【OTL.txt】
[color=#E56717]========== FireFox ==========[/color]
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll ( Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.45.2: C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.45.2: C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.co.jp/NxGame: C:\ProgramData\NexonJP\NGM\npNxGameJP.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\pmang.jp/pmangdiagnostic-1: D:\AVA\GameOn\Common files\nppmangdiagnostic.dll (gameon)
FF - HKLM\Software\MozillaPlugins\pmang.jp/pmangsupport-1: D:\AVA\GameOn\Common files\nppmangsupport.dll (gameon)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\PROGRAM FILES\ESET\ESET SMART SECURITY\MOZILLA THUNDERBIRD
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
[color=#E56717]========== Chrome ==========[/color]
CHR - Extension: No name found = \Users\Taisei\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = \Users\Taisei\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = \Users\Taisei\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = \Users\Taisei\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = \Users\Taisei\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = \Users\Taisei\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\
CHR - Extension: No name found = \Users\Taisei\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\8.4.0.9160_0\
CHR - Extension: No name found = \Users\Taisei\AppData\Local\Google\Chrome\User Data\Default\Extensions\mchkplpllicffdchiohkjlkpednaoefj\1.0_0\
CHR - Extension: No name found = \Users\Taisei\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.0_0\
CHR - Extension: No name found = \Users\Taisei\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\6.9.2_0\
CHR - Extension: No name found = \Users\Taisei\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
CHR - Extension: No name found = \Users\Taisei\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5216.530.0.15_0\
O1 HOSTS File: ([2016/04/23 15:34:03 | 000,000,831 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:[b]64bit:[/b] - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {001032CB-B0AC-4F2C-A650-AD4B2B26E5DA} - No CLSID value found.
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:[b]64bit:[/b] - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:[b]64bit:[/b] - HKLM..\Run: [AtwtusbIcon] C:\WINDOWS\SysNative\AtwtusbIcon.exe ()
O4:[b]64bit:[/b] - HKLM..\Run: [MouseDriver] C:\WINDOWS\SysNative\TiltWheelMouse.exe (Pixart Imaging Inc)
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ASUSPRP] C:\Program Files (x86)\ASUS\APRP\APRP.EXE (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [BSMBU18] C:\Program Files (x86)\BUFFALO\BSMBU18\PanelEx.exe (Buffalo)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Google Japanese Input Prelauncher] C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe (Google Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\.DEFAULT..\Run: [スーパーセキュリティ パスワード管理] "C:\Program Files\スーパーセキュリティ\スーパーセキュリティ ZERO\pwdmanui.exe" --hidden --nowizard File not found
O4 - HKU\.DEFAULT..\Run: [スーパーセキュリティ パスワード管理 アプリケーション・エージェント] "C:\Program Files\スーパーセキュリティ\スーパーセキュリティ ZERO\antispam32\bdapppassmgr.exe" File not found
O4 - HKU\.DEFAULT..\Run: [スーパーセキュリティ パスワード管理 エージェント] "C:\Program Files\スーパーセキュリティ\スーパーセキュリティ ZERO\pmbxag.exe" File not found
O4 - HKU\S-1-5-18..\Run: [スーパーセキュリティ パスワード管理] "C:\Program Files\スーパーセキュリティ\スーパーセキュリティ ZERO\pwdmanui.exe" --hidden --nowizard File not found
O4 - HKU\S-1-5-18..\Run: [スーパーセキュリティ パスワード管理 アプリケーション・エージェント] "C:\Program Files\スーパーセキュリティ\スーパーセキュリティ ZERO\antispam32\bdapppassmgr.exe" File not found
O4 - HKU\S-1-5-18..\Run: [スーパーセキュリティ パスワード管理 エージェント] "C:\Program Files\スーパーセキュリティ\スーパーセキュリティ ZERO\pmbxag.exe" File not found
O4 - HKU\S-1-5-21-4118171347-2157590342-397946843-1002..\Run: [AppEx Accelerator UI] C:\Program Files\AMD Quick Stream\AMDQuickStream.exe (AppEx Networks Corporation)
O4 - HKU\S-1-5-21-4118171347-2157590342-397946843-1002..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-4118171347-2157590342-397946843-1002..\Run: [EPSON EP-302] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIFFJ.EXE /FU "C:\WINDOWS\TEMP\E_S2FAF.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-4118171347-2157590342-397946843-1002..\Run: [Folder Size] D:\Folder Size\FolderSize.exe (Brio)
O4 - HKU\S-1-5-21-4118171347-2157590342-397946843-1002..\Run: [Gyazo] C:\Program Files (x86)\Gyazo\GyStation.exe (Nota Inc.)
