AVASTにて、「感染をブロックしました」と表示される
yahoo知恵袋に同様の症状がありましたので、相談させていただきます。

hijackthis.log
-------------------------------------
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 0:01:24, on 2015/03/22
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)

FIREFOX: 36.0.3 (x86 ja)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\EPSON\MyEPSON Connect\mep.exe
C:\VIA_XHCI\usb3Monitor.exe
C:\Program Files (x86)\AgnType\AgnType.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
D:\W32_TOOL\TinyMon.exe
C:\Program Files (x86)\husen2K\Husen2K.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaConverter.exe
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaRenderer.exe
C:\Program Files (x86)\Justsystems\Shuriken\JsvMail.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_134.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_134.exe
D:\W32_TOOL\Whf.exe
C:\Users\ME\Desktop\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll
O2 - BHO: PhishWall - {8CA7E745-EF75-4E7B-BB86-8065C0CE29CA} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft アカウント サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll
O3 - Toolbar: PhishWall - {BB62FFF4-41CB-4AFC-BB8C-2A4D4B42BBDC} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [JustOnlineUpdate] "C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe" /startup
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [EMET 4.1 Update 1 Agent] "C:\Program Files (x86)\EMET 4.1\EMET_agent.exe"
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Google Japanese Input Prelauncher] "C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe" --mode=prelaunch_processes
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [IME14 JPN Uninstall] C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /JPN /Log
O4 - HKLM\..\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: AgainTyper.lnk = C:\Program Files (x86)\AgnType\AgnType.exe
O4 - Startup: HitoKoe10.lnk = D:\W32_TOOL\GO_START\HitoKoe10.exe
O4 - Startup: IPMSG for Win32.lnk = C:\Program Files\IPMsg\ipmsg.exe
O4 - Startup: KYOU.lnk = D:\W32_TOOL\KYOU.EXE
O4 - Startup: Shuriken着信監視.lnk = C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
O4 - Startup: TinyMon.lnk = D:\W32_TOOL\TinyMon.exe
O4 - Startup: 付箋紙21.lnk = C:\Program Files (x86)\husen2K\Husen2K.exe
O4 - Global Startup: SignalNowExpress.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: SunのJavaコンソール - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://gdmp.canon.jp
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {AF4D6906-EB10-48C1-A0CF-9328196158AE} (PrintControl) - http://gdmp.canon.jp/gundam/activex/PrintControl.ocx
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com/bin/srldetect_intel_4.5.22.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D89B3FF-5B44-4C7F-8D7F-9EC2661F9409}: NameServer = 192.168.1.1
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: CyberLink Product - 2013/07/21 18:58:07 (CLKMSVC10_38F51D56) - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe,-100 (GoogleIMEJaCacheService) - Google Inc. - C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mei006h Service (Mei006h) - Unknown owner - C:\Windows\SysWOW64\mei006h.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyEPSON Connect Service - SEIKO EPSON CORPORATION - C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SDPAUMS server service (SDPASVC) - Unknown owner - C:\Windows\SysWOW64\sdpasvc.exe (file missing)
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: SecureBrain PhishWall Update - SecureBrain Corporation - C:\Program Files (x86)\SecureBrain\PhishWall\sbpwupdx.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service2 - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TEPRA Driver Option UI Manager (TepOuService) - Unknown owner - C:\Windows\system32\TPOUSVR.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Update Jotzey - Unknown owner - C:\Program Files (x86)\Jotzey\updateJotzey.exe (file missing)
O23 - Service: Update PodoWeb - Unknown owner - C:\Program Files (x86)\PodoWeb\updatePodoWeb.exe (file missing)
O23 - Service: uvnc_service - UltraVNC - C:\Program Files\uvnc bvba\UltraVNC\WinVNC.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 17558 bytes

install.txt
---------------
Adobe AIR Adobe Systems Incorporated 2015/03/14 17.0.0.124
Adobe Flash Player 17 ActiveX Adobe Systems Incorporated 2015/03/14 6.00 MB 17.0.0.134
Adobe Flash Player 17 NPAPI Adobe Systems Incorporated 2015/03/14 6.00 MB 17.0.0.134
Adobe Reader XI (11.0.10) - Japanese Adobe Systems Incorporated 2014/12/12 203 MB 11.0.10
Adobe Shockwave Player 12.1 Adobe Systems, Inc. 2014/12/13 12.1.5.155
AgainTyper 2013/05/31
AGMDecoder T.Ishii (t-ishii@js2.so-net.ne.jp) 2014/05/05 344 KB 1.1.1
AGMDecoder64 T.Ishii (t-ishii@js2.so-net.ne.jp) 2014/05/05 224 KB 1.1.1
AMD Catalyst Install Manager Advanced Micro Devices, Inc. 2014/12/09 26.7 MB 8.0.916.0
Apple Application Support Apple Inc. 2014/02/26 64.0 MB 2.3.6
Apple Software Update Apple Inc. 2013/05/31 2.38 MB 2.1.3.127
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver Atheros Communications Inc. 2013/05/31 2.1.0.7
Avast Free Antivirus AVAST Software 2015/03/17 10.2.2214
AviSynth 2.5 2013/10/26
BD_3D Advisor CyberLink Corp. 2013/07/21 12.6 MB 2.0.5913
CCleaner Piriform 2015/03/21 5.03
CDBurnerXP CDBurnerXP 2014/09/10 13.2 MB 4.5.4.5000
CyberLink Media Suite 10 CyberLink Corp. 2013/07/21 277 MB 10.0
Defraggler Piriform 2013/12/22 2.16
DivXセットアップ DivX, LLC 2014/09/21 2.6.1.8
DVD Decrypter (Remove Only) 2013/05/31
DVD Flick 1.3.0.7 Dennis Meuwissen 2013/10/06 1.3.0.7
DVD Shrink 3.2 DVD Shrink 2013/05/31
DVDFab 9.1.5.0 (30/05/2014) Fengtao Software Inc. 2014/06/07 109 MB
EMET 4.1 Update 1 Microsoft Corporation 2014/05/24 18.1 MB 4.1.1
EPSON EP-806A Series プリンター アンインストール SEIKO EPSON Corporation 2014/09/20
EPSON Scan Seiko Epson Corporation 2014/09/20
EpsonNet Print SEIKO EPSON CORPORATION 2014/09/20 2.6.0
FormatFactory 3.6.0.0 Format Factory 2015/02/27 3.6.0.0
GOM Player Gretech Corporation 2015/02/07 2.2.67.5221
Google 日本語入力 Google Inc. 2014/10/28 84.1 MB 1.13.1641.0
Intel(R) Management Engine Components Intel Corporation 2013/05/31 8.1.0.1252
Intel(R) Processor Graphics Intel Corporation 2014/06/11 10.18.10.3621
Intel(R) Rapid Storage Technology Intel Corporation 2014/03/08 12.9.0.1001
Intel(R) SDK for OpenCL - CPU Only Runtime Package Intel Corporation 2013/05/31 3.0.0.63463
Intel(R) Update Manager Intel Corporation 2014/04/18 22.6 MB 2.3.1338
Intel(R) USB 3.0 eXtensible Host Controller Driver Intel Corporation 2013/05/31 1.0.5.235
Intel® SSD Toolbox Intel Corporation 2014/11/12 3.2.3.400
IObit Uninstaller IObit 2015/02/19 4.2.6.2
IP Messenger for Win 2013/05/31
Java 7 Update 76 Oracle 2015/02/13 120 MB 7.0.760
Java 7 Update 9 Oracle 2013/05/31 130 MB 7.0.90
Java 8 Update 25 Oracle Corporation 2014/10/15 73.3 MB 8.0.250
Java 8 Update 31 Oracle Corporation 2015/01/31 74.0 MB 8.0.310
Java 8 Update 40 Oracle Corporation 2015/03/14 76.9 MB 8.0.400
JUSTオンラインアップデート 株式会社ジャストシステム 2014/06/11 1.0.1.0
Lagarith Lossless Codec (1.3.27) 2014/09/21 1.02 MB
Media Go Sony 2014/10/28 148 MB 2.8.303
Media Go Network Downloader Sony 2014/10/28 1.33 MB 1.5.19.0
Media Go Video Playback Engine 2.12.110.06300 Sony 2014/10/28 21.0 MB 2.12.110.06300
Microsoft .NET Framework 4.5.2 Microsoft Corporation 2015/01/15 38.8 MB 4.5.51209
Microsoft .NET Framework 4.5.2 (日本語) Microsoft Corporation 2015/02/14 2.93 MB 4.5.51209
Microsoft Office 365 Small Business Premium - ja-jp Microsoft Corporation 2015/03/14 15.0.4701.1002
Microsoft Silverlight Microsoft Corporation 2014/07/24 298 MB 5.1.30514.0
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2014/04/30 1.69 MB 3.1.0000
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2013/05/31 300 KB 8.0.59193
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 Microsoft Corporation 2014/09/14 894 KB 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2014/03/08 788 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2014/07/17 232 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 2014/03/09 786 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Corporation 2015/02/16 1.41 MB 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2014/02/01 238 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2014/08/10 230 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2014/07/17 222 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2013/05/31 598 KB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2015/02/13 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2015/02/13 11.1 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Corporation 2015/02/12 20.5 MB 11.0.61030.0
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 2015/02/12 17.3 MB 11.0.61030.0
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 Microsoft Corporation 2014/10/28 17.1 MB 12.0.21005.1
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Microsoft Corporation 2015/02/13 10.0.50903
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - 日本語 Microsoft Corporation 2015/02/13 10.0.50903
Mozilla Firefox 36.0.3 (x86 ja) Mozilla 2015/03/21 85.4 MB 36.0.3
Mozilla Maintenance Service Mozilla 2014/04/30 341 KB 29.0
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2013/06/01 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2013/06/01 1.33 MB 4.20.9876.0
MSXML 4.0 SP2 パーサーと SDK Microsoft Corporation 2013/05/31 1.22 MB 4.20.9818.0
MyEPSON Portal SEIKO EPSON Corporation 2014/09/20
NextFTP 2013/05/31
OpenSource Flash Video Splitter 1.0.0.5 2014/09/21 1.0.0.5
PDF reDirect (remove only) EXP Systems LLC 2013/07/09 v2.5.2
PhishWall SecureBrain Corporation 2014/04/19 3.5.8
QUAD-CAPTURE Driver Roland Corporation 2013/05/31
QuickTime 7 Apple Inc. 2014/10/29 70.2 MB 7.76.80.95
Shuriken 2012 株式会社ジャストシステム 2013/05/31 84.5 MB 11.0.4
SignalNow Express ストラテジー株式会社 2015/03/08 2.0.0.0
Software Updater SEIKO EPSON CORPORATION 2014/11/16 9.70 MB 4.3.3
Sony Media Library Earth 9.2.00 Sony Corporation 2015/02/10 49.5 MB 9.2.00.01271
Sony Mobile Update Engine Sony Mobile Communications AB 2014/02/15 2.14.2.201402071544
Sony PC Companion 2.10.245 Sony 2015/02/22 19.6 MB 2.10.245
Spybot - Search & Destroy Safer-Networking Ltd. 2014/11/16 154 MB 2.4.40
System Requirements Lab for Intel Husdawg, LLC 2014/08/14 1.12 MB 4.5.24.0
UltraVnc uvnc bvba 2013/05/31 12.3 MB 1.1.9.0
Vb5rs3 2013/05/31
VIA プラットフォーム・デバイス・マネージャ VIA Technologies, Inc. 2013/05/31 2.62 MB 1.38
VirtualCloneDrive Elaborate Bytes 2013/05/31
VMware Player VMware, Inc 2015/02/07 390 MB 6.0.5
Winamp Nullsoft, Inc 2013/11/27 5.666
Windows Live Essentials Microsoft Corporation 2014/04/30 16.4.3528.0331
Wise Registry Cleaner 8.31 WiseCleaner.com, Inc. 2015/01/05 7.12 MB 8.31
x-アプリ 6.0.01 Sony Corporation 2015/02/10 88.6 MB 10.0.01
x64 Components v4.7.6 Shark007 2014/09/21 91.1 MB 4.7.6
Xvid Video Codec Xvid Team 2014/09/21 1.3.2
「テプラ」PRO PCラベルソフト SPC9C KING JIM 2013/11/17 3.70.000
「テプラ」PRO SPC9C プリンタドライバ 2013/11/17
らくちんCDラベルメーカー15 MediaNavi 2013/05/31 15.0.0.0
チャクモエ for PC メイドボイス 2013/05/31
ナビマスター S V1.0 クラリオン株式会社 2014/06/21 15.2 MB 1.0.0
ミュージックCDデザイナー3 MEGASOFT Inc. 2013/06/09
ラベル屋さん9 A-one Co.,Ltd. 2014/10/11 9.0.700
付箋紙21 2013/05/31
秀丸エディタ (8.21) 有限会社サイトー企画 2013/05/31 8.21
秀丸パブリッシャー 2013/05/31
筆まめ Ver.24 販売元:株式会社筆まめ 開発元:株式会社モーリン 2014/12/20 1.12 GB 24.09.2410.0
電波時計用JJYシミュレータ スタアストーンソフト 2014/03/15 656 KB 1.0.5.0

  • pxu10652
  • 2015/03/22 (Sun) 00:18:05
Spybotは以後は非使用検討を
こんばんは。
いかにも悪党なIDの悪代官です。
でも正体は甘党です。その証拠に脳内がスイートです(爆

説明とログを見せていただきました。
Spybot - Search & Destroyを昨年から使っているようですが、これは今回のスレが解決したらできれば削除と非使用を検討ください。
現在これは検出保護力で信頼できるレベルではなくなっているので、どうしても使うなら設定と機能を十分把握して、完全に自己責任で判断してください。

では本題の解析に入りましょう。

まず最初にお伝えしておきます。
見てのとおり現在相談者さん多数のため、相談受けてから皆さんに順番にレスできるまで、毎回1日かそれ以上かかる可能性もあるので、すみませんがご了承ください。

では以下の説明をよく見てから、順番に作業をお願いします。
既に準備した物もあるはずですが、一応説明を再度見ておいてください。

隠しファイルと拡張子を表示設定にしてください(やり方↓)
http://pasofaq.jp/windows/mycomputer/hiddenfile.htm
http://support.microsoft.com/kb/978449/ja

下記のツールをダウンロードして、基本の使い方を把握しておいてください。
ただし、配布サイトで他のアプリをダウンロードしろと勧めてくるような広告も出てきたらそれらは絶対にクリックしないでください。
「ATF-Cleaner」(通称:ATF)
説明↓
http://freesoft.tvbok.com/freesoft/pc_system/atf-cleaner.html
ダウンロード↓
http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25
中央の赤い文字がダウンロードリンクです。
片付けるときはファイルを直接削除してください。

「GeekUninstaller」(通称:GU)
説明ページ↓
http://www.gigafree.net/system/install/geekuninstaller.html
ダウンロード↓
http://www.geekuninstaller.com/download
「download free」をクリック、保存後、解凍してください。
片付ける時はフォルダごと手動で削除してください。

「CCleaner」(通称:CC)
説明↓
http://www.gigafree.net/system/clean/ccleaner.html
http://note.chiebukuro.yahoo.co.jp/detail/n178757
ダウンロード↓
http://www.piriform.com/ccleaner/download/standard
最新バージョンをダウンロードしてください。なお、インストール時におまけのアプリも勧めてくることがありますが、それらはチェック外してインストールは避けてください。
片付けるときはアンインストールしてください。

ここで重要な注意です。
CCは本来は高い性能を持つメンテナンスソフトですが、間違った使い方すると
【Windowsにダメージを与えてしまうおそれもある】
ので、ここでは解析ツールとしてのみ使います。
説明をしっかり読んで、自分が指示した以外の操作はしないように。

「AdwCleaner」(通称:AC)
http://www.bleepingcomputer.com/download/adwcleaner/dl/125/
ファイル直リンです。アクセスしてファイルをデスクトップにでも保存しておいてください。
片付けるときは起動後に「uninstall」ボタンを押せば自動で削除されます。
使い方は下記サイト様に詳しい説明があるのでサンショウウオ↓
http://www.japan-secure.com/entry/adwcleaner.html

そして下記ページは作業開始前に必ず熟読して、必要な場合が出たらそれに沿って対処してください。この対処が必要な事例が増えています。
http://note.chiebukuro.yahoo.co.jp/detail/n335704

準備できたら作業開始です。
なお、このあとの作業で探しても見つからないものはスルーして進めていいですが、指示した対象外の物は絶対にいじらないようによく見て作業してください。

少なくとも下記のアプリは旧バージョンです。
>Adobe Shockwave Player 12.1 Adobe Systems, Inc. 2014/12/13 12.1.5.155
>EMET 4.1 Update 1 Microsoft Corporation 2014/05/24 18.1 MB 4.1.1

各種アプリの更新を怠っただけでも、脆弱性を悪用されて深刻な感染はあっさり起きます。
使うなら最新版に更新してください。使わないアプリならアンインストールが安全です。
他にも旧バージョンないか調べて、あれば同様に更新するか、アンインストールしてください。

ここでWindowsの標準機能である「システムの復元」での復元ポイントをひとつ、手動で作成しておいてください。
これはこの後の作業で、間違って対象外のものをいじってしまうとそれだけでWindowsに深刻な不具合を起こすこともあるので、万一の際に復元可能にしておくためです。
http://windows.microsoft.com/ja-jp/windows7/create-a-restore-point

次にここで一度ACを起動してください。
起動するとまず定義の更新が行われるはずなので、更新だけしてから、それができたらACは一旦終了してください。
ここではスキャンもしなくていいです。

今度はPCをセーフモードで起動してください(やり方↓)
http://www.pc-master.jp/sousa/s-safemode.html

セーフモードでGEを使って、下記をアンインストールしてください。
>DVD Decrypter (Remove Only) 2013/05/31
>DVD Flick 1.3.0.7 Dennis Meuwissen 2013/10/06 1.3.0.7
>DVD Shrink 3.2 DVD Shrink 2013/05/31
>DVDFab 9.1.5.0 (30/05/2014) Fengtao Software Inc. 2014/06/07 109 MB
>GOM Player Gretech Corporation 2015/02/07 2.2.67.5221

セーフモードのままでATFを起動して、「Recycle bin」(ゴミ箱)以外の箇所全部にチェックしてから、下部の「Empty selected」を押してください。
これでPC内の一時ファイル等のゴミが掃除できます。
ゴミ箱を空にしないのは、もし間違って安全なファイルを削除しても戻せるようにとの対処です。

HJTを起動させ、スキャンを行ってください。
スキャン結果が表示されましたら、以下の項目にチェックを入れてください。
ただし、特にHJTでの作業は一歩間違えれば簡単にPCが起動しなくなるため、こちらが指示した以外のものは絶対にチェックを入れないでください。
>O23 - Service: Update Jotzey - Unknown owner - C:\Program Files (x86)\Jotzey\updateJotzey.exe (file missing)
>O23 - Service: Update PodoWeb - Unknown owner - C:\Program Files (x86)\PodoWeb\updatePodoWeb.exe (file missing)

必要な項目すべてにチェックが入りましたら、Fix checkedをクリックしてください。
探しても見つからないものはスルーして進めていいです。

今度は先にも起動したACを再度起動してください。
起動したら今度は「スキャン」したあと、そのスキャン終了後に検出されたものがあったら「除去」を押してください。
表示された画面で「はい」を選択すると処置開始されます。

処置完了したらそこでPCを通常モードで再起動してください。

再起動後にACのあらたなログが出るので、それをデスクトップにでも保存しておいてください。
ですが、もし作業後にログが出ないorわからない場合はマイコンピュータのCドライブを開くとその直下に以下のような名前のファイルが作成されているので、それがACのログです。
>AdwCleaner[英数字].txt
同じような名前のログが複数ある時は、作成日時が作業処置時のファイルが対象のログです。

今度はCCを起動してください。
起動したら、「ツール」→」「スタートアップ」→「Windows」タブを開いてください。
そこで右下の「テキストとして保存」を押すと、表示の内容がログとして保存できるので、ログをデスクトップにでも保存しておいてください。

続いて「InternetExplorer」タブ以下の各タブも順番に開いて、そのログもとっておいてください。
ただし、「コンテキストメニュー」のログは取らなくていいです。

CCの各ログをとったらCCは終了してください。

このあとブラウザを起動して、数時間ほどPC状態を様子見したあと、あらたにHJTとCCでのインストール情報ログを取り直してください。

取り直した両ログと、ACとCCの各ログを返信に貼って、状態報告とともにレスください。
それらを見てから続きの作業を指示します。
  • 悪代官
  • 2015/03/22 (Sun) 18:11:34
駆除できたように見えて、再発する
 一旦はHJTとACで駆除できたように見えたのですが、PCを再起動を何度か繰り返しているうちに
元の状態に戻ってしまいました。


ACでの駆除時のログ

# AdwCleaner v4.112 - ログファイルの作成日 22/03/2015 作成時間 22:39:44
# 更新日 09/03/2015 作成元 Xplode
# データベース : 2015-03-05.1 [ローカル]
# オペレーティングシステム : Windows 7 Ultimate Service Pack 1 (x64)
# ユーザー名 : ME - PC-ME7
# 実行場所 : C:\Users\ME\Desktop\AdwCleaner.exe
# オプション : 削除

***** [ サービス ] *****

[#] サービス 削除済み項目 : Update PodoWeb
[#] サービス 削除済み項目 : Update Jotzey
[#] サービス 削除済み項目 : {00c97d86-accb-4288-9972-6d929c1fe93a}Gw64

***** [ ファイル / フォルダ ] *****

フォルダ 削除済み項目 : C:\Users\ME\Favorites\Search
フォルダ 削除済み項目 : C:\ProgramData\apn
フォルダ 削除済み項目 : C:\ProgramData\Ask
フォルダ 削除済み項目 : C:\ProgramData\baidu
フォルダ 削除済み項目 : C:\Program Files (x86)\PodoWeb
フォルダ 削除済み項目 : C:\Users\ME\AppData\Local\Bundled software uninstaller
フォルダ 削除済み項目 : C:\Users\ME\AppData\LocalLow\Delta
フォルダ 削除済み項目 : C:\Users\ME\AppData\Roaming\baidu
ファイル 削除済み項目 : C:\Windows\System32\drivers\{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64.sys
ファイル 削除済み項目 : C:\Users\ME\AppData\Roaming\Mozilla\Firefox\Profiles\fmug7izv.default\user.js

***** [ スケジュールタスク ] *****


***** [ ショートカット ] *****


***** [ レジストリ ] *****

キー 削除済み項目 : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
キー 削除済み項目 : HKLM\SOFTWARE\Classes\AppID\WMHelper.DLL
キー 削除済み項目 : HKLM\SOFTWARE\Classes\Prod.cap
キー 削除済み項目 : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
キー 削除済み項目 : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
キー 削除済み項目 : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
キー 削除済み項目 : HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
キー 削除済み項目 : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
キー 削除済み項目 : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
キー 削除済み項目 : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
キー 削除済み項目 : HKLM\SOFTWARE\Classes\TypeLib\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}
キー 削除済み項目 : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
キー 削除済み項目 : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
キー 削除済み項目 : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
キー 削除済み項目 : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
キー 削除済み項目 : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
キー 削除済み項目 : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
値 削除済み項目 : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D7E97865-918F-41E4-9CD0-25AB1C574CE8}]
キー 削除済み項目 : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
キー 削除済み項目 : [x64] HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
キー 削除済み項目 : [x64] HKLM\SOFTWARE\Classes\Interface\{28C3737A-32D1-492D-B76B-8D75EBBFB887}
キー 削除済み項目 : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
キー 削除済み項目 : [x64] HKLM\SOFTWARE\Classes\Interface\{CE057E0D-2D7E-4DFF-A890-07BA69B8C762}
キー 削除済み項目 : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
キー 削除済み項目 : [x64] HKLM\SOFTWARE\Classes\Interface\{682E055E-0863-4334-918C-29CD4F3F4D96}
キー 削除済み項目 : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
キー 削除済み項目 : HKCU\Software\BI
キー 削除済み項目 : HKCU\Software\DataMngr
[#] キー 削除済み項目 : HKCU\Software\DataMngr_Toolbar
キー 削除済み項目 : HKCU\Software\ilivid
キー 削除済み項目 : HKCU\Software\Softonic
キー 削除済み項目 : HKCU\Software\Baidu
キー 削除済み項目 : HKCU\Software\Squeaky
キー 削除済み項目 : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
キー 削除済み項目 : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
キー 削除済み項目 : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
キー 削除済み項目 : HKLM\SOFTWARE\DataMngr
データ 削除済み項目 : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>
データ 削除済み項目 : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - localhost:8080

***** [ Webブラウザ ] *****

-\\ Internet Explorer v11.0.9600.17689


-\\ Mozilla Firefox v36.0.4 (x86 ja)

[fmug7izv.default\prefs.js] - ライン 削除済み項目 : user_pref("extensions.toolbar_ORJ-SPE@apn.ask.com.install-event-fired", true);

*************************

AdwCleaner[R0].txt - [5581 bytes] - [22/03/2015 22:38:36]
AdwCleaner[S0].txt - [5005 bytes] - [22/03/2015 22:39:44]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5064 bytes] ##########


最新のACログ

# AdwCleaner v4.112 - ログファイルの作成日 22/03/2015 作成時間 22:54:24
# 更新日 09/03/2015 作成元 Xplode
# データベース : 2015-03-05.1 [ローカル]
# オペレーティングシステム : Windows 7 Ultimate Service Pack 1 (x64)
# ユーザー名 : ME - PC-ME7
# 実行場所 : C:\Users\ME\Desktop\AdwCleaner.exe
# オプション : 削除

***** [ サービス ] *****


***** [ ファイル / フォルダ ] *****


***** [ スケジュールタスク ] *****


***** [ ショートカット ] *****


***** [ レジストリ ] *****


***** [ Webブラウザ ] *****

-\\ Internet Explorer v11.0.9600.17689


-\\ Mozilla Firefox v36.0.4 (x86 ja)


*************************

AdwCleaner[R0].txt - [5581 bytes] - [22/03/2015 22:38:36]
AdwCleaner[R1].txt - [1058 bytes] - [22/03/2015 22:42:25]
AdwCleaner[R2].txt - [960 bytes] - [22/03/2015 22:44:43]
AdwCleaner[R3].txt - [1018 bytes] - [22/03/2015 22:52:47]
AdwCleaner[R4].txt - [1077 bytes] - [22/03/2015 22:53:42]
AdwCleaner[S0].txt - [5176 bytes] - [22/03/2015 22:39:44]
AdwCleaner[S1].txt - [998 bytes] - [22/03/2015 22:54:24]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1056 bytes] ##########


CCのstartup

有効 HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run Sidebar Microsoft Corporation C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
有効 HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
有効 HKLM:Run AvastUI.exe Avast Software s.r.o. "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
有効 HKLM:Run BDRegion cyberlink C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
有効 HKLM:Run DivXMediaServer DivX, LLC C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
有効 HKLM:Run DivXUpdate DivX, LLC "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
有効 HKLM:Run Google Japanese Input Prelauncher Google Inc. "C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe" --mode=prelaunch_processes
有効 HKLM:Run IAStorIcon Intel Corporation "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
有効 HKLM:Run IME14 JPN Uninstall Microsoft Corporation C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /JPN /Log
有効 HKLM:Run JustOnlineUpdate 株式会社ジャストシステム "C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe" /startup
有効 HKLM:Run QuickTime Task Apple Inc. "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
有効 HKLM:Run RemoteControl10 CyberLink Corp. "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
有効 HKLM:Run StartCCC Advanced Micro Devices, Inc. "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
有効 HKLM:Run SunJavaUpdateSched Oracle Corporation "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
有効 HKLM:Run TepOuService KING JIM CO.,LTD. C:\Windows\system32\TPOUSVR.EXE -uimanage
有効 HKLM:Run USB3MON Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
有効 HKLM:Run VIAxHCUtl VIA Technologies, Inc. C:\VIA_XHCI\usb3Monitor.exe
有効 HKLM:Run VirtualCloneDrive Elaborate Bytes AG "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
有効 Startup Common SignalNowExpress.lnk ストラテジー株式会社 C:\Program Files (x86)\ストラテジー株式会社\SignalNow Express\SignalNowExpress.exe
有効 Startup User AgainTyper.lnk C:\Program Files (x86)\AgnType\AgnType.exe
有効 Startup User HitoKoe10.lnk D:\W32_TOOL\GO_START\HitoKoe10.exe
有効 Startup User IPMSG for Win32.lnk H.Shirouzu C:\Program Files\IPMsg\ipmsg.exe
有効 Startup User KYOU.lnk D:\W32_TOOL\KYOU.EXE
有効 Startup User Shuriken着信監視.lnk 株式会社ジャストシステム C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
有効 Startup User TinyMon.lnk D:\W32_TOOL\TinyMon.exe
有効 Startup User 付箋紙21.lnk ROTO C:\Program Files (x86)\husen2K\Husen2K.exe



