知恵袋で質問している件
知恵袋でお世話になっております、shinzou_puripuriです。
こちらにログを投稿させて頂きます。
ご確認をお願い致します。
お手数をおかけして申し訳ありませんが、完全削除できるまでご協力して頂けると助かります…!



HJTのログ↓

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 8:22:29, on 2016/12/06
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18525)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Lenovo\Lsf\LsfHelper.exe
C:\Program Files (x86)\Lenovo\Lsf\Lsf.exe
C:\Program Files (x86)\Lenovo\PCManager\LenovoTray.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe
C:\Users\youazuma\AppData\Local\Chromium\Application\chrome.exe
C:\Users\youazuma\AppData\Local\Temp\is-H1278.tmp\popwnd.exe
C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe
C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe
C:\Program Files (x86)\wanttoxiamen\uc.exe
C:\Users\youazuma\AppData\Local\Chromium\Application\chrome.exe
C:\Program Files (x86)\UCBrowser\Application\5.7.16400.16\Installer\setup.exe
C:\Users\youazuma\AppData\Local\Chromium\Application\chrome.exe
C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\JWord\Plugin2\jwdsrch.exe
C:\Users\youazuma\AppData\Roaming\UPUpdata\cleaner.exe
C:\Program Files (x86)\wanttoxiamen\uc.exe
C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe
C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe
C:\Program Files\Tablet\Wacom\32\WacomDesktopCenter.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
C:\Windows\Temp\5DBD.tmp
C:\Windows\Temp\5DBE.tmp
C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Users\youazuma\Downloads\HijackThis.exe

R3 - URLSearchHook: MyUrlSearchHook Class - {2ACECADE-0BC7-4C6F-95CF-A221CC161B52} - C:\PROGRA~2\JWord\Plugin2\jwdsrch.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Yahoo!ツールバーフィッシング警告 - {1F68E72C-50E5-44B8-8F56-6A54D3AF1DA4} - C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\ypho.dll
O2 - BHO: Yahoo!ツールバーヘルパー - {EEBA90E6-2B14-413F-9BF8-61A8BDF92258} - C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\YahooToolBar.dll
O3 - Toolbar: Yahoo!ツールバー - {AEF44653-C059-42CB-A5B7-41C640DA4A67} - C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\YahooToolBar.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [jwdsrch] C:\Program Files (x86)\JWord\Plugin2\jwdsrch.exe
O4 - HKLM\..\Run: [cleaner] C:\Users\youazuma\AppData\Roaming\UPUpdata\cleaner.exe
O4 - HKLM\..\Run: [app] C:\Program Files (x86)\wanttoxiamen\uc.exe
O4 - HKLM\..\Run: [LsfHelper] "C:\Program Files (x86)\Lenovo\Lsf\LsfHelper.exe"
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe"
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_5850FDE37EF22CDAB7B2FC1F7CA062A9] "C:\Users\youazuma\AppData\Local\Chromium\Application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
O4 - HKCU\..\Run: [msiql] C:\Users\youazuma\AppData\Local\Temp\is-H1278.tmp\popwnd.exe /RUNNING
O4 - HKCU\..\Run: [svchost0] "C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe"\UUC0789.exe
O4 - HKCU\..\Run: [osmsg] C:\ProgramData\WindowsMsg\Chrome.exe /AUTORUN
O4 - HKCU\..\Run: [apphide] C:\Program Files (x86)\wanttoxiamen\uc.exe
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\youazuma\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\youazuma\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: JWord プラグイン - {34D67ED2-C837-4627-838C-2264E347D291} - http://www.jword.jp/intro/?partner=AP&type=lk&frm=iebutton&pver=2 (file missing)
O9 - Extra 'Tools' menuitem: JWord プラグインについて - {34D67ED2-C837-4627-838C-2264E347D291} - http://www.jword.jp/intro/?partner=AP&type=lk&frm=iebutton&pver=2 (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O11 - Options group: [JWDSearch] JWord プラグイン
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GoogleChromeUpService - Unknown owner - C:\ProgramData\service.exe
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Memory Stick Wheel Mouse (jeguwuze) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LenovoPcManagerService - Lenovo Corporation - C:\Program Files (x86)\Lenovo\PCManager\LenovoPcManagerService.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MaohaWiFiService (MaohaWifiSvr) - 深?市猫哈网?科技?展有限公司 - C:\Program Files (x86)\Maoha\MaohaAP\MaohaWifiSvr.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: The Calendar Service (TheCalendarService) - Unknown owner - C:\Program Files (x86)\CalendarTool\2.0.0.11382\CalendarServ.exe
O23 - Service: UC??器基?服? (UCBrowserSvc) - Unknown owner - C:\Program Files (x86)\UCBrowser\Application\UCService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wacom Professional Service (WTabletServicePro) - Wacom Technology, Corp. - C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
O23 - Service: 主?防御 (ZhuDongFangYu) - Unknown owner - C:\Program Files (x86)\360\360Safe\deepscan\zhudongfangyu.exe (file missing)
O23 - Service: Double Spaced Firewall (zigipyro) - Unknown owner - C:\Users\youazuma\AppData\Local\03000200-1481004981-0500-0006-000700080009\qnsh6F48.tmp

--
End of file - 10959 bytes



  • puri
  • 2016/12/08 (Thu) 05:36:43
Re: 知恵袋で質問している件
CCのログ↓


Adobe Flash Player 10 ActiveX Adobe Systems Incorporated 2014/10/06 6.00 MB 10.2.152.32
Adobe Illustrator CS2 Adobe Systems Inc. 2016/02/19 12.000.000
Adobe Photoshop CS2 Adobe Systems, Inc. 2016/02/19 9.0
Adobe Reader X (10.0.1) - Japanese Adobe Systems Incorporated 2014/10/06 131 MB 10.0.1
Adobe SVG Viewer 3.0 Adobe Systems, Inc. 2016/02/19 3.0
Advanced Calendar 2.0.0.11382 MEIXIAN XIE 2015/09/21 2.0.0.11382
Becky! Ver.2 RimArts 2015/09/20
Body Text Feathering Body Text Feathering 2016/12/06 1.0.0.0
Canon MP Navigator EX 4.0 2015/05/11
CanoScan LiDE 210 Scanner Driver Canon Inc. 2015/05/11
CCleaner Piriform 2016/12/06 5.24
CyberLink Media Suite 10 CyberLink Corp. 2015/08/23 962 MB 10.0
CyberLink PowerDVD 10 CyberLink Corp. 2015/08/23 183 MB 10.0.4508.02
Google Chrome Google Inc. 2016/12/06 55.0.2883.75
Intel(R) Control Center Intel Corporation 2015/05/08 1.2.1.1010
Intel(R) Manageability Engine Firmware Recovery Agent Intel Corporation 2014/10/06 54.8 MB 1.0.0.36702
Intel(R) Management Engine Components Intel Corporation 2015/05/08 9.0.0.1310
Intel(R) Processor Graphics Intel Corporation 2015/05/08 10.18.10.3496
Intel(R) USB 3.0 eXtensible Host Controller Driver Intel Corporation 2015/05/08 3.0.0.19
JWord プラグイン JWord, Inc. 2016/01/23 2.1.0.7
Kingsoft Office 2013 (9.1.0.4059) Kingsoft Corp. 2014/10/06 9.1.0.4059
Microsoft .NET Framework 4.6.1 Microsoft Corporation 2016/02/11 38.8 MB 4.6.01055
Microsoft .NET Framework 4.6.1 (日本語) Microsoft Corporation 2016/05/20 2.93 MB 4.6.01055
Microsoft Silverlight Microsoft Corporation 2016/10/13 299 MB 5.1.50901.0
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2015/09/21 300 KB 8.0.61001
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2014/10/06 608 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2014/10/06 586 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2015/09/21 598 KB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/06 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/06 11.1 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 2016/08/16 17.3 MB 11.0.61030.0
Mozilla Maintenance Service Mozilla 2015/09/20 250 KB 38.2.0
Mozilla Thunderbird 38.4.0 (x86 ja) Mozilla 2016/03/13 79.9 MB 38.4.0
Rakuten Kobo Desktop Rakuten Kobo Inc. 2016/08/16 3.19.3765
Realtek Ethernet Controller Driver Realtek 2014/10/06 7.78.1218.2013
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2014/10/06 6.0.1.7188
WebTablet FB Plugin 32 bit Wacom Technology Corp. 2015/05/08 2.1.0.7
WebTablet FB Plugin 64 bit Wacom Technology Corp. 2015/05/08 2.1.0.7
WinRAR 4.00 beta 4 (32-bit) win.rar GmbH 2016/10/23 4.00.4
Yahoo!ツールバー Yahoo! JAPAN. 2016/01/23 4.01 MB 8.0.0.3
ペイントツールSAI Ver.1 2015/05/08
ワコム タブレット Wacom Technology Corp. 2015/05/08 6.3.11-4
  • puri
  • 2016/12/08 (Thu) 05:38:48
絶望的な感染量です
こんばんは、IVNOと申します。
悪代官さんのご案内の方でしたか。
件名のとおりとはなるのですが、絶望的な感染量です。
中華系マルウェアの大量感染、偽Google Chrome、挙句はトロイの木馬と、マルウェアの見本市状態となっております。
とりあえずこのまま放ってはおけないので処置を行うのですが、一点利用規約に影響しそうな部分があります。
イラフォトが導入されていますので、次回レスの際にイラフォトの導入理由について差し支えない範囲でお知らせください。
また感染の恐れがある古いソフトウェアはここで削除をご案内いたします。

それでは作業準備を行いましょう。

まずはじめに連絡事項がございます。
相談いただいてから回答できるまでに、毎回1日かそれ以上かかる可能性もございます。
ご不便をおかけいたしますが、ご理解とご協力を賜りますよう、お願い申し上げます。
また、回答者側から「解決」と通達があるまで、駆除作業は続いております。
そのため、途中でPCの状況が良くなったかのように感じたからと言って、解決のご案内を待たずして作業を中断なされると、
高確率で再発しているのが現状で、再発時にこちらにお戻りになられる方が続出しております。
回答者から「解決」と「自衛策」の案内があるまでは、作業を続けるようにしてください。

それでは以下の説明を熟読し、順番に作業をお願いします。
既に準備した物もある場合があります、その場合でも一応説明を再度ご確認ください。

隠しファイルと拡張子を表示設定にしてください(やり方↓)
http://pasofaq.jp/windows/mycomputer/hiddenfile.htm
http://support.microsoft.com/kb/978449/ja

下記のツールをダウンロードし、作業指示のある場合にのみ手順に従ってお使いください。
ただし、配布サイトで他のソフトウェアをダウンロードしろと勧めてくるような広告も出てくる可能性がありますが、
それらは絶対にクリックしないようになされてください。

GeekUninstaller(以下GU)
ダウンロード
http://www.geekuninstaller.com/geek.zip
ファイル直リンクです。zipファイルですので使用前に展開してください。
展開が完了した後のzipファイルは不要となりますので、そちらは削除を行ってください。
GU本体の削除を案内された際は、そのままごみ箱に処分してください。

CCleaner(以下CC)
説明↓
http://www.gigafree.net/system/clean/ccleaner.html
http://note.chiebukuro.yahoo.co.jp/detail/n178757
ダウンロード↓
http://www.piriform.com/ccleaner/download/standard
最新バージョンをダウンロードするようにしましょう。
なお、インストール時におまけのアプリも勧めてくることがありますが、それらはチェック外してインストールは避けてください。
削除の際はGUなどでアンインストールしてください。

ここで重要な注意です。
CCは本来は高い性能を持つメンテナンスソフトですが、間違った使い方すると
【操作次第ではWindowsが動作しなくなる可能性もある】
ので、ここでは解析ツールとしてのみ使います。
説明をしっかり読み、こちらが指示した以外の操作はしないようになされてください。

以降の駆除作業でトラブルが発生しても直ちに復旧できるよう、システムの復元ポイントを手動で作成しましょう。
http://windows.microsoft.com/ja-jp/windows7/create-a-restore-point
しかし、システムの復元はPCにかなりのダメージを与えますので、できれば使わないほうが望ましいです。
システムの復元が必要のない、慎重な作業を心がけましょう。

それでは処置を開始しましょう。

PCをセーフモードで起動してください。
Windows Vistaまたは7の方は以下を参考になされてください。
http://www.pc-master.jp/sousa/s-safemode.html
Windows 8または8.1の方は以下を参考になされてください。
http://121ware.com/qasearch/1007/app/servlet/relatedqa?QID=015917
Windows 10の方は以下を参考になされてください。
https://121ware.com/qasearch/1007/app/servlet/relatedqa?QID=017878

HJTを起動させ、今一度スキャンを行ってください。
スキャン結果が表示されましたら、以下の項目にチェックを入れてください。
ただし、特にHJTでの作業は一歩間違えれば簡単にPCが起動しなくなるため、
こちらが指示した以外のものは絶対にチェックを入れないでください。

R3 - URLSearchHook: MyUrlSearchHook Class - {2ACECADE-0BC7-4C6F-95CF-A221CC161B52} - C:\PROGRA~2\JWord\Plugin2\jwdsrch.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [cleaner] C:\Users\youazuma\AppData\Roaming\UPUpdata\cleaner.exe
O4 - HKLM\..\Run: [app] C:\Program Files (x86)\wanttoxiamen\uc.exe
O4 - HKCU\..\Run: [msiql] C:\Users\youazuma\AppData\Local\Temp\is-H1278.tmp\popwnd.exe /RUNNING
O4 - HKCU\..\Run: [svchost0] "C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe"\UUC0789.exe
O4 - HKCU\..\Run: [osmsg] C:\ProgramData\WindowsMsg\Chrome.exe /AUTORUN
O4 - HKCU\..\Run: [apphide] C:\Program Files (x86)\wanttoxiamen\uc.exe
O9 - Extra button: JWord プラグイン - {34D67ED2-C837-4627-838C-2264E347D291} - http://www.jword.jp/intro/?partner=AP&type=lk&frm=iebutton&pver=2 (file missing)
O9 - Extra 'Tools' menuitem: JWord プラグインについて - {34D67ED2-C837-4627-838C-2264E347D291} - http://www.jword.jp/intro/?partner=AP&type=lk&frm=iebutton&pver=2 (file missing)
O11 - Options group: [JWDSearch] JWord プラグイン
O23 - Service: GoogleChromeUpService - Unknown owner - C:\ProgramData\service.exe
O23 - Service: Memory Stick Wheel Mouse (jeguwuze) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: MaohaWiFiService (MaohaWifiSvr) - 深?市猫哈网?科技?展有限公司 - C:\Program Files (x86)\Maoha\MaohaAP\MaohaWifiSvr.exe
O23 - Service: UC??器基?服? (UCBrowserSvc) - Unknown owner - C:\Program Files (x86)\UCBrowser\Application\UCService.exe
O23 - Service: 主?防御 (ZhuDongFangYu) - Unknown owner - C:\Program Files (x86)\360\360Safe\deepscan\zhudongfangyu.exe (file missing)
O23 - Service: Double Spaced Firewall (zigipyro) - Unknown owner - C:\Users\youazuma\AppData\Local\03000200-1481004981-0500-0006-000700080009\qnsh6F48.tmp

必要な項目すべてにチェックが入りましたら、Fix checkedをクリックしてください。
上記のFixが完了したら、GUを起動させ、以下を削除してください。

Adobe Reader X (10.0.1) - Japanese Adobe Systems Incorporated 2014/10/06 131 MB 10.0.1
Body Text Feathering Body Text Feathering 2016/12/06 1.0.0.0
JWord プラグイン JWord, Inc. 2016/01/23 2.1.0.7

GU上に表示されているソフトウェアをダブルクリックで削除できます。
削除が完了すると自動的にスキャンが開始されますので、
スキャンが完了しましたらOKを押して削除を完了させてください。
GUでのアンインストールが完了しましたら、GUを終了させてください。
Windowsインストーラーがどうとかの表示が出た場合はPCを通常モードで再起動し、
その状態で改めて該当ソフトウェアのみをアンインストールしてください。
通常モードとセーフモードを使い分けながらご案内しているすべてのソフトウェアの削除が完了するまで続けてください。
PCを通常モードで再起動させてください。
キーボードの左Ctrlと左Altの間にあるスタートボタンを押しながらRボタンを押します。
ファイル名を指定して実行と言うものが起動しますので、そちらに半角英数で以下を入力してください。

cleanmgr

入力が完了しましたらエンターキーを押してください。
C:ドライブを選択してOKを押します。
スキャンが開始されますので完了するまでお待ちください。
スキャンが完了すると一覧が表示されますので、すべてにチェックを入れてOKを押してください。
ただし、OKを押すとごみ箱の中身を含めてすべて削除されますので、
ごみ箱の中に必要なファイルが入っている場合はご注意ください。
ここまで終了しましたら、改めましてHJTのログ、CCのインストール情報ログをご相談前に行っていただく作業の手順に従って再取得し、
そちらで取得したログをすべて貼り付けてご連絡をお願いいたします。
……とまぁ、イラフォトの導入理由を聞くのは後記の悪代官さんのレスの内容が理由となるのです。
ちなみに、イラストレーターとフォトショップを縮めてイラフォトと業界では呼ばれています。
この2つは並行して利用することが多いため、セットで呼ばれるようになりました。
と言う豆知識です。
  • IVNO
  • 2016/12/08 (Thu) 06:04:12
追加でPC環境の説明もお願いします
こんばんは。
知恵袋から移動された方ですね。
http://detail.chiebukuro.yahoo.co.jp/qa/question_detail/q14167631599

あちらでもレスしたakuda_ikanこと悪代官です。
ログを見せてもらいました。
IVNOさんも説明されてますが、予想以上にくらってますね。
それもそのはずです。
UCBrowserを入れちゃってますね。
これはご自身で必要として入れたものですか?

UCBrowserはC国製のブラウザと言われてますが、実際はブラウザと言うより他の意味や性質を持つようなモノです。
おそらくそれを介して更によくないモノも呼び込んだ疑いがあります。

自分から見てもログ全体を見る限りまったく油断できない状態です。
はっきり言えば安全優先の意味では、必要なデータのバックアップしたうえで一度PCのリカバリして仕切り直すのがもっとも簡単かつ確実です。

ですがリカバリを避けたいなら、ある程度手間を覚悟で作業してもらうことになります。
それを厭わないなら解決は可能でしょう。。

まずはIVNOさんが指示された作業のあと、続きのログと説明をレスください。
それを見てからIVNOさんか自分がまたレスに来ましょう。

それとは別に追加の確認もお願いします。

お使いのPCはお仕事に使っているPCですか?
業務にも使うようなAdobe製の高価なアプリ等がログに見えてます。
Adobe Illustrator CS2 Adobe Systems Inc. 2016/02/19 12.000.000
Adobe Photoshop CS2 Adobe Systems, Inc. 2016/02/19 9.0

お仕事使用のPCで起きたトラブルには外部の人間はまずタッチできないと思ってください。
処置の成否に関係なく、重大な責任問題にまで発展します。

完全にお仕事とは無縁の個人・私用PCなら支障ない範囲でPC環境の説明をレスください。
説明で協力可能と判断できたら改めて処置レスしていきますが、本当にお仕事PCならこれ以上のログ提示や説明は止めておくのがいろいろな意味で無難と思ってください
  • 悪代官
  • 2016/12/08 (Thu) 20:04:27
再度ログを取りました
レス有難うございます…!
ご協力頂けて大変感謝しております。

指示通り作業し、ログを取りましたのでご確認お願い致します。
あまり変わっていないような…

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 7:18:11, on 2016/12/09
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18525)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Lenovo\Lsf\LsfHelper.exe
C:\Program Files (x86)\Lenovo\Lsf\Lsf.exe
C:\Program Files (x86)\Lenovo\PCManager\LenovoTray.exe
C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
C:\Program Files (x86)\Lenovo\PCManager\LenovoMessage.exe
C:\Users\youazuma\Downloads\HijackThis.exe

O2 - BHO: Yahoo!ツールバーフィッシング警告 - {1F68E72C-50E5-44B8-8F56-6A54D3AF1DA4} - C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\ypho.dll
O2 - BHO: Yahoo!ツールバーヘルパー - {EEBA90E6-2B14-413F-9BF8-61A8BDF92258} - C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\YahooToolBar.dll
O3 - Toolbar: Yahoo!ツールバー - {AEF44653-C059-42CB-A5B7-41C640DA4A67} - C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\YahooToolBar.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [LsfHelper] "C:\Program Files (x86)\Lenovo\Lsf\LsfHelper.exe"
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe"
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_5850FDE37EF22CDAB7B2FC1F7CA062A9] "C:\Users\youazuma\AppData\Local\Chromium\Application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [osmsg] C:\ProgramData\WindowsMsg\Chrome.exe /AUTORUN
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\youazuma\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\youazuma\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: WAN New Document (kuwitizo) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: LenovoPcManagerService - Lenovo Corporation - C:\Program Files (x86)\Lenovo\PCManager\LenovoPcManagerService.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MaohaWiFiService (MaohaWifiSvr) - 深?市猫哈网?科技?展有限公司 - C:\Program Files (x86)\Maoha\MaohaAP\MaohaWifiSvr.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: The Calendar Service (TheCalendarService) - Unknown owner - C:\Program Files (x86)\CalendarTool\2.0.0.11382\CalendarServ.exe
O23 - Service: UC??器基?服? (UCBrowserSvc) - Unknown owner - C:\Program Files (x86)\UCBrowser\Application\UCService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wacom Professional Service (WTabletServicePro) - Wacom Technology, Corp. - C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
O23 - Service: 主?防御 (ZhuDongFangYu) - Unknown owner - C:\Program Files (x86)\360\360Safe\deepscan\zhudongfangyu.exe (file missing)

--
End of file - 8474 bytes
  • puri
  • 2016/12/09 (Fri) 07:25:37
CCのログ
Adobe Flash Player 10 ActiveX Adobe Systems Incorporated 2014/10/06 6.00 MB 10.2.152.32
Adobe Illustrator CS2 Adobe Systems Inc. 2016/02/19 12.000.000
Adobe Photoshop CS2 Adobe Systems, Inc. 2016/02/19 9.0
Adobe SVG Viewer 3.0 Adobe Systems, Inc. 2016/02/19 3.0
Advanced Calendar 2.0.0.11382 MEIXIAN XIE 2015/09/21 2.0.0.11382
Becky! Ver.2 RimArts 2015/09/20
Canon MP Navigator EX 4.0 2015/05/11
CanoScan LiDE 210 Scanner Driver Canon Inc. 2015/05/11
CCleaner Piriform 2016/12/06 5.24
CyberLink Media Suite 10 CyberLink Corp. 2015/08/23 962 MB 10.0
CyberLink PowerDVD 10 CyberLink Corp. 2015/08/23 183 MB 10.0.4508.02
Google Chrome Google Inc. 2016/12/06 55.0.2883.75
Intel(R) Control Center Intel Corporation 2015/05/08 1.2.1.1010
Intel(R) Manageability Engine Firmware Recovery Agent Intel Corporation 2014/10/06 54.8 MB 1.0.0.36702
Intel(R) Management Engine Components Intel Corporation 2015/05/08 9.0.0.1310
Intel(R) Processor Graphics Intel Corporation 2015/05/08 10.18.10.3496
Intel(R) USB 3.0 eXtensible Host Controller Driver Intel Corporation 2015/05/08 3.0.0.19
Kingsoft Office 2013 (9.1.0.4059) Kingsoft Corp. 2014/10/06 9.1.0.4059
Microsoft .NET Framework 4.6.1 Microsoft Corporation 2016/02/11 38.8 MB 4.6.01055
Microsoft .NET Framework 4.6.1 (日本語) Microsoft Corporation 2016/05/20 2.93 MB 4.6.01055
Microsoft Silverlight Microsoft Corporation 2016/10/13 299 MB 5.1.50901.0
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2015/09/21 300 KB 8.0.61001
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2014/10/06 608 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2014/10/06 586 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2015/09/21 598 KB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/06 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/06 11.1 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 2016/08/16 17.3 MB 11.0.61030.0
Mozilla Maintenance Service Mozilla 2015/09/20 250 KB 38.2.0
Mozilla Thunderbird 38.4.0 (x86 ja) Mozilla 2016/03/13 79.9 MB 38.4.0
Rakuten Kobo Desktop Rakuten Kobo Inc. 2016/08/16 3.19.3765
Realtek Ethernet Controller Driver Realtek 2014/10/06 7.78.1218.2013
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2014/10/06 6.0.1.7188
WebTablet FB Plugin 32 bit Wacom Technology Corp. 2015/05/08 2.1.0.7
WebTablet FB Plugin 64 bit Wacom Technology Corp. 2015/05/08 2.1.0.7
WinRAR 4.00 beta 4 (32-bit) win.rar GmbH 2016/10/23 4.00.4
Yahoo!ツールバー Yahoo! JAPAN. 2016/01/23 4.01 MB 8.0.0.3
ペイントツールSAI Ver.1 2015/05/08
ワコム タブレット Wacom Technology Corp. 2015/05/08 6.3.11-4
ソ・ケ 上海广乐网络科技有限公司 2016/12/08 2.8.25.4