O4 - HKU\S-1-5-21-4118171347-2157590342-397946843-1002..\Run: [Hifito] D:\Hifito\Hifito.exe ()
O4 - Startup: C:\Users\All Users\1412612002.bdinstall.bin ()
O4 - Startup: C:\Users\All Users\1415283295.bdinstall.bin ()
O4 - Startup: C:\Users\All Users\34BE82C4-E596-4e99-A191-52C6199EBF69 [2016/04/27 22:18:15 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Adobe [2015/11/03 17:37:03 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Aiseesoft Studio [2016/07/04 15:21:31 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\AMD [2016/05/02 22:28:32 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Amv4VideoCodec [2015/03/01 02:13:21 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Apple [2014/03/27 23:42:46 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Apple Computer [2014/03/27 23:42:56 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Application Data [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\ASign [2014/07/26 16:46:57 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\ASUS [2013/11/22 03:08:30 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\ASUS WebStorage [2013/11/22 03:14:53 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\ATI [2016/05/02 22:33:00 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\BDLogging [2014/10/08 22:47:02 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\boost_interprocess [2016/03/09 22:08:44 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\BUFFALO_ClientMgrV [2015/07/30 13:08:06 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\CLSK [2013/11/22 03:23:34 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Corel [2015/03/05 01:29:28 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\CyberLink [2016/04/18 22:27:51 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\DAEMON Tools Lite [2014/07/26 16:42:19 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Desktop [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\Documents [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\DP45977C.lfl ()
O4 - Startup: C:\Users\All Users\Electronic Arts [2016/04/19 17:28:04 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Emurasoft [2015/12/25 20:40:00 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\EPSON [2016/04/25 21:44:01 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Freemake [2016/04/19 18:34:07 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Fujisoft [2014/12/13 23:15:09 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Google [2014/03/27 17:10:55 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\GRETECH [2016/04/23 10:04:50 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Gyazo [2015/07/08 19:47:11 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\install_clap [2015/07/29 02:03:40 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Kingsoft [2014/08/26 22:24:24 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\KORG [2015/12/11 23:44:19 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Line 6 [2015/12/12 00:43:10 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Malwarebytes [2016/09/08 21:55:12 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Martau [2015/08/10 00:13:33 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Microsoft [2016/07/19 23:10:19 | 000,000,000 | --SD | M]
O4 - Startup: C:\Users\All Users\Microsoft OneDrive [2014/07/07 14:37:52 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Microsoft SkyDrive [2013/11/22 03:36:36 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\mntemp ()
O4 - Startup: C:\Users\All Users\Mozilla [2014/03/27 22:36:51 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Native Instruments [2016/01/20 03:30:32 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Nexon [2014/07/25 21:28:43 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\NexonJP [2014/07/26 10:16:22 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Norton [2014/05/18 23:21:53 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\NortonInstaller [2014/04/27 02:40:56 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\ntuser.dat ()
O4 - Startup: C:\Users\All Users\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\All Users\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\All Users\ntuser.dat{7b061a0a-65bf-11e4-82bc-e03f49e6dbcc}.TM.blf ()
O4 - Startup: C:\Users\All Users\ntuser.dat{7b061a0a-65bf-11e4-82bc-e03f49e6dbcc}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\All Users\ntuser.dat{7b061a0a-65bf-11e4-82bc-e03f49e6dbcc}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\All Users\ntuser.pol ()
O4 - Startup: C:\Users\All Users\NuGet [2015/12/15 00:34:08 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Oracle [2015/04/18 22:55:55 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Origin [2014/10/26 12:55:47 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Package Cache [2016/05/02 22:27:04 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\PDVD [2015/02/27 21:42:39 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\PreEmptive Solutions [2015/12/15 00:35:58 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\ProductData [2016/09/03 22:38:45 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Propellerhead Software [2016/04/19 18:31:54 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Protexis [2015/03/05 00:00:15 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Real [2014/12/06 16:16:21 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\regid.1986-12.com.adobe [2015/03/06 00:39:48 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\regid.1991-06.com.microsoft [2015/12/15 00:21:04 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Skype [2016/09/07 20:52:42 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\sMedio [2015/07/26 12:22:07 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\SpaceClaim [2016/07/31 00:54:30 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Start Menu [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\Sun [2014/03/27 16:20:12 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\SUPPORTDIR [2016/04/18 22:28:03 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Tablet [2016/09/04 00:17:18 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Temp [2016/04/18 22:28:03 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Templates [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\tks [2015/03/04 22:54:22 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\All Users\Trend Micro [2014/06/10 22:54:46 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Trend Micro Installer [2014/09/02 17:13:12 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Unity [2015/12/19 12:21:22 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\vid [2015/03/04 22:54:22 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\All Users\WebStorage [2013/11/22 03:14:53 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\{00E0164B-B182-4800-96DA-F8D39B3A7189} [2016/04/18 22:31:25 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\All Users\{39F0D482-6A42-445B-B6E2-506945189709} [2016/04/18 22:31:29 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\All Users\{9327ACE9-CC82-4A33-9B33-291ACA1E267B} [2016/04/18 22:31:18 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\All Users\{95B4F0ED-951F-4D36-B068-5EC1C4C19C14} [2016/01/20 03:30:33 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\All Users\{A9158F4E-7914-4019-808A-D4D4993E9958} [2016/04/18 22:30:32 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\All Users\{C1CF19B4-9194-417A-8B85-84F1471783CE} [2016/04/18 22:31:23 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\All Users\{F21A5765-AACF-4530-991E-CE1346273F96} [2016/04/18 22:31:32 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\All Users\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98} [2016/09/03 22:38:43 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\スタート メニュー [2014/03/27 11:44:18 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\デスクトップ [2014/03/27 11:44:18 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\AppData [2013/08/23 00:36:30 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\Default\Application Data [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Cookies [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Desktop [2013/08/23 00:36:30 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\Documents [2013/08/22 23:45:52 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\Downloads [2013/08/23 00:36:30 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\Favorites [2014/06/02 01:01:12 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\Links [2013/11/22 03:36:37 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\Local Settings [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Music [2013/08/23 00:36:30 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\My Documents [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\NetHood [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\NTUSER.DAT ()
O4 - Startup: C:\Users\Default\NTUSER.DAT.LOG1 ()
O4 - Startup: C:\Users\Default\NTUSER.DAT.LOG2 ()
O4 - Startup: C:\Users\Default\NTUSER.DAT{86b4162a-097f-11e6-8379-e03f49e6dbcc}.TM.blf ()
O4 - Startup: C:\Users\Default\NTUSER.DAT{86b4162a-097f-11e6-8379-e03f49e6dbcc}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Default\NTUSER.DAT{86b4162a-097f-11e6-8379-e03f49e6dbcc}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Default\NTUSER.DAT{e19765f3-0b7b-11e3-93fa-782bcb37e60c}.TM.blf ()
O4 - Startup: C:\Users\Default\NTUSER.DAT{e19765f3-0b7b-11e3-93fa-782bcb37e60c}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Default\NTUSER.DAT{e19765f3-0b7b-11e3-93fa-782bcb37e60c}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Default\Pictures [2013/08/23 00:36:30 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\PrintHood [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Recent [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Saved Games [2013/08/23 00:36:30 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Default\SendTo [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Start Menu [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Templates [2013/08/22 23:45:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Videos [2013/08/23 00:36:30 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\スタート メニュー [2014/03/27 11:44:18 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\dub_cm_auto\Application Data [2014/04/23 21:30:10 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\dub_cm_auto\NTUSER.DAT ()
O4 - Startup: C:\Users\dub_cm_auto\NTUSER.DAT.LOG1 ()
O4 - Startup: C:\Users\dub_cm_auto\NTUSER.DAT.LOG2 ()
O4 - Startup: C:\Users\dub_cm_auto\NTUSER.DAT{a9c178a5-dd7c-11e3-827d-e03f49e6dbcc}.TM.blf ()
O4 - Startup: C:\Users\dub_cm_auto\NTUSER.DAT{a9c178a5-dd7c-11e3-827d-e03f49e6dbcc}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\dub_cm_auto\NTUSER.DAT{a9c178a5-dd7c-11e3-827d-e03f49e6dbcc}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Public\AccountPictures [2015/01/01 12:09:03 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\Public\Desktop [2016/09/08 21:55:18 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\Public\Documents [2016/04/24 03:25:05 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Downloads [2013/08/23 00:36:32 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Libraries [2016/04/24 03:19:07 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Public\Music [2016/04/24 03:28:41 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\NTUSER.DAT ()
O4 - Startup: C:\Users\Public\NTUSER.DAT.LOG1 ()
O4 - Startup: C:\Users\Public\NTUSER.DAT.LOG2 ()
O4 - Startup: C:\Users\Public\NTUSER.DAT{3acc8bef-b5bc-11e3-825c-e03f49e6dbcc}.TM.blf ()