CCのstartup(IE)
無効 Extension Lync Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
無効 Extension Lync Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
有効 Helper avast! Online Security Avast Software s.r.o. C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
有効 Helper avast! Online Security Avast Software s.r.o. C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
有効 Helper ExplorerWnd Helper IObit C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll
無効 Helper Lync Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
無効 Helper Lync Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
有効 Helper Microsoft SkyDrive Pro Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
有効 Helper Microsoft SkyDrive Pro Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
無効 Helper Microsoft アカウント サインイン ヘルパー Microsoft Corp. C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
無効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
無効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
有効 Helper PhishWall SecureBrain Corporation C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
無効 Helper Windows Live ID Sign-in Helper Microsoft Corp. C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 Toolbar PhishWall SecureBrain Corporation C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll



CCのstartup(Firefox)
有効 Extension Avast Online Security 10.2.0.187 AVAST Software default Firefox 36.0.4 C:\Program Files\AVAST Software\Avast\WebRep\FF
有効 Plugin Adobe Acrobat 11.0.10.32 Adobe Systems Inc. default Firefox 36.0.4 C:\Program Files (x86)\Adobe\Reader 11.0\Reader\browser\nppdf32.dll
有効 Plugin DivX Plus Web Player 3.2.3.1164 DivX, LLC default Firefox 36.0.4 C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll
有効 Plugin DivX VOD Helper Plug-in 1.1.0.14 DivX, LLC. default Firefox 36.0.4 C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
有効 Plugin Google Update 1.3.26.9 Google Inc. default Firefox 36.0.4 C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
有効 Plugin Intel Identity Protection Technology 2.1.42.0 Intel Corporation default Firefox 36.0.4 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
有効 Plugin Intel Identity Protection Technology 2.1.42.0 Intel Corporation default Firefox 36.0.4 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
有効 Plugin Java Deployment Toolkit 8.0.400.25 11.40.2.25 Oracle Corporation default Firefox 36.0.4 C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npdeployJava1.dll
有効 Plugin Java(TM) Platform SE 8 U40 11.40.2.25 Oracle Corporation default Firefox 36.0.4 C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll
有効 Plugin Microsoft Office 2013 15.0.4514.1000 Microsoft Corporation default Firefox 36.0.4 C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL
有効 Plugin Microsoft Office 2013 15.0.4545.1000 Microsoft Corporation default Firefox 36.0.4 C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
有効 Plugin Photo Gallery 16.4.3528.331 Microsoft Corporation default Firefox 36.0.4 C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
有効 Plugin QuickTime Plug-in 7.7.6 7.7.6.0 Apple Inc. default Firefox 36.0.4 C:\Program Files (x86)\QuickTime\Plugins\npqtplugin5.dll
有効 Plugin Shockwave Flash 17.0.0.134 Adobe Systems Incorporated default Firefox 36.0.4 C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll
有効 Plugin Shockwave for Director 12.1.7.157 Adobe Systems, Inc. default Firefox 36.0.4 C:\Windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll
有効 Plugin Silverlight Plug-In 5.1.30514.0 Microsoft Corporation default Firefox 36.0.4 C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
  • pxu10652
  • 2015/03/22 (Sun) 23:19:49
続きのログと、MBAMスキャンを
作業と報告、ご苦労様です。

>一旦はHJTとACで駆除できたように見えたのですが、PCを再起動を何度か繰り返しているうちに
>元の状態に戻ってしまいました。

はい、まだ簡単には片付きません。この種の事例では最初の作業だけで解決することはありませんから。
あちらも簡単には駆除されては商売にならないので、幾重にも検出処置逃れの策を弄してきます。
しかも一度削除されても一定間隔ごとに復活する仕組みも組み込んでますから、焦らずひとつずつ進めてください。

では次の確認と作業をお願いします。

まずCCの各タブのログで「スケジュールされたタスク」タブのログだけ出てないので、このログも次回レスで見せてください。

次に以下のアプリを準備してください。
Malwarebytes' Anti-Malware(通称・MBAM)
本家サイト
http://www.malwarebytes.org/

ですが、MBAMは現在安定性や動作でかなり難が出ており、普通に使っても正常にスキャンができないバグまで多発中です。
そのため本家サイトから最新版のダウンロードせず、ここではあえて旧バージョンで作業します。

旧バージョンの説明サイト↓
http://fine.tok2.com/home/heto2/0700SecurityApp/Malwarebytes/0001.htm

以下のURLからMBAMの旧バージョンをダウンロードしてください。
http://www.oldapps.com/malwarebytes.php?old_malwarebytes=12090?download
ファイル直リンです。保存しておいてください。

注)インストール時に日本語でインストールすると文字化けすることがあります。英語でインストール後に日本語化してください。
MBAM起動して「Settings」タブ→「Language」→「Japanese」で日本語化できます。

準備できたらMBAMをインストールとアップデートまでしておいてください。
ただし、ここではまだスキャンはしないように。
なお、ここでMBAMの更新で「プログラム」自体は更新せず、定義だけ更新しておいてください。
プログラム本体を更新すると、バグ多発中の最新版になってしまうので、せっかく旧バージョンでインストールした意味がなくなります。

アップデートまでできたらPCをセーフモードで再起動してから、ATFを使ってゴミファイルの掃除してください。

続いてセーフモードのままMBAMでスキャンしてください。
MBAM起動したら「スキャナー」タブから「フルスキャン」してください。
対象ドライブはCを含めて全ドライブを選択してください。

スキャン対象は全ドライブを選択(チェック)してください。時間はかかりますができるだけ細かくスキャンするためです。
順番はどちらからでもいいですが、なにか検出されたらそれを選択して「remove」(隔離)したあと、再起動を促す表示が出たらそこで一度PCを再起動してください。
もし再起動表示が出ないときは手動で再起動してください。

またMBAMスキャン終了後、「詳細を表示」を押すとその結果が表示されるはずなので、そこで「ログを保存」を押すとそのログが保存可能になります。
そのログをデスクトップにでも保存しておいてください。
このログ確認が特に重要なので、忘れないようにお願いします。

このあとMBAMのログを返信に貼り付けて、それを状態報告とともにレスで見せてください。
  • 悪代官
  • 2015/03/23 (Mon) 05:55:52
今のところは検出されず、落ち着いています
「スケジュールされたタスク」タブのログ
----------------------------------------------------------------------------------------------
有効 Task Adobe Acrobat Update Task Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task BELL D:\W32_TOOL\HitoKoe10.exe
有効 Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task EPSON EP-806A Series Update {06D96841-E0D2-4E1C-AB1C-7A5B5087D513} SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLKJ.EXE /EXE:"{06D96841-E0D2-4E1C-AB1C-7A5B5087D513}" /F:"Update"
有効 Task GO_BED1 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GO_BED2 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task Intel_C_CVKI302402M9240DGN Intel C:\Program Files (x86)\Intel\Intel(R) SSD Toolbox\Intel SSD Toolbox.exe -drive_letter C -drive_serial CVKI302402M9240DGN -trim scheduled
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 Intel® Services Manager C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon Intel® Services Manager "C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe" --automatic
有効 Task RealDownloaderRealUpgradeLogonTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe /logoncheck
有効 Task RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe /scheduledcheck
有効 Task RealPlayerRealUpgradeLogonTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /logoncheck
有効 Task RealPlayerRealUpgradeScheduledTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /scheduledcheck
有効 Task SidebarExecute Microsoft Corporation C:\Program Files\Windows Sidebar\sidebar.exe
有効 Task Task_ShellExecuteAs Mozilla Corporation "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" "http://www.gomplayer.jp/?utm_source=promo&utm_medium=pic&utm_campaign=cancel"
有効 Task Uninstaller_SkipUac_ME IObit C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer
有効 Task Wise Registry Cleaner Schedule Task WiseCleaner.com C:\Program Files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe -a
有効 Task {347B1250-69E4-4364-8B93-67A85D5C482E} D:\APPS_IMG\D_ANIME\SETUP.EXE
有効 Task {81A9FF38-7B0A-460A-B8FC-0F45C1356FE9} D:\APPS_IMG\D_ANIME\SETUP.EXE
有効 Task {B3E8EFA4-C22A-41B4-9924-812F34233732} D:\APPS_IMG\D_ANIME\SETUP.EXE


MBAMのログ
----------------------------------------------------------------------------------------------
Malwarebytes Anti-Malware (試用) 1.75.0.1300
www.malwarebytes.org

定義バージョン: v2015.03.23.03

Windows 7 Service Pack 1 x64 NTFS (セーフモード)
Internet Explorer 11.0.9600.17691
ME :: PC-ME7 [管理者]

リアルタイム保護: 無効

2015/03/23 22:25:55
mbam-log-2015-03-23 (22-25-55).txt

スキャンタイプ: フルスキャン (C:\|D:\|E:\|F:\|Y:\|Z:\|)
有効なスキャン領域: メモリ | スタートアップ | レジストリ | ファイルシステム | ヒューリスティック/追加アイテムのスキャン  | ヒューリスティック/Shuriken エンジンを使用してスキャン  | 不審なプログラム (PUP) | 不審な変更 (PUM)
無効なスキャン領域: ピア・ツー・ピアプログラム(P2P)
スキャンしたアイテム数: 869501
経過時間: 1 時間, 15 分, 48 秒

メモリプロセスの検出: 0
(悪意のあるアイテムは検出されていません。)

メモリモジュールの検出: 0
(悪意のあるアイテムは検出されていません。)

レジストリキーの検出: 0
(悪意のあるアイテムは検出されていません。)

レジストリ値の検出: 0
(悪意のあるアイテムは検出されていません。)

レジストリデータ項目の検出: 0
(悪意のあるアイテムは検出されていません。)

フォルダの検出: 0
(悪意のあるアイテムは検出されていません。)

ファイルの検出: 3
C:\AdwCleaner\Quarantine\C\Users\ME\AppData\Local\Bundled software uninstaller\bi_client.exe.vir (PUP.Optional.Somoto.A) -> 正常に隔離され削除されました。
D:\APPS_CDR\DVD_COPY\CPRMDecrypter\cprmgetkey.exe (HackTool.Agent) -> 正常に隔離され削除されました。
E:\N_SOFT\_Win32\HTML\irvine1_1_2.zip (Adware.CnsMin) -> 正常に隔離され削除されました。

(終)
  • pxu10652
  • 2015/03/23 (Mon) 23:59:12
MBAMは削除しCCで作業を
こんばんは、IVNOと申します。
悪代官さんがご多忙と見受けられますため、代理でご案内いたします。
と言う私もあまり余裕はないので返答が遅れる可能性はあります。
MBAMのログを確認いたしましたが、こちらは問題ないようです。
MBAMは必要ありませんので、導入時の指示に従って削除なされてください。
CCのスケジュールされたタスクのログを確認いたしました。
こちらのログを一度処置だけしましょう。

CCを起動させ、ツール→スタートアップ→スケジュールされたタスクのタブを開き、
以下を無効→エントリの削除の順番にクリックしてください。

有効 Task {347B1250-69E4-4364-8B93-67A85D5C482E} D:\APPS_IMG\D_ANIME\SETUP.EXE
有効 Task {81A9FF38-7B0A-460A-B8FC-0F45C1356FE9} D:\APPS_IMG\D_ANIME\SETUP.EXE
有効 Task {B3E8EFA4-C22A-41B4-9924-812F34233732} D:\APPS_IMG\D_ANIME\SETUP.EXE

作業が完了しましたら、CCは終了させてください。
手動駆除に移行する前に一度ログの見直しを行いたいと思います。
HJTのログ、CCのインストール情報ログ、CCのスタートアップの各タブのログを取得し、
それらを貼り付けてご連絡をお願いいたします。
  • IVNO
  • MAIL
  • 2015/03/25 (Wed) 18:43:37
対応後のログです
HJTのログ
------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 21:58:29, on 2015/03/25
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)

FIREFOX: 36.0.4 (x86 ja)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\EPSON\MyEPSON Connect\mep.exe
C:\VIA_XHCI\usb3Monitor.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\AgnType\AgnType.exe
C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
D:\W32_TOOL\TinyMon.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\husen2K\Husen2K.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaConverter.exe
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaRenderer.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Justsystems\Shuriken\JsvMail.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_134.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_134.exe
C:\Users\ME\Desktop\ウィルス対策\HJT(HijackThis).exe

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll
O2 - BHO: PhishWall - {8CA7E745-EF75-4E7B-BB86-8065C0CE29CA} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft アカウント サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll
O3 - Toolbar: PhishWall - {BB62FFF4-41CB-4AFC-BB8C-2A4D4B42BBDC} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [JustOnlineUpdate] "C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe" /startup
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Google Japanese Input Prelauncher] "C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe" --mode=prelaunch_processes
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [IME14 JPN Uninstall] C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /JPN /Log
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: AgainTyper.lnk = C:\Program Files (x86)\AgnType\AgnType.exe
O4 - Startup: HitoKoe10.lnk = D:\W32_TOOL\GO_START\HitoKoe10.exe
O4 - Startup: IPMSG for Win32.lnk = C:\Program Files\IPMsg\ipmsg.exe
O4 - Startup: KYOU.lnk = D:\W32_TOOL\KYOU.EXE
O4 - Startup: Shuriken着信監視.lnk = C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
O4 - Startup: TinyMon.lnk = D:\W32_TOOL\TinyMon.exe
O4 - Startup: 付箋紙21.lnk = C:\Program Files (x86)\husen2K\Husen2K.exe
O4 - Global Startup: SignalNowExpress.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: SunのJavaコンソール - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://gdmp.canon.jp
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {AF4D6906-EB10-48C1-A0CF-9328196158AE} (PrintControl) - http://gdmp.canon.jp/gundam/activex/PrintControl.ocx
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com/bin/srldetect_intel_4.5.22.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D89B3FF-5B44-4C7F-8D7F-9EC2661F9409}: NameServer = 192.168.1.1
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: CyberLink Product - 2013/07/21 18:58:07 (CLKMSVC10_38F51D56) - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe,-100 (GoogleIMEJaCacheService) - Google Inc. - C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mei006h Service (Mei006h) - Unknown owner - C:\Windows\SysWOW64\mei006h.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyEPSON Connect Service - SEIKO EPSON CORPORATION - C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SDPAUMS server service (SDPASVC) - Unknown owner - C:\Windows\SysWOW64\sdpasvc.exe (file missing)
O23 - Service: SecureBrain PhishWall Update - SecureBrain Corporation - C:\Program Files (x86)\SecureBrain\PhishWall\sbpwupdx.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service2 - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TEPRA Driver Option UI Manager (TepOuService) - Unknown owner - C:\Windows\system32\TPOUSVR.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: uvnc_service - UltraVNC - C:\Program Files\uvnc bvba\UltraVNC\WinVNC.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 16428 bytes

CCのインストール情報ログ
---------------------------------------------------------
Adobe AIR Adobe Systems Incorporated 2015/03/14 17.0.0.124
Adobe Flash Player 17 ActiveX Adobe Systems Incorporated 2015/03/14 6.00 MB 17.0.0.134
Adobe Flash Player 17 NPAPI Adobe Systems Incorporated 2015/03/14 6.00 MB 17.0.0.134
Adobe Reader XI (11.0.10) - Japanese Adobe Systems Incorporated 2014/12/12 203 MB 11.0.10
Adobe Shockwave Player 12.1 Adobe Systems, Inc. 2015/03/22 12.1.7.157
AgainTyper 2013/05/31
AGMDecoder T.Ishii (t-ishii@js2.so-net.ne.jp) 2014/05/05 344 KB 1.1.1
AGMDecoder64 T.Ishii (t-ishii@js2.so-net.ne.jp) 2014/05/05 224 KB 1.1.1
AMD Catalyst Install Manager Advanced Micro Devices, Inc. 2014/12/09 26.7 MB 8.0.916.0
Apple Application Support Apple Inc. 2014/02/26 64.0 MB 2.3.6
Apple Software Update Apple Inc. 2013/05/31 2.38 MB 2.1.3.127
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver Atheros Communications Inc. 2013/05/31 2.1.0.7
Avast Free Antivirus AVAST Software 2015/03/17 10.2.2214
AviSynth 2.5 2013/10/26
BD_3D Advisor CyberLink Corp. 2013/07/21 12.6 MB 2.0.5913
CCleaner Piriform 2015/03/21 5.03
CDBurnerXP CDBurnerXP 2014/09/10 13.2 MB 4.5.4.5000
CyberLink Media Suite 10 CyberLink Corp. 2013/07/21 277 MB 10.0
Defraggler Piriform 2013/12/22 2.16
DivXセットアップ DivX, LLC 2014/09/21 2.6.1.8
EMET 5.2 Microsoft Corporation 2015/03/22 56.6 MB 5.2
EPSON EP-806A Series プリンター アンインストール SEIKO EPSON Corporation 2014/09/20
EPSON Scan Seiko Epson Corporation 2014/09/20
EpsonNet Print SEIKO EPSON CORPORATION 2014/09/20 2.6.0
FormatFactory 3.6.0.0 Format Factory 2015/02/27 3.6.0.0
Google 日本語入力 Google Inc. 2014/10/28 84.1 MB 1.13.1641.0
Intel(R) Management Engine Components Intel Corporation 2013/05/31 8.1.0.1252
Intel(R) Processor Graphics Intel Corporation 2014/06/11 10.18.10.3621
Intel(R) Rapid Storage Technology Intel Corporation 2014/03/08 12.9.0.1001
Intel(R) SDK for OpenCL - CPU Only Runtime Package Intel Corporation 2013/05/31 3.0.0.63463
Intel(R) Update Manager Intel Corporation 2014/04/18 22.6 MB 2.3.1338
Intel(R) USB 3.0 eXtensible Host Controller Driver Intel Corporation 2013/05/31 1.0.5.235
Intel® SSD Toolbox Intel Corporation 2014/11/12 3.2.3.400
IObit Uninstaller IObit 2015/02/19 4.2.6.2
IP Messenger for Win 2013/05/31
Java 7 Update 76 Oracle 2015/02/13 120 MB 7.0.760
Java 7 Update 9 Oracle 2013/05/31 130 MB 7.0.90
Java 8 Update 25 Oracle Corporation 2014/10/15 73.3 MB 8.0.250
Java 8 Update 31 Oracle Corporation 2015/01/31 74.0 MB 8.0.310
Java 8 Update 40 Oracle Corporation 2015/03/14 76.9 MB 8.0.400
JUSTオンラインアップデート 株式会社ジャストシステム 2014/06/11 1.0.1.0
Lagarith Lossless Codec (1.3.27) 2014/09/21 1.02 MB
Media Go Sony 2014/10/28 148 MB 2.8.303
Media Go Network Downloader Sony 2014/10/28 1.33 MB 1.5.19.0
Media Go Video Playback Engine 2.12.110.06300 Sony 2014/10/28 21.0 MB 2.12.110.06300
Microsoft .NET Framework 4.5.2 Microsoft Corporation 2015/01/15 38.8 MB 4.5.51209
Microsoft .NET Framework 4.5.2 (日本語) Microsoft Corporation 2015/02/14 2.93 MB 4.5.51209
Microsoft Office 365 Small Business Premium - ja-jp Microsoft Corporation 2015/03/14 15.0.4701.1002
Microsoft Silverlight Microsoft Corporation 2014/07/24 298 MB 5.1.30514.0
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2014/04/30 1.69 MB 3.1.0000
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2013/05/31 300 KB 8.0.59193
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 Microsoft Corporation 2014/09/14 894 KB 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2014/03/08 788 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2014/07/17 232 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 2014/03/09 786 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Corporation 2015/02/16 1.41 MB 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2014/02/01 238 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2014/08/10 230 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2014/07/17 222 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2013/05/31 598 KB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2015/02/13 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2015/02/13 11.1 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Corporation 2015/02/12 20.5 MB 11.0.61030.0
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 2015/02/12 17.3 MB 11.0.61030.0
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 Microsoft Corporation 2014/10/28 17.1 MB 12.0.21005.1
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Microsoft Corporation 2015/02/13 10.0.50903
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - 日本語 Microsoft Corporation 2015/02/13 10.0.50903
Mozilla Firefox 36.0.4 (x86 ja) Mozilla 2015/03/22 85.5 MB 36.0.4
Mozilla Maintenance Service Mozilla 2014/04/30 341 KB 29.0
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2013/06/01 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2013/06/01 1.33 MB 4.20.9876.0
MSXML 4.0 SP2 パーサーと SDK Microsoft Corporation 2013/05/31 1.22 MB 4.20.9818.0
MyEPSON Portal SEIKO EPSON Corporation 2014/09/20
NextFTP 2013/05/31
OpenSource Flash Video Splitter 1.0.0.5 2014/09/21 1.0.0.5
PDF reDirect (remove only) EXP Systems LLC 2013/07/09 v2.5.2
PhishWall SecureBrain Corporation 2014/04/19 3.5.8
QUAD-CAPTURE Driver Roland Corporation 2013/05/31
QuickTime 7 Apple Inc. 2014/10/29 70.2 MB 7.76.80.95
Shuriken 2012 株式会社ジャストシステム 2013/05/31 84.5 MB 11.0.4
SignalNow Express ストラテジー株式会社 2015/03/08 2.0.0.0
Software Updater SEIKO EPSON CORPORATION 2014/11/16 9.70 MB 4.3.3
Sony Media Library Earth 9.2.00 Sony Corporation 2015/02/10 49.5 MB 9.2.00.01271
Sony Mobile Update Engine Sony Mobile Communications AB 2014/02/15 2.14.2.201402071544
Sony PC Companion 2.10.245 Sony 2015/02/22 19.6 MB 2.10.245
System Requirements Lab for Intel Husdawg, LLC 2014/08/14 1.12 MB 4.5.24.0
UltraVnc uvnc bvba 2013/05/31 12.3 MB 1.1.9.0
Vb5rs3 2013/05/31
VIA プラットフォーム・デバイス・マネージャ VIA Technologies, Inc. 2013/05/31 2.62 MB 1.38
VirtualCloneDrive Elaborate Bytes 2013/05/31
VMware Player VMware, Inc 2015/02/07 390 MB 6.0.5
Winamp Nullsoft, Inc 2013/11/27 5.666
Windows Live Essentials Microsoft Corporation 2014/04/30 16.4.3528.0331
Wise Registry Cleaner 8.31 WiseCleaner.com, Inc. 2015/01/05 7.12 MB 8.31
x-アプリ 6.0.01 Sony Corporation 2015/02/10 88.6 MB 10.0.01
x64 Components v4.7.6 Shark007 2014/09/21 91.1 MB 4.7.6
Xvid Video Codec Xvid Team 2014/09/21 1.3.2
「テプラ」PRO PCラベルソフト SPC9C KING JIM 2013/11/17 3.70.000
「テプラ」PRO SPC9C プリンタドライバ 2013/11/17
らくちんCDラベルメーカー15 MediaNavi 2013/05/31 15.0.0.0
チャクモエ for PC メイドボイス 2013/05/31
ナビマスター S V1.0 クラリオン株式会社 2014/06/21 15.2 MB 1.0.0
ミュージックCDデザイナー3 MEGASOFT Inc. 2013/06/09
ラベル屋さん9 A-one Co.,Ltd. 2014/10/11 9.0.700
付箋紙21 2013/05/31
秀丸エディタ (8.21) 有限会社サイトー企画 2013/05/31 8.21
秀丸パブリッシャー 2013/05/31
筆まめ Ver.24 販売元:株式会社筆まめ 開発元:株式会社モーリン 2014/12/20 1.12 GB 24.09.2410.0
電波時計用JJYシミュレータ スタアストーンソフト 2014/03/15 656 KB 1.0.5.0

スタートアップのログ
------------------------------------------
有効 HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run Sidebar Microsoft Corporation C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
有効 HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
有効 HKLM:Run AvastUI.exe Avast Software s.r.o. "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
有効 HKLM:Run BDRegion cyberlink C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
有効 HKLM:Run DivXMediaServer DivX, LLC C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
有効 HKLM:Run DivXUpdate DivX, LLC "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
有効 HKLM:Run Google Japanese Input Prelauncher Google Inc. "C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe" --mode=prelaunch_processes
有効 HKLM:Run IAStorIcon Intel Corporation "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
有効 HKLM:Run IME14 JPN Uninstall Microsoft Corporation C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /JPN /Log
有効 HKLM:Run JustOnlineUpdate 株式会社ジャストシステム "C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe" /startup
有効 HKLM:Run QuickTime Task Apple Inc. "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
有効 HKLM:Run RemoteControl10 CyberLink Corp. "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
有効 HKLM:Run StartCCC Advanced Micro Devices, Inc. "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
有効 HKLM:Run SunJavaUpdateSched Oracle Corporation "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
有効 HKLM:Run TepOuService KING JIM CO.,LTD. C:\Windows\system32\TPOUSVR.EXE -uimanage
有効 HKLM:Run USB3MON Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
有効 HKLM:Run VIAxHCUtl VIA Technologies, Inc. C:\VIA_XHCI\usb3Monitor.exe
有効 HKLM:Run VirtualCloneDrive Elaborate Bytes AG "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
有効 Startup Common SignalNowExpress.lnk ストラテジー株式会社 C:\Program Files (x86)\ストラテジー株式会社\SignalNow Express\SignalNowExpress.exe
有効 Startup User AgainTyper.lnk C:\Program Files (x86)\AgnType\AgnType.exe
有効 Startup User HitoKoe10.lnk D:\W32_TOOL\GO_START\HitoKoe10.exe
有効 Startup User IPMSG for Win32.lnk H.Shirouzu C:\Program Files\IPMsg\ipmsg.exe
有効 Startup User KYOU.lnk D:\W32_TOOL\KYOU.EXE
有効 Startup User Shuriken着信監視.lnk 株式会社ジャストシステム C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
有効 Startup User TinyMon.lnk D:\W32_TOOL\TinyMon.exe
有効 Startup User 付箋紙21.lnk ROTO C:\Program Files (x86)\husen2K\Husen2K.exe


スタートアップ(IE)のログ
------------------------------------------
無効 Extension Lync Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
無効 Extension Lync Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
有効 Helper avast! Online Security Avast Software s.r.o. C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
有効 Helper avast! Online Security Avast Software s.r.o. C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
有効 Helper ExplorerWnd Helper IObit C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll
無効 Helper Lync Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
無効 Helper Lync Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
有効 Helper Microsoft SkyDrive Pro Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
有効 Helper Microsoft SkyDrive Pro Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
無効 Helper Microsoft アカウント サインイン ヘルパー Microsoft Corp. C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
無効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
無効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
有効 Helper PhishWall SecureBrain Corporation C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
無効 Helper Windows Live ID Sign-in Helper Microsoft Corp. C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 Toolbar PhishWall SecureBrain Corporation C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll


スタートアップ(Firefox)のログ
------------------------------------------
有効 Extension Avast Online Security 10.2.0.187 AVAST Software default Firefox 36.0.4 C:\Program Files\AVAST Software\Avast\WebRep\FF
有効 Plugin Adobe Acrobat 11.0.10.32 Adobe Systems Inc. default Firefox 36.0.4 C:\Program Files (x86)\Adobe\Reader 11.0\Reader\browser\nppdf32.dll
有効 Plugin DivX Plus Web Player 3.2.3.1164 DivX, LLC default Firefox 36.0.4 C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll
有効 Plugin DivX VOD Helper Plug-in 1.1.0.14 DivX, LLC. default Firefox 36.0.4 C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
有効 Plugin Google Update 1.3.26.9 Google Inc. default Firefox 36.0.4 C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
有効 Plugin Intel® Identity Protection Technology 2.1.42.0 Intel Corporation default Firefox 36.0.4 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
有効 Plugin Intel® Identity Protection Technology 2.1.42.0 Intel Corporation default Firefox 36.0.4 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
有効 Plugin Java Deployment Toolkit 8.0.400.25 11.40.2.25 Oracle Corporation default Firefox 36.0.4 C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npdeployJava1.dll
有効 Plugin Java(TM) Platform SE 8 U40 11.40.2.25 Oracle Corporation default Firefox 36.0.4 C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll
有効 Plugin Microsoft Office 2013 15.0.4514.1000 Microsoft Corporation default Firefox 36.0.4 C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL
有効 Plugin Microsoft Office 2013 15.0.4545.1000 Microsoft Corporation default Firefox 36.0.4 C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
有効 Plugin Photo Gallery 16.4.3528.331 Microsoft Corporation default Firefox 36.0.4 C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
有効 Plugin QuickTime Plug-in 7.7.6 7.7.6.0 Apple Inc. default Firefox 36.0.4 C:\Program Files (x86)\QuickTime\Plugins\npqtplugin5.dll
有効 Plugin Shockwave Flash 17.0.0.134 Adobe Systems Incorporated default Firefox 36.0.4 C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll
有効 Plugin Shockwave for Director 12.1.7.157 Adobe Systems, Inc. default Firefox 36.0.4 C:\Windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll
有効 Plugin Silverlight Plug-In 5.1.30514.0 Microsoft Corporation default Firefox 36.0.4 C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

