悪代官の伏魔殿掲示板
リカバリ後の気になる動作について
お世話になります。
前スレでお話ししましたリカバリ後の以下不審な動作について
新スレッドを立てました。
>①notepad.exeがアプリに占有されている
>②キーボードの予測候補がおかしい

>リカバリ後のPCで使用しているIMEにMicrosoft IME以外のIMEを入れていませんか?
いえ、MicrosoftのIMEのみです。
ATOKは使用しないため、今回は最初から入れていません。

HJTとCCのログを取りました。
以前取得したログと比べて、取り立てて怪しいものは
ないように見受けられます。
一部プリインストールで追加されるソフトに
新しいものがあるようですが、怪しいものではなさそうです。

[HJT]
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 22:09:40, on 2022/06/20
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.19041.1566)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Corel\MLSDK\CorelDesktopAgent.exe
C:\Users\ユーザー名\Desktop\HijackThis.exe

F2 - REG:system.ini: UserInit=
O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\102.0.1245.44\BHO\ie_to_edge_bho.dll
O2 - BHO: Internet SagiWall BHO - {BA4D2304-4547-45D5-8338-5F0E97BE5D44} - C:\Program Files (x86)\BBSS\Internet SagiWall\IswBHO_32.dll
O3 - Toolbar: 詐欺ウォール ToolBar - {D5256D78-4904-439D-A045-317A2E2F6A34} - C:\Program Files (x86)\BBSS\Internet SagiWall\IswBHO_32.dll
O4 - HKLM\..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe -scheduler
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - Global Startup: PC情報取得.lnk = C:\Program Files (x86)\Fujitsu\SptNavi\EzCheckPC.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLMF.DLL
O23 - Service: Roxio SAIB Service (9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269) - Unknown owner - C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: BOT4Service - Unknown owner - C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe
O23 - Service: CorelDAWatchdog - Unknown owner - C:\Program Files (x86)\Corel\MLSDK\CorelAgentService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b63cd4c0552eccb9\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b63cd4c0552eccb9\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\Windows\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_2a9d7 - Unknown owner - C:\Windows\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CriDspApo Service (CriDspApoService) - Unknown owner - C:\Windows\System32\CriDspApoService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Security\ekrn.exe
O23 - Service: ESET Firewall Helper (ekrnEpfw) - ESET - C:\Program Files\ESET\ESET Security\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @oem82.inf,%FBIOSDRV_Utility_Service_DisplayName%;Fujitsu BIOS Driver Service (FBIOSDRVService) - FUJITSU CLIENT COMPUTING LIMITED - C:\Windows\System32\DriverStore\FileRepository\fbiosdrv.inf_amd64_eebbf351c9bcc9b3\fbiosdrv-service.exe
O23 - Service: FJAgentSVC - 富士通クライアントコンピューティング株式会社 - C:\Program Files (x86)\Fujitsu\FJAgent\Core\bin\FJAgentSVC.exe
O23 - Service: @oem17.inf,%Fuj02e3_Utility_Service_DisplayName%;Fujitsu FUJ02E3 Device Driver - Utility Service (Fuj02e3DriverUtilityService) - FUJITSU CLIENT COMPUTING LIMITED - C:\Windows\System32\DriverStore\FileRepository\fuj02e3.inf_amd64_1683545b1e151564\fuj02e3-utility.exe
O23 - Service: @oem21.inf,%iaStorAfsService.ServiceName%;Intel(R) Optane(TM) Memory Service (iaStorAfsService) - Unknown owner - C:\Windows\System32\iaStorAfsService.exe (file missing)
O23 - Service: Intel(R) Graphics Command Center Service (igccservice) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_a84f31b20764b965\OneApp.IGCC.WinService.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_ba355e1f8cdccc52\igfxCUIService.exe
O23 - Service: @oem84.inf,%SocketHECIServiceName%;Intel(R) Capability Licensing Service TCP IP Interface (Intel(R) Capability Licensing Service TCP IP Interface) - Intel(R) Corporation - C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\SocketHeciServer.exe
O23 - Service: @oem84.inf,%TPMProvisioningServiceName%;Intel(R) TPM Provisioning Service (Intel(R) TPM Provisioning Service) - Intel(R) Corporation - C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\TPMProvisioningService.exe
O23 - Service: Intel(R) Audio Service (IntelAudioService) - Unknown owner - C:\Windows\system32\cAVS\IAS\IntelAudioService.exe (file missing)
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_dd349ca1e8d98184\LMS.exe
O23 - Service: MyCloudコンテンツ管理Utility(管理サービス) (MCCManageSVC) - 富士通クライアントコンピューティング株式会社 - C:\Program Files (x86)\Fujitsu\MCCMUtility\MCCManageSVC.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyCloudRemoteAccessConnectSvc - FUJITSU CLIENT COMPUTING LIMITED - C:\Program Files (x86)\Fujitsu\MCRemoteAccess\MCTunnel.exe
O23 - Service: MyCloudRemoteAccessSvc - FUJITSU CLIENT COMPUTING LIMITED - C:\Program Files (x86)\Fujitsu\MCRemoteAccess\svcMPPFclient.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\Windows\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: Corel License Validation Service V2, Powered by arvato (PSI_SVC_2) - arvato digital services llc - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Corel License Validation Service V2 x64, Powered by arvato (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @oem21.inf,%RstMwService.ServiceName%;Intel(R) Storage Middleware Service (RstMwService) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_ba273d0ffb93e225\RstMwService.exe
O23 - Service: Realtek Audio Universal Service (RtkAudioUniversalService) - Realtek Semiconductor - C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_f043f909bedcd504\RtkAudUService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\Windows\system32\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\steamservice.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: UpdateNaviInstallService - FUJITSU CLIENT COMPUTING LIMITED - C:\Program Files\Fujitsu\chitose\updnvsrv.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11571 bytes


[CC]
[インストール情報]
3D ビューアー Microsoft Corporation 2022/06/18 7.2107.7012.0
7-Zip 21.07 (x64) Igor Pavlov 2022/06/19 21.07
CCleaner Piriform 2022/06/20 6.01
Corel Digital Studio Corel Corporation 2022/06/18 1.39.12.0
Corel Digital Studio サービス Corel Corporation 2022/06/18 1.5.39.12
Corel PaintShop Pro 2020 Corel Corporation 2022/06/18 22.2.0.7
Corel WinDVD Corel Inc. 2020/06/27 458 MB 10.9.0.311
Cortana Microsoft Corporation 2022/06/18 4.2204.13303.0
CyberLink Power Media Player14 for FUJITSU CYBERLINK.COM CORPORATION. 2022/06/18 14.1.9027.0
CyberLink PowerDirector 16 AVCHD CyberLink Corp. 2022/06/18 16.0.4908.0
Dirac Audio by CRI for Fujitsu CRIWARE 2022/06/18 1.4.2.0
Disney+ Disney 2022/06/18 1.30.6.0
DMMGamePlayer 5.1.9 DMM.com 2022/06/19 5.1.9
ESET Security ESET, spol. s r.o. 2022/06/18 84.8 MB 15.1.12.0
FMVポータル FUJITSU 2022/06/18 3.1.3.0
FUJITSU Software パソコン乗換ガイド 株式会社富士通ソフトウェアテクノロジーズ 2020/06/27 2.2.0.1
GIMP 2.10.32 The GIMP Team 2022/06/19 2.10.32
Groove ミュージック Microsoft Corporation 2022/06/18 10.22031.10091.0
HEIF Image Extensions Microsoft Corporation 2022/06/18 1.0.43012.0
Intel(R) Processor Graphics Intel Corporation 2022/06/18 26.20.100.7985
Intel® Optane™ Memory and Storage Management INTEL CORP 2022/06/18 18.1.1026.0
Learn to Speak English X3 eLanguage, LLC 2022/06/18 13.0.16.0
Little Witch Nobeta Demo Pupuya Games 2022/06/19
Microsoft Edge Microsoft Corporation 2022/06/19 102.0.1245.44
Microsoft Office Home and Business 2019 - ja-jp Microsoft Corporation 2022/06/18 16.0.11929.20394
Microsoft Pay Microsoft Corporation 2022/06/18 2.4.18324.0
Microsoft SQL Server Compact 4.0 SP1 x64 JPN Microsoft Corporation 2020/06/27 22.2 MB 4.0.8876.1
Microsoft Store Microsoft Corporation 2022/06/18 22204.1401.5.0
Microsoft Store エクスペリエンス ホスト Microsoft Corporation 2022/06/18 12203.44.0.0
Microsoft Update Health Tools Microsoft Corporation 2022/06/18 1.01 MB 3.67.0.0
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2020/06/27 4.84 MB 8.0.61001
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2020/06/27 13.2 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2020/06/27 733 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2020/06/27 8.13 MB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2020/06/27 10.1 MB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2022/06/19 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2020/06/27 11.1 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Corporation 2022/06/19 11.0.61030.0
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 2022/06/19 11.0.61030.0
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 Microsoft Corporation 2022/06/19 12.0.30501.0
Microsoft Visual C++ 2017 Redistributable (x64) - 14.16.27027 Microsoft Corporation 2022/06/19 14.16.27027.1
Microsoft Visual C++ 2017 Redistributable (x86) - 14.16.27027 Microsoft Corporation 2022/06/19 14.16.27027.1
Microsoft 付箋 Microsoft Corporation 2022/06/18 4.5.1.0
Mixed Reality ポータル Microsoft Corporation 2022/06/18 2000.21051.1282.0
Mozilla Firefox (x64 ja) Mozilla 2022/06/18 101.0.1
Mozilla Maintenance Service Mozilla 2022/06/18 101.0.1
MPEG-2 ビデオ拡張機能 Microsoft Corporation 2022/06/18 1.0.50901.0
My Cloud スタジオ CYBERLINK.COM CORPORATION. 2022/06/18 1.8.5115.57929
My Cloud トピック FUJITSU 2022/06/18 2.2.2.0
My Cloud プレイ FUJITSU 2022/06/18 7.5.4.3
My Cloud リモートアクセス設定Utility FUJITSU CLIENT COMPUTING LIMITED 2022/06/18 7.5.4.6
Office Microsoft Corporation 2022/06/18 18.2205.1091.0
OneNote for Windows 10 Microsoft Corporation 2022/06/18 16001.14326.20838.0
People Microsoft Corporation 2022/06/18 10.2105.4.0
Pointing Device Utility for Precision Touchpad FUJITSU 2022/06/18 4.1.6.0
PrintDialog 2022/06/18
Realtek Audio Console Realtek Semiconductor Corp 2022/06/18 1.29.256.0
Realtek Audio Driver Realtek Semiconductor Corp. 2020/06/27 6.0.8924.1
Realtek Card Reader Realtek Semiconductor Corp. 2020/06/27 10.0.18362.21317
Realtek Ethernet Controller Driver Realtek 2020/06/27 10.35.510.2019
Roxio Creator LJB Roxio 2020/06/27 12.2.56.3
SAKURA Editor(サクラエディタ) 2.4.1.2849 (x86) サクラエディタ開発チーム 2022/06/19 2.4.1.2849
Skype Skype 2022/06/18 15.83.3409.0
Solitaire Collection Microsoft Studios 2022/06/18 4.13.5310.0
Spotify Spotify AB 2022/06/18 1.187.612.0
Steam Valve Corporation 2022/06/19 2.10.91.91
Ut Video Codec Suite UMEZAWA Takeshi 2022/06/19 23.0.1
VP9 Video Extensions Microsoft Corporation 2022/06/18 1.0.51171.0
VRoidStudio バージョン 1.8.0 pixiv Inc. 2022/06/19 1.8.0
Web メディア拡張機能 Microsoft Corporation 2022/06/18 1.0.42192.0
Webp 画像拡張機能 Microsoft Corporation 2022/06/18 1.0.42351.0
Windows PC 正常性チェック Microsoft Corporation 2022/06/18 11.6 MB 3.6.2204.08001
Xbox Game bar Microsoft Corporation 2022/06/18 1.54.4001.0
Xbox Game Bar Microsoft Corporation 2022/06/18 5.722.5052.0
Xbox Game Speech Window Microsoft Corporation 2022/06/18 1.21.13002.0
Xbox Identity Provider Microsoft Corporation 2022/06/18 12.85.31001.0
Xbox Live Microsoft Corporation 2022/06/18 1.24.10001.0
Xbox コンソール コンパニオン Microsoft Corporation 2022/06/18 48.88.11001.0
いつもアシスト ふくまろ FUJITSU 2022/06/18 3.9.7.0
アップデートナビ FUJITSU 2022/06/18 1.2.118.0
アップデートナビ インストールサービス FUJITSU CLIENT COMPUTING LIMITED 2020/06/27 318 KB 1.2.0108
アプリ インストーラー Microsoft Corporation 2022/06/18 1.17.10941.0
アラーム & クロック Microsoft Corporation 2022/06/18 10.2101.28.0
インテル® グラフィックス・コマンド・センター INTEL CORP 2022/06/18 1.100.3408.0
カメラ Microsoft Corporation 2022/06/18 2021.105.10.0
スマートフォン連携 Microsoft Corporation 2022/06/18 1.22042.168.0
デバイス製造元からの HEVC ビデオ拡張機能 Microsoft Corporation 2022/06/18 2.0.51121.0
バッテリーユーティリティ FUJITSU 2022/06/18 5.0.8.0
ヒント Microsoft Corporation 2022/06/18 10.2204.1.0
フィードバック Hub Microsoft Corporation 2022/06/18 1.2203.761.0
フォト Microsoft Corporation 2022/06/18 2022.30060.3006.0
プログラミングゼミ 譬ェ蠑丈シ夂、セ繝・ぅ繝シ繝サ繧ィ繝後・繧ィ繝シ 2022/06/18 1.0.97.0
ペイント 3D Microsoft Corporation 2022/06/18 6.2203.1037.0
ボイス レコーダー Microsoft Corporation 2022/06/18 10.2103.28.0
マップ Microsoft Corporation 2022/06/18 10.2104.2.0
メール/カレンダー Microsoft Corporation 2022/06/18 16005.14326.20970.0
ワンタッチボタン設定 FUJITSU 2022/06/18 10.4.1.0
ワンタッチボタン設定 - ボタン構成 (Internet, MENU, SUPPORT) FUJITSU 2022/06/18 1.0.0.0
切り取り & スケッチ Microsoft Corporation 2022/06/18 10.2008.2277.0
問い合わせ Microsoft Corporation 2022/06/18 10.2204.1222.0
天気 Microsoft Corporation 2022/06/18 4.53.41582.0
富士通アドバイザー FUJITSU 2022/06/18 6.4.16.0
富士通アドバイザー サービス FUJITSU CLIENT COMPUTING LIMITED 2022/06/18 6.4.7.0
富士通パソコン お客様サポート FUJITSU 2022/06/18 1.0.0.2
日本語 ローカル エクスペリエンス パック Microsoft Corporation 2022/06/18 19041.48.145.0
映画 & テレビ Microsoft Corporation 2022/06/18 10.22041.10091.0
楽しもう Office Microsoft Corporation 2022/06/18 1.0.60.0
筆ぐるめ 27 FUJI SOFT INCORPORATED... 2022/06/18 27.2.1.0
詐欺ウォール BBソフトサービス株式会社 2020/06/27 18.6 MB 3.5.6
電卓 Microsoft Corporation 2022/06/18 10.2103.8.0
@メニュー FUJITSU CLIENT COMPUTING LIMITED 2020/06/27 7.6.0.0
@メニュー 2022/06/18 V7.6

[スタートアップ(Windows)]
有効 HKCU:Run CCleaner Smart Cleaning Piriform Software Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
無効 HKCU:Run Steam Valve Corporation "C:\Program Files (x86)\Steam\steam.exe" -silent
有効 HKLM:Run egui ESET "C:\Program Files\ESET\ESET Security\ecmds.exe" /run /hide /proxy
無効 HKLM:Run ISUSPM Flexera Software, Inc. C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe -scheduler
有効 HKLM:Run RtkAudUService Realtek Semiconductor "C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_f043f909bedcd504\RtkAudUService64.exe" -background
有効 HKLM:Run SecurityHealth Microsoft Corporation %windir%\system32\SecurityHealthSystray.exe
有効 Startup Common PC情報取得.lnk FUJITSU CLIENT COMPUTING LIMITED C:\Program Files (x86)\Fujitsu\SptNavi\EzCheckPC.exe

[スタートアップ(コンテキストメニュー)]
有効 Directory 7-Zip Igor Pavlov C:\Program Files\7-Zip\7-zip.dll
有効 Directory Corel PaintShop Pro 2020 で参照します Corel, Inc. "c:\Program Files\Corel\Corel PaintShop Pro 2020 (64-bit)\Corel PaintShop Pro.exe" "%L"
有効 Directory PowerShell ウィンドウをここで開く(S) powershell.exe -noexit -command Set-Location -literalPath '%V'
有効 Directory ファイルの所有権
有効 Drive Corel PaintShop Pro 2020 で参照します Corel, Inc. "c:\Program Files\Corel\Corel PaintShop Pro 2020 (64-bit)\Corel PaintShop Pro.exe" "%L"
有効 Drive ESET Security Shell ESET C:\Program Files\ESET\ESET Security\shellExt.dll
有効 Drive PowerShell ウィンドウをここで開く(S) powershell.exe -noexit -command Set-Location -literalPath '%V'
有効 File 7-Zip Igor Pavlov C:\Program Files\7-Zip\7-zip.dll
有効 File ESET Security Shell ESET C:\Program Files\ESET\ESET Security\shellExt.dll
有効 Folder 7-Zip Igor Pavlov C:\Program Files\7-Zip\7-zip.dll
有効 Folder ESET Security Shell ESET C:\Program Files\ESET\ESET Security\shellExt.dll

[スタートアップ(サービス)]
有効 Service BOT4Service "C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe"
有効 Service Corel License Validation Service V2 x64, Powered by arvato arvato digital services llc "c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe"
有効 Service Corel License Validation Service V2, Powered by arvato arvato digital services llc "c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
有効 Service CorelDAWatchdog Corel Corporation "C:\Program Files (x86)\Corel\MLSDK\CorelAgentService.exe"
無効 Service ESET Firewall Helper ESET "C:\Program Files\ESET\ESET Security\ekrn.exe"
有効 Service ESET Service ESET "C:\Program Files\ESET\ESET Security\ekrn.exe"
無効 Service EzInfoSvc FUJITSU CLIENT COMPUTING LIMITED "C:\Program Files (x86)\Fujitsu\SptNavi\EzInfoSvc.exe"
無効 Service FJAgentSVC 富士通クライアントコンピューティング株式会社 "C:\Program Files (x86)\Fujitsu\FJAgent\Core\bin\FJAgentSVC.exe"
無効 Service Fujitsu BIOS Driver Service FUJITSU CLIENT COMPUTING LIMITED C:\Windows\System32\DriverStore\FileRepository\fbiosdrv.inf_amd64_eebbf351c9bcc9b3\fbiosdrv-service.exe
有効 Service Fujitsu FUJ02E3 Device Driver - Utility Service FUJITSU CLIENT COMPUTING LIMITED C:\Windows\System32\DriverStore\FileRepository\fuj02e3.inf_amd64_1683545b1e151564\fuj02e3-utility.exe
有効 Service Intel(R) Audio Service Intel C:\Windows\system32\cAVS\IAS\IntelAudioService.exe
無効 Service Intel(R) Capability Licensing Service TCP IP Interface Intel(R) Corporation C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\SocketHeciServer.exe
有効 Service Intel(R) Content Protection HDCP Service Intel Corporation C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b63cd4c0552eccb9\IntelCpHDCPSvc.exe
無効 Service Intel(R) Content Protection HECI Service Intel Corporation C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b63cd4c0552eccb9\IntelCpHeciSvc.exe
有効 Service Intel(R) Dynamic Application Loader Host Interface Service Intel Corporation C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
有効 Service Intel(R) Graphics Command Center Service Intel Corporation C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_a84f31b20764b965\OneApp.IGCC.WinService.exe
有効 Service Intel(R) HD Graphics Control Panel Service Intel Corporation C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_ba355e1f8cdccc52\igfxCUIService.exe
有効 Service Intel(R) Management and Security Application Local Management Service Intel Corporation C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_dd349ca1e8d98184\LMS.exe
無効 Service Intel(R) Optane(TM) Memory Service Intel Corporation C:\Windows\System32\iaStorAfsService.exe
無効 Service Intel(R) RST HFC Disable Service Intel Corporation C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_ba273d0ffb93e225\HfcDisableService.exe
有効 Service Intel(R) Storage Middleware Service Intel Corporation C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_ba273d0ffb93e225\RstMwService.exe
有効 Service Intel(R) TPM Provisioning Service Intel(R) Corporation C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\TPMProvisioningService.exe
有効 Service IviRegMgr InterVideo "C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe"
無効 Service Mozilla Maintenance Service Mozilla Foundation "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe"
無効 Service MyCloudRemoteAccessConnectSvc FUJITSU CLIENT COMPUTING LIMITED "C:\Program Files (x86)\Fujitsu\MCRemoteAccess\MCTunnel.exe"
有効 Service MyCloudRemoteAccessSvc FUJITSU CLIENT COMPUTING LIMITED "C:\Program Files (x86)\Fujitsu\MCRemoteAccess\svcMPPFclient.exe"
有効 Service MyCloudコンテンツ管理Utility(管理サービス) 富士通クライアントコンピューティング株式会社 "C:\Program Files (x86)\Fujitsu\MCCMUtility\MCCManageSVC.exe"
無効 Service OpenSSH Authentication Agent C:\Windows\System32\OpenSSH\ssh-agent.exe
有効 Service Realtek Audio Universal Service Realtek Semiconductor "C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_f043f909bedcd504\RtkAudUService64.exe"
有効 Service Roxio SAIB Service Corel Corporation C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe
無効 Service Steam Client Service Valve Corporation "C:\Program Files (x86)\Common Files\Steam\steamservice.exe" /RunAsService
有効 Service UpdateNaviInstallService FUJITSU CLIENT COMPUTING LIMITED "C:\Program Files\Fujitsu\chitose\updnvsrv.exe"

[スタートアップ(スケジュールされたタスク)]
有効 Task CCleanerSkipUAC - ユーザー名 Piriform Software Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
無効 Task CorelUpdateHelperTaskCore Corel Corporation c:\Program Files (x86)\Corel\CUH\v2\CUH.exe /t
有効 Task MicrosoftEdgeUpdateTaskMachineCore1d882dc4802202a Microsoft Corporation C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /c
有効 Task MicrosoftEdgeUpdateTaskMachineUA Microsoft Corporation C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /ua /installsource scheduler
無効 Task OneDrive Standalone Update Task-S-1-5-21-840347549-3868661969-2851523628-500 %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
有効 Task SagiWallNaviTask BBSS Corporation C:\Program Files (x86)\BBSS\Internet SagiWall\SagiWallNavi.exe

[Windowsバージョン]
Microsoft Windows [Version 10.0.19044.1766]

以上です。よろしくお願いいたします。
  • Rid
  • 2022/06/20 (Mon) 22:52:51
手動目視で確認をお願いできますか
作業と報告、ご苦労様です。
新たに取り直したログを見せてもらいましたが、不審な痕跡は見えませんね。
IMEも変なものは入ってないのでその点はいいですが、少し原因を切り分けてみましょう。

まずキーボードでの予測変換異常ですが、これはnotepad(メモ帳)だけで起きるのか、それともブラウザや他のアプリ上入力でも起きますか?
Officeで入力を試してnotepadと同じような変換異常が出ずメモ帳だけの症状かどうかを教えてください。

次にタスクマネージャーを開いてください。

タスク画面で「プロセス」タブを開いて、メモ帳項目のCPUやメモリが異常に高くなっていないかを見たうえで、メモ帳欄を右クリックして「ファイルの場所を開く」。

メモ帳のあるフォルダが開いたらそのフォルダのパスをコピーして、そのパスもレスに貼って教えてください。

現在Windows10では複数のパスにnotepadがある仕様ですが、万一正規ではないパスにいつの間にか別のnotepadが存在してそれが起動しているようならまずいかもしれません。
その可能性は薄いですが、過去の相談事例では正規プログラムの名を騙って別のパスに入り込んだマルウェアも多数存在しました。

あと、一応キーボードのドライバー確認もお願いします。

コントロールパネルの「キーボード」を開いて「ハードウェア」→「プロパティ」→「ドライバー」タブから「ドライバーの詳細」の順に開くと使用中のドライバーが表示されるはずです。
そこに複数のドライバーが表示されていたら、別のドライバーを選択してからキーボード動作確認です。
念のため最初に設定されていたドライバー名を記憶しておいて、異常起きたら元のドライバーの戻せる準備したうえで設定変更しましょう。
キーボードのドライバーが知らぬ間に変わっていてのバグもたまにあるのでこれで戻るならいいのですが、状況からみて今回は該当しないと思います。
一応確認はしておいてください
  • 悪代官
  • 2022/06/21 (Tue) 21:48:58
Re: リカバリ後の気になる動作について
お世話になります。
各種確認しました。

>キーボードでの予測変換異常ですが、これはnotepad(メモ帳)だけで起きるのか、それともブラウザや他のアプリ上入力でも起きますか?
メモ帳以外でも発生しています。
ブラウザ上、officeなどすべてで発生します。

>メモ帳項目のCPUやメモリが異常に高くなっていないか
プロセス内にnotepad.exeは常駐していないようです。
念のため、メモ帳を開いて、フォルダの場所にジャンプしましたが
notepad.exeの場所は以下でした。
 C:\Windows\System32
開いている際のメモ帳のCPU使用率も無操作なら0%でした。

>そこに複数のドライバーが表示されていたら、別のドライバーを選択してから
ドライバー変更できませんでした。
以下3つのドライバがあるのですが、選択してOKを押しても
変化がありませんでした。
 C:\Windows\System32\drivers\ekbdflt.sys
 C:\Windows\System32\drivers\kbdclass.sys
 C:\Windows\System32\drivers\kbdhid.sys

【補足】
予測変換の候補ですが、リカバリ前に使用していた
すべての単語が出ているわけではなく、ほんの一部です。
そのゲームのキャラ名も、すべてが出るわけではありませんでした。

以上です。よろしくお願いいたします。
  • Rid
  • 2022/06/21 (Tue) 22:42:38
ユーザー辞書ツールの確認を
続きの説明ありがとうございます。
少し状況が見えてきたかもしれません。

変換候補のぶれはIMEのユーザー辞書が影響している可能性があります。

では以下の手順で確認してもらえますか。

タスクバーに表示されているIMEのアイコン(「あ」か「A」の表示)を右クリックして「設定」から、表示された画面で「学習と辞書」。

そこで「ユーザー辞書ツール」を開いて、誤変換らしい候補がないか見てください。

もし誤変換らしいものがあればそれを選択して上部の「編集」から「削除」で削除できます。
誤変換候補がなければ辞書画面は閉じていいです。

次に先の学習と辞書画面で「入力の精度を高めるために入力履歴を使用する」がオンになっていればそのチェックを外す。

続いて「入力履歴を消去」を押せば履歴消去できます。
この時確認画面が出ますが履歴消去しても構わないなら消去です。
消去したくない履歴あるならスルーでいいです。

設定画面を閉じたらブラウザやメモ帳等でまた入力操作してみて、誤変換の有無を確認してください。
  • 悪代官
  • 2022/06/22 (Wed) 21:14:26
Re: リカバリ後の気になる動作について
お世話になります。

>「ユーザー辞書ツール」を開いて、誤変換らしい候補がないか見てください。
自分で登録した一文字以外はありませんでした。
登録したのは該当のゲームやキャラ名とは関係ない文言です。

>「入力の精度を高めるために入力履歴を使用する」がオンになっていればそのチェックを外す
>「入力履歴を消去」を押せば履歴消去できます。
>設定画面を閉じたらブラウザやメモ帳等でまた入力操作してみて、誤変換の有無を確認してください。
履歴を消しました。
結果、予測変換からキャラ名の候補は消え
一般的な語句がトップになりました。

以上です。よろしくお願いいたします。
  • Rid
  • 2022/06/22 (Wed) 21:54:06
変換のほうは再発なければいいでしょう
こんばんは。
作業後のレスも見せていただきました。

>履歴を消しました。
>結果、予測変換からキャラ名の候補は消え
>一般的な語句がトップになりました。

やはりIMEの学習が絡んでましたか。
変換候補はこれで再発しなければ原因確定と見て以後はまた誤変換が起きたら同様の対処してみてください。

さて変換のほうはいいとして、notepadのほうはまだ起動しても負荷かかってますか?

以前にご自身で作成保存したtxtファイルでもあればその関連付けを確認してみてください。

txtファイルを右クリックから「プロパティ」。

「全般」タブでプログラムがメモ帳なら正規ですが、これが別のプログラムに関連付けされているとtxtもメモ帳では開かなくなります。

ただ関連付けが変わるとファイルのアイコンもメモ帳ではなくプログラムのアイコンになるので普通はすぐ気づくでしょうが、念のため確認してみてください。

あとはプロパティで「セキュリティ」タブ内にsystemや本来のユーザーやAdmin等以外のユーザー名が表示されていないかも見てください。

もしやIMEの履歴消去後メモ帳も普通に動作するならそのことだけ教えてください
  • 悪代官
  • 2022/06/23 (Thu) 21:32:41
Re: リカバリ後の気になる動作について
お世話になります。

>変換候補はこれで再発しなければ原因確定と見て
こちらの理解不足で申し訳ないのですが
リカバリ後に、まだ打ってもないマイナーな文言が
予測候補のトップとして挙がる理由について、まだ理解に及んでおらず
なにかわかったことがあれば、ご説明いただきたいです。
マルウェアや乗っ取りによる心配はない、ということでしょうか?

>変換候補のぶれはIMEのユーザー辞書が影響している可能性があります。
問題となっている単語は、ユーザー辞書に登録していた単語ではなく
また、リカバリするとこれらは全部初期化される認識です。
リカバリ前に打っていた、自分以外打たないであろう言葉や
あまりトレンドとして挙がらないキャラの愛称などが
リカバリ後の初期状態でIMEの予測候補のトップに出る理由として
まだ結びついておらず……。

リカバリ前に打っていたものが、IMEのサーバー経由で残っていたとかでしょうか?
後、最近もしかして、と思ったのは
microsoftアカウントで予測候補が同期していた……とかでしょうか?
一応リカバリ前後でmicrosoftアカウントは同じものを使用していますので……
(ただ、microsoftアカウントはほとんど使用していないため、確証はないですが……)


メモ帳の件ですが、回答いたします。

>notepadのほうはまだ起動しても負荷かかってますか?
タスクマネージャーのプロセスにはおらず、手動起動しても
無操作ならメモリも何も使いません。
ただ、ESETの詳細スキャンをかけるとまだ以下が出ます。
 c:\windows\notepad.exe - を開けません [4]
 c:\windows\system32\notepad.exe - を開けません [4]
 c:\windows\syswow64\notepad.exe - を開けません [4]
プロセスには出ていないが、何かのアプリがnotepad.exeを使い続けているのでしょうか……。

>「全般」タブでプログラムがメモ帳なら正規
メモ帳でした

>「セキュリティ」タブ内にsystemや本来のユーザーやAdmin等以外のユーザー名が表示されていないか
以下4つでした。
 Authenticated Users
 SYSTEM
 Administrators
 Users

>もしやIMEの履歴消去後メモ帳も普通に動作するならそのことだけ教えてください 
消去前も、消去後もメモ帳は普通に開いて使えます。

以上です。よろしくお願いいたします。
  • Rid
  • 2022/06/23 (Thu) 22:43:03
自分が勘違いしてました
またレスが遅くなってごめんなさい。

>リカバリ後に、まだ打ってもないマイナーな文言が
>予測候補のトップとして挙がる理由について、まだ理解に及んでおらず
>なにかわかったことがあれば、ご説明いただきたいです。

いえ、自分のほうが勘違いしてました。
入力途中でそれに続くワードの利用頻度が多いワードは予測変換で上位に表示されるのは普通です。
https://faq.nec-lavie.jp/qasearch/1007/app/servlet/qadoc?QID=020685#a02

こちらの設定でオフにしても症状は変わらないわけですか?

