecsExt.dll
[2015/01/06 20:59:29 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIAnimation.dll
[2015/01/06 20:59:29 | 000,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll
[2015/01/06 20:59:29 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAnimation.dll
[2015/01/06 20:45:35 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT
[2015/01/06 20:23:13 | 003,209,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2015/01/06 20:23:13 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2015/01/06 20:23:13 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll
[2015/01/06 20:23:13 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rrinstaller.exe
[2015/01/06 20:23:13 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rrinstaller.exe
[2015/01/06 20:23:13 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfpmp.exe
[2015/01/06 20:23:13 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfpmp.exe
[2015/01/06 20:23:13 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mferror.dll
[2015/01/06 20:23:13 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mferror.dll
[2015/01/06 20:23:12 | 004,121,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2015/01/06 20:22:09 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFx.dll
[2015/01/06 20:22:09 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFHost.exe
[2015/01/06 20:22:09 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFPlatform.dll
[2015/01/06 20:22:09 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFCoinstaller.dll
[2015/01/06 20:19:06 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2015/01/06 20:18:48 | 006,783,776 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll
[2015/01/06 20:18:48 | 003,522,392 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll
[2015/01/06 20:18:48 | 002,559,960 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll
[2015/01/06 20:18:48 | 000,386,520 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll
[2015/01/06 20:18:48 | 000,062,808 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll
[2015/01/06 20:18:37 | 000,075,040 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2015/01/06 20:18:37 | 000,061,912 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2015/01/06 20:18:29 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2015/01/06 20:18:25 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2015/01/06 20:18:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2015/01/06 20:15:45 | 000,023,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fs_rec.sys
[2015/01/06 20:11:32 | 001,389,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardagt.exe
[2015/01/06 20:11:32 | 000,619,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardagt.exe
[2015/01/06 20:11:32 | 000,171,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\infocardapi.dll
[2015/01/06 20:11:32 | 000,099,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\infocardapi.dll
[2015/01/06 20:11:32 | 000,008,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardres.dll
[2015/01/06 20:11:32 | 000,008,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardres.dll
[2015/01/06 20:11:28 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TsWpfWrp.exe
[2015/01/06 20:11:28 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsWpfWrp.exe
[2015/01/06 20:10:35 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptdlg.dll
[2015/01/06 20:10:34 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptdlg.dll
[2015/01/06 20:08:29 | 001,474,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2015/01/06 20:08:29 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2015/01/06 20:08:22 | 000,722,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\objsel.dll
[2015/01/06 20:08:22 | 000,538,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\objsel.dll
[2015/01/06 20:08:22 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2015/01/06 20:08:22 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2015/01/06 20:08:22 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cngprovider.dll
[2015/01/06 20:08:22 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adprovider.dll
[2015/01/06 20:08:22 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\capiprovider.dll
[2015/01/06 20:08:22 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpapiprovider.dll
[2015/01/06 20:08:22 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cngprovider.dll
[2015/01/06 20:08:22 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adprovider.dll
[2015/01/06 20:08:22 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\capiprovider.dll
[2015/01/06 20:08:22 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dpapiprovider.dll
[2015/01/06 20:08:22 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dimsroam.dll
[2015/01/06 20:08:22 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2015/01/06 20:08:22 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wincredprovider.dll
[2015/01/06 20:08:22 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dimsroam.dll
[2015/01/06 20:08:22 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wincredprovider.dll
[2015/01/06 20:08:22 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll
[2015/01/06 20:08:22 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apisetschema.dll
[2015/01/06 20:08:18 | 000,658,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe
[2015/01/06 20:08:18 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe
[2015/01/06 20:08:18 | 000,594,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe
[2015/01/06 20:08:18 | 000,572,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe
[2015/01/06 20:08:18 | 000,553,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe
[2015/01/06 20:08:18 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2015/01/06 20:08:18 | 000,528,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdrm.dll
[2015/01/06 20:08:18 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe
[2015/01/06 20:08:18 | 000,508,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2015/01/06 20:08:18 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll
[2015/01/06 20:08:18 | 000,485,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll
[2015/01/06 20:08:18 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2015/01/06 20:08:18 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll
[2015/01/06 20:08:18 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll
[2015/01/06 20:08:18 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll
[2015/01/06 20:08:18 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll
[2015/01/06 20:08:18 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll
[2015/01/06 20:08:14 | 000,681,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adtschema.dll
[2015/01/06 20:08:14 | 000,681,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adtschema.dll
[2015/01/06 20:08:14 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msaudite.dll
[2015/01/06 20:08:14 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msaudite.dll
[2015/01/06 20:07:58 | 002,746,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gameux.dll
[2015/01/06 20:07:58 | 002,576,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gameux.dll
[2015/01/06 20:07:58 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wpc.dll
[2015/01/06 20:07:58 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Wpc.dll
[2015/01/06 20:07:58 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\cero.rs
[2015/01/06 20:07:58 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\SysNative\cero.rs
[2015/01/06 20:07:58 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\esrb.rs
[2015/01/06 20:07:58 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\SysNative\esrb.rs
[2015/01/06 20:07:58 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\fpb.rs
[2015/01/06 20:07:58 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\SysNative\fpb.rs
[2015/01/06 20:07:58 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\oflc-nz.rs
[2015/01/06 20:07:58 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\SysNative\oflc-nz.rs
[2015/01/06 20:07:58 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegibbfc.rs
[2015/01/06 20:07:58 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegibbfc.rs
[2015/01/06 20:07:58 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\csrr.rs
[2015/01/06 20:07:58 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\SysNative\csrr.rs
[2015/01/06 20:07:58 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\cob-au.rs
[2015/01/06 20:07:58 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\SysNative\cob-au.rs
[2015/01/06 20:07:58 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\usk.rs
[2015/01/06 20:07:58 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\SysNative\usk.rs
[2015/01/06 20:07:58 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\oflc.rs
[2015/01/06 20:07:58 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\SysNative\oflc.rs
[2015/01/06 20:07:58 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\grb.rs
[2015/01/06 20:07:58 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\SysNative\grb.rs
[2015/01/06 20:07:58 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi-pt.rs
[2015/01/06 20:07:58 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi-pt.rs
[2015/01/06 20:07:58 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi-fi.rs
[2015/01/06 20:07:58 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi-fi.rs
[2015/01/06 20:07:58 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi.rs
[2015/01/06 20:07:58 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi.rs
[2015/01/06 20:07:58 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\djctq.rs
[2015/01/06 20:07:58 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\SysNative\djctq.rs
  • penpen
  • 2015/01/31 (Sat) 01:57:21
OTLログ3
OTLログ3