スタートアップ(タスク)のログ
------------------------------------------
有効 Task Adobe Acrobat Update Task Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task BELL D:\W32_TOOL\HitoKoe10.exe
有効 Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task EPSON EP-806A Series Update {06D96841-E0D2-4E1C-AB1C-7A5B5087D513} SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLKJ.EXE /EXE:"{06D96841-E0D2-4E1C-AB1C-7A5B5087D513}" /F:"Update"
有効 Task GO_BED1 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GO_BED2 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task Intel_C_CVKI302402M9240DGN Intel C:\Program Files (x86)\Intel\Intel(R) SSD Toolbox\Intel SSD Toolbox.exe -drive_letter C -drive_serial CVKI302402M9240DGN -trim scheduled
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 Intel® Services Manager C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon Intel® Services Manager "C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe" --automatic
有効 Task RealDownloaderRealUpgradeLogonTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe /logoncheck
有効 Task RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe /scheduledcheck
有効 Task RealPlayerRealUpgradeLogonTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /logoncheck
有効 Task RealPlayerRealUpgradeScheduledTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /scheduledcheck
有効 Task SidebarExecute Microsoft Corporation C:\Program Files\Windows Sidebar\sidebar.exe
有効 Task Task_ShellExecuteAs Mozilla Corporation "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" "http://www.gomplayer.jp/?utm_source=promo&utm_medium=pic&utm_campaign=cancel"
有効 Task Uninstaller_SkipUac_ME IObit C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer
有効 Task Wise Registry Cleaner Schedule Task WiseCleaner.com C:\Program Files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe -a

  • pxu10652
  • 2015/03/25 (Wed) 22:08:11
GOMのゴミを掃除します
レスが遅くなってごめんなさい。
回線障害で丸1日以上ネットが使えませんでした。
IVNOさんにもまたご迷惑かけてすみません。

各ログを見たところ、まだひとつ残ってるようなのでこれを修正しましょう。

またCC起動して「スケジュール」タブ内の下記を「無効」「エントリの削除」してください。
>有効 Task Task_ShellExecuteAs Mozilla Corporation "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" "http://www.gomplayer.jp/?utm_source=promo&utm_medium=pic&utm_campaign=cancel"

これができたら一度CC終了後に再度CC起動して、スケジュールタブのログだけ取り直して、それをまたレスください
  • 悪代官
  • 2015/03/25 (Wed) 22:25:56
GOM掃除しました。
有効 Task Adobe Acrobat Update Task Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task BELL D:\W32_TOOL\HitoKoe10.exe
有効 Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task EPSON EP-806A Series Update {06D96841-E0D2-4E1C-AB1C-7A5B5087D513} SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLKJ.EXE /EXE:"{06D96841-E0D2-4E1C-AB1C-7A5B5087D513}" /F:"Update"
有効 Task GO_BED1 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GO_BED2 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task Intel_C_CVKI302402M9240DGN Intel C:\Program Files (x86)\Intel\Intel(R) SSD Toolbox\Intel SSD Toolbox.exe -drive_letter C -drive_serial CVKI302402M9240DGN -trim scheduled
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 Intel® Services Manager C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon Intel® Services Manager "C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe" --automatic
有効 Task RealDownloaderRealUpgradeLogonTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe /logoncheck
有効 Task RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe /scheduledcheck
有効 Task RealPlayerRealUpgradeLogonTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /logoncheck
有効 Task RealPlayerRealUpgradeScheduledTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /scheduledcheck
有効 Task SidebarExecute Microsoft Corporation C:\Program Files\Windows Sidebar\sidebar.exe
有効 Task Uninstaller_SkipUac_ME IObit C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer
有効 Task Wise Registry Cleaner Schedule Task WiseCleaner.com C:\Program Files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe -a
  • pxu10652
  • 2015/03/25 (Wed) 23:24:49
次はOTLで解析します
おはようございます。
GOMのゴミも掃除できましたね。
これで不審な痕跡は消えたようです。

それではヤマの解析作業しましょう。
以下のツールを準備してください。
OTL(OldTimer Listit)
ファイル直リンなので、DLしたら保存しておいてください。
http://oldtimer.geekstogo.com/OTL.exe
片付けるときは起動後に「Cleanup」ボタンを押せば自動で削除されます。

他のプログラムを起動しない状態でOTLを起動してください。
起動したら、ウィンドウの上の方にある「Scan All Users」にチェックを入れ、以下のコマンドを「Custom Scan/Fixes」にコピペしてください。

%windir%\tasks\*.job
DRIVES
BASESERVICES
%SYSTEMDRIVE%\*.exe
CREATERESTOREPOINT

その後、左上の「Run Scan」を押すとスキャン開始されます。
スキャン開始後、PC環境にもよりますが数分ほどすると、「OTL.txt」と「Extras.txt」がOTL.exeと同じ場所に作成されるはずなので、この2つのファイルをデスクトップあたりに保存しておいてください。
なお、Extras.txtは出ないこともありますが、その場合はOTL.txtだけでもいいです。

このあとOTLログを丸ごと返信に貼り付けてレスで見せてください。
ただしOTLログはかなり長くなるため、一度に送信してもfc2の文字数制限で途切れます。
なのでログも適当なところで分割して、複数回に分けてレス送信してください。

OTLでスキャンしただけでは何も変化は起きません。
この結果を見て、検出されたものを次回以降の作業で処置することになるはずです
  • 悪代官
  • 2015/03/26 (Thu) 07:32:13
Extras.Txtです。
Extras.Txt

OTL Extras logfile created on: 2015/03/26 23:02:58 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\ME\Desktop\ウィルス対策
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17691)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

31.96 Gb Total Physical Memory | 28.25 Gb Available Physical Memory | 88.38% Memory free
31.96 Gb Paging File | 27.96 Gb Available in Paging File | 87.50% Paging File free
Paging file location(s): [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 223.47 Gb Total Space | 134.86 Gb Free Space | 60.35% Space Free | Partition Type: NTFS
Drive D: | 100.10 Gb Total Space | 73.49 Gb Free Space | 73.42% Space Free | Partition Type: NTFS
Drive E: | 500.39 Gb Total Space | 361.14 Gb Free Space | 72.17% Space Free | Partition Type: NTFS
Drive F: | 2824.31 Gb Total Space | 1146.00 Gb Free Space | 40.58% Space Free | Partition Type: NTFS
Drive K: | 3.93 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive L: | 7.63 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive M: | 4.16 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive N: | 4.02 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive O: | 4.17 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive P: | 4.03 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive T: | 4.24 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive U: | 4.27 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive V: | 7.57 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive Y: | 200.90 Gb Total Space | 87.62 Gb Free Space | 43.62% Space Free | Partition Type: NTFS
Drive Z: | 100.10 Gb Total Space | 50.99 Gb Free Space | 50.94% Space Free | Partition Type: NTFS

Computer Name: PC-ME7 | User Name: ME | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.txt[@ = hidemaru.txt] -- D:\W32_TOOL\HIDEMARU\Hidemaru.exe (有限会社サイトー企画)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.txt [@ = hidemaru.txt] -- D:\W32_TOOL\HIDEMARU\Hidemaru.exe (有限会社サイトー企画)

[HKEY_USERS\S-1-5-21-3953051745-2568508545-2191147087-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- D:\W32_TOOL\HIDEMARU\Hidemaru.exe %1 (有限会社サイトー企画)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- Reg Error: Value error.
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- D:\W32_TOOL\HIDEMARU\Hidemaru.exe %1 (有限会社サイトー企画)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- Reg Error: Value error.
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[color=#E56717]========== Authorized Applications List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{056FD2F9-68D2-416E-AFC6-19DB35BD673C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{104C8410-0FCE-402A-8FB7-5FDDE9542850}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{16FDD0B1-C7E2-42A2-8106-010C5C14235A}" = rport=10243 | protocol=6 | dir=out | app=system |
"{280E00FB-ECE0-467B-8651-DE7BD06C3C7C}" = lport=29101 | protocol=6 | dir=in | name=tepouservice port |
"{2A3E2773-10AF-4171-84DE-3826AF4CD724}" = lport=445 | protocol=6 | dir=in | app=system |
"{2C8F1B67-2594-4258-A3ED-A3FB8C71A181}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{316EFDD2-5359-49AC-92DC-A09104C30FEE}" = lport=49221 | protocol=6 | dir=in | name=akamai netsession interface |
"{379511CA-C90A-418C-84E2-5CC2946D6466}" = lport=2869 | protocol=6 | dir=in | app=system |
"{484E7ECD-EA30-4A80-B02E-12460CAF76A5}" = lport=137 | protocol=17 | dir=in | app=system |
"{4DB98025-8ED8-440A-929E-1972097A23DD}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{51FBBFED-6F82-448B-8974-1F92A1FC5131}" = rport=139 | protocol=6 | dir=out | app=system |
"{5308BE4D-82DB-42F5-B88A-3BAA7E2F1BE6}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{698E4B64-634A-4F95-B91D-2CE4363FFFA1}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{6C2EA3AC-A1D1-4007-A914-5574069D5289}" = rport=138 | protocol=17 | dir=out | app=system |
"{6DB7BC42-69FB-4894-9357-F0ACC18F9C63}" = lport=138 | protocol=17 | dir=in | app=system |
"{6E0A68AC-3F37-42E4-80EC-1DD72888D7FF}" = lport=5800 | protocol=6 | dir=in | name=vnc5800 |
"{76660EFE-FB4A-4542-B700-992475EA3585}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{81DF7740-19D0-41AE-948A-A59B4D43D957}" = lport=49170 | protocol=6 | dir=in | name=akamai netsession interface |
"{93B2F679-8C93-4E32-B823-649EF3805F90}" = rport=445 | protocol=6 | dir=out | app=system |
"{981E3F55-8A47-4C2A-9BC9-E2A1D2D51AF1}" = lport=3389 | protocol=6 | dir=in | app=system |
"{A4FB42B2-6658-4BD9-8219-58ED3F1DC5D1}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A6991368-2FAD-4FD7-A2A1-296EA41B45C0}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AFCEA8A1-B63E-4CC3-B986-1287B2CEEFF7}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{B02AFDC4-E084-42B4-89D2-472D5E229794}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\outlook.exe |
"{B1A6C8A2-C031-470E-A4EA-CE36CB35E99A}" = lport=5900 | protocol=6 | dir=in | name=vnc5900 |
"{BB491871-2C7D-4F5C-A4D8-932CA9D4950D}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{BF027025-5794-4A3B-88B3-7A1E9F235892}" = lport=3389 | protocol=6 | dir=in | svc=termservice | app=%systemroot%\system32\svchost.exe |
"{CE2D7BEA-FA2A-45A1-A776-E9F57A02C195}" = lport=10243 | protocol=6 | dir=in | app=system |
"{D019C75E-BCE1-4955-8273-13744C539B26}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{D1B1CF26-3786-40EF-874B-DF811396C89C}" = lport=139 | protocol=6 | dir=in | app=system |
"{D2EDCC51-7A2D-451E-9301-C806848688F9}" = lport=49223 | protocol=6 | dir=in | name=akamai netsession interface |
"{D49B848F-51B3-4DB4-AD48-A28105F0841B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D6FE5603-FC05-4DE6-8016-393D19F6CA7F}" = rport=137 | protocol=17 | dir=out | app=system |
"{DB852EF2-E37A-4443-A49E-14E4E91B2E55}" = lport=3389 | protocol=17 | dir=in | svc=termservice | app=%systemroot%\system32\svchost.exe |
"{E6F01AEB-E69C-4946-9757-DBA05BF4D7D5}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0259492F-CF87-44CB-9907-80DADDAD50A6}" = protocol=17 | dir=in | app=c:\program files\uvnc bvba\ultravnc\vncviewer.exe |
"{0C8445CD-89FA-486F-81E7-819575F7196D}" = protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\ucmapi.exe |
"{1F141707-3823-40B8-A3D5-BFE767D29469}" = protocol=6 | dir=out | app=system |
"{23B97B86-1424-444A-89C7-573E31E0860B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{2A316C61-FA0F-4B1E-9205-56588A12387D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{30AC227B-DC3C-4367-9263-96024B5F3041}" = protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\lync.exe |
"{31504F49-44E1-45E7-8C07-2C2AC0CAF67A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3CE19D85-D094-4B56-81CE-9BE2D3C3C4AA}" = protocol=6 | dir=in | app=c:\program files\avast software\avast\ng\vbox\aswfe.exe |
"{3D069458-E366-4E57-A925-A62B6C3AABC6}" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"{3F284309-4358-41EA-BCC9-BDDC7D7F9542}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe |
"{42515B6D-1C68-4B0C-A3D1-DD08DD5B9437}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{4819A43F-15A5-4E3A-A5DC-B605DA2A2089}" = protocol=6 | dir=in | app=z:\temp\wzse0.tmp\fwd784tl\epfwupd.exe |
"{51B50783-EF9E-40B5-9958-4ED58B381E95}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{55E0E470-387C-4718-BA4A-C4C125E89646}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{59C1139C-A3D0-493D-B45C-3FFF520EC881}" = protocol=17 | dir=in | app=c:\program files\uvnc bvba\ultravnc\winvnc.exe |
"{5C00C531-FD02-407C-824F-9CA3D8C58352}" = protocol=6 | dir=in | app=c:\program files\uvnc bvba\ultravnc\winvnc.exe |
"{63B46EB2-64FC-4C64-9DA7-47A091D6927E}" = protocol=17 | dir=in | app=z:\temp\epinsnav\dl\3013\network\epsonnetsetup\epsonnetsetup3_6_1_2200\eneasyapp.exe |
"{6659FF4D-2D72-44E2-8C89-73EAA399E135}" = protocol=6 | dir=in | app=c:\program files (x86)\sony mobile\update engine\sony mobile update engine.exe |
"{6834211E-C011-4F29-963E-6A2A09C634B6}" = protocol=17 | dir=in | app=c:\program files (x86)\freetime\formatfactory\formatfactory.exe |
"{687BDC45-35A4-4C76-81CF-BE6AC18F0AF0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{6BF56C40-41CE-4229-85B0-1AE983BE9AD2}" = dir=in | app=c:\program files (x86)\vmware\vmware player\vmware-authd.exe |
"{6E8AB753-6662-46E1-B3AB-86C73712B3A2}" = protocol=17 | dir=in | app=z:\temp\wzse0.tmp\fwd784tl\epfwupd.exe |
"{6E9062D1-647C-4CF2-92E3-D32709C5E6DA}" = protocol=17 | dir=in | app=c:\program files\avast software\avast\ng\vbox\aswfe.exe |
"{6F2D4823-A34F-4FE0-A7A1-88604C725E0E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{751BDA87-ECAF-4F25-A7A5-387CF49C99D6}" = dir=out | app=z:\temp\nsu33e.tmp\cnetinstaller-10605508.exe |
"{809DB32B-D564-42C1-BDBC-89303D79DD75}" = protocol=6 | dir=in | app=c:\program files (x86)\freetime\formatfactory\formatfactory.exe |
"{84D65B93-D4FC-47EB-840D-2497DC91CF25}" = protocol=6 | dir=in | app=c:\program files\microsoft office 15\root\office15\ucmapi.exe |
"{8955C88F-A8D9-4E7D-A4D4-B26A7646592A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8C18593B-3B8F-44CC-8C01-0FBC0B69A547}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{8F051661-59FC-4939-84D9-1B54FFD1D449}" = dir=in | app=c:\program files (x86)\vmware\vmware player\vmware-authd.exe |
"{8FF191BC-41FD-4742-86F9-16E5AEC44494}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{9090FDBB-C017-425E-99AA-6FDF6AE0D72E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9C6114E3-66DF-4EBD-B708-9FFD74958F20}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A1BDC2D9-6849-43B0-88F9-9A6F70F68809}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe |
"{A99DDF06-974A-47BE-AF3F-F6C228DB4108}" = protocol=6 | dir=in | app=z:\temp\epinsnav\dl\3013\network\epsonnetsetup\epsonnetsetup3_6_1_2200\eneasyapp.exe |
"{AB3F819C-C65D-464E-805D-684F591EE953}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{AFEC213B-0B07-44FA-8949-A270D0134147}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B306A4BD-BDB8-41E4-902F-7D07EA043FD6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BBB1C414-CE55-4AE7-A9CE-2D8FCDAE9AA0}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BD086409-7883-4328-A452-1271330AFFCC}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe |
"{C331D008-A046-4269-8A26-74A99814DAFE}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe |
"{C752A5C2-0D2E-4189-9A37-9E64B606745F}" = protocol=6 | dir=in | app=c:\program files\uvnc bvba\ultravnc\vncviewer.exe |
"{C92713C1-0941-4D0A-947A-758B030F3111}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{CDB73764-C894-4194-94DE-404F834DD5BE}" = protocol=6 | dir=in | app=c:\program files\microsoft office 15\root\office15\lync.exe |
"{D16FD926-AB31-4ED9-B99A-CDEC7288BF2C}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D5FC02D8-2255-4B06-BA9A-48F0754B7B31}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{DF453315-A999-4DAB-8CC5-392262E14843}" = protocol=6 | dir=in | app=z:\temp\wzse0.tmp\fwd784tl\epfwupd.exe |
"{E90E18E9-2616-4BA5-B57B-7CAE4A0BE31F}" = dir=in | app=z:\temp\nsu33e.tmp\cnetinstaller-10605508.exe |
"{EF2E3B7F-E162-4FF9-AA1B-6B257229E808}" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"{F007DA2C-1383-463B-8ACE-EF0A3CCF04D7}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{FAE738ED-E011-4016-A4C8-B9BBEDC694E5}" = protocol=6 | dir=in | app=z:\temp\epinsnav\dl\3013\network\epsonnetsetup\epsonnetsetup3_6_1_2200\eneasyapp.exe |
"{FB14FC58-16DB-43AE-B69E-F69CC014293A}" = protocol=17 | dir=in | app=c:\program files (x86)\sony mobile\update engine\sony mobile update engine.exe |
"{FC7EB1E0-4297-4976-9E8C-5A832ABFB83C}" = protocol=17 | dir=in | app=z:\temp\wzse0.tmp\fwd784tl\epfwupd.exe |
"{FD5900D8-8878-42C8-B230-E312861A0D1C}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{FD6F8955-56DB-407C-8A6E-D456E85FA311}" = protocol=17 | dir=in | app=z:\temp\epinsnav\dl\3013\network\epsonnetsetup\epsonnetsetup3_6_1_2200\eneasyapp.exe |
"TCP Query User{491B718F-36F6-4C5F-9DA0-E635F34EB29B}C:\program files\ipmsg\ipmsg.exe" = protocol=6 | dir=in | app=c:\program files\ipmsg\ipmsg.exe |
"TCP Query User{74869566-B243-4BC7-BE13-0F3CBA65C810}C:\program files (x86)\freetime\formatfactory\formatfactory.exe" = protocol=6 | dir=in | app=c:\program files (x86)\freetime\formatfactory\formatfactory.exe |
"TCP Query User{8192B284-1B89-4688-87F1-E496699733BC}C:\program files\ipmsg\ipmsg.exe" = protocol=6 | dir=in | app=c:\program files\ipmsg\ipmsg.exe |
"TCP Query User{A3504BFC-2E5C-4414-B247-913745516561}C:\bitnami\redmine-2.6.1-2\apache2\bin\httpd.exe" = protocol=6 | dir=in | app=c:\bitnami\redmine-2.6.1-2\apache2\bin\httpd.exe |
"TCP Query User{B9797E2F-3AEB-493B-B1C9-159F05583D6E}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{DC5DF275-F6E7-436F-83C0-05B4C9C9F62D}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"UDP Query User{2549B84A-D7FD-4C99-98AB-9FBE5C80E71D}C:\program files (x86)\freetime\formatfactory\formatfactory.exe" = protocol=17 | dir=in | app=c:\program files (x86)\freetime\formatfactory\formatfactory.exe |
"UDP Query User{39672F37-8792-46DE-B56E-F4BE130138CE}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"UDP Query User{9A44B053-5EED-4AB8-ACBC-9A76E3DA9C9A}C:\program files\ipmsg\ipmsg.exe" = protocol=17 | dir=in | app=c:\program files\ipmsg\ipmsg.exe |
"UDP Query User{AED56CCC-7D6E-4836-903E-63FED59C8E4B}C:\program files\ipmsg\ipmsg.exe" = protocol=17 | dir=in | app=c:\program files\ipmsg\ipmsg.exe |
"UDP Query User{C4116237-0C8F-4428-B51B-F04A1EEBCD7F}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{F997B43F-94EB-41E0-83A6-77086EFE2BB2}C:\bitnami\redmine-2.6.1-2\apache2\bin\httpd.exe" = protocol=17 | dir=in | app=c:\bitnami\redmine-2.6.1-2\apache2\bin\httpd.exe |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A2E1907-D0DE-0D01-CA64-CB0AB0BFE539}" = AMD Wireless Display v3.0
"{1664D45E-FA92-8C52-92E9-E8ADB04A18ED}" = AMD Drag and Drop Transcoding
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26784146-6E05-3FF9-9335-786C7C0FB5BE}" = Microsoft .NET Framework 4.5.2
"{27DEA29A-222C-45F8-B70D-0A7B303FC71B}" = Intel(R) Rapid Storage Technology
"{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
"{409CB30E-E457-4008-9B1A-ED1B9EA21140}" = Intel(R) Rapid Storage Technology
"{4230B46F-DB0B-479C-B955-AD2DF3AD0350}" = AGMDecoder64
"{426582A8-202F-D13C-8BD5-F00551BAFC93}" = AMD Wireless Display v3.0
"{43E67915-502D-3B7E-8FCD-ABB40088E45C}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{63B4D665-34F5-333A-BE00-6DDE0CBD4A6C}" = Microsoft .NET Framework 4.5.2 (JPN)
"{6A1E4EFB-3EE0-40A0-9D6D-E865370289DB}" = Google 日本語入力
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8F2415FA-72F2-F029-0450-4EB2FAE484C5}" = AMD Accelerated Video Transcoding
"{90150000-007E-0000-1000-0000000FF1CE}" = Office 15 Click-to-Run Licensing Component
"{90150000-008C-0000-1000-0000000FF1CE}" = Office 15 Click-to-Run Extensibility Component
"{90150000-008C-0411-1000-0000000FF1CE}" = Office 15 Click-to-Run Localization Component
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.2
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1041" = Microsoft .NET Framework 4.5.2 (日本語)
"{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{C16CD4C0-48EE-0F40-C9FD-0778EAF73FBD}" = AMD Wireless Display v3.0
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
"{D2837730-4960-3B35-8088-201387FD3BDB}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - JPN
"{E452E727-86B8-4233-8CC3-41FD817AFAFF}" = VMware Player
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{F2A7CE36-57BF-5C86-952D-90DBF3746D82}" = AMD Catalyst Install Manager
"{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}" = Intel® Trusted Connect Service Client
"「テプラ」PRO SPC9C プリンタドライバ" = 「テプラ」PRO SPC9C プリンタドライバ
"Advanced x64Components_is1" = x64 Components v4.7.6
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"EPSON EP-806A Series" = EPSON EP-806A Series プリンター アンインストール
"IPMSG for Win32" = IP Messenger for Win
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - JPN" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - 日本語
"NextFTP" = NextFTP
"O365SmallBusPremRetail - ja-jp" = Microsoft Office 365 Small Business Premium - ja-jp
"RolandRDID0117" = QUAD-CAPTURE Driver
"Ultravnc2_is1" = UltraVnc

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}" = tools-freebsd
"{00F9DB8C-65D7-4D47-AB5F-F698EE38580D}" = Windows Live UX Platform
"{024D6C9E-4775-421D-B0D0-D4F123687778}" = Windows Live Essentials
"{04C4B49D-45D9-4A28-9ED1-B45CBD99B8C7}" = System Requirements Lab for Intel
"{06D085C8-1F00-11B2-96A7-8f0CE39193ED}" = Intel® SSD Toolbox
"{07AAB66E-4718-422D-9218-4AFB3C922A71}" = Photo Gallery
"{0FE3F13F-8A37-46BA-F973-762F81E833C3}" = CCC Help French
"{10E629F6-A672-4631-9305-881DFFC5B39B}" = 「テプラ」PRO PCラベルソフト SPC9C
"{11087D24-567D-7D88-69C6-D7A08B5F4C47}" = Catalyst Control Center - Branding
"{12914061-EB9B-4AE7-AC7E-0B8A607C7DF4}" = Intel(R) Update Manager
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{15023164-F226-9ECA-D0CB-59AB4B40D222}" = Media Go Video Playback Engine 2.12.110.06300
"{1543E140-FADF-9E99-D388-4435C2FBC55E}" = CCC Help Chinese Standard
"{162B6299-BB26-416A-AF4C-0F24A843A9E8}" = SignalNow Express
"{197597A7-AD33-4898-9D8E-73066818B464}" = tools-netware
"{1D6432B4-E24D-405E-A4AB-D7E6D088CBC9}" = Windows Live Photo Common
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{20F230E0-5C5E-42D8-ABA1-8BDAF8AD9929}" = ナビマスター S V1.0
"{223469C7-3B3F-4D18-AB4A-4F4B298D0DB2}" = x-APPLICATION Components
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F03217076FF}" = Java 7 Update 76
"{26A24AE4-039D-4CA4-87B4-2F83217009F0}" = Java 7 Update 9
"{26A24AE4-039D-4CA4-87B4-2F83218025F0}" = Java 8 Update 25
"{26A24AE4-039D-4CA4-87B4-2F83218031F0}" = Java 8 Update 31
"{26A24AE4-039D-4CA4-87B4-2F83218040F0}" = Java 8 Update 40
"{2C9A2369-162D-7AD7-D50F-5F59CEC8A046}" = CCC Help Danish
"{2D2D8FE2-605C-4D3C-B706-36E981E7EEF0}" = BD_3D Advisor
"{2D61415B-F99C-8161-F452-760B6E441428}" = CCC Help Hungarian
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
"{3361D415-BA35-4143-B301-661991BA6219}" = MyEPSON Portal
"{339647D6-A277-974F-FF29-83CA6284559B}" = CCC Help German
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{34927EBC-98D4-4D53-98BE-510DF5999F50}" = Adobe AIR
"{3813B1A7-782C-4954-BCD2-2D2705DA3101}" = 筆まめ Ver.24
"{3BB91D6B-258C-44E7-B5D1-55031D3C22BD}" = x-アプリ
"{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}" = QuickTime 7
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{402ED4A1-8F5B-387A-8688-997ABF58B8F2}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{41C61308-6CFD-4D54-AB6A-7136ED08A18E}" = Windows Live Communications Platform
"{46F044A5-CE8B-4196-984E-5BD6525E361D}" = Apple Application Support
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BD8FB0D-9407-429D-C412-FAE0A318A8AE}" = CCC Help Polish
"{4D594F78-0C6D-1442-61CC-94D735FEC05D}" = CCC Help English
"{5562F05F-908C-4F15-9B3C-98D5FD32DCAB}" = Media Go Network Downloader
"{55641498-D428-4EE8-9694-5534706C4A62}" = JUSTオンラインアップデート
"{561A6F14-EDFB-43FC-9803-CAD174D08F26}" = Sony Media Library Earth 9.2.00
"{5958C669-28BF-D667-A004-E6FBF448027D}" = CCC Help Spanish
"{5E848897-1113-49FE-8FCE-D4BF39EDE254}" = Windows Live UX Platform Language Pack
"{5F2EADA0-6025-4815-9269-9A8D3B5370B6}" = AGMDecoder
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{637B1239-84B7-0B0F-2549-7020CA57C831}" = CCC Help Thai
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{659CB81C-B54E-4DF1-B618-F35777393A54}" = Windows Live Installer
"{6AE0A655-9BB8-460E-1956-ED37E3B221FA}" = CCC Help Greek
"{6B254D2F-6F6F-5455-DD3B-E71E5C1C0C9A}" = AMD Catalyst Control Center
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 パーサーと SDK
"{7481E13B-EC16-1B14-0E32-E88165CD4C57}" = Catalyst Control Center Graphics Previews Common
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7ABA4B54-3672-0548-C1CC-97405F767061}" = CCC Help Russian
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7FE73251-50FA-E864-67EB-19C4BC7AA1C9}" = CCC Help Portuguese
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{870F30A2-7AA3-41DB-8F3E-BACA597E7EF6}" = 電波時計用JJYシミュレータ
"{894CBED0-8225-D59B-5632-D01B14C6D520}" = CCC Help Norwegian
"{8BD7C51C-0CC4-3E28-CFDC-F7D4C5583783}" = CCC Help Finnish
"{8C0B0C9E-60E6-48CD-8080-615A6D271C0F}" = PhishWall
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8ECCC07B-83E3-3877-26DF-815CD2B30749}" = CCC Help Italian
"{90D497A9-5BE3-56F5-C62E-821F93C2E985}" = ラベル屋さん9
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{97E3AE69-8FB1-496A-8CA0-AE491902DCD7}" = Movie Maker
"{988949CE-DE9A-D187-A010-22B9085FB813}" = CCC Help Swedish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A85092B2-8FB5-5A8C-B27A-69A3D78979D8}" = CCC Help Korean
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}" = tools-solaris
"{AC76BA86-0804-1033-1959-001802114130}" = Adobe Refresh Manager
"{AC76BA86-7AD7-1041-7B44-AB0000000001}" = Adobe Reader XI (11.0.10) - Japanese
"{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}" = tools-winPre2k
"{AF06B8FA-B916-4001-AE51-6645488DEF09}" = Media Go
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B1977E93-5FC0-0BA4-2D5A-D3E69870C7D4}" = CCC Help Chinese Traditional
"{B2611F8A-EFE7-4E88-875D-19F0EFAE87E4}" = Windows Live PIMT Platform
"{BBC9BF50-A35D-B0C2-9117-F3CA2F6BB64A}" = CCC Help Czech
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
"{CDC1AB00-01FF-4FC7-816A-16C67F0923C0}" = Windows Live SOXE
"{ce085a78-074e-4823-8dc1-8a721b94b76d}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
"{D0FD2FF9-1BE9-E729-3878-9A603B5F1529}" = Catalyst Control Center Localization All
"{D102611A-6466-4101-A51D-51069303AC65}" = tools-linux
"{D1893000-EA77-493C-8DDD-E262436E959B}" = Windows Live SOXE Definitions
"{D6D69EE4-00F6-4DCE-B7AF-E90042BDE39B}" = フォト ギャラリー
"{D94F2DE6-55B4-B211-A381-54089BC791A0}" = CCC Help Japanese
"{DD67BE4B-7E62-4215-AFA3-F123A800A389}" = Movie Maker
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{EEFDBD75-0BD9-AC5F-8F61-903C6A19C0ED}" = CCC Help Dutch
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony PC Companion 2.10.245
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F2CBBC39-0AEC-4D60-8DD7-701FD087A6FD}" = Shuriken 2012
"{F3BB7E2D-62E0-4008-8727-588EDC274C25}" = Photo Common
"{F4DCB44D-F072-43A1-B4A5-57619C7B22D2}" = EMET 5.2
"{F59AC46C-10C3-4023-882C-4212A92283B3}_is1" = Lagarith Lossless Codec (1.3.27)
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{FA7EE274-7370-43B7-9A45-A39B17CCCDC5}" = Software Updater
"{FB415F81-DC5E-ED99-D2FE-3DC4D88BCA58}" = CCC Help Turkish
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 17 ActiveX
"Adobe Flash Player NPAPI" = Adobe Flash Player 17 NPAPI
"Adobe Shockwave Player" = Adobe Shockwave Player 12.1
"avast" = Avast Free Antivirus
"AviSynth" = AviSynth 2.5
"com.itec.ngl.NGL" = ラベル屋さん9
"DivX Setup" = DivXセットアップ
"EPSON Scanner" = EPSON Scan
"FormatFactory" = FormatFactory 3.6.0.0
"Hidemaru" = 秀丸エディタ (8.21)
"husen2000" = 付箋紙21
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA プラットフォーム・デバイス・マネージャ
"InstallShield_{3BB91D6B-258C-44E7-B5D1-55031D3C22BD}" = x-アプリ 6.0.01
"InstallShield_{561A6F14-EDFB-43FC-9803-CAD174D08F26}" = Sony Media Library Earth 9.2.00
"InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}" = CyberLink Media Suite 10
"IObitUninstall" = IObit Uninstaller
"MediaNavi.CDLabel15Std" = らくちんCDラベルメーカー15
"Mozilla Firefox 36.0.4 (x86 ja)" = Mozilla Firefox 36.0.4 (x86 ja)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MyEPSON Connect" = MyEPSON Portal
"NextFTP" = NextFTP
"OpenSource Flash Video Splitter" = OpenSource Flash Video Splitter 1.0.0.5
"PDF reDirect" = PDF reDirect (remove only)
"setup_agntype" = AgainTyper
"ST5UNST #1" = Vb5rs3
"ST6UNST #1" = 秀丸パブリッシャー
"Update Engine" = Sony Mobile Update Engine
"VirtualCloneDrive" = VirtualCloneDrive
"VMware_Player" = VMware Player
"Winamp" = Winamp
"WinLiveSuite" = Windows Live Essentials
"Wise Registry Cleaner_is1" = Wise Registry Cleaner 8.31
"Xvid Video Codec 1.3.2" = Xvid Video Codec
"チャクモエ for PC メイドボイス_is1" = チャクモエ for PC メイドボイス
"ミュージックCDデザイナー3" = ミュージックCDデザイナー3