それとメモ帳の動作ですが、上部の「書式」→「右端で折り返す」が有効になっていると負荷がかかるようなので、もしオンになっていたらオフにしてみてください。

自分が説明を読み間違えて角度外れのレスしてしまってすみません。

リカバリすると以前にユーザーが使いやすいように書式やフォルダ含む各種設定していたのも当然初期化されてしまうので、本人が以前の設定を細かい部分まで覚えていれば元通りに復元もできるでしょうが、実際はユーザー自身が以前にカスタマイズしたはずの設定も忘れていて思い出せす戸惑うことも少なくありません。

簡単な例ではWindows標準のフォルダオプション設定もちょっとクリックミスしただけでがらりと表示スタイル変わってしまって慌てたりします。

ただメモ帳がアプリに占有されて重くなるというなら折り返し設定が原因でもなさそうですね。
  • 悪代官
  • 2022/06/24 (Fri) 22:17:27
Re: リカバリ後の気になる動作について
お世話になります。

>こちらの設定でオフにしても症状は変わらないわけですか?
前に行った履歴のクリアで入力候補は初期化され、以後は再発していません。
(リカバリ前の単語は候補に出てきていません)
ただ、これで問題が解決された、と見てよいのか判断できず……。
リカバリ後の何も学習していないIMEで
リカバリ前に使っていた、造語に近い単語とかまで
入力候補のトップに出てくる理由については不明、ということでしょうか……。

>入力途中でそれに続くワードの利用頻度が多いワードは予測変換で上位に表示されるのは普通です。
はい、入力を繰り返してIMEに学習させていれば、その認識です。
ですが、リカバリをしたため、そういったIMEの学習や覚えた単語は
すべて初期状態に戻っているはずなのです。
リカバリをして間もない、まだ何も単語を入力していない真っ新な環境で
一般的に利用頻度が高いわけでもない、ましてや自分で作った造語に近いような単語まで
1文字打っただけで候補トップに出てくる、というのは明らかに不審です。

また、以前書いたmicrosoftアカウントの件ですが、関係はなさそうでした……。
一応履歴削除後にmicrosoftアカウントに切り替えて
予測候補が復活しないか確認しましたが、特に変化しませんでした。

こうなるとやはり、バックアップメディアにマルウェアがくっついていて
それが復元時に入り込んできて、リカバリ前の設定を持ってきて悪用されているのでは……
履歴はクリアしたけど、まだマルウェア本体は潜んでいるのでは……
みたいな相当突飛ではあると思いますが、他に説明のつく理由もなく、不安です……。


以下、メモ帳の件です。
>上部の「書式」→「右端で折り返す」が有効になっていると負荷がかかるようなので、もしオンになっていたらオフにしてみてください。
オフになっていました

>メモ帳がアプリに占有されて重くなる
重くなっているわけではありません。
ESETの検出ログで
「検査のためにメモ帳を開こうとしたけど
他のアプリが占有しているためメモ帳が開けなかった」
という意味のものが出ているだけです。
タスクに常駐して、しかも重くなっているということはありません。

ESETはこの手の「開けなかった」系のログはよく出すのですが
メモ帳というのは初めてで、かつメモ帳を占有するなんて
通常のアプリの挙動ではあまり考えられず
メモ帳がらみのマルウェアの話もネットで見ていたこともあり
不審なマルウェアが裏でメモ帳をこっそり悪用しているのではないか
と不安になったというものです。
(ログ出力とかに使用しているのでしょうか……)


説明がわかりにくくて申し訳ございません。
とにかく、今のPCに不審なマルウェアがないか
ということを確認したいです……。

以上です。よろしくお願いいたします
  • Rid
  • 2022/06/24 (Fri) 23:25:36
CCの詳細モードで解析を
今夜もレスが遅くなってすみません。

>リカバリ後の何も学習していないIMEで
>リカバリ前に使っていた、造語に近い単語とかまで
>入力候補のトップに出てくる理由については不明、ということでしょうか……。

はい、感染による症状の恐れは少ないでしょうが今のところ自分の知る範囲ではわかりません。

>リカバリをして間もない、まだ何も単語を入力していない真っ新な環境で
>一般的に利用頻度が高いわけでもない、ましてや自分で作った造語に近いような単語まで
>1文字打っただけで候補トップに出てくる、というのは明らかに不審です。

LANを抜くなりして物理的にネットから切断した状態で予測変換が出なければMSのサーバーから予測変換の候補が表示される可能性もあります。

>バックアップメディアにマルウェアがくっついていて
>それが復元時に入り込んできて、リカバリ前の設定を持ってきて悪用されているのでは……

どんなデータをバックアップしたかによってその可能性はありえます。

ではお手数ですがCCでまたひとつ解析してみますか。

CCで「ツール」→「スタートアップ」→「スケジュールされたタスク」タブを表示して、そこで「詳細モード」にチェック入れて、その状態で同タブのログをとってから、そのログをレスで見せてください。

ログを取ったら誤操作を防ぐために詳細モードのチェックは外してからCC終了していいです。

スケジュールタブの詳細モードはより多数のエントリを見ることができるので通常は見つけられない部分も解析可能になります。
逆にシステム上重要な個所も表示できるため、うかつにいじるとWindows自体に不具合きたすおそれもあるのでCCの詳細モードは使用推奨も説明も普段はしません。

他にもCCはうまく使えば解析とシステム設定でかなり便利ですがひとつ間違えただけで深刻な不具合に至る危険もはらんでいます。これはCCに限らずシステム系ツール全部に共通する性質です。
HJTももともとはシステム解析と設定のために開発されたツールですが、マルウェアかいせきと処置に高い効果を発揮する働きが世界中の有識者に注目されたせいで一部にはセキュリティ用ツールと思い込む方もいたほどです。

高性能なツールを使う前にはご自身のPC環境を把握して、安全な範囲内で判断することも認識しましょう
  • 悪代官
  • 2022/06/25 (Sat) 21:25:45
Re: リカバリ後の気になる動作について
お世話になります。

>はい、感染による症状の恐れは少ないでしょうが今のところ自分の知る範囲ではわかりません。
承知しました。

>CCで「ツール」→「スタートアップ」→「スケジュールされたタスク」タブを表示して、
>そこで「詳細モード」にチェック入れて、その状態で同タブのログをとってから、そのログをレスで見せてください。
以下、CCの詳細モードでスケジュールされたタスクのログを取得しましたので
お手数をおかけいたしますが、ご確認お願い致します。

無効 Task Account Cleanup Microsoft Corporation %windir%\System32\rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance \Microsoft\Windows\SharedPC
無効 Task AD RMS Rights Policy Template Management (Automated) \Microsoft\Windows\Active Directory Rights Management Services Client
有効 Task AD RMS Rights Policy Template Management (Manual) \Microsoft\Windows\Active Directory Rights Management Services Client
有効 Task AikCertEnrollTask \Microsoft\Windows\CertificateServicesClient
有効 Task AnalyzeSystem \Microsoft\Windows\Power Efficiency Diagnostics
有効 Task appuriverifierdaily Microsoft Corporation %windir%\system32\AppHostRegistrationVerifier.exe \Microsoft\Windows\ApplicationData
有効 Task appuriverifierinstall Microsoft Corporation %windir%\system32\AppHostRegistrationVerifier.exe \Microsoft\Windows\ApplicationData
無効 Task Automatic-Device-Join Microsoft Corporation %SystemRoot%\System32\dsregcmd.exe $(Arg0) $(Arg1) $(Arg2) \Microsoft\Windows\Workplace Join
有効 Task Backup \Microsoft\Windows\AppListBackup
有効 Task BgTaskRegistrationMaintenanceTask \Microsoft\Windows\BrokerInfrastructure
有効 Task BitLocker Encrypt All Drives \Microsoft\Windows\BitLocker
有効 Task BitLocker MDM policy Refresh \Microsoft\Windows\BitLocker
有効 Task CacheTask \Microsoft\Windows\Wininet
有効 Task Calibration Loader \Microsoft\Windows\WindowsColorSystem
有効 Task CCleanerSkipUAC - ユーザー名 Piriform Software Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0) \
有効 Task CDSSync \Microsoft\Windows\WlanSvc
有効 Task CleanupTemporaryState Microsoft Corporation %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState \Microsoft\Windows\ApplicationData
有効 Task Consolidator Microsoft Corporation %SystemRoot%\System32\wsqmcons.exe \Microsoft\Windows\Customer Experience Improvement Program
無効 Task CorelUpdateHelperTaskCore Corel Corporation c:\Program Files (x86)\Corel\CUH\v2\CUH.exe /t \
有効 Task CryptoPolicyTask \Microsoft\Windows\CertificateServicesClient
有効 Task Data Integrity Check And Scan \Microsoft\Windows\Data Integrity Scan
有効 Task Data Integrity Scan \Microsoft\Windows\Data Integrity Scan
無効 Task DBDownloadCheck Fujitsu C:\Program Files (x86)\Fujitsu\FJAgent\Engines\DBDownloader\DBDownloader.exe /normal \Fujitsu\MyCloud
有効 Task Device Microsoft Corporation %windir%\system32\devicecensus.exe SystemCxt \Microsoft\Windows\Device Information
有効 Task Device User Microsoft Corporation %windir%\system32\devicecensus.exe UserCxt \Microsoft\Windows\Device Information
無効 Task Device-Sync \Microsoft\Windows\Workplace Join
有効 Task Diagnostics Microsoft Corporation %windir%\system32\disksnapshot.exe -z \Microsoft\Windows\DiskFootprint
有効 Task DmClient Microsoft Corporation %windir%\system32\dmclient.exe \Microsoft\Windows\Feedback\Siuf
有効 Task DmClientOnScenarioDownload Microsoft Corporation %windir%\system32\dmclient.exe utcwnf \Microsoft\Windows\Feedback\Siuf
有効 Task DsSvcCleanup Microsoft Corporation %windir%\system32\dstokenclean.exe \Microsoft\Windows\ApplicationData
有効 Task dusmtask Microsoft Corporation %SystemRoot%\System32\dusmtask.exe \Microsoft\Windows\DUSM
有効 Task EDP App Launch Task \Microsoft\Windows\EDP
有効 Task EDP Auth Task \Microsoft\Windows\EDP
有効 Task EDP Inaccessible Credentials Task \Microsoft\Windows\EDP
有効 Task EDP Policy Manager \Microsoft\Windows\AppID
有効 Task EduPrintProv Microsoft Corporation %windir%\system32\eduprintprov.exe \Microsoft\Windows\Printing
有効 Task ExploitGuard MDM policy Refresh \Microsoft\Windows\ExploitGuard
有効 Task FamilySafetyMonitor Microsoft Corporation %windir%\System32\wpcmon.exe \Microsoft\Windows\Shell
有効 Task FamilySafetyRefreshTask \Microsoft\Windows\Shell
有効 Task File History (maintenance mode) \Microsoft\Windows\FileHistory
有効 Task Firefox Background Update 308046B0AF4A39CB Mozilla Corporation C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate \Mozilla
有効 Task Firefox Default Browser Agent 308046B0AF4A39CB Mozilla Foundation C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB" \Mozilla
有効 Task ForceSynchronizeTime \Microsoft\Windows\Time Synchronization
有効 Task GatherNetworkInfo %windir%\system32\gatherNetworkInfo.vbs \Microsoft\Windows\NetTrace
有効 Task GetAnnouncement "%ProgramFiles(x86)%\Fujitsu\SptNavi\EzSptTask.exe" \Fujitsu\SptNavi
有効 Task GetRunningApp "%ProgramFiles(x86)%\Fujitsu\SptNavi\EzCheckPC.exe" /e \Fujitsu\SptNavi
有効 Task HeadsetButtonPress Microsoft Corporation %windir%\system32\speech_onecore\common\SpeechRuntime.exe StartedFromTask \Microsoft\Windows\Speech
無効 Task HiveUploadTask \Microsoft\Windows\User Profile Service
無効 Task HybridDriveCachePrepopulate \Microsoft\Windows\Sysmain
無効 Task HybridDriveCacheRebalance \Microsoft\Windows\Sysmain
有効 Task IMESharePointDictionary Microsoft Corporation "c:\Program Files (x86)\Common Files\Microsoft Shared\IME16\IMESharePointDictionary.exe" -updateall \Microsoft\Office
有効 Task IndexerAutomaticMaintenance \Microsoft\Windows\Shell
有効 Task Installation \Microsoft\Windows\LanguageComponentsInstaller
無効 Task IntroTool FUJITSU CLIENT COMPUTING LIMITED "C:\Program Files (x86)\Fujitsu\IntroTool\IntroTool.exe" /auto \Fujitsu\IntroTool
有効 Task IntroToolOFF FUJITSU LIMITED "C:\Program Files (x86)\Fujitsu\IntroTool\GExc.exe" GExc-off.ini \Fujitsu\IntroTool
有効 Task IntroToolON FUJITSU LIMITED "C:\Program Files (x86)\Fujitsu\IntroTool\GExc.exe" GExc-on.ini \Fujitsu\IntroTool
無効 Task IntroToolUser FUJITSU CLIENT COMPUTING LIMITED "C:\Program Files (x86)\Fujitsu\IntroTool\AdvRegUser.exe" \Fujitsu\IntroTool
有効 Task IntroToolUserOFF FUJITSU LIMITED "C:\Program Files (x86)\Fujitsu\IntroTool\GExc.exe" GExc-off-user.ini \Fujitsu\IntroTool
有効 Task KeyPreGenTask \Microsoft\Windows\CertificateServicesClient
有効 Task LocalUserSyncDataAvailable \Microsoft\Windows\Input
無効 Task LoginCheck Microsoft Corporation %windir%\system32\sc.exe start pushtoinstall login \Microsoft\Windows\PushToInstall
有効 Task Logon Microsoft Corporation %windir%\system32\ProvTool.exe /turn 5 /source LogonIdleTask \Microsoft\Windows\Management\Provisioning
有効 Task LPRemove Microsoft Corporation %windir%\system32\lpremove.exe \Microsoft\Windows\MUI
有効 Task MaintenanceTasks Microsoft Corporation %windir%\system32\rundll32.exe %windir%\system32\Windows.StateRepositoryClient.dll,StateRepositoryDoMaintenanceTasks \Microsoft\Windows\StateRepository
有効 Task MapsUpdateTask \Microsoft\Windows\Maps
有効 Task Microsoft Compatibility Appraiser Microsoft Corporation %windir%\system32\compattelrunner.exe \Microsoft\Windows\Application Experience
有効 Task MicrosoftEdgeUpdateTaskMachineCore1d882dc4802202a Microsoft Corporation C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /c \
有効 Task MicrosoftEdgeUpdateTaskMachineUA Microsoft Corporation C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /ua /installsource scheduler \
有効 Task MNO Metadata Parser Microsoft Corporation %SystemRoot%\System32\MbaeParserTask.exe \Microsoft\Windows\Mobile Broadband Accounts
有効 Task MobilityManager \Microsoft\Windows\Ras
有効 Task MouseSyncDataAvailable \Microsoft\Windows\Input
有効 Task Notifications Microsoft Corporation %windir%\System32\LocationNotificationWindows.exe \Microsoft\Windows\Location
有効 Task Office Automatic Updates 2.0 Microsoft Corporation C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /frequentupdate SCHEDULEDTASK displaylevel=False \Microsoft\Office
有効 Task Office ClickToRun Service Monitor Microsoft Corporation C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService \Microsoft\Office
有効 Task Office Feature Updates Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe \Microsoft\Office
有効 Task Office Feature Updates Logon Microsoft Corporation C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe /onlogon \Microsoft\Office
無効 Task OneDrive Standalone Update Task-S-1-5-21-840347549-3868661969-2851523628-500 %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe \
有効 Task OobeDiscovery \Microsoft\Windows\WwanSvc
有効 Task PcaPatchDbTask Microsoft Corporation %windir%\system32\rundll32.exe %windir%\system32\PcaSvc.dll,PcaPatchSdbTask \Microsoft\Windows\Application Experience
有効 Task PenSyncDataAvailable \Microsoft\Windows\Input
無効 Task PerformRemediation \Microsoft\Windows\WaaSMedic
無効 Task PolicyConverter Microsoft Corporation %windir%\system32\appidpolicyconverter.exe \Microsoft\Windows\AppID
有効 Task ProactiveScan \Microsoft\Windows\Chkdsk
有効 Task ProgramDataUpdater Microsoft Corporation %windir%\system32\compattelrunner.exe -maintenance \Microsoft\Windows\Application Experience
有効 Task Proxy Microsoft Corporation %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations \Microsoft\Windows\Autochk
有効 Task QueueReporting Microsoft Corporation %windir%\system32\wermgr.exe -upload \Microsoft\Windows\Windows Error Reporting
有効 Task RecommendedTroubleshootingScanner \Microsoft\Windows\Diagnosis
有効 Task ReconcileFeatures \Microsoft\Windows\Flighting\FeatureConfig
有効 Task ReconcileLanguageResources \Microsoft\Windows\LanguageComponentsInstaller
無効 Task Recovery-Check Microsoft Corporation %SystemRoot%\System32\dsregcmd.exe /checkrecovery \Microsoft\Windows\Workplace Join
有効 Task RefreshCache \Microsoft\Windows\Flighting\OneSettings
有効 Task Registration Microsoft Corporation %windir%\system32\sc.exe start pushtoinstall registration \Microsoft\Windows\PushToInstall
有効 Task Report policies Microsoft Corporation %systemroot%\system32\usoclient.exe ReportPolicies \Microsoft\Windows\UpdateOrchestrator
有効 Task ResPriStaticDbSync \Microsoft\Windows\Sysmain
無効 Task Retry Microsoft Corporation %windir%\system32\ProvTool.exe /turn 5 /source ProvRetryTask \Microsoft\Windows\Management\Provisioning
無効 Task RunOnReboot Microsoft Corporation %windir%\system32\ProvTool.exe /turn 5 /source ContinueSessionTask \Microsoft\Windows\Management\Provisioning
無効 Task RunUpdateNotificationMgr Microsoft Corporation %windir%\System32\UNP\UpdateNotificationMgr.exe \Microsoft\Windows\UNP
有効 Task SagiWallNaviTask BBSS Corporation C:\Program Files (x86)\BBSS\Internet SagiWall\SagiWallNavi.exe \
有効 Task ScanForUpdates \Microsoft\Windows\InstallService
有効 Task ScanForUpdatesAsUser \Microsoft\Windows\InstallService
無効 Task Schedule Maintenance Work Microsoft Corporation %systemroot%\system32\usoclient.exe StartMaintenanceWork \Microsoft\Windows\UpdateOrchestrator
有効 Task Schedule Scan Microsoft Corporation %systemroot%\system32\usoclient.exe StartScan \Microsoft\Windows\UpdateOrchestrator
有効 Task Schedule Scan Static Task Microsoft Corporation %systemroot%\system32\usoclient.exe StartScan \Microsoft\Windows\UpdateOrchestrator
無効 Task Schedule Wake To Work Microsoft Corporation %systemroot%\system32\usoclient.exe StartWork \Microsoft\Windows\UpdateOrchestrator
無効 Task Schedule Work Microsoft Corporation %systemroot%\system32\usoclient.exe StartWork \Microsoft\Windows\UpdateOrchestrator
有効 Task Scheduled Start Microsoft Corporation C:\Windows\system32\sc.exe start wuauserv \Microsoft\Windows\WindowsUpdate
有効 Task ScheduledDefrag Microsoft Corp. %windir%\system32\defrag.exe -c -h -o -$ \Microsoft\Windows\Defrag
有効 Task Secure-Boot-Update \Microsoft\Windows\PI
有効 Task ServiceCheck cmd /C start /LOW powershell -NoProfile -NoLogo -NonInteractive -ExecutionPolicy RemoteSigned -File "C:\Program Files (x86)\Fujitsu\MCRemoteAccess\ServiceCheck_run.ps1" \Fujitsu\MyCloud
有効 Task sihpostreboot Microsoft Corporation %systemroot%\system32\sihclient.exe /PostReboot \Microsoft\Windows\WindowsUpdate
有効 Task SilentCleanup Microsoft Corporation %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive% \Microsoft\Windows\DiskCleanup
有効 Task SmartRetry \Microsoft\Windows\InstallService
有効 Task SpaceAgentTask Microsoft Corporation %windir%\system32\SpaceAgent.exe \Microsoft\Windows\SpacePort
有効 Task SpaceManagerTask Microsoft Corporation %windir%\system32\spaceman.exe /Work \Microsoft\Windows\SpacePort
有効 Task SpeechModelDownloadTask Microsoft Corporation %windir%\system32\speech_onecore\common\SpeechModelDownload.exe \Microsoft\Windows\Speech
有効 Task Sqm-Tasks \Microsoft\Windows\PI
有効 Task SR Microsoft Corporation %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation \Microsoft\Windows\SystemRestore
有効 Task StartComponentCleanup \Microsoft\Windows\Servicing
有効 Task StartEzInfoSvc "%ProgramFiles(x86)%\Fujitsu\SptNavi\EzSvcLnc.exe" \Fujitsu\SptNavi
有効 Task StartupAppTask Microsoft Corporation %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask \Microsoft\Windows\Application Experience
有効 Task Storage Tiers Management Initialization \Microsoft\Windows\Storage Tiers Management
無効 Task Storage Tiers Optimization Microsoft Corp. %windir%\system32\defrag.exe -c -h -g -# -m 8 -i 13500 \Microsoft\Windows\Storage Tiers Management
有効 Task StorageCardEncryption Task \Microsoft\Windows\EDP
有効 Task StorageSense \Microsoft\Windows\DiskFootprint
有効 Task Synchronize Language Settings \Microsoft\Windows\International
有効 Task SynchronizeTime Microsoft Corporation %windir%\system32\sc.exe start w32time task_started \Microsoft\Windows\Time Synchronization
有効 Task SynchronizeTimeZone Microsoft Corporation %windir%\system32\tzsync.exe \Microsoft\Windows\Time Zone
有効 Task Sysprep Generalize Drivers Microsoft Corporation %SystemRoot%\System32\drvinst.exe 6 \Microsoft\Windows\Plug and Play
有効 Task SystemSoundsService \Microsoft\Windows\Multimedia
有効 Task SystemTask \Microsoft\Windows\CertificateServicesClient
有効 Task TCMStart C:\Program Files (x86)\Fujitsu\MCCMUtility\TCMStart.bat \Fujitsu\MCCMUtility
有効 Task TouchpadSyncDataAvailable \Microsoft\Windows\Input
有効 Task Tpm-HASCertRetr \Microsoft\Windows\TPM
有効 Task Tpm-Maintenance \Microsoft\Windows\TPM
無効 Task Uninstallation \Microsoft\Windows\LanguageComponentsInstaller
有効 Task UninstallDeviceTask Microsoft Corporation BthUdTask.exe $(Arg0) \Microsoft\Windows\Bluetooth
有効 Task UninstallSMB1ClientTask Microsoft Corporation %windir%\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client" \Microsoft\Windows\SMB
有効 Task UninstallSMB1ServerTask Microsoft Corporation %windir%\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server" \Microsoft\Windows\SMB
有効 Task UpdateCheck Fujitsu Client Computing Limited C:\Program Files (x86)\Fujitsu\McUpdatechk\McUpdateChk.exe /normal \Fujitsu\MyCloud
有効 Task UpdateLibrary "%ProgramFiles%\Windows Media Player\wmpnscfg.exe" \Microsoft\Windows\Windows Media Sharing
有効 Task UpdateModelTask Microsoft Corporation %systemroot%\system32\usoclient.exe StartModelUpdates \Microsoft\Windows\UpdateOrchestrator
有効 Task UpdateUserPictureTask \Microsoft\Windows\Shell
有効 Task UPnPHostConfig Microsoft Corporation sc.exe config upnphost start= auto \Microsoft\Windows\UPnP
有効 Task UsageDataFlushing \Microsoft\Windows\Flighting\FeatureConfig
有効 Task UsageDataReporting \Microsoft\Windows\Flighting\FeatureConfig
有効 Task UseDataAgent FUJITSU LIMITED C:\Program Files (x86)\Fujitsu\MCRemoteAccess\UseDataAgent.exe -b \Fujitsu\MyCloud
有効 Task UserTask \Microsoft\Windows\CertificateServicesClient
有効 Task UserTask-Roam \Microsoft\Windows\CertificateServicesClient
有効 Task USO_UxBroker Microsoft Corporation %systemroot%\system32\MusNotification.exe \Microsoft\Windows\UpdateOrchestrator
無効 Task VerifiedPublisherCertStoreCheck Microsoft Corporation %windir%\system32\appidcertstorecheck.exe \Microsoft\Windows\AppID
無効 Task WakeUpAndContinueUpdates \Microsoft\Windows\InstallService
無効 Task WakeUpAndScanForUpdates \Microsoft\Windows\InstallService
有効 Task WIM-Hash-Management \Microsoft\Windows\WOF
無効 Task WIM-Hash-Validation \Microsoft\Windows\WOF
有効 Task WindowsActionDialog Microsoft Corporation %windir%\System32\WindowsActionDialog.exe \Microsoft\Windows\Location
有効 Task WinSAT \Microsoft\Windows\Maintenance
有効 Task Work Folders Logon Synchronization \Microsoft\Windows\Work Folders
有効 Task Work Folders Maintenance Work \Microsoft\Windows\Work Folders
有効 Task WsSwapAssessmentTask Microsoft Corporation %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask \Microsoft\Windows\Sysmain
有効 Task XblGameSaveTask Microsoft Corporation %windir%\System32\XblGameSaveTask.exe standby \Microsoft\XblGameSave

以上です。よろしくお願いいたします
  • Rid
  • 2022/06/25 (Sat) 22:13:30
IMEを変更して動作確認も手です
こんばんは。
今夜もレスが遅くなってすみません。
詳細モードのタスクスケジュールログを見せてもらいましたが、こちらでも怪しいものは見えないようです。

IMEによる変換候補が気になるなら別のIMEで動作確認するという方法もあります。

「Google 日本語入力」
https://www.google.co.jp/ime/

これはIMEではMSの後発ですが変換候補の多彩さでMS以上の語句をカバーしており、日本語だけでもMSがカバーできていないローカルな地名も変換候補に出てくるのでユーザーが自分で学習設定する手間もかなり省けます。

これをインストールしてPCデフォルトのIMEに設定して、メモ帳やブラウザ上での変換動作を確認してみますか?
一応MSとこれを両方インストールしてもユーザーがそれぞれのIMEを切り替えて使うことはできるので使いにくければいつでも元のMS IMEに戻せるし不要ならGoogle日本語入力はいつでもアンインストールできます。

Googleで入力した語句の変換と、MSで入力した語句の変換が違っていればGoogleとMSの変換候補の違いと考えられます。

ただGoogle日本語入力は変換候補が多彩すぎるとか使い勝手で不便とかいうユーザーもいるので慣れない方にはWindows標準のIMEのほうがいいかもしれません。
またGoogleアプリはインストールするとタスクスケジューラに更新のエントリが追加されたりもするのでこの動作が不要ならユーザーが手動目視で無効化設定することになります。
これの使用の判断はRidさんにお任せしますので、使いたくないなら入れずにその旨だけお返事くださればいいです
  • 悪代官
  • 2022/06/26 (Sun) 21:52:09
Re: リカバリ後の気になる動作について
お世話になります。
>詳細モードのタスクスケジュールログを見せてもらいましたが、こちらでも怪しいものは見えないようです。
ご確認ありがとうございます。

>Google日本語入力
>これの使用の判断はRidさんにお任せしますので、使いたくないなら入れずにその旨だけお返事くださればいいです
少し迷いましたが、現状見送りとします。
理由として、発生時は自分で作った一般的には確実に認知されていない単語も候補として出てきたことを踏まえ
IMEの差異によるものとは考えにくい、と思ったためです。
それでも、こういう理由もあるから、というものがあれば試そうとは思いますが……。

以上です。よろしくお願いいたします。
  • Rid
  • 2022/06/27 (Mon) 01:34:09
どうしても気になるならOTLで解析しますか
昨夜はレスできなくてごめんなさい。

Google日本語入力は非使用ということですね。了解しました。

それではちょっとログが大きくなりますがOTLでの解析を試してみますか?
HJTやCCよりも詳細なログ解析可能なツールですがその分ログも長くなるので、不安ならこれも使わずその旨だけお返事くださればいいです。
作業するなら以下の手順で。

以下のツールを準備してください。
OTL(OldTimer Listit)
「Download」ボタンからDLしたら保存しておいてください。
http://oldtimer.geekstogo.com/OTL.exe
片付けるときは起動後に「Cleanup」ボタンを押せば自動で削除されます。
ただし、Windows10をお使いの場合は本体ファイルをそのまま削除すればいいです。

他のプログラムを起動しない状態でOTLを起動してください。
起動したら、ウィンドウの上の方にある「Scan All Users」にチェックを入れ、以下のコマンドを「Custom Scan/Fixes」にコピペしてください。

SHOWHIDDEN
%windir%\tasks\*.job
DRIVES
BASESERVICES
%SYSTEMDRIVE%\*.exe
ACTIVEX
CREATERESTOREPOINT

その後、左上の「Run Scan」を押すとスキャン開始されます。
スキャン開始後、PC環境にもよりますが数分ほどすると、「OTL.txt」と「Extras.txt」がOTL.exeと同じ場所に作成されるはずなので、この2つのファイルをデスクトップあたりに保存しておいてください。
なお、Extras.txtは出ないこともありますが、その場合はOTL.txtだけでもいいです。

このあとOTLログを丸ごと返信に貼り付けてレスで見せてください。
ただしOTLログはかなり長くなるため、一度に送信してもfc2の文字数制限で途切れます。
なのでログも適当なところで1万文字以内に分割して、複数回に分けてレス送信してください。
1万文字を越えた投稿はfc2の文字数制限で途切れてしまうためです。
http://www1.odn.ne.jp/megukuma/count.htm

ログの最後に< End of report >という表示が出るのでそこまで全部貼り付けてください。

OTLでスキャンしただけでは何も変化は起きません。
この結果を見て、検出されたものを次回以降の作業で処置することになるはずです
  • 悪代官
  • 2022/06/28 (Tue) 21:22:43
アクティビティ履歴ではないでしょうか
再登場です。

お話を伺う限りでは、Windowsアクティビティ履歴の影響ではないかと思われます。
https://support.microsoft.com/ja-jp/windows/-windows%E5%B1%A5%E6%AD%B4%E3%81%A8%E3%83%97%E3%83%A9%E3%82%A4%E3%83%90%E3%82%B7%E3%83%BC-2b279964-44ec-8c2f-e0c2-6779b07d2cbd

特に、Microsoftアカウントを使っていると、自動同期によってこの症状が発生しやすいです。
ですので、リカバリを行われる際には、インターネット接続を物理的に遮断した状態でリカバリを行い、ローカルユーザーアカウントを作ることが望ましいですね。