UCBrowserに関しては、名前も知らないものなので勝手に入ったのだと思われます…

イラフォトに関してですが、仕事用のPCではなく趣味で使用する為に、公式サイトで無料提供されていたのを入れた記憶があります。
(詳しいことはうろ覚えで申し訳ありません…)

PC環境ですが、
OS:Windows 7 Home Premium
プロセッサ:Intel(R) Pentium(R) CPU G3220 @ 3.00GHz 3.00 GHz
実装メモリ:4.00GB (3.87GB使用可能)
システムの種類:64ビット オペレーティングシステム

他に伝えておかないといけないPC環境がありましたら、教えて下さい。

それでは、大変お手数をおかけして申し訳ありませんが、引き続き宜しくお願い致します。
  • puri
  • 2016/12/09 (Fri) 07:43:26
復活してますね
ログを見る限り、復活しているようです。
360 Safeも削除して、出所の確かな別のセキュリティソフトにしましょうか。
有料でも良ければ以下のようなものがあります。
https://eset-info.canon-its.jp/
私はこれの1台3年版がビックカメラで4800円くらいで売られていたのですが、
それをビックカメラのWebページの価格同等まで値切り、そこからさらに値切って税込3500円で購入できました。
同じようにすれば同じような価格で購入することができるかもしれませんのでご一考ください。
無料セキュリティに関しては自力駆除ができることが前提でのご利用を想定したものであるためおすすめしません。
それでもどうしても無料でとなるなら、MSE+EMETと言うマイクロソフト製ソフトウェアのご利用でも良いです。

さてこれから先の手順ですが、この状況でツールによる自動駆除を行うのはリスクが高いと判断します。
よって、OTLによる手動駆除を行った後、各種ツールを用いた自動駆除と言う流れで行くことにしましょう。

以下のソフトウェアをご用意ください。

OTL(OldTimer's List-It)
http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/
緑のDownloadボタンを押してダウンロードを行ってください。
ダウンロードが完了しましたら、わかりやすい場所に移動させておいてください。
なおOTLはHJT等と同じく通常起動時の異常個所を調査するために使いますので、
セーフモードでのスキャンは行わないようになされてください。
削除の際はOTLを起動させ、CleanUpボタンを押すことで削除が可能です。

準備ができましたら作業を開始しましょう。

OTLを起動させてください。
OTLが表示されましたら、上部中央にある「Scan All Users」にチェックを入れます。
「Costom Scans/Fixes」の項目に以下をコピペします。

------コピペここから------
SHOWHIDDEN
%windir%\tasks\*.job
DRIVES
BASESERVICES
%SYSTEMDRIVE%\*.exe
ACTIVEX
CREATERESTOREPOINT
------コピペここまで------

コピペが完了しましたら、OTLを除き、ブラウザを含めて可能な限りすべてのソフトウェアを終了させてください。
ソフトウェアを終了させたら、青い文字の「Run Scan」ボタンをクリックしてスキャンを行ってください。
スキャン完了まで数分程度かかりますので、今しばらくお待ちください。
スキャンが完了しましたら、OTLを保存した場所と同じところに、
OTL.txtとExtras.txtの2つのログが出力されますので、そちらをそれぞれ貼り付けてご連絡ください。
なお、OTLはその特性上、非常に長文となります。
文字数カウンター等のサイトを活用して文字数の合計が3万文字程度になるように調整し、
ログを分割されて貼り付けを行うようになされてください。
  • IVNO
  • 2016/12/09 (Fri) 16:49:52
OTL.txt ログ①
OTL logfile created on: 2016/12/10 7:58:15 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\youazuma\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18524)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

3.87 Gb Total Physical Memory | 3.08 Gb Available Physical Memory | 79.39% Memory free
7.75 Gb Paging File | 6.00 Gb Available in Paging File | 77.47% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 349.10 Gb Free Space | 74.97% Space Free | Partition Type: NTFS
Drive I: | 465.76 Gb Total Space | 437.57 Gb Free Space | 93.95% Space Free | Partition Type: NTFS

Computer Name: YOUAZUMA-PC | User Name: youazuma | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2016/12/10 07:55:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\youazuma\Downloads\OTL.exe
PRC - [2016/12/10 06:13:54 | 000,428,544 | ---- | M] () -- C:\Program Files (x86)\03000200-1480898246-0500-0006-000700080009\knsDABE.tmp
PRC - [2016/12/09 07:22:24 | 001,750,016 | ---- | M] () -- C:\Windows\Temp\D7CA.tmp
PRC - [2016/12/08 17:07:44 | 001,266,496 | ---- | M] (Lenovo Corporation) -- C:\Program Files (x86)\Lenovo\PCManager\LenovoTray.exe
PRC - [2016/12/08 17:07:40 | 000,848,200 | ---- | M] (Lenovo Corporation) -- C:\Program Files (x86)\Lenovo\PCManager\LenovoPcManagerService.exe
PRC - [2016/12/08 17:07:38 | 001,381,696 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\PCManager\LenovoMessage.exe
PRC - [2016/12/08 17:07:36 | 000,409,920 | ---- | M] (联想(北京)有限公司) -- C:\Program Files (x86)\Lenovo\PCManager\LenovoDRS.exe
PRC - [2016/12/06 06:05:26 | 000,288,920 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
PRC - [2016/11/30 10:12:42 | 002,146,192 | ---- | M] () -- C:\Program Files (x86)\UCBrowser\Application\5.7.16400.812\UCAgent.exe
PRC - [2016/11/30 10:05:10 | 000,935,312 | ---- | M] () -- C:\Program Files (x86)\UCBrowser\Application\UCService.exe
PRC - [2016/11/26 14:55:53 | 000,168,992 | ---- | M] (深圳市猫哈网络科技发展有限公司) -- C:\Program Files (x86)\Maoha\MaohaAP\MaohaWifiSvr.exe
PRC - [2016/10/14 13:51:28 | 002,157,408 | ---- | M] (联想软件) -- C:\Program Files (x86)\Lenovo\Lsf\Lsf.exe
PRC - [2016/10/14 13:51:28 | 000,890,720 | ---- | M] (联想软件) -- C:\Program Files (x86)\Lenovo\Lsf\LsfHelper.exe
PRC - [2016/05/20 11:02:40 | 000,151,152 | ---- | M] () -- C:\Program Files (x86)\CalendarTool\2.0.0.11382\CalendarServ.exe
PRC - [2014/03/06 10:08:50 | 000,292,848 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2013/02/16 08:17:18 | 000,366,552 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2013/02/16 08:17:16 | 000,131,544 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
PRC - [2013/02/16 08:17:12 | 000,169,432 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
PRC - [2012/10/09 08:15:51 | 000,039,808 | ---- | M] (Wacom Technology) -- C:\Program Files\Tablet\Wacom\WacomHost.exe
PRC - [2012/07/24 12:06:16 | 000,119,808 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
PRC - [2012/07/13 15:50:00 | 000,093,296 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2012/06/14 12:05:16 | 000,648,544 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
PRC - [2012/05/14 17:26:32 | 002,646,504 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe
PRC - [2011/03/09 14:21:54 | 000,107,816 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2016/12/09 07:22:24 | 001,750,016 | ---- | M] () -- C:\Windows\Temp\D7CA.tmp
MOD - [2016/11/30 10:12:42 | 002,146,192 | ---- | M] () -- C:\Program Files (x86)\UCBrowser\Application\5.7.16400.812\UCAgent.exe
MOD - [2012/07/24 12:06:16 | 000,119,808 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
MOD - [2012/07/04 18:13:50 | 001,780,848 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\Language\Jpn\P2GRC.dll
MOD - [2012/06/14 12:06:20 | 000,500,064 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll
MOD - [2012/06/14 11:57:22 | 000,015,872 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll
MOD - [2012/06/14 11:56:52 | 000,481,792 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll
MOD - [2012/06/14 11:55:22 | 000,013,824 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll
MOD - [2011/08/17 16:48:24 | 000,322,048 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll
MOD - [2011/08/17 16:48:22 | 000,195,584 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll
MOD - [2011/08/17 16:41:36 | 000,400,384 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll
MOD - [2011/08/15 20:17:30 | 009,224,704 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtGui4.dll
MOD - [2011/08/15 20:15:44 | 000,382,464 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll
MOD - [2011/08/15 20:12:04 | 002,603,520 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll
MOD - [2011/08/15 20:12:04 | 001,006,592 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll
MOD - [2011/08/15 19:23:00 | 000,062,464 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll
MOD - [2011/07/19 16:05:40 | 014,978,048 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtWebKit4.dll
MOD - [2011/07/19 16:04:56 | 000,317,952 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\phonon4.dll
MOD - [2011/03/09 14:21:56 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
MOD - [2011/03/09 14:21:56 | 000,144,680 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLVistaAudioMixer.dll
MOD - [2011/03/09 14:21:48 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2016/12/08 00:43:38 | 000,219,032 | ---- | M] () [Auto | Running] -- C:\Program Files\ソ・ケ\X86\kuaizipUpdateChecker.dll -- (KuaizipUpdateChecker)
SRV:[b]64bit:[/b] - [2016/10/28 03:37:41 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2016/08/23 01:19:43 | 001,386,496 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:[b]64bit:[/b] - [2015/02/27 07:16:37 | 000,672,024 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Wacom\WTabletServicePro.exe -- (WTabletServicePro)
SRV:[b]64bit:[/b] - [2014/03/12 09:16:00 | 000,282,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\igfxCUIService.exe -- (igfxCUIService1.0.0.0)
SRV:[b]64bit:[/b] - [2013/05/27 14:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2012/12/10 14:31:44 | 000,803,872 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2012/12/10 14:31:28 | 000,732,160 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
SRV - [2016/12/10 06:13:54 | 000,428,544 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\03000200-1480898246-0500-0006-000700080009\knsDABE.tmp -- (sirozysi)
SRV - [2016/12/08 17:07:40 | 000,848,200 | ---- | M] (Lenovo Corporation) [Auto | Running] -- C:\Program Files (x86)\Lenovo\PCManager\LenovoPcManagerService.exe -- (LenovoPcManagerService)
SRV - [2016/12/08 17:07:36 | 000,409,920 | ---- | M] (联想(北京)有限公司) [Auto | Running] -- C:\Program Files (x86)\Lenovo\PCManager\LenovoDRS.exe -- (LenovoDRS)
SRV - [2016/12/05 10:26:52 | 001,620,992 | ---- | M] () [Disabled | Stopped] -- C:\ProgramData\service.exe -- (GoogleChromeUpService)
SRV - [2016/11/30 10:05:10 | 000,935,312 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\UCBrowser\Application\UCService.exe -- (UCBrowserSvc)
SRV - [2016/11/26 14:55:53 | 000,168,992 | ---- | M] (深圳市猫哈网络科技发展有限公司) [Auto | Running] -- C:\Program Files (x86)\Maoha\MaohaAP\MaohaWifiSvr.exe -- (MaohaWifiSvr)
SRV - [2016/05/20 11:02:40 | 000,151,152 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\CalendarTool\2.0.0.11382\CalendarServ.exe -- (TheCalendarService)
SRV - [2016/02/15 11:36:54 | 000,147,624 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2015/11/05 20:36:48 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2014/03/21 07:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2014/03/12 09:16:04 | 000,279,024 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2013/02/16 08:17:18 | 000,366,552 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2013/02/16 08:17:16 | 000,131,544 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe -- (Intel(R)
SRV - [2013/02/16 08:17:12 | 000,169,432 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - File not found [Kernel | System | Running] -- C:\Windows\SysNative\drivers:ucdrv-x64.sys -- (ucdrv)
DRV:[b]64bit:[/b] - [2016/12/08 00:43:38 | 000,092,832 | ---- | M] (WinMount International Inc) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\KuaiZipDrive.sys -- (KuaiZipDrive)
DRV:[b]64bit:[/b] - [2016/12/01 17:07:10 | 000,097,728 | ---- | M] (Huorong Borui (Beijing) Technology Co., Ltd.) [Kernel | System | Unknown] -- C:\Windows\SysNative\drivers\lnvguard.sys -- (lnvguard)
DRV:[b]64bit:[/b] - [2016/08/29 19:46:57 | 000,081,792 | ---- | M] (Huorong Borui (Beijing) Technology Co., Ltd.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ucguard.sys -- (UCGuard)
DRV:[b]64bit:[/b] - [2016/07/18 13:37:20 | 000,405,224 | ---- | M] (360.cn) [File_System | System | Running] -- C:\Windows\SysNative\drivers\360FsFlt.sys -- (360FsFlt)
DRV:[b]64bit:[/b] - [2016/07/12 15:03:02 | 000,190,696 | ---- | M] (360.cn) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BAPIDRV64.SYS -- (BAPIDRV)
DRV:[b]64bit:[/b] - [2016/06/27 15:23:42 | 000,255,208 | ---- | M] (360安全中心) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\360Hvm64.sys -- (360Hvm)
DRV:[b]64bit:[/b] - [2016/06/12 11:11:20 | 000,081,344 | ---- | M] (360.cn) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\360netmon.sys -- (360netmon)
DRV:[b]64bit:[/b] - [2016/05/12 11:16:42 | 000,151,784 | ---- | M] (360.cn) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\360AntiHacker64.sys -- (360AntiHacker)
DRV:[b]64bit:[/b] - [2016/02/19 21:06:16 | 000,068,176 | ---- | M] (360.cn) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\360reskit64.sys -- (360reskit64)
DRV:[b]64bit:[/b] - [2015/10/16 16:35:10 | 000,321,616 | ---- | M] (360.cn) [File_System | System | Running] -- C:\Windows\SysNative\drivers\360Box64.sys -- (360Box64)
DRV:[b]64bit:[/b] - [2014/10/26 05:52:20 | 000,100,664 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wachidrouter.sys -- (WacHidRouter)
DRV:[b]64bit:[/b] - [2014/10/26 05:52:20 | 000,015,160 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomrouterfilter.sys -- (wacomrouterfilter)
DRV:[b]64bit:[/b] - [2014/10/26 05:52:20 | 000,014,136 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hidkmdf.sys -- (hidkmdf)
DRV:[b]64bit:[/b] - [2014/04/18 17:30:28 | 000,040,520 | ---- | M] (360.cn) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\360Camera64.sys -- (360Camera)
DRV:[b]64bit:[/b] - [2014/03/08 00:26:42 | 000,450,520 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2014/03/08 00:18:24 | 003,729,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2014/03/06 10:08:20 | 000,020,464 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:[b]64bit:[/b] - [2014/03/06 10:08:18 | 000,791,024 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:[b]64bit:[/b] - [2014/03/06 10:08:18 | 000,370,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:[b]64bit:[/b] - [2013/12/18 11:34:38 | 000,888,536 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2013/03/22 08:38:18 | 000,678,384 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:[b]64bit:[/b] - [2013/03/22 08:38:18 | 000,028,656 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorF.sys -- (iaStorF)
DRV:[b]64bit:[/b] - [2013/02/16 08:17:14 | 000,064,624 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:[b]64bit:[/b] - [2012/03/01 15:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2011/03/11 15:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011/03/11 15:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2010/11/21 12:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2010/11/21 12:23:47 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2010/11/21 12:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010/11/21 12:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2009/07/14 10:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/14 10:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/14 10:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/11 05:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2016/11/26 14:52:38 | 001,030,496 | ---- | M] () [Kernel | System | Running] -- C:\Program Files (x86)\Maoha\MaohaAP\MaoHaWiFiNet64.sys -- (MaohaWifiNetPro)
DRV - [2009/07/14 10:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://hao.360.cn/?installer
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-caeb2974&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{d4fee3d1-1014-4db8-a824-573bf9ab51c7}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://hao.360.cn/?installer
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://hao.360.cn/?installer
IE - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/ja-jp/?ocid=iehp
IE - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = ja
IE - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-caeb2974&q={searchTerms}
IE - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\..\SearchScopes\{d4fee3d1-1014-4db8-a824-573bf9ab51c7}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[color=#E56717]========== FireFox ==========[/color]

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll ( Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.7: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.7: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKLM\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 38.4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 38.4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 38.4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 38.4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2015/09/20 16:06:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\youazuma\AppData\Roaming\mozilla\Extensions

[color=#E56717]========== Chrome ==========[/color]

CHR - Extension: No name found = C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\
CHR - Extension: No name found = C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\kaefldlncokopeklgbllnmmnmdomodpj\1.0.0.3_0\
CHR - Extension: No name found = C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.0_0\
CHR - Extension: No name found = C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\paangjfdbofpdicjllcdhhojebiblepe\1.0.0.12_0\
CHR - Extension: No name found = C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
CHR - Extension: No name found = C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\

O1 HOSTS File: ([2016/12/05 09:36:40 | 000,001,006 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 down.baidu2016.com
O1 - Hosts: 127.0.0.1 123.sogou.com
O1 - Hosts: 127.0.0.1 www.czzsyzgm.com
O1 - Hosts: 127.0.0.1 www.czzsyzxl.com
O1 - Hosts: 127.0.0.1 union.baidu2019.com
O2:[b]64bit:[/b] - BHO: (Yahoo!ツールバーフィッシング警告) - {1F68E72C-50E5-44B8-8F56-6A54D3AF1DA4} - C:\Program Files\Yahoo!J\Toolbar64\8_0_0_3\Modules\ypho.dll (Yahoo Japan Corporation. )
O2:[b]64bit:[/b] - BHO: (Yahoo!ツールバーヘルパー) - {EEBA90E6-2B14-413F-9BF8-61A8BDF92258} - C:\Program Files\Yahoo!J\Toolbar64\8_0_0_3\Modules\YahooToolBar.dll (Yahoo! JAPAN)
O2 - BHO: (Yahoo!ツールバーフィッシング警告) - {1F68E72C-50E5-44B8-8F56-6A54D3AF1DA4} - C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\ypho.dll (Yahoo Japan Corporation. )
O2 - BHO: (Yahoo!ツールバーヘルパー) - {EEBA90E6-2B14-413F-9BF8-61A8BDF92258} - C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\YahooToolBar.dll (Yahoo! JAPAN)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Yahoo!ツールバー) - {AEF44653-C059-42CB-A5B7-41C640DA4A67} - C:\Program Files\Yahoo!J\Toolbar64\8_0_0_3\Modules\YahooToolBar.dll (Yahoo! JAPAN)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo!ツールバー) - {AEF44653-C059-42CB-A5B7-41C640DA4A67} - C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\YahooToolBar.dll (Yahoo! JAPAN)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:[b]64bit:[/b] - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKU\.DEFAULT..\Run: [] File not found
O4 - HKU\S-1-5-18..\Run: [] File not found
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000..\Run: [GoogleChromeAutoLaunch_5850FDE37EF22CDAB7B2FC1F7CA062A9] C:\Users\youazuma\AppData\Local\Chromium\Application\chrome.exe (The Chromium Authors)
O4 - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000..\Run: [osmsg] C:\ProgramData\WindowsMsg\Chrome.exe ()
O4 - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000..\Run: [Power2GoExpress] C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe (CyberLink Corp.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000..\RunOnce: [Uninstall C:\Users\youazuma\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\youazuma\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64" File not found
O4 - Startup: C:\Users\youazuma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
  • puri
  • 2016/12/10 (Sat) 08:36:50
OTL.txt ログ②
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 163.139.230.168 163.139.21.197
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9C37FE4A-43CC-44D3-ADDE-83321CE7C258}: DhcpNameServer = 163.139.230.168 163.139.21.197
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28:[b]64bit:[/b] - HKLM ShellExecuteHooks: {F88FBE68-AB36-11E6-A61B-64006A5CFC23} - C:\Users\youazuma\AppData\Roaming\Reezientaromry\Whatherrnuly.dll ()
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:[b]64bit:[/b] {26784146-6E05-3FF9-9335-786C7C0FB5BE} - .NET Framework
ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:[b]64bit:[/b] {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:[b]64bit:[/b] {66C64F22-FC60-4E6C-A6B5-F0D580E680CE} - C:\Windows\System32\ie4uinit.exe -EnableTLS
ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:[b]64bit:[/b] {7D715857-A67C-4C2F-A929-038448584D63} - C:\Windows\System32\ie4uinit.exe -DisableSSL3
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:[b]64bit:[/b] {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.75\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:[b]64bit:[/b] {BD6F5371-DAC1-30F0-9DDE-CAC6791E28C3} - .NET Framework
ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:[b]64bit:[/b] {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework
ActiveX: {26784146-6E05-3FF9-9335-786C7C0FB5BE} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {65122CB0-EA0F-47DF-A953-017170ED12F9} - "C:\Program Files (x86)\UCBrowser\Application\5.7.15319.5\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --wow-install-target-path="C:\Program Files (x86)\UCBrowser"
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {BD6F5371-DAC1-30F0-9DDE-CAC6791E28C3} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2016/12/10 00:46:57 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\reaper_data
[2016/12/10 00:36:33 | 000,097,728 | ---- | C] (Huorong Borui (Beijing) Technology Co., Ltd.) -- C:\Windows\SysNative\drivers\lnvguard.sys
[2016/12/08 00:43:36 | 000,000,000 | ---D | C] -- C:\Program Files\ソ・ケ
[2016/12/06 08:23:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2016/12/06 08:23:48 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2016/12/06 06:06:02 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Local\Google
[2016/12/06 06:05:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2016/12/06 05:42:25 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\360DiagnoseScan
[2016/12/06 05:42:24 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\Expert
[2016/12/06 05:42:24 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\360Login
[2016/12/06 05:20:04 | 000,000,000 | -HSD | C] -- C:\Users\youazuma\AppData\Roaming\360Quarant
[2016/12/06 05:20:04 | 000,000,000 | -HSD | C] -- C:\$360Section
[2016/12/06 05:15:49 | 000,000,000 | ---D | C] -- C:\ProgramData\360safe
[2016/12/06 05:15:47 | 000,068,176 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360reskit64.sys
[2016/12/06 05:15:38 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\360mobilemgr
[2016/12/06 05:15:29 | 000,405,224 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360FsFlt.sys
[2016/12/06 05:15:29 | 000,060,416 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360LanProtect.sys
[2016/12/06 05:15:24 | 000,190,696 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\BAPIDRV64.SYS
[2016/12/06 05:15:22 | 000,255,208 | ---- | C] (360安全中心) -- C:\Windows\SysNative\drivers\360Hvm64.sys
[2016/12/06 05:15:22 | 000,151,784 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360AntiHacker64.sys
[2016/12/06 05:15:21 | 000,040,520 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360Camera64.sys
[2016/12/06 05:15:20 | 000,000,000 | RHSD | C] -- C:\360SANDBOX
[2016/12/06 05:15:19 | 000,321,616 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360Box64.sys
[2016/12/06 05:15:15 | 000,180,336 | ---- | C] (360.cn) -- C:\Windows\SysWow64\360SoftMgr.cpl
[2016/12/06 05:15:13 | 000,081,344 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360netmon.sys
[2016/12/06 05:15:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360安全中心
[2016/12/06 05:07:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\360
[2016/12/06 05:06:52 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\360Safe
[2016/12/06 04:30:15 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\Geek Uninstaller
[2016/12/05 17:06:20 | 000,000,000 | ---D | C] -- C:\ProgramData\baidu
[2016/12/05 17:06:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Baidu
[2016/12/05 16:57:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2016/12/05 16:57:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Avg
[2016/12/05 16:57:53 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2016/12/05 16:55:46 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk
[2016/12/05 16:55:22 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Local\Fobiingarerterk
[2016/12/05 10:30:19 | 000,081,792 | ---- | C] (Huorong Borui (Beijing) Technology Co., Ltd.) -- C:\Windows\SysNative\drivers\ucguard.sys
[2016/12/05 10:29:36 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Local\CEF
[2016/12/05 10:29:28 | 000,000,000 | -HSD | C] -- C:\ProgramData\WindowsMsg
[2016/12/05 10:29:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
[2016/12/05 10:28:47 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\Lenovo
[2016/12/05 10:28:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lenovo
[2016/12/05 10:28:37 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Local\Lenovo
[2016/12/05 10:28:05 | 000,092,832 | ---- | C] (WinMount International Inc) -- C:\Windows\SysNative\drivers\KuaiZipDrive.sys
[2016/12/05 10:28:04 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\KuaiZip
[2016/12/05 10:27:30 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\Softlink
[2016/12/05 10:27:23 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Local\UCBrowser
[2016/12/05 10:27:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\UCBrowser
[2016/12/05 10:27:03 | 000,000,000 | -HSD | C] -- C:\Users\youazuma\AppData\Local\svchost
[2016/12/05 10:27:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MaohaWiFi
[2016/12/05 10:26:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Maoha
[2016/12/05 10:26:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Thunder Network
[2016/12/05 10:26:10 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\vnlgp
[2016/12/05 10:26:10 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\gplyra
[2016/12/05 09:40:29 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Local\app
[2016/12/05 09:40:24 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\Reezientaromry
[2016/12/05 09:40:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Thihurzuly
[2016/12/05 09:40:23 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\Profiles
[2016/12/05 09:40:23 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Local\Nicether
[2016/12/05 09:39:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wanttoxiamen
[2016/12/05 09:39:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\wanttoxiamen
[2016/12/05 09:39:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microleaves
[2016/12/05 09:38:25 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\UPUpdata
[2016/12/05 09:38:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CalendarTool
[2016/12/05 09:38:19 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Tools
[2016/12/05 09:38:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CleanBrowser
[2016/12/05 09:38:19 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\CalendarTool
[2016/12/05 09:38:16 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Guid
[2016/12/05 09:37:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\03000200-1480898246-0500-0006-000700080009
[2016/12/05 09:36:20 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\Microleaves
[2016/12/05 09:35:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Speed Up
[2016/12/05 09:35:27 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\efo
[2016/12/05 09:35:18 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\baidu
[2016/12/05 09:35:18 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Baidu
[2016/12/05 08:08:20 | 000,000,000 | ---D | C] -- C:\ProgramData\FFinder LTD
[2016/11/30 10:13:06 | 000,000,000 | ---D | C] -- C:\Users\youazuma\Desktop\よるとあさの歌
[2016/11/30 04:21:26 | 000,000,000 | ---D | C] -- C:\Users\youazuma\Desktop\未読
[2016/11/28 03:28:23 | 000,000,000 | ---D | C] -- C:\Users\youazuma\Desktop\新しいフォルダー
[2016/11/23 03:55:46 | 000,000,000 | ---D | C] -- C:\Users\youazuma\Desktop\商業bl
[2016/11/14 20:22:37 | 000,000,000 | ---D | C] -- C:\Users\youazuma\Desktop\俺と上司の