[2015/01/06 20:07:53 | 001,460,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2015/01/06 20:07:53 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2015/01/06 20:07:53 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2015/01/06 20:07:53 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2015/01/06 20:07:50 | 000,265,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2015/01/06 20:07:50 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2015/01/06 20:07:49 | 000,368,128 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
[2015/01/06 20:07:49 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2015/01/06 20:07:49 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
[2015/01/06 20:07:49 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[2015/01/06 20:07:49 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll
[2015/01/06 20:07:49 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lpk.dll
[2015/01/06 20:07:49 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll
[2015/01/06 20:07:49 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dciman32.dll
[2015/01/06 20:07:45 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\synceng.dll
[2015/01/06 20:07:45 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\synceng.dll
[2015/01/06 20:07:05 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\poqexec.exe
[2015/01/06 20:07:05 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\poqexec.exe
[2015/01/06 20:07:04 | 000,509,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntshrui.dll
[2015/01/06 20:07:02 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll
[2015/01/06 20:07:00 | 001,732,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2015/01/06 20:07:00 | 000,878,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
[2015/01/06 20:07:00 | 000,859,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdh.dll
[2015/01/06 20:07:00 | 000,619,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdh.dll
[2015/01/06 20:06:57 | 000,224,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2015/01/06 20:06:51 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netcorehc.dll
[2015/01/06 20:06:51 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncsi.dll
[2015/01/06 20:06:51 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netcorehc.dll
[2015/01/06 20:06:51 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netevent.dll
[2015/01/06 20:06:51 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netevent.dll
[2015/01/06 20:06:48 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\davclnt.dll
[2015/01/06 20:06:46 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbcjt32.dll
[2015/01/06 20:06:46 | 000,212,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbctrac.dll
[2015/01/06 20:06:46 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbctrac.dll
[2015/01/06 20:06:46 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccp32.dll
[2015/01/06 20:06:46 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccp32.dll
[2015/01/06 20:06:46 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccu32.dll
[2015/01/06 20:06:46 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccr32.dll
[2015/01/06 20:06:46 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccu32.dll
[2015/01/06 20:06:46 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccr32.dll
[2015/01/06 20:06:45 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcore6.dll
[2015/01/06 20:06:45 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dhcpcore6.dll
[2015/01/06 20:06:45 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcsvc6.dll
[2015/01/06 20:06:41 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webio.dll
[2015/01/06 20:06:41 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webio.dll
[2015/01/06 20:06:40 | 002,315,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tquery.dll
[2015/01/06 20:06:40 | 002,223,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssrch.dll
[2015/01/06 20:06:40 | 001,549,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tquery.dll
[2015/01/06 20:06:40 | 001,401,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssrch.dll
[2015/01/06 20:06:40 | 000,778,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssvp.dll
[2015/01/06 20:06:40 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssvp.dll
[2015/01/06 20:06:40 | 000,491,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssph.dll
[2015/01/06 20:06:40 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssph.dll
[2015/01/06 20:06:40 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssphtb.dll
[2015/01/06 20:06:40 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchProtocolHost.exe
[2015/01/06 20:06:40 | 000,113,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFilterHost.exe
[2015/01/06 20:06:40 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscntrs.dll
[2015/01/06 20:06:40 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscntrs.dll
[2015/01/06 20:06:39 | 000,801,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usp10.dll
[2015/01/06 20:06:38 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll
[2015/01/06 20:06:38 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmartcardCredentialProvider.dll
[2015/01/06 20:06:38 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SmartcardCredentialProvider.dll
[2015/01/06 20:06:35 | 000,751,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll
[2015/01/06 20:06:35 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comctl32.dll
[2015/01/06 20:06:35 | 000,492,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll
[2015/01/06 20:06:33 | 000,335,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msieftp.dll
[2015/01/06 20:06:33 | 000,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msieftp.dll
[2015/01/06 20:06:32 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsapi.dll
[2015/01/06 20:06:32 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnscacheugc.exe
[2015/01/06 20:06:32 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dnscacheugc.exe
[2015/01/06 20:06:31 | 000,155,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ataport.sys
[2015/01/06 20:06:31 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imagehlp.dll
[2015/01/06 20:06:29 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanprotdim.dll
[2015/01/06 20:06:28 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usb8023.sys
[2015/01/06 20:06:27 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xmllite.dll
[2015/01/06 20:06:19 | 001,232,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aitstatic.exe
[2015/01/06 20:06:19 | 001,083,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2015/01/06 20:06:19 | 000,830,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appraiser.dll
[2015/01/06 20:06:19 | 000,741,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\invagent.dll
[2015/01/06 20:06:19 | 000,413,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll
[2015/01/06 20:06:19 | 000,396,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\devinv.dll
[2015/01/06 20:06:19 | 000,227,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2015/01/06 20:06:19 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepic.dll
[2015/01/06 20:06:17 | 001,943,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfshim.dll
[2015/01/06 20:06:17 | 001,131,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll
[2015/01/06 20:06:17 | 000,156,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscorier.dll
[2015/01/06 20:06:17 | 000,156,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscorier.dll
[2015/01/06 20:06:17 | 000,081,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscories.dll
[2015/01/06 20:06:17 | 000,073,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscories.dll
[2015/01/06 20:06:15 | 001,887,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll
[2015/01/06 20:06:15 | 001,505,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll
[2015/01/06 20:06:14 | 001,118,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sbe.dll
[2015/01/06 20:06:14 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll
[2015/01/06 20:06:14 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sbe.dll
[2015/01/06 20:06:14 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll
[2015/01/06 20:06:14 | 000,259,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax
[2015/01/06 20:06:14 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax
[2015/01/06 20:06:14 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfLdr.sys
[2015/01/06 20:06:14 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wdfres.dll
[2015/01/06 20:06:08 | 000,500,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AUDIOKSE.dll
[2015/01/06 20:06:08 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AUDIOKSE.dll
[2015/01/06 20:06:08 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll
[2015/01/06 20:06:08 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2015/01/06 20:06:08 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDump.dll
[2015/01/06 20:06:07 | 001,395,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfc42.dll
[2015/01/06 20:06:07 | 001,359,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfc42u.dll
[2015/01/06 20:06:07 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42u.dll
[2015/01/06 20:06:07 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42.dll
[2015/01/06 20:06:06 | 000,376,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys
[2015/01/06 20:06:06 | 000,288,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2015/01/06 20:06:05 | 001,888,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2015/01/06 20:06:05 | 001,620,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2015/01/06 20:06:05 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSManMigrationPlugin.dll
[2015/01/06 20:06:05 | 000,310,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmWmiPl.dll
[2015/01/06 20:06:05 | 000,266,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSManHTTPConfig.exe
[2015/01/06 20:06:05 | 000,248,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManMigrationPlugin.dll
[2015/01/06 20:06:05 | 000,214,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmWmiPl.dll
[2015/01/06 20:06:05 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManHTTPConfig.exe
[2015/01/06 20:06:05 | 000,181,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmAuto.dll
[2015/01/06 20:06:05 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmAuto.dll
[2015/01/06 20:06:04 | 000,642,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2015/01/06 20:06:04 | 000,605,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2015/01/06 20:06:04 | 000,566,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2015/01/06 20:06:04 | 000,518,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe
[2015/01/06 20:06:04 | 000,020,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdusb.dll
[2015/01/06 20:06:04 | 000,019,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kd1394.dll
[2015/01/06 20:06:04 | 000,017,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdcom.dll
[2015/01/06 20:06:03 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll
[2015/01/06 20:06:03 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll
[2015/01/06 20:06:03 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisrndr.ax
[2015/01/06 20:06:03 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisrndr.ax
[2015/01/06 20:06:02 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll
[2015/01/06 20:06:02 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll
[2015/01/06 20:06:01 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OxpsConverter.exe
[2015/01/06 20:06:00 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml6r.dll
[2015/01/06 20:06:00 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml6r.dll
[2015/01/06 20:05:59 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\RNDISMP.sys
[2015/01/06 20:05:58 | 000,692,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\osk.exe
[2015/01/06 20:05:58 | 000,646,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\osk.exe
[2015/01/06 20:05:56 | 000,878,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IMJP10K.DLL
[2015/01/06 20:05:56 | 000,701,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IMJP10K.DLL
[2015/01/06 20:05:55 | 001,031,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWorkspace.dll
[2015/01/06 20:05:55 | 000,793,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TSWorkspace.dll
[2015/01/06 20:05:50 | 000,624,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qedit.dll
[2015/01/06 20:05:50 | 000,509,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qedit.dll
[2015/01/06 20:05:48 | 001,572,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2015/01/06 20:05:48 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2015/01/06 20:05:46 | 000,124,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2015/01/06 20:05:46 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2015/01/06 20:05:44 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rastls.dll
[2015/01/06 20:05:44 | 000,372,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rastls.dll
[2015/01/06 20:05:42 | 000,484,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wer.dll
[2015/01/06 20:05:42 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wer.dll
[2015/01/06 20:05:41 | 000,190,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storport.sys
[2015/01/06 20:05:41 | 000,027,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys
[2015/01/06 20:05:41 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iologmsg.dll
[2015/01/06 20:05:41 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iologmsg.dll
[2015/01/06 20:05:38 | 000,165,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\charmap.exe
[2015/01/06 20:05:38 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\charmap.exe
[2015/01/06 20:05:36 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbport.sys
[2015/01/06 20:05:36 | 000,007,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbd.sys
[2015/01/06 20:05:34 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidclass.sys