O4 - Startup: C:\Users\Public\NTUSER.DAT{3acc8bef-b5bc-11e3-825c-e03f49e6dbcc}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Public\NTUSER.DAT{3acc8bef-b5bc-11e3-825c-e03f49e6dbcc}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Public\Pictures [2016/05/12 22:39:25 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Videos [2016/05/12 22:39:25 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Taisei\.gimp-2.6 [2016/01/02 23:57:26 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Taisei\.gimp-2.8 [2016/09/03 22:46:07 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Taisei\.thumbnails [2014/07/05 17:12:44 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Taisei\.VirtualBox [2015/10/31 11:38:35 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Taisei\AppData [2016/09/03 22:36:52 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\Taisei\Application Data [2016/04/24 03:18:11 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Taisei\Contacts [2014/09/17 19:03:40 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Taisei\Cookies [2016/04/24 03:18:11 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Taisei\Corel [2015/03/05 01:28:34 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Taisei\Creative Cloud Files [2015/11/21 16:32:16 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Taisei\Desktop [2016/09/09 21:39:32 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Taisei\Documents [2016/04/18 21:25:39 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Taisei\Downloads [2016/09/09 21:39:32 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Taisei\Favorites [2016/04/24 03:21:23 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Taisei\hello.c ()
O4 - Startup: C:\Users\Taisei\Links [2016/07/12 00:38:02 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Taisei\Local Settings [2016/04/24 03:18:11 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Taisei\Music [2016/04/18 21:35:31 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Taisei\My Documents [2016/04/24 03:18:11 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Taisei\NetHood [2016/04/24 03:18:11 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Taisei\ntuser.dat ()
O4 - Startup: C:\Users\Taisei\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\Taisei\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\Taisei\NTUSER.DAT{86b4162a-097f-11e6-8379-e03f49e6dbcc}.TM.blf ()
O4 - Startup: C:\Users\Taisei\NTUSER.DAT{86b4162a-097f-11e6-8379-e03f49e6dbcc}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Taisei\NTUSER.DAT{86b4162a-097f-11e6-8379-e03f49e6dbcc}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Taisei\ntuser.dat{92c3bcb7-71e9-11e6-83ea-e03f49e6dbcc}.TM.blf ()
O4 - Startup: C:\Users\Taisei\ntuser.dat{92c3bcb7-71e9-11e6-83ea-e03f49e6dbcc}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Taisei\ntuser.dat{92c3bcb7-71e9-11e6-83ea-e03f49e6dbcc}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Taisei\ntuser.dat{c3fd762c-74fd-11e6-83ef-e03f49e6dbcc}.TM.blf ()
O4 - Startup: C:\Users\Taisei\ntuser.dat{c3fd762c-74fd-11e6-83ef-e03f49e6dbcc}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Taisei\ntuser.dat{c3fd762c-74fd-11e6-83ef-e03f49e6dbcc}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Taisei\ntuser.ini ()
O4 - Startup: C:\Users\Taisei\OneDrive [2016/03/12 07:44:45 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Taisei\PrintHood [2016/04/24 03:18:11 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Taisei\quest1.c ()
O4 - Startup: C:\Users\Taisei\Recent [2016/04/24 03:18:11 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Taisei\Saved Games [2014/09/17 19:03:41 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Taisei\Searches [2016/04/24 04:30:46 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Taisei\SendTo [2016/04/24 03:18:11 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Taisei\SkyDrive [2016/09/09 20:29:40 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Taisei\sMedio [2015/07/26 12:22:19 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Taisei\Sti_Trace.log ()
O4 - Startup: C:\Users\Taisei\Templates [2016/04/24 03:18:11 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Taisei\Tracing [2015/03/15 19:39:47 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Taisei\umbrella0.log ()
O4 - Startup: C:\Users\Taisei\スタート メニュー [2016/04/24 03:18:11 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Taisei\泰生 [2016/04/07 01:02:33 | 000,000,000 | ---D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:[b]64bit:[/b] - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C}
http://dist.cdnetworks.co.jp/cdndist/neffy/NeffyLauncher.cab (NeffyLauncherCtl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.8.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ECA9E031-BC51-45D8-9954-36C51048B8AE}: DhcpNameServer = 192.168.0.1
O18:[b]64bit:[/b] - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} -
ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:[b]64bit:[/b] {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:[b]64bit:[/b] {66C64F22-FC60-4E6C-A6B5-F0D580E680CE} - C:\Windows\System32\ie4uinit.exe -EnableTLS
ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:[b]64bit:[/b] {7D715857-A67C-4C2F-A929-038448584D63} - C:\Windows\System32\ie4uinit.exe -DisableSSL3
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} -
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
ActiveX:[b]64bit:[/b] {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:[b]64bit:[/b] {BD6F5371-DAC1-30F0-9DDE-CAC6791E28C3} - .NET Framework
ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework
ActiveX: {30500C7C-2206-3DC6-9792-96E95A04669D} - .NET Framework
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2016/09/08 21:55:46 | 000,192,216 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2016/09/08 21:55:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2016/09/08 21:55:12 | 000,140,672 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbamchameleon.sys
[2016/09/08 21:55:12 | 000,065,408 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2016/09/08 21:55:12 | 000,027,008 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2016/09/08 21:55:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2016/09/08 21:55:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2016/09/08 21:53:54 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2016/09/08 21:53:54 | 000,000,000 | ---D | C] -- \AdwCleaner