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2016/12/10 07:57:00 | 000,000,390 | ---- | M] () -- C:\Windows\tasks\WpsUpdateTask_Administrator.job
[2016/12/10 07:53:36 | 000,002,591 | ---- | M] () -- C:\Users\youazuma\Application Data\Microsoft\Internet Explorer\Quick Launch\Chromium.lnk
[2016/12/10 07:53:36 | 000,002,477 | ---- | M] () -- C:\Users\youazuma\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2016/12/10 07:53:36 | 000,002,453 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2016/12/10 07:53:36 | 000,001,074 | ---- | M] () -- C:\Users\youazuma\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2016/12/10 07:52:00 | 000,000,282 | ---- | M] () -- C:\Windows\tasks\UpdateTask.job
[2016/12/10 07:43:01 | 000,000,694 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2016/12/10 07:43:00 | 000,000,298 | ---- | M] () -- C:\Windows\tasks\UCBrowserUpdaterCore.job
[2016/12/10 07:42:53 | 000,000,462 | ---- | M] () -- C:\Windows\tasks\UCBrowserUpdater.job
[2016/12/10 07:42:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2016/12/10 06:10:03 | 000,000,690 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2016/12/10 04:13:28 | 000,000,526 | ---- | M] () -- C:\Windows\tasks\BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B}.job
[2016/12/10 04:01:42 | 000,021,840 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2016/12/10 04:01:42 | 000,021,840 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2016/12/09 06:51:50 | 000,000,001 | ---- | M] () -- C:\Windows\SysNative\drivers\360Hvm64.dat
[2016/12/09 06:51:43 | 3120,238,592 | -HS- | M] () -- C:\hiberfil.sys
[2016/12/08 00:43:38 | 000,092,832 | ---- | M] (WinMount International Inc) -- C:\Windows\SysNative\drivers\KuaiZipDrive.sys
[2016/12/08 00:43:38 | 000,000,809 | ---- | M] () -- C:\Users\youazuma\Desktop\ソ・ケ.lnk
[2016/12/06 08:27:57 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2016/12/05 17:43:31 | 000,196,998 | ---- | M] () -- C:\Users\youazuma\Desktop\新規キャンバス.jpg
[2016/12/05 16:55:49 | 000,001,099 | ---- | M] () -- C:\Users\youazuma\Desktop\クロックAT.lnk
[2016/12/05 10:27:04 | 000,001,137 | ---- | M] () -- C:\Users\youazuma\Application Data\Microsoft\Internet Explorer\Quick Launch\MaohaWiFi.lnk
[2016/12/05 10:27:03 | 000,001,113 | ---- | M] () -- C:\Users\youazuma\Desktop\MaohaWiFi.lnk
[2016/12/05 10:26:52 | 001,620,992 | ---- | M] () -- C:\ProgramData\service.exe
[2016/12/05 10:26:50 | 000,001,099 | ---- | M] () -- C:\Users\youazuma\Desktop\AutoTime.lnk
[2016/12/05 09:37:26 | 000,000,000 | ---- | M] () -- C:\TOSTACK
[2016/12/01 17:07:10 | 000,097,728 | ---- | M] (Huorong Borui (Beijing) Technology Co., Ltd.) -- C:\Windows\SysNative\drivers\lnvguard.sys

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2016/12/06 08:23:50 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2016/12/06 06:06:01 | 000,002,477 | ---- | C] () -- C:\Users\youazuma\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2016/12/06 06:06:01 | 000,002,465 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[2016/12/06 06:06:01 | 000,002,453 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2016/12/06 06:05:30 | 000,000,694 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2016/12/06 06:05:29 | 000,000,690 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2016/12/06 05:15:22 | 000,000,001 | ---- | C] () -- C:\Windows\SysNative\drivers\360Hvm64.dat
[2016/12/05 17:43:31 | 000,196,998 | ---- | C] () -- C:\Users\youazuma\Desktop\新規キャンバス.jpg
[2016/12/05 17:06:20 | 000,000,526 | ---- | C] () -- C:\Windows\tasks\BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B}.job
[2016/12/05 16:55:49 | 000,001,099 | ---- | C] () -- C:\Users\youazuma\Desktop\クロックAT.lnk
[2016/12/05 10:28:18 | 000,000,298 | ---- | C] () -- C:\Windows\tasks\UCBrowserUpdaterCore.job
[2016/12/05 10:28:09 | 000,000,462 | ---- | C] () -- C:\Windows\tasks\UCBrowserUpdater.job
[2016/12/05 10:28:04 | 000,000,809 | ---- | C] () -- C:\Users\youazuma\Desktop\ソ・ケ.lnk
[2016/12/05 10:27:04 | 000,001,137 | ---- | C] () -- C:\Users\youazuma\Application Data\Microsoft\Internet Explorer\Quick Launch\MaohaWiFi.lnk
[2016/12/05 10:27:03 | 000,001,113 | ---- | C] () -- C:\Users\youazuma\Desktop\MaohaWiFi.lnk
[2016/12/05 10:26:57 | 001,620,992 | ---- | C] () -- C:\ProgramData\service.exe
[2016/12/05 10:26:55 | 000,778,752 | ---- | C] () -- C:\Windows\SysNative\chtbrkg.dll
[2016/12/05 10:26:55 | 000,590,848 | ---- | C] () -- C:\Windows\SysWow64\chtbrkg.dll
[2016/12/05 10:26:50 | 000,001,099 | ---- | C] () -- C:\Users\youazuma\Desktop\AutoTime.lnk
[2016/12/05 09:37:26 | 000,000,000 | ---- | C] () -- C:\TOSTACK
[2016/02/19 16:33:46 | 000,016,384 | ---- | C] () -- C:\Windows\SysWow64\FileOps.exe
[2016/02/04 04:52:03 | 000,000,228 | ---- | C] () -- C:\Users\youazuma\AppData\Roaming\WB.CFG
[2016/02/04 03:52:19 | 000,000,242 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2015/12/19 03:04:56 | 001,291,102 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2015/05/10 20:08:50 | 000,393,256 | ---- | C] () -- C:\Windows\SysWow64\CNQ4809N.DAT
[2014/10/06 14:24:11 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009/07/14 13:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2016/08/30 00:31:19 | 014,183,424 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2016/08/30 00:12:50 | 012,880,384 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 10:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 12:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 10:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

  • puri
  • 2016/12/10 (Sat) 08:40:51
OTL.txt ログ③
[color=#E56717]========== Custom Scans ==========[/color]
[2015/05/06 19:24:24 | 000,000,000 | RH-D | M] -- C:\KRECYCLE
[2016/12/05 16:57:23 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
[2016/12/05 16:57:23 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
[2009/06/23 11:47:04 | 000,308,576 | -H-- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\MP Navigator EX 4.0\Maint.exe
[2015/06/10 03:54:13 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Common Files\nsklog
[2015/12/31 22:25:52 | 000,265,728 | -H-- | M] (Igor Pavlov) -- C:\Program Files (x86)\wanttoxiamen\111.exe
[2016/12/02 23:40:28 | 000,229,455 | -H-- | M] () -- C:\Program Files (x86)\wanttoxiamen\Bind.exe
[2015/05/11 09:47:47 | 000,000,000 | -H-D | M] -- C:\Program Files\CanonBJ
[2015/05/11 09:47:47 | 000,000,000 | -H-D | M] -- C:\Program Files\CanonBJ\IJScan
[2015/05/11 09:47:54 | 000,000,000 | -H-D | M] -- C:\Program Files\CanonBJ\IJScan\CNQ4809
[2016/01/06 12:44:15 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonIJETV
[2015/05/11 11:40:22 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonIJScan
[2015/05/11 11:40:22 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonIJScan\CNQ4809
[2015/08/23 19:10:53 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\BDNAV
[2016/12/09 06:53:13 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\EvoParser
[2015/08/23 19:14:38 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CAE\a95a1738
[2015/08/23 19:15:18 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\CLMPSvc.exe
[2015/08/23 19:08:04 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\CyberLink_PowerDVD_Downloader.exe
[2015/08/23 19:14:14 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\OLRSubmission.exe
[2015/08/23 19:44:36 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVD.exe
[2015/08/23 19:14:39 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVD15Agent.exe
[2015/08/23 19:16:17 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVDMovie.exe
[2015/08/23 19:44:59 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\setup.exe
[2015/08/23 19:06:55 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\ToGo
[2015/05/06 19:47:00 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CLUpdater\Power2Go\7.0
[2015/08/23 20:06:52 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CLUpdater\PowerDVD\10.0
[2015/08/23 19:11:57 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\CLUpdater\PowerDVD\15.0
[2015/05/06 19:46:59 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\EvoParser\Power2Go\7.0
[2015/08/23 20:06:52 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\EvoParser\PowerDVD\10.0
[2015/08/23 19:44:48 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\EvoParser\PowerDVD\15.0
[2015/08/23 19:11:07 | 000,000,000 | -H-D | M] -- C:\ProgramData\CyberLink\EvoParser\PowerDVD\15.0\Boomerang
[2009/07/14 14:32:38 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc
[2009/07/14 14:32:38 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc\Profiles
[2015/05/06 19:22:58 | 000,000,000 | RH-D | M] -- C:\Users\Default
[2016/01/06 12:44:15 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonIJETV
[2015/05/11 11:40:22 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonIJScan
[2015/05/11 11:40:22 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonIJScan\CNQ4809
[2015/08/23 19:10:53 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\BDNAV
[2016/12/09 06:53:13 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\EvoParser
[2015/08/23 19:14:38 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CAE\a95a1738
[2015/08/23 19:15:18 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\CLMPSvc.exe
[2015/08/23 19:08:04 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\CyberLink_PowerDVD_Downloader.exe
[2015/08/23 19:14:14 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\OLRSubmission.exe
[2015/08/23 19:44:36 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVD.exe
[2015/08/23 19:14:39 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVD15Agent.exe
[2015/08/23 19:16:17 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\PowerDVDMovie.exe
[2015/08/23 19:44:59 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\setup.exe
[2015/08/23 19:06:55 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\ToGo
[2015/05/06 19:47:00 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CLUpdater\Power2Go\7.0
[2015/08/23 20:06:52 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CLUpdater\PowerDVD\10.0
[2015/08/23 19:11:57 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\CLUpdater\PowerDVD\15.0
[2015/05/06 19:46:59 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\EvoParser\Power2Go\7.0
[2015/08/23 20:06:52 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\EvoParser\PowerDVD\10.0
[2015/08/23 19:44:48 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\EvoParser\PowerDVD\15.0
[2015/08/23 19:11:07 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CyberLink\EvoParser\PowerDVD\15.0\Boomerang
[2009/07/14 14:32:38 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc
[2009/07/14 14:32:38 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc\Profiles
[2009/07/14 12:20:08 | 000,000,000 | -H-D | M] -- C:\Users\Default\AppData
[2016/12/06 08:23:50 | 000,000,000 | RH-D | M] -- C:\Users\Public\Desktop
[2009/07/14 11:34:59 | 000,000,000 | RH-D | M] -- C:\Users\Public\Favorites
[2015/05/06 19:23:00 | 000,000,000 | RH-D | M] -- C:\Users\Public\Libraries
[2015/05/06 19:47:09 | 000,000,000 | -H-D | M] -- C:\Users\Public\CyberLink\OLReg
[2015/05/06 19:47:10 | 000,000,000 | -H-D | M] -- C:\Users\Public\CyberLink\Power2Go
[2015/05/06 19:48:11 | 000,000,000 | -H-D | M] -- C:\Users\Public\CyberLink\OLReg\HKEY_CLASS_ROOT\CLSID\{29964B14-C117-46b6-B108-11F211ED9388}\Version\6.0
[2015/05/06 19:47:09 | 000,000,000 | -H-D | M] -- C:\Users\Public\CyberLink\OLReg\HKEY_CLASS_ROOT\CLSID\{397A21FB-EADF-4116-9027-32B8FA04C3E2}\Version\7.0
[2015/05/06 19:47:09 | 000,000,000 | -H-D | M] -- C:\Users\Public\CyberLink\OLReg\HKEY_CLASS_ROOT\CLSID\{6F7425F3-EB34-46b0-9B63-430203611455}\Version\10.0
[2015/08/23 19:14:36 | 000,000,000 | -H-D | M] -- C:\Users\Public\CyberLink\OLReg\HKEY_CLASS_ROOT\CLSID\{6F7425F3-EB34-46b0-9B63-430203611455}\Version\15.0
[2015/05/06 19:33:08 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData
[2015/09/22 15:25:31 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Local\Microsoft\Device Metadata\dmrccache\downloads
[2015/05/06 19:35:28 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~
[2015/05/06 19:39:14 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~
[2015/05/12 10:20:51 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Local\Microsoft\Media Player\アート キャッシュ
[2015/09/22 15:26:21 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Local\Microsoft\Media Player\ダウンロード ファイルの同期
[2015/05/06 19:35:33 | 000,000,000 | RH-D | M] -- C:\Users\youazuma\AppData\Local\Microsoft\Windows\Burn\Burn
[2015/05/11 11:41:28 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history
[2016/03/26 11:42:15 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc
[2015/05/11 11:41:28 | 000,000,974 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0001.lnk
[2015/05/23 20:13:24 | 000,000,927 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0002.lnk
[2015/06/09 03:14:42 | 000,000,900 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0003.lnk
[2015/07/18 20:36:37 | 000,000,950 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0004.lnk
[2015/07/18 20:36:38 | 000,000,950 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0005.lnk
[2015/08/23 20:18:41 | 000,000,900 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0006.lnk
[2015/09/29 22:34:35 | 000,000,907 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0007.lnk
[2015/09/30 20:49:49 | 000,000,907 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0008.lnk
[2015/12/10 17:28:13 | 000,000,830 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0009.lnk
[2015/12/10 17:31:21 | 000,000,861 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0010.lnk
[2015/12/29 16:51:54 | 000,000,614 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0011.lnk
[2015/12/29 16:52:51 | 000,000,645 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0012.lnk
[2015/12/29 22:55:08 | 000,000,800 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0013.lnk
[2015/12/30 19:51:00 | 000,000,800 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0014.lnk
[2015/12/30 22:42:02 | 000,000,831 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0015.lnk
[2016/01/18 03:29:51 | 000,000,799 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0016.lnk
[2016/01/18 03:29:52 | 000,000,799 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0017.lnk
[2016/01/18 03:29:53 | 000,000,799 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0018.lnk
[2016/01/18 03:29:54 | 000,000,799 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0019.lnk
[2016/01/18 03:29:55 | 000,000,799 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0020.lnk
[2016/03/26 11:42:15 | 000,000,834 | -H-- | M] () -- C:\Users\youazuma\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\hstr_0021.lnk
[2015/08/23 19:15:19 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Roaming\CyberLink\MediaCache
[2015/08/24 09:17:01 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Roaming\CyberLink\Power2Go
[2016/12/09 06:21:33 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Roaming\CyberLink\Power2Go\7.0
[2016/12/05 09:35:25 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2015/05/15 03:22:23 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Roaming\Microsoft\Windows\DNTException\Low
[2015/05/15 03:22:15 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Roaming\Microsoft\Windows\IECompatCache\Low
[2015/05/15 03:22:15 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Roaming\Microsoft\Windows\IECompatUACache\Low
[2015/05/10 23:38:44 | 000,000,000 | -H-D | M] -- C:\Users\youazuma\AppData\Roaming\Microsoft\Windows\PrivacIE\Low
[2016/04/05 09:53:24 | 000,000,000 | -H-D | M] -- C:\Windows\ServiceProfiles\LocalService\AppData
[2009/07/14 13:45:47 | 000,000,000 | -H-D | M] -- C:\Windows\ServiceProfiles\NetworkService\AppData
[2015/05/06 19:38:23 | 000,000,000 | -H-D | M] -- C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Media Player\アート キャッシュ
[2015/05/11 09:47:54 | 000,000,000 | -H-D | M] -- C:\Windows\SysNative\CanonIJ Uninstaller Information
[2016/02/04 03:52:18 | 000,000,000 | -H-D | M] -- C:\Windows\SysNative\GroupPolicy

[color=#A23BEC]< %windir%\tasks\*.job >[/color]
[2016/12/10 04:13:28 | 000,000,526 | ---- | M] () -- C:\Windows\tasks\BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B}.job
[2016/12/10 06:10:03 | 000,000,690 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2016/12/10 08:10:00 | 000,000,694 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2016/12/10 07:42:53 | 000,000,462 | ---- | M] () -- C:\Windows\tasks\UCBrowserUpdater.job
[2016/12/10 07:43:00 | 000,000,298 | ---- | M] () -- C:\Windows\tasks\UCBrowserUpdaterCore.job
[2016/12/10 07:52:00 | 000,000,282 | ---- | M] () -- C:\Windows\tasks\UpdateTask.job
[2016/12/10 07:57:00 | 000,000,390 | ---- | M] () -- C:\Windows\tasks\WpsUpdateTask_Administrator.job

[color=#E56717]========== Drive Information ==========[/color]

Physical Drives
---------------

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: ATA WDC WD5000AAKX-0 SCSI Disk Device
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 - External hard disk media
Interface type: USB
Media Type: External hard disk media
Model: LaCie Rikiki USB 3.0 USB Device
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: Generic- Compact Flash USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: Generic- SM/xD-Picture USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model: Generic- SD/MMC USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE5 -
Interface type: USB
Media Type:
Model: Generic- MS/MS-Pro USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
---------------

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 105906176
Hidden sectors: 0


DeviceID: Disk #1, Partition #0
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 1048576
Hidden sectors: 0


[color=#E56717]========== Base Services ==========[/color]
SRV:[b]64bit:[/b] - [2015/10/30 02:50:29 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc)
SRV:[b]64bit:[/b] - [2016/05/05 02:16:57 | 000,070,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:[b]64bit:[/b] - [2009/07/14 10:38:55 | 000,079,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:51 | 000,849,920 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:00 | 000,705,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:[b]64bit:[/b] - [2016/10/10 23:55:00 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lsass.exe -- (KeyIso)
SRV:[b]64bit:[/b] - [2009/07/14 10:40:50 | 000,402,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV - [2009/07/14 10:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV:[b]64bit:[/b] - [2012/07/05 07:13:27 | 000,136,704 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:[b]64bit:[/b] - [2016/06/15 02:16:25 | 000,190,976 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV - [2016/06/15 00:21:20 | 000,145,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\cryptsvc.dll -- (CryptSvc)
SRV:[b]64bit:[/b] - [2016/02/03 03:57:35 | 000,511,488 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:00 | 000,317,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV - [2010/11/21 12:24:09 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV:[b]64bit:[/b] - [2011/03/03 15:24:16 | 000,183,296 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:[b]64bit:[/b] - [2009/07/14 10:40:35 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\eapsvc.dll -- (EapHost)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:00 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV - [2009/07/14 10:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:[b]64bit:[/b] - [2016/05/13 02:14:48 | 000,502,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:[b]64bit:[/b] - [2009/07/14 10:41:54 | 000,524,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:52 | 000,459,776 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofm.dll -- (netprofm)
SRV - [2009/07/14 10:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\netprofm.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2014/12/06 13:17:27 | 000,303,616 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:53 | 000,025,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:[b]64bit:[/b] - [2011/05/24 20:42:55 | 000,404,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:[b]64bit:[/b] - [2012/02/11 15:36:02 | 000,559,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
SRV:[b]64bit:[/b] - [2016/10/10 23:55:00 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV:[b]64bit:[/b] - [2009/07/14 10:41:53 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:17 | 000,344,064 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:[b]64bit:[/b] - [2016/02/03 03:57:35 | 000,511,488 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:[b]64bit:[/b] - [2016/02/09 18:55:34 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:[b]64bit:[/b] - [2016/10/10 23:55:00 | 000,030,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:58 | 000,097,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:48 | 000,236,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:55 | 000,370,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV - [2010/11/21 12:24:03 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV:[b]64bit:[/b] - [2015/08/06 02:56:14 | 001,110,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:32 | 000,316,928 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV - [2010/11/21 12:24:00 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:[b]64bit:[/b] - [2014/12/19 12:06:55 | 000,210,432 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:55 | 001,600,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:[b]64bit:[/b] - [2016/06/15 02:16:23 | 000,680,448 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioSrv)
SRV:[b]64bit:[/b] - [2016/06/15 02:16:23 | 000,680,448 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2010/11/21 12:25:06 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
SRV:[b]64bit:[/b] - [2013/05/27 14:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:55 | 001,646,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (eventlog)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:28 | 000,828,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:48 | 000,580,096 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:[b]64bit:[/b] - [2016/05/05 00:04:16 | 000,128,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver)
SRV - [2016/05/04 23:55:38 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:56 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:[b]64bit:[/b] - [2016/05/14 06:55:20 | 002,607,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:09 | 000,252,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:56 | 000,886,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (Wlansvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:32 | 000,118,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

[color=#E56717]========== Files - Unicode (All) ==========[/color]
[2016/12/05 16:24:45 | 000,001,538 | ---- | M] ()(C:\Users\youazuma\Application Data\Microsoft\Internet Explorer\Quick Launch\UC??器.lnk) -- C:\Users\youazuma\Application Data\Microsoft\Internet Explorer\Quick Launch\UC浏览器.lnk
[2016/12/05 10:27:22 | 000,001,538 | ---- | C] ()(C:\Users\youazuma\Application Data\Microsoft\Internet Explorer\Quick Launch\UC??器.lnk) -- C:\Users\youazuma\Application Data\Microsoft\Internet Explorer\Quick Launch\UC浏览器.lnk

< End of report >
  • puri
  • 2016/12/10 (Sat) 08:41:53
Extras.txt ログ
OTL Extras logfile created on: 2016/12/10 7:58:15 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\youazuma\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18524)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

3.87 Gb Total Physical Memory | 3.08 Gb Available Physical Memory | 79.39% Memory free
7.75 Gb Paging File | 6.00 Gb Available in Paging File | 77.47% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 349.10 Gb Free Space | 74.97% Space Free | Partition Type: NTFS
Drive I: | 465.76 Gb Total Space | 437.57 Gb Free Space | 93.95% Space Free | Partition Type: NTFS

Computer Name: YOUAZUMA-PC | User Name: youazuma | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\SOFTWARE\Classes\<extension>]
.html [@ = UCHTML] -- C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe (UCWeb Inc.)