Microsoftアカウント使用中のアクティビティ履歴は、設定で拒否しない限りは自動的にMicrosoftに情報がバックアップされ、その内容を機械的に解析、個々人の利用パターンに応じた広告を表示する形でフィードバックされるほか、リカバリを行った際に、過去の履歴がアカウント同期を介してPCに復元されます。

今回発生している症状は、過去の入力履歴から予測変換を復元されたものではないかと思われます。

尤も、これだけではメモ帳が専有されていることの理由付けにはなりませんし、そもそもメモ帳は多重起動が可能であるため、専有されると言うことそのものが不自然となります。
本来専有されるはずのないプログラムが専有状態にあるのであれば、何らかのトラブルが発生している可能性が濃厚であると言い換えることができます。
そして、リカバリ直後で発生している状況ですので、可能性はほぼ以下の3つに絞られます。

可能性1. リカバリデータ内部にプリインストール(初期導入)されているドライバのバージョンが古く、最新版のWindowsとの互換性がない。
可能性2. WindowsをインストールしているSSDまたはHDDのセレクタ(保存領域)が一部破損している。
可能性3. リカバリ耐性のあるマルウェアに感染している。

可能性1の場合は、ドライバのアップデートで対応可能です。
特に、チップセットドライバ等が原因となっている可能性があります。
可能性2の場合は、SSDやHDDの健康状態をチェックすると見えてきます。有名所では、CrystalDiskInfoでしょうか。
可能性3の場合は、低確率でSSD、HDD、マザーボード(基板)のいずれか、途轍もなく低確率でルーターの4つのうちいずれかが感染している可能性があります。
この場合は、該当する本体ごと買い替える方が無難です。

参考までに。
  • IVNO
  • 2022/06/28 (Tue) 21:24:02
OTLでの解析を希望します
お世話になります。

>それではちょっとログが大きくなりますがOTLでの解析を試してみますか?
 はい、以下、IVNOさんのお話もありますので実施します。
 ログは以下に貼ります。

>Microsoftアカウント使用中のアクティビティ履歴は、設定で拒否しない限りは
>自動的にMicrosoftに情報がバックアップされ、その内容を機械的に解析、
>個々人の利用パターンに応じた広告を表示する形でフィードバックされるほか、
>リカバリを行った際に、過去の履歴がアカウント同期を介してPCに復元されます。
>今回発生している症状は、過去の入力履歴から予測変換を復元されたものではないかと思われます。
 ありがとうございます。
 前に似たような可能性を疑い、IMEの履歴削除後に
 microsoftアカウントにログインしたのですが
 入力候補が復帰しませんでした……。
 その後、すぐにローカルアカウントに戻してしまったため
 もしかして同期のタイミングが合わなかっただけかもしれませんが……。
 ただ、やはりマルウェア以外であると考えられる可能性は
 これ以外にない気もします……。

メモ帳の件ですが
>可能性1. リカバリデータ内部にプリインストール(初期導入)されているドライバのバージョンが古く、最新版のWindowsとの互換性がない。
 現状、どのドライバが該当するかも不明なため、追って確認はしようと思います。
 
>可能性2. WindowsをインストールしているSSDまたはHDDのセレクタ(保存領域)が一部破損している。
 CrystalDiskInfoは所持しているため、確認してみましたが
 一応、「正常」と出ました。
 
>可能性3. リカバリ耐性のあるマルウェアに感染している。
 この可能性が一番恐ろしいため、引き続きOTLでの確認を行います……。
 ちなみにリカバリ直前にバックアップをするためにESETでフルスキャンした際は
 「メモ帳が使用中のため~」というログは出てきませんでした。
 リカバリ後に初めて見ました。
 リカバリ後のプリインストールのソフトが購入当時から変わっているもの
 新バージョンになっているものもあるため、それらが使用している……
 という可能性を信じたいですが……。

以下、OTL.Txtのログです。
「Extras.txt」は出力されませんでした。
OTL logfile created on: 2022/06/28 22:23:07 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\ユーザー名\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.19041.0)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

7.74 Gb Total Physical Memory | 4.26 Gb Available Physical Memory | 55.01% Memory free
9.05 Gb Paging File | 6.01 Gb Available in Paging File | 66.47% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 234.34 Gb Total Space | 148.03 Gb Free Space | 63.17% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 684.69 Gb Free Space | 73.50% Space Free | Partition Type: NTFS

Computer Name: PC名 | User Name: ユーザー名 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - File not found --
PRC - [2022/06/28 21:45:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\ユーザー名\Desktop\OTL.exe
PRC - [2022/03/31 01:44:09 | 000,676,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\fontdrvhost.exe
PRC - [2022/02/10 13:22:36 | 000,410,424 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) -- C:\Program Files (x86)\Fujitsu\SptNavi\EzWatch.exe
PRC - [2022/02/10 13:22:34 | 000,441,656 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) -- C:\Program Files (x86)\Fujitsu\SptNavi\EzCheckPC.exe
PRC - [2021/09/21 10:13:08 | 000,872,568 | ---- | M] (富士通クライアントコンピューティング株式会社) -- C:\Program Files (x86)\Fujitsu\MCCMUtility\MCCManageSVC.exe
PRC - [2021/03/13 12:33:42 | 000,418,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
PRC - [2020/03/15 01:04:00 | 000,029,696 | ---- | M] () -- C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe
PRC - [2019/11/15 17:25:24 | 000,049,016 | ---- | M] (COREL TW CORP.) -- C:\Program Files (x86)\Corel\MLSDK\CorelDesktopAgent.exe
PRC - [2019/11/15 17:25:24 | 000,022,392 | ---- | M] () -- C:\Program Files (x86)\Corel\MLSDK\CorelAgentService.exe
PRC - [2019/02/07 11:26:26 | 000,166,608 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) -- C:\Program Files (x86)\Fujitsu\MCRemoteAccess\svcMPPFclient.exe
PRC - [2017/12/14 10:48:16 | 000,504,160 | ---- | M] () -- C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe
PRC - [2014/04/30 16:00:36 | 000,277,360 | ---- | M] (arvato digital services llc) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2010/05/20 16:15:00 | 000,110,736 | R--- | M] (InterVideo) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2022/06/18 16:49:25 | 007,806,976 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\a31aa6dffae217ee1ebf503e3a6fd9b5\System.Xml.ni.dll
MOD - [2022/06/18 16:49:20 | 020,930,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\fc8c48c599d389c092583c5fc0f6e563\PresentationFramework.ni.dll
MOD - [2022/06/18 16:49:10 | 012,841,472 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\074da4c6824bc84932350b813f62f7fe\PresentationCore.ni.dll
MOD - [2022/06/18 16:49:03 | 004,297,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\cd5694667611daff5df925fb79b44ae7\WindowsBase.ni.dll
MOD - [2022/06/18 16:49:03 | 000,564,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatioaec034ca#\20f3875e79c37f22e393fd5fa7b4f531\PresentationFramework.Aero2.ni.dll
MOD - [2022/06/18 16:49:00 | 001,060,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\1b4ba721e83857649d0137f5084983eb\System.Configuration.ni.dll
MOD - [2022/06/18 16:48:59 | 008,476,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\57764fb7ec10bfe068aade4e141f0be5\System.Core.ni.dll
MOD - [2022/06/18 16:48:54 | 002,098,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\7a396e1d2c8a237861d51047acc444dd\System.Xaml.ni.dll
MOD - [2022/06/18 16:48:53 | 010,827,776 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\8544565b0ccfddb579837a5d8887dbad\System.ni.dll
MOD - [2022/04/06 14:35:22 | 021,039,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a403a0b75e95c07da2caa7f780446a62\mscorlib.ni.dll
MOD - [2021/10/13 23:16:22 | 000,611,960 | ---- | M] () -- C:\Windows\SysWOW64\TextShaping.dll
MOD - [2021/03/13 12:33:59 | 000,047,472 | ---- | M] () -- C:\Windows\SysWOW64\umpdc.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2022/06/19 00:21:22 | 000,096,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\inetsrv\w3logsvc.dll -- (w3logsvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:42:16 | 000,877,056 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Spectrum.exe -- (spectrum)
SRV:[b]64bit:[/b] - [2022/06/15 21:42:16 | 000,307,200 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SharedRealitySvc.dll -- (SharedRealitySvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:42:16 | 000,304,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvcext.dll -- (vmicvss)
SRV:[b]64bit:[/b] - [2022/06/15 21:42:16 | 000,304,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvcext.dll -- (vmicrdv)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:54 | 002,240,000 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\windowsudk.shellcommon.dll -- (UdkUserSvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:54 | 000,847,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:51 | 003,904,512 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:47 | 001,483,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\usermgr.dll -- (UserManager)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:46 | 000,329,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NetSetupSvc.dll -- (NetSetupSvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:45 | 003,819,008 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:38 | 000,570,368 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\usosvc.dll -- (UsoSvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:37 | 000,601,600 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\EnterpriseAppMgmtSvc.dll -- (EntAppSvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:35 | 001,554,944 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\UserDataService.dll -- (UserDataSvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:35 | 001,191,936 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\Unistore.dll -- (UnistoreSvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:35 | 000,333,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\PushToInstall.dll -- (PushToInstall)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:35 | 000,196,096 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\PimIndexMaintenance.dll -- (PimIndexMaintenanceSvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:32 | 001,223,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SEMgrSvc.dll -- (SEMgrSvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:26 | 001,111,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ClipSVC.dll -- (ClipSVC)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:23 | 000,988,096 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\SecurityHealthService.exe -- (SecurityHealthService)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:21 | 000,992,768 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:20 | 001,291,264 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XblGameSave.dll -- (XblGameSave)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:20 | 000,940,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FlightSettings.dll -- (wisvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:20 | 000,811,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Windows.Management.Service.dll -- (WManSvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:20 | 000,487,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\MitigationClient.dll -- (TroubleshootingSvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:19 | 003,596,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:[b]64bit:[/b] - [2022/05/11 21:42:54 | 001,387,520 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\bcastdvruserservice.dll -- (BcastDVRUserService)
SRV:[b]64bit:[/b] - [2022/05/11 21:42:25 | 001,015,808 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
SRV:[b]64bit:[/b] - [2022/05/11 21:42:24 | 000,875,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:[b]64bit:[/b] - [2022/05/11 21:42:08 | 000,433,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WaaSMedicSvc.dll -- (WaaSMedicSvc)
SRV:[b]64bit:[/b] - [2022/05/11 21:42:07 | 002,430,976 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\InstallService.dll -- (InstallService)
SRV:[b]64bit:[/b] - [2022/05/11 21:42:05 | 002,244,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:[b]64bit:[/b] - [2022/05/11 21:42:00 | 001,870,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WpcDesktopMonSvc.dll -- (WpcMonSvc)
SRV:[b]64bit:[/b] - [2022/05/11 21:41:59 | 000,964,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\PhoneService.dll -- (PhoneSvc)
SRV:[b]64bit:[/b] - [2022/04/14 22:07:38 | 002,233,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:[b]64bit:[/b] - [2022/04/14 22:07:29 | 000,370,688 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:[b]64bit:[/b] - [2022/03/31 01:43:43 | 000,461,824 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\AarSvc.dll -- (AarSvc)
SRV:[b]64bit:[/b] - [2022/03/31 01:43:43 | 000,391,168 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\BthAvctpSvc.dll -- (BthAvctpSvc)
SRV:[b]64bit:[/b] - [2022/03/23 21:12:56 | 000,346,448 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Update Health Tools\uhssvc.exe -- (uhssvc)
SRV:[b]64bit:[/b] - [2022/03/15 14:46:52 | 003,210,720 | ---- | M] (ESET) [On_Demand | Running] -- C:\Program Files\ESET\ESET Security\ekrn.exe -- (ekrnEpfw)
SRV:[b]64bit:[/b] - [2022/03/15 14:46:52 | 003,210,720 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Security\ekrn.exe -- (ekrn)
SRV:[b]64bit:[/b] - [2022/03/09 23:29:46 | 000,085,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:[b]64bit:[/b] - [2022/03/09 23:29:41 | 001,049,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XblAuthManager.dll -- (XblAuthManager)
SRV:[b]64bit:[/b] - [2022/03/05 19:20:16 | 000,379,392 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\DispBroker.Desktop.dll -- (DispBrokerDesktopSvc)
SRV:[b]64bit:[/b] - [2022/03/05 19:20:14 | 000,643,072 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SmsRouterSvc.dll -- (SmsRouter)
SRV:[b]64bit:[/b] - [2022/03/05 19:20:00 | 000,878,080 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\svchost.exe -- (WpnUserService_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\svchost.exe -- (UserDataSvc_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\svchost.exe -- (UnistoreSvc_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (UdkUserSvc_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (PrintWorkflowUserSvc_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\svchost.exe -- (PimIndexMaintenanceSvc_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\svchost.exe -- (OneSyncSvc_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (MessagingService_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (DevicesFlowUserSvc_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (DevicePickerUserSvc_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (DeviceAssociationBrokerSvc_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (ConsentUxUserSvc_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\svchost.exe -- (CDPUserSvc_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\svchost.exe -- (cbdhsvc_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (CaptureService_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (BluetoothUserService_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (BcastDVRUserService_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:55 | 000,059,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (AarSvc_2fccc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:42 | 001,503,232 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dosvc.dll -- (DoSvc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:42 | 000,927,744 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ngcsvc.dll -- (NgcSvc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:42 | 000,771,072 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NgcCtnrSvc.dll -- (NgcCtnrSvc)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:41 | 001,522,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TokenBroker.dll -- (TokenBroker)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:40 | 000,503,296 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\cdpusersvc.dll -- (CDPUserSvc)
SRV:[b]64bit:[/b] - [2022/02/12 01:22:32 | 000,988,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FrameServer.dll -- (FrameServer)
SRV:[b]64bit:[/b] - [2022/02/12 01:22:27 | 001,025,024 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\CBDHSvc.dll -- (cbdhsvc)
SRV:[b]64bit:[/b] - [2022/02/12 01:21:47 | 000,611,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cdpsvc.dll -- (CDPSvc)
SRV:[b]64bit:[/b] - [2022/02/12 01:21:44 | 000,744,448 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2022/02/02 23:02:28 | 000,089,664 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\igcc_dch.inf_amd64_a84f31b20764b965\OneApp.IGCC.WinService.exe -- (igccservice)
SRV:[b]64bit:[/b] - [2022/02/02 23:02:02 | 000,522,280 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\iigd_dch.inf_amd64_b63cd4c0552eccb9\IntelCpHeciSvc.exe -- (cphs)
SRV:[b]64bit:[/b] - [2022/02/02 23:01:58 | 000,345,624 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\iigd_dch.inf_amd64_b63cd4c0552eccb9\IntelCpHDCPSvc.exe -- (cplspcon)
SRV:[b]64bit:[/b] - [2022/02/02 23:01:28 | 000,399,896 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\cui_dch.inf_amd64_ba355e1f8cdccc52\igfxCUIService.exe -- (igfxCUIService2.0.0.0)
SRV:[b]64bit:[/b] - [2022/01/14 23:58:33 | 000,094,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe -- (diagnosticshub.standardcollector.service)
SRV:[b]64bit:[/b] - [2022/01/14 23:58:27 | 000,223,232 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\Windows.SharedPC.AccountManager.dll -- (shpamsvc)
SRV:[b]64bit:[/b] - [2022/01/14 23:58:25 | 005,858,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\Windows.StateRepository.dll -- (StateRepository)
SRV:[b]64bit:[/b] - [2021/10/21 00:35:22 | 001,369,624 | ---- | M] (Realtek Semiconductor) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\realtekservice.inf_amd64_f043f909bedcd504\RtkAudUService64.exe -- (RtkAudioUniversalService)
SRV:[b]64bit:[/b] - [2021/10/13 23:16:30 | 000,036,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:[b]64bit:[/b] - [2021/10/12 06:12:50 | 002,244,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\iastorac.inf_amd64_ba273d0ffb93e225\RstMwService.exe -- (RstMwService)
SRV:[b]64bit:[/b] - [2021/10/12 06:12:42 | 001,917,632 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\DriverStore\FileRepository\iastorac.inf_amd64_ba273d0ffb93e225\HfcDisableService.exe -- (HfcDisableService)
SRV:[b]64bit:[/b] - [2021/09/15 23:51:40 | 000,382,464 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:[b]64bit:[/b] - [2021/09/15 23:51:40 | 000,251,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:[b]64bit:[/b] - [2021/09/15 23:51:32 | 000,677,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WFDSConMgrSvc.dll -- (WFDSConMgrSvc)
SRV:[b]64bit:[/b] - [2021/09/15 23:51:32 | 000,382,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\CredentialEnrollmentManager.exe -- (CredentialEnrollmentManagerUserSvc_2fccc)
SRV:[b]64bit:[/b] - [2021/09/15 23:51:32 | 000,382,696 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\CredentialEnrollmentManager.exe -- (CredentialEnrollmentManagerUserSvc)
SRV:[b]64bit:[/b] - [2021/09/08 19:11:54 | 000,134,368 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) [On_Demand | Stopped] -- C:\Windows\SysNative\DriverStore\FileRepository\fbiosdrv.inf_amd64_eebbf351c9bcc9b3\fbiosdrv-service.exe -- (FBIOSDRVService)
SRV:[b]64bit:[/b] - [2021/09/08 18:08:18 | 000,163,016 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\fuj02e3.inf_amd64_1683545b1e151564\fuj02e3-utility.exe -- (Fuj02e3DriverUtilityService)
SRV:[b]64bit:[/b] - [2021/07/16 01:51:39 | 000,124,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:[b]64bit:[/b] - [2021/07/07 21:51:15 | 000,205,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DiagSvc.dll -- (diagsvc)
SRV:[b]64bit:[/b] - [2021/05/12 23:10:22 | 000,442,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WalletService.dll -- (WalletService)
SRV:[b]64bit:[/b] - [2021/04/29 13:12:36 | 000,382,976 | ---- | M] () [Disabled | Stopped] -- C:\Windows\SysNative\OpenSSH\ssh-agent.exe -- (ssh-agent)
SRV:[b]64bit:[/b] - [2021/04/29 13:11:58 | 000,598,016 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\DevicesFlowBroker.dll -- (DevicesFlowUserSvc)
SRV:[b]64bit:[/b] - [2021/03/30 12:40:48 | 000,482,816 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\Windows.Devices.Picker.dll -- (DevicePickerUserSvc)
SRV:[b]64bit:[/b] - [2021/03/30 12:40:25 | 001,192,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\Microsoft.Graphics.Display.DisplayEnhancementService.dll -- (DisplayEnhancementService)
SRV:[b]64bit:[/b] - [2021/03/13 12:36:00 | 000,734,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\RDXService.dll -- (RetailDemo)
SRV:[b]64bit:[/b] - [2021/03/13 12:35:57 | 000,651,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:[b]64bit:[/b] - [2021/03/13 12:35:51 | 000,351,744 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\APHostService.dll -- (OneSyncSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:35:20 | 000,134,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\MixedRealityRuntime.dll -- (MixedRealityOpenXRSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:45 | 000,293,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvmsession)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:45 | 000,293,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:45 | 000,293,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:45 | 000,293,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:45 | 000,293,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:45 | 000,293,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:42 | 000,326,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\TieringEngineService.exe -- (TieringEngineService)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:29 | 000,087,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:25 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\ConsentUxClient.dll -- (ConsentUxUserSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:23 | 000,106,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\PerceptionSimulation\PerceptionSimulationService.exe -- (perceptionsimulation)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:21 | 001,295,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XboxNetApiSvc.dll -- (XboxNetApiSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:21 | 000,329,504 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SgrmBroker.exe -- (SgrmBroker)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:20 | 000,114,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\autotimesvc.dll -- (autotimesvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:33:29 | 001,265,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SensorDataService.exe -- (SensorDataService)
SRV:[b]64bit:[/b] - [2021/03/13 12:33:29 | 000,205,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:[b]64bit:[/b] - [2021/03/13 12:33:24 | 000,152,576 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\RMapi.dll -- (RmSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:33:22 | 000,182,272 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\PrintWorkflowService.dll -- (PrintWorkflowUserSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:55 | 000,094,208 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:51 | 000,986,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\CoreMessaging.dll -- (CoreMessagingRegistrar)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:50 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\CaptureService.dll -- (CaptureService)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:35 | 000,489,472 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:35 | 000,466,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SensorService.dll -- (SensorService)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:33 | 000,247,296 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\psmsrv.dll -- (BrokerInfrastructure)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:33 | 000,245,248 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wpnservice.dll -- (WpnService)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:33 | 000,085,504 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\WpnUserService.dll -- (WpnUserService)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:31 | 000,179,712 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBrokerSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:28 | 000,051,200 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\LicenseManagerSvc.dll -- (LicenseManager)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:23 | 000,106,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GraphicsPerfSvc.dll -- (GraphicsPerfSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:14 | 000,391,168 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\CapabilityAccessManager.dll -- (camsvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:13 | 000,240,688 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\deviceaccess.dll -- (DeviceAssociationBrokerSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:12 | 000,097,792 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\tzautoupdate.dll -- (tzautoupdate)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:08 | 000,162,816 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\dssvc.dll -- (DsSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:06 | 000,288,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:05 | 000,159,744 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\embeddedmodesvc.dll -- (embeddedmode)
SRV:[b]64bit:[/b] - [2021/03/13 12:31:55 | 000,454,656 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NaturalAuth.dll -- (NaturalAuthentication)
SRV:[b]64bit:[/b] - [2021/03/13 12:31:51 | 000,382,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vac.dll -- (VacSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:31:48 | 000,302,080 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\LanguageOverlayServer.dll -- (LxpSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:31:48 | 000,238,080 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tetheringservice.dll -- (icssvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:31:48 | 000,091,648 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\MessagingService.dll -- (MessagingService)
SRV:[b]64bit:[/b] - [2021/03/13 12:31:46 | 001,253,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lpasvc.dll -- (wlpasvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:31:46 | 001,023,488 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\BTAGService.dll -- (BTAGService)
SRV:[b]64bit:[/b] - [2021/03/13 12:31:46 | 000,500,736 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\Microsoft.Bluetooth.UserService.dll -- (BluetoothUserService)
SRV:[b]64bit:[/b] - [2021/03/13 12:31:46 | 000,072,704 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\xboxgipsvc.dll -- (XboxGipSvc)
SRV:[b]64bit:[/b] - [2021/01/27 06:00:06 | 003,408,776 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\lms.inf_amd64_dd349ca1e8d98184\LMS.exe -- (LMS)
SRV:[b]64bit:[/b] - [2021/01/24 01:53:08 | 000,628,608 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe -- (jhi_service)
SRV:[b]64bit:[/b] - [2021/01/11 17:47:04 | 000,113,584 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\CriDspApoService.exe -- (CriDspApoService)
SRV:[b]64bit:[/b] - [2020/09/17 09:33:16 | 000,784,664 | ---- | M] (Intel(R) Corporation) [Auto | Stopped] -- C:\Windows\SysNative\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\TPMProvisioningService.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2020/09/17 09:33:14 | 000,861,976 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\SocketHeciServer.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2020/03/09 10:35:48 | 000,390,688 | ---- | M] (Intel) [Auto | Running] -- C:\Windows\SysNative\cAVS\IAS\IntelAudioService.exe -- (IntelAudioService)
SRV:[b]64bit:[/b] - [2019/12/07 18:09:54 | 000,092,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:[b]64bit:[/b] - [2019/12/07 18:09:51 | 000,014,336 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:[b]64bit:[/b] - [2019/12/07 18:09:37 | 000,028,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:[b]64bit:[/b] - [2019/12/07 18:09:33 | 000,341,504 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dusmsvc.dll -- (DusmSvc)
SRV:[b]64bit:[/b] - [2019/12/07 18:09:33 | 000,066,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\hvhostsvc.dll -- (HvHost)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:54 | 000,048,640 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lfsvc.dll -- (lfsvc)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:52 | 000,171,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:52 | 000,058,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dmwappushsvc.dll -- (dmwappushservice)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:33 | 000,065,024 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DevQueryBroker.dll -- (DevQueryBroker)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:27 | 000,094,720 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\moshost.dll -- (MapsBroker)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:27 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Windows.WARP.JITService.dll -- (WarpJITSvc)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:22 | 000,026,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AJRouter.dll -- (AJRouter)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:16 | 003,004,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:16 | 000,103,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:05 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ipxlatcfg.dll -- (IpxlatCfgSvc)
SRV:[b]64bit:[/b] - [2019/03/18 14:57:50 | 000,017,920 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) [Auto | Running] -- C:\Program Files\Fujitsu\chitose\updnvsrv.exe -- (UpdateNaviInstallService)
SRV:[b]64bit:[/b] - [2014/04/30 16:33:52 | 000,337,776 | ---- | M] (arvato digital services llc) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2_x64)
SRV - [2022/06/22 16:02:55 | 001,696,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\Edge\Application\103.0.1264.37\elevation_service.exe -- (MicrosoftEdgeElevationService)
SRV - [2022/06/19 00:21:22 | 000,494,592 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
SRV - [2022/06/19 00:21:22 | 000,494,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (W3SVC)
SRV - [2022/06/19 00:21:22 | 000,075,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\w3logsvc.dll -- (w3logsvc)
SRV - [2022/06/19 00:21:22 | 000,059,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
SRV - [2022/06/15 21:41:19 | 003,596,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2022/06/09 06:20:54 | 000,231,360 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2022/06/07 13:27:36 | 002,814,424 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\steamservice.exe -- (Steam Client Service)
SRV - [2022/05/11 21:42:52 | 000,712,192 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
SRV - [2022/05/11 21:42:50 | 001,839,616 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\InstallService.dll -- (InstallService)
SRV - [2022/03/31 01:44:06 | 000,753,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\FlightSettings.dll -- (wisvc)
SRV - [2022/03/31 01:44:06 | 000,352,256 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\AarSvc.dll -- (AarSvc)
SRV - [2022/03/05 19:20:04 | 001,235,456 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\TokenBroker.dll -- (TokenBroker)
SRV - [2022/02/10 13:22:34 | 000,405,816 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) [Disabled | Stopped] -- C:\Program Files (x86)\Fujitsu\SptNavi\EzInfoSvc.exe -- (EzInfoSvc)
SRV - [2022/02/02 23:02:28 | 000,089,664 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_a84f31b20764b965\OneApp.IGCC.WinService.exe -- (igccservice)
SRV - [2022/02/02 23:02:02 | 000,522,280 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b63cd4c0552eccb9\IntelCpHeciSvc.exe -- (cphs)
SRV - [2022/02/02 23:01:58 | 000,345,624 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b63cd4c0552eccb9\IntelCpHDCPSvc.exe -- (cplspcon)
SRV - [2022/02/02 23:01:28 | 000,399,896 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_ba355e1f8cdccc52\igfxCUIService.exe -- (igfxCUIService2.0.0.0)
SRV - [2022/01/14 23:58:39 | 005,420,640 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\Windows.StateRepository.dll -- (StateRepository)
SRV - [2021/10/21 00:35:22 | 001,369,624 | ---- | M] (Realtek Semiconductor) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_f043f909bedcd504\RtkAudUService64.exe -- (RtkAudioUniversalService)
SRV - [2021/10/13 23:16:39 | 000,033,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2021/10/12 06:12:50 | 002,244,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_ba273d0ffb93e225\RstMwService.exe -- (RstMwService)
SRV - [2021/10/12 06:12:42 | 001,917,632 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_ba273d0ffb93e225\HfcDisableService.exe -- (HfcDisableService)
SRV - [2021/09/21 10:13:08 | 000,872,568 | ---- | M] (富士通クライアントコンピューティング株式会社) [Auto | Running] -- C:\Program Files (x86)\Fujitsu\MCCMUtility\MCCManageSVC.exe -- (MCCManageSVC)
SRV - [2021/09/08 19:11:54 | 000,134,368 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) [On_Demand | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\fbiosdrv.inf_amd64_eebbf351c9bcc9b3\fbiosdrv-service.exe -- (FBIOSDRVService)
SRV - [2021/09/08 18:08:18 | 000,163,016 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\fuj02e3.inf_amd64_1683545b1e151564\fuj02e3-utility.exe -- (Fuj02e3DriverUtilityService)
SRV - [2021/08/06 07:41:06 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe -- (edgeupdatem)
SRV - [2021/08/06 07:41:06 | 000,214,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe -- (edgeupdate)
SRV - [2021/03/30 12:40:49 | 000,342,016 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\Windows.Devices.Picker.dll -- (DevicePickerUserSvc)
SRV - [2021/03/13 12:35:23 | 000,104,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\MixedRealityRuntime.dll -- (MixedRealityOpenXRSvc)
SRV - [2021/03/13 12:34:16 | 000,138,752 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\PrintWorkflowService.dll -- (PrintWorkflowUserSvc)
SRV - [2021/03/13 12:34:07 | 000,630,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\CoreMessaging.dll -- (CoreMessagingRegistrar)
SRV - [2021/03/13 12:34:01 | 000,188,536 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\deviceaccess.dll -- (DeviceAssociationBrokerSvc)
SRV - [2021/03/13 12:34:00 | 000,073,728 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysWOW64\tzautoupdate.dll -- (tzautoupdate)
SRV - [2021/03/13 12:33:55 | 000,962,048 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\Unistore.dll -- (UnistoreSvc)
SRV - [2021/03/13 12:33:33 | 000,733,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\BTAGService.dll -- (BTAGService)
SRV - [2021/01/27 06:00:06 | 003,408,776 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_dd349ca1e8d98184\LMS.exe -- (LMS)
SRV - [2021/01/24 01:53:08 | 000,628,608 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe -- (jhi_service)
SRV - [2020/09/17 09:33:16 | 000,784,664 | ---- | M] (Intel(R) Corporation) [Auto | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\TPMProvisioningService.exe -- (Intel(R)
SRV - [2020/09/17 09:33:14 | 000,861,976 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\SocketHeciServer.exe -- (Intel(R)
SRV - [2020/03/15 01:04:00 | 000,029,696 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe -- (BOT4Service)
SRV - [2019/11/15 17:25:24 | 000,022,392 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Corel\MLSDK\CorelAgentService.exe -- (CorelDAWatchdog)
SRV - [2019/02/07 11:26:26 | 000,166,608 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) [Auto | Running] -- C:\Program Files (x86)\Fujitsu\MCRemoteAccess\svcMPPFclient.exe -- (MyCloudRemoteAccessSvc)
SRV - [2019/02/07 11:25:56 | 000,083,152 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) [On_Demand | Stopped] -- C:\Program Files (x86)\Fujitsu\MCRemoteAccess\MCTunnel.exe -- (MyCloudRemoteAccessConnectSvc)
SRV - [2018/04/25 15:35:30 | 000,236,240 | ---- | M] (富士通クライアントコンピューティング株式会社) [On_Demand | Stopped] -- C:\Program Files (x86)\Fujitsu\FJAgent\Core\bin\FJAgentSVC.exe -- (FJAgentSVC)
SRV - [2017/12/14 10:48:16 | 000,504,160 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe -- (9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269)
SRV - [2014/04/30 16:00:36 | 000,277,360 | ---- | M] (arvato digital services llc) [Auto | Running] -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2010/05/20 16:15:00 | 000,110,736 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)