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-3953051745-2568508545-2191147087-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2015/03/25 9:40:01 | Computer Name = PC-ME7 | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: igfxCUIService.exe、バージョン: 6.15.10.3621、タイム スタンプ:
0x5376e21a 障害が発生しているモジュール名: igfxCUIService.exe、バージョン: 6.15.10.3621、タイム スタンプ: 0x5376e21a
例外コード:
0xc0000005 障害オフセット: 0x000000000000ec68 障害が発生しているプロセス ID: 0x554 障害が発生しているアプリケーションの開始時刻:
0x01d067012faff08f 障害が発生しているアプリケーション パス: C:\Windows\system32\igfxCUIService.exe 障害が発生しているモジュール
パス: C:\Windows\system32\igfxCUIService.exe レポート ID: 6eff6d9f-d2f4-11e4-b0c9-005056c00008

Error - 2015/03/25 9:45:50 | Computer Name = PC-ME7 | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: igfxCUIService.exe、バージョン: 6.15.10.3621、タイム スタンプ:
0x5376e21a 障害が発生しているモジュール名: igfxCUIService.exe、バージョン: 6.15.10.3621、タイム スタンプ: 0x5376e21a
例外コード:
0xc0000005 障害オフセット: 0x000000000000ec68 障害が発生しているプロセス ID: 0x53c 障害が発生しているアプリケーションの開始時刻:
0x01d06701fefff60b 障害が発生しているアプリケーション パス: C:\Windows\system32\igfxCUIService.exe 障害が発生しているモジュール
パス: C:\Windows\system32\igfxCUIService.exe レポート ID: 3ede45ac-d2f5-11e4-ad69-005056c00008

Error - 2015/03/25 9:45:58 | Computer Name = PC-ME7 | Source = WinMgmt | ID = 10
Description =

Error - 2015/03/25 9:50:10 | Computer Name = PC-ME7 | Source = WinMgmt | ID = 10
Description =

Error - 2015/03/25 9:52:03 | Computer Name = PC-ME7 | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: igfxCUIService.exe、バージョン: 6.15.10.3621、タイム スタンプ:
0x5376e21a 障害が発生しているモジュール名: igfxCUIService.exe、バージョン: 6.15.10.3621、タイム スタンプ: 0x5376e21a
例外コード:
0xc0000005 障害オフセット: 0x000000000000ec68 障害が発生しているプロセス ID: 0x544 障害が発生しているアプリケーションの開始時刻:
0x01d06702ddcce328 障害が発生しているアプリケーション パス: C:\Windows\system32\igfxCUIService.exe 障害が発生しているモジュール
パス: C:\Windows\system32\igfxCUIService.exe レポート ID: 1dab32c9-d2f6-11e4-9457-005056c00008

Error - 2015/03/25 9:52:12 | Computer Name = PC-ME7 | Source = WinMgmt | ID = 10
Description =

Error - 2015/03/25 10:12:55 | Computer Name = PC-ME7 | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: igfxCUIService.exe、バージョン: 6.15.10.3621、タイム スタンプ:
0x5376e21a 障害が発生しているモジュール名: igfxCUIService.exe、バージョン: 6.15.10.3621、タイム スタンプ: 0x5376e21a
例外コード:
0xc0000005 障害オフセット: 0x000000000000ec68 障害が発生しているプロセス ID: 0x538 障害が発生しているアプリケーションの開始時刻:
0x01d06705c80ced28 障害が発生しているアプリケーション パス: C:\Windows\system32\igfxCUIService.exe 障害が発生しているモジュール
パス: C:\Windows\system32\igfxCUIService.exe レポート ID: 07e1b748-d2f9-11e4-b5f2-005056c00008

Error - 2015/03/25 10:13:04 | Computer Name = PC-ME7 | Source = WinMgmt | ID = 10
Description =

Error - 2015/03/26 9:49:04 | Computer Name = PC-ME7 | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: igfxCUIService.exe、バージョン: 6.15.10.3621、タイム スタンプ:
0x5376e21a 障害が発生しているモジュール名: igfxCUIService.exe、バージョン: 6.15.10.3621、タイム スタンプ: 0x5376e21a
例外コード:
0xc0000005 障害オフセット: 0x000000000000ec68 障害が発生しているプロセス ID: 0x548 障害が発生しているアプリケーションの開始時刻:
0x01d067cb9d2390ce 障害が発生しているアプリケーション パス: C:\Windows\system32\igfxCUIService.exe 障害が発生しているモジュール
パス: C:\Windows\system32\igfxCUIService.exe レポート ID: dd06a330-d3be-11e4-90d3-005056c00008

Error - 2015/03/26 9:49:08 | Computer Name = PC-ME7 | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 2015/03/25 9:48:26 | Computer Name = PC-ME7 | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2015/03/25 9:51:54 | Computer Name = PC-ME7 | Source = volmgr | ID = 262190
Description = クラッシュ ダンプを初期化できませんでした。

Error - 2015/03/25 9:51:54 | Computer Name = PC-ME7 | Source = Application Popup | ID = 1060
Description = このシステムとの互換性がないため、\SystemRoot\SysWow64\Drivers\cdrbsvsd.SYS の読み込みはブロックされています。ソフトウェア
ベンダーに連絡して、互換性があるバージョンのドライバーを入手してください。

Error - 2015/03/25 9:52:02 | Computer Name = PC-ME7 | Source = Service Control Manager | ID = 7023
Description = Intel(R) HD Graphics Control Panel Service サービスは、次のエラーで終了しました: %%-2147467259

Error - 2015/03/25 10:12:46 | Computer Name = PC-ME7 | Source = volmgr | ID = 262190
Description = クラッシュ ダンプを初期化できませんでした。

Error - 2015/03/25 10:12:46 | Computer Name = PC-ME7 | Source = Application Popup | ID = 1060
Description = このシステムとの互換性がないため、\SystemRoot\SysWow64\Drivers\cdrbsvsd.SYS の読み込みはブロックされています。ソフトウェア
ベンダーに連絡して、互換性があるバージョンのドライバーを入手してください。

Error - 2015/03/25 10:12:54 | Computer Name = PC-ME7 | Source = Service Control Manager | ID = 7023
Description = Intel(R) HD Graphics Control Panel Service サービスは、次のエラーで終了しました: %%-2147467259

Error - 2015/03/26 9:48:54 | Computer Name = PC-ME7 | Source = volmgr | ID = 262190
Description = クラッシュ ダンプを初期化できませんでした。

Error - 2015/03/26 9:48:54 | Computer Name = PC-ME7 | Source = Application Popup | ID = 1060
Description = このシステムとの互換性がないため、\SystemRoot\SysWow64\Drivers\cdrbsvsd.SYS の読み込みはブロックされています。ソフトウェア
ベンダーに連絡して、互換性があるバージョンのドライバーを入手してください。

Error - 2015/03/26 9:49:03 | Computer Name = PC-ME7 | Source = Service Control Manager | ID = 7023
Description = Intel(R) HD Graphics Control Panel Service サービスは、次のエラーで終了しました: %%-2147467259


< End of report >
  • pxu10652
  • 2015/03/26 (Thu) 23:22:33
OLTその1
OTL logfile created on: 2015/03/26 23:02:58 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\ME\Desktop\ウィルス対策
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17691)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

31.96 Gb Total Physical Memory | 28.25 Gb Available Physical Memory | 88.38% Memory free
31.96 Gb Paging File | 27.96 Gb Available in Paging File | 87.50% Paging File free
Paging file location(s): [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 223.47 Gb Total Space | 134.86 Gb Free Space | 60.35% Space Free | Partition Type: NTFS
Drive D: | 100.10 Gb Total Space | 73.49 Gb Free Space | 73.42% Space Free | Partition Type: NTFS
Drive E: | 500.39 Gb Total Space | 361.14 Gb Free Space | 72.17% Space Free | Partition Type: NTFS
Drive F: | 2824.31 Gb Total Space | 1146.00 Gb Free Space | 40.58% Space Free | Partition Type: NTFS
Drive K: | 3.93 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive L: | 7.63 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive M: | 4.16 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive N: | 4.02 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive O: | 4.17 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive P: | 4.03 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive T: | 4.24 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive U: | 4.27 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive V: | 7.57 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive Y: | 200.90 Gb Total Space | 87.62 Gb Free Space | 43.62% Space Free | Partition Type: NTFS
Drive Z: | 100.10 Gb Total Space | 50.99 Gb Free Space | 50.94% Space Free | Partition Type: NTFS

Computer Name: PC-ME7 | User Name: ME | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2015/03/26 23:01:31 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\ME\Desktop\ウィルス対策\OTL.exe
PRC - [2015/03/22 18:57:52 | 000,376,944 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2015/03/19 22:38:07 | 005,511,352 | ---- | M] (Avast Software s.r.o.) -- C:\Program Files\AVAST Software\Avast\avastui.exe
PRC - [2015/03/17 22:13:09 | 000,343,336 | ---- | M] (Avast Software s.r.o.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2015/03/14 23:32:12 | 001,893,040 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_134.exe
PRC - [2015/02/19 08:17:55 | 001,088,800 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
PRC - [2015/01/16 18:15:26 | 000,359,128 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnetdhcp.exe
PRC - [2015/01/16 18:15:16 | 000,437,976 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnat.exe
PRC - [2015/01/16 17:12:26 | 000,087,256 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
PRC - [2014/12/19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/07/28 23:31:09 | 000,093,800 | ---- | M] (SecureBrain Corporation) -- C:\Program Files (x86)\SecureBrain\PhishWall\sbpwupdx.exe
PRC - [2014/06/10 12:00:00 | 000,395,600 | ---- | M] (株式会社ジャストシステム) -- C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe
PRC - [2014/01/10 14:26:44 | 001,861,968 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2013/12/18 01:56:20 | 054,253,080 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaConverter.exe
PRC - [2013/12/18 01:56:16 | 001,334,296 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaRenderer.exe
PRC - [2013/12/18 01:56:16 | 000,754,712 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe
PRC - [2013/11/21 08:31:44 | 000,287,592 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2013/11/21 08:31:44 | 000,015,720 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2013/09/13 15:28:58 | 002,387,520 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\epson\MyEPSON Connect\mep.exe
PRC - [2012/10/01 16:17:38 | 000,703,616 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\epson\MyEPSON Connect\mepService.exe
PRC - [2012/08/27 19:25:29 | 000,078,352 | ---- | M] (cyberlink) -- C:\Program Files (x86)\CyberLink\Shared files\brs.exe
PRC - [2012/07/17 14:57:22 | 000,365,376 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2012/07/17 14:57:20 | 000,277,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2012/07/13 15:50:00 | 000,093,296 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2012/06/25 10:57:14 | 000,166,720 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
PRC - [2012/05/21 01:26:26 | 000,291,648 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2011/07/12 17:14:26 | 000,331,776 | R--- | M] (VIA Technologies, Inc.) -- C:\VIA_XHCI\usb3Monitor.exe
PRC - [2007/02/22 14:18:20 | 000,061,440 | ---- | M] () -- C:\Windows\SysWOW64\mei006h.exe
PRC - [2006/12/28 21:18:16 | 000,122,512 | ---- | M] (B.H.A Corporation) -- C:\Windows\SysWOW64\bgsvcgen.exe
PRC - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2015/03/17 22:13:10 | 040,540,672 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2015/03/17 22:13:09 | 001,359,872 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libGLESv2.dll
MOD - [2015/03/17 22:13:09 | 000,212,992 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libEGL.dll
MOD - [2015/03/17 22:13:09 | 000,104,400 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\log.dll
MOD - [2015/03/17 22:13:09 | 000,081,728 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
MOD - [2015/03/14 23:32:12 | 016,858,288 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll
MOD - [2015/01/17 19:43:28 | 010,069,504 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\d18e2115a3270f89663fce831547f534\System.ni.dll
MOD - [2015/01/17 19:42:44 | 000,118,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\93a0883923e78cc3e80b7ac4a9768c60\SMDiagnostics.ni.dll
MOD - [2015/01/17 19:42:29 | 019,734,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\f9d8efe5e01d08740774a12f20a3e640\System.ServiceModel.ni.dll
MOD - [2015/01/17 19:39:49 | 003,049,472 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\201032e5afa8609da580589102a67857\System.IdentityModel.ni.dll
MOD - [2015/01/17 19:39:41 | 001,123,328 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servf73e6522#\edc5c7073370a2c2049f96761c1e3bfb\System.ServiceModel.Web.ni.dll
MOD - [2015/01/15 23:00:47 | 012,895,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\d8223c30928e02bc7ed5b8b81effa7b5\System.Windows.Forms.ni.dll
MOD - [2015/01/15 23:00:44 | 002,855,424 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\187177229c00aec6dec613ea4b9ff209\System.Runtime.Serialization.ni.dll
MOD - [2015/01/15 23:00:43 | 000,790,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\14cc73701aac461eb89d6473a88fcd56\System.ServiceModel.Internals.ni.dll
MOD - [2015/01/15 23:00:38 | 001,642,496 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\dd2f9ea99ac0f984b9dc430824638c9f\System.Drawing.ni.dll
MOD - [2015/01/15 23:00:22 | 001,873,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\1196cc375887ce75f134047505fe19bf\System.Xaml.ni.dll
MOD - [2015/01/15 23:00:18 | 007,793,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\3d6ee4ffbd9a86ac1e7b01800b6fe9c7\System.Xml.ni.dll
MOD - [2015/01/15 23:00:16 | 000,972,288 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\5a977e1f055b4f8f41da5d9142a1913c\System.Configuration.ni.dll
MOD - [2015/01/15 23:00:15 | 007,002,624 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\23d1162d1943c1b1d6c4fd7c6d8512d4\System.Core.ni.dll
MOD - [2015/01/15 23:00:09 | 017,207,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\d1265d6159ea876f9d63ea4c1361b587\mscorlib.ni.dll
MOD - [2014/01/10 14:28:18 | 000,100,688 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2014/01/10 14:26:44 | 001,861,968 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2013/10/18 16:14:58 | 000,036,864 | ---- | M] () -- C:\Program Files (x86)\AgnType\AT_dll.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2015/03/17 22:13:09 | 000,343,336 | ---- | M] (Avast Software s.r.o.) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:[b]64bit:[/b] - [2015/03/17 22:13:07 | 004,030,800 | ---- | M] (Avast Software) [On_Demand | Running] -- C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe -- (AvastVBoxSvc)
SRV:[b]64bit:[/b] - [2015/02/20 11:35:05 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2015/02/10 03:55:42 | 002,714,800 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe -- (ClickToRunSvc)
SRV:[b]64bit:[/b] - [2014/11/21 11:12:40 | 000,244,736 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:[b]64bit:[/b] - [2014/05/21 00:33:44 | 000,314,696 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Windows\SysNative\igfxCUIService.exe -- (igfxCUIService1.0.0.0)
SRV:[b]64bit:[/b] - [2013/11/21 08:31:44 | 000,015,720 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV:[b]64bit:[/b] - [2013/05/27 14:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2013/04/29 21:29:04 | 002,183,416 | ---- | M] (UltraVNC) [Auto | Running] -- C:\Program Files\uvnc bvba\UltraVNC\winvnc.exe -- (uvnc_service)
SRV:[b]64bit:[/b] - [2012/11/02 17:50:36 | 000,101,704 | ---- | M] (KING JIM CO.,LTD.) [Auto | Running] -- C:\Windows\SysNative\TPOUSVR.exe -- (TepOuService)
SRV:[b]64bit:[/b] - [2012/05/17 00:00:00 | 000,144,560 | ---- | M] (Seiko Epson Corporation) [Auto | Running] -- C:\Windows\SysNative\escsvc64.exe -- (EpsonScanSvc)
SRV:[b]64bit:[/b] - [2012/04/20 14:16:12 | 000,635,104 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2009/07/14 10:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2015/03/22 18:57:52 | 000,148,080 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2015/03/14 23:32:12 | 000,268,464 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015/03/11 16:43:04 | 000,022,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\EMET 5.2\EMET_Service.exe -- (EMET_Service)
SRV - [2015/02/19 08:17:55 | 002,635,552 | ---- | M] (IObit) [Auto | Stopped] -- C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe -- (LiveUpdateSvc)
SRV - [2015/02/05 17:25:38 | 000,131,608 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe -- (SonicStage Back-End Service2)
SRV - [2015/01/27 10:12:02 | 000,167,208 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2015/01/16 18:15:26 | 000,359,128 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2015/01/16 18:15:16 | 000,437,976 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
SRV - [2015/01/16 17:12:26 | 000,087,256 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe -- (VMAuthdService)
SRV - [2014/12/19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/08/21 08:07:12 | 000,906,432 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe -- (VMUSBArbService)
SRV - [2014/07/28 23:31:09 | 000,093,800 | ---- | M] (SecureBrain Corporation) [Auto | Running] -- C:\Program Files (x86)\SecureBrain\PhishWall\sbpwupdx.exe -- (SecureBrain PhishWall Update)
SRV - [2014/05/21 00:33:48 | 000,278,344 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2014/04/11 23:08:08 | 000,103,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2014/03/21 07:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2014/02/28 11:32:36 | 000,174,368 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe -- (iumsvc)
SRV - [2013/12/18 01:56:16 | 000,754,712 | ---- | M] (Google Inc.) [Auto | Running] -- C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe -- (GoogleIMEJaCacheService)
SRV - [2013/02/04 17:43:22 | 000,155,824 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion)
SRV - [2012/10/01 16:17:38 | 000,703,616 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files (x86)\epson\MyEPSON Connect\mepService.exe -- (MyEPSON Connect Service)
SRV - [2012/08/27 18:25:30 | 000,243,728 | ---- | M] (CyberLink) [Auto | Stopped] -- C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe -- (CLKMSVC10_38F51D56)
SRV - [2012/07/17 14:57:22 | 000,365,376 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2012/07/17 14:57:20 | 000,277,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2012/06/25 10:57:14 | 000,166,720 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2012/04/24 14:37:56 | 000,169,752 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe -- (ICCS)
SRV - [2007/02/22 14:18:20 | 000,061,440 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\mei006h.exe -- (Mei006h)
SRV - [2006/12/28 21:18:16 | 000,122,512 | ---- | M] (B.H.A Corporation) [Auto | Running] -- C:\Windows\SysWOW64\bgsvcgen.exe -- (bgsvcgen)
SRV - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2015/03/17 22:13:10 | 000,441,728 | ---- | M] (Avast Software s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:[b]64bit:[/b] - [2015/03/17 22:13:10 | 000,268,640 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:[b]64bit:[/b] - [2015/03/17 22:13:10 | 000,136,752 | ---- | M] (Avast Software s.r.o.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:[b]64bit:[/b] - [2015/03/17 22:13:10 | 000,093,528 | ---- | M] (Avast Software s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:[b]64bit:[/b] - [2015/03/17 22:13:10 | 000,088,408 | ---- | M] (Avast Software s.r.o.) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:[b]64bit:[/b] - [2015/03/17 22:13:10 | 000,065,736 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:[b]64bit:[/b] - [2015/03/17 22:13:10 | 000,029,168 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:[b]64bit:[/b] - [2015/03/17 22:13:08 | 001,047,320 | ---- | M] (Avast Software s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:[b]64bit:[/b] - [2015/03/17 22:13:07 | 000,273,824 | ---- | M] (Avast Software) [Kernel | Auto | Running] -- C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys -- (VBoxAswDrv)
DRV:[b]64bit:[/b] - [2015/01/16 18:15:38 | 000,064,728 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)
DRV:[b]64bit:[/b] - [2015/01/16 18:15:20 | 000,031,448 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV:[b]64bit:[/b] - [2015/01/16 18:14:56 | 000,046,160 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV:[b]64bit:[/b] - [2015/01/16 18:14:56 | 000,020,560 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV:[b]64bit:[/b] - [2015/01/16 18:14:48 | 000,033,496 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VMkbd.sys -- (vmkbd)
DRV:[b]64bit:[/b] - [2014/11/21 11:40:00 | 018,959,360 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:[b]64bit:[/b] - [2014/11/21 11:08:54 | 000,589,312 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:[b]64bit:[/b] - [2014/08/21 08:07:02 | 000,054,976 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
DRV:[b]64bit:[/b] - [2014/05/21 00:33:36 | 003,791,872 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2014/03/07 09:26:44 | 000,450,520 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2014/02/15 01:32:55 | 000,027,760 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggsemc.sys -- (ggsemc)
DRV:[b]64bit:[/b] - [2014/02/15 01:32:55 | 000,014,448 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggflt.sys -- (ggflt)
DRV:[b]64bit:[/b] - [2013/11/21 08:31:28 | 000,632,168 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:[b]64bit:[/b] - [2013/11/21 08:31:28 | 000,028,008 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorF.sys -- (iaStorF)
DRV:[b]64bit:[/b] - [2013/10/08 18:21:10 | 000,073,296 | ---- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vsock.sys -- (vsock)
DRV:[b]64bit:[/b] - [2013/10/08 18:21:06 | 000,085,584 | ---- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)
DRV:[b]64bit:[/b] - [2013/10/02 11:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2012/10/23 12:08:00 | 000,304,256 | ---- | M] (Roland Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RDWM1117.sys -- (RDID1117)
DRV:[b]64bit:[/b] - [2012/08/23 23:12:16 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2012/08/23 23:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2012/08/23 23:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2012/08/15 15:24:54 | 000,056,336 | ---- | M] (Corel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:[b]64bit:[/b] - [2012/07/19 18:14:28 | 000,110,744 | ---- | M] (Qualcomm Atheros Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:[b]64bit:[/b] - [2012/07/02 15:16:02 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:[b]64bit:[/b] - [2012/05/21 01:25:32 | 000,789,824 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:[b]64bit:[/b] - [2012/05/21 01:25:32 | 000,357,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:[b]64bit:[/b] - [2012/05/21 01:25:32 | 000,019,264 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:[b]64bit:[/b] - [2012/03/01 15:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2012/01/20 13:39:16 | 000,205,312 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ViaHub3.sys -- (VUSB3HUB)
DRV:[b]64bit:[/b] - [2012/01/20 13:39:04 | 000,254,464 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xhcdrv.sys -- (xhcdrv)
DRV:[b]64bit:[/b] - [2011/03/11 15:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011/03/11 15:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2011/01/16 01:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:[b]64bit:[/b] - [2010/12/17 07:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:[b]64bit:[/b] - [2010/11/21 12:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:[b]64bit:[/b] - [2010/11/21 12:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:[b]64bit:[/b] - [2010/11/21 12:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2010/11/21 12:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2009/07/14 10:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/14 10:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/14 10:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/11 05:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/11 05:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2011/06/02 10:08:34 | 000,017,864 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys -- (cpudrv64)
DRV - [2009/07/14 10:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2000/08/22 21:06:28 | 000,007,870 | ---- | M] (B.H.A Co.,Ltd.) [Kernel | System | Stopped] -- C:\Windows\SysWow64\drivers\cdrbsvsd.sys -- (cdrbsvsd)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = file:///D:/USER/HP_SEL/index.htm
IE - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://jp.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = ja
IE - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4C 30 BA 2C 9B 5D CE 01 [binary data]
IE - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\..\SearchScopes,DefaultScope = {B5F4E20C-0E4A-4654-979B-C1F4E085E5C5}
IE - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\..\SearchScopes\{B5F4E20C-0E4A-4654-979B-C1F4E085E5C5}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\..\SearchScopes\{D7822133-4A13-4BA9-BE47-F900A746B4C7}: "URL" = http://www.amazon.co.jp/s/ref=azs_osd_ieajp?ie=UTF-8&tag=amznsearch.jp.ms-22&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
IE - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\..\SearchScopes\F8649C1F03A846A78AE73B0CB85DBDE3: "URL" = http://www.google.co.jp/search?hl=ja&q={searchTerms}&lr=lang_ja
IE - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.countryCode: "JP"
FF - prefs.js..browser.search.highlightCount: 0
FF - prefs.js..browser.search.isUS: false
FF - prefs.js..browser.search.region: "JP"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "file:///D:/USER/HP_SEL/INDEX.HTM|https://dimora.jp/dc/pc/autoLogin.do|http://www.nifty.com/|https://www.facebook.com/Producer.of.LMO#!/|http://oshiete.watch.impress.co.jp/|http://kaden.watch.impress.co.jp/|http://club.panasonic.jp/campaignlist/index.html|https://www.discas.net/netdvd/wishlist.do?pT=0|https://kanri.m-cloud.jp/|http://other-place.bbs.fc2.com/"
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:10.2.0.187
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:36.0.4
FF - user.js - File not found

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Web Player Plug-In,version=1.0.0: C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.40.2: C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.40.2: C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2015/03/17 22:13:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 36.0.4\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 36.0.4\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2015/03/22 18:57:51 | 000,000,000 | ---D | M]

[2014/02/09 11:37:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ME\AppData\Roaming\mozilla\Extensions
[2015/03/14 23:31:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ME\AppData\Roaming\mozilla\Firefox\Profiles\fmug7izv.default\extensions
[2015/03/22 18:57:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2015/03/22 18:57:52 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2015/03/17 22:13:10 | 000,000,000 | ---D | M] ("Avast Online Security") -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF

O1 HOSTS File: ([2015/03/18 23:05:15 | 000,450,713 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15469 more lines...
O2:[b]64bit:[/b] - BHO: (ExplorerWnd Helper) - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
O2:[b]64bit:[/b] - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\ochelper.dll (Microsoft Corporation)
O2:[b]64bit:[/b] - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (Avast Software s.r.o.)
O2:[b]64bit:[/b] - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\urlredir.dll (Microsoft Corporation)
O2:[b]64bit:[/b] - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\office15\grooveex.dll (Microsoft Corporation)
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (PhishWall) - {8CA7E745-EF75-4E7B-BB86-8065C0CE29CA} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll (SecureBrain Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (Avast Software s.r.o.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\urlredir.dll (Microsoft Corporation)
O2 - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\grooveex.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll (Oracle Corporation)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (PhishWall) - {BB62FFF4-41CB-4AFC-BB8C-2A4D4B42BBDC} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll (SecureBrain Corporation)
O3 - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\..\Toolbar\WebBrowser: (no name) - {AEF44653-C059-42CB-A5B7-41C640DA4A67} - No CLSID value found.
O4:[b]64bit:[/b] - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [TepOuService] C:\Windows\SysNative\TPOUSVR.EXE (KING JIM CO.,LTD.)
O4:[b]64bit:[/b] - HKLM..\Run: [VIAxHCUtl] C:\VIA_XHCI\usb3Monitor.exe (VIA Technologies, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o.)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Google Japanese Input Prelauncher] C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe (Google Inc.)
O4 - HKLM..\Run: [JustOnlineUpdate] C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe (株式会社ジャストシステム)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\ME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AgainTyper.lnk = C:\Program Files (x86)\AgnType\AgnType.exe ()
O4 - Startup: C:\Users\ME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HitoKoe10.lnk = D:\W32_TOOL\GO_START\HitoKoe10.exe ()
O4 - Startup: C:\Users\ME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IPMSG for Win32.lnk = File not found
O4 - Startup: C:\Users\ME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KYOU.lnk = D:\W32_TOOL\KYOU.EXE ()
O4 - Startup: C:\Users\ME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Shuriken着信監視.lnk = C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe (株式会社ジャストシステム)
O4 - Startup: C:\Users\ME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TinyMon.lnk = D:\W32_TOOL\TinyMon.exe ()
O4 - Startup: C:\Users\ME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\付箋紙21.lnk = C:\Program Files (x86)\husen2K\Husen2K.exe (ROTO)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O7 - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O7 - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8:[b]64bit:[/b] - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O8:[b]64bit:[/b] - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\ochelper.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\ochelper.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : SunのJavaコンソール - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\onbttnie.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\onbttnie.dll (Microsoft Corporation)
O9 - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\onbttnielinkednotes.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\..Trusted Domains: canon.jp ([gdmp] http in Trusted sites)
O15 - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\..Trusted Domains: sharepoint.com ([produceroflmo] https in Trusted sites)
O15 - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\..Trusted Domains: sharepoint.com ([produceroflmo-my] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {AF4D6906-EB10-48C1-A0CF-9328196158AE} http://gdmp.canon.jp/gundam/activex/PrintControl.ocx (PrintControl)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com/bin/srldetect_intel_4.5.22.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D89B3FF-5B44-4C7F-8D7F-9EC2661F9409}: NameServer = 192.168.1.1
O18:[b]64bit:[/b] - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\msosb.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - File not found
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{26a8b93e-5b8f-11e4-a67d-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{26a8b93e-5b8f-11e4-a67d-005056c00008}\Shell\AutoRun\command - "" = G:\startme.exe
O33 - MountPoints2\{39e19e87-9595-11e3-93c4-902b34d503ff}\Shell - "" = AutoRun
O33 - MountPoints2\{39e19e87-9595-11e3-93c4-902b34d503ff}\Shell\AutoRun\command - "" = G:\Startme.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point
  • pxu10652
  • 2015/03/26 (Thu) 23:24:52
OLTその2
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2015/03/25 22:39:04 | 000,000,000 | ---D | C] -- C:\Users\ME\AppData\Local\Skype
[2015/03/25 22:39:03 | 000,000,000 | ---D | C] -- C:\Users\ME\AppData\Roaming\Skype
[2015/03/25 22:38:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2015/03/25 21:46:12 | 001,107,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2015/03/25 21:46:12 | 000,943,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appraiser.dll
[2015/03/25 21:46:12 | 000,760,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\invagent.dll
[2015/03/25 21:46:12 | 000,677,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll
[2015/03/25 21:46:12 | 000,414,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\devinv.dll
[2015/03/25 21:46:12 | 000,227,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2015/03/25 21:46:12 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepic.dll
[2015/03/25 21:46:12 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\acmigration.dll
[2015/03/23 22:08:28 | 000,000,000 | ---D | C] -- C:\Users\ME\AppData\Roaming\Malwarebytes
[2015/03/23 22:07:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2015/03/22 23:27:02 | 000,000,000 | ---D | C] -- C:\Users\ME\Desktop\ウィルス対策
[2015/03/22 22:38:15 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2015/03/22 22:37:04 | 000,000,000 | ---D | C] -- C:\Users\ME\Desktop\backups
[2015/03/22 22:33:03 | 000,000,000 | ---D | C] -- D:\USER\DVDFab9
[2015/03/22 22:31:32 | 000,000,000 | ---D | C] -- C:\Users\ME\AppData\Roaming\Geek Uninstaller
[2015/03/22 22:26:44 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2015/03/22 22:04:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enhanced Mitigation Experience Toolkit
[2015/03/22 22:04:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EMET 5.2
[2015/03/22 18:57:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2015/03/21 23:39:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2015/03/21 23:39:11 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2015/03/17 22:13:10 | 000,364,472 | ---- | C] (Avast Software s.r.o.) -- C:\Windows\SysNative\aswBoot.exe
[2015/03/17 22:13:09 | 000,043,112 | ---- | C] (Avast Software s.r.o.) -- C:\Windows\avastSS.scr
[2015/03/15 17:36:03 | 000,000,000 | ---D | C] -- D:\USER\Blue Cat Audio
[2015/03/15 17:35:55 | 000,000,000 | ---D | C] -- D:\USER\Toontrack
[2015/03/14 23:42:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2015/03/11 22:16:33 | 000,372,224 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
[2015/03/11 22:16:33 | 000,299,008 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2015/03/11 22:16:33 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
[2015/03/11 22:16:33 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[2015/03/11 22:16:33 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll
[2015/03/11 22:16:33 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lpk.dll
[2015/03/11 22:16:33 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll
[2015/03/11 22:16:33 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dciman32.dll
[2015/03/11 22:16:31 | 011,411,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2015/03/11 22:16:31 | 005,554,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2015/03/11 22:16:31 | 003,209,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2015/03/11 22:16:30 | 003,973,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2015/03/11 22:16:30 | 003,917,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2015/03/11 22:16:30 | 001,480,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2015/03/11 22:16:29 | 004,121,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2015/03/11 22:16:29 | 000,616,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2015/03/11 22:16:28 | 014,632,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2015/03/11 22:16:28 | 001,574,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2015/03/11 22:16:28 | 001,329,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2015/03/11 22:16:28 | 001,202,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmv2clt.dll
[2015/03/11 22:16:28 | 000,988,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmv2clt.dll
[2015/03/11 22:16:28 | 000,693,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2015/03/11 22:16:27 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptui.dll
[2015/03/11 22:16:27 | 001,005,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptui.dll
[2015/03/11 22:16:27 | 000,842,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\blackbox.dll
[2015/03/11 22:16:27 | 000,782,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmsdk.dll
[2015/03/11 22:16:27 | 000,744,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\blackbox.dll
[2015/03/11 22:16:27 | 000,641,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscp.dll
[2015/03/11 22:16:27 | 000,619,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2015/03/11 22:16:27 | 000,617,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmsdk.dll
[2015/03/11 22:16:27 | 000,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2015/03/11 22:16:27 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2015/03/11 22:16:27 | 000,497,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmmgrtn.dll
[2015/03/11 22:16:27 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2015/03/11 22:16:27 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2015/03/11 22:16:27 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2015/03/11 22:16:26 | 000,631,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\evr.dll
[2015/03/11 22:16:26 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscp.dll
[2015/03/11 22:16:26 | 000,500,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AUDIOKSE.dll
[2015/03/11 22:16:26 | 000,489,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\evr.dll
[2015/03/11 22:16:26 | 000,432,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfplat.dll
[2015/03/11 22:16:26 | 000,406,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmmgrtn.dll
[2015/03/11 22:16:26 | 000,371,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2015/03/11 22:16:26 | 000,354,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfplat.dll
[2015/03/11 22:16:26 | 000,325,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msnetobj.dll
[2015/03/11 22:16:26 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2015/03/11 22:16:26 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\audiodg.exe
[2015/03/11 22:16:25 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AUDIOKSE.dll
[2015/03/11 22:16:25 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll
[2015/03/11 22:16:25 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDump.dll
[2015/03/11 22:16:25 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msnetobj.dll
[2015/03/11 22:16:25 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2015/03/11 22:16:25 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidpolicyconverter.exe
[2015/03/11 22:16:25 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2015/03/11 22:16:25 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll
[2015/03/11 22:16:25 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptsp.dll
[2015/03/11 22:16:25 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setbcdlocale.dll
[2015/03/11 22:16:25 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidapi.dll
[2015/03/11 22:16:25 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rrinstaller.exe
[2015/03/11 22:16:25 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\appidapi.dll
[2015/03/11 22:16:25 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll
[2015/03/11 22:16:25 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rrinstaller.exe
[2015/03/11 22:16:25 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2015/03/11 22:16:25 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pcadm.dll
[2015/03/11 22:16:25 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfpmp.exe
[2015/03/11 22:16:25 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfpmp.exe
[2015/03/11 22:16:25 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pcawrk.exe
[2015/03/11 22:16:25 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmmsp.dll
[2015/03/11 22:16:25 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pcalua.exe
[2015/03/11 22:16:24 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2015/03/11 22:16:24 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidcertstorecheck.exe
[2015/03/11 22:16:24 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwmp.dll
[2015/03/11 22:16:24 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pcaevts.dll
[2015/03/11 22:16:24 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwmp.dll
[2015/03/11 22:16:24 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll
[2015/03/11 22:16:24 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apisetschema.dll
[2015/03/11 22:16:24 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdxm.ocx
[2015/03/11 22:16:24 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxmasf.dll
[2015/03/11 22:16:24 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdxm.ocx
[2015/03/11 22:16:24 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxmasf.dll
[2015/03/11 22:16:23 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2015/03/11 22:16:23 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mferror.dll
[2015/03/11 22:16:23 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mferror.dll
[2015/03/11 22:16:20 | 003,179,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll
[2015/03/11 22:16:20 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpudd.dll
[2015/03/11 22:16:20 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2015/03/11 22:16:15 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ubpm.dll
[2015/03/11 22:16:15 | 000,171,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ubpm.dll
[2015/03/11 22:16:12 | 001,461,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2015/03/11 22:16:12 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2015/03/11 22:16:12 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2015/03/11 22:16:12 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\auditpol.exe
[2015/03/11 22:16:12 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\auditpol.exe
[2015/03/11 22:16:12 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2015/03/11 22:16:11 | 000,686,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adtschema.dll
[2015/03/11 22:16:11 | 000,686,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adtschema.dll
[2015/03/11 22:16:11 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msaudite.dll
[2015/03/11 22:16:11 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msaudite.dll
[2015/03/11 22:16:11 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msobjs.dll
[2015/03/11 22:16:11 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msobjs.dll
[2015/03/11 22:16:11 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2015/03/11 22:16:10 | 001,067,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msctf.dll
[2015/03/11 22:16:09 | 001,424,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll
[2015/03/11 22:16:08 | 000,718,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2015/03/11 22:16:08 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2015/03/11 22:16:08 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2015/03/11 22:16:08 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2015/03/11 22:16:08 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2015/03/11 22:16:08 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2015/03/11 22:16:08 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2015/03/11 22:16:08 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2015/03/11 22:16:08 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2015/03/11 22:16:08 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2015/03/11 22:16:07 | 002,052,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2015/03/11 22:16:07 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2015/03/11 22:16:07 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2015/03/11 22:16:06 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2015/03/11 22:16:06 | 000,801,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2015/03/11 22:16:06 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2015/03/11 22:16:06 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2015/03/11 22:16:06 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2015/03/11 22:16:06 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2015/03/11 22:16:06 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2015/03/11 22:16:06 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2015/03/11 22:16:05 | 002,125,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2015/03/11 22:16:05 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2015/03/11 22:16:05 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2015/03/11 22:16:04 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2015/03/11 22:16:04 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2015/03/11 22:16:04 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2015/03/11 22:16:04 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2015/03/11 22:16:04 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2015/03/11 22:16:03 | 006,035,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2015/03/11 22:16:03 | 001,359,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2015/03/11 22:16:03 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2015/03/11 22:16:03 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2015/03/11 22:16:03 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2015/03/11 22:16:03 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2015/03/11 22:16:02 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll
[2015/03/11 22:16:02 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll
[2015/03/08 22:51:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SignalNowExpress
[2015/02/27 22:05:11 | 000,000,000 | ---D | C] -- C:\Users\ME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
[2014/10/25 01:15:27 | 028,474,512 | ---- | C] (Sony Mobile Communications ) -- C:\Users\ME\AppData\Local\pcc.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2015/03/26 23:01:43 | 000,026,960 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015/03/26 23:01:43 | 000,026,960 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015/03/26 22:54:31 | 001,324,866 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2015/03/26 22:54:31 | 000,658,014 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2015/03/26 22:54:31 | 000,414,922 | ---- | M] () -- C:\Windows\SysNative\perfh011.dat
[2015/03/26 22:54:31 | 000,123,992 | ---- | M] () -- C:\Windows\SysNative\perfc011.dat
[2015/03/26 22:54:31 | 000,123,910 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2015/03/26 22:49:04 | 000,000,686 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/03/26 22:48:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015/03/25 22:41:00 | 000,000,911 | ---- | M] () -- C:\Windows\tasks\EPSON EP-806A Series Update {06D96841-E0D2-4E1C-AB1C-7A5B5087D513}.job
[2015/03/25 22:39:00 | 000,000,626 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015/03/25 22:32:21 | 000,000,690 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/03/25 22:21:01 | 000,000,047 | ---- | M] () -- C:\Windows\MCDDUserPaperInfo.ini
[2015/03/22 18:44:26 | 000,000,085 | ---- | M] () -- C:\Windows\wininit.ini
[2015/03/18 23:05:15 | 000,450,713 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2015/03/17 23:14:18 | 000,002,458 | ---- | M] () -- C:\Users\ME\Desktop\INDEX.lnk
[2015/03/17 22:30:00 | 000,000,460 | ---- | M] () -- C:\Windows\tasks\Wise Registry Cleaner Schedule Task.job
[2015/03/17 22:13:10 | 000,441,728 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswSP.sys
[2015/03/17 22:13:10 | 000,364,472 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\SysNative\aswBoot.exe
[2015/03/17 22:13:10 | 000,268,640 | ---- | M] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2015/03/17 22:13:10 | 000,136,752 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswStm.sys
[2015/03/17 22:13:10 | 000,093,528 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2015/03/17 22:13:10 | 000,088,408 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2015/03/17 22:13:10 | 000,065,736 | ---- | M] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2015/03/17 22:13:10 | 000,029,168 | ---- | M] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2015/03/17 22:13:09 | 000,043,112 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\avastSS.scr
[2015/03/17 22:13:08 | 001,047,320 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2015/03/14 23:41:57 | 000,098,216 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2015/03/14 23:32:12 | 000,778,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2015/03/14 23:32:12 | 000,142,512 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2015/03/11 23:29:18 | 000,941,152 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2015/03/11 13:06:14 | 000,677,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll
[2015/03/11 13:06:05 | 000,760,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\invagent.dll
[2015/03/11 13:06:02 | 000,414,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\devinv.dll
[2015/03/11 13:06:00 | 000,943,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\appraiser.dll
[2015/03/11 13:05:59 | 000,227,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2015/03/11 13:05:59 | 000,192,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aepic.dll
[2015/03/11 13:05:59 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\acmigration.dll
[2015/03/11 13:02:07 | 001,107,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2015/03/08 22:51:50 | 000,002,207 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SignalNowExpress.lnk
[2015/03/06 14:42:35 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2015/03/06 14:42:35 | 000,029,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2015/03/06 14:42:33 | 000,028,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2015/03/06 14:42:29 | 000,309,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2015/03/06 14:42:27 | 001,461,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2015/03/06 14:41:31 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\auditpol.exe
[2015/03/06 14:39:16 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msobjs.dll
[2015/03/06 14:38:57 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msaudite.dll
[2015/03/06 14:36:56 | 000,686,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\adtschema.dll
[2015/03/06 14:09:31 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\auditpol.exe
[2015/03/06 14:07:50 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msobjs.dll
[2015/03/06 14:07:43 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msaudite.dll
[2015/03/06 14:06:20 | 000,686,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\adtschema.dll
[2015/03/05 23:02:30 | 000,450,713 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20150318-230515.backup
[2015/02/27 22:05:11 | 000,001,206 | ---- | M] () -- C:\Users\ME\Desktop\Format Factory.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2015/03/22 18:44:24 | 000,000,085 | ---- | C] () -- C:\Windows\wininit.ini
[2015/03/08 22:51:50 | 000,002,207 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SignalNowExpress.lnk
[2014/11/20 21:35:00 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2014/11/08 22:20:36 | 000,005,120 | ---- | C] () -- C:\Users\ME\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/10/16 10:25:59 | 000,217,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2014/09/21 18:14:06 | 000,645,632 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2014/09/21 18:14:06 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2014/09/21 18:14:03 | 000,715,038 | ---- | C] () -- C:\Windows\unins000.exe
[2014/09/21 18:14:03 | 000,001,985 | ---- | C] () -- C:\Windows\unins000.dat
[2014/08/10 23:05:52 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2014/05/21 00:33:38 | 000,348,088 | ---- | C] () -- C:\Windows\SysWow64\igdmd32.dll
[2014/05/21 00:33:32 | 000,183,808 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2014/05/21 00:33:32 | 000,142,848 | ---- | C] () -- C:\Windows\SysWow64\igdail32.dll
[2014/04/18 11:22:56 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2014/04/18 11:22:56 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2014/04/18 10:25:52 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2014/04/18 10:25:50 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2014/01/16 23:10:47 | 000,000,000 | ---- | C] () -- C:\Windows\EEventManager.INI
[2013/10/30 23:03:04 | 000,000,177 | ---- | C] () -- C:\Windows\JSINSLOG.INI
[2013/10/30 22:29:18 | 000,000,926 | ---- | C] () -- C:\Windows\JSSETUP.INI
[2013/08/18 11:13:05 | 000,000,047 | ---- | C] () -- C:\Windows\MCDDUserPaperInfo.ini
[2013/06/10 22:53:46 | 000,007,608 | ---- | C] () -- C:\Users\ME\AppData\Local\Resmon.ResmonCfg
[2013/05/31 14:35:43 | 000,061,440 | ---- | C] () -- C:\Windows\SysWow64\mei006h.exe
[2013/05/31 00:44:46 | 001,303,714 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/05/23 22:17:28 | 000,640,512 | ---- | C] () -- C:\Windows\SysWow64\7-zip32.dll
[2013/05/23 22:17:28 | 000,487,424 | ---- | C] ( ) -- C:\Windows\SysWow64\tar32.dll
[2013/05/23 22:17:28 | 000,351,232 | ---- | C] () -- C:\Windows\SysWow64\UNLHA32.DLL
[2013/05/23 22:17:28 | 000,090,624 | ---- | C] () -- C:\Windows\SysWow64\ISH32.DLL
[2013/05/23 22:17:28 | 000,082,432 | ---- | C] () -- C:\Windows\SysWow64\AISH32.DLL
[2013/05/23 22:17:28 | 000,068,096 | ---- | C] () -- C:\Windows\SysWow64\Aishmv32.dll
[2013/05/23 22:17:28 | 000,040,960 | ---- | C] () -- C:\Windows\SysWow64\yzdec.exe

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009/07/14 13:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015/02/13 14:22:33 | 014,177,280 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015/02/13 14:26:18 | 012,875,264 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 10:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 12:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 10:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC]< %windir%\tasks\*.job >[/color]
[2015/03/25 22:39:00 | 000,000,626 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015/03/25 22:41:00 | 000,000,911 | ---- | M] () -- C:\Windows\tasks\EPSON EP-806A Series Update {06D96841-E0D2-4E1C-AB1C-7A5B5087D513}.job
[2015/03/26 22:49:04 | 000,000,686 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/03/25 22:32:21 | 000,000,690 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/03/17 22:30:00 | 000,000,460 | ---- | M] () -- C:\Windows\tasks\Wise Registry Cleaner Schedule Task.job

[color=#E56717]========== Drive Information ==========[/color]

Physical Drives
---------------

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: SCSI
Media Type: Fixed hard disk media
Model: INTEL SSDSC2CT240A4 SCSI Disk Device
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 - Fixed hard disk media
Interface type: SCSI
Media Type: Fixed hard disk media
Model: Intel Raid 1 Volume SCSI Disk Device
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 - Fixed hard disk media
Interface type: SCSI
Media Type: Fixed hard disk media
Model: Intel Raid 1 Volume SCSI Disk Device
Partitions: 4
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: Generic STORAGE DEVICE USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
---------------

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 223.00GB
Starting Offset: 105906176
Hidden sectors: 0


DeviceID: Disk #1, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #1, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 201.00GB
Starting Offset: 105906176
Hidden sectors: 0


DeviceID: Disk #2, Partition #0
PartitionType: GPT: Basic Data
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 100.00GB
Starting Offset: 135266304
Hidden sectors: 0


DeviceID: Disk #2, Partition #1
PartitionType: GPT: Basic Data
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 100.00GB
Starting Offset: 107614306304
Hidden sectors: 0


DeviceID: Disk #2, Partition #2
PartitionType: GPT: Basic Data
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 500.00GB
Starting Offset: 215093346304
Hidden sectors: 0


DeviceID: Disk #2, Partition #3
PartitionType: GPT: Basic Data
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 2,824.00GB
Starting Offset: 752383688704
Hidden sectors: 0


[color=#E56717]========== Base Services ==========[/color]
SRV:[b]64bit:[/b] - [2009/07/14 10:40:01 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc)
SRV:[b]64bit:[/b] - [2013/02/27 14:47:10 | 000,070,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:[b]64bit:[/b] - [2009/07/14 10:38:55 | 000,079,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:51 | 000,849,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:00 | 000,705,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:[b]64bit:[/b] - [2015/03/06 14:41:46 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (KeyIso)
SRV:[b]64bit:[/b] - [2009/07/14 10:40:50 | 000,402,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV - [2009/07/14 10:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV:[b]64bit:[/b] - [2012/07/05 07:13:27 | 000,136,704 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:[b]64bit:[/b] - [2015/02/03 12:30:56 | 000,187,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV - [2015/02/03 12:12:14 | 000,143,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\cryptsvc.dll -- (CryptSvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:00 | 000,317,952 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV - [2010/11/21 12:24:09 | 000,254,464 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV:[b]64bit:[/b] - [2011/03/03 15:24:16 | 000,183,296 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:[b]64bit:[/b] - [2009/07/14 10:40:35 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\eapsvc.dll -- (EapHost)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:00 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV - [2009/07/14 10:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:48 | 000,501,248 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:[b]64bit:[/b] - [2009/07/14 10:41:54 | 000,524,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\swprv.dll -- (swprv)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:52 | 000,459,776 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofm.dll -- (netprofm)
SRV - [2009/07/14 10:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\netprofm.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2014/12/06 13:17:27 | 000,303,616 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:53 | 000,025,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:[b]64bit:[/b] - [2011/05/24 20:42:55 | 000,404,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:[b]64bit:[/b] - [2012/02/11 15:36:02 | 000,559,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
SRV:[b]64bit:[/b] - [2015/03/06 14:41:46 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV:[b]64bit:[/b] - [2009/07/14 10:41:53 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:17 | 000,344,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:[b]64bit:[/b] - [2015/03/06 14:41:46 | 000,031,232 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:58 | 000,097,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:48 | 000,236,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:55 | 000,370,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV - [2010/11/21 12:24:03 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV:[b]64bit:[/b] - [2010/11/21 12:24:16 | 001,110,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:32 | 000,316,928 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV - [2010/11/21 12:24:00 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:[b]64bit:[/b] - [2014/12/19 12:06:55 | 000,210,432 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:55 | 001,600,512 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:[b]64bit:[/b] - [2015/02/03 12:30:55 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioSrv)
SRV:[b]64bit:[/b] - [2015/02/03 12:30:55 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2010/11/21 12:25:06 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
SRV:[b]64bit:[/b] - [2013/05/27 14:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2010/11/21 12:23:55 | 001,646,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (eventlog)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:28 | 000,828,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:48 | 000,580,096 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:15 | 000,128,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver)
SRV - [2010/11/21 12:24:28 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:56 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:[b]64bit:[/b] - [2014/05/15 01:23:46 | 002,477,536 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:09 | 000,252,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:[b]64bit:[/b] - [2009/07/14 10:41:56 | 000,886,784 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlansvc.dll -- (Wlansvc)
SRV:[b]64bit:[/b] - [2010/11/21 12:24:32 | 000,118,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

< End of report >
  • pxu10652
  • 2015/03/26 (Thu) 23:26:09
悪代官さんへ
まずはExtrasのFirewall関連のOTL処置対象スクリプトです。
今回はFlashやJavaのTEMPも片づけた方が良いですね。

------コピペここから------
:Files
c:\program files (x86)\freetime
z:\temp\nsu33e.tmp

:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{316EFDD2-5359-49AC-92DC-A09104C30FEE}"=-
"{81DF7740-19D0-41AE-948A-A59B4D43D957}"=-
"{AFCEA8A1-B63E-4CC3-B986-1287B2CEEFF7}"=-
"{BB491871-2C7D-4F5C-A4D8-932CA9D4950D}"=-
"{D2EDCC51-7A2D-451E-9301-C806848688F9}"=-
"{6834211E-C011-4F29-963E-6A2A09C634B6}"=-
"{6E8AB753-6662-46E1-B3AB-86C73712B3A2}"=-
"{809DB32B-D564-42C1-BDBC-89303D79DD75}"=-
"{E90E18E9-2616-4BA5-B57B-7CAE4A0BE31F}"=-
"{74869566-B243-4BC7-BE13-0F3CBA65C810}"=-
"{2549B84A-D7FD-4C99-98AB-9FBE5C80E71D}"=-

:Commands
[purity]
[resethosts]
[emptyflash]
[emptyjava]
[emptytemp]
[createrestorepoint]
[reboot]
------コピペここまで------

それから以下が現在問題ありと判断できるソフトウェアです。
これはIU経由がいいでしょうけど。

"{26A24AE4-039D-4CA4-87B4-2F03217076FF}" = Java 7 Update 76
"{26A24AE4-039D-4CA4-87B4-2F83217009F0}" = Java 7 Update 9
"{26A24AE4-039D-4CA4-87B4-2F83218025F0}" = Java 8 Update 25
"{26A24AE4-039D-4CA4-87B4-2F83218031F0}" = Java 8 Update 31
"{26A24AE4-039D-4CA4-87B4-2F83218040F0}" = Java 8 Update 40
"FormatFactory" = FormatFactory 3.6.0.0

あとIntelのグラフィックドライバのバージョンが古すぎてWindowsとの互換性が切れています。
これによりBSoDが発生しますし、統合グラフィックスの更新もすべきでしょう。
以上、横やりでした。
  • IVNO
  • MAIL
  • 2015/03/26 (Thu) 23:42:57
色々とフォローありがとうございます
レスが遅くなってすみません。
IVNOさん、フォローありがとうございます。
ではスクリプトをありがたく使わせていただきます。

ではOTLで続きの作業をお願いします。
その前にFirefoxのブックマークで必要なものがあったら、ブクマを事前にエクスポート(バックアップ)しておいてください。
これは作業後にFFで異常が起きたらFFの再インストールも可能にしておくためです。

準備できたらOTLでの作業です。

このレスの最後にスクリプトを貼っておくので、それを丸ごとコピーして、それをWindowsのメモ帳ファイルに貼り付けて保存しておいてください。

用意できたらPCをまたセーフモードで再起動してOTL起動してください。
起動したらOTLのウインドウ下部にスクリプトを貼り付けて、今度は「Run fix」(赤字のボタン)を押してください。
これでOTLでの処置が開始されます。

しばらく待って処置ができたらPCを通常モードで再起動すると、またOTLのログが出るはずなので、それを保存してから、しばらく様子見の後、OTLのログとともに状態報告をレスください。
OTLのスクリプトは以下になります。破線内(-----)を含まない箇所を丸ごとコピーして、それをOTLに貼って作業してください
------コピペここから------
:OTL
IE - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\..\SearchScopes\{D7822133-4A13-4BA9-BE47-F900A746B4C7}: "URL" = http://www.amazon.co.jp/s/ref=azs_osd_ieajp?ie=UTF-8&tag=amznsearch.jp.ms-22&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
IE - HKU\S-1-5-21-3953051745-2568508545-2191147087-1000\..\SearchScopes\F8649C1F03A846A78AE73B0CB85DBDE3: "URL" = http://www.google.co.jp/search?hl=ja&q={searchTerms}&lr=lang_ja
FF - prefs.js..browser.startup.homepage: "file:///D:/USER/HP_SEL/INDEX.HTM|https://dimora.jp/dc/pc/autoLogin.do|http://www.nifty.com/|https://www.facebook.com/Producer.of.LMO#!/|http://oshiete.watch.impress.co.jp/|http://kaden.watch.impress.co.jp/|http://club.panasonic.jp/campaignlist/index.html|https://www.discas.net/netdvd/wishlist.do?pT=0|https://kanri.m-cloud.jp/|http://other-place.bbs.fc2.com/"
[2015/03/22 22:33:03 | 000,000,000 | ---D | C] -- D:\USER\DVDFab9

