悪代官の伏魔殿掲示板
検索語:
OR  AND

Baiduの残骸は見えますね
こんばんは、IVNOと申します。
Baiduなど感染していた痕跡は見えていますね。
ただこちらでは基本的に駆除のご案内とそれに付随するご案内しかしておりません。
これは規約にも記述していることですので、万一感染以外の原因で重いと言うのであれば、
そちらに関しては当掲示板では対策をご案内いたしません。
精密検査を行い、その結果次第で対応するか否かを決めたいと思います。

以下のソフトウェアをご準備ください。

OldTimer Listit(通称:OTL)
http://oldtimer.geekstogo.com/OTL.exe
直リンクです。デスクトップ等、分かりやすい場所に保存してください。
削除する際は起動後に「Cleanup」ボタンを押すことにより、自動的に削除されます。
ただし、Windows 10の方に限り「Cleanup」ボタンを押さずにファイルのみ削除してください。
このOTLでのスキャンは再度ご案内する場合がありますが、
その際はこちらの手順をそのまま繰り返していただくこととなります。
OTLで再度スキャンをと言われた場合、こちらの作業のやり直しをお願いいたします。

OTLを起動させる前にブラウザを含め、可能な限りのソフトウェアを終了させてください。
ソフトウェアの終了が完了しましたら、OTLを起動させてください。
表示画面上部中央にあるScan All Usersにチェックを入れてください。
設定が完了しましたら、Custom Scan/Fixesの項目内に以下をコピペしてください。

------コピペこの下より------
SHOWHIDDEN
%windir%\tasks\*.job
DRIVES
BASESERVICES
%SYSTEMDRIVE%\*.exe
ACTIVEX
CREATERESTOREPOINT
------コピペこの上まで------

コピペが完了しましたら、Run Scanをクリックしてスキャンを行ってください。
スキャン完了まで数分程度かかりますので、今しばらくお待ちください。
スキャンが完了しましたら、OTLを保存した場所と同じところに、
OTL.txtとExtras.txtが出力されますので、そちらを貼り付けてご連絡ください。
なお、OTLはその特性上、非常に長文となります。
こちらの掲示板の文字数上限がひらがな換算で約3万文字、英数字換算で約6万文字です。
確実に文字数オーバーとなりますので、余裕を見て5万5千文字程度になるように、
以下のURLの文字数カウンター等で確認しつつ、ログを分割されてご連絡ください。
http://www2u.biglobe.ne.jp/~yuichi/rest/strcount.html
  • IVNO
  • 2015/10/17 (Sat) 04:03:01
リカバリ
富士通のHPからリカバリをしてみましたが、2時間ほどかかりまして
今終了しました。
しかし、まだ何もセキュリティなど何もいれていない状態のはずですが、
リカバリ前と全く同じ様な気がします。

なにかまちがっていますでしょうか?

ログを取ってみました。

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 11:43:11, on 2015/10/17
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16708)


Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMECMNT.EXE
C:\Windows\System32\igfxpers.exe
C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Fujitsu\DustSolution\HokoriApp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Fujitsu\IndicatorUtility\IndicatorUty.exe
C:\Program Files\Fujitsu\Fujitsu Quick Touch\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Fujitsu\PowerUtility\schedule\PUSCDaemon.exe
C:\Program Files\Fujitsu\PowerUtility\schedule\PUSCKAPLEXE.exe
C:\Program Files\Fujitsu\Plugfree NETWORK\PfNet.exe
C:\Program Files\Fujitsu\chitose\updatenv.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Creative\Sound Blaster X-Fi Go Pro\Volume Panel\VolPanlu.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\K7 Computing\K7TSecurity\k7tsecurity.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\K7 Computing\K7TSecurity\K7SysMon.Exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Terry\Documents\Downloads\HijackThis (4).exe