続く
  • Rid
  • 2022/06/28 (Tue) 23:23:15
OTL2
OTLログの続きです。

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2022/06/15 21:42:11 | 000,032,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2022/06/15 21:42:03 | 000,096,096 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hvservice.sys -- (hvservice)
DRV:[b]64bit:[/b] - [2022/06/15 21:41:47 | 000,415,080 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:[b]64bit:[/b] - [2022/06/15 21:41:42 | 002,008,944 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\refs.sys -- (ReFS)
DRV:[b]64bit:[/b] - [2022/06/15 21:41:42 | 000,498,176 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\cldflt.sys -- (CldFlt)
DRV:[b]64bit:[/b] - [2022/06/15 21:41:37 | 000,181,592 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:[b]64bit:[/b] - [2022/06/15 21:41:37 | 000,145,768 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\bindflt.sys -- (bindflt)
DRV:[b]64bit:[/b] - [2022/06/15 21:41:37 | 000,093,184 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wcnfs.sys -- (wcnfs)
DRV:[b]64bit:[/b] - [2022/06/15 21:41:21 | 000,967,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WdiWiFi.sys -- (wdiwifi)
DRV:[b]64bit:[/b] - [2022/06/15 21:41:19 | 000,680,800 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:[b]64bit:[/b] - [2022/06/15 21:41:19 | 000,620,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:[b]64bit:[/b] - [2022/06/15 21:41:19 | 000,287,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthA2dp.sys -- (BthA2dp)
DRV:[b]64bit:[/b] - [2022/06/15 21:41:19 | 000,252,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc.sys -- (netvsc)
DRV:[b]64bit:[/b] - [2022/05/11 21:43:02 | 000,131,424 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PktMon.sys -- (PktMon)
DRV:[b]64bit:[/b] - [2022/05/11 21:42:09 | 000,093,696 | ---- | M] () [File_System | System | Running] -- C:\Windows\SysNative\drivers\cimfs.sys -- (CimFS)
DRV:[b]64bit:[/b] - [2022/05/11 21:41:58 | 000,306,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2022/05/11 21:41:58 | 000,142,184 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\pmem.sys -- (pmem)
DRV:[b]64bit:[/b] - [2022/05/11 21:41:58 | 000,083,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:[b]64bit:[/b] - [2022/05/11 21:41:58 | 000,064,848 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storufs.sys -- (storufs)
DRV:[b]64bit:[/b] - [2022/05/11 21:41:58 | 000,045,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthMini.SYS -- (BthMini)
DRV:[b]64bit:[/b] - [2022/03/31 01:44:02 | 000,210,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NetAdapterCx.sys -- (NetAdapterCx)
DRV:[b]64bit:[/b] - [2022/03/31 01:43:43 | 000,386,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MbbCx.sys -- (MbbCx)
DRV:[b]64bit:[/b] - [2022/03/31 01:43:37 | 000,147,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthHfEnum.sys -- (BthHFEnum)
DRV:[b]64bit:[/b] - [2022/03/15 14:36:24 | 000,226,264 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:[b]64bit:[/b] - [2022/03/15 14:36:24 | 000,183,888 | ---- | M] (ESET) [File_System | System | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:[b]64bit:[/b] - [2022/03/15 14:36:24 | 000,111,624 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\epfwwfp.sys -- (epfwwfp)
DRV:[b]64bit:[/b] - [2022/03/15 14:36:24 | 000,107,944 | ---- | M] (ESET) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\edevmon.sys -- (edevmon)
DRV:[b]64bit:[/b] - [2022/03/15 14:36:24 | 000,070,776 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\epfw.sys -- (epfw)
DRV:[b]64bit:[/b] - [2022/03/15 14:36:24 | 000,044,968 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\ekbdflt.sys -- (ekbdflt)
DRV:[b]64bit:[/b] - [2022/03/11 17:27:16 | 000,015,824 | ---- | M] (ESET) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\eelam.sys -- (eelam)
DRV:[b]64bit:[/b] - [2022/03/05 19:20:00 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\afunix.sys -- (afunix)
DRV:[b]64bit:[/b] - [2022/03/05 19:19:52 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\applockerfltr.sys -- (applockerfltr)
DRV:[b]64bit:[/b] - [2022/03/05 19:19:38 | 000,261,120 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winnat.sys -- (WinNat)
DRV:[b]64bit:[/b] - [2022/03/05 19:19:34 | 000,332,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xboxgip.sys -- (xboxgip)
DRV:[b]64bit:[/b] - [2022/03/05 19:19:34 | 000,162,128 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:[b]64bit:[/b] - [2022/02/12 01:21:44 | 000,694,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Acx01000.sys -- (Acx01000)
DRV:[b]64bit:[/b] - [2022/02/12 01:21:43 | 000,158,520 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\scmbus.sys -- (scmbus)
DRV:[b]64bit:[/b] - [2022/02/02 23:02:54 | 000,351,792 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\intcdaud.inf_amd64_658abcf72ee536fa\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2022/02/02 23:01:20 | 031,126,592 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\iigd_dch.inf_amd64_b63cd4c0552eccb9\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2022/01/14 23:58:28 | 000,990,536 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\refsv1.sys -- (ReFSv1)
DRV:[b]64bit:[/b] - [2022/01/14 23:58:17 | 000,641,352 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\Vid.sys -- (Vid)
DRV:[b]64bit:[/b] - [2022/01/07 13:36:28 | 004,955,248 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Netwtw10.sys -- (Netwtw10)
DRV:[b]64bit:[/b] - [2021/12/22 14:52:36 | 001,299,528 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\ibtusb.inf_amd64_4d35f1692a1511ec\ibtusb.sys -- (ibtusb)
DRV:[b]64bit:[/b] - [2021/12/18 01:20:16 | 000,051,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xinputhid.sys -- (xinputhid)
DRV:[b]64bit:[/b] - [2021/11/13 01:00:01 | 000,324,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ufx01000.sys -- (Ufx01000)
DRV:[b]64bit:[/b] - [2021/11/13 01:00:01 | 000,202,568 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\wcifs.sys -- (wcifs)
DRV:[b]64bit:[/b] - [2021/10/13 23:16:07 | 000,160,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmCx.sys -- (UcmCx0101)
DRV:[b]64bit:[/b] - [2021/10/13 23:15:51 | 000,418,800 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:[b]64bit:[/b] - [2021/10/13 23:15:51 | 000,186,168 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:[b]64bit:[/b] - [2021/10/13 23:15:51 | 000,104,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:[b]64bit:[/b] - [2021/10/12 06:12:44 | 001,347,776 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorAC.sys -- (iaStorAC)
DRV:[b]64bit:[/b] - [2021/10/12 06:12:44 | 000,073,920 | ---- | M] (Intel Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaStorAfs.sys -- (iaStorAfs)
DRV:[b]64bit:[/b] - [2021/09/15 23:51:29 | 000,648,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:[b]64bit:[/b] - [2021/09/15 23:51:29 | 000,081,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:[b]64bit:[/b] - [2021/09/08 19:12:00 | 000,038,088 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\fbiosdrv.inf_amd64_eebbf351c9bcc9b3\FBIOSDRV.sys -- (FBIOSDRV)
DRV:[b]64bit:[/b] - [2021/09/08 18:08:20 | 000,049,352 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\fuj02e3.inf_amd64_1683545b1e151564\fuj02e3.sys -- (fuj02e3)
DRV:[b]64bit:[/b] - [2021/08/31 01:18:06 | 000,047,840 | ---- | M] (Fujitsu Client Computing Limited) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GabiAcpi.sys -- (GabiAcpi)
DRV:[b]64bit:[/b] - [2021/08/13 01:39:56 | 000,037,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2021/07/16 01:51:27 | 000,057,144 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:[b]64bit:[/b] - [2021/06/11 23:04:13 | 000,097,096 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:[b]64bit:[/b] - [2021/06/11 23:03:54 | 000,159,056 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:[b]64bit:[/b] - [2021/06/11 23:03:51 | 000,057,168 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iorate.sys -- (iorate)
DRV:[b]64bit:[/b] - [2021/04/29 13:12:14 | 000,095,032 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:[b]64bit:[/b] - [2021/04/21 04:23:46 | 001,149,432 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rt640x64.sys -- (rt640x64)
DRV:[b]64bit:[/b] - [2021/04/15 00:32:36 | 000,292,352 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:[b]64bit:[/b] - [2021/04/15 00:32:33 | 000,234,296 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\wof.sys -- (Wof)
DRV:[b]64bit:[/b] - [2021/04/15 00:32:25 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:[b]64bit:[/b] - [2021/03/17 00:01:50 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\basicdisplay.inf_amd64_65ab9a260dbf7467\BasicDisplay.sys -- (BasicDisplay)
DRV:[b]64bit:[/b] - [2021/03/17 00:01:50 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\basicrender.inf_amd64_df49c4daa6251397\BasicRender.sys -- (BasicRender)
DRV:[b]64bit:[/b] - [2021/03/13 12:33:20 | 000,135,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:[b]64bit:[/b] - [2021/03/13 12:32:54 | 000,322,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\msquic.sys -- (MsQuic)
DRV:[b]64bit:[/b] - [2021/03/13 12:32:35 | 000,113,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmUcsiCx.sys -- (UcmUcsiCx0101)
DRV:[b]64bit:[/b] - [2021/03/13 12:32:35 | 000,047,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IndirectKmd.sys -- (IndirectKmd)
DRV:[b]64bit:[/b] - [2021/03/13 12:32:14 | 000,183,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:[b]64bit:[/b] - [2021/03/13 12:31:51 | 000,053,248 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mmcss.sys -- (MMCSS)
DRV:[b]64bit:[/b] - [2021/03/13 12:31:37 | 000,255,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2021/03/13 12:31:36 | 000,168,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ufxsynopsys.sys -- (ufxsynopsys)
DRV:[b]64bit:[/b] - [2021/03/13 12:31:36 | 000,106,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys -- (BthLEEnum)
DRV:[b]64bit:[/b] - [2021/03/13 12:31:35 | 000,026,608 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\IntelTA.sys -- (Telemetry)
DRV:[b]64bit:[/b] - [2021/01/10 23:47:06 | 000,310,656 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\heci.inf_amd64_a54e540558404ee5\x64\TeeDriverW10x64.sys -- (MEIx64)
DRV:[b]64bit:[/b] - [2020/12/29 12:13:42 | 000,173,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\wiman.inf_amd64_6eb0b77a25e99e6e\WiManH\WiManH.sys -- (WiManH)
DRV:[b]64bit:[/b] - [2020/07/29 01:15:58 | 001,409,568 | ---- | M] (Realsil Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPer.sys -- (RTSPER)
DRV:[b]64bit:[/b] - [2020/05/15 00:42:42 | 000,196,360 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\ialpss2_i2c_cnl.inf_amd64_666eecf21665eb26\iaLPSS2_I2C_CNL.sys -- (iaLPSS2_I2C_CNL)
DRV:[b]64bit:[/b] - [2020/05/15 00:42:40 | 000,128,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\ialpss2_gpio2_cnl.inf_amd64_d920c2a844f26eba\iaLPSS2_GPIO2_CNL.sys -- (iaLPSS2_GPIO2_CNL)
DRV:[b]64bit:[/b] - [2020/02/28 07:21:22 | 001,256,104 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\intcoed.inf_amd64_8e768f579c464d53\IntcOED.sys -- (IntcOED)
DRV:[b]64bit:[/b] - [2020/02/28 07:21:22 | 000,664,744 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\intcdmic.inf_amd64_5807aea3a75230cd\IntcDMic.sys -- (IntcDMic)
DRV:[b]64bit:[/b] - [2020/02/28 07:21:20 | 000,289,448 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\intcaudiobus.inf_amd64_1e81e333a2d66ee6\IntcAudioBus.sys -- (IntcAudioBus)
DRV:[b]64bit:[/b] - [2019/12/25 06:48:46 | 000,306,688 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DriverStore\FileRepository\ialpss2_uart2_cnl.inf_amd64_f4d3fa40a0f0bb6a\iaLPSS2_UART2_CNL.sys -- (iaLPSS2_UART2_CNL)
DRV:[b]64bit:[/b] - [2019/12/25 06:48:46 | 000,157,696 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DriverStore\FileRepository\ialpss2_spi_cnl.inf_amd64_aee9bf9b17daaee3\iaLPSS2_SPI_CNL.sys -- (iaLPSS2_SPI_CNL)
DRV:[b]64bit:[/b] - [2019/12/08 00:13:36 | 000,032,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:[b]64bit:[/b] - [2019/12/08 00:13:35 | 000,090,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpatialGraphFilter.sys -- (SpatialGraphFilter)
DRV:[b]64bit:[/b] - [2019/12/07 18:09:48 | 000,072,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NDKPing.sys -- (NDKPing)
DRV:[b]64bit:[/b] - [2019/12/07 18:09:34 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\spaceparser.sys -- (spaceparser)
DRV:[b]64bit:[/b] - [2019/12/07 18:09:33 | 000,131,584 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:[b]64bit:[/b] - [2019/12/07 18:09:33 | 000,088,080 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SgrmAgent.sys -- (SgrmAgent)
DRV:[b]64bit:[/b] - [2019/12/07 18:09:05 | 000,078,848 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:[b]64bit:[/b] - [2019/12/07 18:09:05 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:49 | 000,347,448 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:49 | 000,033,592 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:41 | 000,078,136 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\bam.sys -- (bam)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:39 | 000,023,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdmCompanionFilter.sys -- (WdmCompanionFilter)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:37 | 000,188,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmTcpciCx.sys -- (UcmTcpciCx0101)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:37 | 000,092,984 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\storqosflt.sys -- (storqosflt)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:37 | 000,087,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:37 | 000,076,984 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\WindowsTrustedRT.sys -- (WindowsTrustedRT)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:37 | 000,076,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\urscx01000.sys -- (UrsCx01000)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:37 | 000,040,968 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\cnghwassist.sys -- (cnghwassist)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:36 | 000,173,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:36 | 000,086,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:36 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshwnclx.sys -- (HwNClx0101)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:36 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\portcfg.sys -- (portcfg)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:16 | 000,054,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:16 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:15 | 000,350,136 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:15 | 000,046,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:09 | 000,259,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Ucx01000.sys -- (Ucx01000)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:09 | 000,139,792 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:09 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:09 | 000,059,704 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ipt.sys -- (IPT)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:09 | 000,059,392 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\filecrypt.sys -- (FileCrypt)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:09 | 000,052,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Udecx.sys -- (UdeCx)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:09 | 000,042,296 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\ramdisk.sys -- (Ramdisk)
DRV:[b]64bit:[/b] - [2019/12/07 18:08:05 | 000,008,704 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\gpuenergydrv.sys -- (GpuEnergyDrv)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:57 | 000,089,400 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:57 | 000,059,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:57 | 000,041,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:57 | 000,035,128 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\hvcrash.sys -- (hvcrash)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:57 | 000,027,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:57 | 000,023,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:57 | 000,019,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgid.sys -- (vmgid)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:57 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DriverStore\FileRepository\vrd.inf_amd64_81fbd405ff2470fc\vrd.sys -- (VirtualRender)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,110,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DriverStore\FileRepository\ufxchipidea.inf_amd64_1c78775fffab6a0a\UfxChipidea.sys -- (UfxChipidea)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidspi.sys -- (hidspi)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,056,120 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,055,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidinterrupt.sys -- (hidinterrupt)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,044,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\buttonconverter.sys -- (buttonconverter)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,041,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,036,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmUcsiAcpiClient.sys -- (UcmUcsiAcpiClient)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,033,296 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,032,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\urschipidea.inf_amd64_78ad1c14e33df968\urschipidea.sys -- (UrsChipidea)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,029,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DriverStore\FileRepository\urssynopsys.inf_amd64_057fa37902020500\urssynopsys.sys -- (UrsSynopsys)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,027,648 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DriverStore\FileRepository\genericusbfn.inf_amd64_53931f0ae21d6d2c\genericusbfn.sys -- (genericusbfn)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:56 | 000,018,920 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\WindowsTrustedRTProxy.sys -- (WindowsTrustedRTProxy)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 001,853,752 | ---- | M] (Chelsio Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cht4vx64.sys -- (cht4vbd)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 001,131,320 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mlx4_bus.sys -- (mlx4_bus)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,884,752 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAVC.sys -- (iaStorAVC)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,558,904 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ibbus.sys -- (ibbus)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,537,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mausbhost.sys -- (mausbhost)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,319,800 | ---- | M] (Chelsio Communications) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\cht4sx64.sys -- (cht4iscsi)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,305,464 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,168,464 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\nvdimm.sys -- (nvdimm)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,146,232 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndfltr.sys -- (ndfltr)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,073,016 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winverbs.sys -- (WinVerbs)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,064,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mausbip.sys -- (mausbip)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,047,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vhf.sys -- (vhf)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,043,832 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bttflt.sys -- (bttflt)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,036,152 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winmad.sys -- (WinMad)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:54 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 001,135,416 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,259,384 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,209,720 | ---- | M] (Microsemi Corportation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\SmartSAMD.sys -- (SmartSAMD)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,172,344 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\ItSas35i.sys -- (ItSas35i)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,135,992 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3i.sys -- (LSI_SAS3i)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,124,216 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2i.sys -- (LSI_SAS2i)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,107,320 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,105,480 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\megasas35i.sys -- (megasas35i)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,083,256 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,082,744 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,081,720 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\MegaSas2i.sys -- (megasas2i)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,068,408 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\percsas3i.sys -- (percsas3i)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,064,312 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,063,800 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,058,680 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\percsas2i.sys -- (percsas2i)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,058,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\umbus.inf_amd64_b78a9c5b6fd62c27\umbus.sys -- (umbus)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,034,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\uefi.inf_amd64_c1628ffa62c8e54c\uefi.sys -- (UEFI)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,031,032 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,026,936 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AcpiDev.sys -- (AcpiDev)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:53 | 000,016,696 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volume.sys -- (volume)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:50 | 003,418,936 | ---- | M] (QLogic Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:50 | 000,533,816 | ---- | M] (QLogic Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:50 | 000,260,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaudio2.sys -- (usbaudio2)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:50 | 000,124,728 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:50 | 000,115,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rhproxy.sys -- (rhproxy)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:50 | 000,113,152 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:50 | 000,041,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\compositebus.inf_amd64_7500cffa210c6946\CompositeBus.sys -- (CompositeBus)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:50 | 000,038,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:50 | 000,035,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SDFRd.sys -- (SDFRd)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:50 | 000,018,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\swenum.inf_amd64_16a14542b63c02af\swenum.sys -- (swenum)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:50 | 000,017,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pnpmem.sys -- (PNPMEM)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,177,664 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_I2C_GLK.sys -- (iaLPSS2i_I2C_GLK)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,177,152 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_I2C_CNL.sys -- (iaLPSS2i_I2C_CNL)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,175,104 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_I2C_BXT_P.sys -- (iaLPSS2i_I2C_BXT_P)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,171,520 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_I2C.sys -- (iaLPSS2i_I2C)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,112,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_GPIO2_CNL.sys -- (iaLPSS2i_GPIO2_CNL)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,096,256 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_GPIO2_GLK.sys -- (iaLPSS2i_GPIO2_GLK)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,093,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_GPIO2_BXT_P.sys -- (iaLPSS2i_GPIO2_BXT_P)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,091,136 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iai2c.sys -- (iai2c)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,079,360 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSS2i_GPIO2.sys -- (iaLPSS2i_GPIO2)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,066,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CAD.sys -- (CAD)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,065,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Microsoft.Bluetooth.AvrcpTransport.sys -- (Microsoft_Bluetooth_AvrcpTransport)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,045,568 | ---- | M] (Advanced Micro Devices, Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdi2c.sys -- (amdi2c)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,036,352 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iagpio.sys -- (iagpio)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelpmax.sys -- (intelpmax)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,018,432 | ---- | M] (Advanced Micro Devices, Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdgpio2.sys -- (amdgpio2)
DRV:[b]64bit:[/b] - [2019/12/07 18:07:47 | 000,009,728 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:[b]64bit:[/b] - [2019/03/28 03:01:00 | 000,073,464 | ---- | M] (Corel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:[b]64bit:[/b] - [2017/12/14 01:00:00 | 000,046,392 | ---- | M] (Corel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Sahdad64.sys -- (Sahdad64)
DRV:[b]64bit:[/b] - [2017/12/14 01:00:00 | 000,045,880 | ---- | M] (Corel Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SaibVdAd64.sys -- (SaibVdAd64)
DRV:[b]64bit:[/b] - [2017/12/14 01:00:00 | 000,038,200 | ---- | M] (Corel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Saibad64.sys -- (Saibad64)
DRV:[b]64bit:[/b] - [2016/06/01 17:25:26 | 000,085,712 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\ntk_FujitsuMCP\ntk_FujitsuMCP_64.sys -- (ntk_FujitsuMCP)
DRV:[b]64bit:[/b] - [2014/01/02 15:54:44 | 000,029,400 | ---- | M] (Realtek semiconductor corp) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\RealWoW60.sys -- (RealWoW60)
DRV - [2022/03/05 19:20:13 | 000,034,304 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysWOW64\drivers\afunix.sys -- (afunix)
DRV - [2022/02/02 23:02:54 | 000,351,792 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\intcdaud.inf_amd64_658abcf72ee536fa\IntcDAud.sys -- (IntcDAud)
DRV - [2022/02/02 23:01:20 | 031,126,592 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b63cd4c0552eccb9\igdkmd64.sys -- (igfx)
DRV - [2021/12/22 14:52:36 | 001,299,528 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\ibtusb.inf_amd64_4d35f1692a1511ec\ibtusb.sys -- (ibtusb)
DRV - [2021/09/08 19:12:00 | 000,038,088 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\fbiosdrv.inf_amd64_eebbf351c9bcc9b3\FBIOSDRV.sys -- (FBIOSDRV)
DRV - [2021/09/08 18:08:20 | 000,049,352 | ---- | M] (FUJITSU CLIENT COMPUTING LIMITED) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\fuj02e3.inf_amd64_1683545b1e151564\fuj02e3.sys -- (fuj02e3)
DRV - [2021/03/17 00:01:50 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_65ab9a260dbf7467\BasicDisplay.sys -- (BasicDisplay)
DRV - [2021/03/17 00:01:50 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\DriverStore\FileRepository\basicrender.inf_amd64_df49c4daa6251397\BasicRender.sys -- (BasicRender)
DRV - [2021/01/10 23:47:06 | 000,310,656 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\heci.inf_amd64_a54e540558404ee5\x64\TeeDriverW10x64.sys -- (MEIx64)
DRV - [2020/12/29 12:13:42 | 000,173,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\wiman.inf_amd64_6eb0b77a25e99e6e\WiManH\WiManH.sys -- (WiManH)
DRV - [2020/05/15 00:42:42 | 000,196,360 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\ialpss2_i2c_cnl.inf_amd64_666eecf21665eb26\iaLPSS2_I2C_CNL.sys -- (iaLPSS2_I2C_CNL)
DRV - [2020/05/15 00:42:40 | 000,128,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\ialpss2_gpio2_cnl.inf_amd64_d920c2a844f26eba\iaLPSS2_GPIO2_CNL.sys -- (iaLPSS2_GPIO2_CNL)
DRV - [2020/02/28 07:21:22 | 001,256,104 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_8e768f579c464d53\IntcOED.sys -- (IntcOED)
DRV - [2020/02/28 07:21:22 | 000,664,744 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\intcdmic.inf_amd64_5807aea3a75230cd\IntcDMic.sys -- (IntcDMic)
DRV - [2020/02/28 07:21:20 | 000,289,448 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\intcaudiobus.inf_amd64_1e81e333a2d66ee6\IntcAudioBus.sys -- (IntcAudioBus)
DRV - [2019/12/25 06:48:46 | 000,306,688 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\ialpss2_uart2_cnl.inf_amd64_f4d3fa40a0f0bb6a\iaLPSS2_UART2_CNL.sys -- (iaLPSS2_UART2_CNL)
DRV - [2019/12/25 06:48:46 | 000,157,696 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\ialpss2_spi_cnl.inf_amd64_aee9bf9b17daaee3\iaLPSS2_SPI_CNL.sys -- (iaLPSS2_SPI_CNL)
DRV - [2019/12/07 18:07:57 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\vrd.inf_amd64_81fbd405ff2470fc\vrd.sys -- (VirtualRender)
DRV - [2019/12/07 18:07:56 | 000,110,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\ufxchipidea.inf_amd64_1c78775fffab6a0a\UfxChipidea.sys -- (UfxChipidea)
DRV - [2019/12/07 18:07:56 | 000,032,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\urschipidea.inf_amd64_78ad1c14e33df968\urschipidea.sys -- (UrsChipidea)
DRV - [2019/12/07 18:07:56 | 000,029,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\urssynopsys.inf_amd64_057fa37902020500\urssynopsys.sys -- (UrsSynopsys)
DRV - [2019/12/07 18:07:56 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\genericusbfn.inf_amd64_53931f0ae21d6d2c\genericusbfn.sys -- (genericusbfn)
DRV - [2019/12/07 18:07:53 | 000,058,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\umbus.inf_amd64_b78a9c5b6fd62c27\umbus.sys -- (umbus)
DRV - [2019/12/07 18:07:53 | 000,034,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\uefi.inf_amd64_c1628ffa62c8e54c\UEFI.sys -- (UEFI)
DRV - [2019/12/07 18:07:50 | 000,041,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_7500cffa210c6946\CompositeBus.sys -- (CompositeBus)
DRV - [2019/12/07 18:07:50 | 000,018,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\DriverStore\FileRepository\swenum.inf_amd64_16a14542b63c02af\swenum.sys -- (swenum)
続く
  • Rid
  • 2022/06/28 (Tue) 23:28:16
OTL3
OTLログの続きです。



[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {15F8AD30-9B08-49F5-8596-1D9AFA4B8336}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{15F8AD30-9B08-49F5-8596-1D9AFA4B8336}: "URL" = http://www.bing.com/search?q={searchTerms}&form=PRLNC1&src=IE11TR&pc=LCTE
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {15F8AD30-9B08-49F5-8596-1D9AFA4B8336}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{15F8AD30-9B08-49F5-8596-1D9AFA4B8336}: "URL" = http://www.bing.com/search?q={searchTerms}&form=PRLNC1&src=IE11TR&pc=LCTE


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm

IE - HKU\S-1-5-21-3978063322-4164341669-3297651403-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?pc=LCTE
IE - HKU\S-1-5-21-3978063322-4164341669-3297651403-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://azby.fmworld.net/?ref=202005 [binary data]
IE - HKU\S-1-5-21-3978063322-4164341669-3297651403-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-21-3978063322-4164341669-3297651403-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://azby.fmworld.net/?ref=202005 [binary data]
IE - HKU\S-1-5-21-3978063322-4164341669-3297651403-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=LCTE
IE - HKU\S-1-5-21-3978063322-4164341669-3297651403-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.region: "JP"
FF - prefs.js..browser.startup.homepage: "https://www.google.com/"
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL (Microsoft Corporation)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 101.0.1\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 101.0.1\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS

[2022/06/18 23:59:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ユーザー名\AppData\Roaming\mozilla\Extensions
[2022/06/19 00:00:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ユーザー名\AppData\Roaming\mozilla\Firefox\Profiles\プロファイル名\extensions
[2022/06/18 23:59:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ユーザー名\AppData\Roaming\mozilla\Firefox\Profiles\プロファイル名\storage\default\moz-extension+++5a4f69b1-37c3-443c-b4ed-f5154d258018^userContextId=4294967295
[2022/06/26 12:08:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ユーザー名\AppData\Roaming\mozilla\Firefox\Profiles\プロファイル名\storage\default\moz-extension+++5a4f69b1-37c3-443c-b4ed-f5154d258018^userContextId=4294967295\idb
[2022/06/19 00:00:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ユーザー名\AppData\Roaming\mozilla\Firefox\Profiles\プロファイル名\storage\default\moz-extension+++65c3b622-8826-42d7-b279-81af210d94e5
[2022/06/28 22:21:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ユーザー名\AppData\Roaming\mozilla\Firefox\Profiles\プロファイル名\storage\default\moz-extension+++65c3b622-8826-42d7-b279-81af210d94e5\idb
[2022/06/19 00:00:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ユーザー名\AppData\Roaming\mozilla\Firefox\Profiles\プロファイル名\storage\default\moz-extension+++65c3b622-8826-42d7-b279-81af210d94e5^userContextId=4294967295
[2022/06/28 22:22:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ユーザー名\AppData\Roaming\mozilla\Firefox\Profiles\プロファイル名\storage\default\moz-extension+++65c3b622-8826-42d7-b279-81af210d94e5^userContextId=4294967295\idb
[2022/06/19 00:00:58 | 003,318,964 | ---- | M] () (No name found) -- C:\Users\ユーザー名\AppData\Roaming\mozilla\firefox\profiles\プロファイル名\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