[2015/01/06 20:05:34 | 000,032,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidparse.sys
[2015/01/06 20:05:32 | 000,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2015/01/06 20:05:32 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpnet.dll
[2015/01/06 20:05:32 | 000,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dpnet.dll
[2015/01/06 20:05:32 | 000,371,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2015/01/06 20:05:31 | 000,515,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\timedate.cpl
[2015/01/06 20:05:31 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\timedate.cpl
[2015/01/06 20:05:30 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskhost.exe
[2015/01/06 20:05:29 | 000,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\portcls.sys
[2015/01/06 20:05:29 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\drmk.sys
[2015/01/06 20:05:28 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drvinst.exe
[2015/01/06 20:05:28 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\devrtl.dll
[2015/01/06 20:03:23 | 000,861,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2015/01/06 20:03:21 | 000,830,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll
[2015/01/06 20:03:21 | 000,656,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll
[2015/01/06 20:03:21 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL
[2015/01/06 20:03:21 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL
[2015/01/06 19:59:19 | 000,455,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
[2015/01/06 19:59:19 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsta.dll
[2015/01/06 19:59:19 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2015/01/06 19:59:19 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
[2015/01/06 19:59:19 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
[2015/01/06 19:58:50 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2015/01/06 19:58:47 | 000,634,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcrt.dll
[2015/01/06 19:55:12 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netapi32.dll
[2015/01/06 19:55:12 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browcli.dll
[2015/01/06 19:55:12 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\browcli.dll
[2015/01/06 19:54:13 | 000,956,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll
[2015/01/06 19:53:40 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prevhost.exe
[2015/01/06 19:53:40 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prevhost.exe
[2015/01/06 19:53:23 | 003,241,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2015/01/06 19:53:23 | 001,941,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
[2015/01/06 19:53:23 | 001,805,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2015/01/06 19:53:23 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msihnd.dll
[2015/01/06 19:53:23 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msihnd.dll
[2015/01/06 19:53:23 | 000,112,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\consent.exe
[2015/01/06 19:53:15 | 000,461,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scavengeui.dll
[2015/01/06 19:53:11 | 001,192,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certutil.exe
[2015/01/06 19:53:11 | 000,903,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certutil.exe
[2015/01/06 19:53:10 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certenc.dll
[2015/01/06 19:53:10 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certenc.dll
[2015/01/06 19:53:07 | 001,163,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2015/01/06 19:53:07 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2015/01/06 19:53:07 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2015/01/06 19:53:07 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2015/01/06 19:53:06 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2015/01/06 19:53:06 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2015/01/06 19:53:06 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2015/01/06 19:53:06 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2015/01/06 19:53:06 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2015/01/06 19:53:06 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2015/01/06 19:53:06 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2015/01/06 19:53:06 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2015/01/06 19:53:06 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2015/01/06 19:53:06 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2015/01/06 19:53:06 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2015/01/06 19:53:06 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2015/01/06 19:53:06 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2015/01/06 19:53:06 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2015/01/06 19:53:06 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2015/01/06 19:53:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2015/01/06 19:53:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2015/01/06 19:53:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2015/01/06 19:53:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2015/01/06 19:53:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2015/01/06 19:53:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2015/01/06 19:53:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2015/01/06 19:53:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2015/01/06 19:53:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2015/01/06 19:53:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2015/01/06 19:53:06 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2015/01/06 19:53:04 | 001,216,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll
[2015/01/06 19:53:03 | 000,404,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
[2015/01/06 19:53:01 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdosys.dll
[2015/01/06 19:53:01 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdosys.dll
[2015/01/06 19:52:58 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2015/01/06 19:52:58 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2015/01/06 19:52:57 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scrrun.dll
[2015/01/06 19:52:57 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scrrun.dll
[2015/01/06 19:52:57 | 000,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cscript.exe
[2015/01/06 19:52:57 | 000,150,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wshom.ocx
[2015/01/06 19:52:57 | 000,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cscript.exe
[2015/01/06 19:52:57 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wshom.ocx
[2015/01/06 19:52:54 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSCOVER.exe
[2015/01/06 19:52:51 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleacc.dll
[2015/01/06 19:52:49 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll
[2015/01/06 19:52:49 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll
[2015/01/06 19:47:46 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Roaming\ESET
[2015/01/06 19:47:46 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Local\ESET
[2015/01/06 19:47:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2015/01/06 19:47:11 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET
[2015/01/06 19:47:11 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2015/01/06 19:46:04 | 001,031,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcore.dll
[2015/01/06 19:46:04 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpcore.dll
[2015/01/06 19:44:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2015/01/06 19:40:28 | 002,620,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2015/01/06 19:40:28 | 000,058,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2015/01/06 19:40:28 | 000,044,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2015/01/06 19:40:22 | 000,700,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2015/01/06 19:40:22 | 000,581,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll
[2015/01/06 19:40:22 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2015/01/06 19:40:22 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wudriver.dll
[2015/01/06 19:40:22 | 000,038,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2015/01/06 19:40:22 | 000,036,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wups.dll
[2015/01/06 19:40:16 | 000,198,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2015/01/06 19:40:16 | 000,179,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuwebv.dll
[2015/01/06 19:40:16 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2015/01/06 19:40:16 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapp.exe
[2015/01/06 19:36:35 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
[2015/01/06 19:36:35 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2015/01/06 18:45:12 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2015/01/06 18:35:38 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Local\Diagnostics
[2015/01/06 18:18:54 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Local\Google
[2015/01/06 18:10:14 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2015/01/06 18:10:14 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\Searches
[2015/01/06 18:10:14 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2015/01/06 18:10:14 | 000,000,000 | -H-D | C] -- C:\Users\ZexqTTA3\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2015/01/06 18:10:05 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Roaming\Identities
[2015/01/06 18:10:03 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\Contacts
[2015/01/06 18:10:01 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Local\VirtualStore
[2015/01/06 18:09:53 | 000,000,000 | --SD | C] -- C:\Users\ZexqTTA3\AppData\Roaming\Microsoft
[2015/01/06 18:09:53 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\Videos
[2015/01/06 18:09:53 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\Saved Games
[2015/01/06 18:09:53 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\Pictures
[2015/01/06 18:09:53 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\Music
[2015/01/06 18:09:53 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2015/01/06 18:09:53 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\Links
[2015/01/06 18:09:53 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\Favorites
[2015/01/06 18:09:53 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\Downloads
[2015/01/06 18:09:53 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\Documents
[2015/01/06 18:09:53 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\Desktop
[2015/01/06 18:09:53 | 000,000,000 | R--D | C] -- C:\Users\ZexqTTA3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\スタート メニュー
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\AppData\Local\Temporary Internet Files
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\Templates
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\SendTo
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\Recent
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\PrintHood
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\NetHood
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\Documents\My Videos
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\Documents\My Pictures
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\Documents\My Music
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\My Documents
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\Local Settings
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\AppData\Local\History
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\Cookies
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\Application Data
[2015/01/06 18:09:53 | 000,000,000 | -HSD | C] -- C:\Users\ZexqTTA3\AppData\Local\Application Data
[2015/01/06 18:09:53 | 000,000,000 | -H-D | C] -- C:\Users\ZexqTTA3\AppData
[2015/01/06 18:09:53 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Local\Temp
[2015/01/06 18:09:53 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Local\Microsoft
[2015/01/06 18:09:53 | 000,000,000 | ---D | C] -- C:\Users\ZexqTTA3\AppData\Roaming\Media Center Programs
[2015/01/06 18:09:48 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2015/01/06 18:09:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2015/01/06 18:09:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Partner
[2015/01/06 18:09:02 | 000,000,000 | ---D | C] -- C:\Windows\ja
[2015/01/06 18:08:16 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2015/01/06 18:07:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2015/01/06 18:07:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live
[2015/01/06 18:06:51 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2015/01/06 18:06:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Live Remote
[2015/01/06 18:06:37 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2015/01/06 18:06:18 | 000,523,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_42.dll
[2015/01/06 18:06:18 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_5.dll
[2015/01/06 18:06:18 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_42.dll
[2015/01/06 18:06:18 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_3.dll
[2015/01/06 18:05:55 | 004,398,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_32.dll
[2015/01/06 18:05:55 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_32.dll
[2015/01/06 18:04:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live
[2015/01/06 18:04:13 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2015/01/06 18:04:06 | 000,000,000 | -HSD | C] -- C:\ProgramData\デスクトップ
[2015/01/06 18:04:06 | 000,000,000 | -HSD | C] -- C:\ProgramData\スタート メニュー
[2015/01/06 18:04:06 | 000,000,000 | -HSD | C] -- C:\Recovery
[2015/01/06 18:04:03 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2015/01/06 17:57:49 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2015/01/06 17:57:20 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2015/01/06 17:56:48 | 000,000,000 | ---D | C] -- C:\Windows\Panther
  • penpen
  • 2015/01/31 (Sat) 01:58:55
OTLログ4
OTLログ4