[HKEY_USERS\S-1-5-18\SOFTWARE\Classes\<extension>]
.html [@ = UCHTML] -- C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe (UCWeb Inc.)

[HKEY_USERS\S-1-5-21-1134703352-1772604644-2719378906-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe" --wow-as-default=2 -- "%1"youazuma\AppData\Local\Microsoft\OneDrive\17.3.5951
https [open] -- "C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe" --wow-as-default=2 -- "%1"fault=2 -- "%1"youazuma\AppData\Local\Microsoft\OneDrive\17.3.5951

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- C:\Users\youazuma\AppData\Roaming\efo\efo.exe "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe" --wow-as-default=2 -- "%1"et Explorer\iexplore.exe" (Microsoft Corporation)

https [open] -- "C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe" --wow-as-default=2 -- "%1"et Explorer\iexplore.exe" (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- C:\Users\youazuma\AppData\Roaming\efo\efo.exe "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[color=#E56717]========== Authorized Applications List ==========[/color]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{23BB4C16-481B-48E6-A6FD-ECEC98D48C41}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{36C87CBB-8BD7-4DD1-BFA3-C07D4FE3B3BF}" = rport=445 | protocol=6 | dir=out | app=system |
"{3FFA9375-73AF-42EA-AD06-A1D912085620}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4A4FFCC4-70BB-4DE1-AC15-42A4A80E3AC1}" = lport=138 | protocol=17 | dir=in | app=system |
"{4DF41FA9-9E51-4B03-AA59-CD7BF17DB47D}" = rport=137 | protocol=17 | dir=out | app=system |
"{6241AF86-84E3-4A75-8BF9-8CD2A88115C8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6EA8EBB7-A4FF-4E45-8262-9DC52636A921}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{79941026-3E86-41A5-A658-F1ECF4B9ED73}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8C40B044-B6A2-49E0-AF00-F289814B42D2}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\ucbrowser\application\ucbrowser.exe |
"{8D8D7697-DFD4-4C72-971D-76211CBC0350}" = lport=2869 | protocol=6 | dir=in | app=system |
"{90546E66-CB7E-448B-A1C8-033948BEC77D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{96968345-19CF-40AC-AD22-05148FA51D93}" = lport=445 | protocol=6 | dir=in | app=system |
"{9E79D9E1-8741-43EC-9F62-C7B1FD876A7C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{9FB95786-9419-438B-A0ED-356E9D9CBF86}" = rport=138 | protocol=17 | dir=out | app=system |
"{AA3F339B-77FE-4ED4-BC70-78FBDB5B61BC}" = lport=10243 | protocol=6 | dir=in | app=system |
"{B6A83F09-5883-4F34-8851-23145693B8F4}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B6E0DFDE-88C4-462A-B41A-B82ABDC582AE}" = rport=10243 | protocol=6 | dir=out | app=system |
"{BE1C6E11-5626-41C3-BD93-BA98BC4D22C7}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{C447E3E7-77C1-4A27-BBA3-981A5D02BC10}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C6D63AA5-D78A-4B75-A41C-3EC192951546}" = lport=5353 | protocol=17 | dir=in | app=c:\users\youazuma\appdata\local\chromium\application\chrome.exe |
"{D131E75A-915F-4A31-BE18-B6213CC8F09F}" = lport=137 | protocol=17 | dir=in | app=system |
"{E4C3AD13-EC6D-4F2E-8704-F2C855AFEFD0}" = lport=139 | protocol=6 | dir=in | app=system |
"{ECD279FD-5B46-41B5-8189-F8DC22159075}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F28F7F13-3859-48EC-B7B5-289566DED0BE}" = rport=139 | protocol=6 | dir=out | app=system |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E3EBC51-E2C9-456F-BC7B-4ACF1D05840D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{0FB3D3C9-6075-4DF6-BEF4-C497AA535E03}" = dir=in | app=c:\program files (x86)\ucbrowser\application\ucbrowser.exe |
"{117D4F02-FEA8-4A35-836F-B866B9C5F5BA}" = protocol=6 | dir=out | app=system |
"{1AEED2DF-C444-48EC-8A69-759A487975EE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{30182D88-1DA9-441D-BA78-DA9E1B18D089}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{35C52908-6C84-4C3B-8C5E-5DC414B5AF19}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{364BC6FD-D213-4892-816B-3BA719050AA4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{4A4494F3-1FDA-4F60-BBB5-D72C274876EB}" = protocol=6 | dir=in | app=c:\program files (x86)\360\360safe\safemon\360tray.exe |
"{5A459776-539C-4A15-A53B-6B23607CEE0C}" = protocol=17 | dir=in | app=c:\program files (x86)\lenovo\lsf\lsfhelper.exe |
"{5CFD9FC1-54DA-47F9-933D-FEB04650AB05}" = protocol=17 | dir=in | app=c:\program files (x86)\360\360safe\safemon\360tray.exe |
"{5E797243-07E9-4E3C-8874-9C1B041FFEA0}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{63FF9DCA-83F1-40FC-A35C-1FFA5826E6C9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7415724A-F79C-4FFB-A874-97896306E50E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7445BCFE-E03D-465D-81E6-2A5CA9075F2E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{793D70BE-FBFE-470D-A5AE-06645427228B}" = protocol=17 | dir=in | app=c:\program files (x86)\360\360safe\liveupdate360.exe |
"{7C39E88B-E9E2-49DF-AB26-418840D9D3A1}" = dir=in | app=c:\program files (x86)\maoha\maohaap\maohawifisvr.exe |
"{8B5B7E46-A892-4681-9E46-92867253251F}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe |
"{966C723A-24B2-4FBD-BD06-BD4A2F8F4A9F}" = protocol=6 | dir=in | app=c:\program files (x86)\lenovo\lsf\lsfhelper.exe |
"{9A8D0AE5-9A28-49CC-B87C-54CEE3B125A8}" = dir=in | app=c:\program files (x86)\ucbrowser\application\downloader\download\minithunderplatform.exe |
"{A5F5DCF8-AFE6-4D47-98CA-FEABEC5D63DA}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\kingsoft\kiscommon\kxeserv.exe |
"{AA4F34BB-7445-49CA-AE69-F26575AA5A9F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BD2D30DD-7F30-4A99-8EE9-F7C7B72DCC3C}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\kingsoft\kiscommon\kxeserv.exe |
"{C63193A5-B952-4A9F-B3A0-59A576B03B45}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C6446BF1-3CD9-4D44-B40A-D58C50F87C98}" = protocol=6 | dir=in | app=c:\program files (x86)\lenovo\lsf\lsf.exe |
"{CB77458D-8616-4143-A240-00303D220235}" = protocol=17 | dir=in | app=c:\program files (x86)\lenovo\lsf\lsf.exe |
"{CC5F930A-2959-425F-ADA5-4D8DC042CE30}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CC84B255-FF9D-418B-9C78-CAAFA5A6FB8D}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe |
"{D099A4A8-4CA3-4DBC-AC75-92BCF17E62EF}" = protocol=6 | dir=in | app=c:\program files (x86)\360\360safe\liveupdate360.exe |
"{DB78BEC7-82F6-4500-A8F6-A0547A3723C3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E553EEB1-CFE9-492A-B475-09EEDF9E712B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EB81ABDC-8E74-4601-AEBF-62B7010AE512}" = dir=in | app=c:\users\youazuma\appdata\local\temp\is-ki6l3.tmp\download\minithunderplatform.exe |
"{F5943BAB-7785-4C7F-8624-BCFE37D16865}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F9E81348-F3C4-45A9-B409-3C549B04E2A5}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{FA22B3D9-14B5-4554-984A-1FF2A63776AB}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{FE506148-4749-4E0C-BC75-F188D22E64A1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4809" = CanoScan LiDE 210 Scanner Driver
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.6.1
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1041" = Microsoft .NET Framework 4.6.1 (日本語)
"{B7CC660E-F31D-490C-BD2A-2CB2EC5A5E3A}" = Intel(R) Chipset Device Software
"{BD6F5371-DAC1-30F0-9DDE-CAC6791E28C3}" = Microsoft .NET Framework 4.6.1
"{D0E18DF2-9E19-3BC5-9D77-5ECB9AC1A346}" = Microsoft .NET Framework 4.6.1 (JPN)
"{D9BAB2C9-5236-48c3-AF02-67E799F09BBD}" = Advanced Calendar 2.0.0.11382
"{FA00A3CC-7440-4938-A271-F186F50DD40D}" = Intel® Trusted Connect Service Client
"CCleaner" = CCleaner
"Wacom Tablet Driver" = ワコム タブレット
"Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin 64 bit

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{236BB7C4-4419-42FD-0411-1E257A25E34D}" = Adobe Photoshop CS2
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{402ED4A1-8F5B-387A-8688-997ABF58B8F2}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{786C5747-0C40-4930-9AFE-113BCE553101}" = Adobe Stock Photos 1.0
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8EDBA74D-0686-4C99-BFDD-F894678E5101}" = Adobe Common File Installer
"{8FCCB703-3FBF-49e7-A43F-A81E27D9B07E}" = CyberLink MediaShow 6
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A6C48A9F-694A-4234-B3AA-62590B668927}" = Intel(R) Manageability Engine Firmware Recovery Agent
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601}" = Adobe Illustrator CS2
"{B74D4E10-6884-0000-0000-000000000101}" = Adobe Bridge 1.0
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"{e48a2f61-851a-4155-82f9-af1b04db8c3b}" = インテル® チップセット デバイス ソフトウェア
"{E9787678-551D-4478-9682-DBB587257110}" = Adobe Help Center 1.0
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Illustrator CS2" = Adobe Illustrator CS2
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0411-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"B2" = Becky! Ver.2
"cleaner" = cleaner 1.0.1
"Google Chrome" = Google Chrome
"InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}" = CyberLink Media Suite 10
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"Kingsoft Office" = Kingsoft Office 2013 (9.1.0.4059)
"Kobo" = Rakuten Kobo Desktop
"KuaiZip" = ソ・ケ
"Lsf" = 联想帐号
"Mozilla Thunderbird 38.4.0 (x86 ja)" = Mozilla Thunderbird 38.4.0 (x86 ja)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 4.0" = Canon MP Navigator EX 4.0
"PaintToolSAI" = ペイントツールSAI Ver.1
"Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin 32 bit
"WinRAR archiver" = WinRAR 4.00 beta 4 (32-bit)
"Yahoo!Jツールバー" = Yahoo!ツールバー

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-1134703352-1772604644-2719378906-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2016/01/12 9:28:52 | Computer Name = youazuma-PC | Source = Application Hang | ID = 1002
Description = プログラム sai.exe バージョン 1.2.0.1 は Windows との対話を停止し、終了しました。問題に関する詳細な情報があるかどうかを確認するには、アクション
センター コントロール パネルで、問題の履歴をクリックしてください。 プロセス ID: 6a4 開始時刻: 01d1459af92e8f80 終了時刻: 551 アプリケーション
パス: C:\PaintToolSAI\sai.exe レポート ID: 6628e854-b930-11e5-b0f5-c03fd5481fbd

Error - 2016/01/13 14:34:07 | Computer Name = youazuma-PC | Source = WinMgmt | ID = 10
Description =

Error - 2016/01/26 19:58:41 | Computer Name = youazuma-PC | Source = WinMgmt | ID = 10
Description =

Error - 2016/02/02 20:03:12 | Computer Name = youazuma-PC | Source = WinMgmt | ID = 10
Description =

Error - 2016/02/08 20:01:48 | Computer Name = youazuma-PC | Source = WinMgmt | ID = 10
Description =

Error - 2016/02/10 10:39:02 | Computer Name = youazuma-PC | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: Wacom_Tablet.exe、バージョン: 6.3.11.4、タイム スタンプ: 0x54ee4559
障害が発生しているモジュール名:
Wacom_Touch_Tablet.dll、バージョン: 6.3.11.4、タイム スタンプ: 0x54ee45a2 例外コード: 0xc0000005 障害オフセット:
0x0000000000109199 障害が発生しているプロセス ID: 0xe1c 障害が発生しているアプリケーションの開始時刻: 0x01d162b040438769
障害が発生しているアプリケーション
パス: C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe 障害が発生しているモジュール パス: C:\Windows\system32\Wacom_Touch_Tablet.dll
レポート
ID: 06867f65-d004-11e5-b3b8-c03fd5481fbd

Error - 2016/02/10 14:43:49 | Computer Name = youazuma-PC | Source = WinMgmt | ID = 10
Description =

Error - 2016/02/12 16:36:54 | Computer Name = youazuma-PC | Source = Application Hang | ID = 1002
Description = プログラム IEXPLORE.EXE バージョン 11.0.9600.18205 は Windows との対話を停止し、終了しました。問題に関する詳細な情報があるかどうかを確認するには、アクション
センター コントロール パネルで、問題の履歴をクリックしてください。 プロセス ID: 1b84 開始時刻: 01d165d5073511d5 終了時刻: 0 アプリケーション
パス: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE レポート ID:

Error - 2016/02/28 16:40:27 | Computer Name = youazuma-PC | Source = WinMgmt | ID = 10
Description =

Error - 2016/02/29 15:04:26 | Computer Name = youazuma-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 2016/12/08 17:46:03 | Computer Name = youazuma-PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2016/12/08 17:47:20 | Computer Name = youazuma-PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2016/12/08 17:47:50 | Computer Name = youazuma-PC | Source = DCOM | ID = 10005
Description =

Error - 2016/12/08 17:47:50 | Computer Name = youazuma-PC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2016/12/08 17:48:02 | Computer Name = youazuma-PC | Source = DCOM | ID = 10005
Description =

Error - 2016/12/08 17:49:00 | Computer Name = youazuma-PC | Source = DCOM | ID = 10005
Description =

Error - 2016/12/08 17:51:11 | Computer Name = youazuma-PC | Source = DCOM | ID = 10010
Description =

Error - 2016/12/08 17:51:51 | Computer Name = youazuma-PC | Source = Service Control Manager | ID = 7000
Description = 主?防御 サービスを、次のエラーが原因で開始できませんでした: %%2

Error - 2016/12/08 17:51:54 | Computer Name = youazuma-PC | Source = Service Control Manager | ID = 7023
Description = Ckipecultvezied サービスは、次のエラーで終了しました: %%126

Error - 2016/12/09 14:38:02 | Computer Name = youazuma-PC | Source = Schannel | ID = 36887
Description = 次の致命的な警告を受け取りました: 20。


< End of report >



以上になります。お手数で申し訳ありませんがご確認をお願い致します。
セキュリティソフトは無料のMSE+EMETを希望致します。
どのタイミングで導入したらいいのでしょうか?
  • puri
  • 2016/12/10 (Sat) 08:46:00
OTLで大掃除を
セキュリティソフトはMSEとEMETをご希望とのことですね。
こちらのMSEは万一の感染時は1件につき5000円(税別)で駆除対応を受けることが可能となります。

MSEのダウンロードはこちらです。
http://download.microsoft.com/download/6/B/A/6BA6CAB0-DDB8-4DDD-88E3-F707D96E84D7/JAJP/amd64/MSEInstall.exe
EMETのダウンロードはこちらです。
https://www.microsoft.com/en-us/download/details.aspx?id=53354

ダウンロード後、直ちにインストールしてください。
さて以降はOTLでこの莫大な量の大掃除を行いましょう。

メモ帳を起動させ、以下をコピペしてください。

------コピペここから------
:otl
MOD - [2016/12/09 07:22:24 | 001,750,016 | ---- | M] () -- C:\Windows\Temp\D7CA.tmp
SRV:[b]64bit:[/b] - [2016/12/08 00:43:38 | 000,219,032 | ---- | M] () [Auto | Running] -- C:\Program Files\ソ・ケ\X86\kuaizipUpdateChecker.dll -- (KuaizipUpdateChecker)
SRV - [2016/12/10 06:13:54 | 000,428,544 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\03000200-1480898246-0500-0006-000700080009\knsDABE.tmp -- (sirozysi)
SRV - [2016/12/05 10:26:52 | 001,620,992 | ---- | M] () [Disabled | Stopped] -- C:\ProgramData\service.exe -- (GoogleChromeUpService)
SRV - [2016/11/30 10:05:10 | 000,935,312 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\UCBrowser\Application\UCService.exe -- (UCBrowserSvc)
SRV - [2016/11/26 14:55:53 | 000,168,992 | ---- | M] (深圳市猫哈网络科技发展有限公司) [Auto | Running] -- C:\Program Files (x86)\Maoha\MaohaAP\MaohaWifiSvr.exe -- (MaohaWifiSvr)
SRV - [2016/05/20 11:02:40 | 000,151,152 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\CalendarTool\2.0.0.11382\CalendarServ.exe -- (TheCalendarService)
DRV:[b]64bit:[/b] - File not found [Kernel | System | Running] -- C:\Windows\SysNative\drivers:ucdrv-x64.sys -- (ucdrv)
DRV:[b]64bit:[/b] - [2016/12/08 00:43:38 | 000,092,832 | ---- | M] (WinMount International Inc) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\KuaiZipDrive.sys -- (KuaiZipDrive)
DRV:[b]64bit:[/b] - [2016/07/18 13:37:20 | 000,405,224 | ---- | M] (360.cn) [File_System | System | Running] -- C:\Windows\SysNative\drivers\360FsFlt.sys -- (360FsFlt)
DRV:[b]64bit:[/b] - [2016/07/12 15:03:02 | 000,190,696 | ---- | M] (360.cn) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BAPIDRV64.SYS -- (BAPIDRV)
DRV:[b]64bit:[/b] - [2016/06/27 15:23:42 | 000,255,208 | ---- | M] (360安全中心) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\360Hvm64.sys -- (360Hvm)
DRV:[b]64bit:[/b] - [2016/06/12 11:11:20 | 000,081,344 | ---- | M] (360.cn) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\360netmon.sys -- (360netmon)
DRV:[b]64bit:[/b] - [2016/05/12 11:16:42 | 000,151,784 | ---- | M] (360.cn) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\360AntiHacker64.sys -- (360AntiHacker)
DRV:[b]64bit:[/b] - [2016/02/19 21:06:16 | 000,068,176 | ---- | M] (360.cn) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\360reskit64.sys -- (360reskit64)
DRV:[b]64bit:[/b] - [2015/10/16 16:35:10 | 000,321,616 | ---- | M] (360.cn) [File_System | System | Running] -- C:\Windows\SysNative\drivers\360Box64.sys -- (360Box64)
DRV:[b]64bit:[/b] - [2014/04/18 17:30:28 | 000,040,520 | ---- | M] (360.cn) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\360Camera64.sys -- (360Camera)
DRV - [2016/11/26 14:52:38 | 001,030,496 | ---- | M] () [Kernel | System | Running] -- C:\Program Files (x86)\Maoha\MaohaAP\MaoHaWiFiNet64.sys -- (MaohaWifiNetPro)
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://hao.360.cn/?installer
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://hao.360.cn/?installer
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://hao.360.cn/?installer
CHR - Extension: No name found = C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\kaefldlncokopeklgbllnmmnmdomodpj\1.0.0.3_0\
CHR - Extension: No name found = C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\
O4 - HKU\S-1-5-21-1134703352-1772604644-2719378906-1000..\Run: [osmsg] C:\ProgramData\WindowsMsg\Chrome.exe ()
[2016/12/10 00:46:57 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\reaper_data
[2016/12/08 00:43:36 | 000,000,000 | ---D | C] -- C:\Program Files\ソ・ケ
[2016/12/06 05:42:25 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\360DiagnoseScan
[2016/12/06 05:42:24 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\360Login
[2016/12/06 05:20:04 | 000,000,000 | -HSD | C] -- C:\Users\youazuma\AppData\Roaming\360Quarant
[2016/12/06 05:20:04 | 000,000,000 | -HSD | C] -- C:\$360Section
[2016/12/06 05:15:49 | 000,000,000 | ---D | C] -- C:\ProgramData\360safe
[2016/12/06 05:15:47 | 000,068,176 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360reskit64.sys
[2016/12/06 05:15:38 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\360mobilemgr
[2016/12/06 05:15:29 | 000,405,224 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360FsFlt.sys
[2016/12/06 05:15:29 | 000,060,416 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360LanProtect.sys
[2016/12/06 05:15:24 | 000,190,696 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\BAPIDRV64.SYS
[2016/12/06 05:15:22 | 000,255,208 | ---- | C] (360安全中心) -- C:\Windows\SysNative\drivers\360Hvm64.sys
[2016/12/06 05:15:22 | 000,151,784 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360AntiHacker64.sys
[2016/12/06 05:15:21 | 000,040,520 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360Camera64.sys
[2016/12/06 05:15:20 | 000,000,000 | RHSD | C] -- C:\360SANDBOX
[2016/12/06 05:15:19 | 000,321,616 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360Box64.sys
[2016/12/06 05:15:15 | 000,180,336 | ---- | C] (360.cn) -- C:\Windows\SysWow64\360SoftMgr.cpl
[2016/12/06 05:15:13 | 000,081,344 | ---- | C] (360.cn) -- C:\Windows\SysNative\drivers\360netmon.sys
[2016/12/06 05:15:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360安全中心
[2016/12/06 05:07:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\360
[2016/12/06 05:06:52 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\360Safe
[2016/12/05 17:06:20 | 000,000,000 | ---D | C] -- C:\ProgramData\baidu
[2016/12/05 17:06:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Baidu
[2016/12/05 16:57:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2016/12/05 16:57:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Avg
[2016/12/05 16:57:53 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2016/12/05 16:55:46 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk
[2016/12/05 16:55:22 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Local\Fobiingarerterk
[2016/12/05 10:30:19 | 000,081,792 | ---- | C] (Huorong Borui (Beijing) Technology Co., Ltd.) -- C:\Windows\SysNative\drivers\ucguard.sys
[2016/12/05 10:29:28 | 000,000,000 | -HSD | C] -- C:\ProgramData\WindowsMsg
[2016/12/05 10:28:05 | 000,092,832 | ---- | C] (WinMount International Inc) -- C:\Windows\SysNative\drivers\KuaiZipDrive.sys
[2016/12/05 10:28:04 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\KuaiZip
[2016/12/05 10:27:23 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Local\UCBrowser
[2016/12/05 10:27:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\UCBrowser
[2016/12/05 10:27:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MaohaWiFi
[2016/12/05 10:26:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Maoha
[2016/12/05 10:26:10 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\vnlgp
[2016/12/05 10:26:10 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\gplyra
[2016/12/05 09:40:24 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\Reezientaromry
[2016/12/05 09:40:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Thihurzuly
[2016/12/05 09:40:23 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Local\Nicether
[2016/12/05 09:39:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wanttoxiamen
[2016/12/05 09:39:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\wanttoxiamen
[2016/12/05 09:38:25 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\UPUpdata
[2016/12/05 09:38:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CalendarTool
[2016/12/05 09:38:19 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Tools
[2016/12/05 09:38:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CleanBrowser
[2016/12/05 09:38:19 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\CalendarTool
[2016/12/05 09:37:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\03000200-1480898246-0500-0006-000700080009
[2016/12/05 09:36:20 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\Microleaves
[2016/12/05 09:35:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Speed Up
[2016/12/05 09:35:27 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\efo
[2016/12/05 09:35:18 | 000,000,000 | ---D | C] -- C:\Users\youazuma\AppData\Roaming\baidu
[2016/12/05 09:35:18 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Baidu
[2016/12/05 08:08:20 | 000,000,000 | ---D | C] -- C:\ProgramData\FFinder LTD
[2016/12/10 07:43:00 | 000,000,298 | ---- | M] () -- C:\Windows\tasks\UCBrowserUpdaterCore.job
[2016/12/10 07:42:53 | 000,000,462 | ---- | M] () -- C:\Windows\tasks\UCBrowserUpdater.job
[2016/12/10 04:13:28 | 000,000,526 | ---- | M] () -- C:\Windows\tasks\BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B}.job
[2016/12/09 06:51:50 | 000,000,001 | ---- | M] () -- C:\Windows\SysNative\drivers\360Hvm64.dat
[2016/12/08 00:43:38 | 000,092,832 | ---- | M] (WinMount International Inc) -- C:\Windows\SysNative\drivers\KuaiZipDrive.sys
[2016/12/08 00:43:38 | 000,000,809 | ---- | M] () -- C:\Users\youazuma\Desktop\ソ・ケ.lnk
[2016/12/05 10:27:04 | 000,001,137 | ---- | M] () -- C:\Users\youazuma\Application Data\Microsoft\Internet Explorer\Quick Launch\MaohaWiFi.lnk
[2016/12/05 10:27:03 | 000,001,113 | ---- | M] () -- C:\Users\youazuma\Desktop\MaohaWiFi.lnk
[2016/12/10 07:52:00 | 000,000,282 | ---- | M] () -- C:\Windows\tasks\UpdateTask.job