O1 HOSTS File: ([2019/03/19 13:49:40 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (IEToEdge BHO) - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\103.0.1264.37\BHO\ie_to_edge_bho_64.dll (Microsoft Corporation)
O2:[b]64bit:[/b] - BHO: (Internet SagiWall BHO) - {BA4D2304-4547-45D5-8338-5F0E97BE5D44} - C:\Program Files (x86)\BBSS\Internet SagiWall\IswBHO_64.dll ()
O2 - BHO: (IEToEdge BHO) - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\103.0.1264.37\BHO\ie_to_edge_bho.dll (Microsoft Corporation)
O2 - BHO: (Internet SagiWall BHO) - {BA4D2304-4547-45D5-8338-5F0E97BE5D44} - C:\Program Files (x86)\BBSS\Internet SagiWall\IswBHO_32.dll ()
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (詐欺ウォール ToolBar) - {D5256D78-4904-439D-A045-317A2E2F6A34} - C:\Program Files (x86)\BBSS\Internet SagiWall\IswBHO_64.dll ()
O3 - HKLM\..\Toolbar: (詐欺ウォール ToolBar) - {D5256D78-4904-439D-A045-317A2E2F6A34} - C:\Program Files (x86)\BBSS\Internet SagiWall\IswBHO_32.dll ()
O4:[b]64bit:[/b] - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Security\ecmds.exe (ESET)
O4:[b]64bit:[/b] - HKLM..\Run: [RtkAudUService] C:\Windows\SysNative\DriverStore\FileRepository\realtekservice.inf_amd64_f043f909bedcd504\RtkAudUService64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [SecurityHealth] C:\Windows\SysNative\SecurityHealthSystray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\isuspm.exe (Flexera Software, Inc.)
O4 - HKU\S-1-5-19..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3978063322-4164341669-3297651403-1001..\Run: [CCleaner Smart Cleaning] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Software Ltd)
O4 - HKU\S-1-5-21-3978063322-4164341669-3297651403-1001..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DSCAutomationHostEnabled = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableFullTrustStartupTasks = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUwpStartupTasks = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SupportFullTrustStartupTasks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SupportUwpStartupTasks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 1
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{86382596-4b2b-4c7a-a0e3-ac876c643695}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{a9e3f210-1795-4f5e-9427-e0fef3821e87}: DhcpNameServer = 40.50.1.13
O18:[b]64bit:[/b] - Protocol\Handler\mso-minsb.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\mso-minsb-roaming.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\osf.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\osf-roaming.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - U
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
ActiveX:[b]64bit:[/b] {8F5D9E08-71EC-370E-BA96-36E6EF916DF2} - .NET Framework
ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:[b]64bit:[/b] {9459C573-B17A-45AE-9F64-1857B5D58CEE} - "C:\Program Files (x86)\Microsoft\Edge\Application\103.0.1264.37\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --msedge --channel=stable
ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {990CB269-A600-38D0-B7D1-FBD392495F13} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2022/06/28 21:45:44 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\ユーザー名\Desktop\OTL.exe
[2022/06/27 21:51:55 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\voicevox-engine
[2022/06/27 21:51:47 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Roaming\voicevox-cpu
[2022/06/27 01:36:24 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\Documents\Office のカスタム テンプレート
[2022/06/24 22:24:57 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2022/06/20 22:06:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2022/06/20 22:06:47 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2022/06/20 02:08:24 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Roaming\Kisekae-Tai!
[2022/06/19 21:01:03 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\Steam
[2022/06/19 20:59:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2022/06/19 20:59:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2022/06/19 20:59:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2022/06/19 17:46:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\サクラエディタ
[2022/06/19 17:46:10 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Roaming\sakura
[2022/06/19 17:46:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\sakura
[2022/06/19 13:30:15 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2022/06/19 12:05:43 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\priconner
[2022/06/19 12:03:23 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Roaming\dmmgameplayer5
[2022/06/19 12:03:22 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\.DMMGAMEPLAYERSDK
[2022/06/19 12:03:20 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\dmmgameplayer5-updater
[2022/06/19 12:03:10 | 000,000,000 | ---D | C] -- C:\Program Files\DMMGamePlayer
[2022/06/19 12:01:51 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\.cache
[2022/06/19 12:01:48 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Roaming\GIMP
[2022/06/19 12:01:48 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\GIMP
[2022/06/19 12:01:47 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\gegl-0.4
[2022/06/19 12:01:47 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\babl-0.1
[2022/06/19 11:57:27 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP 2
[2022/06/19 11:45:01 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\SYSTEMAX Software Development
[2022/06/19 11:44:59 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\Documents\SYSTEMAX Software Development
[2022/06/19 11:00:12 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Roaming\ESET
[2022/06/19 10:59:58 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\Documents\Outlook ファイル
[2022/06/19 00:44:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2022/06/19 00:44:20 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2022/06/19 00:32:23 | 000,320,512 | ---- | C] (TODO: <会社名>) -- C:\Windows\SysNative\utv_dmo.dll
[2022/06/19 00:32:23 | 000,275,968 | ---- | C] (TODO: <会社名>) -- C:\Windows\SysWow64\utv_dmo.dll
[2022/06/19 00:32:23 | 000,000,000 | ---D | C] -- C:\Program Files\utvideo
[2022/06/19 00:32:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ut Video Codec Suite
[2022/06/19 00:32:03 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\Programs
[2022/06/19 00:21:23 | 000,000,000 | ---D | C] -- C:\inetpub
[2022/06/19 00:21:23 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\BestPractices
[2022/06/19 00:21:23 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\BestPractices
[2022/06/19 00:18:45 | 002,526,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_43.dll
[2022/06/19 00:18:45 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_43.dll
[2022/06/19 00:18:45 | 001,907,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dcsx_43.dll
[2022/06/19 00:18:45 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_43.dll
[2022/06/19 00:18:45 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_7.dll
[2022/06/19 00:18:45 | 000,518,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_7.dll
[2022/06/19 00:18:45 | 000,276,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx11_43.dll
[2022/06/19 00:18:45 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_43.dll
[2022/06/19 00:18:45 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_7.dll
[2022/06/19 00:18:45 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_7.dll
[2022/06/19 00:18:45 | 000,077,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_5.dll
[2022/06/19 00:18:45 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_5.dll
[2022/06/19 00:18:44 | 002,401,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_43.dll
[2022/06/19 00:18:44 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_43.dll
[2022/06/19 00:18:44 | 000,530,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_6.dll
[2022/06/19 00:18:44 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_6.dll
[2022/06/19 00:18:44 | 000,511,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_43.dll
[2022/06/19 00:18:44 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_43.dll
[2022/06/19 00:18:44 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_6.dll
[2022/06/19 00:18:44 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_6.dll
[2022/06/19 00:18:44 | 000,078,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_4.dll
[2022/06/19 00:18:44 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_4.dll
[2022/06/19 00:18:44 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_7.dll
[2022/06/19 00:18:44 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_7.dll
[2022/06/19 00:18:43 | 005,554,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dcsx_42.dll
[2022/06/19 00:18:43 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_42.dll
[2022/06/19 00:18:43 | 002,582,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_42.dll
[2022/06/19 00:18:43 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_42.dll
[2022/06/19 00:18:43 | 000,523,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_42.dll
[2022/06/19 00:18:43 | 000,517,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_5.dll
[2022/06/19 00:18:43 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_5.dll
[2022/06/19 00:18:43 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_42.dll
[2022/06/19 00:18:43 | 000,285,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx11_42.dll
[2022/06/19 00:18:43 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_5.dll
[2022/06/19 00:18:43 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_42.dll
[2022/06/19 00:18:43 | 000,176,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_5.dll
[2022/06/19 00:18:42 | 005,425,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_41.dll
[2022/06/19 00:18:42 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_41.dll
[2022/06/19 00:18:42 | 002,475,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_42.dll
[2022/06/19 00:18:42 | 002,430,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_41.dll
[2022/06/19 00:18:42 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_42.dll
[2022/06/19 00:18:42 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_41.dll
[2022/06/19 00:18:42 | 000,520,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_41.dll
[2022/06/19 00:18:42 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_41.dll
[2022/06/19 00:18:41 | 002,605,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_40.dll
[2022/06/19 00:18:41 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_40.dll
[2022/06/19 00:18:41 | 000,521,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_4.dll
[2022/06/19 00:18:41 | 000,519,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_40.dll
[2022/06/19 00:18:41 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_4.dll
[2022/06/19 00:18:41 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_40.dll
[2022/06/19 00:18:41 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_4.dll
[2022/06/19 00:18:41 | 000,174,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_4.dll
[2022/06/19 00:18:41 | 000,073,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_3.dll
[2022/06/19 00:18:41 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_3.dll
[2022/06/19 00:18:41 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_6.dll
[2022/06/19 00:18:41 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_6.dll
[2022/06/19 00:18:40 | 005,631,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_40.dll
[2022/06/19 00:18:40 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_40.dll
[2022/06/19 00:18:40 | 000,518,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_3.dll
[2022/06/19 00:18:40 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_3.dll
[2022/06/19 00:18:40 | 000,513,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_2.dll
[2022/06/19 00:18:40 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_2.dll
[2022/06/19 00:18:40 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_2.dll
[2022/06/19 00:18:40 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_3.dll
[2022/06/19 00:18:40 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_2.dll
[2022/06/19 00:18:40 | 000,175,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_3.dll
[2022/06/19 00:18:40 | 000,074,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_2.dll
[2022/06/19 00:18:40 | 000,072,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_1.dll
[2022/06/19 00:18:40 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_2.dll
[2022/06/19 00:18:40 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_1.dll
[2022/06/19 00:18:40 | 000,025,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_5.dll
[2022/06/19 00:18:40 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_5.dll
[2022/06/19 00:18:39 | 004,992,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_39.dll
[2022/06/19 00:18:39 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_39.dll
[2022/06/19 00:18:39 | 001,942,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_39.dll
[2022/06/19 00:18:39 | 001,941,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_38.dll
[2022/06/19 00:18:39 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_39.dll
[2022/06/19 00:18:39 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_38.dll
[2022/06/19 00:18:39 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_39.dll
[2022/06/19 00:18:39 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_38.dll
[2022/06/19 00:18:39 | 000,511,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_1.dll
[2022/06/19 00:18:39 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_1.dll
[2022/06/19 00:18:39 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_39.dll
[2022/06/19 00:18:39 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_38.dll
[2022/06/19 00:18:39 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_1.dll
[2022/06/19 00:18:39 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_1.dll
[2022/06/19 00:18:39 | 000,068,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_0.dll
[2022/06/19 00:18:39 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_0.dll
[2022/06/19 00:18:39 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_4.dll
[2022/06/19 00:18:39 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_4.dll
[2022/06/19 00:18:38 | 004,991,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_38.dll
[2022/06/19 00:18:38 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_38.dll
[2022/06/19 00:18:38 | 001,860,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_37.dll
[2022/06/19 00:18:38 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_37.dll
[2022/06/19 00:18:38 | 000,529,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_37.dll
[2022/06/19 00:18:38 | 000,489,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_0.dll
[2022/06/19 00:18:38 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_0.dll
[2022/06/19 00:18:38 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_37.dll
[2022/06/19 00:18:38 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_0.dll
[2022/06/19 00:18:38 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_0.dll
[2022/06/19 00:18:38 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_3.dll
[2022/06/19 00:18:38 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_3.dll
[2022/06/19 00:18:37 | 005,081,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_36.dll
[2022/06/19 00:18:37 | 004,910,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_37.dll
[2022/06/19 00:18:37 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_37.dll
[2022/06/19 00:18:37 | 002,006,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_36.dll
[2022/06/19 00:18:37 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_36.dll
[2022/06/19 00:18:37 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_36.dll
[2022/06/19 00:18:37 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_36.dll
[2022/06/19 00:18:37 | 000,411,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_10.dll
[2022/06/19 00:18:37 | 000,411,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_9.dll
[2022/06/19 00:18:37 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_10.dll
[2022/06/19 00:18:37 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_9.dll
[2022/06/19 00:18:36 | 005,073,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_35.dll
[2022/06/19 00:18:36 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_35.dll
[2022/06/19 00:18:36 | 001,985,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_35.dll
[2022/06/19 00:18:36 | 001,401,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_34.dll
[2022/06/19 00:18:36 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_35.dll
[2022/06/19 00:18:36 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_34.dll
[2022/06/19 00:18:36 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_35.dll
[2022/06/19 00:18:36 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_34.dll
[2022/06/19 00:18:36 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_35.dll
[2022/06/19 00:18:36 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_34.dll
[2022/06/19 00:18:36 | 000,409,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_8.dll
[2022/06/19 00:18:36 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_8.dll
[2022/06/19 00:18:36 | 000,021,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_2.dll
[2022/06/19 00:18:36 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_2.dll
[2022/06/19 00:18:35 | 004,496,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_34.dll
[2022/06/19 00:18:35 | 004,494,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_33.dll
[2022/06/19 00:18:35 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_34.dll
[2022/06/19 00:18:35 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_33.dll
[2022/06/19 00:18:35 | 001,400,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_33.dll
[2022/06/19 00:18:35 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_33.dll
[2022/06/19 00:18:35 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_33.dll
[2022/06/19 00:18:35 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_33.dll
[2022/06/19 00:18:35 | 000,403,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_7.dll
[2022/06/19 00:18:35 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_7.dll
[2022/06/19 00:18:35 | 000,107,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_3.dll
[2022/06/19 00:18:35 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_3.dll
[2022/06/19 00:18:34 | 004,398,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_32.dll
[2022/06/19 00:18:34 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_32.dll
[2022/06/19 00:18:34 | 000,469,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10.dll
[2022/06/19 00:18:34 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10.dll
[2022/06/19 00:18:34 | 000,393,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_6.dll
[2022/06/19 00:18:34 | 000,390,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_5.dll
[2022/06/19 00:18:34 | 000,364,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_4.dll
[2022/06/19 00:18:34 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_6.dll
[2022/06/19 00:18:34 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_5.dll
[2022/06/19 00:18:34 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_4.dll
[2022/06/19 00:18:34 | 000,017,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\x3daudio1_1.dll
[2022/06/19 00:18:34 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_1.dll
[2022/06/19 00:18:33 | 003,977,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_31.dll
[2022/06/19 00:18:33 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_31.dll
[2022/06/19 00:18:33 | 000,363,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_3.dll
[2022/06/19 00:18:33 | 000,354,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_2.dll
[2022/06/19 00:18:33 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_3.dll
[2022/06/19 00:18:33 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_2.dll
[2022/06/19 00:18:33 | 000,083,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_2.dll
[2022/06/19 00:18:33 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_2.dll
[2022/06/19 00:18:32 | 003,927,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_30.dll
[2022/06/19 00:18:32 | 003,830,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_29.dll
[2022/06/19 00:18:32 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_30.dll
[2022/06/19 00:18:32 | 000,355,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_0.dll
[2022/06/19 00:18:32 | 000,352,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_1.dll
[2022/06/19 00:18:32 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_0.dll
[2022/06/19 00:18:32 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_1.dll
[2022/06/19 00:18:32 | 000,083,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_1.dll
[2022/06/19 00:18:32 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_1.dll
[2022/06/19 00:18:32 | 000,016,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\x3daudio1_0.dll
[2022/06/19 00:18:32 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_0.dll
[2022/06/19 00:18:31 | 003,823,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_25.dll
[2022/06/19 00:18:31 | 003,815,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_28.dll
[2022/06/19 00:18:31 | 003,807,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_27.dll
[2022/06/19 00:18:31 | 003,767,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_26.dll
[2022/06/19 00:18:31 | 003,544,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_24.dll
[2022/06/19 00:18:31 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_25.dll
[2022/06/19 00:18:31 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_28.dll
[2022/06/19 00:18:31 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_27.dll
[2022/06/19 00:18:31 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_26.dll
[2022/06/19 00:18:31 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_24.dll
[2022/06/19 00:17:43 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx
[2022/06/18 23:59:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
[2022/06/18 23:59:56 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Roaming\Mozilla
[2022/06/18 23:59:56 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\Mozilla
[2022/06/18 23:59:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2022/06/18 23:59:53 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2022/06/18 17:04:16 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\OneDrive
[2022/06/18 16:31:56 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\ESET
[2022/06/18 16:31:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2022/06/18 16:31:38 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET
[2022/06/18 16:31:38 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2022/06/18 16:22:52 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\CEF
[2022/06/18 16:17:40 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\Fujitsu_Client_Computing_
[2022/06/18 16:14:32 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\Corel
[2022/06/18 16:14:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Corel
[2022/06/18 16:12:37 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Roaming\Fujitsu
[2022/06/18 16:01:11 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\D3DSCache
[2022/06/18 15:54:14 | 000,000,000 | -H-D | C] -- C:\$WinREAgent
[2022/06/18 15:52:40 | 000,601,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sedplugins.dll
[2022/06/18 15:52:40 | 000,483,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\QualityUpdateAssistant.dll
[2022/06/18 15:52:40 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Logs
[2022/06/18 15:52:39 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Update Health Tools
[2022/06/18 15:51:28 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT
[2022/06/18 15:51:20 | 000,000,000 | ---D | C] -- C:\Program Files\PCHealthCheck
[2022/06/18 15:50:10 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\Comms
[2022/06/18 15:49:14 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\PlaceholderTileLogoFolder
[2022/06/18 15:46:47 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\OneDrive
[2022/06/18 15:45:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft OneDrive
[2022/06/18 15:45:39 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\Fujitsu
[2022/06/18 15:44:36 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Roaming\Ulead Systems
[2022/06/18 15:44:35 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\Publishers
[2022/06/18 15:44:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Packages
[2022/06/18 15:44:32 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\Documents\Corel Digital Studio SE
[2022/06/18 15:44:31 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2022/06/18 15:44:31 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\Searches
[2022/06/18 15:44:31 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\Contacts
[2022/06/18 15:44:31 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2022/06/18 15:44:31 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\3D Objects
[2022/06/18 15:44:31 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\Documents\Corel
[2022/06/18 15:44:30 | 000,000,000 | -H-D | C] -- C:\Users\ユーザー名\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2022/06/18 15:44:30 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\VirtualStore
[2022/06/18 15:44:30 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\Packages
[2022/06/18 15:44:30 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Roaming\Adobe
[2022/06/18 15:44:29 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\IntelGraphicsProfiles
[2022/06/18 15:44:29 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\ConnectedDevicesPlatform
[2022/06/18 15:40:39 | 000,000,000 | --SD | C] -- C:\Users\ユーザー名\AppData\Roaming\Microsoft
[2022/06/18 15:40:39 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\Videos
[2022/06/18 15:40:39 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2022/06/18 15:40:39 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\Saved Games
[2022/06/18 15:40:39 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\Pictures
[2022/06/18 15:40:39 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\Music
[2022/06/18 15:40:39 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\Links
[2022/06/18 15:40:39 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\Favorites
[2022/06/18 15:40:39 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\Downloads
[2022/06/18 15:40:39 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\Documents
[2022/06/18 15:40:39 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\Desktop
[2022/06/18 15:40:39 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2022/06/18 15:40:39 | 000,000,000 | R--D | C] -- C:\Users\ユーザー名\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
続く
  • Rid
  • 2022/06/28 (Tue) 23:29:04
OTL4
OTLログの続きです。
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\スタート メニュー
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\AppData\Local\Temporary Internet Files
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\Templates
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\SendTo
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\Recent
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\PrintHood
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\NetHood
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\Documents\My Videos
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\Documents\My Pictures
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\Documents\My Music
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\My Documents
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\Local Settings
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\AppData\Local\History
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\Cookies
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\Application Data
[2022/06/18 15:40:39 | 000,000,000 | -HSD | C] -- C:\Users\ユーザー名\AppData\Local\Application Data
[2022/06/18 15:40:39 | 000,000,000 | -H-D | C] -- C:\Users\ユーザー名\AppData
[2022/06/18 15:40:39 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
[2022/06/18 15:40:39 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\Temp
[2022/06/18 15:40:39 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Local\Microsoft
[2022/06/18 15:40:39 | 000,000,000 | ---D | C] -- C:\Users\ユーザー名\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2022/06/18 15:34:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\デスクトップ
[2022/06/18 15:34:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\スタート メニュー
[2022/06/18 15:34:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Templates
[2022/06/18 15:34:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\My Videos
[2022/06/18 15:34:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\My Pictures
[2022/06/18 15:34:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\My Music
[2022/06/18 15:34:04 | 000,000,000 | -HSD | C] -- C:\Documents and Settings
[2022/06/18 15:34:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Documents
[2022/06/18 15:34:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Application Data
[2022/06/18 15:28:07 | 002,877,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PrintConfig.dll
[2022/06/18 15:26:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2022/06/18 15:26:10 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2022/06/18 15:26:00 | 000,000,000 | ---D | C] -- C:\Intel
[2022/06/18 15:25:52 | 000,000,000 | --SD | C] -- C:\Windows\SysNative\Microsoft
[2022/06/18 15:25:52 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SleepStudy
[2022/06/18 15:25:52 | 000,000,000 | ---D | C] -- C:\Windows\ServiceProfiles
[2022/06/18 13:12:05 | 000,000,000 | ---D | C] -- C:\Fujitsu
[2022/06/18 10:12:38 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2022/06/18 10:08:54 | 000,000,000 | ---D | C] -- C:\Windows\Firmware
[2022/06/18 10:08:20 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Intel
[2022/06/18 10:08:20 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\cAVS
[2022/06/18 10:05:42 | 000,000,000 | ---D | C] -- C:\Windows\Setup
[2022/06/18 10:05:28 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\XPSViewer
[2022/06/18 10:05:28 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\OpenSSH
[2022/06/18 10:05:28 | 000,000,000 | ---D | C] -- C:\Windows\OCR
[2022/06/18 10:05:28 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\MailContactsCalendarSync
[2022/06/18 10:05:28 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MailContactsCalendarSync
[2022/06/18 10:05:28 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\FxsTmp
[2022/06/18 10:05:28 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\FxsTmp
[2022/06/18 10:05:27 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
[2022/06/18 10:05:27 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2022/06/18 10:05:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Media Player
[2022/06/18 10:05:27 | 000,000,000 | ---D | C] -- C:\ProgramData\ssh
[2022/06/18 10:05:27 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2022/06/18 10:05:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies
[2022/06/18 10:05:27 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2022/06/18 10:05:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
[2022/06/18 10:05:27 | 000,000,000 | ---D | C] -- C:\Windows\addins
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\winrm
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\winrm
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\WCN
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\WCN
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\UMDF
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\sysprep
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\slmgr
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\slmgr
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Printing_Admin_Scripts
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Printing_Admin_Scripts
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\ja-JP
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ja
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ja
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\UMDF\en-US
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\en-US
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\en
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\en
[2022/06/18 10:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\0409
[2022/06/18 10:05:10 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\UMDF\ja-JP
[2022/06/18 10:05:10 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\ja-JP
[2022/06/18 10:05:10 | 000,000,000 | ---D | C] -- C:\Windows\ja-JP
[2022/06/18 10:05:10 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\UMDF\en-US
[2022/06/18 10:05:10 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\en-US
[2022/06/18 10:05:10 | 000,000,000 | ---D | C] -- C:\Windows\en-US
[2022/06/18 10:05:10 | 000,000,000 | ---D | C] -- C:\Windows\DigitalLocker
[2022/06/18 10:05:10 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0409
[2022/06/18 10:04:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft
[2022/06/18 10:03:42 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msclmd.dll
[2022/06/18 10:03:40 | 000,230,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msclmd.dll
[2022/06/18 10:03:40 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OEMDefaultAssociations.dll
[2022/06/18 10:03:38 | 000,000,000 | --SD | C] -- C:\Windows\SysNative\UNP
[2022/06/18 10:03:38 | 000,000,000 | --SD | C] -- C:\Windows\SysWow64\Nui
[2022/06/18 10:03:38 | 000,000,000 | --SD | C] -- C:\Windows\SysNative\Nui
[2022/06/18 10:03:38 | 000,000,000 | --SD | C] -- C:\Windows\SysWow64\F12
[2022/06/18 10:03:38 | 000,000,000 | --SD | C] -- C:\Windows\SysNative\F12
[2022/06/18 10:03:38 | 000,000,000 | --SD | C] -- C:\Windows\SysNative\dsc
[2022/06/18 10:03:38 | 000,000,000 | --SD | C] -- C:\Windows\SysWow64\DiagSvcs
[2022/06/18 10:03:38 | 000,000,000 | --SD | C] -- C:\Windows\SysNative\DiagSvcs
[2022/06/18 10:03:38 | 000,000,000 | --SD | C] -- C:\Windows\SysWow64\Configuration
[2022/06/18 10:03:38 | 000,000,000 | --SD | C] -- C:\Windows\SysNative\Configuration
[2022/06/18 10:03:38 | 000,000,000 | R--D | C] -- C:\Windows\PrintDialog
[2022/06/18 10:03:38 | 000,000,000 | R--D | C] -- C:\Windows\Offline Web Pages
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\zh-TW
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\zh-TW
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\zh-CN
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\zh-CN
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\WinMetadata
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\WinMetadata
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\winevt
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\WindowsPowerShell
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\WindowsPowerShell
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\WinBioPlugIns
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\WinBioDatabase
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\Web
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\WDI
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\wbem
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\wbem
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\WaaS
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\Vss
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\uk-UA
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\uk-UA
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\twain_32
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\tr-TR
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\tr-TR
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\tracing
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ti-et
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\th-TH
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\th-TH
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\Temp
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Tasks
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Tasks
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\TAPI
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ta-lk
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ta-in
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWOW64
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SystemTemp
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SystemResources
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SystemResetPlatform
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SystemApps
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\System
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\sv-SE
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\sv-SE
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\sru
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\sru
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\sr-Latn-RS
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\sr-Latn-RS
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\sppui
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\sppui
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\spp
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\spp
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\spool
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Speech_OneCore
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Speech_OneCore
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\Speech_OneCore
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Speech
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\System\Speech
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Speech
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\Speech
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\SMI
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\sl-SI
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\sl-SI
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\sk-SK
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\sk-SK
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SKB
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\si-lk
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ShellExperiences
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\ShellExperiences
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\ShellComponents
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Sgrm
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\setup
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\setup
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\ServiceState
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\security
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SecureBootUpdates
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\schemas
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SchCache
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ru-RU
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ru-RU
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ro-RO
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ro-RO
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\restore
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\restore
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\Resources
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\rescache
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\Registration
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Recovery
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Recovery
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RasToast
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\RasToast
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ras
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ras
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\pt-PT
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\pt-PT
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\pt-BR
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\pt-BR
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ProximityToast
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\Provisioning
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\prefetch
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\PolicyDefinitions
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\PointOfService
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\pl-PL
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\pl-PL
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\PLA
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\Performance
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\PerceptionSimulation
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\PerceptionSimulation
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\osa-Osge-001
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\oobe
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\oobe
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\nl-NL
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\nl-NL
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\networklist
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\networklist
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\NDF
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\NDF
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\nb-NO
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\nb-NO
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\my-mm
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\MUI
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MUI
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Msdtc
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\MSDRM
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MSDRM
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\ModemLogs
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\migwiz
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\migwiz
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\migration
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\migration
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\Migration
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\lv-LV
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\lv-LV
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\lt-LT
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\lt-LT
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\LogFiles
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\LogFiles
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Licenses
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Licenses
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ko-KR
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ko-KR
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Keywords
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Keywords
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ja-JP
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ja-jp
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\it-IT
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\it-IT
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Ipmi
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Ipmi
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\InstallShield
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\InputMethod
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\InputMethod
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\inetsrv
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\inetsrv
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\IME
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\IME
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\icsxml
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\icsxml
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Hydrogen
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\hu-HU
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\hu-HU
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\hr-HR
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\hr-HR
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\he-IL
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\he-IL
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\GroupPolicyUsers
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\GroupPolicy
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\fr-FR
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\fr-FR
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\fr-CA
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\fr-CA
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\fi-FI
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\fi-FI
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ff-Adlm-SN
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\et-EE
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\et-EE
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\etc
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\es-MX
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\es-MX
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\es-ES
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\es-ES
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\en-US
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\en-US
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\en-GB
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\en-GB
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\el-GR
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\el-GR
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\DriverStore
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DriverState
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\DriverData
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\downlevel
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\downlevel
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Dism
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Dism
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\de-DE
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\de-DE
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DDFs
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\da-DK
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\da-DK
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\cs-CZ
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\cs-CZ
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ContainerSettingsProviders
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\config
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Com
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Com
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\CodeIntegrity
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\catroot2
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\catroot
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Bthprops
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Bthprops
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Boot
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\bg-BG
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\bg-BG
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ar-SA
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ar-SA
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appraiser
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\AppLocker
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\AppLocker
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\am-et
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\AdvancedInstallers
[2022/06/18 10:03:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\AdvancedInstallers
[2022/06/18 10:03:37 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft
[2022/06/18 10:03:37 | 000,000,000 | --SD | C] -- C:\Windows\Downloaded Program Files
[2022/06/18 10:03:37 | 000,000,000 | R-SD | C] -- C:\Windows\Media
[2022/06/18 10:03:37 | 000,000,000 | R-SD | C] -- C:\Windows\Fonts
[2022/06/18 10:03:37 | 000,000,000 | R-SD | C] -- C:\Windows\assembly
[2022/06/18 10:03:37 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
[2022/06/18 10:03:37 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
[2022/06/18 10:03:37 | 000,000,000 | R--D | C] -- C:\Program Files
[2022/06/18 10:03:37 | 000,000,000 | R--D | C] -- C:\Program Files (x86)
[2022/06/18 10:03:37 | 000,000,000 | R--D | C] -- C:\Windows\Microsoft.NET
[2022/06/18 10:03:37 | 000,000,000 | R--D | C] -- C:\Windows\ImmersiveControlPanel
[2022/06/18 10:03:37 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2022/06/18 10:03:37 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
[2022/06/18 10:03:37 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
[2022/06/18 10:03:37 | 000,000,000 | -HSD | C] -- C:\Program Files\Windows Sidebar
[2022/06/18 10:03:37 | 000,000,000 | -HSD | C] -- C:\Program Files (x86)\Windows Sidebar
[2022/06/18 10:03:37 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2022/06/18 10:03:37 | 000,000,000 | -HSD | C] -- C:\$Recycle.Bin
[2022/06/18 10:03:37 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsApps
[2022/06/18 10:03:37 | 000,000,000 | -H-D | C] -- C:\ProgramData
[2022/06/18 10:03:37 | 000,000,000 | -H-D | C] -- C:\Windows\LanguageOverlayCache
[2022/06/18 10:03:37 | 000,000,000 | -H-D | C] -- C:\Windows\ELAMBKUP
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\WindowsPowerShell
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WindowsPowerShell
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsHolographicDevices
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Security
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Portable Devices
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Photo Viewer
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Photo Viewer
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\Windows NT
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows NT
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Multimedia Platform
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Multimedia Platform
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Mail
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Mail
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Defender
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Defender
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\ProgramData\USOShared
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\ProgramData\USOPrivate
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\System
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\System
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Sysprep
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\ProgramData\SoftwareDistribution
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Services
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1991-06.com.microsoft
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\PerfLogs
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\ModifiableWindowsApps
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\microsoft shared
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Microsoft Shared
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\Logs
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\LiveKernelReports
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\L2Schemas
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Explorer
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Internet Explorer
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\InputMethod
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\IME
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\IdentityCRL
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\Help
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\Globalization
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\GameBarPresenceWriter
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\DiagTrack
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\diagnostics
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\debug
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\Cursors
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\Containers
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\Branding
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\Boot
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\bcastdvr
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\AppReadiness
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\apppatch
[2022/06/18 10:03:37 | 000,000,000 | ---D | C] -- C:\Windows\appcompat
[2022/06/18 10:03:20 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\UMDF
[2022/06/18 10:03:20 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers
[2022/06/18 10:02:48 | 000,000,000 | ---D | C] -- C:\Windows\INF
[2022/06/18 10:00:34 | 000,000,000 | ---D | C] -- C:\Windows\CbsTemp
[2022/06/18 10:00:12 | 000,000,000 | R--D | C] -- C:\Users
[2022/06/18 10:00:12 | 000,000,000 | ---D | C] -- C:\Windows\WinSxS
[2022/06/18 10:00:12 | 000,000,000 | ---D | C] -- C:\Windows
[2022/06/18 10:00:12 | 000,000,000 | ---D | C] -- C:\Windows\System32
[2022/06/18 10:00:12 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SMI
[2022/06/18 10:00:12 | 000,000,000 | ---D | C] -- C:\Windows\servicing
[2022/06/18 10:00:12 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DriverStore
[2022/06/18 10:00:12 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\config
[2022/06/18 10:00:12 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\CatRoot
[2022/06/18 09:59:01 | 000,000,000 | -H-D | C] -- C:\$SysReset
[2022/06/15 21:42:35 | 004,407,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdp.dll
[2022/06/15 21:42:35 | 000,351,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fveui.dll
[2022/06/15 21:42:35 | 000,183,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SystemSettings.DeviceEncryptionHandlers.dll
[2022/06/15 21:42:35 | 000,178,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BitLockerDeviceEncryption.exe
[2022/06/15 21:42:35 | 000,095,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dumpfve.sys
[2022/06/15 21:42:35 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BdeUISrv.exe
[2022/06/15 21:42:31 | 004,998,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdp.dll
[2022/06/15 21:42:31 | 000,201,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\notepad.exe
[2022/06/15 21:42:26 | 000,961,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DolbyDecMFT.dll
[2022/06/15 21:42:26 | 000,801,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSMPEG2ENC.DLL
[2022/06/15 21:42:25 | 005,357,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Media.dll
[2022/06/15 21:42:25 | 003,560,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfcore.dll
[2022/06/15 21:42:25 | 001,136,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DolbyDecMFT.dll
[2022/06/15 21:42:25 | 001,092,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\HoloSI.PCShell.dll
[2022/06/15 21:42:25 | 000,488,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\HolographicRuntimes.dll
[2022/06/15 21:42:25 | 000,421,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MixedReality.Broker.dll
[2022/06/15 21:42:25 | 000,130,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll
[2022/06/15 21:42:24 | 024,272,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Hydrogen.dll
[2022/06/15 21:42:23 | 007,550,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Media.dll
[2022/06/15 21:42:23 | 002,520,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2vdec.dll
[2022/06/15 21:42:23 | 000,944,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSMPEG2ENC.DLL
[2022/06/15 21:42:23 | 000,848,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\HolographicExtensions.dll
[2022/06/15 21:42:23 | 000,561,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DMRServer.dll
[2022/06/15 21:42:23 | 000,268,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2022/06/15 21:42:22 | 007,122,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2022/06/15 21:42:22 | 004,799,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfcore.dll
[2022/06/15 21:42:22 | 003,380,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Mirage.dll
[2022/06/15 21:42:22 | 001,345,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsp_health.dll
[2022/06/15 21:42:22 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdt.exe
[2022/06/15 21:42:22 | 000,273,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\provplatformdesktop.dll
[2022/06/15 21:42:22 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\provmigrate.dll
[2022/06/15 21:42:22 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AcWinRT.dll
[2022/06/15 21:42:22 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\provisioningcommandscsp.dll
[2022/06/15 21:42:22 | 000,054,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
[2022/06/15 21:42:22 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\provlaunch.exe
[2022/06/15 21:42:21 | 001,542,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsp_fs.dll
[2022/06/15 21:42:21 | 001,075,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpcore.dll
[2022/06/15 21:42:21 | 000,924,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\opengl32.dll
[2022/06/15 21:42:21 | 000,617,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll
[2022/06/15 21:42:21 | 000,604,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbc32.dll
[2022/06/15 21:42:21 | 000,399,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tracerpt.exe
[2022/06/15 21:42:21 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieproxy.dll
[2022/06/15 21:42:21 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\glu32.dll
[2022/06/15 21:42:21 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\logman.exe
[2022/06/15 21:42:21 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsiwmiv2.dll
[2022/06/15 21:42:21 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsiwmi.dll
[2022/06/15 21:42:21 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iemigplugin.dll
[2022/06/15 21:42:21 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsidsc.dll
[2022/06/15 21:42:21 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\relog.exe
[2022/06/15 21:42:21 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsicli.exe
[2022/06/15 21:42:21 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\typeperf.exe
[2022/06/15 21:42:21 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsium.dll
[2022/06/15 21:42:21 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msimsg.dll
[2022/06/15 21:42:21 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\diskperf.exe
[2022/06/15 21:42:21 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsied.dll
[2022/06/15 21:42:20 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IndexedDbLegacy.dll
[2022/06/15 21:42:18 | 019,865,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\edgehtml.dll
[2022/06/15 21:42:18 | 000,464,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxdiagn.dll
[2022/06/15 21:42:18 | 000,443,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2022/06/15 21:42:18 | 000,231,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\GameBarPresenceWriter.exe
[2022/06/15 21:42:18 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Robocopy.exe
[2022/06/15 21:42:18 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dataclen.dll
[2022/06/15 21:42:18 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\GameBarPresenceWriter.proxy.dll
[2022/06/15 21:42:17 | 000,170,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wslapi.dll
[2022/06/15 21:42:16 | 004,374,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Mirage.dll
[2022/06/15 21:42:16 | 000,877,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Spectrum.exe
[2022/06/15 21:42:16 | 000,867,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Mirage.Internal.dll
[2022/06/15 21:42:16 | 000,416,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\provplatformdesktop.dll
[2022/06/15 21:42:16 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SharedRealitySvc.dll
[2022/06/15 21:42:16 | 000,304,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icsvcext.dll
[2022/06/15 21:42:16 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdsdwmdr.dll
[2022/06/15 21:42:16 | 000,120,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\vmbkmcl.sys
[2022/06/15 21:42:16 | 000,119,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mgmtrefreshcredprov.dll
[2022/06/15 21:42:16 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\provmigrate.dll
[2022/06/15 21:42:16 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\provisioningcommandscsp.dll
[2022/06/15 21:42:16 | 000,071,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
[2022/06/15 21:42:16 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AcWinRT.dll
[2022/06/15 21:42:16 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\provlaunch.exe
[2022/06/15 21:42:15 | 008,252,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2022/06/15 21:42:14 | 000,496,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdt.exe
[2022/06/15 21:42:11 | 002,430,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ResetEngine.dll
[2022/06/15 21:42:11 | 002,031,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsp_fs.dll
[2022/06/15 21:42:11 | 001,763,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsp_health.dll
[2022/06/15 21:42:11 | 001,638,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll
[2022/06/15 21:42:11 | 001,287,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcore.dll
[2022/06/15 21:42:11 | 000,545,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nltest.exe
[2022/06/15 21:42:11 | 000,098,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpudd.dll
[2022/06/15 21:42:11 | 000,032,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2022/06/15 21:42:10 | 003,336,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2022/06/15 21:42:10 | 001,953,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mmc.exe
[2022/06/15 21:42:10 | 001,065,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\opengl32.dll
[2022/06/15 21:42:10 | 000,793,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll
[2022/06/15 21:42:10 | 000,724,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbc32.dll
[2022/06/15 21:42:10 | 000,532,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IESettingSync.exe
[2022/06/15 21:42:10 | 000,485,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DscCore.dll
[2022/06/15 21:42:10 | 000,463,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tracerpt.exe
[2022/06/15 21:42:10 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\glu32.dll
[2022/06/15 21:42:10 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sendmail.dll
[2022/06/15 21:42:10 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iscsiwmiv2.dll
[2022/06/15 21:42:10 | 000,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\logman.exe
[2022/06/15 21:42:10 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iscsiwmi.dll
[2022/06/15 21:42:10 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iscsidsc.dll
[2022/06/15 21:42:10 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iemigplugin.dll
[2022/06/15 21:42:10 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\relog.exe
[2022/06/15 21:42:10 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iscsicli.exe
[2022/06/15 21:42:10 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\typeperf.exe
[2022/06/15 21:42:10 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iscsium.dll
[2022/06/15 21:42:10 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msimsg.dll
[2022/06/15 21:42:10 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diskperf.exe
[2022/06/15 21:42:10 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iscsied.dll
[2022/06/15 21:42:09 | 000,929,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieproxy.dll
[2022/06/15 21:42:09 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IndexedDbLegacy.dll
続く
  • Rid
  • 2022/06/28 (Tue) 23:30:32
OTL5
OTLログの続きです。
[2022/06/15 21:42:06 | 026,268,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\edgehtml.dll
[2022/06/15 21:42:06 | 000,559,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2022/06/15 21:42:06 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\StorageUsage.dll
[2022/06/15 21:42:05 | 000,678,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\computecore.dll
[2022/06/15 21:42:05 | 000,565,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxdiagn.dll
[2022/06/15 21:42:05 | 000,308,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\computestorage.dll
[2022/06/15 21:42:05 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vmdevicehost.dll
[2022/06/15 21:42:05 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Robocopy.exe
[2022/06/15 21:42:05 | 000,134,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinHvPlatform.dll
[2022/06/15 21:42:05 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dataclen.dll
[2022/06/15 21:42:03 | 001,573,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hvix64.exe
[2022/06/15 21:42:03 | 001,270,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hvax64.exe
[2022/06/15 21:42:03 | 000,922,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\securekernel.exe
[2022/06/15 21:42:03 | 000,809,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tcblaunch.exe
[2022/06/15 21:42:03 | 000,502,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ucrtbase_enclave.dll
[2022/06/15 21:42:03 | 000,342,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\GameBarPresenceWriter.exe
[2022/06/15 21:42:03 | 000,307,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\skci.dll
[2022/06/15 21:42:03 | 000,223,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tcbloader.dll
[2022/06/15 21:42:03 | 000,173,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vertdll.dll
[2022/06/15 21:42:03 | 000,119,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hvloader.dll
[2022/06/15 21:42:03 | 000,096,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hvservice.sys
[2022/06/15 21:42:03 | 000,026,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iumbase.dll
[2022/06/15 21:42:03 | 000,022,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdhvcom.dll
[2022/06/15 21:42:03 | 000,016,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iumdll.dll
[2022/06/15 21:42:03 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\GameBarPresenceWriter.proxy.dll
[2022/06/15 21:42:02 | 000,436,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mprapi.dll
[2022/06/15 21:42:02 | 000,354,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\LockAppBroker.dll
[2022/06/15 21:42:02 | 000,331,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AboveLockAppHost.dll
[2022/06/15 21:42:02 | 000,212,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prnfldr.dll
[2022/06/15 21:42:02 | 000,150,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twext.dll
[2022/06/15 21:42:02 | 000,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netid.dll
[2022/06/15 21:42:02 | 000,068,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SortWindows64.dll
[2022/06/15 21:42:01 | 008,902,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Media.Protection.PlayReady.dll
[2022/06/15 21:42:01 | 000,402,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\edgeIso.dll
[2022/06/15 21:42:01 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wusa.exe
[2022/06/15 21:42:01 | 000,271,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msIso.dll
[2022/06/15 21:42:00 | 000,896,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gdi32full.dll
[2022/06/15 21:42:00 | 000,885,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdh.dll
[2022/06/15 21:42:00 | 000,556,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dmenrollengine.dll
[2022/06/15 21:42:00 | 000,532,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\policymanager.dll
[2022/06/15 21:42:00 | 000,164,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dmcmnutils.dll
[2022/06/15 21:42:00 | 000,111,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rekeywiz.exe
[2022/06/15 21:42:00 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\enrollmentapi.dll
[2022/06/15 21:42:00 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\userinitext.dll
[2022/06/15 21:41:59 | 002,753,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32kfull.sys
[2022/06/15 21:41:59 | 002,630,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\combase.dll
[2022/06/15 21:41:59 | 001,651,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winmsipc.dll
[2022/06/15 21:41:59 | 001,450,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dcomp.dll
[2022/06/15 21:41:59 | 000,800,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winipcsecproc.dll
[2022/06/15 21:41:59 | 000,508,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\daxexec.dll
[2022/06/15 21:41:59 | 000,446,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mmsys.cpl
[2022/06/15 21:41:59 | 000,355,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winipcfile.dll
[2022/06/15 21:41:59 | 000,329,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32k.sys
[2022/06/15 21:41:59 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SndVolSSO.dll
[2022/06/15 21:41:59 | 000,226,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SndVol.exe
[2022/06/15 21:41:59 | 000,203,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UserMgrProxy.dll
[2022/06/15 21:41:59 | 000,188,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ocsetapi.dll
[2022/06/15 21:41:59 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wincredui.dll
[2022/06/15 21:41:59 | 000,114,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CredentialUIBroker.exe
[2022/06/15 21:41:59 | 000,094,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32u.dll
[2022/06/15 21:41:59 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\userinit.exe
[2022/06/15 21:41:58 | 006,374,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\windows.storage.dll
[2022/06/15 21:41:58 | 001,611,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpserverbase.dll
[2022/06/15 21:41:58 | 000,968,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\InputHost.dll
[2022/06/15 21:41:58 | 000,754,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TextInputFramework.dll
[2022/06/15 21:41:58 | 000,702,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Core.TextInput.dll
[2022/06/15 21:41:58 | 000,448,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ttdrecord.dll
[2022/06/15 21:41:58 | 000,276,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Devices.Lights.dll
[2022/06/15 21:41:58 | 000,213,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ttdinject.exe
[2022/06/15 21:41:58 | 000,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fidocredprov.dll
[2022/06/15 21:41:58 | 000,151,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Energy.dll
[2022/06/15 21:41:58 | 000,072,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tttracer.exe
[2022/06/15 21:41:58 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EditBufferTestHook.dll
[2022/06/15 21:41:58 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WordBreakers.dll
[2022/06/15 21:41:57 | 002,607,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tquery.dll
[2022/06/15 21:41:57 | 002,538,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAutomationCore.dll
[2022/06/15 21:41:57 | 002,315,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssrch.dll
[2022/06/15 21:41:57 | 001,965,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll
[2022/06/15 21:41:57 | 001,011,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CloudExperienceHostCommon.dll
[2022/06/15 21:41:57 | 000,878,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ShareHost.dll
[2022/06/15 21:41:57 | 000,653,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ActivationManager.dll
[2022/06/15 21:41:57 | 000,554,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d9on12.dll
[2022/06/15 21:41:57 | 000,303,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssvp.dll
[2022/06/15 21:41:57 | 000,286,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Search.ProtocolHandler.MAPI2.dll
[2022/06/15 21:41:57 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssph.dll
[2022/06/15 21:41:57 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssitlb.dll
[2022/06/15 21:41:57 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ApiSetHost.AppExecutionAlias.dll
[2022/06/15 21:41:57 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\crypttpmeksvc.dll
[2022/06/15 21:41:57 | 000,062,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\GameInput.dll
[2022/06/15 21:41:57 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscntrs.dll
[2022/06/15 21:41:56 | 014,778,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Xaml.dll
[2022/06/15 21:41:56 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mapistub.dll
[2022/06/15 21:41:56 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\LaunchWinApp.exe
[2022/06/15 21:41:56 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fixmapi.exe
[2022/06/15 21:41:55 | 004,748,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.dll
[2022/06/15 21:41:55 | 004,493,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe
[2022/06/15 21:41:55 | 000,941,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TpmCoreProvisioning.dll
[2022/06/15 21:41:55 | 000,641,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\LicensingWinRT.dll
[2022/06/15 21:41:55 | 000,512,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinapi.dll
[2022/06/15 21:41:55 | 000,430,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\InputSwitch.dll
[2022/06/15 21:41:55 | 000,350,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2022/06/15 21:41:55 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sppcomapi.dll
[2022/06/15 21:41:55 | 000,250,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PkgMgr.exe
[2022/06/15 21:41:55 | 000,214,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EditionUpgradeManagerObj.dll
[2022/06/15 21:41:55 | 000,165,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EditionUpgradeHelper.dll
[2022/06/15 21:41:55 | 000,153,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RTWorkQ.dll
[2022/06/15 21:41:55 | 000,070,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DeviceReactivation.dll
[2022/06/15 21:41:55 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DmApiSetExtImplDesktop.dll
[2022/06/15 21:41:54 | 006,190,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.dll
[2022/06/15 21:41:54 | 002,240,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\windowsudk.shellcommon.dll
[2022/06/15 21:41:54 | 000,766,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2022/06/15 21:41:54 | 000,669,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinapi.dll
[2022/06/15 21:41:54 | 000,479,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CoreShellAPI.dll
[2022/06/15 21:41:54 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PkgMgr.exe
[2022/06/15 21:41:54 | 000,159,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mapistub.dll
[2022/06/15 21:41:54 | 000,159,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mapi32.dll
[2022/06/15 21:41:54 | 000,059,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sfc_os.dll
[2022/06/15 21:41:54 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LaunchWinApp.exe
[2022/06/15 21:41:54 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fixmapi.exe
[2022/06/15 21:41:54 | 000,012,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sfc.dll
[2022/06/15 21:41:53 | 000,847,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsm.dll
[2022/06/15 21:41:53 | 000,737,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vpnike.dll
[2022/06/15 21:41:53 | 000,540,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\InputSwitch.dll
[2022/06/15 21:41:53 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mprapi.dll
[2022/06/15 21:41:53 | 000,412,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFolder.dll
[2022/06/15 21:41:52 | 004,677,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setupapi.dll
[2022/06/15 21:41:52 | 003,945,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingsHandlers_nt.dll
[2022/06/15 21:41:52 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tcpmon.dll
[2022/06/15 21:41:52 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingsHandlers_Gpu.dll
[2022/06/15 21:41:52 | 000,239,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prnfldr.dll
[2022/06/15 21:41:52 | 000,181,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netid.dll
[2022/06/15 21:41:51 | 003,904,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentServer.dll
[2022/06/15 21:41:51 | 002,461,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.onecore.dll
[2022/06/15 21:41:51 | 001,769,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.desktop.dll
[2022/06/15 21:41:51 | 001,207,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ApplyTrustOffline.exe
[2022/06/15 21:41:51 | 001,023,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Facilitator.dll
[2022/06/15 21:41:51 | 000,210,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXApplicabilityBlob.dll
[2022/06/15 21:41:51 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CustomInstallExec.exe
[2022/06/15 21:41:50 | 000,457,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LockHostingFramework.dll
[2022/06/15 21:41:50 | 000,455,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LockAppBroker.dll
[2022/06/15 21:41:50 | 000,448,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\edgeIso.dll
[2022/06/15 21:41:50 | 000,339,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msIso.dll