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2015/01/31 00:01:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015/01/31 00:01:14 | 2129,919,999 | -HS- | M] () -- C:\hiberfil.sys
[2015/01/30 23:30:00 | 000,000,626 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015/01/30 23:19:00 | 000,000,690 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/01/30 23:14:13 | 000,016,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015/01/30 23:14:13 | 000,016,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015/01/30 23:07:33 | 000,000,686 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/01/29 00:58:26 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2015/01/27 05:54:15 | 001,310,874 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2015/01/27 05:54:15 | 000,653,526 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2015/01/27 05:54:15 | 000,410,434 | ---- | M] () -- C:\Windows\SysNative\perfh011.dat
[2015/01/27 05:54:15 | 000,121,480 | ---- | M] () -- C:\Windows\SysNative\perfc011.dat
[2015/01/27 05:54:15 | 000,121,398 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2015/01/26 17:30:09 | 000,701,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2015/01/26 17:30:09 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2015/01/23 00:23:34 | 000,026,528 | ---- | M] (REALiX(tm)) -- C:\Windows\SysNative\drivers\HWiNFO64A.SYS
[2015/01/13 00:40:54 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_sonyfelicaportm_01009.Wdf
[2015/01/08 19:55:29 | 000,403,677 | ---- | M] () -- C:\Users\ZexqTTA3\Desktop\150108kouhyou_1.pdf
[2015/01/08 01:48:22 | 000,325,144 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2015/01/07 18:23:48 | 056,106,416 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Users\ZexqTTA3\Desktop\shuriken2014_tr.exe
[2015/01/07 17:42:23 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2015/01/07 01:04:43 | 000,002,265 | ---- | M] () -- C:\Users\ZexqTTA3\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2015/01/06 22:33:41 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_point64_01011.Wdf
[2015/01/06 22:30:50 | 001,289,954 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2015/01/06 21:58:09 | 001,760,104 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco64.dll
[2015/01/06 21:58:09 | 001,482,600 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco64.dll
[2015/01/06 21:03:50 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2015/01/06 21:03:48 | 000,645,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2015/01/06 21:03:48 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2015/01/06 21:03:48 | 000,478,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2015/01/06 21:03:48 | 000,337,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2015/01/06 21:03:48 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2015/01/06 21:03:48 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2015/01/06 21:03:48 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2015/01/06 21:03:48 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2015/01/06 21:03:48 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2015/01/06 21:03:47 | 002,052,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2015/01/06 21:03:47 | 001,155,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2015/01/06 21:03:47 | 000,710,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2015/01/06 21:03:47 | 000,610,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2015/01/06 21:03:47 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2015/01/06 21:03:47 | 000,151,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2015/01/06 21:03:47 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2015/01/06 21:03:47 | 000,127,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2015/01/06 21:03:47 | 000,083,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2015/01/06 21:03:47 | 000,076,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2015/01/06 21:03:47 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2015/01/06 21:03:47 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2015/01/06 21:03:47 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2015/01/06 21:03:47 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2015/01/06 21:03:47 | 000,047,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2015/01/06 21:03:47 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2015/01/06 21:03:47 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2015/01/06 21:03:47 | 000,016,284 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2015/01/06 21:03:46 | 000,942,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2015/01/06 21:03:46 | 000,814,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2015/01/06 21:03:46 | 000,620,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2015/01/06 21:03:46 | 000,247,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2015/01/06 21:03:46 | 000,199,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2015/01/06 21:03:46 | 000,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2015/01/06 21:03:46 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2015/01/06 21:03:46 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2015/01/06 21:03:46 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2015/01/06 21:03:46 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2015/01/06 21:03:46 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2015/01/06 21:03:46 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2015/01/06 21:03:46 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2015/01/06 21:03:46 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2015/01/06 21:03:46 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2015/01/06 21:03:45 | 006,039,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2015/01/06 21:03:45 | 002,125,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2015/01/06 21:03:45 | 001,359,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2015/01/06 21:03:45 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2015/01/06 21:03:45 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2015/01/06 21:03:45 | 000,718,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2015/01/06 21:03:45 | 000,633,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2015/01/06 21:03:45 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2015/01/06 21:03:45 | 000,580,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2015/01/06 21:03:45 | 000,490,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2015/01/06 21:03:45 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2015/01/06 21:03:45 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2015/01/06 21:03:45 | 000,235,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2015/01/06 21:03:45 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2015/01/06 21:03:45 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2015/01/06 21:03:45 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2015/01/06 21:03:45 | 000,101,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2015/01/06 21:03:45 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2015/01/06 21:03:45 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2015/01/06 21:03:45 | 000,077,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2015/01/06 21:03:45 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2015/01/06 21:03:45 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2015/01/06 21:03:45 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2015/01/06 21:03:45 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2015/01/06 21:03:45 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2015/01/06 21:03:45 | 000,016,284 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2015/01/06 21:03:44 | 000,774,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2015/01/06 21:03:44 | 000,147,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2015/01/06 21:03:44 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2015/01/06 21:03:44 | 000,114,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2015/01/06 21:03:44 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2015/01/06 21:03:44 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2015/01/06 21:03:44 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2015/01/06 21:03:44 | 000,048,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2015/01/06 21:03:44 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2015/01/06 21:03:44 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2015/01/06 20:59:30 | 001,682,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll
[2015/01/06 20:59:30 | 001,158,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll
[2015/01/06 20:59:30 | 000,522,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll
[2015/01/06 20:59:30 | 000,364,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll
[2015/01/06 20:59:30 | 000,010,752 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,010,752 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,009,728 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2015/01/06 20:59:30 | 000,009,728 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2015/01/06 20:59:30 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2015/01/06 20:59:30 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2015/01/06 20:59:30 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2015/01/06 20:59:30 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2015/01/06 20:59:30 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2015/01/06 20:59:30 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2015/01/06 20:59:30 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2015/01/06 20:59:30 | 000,002,560 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2015/01/06 20:59:30 | 000,002,560 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2015/01/06 20:59:29 | 001,643,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2015/01/06 20:59:29 | 001,238,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10.dll
[2015/01/06 20:59:29 | 000,648,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll
[2015/01/06 20:59:29 | 000,363,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll
[2015/01/06 20:59:29 | 000,333,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll
[2015/01/06 20:59:29 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10core.dll
[2015/01/06 20:59:29 | 000,245,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecsExt.dll
[2015/01/06 20:59:29 | 000,221,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\UIAnimation.dll
[2015/01/06 20:59:29 | 000,194,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll
[2015/01/06 20:59:29 | 000,187,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAnimation.dll
[2015/01/06 18:18:52 | 000,001,381 | ---- | M] () -- C:\Users\ZexqTTA3\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2015/01/06 18:00:13 | 000,163,195 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2015/01/06 18:00:13 | 000,163,195 | ---- | M] () -- C:\Windows\SysNative\license.rtf