[2016/09/07 21:18:53 | 000,828,408 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2016/09/07 21:18:53 | 000,176,632 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2016/09/07 21:01:27 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2016/09/07 21:01:27 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2016/09/07 21:01:26 | 002,055,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2016/09/07 21:01:26 | 000,806,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2016/09/07 21:01:26 | 000,663,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2016/09/07 21:01:26 | 000,572,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2016/09/07 21:01:25 | 002,131,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2016/09/07 21:01:24 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2016/09/07 21:01:24 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2016/09/07 21:01:24 | 000,315,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2016/09/07 21:01:23 | 006,047,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2016/09/07 21:01:23 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2016/09/07 21:01:23 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2016/09/07 21:01:21 | 000,724,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2016/09/07 21:01:21 | 000,615,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieui.dll
[2016/09/07 21:01:21 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2016/09/07 20:56:40 | 001,970,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\crypt32.dll
[2016/09/07 20:56:40 | 001,134,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2016/09/07 20:56:39 | 002,635,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CertEnroll.dll
[2016/09/07 20:56:38 | 003,820,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcore.dll
[2016/09/07 20:56:38 | 002,317,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CertEnroll.dll
[2016/09/07 20:56:38 | 002,230,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2016/09/07 20:56:38 | 000,897,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2016/09/07 20:56:38 | 000,509,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\webio.dll
[2016/09/07 20:56:38 | 000,482,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tpmvsc.dll
[2016/09/07 20:56:38 | 000,413,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\webio.dll
[2016/09/07 20:56:38 | 000,379,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\storport.sys
[2016/09/07 20:56:38 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\hidclass.sys
[2016/09/07 20:56:37 | 003,320,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2016/09/07 20:56:37 | 001,291,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certutil.exe
[2016/09/07 20:56:37 | 000,091,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptsslp.dll
[2016/09/07 20:56:36 | 003,273,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdpcore.dll
[2016/09/07 20:56:36 | 000,727,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2016/09/07 20:56:36 | 000,331,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\Classpnp.sys
[2016/09/07 20:56:36 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gpresult.exe
[2016/09/07 20:56:36 | 000,107,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptsslp.dll
[2016/09/07 20:56:36 | 000,072,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpfve.sys
[2016/09/07 20:56:36 | 000,057,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\stornvme.sys
[2016/09/07 20:56:35 | 000,261,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppwinob.dll
[2016/09/07 20:56:35 | 000,125,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cryptxml.dll
[2016/09/07 20:56:35 | 000,099,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\cryptxml.dll
[2016/09/07 20:56:34 | 001,487,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppobjs.dll
[2016/09/07 20:56:34 | 000,409,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2016/09/07 20:56:34 | 000,136,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2016/09/07 20:56:34 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hbaapi.dll
[2016/09/07 20:56:34 | 000,034,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserAccountBroker.exe
[2016/09/07 20:56:34 | 000,030,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UserAccountBroker.exe
[2016/09/07 20:56:33 | 002,778,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2016/09/07 20:56:33 | 002,464,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2016/09/07 20:56:33 | 001,060,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certutil.exe
[2016/09/07 20:56:33 | 000,192,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gpresult.exe
[2016/09/07 20:56:33 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
[2016/09/07 20:56:33 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
[2016/09/07 20:56:33 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
[2016/09/07 20:56:33 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
[2016/09/07 20:56:33 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\hbaapi.dll
[2016/09/07 20:56:33 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certenc.dll
[2016/09/07 20:56:33 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certenc.dll
[2016/09/07 20:56:33 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
[2016/09/07 20:56:33 | 000,032,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\hidparse.sys
[2016/09/07 20:56:33 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
[2016/09/07 20:56:26 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\polstore.dll
[2016/09/07 20:56:26 | 000,291,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\polstore.dll
[2016/09/07 20:56:26 | 000,135,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gpapi.dll
[2016/09/07 20:56:26 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FwRemoteSvr.dll
[2016/09/07 20:56:26 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\FwRemoteSvr.dll
[2016/09/07 20:56:25 | 000,840,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netlogon.dll
[2016/09/07 20:56:20 | 000,748,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StructuredQuery.dll
[2016/09/07 20:56:18 | 007,445,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2016/09/07 20:56:18 | 002,897,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\esent.dll