O1 - Hosts: ::1 localhost
O2 - BHO: K7 Web Protection - {08B3B4B6-02DA-4658-8BA6-5974E3EBB03D} - C:\Program Files\K7 Computing\K7TSecurity\K7SRExt.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Incredibar.com Helper Object - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files\Incredibar.com\incredibar\1.5.3.27\bh\incredibar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - (no file)
O3 - Toolbar: Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.3.27\incredibarTlbr.dll
O3 - Toolbar: K7 Web Protection - {8551D65A-13A9-4e63-8472-9325B1B928C0} - C:\Program Files\K7 Computing\K7TSecurity\K7SRExt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LoadFUJ02E3] C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TvOutSwitch] c:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe
O4 - HKLM\..\Run: [FJDust] c:\Program Files\Fujitsu\DustSolution\HokoriApp.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\IndicatorUtility\IndicatorUty.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Fujitsu Quick Touch\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [LoadPUSCDaemon] C:\Program Files\Fujitsu\PowerUtility\schedule\PUSCDaemon.exe
O4 - HKLM\..\Run: [PUSCKAPLEXE] C:\Program Files\Fujitsu\PowerUtility\schedule\PUSCKAPLEXE.exe
O4 - HKLM\..\Run: [IME JPN 2007 Migration] C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEJP\IMJPKLMG.EXE /Preload
O4 - HKLM\..\Run: [PfNet] C:\Program Files\FUJITSU\Plugfree NETWORK\PFNet.exe /r
O4 - HKLM\..\Run: [FJUPDNV_Chitose] C:\Program Files\Fujitsu\chitose\updatenv.exe
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi Go Pro\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Corel\Corel MyPhoto\Corel Photo Downloader.exe" -startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Creative SB Monitoring Utility] RunDll32 sbavmon.dll,SBAVMonitor
O4 - HKLM\..\Run: [K7TSStart] C:\Program Files\K7 Computing\K7TSecurity\K7TSecurity.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} (DMM Downloader) - http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab
O16 - DPF: {1DC420F0-D89A-40D0-B5CC-92B9AD19A1AC} (HGPluginJP28 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP28.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{569ECBA1-D676-4E8C-94F7-F482CF8AE881}: NameServer = 192.168.3.1
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FjDstService - FUJITSU LIMITED - c:\Program Files\Fujitsu\DustSolution\FJDService.exe
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: K7Carnivore Service (K7CrvSvc) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7CrvSvc.exe
O23 - Service: K7Computng - EMail Proxy Server (K7EmlPxy) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7EmlPxy.exe
O23 - Service: K7Firewall Services (K7FWSrvc) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7FWSrvc.exe
O23 - Service: K7Privacy Services (K7PSSrvc) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7PSSrvc.exe
O23 - Service: K7RealTime AntiVirus Services (K7RTScan) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7RTScan.exe
O23 - Service: K7SpmSrc - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7SpmSrc.exe
O23 - Service: K7TotalSecurity Manager (K7TSMngr) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7TSMngr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PFNService - Unknown owner - C:\Program Files\FUJITSU\Plugfree NETWORK\PFNService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: PowerUtility - スケジュール機能 (PUSCSRVC) - FUJITSU LIMITED - C:\Program Files\Fujitsu\PowerUtility\schedule\PUSCSRVC.exe
O23 - Service: PowerUtility Remote Power Management Service (putlrsrv) - FUJITSU LIMITED - C:\PROGRA~1\Fujitsu\POWERU~1\remote\PUTLRSRV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: UpdateNaviInstallService - FUJITSU LIMITED - c:\Program Files\Fujitsu\chitose\updnvsrv.exe
O23 - Service: xsherlock - Wellbia.com Co., Ltd. - C:\Windows\system32\xsherlock.xem