[2022/06/15 21:41:50 | 000,074,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SortWindows64.dll
[2022/06/15 21:41:50 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\userinitext.dll
[2022/06/15 21:41:49 | 002,142,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MdmDiagnostics.dll
[2022/06/15 21:41:49 | 002,028,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LocationFramework.dll
[2022/06/15 21:41:49 | 001,874,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d9.dll
[2022/06/15 21:41:49 | 001,793,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\enterprisecsps.dll
[2022/06/15 21:41:49 | 001,127,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdh.dll
[2022/06/15 21:41:49 | 000,681,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dmenrollengine.dll
[2022/06/15 21:41:49 | 000,647,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\policymanager.dll
[2022/06/15 21:41:49 | 000,545,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DMPushRouterCore.dll
[2022/06/15 21:41:49 | 000,432,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\omadmclient.exe
[2022/06/15 21:41:49 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mdmmigrator.dll
[2022/06/15 21:41:49 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rekeywiz.exe
[2022/06/15 21:41:49 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\enrollmentapi.dll
[2022/06/15 21:41:49 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DmOmaCpMo.exe
[2022/06/15 21:41:49 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d8thk.dll
[2022/06/15 21:41:48 | 001,088,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pidgenx.dll
[2022/06/15 21:41:48 | 000,889,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pidgenx.dll
[2022/06/15 21:41:48 | 000,757,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LicensingWinRT.dll
[2022/06/15 21:41:48 | 000,547,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\slui.exe
[2022/06/15 21:41:48 | 000,316,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppcomapi.dll
[2022/06/15 21:41:48 | 000,241,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EditionUpgradeManagerObj.dll
[2022/06/15 21:41:48 | 000,229,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dmcmnutils.dll
[2022/06/15 21:41:48 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wincredui.dll
[2022/06/15 21:41:48 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dmcsps.dll
[2022/06/15 21:41:48 | 000,179,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EditionUpgradeHelper.dll
[2022/06/15 21:41:48 | 000,149,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CredentialUIBroker.exe
[2022/06/15 21:41:48 | 000,093,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DeviceReactivation.dll
[2022/06/15 21:41:48 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll
[2022/06/15 21:41:47 | 001,483,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usermgr.dll
[2022/06/15 21:41:47 | 001,129,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msctf.dll
[2022/06/15 21:41:47 | 001,127,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSyncCore.dll
[2022/06/15 21:41:47 | 000,969,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSyncHost.exe
[2022/06/15 21:41:47 | 000,909,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
[2022/06/15 21:41:47 | 000,858,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comdlg32.dll
[2022/06/15 21:41:47 | 000,489,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntshrui.dll
[2022/06/15 21:41:47 | 000,415,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\clfs.sys
[2022/06/15 21:41:47 | 000,373,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.FileExplorer.Common.dll
[2022/06/15 21:41:47 | 000,323,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UserMgrProxy.dll
[2022/06/15 21:41:47 | 000,274,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.FileExplorer.dll
[2022/06/15 21:41:47 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twext.dll
[2022/06/15 21:41:46 | 002,946,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2022/06/15 21:41:46 | 000,329,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NetSetupSvc.dll
[2022/06/15 21:41:45 | 010,849,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2022/06/15 21:41:45 | 002,027,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2022/06/15 21:41:45 | 000,018,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hal.dll
[2022/06/15 21:41:44 | 003,819,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diagtrack.dll
[2022/06/15 21:41:44 | 001,658,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2022/06/15 21:41:44 | 000,327,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wldap32.dll
[2022/06/15 21:41:44 | 000,136,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\offlinelsa.dll
[2022/06/15 21:41:44 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\userinit.exe
[2022/06/15 21:41:43 | 003,503,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\combase.dll
[2022/06/15 21:41:43 | 000,924,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll
[2022/06/15 21:41:42 | 001,974,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dcomp.dll
[2022/06/15 21:41:42 | 001,828,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2022/06/15 21:41:42 | 001,561,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2022/06/15 21:41:42 | 001,396,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2022/06/15 21:41:42 | 001,200,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe
[2022/06/15 21:41:42 | 001,009,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\uDWM.dll
[2022/06/15 21:41:42 | 000,498,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\cldflt.sys
[2022/06/15 21:41:42 | 000,202,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ocsetapi.dll
[2022/06/15 21:41:41 | 002,008,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\refs.sys
[2022/06/15 21:41:41 | 000,544,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mmsys.cpl
[2022/06/15 21:41:41 | 000,309,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SndVolSSO.dll
[2022/06/15 21:41:41 | 000,276,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SndVol.exe
[2022/06/15 21:41:40 | 001,208,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NotificationController.dll
[2022/06/15 21:41:40 | 000,866,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ShellAppRuntime.exe
[2022/06/15 21:41:40 | 000,379,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NotificationControllerPS.dll
[2022/06/15 21:41:39 | 006,417,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.pcshell.dll
[2022/06/15 21:41:39 | 004,009,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SystemSettingsThresholdAdminFlowUI.dll
[2022/06/15 21:41:39 | 002,622,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UpdateAgent.dll
[2022/06/15 21:41:39 | 000,519,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SystemSettingsAdminFlows.exe
[2022/06/15 21:41:39 | 000,230,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\convertvhd.exe
[2022/06/15 21:41:38 | 001,680,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MoUsoCoreWorker.exe
[2022/06/15 21:41:38 | 001,413,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usocoreworker.exe
[2022/06/15 21:41:38 | 001,163,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MusUpdateHandlers.dll
[2022/06/15 21:41:38 | 000,700,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SHCore.dll
[2022/06/15 21:41:38 | 000,692,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MusNotification.exe
[2022/06/15 21:41:38 | 000,630,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MusNotificationUx.exe
[2022/06/15 21:41:38 | 000,570,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usosvc.dll
[2022/06/15 21:41:37 | 003,814,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32kfull.sys
[2022/06/15 21:41:37 | 003,760,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Microsoft.Bluetooth.Service.dll
[2022/06/15 21:41:37 | 002,343,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winmsipc.dll
[2022/06/15 21:41:37 | 001,856,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpserverbase.dll
[2022/06/15 21:41:37 | 000,904,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winipcsecproc.dll
[2022/06/15 21:41:37 | 000,686,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\daxexec.dll
[2022/06/15 21:41:37 | 000,601,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EnterpriseAppMgmtSvc.dll
[2022/06/15 21:41:37 | 000,513,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winipcfile.dll
[2022/06/15 21:41:37 | 000,392,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Devices.Lights.dll
[2022/06/15 21:41:37 | 000,303,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UMDF\IddCx.dll
[2022/06/15 21:41:37 | 000,181,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wfplwfs.sys
[2022/06/15 21:41:37 | 000,145,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\bindflt.sys
[2022/06/15 21:41:37 | 000,133,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32u.dll
[2022/06/15 21:41:37 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bindfltapi.dll
[2022/06/15 21:41:37 | 000,093,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wcnfs.sys
[2022/06/15 21:41:37 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dumpsdport.sys
[2022/06/15 21:41:36 | 001,004,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\propsys.dll
[2022/06/15 21:41:36 | 000,506,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL
[2022/06/15 21:41:36 | 000,412,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2022/06/15 21:41:36 | 000,203,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Storage.OneCore.dll
[2022/06/15 21:41:36 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fwmdmcsp.dll
[2022/06/15 21:41:35 | 007,984,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\windows.storage.dll
[2022/06/15 21:41:35 | 002,250,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ISM.dll
[2022/06/15 21:41:35 | 001,554,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UserDataService.dll
[2022/06/15 21:41:35 | 001,191,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Unistore.dll
[2022/06/15 21:41:35 | 001,145,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EmailApis.dll
[2022/06/15 21:41:35 | 000,648,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ttdrecord.dll
[2022/06/15 21:41:35 | 000,333,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PushToInstall.dll
[2022/06/15 21:41:35 | 000,283,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ttdinject.exe
[2022/06/15 21:41:35 | 000,236,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fidocredprov.dll
[2022/06/15 21:41:35 | 000,196,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PimIndexMaintenance.dll
[2022/06/15 21:41:35 | 000,086,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tttracer.exe
[2022/06/15 21:41:34 | 004,731,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\InputService.dll
[2022/06/15 21:41:34 | 003,308,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tquery.dll
[2022/06/15 21:41:34 | 001,379,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\InputHost.dll
[2022/06/15 21:41:34 | 001,039,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Core.TextInput.dll
[2022/06/15 21:41:34 | 001,015,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TextInputFramework.dll
[2022/06/15 21:41:34 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\InputLocaleManager.dll
[2022/06/15 21:41:34 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EditBufferTestHook.dll
[2022/06/15 21:41:34 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WordBreakers.dll
[2022/06/15 21:41:33 | 002,976,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssrch.dll
[2022/06/15 21:41:33 | 002,892,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32kbase.sys
[2022/06/15 21:41:33 | 002,505,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll
[2022/06/15 21:41:33 | 000,981,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll
[2022/06/15 21:41:33 | 000,741,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d9on12.dll
[2022/06/15 21:41:33 | 000,418,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchProtocolHost.exe
[2022/06/15 21:41:33 | 000,402,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Search.ProtocolHandler.MAPI2.dll
[2022/06/15 21:41:33 | 000,381,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssvp.dll
[2022/06/15 21:41:33 | 000,293,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\directxdatabaseupdater.exe
[2022/06/15 21:41:33 | 000,272,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFilterHost.exe
[2022/06/15 21:41:33 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxgiadaptercache.exe
[2022/06/15 21:41:33 | 000,214,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssph.dll
[2022/06/15 21:41:33 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssprxy.dll
[2022/06/15 21:41:33 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssitlb.dll
[2022/06/15 21:41:33 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscntrs.dll
[2022/06/15 21:41:32 | 003,749,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EdgeContent.dll
[2022/06/15 21:41:32 | 001,223,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SEMgrSvc.dll
[2022/06/15 21:41:26 | 001,096,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ClipSp.sys
[2022/06/15 21:41:26 | 000,903,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms2.sys
[2022/06/15 21:41:26 | 000,456,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2022/06/15 21:41:26 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licensingdiag.exe
[2022/06/15 21:41:26 | 000,267,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2022/06/15 21:41:26 | 000,187,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Clipc.dll
[2022/06/15 21:41:26 | 000,134,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oemlicense.dll
[2022/06/15 21:41:25 | 003,062,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIAutomationCore.dll
[2022/06/15 21:41:25 | 002,100,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinapi.appcore.dll
[2022/06/15 21:41:25 | 001,187,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CloudExperienceHostCommon.dll
[2022/06/15 21:41:25 | 001,111,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ClipSVC.dll
[2022/06/15 21:41:25 | 000,797,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ActivationManager.dll
[2022/06/15 21:41:25 | 000,791,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Storage.Search.dll
[2022/06/15 21:41:25 | 000,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cloudAP.dll
[2022/06/15 21:41:25 | 000,402,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\thumbcache.dll
[2022/06/15 21:41:25 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Energy.dll
[2022/06/15 21:41:25 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ApiSetHost.AppExecutionAlias.dll
[2022/06/15 21:41:25 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypttpmeksvc.dll
[2022/06/15 21:41:25 | 000,072,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\GameInput.dll
[2022/06/15 21:41:25 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PackageStateChangeHandler.dll
[2022/06/15 21:41:25 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Xaml.Resources.Common.dll
[2022/06/15 21:41:23 | 017,561,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Xaml.dll
[2022/06/15 21:41:23 | 001,117,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ShareHost.dll
[2022/06/15 21:41:23 | 000,988,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SecurityHealthService.exe
[2022/06/15 21:41:23 | 000,443,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SecurityHealthAgent.dll
[2022/06/15 21:41:23 | 000,120,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SecurityHealthProxyStub.dll
[2022/06/15 21:41:23 | 000,099,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SecurityHealthHost.exe
[2022/06/15 21:41:22 | 010,350,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Media.Protection.PlayReady.dll
[2022/06/15 21:41:22 | 005,760,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\StartTileData.dll
[2022/06/15 21:41:22 | 000,480,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlansec.dll
[2022/06/15 21:41:22 | 000,470,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanapi.dll
[2022/06/15 21:41:22 | 000,435,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanmsm.dll
[2022/06/15 21:41:22 | 000,345,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wusa.exe
[2022/06/15 21:41:22 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WiFiConfigSP.dll
[2022/06/15 21:41:22 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wfdprov.dll
[2022/06/15 21:41:22 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlansvcpal.dll
[2022/06/15 21:41:22 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanhlp.dll
[2022/06/15 21:41:21 | 005,117,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2022/06/15 21:41:21 | 001,171,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TpmCoreProvisioning.dll
[2022/06/15 21:41:21 | 001,094,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskbarcpl.dll
[2022/06/15 21:41:21 | 000,992,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wcmsvc.dll
[2022/06/15 21:41:21 | 000,967,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdiWiFi.sys
[2022/06/15 21:41:21 | 000,457,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingsHandlers_WorkAccess.dll
[2022/06/15 21:41:21 | 000,311,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\stobject.dll
[2022/06/15 21:41:21 | 000,295,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\provops.dll
[2022/06/15 21:41:21 | 000,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ptpprov.dll
[2022/06/15 21:41:21 | 000,133,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SecureTimeAggregator.dll
[2022/06/15 21:41:21 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NFCProvisioningPlugin.dll
[2022/06/15 21:41:21 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FaxPrinterInstaller.dll
[2022/06/15 21:41:20 | 001,580,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SpeechPal.dll
[2022/06/15 21:41:20 | 001,568,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2022/06/15 21:41:20 | 001,543,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TaskFlowDataEngine.dll
[2022/06/15 21:41:20 | 001,291,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XblGameSave.dll
[2022/06/15 21:41:20 | 001,274,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll
[2022/06/15 21:41:20 | 001,034,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WpcRefreshTask.dll
[2022/06/15 21:41:20 | 000,940,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FlightSettings.dll
[2022/06/15 21:41:20 | 000,811,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Management.Service.dll
[2022/06/15 21:41:20 | 000,722,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storport.sys
[2022/06/15 21:41:20 | 000,487,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MitigationClient.dll
[2022/06/15 21:41:20 | 000,349,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSrvPolicyManager.dll
[2022/06/15 21:41:20 | 000,265,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fcon.dll
[2022/06/15 21:41:20 | 000,258,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WpcTok.exe
[2022/06/15 21:41:20 | 000,211,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OmaDmAgent.dll
[2022/06/15 21:41:20 | 000,184,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RTWorkQ.dll
[2022/06/15 21:41:20 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\splwow64.exe
[2022/06/15 21:41:20 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XblAuthTokenBrokerExt.dll
[2022/06/15 21:41:20 | 000,106,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\sdport.sys
[2022/06/15 21:41:20 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DmApiSetExtImplDesktop.dll
[2022/06/15 21:41:20 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XblGameSaveTask.exe
[2022/06/15 21:41:19 | 000,680,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\spaceport.sys
[2022/06/15 21:41:19 | 000,620,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBXHCI.SYS
[2022/06/15 21:41:19 | 000,287,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\BthA2dp.sys
[2022/06/15 21:41:19 | 000,264,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UMDF\RdpIdd.dll
[2022/06/15 21:41:19 | 000,252,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netvsc.sys
[2022/06/15 21:41:19 | 000,220,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\spacedump.sys
[2022/06/15 21:41:19 | 000,152,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ClipRenew.exe
[2022/06/15 21:41:19 | 000,138,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UMDF\UsbXhciCompanion.dll
[2022/06/15 21:41:19 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UMDF\HidTelephony.dll
[2022/06/15 21:41:19 | 000,048,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UMDF\SecureUSBVideo.dll
[2022/06/15 21:32:54 | 000,392,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\poqexec.exe
[2022/06/15 21:32:53 | 000,497,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\poqexec.exe
[1 C:\*.tmp files -> C:\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2022/06/28 21:48:34 | 001,669,676 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2022/06/28 21:48:34 | 000,795,274 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2022/06/28 21:48:34 | 000,533,620 | ---- | M] () -- C:\Windows\SysNative\perfh011.dat
[2022/06/28 21:48:34 | 000,167,564 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2022/06/28 21:48:34 | 000,167,088 | ---- | M] () -- C:\Windows\SysNative\perfc011.dat
[2022/06/28 21:45:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\ユーザー名\Desktop\OTL.exe
[2022/06/28 21:45:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2022/06/28 21:43:18 | 3322,929,152 | -HS- | M] () -- C:\hiberfil.sys
[2022/06/28 21:43:18 | 016,777,216 | -HS- | M] () -- C:\swapfile.sys
[2022/06/19 17:46:11 | 000,001,076 | ---- | M] () -- C:\Users\ユーザー名\Application Data\Microsoft\Internet Explorer\Quick Launch\サクラエディタ.lnk
[2022/06/19 13:47:58 | 000,000,214 | ---- | M] () -- C:\Windows\tasks\CreateExplorerShellUnelevatedTask.job
[2022/06/19 13:43:03 | 000,007,599 | ---- | M] () -- C:\Users\ユーザー名\AppData\Local\Resmon.ResmonCfg
[2022/06/19 11:00:12 | 000,001,301 | ---- | M] () -- C:\Users\ユーザー名\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2022/06/19 00:21:30 | 001,620,208 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2022/06/19 00:21:23 | 000,208,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iisRtl.dll
[2022/06/19 00:21:23 | 000,053,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ahadmin.dll
[2022/06/19 00:21:23 | 000,014,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cngkeyhelper.dll
[2022/06/19 00:21:22 | 000,169,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iisRtl.dll
[2022/06/19 00:21:22 | 000,057,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\admwprox.dll
[2022/06/19 00:21:22 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\admwprox.dll
[2022/06/19 00:21:22 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ahadmin.dll
[2022/06/19 00:21:22 | 000,019,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iisreset.exe
[2022/06/19 00:21:22 | 000,016,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iisreset.exe
[2022/06/19 00:21:22 | 000,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wamregps.dll
[2022/06/19 00:21:22 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iisrstap.dll
[2022/06/19 00:21:22 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wamregps.dll
[2022/06/19 00:21:22 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\cngkeyhelper.dll
[2022/06/19 00:21:22 | 000,009,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iisrstap.dll
[2022/06/18 18:57:21 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2022/06/18 16:14:40 | 000,002,080 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PC情報取得.lnk
[2022/06/18 15:58:50 | 000,383,488 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2022/06/18 15:52:38 | 000,002,368 | ---- | M] () -- C:\Users\ユーザー名\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk
[2022/06/18 15:26:02 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\GfxValDisplayLog.bin
[2022/06/18 10:05:07 | 000,144,624 | ---- | M] () -- C:\Windows\SysNative\perfi011.dat
[2022/06/18 10:05:07 | 000,033,402 | ---- | M] () -- C:\Windows\SysNative\perfd011.dat
[2022/06/18 10:02:35 | 000,215,943 | ---- | M] () -- C:\Windows\SysWow64\dssec.dat
[2022/06/18 10:02:35 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msclmd.dll
[2022/06/18 10:02:35 | 000,003,683 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\lmhosts.sam
[2022/06/18 10:02:35 | 000,003,103 | ---- | M] () -- C:\Windows\SysWow64\mmc.exe.config
[2022/06/18 10:02:35 | 000,000,741 | ---- | M] () -- C:\Windows\SysWow64\NOISE.DAT
[2022/06/18 10:02:34 | 000,297,062 | ---- | M] () -- C:\Windows\SysNative\perfi009.dat
[2022/06/18 10:02:34 | 000,230,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msclmd.dll
[2022/06/18 10:02:34 | 000,215,943 | ---- | M] () -- C:\Windows\SysNative\dssec.dat
[2022/06/18 10:02:34 | 000,033,424 | ---- | M] () -- C:\Windows\SysNative\perfd009.dat
[2022/06/18 10:02:34 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\OEMDefaultAssociations.dll
[2022/06/18 10:02:34 | 000,020,908 | ---- | M] () -- C:\Windows\SysNative\OEMDefaultAssociations.xml
[2022/06/18 10:02:34 | 000,003,103 | ---- | M] () -- C:\Windows\SysNative\mmc.exe.config
[2022/06/18 10:02:34 | 000,000,858 | ---- | M] () -- C:\Windows\SysNative\DefaultQuestions.json
[2022/06/18 10:02:34 | 000,000,741 | ---- | M] () -- C:\Windows\SysNative\NOISE.DAT
[2022/06/15 21:42:35 | 004,407,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\cdp.dll
[2022/06/15 21:42:35 | 000,351,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\fveui.dll
[2022/06/15 21:42:35 | 000,183,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SystemSettings.DeviceEncryptionHandlers.dll
[2022/06/15 21:42:35 | 000,178,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\BitLockerDeviceEncryption.exe
[2022/06/15 21:42:35 | 000,095,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dumpfve.sys
[2022/06/15 21:42:35 | 000,055,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\BdeUISrv.exe
[2022/06/15 21:42:31 | 004,998,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cdp.dll
[2022/06/15 21:42:31 | 000,201,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\notepad.exe
[2022/06/15 21:42:26 | 005,357,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Media.dll
[2022/06/15 21:42:26 | 000,961,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\DolbyDecMFT.dll
[2022/06/15 21:42:26 | 000,801,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MSMPEG2ENC.DLL
[2022/06/15 21:42:25 | 024,272,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Hydrogen.dll
[2022/06/15 21:42:25 | 003,560,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfcore.dll
[2022/06/15 21:42:25 | 001,136,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DolbyDecMFT.dll
[2022/06/15 21:42:25 | 001,092,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\HoloSI.PCShell.dll
[2022/06/15 21:42:25 | 000,488,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\HolographicRuntimes.dll
[2022/06/15 21:42:25 | 000,421,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MixedReality.Broker.dll
[2022/06/15 21:42:25 | 000,130,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll
[2022/06/15 21:42:23 | 007,550,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Media.dll
[2022/06/15 21:42:23 | 004,799,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfcore.dll
[2022/06/15 21:42:23 | 002,520,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2vdec.dll
[2022/06/15 21:42:23 | 000,944,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MSMPEG2ENC.DLL
[2022/06/15 21:42:23 | 000,848,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\HolographicExtensions.dll
[2022/06/15 21:42:23 | 000,561,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DMRServer.dll
[2022/06/15 21:42:23 | 000,268,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2022/06/15 21:42:22 | 007,122,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2022/06/15 21:42:22 | 003,380,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Mirage.dll
[2022/06/15 21:42:22 | 001,542,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wsp_fs.dll
[2022/06/15 21:42:22 | 001,345,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wsp_health.dll
[2022/06/15 21:42:22 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msdt.exe
[2022/06/15 21:42:22 | 000,273,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\provplatformdesktop.dll
[2022/06/15 21:42:22 | 000,077,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\provmigrate.dll
[2022/06/15 21:42:22 | 000,068,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\AcWinRT.dll
[2022/06/15 21:42:22 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\provisioningcommandscsp.dll
[2022/06/15 21:42:22 | 000,054,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
[2022/06/15 21:42:22 | 000,045,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\provlaunch.exe
[2022/06/15 21:42:21 | 001,075,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpcore.dll
[2022/06/15 21:42:21 | 000,924,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\opengl32.dll
[2022/06/15 21:42:21 | 000,617,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll
[2022/06/15 21:42:21 | 000,604,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\odbc32.dll
[2022/06/15 21:42:21 | 000,399,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tracerpt.exe
[2022/06/15 21:42:21 | 000,395,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieproxy.dll
[2022/06/15 21:42:21 | 000,245,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\glu32.dll
[2022/06/15 21:42:21 | 000,098,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\logman.exe
[2022/06/15 21:42:21 | 000,094,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsiwmiv2.dll
[2022/06/15 21:42:21 | 000,068,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsiwmi.dll
[2022/06/15 21:42:21 | 000,062,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iemigplugin.dll
[2022/06/15 21:42:21 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsidsc.dll
[2022/06/15 21:42:21 | 000,045,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\relog.exe
[2022/06/15 21:42:21 | 000,044,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsicli.exe
[2022/06/15 21:42:21 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\typeperf.exe
[2022/06/15 21:42:21 | 000,029,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsium.dll
[2022/06/15 21:42:21 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msimsg.dll
[2022/06/15 21:42:21 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\diskperf.exe
[2022/06/15 21:42:21 | 000,009,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsied.dll
[2022/06/15 21:42:20 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IndexedDbLegacy.dll
[2022/06/15 21:42:19 | 019,865,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\edgehtml.dll
[2022/06/15 21:42:18 | 000,464,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dxdiagn.dll
[2022/06/15 21:42:18 | 000,443,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2022/06/15 21:42:18 | 000,231,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\GameBarPresenceWriter.exe
[2022/06/15 21:42:18 | 000,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Robocopy.exe
[2022/06/15 21:42:18 | 000,048,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dataclen.dll
[2022/06/15 21:42:18 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\GameBarPresenceWriter.proxy.dll
[2022/06/15 21:42:17 | 000,170,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wslapi.dll
[2022/06/15 21:42:16 | 008,252,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2022/06/15 21:42:16 | 004,374,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Mirage.dll
[2022/06/15 21:42:16 | 000,877,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Spectrum.exe
[2022/06/15 21:42:16 | 000,867,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Mirage.Internal.dll
[2022/06/15 21:42:16 | 000,416,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\provplatformdesktop.dll
[2022/06/15 21:42:16 | 000,307,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SharedRealitySvc.dll
[2022/06/15 21:42:16 | 000,304,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icsvcext.dll
[2022/06/15 21:42:16 | 000,228,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\rdsdwmdr.dll
[2022/06/15 21:42:16 | 000,120,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\vmbkmcl.sys
[2022/06/15 21:42:16 | 000,119,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mgmtrefreshcredprov.dll
[2022/06/15 21:42:16 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\provmigrate.dll
[2022/06/15 21:42:16 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\provisioningcommandscsp.dll
[2022/06/15 21:42:16 | 000,071,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
[2022/06/15 21:42:16 | 000,068,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AcWinRT.dll
[2022/06/15 21:42:16 | 000,062,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\provlaunch.exe
[2022/06/15 21:42:15 | 000,104,448 | ---- | M] () -- C:\Windows\SysNative\nettraceex.dll
[2022/06/15 21:42:14 | 000,496,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msdt.exe
[2022/06/15 21:42:11 | 002,430,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ResetEngine.dll
[2022/06/15 21:42:11 | 002,031,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wsp_fs.dll
[2022/06/15 21:42:11 | 001,763,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wsp_health.dll
[2022/06/15 21:42:11 | 001,638,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll
[2022/06/15 21:42:11 | 001,287,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcore.dll
[2022/06/15 21:42:11 | 000,545,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\nltest.exe
[2022/06/15 21:42:11 | 000,098,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\rdpudd.dll
[2022/06/15 21:42:11 | 000,032,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2022/06/15 21:42:10 | 003,336,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2022/06/15 21:42:10 | 001,953,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mmc.exe
[2022/06/15 21:42:10 | 001,065,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\opengl32.dll
[2022/06/15 21:42:10 | 000,793,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll
[2022/06/15 21:42:10 | 000,724,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\odbc32.dll
[2022/06/15 21:42:10 | 000,532,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IESettingSync.exe
[2022/06/15 21:42:10 | 000,485,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DscCore.dll
[2022/06/15 21:42:10 | 000,463,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tracerpt.exe
[2022/06/15 21:42:10 | 000,164,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\glu32.dll
[2022/06/15 21:42:10 | 000,147,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sendmail.dll
[2022/06/15 21:42:10 | 000,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iscsiwmiv2.dll
[2022/06/15 21:42:10 | 000,120,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\logman.exe
[2022/06/15 21:42:10 | 000,084,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iscsiwmi.dll
[2022/06/15 21:42:10 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iscsidsc.dll
[2022/06/15 21:42:10 | 000,065,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iemigplugin.dll
[2022/06/15 21:42:10 | 000,053,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\relog.exe
[2022/06/15 21:42:10 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iscsicli.exe
[2022/06/15 21:42:10 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\typeperf.exe
[2022/06/15 21:42:10 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iscsium.dll
[2022/06/15 21:42:10 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msimsg.dll
[2022/06/15 21:42:10 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\diskperf.exe
[2022/06/15 21:42:10 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iscsied.dll
[2022/06/15 21:42:09 | 000,929,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieproxy.dll
[2022/06/15 21:42:09 | 000,237,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IndexedDbLegacy.dll
[2022/06/15 21:42:07 | 026,268,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\edgehtml.dll
[2022/06/15 21:42:06 | 000,559,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2022/06/15 21:42:06 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\StorageUsage.dll
[2022/06/15 21:42:05 | 000,678,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\computecore.dll
[2022/06/15 21:42:05 | 000,565,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxdiagn.dll
[2022/06/15 21:42:05 | 000,308,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\computestorage.dll
[2022/06/15 21:42:05 | 000,219,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vmdevicehost.dll
[2022/06/15 21:42:05 | 000,172,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Robocopy.exe
[2022/06/15 21:42:05 | 000,134,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WinHvPlatform.dll
[2022/06/15 21:42:05 | 000,062,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dataclen.dll
[2022/06/15 21:42:03 | 001,573,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\hvix64.exe
[2022/06/15 21:42:03 | 001,270,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\hvax64.exe
[2022/06/15 21:42:03 | 000,922,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\securekernel.exe
[2022/06/15 21:42:03 | 000,809,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tcblaunch.exe
[2022/06/15 21:42:03 | 000,502,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ucrtbase_enclave.dll
[2022/06/15 21:42:03 | 000,342,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\GameBarPresenceWriter.exe
[2022/06/15 21:42:03 | 000,307,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\skci.dll
[2022/06/15 21:42:03 | 000,223,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tcbloader.dll
[2022/06/15 21:42:03 | 000,173,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vertdll.dll
[2022/06/15 21:42:03 | 000,119,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\hvloader.dll
[2022/06/15 21:42:03 | 000,096,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hvservice.sys
[2022/06/15 21:42:03 | 000,026,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iumbase.dll
[2022/06/15 21:42:03 | 000,022,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\kdhvcom.dll
[2022/06/15 21:42:03 | 000,016,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iumdll.dll
[2022/06/15 21:42:03 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\GameBarPresenceWriter.proxy.dll
[2022/06/15 21:42:03 | 000,011,787 | ---- | M] () -- C:\Windows\SysNative\DrtmAuthTxt.wim
[2022/06/15 21:42:02 | 008,902,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Media.Protection.PlayReady.dll
[2022/06/15 21:42:02 | 000,436,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mprapi.dll
[2022/06/15 21:42:02 | 000,354,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\LockAppBroker.dll
[2022/06/15 21:42:02 | 000,331,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\AboveLockAppHost.dll
[2022/06/15 21:42:02 | 000,212,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\prnfldr.dll
[2022/06/15 21:42:02 | 000,150,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\twext.dll
[2022/06/15 21:42:02 | 000,126,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\netid.dll
[2022/06/15 21:42:02 | 000,068,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SortWindows64.dll
[2022/06/15 21:42:01 | 000,402,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\edgeIso.dll
[2022/06/15 21:42:01 | 000,325,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wusa.exe
[2022/06/15 21:42:01 | 000,271,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msIso.dll
[2022/06/15 21:42:00 | 000,896,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\gdi32full.dll
[2022/06/15 21:42:00 | 000,885,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdh.dll
[2022/06/15 21:42:00 | 000,556,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dmenrollengine.dll
[2022/06/15 21:42:00 | 000,532,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\policymanager.dll
[2022/06/15 21:42:00 | 000,164,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dmcmnutils.dll
[2022/06/15 21:42:00 | 000,111,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\rekeywiz.exe
[2022/06/15 21:42:00 | 000,040,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\enrollmentapi.dll
[2022/06/15 21:42:00 | 000,025,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\userinitext.dll
続く
  • Rid
  • 2022/06/28 (Tue) 23:31:52
OTL最後です
OTLログ最後です。
[2022/06/15 21:41:59 | 002,753,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\win32kfull.sys
[2022/06/15 21:41:59 | 002,630,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\combase.dll
[2022/06/15 21:41:59 | 001,651,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\winmsipc.dll
[2022/06/15 21:41:59 | 001,611,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpserverbase.dll
[2022/06/15 21:41:59 | 001,450,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dcomp.dll
[2022/06/15 21:41:59 | 000,800,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\winipcsecproc.dll
[2022/06/15 21:41:59 | 000,508,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\daxexec.dll
[2022/06/15 21:41:59 | 000,446,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mmsys.cpl
[2022/06/15 21:41:59 | 000,355,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\winipcfile.dll
[2022/06/15 21:41:59 | 000,329,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\win32k.sys
[2022/06/15 21:41:59 | 000,246,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SndVolSSO.dll
[2022/06/15 21:41:59 | 000,226,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SndVol.exe
[2022/06/15 21:41:59 | 000,203,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\UserMgrProxy.dll
[2022/06/15 21:41:59 | 000,188,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ocsetapi.dll
[2022/06/15 21:41:59 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wincredui.dll
[2022/06/15 21:41:59 | 000,114,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\CredentialUIBroker.exe
[2022/06/15 21:41:59 | 000,094,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\win32u.dll
[2022/06/15 21:41:59 | 000,045,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\userinit.exe
[2022/06/15 21:41:58 | 006,374,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\windows.storage.dll
[2022/06/15 21:41:58 | 002,607,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tquery.dll
[2022/06/15 21:41:58 | 001,333,760 | ---- | M] () -- C:\Windows\SysWow64\TextInputMethodFormatter.dll
[2022/06/15 21:41:58 | 000,968,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\InputHost.dll
[2022/06/15 21:41:58 | 000,754,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\TextInputFramework.dll
[2022/06/15 21:41:58 | 000,702,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Core.TextInput.dll
[2022/06/15 21:41:58 | 000,448,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ttdrecord.dll
[2022/06/15 21:41:58 | 000,276,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Devices.Lights.dll
[2022/06/15 21:41:58 | 000,213,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ttdinject.exe
[2022/06/15 21:41:58 | 000,183,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\fidocredprov.dll
[2022/06/15 21:41:58 | 000,151,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Energy.dll
[2022/06/15 21:41:58 | 000,072,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tttracer.exe
[2022/06/15 21:41:58 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\EditBufferTestHook.dll
[2022/06/15 21:41:58 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WordBreakers.dll
[2022/06/15 21:41:57 | 002,538,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAutomationCore.dll
[2022/06/15 21:41:57 | 002,315,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mssrch.dll
[2022/06/15 21:41:57 | 001,965,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll
[2022/06/15 21:41:57 | 001,011,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\CloudExperienceHostCommon.dll
[2022/06/15 21:41:57 | 000,878,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ShareHost.dll
[2022/06/15 21:41:57 | 000,653,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ActivationManager.dll
[2022/06/15 21:41:57 | 000,554,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d9on12.dll
[2022/06/15 21:41:57 | 000,303,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mssvp.dll
[2022/06/15 21:41:57 | 000,286,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Search.ProtocolHandler.MAPI2.dll
[2022/06/15 21:41:57 | 000,164,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mssph.dll
[2022/06/15 21:41:57 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mssitlb.dll
[2022/06/15 21:41:57 | 000,083,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ApiSetHost.AppExecutionAlias.dll
[2022/06/15 21:41:57 | 000,072,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\crypttpmeksvc.dll
[2022/06/15 21:41:57 | 000,062,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\GameInput.dll
[2022/06/15 21:41:57 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msscntrs.dll
[2022/06/15 21:41:56 | 014,778,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Xaml.dll
[2022/06/15 21:41:56 | 004,748,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.dll
[2022/06/15 21:41:56 | 000,122,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mapistub.dll
[2022/06/15 21:41:56 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\LaunchWinApp.exe
[2022/06/15 21:41:56 | 000,016,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\fixmapi.exe
[2022/06/15 21:41:55 | 004,493,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe
[2022/06/15 21:41:55 | 000,941,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\TpmCoreProvisioning.dll
[2022/06/15 21:41:55 | 000,641,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\LicensingWinRT.dll
[2022/06/15 21:41:55 | 000,512,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\twinapi.dll
[2022/06/15 21:41:55 | 000,430,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\InputSwitch.dll
[2022/06/15 21:41:55 | 000,350,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2022/06/15 21:41:55 | 000,283,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\sppcomapi.dll
[2022/06/15 21:41:55 | 000,250,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\PkgMgr.exe
[2022/06/15 21:41:55 | 000,214,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\EditionUpgradeManagerObj.dll
[2022/06/15 21:41:55 | 000,165,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\EditionUpgradeHelper.dll
[2022/06/15 21:41:55 | 000,153,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RTWorkQ.dll
[2022/06/15 21:41:55 | 000,070,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\DeviceReactivation.dll
[2022/06/15 21:41:55 | 000,060,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\DmApiSetExtImplDesktop.dll
[2022/06/15 21:41:54 | 006,190,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.dll
[2022/06/15 21:41:54 | 002,240,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\windowsudk.shellcommon.dll
[2022/06/15 21:41:54 | 000,847,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\lsm.dll
[2022/06/15 21:41:54 | 000,766,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2022/06/15 21:41:54 | 000,669,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\twinapi.dll
[2022/06/15 21:41:54 | 000,479,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\CoreShellAPI.dll
[2022/06/15 21:41:54 | 000,229,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\PkgMgr.exe
[2022/06/15 21:41:54 | 000,159,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mapistub.dll
[2022/06/15 21:41:54 | 000,159,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mapi32.dll
[2022/06/15 21:41:54 | 000,059,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sfc_os.dll
[2022/06/15 21:41:54 | 000,045,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\LaunchWinApp.exe
[2022/06/15 21:41:54 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\fixmapi.exe
[2022/06/15 21:41:54 | 000,012,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sfc.dll
[2022/06/15 21:41:53 | 000,737,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vpnike.dll
[2022/06/15 21:41:53 | 000,540,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\InputSwitch.dll
[2022/06/15 21:41:53 | 000,526,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mprapi.dll
[2022/06/15 21:41:53 | 000,412,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFolder.dll
[2022/06/15 21:41:52 | 004,677,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\setupapi.dll
[2022/06/15 21:41:52 | 003,945,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SettingsHandlers_nt.dll
[2022/06/15 21:41:52 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tcpmon.dll
[2022/06/15 21:41:52 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SettingsHandlers_Gpu.dll
[2022/06/15 21:41:52 | 000,239,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\prnfldr.dll
[2022/06/15 21:41:52 | 000,181,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\netid.dll
[2022/06/15 21:41:51 | 003,904,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentServer.dll
[2022/06/15 21:41:51 | 002,461,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.onecore.dll
[2022/06/15 21:41:51 | 001,769,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.desktop.dll
[2022/06/15 21:41:51 | 001,207,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ApplyTrustOffline.exe
[2022/06/15 21:41:51 | 001,023,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Facilitator.dll
[2022/06/15 21:41:51 | 000,210,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AppXApplicabilityBlob.dll
[2022/06/15 21:41:51 | 000,138,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\CustomInstallExec.exe
[2022/06/15 21:41:50 | 002,028,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\LocationFramework.dll
[2022/06/15 21:41:50 | 000,457,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\LockHostingFramework.dll
[2022/06/15 21:41:50 | 000,455,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\LockAppBroker.dll
[2022/06/15 21:41:50 | 000,448,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\edgeIso.dll
[2022/06/15 21:41:50 | 000,339,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msIso.dll
[2022/06/15 21:41:50 | 000,074,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SortWindows64.dll
[2022/06/15 21:41:50 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\userinitext.dll
[2022/06/15 21:41:49 | 002,142,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MdmDiagnostics.dll
[2022/06/15 21:41:49 | 001,874,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d9.dll
[2022/06/15 21:41:49 | 001,793,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\enterprisecsps.dll
[2022/06/15 21:41:49 | 001,127,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdh.dll
[2022/06/15 21:41:49 | 000,681,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dmenrollengine.dll
[2022/06/15 21:41:49 | 000,647,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\policymanager.dll
[2022/06/15 21:41:49 | 000,545,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DMPushRouterCore.dll
[2022/06/15 21:41:49 | 000,432,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\omadmclient.exe
[2022/06/15 21:41:49 | 000,169,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mdmmigrator.dll
[2022/06/15 21:41:49 | 000,122,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\rekeywiz.exe
[2022/06/15 21:41:49 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\enrollmentapi.dll
[2022/06/15 21:41:49 | 000,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DmOmaCpMo.exe
[2022/06/15 21:41:49 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d8thk.dll
[2022/06/15 21:41:48 | 001,088,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pidgenx.dll
[2022/06/15 21:41:48 | 000,889,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pidgenx.dll
[2022/06/15 21:41:48 | 000,757,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\LicensingWinRT.dll
[2022/06/15 21:41:48 | 000,547,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\slui.exe
[2022/06/15 21:41:48 | 000,316,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sppcomapi.dll
[2022/06/15 21:41:48 | 000,241,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\EditionUpgradeManagerObj.dll
[2022/06/15 21:41:48 | 000,229,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dmcmnutils.dll
[2022/06/15 21:41:48 | 000,216,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wincredui.dll
[2022/06/15 21:41:48 | 000,215,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dmcsps.dll
[2022/06/15 21:41:48 | 000,179,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\EditionUpgradeHelper.dll
[2022/06/15 21:41:48 | 000,149,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\CredentialUIBroker.exe
[2022/06/15 21:41:48 | 000,093,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DeviceReactivation.dll
[2022/06/15 21:41:48 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll
[2022/06/15 21:41:47 | 001,483,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\usermgr.dll
[2022/06/15 21:41:47 | 001,129,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msctf.dll
[2022/06/15 21:41:47 | 001,127,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSyncCore.dll
[2022/06/15 21:41:47 | 000,969,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSyncHost.exe
[2022/06/15 21:41:47 | 000,909,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
[2022/06/15 21:41:47 | 000,858,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\comdlg32.dll
[2022/06/15 21:41:47 | 000,489,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntshrui.dll
[2022/06/15 21:41:47 | 000,415,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\clfs.sys
[2022/06/15 21:41:47 | 000,373,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.FileExplorer.Common.dll
[2022/06/15 21:41:47 | 000,323,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\UserMgrProxy.dll
[2022/06/15 21:41:47 | 000,274,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.FileExplorer.dll
[2022/06/15 21:41:47 | 000,186,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\twext.dll
[2022/06/15 21:41:46 | 010,849,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2022/06/15 21:41:46 | 002,946,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2022/06/15 21:41:46 | 000,329,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\NetSetupSvc.dll
[2022/06/15 21:41:45 | 003,819,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\diagtrack.dll
[2022/06/15 21:41:45 | 002,027,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2022/06/15 21:41:45 | 000,018,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\hal.dll
[2022/06/15 21:41:44 | 001,658,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2022/06/15 21:41:44 | 000,327,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Wldap32.dll
[2022/06/15 21:41:44 | 000,136,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\offlinelsa.dll
[2022/06/15 21:41:44 | 000,058,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\userinit.exe
[2022/06/15 21:41:43 | 003,503,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\combase.dll
[2022/06/15 21:41:43 | 001,974,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dcomp.dll
[2022/06/15 21:41:43 | 000,924,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll
[2022/06/15 21:41:42 | 002,008,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\refs.sys
[2022/06/15 21:41:42 | 001,828,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2022/06/15 21:41:42 | 001,561,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2022/06/15 21:41:42 | 001,396,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2022/06/15 21:41:42 | 001,200,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe
[2022/06/15 21:41:42 | 001,009,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\uDWM.dll
[2022/06/15 21:41:42 | 000,498,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\cldflt.sys
[2022/06/15 21:41:42 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ocsetapi.dll
[2022/06/15 21:41:41 | 000,544,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mmsys.cpl
[2022/06/15 21:41:41 | 000,309,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SndVolSSO.dll
[2022/06/15 21:41:41 | 000,276,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SndVol.exe
[2022/06/15 21:41:40 | 006,417,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.pcshell.dll
[2022/06/15 21:41:40 | 001,208,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\NotificationController.dll
[2022/06/15 21:41:40 | 000,866,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ShellAppRuntime.exe
[2022/06/15 21:41:40 | 000,379,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\NotificationControllerPS.dll
[2022/06/15 21:41:39 | 004,009,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SystemSettingsThresholdAdminFlowUI.dll
[2022/06/15 21:41:39 | 002,622,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\UpdateAgent.dll
[2022/06/15 21:41:39 | 000,519,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SystemSettingsAdminFlows.exe
[2022/06/15 21:41:39 | 000,230,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\convertvhd.exe
[2022/06/15 21:41:38 | 001,680,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MoUsoCoreWorker.exe
[2022/06/15 21:41:38 | 001,413,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\usocoreworker.exe
[2022/06/15 21:41:38 | 001,163,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MusUpdateHandlers.dll
[2022/06/15 21:41:38 | 000,700,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SHCore.dll
[2022/06/15 21:41:38 | 000,692,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MusNotification.exe
[2022/06/15 21:41:38 | 000,630,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MusNotificationUx.exe
[2022/06/15 21:41:38 | 000,570,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\usosvc.dll
[2022/06/15 21:41:37 | 003,814,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\win32kfull.sys
[2022/06/15 21:41:37 | 003,760,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Microsoft.Bluetooth.Service.dll
[2022/06/15 21:41:37 | 002,343,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winmsipc.dll
[2022/06/15 21:41:37 | 001,856,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\rdpserverbase.dll
[2022/06/15 21:41:37 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winipcsecproc.dll
[2022/06/15 21:41:37 | 000,686,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\daxexec.dll
[2022/06/15 21:41:37 | 000,601,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\EnterpriseAppMgmtSvc.dll
[2022/06/15 21:41:37 | 000,513,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winipcfile.dll
[2022/06/15 21:41:37 | 000,506,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL
[2022/06/15 21:41:37 | 000,392,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Devices.Lights.dll
[2022/06/15 21:41:37 | 000,303,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UMDF\IddCx.dll
[2022/06/15 21:41:37 | 000,232,288 | ---- | M] () -- C:\Windows\SysNative\containerdevicemanagement.dll
[2022/06/15 21:41:37 | 000,181,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wfplwfs.sys
[2022/06/15 21:41:37 | 000,145,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\bindflt.sys
[2022/06/15 21:41:37 | 000,133,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\win32u.dll
[2022/06/15 21:41:37 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\bindfltapi.dll
[2022/06/15 21:41:37 | 000,093,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wcnfs.sys
[2022/06/15 21:41:37 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dumpsdport.sys
[2022/06/15 21:41:36 | 007,984,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\windows.storage.dll
[2022/06/15 21:41:36 | 001,004,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\propsys.dll
[2022/06/15 21:41:36 | 000,412,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2022/06/15 21:41:36 | 000,203,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Storage.OneCore.dll
[2022/06/15 21:41:36 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\fwmdmcsp.dll
[2022/06/15 21:41:35 | 002,250,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ISM.dll
[2022/06/15 21:41:35 | 001,554,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\UserDataService.dll
[2022/06/15 21:41:35 | 001,379,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\InputHost.dll
[2022/06/15 21:41:35 | 001,191,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Unistore.dll
[2022/06/15 21:41:35 | 001,145,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\EmailApis.dll
[2022/06/15 21:41:35 | 000,648,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ttdrecord.dll
[2022/06/15 21:41:35 | 000,333,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\PushToInstall.dll
[2022/06/15 21:41:35 | 000,283,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ttdinject.exe
[2022/06/15 21:41:35 | 000,236,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\fidocredprov.dll
[2022/06/15 21:41:35 | 000,196,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\PimIndexMaintenance.dll
[2022/06/15 21:41:35 | 000,086,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tttracer.exe
[2022/06/15 21:41:34 | 004,731,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\InputService.dll
[2022/06/15 21:41:34 | 003,308,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tquery.dll
[2022/06/15 21:41:34 | 002,976,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mssrch.dll
[2022/06/15 21:41:34 | 002,260,480 | ---- | M] () -- C:\Windows\SysNative\TextInputMethodFormatter.dll
[2022/06/15 21:41:34 | 001,039,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Core.TextInput.dll
[2022/06/15 21:41:34 | 001,015,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\TextInputFramework.dll
[2022/06/15 21:41:34 | 000,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\InputLocaleManager.dll
[2022/06/15 21:41:34 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\EditBufferTestHook.dll
[2022/06/15 21:41:34 | 000,044,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WordBreakers.dll
[2022/06/15 21:41:33 | 003,749,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\EdgeContent.dll
[2022/06/15 21:41:33 | 002,892,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\win32kbase.sys
[2022/06/15 21:41:33 | 002,505,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll
[2022/06/15 21:41:33 | 000,981,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll
[2022/06/15 21:41:33 | 000,741,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d9on12.dll
[2022/06/15 21:41:33 | 000,418,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SearchProtocolHost.exe
[2022/06/15 21:41:33 | 000,402,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Search.ProtocolHandler.MAPI2.dll
[2022/06/15 21:41:33 | 000,381,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mssvp.dll
[2022/06/15 21:41:33 | 000,293,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\directxdatabaseupdater.exe
[2022/06/15 21:41:33 | 000,272,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFilterHost.exe
[2022/06/15 21:41:33 | 000,237,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxgiadaptercache.exe
[2022/06/15 21:41:33 | 000,214,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mssph.dll
[2022/06/15 21:41:33 | 000,145,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mssprxy.dll
[2022/06/15 21:41:33 | 000,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mssitlb.dll
[2022/06/15 21:41:33 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msscntrs.dll
[2022/06/15 21:41:32 | 001,223,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SEMgrSvc.dll
[2022/06/15 21:41:26 | 001,111,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ClipSVC.dll
[2022/06/15 21:41:26 | 001,096,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ClipSp.sys
[2022/06/15 21:41:26 | 000,903,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms2.sys
[2022/06/15 21:41:26 | 000,456,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2022/06/15 21:41:26 | 000,395,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licensingdiag.exe
[2022/06/15 21:41:26 | 000,267,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2022/06/15 21:41:26 | 000,187,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Clipc.dll
[2022/06/15 21:41:26 | 000,134,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\oemlicense.dll
[2022/06/15 21:41:25 | 003,062,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\UIAutomationCore.dll
[2022/06/15 21:41:25 | 002,100,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\twinapi.appcore.dll
[2022/06/15 21:41:25 | 001,187,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\CloudExperienceHostCommon.dll
[2022/06/15 21:41:25 | 000,797,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ActivationManager.dll
[2022/06/15 21:41:25 | 000,791,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Storage.Search.dll
[2022/06/15 21:41:25 | 000,594,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cloudAP.dll
[2022/06/15 21:41:25 | 000,402,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\thumbcache.dll
[2022/06/15 21:41:25 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Energy.dll
[2022/06/15 21:41:25 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ApiSetHost.AppExecutionAlias.dll
[2022/06/15 21:41:25 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\crypttpmeksvc.dll
[2022/06/15 21:41:25 | 000,072,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\GameInput.dll
[2022/06/15 21:41:25 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\PackageStateChangeHandler.dll
[2022/06/15 21:41:25 | 000,044,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Xaml.Resources.Common.dll
[2022/06/15 21:41:24 | 017,561,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Xaml.dll
[2022/06/15 21:41:23 | 010,350,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Media.Protection.PlayReady.dll
[2022/06/15 21:41:23 | 001,117,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ShareHost.dll
[2022/06/15 21:41:23 | 000,988,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SecurityHealthService.exe
[2022/06/15 21:41:23 | 000,443,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SecurityHealthAgent.dll
[2022/06/15 21:41:23 | 000,120,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SecurityHealthProxyStub.dll
[2022/06/15 21:41:23 | 000,099,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SecurityHealthHost.exe
[2022/06/15 21:41:22 | 005,760,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\StartTileData.dll
[2022/06/15 21:41:22 | 000,480,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wlansec.dll
[2022/06/15 21:41:22 | 000,470,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wlanapi.dll
[2022/06/15 21:41:22 | 000,435,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wlanmsm.dll
[2022/06/15 21:41:22 | 000,345,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wusa.exe
[2022/06/15 21:41:22 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WiFiConfigSP.dll
[2022/06/15 21:41:22 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wfdprov.dll
[2022/06/15 21:41:22 | 000,036,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wlansvcpal.dll
[2022/06/15 21:41:22 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wlanhlp.dll
[2022/06/15 21:41:21 | 005,117,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2022/06/15 21:41:21 | 001,274,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll
[2022/06/15 21:41:21 | 001,171,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\TpmCoreProvisioning.dll
[2022/06/15 21:41:21 | 001,094,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\taskbarcpl.dll
[2022/06/15 21:41:21 | 000,992,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wcmsvc.dll
[2022/06/15 21:41:21 | 000,967,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdiWiFi.sys
[2022/06/15 21:41:21 | 000,457,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SettingsHandlers_WorkAccess.dll
[2022/06/15 21:41:21 | 000,311,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\stobject.dll
[2022/06/15 21:41:21 | 000,295,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\provops.dll
[2022/06/15 21:41:21 | 000,217,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ptpprov.dll
[2022/06/15 21:41:21 | 000,133,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SecureTimeAggregator.dll
[2022/06/15 21:41:21 | 000,107,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\NFCProvisioningPlugin.dll
[2022/06/15 21:41:21 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\FaxPrinterInstaller.dll
[2022/06/15 21:41:20 | 001,580,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SpeechPal.dll
[2022/06/15 21:41:20 | 001,568,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2022/06/15 21:41:20 | 001,543,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\TaskFlowDataEngine.dll
[2022/06/15 21:41:20 | 001,291,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\XblGameSave.dll
[2022/06/15 21:41:20 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WpcRefreshTask.dll
[2022/06/15 21:41:20 | 000,940,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\FlightSettings.dll
[2022/06/15 21:41:20 | 000,811,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Management.Service.dll
[2022/06/15 21:41:20 | 000,722,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storport.sys
[2022/06/15 21:41:20 | 000,487,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MitigationClient.dll
[2022/06/15 21:41:20 | 000,349,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSrvPolicyManager.dll
[2022/06/15 21:41:20 | 000,265,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\fcon.dll
[2022/06/15 21:41:20 | 000,258,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WpcTok.exe
[2022/06/15 21:41:20 | 000,211,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\OmaDmAgent.dll
[2022/06/15 21:41:20 | 000,184,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RTWorkQ.dll
[2022/06/15 21:41:20 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\splwow64.exe
[2022/06/15 21:41:20 | 000,114,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\XblAuthTokenBrokerExt.dll
[2022/06/15 21:41:20 | 000,106,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\sdport.sys
[2022/06/15 21:41:20 | 000,083,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DmApiSetExtImplDesktop.dll
[2022/06/15 21:41:20 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\XblGameSaveTask.exe
[2022/06/15 21:41:19 | 002,877,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\PrintConfig.dll
[2022/06/15 21:41:19 | 000,680,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\spaceport.sys
[2022/06/15 21:41:19 | 000,620,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBXHCI.SYS
[2022/06/15 21:41:19 | 000,287,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\BthA2dp.sys
[2022/06/15 21:41:19 | 000,264,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UMDF\RdpIdd.dll
[2022/06/15 21:41:19 | 000,252,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netvsc.sys
[2022/06/15 21:41:19 | 000,220,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\spacedump.sys
[2022/06/15 21:41:19 | 000,152,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ClipRenew.exe
[2022/06/15 21:41:19 | 000,138,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UMDF\UsbXhciCompanion.dll
[2022/06/15 21:41:19 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UMDF\HidTelephony.dll
[2022/06/15 21:41:19 | 000,048,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UMDF\SecureUSBVideo.dll
[1 C:\*.tmp files -> C:\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2022/06/19 17:46:11 | 000,001,076 | ---- | C] () -- C:\Users\ユーザー名\Application Data\Microsoft\Internet Explorer\Quick Launch\サクラエディタ.lnk
[2022/06/19 16:57:02 | 000,001,424 | ---- | C] () -- C:\Users\ユーザー名\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VRoidStudio 1.8.0.lnk
[2022/06/19 13:43:03 | 000,007,599 | ---- | C] () -- C:\Users\ユーザー名\AppData\Local\Resmon.ResmonCfg
[2022/06/19 13:30:58 | 000,000,214 | ---- | C] () -- C:\Windows\tasks\CreateExplorerShellUnelevatedTask.job
[2022/06/19 12:03:22 | 000,001,932 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DMMGamePlayer.lnk
[2022/06/19 12:01:37 | 000,000,946 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.10.32.lnk
[2022/06/19 11:00:12 | 000,001,301 | ---- | C] () -- C:\Users\ユーザー名\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2022/06/19 00:32:23 | 001,740,800 | ---- | C] () -- C:\Windows\SysNative\utv_core.dll
[2022/06/19 00:32:23 | 001,385,984 | ---- | C] () -- C:\Windows\SysWow64\utv_core.dll
[2022/06/19 00:32:23 | 000,141,824 | ---- | C] () -- C:\Windows\SysNative\utv_vcm.dll
[2022/06/19 00:32:23 | 000,113,152 | ---- | C] () -- C:\Windows\SysWow64\utv_vcm.dll
[2022/06/19 00:21:30 | 001,620,208 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2022/06/18 23:59:55 | 000,001,005 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
[2022/06/18 18:57:21 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2022/06/18 15:51:20 | 000,001,146 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
[2022/06/18 15:44:31 | 000,002,368 | ---- | C] () -- C:\Users\ユーザー名\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk
[2022/06/18 15:40:39 | 000,000,352 | ---- | C] () -- C:\Users\ユーザー名\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2022/06/18 15:40:39 | 000,000,334 | ---- | C] () -- C:\Users\ユーザー名\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2022/06/18 15:37:51 | 001,669,676 | ---- | C] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2022/06/18 15:37:32 | 000,508,196 | ---- | C] () -- C:\Windows\SysWow64\license.rtf
[2022/06/18 15:37:32 | 000,508,196 | ---- | C] () -- C:\Windows\SysNative\license.rtf
[2022/06/18 15:33:24 | 3322,929,152 | -HS- | C] () -- C:\hiberfil.sys
[2022/06/18 15:26:03 | 000,002,430 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
[2022/06/18 15:26:02 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\GfxValDisplayLog.bin
[2022/06/18 15:25:52 | 000,383,488 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2022/06/18 10:10:07 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2022/06/18 10:05:12 | 000,533,620 | ---- | C] () -- C:\Windows\SysNative\perfh011.dat
[2022/06/18 10:05:12 | 000,167,088 | ---- | C] () -- C:\Windows\SysNative\perfc011.dat
[2022/06/18 10:05:12 | 000,144,624 | ---- | C] () -- C:\Windows\SysNative\perfi011.dat
[2022/06/18 10:05:12 | 000,033,402 | ---- | C] () -- C:\Windows\SysNative\perfd011.dat
[2022/06/18 10:04:18 | 000,795,274 | ---- | C] () -- C:\Windows\SysNative\perfh009.dat
[2022/06/18 10:04:18 | 000,297,062 | ---- | C] () -- C:\Windows\SysNative\perfi009.dat
[2022/06/18 10:04:18 | 000,167,564 | ---- | C] () -- C:\Windows\SysNative\perfc009.dat
[2022/06/18 10:04:18 | 000,033,424 | ---- | C] () -- C:\Windows\SysNative\perfd009.dat
[2022/06/18 10:03:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2022/06/18 10:03:42 | 000,003,103 | ---- | C] () -- C:\Windows\SysWow64\mmc.exe.config
[2022/06/18 10:03:42 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2022/06/18 10:03:41 | 000,003,683 | ---- | C] () -- C:\Windows\SysNative\drivers\etc\lmhosts.sam
[2022/06/18 10:03:40 | 000,215,943 | ---- | C] () -- C:\Windows\SysNative\dssec.dat
[2022/06/18 10:03:40 | 000,020,908 | ---- | C] () -- C:\Windows\SysNative\OEMDefaultAssociations.xml
[2022/06/18 10:03:40 | 000,003,103 | ---- | C] () -- C:\Windows\SysNative\mmc.exe.config
[2022/06/18 10:03:40 | 000,000,858 | ---- | C] () -- C:\Windows\SysNative\DefaultQuestions.json
[2022/06/18 10:03:40 | 000,000,741 | ---- | C] () -- C:\Windows\SysNative\NOISE.DAT
[2022/06/15 21:42:15 | 000,104,448 | ---- | C] () -- C:\Windows\SysNative\nettraceex.dll
[2022/06/15 21:42:03 | 000,011,787 | ---- | C] () -- C:\Windows\SysNative\DrtmAuthTxt.wim
[2022/06/15 21:41:58 | 001,333,760 | ---- | C] () -- C:\Windows\SysWow64\TextInputMethodFormatter.dll
[2022/06/15 21:41:37 | 000,232,288 | ---- | C] () -- C:\Windows\SysNative\containerdevicemanagement.dll
[2022/06/15 21:41:34 | 002,260,480 | ---- | C] () -- C:\Windows\SysNative\TextInputMethodFormatter.dll
[2022/04/24 19:52:11 | 001,451,056 | ---- | C] () -- C:\Windows\SysWow64\vulkaninfo-1-999-0-0-0.exe
[2022/04/24 19:52:11 | 001,451,056 | ---- | C] () -- C:\Windows\SysWow64\vulkaninfo.exe
[2022/04/24 19:52:10 | 000,970,256 | ---- | C] () -- C:\Windows\SysWow64\vulkan-1-999-0-0-0.dll
[2022/04/24 19:52:10 | 000,970,256 | ---- | C] () -- C:\Windows\SysWow64\vulkan-1.dll
[2022/03/05 19:20:04 | 000,223,744 | ---- | C] () -- C:\Windows\SysWow64\TpmTool.exe
[2021/10/13 23:16:22 | 000,611,960 | ---- | C] () -- C:\Windows\SysWow64\TextShaping.dll
[2021/06/11 23:04:33 | 000,468,440 | ---- | C] () -- C:\Windows\SysWow64\WindowManagementAPI.dll
[2021/03/13 12:34:55 | 000,053,760 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2021/03/13 12:33:59 | 000,047,472 | ---- | C] () -- C:\Windows\SysWow64\umpdc.dll
[2021/03/13 12:33:52 | 000,235,520 | ---- | C] () -- C:\Windows\SysWow64\HeatCore.dll
[2021/03/13 12:33:39 | 000,266,240 | ---- | C] () -- C:\Windows\SysWow64\Windows.Internal.UI.Shell.WindowTabManager.dll
[2021/03/13 12:33:34 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\CoreMas.dll
[2021/03/13 12:33:33 | 000,330,752 | ---- | C] () -- C:\Windows\SysWow64\ssdm.dll
[2021/03/13 12:33:33 | 000,010,752 | ---- | C] () -- C:\Windows\SysWow64\agentactivationruntimestarter.exe