:Files
c:\program files (x86)\freetime
z:\temp\nsu33e.tmp
D:\USER\DVDFab9

:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{316EFDD2-5359-49AC-92DC-A09104C30FEE}"=-
"{81DF7740-19D0-41AE-948A-A59B4D43D957}"=-
"{AFCEA8A1-B63E-4CC3-B986-1287B2CEEFF7}"=-
"{BB491871-2C7D-4F5C-A4D8-932CA9D4950D}"=-
"{D2EDCC51-7A2D-451E-9301-C806848688F9}"=-
"{6834211E-C011-4F29-963E-6A2A09C634B6}"=-
"{6E8AB753-6662-46E1-B3AB-86C73712B3A2}"=-
"{809DB32B-D564-42C1-BDBC-89303D79DD75}"=-
"{E90E18E9-2616-4BA5-B57B-7CAE4A0BE31F}"=-
"{74869566-B243-4BC7-BE13-0F3CBA65C810}"=-
"{2549B84A-D7FD-4C99-98AB-9FBE5C80E71D}"=-

:Commands
[purity]
[resethosts]
[emptyflash]
[emptyjava]
[emptytemp]
[createrestorepoint]
[reboot]
------コピペここまで------
  • 悪代官
  • 2015/03/27 (Fri) 21:06:39
OLTのログです。
OLTのログです。AVASTはこの数日は、起動時にマルウェアの検出はしていません。

All processes killed
========== OTL ==========
Registry key HKEY_USERS\S-1-5-21-3953051745-2568508545-2191147087-1000\Software\Microsoft\Internet Explorer\SearchScopes\{D7822133-4A13-4BA9-BE47-F900A746B4C7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D7822133-4A13-4BA9-BE47-F900A746B4C7}\ not found.
Registry key HKEY_USERS\S-1-5-21-3953051745-2568508545-2191147087-1000\Software\Microsoft\Internet Explorer\SearchScopes\{searchTerms}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{searchTerms}\ not found.
Prefs.js: "file:///D:/USER/HP_SEL/INDEX.HTM|https://dimora.jp/dc/pc/autoLogin.do|http://www.nifty.com/|https://www.facebook.com/Producer.of.LMO#!/|http://oshiete.watch.impress.co.jp/|http://kaden.watch.impress.co.jp/|http://club.panasonic.jp/campaignlist/index.html|https://www.discas.net/netdvd/wishlist.do?pT=0|https://kanri.m-cloud.jp/|http://other-place.bbs.fc2.com/" removed from browser.startup.homepage
D:\USER\DVDFab9\Log folder moved successfully.
D:\USER\DVDFab9 folder moved successfully.
========== FILES ==========
c:\program files (x86)\FreeTime\FormatFactory\Plugin\BAVScan folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\Plugin folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\Language folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\Help folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\RMCodecs\tools folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\RMCodecs\plugins folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\RMCodecs\decodecs folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\RMCodecs\common folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\RMCodecs\codecs folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\RMCodecs\audiences folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\RMCodecs folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\Package\Ask folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\Package folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\Filters\Haali folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\Filters\ffdshow folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\Filters folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\Encoder\mplayer folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\Encoder\MP4Box folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\Encoder\codecs folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\Encoder folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules\AviSynthPlugins folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory\FFModules folder moved successfully.
c:\program files (x86)\FreeTime\FormatFactory folder moved successfully.
c:\program files (x86)\FreeTime folder moved successfully.
File\Folder z:\temp\nsu33e.tmp not found.
File\Folder D:\USER\DVDFab9 not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{316EFDD2-5359-49AC-92DC-A09104C30FEE} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{316EFDD2-5359-49AC-92DC-A09104C30FEE}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{81DF7740-19D0-41AE-948A-A59B4D43D957} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{81DF7740-19D0-41AE-948A-A59B4D43D957}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AFCEA8A1-B63E-4CC3-B986-1287B2CEEFF7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFCEA8A1-B63E-4CC3-B986-1287B2CEEFF7}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BB491871-2C7D-4F5C-A4D8-932CA9D4950D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BB491871-2C7D-4F5C-A4D8-932CA9D4950D}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D2EDCC51-7A2D-451E-9301-C806848688F9} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2EDCC51-7A2D-451E-9301-C806848688F9}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6834211E-C011-4F29-963E-6A2A09C634B6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6834211E-C011-4F29-963E-6A2A09C634B6}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6E8AB753-6662-46E1-B3AB-86C73712B3A2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6E8AB753-6662-46E1-B3AB-86C73712B3A2}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{809DB32B-D564-42C1-BDBC-89303D79DD75} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{809DB32B-D564-42C1-BDBC-89303D79DD75}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E90E18E9-2616-4BA5-B57B-7CAE4A0BE31F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E90E18E9-2616-4BA5-B57B-7CAE4A0BE31F}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{74869566-B243-4BC7-BE13-0F3CBA65C810} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74869566-B243-4BC7-BE13-0F3CBA65C810}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2549B84A-D7FD-4C99-98AB-9FBE5C80E71D} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2549B84A-D7FD-4C99-98AB-9FBE5C80E71D}\ not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 57311 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: ME
->Flash cache emptied: 91874 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


[EMPTYJAVA]

User: All Users

User: Default

User: Default User

User: ME
->Java cache emptied: 186917 bytes

User: Public

Total Java Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: ME
->Temp folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 25471636 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 9458 bytes
Session Manager Temp folder emptied: 224113 bytes
Session Manager Tmp folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 68273 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 25.00 mb

Unable to start System Restore Service. Error code 1084

OTL by OldTimer - Version 3.2.69.0 log created on 03282015_003330

Files\Folders moved on Reboot...
Z:\TEMP\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • pxu10652
  • 2015/03/28 (Sat) 00:41:32
ログから全体の再確認します
作業と報告、ご苦労様です。

>AVASTはこの数日は、起動時にマルウェアの検出はしていません。

はい、異常は治まってますね。
ログを見せてもらいましたが、OTLでの掃除はできたようです。
しかしFirefoxに見えていたエントリが妙でしたね。
普通にユーザー自身がアクセスしていたサイトでも、こんな形でエントリに出ることはないはずですが、処置はできたので良しとしましょう。

では全体の再確認します。
またHJTとインストール情報ログと、CCでの各タブのログを取り直して、それらをレスで見せてください。
そのログから見落としがないか調べてみます
  • 悪代官
  • 2015/03/28 (Sat) 20:08:43
現在のログです
HJTのログ

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 23:01:27, on 2015/03/28
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)

FIREFOX: 36.0.4 (x86 ja)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\EPSON\MyEPSON Connect\mep.exe
C:\VIA_XHCI\usb3Monitor.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\AgnType\AgnType.exe
C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
D:\W32_TOOL\TinyMon.exe
C:\Program Files (x86)\husen2K\Husen2K.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaConverter.exe
C:\Program Files (x86)\Justsystems\Shuriken\JsvMail.exe
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaRenderer.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
D:\W32_TOOL\Whf.exe
C:\Users\ME\Desktop\ウィルス対策\HJT(HijackThis).exe

F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ・・127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll
O2 - BHO: PhishWall - {8CA7E745-EF75-4E7B-BB86-8065C0CE29CA} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft アカウント サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll
O3 - Toolbar: PhishWall - {BB62FFF4-41CB-4AFC-BB8C-2A4D4B42BBDC} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [JustOnlineUpdate] "C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe" /startup
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Google Japanese Input Prelauncher] "C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe" --mode=prelaunch_processes
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [IME14 JPN Uninstall] C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /JPN /Log
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: AgainTyper.lnk = C:\Program Files (x86)\AgnType\AgnType.exe
O4 - Startup: HitoKoe10.lnk = D:\W32_TOOL\GO_START\HitoKoe10.exe
O4 - Startup: IPMSG for Win32.lnk = C:\Program Files\IPMsg\ipmsg.exe
O4 - Startup: KYOU.lnk = D:\W32_TOOL\KYOU.EXE
O4 - Startup: Shuriken着信監視.lnk = C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
O4 - Startup: TinyMon.lnk = D:\W32_TOOL\TinyMon.exe
O4 - Startup: 付箋紙21.lnk = C:\Program Files (x86)\husen2K\Husen2K.exe
O4 - Global Startup: SignalNowExpress.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: SunのJavaコンソール - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://gdmp.canon.jp
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {AF4D6906-EB10-48C1-A0CF-9328196158AE} (PrintControl) - http://gdmp.canon.jp/gundam/activex/PrintControl.ocx
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com/bin/srldetect_intel_4.5.22.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D89B3FF-5B44-4C7F-8D7F-9EC2661F9409}: NameServer = 192.168.1.1
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: CyberLink Product - 2013/07/21 18:58:07 (CLKMSVC10_38F51D56) - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe,-100 (GoogleIMEJaCacheService) - Google Inc. - C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mei006h Service (Mei006h) - Unknown owner - C:\Windows\SysWOW64\mei006h.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyEPSON Connect Service - SEIKO EPSON CORPORATION - C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SDPAUMS server service (SDPASVC) - Unknown owner - C:\Windows\SysWOW64\sdpasvc.exe (file missing)
O23 - Service: SecureBrain PhishWall Update - SecureBrain Corporation - C:\Program Files (x86)\SecureBrain\PhishWall\sbpwupdx.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service2 - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TEPRA Driver Option UI Manager (TepOuService) - Unknown owner - C:\Windows\system32\TPOUSVR.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: uvnc_service - UltraVNC - C:\Program Files\uvnc bvba\UltraVNC\WinVNC.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 16312 bytes

スタートアップWindows
有効 HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run Sidebar Microsoft Corporation C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
有効 HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
有効 HKLM:Run AvastUI.exe Avast Software s.r.o. "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
有効 HKLM:Run BDRegion cyberlink C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
有効 HKLM:Run DivXMediaServer DivX, LLC C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
有効 HKLM:Run DivXUpdate DivX, LLC "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
有効 HKLM:Run Google Japanese Input Prelauncher Google Inc. "C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe" --mode=prelaunch_processes
有効 HKLM:Run IAStorIcon Intel Corporation "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
有効 HKLM:Run IME14 JPN Uninstall Microsoft Corporation C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /JPN /Log
有効 HKLM:Run JustOnlineUpdate 株式会社ジャストシステム "C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe" /startup
有効 HKLM:Run QuickTime Task Apple Inc. "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
有効 HKLM:Run RemoteControl10 CyberLink Corp. "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
有効 HKLM:Run StartCCC Advanced Micro Devices, Inc. "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
有効 HKLM:Run SunJavaUpdateSched Oracle Corporation "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
有効 HKLM:Run TepOuService KING JIM CO.,LTD. C:\Windows\system32\TPOUSVR.EXE -uimanage
有効 HKLM:Run USB3MON Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
有効 HKLM:Run VIAxHCUtl VIA Technologies, Inc. C:\VIA_XHCI\usb3Monitor.exe
有効 HKLM:Run VirtualCloneDrive Elaborate Bytes AG "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
有効 Startup Common SignalNowExpress.lnk ストラテジー株式会社 C:\Program Files (x86)\ストラテジー株式会社\SignalNow Express\SignalNowExpress.exe
有効 Startup User AgainTyper.lnk C:\Program Files (x86)\AgnType\AgnType.exe
有効 Startup User HitoKoe10.lnk D:\W32_TOOL\GO_START\HitoKoe10.exe
有効 Startup User IPMSG for Win32.lnk H.Shirouzu C:\Program Files\IPMsg\ipmsg.exe
有効 Startup User KYOU.lnk D:\W32_TOOL\KYOU.EXE
有効 Startup User Shuriken着信監視.lnk 株式会社ジャストシステム C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
有効 Startup User TinyMon.lnk D:\W32_TOOL\TinyMon.exe
有効 Startup User 付箋紙21.lnk ROTO C:\Program Files (x86)\husen2K\Husen2K.exe

スタートアップ(IE)
無効 Extension Lync Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
無効 Extension Lync Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
有効 Helper avast! Online Security Avast Software s.r.o. C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
有効 Helper avast! Online Security Avast Software s.r.o. C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
有効 Helper ExplorerWnd Helper IObit C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll
無効 Helper Lync Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
無効 Helper Lync Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
有効 Helper Microsoft SkyDrive Pro Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
有効 Helper Microsoft SkyDrive Pro Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
無効 Helper Microsoft アカウント サインイン ヘルパー Microsoft Corp. C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
無効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
無効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
有効 Helper PhishWall SecureBrain Corporation C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
無効 Helper Windows Live ID Sign-in Helper Microsoft Corp. C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 Toolbar PhishWall SecureBrain Corporation C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll

スタートアップ(Firefox)
有効 Extension Avast Online Security 10.2.0.187 AVAST Software default Firefox 36.0.4 C:\Program Files\AVAST Software\Avast\WebRep\FF
有効 Plugin Adobe Acrobat 11.0.10.32 Adobe Systems Inc. default Firefox 36.0.4 C:\Program Files (x86)\Adobe\Reader 11.0\Reader\browser\nppdf32.dll
有効 Plugin DivX Plus Web Player 3.2.3.1164 DivX, LLC default Firefox 36.0.4 C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll
有効 Plugin DivX VOD Helper Plug-in 1.1.0.14 DivX, LLC. default Firefox 36.0.4 C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
有効 Plugin Google Update 1.3.26.9 Google Inc. default Firefox 36.0.4 C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
有効 Plugin Intel® Identity Protection Technology 2.1.42.0 Intel Corporation default Firefox 36.0.4 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
有効 Plugin Intel® Identity Protection Technology 2.1.42.0 Intel Corporation default Firefox 36.0.4 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
有効 Plugin Java Deployment Toolkit 8.0.400.25 11.40.2.25 Oracle Corporation default Firefox 36.0.4 C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npdeployJava1.dll
有効 Plugin Java(TM) Platform SE 8 U40 11.40.2.25 Oracle Corporation default Firefox 36.0.4 C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll
有効 Plugin Microsoft Office 2013 15.0.4514.1000 Microsoft Corporation default Firefox 36.0.4 C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL
有効 Plugin Microsoft Office 2013 15.0.4545.1000 Microsoft Corporation default Firefox 36.0.4 C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
有効 Plugin Photo Gallery 16.4.3528.331 Microsoft Corporation default Firefox 36.0.4 C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
有効 Plugin QuickTime Plug-in 7.7.6 7.7.6.0 Apple Inc. default Firefox 36.0.4 C:\Program Files (x86)\QuickTime\Plugins\npqtplugin5.dll
有効 Plugin Shockwave Flash 17.0.0.134 Adobe Systems Incorporated default Firefox 36.0.4 C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll
有効 Plugin Shockwave for Director 12.1.7.157 Adobe Systems, Inc. default Firefox 36.0.4 C:\Windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll
有効 Plugin Silverlight Plug-In 5.1.30514.0 Microsoft Corporation default Firefox 36.0.4 C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

スタートアップ(タスク)
有効 Task Adobe Acrobat Update Task Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task BELL D:\W32_TOOL\HitoKoe10.exe
有効 Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task EPSON EP-806A Series Update {06D96841-E0D2-4E1C-AB1C-7A5B5087D513} SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLKJ.EXE /EXE:"{06D96841-E0D2-4E1C-AB1C-7A5B5087D513}" /F:"Update"
有効 Task GO_BED1 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GO_BED2 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task Intel_C_CVKI302402M9240DGN Intel C:\Program Files (x86)\Intel\Intel(R) SSD Toolbox\Intel SSD Toolbox.exe -drive_letter C -drive_serial CVKI302402M9240DGN -trim scheduled
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 Intel® Services Manager C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon Intel® Services Manager "C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe" --automatic
有効 Task RealDownloaderRealUpgradeLogonTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe /logoncheck
有効 Task RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe /scheduledcheck
有効 Task RealPlayerRealUpgradeLogonTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /logoncheck
有効 Task RealPlayerRealUpgradeScheduledTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /scheduledcheck
有効 Task SidebarExecute Microsoft Corporation C:\Program Files\Windows Sidebar\sidebar.exe
有効 Task Uninstaller_SkipUac_ME IObit C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer
有効 Task Wise Registry Cleaner Schedule Task WiseCleaner.com C:\Program Files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe -a
  • pxu10652
  • 2015/03/28 (Sat) 23:10:37
しばらく様子見しましょう
おはようございます。
各ログも見せてもらいましたが、おかしなものはなさそうですね。

ではそのまましばらく様子見をお願いします。
そのまま普通にPCを使いながら1週間様子見後、そこでまた今回同様にHJTと情報ログと、CCで各タブのログを取り直して、それらを様子見中の状態報告とともにレスください。

様子見で異常が見えなくても、ログを見直すと再感染が見つかることがありますし、逆にログには出なくても異常が出ることも多いので、最後まで気を抜かずにかかってください
  • 悪代官
  • 2015/03/29 (Sun) 07:30:58
ちょっとお待ちください
悪代官さんすみませんまた横やり入れます。
pxu10652さんお手数ですがひとつ教えていただけないでしょうか。
現在PCを操作していて、特に動画を閲覧した際にPCが動作を停止させ、
BSoD(Blue Screen of Death)と呼ばれる添付画像みたいな画面にならないでしょうか。
もしこの症状が発生するのであれば、お手数ですがPCの型番をご連絡ください。
ノートPCの場合はPCの底面にラベル等があり、そこに型番が記述されているはずです。
型番をご提示いただけましたら次の処置をご案内いたします。
もしBSoDが発生していない場合はその旨ご連絡ください。
  • IVNO
  • MAIL
  • 2015/03/29 (Sun) 13:29:47
ブルースクリーンは出ていません
PCは自作機(M/B:GIGABYTE GA-Z77-UD3H)です。最初はCPUのビデオ機能を使ってましたが、モニターを
WQHD(2560×1440ドット)に変えるときに「Radeon R9 270X」を追加しました。
RAID10+SSDなDAW対応32GBマシンです。
  • pxu10652
  • 2015/03/29 (Sun) 20:23:08
なるほど
ではBSoDは発生していないと言うことですね。
ただIntel関連のエラーが3/25日、つまりOTLのログを上げてもらう前日にも発生していますので、
IntelのZ77 Expressチップセットドライバの更新を行ったほうが良いでしょう。

GIGABYTE - マザーボード - Socket 1155 - GA-Z77X-UD3H (rev. 1.0)
http://www.gigabyte.jp/products/product-page.aspx?pid=4153#dl

以下が上記ページの該当ドライバです。

Intel Management Engine Interface(ダウンロード先:アジア)
http://download.gigabyte.asia/FileList/Driver/mb_driver_intel_me_7series.exe

以降は悪代官さんのご案内に従って様子見をお願いいたします。
  • IVNO
  • MAIL
  • 2015/03/29 (Sun) 22:32:49
OTL続き
[color=#E56717]========== Chrome ==========[/color]

CHR - default_search_provider: (Enabled)
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\yuma\AppData\Local\Google\Chrome\User Data\PepperFlash\16.0.0.305\pepflashplayer.dll
CHR - plugin: Widevine Content Decryption Module (Enabled) = C:\Users\yuma\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.758\_platform_specific\win_x86\widevinecdmadapter.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.91\internal-nacl-plugin
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.91\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
CHR - plugin: Battlelog Game Launcher (Disabled) = C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Intelツョ Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intelツョ Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: Java Deployment Toolkit 8.0.400.26 (Enabled) = C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll
CHR - plugin: Java(TM) Platform SE 8 U40 (Enabled) = C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Microsoft Office 2013 (Enabled) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL
CHR - plugin: Unity Player (Enabled) = C:\Users\yuma\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\yuma\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\yuma\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Renderer (Enabled) = C:\Users\yuma\AppData\Roaming\Mozilla\plugins\npo1d.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll

O1 HOSTS File: ([2015/01/30 20:06:04 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:[b]64bit:[/b] - BHO: (ExplorerWnd Helper) - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll File not found
O2:[b]64bit:[/b] - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Evernote extension) - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\grooveex.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll (Oracle Corporation)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (TrendMicro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll File not found
O3 - HKU\S-1-5-21-2249536979-1459881710-1224475315-1000\..\Toolbar\WebBrowser: (no name) - {AEF44653-C059-42CB-A5B7-41C640DA4A67} - No CLSID value found.
O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\SysNative\hkcmd.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\WINDOWS\SysNative\igfxtray.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" File not found
O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\WINDOWS\SysNative\igfxpers.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [ShadowPlay] C:\WINDOWS\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [GamingMouse] C:\Program Files (x86)\Drakonia Configurator\hid.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKU\S-1-5-21-2249536979-1459881710-1224475315-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-2249536979-1459881710-1224475315-1000..\Run: [EPSON EP-704A] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHNJ.EXE /FU "C:\Users\yuma\AppData\Local\Temp\E_S4C13.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-2249536979-1459881710-1224475315-1000..\Run: [Google Update] C:\Users\yuma\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKU\S-1-5-21-2249536979-1459881710-1224475315-1000..\Run: [Line] C:\Program Files (x86)\Naver\LINE\Line.exe (LINE Corporation)
O4 - HKU\S-1-5-21-2249536979-1459881710-1224475315-1000..\Run: [Skype] C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - Startup: C:\Users\narus_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
O4 - Startup: C:\Users\yuma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote に送る.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8:[b]64bit:[/b] - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\onbttnie.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\onbttnie.dll (Microsoft Corporation)
O9 - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html ()
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html ()
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2249536979-1459881710-1224475315-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2249536979-1459881710-1224475315-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2249536979-1459881710-1224475315-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2249536979-1459881710-1224475315-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {7216BF69-1FB3-438C-9A51-9DA82B676BC0} http://userimg.arario.jp/activeX/AraGameStarterW6.cab (ArarioGameStarter6 Class)
O16 - DPF: {98FFD412-1A12-4BCE-8AB2-247C78E22227} https://static.ncsoft.jp/js/login/activex/NCLoader.8.cab (NCLoaderCtl Class)
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} http://dist.cdnetworks.co.jp/cdndist/neffy/NeffyLauncher_v1013.cab (NeffyLauncherCtl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{93B117B2-7B46-4A2F-818A-32351D1942D6}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{93B117B2-7B46-4A2F-818A-32351D1942D6}: NameServer = 8.8.8.8,8.8.4.4
O18:[b]64bit:[/b] - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\msosb.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20:[b]64bit:[/b] - AppInit_DLLs: (C:\WINDOWS\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\WINDOWS\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\WINDOWS\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\SysNative\igfxdev.dll (Intel Corporation)
O21:[b]64bit:[/b] - SSODL: EldosMountNotificator - {C28617FD-4FE7-4043-AD51-C8132CE90106} - C:\Windows\SysNative\SSCbFsMntNtf3.dll (EldoS Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: EldosMountNotificator - {C28617FD-4FE7-4043-AD51-C8132CE90106} - C:\Windows\SysWOW64\SSCbFsMntNtf3.dll (EldoS Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:[b]64bit:[/b] - SharedTaskScheduler: {C28617FD-4FE7-4043-AD51-C8132CE90106} - Virtual Storage Mount Notification - C:\Windows\SysNative\SSCbFsMntNtf3.dll (EldoS Corporation)
O22 - SharedTaskScheduler: {C28617FD-4FE7-4043-AD51-C8132CE90106} - Virtual Storage Mount Notification - C:\Windows\SysWOW64\SSCbFsMntNtf3.dll (EldoS Corporation)
O29:[b]64bit:[/b] - HKLM SecurityProviders - (credssp.dll) - C:\WINDOWS\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\WINDOWS\SysWow64\credssp.dll (Microsoft Corporation)
O30:[b]64bit:[/b] - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:[b]64bit:[/b] - LSA: Security Packages - (kerberos) - C:\WINDOWS\SysNative\kerberos.dll (Microsoft Corporation)
O30:[b]64bit:[/b] - LSA: Security Packages - (msv1_0) - C:\WINDOWS\SysNative\msv1_0.dll (Microsoft Corporation)
O30:[b]64bit:[/b] - LSA: Security Packages - (schannel) - C:\WINDOWS\SysNative\schannel.dll (Microsoft Corporation)
O30:[b]64bit:[/b] - LSA: Security Packages - (wdigest) - C:\WINDOWS\SysNative\wdigest.dll (Microsoft Corporation)
O30:[b]64bit:[/b] - LSA: Security Packages - (tspkg) - C:\WINDOWS\SysNative\tspkg.dll (Microsoft Corporation)
O30:[b]64bit:[/b] - LSA: Security Packages - (pku2u) - C:\WINDOWS\SysNative\pku2u.dll (Microsoft Corporation)
O30:[b]64bit:[/b] - LSA: Security Packages - (livessp) - C:\WINDOWS\SysNative\livessp.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\WINDOWS\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\WINDOWS\SysWow64\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2014/03/28 00:00:00 | 000,000,147 | R--- | M] () - M:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{40fb983e-79e8-11e2-b728-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{40fb983e-79e8-11e2-b728-806e6f6e6963}\Shell\AutoRun\command - "" = M:\startup.exe -- [2014/03/28 00:00:00 | 000,301,052 | R--- | M] (NanaWind)
O33 - MountPoints2\{40fb983e-79e8-11e2-b728-806e6f6e6963}\Shell\readme\command - "" = notepad readme.txt
O33 - MountPoints2\{e92ab227-d282-11e3-beb8-bc5ff4895894}\Shell - "" = AutoRun
O33 - MountPoints2\{e92ab227-d282-11e3-beb8-bc5ff4895894}\Shell\AutoRun\command - "" = "E:\autorun.exe"
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2015/03/27 03:45:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\herdProtect
[2015/03/27 03:45:24 | 000,000,000 | ---D | C] -- C:\Program Files\Reason
[2015/03/27 03:16:42 | 000,000,000 | ---D | C] -- C:\Users\yuma\AppData\Local\Adobe
[2015/03/26 20:46:21 | 000,000,000 | ---D | C] -- C:\Users\yuma\Tracing
[2015/03/24 21:32:00 | 000,000,000 | ---D | C] -- C:\Users\yuma\AppData\Local\Apple
[2015/03/24 21:03:41 | 000,000,000 | ---D | C] -- C:\Users\yuma\Documents\Banished
[2015/03/23 23:05:07 | 000,000,000 | ---D | C] -- C:\Users\yuma\AppData\Roaming\Geek Uninstaller
[2015/03/23 22:07:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2015/03/23 21:56:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2015/03/23 21:56:51 | 000,098,216 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
[2015/03/23 21:55:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2015/03/23 19:46:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2015/03/23 19:46:02 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2015/03/22 15:10:54 | 000,622,224 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvStreaming.exe
[2015/03/22 15:06:46 | 000,030,536 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvhdap64.dll
[2015/03/22 15:06:45 | 032,114,888 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvoglv64.dll
[2015/03/22 15:06:45 | 024,775,368 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvoglv32.dll
[2015/03/22 15:06:45 | 013,297,144 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvopencl.dll
[2015/03/22 15:06:45 | 010,775,080 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvopencl.dll
[2015/03/22 15:06:45 | 001,540,240 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvhdagenco6420103.dll
[2015/03/22 15:06:45 | 000,970,384 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFR64.dll
[2015/03/22 15:06:45 | 000,944,784 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvFBC64.dll
[2015/03/22 15:06:45 | 000,930,448 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFR.dll
[2015/03/22 15:06:45 | 000,909,512 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvFBC.dll
[2015/03/22 15:06:45 | 000,496,272 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvEncodeAPI64.dll
[2015/03/22 15:06:45 | 000,400,584 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvEncodeAPI.dll
[2015/03/22 15:06:45 | 000,390,288 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFROpenGL.dll
[2015/03/22 15:06:45 | 000,354,112 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvoglshim64.dll
[2015/03/22 15:06:45 | 000,346,824 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFROpenGL.dll
[2015/03/22 15:06:45 | 000,306,208 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvoglshim32.dll
[2015/03/22 15:06:45 | 000,195,728 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\drivers\nvhda64v.sys
[2015/03/22 15:06:42 | 001,896,136 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispco6434788.dll
[2015/03/22 15:06:42 | 001,557,648 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispgenco6434788.dll
[2015/03/22 15:06:41 | 017,258,024 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvd3dumx.dll
[2015/03/22 15:06:40 | 013,210,080 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuda.dll
[2015/03/22 15:06:40 | 003,611,792 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuvid.dll
[2015/03/22 15:06:40 | 003,249,352 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuvid.dll
[2015/03/22 15:06:37 | 010,715,864 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuda.dll
[2015/03/22 15:06:34 | 025,460,880 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcompiler.dll
[2015/03/22 15:06:34 | 020,466,376 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcompiler.dll
[2015/03/22 15:06:34 | 002,906,928 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvapi.dll
[2015/03/22 15:00:37 | 000,038,032 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\drivers\nvvad64v.sys
[2015/03/22 15:00:37 | 000,032,400 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvaudcap32v.dll
[2015/03/17 17:57:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Google
[2015/03/17 05:28:51 | 000,000,000 | ---D | C] -- C:\Users\yuma\AppData\Local\SCE
[2015/03/17 04:13:33 | 000,000,000 | ---D | C] -- C:\Users\yuma\AppData\Local\Steam
[2015/03/12 20:34:55 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\CompatTel
[2015/03/12 04:44:47 | 018,822,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll
[2015/03/12 04:44:45 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msihnd.dll
[2015/03/12 04:44:45 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msihnd.dll
[2015/03/12 04:44:44 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\packager.dll
[2015/03/12 04:44:42 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\packager.dll
[2015/03/12 04:44:40 | 000,116,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\consent.exe
[2015/03/12 04:44:39 | 003,320,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2015/03/12 04:44:38 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dpapisrv.dll
[2015/03/12 04:44:36 | 015,157,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
[2015/03/12 04:44:34 | 015,432,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmp.dll
[2015/03/12 04:44:26 | 013,784,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vmms.exe
[2015/03/12 04:44:23 | 013,318,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wmp.dll
[2015/03/12 04:44:15 | 014,354,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2015/03/12 04:44:14 | 009,530,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Search.dll
[2015/03/12 04:44:13 | 003,460,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSService.dll
[2015/03/12 04:44:12 | 012,749,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2015/03/12 04:44:12 | 007,032,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll
[2015/03/12 04:44:10 | 007,075,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\glcndFilter.dll
[2015/03/12 04:44:09 | 007,784,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Data.Pdf.dll
[2015/03/12 04:44:08 | 006,386,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Search.dll
[2015/03/12 04:44:07 | 006,213,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll
[2015/03/12 04:44:06 | 003,307,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msmpeg2vdec.dll
[2015/03/12 04:44:04 | 005,267,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\glcndFilter.dll
[2015/03/12 04:44:02 | 005,264,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Data.Pdf.dll
[2015/03/12 04:44:01 | 003,820,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcore.dll
[2015/03/12 04:44:01 | 000,360,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpclip.exe
[2015/03/12 04:44:01 | 000,165,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpinput.exe
[2015/03/12 04:44:00 | 004,709,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d2d1.dll
[2015/03/12 04:44:00 | 002,890,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msmpeg2vdec.dll
[2015/03/12 04:43:59 | 004,483,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIRibbon.dll
[2015/03/12 04:43:58 | 003,633,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tquery.dll
[2015/03/12 04:43:58 | 002,334,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfcore.dll
[2015/03/12 04:43:56 | 004,690,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xpsrchvw.exe
[2015/03/12 04:43:56 | 000,941,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XpsFilt.dll
[2015/03/12 04:43:55 | 002,554,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssrch.dll
[2015/03/12 04:43:54 | 002,324,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfcore.dll
[2015/03/12 04:43:53 | 004,418,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dbgeng.dll
[2015/03/12 04:43:53 | 003,138,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMVCORE.DLL
[2015/03/12 04:43:52 | 006,287,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vmwp.exe
[2015/03/12 04:43:50 | 003,561,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIRibbon.dll
[2015/03/12 04:43:49 | 002,896,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\esent.dll
[2015/03/12 04:43:48 | 003,056,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xpsservices.dll
[2015/03/12 04:43:48 | 001,919,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XpsPrint.dll
[2015/03/12 04:43:47 | 003,273,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdpcore.dll
[2015/03/12 04:43:47 | 002,542,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\esent.dll
[2015/03/12 04:43:46 | 003,109,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ExplorerFrame.dll
[2015/03/12 04:43:46 | 002,814,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers.dll
[2015/03/12 04:43:44 | 001,286,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MSAudDecMFT.dll
[2015/03/12 04:43:43 | 002,464,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d10warp.dll
[2015/03/12 04:43:42 | 002,749,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tquery.dll
[2015/03/12 04:43:41 | 002,174,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\combase.dll
[2015/03/12 04:43:41 | 001,922,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssrch.dll
[2015/03/12 04:43:40 | 003,256,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Wpc.dll
[2015/03/12 04:43:40 | 003,118,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WpcMon.exe
[2015/03/12 04:43:39 | 002,706,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ExplorerFrame.dll
[2015/03/12 04:43:39 | 002,314,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d11.dll
[2015/03/12 04:43:38 | 002,229,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d9.dll
[2015/03/12 04:43:37 | 002,984,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dbgeng.dll
[2015/03/12 04:43:36 | 002,745,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMVDECOD.DLL
[2015/03/12 04:43:35 | 002,941,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WpcWebSync.dll
[2015/03/12 04:43:35 | 002,924,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mmcndmgr.dll
[2015/03/12 04:43:33 | 001,999,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll
[2015/03/12 04:43:32 | 000,373,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\storport.sys
[2015/03/12 04:43:31 | 000,085,504 | ---- | C] (Radius Inc.) -- C:\WINDOWS\SysWow64\iccvid.dll
[2015/03/12 04:43:30 | 002,528,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMVDECOD.DLL
[2015/03/12 04:43:30 | 001,660,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ole32.dll
[2015/03/12 04:43:30 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
[2015/03/12 04:43:30 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
[2015/03/12 04:43:29 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
[2015/03/12 04:43:29 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
[2015/03/12 04:43:29 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
[2015/03/12 04:43:29 | 000,055,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2015/03/12 04:43:29 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
[2015/03/12 04:43:29 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuaext.dll
[2015/03/12 04:43:28 | 001,714,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2015/03/12 04:43:28 | 000,894,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2015/03/12 04:43:28 | 000,723,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2015/03/12 04:43:28 | 000,407,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2015/03/12 04:43:27 | 001,275,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFolder.dll
[2015/03/12 04:43:26 | 001,564,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\combase.dll
[2015/03/12 04:43:25 | 001,518,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmde.dll
[2015/03/12 04:43:25 | 001,509,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmpmde.dll
[2015/03/12 04:43:24 | 002,487,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storagewmi.dll
[2015/03/12 04:43:24 | 001,310,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rpcrt4.dll
[2015/03/12 04:43:23 | 001,348,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2015/03/12 04:43:23 | 001,024,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MSAudDecMFT.dll
[2015/03/12 04:43:22 | 002,072,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\OpcServices.dll
[2015/03/12 04:43:22 | 001,822,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dui70.dll
[2015/03/12 04:43:22 | 001,668,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\workfolderssvc.dll
[2015/03/12 04:43:21 | 001,946,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3d11.dll
[2015/03/12 04:43:20 | 002,635,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CertEnroll.dll
[2015/03/12 04:43:19 | 001,288,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfnetsrc.dll
[2015/03/12 04:43:18 | 002,317,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CertEnroll.dll
[2015/03/12 04:43:18 | 002,162,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SRH.dll
[2015/03/12 04:43:18 | 001,639,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidsvc.dll
[2015/03/12 04:43:18 | 001,165,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfasfsrcsnk.dll
[2015/03/12 04:43:17 | 000,785,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\blackbox.dll
[2015/03/12 04:43:15 | 001,490,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GdiPlus.dll
[2015/03/12 04:43:14 | 001,816,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\taskschd.dll
[2015/03/12 04:43:14 | 001,221,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.appcore.dll
[2015/03/12 04:43:13 | 001,725,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Immersive.dll
[2015/03/12 04:43:13 | 001,544,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Immersive.dll
[2015/03/12 04:43:13 | 001,461,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dui70.dll
[2015/03/12 04:43:12 | 002,364,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mmcndmgr.dll
[2015/03/12 04:43:12 | 000,945,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PeerDistCacheProvider.dll
[2015/03/12 04:43:11 | 002,469,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Wpc.dll
[2015/03/12 04:43:10 | 002,450,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMVENCOD.DLL
[2015/03/12 04:43:09 | 002,447,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMVENCOD.DLL
[2015/03/12 04:43:09 | 001,753,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GdiPlus.dll
[2015/03/12 04:43:09 | 001,543,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\webservices.dll
[2015/03/12 04:43:08 | 001,500,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\quartz.dll
[2015/03/12 04:43:07 | 001,321,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmde.dll
[2015/03/12 04:43:05 | 001,482,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\storagewmi.dll
[2015/03/12 04:43:05 | 001,250,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIAutomationCore.dll
[2015/03/12 04:43:04 | 003,553,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xpsrchvw.exe
[2015/03/12 04:43:03 | 002,003,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mmc.exe
[2015/03/12 04:43:03 | 001,697,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\quartz.dll
[2015/03/12 04:43:02 | 002,090,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemSettingsAdminFlowUI.dll
[2015/03/12 04:43:01 | 002,880,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpccpl.dll
[2015/03/12 04:43:01 | 001,540,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\diagperf.dll
  • ZZ
  • 2015/03/29 (Sun) 23:13:57
Re: AVASTにて、「感染をブロックしました」と表示される
申し訳ございません投稿先を間違えてしまいました。
  • ZZ
  • 2015/03/29 (Sun) 23:14:49
GA-Z77X-UD3Hでした。(^_^;
Intel Management Engine Interfaceをアップデートしました。
GA-Z77-HD3とごっちゃになってGA-Z77X-UD3HをGA-Z77-UD3Hと書いていたことに
指摘されて気づきました。(^_^;
  • pxu10652
  • 2015/03/30 (Mon) 22:52:28
約1周間経過したので、ログをアップします。
起動時にAVASTで警告されることはなくなりました。ただ、Word2013やExcel2013を終了させたのに、勝手に
起動することがあり、それだけがちょっと気になっています。あと、ReslPlayerをアンインストールしたのに
タスクに残っているので、消したいです。