--
End of file - 10298 bytes


1ClickDownload 1ClickDownload 2012/03/12 1.23 MB 2.1 Build 26473
3D MediaSurfing 富士通株式会社 2008/10/24 36.3 MB V4.0
@niftyでブロードバンド ニフティ株式会社 2011/02/25 256 KB
Adobe AIR Adobe Systems Incorporated 2011/09/03 29.7 MB 2.7.1.19610
Adobe Flash Media Live Encoder 3.2 Adobe Systems Incorporated 2011/05/12 14.0 MB 3.2.0
Adobe Flash Player 19 ActiveX Adobe Systems Incorporated 2015/10/17 19.0.0.226
Adobe Flash Player 19 NPAPI Adobe Systems Incorporated 2015/10/17 19.0.0.226
ALPS Touch Pad Driver Alps Electric 2008/10/09
AmaRecTV Live 2011/05/05 1.04 MB
AmvVideoCodec 2011/08/07 7.65 MB
Apple Application Support(32 ビット) Apple Inc. 2015/02/06 95.4 MB 3.1.1
Apple Mobile Device Support Apple Inc. 2015/02/06 22.5 MB 8.1.0.18
Apple Software Update Apple Inc. 2011/12/27 2.38 MB 2.1.3.127
Broadway 5.0.12 Voralent Computer Service 2013/05/04 7.71 MB 10.18.850
CamStudio OSS Desktop Recorder CamStudio Open Source Dev Team 2011/05/17 14.9 MB 2.6 Beta r294
Canon Auto Update Service Canon Inc. 2012/08/15 1.89 MB 1.1.2.18
CANON iMAGE GATEWAY MyCamera Download Plugin Canon Inc. 2012/08/15 616 KB 3.1.1.2
CANON iMAGE GATEWAY Task for ZoomBrowser EX Canon Inc. 2012/08/15 48.1 MB 1.9.0.9
Canon MOV Decoder Canon Inc. 2012/08/15 4.65 MB 1.9.0.8
Canon MOV Encoder Canon Inc. 2012/08/15 2.85 MB 1.8.0.1
Canon MovieEdit Task for ZoomBrowser EX Canon Inc. 2012/08/15 48.1 MB 3.9.0.6
Canon PhotoRecord 2012/08/15
Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX Canon Inc. 2012/08/15 2.00 MB 1.0.0.10
Canon Utilities PhotoStitch 2012/08/15 3.1.20.44
Canon Utilities RemoteCapture 2.5 2012/08/15 7.55 MB
Canon Utilities ZoomBrowser EX Canon Inc. 2012/08/15 6.9.0.1
Canon ZoomBrowser EX Memory Card Utility Canon Inc. 2012/08/15 11.7 MB 1.6.0.15
CCleaner Piriform 2015/10/15 9.21 MB 5.10
CPUID CPU-Z 1.60.1 2012/07/30 3.01 MB
Craving Explorer Version 1.5.0 T-Craft / tuck 2012/10/18 15.3 MB 1.5.0.0
Creative システム インフォメーション Creative Technology Limited 2011/08/07 1.17 MB 1.10
FM かんたんバックアップ 富士通株式会社 2008/10/09 6.27 MB 5.0
FMVユーザー登録 富士通株式会社 2008/10/09 V3.2L10
FMV辞書セット(広辞苑第六版+現代用語の基礎知識+学研パーソナル統合辞典) 富士通株式会社 2008/10/09 4.00 KB 1.0.0
Fujitsu Display Manager FUJITSU LIMITED 2008/10/09 5.62 MB 61.32.0.0
Google Chrome Google Inc. 2013/08/19 453 MB 46.0.2490.71
HP Photosmart Essential HP 2011/07/24 10.1 MB 1.12.0.46
HP Product Detection Hewlett-Packard Company 2011/07/24 1.90 MB 10.7.9.0
HP Update Hewlett-Packard 2015/10/07 3.94 MB 5.005.002.002
HPSSupply 会社名 2011/07/24 987 KB 2.1.3.0000
iCloud Apple Inc. 2014/04/19 112 MB 2.1.3.25
Incredibar Toolbar on IE and Chrome 2012/03/10 2.01 MB
IndicatorUtility 富士通株式会社 2008/10/09 248 KB 3.3.0.0
Inspirium辞書検索ライブラリ Fujitsu 2008/10/09 604 KB 2.0.0
Intel(R) Graphics Media Accelerator Driver Intel Corporation 2011/02/25
its-moNavi PC ZENRIN 2008/10/09 15.6 MB 5.6.0
Java 8 Update 51 Oracle Corporation 2015/09/30 77.1 MB 8.0.510
Lhaplus 2011/04/16 3.22 MB
LightCapture I-O DATA DEVICE,INC. 2011/08/07 5.62 MB 1.00.0000
Microsoft .NET Framework 3.5 Language Pack SP1 - 日本語 Microsoft Corporation 2011/04/09 36.7 MB
Microsoft .NET Framework 3.5 SP1 Microsoft Corporation 2011/02/26 36.7 MB
Microsoft .NET Framework 4.5.1 Microsoft Corporation 2014/08/06 289 MB 4.5.50938