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2015/01/29 00:58:26 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2015/01/13 00:40:54 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_sonyfelicaportm_01009.Wdf
[2015/01/08 19:55:29 | 000,403,677 | ---- | C] () -- C:\Users\ZexqTTA3\Desktop\150108kouhyou_1.pdf
[2015/01/08 01:46:06 | 000,000,997 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2015/01/08 01:43:35 | 000,001,912 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Elements 10.lnk
[2015/01/08 01:33:52 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2015/01/08 01:01:35 | 000,065,793 | ---- | C] () -- C:\Windows\SysNative\esfwa1.bin
[2015/01/08 00:55:42 | 000,002,507 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Standard.lnk
[2015/01/08 00:55:42 | 000,002,465 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
[2015/01/07 17:42:23 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2015/01/06 23:29:48 | 000,001,813 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EmEditor.lnk
[2015/01/06 23:22:07 | 000,002,265 | ---- | C] () -- C:\Users\ZexqTTA3\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2015/01/06 23:14:06 | 000,001,159 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2015/01/06 22:36:33 | 000,000,626 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015/01/06 22:33:41 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_point64_01011.Wdf
[2015/01/06 21:48:17 | 000,008,192 | ---- | C] () -- C:\Windows\SysNative\drivers\IntelMEFWVer.dll
[2015/01/06 21:13:25 | 001,289,954 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2015/01/06 21:03:47 | 000,016,284 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2015/01/06 21:03:45 | 000,016,284 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2015/01/06 20:22:08 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2015/01/06 20:18:48 | 003,826,628 | ---- | C] () -- C:\Windows\SysNative\nvcoproc.bin
[2015/01/06 20:06:14 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2015/01/06 18:18:52 | 000,001,381 | ---- | C] () -- C:\Users\ZexqTTA3\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2015/01/06 18:10:15 | 000,001,357 | ---- | C] () -- C:\Users\ZexqTTA3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2015/01/06 18:09:53 | 000,000,290 | ---- | C] () -- C:\Users\ZexqTTA3\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2015/01/06 18:09:53 | 000,000,272 | ---- | C] () -- C:\Users\ZexqTTA3\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2015/01/06 18:09:44 | 000,000,690 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/01/06 18:09:43 | 000,000,686 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/01/06 18:08:11 | 000,001,305 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2015/01/06 18:08:02 | 000,001,374 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2015/01/06 18:07:46 | 000,001,458 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2015/01/06 18:07:38 | 000,002,486 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2015/01/06 17:59:56 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2015/01/06 17:59:48 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2015/01/06 17:57:20 | 2129,919,999 | -HS- | C] () -- C:\hiberfil.sys