:files
c:\program files (x86)\ucbrowser
c:\program files (x86)\360
c:\program files (x86)\maoha
c:\program files (x86)\ucbrowser

:reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0FB3D3C9-6075-4DF6-BEF4-C497AA535E03}" =-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{4A4494F3-1FDA-4F60-BBB5-D72C274876EB}" =-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{5CFD9FC1-54DA-47F9-933D-FEB04650AB05}" =-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{793D70BE-FBFE-470D-A5AE-06645427228B}" =-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{7C39E88B-E9E2-49DF-AB26-418840D9D3A1}" =-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{9A8D0AE5-9A28-49CC-B87C-54CEE3B125A8}" =-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{D099A4A8-4CA3-4DBC-AC75-92BCF17E62EF}" =-

:commands
[purity]
[resethosts]
[emptyflash]
[emptyjava]
[emptytemp]
[createrestorepoint]
[reboot]
------コピペここまで------

コピペが完了しましたら、わかりやすい場所に任意のお名前を付けて保存してください。
保存が完了しましたら、PCをセーフモードで再起動させてください。
PCがセーフモードで起動しましたら、OTLを起動させます。
「Costom Scans/Fixes」と言う項目に先ほど作ったメモ帳の中身をコピペしてください。
コピペが完了しましたら、OTLの画面にある赤い文字のRun Fixと言う左上2列目のボタンを押してください。
処置が開始されますので、処置が完了するまでお待ちください。
処置が完了しましたら、OKを押して再起動を行ってください。
再起動が完了しましたら処置ログが表示されますので、そちらを貼り付けてご連絡ください。
  • IVNO
  • 2016/12/10 (Sat) 16:15:39
処置ログ①
大掃除しましたので、ご確認お願い致します。

C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_metadata folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\zu folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\zh_TW folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\zh_HK folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\zh_CN folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\vi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\ur folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\uk folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\tr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\th folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\te folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\ta folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\sw folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\sv folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\sr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\sl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\sk folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\si folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\ru folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\ro folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\pt_PT folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\pt_BR folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\pl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\no folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\nl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\ne folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\ms folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\mr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\mn folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\ml folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\lv folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\lt folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\lo folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\ko folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\kn folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\km folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\ka folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\ja folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\iw folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\it folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\is folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\id folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\hy folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\hu folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\hr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\hi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\gu folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\gl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\fr_CA folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\fr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\fil folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\fi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\fa folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\eu folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\et folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\es_419 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\es folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\en_US folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\en_GB folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\el folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\de folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\da folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\cs folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\ca folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\bn folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\bg folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\az folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\ar folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\am folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales\af folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_locales folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\fgdmffdjodbbbifinkneeddcphmldpag\1.0.0.2_0\_metadata folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\fgdmffdjodbbbifinkneeddcphmldpag\1.0.0.2_0\img folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\fgdmffdjodbbbifinkneeddcphmldpag\1.0.0.2_0\html folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\fgdmffdjodbbbifinkneeddcphmldpag\1.0.0.2_0\css folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\fgdmffdjodbbbifinkneeddcphmldpag\1.0.0.2_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\fgdmffdjodbbbifinkneeddcphmldpag folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_metadata folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\zh_TW folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\zh_CN folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\vi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\uk folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\tr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\th folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\sv folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\sr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\sl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\sk folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ru folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ro folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\pt_PT folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\pt_BR folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\pl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\no folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\nl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ms folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\lv folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\lt folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ko folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ja folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\it folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\id folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\hu folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\hi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\he folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\fr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\fil folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\fi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\et folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\es_419 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\es folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\en_US folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\en_GB folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\el folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\de folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\da folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\cs folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ca folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\bg folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ar folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_metadata folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\hu folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\hr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\hi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\he folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\fr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\fil folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\fi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\et folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\es_419 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\es folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\en_US folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\en_GB folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\en folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\el folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\de folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\da folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\cs folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\ca folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\bg folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales\ar folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\_locales folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_metadata folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\zh_TW folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\zh_CN folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\vi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\uk folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\tr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\th folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\sv folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\sr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\sl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\sk folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\ru folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\ro folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\pt_PT folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\pt_BR folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\pl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\no folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\nl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\lv folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\lt folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\ko folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\ja folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\it folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\id folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\hu folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\hr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\hi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\he folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\fr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\fil folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\fi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\es folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\en folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\el folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\de folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\da folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\cs folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\ca folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\bg folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\ar folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0 folder moved successfully.
  • puri
  • 2016/12/11 (Sun) 08:04:54
処置ログ②
続きです

C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_metadata folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\zh_TW folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\zh_CN folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\vi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\uk folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\tr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\th folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\sv folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\sr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\sl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\sk folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\ru folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\ro folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\pt_PT folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\pt_BR folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\pl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\no folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\nl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\ms folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\lv folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\lt folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\ko folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\ja folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\it folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\id folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\hu folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\hr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\hi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\he folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\fr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\fil folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\fi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\eu folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\et folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\es_419 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\es folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\en_US folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\en_GB folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\el folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\de folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\da folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\cs folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\ca folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\bg folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\ar folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_metadata folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\zh_TW folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\zh_CN folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\vi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\uk folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\tr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\th folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sv folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sk folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ru folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ro folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_PT folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_BR folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\no folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\nl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ms folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lv folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lt folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ko folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ja folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\it folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\id folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hu folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\he folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fil folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\et folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es_419 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_US folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_GB folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\el folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\de folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\da folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\cs folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ca folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\bg folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ar folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aohghmighlieiainnegkcijnfilokake folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_metadata folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\zh_TW folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\zh_CN folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\vi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\uk folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\tr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\th folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sv folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sk folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ru folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ro folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\pt_PT folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\pt_BR folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\pl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\no folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\nl folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ms folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\lv folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\lt folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ko folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ja folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\it folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\id folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\hu folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\hi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\he folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\fr folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\fil folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\fi folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\et folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\es_419 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\es folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\en_US folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\en_GB folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\el folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\de folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\da folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\cs folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ca folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\bg folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ar folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extensions folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extension State folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Extension Rules folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\data_reduction_proxy_leveldb folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\databases\http_www.flirt4free.com_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\databases\http_seesaawiki.jp_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\databases\http_rapidgator.net_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\databases\http_d.pixiv.org_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\databases\http_content.adriver.ru_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\databases\https_www.suruga-ya.jp_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\databases\https_www.flirt.com_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\databases\https_rapidgator.net_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\databases\https_googleads.g.doubleclick.net_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\databases\https_calendar.google.com_0 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\databases folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default\Application Cache folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Default folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Crashpad\reports folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Crashpad folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\CertificateTransparency\231\_platform_specific\all\sths folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\CertificateTransparency\231\_platform_specific\all folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\CertificateTransparency\231\_platform_specific folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\CertificateTransparency\231 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\CertificateTransparency\230\_platform_specific\all\sths folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\CertificateTransparency\230\_platform_specific\all folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\CertificateTransparency\230\_platform_specific folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\CertificateTransparency\230 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\CertificateTransparency\229\_platform_specific\all\sths folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\CertificateTransparency\229\_platform_specific\all folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\CertificateTransparency\229\_platform_specific folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\CertificateTransparency\229 folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\CertificateTransparency folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Caps folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether\Avatars folder moved successfully.
C:\Users\youazuma\AppData\Local\Nicether folder moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wanttoxiamen folder moved successfully.
  • puri
  • 2016/12/11 (Sun) 08:09:15
処置ログ③
最後です、宜しくお願い致します。


C:\Program Files (x86)\wanttoxiamen folder moved successfully.
C:\Users\youazuma\AppData\Roaming\UPUpdata folder moved successfully.
C:\Program Files (x86)\CalendarTool\2.0.0.11382\skin\images folder moved successfully.
C:\Program Files (x86)\CalendarTool\2.0.0.11382\skin folder moved successfully.
C:\Program Files (x86)\CalendarTool\2.0.0.11382\EVPData folder moved successfully.
C:\Program Files (x86)\CalendarTool\2.0.0.11382\DefaultConfig folder moved successfully.
C:\Program Files (x86)\CalendarTool\2.0.0.11382\Config9 folder moved successfully.
C:\Program Files (x86)\CalendarTool\2.0.0.11382\Config8 folder moved successfully.
C:\Program Files (x86)\CalendarTool\2.0.0.11382\Config7 folder moved successfully.
C:\Program Files (x86)\CalendarTool\2.0.0.11382\Config-3 folder moved successfully.
C:\Program Files (x86)\CalendarTool\2.0.0.11382 folder moved successfully.
C:\Program Files (x86)\CalendarTool folder moved successfully.
C:\Users\Public\Documents\Tools\Common\I18N folder moved successfully.
C:\Users\Public\Documents\Tools\Common folder moved successfully.
C:\Users\Public\Documents\Tools folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\bin\locales folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\bin folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\tunnel-agent folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\tough-cookie\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\tough-cookie folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\stringstream folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\qs\test folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\qs\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\qs\dist folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\qs folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\oauth-sign folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\node-uuid\test folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\node-uuid\bin folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\node-uuid\benchmark folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\node-uuid folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\mime-types\node_modules\mime-db folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\mime-types\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\mime-types folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\json-stringify-safe\test folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\json-stringify-safe folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\isstream folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\is-typedarray folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\tweetnacl folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jsbn folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519 folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\ecc-jsbn\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\ecc-jsbn folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\dashdash\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\dashdash\etc folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\dashdash folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\tst\ber folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\tst folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\lib\ber folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1 folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\man\man1 folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\man folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\formats folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\bin folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\tests folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\examples folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\test folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-04 folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-03\examples folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-03 folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-02 folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-01 folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-00 folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\examples folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\assert-plus folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules\.bin folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\http-signature folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\test folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\test folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\examples folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\sntp folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\test\modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\test folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\images folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\hoek folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\cryptiles\test folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\cryptiles\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\cryptiles folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\boom\test folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\boom\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\boom\images folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules\boom folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\images folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\example folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk\dist folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\hawk folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise\node_modules\pinkie folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4 folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\fixtures folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\xtend folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\jsonpointer folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\node_modules\is-property folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-function folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\node_modules\graceful-readlink folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\commander folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\supports-color folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi\node_modules\ansi-regex folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi\node_modules\ansi-regex folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\escape-string-regexp folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\ansi-styles folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\lib\schemas folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator\bin folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\har-validator folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\form-data\node_modules\async\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\form-data\node_modules\async\dist folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\form-data\node_modules\async folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\form-data\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\form-data\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\form-data folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\forever-agent folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\extend folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\combined-stream\node_modules\delayed-stream\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\combined-stream\node_modules\delayed-stream folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\combined-stream\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\combined-stream\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\combined-stream folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\caseless folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\test folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\util-deprecate folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\string_decoder folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\process-nextick-args folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\isarray\build folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\isarray folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\inherits folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\core-util-is\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\core-util-is folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\doc\wg-meetings folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\doc folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\bl folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\test folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\aws4\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\aws4 folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\aws-sign2 folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules\.bin folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request\lib folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules\request folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app\node_modules folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app\app folder moved successfully.
C:\Program Files (x86)\CleanBrowser\app folder moved successfully.
C:\Program Files (x86)\CleanBrowser folder moved successfully.
C:\Users\youazuma\AppData\Roaming\CalendarTool\dump folder moved successfully.
C:\Users\youazuma\AppData\Roaming\CalendarTool folder moved successfully.
C:\Program Files (x86)\03000200-1480898246-0500-0006-000700080009 folder moved successfully.
C:\Users\youazuma\AppData\Roaming\Microleaves folder moved successfully.
C:\Program Files (x86)\PC Speed Up folder moved successfully.
C:\Users\youazuma\AppData\Roaming\efo\langs folder moved successfully.
C:\Users\youazuma\AppData\Roaming\efo folder moved successfully.
C:\Users\youazuma\AppData\Roaming\baidu\UpdatePlatform\dump folder moved successfully.
C:\Users\youazuma\AppData\Roaming\baidu\UpdatePlatform folder moved successfully.
C:\Users\youazuma\AppData\Roaming\baidu folder moved successfully.
C:\Users\Public\Documents\Baidu\Common\I18N\IPCSUpdateCache\baidujp_update folder moved successfully.
C:\Users\Public\Documents\Baidu\Common\I18N\IPCSUpdateCache folder moved successfully.
C:\Users\Public\Documents\Baidu\Common\I18N folder moved successfully.
C:\Users\Public\Documents\Baidu\Common folder moved successfully.
C:\Users\Public\Documents\Baidu folder moved successfully.
C:\ProgramData\FFinder LTD folder moved successfully.
C:\Windows\Tasks\UCBrowserUpdaterCore.job moved successfully.
C:\Windows\Tasks\UCBrowserUpdater.job moved successfully.
C:\Windows\Tasks\BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B}.job moved successfully.
C:\Windows\SysNative\drivers\360Hvm64.dat moved successfully.
File C:\Windows\SysNative\drivers\KuaiZipDrive.sys not found.
C:\Users\youazuma\Desktop\ソ・ケ.lnk moved successfully.
C:\Users\youazuma\Application Data\Microsoft\Internet Explorer\Quick Launch\MaohaWiFi.lnk moved successfully.
C:\Users\youazuma\Desktop\MaohaWiFi.lnk moved successfully.
C:\Windows\Tasks\UpdateTask.job moved successfully.
========== FILES ==========
File\Folder c:\program files (x86)\ucbrowser not found.
File\Folder c:\program files (x86)\360 not found.
File\Folder c:\program files (x86)\maoha not found.
File\Folder c:\program files (x86)\ucbrowser not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0FB3D3C9-6075-4DF6-BEF4-C497AA535E03} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FB3D3C9-6075-4DF6-BEF4-C497AA535E03}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4A4494F3-1FDA-4F60-BBB5-D72C274876EB} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4A4494F3-1FDA-4F60-BBB5-D72C274876EB}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5CFD9FC1-54DA-47F9-933D-FEB04650AB05} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5CFD9FC1-54DA-47F9-933D-FEB04650AB05}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{793D70BE-FBFE-470D-A5AE-06645427228B} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{793D70BE-FBFE-470D-A5AE-06645427228B}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7C39E88B-E9E2-49DF-AB26-418840D9D3A1} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C39E88B-E9E2-49DF-AB26-418840D9D3A1}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9A8D0AE5-9A28-49CC-B87C-54CEE3B125A8} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A8D0AE5-9A28-49CC-B87C-54CEE3B125A8}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D099A4A8-4CA3-4DBC-AC75-92BCF17E62EF} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D099A4A8-4CA3-4DBC-AC75-92BCF17E62EF}\ not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: youazuma
->Flash cache emptied: 456 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYJAVA]

User: All Users

User: Default

User: Default User

User: Public

User: youazuma

Total Java Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: youazuma
->Temp folder emptied: 358789588 bytes
->Temporary Internet Files folder emptied: 21212979 bytes
->Google Chrome cache emptied: 415444468 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 887113954 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33298 bytes
RecycleBin emptied: 180793421 bytes

Total Files Cleaned = 1,777.00 mb

Unable to start System Restore Service. Error code 1084

OTL by OldTimer - Version 3.2.69.0 log created on 12112016_072854

Files\Folders moved on Reboot...
File move failed. C:\Windows\SysNative\drivers:ucdrv-x64.sys scheduled to be moved on reboot.
C:\Users\youazuma\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\youazuma\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • puri
  • 2016/12/11 (Sun) 08:10:24
とりあえずいいでしょう
前半の半分以上のログのご提示がいただけていない状態ですが、とりあえず良いです。
OTLでの処置は後半のログを観る限り、一通り正常に終了した模様です。

それではここで一度見直しを行った後、通常の手順での作業に戻りたいと思います。
HJTのログ、CCのインストール情報ログを通常モードで再取得し、貼り付けてご連絡ください。
  • IVNO
  • 2016/12/11 (Sun) 15:26:09
HJTのログ
たしかに、広告は出なくなりました…有難うございます。
ログを取りましたので貼り付けます。ご確認お願い致します。


Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 8:25:42, on 2016/12/12
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18525)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
C:\Users\youazuma\Downloads\HijackThis.exe

O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo!ツールバーフィッシング警告 - {1F68E72C-50E5-44B8-8F56-6A54D3AF1DA4} - C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\ypho.dll
O2 - BHO: Yahoo!ツールバーヘルパー - {EEBA90E6-2B14-413F-9BF8-61A8BDF92258} - C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\YahooToolBar.dll
O3 - Toolbar: Yahoo!ツールバー - {AEF44653-C059-42CB-A5B7-41C640DA4A67} - C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\YahooToolBar.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe"
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_5850FDE37EF22CDAB7B2FC1F7CA062A9] "C:\Users\youazuma\AppData\Local\Chromium\Application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\youazuma\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\youazuma\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Watermark Web Directory (gexyfequ) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ?想??硬件修?模? (LenovoDRS) - ?想(北京)有限公司 - C:\Program Files (x86)\Lenovo\PCManager\LenovoDRS.exe
O23 - Service: LenovoPcManagerService - Lenovo Corporation - C:\Program Files (x86)\Lenovo\PCManager\LenovoPcManagerService.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wacom Professional Service (WTabletServicePro) - Wacom Technology, Corp. - C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
O23 - Service: 主?防御 (ZhuDongFangYu) - Unknown owner - C:\Program Files (x86)\360\360Safe\deepscan\zhudongfangyu.exe (file missing)

--
End of file - 7409 bytes
  • puri
  • 2016/12/12 (Mon) 08:28:10
CCのログ
Adobe Flash Player 10 ActiveX Adobe Systems Incorporated 2014/10/06 6.00 MB 10.2.152.32
Adobe Illustrator CS2 Adobe Systems Inc. 2016/02/19 12.000.000
Adobe Photoshop CS2 Adobe Systems, Inc. 2016/02/19 9.0
Adobe SVG Viewer 3.0 Adobe Systems, Inc. 2016/02/19 3.0
Advanced Calendar 2.0.0.11382 MEIXIAN XIE 2015/09/21 2.0.0.11382
Becky! Ver.2 RimArts 2015/09/20
Canon MP Navigator EX 4.0 2015/05/11
CanoScan LiDE 210 Scanner Driver Canon Inc. 2015/05/11
CCleaner Piriform 2016/12/06 5.24
CyberLink Media Suite 10 CyberLink Corp. 2015/08/23 962 MB 10.0
CyberLink PowerDVD 10 CyberLink Corp. 2015/08/23 183 MB 10.0.4508.02
EMET 5.51 Microsoft Corporation 2016/12/11 45.9 MB 5.51
Google Chrome Google Inc. 2016/12/06 55.0.2883.75
Intel(R) Control Center Intel Corporation 2015/05/08 1.2.1.1010
Intel(R) Manageability Engine Firmware Recovery Agent Intel Corporation 2014/10/06 54.8 MB 1.0.0.36702
Intel(R) Management Engine Components Intel Corporation 2015/05/08 9.0.0.1310
Intel(R) Processor Graphics Intel Corporation 2015/05/08 10.18.10.3496
Intel(R) USB 3.0 eXtensible Host Controller Driver Intel Corporation 2015/05/08 3.0.0.19
Kingsoft Office 2013 (9.1.0.4059) Kingsoft Corp. 2014/10/06 9.1.0.4059
Microsoft .NET Framework 4.6.1 Microsoft Corporation 2016/02/11 38.8 MB 4.6.01055
Microsoft .NET Framework 4.6.1 (日本語) Microsoft Corporation 2016/05/20 2.93 MB 4.6.01055
Microsoft Security Essentials Microsoft Corporation 2016/12/11 4.10.209.0
Microsoft Silverlight Microsoft Corporation 2016/10/13 299 MB 5.1.50901.0
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2015/09/21 300 KB 8.0.61001
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2014/10/06 608 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2014/10/06 586 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2015/09/21 598 KB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/06 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/06 11.1 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 2016/08/16 17.3 MB 11.0.61030.0
Mozilla Maintenance Service Mozilla 2015/09/20 250 KB 38.2.0
Mozilla Thunderbird 38.4.0 (x86 ja) Mozilla 2016/03/13 79.9 MB 38.4.0
Rakuten Kobo Desktop Rakuten Kobo Inc. 2016/08/16 3.19.3765
Realtek Ethernet Controller Driver Realtek 2014/10/06 7.78.1218.2013
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2014/10/06 6.0.1.7188
WebTablet FB Plugin 32 bit Wacom Technology Corp. 2015/05/08 2.1.0.7
WebTablet FB Plugin 64 bit Wacom Technology Corp. 2015/05/08 2.1.0.7
WinRAR 4.00 beta 4 (32-bit) win.rar GmbH 2016/10/23 4.00.4
Yahoo!ツールバー Yahoo! JAPAN. 2016/01/23 4.01 MB 8.0.0.3
ペイントツールSAI Ver.1 2015/05/08
ワコム タブレット Wacom Technology Corp. 2015/05/08 6.3.11-4
联想帐号 Lenovo 2016/12/10 4.56 MB 1.0.2.141
ソ・ケ 上海广乐网络科技有限公司 2016/12/08 2.8.25.4
  • puri
  • 2016/12/12 (Mon) 08:31:08
遅くなりました
回答が遅くなりまことに申し訳ありません。
では続けてHJTとCCで処置を行いましょう。