[2016/09/07 20:56:18 | 002,539,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\esent.dll
[2016/09/07 20:56:17 | 003,547,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2016/09/07 20:56:17 | 001,661,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ole32.dll
[2016/09/07 20:56:17 | 000,704,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rasapi32.dll
[2016/09/07 20:56:17 | 000,657,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dnsapi.dll
[2016/09/07 20:56:17 | 000,429,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vpnike.dll
[2016/09/07 20:56:17 | 000,377,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mprddm.dll
[2016/09/07 20:56:17 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mprddm.dll
[2016/09/07 20:56:16 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nshwfp.dll
[2016/09/07 20:56:16 | 000,360,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpclip.exe
[2016/09/07 20:56:16 | 000,323,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iprtrmgr.dll
[2016/09/07 20:56:16 | 000,285,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iprtrmgr.dll
[2016/09/07 20:56:16 | 000,272,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rasppp.dll
[2016/09/07 20:56:16 | 000,254,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rascustom.dll
[2016/09/07 20:56:16 | 000,197,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dssenh.dll
[2016/09/07 20:56:16 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rasppp.dll
[2016/09/07 20:56:16 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rasman.dll
[2016/09/07 20:56:16 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2016/09/07 20:55:33 | 001,490,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\appraiser.dll
[2016/09/07 20:55:33 | 001,208,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2016/09/07 20:55:33 | 000,571,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2016/09/07 20:55:33 | 000,544,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2016/09/07 20:55:33 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\invagent.dll
[2016/09/07 20:55:33 | 000,268,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\centel.dll
[2016/09/07 20:55:33 | 000,219,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepic.dll
[2016/09/07 20:55:33 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\acmigration.dll
[2016/09/07 20:55:33 | 000,050,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CompatTelRunner.exe
[2016/09/07 20:54:51 | 001,753,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GdiPlus.dll
[2016/09/07 20:54:51 | 001,491,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GdiPlus.dll
[2016/09/07 20:54:45 | 001,445,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2016/09/07 20:54:45 | 000,445,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certcli.dll
[2016/09/07 20:54:45 | 000,397,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcryptprimitives.dll
[2016/09/07 20:54:45 | 000,340,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcryptprimitives.dll
[2016/09/07 20:54:45 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certcli.dll
[2016/09/07 20:54:35 | 001,094,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\localspl.dll
[2016/09/07 20:54:35 | 000,864,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32spl.dll
[2016/09/07 20:54:35 | 000,477,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiobj.dll
[2016/09/07 20:54:35 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiobj.dll
[2016/09/07 20:54:35 | 000,345,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntprint.dll
[2016/09/07 20:54:35 | 000,306,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ntprint.dll
[2016/09/07 20:54:35 | 000,269,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DafPrintProvider.dll
[2016/09/07 20:54:35 | 000,203,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DafPrintProvider.dll
[2016/09/07 20:54:35 | 000,192,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiapi.dll
[2016/09/07 20:54:35 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiapi.dll
[2016/09/07 20:54:35 | 000,165,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetpp.dll
[2016/09/07 20:54:34 | 007,793,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Data.Pdf.dll
[2016/09/07 20:54:34 | 007,075,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\glcndFilter.dll
[2016/09/07 20:54:33 | 005,270,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\glcndFilter.dll
[2016/09/07 20:54:33 | 005,265,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Data.Pdf.dll
[2016/09/07 20:54:30 | 000,363,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ws2_32.dll
[2016/09/07 20:54:28 | 000,372,568 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysNative\atmfd.dll
[2016/09/07 20:54:28 | 000,315,224 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\atmfd.dll
[2016/09/07 20:54:28 | 000,044,032 | ---- | C] (Adobe Systems) -- C:\WINDOWS\SysNative\atmlib.dll
[2016/09/07 20:54:28 | 000,035,840 | ---- | C] (Adobe Systems) -- C:\WINDOWS\SysWow64\atmlib.dll
[2016/09/07 20:54:20 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\poqexec.exe
[2016/09/07 20:54:20 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\poqexec.exe
[2016/09/07 20:54:11 | 001,379,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32.dll
[2016/09/04 01:19:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Splashtop Remote
[2016/09/04 01:19:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Splashtop
[2016/09/03 23:31:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\herdProtect
[2016/09/03 23:31:07 | 000,000,000 | ---D | C] -- C:\Program Files\Reason
[2016/09/03 22:38:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\tasks\ImCleanDisabled
[2016/09/03 22:38:43 | 000,000,000 | ---D | C] -- C:\ProgramData\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98}
[2016/09/03 22:38:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\IObit
[2016/09/03 22:29:37 | 000,000,000 | ---D | C] -- C:\ProgramData\ProductData