HJTのログ
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 11:40:05, on 2015/04/04
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)

FIREFOX: 37.0.1 (x86 ja)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\EPSON\MyEPSON Connect\mep.exe
C:\VIA_XHCI\usb3Monitor.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\AgnType\AgnType.exe
C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
D:\W32_TOOL\TinyMon.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\husen2K\Husen2K.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaConverter.exe
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaRenderer.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
D:\W32_TOOL\Whf.exe
C:\Program Files (x86)\Justsystems\Shuriken\JsvMail.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\ME\Desktop\ウィルス対策\HJT(HijackThis).exe

F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll
O2 - BHO: PhishWall - {8CA7E745-EF75-4E7B-BB86-8065C0CE29CA} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft アカウント サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll
O3 - Toolbar: PhishWall - {BB62FFF4-41CB-4AFC-BB8C-2A4D4B42BBDC} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [JustOnlineUpdate] "C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe" /startup
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Google Japanese Input Prelauncher] "C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe" --mode=prelaunch_processes
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [IME14 JPN Uninstall] C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /JPN /Log
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: AgainTyper.lnk = C:\Program Files (x86)\AgnType\AgnType.exe
O4 - Startup: HitoKoe10.lnk = D:\W32_TOOL\GO_START\HitoKoe10.exe
O4 - Startup: IPMSG for Win32.lnk = C:\Program Files\IPMsg\ipmsg.exe
O4 - Startup: KYOU.lnk = D:\W32_TOOL\KYOU.EXE
O4 - Startup: Shuriken着信監視.lnk = C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
O4 - Startup: TinyMon.lnk = D:\W32_TOOL\TinyMon.exe
O4 - Startup: 付箋紙21.lnk = C:\Program Files (x86)\husen2K\Husen2K.exe
O4 - Global Startup: SignalNowExpress.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: SunのJavaコンソール - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://gdmp.canon.jp
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {AF4D6906-EB10-48C1-A0CF-9328196158AE} (PrintControl) - http://gdmp.canon.jp/gundam/activex/PrintControl.ocx
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com/bin/srldetect_intel_4.5.22.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D89B3FF-5B44-4C7F-8D7F-9EC2661F9409}: NameServer = 192.168.1.1
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: CyberLink Product - 2013/07/21 18:58:07 (CLKMSVC10_38F51D56) - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe,-100 (GoogleIMEJaCacheService) - Google Inc. - C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mei006h Service (Mei006h) - Unknown owner - C:\Windows\SysWOW64\mei006h.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyEPSON Connect Service - SEIKO EPSON CORPORATION - C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SDPAUMS server service (SDPASVC) - Unknown owner - C:\Windows\SysWOW64\sdpasvc.exe (file missing)
O23 - Service: SecureBrain PhishWall Update - SecureBrain Corporation - C:\Program Files (x86)\SecureBrain\PhishWall\sbpwupdx.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service2 - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TEPRA Driver Option UI Manager (TepOuService) - Unknown owner - C:\Windows\system32\TPOUSVR.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: uvnc_service - UltraVNC - C:\Program Files\uvnc bvba\UltraVNC\WinVNC.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 16270 bytes

CCのスタートアップ
有効 HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run Sidebar Microsoft Corporation C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
有効 HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
有効 HKLM:Run AvastUI.exe Avast Software s.r.o. "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
有効 HKLM:Run BDRegion cyberlink C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
有効 HKLM:Run DivXMediaServer DivX, LLC C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
有効 HKLM:Run DivXUpdate DivX, LLC "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
有効 HKLM:Run Google Japanese Input Prelauncher Google Inc. "C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe" --mode=prelaunch_processes
有効 HKLM:Run IAStorIcon Intel Corporation "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
有効 HKLM:Run IME14 JPN Uninstall Microsoft Corporation C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /JPN /Log
有効 HKLM:Run JustOnlineUpdate 株式会社ジャストシステム "C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe" /startup
有効 HKLM:Run QuickTime Task Apple Inc. "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
有効 HKLM:Run RemoteControl10 CyberLink Corp. "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
有効 HKLM:Run StartCCC Advanced Micro Devices, Inc. "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
有効 HKLM:Run SunJavaUpdateSched Oracle Corporation "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
有効 HKLM:Run TepOuService KING JIM CO.,LTD. C:\Windows\system32\TPOUSVR.EXE -uimanage
有効 HKLM:Run USB3MON Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
有効 HKLM:Run VIAxHCUtl VIA Technologies, Inc. C:\VIA_XHCI\usb3Monitor.exe
有効 HKLM:Run VirtualCloneDrive Elaborate Bytes AG "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
有効 Startup Common SignalNowExpress.lnk ストラテジー株式会社 C:\Program Files (x86)\ストラテジー株式会社\SignalNow Express\SignalNowExpress.exe
有効 Startup User AgainTyper.lnk C:\Program Files (x86)\AgnType\AgnType.exe
有効 Startup User HitoKoe10.lnk D:\W32_TOOL\GO_START\HitoKoe10.exe
有効 Startup User IPMSG for Win32.lnk H.Shirouzu C:\Program Files\IPMsg\ipmsg.exe
有効 Startup User KYOU.lnk D:\W32_TOOL\KYOU.EXE
有効 Startup User Shuriken着信監視.lnk 株式会社ジャストシステム C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
有効 Startup User TinyMon.lnk D:\W32_TOOL\TinyMon.exe
有効 Startup User 付箋紙21.lnk ROTO C:\Program Files (x86)\husen2K\Husen2K.exe


スタートアップ(IE)
無効 Extension Lync Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
無効 Extension Lync Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
有効 Helper avast! Online Security Avast Software s.r.o. C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
有効 Helper avast! Online Security Avast Software s.r.o. C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
有効 Helper ExplorerWnd Helper IObit C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll
無効 Helper Lync Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
無効 Helper Lync Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
有効 Helper Microsoft SkyDrive Pro Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
有効 Helper Microsoft SkyDrive Pro Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
無効 Helper Microsoft アカウント サインイン ヘルパー Microsoft Corp. C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
無効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
無効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
有効 Helper PhishWall SecureBrain Corporation C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
無効 Helper Windows Live ID Sign-in Helper Microsoft Corp. C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 Toolbar PhishWall SecureBrain Corporation C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll



スタートアップ(Firefox)
有効 Extension Avast Online Security 10.2.0.187 AVAST Software default Firefox 37.0.1 C:\Program Files\AVAST Software\Avast\WebRep\FF
有効 Plugin Adobe Acrobat 11.0.10.32 Adobe Systems Inc. default Firefox 37.0.1 C:\Program Files (x86)\Adobe\Reader 11.0\Reader\browser\nppdf32.dll
有効 Plugin DivX Plus Web Player 3.2.3.1164 DivX, LLC default Firefox 37.0.1 C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll
有効 Plugin DivX VOD Helper Plug-in 1.1.0.14 DivX, LLC. default Firefox 37.0.1 C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
有効 Plugin Google Update 1.3.26.9 Google Inc. default Firefox 37.0.1 C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
有効 Plugin Intel® Identity Protection Technology 4.0.5.0 Intel Corporation default Firefox 37.0.1 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
有効 Plugin Intel® Identity Protection Technology 4.0.5.0 Intel Corporation default Firefox 37.0.1 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
有効 Plugin Java Deployment Toolkit 8.0.400.25 11.40.2.25 Oracle Corporation default Firefox 37.0.1 C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npdeployJava1.dll
有効 Plugin Java(TM) Platform SE 8 U40 11.40.2.25 Oracle Corporation default Firefox 37.0.1 C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll
有効 Plugin Microsoft Office 2013 15.0.4514.1000 Microsoft Corporation default Firefox 37.0.1 C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL
有効 Plugin Microsoft Office 2013 15.0.4545.1000 Microsoft Corporation default Firefox 37.0.1 C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
有効 Plugin Photo Gallery 16.4.3528.331 Microsoft Corporation default Firefox 37.0.1 C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
有効 Plugin QuickTime Plug-in 7.7.6 7.7.6.0 Apple Inc. default Firefox 37.0.1 C:\Program Files (x86)\QuickTime\Plugins\npqtplugin5.dll
有効 Plugin Shockwave Flash 17.0.0.134 Adobe Systems Incorporated default Firefox 37.0.1 C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll
有効 Plugin Shockwave for Director 12.1.7.157 Adobe Systems, Inc. default Firefox 37.0.1 C:\Windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll
有効 Plugin Silverlight Plug-In 5.1.30514.0 Microsoft Corporation default Firefox 37.0.1 C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll


スタートアップ(タスク)
有効 Task Adobe Acrobat Update Task Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task BELL D:\W32_TOOL\HitoKoe10.exe
有効 Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task EPSON EP-806A Series Update {06D96841-E0D2-4E1C-AB1C-7A5B5087D513} SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLKJ.EXE /EXE:"{06D96841-E0D2-4E1C-AB1C-7A5B5087D513}" /F:"Update"
有効 Task GO_BED1 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GO_BED2 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task Intel_C_CVKI302402M9240DGN Intel C:\Program Files (x86)\Intel\Intel(R) SSD Toolbox\Intel SSD Toolbox.exe -drive_letter C -drive_serial CVKI302402M9240DGN -trim scheduled
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 Intel® Services Manager C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon Intel® Services Manager "C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe" --automatic
有効 Task RealDownloaderRealUpgradeLogonTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe /logoncheck
有効 Task RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe /scheduledcheck
有効 Task RealPlayerRealUpgradeLogonTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /logoncheck
有効 Task RealPlayerRealUpgradeScheduledTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /scheduledcheck
有効 Task SidebarExecute Microsoft Corporation C:\Program Files\Windows Sidebar\sidebar.exe
有効 Task Uninstaller_SkipUac_ME IObit C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer
有効 Task Wise Registry Cleaner Schedule Task WiseCleaner.com C:\Program Files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe -a

  • pxu10652
  • 2015/04/04 (Sat) 11:50:44
CCで少し処置と、追加のログも
こんばんは。
レスが遅くなってすみません。

>起動時にAVASTで警告されることはなくなりました。ただ、Word2013やExcel2013を終了させたのに、勝手に
起動することがあり、それだけがちょっと気になっています。あと、ReslPlayerをアンインストールしたのに
タスクに残っているので、消したいです。

はい、ログを見ましたが、インストール情報ログだけまだ出てないので、このログも追加で見せてください。

それとRealはアンインストールしたということですね。
ではこれの処置もしますか。

CCを起動して「スケジュールされたタスク」内の下記を右クリックから「無効」にしたあと「エントリの削除」してください。
>有効 Task RealDownloaderRealUpgradeLogonTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe /logoncheck
>有効 Task RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe /scheduledcheck
>有効 Task RealPlayerRealUpgradeLogonTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /logoncheck
>有効 Task RealPlayerRealUpgradeScheduledTaskS-1-5-21-3953051745-2568508545-2191147087-1000 C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /scheduledcheck

ここにまだRealが残っているのがわかるでしょう。しかも「有効」状態なら生きて動いているということです。
目障りなのでここで息の根を止めましょう(←この辺が悪代官

これができたらインストール情報ログをレスで見せてください
  • 悪代官
  • 2015/04/04 (Sat) 21:14:55
インストール情報ログ
CCのスタートアップに気が取られて、インストール情報ログを忘れてました。

インストール情報ログ
Adobe AIR Adobe Systems Incorporated 2015/03/14 17.0.0.124
Adobe Flash Player 17 ActiveX Adobe Systems Incorporated 2015/03/14 6.00 MB 17.0.0.134
Adobe Flash Player 17 NPAPI Adobe Systems Incorporated 2015/03/14 6.00 MB 17.0.0.134
Adobe Reader XI (11.0.10) - Japanese Adobe Systems Incorporated 2014/12/12 203 MB 11.0.10
Adobe Shockwave Player 12.1 Adobe Systems, Inc. 2015/03/22 12.1.7.157
AgainTyper 2013/05/31
AGMDecoder T.Ishii (t-ishii@js2.so-net.ne.jp) 2014/05/05 344 KB 1.1.1
AGMDecoder64 T.Ishii (t-ishii@js2.so-net.ne.jp) 2014/05/05 224 KB 1.1.1
AMD Catalyst Install Manager Advanced Micro Devices, Inc. 2014/12/09 26.7 MB 8.0.916.0
Apple Application Support Apple Inc. 2014/02/26 64.0 MB 2.3.6
Apple Software Update Apple Inc. 2013/05/31 2.38 MB 2.1.3.127
Avast Free Antivirus AVAST Software 2015/03/17 10.2.2214
AviSynth 2.5 2013/10/26
BD_3D Advisor CyberLink Corp. 2013/07/21 12.6 MB 2.0.5913
CCleaner Piriform 2015/03/30 5.04
CDBurnerXP CDBurnerXP 2014/09/10 13.2 MB 4.5.4.5000
CyberLink Media Suite 10 CyberLink Corp. 2013/07/21 277 MB 10.0
Defraggler Piriform 2013/12/22 2.16
DivXセットアップ DivX, LLC 2014/09/21 2.6.1.8
EMET 5.2 Microsoft Corporation 2015/03/22 56.6 MB 5.2
EPSON EP-806A Series プリンター アンインストール SEIKO EPSON Corporation 2014/09/20
EPSON Scan Seiko Epson Corporation 2014/09/20
EPSON マニュアル SEIKO EPSON CORPORATION 2015/03/29 704 KB 1.32.0.0
EpsonNet Print SEIKO EPSON CORPORATION 2014/09/20 2.6.0
FormatFactory 3.6.0.0 Format Factory 2015/02/27 3.6.0.0
Google 日本語入力 Google Inc. 2014/10/28 84.1 MB 1.13.1641.0
Intel(R) Management Engine Components Intel Corporation 2015/03/30 9.5.15.1730
Intel(R) Processor Graphics Intel Corporation 2014/06/11 10.18.10.3621
Intel(R) Rapid Storage Technology Intel Corporation 2015/04/04 13.6.0.1002
Intel(R) SDK for OpenCL - CPU Only Runtime Package Intel Corporation 2013/05/31 3.0.0.63463
Intel(R) Update Manager Intel Corporation 2014/04/18 22.6 MB 2.3.1338
Intel(R) USB 3.0 eXtensible Host Controller Driver Intel Corporation 2015/04/04 1.0.10.255
Intel® Driver Update Utility Intel 2015/04/03 6.91 MB 2.0.0.29
Intel® SSD Toolbox Intel Corporation 2014/11/12 3.2.3.400
IObit Uninstaller IObit 2015/02/19 4.2.6.2
IP Messenger for Win 2013/05/31
Java 7 Update 76 Oracle 2015/02/13 120 MB 7.0.760
Java 7 Update 9 Oracle 2013/05/31 130 MB 7.0.90
Java 8 Update 25 Oracle Corporation 2014/10/15 73.3 MB 8.0.250
Java 8 Update 31 Oracle Corporation 2015/01/31 74.0 MB 8.0.310
Java 8 Update 40 Oracle Corporation 2015/03/14 76.9 MB 8.0.400
JUSTオンラインアップデート 株式会社ジャストシステム 2014/06/11 1.0.1.0
Lagarith Lossless Codec (1.3.27) 2014/09/21 1.02 MB
Media Go Sony 2014/10/28 148 MB 2.8.303
Media Go Network Downloader Sony 2014/10/28 1.33 MB 1.5.19.0
Media Go Video Playback Engine 2.12.110.06300 Sony 2014/10/28 21.0 MB 2.12.110.06300
Microsoft .NET Framework 4.5.2 Microsoft Corporation 2015/01/15 38.8 MB 4.5.51209
Microsoft .NET Framework 4.5.2 (日本語) Microsoft Corporation 2015/02/14 2.93 MB 4.5.51209
Microsoft Office 365 Small Business Premium - ja-jp Microsoft Corporation 2015/03/14 15.0.4701.1002
Microsoft Silverlight Microsoft Corporation 2014/07/24 298 MB 5.1.30514.0
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2014/04/30 1.69 MB 3.1.0000
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2013/05/31 300 KB 8.0.59193
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 Microsoft Corporation 2014/09/14 894 KB 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2014/03/08 788 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2014/07/17 232 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 2014/03/09 786 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Corporation 2015/02/16 1.41 MB 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2014/02/01 238 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2014/08/10 230 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2014/07/17 222 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2013/05/31 598 KB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2015/03/30 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2015/03/30 11.1 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Corporation 2015/02/12 20.5 MB 11.0.61030.0
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 2015/02/12 17.3 MB 11.0.61030.0
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 Microsoft Corporation 2014/10/28 17.1 MB 12.0.21005.1
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Microsoft Corporation 2015/02/13 10.0.50903
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - 日本語 Microsoft Corporation 2015/02/13 10.0.50903
Mozilla Firefox 37.0.1 (x86 ja) Mozilla 2015/04/04 84.4 MB 37.0.1
Mozilla Maintenance Service Mozilla 2014/04/30 341 KB 29.0
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2013/06/01 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2013/06/01 1.33 MB 4.20.9876.0
MSXML 4.0 SP2 パーサーと SDK Microsoft Corporation 2013/05/31 1.22 MB 4.20.9818.0
MyEPSON Portal SEIKO EPSON Corporation 2014/09/20
NextFTP 2013/05/31
OpenSource Flash Video Splitter 1.0.0.5 2014/09/21 1.0.0.5
PDF reDirect (remove only) EXP Systems LLC 2013/07/09 v2.5.2
PhishWall SecureBrain Corporation 2014/04/19 3.5.8
QUAD-CAPTURE Driver Roland Corporation 2013/05/31
Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver Qualcomm Atheros Inc. 2015/04/04 2.1.0.21
QuickTime 7 Apple Inc. 2014/10/29 70.2 MB 7.76.80.95
Shuriken 2012 株式会社ジャストシステム 2013/05/31 84.5 MB 11.0.4
SignalNow Express ストラテジー株式会社 2015/03/08 2.0.0.0
Software Updater SEIKO EPSON CORPORATION 2015/03/29 10.0 MB 4.3.7
Sony Media Library Earth 9.2.00 Sony Corporation 2015/02/10 49.5 MB 9.2.00.01271
Sony Mobile Update Engine Sony Mobile Communications AB 2014/02/15 2.14.2.201402071544
Sony PC Companion 2.10.245 Sony 2015/02/22 19.6 MB 2.10.245
System Requirements Lab for Intel Husdawg, LLC 2014/08/14 1.12 MB 4.5.24.0
UltraVnc uvnc bvba 2013/05/31 12.3 MB 1.1.9.0
Vb5rs3 2013/05/31
VIA プラットフォーム・デバイス・マネージャ VIA Technologies, Inc. 2013/05/31 2.62 MB 1.38
VirtualCloneDrive Elaborate Bytes 2013/05/31
VMware Player VMware, Inc 2015/02/07 390 MB 6.0.5
Winamp Nullsoft, Inc 2013/11/27 5.666
Windows Live Essentials Microsoft Corporation 2014/04/30 16.4.3528.0331
Wise Registry Cleaner 8.31 WiseCleaner.com, Inc. 2015/01/05 7.12 MB 8.31
x-アプリ 6.0.01 Sony Corporation 2015/02/10 88.6 MB 10.0.01
x64 Components v4.7.6 Shark007 2014/09/21 91.1 MB 4.7.6
Xvid Video Codec Xvid Team 2014/09/21 1.3.2
「テプラ」PRO PCラベルソフト SPC9C KING JIM 2013/11/17 3.70.000
「テプラ」PRO SPC9C プリンタドライバ 2013/11/17
らくちんCDラベルメーカー15 MediaNavi 2013/05/31 15.0.0.0
チャクモエ for PC メイドボイス 2013/05/31
ナビマスター S V1.0 クラリオン株式会社 2014/06/21 15.2 MB 1.0.0
ミュージックCDデザイナー3 MEGASOFT Inc. 2013/06/09
ラベル屋さん9 A-one Co.,Ltd. 2014/10/11 9.0.700
付箋紙21 2013/05/31
秀丸エディタ (8.21) 有限会社サイトー企画 2013/05/31 8.21
秀丸パブリッシャー 2013/05/31
筆まめ Ver.24 販売元:株式会社筆まめ 開発元:株式会社モーリン 2014/12/20 1.12 GB 24.09.2410.0
電波時計用JJYシミュレータ スタアストーンソフト 2014/03/15 656 KB 1.0.5.0

それから、Realのタスクを止めました。
有効 Task Adobe Acrobat Update Task Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task BELL D:\W32_TOOL\HitoKoe10.exe
有効 Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task EPSON EP-806A Series Update {06D96841-E0D2-4E1C-AB1C-7A5B5087D513} SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLKJ.EXE /EXE:"{06D96841-E0D2-4E1C-AB1C-7A5B5087D513}" /F:"Update"
有効 Task GO_BED1 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GO_BED2 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task Intel_C_CVKI302402M9240DGN Intel C:\Program Files (x86)\Intel\Intel(R) SSD Toolbox\Intel SSD Toolbox.exe -drive_letter C -drive_serial CVKI302402M9240DGN -trim scheduled
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 Intel® Services Manager C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon Intel® Services Manager "C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe" --automatic
有効 Task SidebarExecute Microsoft Corporation C:\Program Files\Windows Sidebar\sidebar.exe
有効 Task Uninstaller_SkipUac_ME IObit C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer
有効 Task Wise Registry Cleaner Schedule Task WiseCleaner.com C:\Program Files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe -a
  • pxu10652
  • 2015/04/05 (Sun) 11:09:20
あとはOfficeですか
作業と報告、ご苦労様です。
Real系はCCから処置しましたね。
インストール情報ログも見せてもらいました。
こちらで異常の痕跡はなさそうです。

あとはOffice関連の異常ですか。

でもそれ関連の起動痕跡は見えませんね。
件の異常もまだ続いてますか?