PCをセーフモードで起動させてください。

HJTを起動させ、今一度スキャンを行ってください。
スキャン結果が表示されましたら、以下の項目にチェックを入れてください。
ただし、特にHJTでの作業は一歩間違えれば簡単にPCが起動しなくなるため、
こちらが指示した以外のものは絶対にチェックを入れないでください。

O23 - Service: 主?防御 (ZhuDongFangYu) - Unknown owner - C:\Program Files (x86)\360\360Safe\deepscan\zhudongfangyu.exe (file missing)

必要な項目すべてにチェックが入りましたら、Fix checkedをクリックしてください。
上記のFixが完了したら、HJTを終了させGUを起動させてください。
以下の項目を探し出し、ダブルクリックで削除を行ってください。

ソ・ケ 上海广乐网络科技有限公司 2016/12/08 2.8.25.4

GU上に表示されているソフトウェアをダブルクリックで削除できます。
削除が完了すると自動的にスキャンが開始されますので、
スキャンが完了しましたらOKを押して削除を完了させてください。
ただ、今回のものは既にOTLで削除済みですのでアンインストールできない場合があります。
その場合は該当の項目を右クリックし、エントリの削除を押してください。
GUでのアンインストールまたは削除が完了しましたら、GUを終了させてください。
Windowsインストーラーがどうとかの表示が出た場合はPCを通常モードで再起動し、
その状態で改めて該当ソフトウェアのみをアンインストールしてください。
通常モードとセーフモードを使い分けながらご案内しているすべてのソフトウェアの削除が完了するまで続けてください。
PCを通常モードで再起動させてください。
キーボードの左Ctrlと左Altの間にあるスタートボタンを押しながらRボタンを押します。
ファイル名を指定して実行と言うものが起動しますので、そちらに半角英数で以下を入力してください。

cleanmgr

入力が完了しましたらエンターキーを押してください。
C:ドライブを選択してOKを押します。
スキャンが開始されますので完了するまでお待ちください。
スキャンが完了すると一覧が表示されますので、すべてにチェックを入れてOKを押してください。
ただし、OKを押すとごみ箱の中身を含めてすべて削除されますので、
ごみ箱の中に必要なファイルが入っている場合はご注意ください。
CCを起動させてください。
「ツール」→「スタートアップ」→「Windows」のタブを開いてください。
そこで右下の「テキストとして保存」を押すと、表示の内容がログとして保存できますので、
デスクトップ等、分かりやすい場所に最新のログのみ保存しておきましょう。
同じく「スケジュールされたタスク」のタブ、「コンテキストメニュー」のタブもログ保存を行います。
次にブラウザプラグインの項目を開き、「Internet Explorer」、「Firefox」、「Google Chrome」の各タブもログ保存を行います。
タブが存在しないものがある場合、そちらは飛ばしてログ取得を続けてください。
保存したログをすべて貼り付けてご連絡をお願いいたします。
  • IVNO
  • 2016/12/13 (Tue) 19:23:36
GUについて
こちらこそ遅くなって申し訳ありません。

GUが起動しなくなってしまいました。
再度ダウンロードしても、起動させようとすると「アプリケーションが見つかりません」と出てきます。
どうしたらいいでしょうか?

お手数で申し訳ありませんがご返信お待ちしております。
  • puri
  • 2016/12/15 (Thu) 06:28:23
なぜか嫌な予感がしますが
GUが動作しなくなりましたか。
少し前にもこれと似たような症状が発生したことがあるのですが、とりあえず正攻法でいきましょうか。

それではGUの部分は以降すべて「プログラムと機能」に読み替えてください。
コントロールパネル→プログラムと機能から削除を行ってみてください。
  • IVNO
  • 2016/12/15 (Thu) 07:17:54
ログを取りました
ログを取りました。ご確認お願い致します。

Windows

有効 HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run GoogleChromeAutoLaunch_5850FDE37EF22CDAB7B2FC1F7CA062A9 The Chromium Authors "C:\Users\youazuma\AppData\Local\Chromium\Application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
有効 HKCU:Run Power2GoExpress CyberLink Corp. "C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe"
有効 HKCU:RunOnce Uninstall C:\Users\youazuma\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64 Microsoft Corporation C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\youazuma\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"
有効 HKLM:Run CLMLServer CyberLink "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
有効 HKLM:Run MSC Microsoft Corporation "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
有効 HKLM:Run RemoteControl10 CyberLink Corp. "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
有効 HKLM:Run RTHDVCPL Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
有効 HKLM:Run USB3MON Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
有効 Startup User Adobe Gamma.lnk Adobe Systems, Inc. C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe



スケジュールされたタスク

有効 Task BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B} C:\Program Files (x86)\baidu\update\baidujp_update.exe -Update
有効 Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task ea5c627cab74616cc44f5ed6ed47587b Microsoft Corporation rundll32.exe "C:\Program Files (x86)\Canon\41dm1x.dll",e62dc6c6547f46bda862da2d05af6862
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task Grocather Configuration "C:\Program Files (x86)\Analerpy\prubile.exe" 9ff87276-13f7-44d9-a4bb-dd6ca24d6365
有効 Task ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe" --domain-id 4e00205a-2ab1-4423-8f77-cc25b82cde1d --caller scheduler-impersonate
有効 Task ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe" --domain-id 4e00205a-2ab1-4423-8f77-cc25b82cde1d --caller winlogon-impersonate
有効 Task KuaiZip_Update C:\PROGRA~1\ソ・ケ\X86\Update.exe
有効 Task Lenovo LSF Task 联想软件 "C:\Program Files (x86)\Lenovo\Lsf\LsfHelper.exe"
有効 Task osTip C:\ProgramData\WindowsMsg\Chrome.exe
有効 Task SecureUpdater "C:\Program Files (x86)\UCBrowser\Security\uclauncher.exe" --update-config
有効 Task UCBrowserUpdater C:\Program Files (x86)\UCBrowser\Application\update_task.exe /update
有効 Task UCBrowserUpdaterCore C:\Program Files (x86)\UCBrowser\Application\update_task.exe /task=1
有効 Task UpdateTask C:\Users\youazuma\AppData\Local\{11022~1\UNINST~1.EXE /Check
有効 Task WpsUpdateTask_Administrator Zhuhai Kingsoft Office Software Co.,Ltd C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsupdate.exe -from=task



コンテキストメニュー

有効 Directory KuaiZipShlExt C:\Program Files\ソ・ケ\X64\KZipShell.dll
有効 Directory WinRAR C:\Program Files (x86)\WinRAR\rarext64.dll
有効 Directory WinRAR32 C:\Program Files (x86)\WinRAR\rarext.dll
有効 Drive KuaiZipShlExt C:\Program Files\ソ・ケ\X64\KZipShell.dll
有効 File KuaiZipShlExt C:\Program Files\ソ・ケ\X64\KZipShell.dll
有効 File ContextMenuExt C:\Program Files\ソ・ケ\X64\KZipShell.dll
有効 File WinRAR C:\Program Files (x86)\WinRAR\rarext64.dll
有効 File WinRAR32 C:\Program Files (x86)\WinRAR\rarext.dll
有効 Folder WinRAR C:\Program Files (x86)\WinRAR\rarext64.dll
有効 Folder WinRAR32 C:\Program Files (x86)\WinRAR\rarext.dll



Internet Explorer

無効 Helper Yahoo!ツールバーフィッシング警告 Yahoo Japan Corporation. C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\ypho.dll
無効 Helper Yahoo!ツールバーフィッシング警告 Yahoo Japan Corporation. C:\Program Files\Yahoo!J\Toolbar64\8_0_0_3\Modules\ypho.dll
無効 Helper Yahoo!ツールバーヘルパー Yahoo! JAPAN C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\YahooToolBar.dll
無効 Helper Yahoo!ツールバーヘルパー Yahoo! JAPAN C:\Program Files\Yahoo!J\Toolbar64\8_0_0_3\Modules\YahooToolBar.dll
無効 Toolbar Yahoo!ツールバー Yahoo! JAPAN C:\Program Files (x86)\Yahoo!J\Toolbar\8_0_0_3\Modules\YahooToolBar.dll
無効 Toolbar Yahoo!ツールバー Yahoo! JAPAN C:\Program Files\Yahoo!J\Toolbar64\8_0_0_3\Modules\YahooToolBar.dll



Google Chrome

有効 App Gmail 8.1 ユーザー 1 C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0
有効 App Google ドライブ 14.1 ユーザー 1 C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0
有効 App YouTube 4.2.8 ユーザー 1 C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0
有効 Extension Google オフライン ドキュメント 1.4 ユーザー 1 C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1
有効 Extension Google ドキュメント 0.9 ユーザー 1 C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0
有効 Extension Yahoo! JAPANに簡単アクセス 1.0.0.12 ユーザー 1 C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\paangjfdbofpdicjllcdhhojebiblepe\1.0.0.12_0
無効 Extension Yahoo!検索設定 1.0.0.3 ユーザー 1 C:\Users\youazuma\AppData\Local\Google\Chrome\User Data\Default\Extensions\kaefldlncokopeklgbllnmmnmdomodpj\1.0.0.3_0
  • puri
  • 2016/12/15 (Thu) 08:31:06
安定版の旧MBAMでスキャンを
こんばんは。

IVNOさんがご多忙で遅くなりそうなので、極道な自分が代打レスします(←どこのヒットマンだよぅ

ログを見せてもらいましたが、自分も予想してたモノが見つかってますね。

では以下の説明を読んでから、続きの作業してもらえますか。

まず作業に使っているCCを更新しておいてください。本日更新がリリースされています。

更新できたらCCを起動して「スケジュールされたタスク」タブ内の下記を選択して「無効」にしたあと、続けて「エントリの削除」してください。無効にできないときはそのまま削除でもいいです。
有効 Task BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B} C:\Program Files (x86)\baidu\update\baidujp_update.exe -Update

有効 Task KuaiZip_Update C:\PROGRA~1\ソ・ケ\X86\Update.exe

有効 Task SecureUpdater "C:\Program Files (x86)\UCBrowser\Security\uclauncher.exe" --update-config

有効 Task UCBrowserUpdater C:\Program Files (x86)\UCBrowser\Application\update_task.exe /update

有効 Task UCBrowserUpdaterCore C:\Program Files (x86)\UCBrowser\Application\update_task.exe /task=1

有効 Task UpdateTask C:\Users\youazuma\AppData\Local\{11022~1\UNINST~1.EXE /Check

次に「コンテキストメニュー」タブでも下記を同様に処置です。
有効 Directory KuaiZipShlExt C:\Program Files\ソ・ケ\X64\KZipShell.dll

有効 Drive KuaiZipShlExt C:\Program Files\ソ・ケ\X64\KZipShell.dll

有効 File KuaiZipShlExt C:\Program Files\ソ・ケ\X64\KZipShell.dll

CCを終了したら次は下記のツールを準備してください。
「AdwCleaner」(通称:AC)
http://www.bleepingcomputer.com/download/adwcleaner/dl/125/
ファイル直リンです。アクセスしてファイルをデスクトップにでも保存しておいてください。
片付けるときは起動後に「uninstall」ボタンを押せば自動で削除されます。
使い方は下記サイト様に詳しい説明があるのでサンショウウオ↓
http://www.japan-secure.com/entry/adwcleaner.html

Malwarebytes' Anti-Malware(通称・MBAM)
本家サイト
http://www.malwarebytes.org/

ですが、MBAMは現在安定性や動作で時々バグが出ており、普通に使っても正常にスキャンができないバグまで起きることがあります。
そのため本家サイトから最新版のダウンロードせず、ここではあえて旧バージョンで作業します。

旧バージョンの説明サイト↓
http://www.japan-secure.com/entry/blog-entry-7.html

以下のURLからMBAMの旧バージョンをダウンロードしてください。
http://www.oldapps.com/malwarebytes.php?old_malwarebytes=12090?download
ファイル直リンです。保存しておいてください。

注)インストール時に日本語でインストールすると文字化けすることがあります。英語でインストール後に日本語化してください。
MBAM起動して「Settings」タブ→「Language」→「Japanese」で日本語化できます。

準備できたらMBAMをインストールとアップデートまでしておいてください。
ただし、ここではまだスキャンはしないように。
なお、ここでMBAMの更新で「プログラム」自体は更新せず、定義だけ更新しておいてください。
プログラム本体を更新すると、バグ多発中の最新版になってしまうので、せっかく旧バージョンでインストールした意味がなくなります。

両ツールのアップデートができたらディスククリーンアップを使ってゴミファイルの掃除したあと、ACを起動してください。
起動したら今度は「スキャン」したあと、そのスキャン終了後に検出されたものがあったら「除去」を押してください。
表示された画面で「はい」を選択すると処置開始されます。

処置完了したらそこでPCを通常モードで再起動してください。

再起動後にACのあらたなログが出るので、それをデスクトップにでも保存しておいてください。
ですが、もし作業後にログが出ないorわからない場合はマイコンピュータのCドライブを開くとその直下に以下のような名前のファイルが作成されているので、それがACのログです。
>AdwCleaner[英数字].txt
同じような名前のログが複数ある時は、作成日時が作業処置時のファイルが対象のログです。

続いてPCをセーフモード再起動したら、先に一度起動したMBAMを再度起動して今度はスキャンしてください。
MBAM起動したら「スキャナー」タブから「フルスキャン」してください。
対象ドライブはCを含めて全ドライブを選択してください。

スキャン対象は全ドライブを選択(チェック)してください。時間はかかりますができるだけ細かくスキャンするためです。
順番はどちらからでもいいですが、なにか検出されたらそれを選択して「remove」(隔離)したあと、再起動を促す表示が出たらそこで一度PCを再起動してください。
もし再起動表示が出ないときは手動で再起動してください。

またMBAMスキャン終了後、「詳細を表示」を押すとその結果が表示されるはずなので、そこで「ログを保存」を押すとそのログが保存可能になります。
そのログをデスクトップにでも保存しておいてください。
このログ確認が特に重要なので、忘れないようにお願いします。

このあとしばらくPC状態を様子見後、作業後に保存したACとMBAMのログを返信に貼り付けて、それを状態報告とともにレスで見せてください。
  • 悪代官
  • 2016/12/15 (Thu) 17:18:31
MBAMのダウンロード
ご返信有難うございます。

MBAMの旧バージョンをダウンロードしようとすると、
「この先のサイトには有害なプログラムがあります」というページに飛んでダウンロードできません…

また、CCの作業で以下の項目は削除しなくても大丈夫なのでしょうか?
有効 File ContextMenuExt C:\Program Files\ソ・ケ\X64\KZipShell.dl

宜しくお願い致します。
  • puri
  • 2016/12/16 (Fri) 08:30:54
そうなんですよね
OldAppsはなぜかブロックされてダウンロードできない場合があるんですよね。
私のオンラインストレージ経由のダウンロードリンクを貼っておきますので、こちらからダウンロードなされてください。
https://apps.tourocloudbackup.com/d/?94934XDJ78
  • IVNO
  • 2016/12/16 (Fri) 08:36:24
もしやブラウザはChromeでアクセスしましたか?
レスが遅くなってすみません。

IVNOさん、フォローありがとうございます。

ところでpuriさん、MBAM旧バージョンのページにアクセスできなかったのはブラウザがChromeでアクセスしましたか?

もしそうならブラウザをIEかFirefoxあたりでアクセスすればおそらくDLできると思います。
Chromeはサイト判定も結構独特なので、当掲示板で作業に使っている各ツールのページもブロックされることが多いので。

それと下記ですが
>有効 File ContextMenuExt C:\Program Files\ソ・ケ\X64\KZipShell.dl

これも無効と削除しておいてください。
また自分の指示が抜けてて申し訳ありません。
ではMBAM安定版のスキャンできたらその結果ログもまたレスお願いします
  • 悪代官
  • 2016/12/16 (Fri) 22:00:44
つまずいております…
IEでMBAMをダウンロードしました。

>準備できたらMBAMをインストールとアップデートまでしておいてください。
ただし、ここではまだスキャンはしないように。
なお、ここでMBAMの更新で「プログラム」自体は更新せず、定義だけ更新しておいてください。

アップデートがよくわからなかったのでとりあえずインストールだけ行って、
定義の更新というのもよくわからなかったので行っておりません…

MBAMはこのような状態で、次の作業に入ってしまいました。
ACを起動、スキャン、除去、通常モードで再起動、ログをデスクトップに保存、
セーフモードで再起動しました。

MBAMを起動したのですが、スキャンタブに「フルスキャン」というものがありませんでした。
うろ覚えで申し訳ないのですが、
脅威スキャン、カスタマイズスキャン、ハイパースキャン
と表示されておりました。
旧バージョンを上手くインストールできていないのでしょうか?

また、PCが急にとても起動が遅くなったり、画面が黒いまま動かなくなったり、デスクトップで固まるようになってしまっています…
  • puri
  • 2016/12/18 (Sun) 06:43:27
そちらは最新版ですね
残念ながら、そちらは最新バージョンのMBAMとなります。
誤って最新バージョンにアップデートしてしまったみたいですので、一度アンインストールされてください。
改めて手順を記載いたしますのでご確認ください。

最新バージョンには動作しなくなるなどの不具合があるため、ここでは旧バージョンを利用します。
インストールの最後に出てくるMalwarebytes Anti-Malware Pro版の無料試用を開始する。のチェックを外します。
このソフトウェアは日本語対応ではありますが、初回起動時は文字化けしておりますので、以下の手順で日本語化を行ってください。
MBAMを起動させてください。
MBAMを起動時に自動アップデートが始まります。
最新バージョンをダウンロードしたと表示されたら、必ずキャンセルを押してください。
次にウイルス定義ファイルのアップデートが始まりますので、アップデート終了までお待ちください。
ウイルス定義ファイルのバージョンアップが完了すると、再度最新バージョンをダウンロードしたと出ますので、
再びキャンセルを押してアップデートを中止してください。
MBAMが起動したら設定タブを開き、Languageの項目の部分をJapaneseに再度変更することで日本語化が可能です。
この段階ではスキャンは行いませんので、設定が完了したらMBAMを終了させておいてください。

PCをセーフモードで起動させ、悪代官さんの指示に従って処置を行ってください。
  • IVNO
  • 2016/12/18 (Sun) 11:04:30
遅くなりました
遅くなって申し訳ありません!
無事作業を進めることができました。
ログを貼りますので、ご確認お願い致します。

ACのログ

# AdwCleaner v6.040 - ログファイルの作成日 18/12/2016 作成時間 05:45:30
# Malwarebytesによる 02/12/2016 の更新日
# データベース : 2016-12-17.2 [サーバー]
# オペレーティングシステム : Windows 7 Home Premium Service Pack 1 (X64)
# ユーザー名 : youazuma - YOUAZUMA-PC
# 実行場所 : C:\Users\youazuma\Downloads\AdwCleaner.exe
# モード:安全
# サポート : https://www.malwarebytes.com/support



***** [ サービス ] *****

[-] 削除済みサービス:gexyfequ
[-] 削除済みサービス:UCGuard


***** [ フォルダ ] *****

[-] 削除済みフォルダ:C:\Users\youazuma\AppData\Roaming\Softlink
[-] 削除済みフォルダ:C:\ProgramData\Thunder Network
[-] 削除済みフォルダ:C:\ProgramData\Microleaves
[#] 再起動時に削除されたフォルダ::C:\ProgramData\thunder network
[#] 再起動時に削除されたフォルダ::C:\ProgramData\Application Data\Thunder Network
[#] 再起動時に削除されたフォルダ::C:\ProgramData\Application Data\Microleaves
[#] 再起動時に削除されたフォルダ::C:\ProgramData\Application Data\thunder network
[-] 削除済みフォルダ:C:\Users\Public\Documents\Guid
[-] 削除済みフォルダ:C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\CalendarTool
[-] 削除済みフォルダ:C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\WeatherTool
[-] 削除済みフォルダ:C:\Users\youazuma\AppData\Local\app


***** [ ファイル ] *****

[-] 削除済みファイル:C:\Users\youazuma\Desktop\AutoTime.lnk


***** [ DLL ] *****



***** [ WMI ] *****



***** [ ショートカット ] *****

[-] 修正済みショートカット:C:\Users\Public\Desktop\Google Chrome.lnk
[-] 修正済みショートカット:C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[-] 修正済みショートカット:C:\Users\youazuma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[-] 修正済みショートカット:C:\Users\youazuma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Chromium.lnk
[-] 修正済みショートカット:C:\Users\youazuma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[-] 修正済みショートカット:C:\Users\youazuma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[-] 修正済みショートカット:C:\Users\youazuma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
[-] 修正済みショートカット:C:\Users\youazuma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk


***** [ スケジュール済みタスク ] *****

[-] 検出済みタスク:osTip


***** [ レジストリ ] *****

[-] 削除済みキー:HKLM\SOFTWARE\Classes\UCHTML
[-] 削除済みキー:HKLM\SOFTWARE\Classes\UCHTML.AssocFile.CRX
[-] 削除済みキー:HKLM\SOFTWARE\Classes\UCHTML.AssocFile.HTM
[-] 削除済みキー:HKLM\SOFTWARE\Classes\UCHTML.AssocFile.HTML
[-] 削除済みキー:HKLM\SOFTWARE\Classes\UCHTML.AssocFile.MHT
[-] 削除済みキー:HKLM\SOFTWARE\Classes\UCHTML.AssocFile.SHTM
[-] 削除済みキー:HKLM\SOFTWARE\Classes\UCHTML.AssocFile.SHTML
[-] 削除済みキー:HKLM\SOFTWARE\Classes\UCHTML.AssocFile.WEBP
[-] 削除済みキー:HKLM\SOFTWARE\Classes\UCHTML.AssocFile.XHT
[-] 削除済みキー:HKLM\SOFTWARE\Classes\UCHTML.AssocFile.XHTML
[-] 削除済みキー:HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\GoogleChromeUpService
[#] 再起動時に削除されたキー:[x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\GoogleChromeUpService
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.001
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.002
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.003
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.004
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.005
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.006
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.007
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.008
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.009
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.01
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.010
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.011
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.012
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.013
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.014
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.015
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.016
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.017
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.018
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.019
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.02
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.020
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.021
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.022
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.023
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.024
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.025
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.026
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.027
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.028
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.029
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.03
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.030
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.031
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.032
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.033
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.034
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.035
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.036
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.037
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.038
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.039
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.04
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.040
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.041
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.042
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.043
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.044
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.045
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.046
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.047
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.048
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.049
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.05
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.050
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.051
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.052
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.053
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.054
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.055
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.056
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.057
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.058
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.059
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.06
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.060
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.061
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.062
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.063
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.064
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.065
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.066
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.067
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.068
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.069
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.07
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.070
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.071
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.072
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.073
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.074
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.075
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.076
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.077
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.078
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.079
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.08
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.080
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.081
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.082
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.083
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.084
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.085
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.086
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.087
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.088
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.089
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.09
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.090
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.091
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.092
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.093
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.094
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.095
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.096
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.097
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.098
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.099
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.7z
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.arj
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.bz2
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.cab
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.gz
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.gzip
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.jar
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.kz
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.lzh
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.mou
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.rar
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.rpm
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.tar
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.tbz
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.tgz
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.wim
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.z
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip.zip
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZipMount.ape
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZipMount.bin
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZipMount.ccd
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZipMount.cue
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZipMount.flac
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZipMount.iso
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZipMount.isz
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZipMount.mdf
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZipMount.mds
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZipMount.nrg
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZipMount.vcd
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZipMount.wv
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZipMount_FileAsso.Origin
[-] 削除済みキー:HKLM\SOFTWARE\Classes\KuaiZip_FileAsso.Origin
[-] 削除済みキー:HKLM\SOFTWARE\Classes\QZipShell.ContextMenuExt
[-] 削除済みキー:HKLM\SOFTWARE\Classes\QZipShell.ContextMenuExt.1
[-] 削除済みキー:HKLM\SOFTWARE\Classes\QZipShell.DragDropMenu
[-] 削除済みキー:HKLM\SOFTWARE\Classes\QZipShell.DragDropMenu.1
[-] 削除済みキー:HKLM\SOFTWARE\Classes\QZipShell.KYDropHandler
[-] 削除済みキー:HKLM\SOFTWARE\Classes\QZipShell.KYDropHandler.1
[-] 削除済みキー:HKLM\SOFTWARE\Classes\QZipShell.KzShlobj
[-] 削除済みキー:HKLM\SOFTWARE\Classes\QZipShell.KzShlobj.1
[-] 削除済みキー:HKLM\SOFTWARE\Classes\QZipShell.PropertyExt
[-] 削除済みキー:HKLM\SOFTWARE\Classes\QZipShell.PropertyExt.1
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.001
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.002
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.003
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.004
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.005
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.006
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.007
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.008
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.009
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.01
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.010
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.011
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.012
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.013
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.014
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.015
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.016
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.017
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.018
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.019
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.02
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.020
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.021
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.022
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.023
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.024
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.025
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.026
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.027
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.028
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.029
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.03
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.030
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.031
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.032
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.033
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.034
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.035
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.036
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.037
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.038
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.039
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.04
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.040
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.041
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.042
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.043
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.044
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.045
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.046
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.047
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.048
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.049
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.05
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.050
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.051
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.052
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.053
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.054
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.055
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.056
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.057
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.058
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.059
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.06
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.060
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.061
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.062
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.063
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.064
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.065
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.066
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.067
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.068
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.069
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.07
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.070
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.071
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.072
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.073
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.074
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.075
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.076
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.077
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.078
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.079
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.08
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.080
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.081
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.082
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.083
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.084
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.085
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.086
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.087
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.088
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.089
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.09
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.090
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.091
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.092
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.093
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.094
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.095
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.096
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.097
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.098
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.099
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.7z
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.arj
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.bz2
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.cab
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.gz
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.gzip
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.jar
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.kz
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.lzh
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.mou
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.rar
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.rpm
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.tar
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.tbz
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.tgz
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.wim
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.z
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip.zip
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZipMount.ape
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZipMount.bin
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZipMount.ccd
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZipMount.cue
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZipMount.flac
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZipMount.iso
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZipMount.isz
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZipMount.mdf
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZipMount.mds
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZipMount.nrg
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZipMount.vcd
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZipMount.wv
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZipMount_FileAsso.Origin
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\KuaiZip_FileAsso.Origin
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\QZipShell.ContextMenuExt
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\QZipShell.ContextMenuExt.1
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\QZipShell.DragDropMenu
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\QZipShell.DragDropMenu.1
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\QZipShell.KYDropHandler
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\QZipShell.KYDropHandler.1
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\QZipShell.KzShlobj
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\QZipShell.KzShlobj.1
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\QZipShell.PropertyExt
[#] 再起動時に削除されたキー:[x64] HKLM\SOFTWARE\Classes\QZipShell.PropertyExt.1
[-] 削除済みキー:HKLM\SOFTWARE\Classes\AppID\{9CC34070-3A38-4C7A-89CB-EF8177EF07A1}
[-] 削除済みキー:HKLM\SOFTWARE\Classes\TypeLib\{86C4C3BA-4EA4-4CF8-98B9-6B07B477B835}
[-] 削除済みキー:HKU\.DEFAULT\Software\UCBrowser
[-] 削除済みキー:HKU\.DEFAULT\Software\KuaiZip
[-] 削除済みキー:HKU\S-1-5-20\Software\UCBrowser
[-] 削除済みキー:HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\Software\Installer
[-] 削除済みキー:HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\Software\powerpack
[-] 削除済みキー:HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\Software\PRODUCTSETUP
[-] 削除済みキー:HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\Software\BingProvidedSearch
[-] 削除済みキー:HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\Software\osTip
[-] 削除済みキー:HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\Software\UCBrowser
[-] 削除済みキー:HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\Software\UCBrowserPID
[-] 削除済みキー:HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\Software\AutoTime
[-] 削除済みキー:HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\Software\KuaiZip
[-] 削除済みキー:HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\Software\SNDA
[-] 削除済みキー:HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\Software\KuaiZipSFX
[-] 削除済みキー:HKU\S-1-5-21-1134703352-1772604644-2719378906-1000\Software\Maoha
[#] 再起動時に削除されたキー:HKU\S-1-5-18\Software\UCBrowser
[#] 再起動時に削除されたキー:HKU\S-1-5-18\Software\KuaiZip
[#] 再起動時に削除されたキー:HKCU\Software\Installer
[#] 再起動時に削除されたキー:HKCU\Software\powerpack
[#] 再起動時に削除されたキー:HKCU\Software\PRODUCTSETUP
[#] 再起動時に削除されたキー:HKCU\Software\BingProvidedSearch
[#] 再起動時に削除されたキー:HKCU\Software\osTip
[#] 再起動時に削除されたキー:HKCU\Software\UCBrowser
[#] 再起動時に削除されたキー:HKCU\Software\UCBrowserPID
[#] 再起動時に削除されたキー:HKCU\Software\AutoTime
[#] 再起動時に削除されたキー:HKCU\Software\KuaiZip
[#] 再起動時に削除されたキー:HKCU\Software\SNDA
[#] 再起動時に削除されたキー:HKCU\Software\KuaiZipSFX
[#] 再起動時に削除されたキー:HKCU\Software\Maoha
[-] 削除済みキー:HKLM\SOFTWARE\UCBrowser
[-] 削除済みキー:HKLM\SOFTWARE\UCBrowserPID
[-] 削除済みキー:HKLM\SOFTWARE\Maoha
[-] 削除済みキー:HKLM\SOFTWARE\FFinder LTD
[-] 削除済みキー:HKLM\SOFTWARE\Microleaves
[#] 再起動時に削除されたキー:[x64] HKCU\Software\Installer
[#] 再起動時に削除されたキー:[x64] HKCU\Software\powerpack
[#] 再起動時に削除されたキー:[x64] HKCU\Software\PRODUCTSETUP
[#] 再起動時に削除されたキー:[x64] HKCU\Software\BingProvidedSearch
[#] 再起動時に削除されたキー:[x64] HKCU\Software\osTip
[#] 再起動時に削除されたキー:[x64] HKCU\Software\UCBrowser
[#] 再起動時に削除されたキー:[x64] HKCU\Software\UCBrowserPID
[#] 再起動時に削除されたキー:[x64] HKCU\Software\AutoTime
[#] 再起動時に削除されたキー:[x64] HKCU\Software\KuaiZip
[#] 再起動時に削除されたキー:[x64] HKCU\Software\SNDA
[#] 再起動時に削除されたキー:[x64] HKCU\Software\KuaiZipSFX
[#] 再起動時に削除されたキー:[x64] HKCU\Software\Maoha
[-] 削除済みキー:[x64] HKLM\SOFTWARE\CALENDARTOOL
[-] 削除済みキー:[x64] HKLM\SOFTWARE\UCBrowser
[-] 削除済みキー:[x64] HKLM\SOFTWARE\pcv-var
[-] 削除済みキー:[x64] HKLM\SOFTWARE\DtsEncodeTools
[-] 削除済みキー:[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D9BAB2C9-5236-48c3-AF02-67E799F09BBD}
[-] 削除済みキー:HKCU\Software\Microsoft\Internet Explorer\DOMStorage\yeabd66.cc
[-] 削除済みキー:HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\yeabd66.cc
[#] 再起動時に削除されたキー:[x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\yeabd66.cc
[#] 再起動時に削除されたキー:[x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\yeabd66.cc
[-] 削除済みキー:HKLM\SOFTWARE\Clients\StartMenuInternet\UCBrowser
[-] 削除済みキー:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\UCBrowser.exe
[-] 復元済み値:HKLM\SOFTWARE\RegisteredApplications [UCBrowser]
[-] 削除済みキー:HKLM\SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\UCBrowser.exe
[-] 復元済み値:HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [kuaizipupdatesvc]
[-] 削除済みキー:HKLM\SOFTWARE\Classes\AppID\QZipShell.DLL


***** [ ブラウザ ] *****



*************************

:: "Tracing" キーを削除しました
:: Winsock設定を削除しました

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [30244 バイト] - [18/12/2016 05:45:30]
C:\AdwCleaner\AdwCleaner[S0].txt - [27386 バイト] - [18/12/2016 05:41:28]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [30400 バイト] ##########
  • puri
  • 2016/12/21 (Wed) 07:11:46
MBAMのログ
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

定義バージョン: v2016.12.19.11

Windows 7 Service Pack 1 x64 NTFS (セーフモード)
Internet Explorer 11.0.9600.18537
youazuma :: YOUAZUMA-PC [管理者]

2016/12/20 8:02:36
mbam-log-2016-12-20 (08-02-36).txt

スキャンタイプ: フルスキャン (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
有効なスキャン領域: メモリ | スタートアップ | レジストリ | ファイルシステム | ヒューリスティック/追加アイテムのスキャン  | ヒューリスティック/Shuriken エンジンを使用してスキャン  | 不審なプログラム (PUP) | 不審な変更 (PUM)
無効なスキャン領域: ピア・ツー・ピアプログラム(P2P)
スキャンしたアイテム数: 437279
経過時間: 37 分, 32 秒

メモリプロセスの検出: 0
(悪意のあるアイテムは検出されていません。)

メモリモジュールの検出: 0
(悪意のあるアイテムは検出されていません。)

レジストリキーの検出: 2
HKCU\Software\magryful (PUP.Optional.Hicosmea) -> 何の措置も取られませんでした。
HKLM\SYSTEM\CurrentControlSet\Services\PCSUUCDRV (PUP.Optional.PCSpeedUp) -> 何の措置も取られませんでした。

レジストリ値の検出: 1
HKCU\Software\Microsoft\Windows\CurrentVersion\Run|GoogleChromeAutoLaunch_5850FDE37EF22CDAB7B2FC1F7CA062A9 (PUP.Optional.NotChromeRun) -> データ: "C:\Users\youazuma\AppData\Local\Chromium\Application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session -> 何の措置も取られませんでした。

レジストリデータ項目の検出: 0
(悪意のあるアイテムは検出されていません。)

フォルダの検出: 0
(悪意のあるアイテムは検出されていません。)

ファイルの検出: 21
C:\Users\youazuma\Downloads\LB2zip.zip (PUP.Optional.Amonetize) -> 何の措置も取られませんでした。
C:\Users\youazuma\Downloads\media-player_install.zip (PUP.Optional.BundleInstaller) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files\ソ・ケ\X64\KZMount2.exe (PUP.Optional.Kuaizip) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files\ソ・ケ\X86\DiskOpt.exe (PUP.Optional.Kuaizip) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files\ソ・ケ\X86\KuaiZip.exe (PUP.Optional.Kuaizip) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files\ソ・ケ\X86\KZReport.exe (PUP.Optional.Kuaizip) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files\ソ・ケ\X86\Uninst.exe (PUP.Optional.Kuaizip) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files\ソ・ケ\X86\UpdateChecker.exe (PUP.Optional.ChinAd) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files (x86)\Thihurzuly\launcher_18.dll (PUP.Optional.Elex) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files (x86)\Thihurzuly\Release_16.dll (PUP.Optional.Elex) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_ProgramData\service.exe (PUP.Optional.Elex) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Users\youazuma\AppData\Roaming\efo\efo.exe (PUP.Optional.EasyFileOpener) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Users\youazuma\AppData\Roaming\KuaiZip\kminiinews4.exe (PUP.Optional.ChinAd) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Users\youazuma\AppData\Roaming\KuaiZip\KuaizipSetup_zzlm_013.exe (PUP.Optional.Kuaizip) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Users\youazuma\AppData\Roaming\KuaiZip\kyminiinewsxktt.exe (PUP.Optional.ChinAd) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Users\youazuma\AppData\Roaming\KuaiZip\kyminiiniewsgw.exe (PUP.Optional.ChinAd) -> 何の措置も取られませんでした。
C:\_OTL\MovedFiles\12112016_072854\C_Users\youazuma\AppData\Roaming\KuaiZip\miniinewsxktt2.exe (PUP.Optional.ChinAd) -> 何の措置も取られませんでした。
C:\Users\youazuma\Downloads\Downloader.exe (Adware.FileFinder) -> 正常に隔離され削除されました。
C:\Users\youazuma\Downloads\LB2.zip_downloader.exe (Adware.FileFinder) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_ProgramData\WindowsMsg\Chrome.exe (Adware.Eszjuxuan) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Users\youazuma\AppData\Roaming\Reezientaromry\Whatherrnuly.dll (Adware.Elex.SHHKRST) -> 正常に隔離され削除されました。

(終)


PC状態ですが、Chromeを開こうとすると「次の場所から拡張機能を読み込むことができませんでした。マニフェストファイルが見つからないか読み取れません。」と出てくるようになりました。
あと、ChromeでもIEでも、http://yeabd66.cc/がまだ出てきます
また、スタートを押すとUCがまだ表示されます。
デスクトップにはクロックATというのがまだ残っています。


お手数ですが、次の指示を頂ければと思います。宜しくお願い致します。
  • puri
  • 2016/12/21 (Wed) 07:19:31
MBAMの設定を変更して再度処置を
ログを確認いたしました。
MBAMでの処置の際、チェックボックスにチェックが入っていないものが一部存在したため、
MBAMでの処置が正常に行われていないものがあります。
以下の手順でMBAMの設定を行い、その後再度フルスキャンを行ってください。

MBAMを起動させてください。
最新バージョンにするかと問われますので、キャンセルを押します。
設定のタブを開きます。
スキャン設定のタブを開き、不審なプログラム(PUP)への処置の項目とピア・ツー・ピアプログラム(P2P)への処置の項目を、
詳細リストに表示して「除去」にチェックに変更してください。
設定が完了しましたら再度フルスキャンを行い、駆除を行ってください。
処置後のログを貼り付けてご連絡ください。
  • IVNO
  • 2016/12/21 (Wed) 17:23:28
遅くなりました
遅くなって申し訳ありません。
ログを貼りますので、お手数ですがご確認をお願い致します。

またPCの状態は前回と全く変わりありません…


Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

定義バージョン: v2016.12.19.11

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.18537
youazuma :: YOUAZUMA-PC [管理者]

2016/12/26 9:09:59
mbam-log-2016-12-26 (09-09-59).txt

スキャンタイプ: フルスキャン (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
有効なスキャン領域: メモリ | スタートアップ | レジストリ | ファイルシステム | ヒューリスティック/追加アイテムのスキャン  | ヒューリスティック/Shuriken エンジンを使用してスキャン  | 不審なプログラム (PUP) | 不審な変更 (PUM) | ピア・ツー・ピアプログラム(P2P)
無効なスキャン領域:
スキャンしたアイテム数: 434621
経過時間: 1 時間, 3 分, 37 秒

メモリプロセスの検出: 0
(悪意のあるアイテムは検出されていません。)

メモリモジュールの検出: 0
(悪意のあるアイテムは検出されていません。)

レジストリキーの検出: 2
HKCU\Software\magryful (PUP.Optional.Hicosmea) -> 正常に隔離され削除されました。
HKLM\SYSTEM\CurrentControlSet\Services\PCSUUCDRV (PUP.Optional.PCSpeedUp) -> 正常に隔離され削除されました。

レジストリ値の検出: 1
HKCU\Software\Microsoft\Windows\CurrentVersion\Run|GoogleChromeAutoLaunch_5850FDE37EF22CDAB7B2FC1F7CA062A9 (PUP.Optional.NotChromeRun) -> データ: "C:\Users\youazuma\AppData\Local\Chromium\Application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session -> 正常に隔離され削除されました。

レジストリデータ項目の検出: 0
(悪意のあるアイテムは検出されていません。)

フォルダの検出: 0
(悪意のあるアイテムは検出されていません。)

ファイルの検出: 17
C:\Users\youazuma\Downloads\LB2zip.zip (PUP.Optional.Amonetize) -> 正常に隔離され削除されました。
C:\Users\youazuma\Downloads\media-player_install.zip (PUP.Optional.BundleInstaller) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files\ソ・ケ\X64\KZMount2.exe (PUP.Optional.Kuaizip) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files\ソ・ケ\X86\DiskOpt.exe (PUP.Optional.Kuaizip) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files\ソ・ケ\X86\KuaiZip.exe (PUP.Optional.Kuaizip) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files\ソ・ケ\X86\KZReport.exe (PUP.Optional.Kuaizip) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files\ソ・ケ\X86\Uninst.exe (PUP.Optional.Kuaizip) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files\ソ・ケ\X86\UpdateChecker.exe (PUP.Optional.ChinAd) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files (x86)\Thihurzuly\launcher_18.dll (PUP.Optional.Elex) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Program Files (x86)\Thihurzuly\Release_16.dll (PUP.Optional.Elex) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_ProgramData\service.exe (PUP.Optional.Elex) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Users\youazuma\AppData\Roaming\efo\efo.exe (PUP.Optional.EasyFileOpener) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Users\youazuma\AppData\Roaming\KuaiZip\kminiinews4.exe (PUP.Optional.ChinAd) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Users\youazuma\AppData\Roaming\KuaiZip\KuaizipSetup_zzlm_013.exe (PUP.Optional.Kuaizip) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Users\youazuma\AppData\Roaming\KuaiZip\kyminiinewsxktt.exe (PUP.Optional.ChinAd) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Users\youazuma\AppData\Roaming\KuaiZip\kyminiiniewsgw.exe (PUP.Optional.ChinAd) -> 正常に隔離され削除されました。
C:\_OTL\MovedFiles\12112016_072854\C_Users\youazuma\AppData\Roaming\KuaiZip\miniinewsxktt2.exe (PUP.Optional.ChinAd) -> 正常に隔離され削除されました。

(終)
  • puri
  • 2016/12/26 (Mon) 16:14:07
HPでスキャンを
OTL、AC、MBAMでこれだけの数があったことからも、まだ潜んでいて不思議はなさそうです。
続けて調査を行いましょう。

以下のソフトウェアをご用意ください。

herdProtect(以下HP)
http://www.herdprotect.com/installers/herdProtectScan_Setup.exe
インストールが完了しましたら起動させます。

ソフトウェアの特性上、セーフモードだと正常に動作しませんので、
セーフモードで起動中の場合は通常モードに切り替えてください。
Scanのボタンが緑色になりましたら、Scanをクリックしてスキャンを開始してください。
スキャンに必要な情報を収集したり、発見された不審なソフトウェアを
各種セキュリティソフトで調査している間は、スキャン作業が停止します。
スキャンが進行しないからと言ってフリーズしたわけではありませんので、
スキャンが完了するまで今しばらくお待ちください。
なお、HPは誤検出が非常に多いことで有名です。
検出されたからと言って安易に削除すると、Windowsが起動しなくなる可能性もあります。
ですのでここでは次回のご案内まで削除を行わないようにしてください。
スキャンが完了しましたらスキャン結果が表示されますので、
画面右上にあるSave resultsという文字をクリックしてログを出力してください。
ログは任意のお名前をつけて、分かりやすいところに保存してください。
出力されたログを貼り付けてご連絡ください。
なお、OTL同様に長文となる可能性があります。
万一長文となった際は、分割して貼り付けをお願いいたします。
  • IVNO
  • 2016/12/26 (Mon) 16:19:54
申し訳ありません
ご返信有難うございます。
ちょっと今は時間が取れないので、後日やってみます…申し訳ありません。

今急に、
Assertion failed!
という表示が出て、
中止、再試行、無視と選択肢があるんですが、どうしたらいいでしょうか?
無視を押してもずっと出続けます…
  • puri
  • 2016/12/26 (Mon) 16:29:32
HPログ
ログを貼ります。お手数ですがご確認をお願い致します。
また、Assertion failed!の表示はそのまま放置しています。


Saved date: 2016/12/27 6:17:57
Files detected: 47
Files scanned: 7,881
Processes scanned: 81
Modules scanned: 692
ASEPs scanned: 407
Downloads scanned: 9
Deep analysis: 2/0
---------------------------------------------------------------------------------

Files

---------------------------------------------------------------------------------

File path: c:\windows\system32\sechost.dll
Publisher: Microsoft Corporation
MD5: 4f90a7a0fcbc0ed18e573917860062ff
SHA-1: f12a8d4dcda17a84138966f2104500e768c7283d
Created: 2015/06/10 23:29:22
Detections: 1
Determination: Inconclusive
- Avira AntiVirus as TR/Patched.Gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\system32\rpcrtremote.dll
Publisher: Microsoft Corporation
MD5: c2a8cb1275ecb85d246a9ecc02a728e3
SHA-1: 4417207821fc8f5c72ff531683f183caef297882
Created: 2010/11/21 12:24:01
Detections: 1
Determination: Inconclusive
- Avira AntiVirus as W32/Ramnit.A (Malware)

---------------------------------------------------------------------------------

File path: c:\windows\system32\mssprxy.dll
Publisher: Microsoft Corporation
MD5: ace1bb07e0377e37a2c514cd2ec119b1
SHA-1: 25addf65f13d1d7f1e8fdab7e0031be2d86b4356
Created: 2009/07/14 9:29:39
Detections: 1
Determination: Inconclusive
- Avira AntiVirus as TR/Patched.Gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\system32\dxgi.dll
Publisher: Microsoft Corporation
MD5: 8dfb5752fce145a6b295093c0a8be131
SHA-1: 8b9e8b1233360dfca073236f359042e335fe551e
Created: 2015/05/10 22:26:13
Detections: 1
Determination: Inconclusive
- Avira AntiVirus as W32/Sality.AT (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\system32\opengl32.dll
Publisher: Microsoft Corporation
MD5: 585fed4cdb8034b8b58aeb8008255817
SHA-1: bb671e588d77f3260b17c0ae847022d4c6467c52
Created: 2009/07/14 8:42:17
Detections: 1
Determination: Inconclusive
- Avira AntiVirus as W32/Ramnit.C (Malware)

---------------------------------------------------------------------------------