Microsoft .NET Framework 4.5.1 (日本語) Microsoft Corporation 2014/09/05 38.6 MB 4.5.50938
Microsoft Automated Troubleshooting Services Shim 2014/09/05
Microsoft Expression Encoder 4 Microsoft Corporation 2011/05/03 81.2 MB 4.0.1651.0
Microsoft Expression Encoder 4 Screen Capture Codec Microsoft Corporation 2011/05/03 1.80 MB 4.0.1651.0
Microsoft Office File Validation Add-In Microsoft Corporation 2014/09/05 277 KB 14.0.5130.5003
Microsoft Office Personal 2007 Microsoft Corporation 2014/01/17 275 MB 12.0.6612.1000
Microsoft Office ナビ 2007 Microsoft Corporation 2011/02/25 12.0.6701.1000
Microsoft PowerPoint 2010 Microsoft Corporation 2015/07/04 517 MB 14.0.7015.1000
Microsoft Silverlight Microsoft Corporation 2015/09/30 20.3 MB 5.1.40728.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 2011/04/17 251 KB 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2011/06/17 294 KB 8.0.61001
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Corporation 2011/05/06 199 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Corporation 2012/12/31 1.41 MB 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2011/05/04 590 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2011/06/17 594 KB 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2015/03/29 742 KB 10.0.40219
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Microsoft Corporation 2015/03/29 5.53 MB 10.0.50903
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - 日本語 Microsoft Corporation 2015/03/29 5.53 MB 10.0.50903
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2011/02/26 35.0 KB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2011/02/26 1.33 MB 4.20.9876.0
Mumble and Murmur Mumble 2011/04/18 22.0 MB 1.1.3
MyBookEditor3 Asukanet Co.,Ltd. 2008/10/09 11.4 MB 1.0.4
PC乗換ガイド 富士通株式会社 2008/10/09 7.57 MB
Plugfree NETWORK 富士通株式会社 2008/10/09 19.1 MB 4.6.0.1
PowerUtility - スケジュール機能 富士通株式会社 2008/10/09
PowerUtility - リモート管理機能 富士通株式会社 2008/10/09 30.3 MB
RealPlayer RealNetworks 2011/10/06 92.4 MB
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2008/10/09 26.6 MB 6.0.1.5689
Realtek USB 2.0 Card Reader Realtek Semiconductor Corp. 2008/10/09 4.01 MB
Roxio Creator LJ Roxio 2011/02/25 5.25 MB 10.1
Sound Blaster X-Fi Go! Pro Creative Technology Limited 2011/08/07 57.0 MB 1.0
Windows Media エンコーダ 9 シリーズ 2008/10/24 13.9 MB
Windows Movie Maker 2.6 Microsoft Corporation 2012/03/04 12.3 MB 2.6.4040.0
WinDVD for FUJITSU InterVideo Inc. 2008/10/09 110 MB 8.0-B9.596
お手入れナビ FUJITSU LIMITED 2008/10/09 3.82 MB 1.0.51.1
ゆったり設定2 富士通株式会社 2008/10/09 V3.0L22
らくらく手書き入力 FUJITSU LIMITED 2008/10/09 7.23 MB 4.0.44
アップデートナビ FUJITSU LIMITED 2008/10/09 1.43 MB 1.2.0027
ウイルスセキュリティ ソースネクスト株式会社 2015/10/03 394 MB 14.00
セキュリティ対策ソフト選択 富士通株式会社 2008/10/23
パソコン準備ばっちりガイド 富士通株式会社 2008/10/09
マイフォト Corel Corporation 2008/10/09 47.7 MB 1.001.0006
メールソフト切り替えツール 富士通株式会社 2008/10/09 736 KB
ワンタッチボタン設定 富士通株式会社 2008/10/09 6.45 MB 7.3.0.0
乗換案内 旅費精算 Jorudan Co,.Ltd. 2008/10/09 5.28 MB 1.2.0.186
壁紙かんたん模様替え 富士通株式会社 2008/10/09
富士通モビリティセンター拡張 FUJITSU LIMITED 2008/10/09 316 KB 1.0.1.0
富士通拡張機能ユーティリティ 富士通株式会社 2008/10/09 212 KB 2.8.0.0
電子辞書 富士通株式会社 2008/10/09 14.1 MB V2.0
@フォトレタッチ 富士通株式会社 2008/10/09 17.5 MB
@メニュー 富士通株式会社 2008/10/09
@映像館 富士通株式会社 2008/10/09 294 MB
@FTP 富士通株式会社 2008/10/09 224 KB 20.0.0.0
FMV画面で見るマニュアル 富士通株式会社 2015/10/17 547 MB V16L10