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2022/06/19 00:18:27 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\windows.storage.dll -- [2022/06/15 21:41:36 | 007,984,096 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\windows.storage.dll -- [2022/06/15 21:41:58 | 006,374,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2021/03/13 12:31:55 | 001,075,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2021/03/13 12:33:42 | 000,804,352 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2019/12/07 18:08:19 | 000,514,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== Custom Scans ==========[/color]
[2022/06/18 23:59:56 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2022/06/18 13:12:05 | 000,000,000 | -H-D | M] -- C:\Recovery
[2020/06/27 20:51:31 | 000,000,000 | -H-D | M] -- C:\My Cloud Public\AlbumThumbnail
[2020/06/27 20:51:31 | 000,000,000 | -H-D | M] -- C:\My Cloud Public\FaceThumbs
[2022/06/18 16:14:43 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
[2020/06/27 20:20:19 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
[2022/06/28 21:51:42 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsApps
[2022/06/18 10:03:37 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\Settings
[2022/06/18 10:03:37 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc
[2022/06/18 15:37:03 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrccache\downloads
[2022/06/18 10:03:37 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc\DMProfiles
[2022/06/18 10:03:37 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc\Profiles
[2022/06/18 15:34:04 | 000,000,000 | RH-D | M] -- C:\Users\Default
[2022/06/18 10:03:37 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\Settings
[2022/06/18 10:03:37 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc
[2022/06/18 15:37:03 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\Windows\DeviceMetadataCache\dmrccache\downloads
[2022/06/18 10:03:37 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc\DMProfiles
[2022/06/18 10:03:37 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc\Profiles
[2022/06/18 10:03:37 | 000,000,000 | -H-D | M] -- C:\Users\Default\AppData
[2022/06/19 01:31:09 | 000,000,000 | RH-D | M] -- C:\Users\Public\AccountPictures
[2022/06/20 22:07:32 | 000,000,000 | RH-D | M] -- C:\Users\Public\Desktop
[2022/06/18 15:33:46 | 000,000,000 | RH-D | M] -- C:\Users\Public\Libraries
[2022/06/18 15:40:39 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\AppData
[2022/06/18 15:44:30 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\AppData\Local\Microsoft\Windows\IECompatCache
[2022/06/18 15:44:30 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\AppData\Local\Microsoft\Windows\IECompatUaCache
[2022/06/18 15:45:38 | 000,000,000 | RH-D | M] -- C:\Users\ユーザー名\AppData\Local\Microsoft\Windows\Burn\Burn
[2022/06/18 15:44:30 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\AppData\Local\Microsoft\Windows\IECompatCache\Low
[2022/06/18 15:44:30 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\AppData\Local\Microsoft\Windows\IECompatUaCache\Low
[2022/06/27 01:36:30 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\AppData\Local\Microsoft\Windows\INetCache\Content.MSO
[2022/06/19 21:02:00 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\AppData\Local\Microsoft\Windows\INetCache\Content.Word
[2022/06/18 15:44:30 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\AppData\Local\Microsoft\Windows\INetCache\Virtualized
[2022/06/18 15:44:30 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\AppData\Local\Microsoft\Windows\INetCookies\DNTException\Low
[2022/06/18 15:44:30 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\AppData\Local\Microsoft\Windows\INetCookies\PrivacIE\Low
[2022/06/18 15:44:30 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\AppData\Local\Temp\DownloaderEngine
[2022/06/18 15:44:34 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2022/06/18 15:44:30 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\Music\My Cloud DB
[2022/06/18 15:59:54 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\Pictures\My Cloud DB
[2022/06/18 16:14:32 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\Videos\My Cloud DB
[2022/06/18 15:44:30 | 000,000,000 | -H-D | M] -- C:\Users\ユーザー名\Videos\My Cloud Play Album
[2022/06/18 16:31:40 | 000,000,000 | -H-D | M] -- C:\Windows\ELAMBKUP
[2022/06/18 10:03:37 | 000,000,000 | -H-D | M] -- C:\Windows\LanguageOverlayCache
[2022/06/25 00:00:16 | 000,000,000 | -H-D | M] -- C:\Windows\ServiceProfiles\LocalService\AppData
[2022/06/18 15:25:52 | 000,000,000 | -H-D | M] -- C:\Windows\ServiceProfiles\NetworkService\AppData