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009/07/14 13:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/06/25 11:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/25 10:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 10:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 12:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 10:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC]< %windir%\tasks\*.job >[/color]
[2015/01/30 23:30:00 | 000,000,626 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015/01/30 23:07:33 | 000,000,686 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/01/30 23:19:00 | 000,000,690 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

[color=#E56717]========== Drive Information ==========[/color]

Physical Drives
---------------

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: ST1000DM003-9YN162
Partitions: 2
Status: OK
Status Info: 0

Partitions
---------------

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 931.00GB
Starting Offset: 105906176
Hidden sectors: 0


[color=#E56717]========== Base Services ==========[/color]
SRV:[b]64bit:[/b] - [2009/07/14 10:40:01 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc)
SRV:[b]64bit:[/b] - [2013/02/27 14:47:10 | 000,070,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:[b]64bit:[/b] - [2009/07/14 10:38:55 | 000,079,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:51 | 000,849,920 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:00 | 000,705,024 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:[b]64bit:[/b] - [2014/04/12 11:19:05 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (KeyIso)
SRV:[b]64bit:[/b] - [2009/07/14 10:40:50 | 000,402,944 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV - [2009/07/14 10:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV:[b]64bit:[/b] - [2012/07/05 07:13:27 | 000,136,704 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:[b]64bit:[/b] - [2013/07/09 14:46:20 | 000,184,320 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV - [2013/07/09 13:46:31 | 000,140,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\cryptsvc.dll -- (CryptSvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:00 | 000,317,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV - [2010/11/21 12:24:09 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV:[b]64bit:[/b] - [2011/03/03 15:24:16 | 000,183,296 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:[b]64bit:[/b] - [2009/07/14 10:40:35 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\eapsvc.dll -- (EapHost)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:00 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV - [2009/07/14 10:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:48 | 000,501,248 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:[b]64bit:[/b] - [2009/07/14 10:41:54 | 000,524,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:52 | 000,459,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netprofm.dll -- (netprofm)
SRV - [2009/07/14 10:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\netprofm.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2014/12/06 13:17:27 | 000,303,616 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:53 | 000,025,600 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:[b]64bit:[/b] - [2011/05/24 20:42:55 | 000,404,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:[b]64bit:[/b] - [2012/02/11 15:36:02 | 000,559,104 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
SRV:[b]64bit:[/b] - [2014/04/12 11:19:05 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV:[b]64bit:[/b] - [2009/07/14 10:41:53 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:17 | 000,344,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:[b]64bit:[/b] - [2014/04/12 11:19:05 | 000,031,232 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:58 | 000,097,280 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:48 | 000,236,032 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:55 | 000,370,688 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV - [2010/11/21 12:24:03 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV:[b]64bit:[/b] - [2010/11/21 12:24:16 | 001,110,016 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:32 | 000,316,928 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV - [2010/11/21 12:24:00 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:[b]64bit:[/b] - [2014/12/19 12:06:55 | 000,210,432 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:55 | 001,600,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:[b]64bit:[/b] - [2014/10/03 11:11:51 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\audiosrv.dll -- (AudioSrv)
SRV:[b]64bit:[/b] - [2014/10/03 11:11:51 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\audiosrv.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2010/11/21 12:25:06 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
SRV:[b]64bit:[/b] - [2013/05/27 14:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:55 | 001,646,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (eventlog)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:28 | 000,828,416 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:48 | 000,580,096 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:15 | 000,128,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver)
SRV - [2010/11/21 12:24:28 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:56 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:[b]64bit:[/b] - [2014/05/15 01:23:46 | 002,477,536 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:09 | 000,252,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:56 | 000,886,784 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlansvc.dll -- (Wlansvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:32 | 000,118,784 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