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2016/09/09 21:41:00 | 000,000,396 | ---- | M] () -- C:\WINDOWS\tasks\WpsUpdateTask_Taisei.job
[2016/09/09 21:27:39 | 000,000,718 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2016/09/09 20:29:36 | 000,000,714 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2016/09/09 20:28:52 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2016/09/09 01:28:42 | 000,192,216 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2016/09/09 01:17:58 | 000,001,075 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2016/09/09 01:17:34 | 000,002,252 | ---- | M] () -- C:\Users\Taisei\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2016/09/09 01:17:34 | 000,001,387 | ---- | M] () -- C:\Users\Taisei\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2016/09/09 01:17:34 | 000,000,352 | ---- | M] () -- C:\Users\Taisei\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2016/09/09 01:17:34 | 000,000,334 | ---- | M] () -- C:\Users\Taisei\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2016/09/09 01:17:14 | 000,000,025 | -HS- | M] () -- C:\WINDOWS\SysWow64\ReadTag.ini
[2016/09/09 01:16:58 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2016/09/09 01:16:57 | 167,165,949 | -HS- | M] () -- C:\hiberfil.sys
[2016/09/08 23:31:40 | 000,065,536 | ---- | M] () -- C:\WINDOWS\SysNative\spu_storage.bin
[2016/09/08 23:24:16 | 005,506,328 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2016/09/08 21:55:18 | 000,001,075 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2016/08/24 18:05:21 | 000,002,252 | ---- | C] () -- C:\Users\Taisei\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2016/08/24 18:05:21 | 000,002,240 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[2016/04/24 03:18:45 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2015/12/25 21:34:00 | 000,000,221 | ---- | C] () -- C:\Users\Taisei\quest1.c
[2015/12/25 14:39:30 | 000,000,271 | ---- | C] () -- C:\Users\Taisei\hello.c
[2015/10/25 10:32:18 | 000,266,240 | ---- | C] () -- C:\WINDOWS\tn01uninstall.exe
[2015/08/04 11:56:54 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll
[2015/08/04 11:07:42 | 000,143,872 | ---- | C] () -- C:\WINDOWS\SysWow64\atieah32.exe
[2015/08/04 11:07:34 | 000,189,952 | ---- | C] () -- C:\WINDOWS\SysWow64\amdgfxinfo32.dll
[2015/08/04 10:37:22 | 000,102,400 | ---- | C] () -- C:\WINDOWS\SysWow64\hsa-thunk.dll
[2015/07/26 12:46:19 | 000,000,016 | ---- | C] () -- C:\ProgramData\mntemp
[2015/03/14 01:40:16 | 000,107,008 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2015/03/14 01:39:11 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2015/01/20 00:38:51 | 000,000,030 | ---- | C] () -- \AVScanner.ini
[2014/11/06 23:15:48 | 000,255,432 | ---- | C] () -- C:\ProgramData\1415283295.bdinstall.bin
[2014/10/07 01:22:28 | 000,425,044 | ---- | C] () -- C:\ProgramData\1412612002.bdinstall.bin
[2014/07/25 21:27:42 | 000,004,096 | -HS- | C] () -- \radial.cdb
[2014/06/10 22:59:03 | 000,000,242 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014/04/27 13:05:07 | 000,152,064 | ---- | C] () -- \KWDLL.dll
[2014/04/09 23:13:00 | 000,489,064 | ---- | C] () -- \SecurityScanner.dll
[2014/03/06 19:11:54 | 167,165,949 | -HS- | C] () -- \hiberfil.sys
[2014/03/06 19:09:14 | 268,435,456 | -HS- | C] () -- \swapfile.sys
[2013/11/22 02:47:28 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
[2013/08/23 00:44:04 | 000,000,001 | -HS- | C] () -- \BOOTNXT
[2013/08/23 00:44:03 | 000,398,356 | RHS- | C] () -- \bootmgr
[color=#E56717]========== ZeroAccess Check ==========[/color]
[2014/03/28 22:25:04 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2016/05/29 16:08:41 | 022,361,344 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2016/05/29 03:31:21 | 019,788,688 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2014/10/29 10:19:43 | 001,013,760 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2014/10/29 09:59:23 | 000,786,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2014/10/29 10:16:01 | 000,512,512 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
[color=#E56717]========== Custom Scans ==========[/color]
[2016/09/08 23:27:10 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2014/10/11 15:50:46 | 000,000,000 | -H-D | M] -- C:\dmmgames\config
[2016/06/10 21:38:33 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
[2013/11/22 02:47:31 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
[2016/09/07 22:10:27 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsApps
[2015/03/04 22:54:22 | 000,000,000 | -H-D | M] -- C:\ProgramData\tks
[2015/03/04 22:54:22 | 000,000,000 | -H-D | M] -- C:\ProgramData\vid
[2016/04/18 22:31:25 | 000,000,000 | -H-D | M] -- C:\ProgramData\{00E0164B-B182-4800-96DA-F8D39B3A7189}
[2016/04/18 22:31:29 | 000,000,000 | -H-D | M] -- C:\ProgramData\{39F0D482-6A42-445B-B6E2-506945189709}
[2016/04/18 22:31:18 | 000,000,000 | -H-D | M] -- C:\ProgramData\{9327ACE9-CC82-4A33-9B33-291ACA1E267B}
[2016/01/20 03:30:33 | 000,000,000 | -H-D | M] -- C:\ProgramData\{95B4F0ED-951F-4D36-B068-5EC1C4C19C14}
[2016/04/18 22:30:32 | 000,000,000 | -H-D | M] -- C:\ProgramData\{A9158F4E-7914-4019-808A-D4D4993E9958}
[2016/04/18 22:31:23 | 000,000,000 | -H-D | M] -- C:\ProgramData\{C1CF19B4-9194-417A-8B85-84F1471783CE}
[2016/04/18 22:31:32 | 000,000,000 | -H-D | M] -- C:\ProgramData\{F21A5765-AACF-4530-991E-CE1346273F96}
[2016/04/27 22:18:18 | 000,000,000 | -H-D | M] -- C:\ProgramData\Apple Computer\iTunes\SC Info
[2015/02/27 21:46:10 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\BDNAV
[2016/04/18 22:27:33 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\EvoParser
[2015/02/27 21:43:57 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CAE\a95a1738
[2015/08/04 20:26:26 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\CLMPSvc.exe
[2015/07/29 02:03:33 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\CyberLink_PowerDVD_Downloader.exe
[2015/02/27 21:43:51 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\OLRSubmission.exe
[2016/04/18 22:27:34 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVD.exe
[2015/02/27 21:43:58 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVD14Agent.exe