ログには出なくても異常が起きることも珍しくないので、異常が続いているならもう少し調べてみましょうか。

Officeの異常が続いているなら、それが起きる時の共通状態があればそれを教えてください。
特定のアプリを起動した直後にOfficeが起動するとかならそのあたりから調べてみましょうか
  • 悪代官
  • 2015/04/05 (Sun) 17:41:49
Officeの件
 Excel2013やWord2013を使用して終了させたのに、「再起動しています」と言うメッセージが出て、
ExcelやWordが新規文書作成の状態で起動することがあります。ただ、使用頻度があまり高くないので、
ちょっと変な動きするかなッて感じです。ひとまず、コンパネからOffice2013(Office365)の復旧を
実施しました。これで、1~2週間様子を見てみたいと思っています。
  • pxu10652
  • 2015/04/07 (Tue) 22:49:18
Officeの件 その2
Office2013(Office365)の復旧をしても発生したので、昨日アンインストールして、再インストールしました。
今日使ってみたら、「再起動しています」が発生しました。気持ち悪いですけど、実害はないので、このままで
良いかなと思っています。
  • pxu10652
  • 2015/04/10 (Fri) 22:23:10
CCでOffice拡張の修復を
レスが遅くなってすみません。
またOfficeで異常出てますか。

ただ、説明やログを見る限りではその症状はマルウェアによるものとは見えないと思います。
どちらかというとOfficeかWindowsの異常による疑いがあります。
その異常にについては自分でははっきりした原因はまだつかめないので、うかつに間違った対処を指示するのも危険ですからこれ以上は控えておきます。
直接の改善にならなくてごめんなさい。

ただMS OfficeでのトラブルならMSの公式サポートを受けられるはずなので、そちらに連絡を取ってみてはどうでしょうか。
http://www.microsoft.com/ja-jp/office/365/default.aspx

それと、CCを起動して「Windows」タブ内の下記を「有効」に戻しておいてください。
>無効 Extension Lync Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
>無効 Extension Lync Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
>無効 Helper Lync Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
>無効 Helper Lync Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
>無効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
>無効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL

これらは見てのとおりOffice 15のエントリですが無効になってますね。
もしかしたらこれが無効になっている影響でアプリが不安定化しているかもしれませんから、有効にしたうえで異常が修復できるかも見てください
  • 悪代官
  • 2015/04/11 (Sat) 22:23:35
CCのスタートアップIEのログ
「それと、CCを起動して「Windows」タブ内の下記を「有効」に戻しておいてください。」

 再インストールした際に、有効に再設定されたようです。その状態で、「再起動しています」が発生しています。

 ログを見ると、MS関連で、2つ「無効」になっているものがありますが、「有効」を押しても「自動起動「有効/無効」の指定に失敗:アクセスが拒否されました。」と出ます。

有効 Extension Lync Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
有効 Extension Lync Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
有効 Helper avast! Online Security Avast Software s.r.o. C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
有効 Helper avast! Online Security Avast Software s.r.o. C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
有効 Helper ExplorerWnd Helper IObit C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll
有効 Helper Lync Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
有効 Helper Lync Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
有効 Helper Microsoft SkyDrive Pro Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
有効 Helper Microsoft SkyDrive Pro Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
無効 Helper Microsoft アカウント サインイン ヘルパー Microsoft Corp. C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
有効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
有効 Helper PhishWall SecureBrain Corporation C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
無効 Helper Windows Live ID Sign-in Helper Microsoft Corp. C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 Toolbar PhishWall SecureBrain Corporation C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
  • pxu10652
  • 2015/04/11 (Sat) 23:15:35
EMETをアンインストールしたら、改善!?
 Officeで「再起動しています」が出始めたのが、EMETをバージョンアップしてからだった気がしたので、
EMETをアンインストールしたら症状が収まった気がします。このまま1週間ぐらい様子を見てみます。
  • pxu10652
  • 2015/04/12 (Sun) 12:03:28
久々にEMETが競合してましたか
レスが遅くなってすみません。

>Officeで「再起動しています」が出始めたのが、EMETをバージョンアップしてからだった気がしたので、
>EMETをアンインストールしたら症状が収まった気がします

はい、EMETが引っかかっていた疑いがありましたか。
確かに以前に他の方の相談でEMET設定で詰まったような事例もあったのですが、久々にそれでしたか。
以前に他の方のスレでEMETでの競合を調べたことも幾度かありましたが、これの削除や無効化で治まることはほとんどなかったので今回も見落としてました。
どうも自分の判断ミスだったようです。
いけねぇ、こいつはうっかりだぁ!(←それ悪代官ポジションじゃないから

ではそのまま様子見をお願いします。
様子見後に再発も出ないならこれ絡みと判断できそうですが、その場合は他の方のトラブルにもかなり役立つ情報になりそうです
  • 悪代官
  • 2015/04/13 (Mon) 20:21:19
EMETをアンインストールしたら、改善しました。
Officeで「再起動しています」のメッセージは、EMETをアンインストール後、出なくなりました。
PCの挙動は安定しています。これで、対応完了になりますでしょうか?
  • pxu10652
  • 2015/04/18 (Sat) 22:36:08
やはりEMET確定ですね
おはようございます。

>Officeで「再起動しています」のメッセージは、EMETをアンインストール後、出なくなりました。

はい、どうやらEMET絡みと確定ですね。
これも妙な干渉による不具合が出だしているんでしょうか。
使い方次第では自衛の上でかなり有用ですが、バージョンアップで安定性に難が出ているのかもしれません。
各ユーザーのPC環境によっても影響する可能性がありますが、とりあえずEMETはそのまま非使用がいいでしょう。

では現在特に異常も出てないようですが、一応状態を再確認してみましょう。
お手数ですがまたCCの各タブのログと、HJTとインストール情報のログを取り直して、それらを見せてもらえますか。
他の方のスレでも処置後に再感染や再発の事例がやたらと目立ってきているので、最後まで気を抜かずに見てみましょう
  • 悪代官
  • 2015/04/19 (Sun) 08:07:15
現状のログです
HJTのログ

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 22:29:58, on 2015/04/19
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17728)

FIREFOX: 37.0.1 (x86 ja)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\EPSON\MyEPSON Connect\mep.exe
C:\VIA_XHCI\usb3Monitor.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\AgnType\AgnType.exe
C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
D:\W32_TOOL\TinyMon.exe
C:\Program Files (x86)\husen2K\Husen2K.exe
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaConverter.exe
C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaRenderer.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Justsystems\Shuriken\JsvMail.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
C:\Users\ME\Desktop\ウィルス対策\HJT(HijackThis).exe

F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll
O2 - BHO: PhishWall - {8CA7E745-EF75-4E7B-BB86-8065C0CE29CA} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft アカウント サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll
O3 - Toolbar: PhishWall - {BB62FFF4-41CB-4AFC-BB8C-2A4D4B42BBDC} - C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [JustOnlineUpdate] "C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe" /startup
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Google Japanese Input Prelauncher] "C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe" --mode=prelaunch_processes
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [IME14 JPN Uninstall] C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /JPN /Log
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: AgainTyper.lnk = C:\Program Files (x86)\AgnType\AgnType.exe
O4 - Startup: HitoKoe10.lnk = D:\W32_TOOL\GO_START\HitoKoe10.exe
O4 - Startup: IPMSG for Win32.lnk = C:\Program Files\IPMsg\ipmsg.exe
O4 - Startup: KYOU.lnk = D:\W32_TOOL\KYOU.EXE
O4 - Startup: Shuriken着信監視.lnk = C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
O4 - Startup: TinyMon.lnk = D:\W32_TOOL\TinyMon.exe
O4 - Startup: 付箋紙21.lnk = C:\Program Files (x86)\husen2K\Husen2K.exe
O4 - Global Startup: SignalNowExpress.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: SunのJavaコンソール - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://gdmp.canon.jp
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {AF4D6906-EB10-48C1-A0CF-9328196158AE} (PrintControl) - http://gdmp.canon.jp/gundam/activex/PrintControl.ocx
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com/bin/srldetect_intel_4.5.22.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D89B3FF-5B44-4C7F-8D7F-9EC2661F9409}: NameServer = 192.168.1.1
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: CyberLink Product - 2013/07/21 18:58:07 (CLKMSVC10_38F51D56) - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe,-100 (GoogleIMEJaCacheService) - Google Inc. - C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaCacheService.exe
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mei006h Service (Mei006h) - Unknown owner - C:\Windows\SysWOW64\mei006h.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyEPSON Connect Service - SEIKO EPSON CORPORATION - C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SDPAUMS server service (SDPASVC) - Unknown owner - C:\Windows\SysWOW64\sdpasvc.exe (file missing)
O23 - Service: SecureBrain PhishWall Update - SecureBrain Corporation - C:\Program Files (x86)\SecureBrain\PhishWall\sbpwupdx.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service2 - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeService2.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TEPRA Driver Option UI Manager (TepOuService) - Unknown owner - C:\Windows\system32\TPOUSVR.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: uvnc_service - UltraVNC - C:\Program Files\uvnc bvba\UltraVNC\WinVNC.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 16266 bytes

インストール情報
Adobe AIR Adobe Systems Incorporated 2015/04/16 17.0.0.144
Adobe Flash Player 17 ActiveX Adobe Systems Incorporated 2015/04/15 6.00 MB 17.0.0.169
Adobe Flash Player 17 NPAPI Adobe Systems Incorporated 2015/04/16 6.00 MB 17.0.0.169
Adobe Reader XI (11.0.10) - Japanese Adobe Systems Incorporated 2014/12/12 203 MB 11.0.10
Adobe Shockwave Player 12.1 Adobe Systems, Inc. 2015/03/22 12.1.7.157
AgainTyper 2013/05/31
AGMDecoder T.Ishii (t-ishii@js2.so-net.ne.jp) 2014/05/05 344 KB 1.1.1
AGMDecoder64 T.Ishii (t-ishii@js2.so-net.ne.jp) 2014/05/05 224 KB 1.1.1
AMD Catalyst Install Manager Advanced Micro Devices, Inc. 2014/12/09 26.7 MB 8.0.916.0
Apple Application Support Apple Inc. 2014/02/26 64.0 MB 2.3.6
Apple Software Update Apple Inc. 2013/05/31 2.38 MB 2.1.3.127
Avast Free Antivirus AVAST Software 2015/04/13 10.2.2215
AviSynth 2.5 2013/10/26
BD_3D Advisor CyberLink Corp. 2013/07/21 12.6 MB 2.0.5913
CCleaner Piriform 2015/03/30 5.04
CDBurnerXP CDBurnerXP 2014/09/10 13.2 MB 4.5.4.5000
CyberLink Media Suite 10 CyberLink Corp. 2013/07/21 277 MB 10.0
Defraggler Piriform 2013/12/22 2.16
DivXセットアップ DivX, LLC 2014/09/21 2.6.1.8
EPSON EP-806A Series プリンター アンインストール SEIKO EPSON Corporation 2014/09/20
EPSON Scan Seiko Epson Corporation 2014/09/20
EPSON マニュアル SEIKO EPSON CORPORATION 2015/03/29 704 KB 1.32.0.0
EpsonNet Print SEIKO EPSON CORPORATION 2014/09/20 2.6.0
FormatFactory 3.6.0.0 Format Factory 2015/02/27 3.6.0.0
Google 日本語入力 Google Inc. 2014/10/28 84.1 MB 1.13.1641.0
Intel(R) Management Engine Components Intel Corporation 2015/03/30 9.5.15.1730
Intel(R) Processor Graphics Intel Corporation 2014/06/11 10.18.10.3621
Intel(R) Rapid Storage Technology Intel Corporation 2015/04/04 13.6.0.1002
Intel(R) SDK for OpenCL - CPU Only Runtime Package Intel Corporation 2013/05/31 3.0.0.63463
Intel(R) Update Manager Intel Corporation 2014/04/18 22.6 MB 2.3.1338
Intel(R) USB 3.0 eXtensible Host Controller Driver Intel Corporation 2015/04/04 1.0.10.255
Intel® Driver Update Utility Intel 2015/04/03 6.91 MB 2.0.0.29
Intel® SSD Toolbox Intel Corporation 2014/11/12 3.2.3.400
IObit Uninstaller IObit 2015/02/19 4.2.6.2
IP Messenger for Win 2013/05/31
Java 7 Update 76 Oracle 2015/02/13 120 MB 7.0.760
Java 8 Update 45 Oracle Corporation 2015/04/19 9.33 MB 8.0.450
JUSTオンラインアップデート 株式会社ジャストシステム 2014/06/11 1.0.1.0
Lagarith Lossless Codec (1.3.27) 2014/09/21 1.02 MB
Media Go Sony 2014/10/28 148 MB 2.8.303
Media Go Network Downloader Sony 2014/10/28 1.33 MB 1.5.19.0
Media Go Video Playback Engine 2.12.110.06300 Sony 2014/10/28 21.0 MB 2.12.110.06300
Microsoft .NET Framework 4.5.2 Microsoft Corporation 2015/01/15 38.8 MB 4.5.51209
Microsoft .NET Framework 4.5.2 (日本語) Microsoft Corporation 2015/02/14 2.93 MB 4.5.51209
Microsoft Office 365 Small Business Premium - ja-jp Microsoft Corporation 2015/04/17 15.0.4711.1002
Microsoft Silverlight Microsoft Corporation 2014/07/24 298 MB 5.1.30514.0
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2014/04/30 1.69 MB 3.1.0000
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2013/05/31 300 KB 8.0.59193
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 Microsoft Corporation 2014/09/14 894 KB 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 2014/03/08 788 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 2014/07/17 232 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 2014/03/09 786 KB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Corporation 2015/02/16 1.41 MB 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2014/02/01 238 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2014/08/10 230 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 2014/07/17 222 KB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2013/05/31 598 KB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2015/03/30 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2015/03/30 11.1 MB 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Corporation 2015/02/12 20.5 MB 11.0.61030.0
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 2015/02/12 17.3 MB 11.0.61030.0
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 Microsoft Corporation 2014/10/28 17.1 MB 12.0.21005.1
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Microsoft Corporation 2015/02/13 10.0.50903
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - 日本語 Microsoft Corporation 2015/02/13 10.0.50903
Mozilla Firefox 37.0.1 (x86 ja) Mozilla 2015/04/04 84.4 MB 37.0.1
Mozilla Maintenance Service Mozilla 2014/04/30 341 KB 29.0
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 2013/06/01 1.27 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 2013/06/01 1.33 MB 4.20.9876.0
MSXML 4.0 SP2 パーサーと SDK Microsoft Corporation 2013/05/31 1.22 MB 4.20.9818.0
MyEPSON Portal SEIKO EPSON Corporation 2014/09/20
NextFTP 2013/05/31
OpenSource Flash Video Splitter 1.0.0.5 2014/09/21 1.0.0.5
PDF reDirect (remove only) EXP Systems LLC 2013/07/09 v2.5.2
PhishWall SecureBrain Corporation 2014/04/19 3.5.8
QUAD-CAPTURE Driver Roland Corporation 2013/05/31
Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver Qualcomm Atheros Inc. 2015/04/04 2.1.0.21
QuickTime 7 Apple Inc. 2014/10/29 70.2 MB 7.76.80.95
Shuriken 2012 株式会社ジャストシステム 2013/05/31 84.5 MB 11.0.4
SignalNow Express ストラテジー株式会社 2015/03/08 2.0.0.0
Software Updater SEIKO EPSON CORPORATION 2015/03/29 10.0 MB 4.3.7
Sony Media Library Earth 9.2.00 Sony Corporation 2015/02/10 49.5 MB 9.2.00.01271
Sony Mobile Update Engine Sony Mobile Communications AB 2014/02/15 2.14.2.201402071544
Sony PC Companion 2.10.245 Sony 2015/02/22 19.6 MB 2.10.245
System Requirements Lab for Intel Husdawg, LLC 2014/08/14 1.12 MB 4.5.24.0
UltraVnc uvnc bvba 2013/05/31 12.3 MB 1.1.9.0
Vb5rs3 2013/05/31
VIA プラットフォーム・デバイス・マネージャ VIA Technologies, Inc. 2013/05/31 2.62 MB 1.38
VirtualCloneDrive Elaborate Bytes 2013/05/31
VMware Player VMware, Inc 2015/02/07 390 MB 6.0.5
Winamp Nullsoft, Inc 2013/11/27 5.666
Windows Live Essentials Microsoft Corporation 2014/04/30 16.4.3528.0331
Wise Registry Cleaner 8.31 WiseCleaner.com, Inc. 2015/01/05 7.12 MB 8.31
x-アプリ 6.0.01 Sony Corporation 2015/02/10 88.6 MB 10.0.01
x64 Components v4.7.6 Shark007 2014/09/21 91.1 MB 4.7.6
Xvid Video Codec Xvid Team 2014/09/21 1.3.2
「テプラ」PRO PCラベルソフト SPC9C KING JIM 2013/11/17 3.70.000
「テプラ」PRO SPC9C プリンタドライバ 2013/11/17
らくちんCDラベルメーカー15 MediaNavi 2013/05/31 15.0.0.0
チャクモエ for PC メイドボイス 2013/05/31
ナビマスター S V1.0 クラリオン株式会社 2014/06/21 15.2 MB 1.0.0
ミュージックCDデザイナー3 MEGASOFT Inc. 2013/06/09
ラベル屋さん9 A-one Co.,Ltd. 2014/10/11 9.0.700
付箋紙21 2013/05/31
秀丸エディタ (8.21) 有限会社サイトー企画 2013/05/31 8.21
秀丸パブリッシャー 2013/05/31
筆まめ Ver.24 販売元:株式会社筆まめ 開発元:株式会社モーリン 2014/12/20 1.12 GB 24.09.2410.0
証明写真をつくろう! ニコニコソフト 2015/04/12
電波時計用JJYシミュレータ スタアストーンソフト 2014/03/15 656 KB 1.0.5.0

スタートアップ
有効 HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run Sidebar Microsoft Corporation C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
有効 HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
有効 HKLM:Run AvastUI.exe Avast Software s.r.o. "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
有効 HKLM:Run BDRegion cyberlink C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
有効 HKLM:Run DivXMediaServer DivX, LLC C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
有効 HKLM:Run DivXUpdate DivX, LLC "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
有効 HKLM:Run Google Japanese Input Prelauncher Google Inc. "C:\Program Files (x86)\Google\Google Japanese Input\GoogleIMEJaBroker32.exe" --mode=prelaunch_processes
有効 HKLM:Run IAStorIcon Intel Corporation "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
有効 HKLM:Run IME14 JPN Uninstall Microsoft Corporation C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /JPN /Log
有効 HKLM:Run JustOnlineUpdate 株式会社ジャストシステム "C:\Program Files (x86)\Common Files\Justsystem\JustOnlineUpdate\JustOnlineUpdate.exe" /startup
有効 HKLM:Run QuickTime Task Apple Inc. "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
有効 HKLM:Run RemoteControl10 CyberLink Corp. "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
有効 HKLM:Run StartCCC Advanced Micro Devices, Inc. "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
有効 HKLM:Run TepOuService KING JIM CO.,LTD. C:\Windows\system32\TPOUSVR.EXE -uimanage
有効 HKLM:Run USB3MON Intel Corporation "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
有効 HKLM:Run VIAxHCUtl VIA Technologies, Inc. C:\VIA_XHCI\usb3Monitor.exe
有効 HKLM:Run VirtualCloneDrive Elaborate Bytes AG "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
有効 Startup Common SignalNowExpress.lnk ストラテジー株式会社 C:\Program Files (x86)\ストラテジー株式会社\SignalNow Express\SignalNowExpress.exe
有効 Startup User AgainTyper.lnk C:\Program Files (x86)\AgnType\AgnType.exe
有効 Startup User HitoKoe10.lnk D:\W32_TOOL\GO_START\HitoKoe10.exe
有効 Startup User IPMSG for Win32.lnk H.Shirouzu C:\Program Files\IPMsg\ipmsg.exe
有効 Startup User KYOU.lnk D:\W32_TOOL\KYOU.EXE
有効 Startup User Shuriken着信監視.lnk 株式会社ジャストシステム C:\Program Files (x86)\Justsystems\Shuriken\JsvBiff.exe
有効 Startup User TinyMon.lnk D:\W32_TOOL\TinyMon.exe
有効 Startup User 付箋紙21.lnk ROTO C:\Program Files (x86)\husen2K\Husen2K.exe

スタートアップ(IE)
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
有効 Extension OneNote Linked Notes Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
有効 Extension Send to OneNote Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
有効 Extension Skype for Business Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
有効 Extension Skype for Business Click to Call Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
有効 Helper avast! Online Security Avast Software s.r.o. C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
有効 Helper avast! Online Security Avast Software s.r.o. C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
有効 Helper ExplorerWnd Helper IObit C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
有効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll
有効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll
有効 Helper Microsoft SkyDrive Pro Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
有効 Helper Microsoft SkyDrive Pro Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
無効 Helper Microsoft アカウント サインイン ヘルパー Microsoft Corp. C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
有効 Helper Office Document Cache Handler Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
有効 Helper PhishWall SecureBrain Corporation C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll
有効 Helper Skype for Business Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
有効 Helper Skype for Business Browser Helper Microsoft Corporation C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
無効 Helper Windows Live ID Sign-in Helper Microsoft Corp. C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
有効 Toolbar PhishWall SecureBrain Corporation C:\Program Files (x86)\SecureBrain\PhishWall\sbpw32.dll

スタートアップ(Firefox)
有効 Extension Avast Online Security 10.2.0.187 AVAST Software default Firefox 37.0.1 C:\Program Files\AVAST Software\Avast\WebRep\FF
有効 Plugin Adobe Acrobat 11.0.10.32 Adobe Systems Inc. default Firefox 37.0.1 C:\Program Files (x86)\Adobe\Reader 11.0\Reader\browser\nppdf32.dll
有効 Plugin DivX Plus Web Player 3.2.3.1164 DivX, LLC default Firefox 37.0.1 C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll
有効 Plugin DivX VOD Helper Plug-in 1.1.0.14 DivX, LLC. default Firefox 37.0.1 C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
有効 Plugin Google Update 1.3.26.9 Google Inc. default Firefox 37.0.1 C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
有効 Plugin Intel® Identity Protection Technology 4.0.5.0 Intel Corporation default Firefox 37.0.1 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
有効 Plugin Intel® Identity Protection Technology 4.0.5.0 Intel Corporation default Firefox 37.0.1 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
有効 Plugin Java Deployment Toolkit 8.0.450.14 11.45.2.14 Oracle Corporation default Firefox 37.0.1 C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npdeployJava1.dll
有効 Plugin Java(TM) Platform SE 8 U45 11.45.2.14 Oracle Corporation default Firefox 37.0.1 C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll
有効 Plugin Microsoft Office 2013 15.0.4514.1000 Microsoft Corporation default Firefox 37.0.1 C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL
有効 Plugin Microsoft Office 2013 15.0.4703.1000 Microsoft Corporation default Firefox 37.0.1 C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
有効 Plugin Photo Gallery 16.4.3528.331 Microsoft Corporation default Firefox 37.0.1 C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
有効 Plugin QuickTime Plug-in 7.7.6 7.7.6.0 Apple Inc. default Firefox 37.0.1 C:\Program Files (x86)\QuickTime\Plugins\npqtplugin5.dll
有効 Plugin Shockwave Flash 17.0.0.169 Adobe Systems Incorporated default Firefox 37.0.1 C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll
有効 Plugin Shockwave for Director 12.1.7.157 Adobe Systems, Inc. default Firefox 37.0.1 C:\Windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll
有効 Plugin Silverlight Plug-In 5.1.30514.0 Microsoft Corporation default Firefox 37.0.1 C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

タスク
有効 Task Adobe Acrobat Update Task Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task BELL D:\W32_TOOL\HitoKoe10.exe
有効 Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task EPSON EP-806A Series Update {06D96841-E0D2-4E1C-AB1C-7A5B5087D513} SEIKO EPSON CORPORATION C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLKJ.EXE /EXE:"{06D96841-E0D2-4E1C-AB1C-7A5B5087D513}" /F:"Update"
有効 Task GO_BED1 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GO_BED2 D:\W32_TOOL\GO_BED\Sukoe20.exe
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task Intel_C_CVKI302402M9240DGN Intel C:\Program Files (x86)\Intel\Intel(R) SSD Toolbox\Intel SSD Toolbox.exe -drive_letter C -drive_serial CVKI302402M9240DGN -trim scheduled
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 Intel® Services Manager C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic
有効 Task IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon Intel® Services Manager "C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe" --automatic
有効 Task SidebarExecute Microsoft Corporation C:\Program Files\Windows Sidebar\sidebar.exe
有効 Task Uninstaller_SkipUac_ME IObit C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer
有効 Task Wise Registry Cleaner Schedule Task WiseCleaner.com C:\Program Files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe -a




  • pxu10652
  • 2015/04/19 (Sun) 22:37:11
なんとか乗り切ったようですね
レスが遅くなってごめんなさい。

各ログを見せてもらいましたが、不審なところは見えないですね。
では異常も出てなければ本題の処置については終了でいいかと思います。

ですがこれで完全に「解決」とは思わないでください。
以後の再被害を防ぐための自衛はここからがスタートです。
ブラウザの設定を少し固めるだけでも、セキュリティ上の効果を高めることが可能です。
「インターネットオプション」→「プライバシー」→「詳細設定」と開いて、「自動cookie処理」と「サードパーティのcookieをブロック」にチェックして「適用」して「OK」。
これをやっておくと、多くの危険サイトからの保護にかなり有効です。
が、これもすべての危険サイトに有効でもないし、本物の危険サイトではこの程度ではまったく太刀打ちできないので、過信はしないこと。
また、「すべてのcookieをブロックする」設定にすると、プロバイダのメールボックスなどログイン必要なページに入れなくなる弊害も出るので、これは状況を考えて使い分けるといいでしょう。
安全なサイトでもcookieブロックだと閲覧や投稿ができなくなるところもあるのでこれも注意。

次に、アンチウイルスやファイアウォール等のセキュリティソフトの使い方も注意してください。
セキュリティソフトはただ入れてさえいればそれだけでフル機能を発揮するものではありません。
設定と機能をできるだけ把握して、正しく使うことが重要です。
間違った使い方すると、本来ならブロックできた感染でもあっさりスルーします。

また、いくら高性能なセキュリティソフトがあっても、ユーザーが自分から危険なサイトやファイルにアクセスしてたらまったく保護もできません。
セキュリティソフトは使い方次第でその性能を、倍にも半にも無にも変動させます。

そして百聞は一見にしかず。
現在この掲示板で継続中や解決済みの他スレもできるだけ見ておくことをおすすめします。
同様、類似、別種含めて参考になる部分は多いでしょう。

悪意のプログラムやその作者は常に一般ユーザーの油断や隙を狙ってきます。
一度見つけて処置できたマルウェアでも、その後改変を繰り返して何度でも感染侵入を企みます。

一度処置できた感染でも2度続けて同じ処置が効くことはむしろ少ないことも認識しておいてください。
実際同じ名前のマルウェアでも、この掲示板で過去に相談受けた事例では毎回まったく違う手順でないと処置できなかったことも多かったのです。
悪意の者がいかに対策逃れの改変を繰り返しているかの証明ですね。

PCセキュリティの上では覚えておくべきことは多数ありますが、最初から全部頭に詰め込む必要もないので、わかる範囲からひとつずつでも消化しながらPC環境とセキュリティ意識を見直していってください。

慣れない作業を頑張ってくれてお疲れ様でした。
きれいになったPCを大事に使いながら、以後は安全で快適なPCライフを
  • 悪代官
  • 2015/04/20 (Mon) 20:55:47
お世話になりました。
 悪代官様、長い間、ありがとうございました。m(_._)m 二度とお手間を取らせないように、
気をつけたいと思います。
  • pxu10652
  • 2015/04/20 (Mon) 21:58:41

返信フォーム※初心者、通りすがり等、重複しやすい名前の利用はご遠慮ください。




プレビュー (投稿前に内容を確認)