< End of report >
  • penpen
  • 2015/01/31 (Sat) 01:59:56
Extrasログ
Extrasログ

OTL Extras logfile created on: 2015/01/31 0:05:11 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\dEaAD2sZ\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

7.98 Gb Total Physical Memory | 7.29 Gb Available Physical Memory | 91.35% Memory free
15.95 Gb Paging File | 15.30 Gb Available in Paging File | 95.89% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 765.43 Gb Free Space | 82.18% Space Free | Partition Type: NTFS

Computer Name: PC | User Name: ZexqTTA3 | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.txt[@ = emeditor.txt] -- C:\Program Files\EmEditor\EMEDITOR.EXE (Emurasoft, Inc.)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.txt [@ = emeditor.txt] -- C:\Program Files\EmEditor\EMEDITOR.EXE (Emurasoft, Inc.)

[HKEY_USERS\S-1-5-21-1099055701-4194996230-893242877-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

[HKEY_USERS\S-1-5-21-1099055701-4194996230-893242877-1002\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[color=#E56717]========== Authorized Applications List ==========[/color]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2DD99D35-0CE1-4E21-B940-8EA917F858FF}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{B00D571B-45B1-4EBC-A03C-42C2F745A858}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{F1A45805-A1F5-4A4A-826D-8B8731589202}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B39945C-59BA-4AF0-A253-2CB96F960F66}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{297A2CD5-8DF5-4E7D-BCEB-CBEB0B862188}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{3BC9670E-244E-4243-95F0-27603C72796C}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{C5D958B9-7B39-458F-8BAE-546A8B482C94}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{C5E7FB31-478C-4237-90C4-7BB0FB8B6761}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2700_series" = Canon iP2700 series Printer Driver
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1AAF6669-31B2-3840-9346-F0F653840FD1}" = Microsoft .NET Framework 4.5.1 (JPN)
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{23D2AFC7-C01E-4413-9D9A-0BABF52569BF}" = Microsoft マウス キーボード センター
"{3BF2C0A8-2C44-4A36-AA96-3BD6FB7BB01F}" = Windows Live Remote Client Resources
"{53FD613C-BCA1-4C88-A9E1-CE2F3BFD629D}" = ESET Smart Security
"{54C5B89F-0A8C-4C07-A51D-7380974DA459}" = Windows Live Remote Service Resources
"{6A1E4EFB-3EE0-40A0-9D6D-E865370289DB}" = Google 日本語入力
"{6D80AAE7-FF65-4950-B1CA-3A7EA4995574}_is1" = Adobe Reader 64-bit fixes
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-0028-0411-1000-0000000FF1CE}" = Microsoft Office IME (Japanese) 2010
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0411-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Japanese) 2010
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1041" = Microsoft .NET Framework 4.5.1 (日本語)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A0FCAA03-7CAC-49D5-9EB8-9417B195CA7E}" = EmEditor (64-bit)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision ドライバー 340.52
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA コントロール パネル 340.52
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA グラフィックス ドライバー 340.52
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision コントローラー ドライバー 306.23
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX システム ソフトウェア 9.12.0604
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 10.4.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD オーディオ ドライバー 1.3.30.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{BA5C0CC3-421B-4AE5-9370-1650D1941F30}" = Adobe PDF iFilter 11 for 64-bit platforms
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"CCleaner" = CCleaner
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.26
"HWiNFO64_is1" = HWiNFO64 Version 4.48
"Microsoft Mouse and Keyboard Center" = Microsoft マウス キーボード センター