  • hatimitu
  • 2015/10/17 (Sat) 12:07:31
マルウェアに感染したようです
chromeでインターネットを使っていたところマルウェアを拾ってきたようです。
windowsDifenderで検出されたのですが、解決に至っていないので解決方法がございましたらご教示ください。

URLを開いたりしたときに、毎回広告サイトに飛んでしまいます。

HJTのログ
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 12:06:34, on 2015/10/17
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Lenovo\Lenovo Transition\Lenovo Transition.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\ProgramData\YogaSmartSwicth\yogaserver.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\kenya\AppData\Local\Microsoft\BingSvc\BingSvc.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files (x86)\Lenovo\MotionControl\MotionControl.exe
C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\kenya\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Naver\LINE\LINE.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\kenya\Downloads\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll
O4 - HKLM\..\Run: [YouCam Mirage] "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_903DE78A6F239CBC42F4A265295F473C] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [Dropbox Update] "C:\Users\kenya\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
O4 - HKCU\..\Run: [BingSvc] C:\Users\kenya\AppData\Local\Microsoft\BingSvc\BingSvc.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [Application Restart #0] C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe /Crashed (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Application Restart #0] C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe /Crashed (User 'Default user')
O4 - Startup: Dropbox.lnk = C:\Users\kenya\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: IO Control.lnk = ?
O4 - Global Startup: Motion Control.lnk = C:\Program Files (x86)\Lenovo\MotionControl\MotionControl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Bluetoothデバイスにページを送信する - C:\Program Files (x86)\REALTEK\Realtek Bluetooth\btsendto_ie.htm
O8 - Extra context menu item: Bluetoothデバイスに画像を送信する - C:\Program Files (x86)\REALTEK\Realtek Bluetooth\btsendto_ie_ctx.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\REALTEK\Realtek Bluetooth\LANG\BtServer_LANG.dll,-134 - {D870B030-8D66-423b-9B97-894D4A0DEC23} - C:\Program Files (x86)\REALTEK\Realtek Bluetooth\btsendto_ie.htm (HKCU)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\REALTEK\Realtek Bluetooth\LANG\BtServer_LANG.dll,-134 - {D870B030-8D66-423b-9B97-894D4A0DEC23} - C:\Program Files (x86)\REALTEK\Realtek Bluetooth\btsendto_ie.htm (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\agilent\io libraries suite\lximdnsnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O20 - AppInit_DLLs:
O23 - Service: Agilent Communications Fabric (AgilentCommunicationsFabric) - Keysight Technologies - C:\Program Files (x86)\Agilent\Communications\Fabric\AgilentCommunicationsFabric.exe
O23 - Service: Agilent Instrument Discovery Service (AgilentInstrumentDiscoveryService) - Keysight - C:\Program Files\Agilent\IO Libraries Suite\ACE2-Service.exe
O23 - Service: Agilent IO Libraries Service (AgilentIOLibrariesService) - Keysight - C:\Program Files\Agilent\IO Libraries Suite\AgilentIOLibrariesService.exe
O23 - Service: Agilent PXI Resource Manager (AgilentPXIResourceManager) - Keysight - C:\Program Files (x86)\Agilent\IO Libraries Suite\AgilentPXIResourceManager.exe
O23 - Service: Agilent mDNS Responder Service (AgtMdnsResponder) - Keysight Technologies - C:\Program Files\Agilent\IO Libraries Suite\LxiMdnsResponder.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: BTDevManager - Unknown owner - C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Conexant Audio Message Service (CxAudMsg) - Unknown owner - C:\WINDOWS\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: Altera JTAG Server (JTAGServer) - Unknown owner - c:\altera\12.1\quartus\bin64\jtagserver.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ymc - Lenovo - C:\ProgramData\YogaSmartSwicth\Server\x64\ymc.exe