[2015/07/29 02:05:45 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVD15Agent.exe
[2015/08/04 22:46:10 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVDMovie.exe
[2016/04/18 22:27:58 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\setup.exe
[2015/02/27 21:37:23 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\ToGo
[2015/02/27 21:45:30 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CLUpdater\PowerDVD\14.0
[2015/07/29 02:05:22 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CLUpdater\PowerDVD\15.0
[2016/04/18 22:27:02 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\EvoParser\PowerDVD\14.0
[2016/04/18 22:27:51 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\EvoParser\PowerDVD\15.0
[2015/07/29 02:05:08 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\EvoParser\PowerDVD\15.0\Boomerang
[2014/05/14 03:28:16 | 000,000,000 | -H-D | M] -- C:\ProgramData\EPSON\PRINTER
[2014/05/14 03:26:26 | 000,000,000 | -H-D | M] -- C:\ProgramData\EPSON\EPSON EP-302\Language
[2013/08/23 00:36:30 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc
[2014/05/14 03:24:37 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrccache\downloads
[2013/08/23 00:36:30 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc\Profiles
[2016/04/24 03:17:41 | 000,000,000 | RH-D | M] -- C:\Users\Default
[2015/03/04 22:54:22 | 000,000,000 | -H-D | M] -- C:\Users\All Users\tks
[2015/03/04 22:54:22 | 000,000,000 | -H-D | M] -- C:\Users\All Users\vid
[2016/04/18 22:31:25 | 000,000,000 | -H-D | M] -- C:\Users\All Users\{00E0164B-B182-4800-96DA-F8D39B3A7189}
[2016/04/18 22:31:29 | 000,000,000 | -H-D | M] -- C:\Users\All Users\{39F0D482-6A42-445B-B6E2-506945189709}
[2016/04/18 22:31:18 | 000,000,000 | -H-D | M] -- C:\Users\All Users\{9327ACE9-CC82-4A33-9B33-291ACA1E267B}
[2016/01/20 03:30:33 | 000,000,000 | -H-D | M] -- C:\Users\All Users\{95B4F0ED-951F-4D36-B068-5EC1C4C19C14}
[2016/04/18 22:30:32 | 000,000,000 | -H-D | M] -- C:\Users\All Users\{A9158F4E-7914-4019-808A-D4D4993E9958}
[2016/04/18 22:31:23 | 000,000,000 | -H-D | M] -- C:\Users\All Users\{C1CF19B4-9194-417A-8B85-84F1471783CE}
[2016/04/18 22:31:32 | 000,000,000 | -H-D | M] -- C:\Users\All Users\{F21A5765-AACF-4530-991E-CE1346273F96}
[2016/04/27 22:18:18 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Apple Computer\iTunes\SC Info
[2015/02/27 21:46:10 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\BDNAV
[2016/04/18 22:27:33 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\EvoParser
[2015/02/27 21:43:57 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CAE\a95a1738
[2015/08/04 20:26:26 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\CLMPSvc.exe
[2015/07/29 02:03:33 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\CyberLink_PowerDVD_Downloader.exe
[2015/02/27 21:43:51 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\OLRSubmission.exe
[2016/04/18 22:27:34 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVD.exe
[2015/02/27 21:43:58 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVD14Agent.exe
[2015/07/29 02:05:45 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVD15Agent.exe
[2015/08/04 22:46:10 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVDMovie.exe
[2016/04/18 22:27:58 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\setup.exe
[2015/02/27 21:37:23 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\ToGo
[2015/02/27 21:45:30 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CLUpdater\PowerDVD\14.0
[2015/07/29 02:05:22 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CLUpdater\PowerDVD\15.0
[2016/04/18 22:27:02 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\EvoParser\PowerDVD\14.0
[2016/04/18 22:27:51 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\EvoParser\PowerDVD\15.0
[2015/07/29 02:05:08 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\EvoParser\PowerDVD\15.0\Boomerang
[2014/05/14 03:28:16 | 000,000,000 | -H-D | M] -- C:\Users\All Users\EPSON\PRINTER
[2014/05/14 03:26:26 | 000,000,000 | -H-D | M] -- C:\Users\All Users\EPSON\EPSON EP-302\Language
[2013/08/23 00:36:30 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc
[2014/05/14 03:24:37 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\Windows\DeviceMetadataCache\dmrccache\downloads
[2013/08/23 00:36:30 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc\Profiles
[2013/08/23 00:36:30 | 000,000,000 | -H-D | M] -- C:\Users\Default\AppData
[2015/01/01 12:09:03 | 000,000,000 | RH-D | M] -- C:\Users\Public\AccountPictures
[2016/09/08 21:55:18 | 000,000,000 | RH-D | M] -- C:\Users\Public\Desktop
[2016/09/03 22:36:52 | 000,000,000 | -H-D | M] -- C:\Users\Taisei\AppData
[2016/07/05 19:10:54 | 000,889,808 | -H-- | M] (LINE Corporation) -- C:\Users\Taisei\AppData\Local\LINE\bin\LineUpdater.exe
[2014/03/27 11:59:26 | 000,000,000 | -H-D | M] -- C:\Users\Taisei\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~
[2016/05/19 22:48:36 | 000,000,000 | -H-D | M] -- C:\Users\Taisei\AppData\Local\Microsoft\Media Player\アート キャッシュ
[2016/04/24 03:21:19 | 000,000,000 | -H-D | M] -- C:\Users\Taisei\AppData\Local\Microsoft\Windows\PrivacIE
[2016/04/24 03:22:23 | 000,000,000 | RH-D | M] -- C:\Users\Taisei\AppData\Local\Microsoft\Windows\Burn\Burn
[2016/04/24 15:26:20 | 000,000,000 | -H-D | M] -- C:\Users\Taisei\AppData\Local\Microsoft\Windows\INetCache\Virtualized
[2016/04/24 03:21:19 | 000,000,000 | -H-D | M] -- C:\Users\Taisei\AppData\Local\Microsoft\Windows\PrivacIE\Low
[2016/04/24 03:21:17 | 000,000,000 | -H-D | M] -- C:\Users\Taisei\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2014/03/27 16:34:25 | 000,000,000 | -H-D | M] -- C:\Windows\ServiceProfiles\LocalService\AppData
[2014/03/28 19:25:44 | 000,000,000 | -H-D | M] -- C:\Windows\ServiceProfiles\NetworkService\AppData
[2014/06/10 22:59:03 | 000,000,000 | -H-D | M] -- C:\WINDOWS\SysNative\GroupPolicy
[color=#A23BEC]< %windir%\tasks\*.job >[/color]
[2016/09/09 20:29:36 | 000,000,714 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2016/09/09 21:27:39 | 000,000,718 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2016/09/09 21:41:00 | 000,000,39