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{019EF473-6D0A-415C-9A2E-1AF5F66AC60F}" = Windows Live Messenger
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{10AB1F40-BDEC-4A8D-B427-30F9429378B0}" = Windows Live Movie Maker
"{11D08055-939C-432b-98C3-E072478A0CD7}" = PSE10 STI Installer
"{12BA8103-EF4F-4535-9E4F-B10F720648B4}" = Shuriken 2014体験版
"{15D95497-8F76-41E5-8894-EDDB59E39BD9}" = Windows Live メール
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FCD587F-ACBF-41BF-8CFF-4FDC99330037}" = NFC Port Software
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{22D3A614-482C-444A-932C-9DA1B8ECDFD2}" = Elements 10 Organizer
"{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{4FD2D1C8-8636-11E4-9D21-00163E98E7D6}" = Evernote v. 5.8.1
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}" = EPSON Scan OCR コンポーネント
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{675D8E1E-2388-4718-902C-E5FC4888AC0E}" = Windows Live Essentials
"{680979B2-3EAD-4219-B32C-7A6BC02B39F9}" = 読んde!!ココ パーソナル
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6C3F8916-D6A5-4A31-9DA8-80C973CE437F}" = Windows Live Writer
"{7134EF35-DA07-41F8-A71F-66709E194BB5}" = Windows Live Mesh
"{824E88CC-98B2-4DE6-9370-4589070C741C}" = honto
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{88A686A9-D687-4295-B633-50D8A4B88371}" = Windows Live Writer Resources
"{8A66A2C8-0032-4949-8D99-C293A3EACF79}" = Windows Live Photo Common
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D59BE38-3A4F-4525-AD0D-8980E9E31EFA}" = Windows Live フォト ギャラリー
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F01524C-0676-4CC1-B4AE-64753C723391}" = Epson Event Manager
"{90140000-0016-0411-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Japanese) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0411-0000-0000000FF1CE}" = Microsoft Office Proof (Japanese) 2010
"{90140000-0028-0411-0000-0000000FF1CE}" = Microsoft Office IME (Japanese) 2010
"{90140000-002C-0411-0000-0000000FF1CE}" = Microsoft Office Proofing (Japanese) 2010
"{90140000-006E-0411-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Japanese) 2010
"{91140000-0016-0000-0000-0000000FF1CE}" = Microsoft Office Excel 2010
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A127C3C0-055E-38CF-B38F-1E85F8BBBFFE}" = Adobe Community Help
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}" = Epson Copy Utility 3.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-1041-0000-BA7E-000000000005}" = Adobe Acrobat X Standard - Japanese
"{AC76BA86-7AD7-1041-7B44-AB0000000001}" = Adobe Reader XI (11.0.10) - Japanese
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{BAF0CA91-4642-46C8-9BCD-C93B61508701}" = リモート接続用の Windows Live Mesh ActiveX コントロール (日本語)
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EE408577-9C0E-4E5F-BCB2-DB5B3A220958}" = Windows Live UX Platform Language Pack
"{EE549AF9-8FAA-4584-83B2-ECF1BC9DC1FF}" = Adobe Photoshop Elements 10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 16 ActiveX
"Adobe Photoshop Elements 10" = Adobe Photoshop Elements 10
"AI RoboForm" = RoboForm 7-9-12-2 (All Users)
"Canon My Image Garden" = Canon My Image Garden
"Canon My Image Garden Design Files" = Canon My Image Garden Design Files
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"EPSON GT-X820 Useg" = EPSON GT-X820 ユーザーズガイド
"EPSON Scanner" = EPSON Scan
"Google Chrome" = Google Chrome
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"Mozilla Firefox 35.0.1 (x86 ja)" = Mozilla Firefox 35.0.1 (x86 ja)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.EXCELR" = Microsoft Excel 2010
"ThumbGensPack" = ThumbGensPack 2014年12月22日 11:48:18
"WinLiveSuite" = Windows Live Essentials

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2015/01/27 6:44:57 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2015/01/27 9:04:23 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2015/01/28 5:33:51 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2015/01/28 10:07:55 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2015/01/28 12:18:14 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2015/01/29 2:45:12 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2015/01/29 10:21:48 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2015/01/29 22:02:54 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2015/01/30 7:38:10 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

Error - 2015/01/30 10:08:43 | Computer Name = PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 2015/01/30 11:02:04 | Computer Name = PC | Source = DCOM | ID = 10005
Description =

Error - 2015/01/30 11:02:04 | Computer Name = PC | Source = DCOM | ID = 10005
Description =

Error - 2015/01/30 11:02:04 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2015/01/30 11:02:04 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2015/01/30 11:02:05 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2015/01/30 11:02:05 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2015/01/30 11:02:05 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2015/01/30 11:02:05 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2015/01/30 11:02:05 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2015/01/30 11:02:05 | Computer Name = PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068


< End of report >

  • penpen
  • 2015/01/31 (Sat) 02:00:55
以後の自衛して「解決」ですね
レスが遅くなってすみません。
OTLログを見せてもらいましたが、おかしなものはないみたいですね。

では異常もないようなら「解決」でいいでしょう。
作業に使ったツール類は準備時の説明に沿って片付けてください。

以後の再被害を防ぐための自衛も忘れないでください。
自衛を怠ると、たとえ何度リカバリしてもそのたびに再被害も平気で襲ってきます。

ブラウザの設定を少し固めるだけでも、セキュリティ上の効果を高めることが可能です。
「インターネットオプション」→「プライバシー」→「詳細設定」と開いて、「自動cookie処理」と「サードパーティのcookieをブロック」にチェックして「適用」して「OK」。
これをやっておくと、多くの危険サイトからの保護にかなり有効です。
が、これもすべての危険サイトに有効でもないし、本物の危険サイトではこの程度ではまったく太刀打ちできないので、過信はしないこと。
また、「すべてのcookieをブロックする」設定にすると、プロバイダのメールボックスなどログイン必要なページに入れなくなる弊害も出るので、これは状況を考えて使い分けるといいでしょう。
安全なサイトでもcookieブロックだと閲覧や投稿ができなくなるところもあるのでこれも注意。

次に、アンチウイルスやファイアウォール等のセキュリティソフトの使い方も注意してください。
セキュリティソフトはただ入れてさえいればそれだけでフル機能を発揮するものではありません。
設定と機能をできるだけ把握して、正しく使うことが重要です。
間違った使い方すると、本来ならブロックできた感染でもあっさりスルーします。

また、いくら高性能なセキュリティソフトがあっても、ユーザーが自分から危険なサイトやファイルにアクセスしてたらまったく保護もできません。
セキュリティソフトは使い方次第でその性能を、倍にも半にも無にも変動させます。

そして百聞は一見にしかず。
現在この掲示板で継続中や解決済みの他スレもできるだけ見ておくことをおすすめします。
同様、類似、別種含めて参考になる部分は多いでしょう。

普段から自PCの設定や動きを毎日把握しておくことも大事です。
ちょっとした異常に気付いたらそれだけ早く原因特定と対処することも可能です。
何より自分で変更してもいないのにPCの各種設定が変更されていたらその原因を考えるようにしましょう。
他の方が苦労しながら作業して、解決に至った各スレはどれもみな参考になります。
まったく違う事例でも角度を変えてみれば、別の異常事例にも応用できることも多いのです。

慣れない作業を頑張ってくれてお疲れ様でした。
以後は安全で快適なPCライフを
  • 悪代官
  • 2015/01/31 (Sat) 17:55:58

返信フォーム






プレビュー (投稿前に内容を確認)