--
End of file - 11439 bytes


CCのログ
7-Zip 9.20 (x64 edition) Igor Pavlov 2014/04/16 4.53 MB 9.20.00.0
Arduino Arduino LLC 2015/04/06 251 MB 1.0.5-r2
Canon IJ Scan Utility Canon Inc. 2015/05/31
Canon MG7100 series MP Drivers Canon Inc. 2015/05/31 1.01
CCleaner Piriform 2015/10/17 5.10
Dropbox Dropbox, Inc. 2015/10/05 3.10.7
Energy Management Lenovo 2013/01/15 49.8 MB 8.0.2.4
GOM Player Gretech Corporation 2015/08/30 2.2.73.5235
Google Chrome Google Inc. 2013/03/28 46.0.2490.71
HI-TECH Universal Toolsuite plugin for MPLAB V1.37PL0 HI-TECH Software 2013/04/25 1.37
Intel(R) Dynamic Platform and Thermal Framework Intel Corporation 2013/11/14 6.0.5.1080
Intel(R) Management Engine Components Intel Corporation 2013/04/23 8.1.0.1252
Intel(R) Processor Graphics Intel Corporation 2013/11/15 10.18.10.3316
Intel(R) SDK for OpenCL - CPU Only Runtime Package Intel Corporation 2013/11/14 2.0.0.37149
IObit Uninstaller IObit 2014/10/17 4.0.4.1
Java 8 Update 60 Oracle Corporation 2015/09/21 20.6 MB 8.0.600.27
Java 8 Update 60 (64-bit) Oracle Corporation 2015/09/21 22.7 MB 8.0.600.27
Java SE Development Kit 8 Update 45 (64-bit) Oracle Corporation 2015/05/18 278 MB 8.0.450.15
Keysight Communications Fabric KeysightTechnologies, Inc. 2015/01/20 749 KB 1.3.18619.11620
Keysight IO Libraries Suite 17.0 Keysight Technologies 2015/01/20 14.2 MB 17.0.19013.0
Lenovo EasyCamera Lenovo EasyCamera 2013/11/14 7.66 MB 3.4.5.13
Lenovo OneKey Recovery CyberLink Corp. 2013/11/14 8.0.0.0710
Lenovo Transition Lenovo 2013/11/14 1.4.2.20
Lenovo YouCam CyberLink Corp. 2013/01/15 211 MB 4.1.3127
LINE LINE Corporation 2015/10/16 4.1.3.586
Microsoft .NET Framework 4 Multi-Targeting Pack Microsoft Corporation 2014/09/11 83.4 MB 4.0.30319
Microsoft Help Viewer 1.0 Microsoft Corporation 2014/09/11 3.97 MB 1.0.30319
Microsoft Office Korrekturhilfen 2013 - Deutsch Microsoft Corporation 2013/11/18 35.8 MB 15.0.4420.1017
Microsoft Office Professional Plus 2013 - ja-jp Microsoft Corporation 2015/09/24 15.0.4753.1003
Microsoft SQL Server 2008 R2 Data-Tier Application Project Microsoft Corporation 2014/09/11 14.1 MB 10.50.1447.4
Microsoft SQL Server 2008 R2 Transact-SQL Language Service Microsoft Corporation 2014/09/11 5.41 MB 10.50.1447.4
Microsoft SQL Server 2008 R2 データ層アプリケーション フレームワーク Microsoft Corporation 2014/09/11 383 KB 10.50.1447.4
Microsoft SQL Server 2008 R2 管理オブジェクト Microsoft Corporation 2014/09/11 17.2 MB 10.50.1447.4
Microsoft SQL Server 2008 R2 管理オブジェクト (x64) Microsoft Corporation 2014/09/11 10.4 MB 10.50.1447.4
Microsoft SQL Server Compact 3.5 SP2 JPN Microsoft Corporation 2014/09/11 4.89 MB 3.5.8080.0
Microsoft SQL Server Compact 3.5 SP2 x64 JPN Microsoft Corporation 2014/09/11 7.08 MB 3.5.8080.0
Microsoft SQL Server Database Publishing Wizard 1.4 Microsoft Corporation 2014/09/11 10.1 MB 10.1.2512.8
Microsoft SQL Server System CLR Types Microsoft Corporation 2014/09/11 2.58 MB 10.50.1447.4
Microsoft SQL Server System CLR Types (x64) Microsoft Corporation 2014/09/11 3.15 MB 10.50.1447.4
Microsoft Team Foundation Server 2010 オブジェクト モデル - 日本語 Microsoft Corporation 2014/09/11 10.0.30319
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2013/01/15 4.99 MB 8.0.56336
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2013/09/05 12.4 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2013/01/15 13.1 MB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2013/04/11 19.9 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2014/09/01 10.1 MB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 Microsoft Corporation 2014/09/11 10.1 MB 9.0.30729.4974
Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319 Microsoft Corporation 2014/09/11 314 KB 10.0.30319
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2013/01/15 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319 Microsoft Corporation 2014/09/11 20.2 MB 10.0.30319
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2013/01/15 11.1 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319 Microsoft Corporation 2014/09/11 15.6 MB 10.0.30319
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 Microsoft Corporation 2015/01/20 20.5 MB 11.0.51106.1
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 Microsoft Corporation 2015/01/20 17.4 MB 11.0.51106.1
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Microsoft Corporation 2014/09/11 10.0.30319
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - 日本語 Microsoft Corporation 2014/09/11 10.0.30319
Microsoft Visual Studio Macro Tools Microsoft Corporation 2014/09/11 9.0.30729
Microsoft Visual Studio Macro Tools - JPN Language Pack Microsoft Corporation 2014/09/11 9.0.30729
Microsoft ヘルプ ビューアー 1.0 Language Pack - JPN Microsoft Corporation 2014/09/11 1.95 MB 1.0.30319
ModelSim-Altera 10.1b (Quartus II 12.1) Starter Edition (Build 177) Altera Corporation 2013/11/14 3.12 GB
Motion Control Lenovo 2013/11/14 1.1.2.41
OneKey Recovery CyberLink Corp. 2013/04/23 8.0.0.0710
Pool Virtual Heap corp 2013/11/14 1.0.7
Quartus II 12.1 Web Edition (Build 177) Altera Corporation 2013/11/14 4.67 GB
Realtek USB 2.0 Card Reader Realtek Semiconductor Corp. 2013/01/15 6.1.8400.39030
REALTEK Wireless LAN and Bluetooth Driver REALTEK Semiconductor Corp. 2013/01/15 1.00.0196
sakura editor(サクラエディタ) サクラエディタ開発チーム 2013/05/07 4.63 MB
scilab-5.5.1 (64-bit) Scilab Enterprises 2015/10/08 442 MB
Shared C Run-time for x64 McAfee 2013/01/15 1.38 MB 10.0.0
Skype(TM) 7.7 Skype Technologies S.A. 2015/07/26 71.2 MB 7.7.102
Synaptics Pointing Device Driver Synaptics Incorporated 2014/02/19 46.4 MB 16.2.21.4
Update for Japanese Microsoft IME Postal Code Dictionary Microsoft Corporation 2014/10/31 7.60 MB 16.0.1171.1
Update for Japanese Microsoft IME Standard Dictionary Microsoft Corporation 2015/09/07 41.7 MB 16.0.1404.1
Update for Japanese Microsoft IME Standard Extended Dictionary Microsoft Corporation 2015/09/07 11.6 MB 15.0.2013
Update for Japanese Microsoft IME Trending Words Dictionary Microsoft Corporation 2015/05/31 9.00 KB 16.0.1515.1
VISA Shared Components 64-Bit IVI Foundation 2015/01/20 1.6
Visual Studio 2010 Prerequisites - English Microsoft Corporation 2014/09/11 6.12 MB 10.0.30319
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 JPN Microsoft Corporation 2014/09/11 11.2 MB 4.0.8080.0
Windows ドライバ パッケージ - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) Lenovo 2013/11/14 06/15/2012 8.1.0.1
Windows ドライバ パッケージ - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) Lenovo 2013/11/14 06/19/2012 10.13.29.733
『Let's CASLⅡ(Vista用)』 2014/10/10
  • 龍戦士
  • 2015/10/17 (Sat) 12:24:27
OTLのログ送付&状況報告
ご返信ありがとうございます。
OTLのログと状況をご報告します。