File path: c:\windows\system32\wudfx.dll
Publisher: Microsoft Corporation
MD5: 25ae683dcb4ae7e6f1b193a0cb9db35f
SHA-1: 458e6b66ec1862dfa8c2c65cc1c2e1a9e6297f18
Created: 2015/05/10 21:29:25
Detections: 1
Determination: Inconclusive
- Avira AntiVirus as TR/Dropper.Gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\system32\umpnpmgr.dll
Publisher: Microsoft Corporation
MD5: 25fbdef06c4d92815b353f6e792c8129
SHA-1: 919b3248572e6ae839b2c6f9864f1869cb2800bb
Created: 2015/05/08 5:49:52
Detections: 1
Determination: Inconclusive
- Avira AntiVirus as W32/Sality.AT (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\common files\adobe\calibration\adobe gamma loader.exe
Publisher: Adobe Systems, Inc.
MD5: c2ff17734176cd15221c10044ef0ba1a
SHA-1: c5b97dcd1ef1dd4a0fb5d7ce13e85fe1820cef47
Created: 2005/03/16 19:16:50
Detections: 1
Determination: Ignore detections (false positive)
- Boost by Reason as Optional.Startup.AdobeSystems.S

---------------------------------------------------------------------------------

File path: c:\users\youazuma\downloads\ccsetup525.exe
Publisher: Piriform Ltd
Signer: Piriform Ltd
MD5: 0bbf9bb937c34b05655a6d30e52a516e
SHA-1: f9d434eec90359c58a2f49ac5e924b9c80fe9630
Created: 2016/12/16 8:04:05
Detections: 1
Determination: Ignore detections (false positive)
- ESET NOD32 as Win32/Bundled.Toolbar.Google.D potentially unsafe application (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\youazuma\downloads\ccsetup524.exe
Publisher: Piriform Ltd
Signer: Piriform Ltd
MD5: 90f503a58ed6b340c78d626d553672f6
SHA-1: 6485c514e69979ea39ef29270f1df101bb4490b1
Created: 2016/12/06 8:21:07
Detections: 2
Determination: Inconclusive
- ESET NOD32 as Win32/Bundled.Toolbar.Google.D potentially unsafe application (Undefined)
- Reason Heuristics as PUP.Bundled.Toolbar.ET (M) (Adware)

---------------------------------------------------------------------------------

File path: c:\users\youazuma\downloads\hijackthis.exe
Publisher: Trend Micro Inc.
MD5: 47811d50390a86a17102d7496e6eabb9
SHA-1: 2623749cdb27887f6746acdee7e8065475f8b541
Created: 2016/12/06 8:20:37
Detections: 2
Determination: Ignore detections (false positive)
- Kingsoft AntiVirus as Win32.HeurC.KVM099.a.(kcloud) (Undefined)
- Rising Antivirus as PE:Trojan.VBInject!1.6546 (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\youazuma\downloads\bk27101j.exe
Publisher:
Signer: RimArts Inc.
MD5: 9bbe4d73cef81e0ccb80ca57fc8895e8
SHA-1: f155da8df567865cfcf814c58c7621adfb778b87
Created: 2015/09/20 17:10:33
Detections: 1
Determination: Ignore detections (false positive)
- ByteHero BDV as Trojan.Malware.Obscu.Gen.001 (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\youazuma\downloads\ccsetup524 (1).exe
Publisher: Piriform Ltd
Signer: Piriform Ltd
MD5: 90f503a58ed6b340c78d626d553672f6
SHA-1: 6485c514e69979ea39ef29270f1df101bb4490b1
Created: 2016/12/06 8:24:45
Detections: 2
Determination: Inconclusive
- ESET NOD32 as Win32/Bundled.Toolbar.Google.D potentially unsafe application (Undefined)
- Reason Heuristics as PUP.Bundled.Toolbar.ET (M) (Adware)

---------------------------------------------------------------------------------

File path: c:\users\youazuma\downloads\cf125b.exe
Publisher: ちとらsoft
MD5: 0a0deaaa0b4ac92d379c1bc07989e509
SHA-1: 7e403a0790d68875ff07c9deaaa195a1ba56a258
Created: 2015/07/21 0:12:40
Detections: 1
Determination: Ignore detections (false positive)
- F-Prot as W32/Agent.IK.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\youazuma\downloads\download-winrar-4.00-beta-4.exe
Publisher:
MD5: b966487e3256593c893f815f68222e2d
SHA-1: 27d612d9435f74e43217334f838ac92f2f453c17
Created: 2016/10/23 6:00:21
Detections: 4
Determination: Inconclusive
- Zillya! Antivirus as Trojan.Inject.Win32.151536 (Undefined)
- Clam AntiVirus as Trojan.Agent-283753 (Undefined)
- Kingsoft AntiVirus as Win32.Troj.Generic.(kcloud) (Undefined)
- Rising Antivirus as PE:Trojan.Win32.Generic.127C34D9!310129881 (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\youazuma\downloads\kobosetup.exe
Publisher:
Signer: Rakuten Kobo Inc.
MD5: 6c651a147df763504e1c1a1e446cc682
SHA-1: 19f7ad939b74832248d9f63ad3172e28da34288e
Created: 2016/08/16 4:09:52
Detections: 1
Determination: Adware
- Reason Heuristics as Adware.Linkury (Adware)

---------------------------------------------------------------------------------

File path: c:\users\youazuma\downloads\ukiuk210.exe
Publisher: 株式会社イーズ
MD5: 36b46dbe3e24f0d8a8411e889ab3aa5b
SHA-1: 6ca9d2afc9a9f06931d3b182333801136ee72bb0
Created: 2016/01/23 18:19:01
Detections: 5
Determination: Inconclusive
- Antiy Labs AVL as Trojan/Win32.TSGeneric (Undefined)
- G Data as Win32.Application.CNSHelper (Undefined)
- Vba32 AntiVirus as suspected of Malware.VB.46 (Undefined)
- McAfee Web Gateway as Artemis (Undefined)
- McAfee as Artemis!36B46DBE3E24 (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\youazuma\desktop\confedit125b.exe
Publisher:
MD5: 3f6332dfd46ff89bfd2d10122a88acfc
SHA-1: 92723c7c29ddf2a0df7a75159d6dad7f8df35bf9
Created: 2009/02/15 23:40:30
Detections: 1
Determination: Ignore detections (false positive)
- Vba32 AntiVirus as suspected of Trojan.StartPage.7 (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\youazuma\desktop\otl.exe
Publisher: OldTimer Tools
MD5: 4adcfee16ee9978f06157634669d36fb
SHA-1: 30b37076552e49276836d02dd73d038c27dbbee9
Created: 2016/12/10 7:55:29
Detections: 2
Determination: Ignore detections (false positive)
- Agnitum Outpost as Packed/PECompact
- Bkav FE as HW32.CDB (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\system32\chtbrkg.dll
Publisher:
MD5: bafb36bb874d7ae136cc06cc0ea56bc7
SHA-1: d007a9fa5c2ac5a09d099d2bf83cefcf6c46401d
Created: 2016/12/05 10:26:55
Detections: 1
Determination: UndefinedMalware
- Reason Heuristics as Trojan.Downloader (M) (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\system32\mfc42u.dll
Publisher: Microsoft Corporation
MD5: 19f9b524a525d202194247e96656cb88
SHA-1: 6236fee9636d3cd24b5ecb886f66ab49d71540b7
Created: 2015/05/08 5:57:39
Detections: 1
Determination: Inconclusive
- Avira AntiVirus as W32/Sality.AG (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\syswow64\chtbrkg.dll
Publisher:
MD5: eeb65d6b2bb89a461dbd1eb88015a4aa
SHA-1: fa3d126e0e51d3a0a1205b9c734076faca2434ae
Created: 2016/12/05 10:26:55
Detections: 1
Determination: UndefinedMalware
- Reason Heuristics as Trojan.Downloader (M) (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\syswow64\igdrcl32.dll
Publisher: Intel Corporation
MD5: 5d7a702c5dc8c2a4087b7be235f95524
SHA-1: 72e4401452f52639ae7c2e674fdf8f6b5da1d09a
Created: 2014/05/02 13:13:36
Detections: 1
Determination: Ignore detections (false positive)
- AegisLab AV Signature as Troj.W32.Gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\youazuma\appdata\local\chromium\application\chrome.exe
Publisher: The Chromium Authors
MD5: d6a9b136162eae1fce889f762efc8c53
SHA-1: 41cf066b43ef3d34660841afb1ef81f89794da64
Created: 2016/02/04 3:53:06
Detections: 3
Determination: UndefinedMalware
- Avira AntiVirus as W32/Chir.B (Undefined)
- Rising Antivirus as PE:Trojan.Bayrob!1.A403 [F] (Undefined)
- Reason Heuristics as Win32.Generic (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\youazuma\appdata\local\chromium\application\46.0.2480.0\libexif.dll
Publisher:
MD5: bb6542accdc386912b163738fac1a4e3
SHA-1: 4a964c42ff766f15557276a2752431ac1b9a4ef7
Created: 2016/02/04 3:53:06
Detections: 1
Determination: Inconclusive
- Avira AntiVirus as W32/Sality.AT (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\youazuma\appdata\local\svchost\svchost.exe
Publisher:
MD5: 8737b9f19e867ffe3d950b106ea25317
SHA-1: b7b026b1ce9c4ab6193fa9fe429bc52bfe6735ce
Created: 2016/12/05 10:27:03
Detections: 2
Determination: Adware
- ESET NOD32 as Win32/Adware.Eszjuxuan.E application (Adware)
- Reason Heuristics as Trojan.Downloader (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files\ccleaner\lang\lang-1025.dll
Publisher:
MD5: 4f39f1882751f18e9f71ad7c69bd7dca
SHA-1: c4109e88398356f7d4ed3f6f9cb07c004ea89381
Created: 2016/12/06 23:09:28
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/Injector.vhp (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files\ccleaner\lang\lang-1049.dll
Publisher:
MD5: 56796fb0d1108bb9dd5cf306ac519e3b
SHA-1: 4573803b33eac694b4c6d6b330a5d4b9f5f6772f
Created: 2016/12/06 23:09:36
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/PSW.Kates.bw (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files\tablet\wacom\32\lcdsettings.exe
Publisher: Wacom Technology, Corp.
MD5: 645b99fbd800df4b95d9abead611eee7
SHA-1: 26be7e7d76f32819f58649fea5b0b876647323b4
Created: 2015/05/08 6:09:16
Detections: 1
Determination: Ignore detections (false positive)
- ByteHero BDV as Trojan.Exception.gen.101 (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files\tablet\wacom\32\wacadb.exe
Publisher:
MD5: 65e1401fcec9a3c2e0849a374f345290
SHA-1: c6be15f3cfb577b78c6818bae0a0b26dad371f24
Created: 2015/05/08 6:09:17
Detections: 1
Determination: Ignore detections (false positive)
- Bkav FE as W32.HfsAutoB (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\adobe\adobe bridge\adobelm.dll
Publisher: Adobe Systems, Inc.
MD5: 5dc63a14271860cb1fa46d6ed9d8019a
SHA-1: ad41a2cc61b87371934a3fd5d9d56c7eece2cd07
Created: 2005/04/08 14:01:40
Detections: 1
Determination: Ignore detections (false positive)
- Bkav FE as HW32.CDB (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\adobe\adobe bridge\browser\es262-32.dll
Publisher: Opera Software ASA
MD5: 20fe85c42cfe193cd41d4fc447d9b301
SHA-1: 068fe84436d4ce5935004b9a78c0da2ae7056779
Created: 2005/04/08 14:03:58
Detections: 1
Determination: Ignore detections (false positive)
- Clam AntiVirus as PUA.Packed.ASPack

---------------------------------------------------------------------------------

File path: c:\program files (x86)\adobe\adobe help center\browser\ouniansi.dll
Publisher:
MD5: 24aadd77ec18a865f15a0d8b7bcd6b63
SHA-1: 3bd26bd9bff56f0f8c33e5d9cbeae531c0c388de
Created: 2005/04/20 16:31:24
Detections: 1
Determination: Ignore detections (false positive)
- Clam AntiVirus as PUA.Packed.ASPack

---------------------------------------------------------------------------------

File path: c:\program files (x86)\adobe\adobe photoshop cs2\サンプル\ドロップレット\imageready ドロップレット\64x64 pixels に固定.exe
Publisher: Adobe Systems, Inc.
MD5: 00b03ab96c1292c09d4c50dead8ab58b
SHA-1: 6969853c8ab128a965dce123d0dd0366fdbb010a
Created: 2005/04/27 13:45:28
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/Downloader.Boltolog.ldg (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\adobe\adobe photoshop cs2\サンプル\ドロップレット\imageready ドロップレット\jpeg を作成 (画質 10).exe
Publisher: Adobe Systems, Inc.
MD5: 50578981a0e4925db4c40e3c29236e47
SHA-1: d08c8b7c62d1f28771b79e72cee275caa1788dba
Created: 2005/04/27 13:45:28
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/Downloader.Boltolog.ldg (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\adobe\adobe photoshop cs2\サンプル\ドロップレット\imageready ドロップレット\スライドサムネール.exe
Publisher: Adobe Systems, Inc.
MD5: ddb3f3905d0cc1a1678200fe72e7f868
SHA-1: 77d39674622266008bf72916fb280a8fe6844dff
Created: 2005/04/27 13:45:28
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/Downloader.Boltolog.ldg (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\adobe\adobe photoshop cs2\サンプル\ドロップレット\imageready ドロップレット\メタルスライドサムネール.exe
Publisher: Adobe Systems, Inc.
MD5: 909922d2429c821d1da2eed8e3a1093e
SHA-1: 63c773179b0a9c8f5a0a1e79264aabf43e7e98eb
Created: 2005/04/27 13:45:28
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/Downloader.Boltolog.ldg (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\adobe\adobe photoshop cs2\サンプル\ドロップレット\imageready ドロップレット\角丸長方形サムネール.exe
Publisher: Adobe Systems, Inc.
MD5: c1f7ec408812e0ccf5329e4564d94ef3
SHA-1: 9d4a86cce8db6caa83c546947e86333a5161e5f4
Created: 2005/04/27 13:45:28
Detections: 1
Determination: Ignore detections (false positive)
- The Hacker as Trojan/Downloader.Boltolog.ldg (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\adobe\adobe photoshop cs2\サンプル\ドロップレット\photoshop ドロップレット\64 pixels に固定.exe
Publisher: Adobe Systems, Incorporated
MD5: 133c48ca0626ed6bc7e2f7ed1906fe22
SHA-1: 4fc6bfcbbb259f87996f3ceeb30ef0b3dede4137
Created: 2004/11/16 12:43:24
Detections: 1
Determination: Ignore detections (false positive)
- Rising Antivirus as PE:Malware.XPACK/RDM!5.1

---------------------------------------------------------------------------------

File path: c:\program files (x86)\adobe\adobe photoshop cs2\サンプル\ドロップレット\photoshop ドロップレット\jpeg 標準で保存.exe
Publisher: Adobe Systems, Incorporated
MD5: 9b1df1c2835364001270d021f203c2ba
SHA-1: 03c58f5521e75e3acaf262b829eb62d375457406
Created: 2004/11/16 12:43:24
Detections: 1
Determination: Ignore detections (false positive)
- Rising Antivirus as PE:Malware.XPACK/RDM!5.1

---------------------------------------------------------------------------------

File path: c:\program files (x86)\adobe\adobe photoshop cs2\サンプル\ドロップレット\photoshop ドロップレット\ドロップシャドウフレーム.exe
Publisher: Adobe Systems, Incorporated
MD5: a67d4f141c89af3643583e9bbebe5ec6
SHA-1: 659a807f7c791a4edbac69b25f004f6b0457b3e2
Created: 2004/11/16 12:43:24
Detections: 1
Determination: Ignore detections (false positive)
- Rising Antivirus as PE:Malware.XPACK/RDM!5.1

---------------------------------------------------------------------------------

File path: c:\program files (x86)\adobe\adobe photoshop cs2\サンプル\ドロップレット\photoshop ドロップレット\ボタンを作成.exe
Publisher: Adobe Systems, Incorporated
MD5: b1e48203d3b500a92d56fa2ba75ae3fd
SHA-1: 2cf023b0ac771c1f42fbc50c0456841af097056d
Created: 2004/11/16 12:43:24
Detections: 1
Determination: Ignore detections (false positive)
- Rising Antivirus as PE:Malware.XPACK/RDM!5.1

---------------------------------------------------------------------------------

File path: c:\program files (x86)\common files\adobe\updater\adobeupdater.exe
Publisher: Adobe Systems Incorporated
MD5: af82432702ab794ff778276f20c1e920
SHA-1: 64594c82f30cb4eeaacfb62025b2064cf2567d6f
Created: 2005/03/16 19:16:40
Detections: 1
Determination: Ignore detections (false positive)
- Boost by Reason as Optional.AdobeSystemsorporated.M

---------------------------------------------------------------------------------

File path: c:\program files (x86)\cyberlink\powerdvd10\audiofilter\dolbyhph.dll
Publisher: Lake Technology Limited, http://www.lake.com.au
MD5: 442b5be8aa79b0496c5d0234b78e20ce
SHA-1: 9956235bf6fe3a3220c73a84c8f57c951226655a
Created: 2012/08/27 18:25:50
Detections: 2
Determination: Inconclusive
- Bkav FE as HW32.CDB (Undefined)
- Avira AntiVirus as W32/Sality.AT (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\kobo\uninstall.exe
Publisher:
MD5: 064e19ea95b053a18f144867ce53530e
SHA-1: fbeb3acddc405d68d3c3c3e99ee12ce0264d6e42
Created: 2016/08/16 4:11:03
Detections: 1
Determination: Adware
- Reason Heuristics as Adware.Linkury (Adware)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\nsis uninstall information\{de85b8f3-d088-4d6e-a970-ee0bc7883a66}\setup.exe
Publisher:
MD5: 9d687dc970d92d21ec52ceddf82174f6
SHA-1: 29b6a51484a78aa0bc163ca1ccdbb68d5db58481
Created: 2015/08/23 19:10:50
Detections: 1
Determination: Inconclusive
- Avira AntiVirus as W32/Sality.Y (Undefined)

---------------------------------------------------------------------------------

File path: c:\program files (x86)\rimarts\b2\b2.exe
Publisher: RimArts Inc.
Signer: RimArts Inc.
MD5: aaf01c9d484e225c9e5ceaa92cefbe90
SHA-1: 540b60b8fa7e10af76751d10d666f25cbeb733ab
Created: 2015/09/20 17:11:12
Detections: 1
Determination: Ignore detections (false positive)
- ByteHero BDV as Trojan.Exception.gen.101 (Undefined)

  • puri
  • 2016/12/27 (Tue) 06:20:38
可能なら表示画面をキャプチャできますか
レスが遅くなってすみません。また湧いてきた悪代官です。
さっきまで風呂入ってました(←うちの風呂には由美○おるはいません

まず、Assertion failed!の表示が出ている状態をキャプチャできますか?
キャプチャできるならその画像を保存してから、次回レス時に添付で見せてください。
何が原因でアサーションエラーを吐いているか、どういうウインドウや画面で出ているかを調べたほうがよさそうです。

HPのログも見せてもらいましたが、こちらでは不審なものは見えないです。
とりあえず件のAssertion failed!の画面を見てから次の対処を考えましょう
  • 悪代官
  • 2016/12/28 (Wed) 20:24:23
遅くなりました
遅くなって申し訳ありません。
キャプチャ撮りましたので、ご確認をお願い致します。
  • puri
  • 2016/12/31 (Sat) 08:07:05
サーバーのMongooseエラーみたいですが
またレスが遅くなってすみません。
こうやって敵を焦らしてから隙を突いて倒すのが悪代官の策略です(←いったい何と戦ってるんだ

画像を見せてもらいました。
それで少し状況が見えてきました。

HTTPサーバのMongooseをお使いですか?
表示のエラーはそれが絡んでいるようです。

確認しますが、上記のMongooseはご自身で必要として入れたものですか?
それなら設定を見直すか、または新たなバージョンに入れなおすことで改善するかとおもいますが、もし覚えもないのに入っていたならそのことを教えてください
  • 悪代官
  • 2016/12/31 (Sat) 22:03:32
遅くなって申し訳ありません
すごく遅くなって申し訳ありません!
あけましておめでとうございます。今年も何卒宜しくお願い致します。

Mongooseですが、全く覚えがないです。
どういうものかすら知りません…

年末から画面そのままの状態で待機しております。
ご返信お待ちしております。
  • puri
  • 2017/01/06 (Fri) 05:32:41
新年早々遅くなりました
遅くなりましたがあけましておめでとうございます。
新年最初のレスです。

>Mongooseですが、全く覚えがないです。

なるほど、サーバーのMongooseは入れた覚えもないとのことですね。

とすると、エラーで表示されているMongooseは同名を騙った別のプログラムの疑いも出てきました。
ですがエラーの内容をweb検索にかけてみたところ、同内容表示のエラー事例もいくつか出ているようです。
それらのエラー事例でもみな直接の原因特定にはつながらないままなので糸口もつかめませんね。

>年末から画面そのままの状態で待機しております。

長いこと待たせてしまって本当にごめんなさい。
では次にその画面が出たら「無視」選択してください。

それと次の確認作業もお願いします。

Win7のファイル検索で調べましょう。
スタートメニューの「プログラムとファイルの検索」欄に下記をコピペで貼り付けて検索してください。

Mongoose

これで検索後に表示されたら「検索結果の続きを表示」してください。

エクスプローラーでその結果が表示されたら、それで表示されたファイル名を教えてください
複数見つかったらそのうちの数個だけでもいいですが、ファイル名の拡張子(末尾)が「.dic」になっているようなら自分の予想が当たるかもしれません
この確認の結果が出たらそれをレスください
  • 悪代官
  • 2017/01/06 (Fri) 20:23:01
ありがとうございます
ご返信ありがとうございます!

画面ですが、「無視」を選択しても何度も同じ画面が表示されてしまいます…

また、プログラムとファイルの検索でMongooseとコピペして検索しましたが、
検索条件に一致する項目はありませんと表示されました…

  • puri
  • 2017/01/07 (Sat) 06:42:26
Visual C++のエラーぽいですが
またもレスが遅くなってすみません。

>画面ですが、「無視」を選択しても何度も同じ画面が表示されてしまいます…

>また、プログラムとファイルの検索でMongooseとコピペして検索しましたが、
>検索条件に一致する項目はありませんと表示されました…

はい、わかりました。
エラー画面が出続けるのはともかく、ファイル検索でひっかからないならMongooseは入っていないということでしょう。

ここまでの経緯を見ると、どうもVisual C++のバグの疑いが考えられます。
では無難な範囲で力技を試しますか。

コントロールパネルの「プログラムと機能」欄で、下記を一度アンインストールしてみてください。
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2015/09/21 300 KB 8.0.61001

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2014/10/06 608 KB 9.0.30729

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2014/10/06 586 KB 9.0.30729

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2015/09/21 598 KB 9.0.30729.6161

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/06 13.8 MB 10.0.40219

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/06 11.1 MB 10.0.40219

Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 2016/08/16 17.3 MB 11.0.61030.0

全部アンインストールしたら一度PC再起動後、ディスククリーンアップのあと、そこでしばらく動作を様子見してください。

ここで異常が消えていればそのことを次回レス時に教えてください。

様子見のあと、今度は削除した上記を再インストールです。
WindowsUpdateで入れなおすのもいいですが、MSのダウンロードセンターで各アプリの再頒布可能パッケージをダウンロード、インストールしてもいいでしょう。
たとえば2012なら下記ページですね。
https://www.microsoft.com/ja-jp/download/details.aspx?id=30679

削除と入れなおしできたらそこでまた動作確認後、状態報告をレスください
  • 悪代官
  • 2017/01/07 (Sat) 20:43:53

返信フォーム※初心者、通りすがり等、重複しやすい名前の利用はご遠慮ください。




プレビュー (投稿前に内容を確認)