[color=#A23BEC]< %windir%\tasks\*.job >[/color]
[2022/06/19 13:47:58 | 000,000,214 | ---- | M] () -- C:\Windows\tasks\CreateExplorerShellUnelevatedTask.job

[color=#E56717]========== Drive Information ==========[/color]

Physical Drives
---------------

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: SCSI
Media Type: Fixed hard disk media
Model: WDC WD10SPZX-16Z10T1
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 - Fixed hard disk media
Interface type: SCSI
Media Type: Fixed hard disk media
Model: Intel Optane+238GBSSD
Partitions: 3
Status: OK
Status Info: 0

Partitions
---------------

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 932.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #1, Partition #0
PartitionType: GPT: System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 1,024.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #1, Partition #1
PartitionType: GPT: Basic Data
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 234.00GB
Starting Offset: 1209008128
Hidden sectors: 0


DeviceID: Disk #1, Partition #2
PartitionType: GPT: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: False
Size: 3.00GB
Starting Offset: 252827402240
Hidden sectors: 0


[color=#E56717]========== Base Services ==========[/color]
No service found with a name of AeLookupSvc
SRV:[b]64bit:[/b] - [2022/06/15 21:41:25 | 000,217,600 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:34 | 000,095,744 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:[b]64bit:[/b] - [2021/10/13 23:15:58 | 001,481,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:36 | 000,892,928 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:55 | 000,094,208 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV - [2021/03/13 12:34:10 | 000,066,560 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2022/01/14 23:58:29 | 000,414,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV - [2022/01/14 23:58:41 | 000,335,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV:[b]64bit:[/b] - [2022/06/18 10:02:12 | 000,140,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:48 | 000,104,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:43 | 001,326,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:54 | 000,400,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV - [2021/03/13 12:34:07 | 000,329,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV:[b]64bit:[/b] - [2022/03/31 01:43:59 | 000,349,696 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:09 | 000,112,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\eapsvc.dll -- (Eaphost)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:55 | 000,036,352 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV - [2019/12/07 18:09:27 | 000,029,696 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV:[b]64bit:[/b] - [2021/03/13 12:33:27 | 000,619,008 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:[b]64bit:[/b] - [2022/05/11 21:42:26 | 000,463,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:[b]64bit:[/b] - [2022/06/15 21:41:39 | 000,500,224 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv)
No service found with a name of MMCSS
SRV:[b]64bit:[/b] - [2021/03/13 12:31:55 | 000,288,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:[b]64bit:[/b] - [2022/03/05 19:20:00 | 000,878,080 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2021/08/13 01:40:20 | 000,388,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:59 | 000,034,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:[b]64bit:[/b] - [2021/03/13 12:33:22 | 000,133,120 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:20 | 000,832,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
No service found with a name of ProtectedStorage
No service found with a name of EMDMgmt
SRV:[b]64bit:[/b] - [2021/03/13 12:33:24 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:[b]64bit:[/b] - [2022/05/11 21:42:45 | 001,026,560 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:43 | 001,326,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:[b]64bit:[/b] - [2019/12/07 18:09:05 | 000,032,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:[b]64bit:[/b] - [2022/03/09 23:29:46 | 000,059,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:39 | 000,332,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:[b]64bit:[/b] - [2022/05/11 21:42:24 | 000,302,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:[b]64bit:[/b] - [2022/06/15 21:42:05 | 000,283,136 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV - [2022/06/15 21:42:18 | 000,209,408 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV:[b]64bit:[/b] - [2022/02/12 01:22:14 | 000,814,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:42 | 000,316,928 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV - [2021/03/13 12:35:04 | 000,251,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV:[b]64bit:[/b] - [2019/12/07 18:09:00 | 000,070,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:44 | 000,488,448 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:39 | 001,495,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:[b]64bit:[/b] - [2022/03/05 19:19:38 | 001,838,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (Audiosrv)
SRV:[b]64bit:[/b] - [2022/02/12 01:21:44 | 000,744,448 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:23 | 000,154,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
SRV:[b]64bit:[/b] - [2019/12/07 18:08:16 | 000,103,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:38 | 001,879,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (EventLog)
SRV:[b]64bit:[/b] - [2022/05/11 21:42:09 | 001,173,504 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (mpssvc)
SRV:[b]64bit:[/b] - [2021/03/13 12:34:29 | 000,687,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:[b]64bit:[/b] - [2019/12/07 18:09:44 | 000,069,632 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver)
SRV - [2019/12/07 18:10:02 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver)
SRV:[b]64bit:[/b] - [2021/03/13 12:32:41 | 000,243,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:[b]64bit:[/b] - [2022/05/11 21:42:10 | 003,406,336 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:[b]64bit:[/b] - [2022/05/11 21:42:02 | 000,329,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:[b]64bit:[/b] - [2022/06/15 21:41:22 | 002,657,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (WlanSvc)
SRV:[b]64bit:[/b] - [2022/01/14 23:58:33 | 000,302,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

< End of report >

以上です。よろしくお願いいたします。
  • Rid
  • 2022/06/28 (Tue) 23:33:15
OTLでも感染の恐れはなさそうです
IVNOさん、フォローありがとうございます。
ドライバ破損は気づきませんでした。

Ridさん、作業と報告、ご苦労様です。
OTLログも見せてもらいました。
ログを見る限りでは感染の痕跡もうかがえないようです。
OTLで変な痕跡見えないならMBAM等のツールでスキャンしてもマルウェア見つかる可能性は薄いでしょう。
OTLは準備時の説明に沿って片付けていいです。

IVNOさんがおっしゃられたCrystalDiskInfoは窓の杜でも入手可能です。
https://forest.watch.impress.co.jp/library/software/crdiskinfo/

公式サイトに行けばインストールする通常型以外に単体動作できるポータブル版(ZIP)もあるのでそちらを使うのが早いでしょう。
https://crystalmark.info/ja/download/

他にもHDD状態チェック可能なツールはありますが、あまりいくつもツール使ってデリケートな領域をいじるとかえってダメージ起きかねません。

特にPCの奥深い領域に食い込んで隠れるルートキットのようなマルウェアだと並みのセキュリティツールではスキャンしても検出すら難しいので、ノートンパワーイレイサーやTDSSKiller等がありますが、これらはお勧めしません。
ルートキット検出ツールはWindowsの正規システムでも誤検出する可能性が高いほど扱いが難しいものなので、検出されたものをよく吟味して対処を判断しないといけない完全自己責任で使うものです。
またTDSSKillerは現在いろいろと評価が厳しいベンダー製のツールでもあり、その意味でもお勧めしません。

一応MBAMでもルートキットスキャンはできますが、これのルートキットスキャンはかなりPCリソース消費するうえ時間もかかるのでPCのスペックによっては丸1日かかっても終わらないこともあります。

ここまで解析した限りでは現時点ではマルウェア感染や攻撃のおそれは少ないと思われます。
  • 悪代官
  • 2022/06/29 (Wed) 22:02:29
今後について
お世話になります。

>ここまで解析した限りでは現時点ではマルウェア感染や攻撃のおそれは少ないと思われます。
ご確認、ありがとうございました。
そうなりますと、現状解析としては、これ以上は不要と見てよろしいしょうか?

>ドライバ破損は気づきませんでした。
>可能性1. リカバリデータ内部にプリインストール(初期導入)されているドライバのバージョンが古く、最新版のWindowsとの互換性がない
こちらについては、現PC製造元の富士通のサイトを確認したところ
ドライバはWindowsアップデートで提供され、自動更新される、とありました。
それ以外で実施したほうがいいことがあれば、申し訳ございませんが
アドバイスいただけると助かります。

以上です。よろしくお願いいたします。
  • Rid
  • 2022/06/29 (Wed) 22:24:53
あれはあまりアテにならないと言いますか
昔と言えるほど昔ではなく、むしろ最近と言える話かもしれませんが、少し昔語りをしたいと思います。

今から3ヶ月ほど前のことでした。
私はお客さんから、リカバリ後に動作が不安定になったPCを直してくれという依頼を受けました。
お客さんのところに出向するか遠隔操作で対応するかを問うと、遠隔操作でと依頼されたため、自宅から遠隔操作でお客さんのPCをチェックしました。
遠隔操作を行った結果として見えてきたのは、デバイスが正常に動作していないというものでした。
これはつまり、ドライバが正常に動作していないことを意味します。
調べてみると、どことは言いませんがマウスコンピ何とか社という中国メーカーの製品でした。
某社のサイトからドライバを探そうとしましたが、某社サイトにはドライバもBIOSも存在していませんでした。
某社には、Windows Updateを経由して最新ドライバを入手しろとありましたが、そんなものWindows Updateには存在しませんでした。
BIOS画面は遠隔操作で見ることができないため、仕方なくお客さんにBIOS画面を開いてもらうと、ASUS社のPRIME B550M-Aというマザーボードであることが特定できました。
そこからの展開は早く、ASUS社から最新のBIOSと各種ドライバを確保し、アップデートを行いました。
BIOSの更新に伴って某社のロゴマークは消えましたが、BIOSもドライバもすべて最新版としたことで、不具合が解消されたのが確認できました。

ということで、昔語りでした。
まあ、常識で考えれば、自社製品の維持管理を他社に丸投げするとか、普通ありえないですよね。
他社製品を使ってPCを組み立てているから、対応は製品を製造したメーカーに対応してもらえってことなのでしょうが、富士通とかは特にマザーボードは特注品である可能性が高いため、それは望めません。
そして、そんな特注品のマザーボードのドライバを、わざわざMicrosoft社が自社のお金で作ってくれるとも思えません。
よって、さらに細かい分野、例えばLANやオーディオはRealtek社の部品が使われているから、LANドライバやオーディオドライバはRealtek社から回収してこようとか、そういった部品メーカー単位で調べていく必要があるかと思われます。
それなりの知識を必要としますし、当然時間もかかります。
ですが、身に付ければPC関連では応用の効く知識にもなりますし、検討してみられるのも一つかもしれませんね。
  • IVNO
  • 2022/06/30 (Thu) 16:09:32
ドライバ確認可能なツールもありはしますが
こんばんは。
昨日はレスできなくてごめんなさい。

IVNOさん、またフォローありがとうございます。
PC本体に限らず各メーカーはサポートをどんどん削る方向に動いているのは自分が伏魔殿を立ち上げたころから目に見えていましたね。
日本人ユーザーからの問い合わせに対して日本語が微妙な外国人オペレーターが電話対応しだしてからはユーザー離れも加速してましたし。

Ridさん、ドライバをログから見ることができるツールもいくつかありますが、それらのツールを案内するのは控えておきます。
自分もそういうツールを使用していますが、使い方を間違えると前述のシステム系ツール同様深刻な不具合に直結するからです。

>そうなりますと、現状解析としては、これ以上は不要と見てよろしいしょうか?

現時点で自分のアタマで考え付く範囲では感染の恐れは低く、それ以外の面でも今のところ自分ができることはほとんどないと思われます(←単に役立たず
わからないことに対して無理に作業を提示して傷口広げるよなことはできませんので、安全優先の面からこれ以上の作業は止めておきます。
  • 悪代官
  • 2022/07/01 (Fri) 21:52:06
ありがとうございました
悪代官さん、IVNOさん

何度も何度も本当にありがとうございました……。
心配性が過ぎるのもいけないと思いつつも……。

①感染の心配はほぼない
②メモ帳はプリインストールアプリかドライバ
③予測変換はアクティビティ履歴
④PCに現状、不審な動きはない

ということから、本件は解決とさせていただきます。
ドライバに関しては時間があるときに、知識として調べてみようとは思います。

以上です。ありがとうございました。
  • Rid
  • 2022/07/01 (Fri) 22:07:49

返信フォーム






プレビュー (投稿前に内容を確認)