①OTLのログ

---
All processes killed
========== OTL ==========
C:\Users\Tatsu\AppData\Roaming\mozilla\Firefox\Profiles\wn2i11us.default\extension-data\toolbar_ORJ-SPE@apn.ask.com\jsonstore\toolbar folder moved successfully.
C:\Users\Tatsu\AppData\Roaming\mozilla\Firefox\Profiles\wn2i11us.default\extension-data\toolbar_ORJ-SPE@apn.ask.com\jsonstore folder moved successfully.
C:\Users\Tatsu\AppData\Roaming\mozilla\Firefox\Profiles\wn2i11us.default\extension-data\toolbar_ORJ-SPE@apn.ask.com folder moved successfully.
C:\Users\Tatsu\AppData\Roaming\mozilla\firefox\profiles\wn2i11us.default\searchplugins\-customized-web-search.xml moved successfully.
C:\Users\Tatsu\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjaooagfdhdhmbfchnkhggjmacjlacla\0.2.4_0\_metadata folder moved successfully.
C:\Users\Tatsu\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjaooagfdhdhmbfchnkhggjmacjlacla\0.2.4_0 folder moved successfully.
C:\Users\Tatsu\AppData\Local\Google\Chrome\User Data\Default\Extensions\omdhfcagdlpjbpfldpabhkdibdcbaiih\3.4_0\images folder moved successfully.
C:\Users\Tatsu\AppData\Local\Google\Chrome\User Data\Default\Extensions\omdhfcagdlpjbpfldpabhkdibdcbaiih\3.4_0 folder moved successfully.
C:\Users\Tatsu\AppData\Roaming\NewSoft\PRTemp folder moved successfully.
C:\Users\Tatsu\AppData\Roaming\NewSoft folder moved successfully.
C:\Users\Tatsu\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine folder moved successfully.
C:\Users\Tatsu\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs folder moved successfully.
C:\Users\Tatsu\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware folder moved successfully.
C:\Users\Tatsu\AppData\Roaming\Malwarebytes folder moved successfully.
C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Logs folder moved successfully.
C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Configuration folder moved successfully.
C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware folder moved successfully.
C:\ProgramData\Malwarebytes folder moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4AEB8EF2-8229-4B0F-9A3B-A2B8C44B65CA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4AEB8EF2-8229-4B0F-9A3B-A2B8C44B65CA}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{676030FD-F736-4196-91B4-5265C612D5E6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{676030FD-F736-4196-91B4-5265C612D5E6}\ not found.
========== FILES ==========
c:\program files (x86)\Veoh Networks\VeohWebPlayer\skins\black\Playback folder moved successfully.
c:\program files (x86)\Veoh Networks\VeohWebPlayer\skins\black\library folder moved successfully.
c:\program files (x86)\Veoh Networks\VeohWebPlayer\skins\black\forms folder moved successfully.
c:\program files (x86)\Veoh Networks\VeohWebPlayer\skins\black folder moved successfully.
c:\program files (x86)\Veoh Networks\VeohWebPlayer\skins folder moved successfully.
c:\program files (x86)\Veoh Networks\VeohWebPlayer folder moved successfully.
c:\program files (x86)\Veoh Networks folder moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: Tatsu
->Flash cache emptied: 58137 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYJAVA]

User: All Users

User: Default

User: Default User

User: Public

User: Tatsu
->Java cache emptied: 0 bytes

Total Java Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Tatsu
->Temp folder emptied: 4852174 bytes
->Temporary Internet Files folder emptied: 3318403 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 201074044 bytes
->Google Chrome cache emptied: 7677111 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1557185 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 239 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
RecycleBin emptied: 2657378554 bytes

Total Files Cleaned = 2,743.00 mb

Unable to start System Restore Service. Error code 1084

OTL by OldTimer - Version 3.2.69.0 log created on 10172015_114708

Files\Folders moved on Reboot...
C:\Users\Tatsu\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Tatsu\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
---

②状況報告
暫定処置以降、一度もLaSuperbaの広告は出ておりません。
PCがビジー状態になることもなく、見た目には何ら問題ありません。

ご確認よろしくお願いします。
  • ぽっぽ
  • 2015/10/17 (Sat) 12:30:41
Re: DNS unlockerという広告が出てしまいます
失礼しました。貼り忘れてました。

有効 HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run EPLTarget\P0000000000000000 SEIKO EPSON CORPORATION C:\windows\system32\spool\DRIVERS\x64\3\E_IATIIGJ.EXE /EPT "EPLTarget\P0000000000000000" /M "PX-045A Series" /EF "HKCU"
無効 HKLM:Run AtwtusbIcon WALTOP International Corporation C:\WINDOWS\System32\AtwtusbIcon.exe
有効 HKLM:Run cAudioFilterAgent Conexant Systems, Inc. C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe
有効 HKLM:Run EEventManager SEIKO EPSON CORPORATION "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
有効 HKLM:Run HotKeysCmds Intel Corporation C:\windows\system32\hkcmd.exe
有効 HKLM:Run IgfxTray Intel Corporation C:\windows\system32\igfxtray.exe
有効 HKLM:Run IME14 JPN Setup Microsoft Corporation C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
有効 HKLM:Run IntelPAN Intel(R) Corporation "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
有効 HKLM:Run iTunesHelper Apple Inc. "C:\Program Files\iTunes\iTunesHelper.exe"
有効 HKLM:Run LLHDUSER Intercom, Inc. "C:\Program Files (x86)\Intercom\LAPLINK HelpDesk Client\llhuser.exe"
有効 HKLM:Run Persistence Intel Corporation C:\windows\system32\igfxpers.exe
有効 HKLM:Run SmartAudio Conexant systems, Inc. C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
有効 HKLM:Run SunJavaUpdateSched Oracle Corporation "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
有効 HKLM:Run SynTPEnh Synaptics Incorporated %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
無効 HKLM:Run TCrdMain TOSHIBA Corporation %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
有効 HKLM:Run Teco "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
有効 HKLM:Run TKRTL TOSHIBA Corporation %ProgramFiles%\TOSHIBA\TKRTL\KarteLite.exe -h
無効 HKLM:Run ToshibaPlacesGadget "C:\Program Files (x86)\Toshiba Places Gadget\ToshibaPlacesGadget.exe" -atboottime
有効 HKLM:Run TosSENotify TOSHIBA Corporation C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
有効 HKLM:Run TosWaitSrv TOSHIBA Corporation %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
無効 HKLM:Run TouchFree C:\Program Files (x86)\TOSHIBA\TouchFree\TouchFreeTray.exe
有効 HKLM:Run TPSCMain TOSHIBA Corporation %ProgramFiles%\TOSHIBA\PeakShift\TPSCMain.exe
有効 HKLM:Run TPwrMain TOSHIBA Corporation %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
有効 HKLM:Run TSleepSrv TOSHIBA %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
有効 HKLM:Run TSUScheduler TOSHIBA Corporation %ProgramFiles(x86)%\TOSHIBA\Sync Utility\TosSyncScheduler.exe
有効 HKLM:Run Unattend0000000001{B59BFB3E-8CFD-4B5A-A936-B3766895D6AB} AnywhereWorking L.T.D. C:\tosutils\palakidou\palakidou.exe
  • とらまる
  • 2015/10/17 (Sat) 13:39:11